����JFIFXX�����    $.' ",#(7),01444'9=82<.342  2!!22222222222222222222222222222222222222222222222222����"��4�� ���,�PG"Z_�4�˷����kjز�Z�,F+��_z�,�© �����zh6�٨�ic�fu���#ډb���_�N�?��wQ���5-�~�I���8����TK<5o�Iv-�����k�_U_�����~b�M��d����Ӝ�U�Hh��?]��E�w��Q���k�{��_}qFW7HTՑ��Y��F�?_�'ϔ��_�Ջt��=||I ��6�έ"�����D���/[�k�9���Y�8ds|\���Ҿp6�Ҵ���]��.����6�z<�v��@]�i%��$j��~�g��J>��no����pM[me�i$[����s�o�ᘨ�˸ nɜG-�ĨU�ycP�3.DB�li�;��hj���x7Z^�N�h������N3u{�:j�x�힞��#M&��jL P@_���� P��&��o8������9�����@Sz6�t7#O�ߋ �s}Yf�T���lmr����Z)'N��k�۞p����w\�Tȯ?�8`�O��i{wﭹW�[�r�� ��Q4F�׊���3m&L�=��h3����z~��#�\�l :�F,j@�� ʱ�wQT����8�"kJO���6�֚l����}���R�>ډK���]��y����&����p�}b��;N�1�m�r$�|��7�>e�@B�TM*-iH��g�D�)� E�m�|�ؘbҗ�a��Ҿ����t4���o���G��*oCN�rP���Q��@z,|?W[0�����:�n,jWiE��W��$~/�hp\��?��{(�0���+�Y8rΟ�+����>S-S����VN;�}�s?.����� w�9��˟<���Mq4�Wv'��{)0�1mB��V����W[�����8�/<� �%���wT^�5���b��)iM� pg�N�&ݝ��VO~�q���u���9� ����!��J27����$O-���! �:�%H��� ـ����y�ΠM=t{!S�� oK8������t<����è:a������[�����ա�H���~��w��Qz`�po�^ ����Q��n� �,uu�C�$ ^���,������8�#��:�6��e�|~���!�3�3.�\0��q��o�4`.|� ����y�Q�`~;�d�ׯ,��O�Zw�������`73�v�܋�<���Ȏ�� ـ4k��5�K�a�u�=9Yd��$>x�A�&�� j0� ���vF��� Y�|�y��� ~�6�@c��1vOp�Ig����4��l�OD���L����� R���c���j�_�uX6��3?nk��Wy�f;^*B� ��@�~a�`��Eu������+���6�L��.ü>��}y���}_�O�6�͐�:�YrG�X��kG�����l^w���~㒶sy��Iu�!� W ��X��N�7BV��O��!X�2����wvG�R�f�T#�����t�/?���%8�^�W�aT��G�cL�M���I��(J����1~�8�?aT ���]����AS�E��(��*E}� 2��#I/�׍qz��^t�̔���b�Yz4x���t�){ OH��+(E��A&�N�������XT��o��"�XC��'���)}�J�z�p� ��~5�}�^����+�6����w��c��Q�|Lp�d�H��}�(�.|����k��c4^�"�����Z?ȕ ��a<�L�!039C� �Eu�C�F�Ew�ç ;�n?�*o���B�8�bʝ���'#Rqf���M}7����]����s2tcS{�\icTx;�\��7K���P���ʇ Z O-��~��c>"��?�������P��E��O�8��@�8��G��Q�g�a�Վ���󁶠�䧘��_%#r�>�1�z�a��eb��qcPѵ��n���#L��� =��׀t� L�7�`��V���A{�C:�g���e@�w1 Xp3�c3�ġ����p��M"'-�@n4���fG��B3�DJ�8[Jo�ߐ���gK)ƛ��$���� ���8�3�����+���� �����6�ʻ���� ���S�kI�*KZlT _`���?��K����QK�d����B`�s}�>���`��*�>��,*@J�d�oF*����弝��O}�k��s��]��y�ߘ��c1G�V���<=�7��7����6�q�PT��tXԀ�!9*4�4Tހ3XΛex�46���Y��D ����� �BdemDa����\�_l,��G�/���֌7���Y�](�xTt^%�GE�����4�}bT���ڹ�����;Y)���B�Q��u��>J/J �⮶.�XԄ��j�ݳ�+E��d ��r�5�_D�1 ��o�� �B�x�΢�#���<��W�����8���R6�@g�M�.��� dr�D��>(otU��@x=��~v���2� ӣ�d�oBd��3�eO�6�㣷�����ݜ6��6Y��Qz`��S��{���\P�~z m5{J/L��1������<�e�ͅPu�b�]�ϔ���'������f�b� Zpw��c`"��i���BD@:)ִ�:�]��hv�E�w���T�l��P���"Ju�}��وV J��G6��. J/�Qgl߭�e�����@�z�Zev2u�)]կ�����7x���s�M�-<ɯ�c��r�v�����@��$�ޮ}lk���a���'����>x��O\�ZFu>�����ck#��&:��`�$�ai�>2Δ����l���oF[h��lE�ܺ�Πk:)���`�� $[6�����9�����kOw�\|���8}������ބ:��񶐕��I�A1/�=�2[�,�!��.}gN#�u����b��� ~��݊��}34q����d�E��Lc��$��"�[q�U�硬g^��%B �z���r�pJ�ru%v\h1Y�ne`ǥ:g���pQM~�^�Xi� ��`S�:V29.�P���V�?B�k�� AEvw%�_�9C�Q����wKekPؠ�\�;Io d�{ ߞo�c1eP����\� `����E=���@K<�Y���eڼ�J���w����{av�F�'�M�@/J��+9p���|]�����Iw &`��8���&M�hg��[�{��Xj��%��Ӓ�$��(����ʹN���<>�I���RY���K2�NPlL�ɀ)��&e����B+ь����( � �JTx���_?EZ� }@ 6�U���뙢ط�z��dWI�n` D����噥�[��uV��"�G&Ú����2g�}&m��?ċ�"����Om#��������� ��{�ON��"S�X��Ne��ysQ���@Fn��Vg���dX�~nj�]J�<�K]:��FW��b�������62�=��5f����JKw��bf�X�55��~J �%^����:�-�QIE��P��v�nZum� z � ~ə ���� ���ة����;�f��\v���g�8�1��f24;�V���ǔ�)����9���1\��c��v�/'Ƞ�w�������$�4�R-��t���� e�6�/�ġ �̕Ecy�J���u�B���<�W�ַ~�w[B1L۲�-JS΂�{���΃������A��20�c#��@ 0!1@AP"#2Q`$3V�%45a6�FRUq��� ����^7ׅ,$n�������+��F�`��2X'��0vM��p�L=������5��8������u�p~���.�`r�����\���O��,ư�0oS ��_�M�����l���4�kv\JSd���x���SW�<��Ae�IX����������$I���w�:S���y���›R��9�Q[���,�5�;�@]�%���u�@ *ro�lbI �� ��+���%m:�͇ZV�����u�̉����θau<�fc�.����{�4Ա� �Q����*�Sm��8\ujqs]{kN���)qO�y�_*dJ�b�7���yQqI&9�ԌK!�M}�R�;������S�T���1���i[U�ɵz�]��U)V�S6���3$K{�ߊ<�(� E]Զ[ǼENg�����'�\?#)Dkf��J���o��v���'�%ƞ�&K�u�!��b�35LX�Ϸ��63$K�a�;�9>,R��W��3�3� d�JeTYE.Mϧ��-�o�j3+y��y^�c�������VO�9NV\nd�1 ��!͕_)a�v;����թ�M�lWR1��)El��P;��yوÏ�u 3�k�5Pr6<�⒲l�!˞*��u־�n�!�l:����UNW ��%��Chx8vL'��X�@��*��)���̮��ˍ��� ���D-M�+J�U�kvK����+�x8��cY������?�Ԡ��~3mo��|�u@[XeY�C�\Kp�x8�oC�C�&����N�~3-H���� ��MX�s�u<`���~"WL��$8ξ��3���a�)|:@�m�\���^�`�@ҷ)�5p+��6���p�%i)P M���ngc�����#0Aruz���RL+xSS?���ʮ}()#�t��mˇ!��0}}y����<�e� �-ή�Ԩ��X������ MF���ԙ~l L.3���}�V뽺�v�����멬��Nl�)�2����^�Iq��a��M��qG��T�����c3#������3U�Ǎ���}��לS�|qa��ڃ�+���-��2�f����/��bz��ڐ�� �ݼ[2�ç����k�X�2�* �Z�d���J�G����M*9W���s{��w���T��x��y,�in�O�v��]���n����P�$�JB@=4�OTI�n��e�22a\����q�d���%�$��(���:���: /*�K[PR�fr\nڙdN���F�n�$�4�[�� U�zƶ����� �mʋ���,�ao�u 3�z� �x��Kn����\[��VFmbE;�_U��&V�Gg�]L�۪&#n%�$ɯ�dG���D�TI=�%+AB�Ru#��b4�1�»x�cs�YzڙJG��f��Il��d�eF'T� iA��T���uC�$����Y��H?����[!G`}���ͪ� �纤Hv\������j�Ex�K���!���OiƸ�Yj�+u-<���'q����uN�*�r\��+�]���<�wOZ.fp�ێ��,-*)V?j-kÊ#�`�r��dV����(�ݽBk�����G�ƛk�QmUڗe��Z���f}|����8�8��a���i��3'J�����~G_�^���d�8w������ R�`(�~�.��u���l�s+g�bv���W���lGc}��u���afE~1�Ue������Z�0�8�=e�� f@/�jqEKQQ�J��oN��J���W5~M>$6�Lt�;$ʳ{���^��6�{����v6���ķܰg�V�cnn �~z�x�«�,2�u�?cE+Ș�H؎�%�Za�)���X>uW�Tz�Nyo����s���FQƤ��$��*�&�LLXL)�1�" L��eO��ɟ�9=���:t��Z���c��Ž���Y?�ӭV�wv�~,Y��r�ۗ�|�y��GaF�����C�����.�+� ���v1���fήJ�����]�S��T��B��n5sW}y�$��~z�'�c ��8 ��� ,! �p��VN�S��N�N�q��y8z˱�A��4��*��'������2n<�s���^ǧ˭P�Jޮɏ�U�G�L�J�*#��<�V��t7�8����TĜ>��i}K%,���)[��z�21z ?�N�i�n1?T�I�R#��m-�����������������1����lA�`��fT5+��ܐ�c�q՝��ʐ��,���3�f2U�եmab��#ŠdQ�y>\��)�SLY����w#��.���ʑ�f��� ,"+�w�~�N�'�c�O�3F�������N<���)j��&��,-� �љ���֊�_�zS���TǦ����w�>��?�������n��U仆�V���e�����0���$�C�d���rP �m�׈e�Xm�Vu� �L��.�bֹ��� �[Դaզ���*��\y�8�Է:�Ez\�0�Kq�C b��̘��cө���Q��=0Y��s�N��S.���3.���O�o:���#���v7�[#߫ ��5�܎�L���Er4���9n��COWlG�^��0k�%<���ZB���aB_���������'=��{i�v�l�$�uC���mƎҝ{�c㱼�y]���W�i ��ߧc��m�H� m�"�"�����;Y�ߝ�Z�Ǔ�����:S#��|}�y�,/k�Ld� TA�(�AI$+I3��;Y*���Z��}|��ӧO��d�v��..#:n��f>�>���ȶI�TX��� 8��y����"d�R�|�)0���=���n4��6ⲑ�+��r<�O�܂~zh�z����7ܓ�HH�Ga롏���nCo�>������a ���~]���R���̲c?�6(�q�;5%� |�uj�~z8R=X��I�V=�|{v�Gj\gc��q����z�؋%M�ߍ����1y��#��@f^���^�>N�����#x#۹��6�Y~�?�dfPO��{��P�4��V��u1E1J �*|���%���JN��`eWu�zk M6���q t[�� ��g�G���v��WIG��u_ft����5�j�"�Y�:T��ɐ���*�;� e5���4����q$C��2d�}���� _S�L#m�Yp��O�.�C�;��c����Hi#֩%+) �Ӎ��ƲV���SYź��g |���tj��3�8���r|���V��1#;.SQ�A[���S������#���`n�+���$��$I �P\[�@�s��(�ED�z���P��])8�G#��0B��[ى��X�II�q<��9�~[Z멜�Z�⊔IWU&A>�P~�#��dp<�?����7���c��'~���5 ��+$���lx@�M�dm��n<=e�dyX��?{�|Aef ,|n3�<~z�ƃ�uۧ�����P��Y,�ӥQ�*g�#먙R�\���;T��i,��[9Qi歉����c>]9�� ��"�c��P�� �Md?٥��If�ت�u��k��/����F��9�c*9��Ǎ:�ØF���z�n*�@|I�ށ9����N3{'��[�'ͬ�Ҳ4��#}��!�V� Fu��,�,mTIk���v C�7v���B�6k�T9��1�*l� '~��ƞF��lU��'�M ����][ΩũJ_�{�i�I�n��$���L�� j��O�dx�����kza۪��#�E��Cl����x˘�o�����V���ɞ�ljr��)�/,�߬h�L��#��^��L�ф�,íMƁe�̩�NB�L�����iL����q�}��(��q��6IçJ$�W�E$��:������=#����(�K�B����zђ <��K(�N�۫K�w��^O{!����)�H���>x�������lx�?>Պ�+�>�W���,Ly!_�D���Ō�l���Q�!�[ �S����J��1��Ɛ�Y}��b,+�Lo�x�ɓ)����=�y�oh�@�꥟/��I��ѭ=��P�y9��� �ۍYӘ�e+�p�Jnϱ?V\SO%�(�t� ���=?MR�[Ș�����d�/ ��n�l��B�7j� ��!�;ӥ�/�[-���A�>�dN�sLj ��,ɪv��=1c�.SQ�O3�U���ƀ�ܽ�E����������̻��9G�ϷD�7(�}��Ävӌ\�y�_0[w ���<΍>����a_��[0+�L��F.�޺��f�>oN�T����q;���y\��bՃ��y�jH�<|q-eɏ�_?_9+P���Hp$�����[ux�K w�Mw��N�ی'$Y2�=��q���KB��P��~������Yul:�[<����F1�2�O���5=d����]Y�sw:���Ϯ���E��j,_Q��X��z`H1,#II ��d�wr��P˂@�ZJV����y$�\y�{}��^~���[:N����ߌ�U�������O��d�����ؾe��${p>G��3c���Ė�lʌ�� ת��[��`ϱ�-W����dg�I��ig2��� ��}s ��ؤ(%#sS@���~���3�X�nRG�~\jc3�v��ӍL��M[JB�T��s3}��j�Nʖ��W����;7��ç?=X�F=-�=����q�ߚ���#���='�c��7���ڑW�I(O+=:uxq�������������e2�zi+�kuG�R��������0�&e�n���iT^J����~\jy���p'dtG��s����O��3����9* �b#Ɋ�� p������[Bws�T�>d4�ۧs���nv�n���U���_�~,�v����ƜJ1��s�� �QIz��)�(lv8M���U=�;����56��G���s#�K���MP�=��LvyGd��}�VwWBF�'�à �?MH�U�g2�� ����!�p�7Q��j��ڴ����=��j�u��� Jn�A s���uM������e��Ɔ�Ҕ�!)'��8Ϣ�ٔ��ޝ(��Vp���צ֖d=�IC�J�Ǡ{q������kԭ�߸���i��@K����u�|�p=..�*+����x�����z[Aqġ#s2a�Ɗ���RR�)*HRsi�~�a &f��M��P����-K�L@��Z��Xy�'x�{}��Zm+���:�)�) IJ�-i�u���� ���ܒH��'�L(7�y�GӜq���� j��� 6ߌg1�g�o���,kر���tY�?W,���p���e���f�OQS��!K�۟cҒA�|ս�j�>��=⬒��˧L[�� �߿2JaB~R��u�:��Q�] �0H~���]�7��Ƽ�I���(}��cq '�ήET���q�?f�ab���ӥvr� �)o��-Q��_'����ᴎo��K������;��V���o��%���~OK ����*��b�f:���-ťIR��`B�5!RB@���ï�� �u �̯e\�_U�_������� g�ES��3�������QT��a����x����U<~�c?�*�#]�MW,[8O�a�x��]�1bC|踤�P��lw5V%�)�{t�<��d��5���0i�XSU��m:��Z�┵�i�"��1�^B�-��P�hJ��&)O��*�D��c�W��vM��)����}���P��ܗ-q����\mmζZ-l@�}��a��E�6��F�@��&Sg@���ݚ�M����� ȹ 4����#p�\H����dYDo�H���"��\��..R�B�H�z_�/5˘����6��KhJR��P�mƶi�m���3�,#c�co��q�a)*Pt����R�m�k�7x�D�E�\Y�閣_X�<���~�)���c[[�BP����6�Yq���S��0����%_����;��Àv�~�| VS؇ ��'O0��F0��\���U�-�d@�����7�SJ*z��3n��y��P����O���������m�~�P�3|Y��ʉr#�C�<�G~�.,! ���bqx���h~0=��!ǫ�jy����l�O,�[B��~��|9��ٱ����Xly�#�i�B��g%�S��������tˋ���e���ې��\[d�t)��.+u�|1 ������#�~Oj����hS�%��i.�~X���I�H�m��0n���c�1uE�q��cF�RF�o���7� �O�ꮧ� ���ۛ{��ʛi5�rw?׌#Qn�TW��~?y$��m\�\o����%W� ?=>S�N@�� �Ʈ���R����N�)�r"C�:��:����� �����#��qb��Y�. �6[��2K����2u�Ǧ�HYR��Q�MV��� �G�$��Q+.>�����nNH��q�^��� ����q��mM��V��D�+�-�#*�U�̒ ���p욳��u:�������IB���m���PV@O���r[b= �� ��1U�E��_Nm�yKbN�O���U�}�the�`�|6֮P>�\2�P�V���I�D�i�P�O;�9�r�mAHG�W�S]��J*�_�G��+kP�2����Ka�Z���H�'K�x�W�MZ%�O�YD�Rc+o��?�q��Ghm��d�S�oh�\�D�|:W������UA�Qc yT�q������~^�H��/��#p�CZ���T�I�1�ӏT����4��"�ČZ�����}��`w�#�*,ʹ�� ��0�i��課�Om�*�da��^gJ݅{���l�e9uF#T�ֲ��̲�ٞC"�q���ߍ ոޑ�o#�XZTp����@ o�8��(jd��xw�]�,f���`~�|,s��^����f�1���t��|��m�򸄭/ctr��5s��7�9Q�4�H1꠲BB@l9@���C�����+�wp�xu�£Yc�9��?`@#�o�mH�s2��)�=��2�.�l����jg�9$�Y�S�%*L������R�Y������7Z���,*=�䷘$�������arm�o�ϰ���UW.|�r�uf����IGw�t����Zwo��~5 ��YյhO+=8fF�)�W�7�L9lM�̘·Y���֘YLf�큹�pRF���99.A �"wz��=E\Z���'a� 2��Ǚ�#;�'}�G���*��l��^"q��+2FQ� hj��kŦ��${���ޮ-�T�٭cf�|�3#~�RJ����t��$b�(R��(����r���dx� >U b�&9,>���%E\� Ά�e�$��'�q't��*�א���ެ�b��-|d���SB�O�O��$�R+�H�)�܎�K��1m`;�J�2�Y~9��O�g8=vqD`K[�F)k�[���1m޼c��n���]s�k�z$@��)!I �x՝"v��9=�ZA=`Ɠi �:�E��)`7��vI��}d�YI�_ �o�:ob���o ���3Q��&D&�2=�� �Ά��;>�h����y.*ⅥS������Ӭ�+q&����j|UƧ����}���J0��WW< ۋS�)jQR�j���Ư��rN)�Gű�4Ѷ(�S)Ǣ�8��i��W52���No˓� ۍ%�5brOn�L�;�n��\G����=�^U�dI���8$�&���h��'���+�(������cȁ߫k�l��S^���cƗjԌE�ꭔ��gF���Ȓ��@���}O���*;e�v�WV���YJ\�]X'5��ղ�k�F��b 6R�o՜m��i N�i����>J����?��lPm�U��}>_Z&�KK��q�r��I�D�Չ~�q�3fL�:S�e>���E���-G���{L�6p�e,8��������QI��h��a�Xa��U�A'���ʂ���s�+טIjP�-��y�8ۈZ?J$��W�P� ��R�s�]��|�l(�ԓ��sƊi��o(��S0��Y� 8�T97.�����WiL��c�~�dxc�E|�2!�X�K�Ƙਫ਼�$((�6�~|d9u+�qd�^3�89��Y�6L�.I�����?���iI�q���9�)O/뚅����O���X��X�V��ZF[�یgQ�L��K1���RҖr@v�#��X�l��F���Нy�S�8�7�kF!A��sM���^rkp�jP�DyS$N���q��nxҍ!U�f�!eh�i�2�m���`�Y�I�9r�6� �TF���C}/�y�^���Η���5d�'��9A-��J��>{�_l+�`��A���[�'��յ�ϛ#w:݅�%��X�}�&�PSt�Q�"�-��\縵�/����$Ɨh�Xb�*�y��BS����;W�ջ_mc�����vt?2}1�;qS�d�d~u:2k5�2�R�~�z+|HE!)�Ǟl��7`��0�<�,�2*���Hl-��x�^����'_TV�gZA�'j� ^�2Ϊ��N7t�����?w�� �x1��f��Iz�C-Ȗ��K�^q�;���-W�DvT�7��8�Z�������� hK�(P:��Q- �8�n�Z���܃e貾�<�1�YT<�,�����"�6{/ �?�͟��|1�:�#g��W�>$����d��J��d�B��=��jf[��%rE^��il:��B���x���Sּ�1հ��,�=��*�7 fcG��#q� �eh?��2�7�����,�!7x��6�n�LC�4x��},Geǝ�tC.��vS �F�43��zz\��;QYC,6����~;RYS/6���|2���5���v��T��i����������mlv��������&� �nRh^ejR�LG�f���? �ۉҬܦƩ��|��Ȱ����>3����!v��i�ʯ�>�v��オ�X3e���_1z�Kȗ\<������!�8���V��]��?b�k41�Re��T�q��mz��TiOʦ�Z��Xq���L������q"+���2ۨ��8}�&N7XU7Ap�d�X��~�׿��&4e�o�F��� �H����O���č�c�� 懴�6���͉��+)��v;j��ݷ�� �UV�� i��� j���Y9GdÒJ1��詞�����V?h��l����l�cGs�ځ�������y�Ac�����\V3�? �� ܙg�>qH�S,�E�W�[�㺨�uch�⍸�O�}���a��>�q�6�n6����N6�q������N ! 1AQaq�0@����"2BRb�#Pr���3C`��Scst���$4D���%Td�� ?���N����a��3��m���C���w��������xA�m�q�m���m������$����4n淿t'��C"w��zU=D�\R+w�p+Y�T�&�պ@��ƃ��3ޯ?�Aﶂ��aŘ���@-�����Q�=���9D��ռ�ѻ@��M�V��P��܅�G5�f�Y<�u=,EC)�<�Fy'�"�&�չ�X~f��l�KԆV��?�� �W�N����=(� �;���{�r����ٌ�Y���h{�١������jW����P���Tc�����X�K�r��}���w�R��%��?���E��m�� �Y�q|����\lEE4���r���}�lsI�Y������f�$�=�d�yO����p�����yBj8jU�o�/�S��?�U��*������ˍ�0������u�q�m [�?f����a�� )Q�>����6#������� ?����0UQ����,IX���(6ڵ[�DI�MNލ�c&���υ�j\��X�R|,4��� j������T�hA�e��^���d���b<����n�� �즇�=!���3�^�`j�h�ȓr��jẕ�c�,ٞX����-����a�ﶔ���#�$��]w�O��Ӫ�1y%��L�Y<�wg#�ǝ�̗`�x�xa�t�w��»1���o7o5��>�m뭛C���Uƃߜ}�C���y1Xνm�F8�jI���]����H���ۺиE@I�i;r�8ӭ����V�F�Շ| ��&?�3|x�B�MuS�Ge�=Ӕ�#BE5G�����Y!z��_e��q�р/W>|-�Ci߇�t�1ޯќd�R3�u��g�=0 5��[?�#͏��q�cf���H��{ ?u�=?�?ǯ���}Z��z���hmΔ�BFTW�����<�q�(v� ��!��z���iW]*�J�V�z��gX֧A�q�&��/w���u�gYӘa���; �i=����g:��?2�dž6�ى�k�4�>�Pxs����}������G�9��3 ���)gG�R<>r h�$��'nc�h�P��Bj��J�ҧH� -��N1���N��?��~��}-q!=��_2hc�M��l�vY%UE�@|�v����M2�.Y[|y�"Eï��K�ZF,�ɯ?,q�?v�M 80jx�"�;�9vk�����+ ֧�� �ȺU��?�%�vcV��mA�6��Qg^M����A}�3�nl� QRN�l8�kkn�'�����(��M�7m9و�q���%ޟ���*h$Zk"��$�9��: �?U8�Sl��,,|ɒ��xH(ѷ����Gn�/Q�4�P��G�%��Ա8�N��!� �&�7�;���eKM7�4��9R/%����l�c>�x;������>��C�:�����t��h?aKX�bhe�ᜋ^�$�Iհ �hr7%F$�E��Fd���t��5���+�(M6�t����Ü�UU|zW�=a�Ts�Tg������dqP�Q����b'�m���1{|Y����X�N��b �P~��F^F:����k6�"�j!�� �I�r�`��1&�-$�Bevk:y���#yw��I0��x��=D�4��tU���P�ZH��ڠ底taP��6����b>�xa����Q�#� WeF��ŮNj�p�J* mQ�N����*I�-*�ȩ�F�g�3 �5��V�ʊ�ɮ�a��5F���O@{���NX��?����H�]3��1�Ri_u��������ѕ�� ����0��� F��~��:60�p�͈�S��qX#a�5>���`�o&+�<2�D����: �������ڝ�$�nP���*)�N�|y�Ej�F�5ټ�e���ihy�Z �>���k�bH�a�v��h�-#���!�Po=@k̆IEN��@��}Ll?j�O������߭�ʞ���Q|A07x���wt!xf���I2?Z��<ץ�T���cU�j��]��陎Ltl �}5�ϓ��$�,��O�mˊ�;�@O��jE��j(�ا,��LX���LO���Ц�90�O �.����a��nA���7������j4 ��W��_ٓ���zW�jcB������y՗+EM�)d���N�g6�y1_x��p�$Lv:��9�"z��p���ʙ$��^��JԼ*�ϭ����o���=x�Lj�6�J��u82�A�H�3$�ٕ@�=Vv�]�'�qEz�;I˼��)��=��ɯ���x �/�W(V���p�����$ �m�������u�����񶤑Oqˎ�T����r��㠚x�sr�GC��byp�G��1ߠ�w e�8�$⿄����/�M{*}��W�]˷.�CK\�ުx���/$�WPw���r� |i���&�}�{�X� �>��$-��l���?-z���g����lΆ���(F���h�vS*���b���߲ڡn,|)mrH[���a�3�ר�[1��3o_�U�3�TC�$��(�=�)0�kgP���� ��u�^=��4 �WYCҸ:��vQ�ר�X�à��tk�m,�t*��^�,�}D*� �"(�I��9R����>`�`��[~Q]�#af��i6l��8���6�:,s�s�N6�j"�A4���IuQ��6E,�GnH��zS�HO�uk�5$�I�4��ؤ�Q9�@��C����wp�BGv[]�u�Ov���0I4���\��y�����Q�Ѹ��~>Z��8�T��a��q�ޣ;z��a���/��S��I:�ܫ_�|������>=Z����8:�S��U�I�J��"IY���8%b8���H��:�QO�6�;7�I�S��J��ҌAά3��>c���E+&jf$eC+�z�;��V����� �r���ʺ������my�e���aQ�f&��6�ND��.:��NT�vm�<- u���ǝ\MvZY�N�NT��-A�>jr!S��n�O 1�3�Ns�%�3D@���`������ܟ 1�^c<���� �a�ɽ�̲�Xë#�w�|y�cW�=�9I*H8�p�^(4���՗�k��arOcW�tO�\�ƍR��8����'�K���I�Q�����?5�>[�}��yU�ײ -h��=��% q�ThG�2�)���"ו3]�!kB��*p�FDl�A���,�eEi�H�f�Ps�����5�H:�Փ~�H�0Dت�D�I����h�F3�������c��2���E��9�H��5�zԑ�ʚ�i�X�=:m�xg�hd(�v����׊�9iS��O��d@0ڽ���:�p�5�h-��t�&���X�q�ӕ,��ie�|���7A�2���O%P��E��htj��Y1��w�Ѓ!����  ���� ࢽ��My�7�\�a�@�ţ�J �4�Ȼ�F�@o�̒?4�wx��)��]�P��~�����u�����5�����7X ��9��^ܩ�U;Iꭆ 5 �������eK2�7(�{|��Y׎ �V��\"���Z�1� Z�����}��(�Ǝ"�1S���_�vE30>���p;� ΝD��%x�W�?W?v����o�^V�i�d��r[��/&>�~`�9Wh��y�;���R��� ;;ɮT��?����r$�g1�K����A��C��c��K��l:�'��3 c�ﳯ*"t8�~l��)���m��+U,z��`(�>yJ�?����h>��]��v��ЍG*�{`��;y]��I�T� ;c��NU�fo¾h���/$���|NS���1�S�"�H��V���T���4��uhǜ�]�v;���5�͠x��'C\�SBpl���h}�N����� A�Bx���%��ޭ�l��/����T��w�ʽ]D�=����K���ž�r㻠l4�S�O?=�k �M:� ��c�C�a�#ha���)�ѐxc�s���gP�iG��{+���x���Q���I= �� z��ԫ+ �8"�k�ñ�j=|����c ��y��CF��/��*9ж�h{ �?4�o� ��k�m�Q�N�x��;�Y��4膚�a�w?�6�>e]�����Q�r�:����g�,i"�����ԩA�*M�<�G��b�if��l^M��5� �Ҩ�{����6J��ZJ�����P�*�����Y���ݛu�_4�9�I8�7���������,^ToR���m4�H��?�N�S�ѕw��/S��甍�@�9H�S�T��t�ƻ���ʒU��*{Xs�@����f�����֒Li�K{H�w^���������Ϥm�tq���s� ���ք��f:��o~s��g�r��ט� �S�ѱC�e]�x���a��) ���(b-$(�j>�7q�B?ӕ�F��hV25r[7 Y� }L�R��}����*sg+��x�r�2�U=�*'WS��ZDW]�WǞ�<��叓���{�$�9Ou4��y�90-�1�'*D`�c�^o?(�9��u���ݐ��'PI&� f�Jݮ�������:wS����jfP1F:X �H�9dԯ���˝[�_54 �}*;@�ܨ�� ð�yn�T���?�ןd�#���4rG�ͨ��H�1�|-#���Mr�S3��G�3�����)�.᧏3v�z֑��r����$G"�`j �1t��x0<Ɔ�Wh6�y�6��,œ�Ga��gA����y��b��)��h�D��ß�_�m��ü �gG;��e�v��ݝ�nQ� ��C����-�*��o���y�a��M��I�>�<���]obD��"�:���G�A��-\%LT�8���c�)��+y76���o�Q�#*{�(F�⽕�y����=���rW�\p���۩�c���A���^e6��K������ʐ�cVf5$�'->���ՉN"���F�"�UQ@�f��Gb~��#�&�M=��8�ט�JNu9��D��[̤�s�o�~������ G��9T�tW^g5y$b��Y'��س�Ǵ�=��U-2 #�MC�t(�i� �lj�@Q 5�̣i�*�O����s�x�K�f��}\��M{E�V�{�υ��Ƈ�����);�H����I��fe�Lȣr�2��>��W�I�Ȃ6������i��k�� �5�YOxȺ����>��Y�f5'��|��H+��98pj�n�.O�y�������jY��~��i�w'������l�;�s�2��Y��:'lg�ꥴ)o#'Sa�a�K��Z� �m��}�`169�n���"���x��I ��*+� }F<��cГ���F�P�������ֹ*�PqX�x۩��,� ��N�� �4<-����%����:��7����W���u�`����� $�?�I��&����o��o��`v�>��P��"��l���4��5'�Z�gE���8���?��[�X�7(��.Q�-��*���ތL@̲����v��.5���[��=�t\+�CNܛ��,g�SQnH����}*F�G16���&:�t��4ُ"A��̣��$�b �|����#rs��a�����T�� ]�<�j��BS�('$�ɻ� �wP;�/�n��?�ݜ��x�F��yUn�~mL*-�������Xf�wd^�a�}��f�,=t�׵i�.2/wpN�Ep8�OР���•��R�FJ� 55TZ��T �ɭ�<��]��/�0�r�@�f��V��V����Nz�G��^���7hZi����k��3�,kN�e|�vg�1{9]_i��X5y7� 8e]�U����'�-2,���e"����]ot�I��Y_��n�(JҼ��1�O ]bXc���Nu�No��pS���Q_���_�?i�~�x h5d'�(qw52] ��'ޤ�q��o1�R!���`ywy�A4u���h<קy���\[~�4�\ X�Wt/� 6�����n�F�a8��f���z �3$�t(���q��q�x��^�XWeN'p<-v�!�{�(>ӽDP7��ո0�y)�e$ٕv�Ih'Q�EA�m*�H��RI��=:��� ���4牢) �%_iN�ݧ�l]� �Nt���G��H�L��� ɱ�g<���1V�,�J~�ٹ�"K��Q�� 9�HS�9�?@��k����r�;we݁�]I�!{ �@�G�[�"��`���J:�n]�{�cA�E����V��ʆ���#��U9�6����j�#Y�m\��q�e4h�B�7��C�������d<�?J����1g:ٳ���=Y���D�p�ц� ׈ǔ��1�]26؜oS�'��9�V�FVu�P�h�9�xc�oq�X��p�o�5��Ա5$�9W�V(�[Ak�aY錎qf;�'�[�|���b�6�Ck��)��#a#a˙��8���=äh�4��2��C��4tm^ �n'c���]GQ$[Wҿ��i���vN�{Fu ��1�gx��1┷���N�m��{j-,��x�� Ūm�ЧS�[�s���Gna���䑴�� x�p 8<������97�Q���ϴ�v�aϚG��Rt�Һ׈�f^\r��WH�JU�7Z���y)�vg=����n��4�_)y��D'y�6�]�c�5̪�\� �PF�k����&�c;��cq�$~T�7j ���nç]�<�g ":�to�t}�159�<�/�8������m�b�K#g'I'.W�����6��I/��>v��\�MN��g���m�A�yQL�4u�Lj�j9��#44�t��l^�}L����n��R��!��t��±]��r��h6ٍ>�yҏ�N��fU�� ���� Fm@�8}�/u��jb9������he:A�y�ծw��GpΧh�5����l}�3p468��)U��d��c����;Us/�֔�YX�1�O2��uq�s��`hwg�r~�{ R��mhN��؎*q 42�*th��>�#���E����#��Hv�O����q�}�����6�e��\�,Wk�#���X��b>��p}�դ��3���T5��†��6��[��@�P�y*n��|'f�֧>�lư΂�̺����SU�'*�q�p�_S�����M�� '��c�6�����m�� ySʨ;M��r���Ƌ�m�Kxo,���Gm�P��A�G�:��i��w�9�}M(�^�V��$ǒ�ѽ�9���|���� �a����J�SQ�a���r�B;����}���ٻ֢�2�%U���c�#�g���N�a�ݕ�'�v�[�OY'��3L�3�;,p�]@�S��{ls��X�'���c�jw�k'a�.��}�}&�� �dP�*�bK=ɍ!����;3n�gΊU�ߴmt�'*{,=SzfD� A��ko~�G�aoq�_mi}#�m�������P�Xhύ����mxǍ�΂���巿zf��Q���c���|kc�����?���W��Y�$���_Lv����l߶��c���`?����l�j�ݲˏ!V��6����U�Ђ(A���4y)H���p�Z_�x��>���e��R��$�/�`^'3qˏ�-&Q�=?��CFVR �D�fV�9��{�8g�������n�h�(P"��6�[�D���< E�����~0<@�`�G�6����Hг�cc�� �c�K.5��D��d�B���`?�XQ��2��ٿyqo&+�1^� DW�0�ꊩ���G�#��Q�nL3��c���������/��x ��1�1[y�x�პCW��C�c�UĨ80�m�e�4.{�m��u���I=��f�����0QRls9���f���������9���~f�����Ǩ��a�"@�8���ȁ�Q����#c�ic������G��$���G���r/$W�(��W���V�"��m�7�[m�A�m����bo��D� j����۳� l���^�k�h׽����� ��#� iXn�v��eT�k�a�^Y�4�BN��ĕ��0 !01@Q"2AaPq3BR������?���@4�Q�����T3,���㺠�W�[=JK�Ϟ���2�r^7��vc�:�9 �E�ߴ�w�S#d���Ix��u��:��Hp��9E!�� V 2;73|F��9Y���*ʬ�F��D����u&���y؟��^EA��A��(ɩ���^��GV:ݜDy�`��Jr29ܾ�㝉��[���E;Fzx��YG��U�e�Y�C���� ����v-tx����I�sם�Ę�q��Eb�+P\ :>�i�C'�;�����k|z�رn�y]�#ǿb��Q��������w�����(�r|ӹs��[�D��2v-%��@;�8<a���[\o[ϧw��I!��*0�krs)�[�J9^��ʜ��p1)� "��/_>��o��<1����A�E�y^�C��`�x1'ܣn�p��s`l���fQ��):�l����b>�Me�jH^?�kl3(�z:���1ŠK&?Q�~�{�ٺ�h�y���/�[��V�|6��}�KbX����mn[-��7�5q�94�������dm���c^���h� X��5��<�eޘ>G���-�}�دB�ޟ� ��|�rt�M��V+�]�c?�-#ڛ��^ǂ}���Lkr���O��u�>�-D�ry� D?:ޞ�U��ǜ�7�V��?瓮�"�#���r��չģVR;�n���/_� ؉v�ݶe5d�b9��/O��009�G���5n�W����JpA�*�r9�>�1��.[t���s�F���nQ� V 77R�]�ɫ8����_0<՜�IF�u(v��4��F�k�3��E)��N:��yڮe��P�`�1}�$WS��J�SQ�N�j�ٺ��޵�#l���ј(�5=��5�lǏmoW�v-�1����v,W�mn��߀$x�<����v�j(����c]��@#��1������Ǔ���o'��u+����;G�#�޸��v-lη��/(`i⣍Pm^���ԯ̾9Z��F��������n��1��� ��]�[��)�'������:�֪�W��FC����� �B9،!?���]��V��A�Վ�M��b�w��G F>_DȬ0¤�#�QR�[V��kz���m�w�"��9ZG�7'[��=�Q����j8R?�zf�\a�=��O�U����*oB�A�|G���2�54 �p��.w7� �� ��&������ξxGHp� B%��$g�����t�Џ򤵍z���HN�u�Я�-�'4��0��;_��3 !01"@AQa2Pq#3BR������?��ʩca��en��^��8���<�u#��m*08r��y�N"�<�Ѳ0��@\�p��� �����Kv�D��J8�Fҽ� �f�Y��-m�ybX�NP����}�!*8t(�OqѢ��Q�wW�K��ZD��Δ^e��!� ��B�K��p~�����e*l}z#9ң�k���q#�Ft�o��S�R����-�w�!�S���Ӥß|M�l޶V��!eˈ�8Y���c�ЮM2��tk���� ������J�fS����Ö*i/2�����n]�k�\���|4yX�8��U�P.���Ы[���l��@"�t�<������5�lF���vU�����W��W��;�b�cД^6[#7@vU�xgZv��F�6��Q,K�v��� �+Ъ��n��Ǣ��Ft���8��0��c�@�!�Zq s�v�t�;#](B��-�nῃ~���3g������5�J�%���O������n�kB�ĺ�.r��+���#�N$?�q�/�s�6��p��a����a��J/��M�8��6�ܰ"�*������ɗud"\w���aT(����[��F��U՛����RT�b���n�*��6���O��SJ�.�ij<�v�MT��R\c��5l�sZB>F��<7�;EA��{��E���Ö��1U/�#��d1�a�n.1ě����0�ʾR�h��|�R��Ao�3�m3 ��%�� ���28Q� ��y��φ���H�To�7�lW>����#i`�q���c����a��� �m,B�-j����݋�'mR1Ήt�>��V��p���s�0IbI�C.���1R�ea�����]H�6����������4B>��o��](��$B���m�����a�!=��?�B� K�Ǿ+�Ծ"�n���K��*��+��[T#�{E�J�S����Q�����s�5�:�U�\wĐ�f�3����܆&�)����I���Ԇw��E T�lrTf6Q|R�h:��[K�� �z��c֧�G�C��%\��_�a�84��HcO�bi��ؖV��7H �)*ģK~Xhչ0��4?�0��� �E<���}3���#���u�?�� ��|g�S�6ꊤ�|�I#Hڛ� �ա��w�X��9��7���Ŀ%�SL��y6č��|�F�a 8���b��$�sק�h���b9RAu7�˨p�Č�_\*w��묦��F ����4D~�f����|(�"m���NK��i�S�>�$d7SlA��/�²����SL��|6N�}���S�˯���g��]6��; �#�.��<���q'Q�1|KQ$�����񛩶"�$r�b:���N8�w@��8$�� �AjfG|~�9F ���Y��ʺ��Bwؒ������M:I岎�G��`s�YV5����6��A �b:�W���G�q%l�����F��H���7�������Fsv7��k�� 403WebShell
403Webshell
Server IP : 51.161.54.47  /  Your IP : 216.73.216.98
Web Server : Apache/2.4.68 (Unix) OpenSSL/1.1.1k
System : Linux host.ditinformatica.ar 4.18.0-553.153.1.el8_10.x86_64 #1 SMP Thu Aug 6 00:53:12 EDT 2026 x86_64
User : kalaycom ( 1021)
PHP Version : 7.4.33
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : ON
Directory :  /usr/share/xml/scap/ssg/content/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /usr/share/xml/scap/ssg/content/ssg-almalinux8-ds.xml
<?xml version="1.0" encoding="utf-8"?>
<ds:data-stream-collection xmlns:cat="urn:oasis:names:tc:entity:xmlns:xml:catalog" xmlns:cpe-dict="http://cpe.mitre.org/dictionary/2.0" xmlns:cpe-lang="http://cpe.mitre.org/language/2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ds="http://scap.nist.gov/schema/scap/source/1.2" xmlns:html="http://www.w3.org/1999/xhtml" xmlns:ind="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:linux="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:ocil="http://scap.nist.gov/schema/ocil/2.0" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" id="scap_org.open-scap_collection_from_xccdf_ssg-almalinux8-xccdf.xml" schematron-version="1.3">
  <ds:data-stream id="scap_org.open-scap_datastream_from_xccdf_ssg-almalinux8-xccdf.xml" scap-version="1.3" timestamp="2026-06-15T09:09:30" use-case="OTHER">
    <ds:dictionaries>
      <ds:component-ref id="scap_org.open-scap_cref_ssg-almalinux8-cpe-dictionary.xml" xlink:href="#scap_org.open-scap_comp_ssg-almalinux8-cpe-dictionary.xml">
        <cat:catalog>
          <cat:uri name="ssg-almalinux8-cpe-oval.xml" uri="#scap_org.open-scap_cref_ssg-almalinux8-cpe-oval.xml"/>
        </cat:catalog>
      </ds:component-ref>
    </ds:dictionaries>
    <ds:checklists>
      <ds:component-ref id="scap_org.open-scap_cref_ssg-almalinux8-xccdf.xml" xlink:href="#scap_org.open-scap_comp_ssg-almalinux8-xccdf.xml">
        <cat:catalog>
          <cat:uri name="ssg-almalinux8-oval.xml" uri="#scap_org.open-scap_cref_ssg-almalinux8-oval.xml"/>
          <cat:uri name="ssg-almalinux8-ocil.xml" uri="#scap_org.open-scap_cref_ssg-almalinux8-ocil.xml"/>
          <cat:uri name="ssg-almalinux8-cpe-oval.xml" uri="#scap_org.open-scap_cref_ssg-almalinux8-cpe-oval.xml"/>
          <cat:uri name="oval-org.almalinux.alsa-8.xml.bz2" uri="#scap_org.open-scap_cref_oval-org.almalinux.alsa-8.xml.bz2"/>
        </cat:catalog>
      </ds:component-ref>
    </ds:checklists>
    <ds:checks>
      <ds:component-ref id="scap_org.open-scap_cref_ssg-almalinux8-oval.xml" xlink:href="#scap_org.open-scap_comp_ssg-almalinux8-oval.xml"/>
      <ds:component-ref id="scap_org.open-scap_cref_ssg-almalinux8-ocil.xml" xlink:href="#scap_org.open-scap_comp_ssg-almalinux8-ocil.xml"/>
      <ds:component-ref id="scap_org.open-scap_cref_ssg-almalinux8-cpe-oval.xml" xlink:href="#scap_org.open-scap_comp_ssg-almalinux8-cpe-oval.xml"/>
      <ds:component-ref id="scap_org.open-scap_cref_oval-org.almalinux.alsa-8.xml.bz2" xlink:href="https://security.almalinux.org/oval/org.almalinux.alsa-8.xml.bz2"/>
    </ds:checks>
  </ds:data-stream>
  <ds:component id="scap_org.open-scap_comp_ssg-almalinux8-cpe-dictionary.xml" timestamp="2026-06-15T09:09:30">
    <cpe-dict:cpe-list xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0 http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
      <cpe-dict:cpe-item name="cpe:/o:almalinux:almalinux:8">
        <cpe-dict:title xml:lang="en-us">AlmaLinux OS 8</cpe-dict:title>
        <cpe-dict:check href="ssg-almalinux8-cpe-oval.xml" system="http://oval.mitre.org/XMLSchema/oval-definitions-5">oval:ssg-installed_OS_is_almalinux8:def:1</cpe-dict:check>
      </cpe-dict:cpe-item>
    </cpe-dict:cpe-list>
  </ds:component>
  <ds:component id="scap_org.open-scap_comp_ssg-almalinux8-xccdf.xml" timestamp="2026-06-15T09:09:30">
    <xccdf-1.2:Benchmark id="xccdf_org.ssgproject.content_benchmark_ALMALINUX-8" resolved="true" style="SCAP_1.2" xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2 xccdf-1.2.xsd" xml:lang="en-US">
      <xccdf-1.2:status date="2026-06-15">draft</xccdf-1.2:status>
      <xccdf-1.2:title>Guide to the Secure Configuration of AlmaLinux OS 8</xccdf-1.2:title>
      <xccdf-1.2:description>This guide presents a catalog of security-relevant
configuration settings for AlmaLinux OS 8. It is a rendering of
content structured in the eXtensible Configuration Checklist Description Format (XCCDF)
in order to support security automation.  The SCAP content is
is available in the <html:code>scap-security-guide</html:code> package which is developed at

    <html:a href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>.
<html:br/><html:br/>
Providing system administrators with such guidance informs them how to securely
configure systems under their control in a variety of network roles. Policy
makers and baseline creators can use this catalog of settings, with its
associated references to higher-level security control catalogs, in order to
assist them in security baseline creation. This guide is a <html:em>catalog, not a
checklist</html:em>, and satisfaction of every item is not likely to be possible or
sensible in many operational scenarios. However, the XCCDF format enables
granular selection and adjustment of settings, and their association with OVAL
and OCIL content provides an automated checking capability. Transformations of
this document, and its associated automated checking content, are capable of
providing baselines that meet a diverse set of policy objectives. Some example
XCCDF <html:em>Profiles</html:em>, which are selections of items that form checklists and
can be used as baselines, are available with this guide. They can be
processed, in an automated fashion, with tools that support the Security
Content Automation Protocol (SCAP). The DISA STIG, which provides required
settings for US Department of Defense systems, is one example of a baseline
created from this guidance.
</xccdf-1.2:description>
      <xccdf-1.2:notice id="terms_of_use">Do not attempt to implement any of the settings in
this guide without first testing them in a non-operational environment. The
creators of this guidance assume no responsibility whatsoever for its use by
other parties, and makes no guarantees, expressed or implied, about its
quality, reliability, or any other characteristic.
</xccdf-1.2:notice>
      <xccdf-1.2:front-matter>The SCAP Security Guide Project<html:br/>

    <html:a href="https://www.open-scap.org/security-policies/scap-security-guide">https://www.open-scap.org/security-policies/scap-security-guide</html:a>
</xccdf-1.2:front-matter>
      <xccdf-1.2:rear-matter>Red Hat and Red Hat Enterprise Linux are either registered
trademarks or trademarks of Red Hat, Inc. in the United States and other
countries. All other names are registered trademarks or trademarks of their
respective companies.</xccdf-1.2:rear-matter>
      <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">anssi</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=application-servers">app-srg</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">app-srg-ctr</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf">bsi</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">cis</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">cis-csc</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">cjis</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">cobit5</xccdf-1.2:reference>
      <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">cui</xccdf-1.2:reference>
      <xccdf-1.2:reference href="not_officially_available">dcid</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.cyber.mil/stigs/cci/">disa</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">hipaa</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">isa-62443-2009</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">isa-62443-2013</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">ism</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">iso27001-2013</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">nerc-cip</xccdf-1.2:reference>
      <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">nist</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">nist-csf</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
      <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
      <cpe-lang:platform-specification>
        <cpe-lang:platform id="aarch64_arch">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="aarch64_arch_or_x86_64_arch">
          <cpe-lang:logical-test negate="false" operator="OR">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="bootc_or_osbuild_or_selinux">
          <cpe-lang:logical-test negate="false" operator="OR">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-bootc:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_is_osbuild:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-selinux_is_enabled:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="grub2">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_has_grub2_package:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="grub2_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_has_grub2_package:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="ipv6_enabled">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-ipv6_enabled:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="krb5_server_older_than_1_17-18">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-krb5_server_older_than_1_17_18:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="krb5_server_older_than_1_17-18_and_krb5_workstation_older_than_1_17-18">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-krb5_server_older_than_1_17_18:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-krb5_workstation_older_than_1_17_18:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="krb5_workstation_older_than_1_17-18">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-krb5_workstation_older_than_1_17_18:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="machine">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_is_a_machine:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="machine_and_package_systemd-journal-remote">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_is_a_machine:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_systemd-journal-remote:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="mount_boot-efi">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_mount_boot-efi:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="mount_home">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_mount_home:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="mount_opt">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_mount_opt:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="mount_srv">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_mount_srv:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="mount_tmp">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_mount_tmp:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="mount_var">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_mount_var:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="mount_var-log">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_mount_var-log:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="mount_var-log-audit">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_mount_var-log-audit:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="mount_var-tmp">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_mount_var-tmp:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="nfs_mount_defined">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-nfs_mount_defined:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="no_ovirt">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_has_no_ovirt:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="non-uefi">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="non-uefi_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="not_aarch64_arch">
          <cpe-lang:logical-test negate="true" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="not_aarch64_arch_and_not_s390x_arch">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:logical-test negate="true" operator="AND">
              <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            </cpe-lang:logical-test>
            <cpe-lang:logical-test negate="true" operator="AND">
              <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            </cpe-lang:logical-test>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="not_aarch64_arch_and_os_linux_ol_gt_or_eq_9_0_or_aarch64_arch_and_os_linux_rhel_gt_or_eq_9_0_or_os_linux_rhel_le_or_eq_8_4_and_s390x_arch">
          <cpe-lang:logical-test negate="true" operator="AND">
            <cpe-lang:logical-test negate="false" operator="OR">
              <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
                <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-os_linux_ol_gt_or_eq_9_0:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
              </cpe-lang:logical-test>
              <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
                <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-os_linux_rhel_gt_or_eq_9_0:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
              </cpe-lang:logical-test>
              <cpe-lang:logical-test negate="false" operator="AND">
                <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-os_linux_rhel_le_or_eq_8_4:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
                <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
              </cpe-lang:logical-test>
            </cpe-lang:logical-test>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="not_bootc">
          <cpe-lang:logical-test negate="true" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-bootc:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="not_bootc_and_not_container">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:logical-test negate="true" operator="AND">
              <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-bootc:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            </cpe-lang:logical-test>
            <cpe-lang:logical-test negate="true" operator="AND">
              <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_is_a_container:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            </cpe-lang:logical-test>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="not_bootc_and_not_osbuild_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:logical-test negate="true" operator="AND">
              <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-bootc:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            </cpe-lang:logical-test>
            <cpe-lang:logical-test negate="true" operator="AND">
              <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_is_osbuild:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            </cpe-lang:logical-test>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="not_bootc_and_package_yum">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:logical-test negate="true" operator="AND">
              <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-bootc:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            </cpe-lang:logical-test>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_yum:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="not_container">
          <cpe-lang:logical-test negate="true" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_is_a_container:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="not_container_and_wifi-iface">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:logical-test negate="true" operator="AND">
              <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_is_a_container:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            </cpe-lang:logical-test>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_has_wifi_interface:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="not_osbuild_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:logical-test negate="true" operator="AND">
              <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_env_is_osbuild:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            </cpe-lang:logical-test>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="not_package_gdm">
          <cpe-lang:logical-test negate="true" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_gdm:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="not_package_nftables_and_not_package_ufw">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:logical-test negate="true" operator="AND">
              <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_nftables:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            </cpe-lang:logical-test>
            <cpe-lang:logical-test negate="true" operator="AND">
              <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_ufw:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            </cpe-lang:logical-test>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="not_package_nftables_and_not_package_ufw_and_package_iptables">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:logical-test negate="true" operator="AND">
              <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_nftables:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            </cpe-lang:logical-test>
            <cpe-lang:logical-test negate="true" operator="AND">
              <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_ufw:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            </cpe-lang:logical-test>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_iptables:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:logical-test negate="true" operator="AND">
              <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            </cpe-lang:logical-test>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-service_disabled_nftables:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-service_disabled_ufw:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="not_s390x_arch">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="not_s390x_arch_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="os_linux_ol_gt_or_eq_8_7">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="os_linux_rhel_gt_or_eq_8_2_and_package_pam">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_2:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_pam:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="os_linux_rhel_le_or_eq_8_3_or_os_linux_rhel_gt_or_eq_8_4_and_not_runtime_kernel_fips_enabled">
          <cpe-lang:logical-test negate="false" operator="OR">
            <cpe-lang:logical-test negate="false" operator="AND">
              <cpe-lang:logical-test negate="true" operator="AND">
                <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
              </cpe-lang:logical-test>
              <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_4:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            </cpe-lang:logical-test>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-os_linux_rhel_le_or_eq_8_3:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="os_linux_rhel_le_or_eq_8_3_or_os_linux_rhel_gt_or_eq_8_4_and_not_runtime_kernel_fips_enabled_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="OR">
            <cpe-lang:logical-test negate="false" operator="AND">
              <cpe-lang:logical-test negate="true" operator="AND">
                <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
              </cpe-lang:logical-test>
              <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_4:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
              <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            </cpe-lang:logical-test>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-os_linux_rhel_le_or_eq_8_3:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="os_linux_sles_gt_or_eq_15">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-os_linux_sles_gt_or_eq_15:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_audit">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_audit:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_autofs_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_autofs:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_avahi_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_avahi:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_bash">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_bash:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_bind">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_bind:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_chrony">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_chrony:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_chrony_or_package_ntp">
          <cpe-lang:logical-test negate="false" operator="OR">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_chrony:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_ntp:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_dnf">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_dnf:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_firewalld">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_firewalld:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_firewalld_and_package_nftables_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_firewalld:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_nftables:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_gdm">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_gdm:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_iptables">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_iptables:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_iptables:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-service_disabled_firewalld:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_krb5-libs">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_krb5-libs:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_libpwquality">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_libpwquality:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_libreswan">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_libreswan:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_libreswan_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_libreswan:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_libuser">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_libuser:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_logrotate">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_logrotate:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_net-snmp">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_net-snmp:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_nftables">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_nftables:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_nftables:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-service_disabled_firewalld:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_nss-pam-ldapd">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_nss-pam-ldapd:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_ntp">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_ntp:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_openssh">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_openssh:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_openssh-clients">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_openssh-clients:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_openssh-server_le_7_0">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_openssh-server_le_7_0:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_openssh-server_le_7_5">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_openssh-server_le_7_5:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_openssl">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_openssl:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_pam">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_pam:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_pam_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_pam:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_polkit">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_polkit:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_postfix">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_postfix:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_rootfiles">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_rootfiles:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_rsh-server">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_rsh-server:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_rsyslog">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_rsyslog:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_shadow-utils">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_shadow-utils:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_shadow-utils_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_shadow-utils:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_snmpd_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_snmpd:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_squid_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_squid:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_sssd">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_sssd:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_sssd_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_sssd:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_sudo">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_sudo:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_systemd">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_systemd:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_tcsh">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_tcsh:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_telnet-server_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_telnet-server:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_tftp-server">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_tftp-server:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_tmux">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_tmux:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_ufw_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_ufw:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_usbguard">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_usbguard:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="package_yum">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-package_yum:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="s390x_arch">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="service_disabled_iptables_and_service_disabled_ufw_and_system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-service_disabled_iptables:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-service_disabled_ufw:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="sssd-ldap">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-sssd_conf_uses_ldap:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="system_with_kernel">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="system_with_kernel_and_x86_64_arch">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_with_kernel:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="uefi">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-system_boot_mode_is_uefi:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
        <cpe-lang:platform id="x86_64_arch">
          <cpe-lang:logical-test negate="false" operator="AND">
            <cpe-lang:check-fact-ref href="ssg-almalinux8-cpe-oval.xml" id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1" system="http://oval.mitre.org/XMLSchema/oval-definitions-5"/>
          </cpe-lang:logical-test>
        </cpe-lang:platform>
      </cpe-lang:platform-specification>
      <xccdf-1.2:platform idref="cpe:/o:almalinux:almalinux:8"/>
      <xccdf-1.2:version update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.81</xccdf-1.2:version>
      <xccdf-1.2:metadata>
        <dc:publisher>SCAP Security Guide Project</dc:publisher>
        <dc:creator>SCAP Security Guide Project</dc:creator>
        <dc:contributor>Frank J Cameron (CAM1244) &lt;cameron@ctc.com&gt;</dc:contributor>
        <dc:contributor>0x66656c6978 &lt;0x66656c6978@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Håvard F. Aasen &lt;havard.f.aasen@pfft.no&gt;</dc:contributor>
        <dc:contributor>Armando Acosta &lt;armando.acosta@oracle.com&gt;</dc:contributor>
        <dc:contributor>Jack Adolph &lt;jack.adolph@gmail.com&gt;</dc:contributor>
        <dc:contributor>Edgar Aguilar &lt;edgar.aguilar@oracle.com&gt;</dc:contributor>
        <dc:contributor>akuster &lt;akuster808@gmail.com&gt;</dc:contributor>
        <dc:contributor>Gabe Alford &lt;redhatrises@gmail.com&gt;</dc:contributor>
        <dc:contributor>Firas AlShafei &lt;firas.alshafei@us.abb.com&gt;</dc:contributor>
        <dc:contributor>Rodrigo Alvares &lt;ralvares@redhat.com&gt;</dc:contributor>
        <dc:contributor>am-tux &lt;andrew.miller11@gmail.com&gt;</dc:contributor>
        <dc:contributor>Christopher Anderson &lt;cba@fedoraproject.org&gt;</dc:contributor>
        <dc:contributor>Craig Andrews &lt;candrews@integralblue.com&gt;</dc:contributor>
        <dc:contributor>angystardust &lt;angystardust@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>anivan-suse &lt;anastasija.ivanovic@suse.com&gt;</dc:contributor>
        <dc:contributor>anixon-rh &lt;55244503+anixon-rh@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Anna-Koudelkova &lt;akoudelk@redhat.com&gt;</dc:contributor>
        <dc:contributor>Arden97 &lt;arden2545@gmail.com&gt;</dc:contributor>
        <dc:contributor>Steve Arnold &lt;sarnold@vctlabs.com&gt;</dc:contributor>
        <dc:contributor>Ikko Ashimine &lt;eltociear@gmail.com&gt;</dc:contributor>
        <dc:contributor>Chuck Atkins &lt;chuck.atkins@kitware.com&gt;</dc:contributor>
        <dc:contributor>axuan &lt;axuan@redhat.com&gt;</dc:contributor>
        <dc:contributor>Bharath B &lt;bhb@redhat.com&gt;</dc:contributor>
        <dc:contributor>Ryan Ballanger &lt;root@rballang-admin-2.fastenal.com&gt;</dc:contributor>
        <dc:contributor>Alex Baranowski &lt;alex@euro-linux.com&gt;</dc:contributor>
        <dc:contributor>Eduardo Barretto &lt;eduardo.barretto@canonical.com&gt;</dc:contributor>
        <dc:contributor>Paul Bastide &lt;pbastide@us.ibm.com&gt;</dc:contributor>
        <dc:contributor>Molly Jo Bault &lt;Molly.Jo.Bault@ballardtech.com&gt;</dc:contributor>
        <dc:contributor>Andrew Becker &lt;A-Beck@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Gabriel Becker &lt;ggasparb@redhat.com&gt;</dc:contributor>
        <dc:contributor>BenGui &lt;benoit.guillon1@etu.unilim.fr&gt;</dc:contributor>
        <dc:contributor>Alexander Bergmann &lt;abergmann@suse.com&gt;</dc:contributor>
        <dc:contributor>Eric Berry &lt;eric@approvedworkman.com&gt;</dc:contributor>
        <dc:contributor>Dale Bewley &lt;dale@bewley.net&gt;</dc:contributor>
        <dc:contributor>Jose Luis BG &lt;bgjoseluis@gmail.com&gt;</dc:contributor>
        <dc:contributor>binyanling &lt;binyanling@uniontech.com&gt;</dc:contributor>
        <dc:contributor>Joseph Bisch &lt;joseph.bisch@gmail.com&gt;</dc:contributor>
        <dc:contributor>Jeff Blank &lt;blank@eclipse.ncsc.mil&gt;</dc:contributor>
        <dc:contributor>Olivier Bonhomme &lt;ptitoliv@ptitoliv.net&gt;</dc:contributor>
        <dc:contributor>bontreger &lt;bontreger@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Lance Bragstad &lt;lbragstad@gmail.com&gt;</dc:contributor>
        <dc:contributor>Vickey Brown &lt;vibrown@redhat.com&gt;</dc:contributor>
        <dc:contributor>Ted Brunell &lt;tbrunell@redhat.com&gt;</dc:contributor>
        <dc:contributor>Marcus Burghardt &lt;maburgha@redhat.com&gt;</dc:contributor>
        <dc:contributor>Matthew Burket &lt;mburket@redhat.com&gt;</dc:contributor>
        <dc:contributor>Blake Burkhart &lt;blake.burkhart@us.af.mil&gt;</dc:contributor>
        <dc:contributor>Patrick Callahan &lt;pmc@patrickcallahan.com&gt;</dc:contributor>
        <dc:contributor>George Campbell &lt;gcampbell@palantir.com&gt;</dc:contributor>
        <dc:contributor>Nick Carboni &lt;ncarboni@redhat.com&gt;</dc:contributor>
        <dc:contributor>Carlos &lt;64919342+carlosmmatos@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>James Cassell &lt;james.cassell@ll.mit.edu&gt;</dc:contributor>
        <dc:contributor>Frank Caviggia &lt;fcaviggia@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Sinong Chen &lt;costinchen@tencent.com&gt;</dc:contributor>
        <dc:contributor>Eric Christensen &lt;echriste@redhat.com&gt;</dc:contributor>
        <dc:contributor>Dan Clark &lt;danclark@redhat.com&gt;</dc:contributor>
        <dc:contributor>Jayson Cofell &lt;1051437+70k10@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>David du Colombier &lt;djc@datadoghq.com&gt;</dc:contributor>
        <dc:contributor>Commandcracker &lt;lukas.fricke.dev@gmail.com&gt;</dc:contributor>
        <dc:contributor>Caleb Cooper &lt;coopercd@ornl.gov&gt;</dc:contributor>
        <dc:contributor>CoreyCook8 &lt;129206271+CoreyCook8@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>cortesana &lt;acortes@redhat.com&gt;</dc:contributor>
        <dc:contributor>Richard Maciel Costa &lt;richard.maciel.costa@canonical.com&gt;</dc:contributor>
        <dc:contributor>Xavier Coulon &lt;xavier.coulon@suse.com&gt;</dc:contributor>
        <dc:contributor>Deric Crago &lt;deric.crago@gmail.com&gt;</dc:contributor>
        <dc:contributor>crleekwc &lt;crleekwc@gmail.com&gt;</dc:contributor>
        <dc:contributor>cueball23 &lt;christoph.alms@westnetz.de&gt;</dc:contributor>
        <dc:contributor>cyarbrough76 &lt;42849651+cyarbrough76@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Maura Dailey &lt;maura@eclipse.ncsc.mil&gt;</dc:contributor>
        <dc:contributor>Harold Dean &lt;hdean3@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Benjamin Deering &lt;ben_deering@jeepingben.net&gt;</dc:contributor>
        <dc:contributor>Shane Dell &lt;shanedell100@gmail.com&gt;</dc:contributor>
        <dc:contributor>Klaas Demter &lt;demter@atix.de&gt;</dc:contributor>
        <dc:contributor>denknorr &lt;dennis.knorr@suse.com&gt;</dc:contributor>
        <dc:contributor>dhanushkar-wso2 &lt;dhanushkar@wso2.com&gt;</dc:contributor>
        <dc:contributor>Andrew DiPrinzio &lt;andrew.diprinzio@jhuapl.edu&gt;</dc:contributor>
        <dc:contributor>dom &lt;dominique.blaze@devinci.fr&gt;</dc:contributor>
        <dc:contributor>Jean-Baptiste Donnette &lt;jean-baptiste.donnette@epita.fr&gt;</dc:contributor>
        <dc:contributor>Marco De Donno &lt;mdedonno1337@gmail.com&gt;</dc:contributor>
        <dc:contributor>dperrone &lt;dperrone@redhat.com&gt;</dc:contributor>
        <dc:contributor>drax &lt;applezip@gmail.com&gt;</dc:contributor>
        <dc:contributor>Qingmin Duanmu &lt;qduanmu@redhat.com&gt;</dc:contributor>
        <dc:contributor>Sebastian Dunne &lt;sdunne@redhat.com&gt;</dc:contributor>
        <dc:contributor>François Duthilleul &lt;francoisduthilleul@gmail.com&gt;</dc:contributor>
        <dc:contributor>Greg Elin &lt;gregelin@gitmachines.com&gt;</dc:contributor>
        <dc:contributor>eradot4027 &lt;jrtonmac@gmail.com&gt;</dc:contributor>
        <dc:contributor>ericeberry &lt;ericeberry@gmail.com&gt;</dc:contributor>
        <dc:contributor>ermeratos &lt;manuel.ermer@eviden.net&gt;</dc:contributor>
        <dc:contributor>Evelyn &lt;evansvevelyn@gmail.com&gt;</dc:contributor>
        <dc:contributor>Alexis Facques &lt;alexis.facques@mythalesgroup.io&gt;</dc:contributor>
        <dc:contributor>Jan Fader &lt;jan.fader@web.de&gt;</dc:contributor>
        <dc:contributor>felixmarch &lt;felixmarch@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Asser Schrøder Femø &lt;asser@asser.org&gt;</dc:contributor>
        <dc:contributor>Henry Finucane &lt;hfinucane@zscaler.com&gt;</dc:contributor>
        <dc:contributor>Leah Fisher &lt;lfisher047@gmail.com&gt;</dc:contributor>
        <dc:contributor>Marco Fortina &lt;marco_fortina@hotmail.it&gt;</dc:contributor>
        <dc:contributor>Yavor Georgiev &lt;strandjata@gmail.com&gt;</dc:contributor>
        <dc:contributor>Alijohn Ghassemlouei &lt;alijohn@secureagc.com&gt;</dc:contributor>
        <dc:contributor>Swarup Ghosh &lt;swghosh@redhat.com&gt;</dc:contributor>
        <dc:contributor>ghylock &lt;ghylock@gmail.com&gt;</dc:contributor>
        <dc:contributor>Andrew Gilmore &lt;agilmore2@gmail.com&gt;</dc:contributor>
        <dc:contributor>Joshua Glemza &lt;jglemza@nasa.gov&gt;</dc:contributor>
        <dc:contributor>Nick Gompper &lt;forestgomp@yahoo.com&gt;</dc:contributor>
        <dc:contributor>David Fernandez Gonzalez &lt;david.fernandezgonzalez@canonical.com&gt;</dc:contributor>
        <dc:contributor>Loren Gordon &lt;lorengordon@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Gene Gotimer &lt;otherdevopsgene@portinfo.com&gt;</dc:contributor>
        <dc:contributor>Patrik Greco &lt;sikevux@sikevux.se&gt;</dc:contributor>
        <dc:contributor>Steve Grubb &lt;sgrubb@redhat.com&gt;</dc:contributor>
        <dc:contributor>guangyee &lt;gyee@suse.com&gt;</dc:contributor>
        <dc:contributor>Bhargavi Gudi &lt;bgudi@bgudi-thinkpadt14sgen2i.remote.csb&gt;</dc:contributor>
        <dc:contributor>Christian Hagenest &lt;christian.hagenest@suse.com&gt;</dc:contributor>
        <dc:contributor>Marek Haicman &lt;mhaicman@redhat.com&gt;</dc:contributor>
        <dc:contributor>Sun, Haoxiang &lt;haoxiang.sun@intel.com&gt;</dc:contributor>
        <dc:contributor>Vern Hart &lt;vern.hart@canonical.com&gt;</dc:contributor>
        <dc:contributor>Alex Haydock &lt;alex@alexhaydock.co.uk&gt;</dc:contributor>
        <dc:contributor>Rebekah Hayes &lt;rhayes@corp.rivierautilities.com&gt;</dc:contributor>
        <dc:contributor>hazerre &lt;kotadouglas2@gmail.com&gt;</dc:contributor>
        <dc:contributor>Trey Henefield &lt;thenefield@gmail.com&gt;</dc:contributor>
        <dc:contributor>Henning Henkel &lt;henning.henkel@helvetia.ch&gt;</dc:contributor>
        <dc:contributor>hex2a &lt;hex2a@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>hipponix &lt;mirco.santori@gmail.com&gt;</dc:contributor>
        <dc:contributor>John Hooks &lt;jhooks@starscream.pa.jhbcomputers.com&gt;</dc:contributor>
        <dc:contributor>Jakub Hrozek &lt;jhrozek@redhat.com&gt;</dc:contributor>
        <dc:contributor>Donald Hunter &lt;donald.hunter@gmail.com&gt;</dc:contributor>
        <dc:contributor>De Huo &lt;De.Huo@windriver.com&gt;</dc:contributor>
        <dc:contributor>Robin Price II &lt;robin@redhat.com&gt;</dc:contributor>
        <dc:contributor>Yasir Imam &lt;yimam@redhat.com&gt;</dc:contributor>
        <dc:contributor>Jiri Jaburek &lt;jjaburek@redhat.com&gt;</dc:contributor>
        <dc:contributor>Keith Jackson &lt;keithkjackson@gmail.com&gt;</dc:contributor>
        <dc:contributor>Marc Jadoul &lt;mgjadoul@laptomatic.auth-o-matic.corp&gt;</dc:contributor>
        <dc:contributor>Jeremiah Jahn &lt;jeremiah@goodinassociates.com&gt;</dc:contributor>
        <dc:contributor>Jakub Jelen &lt;jjelen@redhat.com&gt;</dc:contributor>
        <dc:contributor>Jessicahfy &lt;Jessicahfy@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Stephan Joerrens &lt;Stephan.Joerrens@fiduciagad.de&gt;</dc:contributor>
        <dc:contributor>Simon John &lt;sjohn@tuxcare.com&gt;</dc:contributor>
        <dc:contributor>Hunter Jones &lt;hjones2199@gmail.com&gt;</dc:contributor>
        <dc:contributor>Jono &lt;jono@ubuntu-18.localdomain&gt;</dc:contributor>
        <dc:contributor>julius.ish &lt;julius.ish@zetier.com&gt;</dc:contributor>
        <dc:contributor>justchris1 &lt;justchris1@justchris1.email&gt;</dc:contributor>
        <dc:contributor>Kacper &lt;kacper@kacper.se&gt;</dc:contributor>
        <dc:contributor>Kai Kang &lt;kai.kang@windriver.com&gt;</dc:contributor>
        <dc:contributor>Charles Kernstock &lt;charles.kernstock@ultra-ats.com&gt;</dc:contributor>
        <dc:contributor>Yuli Khodorkovskiy &lt;ykhodorkovskiy@tresys.com&gt;</dc:contributor>
        <dc:contributor>Sherine Khoury &lt;skhoury@redhat.com&gt;</dc:contributor>
        <dc:contributor>Nathan Kinder &lt;nkinder@redhat.com&gt;</dc:contributor>
        <dc:contributor>Lee Kinser &lt;lee.kinser@gmail.com&gt;</dc:contributor>
        <dc:contributor>Evgeny Kolesnikov &lt;ekolesni@redhat.com&gt;</dc:contributor>
        <dc:contributor>Peter 'Pessoft' Kolínek &lt;github@pessoft.com&gt;</dc:contributor>
        <dc:contributor>Luke Kordell &lt;luke.t.kordell@lmco.com&gt;</dc:contributor>
        <dc:contributor>Malte Kraus &lt;malte.kraus@suse.com&gt;</dc:contributor>
        <dc:contributor>Seth Kress &lt;seth.kress@dsainc.com&gt;</dc:contributor>
        <dc:contributor>Felix Krohn &lt;felix.krohn@helvetia.ch&gt;</dc:contributor>
        <dc:contributor>kspargur &lt;kspargur@kspargur.csb&gt;</dc:contributor>
        <dc:contributor>Amit Kumar &lt;amitkuma@redhat.com&gt;</dc:contributor>
        <dc:contributor>Fen Labalme &lt;fen@civicactions.com&gt;</dc:contributor>
        <dc:contributor>Dexter Le &lt;dexter.le@sap.com&gt;</dc:contributor>
        <dc:contributor>Dimitri John Ledkov &lt;dimitri.ledkov@surgut.co.uk&gt;</dc:contributor>
        <dc:contributor>Ade Lee &lt;alee@redhat.com&gt;</dc:contributor>
        <dc:contributor>Christopher Lee &lt;Crleekwc@gmail.com&gt;</dc:contributor>
        <dc:contributor>Ian Lee &lt;lee1001@llnl.gov&gt;</dc:contributor>
        <dc:contributor>Jarrett Lee &lt;jarrettl@umd.edu&gt;</dc:contributor>
        <dc:contributor>Joseph Lenox &lt;joseph.lenox@collins.com&gt;</dc:contributor>
        <dc:contributor>Stefano Libero &lt;stefano.libero@nozominetworks.com&gt;</dc:contributor>
        <dc:contributor>lichtblaugue &lt;guenther.lichtblau@eviden.com&gt;</dc:contributor>
        <dc:contributor>Jan Lieskovsky &lt;jlieskov@redhat.com&gt;</dc:contributor>
        <dc:contributor>Markus Linnala &lt;Markus.Linnala@knowit.fi&gt;</dc:contributor>
        <dc:contributor>Flos Lonicerae &lt;lonicerae@gmail.com&gt;</dc:contributor>
        <dc:contributor>Simon Lukasik &lt;slukasik@redhat.com&gt;</dc:contributor>
        <dc:contributor>Andrew Lukoshko &lt;andrew.lukoshko@gmail.com&gt;</dc:contributor>
        <dc:contributor>Milan Lysonek &lt;mlysonek@redhat.com&gt;</dc:contributor>
        <dc:contributor>Fredrik Lysén &lt;fredrik@pipemore.se&gt;</dc:contributor>
        <dc:contributor>Mackemania &lt;8738793+Mackemania@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Peter Macko &lt;pmacko@redhat.com&gt;</dc:contributor>
        <dc:contributor>Caitlin Macleod &lt;caitelatte@gmail.com&gt;</dc:contributor>
        <dc:contributor>Dmitry Makovey &lt;dmakovey@yahoo.com&gt;</dc:contributor>
        <dc:contributor>Nick Maludy &lt;nmaludy@gmail.com&gt;</dc:contributor>
        <dc:contributor>Lokesh Mandvekar &lt;lsm5@fedoraproject.org&gt;</dc:contributor>
        <dc:contributor>Matus Marhefka &lt;mmarhefk@redhat.com&gt;</dc:contributor>
        <dc:contributor>Jamie Lorwey Martin &lt;jlmartin@redhat.com&gt;</dc:contributor>
        <dc:contributor>Carlos Matos &lt;cmatos@redhat.com&gt;</dc:contributor>
        <dc:contributor>Robert McAllister &lt;rmcallis@redhat.com&gt;</dc:contributor>
        <dc:contributor>Karen McCarron &lt;kmccarro@redhat.com&gt;</dc:contributor>
        <dc:contributor>Michael McConachie &lt;michael@redhat.com&gt;</dc:contributor>
        <dc:contributor>Marcus Meissner &lt;meissner@suse.de&gt;</dc:contributor>
        <dc:contributor>Khary Mendez &lt;kmendez@redhat.com&gt;</dc:contributor>
        <dc:contributor>Rodney Mercer &lt;rmercer@harris.com&gt;</dc:contributor>
        <dc:contributor>Matt Micene &lt;nzwulfin@gmail.com&gt;</dc:contributor>
        <dc:contributor>Brian Millett &lt;bmillett@gmail.com&gt;</dc:contributor>
        <dc:contributor>Takuya Mishina &lt;tmishina@jp.ibm.com&gt;</dc:contributor>
        <dc:contributor>Mixer9 &lt;35545791+Mixer9@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>mmosel &lt;mmosel@kde.example.com&gt;</dc:contributor>
        <dc:contributor>Thomas Montague &lt;montague.thomas@gmail.com&gt;</dc:contributor>
        <dc:contributor>Alan Moore &lt;alan.moore@canonical.com&gt;</dc:contributor>
        <dc:contributor>Zbynek Moravec &lt;zmoravec@redhat.com&gt;</dc:contributor>
        <dc:contributor>Kazuo Moriwaka &lt;moriwaka@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Michael Moseley &lt;michael@eclipse.ncsc.mil&gt;</dc:contributor>
        <dc:contributor>Samir MOUHOUNE &lt;samir.mouhoune@nav-timing.safrangroup.com&gt;</dc:contributor>
        <dc:contributor>Nathan Moyer &lt;nmoyer@spectric.com&gt;</dc:contributor>
        <dc:contributor>Ross Murphy &lt;RossMurphy@ibm.com&gt;</dc:contributor>
        <dc:contributor>Renaud Métrich &lt;rmetrich@redhat.com&gt;</dc:contributor>
        <dc:contributor>Joe Nall &lt;joe@nall.com&gt;</dc:contributor>
        <dc:contributor>namoyer10 &lt;48189779+namoyer10@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Neiloy &lt;neiloy@redhat.com&gt;</dc:contributor>
        <dc:contributor>Axel Nennker &lt;axel@nennker.de&gt;</dc:contributor>
        <dc:contributor>Michele Newman &lt;mnewman@redhat.com&gt;</dc:contributor>
        <dc:contributor>nnerdmann &lt;128606223+nnerdmann@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Sean O'Keeffe &lt;seanokeeffe797@gmail.com&gt;</dc:contributor>
        <dc:contributor>Jiri Odehnal &lt;jodehnal@redhat.com&gt;</dc:contributor>
        <dc:contributor>Ilya Okomin &lt;ilya.okomin@oracle.com&gt;</dc:contributor>
        <dc:contributor>Kaustubh Padegaonkar &lt;theTuxRacer@gmail.com&gt;</dc:contributor>
        <dc:contributor>Michael Palmiotto &lt;mpalmiotto@tresys.com&gt;</dc:contributor>
        <dc:contributor>Eryx Paredes &lt;eryxp@lyft.com&gt;</dc:contributor>
        <dc:contributor>Max R.D. Parmer &lt;maxp@trystero.is&gt;</dc:contributor>
        <dc:contributor>Arnaud Patard &lt;apatard@hupstream.com&gt;</dc:contributor>
        <dc:contributor>Jan Pazdziora &lt;jpazdziora@redhat.com&gt;</dc:contributor>
        <dc:contributor>pcactr &lt;paul.c.arnold4.ctr@mail.mil&gt;</dc:contributor>
        <dc:contributor>Kenneth Peeples &lt;kennethwpeeples@gmail.com&gt;</dc:contributor>
        <dc:contributor>Nathan Peters &lt;Nathaniel.Peters@ca.com&gt;</dc:contributor>
        <dc:contributor>Frank Lin PIAT &lt;fpiat@klabs.be&gt;</dc:contributor>
        <dc:contributor>Stefan Pietsch &lt;mail.ipv4v6+gh@gmail.com&gt;</dc:contributor>
        <dc:contributor>piggyvenus &lt;piggyvenus@gmail.com&gt;</dc:contributor>
        <dc:contributor>Vojtech Polasek &lt;vpolasek@redhat.com&gt;</dc:contributor>
        <dc:contributor>Orion Poplawski &lt;orion@nwra.com&gt;</dc:contributor>
        <dc:contributor>Jennifer Power &lt;barnabei.jennifer@gmail.com&gt;</dc:contributor>
        <dc:contributor>Nick Poyant &lt;npoyant@redhat.com&gt;</dc:contributor>
        <dc:contributor>Martin Preisler &lt;mpreisle@redhat.com&gt;</dc:contributor>
        <dc:contributor>Wesley Ceraso Prudencio &lt;wcerasop@redhat.com&gt;</dc:contributor>
        <dc:contributor>Raphael Sanchez Prudencio &lt;rsprudencio@redhat.com&gt;</dc:contributor>
        <dc:contributor>Miha Purg &lt;miha.purg@canonical.com&gt;</dc:contributor>
        <dc:contributor>T.O. Radzy Radzykewycz &lt;radzy@windriver.com&gt;</dc:contributor>
        <dc:contributor>rain-Qing &lt;yangyuqing6@qq.com&gt;</dc:contributor>
        <dc:contributor>Kenyon Ralph &lt;kenyon@kenyonralph.com&gt;</dc:contributor>
        <dc:contributor>Mike Ralph &lt;mralph@redhat.com&gt;</dc:contributor>
        <dc:contributor>Federico Ramirez &lt;federico.r.ramirez@oracle.com&gt;</dc:contributor>
        <dc:contributor>rchikov &lt;rumen.chikov@suse.com&gt;</dc:contributor>
        <dc:contributor>Rick Renshaw &lt;Richard_Renshaw@xtoenergy.com&gt;</dc:contributor>
        <dc:contributor>Paul Rensing &lt;prensing@cimetrics.com&gt;</dc:contributor>
        <dc:contributor>Chris Reynolds &lt;c.reynolds82@gmail.com&gt;</dc:contributor>
        <dc:contributor>rhayes &lt;rhayes@rivierautilities.com&gt;</dc:contributor>
        <dc:contributor>Pat Riehecky &lt;riehecky@fnal.gov&gt;</dc:contributor>
        <dc:contributor>rlucente-se-jboss &lt;rlucente@redhat.com&gt;</dc:contributor>
        <dc:contributor>Juan Antonio Osorio Robles &lt;juan.osoriorobles@eu.equinix.com&gt;</dc:contributor>
        <dc:contributor>Paul Roche &lt;paul.roche@menlosecurity.com&gt;</dc:contributor>
        <dc:contributor>Jan Rodak &lt;hony.com@seznam.cz&gt;</dc:contributor>
        <dc:contributor>Matt Rogers &lt;mrogers@redhat.com&gt;</dc:contributor>
        <dc:contributor>Jesse Roland &lt;jesse.roland@onyxpoint.com&gt;</dc:contributor>
        <dc:contributor>Joshua Roys &lt;roysjosh@gmail.com&gt;</dc:contributor>
        <dc:contributor>rrenshaw &lt;bofh69@yahoo.com&gt;</dc:contributor>
        <dc:contributor>Daniel Ruf &lt;daniel@daniel-ruf.de&gt;</dc:contributor>
        <dc:contributor>Chris Ruffalo &lt;chris.ruffalo@gmail.com&gt;</dc:contributor>
        <dc:contributor>Benjamin Ruland &lt;benjamin.ruland@gmail.com&gt;</dc:contributor>
        <dc:contributor>rumch-se &lt;77793453+rumch-se@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Rutvik &lt;rutksh@gmail.com&gt;</dc:contributor>
        <dc:contributor>Ray Shaw (Cont ARL/CISD) rvshaw &lt;rvshaw@esme.arl.army.mil&gt;</dc:contributor>
        <dc:contributor>Nicolas SAID &lt;nicolas.said@atos.net&gt;</dc:contributor>
        <dc:contributor>Earl Sampson &lt;ESampson@suse.com&gt;</dc:contributor>
        <dc:contributor>sampsone &lt;esampson@suse.com&gt;</dc:contributor>
        <dc:contributor>Mirco Santori &lt;mirco.santori@roche.com&gt;</dc:contributor>
        <dc:contributor>Willy Santos &lt;wsantos@redhat.com&gt;</dc:contributor>
        <dc:contributor>Nagarjuna Sarvepalli &lt;snagarju@redhat.com&gt;</dc:contributor>
        <dc:contributor>Anderson Sasaki &lt;33833274+ansasaki@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Gautam Satish &lt;gautams@hpe.com&gt;</dc:contributor>
        <dc:contributor>Watson Sato &lt;wsato@redhat.com&gt;</dc:contributor>
        <dc:contributor>Satoru SATOH &lt;satoru.satoh@gmail.com&gt;</dc:contributor>
        <dc:contributor>Alexander Scheel &lt;alexander.m.scheel@gmail.com&gt;</dc:contributor>
        <dc:contributor>Bryan Schneiders &lt;pschneiders@trisept.com&gt;</dc:contributor>
        <dc:contributor>Robert Schweikert &lt;rjschwei@suse.com&gt;</dc:contributor>
        <dc:contributor>shaneboulden &lt;shane.boulden@gmail.com&gt;</dc:contributor>
        <dc:contributor>Vincent Shen &lt;wenshen@redhat.com&gt;</dc:contributor>
        <dc:contributor>Dhriti Shikhar &lt;dhriti.shikhar.rokz@gmail.com&gt;</dc:contributor>
        <dc:contributor>Spencer Shimko &lt;sshimko@tresys.com&gt;</dc:contributor>
        <dc:contributor>Mark Shoger &lt;mshoger@redhat.com&gt;</dc:contributor>
        <dc:contributor>Shane Siebken &lt;shane.siebken@capellaspace.com&gt;</dc:contributor>
        <dc:contributor>THOBY Simon &lt;Simon.THOBY@viveris.fr&gt;</dc:contributor>
        <dc:contributor>Thomas Sjögren &lt;konstruktoid@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Jindrich Skacel &lt;102800748+jskacel@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Alexandre Skrzyniarz &lt;alexandre.skrzyniarz@laposte.net&gt;</dc:contributor>
        <dc:contributor>Francisco Slavin &lt;fslavin@tresys.com&gt;</dc:contributor>
        <dc:contributor>sluetze &lt;13255307+sluetze@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Dave Smith &lt;dsmith@eclipse.ncsc.mil&gt;</dc:contributor>
        <dc:contributor>David Smith &lt;dsmith@fornax.eclipse.ncsc.mil&gt;</dc:contributor>
        <dc:contributor>Kevin Spargur &lt;kspargur@redhat.com&gt;</dc:contributor>
        <dc:contributor>Kenneth Stailey &lt;kstailey.lists@gmail.com&gt;</dc:contributor>
        <dc:contributor>Leland Steinke &lt;leland.j.steinke.ctr@mail.mil&gt;</dc:contributor>
        <dc:contributor>Justin Stephenson &lt;jstephen@redhat.com&gt;</dc:contributor>
        <dc:contributor>steven.y.gui &lt;steven_ygui@163.com&gt;</dc:contributor>
        <dc:contributor>Brian Stinson &lt;brian@bstinson.com&gt;</dc:contributor>
        <dc:contributor>Jake Stookey &lt;jakestookey@gmail.com&gt;</dc:contributor>
        <dc:contributor>Nathan Strahs &lt;135379779+nathanstrahs@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Jonathan Sturges &lt;jsturges@redhat.com&gt;</dc:contributor>
        <dc:contributor>svet-se &lt;svetlin.boychev@suse.com&gt;</dc:contributor>
        <dc:contributor>taimurhafeez &lt;taimurhafeez93@gmail.com&gt;</dc:contributor>
        <dc:contributor>Kaushik Talathi &lt;kaushik.talathi1@ibm.com&gt;</dc:contributor>
        <dc:contributor>teacup-on-rockingchair &lt;315160+teacup-on-rockingchair@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Ian Tewksbury &lt;itewk@redhat.com&gt;</dc:contributor>
        <dc:contributor>Philippe Thierry &lt;phil@reseau-libre.net&gt;</dc:contributor>
        <dc:contributor>Simon THOBY &lt;git@nightmared.fr&gt;</dc:contributor>
        <dc:contributor>Derek Thurston &lt;thegrit@gmail.com&gt;</dc:contributor>
        <dc:contributor>tianzhenjia &lt;jiatianzhen@cmss.chinamobile.com&gt;</dc:contributor>
        <dc:contributor>Greg Tinsley &lt;gtinsley@redhat.com&gt;</dc:contributor>
        <dc:contributor>Paul Tittle &lt;ptittle@cmf.nrl.navy.mil&gt;</dc:contributor>
        <dc:contributor>tom &lt;tom@localhost.localdomain&gt;</dc:contributor>
        <dc:contributor>tomas.hudik &lt;tomas.hudik@embedit.cz&gt;</dc:contributor>
        <dc:contributor>Jeb Trayer &lt;jeb.d.trayer@uscg.mil&gt;</dc:contributor>
        <dc:contributor>TrilokGeer &lt;tgeer@redhat.com&gt;</dc:contributor>
        <dc:contributor>Viktors Trubovics &lt;viktors.trubovics@suse.com&gt;</dc:contributor>
        <dc:contributor>Nico Truzzolino &lt;nico.truzzolino@gmx.de&gt;</dc:contributor>
        <dc:contributor>Brian Turek &lt;brian.turek@gmail.com&gt;</dc:contributor>
        <dc:contributor>Matěj Týč &lt;matyc@redhat.com&gt;</dc:contributor>
        <dc:contributor>Jörgen Uhr &lt;jorgen.uhr@sitevision.se&gt;</dc:contributor>
        <dc:contributor>VadimDor &lt;29509093+VadimDor@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Trevor Vaughan &lt;tvaughan@onyxpoint.com&gt;</dc:contributor>
        <dc:contributor>vtrubovics &lt;82443408+vtrubovics@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Sophia Wang &lt;huiwang@redhat.com&gt;</dc:contributor>
        <dc:contributor>Samuel Warren &lt;swarren@redhat.com&gt;</dc:contributor>
        <dc:contributor>wcushen &lt;54533890+wcushen@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Shawn Wells &lt;shawn@redhat.com&gt;</dc:contributor>
        <dc:contributor>Whidix &lt;31294015+Whidix@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Daniel E. White &lt;linuxdan@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>Bernhard M. Wiedemann &lt;bwiedemann@suse.de&gt;</dc:contributor>
        <dc:contributor>Roy Williams &lt;roywilli@roywilli.redhat.com&gt;</dc:contributor>
        <dc:contributor>Willumpie &lt;willumpie@xs4all.nl&gt;</dc:contributor>
        <dc:contributor>Rob Wilmoth &lt;rwilmoth@redhat.com&gt;</dc:contributor>
        <dc:contributor>win97pro &lt;win97pro@protonmail.com&gt;</dc:contributor>
        <dc:contributor>xcfxr &lt;xucee@qq.com&gt;</dc:contributor>
        <dc:contributor>Lucas Yamanishi &lt;lucas.yamanishi@onyxpoint.com&gt;</dc:contributor>
        <dc:contributor>Xirui Yang &lt;xirui.yang@oracle.com&gt;</dc:contributor>
        <dc:contributor>Yuqing Yang &lt;yyq01323329@alibaba-inc.com&gt;</dc:contributor>
        <dc:contributor>yarunachalam &lt;yarunachalam@suse.com&gt;</dc:contributor>
        <dc:contributor>Guang Yee &lt;guang.yee@suse.com&gt;</dc:contributor>
        <dc:contributor>Achilleas John Yfantis &lt;ayfantis@redhat.com&gt;</dc:contributor>
        <dc:contributor>YiLin.Li &lt;YiLin.Li@linux.alibaba.com&gt;</dc:contributor>
        <dc:contributor>yu410621 &lt;lihuanyu410621@gmail.com&gt;</dc:contributor>
        <dc:contributor>Xiaojie Yuan &lt;xiyuan@redhat.com&gt;</dc:contributor>
        <dc:contributor>yungcero &lt;133906218+yungcero@users.noreply.github.com&gt;</dc:contributor>
        <dc:contributor>yunimoo &lt;yunimoo@nekocake.cafe&gt;</dc:contributor>
        <dc:contributor>YuQing &lt;yyq0391@163.com&gt;</dc:contributor>
        <dc:contributor>zhaoyun &lt;zhaoyun@kylinos.cn&gt;</dc:contributor>
        <dc:contributor>Kevin Zimmerman &lt;kevin.zimmerman@kitware.com&gt;</dc:contributor>
        <dc:contributor>Luigi Mario Zuccarelli &lt;luzuccar@redhat.com&gt;</dc:contributor>
        <dc:contributor>Jan Černý &lt;jcerny@redhat.com&gt;</dc:contributor>
        <dc:contributor>Michal Šrubař &lt;msrubar@redhat.com&gt;</dc:contributor>
        <dc:source>https://github.com/ComplianceAsCode/content/releases/latest</dc:source>
      </xccdf-1.2:metadata>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_anssi_bp28_enhanced">
        <xccdf-1.2:title override="true">ANSSI-BP-028 (enhanced)</xccdf-1.2:title>
        <xccdf-1.2:description override="true">This profile contains configurations that align to ANSSI-BP-028 v2.0 at the enhanced hardening level.

ANSSI is the French National Information Security Agency, and stands for Agence nationale de la sécurité des systèmes d'information.
ANSSI-BP-028 is a configuration recommendation for GNU/Linux systems.

A copy of the ANSSI-BP-028 can be found at the ANSSI website:
https://www.ssi.gouv.fr/administration/guide/recommandations-de-securite-relatives-a-un-systeme-gnulinux/

An English version of the ANSSI-BP-028 can also be found at the ANSSI website:
https://cyber.gouv.fr/publications/configuration-recommendations-gnulinux-system</xccdf-1.2:description>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_minlen_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_dcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_lcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minclass" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minlen" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ocredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_retry" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ucredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_remember" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_rounds_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_rounds_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_max_life_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_interval" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_polyinstantiated_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_polyinstantiated_var_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_tmout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_bashrc" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_profile" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_dot_group_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_dot_user_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_users_home_files_groupownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_users_home_files_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_users_home_files_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_build_database" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmodat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchownat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fremovexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fsetxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lchown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lremovexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lsetxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_removexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_setxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_umount2" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rename" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_renameat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rmdir" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlink" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlinkat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_immutable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_delete" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_finit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_init" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_faillock" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_lastlog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_mac_modification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_media_export" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_networkconfig_modification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_kmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_btmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_utmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_wtmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_sysadmin_actions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_adjtimex" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_clock_settime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_stime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_watch_localtime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_creat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_ftruncate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_openat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_truncate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_sudo_log_events" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_specify_remote_server" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_root_owned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_system_commands_group_root_owned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_system_commands_root_owned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_ipsecd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_iptables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_nftables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_selinux" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_sudoersd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_sysctld" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_ipsecd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_iptables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_nftables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_selinux" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_sudoersd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_sysctld" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_ipsecd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_iptables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_nftables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_selinux" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_sudoersd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_sysctld" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dnf-automatic_security_updates_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_authselect" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_pam_namespace" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_almalinux_gpgkey_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_logrotate_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_chrony_keys" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_crypttab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_ipsec_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_ipsec_secrets" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_sestatus_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_sudoers" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_systemmap" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_system_commands_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_chrony_keys" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_crypttab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_ipsec_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_ipsec_secrets" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_sestatus_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_sudoers" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_systemmap" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_binary_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permission_user_init_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_binary_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_chrony_keys" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_crypttab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_ipsec_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_ipsec_secrets" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_sestatus_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_sudoers" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sudo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_systemmap" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_sgid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_suid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_world_writable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_ungroupowned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_enable_iommu_force" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_l1tf_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_mce_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_nosmap_argument_absent" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_nosmep_argument_absent" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_page_poison_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_pti_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_rng_core_default_quality_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_slab_nomerge_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_slub_debug_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_spec_store_bypass_disable_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_spectre_v2_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_uefi_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_install_PAE_kernel_on_x86-32" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ldap_client_start_tls" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ldap_client_tls_cacertpath" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_logind_session_timeout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_boot_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_boot_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_nodev_nonroot_local_partitions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_opt_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_srv_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_direct_root_logins" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_files_unowned_by_user" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_nis_in_nsswitch" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_aide_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_audit_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_chrony_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dhcp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_logrotate_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsyslog-gnutls_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sendmail_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sssd_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sudo_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_xinetd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypbind_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypserv_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_boot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_home" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_opt" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_srv" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_usr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_postfix_client_configure_mail_alias" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_postfix_network_listening_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_prefer_64bit_os" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_groupownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_remote_loghost" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_remote_tls" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_remote_tls_cacert" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sebool_polyinstantiation_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_security_patches_up_to_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_policytype" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_state" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_auditd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_chronyd_or_ntpd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_sssd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_systemauth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_enable_pam_services" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_ldap_configure_tls_reqcert" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_ldap_start_tls" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_env_reset" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_ignore_dot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_requiretty" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_umask" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_use_pty" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_dedicated_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudoers_explicit_command_args" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudoers_no_command_negation" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudoers_no_root_target" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_hardlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_symlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_suid_dumpable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_modules_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_panic_on_oops" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_perf_cpu_time_max_percent" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_perf_event_max_sample_rate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_perf_event_paranoid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_pid_max" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_sysrq" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_unprivileged_bpf_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_yama_ptrace_scope" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_core_bpf_jit_harden" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_local" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_arp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_arp_ignore" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_drop_gratuitous_arp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_route_localnet" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_shared_media" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_shared_media" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_ignore_bogus_error_responses" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_forward" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_local_port_range" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_rfc1337" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_syncookies" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra_defrtr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra_pinfo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_autoconf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_max_addresses" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_router_solicitations" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra_defrtr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra_pinfo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_autoconf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_max_addresses" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_router_solicitations" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_vm_mmap_min_addr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_systemd_tmp_mount_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_timer_dnf-automatic_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_389_ds" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_account_expiration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-banners" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_acl_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_selinux_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_base" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_bootloader-zipl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_certified-vendor" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_auditd_data_retention" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_console_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_cron_and_at" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_crypto" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_deprecated" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disable_avahi_group" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_cyrus-imapd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dns_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfsd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nginx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_snmp_service" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_squid" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_xwindows" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_entropy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fapolicyd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_file_permissions_auditd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fips" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_firewalld_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gcc_plugin" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_login_screen" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_media_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_remote_access_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_system_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gui_login_banner" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_http" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_imap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_journald" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kerberos" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kernel_build_config" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting_remote_filesystems" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-firewalld" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ufw" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-uncommon" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-wireless" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_and_rpc" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_clients" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_servers" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_var_log_dir" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_policy_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_harden_os" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_cfg" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_proxy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_r_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_radius" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_restrict_at_cron_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rng" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_root_paths" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rootfiles" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rpm_verification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_accepting_remote_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smart_card_login" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smb" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ssh_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_system-tools" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_talk" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_usbguard" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_wireless_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_xwindows" selected="false"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm" selector="SHA512"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" selector="sha512"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_rounds" selector="65536"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minclass" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_root" selector="365"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" selector="15"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_password_minlen_login_defs" selector="15"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_ocredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_dcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_ucredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_lcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_fail_interval" selector="900"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_tally2" selector="5"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_tally2_unlock_time" selector="1800"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" selector="900"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_remember" selector="2"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_polyinstantiation_enabled" selector="on"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sudo_umask" selector="0077"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_logind_session_timeout" selector="10_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_tmout" selector="10_min"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_shared_media_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_shared_media_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_arp_ignore_value" selector="2"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_kernel_kptr_restrict_value" selector="2"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_l1tf_options" selector="full_force"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_slub_debug_options" selector="FZP"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_spec_store_bypass_disable_options" selector="seccomp"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_mds_options" selector="full_nosmt"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_rng_core_default_quality" selector="500"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" selector="targeted"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sudo_dedicated_group" selector="sudogrp"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_state" selector="enforcing"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" selector="077"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_anssi_bp28_high">
        <xccdf-1.2:title override="true">ANSSI-BP-028 (high)</xccdf-1.2:title>
        <xccdf-1.2:description override="true">This profile contains configurations that align to ANSSI-BP-028 v2.0 at the high hardening level.

ANSSI is the French National Information Security Agency, and stands for Agence nationale de la sécurité des systèmes d'information.
ANSSI-BP-028 is a configuration recommendation for GNU/Linux systems.

A copy of the ANSSI-BP-028 can be found at the ANSSI website:
https://www.ssi.gouv.fr/administration/guide/recommandations-de-securite-relatives-a-un-systeme-gnulinux/

An English version of the ANSSI-BP-028 can also be found at the ANSSI website:
https://cyber.gouv.fr/publications/configuration-recommendations-gnulinux-system</xccdf-1.2:description>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_minlen_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_dcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_lcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minclass" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minlen" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ocredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_retry" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ucredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_remember" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_rounds_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_rounds_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_max_life_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_interval" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_polyinstantiated_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_polyinstantiated_var_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_tmout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_bashrc" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_profile" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_dot_group_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_dot_user_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_users_home_files_groupownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_users_home_files_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_users_home_files_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_build_database" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_periodic_cron_checking" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_scan_notification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_verify_acls" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_verify_ext_attributes" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmodat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchownat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fremovexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fsetxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lchown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lremovexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lsetxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_removexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_setxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_umount2" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rename" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_renameat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rmdir" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlink" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlinkat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_immutable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_delete" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_finit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_init" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_faillock" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_lastlog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_mac_modification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_media_export" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_networkconfig_modification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_kmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_btmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_utmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_wtmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_sysadmin_actions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_adjtimex" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_clock_settime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_stime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_watch_localtime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_creat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_ftruncate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_openat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_truncate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_sudo_log_events" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_specify_remote_server" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_root_owned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_system_commands_group_root_owned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_system_commands_root_owned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_ipsecd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_iptables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_nftables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_selinux" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_sudoersd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_sysctld" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_ipsecd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_iptables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_nftables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_selinux" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_sudoersd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_sysctld" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_ipsecd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_iptables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_nftables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_selinux" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_sudoersd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_sysctld" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dnf-automatic_security_updates_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_authselect" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_pam_namespace" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_almalinux_gpgkey_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_logrotate_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_chrony_keys" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_crypttab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_ipsec_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_ipsec_secrets" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_sestatus_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_sudoers" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_systemmap" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_system_commands_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_chrony_keys" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_crypttab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_ipsec_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_ipsec_secrets" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_sestatus_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_sudoers" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_systemmap" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_binary_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permission_user_init_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_binary_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_chrony_keys" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_crypttab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_ipsec_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_ipsec_secrets" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_sestatus_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_sudoers" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sudo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_systemmap" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_sgid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_suid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_world_writable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_ungroupowned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_enable_iommu_force" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_l1tf_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_mce_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_nosmap_argument_absent" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_nosmep_argument_absent" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_page_poison_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_pti_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_rng_core_default_quality_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_slab_nomerge_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_slub_debug_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_spec_store_bypass_disable_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_spectre_v2_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_uefi_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_install_PAE_kernel_on_x86-32" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_acpi_custom_method" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_arm64_sw_ttbr0_pan" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_binfmt_misc" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_bug" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_bug_on_data_corruption" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_compat_brk" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_compat_vdso" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_debug_credentials" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_debug_fs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_debug_list" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_debug_notifiers" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_debug_sg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_debug_wx" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_default_mmap_min_addr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_devkmem" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_fortify_source" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_gcc_plugin_latent_entropy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_gcc_plugin_structleak" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_hardened_usercopy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_hardened_usercopy_fallback" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_hibernation" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_ia32_emulation" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_kexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_legacy_ptys" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_legacy_vsyscall_emulate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_legacy_vsyscall_none" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_modify_ldt_syscall" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_module_sig" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_module_sig_all" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_module_sig_force" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_module_sig_hash" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_module_sig_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_module_sig_sha512" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_page_poisoning" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_page_poisoning_no_sanity" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_page_poisoning_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_page_table_isolation" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_panic_on_oops" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_panic_timeout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_proc_kcore" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_randomize_base" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_randomize_memory" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_refcount_full" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_retpoline" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_sched_stack_end_check" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_seccomp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_seccomp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_security" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_security_dmesg_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_security_writable_hooks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_security_yama" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_slab_freelist_hardened" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_slab_freelist_random" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_slab_merge_default" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_slub_debug" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_stackprotector" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_stackprotector_strong" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_strict_kernel_rwx" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_strict_module_rwx" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_syn_cookies" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_unmap_kernel_at_el0" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_vmap_stack" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_config_x86_vsyscall_emulation" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ldap_client_start_tls" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ldap_client_tls_cacertpath" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_logind_session_timeout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_boot_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_boot_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_nodev_nonroot_local_partitions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_opt_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_srv_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_direct_root_logins" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_files_unowned_by_user" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_nis_in_nsswitch" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_aide_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_audit_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_chrony_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dhcp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_logrotate_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsyslog-gnutls_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sendmail_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_setroubleshoot-plugins_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_setroubleshoot-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_setroubleshoot_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sssd_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sudo_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_xinetd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypbind_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypserv_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_boot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_home" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_opt" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_srv" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_usr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_postfix_client_configure_mail_alias" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_postfix_network_listening_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_prefer_64bit_os" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_groupownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_remote_loghost" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_remote_tls" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_remote_tls_cacert" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sebool_deny_execmem" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sebool_polyinstantiation_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_execheap" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_execstack" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sebool_ssh_sysadm_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_security_patches_up_to_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_policytype" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_state" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_auditd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_chronyd_or_ntpd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_sssd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_systemauth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_enable_pam_services" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_ldap_configure_tls_reqcert" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_ldap_start_tls" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_env_reset" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_ignore_dot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_requiretty" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_umask" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_use_pty" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_dedicated_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudoers_explicit_command_args" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudoers_no_command_negation" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudoers_no_root_target" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_hardlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_symlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_suid_dumpable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_modules_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_panic_on_oops" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_perf_cpu_time_max_percent" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_perf_event_max_sample_rate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_perf_event_paranoid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_pid_max" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_sysrq" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_unprivileged_bpf_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_yama_ptrace_scope" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_core_bpf_jit_harden" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_local" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_arp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_arp_ignore" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_drop_gratuitous_arp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_route_localnet" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_shared_media" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_shared_media" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_ignore_bogus_error_responses" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_forward" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_local_port_range" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_rfc1337" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_syncookies" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra_defrtr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra_pinfo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_autoconf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_max_addresses" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_router_solicitations" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra_defrtr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra_pinfo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_autoconf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_max_addresses" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_router_solicitations" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_vm_mmap_min_addr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_systemd_tmp_mount_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_timer_dnf-automatic_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_389_ds" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_account_expiration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-banners" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_acl_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_selinux_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_base" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_bootloader-zipl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_certified-vendor" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_auditd_data_retention" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_console_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_cron_and_at" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_crypto" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_deprecated" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disable_avahi_group" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_cyrus-imapd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dns_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfsd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nginx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_snmp_service" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_squid" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_xwindows" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_entropy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fapolicyd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_file_permissions_auditd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fips" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_firewalld_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_login_screen" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_media_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_remote_access_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_system_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gui_login_banner" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_http" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_imap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_journald" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kerberos" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting_remote_filesystems" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-firewalld" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ufw" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-uncommon" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-wireless" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_and_rpc" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_clients" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_servers" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_var_log_dir" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_policy_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_harden_os" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_cfg" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_proxy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_r_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_radius" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_restrict_at_cron_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rng" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_root_paths" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rootfiles" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rpm_verification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_accepting_remote_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smart_card_login" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smb" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ssh_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_system-tools" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_talk" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_usbguard" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_wireless_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_xwindows" selected="false"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm" selector="SHA512"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" selector="sha512"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_rounds" selector="65536"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minclass" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_root" selector="365"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" selector="15"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_password_minlen_login_defs" selector="15"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_ocredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_dcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_ucredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_lcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_fail_interval" selector="900"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_tally2" selector="5"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_tally2_unlock_time" selector="1800"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" selector="900"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_remember" selector="2"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_polyinstantiation_enabled" selector="on"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sudo_umask" selector="0077"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_logind_session_timeout" selector="10_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_tmout" selector="10_min"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_shared_media_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_shared_media_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_arp_ignore_value" selector="2"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_kernel_kptr_restrict_value" selector="2"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_l1tf_options" selector="full_force"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_slub_debug_options" selector="FZP"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_spec_store_bypass_disable_options" selector="seccomp"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_mds_options" selector="full_nosmt"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_rng_core_default_quality" selector="500"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sudo_dedicated_group" selector="sudogrp"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_state" selector="enforcing"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" selector="077"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinuxuser_execheap" selector="off"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_deny_execmem" selector="on"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinuxuser_execstack" selector="off"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_secure_mode_insmod" selector="on"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" selector="targeted"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_anssi_bp28_intermediary">
        <xccdf-1.2:title override="true">ANSSI-BP-028 (intermediary)</xccdf-1.2:title>
        <xccdf-1.2:description override="true">This profile contains configurations that align to ANSSI-BP-028 v2.0 at the intermediary hardening level.

ANSSI is the French National Information Security Agency, and stands for Agence nationale de la sécurité des systèmes d'information.
ANSSI-BP-028 is a configuration recommendation for GNU/Linux systems.

A copy of the ANSSI-BP-028 can be found at the ANSSI website:
https://www.ssi.gouv.fr/administration/guide/recommandations-de-securite-relatives-a-un-systeme-gnulinux/

An English version of the ANSSI-BP-028 can also be found at the ANSSI website:
https://cyber.gouv.fr/publications/configuration-recommendations-gnulinux-system</xccdf-1.2:description>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_minlen_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_dcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_lcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minclass" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minlen" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ocredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_retry" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ucredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_remember" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_rounds_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_rounds_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_max_life_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_interval" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_polyinstantiated_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_polyinstantiated_var_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_tmout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_dot_group_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_dot_user_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_users_home_files_groupownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_users_home_files_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_users_home_files_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_build_database" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_root_owned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_system_commands_group_root_owned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_system_commands_root_owned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_ipsecd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_iptables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_nftables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_selinux" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_sudoersd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_sysctld" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_ipsecd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_iptables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_nftables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_selinux" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_sudoersd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_owner_etc_sysctld" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_ipsecd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_iptables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_nftables" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_selinux" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_sudoersd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_etc_sysctld" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dnf-automatic_security_updates_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_authselect" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_pam_namespace" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_almalinux_gpgkey_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_chrony_keys" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_crypttab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_ipsec_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_ipsec_secrets" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_sestatus_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_sudoers" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_system_commands_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_chrony_keys" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_crypttab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_ipsec_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_ipsec_secrets" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_sestatus_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_sudoers" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_binary_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permission_user_init_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_binary_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_chrony_keys" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_crypttab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_ipsec_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_ipsec_secrets" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_sestatus_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_sudoers" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_sgid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_suid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_world_writable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_ungroupowned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_l1tf_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_mce_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_page_poison_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_pti_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_rng_core_default_quality_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_slab_nomerge_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_slub_debug_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_spec_store_bypass_disable_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_spectre_v2_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_uefi_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ldap_client_start_tls" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ldap_client_tls_cacertpath" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_logind_session_timeout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_boot_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_boot_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_nodev_nonroot_local_partitions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_opt_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_srv_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_direct_root_logins" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_files_unowned_by_user" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_nis_in_nsswitch" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_aide_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_audit_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dhcp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sendmail_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sssd_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sudo_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_xinetd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypbind_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypserv_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_boot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_home" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_opt" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_srv" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_usr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_postfix_client_configure_mail_alias" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_postfix_network_listening_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sebool_polyinstantiation_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_security_patches_up_to_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_state" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_auditd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_sssd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_systemauth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_enable_pam_services" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_ldap_configure_tls_reqcert" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_ldap_start_tls" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_env_reset" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_ignore_dot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_requiretty" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_umask" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_use_pty" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudoers_explicit_command_args" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudoers_no_command_negation" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudoers_no_root_target" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_hardlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_symlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_suid_dumpable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_panic_on_oops" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_perf_cpu_time_max_percent" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_perf_event_max_sample_rate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_perf_event_paranoid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_pid_max" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_sysrq" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_unprivileged_bpf_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_yama_ptrace_scope" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_core_bpf_jit_harden" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_local" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_arp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_arp_ignore" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_drop_gratuitous_arp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_route_localnet" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_shared_media" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_shared_media" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_ignore_bogus_error_responses" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_forward" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_local_port_range" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_rfc1337" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_syncookies" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra_defrtr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra_pinfo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_autoconf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_max_addresses" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_router_solicitations" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra_defrtr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra_pinfo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_autoconf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_max_addresses" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_router_solicitations" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_vm_mmap_min_addr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_systemd_tmp_mount_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_timer_dnf-automatic_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_389_ds" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_account_expiration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-banners" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_dac_actions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_acl_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_selinux_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_file_deletion_events" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_file_modification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_kernel_module_loading" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_login_events" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_time_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_base" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_bootloader-zipl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_certified-vendor" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_auditd_data_retention" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_console_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_cron_and_at" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_crypto" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_deprecated" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disable_avahi_group" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_cyrus-imapd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dns_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfsd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nginx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_snmp_service" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_squid" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_xwindows" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_enable_nx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ensure_rsyslog_log_file_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_entropy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fapolicyd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_file_permissions_auditd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fips" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_firewalld_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gcc_plugin" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_login_screen" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_media_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_remote_access_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_system_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gui_login_banner" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_http" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_imap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_journald" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kerberos" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kernel_build_config" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_log_rotation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_logging" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting_remote_filesystems" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-firewalld" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ufw" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-uncommon" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-wireless" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_and_rpc" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_clients" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_servers" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_var_log_dir" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_policy_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_harden_os" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_cfg" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_proxy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_r_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_radius" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_restrict_at_cron_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rng" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_root_paths" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rootfiles" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rpm_verification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_accepting_remote_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_sending_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smart_card_login" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smb" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ssh_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_system-tools" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_talk" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_usbguard" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_user_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_wireless_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_xwindows" selected="false"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm" selector="SHA512"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" selector="sha512"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_rounds" selector="65536"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minclass" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_root" selector="365"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" selector="15"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_password_minlen_login_defs" selector="15"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_ocredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_dcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_ucredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_lcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_fail_interval" selector="900"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_tally2" selector="5"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_tally2_unlock_time" selector="1800"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" selector="900"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_remember" selector="2"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_state" selector="enforcing"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_polyinstantiation_enabled" selector="on"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sudo_umask" selector="0077"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_logind_session_timeout" selector="10_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_tmout" selector="10_min"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_shared_media_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_shared_media_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_arp_ignore_value" selector="2"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_kernel_kptr_restrict_value" selector="2"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_l1tf_options" selector="full_force"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_slub_debug_options" selector="FZP"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_spec_store_bypass_disable_options" selector="seccomp"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_mds_options" selector="full_nosmt"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_rng_core_default_quality" selector="500"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_anssi_bp28_minimal">
        <xccdf-1.2:title override="true">ANSSI-BP-028 (minimal)</xccdf-1.2:title>
        <xccdf-1.2:description override="true">This profile contains configurations that align to ANSSI-BP-028 v2.0 at the minimal hardening level.

ANSSI is the French National Information Security Agency, and stands for Agence nationale de la sécurité des systèmes d'information.
ANSSI-BP-028 is a configuration recommendation for GNU/Linux systems.

A copy of the ANSSI-BP-028 can be found at the ANSSI website:
https://www.ssi.gouv.fr/administration/guide/recommandations-de-securite-relatives-a-un-systeme-gnulinux/

An English version of the ANSSI-BP-028 can also be found at the ANSSI website:
https://cyber.gouv.fr/publications/configuration-recommendations-gnulinux-system</xccdf-1.2:description>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_minlen_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_dcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_lcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minclass" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minlen" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ocredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_retry" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ucredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_remember" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_rounds_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_rounds_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_max_life_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_interval" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_root_owned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dnf-automatic_security_updates_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_authselect" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_almalinux_gpgkey_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_sgid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_suid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_world_writable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_ungroupowned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_files_unowned_by_user" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dhcp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sendmail_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_xinetd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypbind_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypserv_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_security_patches_up_to_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_systemauth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_timer_dnf-automatic_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_389_ds" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_account_expiration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-banners" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-physical" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-session" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_aide" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_dac_actions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_acl_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_selinux_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_file_deletion_events" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_file_modification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_kernel_module_loading" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_login_events" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_privileged_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_time_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_auditd_configure_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_auditing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_base" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_bootloader-grub2" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_bootloader-zipl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_certified-vendor" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_auditd_data_retention" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_console_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_coredumps" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_cron_and_at" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_crypto" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_deprecated" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disable_avahi_group" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_cyrus-imapd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dns_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfsd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nginx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_snmp_service" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_squid" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_xwindows" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disk_partitioning" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_enable_execshield_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_enable_nx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ensure_rsyslog_log_file_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_entropy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fapolicyd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_file_permissions_auditd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fips" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_firewalld_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gcc_plugin" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_login_screen" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_media_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_remote_access_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_system_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gui_login_banner" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_http" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_imap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_integrity" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_journald" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kerberos" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kernel_build_config" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_log_rotation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_logging" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting_remote_filesystems" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-firewalld" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ipsec" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-iptables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-kernel" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-nftables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ufw" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-uncommon" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-wireless" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network_host_and_router_parameters" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network_host_parameters" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_and_rpc" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_clients" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_servers" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_non-uefi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ntp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_partitions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_important_account_files" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_var_log_dir" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_within_important_dirs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_poisoning" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_policy_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_harden_os" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_cfg" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_proxy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_r_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_radius" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_restrict_at_cron_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_restrictions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rng" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_root_logins" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_root_paths" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rootfiles" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rpm_verification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_accepting_remote_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_sending_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_selinux" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_selinux-booleans" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smart_card_login" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smb" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_software-integrity" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ssh" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ssh_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ssh_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd-ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sudo" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_system-tools" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_talk" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_uefi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_usbguard" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_user_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_wireless_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_xwindows" selected="false"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm" selector="SHA512"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" selector="sha512"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_rounds" selector="65536"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minclass" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_root" selector="365"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" selector="15"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_password_minlen_login_defs" selector="15"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_ocredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_dcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_ucredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_lcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_fail_interval" selector="900"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_tally2" selector="5"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_tally2_unlock_time" selector="1800"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" selector="900"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_remember" selector="2"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_cis">
        <xccdf-1.2:version>4.0.0</xccdf-1.2:version>
        <xccdf-1.2:title override="true">CIS AlmaLinux OS 8 Benchmark for Level 2 - Server</xccdf-1.2:title>
        <xccdf-1.2:description override="true">This profile defines a baseline that aligns to the "Level 2 - Server"
configuration from the Center for Internet Security® 
AlmaLinux OS 8 Benchmark™, v4.0.0, released 2025-08-28.

This profile includes Center for Internet Security®
AlmaLinux OS 8 CIS Benchmarks™ content.</xccdf-1.2:description>
        <xccdf-1.2:reference>https://www.cisecurity.org/benchmark/almalinuxos_linux/</xccdf-1.2:reference>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_disable_post_pw_expiration" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_password_pam_faillock_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_password_pam_faillock_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_unique_id" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_unique_name" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_maximum_age_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_no_uid_except_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_all_shadowed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_last_change_is_in_past" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_dictcheck" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_difok" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_enforce_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxrepeat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxsequence" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minlen" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_modules_in_authselect_profile" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_enforce_for_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_remember_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_remember_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_use_authtok" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwquality_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwquality_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_authtok" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_no_remember" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_max_life_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_warn_age_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_warn_age_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time_with_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_root_gid_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_root_path_dirs_no_write" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_set_post_pw_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_tmout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_bashrc" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_profile" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_dot_group_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_dot_user_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_interactive_home_directory_exists" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_build_database" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_check_audit_tools" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_periodic_cron_checking" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_continue_loading" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmodat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchownat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fremovexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fsetxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lchown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lremovexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lsetxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_removexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_setxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_chacl" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_chcon" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_setfacl" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rename" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_renameat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlink" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlinkat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_immutable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_create" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_delete" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_finit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_init" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_query" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_faillock" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_lastlog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_mac_modification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_mac_modification_usr_share" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_media_export" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_networkconfig_modification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_networkconfig_modification_network_scripts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_kmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_usermod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_btmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_utmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_wtmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_suid_auid_privilege_function" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_sysadmin_actions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_adjtimex" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_clock_settime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_settimeofday" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_watch_localtime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_creat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_ftruncate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_openat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_truncate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_nsswitch_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_pam_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_pamd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_sudo_log_events" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_disk_error_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_disk_full_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_admin_space_left_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_max_log_file" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_max_log_file_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_space_left_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_banner_etc_issue_cis" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_banner_etc_issue_net_cis" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_banner_etc_motd_cis" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_run_as_chrony_user" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_specify_remote_server" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_custom_crypto_policy_cis" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_backtraces" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_storage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_db_up_to_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_banner_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_automount" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_automount_open" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_autorun" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_user_list" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_login_banner_text" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_idle_delay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_delay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_user_locks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_session_idle_user_locks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_host_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_users_coredumps" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_weak_deps" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_authselect" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_almalinux_gpgkey_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_pam_wheel_group_empty" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_root_password_configured" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_at_allow_exists" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_at_deny_not_exist" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_cron_allow_exists" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_cron_deny_not_exist" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_group_ownership_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_at_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_daily" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_hourly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_monthly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_weekly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_yearly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_issue" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_issue_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_motd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_security_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_security_opasswd_old" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_sysconfig_sshd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_audit_binaries" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_audit_configuration" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_at_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_daily" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_hourly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_monthly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_weekly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_yearly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_issue" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_issue_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_motd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_security_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_security_opasswd_old" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_sysconfig_sshd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_audit_binaries" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_audit_configuration" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_home_directories" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_var_log_audit_stig" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permission_user_bash_history" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permission_user_init_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_at_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_audit_binaries" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_audit_configuration" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_daily" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_hourly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_monthly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_weekly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_yearly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_issue" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_issue_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_motd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_security_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_security_opasswd_old" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_sysconfig_sshd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_home_directories" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_world_writable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firewalld-backend" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_gid_passwd_group_same" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_gnome_gdm_disable_xdmcp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_group_unique_id" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_group_unique_name" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_groups_no_zero_gid_except_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_backlog_limit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_enable_selinux" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_uefi_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_has_nonlocal_mta" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_journald_compress" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_journald_disable_forward_to_syslog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_journald_storage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_atm_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_can_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_cramfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_dccp_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_firewire-core_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_freevxfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_hfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_hfsplus_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_jffs2_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_overlayfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_rds_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_sctp_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_squashfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_tipc_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_udf_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_usb-storage_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_files_or_dirs_ungroupowned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_files_or_dirs_unowned_by_user" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_forward_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_invalid_shell_accounts_unlocked" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_netrc_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_nologin_in_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_password_auth_for_systemaccounts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_rhost_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_shelllogin_for_systemaccounts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_aide_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_audit-libs_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_audit_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_authselect_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_bind_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_chrony_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_cron_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_cyrus-imapd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dhcp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dovecot_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_firewalld_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ftp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_gdm_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_httpd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_libselinux_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_mcstrans_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_net-snmp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_nginx_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_openldap-clients_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_pam_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsync_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsyslog_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_samba_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_setroubleshoot_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_squid_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sudo_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_systemd-journal-remote_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_vsftpd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_xinetd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_xorg-x11-server-Xwayland_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypbind_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypserv_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_dev_shm" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_home" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_postfix_network_listening_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_root_path_no_dot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_filecreatemode" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_groupownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_nolisten" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_not_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_policytype" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_state" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_auditd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_autofs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_avahi-daemon_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_bluetooth_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_cockpit_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_crond_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_cups_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_dnsmasq_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_firewalld_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_nfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_rpcbind_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_rsyslog_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_systemd-journal-upload_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_systemd-journald_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_logindefs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_passwordauth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_systemauth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_socket_systemd-journal-remote_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_rhosts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_do_not_permit_user_env" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_pam" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_warning_banner_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_limit_user_access" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_idle_timeout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_keepalive" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_login_grace_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_loglevel_verbose" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_max_auth_tries" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_max_sessions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_maxstartups" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_use_pty" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_custom_logfile" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_nopasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_require_reauthentication" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_hardlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_symlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_suid_dumpable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_yama_ptrace_scope" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_log_martians" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_log_martians" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_echo_ignore_broadcasts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_ignore_bogus_error_responses" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_forward" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_syncookies" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_use_pam_wheel_group_for_su" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_wireless_disable_interfaces" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_xwayland_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_389_ds" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-physical" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_bootloader-zipl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_certified-vendor" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_console_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_deprecated" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_enable_nx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_entropy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fapolicyd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fips" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gcc_plugin" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_remote_access_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_system_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kerberos" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kernel_build_config" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_log_rotation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting_remote_filesystems" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ipsec" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-iptables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-nftables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ufw" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_servers" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_var_log_dir" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_within_important_dirs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_poisoning" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_policy_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_harden_os" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_cfg" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_r_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_radius" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rng" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rootfiles" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rpm_verification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_sending_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_selinux-booleans" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smart_card_login" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ssh_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd-ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_system-tools" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_talk" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_usbguard" selected="false"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_user_initialization_files_regex" selector="all_dotfiles"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" selector="027"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_tmout" selector="15_min"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration" selector="45"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm" selector="cis_rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_password_warn_age_login_defs" selector="7"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" selector="365"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" selector="cis_rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_remember_control_flag" selector="requisite_or_required"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_remember" selector="24"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_dictcheck" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxsequence" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxrepeat" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" selector="14"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_difok" selector="2"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" selector="900"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" selector="5"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_pam_wheel_group_for_su" selector="cis"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sudo_timestamp_timeout" selector="15_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_maxstartups" selector="10:30:60"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_max_sessions" selector="10"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_max_auth_tries_value" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_login_grace_time" selector="60"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_idle_timeout_value" selector="5_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_keepalive" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_source_route_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_source_route_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_forwarding_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_forwarding_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_tcp_syncookies_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_log_martians_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_log_martians_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_source_route_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_source_route_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_rp_filter_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_rp_filter_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_secure_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_secure_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_forwarding_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_multiple_time_servers" selector="rhel"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_postfix_inet_interfaces" selector="loopback-only"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_inactivity_timeout_value" selector="15_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_screensaver_lock_delay" selector="5_seconds"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_dconf_login_banner_text" selector="cis_banners"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_dconf_login_banner_contents" selector="cis_default"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_cis_banner_text" selector="cis"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" selector="targeted"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_authselect_profile" selector="sssd"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir" selector="run"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_admin_space_left_action" selector="cis_rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_space_left_action" selector="cis_rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_disk_error_action" selector="cis_rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_disk_full_action" selector="cis_rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_max_log_file_action" selector="keep_logs"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_max_log_file" selector="8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_audit_backlog_limit" selector="8192"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_root_unlock_time" selector="60"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_state" selector="enforcing"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_cis_server_l1">
        <xccdf-1.2:version>4.0.0</xccdf-1.2:version>
        <xccdf-1.2:title override="true">CIS AlmaLinux OS 8 Benchmark for Level 1 - Server</xccdf-1.2:title>
        <xccdf-1.2:description override="true">This profile defines a baseline that aligns to the "Level 1 - Server"
configuration from the Center for Internet Security® 
AlmaLinux OS 8 Benchmark™, v4.0.0, released 2025-08-28.

This profile includes Center for Internet Security®
AlmaLinux OS 8 CIS Benchmarks™ content.</xccdf-1.2:description>
        <xccdf-1.2:reference>https://www.cisecurity.org/benchmark/almalinuxos_linux/</xccdf-1.2:reference>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_disable_post_pw_expiration" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_password_pam_faillock_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_password_pam_faillock_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_unique_id" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_unique_name" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_maximum_age_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_no_uid_except_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_all_shadowed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_last_change_is_in_past" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_dictcheck" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_difok" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_enforce_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxrepeat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxsequence" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minlen" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_modules_in_authselect_profile" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_enforce_for_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_remember_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_remember_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_use_authtok" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwquality_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwquality_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_authtok" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_no_remember" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_max_life_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_warn_age_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_warn_age_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time_with_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_root_gid_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_root_path_dirs_no_write" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_set_post_pw_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_tmout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_bashrc" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_profile" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_dot_group_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_dot_user_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_interactive_home_directory_exists" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_build_database" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_check_audit_tools" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_periodic_cron_checking" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_banner_etc_issue_cis" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_banner_etc_issue_net_cis" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_banner_etc_motd_cis" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_run_as_chrony_user" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_specify_remote_server" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_custom_crypto_policy_cis" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_backtraces" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_storage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_db_up_to_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_banner_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_automount" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_automount_open" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_autorun" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_user_list" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_login_banner_text" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_idle_delay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_delay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_user_locks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_session_idle_user_locks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_host_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_users_coredumps" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_authselect" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_almalinux_gpgkey_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_pam_wheel_group_empty" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_root_password_configured" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_at_allow_exists" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_at_deny_not_exist" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_cron_allow_exists" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_cron_deny_not_exist" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_at_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_daily" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_hourly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_monthly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_weekly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_yearly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_issue" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_issue_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_motd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_security_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_security_opasswd_old" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_sysconfig_sshd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_at_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_daily" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_hourly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_monthly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_weekly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_yearly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_issue" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_issue_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_motd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_security_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_security_opasswd_old" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_sysconfig_sshd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_home_directories" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permission_user_bash_history" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permission_user_init_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_at_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_daily" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_hourly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_monthly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_weekly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_yearly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_issue" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_issue_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_motd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_security_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_security_opasswd_old" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_sysconfig_sshd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_home_directories" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_world_writable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firewalld-backend" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_gid_passwd_group_same" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_gnome_gdm_disable_xdmcp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_group_unique_id" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_group_unique_name" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_groups_no_zero_gid_except_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_enable_selinux" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_uefi_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_has_nonlocal_mta" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_journald_compress" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_journald_disable_forward_to_syslog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_journald_storage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_atm_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_can_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_cramfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_dccp_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_firewire-core_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_freevxfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_hfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_hfsplus_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_jffs2_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_rds_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_sctp_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_tipc_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_usb-storage_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_files_or_dirs_ungroupowned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_files_or_dirs_unowned_by_user" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_forward_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_invalid_shell_accounts_unlocked" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_netrc_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_password_auth_for_systemaccounts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_rhost_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_shelllogin_for_systemaccounts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_aide_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_authselect_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_bind_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_chrony_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_cron_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_cyrus-imapd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dhcp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dovecot_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_firewalld_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ftp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_httpd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_libselinux_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_mcstrans_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_net-snmp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_nginx_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_pam_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsync_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsyslog_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_samba_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_setroubleshoot_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_squid_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sudo_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_systemd-journal-remote_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_vsftpd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_xinetd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypbind_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypserv_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_dev_shm" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_postfix_network_listening_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_root_path_no_dot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_filecreatemode" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_groupownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_nolisten" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_not_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_policytype" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_autofs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_avahi-daemon_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_bluetooth_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_crond_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_cups_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_dnsmasq_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_firewalld_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_nfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_rpcbind_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_rsyslog_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_systemd-journal-upload_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_systemd-journald_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_logindefs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_passwordauth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_systemauth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_socket_systemd-journal-remote_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_rhosts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_do_not_permit_user_env" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_pam" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_warning_banner_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_limit_user_access" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_idle_timeout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_keepalive" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_login_grace_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_loglevel_verbose" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_max_auth_tries" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_max_sessions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_maxstartups" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_use_pty" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_custom_logfile" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_require_reauthentication" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_hardlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_suid_dumpable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_yama_ptrace_scope" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_log_martians" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_log_martians" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_echo_ignore_broadcasts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_ignore_bogus_error_responses" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_syncookies" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_use_pam_wheel_group_for_su" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_wireless_disable_interfaces" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_389_ds" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-physical" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_dac_actions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_acl_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_selinux_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_file_deletion_events" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_file_modification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_kernel_module_loading" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_login_events" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_privileged_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_time_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_auditd_configure_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_auditing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_base" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_bootloader-zipl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_certified-vendor" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_auditd_data_retention" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_console_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_deprecated" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_xwindows" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_enable_nx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_entropy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fapolicyd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_file_permissions_auditd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fips" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gcc_plugin" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_remote_access_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_system_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kerberos" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kernel_build_config" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_log_rotation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting_remote_filesystems" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ipsec" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-iptables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-nftables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ufw" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_servers" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_var_log_dir" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_within_important_dirs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_poisoning" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_policy_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_harden_os" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_cfg" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_r_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_radius" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rng" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rootfiles" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rpm_verification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_sending_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_selinux-booleans" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smart_card_login" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ssh_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd-ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_system-tools" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_talk" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_usbguard" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_xwindows" selected="false"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_user_initialization_files_regex" selector="all_dotfiles"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" selector="027"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_tmout" selector="15_min"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration" selector="45"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm" selector="cis_rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_password_warn_age_login_defs" selector="7"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" selector="365"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" selector="cis_rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_remember_control_flag" selector="requisite_or_required"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_remember" selector="24"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_dictcheck" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxsequence" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxrepeat" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" selector="14"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_difok" selector="2"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" selector="900"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" selector="5"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_pam_wheel_group_for_su" selector="cis"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sudo_timestamp_timeout" selector="15_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_maxstartups" selector="10:30:60"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_max_sessions" selector="10"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_max_auth_tries_value" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_login_grace_time" selector="60"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_idle_timeout_value" selector="5_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_keepalive" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_source_route_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_source_route_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_forwarding_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_forwarding_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_tcp_syncookies_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_log_martians_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_log_martians_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_source_route_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_source_route_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_rp_filter_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_rp_filter_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_secure_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_secure_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_forwarding_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_multiple_time_servers" selector="rhel"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_postfix_inet_interfaces" selector="loopback-only"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_inactivity_timeout_value" selector="15_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_screensaver_lock_delay" selector="5_seconds"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_dconf_login_banner_text" selector="cis_banners"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_dconf_login_banner_contents" selector="cis_default"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_cis_banner_text" selector="cis"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" selector="targeted"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_authselect_profile" selector="sssd"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_cis_workstation_l1">
        <xccdf-1.2:version>4.0.0</xccdf-1.2:version>
        <xccdf-1.2:title override="true">CIS AlmaLinux OS 8 Benchmark for Level 1 - Workstation</xccdf-1.2:title>
        <xccdf-1.2:description override="true">This profile defines a baseline that aligns to the "Level 1 - Workstation"
configuration from the Center for Internet Security® 
AlmaLinux OS 8 Benchmark™, v4.0.0, released 2025-08-28.

This profile includes Center for Internet Security®
AlmaLinux OS 8 CIS Benchmarks™ content.</xccdf-1.2:description>
        <xccdf-1.2:reference>https://www.cisecurity.org/benchmark/almalinuxos_linux/</xccdf-1.2:reference>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_disable_post_pw_expiration" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_password_pam_faillock_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_password_pam_faillock_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_unique_id" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_unique_name" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_maximum_age_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_no_uid_except_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_all_shadowed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_last_change_is_in_past" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_dictcheck" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_difok" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_enforce_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxrepeat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxsequence" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minlen" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_modules_in_authselect_profile" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_enforce_for_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_remember_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_remember_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_use_authtok" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwquality_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwquality_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_authtok" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_no_remember" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_max_life_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_warn_age_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_warn_age_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time_with_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_root_gid_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_root_path_dirs_no_write" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_set_post_pw_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_tmout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_bashrc" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_profile" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_dot_group_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_dot_user_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_interactive_home_directory_exists" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_build_database" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_check_audit_tools" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_periodic_cron_checking" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_banner_etc_issue_cis" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_banner_etc_issue_net_cis" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_banner_etc_motd_cis" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_run_as_chrony_user" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_specify_remote_server" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_custom_crypto_policy_cis" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_backtraces" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_storage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_db_up_to_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_banner_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_autorun" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_user_list" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_login_banner_text" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_idle_delay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_delay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_user_locks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_session_idle_user_locks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_host_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_users_coredumps" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_authselect" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_almalinux_gpgkey_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_pam_wheel_group_empty" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_root_password_configured" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_at_allow_exists" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_at_deny_not_exist" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_cron_allow_exists" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_cron_deny_not_exist" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_at_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_daily" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_hourly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_monthly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_weekly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_yearly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_issue" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_issue_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_motd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_security_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_security_opasswd_old" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_sysconfig_sshd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_at_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_daily" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_hourly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_monthly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_weekly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_yearly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_issue" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_issue_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_motd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_security_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_security_opasswd_old" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_sysconfig_sshd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_home_directories" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permission_user_bash_history" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permission_user_init_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_at_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_daily" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_hourly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_monthly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_weekly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_yearly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_issue" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_issue_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_motd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_security_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_security_opasswd_old" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_sysconfig_sshd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_home_directories" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_world_writable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firewalld-backend" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_gid_passwd_group_same" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_gnome_gdm_disable_xdmcp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_group_unique_id" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_group_unique_name" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_groups_no_zero_gid_except_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_enable_selinux" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_uefi_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_has_nonlocal_mta" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_journald_compress" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_journald_disable_forward_to_syslog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_journald_storage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_atm_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_can_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_cramfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_dccp_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_firewire-core_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_freevxfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_hfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_hfsplus_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_jffs2_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_rds_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_sctp_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_tipc_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_files_or_dirs_ungroupowned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_files_or_dirs_unowned_by_user" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_forward_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_invalid_shell_accounts_unlocked" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_netrc_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_password_auth_for_systemaccounts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_rhost_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_shelllogin_for_systemaccounts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_aide_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_authselect_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_bind_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_chrony_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_cron_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_cyrus-imapd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dhcp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dovecot_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_firewalld_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ftp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_httpd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_libselinux_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_mcstrans_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_net-snmp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_nginx_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_pam_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsync_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsyslog_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_samba_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_squid_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sudo_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_systemd-journal-remote_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_vsftpd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_xinetd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypbind_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypserv_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_dev_shm" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_postfix_network_listening_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_root_path_no_dot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_filecreatemode" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_groupownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_nolisten" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_not_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_policytype" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_crond_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_dnsmasq_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_firewalld_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_nfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_rpcbind_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_rsyslog_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_systemd-journal-upload_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_systemd-journald_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_logindefs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_passwordauth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_systemauth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_socket_systemd-journal-remote_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_rhosts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_do_not_permit_user_env" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_pam" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_warning_banner_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_limit_user_access" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_idle_timeout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_keepalive" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_login_grace_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_loglevel_verbose" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_max_auth_tries" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_max_sessions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_maxstartups" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_use_pty" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_custom_logfile" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_require_reauthentication" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_hardlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_suid_dumpable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_yama_ptrace_scope" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_log_martians" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_log_martians" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_echo_ignore_broadcasts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_ignore_bogus_error_responses" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_forward" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_syncookies" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_use_pam_wheel_group_for_su" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_389_ds" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-physical" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_dac_actions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_acl_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_selinux_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_file_deletion_events" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_file_modification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_kernel_module_loading" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_login_events" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_privileged_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_time_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_auditd_configure_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_auditing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_base" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_bootloader-zipl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_certified-vendor" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_auditd_data_retention" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_console_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_deprecated" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disable_avahi_group" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_xwindows" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_enable_nx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_entropy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fapolicyd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_file_permissions_auditd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fips" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gcc_plugin" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_remote_access_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_system_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kerberos" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kernel_build_config" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_log_rotation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting_remote_filesystems" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ipsec" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-iptables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-nftables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ufw" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-wireless" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_servers" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_var_log_dir" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_within_important_dirs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_poisoning" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_policy_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_harden_os" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_cfg" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_r_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_radius" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rng" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rootfiles" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rpm_verification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_sending_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_selinux-booleans" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smart_card_login" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ssh_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd-ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_system-tools" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_talk" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_usbguard" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_wireless_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_xwindows" selected="false"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_user_initialization_files_regex" selector="all_dotfiles"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" selector="027"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_tmout" selector="15_min"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration" selector="45"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm" selector="cis_rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_password_warn_age_login_defs" selector="7"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" selector="365"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" selector="cis_rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_remember_control_flag" selector="requisite_or_required"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_remember" selector="24"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_dictcheck" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxsequence" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxrepeat" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" selector="14"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_difok" selector="2"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" selector="900"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" selector="5"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_pam_wheel_group_for_su" selector="cis"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sudo_timestamp_timeout" selector="15_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_maxstartups" selector="10:30:60"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_max_sessions" selector="10"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_max_auth_tries_value" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_login_grace_time" selector="60"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_idle_timeout_value" selector="5_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_keepalive" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_source_route_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_source_route_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_forwarding_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_forwarding_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_tcp_syncookies_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_log_martians_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_log_martians_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_source_route_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_source_route_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_rp_filter_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_rp_filter_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_secure_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_secure_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_forwarding_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_multiple_time_servers" selector="rhel"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_postfix_inet_interfaces" selector="loopback-only"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_inactivity_timeout_value" selector="15_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_screensaver_lock_delay" selector="5_seconds"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_dconf_login_banner_text" selector="cis_banners"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_dconf_login_banner_contents" selector="cis_default"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_cis_banner_text" selector="cis"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" selector="targeted"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_authselect_profile" selector="sssd"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_cis_workstation_l2">
        <xccdf-1.2:version>4.0.0</xccdf-1.2:version>
        <xccdf-1.2:title override="true">CIS AlmaLinux OS 8 Benchmark for Level 2 - Workstation</xccdf-1.2:title>
        <xccdf-1.2:description override="true">This profile defines a baseline that aligns to the "Level 2 - Workstation"
configuration from the Center for Internet Security® 
AlmaLinux OS 8 Benchmark™, v4.0.0, released 2025-08-28.

This profile includes Center for Internet Security®
AlmaLinux OS 8 CIS Benchmarks™ content.</xccdf-1.2:description>
        <xccdf-1.2:reference>https://www.cisecurity.org/benchmark/almalinuxos_linux/</xccdf-1.2:reference>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_disable_post_pw_expiration" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_password_pam_faillock_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_password_pam_faillock_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_unique_id" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_unique_name" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_maximum_age_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_no_uid_except_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_all_shadowed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_last_change_is_in_past" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_dictcheck" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_difok" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_enforce_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxrepeat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxsequence" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minlen" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_modules_in_authselect_profile" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_enforce_for_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_remember_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_remember_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_use_authtok" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwquality_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwquality_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_authtok" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_no_remember" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_max_life_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_warn_age_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_warn_age_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time_with_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_root_gid_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_root_path_dirs_no_write" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_set_post_pw_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_tmout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_bashrc" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_profile" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_dot_group_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_dot_user_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_interactive_home_directory_exists" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_build_database" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_check_audit_tools" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_periodic_cron_checking" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_continue_loading" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmodat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchownat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fremovexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fsetxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lchown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lremovexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lsetxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_removexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_setxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_chacl" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_chcon" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_setfacl" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rename" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_renameat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlink" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlinkat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_immutable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_create" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_delete" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_finit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_init" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_query" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_faillock" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_lastlog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_mac_modification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_mac_modification_usr_share" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_media_export" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_networkconfig_modification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_networkconfig_modification_network_scripts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_kmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_usermod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_btmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_utmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_wtmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_suid_auid_privilege_function" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_sysadmin_actions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_adjtimex" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_clock_settime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_settimeofday" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_watch_localtime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_creat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_ftruncate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_openat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_truncate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_nsswitch_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_pam_conf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_pamd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_sudo_log_events" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_disk_error_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_disk_full_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_admin_space_left_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_max_log_file" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_max_log_file_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_space_left_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_banner_etc_issue_cis" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_banner_etc_issue_net_cis" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_banner_etc_motd_cis" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_run_as_chrony_user" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_specify_remote_server" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_custom_crypto_policy_cis" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_backtraces" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_storage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_db_up_to_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_banner_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_automount" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_automount_open" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_autorun" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_user_list" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_login_banner_text" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_idle_delay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_delay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_user_locks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_session_idle_user_locks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_host_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_users_coredumps" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_weak_deps" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_authselect" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_almalinux_gpgkey_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_pam_wheel_group_empty" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_root_password_configured" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_at_allow_exists" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_at_deny_not_exist" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_cron_allow_exists" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_cron_deny_not_exist" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_group_ownership_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_at_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_daily" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_hourly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_monthly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_weekly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_yearly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_issue" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_issue_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_motd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_security_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_security_opasswd_old" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_sysconfig_sshd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_audit_binaries" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_audit_configuration" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_at_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_daily" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_hourly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_monthly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_weekly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_yearly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_issue" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_issue_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_motd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_security_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_security_opasswd_old" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_sysconfig_sshd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_audit_binaries" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_audit_configuration" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_home_directories" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_var_log_audit_stig" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permission_user_bash_history" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permission_user_init_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_at_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_audit_binaries" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_audit_configuration" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_daily" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_hourly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_monthly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_weekly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_yearly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_efi_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_efi_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_issue" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_issue_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_motd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_security_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_security_opasswd_old" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_sysconfig_sshd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_home_directories" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_world_writable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firewalld-backend" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_gid_passwd_group_same" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_gnome_gdm_disable_xdmcp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_group_unique_id" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_group_unique_name" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_groups_no_zero_gid_except_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_backlog_limit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_enable_selinux" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_uefi_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_has_nonlocal_mta" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_journald_compress" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_journald_disable_forward_to_syslog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_journald_storage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_atm_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_can_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_cramfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_dccp_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_firewire-core_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_freevxfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_hfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_hfsplus_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_jffs2_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_overlayfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_rds_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_sctp_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_squashfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_tipc_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_udf_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_usb-storage_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_files_or_dirs_ungroupowned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_files_or_dirs_unowned_by_user" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_forward_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_invalid_shell_accounts_unlocked" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_netrc_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_nologin_in_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_password_auth_for_systemaccounts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_rhost_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_shelllogin_for_systemaccounts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_aide_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_audit-libs_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_audit_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_authselect_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_bind_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_chrony_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_cron_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_cyrus-imapd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dhcp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dovecot_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_firewalld_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ftp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_httpd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_libselinux_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_mcstrans_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_net-snmp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_nginx_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_openldap-clients_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_pam_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsync_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsyslog_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_samba_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_squid_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sudo_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_systemd-journal-remote_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_vsftpd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_xinetd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypbind_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypserv_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_dev_shm" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_home" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_postfix_network_listening_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_root_path_no_dot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_filecreatemode" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_groupownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_nolisten" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_not_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_policytype" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_state" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_auditd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_autofs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_avahi-daemon_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_bluetooth_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_cockpit_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_crond_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_dnsmasq_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_firewalld_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_nfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_rpcbind_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_rsyslog_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_systemd-journal-upload_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_systemd-journald_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_logindefs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_passwordauth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_systemauth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_socket_systemd-journal-remote_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_rhosts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_do_not_permit_user_env" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_pam" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_warning_banner_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_limit_user_access" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_idle_timeout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_keepalive" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_login_grace_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_loglevel_verbose" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_max_auth_tries" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_max_sessions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_maxstartups" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_use_pty" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_custom_logfile" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_nopasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_require_reauthentication" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_hardlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_symlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_suid_dumpable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_yama_ptrace_scope" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_log_martians" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_log_martians" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_echo_ignore_broadcasts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_ignore_bogus_error_responses" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_forward" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_syncookies" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_use_pam_wheel_group_for_su" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_xwayland_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_389_ds" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-physical" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_bootloader-zipl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_certified-vendor" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_console_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_deprecated" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_xwindows" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_enable_nx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_entropy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fapolicyd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fips" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gcc_plugin" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_remote_access_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_system_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kerberos" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kernel_build_config" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_log_rotation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting_remote_filesystems" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ipsec" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-iptables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-nftables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ufw" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_servers" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_var_log_dir" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_within_important_dirs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_poisoning" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_policy_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_harden_os" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_cfg" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_r_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_radius" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rng" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rootfiles" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rpm_verification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_sending_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_selinux-booleans" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smart_card_login" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ssh_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd-ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_system-tools" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_talk" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_usbguard" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_xwindows" selected="false"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_user_initialization_files_regex" selector="all_dotfiles"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" selector="027"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_tmout" selector="15_min"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration" selector="45"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm" selector="cis_rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_password_warn_age_login_defs" selector="7"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" selector="365"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" selector="cis_rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_remember_control_flag" selector="requisite_or_required"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_remember" selector="24"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_dictcheck" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxsequence" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxrepeat" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" selector="14"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_difok" selector="2"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" selector="900"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" selector="5"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_pam_wheel_group_for_su" selector="cis"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sudo_timestamp_timeout" selector="15_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_maxstartups" selector="10:30:60"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_max_sessions" selector="10"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_max_auth_tries_value" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_login_grace_time" selector="60"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_idle_timeout_value" selector="5_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_keepalive" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_source_route_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_source_route_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_forwarding_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_forwarding_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_tcp_syncookies_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_log_martians_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_log_martians_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_source_route_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_source_route_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_rp_filter_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_rp_filter_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_secure_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_secure_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_redirects_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value" selector="enabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_forwarding_value" selector="disabled"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_multiple_time_servers" selector="rhel"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_postfix_inet_interfaces" selector="loopback-only"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_inactivity_timeout_value" selector="15_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_screensaver_lock_delay" selector="5_seconds"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_dconf_login_banner_text" selector="cis_banners"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_dconf_login_banner_contents" selector="cis_default"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_cis_banner_text" selector="cis"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" selector="targeted"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_authselect_profile" selector="sssd"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir" selector="run"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_admin_space_left_action" selector="cis_rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_space_left_action" selector="cis_rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_disk_error_action" selector="cis_rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_disk_full_action" selector="cis_rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_max_log_file_action" selector="keep_logs"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_max_log_file" selector="8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_audit_backlog_limit" selector="8192"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_root_unlock_time" selector="60"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_state" selector="enforcing"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_cui">
        <xccdf-1.2:version>TBD</xccdf-1.2:version>
        <xccdf-1.2:title override="true">Unclassified Information in Non-federal Information Systems and Organizations (NIST 800-171)</xccdf-1.2:title>
        <xccdf-1.2:description override="true">From NIST 800-171, Section 2.2:
Security requirements for protecting the confidentiality of CUI in nonfederal
information systems and organizations have a well-defined structure that
consists of:

(i) a basic security requirements section;
(ii) a derived security requirements section.

The basic security requirements are obtained from FIPS Publication 200, which
provides the high-level and fundamental security requirements for federal
information and information systems. The derived security requirements, which
supplement the basic security requirements, are taken from the security controls
in NIST Special Publication 800-53.

This profile configures AlmaLinux OS 8 to the NIST Special
Publication 800-53 controls identified for securing Controlled Unclassified
Information (CUI)."</xccdf-1.2:description>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_dcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_difok" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_lcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxclassrepeat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxrepeat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minlen" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ocredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ucredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_remember" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_interval" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_bashrc" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_csh_cshrc" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_profile" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_access_failed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_access_success" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_basic_configuration" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_create_failed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_create_success" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_delete_failed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_delete_success" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_immutable_login_uids" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_modify_failed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_modify_success" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_module_load" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_ospp_general" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_owner_change_failed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_owner_change_success" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_perm_change_failed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_perm_change_success" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_flush" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_freq" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_local_events" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_log_format" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_name_format" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_write_logs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_client_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_configure_local_socket" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_no_chronyc_network" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_bashrc_exec_tmux" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_bind_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_kerberos_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_libreswan_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_openssl_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_tmux_lock_after_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_tmux_lock_command" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_usbguard_auditbackend" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_backtraces" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_storage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_burstaction" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_reboot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_host_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_users_coredumps" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dnf-automatic_security_updates_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_authselect" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_dracut_fips_module" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_fips_mode" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_almalinux_gpgkey_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_backlog_limit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_disable_recovery" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_kernel_trust_cpu_rng" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_page_poison_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_pti_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_slub_debug_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_uefi_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_vsyscall_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kerberos_disable_no_keytab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_atm_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_bluetooth_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_can_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_cramfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_firewire-core_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_sctp_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_tipc_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_boot_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_boot_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_nodev_nonroot_local_partitions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_tmux_in_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_openssl_use_strong_entropy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt-addon-ccpp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt-addon-kerneloops_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt-cli_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt-plugin-sosreport_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_aide_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_audit_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_chrony_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_crypto-policies_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dnf-plugin-subscription-manager_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_fapolicyd_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_firewalld_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_gssproxy_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_iprutils_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_krb5-workstation_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_libreport-plugin-logger_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_libreport-plugin-rhtsupport_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_nfs-utils_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_openscap-scanner_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_openssh-clients_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_openssh-server_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_policycoreutils-python-utils_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_policycoreutils_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_python3-abrt-addon_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsyslog_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_scap-security-guide_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sendmail_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_subscription-manager_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sudo_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tmux_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_usbguard_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_home" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_require_singleuser_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_securetty_root_login_console_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_policytype" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_state" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_auditd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_debug-shell_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_fapolicyd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_firewalld_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_kdump_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_systemd-coredump_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_usbguard_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ssh_client_rekey_limit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ssh_client_use_strong_rng_csh" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ssh_client_use_strong_rng_sh" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_kerb_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_strictmodes" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_warning_banner" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_rekey_limit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_idle_timeout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_keepalive_0" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_use_strong_rng" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_hardlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_symlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_core_pattern" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kexec_load_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_perf_event_paranoid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_unprivileged_bpf_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_yama_ptrace_scope" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_core_bpf_jit_harden" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_log_martians" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_log_martians" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_echo_ignore_broadcasts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_ignore_bogus_error_responses" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_forward" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_syncookies" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_user_max_user_namespaces" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_timer_dnf-automatic_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_usbguard_allow_hid_and_hub" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_use_pam_wheel_for_su" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_zipl_audit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_zipl_audit_backlog_limit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_zipl_bls_entries_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_zipl_bootmap_is_up_to_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_zipl_page_poison_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_zipl_slub_debug_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_389_ds" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_account_expiration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-banners" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_dac_actions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_acl_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_selinux_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_file_deletion_events" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_file_modification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_kernel_module_loading" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_login_events" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_privileged_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_time_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_auditd_configure_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_certified-vendor" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_cron_and_at" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_deprecated" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disable_avahi_group" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_cyrus-imapd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dns_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfsd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nginx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_snmp_service" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_squid" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_xwindows" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_enable_nx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ensure_rsyslog_log_file_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_entropy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_file_permissions_auditd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gcc_plugin" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_login_screen" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_media_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_remote_access_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_system_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gui_login_banner" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_http" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_imap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_inetd_and_xinetd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_journald" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kernel_build_config" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_log_rotation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting_remote_filesystems" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ipsec" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-iptables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-nftables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ufw" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_clients" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_servers" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nis" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_non-uefi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_obsolete" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_password_expiration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_important_account_files" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_var_log_dir" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_within_important_dirs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_harden_os" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_cfg" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_proxy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_r_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_radius" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_restrict_at_cron_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rng" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_root_paths" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rootfiles" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rpm_verification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_accepting_remote_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_sending_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_selinux-booleans" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_set_password_hashing_algorithm" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smart_card_login" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smb" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd-ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_talk" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_telnet" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_tftp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_xwindows" selected="false"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_logind_session_timeout" selector="5_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" selector="12"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_ocredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_dcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_ucredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_lcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_kernel_unprivileged_bpf_disabled_value" selector="2"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_state" selector="enforcing"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" selector="targeted"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_fail_interval" selector="900"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" selector="never"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_size" selector="1G"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_time" selector="1hour"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_rekey_limit_size" selector="1G"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_rekey_limit_time" selector="1hour"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_system_crypto_policy" selector="fips"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_audit_backlog_limit" selector="8192"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_flush" selector="incremental_async"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_idle_timeout_value" selector="14_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxclassrepeat" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_remember" selector="5"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_authselect_profile" selector="minimal"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" selector="027"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_max_concurrent_login_sessions" selector="10"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_difok" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxrepeat" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_keepalive" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_slub_debug_options" selector="P"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_inactivity_timeout_value" selector="10_minutes"/>
        <xccdf-1.2:refine-rule idref="xccdf_org.ssgproject.content_rule_sysctl_user_max_user_namespaces" role="unscored" severity="info"/>
        <xccdf-1.2:refine-rule idref="xccdf_org.ssgproject.content_rule_grub2_vsyscall_argument" role="unscored" severity="info"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_e8">
        <xccdf-1.2:title override="true">Australian Cyber Security Centre (ACSC) Essential Eight</xccdf-1.2:title>
        <xccdf-1.2:description override="true">This profile contains configuration checks for AlmaLinux OS 8
that align to the Australian Cyber Security Centre (ACSC) Essential Eight.

A copy of the Essential Eight in Linux Environments guide can be found at the
ACSC website:

https://www.cyber.gov.au/acsc/view-all-content/publications/hardening-linux-workstations-and-servers</xccdf-1.2:description>
        <xccdf-1.2:reference>https://www.cyber.gov.au/acsc/view-all-content/publications/hardening-linux-workstations-and-servers</xccdf-1.2:reference>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_no_uid_except_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_chcon" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_restorecon" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_semanage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_setfiles" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_setsebool" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_seunshare" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_faillock" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_lastlog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_tallylog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_networkconfig_modification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_sysadmin_actions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_adjtimex" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_clock_settime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_settimeofday" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_stime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_watch_localtime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_flush" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_freq" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_local_events" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_log_format" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_name_format" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_write_logs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dnf-automatic_security_updates_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_authselect" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_almalinux_gpgkey_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_binary_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_library_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_binary_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_library_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_sgid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_suid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_world_writable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_network_sniffer_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_fapolicyd_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_firewalld_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rear_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsyslog_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_squid_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_xinetd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypbind_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rpm_verify_hashes" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rpm_verify_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rpm_verify_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_security_patches_up_to_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_policytype" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_state" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_auditd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_avahi-daemon_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_fapolicyd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_firewalld_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_kdump_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_rsyslog_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_squid_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_telnet_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_xinetd_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_rhosts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_user_known_hosts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_do_not_permit_user_env" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_strictmodes" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_print_last_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_loglevel_info" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_nopasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_require_authentication" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_exec_shield" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kexec_load_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_unprivileged_bpf_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_yama_ptrace_scope" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_core_bpf_jit_harden" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_389_ds" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_account_expiration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-banners" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-pam" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-physical" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-session" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_aide" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_acl_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_file_deletion_events" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_file_modification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_privileged_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_bootloader-grub2" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_bootloader-zipl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_certified-vendor" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_console_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_coredumps" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_cron_and_at" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_deprecated" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_cyrus-imapd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dns_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfsd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nginx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_snmp_service" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_xwindows" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disk_partitioning" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_enable_nx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ensure_rsyslog_log_file_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_entropy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_file_permissions_auditd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fips" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gcc_plugin" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_login_screen" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_media_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_remote_access_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_system_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gui_login_banner" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_http" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_imap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_journald" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kerberos" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kernel_build_config" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_locking_out_password_attempts" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_log_rotation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mail" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting_remote_filesystems" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ipsec" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-iptables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-kernel" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-nftables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ufw" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-uncommon" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-wireless" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network_host_and_router_parameters" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network_host_parameters" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_and_rpc" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_clients" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_servers" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_non-uefi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ntp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_password_expiration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_password_quality" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_password_quality_pwquality" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_important_account_files" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_var_log_dir" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_poisoning" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_policy_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_harden_os" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_cfg" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_r_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_radius" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_restrict_at_cron_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rng" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_root_paths" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rootfiles" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_accepting_remote_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_sending_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_selinux-booleans" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_set_password_hashing_algorithm" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smart_card_login" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smb" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ssh_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd-ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_talk" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_tftp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_uefi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_usbguard" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_user_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_wireless_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_xwindows" selected="false"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_system_crypto_policy" selector="default_nosha1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_flush" selector="incremental_async"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_state" selector="enforcing"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" selector="targeted"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_authselect_profile" selector="sssd"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_hipaa">
        <xccdf-1.2:title override="true">Health Insurance Portability and Accountability Act (HIPAA)</xccdf-1.2:title>
        <xccdf-1.2:description override="true">The HIPAA Security Rule establishes U.S. national standards to protect individuals’
electronic personal health information that is created, received, used, or
maintained by a covered entity. The Security Rule requires appropriate
administrative, physical and technical safeguards to ensure the
confidentiality, integrity, and security of electronic protected health
information.

This profile configures AlmaLinux OS 8 to the HIPAA Security
Rule identified for securing of electronic protected health information.
Use of this profile in no way guarantees or makes claims against legal compliance against the HIPAA Security Rule(s).</xccdf-1.2:description>
        <xccdf-1.2:reference>https://www.hhs.gov/hipaa/for-professionals/index.html</xccdf-1.2:reference>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmodat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchownat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fremovexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fsetxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lchown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lremovexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lsetxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_removexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_setxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_chcon" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_restorecon" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_semanage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_setsebool" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rename" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_renameat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rmdir" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlink" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlinkat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_immutable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_delete" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_init" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_faillock" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_lastlog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_tallylog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_mac_modification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_media_export" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_networkconfig_modification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_chage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_chsh" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_gpasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_newgrp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_pam_timestamp_check" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_postdrop" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_postqueue" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_ssh_keysign" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_su" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudoedit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_umount" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_unix_chkpwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_userhelper" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_btmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_utmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_wtmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_sysadmin_actions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_system_shutdown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_adjtimex" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_clock_settime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_settimeofday" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_stime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_watch_localtime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_creat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_ftruncate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_by_handle_at" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_openat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_truncate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_audispd_syslog_plugin_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_flush" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_db_up_to_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_remote_access_credential_prompt" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_remote_access_encryption" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_burstaction" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_reboot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_host_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_authselect" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_encrypt_partitions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_almalinux_gpgkey_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_backlog_limit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_disable_interactive_boot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_enable_selinux" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_uefi_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_usb-storage_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_libreswan_approved_tunnels" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_direct_root_logins" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_rsh_trust_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_postfix_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_xinetd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_require_singleuser_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_restrict_serial_port_logins" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rpm_verify_hashes" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rpm_verify_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_remote_loghost" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_execheap" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_execmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_execstack" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_securetty_root_login_console_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_confinement_of_daemons" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_policytype" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_state" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_auditd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_autofs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_crond_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_debug-shell_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_kdump_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_telnet_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_xinetd_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_allow_only_protocol2" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_compression" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_kerb_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_do_not_permit_user_env" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_strictmodes" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_warning_banner" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_keepalive_0" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_suid_dumpable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_exec_shield" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_use_kerberos_security_all_exports" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_389_ds" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_account_expiration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-banners" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-pam" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-session" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_aide" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_acl_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_bootloader-zipl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_certified-vendor" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_console_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_deprecated" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disable_avahi_group" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_cyrus-imapd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dns_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfsd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nginx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_snmp_service" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_squid" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_xwindows" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_enable_nx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ensure_rsyslog_log_file_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_entropy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fapolicyd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_file_permissions_auditd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_files" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fips" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_firewalld_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gcc_plugin" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_login_screen" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_media_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_system_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gui_login_banner" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_http" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_imap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_journald" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kerberos" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kernel_build_config" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_locking_out_password_attempts" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_log_rotation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting_remote_filesystems" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-firewalld" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-iptables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-kernel" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-nftables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ufw" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-uncommon" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-wireless" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network_host_and_router_parameters" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network_host_parameters" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_clients" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nis" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ntp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_partitions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_password_expiration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_password_quality" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_password_quality_pwquality" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_important_account_files" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_var_log_dir" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_within_important_dirs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_poisoning" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_policy_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_harden_os" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_cfg" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_proxy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_radius" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_restrict_at_cron_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rng" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_root_paths" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rootfiles" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_accepting_remote_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_set_password_hashing_algorithm" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smart_card_login" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smb" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ssh_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd-ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sudo" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_system-tools" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_talk" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_tftp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_usbguard" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_user_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_wireless_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_xwindows" selected="false"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_audit_failure_mode" selector="panic"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" selector="targeted"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_state" selector="enforcing"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_keepalive" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_authselect_profile" selector="sssd"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_audit_backlog_limit" selector="8192"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_system_crypto_policy" selector="fips"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_ism_o">
        <xccdf-1.2:title override="true">Australian Cyber Security Centre (ACSC) ISM Official</xccdf-1.2:title>
        <xccdf-1.2:description override="true">This profile contains configuration checks for AlmaLinux OS 8
that align to the Australian Cyber Security Centre (ACSC) Information Security Manual (ISM)
with the applicability marking of OFFICIAL.

The ISM uses a risk-based approach to cyber security. This profile provides a guide to aligning
AlmaLinux OS security controls with the ISM, which can be used to select controls
specific to an organisation's security posture and risk profile.

A copy of the ISM can be found at the ACSC website:

https://www.cyber.gov.au/ism</xccdf-1.2:description>
        <xccdf-1.2:reference>https://www.cyber.gov.au/ism</xccdf-1.2:reference>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_maximum_age_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_minimum_age_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_no_uid_except_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_all_shadowed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minlen" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_warn_age_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_interval" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_access_failed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_access_success" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_chcon" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_restorecon" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_semanage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_setfiles" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_setsebool" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_seunshare" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_faillock" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_lastlog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_tallylog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_networkconfig_modification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_btmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_utmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_wtmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_sysadmin_actions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_adjtimex" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_clock_settime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_settimeofday" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_stime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_watch_localtime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_flush" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_freq" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_local_events" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_log_format" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_name_format" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_write_logs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_or_ntpd_specify_multiple_servers" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_specify_remote_server" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_firewalld_ports" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_host_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dnf-automatic_security_updates_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_authselect" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_fips_mode" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_almalinux_gpgkey_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_binary_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_library_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_binary_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_library_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_sgid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_suid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_world_writable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firewalld_sshd_port_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_network_nmcli_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_network_sniffer_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_shelllogin_for_systemaccounts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_openssl_use_strong_entropy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_aide_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_chrony_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_fapolicyd_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_firewalld_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rear_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsyslog-gnutls_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsyslog_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_squid_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sudo_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_usbguard_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_xinetd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypbind_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_require_emergency_target_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_require_singleuser_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rpm_verify_hashes" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rpm_verify_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rpm_verify_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_cron_logging" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_groupownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_nolisten" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_remote_loghost" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_remote_tls" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_remote_tls_cacert" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sebool_auditadm_exec_content" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_security_patches_up_to_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_policytype" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_state" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_auditd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_avahi-daemon_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_chronyd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_chronyd_or_ntpd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_fapolicyd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_firewalld_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_kdump_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_rsyslog_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_snmpd_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_squid_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_telnet_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_usbguard_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_xinetd_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_firewalld_default_zone" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_snmpd_use_newer_protocol" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_allow_only_protocol2" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_kerb_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_rhosts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_user_known_hosts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_x11_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_do_not_permit_user_env" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_strictmodes" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_warning_banner" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_print_last_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_loglevel_info" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_max_auth_tries" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_nopasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_require_authentication" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_exec_shield" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kexec_load_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_unprivileged_bpf_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_yama_ptrace_scope" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_core_bpf_jit_harden" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_usbguard_allow_hid_and_hub" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_wireless_disable_interfaces" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_389_ds" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_account_expiration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-banners" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-session" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_acl_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_file_deletion_events" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_file_modification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_bootloader-grub2" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_bootloader-zipl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_certified-vendor" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_console_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_coredumps" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_cron_and_at" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_deprecated" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_cyrus-imapd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dns_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfsd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nginx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_xwindows" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disk_partitioning" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_enable_nx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_entropy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_file_permissions_auditd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gcc_plugin" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_login_screen" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_media_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_remote_access_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_system_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gui_login_banner" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_http" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_imap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_journald" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kerberos" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kernel_build_config" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_log_rotation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mail" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting_remote_filesystems" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ipsec" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-iptables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-kernel" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-nftables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ufw" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-uncommon" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network_host_and_router_parameters" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network_host_parameters" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_and_rpc" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_clients" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_servers" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_non-uefi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_important_account_files" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_var_log_dir" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_poisoning" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_harden_os" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_cfg" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_r_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_radius" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_restrict_at_cron_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rng" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_root_paths" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rootfiles" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_set_password_hashing_algorithm" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smart_card_login" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smb" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ssh_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd-ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_talk" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_tftp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_uefi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_user_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_xwindows" selected="false"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_system_crypto_policy" selector="fips"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_flush" selector="incremental_async"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_state" selector="enforcing"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" selector="targeted"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_authselect_profile" selector="sssd"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" selector="14"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_password_minlen_login_defs" selector="15"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_max_auth_tries_value" selector="5"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_password_warn_age_login_defs" selector="7"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_minimum_age_login_defs" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" selector="60"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" selector="sha512"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_ospp">
        <xccdf-1.2:version>4.2.1</xccdf-1.2:version>
        <xccdf-1.2:title override="true">Protection Profile for General Purpose Operating Systems</xccdf-1.2:title>
        <xccdf-1.2:description override="true">This profile reflects mandatory configuration controls identified in the
NIAP Configuration Annex to the Protection Profile for General Purpose
Operating Systems (Protection Profile Version 4.2.1).

This configuration profile is consistent with CNSSI-1253, which requires
U.S. National Security Systems to adhere to certain configuration
parameters. Accordingly, this configuration profile is suitable for
use in U.S. National Security Systems.</xccdf-1.2:description>
        <xccdf-1.2:reference>https://www.niap-ccevs.org/Profile/Info.cfm?PPID=442&amp;id=442</xccdf-1.2:reference>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_dcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_difok" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_lcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxclassrepeat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxrepeat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minlen" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ocredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ucredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_remember" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_interval" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_bashrc" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_csh_cshrc" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_profile" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_access_failed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_access_success" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_basic_configuration" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_create_failed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_create_success" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_delete_failed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_delete_success" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_immutable_login_uids" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_modify_failed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_modify_success" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_module_load" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_ospp_general" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_owner_change_failed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_owner_change_success" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_perm_change_failed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_perm_change_success" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_flush" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_freq" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_local_events" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_log_format" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_name_format" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_write_logs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_client_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_configure_local_socket" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_no_chronyc_network" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_bashrc_exec_tmux" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_bind_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_kerberos_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_libreswan_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_openssl_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_tmux_lock_after_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_tmux_lock_command" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_usbguard_auditbackend" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_backtraces" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_storage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_burstaction" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_reboot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_host_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_users_coredumps" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dnf-automatic_security_updates_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_authselect" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_dracut_fips_module" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_fips_mode" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_almalinux_gpgkey_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_backlog_limit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_disable_recovery" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_kernel_trust_cpu_rng" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_page_poison_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_pti_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_slub_debug_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_uefi_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_vsyscall_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kerberos_disable_no_keytab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_atm_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_bluetooth_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_can_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_cramfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_firewire-core_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_sctp_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_tipc_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_boot_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_boot_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_nodev_nonroot_local_partitions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_tmux_in_shells" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_openssl_use_strong_entropy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt-addon-ccpp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt-addon-kerneloops_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt-cli_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt-plugin-sosreport_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_aide_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_audit_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_chrony_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_crypto-policies_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dnf-plugin-subscription-manager_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_fapolicyd_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_firewalld_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_gssproxy_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_iprutils_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_krb5-workstation_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_libreport-plugin-logger_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_libreport-plugin-rhtsupport_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_nfs-utils_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_openscap-scanner_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_openssh-clients_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_openssh-server_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_policycoreutils-python-utils_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_policycoreutils_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_python3-abrt-addon_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsyslog_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_scap-security-guide_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sendmail_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_subscription-manager_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sudo_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tmux_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_usbguard_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_home" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_require_singleuser_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_securetty_root_login_console_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_policytype" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_state" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_auditd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_debug-shell_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_fapolicyd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_firewalld_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_kdump_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_systemd-coredump_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_usbguard_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ssh_client_rekey_limit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ssh_client_use_strong_rng_csh" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ssh_client_use_strong_rng_sh" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_kerb_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_strictmodes" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_warning_banner" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_rekey_limit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_idle_timeout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_keepalive_0" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_use_strong_rng" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_hardlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_symlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_core_pattern" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kexec_load_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_perf_event_paranoid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_unprivileged_bpf_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_yama_ptrace_scope" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_core_bpf_jit_harden" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_log_martians" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_log_martians" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_echo_ignore_broadcasts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_ignore_bogus_error_responses" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_forward" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_syncookies" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_user_max_user_namespaces" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_timer_dnf-automatic_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_usbguard_allow_hid_and_hub" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_use_pam_wheel_for_su" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_zipl_audit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_zipl_audit_backlog_limit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_zipl_bls_entries_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_zipl_bootmap_is_up_to_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_zipl_page_poison_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_zipl_slub_debug_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_389_ds" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_account_expiration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-banners" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_dac_actions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_acl_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_selinux_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_file_deletion_events" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_file_modification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_kernel_module_loading" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_login_events" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_privileged_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_time_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_auditd_configure_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_certified-vendor" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_cron_and_at" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_deprecated" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disable_avahi_group" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_cyrus-imapd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dns_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfsd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nginx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_snmp_service" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_squid" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_xwindows" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_enable_nx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ensure_rsyslog_log_file_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_entropy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_file_permissions_auditd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gcc_plugin" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_login_screen" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_media_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_remote_access_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_system_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gui_login_banner" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_http" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_imap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_inetd_and_xinetd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_journald" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kernel_build_config" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_log_rotation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting_remote_filesystems" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ipsec" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-iptables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-nftables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ufw" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_clients" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_servers" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nis" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_non-uefi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_obsolete" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_password_expiration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_important_account_files" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_var_log_dir" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_within_important_dirs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_harden_os" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_cfg" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_proxy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_r_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_radius" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_restrict_at_cron_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rng" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_root_paths" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rootfiles" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rpm_verification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_accepting_remote_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_sending_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_selinux-booleans" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_set_password_hashing_algorithm" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smart_card_login" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smb" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd-ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_talk" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_telnet" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_tftp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_xwindows" selected="false"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_logind_session_timeout" selector="5_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" selector="12"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_ocredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_dcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_ucredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_lcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sysctl_kernel_unprivileged_bpf_disabled_value" selector="2"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_state" selector="enforcing"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" selector="targeted"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_fail_interval" selector="900"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" selector="never"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_size" selector="1G"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_time" selector="1hour"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_rekey_limit_size" selector="1G"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_rekey_limit_time" selector="1hour"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_system_crypto_policy" selector="fips_ospp"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_audit_backlog_limit" selector="8192"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_flush" selector="incremental_async"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_idle_timeout_value" selector="14_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxclassrepeat" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_remember" selector="5"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_authselect_profile" selector="minimal"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" selector="027"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_max_concurrent_login_sessions" selector="10"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_difok" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxrepeat" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_keepalive" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_slub_debug_options" selector="P"/>
        <xccdf-1.2:refine-rule idref="xccdf_org.ssgproject.content_rule_sysctl_user_max_user_namespaces" role="unscored" severity="info"/>
        <xccdf-1.2:refine-rule idref="xccdf_org.ssgproject.content_rule_grub2_vsyscall_argument" role="unscored" severity="info"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_pci-dss">
        <xccdf-1.2:version>4.0.1</xccdf-1.2:version>
        <xccdf-1.2:title override="true">PCI-DSS v4.0.1 Control Baseline for AlmaLinux OS 8</xccdf-1.2:title>
        <xccdf-1.2:description override="true">Payment Card Industry - Data Security Standard (PCI-DSS) is a set of
security standards designed to ensure the secure handling of payment card
data, with the goal of preventing data breaches and protecting sensitive
financial information.

This profile ensures AlmaLinux OS 8 is configured in alignment
with PCI-DSS v4.0.1 requirements.</xccdf-1.2:description>
        <xccdf-1.2:reference>https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0_1.pdf</xccdf-1.2:reference>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_disable_post_pw_expiration" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_unique_id" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_unique_name" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_maximum_age_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_no_uid_except_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_all_shadowed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_last_change_is_in_past" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_dcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_lcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minlen" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_remember_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_remember_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_remember" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_max_life_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_warn_age_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_warn_age_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_root_gid_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_set_post_pw_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_tmout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_build_database" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_periodic_cron_checking" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmodat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchownat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fremovexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fsetxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lchown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lremovexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lsetxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_removexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_setxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rename" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_renameat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rmdir" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlink" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlinkat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_immutable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_faillock" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_lastlog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_tallylog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_mac_modification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_media_export" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_networkconfig_modification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_btmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_utmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events_wtmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_suid_privilege_function" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_sysadmin_actions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_adjtimex" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_clock_settime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_settimeofday" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_stime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_watch_localtime" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_sudo_log_events" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_audispd_syslog_plugin_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_admin_space_left_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_space_left" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_space_left_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_name_format" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_bios_enable_execution_restrictions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_run_as_chrony_user" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_specify_remote_server" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_firewalld_ports" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_backtraces" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_storage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_db_up_to_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_automount" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_automount_open" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_idle_activation_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_idle_delay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_delay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_mode_blank" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_session_idle_user_locks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_access_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_host_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_users_coredumps" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_display_login_attempts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_authselect" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_almalinux_gpgkey_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_pam_wheel_group_empty" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_root_password_configured" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_at_deny_not_exist" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_cron_deny_not_exist" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_group_ownership_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_at_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_daily" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_hourly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_monthly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_weekly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_issue_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_daily" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_hourly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_monthly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_weekly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_issue_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_at_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_allow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_daily" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_hourly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_monthly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_cron_weekly" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_issue_net" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_grub2_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_config" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_world_writable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_ungroupowned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_user_cfg" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firewalld_loopback_traffic_restricted" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firewalld_loopback_traffic_trusted" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_gid_passwd_group_same" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_gnome_gdm_disable_automatic_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_gnome_gdm_disable_guest_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_group_unique_id" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_group_unique_name" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_backlog_limit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_enable_selinux" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_install_PAE_kernel_on_x86-32" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_dccp_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_sctp_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_usb-storage_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_network_nmcli_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_network_sniffer_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_direct_root_logins" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_files_unowned_by_user" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_password_auth_for_systemaccounts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_shelllogin_for_systemaccounts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_aide_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_audispd-plugins_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_audit_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_chrony_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_cron_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_dhcp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_firewalld_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ftp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_libselinux_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_logrotate_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_net-snmp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_nftables_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_postfix_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sudo_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_xinetd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypbind_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_ypserv_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_postfix_network_listening_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rpm_verify_hashes" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rpm_verify_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_groupownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_securetty_root_login_console_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_security_patches_up_to_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_confinement_of_daemons" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_policytype" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_state" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_auditd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_avahi-daemon_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_chronyd_or_ntpd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_firewalld_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_nftables_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_rpcbind_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_rsyncd_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_firewalld_default_zone" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_ip6tables_default_rule" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_libuserconf" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_logindefs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_systemauth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_rhosts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_tcp_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_x11_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_do_not_permit_user_env" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_pam" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_limit_user_access" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_idle_timeout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_keepalive" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_login_grace_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_loglevel_verbose" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_max_auth_tries" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_max_sessions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_maxstartups" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_use_approved_ciphers" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_use_approved_macs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_use_strong_kex" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_add_use_pty" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_custom_logfile" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_require_authentication" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_require_reauthentication" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_suid_dumpable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_core_pattern" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_secure_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_echo_ignore_broadcasts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_ignore_bogus_error_responses" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_forward" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_syncookies" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_use_pam_wheel_group_for_su" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_wireless_disable_interfaces" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_389_ds" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_accounts-physical" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_acl_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_execution_selinux_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_file_modification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_kernel_module_loading" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_privileged_commands" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_base" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_bootloader-zipl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_certified-vendor" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_console_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_deprecated" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_cyrus-imapd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dns_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfsd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nginx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_squid" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_xwindows" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disk_partitioning" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_entropy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fapolicyd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_file_permissions_auditd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_fips" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gcc_plugin" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_remote_access_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_system_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gui_login_banner" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_http" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_imap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_journald" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kerberos" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kernel_build_config" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mounting_remote_filesystems" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ipsec" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ufw" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_clients" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_servers" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_partitions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_var_log_dir" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_within_important_dirs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_poisoning" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_policy_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_harden_os" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_cfg" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_proxy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_r_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_radius" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rng" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_root_paths" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rootfiles" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_accepting_remote_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_sending_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_selinux-booleans" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smart_card_login" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smb" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ssh_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd-ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_system-tools" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_talk" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_uefi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_usbguard" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_user_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_xwindows" selected="false"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_audit_backlog_limit" selector="8192"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_multiple_time_servers" selector="generic"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_admin_space_left_action" selector="single"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_space_left" selector="100MB"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_space_left_action" selector="email"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_name_format" selector="fqd"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" selector="90"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_password_warn_age_login_defs" selector="7"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_remember" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_remember" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_remember_control_flag" selector="requisite_or_required"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_dcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_lcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" selector="12"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_authselect_profile" selector="sssd"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" selector="10"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" selector="1800"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_tally2" selector="10"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_tally2_unlock_time" selector="1800"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm" selector="SHA512"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" selector="sha512"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_inactivity_timeout_value" selector="15_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_screensaver_lock_delay" selector="10_seconds"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_idle_timeout_value" selector="15_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_keepalive" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration" selector="90"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_system_crypto_policy" selector="default_policy"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_login_grace_time" selector="60"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_postfix_inet_interfaces" selector="loopback-only"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" selector="targeted"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_state" selector="enforcing"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_stig">
        <xccdf-1.2:version>V2R7</xccdf-1.2:version>
        <xccdf-1.2:title override="true">DISA STIG for AlmaLinux OS 8</xccdf-1.2:title>
        <xccdf-1.2:description override="true">This profile contains configuration checks that align to the
DISA STIG for AlmaLinux OS 8 V2R7.</xccdf-1.2:description>
        <xccdf-1.2:reference>https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux</xccdf-1.2:reference>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_disable_post_pw_expiration" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_password_pam_faillock_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_password_pam_faillock_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_password_selinux_faillock_dir" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_temp_expire_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_unique_id" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_authorized_local_users" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_have_homedir_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_maximum_age_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_minimum_age_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_no_uid_except_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_all_shadowed_sha512" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_minlen_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_dcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_dictcheck" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_difok" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_lcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxclassrepeat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxrepeat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minclass" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minlen" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ocredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwquality_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwquality_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_retry" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ucredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_max_life_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_min_life_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_dir" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_interval" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_silent" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_tmout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_interactive_users" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_home_paths_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_interactive_home_directory_defined" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_interactive_home_directory_exists" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_interactive_home_directory_on_separate_partition" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_users_home_files_groupownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_users_home_files_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_build_database" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_check_audit_tools" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_scan_notification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_verify_acls" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_verify_ext_attributes" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmodat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchownat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fremovexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fsetxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lchown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lremovexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lsetxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_removexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_setxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_etc_cron_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_chacl" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_chcon" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_semanage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_setfacl" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_setfiles" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_setsebool" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rename" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_renameat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rmdir" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlink" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlinkat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_immutable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_immutable_login_uids" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_delete" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_finit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_init" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_faillock" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_lastlog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_media_export" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_chage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_chsh" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_gpasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_kmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_mount" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_newgrp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_pam_timestamp_check" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_postdrop" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_postqueue" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_ssh_agent" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_ssh_keysign" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_su" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_umount" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_unix_chkpwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_unix_update" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_userhelper" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_usermod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_sudoers" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_sudoers_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_suid_privilege_function" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_creat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_ftruncate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_by_handle_at" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_openat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_truncate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_var_spool_cron" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_audispd_configure_sufficiently_large_partition" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_disk_error_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_disk_full_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_action_mail_acct" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_space_left_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_space_left_percentage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_local_events" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_log_format" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_name_format" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_overflow_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_banner_etc_issue" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_bios_enable_execution_restrictions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_client_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_configure_local_socket" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_no_chronyc_network" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_or_ntpd_set_maxpoll" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_server_directive" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_specify_remote_server" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_clean_components_post_updating" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_bind_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_firewalld_ports" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_libreswan_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_usbguard_auditbackend" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configured_firewalld_default_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_backtraces" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_storage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_banner_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_ctrlaltdel_reboot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_user_list" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_lock_screen_on_smartcard_removal" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_login_banner_text" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_idle_delay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_delay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_locked" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_user_locks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_session_idle_user_locks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_group_ownership_library_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_ownership_library_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_permissions_library_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_root_owned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_system_owned_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_group_ownership_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_ownership_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_burstaction" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_reboot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_users_coredumps" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disallow_bypass_password_sudo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_authselect" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_gpgcheck_for_all_repositories" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_encrypt_partitions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_almalinux_gpgkey_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_epel_repos_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_fapolicy_default_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_audit_tools_group_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_audit_tools_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_audit_tools_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_group_ownership_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_var_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_var_log_messages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_home_directories" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_system_commands_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_var_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_var_log_messages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_binary_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_library_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_var_log_audit_stig" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permission_user_init_files_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_binary_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_audit_auditd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_audit_rulesd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_home_directories" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_library_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_ungroupowned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_var_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_var_log_messages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_fips_crypto_subpolicy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_fips_custom_stig_sub_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firewalld-backend" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_gnome_gdm_disable_automatic_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_admin_username" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_backlog_limit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_init_on_free" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_page_poison_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_pti_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_uefi_admin_username" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_uefi_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_vsyscall_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_install_smartcard_packages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_installed_OS_is_vendor_supported" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kerberos_disable_no_keytab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_atm_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_bluetooth_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_can_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_cramfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_firewire-core_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_sctp_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_tipc_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_usb-storage_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_uvcvideo_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_logind_session_timeout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_boot_efi_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_boot_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_nodev_nonroot_local_partitions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_nodev_remote_filesystems" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_nodev_removable_partitions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_noexec_remote_filesystems" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_noexec_removable_partitions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_nosuid_remote_filesystems" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_nosuid_removable_partitions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_network_configure_name_resolution" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_network_sniffer_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_files_unowned_by_user" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_host_based_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_user_host_based_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt-addon-ccpp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt-addon-kerneloops_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt-cli_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt-plugin-sosreport_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_aide_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_audit_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_crypto-policies_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_fapolicyd_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_firewalld_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_gssproxy_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_iprutils_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_krb5-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_krb5-workstation_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_libreport-plugin-logger_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_libreport-plugin-rhtsupport_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_mailx_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_opensc_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_openssh-server_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_policycoreutils_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_postfix_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_python3-abrt-addon_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rng-tools_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsyslog-gnutls_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsyslog_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sendmail_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tuned_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_usbguard_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_vsftpd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_home" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_postfix_client_configure_mail_alias_postmaster" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_postfix_prevent_unrestricted_relay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_require_emergency_target_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_require_singleuser_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_root_permissions_syslibrary_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rootfiles_configured" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_cron_logging" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_encrypt_offload_actionsendstreamdriverauthmode" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_encrypt_offload_actionsendstreamdrivermode" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_encrypt_offload_defaultnetstreamdriver" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_remote_access_monitoring" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_remote_loghost" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_security_patches_up_to_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_context_elevation_for_sudo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_policytype" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_state" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_user_login_roles" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_auditd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_autofs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_debug-shell_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_fapolicyd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_firewalld_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_kdump_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_rngd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_rsyslog_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_sshd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_systemd-coredump_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_usbguard_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_firewalld_default_zone" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_logindefs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_passwordauth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_systemauth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_min_rounds_logindefs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ssh_keys_passphrase_protected" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_kerb_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_user_known_hosts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_x11_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_do_not_permit_user_env" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_strictmodes" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_warning_banner" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_print_last_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_rekey_limit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_idle_timeout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_keepalive" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_use_strong_rng" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_x11_use_localhost" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_certificate_verification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_enable_certmap" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_enable_smartcards" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_has_trust_anchor" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_offline_cred_expiration" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_nopasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_require_reauthentication" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_restrict_privilege_elevation_to_authorized" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudoers_default_includedir" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudoers_validate_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_hardlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_symlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_core_pattern" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kexec_load_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_perf_event_paranoid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_unprivileged_bpf_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_yama_ptrace_scope" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_core_bpf_jit_harden" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_echo_ignore_broadcasts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_user_max_user_namespaces_no_remediation" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_tftp_uses_secure_mode_systemd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_usbguard_generate_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_wireless_disable_interfaces" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_xwindows_remove_packages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_xwindows_runlevel_target" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_389_ds" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_time_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_bootloader-zipl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_console_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_cron_and_at" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_deprecated" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disable_avahi_group" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_cyrus-imapd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dns_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfsd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nginx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_snmp_service" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_squid" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_entropy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gcc_plugin" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_media_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_remote_access_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_http" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_imap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_inetd_and_xinetd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_journald" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kernel_build_config" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_log_rotation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ipsec" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-iptables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-nftables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ufw" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_servers" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nis" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_important_account_files" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_policy_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_proxy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_radius" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_restrict_at_cron_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_root_paths" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rpm_verification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_accepting_remote_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_selinux-booleans" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smb" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd-ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_talk" selected="false"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_system_crypto_policy" selector="fips_stig"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_logind_session_timeout" selector="10_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_screensaver_lock_delay" selector="5_seconds"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sudo_timestamp_timeout" selector="always_prompt"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_audit_backlog_limit" selector="8192"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_name_format" selector="stig"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_tmout" selector="10_min"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_user_initialization_files_regex" selector="all_dotfiles"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_rekey_limit_size" selector="1G"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_rekey_limit_time" selector="1hour"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" selector="077"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_difok" selector="8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxrepeat" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm" selector="SHA512"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" selector="sha512"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxclassrepeat" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minclass" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_minimum_age_login_defs" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_max_concurrent_login_sessions" selector="10"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_remember" selector="5"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_remember_control_flag" selector="requisite_or_required"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_state" selector="enforcing"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" selector="targeted"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_min_rounds_login_defs" selector="100000"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" selector="15"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_ocredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_dcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_dictcheck" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_ucredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_lcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_retry" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_keepalive" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_approved_macs" selector="stig_extended"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_approved_ciphers" selector="stig_extended"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_idle_timeout_value" selector="10_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_authorized_local_users_regex" selector="rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_fail_interval" selector="900"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" selector="never"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_size" selector="1G"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_time" selector="1hour"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_fail_delay" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration" selector="35"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_action_mail_acct" selector="root"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_time_service_set_maxpoll" selector="18_hours"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" selector="60"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_space_left_percentage" selector="25pc"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_space_left_action" selector="email"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_disk_error_action" selector="rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_max_log_file_action" selector="syslog"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_disk_full_action" selector="rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sssd_certificate_verification_digest_function" selector="sha1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_login_banner_text" selector="dod_banners"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_login_banner_contents" selector="dod_default"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_dconf_login_banner_text" selector="dod_banners"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_dconf_login_banner_contents" selector="dod_default"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_authselect_profile" selector="sssd"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_multiple_time_servers" selector="stig"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_stig_gui">
        <xccdf-1.2:version>V2R7</xccdf-1.2:version>
        <xccdf-1.2:title override="true">DISA STIG with GUI for AlmaLinux OS 8</xccdf-1.2:title>
        <xccdf-1.2:description override="true">This profile contains configuration checks that align to the
DISA STIG with GUI for AlmaLinux OS 8 V2R7.

Warning: The installation and use of a Graphical User Interface (GUI)
increases your attack vector and decreases your overall security posture. If
your Information Systems Security Officer (ISSO) lacks a documented operational
requirement for a graphical user interface, please consider using the
standard DISA STIG for AlmaLinux OS 8 profile.</xccdf-1.2:description>
        <xccdf-1.2:reference>https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux</xccdf-1.2:reference>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_disable_post_pw_expiration" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_password_pam_faillock_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_password_pam_faillock_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_password_selinux_faillock_dir" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_temp_expire_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_account_unique_id" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_authorized_local_users" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_have_homedir_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_maximum_age_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_minimum_age_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_no_uid_except_zero" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_all_shadowed_sha512" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_minlen_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_dcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_dictcheck" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_difok" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_lcredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxclassrepeat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxrepeat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minclass" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minlen" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ocredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwquality_password_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwquality_system_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_retry" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ucredit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_max_life_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_min_life_existing" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_dir" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_interval" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_silent" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_tmout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_login_defs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_interactive_users" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_home_paths_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_interactive_home_directory_defined" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_interactive_home_directory_exists" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_user_interactive_home_directory_on_separate_partition" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_users_home_files_groupownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_accounts_users_home_files_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_build_database" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_check_audit_tools" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_scan_notification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_verify_acls" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_aide_verify_ext_attributes" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmodat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchownat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fremovexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fsetxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lchown" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lremovexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lsetxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_removexattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_setxattr" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_etc_cron_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_chacl" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_chcon" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_semanage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_setfacl" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_setfiles" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_setsebool" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rename" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_renameat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rmdir" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlink" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlinkat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_immutable" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_immutable_login_uids" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_delete" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_finit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_init" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_faillock" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_lastlog" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_media_export" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_chage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_chsh" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_crontab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_gpasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_kmod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_mount" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_newgrp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_pam_timestamp_check" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_postdrop" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_postqueue" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_ssh_agent" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_ssh_keysign" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_su" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_umount" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_unix_chkpwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_unix_update" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_userhelper" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_usermod" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_sudoers" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_sudoers_d" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_suid_privilege_function" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_creat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_ftruncate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_by_handle_at" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_openat" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_truncate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_gshadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_opasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_audit_rules_var_spool_cron" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_audispd_configure_sufficiently_large_partition" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_disk_error_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_disk_full_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_action_mail_acct" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_space_left_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_space_left_percentage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_local_events" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_log_format" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_name_format" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_auditd_overflow_action" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_banner_etc_issue" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_bios_enable_execution_restrictions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_client_only" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_configure_local_socket" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_no_chronyc_network" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_or_ntpd_set_maxpoll" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_server_directive" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_chronyd_specify_remote_server" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_clean_components_post_updating" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_bind_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_firewalld_ports" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_libreswan_crypto_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configure_usbguard_auditbackend" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_configured_firewalld_default_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_backtraces" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_coredump_disable_storage" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_banner_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_ctrlaltdel_reboot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_user_list" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_lock_screen_on_smartcard_removal" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_login_banner_text" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_idle_delay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_delay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_locked" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_user_locks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_session_idle_user_locks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_group_ownership_library_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_ownership_library_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_permissions_library_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_root_owned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_system_owned_group" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_group_ownership_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_ownership_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_burstaction" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_reboot" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disable_users_coredumps" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_disallow_bypass_password_sudo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_authselect" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_enable_gpgcheck_for_all_repositories" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_encrypt_partitions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_almalinux_gpgkey_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_epel_repos_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_fapolicy_default_deny" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_audit_tools_group_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_audit_tools_ownership" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_audit_tools_permissions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_group_ownership_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_var_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_var_log_messages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_home_directories" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_system_commands_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_var_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_owner_var_log_messages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_binary_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_library_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_ownership_var_log_audit_stig" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permission_user_init_files_root" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_binary_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_audit_auditd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_audit_rulesd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_home_directories" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_library_dirs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_private_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_pub_key" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_ungroupowned" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_var_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_file_permissions_var_log_messages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_fips_crypto_subpolicy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_fips_custom_stig_sub_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_firewalld-backend" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_gnome_gdm_disable_automatic_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_admin_username" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_backlog_limit_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_init_on_free" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_page_poison_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_pti_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_uefi_admin_username" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_uefi_password" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_grub2_vsyscall_argument" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_install_smartcard_packages" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_installed_OS_is_vendor_supported" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kerberos_disable_no_keytab" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_atm_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_bluetooth_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_can_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_cramfs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_firewire-core_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_sctp_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_tipc_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_usb-storage_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_kernel_module_uvcvideo_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_boot_efi_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_boot_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_nodev_nonroot_local_partitions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_nodev_remote_filesystems" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_nodev_removable_partitions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_noexec_remote_filesystems" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_noexec_removable_partitions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_nosuid_remote_filesystems" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_nosuid_removable_partitions" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_log_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nodev" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_noexec" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nosuid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_network_configure_name_resolution" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_network_sniffer_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords_etc_shadow" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_files_unowned_by_user" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_host_based_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_no_user_host_based_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt-addon-ccpp_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt-addon-kerneloops_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt-cli_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt-plugin-sosreport_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_abrt_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_aide_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_audit_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_crypto-policies_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_fapolicyd_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_firewalld_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_gssproxy_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_iprutils_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_krb5-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_krb5-workstation_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_libreport-plugin-logger_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_mailx_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_opensc_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_openssh-server_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_policycoreutils_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_postfix_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_python3-abrt-addon_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rng-tools_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsyslog-gnutls_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_rsyslog_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_sendmail_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_telnet-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tftp-server_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_tuned_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_usbguard_installed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_package_vsftpd_removed" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_home" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log_audit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_tmp" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_postfix_client_configure_mail_alias_postmaster" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_postfix_prevent_unrestricted_relay" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_require_emergency_target_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_require_singleuser_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_root_permissions_syslibrary_files" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rootfiles_configured" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_cron_logging" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_encrypt_offload_actionsendstreamdriverauthmode" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_encrypt_offload_actionsendstreamdrivermode" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_encrypt_offload_defaultnetstreamdriver" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_remote_access_monitoring" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_rsyslog_remote_loghost" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_security_patches_up_to_date" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_context_elevation_for_sudo" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_policytype" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_state" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_selinux_user_login_roles" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_auditd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_autofs_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_debug-shell_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_fapolicyd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_firewalld_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_kdump_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_rngd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_rsyslog_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_sshd_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_systemd-coredump_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_service_usbguard_enabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_firewalld_default_zone" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_logindefs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_passwordauth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_systemauth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_min_rounds_logindefs" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_ssh_keys_passphrase_protected" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_empty_passwords" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_kerb_auth" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_user_known_hosts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_x11_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_do_not_permit_user_env" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_strictmodes" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_warning_banner" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_print_last_log" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_rekey_limit" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_idle_timeout" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_set_keepalive" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_use_strong_rng" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sshd_x11_use_localhost" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_certificate_verification" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_enable_certmap" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_enable_smartcards" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_has_trust_anchor" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sssd_offline_cred_expiration" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_nopasswd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_require_reauthentication" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudo_restrict_privilege_elevation_to_authorized" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudoers_default_includedir" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sudoers_validate_passwd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_hardlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_symlinks" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_core_pattern" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kexec_load_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_perf_event_paranoid" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_unprivileged_bpf_disabled" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_yama_ptrace_scope" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_core_bpf_jit_harden" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_rp_filter" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_send_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_echo_ignore_broadcasts" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_forwarding" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_redirects" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_source_route" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_sysctl_user_max_user_namespaces_no_remediation" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_tftp_uses_secure_mode_systemd" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_usbguard_generate_policy" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_rule_wireless_disable_interfaces" selected="true"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_389_ds" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_audit_time_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_bootloader-zipl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_console_screen_locking" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_cron_and_at" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_deprecated" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disable_avahi_group" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_cyrus-imapd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dns_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_dovecot" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfs_services" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nfsd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_nginx" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_samba" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_snmp_service" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_squid" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_disabling_xwindows" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_entropy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gcc_plugin" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_media_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_gnome_remote_access_settings" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_http" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_imap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_inetd_and_xinetd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_activation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_journald" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_kernel_build_config" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_log_rotation" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_endpoint_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ipsec" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-iptables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-nftables" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_network-ufw" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_servers" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_nis" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_client" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_permissions_important_account_files" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_policy_rules" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_printing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_proxy" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_radius" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_restrict_at_cron_users" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_root_paths" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rpm_verification" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_rsyslog_accepting_remote_messages" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_selinux-booleans" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_smb" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_sssd-ldap" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_talk" selected="false"/>
        <xccdf-1.2:select idref="xccdf_org.ssgproject.content_group_xwindows" selected="false"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_system_crypto_policy" selector="fips_stig"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_logind_session_timeout" selector="10_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_screensaver_lock_delay" selector="5_seconds"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sudo_timestamp_timeout" selector="always_prompt"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_audit_backlog_limit" selector="8192"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_name_format" selector="stig"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_tmout" selector="10_min"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_user_initialization_files_regex" selector="all_dotfiles"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_rekey_limit_size" selector="1G"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_rekey_limit_time" selector="1hour"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" selector="077"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_difok" selector="8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxrepeat" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm" selector="SHA512"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" selector="sha512"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxclassrepeat" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minclass" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_minimum_age_login_defs" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_max_concurrent_login_sessions" selector="10"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_remember" selector="5"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_remember_control_flag" selector="requisite_or_required"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_state" selector="enforcing"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" selector="targeted"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_hashing_min_rounds_login_defs" selector="100000"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" selector="15"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_ocredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_dcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_dictcheck" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_ucredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_lcredit" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_retry" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sshd_set_keepalive" selector="1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_approved_macs" selector="stig_extended"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_approved_ciphers" selector="stig_extended"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_sshd_idle_timeout_value" selector="10_minutes"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_authorized_local_users_regex" selector="rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" selector="3"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_fail_interval" selector="900"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" selector="never"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_size" selector="1G"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_time" selector="1hour"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_fail_delay" selector="4"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration" selector="35"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_action_mail_acct" selector="root"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_time_service_set_maxpoll" selector="18_hours"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" selector="60"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_space_left_percentage" selector="25pc"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_space_left_action" selector="email"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_disk_error_action" selector="rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_max_log_file_action" selector="syslog"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_disk_full_action" selector="rhel8"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_sssd_certificate_verification_digest_function" selector="sha1"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_login_banner_text" selector="dod_banners"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_login_banner_contents" selector="dod_default"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_dconf_login_banner_text" selector="dod_banners"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_dconf_login_banner_contents" selector="dod_default"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_authselect_profile" selector="sssd"/>
        <xccdf-1.2:refine-value idref="xccdf_org.ssgproject.content_value_var_multiple_time_servers" selector="stig"/>
      </xccdf-1.2:Profile>
      <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_system">
        <xccdf-1.2:title>System Settings</xccdf-1.2:title>
        <xccdf-1.2:description>Contains rules that check correct system settings.</xccdf-1.2:description>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_software">
          <xccdf-1.2:title>Installing and Maintaining Software</xccdf-1.2:title>
          <xccdf-1.2:description>The following sections contain information on
security-relevant choices during the initial operating system
installation process and the setup of software
updates.</xccdf-1.2:description>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_prefer_64bit_os" selected="false" severity="medium">
            <xccdf-1.2:title>Prefer to use a 64-bit Operating System when supported</xccdf-1.2:title>
            <xccdf-1.2:description>Prefer installation of 64-bit operating systems when the CPU supports it.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation besides installing a 64-bit operating system.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R1</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Use of a 64-bit operating system offers a few advantages, like a larger address space range for
Address Space Layout Randomization (ASLR) and systematic presence of No eXecute and Execute Disable (NX/XD) protection bits.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-prefer_64bit_os:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-prefer_64bit_os_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_integrity">
            <xccdf-1.2:title>System and Software Integrity</xccdf-1.2:title>
            <xccdf-1.2:description>System and software integrity can be gained by installing antivirus, increasing
system encryption strength with FIPS, verifying installed software, enabling SELinux,
installing an Intrusion Prevention System, etc. However, installing or enabling integrity
checking tools cannot <html:i>prevent</html:i> intrusions, but they can detect that an intrusion
may have occurred. Requirements for integrity checking may be highly dependent on
the environment in which the system will be used. Snapshot-based approaches such
as AIDE may induce considerable overhead in the presence of frequent software updates.</xccdf-1.2:description>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_software-integrity">
              <xccdf-1.2:title>Software Integrity Checking</xccdf-1.2:title>
              <xccdf-1.2:description>Both the AIDE (Advanced Intrusion Detection Environment)
software and the RPM package management system provide
mechanisms for verifying the integrity of installed software.
AIDE uses snapshots of file metadata (such as hashes) and compares these
to current system files in order to detect changes.
<html:br/><html:br/>
The RPM package management system can conduct integrity
checks by comparing information in its metadata database with
files installed on the system.</xccdf-1.2:description>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_aide_scan_notification_email" interactive="true" type="string">
                <xccdf-1.2:title>Integrity Scan Notification Email Address</xccdf-1.2:title>
                <xccdf-1.2:description>Specify the email address for designated personnel if baseline
configurations are changed in an unauthorized manner.</xccdf-1.2:description>
                <xccdf-1.2:value>root@localhost</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_rpm_verification">
                <xccdf-1.2:title>Verify Integrity with RPM</xccdf-1.2:title>
                <xccdf-1.2:description>The RPM package management system includes the ability
to verify the integrity of installed packages by comparing the
installed files with information about the files taken from the
package metadata stored in the RPM database. Although an attacker
could corrupt the RPM database (analogous to attacking the AIDE
database as described above), this check can still reveal
modification of important files. To list which files on the system differ from what is expected by the RPM database:
<html:pre>$ rpm -qVa</html:pre>
See the man page for <html:code>rpm</html:code> to see a complete explanation of each column.</xccdf-1.2:description>
                <xccdf-1.2:platform idref="#not_bootc"/>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rpm_verify_hashes" selected="false" severity="high">
                  <xccdf-1.2:title>Verify File Hashes with RPM</xccdf-1.2:title>
                  <xccdf-1.2:description>Without cryptographic integrity protections, system executables and files can be altered by
unauthorized users without detection. The RPM package management system can check the hashes
of installed software packages, including many that are important to system security.

To verify that the cryptographic hash of system files and commands matches vendor values, run
the following command to list which files on the system have hashes that differ from what is
expected by the RPM database:
<html:pre>$ rpm -Va --noconfig | grep '^..5'</html:pre>

If the file was not expected to change, investigate the cause of the change using audit logs
or other means. The package can then be reinstalled to restore the file. Run the following
command to determine which package owns the file:
<html:pre>$ rpm -qf <html:i>FILENAME</html:i></html:pre>

The package can be reinstalled from a yum repository using the command:
<html:pre>$ sudo yum reinstall <html:i>PACKAGENAME</html:i></html:pre>

Alternatively, the package can be reinstalled from trusted media using the command:
<html:pre>$ sudo rpm -Uvh <html:i>PACKAGENAME</html:i></html:pre></xccdf-1.2:description>
                  <xccdf-1.2:warning category="general">This rule can take a long time to perform the check and might consume a considerable
amount of resources depending on the number of packages present on the system. It is not a
problem in most cases, but especially systems with a large number of installed packages
can be affected.</xccdf-1.2:warning>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI06.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(c)(1)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(c)(2)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(i)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(d)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(c)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7(1)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7(6)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9(3)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-11.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">11.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>The hashes of important files like system executables should match the
information given by the RPM database. Executables with erroneous hashes could
be a sign of nefarious activity on the system.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix id="rpm_verify_hashes" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ); then

# Find which files have incorrect hash (not in /etc, because of the system related config files) and then get files names
files_with_incorrect_hash="$(rpm -Va --noconfig | grep -E '^..5' | awk '{print $NF}' )"

if [ -n "$files_with_incorrect_hash" ]; then
    # From files names get package names and change newline to space, because rpm writes each package to new line
    packages_to_reinstall="$(rpm -qf $files_with_incorrect_hash | tr '\n' ' ')"

    
    yum reinstall -y $packages_to_reinstall
    
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="high" disruption="medium" id="rpm_verify_hashes" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.3.8
  - NIST-800-171-3.4.1
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(c)
  - NIST-800-53-CM-6(d)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - NIST-800-53-SI-7(6)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - high_complexity
  - high_severity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy
  - rpm_verify_hashes

- name: 'Set fact: Package manager reinstall command'
  ansible.builtin.set_fact:
    package_manager_reinstall_cmd: yum reinstall -y
  when:
  - not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline )
  - ansible_distribution in [ "Fedora", "RedHat", "CentOS", "OracleLinux", "AlmaLinux"
    ]
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.3.8
  - NIST-800-171-3.4.1
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(c)
  - NIST-800-53-CM-6(d)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - NIST-800-53-SI-7(6)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - high_complexity
  - high_severity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy
  - rpm_verify_hashes

- name: 'Set fact: Package manager reinstall command (zypper)'
  ansible.builtin.set_fact:
    package_manager_reinstall_cmd: zypper in -f -y
  when:
  - not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline )
  - ansible_distribution == "SLES"
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.3.8
  - NIST-800-171-3.4.1
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(c)
  - NIST-800-53-CM-6(d)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - NIST-800-53-SI-7(6)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - high_complexity
  - high_severity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy
  - rpm_verify_hashes

- name: Read files with incorrect hash
  ansible.builtin.command: rpm -Va --nodeps --nosize --nomtime --nordev --nocaps --nolinkto
    --nouser --nogroup --nomode --noghost --noconfig
  register: files_with_incorrect_hash
  changed_when: false
  failed_when: files_with_incorrect_hash.rc &gt; 1
  check_mode: false
  when:
  - not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline )
  - (package_manager_reinstall_cmd is defined)
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.3.8
  - NIST-800-171-3.4.1
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(c)
  - NIST-800-53-CM-6(d)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - NIST-800-53-SI-7(6)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - high_complexity
  - high_severity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy
  - rpm_verify_hashes

- name: Create list of packages
  ansible.builtin.command: rpm -qf "{{ item }}"
  with_items: '{{ files_with_incorrect_hash.stdout_lines | map(''regex_findall'',
    ''^[.]+[5]+.* (\/.*)'', ''\1'') | map(''join'') | select(''match'', ''(\/.*)'')
    | list | unique }}'
  register: list_of_packages
  changed_when: false
  check_mode: false
  when:
  - not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline )
  - files_with_incorrect_hash.stdout_lines is defined
  - (files_with_incorrect_hash.stdout_lines | length &gt; 0)
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.3.8
  - NIST-800-171-3.4.1
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(c)
  - NIST-800-53-CM-6(d)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - NIST-800-53-SI-7(6)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - high_complexity
  - high_severity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy
  - rpm_verify_hashes

- name: Reinstall packages of files with incorrect hash
  ansible.builtin.command: '{{ package_manager_reinstall_cmd }} ''{{ item }}'''
  with_items: '{{ list_of_packages.results | map(attribute=''stdout_lines'') | list
    | unique }}'
  when:
  - not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline )
  - files_with_incorrect_hash.stdout_lines is defined
  - (package_manager_reinstall_cmd is defined and (files_with_incorrect_hash.stdout_lines
    | length &gt; 0))
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.3.8
  - NIST-800-171-3.4.1
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(c)
  - NIST-800-53-CM-6(d)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - NIST-800-53-SI-7(6)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - high_complexity
  - high_severity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy
  - rpm_verify_hashes
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rpm_verify_hashes:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rpm_verify_hashes_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rpm_verify_ownership" selected="false" severity="high">
                  <xccdf-1.2:title>Verify and Correct Ownership with RPM</xccdf-1.2:title>
                  <xccdf-1.2:description>The RPM package management system can check file ownership permissions of installed software
packages, including many that are important to system security. After locating a file with
incorrect permissions, which can be found with:
<html:pre>rpm -Va | awk '{ if (substr($0,6,1)=="U" || substr($0,7,1)=="G") print $NF }'</html:pre>
run the following command to determine which package owns it:
<html:pre>$ rpm -qf <html:i>FILENAME</html:i></html:pre>
Next, run the following command to reset its permissions to the correct values:
<html:pre>$ sudo rpm --restore <html:i>PACKAGENAME</html:i></html:pre></xccdf-1.2:description>
                  <xccdf-1.2:warning category="general">Profiles may require that specific files be owned by root while the default owner defined
by the vendor is different. Such files will be reported as a finding and need to be
evaluated according to your policy and deployment environment.</xccdf-1.2:warning>
                  <xccdf-1.2:warning category="general">This rule can take a long time to perform the check and might consume a considerable
amount of resources depending on the number of packages present on the system. It is not a
problem in most cases, but especially systems with a large number of installed packages
can be affected.</xccdf-1.2:warning>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(d)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(c)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7(1)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7(6)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9(3)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-11.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000256-GPOS-00097</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000257-GPOS-00098</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000278-GPOS-00108</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">11.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Ownership of binaries and configuration files that is incorrect could allow an unauthorized
user to gain privileges that they should not have. The ownership set by the vendor should be
maintained. Any deviations from this baseline should be investigated.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix complexity="high" disruption="medium" id="rpm_verify_ownership" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ); then

# Declare array to hold set of RPM packages we need to correct permissions for
declare -A SETPERMS_RPM_DICT

# Create a list of files on the system having permissions different from what
# is expected by the RPM database
readarray -t FILES_WITH_INCORRECT_PERMS &lt; &lt;(rpm -Va --nofiledigest | awk '{ if (substr($0,6,1)=="U" || substr($0,7,1)=="G") print $NF }')

for FILE_PATH in "${FILES_WITH_INCORRECT_PERMS[@]}"
do
        RPM_PACKAGE=$(rpm -qf "$FILE_PATH")
	# Use an associative array to store packages as it's keys, not having to care about duplicates.
	SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1
done

# For each of the RPM packages left in the list -- reset its permissions to the
# correct values
for RPM_PACKAGE in "${!SETPERMS_RPM_DICT[@]}"
do
        rpm --restore "${RPM_PACKAGE}"
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="high" disruption="medium" id="rpm_verify_ownership" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.3.8
  - NIST-800-171-3.4.1
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(c)
  - NIST-800-53-CM-6(d)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - NIST-800-53-SI-7(6)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - high_complexity
  - high_severity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy
  - rpm_verify_ownership

- name: Read list of files with incorrect ownership
  ansible.builtin.command: rpm -Va --nodeps --nosignature --nofiledigest --nosize
    --nomtime --nordev --nocaps --nolinkto --nomode
  register: files_with_incorrect_ownership
  failed_when: files_with_incorrect_ownership.rc &gt; 1
  changed_when: false
  check_mode: false
  when: not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline )
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.3.8
  - NIST-800-171-3.4.1
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(c)
  - NIST-800-53-CM-6(d)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - NIST-800-53-SI-7(6)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - high_complexity
  - high_severity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy
  - rpm_verify_ownership

- name: Create list of packages
  ansible.builtin.command: rpm -qf "{{ item }}"
  with_items: '{{ files_with_incorrect_ownership.stdout_lines | map(''regex_findall'',
    ''^[.]+[U|G]+.* (\/.*)'', ''\1'') | map(''join'') | select(''match'', ''(\/.*)'')
    | list | unique }}'
  register: list_of_packages
  changed_when: false
  check_mode: false
  when:
  - not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline )
  - (files_with_incorrect_ownership.stdout_lines | length &gt; 0)
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.3.8
  - NIST-800-171-3.4.1
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(c)
  - NIST-800-53-CM-6(d)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - NIST-800-53-SI-7(6)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - high_complexity
  - high_severity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy
  - rpm_verify_ownership

- name: Correct file ownership with RPM
  ansible.builtin.command: rpm --restore '{{ item }}'
  with_items: '{{ list_of_packages.results | map(attribute=''stdout_lines'') | list
    | unique }}'
  when:
  - not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline )
  - (files_with_incorrect_ownership.stdout_lines | length &gt; 0)
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.3.8
  - NIST-800-171-3.4.1
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(c)
  - NIST-800-53-CM-6(d)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - NIST-800-53-SI-7(6)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - high_complexity
  - high_severity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy
  - rpm_verify_ownership
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rpm_verify_ownership:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rpm_verify_ownership_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rpm_verify_permissions" selected="false" severity="high">
                  <xccdf-1.2:title>Verify and Correct File Permissions with RPM</xccdf-1.2:title>
                  <xccdf-1.2:description>The RPM package management system can check file access permissions of installed software
packages, including many that are important to system security. Verify that the file
permissions of system files and commands match vendor values. Check the file permissions with
the following command:
<html:pre>$ sudo rpm -Va | awk '{ if (substr($0,2,1)=="M") print $NF }'</html:pre>
Output indicates files that do not match vendor defaults.

After locating a file with incorrect permissions, run the following command to determine which
package owns it:
<html:pre>$ rpm -qf <html:i>FILENAME</html:i></html:pre>
<html:br/>
Next, run the following command to reset its permissions to the correct values:
<html:pre>$ sudo rpm --restore <html:i>PACKAGENAME</html:i></html:pre></xccdf-1.2:description>
                  <xccdf-1.2:warning category="general">Profiles may require that specific files have stricter file permissions than defined by
the vendor. Such files will be reported as a finding and need to be evaluated according to
your policy and deployment environment.</xccdf-1.2:warning>
                  <xccdf-1.2:warning category="general">This rule can take a long time to perform the check and might consume a considerable
amount of resources depending on the number of packages present on the system. It is not a
problem in most cases, but especially systems with a large number of installed packages
can be affected.</xccdf-1.2:warning>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(c)(1)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(c)(2)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(i)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(d)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(c)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7(1)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7(6)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9(3)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-11.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000256-GPOS-00097</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000257-GPOS-00098</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000258-GPOS-00099</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000278-GPOS-00108</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">11.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Permissions on system binaries and configuration files that are too generous could allow an
unauthorized user to gain privileges that they should not have. The permissions set by the
vendor should be maintained. Any deviations from this baseline should be investigated.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix complexity="high" disruption="medium" id="rpm_verify_permissions" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ); then

# Declare array to hold set of RPM packages we need to correct permissions for
declare -A SETPERMS_RPM_DICT

# Create a list of files on the system having permissions different from what
# is expected by the RPM database
readarray -t FILES_WITH_INCORRECT_PERMS &lt; &lt;(rpm -Va --nofiledigest | awk '{ if (substr($0,2,1)=="M") print $NF }')

for FILE_PATH in "${FILES_WITH_INCORRECT_PERMS[@]}"
do
        # NOTE: some files maybe controlled by more then one package
        readarray -t RPM_PACKAGES &lt; &lt;(rpm -qf "${FILE_PATH}")
        for RPM_PACKAGE in "${RPM_PACKAGES[@]}"
        do
                # Use an associative array to store packages as it's keys, not having to care about duplicates.
                SETPERMS_RPM_DICT["$RPM_PACKAGE"]=1
        done
done

# For each of the RPM packages left in the list -- reset its permissions to the
# correct values
for RPM_PACKAGE in "${!SETPERMS_RPM_DICT[@]}"
do
	rpm --restore "${RPM_PACKAGE}"
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="high" disruption="medium" id="rpm_verify_permissions" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.3.8
  - NIST-800-171-3.4.1
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(c)
  - NIST-800-53-CM-6(d)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - NIST-800-53-SI-7(6)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - high_complexity
  - high_severity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy
  - rpm_verify_permissions

- name: Read list of files with incorrect permissions
  ansible.builtin.command: rpm -Va --nodeps --nosignature --nofiledigest --nosize
    --nomtime --nordev --nocaps --nolinkto --nouser --nogroup
  register: files_with_incorrect_permissions
  failed_when: files_with_incorrect_permissions.rc &gt; 1
  changed_when: false
  check_mode: false
  when: not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline )
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.3.8
  - NIST-800-171-3.4.1
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(c)
  - NIST-800-53-CM-6(d)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - NIST-800-53-SI-7(6)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - high_complexity
  - high_severity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy
  - rpm_verify_permissions

- name: Create list of packages
  ansible.builtin.command: rpm -qf "{{ item }}"
  with_items: '{{ files_with_incorrect_permissions.stdout_lines | map(''regex_findall'',
    ''^[.]+[M]+.* (\/.*)'', ''\1'') | map(''join'') | select(''match'', ''(\/.*)'')
    | list | unique }}'
  register: list_of_packages
  changed_when: false
  check_mode: false
  when:
  - not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline )
  - (files_with_incorrect_permissions.stdout_lines | length &gt; 0)
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.3.8
  - NIST-800-171-3.4.1
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(c)
  - NIST-800-53-CM-6(d)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - NIST-800-53-SI-7(6)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - high_complexity
  - high_severity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy
  - rpm_verify_permissions

- name: Correct file permissions with RPM
  ansible.builtin.command: rpm --restore '{{ item }}'
  with_items: '{{ list_of_packages.results | map(attribute=''stdout_lines'') | list
    | unique }}'
  when:
  - not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline )
  - (files_with_incorrect_permissions.stdout_lines | length &gt; 0)
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.3.8
  - NIST-800-171-3.4.1
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(c)
  - NIST-800-53-CM-6(d)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - NIST-800-53-SI-7(6)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - high_complexity
  - high_severity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy
  - rpm_verify_permissions
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rpm_verify_permissions:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rpm_verify_permissions_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
              </xccdf-1.2:Group>
              <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_aide">
                <xccdf-1.2:title>Verify Integrity with AIDE</xccdf-1.2:title>
                <xccdf-1.2:description>AIDE conducts integrity checks by comparing information about
files with previously-gathered information. Ideally, the AIDE database is
created immediately after initial system configuration, and then again after any
software update.  AIDE is highly configurable, with further configuration
information located in <html:code>/usr/share/doc/aide-<html:i>VERSION</html:i></html:code>.</xccdf-1.2:description>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_aide_installed" selected="false" severity="medium">
                  <xccdf-1.2:title>Install AIDE</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>aide</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install aide</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI01.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI02.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI06.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS04.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-11.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000445-GPOS-00199</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R76</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R79</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1034</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1288</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1341</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1417</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">11.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010359</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-251710r958944_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>The AIDE package must be installed if it is to be available for integrity checking.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_aide_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "aide" ; then
    yum install -y "aide"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_aide_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.10.1.3
  - DISA-STIG-RHEL-08-010359
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_aide_installed

- name: Ensure aide is installed
  ansible.builtin.package:
    name: aide
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.3
  - DISA-STIG-RHEL-08-010359
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_aide_installed
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_aide_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_aide

class install_aide {
  package { 'aide':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_aide_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=aide
</xccdf-1.2:fix>
                  <xccdf-1.2:fix id="package_aide_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "aide"
version = "*"
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_aide_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install aide
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_aide_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install aide
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_aide_installed:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_aide_installed_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_aide_build_database" selected="false" severity="medium">
                  <xccdf-1.2:title>Build and Test AIDE Database</xccdf-1.2:title>
                  <xccdf-1.2:description>Run the following command to generate a new database:

<html:pre>$ sudo /usr/sbin/aide --init</html:pre>

By default, the database will be written to the file

<html:code>/var/lib/aide/aide.db.new.gz</html:code>.

Storing the database, the configuration file <html:code>/etc/aide.conf</html:code>, and the binary
<html:code>/usr/sbin/aide</html:code>
(or hashes of these files), in a secure location (such as on read-only media) provides additional assurance about their integrity.
The newly-generated database can be installed as follows:

<html:pre>$ sudo cp /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz</html:pre>

To initiate a manual check, run the following command:
<html:pre>$ sudo /usr/sbin/aide --check</html:pre>
If this check produces any unexpected output, investigate.</xccdf-1.2:description>
                  <xccdf-1.2:warning category="general">In RHEL Image Mode (bootc) systems, the AIDE database must be regenerated after each system update.
Image Mode systems receive updates through new container images that may include modified files.
After applying system updates, run the following commands to regenerate the AIDE database:
<html:pre>$ sudo /usr/sbin/aide --init</html:pre>
Then replace the existing database:
<html:pre>$ sudo cp /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz</html:pre>
Failure to regenerate the AIDE database after updates will result in false positive alerts
for legitimate system changes introduced by the update process.</xccdf-1.2:warning>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI01.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI02.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI06.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS04.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-11.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000445-GPOS-00199</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R76</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R79</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">11.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010359</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-251710r958944_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>For AIDE to be effective, an initial database of "known-good" information about files
must be captured and it should be able to be verified against the installed files.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix id="aide_build_database" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "aide" ; then
    yum install -y "aide"
fi

/usr/sbin/aide --init
/bin/cp -p /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="aide_build_database" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.10.1.3
  - DISA-STIG-RHEL-08-010359
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - aide_build_database
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Build and Test AIDE Database - Ensure AIDE Is Installed
  ansible.builtin.package:
    name: '{{ item }}'
    state: present
  with_items:
  - aide
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.3
  - DISA-STIG-RHEL-08-010359
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - aide_build_database
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Build and Test AIDE Database - Check Whether the Stock AIDE Database Exists
  ansible.builtin.stat:
    path: /var/lib/aide/aide.db.new.gz
  register: aide_database_stat
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.3
  - DISA-STIG-RHEL-08-010359
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - aide_build_database
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Build and Test AIDE Database - Build and Test AIDE Database
  ansible.builtin.command: /usr/sbin/aide --init
  changed_when: true
  when:
  - '"kernel" in ansible_facts.packages'
  - not (aide_database_stat.stat.exists is defined and aide_database_stat.stat.exists)
  register: aide_database_init
  tags:
  - CJIS-5.10.1.3
  - DISA-STIG-RHEL-08-010359
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - aide_build_database
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Build and Test AIDE Database - Stage AIDE Database
  ansible.builtin.copy:
    src: /var/lib/aide/aide.db.new.gz
    dest: /var/lib/aide/aide.db.gz
    backup: true
    remote_src: true
  when:
  - '"kernel" in ansible_facts.packages'
  - aide_database_init is changed
  - not ansible_check_mode
  tags:
  - CJIS-5.10.1.3
  - DISA-STIG-RHEL-08-010359
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - aide_build_database
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-aide_build_database:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-aide_build_database_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_aide_check_audit_tools" selected="false" severity="medium">
                  <xccdf-1.2:title>Configure AIDE to Verify the Audit Tools</xccdf-1.2:title>
                  <xccdf-1.2:description>The operating system file integrity tool must be configured to protect the integrity of the audit tools.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9(3)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9(3).1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000278-GPOS-00108</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030650</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230475r1017266_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Protecting the integrity of the tools used for auditing purposes is a
critical step toward ensuring the integrity of audit information. Audit
information includes all information (e.g., audit records, audit settings,
and audit reports) needed to successfully audit information system
activity.

Audit tools include but are not limited to vendor-provided and open-source
audit tools needed to successfully view and manipulate audit information
system activity and records. Audit tools include custom queries and report
generators.

It is not uncommon for attackers to replace the audit tools or inject code
into the existing tools to provide the capability to hide or erase system
activity from the audit logs.

To address this risk, audit tools must be cryptographically signed to
provide the capability to identify when the audit tools have been modified,
manipulated, or replaced. An example is a checksum hash of the file or
files.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="aide_check_audit_tools" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "aide" ; then
    yum install -y "aide"
fi










if grep -i -E '^.*(/usr)?/sbin/auditctl.*$' /etc/aide.conf; then
sed -i -r "s#.*(/usr)?/sbin/auditctl.*#/usr/sbin/auditctl p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#" /etc/aide.conf
else
echo "/usr/sbin/auditctl p+i+n+u+g+s+b+acl+selinux+xattrs+sha512" &gt;&gt; /etc/aide.conf
fi

if grep -i -E '^.*(/usr)?/sbin/auditd.*$' /etc/aide.conf; then
sed -i -r "s#.*(/usr)?/sbin/auditd.*#/usr/sbin/auditd p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#" /etc/aide.conf
else
echo "/usr/sbin/auditd p+i+n+u+g+s+b+acl+selinux+xattrs+sha512" &gt;&gt; /etc/aide.conf
fi

if grep -i -E '^.*(/usr)?/sbin/ausearch.*$' /etc/aide.conf; then
sed -i -r "s#.*(/usr)?/sbin/ausearch.*#/usr/sbin/ausearch p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#" /etc/aide.conf
else
echo "/usr/sbin/ausearch p+i+n+u+g+s+b+acl+selinux+xattrs+sha512" &gt;&gt; /etc/aide.conf
fi

if grep -i -E '^.*(/usr)?/sbin/aureport.*$' /etc/aide.conf; then
sed -i -r "s#.*(/usr)?/sbin/aureport.*#/usr/sbin/aureport p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#" /etc/aide.conf
else
echo "/usr/sbin/aureport p+i+n+u+g+s+b+acl+selinux+xattrs+sha512" &gt;&gt; /etc/aide.conf
fi

if grep -i -E '^.*(/usr)?/sbin/autrace.*$' /etc/aide.conf; then
sed -i -r "s#.*(/usr)?/sbin/autrace.*#/usr/sbin/autrace p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#" /etc/aide.conf
else
echo "/usr/sbin/autrace p+i+n+u+g+s+b+acl+selinux+xattrs+sha512" &gt;&gt; /etc/aide.conf
fi

if grep -i -E '^.*(/usr)?/sbin/augenrules.*$' /etc/aide.conf; then
sed -i -r "s#.*(/usr)?/sbin/augenrules.*#/usr/sbin/augenrules p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#" /etc/aide.conf
else
echo "/usr/sbin/augenrules p+i+n+u+g+s+b+acl+selinux+xattrs+sha512" &gt;&gt; /etc/aide.conf
fi

if grep -i -E '^.*(/usr)?/sbin/rsyslogd.*$' /etc/aide.conf; then
sed -i -r "s#.*(/usr)?/sbin/rsyslogd.*#/usr/sbin/rsyslogd p+i+n+u+g+s+b+acl+selinux+xattrs+sha512#" /etc/aide.conf
else
echo "/usr/sbin/rsyslogd p+i+n+u+g+s+b+acl+selinux+xattrs+sha512" &gt;&gt; /etc/aide.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="aide_check_audit_tools" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030650
  - NIST-800-53-AU-9(3)
  - NIST-800-53-AU-9(3).1
  - aide_check_audit_tools
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure AIDE to Verify the Audit Tools - Gather List of Packages
  tags:
  - DISA-STIG-RHEL-08-030650
  - NIST-800-53-AU-9(3)
  - NIST-800-53-AU-9(3).1
  - aide_check_audit_tools
  - aide_check_audit_tools
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  ansible.builtin.package_facts:
    manager: auto
  when: '"kernel" in ansible_facts.packages'

- name: Configure AIDE to Verify the Audit Tools - Ensure AIDE is Installed
  ansible.builtin.package:
    name: '{{ item }}'
    state: present
  with_items:
  - aide
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030650
  - NIST-800-53-AU-9(3)
  - NIST-800-53-AU-9(3).1
  - aide_check_audit_tools
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure AIDE to Verify the Audit Tools - Gather the Package Facts
  ansible.builtin.package_facts:
    manager: auto
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030650
  - NIST-800-53-AU-9(3)
  - NIST-800-53-AU-9(3).1
  - aide_check_audit_tools
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set "Configure AIDE to Verify the Audit Tools - audit_tools fact"
  ansible.builtin.set_fact:
    audit_tools:
    - /usr/sbin/auditctl
    - /usr/sbin/auditd
    - /usr/sbin/augenrules
    - /usr/sbin/aureport
    - /usr/sbin/ausearch
    - /usr/sbin/autrace
    - /usr/sbin/rsyslogd
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030650
  - NIST-800-53-AU-9(3)
  - NIST-800-53-AU-9(3).1
  - aide_check_audit_tools
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure AIDE to Verify the Audit Tools - Ensure Existing AIDE Configuration
    for Audit Tools are Correct
  ansible.builtin.lineinfile:
    path: /etc/aide.conf
    regexp: ^{{ item }}\s
    line: '{{ item }} p+i+n+u+g+s+b+acl+selinux+xattrs+sha512'
    create: true
  with_items: '{{ audit_tools }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"aide" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030650
  - NIST-800-53-AU-9(3)
  - NIST-800-53-AU-9(3).1
  - aide_check_audit_tools
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure AIDE to Verify the Audit Tools - Configure AIDE to Properly Protect
    Audit Tools
  ansible.builtin.lineinfile:
    path: /etc/aide.conf
    line: '{{ item }} p+i+n+u+g+s+b+acl+selinux+xattrs+sha512'
    create: true
  with_items: '{{ audit_tools }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"aide" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030650
  - NIST-800-53-AU-9(3)
  - NIST-800-53-AU-9(3).1
  - aide_check_audit_tools
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-aide_check_audit_tools:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-aide_check_audit_tools_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_aide_periodic_cron_checking" selected="false" severity="medium">
                  <xccdf-1.2:title>Configure Periodic Execution of AIDE</xccdf-1.2:title>
                  <xccdf-1.2:description>At a minimum, AIDE should be configured to run a weekly scan.
To implement a daily execution of AIDE at 4:05am using cron, add the following line to <html:code>/etc/crontab</html:code>:
<html:pre>05 4 * * * root /usr/sbin/aide --check</html:pre>
To implement a weekly execution of AIDE at 4:05am using cron, add the following line to <html:code>/etc/crontab</html:code>:
<html:pre>05 4 * * 0 root /usr/sbin/aide --check</html:pre>
AIDE can be executed periodically through other means; this is merely one example.
The usage of cron's special time codes, such as  <html:code>@daily</html:code> and
<html:code>@weekly</html:code> is acceptable.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI01.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI02.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI06.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS04.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7(1)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-11.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000363-GPOS-00150</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000446-GPOS-00200</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000447-GPOS-00201</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R76</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">11.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>By default, AIDE does not install itself for periodic execution. Periodically
running AIDE is necessary to reveal unexpected changes in installed files.
<html:br/><html:br/>
Unauthorized changes to the baseline configuration could make the system vulnerable
to various attacks or allow unauthorized access to the operating system. Changes to
operating system configurations can have unintended side effects, some of which may
be relevant to security.
<html:br/><html:br/>
Detecting such changes and providing an automated response can help avoid unintended,
negative consequences that could ultimately affect the security state of the operating
system. The operating system's Information Management Officer (IMO)/Information System
Security Officer (ISSO) and System Administrators (SAs) must be notified via email and/or
monitoring system trap when there is an unauthorized modification of a configuration item.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix id="aide_periodic_cron_checking" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "aide" ; then
    yum install -y "aide"
fi


if ! rpm -q --quiet "cronie" ; then
    yum install -y "cronie"
fi



CRON_FILE="/etc/crontab"


if ! grep -q "/usr/sbin/aide --check" "${CRON_FILE}" ; then
    echo "05 4 * * * root /usr/sbin/aide --check" &gt;&gt; "${CRON_FILE}"
else
    sed -i '\!^.* --check.*$!d' "${CRON_FILE}"
    echo "05 4 * * * root /usr/sbin/aide --check" &gt;&gt; "${CRON_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="aide_periodic_cron_checking" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.10.1.3
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - aide_periodic_cron_checking
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Periodic Execution of AIDE - Ensure AIDE is installed
  ansible.builtin.package:
    name: aide
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.3
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - aide_periodic_cron_checking
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Periodic Execution of AIDE - Install cron
  ansible.builtin.package:
    name: cronie
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.3
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - aide_periodic_cron_checking
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Periodic Execution of AIDE - Gather List of Installed Packages
  ansible.builtin.package_facts:
    manager: auto
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.3
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - aide_periodic_cron_checking
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Periodic Execution of AIDE - Setup Cron Tab
  ansible.builtin.cron:
    name: run AIDE check
    minute: 5
    hour: 4
    user: root
    job: /usr/sbin/aide --check
  register: crontab_check
  when:
  - '"kernel" in ansible_facts.packages'
  - '''cronie'' in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.3
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - PCI-DSS-Req-11.5
  - PCI-DSSv4-11.5.2
  - aide_periodic_cron_checking
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-aide_periodic_cron_checking:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-aide_periodic_cron_checking_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_aide_scan_notification" selected="false" severity="medium">
                  <xccdf-1.2:title>Configure Notification of Post-AIDE Scan Details</xccdf-1.2:title>
                  <xccdf-1.2:description>AIDE should notify appropriate personnel of the details of a scan after the scan has been run.
If AIDE has already been configured for periodic execution in <html:code>/etc/crontab</html:code>, append the
following line to the existing AIDE line:
<html:pre> | /bin/mail -s "$(hostname) - AIDE Integrity Check" root@localhost</html:pre>
Otherwise, add the following line to <html:code>/etc/crontab</html:code>:
<html:pre>05 4 * * * root /usr/sbin/aide --check | /bin/mail -s "$(hostname) - AIDE Integrity Check" root@localhost</html:pre>
AIDE can be executed periodically through other means; this is merely one example.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI01.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI06.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-3(5)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000363-GPOS-00150</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000446-GPOS-00200</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000447-GPOS-00201</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R76</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010360</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230263r1017083_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Unauthorized changes to the baseline configuration could make the system vulnerable
to various attacks or allow unauthorized access to the operating system. Changes to
operating system configurations can have unintended side effects, some of which may
be relevant to security.
<html:br/><html:br/>
Detecting such changes and providing an automated response can help avoid unintended,
negative consequences that could ultimately affect the security state of the operating
system. The operating system's Information Management Officer (IMO)/Information System
Security Officer (ISSO) and System Administrators (SAs) must be notified via email and/or
monitoring system trap when there is an unauthorized modification of a configuration item.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix id="aide_scan_notification" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "aide" ; then
    yum install -y "aide"
fi
var_aide_scan_notification_email='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_aide_scan_notification_email" use="legacy"/>'



CRONTAB=/etc/crontab
CRONDIRS='/etc/cron.d /etc/cron.daily /etc/cron.weekly /etc/cron.monthly'

# NOTE: on some platforms, /etc/crontab may not exist
if [ -f /etc/crontab ]; then
	CRONTAB_EXIST=/etc/crontab
fi

if [ -f /var/spool/cron/root ]; then
	VARSPOOL=/var/spool/cron/root
fi

if ! grep -qR '^.*/usr/sbin/aide\s*\-\-check.*|.*\/bin\/mail\s*-s\s*".*"\s*.*@.*$' $CRONTAB_EXIST $VARSPOOL $CRONDIRS; then
	echo "0 5 * * * root /usr/sbin/aide  --check | /bin/mail -s \"\$(hostname) - AIDE Integrity Check\" $var_aide_scan_notification_email" &gt;&gt; $CRONTAB
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="aide_scan_notification" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010360
  - NIST-800-53-CM-3(5)
  - NIST-800-53-CM-6(a)
  - aide_scan_notification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_aide_scan_notification_email # promote to variable
  set_fact:
    var_aide_scan_notification_email: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_aide_scan_notification_email" use="legacy"/>
  tags:
    - always

- name: Configure Notification of Post-AIDE Scan Details - Ensure AIDE is installed
  ansible.builtin.package:
    name: '{{ item }}'
    state: present
  with_items:
  - aide
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010360
  - NIST-800-53-CM-3(5)
  - NIST-800-53-CM-6(a)
  - aide_scan_notification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Notification of Post-AIDE Scan Details - Setup Cron Tab
  ansible.builtin.cron:
    name: run AIDE check
    minute: 5
    hour: 4
    weekday: 0
    user: root
    job: /usr/sbin/aide  --check | /bin/mail -s "$(hostname) - AIDE Integrity Check"
      {{ var_aide_scan_notification_email }}
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010360
  - NIST-800-53-CM-3(5)
  - NIST-800-53-CM-6(a)
  - aide_scan_notification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-aide_scan_notification:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-aide_scan_notification_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_aide_use_fips_hashes" selected="false" severity="medium">
                  <xccdf-1.2:title>Configure AIDE to Use FIPS 140-2 for Validating Hashes</xccdf-1.2:title>
                  <xccdf-1.2:description>By default, the <html:code>sha512</html:code> option is added to the <html:code>NORMAL</html:code> ruleset in AIDE.
If using a custom ruleset or the <html:code>sha512</html:code> option is missing, add <html:code>sha512</html:code>
to the appropriate ruleset.
For example, add <html:code>sha512</html:code> to the following line in <html:code>/etc/aide.conf</html:code>:
<html:pre>NORMAL = FIPSR+sha512</html:pre>
AIDE rules can be configured in multiple ways; this is merely one example that is already
configured by default.</xccdf-1.2:description>
                  <xccdf-1.2:warning category="regulatory">System Crypto Modules must be provided by a vendor that undergoes
FIPS-140 certifications.
FIPS-140 is applicable to all Federal agencies that use
cryptographic-based security systems to protect sensitive information
in computer and telecommunication systems (including voice systems) as
defined in Section 5131 of the Information Technology Management Reform
Act of 1996, Public Law 104-106. This standard shall be used in
designing and implementing cryptographic modules that Federal
departments and agencies operate or are operated for them under
contract. See <html:b><html:a href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf">https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf</html:a></html:b>
To meet this, the system has to have cryptographic software provided by
a vendor that has undergone this certification. This means providing
documentation, test results, design information, and independent third
party review by an accredited lab. While open source software is
capable of meeting this, it does not meet FIPS-140 unless the vendor
submits to this process.</xccdf-1.2:warning>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI06.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.13.11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7(1)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>File integrity tools use cryptographic hashes for verifying file contents and directories
have not been altered. These hashes must be FIPS 140-2 approved cryptographic hashes.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix id="aide_use_fips_hashes" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "aide" ; then
    yum install -y "aide"
fi

aide_conf="/etc/aide.conf"
forbidden_hashes=(sha1 rmd160 sha256 whirlpool tiger haval gost crc32)

groups=$(LC_ALL=C grep "^[A-Z][A-Za-z_]*" $aide_conf | cut -f1 -d ' ' | tr -d ' ' | sort -u)

for group in $groups
do
	config=$(grep "^$group\s*=" $aide_conf | cut -f2 -d '=' | tr -d ' ')

	if ! [[ $config = *sha512* ]]
	then
		config=$config"+sha512"
	fi

	for hash in "${forbidden_hashes[@]}"
	do
		config=$(echo $config | sed "s/$hash//")
	done

	config=$(echo $config | sed "s/^\+*//")
	config=$(echo $config | sed "s/\+\++/+/")
	config=$(echo $config | sed "s/\+$//")

	sed -i "s/^$group\s*=.*/$group = $config/g" $aide_conf
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="aide_use_fips_hashes" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - aide_use_fips_hashes
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure AIDE to Use FIPS 140-2 for Validating Hashes - Ensure aide is installed
  ansible.builtin.package:
    name: aide
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - aide_use_fips_hashes
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure AIDE to Use FIPS 140-2 for Validating Hashes - Set-fact aide config
    file and forbidden hashes
  ansible.builtin.set_fact:
    aide_conf: /etc/aide.conf
    forbidden_hashes:
    - sha1
    - rmd160
    - sha256
    - whirlpool
    - tiger
    - haval
    - gost
    - crc32
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - aide_use_fips_hashes
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure AIDE to Use FIPS 140-2 for Validating Hashes - Gather the package
    facts
  ansible.builtin.package_facts:
    manager: auto
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - aide_use_fips_hashes
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure AIDE to Use FIPS 140-2 for Validating Hashes - Remove forbidden
    hashes
  ansible.builtin.replace:
    path: '{{ aide_conf }}'
    regexp: (^\s*[A-Z][A-Za-z_]*\s*=.*?)({{ item }}\+|\+?{{ item }})(.*)
    replace: \1\3
  when:
  - '"kernel" in ansible_facts.packages'
  - '"aide" in ansible_facts.packages'
  loop: '{{ forbidden_hashes }}'
  tags:
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - aide_use_fips_hashes
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure AIDE to Use FIPS 140-2 for Validating Hashes - Set sha512
  ansible.builtin.replace:
    path: '{{ aide_conf }}'
    regexp: (^\s*[A-Z][A-Za-z_]*\s*=)((?:(?!\+?sha512).)*)\s*$
    replace: \1\2+sha512
  when:
  - '"kernel" in ansible_facts.packages'
  - '"aide" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - aide_use_fips_hashes
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-aide_use_fips_hashes:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-aide_use_fips_hashes_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_aide_verify_acls" selected="false" severity="low">
                  <xccdf-1.2:title>Configure AIDE to Verify Access Control Lists (ACLs)</xccdf-1.2:title>
                  <xccdf-1.2:description>By default, the <html:code>acl</html:code> option is added to the <html:code>FIPSR</html:code> ruleset in AIDE.
If using a custom ruleset or the <html:code>acl</html:code> option is missing, add <html:code>acl</html:code>
to the appropriate ruleset.
For example, add <html:code>acl</html:code> to the following line in <html:code>/etc/aide.conf</html:code>:
<html:pre>FIPSR = p+i+n+u+g+s+m+c+acl+selinux+xattrs+sha256</html:pre>
AIDE rules can be configured in multiple ways; this is merely one example that is already
configured by default.


The remediation provided with this rule adds <html:code>acl</html:code> to all rule sets available in
<html:code>/etc/aide.conf</html:code></xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI06.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7(1)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R76</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040310</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230552r1101902_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>ACLs can provide permissions beyond those permitted through the file mode and must be
verified by the file integrity tools.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix id="aide_verify_acls" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "aide" ; then
    yum install -y "aide"
fi

aide_conf="/etc/aide.conf"


groups=$(LC_ALL=C grep "^[A-Z][A-Za-z_]*" $aide_conf | grep -v "^ALLXTRAHASHES" | cut -f1 -d '=' | tr -d ' ' | sort -u)


for group in $groups
do
	config=$(grep "^$group\s*=" $aide_conf | cut -f2 -d '=' | tr -d ' ')

	if ! [[ $config = *acl* ]]
	then
		if [[ -z $config ]]
		then
			config="acl"
		else
			config=$config"+acl"
		fi
	fi
	sed -i "s/^$group\s*=.*/$group = $config/g" $aide_conf
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="aide_verify_acls" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040310
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - aide_verify_acls
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy

- name: Gather list of packages
  ansible.builtin.package_facts:
    manager: auto
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040310
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - aide_verify_acls
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy

- name: Get rules groups
  ansible.builtin.shell: |
    set -o pipefail
    LC_ALL=C grep "^[A-Z][A-Za-z_]*" /etc/aide.conf | grep -v "^ALLXTRAHASHES" | cut -f1 -d '=' | tr -d ' ' | sort -u || true
  when:
  - '"kernel" in ansible_facts.packages'
  - '''aide'' in ansible_facts.packages'
  register: find_rules_groups_results
  changed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-040310
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - aide_verify_acls
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure the acl rule is present when aide is installed.
  ansible.builtin.replace:
    path: /etc/aide.conf
    regexp: (^\s*{{ item }}\s*=\s*)(?!.*acl)([^\s]*)
    replace: \g&lt;1&gt;\g&lt;2&gt;+acl
  when:
  - '"kernel" in ansible_facts.packages'
  - find_rules_groups_results is not skipped and "'aide' in ansible_facts.packages"
  with_items: '{{ find_rules_groups_results.stdout_lines | map(''trim'') | list }}'
  tags:
  - DISA-STIG-RHEL-08-040310
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - aide_verify_acls
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-aide_verify_acls:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-aide_verify_acls_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_aide_verify_ext_attributes" selected="false" severity="low">
                  <xccdf-1.2:title>Configure AIDE to Verify Extended Attributes</xccdf-1.2:title>
                  <xccdf-1.2:description>By default, the <html:code>xattrs</html:code> option is added to the <html:code>FIPSR</html:code> ruleset in AIDE.
If using a custom ruleset or the <html:code>xattrs</html:code> option is missing, add <html:code>xattrs</html:code>
to the appropriate ruleset.
For example, add <html:code>xattrs</html:code> to the following line in <html:code>/etc/aide.conf</html:code>:
<html:pre>FIPSR = p+i+n+u+g+s+m+c+acl+selinux+xattrs+sha256</html:pre>
AIDE rules can be configured in multiple ways; this is merely one example that is already
configured by default.


The remediation provided with this rule adds <html:code>xattrs</html:code> to all rule sets available in
<html:code>/etc/aide.conf</html:code></xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI06.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7(1)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R76</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040300</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230551r1017313_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Extended attributes in file systems are used to contain arbitrary data and file metadata
with security implications.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix id="aide_verify_ext_attributes" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "aide" ; then
    yum install -y "aide"
fi

aide_conf="/etc/aide.conf"


groups=$(LC_ALL=C grep "^[A-Z][A-Za-z_]*" $aide_conf | grep -v "^ALLXTRAHASHES" | cut -f1 -d '=' | tr -d ' ' | sort -u)


for group in $groups
do
	config=$(grep "^$group\s*=" $aide_conf | cut -f2 -d '=' | tr -d ' ')

	if ! [[ $config = *xattrs* ]]
	then
		if [[ -z $config ]]
		then
			config="xattrs"
		else
			config=$config"+xattrs"
		fi
	fi
	sed -i "s/^$group\s*=.*/$group = $config/g" $aide_conf
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="aide_verify_ext_attributes" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040300
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - aide_verify_ext_attributes
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy

- name: Gather list of packages
  ansible.builtin.package_facts:
    manager: auto
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040300
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - aide_verify_ext_attributes
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy

- name: Get rules groups
  ansible.builtin.shell: |
    set -o pipefail
    LC_ALL=C grep "^[A-Z][A-Za-z_]*" /etc/aide.conf | grep -v "^ALLXTRAHASHES" | cut -f1 -d '=' | tr -d ' ' | sort -u || true
  when:
  - '"kernel" in ansible_facts.packages'
  - '''aide'' in ansible_facts.packages'
  register: find_rules_groups_results
  changed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-040300
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - aide_verify_ext_attributes
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure the xattrs rule is present when aide is installed.
  ansible.builtin.replace:
    path: /etc/aide.conf
    regexp: (^\s*{{ item }}\s*=\s*)(?!.*xattrs)([^\s]*)
    replace: \g&lt;1&gt;\g&lt;2&gt;+xattrs
  when:
  - '"kernel" in ansible_facts.packages'
  - find_rules_groups_results is not skipped and "'aide' in ansible_facts.packages"
  with_items: '{{ find_rules_groups_results.stdout_lines | map(''trim'') | list }}'
  tags:
  - DISA-STIG-RHEL-08-040300
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-7
  - NIST-800-53-SI-7(1)
  - aide_verify_ext_attributes
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-aide_verify_ext_attributes:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-aide_verify_ext_attributes_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_audit_tools_group_ownership" selected="false" severity="medium">
                  <xccdf-1.2:title>Audit Tools Must Be Group-owned by Root</xccdf-1.2:title>
                  <xccdf-1.2:description>AlmaLinux OS 8 systems providing tools to interface with audit information will leverage user permissions and roles identifying the user accessing the tools, and the corresponding rights the user enjoys, to make access decisions regarding the access to audit tools.

Audit tools include, but are not limited to, vendor-provided and open source audit tools needed to successfully view and manipulate audit information system activity and records. Audit tools include custom queries and report generators.

Audit tools must have the correct group owner.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000256-GPOS-00097</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000257-GPOS-00098</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000258-GPOS-00099</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030640</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230474r1017265_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Protecting audit information also includes identifying and protecting the tools used to view and manipulate log data.
Therefore, protecting audit tools is necessary to prevent unauthorized operations on audit information.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="file_audit_tools_group_ownership" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/sbin/auditctl" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /sbin/auditctl
fi
if ! stat -c "%g %G" "/sbin/aureport" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /sbin/aureport
fi
if ! stat -c "%g %G" "/sbin/ausearch" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /sbin/ausearch
fi
if ! stat -c "%g %G" "/sbin/autrace" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /sbin/autrace
fi
if ! stat -c "%g %G" "/sbin/auditd" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /sbin/auditd
fi
if ! stat -c "%g %G" "/sbin/rsyslogd" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /sbin/rsyslogd
fi
if ! stat -c "%g %G" "/sbin/augenrules" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /sbin/augenrules
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="file_audit_tools_group_ownership" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030640
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_audit_tools_group_ownership_newgroup variable if represented
    by gid
  ansible.builtin.set_fact:
    file_audit_tools_group_ownership_newgroup: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030640
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/auditctl
  ansible.builtin.stat:
    path: /sbin/auditctl
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030640
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /sbin/auditctl
  ansible.builtin.file:
    path: /sbin/auditctl
    follow: false
    group: '{{ file_audit_tools_group_ownership_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030640
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/aureport
  ansible.builtin.stat:
    path: /sbin/aureport
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030640
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /sbin/aureport
  ansible.builtin.file:
    path: /sbin/aureport
    follow: false
    group: '{{ file_audit_tools_group_ownership_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030640
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/ausearch
  ansible.builtin.stat:
    path: /sbin/ausearch
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030640
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /sbin/ausearch
  ansible.builtin.file:
    path: /sbin/ausearch
    follow: false
    group: '{{ file_audit_tools_group_ownership_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030640
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/autrace
  ansible.builtin.stat:
    path: /sbin/autrace
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030640
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /sbin/autrace
  ansible.builtin.file:
    path: /sbin/autrace
    follow: false
    group: '{{ file_audit_tools_group_ownership_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030640
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/auditd
  ansible.builtin.stat:
    path: /sbin/auditd
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030640
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /sbin/auditd
  ansible.builtin.file:
    path: /sbin/auditd
    follow: false
    group: '{{ file_audit_tools_group_ownership_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030640
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/rsyslogd
  ansible.builtin.stat:
    path: /sbin/rsyslogd
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030640
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /sbin/rsyslogd
  ansible.builtin.file:
    path: /sbin/rsyslogd
    follow: false
    group: '{{ file_audit_tools_group_ownership_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030640
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/augenrules
  ansible.builtin.stat:
    path: /sbin/augenrules
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030640
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /sbin/augenrules
  ansible.builtin.file:
    path: /sbin/augenrules
    follow: false
    group: '{{ file_audit_tools_group_ownership_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030640
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_audit_tools_group_ownership:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_audit_tools_group_ownership_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_audit_tools_ownership" selected="false" severity="medium">
                  <xccdf-1.2:title>Audit Tools Must Be Owned by Root</xccdf-1.2:title>
                  <xccdf-1.2:description>AlmaLinux OS 8 systems providing tools to interface with audit information will leverage user permissions and roles identifying the user accessing the tools, and the corresponding rights the user enjoys, to make access decisions regarding the access to audit tools.

Audit tools include, but are not limited to, vendor-provided and open source audit tools needed to successfully view and manipulate audit information system activity and records. Audit tools include custom queries and report generators.

Audit tools must have the correct owner.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000256-GPOS-00097</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000257-GPOS-00098</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000258-GPOS-00099</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030630</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230473r1017264_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Protecting audit information also includes identifying and protecting the tools used to view and manipulate log data.
Therefore, protecting audit tools is necessary to prevent unauthorized operations on audit information.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="file_audit_tools_ownership" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/sbin/auditctl" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /sbin/auditctl
fi
if ! stat -c "%u %U" "/sbin/aureport" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /sbin/aureport
fi
if ! stat -c "%u %U" "/sbin/ausearch" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /sbin/ausearch
fi
if ! stat -c "%u %U" "/sbin/autrace" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /sbin/autrace
fi
if ! stat -c "%u %U" "/sbin/auditd" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /sbin/auditd
fi
if ! stat -c "%u %U" "/sbin/rsyslogd" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /sbin/rsyslogd
fi
if ! stat -c "%u %U" "/sbin/augenrules" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /sbin/augenrules
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="file_audit_tools_ownership" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030630
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_audit_tools_ownership_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_audit_tools_ownership_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030630
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/auditctl
  ansible.builtin.stat:
    path: /sbin/auditctl
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030630
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /sbin/auditctl
  ansible.builtin.file:
    path: /sbin/auditctl
    follow: false
    owner: '{{ file_audit_tools_ownership_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030630
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/aureport
  ansible.builtin.stat:
    path: /sbin/aureport
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030630
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /sbin/aureport
  ansible.builtin.file:
    path: /sbin/aureport
    follow: false
    owner: '{{ file_audit_tools_ownership_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030630
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/ausearch
  ansible.builtin.stat:
    path: /sbin/ausearch
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030630
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /sbin/ausearch
  ansible.builtin.file:
    path: /sbin/ausearch
    follow: false
    owner: '{{ file_audit_tools_ownership_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030630
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/autrace
  ansible.builtin.stat:
    path: /sbin/autrace
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030630
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /sbin/autrace
  ansible.builtin.file:
    path: /sbin/autrace
    follow: false
    owner: '{{ file_audit_tools_ownership_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030630
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/auditd
  ansible.builtin.stat:
    path: /sbin/auditd
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030630
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /sbin/auditd
  ansible.builtin.file:
    path: /sbin/auditd
    follow: false
    owner: '{{ file_audit_tools_ownership_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030630
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/rsyslogd
  ansible.builtin.stat:
    path: /sbin/rsyslogd
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030630
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /sbin/rsyslogd
  ansible.builtin.file:
    path: /sbin/rsyslogd
    follow: false
    owner: '{{ file_audit_tools_ownership_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030630
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/augenrules
  ansible.builtin.stat:
    path: /sbin/augenrules
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030630
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /sbin/augenrules
  ansible.builtin.file:
    path: /sbin/augenrules
    follow: false
    owner: '{{ file_audit_tools_ownership_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030630
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_audit_tools_ownership:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_audit_tools_ownership_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_audit_tools_permissions" selected="false" severity="medium">
                  <xccdf-1.2:title>Audit Tools Must Have a Mode of 0755 or Less Permissive</xccdf-1.2:title>
                  <xccdf-1.2:description>AlmaLinux OS 8 systems providing tools to interface with audit information will leverage user permissions and roles identifying the user accessing the tools, and the corresponding rights the user enjoys, to make access decisions regarding the access to audit tools.

Audit tools include, but are not limited to, vendor-provided and open source audit tools needed to successfully view and manipulate audit information system activity and records. Audit tools include custom queries and report generators.

Audit tools must have a mode of 0755 or less permissive.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000256-GPOS-00097</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000257-GPOS-00098</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000258-GPOS-00099</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030620</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230472r1017263_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Protecting audit information also includes identifying and protecting the tools used to view and manipulate log data.
Therefore, protecting audit tools is necessary to prevent unauthorized operations on audit information.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="file_audit_tools_permissions" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

chmod u-s,g-ws,o-wt /sbin/auditctl

chmod u-s,g-ws,o-wt /sbin/aureport

chmod u-s,g-ws,o-wt /sbin/ausearch

chmod u-s,g-ws,o-wt /sbin/autrace

chmod u-s,g-ws,o-wt /sbin/auditd

chmod u-s,g-ws,o-wt /sbin/rsyslogd

chmod u-s,g-ws,o-wt /sbin/augenrules

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="file_audit_tools_permissions" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030620
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/auditctl
  ansible.builtin.stat:
    path: /sbin/auditctl
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030620
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-s,g-ws,o-wt on /sbin/auditctl
  ansible.builtin.file:
    path: /sbin/auditctl
    mode: u-s,g-ws,o-wt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030620
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/aureport
  ansible.builtin.stat:
    path: /sbin/aureport
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030620
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-s,g-ws,o-wt on /sbin/aureport
  ansible.builtin.file:
    path: /sbin/aureport
    mode: u-s,g-ws,o-wt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030620
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/ausearch
  ansible.builtin.stat:
    path: /sbin/ausearch
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030620
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-s,g-ws,o-wt on /sbin/ausearch
  ansible.builtin.file:
    path: /sbin/ausearch
    mode: u-s,g-ws,o-wt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030620
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/autrace
  ansible.builtin.stat:
    path: /sbin/autrace
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030620
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-s,g-ws,o-wt on /sbin/autrace
  ansible.builtin.file:
    path: /sbin/autrace
    mode: u-s,g-ws,o-wt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030620
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/auditd
  ansible.builtin.stat:
    path: /sbin/auditd
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030620
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-s,g-ws,o-wt on /sbin/auditd
  ansible.builtin.file:
    path: /sbin/auditd
    mode: u-s,g-ws,o-wt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030620
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/rsyslogd
  ansible.builtin.stat:
    path: /sbin/rsyslogd
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030620
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-s,g-ws,o-wt on /sbin/rsyslogd
  ansible.builtin.file:
    path: /sbin/rsyslogd
    mode: u-s,g-ws,o-wt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030620
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/augenrules
  ansible.builtin.stat:
    path: /sbin/augenrules
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030620
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-s,g-ws,o-wt on /sbin/augenrules
  ansible.builtin.file:
    path: /sbin/augenrules
    mode: u-s,g-ws,o-wt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030620
  - NIST-800-53-AU-9
  - configure_strategy
  - file_audit_tools_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_audit_tools_permissions:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_audit_tools_permissions_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
              </xccdf-1.2:Group>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_fips">
              <xccdf-1.2:title>Federal Information Processing Standard (FIPS)</xccdf-1.2:title>
              <xccdf-1.2:description>The Federal Information Processing Standard (FIPS) is a computer security standard which
is developed by the U.S. Government and industry working groups to validate the quality
of cryptographic modules. The FIPS standard provides four security levels to ensure
adequate coverage of different industries, implementation of cryptographic modules, and
organizational sizes and requirements.
<html:br/><html:br/>
FIPS 140-2 is the current standard for validating that mechanisms used to access cryptographic modules
utilize authentication that meets industry and government requirements. For government systems, this allows
Security Levels 1, 2, 3, or 4 for use on AlmaLinux OS 8.
<html:br/><html:br/>
See <html:b><html:a href="http://csrc.nist.gov/publications/PubsFIPS.html">http://csrc.nist.gov/publications/PubsFIPS.html</html:a></html:b> for more information.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_enable_dracut_fips_module" selected="false" severity="high">
                <xccdf-1.2:title>Enable Dracut FIPS Module</xccdf-1.2:title>
                <xccdf-1.2:description>
To enable FIPS mode, run the following command:
<html:pre>fips-mode-setup --enable</html:pre>

To enable FIPS, the system requires that the <html:code>fips</html:code> module is added in <html:code>dracut</html:code> configuration.
Check if <html:code>/etc/dracut.conf.d/40-fips.conf</html:code> contain <html:code>add_dracutmodules+=" fips "</html:code></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">
The system needs to be rebooted for these changes to take effect.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="regulatory">System Crypto Modules must be provided by a vendor that undergoes FIPS-140 certifications.
FIPS-140 is applicable to all Federal agencies that use cryptographic-based security
systems to protect sensitive information in computer and telecommunication systems
(including voice systems) as defined in Section 5131 of the Information Technology
Management Reform Act of 1996, Public Law 104-106. This standard shall be used in designing
and implementing cryptographic modules that Federal departments and agencies operate or are
operated for them under contract.
See <html:b><html:a href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf">https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf</html:a></html:b>
To meet this, the system has to have cryptographic software provided by a vendor that has
undergone this certification. This means providing documentation, test results, design
information, and independent third party review by an accredited lab. While open source
software is capable of meeting this, it does not meet FIPS-140 unless the vendor submits to
this process.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_RBG_EXT.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000478-GPOS-00223</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1446</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Use of weak or untested encryption algorithms undermines the purposes of utilizing encryption to
protect data. The operating system must implement cryptographic modules adhering to the higher
standards approved by the federal government since this provides assurance they have been tested
and validated.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#not_bootc_and_not_osbuild_and_system_with_kernel"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-enable_dracut_fips_module:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-enable_dracut_fips_module_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_enable_fips_mode" selected="false" severity="high">
                <xccdf-1.2:title>Enable FIPS Mode</xccdf-1.2:title>
                <xccdf-1.2:description>
To enable FIPS mode, run the following command:
<html:pre>fips-mode-setup --enable</html:pre>
<html:br/>
The <html:code>fips-mode-setup</html:code> command will configure the system in
FIPS mode by automatically configuring the following:
<html:ul><html:li>Setting the kernel FIPS mode flag (<html:code>/proc/sys/crypto/fips_enabled</html:code>) to <html:code>1</html:code></html:li><html:li>Creating <html:code>/etc/system-fips</html:code></html:li><html:li>Setting the system crypto policy in <html:code>/etc/crypto-policies/config</html:code> to <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_system_crypto_policy" use="legacy"/></html:code></html:li><html:li>Loading the Dracut <html:code>fips</html:code> module</html:li></html:ul></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">To configure AlmaLinux OS 8 to run in FIPS 140 mode, the kernel parameter "fips=1" needs to be added during its installation.
Only enabling FIPS 140 mode during the AlmaLinux OS 8 installation ensures that the system generates all keys with FIPS-approved algorithms and continuous monitoring tests in place.
Enabling FIPS mode on a preexisting system involves a number of modifications to it and therefore is not supported.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="regulatory">This rule DOES NOT CHECK if the components of the operating system are FIPS certified.
You can find the list of FIPS certified modules at 
<html:a href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules/search">https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules/search</html:a>.
This rule checks if the system is running in FIPS mode.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-3(6)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_COP.1(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_COP.1(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_COP.1(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_COP.1(4)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_CKM.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_CKM.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_TLSC_EXT.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_RBG_EXT.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000478-GPOS-00223</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000396-GPOS-00176</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1446</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Use of weak or untested encryption algorithms undermines the purposes of utilizing encryption to
protect data. The operating system must implement cryptographic modules adhering to the higher
standards approved by the federal government since this provides assurance they have been tested
and validated.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#not_osbuild_and_system_with_kernel"/>
                <xccdf-1.2:fix id="enable_fips_mode" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( ! ( [ "${container:-}" == "bwrap-osbuild" ] ) &amp;&amp; rpm --quiet -q kernel ) ); then

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; }; then
	cat &gt; /usr/lib/bootc/kargs.d/01-fips.toml &lt;&lt; EOF
kargs = ["fips=1"]
EOF
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="enable_fips_mode" system="urn:redhat:osbuild:blueprint">
[customizations]
fips = true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_system_crypto_policy:var:1" value-id="xccdf_org.ssgproject.content_value_var_system_crypto_policy"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-enable_fips_mode:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-enable_fips_mode_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_etc_system_fips_exists" selected="false" severity="high">
                <xccdf-1.2:title>Ensure '/etc/system-fips' exists</xccdf-1.2:title>
                <xccdf-1.2:description>On a system where FIPS mode is enabled, <html:code>/etc/system-fips</html:code> must exist.

To enable FIPS mode, run the following command:
<html:pre>fips-mode-setup --enable</html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">
The system needs to be rebooted for these changes to take effect.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="regulatory">System Crypto Modules must be provided by a vendor that undergoes
FIPS-140 certifications.
FIPS-140 is applicable to all Federal agencies that use
cryptographic-based security systems to protect sensitive information
in computer and telecommunication systems (including voice systems) as
defined in Section 5131 of the Information Technology Management Reform
Act of 1996, Public Law 104-106. This standard shall be used in
designing and implementing cryptographic modules that Federal
departments and agencies operate or are operated for them under
contract. See <html:b><html:a href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf">https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf</html:a></html:b>
To meet this, the system has to have cryptographic software provided by
a vendor that has undergone this certification. This means providing
documentation, test results, design information, and independent third
party review by an accredited lab. While open source software is
capable of meeting this, it does not meet FIPS-140 unless the vendor
submits to this process.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Use of weak or untested encryption algorithms undermines the purposes of utilizing encryption to
protect data. The operating system must implement cryptographic modules adhering to the higher
standards approved by the federal government since this provides assurance they have been tested
and validated.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#not_osbuild_and_system_with_kernel"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-etc_system_fips_exists:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-etc_system_fips_exists_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_fips_crypto_subpolicy" selected="false" severity="medium">
                <xccdf-1.2:title>FIPS Must Use a Supported Subpolicy</xccdf-1.2:title>
                <xccdf-1.2:description>Sub-policies can be used to modify existing crypto policies.
Some sub-policies such as <html:code>NO-ENFORCE-EMS</html:code> reduce the security of the system and should not be used.
Other such as <html:code>AD-SUPPORT</html:code> should only be enabled if operationally required.
The <html:code>OSPP</html:code>, <html:code>NO-SHA1</html:code>, <html:code>NO-CAMELLIA</html:code>, and <html:code>ECDHE-ONLY</html:code> are allowed by this rule.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">This rule does not have a remediation.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000033-GPOS-00014</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010020</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010290</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010291</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010296</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010297</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230223r1155356_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230251r1155370_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230252r1155364_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-272482r1155367_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-272483r1155361_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Sub-policies can cause insecure ciphers to be used.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-fips_crypto_subpolicy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-fips_crypto_subpolicy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_fips_custom_stig_sub_policy" selected="false" severity="medium">
                <xccdf-1.2:title>Implement STIG Sub Crypto Policy</xccdf-1.2:title>
                <xccdf-1.2:description>Create a custom cryptographic policy to follow the guidance from DISA.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000396-GPOS-00176</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000393-GPOS-00173</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000394-GPOS-00174</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010020</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010290</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010291</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010296</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010297</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230223r1155356_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230251r1155370_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230252r1155364_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-272482r1155367_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-272483r1155361_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>To follow STIG policy.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="fips_custom_stig_sub_policy" reboot="true" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &lt;&lt; 'EOF' &gt; /etc/crypto-policies/policies/modules/STIG.pmod
cipher@SSH=AES-256-GCM AES-256-CTR AES-128-GCM AES-128-CTR
mac@SSH=HMAC-SHA2-512 HMAC-SHA2-256
EOF

sudo update-crypto-policies --set FIPS:STIG

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="fips_custom_stig_sub_policy" reboot="true" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010020
  - DISA-STIG-RHEL-08-010290
  - DISA-STIG-RHEL-08-010291
  - DISA-STIG-RHEL-08-010296
  - DISA-STIG-RHEL-08-010297
  - configure_strategy
  - fips_custom_stig_sub_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required

- name: Implement STIG Sub Crypto Policy - Create custom crypto policy - cipher
  ansible.builtin.lineinfile:
    path: /etc/crypto-policies/policies/modules/STIG.pmod
    owner: root
    group: root
    mode: '0644'
    line: cipher@SSH=AES-256-GCM AES-256-CTR AES-128-GCM AES-128-CTR
    create: true
    regexp: cipher@SSH
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010020
  - DISA-STIG-RHEL-08-010290
  - DISA-STIG-RHEL-08-010291
  - DISA-STIG-RHEL-08-010296
  - DISA-STIG-RHEL-08-010297
  - configure_strategy
  - fips_custom_stig_sub_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required

- name: Implement STIG Sub Crypto Policy - Create custom crypto policy - mac
  ansible.builtin.lineinfile:
    path: /etc/crypto-policies/policies/modules/STIG.pmod
    owner: root
    group: root
    mode: '0644'
    line: mac@SSH=HMAC-SHA2-512 HMAC-SHA2-256
    create: true
    regexp: ^mac@SSH=
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010020
  - DISA-STIG-RHEL-08-010290
  - DISA-STIG-RHEL-08-010291
  - DISA-STIG-RHEL-08-010296
  - DISA-STIG-RHEL-08-010297
  - configure_strategy
  - fips_custom_stig_sub_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required

- name: Implement STIG Sub Crypto Policy - Check current crypto policy
  ansible.builtin.command: update-crypto-policies --show
  register: current_crypto_policy
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010020
  - DISA-STIG-RHEL-08-010290
  - DISA-STIG-RHEL-08-010291
  - DISA-STIG-RHEL-08-010296
  - DISA-STIG-RHEL-08-010297
  - configure_strategy
  - fips_custom_stig_sub_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required

- name: Implement STIG Sub Crypto Policy - Update crypto-policies
  ansible.builtin.command: update-crypto-policies --set FIPS:STIG
  when:
  - '"kernel" in ansible_facts.packages'
  - current_crypto_policy.stdout.strip() != "FIPS:STIG"
  tags:
  - DISA-STIG-RHEL-08-010020
  - DISA-STIG-RHEL-08-010290
  - DISA-STIG-RHEL-08-010291
  - DISA-STIG-RHEL-08-010296
  - DISA-STIG-RHEL-08-010297
  - configure_strategy
  - fips_custom_stig_sub_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-fips_custom_stig_sub_policy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-fips_custom_stig_sub_policy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_crypto_fips_enabled" selected="false" severity="high">
                <xccdf-1.2:title>Set kernel parameter 'crypto.fips_enabled' to 1</xccdf-1.2:title>
                <xccdf-1.2:description>System running in FIPS mode is indicated by kernel parameter
<html:code>'crypto.fips_enabled'</html:code>. This parameter should be set to <html:code>1</html:code> in FIPS mode.

To enable FIPS mode, run the following command:
<html:pre>fips-mode-setup --enable</html:pre>



To enable strict FIPS compliance, the fips=1 kernel option needs to be added to the kernel boot
parameters during system installation so key generation is done with FIPS-approved algorithms
and continuous monitoring tests in place.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">The system needs to be rebooted for these changes to take effect.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="regulatory">System Crypto Modules must be provided by a vendor that undergoes FIPS-140 certifications.
FIPS-140 is applicable to all Federal agencies that use cryptographic-based security
systems to protect sensitive information in computer and telecommunication systems
(including voice systems) as defined in Section 5131 of the Information Technology
Management Reform Act of 1996, Public Law 104-106. This standard shall be used in designing
and implementing cryptographic modules that Federal departments and agencies operate or are
operated for them under contract.
See <html:b><html:a href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf">https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf</html:a></html:b>
To meet this, the system has to have cryptographic software provided by a vendor that has
undergone this certification. This means providing documentation, test results, design
information, and independent third party review by an accredited lab. While open source
software is capable of meeting this, it does not meet FIPS-140 unless the vendor submits to
this process.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000033-GPOS-00014</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000125-GPOS-00065</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000393-GPOS-00173</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000394-GPOS-00174</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000396-GPOS-00176</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000423-GPOS-00187</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000478-GPOS-00223</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Use of weak or untested encryption algorithms undermines the purposes of utilizing encryption to
protect data. The operating system must implement cryptographic modules adhering to the higher
standards approved by the federal government since this provides assurance they have been tested
and validated.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#not_osbuild_and_system_with_kernel"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_crypto_fips_enabled:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_crypto_fips_enabled_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_crypto">
              <xccdf-1.2:title>System Cryptographic Policies</xccdf-1.2:title>
              <xccdf-1.2:description>Linux has the capability to centrally configure cryptographic polices. The command
<html:code>update-crypto-policies</html:code> is used to set the policy applicable for the various
cryptographic back-ends, such as SSL/TLS libraries. The configured cryptographic
policies will be the default policy used by these backends unless the application
user configures them otherwise. When the system has been configured to use the
centralized cryptographic policies, the administrator is assured that any application
that utilizes the supported backends will follow a policy that adheres to the
configured profile.

Currently the supported backends are:
<html:ul><html:li>GnuTLS library</html:li><html:li>OpenSSL library</html:li><html:li>NSS library</html:li><html:li>OpenJDK</html:li><html:li>Libkrb5</html:li><html:li>BIND</html:li><html:li>OpenSSH</html:li></html:ul>
Applications and languages which rely on any of these backends will follow the
system policies as well. Examples are apache httpd, nginx, php, and others.</xccdf-1.2:description>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_size" interactive="true" type="string">
                <xccdf-1.2:title>SSH client RekeyLimit - size</xccdf-1.2:title>
                <xccdf-1.2:description>Specify the size component of the rekey limit. This limit signifies amount
of data. After this amount of data is transferred through the connection,
the session key is renegotiated. The number is followed by K, M or G for
kilobytes, megabytes or gigabytes. Note that the RekeyLimit can be also
configured according to elapsed time.</xccdf-1.2:description>
                <xccdf-1.2:value>512M</xccdf-1.2:value>
                <xccdf-1.2:value selector="512M">512M</xccdf-1.2:value>
                <xccdf-1.2:value selector="1G">1G</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_time" interactive="true" type="string">
                <xccdf-1.2:title>SSH client RekeyLimit - time</xccdf-1.2:title>
                <xccdf-1.2:description>Specify the time component of the rekey limit. The session key is
renegotiated after the defined amount of time passes. The number is followed
by units such as H or M for hours or minutes. Note that the RekeyLimit can
be also configured according to amount of transferred data.</xccdf-1.2:description>
                <xccdf-1.2:value>1h</xccdf-1.2:value>
                <xccdf-1.2:value selector="1hour">1h</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_system_crypto_policy" type="string">
                <xccdf-1.2:title>The system-provided crypto policies</xccdf-1.2:title>
                <xccdf-1.2:description>Specify the crypto policy for the system.</xccdf-1.2:description>
                <xccdf-1.2:value>DEFAULT</xccdf-1.2:value>
                <xccdf-1.2:value selector="default_policy">DEFAULT</xccdf-1.2:value>
                <xccdf-1.2:value selector="default_nosha1">DEFAULT:NO-SHA1</xccdf-1.2:value>
                <xccdf-1.2:value selector="fips">FIPS</xccdf-1.2:value>
                <xccdf-1.2:value selector="fips_ospp">FIPS:OSPP</xccdf-1.2:value>
                <xccdf-1.2:value selector="fips_stig">FIPS:STIG</xccdf-1.2:value>
                <xccdf-1.2:value selector="legacy">LEGACY</xccdf-1.2:value>
                <xccdf-1.2:value selector="future">FUTURE</xccdf-1.2:value>
                <xccdf-1.2:value selector="next">NEXT</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_crypto-policies_installed" selected="false" severity="medium">
                <xccdf-1.2:title>Install crypto-policies package</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>crypto-policies</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install crypto-policies</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_COP.1(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_COP.1(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_COP.1(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_COP.1(4)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_CKM.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_CKM.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_TLSC_EXT.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000396-GPOS-00176</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000393-GPOS-00173</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000394-GPOS-00174</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010015</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-279933r1156352_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Centralized cryptographic policies simplify applying secure ciphers across an operating system and
the applications that run on that operating system. Use of weak or untested encryption algorithms
undermines the purposes of utilizing encryption to protect data.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_crypto-policies_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh">
if ! rpm -q --quiet "crypto-policies" ; then
    yum install -y "crypto-policies"
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_crypto-policies_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Ensure crypto-policies is installed
  ansible.builtin.package:
    name: crypto-policies
    state: present
  tags:
  - DISA-STIG-RHEL-08-010015
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_crypto-policies_installed
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_crypto-policies_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_crypto-policies

class install_crypto-policies {
  package { 'crypto-policies':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_crypto-policies_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=crypto-policies
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="package_crypto-policies_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "crypto-policies"
version = "*"
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_crypto-policies_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install crypto-policies
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_crypto-policies_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install crypto-policies
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_crypto-policies_installed:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_crypto-policies_installed_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_bind_crypto_policy" selected="false" severity="high">
                <xccdf-1.2:title>Configure BIND to use System Crypto Policy</xccdf-1.2:title>
                <xccdf-1.2:description>Crypto Policies provide a centralized control over crypto algorithms usage of many packages.
BIND is supported by crypto policy, but the BIND configuration may be
set up to ignore it.

To check that Crypto Policies settings are configured correctly, ensure that the <html:code>/etc/named.conf</html:code>
includes the appropriate configuration:
In the <html:code>options</html:code> section of <html:code>/etc/named.conf</html:code>, make sure that the following line
is not commented out or superseded by later includes:
<html:code>include "/etc/crypto-policies/back-ends/bind.config";</html:code></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000423-GPOS-00187</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000426-GPOS-00190</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010275</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-279931r1156346_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Overriding the system crypto policy makes the behavior of the BIND service violate expectations,
and makes system configuration more fragmented.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_bind"/>
                <xccdf-1.2:fix id="configure_bind_crypto_policy" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q bind; then

function remediate_bind_crypto_policy() {
	CONFIG_FILE="/etc/named.conf"
	if test -f "$CONFIG_FILE"; then
		sed -i 's|options {|&amp;\n\tinclude "/etc/crypto-policies/back-ends/bind.config";|' "$CONFIG_FILE"
		return 0
	else
		echo "Aborting remediation as '$CONFIG_FILE' was not even found." &gt;&amp;2
		return 1
	fi
}

remediate_bind_crypto_policy

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="configure_bind_crypto_policy" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010275
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - configure_bind_crypto_policy
  - configure_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed

- name: Configure BIND to use System Crypto Policy - Check BIND configuration file
    exists
  ansible.builtin.stat:
    path: /etc/named.conf
  register: bind_config_file
  when: '"bind" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010275
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - configure_bind_crypto_policy
  - configure_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed

- name: Configure BIND to use System Crypto Policy - Aborting remediation, file not
    found
  ansible.builtin.debug:
    msg: Aborting remediation as '/etc/named.conf' was not found.
  when:
  - '"bind" in ansible_facts.packages'
  - not bind_config_file.stat.exists
  tags:
  - DISA-STIG-RHEL-08-010275
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - configure_bind_crypto_policy
  - configure_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed

- name: Configure BIND to use System Crypto Policy - Insert crypto-policy into BIND
    config
  ansible.builtin.lineinfile:
    path: /etc/named.conf
    insertafter: ^\s*options\s*{
    line: ' include "/etc/crypto-policies/back-ends/bind.config";'
    state: present
  when:
  - '"bind" in ansible_facts.packages'
  - bind_config_file.stat.exists
  tags:
  - DISA-STIG-RHEL-08-010275
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - configure_bind_crypto_policy
  - configure_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-configure_bind_crypto_policy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_bind_crypto_policy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_crypto_policy" selected="false" severity="high">
                <xccdf-1.2:title>Configure System Cryptography Policy</xccdf-1.2:title>
                <xccdf-1.2:description>To configure the system cryptography policy to use ciphers only from the <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_system_crypto_policy" use="legacy"/></html:code>
policy, run the following command:
<html:pre>$ sudo update-crypto-policies --set <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_system_crypto_policy" use="legacy"/></html:pre>
The rule checks if settings for selected crypto policy are configured as expected. Configuration files in the <html:code>/etc/crypto-policies/back-ends</html:code> are either symlinks to correct files provided by Crypto-policies package or they are regular files in case crypto policy customizations are applied.
Crypto policies may be customized by crypto policy modules, in which case it is delimited from the base policy using a colon.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">The system needs to be rebooted for these changes to take effect.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="regulatory">System Crypto Modules must be provided by a vendor that undergoes
FIPS-140 certifications.
FIPS-140 is applicable to all Federal agencies that use
cryptographic-based security systems to protect sensitive information
in computer and telecommunication systems (including voice systems) as
defined in Section 5131 of the Information Technology Management Reform
Act of 1996, Public Law 104-106. This standard shall be used in
designing and implementing cryptographic modules that Federal
departments and agencies operate or are operated for them under
contract. See <html:b><html:a href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf">https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf</html:a></html:b>
To meet this, the system has to have cryptographic software provided by
a vendor that has undergone this certification. This means providing
documentation, test results, design information, and independent third
party review by an accredited lab. While open source software is
capable of meeting this, it does not meet FIPS-140 unless the vendor
submits to this process.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MA-4(6)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_COP.1(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_COP.1(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_COP.1(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_COP.1(4)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_CKM.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_CKM.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_TLSC_EXT.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000396-GPOS-00176</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000393-GPOS-00173</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000394-GPOS-00174</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1446</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010020</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010270</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010290</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010291</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010296</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010297</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230223r1155356_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-279932r1156349_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230251r1155370_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230252r1155364_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-272482r1155367_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-272483r1155361_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Centralized cryptographic policies simplify applying secure ciphers across an operating system and
the applications that run on that operating system. Use of weak or untested encryption algorithms
undermines the purposes of utilizing encryption to protect data.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="configure_crypto_policy" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh">
var_system_crypto_policy='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_system_crypto_policy" use="legacy"/>'




stderr_of_call=$(update-crypto-policies --set ${var_system_crypto_policy} 2&gt;&amp;1 &gt; /dev/null)
rc=$?

if test "$rc" = 127; then
	echo "$stderr_of_call" &gt;&amp;2
	echo "Make sure that the script is installed on the remediated system." &gt;&amp;2
	echo "See output of the 'dnf provides update-crypto-policies' command" &gt;&amp;2
	echo "to see what package to (re)install" &gt;&amp;2

	false  # end with an error code
elif test "$rc" != 0; then
	echo "Error invoking the update-crypto-policies script: $stderr_of_call" &gt;&amp;2
	false  # end with an error code
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="configure_crypto_policy" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: XCCDF Value var_system_crypto_policy # promote to variable
  set_fact:
    var_system_crypto_policy: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_system_crypto_policy" use="legacy"/>
  tags:
    - always

- name: Configure System Cryptography Policy - Check current crypto policy (runtime)
  ansible.builtin.command: /usr/bin/update-crypto-policies --show
  register: current_crypto_policy
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010020
  - DISA-STIG-RHEL-08-010270
  - DISA-STIG-RHEL-08-010290
  - DISA-STIG-RHEL-08-010291
  - DISA-STIG-RHEL-08-010296
  - DISA-STIG-RHEL-08-010297
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.7
  - configure_crypto_policy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy

- name: Configure System Cryptography Policy - Get mtime of /etc/crypto-policies/config
  ansible.builtin.stat:
    path: /etc/crypto-policies/config
  register: config_file_stat
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010020
  - DISA-STIG-RHEL-08-010270
  - DISA-STIG-RHEL-08-010290
  - DISA-STIG-RHEL-08-010291
  - DISA-STIG-RHEL-08-010296
  - DISA-STIG-RHEL-08-010297
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.7
  - configure_crypto_policy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy

- name: Configure System Cryptography Policy - Get mtime of /etc/crypto-policies/state/current
  ansible.builtin.stat:
    path: /etc/crypto-policies/state/current
  register: current_file_stat
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010020
  - DISA-STIG-RHEL-08-010270
  - DISA-STIG-RHEL-08-010290
  - DISA-STIG-RHEL-08-010291
  - DISA-STIG-RHEL-08-010296
  - DISA-STIG-RHEL-08-010297
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.7
  - configure_crypto_policy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy

- name: Configure System Cryptography Policy - Check existence of /etc/crypto-policies/back-ends/nss.config
  ansible.builtin.stat:
    path: /etc/crypto-policies/back-ends/nss.config
  register: nss_config_stat
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010020
  - DISA-STIG-RHEL-08-010270
  - DISA-STIG-RHEL-08-010290
  - DISA-STIG-RHEL-08-010291
  - DISA-STIG-RHEL-08-010296
  - DISA-STIG-RHEL-08-010297
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.7
  - configure_crypto_policy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy

- name: Configure System Cryptography Policy - Verify that Crypto Policy is Set (runtime)
  ansible.builtin.command: /usr/bin/update-crypto-policies --set {{ var_system_crypto_policy
    }}
  when: (current_crypto_policy.stdout.strip() != var_system_crypto_policy) or (config_file_stat.stat.exists
    and current_file_stat.stat.exists and config_file_stat.stat.mtime &gt; current_file_stat.stat.mtime)
    or (not nss_config_stat.stat.exists)
  tags:
  - DISA-STIG-RHEL-08-010020
  - DISA-STIG-RHEL-08-010270
  - DISA-STIG-RHEL-08-010290
  - DISA-STIG-RHEL-08-010291
  - DISA-STIG-RHEL-08-010296
  - DISA-STIG-RHEL-08-010297
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.7
  - configure_crypto_policy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="configure_crypto_policy" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
        - name: configure-crypto-policy.service
          enabled: true
          contents: |
            [Unit]
            Before=kubelet.service
            [Service]
            Type=oneshot
            ExecStart=update-crypto-policies --set {{.var_system_crypto_policy}}
            RemainAfterExit=yes
            [Install]
            WantedBy=multi-user.target
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_system_crypto_policy:var:1" value-id="xccdf_org.ssgproject.content_value_var_system_crypto_policy"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-configure_crypto_policy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_crypto_policy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_custom_crypto_policy_cis" selected="false" severity="medium">
                <xccdf-1.2:title>Implement Custom Crypto Policy Modules for CIS Benchmark</xccdf-1.2:title>
                <xccdf-1.2:description>Create a custom crypto policy module to enforce the use of strong ciphers and MACs in SSHD, disable CBC mode ciphers in SSHD and disable the use of weak MACs globally.


Add the following line to the file <html:code>/etc/crypto-policies/policies/modules/NO-SSHCBC.pmod</html:code>:
<html:pre>
cipher@SSH = -*-CBC
</html:pre>


Add the following line to the file <html:code>/etc/crypto-policies/policies/modules/NO-SSHWEAKCIPHERS.pmod</html:code>:
<html:pre>
cipher@SSH = -3DES-CBC -AES-128-CBC -AES-192-CBC -AES-256-CBC -CHACHA20-POLY1305
</html:pre>


Add the following line to the file <html:code>/etc/crypto-policies/policies/modules/NO-SSHWEAKMACS.pmod</html:code>:
<html:pre>
mac@SSH = -HMAC-MD5* -UMAC-64* -UMAC-128*
</html:pre>


Add the following line to the file <html:code>/etc/crypto-policies/policies/modules/NO-WEAKMAC.pmod</html:code>:
<html:pre>
mac = -*-128*
</html:pre>

Then, set the system wide crypto policy to use the custom policy.
<html:pre>
$ sudo update-crypto-policies --set DEFAULT:NO-SHA1:NO-SSHCBC:NO-SSHWEAKCIPHERS:NO-SSHWEAKMACS:NO-WEAKMAC
</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.17</xccdf-1.2:reference>
                <xccdf-1.2:rationale>CBC mode ciphers are vulnerable to certain attacks, such as the BEAST attack.
Disabling CBC mode ciphers helps protect against these attacks and ensures that only
strong, proven cryptographic algorithms are used to protect SSH communications.
Weak ciphers that are used for authentication to the cryptographic module cannot be
relied upon to provide confidentiality or integrity, and system data may be compromised.
Message Authentication Codes (MACs) are cryptographic mechanisms used to verify the
integrity and authenticity of data transmitted over SSH connections. Weak MACs that
are used for authentication to the cryptographic module cannot be relied upon to
provide integrity, and system data may be compromised. Implementing a custom crypto
policy that disables weak MAC algorithms helps ensure that only strong, proven
cryptographic algorithms are used to protect SSH communications.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="configure_custom_crypto_policy_cis" reboot="true" strategy="configure" system="urn:xccdf:fix:script:sh">
expected_crypto_policy="DEFAULT:NO-SHA1"


expected_crypto_policy="${expected_crypto_policy}:NO-SSHCBC"
cat &lt;&lt; 'EOF' &gt; /etc/crypto-policies/policies/modules/NO-SSHCBC.pmod
cipher@SSH = -*-CBC
EOF

expected_crypto_policy="${expected_crypto_policy}:NO-SSHWEAKCIPHERS"
cat &lt;&lt; 'EOF' &gt; /etc/crypto-policies/policies/modules/NO-SSHWEAKCIPHERS.pmod
cipher@SSH = -3DES-CBC -AES-128-CBC -AES-192-CBC -AES-256-CBC -CHACHA20-POLY1305
EOF

expected_crypto_policy="${expected_crypto_policy}:NO-SSHWEAKMACS"
cat &lt;&lt; 'EOF' &gt; /etc/crypto-policies/policies/modules/NO-SSHWEAKMACS.pmod
mac@SSH = -HMAC-MD5* -UMAC-64* -UMAC-128*
EOF

expected_crypto_policy="${expected_crypto_policy}:NO-WEAKMAC"
cat &lt;&lt; 'EOF' &gt; /etc/crypto-policies/policies/modules/NO-WEAKMAC.pmod
mac = -*-128*
EOF


current_crypto_policy=$(update-crypto-policies --show)

if [[ "$current_crypto_policy" != "$expected_crypto_policy" ]] ; then
    update-crypto-policies --set "$expected_crypto_policy"
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="configure_custom_crypto_policy_cis" reboot="true" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Implement Custom Crypto Policy Modules for CIS Benchmark - Set the base crypto
    policy
  ansible.builtin.set_fact:
    expected_crypto_policy: DEFAULT:NO-SHA1
  tags:
  - configure_custom_crypto_policy_cis
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required

- name: Implement Custom Crypto Policy Modules for CIS Benchmark - Create custom crypto
    policy module NO-SSHCBC
  ansible.builtin.lineinfile:
    path: /etc/crypto-policies/policies/modules/NO-SSHCBC.pmod
    owner: root
    group: root
    mode: '0644'
    line: cipher@SSH = -*-CBC
    create: true
    regexp: cipher@SSH
  tags:
  - configure_custom_crypto_policy_cis
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required

- name: Implement Custom Crypto Policy Modules for CIS Benchmark - Update the expected
    policy
  ansible.builtin.set_fact:
    expected_crypto_policy: '{{ expected_crypto_policy + '':NO-SSHCBC'' }}'
  tags:
  - configure_custom_crypto_policy_cis
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required

- name: Implement Custom Crypto Policy Modules for CIS Benchmark - Create custom crypto
    policy module NO-SSHWEAKCIPHERS
  ansible.builtin.lineinfile:
    path: /etc/crypto-policies/policies/modules/NO-SSHWEAKCIPHERS.pmod
    owner: root
    group: root
    mode: '0644'
    line: cipher@SSH = -3DES-CBC -AES-128-CBC -AES-192-CBC -AES-256-CBC -CHACHA20-POLY1305
    create: true
    regexp: cipher@SSH
  tags:
  - configure_custom_crypto_policy_cis
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required

- name: Implement Custom Crypto Policy Modules for CIS Benchmark - Update the expected
    policy
  ansible.builtin.set_fact:
    expected_crypto_policy: '{{ expected_crypto_policy + '':NO-SSHWEAKCIPHERS'' }}'
  tags:
  - configure_custom_crypto_policy_cis
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required

- name: Implement Custom Crypto Policy Modules for CIS Benchmark - Create custom crypto
    policy module NO-SSHWEAKMACS
  ansible.builtin.lineinfile:
    path: /etc/crypto-policies/policies/modules/NO-SSHWEAKMACS.pmod
    owner: root
    group: root
    mode: '0644'
    line: mac@SSH = -HMAC-MD5* -UMAC-64* -UMAC-128*
    create: true
    regexp: mac@SSH
  tags:
  - configure_custom_crypto_policy_cis
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required

- name: Implement Custom Crypto Policy Modules for CIS Benchmark - Update the expected
    policy
  ansible.builtin.set_fact:
    expected_crypto_policy: '{{ expected_crypto_policy + '':NO-SSHWEAKMACS'' }}'
  tags:
  - configure_custom_crypto_policy_cis
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required

- name: Implement Custom Crypto Policy Modules for CIS Benchmark - Create custom crypto
    policy module NO-WEAKMAC
  ansible.builtin.lineinfile:
    path: /etc/crypto-policies/policies/modules/NO-WEAKMAC.pmod
    owner: root
    group: root
    mode: '0644'
    line: mac = -*-128*
    create: true
    regexp: mac
  tags:
  - configure_custom_crypto_policy_cis
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required

- name: Implement Custom Crypto Policy Modules for CIS Benchmark - Update the expected
    policy
  ansible.builtin.set_fact:
    expected_crypto_policy: '{{ expected_crypto_policy + '':NO-WEAKMAC'' }}'
  tags:
  - configure_custom_crypto_policy_cis
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required

- name: Implement Custom Crypto Policy Modules for CIS Benchmark - Check current crypto
    policy
  ansible.builtin.command: update-crypto-policies --show
  register: current_crypto_policy
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - configure_custom_crypto_policy_cis
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required

- name: Implement Custom Crypto Policy Modules for CIS Benchmark - Update crypto-policies
  ansible.builtin.command: update-crypto-policies --set {{ expected_crypto_policy
    }}
  when: current_crypto_policy.stdout.strip() != expected_crypto_policy
  tags:
  - configure_custom_crypto_policy_cis
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-configure_custom_crypto_policy_cis:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_custom_crypto_policy_cis_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_gnutls_tls_crypto_policy" selected="false" severity="medium">
                <xccdf-1.2:title>Configure GnuTLS library to use DoD-approved TLS Encryption</xccdf-1.2:title>
                <xccdf-1.2:description>Crypto Policies provide a centralized control over crypto algorithms usage of many packages.
GnuTLS is supported by system crypto policy, but the GnuTLS configuration may be
set up to ignore it.

To check that Crypto Policies settings are configured correctly, ensure that
<html:code>/etc/crypto-policies/back-ends/gnutls.config</html:code> contains the following
line and is not commented out:
<html:code>+VERS-ALL:-VERS-DTLS0.9:-VERS-TLS1.1:-VERS-TLS1.0:-VERS-SSL3.0:-VERS-DTLS1.0</html:code>

These keywords are order-independent, so the line can be in any order. GnuTLS will then prefer the highest version.</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000423-GPOS-00187</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Overriding the system crypto policy makes the behavior of the GnuTLS
library violate expectations, and makes system configuration more
fragmented.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="configure_gnutls_tls_crypto_policy" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:sh">
CONF_FILE=/etc/crypto-policies/back-ends/gnutls.config
correct_value='+VERS-ALL:-VERS-DTLS0.9:-VERS-TLS1.1:-VERS-TLS1.0:-VERS-SSL3.0:-VERS-DTLS1.0'

grep -q ${correct_value} ${CONF_FILE}

if [[ $? -ne 0 ]]; then
    # We need to get the existing value, using PCRE to maintain same regex
    existing_value=$(grep -Po '(\+VERS-ALL(?::-VERS-[A-Z]+\d\.\d)+)' ${CONF_FILE})

    if [[ ! -z ${existing_value} ]]; then
        # replace existing_value with correct_value
        sed -i "s/${existing_value}/${correct_value}/g" ${CONF_FILE}
    else
        # ***NOTE*** #
        # This probably means this file is not here or it's been modified
        # unintentionally.
        # ********** #
        # echo correct_value to end
        echo ${correct_value} &gt;&gt; ${CONF_FILE}
    fi
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="configure_gnutls_tls_crypto_policy" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: 'Configure GnuTLS library to use DoD-approved TLS Encryption: set_fact'
  ansible.builtin.set_fact:
    path: /etc/crypto-policies/back-ends/gnutls.config
    correct_value: +VERS-ALL:-VERS-DTLS0.9:-VERS-TLS1.1:-VERS-TLS1.0:-VERS-SSL3.0:-VERS-DTLS1.0
    lineinfile_reg: \+VERS-ALL:-VERS-DTLS0\.9:-VERS-TLS1\.1:-VERS-TLS1\.0:-VERS-SSL3\.0:-VERS-DTLS1\.0
  tags:
  - NIST-800-53-AC-17(2)
  - configure_gnutls_tls_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure GnuTLS library to use DoD-approved TLS Encryption: stat'
  ansible.builtin.stat:
    path: '{{ path }}'
    follow: true
  register: gnutls_file
  tags:
  - NIST-800-53-AC-17(2)
  - configure_gnutls_tls_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure GnuTLS library to use DoD-approved TLS Encryption: Add'
  ansible.builtin.lineinfile:
    path: '{{ path }}'
    regexp: '{{ lineinfile_reg }}'
    line: '{{ correct_value }}'
    create: true
  when: not gnutls_file.stat.exists or gnutls_file.stat.size &lt;= correct_value|length
  tags:
  - NIST-800-53-AC-17(2)
  - configure_gnutls_tls_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Configure GnuTLS library to use DoD-approved TLS Encryption
  block:

  - name: 'Configure GnuTLS library to use DoD-approved TLS Encryption: Existing value
      check'
    ansible.builtin.lineinfile:
      path: '{{ path }}'
      create: false
      regexp: '{{ lineinfile_reg }}'
      state: absent
    check_mode: true
    changed_when: false
    register: gnutls

  - name: 'Configure GnuTLS library to use DoD-approved TLS Encryption: Update'
    ansible.builtin.replace:
      path: '{{ path }}'
      regexp: (\+VERS-ALL(?::-VERS-[A-Z]+\d\.\d)+)
      replace: '{{ correct_value }}'
    when: gnutls.found is defined and gnutls.found != 1
  when: gnutls_file.stat.exists and gnutls_file.stat.size &gt; correct_value|length
  tags:
  - NIST-800-53-AC-17(2)
  - configure_gnutls_tls_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-configure_gnutls_tls_crypto_policy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_gnutls_tls_crypto_policy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_kerberos_crypto_policy" selected="false" severity="high">
                <xccdf-1.2:title>Configure Kerberos to use System Crypto Policy</xccdf-1.2:title>
                <xccdf-1.2:description>Crypto Policies provide a centralized control over crypto algorithms usage of many packages.
Kerberos is supported by crypto policy, but it's configuration may be
set up to ignore it.
To check that Crypto Policies settings for Kerberos are configured correctly, examine that there is a symlink at
/etc/krb5.conf.d/crypto-policies targeting /etc/cypto-policies/back-ends/krb5.config.
If the symlink exists, Kerberos is configured to use the system-wide crypto policy settings.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000120-GPOS-00061</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0418</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1055</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1402</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Overriding the system crypto policy makes the behavior of Kerberos violate expectations,
and makes system configuration more fragmented.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_krb5-libs"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="configure_kerberos_crypto_policy" reboot="true" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q krb5-libs; then

rm -f /etc/krb5.conf.d/crypto-policies
ln -s /etc/crypto-policies/back-ends/krb5.config /etc/krb5.conf.d/crypto-policies

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="configure_kerberos_crypto_policy" reboot="true" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - configure_kerberos_crypto_policy
  - configure_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - reboot_required

- name: Configure Kerberos to use System Crypto Policy
  ansible.builtin.file:
    src: /etc/crypto-policies/back-ends/krb5.config
    path: /etc/krb5.conf.d/crypto-policies
    state: link
  when: '"krb5-libs" in ansible_facts.packages'
  tags:
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - configure_kerberos_crypto_policy
  - configure_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - reboot_required
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-configure_kerberos_crypto_policy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_kerberos_crypto_policy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_libreswan_crypto_policy" selected="false" severity="high">
                <xccdf-1.2:title>Configure Libreswan to use System Crypto Policy</xccdf-1.2:title>
                <xccdf-1.2:description>Crypto Policies provide a centralized control over crypto algorithms usage of many packages.
Libreswan is supported by system crypto policy, but the Libreswan configuration may be
set up to ignore it.

To check that Crypto Policies settings are configured correctly, ensure that the <html:code>/etc/ipsec.conf</html:code>
includes the appropriate configuration file.
In <html:code>/etc/ipsec.conf</html:code>, make sure that the following line
is not commented out or superseded by later includes:
<html:code>include /etc/crypto-policies/back-ends/libreswan.config</html:code></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MA-4(6)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000033-GPOS-00014</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010280</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-279930r1156343_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Overriding the system crypto policy makes the behavior of the Libreswan
service violate expectations, and makes system configuration more
fragmented.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_libreswan_and_system_with_kernel"/>
                <xccdf-1.2:fix id="configure_libreswan_crypto_policy" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q libreswan &amp;&amp; rpm --quiet -q kernel ) ); then

function remediate_libreswan_crypto_policy() {
    CONFIG_FILE="/etc/ipsec.conf"
    if ! grep -qP "^\s*include\s+/etc/crypto-policies/back-ends/libreswan.config\s*(?:#.*)?$" "$CONFIG_FILE" ; then
        # the file might not end with a new line
        echo -e '\ninclude /etc/crypto-policies/back-ends/libreswan.config' &gt;&gt; "$CONFIG_FILE"
    fi
    return 0
}

remediate_libreswan_crypto_policy

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="configure_libreswan_crypto_policy" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010280
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - PCI-DSS-Req-2.2
  - configure_libreswan_crypto_policy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy

- name: Configure Libreswan to use System Crypto Policy
  ansible.builtin.lineinfile:
    path: /etc/ipsec.conf
    line: include /etc/crypto-policies/back-ends/libreswan.config
    create: true
  when: ( "libreswan" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - DISA-STIG-RHEL-08-010280
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - PCI-DSS-Req-2.2
  - configure_libreswan_crypto_policy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-configure_libreswan_crypto_policy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_libreswan_crypto_policy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_openssl_crypto_policy" selected="false" severity="medium">
                <xccdf-1.2:title>Configure OpenSSL library to use System Crypto Policy</xccdf-1.2:title>
                <xccdf-1.2:description>Crypto Policies provide a centralized control over crypto algorithms usage of many packages.
OpenSSL is supported by crypto policy, but the OpenSSL configuration may be
set up to ignore it.
To check that Crypto Policies settings are configured correctly, you have to examine the OpenSSL config file
available under <html:code>/etc/pki/tls/openssl.cnf</html:code>.
This file has the <html:code>ini</html:code> format, and it enables crypto policy support
if there is a <html:code>[ crypto_policy ]</html:code> section that contains the <html:code>.include /etc/crypto-policies/back-ends/opensslcnf.config</html:code> directive.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MA-4(6)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_CKM.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_CKM.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_CKM.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_COP.1/ENCRYPT</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_COP.1/HASH</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_COP.1/SIGN</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_COP.1/KEYHMAC</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_TLSC_EXT.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_TLSC_EXT.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Overriding the system crypto policy makes the behavior of the Java runtime violates expectations,
and makes system configuration more fragmented.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_openssl"/>
                <xccdf-1.2:fix id="configure_openssl_crypto_policy" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q openssl; then

OPENSSL_CRYPTO_POLICY_SECTION='[ crypto_policy ]'
OPENSSL_CRYPTO_POLICY_SECTION_REGEX='\[\s*crypto_policy\s*\]'

OPENSSL_CRYPTO_POLICY_INCLUSION='.include /etc/crypto-policies/back-ends/opensslcnf.config'

OPENSSL_CRYPTO_POLICY_INCLUSION_REGEX='^\s*\.include\s*(?:=\s*)?/etc/crypto-policies/back-ends/opensslcnf.config$'



  


function remediate_openssl_crypto_policy() {
	CONFIG_FILE=/etc/pki/tls/openssl.cnf
	if test -f "$CONFIG_FILE"; then
		if ! grep -q "^\\s*$OPENSSL_CRYPTO_POLICY_SECTION_REGEX" "$CONFIG_FILE"; then
			printf '\n%s\n\n%s' "$OPENSSL_CRYPTO_POLICY_SECTION" "$OPENSSL_CRYPTO_POLICY_INCLUSION" &gt;&gt; "$CONFIG_FILE"
			return 0
		elif ! grep -q "^\\s*$OPENSSL_CRYPTO_POLICY_INCLUSION_REGEX" "$CONFIG_FILE"; then
			sed -i "s|$OPENSSL_CRYPTO_POLICY_SECTION_REGEX|&amp;\\n\\n$OPENSSL_CRYPTO_POLICY_INCLUSION\\n|" "$CONFIG_FILE"
			return 0
		fi
	else
		echo "Aborting remediation as '$CONFIG_FILE' was not even found." &gt;&amp;2
		return 1
	fi
}

remediate_openssl_crypto_policy

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="configure_openssl_crypto_policy" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - PCI-DSS-Req-2.2
  - configure_openssl_crypto_policy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Configure OpenSSL library to use System Crypto Policy - Search for crypto_policy
    Section
  ansible.builtin.find:
    paths: /etc/pki/tls
    patterns: openssl.cnf
    contains: ^\s*\[\s*crypto_policy\s*]
  register: test_crypto_policy_group
  when: '"openssl" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - PCI-DSS-Req-2.2
  - configure_openssl_crypto_policy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Configure OpenSSL library to use System Crypto Policy - Search for crypto_policy
    Section Together With .include Directive
  ansible.builtin.find:
    paths: /etc/pki/tls
    patterns: openssl.cnf
    contains: ^\s*\.include\s*(?:=\s*)?/etc/crypto-policies/back-ends/opensslcnf.config$
  register: test_crypto_policy_include_directive
  when: '"openssl" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - PCI-DSS-Req-2.2
  - configure_openssl_crypto_policy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Configure OpenSSL library to use System Crypto Policy - Add .include Line
    for opensslcnf.config File in crypto_policy Section
  ansible.builtin.lineinfile:
    create: true
    insertafter: ^\s*\[\s*crypto_policy\s*]\s*
    line: .include /etc/crypto-policies/back-ends/opensslcnf.config
    path: /etc/pki/tls/openssl.cnf
  when:
  - '"openssl" in ansible_facts.packages'
  - test_crypto_policy_group.matched &gt; 0
  - test_crypto_policy_include_directive.matched == 0
  tags:
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - PCI-DSS-Req-2.2
  - configure_openssl_crypto_policy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Configure OpenSSL library to use System Crypto Policy - Add crypto_policy
    Section With .include for opensslcnf.config File
  ansible.builtin.lineinfile:
    create: true
    line: |-
      [crypto_policy]
      .include /etc/crypto-policies/back-ends/opensslcnf.config
    path: /etc/pki/tls/openssl.cnf
  when:
  - '"openssl" in ansible_facts.packages'
  - test_crypto_policy_group.matched == 0
  tags:
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - PCI-DSS-Req-2.2
  - configure_openssl_crypto_policy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-configure_openssl_crypto_policy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_openssl_crypto_policy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_openssl_tls_crypto_policy" selected="false" severity="medium">
                <xccdf-1.2:title>Configure OpenSSL library to use TLS Encryption</xccdf-1.2:title>
                <xccdf-1.2:description>Crypto Policies are means of enforcing certain cryptographic settings for
selected applications including OpenSSL. OpenSSL is by default configured to
modify its configuration based on currently configured Crypto Policy.
Editing the Crypto Policy back-end is not recommended.

Check the crypto-policies(7) man page and choose a policy that configures TLS
protocol to version 1.2 or higher, for example DEFAULT, FUTURE or FIPS policy.
Or create and apply a custom policy that restricts minimum TLS version to 1.2.

For example for versions prior to crypto-policies-20210617-1.gitc776d3e.el8.noarch
this is expected:

<html:pre>$ sudo grep -i MinProtocol /etc/crypto-policies/back-ends/opensslcnf.config

MinProtocol = TLSv1.2
</html:pre>

Or for version crypto-policies-20210617-1.gitc776d3e.el8.noarch and newer this is
expected:

<html:pre>$ sudo grep -i MinProtocol /etc/crypto-policies/back-ends/opensslcnf.config

TLS.MinProtocol = TLSv1.2
DTLS.MinProtocol = DTLSv1.2</html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">This rule doesn't come with a remediation, automatically changing the crypto-policies may be too disruptive.
Ensure the variable <html:code>xccdf_org.ssgproject.content_value_var_system_crypto_policy</html:code> is set to a
Crypto Policy that satisfies OpenSSL minimum TLS protocol version 1.2. Custom policies may be applied too.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000125-GPOS-00065</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000393-GPOS-00173</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000394-GPOS-00174</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Without cryptographic integrity protections, information can be altered by
unauthorized users without detection.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_openssl"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-configure_openssl_tls_crypto_policy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_openssl_tls_crypto_policy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy" selected="false" severity="medium">
                <xccdf-1.2:title>Configure SSH to use System Crypto Policy</xccdf-1.2:title>
                <xccdf-1.2:description>Crypto Policies provide a centralized control over crypto algorithms usage of many packages.
SSH is supported by crypto policy, but the SSH configuration may be
set up to ignore it.
To check that Crypto Policies settings are configured correctly, ensure that
the <html:code>CRYPTO_POLICY</html:code> variable is either commented or not set at all
in the <html:code>/etc/sysconfig/sshd</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MA-4(6)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_SSH_EXT.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_SSHS_EXT.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_SSHC_EXT.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0418</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Overriding the system crypto policy makes the behavior of the SSH service violate expectations,
and makes system configuration more fragmented.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix id="configure_ssh_crypto_policy" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SSH_CONF="/etc/sysconfig/sshd"

sed -i "/^\s*CRYPTO_POLICY.*$/Id" $SSH_CONF

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="configure_ssh_crypto_policy" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-13
  - PCI-DSS-Req-2.2
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.7
  - configure_ssh_crypto_policy
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required

- name: Configure SSH to use System Crypto Policy
  ansible.builtin.lineinfile:
    dest: /etc/sysconfig/sshd
    state: absent
    regexp: (?i)^\s*CRYPTO_POLICY.*$
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-13
  - PCI-DSS-Req-2.2
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.7
  - configure_ssh_crypto_policy
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-configure_ssh_crypto_policy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_ssh_crypto_policy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_harden_openssl_crypto_policy" selected="false" severity="medium">
                <xccdf-1.2:title>Harden OpenSSL Crypto Policy</xccdf-1.2:title>
                <xccdf-1.2:description>Crypto Policies are means of enforcing certain cryptographic settings for
selected applications including OpenSSL. OpenSSL is by default configured to
modify its configuration based on currently configured Crypto Policy.
However, in certain cases it might be needed to override the Crypto Policy
specific to OpenSSL and leave rest of the Crypto Policy intact. This can
be done by dropping a file named <html:code>opensslcnf-xxx.config</html:code>, replacing
<html:code>xxx</html:code> with arbitrary identifier, into
<html:code>/etc/crypto-policies/local.d</html:code>. This has to be followed by running
<html:code>update-crypto-policies</html:code> so that changes are applied. Changes are
propagated into <html:code>/etc/crypto-policies/back-ends/opensslcnf.config</html:code>.
This rule checks if this file contains predefined <html:code>Ciphersuites</html:code>
variable configured with predefined value.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-8(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000396-GPOS-00176</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000424-GPOS-00188</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000478-GPOS-00223</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The Common Criteria requirements specify that certain parameters for OpenSSL
are configured e.g. cipher suites. Currently particular requirements
specified by CC are stricter compared to any existing Crypto Policy.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="harden_openssl_crypto_policy" system="urn:xccdf:fix:script:sh">
cp="Ciphersuites = TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256"
file="/etc/crypto-policies/local.d/opensslcnf-ospp.config"
backend_file="/etc/crypto-policies/back-ends/opensslcnf.config"

sed -i "/Ciphersuites\s*=\s*/d" "$backend_file"
printf "\n%s\n" "$cp" &gt;&gt; "$file"
update-crypto-policies
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="harden_openssl_crypto_policy" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Harden OpenSSL Crypto Policy - Set fact - correct list of ciphersuites
  ansible.builtin.set_fact:
    correct_ciphersuites: TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256
  tags:
  - NIST-800-53-SC-13
  - NIST-800-53-SC-8(1)
  - harden_openssl_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Harden OpenSSL Crypto Policy - Check if /etc/crypto-policies/back-ends/opensslcnf.config
    exists
  ansible.builtin.stat:
    path: /etc/crypto-policies/back-ends/opensslcnf.config
  register: opensslcnf_config_stat
  failed_when: false
  tags:
  - NIST-800-53-SC-13
  - NIST-800-53-SC-8(1)
  - harden_openssl_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Harden OpenSSL Crypto Policy - Retrieve configuration from /etc/crypto-policies/back-ends/opensslcnf.config
  ansible.builtin.slurp:
    path: /etc/crypto-policies/back-ends/opensslcnf.config
  register: opensslcnf_config
  failed_when: false
  when: opensslcnf_config_stat.stat.exists
  tags:
  - NIST-800-53-SC-13
  - NIST-800-53-SC-8(1)
  - harden_openssl_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Harden OpenSSL Crypto Policy - Get ciphersuites from configuration
  ansible.builtin.set_fact:
    opensslcnf_config_ciphersuites: '{{ opensslcnf_config[''content''] | b64decode
      | regex_findall(''^Ciphersuites\s*=\s*(.*)$'',  multiline=True) }}'
  when: opensslcnf_config_stat.stat.exists
  tags:
  - NIST-800-53-SC-13
  - NIST-800-53-SC-8(1)
  - harden_openssl_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Harden OpenSSL Crypto Policy - Remove configuration from backend file /etc/crypto-policies/back-ends/opensslcnf.config
  ansible.builtin.lineinfile:
    path: /etc/crypto-policies/back-ends/opensslcnf.config
    regexp: Ciphersuites\s*=\s*.*
    state: absent
  when: opensslcnf_config_stat.stat.exists and (opensslcnf_config_ciphersuites | length
    == 0 or opensslcnf_config_ciphersuites | last != correct_ciphersuites)
  tags:
  - NIST-800-53-SC-13
  - NIST-800-53-SC-8(1)
  - harden_openssl_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Harden OpenSSL Crypto Policy - Ensure that the correct crypto policy configuration
    exists in /etc/crypto-policies/local.d/opensslcnf-ospp.config
  ansible.builtin.copy:
    dest: /etc/crypto-policies/local.d/opensslcnf-ospp.config
    content: |2

      Ciphersuites = TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256
  when: not opensslcnf_config_stat.stat.exists or opensslcnf_config_ciphersuites |
    length == 0 or opensslcnf_config_ciphersuites | last != correct_ciphersuites
  tags:
  - NIST-800-53-SC-13
  - NIST-800-53-SC-8(1)
  - harden_openssl_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Harden OpenSSL Crypto Policy - Update system crypto policy for changes to
    take effect
  ansible.builtin.command:
    cmd: update-crypto-policies
  when: not opensslcnf_config_stat.stat.exists or opensslcnf_config_ciphersuites |
    length == 0 or opensslcnf_config_ciphersuites | last != correct_ciphersuites
  tags:
  - NIST-800-53-SC-13
  - NIST-800-53-SC-8(1)
  - harden_openssl_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-harden_openssl_crypto_policy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-harden_openssl_crypto_policy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_harden_ssh_client_crypto_policy" selected="false" severity="medium">
                <xccdf-1.2:title>Harden SSH client Crypto Policy</xccdf-1.2:title>
                <xccdf-1.2:description>Crypto Policies are means of enforcing certain cryptographic settings for selected applications including OpenSSH client.
To override the system wide crypto policy for Openssh client, place a file in the <html:code>/etc/ssh/ssh_config.d</html:code> directory so that it is loaded before the <html:code>05-redhat.conf</html:code>. In this case it is the <html:code>/etc/ssh/ssh_config.d/02-ospp.conf</html:code> file containing parameters which need to be changed with respect to the crypto policy.
This rule checks if the file exists and if it contains required parameters and values which modify the Crypto Policy.
During the parsing process, as soon as Openssh client parses some configuration option and its value, it remembers it and ignores any subsequent overrides. The customization mechanism provided by crypto policies appends eventual customizations at the end of the system wide crypto policy. Therefore, if the crypto policy customization overrides some parameter which is already configured in the system wide crypto policy, the SSH client will not honor that customized parameter.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MA-4(6)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000033-GPOS-00014</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000393-GPOS-00173</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000394-GPOS-00174</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The Common Criteria requirements specify how certain parameters for OpenSSH Client are configured. Particular parameters are RekeyLimit, GSSAPIAuthentication, Ciphers, PubkeyAcceptedKeyTypes, MACs and KexAlgorithms. Currently particular requirements specified by CC are stricter compared to any existing Crypto Policy.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="harden_ssh_client_crypto_policy" system="urn:xccdf:fix:script:sh">
#the file starts with 02 so that it is loaded before the 05-redhat.conf which activates configuration provided by system vide crypto policy

file="/etc/ssh/ssh_config.d/02-ospp.conf"
echo -e "Match final all\n\
RekeyLimit 512M 1h\n\
GSSAPIAuthentication no\n\
Ciphers aes256-ctr,aes256-cbc,aes128-ctr,aes128-cbc\n\
PubkeyAcceptedKeyTypes ssh-rsa,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256\n\
MACs hmac-sha2-512,hmac-sha2-256\n\
KexAlgorithms ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group14-sha1\n" &gt; "$file"
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-harden_ssh_client_crypto_policy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-harden_ssh_client_crypto_policy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_harden_sshd_ciphers_openssh_conf_crypto_policy" selected="false" severity="high">
                <xccdf-1.2:title>Configure SSH Client to Use FIPS 140 Validated Ciphers: openssh.config</xccdf-1.2:title>
                <xccdf-1.2:description>Crypto Policies provide a centralized control over crypto algorithms usage of many packages.
OpenSSH is supported by system crypto policy, but the OpenSSH configuration may be
set up incorrectly.

To check that Crypto Policies settings for ciphers are configured correctly, ensure that
<html:code>/etc/crypto-policies/back-ends/openssh.config</html:code> contains the following
line and is not commented out:
<html:pre>Ciphers <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_approved_ciphers" use="legacy"/></html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">The system needs to be rebooted for these changes to take effect.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="regulatory">System Crypto Modules must be provided by a vendor that undergoes
FIPS-140 certifications.
FIPS-140 is applicable to all Federal agencies that use
cryptographic-based security systems to protect sensitive information
in computer and telecommunication systems (including voice systems) as
defined in Section 5131 of the Information Technology Management Reform
Act of 1996, Public Law 104-106. This standard shall be used in
designing and implementing cryptographic modules that Federal
departments and agencies operate or are operated for them under
contract.
To meet this, the system has to have cryptographic software provided by
a vendor that has undergone this certification. This means providing
documentation, test results, design information, and independent third
party review by an accredited lab. While open source software is
capable of meeting this, it does not meet FIPS-140 unless the vendor
submits to this process.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000033-GPOS-00014</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000125-GPOS-00065</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000393-GPOS-00173</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000394-GPOS-00174</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000423-GPOS-00187</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Overriding the system crypto policy makes the behavior of the OpenSSH client
violate expectations, and makes system configuration more fragmented. By
specifying a cipher list with the order of ciphers being in a “strongest to
weakest” orientation, the system will automatically attempt to use the
strongest cipher for securing SSH connections.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_openssh"/>
                <xccdf-1.2:fix id="harden_sshd_ciphers_openssh_conf_crypto_policy" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q openssh; then

sshd_approved_ciphers='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_approved_ciphers" use="legacy"/>'
if [ -e "/etc/crypto-policies/back-ends/openssh.config" ] ; then
    
    LC_ALL=C sed -i "/^.*Ciphers\s\+/d" "/etc/crypto-policies/back-ends/openssh.config"
else
    touch "/etc/crypto-policies/back-ends/openssh.config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/crypto-policies/back-ends/openssh.config"

cp "/etc/crypto-policies/back-ends/openssh.config" "/etc/crypto-policies/back-ends/openssh.config.bak"
# Insert at the end of the file
printf '%s\n' "Ciphers ${sshd_approved_ciphers}" &gt;&gt; "/etc/crypto-policies/back-ends/openssh.config"
# Clean up after ourselves.
rm "/etc/crypto-policies/back-ends/openssh.config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="harden_sshd_ciphers_openssh_conf_crypto_policy" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_ciphers_openssh_conf_crypto_policy
  - high_severity
  - low_complexity
  - low_disruption
  - reboot_required
  - restrict_strategy
- name: XCCDF Value sshd_approved_ciphers # promote to variable
  set_fact:
    sshd_approved_ciphers: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_approved_ciphers" use="legacy"/>
  tags:
    - always

- name: 'Configure SSH Daemon to Use FIPS 140-2 Validated Ciphers: openssh.config'
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/crypto-policies/back-ends/openssh.config
      create: true
      regexp: (?i)^.*Ciphers\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/crypto-policies/back-ends/openssh.config
    ansible.builtin.lineinfile:
      path: /etc/crypto-policies/back-ends/openssh.config
      create: true
      regexp: (?i)^.*Ciphers\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/crypto-policies/back-ends/openssh.config
    ansible.builtin.lineinfile:
      path: /etc/crypto-policies/back-ends/openssh.config
      create: true
      regexp: (?i)^.*Ciphers\s+
      line: Ciphers {{ sshd_approved_ciphers }}
      state: present
  when: '"openssh" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_ciphers_openssh_conf_crypto_policy
  - high_severity
  - low_complexity
  - low_disruption
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sshd_approved_ciphers:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_approved_ciphers"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-harden_sshd_ciphers_openssh_conf_crypto_policy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-harden_sshd_ciphers_openssh_conf_crypto_policy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_harden_sshd_ciphers_opensshserver_conf_crypto_policy" selected="false" severity="medium">
                <xccdf-1.2:title>Configure SSH Server to Use FIPS 140-2 Validated Ciphers: opensshserver.config</xccdf-1.2:title>
                <xccdf-1.2:description>Crypto Policies provide a centralized control over crypto algorithms usage of many packages.
OpenSSH is supported by system crypto policy, but the OpenSSH configuration may be
set up incorrectly.

To check that Crypto Policies settings for ciphers are configured correctly, ensure that
<html:code>/etc/crypto-policies/back-ends/opensshserver.config</html:code> contains the following
text and is not commented out:
<html:pre>-oCiphers=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_approved_ciphers" use="legacy"/></html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">The system needs to be rebooted for these changes to take effect.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="regulatory">System Crypto Modules must be provided by a vendor that undergoes
FIPS-140 certifications.
FIPS-140 is applicable to all Federal agencies that use
cryptographic-based security systems to protect sensitive information
in computer and telecommunication systems (including voice systems) as
defined in Section 5131 of the Information Technology Management Reform
Act of 1996, Public Law 104-106. This standard shall be used in
designing and implementing cryptographic modules that Federal
departments and agencies operate or are operated for them under
contract. See <html:b><html:a href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf">https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf</html:a></html:b>
To meet this, the system has to have cryptographic software provided by
a vendor that has undergone this certification. This means providing
documentation, test results, design information, and independent third
party review by an accredited lab. While open source software is
capable of meeting this, it does not meet FIPS-140 unless the vendor
submits to this process.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000125-GPOS-00065</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Overriding the system crypto policy makes the behavior of the OpenSSH server
violate expectations, and makes system configuration more fragmented. By
specifying a cipher list with the order of ciphers being in a “strongest to
weakest” orientation, the system will automatically attempt to use the
strongest cipher for securing SSH connections.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix id="harden_sshd_ciphers_opensshserver_conf_crypto_policy" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

sshd_approved_ciphers='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_approved_ciphers" use="legacy"/>'
CONF_FILE="/etc/crypto-policies/back-ends/opensshserver.config"
LOCAL_CONF_DIR=/etc/crypto-policies/local.d
LOCAL_CONF_FILE=${LOCAL_CONF_DIR}/opensshserver-ssg.config
correct_value="-oCiphers=${sshd_approved_ciphers}"

# Test if file exists, create default it if not
if [[ ! -s ${CONF_FILE} ]] || ! grep -q "^\s*CRYPTO_POLICY=" ${CONF_FILE} ; then
    update-crypto-policies --no-reload # Generate a default configuration
fi

# Get the last occurrence of CRYPTO_POLICY
last_crypto_policy=$(grep -Eo "^\s*CRYPTO_POLICY='[^']+'" ${CONF_FILE} | tail -n 1)

# Copy the last CRYPTO_POLICY value to the local configuration file
if [[ -n "$last_crypto_policy" ]]; then
    if ! grep -qe "$correct_value" &lt;&lt;&lt; "$last_crypto_policy"; then
        # If an existing -oCiphers= is found, replace it
        # Else, append correct_value before the closing apostrophe
        if [[ "$last_crypto_policy" == *"-oCiphers="* ]]; then
            last_crypto_policy=$(echo "$last_crypto_policy" | sed -E "s/-oCiphers=\S+/${correct_value}/")
        else
            last_crypto_policy=$(echo "$last_crypto_policy" | sed -E "s/'[[:space:]]*$/ ${correct_value}'/")
        fi
        # Write updated line to LOCAL_CONF_FILE
        echo -e "\n$last_crypto_policy" &gt; "$LOCAL_CONF_FILE"
    fi
else
    echo -e "\nCRYPTO_POLICY='${correct_value}'" &gt; ${LOCAL_CONF_FILE}
fi

update-crypto-policies --no-reload

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="harden_sshd_ciphers_opensshserver_conf_crypto_policy" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_ciphers_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
- name: XCCDF Value sshd_approved_ciphers # promote to variable
  set_fact:
    sshd_approved_ciphers: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_approved_ciphers" use="legacy"/>
  tags:
    - always

- name: 'Configure SSH Server to Use FIPS 140-2 Validated Ciphers: opensshserver.config:
    Set relevant paths and correct value'
  ansible.builtin.set_fact:
    opensshserver_path: /etc/crypto-policies/back-ends/opensshserver.config
    local_path: /etc/crypto-policies/local.d/opensshserver-ssg.config
    correct_value: -oCiphers={{ sshd_approved_ciphers }}
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_ciphers_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated Ciphers: opensshserver.config:
    Ensure crypto config exists'
  ansible.builtin.stat:
    path: '{{ opensshserver_path }}'
    follow: true
  register: opensshserver_file
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_ciphers_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated Ciphers: opensshserver.config:
    Generate default config if missing or empty'
  ansible.builtin.command: update-crypto-policies --no-reload
  when:
  - '"kernel" in ansible_facts.packages'
  - not opensshserver_file.stat.exists or opensshserver_file.stat.size == 0
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_ciphers_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated Ciphers: opensshserver.config:
    Read opensshserver.config content'
  ansible.builtin.slurp:
    src: '{{ opensshserver_path }}'
  register: ssh_config_raw
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_ciphers_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated Ciphers: opensshserver.config:
    Extract last CRYPTO_POLICY line'
  ansible.builtin.set_fact:
    last_crypto_policy: '{{ (ssh_config_raw.content | b64decode).splitlines() | select(''match'',
      "^\s*CRYPTO_POLICY=''[^'']+''") | list | last | default('''') }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_ciphers_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated Ciphers: opensshserver.config:
    Check if correct_value is present'
  ansible.builtin.set_fact:
    cipher_is_correct: '{{ correct_value in last_crypto_policy }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_ciphers_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated Ciphers: opensshserver.config:
    Extract current Ciphers if needed'
  ansible.builtin.set_fact:
    existing_cipher: '{{ (last_crypto_policy | regex_findall(''(-oCiphers=\S+)'',
      ''\1'')) | last | default('''') }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - not cipher_is_correct and last_crypto_policy != ''
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_ciphers_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated Ciphers: opensshserver.config:
    Build full updated CRYPTO_POLICY line'
  ansible.builtin.set_fact:
    updated_crypto_policy: '{% if last_crypto_policy == '''' %} CRYPTO_POLICY=''{{
      correct_value }}'' {% elif existing_cipher != '''' %} {{ last_crypto_policy
      | regex_replace(existing_cipher, correct_value) }} {% else %} {{ last_crypto_policy[:-1]
      ~ " " ~ correct_value ~ "''" }} {% endif %}'
  when:
  - '"kernel" in ansible_facts.packages'
  - not cipher_is_correct
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_ciphers_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated Ciphers: opensshserver.config:
    Ensure local.d dir exists'
  ansible.builtin.file:
    path: '{{ local_path | dirname }}'
    state: directory
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_ciphers_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated Ciphers: opensshserver.config:
    Write CRYPTO_POLICY to local config'
  ansible.builtin.lineinfile:
    path: '{{ local_path }}'
    line: |-
      {{ '
      ' ~ updated_crypto_policy }}
    create: true
    insertafter: EOF
  register: local_config
  when:
  - '"kernel" in ansible_facts.packages'
  - not cipher_is_correct
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_ciphers_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated Ciphers: opensshserver.config:
    Apply updated crypto policies'
  ansible.builtin.command: update-crypto-policies --no-reload
  when:
  - '"kernel" in ansible_facts.packages'
  - not cipher_is_correct and local_config is changed
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_ciphers_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sshd_approved_ciphers:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_approved_ciphers"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-harden_sshd_ciphers_opensshserver_conf_crypto_policy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-harden_sshd_ciphers_opensshserver_conf_crypto_policy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_harden_sshd_crypto_policy" selected="false" severity="medium">
                <xccdf-1.2:title>Harden SSHD Crypto Policy</xccdf-1.2:title>
                <xccdf-1.2:description>Crypto Policies are means of enforcing certain cryptographic settings for selected applications including OpenSSH server.
The SSHD service is by default configured to modify its configuration based on currently configured Crypto-Policy. However, in certain cases it might be needed to override the Crypto Policy specific to OpenSSH Server and leave rest of the Crypto Policy intact.
This can be done by dropping a file named <html:code>opensshserver-xxx.config</html:code>, replacing <html:code>xxx</html:code> with arbitrary identifier, into <html:code>/etc/crypto-policies/local.d</html:code>. This has to be followed by running <html:code>update-crypto-policies</html:code> so that changes are applied.
Changes are propagated into <html:code>/etc/crypto-policies/back-ends/opensshserver.config</html:code>. This rule checks if this file contains predefined <html:code>CRYPTO_POLICY</html:code> environment variable configured with predefined value.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MA-4(6)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000033-GPOS-00014</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000120-GPOS-00061</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The Common Criteria requirements specify that certain parameters for OpenSSH Server are configured e.g. supported ciphers, accepted host key algorithms, public key types, key exchange algorithms, HMACs and GSSAPI key exchange is disabled. Currently particular requirements specified by CC are stricter compared to any existing Crypto Policy.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_openssh"/>
                <xccdf-1.2:fix id="harden_sshd_crypto_policy" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q openssh; then

cp="CRYPTO_POLICY='-oCiphers=aes256-ctr,aes128-ctr,aes256-cbc,aes128-cbc -oMACs=hmac-sha2-512,hmac-sha2-256 -oGSSAPIKeyExchange=no -oKexAlgorithms=ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group14-sha1 -oHostKeyAlgorithms=ssh-rsa,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256 -oPubkeyAcceptedKeyTypes=rsa-sha2-512,rsa-sha2-256,ssh-rsa,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256'"
file=/etc/crypto-policies/local.d/opensshserver-ospp.config

#blank line at the beginning to ease later readability
echo '' &gt; "$file"
echo "$cp" &gt;&gt; "$file"
update-crypto-policies

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-harden_sshd_crypto_policy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-harden_sshd_crypto_policy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_harden_sshd_macs_openssh_conf_crypto_policy" selected="false" severity="medium">
                <xccdf-1.2:title>Configure SSH Client to Use FIPS 140-2 Validated MACs: openssh.config</xccdf-1.2:title>
                <xccdf-1.2:description>Crypto Policies provide a centralized control over crypto algorithms usage of many packages.
OpenSSH is supported by system crypto policy, but the OpenSSH configuration may be
set up incorrectly.

To check that Crypto Policies settings are configured correctly, ensure that
<html:code>/etc/crypto-policies/back-ends/openssh.config</html:code> contains the following
line and is not commented out:
<html:code>MACs <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_approved_macs" use="legacy"/></html:code></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">The system needs to be rebooted for these changes to take effect.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="regulatory">System Crypto Modules must be provided by a vendor that undergoes
FIPS-140 certifications.
FIPS-140 is applicable to all Federal agencies that use
cryptographic-based security systems to protect sensitive information
in computer and telecommunication systems (including voice systems) as
defined in Section 5131 of the Information Technology Management Reform
Act of 1996, Public Law 104-106. This standard shall be used in
designing and implementing cryptographic modules that Federal
departments and agencies operate or are operated for them under
contract. See <html:b><html:a href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf">https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf</html:a></html:b>
To meet this, the system has to have cryptographic software provided by
a vendor that has undergone this certification. This means providing
documentation, test results, design information, and independent third
party review by an accredited lab. While open source software is
capable of meeting this, it does not meet FIPS-140 unless the vendor
submits to this process.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000125-GPOS-00065</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Overriding the system crypto policy makes the behavior of the OpenSSH
client violate expectations, and makes system configuration more
fragmented.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_openssh"/>
                <xccdf-1.2:fix id="harden_sshd_macs_openssh_conf_crypto_policy" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q openssh; then

sshd_approved_macs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_approved_macs" use="legacy"/>'
if [ -e "/etc/crypto-policies/back-ends/openssh.config" ] ; then
    
    LC_ALL=C sed -i "/^.*MACs\s\+/d" "/etc/crypto-policies/back-ends/openssh.config"
else
    touch "/etc/crypto-policies/back-ends/openssh.config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/crypto-policies/back-ends/openssh.config"

cp "/etc/crypto-policies/back-ends/openssh.config" "/etc/crypto-policies/back-ends/openssh.config.bak"
# Insert at the end of the file
printf '%s\n' "MACs ${sshd_approved_macs}" &gt;&gt; "/etc/crypto-policies/back-ends/openssh.config"
# Clean up after ourselves.
rm "/etc/crypto-policies/back-ends/openssh.config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="harden_sshd_macs_openssh_conf_crypto_policy" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_macs_openssh_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
- name: XCCDF Value sshd_approved_macs # promote to variable
  set_fact:
    sshd_approved_macs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_approved_macs" use="legacy"/>
  tags:
    - always

- name: 'Configure SSH Daemon to Use FIPS 140-2 Validated MACs: openssh.config'
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/crypto-policies/back-ends/openssh.config
      create: true
      regexp: (?i)^.*MACs\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/crypto-policies/back-ends/openssh.config
    ansible.builtin.lineinfile:
      path: /etc/crypto-policies/back-ends/openssh.config
      create: true
      regexp: (?i)^.*MACs\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/crypto-policies/back-ends/openssh.config
    ansible.builtin.lineinfile:
      path: /etc/crypto-policies/back-ends/openssh.config
      create: true
      regexp: (?i)^.*MACs\s+
      line: MACs {{ sshd_approved_macs }}
      state: present
  when: '"openssh" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_macs_openssh_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sshd_approved_macs:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_approved_macs"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-harden_sshd_macs_openssh_conf_crypto_policy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-harden_sshd_macs_openssh_conf_crypto_policy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_harden_sshd_macs_opensshserver_conf_crypto_policy" selected="false" severity="medium">
                <xccdf-1.2:title>Configure SSH Server to Use FIPS 140-2 Validated MACs: opensshserver.config</xccdf-1.2:title>
                <xccdf-1.2:description>Crypto Policies provide a centralized control over crypto algorithms usage of many packages.
OpenSSH is supported by system crypto policy, but the OpenSSH configuration may be
set up incorrectly.

To check that Crypto Policies settings are configured correctly, ensure that
<html:code>/etc/crypto-policies/back-ends/opensshserver.config</html:code> contains the following
text and is not commented out:
<html:code>-oMACS=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_approved_macs" use="legacy"/></html:code></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">The system needs to be rebooted for these changes to take effect.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="regulatory">System Crypto Modules must be provided by a vendor that undergoes
FIPS-140 certifications.
FIPS-140 is applicable to all Federal agencies that use
cryptographic-based security systems to protect sensitive information
in computer and telecommunication systems (including voice systems) as
defined in Section 5131 of the Information Technology Management Reform
Act of 1996, Public Law 104-106. This standard shall be used in
designing and implementing cryptographic modules that Federal
departments and agencies operate or are operated for them under
contract. See <html:b><html:a href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf">https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf</html:a></html:b>
To meet this, the system has to have cryptographic software provided by
a vendor that has undergone this certification. This means providing
documentation, test results, design information, and independent third
party review by an accredited lab. While open source software is
capable of meeting this, it does not meet FIPS-140 unless the vendor
submits to this process.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000125-GPOS-00065</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Overriding the system crypto policy makes the behavior of the OpenSSH
server violate expectations, and makes system configuration more
fragmented.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix id="harden_sshd_macs_opensshserver_conf_crypto_policy" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

sshd_approved_macs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_approved_macs" use="legacy"/>'
CONF_FILE="/etc/crypto-policies/back-ends/opensshserver.config"
LOCAL_CONF_DIR=/etc/crypto-policies/local.d
LOCAL_CONF_FILE=${LOCAL_CONF_DIR}/opensshserver-ssg.config
correct_value="-oMACs=${sshd_approved_macs}"

# Test if file exists, create default it if not
if [[ ! -s ${CONF_FILE} ]] || ! grep -q "^\s*CRYPTO_POLICY=" ${CONF_FILE} ; then
    update-crypto-policies --no-reload # Generate a default configuration
fi

# Get the last occurrence of CRYPTO_POLICY
last_crypto_policy=$(grep -Eo "^\s*CRYPTO_POLICY='[^']+'" ${CONF_FILE} | tail -n 1)

# Copy the last CRYPTO_POLICY value to the local configuration file
if [[ -n "$last_crypto_policy" ]]; then
    if ! grep -qe "$correct_value" &lt;&lt;&lt; "$last_crypto_policy"; then
        # If an existing -oMACs= is found, replace it
        # Else, append correct_value before the closing apostrophe
        if [[ "$last_crypto_policy" == *"-oMACs="* ]]; then
            last_crypto_policy=$(echo "$last_crypto_policy" | sed -E "s/-oMACs=\S+/${correct_value}/")
        else
            last_crypto_policy=$(echo "$last_crypto_policy" | sed -E "s/'[[:space:]]*$/ ${correct_value}'/")
        fi
        # Write updated line to LOCAL_CONF_FILE
        echo -e "\n$last_crypto_policy" &gt; "$LOCAL_CONF_FILE"
    fi
else
    echo -e "\nCRYPTO_POLICY='${correct_value}'" &gt; ${LOCAL_CONF_FILE}
fi

update-crypto-policies --no-reload

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="harden_sshd_macs_opensshserver_conf_crypto_policy" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_macs_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
- name: XCCDF Value sshd_approved_macs # promote to variable
  set_fact:
    sshd_approved_macs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_approved_macs" use="legacy"/>
  tags:
    - always

- name: 'Configure SSH Server to Use FIPS 140-2 Validated MACs: opensshserver.config:
    Set relevant paths and correct value'
  ansible.builtin.set_fact:
    opensshserver_path: /etc/crypto-policies/back-ends/opensshserver.config
    local_path: /etc/crypto-policies/local.d/opensshserver-ssg.config
    correct_value: -oMACs={{ sshd_approved_macs }}
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_macs_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated MACs: opensshserver.config:
    Ensure crypto config exists'
  ansible.builtin.stat:
    path: '{{ opensshserver_path }}'
    follow: true
  register: opensshserver_file
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_macs_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated MACs: opensshserver.config:
    Generate default config if missing or empty'
  ansible.builtin.command: update-crypto-policies --no-reload
  when:
  - '"kernel" in ansible_facts.packages'
  - not opensshserver_file.stat.exists or opensshserver_file.stat.size == 0
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_macs_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated MACs: opensshserver.config:
    Read opensshserver.config content'
  ansible.builtin.slurp:
    src: '{{ opensshserver_path }}'
  register: ssh_config_raw
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_macs_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated MACs: opensshserver.config:
    Extract last CRYPTO_POLICY line'
  ansible.builtin.set_fact:
    last_crypto_policy: '{{ (ssh_config_raw.content | b64decode).splitlines() | select(''match'',
      "^\s*CRYPTO_POLICY=''[^'']+''") | list | last | default('''') }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_macs_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated MACs: opensshserver.config:
    Check if correct_value is present'
  ansible.builtin.set_fact:
    mac_is_correct: '{{ correct_value in last_crypto_policy }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_macs_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated MACs: opensshserver.config:
    Extract current Ciphers if needed'
  ansible.builtin.set_fact:
    existing_mac: '{{ (last_crypto_policy | regex_findall(''(-oMACs=\S+)'', ''\1''))
      | last | default('''') }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - not mac_is_correct and last_crypto_policy != ''
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_macs_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated MACs: opensshserver.config:
    Build full updated CRYPTO_POLICY line'
  ansible.builtin.set_fact:
    updated_crypto_policy: '{% if last_crypto_policy == '''' %} CRYPTO_POLICY=''{{
      correct_value }}'' {% elif existing_mac != '''' %} {{ last_crypto_policy | regex_replace(existing_mac,
      correct_value) }} {% else %} {{ last_crypto_policy[:-1] ~ " " ~ correct_value
      ~ "''" }} {% endif %}'
  when:
  - '"kernel" in ansible_facts.packages'
  - not mac_is_correct
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_macs_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated MACs: opensshserver.config:
    Ensure local.d dir exists'
  ansible.builtin.file:
    path: '{{ local_path | dirname }}'
    state: directory
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_macs_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated MACs: opensshserver.config:
    Write CRYPTO_POLICY to local config'
  ansible.builtin.lineinfile:
    path: '{{ local_path }}'
    line: |-
      {{ '
      ' ~ updated_crypto_policy }}
    create: true
    insertafter: EOF
  register: local_config
  when:
  - '"kernel" in ansible_facts.packages'
  - not mac_is_correct
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_macs_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: 'Configure SSH Server to Use FIPS 140-2 Validated MACs: opensshserver.config:
    Apply updated crypto policies'
  ansible.builtin.command: update-crypto-policies --no-reload
  when:
  - '"kernel" in ansible_facts.packages'
  - not mac_is_correct and local_config is changed
  tags:
  - NIST-800-53-AC-17(2)
  - harden_sshd_macs_opensshserver_conf_crypto_policy
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sshd_approved_macs:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_approved_macs"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-harden_sshd_macs_opensshserver_conf_crypto_policy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-harden_sshd_macs_opensshserver_conf_crypto_policy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_openssl_use_strong_entropy" selected="false" severity="medium">
                <xccdf-1.2:title>OpenSSL uses strong entropy source</xccdf-1.2:title>
                <xccdf-1.2:description>By default, OpenSSL doesn't always use a SP800-90A compliant random number generator.
A way to configure OpenSSL to always use a strong source is to setup a wrapper that
defines a shell function that shadows the actual <html:code>openssl</html:code> binary,
and that ensures that the <html:code>-rand /dev/random</html:code> option is added to every <html:code>openssl</html:code> invocation.

To do so, place the following shell snippet exactly as-is to <html:code>/etc/profile.d/openssl-rand.sh</html:code>:
<html:pre>
# provide a default -rand /dev/random option to openssl commands that
# support it

# written inefficiently for maximum shell compatibility
openssl()
(
  openssl_bin=/usr/bin/openssl

  case "$*" in
    # if user specified -rand, honor it
    *\ -rand\ *|*\ -help*) exec $openssl_bin "$@" ;;
  esac

  cmds=`$openssl_bin list -digest-commands -cipher-commands | tr '\n' ' '`
  for i in `$openssl_bin list -commands`; do
    if $openssl_bin list -options "$i" | grep -q '^rand '; then
      cmds=" $i $cmds"
    fi
  done

  case "$cmds" in
    *\ "$1"\ *)
      cmd="$1"; shift
      exec $openssl_bin "$cmd" -rand /dev/random "$@" ;;
  esac

  exec $openssl_bin "$@"
)
</html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">This setting can cause problems on computers without the hardware random generator, because insufficient entropy blocks the program until enough entropy is available.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1277</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1552</xccdf-1.2:reference>
                <xccdf-1.2:rationale>This rule ensures that <html:code>openssl</html:code> invocations always uses SP800-90A compliant random number generator as a default behavior.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="openssl_use_strong_entropy" system="urn:xccdf:fix:script:sh">
cat &gt; /etc/profile.d/openssl-rand.sh &lt;&lt;- 'EOM'
# provide a default -rand /dev/random option to openssl commands that
# support it

# written inefficiently for maximum shell compatibility
openssl()
(
  openssl_bin=/usr/bin/openssl

  case "$*" in
    # if user specified -rand, honor it
    *\ -rand\ *|*\ -help*) exec $openssl_bin "$@" ;;
  esac

  cmds=`$openssl_bin list -digest-commands -cipher-commands | tr '\n' ' '`
  for i in `$openssl_bin list -commands`; do
    if $openssl_bin list -options "$i" | grep -q '^rand '; then
      cmds=" $i $cmds"
    fi
  done

  case "$cmds" in
    *\ "$1"\ *)
      cmd="$1"; shift
      exec $openssl_bin "$cmd" -rand /dev/random "$@" ;;
  esac

  exec $openssl_bin "$@"
)
EOM
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="openssl_use_strong_entropy" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Put a file with shell wrapper to configure OpenSSL to always use strong entropy
  copy:
    dest: /etc/profile.d/openssl-rand.sh
    content: |
      # provide a default -rand /dev/random option to openssl commands that
      # support it

      # written inefficiently for maximum shell compatibility
      openssl()
      (
        openssl_bin=/usr/bin/openssl

        case "$*" in
          # if user specified -rand, honor it
          *\ -rand\ *|*\ -help*) exec $openssl_bin "$@" ;;
        esac

        cmds=`$openssl_bin list -digest-commands -cipher-commands | tr '\n' ' '`
        for i in `$openssl_bin list -commands`; do
          if $openssl_bin list -options "$i" | grep -q '^rand '; then
            cmds=" $i $cmds"
          fi
        done

        case "$cmds" in
          *\ "$1"\ *)
            cmd="$1"; shift
            exec $openssl_bin "$cmd" -rand /dev/random "$@" ;;
        esac

        exec $openssl_bin "$@"
      )
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - openssl_use_strong_entropy
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-openssl_use_strong_entropy:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-openssl_use_strong_entropy_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_certified-vendor">
              <xccdf-1.2:title>Operating System Vendor Support and Certification</xccdf-1.2:title>
              <xccdf-1.2:description>The assurance of a vendor to provide operating system support and maintenance
for their product is an important criterion to ensure product stability and
security over the life of the product. A certified product that follows the
necessary standards and government certification requirements guarantees that
known software vulnerabilities will be remediated, and proper guidance for
protecting and securing the operating system will be given.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_installed_OS_is_FIPS_certified" selected="false" severity="high">
                <xccdf-1.2:title>The Installed Operating System Is FIPS 140-2 Certified</xccdf-1.2:title>
                <xccdf-1.2:description>To enable processing of sensitive information the operating system must
provide certified cryptographic modules compliant with FIPS 140-2
standard.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">There is no remediation besides switching to a different operating system.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="regulatory">System Crypto Modules must be provided by a vendor that undergoes
FIPS-140 certifications.
FIPS-140 is applicable to all Federal agencies that use
cryptographic-based security systems to protect sensitive information
in computer and telecommunication systems (including voice systems) as
defined in Section 5131 of the Information Technology Management Reform
Act of 1996, Public Law 104-106. This standard shall be used in
designing and implementing cryptographic modules that Federal
departments and agencies operate or are operated for them under
contract. See <html:b><html:a href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf">https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf</html:a></html:b>
To meet this, the system has to have cryptographic software provided by
a vendor that has undergone this certification. This means providing
documentation, test results, design information, and independent third
party review by an accredited lab. While open source software is
capable of meeting this, it does not meet FIPS-140 unless the vendor
submits to this process.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The Federal Information Processing Standard (FIPS) Publication 140-2, (FIPS
PUB 140-2) is a computer security standard. The standard specifies security
requirements for cryptographic modules used to protect sensitive
unclassified information.  Refer to the full FIPS 140-2 standard at

    <html:a href="http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf">http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf</html:a>
for further details on the requirements.
FIPS 140-2 validation is required by U.S. law when information systems use
cryptography to protect sensitive government information. In order to
achieve FIPS 140-2 certification, cryptographic modules are subject to
extensive testing by independent laboratories, accredited by National
Institute of Standards and Technology (NIST).</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-installed_OS_is_FIPS_certified:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_installed_OS_is_vendor_supported" selected="false" severity="high">
                <xccdf-1.2:title>The Installed Operating System Is Vendor Supported</xccdf-1.2:title>
                <xccdf-1.2:description>The installed operating system must be maintained by a vendor.

AlmaLinux OS is supported by AlmaLinux OS Foundation. As the AlmaLinux OS
vendor, AlmaLinux OS Foundation is responsible for providing security patches.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">There is no remediation besides switching to a different operating system.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MA-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SA-13(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.RA-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010000</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230221r1017040_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>An operating system is considered "supported" if the vendor continues to
provide security patches for the product.  With an unsupported release, it
will not be possible to resolve any security issue discovered in the system
software.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-installed_OS_is_vendor_supported:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-installed_OS_is_vendor_supported_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_endpoint_security_software">
              <xccdf-1.2:title>Endpoint Protection Software</xccdf-1.2:title>
              <xccdf-1.2:description>Endpoint protection security software that is not provided or supported

by Red Hat can be installed to provide complementary or duplicative

security capabilities to those provided by the base platform.  Add-on
software may not be appropriate for some specialized systems.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_user_data_backups" selected="false" severity="medium">
                <xccdf-1.2:title>Configure Backups of User Data</xccdf-1.2:title>
                <xccdf-1.2:description>The operating system must conduct backups of user data contained
in the operating system. The operating system provides utilities for
automating backups of user data. Commercial and open-source products
are also available.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Operating system backup is a critical step in maintaining data assurance and
availability. User-level information is data generated by information system
and/or application users. Backups shall be consistent with organizational
recovery time and recovery point objectives.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_user_data_backups_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_install_antivirus" selected="false" severity="high">
                <xccdf-1.2:title>Install Virus Scanning Software</xccdf-1.2:title>
                <xccdf-1.2:description>Virus scanning software can be used to protect a system from penetration from
computer viruses and to limit their spread through intermediate systems.

The virus scanning software should be configured to perform scans dynamically
on accessed files. If this capability is not available, the system must be
configured to scan, at a minimum, all altered files on the system on a daily
basis.

If the system processes inbound SMTP mail, the virus scanner must be configured
to scan all received mail.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI02.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI06.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS04.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Virus scanning software can be used to detect if a system has been compromised by
computer viruses, as well as to limit their spread to other systems.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-install_antivirus:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-install_antivirus_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_install_hids" selected="false" severity="high">
                <xccdf-1.2:title>Install Intrusion Detection Software</xccdf-1.2:title>
                <xccdf-1.2:description>The base AlmaLinux OS 8 platform already includes a sophisticated auditing system that
can detect intruder activity, as well as SELinux, which provides host-based
intrusion prevention capabilities by confining privileged programs and user
sessions which may become compromised.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">In DoD environments, supplemental intrusion detection and antivirus tools,
such as the McAfee Host-based Security System, are available to integrate with
existing infrastructure. Per DISA guidance, when these supplemental tools interfere
with proper functioning of SELinux, SELinux takes precedence. Should further
clarification be required, DISA contact information is published publicly at
https://www.cyber.mil/stigs/</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-11.4</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Host-based intrusion detection tools provide a system-level defense when an
intruder gains access to a system or network.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:conflicts idref="xccdf_org.ssgproject.content_rule_selinux_state"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-install_hids:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-install_hids_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_mcafee_security_software">
                <xccdf-1.2:title>McAfee Endpoint Security Software</xccdf-1.2:title>
                <xccdf-1.2:description>In DoD environments, McAfee Host-based Security System (HBSS) and
VirusScan Enterprise for Linux (VSEL) is required to be installed on all systems.</xccdf-1.2:description>
                <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mcafee_antivirus_definition_expire" type="number">
                  <xccdf-1.2:title>The age of McAfee definition file before requiring updating</xccdf-1.2:title>
                  <xccdf-1.2:description>Specify the amount of time (in seconds) before McAfee definition files need to be
updated.</xccdf-1.2:description>
                  <xccdf-1.2:value>2592000</xccdf-1.2:value>
                  <xccdf-1.2:value selector="1_day">86400</xccdf-1.2:value>
                  <xccdf-1.2:value selector="1_week">604800</xccdf-1.2:value>
                  <xccdf-1.2:value selector="30_days">2592000</xccdf-1.2:value>
                </xccdf-1.2:Value>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_nails_enabled" selected="false" severity="medium">
                  <xccdf-1.2:title>Enable nails Service</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>nails</html:code> service is used to run McAfee VirusScan Enterprise
for Linux and McAfee Host-based Security System (HBSS) services.

The <html:code>nails</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable nails.service</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI02.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI06.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS04.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-28</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-3(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Virus scanning software can be used to detect if a system has been compromised by
computer viruses, as well as to limit their spread to other systems.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#system_with_kernel"/>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="service_nails_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'nails.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'nails.service'
fi
"$SYSTEMCTL_EXEC" enable 'nails.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="service_nails_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-28
  - NIST-800-53-SI-3(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_nails_enabled

- name: Enable nails Service - Enable service nails
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable nails Service - Enable Service nails
    ansible.builtin.systemd:
      name: nails
      enabled: true
      state: started
      masked: false
    when:
    - '"nails" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-28
  - NIST-800-53-SI-3(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_nails_enabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="service_nails_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_nails

class enable_nails {
  service {'nails':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
                  <xccdf-1.2:fix id="service_nails_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["nails"]
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="service_nails_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable nails
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_nails_enabled:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_nails_enabled_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_install_mcafee_antivirus" selected="false" severity="high">
                  <xccdf-1.2:title>Install McAfee Virus Scanning Software</xccdf-1.2:title>
                  <xccdf-1.2:description>Install McAfee VirusScan Enterprise for Linux antivirus software
which is provided for systems and uses signatures to search for the
presence of viruses on the filesystem.</xccdf-1.2:description>
                  <xccdf-1.2:warning category="general">Due to McAfee HIPS being 3rd party software, automated
remediation is not available for this configuration check.</xccdf-1.2:warning>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI02.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI06.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS04.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-28</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-3(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Virus scanning software can be used to detect if a system has been compromised by
computer viruses, as well as to limit their spread to other systems.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#system_with_kernel"/>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-install_mcafee_antivirus:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-install_mcafee_antivirus_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_install_mcafee_cma_rt" selected="false" severity="medium">
                  <xccdf-1.2:title>Install the McAfee Runtime Libraries and Linux Agent</xccdf-1.2:title>
                  <xccdf-1.2:description>Install the McAfee Runtime Libraries (MFErt) and Linux Agent (MFEcma).</xccdf-1.2:description>
                  <xccdf-1.2:rationale>The McAfee Runtime Libraries (MFErt) and Linux Agent (MFEcma) are dependencies
for VirusScan Enterprise for Linux (VSEL) and Host-based Security System (HBSS)
to run.</xccdf-1.2:rationale>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-install_mcafee_cma_rt:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-install_mcafee_cma_rt_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mcafee_antivirus_definitions_updated" selected="false" severity="medium">
                  <xccdf-1.2:title>Virus Scanning Software Definitions Are Updated</xccdf-1.2:title>
                  <xccdf-1.2:description>Ensure virus definition files are no older than 7 days or their last release.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI02.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI06.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS04.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-28</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-3(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-3(b)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-3(2)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Virus scanning software can be used to detect if a system has been compromised by
computer viruses, as well as to limit their spread to other systems.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#system_with_kernel"/>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-export export-name="oval:ssg-var_mcafee_antivirus_definition_expire:var:1" value-id="xccdf_org.ssgproject.content_value_var_mcafee_antivirus_definition_expire"/>
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mcafee_antivirus_definitions_updated:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mcafee_antivirus_definitions_updated_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_mcafee_endpoint_security_software">
                  <xccdf-1.2:title>McAfee Endpoint Security for Linux (ENSL)</xccdf-1.2:title>
                  <xccdf-1.2:description>McAfee Endpoint Security for Linux (ENSL) is a suite of software applications
used to monitor, detect, and defend computer networks and systems.</xccdf-1.2:description>
                  <xccdf-1.2:platform idref="#system_with_kernel"/>
                  <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_mcafeetp_installed" selected="false" severity="medium">
                    <xccdf-1.2:title>Install McAfee Endpoint Security for Linux (ENSL)</xccdf-1.2:title>
                    <xccdf-1.2:description>Install McAfee Endpoint Security for Linux antivirus software
which is provided for systems and uses signatures to search for the
presence of viruses on the filesystem.

The <html:code>McAfeeTP</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install McAfeeTP</html:pre></xccdf-1.2:description>
                    <xccdf-1.2:warning category="general">Due to McAfee Endpoint Security for Linux (ENSL) being 3rd party software,
automated remediation is not available for this configuration check.</xccdf-1.2:warning>
                    <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-2(2)</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000191-GPOS-00080</xccdf-1.2:reference>
                    <xccdf-1.2:rationale>Virus scanning software can be used to detect if a system has been compromised by
computer viruses, as well as to limit their spread to other systems.</xccdf-1.2:rationale>
                    <xccdf-1.2:fix complexity="low" disruption="low" id="package_mcafeetp_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install McAfeeTP
</xccdf-1.2:fix>
                    <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                      <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_mcafeetp_installed:def:1"/>
                    </xccdf-1.2:check>
                    <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                      <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_mcafeetp_installed_ocil:questionnaire:1"/>
                    </xccdf-1.2:check>
                  </xccdf-1.2:Rule>
                  <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_agent_mfetpd_running" selected="false" severity="medium">
                    <xccdf-1.2:title>Ensure McAfee Endpoint Security for Linux (ENSL) is running</xccdf-1.2:title>
                    <xccdf-1.2:description>Install McAfee Endpoint Security for Linux antivirus software
which is provided for systems and uses signatures to search for the
presence of viruses on the filesystem.</xccdf-1.2:description>
                    <xccdf-1.2:warning category="general">Due to McAfee Endpoint Security for Linux (ENSL) being 3rd party software,
automated remediation is not available for this configuration check.</xccdf-1.2:warning>
                    <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-2(2)</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000191-GPOS-00080</xccdf-1.2:reference>
                    <xccdf-1.2:rationale>Virus scanning software can be used to detect if a system has been compromised by
computer viruses, as well as to limit their spread to other systems.</xccdf-1.2:rationale>
                    <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                      <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-agent_mfetpd_running:def:1"/>
                    </xccdf-1.2:check>
                    <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                      <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-agent_mfetpd_running_ocil:questionnaire:1"/>
                    </xccdf-1.2:check>
                  </xccdf-1.2:Rule>
                </xccdf-1.2:Group>
                <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_mcafee_hbss_software">
                  <xccdf-1.2:title>McAfee Host-Based Intrusion Detection Software (HBSS)</xccdf-1.2:title>
                  <xccdf-1.2:description>McAfee Host-based Security System (HBSS) is a suite of software applications
used to monitor, detect, and defend computer networks and systems.</xccdf-1.2:description>
                  <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_MFEhiplsm_installed" selected="false" severity="medium">
                    <xccdf-1.2:title>Install the Host Intrusion Prevention System (HIPS) Module</xccdf-1.2:title>
                    <xccdf-1.2:description>Install the McAfee Host Intrusion Prevention System (HIPS) Module if it is absolutely
necessary. If SELinux is enabled, do not install or enable this module.</xccdf-1.2:description>
                    <xccdf-1.2:warning category="functionality">Installing and enabling this module conflicts with SELinux.
Per profile guidance, SELinux takes precedence over this module.</xccdf-1.2:warning>
                    <xccdf-1.2:warning category="general">Due to McAfee HIPS being 3rd party software, automated
remediation is not available for this configuration check.</xccdf-1.2:warning>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO07.06</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO08.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.06</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.01</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.02</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.03</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.02</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS04.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.01</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.01</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA03.03</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA03.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.12</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.9</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.9</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.9</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.6</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.2.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.2.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">Clause 16.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">Clause 7.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-6</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.RA-1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.CO-3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-11.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000191-GPOS-00080</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000196</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                    <xccdf-1.2:rationale>Without a host-based intrusion detection tool, there is no system-level defense
when an intruder gains access to a system or network. Additionally, a host-based
intrusion prevention tool can provide methods to immediately lock out detected
intrusion attempts.</xccdf-1.2:rationale>
                    <xccdf-1.2:conflicts idref="xccdf_org.ssgproject.content_rule_selinux_state"/>
                    <xccdf-1.2:fix complexity="low" disruption="low" id="package_MFEhiplsm_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install MFEhiplsm
</xccdf-1.2:fix>
                    <xccdf-1.2:fix complexity="low" disruption="low" id="package_MFEhiplsm_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install MFEhiplsm
</xccdf-1.2:fix>
                    <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                      <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_MFEhiplsm_installed:def:1"/>
                    </xccdf-1.2:check>
                    <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                      <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_MFEhiplsm_installed_ocil:questionnaire:1"/>
                    </xccdf-1.2:check>
                  </xccdf-1.2:Rule>
                  <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_install_mcafee_hbss_accm" selected="false" severity="medium">
                    <xccdf-1.2:title>Install the Asset Configuration Compliance Module (ACCM)</xccdf-1.2:title>
                    <xccdf-1.2:description>Install the Asset Configuration Compliance Module (ACCM).</xccdf-1.2:description>
                    <xccdf-1.2:warning category="general">Due to HBSS ACCM being 3rd party software, automated
remediation is not available for this configuration check.</xccdf-1.2:warning>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO07.06</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO08.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.06</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.01</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.02</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.03</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.02</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS04.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.01</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.01</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA03.03</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA03.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.12</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.9</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.9</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.9</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.6</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.2.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.2.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">Clause 16.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">Clause 7.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-6</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.RA-1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.CO-3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-11.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                    <xccdf-1.2:rationale>Without a host-based intrusion detection tool, there is no system-level defense
when an intruder gains access to a system or network. Additionally, a host-based
intrusion prevention tool can provide methods to immediately lock out detected
intrusion attempts.</xccdf-1.2:rationale>
                    <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                      <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-install_mcafee_hbss_accm:def:1"/>
                    </xccdf-1.2:check>
                    <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                      <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-install_mcafee_hbss_accm_ocil:questionnaire:1"/>
                    </xccdf-1.2:check>
                  </xccdf-1.2:Rule>
                  <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_install_mcafee_hbss_pa" selected="false" severity="medium">
                    <xccdf-1.2:title>Install the Policy Auditor (PA) Module</xccdf-1.2:title>
                    <xccdf-1.2:description>Install the Policy Auditor (PA) Module.</xccdf-1.2:description>
                    <xccdf-1.2:warning category="general">Due to McAfee being 3rd party software, automated
remediation is not available for this configuration check.</xccdf-1.2:warning>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO07.06</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO08.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.06</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.01</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.02</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.03</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.02</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS04.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.01</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.01</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA03.03</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA03.04</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.12</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.9</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.9</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.9</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.6</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.2.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.2.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">Clause 16.1.2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">Clause 7.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-6</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-2</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.RA-1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-8</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.CO-3</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-11.4</xccdf-1.2:reference>
                    <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                    <xccdf-1.2:rationale>Without a host-based intrusion detection tool, there is no system-level defense
when an intruder gains access to a system or network. Additionally, a host-based
intrusion prevention tool can provide methods to immediately lock out detected
intrusion attempts.</xccdf-1.2:rationale>
                    <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                      <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-install_mcafee_hbss_pa:def:1"/>
                    </xccdf-1.2:check>
                    <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                      <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-install_mcafee_hbss_pa_ocil:questionnaire:1"/>
                    </xccdf-1.2:check>
                  </xccdf-1.2:Rule>
                </xccdf-1.2:Group>
              </xccdf-1.2:Group>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disk_partitioning">
            <xccdf-1.2:title>Disk Partitioning</xccdf-1.2:title>
            <xccdf-1.2:description>To ensure separation and protection of data, there
are top-level system directories which should be placed on their
own physical partition or logical volume. The installer's default
partitioning scheme creates separate logical volumes for
<html:code>/</html:code>, <html:code>/boot</html:code>, and <html:code>swap</html:code>.
<html:ul><html:li>If starting with any of the default layouts, check the box to
\"Review and modify partitioning.\" This allows for the easy creation
of additional logical volumes inside the volume group already
created, though it may require making <html:code>/</html:code>'s logical volume smaller to
create space. In general, using logical volumes is preferable to
using partitions because they can be more easily adjusted
later.</html:li><html:li>If creating a custom layout, create the partitions mentioned in
the previous paragraph (which the installer will require anyway),
as well as separate ones described in the following sections.</html:li></html:ul>
If a system has already been installed, and the default
partitioning
scheme was used, it is possible but nontrivial to
modify it to create separate logical volumes for the directories
listed above. The Logical Volume Manager (LVM) makes this possible.</xccdf-1.2:description>
            <xccdf-1.2:platform idref="#not_bootc_and_not_container"/>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_encrypt_partitions" selected="false" severity="high">
              <xccdf-1.2:title>Encrypt Partitions</xccdf-1.2:title>
              <xccdf-1.2:description>AlmaLinux OS 8 natively supports partition encryption through the
Linux Unified Key Setup-on-disk-format (LUKS) technology. The easiest way to
encrypt a partition is during installation time.
<html:br/><html:br/>
For manual installations, select the <html:code>Encrypt</html:code> checkbox during
partition creation to encrypt the partition. When this
option is selected the system will prompt for a passphrase to use in
decrypting the partition. The passphrase will subsequently need to be entered manually
every time the system boots.

<html:br/><html:br/>
For automated/unattended installations, it is possible to use Kickstart by adding
the <html:code>--encrypted</html:code> and <html:code>--passphrase=</html:code> options to the definition of each partition to be
encrypted. For example, the following line would encrypt the root partition:
<html:pre>part / --fstype=ext4 --size=100 --onpart=hda1 --encrypted --passphrase=<html:i>PASSPHRASE</html:i></html:pre>
Any <html:i>PASSPHRASE</html:i> is stored in the Kickstart in plaintext, and the Kickstart
must then be protected accordingly.
Omitting the <html:code>--passphrase=</html:code> option from the partition definition will cause the
installer to pause and interactively ask for the passphrase during installation.
<html:br/><html:br/>
By default, the <html:code>Anaconda</html:code> installer uses <html:code>aes-xts-plain64</html:code> cipher
with a minimum <html:code>512</html:code> bit key size which should be compatible with FIPS enabled.

<html:br/><html:br/>
Detailed information on encrypting partitions using LUKS or LUKS ciphers can be found on
the AlmaLinux OS 8 Documentation web site:<html:br/>

    
    <html:a href="https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/security_hardening/encrypting-block-devices-using-luks_security-hardening">https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/security_hardening/encrypting-block-devices-using-luks_security-hardening</html:a>
.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI06.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS04.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.13.16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(iv)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.314(b)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-28</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-28(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000405-GPOS-00184</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000185-GPOS-00079</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000404-GPOS-00183</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010030</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230224r1044787_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The risk of a system's physical compromise, particularly mobile systems such as
laptops, places its data at risk of compromise.  Encrypting this data mitigates
the risk of its loss if the system is lost.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-encrypt_partitions_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_partition_for_boot" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure /boot Located On Separate Partition</xccdf-1.2:title>
              <xccdf-1.2:description>It is recommended that the <html:code>/boot</html:code> directory resides on a separate
partition. This makes it easier to apply restrictions e.g. through the
<html:code>noexec</html:code> mount option. Eventually, the <html:code>/boot</html:code> partition can
be configured not to be mounted automatically with the <html:code>noauto</html:code> mount
option.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>/boot</html:code> partition contains the kernel and bootloader files.
Access to this partition should be restricted.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="high" id="partition_for_boot" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /boot
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_boot" system="urn:redhat:osbuild:blueprint">
[[customizations.filesystem]]
mountpoint = "/boot"
size = 1073741824
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-partition_for_boot:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-partition_for_boot_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_partition_for_dev_shm" selected="false" severity="low">
              <xccdf-1.2:title>Ensure /dev/shm is configured</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>/dev/shm</html:code> is a traditional shared memory concept.
One program will create a memory portion, which other processes
(if permitted) can access. If <html:code>/dev/shm</html:code> is not configured,
tmpfs will be mounted to /dev/shm by systemd.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule does not have a remediation.
It is expected that this will be managed by systemd and will be a tmpfs partition.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.2.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Any user can upload and execute files inside the <html:code>/dev/shm</html:code> similar to
the <html:code>/tmp</html:code> partition. Configuring <html:code>/dev/shm</html:code> allows an administrator
to set the noexec option on the mount, making /dev/shm useless for an attacker to
install executable code. It would also prevent an attacker from establishing a
hardlink to a system setuid program and wait for it to be updated. Once the program
was updated, the hardlink would be broken and the attacker would have his own copy
of the program. If the program happened to have a security vulnerability, the attacker
could continue to exploit the known flaw.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-partition_for_dev_shm:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_partition_for_home" selected="false" severity="low">
              <xccdf-1.2:title>Ensure /home Located On Separate Partition</xccdf-1.2:title>
              <xccdf-1.2:description>If user home directories will be stored locally, create a separate partition
for <html:code>/home</html:code> at installation time (or migrate it later using LVM). If
<html:code>/home</html:code> will be mounted from another system such as an NFS server, then
creating a separate partition is not necessary at installation time, and the
mountpoint can instead be configured later.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010800</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230328r1155410_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Ensuring that <html:code>/home</html:code> is mounted on its own partition enables the
setting of more restrictive mount options, and also helps ensure that
users cannot trivially fill partitions used for log or audit data storage.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="high" id="partition_for_home" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /home
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_home" system="urn:redhat:osbuild:blueprint">
[[customizations.filesystem]]
mountpoint = "/home"
size = 1073741824
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_home" system="urn:xccdf:fix:script:kickstart">
logvol /home 1024
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-partition_for_home:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-partition_for_home_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_partition_for_opt" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure /opt Located On Separate Partition</xccdf-1.2:title>
              <xccdf-1.2:description>It is recommended that the <html:code>/opt</html:code> directory resides on a separate
partition.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>/opt</html:code> partition contains additional software, usually installed
outside the packaging system. Putting this directory on a separate partition
makes it easier to apply restrictions e.g. through the <html:code>nosuid</html:code> mount
option.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="high" id="partition_for_opt" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /opt
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_opt" system="urn:redhat:osbuild:blueprint">
[[customizations.filesystem]]
mountpoint = "/opt"
size = 1073741824
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_opt" system="urn:xccdf:fix:script:kickstart">
logvol /opt 1024
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-partition_for_opt:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-partition_for_opt_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_partition_for_srv" selected="false" severity="unknown">
              <xccdf-1.2:title>Ensure /srv Located On Separate Partition</xccdf-1.2:title>
              <xccdf-1.2:description>If a file server (FTP, TFTP...) is hosted locally, create a separate partition
for <html:code>/srv</html:code> at installation time (or migrate it later using LVM). If
<html:code>/srv</html:code> will be mounted from another system such as an NFS server, then
creating a separate partition is not necessary at installation time, and the
mountpoint can instead be configured later.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Srv deserves files for local network file server such as FTP. Ensuring
that <html:code>/srv</html:code> is mounted on its own partition enables the setting of
more restrictive mount options, and also helps ensure that
users cannot trivially fill partitions used for log or audit data storage.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="high" id="partition_for_srv" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /srv
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_srv" system="urn:redhat:osbuild:blueprint">
[[customizations.filesystem]]
mountpoint = "/srv"
size = 1073741824
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_srv" system="urn:xccdf:fix:script:kickstart">
logvol /srv 1024
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-partition_for_srv:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-partition_for_srv_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_partition_for_tmp" selected="false" severity="low">
              <xccdf-1.2:title>Ensure /tmp Located On Separate Partition</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>/tmp</html:code> directory is a world-writable directory used
for temporary file storage. Ensure it has its own partition or
logical volume at installation time, or migrate it using LVM.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010543</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230295r1017106_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>/tmp</html:code> partition is used as temporary storage by many programs.
Placing <html:code>/tmp</html:code> in its own partition enables the setting of more
restrictive mount options, which can help protect programs which use it.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="high" id="partition_for_tmp" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /tmp
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_tmp" system="urn:redhat:osbuild:blueprint">
[[customizations.filesystem]]
mountpoint = "/tmp"
size = 1073741824
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_tmp" system="urn:xccdf:fix:script:kickstart">
logvol /tmp 1024
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-partition_for_tmp:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-partition_for_tmp_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_partition_for_usr" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure /usr Located On Separate Partition</xccdf-1.2:title>
              <xccdf-1.2:description>It is recommended that the <html:code>/usr</html:code> directory resides on a separate
partition.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>/usr</html:code> partition contains system software, utilities and files.
Putting it on a separate partition allows limiting its size and applying
restrictions through mount options.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="high" id="partition_for_usr" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /usr
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_usr" system="urn:redhat:osbuild:blueprint">
[[customizations.filesystem]]
mountpoint = "/usr"
size = 5368709120
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_usr" system="urn:xccdf:fix:script:kickstart">
logvol /usr 5120
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-partition_for_usr:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-partition_for_usr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_partition_for_var" selected="false" severity="low">
              <xccdf-1.2:title>Ensure /var Located On Separate Partition</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>/var</html:code> directory is used by daemons and other system
services to store frequently-changing data. Ensure that <html:code>/var</html:code> has its own partition
or logical volume at installation time, or migrate it using LVM.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010540</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230292r1017103_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Ensuring that <html:code>/var</html:code> is mounted on its own partition enables the
setting of more restrictive mount options. This helps protect
system services such as daemons or other programs which use it.
It is not uncommon for the <html:code>/var</html:code> directory to contain
world-writable directories installed by other software packages.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="high" id="partition_for_var" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /var
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_var" system="urn:redhat:osbuild:blueprint">
[[customizations.filesystem]]
mountpoint = "/var"
size = 3221225472
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_var" system="urn:xccdf:fix:script:kickstart">
logvol /var 3072
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-partition_for_var:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-partition_for_var_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_partition_for_var_log" selected="false" severity="low">
              <xccdf-1.2:title>Ensure /var/log Located On Separate Partition</xccdf-1.2:title>
              <xccdf-1.2:description>System logs are stored in the <html:code>/var/log</html:code> directory.

Ensure that <html:code>/var/log</html:code> has its own partition or logical
volume at installation time, or migrate it using LVM.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010541</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230293r1017104_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Placing <html:code>/var/log</html:code> in its own partition
enables better separation between log files
and other files in <html:code>/var/</html:code>.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="high" id="partition_for_var_log" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /var/log
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_var_log" system="urn:redhat:osbuild:blueprint">
[[customizations.filesystem]]
mountpoint = "/var/log"
size = 1073741824
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_var_log" system="urn:xccdf:fix:script:kickstart">
logvol /var/log 1024
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-partition_for_var_log:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-partition_for_var_log_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_partition_for_var_log_audit" selected="false" severity="low">
              <xccdf-1.2:title>Ensure /var/log/audit Located On Separate Partition</xccdf-1.2:title>
              <xccdf-1.2:description>Audit logs are stored in the <html:code>/var/log/audit</html:code> directory.

Ensure that <html:code>/var/log/audit</html:code> has its own partition or logical
volume at installation time, or migrate it using LVM.
Make absolutely certain that it is large enough to store all
audit logs that will be created by the auditing daemon.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000341-GPOS-00132</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000357-CTR-000800</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R71</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010542</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230294r1017105_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Placing <html:code>/var/log/audit</html:code> in its own partition
enables better separation between audit files
and other files, and helps ensure that
auditing cannot be halted due to the partition running out
of space.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="high" id="partition_for_var_log_audit" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /var/log/audit
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_var_log_audit" system="urn:redhat:osbuild:blueprint">
[[customizations.filesystem]]
mountpoint = "/var/log/audit"
size = 10737418240
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_var_log_audit" system="urn:xccdf:fix:script:kickstart">
logvol /var/log/audit 10240
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-partition_for_var_log_audit:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-partition_for_var_log_audit_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_partition_for_var_tmp" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure /var/tmp Located On Separate Partition</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>/var/tmp</html:code> directory is a world-writable directory used
for temporary file storage. Ensure it has its own partition or
logical volume at installation time, or migrate it using LVM.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010544</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244529r1017336_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>/var/tmp</html:code> partition is used as temporary storage by many programs.
Placing <html:code>/var/tmp</html:code> in its own partition enables the setting of more
restrictive mount options, which can help protect programs which use it.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="high" id="partition_for_var_tmp" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /var/tmp
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_var_tmp" system="urn:redhat:osbuild:blueprint">
[[customizations.filesystem]]
mountpoint = "/var/tmp"
size = 1073741824
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="partition_for_var_tmp" system="urn:xccdf:fix:script:kickstart">
logvol /var/tmp 1024
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-partition_for_var_tmp:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-partition_for_var_tmp_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_systemd_tmp_mount_enabled" selected="false" severity="low">
              <xccdf-1.2:title>Ensure tmp.mount Unit Is Enabled</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>/tmp</html:code> directory is a world-writable directory used
for temporary file storage. This directory is managed by <html:code>systemd-tmpfiles</html:code>.
Ensure that the <html:code>tmp.mount</html:code> systemd unit is enabled.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>/tmp</html:code> directory is used as temporary storage by many programs.
Placing <html:code>/tmp</html:code> in a tmpfs filesystem enables the setting of more
restrictive mount options, which can help protect programs which use it.
The <html:code>tmp.mount</html:code> unit configures the tmpfs filesystem and ensures
the <html:code>/tmp</html:code> directory is wiped during reboot.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="systemd_tmp_mount_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'tmp.mount'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'tmp.mount'
fi
"$SYSTEMCTL_EXEC" enable 'tmp.mount'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="systemd_tmp_mount_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - systemd_tmp_mount_enabled

- name: Enable mount tmp
  ansible.builtin.systemd:
    name: tmp.mount
    enabled: 'yes'
    state: started
    masked: 'false'
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - systemd_tmp_mount_enabled
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="systemd_tmp_mount_enabled" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
services --enabled=tmp.mount
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-systemd_tmp_mount_enabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-systemd_tmp_mount_enabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_gnome">
            <xccdf-1.2:title>GNOME Desktop Environment</xccdf-1.2:title>
            <xccdf-1.2:description>GNOME is a graphical desktop environment bundled with many Linux distributions that
allow users to easily interact with the operating system graphically rather than
textually. The GNOME Graphical Display Manager (GDM) provides login, logout, and user
switching contexts as well as display server management.
<html:br/><html:br/>
GNOME is developed by the GNOME Project and is considered the default

AlmaLinux Graphical environment.

<html:br/><html:br/>
For more information on GNOME and the GNOME Project, see <html:b><html:a href="https://www.gnome.org">https://www.gnome.org</html:a></html:b>.</xccdf-1.2:description>
            <xccdf-1.2:platform idref="#package_gdm"/>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_gdm_removed" selected="false" severity="medium">
              <xccdf-1.2:title>Remove the GDM Package Group</xccdf-1.2:title>
              <xccdf-1.2:description>
By removing the <html:code>gdm</html:code> package, the system no longer has GNOME installed.

If X Windows is not installed then the system cannot boot into graphical user mode.
This prevents the system from being accidentally or maliciously booted into a <html:code>graphical.target</html:code>
mode. To do so, run the following command:

<html:pre>$ sudo yum remove gdm</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.21</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unnecessary service packages must not be installed to decrease the attack surface of the system.
A graphical environment is unnecessary for certain types of systems including a virtualization
hypervisor.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_gdm_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# CAUTION: This remediation script will remove gdm
# from the system, and may remove any packages
# that depend on gdm. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "gdm" ; then
yum remove -y "gdm"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_gdm_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_gdm_removed

- name: 'Remove the GDM Package Group: Ensure gdm is removed'
  ansible.builtin.package:
    name: gdm
    state: absent
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_gdm_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_gdm_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_gdm

class remove_gdm {
  package { 'gdm':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_gdm_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=gdm
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_gdm_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove gdm
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_gdm_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove gdm
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_gdm_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_gdm_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_db_up_to_date" selected="false" severity="high">
              <xccdf-1.2:title>Make sure that the dconf databases are up-to-date with regards to respective keyfiles</xccdf-1.2:title>
              <xccdf-1.2:description>By default, DConf uses a binary database as a data backend.
The system-level database is compiled from keyfiles in the /etc/dconf/db/
directory by the <html:pre>dconf update</html:pre> command. More specifically, content present
in the following directories:
<html:pre>/etc/dconf/db/gdm.d</html:pre>
<html:pre>/etc/dconf/db/local.d</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">reload_dconf_db</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unlike text-based keyfiles, the binary database is impossible to check by OVAL.
Therefore, in order to evaluate dconf configuration, both have to be true at the same time -
configuration files have to be compliant, and the database needs to be more recent than those keyfiles,
which gives confidence that it reflects them.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix id="dconf_db_up_to_date" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm &amp;&amp; { rpm --quiet -q kernel; }; then

dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_db_up_to_date" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSS-Req-6.2
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_db_up_to_date
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Make sure that the dconf databases are up-to-date with regards to respective
    keyfiles - Get database modification time for gdm
  ansible.builtin.stat:
    path: /etc/dconf/db/gdm
  register: gdm_db
  when:
  - '"gdm" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSS-Req-6.2
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_db_up_to_date
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Make sure that the dconf databases are up-to-date with regards to respective
    keyfiles - Get keyfiles for gdm
  ansible.builtin.find:
    paths: /etc/dconf/db/gdm.d/
  register: gdm_keyfiles
  when:
  - '"gdm" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSS-Req-6.2
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_db_up_to_date
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Make sure that the dconf databases are up-to-date with regards to respective
    keyfiles - Run dconf update for gdm
  ansible.builtin.command:
    cmd: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not gdm_db.stat.exists or gdm_keyfiles.files | length &gt; 0 and gdm_keyfiles.files
    | map(attribute='mtime') | max &gt; gdm_db.stat.mtime
  tags:
  - PCI-DSS-Req-6.2
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_db_up_to_date
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Make sure that the dconf databases are up-to-date with regards to respective
    keyfiles - Get database modification time for local
  ansible.builtin.stat:
    path: /etc/dconf/db/local
  register: local_db
  when:
  - '"gdm" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSS-Req-6.2
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_db_up_to_date
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Make sure that the dconf databases are up-to-date with regards to respective
    keyfiles - Get keyfiles for local
  ansible.builtin.find:
    paths: /etc/dconf/db/local.d/
  register: local_keyfiles
  when:
  - '"gdm" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSS-Req-6.2
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_db_up_to_date
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Make sure that the dconf databases are up-to-date with regards to respective
    keyfiles - Run dconf update for local
  ansible.builtin.command:
    cmd: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not local_db.stat.exists or local_keyfiles.files | length &gt; 0 and local_keyfiles.files
    | map(attribute='mtime') | max &gt; local_db.stat.mtime
  tags:
  - PCI-DSS-Req-6.2
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_db_up_to_date
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_db_up_to_date:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_db_up_to_date_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_enable_dconf_user_profile" selected="false" severity="high">
              <xccdf-1.2:title>Configure GNOME3 DConf User Profile</xccdf-1.2:title>
              <xccdf-1.2:description>By default, DConf provides a standard user profile. This profile contains a list
of DConf configuration databases. The user profile and database always take the
highest priority. As such the DConf User profile should always exist and be
configured correctly.
<html:br/><html:br/>

To make sure that the user profile is configured correctly, the <html:code>/etc/dconf/profile/user</html:code>
should be set as follows:
<html:pre>user-db:user
system-db:local
system-db:site
system-db:distro
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Failure to have a functional DConf profile prevents GNOME3 configuration settings
from being enforced for all users and allows various security risks.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-enable_dconf_user_profile:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-enable_dconf_user_profile_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_xwayland_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable XWayland</xccdf-1.2:title>
              <xccdf-1.2:description>Edit the file <html:code>/etc/gdm/custom.conf</html:code> and add or modify the following line in the
<html:code>[daemon]</html:code> block:
<html:pre>
[daemon]
WaylandEnable=false
</html:pre>
<html:p>
This will disable XWayland support in GDM.
</html:p></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.8.7</xccdf-1.2:reference>
              <xccdf-1.2:rationale>XWayland is a compatibility layer for running X11 applications on Wayland.
It is not secure and should be disabled. Wayland's security benefits from not relying on X11's network listener. Without X11,
there's no network listener, making it harder for malicious actors to exploit vulnerabilities
in X11. However, enabling Xwayland (running X11 applications on Wayland) introduces
X11's security concerns.
All X vulnerabilities apply to Xwayland, including keylogging, but they only affect X
windows and interactions with them.
Malware can potentially exploit Xwayland vulnerabilities to keylog or intercept other
input events.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="xwayland_disabled" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

found=false

# set value in all files if they contain section or key
for f in $(echo -n "/etc/gdm/custom.conf"); do
    if [ ! -e "$f" ]; then
        continue
    fi

    # find key in section and change value
    if grep -qzosP "(?m)^[[:space:]]*\[daemon\]([^\n\[]*\n+)+?[[:space:]]*WaylandEnable" "$f"; then
        if ! grep -qzosP "(?m)^[[:space:]]*WaylandEnable[[:space:]]*=[[:space:]]*false" "$f"; then

            sed -i "/^[[:space:]]*WaylandEnable/s/\([[:blank:]]*=[[:blank:]]*\).*/\1false/" "$f"

        fi

        found=true

    # find section and add key = value to it
    elif grep -qs "^[[:space:]]*\[daemon\]" "$f"; then

            sed -i "/^[[:space:]]*\[daemon\]/a WaylandEnable=false" "$f"

            found=true
    fi
done

# if section not in any file, append section with key = value to FIRST file in files parameter
if ! $found ; then
    file=$(echo "/etc/gdm/custom.conf" | cut -f1 -d ' ')
    mkdir -p "$(dirname "$file")"

    echo -e "[daemon]\nWaylandEnable=false" &gt;&gt; "$file"

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="xwayland_disabled" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - xwayland_disabled

- name: 'Disable XWayland: Disable XWayland'
  community.general.ini_file:
    path: /etc/gdm/custom.conf
    section: daemon
    option: WaylandEnable
    value: 'false'
    create: true
    state: present
  when: '"gdm" in ansible_facts.packages'
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - xwayland_disabled
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-xwayland_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-xwayland_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_gnome_login_screen">
              <xccdf-1.2:title>Configure GNOME Login Screen</xccdf-1.2:title>
              <xccdf-1.2:description>In the default GNOME desktop, the login is displayed after system boot
and can display user accounts, allow users to reboot the system, and allow users to
login automatically and/or with a guest account. The login screen should be configured
to prevent such behavior.
<html:br/><html:br/>

For more information about enforcing preferences in the GNOME3 environment using the DConf
configuration system, see <html:b><html:a href="https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/desktop_migration_and_administration_guide">https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/desktop_migration_and_administration_guide</html:a>/&gt;</html:b> and the man page <html:code>dconf(1)</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_restart_shutdown" selected="false" severity="high">
                <xccdf-1.2:title>Disable the GNOME3 Login Restart and Shutdown Buttons</xccdf-1.2:title>
                <xccdf-1.2:description>In the default graphical environment, users logging directly into the
system are greeted with a login screen that allows any user, known or
unknown, the ability the ability to shutdown or restart the system. This
functionality should be disabled by setting
<html:code>disable-restart-buttons</html:code> to <html:code>true</html:code>.
<html:br/><html:br/>
To disable, add or edit <html:code>disable-restart-buttons</html:code> to
<html:code>/etc/dconf/db/gdm.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/login-screen]
disable-restart-buttons=true</html:pre>
Once the setting has been added, add a lock to
<html:code>/etc/dconf/db/gdm.d/locks/00-security-settings-lock</html:code> to prevent
user modification. For example:
<html:pre>/org/gnome/login-screen/disable-restart-buttons</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:rationale>A user who is at the console can reboot the system at the login screen. If restart or shutdown buttons
are pressed at the login screen, this can create the risk of short-term loss of availability of systems
due to reboot.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_disable_restart_shutdown" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/login-screen\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|gdm.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/gdm.d/00-security-settings"
DBDIR="/etc/dconf/db/gdm.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*disable-restart-buttons\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)disable-restart-buttons(\s*=)/#\1disable-restart-buttons\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/login-screen\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/login-screen]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "true")"
if grep -q "^\\s*disable-restart-buttons\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*disable-restart-buttons\\s*=\\s*.*/disable-restart-buttons=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/login-screen\\]|a\\disable-restart-buttons=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/login-screen/disable-restart-buttons$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|gdm.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/gdm.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/login-screen/disable-restart-buttons$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/login-screen/disable-restart-buttons$" /etc/dconf/db/gdm.d/
then
    echo "/org/gnome/login-screen/disable-restart-buttons" &gt;&gt; "/etc/dconf/db/gdm.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_disable_restart_shutdown" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(b)
  - dconf_gnome_disable_restart_shutdown
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Disable the GNOME3 Login Restart and Shutdown Buttons
  community.general.ini_file:
    dest: /etc/dconf/db/gdm.d/00-security-settings
    section: org/gnome/login-screen
    option: disable-restart-buttons
    value: 'true'
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(b)
  - dconf_gnome_disable_restart_shutdown
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME disablement of Login Restart and Shutdown
    Buttons
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/gdm.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/login-screen/disable-restart-buttons
    line: /org/gnome/login-screen/disable-restart-buttons
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(b)
  - dconf_gnome_disable_restart_shutdown
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - NIST-800-171-3.1.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(b)
  - dconf_gnome_disable_restart_shutdown
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_disable_restart_shutdown:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_disable_restart_shutdown_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_user_list" selected="false" severity="medium">
                <xccdf-1.2:title>Disable the GNOME3 Login User List</xccdf-1.2:title>
                <xccdf-1.2:description>In the default graphical environment, users logging directly into the
system are greeted with a login screen that displays all known users.
This functionality should be disabled by setting <html:code>disable-user-list</html:code>
to <html:code>true</html:code>.
<html:br/><html:br/>
To disable, add or edit <html:code>disable-user-list</html:code> to
<html:code>/etc/dconf/db/gdm.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/login-screen]
disable-user-list=true</html:pre>
Once the setting has been added, add a lock to
<html:code>/etc/dconf/db/gdm.d/locks/00-security-settings-lock</html:code> to prevent
user modification. For example:
<html:pre>/org/gnome/login-screen/disable-user-list</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-23</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.8.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020032</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244536r1017343_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Leaving the user list enabled is a security risk since it allows anyone
with physical access to the system to quickly enumerate known user accounts
without logging in.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_disable_user_list" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/login-screen\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|gdm.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/gdm.d/00-security-settings"
DBDIR="/etc/dconf/db/gdm.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*disable-user-list\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)disable-user-list(\s*=)/#\1disable-user-list\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/login-screen\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/login-screen]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "true")"
if grep -q "^\\s*disable-user-list\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*disable-user-list\\s*=\\s*.*/disable-user-list=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/login-screen\\]|a\\disable-user-list=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/login-screen/disable-user-list$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|gdm.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/gdm.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/login-screen/disable-user-list$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/login-screen/disable-user-list$" /etc/dconf/db/gdm.d/
then
    echo "/org/gnome/login-screen/disable-user-list" &gt;&gt; "/etc/dconf/db/gdm.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_disable_user_list" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020032
  - NIST-800-53-AC-23
  - NIST-800-53-CM-6(a)
  - dconf_gnome_disable_user_list
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Disable the GNOME3 Login User List
  community.general.ini_file:
    dest: /etc/dconf/db/gdm.d/00-security-settings
    section: org/gnome/login-screen
    option: disable-user-list
    value: 'true'
    no_extra_spaces: true
    create: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020032
  - NIST-800-53-AC-23
  - NIST-800-53-CM-6(a)
  - dconf_gnome_disable_user_list
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME3 disablement of Login User List
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/gdm.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/login-screen/disable-user-list$
    line: /org/gnome/login-screen/disable-user-list
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020032
  - NIST-800-53-AC-23
  - NIST-800-53-CM-6(a)
  - dconf_gnome_disable_user_list
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - DISA-STIG-RHEL-08-020032
  - NIST-800-53-AC-23
  - NIST-800-53-CM-6(a)
  - dconf_gnome_disable_user_list
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_disable_user_list:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_disable_user_list_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_enable_smartcard_auth" selected="false" severity="medium">
                <xccdf-1.2:title>Enable the GNOME3 Login Smartcard Authentication</xccdf-1.2:title>
                <xccdf-1.2:description>In the default graphical environment, smart card authentication
can be enabled on the login screen by setting <html:code>enable-smartcard-authentication</html:code>
to <html:code>true</html:code>.
<html:br/><html:br/>
To enable, add or edit <html:code>enable-smartcard-authentication</html:code> to
<html:code>/etc/dconf/db/gdm.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/login-screen]
enable-smartcard-authentication=true</html:pre>
Once the setting has been added, add a lock to
<html:code>/etc/dconf/db/gdm.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/login-screen/enable-smartcard-authentication</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(4)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(8)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(9)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(11)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000375-GPOS-00160</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000376-GPOS-00161</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000377-GPOS-00162</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Smart card login provides two-factor authentication stronger than
that provided by a username and password combination. Smart cards leverage PKI
(public key infrastructure) in order to provide and verify credentials.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_enable_smartcard_auth" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/login-screen\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|gdm.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/gdm.d/00-security-settings"
DBDIR="/etc/dconf/db/gdm.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*enable-smartcard-authentication\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)enable-smartcard-authentication(\s*=)/#\1enable-smartcard-authentication\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/login-screen\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/login-screen]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "true")"
if grep -q "^\\s*enable-smartcard-authentication\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*enable-smartcard-authentication\\s*=\\s*.*/enable-smartcard-authentication=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/login-screen\\]|a\\enable-smartcard-authentication=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/login-screen/enable-smartcard-authentication$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|gdm.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/gdm.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/login-screen/enable-smartcard-authentication$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/login-screen/enable-smartcard-authentication$" /etc/dconf/db/gdm.d/
then
    echo "/org/gnome/login-screen/enable-smartcard-authentication" &gt;&gt; "/etc/dconf/db/gdm.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_enable_smartcard_auth" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-IA-2(11)
  - NIST-800-53-IA-2(3)
  - NIST-800-53-IA-2(4)
  - NIST-800-53-IA-2(8)
  - NIST-800-53-IA-2(9)
  - PCI-DSS-Req-8.3
  - dconf_gnome_enable_smartcard_auth
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Enable the GNOME3 Login Smartcard Authentication
  community.general.ini_file:
    dest: /etc/dconf/db/gdm.d/00-security-settings
    section: org/gnome/login-screen
    option: enable-smartcard-authentication
    value: 'true'
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-53-IA-2(11)
  - NIST-800-53-IA-2(3)
  - NIST-800-53-IA-2(4)
  - NIST-800-53-IA-2(8)
  - NIST-800-53-IA-2(9)
  - PCI-DSS-Req-8.3
  - dconf_gnome_enable_smartcard_auth
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME3 disablement of Smartcard Authentication
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/gdm.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/login-screen/enable-smartcard-authentication$
    line: /org/gnome/login-screen/enable-smartcard-authentication
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-53-IA-2(11)
  - NIST-800-53-IA-2(3)
  - NIST-800-53-IA-2(4)
  - NIST-800-53-IA-2(8)
  - NIST-800-53-IA-2(9)
  - PCI-DSS-Req-8.3
  - dconf_gnome_enable_smartcard_auth
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - NIST-800-53-IA-2(11)
  - NIST-800-53-IA-2(3)
  - NIST-800-53-IA-2(4)
  - NIST-800-53-IA-2(8)
  - NIST-800-53-IA-2(9)
  - PCI-DSS-Req-8.3
  - dconf_gnome_enable_smartcard_auth
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_enable_smartcard_auth:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_enable_smartcard_auth_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_lock_screen_on_smartcard_removal" selected="false" severity="medium">
                <xccdf-1.2:title>Enable the GNOME3 Screen Locking On Smartcard Removal</xccdf-1.2:title>
                <xccdf-1.2:description>In the default graphical environment, screen locking on smartcard removal
can be enabled by setting <html:code>removal-action</html:code>
to <html:code>'lock-screen'</html:code>.
<html:br/><html:br/>
To enable, add or edit <html:code>removal-action</html:code> to
<html:code>/etc/dconf/db/local.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/settings-daemon/peripherals/smartcard]
removal-action='lock-screen'</html:pre>
Once the setting has been added, add a lock to
<html:code>/etc/dconf/db/local.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/settings-daemon/peripherals/smartcard/removal-action</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000028-GPOS-00009</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000030-GPOS-00011</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020050</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230351r1017164_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Locking the screen automatically when removing the smartcard can
prevent undesired access to system.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_lock_screen_on_smartcard_removal" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/settings-daemon/peripherals/smartcard\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*removal-action\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)removal-action(\s*=)/#\1removal-action\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/settings-daemon/peripherals/smartcard\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/settings-daemon/peripherals/smartcard]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "'lock-screen'")"
if grep -q "^\\s*removal-action\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*removal-action\\s*=\\s*.*/removal-action=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/settings-daemon/peripherals/smartcard\\]|a\\removal-action=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/settings-daemon/peripherals/smartcard/removal-action$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/settings-daemon/peripherals/smartcard/removal-action$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/settings-daemon/peripherals/smartcard/removal-action$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/settings-daemon/peripherals/smartcard/removal-action" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_lock_screen_on_smartcard_removal" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020050
  - dconf_gnome_lock_screen_on_smartcard_removal
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Detect if removal-action can be found on /etc/dconf/db/local.d/
  ansible.builtin.find:
    path: /etc/dconf/db/local.d/
    contains: ^\s*removal-action
  register: dconf_gnome_lock_screen_on_smartcard_removal_config_files
  when: '"gdm" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020050
  - dconf_gnome_lock_screen_on_smartcard_removal
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Configure removal-action - default file
  community.general.ini_file:
    dest: /etc/dconf/db/local.d//00-security-settings
    section: org/gnome/settings-daemon/peripherals/smartcard
    option: removal-action
    value: '''lock-screen'''
    create: true
  when:
  - '"gdm" in ansible_facts.packages'
  - dconf_gnome_lock_screen_on_smartcard_removal_config_files is defined and dconf_gnome_lock_screen_on_smartcard_removal_config_files.matched
    == 0
  register: default_file
  tags:
  - DISA-STIG-RHEL-08-020050
  - dconf_gnome_lock_screen_on_smartcard_removal
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Configure removal-action - existing files
  community.general.ini_file:
    dest: '{{ item.path }}'
    section: org/gnome/settings-daemon/peripherals/smartcard
    option: removal-action
    value: '''lock-screen'''
    create: true
  with_items: '{{ dconf_gnome_lock_screen_on_smartcard_removal_config_files.files
    }}'
  when:
  - '"gdm" in ansible_facts.packages'
  - dconf_gnome_lock_screen_on_smartcard_removal_config_files is defined and dconf_gnome_lock_screen_on_smartcard_removal_config_files.matched
    &gt; 0
  register: existing_files
  tags:
  - DISA-STIG-RHEL-08-020050
  - dconf_gnome_lock_screen_on_smartcard_removal
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Detect if lock for removal-action can be found on /etc/dconf/db/local.d/
  ansible.builtin.find:
    path: /etc/dconf/db/local.d/locks
    contains: ^\s*removal-action
  register: dconf_gnome_lock_screen_on_smartcard_removal_lock_files
  when: '"gdm" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020050
  - dconf_gnome_lock_screen_on_smartcard_removal
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification removal-action - default file
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/settings-daemon/peripherals/smartcard/removal-action$
    line: /org/gnome/settings-daemon/peripherals/smartcard/removal-action
    create: true
  when:
  - '"gdm" in ansible_facts.packages'
  - dconf_gnome_lock_screen_on_smartcard_removal_lock_files is defined and dconf_gnome_lock_screen_on_smartcard_removal_lock_files.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-020050
  - dconf_gnome_lock_screen_on_smartcard_removal
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification removal-action - existing files
  ansible.builtin.lineinfile:
    path: '{{ item.path }}'
    regexp: ^/org/gnome/settings-daemon/peripherals/smartcard/removal-action$
    line: /org/gnome/settings-daemon/peripherals/smartcard/removal-action
    create: true
  with_items: '{{ dconf_gnome_lock_screen_on_smartcard_removal_lock_files.files }}'
  when:
  - '"gdm" in ansible_facts.packages'
  - dconf_gnome_lock_screen_on_smartcard_removal_lock_files is defined and dconf_gnome_lock_screen_on_smartcard_removal_lock_files.matched
    &gt; 0
  tags:
  - DISA-STIG-RHEL-08-020050
  - dconf_gnome_lock_screen_on_smartcard_removal
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update - removal-action
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - default_file is changed or existing_files is changed
  tags:
  - DISA-STIG-RHEL-08-020050
  - dconf_gnome_lock_screen_on_smartcard_removal
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_lock_screen_on_smartcard_removal:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_lock_screen_on_smartcard_removal_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_login_retries" selected="false" severity="medium">
                <xccdf-1.2:title>Set the GNOME3 Login Number of Failures</xccdf-1.2:title>
                <xccdf-1.2:description>In the default graphical environment, the GNOME3 login
screen and be configured to restart the authentication process after
a configured number of attempts. This can be configured by setting
<html:code>allowed-failures</html:code> to <html:code>3</html:code> or less.
<html:br/><html:br/>
To enable, add or edit <html:code>allowed-failures</html:code> to
<html:code>/etc/dconf/db/gdm.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/login-screen]
allowed-failures=3</html:pre>
Once the setting has been added, add a lock to
<html:code>/etc/dconf/db/gdm.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/login-screen/allowed-failures</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.8</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Setting the password retry prompts that are permitted on a per-session basis to a low value
requires some software, such as SSH, to re-connect. This can slow down and
draw additional attention to some types of password-guessing attacks.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_login_retries" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/login-screen\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|gdm.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/gdm.d/00-security-settings"
DBDIR="/etc/dconf/db/gdm.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*allowed-failures\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)allowed-failures(\s*=)/#\1allowed-failures\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/login-screen\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/login-screen]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "3")"
if grep -q "^\\s*allowed-failures\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*allowed-failures\\s*=\\s*.*/allowed-failures=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/login-screen\\]|a\\allowed-failures=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/login-screen/allowed-failures$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|gdm.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/gdm.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/login-screen/allowed-failures$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/login-screen/allowed-failures$" /etc/dconf/db/gdm.d/
then
    echo "/org/gnome/login-screen/allowed-failures" &gt;&gt; "/etc/dconf/db/gdm.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_login_retries" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.8
  - dconf_gnome_login_retries
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Enable the GNOME3 Login Number of Failures
  community.general.ini_file:
    dest: /etc/dconf/db/gdm.d/00-security-settings
    section: org/gnome/login-screen
    option: allowed-failures
    value: '3'
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.8
  - dconf_gnome_login_retries
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME3 Login Number of Failures
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/gdm.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/login-screen/allowed-failures$
    line: /org/gnome/login-screen/allowed-failures
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.8
  - dconf_gnome_login_retries
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - NIST-800-171-3.1.8
  - dconf_gnome_login_retries
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_login_retries:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_login_retries_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_gnome_gdm_disable_automatic_login" selected="false" severity="high">
                <xccdf-1.2:title>Disable GDM Automatic Login</xccdf-1.2:title>
                <xccdf-1.2:description>The GNOME Display Manager (GDM) can allow users to automatically login without
user interaction or credentials. User should always be required to authenticate themselves
to the system that they are authorized to use. To disable user ability to automatically
login to the system, set the <html:code>AutomaticLoginEnable</html:code> to <html:code>false</html:code> in the
<html:code>[daemon]</html:code> section in <html:code>/etc/gdm/custom.conf</html:code>. For example:
<html:pre>[daemon]
AutomaticLoginEnable=false</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00229</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010820</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230329r1017140_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Failure to restrict system access to authenticated users negatively impacts operating
system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="gnome_gdm_disable_automatic_login" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

if rpm --quiet -q gdm
then
	if ! grep -q "^AutomaticLoginEnable=" /etc/gdm/custom.conf
	then
		sed -i "/^\[daemon\]/a \
		AutomaticLoginEnable=False" /etc/gdm/custom.conf
	else
		sed -i "s/^AutomaticLoginEnable=.*/AutomaticLoginEnable=False/g" /etc/gdm/custom.conf
	fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="gnome_gdm_disable_automatic_login" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010820
  - NIST-800-171-3.1.1
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.1
  - gnome_gdm_disable_automatic_login
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Disable GDM Automatic Login
  community.general.ini_file:
    dest: /etc/gdm/custom.conf
    section: daemon
    option: AutomaticLoginEnable
    value: 'false'
    no_extra_spaces: true
    create: true
  when: '"gdm" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010820
  - NIST-800-171-3.1.1
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.1
  - gnome_gdm_disable_automatic_login
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-gnome_gdm_disable_automatic_login:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-gnome_gdm_disable_automatic_login_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_gnome_gdm_disable_guest_login" selected="false" severity="high">
                <xccdf-1.2:title>Disable GDM Guest Login</xccdf-1.2:title>
                <xccdf-1.2:description>The GNOME Display Manager (GDM) can allow users to login without credentials
which can be useful for public kiosk scenarios. Allowing users to login without credentials
or "guest" account access has inherent security risks and should be disabled. To do disable
timed logins or guest account access, set the <html:code>TimedLoginEnable</html:code> to <html:code>false</html:code> in
the <html:code>[daemon]</html:code> section in <html:code>/etc/gdm/custom.conf</html:code>. For example:
<html:pre>[daemon]
TimedLoginEnable=false</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00229</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Failure to restrict system access to authenticated users negatively impacts operating
system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="gnome_gdm_disable_guest_login" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

if rpm --quiet -q gdm
then
	if ! grep -q "^TimedLoginEnable=" /etc/gdm/custom.conf
	then
		sed -i "/^\[daemon\]/a \
		TimedLoginEnable=false" /etc/gdm/custom.conf
	else
		sed -i "s/^TimedLoginEnable=.*/TimedLoginEnable=false/g" /etc/gdm/custom.conf
	fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="gnome_gdm_disable_guest_login" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.1
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-2
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.1
  - gnome_gdm_disable_guest_login
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Disable GDM Guest Login
  community.general.ini_file:
    dest: /etc/gdm/custom.conf
    section: daemon
    option: TimedLoginEnable
    value: 'false'
    no_extra_spaces: true
    create: true
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.1
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-2
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.1
  - gnome_gdm_disable_guest_login
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-gnome_gdm_disable_guest_login:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-gnome_gdm_disable_guest_login_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_gnome_gdm_disable_xdmcp" selected="false" severity="high">
                <xccdf-1.2:title>Disable XDMCP in GDM</xccdf-1.2:title>
                <xccdf-1.2:description>XDMCP is an unencrypted protocol, and therefore, presents a security risk.
To disable XDMCP support in Gnome, set <html:code>Enable</html:code> to <html:code>false</html:code> under the <html:code>[xdmcp]</html:code> configuration section in <html:code>/etc/gdm/custom.conf</html:code>. For example:
<html:pre>
[xdmcp]
Enable=false
</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.8.6</xccdf-1.2:reference>
                <xccdf-1.2:rationale>XDMCP provides unencrypted remote access through the Gnome Display Manager (GDM) which does
not provide for the confidentiality and integrity of user passwords or the
remote session. If a privileged user were to login using XDMCP, the
privileged user password could be compromised due to typed XEvents
and keystrokes will traversing over the network in clear text.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="gnome_gdm_disable_xdmcp" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Try find '[xdmcp]' and 'Enable' in '/etc/gdm/custom.conf', if it exists, set
# to 'false', if it isn't here, add it, if '[xdmcp]' doesn't exist, add it there
if grep -qzosP '[[:space:]]*\[xdmcp]([^\n\[]*\n+)+?[[:space:]]*Enable' '/etc/gdm/custom.conf'; then
    
    sed -i "s/Enable[^(\n)]*/Enable=false/" '/etc/gdm/custom.conf'
elif grep -qs '[[:space:]]*\[xdmcp]' '/etc/gdm/custom.conf'; then
    sed -i "/[[:space:]]*\[xdmcp]/a Enable=false" '/etc/gdm/custom.conf'
else
    if test -d "/etc/gdm"; then
        printf '%s\n' '[xdmcp]' "Enable=false" &gt;&gt; '/etc/gdm/custom.conf'
    else
        echo "Config file directory '/etc/gdm' doesnt exist, not remediating, assuming non-applicability." &gt;&amp;2
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="gnome_gdm_disable_xdmcp" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - gnome_gdm_disable_xdmcp
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Disable XDMCP in GDM
  community.general.ini_file:
    path: /etc/gdm/custom.conf
    section: xdmcp
    option: Enable
    value: 'false'
    create: true
    mode: 420
  when: '"gdm" in ansible_facts.packages'
  tags:
  - gnome_gdm_disable_xdmcp
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-gnome_gdm_disable_xdmcp:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_gnome_media_settings">
              <xccdf-1.2:title>GNOME Media Settings</xccdf-1.2:title>
              <xccdf-1.2:description>GNOME media settings that apply to the graphical interface.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_automount" selected="false" severity="medium">
                <xccdf-1.2:title>Disable GNOME3 Automounting</xccdf-1.2:title>
                <xccdf-1.2:description>The system's default desktop environment, GNOME3, will mount
devices and removable media (such as DVDs, CDs and USB flash drives) whenever
they are inserted into the system. To disable automount within GNOME3, add or set
<html:code>automount</html:code> to <html:code>false</html:code> in <html:code>/etc/dconf/db/gdm.d/00-security-settings</html:code>.
For example:
<html:pre>[org/gnome/desktop/media-handling]
automount=false</html:pre>
Once the settings have been added, add a lock to
<html:code>/etc/dconf/db/gdm.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/desktop/media-handling/automount</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000114-GPOS-00059</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000378-GPOS-00163</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.8.4</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Disabling automatic mounting in GNOME3 can prevent
the introduction of malware via removable media.
It will, however, also prevent desktop users from legitimate use
of removable media.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_disable_automount" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# apply fix for enable_dconf_user_profile, OVAL checks it

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/desktop/media-handling\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*automount\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)automount(\s*=)/#\1automount\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/desktop/media-handling\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/desktop/media-handling]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "false")"
if grep -q "^\\s*automount\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*automount\\s*=\\s*.*/automount=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/desktop/media-handling\\]|a\\automount=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/desktop/media-handling/automount$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/desktop/media-handling/automount$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/desktop/media-handling/automount$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/desktop/media-handling/automount" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_disable_automount" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-3.4
  - PCI-DSSv4-3.4.2
  - dconf_gnome_disable_automount
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Disable GNOME3 Automounting - automount
  community.general.ini_file:
    dest: /etc/dconf/db/local.d/00-security-settings
    section: org/gnome/desktop/media-handling
    option: automount
    value: 'false'
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-3.4
  - PCI-DSSv4-3.4.2
  - dconf_gnome_disable_automount
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME3 Automounting - automount
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/desktop/media-handling/automount$
    line: /org/gnome/desktop/media-handling/automount
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-3.4
  - PCI-DSSv4-3.4.2
  - dconf_gnome_disable_automount
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-3.4
  - PCI-DSSv4-3.4.2
  - dconf_gnome_disable_automount
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_disable_automount:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_disable_automount_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_automount_open" selected="false" severity="medium">
                <xccdf-1.2:title>Disable GNOME3 Automount Opening</xccdf-1.2:title>
                <xccdf-1.2:description>The system's default desktop environment, GNOME3, will mount
devices and removable media (such as DVDs, CDs and USB flash drives) whenever
they are inserted into the system. To disable automount-open within GNOME3, add or set
<html:code>automount-open</html:code> to <html:code>false</html:code> in <html:code>/etc/dconf/db/gdm.d/00-security-settings</html:code>.
For example:
<html:pre>[org/gnome/desktop/media-handling]
automount-open=false</html:pre>
Once the settings have been added, add a lock to
<html:code>/etc/dconf/db/gdm.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/desktop/media-handling/automount-open</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000114-GPOS-00059</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000378-GPOS-00163</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.8.4</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Automatically mounting file systems permits easy introduction of unknown devices, thereby facilitating malicious activity.
Disabling automatic mounting in GNOME3 can prevent
the introduction of malware via removable media.
It will, however, also prevent desktop users from legitimate use
of removable media.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_disable_automount_open" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# apply fix for enable_dconf_user_profile, OVAL checks it

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/desktop/media-handling\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*automount-open\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)automount-open(\s*=)/#\1automount-open\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/desktop/media-handling\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/desktop/media-handling]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "false")"
if grep -q "^\\s*automount-open\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*automount-open\\s*=\\s*.*/automount-open=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/desktop/media-handling\\]|a\\automount-open=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/desktop/media-handling/automount-open$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/desktop/media-handling/automount-open$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/desktop/media-handling/automount-open$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/desktop/media-handling/automount-open" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_disable_automount_open" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-3.4
  - PCI-DSSv4-3.4.2
  - dconf_gnome_disable_automount_open
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Disable GNOME3 Automounting - automount-open
  community.general.ini_file:
    dest: /etc/dconf/db/local.d/00-security-settings
    section: org/gnome/desktop/media-handling
    option: automount-open
    value: 'false'
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-3.4
  - PCI-DSSv4-3.4.2
  - dconf_gnome_disable_automount_open
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME3 Automounting - automount-open
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/desktop/media-handling/automount-open$
    line: /org/gnome/desktop/media-handling/automount-open
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-3.4
  - PCI-DSSv4-3.4.2
  - dconf_gnome_disable_automount_open
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-3.4
  - PCI-DSSv4-3.4.2
  - dconf_gnome_disable_automount_open
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_disable_automount_open:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_disable_automount_open_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_autorun" selected="false" severity="low">
                <xccdf-1.2:title>Disable GNOME3 Automount running</xccdf-1.2:title>
                <xccdf-1.2:description>The system's default desktop environment, GNOME3, will mount
devices and removable media (such as DVDs, CDs and USB flash drives) whenever
they are inserted into the system. To disable autorun-never within GNOME3, add or set
<html:code>autorun-never</html:code> to <html:code>true</html:code> in <html:code>/etc/dconf/db/gdm.d/00-security-settings</html:code>.
For example:
<html:pre>[org/gnome/desktop/media-handling]
autorun-never=true</html:pre>
Once the settings have been added, add a lock to
<html:code>/etc/dconf/db/gdm.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/desktop/media-handling/autorun-never</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000114-GPOS-00059</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000378-GPOS-00163</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.8.5</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Automatically mounting file systems permits easy introduction of unknown devices, thereby facilitating malicious activity.
Disabling automatic mount running in GNOME3 can prevent
the introduction of malware via removable media.
It will, however, also prevent desktop users from legitimate use
of removable media.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_disable_autorun" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/desktop/media-handling\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*autorun-never\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)autorun-never(\s*=)/#\1autorun-never\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/desktop/media-handling\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/desktop/media-handling]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "true")"
if grep -q "^\\s*autorun-never\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*autorun-never\\s*=\\s*.*/autorun-never=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/desktop/media-handling\\]|a\\autorun-never=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/desktop/media-handling/autorun-never$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/desktop/media-handling/autorun-never$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/desktop/media-handling/autorun-never$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/desktop/media-handling/autorun-never" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_disable_autorun" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - dconf_gnome_disable_autorun
  - low_complexity
  - low_severity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Disable GNOME3 Automounting - autorun-never
  community.general.ini_file:
    dest: /etc/dconf/db/local.d/00-security-settings
    section: org/gnome/desktop/media-handling
    option: autorun-never
    value: 'true'
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - dconf_gnome_disable_autorun
  - low_complexity
  - low_severity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME3 Automounting - autorun-never
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/desktop/media-handling/autorun-never$
    line: /org/gnome/desktop/media-handling/autorun-never
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - dconf_gnome_disable_autorun
  - low_complexity
  - low_severity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - dconf_gnome_disable_autorun
  - low_complexity
  - low_severity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_disable_autorun:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_disable_autorun_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_thumbnailers" selected="false" severity="unknown">
                <xccdf-1.2:title>Disable All GNOME3 Thumbnailers</xccdf-1.2:title>
                <xccdf-1.2:description>The system's default desktop environment, GNOME3, uses
a number of different thumbnailer programs to generate thumbnails
for any new or modified content in an opened folder. To disable the
execution of these thumbnail applications, add or set <html:code>disable-all</html:code>
to <html:code>true</html:code> in <html:code>/etc/dconf/db/local.d/00-security-settings</html:code>.
For example:
<html:pre>[org/gnome/desktop/thumbnailers]
disable-all=true</html:pre>
Once the settings have been added, add a lock to
<html:code>/etc/dconf/db/local.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/desktop/thumbnailers/disable-all</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.
This effectively prevents an attacker from gaining access to a
system through a flaw in GNOME3's Nautilus thumbnail creators.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>An attacker with knowledge of a flaw in a GNOME3 thumbnailer application could craft a malicious
file to exploit this flaw. Assuming the attacker could place the malicious file on the local filesystem
(via a web upload for example) and assuming a user browses the same location using Nautilus, the
malicious file would exploit the thumbnailer with the potential for malicious code execution. It
is best to disable these thumbnailer applications unless they are explicitly required.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_disable_thumbnailers" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/desktop/thumbnailers\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*disable-all\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)disable-all(\s*=)/#\1disable-all\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/desktop/thumbnailers\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/desktop/thumbnailers]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "true")"
if grep -q "^\\s*disable-all\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*disable-all\\s*=\\s*.*/disable-all=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/desktop/thumbnailers\\]|a\\disable-all=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/desktop/thumbnailers/disable-all$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/desktop/thumbnailers/disable-all$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/desktop/thumbnailers/disable-all$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/desktop/thumbnailers/disable-all" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_disable_thumbnailers" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - dconf_gnome_disable_thumbnailers
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_severity
  - unknown_strategy

- name: Disable All GNOME3 Thumbnailers
  community.general.ini_file:
    dest: /etc/dconf/db/local.d/00-security-settings
    section: org/gnome/desktop/thumbnailers
    option: disable-all
    value: 'true'
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - dconf_gnome_disable_thumbnailers
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_severity
  - unknown_strategy

- name: Prevent user modification of GNOME3 Thumbnailers
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/desktop/thumbnailers/disable-all$
    line: /org/gnome/desktop/thumbnailers/disable-all
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - dconf_gnome_disable_thumbnailers
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_severity
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - dconf_gnome_disable_thumbnailers
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_severity
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_disable_thumbnailers:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_disable_thumbnailers_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_gnome_network_settings">
              <xccdf-1.2:title>GNOME Network Settings</xccdf-1.2:title>
              <xccdf-1.2:description>GNOME network settings that apply to the graphical interface.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_wifi_create" selected="false" severity="medium">
                <xccdf-1.2:title>Disable WIFI Network Connection Creation in GNOME3</xccdf-1.2:title>
                <xccdf-1.2:description><html:code>GNOME</html:code> allows users to create ad-hoc wireless connections through the
<html:code>NetworkManager</html:code> applet. Wireless connections should be disabled by
adding or setting <html:code>disable-wifi-create</html:code> to <html:code>true</html:code> in
<html:code>/etc/dconf/db/local.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/nm-applet]
disable-wifi-create=true
</html:pre>
Once the settings have been added, add a lock to
<html:code>/etc/dconf/db/local.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/nm-applet/disable-wifi-create</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.16</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Wireless network connections should not be allowed to be configured by general
users on a given system as it could open the system to backdoor attacks.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_disable_wifi_create" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/nm-applet\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*disable-wifi-create\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)disable-wifi-create(\s*=)/#\1disable-wifi-create\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/nm-applet\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/nm-applet]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "true")"
if grep -q "^\\s*disable-wifi-create\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*disable-wifi-create\\s*=\\s*.*/disable-wifi-create=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/nm-applet\\]|a\\disable-wifi-create=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/nm-applet/disable-wifi-create$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/nm-applet/disable-wifi-create$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/nm-applet/disable-wifi-create$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/nm-applet/disable-wifi-create" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_disable_wifi_create" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.16
  - dconf_gnome_disable_wifi_create
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Disable WiFi Network Connection Creation in GNOME3
  community.general.ini_file:
    dest: /etc/dconf/db/local.d/00-security-settings
    section: org/gnome/nm-applet
    option: disable-wifi-create
    value: 'true'
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.16
  - dconf_gnome_disable_wifi_create
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME3 disablement of WiFi
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/nm-applet/disable-wifi-create$
    line: /org/gnome/nm-applet/disable-wifi-create
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.16
  - dconf_gnome_disable_wifi_create
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - NIST-800-171-3.1.16
  - dconf_gnome_disable_wifi_create
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_disable_wifi_create:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_disable_wifi_create_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_wifi_notification" selected="false" severity="medium">
                <xccdf-1.2:title>Disable WIFI Network Notification in GNOME3</xccdf-1.2:title>
                <xccdf-1.2:description>By default, <html:code>GNOME</html:code> disables WIFI notification. This should be permanently set
so that users do not connect to a wireless network when the system finds one.
While useful for mobile devices, this setting should be disabled for all other systems.
To configure the system to disable the WIFI notification, add or set
<html:code>suppress-wireless-networks-available</html:code> to <html:code>true</html:code> in
<html:code>/etc/dconf/db/local.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/nm-applet]
suppress-wireless-networks-available=true
</html:pre>
Once the settings have been added, add a lock to
<html:code>/etc/dconf/db/local.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/nm-applet/suppress-wireless-networks-available</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.16</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Wireless network connections should not be allowed to be configured by general
users on a given system as it could open the system to backdoor attacks.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_disable_wifi_notification" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/nm-applet\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*suppress-wireless-networks-available\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)suppress-wireless-networks-available(\s*=)/#\1suppress-wireless-networks-available\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/nm-applet\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/nm-applet]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "true")"
if grep -q "^\\s*suppress-wireless-networks-available\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*suppress-wireless-networks-available\\s*=\\s*.*/suppress-wireless-networks-available=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/nm-applet\\]|a\\suppress-wireless-networks-available=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/nm-applet/suppress-wireless-networks-available$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/nm-applet/suppress-wireless-networks-available$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/nm-applet/suppress-wireless-networks-available$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/nm-applet/suppress-wireless-networks-available" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_disable_wifi_notification" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.16
  - dconf_gnome_disable_wifi_notification
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Disable WiFi Network Notification in GNOME3
  community.general.ini_file:
    dest: /etc/dconf/db/local.d/00-security-settings
    section: org/gnome/nm-applet
    option: suppress-wireless-networks-available
    value: 'true'
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.16
  - dconf_gnome_disable_wifi_notification
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME3 disablement of WiFi
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/nm-applet/suppress-wireless-networks-available$
    line: /org/gnome/nm-applet/suppress-wireless-networks-available
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.16
  - dconf_gnome_disable_wifi_notification
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - NIST-800-171-3.1.16
  - dconf_gnome_disable_wifi_notification
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_disable_wifi_notification:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_disable_wifi_notification_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_gnome_remote_access_settings">
              <xccdf-1.2:title>GNOME Remote Access Settings</xccdf-1.2:title>
              <xccdf-1.2:description>GNOME remote access settings that apply to the graphical interface.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_remote_access_credential_prompt" selected="false" severity="medium">
                <xccdf-1.2:title>Require Credential Prompting for Remote Access in GNOME3</xccdf-1.2:title>
                <xccdf-1.2:description>By default, <html:code>GNOME</html:code> does not require credentials when using <html:code>Vino</html:code> for
remote access. To configure the system to require remote credentials, add or set
<html:code>authentication-methods</html:code> to <html:code>['vnc']</html:code> in
<html:code>/etc/dconf/db/gdm.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/Vino]
authentication-methods=['vnc']
</html:pre>
Once the settings have been added, add a lock to
<html:code>/etc/dconf/db/gdm.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/Vino/authentication-methods</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Username and password prompting is required for remote access. Otherwise, non-authorized
and nefarious users can access the system freely.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_remote_access_credential_prompt" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/Vino\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*authentication-methods\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)authentication-methods(\s*=)/#\1authentication-methods\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/Vino\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/Vino]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "['vnc']")"
if grep -q "^\\s*authentication-methods\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*authentication-methods\\s*=\\s*.*/authentication-methods=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/Vino\\]|a\\authentication-methods=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/Vino/authentication-methods$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/Vino/authentication-methods$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/Vino/authentication-methods$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/Vino/authentication-methods" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_remote_access_credential_prompt" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.12
  - dconf_gnome_remote_access_credential_prompt
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Require Credential Prompting for Remote Access in GNOME3
  community.general.ini_file:
    dest: /etc/dconf/db/local.d/00-security-settings
    section: org/gnome/Vino
    option: authentication-methods
    value: '[''vnc'']'
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.12
  - dconf_gnome_remote_access_credential_prompt
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME3 Credential Prompting for Remote Access
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/Vino/authentication-methods$
    line: /org/gnome/Vino/authentication-methods
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.12
  - dconf_gnome_remote_access_credential_prompt
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - NIST-800-171-3.1.12
  - dconf_gnome_remote_access_credential_prompt
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_remote_access_credential_prompt:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_remote_access_credential_prompt_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_remote_access_encryption" selected="false" severity="medium">
                <xccdf-1.2:title>Require Encryption for Remote Access in GNOME3</xccdf-1.2:title>
                <xccdf-1.2:description>By default, <html:code>GNOME</html:code> requires encryption when using <html:code>Vino</html:code> for remote access.
To prevent remote access encryption from being disabled, add or set
<html:code>require-encryption</html:code> to <html:code>true</html:code> in
<html:code>/etc/dconf/db/gdm.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/Vino]
require-encryption=true
</html:pre>
Once the settings have been added, add a lock to
<html:code>/etc/dconf/db/gdm.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/Vino/require-encryption</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.08</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI07.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Open X displays allow an attacker to capture keystrokes and to execute commands
remotely.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_remote_access_encryption" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/Vino\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*require-encryption\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)require-encryption(\s*=)/#\1require-encryption\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/Vino\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/Vino]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "true")"
if grep -q "^\\s*require-encryption\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*require-encryption\\s*=\\s*.*/require-encryption=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/Vino\\]|a\\require-encryption=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/Vino/require-encryption$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/Vino/require-encryption$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/Vino/require-encryption$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/Vino/require-encryption" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_remote_access_encryption" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.13
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - dconf_gnome_remote_access_encryption
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Require Encryption for Remote Access in GNOME3
  community.general.ini_file:
    dest: /etc/dconf/db/local.d/00-security-settings
    section: org/gnome/Vino
    option: require-encryption
    value: 'true'
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.13
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - dconf_gnome_remote_access_encryption
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME3 Encryption for Remote Access
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/Vino/require-encryption$
    line: /org/gnome/Vino/require-encryption
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.13
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - dconf_gnome_remote_access_encryption
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - NIST-800-171-3.1.13
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - dconf_gnome_remote_access_encryption
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_remote_access_encryption:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_remote_access_encryption_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_gnome_screen_locking">
              <xccdf-1.2:title>Configure GNOME Screen Locking</xccdf-1.2:title>
              <xccdf-1.2:description>In the default GNOME3 desktop, the screen can be locked
by selecting the user name in the far right corner of the main panel and
selecting <html:b>Lock</html:b>.
<html:br/><html:br/>
The following sections detail commands to enforce idle activation of the screensaver,
screen locking, a blank-screen screensaver, and an idle activation time.
<html:br/><html:br/>
Because users should be trained to lock the screen when they
step away from the computer, the automatic locking feature is only
meant as a backup.
<html:br/><html:br/>
The root account can be screen-locked; however, the root account should
<html:i>never</html:i> be used to log into an X Windows environment and should only
be used to for direct login via console in emergency circumstances.
<html:br/><html:br/>
For more information about enforcing preferences in the GNOME3 environment using the DConf
configuration system, see <html:b><html:a href="http://wiki.gnome.org/dconf">http://wiki.gnome.org/dconf</html:a></html:b> and
the man page <html:code>dconf(1)</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_inactivity_timeout_value" type="number">
                <xccdf-1.2:title>Screensaver Inactivity timeout</xccdf-1.2:title>
                <xccdf-1.2:description>Choose allowed duration (in seconds) of inactive graphical sessions</xccdf-1.2:description>
                <xccdf-1.2:value selector="10_minutes">600</xccdf-1.2:value>
                <xccdf-1.2:value selector="15_minutes">900</xccdf-1.2:value>
                <xccdf-1.2:value selector="30_minutes">1800</xccdf-1.2:value>
                <xccdf-1.2:value selector="5_minutes">300</xccdf-1.2:value>
                <xccdf-1.2:value>900</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_screensaver_lock_delay" type="number">
                <xccdf-1.2:title>Screensaver Lock Delay</xccdf-1.2:title>
                <xccdf-1.2:description>Choose allowed duration (in seconds) after a screensaver becomes active before displaying an authentication prompt</xccdf-1.2:description>
                <xccdf-1.2:value selector="10_seconds">10</xccdf-1.2:value>
                <xccdf-1.2:value selector="5_seconds">5</xccdf-1.2:value>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="immediate">0</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_idle_activation_enabled" selected="false" severity="medium">
                <xccdf-1.2:title>Enable GNOME3 Screensaver Idle Activation</xccdf-1.2:title>
                <xccdf-1.2:description>To activate the screensaver in the GNOME3 desktop after a period of inactivity,
add or set <html:code>idle-activation-enabled</html:code> to <html:code>true</html:code> in
<html:code>/etc/dconf/db/gdm.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/desktop/screensaver]
idle-activation-enabled=true</html:pre>
Once the setting has been added, add a lock to
<html:code>/etc/dconf/db/gdm.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/desktop/screensaver/idle-activation-enabled</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-11(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000029-GPOS-00010</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
                <xccdf-1.2:rationale>A session time-out lock is a temporary action taken when a user stops work and moves away from the immediate
physical vicinity of the information system but does not logout because of the temporary nature of the absence.
Rather than relying on the user to manually lock their operating system session prior to vacating the vicinity,
GNOME desktops can be configured to identify when a user's session has idled and take action to initiate the
session lock.
<html:br/><html:br/>
Enabling idle activation of the screensaver ensures the screensaver will
be activated after the idle delay.  Applications requiring continuous,
real-time screen display (such as network management products) require the
login session does not have administrator rights and the display station is located in a
controlled-access area.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_screensaver_idle_activation_enabled" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/desktop/screensaver\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*idle-activation-enabled\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)idle-activation-enabled(\s*=)/#\1idle-activation-enabled\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/desktop/screensaver\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/desktop/screensaver]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "true")"
if grep -q "^\\s*idle-activation-enabled\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*idle-activation-enabled\\s*=\\s*.*/idle-activation-enabled=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/desktop/screensaver\\]|a\\idle-activation-enabled=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/desktop/screensaver/idle-activation-enabled$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/desktop/screensaver/idle-activation-enabled$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/desktop/screensaver/idle-activation-enabled$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/desktop/screensaver/idle-activation-enabled" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_screensaver_idle_activation_enabled" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.5
  - NIST-800-171-3.1.10
  - NIST-800-53-AC-11(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_idle_activation_enabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Enable GNOME3 Screensaver Idle Activation
  community.general.ini_file:
    dest: /etc/dconf/db/local.d/00-security-settings
    section: org/gnome/desktop/screensaver
    option: idle-activation-enabled
    value: 'true'
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - CJIS-5.5.5
  - NIST-800-171-3.1.10
  - NIST-800-53-AC-11(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_idle_activation_enabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME idle-activation-enabled
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/desktop/screensaver/idle-activation-enabled$
    line: /org/gnome/desktop/screensaver/idle-activation-enabled
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - CJIS-5.5.5
  - NIST-800-171-3.1.10
  - NIST-800-53-AC-11(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_idle_activation_enabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - CJIS-5.5.5
  - NIST-800-171-3.1.10
  - NIST-800-53-AC-11(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_idle_activation_enabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_screensaver_idle_activation_enabled:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_screensaver_idle_activation_enabled_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_idle_activation_locked" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure Users Cannot Change GNOME3 Screensaver Idle Activation</xccdf-1.2:title>
                <xccdf-1.2:description>If not already configured, ensure that users cannot change GNOME3 screensaver lock settings
by adding <html:pre>/org/gnome/desktop/screensaver/idle-activation-enabled</html:pre>
to <html:code>/etc/dconf/db/local.d/00-security-settings</html:code>.
For example:
<html:pre>/org/gnome/desktop/screensaver/idle-activation-enabled</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000029-GPOS-00010</xccdf-1.2:reference>
                <xccdf-1.2:rationale>A session lock is a temporary action taken when a user stops work and moves away from the immediate physical vicinity
of the information system but does not want to logout because of the temporary nature of the absence.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_screensaver_idle_activation_locked" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/desktop/screensaver/idle-activation-enabled$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/desktop/screensaver/idle-activation-enabled$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/desktop/screensaver/idle-activation-enabled$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/desktop/screensaver/idle-activation-enabled" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_screensaver_idle_activation_locked" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.5
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - dconf_gnome_screensaver_idle_activation_locked
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME Screensaver idle-activation-enabled
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/desktop/screensaver/idle-activation-enabled$
    line: /org/gnome/desktop/screensaver/idle-activation-enabled
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - CJIS-5.5.5
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - dconf_gnome_screensaver_idle_activation_locked
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_lineinfile is changed
  tags:
  - CJIS-5.5.5
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - dconf_gnome_screensaver_idle_activation_locked
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_screensaver_idle_activation_locked:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_screensaver_idle_activation_locked_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_idle_delay" selected="false" severity="medium">
                <xccdf-1.2:title>Set GNOME3 Screensaver Inactivity Timeout</xccdf-1.2:title>
                <xccdf-1.2:description>The idle time-out value for inactivity in the GNOME3 desktop is configured via the <html:code>idle-delay</html:code>
setting must be set under an appropriate configuration file(s) in the <html:code>/etc/dconf/db/gdm.d</html:code> directory
and locked in <html:code>/etc/dconf/db/gdm.d/locks</html:code> directory to prevent user modification.
<html:br/><html:br/>
For example, to configure the system for a 15 minute delay, add the following to
<html:code>/etc/dconf/db/gdm.d/00-security-settings</html:code>:
<html:pre>[org/gnome/desktop/session]
idle-delay=uint32 900</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-11(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000029-GPOS-00010</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000031-GPOS-00012</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020060</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230352r1155401_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>A session time-out lock is a temporary action taken when a user stops work and moves away from
the immediate physical vicinity of the information system but does not logout because of the
temporary nature of the absence. Rather than relying on the user to manually lock their operating
system session prior to vacating the vicinity, GNOME3 can be configured to identify when
a user's session has idled and take action to initiate a session lock.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_screensaver_idle_delay" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

inactivity_timeout_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_inactivity_timeout_value" use="legacy"/>'



# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/desktop/session\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*idle-delay\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)idle-delay(\s*=)/#\1idle-delay\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/desktop/session\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/desktop/session]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "uint32 ${inactivity_timeout_value}")"
if grep -q "^\\s*idle-delay\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*idle-delay\\s*=\\s*.*/idle-delay=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/desktop/session\\]|a\\idle-delay=${escaped_value}" "${DCONFFILE}"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_screensaver_idle_delay" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.5
  - DISA-STIG-RHEL-08-020060
  - NIST-800-171-3.1.10
  - NIST-800-53-AC-11(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_idle_delay
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
- name: XCCDF Value inactivity_timeout_value # promote to variable
  set_fact:
    inactivity_timeout_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_inactivity_timeout_value" use="legacy"/>
  tags:
    - always

- name: Set GNOME3 Screensaver Inactivity Timeout
  community.general.ini_file:
    dest: /etc/dconf/db/local.d/00-security-settings
    section: org/gnome/desktop/session
    option: idle-delay
    value: uint32 {{ inactivity_timeout_value }}
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - CJIS-5.5.5
  - DISA-STIG-RHEL-08-020060
  - NIST-800-171-3.1.10
  - NIST-800-53-AC-11(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_idle_delay
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed
  tags:
  - CJIS-5.5.5
  - DISA-STIG-RHEL-08-020060
  - NIST-800-171-3.1.10
  - NIST-800-53-AC-11(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_idle_delay
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-inactivity_timeout_value:var:1" value-id="xccdf_org.ssgproject.content_value_inactivity_timeout_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_screensaver_idle_delay:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_screensaver_idle_delay_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_delay" selected="false" severity="medium">
                <xccdf-1.2:title>Set GNOME3 Screensaver Lock Delay After Activation Period</xccdf-1.2:title>
                <xccdf-1.2:description>To activate the locking delay of the screensaver in the GNOME3 desktop when
the screensaver is activated, add or set <html:code>lock-delay</html:code> to <html:code>uint32 <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_screensaver_lock_delay" use="legacy"/></html:code> in
<html:code>/etc/dconf/db/gdm.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/desktop/screensaver]
lock-delay=uint32 <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_screensaver_lock_delay" use="legacy"/>
</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-11(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000029-GPOS-00010</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000031-GPOS-00012</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020031</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244535r1017342_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>A session lock is a temporary action taken when a user stops work and moves away from the immediate physical vicinity
of the information system but does not want to logout because of the temporary nature of the absence.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_screensaver_lock_delay" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

var_screensaver_lock_delay='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_screensaver_lock_delay" use="legacy"/>'



# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/desktop/screensaver\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*lock-delay\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)lock-delay(\s*=)/#\1lock-delay\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/desktop/screensaver\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/desktop/screensaver]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "uint32 ${var_screensaver_lock_delay}")"
if grep -q "^\\s*lock-delay\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*lock-delay\\s*=\\s*.*/lock-delay=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/desktop/screensaver\\]|a\\lock-delay=${escaped_value}" "${DCONFFILE}"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_screensaver_lock_delay" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020031
  - NIST-800-171-3.1.10
  - NIST-800-53-AC-11(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_lock_delay
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
- name: XCCDF Value var_screensaver_lock_delay # promote to variable
  set_fact:
    var_screensaver_lock_delay: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_screensaver_lock_delay" use="legacy"/>
  tags:
    - always

- name: Set GNOME3 Screensaver Lock Delay After Activation Period
  community.general.ini_file:
    dest: /etc/dconf/db/local.d/00-security-settings
    section: org/gnome/desktop/screensaver
    option: lock-delay
    value: uint32 {{ var_screensaver_lock_delay }}
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020031
  - NIST-800-171-3.1.10
  - NIST-800-53-AC-11(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_lock_delay
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed
  tags:
  - DISA-STIG-RHEL-08-020031
  - NIST-800-171-3.1.10
  - NIST-800-53-AC-11(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_lock_delay
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_screensaver_lock_delay:var:1" value-id="xccdf_org.ssgproject.content_value_var_screensaver_lock_delay"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_screensaver_lock_delay:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_screensaver_lock_delay_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_enabled" selected="false" severity="medium">
                <xccdf-1.2:title>Enable GNOME3 Screensaver Lock After Idle Period</xccdf-1.2:title>
                <xccdf-1.2:description>
To activate locking of the screensaver in the GNOME3 desktop when it is activated,
add or set <html:code>lock-enabled</html:code> to <html:code>true</html:code> in
<html:code>/etc/dconf/db/gdm.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/desktop/screensaver]
lock-enabled=true
</html:pre>
Once the settings have been added, add a lock to
<html:code>/etc/dconf/db/gdm.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/desktop/screensaver/lock-enabled</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000028-GPOS-00009</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000030-GPOS-00011</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020030</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230347r1017160_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>A session lock is a temporary action taken when a user stops work and moves away from the immediate physical vicinity
of the information system but does not want to logout because of the temporary nature of the absence.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_screensaver_lock_enabled" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/desktop/screensaver\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*lock-enabled\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)lock-enabled(\s*=)/#\1lock-enabled\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/desktop/screensaver\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/desktop/screensaver]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "true")"
if grep -q "^\\s*lock-enabled\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*lock-enabled\\s*=\\s*.*/lock-enabled=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/desktop/screensaver\\]|a\\lock-enabled=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/desktop/screensaver/lock-enabled$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/desktop/screensaver/lock-enabled$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/desktop/screensaver/lock-enabled$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/desktop/screensaver/lock-enabled" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_screensaver_lock_enabled" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.5
  - DISA-STIG-RHEL-08-020030
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_lock_enabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Enable GNOME3 Screensaver Lock After Idle Period - Enable GNOME3 Screensaver
    Lock After Idle Period
  community.general.ini_file:
    dest: /etc/dconf/db/local.d/00-security-settings
    section: org/gnome/desktop/screensaver
    option: lock-enabled
    value: 'true'
    create: true
    no_extra_spaces: true
  when:
  - '"gdm" in ansible_facts.packages'
  - ansible_distribution != 'SLES'
  register: screensaver_config
  tags:
  - CJIS-5.5.5
  - DISA-STIG-RHEL-08-020030
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_lock_enabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Enable GNOME3 Screensaver Lock After Idle Period - Prevent user modification
    of GNOME lock-enabled
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/desktop/screensaver/lock-enabled$
    line: /org/gnome/desktop/screensaver/lock-enabled
    create: true
  when:
  - '"gdm" in ansible_facts.packages'
  - ansible_distribution != 'SLES'
  register: screensaver_lock
  tags:
  - CJIS-5.5.5
  - DISA-STIG-RHEL-08-020030
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_lock_enabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Enable GNOME3 Screensaver Lock After Idle Period - Enable GNOME3 Screensaver
    Lock After Idle Period
  community.general.ini_file:
    dest: /etc/dconf/db/gdm.d/00-security-settings
    section: org/gnome/desktop/lockdown
    option: disable-lock-screen
    value: 'false'
    create: true
    no_extra_spaces: true
  when:
  - '"gdm" in ansible_facts.packages'
  - ansible_distribution == 'SLES'
  register: lockdown_config
  tags:
  - CJIS-5.5.5
  - DISA-STIG-RHEL-08-020030
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_lock_enabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Enable GNOME3 Screensaver Lock After Idle Period - Prevent user modification
    of GNOME disable-lock-screen
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/gdm.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/desktop/lockdown/disable-lock-screen$
    line: /org/gnome/desktop/lockdown/disable-lock-screen
    create: true
  when:
  - '"gdm" in ansible_facts.packages'
  - ansible_distribution == 'SLES'
  register: lockdown_lock
  tags:
  - CJIS-5.5.5
  - DISA-STIG-RHEL-08-020030
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_lock_enabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Enable GNOME3 Screensaver Lock After Idle Period - Check GNOME3 screenserver
    disable-lock-screen false
  ansible.builtin.command: gsettings get org.gnome.desktop.lockdown disable-lock-screen
  register: cmd_out
  when:
  - '"gdm" in ansible_facts.packages'
  - ansible_distribution == 'SLES'
  changed_when: false
  tags:
  - CJIS-5.5.5
  - DISA-STIG-RHEL-08-020030
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_lock_enabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Enable GNOME3 Screensaver Lock After Idle Period - Update GNOME3 screenserver
    disable-lock-screen false
  ansible.builtin.command: gsettings set org.gnome.desktop.lockdown disable-lock-screen
    false
  when:
  - '"gdm" in ansible_facts.packages'
  - ansible_distribution == 'SLES'
  - cmd_out.stdout != 'false'
  tags:
  - CJIS-5.5.5
  - DISA-STIG-RHEL-08-020030
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_lock_enabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Enable GNOME3 Screensaver Lock After Idle Period - Update dconf database for
    non-SLES systems
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - ansible_distribution != 'SLES'
  - (screensaver_config is changed or screensaver_lock is changed)
  tags:
  - CJIS-5.5.5
  - DISA-STIG-RHEL-08-020030
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_lock_enabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Enable GNOME3 Screensaver Lock After Idle Period - Update dconf database for
    SLES systems
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - ansible_distribution == 'SLES'
  - (lockdown_config is changed or lockdown_lock is changed)
  tags:
  - CJIS-5.5.5
  - DISA-STIG-RHEL-08-020030
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_lock_enabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_screensaver_lock_enabled:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_screensaver_lock_enabled_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_locked" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure Users Cannot Change GNOME3 Screensaver Lock After Idle Period</xccdf-1.2:title>
                <xccdf-1.2:description>If not already configured, ensure that users cannot change GNOME3 screensaver lock settings
by adding <html:pre>/org/gnome/desktop/screensaver/lock-enabled</html:pre>
to <html:code>/etc/dconf/db/local.d/locks/00-security-settings</html:code>.
For example:
<html:pre>/org/gnome/desktop/screensaver/lock-enabled</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000028-GPOS-00009</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000030-GPOS-00011</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020082</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244539r1069325_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>A session lock is a temporary action taken when a user stops work and moves away from the immediate physical vicinity
of the information system but does not want to logout because of the temporary nature of the absence.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_screensaver_lock_locked" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/desktop/screensaver/lock-enabled$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/desktop/screensaver/lock-enabled$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/desktop/screensaver/lock-enabled$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/desktop/screensaver/lock-enabled" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_screensaver_lock_locked" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.5
  - DISA-STIG-RHEL-08-020082
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - dconf_gnome_screensaver_lock_locked
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME Screensaver lock-enabled
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/desktop/screensaver/lock-enabled$
    line: /org/gnome/desktop/screensaver/lock-enabled
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - CJIS-5.5.5
  - DISA-STIG-RHEL-08-020082
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - dconf_gnome_screensaver_lock_locked
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_lineinfile is changed
  tags:
  - CJIS-5.5.5
  - DISA-STIG-RHEL-08-020082
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - dconf_gnome_screensaver_lock_locked
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_screensaver_lock_locked:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_screensaver_lock_locked_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_mode_blank" selected="false" severity="medium">
                <xccdf-1.2:title>Implement Blank Screensaver</xccdf-1.2:title>
                <xccdf-1.2:description>


To set the screensaver mode in the GNOME3 desktop to a blank screen,
add or set <html:code>picture-uri</html:code> to <html:code>string ''</html:code> in
<html:code>/etc/dconf/db/gdm.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/desktop/screensaver]
picture-uri=string ''
</html:pre>
Once the settings have been added, add a lock to
<html:code>/etc/dconf/db/gdm.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/desktop/screensaver/picture-uri</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-11(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-11(1).1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000031-GPOS-00012</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Setting the screensaver mode to blank-only conceals the
contents of the display from passersby.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_screensaver_mode_blank" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/desktop/screensaver\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*picture-uri\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)picture-uri(\s*=)/#\1picture-uri\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/desktop/screensaver\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/desktop/screensaver]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "string ''")"
if grep -q "^\\s*picture-uri\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*picture-uri\\s*=\\s*.*/picture-uri=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/desktop/screensaver\\]|a\\picture-uri=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/desktop/screensaver/picture-uri$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/desktop/screensaver/picture-uri$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/desktop/screensaver/picture-uri$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/desktop/screensaver/picture-uri" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_screensaver_mode_blank" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.5
  - NIST-800-171-3.1.10
  - NIST-800-53-AC-11(1)
  - NIST-800-53-AC-11(1).1
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_mode_blank
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Implement Blank Screensaver
  community.general.ini_file:
    dest: /etc/dconf/db/local.d/00-security-settings
    section: org/gnome/desktop/screensaver
    option: picture-uri
    value: string ''
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - CJIS-5.5.5
  - NIST-800-171-3.1.10
  - NIST-800-53-AC-11(1)
  - NIST-800-53-AC-11(1).1
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_mode_blank
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME picture-uri
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/desktop/screensaver/picture-uri$
    line: /org/gnome/desktop/screensaver/picture-uri
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - CJIS-5.5.5
  - NIST-800-171-3.1.10
  - NIST-800-53-AC-11(1)
  - NIST-800-53-AC-11(1).1
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_mode_blank
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - CJIS-5.5.5
  - NIST-800-171-3.1.10
  - NIST-800-53-AC-11(1)
  - NIST-800-53-AC-11(1).1
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_screensaver_mode_blank
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_screensaver_mode_blank:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_screensaver_mode_blank_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_user_info" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Full User Name on Splash Shield</xccdf-1.2:title>
                <xccdf-1.2:description>By default when the screen is locked, the splash shield will show the user's
full name. This should be disabled to prevent casual observers from seeing
who has access to the system. This can be disabled by adding or setting
<html:code>show-full-name-in-top-bar</html:code> to <html:code>false</html:code> in
<html:code>/etc/dconf/db/local.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/desktop/screensaver]
show-full-name-in-top-bar=false
</html:pre>
Once the settings have been added, add a lock to
<html:code>/etc/dconf/db/local.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/desktop/screensaver/show-full-name-in-top-bar</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Setting the splash screen to not reveal the logged in user's name
conceals who has access to the system from passersby.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_screensaver_user_info" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/desktop/screensaver\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*show-full-name-in-top-bar\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)show-full-name-in-top-bar(\s*=)/#\1show-full-name-in-top-bar\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/desktop/screensaver\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/desktop/screensaver]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "false")"
if grep -q "^\\s*show-full-name-in-top-bar\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*show-full-name-in-top-bar\\s*=\\s*.*/show-full-name-in-top-bar=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/desktop/screensaver\\]|a\\show-full-name-in-top-bar=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/desktop/screensaver/show-full-name-in-top-bar$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/desktop/screensaver/show-full-name-in-top-bar$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/desktop/screensaver/show-full-name-in-top-bar$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/desktop/screensaver/show-full-name-in-top-bar" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_screensaver_user_info" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - dconf_gnome_screensaver_user_info
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Disable Full Username on Splash Screen
  community.general.ini_file:
    dest: /etc/dconf/db/local.d/00-security-settings
    section: org/gnome/desktop/screensaver
    option: show-full-name-in-top-bar
    value: 'false'
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - dconf_gnome_screensaver_user_info
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME show-full-name-in-top-bar
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/desktop/screensaver/show-full-name-in-top-bar$
    line: /org/gnome/desktop/screensaver/show-full-name-in-top-bar
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - dconf_gnome_screensaver_user_info
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - dconf_gnome_screensaver_user_info
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_screensaver_user_info:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_screensaver_user_info_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_user_locks" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure Users Cannot Change GNOME3 Screensaver Settings</xccdf-1.2:title>
                <xccdf-1.2:description>If not already configured, ensure that users cannot change GNOME3 screensaver lock settings
by adding <html:code>/org/gnome/desktop/screensaver/lock-delay</html:code>
to <html:code>/etc/dconf/db/gdm.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/desktop/screensaver/lock-delay</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000029-GPOS-00010</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000031-GPOS-00012</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020080</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230354r1069323_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>A session time-out lock is a temporary action taken when a user stops work and moves away from the immediate
physical vicinity of the information system but does not logout because of the temporary nature of the absence.
Rather than relying on the user to manually lock their operating system session prior to vacating the vicinity,
GNOME desktops can be configured to identify when a user's session has idled and take action to initiate the
session lock. As such, users should not be allowed to change session settings.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_screensaver_user_locks" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/desktop/screensaver/lock-delay$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/desktop/screensaver/lock-delay$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/desktop/screensaver/lock-delay$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/desktop/screensaver/lock-delay" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_screensaver_user_locks" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020080
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - dconf_gnome_screensaver_user_locks
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME lock-delay
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/desktop/screensaver/lock-delay$
    line: /org/gnome/desktop/screensaver/lock-delay
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020080
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - dconf_gnome_screensaver_user_locks
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_lineinfile is changed
  tags:
  - DISA-STIG-RHEL-08-020080
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - dconf_gnome_screensaver_user_locks
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_screensaver_user_locks:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_screensaver_user_locks_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_session_idle_user_locks" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure Users Cannot Change GNOME3 Session Idle Settings</xccdf-1.2:title>
                <xccdf-1.2:description>If not already configured, ensure that users cannot change GNOME3 session idle settings
by adding <html:code>/org/gnome/desktop/session/idle-delay</html:code>
to <html:code>/etc/dconf/db/gdm.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/desktop/session/idle-delay</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000029-GPOS-00010</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000031-GPOS-00012</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020081</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244538r1069324_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>A session time-out lock is a temporary action taken when a user stops work and moves away from the immediate
physical vicinity of the information system but does not logout because of the temporary nature of the absence.
Rather than relying on the user to manually lock their operating system session prior to vacating the vicinity,
GNOME desktops can be configured to identify when a user's session has idled and take action to initiate the
session lock. As such, users should not be allowed to change session settings.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_session_idle_user_locks" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/desktop/session/idle-delay$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/desktop/session/idle-delay$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/desktop/session/idle-delay$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/desktop/session/idle-delay" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_session_idle_user_locks" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020081
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_session_idle_user_locks
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME Session idle-delay
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/desktop/session/idle-delay$
    line: /org/gnome/desktop/session/idle-delay
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020081
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_session_idle_user_locks
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_lineinfile is changed
  tags:
  - DISA-STIG-RHEL-08-020081
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - dconf_gnome_session_idle_user_locks
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_session_idle_user_locks:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_session_idle_user_locks_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_gnome_system_settings">
              <xccdf-1.2:title>GNOME System Settings</xccdf-1.2:title>
              <xccdf-1.2:description>GNOME provides configuration and functionality to a graphical desktop environment
that changes graphical configurations or allow a user to perform
actions that users normally would not be able to do in non-graphical mode such as
remote access configuration, power policies, Geo-location, etc.
Configuring such settings in GNOME will prevent accidental graphical configuration
changes by users from taking place.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_ctrlaltdel_reboot" selected="false" severity="high">
                <xccdf-1.2:title>Disable Ctrl-Alt-Del Reboot Key Sequence in GNOME3</xccdf-1.2:title>
                <xccdf-1.2:description>By default, <html:code>GNOME</html:code> will reboot the system if the
<html:code>Ctrl-Alt-Del</html:code> key sequence is pressed.
<html:br/><html:br/>
To configure the system to ignore the <html:code>Ctrl-Alt-Del</html:code> key sequence
from the Graphical User Interface (GUI) instead of rebooting the system,
add or set <html:code>logout</html:code> to <html:code>['']</html:code> in
<html:code>/etc/dconf/db/local.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/settings-daemon/plugins/media-keys]
logout=['']</html:pre>
Once the settings have been added, add a lock to
<html:code>/etc/dconf/db/local.d/locks/00-security-settings-lock</html:code> to prevent
user modification. For example:
<html:pre>/org/gnome/settings-daemon/plugins/media-keys/logout</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040171</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230530r1069317_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>A locally logged-in user who presses Ctrl-Alt-Del, when at the console,
can reboot the system. If accidentally pressed, as could happen in
the case of mixed OS environment, this can create the risk of short-term
loss of availability of systems due to unintentional reboot.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_disable_ctrlaltdel_reboot" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/settings-daemon/plugins/media-keys\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*logout\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)logout(\s*=)/#\1logout\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/settings-daemon/plugins/media-keys\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/settings-daemon/plugins/media-keys]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "['']")"
if grep -q "^\\s*logout\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*logout\\s*=\\s*.*/logout=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/settings-daemon/plugins/media-keys\\]|a\\logout=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/settings-daemon/plugins/media-keys/logout$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/settings-daemon/plugins/media-keys/logout$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/settings-daemon/plugins/media-keys/logout$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/settings-daemon/plugins/media-keys/logout" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_disable_ctrlaltdel_reboot" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040171
  - NIST-800-171-3.1.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(b)
  - dconf_gnome_disable_ctrlaltdel_reboot
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Disable Ctrl-Alt-Del Reboot Key Sequence in GNOME3
  community.general.ini_file:
    dest: /etc/dconf/db/local.d/00-security-settings
    section: org/gnome/settings-daemon/plugins/media-keys
    option: logout
    value: '['''']'
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040171
  - NIST-800-171-3.1.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(b)
  - dconf_gnome_disable_ctrlaltdel_reboot
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME disablement of Ctrl-Alt-Del
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/settings-daemon/plugins/media-keys/logout$
    line: /org/gnome/settings-daemon/plugins/media-keys/logout
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040171
  - NIST-800-171-3.1.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(b)
  - dconf_gnome_disable_ctrlaltdel_reboot
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - DISA-STIG-RHEL-08-040171
  - NIST-800-171-3.1.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(b)
  - dconf_gnome_disable_ctrlaltdel_reboot
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_disable_ctrlaltdel_reboot:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_disable_ctrlaltdel_reboot_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_geolocation" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Geolocation in GNOME3</xccdf-1.2:title>
                <xccdf-1.2:description><html:code>GNOME</html:code> allows the clock and applications to track and access
location information. This setting should be disabled as applications
should not track system location. To configure the system to disable
location tracking, add or set <html:code>enabled</html:code> to <html:code>false</html:code> in
<html:code>/etc/dconf/db/local.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/system/location]
enabled=false</html:pre>
To configure the clock to disable location tracking, add or set
<html:code>geolocation</html:code> to <html:code>false</html:code> in
<html:code>/etc/dconf/db/local.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/clocks]
geolocation=false</html:pre>
Once the settings have been added, add a lock to
<html:code>/etc/dconf/db/local.d/locks/00-security-settings-lock</html:code> to prevent
user modification. For example:
<html:pre>/org/gnome/system/location/enabled
/org/gnome/clocks/geolocation</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Power settings should not be enabled on systems that are not mobile devices.
Enabling power settings on non-mobile devices could have unintended processing
consequences on standard systems.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_disable_geolocation" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/system/location\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*enabled\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)enabled(\s*=)/#\1enabled\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/system/location\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/system/location]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "false")"
if grep -q "^\\s*enabled\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*enabled\\s*=\\s*.*/enabled=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/system/location\\]|a\\enabled=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/clocks\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*geolocation\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)geolocation(\s*=)/#\1geolocation\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/clocks\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/clocks]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "false")"
if grep -q "^\\s*geolocation\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*geolocation\\s*=\\s*.*/geolocation=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/clocks\\]|a\\geolocation=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/system/location/enabled$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/system/location/enabled$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/system/location/enabled$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/system/location/enabled" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/clocks/geolocation$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/clocks/geolocation$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/clocks/geolocation$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/clocks/geolocation" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_disable_geolocation" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - dconf_gnome_disable_geolocation
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Disable Geolocation in GNOME3 - location tracking
  community.general.ini_file:
    dest: /etc/dconf/db/local.d/00-security-settings
    section: org/gnome/system/location
    option: enabled
    value: 'false'
    create: true
    no_extra_spaces: true
  register: result_ini1
  when: '"gdm" in ansible_facts.packages'
  tags:
  - dconf_gnome_disable_geolocation
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Disable Geolocation in GNOME3 - clock location tracking
  community.general.ini_file:
    dest: /etc/dconf/db/local.d/00-security-settings
    section: org/gnome/clocks
    option: gelocation
    value: 'false'
    create: true
  register: result_ini2
  when: '"gdm" in ansible_facts.packages'
  tags:
  - dconf_gnome_disable_geolocation
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME geolocation - location tracking
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/system/location/enabled$
    line: /org/gnome/system/location/enabled
    create: true
  register: result_lineinfile1
  when: '"gdm" in ansible_facts.packages'
  tags:
  - dconf_gnome_disable_geolocation
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME geolocation - clock location tracking
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/clocks/geolocation$
    line: /org/gnome/clocks/geolocation
    create: true
  register: result_lineinfile2
  when: '"gdm" in ansible_facts.packages'
  tags:
  - dconf_gnome_disable_geolocation
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini1 is changed or result_ini2 is changed or result_lineinfile1 is changed
    or result_lineinfile2 is changed
  tags:
  - dconf_gnome_disable_geolocation
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_disable_geolocation:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_disable_geolocation_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_power_settings" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Power Settings in GNOME3</xccdf-1.2:title>
                <xccdf-1.2:description>By default, <html:code>GNOME</html:code> enables a power profile designed for mobile devices
with battery usage. While useful for mobile devices, this setting should be disabled
for all other systems. To configure the system to disable the power setting, add or set
<html:code>active</html:code> to <html:code>false</html:code> in
<html:code>/etc/dconf/db/local.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/settings-daemon/plugins/power]
active=false
</html:pre>
Once the settings have been added, add a lock to
<html:code>/etc/dconf/db/local.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/settings-daemon/plugins/power</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Power settings should not be enabled on systems that are not mobile devices.
Enabling power settings on non-mobile devices could have unintended processing
consequences on standard systems.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_disable_power_settings:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_disable_power_settings_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_user_admin" selected="false" severity="high">
                <xccdf-1.2:title>Disable User Administration in GNOME3</xccdf-1.2:title>
                <xccdf-1.2:description>By default, <html:code>GNOME</html:code> will allow all users to have some administratrion
capability. This should be disabled so that non-administrative users are not making
configuration changes. To configure the system to disable user administration
capability in the Graphical User Interface (GUI), add or set
<html:code>user-administration-disabled</html:code> to <html:code>true</html:code> in
<html:code>/etc/dconf/db/local.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/desktop/lockdown]
user-administration-disabled=true
</html:pre>
Once the settings have been added, add a lock to
<html:code>/etc/dconf/db/local.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/desktop/lockdown/user-administration-disabled</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.5</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Allowing all users to have some administratrive capabilities to the system through
the Graphical User Interface (GUI) when they would not have them otherwise could allow
unintended configuration changes as well as a nefarious user the capability to make system
changes such as adding new accounts, etc.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_disable_user_admin" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/desktop/lockdown\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|local.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/local.d/00-security-settings"
DBDIR="/etc/dconf/db/local.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*user-administration-disabled\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)user-administration-disabled(\s*=)/#\1user-administration-disabled\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/desktop/lockdown\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/desktop/lockdown]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "true")"
if grep -q "^\\s*user-administration-disabled\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*user-administration-disabled\\s*=\\s*.*/user-administration-disabled=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/desktop/lockdown\\]|a\\user-administration-disabled=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/desktop/lockdown/user-administration-disabled$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|local.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/local.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/desktop/lockdown/user-administration-disabled$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/desktop/lockdown/user-administration-disabled$" /etc/dconf/db/local.d/
then
    echo "/org/gnome/desktop/lockdown/user-administration-disabled" &gt;&gt; "/etc/dconf/db/local.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_disable_user_admin" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.5
  - dconf_gnome_disable_user_admin
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Detect if user-administration-disabled can be found on /etc/dconf/db/local.d/
  ansible.builtin.find:
    path: /etc/dconf/db/local.d/
    contains: ^\s*user-administration-disabled
  register: dconf_gnome_disable_user_admin_config_files
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.5
  - dconf_gnome_disable_user_admin
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Configure user-administration-disabled - default file
  community.general.ini_file:
    dest: /etc/dconf/db/local.d//00-security-settings
    section: org/gnome/desktop/lockdown
    option: user-administration-disabled
    value: 'true'
    create: true
  when:
  - '"gdm" in ansible_facts.packages'
  - dconf_gnome_disable_user_admin_config_files is defined and dconf_gnome_disable_user_admin_config_files.matched
    == 0
  register: default_file
  tags:
  - NIST-800-171-3.1.5
  - dconf_gnome_disable_user_admin
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Configure user-administration-disabled - existing files
  community.general.ini_file:
    dest: '{{ item.path }}'
    section: org/gnome/desktop/lockdown
    option: user-administration-disabled
    value: 'true'
    create: true
  with_items: '{{ dconf_gnome_disable_user_admin_config_files.files }}'
  when:
  - '"gdm" in ansible_facts.packages'
  - dconf_gnome_disable_user_admin_config_files is defined and dconf_gnome_disable_user_admin_config_files.matched
    &gt; 0
  register: existing_files
  tags:
  - NIST-800-171-3.1.5
  - dconf_gnome_disable_user_admin
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Detect if lock for user-administration-disabled can be found on /etc/dconf/db/local.d/
  ansible.builtin.find:
    path: /etc/dconf/db/local.d/locks
    contains: ^\s*user-administration-disabled
  register: dconf_gnome_disable_user_admin_lock_files
  when: '"gdm" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.5
  - dconf_gnome_disable_user_admin
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification user-administration-disabled - default file
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/local.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/desktop/lockdown/user-administration-disabled$
    line: /org/gnome/desktop/lockdown/user-administration-disabled
    create: true
  when:
  - '"gdm" in ansible_facts.packages'
  - dconf_gnome_disable_user_admin_lock_files is defined and dconf_gnome_disable_user_admin_lock_files.matched
    == 0
  tags:
  - NIST-800-171-3.1.5
  - dconf_gnome_disable_user_admin
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification user-administration-disabled - existing files
  ansible.builtin.lineinfile:
    path: '{{ item.path }}'
    regexp: ^/org/gnome/desktop/lockdown/user-administration-disabled$
    line: /org/gnome/desktop/lockdown/user-administration-disabled
    create: true
  with_items: '{{ dconf_gnome_disable_user_admin_lock_files.files }}'
  when:
  - '"gdm" in ansible_facts.packages'
  - dconf_gnome_disable_user_admin_lock_files is defined and dconf_gnome_disable_user_admin_lock_files.matched
    &gt; 0
  tags:
  - NIST-800-171-3.1.5
  - dconf_gnome_disable_user_admin
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update - user-administration-disabled
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - default_file is changed or existing_files is changed
  tags:
  - NIST-800-171-3.1.5
  - dconf_gnome_disable_user_admin
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_disable_user_admin:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_disable_user_admin_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_sudo">
            <xccdf-1.2:title>Sudo</xccdf-1.2:title>
            <xccdf-1.2:description><html:code>Sudo</html:code>, which stands for "su 'do'", provides the ability to delegate authority
to certain users, groups of users, or system administrators. When configured for system
users and/or groups, <html:code>Sudo</html:code> can allow a user or group to execute privileged commands
that normally only <html:code>root</html:code> is allowed to execute.
<html:br/><html:br/>
For more information on <html:code>Sudo</html:code> and addition <html:code>Sudo</html:code> configuration options, see
<html:b><html:a href="https://www.sudo.ws">https://www.sudo.ws</html:a></html:b>.</xccdf-1.2:description>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sudo_dedicated_group" interactive="true" type="string">
              <xccdf-1.2:title>Group name dedicated to the use of sudo</xccdf-1.2:title>
              <xccdf-1.2:description>Specify the name of the group that should own /usr/bin/sudo.</xccdf-1.2:description>
              <xccdf-1.2:value>root</xccdf-1.2:value>
              <xccdf-1.2:value selector="root">root</xccdf-1.2:value>
              <xccdf-1.2:value selector="sudogrp">sudogrp</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sudo_logfile" interactive="true" type="string">
              <xccdf-1.2:title>Sudo - logfile value</xccdf-1.2:title>
              <xccdf-1.2:description>Specify the sudo logfile to use. The default value used here matches the example
location from CIS, which uses /var/log/sudo.log.</xccdf-1.2:description>
              <xccdf-1.2:value>/var/log/sudo.log</xccdf-1.2:value>
              <xccdf-1.2:value selector="var_log_sudo_log">/var/log/sudo.log</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sudo_passwd_timeout" type="string">
              <xccdf-1.2:title>Sudo - passwd_timeout value</xccdf-1.2:title>
              <xccdf-1.2:description>Defines the number of minutes before the <html:code>sudo</html:code> password prompt times out.
Defining 0 means no timeout. The default timeout value is 5 minutes.</xccdf-1.2:description>
              <xccdf-1.2:value>5</xccdf-1.2:value>
              <xccdf-1.2:value selector="infinite">0</xccdf-1.2:value>
              <xccdf-1.2:value selector="1_minute">1</xccdf-1.2:value>
              <xccdf-1.2:value selector="2_minutes">2</xccdf-1.2:value>
              <xccdf-1.2:value selector="3_minutes">3</xccdf-1.2:value>
              <xccdf-1.2:value selector="5_minutes">5</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sudo_timestamp_timeout" type="string">
              <xccdf-1.2:title>Sudo - timestamp_timeout value</xccdf-1.2:title>
              <xccdf-1.2:description>Defines the number of minutes that can elapse before <html:code>sudo</html:code> will ask for a passwd again.
If set to a value less than 0 the user's time stamp will never expire. Defining 0 means always prompt for a 
password. The default timeout value is 5 minutes.</xccdf-1.2:description>
              <xccdf-1.2:value>5</xccdf-1.2:value>
              <xccdf-1.2:value selector="always_prompt">0</xccdf-1.2:value>
              <xccdf-1.2:value selector="1_minute">1</xccdf-1.2:value>
              <xccdf-1.2:value selector="2_minutes">2</xccdf-1.2:value>
              <xccdf-1.2:value selector="3_minutes">3</xccdf-1.2:value>
              <xccdf-1.2:value selector="5_minutes">5</xccdf-1.2:value>
              <xccdf-1.2:value selector="15_minutes">15</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sudo_umask" type="string">
              <xccdf-1.2:title>Sudo - umask value</xccdf-1.2:title>
              <xccdf-1.2:description>Specify the sudo umask to use. The actual umask value that is used is the union
of the user's umask and the sudo umask.
The default sudo umask is 0022. This guarantess sudo never lowers the umask when
running a command.</xccdf-1.2:description>
              <xccdf-1.2:value>0022</xccdf-1.2:value>
              <xccdf-1.2:value selector="0022">0022</xccdf-1.2:value>
              <xccdf-1.2:value selector="0027">0027</xccdf-1.2:value>
              <xccdf-1.2:value selector="0077">0077</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_sudo_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install sudo Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>sudo</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install sudo</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_MOF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000324-GPOS-00125</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R33</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1386</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.2.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>sudo</html:code> is a program designed to allow a system administrator to give
limited root privileges to users and log root activity. The basic philosophy
is to give as few privileges as possible but still allow system users to
get their work done.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_sudo_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "sudo" ; then
    yum install -y "sudo"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_sudo_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_sudo_installed

- name: Ensure sudo is installed
  ansible.builtin.package:
    name: sudo
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_sudo_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_sudo_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_sudo

class install_sudo {
  package { 'sudo':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_sudo_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=sudo
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_sudo_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "sudo"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_sudo_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install sudo
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_sudo_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install sudo
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_sudo_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_sudo_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_sudoersd" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Group Who Owns /etc/sudoers.d Directory</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/sudoers.d</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/sudoers.d</html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The ownership of the /etc/sudoers.d directory by the root group is important
because this directory hosts sudo configuration. Protection of this
directory is critical for system security. Assigning the ownership to root
ensures exclusive control of the sudo configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_groupowner_etc_sudoersd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "root" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="root"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "root is not a defined group on the system"
else
find -P /etc/sudoers.d/ -maxdepth 0 -type d  ! -group root -exec chgrp --no-dereference "$newgroup" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_groupowner_etc_sudoersd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_groupowner_etc_sudoersd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Check that the root group is defined
  ansible.builtin.getent:
    database: group
    key: root
  ignore_errors: true
  when:
  - '"kernel" in ansible_facts.packages'
  - directory_groupowner_etc_sudoersd_newgroup is undefined
  tags:
  - configure_strategy
  - directory_groupowner_etc_sudoersd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the directory_groupowner_etc_sudoersd_newgroup variable if root found
  ansible.builtin.set_fact:
    directory_groupowner_etc_sudoersd_newgroup: root
  when:
  - '"kernel" in ansible_facts.packages'
  - ansible_facts.getent_group["root"] is defined
  tags:
  - configure_strategy
  - directory_groupowner_etc_sudoersd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/sudoers.d/
  ansible.builtin.file:
    path: /etc/sudoers.d/
    follow: false
    state: directory
    group: '{{ directory_groupowner_etc_sudoersd_newgroup }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_groupowner_etc_sudoersd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_groupowner_etc_sudoersd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_groupowner_etc_sudoersd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_owner_etc_sudoersd" selected="false" severity="medium">
              <xccdf-1.2:title>Verify User Who Owns /etc/sudoers.d Directory</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the owner of <html:code>/etc/sudoers.d</html:code>, run the command:
<html:pre>$ sudo chown root /etc/sudoers.d </html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The ownership of the /etc/sudoers.d directory by the root user is important
because this directory hosts sudo configuration. Protection of this
directory is critical for system security. Assigning the ownership to root
ensures exclusive control of the sudo configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_owner_etc_sudoersd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
find -P /etc/sudoers.d/ -maxdepth 0 -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_owner_etc_sudoersd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_owner_etc_sudoersd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the directory_owner_etc_sudoersd_newown variable if represented by uid
  ansible.builtin.set_fact:
    directory_owner_etc_sudoersd_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_owner_etc_sudoersd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /etc/sudoers.d/
  ansible.builtin.file:
    path: /etc/sudoers.d/
    follow: false
    state: directory
    owner: '{{ directory_owner_etc_sudoersd_newown }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_owner_etc_sudoersd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_owner_etc_sudoersd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_owner_etc_sudoersd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_permissions_etc_sudoersd" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Permissions On /etc/sudoers.d Directory</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/sudoers.d</html:code>, run the command: <html:pre>$ sudo chmod 0750 /etc/sudoers.d</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Setting correct permissions on the /etc/sudoers.d directory is important
because this directory hosts sudo configuration. Protection of this
directory is critical for system security. Restricting the permissions
ensures exclusive control of the sudo configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_permissions_etc_sudoersd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

find -H /etc/sudoers.d/ -maxdepth 0 -perm /u+s,g+ws,o+xwrt -type d -exec chmod u-s,g-ws,o-xwrt {} \;

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_permissions_etc_sudoersd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_permissions_etc_sudoersd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/sudoers.d/ file(s)
  ansible.builtin.command: 'find -P /etc/sudoers.d/ -maxdepth 0 -perm /u+s,g+ws,o+xwrt  -type
    d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_permissions_etc_sudoersd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /etc/sudoers.d/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-ws,o-xwrt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_permissions_etc_sudoersd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_permissions_etc_sudoersd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_permissions_etc_sudoersd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_etc_sudoers" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Group Who Owns /etc/sudoers File</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/sudoers</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/sudoers</html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The ownership of the /etc/sudoers file by the root group is important
because this file hosts sudo configuration. Protection of this
file is critical for system security. Assigning the ownership to root
ensures exclusive control of the sudo configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_sudoers" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "root" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="root"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "root is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/sudoers" | grep -E -w -q "root"; then
    chgrp --no-dereference "$newgroup" /etc/sudoers
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_sudoers" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_groupowner_etc_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Check that the root group is defined
  ansible.builtin.getent:
    database: group
    key: root
  ignore_errors: true
  when:
  - '"kernel" in ansible_facts.packages'
  - file_groupowner_etc_sudoers_newgroup is undefined
  tags:
  - configure_strategy
  - file_groupowner_etc_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_etc_sudoers_newgroup variable if root found
  ansible.builtin.set_fact:
    file_groupowner_etc_sudoers_newgroup: root
  when:
  - '"kernel" in ansible_facts.packages'
  - ansible_facts.getent_group["root"] is defined
  tags:
  - configure_strategy
  - file_groupowner_etc_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/sudoers
  ansible.builtin.stat:
    path: /etc/sudoers
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupowner_etc_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/sudoers
  ansible.builtin.file:
    path: /etc/sudoers
    follow: false
    group: '{{ file_groupowner_etc_sudoers_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupowner_etc_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_etc_sudoers:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_etc_sudoers_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_etc_sudoers" selected="false" severity="medium">
              <xccdf-1.2:title>Verify User Who Owns /etc/sudoers File</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the owner of <html:code>/etc/sudoers</html:code>, run the command:
<html:pre>$ sudo chown root /etc/sudoers </html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The ownership of the /etc/sudoers file by the root user is important
because this file hosts sudo configuration. Protection of this
file is critical for system security. Assigning the ownership to root
ensures exclusive control of the sudo configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_sudoers" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/sudoers" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/sudoers
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_sudoers" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_owner_etc_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_etc_sudoers_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_etc_sudoers_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_etc_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/sudoers
  ansible.builtin.stat:
    path: /etc/sudoers
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_etc_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/sudoers
  ansible.builtin.file:
    path: /etc/sudoers
    follow: false
    owner: '{{ file_owner_etc_sudoers_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_owner_etc_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_etc_sudoers:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_etc_sudoers_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_sudoers" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Permissions On /etc/sudoers File</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/sudoers</html:code>, run the command: <html:pre>$ sudo chmod 0440 /etc/sudoers</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Setting correct permissions on the /etc/sudoers file is important
because this file hosts sudo configuration. Protection of this
file is critical for system security. Restricting the permissions
ensures exclusive control of the sudo configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_sudoers" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

chmod u-xws,g-xws,o-xwrt /etc/sudoers

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_sudoers" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_permissions_etc_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/sudoers
  ansible.builtin.stat:
    path: /etc/sudoers
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_permissions_etc_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xws,g-xws,o-xwrt on /etc/sudoers
  ansible.builtin.file:
    path: /etc/sudoers
    mode: u-xws,g-xws,o-xwrt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_etc_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_sudoers:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_sudoers_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_sudo" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure That the sudo Binary Has the Correct Permissions</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the permissions of <html:code>/usr/bin/sudo</html:code>, run the command:
<html:pre>$ sudo chmod 4110 /usr/bin/sudo</html:pre>
In order to use this rule, the group owner for /usr/bin/sudo needs to be changed to a
group other than root to effectively limit access to sudo.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R38</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The sudoers program should only be usable by people who have the correct permissions.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_sudo"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_sudo" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q sudo; }; then

chmod 4110 /usr/bin/sudo

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_sudo" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_permissions_sudo
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /usr/bin/sudo
  ansible.builtin.stat:
    path: /usr/bin/sudo
  register: file_exists
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_permissions_sudo
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission 4110 on /usr/bin/sudo
  ansible.builtin.file:
    path: /usr/bin/sudo
    mode: '4110'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_sudo
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_sudo:def:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudo_add_env_reset" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure sudo Runs In A Minimal Environment - sudo env_reset</xccdf-1.2:title>
              <xccdf-1.2:description>The sudo <html:code>env_reset</html:code> tag, when specified, will run the command in a minimal environment,
containing the TERM, PATH, HOME, MAIL, SHELL, LOGNAME, USER and SUDO_* variables.
This should be enabled by making sure that the <html:code>env_reset</html:code> tag exists in
<html:code>/etc/sudoers</html:code> configuration file or any sudo configuration snippets
in <html:code>/etc/sudoers.d/</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R39</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Forcing sudo to reset the environment ensures that environment variables are not passed on to the
command accidentally, preventing leak of potentially sensitive information.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_add_env_reset" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if /usr/sbin/visudo -qcf /etc/sudoers; then
    cp /etc/sudoers /etc/sudoers.bak
    if ! grep -P '^[\s]*Defaults\b[^!\n]*\benv_reset.*$' /etc/sudoers; then
        # sudoers file doesn't define Option env_reset
        echo "Defaults env_reset" &gt;&gt; /etc/sudoers
    fi
    
    # Check validity of sudoers and cleanup bak
    if /usr/sbin/visudo -qcf /etc/sudoers; then
        rm -f /etc/sudoers.bak
    else
        echo "Fail to validate remediated /etc/sudoers, reverting to original file."
        mv /etc/sudoers.bak /etc/sudoers
        false
    fi
else
    echo "Skipping remediation, /etc/sudoers failed to validate"
    false
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_add_env_reset" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_add_env_reset

- name: Ensure env_reset is enabled in /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    regexp: ^[\s]*Defaults.*\benv_reset\b.*$
    line: Defaults env_reset
    validate: /usr/sbin/visudo -cf %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_add_env_reset
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudo_add_env_reset:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudo_add_env_reset_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudo_add_ignore_dot" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure sudo Ignores Commands In Current Dir - sudo ignore_dot</xccdf-1.2:title>
              <xccdf-1.2:description>The sudo <html:code>ignore_dot</html:code> tag, when specified, will ignore the current directory
in the PATH environment variable.
This should be enabled by making sure that the <html:code>ignore_dot</html:code> tag exists in
<html:code>/etc/sudoers</html:code> configuration file or any sudo configuration snippets
in <html:code>/etc/sudoers.d/</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R39</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Ignoring the commands in the user's current directory prevents an attacker from executing commands
downloaded locally.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_add_ignore_dot" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if /usr/sbin/visudo -qcf /etc/sudoers; then
    cp /etc/sudoers /etc/sudoers.bak
    if ! grep -P '^[\s]*Defaults\b[^!\n]*\bignore_dot.*$' /etc/sudoers; then
        # sudoers file doesn't define Option ignore_dot
        echo "Defaults ignore_dot" &gt;&gt; /etc/sudoers
    fi
    
    # Check validity of sudoers and cleanup bak
    if /usr/sbin/visudo -qcf /etc/sudoers; then
        rm -f /etc/sudoers.bak
    else
        echo "Fail to validate remediated /etc/sudoers, reverting to original file."
        mv /etc/sudoers.bak /etc/sudoers
        false
    fi
else
    echo "Skipping remediation, /etc/sudoers failed to validate"
    false
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_add_ignore_dot" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_add_ignore_dot

- name: Ensure ignore_dot is enabled in /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    regexp: ^[\s]*Defaults.*\bignore_dot\b.*$
    line: Defaults ignore_dot
    validate: /usr/sbin/visudo -cf %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_add_ignore_dot
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudo_add_ignore_dot:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudo_add_ignore_dot_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudo_add_noexec" selected="false" severity="high">
              <xccdf-1.2:title>Ensure Privileged Escalated Commands Cannot Execute Other Commands - sudo NOEXEC</xccdf-1.2:title>
              <xccdf-1.2:description>The sudo <html:code>NOEXEC</html:code> tag, when specified, prevents user executed
commands from executing other commands, like a shell for example.
This should be enabled by making sure that the <html:code>NOEXEC</html:code> tag exists in
<html:code>/etc/sudoers</html:code> configuration file or any sudo configuration snippets
in <html:code>/etc/sudoers.d/</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R39</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Restricting the capability of sudo allowed commands to execute sub-commands
prevents users from running programs with privileges they wouldn't have otherwise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_add_noexec" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if /usr/sbin/visudo -qcf /etc/sudoers; then
    cp /etc/sudoers /etc/sudoers.bak
    if ! grep -P '^[\s]*Defaults\b[^!\n]*\bnoexec.*$' /etc/sudoers; then
        # sudoers file doesn't define Option noexec
        echo "Defaults noexec" &gt;&gt; /etc/sudoers
    fi
    
    # Check validity of sudoers and cleanup bak
    if /usr/sbin/visudo -qcf /etc/sudoers; then
        rm -f /etc/sudoers.bak
    else
        echo "Fail to validate remediated /etc/sudoers, reverting to original file."
        mv /etc/sudoers.bak /etc/sudoers
        false
    fi
else
    echo "Skipping remediation, /etc/sudoers failed to validate"
    false
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_add_noexec" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy
  - sudo_add_noexec

- name: Ensure noexec is enabled in /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    regexp: ^[\s]*Defaults.*\bnoexec\b.*$
    line: Defaults noexec
    validate: /usr/sbin/visudo -cf %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy
  - sudo_add_noexec
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudo_add_noexec:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudo_add_noexec_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudo_add_passwd_timeout" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure sudo passwd_timeout is appropriate - sudo passwd_timeout</xccdf-1.2:title>
              <xccdf-1.2:description>The sudo <html:code>passwd_timeout</html:code> tag sets the amount of time sudo password prompt waits.
The passwd_timeout should be configured by making sure that the
<html:code>passwd_timeout=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sudo_passwd_timeout" use="legacy"/></html:code> tag exists in
<html:code>/etc/sudoers</html:code> configuration file or any sudo configuration snippets
in <html:code>/etc/sudoers.d/</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:rationale>Reducing the time <html:code>sudo</html:code> waits for a a password reduces the time the process is exposed.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_add_passwd_timeout" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_sudo_passwd_timeout='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sudo_passwd_timeout" use="legacy"/>'


if /usr/sbin/visudo -qcf /etc/sudoers; then
    cp /etc/sudoers /etc/sudoers.bak
    if ! grep -P '^[\s]*Defaults\b[^!\n]*\bpasswd_timeout=\w+\b.*$' /etc/sudoers; then
        # sudoers file doesn't define Option passwd_timeout
        echo "Defaults passwd_timeout=${var_sudo_passwd_timeout}" &gt;&gt; /etc/sudoers
    else
        # sudoers file defines Option passwd_timeout, remediate if appropriate value is not set
        if ! grep -P "^[\s]*Defaults.*\bpasswd_timeout=${var_sudo_passwd_timeout}\b.*$" /etc/sudoers; then
            
            escaped_variable=${var_sudo_passwd_timeout//$'/'/$'\/'}
            sed -Ei "s/(^[\s]*Defaults.*\bpasswd_timeout=)[-]?.+(\b.*$)/\1$escaped_variable\2/" /etc/sudoers
        fi
    fi
    
    # Check validity of sudoers and cleanup bak
    if /usr/sbin/visudo -qcf /etc/sudoers; then
        rm -f /etc/sudoers.bak
    else
        echo "Fail to validate remediated /etc/sudoers, reverting to original file."
        mv /etc/sudoers.bak /etc/sudoers
        false
    fi
else
    echo "Skipping remediation, /etc/sudoers failed to validate"
    false
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_add_passwd_timeout" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_add_passwd_timeout
- name: XCCDF Value var_sudo_passwd_timeout # promote to variable
  set_fact:
    var_sudo_passwd_timeout: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sudo_passwd_timeout" use="legacy"/>
  tags:
    - always

- name: Ensure passwd_timeout is enabled with the appropriate value in /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    regexp: ^[\s]*Defaults\s(.*)\bpasswd_timeout=[-]?.+\b(.*)$
    line: Defaults \1passwd_timeout={{ var_sudo_passwd_timeout }}\2
    validate: /usr/sbin/visudo -cf %s
    backrefs: true
  register: edit_sudoers_passwd_timeout_option
  when: '"kernel" in ansible_facts.packages'
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_add_passwd_timeout

- name: Enable passwd_timeout option with appropriate value in /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    line: Defaults passwd_timeout={{ var_sudo_passwd_timeout }}
    validate: /usr/sbin/visudo -cf %s
  when:
  - '"kernel" in ansible_facts.packages'
  - edit_sudoers_passwd_timeout_option is defined and not edit_sudoers_passwd_timeout_option.changed
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_add_passwd_timeout
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sudo_passwd_timeout:var:1" value-id="xccdf_org.ssgproject.content_value_var_sudo_passwd_timeout"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudo_add_passwd_timeout:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudo_add_passwd_timeout_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudo_add_requiretty" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo requiretty</xccdf-1.2:title>
              <xccdf-1.2:description>The sudo <html:code>requiretty</html:code> tag, when specified, will only execute sudo
commands from users logged in to a real tty.
This should be enabled by making sure that the <html:code>requiretty</html:code> tag exists in
<html:code>/etc/sudoers</html:code> configuration file or any sudo configuration snippets
in <html:code>/etc/sudoers.d/</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R39</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Restricting the use cases in which a user is allowed to execute sudo commands
reduces the attack surface.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_add_requiretty" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if /usr/sbin/visudo -qcf /etc/sudoers; then
    cp /etc/sudoers /etc/sudoers.bak
    if ! grep -P '^[\s]*Defaults\b[^!\n]*\brequiretty.*$' /etc/sudoers; then
        # sudoers file doesn't define Option requiretty
        echo "Defaults requiretty" &gt;&gt; /etc/sudoers
    fi
    
    # Check validity of sudoers and cleanup bak
    if /usr/sbin/visudo -qcf /etc/sudoers; then
        rm -f /etc/sudoers.bak
    else
        echo "Fail to validate remediated /etc/sudoers, reverting to original file."
        mv /etc/sudoers.bak /etc/sudoers
        false
    fi
else
    echo "Skipping remediation, /etc/sudoers failed to validate"
    false
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_add_requiretty" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_add_requiretty

- name: Ensure requiretty is enabled in /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    regexp: ^[\s]*Defaults.*\brequiretty\b.*$
    line: Defaults requiretty
    validate: /usr/sbin/visudo -cf %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_add_requiretty
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudo_add_requiretty:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudo_add_requiretty_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudo_add_umask" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure sudo umask is appropriate - sudo umask</xccdf-1.2:title>
              <xccdf-1.2:description>The sudo <html:code>umask</html:code> tag, when specified, will be added the to the user's umask in the
command environment.
The umask should be configured by making sure that the <html:code>umask=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sudo_umask" use="legacy"/></html:code> tag exists in
<html:code>/etc/sudoers</html:code> configuration file or any sudo configuration snippets
in <html:code>/etc/sudoers.d/</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R39</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The umask value influences the permissions assigned to files when they are created.
A misconfigured umask value could result in files with excessive permissions that can be read or
written to by unauthorized users.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_add_umask" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_sudo_umask='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sudo_umask" use="legacy"/>'


if /usr/sbin/visudo -qcf /etc/sudoers; then
    cp /etc/sudoers /etc/sudoers.bak
    if ! grep -P '^[\s]*Defaults\b[^!\n]*\bumask=\w+\b.*$' /etc/sudoers; then
        # sudoers file doesn't define Option umask
        echo "Defaults umask=${var_sudo_umask}" &gt;&gt; /etc/sudoers
    else
        # sudoers file defines Option umask, remediate if appropriate value is not set
        if ! grep -P "^[\s]*Defaults.*\bumask=${var_sudo_umask}\b.*$" /etc/sudoers; then
            
            escaped_variable=${var_sudo_umask//$'/'/$'\/'}
            sed -Ei "s/(^[\s]*Defaults.*\bumask=)[-]?.+(\b.*$)/\1$escaped_variable\2/" /etc/sudoers
        fi
    fi
    
    # Check validity of sudoers and cleanup bak
    if /usr/sbin/visudo -qcf /etc/sudoers; then
        rm -f /etc/sudoers.bak
    else
        echo "Fail to validate remediated /etc/sudoers, reverting to original file."
        mv /etc/sudoers.bak /etc/sudoers
        false
    fi
else
    echo "Skipping remediation, /etc/sudoers failed to validate"
    false
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_add_umask" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_add_umask
- name: XCCDF Value var_sudo_umask # promote to variable
  set_fact:
    var_sudo_umask: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sudo_umask" use="legacy"/>
  tags:
    - always

- name: Ensure umask is enabled with the appropriate value in /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    regexp: ^[\s]*Defaults\s(.*)\bumask=[-]?.+\b(.*)$
    line: Defaults \1umask={{ var_sudo_umask }}\2
    validate: /usr/sbin/visudo -cf %s
    backrefs: true
  register: edit_sudoers_umask_option
  when: '"kernel" in ansible_facts.packages'
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_add_umask

- name: Enable umask option with appropriate value in /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    line: Defaults umask={{ var_sudo_umask }}
    validate: /usr/sbin/visudo -cf %s
  when:
  - '"kernel" in ansible_facts.packages'
  - edit_sudoers_umask_option is defined and not edit_sudoers_umask_option.changed
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_add_umask
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sudo_umask:var:1" value-id="xccdf_org.ssgproject.content_value_var_sudo_umask"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudo_add_umask:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudo_add_umask_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudo_add_use_pty" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty</xccdf-1.2:title>
              <xccdf-1.2:description>The sudo <html:code>use_pty</html:code> tag, when specified, will only execute sudo
commands from users logged in to a real tty.
This should be enabled by making sure that the <html:code>use_pty</html:code> tag exists in
<html:code>/etc/sudoers</html:code> configuration file or any sudo configuration snippets
in <html:code>/etc/sudoers.d/</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R39</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.2.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Requiring that sudo commands be run in a pseudo-terminal can prevent an attacker from retaining
access to the user's terminal after the main program has finished executing.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_sudo"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_add_use_pty" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q sudo; }; then

if /usr/sbin/visudo -qcf /etc/sudoers; then
    cp /etc/sudoers /etc/sudoers.bak
    if ! grep -P '^[\s]*Defaults\b[^!\n]*\buse_pty.*$' /etc/sudoers; then
        # sudoers file doesn't define Option use_pty
        echo "Defaults use_pty" &gt;&gt; /etc/sudoers
    fi
    
    # Check validity of sudoers and cleanup bak
    if /usr/sbin/visudo -qcf /etc/sudoers; then
        rm -f /etc/sudoers.bak
    else
        echo "Fail to validate remediated /etc/sudoers, reverting to original file."
        mv /etc/sudoers.bak /etc/sudoers
        false
    fi
else
    echo "Skipping remediation, /etc/sudoers failed to validate"
    false
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_add_use_pty" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_add_use_pty

- name: Ensure use_pty is enabled in /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    regexp: ^[\s]*Defaults.*\buse_pty\b.*$
    line: Defaults use_pty
    validate: /usr/sbin/visudo -cf %s
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_add_use_pty
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudo_add_use_pty:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudo_add_use_pty_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudo_custom_logfile" selected="false" severity="low">
              <xccdf-1.2:title>Ensure Sudo Logfile Exists - sudo logfile</xccdf-1.2:title>
              <xccdf-1.2:description>A custom log sudo file can be configured with the 'logfile' tag. This rule configures
a sudo custom logfile at the default location suggested by CIS, which uses
/var/log/sudo.log.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.2.3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>A sudo log file simplifies auditing of sudo commands.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_sudo"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_custom_logfile" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q sudo; }; then

var_sudo_logfile='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sudo_logfile" use="legacy"/>'


if /usr/sbin/visudo -qcf /etc/sudoers; then
    cp /etc/sudoers /etc/sudoers.bak
    if ! grep -P '^[\s]*Defaults\b[^!\n]*\blogfile\s*=\s*(?:"?([^",\s]+)"?).*$' /etc/sudoers; then
        # sudoers file doesn't define Option logfile
        echo "Defaults logfile=${var_sudo_logfile}" &gt;&gt; /etc/sudoers
    else
        # sudoers file defines Option logfile, remediate if appropriate value is not set
        if ! grep -P "^[\s]*Defaults.*\blogfile=${var_sudo_logfile}\b.*$" /etc/sudoers; then
            
            escaped_variable=${var_sudo_logfile//$'/'/$'\/'}
            sed -Ei "s/(^[\s]*Defaults.*\blogfile=)[-]?.+(\b.*$)/\1$escaped_variable\2/" /etc/sudoers
        fi
    fi
    
    # Check validity of sudoers and cleanup bak
    if /usr/sbin/visudo -qcf /etc/sudoers; then
        rm -f /etc/sudoers.bak
    else
        echo "Fail to validate remediated /etc/sudoers, reverting to original file."
        mv /etc/sudoers.bak /etc/sudoers
        false
    fi
else
    echo "Skipping remediation, /etc/sudoers failed to validate"
    false
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_custom_logfile" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_custom_logfile
- name: XCCDF Value var_sudo_logfile # promote to variable
  set_fact:
    var_sudo_logfile: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sudo_logfile" use="legacy"/>
  tags:
    - always

- name: Ensure logfile is enabled with the appropriate value in /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    regexp: ^[\s]*Defaults\s(.*)\blogfile=[-]?.+\b(.*)$
    line: Defaults \1logfile={{ var_sudo_logfile }}\2
    validate: /usr/sbin/visudo -cf %s
    backrefs: true
  register: edit_sudoers_logfile_option
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_custom_logfile

- name: Enable logfile option with appropriate value in /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    line: Defaults logfile={{ var_sudo_logfile }}
    validate: /usr/sbin/visudo -cf %s
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  - edit_sudoers_logfile_option is defined and not edit_sudoers_logfile_option.changed
  tags:
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_custom_logfile
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sudo_logfile:var:1" value-id="xccdf_org.ssgproject.content_value_var_sudo_logfile"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudo_custom_logfile:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudo_dedicated_group" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure a dedicated group owns sudo</xccdf-1.2:title>
              <xccdf-1.2:description>Restrict the execution of privilege escalated commands to a dedicated group of users.
Ensure the group owner of /usr/bin/sudo is <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sudo_dedicated_group" use="legacy"/>.</xccdf-1.2:description>
              <xccdf-1.2:warning category="functionality">Changing group owner of <html:code>/usr/bin/sudo</html:code> to a group with no member users will prevent
any and all escalatation of privileges.
Additionally, the system may become unmanageable if root logins are not allowed.</xccdf-1.2:warning>
              <xccdf-1.2:warning category="general">This rule doesn't come with a remediation, before remediating the sysadmin needs to add users to the dedicated sudo group.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R38</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Restricting the set of users able to execute commands as privileged user reduces the attack surface.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sudo_dedicated_group:var:1" value-id="xccdf_org.ssgproject.content_value_var_sudo_dedicated_group"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudo_dedicated_group:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudo_dedicated_group_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Users Re-Authenticate for Privilege Escalation - sudo !authenticate</xccdf-1.2:title>
              <xccdf-1.2:description>The sudo <html:code>!authenticate</html:code> option, when specified, allows a user to execute commands using
sudo without having to authenticate. This should be disabled by making sure that the
<html:code>!authenticate</html:code> option does not exist in <html:code>/etc/sudoers</html:code> configuration file or
any sudo configuration snippets in <html:code>/etc/sudoers.d/</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000373-GPOS-00156</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000373-GPOS-00157</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000373-GPOS-00158</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010381</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230272r1101898_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Without re-authentication, users may access resources or perform tasks for which they
do not have authorization.
<html:br/><html:br/>
When operating systems provide the capability to escalate a functional capability, it
is critical that the user re-authenticate.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_remove_no_authenticate" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

for f in /etc/sudoers /etc/sudoers.d/* ; do
  if [ ! -e "$f" ] ; then
    continue
  fi
  matching_list=$(grep -P '^(?!#).*[\s]+\!authenticate.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      # comment out "!authenticate" matches to preserve user data
      sed -i "s|^${entry}$|# &amp;|g" $f
    done &lt;&lt;&lt; "$matching_list"

    /usr/sbin/visudo -cf $f &amp;&gt; /dev/null || echo "Fail to validate $f with visudo"
  fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_remove_no_authenticate" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010381
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-11
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_remove_no_authenticate

- name: Find /etc/sudoers.d/ files
  ansible.builtin.find:
    paths:
    - /etc/sudoers.d/
  register: sudoers
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010381
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-11
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_remove_no_authenticate

- name: Remove lines containing !authenticate from sudoers files
  ansible.builtin.replace:
    regexp: (^(?!#).*[\s]+\!authenticate.*$)
    replace: '# \g&lt;1&gt;'
    path: '{{ item.path }}'
    validate: /usr/sbin/visudo -cf %s
  with_items:
  - path: /etc/sudoers
  - '{{ sudoers.files }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010381
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-11
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_remove_no_authenticate
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudo_remove_no_authenticate:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudo_remove_nopasswd" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Users Re-Authenticate for Privilege Escalation - sudo NOPASSWD</xccdf-1.2:title>
              <xccdf-1.2:description>The sudo <html:code>NOPASSWD</html:code> tag, when specified, allows a user to execute
commands using sudo without having to authenticate. This should be disabled
by making sure that the <html:code>NOPASSWD</html:code> tag does not exist in
<html:code>/etc/sudoers</html:code> configuration file or any sudo configuration snippets
in <html:code>/etc/sudoers.d/</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule is disabled on Red Hat Virtualization Hosts and Managers, it will report not applicable.
RHV requires to perform operations as root without being asked for password.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000373-GPOS-00156</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000373-GPOS-00157</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000373-GPOS-00158</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010380</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230271r1101896_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Without re-authentication, users may access resources or perform tasks for which they
do not have authorization.
<html:br/><html:br/>
When operating systems provide the capability to escalate a functional capability, it
is critical that the user re-authenticate.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#no_ovirt"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_remove_nopasswd" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

for f in /etc/sudoers /etc/sudoers.d/* ; do
  if [ ! -e "$f" ] ; then
    continue
  fi
  matching_list=$(grep -P '^(?!#).*[\s]+NOPASSWD[\s]*\:.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      # comment out "NOPASSWD" matches to preserve user data
      sed -i "s|^${entry}$|# &amp;|g" $f
    done &lt;&lt;&lt; "$matching_list"

    /usr/sbin/visudo -cf $f &amp;&gt; /dev/null || echo "Fail to validate $f with visudo"
  fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_remove_nopasswd" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010380
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-11
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_remove_nopasswd

- name: Find /etc/sudoers.d/ files
  ansible.builtin.find:
    paths:
    - /etc/sudoers.d/
  register: sudoers
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010380
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-11
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_remove_nopasswd

- name: Remove lines containing NOPASSWD from sudoers files
  ansible.builtin.replace:
    regexp: (^(?!#).*[\s]+NOPASSWD[\s]*\:.*$)
    replace: '# \g&lt;1&gt;'
    path: '{{ item.path }}'
    validate: /usr/sbin/visudo -cf %s
  with_items:
  - path: /etc/sudoers
  - '{{ sudoers.files }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010380
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-11
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_remove_nopasswd
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudo_remove_nopasswd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudo_remove_nopasswd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudo_require_authentication" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Users Re-Authenticate for Privilege Escalation - sudo</xccdf-1.2:title>
              <xccdf-1.2:description>The sudo <html:code>NOPASSWD</html:code> and <html:code>!authenticate</html:code> option, when
specified, allows a user to execute commands using sudo without having to
authenticate. This should be disabled by making sure that
<html:code>NOPASSWD</html:code> and/or <html:code>!authenticate</html:code> do not exist in
<html:code>/etc/sudoers</html:code> configuration file or any sudo configuration snippets
in <html:code>/etc/sudoers.d/</html:code>."</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000373-GPOS-00156</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Without re-authentication, users may access resources or perform tasks for which they
do not have authorization.
<html:br/><html:br/>
When operating systems provide the capability to escalate a functional capability, it
is critical that the user re-authenticate.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_require_authentication" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

for f in /etc/sudoers /etc/sudoers.d/* ; do
  if [ ! -e "$f" ] ; then
    continue
  fi
  matching_list=$(grep -P '^(?!#).*[\s]+NOPASSWD[\s]*\:.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      # comment out "NOPASSWD" matches to preserve user data
      sed -i "s|^${entry}$|# &amp;|g" $f
    done &lt;&lt;&lt; "$matching_list"

    /usr/sbin/visudo -cf $f &amp;&gt; /dev/null || echo "Fail to validate $f with visudo"
  fi
done

for f in /etc/sudoers /etc/sudoers.d/* ; do
  if [ ! -e "$f" ] ; then
    continue
  fi
  matching_list=$(grep -P '^(?!#).*[\s]+\!authenticate.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      # comment out "!authenticate" matches to preserve user data
      sed -i "s|^${entry}$|# &amp;|g" $f
    done &lt;&lt;&lt; "$matching_list"

    /usr/sbin/visudo -cf $f &amp;&gt; /dev/null || echo "Fail to validate $f with visudo"
  fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_require_authentication" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-11
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_require_authentication

- name: Find /etc/sudoers.d/ files
  ansible.builtin.find:
    paths:
    - /etc/sudoers.d/
  register: sudoers
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-11
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_require_authentication

- name: Remove lines containing NOPASSWD from sudoers files
  ansible.builtin.replace:
    regexp: (^(?!#).*[\s]+NOPASSWD[\s]*\:.*$)
    replace: '# \g&lt;1&gt;'
    path: '{{ item.path }}'
    validate: /usr/sbin/visudo -cf %s
  with_items:
  - path: /etc/sudoers
  - '{{ sudoers.files }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-11
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_require_authentication

- name: Find /etc/sudoers.d/ files
  ansible.builtin.find:
    paths:
    - /etc/sudoers.d/
  register: sudoers
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-11
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_require_authentication

- name: Remove lines containing !authenticate from sudoers files
  ansible.builtin.replace:
    regexp: (^(?!#).*[\s]+\!authenticate.*$)
    replace: '# \g&lt;1&gt;'
    path: '{{ item.path }}'
    validate: /usr/sbin/visudo -cf %s
  with_items:
  - path: /etc/sudoers
  - '{{ sudoers.files }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-11
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_require_authentication
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudo_require_authentication:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudo_require_authentication_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudo_require_reauthentication" selected="false" severity="medium">
              <xccdf-1.2:title>Require Re-Authentication When Using the sudo Command</xccdf-1.2:title>
              <xccdf-1.2:description>The sudo <html:code>timestamp_timeout</html:code> tag sets the amount of time sudo password prompt waits.
The default <html:code>timestamp_timeout</html:code> value is 5 minutes.
The timestamp_timeout should be configured by making sure that the
<html:code>timestamp_timeout</html:code> tag exists in
<html:code>/etc/sudoers</html:code> configuration file or any sudo configuration snippets
in <html:code>/etc/sudoers.d/</html:code>.
If the value is set to an integer less than 0, the user's time stamp will not expire
and the user will not have to re-authenticate for privileged actions until the user's session is terminated.</xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000373-GPOS-00156</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000373-GPOS-00157</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000373-GPOS-00158</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010384</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-237643r1050789_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Without re-authentication, users may access resources or perform tasks for which they
do not have authorization.
<html:br/><html:br/>
When operating systems provide the capability to escalate a functional capability, it
is critical that the user re-authenticate.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_sudo"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_require_reauthentication" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q sudo; }; then

var_sudo_timestamp_timeout='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sudo_timestamp_timeout" use="legacy"/>'


if grep -Px '^[\s]*Defaults.*timestamp_timeout[\s]*=.*' /etc/sudoers.d/*; then
    find /etc/sudoers.d/ -type f -exec sed -Ei "/^[[:blank:]]*Defaults.*timestamp_timeout[[:blank:]]*=.*/d" {} \;
fi

if /usr/sbin/visudo -qcf /etc/sudoers; then
    cp /etc/sudoers /etc/sudoers.bak
    if ! grep -P '^[\s]*Defaults.*timestamp_timeout[\s]*=[\s]*[-]?\w+.*$' /etc/sudoers; then
        # sudoers file doesn't define Option timestamp_timeout
        echo "Defaults timestamp_timeout=${var_sudo_timestamp_timeout}" &gt;&gt; /etc/sudoers
    else
        # sudoers file defines Option timestamp_timeout, remediate wrong values if present
        if grep -qP "^[\s]*Defaults\s.*\btimestamp_timeout[\s]*=[\s]*(?!${var_sudo_timestamp_timeout}\b)[-]?\w+\b.*$" /etc/sudoers; then
            sed -Ei "s/(^[[:blank:]]*Defaults.*timestamp_timeout[[:blank:]]*=)[[:blank:]]*[-]?\w+(.*$)/\1${var_sudo_timestamp_timeout}\2/" /etc/sudoers
        fi
    fi
    
    # Check validity of sudoers and cleanup bak
    if /usr/sbin/visudo -qcf /etc/sudoers; then
        rm -f /etc/sudoers.bak
    else
        echo "Fail to validate remediated /etc/sudoers, reverting to original file."
        mv /etc/sudoers.bak /etc/sudoers
        false
    fi
else
    echo "Skipping remediation, /etc/sudoers failed to validate"
    false
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_require_reauthentication" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010384
  - NIST-800-53-IA-11
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_require_reauthentication
- name: XCCDF Value var_sudo_timestamp_timeout # promote to variable
  set_fact:
    var_sudo_timestamp_timeout: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sudo_timestamp_timeout" use="legacy"/>
  tags:
    - always

- name: Require Re-Authentication When Using the sudo Command - Find /etc/sudoers.d/*
    files containing 'Defaults timestamp_timeout'
  ansible.builtin.find:
    path: /etc/sudoers.d
    patterns: '*'
    contains: ^[\s]*Defaults\s.*\btimestamp_timeout[\s]*=.*
  register: sudoers_d_defaults_timestamp_timeout
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010384
  - NIST-800-53-IA-11
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_require_reauthentication

- name: Require Re-Authentication When Using the sudo Command - Remove 'Defaults timestamp_timeout'
    from /etc/sudoers.d/* files
  ansible.builtin.lineinfile:
    path: '{{ item.path }}'
    regexp: ^[\s]*Defaults\s.*\btimestamp_timeout[\s]*=.*
    state: absent
  with_items: '{{ sudoers_d_defaults_timestamp_timeout.files }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010384
  - NIST-800-53-IA-11
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_require_reauthentication

- name: Require Re-Authentication When Using the sudo Command - Ensure timestamp_timeout
    has the appropriate value in /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    regexp: ^[\s]*Defaults\s(.*)\btimestamp_timeout[\s]*=[\s]*[-]?\w+\b(.*)$
    line: Defaults \1timestamp_timeout={{ var_sudo_timestamp_timeout }}\2
    validate: /usr/sbin/visudo -cf %s
    backrefs: true
  register: edit_sudoers_timestamp_timeout_option
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010384
  - NIST-800-53-IA-11
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_require_reauthentication

- name: Require Re-Authentication When Using the sudo Command - Enable timestamp_timeout
    option with correct value in /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    line: Defaults timestamp_timeout={{ var_sudo_timestamp_timeout }}
    validate: /usr/sbin/visudo -cf %s
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  - |
    edit_sudoers_timestamp_timeout_option is defined and not edit_sudoers_timestamp_timeout_option.changed
  tags:
  - DISA-STIG-RHEL-08-010384
  - NIST-800-53-IA-11
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_require_reauthentication

- name: Require Re-Authentication When Using the sudo Command - Remove timestamp_timeout
    wrong values in /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    regexp: ^[\s]*Defaults\s.*\btimestamp_timeout[\s]*=[\s]*(?!{{ var_sudo_timestamp_timeout
      }}\b)[-]?\w+\b.*$
    state: absent
    validate: /usr/sbin/visudo -cf %s
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010384
  - NIST-800-53-IA-11
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudo_require_reauthentication
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudo_require_reauthentication:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudo_require_reauthentication_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudo_restrict_others_executable_permission" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure only owner and members of group owner of /usr/bin/sudo can execute it</xccdf-1.2:title>
              <xccdf-1.2:description>Remove the execute permission bit of <html:code>/etc/bin/sudo</html:code> for the other users.
To properly set the permissions of <html:code>/usr/bin/sudo</html:code>, run the command:
<html:pre>$ sudo chmod 4110 /usr/bin/sudo</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>Restricting the set of users able to execute commands as privileged user reduces the attack surface.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_restrict_others_executable_permission" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

chmod u-wr,g-wrs,o-xwrt /usr/bin/sudo

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudo_restrict_others_executable_permission" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sudo_restrict_others_executable_permission

- name: Test for existence /usr/bin/sudo
  ansible.builtin.stat:
    path: /usr/bin/sudo
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sudo_restrict_others_executable_permission

- name: Ensure permission u-wr,g-wrs,o-xwrt on /usr/bin/sudo
  ansible.builtin.file:
    path: /usr/bin/sudo
    mode: u-wr,g-wrs,o-xwrt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sudo_restrict_others_executable_permission
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudo_restrict_others_executable_permission:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudo_restrict_others_executable_permission_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudo_restrict_privilege_elevation_to_authorized" selected="false" severity="medium">
              <xccdf-1.2:title>The operating system must restrict privilege elevation to authorized personnel</xccdf-1.2:title>
              <xccdf-1.2:description>The sudo command allows a user to execute programs with elevated
(administrator) privileges. It prompts the user for their password
and confirms your request to execute a command by checking a file,
called sudoers.
Restrict privileged actions by removing the following entries from the sudoers file:
<html:code>ALL ALL=(ALL) ALL</html:code>
<html:code>ALL ALL=(ALL:ALL) ALL</html:code></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule doesn't come with a remediation, as the exact requirement allows exceptions,
and removing lines from the sudoers file can make the system non-administrable.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(iv)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010382</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-237641r1101904_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If the "sudoers" file is not configured correctly, any user defined
on the system can initiate privileged actions on the target system.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_sudo"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudo_restrict_privilege_elevation_to_authorized:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudo_vdsm_nopasswd" selected="false" severity="medium">
              <xccdf-1.2:title>Only the VDSM User Can Use sudo NOPASSWD</xccdf-1.2:title>
              <xccdf-1.2:description>The sudo <html:code>NOPASSWD</html:code> tag, when specified, allows a user to execute commands using sudo without having to authenticate. Only the <html:code>vdsm</html:code> user should have this capability in any sudo configuration snippets in <html:code>/etc/sudoers.d/</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:rationale>Without re-authentication, users may access resources or perform tasks for which they
do not have authorization.
<html:br/><html:br/>
When operating systems provide the capability to escalate a functional capability, it
is critical that the user re-authenticate.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudo_vdsm_nopasswd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudo_vdsm_nopasswd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudoers_default_includedir" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure sudo only includes the default configuration directory</xccdf-1.2:title>
              <xccdf-1.2:description>Administrators can configure authorized <html:code>sudo</html:code> users via drop-in files, and it is possible to include
other directories and configuration files from the file currently being parsed.

Make sure that <html:code>/etc/sudoers</html:code> only includes drop-in configuration files from <html:code>/etc/sudoers.d</html:code>,
or that no drop-in file is included.
Either the <html:code>/etc/sudoers</html:code> should contain only one <html:code>#includedir</html:code> directive pointing to
<html:code>/etc/sudoers.d</html:code>, and no file in <html:code>/etc/sudoers.d/</html:code> should include other files or directories;
Or the <html:code>/etc/sudoers</html:code> should not contain any <html:code>#include</html:code>,
<html:code>@include</html:code>, <html:code>#includedir</html:code> or <html:code>@includedir</html:code> directives.
Note that the '#' character doesn't denote a comment in the configuration file.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010379</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-251711r1017365_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Some <html:code>sudo</html:code> configuration options allow users to run programs without re-authenticating.
Use of these configuration options makes it easier for one compromised account to be used to
compromise other accounts.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="sudoers_default_includedir" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

sudoers_config_file="/etc/sudoers"
sudoers_config_dir="/etc/sudoers.d"
sudoers_includedir_count=$(grep -c "#includedir" "$sudoers_config_file")
if [ "$sudoers_includedir_count" -gt 1 ]; then
    sed -i "/#includedir/d" "$sudoers_config_file"
    echo "#includedir /etc/sudoers.d" &gt;&gt; "$sudoers_config_file"
elif [ "$sudoers_includedir_count" -eq 0 ]; then
    echo "#includedir /etc/sudoers.d" &gt;&gt; "$sudoers_config_file"
else
    if ! grep -q "^#includedir /etc/sudoers.d" "$sudoers_config_file"; then
        sed -i "s|^#includedir.*|#includedir /etc/sudoers.d|g" "$sudoers_config_file"
    fi
fi

sed -Ei "/^#include\s/d; /^@includedir\s/d" "$sudoers_config_file"

if grep -Pr "^[#@]include(dir)?\s" "$sudoers_config_dir" ; then
    sed -Ei "/^[#@]include(dir)?\s/d" "$sudoers_config_dir"/*
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudoers_default_includedir" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010379
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sudoers_default_includedir

- name: Check for duplicate values
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    create: false
    regexp: ^#includedir.*$
    state: absent
  check_mode: true
  changed_when: false
  register: dupes
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010379
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sudoers_default_includedir

- name: Deduplicate values from /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    create: false
    regexp: ^#includedir.*$
    state: absent
  when:
  - '"kernel" in ansible_facts.packages'
  - dupes.found is defined and dupes.found &gt; 1
  tags:
  - DISA-STIG-RHEL-08-010379
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sudoers_default_includedir

- name: Insert correct line into /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    create: false
    regexp: ^#includedir.*$
    line: '#includedir /etc/sudoers.d'
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010379
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sudoers_default_includedir

- name: Ensure sudoers doesn't include other non-default file
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    create: false
    regexp: ^[#@]include[\s]+.*$
    state: absent
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010379
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sudoers_default_includedir

- name: Ensure sudoers doesn't have non-default includedir
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    create: false
    regexp: ^@includedir[\s]+.*$
    state: absent
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010379
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sudoers_default_includedir

- name: Find out if /etc/sudoers.d/* files contain file or directory includes
  ansible.builtin.find:
    path: /etc/sudoers.d
    patterns: '*'
    contains: ^[#@]include(dir)?\s.*$
  register: sudoers_d_includes
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010379
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sudoers_default_includedir

- name: Remove found occurrences of file and directory includes from /etc/sudoers.d/*
    files
  ansible.builtin.lineinfile:
    path: '{{ item.path }}'
    regexp: ^[#@]include(dir)?\s.*$
    state: absent
  with_items: '{{ sudoers_d_includes.files }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010379
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sudoers_default_includedir
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudoers_default_includedir:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudoers_default_includedir_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudoers_explicit_command_args" selected="false" severity="medium">
              <xccdf-1.2:title>Explicit arguments in sudo specifications</xccdf-1.2:title>
              <xccdf-1.2:description>All commands in the sudoers file must strictly specify the arguments allowed to be used for a given user.
If the command is supposed to be executed only without arguments, pass "" as an argument in the corresponding user specification.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule doesn't come with a remediation, as absence of arguments in the user spec doesn't mean that the command is intended to be executed with no arguments.</xccdf-1.2:warning>
              <xccdf-1.2:warning category="general">The rule can produce false findings when an argument contains a comma - sudoers syntax allows comma escaping using backslash, but the check doesn't support that. For example, <html:code>root ALL=(ALL) echo 1\,2</html:code> allows root to execute <html:code>echo 1,2</html:code>, but the check would interpret it as two commands <html:code>echo 1\</html:code> and <html:code>2</html:code>.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R43</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Any argument can modify quite significantly the behavior of a program, whether regarding the
realized operation (read, write, delete, etc.) or accessed resources (path in a file system tree). To
avoid any possibility of misuse of a command by a user, the ambiguities must be removed at the
level of its specification.

For example, on some systems, the kernel messages are only accessible by root.
If a user nevertheless must have the privileges to read them, the argument of the dmesg command has to be restricted
in order to prevent the user from flushing the buffer through the -c option:
<html:pre>
user ALL = dmesg ""
</html:pre></xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_sudo"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudoers_explicit_command_args:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudoers_explicit_command_args_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudoers_no_command_negation" selected="false" severity="medium">
              <xccdf-1.2:title>Don't define allowed commands in sudoers by means of exclusion</xccdf-1.2:title>
              <xccdf-1.2:description>Policies applied by sudo through the sudoers file should not involve negation.

Each user specification in the <html:code>sudoers</html:code> file contains a comma-delimited list of command specifications.
The definition can make use glob patterns, as well as of negations.
Indirect definition of those commands by means of exclusion of a set of commands is trivial to bypass, so it is not allowed to use such constructs.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule doesn't come with a remediation, as negations indicate design issues with the sudoers user specifications design. Just removing negations doesn't increase the security - you typically have to rethink the definition of allowed commands to fix the issue.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R42</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Specifying access right using negation is inefficient and can be easily circumvented.
For example, it is expected that a specification like <html:pre>
# To avoid absolutely , this rule can be easily circumvented!
user ALL = ALL ,!/ bin/sh
</html:pre> prevents the execution of the shell
but that’s not the case: just copy the binary <html:code>/bin/sh</html:code> to a different name to make it executable
again through the rule keyword <html:code>ALL</html:code>.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_sudo"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudoers_no_command_negation:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudoers_no_command_negation_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudoers_no_root_target" selected="false" severity="medium">
              <xccdf-1.2:title>Don't target root user in the sudoers file</xccdf-1.2:title>
              <xccdf-1.2:description>The targeted users of a user specification should be, as much as possible, non privileged users (i.e.: non-root).

User specifications have to explicitly list the runas spec (i.e. the list of target users that can be impersonated), and <html:code>ALL</html:code> or <html:code>root</html:code> should not be used.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule doesn't come with a remediation, as the exact requirement allows exceptions, and removing lines from the sudoers file can make the system non-administrable.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R40</xccdf-1.2:reference>
              <xccdf-1.2:rationale>It is common that the command to be executed does not require superuser rights (editing a file
whose the owner is not root, sending a signal to an unprivileged process,etc.). In order to limit
any attempt of privilege escalation through a command, it is better to apply normal user rights.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_sudo"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudoers_no_root_target:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sudoers_validate_passwd" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure invoking users password for privilege escalation when using sudo</xccdf-1.2:title>
              <xccdf-1.2:description>The sudoers security policy requires that users authenticate themselves before they can use sudo.
When sudoers requires authentication, it validates the invoking user's credentials.
The expected output for:
<html:pre> sudo cvtsudoers -f sudoers /etc/sudoers | grep -E '^Defaults !?(rootpw|targetpw|runaspw)$' </html:pre>
<html:pre> Defaults !targetpw
      Defaults !rootpw
      Defaults !runaspw </html:pre>
or if cvtsudoers not supported:
<html:pre> sudo find /etc/sudoers /etc/sudoers.d \( \! -name '*~' -a \! -name '*.*' \) -exec grep -E --with-filename '^[[:blank:]]*Defaults[[:blank:]](.*[[:blank:]])?!?\b(rootpw|targetpw|runaspw)' -- {} \; </html:pre>
<html:pre> /etc/sudoers:Defaults !targetpw
      /etc/sudoers:Defaults !rootpw
      /etc/sudoers:Defaults !runaspw </html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6.1(iv)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010383</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-237642r991589_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If the rootpw, targetpw, or runaspw flags are defined and not disabled, by default the operating system will prompt
the invoking user for the "root" user password.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_sudo"/>
              <xccdf-1.2:fix id="sudoers_validate_passwd" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q sudo; }; then

if grep -x '^Defaults targetpw$' /etc/sudoers; then
    sed -i "/Defaults targetpw/d" /etc/sudoers \;
fi
if grep -x '^Defaults targetpw$' /etc/sudoers.d/*; then
    find /etc/sudoers.d/ -type f -exec sed -i "/Defaults targetpw/d" {} \;
fi
if grep -x '^Defaults rootpw$' /etc/sudoers; then
    sed -i "/Defaults rootpw/d" /etc/sudoers \;
fi
if grep -x '^Defaults rootpw$' /etc/sudoers.d/*; then
    find /etc/sudoers.d/ -type f -exec sed -i "/Defaults rootpw/d" {} \;
fi
if grep -x '^Defaults runaspw$' /etc/sudoers; then
    sed -i "/Defaults runaspw/d" /etc/sudoers \;
fi
if grep -x '^Defaults runaspw$' /etc/sudoers.d/*; then
    find /etc/sudoers.d/ -type f -exec sed -i "/Defaults runaspw/d" {} \;
fi

if [ -e "/etc/sudoers" ] ; then
    
    LC_ALL=C sed -i "/Defaults !targetpw/d" "/etc/sudoers"
else
    touch "/etc/sudoers"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/sudoers"

cp "/etc/sudoers" "/etc/sudoers.bak"
# Insert at the end of the file
printf '%s\n' "Defaults !targetpw" &gt;&gt; "/etc/sudoers"
# Clean up after ourselves.
rm "/etc/sudoers.bak"
if [ -e "/etc/sudoers" ] ; then
    
    LC_ALL=C sed -i "/Defaults !rootpw/d" "/etc/sudoers"
else
    touch "/etc/sudoers"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/sudoers"

cp "/etc/sudoers" "/etc/sudoers.bak"
# Insert at the end of the file
printf '%s\n' "Defaults !rootpw" &gt;&gt; "/etc/sudoers"
# Clean up after ourselves.
rm "/etc/sudoers.bak"
if [ -e "/etc/sudoers" ] ; then
    
    LC_ALL=C sed -i "/Defaults !runaspw/d" "/etc/sudoers"
else
    touch "/etc/sudoers"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/sudoers"

cp "/etc/sudoers" "/etc/sudoers.bak"
# Insert at the end of the file
printf '%s\n' "Defaults !runaspw" &gt;&gt; "/etc/sudoers"
# Clean up after ourselves.
rm "/etc/sudoers.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sudoers_validate_passwd" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Find out if /etc/sudoers.d/* files contain Defaults targetpw to be deduplicated
  ansible.builtin.find:
    path: /etc/sudoers.d
    patterns: '*'
    contains: ^Defaults targetpw$
  register: sudoers_d_defaults
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Remove found occurrences of Defaults targetpw from /etc/sudoers.d/* files
  ansible.builtin.lineinfile:
    path: '{{ item.path }}'
    regexp: ^Defaults targetpw$
    state: absent
  with_items: '{{ sudoers_d_defaults.files }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Find out if /etc/sudoers.d/* files contain Defaults rootpw to be deduplicated
  ansible.builtin.find:
    path: /etc/sudoers.d
    patterns: '*'
    contains: ^Defaults rootpw$
  register: sudoers_d_defaults
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Remove found occurrences of Defaults rootpw from /etc/sudoers.d/* files
  ansible.builtin.lineinfile:
    path: '{{ item.path }}'
    regexp: ^Defaults rootpw$
    state: absent
  with_items: '{{ sudoers_d_defaults.files }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Find out if /etc/sudoers.d/* files contain Defaults runaspw to be deduplicated
  ansible.builtin.find:
    path: /etc/sudoers.d
    patterns: '*'
    contains: ^Defaults runaspw$
  register: sudoers_d_defaults
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Remove found occurrences of Defaults runaspw from /etc/sudoers.d/* files
  ansible.builtin.lineinfile:
    path: '{{ item.path }}'
    regexp: ^Defaults runaspw$
    state: absent
  with_items: '{{ sudoers_d_defaults.files }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Remove any occurrences of Defaults targetpw in /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    regexp: ^Defaults targetpw$
    validate: /usr/sbin/visudo -cf %s
    state: absent
  register: sudoers_file_defaults
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Remove any occurrences of Defaults rootpw in /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    regexp: ^Defaults rootpw$
    validate: /usr/sbin/visudo -cf %s
    state: absent
  register: sudoers_file_defaults
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Remove any occurrences of Defaults runaspw in /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    regexp: ^Defaults runaspw$
    validate: /usr/sbin/visudo -cf %s
    state: absent
  register: sudoers_file_defaults
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Check for duplicate values
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    create: false
    regexp: ^Defaults !targetpw$
    state: absent
  check_mode: true
  changed_when: false
  register: dupes
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Deduplicate values from /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    create: false
    regexp: ^Defaults !targetpw$
    state: absent
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  - dupes.found is defined and dupes.found &gt; 1
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Insert correct line into /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    create: false
    regexp: ^Defaults !targetpw$
    line: Defaults !targetpw
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Check for duplicate values
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    create: false
    regexp: ^Defaults !rootpw$
    state: absent
  check_mode: true
  changed_when: false
  register: dupes
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Deduplicate values from /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    create: false
    regexp: ^Defaults !rootpw$
    state: absent
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  - dupes.found is defined and dupes.found &gt; 1
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Insert correct line into /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    create: false
    regexp: ^Defaults !rootpw$
    line: Defaults !rootpw
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Check for duplicate values
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    create: false
    regexp: ^Defaults !runaspw$
    state: absent
  check_mode: true
  changed_when: false
  register: dupes
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Deduplicate values from /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    create: false
    regexp: ^Defaults !runaspw$
    state: absent
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  - dupes.found is defined and dupes.found &gt; 1
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd

- name: Insert correct line into /etc/sudoers
  ansible.builtin.lineinfile:
    path: /etc/sudoers
    create: false
    regexp: ^Defaults !runaspw$
    line: Defaults !runaspw
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sudo" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010383
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sudoers_validate_passwd
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sudoers_validate_passwd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sudoers_validate_passwd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_system-tools">
            <xccdf-1.2:title>System Tooling / Utilities</xccdf-1.2:title>
            <xccdf-1.2:description>The following checks evaluate the system for recommended base packages -- both for installation
and removal.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_binutils_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install binutils Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>binutils</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install binutils</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale><html:code>binutils</html:code> is a collection of binary utilities required for
foundational system operator activities, such as <html:code>ld</html:code>,
<html:code>nm</html:code>, <html:code>objcopy</html:code> and <html:code>readelf</html:code>.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_binutils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh">
if ! rpm -q --quiet "binutils" ; then
    yum install -y "binutils"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_binutils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Ensure binutils is installed
  ansible.builtin.package:
    name: binutils
    state: present
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_binutils_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_binutils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_binutils

class install_binutils {
  package { 'binutils':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_binutils_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=binutils
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_binutils_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "binutils"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_binutils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install binutils
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_binutils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install binutils
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_binutils_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_binutils_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_dnf-plugin-subscription-manager_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install dnf-plugin-subscription-manager Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>dnf-plugin-subscription-manager</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install dnf-plugin-subscription-manager</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_TUD_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_TUD_EXT.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000366-GPOS-00153</xccdf-1.2:reference>
              <xccdf-1.2:rationale>This package provides plugins to interact with repositories and subscriptions
from the Red Hat entitlement platform; contains subscription-manager and
product-id plugins.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnf-plugin-subscription-manager_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh">
if ! rpm -q --quiet "dnf-plugin-subscription-manager" ; then
    yum install -y "dnf-plugin-subscription-manager"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnf-plugin-subscription-manager_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Ensure dnf-plugin-subscription-manager is installed
  ansible.builtin.package:
    name: dnf-plugin-subscription-manager
    state: present
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_dnf-plugin-subscription-manager_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnf-plugin-subscription-manager_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_dnf-plugin-subscription-manager

class install_dnf-plugin-subscription-manager {
  package { 'dnf-plugin-subscription-manager':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnf-plugin-subscription-manager_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=dnf-plugin-subscription-manager
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_dnf-plugin-subscription-manager_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "dnf-plugin-subscription-manager"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnf-plugin-subscription-manager_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install dnf-plugin-subscription-manager
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnf-plugin-subscription-manager_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install dnf-plugin-subscription-manager
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_dnf-plugin-subscription-manager_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_dnf-plugin-subscription-manager_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_gnutls-utils_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure gnutls-utils is installed</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>gnutls-utils</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install gnutls-utils</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_X509_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_X509_EXT.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_X509_EXT.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>GnuTLS is a secure communications library implementing the SSL, TLS and DTLS
protocols and technologies around them. It provides a simple C language
application programming interface (API) to access the secure communications
protocols as well as APIs to parse and write X.509, PKCS #12, OpenPGP and
other required structures.
This package contains command line TLS client and server and certificate
manipulation tools.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_gnutls-utils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "gnutls-utils" ; then
    yum install -y "gnutls-utils"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_gnutls-utils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_gnutls-utils_installed

- name: Ensure gnutls-utils is installed
  ansible.builtin.package:
    name: gnutls-utils
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_gnutls-utils_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_gnutls-utils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_gnutls-utils

class install_gnutls-utils {
  package { 'gnutls-utils':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_gnutls-utils_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=gnutls-utils
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_gnutls-utils_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "gnutls-utils"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_gnutls-utils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install gnutls-utils
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_gnutls-utils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install gnutls-utils
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_gnutls-utils_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_gnutls-utils_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_libcap-ng-utils_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install libcap-ng-utils Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>libcap-ng-utils</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install libcap-ng-utils</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000445-GPOS-00199</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>libcap-ng-utils</html:code> contains applications to analyze the posix
posix capabilities of all the programs running on a system.
<html:code>libcap-ng-utils</html:code> also lets system operators set the file
system based capabilities.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libcap-ng-utils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh">
if ! rpm -q --quiet "libcap-ng-utils" ; then
    yum install -y "libcap-ng-utils"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libcap-ng-utils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Ensure libcap-ng-utils is installed
  ansible.builtin.package:
    name: libcap-ng-utils
    state: present
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_libcap-ng-utils_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libcap-ng-utils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_libcap-ng-utils

class install_libcap-ng-utils {
  package { 'libcap-ng-utils':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libcap-ng-utils_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=libcap-ng-utils
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_libcap-ng-utils_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "libcap-ng-utils"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libcap-ng-utils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install libcap-ng-utils
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libcap-ng-utils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install libcap-ng-utils
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_libcap-ng-utils_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_libcap-ng-utils_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_nss-tools_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure nss-tools is installed</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nss-tools</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install nss-tools</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Network Security Services (NSS) is a set of libraries designed to
support cross-platform development of security-enabled client and
server applications. Install the <html:code>nss-tools</html:code> package
to install command-line tools to manipulate the NSS certificate
and key database.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nss-tools_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "nss-tools" ; then
    yum install -y "nss-tools"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nss-tools_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_nss-tools_installed

- name: Ensure nss-tools is installed
  ansible.builtin.package:
    name: nss-tools
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_nss-tools_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nss-tools_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_nss-tools

class install_nss-tools {
  package { 'nss-tools':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nss-tools_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=nss-tools
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_nss-tools_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "nss-tools"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nss-tools_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install nss-tools
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nss-tools_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install nss-tools
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_nss-tools_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_nss-tools_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_openscap-scanner_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install openscap-scanner Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>openscap-scanner</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install openscap-scanner</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">AGD_PRE.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">AGD_OPE.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000191-GPOS-00080</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>openscap-scanner</html:code> contains the <html:code>oscap</html:code> command line tool. This tool is a
configuration and vulnerability scanner, capable of performing compliance checking using
SCAP content.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openscap-scanner_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "openscap-scanner" ; then
    yum install -y "openscap-scanner"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openscap-scanner_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_openscap-scanner_installed

- name: Ensure openscap-scanner is installed
  ansible.builtin.package:
    name: openscap-scanner
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_openscap-scanner_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openscap-scanner_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_openscap-scanner

class install_openscap-scanner {
  package { 'openscap-scanner':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openscap-scanner_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=openscap-scanner
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_openscap-scanner_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "openscap-scanner"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openscap-scanner_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install openscap-scanner
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openscap-scanner_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install openscap-scanner
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_openscap-scanner_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_openscap-scanner_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_rear_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install rear Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>rear</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install rear</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>rear</html:code> contains the Relax-and-Recover (ReaR) utility. ReaR produces a bootable
image of a system and restores from backup using this image.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch_and_os_linux_ol_gt_or_eq_9_0_or_aarch64_arch_and_os_linux_rhel_gt_or_eq_9_0_or_os_linux_rhel_le_or_eq_8_4_and_s390x_arch"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rear_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( ( ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) &amp;&amp; grep -qP "^ID=[\"']?ol[\"']?$" "/etc/os-release" &amp;&amp; { real="$(grep -P "^VERSION_ID=[\"']?[\w.]+[\"']?$" /etc/os-release | sed "s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")"; expected="9.0"; printf "%s\n%s" "$expected" "$real" | sort -VC; } ) || ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) &amp;&amp; grep -qP "^ID=[\"']?rhel[\"']?$" "/etc/os-release" &amp;&amp; { real="$(grep -P "^VERSION_ID=[\"']?[\w.]+[\"']?$" /etc/os-release | sed "s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")"; expected="9.0"; printf "%s\n%s" "$expected" "$real" | sort -VC; } ) || ( grep -qP "^ID=[\"']?rhel[\"']?$" "/etc/os-release" &amp;&amp; { real="$(grep -P "^VERSION_ID=[\"']?[\w.]+[\"']?$" /etc/os-release | sed "s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")"; expected="8.4"; printf "%s\n%s" "$real" "$expected" | sort -VC; } &amp;&amp; ( grep -sqE "^.*\.s390x$" /proc/sys/kernel/osrelease || grep -sqE "^s390x$" /proc/sys/kernel/arch; ) ) ) ) ); then

if ! rpm -q --quiet "rear" ; then
    yum install -y "rear"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rear_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Ensure rear is installed
  ansible.builtin.package:
    name: rear
    state: present
  when: not ( ( ( ansible_architecture == "aarch64" and ansible_distribution == 'OracleLinux'
    and ansible_distribution_version is version('9.0', '&gt;=') ) or ( ansible_architecture
    == "aarch64" and ansible_distribution == 'RedHat' and ansible_distribution_version
    is version('9.0', '&gt;=') ) or ( ansible_distribution == 'RedHat' and ansible_distribution_version
    is version('8.4', '&lt;=') and ansible_architecture == "s390x" ) ) )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_rear_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rear_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_rear

class install_rear {
  package { 'rear':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rear_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=rear
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_rear_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "rear"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rear_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install rear
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rear_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install rear
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_rear_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_rear_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_rng-tools_installed" selected="false" severity="low">
              <xccdf-1.2:title>Install rng-tools Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>rng-tools</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install rng-tools</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">For RHEL versions 8.4 and above running with kernel FIPS mode enabled this rule is not applicable.
The in-kernel deterministic random bit generator (DRBG) is used in FIPS mode instead.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010472</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244527r1017333_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>rng-tools</html:code> provides hardware random number generator tools,
such as those used in the formation of x509/PKI certificates.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#os_linux_rhel_le_or_eq_8_3_or_os_linux_rhel_gt_or_eq_8_4_and_not_runtime_kernel_fips_enabled_and_system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rng-tools_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( grep -qP "^ID=[\"']?rhel[\"']?$" "/etc/os-release" &amp;&amp; { real="$(grep -P "^VERSION_ID=[\"']?[\w.]+[\"']?$" /etc/os-release | sed "s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")"; expected="8.3"; printf "%s\n%s" "$real" "$expected" | sort -VC; } || ( grep -qP "^ID=[\"']?rhel[\"']?$" "/etc/os-release" &amp;&amp; { real="$(grep -P "^VERSION_ID=[\"']?[\w.]+[\"']?$" /etc/os-release | sed "s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")"; expected="8.4"; printf "%s\n%s" "$expected" "$real" | sort -VC; } &amp;&amp; ! ( [ "$(sysctl -a | grep -c 'fips_enabled.*1')" -eq 1 ] ) &amp;&amp; rpm --quiet -q kernel ) ) ); then

if ! rpm -q --quiet "rng-tools" ; then
    yum install -y "rng-tools"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rng-tools_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010472
  - enable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_rng-tools_installed

- name: Ensure rng-tools is installed
  ansible.builtin.package:
    name: rng-tools
    state: present
  when: ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.3',
    '&lt;=') or ( ansible_distribution == 'RedHat' and ansible_distribution_version is
    version('8.4', '&gt;=') and "kernel" in ansible_facts.packages ) )
  tags:
  - DISA-STIG-RHEL-08-010472
  - enable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_rng-tools_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rng-tools_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_rng-tools

class install_rng-tools {
  package { 'rng-tools':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rng-tools_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=rng-tools
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_rng-tools_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "rng-tools"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rng-tools_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install rng-tools
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rng-tools_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install rng-tools
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_rng-tools_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_rng-tools_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_scap-security-guide_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install scap-security-guide Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>scap-security-guide</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install scap-security-guide</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">AGD_PRE.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">AGD_OPE.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>scap-security-guide</html:code> package provides a guide for configuration of the system
from the final system's security point of view. The guidance is specified in the Security
Content Automation Protocol (SCAP) format and constitutes a catalog of practical hardening
advice, linked to government requirements where applicable. The SCAP Security Guide project
bridges the gap between generalized policy requirements and specific implementation guidelines.
A system administrator can use the <html:code>oscap</html:code> CLI tool from the <html:code>openscap-scanner</html:code>
package, or the SCAP Workbench GUI tool from the <html:code>scap-workbench</html:code> package, to verify
that the system conforms to provided guidelines. Refer to the scap-security-guide(8) manual
page for further information.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_scap-security-guide_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "scap-security-guide" ; then
    yum install -y "scap-security-guide"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_scap-security-guide_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_scap-security-guide_installed

- name: Ensure scap-security-guide is installed
  ansible.builtin.package:
    name: scap-security-guide
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_scap-security-guide_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_scap-security-guide_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_scap-security-guide

class install_scap-security-guide {
  package { 'scap-security-guide':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_scap-security-guide_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=scap-security-guide
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_scap-security-guide_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "scap-security-guide"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_scap-security-guide_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install scap-security-guide
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_scap-security-guide_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install scap-security-guide
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_scap-security-guide_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_scap-security-guide_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_subscription-manager_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install subscription-manager Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>subscription-manager</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install subscription-manager</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_TUD_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_TUD_EXT.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000366-GPOS-00153</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1467</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1483</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1493</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Red Hat Subscription Manager is a local service which tracks installed products
and subscriptions on a local system to help manage subscription assignments.
It communicates with the backend subscription service (the Customer Portal
or an on-premise server such as Subscription Asset Manager) and works with
content management tools such as .</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_subscription-manager_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "subscription-manager" ; then
    yum install -y "subscription-manager"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_subscription-manager_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_subscription-manager_installed

- name: Ensure subscription-manager is installed
  ansible.builtin.package:
    name: subscription-manager
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_subscription-manager_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_subscription-manager_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_subscription-manager

class install_subscription-manager {
  package { 'subscription-manager':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_subscription-manager_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=subscription-manager
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_subscription-manager_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "subscription-manager"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_subscription-manager_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install subscription-manager
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_subscription-manager_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install subscription-manager
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_subscription-manager_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_subscription-manager_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_tar_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install tar Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>tar</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install tar</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>The GNU <html:code>tar</html:code> program saves many files together into one archive and
can restore individual files (or all of the files) from the archive. <html:code>tar</html:code>
includes multivolume support, automatic archive compression/decompression, the
the ability to perform incremental and full backups. If </xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tar_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh">
if ! rpm -q --quiet "tar" ; then
    yum install -y "tar"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tar_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Ensure tar is installed
  ansible.builtin.package:
    name: tar
    state: present
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_tar_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tar_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_tar

class install_tar {
  package { 'tar':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tar_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=tar
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_tar_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "tar"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tar_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install tar
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tar_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install tar
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_tar_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_tar_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_vim_installed" selected="false" severity="low">
              <xccdf-1.2:title>Install vim Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>vim-enhanced</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install vim-enhanced</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>Vim (Vi IMproved) is an almost compatible version of the UNIX editor <html:code>vi</html:code>. </xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vim_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh">
if ! rpm -q --quiet "vim-enhanced" ; then
    yum install -y "vim-enhanced"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vim_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Ensure vim-enhanced is installed
  ansible.builtin.package:
    name: vim-enhanced
    state: present
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_vim_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vim_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_vim-enhanced

class install_vim-enhanced {
  package { 'vim-enhanced':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vim_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=vim-enhanced
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_vim_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "vim-enhanced"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vim_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install vim-enhanced
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vim_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install vim-enhanced
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_vim_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_vim_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_abrt-addon-ccpp_removed" selected="false" severity="low">
              <xccdf-1.2:title>Uninstall abrt-addon-ccpp Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>abrt-addon-ccpp</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase abrt-addon-ccpp</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040001</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230488r1017272_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>abrt-addon-ccpp</html:code> contains hooks for C/C++ crashed programs and <html:code>abrt</html:code>'s
C/C++ analyzer plugin.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-addon-ccpp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove abrt-addon-ccpp
# from the system, and may remove any packages
# that depend on abrt-addon-ccpp. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "abrt-addon-ccpp" ; then
yum remove -y "abrt-addon-ccpp"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-addon-ccpp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall abrt-addon-ccpp Package: Ensure abrt-addon-ccpp is removed'
  ansible.builtin.package:
    name: abrt-addon-ccpp
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040001
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_abrt-addon-ccpp_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-addon-ccpp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_abrt-addon-ccpp

class remove_abrt-addon-ccpp {
  package { 'abrt-addon-ccpp':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-addon-ccpp_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=abrt-addon-ccpp
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-addon-ccpp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove abrt-addon-ccpp
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-addon-ccpp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove abrt-addon-ccpp
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_abrt-addon-ccpp_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_abrt-addon-ccpp_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_abrt-addon-kerneloops_removed" selected="false" severity="low">
              <xccdf-1.2:title>Uninstall abrt-addon-kerneloops Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>abrt-addon-kerneloops</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase abrt-addon-kerneloops</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040001</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230488r1017272_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>abrt-addon-kerneloops</html:code> contains plugins for collecting kernel crash information and
reporter plugin which sends this information to a specified server, usually to kerneloops.org.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-addon-kerneloops_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove abrt-addon-kerneloops
# from the system, and may remove any packages
# that depend on abrt-addon-kerneloops. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "abrt-addon-kerneloops" ; then
yum remove -y "abrt-addon-kerneloops"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-addon-kerneloops_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall abrt-addon-kerneloops Package: Ensure abrt-addon-kerneloops is
    removed'
  ansible.builtin.package:
    name: abrt-addon-kerneloops
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040001
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_abrt-addon-kerneloops_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-addon-kerneloops_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_abrt-addon-kerneloops

class remove_abrt-addon-kerneloops {
  package { 'abrt-addon-kerneloops':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-addon-kerneloops_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=abrt-addon-kerneloops
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-addon-kerneloops_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove abrt-addon-kerneloops
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-addon-kerneloops_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove abrt-addon-kerneloops
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_abrt-addon-kerneloops_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_abrt-addon-kerneloops_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_abrt-cli_removed" selected="false" severity="low">
              <xccdf-1.2:title>Uninstall abrt-cli Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>abrt-cli</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase abrt-cli</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040001</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230488r1017272_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>abrt-cli</html:code> contains a command line client for controlling abrt daemon
over sockets.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-cli_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove abrt-cli
# from the system, and may remove any packages
# that depend on abrt-cli. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "abrt-cli" ; then
yum remove -y "abrt-cli"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-cli_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall abrt-cli Package: Ensure abrt-cli is removed'
  ansible.builtin.package:
    name: abrt-cli
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040001
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_abrt-cli_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-cli_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_abrt-cli

class remove_abrt-cli {
  package { 'abrt-cli':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-cli_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=abrt-cli
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-cli_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove abrt-cli
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-cli_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove abrt-cli
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_abrt-cli_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_abrt-cli_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_abrt-plugin-logger_removed" selected="false" severity="low">
              <xccdf-1.2:title>Uninstall abrt-plugin-logger Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>abrt-plugin-logger</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase abrt-plugin-logger</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>abrt-plugin-logger</html:code> is an ABRT plugin which writes a report
to a specified file.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-logger_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove abrt-plugin-logger
# from the system, and may remove any packages
# that depend on abrt-plugin-logger. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "abrt-plugin-logger" ; then
yum remove -y "abrt-plugin-logger"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-logger_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall abrt-plugin-logger Package: Ensure abrt-plugin-logger is removed'
  ansible.builtin.package:
    name: abrt-plugin-logger
    state: absent
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_abrt-plugin-logger_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-logger_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_abrt-plugin-logger

class remove_abrt-plugin-logger {
  package { 'abrt-plugin-logger':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-logger_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=abrt-plugin-logger
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-logger_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove abrt-plugin-logger
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-logger_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove abrt-plugin-logger
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_abrt-plugin-logger_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_abrt-plugin-logger_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_abrt-plugin-rhtsupport_removed" selected="false" severity="low">
              <xccdf-1.2:title>Uninstall abrt-plugin-rhtsupport Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>abrt-plugin-rhtsupport</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase abrt-plugin-rhtsupport</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>abrt-plugin-rhtsupport</html:code> is a ABRT plugin to report bugs into the
Red Hat Support system.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-rhtsupport_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove abrt-plugin-rhtsupport
# from the system, and may remove any packages
# that depend on abrt-plugin-rhtsupport. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "abrt-plugin-rhtsupport" ; then
yum remove -y "abrt-plugin-rhtsupport"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-rhtsupport_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall abrt-plugin-rhtsupport Package: Ensure abrt-plugin-rhtsupport is
    removed'
  ansible.builtin.package:
    name: abrt-plugin-rhtsupport
    state: absent
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_abrt-plugin-rhtsupport_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-rhtsupport_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_abrt-plugin-rhtsupport

class remove_abrt-plugin-rhtsupport {
  package { 'abrt-plugin-rhtsupport':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-rhtsupport_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=abrt-plugin-rhtsupport
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-rhtsupport_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove abrt-plugin-rhtsupport
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-rhtsupport_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove abrt-plugin-rhtsupport
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_abrt-plugin-rhtsupport_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_abrt-plugin-rhtsupport_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_abrt-plugin-sosreport_removed" selected="false" severity="low">
              <xccdf-1.2:title>Uninstall abrt-plugin-sosreport Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>abrt-plugin-sosreport</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase abrt-plugin-sosreport</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040001</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230488r1017272_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>abrt-plugin-sosreport</html:code> provides a plugin to include an sosreport in an ABRT report.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-sosreport_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove abrt-plugin-sosreport
# from the system, and may remove any packages
# that depend on abrt-plugin-sosreport. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "abrt-plugin-sosreport" ; then
yum remove -y "abrt-plugin-sosreport"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-sosreport_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall abrt-plugin-sosreport Package: Ensure abrt-plugin-sosreport is
    removed'
  ansible.builtin.package:
    name: abrt-plugin-sosreport
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040001
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_abrt-plugin-sosreport_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-sosreport_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_abrt-plugin-sosreport

class remove_abrt-plugin-sosreport {
  package { 'abrt-plugin-sosreport':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-sosreport_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=abrt-plugin-sosreport
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-sosreport_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove abrt-plugin-sosreport
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt-plugin-sosreport_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove abrt-plugin-sosreport
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_abrt-plugin-sosreport_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_abrt-plugin-sosreport_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_geolite2-city_removed" selected="false" severity="low">
              <xccdf-1.2:title>Uninstall geolite2-city Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>geolite2-city</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase geolite2-city</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale><html:code>geolite2-city</html:code> is part of the GeoLite2 database packages, offering geolocation databases and tooling.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_geolite2-city_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove geolite2-city
# from the system, and may remove any packages
# that depend on geolite2-city. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "geolite2-city" ; then
yum remove -y "geolite2-city"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_geolite2-city_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall geolite2-city Package: Ensure geolite2-city is removed'
  ansible.builtin.package:
    name: geolite2-city
    state: absent
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_geolite2-city_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_geolite2-city_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_geolite2-city

class remove_geolite2-city {
  package { 'geolite2-city':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_geolite2-city_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=geolite2-city
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_geolite2-city_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove geolite2-city
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_geolite2-city_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove geolite2-city
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_geolite2-city_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_geolite2-city_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_geolite2-country_removed" selected="false" severity="low">
              <xccdf-1.2:title>Uninstall geolite2-country Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>geolite2-country</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase geolite2-country</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale><html:code>geolite2-country</html:code> is part of the GeoLite2 database packages, offering geolocation databases and tooling.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_geolite2-country_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove geolite2-country
# from the system, and may remove any packages
# that depend on geolite2-country. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "geolite2-country" ; then
yum remove -y "geolite2-country"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_geolite2-country_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall geolite2-country Package: Ensure geolite2-country is removed'
  ansible.builtin.package:
    name: geolite2-country
    state: absent
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_geolite2-country_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_geolite2-country_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_geolite2-country

class remove_geolite2-country {
  package { 'geolite2-country':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_geolite2-country_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=geolite2-country
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_geolite2-country_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove geolite2-country
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_geolite2-country_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove geolite2-country
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_geolite2-country_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_geolite2-country_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_gssproxy_removed" selected="false" severity="medium">
              <xccdf-1.2:title>Uninstall gssproxy Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>gssproxy</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase gssproxy</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule is disabled on Red Hat Virtualization Hosts and Managers, it will report not applicable.
RHV uses NFS storage, which has dependency on gssproxy.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040370</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230559r1155398_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>gssproxy</html:code> is a proxy for GSS API credential handling.
Kerberos relies on some key derivation functions that may not
be compatible with some site policies such as FIPS 140.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#no_ovirt"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_gssproxy_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove gssproxy
# from the system, and may remove any packages
# that depend on gssproxy. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "gssproxy" ; then
yum remove -y "gssproxy"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_gssproxy_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall gssproxy Package: Ensure gssproxy is removed'
  ansible.builtin.package:
    name: gssproxy
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040370
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_gssproxy_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_gssproxy_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_gssproxy

class remove_gssproxy {
  package { 'gssproxy':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_gssproxy_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove gssproxy
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_gssproxy_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove gssproxy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_gssproxy_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_gssproxy_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_iprutils_removed" selected="false" severity="medium">
              <xccdf-1.2:title>Uninstall iprutils Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>iprutils</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase iprutils</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040380</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230560r1017321_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>iprutils</html:code> provides a suite of utlilities to manage and configure SCSI devices
supported by the ipr SCSI storage device driver.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iprutils_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove iprutils
# from the system, and may remove any packages
# that depend on iprutils. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "iprutils" ; then
yum remove -y "iprutils"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iprutils_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall iprutils Package: Ensure iprutils is removed'
  ansible.builtin.package:
    name: iprutils
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040380
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_iprutils_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iprutils_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_iprutils

class remove_iprutils {
  package { 'iprutils':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iprutils_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=iprutils
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iprutils_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove iprutils
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iprutils_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove iprutils
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_iprutils_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_iprutils_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_krb5-workstation_removed" selected="false" severity="medium">
              <xccdf-1.2:title>Uninstall krb5-workstation Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>krb5-workstation</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase krb5-workstation</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule is disabled on Red Hat Virtualization Hosts and Managers, it will report not applicable.
RHV hosts require ipa-client package, which has dependency on krb5-workstation.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000120-GPOS-00061</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010162</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230239r1017058_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Kerberos is a network authentication system. The <html:code>krb5-workstation</html:code> package contains the basic
Kerberos programs (<html:code>kinit</html:code>, <html:code>klist</html:code>, <html:code>kdestroy</html:code>, <html:code>kpasswd</html:code>).</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#krb5_workstation_older_than_1_17-18"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_krb5-workstation_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove krb5-workstation
# from the system, and may remove any packages
# that depend on krb5-workstation. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "krb5-workstation" ; then
yum remove -y "krb5-workstation"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_krb5-workstation_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall krb5-workstation Package: Ensure krb5-workstation is removed'
  ansible.builtin.package:
    name: krb5-workstation
    state: absent
  tags:
  - DISA-STIG-RHEL-08-010162
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_krb5-workstation_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_krb5-workstation_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_krb5-workstation

class remove_krb5-workstation {
  package { 'krb5-workstation':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_krb5-workstation_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=krb5-workstation
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_krb5-workstation_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove krb5-workstation
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_krb5-workstation_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove krb5-workstation
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_krb5-workstation_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_krb5-workstation_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_libreport-plugin-logger_removed" selected="false" severity="low">
              <xccdf-1.2:title>Uninstall libreport-plugin-logger Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>libreport-plugin-logger</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase libreport-plugin-logger</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040001</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230488r1017272_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>libreport-plugin-logger</html:code> is a ABRT plugin to report bugs into the
Red Hat Support system.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreport-plugin-logger_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove libreport-plugin-logger
# from the system, and may remove any packages
# that depend on libreport-plugin-logger. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "libreport-plugin-logger" ; then
yum remove -y "libreport-plugin-logger"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreport-plugin-logger_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall libreport-plugin-logger Package: Ensure libreport-plugin-logger
    is removed'
  ansible.builtin.package:
    name: libreport-plugin-logger
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040001
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_libreport-plugin-logger_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreport-plugin-logger_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_libreport-plugin-logger

class remove_libreport-plugin-logger {
  package { 'libreport-plugin-logger':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreport-plugin-logger_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=libreport-plugin-logger
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreport-plugin-logger_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove libreport-plugin-logger
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreport-plugin-logger_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove libreport-plugin-logger
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_libreport-plugin-logger_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_libreport-plugin-logger_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_libreport-plugin-rhtsupport_removed" selected="false" severity="low">
              <xccdf-1.2:title>Uninstall libreport-plugin-rhtsupport Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>libreport-plugin-rhtsupport</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase libreport-plugin-rhtsupport</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040001</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230488r1017272_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>libreport-plugin-rhtsupport</html:code> is a ABRT plugin to report bugs into the
Red Hat Support system.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreport-plugin-rhtsupport_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove libreport-plugin-rhtsupport
# from the system, and may remove any packages
# that depend on libreport-plugin-rhtsupport. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "libreport-plugin-rhtsupport" ; then
yum remove -y "libreport-plugin-rhtsupport"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreport-plugin-rhtsupport_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall libreport-plugin-rhtsupport Package: Ensure libreport-plugin-rhtsupport
    is removed'
  ansible.builtin.package:
    name: libreport-plugin-rhtsupport
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040001
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_libreport-plugin-rhtsupport_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreport-plugin-rhtsupport_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_libreport-plugin-rhtsupport

class remove_libreport-plugin-rhtsupport {
  package { 'libreport-plugin-rhtsupport':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreport-plugin-rhtsupport_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=libreport-plugin-rhtsupport
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreport-plugin-rhtsupport_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove libreport-plugin-rhtsupport
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreport-plugin-rhtsupport_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove libreport-plugin-rhtsupport
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_libreport-plugin-rhtsupport_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_libreport-plugin-rhtsupport_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_pigz_removed" selected="false" severity="low">
              <xccdf-1.2:title>Uninstall pigz Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>pigz</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase pigz</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000433-GPOS-00192</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Binaries shipped in <html:code>pigz</html:code> package in AlmaLinux OS 8
have not been compiled using recommended compiler flags. The binaries
are compiled without sufficient stack protection and its address space
layout randomization (ASLR) is weak.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pigz_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove pigz
# from the system, and may remove any packages
# that depend on pigz. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "pigz" ; then
yum remove -y "pigz"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pigz_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall pigz Package: Ensure pigz is removed'
  ansible.builtin.package:
    name: pigz
    state: absent
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_pigz_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pigz_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_pigz

class remove_pigz {
  package { 'pigz':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pigz_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=pigz
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pigz_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove pigz
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pigz_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove pigz
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_pigz_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_pigz_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_python3-abrt-addon_removed" selected="false" severity="low">
              <xccdf-1.2:title>Uninstall python3-abrt-addon Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>python3-abrt-addon</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase python3-abrt-addon</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040001</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230488r1017272_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>python3-abrt-addon</html:code> contains python hook and python analyzer
plugin for handling uncaught exceptions in python programs.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_python3-abrt-addon_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove python3-abrt-addon
# from the system, and may remove any packages
# that depend on python3-abrt-addon. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "python3-abrt-addon" ; then
yum remove -y "python3-abrt-addon"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_python3-abrt-addon_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall python3-abrt-addon Package: Ensure python3-abrt-addon is removed'
  ansible.builtin.package:
    name: python3-abrt-addon
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040001
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_python3-abrt-addon_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_python3-abrt-addon_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_python3-abrt-addon

class remove_python3-abrt-addon {
  package { 'python3-abrt-addon':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_python3-abrt-addon_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=python3-abrt-addon
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_python3-abrt-addon_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove python3-abrt-addon
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_python3-abrt-addon_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove python3-abrt-addon
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_python3-abrt-addon_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_python3-abrt-addon_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_tuned_removed" selected="false" severity="medium">
              <xccdf-1.2:title>Uninstall tuned Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>tuned</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase tuned</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule is disabled on Red Hat Virtualization Hosts and Managers, it will report not applicable.
RHV requires tuned package for tuning profiles that can enhance virtualization performance.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040390</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230561r1017322_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>tuned</html:code> contains a daemon that tunes the system settings dynamically.
It does so by monitoring the usage of several system components periodically. Based
on that information, components will then be put into lower or higher power savings
modes to adapt to the current usage.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#no_ovirt"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tuned_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove tuned
# from the system, and may remove any packages
# that depend on tuned. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "tuned" ; then
yum remove -y "tuned"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tuned_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall tuned Package: Ensure tuned is removed'
  ansible.builtin.package:
    name: tuned
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040390
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_tuned_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tuned_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_tuned

class remove_tuned {
  package { 'tuned':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tuned_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=tuned
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tuned_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove tuned
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tuned_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove tuned
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_tuned_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_tuned_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_updating">
            <xccdf-1.2:title>Updating Software</xccdf-1.2:title>
            <xccdf-1.2:description>
The <html:code>yum</html:code> command line tool is used to install and
update software packages. The system also provides a graphical
software update tool in the <html:b>System</html:b> menu, in the <html:b>Administration</html:b> submenu,
called <html:b>Software Update</html:b>.
<html:br/><html:br/>
AlmaLinux OS 8 systems contain an installed software catalog called
the RPM database, which records metadata of installed packages. Consistently using
<html:code>yum</html:code> or the graphical <html:b>Software Update</html:b> for all software installation
allows for insight into the current inventory of installed software on the system.
<html:br/><html:br/></xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install dnf-automatic Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>dnf-automatic</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install dnf-automatic</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_TUD_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_TUD_EXT.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000191-GPOS-00080</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R61</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>dnf-automatic</html:code> is an alternative command line interface (CLI)
to <html:code>dnf upgrade</html:code> suitable for automatic, regular execution.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_bootc_and_not_container"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnf-automatic_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) ); then

if ! rpm -q --quiet "dnf-automatic" ; then
    yum install -y "dnf-automatic"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnf-automatic_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_dnf-automatic_installed

- name: Ensure dnf-automatic is installed
  ansible.builtin.package:
    name: dnf-automatic
    state: present
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_dnf-automatic_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnf-automatic_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_dnf-automatic

class install_dnf-automatic {
  package { 'dnf-automatic':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnf-automatic_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=dnf-automatic
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_dnf-automatic_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "dnf-automatic"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnf-automatic_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install dnf-automatic
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnf-automatic_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install dnf-automatic
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_dnf-automatic_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_dnf-automatic_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_clean_components_post_updating" selected="false" severity="low">
              <xccdf-1.2:title>Ensure yum Removes Previous Package Versions</xccdf-1.2:title>
              <xccdf-1.2:description><html:code>yum</html:code> should be configured to remove previous software components after
new versions have been installed. To configure <html:code>yum</html:code> to remove the

previous software components after updating, set the <html:code>clean_requirements_on_remove</html:code>


to <html:code>1</html:code> in <html:code>/etc/yum.conf</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">20</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-2(6)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-11(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-11(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.RA-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000437-GPOS-00194</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010440</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230281r958936_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Previous versions of software components that are not removed from the information
system after updates have been installed may be exploited by some adversaries.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_bootc_and_package_yum"/>
              <xccdf-1.2:fix id="clean_components_post_updating" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; rpm --quiet -q yum ) ); then

if grep --silent ^clean_requirements_on_remove /etc/yum.conf ; then
        sed -i "s/^clean_requirements_on_remove.*/clean_requirements_on_remove=1/g" /etc/yum.conf
else
        echo -e "\n# Set clean_requirements_on_remove to 1 per security requirements" &gt;&gt; /etc/yum.conf
        echo "clean_requirements_on_remove=1" &gt;&gt; /etc/yum.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="clean_components_post_updating" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010440
  - NIST-800-171-3.4.8
  - NIST-800-53-CM-11(a)
  - NIST-800-53-CM-11(b)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-2(6)
  - clean_components_post_updating
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure yum Removes Previous Package Versions - Ensure YUM Removes Previous
    Package Versions
  ansible.builtin.lineinfile:
    dest: /etc/yum.conf
    regexp: ^#?clean_requirements_on_remove
    line: clean_requirements_on_remove=1
    insertafter: \[main\]
    create: true
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and "yum" in ansible_facts.packages )
  tags:
  - DISA-STIG-RHEL-08-010440
  - NIST-800-171-3.4.8
  - NIST-800-53-CM-11(a)
  - NIST-800-53-CM-11(b)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-2(6)
  - clean_components_post_updating
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-clean_components_post_updating:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-clean_components_post_updating_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_disable_weak_deps" selected="false" severity="medium">
              <xccdf-1.2:title>Disable Installation of Weak Dependencies in DNF</xccdf-1.2:title>
              <xccdf-1.2:description>To disable weak dependencies, set the <html:code>install_weak_deps</html:code> option to <html:code>0</html:code> in the <html:code>/etc/dnf/dnf.conf</html:code> file.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.2.1.5</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unless a system specifically requires the additional capabilities provides by the weak
dependencies, it is recommended that the packages are not installed to reduce the
potential attack surface.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_dnf"/>
              <xccdf-1.2:fix id="disable_weak_deps" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q dnf; then

found=false

# set value in all files if they contain section or key
for f in $(echo -n "/etc/dnf/dnf.conf"); do
    if [ ! -e "$f" ]; then
        continue
    fi

    # find key in section and change value
    if grep -qzosP "(?m)^[[:space:]]*\[main\]([^\n\[]*\n+)+?[[:space:]]*install_weak_deps" "$f"; then
        if ! grep -qzosP "(?m)^[[:space:]]*install_weak_deps[[:space:]]*=[[:space:]]*0" "$f"; then

            sed -i "/^[[:space:]]*install_weak_deps/s/\([[:blank:]]*=[[:blank:]]*\).*/\10/" "$f"

        fi

        found=true

    # find section and add key = value to it
    elif grep -qs "^[[:space:]]*\[main\]" "$f"; then

            sed -i "/^[[:space:]]*\[main\]/a install_weak_deps=0" "$f"

            found=true
    fi
done

# if section not in any file, append section with key = value to FIRST file in files parameter
if ! $found ; then
    file=$(echo "/etc/dnf/dnf.conf" | cut -f1 -d ' ')
    mkdir -p "$(dirname "$file")"

    echo -e "[main]\ninstall_weak_deps=0" &gt;&gt; "$file"

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="disable_weak_deps" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_weak_deps
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable Installation of Weak Dependencies in DNF - Disable weak dependencies
  community.general.ini_file:
    path: /etc/dnf/dnf.conf
    section: main
    option: install_weak_deps
    value: 0
    create: true
    state: present
  when: '"dnf" in ansible_facts.packages'
  tags:
  - disable_weak_deps
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-disable_weak_deps:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-disable_weak_deps_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dnf-automatic_apply_updates" selected="false" severity="medium">
              <xccdf-1.2:title>Configure dnf-automatic to Install Available Updates Automatically</xccdf-1.2:title>
              <xccdf-1.2:description>To ensure that the packages comprising the available updates will be automatically installed by <html:code>dnf-automatic</html:code>, set <html:code>apply_updates</html:code> to <html:code>yes</html:code> under <html:code>[commands]</html:code> section in <html:code>/etc/dnf/automatic.conf</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-2(5)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-2(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000805-GPOS-00260</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R61</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1467</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1483</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1493</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Installing software updates is a fundamental mitigation against
the exploitation of publicly-known vulnerabilities. If the most
recent security patches and updates are not installed, unauthorized
users may take advantage of weaknesses in the unpatched software. The
lack of prompt attention to patching could result in a system compromise.
The automated installation of updates ensures that recent security patches
are applied in a timely manner.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_bootc_and_not_container"/>
              <xccdf-1.2:fix id="dnf-automatic_apply_updates" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) ); then

found=false

# set value in all files if they contain section or key
for f in $(echo -n "/etc/dnf/automatic.conf"); do
    if [ ! -e "$f" ]; then
        continue
    fi

    # find key in section and change value
    if grep -qzosP "(?m)^[[:space:]]*\[commands\]([^\n\[]*\n+)+?[[:space:]]*apply_updates" "$f"; then
        if ! grep -qzosP "(?m)^[[:space:]]*apply_updates[[:space:]]*=[[:space:]]*yes" "$f"; then

            sed -i "/^[[:space:]]*apply_updates/s/\([[:blank:]]*=[[:blank:]]*\).*/\1yes/" "$f"

        fi

        found=true

    # find section and add key = value to it
    elif grep -qs "^[[:space:]]*\[commands\]" "$f"; then

            sed -i "/^[[:space:]]*\[commands\]/a apply_updates=yes" "$f"

            found=true
    fi
done

# if section not in any file, append section with key = value to FIRST file in files parameter
if ! $found ; then
    file=$(echo "/etc/dnf/automatic.conf" | cut -f1 -d ' ')
    mkdir -p "$(dirname "$file")"

    echo -e "[commands]\napply_updates=yes" &gt;&gt; "$file"

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="dnf-automatic_apply_updates" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-2(5)
  - NIST-800-53-SI-2(c)
  - dnf-automatic_apply_updates
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Configure dnf-automatic to Install Available Updates Automatically
  community.general.ini_file:
    dest: /etc/dnf/automatic.conf
    section: commands
    option: apply_updates
    value: 'yes'
    create: true
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-2(5)
  - NIST-800-53-SI-2(c)
  - dnf-automatic_apply_updates
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dnf-automatic_apply_updates:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dnf-automatic_apply_updates_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dnf-automatic_security_updates_only" selected="false" severity="low">
              <xccdf-1.2:title>Configure dnf-automatic to Install Only Security Updates</xccdf-1.2:title>
              <xccdf-1.2:description>To configure <html:code>dnf-automatic</html:code> to install only security updates
automatically, set <html:code>upgrade_type</html:code> to <html:code>security</html:code> under
<html:code>[commands]</html:code> section in <html:code>/etc/dnf/automatic.conf</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-2(5)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-2(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000191-GPOS-00080</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R61</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1493</xccdf-1.2:reference>
              <xccdf-1.2:rationale>By default, <html:code>dnf-automatic</html:code> installs all available updates.
Reducing the amount of updated packages only to updates that were
issued as a part of a security advisory increases the system stability.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_bootc_and_not_container"/>
              <xccdf-1.2:fix id="dnf-automatic_security_updates_only" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) ); then

found=false

# set value in all files if they contain section or key
for f in $(echo -n "/etc/dnf/automatic.conf"); do
    if [ ! -e "$f" ]; then
        continue
    fi

    # find key in section and change value
    if grep -qzosP "(?m)^[[:space:]]*\[commands\]([^\n\[]*\n+)+?[[:space:]]*upgrade_type" "$f"; then
        if ! grep -qzosP "(?m)^[[:space:]]*upgrade_type[[:space:]]*=[[:space:]]*security" "$f"; then

            sed -i "/^[[:space:]]*upgrade_type/s/\([[:blank:]]*=[[:blank:]]*\).*/\1security/" "$f"

        fi

        found=true

    # find section and add key = value to it
    elif grep -qs "^[[:space:]]*\[commands\]" "$f"; then

            sed -i "/^[[:space:]]*\[commands\]/a upgrade_type=security" "$f"

            found=true
    fi
done

# if section not in any file, append section with key = value to FIRST file in files parameter
if ! $found ; then
    file=$(echo "/etc/dnf/automatic.conf" | cut -f1 -d ' ')
    mkdir -p "$(dirname "$file")"

    echo -e "[commands]\nupgrade_type=security" &gt;&gt; "$file"

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="dnf-automatic_security_updates_only" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-2(5)
  - NIST-800-53-SI-2(c)
  - dnf-automatic_security_updates_only
  - low_complexity
  - low_severity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Configure dnf-automatic to Install Only Security Updates
  community.general.ini_file:
    dest: /etc/dnf/automatic.conf
    section: commands
    option: upgrade_type
    value: security
    create: true
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-2(5)
  - NIST-800-53-SI-2(c)
  - dnf-automatic_security_updates_only
  - low_complexity
  - low_severity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dnf-automatic_security_updates_only:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dnf-automatic_security_updates_only_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_enable_gpgcheck_for_all_repositories" selected="false" severity="high">
              <xccdf-1.2:title>Ensure gpgcheck Is Enabled for All Package Repositories</xccdf-1.2:title>
              <xccdf-1.2:description>To ensure signature checking is enabled for all package repositories, the
<html:code>gpgcheck</html:code> option must be enabled for all repos.
Configure the operating system to verify the signature of packages from
a repository prior to install by setting the following option in
the <html:code>"/etc/yum.repos.d/[your_repo_name].repo"</html:code> file:
<html:pre>gpgcheck=1</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000366-GPOS-00153</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010370</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230264r1017377_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Changes to any software components can have significant effects on the
overall security of the operating system. This requirement ensures the
software has not been tampered with and that it has been provided by
a trusted vendor.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="enable_gpgcheck_for_all_repositories" system="urn:xccdf:fix:script:sh">
function replace_all_gpgcheck {
    sed -i 's/gpgcheck\s*=.*/gpgcheck=1/g' /etc/yum.repos.d/*
}

function add_gpgcheck_where_missing {
    for repofile in /etc/yum.repos.d/* ; do
        declare -a sections_without_gpgcheck
        section="false"
        section_has_gpgcheck="false"
        section_name=""
        while IFS= read -r line; do
            if grep -qP '^\[.*\]$' &lt;( echo "$line" ) ; then
                # new section starts
                if [[ "$section" == "true" ]] &amp;&amp; [[ "$section_has_gpgcheck" == "false" ]] ; then
                    sections_without_gpgcheck+=("$section_name")
                    section="false"
                fi
                section="true"
                section_has_gpgcheck="false"
                section_name=$(echo "$line" | sed -n 's/^\[\(.*\)\]$/\1/p')
            fi
            if grep -qP '^\s*gpgcheck\s*=\s*' &lt;( echo "$line" ) ; then
                section_has_gpgcheck="true"
            fi
        done &lt; "$repofile"
        if [[ "$section" == "true" ]] &amp;&amp; [[ "$section_has_gpgcheck" == "false" ]] ; then
            sections_without_gpgcheck+=("$section_name")
            section="false"
        fi

        for x in "${sections_without_gpgcheck[@]}" ; do
            sed -i "s/^\[$x\]/&amp;\ngpgcheck=1/" "$repofile"
        done
    done
}

replace_all_gpgcheck
add_gpgcheck_where_missing
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="enable_gpgcheck_for_all_repositories" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: 'Ensure gpgcheck Is Enabled for All Package Repositories: Grep for yum repo
    section names'
  ansible.builtin.shell: |
    set -o pipefail
    grep -HEr '^\[.+\]' -r /etc/yum.repos.d/
  register: repo_grep_results
  failed_when: repo_grep_results.rc not in [0, 1]
  changed_when: false
  tags:
  - DISA-STIG-RHEL-08-010370
  - enable_gpgcheck_for_all_repositories
  - enable_strategy
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed

- name: 'Ensure gpgcheck Is Enabled for All Package Repositories: Set gpgcheck=1 for
    each yum repo'
  community.general.ini_file:
    path: '{{ item[0] }}'
    section: '{{ item[1] }}'
    option: gpgcheck
    value: '1'
    no_extra_spaces: true
  loop: '{{ repo_grep_results.stdout | regex_findall( ''(.+\.repo):\[(.+)\]\n?'' )
    if repo_grep_results is not skipped else [] }}'
  when: repo_grep_results is not skipped
  tags:
  - DISA-STIG-RHEL-08-010370
  - enable_gpgcheck_for_all_repositories
  - enable_strategy
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-enable_gpgcheck_for_all_repositories:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-enable_gpgcheck_for_all_repositories_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ensure_almalinux_gpgkey_installed" selected="false" severity="high">
              <xccdf-1.2:title>Ensure AlmaLinux GPG Key Installed</xccdf-1.2:title>
              <xccdf-1.2:description>To ensure the system can cryptographically verify base software packages
come from AlmaLinux (and to connect to the AlmaLinux repos to receive them),
the AlmaLinux GPG key must properly be installed. To install the AlmaLinux GPG
key, run:
<html:pre>$ sudo rpm --import https://repo.almalinux.org/almalinux/RPM-GPG-KEY-AlmaLinux</html:pre>

If the system is not connected to the Internet, then
install the AlmaLinux GPG key from trusted media such as the AlmaLinux
installation CD-ROM or DVD. Assuming the disc is mounted in
<html:code>/media/cdrom</html:code>, use the following command as the root user to import
it into the keyring:
<html:pre>$ sudo rpm --import /media/cdrom/RPM-GPG-KEY-AlmaLinux</html:pre>

Alternatively, the key may be pre-loaded during the AlmaLinux installation. In
such cases, the key can be installed by running the following command:
<html:pre>sudo rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-AlmaLinux</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI06.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(c)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(c)(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_TUD_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_TUD_EXT.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000366-GPOS-00153</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R59</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1493</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">6.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.2.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010019</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-256973r1017373_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Changes to software components can have significant effects on the overall
security of the operating system. This requirement ensures the software has
not been tampered with and that it has been provided by a trusted vendor.
The AlmaLinux GPG key is necessary to cryptographically verify packages are
from AlmaLinux.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="ensure_almalinux_gpgkey_installed" system="urn:xccdf:fix:script:sh"># The two fingerprints below are retrieved from https://almalinux.org/security/
readonly ALMALINUX_RELEASE_FINGERPRINT="5E9B8F5617B5066CE92057C3488FCF7C3ABB34F8"
readonly ALMALINUX_AUXILIARY_FINGERPRINT="BC5EDDCADF502C077F1582882AE81E8ACED7258B"

# Location of the key we would like to import (once it's integrity verified)
readonly ALMALINUX_RELEASE_KEY="/etc/pki/rpm-gpg/RPM-GPG-KEY-AlmaLinux"

RPM_GPG_DIR_PERMS=$(stat -c %a "$(dirname "$ALMALINUX_RELEASE_KEY")")

# Verify /etc/pki/rpm-gpg directory permissions are safe
if [ "${RPM_GPG_DIR_PERMS}" -le "755" ]
then
  # If they are safe, try to obtain fingerprints from the key file
  # (to ensure there won't be e.g. CRC error).
  readarray -t GPG_OUT &lt; &lt;(gpg --show-keys --with-fingerprint --with-colons "$ALMALINUX_RELEASE_KEY" | grep -A1 "^pub" | grep "^fpr" | cut -d ":" -f 10)
  GPG_RESULT=$?
  # No CRC error, safe to proceed
  if [ "${GPG_RESULT}" -eq "0" ]
  then
    echo "${GPG_OUT[*]}" | grep -vE "${ALMALINUX_RELEASE_FINGERPRINT}|${ALMALINUX_AUXILIARY_FINGERPRINT}" || {
      # If $ALMALINUX_RELEASE_KEY file doesn't contain any keys with unknown fingerprint, import it
      rpm --import "${ALMALINUX_RELEASE_KEY}"
    }
  fi
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="medium" disruption="medium" id="ensure_almalinux_gpgkey_installed" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Read permission of GPG key directory
  ansible.builtin.stat:
    path: /etc/pki/rpm-gpg/
  register: gpg_key_directory_permission
  check_mode: false
  tags:
  - CJIS-5.10.4.1
  - DISA-STIG-RHEL-08-010019
  - NIST-800-171-3.4.8
  - NIST-800-53-CM-5(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SI-7
  - PCI-DSS-Req-6.2
  - PCI-DSSv4-6.3
  - PCI-DSSv4-6.3.3
  - ensure_almalinux_gpgkey_installed
  - high_severity
  - medium_complexity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy

- name: Read signatures in GPG key
  ansible.builtin.command: gpg --show-keys --with-fingerprint --with-colons "/etc/pki/rpm-gpg/RPM-GPG-KEY-AlmaLinux"
  changed_when: false
  register: gpg_fingerprints
  check_mode: false
  tags:
  - CJIS-5.10.4.1
  - DISA-STIG-RHEL-08-010019
  - NIST-800-171-3.4.8
  - NIST-800-53-CM-5(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SI-7
  - PCI-DSS-Req-6.2
  - PCI-DSSv4-6.3
  - PCI-DSSv4-6.3.3
  - ensure_almalinux_gpgkey_installed
  - high_severity
  - medium_complexity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy

- name: Set Fact - Installed GPG Fingerprints
  ansible.builtin.set_fact:
    gpg_installed_fingerprints: |-
      {{ gpg_fingerprints.stdout | regex_findall('^pub.*
      (?:^fpr[:]*)([0-9A-Fa-f]*)', '\1') | list }}
  tags:
  - CJIS-5.10.4.1
  - DISA-STIG-RHEL-08-010019
  - NIST-800-171-3.4.8
  - NIST-800-53-CM-5(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SI-7
  - PCI-DSS-Req-6.2
  - PCI-DSSv4-6.3
  - PCI-DSSv4-6.3.3
  - ensure_almalinux_gpgkey_installed
  - high_severity
  - medium_complexity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy

- name: Set Fact - Valid fingerprints
  ansible.builtin.set_fact:
    gpg_valid_fingerprints:
    - 5E9B8F5617B5066CE92057C3488FCF7C3ABB34F8
    - BC5EDDCADF502C077F1582882AE81E8ACED7258B
  tags:
  - CJIS-5.10.4.1
  - DISA-STIG-RHEL-08-010019
  - NIST-800-171-3.4.8
  - NIST-800-53-CM-5(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SI-7
  - PCI-DSS-Req-6.2
  - PCI-DSSv4-6.3
  - PCI-DSSv4-6.3.3
  - ensure_almalinux_gpgkey_installed
  - high_severity
  - medium_complexity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy

- name: Import AlmaLinux GPG key
  ansible.builtin.rpm_key:
    state: present
    key: /etc/pki/rpm-gpg/RPM-GPG-KEY-AlmaLinux
  when:
  - gpg_key_directory_permission.stat.mode &lt;= '0755'
  - (gpg_installed_fingerprints | difference(gpg_valid_fingerprints)) | length ==
    0
  - gpg_installed_fingerprints | length &gt; 0
  - ansible_distribution == "AlmaLinux" and ansible_distribution_version == "8"
  tags:
  - CJIS-5.10.4.1
  - DISA-STIG-RHEL-08-010019
  - NIST-800-171-3.4.8
  - NIST-800-53-CM-5(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SI-7
  - PCI-DSS-Req-6.2
  - PCI-DSSv4-6.3
  - PCI-DSSv4-6.3.3
  - ensure_almalinux_gpgkey_installed
  - high_severity
  - medium_complexity
  - medium_disruption
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ensure_almalinux_gpgkey_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ensure_almalinux_gpgkey_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ensure_epel_repos_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure EPEL Repository is Disabled</xccdf-1.2:title>
              <xccdf-1.2:description>The system must not have the EPEL (Extra Packages for Enterprise Linux) repository enabled.
EPEL provides additional packages that are not part of the official RHEL distribution and
may not meet enterprise security requirements.

Check if any repository files in <html:code>/etc/yum.repos.d/</html:code> contain enabled EPEL repositories
by running:
<html:pre>$ grep -r "^\[.*epel.*\]" /etc/yum.repos.d/</html:pre>

If EPEL repositories are found, ensure they are disabled by setting <html:code>enabled=0</html:code> in
the repository configuration file.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040010</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230492r1134888_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The EPEL repository is not officially supported by Red Hat and may contain packages that have
not been vetted for security in an enterprise environment. Using unsupported repositories can
introduce vulnerabilities, compatibility issues, or packages that do not meet DoD security
requirements. Only packages from authorized repositories should be installed to maintain
system integrity and security.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="ensure_epel_repos_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# Ensure dnf-plugins-core is available for dnf config-manager
if ! command -v dnf &amp;&gt; /dev/null; then
    # System uses yum instead of dnf
    if command -v yum-config-manager &amp;&gt; /dev/null; then
        CONFIG_MANAGER="yum-config-manager"
    else
        echo "Neither dnf nor yum-config-manager found, cannot disable repositories" &gt;&amp;2
        exit 1
    fi
else
    # System uses dnf
    if ! command -v dnf config-manager &amp;&gt; /dev/null 2&gt;&amp;1; then
        dnf install -y dnf-plugins-core
    fi
    CONFIG_MANAGER="dnf config-manager"
fi

# Find all EPEL repository IDs by name pattern
for repo_file in /etc/yum.repos.d/*.repo; do
    [ -f "$repo_file" ] || continue

    # Extract repository IDs that contain "epel" (case-insensitive)
    while IFS= read -r repo_id; do
        $CONFIG_MANAGER --set-disabled "$repo_id"
    done &lt; &lt;(grep -ioP '^\[\K[^\]]*epel[^\]]*(?=\])' "$repo_file")
done
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="ensure_epel_repos_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Ensure dnf-plugins-core is installed
  package:
    name: dnf-plugins-core
    state: present
  when: ansible_pkg_mgr == "dnf"
  tags:
  - DISA-STIG-RHEL-08-040010
  - disable_strategy
  - ensure_epel_repos_disabled
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find all repository files
  find:
    paths: /etc/yum.repos.d/
    patterns: '*.repo'
  register: repo_files
  tags:
  - DISA-STIG-RHEL-08-040010
  - disable_strategy
  - ensure_epel_repos_disabled
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find EPEL repository IDs by name
  shell: |
    set -o pipefail
    # Find repository IDs by name (case-insensitive)
    grep -ioP '^\[\K[^\]]*epel[^\]]*(?=\])' "{{ item.path }}" || true
  register: epel_repo_ids
  loop: '{{ repo_files.files }}'
  changed_when: false
  when: repo_files.files is defined
  tags:
  - DISA-STIG-RHEL-08-040010
  - disable_strategy
  - ensure_epel_repos_disabled
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Disable EPEL repositories using dnf/yum config-manager
  command: '{% if ansible_pkg_mgr == "dnf" %} dnf config-manager --set-disabled {{
    item.1 }} {% else %} yum-config-manager --set-disabled {{ item.1 }} {% endif %}'
  loop: '{{ epel_repo_ids.results | subelements(''stdout_lines'', skip_missing=True)
    }}'
  when:
  - epel_repo_ids.results is defined
  - item.1 | length &gt; 0
  loop_control:
    label: '{{ item.1 }}'
  register: disable_result
  changed_when: disable_result.rc == 0
  failed_when: false
  tags:
  - DISA-STIG-RHEL-08-040010
  - disable_strategy
  - ensure_epel_repos_disabled
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ensure_epel_repos_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ensure_epel_repos_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated" selected="false" severity="high">
              <xccdf-1.2:title>Ensure gpgcheck Enabled In Main yum Configuration</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>gpgcheck</html:code> option controls whether
RPM packages' signatures are always checked prior to installation.
To configure yum to check package signatures before installing
them, ensure the following line appears in <html:code>/etc/yum.conf</html:code> in
the <html:code>[main]</html:code> section:
<html:pre>gpgcheck=1</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI06.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(c)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(c)(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SA-12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SA-12(10)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-11(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-11(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_TUD_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_TUD_EXT.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000366-GPOS-00153</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R59</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1493</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">6.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.2.1.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Changes to any software components can have significant effects on the
overall security of the operating system. This requirement ensures the
software has not been tampered with and that it has been provided by a
trusted vendor.
<html:br/>
Accordingly, patches, service packs, device drivers, or operating system
components must be signed with a certificate recognized and approved by the
organization.
<html:br/>Verifying the authenticity of the software prior to installation
validates the integrity of the patch or upgrade received from a vendor.
This ensures the software has not been tampered with and that it has been
provided by a trusted vendor. Self-signed certificates are disallowed by
this requirement. Certificates used to verify the software must be from an
approved Certificate Authority (CA).</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_yum"/>
              <xccdf-1.2:fix id="ensure_gpgcheck_globally_activated" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q yum; then

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^gpgcheck")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "1"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^gpgcheck\\&gt;" "/etc/yum.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^gpgcheck\\&gt;.*/$escaped_formatted_output/gi" "/etc/yum.conf"
else
    if [[ -s "/etc/yum.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/yum.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/yum.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/yum.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="ensure_gpgcheck_globally_activated" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.4.8
  - NIST-800-53-CM-11(a)
  - NIST-800-53-CM-11(b)
  - NIST-800-53-CM-5(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SA-12
  - NIST-800-53-SA-12(10)
  - NIST-800-53-SC-12
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SI-7
  - PCI-DSS-Req-6.2
  - PCI-DSSv4-6.3
  - PCI-DSSv4-6.3.3
  - configure_strategy
  - ensure_gpgcheck_globally_activated
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed

- name: Ensure GPG check is globally activated
  community.general.ini_file:
    dest: /etc/yum.conf
    section: main
    option: gpgcheck
    value: 1
    no_extra_spaces: true
    create: false
  when: '"yum" in ansible_facts.packages'
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.4.8
  - NIST-800-53-CM-11(a)
  - NIST-800-53-CM-11(b)
  - NIST-800-53-CM-5(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SA-12
  - NIST-800-53-SA-12(10)
  - NIST-800-53-SC-12
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SI-7
  - PCI-DSS-Req-6.2
  - PCI-DSSv4-6.3
  - PCI-DSSv4-6.3.3
  - configure_strategy
  - ensure_gpgcheck_globally_activated
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ensure_gpgcheck_globally_activated:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages" selected="false" severity="high">
              <xccdf-1.2:title>Ensure gpgcheck Enabled for Local Packages</xccdf-1.2:title>
              <xccdf-1.2:description><html:code>yum</html:code> should be configured to verify the signature(s) of local packages
prior to installation. To configure <html:code>yum</html:code> to verify signatures of local
packages, set the <html:code>localpkg_gpgcheck</html:code> to <html:code>1</html:code> in <html:code>/etc/yum.conf</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(c)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(c)(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-11(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-11(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SA-12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SA-12(10)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_TUD_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_TUD_EXT.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000366-GPOS-00153</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R59</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1493</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010371</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230265r1017378_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Changes to any software components can have significant effects to the overall security
of the operating system. This requirement ensures the software has not been tampered and
has been provided by a trusted vendor.
<html:br/><html:br/>
Accordingly, patches, service packs, device drivers, or operating system components must
be signed with a certificate recognized and approved by the organization.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_yum"/>
              <xccdf-1.2:fix id="ensure_gpgcheck_local_packages" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q yum; then

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^localpkg_gpgcheck")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "1"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^localpkg_gpgcheck\\&gt;" "/etc/yum.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^localpkg_gpgcheck\\&gt;.*/$escaped_formatted_output/gi" "/etc/yum.conf"
else
    if [[ -s "/etc/yum.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/yum.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/yum.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/yum.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="ensure_gpgcheck_local_packages" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010371
  - NIST-800-171-3.4.8
  - NIST-800-53-CM-11(a)
  - NIST-800-53-CM-11(b)
  - NIST-800-53-CM-5(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SA-12
  - NIST-800-53-SA-12(10)
  - ensure_gpgcheck_local_packages
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy

- name: Ensure GPG check Enabled for Local Packages (yum)
  block:

  - name: Check stats of yum
    ansible.builtin.stat:
      path: /etc/yum.conf
    register: pkg

  - name: Check if config file of yum is a symlink
    ansible.builtin.set_fact:
      pkg_config_file_symlink: '{{ pkg.stat.lnk_target if pkg.stat.lnk_target is match("^/.*")
        else "/etc/yum.conf" | dirname ~ "/" ~ pkg.stat.lnk_target }}'
    when: pkg.stat.lnk_target is defined

  - name: Ensure GPG check Enabled for Local Packages (yum)
    community.general.ini_file:
      dest: '{{ pkg_config_file_symlink |  default("/etc/yum.conf") }}'
      section: main
      option: localpkg_gpgcheck
      value: 1
      no_extra_spaces: true
      create: true
  when: '"yum" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010371
  - NIST-800-171-3.4.8
  - NIST-800-53-CM-11(a)
  - NIST-800-53-CM-11(b)
  - NIST-800-53-CM-5(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SA-12
  - NIST-800-53-SA-12(10)
  - ensure_gpgcheck_local_packages
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ensure_gpgcheck_local_packages:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ensure_gpgcheck_local_packages_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled" selected="false" severity="high">
              <xccdf-1.2:title>Ensure gpgcheck Enabled for All yum Package Repositories</xccdf-1.2:title>
              <xccdf-1.2:description>To ensure signature checking is not disabled for
any repos, remove any lines from files in <html:code>/etc/yum.repos.d</html:code> of the form:
<html:pre>gpgcheck=0</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI06.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(c)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(c)(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SA-12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SA-12(10)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-11(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-11(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_TUD_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_TUD_EXT.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000366-GPOS-00153</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R59</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1493</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">6.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.2.1.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Verifying the authenticity of the software prior to installation validates
the integrity of the patch or upgrade received from a vendor. This ensures
the software has not been tampered with and that it has been provided by a
trusted vendor. Self-signed certificates are disallowed by this
requirement. Certificates used to verify the software must be from an
approved Certificate Authority (CA)."</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="ensure_gpgcheck_never_disabled" system="urn:xccdf:fix:script:sh">
sed -i 's/gpgcheck\s*=.*/gpgcheck=1/g' /etc/yum.repos.d/*
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="ensure_gpgcheck_never_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Grep for yum repo section names
  ansible.builtin.shell: |
    set -o pipefail
    grep -HEr '^\[.+\]' -r /etc/yum.repos.d/
  register: repo_grep_results
  failed_when: repo_grep_results.rc not in [0, 1]
  changed_when: false
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.4.8
  - NIST-800-53-CM-11(a)
  - NIST-800-53-CM-11(b)
  - NIST-800-53-CM-5(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SA-12
  - NIST-800-53-SA-12(10)
  - NIST-800-53-SC-12
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SI-7
  - PCI-DSS-Req-6.2
  - PCI-DSSv4-6.3
  - PCI-DSSv4-6.3.3
  - enable_strategy
  - ensure_gpgcheck_never_disabled
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed

- name: Set gpgcheck=1 for each yum repo
  community.general.ini_file:
    path: '{{ item[0] }}'
    section: '{{ item[1] }}'
    option: gpgcheck
    value: '1'
    no_extra_spaces: true
  loop: '{{ repo_grep_results.stdout |regex_findall( ''(.+\.repo):\[(.+)\]\n?'' )
    if repo_grep_results is not skipped else [] }}'
  when: repo_grep_results is not skipped
  tags:
  - CJIS-5.10.4.1
  - NIST-800-171-3.4.8
  - NIST-800-53-CM-11(a)
  - NIST-800-53-CM-11(b)
  - NIST-800-53-CM-5(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SA-12
  - NIST-800-53-SA-12(10)
  - NIST-800-53-SC-12
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SI-7
  - PCI-DSS-Req-6.2
  - PCI-DSSv4-6.3
  - PCI-DSSv4-6.3.3
  - enable_strategy
  - ensure_gpgcheck_never_disabled
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ensure_gpgcheck_never_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ensure_gpgcheck_never_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_repo_metadata" selected="false" severity="high">
              <xccdf-1.2:title>Ensure gpgcheck Enabled for Repository Metadata</xccdf-1.2:title>
              <xccdf-1.2:description>Verify the operating system prevents the installation of patches,
service packs, device drivers, or operating system components of
local packages without verification of the repository metadata.
Check that <html:code>yum</html:code> verifies the repository
metadata prior to install with the following command.
This should be configured by setting <html:code>repo_gpgcheck</html:code> to <html:code>1</html:code>
in <html:code>/etc/yum.conf</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(c)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(c)(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SA-12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SA-12(10)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-11(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-11(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000366-GPOS-00153</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Changes to any software components can have significant effects to the
overall security of the operating system. This requirement ensures the
software has not been tampered and has been provided by a trusted vendor.
Accordingly, patches, service packs, device drivers, or operating system
components must be signed with a certificate recognized and approved by
the organization. Verifying the authenticity of the software prior to
installation validates the integrity of the patch or upgrade received from
a vendor. This ensures the software has not been tampered with and that it
has been provided by a trusted vendor. Self-signed certificates are
disallowed by this requirement. The operating system should not have
to verify the software again. NOTE: For U.S. Military systems, this
requirement does not mandate DoD certificates for this purpose; however,
the certificate used to verify the software must be from an approved
Certificate Authority.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_yum"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ensure_gpgcheck_repo_metadata:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ensure_gpgcheck_repo_metadata_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_security_patches_up_to_date" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Software Patches Installed</xccdf-1.2:title>
              <xccdf-1.2:description>
Run the following command to install updates:
<html:pre>$ sudo yum update</html:pre>
If the system is not configured to use repos, updates (in the form of RPM packages)
can be manually downloaded from the repos and installed using <html:code>rpm</html:code>.

<html:br/><html:br/>
NOTE: U.S. Defense systems are required to be patched within 30 days or sooner as local policy
dictates.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">The OVAL feed of AlmaLinux OS 8 is not a XML file, which may not be understood by all scanners.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">20</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-2(5)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-2(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.RA-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_MOF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R61</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">6.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010010</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230222r1017041_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Installing software updates is a fundamental mitigation against
the exploitation of publicly-known vulnerabilities. If the most
recent security patches and updates are not installed, unauthorized
users may take advantage of weaknesses in the unpatched software. The
lack of prompt attention to patching could result in a system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check multi-check="true" system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="oval-org.almalinux.alsa-8.xml.bz2"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_timer_dnf-automatic_enabled" selected="false" severity="medium">
              <xccdf-1.2:title>Enable dnf-automatic Timer</xccdf-1.2:title>
              <xccdf-1.2:description>
The <html:code>dnf-automatic</html:code> timer can be enabled with the following command:
<html:pre>$ sudo systemctl enable dnf-automatic.timer</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-2(5)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-2(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000191-GPOS-00080</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R61</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>dnf-automatic</html:code> is an alternative command line interface (CLI) to <html:code>dnf upgrade</html:code> with specific facilities to make it suitable to be executed automatically and regularly from systemd timers, cron jobs and similar.
The tool is controlled by <html:code>dnf-automatic.timer</html:code> SystemD timer.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_bootc_and_not_container"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="timer_dnf-automatic_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) ); then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'dnf-automatic.timer'
fi
"$SYSTEMCTL_EXEC" enable 'dnf-automatic.timer'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="timer_dnf-automatic_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-2(5)
  - NIST-800-53-SI-2(c)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - timer_dnf-automatic_enabled

- name: Enable timer dnf-automatic
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable timer dnf-automatic
    ansible.builtin.systemd:
      name: dnf-automatic.timer
      enabled: 'yes'
      state: started
    when:
    - '"dnf-automatic" in ansible_facts.packages'
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-2(5)
  - NIST-800-53-SI-2(c)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - timer_dnf-automatic_enabled
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-timer_dnf-automatic_enabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-timer_dnf-automatic_enabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_accounts">
          <xccdf-1.2:title>Account and Access Control</xccdf-1.2:title>
          <xccdf-1.2:description>In traditional Unix security, if an attacker gains
shell access to a certain login account, they can perform any action
or access any file to which that account has access. Therefore,
making it more difficult for unauthorized people to gain shell
access to accounts, particularly to privileged accounts, is a
necessary part of securing a system. This section introduces
mechanisms for restricting access to accounts under
AlmaLinux OS 8.</xccdf-1.2:description>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_authselect_profile" type="string">
            <xccdf-1.2:title>Authselect profile</xccdf-1.2:title>
            <xccdf-1.2:description>Specify the authselect profile to select</xccdf-1.2:description>
            <xccdf-1.2:value selector="local">local</xccdf-1.2:value>
            <xccdf-1.2:value>minimal</xccdf-1.2:value>
            <xccdf-1.2:value selector="minimal">minimal</xccdf-1.2:value>
            <xccdf-1.2:value selector="sssd">sssd</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_enable_authselect" selected="false" severity="medium">
            <xccdf-1.2:title>Enable authselect</xccdf-1.2:title>
            <xccdf-1.2:description>Configure user authentication setup to use the <html:code>authselect</html:code> tool.
If authselect profile is selected, the rule will enable the <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_authselect_profile" use="legacy"/> profile.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">If the <html:code>sudo authselect select</html:code> command returns an error informing that the chosen
profile cannot be selected, it is probably because PAM files have already been modified by
the administrator. If this is the case, in order to not overwrite the desired changes made
by the administrator, the current PAM settings should be investigated before forcing the
selection of the chosen authselect profile.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_UAU.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_AFL.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R31</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">enable_authselect</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">needed_rules</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Authselect is a successor to authconfig.
It is a tool to select system authentication and identity sources from a list of supported
profiles instead of letting the administrator manually build the PAM stack.

That way, it avoids potential breakage of configuration, as it ships several tested profiles
that are well tested and supported to solve different use-cases.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix id="enable_authselect" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_authselect_profile='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_authselect_profile" use="legacy"/>'


authselect current

if test "$?" -ne 0; then
    if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; }; then
        authselect select --force "$var_authselect_profile"
    else
        authselect select "$var_authselect_profile"
    fi

    if test "$?" -ne 0; then
        if rpm --quiet --verify pam; then
            authselect select --force "$var_authselect_profile"
        else
	        echo "authselect is not used but files from the 'pam' package have been altered, so the authselect configuration won't be forced." &gt;&amp;2
        fi
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="enable_authselect" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-needed_rules
  - NIST-800-53-AC-3
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - configure_strategy
  - enable_authselect
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
- name: XCCDF Value var_authselect_profile # promote to variable
  set_fact:
    var_authselect_profile: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_authselect_profile" use="legacy"/>
  tags:
    - always

- name: Enable authselect - Check Current authselect Profile
  ansible.builtin.command:
    cmd: authselect current
  register: result_authselect_current
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-needed_rules
  - NIST-800-53-AC-3
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - configure_strategy
  - enable_authselect
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Enable authselect - Try to Select an authselect Profile
  ansible.builtin.command:
    cmd: authselect select "{{ var_authselect_profile }}"
  register: result_authselect_select
  changed_when: result_authselect_select.rc == 0
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - result_authselect_current.rc != 0
  tags:
  - DISA-STIG-needed_rules
  - NIST-800-53-AC-3
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - configure_strategy
  - enable_authselect
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Enable authselect - Verify If pam Has Been Altered
  ansible.builtin.command:
    cmd: rpm -qV pam
  register: result_altered_authselect
  changed_when: false
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - result_authselect_select is not skipped
  - result_authselect_select.rc != 0
  tags:
  - DISA-STIG-needed_rules
  - NIST-800-53-AC-3
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - configure_strategy
  - enable_authselect
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Enable authselect - Informative Message Based on authselect Integrity Check
  ansible.builtin.assert:
    that:
    - result_authselect_current.rc == 0 or result_altered_authselect is skipped or
      result_altered_authselect.rc == 0
    fail_msg:
    - authselect is not used but files from the 'pam' package have been altered, so
      the authselect configuration won't be forced.
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-needed_rules
  - NIST-800-53-AC-3
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - configure_strategy
  - enable_authselect
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Enable authselect - Force authselect Profile Selection
  ansible.builtin.command:
    cmd: authselect select --force "{{ var_authselect_profile }}"
  when:
  - '"kernel" in ansible_facts.packages'
  - result_authselect_current.rc != 0
  - result_authselect_select.rc != 0
  - result_altered_authselect.rc == 0
  tags:
  - DISA-STIG-needed_rules
  - NIST-800-53-AC-3
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - configure_strategy
  - enable_authselect
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-enable_authselect:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-enable_authselect_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_accounts-banners">
            <xccdf-1.2:title>Warning Banners for System Accesses</xccdf-1.2:title>
            <xccdf-1.2:description>Each system should expose as little information about
itself as possible.
<html:br/><html:br/>
System banners, which are typically displayed just before a
login prompt, give out information about the service or the host's
operating system. This might include the distribution name and the
system kernel version, and the particular version of a network
service. This information can assist intruders in gaining access to
the system as it can reveal whether the system is running
vulnerable software. Most network services can be configured to
limit what information is displayed.
<html:br/><html:br/>
Many organizations implement security policies that require a
system banner provide notice of the system's ownership, provide
warning to unauthorized users, and remind authorized users of their
consent to monitoring.</xccdf-1.2:description>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_cis_banner_text" interactive="true" type="string">
              <xccdf-1.2:title>CIS Login Banner Verbiage</xccdf-1.2:title>
              <xccdf-1.2:description>Enter an appropriate login banner for your organization according to the local policy.</xccdf-1.2:description>
              <xccdf-1.2:value>Authorized users only. All activity may be monitored and reported.</xccdf-1.2:value>
              <xccdf-1.2:value selector="cis">Authorized users only. All activity may be monitored and reported.</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_dconf_login_banner_contents" interactive="true" type="string">
              <xccdf-1.2:title>Login Banner Verbiage</xccdf-1.2:title>
              <xccdf-1.2:description>Enter an appropriate login banner text for your organization. This variable is used only in remediations. In OVAL checks a regular expression specified in the login_banner_text variable is used instead. Using a regular expression is needed because some profiles (eg. STIG) allow multiple different banners.</xccdf-1.2:description>
              <xccdf-1.2:value>Authorized users only. All activity may be monitored and reported.</xccdf-1.2:value>
              <xccdf-1.2:value selector="cis_default">Authorized uses only. All activity may be monitored and reported.</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_default">You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions:\n-The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations.\n-At any time, the USG may inspect and seize data stored on this IS.\n-Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose.\n-This IS includes security measures (e.g., authentication and access controls) to protect USG interests--not for your personal benefit or privacy.\n-Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details.</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_short">I've read &amp; consent to terms in IS user agreem't.</xccdf-1.2:value>
              <xccdf-1.2:value selector="dss_odaa_default">Use of this or any other DoD interest computer system constitutes consent to monitoring at all times. This is a DoD interest computer system. All DoD interest computer systems and related equipment are intended for the communication, transmission, processing, and storage of official U.S. Government or other authorized information only. All DoD interest computer systems are subject to monitoring at all times to ensure proper functioning of equipment and systems including security devices and systems, to prevent unauthorized use and violations of statutes and security regulations, to deter criminal activity, and for other similar purposes. Any user of a DoD interest computer system should be aware that any information placed in the system is subject to monitoring and is not subject to any expectation of privacy. If monitoring of this or any other DoD interest computer system reveals possible evidence of violation of criminal statutes, this evidence and any other related information, including identification information about the user, may be provided to law enforcement officials. If monitoring of this or any other DoD interest computer systems reveals violations of security regulations or unauthorized use, employees who violate security regulations or make unauthorized use of DoD interest computer systems are subject to appropriate disciplinary action. Use of this or any other DoD interest computer system constitutes consent to monitoring at all times.</xccdf-1.2:value>
              <xccdf-1.2:value selector="usgcb_default">-- WARNING -- This system is for the use of authorized users only. Individuals using this computer system without authority or in excess of their authority are subject to having all their activities on this system monitored and recorded by system personnel. Anyone using this system expressly consents to such monitoring and is advised that if such monitoring reveals possible evidence of criminal activity system personal may provide the evidence of such monitoring to law enforcement officials.</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_dconf_login_banner_text" interactive="true" type="string">
              <xccdf-1.2:title>Dconf GDM Login Banner Verbiage Regular Expression</xccdf-1.2:title>
              <xccdf-1.2:description>Enter an appropriate login banner regular expression for your organization. Using a regular expression is needed because some profiles (eg. STIG) allow multiple different banners. This regular expression is used only in OVAL checks. In remediations the login_banner_contents variable is used instead. For information about how to generate banner regular expression for your tailoring files, see: https://complianceascode.readthedocs.io/en/latest/manual/developer/05_tools_and_utilities.html#generating-login-banner-regular-expressions</xccdf-1.2:description>
              <xccdf-1.2:value selector="cis_banners">^(Authorized[\s\n]+uses[\s\n]+only\.[\s\n]+All[\s\n]+activity[\s\n]+may[\s\n]+be[\s\n]+monitored[\s\n]+and[\s\n]+reported\.|^(?!.*(\\|fedora|rhel|sle|ubuntu)).*)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="cis_default">^Authorized[\s\n]+uses[\s\n]+only\.[\s\n]+All[\s\n]+activity[\s\n]+may[\s\n]+be[\s\n]+monitored[\s\n]+and[\s\n]+reported\.$</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_banners">^(You[\s\n]+are[\s\n]+accessing[\s\n]+a[\s\n]+U\.S\.[\s\n]+Government[\s\n]+\(USG\)[\s\n]+Information[\s\n]+System[\s\n]+\(IS\)[\s\n]+that[\s\n]+is[\s\n]+provided[\s\n]+for[\s\n]+USG\-authorized[\s\n]+use[\s\n]+only\.[\s\n]+By[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+\(which[\s\n]+includes[\s\n]+any[\s\n]+device[\s\n]+attached[\s\n]+to[\s\n]+this[\s\n]+IS\),[\s\n]+you[\s\n]+consent[\s\n]+to[\s\n]+the[\s\n]+following[\s\n]+conditions\:(?:[\n]+|(?:\\n)+)\-The[\s\n]+USG[\s\n]+routinely[\s\n]+intercepts[\s\n]+and[\s\n]+monitors[\s\n]+communications[\s\n]+on[\s\n]+this[\s\n]+IS[\s\n]+for[\s\n]+purposes[\s\n]+including,[\s\n]+but[\s\n]+not[\s\n]+limited[\s\n]+to,[\s\n]+penetration[\s\n]+testing,[\s\n]+COMSEC[\s\n]+monitoring,[\s\n]+network[\s\n]+operations[\s\n]+and[\s\n]+defense,[\s\n]+personnel[\s\n]+misconduct[\s\n]+\(PM\),[\s\n]+law[\s\n]+enforcement[\s\n]+\(LE\),[\s\n]+and[\s\n]+counterintelligence[\s\n]+\(CI\)[\s\n]+investigations\.(?:[\n]+|(?:\\n)+)\-At[\s\n]+any[\s\n]+time,[\s\n]+the[\s\n]+USG[\s\n]+may[\s\n]+inspect[\s\n]+and[\s\n]+seize[\s\n]+data[\s\n]+stored[\s\n]+on[\s\n]+this[\s\n]+IS\.(?:[\n]+|(?:\\n)+)\-Communications[\s\n]+using,[\s\n]+or[\s\n]+data[\s\n]+stored[\s\n]+on,[\s\n]+this[\s\n]+IS[\s\n]+are[\s\n]+not[\s\n]+private,[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+routine[\s\n]+monitoring,[\s\n]+interception,[\s\n]+and[\s\n]+search,[\s\n]+and[\s\n]+may[\s\n]+be[\s\n]+disclosed[\s\n]+or[\s\n]+used[\s\n]+for[\s\n]+any[\s\n]+USG\-authorized[\s\n]+purpose\.(?:[\n]+|(?:\\n)+)\-This[\s\n]+IS[\s\n]+includes[\s\n]+security[\s\n]+measures[\s\n]+\(e\.g\.,[\s\n]+authentication[\s\n]+and[\s\n]+access[\s\n]+controls\)[\s\n]+to[\s\n]+protect[\s\n]+USG[\s\n]+interests\-\-not[\s\n]+for[\s\n]+your[\s\n]+personal[\s\n]+benefit[\s\n]+or[\s\n]+privacy\.(?:[\n]+|(?:\\n)+)\-Notwithstanding[\s\n]+the[\s\n]+above,[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+does[\s\n]+not[\s\n]+constitute[\s\n]+consent[\s\n]+to[\s\n]+PM,[\s\n]+LE[\s\n]+or[\s\n]+CI[\s\n]+investigative[\s\n]+searching[\s\n]+or[\s\n]+monitoring[\s\n]+of[\s\n]+the[\s\n]+content[\s\n]+of[\s\n]+privileged[\s\n]+communications,[\s\n]+or[\s\n]+work[\s\n]+product,[\s\n]+related[\s\n]+to[\s\n]+personal[\s\n]+representation[\s\n]+or[\s\n]+services[\s\n]+by[\s\n]+attorneys,[\s\n]+psychotherapists,[\s\n]+or[\s\n]+clergy,[\s\n]+and[\s\n]+their[\s\n]+assistants\.[\s\n]+Such[\s\n]+communications[\s\n]+and[\s\n]+work[\s\n]+product[\s\n]+are[\s\n]+private[\s\n]+and[\s\n]+confidential\.[\s\n]+See[\s\n]+User[\s\n]+Agreement[\s\n]+for[\s\n]+details\.|I've[\s\n]+read[\s\n]+\&amp;[\s\n]+consent[\s\n]+to[\s\n]+terms[\s\n]+in[\s\n]+IS[\s\n]+user[\s\n]+agreem't\.)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_default">^You[\s\n]+are[\s\n]+accessing[\s\n]+a[\s\n]+U\.S\.[\s\n]+Government[\s\n]+\(USG\)[\s\n]+Information[\s\n]+System[\s\n]+\(IS\)[\s\n]+that[\s\n]+is[\s\n]+provided[\s\n]+for[\s\n]+USG\-authorized[\s\n]+use[\s\n]+only\.[\s\n]+By[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+\(which[\s\n]+includes[\s\n]+any[\s\n]+device[\s\n]+attached[\s\n]+to[\s\n]+this[\s\n]+IS\),[\s\n]+you[\s\n]+consent[\s\n]+to[\s\n]+the[\s\n]+following[\s\n]+conditions\:(?:[\n]+|(?:\\n)+)\-The[\s\n]+USG[\s\n]+routinely[\s\n]+intercepts[\s\n]+and[\s\n]+monitors[\s\n]+communications[\s\n]+on[\s\n]+this[\s\n]+IS[\s\n]+for[\s\n]+purposes[\s\n]+including,[\s\n]+but[\s\n]+not[\s\n]+limited[\s\n]+to,[\s\n]+penetration[\s\n]+testing,[\s\n]+COMSEC[\s\n]+monitoring,[\s\n]+network[\s\n]+operations[\s\n]+and[\s\n]+defense,[\s\n]+personnel[\s\n]+misconduct[\s\n]+\(PM\),[\s\n]+law[\s\n]+enforcement[\s\n]+\(LE\),[\s\n]+and[\s\n]+counterintelligence[\s\n]+\(CI\)[\s\n]+investigations\.(?:[\n]+|(?:\\n)+)\-At[\s\n]+any[\s\n]+time,[\s\n]+the[\s\n]+USG[\s\n]+may[\s\n]+inspect[\s\n]+and[\s\n]+seize[\s\n]+data[\s\n]+stored[\s\n]+on[\s\n]+this[\s\n]+IS\.(?:[\n]+|(?:\\n)+)\-Communications[\s\n]+using,[\s\n]+or[\s\n]+data[\s\n]+stored[\s\n]+on,[\s\n]+this[\s\n]+IS[\s\n]+are[\s\n]+not[\s\n]+private,[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+routine[\s\n]+monitoring,[\s\n]+interception,[\s\n]+and[\s\n]+search,[\s\n]+and[\s\n]+may[\s\n]+be[\s\n]+disclosed[\s\n]+or[\s\n]+used[\s\n]+for[\s\n]+any[\s\n]+USG\-authorized[\s\n]+purpose\.(?:[\n]+|(?:\\n)+)\-This[\s\n]+IS[\s\n]+includes[\s\n]+security[\s\n]+measures[\s\n]+\(e\.g\.,[\s\n]+authentication[\s\n]+and[\s\n]+access[\s\n]+controls\)[\s\n]+to[\s\n]+protect[\s\n]+USG[\s\n]+interests\-\-not[\s\n]+for[\s\n]+your[\s\n]+personal[\s\n]+benefit[\s\n]+or[\s\n]+privacy\.(?:[\n]+|(?:\\n)+)\-Notwithstanding[\s\n]+the[\s\n]+above,[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+does[\s\n]+not[\s\n]+constitute[\s\n]+consent[\s\n]+to[\s\n]+PM,[\s\n]+LE[\s\n]+or[\s\n]+CI[\s\n]+investigative[\s\n]+searching[\s\n]+or[\s\n]+monitoring[\s\n]+of[\s\n]+the[\s\n]+content[\s\n]+of[\s\n]+privileged[\s\n]+communications,[\s\n]+or[\s\n]+work[\s\n]+product,[\s\n]+related[\s\n]+to[\s\n]+personal[\s\n]+representation[\s\n]+or[\s\n]+services[\s\n]+by[\s\n]+attorneys,[\s\n]+psychotherapists,[\s\n]+or[\s\n]+clergy,[\s\n]+and[\s\n]+their[\s\n]+assistants\.[\s\n]+Such[\s\n]+communications[\s\n]+and[\s\n]+work[\s\n]+product[\s\n]+are[\s\n]+private[\s\n]+and[\s\n]+confidential\.[\s\n]+See[\s\n]+User[\s\n]+Agreement[\s\n]+for[\s\n]+details\.$</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_short">^I've[\s\n]+read[\s\n]+\&amp;[\s\n]+consent[\s\n]+to[\s\n]+terms[\s\n]+in[\s\n]+IS[\s\n]+user[\s\n]+agreem't\.$</xccdf-1.2:value>
              <xccdf-1.2:value selector="dss_odaa_default">^Use[\s\n]+of[\s\n]+this[\s\n]+or[\s\n]+any[\s\n]+other[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system[\s\n]+constitutes[\s\n]+consent[\s\n]+to[\s\n]+monitoring[\s\n]+at[\s\n]+all[\s\n]+times\.[\s\n]+This[\s\n]+is[\s\n]+a[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system\.[\s\n]+All[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+systems[\s\n]+and[\s\n]+related[\s\n]+equipment[\s\n]+are[\s\n]+intended[\s\n]+for[\s\n]+the[\s\n]+communication,[\s\n]+transmission,[\s\n]+processing,[\s\n]+and[\s\n]+storage[\s\n]+of[\s\n]+official[\s\n]+U\.S\.[\s\n]+Government[\s\n]+or[\s\n]+other[\s\n]+authorized[\s\n]+information[\s\n]+only\.[\s\n]+All[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+systems[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+monitoring[\s\n]+at[\s\n]+all[\s\n]+times[\s\n]+to[\s\n]+ensure[\s\n]+proper[\s\n]+functioning[\s\n]+of[\s\n]+equipment[\s\n]+and[\s\n]+systems[\s\n]+including[\s\n]+security[\s\n]+devices[\s\n]+and[\s\n]+systems,[\s\n]+to[\s\n]+prevent[\s\n]+unauthorized[\s\n]+use[\s\n]+and[\s\n]+violations[\s\n]+of[\s\n]+statutes[\s\n]+and[\s\n]+security[\s\n]+regulations,[\s\n]+to[\s\n]+deter[\s\n]+criminal[\s\n]+activity,[\s\n]+and[\s\n]+for[\s\n]+other[\s\n]+similar[\s\n]+purposes\.[\s\n]+Any[\s\n]+user[\s\n]+of[\s\n]+a[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system[\s\n]+should[\s\n]+be[\s\n]+aware[\s\n]+that[\s\n]+any[\s\n]+information[\s\n]+placed[\s\n]+in[\s\n]+the[\s\n]+system[\s\n]+is[\s\n]+subject[\s\n]+to[\s\n]+monitoring[\s\n]+and[\s\n]+is[\s\n]+not[\s\n]+subject[\s\n]+to[\s\n]+any[\s\n]+expectation[\s\n]+of[\s\n]+privacy\.[\s\n]+If[\s\n]+monitoring[\s\n]+of[\s\n]+this[\s\n]+or[\s\n]+any[\s\n]+other[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system[\s\n]+reveals[\s\n]+possible[\s\n]+evidence[\s\n]+of[\s\n]+violation[\s\n]+of[\s\n]+criminal[\s\n]+statutes,[\s\n]+this[\s\n]+evidence[\s\n]+and[\s\n]+any[\s\n]+other[\s\n]+related[\s\n]+information,[\s\n]+including[\s\n]+identification[\s\n]+information[\s\n]+about[\s\n]+the[\s\n]+user,[\s\n]+may[\s\n]+be[\s\n]+provided[\s\n]+to[\s\n]+law[\s\n]+enforcement[\s\n]+officials\.[\s\n]+If[\s\n]+monitoring[\s\n]+of[\s\n]+this[\s\n]+or[\s\n]+any[\s\n]+other[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+systems[\s\n]+reveals[\s\n]+violations[\s\n]+of[\s\n]+security[\s\n]+regulations[\s\n]+or[\s\n]+unauthorized[\s\n]+use,[\s\n]+employees[\s\n]+who[\s\n]+violate[\s\n]+security[\s\n]+regulations[\s\n]+or[\s\n]+make[\s\n]+unauthorized[\s\n]+use[\s\n]+of[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+systems[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+appropriate[\s\n]+disciplinary[\s\n]+action\.[\s\n]+Use[\s\n]+of[\s\n]+this[\s\n]+or[\s\n]+any[\s\n]+other[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system[\s\n]+constitutes[\s\n]+consent[\s\n]+to[\s\n]+monitoring[\s\n]+at[\s\n]+all[\s\n]+times\.$</xccdf-1.2:value>
              <xccdf-1.2:value selector="usgcb_default">^\-\-[\s\n]+WARNING[\s\n]+\-\-[\s\n]+This[\s\n]+system[\s\n]+is[\s\n]+for[\s\n]+the[\s\n]+use[\s\n]+of[\s\n]+authorized[\s\n]+users[\s\n]+only\.[\s\n]+Individuals[\s\n]+using[\s\n]+this[\s\n]+computer[\s\n]+system[\s\n]+without[\s\n]+authority[\s\n]+or[\s\n]+in[\s\n]+excess[\s\n]+of[\s\n]+their[\s\n]+authority[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+having[\s\n]+all[\s\n]+their[\s\n]+activities[\s\n]+on[\s\n]+this[\s\n]+system[\s\n]+monitored[\s\n]+and[\s\n]+recorded[\s\n]+by[\s\n]+system[\s\n]+personnel\.[\s\n]+Anyone[\s\n]+using[\s\n]+this[\s\n]+system[\s\n]+expressly[\s\n]+consents[\s\n]+to[\s\n]+such[\s\n]+monitoring[\s\n]+and[\s\n]+is[\s\n]+advised[\s\n]+that[\s\n]+if[\s\n]+such[\s\n]+monitoring[\s\n]+reveals[\s\n]+possible[\s\n]+evidence[\s\n]+of[\s\n]+criminal[\s\n]+activity[\s\n]+system[\s\n]+personal[\s\n]+may[\s\n]+provide[\s\n]+the[\s\n]+evidence[\s\n]+of[\s\n]+such[\s\n]+monitoring[\s\n]+to[\s\n]+law[\s\n]+enforcement[\s\n]+officials\.$</xccdf-1.2:value>
              <xccdf-1.2:value>^Authorized[\s\n]+users[\s\n]+only\.[\s\n]+All[\s\n]+activity[\s\n]+may[\s\n]+be[\s\n]+monitored[\s\n]+and[\s\n]+reported\.$</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_login_banner_contents" interactive="true" type="string">
              <xccdf-1.2:title>Login Banner Verbiage</xccdf-1.2:title>
              <xccdf-1.2:description>Enter an appropriate login banner text for your organization. This variable is used only in remediations. In OVAL checks a regular expression specified in the login_banner_text variable is used instead. Using a regular expression is needed because some profiles (eg. STIG) allow multiple different banners.</xccdf-1.2:description>
              <xccdf-1.2:value>Authorized users only. All activity may be monitored and reported.</xccdf-1.2:value>
              <xccdf-1.2:value selector="cis_default">Authorized users only. All activity may be monitored and reported.</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_default">You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only. By using this IS (which includes any\ndevice attached to this IS), you consent to the following conditions:\n\n-The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n-At any time, the USG may inspect and seize data stored on this IS.\n\n-Communications using, or data stored on, this IS are not private, are subject\nto routine monitoring, interception, and search, and may be disclosed or used\nfor any USG-authorized purpose.\n\n-This IS includes security measures (e.g., authentication and access controls)\nto protect USG interests--not for your personal benefit or privacy.\n\n-Notwithstanding the above, using this IS does not constitute consent to PM, LE\nor CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_short">I've read &amp; consent to terms in IS user agreem't.</xccdf-1.2:value>
              <xccdf-1.2:value selector="dss_odaa_default">Use of this or any other DoD interest computer system constitutes consent to\nmonitoring at all times. This is a DoD interest computer system. All DoD\ninterest computer systems and related equipment are intended for the\ncommunication, transmission, processing, and storage of official U.S.\nGovernment or other authorized information only. All DoD interest computer\nsystems are subject to monitoring at all times to ensure proper functioning of\nequipment and systems including security devices and systems, to prevent\nunauthorized use and violations of statutes and security regulations, to deter\ncriminal activity, and for other similar purposes. Any user of a DoD interest\ncomputer system should be aware that any information placed in the system is\nsubject to monitoring and is not subject to any expectation of privacy. If\nmonitoring of this or any other DoD interest computer system reveals possible\nevidence of violation of criminal statutes, this evidence and any other related\ninformation, including identification information about the user, may be\nprovided to law enforcement officials. If monitoring of this or any other DoD\ninterest computer systems reveals violations of security regulations or\nunauthorized use, employees who violate security regulations or make\nunauthorized use of DoD interest computer systems are subject to appropriate\ndisciplinary action. Use of this or any other DoD interest computer system\nconstitutes consent to monitoring at all times.</xccdf-1.2:value>
              <xccdf-1.2:value selector="usgcb_default">-- WARNING -- This system is for the use of authorized users only. Individuals\nusing this computer system without authority or in excess of their authority\nare subject to having all their activities on this system monitored and\nrecorded by system personnel. Anyone using this system expressly consents to\nsuch monitoring and is advised that if such monitoring reveals possible\nevidence of criminal activity system personal may provide the evidence of such\nmonitoring to law enforcement officials.</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_login_banner_text" interactive="true" type="string">
              <xccdf-1.2:title>Login Banner Verbiage Regular Expression</xccdf-1.2:title>
              <xccdf-1.2:description>Enter an appropriate login banner regular expression for your organization. Using a regular expression is needed because some profiles (eg. STIG) allow multiple different banners. This regular expression is used only in OVAL checks. In remediations the login_banner_contents variable is used instead. For information about how to generate banner regular expression for your tailoring files, see: https://complianceascode.readthedocs.io/en/latest/manual/developer/05_tools_and_utilities.html#generating-login-banner-regular-expressions</xccdf-1.2:description>
              <xccdf-1.2:value selector="cis_banners">^(Authorized[\s\n]+users[\s\n]+only\.[\s\n]+All[\s\n]+activity[\s\n]+may[\s\n]+be[\s\n]+monitored[\s\n]+and[\s\n]+reported\.|^(?!.*(\\|fedora|rhel|sle|ubuntu)).*)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="cis_default">^Authorized[\s\n]+users[\s\n]+only\.[\s\n]+All[\s\n]+activity[\s\n]+may[\s\n]+be[\s\n]+monitored[\s\n]+and[\s\n]+reported\.$</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_banners">^(You[\s\n]+are[\s\n]+accessing[\s\n]+a[\s\n]+U\.S\.[\s\n]+Government[\s\n]+\(USG\)[\s\n]+Information[\s\n]+System[\s\n]+\(IS\)[\s\n]+that[\s\n]+is[\s\n]+provided[\s\n]+for[\s\n]+USG\-authorized[\s\n]+use[\s\n]+only\.[\s\n]+By[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+\(which[\s\n]+includes[\s\n]+any[\s\n]+device[\s\n]+attached[\s\n]+to[\s\n]+this[\s\n]+IS\),[\s\n]+you[\s\n]+consent[\s\n]+to[\s\n]+the[\s\n]+following[\s\n]+conditions\:(?:[\n]+|(?:\\n)+)\-The[\s\n]+USG[\s\n]+routinely[\s\n]+intercepts[\s\n]+and[\s\n]+monitors[\s\n]+communications[\s\n]+on[\s\n]+this[\s\n]+IS[\s\n]+for[\s\n]+purposes[\s\n]+including,[\s\n]+but[\s\n]+not[\s\n]+limited[\s\n]+to,[\s\n]+penetration[\s\n]+testing,[\s\n]+COMSEC[\s\n]+monitoring,[\s\n]+network[\s\n]+operations[\s\n]+and[\s\n]+defense,[\s\n]+personnel[\s\n]+misconduct[\s\n]+\(PM\),[\s\n]+law[\s\n]+enforcement[\s\n]+\(LE\),[\s\n]+and[\s\n]+counterintelligence[\s\n]+\(CI\)[\s\n]+investigations\.(?:[\n]+|(?:\\n)+)\-At[\s\n]+any[\s\n]+time,[\s\n]+the[\s\n]+USG[\s\n]+may[\s\n]+inspect[\s\n]+and[\s\n]+seize[\s\n]+data[\s\n]+stored[\s\n]+on[\s\n]+this[\s\n]+IS\.(?:[\n]+|(?:\\n)+)\-Communications[\s\n]+using,[\s\n]+or[\s\n]+data[\s\n]+stored[\s\n]+on,[\s\n]+this[\s\n]+IS[\s\n]+are[\s\n]+not[\s\n]+private,[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+routine[\s\n]+monitoring,[\s\n]+interception,[\s\n]+and[\s\n]+search,[\s\n]+and[\s\n]+may[\s\n]+be[\s\n]+disclosed[\s\n]+or[\s\n]+used[\s\n]+for[\s\n]+any[\s\n]+USG\-authorized[\s\n]+purpose\.(?:[\n]+|(?:\\n)+)\-This[\s\n]+IS[\s\n]+includes[\s\n]+security[\s\n]+measures[\s\n]+\(e\.g\.,[\s\n]+authentication[\s\n]+and[\s\n]+access[\s\n]+controls\)[\s\n]+to[\s\n]+protect[\s\n]+USG[\s\n]+interests\-\-not[\s\n]+for[\s\n]+your[\s\n]+personal[\s\n]+benefit[\s\n]+or[\s\n]+privacy\.(?:[\n]+|(?:\\n)+)\-Notwithstanding[\s\n]+the[\s\n]+above,[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+does[\s\n]+not[\s\n]+constitute[\s\n]+consent[\s\n]+to[\s\n]+PM,[\s\n]+LE[\s\n]+or[\s\n]+CI[\s\n]+investigative[\s\n]+searching[\s\n]+or[\s\n]+monitoring[\s\n]+of[\s\n]+the[\s\n]+content[\s\n]+of[\s\n]+privileged[\s\n]+communications,[\s\n]+or[\s\n]+work[\s\n]+product,[\s\n]+related[\s\n]+to[\s\n]+personal[\s\n]+representation[\s\n]+or[\s\n]+services[\s\n]+by[\s\n]+attorneys,[\s\n]+psychotherapists,[\s\n]+or[\s\n]+clergy,[\s\n]+and[\s\n]+their[\s\n]+assistants\.[\s\n]+Such[\s\n]+communications[\s\n]+and[\s\n]+work[\s\n]+product[\s\n]+are[\s\n]+private[\s\n]+and[\s\n]+confidential\.[\s\n]+See[\s\n]+User[\s\n]+Agreement[\s\n]+for[\s\n]+details\.|I've[\s\n]+read[\s\n]+\&amp;[\s\n]+consent[\s\n]+to[\s\n]+terms[\s\n]+in[\s\n]+IS[\s\n]+user[\s\n]+agreem't\.)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_default">^You[\s\n]+are[\s\n]+accessing[\s\n]+a[\s\n]+U\.S\.[\s\n]+Government[\s\n]+\(USG\)[\s\n]+Information[\s\n]+System[\s\n]+\(IS\)[\s\n]+that[\s\n]+is[\s\n]+provided[\s\n]+for[\s\n]+USG\-authorized[\s\n]+use[\s\n]+only\.[\s\n]+By[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+\(which[\s\n]+includes[\s\n]+any[\s\n]+device[\s\n]+attached[\s\n]+to[\s\n]+this[\s\n]+IS\),[\s\n]+you[\s\n]+consent[\s\n]+to[\s\n]+the[\s\n]+following[\s\n]+conditions\:(?:[\n]+|(?:\\n)+)\-The[\s\n]+USG[\s\n]+routinely[\s\n]+intercepts[\s\n]+and[\s\n]+monitors[\s\n]+communications[\s\n]+on[\s\n]+this[\s\n]+IS[\s\n]+for[\s\n]+purposes[\s\n]+including,[\s\n]+but[\s\n]+not[\s\n]+limited[\s\n]+to,[\s\n]+penetration[\s\n]+testing,[\s\n]+COMSEC[\s\n]+monitoring,[\s\n]+network[\s\n]+operations[\s\n]+and[\s\n]+defense,[\s\n]+personnel[\s\n]+misconduct[\s\n]+\(PM\),[\s\n]+law[\s\n]+enforcement[\s\n]+\(LE\),[\s\n]+and[\s\n]+counterintelligence[\s\n]+\(CI\)[\s\n]+investigations\.(?:[\n]+|(?:\\n)+)\-At[\s\n]+any[\s\n]+time,[\s\n]+the[\s\n]+USG[\s\n]+may[\s\n]+inspect[\s\n]+and[\s\n]+seize[\s\n]+data[\s\n]+stored[\s\n]+on[\s\n]+this[\s\n]+IS\.(?:[\n]+|(?:\\n)+)\-Communications[\s\n]+using,[\s\n]+or[\s\n]+data[\s\n]+stored[\s\n]+on,[\s\n]+this[\s\n]+IS[\s\n]+are[\s\n]+not[\s\n]+private,[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+routine[\s\n]+monitoring,[\s\n]+interception,[\s\n]+and[\s\n]+search,[\s\n]+and[\s\n]+may[\s\n]+be[\s\n]+disclosed[\s\n]+or[\s\n]+used[\s\n]+for[\s\n]+any[\s\n]+USG\-authorized[\s\n]+purpose\.(?:[\n]+|(?:\\n)+)\-This[\s\n]+IS[\s\n]+includes[\s\n]+security[\s\n]+measures[\s\n]+\(e\.g\.,[\s\n]+authentication[\s\n]+and[\s\n]+access[\s\n]+controls\)[\s\n]+to[\s\n]+protect[\s\n]+USG[\s\n]+interests\-\-not[\s\n]+for[\s\n]+your[\s\n]+personal[\s\n]+benefit[\s\n]+or[\s\n]+privacy\.(?:[\n]+|(?:\\n)+)\-Notwithstanding[\s\n]+the[\s\n]+above,[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+does[\s\n]+not[\s\n]+constitute[\s\n]+consent[\s\n]+to[\s\n]+PM,[\s\n]+LE[\s\n]+or[\s\n]+CI[\s\n]+investigative[\s\n]+searching[\s\n]+or[\s\n]+monitoring[\s\n]+of[\s\n]+the[\s\n]+content[\s\n]+of[\s\n]+privileged[\s\n]+communications,[\s\n]+or[\s\n]+work[\s\n]+product,[\s\n]+related[\s\n]+to[\s\n]+personal[\s\n]+representation[\s\n]+or[\s\n]+services[\s\n]+by[\s\n]+attorneys,[\s\n]+psychotherapists,[\s\n]+or[\s\n]+clergy,[\s\n]+and[\s\n]+their[\s\n]+assistants\.[\s\n]+Such[\s\n]+communications[\s\n]+and[\s\n]+work[\s\n]+product[\s\n]+are[\s\n]+private[\s\n]+and[\s\n]+confidential\.[\s\n]+See[\s\n]+User[\s\n]+Agreement[\s\n]+for[\s\n]+details\.$</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_short">^I've[\s\n]+read[\s\n]+\&amp;[\s\n]+consent[\s\n]+to[\s\n]+terms[\s\n]+in[\s\n]+IS[\s\n]+user[\s\n]+agreem't\.$</xccdf-1.2:value>
              <xccdf-1.2:value selector="dss_odaa_default">^Use[\s\n]+of[\s\n]+this[\s\n]+or[\s\n]+any[\s\n]+other[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system[\s\n]+constitutes[\s\n]+consent[\s\n]+to[\s\n]+monitoring[\s\n]+at[\s\n]+all[\s\n]+times\.[\s\n]+This[\s\n]+is[\s\n]+a[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system\.[\s\n]+All[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+systems[\s\n]+and[\s\n]+related[\s\n]+equipment[\s\n]+are[\s\n]+intended[\s\n]+for[\s\n]+the[\s\n]+communication,[\s\n]+transmission,[\s\n]+processing,[\s\n]+and[\s\n]+storage[\s\n]+of[\s\n]+official[\s\n]+U\.S\.[\s\n]+Government[\s\n]+or[\s\n]+other[\s\n]+authorized[\s\n]+information[\s\n]+only\.[\s\n]+All[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+systems[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+monitoring[\s\n]+at[\s\n]+all[\s\n]+times[\s\n]+to[\s\n]+ensure[\s\n]+proper[\s\n]+functioning[\s\n]+of[\s\n]+equipment[\s\n]+and[\s\n]+systems[\s\n]+including[\s\n]+security[\s\n]+devices[\s\n]+and[\s\n]+systems,[\s\n]+to[\s\n]+prevent[\s\n]+unauthorized[\s\n]+use[\s\n]+and[\s\n]+violations[\s\n]+of[\s\n]+statutes[\s\n]+and[\s\n]+security[\s\n]+regulations,[\s\n]+to[\s\n]+deter[\s\n]+criminal[\s\n]+activity,[\s\n]+and[\s\n]+for[\s\n]+other[\s\n]+similar[\s\n]+purposes\.[\s\n]+Any[\s\n]+user[\s\n]+of[\s\n]+a[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system[\s\n]+should[\s\n]+be[\s\n]+aware[\s\n]+that[\s\n]+any[\s\n]+information[\s\n]+placed[\s\n]+in[\s\n]+the[\s\n]+system[\s\n]+is[\s\n]+subject[\s\n]+to[\s\n]+monitoring[\s\n]+and[\s\n]+is[\s\n]+not[\s\n]+subject[\s\n]+to[\s\n]+any[\s\n]+expectation[\s\n]+of[\s\n]+privacy\.[\s\n]+If[\s\n]+monitoring[\s\n]+of[\s\n]+this[\s\n]+or[\s\n]+any[\s\n]+other[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system[\s\n]+reveals[\s\n]+possible[\s\n]+evidence[\s\n]+of[\s\n]+violation[\s\n]+of[\s\n]+criminal[\s\n]+statutes,[\s\n]+this[\s\n]+evidence[\s\n]+and[\s\n]+any[\s\n]+other[\s\n]+related[\s\n]+information,[\s\n]+including[\s\n]+identification[\s\n]+information[\s\n]+about[\s\n]+the[\s\n]+user,[\s\n]+may[\s\n]+be[\s\n]+provided[\s\n]+to[\s\n]+law[\s\n]+enforcement[\s\n]+officials\.[\s\n]+If[\s\n]+monitoring[\s\n]+of[\s\n]+this[\s\n]+or[\s\n]+any[\s\n]+other[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+systems[\s\n]+reveals[\s\n]+violations[\s\n]+of[\s\n]+security[\s\n]+regulations[\s\n]+or[\s\n]+unauthorized[\s\n]+use,[\s\n]+employees[\s\n]+who[\s\n]+violate[\s\n]+security[\s\n]+regulations[\s\n]+or[\s\n]+make[\s\n]+unauthorized[\s\n]+use[\s\n]+of[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+systems[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+appropriate[\s\n]+disciplinary[\s\n]+action\.[\s\n]+Use[\s\n]+of[\s\n]+this[\s\n]+or[\s\n]+any[\s\n]+other[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system[\s\n]+constitutes[\s\n]+consent[\s\n]+to[\s\n]+monitoring[\s\n]+at[\s\n]+all[\s\n]+times\.$</xccdf-1.2:value>
              <xccdf-1.2:value selector="usgcb_default">^\-\-[\s\n]+WARNING[\s\n]+\-\-[\s\n]+This[\s\n]+system[\s\n]+is[\s\n]+for[\s\n]+the[\s\n]+use[\s\n]+of[\s\n]+authorized[\s\n]+users[\s\n]+only\.[\s\n]+Individuals[\s\n]+using[\s\n]+this[\s\n]+computer[\s\n]+system[\s\n]+without[\s\n]+authority[\s\n]+or[\s\n]+in[\s\n]+excess[\s\n]+of[\s\n]+their[\s\n]+authority[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+having[\s\n]+all[\s\n]+their[\s\n]+activities[\s\n]+on[\s\n]+this[\s\n]+system[\s\n]+monitored[\s\n]+and[\s\n]+recorded[\s\n]+by[\s\n]+system[\s\n]+personnel\.[\s\n]+Anyone[\s\n]+using[\s\n]+this[\s\n]+system[\s\n]+expressly[\s\n]+consents[\s\n]+to[\s\n]+such[\s\n]+monitoring[\s\n]+and[\s\n]+is[\s\n]+advised[\s\n]+that[\s\n]+if[\s\n]+such[\s\n]+monitoring[\s\n]+reveals[\s\n]+possible[\s\n]+evidence[\s\n]+of[\s\n]+criminal[\s\n]+activity[\s\n]+system[\s\n]+personal[\s\n]+may[\s\n]+provide[\s\n]+the[\s\n]+evidence[\s\n]+of[\s\n]+such[\s\n]+monitoring[\s\n]+to[\s\n]+law[\s\n]+enforcement[\s\n]+officials\.$</xccdf-1.2:value>
              <xccdf-1.2:value>^Authorized[\s\n]+users[\s\n]+only\.[\s\n]+All[\s\n]+activity[\s\n]+may[\s\n]+be[\s\n]+monitored[\s\n]+and[\s\n]+reported\.$</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_motd_banner_contents" interactive="true" type="string">
              <xccdf-1.2:title>MotD Banner Verbiage</xccdf-1.2:title>
              <xccdf-1.2:description>Enter an appropriate login banner text for your organization. This variable is used only in remediations. In OVAL checks a regular expression specified in the login_banner_text variable is used instead. Using a regular expression is needed because some profiles (eg. STIG) allow multiple different banners.</xccdf-1.2:description>
              <xccdf-1.2:value>Authorized users only. All activity may be monitored and reported.</xccdf-1.2:value>
              <xccdf-1.2:value selector="cis_default">Authorized users only. All activity may be monitored and reported.</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_default">You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only. By using this IS (which includes any\ndevice attached to this IS), you consent to the following conditions:\n\n-The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n-At any time, the USG may inspect and seize data stored on this IS.\n\n-Communications using, or data stored on, this IS are not private, are subject\nto routine monitoring, interception, and search, and may be disclosed or used\nfor any USG-authorized purpose.\n\n-This IS includes security measures (e.g., authentication and access controls)\nto protect USG interests--not for your personal benefit or privacy.\n\n-Notwithstanding the above, using this IS does not constitute consent to PM, LE\nor CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_short">I've read &amp; consent to terms in IS user agreem't.</xccdf-1.2:value>
              <xccdf-1.2:value selector="dss_odaa_default">Use of this or any other DoD interest computer system constitutes consent to\nmonitoring at all times. This is a DoD interest computer system. All DoD\ninterest computer systems and related equipment are intended for the\ncommunication, transmission, processing, and storage of official U.S.\nGovernment or other authorized information only. All DoD interest computer\nsystems are subject to monitoring at all times to ensure proper functioning of\nequipment and systems including security devices and systems, to prevent\nunauthorized use and violations of statutes and security regulations, to deter\ncriminal activity, and for other similar purposes. Any user of a DoD interest\ncomputer system should be aware that any information placed in the system is\nsubject to monitoring and is not subject to any expectation of privacy. If\nmonitoring of this or any other DoD interest computer system reveals possible\nevidence of violation of criminal statutes, this evidence and any other related\ninformation, including identification information about the user, may be\nprovided to law enforcement officials. If monitoring of this or any other DoD\ninterest computer systems reveals violations of security regulations or\nunauthorized use, employees who violate security regulations or make\nunauthorized use of DoD interest computer systems are subject to appropriate\ndisciplinary action. Use of this or any other DoD interest computer system\nconstitutes consent to monitoring at all times.</xccdf-1.2:value>
              <xccdf-1.2:value selector="usgcb_default">-- WARNING -- This system is for the use of authorized users only. Individuals\nusing this computer system without authority or in excess of their authority\nare subject to having all their activities on this system monitored and\nrecorded by system personnel. Anyone using this system expressly consents to\nsuch monitoring and is advised that if such monitoring reveals possible\nevidence of criminal activity system personal may provide the evidence of such\nmonitoring to law enforcement officials.</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_motd_banner_text" interactive="true" type="string">
              <xccdf-1.2:title>Motd Banner Verbiage Regular Expression</xccdf-1.2:title>
              <xccdf-1.2:description>Enter an appropriate login banner regular expression for your organization. Using a regular expression is needed because some profiles (eg. STIG) allow multiple different banners. This regular expression is used only in OVAL checks. In remediations the motd_banner_contents variable is used instead. For information about how to generate banner regular expression for your tailoring files, see: https://complianceascode.readthedocs.io/en/latest/manual/developer/05_tools_and_utilities.html#generating-login-banner-regular-expressions</xccdf-1.2:description>
              <xccdf-1.2:value selector="cis_banners">^(Authorized[\s\n]+users[\s\n]+only\.[\s\n]+All[\s\n]+activity[\s\n]+may[\s\n]+be[\s\n]+monitored[\s\n]+and[\s\n]+reported\.|^(?!.*(\\|fedora|rhel|sle|ubuntu)).*)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="cis_default">^Authorized[\s\n]+users[\s\n]+only\.[\s\n]+All[\s\n]+activity[\s\n]+may[\s\n]+be[\s\n]+monitored[\s\n]+and[\s\n]+reported\.$</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_banners">^(You[\s\n]+are[\s\n]+accessing[\s\n]+a[\s\n]+U\.S\.[\s\n]+Government[\s\n]+\(USG\)[\s\n]+Information[\s\n]+System[\s\n]+\(IS\)[\s\n]+that[\s\n]+is[\s\n]+provided[\s\n]+for[\s\n]+USG\-authorized[\s\n]+use[\s\n]+only\.[\s\n]+By[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+\(which[\s\n]+includes[\s\n]+any[\s\n]+device[\s\n]+attached[\s\n]+to[\s\n]+this[\s\n]+IS\),[\s\n]+you[\s\n]+consent[\s\n]+to[\s\n]+the[\s\n]+following[\s\n]+conditions\:(?:[\n]+|(?:\\n)+)\-The[\s\n]+USG[\s\n]+routinely[\s\n]+intercepts[\s\n]+and[\s\n]+monitors[\s\n]+communications[\s\n]+on[\s\n]+this[\s\n]+IS[\s\n]+for[\s\n]+purposes[\s\n]+including,[\s\n]+but[\s\n]+not[\s\n]+limited[\s\n]+to,[\s\n]+penetration[\s\n]+testing,[\s\n]+COMSEC[\s\n]+monitoring,[\s\n]+network[\s\n]+operations[\s\n]+and[\s\n]+defense,[\s\n]+personnel[\s\n]+misconduct[\s\n]+\(PM\),[\s\n]+law[\s\n]+enforcement[\s\n]+\(LE\),[\s\n]+and[\s\n]+counterintelligence[\s\n]+\(CI\)[\s\n]+investigations\.(?:[\n]+|(?:\\n)+)\-At[\s\n]+any[\s\n]+time,[\s\n]+the[\s\n]+USG[\s\n]+may[\s\n]+inspect[\s\n]+and[\s\n]+seize[\s\n]+data[\s\n]+stored[\s\n]+on[\s\n]+this[\s\n]+IS\.(?:[\n]+|(?:\\n)+)\-Communications[\s\n]+using,[\s\n]+or[\s\n]+data[\s\n]+stored[\s\n]+on,[\s\n]+this[\s\n]+IS[\s\n]+are[\s\n]+not[\s\n]+private,[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+routine[\s\n]+monitoring,[\s\n]+interception,[\s\n]+and[\s\n]+search,[\s\n]+and[\s\n]+may[\s\n]+be[\s\n]+disclosed[\s\n]+or[\s\n]+used[\s\n]+for[\s\n]+any[\s\n]+USG\-authorized[\s\n]+purpose\.(?:[\n]+|(?:\\n)+)\-This[\s\n]+IS[\s\n]+includes[\s\n]+security[\s\n]+measures[\s\n]+\(e\.g\.,[\s\n]+authentication[\s\n]+and[\s\n]+access[\s\n]+controls\)[\s\n]+to[\s\n]+protect[\s\n]+USG[\s\n]+interests\-\-not[\s\n]+for[\s\n]+your[\s\n]+personal[\s\n]+benefit[\s\n]+or[\s\n]+privacy\.(?:[\n]+|(?:\\n)+)\-Notwithstanding[\s\n]+the[\s\n]+above,[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+does[\s\n]+not[\s\n]+constitute[\s\n]+consent[\s\n]+to[\s\n]+PM,[\s\n]+LE[\s\n]+or[\s\n]+CI[\s\n]+investigative[\s\n]+searching[\s\n]+or[\s\n]+monitoring[\s\n]+of[\s\n]+the[\s\n]+content[\s\n]+of[\s\n]+privileged[\s\n]+communications,[\s\n]+or[\s\n]+work[\s\n]+product,[\s\n]+related[\s\n]+to[\s\n]+personal[\s\n]+representation[\s\n]+or[\s\n]+services[\s\n]+by[\s\n]+attorneys,[\s\n]+psychotherapists,[\s\n]+or[\s\n]+clergy,[\s\n]+and[\s\n]+their[\s\n]+assistants\.[\s\n]+Such[\s\n]+communications[\s\n]+and[\s\n]+work[\s\n]+product[\s\n]+are[\s\n]+private[\s\n]+and[\s\n]+confidential\.[\s\n]+See[\s\n]+User[\s\n]+Agreement[\s\n]+for[\s\n]+details\.|I've[\s\n]+read[\s\n]+\&amp;[\s\n]+consent[\s\n]+to[\s\n]+terms[\s\n]+in[\s\n]+IS[\s\n]+user[\s\n]+agreem't\.)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_default">^You[\s\n]+are[\s\n]+accessing[\s\n]+a[\s\n]+U\.S\.[\s\n]+Government[\s\n]+\(USG\)[\s\n]+Information[\s\n]+System[\s\n]+\(IS\)[\s\n]+that[\s\n]+is[\s\n]+provided[\s\n]+for[\s\n]+USG\-authorized[\s\n]+use[\s\n]+only\.[\s\n]+By[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+\(which[\s\n]+includes[\s\n]+any[\s\n]+device[\s\n]+attached[\s\n]+to[\s\n]+this[\s\n]+IS\),[\s\n]+you[\s\n]+consent[\s\n]+to[\s\n]+the[\s\n]+following[\s\n]+conditions\:(?:[\n]+|(?:\\n)+)\-The[\s\n]+USG[\s\n]+routinely[\s\n]+intercepts[\s\n]+and[\s\n]+monitors[\s\n]+communications[\s\n]+on[\s\n]+this[\s\n]+IS[\s\n]+for[\s\n]+purposes[\s\n]+including,[\s\n]+but[\s\n]+not[\s\n]+limited[\s\n]+to,[\s\n]+penetration[\s\n]+testing,[\s\n]+COMSEC[\s\n]+monitoring,[\s\n]+network[\s\n]+operations[\s\n]+and[\s\n]+defense,[\s\n]+personnel[\s\n]+misconduct[\s\n]+\(PM\),[\s\n]+law[\s\n]+enforcement[\s\n]+\(LE\),[\s\n]+and[\s\n]+counterintelligence[\s\n]+\(CI\)[\s\n]+investigations\.(?:[\n]+|(?:\\n)+)\-At[\s\n]+any[\s\n]+time,[\s\n]+the[\s\n]+USG[\s\n]+may[\s\n]+inspect[\s\n]+and[\s\n]+seize[\s\n]+data[\s\n]+stored[\s\n]+on[\s\n]+this[\s\n]+IS\.(?:[\n]+|(?:\\n)+)\-Communications[\s\n]+using,[\s\n]+or[\s\n]+data[\s\n]+stored[\s\n]+on,[\s\n]+this[\s\n]+IS[\s\n]+are[\s\n]+not[\s\n]+private,[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+routine[\s\n]+monitoring,[\s\n]+interception,[\s\n]+and[\s\n]+search,[\s\n]+and[\s\n]+may[\s\n]+be[\s\n]+disclosed[\s\n]+or[\s\n]+used[\s\n]+for[\s\n]+any[\s\n]+USG\-authorized[\s\n]+purpose\.(?:[\n]+|(?:\\n)+)\-This[\s\n]+IS[\s\n]+includes[\s\n]+security[\s\n]+measures[\s\n]+\(e\.g\.,[\s\n]+authentication[\s\n]+and[\s\n]+access[\s\n]+controls\)[\s\n]+to[\s\n]+protect[\s\n]+USG[\s\n]+interests\-\-not[\s\n]+for[\s\n]+your[\s\n]+personal[\s\n]+benefit[\s\n]+or[\s\n]+privacy\.(?:[\n]+|(?:\\n)+)\-Notwithstanding[\s\n]+the[\s\n]+above,[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+does[\s\n]+not[\s\n]+constitute[\s\n]+consent[\s\n]+to[\s\n]+PM,[\s\n]+LE[\s\n]+or[\s\n]+CI[\s\n]+investigative[\s\n]+searching[\s\n]+or[\s\n]+monitoring[\s\n]+of[\s\n]+the[\s\n]+content[\s\n]+of[\s\n]+privileged[\s\n]+communications,[\s\n]+or[\s\n]+work[\s\n]+product,[\s\n]+related[\s\n]+to[\s\n]+personal[\s\n]+representation[\s\n]+or[\s\n]+services[\s\n]+by[\s\n]+attorneys,[\s\n]+psychotherapists,[\s\n]+or[\s\n]+clergy,[\s\n]+and[\s\n]+their[\s\n]+assistants\.[\s\n]+Such[\s\n]+communications[\s\n]+and[\s\n]+work[\s\n]+product[\s\n]+are[\s\n]+private[\s\n]+and[\s\n]+confidential\.[\s\n]+See[\s\n]+User[\s\n]+Agreement[\s\n]+for[\s\n]+details\.$</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_short">^I've[\s\n]+read[\s\n]+\&amp;[\s\n]+consent[\s\n]+to[\s\n]+terms[\s\n]+in[\s\n]+IS[\s\n]+user[\s\n]+agreem't\.$</xccdf-1.2:value>
              <xccdf-1.2:value selector="dss_odaa_default">^Use[\s\n]+of[\s\n]+this[\s\n]+or[\s\n]+any[\s\n]+other[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system[\s\n]+constitutes[\s\n]+consent[\s\n]+to[\s\n]+monitoring[\s\n]+at[\s\n]+all[\s\n]+times\.[\s\n]+This[\s\n]+is[\s\n]+a[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system\.[\s\n]+All[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+systems[\s\n]+and[\s\n]+related[\s\n]+equipment[\s\n]+are[\s\n]+intended[\s\n]+for[\s\n]+the[\s\n]+communication,[\s\n]+transmission,[\s\n]+processing,[\s\n]+and[\s\n]+storage[\s\n]+of[\s\n]+official[\s\n]+U\.S\.[\s\n]+Government[\s\n]+or[\s\n]+other[\s\n]+authorized[\s\n]+information[\s\n]+only\.[\s\n]+All[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+systems[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+monitoring[\s\n]+at[\s\n]+all[\s\n]+times[\s\n]+to[\s\n]+ensure[\s\n]+proper[\s\n]+functioning[\s\n]+of[\s\n]+equipment[\s\n]+and[\s\n]+systems[\s\n]+including[\s\n]+security[\s\n]+devices[\s\n]+and[\s\n]+systems,[\s\n]+to[\s\n]+prevent[\s\n]+unauthorized[\s\n]+use[\s\n]+and[\s\n]+violations[\s\n]+of[\s\n]+statutes[\s\n]+and[\s\n]+security[\s\n]+regulations,[\s\n]+to[\s\n]+deter[\s\n]+criminal[\s\n]+activity,[\s\n]+and[\s\n]+for[\s\n]+other[\s\n]+similar[\s\n]+purposes\.[\s\n]+Any[\s\n]+user[\s\n]+of[\s\n]+a[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system[\s\n]+should[\s\n]+be[\s\n]+aware[\s\n]+that[\s\n]+any[\s\n]+information[\s\n]+placed[\s\n]+in[\s\n]+the[\s\n]+system[\s\n]+is[\s\n]+subject[\s\n]+to[\s\n]+monitoring[\s\n]+and[\s\n]+is[\s\n]+not[\s\n]+subject[\s\n]+to[\s\n]+any[\s\n]+expectation[\s\n]+of[\s\n]+privacy\.[\s\n]+If[\s\n]+monitoring[\s\n]+of[\s\n]+this[\s\n]+or[\s\n]+any[\s\n]+other[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system[\s\n]+reveals[\s\n]+possible[\s\n]+evidence[\s\n]+of[\s\n]+violation[\s\n]+of[\s\n]+criminal[\s\n]+statutes,[\s\n]+this[\s\n]+evidence[\s\n]+and[\s\n]+any[\s\n]+other[\s\n]+related[\s\n]+information,[\s\n]+including[\s\n]+identification[\s\n]+information[\s\n]+about[\s\n]+the[\s\n]+user,[\s\n]+may[\s\n]+be[\s\n]+provided[\s\n]+to[\s\n]+law[\s\n]+enforcement[\s\n]+officials\.[\s\n]+If[\s\n]+monitoring[\s\n]+of[\s\n]+this[\s\n]+or[\s\n]+any[\s\n]+other[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+systems[\s\n]+reveals[\s\n]+violations[\s\n]+of[\s\n]+security[\s\n]+regulations[\s\n]+or[\s\n]+unauthorized[\s\n]+use,[\s\n]+employees[\s\n]+who[\s\n]+violate[\s\n]+security[\s\n]+regulations[\s\n]+or[\s\n]+make[\s\n]+unauthorized[\s\n]+use[\s\n]+of[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+systems[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+appropriate[\s\n]+disciplinary[\s\n]+action\.[\s\n]+Use[\s\n]+of[\s\n]+this[\s\n]+or[\s\n]+any[\s\n]+other[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system[\s\n]+constitutes[\s\n]+consent[\s\n]+to[\s\n]+monitoring[\s\n]+at[\s\n]+all[\s\n]+times\.$</xccdf-1.2:value>
              <xccdf-1.2:value selector="usgcb_default">^\-\-[\s\n]+WARNING[\s\n]+\-\-[\s\n]+This[\s\n]+system[\s\n]+is[\s\n]+for[\s\n]+the[\s\n]+use[\s\n]+of[\s\n]+authorized[\s\n]+users[\s\n]+only\.[\s\n]+Individuals[\s\n]+using[\s\n]+this[\s\n]+computer[\s\n]+system[\s\n]+without[\s\n]+authority[\s\n]+or[\s\n]+in[\s\n]+excess[\s\n]+of[\s\n]+their[\s\n]+authority[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+having[\s\n]+all[\s\n]+their[\s\n]+activities[\s\n]+on[\s\n]+this[\s\n]+system[\s\n]+monitored[\s\n]+and[\s\n]+recorded[\s\n]+by[\s\n]+system[\s\n]+personnel\.[\s\n]+Anyone[\s\n]+using[\s\n]+this[\s\n]+system[\s\n]+expressly[\s\n]+consents[\s\n]+to[\s\n]+such[\s\n]+monitoring[\s\n]+and[\s\n]+is[\s\n]+advised[\s\n]+that[\s\n]+if[\s\n]+such[\s\n]+monitoring[\s\n]+reveals[\s\n]+possible[\s\n]+evidence[\s\n]+of[\s\n]+criminal[\s\n]+activity[\s\n]+system[\s\n]+personal[\s\n]+may[\s\n]+provide[\s\n]+the[\s\n]+evidence[\s\n]+of[\s\n]+such[\s\n]+monitoring[\s\n]+to[\s\n]+law[\s\n]+enforcement[\s\n]+officials\.$</xccdf-1.2:value>
              <xccdf-1.2:value>^Authorized[\s\n]+users[\s\n]+only\.[\s\n]+All[\s\n]+activity[\s\n]+may[\s\n]+be[\s\n]+monitored[\s\n]+and[\s\n]+reported\.$</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_remote_login_banner_contents" interactive="true" type="string">
              <xccdf-1.2:title>Remote Login Banner Verbiage</xccdf-1.2:title>
              <xccdf-1.2:description>Enter an appropriate login banner text for your organization. This variable is used only in remediations. In OVAL checks a regular expression specified in the remote_login_banner_text variable is used instead. Using a regular expression is needed because some profiles (eg. STIG) allow multiple different banners.</xccdf-1.2:description>
              <xccdf-1.2:value>Authorized users only. All activity may be monitored and reported.</xccdf-1.2:value>
              <xccdf-1.2:value selector="cis_default">Authorized users only. All activity may be monitored and reported.</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_default">You are accessing a U.S. Government (USG) Information System (IS) that is\nprovided for USG-authorized use only. By using this IS (which includes any\ndevice attached to this IS), you consent to the following conditions:\n\n-The USG routinely intercepts and monitors communications on this IS for\npurposes including, but not limited to, penetration testing, COMSEC monitoring,\nnetwork operations and defense, personnel misconduct (PM), law enforcement\n(LE), and counterintelligence (CI) investigations.\n\n-At any time, the USG may inspect and seize data stored on this IS.\n\n-Communications using, or data stored on, this IS are not private, are subject\nto routine monitoring, interception, and search, and may be disclosed or used\nfor any USG-authorized purpose.\n\n-This IS includes security measures (e.g., authentication and access controls)\nto protect USG interests--not for your personal benefit or privacy.\n\n-Notwithstanding the above, using this IS does not constitute consent to PM, LE\nor CI investigative searching or monitoring of the content of privileged\ncommunications, or work product, related to personal representation or services\nby attorneys, psychotherapists, or clergy, and their assistants. Such\ncommunications and work product are private and confidential. See User\nAgreement for details.</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_short">I've read &amp; consent to terms in IS user agreem't.</xccdf-1.2:value>
              <xccdf-1.2:value selector="dss_odaa_default">Use of this or any other DoD interest computer system constitutes consent to\nmonitoring at all times. This is a DoD interest computer system. All DoD\ninterest computer systems and related equipment are intended for the\ncommunication, transmission, processing, and storage of official U.S.\nGovernment or other authorized information only. All DoD interest computer\nsystems are subject to monitoring at all times to ensure proper functioning of\nequipment and systems including security devices and systems, to prevent\nunauthorized use and violations of statutes and security regulations, to deter\ncriminal activity, and for other similar purposes. Any user of a DoD interest\ncomputer system should be aware that any information placed in the system is\nsubject to monitoring and is not subject to any expectation of privacy. If\nmonitoring of this or any other DoD interest computer system reveals possible\nevidence of violation of criminal statutes, this evidence and any other related\ninformation, including identification information about the user, may be\nprovided to law enforcement officials. If monitoring of this or any other DoD\ninterest computer systems reveals violations of security regulations or\nunauthorized use, employees who violate security regulations or make\nunauthorized use of DoD interest computer systems are subject to appropriate\ndisciplinary action. Use of this or any other DoD interest computer system\nconstitutes consent to monitoring at all times.</xccdf-1.2:value>
              <xccdf-1.2:value selector="usgcb_default">-- WARNING -- This system is for the use of authorized users only. Individuals\nusing this computer system without authority or in excess of their authority\nare subject to having all their activities on this system monitored and\nrecorded by system personnel. Anyone using this system expressly consents to\nsuch monitoring and is advised that if such monitoring reveals possible\nevidence of criminal activity system personal may provide the evidence of such\nmonitoring to law enforcement officials.</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_remote_login_banner_text" interactive="true" type="string">
              <xccdf-1.2:title>Remote Login Banner Verbiage Regular Expression</xccdf-1.2:title>
              <xccdf-1.2:description>Enter an appropriate login banner regular expression for your organization. Using a regular expression is needed because some profiles (eg. STIG) allow multiple different banners. This regular expression is used only in OVAL checks. In remediations the remote_login_banner_contents variable is used instead. For information about how to generate banner regular expression for your tailoring files, see: https://complianceascode.readthedocs.io/en/latest/manual/developer/05_tools_and_utilities.html#generating-login-banner-regular-expressions</xccdf-1.2:description>
              <xccdf-1.2:value selector="cis_banners">^(Authorized[\s\n]+users[\s\n]+only\.[\s\n]+All[\s\n]+activity[\s\n]+may[\s\n]+be[\s\n]+monitored[\s\n]+and[\s\n]+reported\.|^(?!.*(\\|fedora|rhel|sle|ubuntu)).*)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="cis_default">^Authorized[\s\n]+users[\s\n]+only\.[\s\n]+All[\s\n]+activity[\s\n]+may[\s\n]+be[\s\n]+monitored[\s\n]+and[\s\n]+reported\.$</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_banners">^(You[\s\n]+are[\s\n]+accessing[\s\n]+a[\s\n]+U\.S\.[\s\n]+Government[\s\n]+\(USG\)[\s\n]+Information[\s\n]+System[\s\n]+\(IS\)[\s\n]+that[\s\n]+is[\s\n]+provided[\s\n]+for[\s\n]+USG\-authorized[\s\n]+use[\s\n]+only\.[\s\n]+By[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+\(which[\s\n]+includes[\s\n]+any[\s\n]+device[\s\n]+attached[\s\n]+to[\s\n]+this[\s\n]+IS\),[\s\n]+you[\s\n]+consent[\s\n]+to[\s\n]+the[\s\n]+following[\s\n]+conditions\:(?:[\n]+|(?:\\n)+)\-The[\s\n]+USG[\s\n]+routinely[\s\n]+intercepts[\s\n]+and[\s\n]+monitors[\s\n]+communications[\s\n]+on[\s\n]+this[\s\n]+IS[\s\n]+for[\s\n]+purposes[\s\n]+including,[\s\n]+but[\s\n]+not[\s\n]+limited[\s\n]+to,[\s\n]+penetration[\s\n]+testing,[\s\n]+COMSEC[\s\n]+monitoring,[\s\n]+network[\s\n]+operations[\s\n]+and[\s\n]+defense,[\s\n]+personnel[\s\n]+misconduct[\s\n]+\(PM\),[\s\n]+law[\s\n]+enforcement[\s\n]+\(LE\),[\s\n]+and[\s\n]+counterintelligence[\s\n]+\(CI\)[\s\n]+investigations\.(?:[\n]+|(?:\\n)+)\-At[\s\n]+any[\s\n]+time,[\s\n]+the[\s\n]+USG[\s\n]+may[\s\n]+inspect[\s\n]+and[\s\n]+seize[\s\n]+data[\s\n]+stored[\s\n]+on[\s\n]+this[\s\n]+IS\.(?:[\n]+|(?:\\n)+)\-Communications[\s\n]+using,[\s\n]+or[\s\n]+data[\s\n]+stored[\s\n]+on,[\s\n]+this[\s\n]+IS[\s\n]+are[\s\n]+not[\s\n]+private,[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+routine[\s\n]+monitoring,[\s\n]+interception,[\s\n]+and[\s\n]+search,[\s\n]+and[\s\n]+may[\s\n]+be[\s\n]+disclosed[\s\n]+or[\s\n]+used[\s\n]+for[\s\n]+any[\s\n]+USG\-authorized[\s\n]+purpose\.(?:[\n]+|(?:\\n)+)\-This[\s\n]+IS[\s\n]+includes[\s\n]+security[\s\n]+measures[\s\n]+\(e\.g\.,[\s\n]+authentication[\s\n]+and[\s\n]+access[\s\n]+controls\)[\s\n]+to[\s\n]+protect[\s\n]+USG[\s\n]+interests\-\-not[\s\n]+for[\s\n]+your[\s\n]+personal[\s\n]+benefit[\s\n]+or[\s\n]+privacy\.(?:[\n]+|(?:\\n)+)\-Notwithstanding[\s\n]+the[\s\n]+above,[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+does[\s\n]+not[\s\n]+constitute[\s\n]+consent[\s\n]+to[\s\n]+PM,[\s\n]+LE[\s\n]+or[\s\n]+CI[\s\n]+investigative[\s\n]+searching[\s\n]+or[\s\n]+monitoring[\s\n]+of[\s\n]+the[\s\n]+content[\s\n]+of[\s\n]+privileged[\s\n]+communications,[\s\n]+or[\s\n]+work[\s\n]+product,[\s\n]+related[\s\n]+to[\s\n]+personal[\s\n]+representation[\s\n]+or[\s\n]+services[\s\n]+by[\s\n]+attorneys,[\s\n]+psychotherapists,[\s\n]+or[\s\n]+clergy,[\s\n]+and[\s\n]+their[\s\n]+assistants\.[\s\n]+Such[\s\n]+communications[\s\n]+and[\s\n]+work[\s\n]+product[\s\n]+are[\s\n]+private[\s\n]+and[\s\n]+confidential\.[\s\n]+See[\s\n]+User[\s\n]+Agreement[\s\n]+for[\s\n]+details\.|I've[\s\n]+read[\s\n]+\&amp;[\s\n]+consent[\s\n]+to[\s\n]+terms[\s\n]+in[\s\n]+IS[\s\n]+user[\s\n]+agreem't\.)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_default">^You[\s\n]+are[\s\n]+accessing[\s\n]+a[\s\n]+U\.S\.[\s\n]+Government[\s\n]+\(USG\)[\s\n]+Information[\s\n]+System[\s\n]+\(IS\)[\s\n]+that[\s\n]+is[\s\n]+provided[\s\n]+for[\s\n]+USG\-authorized[\s\n]+use[\s\n]+only\.[\s\n]+By[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+\(which[\s\n]+includes[\s\n]+any[\s\n]+device[\s\n]+attached[\s\n]+to[\s\n]+this[\s\n]+IS\),[\s\n]+you[\s\n]+consent[\s\n]+to[\s\n]+the[\s\n]+following[\s\n]+conditions\:(?:[\n]+|(?:\\n)+)\-The[\s\n]+USG[\s\n]+routinely[\s\n]+intercepts[\s\n]+and[\s\n]+monitors[\s\n]+communications[\s\n]+on[\s\n]+this[\s\n]+IS[\s\n]+for[\s\n]+purposes[\s\n]+including,[\s\n]+but[\s\n]+not[\s\n]+limited[\s\n]+to,[\s\n]+penetration[\s\n]+testing,[\s\n]+COMSEC[\s\n]+monitoring,[\s\n]+network[\s\n]+operations[\s\n]+and[\s\n]+defense,[\s\n]+personnel[\s\n]+misconduct[\s\n]+\(PM\),[\s\n]+law[\s\n]+enforcement[\s\n]+\(LE\),[\s\n]+and[\s\n]+counterintelligence[\s\n]+\(CI\)[\s\n]+investigations\.(?:[\n]+|(?:\\n)+)\-At[\s\n]+any[\s\n]+time,[\s\n]+the[\s\n]+USG[\s\n]+may[\s\n]+inspect[\s\n]+and[\s\n]+seize[\s\n]+data[\s\n]+stored[\s\n]+on[\s\n]+this[\s\n]+IS\.(?:[\n]+|(?:\\n)+)\-Communications[\s\n]+using,[\s\n]+or[\s\n]+data[\s\n]+stored[\s\n]+on,[\s\n]+this[\s\n]+IS[\s\n]+are[\s\n]+not[\s\n]+private,[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+routine[\s\n]+monitoring,[\s\n]+interception,[\s\n]+and[\s\n]+search,[\s\n]+and[\s\n]+may[\s\n]+be[\s\n]+disclosed[\s\n]+or[\s\n]+used[\s\n]+for[\s\n]+any[\s\n]+USG\-authorized[\s\n]+purpose\.(?:[\n]+|(?:\\n)+)\-This[\s\n]+IS[\s\n]+includes[\s\n]+security[\s\n]+measures[\s\n]+\(e\.g\.,[\s\n]+authentication[\s\n]+and[\s\n]+access[\s\n]+controls\)[\s\n]+to[\s\n]+protect[\s\n]+USG[\s\n]+interests\-\-not[\s\n]+for[\s\n]+your[\s\n]+personal[\s\n]+benefit[\s\n]+or[\s\n]+privacy\.(?:[\n]+|(?:\\n)+)\-Notwithstanding[\s\n]+the[\s\n]+above,[\s\n]+using[\s\n]+this[\s\n]+IS[\s\n]+does[\s\n]+not[\s\n]+constitute[\s\n]+consent[\s\n]+to[\s\n]+PM,[\s\n]+LE[\s\n]+or[\s\n]+CI[\s\n]+investigative[\s\n]+searching[\s\n]+or[\s\n]+monitoring[\s\n]+of[\s\n]+the[\s\n]+content[\s\n]+of[\s\n]+privileged[\s\n]+communications,[\s\n]+or[\s\n]+work[\s\n]+product,[\s\n]+related[\s\n]+to[\s\n]+personal[\s\n]+representation[\s\n]+or[\s\n]+services[\s\n]+by[\s\n]+attorneys,[\s\n]+psychotherapists,[\s\n]+or[\s\n]+clergy,[\s\n]+and[\s\n]+their[\s\n]+assistants\.[\s\n]+Such[\s\n]+communications[\s\n]+and[\s\n]+work[\s\n]+product[\s\n]+are[\s\n]+private[\s\n]+and[\s\n]+confidential\.[\s\n]+See[\s\n]+User[\s\n]+Agreement[\s\n]+for[\s\n]+details\.$</xccdf-1.2:value>
              <xccdf-1.2:value selector="dod_short">^I've[\s\n]+read[\s\n]+\&amp;[\s\n]+consent[\s\n]+to[\s\n]+terms[\s\n]+in[\s\n]+IS[\s\n]+user[\s\n]+agreem't\.$</xccdf-1.2:value>
              <xccdf-1.2:value selector="dss_odaa_default">^Use[\s\n]+of[\s\n]+this[\s\n]+or[\s\n]+any[\s\n]+other[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system[\s\n]+constitutes[\s\n]+consent[\s\n]+to[\s\n]+monitoring[\s\n]+at[\s\n]+all[\s\n]+times\.[\s\n]+This[\s\n]+is[\s\n]+a[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system\.[\s\n]+All[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+systems[\s\n]+and[\s\n]+related[\s\n]+equipment[\s\n]+are[\s\n]+intended[\s\n]+for[\s\n]+the[\s\n]+communication,[\s\n]+transmission,[\s\n]+processing,[\s\n]+and[\s\n]+storage[\s\n]+of[\s\n]+official[\s\n]+U\.S\.[\s\n]+Government[\s\n]+or[\s\n]+other[\s\n]+authorized[\s\n]+information[\s\n]+only\.[\s\n]+All[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+systems[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+monitoring[\s\n]+at[\s\n]+all[\s\n]+times[\s\n]+to[\s\n]+ensure[\s\n]+proper[\s\n]+functioning[\s\n]+of[\s\n]+equipment[\s\n]+and[\s\n]+systems[\s\n]+including[\s\n]+security[\s\n]+devices[\s\n]+and[\s\n]+systems,[\s\n]+to[\s\n]+prevent[\s\n]+unauthorized[\s\n]+use[\s\n]+and[\s\n]+violations[\s\n]+of[\s\n]+statutes[\s\n]+and[\s\n]+security[\s\n]+regulations,[\s\n]+to[\s\n]+deter[\s\n]+criminal[\s\n]+activity,[\s\n]+and[\s\n]+for[\s\n]+other[\s\n]+similar[\s\n]+purposes\.[\s\n]+Any[\s\n]+user[\s\n]+of[\s\n]+a[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system[\s\n]+should[\s\n]+be[\s\n]+aware[\s\n]+that[\s\n]+any[\s\n]+information[\s\n]+placed[\s\n]+in[\s\n]+the[\s\n]+system[\s\n]+is[\s\n]+subject[\s\n]+to[\s\n]+monitoring[\s\n]+and[\s\n]+is[\s\n]+not[\s\n]+subject[\s\n]+to[\s\n]+any[\s\n]+expectation[\s\n]+of[\s\n]+privacy\.[\s\n]+If[\s\n]+monitoring[\s\n]+of[\s\n]+this[\s\n]+or[\s\n]+any[\s\n]+other[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system[\s\n]+reveals[\s\n]+possible[\s\n]+evidence[\s\n]+of[\s\n]+violation[\s\n]+of[\s\n]+criminal[\s\n]+statutes,[\s\n]+this[\s\n]+evidence[\s\n]+and[\s\n]+any[\s\n]+other[\s\n]+related[\s\n]+information,[\s\n]+including[\s\n]+identification[\s\n]+information[\s\n]+about[\s\n]+the[\s\n]+user,[\s\n]+may[\s\n]+be[\s\n]+provided[\s\n]+to[\s\n]+law[\s\n]+enforcement[\s\n]+officials\.[\s\n]+If[\s\n]+monitoring[\s\n]+of[\s\n]+this[\s\n]+or[\s\n]+any[\s\n]+other[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+systems[\s\n]+reveals[\s\n]+violations[\s\n]+of[\s\n]+security[\s\n]+regulations[\s\n]+or[\s\n]+unauthorized[\s\n]+use,[\s\n]+employees[\s\n]+who[\s\n]+violate[\s\n]+security[\s\n]+regulations[\s\n]+or[\s\n]+make[\s\n]+unauthorized[\s\n]+use[\s\n]+of[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+systems[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+appropriate[\s\n]+disciplinary[\s\n]+action\.[\s\n]+Use[\s\n]+of[\s\n]+this[\s\n]+or[\s\n]+any[\s\n]+other[\s\n]+DoD[\s\n]+interest[\s\n]+computer[\s\n]+system[\s\n]+constitutes[\s\n]+consent[\s\n]+to[\s\n]+monitoring[\s\n]+at[\s\n]+all[\s\n]+times\.$</xccdf-1.2:value>
              <xccdf-1.2:value selector="usgcb_default">^\-\-[\s\n]+WARNING[\s\n]+\-\-[\s\n]+This[\s\n]+system[\s\n]+is[\s\n]+for[\s\n]+the[\s\n]+use[\s\n]+of[\s\n]+authorized[\s\n]+users[\s\n]+only\.[\s\n]+Individuals[\s\n]+using[\s\n]+this[\s\n]+computer[\s\n]+system[\s\n]+without[\s\n]+authority[\s\n]+or[\s\n]+in[\s\n]+excess[\s\n]+of[\s\n]+their[\s\n]+authority[\s\n]+are[\s\n]+subject[\s\n]+to[\s\n]+having[\s\n]+all[\s\n]+their[\s\n]+activities[\s\n]+on[\s\n]+this[\s\n]+system[\s\n]+monitored[\s\n]+and[\s\n]+recorded[\s\n]+by[\s\n]+system[\s\n]+personnel\.[\s\n]+Anyone[\s\n]+using[\s\n]+this[\s\n]+system[\s\n]+expressly[\s\n]+consents[\s\n]+to[\s\n]+such[\s\n]+monitoring[\s\n]+and[\s\n]+is[\s\n]+advised[\s\n]+that[\s\n]+if[\s\n]+such[\s\n]+monitoring[\s\n]+reveals[\s\n]+possible[\s\n]+evidence[\s\n]+of[\s\n]+criminal[\s\n]+activity[\s\n]+system[\s\n]+personal[\s\n]+may[\s\n]+provide[\s\n]+the[\s\n]+evidence[\s\n]+of[\s\n]+such[\s\n]+monitoring[\s\n]+to[\s\n]+law[\s\n]+enforcement[\s\n]+officials\.$</xccdf-1.2:value>
              <xccdf-1.2:value>^Authorized[\s\n]+users[\s\n]+only\.[\s\n]+All[\s\n]+activity[\s\n]+may[\s\n]+be[\s\n]+monitored[\s\n]+and[\s\n]+reported\.$</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_banner_etc_issue" selected="false" severity="medium">
              <xccdf-1.2:title>Modify the System Login Banner</xccdf-1.2:title>
              <xccdf-1.2:description>
To configure the system login banner edit <html:code>/etc/issue</html:code>. Replace the
default text with a message compliant with the local site policy or a legal
disclaimer.


The DoD required text is either:
<html:br/><html:br/>
<html:code>You are accessing a U.S. Government (USG) Information System (IS) that
is provided for USG-authorized use only. By using this IS (which includes
any device attached to this IS), you consent to the following conditions:
<html:br/>-The USG routinely intercepts and monitors communications on this IS
for purposes including, but not limited to, penetration testing, COMSEC
monitoring, network operations and defense, personnel misconduct (PM), law
enforcement (LE), and counterintelligence (CI) investigations.
<html:br/>-At any time, the USG may inspect and seize data stored on this IS.
<html:br/>-Communications using, or data stored on, this IS are not private,
are subject to routine monitoring, interception, and search, and may be
disclosed or used for any USG-authorized purpose.
<html:br/>-This IS includes security measures (e.g., authentication and access
controls) to protect USG interests -- not for your personal benefit or
privacy.
<html:br/>-Notwithstanding the above, using this IS does not constitute consent
to PM, LE or CI investigative searching or monitoring of the content of
privileged communications, or work product, related to personal
representation or services by attorneys, psychotherapists, or clergy, and
their assistants. Such communications and work product are private and
confidential. See User Agreement for details.</html:code>
<html:br/><html:br/>
OR:
<html:br/><html:br/>
<html:code>I've read &amp; consent to terms in IS user agreem't.</html:code></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-8(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-8(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000023-GPOS-00006</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000228-GPOS-00088</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010060</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230227r1017046_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Display of a standardized and approved use notification before granting
access to the operating system ensures privacy and security notification
verbiage used is consistent with applicable federal laws, Executive Orders,
directives, policies, regulations, standards, and guidance.
<html:br/><html:br/>
System use notifications are required only for access via login interfaces
with human users and are not required when such human interfaces do not
exist.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix id="banner_etc_issue" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

login_banner_contents=$(echo "<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_login_banner_contents" use="legacy"/>" | sed 's/\\n/\n/g')
echo "$login_banner_contents" &gt; /etc/issue

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="banner_etc_issue" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010060
  - NIST-800-171-3.1.9
  - NIST-800-53-AC-8(a)
  - NIST-800-53-AC-8(c)
  - banner_etc_issue
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
- name: XCCDF Value login_banner_contents # promote to variable
  set_fact:
    login_banner_contents: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_login_banner_contents" use="legacy"/>
  tags:
    - always

- name: Modify the System Login Banner - Ensure Correct Banner
  ansible.builtin.copy:
    dest: /etc/issue
    content: |
      {{ login_banner_contents | replace('\n', '
      ') }}
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010060
  - NIST-800-171-3.1.9
  - NIST-800-53-AC-8(a)
  - NIST-800-53-AC-8(c)
  - banner_etc_issue
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="banner_etc_issue" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
metadata:
  labels:
    machineconfiguration.openshift.io/role: master
    machineconfiguration.openshift.io/role: worker
  name: 75-banner-etc-issue
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,You%20are%20accessing%20a%20U.S.%20Government%20%28USG%29%20Information%20System%20%28IS%29%20that%20is%20%0Aprovided%20for%20USG-authorized%20use%20only.%20By%20using%20this%20IS%20%28which%20includes%20any%20%0Adevice%20attached%20to%20this%20IS%29%2C%20you%20consent%20to%20the%20following%20conditions%3A%0A%0A-The%20USG%20routinely%20intercepts%20and%20monitors%20communications%20on%20this%20IS%20for%20%0Apurposes%20including%2C%20but%20not%20limited%20to%2C%20penetration%20testing%2C%20COMSEC%20monitoring%2C%20%0Anetwork%20operations%20and%20defense%2C%20personnel%20misconduct%20%28PM%29%2C%20law%20enforcement%20%0A%28LE%29%2C%20and%20counterintelligence%20%28CI%29%20investigations.%0A%0A-At%20any%20time%2C%20the%20USG%20may%20inspect%20and%20seize%20data%20stored%20on%20this%20IS.%0A%0A-Communications%20using%2C%20or%20data%20stored%20on%2C%20this%20IS%20are%20not%20private%2C%20are%20subject%20%0Ato%20routine%20monitoring%2C%20interception%2C%20and%20search%2C%20and%20may%20be%20disclosed%20or%20used%20%0Afor%20any%20USG-authorized%20purpose.%0A%0A-This%20IS%20includes%20security%20measures%20%28e.g.%2C%20authentication%20and%20access%20controls%29%20%0Ato%20protect%20USG%20interests--not%20for%20your%20personal%20benefit%20or%20privacy.%0A%0A-Notwithstanding%20the%20above%2C%20using%20this%20IS%20does%20not%20constitute%20consent%20to%20PM%2C%20LE%20%0Aor%20CI%20investigative%20searching%20or%20monitoring%20of%20the%20content%20of%20privileged%20%0Acommunications%2C%20or%20work%20product%2C%20related%20to%20personal%20representation%20or%20services%20%0Aby%20attorneys%2C%20psychotherapists%2C%20or%20clergy%2C%20and%20their%20assistants.%20Such%20%0Acommunications%20and%20work%20product%20are%20private%20and%20confidential.%20See%20User%20%0AAgreement%20for%20details.
        mode: 0644
        path: /etc/issue.d/legal-notice
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-login_banner_text:var:1" value-id="xccdf_org.ssgproject.content_value_login_banner_text"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-banner_etc_issue:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-banner_etc_issue_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_banner_etc_issue_cis" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Local Login Warning Banner Is Configured Properly</xccdf-1.2:title>
              <xccdf-1.2:description>To configure the system local login warning banner edit the <html:code>/etc/issue</html:code> file.
The contents of this file is displayed to users prior to login to local terminals.
Replace the default text with a message compliant with the local site policy.
The message should not contain information about operating system version,
release, kernel version or patch level.

The recommended banner text can be tailored in the XCCDF Value <html:code>xccdf_org.ssgproject.content_value_cis_banner_text</html:code>:
<html:pre><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_cis_banner_text" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.7.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Warning messages inform users who are attempting to login to the system of their legal
status regarding the system and must include the name of the organization that owns
the system and any monitoring policies that are in place. Displaying OS and patch level
information in login banners also has the side effect of providing detailed system
information to attackers attempting to target specific exploits of a system. Authorized
users can easily get this information by running the <html:code>uname -a</html:code> command once they
have logged in.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="banner_etc_issue_cis" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cis_banner_text='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_cis_banner_text" use="legacy"/>'

echo "$cis_banner_text" &gt; "/etc/issue"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="banner_etc_issue_cis" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - banner_etc_issue_cis
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value cis_banner_text # promote to variable
  set_fact:
    cis_banner_text: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_cis_banner_text" use="legacy"/>
  tags:
    - always

- name: Ensure Local Login Warning Banner Is Configured Properly - Copy using inline
    content
  ansible.builtin.copy:
    content: '{{ cis_banner_text }}'
    dest: /etc/issue
  when: '"kernel" in ansible_facts.packages'
  tags:
  - banner_etc_issue_cis
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-banner_etc_issue_cis:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-banner_etc_issue_cis_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_banner_etc_issue_net" selected="false" severity="medium">
              <xccdf-1.2:title>Modify the System Login Banner for Remote Connections</xccdf-1.2:title>
              <xccdf-1.2:description>To configure the system login banner edit <html:code>/etc/issue.net</html:code>. Replace the
default text with a message compliant with the local site policy or a legal
disclaimer.

The DoD required text is either:
<html:br/><html:br/>
<html:code>You are accessing a U.S. Government (USG) Information System (IS) that
is provided for USG-authorized use only. By using this IS (which includes
any device attached to this IS), you consent to the following conditions:
<html:br/>-The USG routinely intercepts and monitors communications on this IS
for purposes including, but not limited to, penetration testing, COMSEC
monitoring, network operations and defense, personnel misconduct (PM), law
enforcement (LE), and counterintelligence (CI) investigations.
<html:br/>-At any time, the USG may inspect and seize data stored on this IS.
<html:br/>-Communications using, or data stored on, this IS are not private,
are subject to routine monitoring, interception, and search, and may be
disclosed or used for any USG-authorized purpose.
<html:br/>-This IS includes security measures (e.g., authentication and access
controls) to protect USG interests -- not for your personal benefit or
privacy.
<html:br/>-Notwithstanding the above, using this IS does not constitute consent
to PM, LE or CI investigative searching or monitoring of the content of
privileged communications, or work product, related to personal
representation or services by attorneys, psychotherapists, or clergy, and
their assistants. Such communications and work product are private and
confidential. See User Agreement for details.</html:code>
<html:br/><html:br/>
OR:
<html:br/><html:br/>
<html:code>I've read &amp; consent to terms in IS user agreem't.</html:code></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000023-GPOS-00006</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000228-GPOS-00088</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Display of a standardized and approved use notification before granting
access to the operating system ensures privacy and security notification
verbiage used is consistent with applicable federal laws, Executive Orders,
directives, policies, regulations, standards, and guidance.
<html:br/><html:br/>
System use notifications are required only for access via login interfaces
with human users and are not required when such human interfaces do not
exist.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix id="banner_etc_issue_net" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

remote_login_banner_contents=$(echo "<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_remote_login_banner_contents" use="legacy"/>" | sed 's/\\n/\n/g')
echo "$remote_login_banner_contents" &gt; /etc/issue.net

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="banner_etc_issue_net" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - banner_etc_issue_net
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
- name: XCCDF Value remote_login_banner_contents # promote to variable
  set_fact:
    remote_login_banner_contents: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_remote_login_banner_contents" use="legacy"/>
  tags:
    - always

- name: Modify the System Login Banner for Remote Connections - ensure correct banner
  ansible.builtin.copy:
    dest: /etc/issue.net
    content: |
      {{ remote_login_banner_contents | replace('\n', '
      ') }}
  when: '"kernel" in ansible_facts.packages'
  tags:
  - banner_etc_issue_net
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-remote_login_banner_text:var:1" value-id="xccdf_org.ssgproject.content_value_remote_login_banner_text"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-banner_etc_issue_net:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-banner_etc_issue_net_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_banner_etc_issue_net_cis" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Remote Login Warning Banner Is Configured Properly</xccdf-1.2:title>
              <xccdf-1.2:description>To configure the system remote login warning banner edit the <html:code>/etc/issue.net</html:code> file.
The contents of this file is displayed to users prior to login from remote connections.
Replace the default text with a message compliant with the local site policy.
The message should not contain information about operating system version,
release, kernel version or patch level.

The recommended banner text can be tailored in the XCCDF Value <html:code>xccdf_org.ssgproject.content_value_cis_banner_text</html:code>:
<html:pre><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_cis_banner_text" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.7.3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Warning messages inform users who are attempting to login to the system of their legal
status regarding the system and must include the name of the organization that owns
the system and any monitoring policies that are in place. Displaying OS and patch level
information in login banners also has the side effect of providing detailed system
information to attackers attempting to target specific exploits of a system. Authorized
users can easily get this information by running the <html:code>uname -a</html:code> command once they
have logged in.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="banner_etc_issue_net_cis" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cis_banner_text='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_cis_banner_text" use="legacy"/>'

echo "$cis_banner_text" &gt; "/etc/issue.net"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="banner_etc_issue_net_cis" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - banner_etc_issue_net_cis
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value cis_banner_text # promote to variable
  set_fact:
    cis_banner_text: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_cis_banner_text" use="legacy"/>
  tags:
    - always

- name: Ensure Remote Login Warning Banner Is Configured Properly - Copy using inline
    content
  ansible.builtin.copy:
    content: '{{ cis_banner_text }}'
    dest: /etc/issue.net
  when: '"kernel" in ansible_facts.packages'
  tags:
  - banner_etc_issue_net_cis
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-banner_etc_issue_net_cis:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-banner_etc_issue_net_cis_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_banner_etc_motd" selected="false" severity="medium">
              <xccdf-1.2:title>Modify the System Message of the Day Banner</xccdf-1.2:title>
              <xccdf-1.2:description>To configure the system message banner edit <html:code>/etc/motd</html:code>. Replace the
default text with a message compliant with the local site policy or a legal
disclaimer.

The DoD required text is either:
<html:br/><html:br/>
<html:code>You are accessing a U.S. Government (USG) Information System (IS) that
is provided for USG-authorized use only. By using this IS (which includes
any device attached to this IS), you consent to the following conditions:
<html:br/>-The USG routinely intercepts and monitors communications on this IS
for purposes including, but not limited to, penetration testing, COMSEC
monitoring, network operations and defense, personnel misconduct (PM), law
enforcement (LE), and counterintelligence (CI) investigations.
<html:br/>-At any time, the USG may inspect and seize data stored on this IS.
<html:br/>-Communications using, or data stored on, this IS are not private,
are subject to routine monitoring, interception, and search, and may be
disclosed or used for any USG-authorized purpose.
<html:br/>-This IS includes security measures (e.g., authentication and access
controls) to protect USG interests -- not for your personal benefit or
privacy.
<html:br/>-Notwithstanding the above, using this IS does not constitute consent
to PM, LE or CI investigative searching or monitoring of the content of
privileged communications, or work product, related to personal
representation or services by attorneys, psychotherapists, or clergy, and
their assistants. Such communications and work product are private and
confidential. See User Agreement for details.</html:code>
<html:br/><html:br/>
OR:
<html:br/><html:br/>
<html:code>I've read &amp; consent to terms in IS user agreem't.</html:code></xccdf-1.2:description>
              <xccdf-1.2:rationale>Display of a standardized and approved use notification before granting
access to the operating system ensures privacy and security notification
verbiage used is consistent with applicable federal laws, Executive Orders,
directives, policies, regulations, standards, and guidance.
<html:br/><html:br/>
System use notifications are required only for access via login interfaces
with human users and are not required when such human interfaces do not
exist.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix id="banner_etc_motd" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

motd_banner_contents=$(echo "<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_motd_banner_contents" use="legacy"/>" | sed 's/\\n/\n/g')
echo "$motd_banner_contents" &gt; /etc/motd

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="banner_etc_motd" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - banner_etc_motd
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
- name: XCCDF Value motd_banner_contents # promote to variable
  set_fact:
    motd_banner_contents: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_motd_banner_contents" use="legacy"/>
  tags:
    - always

- name: Modify the System Message of the Day Banner - ensure correct banner
  ansible.builtin.copy:
    dest: /etc/motd
    content: |
      {{ motd_banner_contents | replace('\n', '
      ') }}
  when: '"kernel" in ansible_facts.packages'
  tags:
  - banner_etc_motd
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-motd_banner_text:var:1" value-id="xccdf_org.ssgproject.content_value_motd_banner_text"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-banner_etc_motd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-banner_etc_motd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_banner_etc_motd_cis" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Message Of The Day Is Configured Properly</xccdf-1.2:title>
              <xccdf-1.2:description>To configure the system message of the day banner edit the <html:code>/etc/motd</html:code> file.
Replace the default text with a message compliant with the local site policy.
The message should not contain information about operating system version,
release, kernel version or patch level.

The recommended banner text can be tailored in the XCCDF Value <html:code>xccdf_org.ssgproject.content_value_cis_banner_text</html:code>:
<html:pre><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_cis_banner_text" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.7.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Warning messages inform users who are attempting to login to the system of their legal
status regarding the system and must include the name of the organization that owns
the system and any monitoring policies that are in place. Displaying OS and patch level
information in login banners also has the side effect of providing detailed system
information to attackers attempting to target specific exploits of a system. Authorized
users can easily get this information by running the <html:code>uname -a</html:code> command once they
have logged in.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="banner_etc_motd_cis" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cis_banner_text='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_cis_banner_text" use="legacy"/>'

echo "$cis_banner_text" &gt; "/etc/motd"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="banner_etc_motd_cis" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - banner_etc_motd_cis
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value cis_banner_text # promote to variable
  set_fact:
    cis_banner_text: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_cis_banner_text" use="legacy"/>
  tags:
    - always

- name: Ensure Message Of The Day Is Configured Properly - Copy using inline content
  ansible.builtin.copy:
    content: '{{ cis_banner_text }}'
    dest: /etc/motd
  when: '"kernel" in ansible_facts.packages'
  tags:
  - banner_etc_motd_cis
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-banner_etc_motd_cis:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-banner_etc_motd_cis_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_etc_issue" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Group Ownership of System Login Banner</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/issue</html:code>, run the command:

  <html:pre>$ sudo chgrp root /etc/issue</html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.7.5</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Display of a standardized and approved use notification before granting
access to the operating system ensures privacy and security notification
verbiage used is consistent with applicable federal laws, Executive Orders,
directives, policies, regulations, standards, and guidance.<html:br/>
Proper group ownership will ensure that only root user can modify the banner.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_issue" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/issue" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/issue
fi

fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_issue" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_groupowner_etc_issue_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_etc_issue_newgroup: '0'
  tags:
  - configure_strategy
  - file_groupowner_etc_issue
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/issue
  ansible.builtin.stat:
    path: /etc/issue
  register: file_exists
  tags:
  - configure_strategy
  - file_groupowner_etc_issue
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/issue
  ansible.builtin.file:
    path: /etc/issue
    follow: false
    group: '{{ file_groupowner_etc_issue_newgroup }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupowner_etc_issue
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_etc_issue:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_etc_issue_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_etc_issue_net" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Group Ownership of System Login Banner for Remote Connections</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/issue.net</html:code>, run the command:

  <html:pre>$ sudo chgrp root /etc/issue.net</html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.7.6</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Display of a standardized and approved use notification before granting
access to the operating system ensures privacy and security notification
verbiage used is consistent with applicable federal laws, Executive Orders,
directives, policies, regulations, standards, and guidance.<html:br/>
Proper group ownership will ensure that only root user can modify the banner.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_issue_net" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/issue.net" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/issue.net
fi

fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_issue_net" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_groupowner_etc_issue_net_newgroup variable if represented by
    gid
  ansible.builtin.set_fact:
    file_groupowner_etc_issue_net_newgroup: '0'
  tags:
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.8
  - configure_strategy
  - file_groupowner_etc_issue_net
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/issue.net
  ansible.builtin.stat:
    path: /etc/issue.net
  register: file_exists
  tags:
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.8
  - configure_strategy
  - file_groupowner_etc_issue_net
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/issue.net
  ansible.builtin.file:
    path: /etc/issue.net
    follow: false
    group: '{{ file_groupowner_etc_issue_net_newgroup }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.8
  - configure_strategy
  - file_groupowner_etc_issue_net
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_etc_issue_net:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_etc_issue_net_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_etc_motd" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Group Ownership of Message of the Day Banner</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/motd</html:code>, run the command:

  <html:pre>$ sudo chgrp root /etc/motd</html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.7.4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Display of a standardized and approved use notification before granting
access to the operating system ensures privacy and security notification
verbiage used is consistent with applicable federal laws, Executive Orders,
directives, policies, regulations, standards, and guidance.<html:br/>
Proper group ownership will ensure that only root user can modify the banner.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_motd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/motd" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/motd
fi

fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_motd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_groupowner_etc_motd_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_etc_motd_newgroup: '0'
  tags:
  - configure_strategy
  - file_groupowner_etc_motd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/motd
  ansible.builtin.stat:
    path: /etc/motd
  register: file_exists
  tags:
  - configure_strategy
  - file_groupowner_etc_motd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/motd
  ansible.builtin.file:
    path: /etc/motd
    follow: false
    group: '{{ file_groupowner_etc_motd_newgroup }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupowner_etc_motd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_etc_motd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_etc_motd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_etc_issue" selected="false" severity="medium">
              <xccdf-1.2:title>Verify ownership of System Login Banner</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the owner of <html:code>/etc/issue</html:code>, run the command:

  <html:pre>$ sudo chown root /etc/issue </html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.7.5</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Display of a standardized and approved use notification before granting
access to the operating system ensures privacy and security notification
verbiage used is consistent with applicable federal laws, Executive Orders,
directives, policies, regulations, standards, and guidance.<html:br/>
Proper ownership will ensure that only root user can modify the banner.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_issue" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/issue" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/issue
fi

fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_issue" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_owner_etc_issue_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_etc_issue_newown: '0'
  tags:
  - configure_strategy
  - file_owner_etc_issue
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/issue
  ansible.builtin.stat:
    path: /etc/issue
  register: file_exists
  tags:
  - configure_strategy
  - file_owner_etc_issue
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/issue
  ansible.builtin.file:
    path: /etc/issue
    follow: false
    owner: '{{ file_owner_etc_issue_newown }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_owner_etc_issue
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_etc_issue:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_etc_issue_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_etc_issue_net" selected="false" severity="medium">
              <xccdf-1.2:title>Verify ownership of System Login Banner for Remote Connections</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the owner of <html:code>/etc/issue.net</html:code>, run the command:

  <html:pre>$ sudo chown root /etc/issue.net </html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.7.6</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Display of a standardized and approved use notification before granting
access to the operating system ensures privacy and security notification
verbiage used is consistent with applicable federal laws, Executive Orders,
directives, policies, regulations, standards, and guidance.<html:br/>
Proper ownership will ensure that only root user can modify the banner.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_issue_net" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/issue.net" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/issue.net
fi

fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_issue_net" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_owner_etc_issue_net_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_etc_issue_net_newown: '0'
  tags:
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.8
  - configure_strategy
  - file_owner_etc_issue_net
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/issue.net
  ansible.builtin.stat:
    path: /etc/issue.net
  register: file_exists
  tags:
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.8
  - configure_strategy
  - file_owner_etc_issue_net
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/issue.net
  ansible.builtin.file:
    path: /etc/issue.net
    follow: false
    owner: '{{ file_owner_etc_issue_net_newown }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.8
  - configure_strategy
  - file_owner_etc_issue_net
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_etc_issue_net:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_etc_issue_net_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_etc_motd" selected="false" severity="medium">
              <xccdf-1.2:title>Verify ownership of Message of the Day Banner</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the owner of <html:code>/etc/motd</html:code>, run the command:

  <html:pre>$ sudo chown root /etc/motd </html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.7.4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Display of a standardized and approved use notification before granting
access to the operating system ensures privacy and security notification
verbiage used is consistent with applicable federal laws, Executive Orders,
directives, policies, regulations, standards, and guidance.<html:br/>
Proper ownership will ensure that only root user can modify the banner.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_motd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/motd" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/motd
fi

fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_motd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_owner_etc_motd_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_etc_motd_newown: '0'
  tags:
  - configure_strategy
  - file_owner_etc_motd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/motd
  ansible.builtin.stat:
    path: /etc/motd
  register: file_exists
  tags:
  - configure_strategy
  - file_owner_etc_motd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/motd
  ansible.builtin.file:
    path: /etc/motd
    follow: false
    owner: '{{ file_owner_etc_motd_newown }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_owner_etc_motd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_etc_motd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_etc_motd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_issue" selected="false" severity="medium">
              <xccdf-1.2:title>Verify permissions on System Login Banner</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/issue</html:code>, run the command:
<html:pre>$ sudo chmod 0644 /etc/issue</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.7.5</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Display of a standardized and approved use notification before granting
access to the operating system ensures privacy and security notification
verbiage used is consistent with applicable federal laws, Executive Orders,
directives, policies, regulations, standards, and guidance.<html:br/>
Proper permissions will ensure that only root user can modify the banner.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_issue" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



chmod u-xs,g-xws,o-xwt /etc/issue
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_issue" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Test for existence /etc/issue
  ansible.builtin.stat:
    path: /etc/issue
  register: file_exists
  tags:
  - configure_strategy
  - file_permissions_etc_issue
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xws,o-xwt on /etc/issue
  ansible.builtin.file:
    path: /etc/issue
    mode: u-xs,g-xws,o-xwt
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_etc_issue
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_issue:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_issue_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_issue_net" selected="false" severity="medium">
              <xccdf-1.2:title>Verify permissions on System Login Banner for Remote Connections</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/issue.net</html:code>, run the command:
<html:pre>$ sudo chmod 0644 /etc/issue.net</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.7.6</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Display of a standardized and approved use notification before granting
access to the operating system ensures privacy and security notification
verbiage used is consistent with applicable federal laws, Executive Orders,
directives, policies, regulations, standards, and guidance.<html:br/>
Proper permissions will ensure that only root user can modify the banner.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_issue_net" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



chmod u-xs,g-xws,o-xwt /etc/issue.net
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_issue_net" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Test for existence /etc/issue.net
  ansible.builtin.stat:
    path: /etc/issue.net
  register: file_exists
  tags:
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.8
  - configure_strategy
  - file_permissions_etc_issue_net
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xws,o-xwt on /etc/issue.net
  ansible.builtin.file:
    path: /etc/issue.net
    mode: u-xs,g-xws,o-xwt
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.8
  - configure_strategy
  - file_permissions_etc_issue_net
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_issue_net:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_issue_net_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_motd" selected="false" severity="medium">
              <xccdf-1.2:title>Verify permissions on Message of the Day Banner</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/motd</html:code>, run the command:
<html:pre>$ sudo chmod 0644 /etc/motd</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.7.4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Display of a standardized and approved use notification before granting
access to the operating system ensures privacy and security notification
verbiage used is consistent with applicable federal laws, Executive Orders,
directives, policies, regulations, standards, and guidance.<html:br/>
Proper permissions will ensure that only root user can modify the banner.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_motd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



chmod u-xs,g-xws,o-xwt /etc/motd
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_motd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Test for existence /etc/motd
  ansible.builtin.stat:
    path: /etc/motd
  register: file_exists
  tags:
  - configure_strategy
  - file_permissions_etc_motd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xws,o-xwt on /etc/motd
  ansible.builtin.file:
    path: /etc/motd
    mode: u-xs,g-xws,o-xwt
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_etc_motd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_motd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_motd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_gui_login_banner">
              <xccdf-1.2:title>Implement a GUI Warning Banner</xccdf-1.2:title>
              <xccdf-1.2:description>In the default graphical environment, users logging
directly into the system are greeted with a login screen provided
by the GNOME Display Manager (GDM). The warning banner should be
displayed in this graphical environment for these users.
The following sections describe how to configure the GDM login
banner.</xccdf-1.2:description>
              <xccdf-1.2:platform idref="#package_gdm"/>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_banner_enabled" selected="false" severity="medium">
                <xccdf-1.2:title>Enable GNOME3 Login Warning Banner</xccdf-1.2:title>
                <xccdf-1.2:description>In the default graphical environment, displaying a login warning banner
in the GNOME Display Manager's login screen can be enabled on the login
screen by setting <html:code>banner-message-enable</html:code> to <html:code>true</html:code>.
<html:br/><html:br/>
To enable, add or edit <html:code>banner-message-enable</html:code> to
<html:code>/etc/dconf/db/gdm.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/login-screen]
banner-message-enable=true</html:pre>
Once the setting has been added, add a lock to
<html:code>/etc/dconf/db/gdm.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/login-screen/banner-message-enable</html:pre>
After the settings have been set, run <html:code>dconf update</html:code>.
The banner text must also be set.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-8(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-8(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-8(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000023-GPOS-00006</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000228-GPOS-00088</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.8.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010049</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244519r1017326_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Display of a standardized and approved use notification before granting access to the operating system
ensures privacy and security notification verbiage used is consistent with applicable federal laws,
Executive Orders, directives, policies, regulations, standards, and guidance.
<html:br/><html:br/>
For U.S. Government systems, system use notifications are required only for access via login interfaces
with human users and are not required when such human interfaces do not exist.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_banner_enabled" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/login-screen\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|gdm.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/gdm.d/00-security-settings"
DBDIR="/etc/dconf/db/gdm.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*banner-message-enable\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)banner-message-enable(\s*=)/#\1banner-message-enable\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/login-screen\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/login-screen]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "true")"
if grep -q "^\\s*banner-message-enable\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*banner-message-enable\\s*=\\s*.*/banner-message-enable=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/login-screen\\]|a\\banner-message-enable=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/login-screen/banner-message-enable$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|gdm.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/gdm.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/login-screen/banner-message-enable$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/login-screen/banner-message-enable$" /etc/dconf/db/gdm.d/
then
    echo "/org/gnome/login-screen/banner-message-enable" &gt;&gt; "/etc/dconf/db/gdm.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_banner_enabled" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010049
  - NIST-800-171-3.1.9
  - NIST-800-53-AC-8(a)
  - NIST-800-53-AC-8(b)
  - NIST-800-53-AC-8(c)
  - dconf_gnome_banner_enabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Enable GNOME3 Login Warning Banner
  community.general.ini_file:
    dest: /etc/dconf/db/gdm.d/00-security-settings
    section: org/gnome/login-screen
    option: banner-message-enable
    value: 'true'
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010049
  - NIST-800-171-3.1.9
  - NIST-800-53-AC-8(a)
  - NIST-800-53-AC-8(b)
  - NIST-800-53-AC-8(c)
  - dconf_gnome_banner_enabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of GNOME banner-message-enabled
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/gdm.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/login-screen/banner-message-enable$
    line: /org/gnome/login-screen/banner-message-enable
    create: true
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010049
  - NIST-800-171-3.1.9
  - NIST-800-53-AC-8(a)
  - NIST-800-53-AC-8(b)
  - NIST-800-53-AC-8(c)
  - dconf_gnome_banner_enabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - DISA-STIG-RHEL-08-010049
  - NIST-800-171-3.1.9
  - NIST-800-53-AC-8(a)
  - NIST-800-53-AC-8(b)
  - NIST-800-53-AC-8(c)
  - dconf_gnome_banner_enabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_banner_enabled:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_banner_enabled_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dconf_gnome_login_banner_text" selected="false" severity="medium">
                <xccdf-1.2:title>Set the GNOME3 Login Warning Banner Text</xccdf-1.2:title>
                <xccdf-1.2:description>In the default graphical environment, configuring the login warning banner text
in the GNOME Display Manager's login screen can be configured on the login
screen by setting <html:code>banner-message-text</html:code> to <html:code>'<html:i>APPROVED_BANNER</html:i>'</html:code>
where <html:i>APPROVED_BANNER</html:i> is the approved banner for your environment.
<html:br/><html:br/>
To enable, add or edit <html:code>banner-message-text</html:code> to

<html:code>/etc/dconf/db/gdm.d/00-security-settings</html:code>. For example:
<html:pre>[org/gnome/login-screen]
banner-message-text='<html:i>APPROVED_BANNER</html:i>'</html:pre>
Once the setting has been added, add a lock to
<html:code>/etc/dconf/db/gdm.d/locks/00-security-settings-lock</html:code> to prevent user modification.
For example:
<html:pre>/org/gnome/login-screen/banner-message-text</html:pre>

After the settings have been set, run <html:code>dconf update</html:code>.
When entering a warning banner that spans several lines, remember
to begin and end the string with <html:code>'</html:code> and use <html:code>\n</html:code> for new lines.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-8(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-8(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000023-GPOS-00006</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000228-GPOS-00088</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.8.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010050</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230226r1069298_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>An appropriate warning message reinforces policy awareness during the logon
process and facilitates possible legal action against attackers.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="dconf_gnome_login_banner_text" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q gdm; then

dconf_login_banner_contents=$(echo "<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_dconf_login_banner_contents" use="legacy"/>" )
# Check for setting in any of the DConf db directories
# If files contain ibus or distro, ignore them.
# The assignment assumes that individual filenames don't contain :
readarray -t SETTINGSFILES &lt; &lt;(grep -r "\\[org/gnome/login-screen\\]" "/etc/dconf/db/" \
                                | grep -v 'distro\|ibus\|gdm.d' | cut -d":" -f1)
DCONFFILE="/etc/dconf/db/gdm.d/00-security-settings"
DBDIR="/etc/dconf/db/gdm.d"

mkdir -p "${DBDIR}"

# Comment out the configurations in databases different from the target one
if [ "${#SETTINGSFILES[@]}" -ne 0 ]
then
    if grep -q "^\\s*banner-message-text\\s*=" "${SETTINGSFILES[@]}"
    then
        
        sed -Ei "s/(^\s*)banner-message-text(\s*=)/#\1banner-message-text\2/g" "${SETTINGSFILES[@]}"
    fi
fi

[ ! -z "${DCONFFILE}" ] &amp;&amp; echo "" &gt;&gt; "${DCONFFILE}"
if ! grep -q "\\[org/gnome/login-screen\\]" "${DCONFFILE}"
then
    printf '%s\n' "[org/gnome/login-screen]" &gt;&gt; ${DCONFFILE}
fi

escaped_value="$(sed -e 's/\\/\\\\/g' &lt;&lt;&lt; "'${dconf_login_banner_contents}'")"
if grep -q "^\\s*banner-message-text\\s*=" "${DCONFFILE}"
then
        sed -i "s/\\s*banner-message-text\\s*=\\s*.*/banner-message-text=${escaped_value}/g" "${DCONFFILE}"
    else
        sed -i "\\|\\[org/gnome/login-screen\\]|a\\banner-message-text=${escaped_value}" "${DCONFFILE}"
fi
dconf update
# Check for setting in any of the DConf db directories
LOCKFILES=$(grep -r "^/org/gnome/login-screen/banner-message-text$" "/etc/dconf/db/" \
            | grep -v 'distro\|ibus\|gdm.d' | grep ":" | cut -d":" -f1)
LOCKSFOLDER="/etc/dconf/db/gdm.d/locks"

mkdir -p "${LOCKSFOLDER}"

# Comment out the configurations in databases different from the target one
if [[ ! -z "${LOCKFILES}" ]]
then
    sed -i -E "s|^/org/gnome/login-screen/banner-message-text$|#&amp;|" "${LOCKFILES[@]}"
fi

if ! grep -qr "^/org/gnome/login-screen/banner-message-text$" /etc/dconf/db/gdm.d/
then
    echo "/org/gnome/login-screen/banner-message-text" &gt;&gt; "/etc/dconf/db/gdm.d/locks/00-security-settings-lock"
fi
dconf update

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="dconf_gnome_login_banner_text" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010050
  - NIST-800-171-3.1.9
  - NIST-800-53-AC-8(a)
  - NIST-800-53-AC-8(c)
  - dconf_gnome_login_banner_text
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
- name: XCCDF Value dconf_login_banner_contents # promote to variable
  set_fact:
    dconf_login_banner_contents: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_dconf_login_banner_contents" use="legacy"/>
  tags:
    - always

- name: Set the GNOME3 Login Warning Banner Text
  ansible.builtin.file:
    path: /etc/dconf/db/{{ item }}
    owner: root
    group: root
    mode: 493
    state: directory
  with_items:
  - gdm.d
  - gdm.d/locks
  when: '"gdm" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010050
  - NIST-800-171-3.1.9
  - NIST-800-53-AC-8(a)
  - NIST-800-53-AC-8(c)
  - dconf_gnome_login_banner_text
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Set the GNOME3 Login Warning Banner Text
  ansible.builtin.file:
    path: /etc/dconf/db/gdm.d/{{ item }}
    owner: root
    group: root
    mode: 420
    state: touch
  with_items:
  - 00-security-settings
  - locks/00-security-settings-lock
  when: '"gdm" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010050
  - NIST-800-171-3.1.9
  - NIST-800-53-AC-8(a)
  - NIST-800-53-AC-8(c)
  - dconf_gnome_login_banner_text
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Set the GNOME3 Login Warning Banner Text
  community.general.ini_file:
    dest: /etc/dconf/db/gdm.d/00-security-settings
    section: org/gnome/login-screen
    option: banner-message-text
    value: '''{{ dconf_login_banner_contents }}'''
    create: true
    no_extra_spaces: true
  register: result_ini
  when: '"gdm" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010050
  - NIST-800-171-3.1.9
  - NIST-800-53-AC-8(a)
  - NIST-800-53-AC-8(c)
  - dconf_gnome_login_banner_text
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Prevent user modification of the GNOME3 Login Warning Banner Text
  ansible.builtin.lineinfile:
    path: /etc/dconf/db/gdm.d/locks/00-security-settings-lock
    regexp: ^/org/gnome/login-screen/banner-message-text$
    line: /org/gnome/login-screen/banner-message-text
    create: true
    state: present
  register: result_lineinfile
  when: '"gdm" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010050
  - NIST-800-171-3.1.9
  - NIST-800-53-AC-8(a)
  - NIST-800-53-AC-8(c)
  - dconf_gnome_login_banner_text
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy

- name: Dconf Update
  ansible.builtin.command: dconf update
  when:
  - '"gdm" in ansible_facts.packages'
  - result_ini is changed or result_lineinfile is changed
  tags:
  - DISA-STIG-RHEL-08-010050
  - NIST-800-171-3.1.9
  - NIST-800-53-AC-8(a)
  - NIST-800-53-AC-8(c)
  - dconf_gnome_login_banner_text
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-dconf_login_banner_text:var:1" value-id="xccdf_org.ssgproject.content_value_dconf_login_banner_text"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dconf_gnome_login_banner_text:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dconf_gnome_login_banner_text_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_accounts-pam">
            <xccdf-1.2:title>Protect Accounts by Configuring PAM</xccdf-1.2:title>
            <xccdf-1.2:description>PAM, or Pluggable Authentication Modules, is a system
which implements modular authentication for Linux programs. PAM provides
a flexible and configurable architecture for authentication, and it should be configured
to minimize exposure to unnecessary risk. This section contains
guidance on how to accomplish that.
<html:br/><html:br/>
PAM is implemented as a set of shared objects which are
loaded and invoked whenever an application wishes to authenticate a
user. Typically, the application must be running as root in order
to take advantage of PAM, because PAM's modules often need to be able
to access sensitive stores of account information, such as /etc/shadow.
Traditional privileged network listeners
(e.g. sshd) or SUID programs (e.g. sudo) already meet this
requirement. An SUID root application, userhelper, is provided so
that programs which are not SUID or privileged themselves can still
take advantage of PAM.
<html:br/><html:br/>
PAM looks in the directory <html:code>/etc/pam.d</html:code> for
application-specific configuration information. For instance, if
the program login attempts to authenticate a user, then PAM's
libraries follow the instructions in the file <html:code>/etc/pam.d/login</html:code>
to determine what actions should be taken.
<html:br/><html:br/>
One very important file in <html:code>/etc/pam.d</html:code> is
<html:code>/etc/pam.d/system-auth</html:code>. This file, which is included by
many other PAM configuration files, defines 'default' system authentication
measures. Modifying this file is a good way to make far-reaching
authentication changes, for instance when implementing a
centralized authentication service.</xccdf-1.2:description>
            <xccdf-1.2:warning category="functionality">Be careful when making changes to PAM's configuration files.
The syntax for these files is complex, and modifications can
have unexpected consequences. The default configurations shipped
with applications should be sufficient for most users.</xccdf-1.2:warning>
            <xccdf-1.2:warning category="functionality">Running <html:code>authconfig</html:code> or <html:code>system-config-authentication</html:code>
will re-write the PAM configuration files, destroying any manually
made changes and replacing them with a series of system defaults.
One reference to the configuration file syntax can be found at

<html:a href="https://fossies.org/linux/Linux-PAM-docs/doc/sag/Linux-PAM_SAG.pdf">https://fossies.org/linux/Linux-PAM-docs/doc/sag/Linux-PAM_SAG.pdf</html:a>.</xccdf-1.2:warning>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm" type="string">
              <xccdf-1.2:title>Password Hashing algorithm</xccdf-1.2:title>
              <xccdf-1.2:description>Specify the system default encryption algorithm for encrypting passwords.
Defines the value set as ENCRYPT_METHOD in /etc/login.defs.</xccdf-1.2:description>
              <xccdf-1.2:value>SHA512</xccdf-1.2:value>
              <xccdf-1.2:value selector="SHA512">SHA512</xccdf-1.2:value>
              <xccdf-1.2:value selector="SHA256">SHA256</xccdf-1.2:value>
              <xccdf-1.2:value selector="yescrypt">YESCRYPT</xccdf-1.2:value>
              <xccdf-1.2:value selector="cis_ubuntu2204">SHA512|YESCRYPT</xccdf-1.2:value>
              <xccdf-1.2:value selector="cis_ubuntu2404">SHA512|YESCRYPT</xccdf-1.2:value>
              <xccdf-1.2:value selector="cis_rhel8">YESCRYPT|SHA512</xccdf-1.2:value>
              <xccdf-1.2:value selector="cis_rhel10">YESCRYPT|SHA512</xccdf-1.2:value>
              <xccdf-1.2:value selector="cis_fedora">YESCRYPT|SHA512</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" type="string">
              <xccdf-1.2:title>Password Hashing algorithm for pam_unix.so</xccdf-1.2:title>
              <xccdf-1.2:description>Specify the system default encryption algorithm for encrypting passwords.
Defines the hashing algorithm to be used in pam_unix.so.</xccdf-1.2:description>
              <xccdf-1.2:value>sha512</xccdf-1.2:value>
              <xccdf-1.2:value selector="sha512">sha512</xccdf-1.2:value>
              <xccdf-1.2:value selector="yescrypt">yescrypt</xccdf-1.2:value>
              <xccdf-1.2:value selector="cis_rhel8">yescrypt|sha512</xccdf-1.2:value>
              <xccdf-1.2:value selector="cis_rhel10">yescrypt|sha512</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_pam_unix_remember" type="number">
              <xccdf-1.2:title>remember</xccdf-1.2:title>
              <xccdf-1.2:description>The last n passwords for each user are saved in
<html:code>/etc/security/opasswd</html:code> in order to force password change history and
keep the user from alternating between the same password too
frequently.</xccdf-1.2:description>
              <xccdf-1.2:value selector="0">0</xccdf-1.2:value>
              <xccdf-1.2:value selector="10">10</xccdf-1.2:value>
              <xccdf-1.2:value selector="24">24</xccdf-1.2:value>
              <xccdf-1.2:value selector="2">2</xccdf-1.2:value>
              <xccdf-1.2:value selector="4">4</xccdf-1.2:value>
              <xccdf-1.2:value selector="5">5</xccdf-1.2:value>
              <xccdf-1.2:value>5</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_authselect_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install authselect Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>authselect</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install authselect</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.1.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>authselect</html:code> package provides a tool to select system authentication and
identity sources from a list of supported profiles instead of letting the administrator
manually build the PAM stack. Authselect is a successor to authconfig and helps avoid
potential breakage of configuration by shipping several tested profiles that are well
tested and supported. Ensuring the latest version of authselect is installed helps
maintain system security by providing the latest security fixes and features.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_authselect_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh">
if ! rpm -q --quiet "authselect" ; then
    yum install -y "authselect"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_authselect_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Ensure authselect is installed
  ansible.builtin.package:
    name: authselect
    state: present
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_authselect_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_authselect_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_authselect

class install_authselect {
  package { 'authselect':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_authselect_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=authselect
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_authselect_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "authselect"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_authselect_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install authselect
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_authselect_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install authselect
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_authselect_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_authselect_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_pam_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install pam Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>pam</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install pam</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.1.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>pam</html:code> package provides Pluggable Authentication Modules (PAM) which
is a system for authenticating users. PAM provides a flexible and centralized
way to manage authentication methods for applications and services. Ensuring
the latest version of pam is installed helps maintain system security by
providing the latest security fixes and features.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pam_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh">
if ! rpm -q --quiet "pam" ; then
    yum install -y "pam"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pam_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Ensure pam is installed
  ansible.builtin.package:
    name: pam
    state: present
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_pam_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pam_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_pam

class install_pam {
  package { 'pam':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pam_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=pam
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_pam_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "pam"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pam_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install pam
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pam_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install pam
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_pam_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_pam_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install pam_pwquality Package</xccdf-1.2:title>
              <xccdf-1.2:description>
The <html:code>libpwquality</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install libpwquality</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00225</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.2.3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Use of a complex password helps to increase the time and resources required
to compromise the password. Password complexity, or strength, is a measure
of the effectiveness of a password in resisting attempts at guessing and
brute-force attacks. "pwquality" enforces complex password construction
configuration and has the ability to limit brute-force attacks on the system.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_pam"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pam_pwquality_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q pam; then

if ! rpm -q --quiet "libpwquality" ; then
    yum install -y "libpwquality"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pam_pwquality_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_pam_pwquality_installed

- name: Ensure libpwquality is installed
  ansible.builtin.package:
    name: libpwquality
    state: present
  when: '"pam" in ansible_facts.packages'
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_pam_pwquality_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pam_pwquality_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_libpwquality

class install_libpwquality {
  package { 'libpwquality':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pam_pwquality_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=libpwquality
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_pam_pwquality_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "libpwquality"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pam_pwquality_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install libpwquality
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_pam_pwquality_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install libpwquality
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_pam_pwquality_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_pam_pwquality_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_modules_in_authselect_profile" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Active Authselect Profile Includes PAM Modules</xccdf-1.2:title>
              <xccdf-1.2:description>The active authselect profile must include the required PAM modules:
<html:code>pam_pwquality.so</html:code>, <html:code>pam_pwhistory.so</html:code>, <html:code>pam_faillock.so</html:code>, and <html:code>pam_unix.so</html:code>
in both <html:code>system-auth</html:code> and <html:code>password-auth</html:code> files.

A custom authselect profile can be created by copying and customizing one of the default profiles.
The default profiles include: <html:code>local</html:code>, <html:code>sssd</html:code>, and <html:code>winbind</html:code>. These profiles can be customized
to follow site specific requirements.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">If local site customizations have been made to the authselect template or files in
/etc/pam.d, these custom entries should be added to the newly created custom profile
before it's applied to the system. The order within the PAM stacks is important when
adding these entries.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.2.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>A custom profile is required to customize many of the PAM options.
Modifications made to a default profile may be overwritten during an update.
When you deploy a profile, the profile is applied to every user logging into the given host.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_pam"/>
              <xccdf-1.2:fix id="accounts_password_pam_modules_in_authselect_profile" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q pam; then

if ! authselect check; then
echo "
authselect integrity check failed. Remediation aborted!
This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
It is not recommended to manually edit the PAM files when authselect tool is available.
In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
exit 1
fi

CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
# If not already in use, a custom profile is created preserving the enabled features.
if [[ ! $CURRENT_PROFILE == custom/* ]]; then
    ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
    # The "local" profile does not contain essential security features required by multiple Benchmarks.
    # If currently used, it is replaced by "sssd", which is the best option in this case.
    if [[ $CURRENT_PROFILE == local ]]; then
        CURRENT_PROFILE="sssd"
    fi
    authselect create-profile hardening -b $CURRENT_PROFILE
    CURRENT_PROFILE="custom/hardening"
    
    authselect apply-changes -b --backup=before-hardening-custom-profile
    authselect select $CURRENT_PROFILE
    for feature in $ENABLED_FEATURES; do
        authselect enable-feature $feature;
    done
    
    authselect apply-changes -b --backup=after-hardening-custom-profile
fi

# Function to add a missing PAM module to a file
# This function handles module placement based on typical PAM stack ordering
add_pam_module() {
    local authselect_file="$1"
    local module="$2"

    # Check if module already exists in any group
    if grep -Pq "^\s*\S+\s+\S+\s+$module" "$authselect_file"; then
        return 0
    fi

    # Special handling for pam_faillock.so - needs entries in auth and account groups
    if [ "$module" = "pam_faillock.so" ]; then
        # Add preauth entry in auth section (at the beginning of auth section)
        if ! grep -Pq "^\s*auth\s+\S+\s+$module" "$authselect_file"; then
            if grep -qP "^auth" "$authselect_file"; then
                FIRST_AUTH_LINE=$(grep -nP "^auth" "$authselect_file" | head -n 1 | cut -d: -f 1)
                if [ ! -z "$FIRST_AUTH_LINE" ]; then
                    sed -i --follow-symlinks "${FIRST_AUTH_LINE}i auth     required    pam_faillock.so preauth" "$authselect_file"
                fi
            else
                # If no auth section exists, create it at the beginning
                sed -i --follow-symlinks "1i auth     required    pam_faillock.so preauth" "$authselect_file"
            fi
        fi
        # Add entry in account section
        if ! grep -Pq "^\s*account\s+\S+\s+$module" "$authselect_file"; then
            if grep -qP "^account" "$authselect_file"; then
                FIRST_ACCOUNT_LINE=$(grep -nP "^account" "$authselect_file" | head -n 1 | cut -d: -f 1)
                if [ ! -z "$FIRST_ACCOUNT_LINE" ]; then
                    sed -i --follow-symlinks "${FIRST_ACCOUNT_LINE}a account     required    pam_faillock.so" "$authselect_file"
                fi
            else
                # If no account section exists, add it after auth section
                if grep -qP "^auth" "$authselect_file"; then
                    LAST_AUTH_LINE=$(grep -nP "^auth" "$authselect_file" | tail -n 1 | cut -d: -f 1)
                    if [ ! -z "$LAST_AUTH_LINE" ]; then
                        sed -i --follow-symlinks "${LAST_AUTH_LINE}a account     required    pam_faillock.so" "$authselect_file"
                    fi
                else
                    echo "account     required    pam_faillock.so" &gt;&gt; "$authselect_file"
                fi
            fi
        fi
        return 0
    fi

    # Handle pam_pwquality.so - goes in password section, before other password modules
    if [ "$module" = "pam_pwquality.so" ]; then
        if grep -qP "^password" "$authselect_file"; then
            FIRST_PASSWORD_LINE=$(grep -nP "^password" "$authselect_file" | head -n 1 | cut -d: -f 1)
            if [ ! -z "$FIRST_PASSWORD_LINE" ]; then
                sed -i --follow-symlinks "${FIRST_PASSWORD_LINE}i password     requisite    pam_pwquality.so" "$authselect_file"
            fi
        else
            # If no password section exists, add it after account section
            if grep -qP "^account" "$authselect_file"; then
                LAST_ACCOUNT_LINE=$(grep -nP "^account" "$authselect_file" | tail -n 1 | cut -d: -f 1)
                if [ ! -z "$LAST_ACCOUNT_LINE" ]; then
                    sed -i --follow-symlinks "${LAST_ACCOUNT_LINE}a password     requisite    pam_pwquality.so" "$authselect_file"
                fi
            else
                echo "password     requisite    pam_pwquality.so" &gt;&gt; "$authselect_file"
            fi
        fi
        return 0
    fi

    # Handle pam_pwhistory.so - goes in password section, after pam_pwquality
    if [ "$module" = "pam_pwhistory.so" ]; then
        if grep -qP "pam_pwquality\.so" "$authselect_file"; then
            # Add after pam_pwquality
            PWQUALITY_LINE=$(grep -nP "pam_pwquality\.so" "$authselect_file" | tail -n 1 | cut -d: -f 1)
            if [ ! -z "$PWQUALITY_LINE" ]; then
                sed -i --follow-symlinks "${PWQUALITY_LINE}a password     requisite    pam_pwhistory.so" "$authselect_file"
            fi
        elif grep -qP "^password" "$authselect_file"; then
            # Add at the beginning of password section if pam_pwquality not found
            FIRST_PASSWORD_LINE=$(grep -nP "^password" "$authselect_file" | head -n 1 | cut -d: -f 1)
            if [ ! -z "$FIRST_PASSWORD_LINE" ]; then
                sed -i --follow-symlinks "${FIRST_PASSWORD_LINE}i password     requisite    pam_pwhistory.so" "$authselect_file"
            fi
        else
            echo "password     requisite    pam_pwhistory.so" &gt;&gt; "$authselect_file"
        fi
        return 0
    fi

    # Handle pam_unix.so - typically appears in multiple groups (auth, account, password, session)
    # We'll add it to password group if missing, as that's most critical for this rule
    if [ "$module" = "pam_unix.so" ]; then
        # Check if it exists in password group
        if ! grep -Pq "^\s*password\s+\S+\s+$module" "$authselect_file"; then
            if grep -qP "pam_pwhistory\.so" "$authselect_file"; then
                # Add after pam_pwhistory
                PWHISTORY_LINE=$(grep -nP "pam_pwhistory\.so" "$authselect_file" | tail -n 1 | cut -d: -f 1)
                if [ ! -z "$PWHISTORY_LINE" ]; then
                    sed -i --follow-symlinks "${PWHISTORY_LINE}a password     sufficient    pam_unix.so" "$authselect_file"
                fi
            elif grep -qP "^password" "$authselect_file"; then
                # Add at the end of password section
                LAST_PASSWORD_LINE=$(grep -nP "^password" "$authselect_file" | tail -n 1 | cut -d: -f 1)
                if [ ! -z "$LAST_PASSWORD_LINE" ]; then
                    sed -i --follow-symlinks "${LAST_PASSWORD_LINE}a password     sufficient    pam_unix.so" "$authselect_file"
                fi
            else
                echo "password     sufficient    pam_unix.so" &gt;&gt; "$authselect_file"
            fi
        fi
        return 0
    fi
}

# Check and ensure modules are present in both system-auth and password-auth
pam_profile="$(head -1 /etc/authselect/authselect.conf)"
pam_profile_path="/etc/authselect/$pam_profile"
for authselect_file in "$pam_profile_path"/system-auth "$pam_profile_path"/password-auth; do
    if [ ! -f "$authselect_file" ]; then
        echo "Warning: $authselect_file not found"
        continue
    fi
    for module in pam_pwquality.so pam_pwhistory.so pam_faillock.so pam_unix.so; do
        if ! grep -Pq "^\s*\S+\s+\S+\s+$module" "$authselect_file"; then
            add_pam_module "$authselect_file" "$module"
        fi
    done
done

authselect apply-changes

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_modules_in_authselect_profile" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Active Authselect Profile Includes PAM Modules - Check integrity of
    authselect current profile
  ansible.builtin.command:
    cmd: authselect check
  register: result_authselect_check_cmd
  changed_when: false
  check_mode: false
  failed_when: false
  when: '"pam" in ansible_facts.packages'
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Active Authselect Profile Includes PAM Modules - Informative message
    based on the authselect integrity check result
  ansible.builtin.assert:
    that:
    - ansible_check_mode or result_authselect_check_cmd.rc == 0
    fail_msg:
    - authselect integrity check failed. Remediation aborted!
    - This remediation could not be applied because an authselect profile was not
      selected or the selected profile is not intact.
    - It is not recommended to manually edit the PAM files when authselect tool is
      available.
    - In cases where the default authselect profile does not cover a specific demand,
      a custom authselect profile is recommended.
    success_msg:
    - authselect integrity check passed
  when: '"pam" in ansible_facts.packages'
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Active Authselect Profile Includes PAM Modules - Get authselect current
    profile
  ansible.builtin.shell:
    cmd: authselect current -r | awk '{ print $1 }'
  register: result_authselect_profile
  changed_when: false
  when:
  - '"pam" in ansible_facts.packages'
  - result_authselect_check_cmd is success
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Active Authselect Profile Includes PAM Modules - Define the current
    authselect profile as a local fact
  ansible.builtin.set_fact:
    authselect_current_profile: '{{ result_authselect_profile.stdout }}'
    authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
  when:
  - '"pam" in ansible_facts.packages'
  - result_authselect_profile is not skipped
  - result_authselect_profile.stdout is match("custom/")
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Active Authselect Profile Includes PAM Modules - Define the new authselect
    custom profile as a local fact
  ansible.builtin.set_fact:
    authselect_current_profile: '{{ result_authselect_profile.stdout }}'
    authselect_custom_profile: custom/hardening
  when:
  - '"pam" in ansible_facts.packages'
  - result_authselect_profile is not skipped
  - result_authselect_profile.stdout is not match("custom/")
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Active Authselect Profile Includes PAM Modules - Get authselect current
    features to also enable them in the custom profile
  ansible.builtin.shell:
    cmd: authselect current | tail -n+3 | awk '{ print $2 }'
  register: result_authselect_features
  changed_when: false
  check_mode: false
  when:
  - '"pam" in ansible_facts.packages'
  - result_authselect_profile is not skipped
  - authselect_current_profile is not match("custom/")
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Active Authselect Profile Includes PAM Modules - Check if any custom
    profile with the same name was already created
  ansible.builtin.stat:
    path: /etc/authselect/{{ authselect_custom_profile }}
  register: result_authselect_custom_profile_present
  changed_when: false
  when:
  - '"pam" in ansible_facts.packages'
  - result_authselect_profile is not skipped
  - authselect_current_profile is not match("custom/")
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Active Authselect Profile Includes PAM Modules - Create an authselect
    custom profile based on the current profile
  ansible.builtin.command:
    cmd: authselect create-profile hardening -b {{ authselect_current_profile }}
  when:
  - '"pam" in ansible_facts.packages'
  - result_authselect_profile is not skipped
  - result_authselect_check_cmd is success
  - authselect_current_profile is not match("^(custom/|local)")
  - not result_authselect_custom_profile_present.stat.exists
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Active Authselect Profile Includes PAM Modules - Create an authselect
    custom profile based on sssd profile
  ansible.builtin.command:
    cmd: authselect create-profile hardening -b sssd
  when:
  - '"pam" in ansible_facts.packages'
  - result_authselect_profile is not skipped
  - result_authselect_check_cmd is success
  - authselect_current_profile is match("local")
  - not result_authselect_custom_profile_present.stat.exists
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Active Authselect Profile Includes PAM Modules - Ensure authselect
    changes are applied
  ansible.builtin.command:
    cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
  when:
  - '"pam" in ansible_facts.packages'
  - result_authselect_check_cmd is success
  - result_authselect_profile is not skipped
  - authselect_current_profile is not match("custom/")
  - authselect_custom_profile is not match(authselect_current_profile)
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Active Authselect Profile Includes PAM Modules - Ensure the authselect
    custom profile is selected
  ansible.builtin.command:
    cmd: authselect select {{ authselect_custom_profile }}
  register: result_pam_authselect_select_profile
  when:
  - '"pam" in ansible_facts.packages'
  - result_authselect_check_cmd is success
  - result_authselect_profile is not skipped
  - authselect_current_profile is not match("custom/")
  - authselect_custom_profile is not match(authselect_current_profile)
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Active Authselect Profile Includes PAM Modules - Restore the authselect
    features in the custom profile
  ansible.builtin.command:
    cmd: authselect enable-feature {{ item }}
  loop: '{{ result_authselect_features.stdout_lines }}'
  register: result_pam_authselect_restore_features
  when:
  - '"pam" in ansible_facts.packages'
  - result_authselect_profile is not skipped
  - result_authselect_features is not skipped
  - result_pam_authselect_select_profile is not skipped
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Active Authselect Profile Includes PAM Modules - Ensure authselect
    changes are applied
  ansible.builtin.command:
    cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
  when:
  - '"pam" in ansible_facts.packages'
  - result_authselect_check_cmd is success
  - result_authselect_profile is not skipped
  - result_pam_authselect_restore_features is not skipped
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Active Authselect Profile Includes PAM Modules - Get authselect current
    profile
  ansible.builtin.command: head -1 /etc/authselect/authselect.conf
  register: result_authselect_profile_name
  changed_when: false
  when:
  - '"pam" in ansible_facts.packages'
  - result_authselect_check_cmd is success
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Active Authselect Profile Includes PAM Modules - Determine PAM profile
    path
  ansible.builtin.set_fact:
    pam_profile_path: '{%- if result_authselect_profile_name.stdout is match(''^custom/'')
      -%} /etc/authselect/{{ result_authselect_profile_name.stdout }} {%- else -%}
      /usr/share/authselect/default/{{ result_authselect_profile_name.stdout }} {%-
      endif %}'
  when:
  - '"pam" in ansible_facts.packages'
  - result_authselect_check_cmd is success
  - result_authselect_profile_name is not skipped
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Active Authselect Profile Includes PAM Modules - Ensure PAM modules
    are present in system-auth and password-auth
  block:

  - name: Ensure Active Authselect Profile Includes PAM Modules - Check if {{ item
      }} file exists
    ansible.builtin.stat:
      path: '{{ pam_profile_path }}/{{ item }}'
    register: pam_file_stat
    loop:
    - system-auth
    - password-auth
    when:
    - pam_profile_path is defined

  - name: Ensure Active Authselect Profile Includes PAM Modules - Set list of PAM
      files to process
    ansible.builtin.set_fact:
      pam_files_to_process: '{{ pam_file_stat.results | default([]) | selectattr(''stat.exists'',
        ''equalto'', true) | map(attribute=''item'') | list }}'

  - name: Ensure Active Authselect Profile Includes PAM Modules - Check if pam_faillock.so
      exists in auth section of {{ item }}
    ansible.builtin.lineinfile:
      path: '{{ pam_profile_path }}/{{ item }}'
      regexp: ^\s*auth\s+\S+\s+pam_faillock\.so\s+preauth
      state: absent
    check_mode: true
    changed_when: false
    register: pam_faillock_auth_check_result
    loop: '{{ pam_files_to_process | default([]) }}'
    when:
    - item is defined
    - pam_profile_path is defined

  - name: Ensure Active Authselect Profile Includes PAM Modules - Add pam_faillock.so
      preauth entry in auth section of {{ item }}
    ansible.builtin.lineinfile:
      path: '{{ pam_profile_path }}/{{ item }}'
      regexp: ^\s*auth\s+\S+\s+pam_faillock\.so\s+preauth
      insertbefore: ^auth
      line: auth     required    pam_faillock.so preauth
      state: present
    register: pam_faillock_auth_add_result
    loop: '{{ pam_files_to_process | default([]) }}'
    when:
    - item is defined
    - pam_profile_path is defined
    - pam_faillock_auth_check_result.results | selectattr('item', 'equalto', item)
      | map(attribute='found') | first | default(1) == 0

  - name: Ensure Active Authselect Profile Includes PAM Modules - Check if pam_faillock.so
      exists in account section of {{ item }}
    ansible.builtin.lineinfile:
      path: '{{ pam_profile_path }}/{{ item }}'
      regexp: ^\s*account\s+\S+\s+pam_faillock\.so
      state: absent
    check_mode: true
    changed_when: false
    register: pam_faillock_account_check_result
    loop: '{{ pam_files_to_process | default([]) }}'
    when:
    - item is defined
    - pam_profile_path is defined

  - name: Ensure Active Authselect Profile Includes PAM Modules - Add pam_faillock.so
      entry in account section of {{ item }}
    ansible.builtin.lineinfile:
      path: '{{ pam_profile_path }}/{{ item }}'
      regexp: ^\s*account\s+\S+\s+pam_faillock\.so
      insertafter: ^account
      line: account     required    pam_faillock.so
      state: present
    register: pam_faillock_account_add_result
    loop: '{{ pam_files_to_process | default([]) }}'
    when:
    - item is defined
    - pam_profile_path is defined
    - pam_faillock_account_check_result.results | selectattr('item', 'equalto', item)
      | map(attribute='found') | first | default(1) == 0

  - name: Ensure Active Authselect Profile Includes PAM Modules - Check if pam_pwquality.so
      exists in {{ item }}
    ansible.builtin.lineinfile:
      path: '{{ pam_profile_path }}/{{ item }}'
      regexp: ^\s*password\s+\S+\s+pam_pwquality\.so
      state: absent
    check_mode: true
    changed_when: false
    register: pam_pwquality_check_result
    loop: '{{ pam_files_to_process | default([]) }}'
    when:
    - item is defined
    - pam_profile_path is defined

  - name: Ensure Active Authselect Profile Includes PAM Modules - Add pam_pwquality.so
      entry in password section of {{ item }}
    ansible.builtin.lineinfile:
      path: '{{ pam_profile_path }}/{{ item }}'
      regexp: ^\s*password\s+\S+\s+pam_pwquality\.so
      insertbefore: ^password
      line: password     requisite    pam_pwquality.so
      state: present
    register: pam_pwquality_add_result
    loop: '{{ pam_files_to_process | default([]) }}'
    when:
    - item is defined
    - pam_profile_path is defined
    - pam_pwquality_check_result.results | selectattr('item', 'equalto', item) | map(attribute='found')
      | first | default(1) == 0

  - name: Ensure Active Authselect Profile Includes PAM Modules - Check if pam_pwhistory.so
      exists in {{ item }}
    ansible.builtin.lineinfile:
      path: '{{ pam_profile_path }}/{{ item }}'
      regexp: ^\s*password\s+\S+\s+pam_pwhistory\.so
      state: absent
    check_mode: true
    changed_when: false
    register: pam_pwhistory_check_result
    loop: '{{ pam_files_to_process | default([]) }}'
    when:
    - item is defined
    - pam_profile_path is defined

  - name: Ensure Active Authselect Profile Includes PAM Modules - Add pam_pwhistory.so
      entry after pam_pwquality in {{ item }}
    ansible.builtin.lineinfile:
      path: '{{ pam_profile_path }}/{{ item }}'
      regexp: ^\s*password\s+\S+\s+pam_pwhistory\.so
      insertafter: ^.*pam_pwquality\.so.*
      line: password     requisite    pam_pwhistory.so
      state: present
    register: pam_pwhistory_add_result
    loop: '{{ pam_files_to_process | default([]) }}'
    when:
    - item is defined
    - pam_profile_path is defined
    - pam_pwhistory_check_result.results | selectattr('item', 'equalto', item) | map(attribute='found')
      | first | default(1) == 0
    - pam_pwquality_check_result.results | selectattr('item', 'equalto', item) | map(attribute='found')
      | first | default(0) &gt; 0

  - name: Ensure Active Authselect Profile Includes PAM Modules - Add pam_pwhistory.so
      entry at beginning of password section in {{ item }}
    ansible.builtin.lineinfile:
      path: '{{ pam_profile_path }}/{{ item }}'
      regexp: ^\s*password\s+\S+\s+pam_pwhistory\.so
      insertbefore: ^password
      line: password     requisite    pam_pwhistory.so
      state: present
    register: pam_pwhistory_add_result
    loop: '{{ pam_files_to_process | default([]) }}'
    when:
    - item is defined
    - pam_profile_path is defined
    - pam_pwhistory_check_result.results | selectattr('item', 'equalto', item) | map(attribute='found')
      | first | default(1) == 0
    - pam_pwquality_check_result.results | selectattr('item', 'equalto', item) | map(attribute='found')
      | first | default(1) == 0

  - name: Ensure Active Authselect Profile Includes PAM Modules - Check if pam_unix.so
      exists in password section of {{ item }}
    ansible.builtin.lineinfile:
      path: '{{ pam_profile_path }}/{{ item }}'
      regexp: ^\s*password\s+\S+\s+pam_unix\.so
      state: absent
    check_mode: true
    changed_when: false
    register: pam_unix_check_result
    loop: '{{ pam_files_to_process | default([]) }}'
    when:
    - item is defined
    - pam_profile_path is defined

  - name: Ensure Active Authselect Profile Includes PAM Modules - Add pam_unix.so
      entry after pam_pwhistory in {{ item }}
    ansible.builtin.lineinfile:
      path: '{{ pam_profile_path }}/{{ item }}'
      regexp: ^\s*password\s+\S+\s+pam_unix\.so
      insertafter: ^.*pam_pwhistory\.so.*
      line: password     sufficient    pam_unix.so
      state: present
    register: pam_unix_add_result
    loop: '{{ pam_files_to_process | default([]) }}'
    when:
    - item is defined
    - pam_profile_path is defined
    - pam_unix_check_result.results | selectattr('item', 'equalto', item) | map(attribute='found')
      | first | default(1) == 0
    - pam_pwhistory_check_result.results | selectattr('item', 'equalto', item) | map(attribute='found')
      | first | default(0) &gt; 0

  - name: Ensure Active Authselect Profile Includes PAM Modules - Add pam_unix.so
      entry at end of password section in {{ item }}
    ansible.builtin.lineinfile:
      path: '{{ pam_profile_path }}/{{ item }}'
      regexp: ^\s*password\s+\S+\s+pam_unix\.so
      insertafter: ^password.*
      line: password     sufficient    pam_unix.so
      state: present
    register: pam_unix_add_result
    loop: '{{ pam_files_to_process | default([]) }}'
    when:
    - item is defined
    - pam_profile_path is defined
    - pam_unix_check_result.results | selectattr('item', 'equalto', item) | map(attribute='found')
      | first | default(1) == 0
    - pam_pwhistory_check_result.results | selectattr('item', 'equalto', item) | map(attribute='found')
      | first | default(1) == 0

  - name: Ensure Active Authselect Profile Includes PAM Modules - Store results for
      {{ item }}
    ansible.builtin.set_fact:
      pam_changes_{{ item | replace('-', '_') }}: |-
        {{ ((pam_faillock_auth_add_result.results | selectattr('item', 'equalto', item) | map(attribute='changed') | first | default(false)) or
           (pam_faillock_account_add_result.results | selectattr('item', 'equalto', item) | map(attribute='changed') | first | default(false)) or
           (pam_pwquality_add_result.results | selectattr('item', 'equalto', item) | map(attribute='changed') | first | default(false)) or
           (pam_pwhistory_add_result.results | selectattr('item', 'equalto', item) | map(attribute='changed') | first | default(false)) or
           (pam_unix_add_result.results | selectattr('item', 'equalto', item) | map(attribute='changed') | first | default(false))) }}
    loop: '{{ pam_files_to_process | default([]) }}'
    when:
    - item is defined
    - pam_profile_path is defined
  when:
  - '"pam" in ansible_facts.packages'
  - result_authselect_check_cmd is success
  - pam_profile_path is defined
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Active Authselect Profile Includes PAM Modules - Ensure authselect
    changes are applied
  ansible.builtin.command:
    cmd: authselect apply-changes -b
  when:
  - '"pam" in ansible_facts.packages'
  - result_authselect_check_cmd is success
  - (pam_changes_system_auth is defined and pam_changes_system_auth) or (pam_changes_password_auth
    is defined and pam_changes_password_auth)
  tags:
  - accounts_password_pam_modules_in_authselect_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_modules_in_authselect_profile:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_modules_in_authselect_profile_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_enabled" selected="false" severity="medium">
              <xccdf-1.2:title>Verify pam_unix module is activated</xccdf-1.2:title>
              <xccdf-1.2:description><html:code>pam_unix</html:code> is the standard Unix authentication module. It uses standard calls from the
system's libraries to retrieve and set account information as well as authentication.
Usually this is obtained from the <html:code>/etc/passwd</html:code> and if shadow is enabled, the
<html:code>/etc/shadow</html:code> file as well.
<html:br/><html:br/>
The account component performs the task of establishing the status of the user's
account and password based on the following shadow elements: <html:code>expire,
last_change, max_change, min_change, warn_change</html:code>. In the case of the latter, it may
offer advice to the user on changing their password or, through the
<html:code>PAM_AUTHTOKEN_REQD</html:code> return, delay giving service to the user until they have
established a new password. The entries listed above are documented in the shadow(5)
manual page. Should the user's record not contain one or more of these entries, the
corresponding shadow check is not performed.
<html:br/><html:br/>
The authentication component performs the task of checking the users credentials
(password). The default action of this module is to not permit the user access to a
service if their official password is blank.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.2.5</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The system should only provide access after performing authentication of a user.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_pam"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_unix_enabled:def:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_disallow_bypass_password_sudo" selected="false" severity="medium">
              <xccdf-1.2:title>Disallow Configuration to Bypass Password Requirements for Privilege Escalation</xccdf-1.2:title>
              <xccdf-1.2:description>Verify the operating system is not configured to bypass password requirements for privilege
escalation. Check the configuration of the "/etc/pam.d/sudo" file with the following command:
<html:pre>$ sudo grep pam_succeed_if /etc/pam.d/sudo</html:pre>
If any occurrences of "pam_succeed_if" is returned from the command, this is a finding.</xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000373-GPOS-00156</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000373-GPOS-00157</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000373-GPOS-00158</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010385</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-251712r1050789_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Without re-authentication, users may access resources or perform tasks for which they do not
have authorization. When operating systems provide the capability to escalate a functional
capability, it is critical the user re-authenticate.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_pam_and_system_with_kernel"/>
              <xccdf-1.2:fix id="disallow_bypass_password_sudo" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q pam &amp;&amp; rpm --quiet -q kernel ) ); then

sed -i '/pam_succeed_if/d' /etc/pam.d/sudo

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="disallow_bypass_password_sudo" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010385
  - NIST-800-53-IA-11
  - disallow_bypass_password_sudo
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Check for pam_succeed_if entry
  ansible.builtin.lineinfile:
    path: /etc/pam.d/sudo
    create: false
    regexp: pam_succeed_if
    state: absent
  when: ( "pam" in ansible_facts.packages and "kernel" in ansible_facts.packages )
  tags:
  - DISA-STIG-RHEL-08-010385
  - NIST-800-53-IA-11
  - disallow_bypass_password_sudo
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-disallow_bypass_password_sudo:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_display_login_attempts" selected="false" severity="low">
              <xccdf-1.2:title>Ensure PAM Displays Last Logon/Access Notification</xccdf-1.2:title>
              <xccdf-1.2:description>To configure the system to notify users of last logon/access using <html:code>pam_lastlog</html:code>,
add or correct the <html:code>pam_lastlog</html:code> settings in <html:code>/etc/pam.d/postlogin</html:code>
to include <html:code>showfailed</html:code> option, such as:
<html:pre>session     [default=1]    pam_lastlog.so showfailed</html:pre>
And make sure that the <html:code>silent</html:code> option is not set for this specific line.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">If the system relies on <html:code>authselect</html:code> tool to manage PAM settings, the remediation
will also use <html:code>authselect</html:code> tool. However, if any manual modification was made in
PAM files, the <html:code>authselect</html:code> integrity check will fail and the remediation will be
aborted in order to preserve intentional changes. In this case, an informative message will
be shown in the remediation report.</xccdf-1.2:warning>
              <xccdf-1.2:warning category="general"><html:code>authselect</html:code> contains an authselect feature to easily and properly enable Last Logon
notifications with <html:code>pam_lastlog.so</html:code> module. If a custom profile was created and used
in the system before this authselect feature was available, the new feature can't be used
with this custom profile and the remediation will fail. In this case, the custom profile
should be recreated or manually updated.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-9(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Users need to be aware of activity that occurs regarding their account. Providing users with
information regarding the number of unsuccessful attempts that were made to login to their
account allows the user to determine if any unauthorized activity has occurred and gives them
an opportunity to notify administrators.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_pam_and_system_with_kernel"/>
              <xccdf-1.2:fix id="display_login_attempts" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q pam &amp;&amp; rpm --quiet -q kernel ) ); then

if [ -f /usr/bin/authselect ]; then
    if authselect list-features sssd | grep -q with-silent-lastlog; then
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi
        authselect disable-feature with-silent-lastlog

        authselect apply-changes -b
    else
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "/etc/pam.d/postlogin")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
        if [ -e "$PAM_FILE_PATH" ] ; then
            PAM_FILE_PATH="$PAM_FILE_PATH"
            if [ -f /usr/bin/authselect ]; then
                
                if ! authselect check; then
                echo "
                authselect integrity check failed. Remediation aborted!
                This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
                It is not recommended to manually edit the PAM files when authselect tool is available.
                In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
                exit 1
                fi

                CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
                # If not already in use, a custom profile is created preserving the enabled features.
                if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                    ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                    # The "local" profile does not contain essential security features required by multiple Benchmarks.
                    # If currently used, it is replaced by "sssd", which is the best option in this case.
                    if [[ $CURRENT_PROFILE == local ]]; then
                        CURRENT_PROFILE="sssd"
                    fi
                    authselect create-profile hardening -b $CURRENT_PROFILE
                    CURRENT_PROFILE="custom/hardening"
                    
                    authselect apply-changes -b --backup=before-hardening-custom-profile
                    authselect select $CURRENT_PROFILE
                    for feature in $ENABLED_FEATURES; do
                        authselect enable-feature $feature;
                    done
                    
                    authselect apply-changes -b --backup=after-hardening-custom-profile
                fi
                PAM_FILE_NAME=$(basename "$PAM_FILE_PATH")
                PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

                authselect apply-changes -b
            fi
            

                if ! grep -qP "^\s*session\s+\[default=1\]\s+pam_lastlog.so\s*.*" "$PAM_FILE_PATH"; then
                    # Line matching group + control + module was not found. Check group + module.
                    if [ "$(grep -cP '^\s*session\s+.*\s+pam_lastlog.so\s*' "$PAM_FILE_PATH")" -eq 1 ]; then
                        # The control is updated only if one single line matches.
                        sed -i -E --follow-symlinks "s/^(\s*session\s+).*(\bpam_lastlog.so.*)/\1[default=1] \2/" "$PAM_FILE_PATH"
                    else
                        LAST_MATCH_LINE=$(grep -nP "^\s*session\s+.*pam_succeed_if\.so.*" "$PAM_FILE_PATH" | tail -n 1 | cut -d: -f 1)
                        if [ ! -z $LAST_MATCH_LINE ]; then
                            sed -i --follow-symlinks $LAST_MATCH_LINE" a session     [default=1]    pam_lastlog.so" "$PAM_FILE_PATH"
                        else
                            echo "session    [default=1]    pam_lastlog.so" &gt;&gt; "$PAM_FILE_PATH"
                        fi
                    fi
                fi
                # Check the option
                if ! grep -qP "^\s*session\s+\[default=1\]\s+pam_lastlog.so\s*.*\sshowfailed\b" "$PAM_FILE_PATH"; then
                    sed -i -E --follow-symlinks "/\s*session\s+\[default=1\]\s+pam_lastlog.so.*/ s/$/ showfailed/" "$PAM_FILE_PATH"
                fi
            if [ -f /usr/bin/authselect ]; then
                
                authselect apply-changes -b
            fi
        else
            echo "$PAM_FILE_PATH was not found" &gt;&amp;2
        fi
        if [ -e "$PAM_FILE_PATH" ] ; then
            PAM_FILE_PATH="$PAM_FILE_PATH"
            if [ -f /usr/bin/authselect ]; then
                
                if ! authselect check; then
                echo "
                authselect integrity check failed. Remediation aborted!
                This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
                It is not recommended to manually edit the PAM files when authselect tool is available.
                In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
                exit 1
                fi

                CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
                # If not already in use, a custom profile is created preserving the enabled features.
                if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                    ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                    # The "local" profile does not contain essential security features required by multiple Benchmarks.
                    # If currently used, it is replaced by "sssd", which is the best option in this case.
                    if [[ $CURRENT_PROFILE == local ]]; then
                        CURRENT_PROFILE="sssd"
                    fi
                    authselect create-profile hardening -b $CURRENT_PROFILE
                    CURRENT_PROFILE="custom/hardening"
                    
                    authselect apply-changes -b --backup=before-hardening-custom-profile
                    authselect select $CURRENT_PROFILE
                    for feature in $ENABLED_FEATURES; do
                        authselect enable-feature $feature;
                    done
                    
                    authselect apply-changes -b --backup=after-hardening-custom-profile
                fi
                PAM_FILE_NAME=$(basename "$PAM_FILE_PATH")
                PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

                authselect apply-changes -b
            fi
            
        if grep -qP "^\s*session\s+[default=1]\s+pam_lastlog.so\s.*\bsilent\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "s/(.*session.*[default=1].*pam_lastlog.so.*)\bsilent\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
        fi
            if [ -f /usr/bin/authselect ]; then
                
                authselect apply-changes -b
            fi
        else
            echo "$PAM_FILE_PATH was not found" &gt;&amp;2
        fi
    fi
else
    if [ -e "/etc/pam.d/postlogin" ] ; then
            PAM_FILE_PATH="/etc/pam.d/postlogin"
            if [ -f /usr/bin/authselect ]; then
                
                if ! authselect check; then
                echo "
                authselect integrity check failed. Remediation aborted!
                This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
                It is not recommended to manually edit the PAM files when authselect tool is available.
                In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
                exit 1
                fi

                CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
                # If not already in use, a custom profile is created preserving the enabled features.
                if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                    ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                    # The "local" profile does not contain essential security features required by multiple Benchmarks.
                    # If currently used, it is replaced by "sssd", which is the best option in this case.
                    if [[ $CURRENT_PROFILE == local ]]; then
                        CURRENT_PROFILE="sssd"
                    fi
                    authselect create-profile hardening -b $CURRENT_PROFILE
                    CURRENT_PROFILE="custom/hardening"
                    
                    authselect apply-changes -b --backup=before-hardening-custom-profile
                    authselect select $CURRENT_PROFILE
                    for feature in $ENABLED_FEATURES; do
                        authselect enable-feature $feature;
                    done
                    
                    authselect apply-changes -b --backup=after-hardening-custom-profile
                fi
                PAM_FILE_NAME=$(basename "/etc/pam.d/postlogin")
                PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

                authselect apply-changes -b
            fi
            

                if ! grep -qP "^\s*session\s+\[default=1\]\s+pam_lastlog.so\s*.*" "$PAM_FILE_PATH"; then
                    # Line matching group + control + module was not found. Check group + module.
                    if [ "$(grep -cP '^\s*session\s+.*\s+pam_lastlog.so\s*' "$PAM_FILE_PATH")" -eq 1 ]; then
                        # The control is updated only if one single line matches.
                        sed -i -E --follow-symlinks "s/^(\s*session\s+).*(\bpam_lastlog.so.*)/\1[default=1] \2/" "$PAM_FILE_PATH"
                    else
                        LAST_MATCH_LINE=$(grep -nP "^\s*session\s+.*pam_succeed_if\.so.*" "$PAM_FILE_PATH" | tail -n 1 | cut -d: -f 1)
                        if [ ! -z $LAST_MATCH_LINE ]; then
                            sed -i --follow-symlinks $LAST_MATCH_LINE" a session     [default=1]    pam_lastlog.so" "$PAM_FILE_PATH"
                        else
                            echo "session    [default=1]    pam_lastlog.so" &gt;&gt; "$PAM_FILE_PATH"
                        fi
                    fi
                fi
                # Check the option
                if ! grep -qP "^\s*session\s+\[default=1\]\s+pam_lastlog.so\s*.*\sshowfailed\b" "$PAM_FILE_PATH"; then
                    sed -i -E --follow-symlinks "/\s*session\s+\[default=1\]\s+pam_lastlog.so.*/ s/$/ showfailed/" "$PAM_FILE_PATH"
                fi
            if [ -f /usr/bin/authselect ]; then
                
                authselect apply-changes -b
            fi
        else
            echo "/etc/pam.d/postlogin was not found" &gt;&amp;2
        fi
    if [ -e "/etc/pam.d/postlogin" ] ; then
            PAM_FILE_PATH="/etc/pam.d/postlogin"
            if [ -f /usr/bin/authselect ]; then
                
                if ! authselect check; then
                echo "
                authselect integrity check failed. Remediation aborted!
                This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
                It is not recommended to manually edit the PAM files when authselect tool is available.
                In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
                exit 1
                fi

                CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
                # If not already in use, a custom profile is created preserving the enabled features.
                if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                    ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                    # The "local" profile does not contain essential security features required by multiple Benchmarks.
                    # If currently used, it is replaced by "sssd", which is the best option in this case.
                    if [[ $CURRENT_PROFILE == local ]]; then
                        CURRENT_PROFILE="sssd"
                    fi
                    authselect create-profile hardening -b $CURRENT_PROFILE
                    CURRENT_PROFILE="custom/hardening"
                    
                    authselect apply-changes -b --backup=before-hardening-custom-profile
                    authselect select $CURRENT_PROFILE
                    for feature in $ENABLED_FEATURES; do
                        authselect enable-feature $feature;
                    done
                    
                    authselect apply-changes -b --backup=after-hardening-custom-profile
                fi
                PAM_FILE_NAME=$(basename "/etc/pam.d/postlogin")
                PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

                authselect apply-changes -b
            fi
            
        if grep -qP "^\s*session\s+[default=1]\s+pam_lastlog.so\s.*\bsilent\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "s/(.*session.*[default=1].*pam_lastlog.so.*)\bsilent\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
        fi
            if [ -f /usr/bin/authselect ]; then
                
                authselect apply-changes -b
            fi
        else
            echo "/etc/pam.d/postlogin was not found" &gt;&amp;2
        fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="display_login_attempts" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.2
  - NIST-800-53-AC-9
  - NIST-800-53-AC-9(1)
  - PCI-DSS-Req-10.2.4
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.4
  - configure_strategy
  - display_login_attempts
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed

- name: Ensure PAM Displays Last Logon/Access Notification - Check if system relies
    on authselect tool
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when: ( "pam" in ansible_facts.packages and "kernel" in ansible_facts.packages )
  tags:
  - CJIS-5.5.2
  - NIST-800-53-AC-9
  - NIST-800-53-AC-9(1)
  - PCI-DSS-Req-10.2.4
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.4
  - configure_strategy
  - display_login_attempts
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed

- name: Ensure PAM Displays Last Logon/Access Notification - Collect the Available
    authselect Features
  ansible.builtin.command:
    cmd: authselect list-features sssd
  register: result_authselect_available_features
  changed_when: false
  check_mode: false
  when:
  - ( "pam" in ansible_facts.packages and "kernel" in ansible_facts.packages )
  - result_authselect_present.stat.exists
  tags:
  - CJIS-5.5.2
  - NIST-800-53-AC-9
  - NIST-800-53-AC-9(1)
  - PCI-DSS-Req-10.2.4
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.4
  - configure_strategy
  - display_login_attempts
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed

- name: Ensure PAM Displays Last Logon/Access Notification - Configure pam_lastlog.so
    Using authselect Feature
  block:

  - name: Ensure PAM Displays Last Logon/Access Notification - Check integrity of
      authselect current profile
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: Ensure PAM Displays Last Logon/Access Notification - Informative message
      based on the authselect integrity check result
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: Ensure PAM Displays Last Logon/Access Notification - Get authselect Features
      Currently Enabled
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: Ensure PAM Displays Last Logon/Access Notification - Ensure "with-silent-lastlog"
      Feature is Disabled Using authselect Tool
    ansible.builtin.command:
      cmd: authselect disable-feature with-silent-lastlog
    register: result_authselect_disable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is search("with-silent-lastlog")

  - name: Ensure PAM Displays Last Logon/Access Notification - Ensure authselect changes
      are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_disable_feature_cmd is not skipped
    - result_authselect_disable_feature_cmd is success
  when:
  - ( "pam" in ansible_facts.packages and "kernel" in ansible_facts.packages )
  - result_authselect_present.stat.exists
  - result_authselect_available_features.stdout is search("with-silent-lastlog")
  tags:
  - CJIS-5.5.2
  - NIST-800-53-AC-9
  - NIST-800-53-AC-9(1)
  - PCI-DSS-Req-10.2.4
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.4
  - configure_strategy
  - display_login_attempts
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed

- name: Ensure PAM Displays Last Logon/Access Notification - Configure pam_lastlog.so
    in appropriate PAM files
  block:

  - name: Ensure PAM Displays Last Logon/Access Notification - Define the PAM file
      to be edited as a local fact
    ansible.builtin.set_fact:
      pam_file_path: /etc/pam.d/postlogin

  - name: Ensure PAM Displays Last Logon/Access Notification - Check if system relies
      on authselect tool
    ansible.builtin.stat:
      path: /usr/bin/authselect
    register: result_authselect_present

  - name: Ensure PAM Displays Last Logon/Access Notification - Ensure authselect custom
      profile is used if authselect is present
    block:

    - name: Ensure PAM Displays Last Logon/Access Notification - Check integrity of
        authselect current profile
      ansible.builtin.command:
        cmd: authselect check
      register: result_authselect_check_cmd
      changed_when: false
      check_mode: false
      failed_when: false

    - name: Ensure PAM Displays Last Logon/Access Notification - Informative message
        based on the authselect integrity check result
      ansible.builtin.assert:
        that:
        - ansible_check_mode or result_authselect_check_cmd.rc == 0
        fail_msg:
        - authselect integrity check failed. Remediation aborted!
        - This remediation could not be applied because an authselect profile was
          not selected or the selected profile is not intact.
        - It is not recommended to manually edit the PAM files when authselect tool
          is available.
        - In cases where the default authselect profile does not cover a specific
          demand, a custom authselect profile is recommended.
        success_msg:
        - authselect integrity check passed

    - name: Ensure PAM Displays Last Logon/Access Notification - Get authselect current
        profile
      ansible.builtin.shell:
        cmd: authselect current -r | awk '{ print $1 }'
      register: result_authselect_profile
      changed_when: false
      when:
      - result_authselect_check_cmd is success

    - name: Ensure PAM Displays Last Logon/Access Notification - Define the current
        authselect profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is match("custom/")

    - name: Ensure PAM Displays Last Logon/Access Notification - Define the new authselect
        custom profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: custom/hardening
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is not match("custom/")

    - name: Ensure PAM Displays Last Logon/Access Notification - Get authselect current
        features to also enable them in the custom profile
      ansible.builtin.shell:
        cmd: authselect current | tail -n+3 | awk '{ print $2 }'
      register: result_authselect_features
      changed_when: false
      check_mode: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Ensure PAM Displays Last Logon/Access Notification - Check if any custom
        profile with the same name was already created
      ansible.builtin.stat:
        path: /etc/authselect/{{ authselect_custom_profile }}
      register: result_authselect_custom_profile_present
      changed_when: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Ensure PAM Displays Last Logon/Access Notification - Create an authselect
        custom profile based on the current profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b {{ authselect_current_profile
          }}
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is not match("^(custom/|local)")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Ensure PAM Displays Last Logon/Access Notification - Create an authselect
        custom profile based on sssd profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b sssd
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is match("local")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Ensure PAM Displays Last Logon/Access Notification - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Ensure PAM Displays Last Logon/Access Notification - Ensure the authselect
        custom profile is selected
      ansible.builtin.command:
        cmd: authselect select {{ authselect_custom_profile }}
      register: result_pam_authselect_select_profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Ensure PAM Displays Last Logon/Access Notification - Restore the authselect
        features in the custom profile
      ansible.builtin.command:
        cmd: authselect enable-feature {{ item }}
      loop: '{{ result_authselect_features.stdout_lines }}'
      register: result_pam_authselect_restore_features
      when:
      - result_authselect_profile is not skipped
      - result_authselect_features is not skipped
      - result_pam_authselect_select_profile is not skipped

    - name: Ensure PAM Displays Last Logon/Access Notification - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - result_pam_authselect_restore_features is not skipped

    - name: Ensure PAM Displays Last Logon/Access Notification - Change the PAM file
        to be edited according to the custom authselect profile
      ansible.builtin.set_fact:
        pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
          | basename }}
      when:
      - authselect_custom_profile is defined
    when:
    - result_authselect_present.stat.exists

  - name: Ensure PAM Displays Last Logon/Access Notification - Define a fact for control
      already filtered in case filters are used
    ansible.builtin.set_fact:
      pam_module_control: '[default=1]'

  - name: Ensure PAM Displays Last Logon/Access Notification - Check if expected PAM
      module line is present in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*session\s+{{ pam_module_control | regex_escape() }}\s+pam_lastlog.so\s*.*
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_line_present

  - name: Ensure PAM Displays Last Logon/Access Notification - Include or update the
      PAM module line in {{ pam_file_path }}
    block:

    - name: Ensure PAM Displays Last Logon/Access Notification - Check if required
        PAM module line is present in {{ pam_file_path }} with different control
      ansible.builtin.lineinfile:
        path: '{{ pam_file_path }}'
        regexp: ^\s*session\s+.*\s+pam_lastlog.so\s*
        state: absent
      check_mode: true
      changed_when: false
      register: result_pam_line_other_control_present

    - name: Ensure PAM Displays Last Logon/Access Notification - Ensure the correct
        control for the required PAM module line in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: ^(\s*session\s+).*(\bpam_lastlog.so.*)
        replace: \1{{ pam_module_control }} \2
      register: result_pam_module_edit
      when:
      - result_pam_line_other_control_present.found == 1

    - name: Ensure PAM Displays Last Logon/Access Notification - Ensure the required
        PAM module line is included in {{ pam_file_path }}
      ansible.builtin.lineinfile:
        dest: '{{ pam_file_path }}'
        insertafter: ^\s*session\s+.*pam_succeed_if\.so.*
        line: session    {{ pam_module_control }}    pam_lastlog.so
      register: result_pam_module_add
      when:
      - result_pam_line_other_control_present.found == 0 or result_pam_line_other_control_present.found
        &gt; 1

    - name: Ensure PAM Displays Last Logon/Access Notification - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present is defined
      - result_authselect_present.stat.exists
      - |-
        (result_pam_module_add is defined and result_pam_module_add.changed)
         or (result_pam_module_edit is defined and result_pam_module_edit.changed)
    when:
    - result_pam_line_present.found is defined
    - result_pam_line_present.found == 0

  - name: Ensure PAM Displays Last Logon/Access Notification - Define a fact for control
      already filtered in case filters are used
    ansible.builtin.set_fact:
      pam_module_control: '[default=1]'

  - name: Ensure PAM Displays Last Logon/Access Notification - Check if the required
      PAM module option is present in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*session\s+{{ pam_module_control | regex_escape() }}\s+pam_lastlog.so\s*.*\sshowfailed\b
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_module_display_login_attempts_option_present

  - name: Ensure PAM Displays Last Logon/Access Notification - Ensure the "showfailed"
      PAM option for "pam_lastlog.so" is included in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      backrefs: true
      regexp: ^(\s*session\s+{{ pam_module_control | regex_escape() }}\s+pam_lastlog.so.*)
      line: \1 showfailed
      state: present
    register: result_pam_display_login_attempts_add
    when:
    - result_pam_module_display_login_attempts_option_present.found is defined
    - result_pam_module_display_login_attempts_option_present.found == 0

  - name: Ensure PAM Displays Last Logon/Access Notification - Define a fact for control
      already filtered in case filters are used
    ansible.builtin.set_fact:
      pam_module_control: '[default=1]'

  - name: Ensure PAM Displays Last Logon/Access Notification - Check if {{ pam_file_path
      }} file is present
    ansible.builtin.stat:
      path: '{{ pam_file_path }}'
    register: result_pam_file_present

  - name: Ensure PAM Displays Last Logon/Access Notification - Ensure the "silent"
      option from "pam_lastlog.so" is not present in {{ pam_file_path }}
    ansible.builtin.replace:
      dest: '{{ pam_file_path }}'
      regexp: (.*session.*{{ pam_module_control | regex_escape() }}.*pam_lastlog.so.*)\bsilent\b=?[0-9a-zA-Z]*(.*)
      replace: \1\2
    register: result_pam_option_removal
    when:
    - result_pam_file_present.stat.exists
  when: ( "pam" in ansible_facts.packages and "kernel" in ansible_facts.packages )
  tags:
  - CJIS-5.5.2
  - NIST-800-53-AC-9
  - NIST-800-53-AC-9(1)
  - PCI-DSS-Req-10.2.4
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.4
  - configure_strategy
  - display_login_attempts
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-display_login_attempts:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-display_login_attempts_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_enable_pam_namespace" selected="false" severity="low">
              <xccdf-1.2:title>Set Up a Private Namespace in PAM Configuration</xccdf-1.2:title>
              <xccdf-1.2:description>To setup a private namespace add the following line to <html:code>/etc/pam.d/login</html:code>:
<html:pre>session    required     pam_namespace.so</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R55</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The pam_namespace PAM module sets up a private namespace for a
session with polyinstantiated directories. A polyinstantiated directory
provides a different instance of itself based on user name, or when using
SELinux, user name, security context or both. The polyinstatied directories
can be used to dedicate separate temporary directories to each account.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_pam_and_system_with_kernel"/>
              <xccdf-1.2:fix id="enable_pam_namespace" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q pam &amp;&amp; rpm --quiet -q kernel ) ); then

if ! grep -Eq '^\s*session\s+required\s+pam_namespace.so\s*$' '/etc/pam.d/login' ; then
    echo "session    required     pam_namespace.so" &gt;&gt; "/etc/pam.d/login"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="enable_pam_namespace" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_pam_namespace
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy

- name: Make changes to /etc/pam.d/login
  ansible.builtin.lineinfile:
    path: /etc/pam.d/login
    create: false
    regexp: ^\s*session\s+required\s+pam_namespace.so\s*$
    line: session    required     pam_namespace.so
    state: present
  when: ( "pam" in ansible_facts.packages and "kernel" in ansible_facts.packages )
  tags:
  - enable_pam_namespace
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-enable_pam_namespace:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-enable_pam_namespace_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_locking_out_password_attempts">
              <xccdf-1.2:title>Set Lockouts for Failed Password Attempts</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>pam_faillock</html:code> PAM module provides the capability to
lock out user accounts after a number of failed login attempts. Its
documentation is available in
<html:code>/usr/share/doc/pam-VERSION/txts/README.pam_faillock</html:code>.
<html:br/><html:br/></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Locking out user accounts presents the
risk of a denial-of-service attack. The lockout policy
must weigh whether the risk of such a
denial-of-service attack outweighs the benefits of thwarting
password guessing attacks.</xccdf-1.2:warning>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" type="number">
                <xccdf-1.2:title>fail_deny</xccdf-1.2:title>
                <xccdf-1.2:description>Number of failed login attempts before account lockout</xccdf-1.2:description>
                <xccdf-1.2:value selector="10">10</xccdf-1.2:value>
                <xccdf-1.2:value selector="3">3</xccdf-1.2:value>
                <xccdf-1.2:value selector="4">4</xccdf-1.2:value>
                <xccdf-1.2:value selector="5">5</xccdf-1.2:value>
                <xccdf-1.2:value selector="6">6</xccdf-1.2:value>
                <xccdf-1.2:value selector="8">8</xccdf-1.2:value>
                <xccdf-1.2:value>3</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir" type="string">
                <xccdf-1.2:title>faillock directory</xccdf-1.2:title>
                <xccdf-1.2:description>The directory where the user files with the failure records are kept</xccdf-1.2:description>
                <xccdf-1.2:value selector="ol8">/var/log/faillock</xccdf-1.2:value>
                <xccdf-1.2:value>/var/log/faillock</xccdf-1.2:value>
                <xccdf-1.2:value selector="run">/var/run/faillock</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_fail_interval" type="number">
                <xccdf-1.2:title>fail_interval</xccdf-1.2:title>
                <xccdf-1.2:description>Interval for counting failed login attempts before account lockout</xccdf-1.2:description>
                <xccdf-1.2:value selector="100000000">100000000</xccdf-1.2:value>
                <xccdf-1.2:value selector="1800">1800</xccdf-1.2:value>
                <xccdf-1.2:value selector="3600">3600</xccdf-1.2:value>
                <xccdf-1.2:value selector="86400">86400</xccdf-1.2:value>
                <xccdf-1.2:value selector="900">900</xccdf-1.2:value>
                <xccdf-1.2:value>900</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_root_unlock_time" type="number">
                <xccdf-1.2:title>fail_root_unlock_time</xccdf-1.2:title>
                <xccdf-1.2:description>Seconds before automatic unlocking or permanently locking after excessive failed logins to root</xccdf-1.2:description>
                <xccdf-1.2:value selector="60">60</xccdf-1.2:value>
                <xccdf-1.2:value selector="1800">1800</xccdf-1.2:value>
                <xccdf-1.2:value selector="3600">3600</xccdf-1.2:value>
                <xccdf-1.2:value selector="600">600</xccdf-1.2:value>
                <xccdf-1.2:value selector="604800">604800</xccdf-1.2:value>
                <xccdf-1.2:value selector="86400">86400</xccdf-1.2:value>
                <xccdf-1.2:value selector="900">900</xccdf-1.2:value>
                <xccdf-1.2:value selector="300">300</xccdf-1.2:value>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="never">0</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" type="number">
                <xccdf-1.2:title>fail_unlock_time</xccdf-1.2:title>
                <xccdf-1.2:description>Seconds before automatic unlocking or permanently locking after excessive failed logins</xccdf-1.2:description>
                <xccdf-1.2:value selector="1800">1800</xccdf-1.2:value>
                <xccdf-1.2:value selector="3600">3600</xccdf-1.2:value>
                <xccdf-1.2:value selector="600">600</xccdf-1.2:value>
                <xccdf-1.2:value selector="604800">604800</xccdf-1.2:value>
                <xccdf-1.2:value selector="86400">86400</xccdf-1.2:value>
                <xccdf-1.2:value selector="900">900</xccdf-1.2:value>
                <xccdf-1.2:value selector="300">300</xccdf-1.2:value>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="never">0</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_tally2_unlock_time" type="number">
                <xccdf-1.2:title>tally2_unlock_time</xccdf-1.2:title>
                <xccdf-1.2:description>Seconds before automatic unlocking or permanently locking after excessive failed logins</xccdf-1.2:description>
                <xccdf-1.2:value selector="1800">1800</xccdf-1.2:value>
                <xccdf-1.2:value selector="3600">3600</xccdf-1.2:value>
                <xccdf-1.2:value selector="600">600</xccdf-1.2:value>
                <xccdf-1.2:value selector="604800">604800</xccdf-1.2:value>
                <xccdf-1.2:value selector="86400">86400</xccdf-1.2:value>
                <xccdf-1.2:value selector="900">900</xccdf-1.2:value>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="never">0</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_pam_remember" type="number">
                <xccdf-1.2:title>pwhistory_remember</xccdf-1.2:title>
                <xccdf-1.2:description>Prevent password reuse using password history lookup</xccdf-1.2:description>
                <xccdf-1.2:value selector="0">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
                <xccdf-1.2:value selector="2">2</xccdf-1.2:value>
                <xccdf-1.2:value selector="3">3</xccdf-1.2:value>
                <xccdf-1.2:value selector="4">4</xccdf-1.2:value>
                <xccdf-1.2:value selector="5">5</xccdf-1.2:value>
                <xccdf-1.2:value selector="6">6</xccdf-1.2:value>
                <xccdf-1.2:value selector="7">7</xccdf-1.2:value>
                <xccdf-1.2:value selector="8">8</xccdf-1.2:value>
                <xccdf-1.2:value selector="9">9</xccdf-1.2:value>
                <xccdf-1.2:value selector="20">20</xccdf-1.2:value>
                <xccdf-1.2:value selector="24">24</xccdf-1.2:value>
                <xccdf-1.2:value>5</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_pam_remember_control_flag" type="string">
                <xccdf-1.2:title>PAM pwhistory remember - control flag</xccdf-1.2:title>
                <xccdf-1.2:description>'Specify the control flag required for password remember requirement. If multiple
values are allowed write them separated by commas as in "required,requisite",
for remediations the first value will be taken'</xccdf-1.2:description>
                <xccdf-1.2:value selector="required">required</xccdf-1.2:value>
                <xccdf-1.2:value selector="optional">optional</xccdf-1.2:value>
                <xccdf-1.2:value selector="requisite">requisite</xccdf-1.2:value>
                <xccdf-1.2:value selector="sufficient">sufficient</xccdf-1.2:value>
                <xccdf-1.2:value selector="binding">binding</xccdf-1.2:value>
                <xccdf-1.2:value selector="ol8">required,requisite</xccdf-1.2:value>
                <xccdf-1.2:value selector="requisite_or_required">requisite,required</xccdf-1.2:value>
                <xccdf-1.2:value>requisite</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_pam_tally2" type="number">
                <xccdf-1.2:title>tally2</xccdf-1.2:title>
                <xccdf-1.2:description>Number of failed login attempts</xccdf-1.2:description>
                <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
                <xccdf-1.2:value selector="2">2</xccdf-1.2:value>
                <xccdf-1.2:value selector="3">3</xccdf-1.2:value>
                <xccdf-1.2:value selector="4">4</xccdf-1.2:value>
                <xccdf-1.2:value selector="5">5</xccdf-1.2:value>
                <xccdf-1.2:value selector="10">10</xccdf-1.2:value>
                <xccdf-1.2:value>3</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_account_password_pam_faillock_password_auth" selected="false" severity="medium">
                <xccdf-1.2:title>Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.</xccdf-1.2:title>
                <xccdf-1.2:description>The pam_faillock.so module must be loaded in preauth in /etc/pam.d/password-auth.</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-7 (a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000021-GPOS-00005</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020026</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244534r1069319_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If the pam_faillock.so module is not loaded the system will not correctly lockout accounts to prevent
password guessing attacks.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="account_password_pam_faillock_password_auth" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

read -ra authselect_args &lt; &lt;(authselect current --raw)
authselect select "${authselect_args[@]}" --force
if [ -f /usr/bin/authselect ]; then
    if ! authselect check; then
echo "
authselect integrity check failed. Remediation aborted!
This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
It is not recommended to manually edit the PAM files when authselect tool is available.
In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
exit 1
fi
authselect enable-feature with-faillock

authselect apply-changes -b
else
    
AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
for pam_file in "${AUTH_FILES[@]}"
do
    if ! grep -qE '^\s*auth\s+required\s+pam_faillock\.so\s+(preauth silent|authfail).*$' "$pam_file" ; then
        sed -i --follow-symlinks '/^auth.*sufficient.*pam_unix\.so.*/i auth        required      pam_faillock.so preauth silent' "$pam_file"
        sed -i --follow-symlinks '/^auth.*required.*pam_deny\.so.*/i auth        required      pam_faillock.so authfail' "$pam_file"
        sed -i --follow-symlinks '/^account.*required.*pam_unix\.so.*/i account     required      pam_faillock.so' "$pam_file"
    fi
    sed -Ei 's/(auth.*)(\[default=die\])(.*pam_faillock\.so)/\1required     \3/g' "$pam_file"
done

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="account_password_pam_faillock_password_auth" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020026
  - NIST-800-53-AC-7 (a)
  - account_password_pam_faillock_password_auth
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth
    File. - Get current authselect profile
  ansible.builtin.command:
    cmd: authselect current --raw
  register: authselect_current_profile
  changed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020026
  - NIST-800-53-AC-7 (a)
  - account_password_pam_faillock_password_auth
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth
    File. - Force reselect authselect profile
  ansible.builtin.command:
    cmd: authselect select {{ authselect_current_profile.stdout }} --force
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020026
  - NIST-800-53-AC-7 (a)
  - account_password_pam_faillock_password_auth
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth
    File. - Check if system relies on authselect tool
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020026
  - NIST-800-53-AC-7 (a)
  - account_password_pam_faillock_password_auth
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth
    File. - Remediation where authselect tool is present
  block:

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth
      File. - Check integrity of authselect current profile
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth
      File. - Informative message based on the authselect integrity check result
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth
      File. - Get authselect current features
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth
      File. - Ensure "with-faillock" feature is enabled using authselect tool
    ansible.builtin.command:
      cmd: authselect enable-feature with-faillock
    register: result_authselect_enable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is not search("with-faillock")

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth
      File. - Ensure authselect changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_enable_feature_cmd is not skipped
    - result_authselect_enable_feature_cmd is success
  when:
  - '"kernel" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020026
  - NIST-800-53-AC-7 (a)
  - account_password_pam_faillock_password_auth
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth
    File. - Remediation where authselect tool is not present
  block:

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth
      File. - Check if pam_faillock.so is already enabled
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail)
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_is_enabled

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth
      File. - Enable pam_faillock.so preauth editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so preauth
      insertbefore: ^auth.*sufficient.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth
      File. - Enable pam_faillock.so authfail editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so authfail
      insertbefore: ^auth.*required.*pam_deny\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth
      File. - Enable pam_faillock.so account section editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: account     required      pam_faillock.so
      insertbefore: ^account.*required.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - not result_authselect_present.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020026
  - NIST-800-53-AC-7 (a)
  - account_password_pam_faillock_password_auth
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-account_password_pam_faillock_password_auth:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-account_password_pam_faillock_password_auth_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_account_password_pam_faillock_system_auth" selected="false" severity="medium">
                <xccdf-1.2:title>Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.</xccdf-1.2:title>
                <xccdf-1.2:description>The pam_faillock.so module must be loaded in preauth in /etc/pam.d/system-auth.</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-7 (a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000021-GPOS-00005</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020025</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244533r1069318_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If the pam_faillock.so module is not loaded the system will not correctly lockout accounts to prevent
password guessing attacks.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="account_password_pam_faillock_system_auth" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -f /usr/bin/authselect ]; then
    if ! authselect check; then
echo "
authselect integrity check failed. Remediation aborted!
This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
It is not recommended to manually edit the PAM files when authselect tool is available.
In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
exit 1
fi
authselect enable-feature with-faillock

authselect apply-changes -b
else
    
AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
for pam_file in "${AUTH_FILES[@]}"
do
    if ! grep -qE '^\s*auth\s+required\s+pam_faillock\.so\s+(preauth silent|authfail).*$' "$pam_file" ; then
        sed -i --follow-symlinks '/^auth.*sufficient.*pam_unix\.so.*/i auth        required      pam_faillock.so preauth silent' "$pam_file"
        sed -i --follow-symlinks '/^auth.*required.*pam_deny\.so.*/i auth        required      pam_faillock.so authfail' "$pam_file"
        sed -i --follow-symlinks '/^account.*required.*pam_unix\.so.*/i account     required      pam_faillock.so' "$pam_file"
    fi
    sed -Ei 's/(auth.*)(\[default=die\])(.*pam_faillock\.so)/\1required     \3/g' "$pam_file"
done

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="account_password_pam_faillock_system_auth" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020025
  - NIST-800-53-AC-7 (a)
  - account_password_pam_faillock_system_auth
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth
    File. - Check if system relies on authselect tool
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020025
  - NIST-800-53-AC-7 (a)
  - account_password_pam_faillock_system_auth
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth
    File. - Remediation where authselect tool is present
  block:

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth
      File. - Check integrity of authselect current profile
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth
      File. - Informative message based on the authselect integrity check result
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth
      File. - Get authselect current features
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth
      File. - Ensure "with-faillock" feature is enabled using authselect tool
    ansible.builtin.command:
      cmd: authselect enable-feature with-faillock
    register: result_authselect_enable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is not search("with-faillock")

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth
      File. - Ensure authselect changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_enable_feature_cmd is not skipped
    - result_authselect_enable_feature_cmd is success
  when:
  - '"kernel" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020025
  - NIST-800-53-AC-7 (a)
  - account_password_pam_faillock_system_auth
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth
    File. - Remediation where authselect tool is not present
  block:

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth
      File. - Check if pam_faillock.so is already enabled
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail)
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_is_enabled

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth
      File. - Enable pam_faillock.so preauth editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so preauth
      insertbefore: ^auth.*sufficient.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth
      File. - Enable pam_faillock.so authfail editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so authfail
      insertbefore: ^auth.*required.*pam_deny\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth
      File. - Enable pam_faillock.so account section editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: account     required      pam_faillock.so
      insertbefore: ^account.*required.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - not result_authselect_present.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020025
  - NIST-800-53-AC-7 (a)
  - account_password_pam_faillock_system_auth
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-account_password_pam_faillock_system_auth:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-account_password_pam_faillock_system_auth_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_account_password_selinux_faillock_dir" selected="false" severity="medium">
                <xccdf-1.2:title>An SELinux Context must be configured for the pam_faillock.so records directory</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>dir</html:code> configuration option in PAM pam_faillock.so module defines where the lockout
records is stored. The configured directory must have the correct SELinux context.</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-7 (a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000021-GPOS-00005</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020027</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020028</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-250315r1017356_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-250316r1017357_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Not having the correct SELinux context on the pam_faillock.so records directory may lead to
unauthorized access to the directory.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix id="account_password_selinux_faillock_dir" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

FAILLOCK_CONF_FILES="/etc/security/faillock.conf /etc/pam.d/system-auth /etc/pam.d/password-auth"

faillock_dirs=$(grep -oP "^\s*(?:auth.*pam_faillock.so.*)?dir\s*=\s*(\S+)" $FAILLOCK_CONF_FILES \
               | sed -r 's/.*=\s*(\S+)/\1/')

# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to semanage and restorecon commands to avoid the issue with the command
# not being found.
if [ -n "$faillock_dirs" ]; then
    for dir in $faillock_dirs; do
        if ! /usr/sbin/semanage fcontext -a -t faillog_t "$dir(/.*)?"; then
            /usr/sbin/semanage fcontext -m -t faillog_t "$dir(/.*)?"
        fi
        if [ ! -e $dir ]; then
            mkdir -p $dir
        fi
        /usr/sbin/restorecon -R -v $dir
    done
else
echo "
The pam_faillock.so dir option is not set in the system.
If this is not expected, make sure pam_faillock.so is properly configured."
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="account_password_selinux_faillock_dir" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020027
  - DISA-STIG-RHEL-08-020028
  - NIST-800-53-AC-7 (a)
  - account_password_selinux_faillock_dir
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: An SELinux Context must be configured for the pam_faillock.so records directory
    - Get directories from faillock
  ansible.builtin.shell: grep -oP '^\s*(?:auth.*pam_faillock.so.*)?dir\s*=\s*(\S+)'
    "{{ item }}" | sed -r 's/.*=\s*(\S+)/\1/'
  register: faillock_output
  changed_when: false
  check_mode: false
  with_items:
  - /etc/security/faillock.conf
  - /etc/pam.d/system-auth
  - /etc/pam.d/password-auth
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020027
  - DISA-STIG-RHEL-08-020028
  - NIST-800-53-AC-7 (a)
  - account_password_selinux_faillock_dir
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: An SELinux Context must be configured for the pam_faillock.so records directory
    - Create a list directories from faillock
  ansible.builtin.set_fact:
    list_faillock_dir: '{{ faillock_output.results | map(attribute=''stdout_lines'')
      | flatten }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020027
  - DISA-STIG-RHEL-08-020028
  - NIST-800-53-AC-7 (a)
  - account_password_selinux_faillock_dir
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: An SELinux Context must be configured for the pam_faillock.so records directory
    - Create directories for faillock
  ansible.builtin.file:
    path: '{{ item }}'
    state: directory
  with_items: '{{ list_faillock_dir }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item != ""
  tags:
  - DISA-STIG-RHEL-08-020027
  - DISA-STIG-RHEL-08-020028
  - NIST-800-53-AC-7 (a)
  - account_password_selinux_faillock_dir
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: An SELinux Context must be configured for the pam_faillock.so records directory
    - Get SELinux context for faillock directories
  ansible.builtin.command: ls -dZ "{{ item }}"
  register: faillock_selinux_context
  changed_when: false
  check_mode: false
  with_items: '{{ list_faillock_dir }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item != ""
  tags:
  - DISA-STIG-RHEL-08-020027
  - DISA-STIG-RHEL-08-020028
  - NIST-800-53-AC-7 (a)
  - account_password_selinux_faillock_dir
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: An SELinux Context must be configured for the pam_faillock.so records directory
    - Set up SELinux context for faillock
  ansible.builtin.shell: |-
    if ! semanage fcontext -a -t faillog_t "{{ item.item }}(/.*)?"; then
      semanage fcontext -m -t faillog_t "{{ item.item }}(/.*)?"
    fi
  with_items: '{{ faillock_selinux_context.results }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.item != ""
  - item.stdout is defined
  - '"faillog_t" not in item.stdout'
  tags:
  - DISA-STIG-RHEL-08-020027
  - DISA-STIG-RHEL-08-020028
  - NIST-800-53-AC-7 (a)
  - account_password_selinux_faillock_dir
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: An SELinux Context must be configured for the pam_faillock.so records directory
    - Restore SELinux context
  ansible.builtin.command: restorecon -R -v "{{ item.item }}"
  with_items: '{{ faillock_selinux_context.results }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.item != ""
  - item.stdout is defined
  - '"faillog_t" not in item.stdout'
  tags:
  - DISA-STIG-RHEL-08-020027
  - DISA-STIG-RHEL-08-020028
  - NIST-800-53-AC-7 (a)
  - account_password_selinux_faillock_dir
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: An SELinux Context must be configured for the pam_faillock.so records directory
    - Verify pam_faillock.so configuration
  ansible.builtin.debug:
    msg: |-
      "The pam_faillock.so dir option is not set in the system.
      If this is not expected, make sure pam_faillock.so is properly configured."
  when:
  - '"kernel" in ansible_facts.packages'
  - list_faillock_dir | length == 0
  tags:
  - DISA-STIG-RHEL-08-020027
  - DISA-STIG-RHEL-08-020028
  - NIST-800-53-AC-7 (a)
  - account_password_selinux_faillock_dir
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-account_password_selinux_faillock_dir:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-account_password_selinux_faillock_dir_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_account_passwords_pam_faillock_audit" selected="false" severity="medium">
                <xccdf-1.2:title>Account Lockouts Must Be Logged</xccdf-1.2:title>
                <xccdf-1.2:description>PAM faillock locks an account due to excessive password failures, this event must be logged.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">This rule is deprecated in favor of the <html:code>accounts_passwords_pam_faillock_audit</html:code> rule.Please consider replacing this rule in your files as it is not expected to receive
updates as of version <html:code>0.1.65</html:code>.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-7 (a)</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Without auditing of these events it may be harder or impossible to identify what an attacker did after an attack.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="account_passwords_pam_faillock_audit" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -f /usr/bin/authselect ]; then
    if ! authselect check; then
echo "
authselect integrity check failed. Remediation aborted!
This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
It is not recommended to manually edit the PAM files when authselect tool is available.
In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
exit 1
fi
authselect enable-feature with-faillock

authselect apply-changes -b
else
    
AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
for pam_file in "${AUTH_FILES[@]}"
do
    if ! grep -qE '^\s*auth\s+required\s+pam_faillock\.so\s+(preauth silent|authfail).*$' "$pam_file" ; then
        sed -i --follow-symlinks '/^auth.*sufficient.*pam_unix\.so.*/i auth        required      pam_faillock.so preauth silent' "$pam_file"
        sed -i --follow-symlinks '/^auth.*required.*pam_deny\.so.*/i auth        required      pam_faillock.so authfail' "$pam_file"
        sed -i --follow-symlinks '/^account.*required.*pam_unix\.so.*/i account     required      pam_faillock.so' "$pam_file"
    fi
    sed -Ei 's/(auth.*)(\[default=die\])(.*pam_faillock\.so)/\1required     \3/g' "$pam_file"
done

fi

AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
SKIP_FAILLOCK_CHECK=false

FAILLOCK_CONF="/etc/security/faillock.conf"
if [ -f $FAILLOCK_CONF ] || [ "$SKIP_FAILLOCK_CHECK" = "true" ]; then
    regex="^\s*audit"
    line="audit"
    if ! grep -q $regex $FAILLOCK_CONF; then
        echo $line &gt;&gt; $FAILLOCK_CONF
    fi
    
    for pam_file in "${AUTH_FILES[@]}"
    do
        if [ -e "$pam_file" ] ; then
            PAM_FILE_PATH="$pam_file"
            if [ -f /usr/bin/authselect ]; then
                
                if ! authselect check; then
                echo "
                authselect integrity check failed. Remediation aborted!
                This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
                It is not recommended to manually edit the PAM files when authselect tool is available.
                In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
                exit 1
                fi

                CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
                # If not already in use, a custom profile is created preserving the enabled features.
                if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                    ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                    # The "local" profile does not contain essential security features required by multiple Benchmarks.
                    # If currently used, it is replaced by "sssd", which is the best option in this case.
                    if [[ $CURRENT_PROFILE == local ]]; then
                        CURRENT_PROFILE="sssd"
                    fi
                    authselect create-profile hardening -b $CURRENT_PROFILE
                    CURRENT_PROFILE="custom/hardening"
                    
                    authselect apply-changes -b --backup=before-hardening-custom-profile
                    authselect select $CURRENT_PROFILE
                    for feature in $ENABLED_FEATURES; do
                        authselect enable-feature $feature;
                    done
                    
                    authselect apply-changes -b --backup=after-hardening-custom-profile
                fi
                PAM_FILE_NAME=$(basename "$pam_file")
                PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

                authselect apply-changes -b
            fi
            
        if grep -qP "^\s*auth\s.*\bpam_faillock.so\s.*\baudit\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "s/(.*auth.*pam_faillock.so.*)\baudit\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
        fi
            if [ -f /usr/bin/authselect ]; then
                
                authselect apply-changes -b
            fi
        else
            echo "$pam_file was not found" &gt;&amp;2
        fi
    done
    
else
    for pam_file in "${AUTH_FILES[@]}"
    do
        if ! grep -qE '^\s*auth.*pam_faillock\.so\s+(preauth|authfail).*audit' "$pam_file"; then
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*preauth.*/ s/$/ audit/' "$pam_file"
        fi
    done
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="account_passwords_pam_faillock_audit" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-7 (a)
  - account_passwords_pam_faillock_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Account Lockouts Must Be Logged - Check if system relies on authselect tool
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-7 (a)
  - account_passwords_pam_faillock_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Account Lockouts Must Be Logged - Remediation where authselect tool is present
  block:

  - name: Account Lockouts Must Be Logged - Check integrity of authselect current
      profile
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: Account Lockouts Must Be Logged - Informative message based on the authselect
      integrity check result
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: Account Lockouts Must Be Logged - Get authselect current features
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: Account Lockouts Must Be Logged - Ensure "with-faillock" feature is enabled
      using authselect tool
    ansible.builtin.command:
      cmd: authselect enable-feature with-faillock
    register: result_authselect_enable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is not search("with-faillock")

  - name: Account Lockouts Must Be Logged - Ensure authselect changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_enable_feature_cmd is not skipped
    - result_authselect_enable_feature_cmd is success
  when:
  - '"kernel" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  tags:
  - NIST-800-53-AC-7 (a)
  - account_passwords_pam_faillock_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Account Lockouts Must Be Logged - Remediation where authselect tool is not
    present
  block:

  - name: Account Lockouts Must Be Logged - Check if pam_faillock.so is already enabled
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail)
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_is_enabled

  - name: Account Lockouts Must Be Logged - Enable pam_faillock.so preauth editing
      PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so preauth
      insertbefore: ^auth.*sufficient.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Account Lockouts Must Be Logged - Enable pam_faillock.so authfail editing
      PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so authfail
      insertbefore: ^auth.*required.*pam_deny\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Account Lockouts Must Be Logged - Enable pam_faillock.so account section
      editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: account     required      pam_faillock.so
      insertbefore: ^account.*required.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - not result_authselect_present.stat.exists
  tags:
  - NIST-800-53-AC-7 (a)
  - account_passwords_pam_faillock_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Account Lockouts Must Be Logged - Check the presence of /etc/security/faillock.conf
    file
  ansible.builtin.stat:
    path: /etc/security/faillock.conf
  register: result_faillock_conf_check
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-7 (a)
  - account_passwords_pam_faillock_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Account Lockouts Must Be Logged - Ensure the pam_faillock.so audit parameter
    in /etc/security/faillock.conf
  ansible.builtin.lineinfile:
    path: /etc/security/faillock.conf
    regexp: ^\s*audit
    line: audit
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - NIST-800-53-AC-7 (a)
  - account_passwords_pam_faillock_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Account Lockouts Must Be Logged - Ensure the pam_faillock.so audit parameter
    not in PAM files
  block:

  - name: Account Lockouts Must Be Logged - Check if /etc/pam.d/system-auth file is
      present
    ansible.builtin.stat:
      path: /etc/pam.d/system-auth
    register: result_pam_auth_file_present

  - name: Account Lockouts Must Be Logged - Check the proper remediation for the system
    block:

    - name: Account Lockouts Must Be Logged - Define the PAM file to be edited as
        a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/system-auth

    - name: Account Lockouts Must Be Logged - Check if system relies on authselect
        tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Account Lockouts Must Be Logged - Ensure authselect custom profile is
        used if authselect is present
      block:

      - name: Account Lockouts Must Be Logged - Check integrity of authselect current
          profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Account Lockouts Must Be Logged - Informative message based on the authselect
          integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Account Lockouts Must Be Logged - Get authselect current profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Account Lockouts Must Be Logged - Define the current authselect profile
          as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Account Lockouts Must Be Logged - Define the new authselect custom profile
          as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Account Lockouts Must Be Logged - Get authselect current features to
          also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Account Lockouts Must Be Logged - Check if any custom profile with the
          same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Account Lockouts Must Be Logged - Create an authselect custom profile
          based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Account Lockouts Must Be Logged - Create an authselect custom profile
          based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Account Lockouts Must Be Logged - Ensure authselect changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Account Lockouts Must Be Logged - Ensure the authselect custom profile
          is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Account Lockouts Must Be Logged - Restore the authselect features in
          the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Account Lockouts Must Be Logged - Ensure authselect changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Account Lockouts Must Be Logged - Change the PAM file to be edited according
          to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Account Lockouts Must Be Logged - Define a fact for control already filtered
        in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Account Lockouts Must Be Logged - Check if {{ pam_file_path }} file is
        present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Account Lockouts Must Be Logged - Ensure the "audit" option from "pam_faillock.so"
        is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\baudit\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Account Lockouts Must Be Logged - Ensure authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_auth_file_present.stat.exists

  - name: Account Lockouts Must Be Logged - Check if /etc/pam.d/password-auth file
      is present
    ansible.builtin.stat:
      path: /etc/pam.d/password-auth
    register: result_pam_password_auth_file_present

  - name: Account Lockouts Must Be Logged - Check the proper remediation for the system
    block:

    - name: Account Lockouts Must Be Logged - Define the PAM file to be edited as
        a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/password-auth

    - name: Account Lockouts Must Be Logged - Check if system relies on authselect
        tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Account Lockouts Must Be Logged - Ensure authselect custom profile is
        used if authselect is present
      block:

      - name: Account Lockouts Must Be Logged - Check integrity of authselect current
          profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Account Lockouts Must Be Logged - Informative message based on the authselect
          integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Account Lockouts Must Be Logged - Get authselect current profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Account Lockouts Must Be Logged - Define the current authselect profile
          as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Account Lockouts Must Be Logged - Define the new authselect custom profile
          as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Account Lockouts Must Be Logged - Get authselect current features to
          also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Account Lockouts Must Be Logged - Check if any custom profile with the
          same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Account Lockouts Must Be Logged - Create an authselect custom profile
          based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Account Lockouts Must Be Logged - Create an authselect custom profile
          based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Account Lockouts Must Be Logged - Ensure authselect changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Account Lockouts Must Be Logged - Ensure the authselect custom profile
          is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Account Lockouts Must Be Logged - Restore the authselect features in
          the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Account Lockouts Must Be Logged - Ensure authselect changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Account Lockouts Must Be Logged - Change the PAM file to be edited according
          to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Account Lockouts Must Be Logged - Define a fact for control already filtered
        in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Account Lockouts Must Be Logged - Check if {{ pam_file_path }} file is
        present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Account Lockouts Must Be Logged - Ensure the "audit" option from "pam_faillock.so"
        is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\baudit\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Account Lockouts Must Be Logged - Ensure authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_password_auth_file_present.stat.exists
  when:
  - '"kernel" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - NIST-800-53-AC-7 (a)
  - account_passwords_pam_faillock_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Account Lockouts Must Be Logged - Ensure the pam_faillock.so audit parameter
    in PAM files
  block:

  - name: Account Lockouts Must Be Logged - Check if pam_faillock.so audit parameter
      is already enabled in pam files
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail).*audit
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_audit_parameter_is_present

  - name: Account Lockouts Must Be Logged - Ensure the inclusion of pam_faillock.so
      preauth audit parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so preauth.*)
      line: \1required\3 audit
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_audit_parameter_is_present.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - not result_faillock_conf_check.stat.exists
  tags:
  - NIST-800-53-AC-7 (a)
  - account_passwords_pam_faillock_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-account_passwords_pam_faillock_audit:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-account_passwords_pam_faillock_audit_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_account_passwords_pam_faillock_dir" selected="false" severity="medium">
                <xccdf-1.2:title>Account Lockouts Must Persist</xccdf-1.2:title>
                <xccdf-1.2:description>By setting a `dir` in the faillock configuration account lockouts will persist across reboots.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">This rule is deprecated in favor of the <html:code>accounts_passwords_pam_faillock_dir</html:code> rule.Please consider replacing this rule in your files as it is not expected to receive
updates as of version <html:code>0.1.65</html:code>.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-7 (ia)</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Having lockouts persist across reboots ensures that account is only unlocked by an administrator.
If the lockouts did not persist across reboots an attack could simply reboot the system to continue brute force attacks against the accounts on the system.
</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-account_passwords_pam_faillock_dir_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_enforce_for_root" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure Password History Is Enforced for the Root User</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>enforce_for_root</html:code> option enforces password history for the root user.
Enable the <html:code>enforce_for_root</html:code> setting in <html:code>/etc/security/pwhistory.conf</html:code>
to require the <html:code>root</html:code> user to use a password that has not been used recently.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.3.2</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Requiring users not to reuse their passwords make it less likely that an attacker will be
able to guess the password or use a compromised password.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_pwhistory_enforce_for_root" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q pam; }; then

if [ -e "/etc/security/pwhistory.conf" ] ; then
    
    LC_ALL=C sed -i "/^\s*enforce_for_root/Id" "/etc/security/pwhistory.conf"
else
    touch "/etc/security/pwhistory.conf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/security/pwhistory.conf"

cp "/etc/security/pwhistory.conf" "/etc/security/pwhistory.conf.bak"
# Insert at the end of the file
printf '%s\n' "enforce_for_root" &gt;&gt; "/etc/security/pwhistory.conf"
# Clean up after ourselves.
rm "/etc/security/pwhistory.conf.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_pwhistory_enforce_for_root" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - accounts_password_pam_pwhistory_enforce_for_root
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Password History Is Enforced for the Root User
  ansible.builtin.lineinfile:
    path: /etc/security/pwhistory.conf
    create: true
    regexp: ''
    line: enforce_for_root
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - accounts_password_pam_pwhistory_enforce_for_root
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_pwhistory_enforce_for_root:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_remember_password_auth" selected="false" severity="medium">
                <xccdf-1.2:title>Limit Password Reuse: password-auth</xccdf-1.2:title>
                <xccdf-1.2:description>Do not allow users to reuse recent passwords. This can be accomplished by using the
<html:code>remember</html:code> option for the <html:code>pam_pwhistory</html:code> PAM module.
<html:br/><html:br/>

On systems with newer versions of <html:code>authselect</html:code>, the <html:code>pam_pwhistory</html:code> PAM module
can be enabled via authselect feature:
<html:pre>authselect enable-feature with-pwhistory</html:pre>

Otherwise, it should be enabled using an authselect custom profile.
<html:br/><html:br/>
Newer systems also have the <html:code>/etc/security/pwhistory.conf</html:code> file for setting
<html:code>pam_pwhistory</html:code> module options. This file should be used whenever available.
Otherwise, the <html:code>pam_pwhistory</html:code> module options can be set in PAM files.
<html:br/><html:br/>
The value for <html:code>remember</html:code> option must be equal or greater than
<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_remember" use="legacy"/></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">If the system relies on <html:code>authselect</html:code> tool to manage PAM settings, the remediation
will also use <html:code>authselect</html:code> tool. However, if any manual modification was made in
PAM files, the <html:code>authselect</html:code> integrity check will fail and the remediation will be
aborted in order to preserve intentional changes. In this case, an informative message will
be shown in the remediation report.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="general">Newer versions of <html:code>authselect</html:code> contain an authselect feature to easily and properly
enable <html:code>pam_pwhistory.so</html:code> module. If this feature is not yet available in your
system, an authselect custom profile must be used to avoid integrity issues in PAM files.
If a custom profile was created and used in the system before this authselect feature was
available, the new feature can't be used with this custom profile and the
remediation will fail. In this case, the custom profile should be recreated or manually
updated.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.6.2.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(f)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(e)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000077-GPOS-00045</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.3.1</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Preventing reuse of previous passwords helps ensure that a compromised password is not
reused by a user.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix id="accounts_password_pam_pwhistory_remember_password_auth" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q pam; }; then

var_password_pam_remember='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_remember" use="legacy"/>'
var_password_pam_remember_control_flag='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_remember_control_flag" use="legacy"/>'


var_password_pam_remember_control_flag="$(echo $var_password_pam_remember_control_flag | cut -d \, -f 1)"

if [ -f /usr/bin/authselect ]; then
    if authselect list-features sssd | grep -q with-pwhistory; then
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi
        authselect enable-feature with-pwhistory

        authselect apply-changes -b
    else
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "/etc/pam.d/password-auth")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
        
        if ! grep -qP "^\s*password\s+\$var_password_pam_remember_control_flag\s+pam_pwhistory.so\s*.*" "$PAM_FILE_PATH"; then
            # Line matching group + control + module was not found. Check group + module.
            if [ "$(grep -cP '^\s*password\s+.*\s+pam_pwhistory.so\s*' "$PAM_FILE_PATH")" -eq 1 ]; then
                # The control is updated only if one single line matches.
                sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_pwhistory.so.*)/\1$var_password_pam_remember_control_flag \2/" "$PAM_FILE_PATH"
            else
                LAST_MATCH_LINE=$(grep -nP "^password.*requisite.*pam_pwquality\.so" "$PAM_FILE_PATH" | tail -n 1 | cut -d: -f 1)
                if [ ! -z $LAST_MATCH_LINE ]; then
                    sed -i --follow-symlinks $LAST_MATCH_LINE" a password     $var_password_pam_remember_control_flag    pam_pwhistory.so" "$PAM_FILE_PATH"
                else
                    echo "password    $var_password_pam_remember_control_flag    pam_pwhistory.so" &gt;&gt; "$PAM_FILE_PATH"
                fi
            fi
        fi
    fi
else

    
    if ! grep -qP "^\s*password\s+\$var_password_pam_remember_control_flag\s+pam_pwhistory.so\s*.*" "/etc/pam.d/password-auth"; then
        # Line matching group + control + module was not found. Check group + module.
        if [ "$(grep -cP '^\s*password\s+.*\s+pam_pwhistory.so\s*' "/etc/pam.d/password-auth")" -eq 1 ]; then
            # The control is updated only if one single line matches.
            sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_pwhistory.so.*)/\1$var_password_pam_remember_control_flag \2/" "/etc/pam.d/password-auth"
        else
            LAST_MATCH_LINE=$(grep -nP "^password.*requisite.*pam_pwquality\.so" "/etc/pam.d/password-auth" | tail -n 1 | cut -d: -f 1)
            if [ ! -z $LAST_MATCH_LINE ]; then
                sed -i --follow-symlinks $LAST_MATCH_LINE" a password     $var_password_pam_remember_control_flag    pam_pwhistory.so" "/etc/pam.d/password-auth"
            else
                echo "password    $var_password_pam_remember_control_flag    pam_pwhistory.so" &gt;&gt; "/etc/pam.d/password-auth"
            fi
        fi
    fi

fi

PWHISTORY_CONF="/etc/security/pwhistory.conf"
if [ -f $PWHISTORY_CONF ]; then
    regex="^\s*remember\s*="
    line="remember = $var_password_pam_remember"
    if ! grep -q $regex $PWHISTORY_CONF; then
        echo $line &gt;&gt; $PWHISTORY_CONF
    else
        sed -i --follow-symlinks 's|^\s*\(remember\s*=\s*\)\(\S\+\)|\1'"$var_password_pam_remember"'|g' $PWHISTORY_CONF
    fi
    if [ -e "/etc/pam.d/password-auth" ] ; then
        PAM_FILE_PATH="/etc/pam.d/password-auth"
        if [ -f /usr/bin/authselect ]; then
            
            if ! authselect check; then
            echo "
            authselect integrity check failed. Remediation aborted!
            This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
            It is not recommended to manually edit the PAM files when authselect tool is available.
            In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
            exit 1
            fi

            CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
            # If not already in use, a custom profile is created preserving the enabled features.
            if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                # The "local" profile does not contain essential security features required by multiple Benchmarks.
                # If currently used, it is replaced by "sssd", which is the best option in this case.
                if [[ $CURRENT_PROFILE == local ]]; then
                    CURRENT_PROFILE="sssd"
                fi
                authselect create-profile hardening -b $CURRENT_PROFILE
                CURRENT_PROFILE="custom/hardening"
                
                authselect apply-changes -b --backup=before-hardening-custom-profile
                authselect select $CURRENT_PROFILE
                for feature in $ENABLED_FEATURES; do
                    authselect enable-feature $feature;
                done
                
                authselect apply-changes -b --backup=after-hardening-custom-profile
            fi
            PAM_FILE_NAME=$(basename "/etc/pam.d/password-auth")
            PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

            authselect apply-changes -b
        fi
        
    if grep -qP "^\s*password\s.*\bpam_pwhistory.so\s.*\bremember\b" "$PAM_FILE_PATH"; then
        sed -i -E --follow-symlinks "s/(.*password.*pam_pwhistory.so.*)\bremember\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
    fi
        if [ -f /usr/bin/authselect ]; then
            
            authselect apply-changes -b
        fi
    else
        echo "/etc/pam.d/password-auth was not found" &gt;&amp;2
    fi
else
    PAM_FILE_PATH="/etc/pam.d/password-auth"
    if [ -f /usr/bin/authselect ]; then
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "/etc/pam.d/password-auth")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
    fi
    

    if ! grep -qP "^\s*password\s+requisite\s+pam_pwhistory.so\s*.*" "$PAM_FILE_PATH"; then
        # Line matching group + control + module was not found. Check group + module.
        if [ "$(grep -cP '^\s*password\s+.*\s+pam_pwhistory.so\s*' "$PAM_FILE_PATH")" -eq 1 ]; then
            # The control is updated only if one single line matches.
            sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_pwhistory.so.*)/\1requisite \2/" "$PAM_FILE_PATH"
        else
            echo "password    requisite    pam_pwhistory.so" &gt;&gt; "$PAM_FILE_PATH"
        fi
    fi
    # Check the option
    if ! grep -qP "^\s*password\s+requisite\s+pam_pwhistory.so\s*.*\sremember\b" "$PAM_FILE_PATH"; then
        sed -i -E --follow-symlinks "/\s*password\s+requisite\s+pam_pwhistory.so.*/ s/$/ remember=$var_password_pam_remember/" "$PAM_FILE_PATH"
    else
        sed -i -E --follow-symlinks "s/(\s*password\s+requisite\s+pam_pwhistory.so\s+.*)(remember=)[[:alnum:]]*\s*(.*)/\1\2$var_password_pam_remember \3/" "$PAM_FILE_PATH"
    fi
    if [ -f /usr/bin/authselect ]; then
        
        authselect apply-changes -b
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="accounts_password_pam_pwhistory_remember_password_auth" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_pwhistory_remember_password_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
- name: XCCDF Value var_password_pam_remember # promote to variable
  set_fact:
    var_password_pam_remember: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_remember" use="legacy"/>
  tags:
    - always
- name: XCCDF Value var_password_pam_remember_control_flag # promote to variable
  set_fact:
    var_password_pam_remember_control_flag: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_remember_control_flag" use="legacy"/>
  tags:
    - always

- name: 'Limit Password Reuse: password-auth - Check if system relies on authselect
    tool'
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_pwhistory_remember_password_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Limit Password Reuse: password-auth - Collect the available authselect features'
  ansible.builtin.command:
    cmd: authselect list-features sssd
  register: result_authselect_available_features
  changed_when: false
  check_mode: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_pwhistory_remember_password_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Limit Password Reuse: password-auth - Enable pam_pwhistory.so using authselect
    feature'
  block:

  - name: 'Limit Password Reuse: password-auth - Check integrity of authselect current
      profile'
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: 'Limit Password Reuse: password-auth - Informative message based on the
      authselect integrity check result'
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: 'Limit Password Reuse: password-auth - Get authselect current features'
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: 'Limit Password Reuse: password-auth - Ensure "with-pwhistory" feature is
      enabled using authselect tool'
    ansible.builtin.command:
      cmd: authselect enable-feature with-pwhistory
    register: result_authselect_enable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is not search("with-pwhistory")

  - name: 'Limit Password Reuse: password-auth - Ensure authselect changes are applied'
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_enable_feature_cmd is not skipped
    - result_authselect_enable_feature_cmd is success
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  - result_authselect_available_features.stdout is search("with-pwhistory")
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_pwhistory_remember_password_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Limit Password Reuse: password-auth - Enable pam_pwhistory.so in appropriate
    PAM files'
  block:

  - name: 'Limit Password Reuse: password-auth - Define the PAM file to be edited
      as a local fact'
    ansible.builtin.set_fact:
      pam_file_path: /etc/pam.d/password-auth

  - name: 'Limit Password Reuse: password-auth - Check if system relies on authselect
      tool'
    ansible.builtin.stat:
      path: /usr/bin/authselect
    register: result_authselect_present

  - name: 'Limit Password Reuse: password-auth - Ensure authselect custom profile
      is used if authselect is present'
    block:

    - name: 'Limit Password Reuse: password-auth - Check integrity of authselect current
        profile'
      ansible.builtin.command:
        cmd: authselect check
      register: result_authselect_check_cmd
      changed_when: false
      check_mode: false
      failed_when: false

    - name: 'Limit Password Reuse: password-auth - Informative message based on the
        authselect integrity check result'
      ansible.builtin.assert:
        that:
        - ansible_check_mode or result_authselect_check_cmd.rc == 0
        fail_msg:
        - authselect integrity check failed. Remediation aborted!
        - This remediation could not be applied because an authselect profile was
          not selected or the selected profile is not intact.
        - It is not recommended to manually edit the PAM files when authselect tool
          is available.
        - In cases where the default authselect profile does not cover a specific
          demand, a custom authselect profile is recommended.
        success_msg:
        - authselect integrity check passed

    - name: 'Limit Password Reuse: password-auth - Get authselect current profile'
      ansible.builtin.shell:
        cmd: authselect current -r | awk '{ print $1 }'
      register: result_authselect_profile
      changed_when: false
      when:
      - result_authselect_check_cmd is success

    - name: 'Limit Password Reuse: password-auth - Define the current authselect profile
        as a local fact'
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is match("custom/")

    - name: 'Limit Password Reuse: password-auth - Define the new authselect custom
        profile as a local fact'
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: custom/hardening
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is not match("custom/")

    - name: 'Limit Password Reuse: password-auth - Get authselect current features
        to also enable them in the custom profile'
      ansible.builtin.shell:
        cmd: authselect current | tail -n+3 | awk '{ print $2 }'
      register: result_authselect_features
      changed_when: false
      check_mode: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: 'Limit Password Reuse: password-auth - Check if any custom profile with
        the same name was already created'
      ansible.builtin.stat:
        path: /etc/authselect/{{ authselect_custom_profile }}
      register: result_authselect_custom_profile_present
      changed_when: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: 'Limit Password Reuse: password-auth - Create an authselect custom profile
        based on the current profile'
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b {{ authselect_current_profile
          }}
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is not match("^(custom/|local)")
      - not result_authselect_custom_profile_present.stat.exists

    - name: 'Limit Password Reuse: password-auth - Create an authselect custom profile
        based on sssd profile'
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b sssd
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is match("local")
      - not result_authselect_custom_profile_present.stat.exists

    - name: 'Limit Password Reuse: password-auth - Ensure authselect changes are applied'
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: 'Limit Password Reuse: password-auth - Ensure the authselect custom profile
        is selected'
      ansible.builtin.command:
        cmd: authselect select {{ authselect_custom_profile }}
      register: result_pam_authselect_select_profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: 'Limit Password Reuse: password-auth - Restore the authselect features
        in the custom profile'
      ansible.builtin.command:
        cmd: authselect enable-feature {{ item }}
      loop: '{{ result_authselect_features.stdout_lines }}'
      register: result_pam_authselect_restore_features
      when:
      - result_authselect_profile is not skipped
      - result_authselect_features is not skipped
      - result_pam_authselect_select_profile is not skipped

    - name: 'Limit Password Reuse: password-auth - Ensure authselect changes are applied'
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - result_pam_authselect_restore_features is not skipped

    - name: 'Limit Password Reuse: password-auth - Change the PAM file to be edited
        according to the custom authselect profile'
      ansible.builtin.set_fact:
        pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
          | basename }}
      when:
      - authselect_custom_profile is defined
    when:
    - result_authselect_present.stat.exists

  - name: 'Limit Password Reuse: password-auth - Define a fact for control already
      filtered in case filters are used'
    ansible.builtin.set_fact:
      pam_module_control: '{{ var_password_pam_remember_control_flag.split(",")[0]
        }}'

  - name: 'Limit Password Reuse: password-auth - Check if expected PAM module line
      is present in {{ pam_file_path }}'
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwhistory.so\s*.*
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_line_present

  - name: 'Limit Password Reuse: password-auth - Include or update the PAM module
      line in {{ pam_file_path }}'
    block:

    - name: 'Limit Password Reuse: password-auth - Check if required PAM module line
        is present in {{ pam_file_path }} with different control'
      ansible.builtin.lineinfile:
        path: '{{ pam_file_path }}'
        regexp: ^\s*password\s+.*\s+pam_pwhistory.so\s*
        state: absent
      check_mode: true
      changed_when: false
      register: result_pam_line_other_control_present

    - name: 'Limit Password Reuse: password-auth - Ensure the correct control for
        the required PAM module line in {{ pam_file_path }}'
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: ^(\s*password\s+).*(\bpam_pwhistory.so.*)
        replace: \1{{ pam_module_control }} \2
      register: result_pam_module_edit
      when:
      - result_pam_line_other_control_present.found == 1

    - name: 'Limit Password Reuse: password-auth - Ensure the required PAM module
        line is included in {{ pam_file_path }}'
      ansible.builtin.lineinfile:
        dest: '{{ pam_file_path }}'
        insertafter: ^password.*requisite.*pam_pwquality\.so
        line: password    {{ pam_module_control }}    pam_pwhistory.so
      register: result_pam_module_add
      when:
      - result_pam_line_other_control_present.found == 0 or result_pam_line_other_control_present.found
        &gt; 1

    - name: 'Limit Password Reuse: password-auth - Ensure authselect changes are applied'
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present is defined
      - result_authselect_present.stat.exists
      - |-
        (result_pam_module_add is defined and result_pam_module_add.changed)
         or (result_pam_module_edit is defined and result_pam_module_edit.changed)
    when:
    - result_pam_line_present.found is defined
    - result_pam_line_present.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - |
    (result_authselect_available_features.stdout is defined and result_authselect_available_features.stdout is not search("with-pwhistory")) or result_authselect_available_features is not defined
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_pwhistory_remember_password_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Limit Password Reuse: password-auth - Check the presence of /etc/security/pwhistory.conf
    file'
  ansible.builtin.stat:
    path: /etc/security/pwhistory.conf
  register: result_pwhistory_conf_check
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_pwhistory_remember_password_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Limit Password Reuse: password-auth - pam_pwhistory.so parameters are configured
    in /etc/security/pwhistory.conf file'
  block:

  - name: 'Limit Password Reuse: password-auth - Ensure the pam_pwhistory.so remember
      parameter in /etc/security/pwhistory.conf'
    ansible.builtin.lineinfile:
      path: /etc/security/pwhistory.conf
      regexp: ^\s*remember\s*=
      line: remember = {{ var_password_pam_remember }}
      state: present

  - name: 'Limit Password Reuse: password-auth - Ensure the pam_pwhistory.so remember
      parameter is removed from PAM files'
    block:

    - name: 'Limit Password Reuse: password-auth - Check if /etc/pam.d/password-auth
        file is present'
      ansible.builtin.stat:
        path: /etc/pam.d/password-auth
      register: result_pam_password_auth_file_present

    - name: 'Limit Password Reuse: password-auth - Check the proper remediation for
        the system'
      block:

      - name: 'Limit Password Reuse: password-auth - Define the PAM file to be edited
          as a local fact'
        ansible.builtin.set_fact:
          pam_file_path: /etc/pam.d/password-auth

      - name: 'Limit Password Reuse: password-auth - Check if system relies on authselect
          tool'
        ansible.builtin.stat:
          path: /usr/bin/authselect
        register: result_authselect_present

      - name: 'Limit Password Reuse: password-auth - Ensure authselect custom profile
          is used if authselect is present'
        block:

        - name: 'Limit Password Reuse: password-auth - Check integrity of authselect
            current profile'
          ansible.builtin.command:
            cmd: authselect check
          register: result_authselect_check_cmd
          changed_when: false
          check_mode: false
          failed_when: false

        - name: 'Limit Password Reuse: password-auth - Informative message based on
            the authselect integrity check result'
          ansible.builtin.assert:
            that:
            - ansible_check_mode or result_authselect_check_cmd.rc == 0
            fail_msg:
            - authselect integrity check failed. Remediation aborted!
            - This remediation could not be applied because an authselect profile
              was not selected or the selected profile is not intact.
            - It is not recommended to manually edit the PAM files when authselect
              tool is available.
            - In cases where the default authselect profile does not cover a specific
              demand, a custom authselect profile is recommended.
            success_msg:
            - authselect integrity check passed

        - name: 'Limit Password Reuse: password-auth - Get authselect current profile'
          ansible.builtin.shell:
            cmd: authselect current -r | awk '{ print $1 }'
          register: result_authselect_profile
          changed_when: false
          when:
          - result_authselect_check_cmd is success

        - name: 'Limit Password Reuse: password-auth - Define the current authselect
            profile as a local fact'
          ansible.builtin.set_fact:
            authselect_current_profile: '{{ result_authselect_profile.stdout }}'
            authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
          when:
          - result_authselect_profile is not skipped
          - result_authselect_profile.stdout is match("custom/")

        - name: 'Limit Password Reuse: password-auth - Define the new authselect custom
            profile as a local fact'
          ansible.builtin.set_fact:
            authselect_current_profile: '{{ result_authselect_profile.stdout }}'
            authselect_custom_profile: custom/hardening
          when:
          - result_authselect_profile is not skipped
          - result_authselect_profile.stdout is not match("custom/")

        - name: 'Limit Password Reuse: password-auth - Get authselect current features
            to also enable them in the custom profile'
          ansible.builtin.shell:
            cmd: authselect current | tail -n+3 | awk '{ print $2 }'
          register: result_authselect_features
          changed_when: false
          check_mode: false
          when:
          - result_authselect_profile is not skipped
          - authselect_current_profile is not match("custom/")

        - name: 'Limit Password Reuse: password-auth - Check if any custom profile
            with the same name was already created'
          ansible.builtin.stat:
            path: /etc/authselect/{{ authselect_custom_profile }}
          register: result_authselect_custom_profile_present
          changed_when: false
          when:
          - result_authselect_profile is not skipped
          - authselect_current_profile is not match("custom/")

        - name: 'Limit Password Reuse: password-auth - Create an authselect custom
            profile based on the current profile'
          ansible.builtin.command:
            cmd: authselect create-profile hardening -b {{ authselect_current_profile
              }}
          when:
          - result_authselect_profile is not skipped
          - result_authselect_check_cmd is success
          - authselect_current_profile is not match("^(custom/|local)")
          - not result_authselect_custom_profile_present.stat.exists

        - name: 'Limit Password Reuse: password-auth - Create an authselect custom
            profile based on sssd profile'
          ansible.builtin.command:
            cmd: authselect create-profile hardening -b sssd
          when:
          - result_authselect_profile is not skipped
          - result_authselect_check_cmd is success
          - authselect_current_profile is match("local")
          - not result_authselect_custom_profile_present.stat.exists

        - name: 'Limit Password Reuse: password-auth - Ensure authselect changes are
            applied'
          ansible.builtin.command:
            cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
          when:
          - result_authselect_check_cmd is success
          - result_authselect_profile is not skipped
          - authselect_current_profile is not match("custom/")
          - authselect_custom_profile is not match(authselect_current_profile)

        - name: 'Limit Password Reuse: password-auth - Ensure the authselect custom
            profile is selected'
          ansible.builtin.command:
            cmd: authselect select {{ authselect_custom_profile }}
          register: result_pam_authselect_select_profile
          when:
          - result_authselect_check_cmd is success
          - result_authselect_profile is not skipped
          - authselect_current_profile is not match("custom/")
          - authselect_custom_profile is not match(authselect_current_profile)

        - name: 'Limit Password Reuse: password-auth - Restore the authselect features
            in the custom profile'
          ansible.builtin.command:
            cmd: authselect enable-feature {{ item }}
          loop: '{{ result_authselect_features.stdout_lines }}'
          register: result_pam_authselect_restore_features
          when:
          - result_authselect_profile is not skipped
          - result_authselect_features is not skipped
          - result_pam_authselect_select_profile is not skipped

        - name: 'Limit Password Reuse: password-auth - Ensure authselect changes are
            applied'
          ansible.builtin.command:
            cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
          when:
          - result_authselect_check_cmd is success
          - result_authselect_profile is not skipped
          - result_pam_authselect_restore_features is not skipped

        - name: 'Limit Password Reuse: password-auth - Change the PAM file to be edited
            according to the custom authselect profile'
          ansible.builtin.set_fact:
            pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
              | basename }}
          when:
          - authselect_custom_profile is defined
        when:
        - result_authselect_present.stat.exists

      - name: 'Limit Password Reuse: password-auth - Define a fact for control already
          filtered in case filters are used'
        ansible.builtin.set_fact:
          pam_module_control: ''

      - name: 'Limit Password Reuse: password-auth - Check if {{ pam_file_path }}
          file is present'
        ansible.builtin.stat:
          path: '{{ pam_file_path }}'
        register: result_pam_file_present

      - name: 'Limit Password Reuse: password-auth - Ensure the "remember" option
          from "pam_pwhistory.so" is not present in {{ pam_file_path }}'
        ansible.builtin.replace:
          dest: '{{ pam_file_path }}'
          regexp: (.*password.*pam_pwhistory.so.*)\bremember\b=?[0-9a-zA-Z]*(.*)
          replace: \1\2
        register: result_pam_option_removal
        when:
        - result_pam_file_present.stat.exists

      - name: 'Limit Password Reuse: password-auth - Ensure authselect changes are
          applied'
        ansible.builtin.command:
          cmd: authselect apply-changes -b
        when:
        - result_authselect_present.stat.exists
        - result_pam_option_removal is changed
      when:
      - result_pam_password_auth_file_present.stat.exists
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_pwhistory_conf_check.stat.exists
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_pwhistory_remember_password_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Limit Password Reuse: password-auth - pam_pwhistory.so parameters are configured
    in PAM files'
  block:

  - name: 'Limit Password Reuse: password-auth - Define the PAM file to be edited
      as a local fact'
    ansible.builtin.set_fact:
      pam_file_path: /etc/pam.d/password-auth

  - name: 'Limit Password Reuse: password-auth - Check if system relies on authselect
      tool'
    ansible.builtin.stat:
      path: /usr/bin/authselect
    register: result_authselect_present

  - name: 'Limit Password Reuse: password-auth - Ensure authselect custom profile
      is used if authselect is present'
    block:

    - name: 'Limit Password Reuse: password-auth - Check integrity of authselect current
        profile'
      ansible.builtin.command:
        cmd: authselect check
      register: result_authselect_check_cmd
      changed_when: false
      check_mode: false
      failed_when: false

    - name: 'Limit Password Reuse: password-auth - Informative message based on the
        authselect integrity check result'
      ansible.builtin.assert:
        that:
        - ansible_check_mode or result_authselect_check_cmd.rc == 0
        fail_msg:
        - authselect integrity check failed. Remediation aborted!
        - This remediation could not be applied because an authselect profile was
          not selected or the selected profile is not intact.
        - It is not recommended to manually edit the PAM files when authselect tool
          is available.
        - In cases where the default authselect profile does not cover a specific
          demand, a custom authselect profile is recommended.
        success_msg:
        - authselect integrity check passed

    - name: 'Limit Password Reuse: password-auth - Get authselect current profile'
      ansible.builtin.shell:
        cmd: authselect current -r | awk '{ print $1 }'
      register: result_authselect_profile
      changed_when: false
      when:
      - result_authselect_check_cmd is success

    - name: 'Limit Password Reuse: password-auth - Define the current authselect profile
        as a local fact'
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is match("custom/")

    - name: 'Limit Password Reuse: password-auth - Define the new authselect custom
        profile as a local fact'
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: custom/hardening
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is not match("custom/")

    - name: 'Limit Password Reuse: password-auth - Get authselect current features
        to also enable them in the custom profile'
      ansible.builtin.shell:
        cmd: authselect current | tail -n+3 | awk '{ print $2 }'
      register: result_authselect_features
      changed_when: false
      check_mode: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: 'Limit Password Reuse: password-auth - Check if any custom profile with
        the same name was already created'
      ansible.builtin.stat:
        path: /etc/authselect/{{ authselect_custom_profile }}
      register: result_authselect_custom_profile_present
      changed_when: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: 'Limit Password Reuse: password-auth - Create an authselect custom profile
        based on the current profile'
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b {{ authselect_current_profile
          }}
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is not match("^(custom/|local)")
      - not result_authselect_custom_profile_present.stat.exists

    - name: 'Limit Password Reuse: password-auth - Create an authselect custom profile
        based on sssd profile'
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b sssd
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is match("local")
      - not result_authselect_custom_profile_present.stat.exists

    - name: 'Limit Password Reuse: password-auth - Ensure authselect changes are applied'
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: 'Limit Password Reuse: password-auth - Ensure the authselect custom profile
        is selected'
      ansible.builtin.command:
        cmd: authselect select {{ authselect_custom_profile }}
      register: result_pam_authselect_select_profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: 'Limit Password Reuse: password-auth - Restore the authselect features
        in the custom profile'
      ansible.builtin.command:
        cmd: authselect enable-feature {{ item }}
      loop: '{{ result_authselect_features.stdout_lines }}'
      register: result_pam_authselect_restore_features
      when:
      - result_authselect_profile is not skipped
      - result_authselect_features is not skipped
      - result_pam_authselect_select_profile is not skipped

    - name: 'Limit Password Reuse: password-auth - Ensure authselect changes are applied'
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - result_pam_authselect_restore_features is not skipped

    - name: 'Limit Password Reuse: password-auth - Change the PAM file to be edited
        according to the custom authselect profile'
      ansible.builtin.set_fact:
        pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
          | basename }}
      when:
      - authselect_custom_profile is defined
    when:
    - result_authselect_present.stat.exists

  - name: 'Limit Password Reuse: password-auth - Define a fact for control already
      filtered in case filters are used'
    ansible.builtin.set_fact:
      pam_module_control: requisite

  - name: 'Limit Password Reuse: password-auth - Check if expected PAM module line
      is present in {{ pam_file_path }}'
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwhistory.so\s*.*
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_line_present

  - name: 'Limit Password Reuse: password-auth - Include or update the PAM module
      line in {{ pam_file_path }}'
    block:

    - name: 'Limit Password Reuse: password-auth - Check if required PAM module line
        is present in {{ pam_file_path }} with different control'
      ansible.builtin.lineinfile:
        path: '{{ pam_file_path }}'
        regexp: ^\s*password\s+.*\s+pam_pwhistory.so\s*
        state: absent
      check_mode: true
      changed_when: false
      register: result_pam_line_other_control_present

    - name: 'Limit Password Reuse: password-auth - Ensure the correct control for
        the required PAM module line in {{ pam_file_path }}'
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: ^(\s*password\s+).*(\bpam_pwhistory.so.*)
        replace: \1{{ pam_module_control }} \2
      register: result_pam_module_edit
      when:
      - result_pam_line_other_control_present.found == 1

    - name: 'Limit Password Reuse: password-auth - Ensure the required PAM module
        line is included in {{ pam_file_path }}'
      ansible.builtin.lineinfile:
        dest: '{{ pam_file_path }}'
        line: password    {{ pam_module_control }}    pam_pwhistory.so
      register: result_pam_module_add
      when:
      - result_pam_line_other_control_present.found == 0 or result_pam_line_other_control_present.found
        &gt; 1

    - name: 'Limit Password Reuse: password-auth - Ensure authselect changes are applied'
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present is defined
      - result_authselect_present.stat.exists
      - |-
        (result_pam_module_add is defined and result_pam_module_add.changed)
         or (result_pam_module_edit is defined and result_pam_module_edit.changed)
    when:
    - result_pam_line_present.found is defined
    - result_pam_line_present.found == 0

  - name: 'Limit Password Reuse: password-auth - Define a fact for control already
      filtered in case filters are used'
    ansible.builtin.set_fact:
      pam_module_control: requisite

  - name: 'Limit Password Reuse: password-auth - Check if the required PAM module
      option is present in {{ pam_file_path }}'
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwhistory.so\s*.*\sremember\b
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_module_accounts_password_pam_pwhistory_remember_password_auth_option_present

  - name: 'Limit Password Reuse: password-auth - Ensure the "remember" PAM option
      for "pam_pwhistory.so" is included in {{ pam_file_path }}'
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      backrefs: true
      regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwhistory.so.*)
      line: \1 remember={{ var_password_pam_remember }}
      state: present
    register: result_pam_accounts_password_pam_pwhistory_remember_password_auth_add
    when:
    - result_pam_module_accounts_password_pam_pwhistory_remember_password_auth_option_present.found
      is defined
    - result_pam_module_accounts_password_pam_pwhistory_remember_password_auth_option_present.found
      == 0

  - name: 'Limit Password Reuse: password-auth - Ensure the required value for "remember"
      PAM option from "pam_pwhistory.so" in {{ pam_file_path }}'
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      backrefs: true
      regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwhistory.so\s+.*)(remember)=[0-9a-zA-Z]*\s*(.*)
      line: \1\2={{ var_password_pam_remember }} \3
    register: result_pam_accounts_password_pam_pwhistory_remember_password_auth_edit
    when:
    - result_pam_module_accounts_password_pam_pwhistory_remember_password_auth_option_present.found
      &gt; 0

  - name: 'Limit Password Reuse: password-auth - Ensure authselect changes are applied'
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_present.stat.exists
    - (result_pam_remember_add is defined and result_pam_remember_add.changed) or
      (result_pam_remember_edit is defined and result_pam_remember_edit.changed)
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_pwhistory_conf_check.stat.exists
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_pwhistory_remember_password_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_remember_control_flag:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_remember_control_flag"/>
                  <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_remember:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_remember"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_pwhistory_remember_password_auth:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_remember_system_auth" selected="false" severity="medium">
                <xccdf-1.2:title>Limit Password Reuse: system-auth</xccdf-1.2:title>
                <xccdf-1.2:description>Do not allow users to reuse recent passwords. This can be accomplished by using the
<html:code>remember</html:code> option for the <html:code>pam_pwhistory</html:code> PAM module.
<html:br/><html:br/>

On systems with newer versions of <html:code>authselect</html:code>, the <html:code>pam_pwhistory</html:code> PAM module
can be enabled via authselect feature:
<html:pre>authselect enable-feature with-pwhistory</html:pre>

Otherwise, it should be enabled using an authselect custom profile.
<html:br/><html:br/>
Newer systems also have the <html:code>/etc/security/pwhistory.conf</html:code> file for setting
<html:code>pam_pwhistory</html:code> module options. This file should be used whenever available.
Otherwise, the <html:code>pam_pwhistory</html:code> module options can be set in PAM files.
<html:br/><html:br/>
The value for <html:code>remember</html:code> option must be equal or greater than
<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_remember" use="legacy"/></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">If the system relies on <html:code>authselect</html:code> tool to manage PAM settings, the remediation
will also use <html:code>authselect</html:code> tool. However, if any manual modification was made in
PAM files, the <html:code>authselect</html:code> integrity check will fail and the remediation will be
aborted in order to preserve intentional changes. In this case, an informative message will
be shown in the remediation report.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="general">Newer versions of <html:code>authselect</html:code> contain an authselect feature to easily and properly
enable <html:code>pam_pwhistory.so</html:code> module. If this feature is not yet available in your
system, an authselect custom profile must be used to avoid integrity issues in PAM files.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.6.2.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(f)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(e)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000077-GPOS-00045</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.3.1</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Preventing reuse of previous passwords helps ensure that a compromised password is not
reused by a user.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix id="accounts_password_pam_pwhistory_remember_system_auth" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q pam; }; then

var_password_pam_remember='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_remember" use="legacy"/>'
var_password_pam_remember_control_flag='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_remember_control_flag" use="legacy"/>'


var_password_pam_remember_control_flag="$(echo $var_password_pam_remember_control_flag | cut -d \, -f 1)"

if [ -f /usr/bin/authselect ]; then
    if authselect list-features sssd | grep -q with-pwhistory; then
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi
        authselect enable-feature with-pwhistory

        authselect apply-changes -b
    else
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "/etc/pam.d/system-auth")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
        
        if ! grep -qP "^\s*password\s+\$var_password_pam_remember_control_flag\s+pam_pwhistory.so\s*.*" "$PAM_FILE_PATH"; then
            # Line matching group + control + module was not found. Check group + module.
            if [ "$(grep -cP '^\s*password\s+.*\s+pam_pwhistory.so\s*' "$PAM_FILE_PATH")" -eq 1 ]; then
                # The control is updated only if one single line matches.
                sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_pwhistory.so.*)/\1$var_password_pam_remember_control_flag \2/" "$PAM_FILE_PATH"
            else
                LAST_MATCH_LINE=$(grep -nP "^password.*requisite.*pam_pwquality\.so" "$PAM_FILE_PATH" | tail -n 1 | cut -d: -f 1)
                if [ ! -z $LAST_MATCH_LINE ]; then
                    sed -i --follow-symlinks $LAST_MATCH_LINE" a password     $var_password_pam_remember_control_flag    pam_pwhistory.so" "$PAM_FILE_PATH"
                else
                    echo "password    $var_password_pam_remember_control_flag    pam_pwhistory.so" &gt;&gt; "$PAM_FILE_PATH"
                fi
            fi
        fi
    fi
else

    
    if ! grep -qP "^\s*password\s+\$var_password_pam_remember_control_flag\s+pam_pwhistory.so\s*.*" "/etc/pam.d/system-auth"; then
        # Line matching group + control + module was not found. Check group + module.
        if [ "$(grep -cP '^\s*password\s+.*\s+pam_pwhistory.so\s*' "/etc/pam.d/system-auth")" -eq 1 ]; then
            # The control is updated only if one single line matches.
            sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_pwhistory.so.*)/\1$var_password_pam_remember_control_flag \2/" "/etc/pam.d/system-auth"
        else
            LAST_MATCH_LINE=$(grep -nP "^password.*requisite.*pam_pwquality\.so" "/etc/pam.d/system-auth" | tail -n 1 | cut -d: -f 1)
            if [ ! -z $LAST_MATCH_LINE ]; then
                sed -i --follow-symlinks $LAST_MATCH_LINE" a password     $var_password_pam_remember_control_flag    pam_pwhistory.so" "/etc/pam.d/system-auth"
            else
                echo "password    $var_password_pam_remember_control_flag    pam_pwhistory.so" &gt;&gt; "/etc/pam.d/system-auth"
            fi
        fi
    fi

fi

PWHISTORY_CONF="/etc/security/pwhistory.conf"
if [ -f $PWHISTORY_CONF ]; then
    regex="^\s*remember\s*="
    line="remember = $var_password_pam_remember"
    if ! grep -q $regex $PWHISTORY_CONF; then
        echo $line &gt;&gt; $PWHISTORY_CONF
    else
        sed -i --follow-symlinks 's|^\s*\(remember\s*=\s*\)\(\S\+\)|\1'"$var_password_pam_remember"'|g' $PWHISTORY_CONF
    fi
    if [ -e "/etc/pam.d/system-auth" ] ; then
        PAM_FILE_PATH="/etc/pam.d/system-auth"
        if [ -f /usr/bin/authselect ]; then
            
            if ! authselect check; then
            echo "
            authselect integrity check failed. Remediation aborted!
            This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
            It is not recommended to manually edit the PAM files when authselect tool is available.
            In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
            exit 1
            fi

            CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
            # If not already in use, a custom profile is created preserving the enabled features.
            if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                # The "local" profile does not contain essential security features required by multiple Benchmarks.
                # If currently used, it is replaced by "sssd", which is the best option in this case.
                if [[ $CURRENT_PROFILE == local ]]; then
                    CURRENT_PROFILE="sssd"
                fi
                authselect create-profile hardening -b $CURRENT_PROFILE
                CURRENT_PROFILE="custom/hardening"
                
                authselect apply-changes -b --backup=before-hardening-custom-profile
                authselect select $CURRENT_PROFILE
                for feature in $ENABLED_FEATURES; do
                    authselect enable-feature $feature;
                done
                
                authselect apply-changes -b --backup=after-hardening-custom-profile
            fi
            PAM_FILE_NAME=$(basename "/etc/pam.d/system-auth")
            PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

            authselect apply-changes -b
        fi
        
    if grep -qP "^\s*password\s.*\bpam_pwhistory.so\s.*\bremember\b" "$PAM_FILE_PATH"; then
        sed -i -E --follow-symlinks "s/(.*password.*pam_pwhistory.so.*)\bremember\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
    fi
        if [ -f /usr/bin/authselect ]; then
            
            authselect apply-changes -b
        fi
    else
        echo "/etc/pam.d/system-auth was not found" &gt;&amp;2
    fi
else
    PAM_FILE_PATH="/etc/pam.d/system-auth"
    if [ -f /usr/bin/authselect ]; then
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "/etc/pam.d/system-auth")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
    fi
    

    if ! grep -qP "^\s*password\s+requisite\s+pam_pwhistory.so\s*.*" "$PAM_FILE_PATH"; then
        # Line matching group + control + module was not found. Check group + module.
        if [ "$(grep -cP '^\s*password\s+.*\s+pam_pwhistory.so\s*' "$PAM_FILE_PATH")" -eq 1 ]; then
            # The control is updated only if one single line matches.
            sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_pwhistory.so.*)/\1requisite \2/" "$PAM_FILE_PATH"
        else
            echo "password    requisite    pam_pwhistory.so" &gt;&gt; "$PAM_FILE_PATH"
        fi
    fi
    # Check the option
    if ! grep -qP "^\s*password\s+requisite\s+pam_pwhistory.so\s*.*\sremember\b" "$PAM_FILE_PATH"; then
        sed -i -E --follow-symlinks "/\s*password\s+requisite\s+pam_pwhistory.so.*/ s/$/ remember=$var_password_pam_remember/" "$PAM_FILE_PATH"
    else
        sed -i -E --follow-symlinks "s/(\s*password\s+requisite\s+pam_pwhistory.so\s+.*)(remember=)[[:alnum:]]*\s*(.*)/\1\2$var_password_pam_remember \3/" "$PAM_FILE_PATH"
    fi
    if [ -f /usr/bin/authselect ]; then
        
        authselect apply-changes -b
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="accounts_password_pam_pwhistory_remember_system_auth" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_pwhistory_remember_system_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
- name: XCCDF Value var_password_pam_remember # promote to variable
  set_fact:
    var_password_pam_remember: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_remember" use="legacy"/>
  tags:
    - always
- name: XCCDF Value var_password_pam_remember_control_flag # promote to variable
  set_fact:
    var_password_pam_remember_control_flag: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_remember_control_flag" use="legacy"/>
  tags:
    - always

- name: 'Limit Password Reuse: system-auth - Check if system relies on authselect
    tool'
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_pwhistory_remember_system_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Limit Password Reuse: system-auth - Collect the available authselect features'
  ansible.builtin.command:
    cmd: authselect list-features sssd
  register: result_authselect_available_features
  changed_when: false
  check_mode: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_pwhistory_remember_system_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Limit Password Reuse: system-auth - Enable pam_pwhistory.so using authselect
    feature'
  block:

  - name: 'Limit Password Reuse: system-auth - Check integrity of authselect current
      profile'
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: 'Limit Password Reuse: system-auth - Informative message based on the authselect
      integrity check result'
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: 'Limit Password Reuse: system-auth - Get authselect current features'
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: 'Limit Password Reuse: system-auth - Ensure "with-pwhistory" feature is
      enabled using authselect tool'
    ansible.builtin.command:
      cmd: authselect enable-feature with-pwhistory
    register: result_authselect_enable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is not search("with-pwhistory")

  - name: 'Limit Password Reuse: system-auth - Ensure authselect changes are applied'
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_enable_feature_cmd is not skipped
    - result_authselect_enable_feature_cmd is success
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  - result_authselect_available_features.stdout is search("with-pwhistory")
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_pwhistory_remember_system_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Limit Password Reuse: system-auth - Enable pam_pwhistory.so in appropriate
    PAM files'
  block:

  - name: 'Limit Password Reuse: system-auth - Define the PAM file to be edited as
      a local fact'
    ansible.builtin.set_fact:
      pam_file_path: /etc/pam.d/system-auth

  - name: 'Limit Password Reuse: system-auth - Check if system relies on authselect
      tool'
    ansible.builtin.stat:
      path: /usr/bin/authselect
    register: result_authselect_present

  - name: 'Limit Password Reuse: system-auth - Ensure authselect custom profile is
      used if authselect is present'
    block:

    - name: 'Limit Password Reuse: system-auth - Check integrity of authselect current
        profile'
      ansible.builtin.command:
        cmd: authselect check
      register: result_authselect_check_cmd
      changed_when: false
      check_mode: false
      failed_when: false

    - name: 'Limit Password Reuse: system-auth - Informative message based on the
        authselect integrity check result'
      ansible.builtin.assert:
        that:
        - ansible_check_mode or result_authselect_check_cmd.rc == 0
        fail_msg:
        - authselect integrity check failed. Remediation aborted!
        - This remediation could not be applied because an authselect profile was
          not selected or the selected profile is not intact.
        - It is not recommended to manually edit the PAM files when authselect tool
          is available.
        - In cases where the default authselect profile does not cover a specific
          demand, a custom authselect profile is recommended.
        success_msg:
        - authselect integrity check passed

    - name: 'Limit Password Reuse: system-auth - Get authselect current profile'
      ansible.builtin.shell:
        cmd: authselect current -r | awk '{ print $1 }'
      register: result_authselect_profile
      changed_when: false
      when:
      - result_authselect_check_cmd is success

    - name: 'Limit Password Reuse: system-auth - Define the current authselect profile
        as a local fact'
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is match("custom/")

    - name: 'Limit Password Reuse: system-auth - Define the new authselect custom
        profile as a local fact'
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: custom/hardening
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is not match("custom/")

    - name: 'Limit Password Reuse: system-auth - Get authselect current features to
        also enable them in the custom profile'
      ansible.builtin.shell:
        cmd: authselect current | tail -n+3 | awk '{ print $2 }'
      register: result_authselect_features
      changed_when: false
      check_mode: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: 'Limit Password Reuse: system-auth - Check if any custom profile with
        the same name was already created'
      ansible.builtin.stat:
        path: /etc/authselect/{{ authselect_custom_profile }}
      register: result_authselect_custom_profile_present
      changed_when: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: 'Limit Password Reuse: system-auth - Create an authselect custom profile
        based on the current profile'
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b {{ authselect_current_profile
          }}
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is not match("^(custom/|local)")
      - not result_authselect_custom_profile_present.stat.exists

    - name: 'Limit Password Reuse: system-auth - Create an authselect custom profile
        based on sssd profile'
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b sssd
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is match("local")
      - not result_authselect_custom_profile_present.stat.exists

    - name: 'Limit Password Reuse: system-auth - Ensure authselect changes are applied'
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: 'Limit Password Reuse: system-auth - Ensure the authselect custom profile
        is selected'
      ansible.builtin.command:
        cmd: authselect select {{ authselect_custom_profile }}
      register: result_pam_authselect_select_profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: 'Limit Password Reuse: system-auth - Restore the authselect features in
        the custom profile'
      ansible.builtin.command:
        cmd: authselect enable-feature {{ item }}
      loop: '{{ result_authselect_features.stdout_lines }}'
      register: result_pam_authselect_restore_features
      when:
      - result_authselect_profile is not skipped
      - result_authselect_features is not skipped
      - result_pam_authselect_select_profile is not skipped

    - name: 'Limit Password Reuse: system-auth - Ensure authselect changes are applied'
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - result_pam_authselect_restore_features is not skipped

    - name: 'Limit Password Reuse: system-auth - Change the PAM file to be edited
        according to the custom authselect profile'
      ansible.builtin.set_fact:
        pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
          | basename }}
      when:
      - authselect_custom_profile is defined
    when:
    - result_authselect_present.stat.exists

  - name: 'Limit Password Reuse: system-auth - Define a fact for control already filtered
      in case filters are used'
    ansible.builtin.set_fact:
      pam_module_control: '{{ var_password_pam_remember_control_flag.split(",")[0]
        }}'

  - name: 'Limit Password Reuse: system-auth - Check if expected PAM module line is
      present in {{ pam_file_path }}'
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwhistory.so\s*.*
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_line_present

  - name: 'Limit Password Reuse: system-auth - Include or update the PAM module line
      in {{ pam_file_path }}'
    block:

    - name: 'Limit Password Reuse: system-auth - Check if required PAM module line
        is present in {{ pam_file_path }} with different control'
      ansible.builtin.lineinfile:
        path: '{{ pam_file_path }}'
        regexp: ^\s*password\s+.*\s+pam_pwhistory.so\s*
        state: absent
      check_mode: true
      changed_when: false
      register: result_pam_line_other_control_present

    - name: 'Limit Password Reuse: system-auth - Ensure the correct control for the
        required PAM module line in {{ pam_file_path }}'
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: ^(\s*password\s+).*(\bpam_pwhistory.so.*)
        replace: \1{{ pam_module_control }} \2
      register: result_pam_module_edit
      when:
      - result_pam_line_other_control_present.found == 1

    - name: 'Limit Password Reuse: system-auth - Ensure the required PAM module line
        is included in {{ pam_file_path }}'
      ansible.builtin.lineinfile:
        dest: '{{ pam_file_path }}'
        insertafter: ^password.*requisite.*pam_pwquality\.so
        line: password    {{ pam_module_control }}    pam_pwhistory.so
      register: result_pam_module_add
      when:
      - result_pam_line_other_control_present.found == 0 or result_pam_line_other_control_present.found
        &gt; 1

    - name: 'Limit Password Reuse: system-auth - Ensure authselect changes are applied'
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present is defined
      - result_authselect_present.stat.exists
      - |-
        (result_pam_module_add is defined and result_pam_module_add.changed)
         or (result_pam_module_edit is defined and result_pam_module_edit.changed)
    when:
    - result_pam_line_present.found is defined
    - result_pam_line_present.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - |
    (result_authselect_available_features.stdout is defined and result_authselect_available_features.stdout is not search("with-pwhistory")) or result_authselect_available_features is not defined
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_pwhistory_remember_system_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Limit Password Reuse: system-auth - Check the presence of /etc/security/pwhistory.conf
    file'
  ansible.builtin.stat:
    path: /etc/security/pwhistory.conf
  register: result_pwhistory_conf_check
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_pwhistory_remember_system_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Limit Password Reuse: system-auth - pam_pwhistory.so parameters are configured
    in /etc/security/pwhistory.conf file'
  block:

  - name: 'Limit Password Reuse: system-auth - Ensure the pam_pwhistory.so remember
      parameter in /etc/security/pwhistory.conf'
    ansible.builtin.lineinfile:
      path: /etc/security/pwhistory.conf
      regexp: ^\s*remember\s*=
      line: remember = {{ var_password_pam_remember }}
      state: present

  - name: 'Limit Password Reuse: system-auth - Ensure the pam_pwhistory.so remember
      parameter is removed from PAM files'
    block:

    - name: 'Limit Password Reuse: system-auth - Check if /etc/pam.d/system-auth file
        is present'
      ansible.builtin.stat:
        path: /etc/pam.d/system-auth
      register: result_pam_auth_file_present

    - name: 'Limit Password Reuse: system-auth - Check the proper remediation for
        the system'
      block:

      - name: 'Limit Password Reuse: system-auth - Define the PAM file to be edited
          as a local fact'
        ansible.builtin.set_fact:
          pam_file_path: /etc/pam.d/system-auth

      - name: 'Limit Password Reuse: system-auth - Check if system relies on authselect
          tool'
        ansible.builtin.stat:
          path: /usr/bin/authselect
        register: result_authselect_present

      - name: 'Limit Password Reuse: system-auth - Ensure authselect custom profile
          is used if authselect is present'
        block:

        - name: 'Limit Password Reuse: system-auth - Check integrity of authselect
            current profile'
          ansible.builtin.command:
            cmd: authselect check
          register: result_authselect_check_cmd
          changed_when: false
          check_mode: false
          failed_when: false

        - name: 'Limit Password Reuse: system-auth - Informative message based on
            the authselect integrity check result'
          ansible.builtin.assert:
            that:
            - ansible_check_mode or result_authselect_check_cmd.rc == 0
            fail_msg:
            - authselect integrity check failed. Remediation aborted!
            - This remediation could not be applied because an authselect profile
              was not selected or the selected profile is not intact.
            - It is not recommended to manually edit the PAM files when authselect
              tool is available.
            - In cases where the default authselect profile does not cover a specific
              demand, a custom authselect profile is recommended.
            success_msg:
            - authselect integrity check passed

        - name: 'Limit Password Reuse: system-auth - Get authselect current profile'
          ansible.builtin.shell:
            cmd: authselect current -r | awk '{ print $1 }'
          register: result_authselect_profile
          changed_when: false
          when:
          - result_authselect_check_cmd is success

        - name: 'Limit Password Reuse: system-auth - Define the current authselect
            profile as a local fact'
          ansible.builtin.set_fact:
            authselect_current_profile: '{{ result_authselect_profile.stdout }}'
            authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
          when:
          - result_authselect_profile is not skipped
          - result_authselect_profile.stdout is match("custom/")

        - name: 'Limit Password Reuse: system-auth - Define the new authselect custom
            profile as a local fact'
          ansible.builtin.set_fact:
            authselect_current_profile: '{{ result_authselect_profile.stdout }}'
            authselect_custom_profile: custom/hardening
          when:
          - result_authselect_profile is not skipped
          - result_authselect_profile.stdout is not match("custom/")

        - name: 'Limit Password Reuse: system-auth - Get authselect current features
            to also enable them in the custom profile'
          ansible.builtin.shell:
            cmd: authselect current | tail -n+3 | awk '{ print $2 }'
          register: result_authselect_features
          changed_when: false
          check_mode: false
          when:
          - result_authselect_profile is not skipped
          - authselect_current_profile is not match("custom/")

        - name: 'Limit Password Reuse: system-auth - Check if any custom profile with
            the same name was already created'
          ansible.builtin.stat:
            path: /etc/authselect/{{ authselect_custom_profile }}
          register: result_authselect_custom_profile_present
          changed_when: false
          when:
          - result_authselect_profile is not skipped
          - authselect_current_profile is not match("custom/")

        - name: 'Limit Password Reuse: system-auth - Create an authselect custom profile
            based on the current profile'
          ansible.builtin.command:
            cmd: authselect create-profile hardening -b {{ authselect_current_profile
              }}
          when:
          - result_authselect_profile is not skipped
          - result_authselect_check_cmd is success
          - authselect_current_profile is not match("^(custom/|local)")
          - not result_authselect_custom_profile_present.stat.exists

        - name: 'Limit Password Reuse: system-auth - Create an authselect custom profile
            based on sssd profile'
          ansible.builtin.command:
            cmd: authselect create-profile hardening -b sssd
          when:
          - result_authselect_profile is not skipped
          - result_authselect_check_cmd is success
          - authselect_current_profile is match("local")
          - not result_authselect_custom_profile_present.stat.exists

        - name: 'Limit Password Reuse: system-auth - Ensure authselect changes are
            applied'
          ansible.builtin.command:
            cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
          when:
          - result_authselect_check_cmd is success
          - result_authselect_profile is not skipped
          - authselect_current_profile is not match("custom/")
          - authselect_custom_profile is not match(authselect_current_profile)

        - name: 'Limit Password Reuse: system-auth - Ensure the authselect custom
            profile is selected'
          ansible.builtin.command:
            cmd: authselect select {{ authselect_custom_profile }}
          register: result_pam_authselect_select_profile
          when:
          - result_authselect_check_cmd is success
          - result_authselect_profile is not skipped
          - authselect_current_profile is not match("custom/")
          - authselect_custom_profile is not match(authselect_current_profile)

        - name: 'Limit Password Reuse: system-auth - Restore the authselect features
            in the custom profile'
          ansible.builtin.command:
            cmd: authselect enable-feature {{ item }}
          loop: '{{ result_authselect_features.stdout_lines }}'
          register: result_pam_authselect_restore_features
          when:
          - result_authselect_profile is not skipped
          - result_authselect_features is not skipped
          - result_pam_authselect_select_profile is not skipped

        - name: 'Limit Password Reuse: system-auth - Ensure authselect changes are
            applied'
          ansible.builtin.command:
            cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
          when:
          - result_authselect_check_cmd is success
          - result_authselect_profile is not skipped
          - result_pam_authselect_restore_features is not skipped

        - name: 'Limit Password Reuse: system-auth - Change the PAM file to be edited
            according to the custom authselect profile'
          ansible.builtin.set_fact:
            pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
              | basename }}
          when:
          - authselect_custom_profile is defined
        when:
        - result_authselect_present.stat.exists

      - name: 'Limit Password Reuse: system-auth - Define a fact for control already
          filtered in case filters are used'
        ansible.builtin.set_fact:
          pam_module_control: ''

      - name: 'Limit Password Reuse: system-auth - Check if {{ pam_file_path }} file
          is present'
        ansible.builtin.stat:
          path: '{{ pam_file_path }}'
        register: result_pam_file_present

      - name: 'Limit Password Reuse: system-auth - Ensure the "remember" option from
          "pam_pwhistory.so" is not present in {{ pam_file_path }}'
        ansible.builtin.replace:
          dest: '{{ pam_file_path }}'
          regexp: (.*password.*pam_pwhistory.so.*)\bremember\b=?[0-9a-zA-Z]*(.*)
          replace: \1\2
        register: result_pam_option_removal
        when:
        - result_pam_file_present.stat.exists

      - name: 'Limit Password Reuse: system-auth - Ensure authselect changes are applied'
        ansible.builtin.command:
          cmd: authselect apply-changes -b
        when:
        - result_authselect_present.stat.exists
        - result_pam_option_removal is changed
      when:
      - result_pam_auth_file_present.stat.exists
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_pwhistory_conf_check.stat.exists
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_pwhistory_remember_system_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Limit Password Reuse: system-auth - pam_pwhistory.so parameters are configured
    in PAM files'
  block:

  - name: 'Limit Password Reuse: system-auth - Define the PAM file to be edited as
      a local fact'
    ansible.builtin.set_fact:
      pam_file_path: /etc/pam.d/system-auth

  - name: 'Limit Password Reuse: system-auth - Check if system relies on authselect
      tool'
    ansible.builtin.stat:
      path: /usr/bin/authselect
    register: result_authselect_present

  - name: 'Limit Password Reuse: system-auth - Ensure authselect custom profile is
      used if authselect is present'
    block:

    - name: 'Limit Password Reuse: system-auth - Check integrity of authselect current
        profile'
      ansible.builtin.command:
        cmd: authselect check
      register: result_authselect_check_cmd
      changed_when: false
      check_mode: false
      failed_when: false

    - name: 'Limit Password Reuse: system-auth - Informative message based on the
        authselect integrity check result'
      ansible.builtin.assert:
        that:
        - ansible_check_mode or result_authselect_check_cmd.rc == 0
        fail_msg:
        - authselect integrity check failed. Remediation aborted!
        - This remediation could not be applied because an authselect profile was
          not selected or the selected profile is not intact.
        - It is not recommended to manually edit the PAM files when authselect tool
          is available.
        - In cases where the default authselect profile does not cover a specific
          demand, a custom authselect profile is recommended.
        success_msg:
        - authselect integrity check passed

    - name: 'Limit Password Reuse: system-auth - Get authselect current profile'
      ansible.builtin.shell:
        cmd: authselect current -r | awk '{ print $1 }'
      register: result_authselect_profile
      changed_when: false
      when:
      - result_authselect_check_cmd is success

    - name: 'Limit Password Reuse: system-auth - Define the current authselect profile
        as a local fact'
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is match("custom/")

    - name: 'Limit Password Reuse: system-auth - Define the new authselect custom
        profile as a local fact'
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: custom/hardening
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is not match("custom/")

    - name: 'Limit Password Reuse: system-auth - Get authselect current features to
        also enable them in the custom profile'
      ansible.builtin.shell:
        cmd: authselect current | tail -n+3 | awk '{ print $2 }'
      register: result_authselect_features
      changed_when: false
      check_mode: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: 'Limit Password Reuse: system-auth - Check if any custom profile with
        the same name was already created'
      ansible.builtin.stat:
        path: /etc/authselect/{{ authselect_custom_profile }}
      register: result_authselect_custom_profile_present
      changed_when: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: 'Limit Password Reuse: system-auth - Create an authselect custom profile
        based on the current profile'
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b {{ authselect_current_profile
          }}
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is not match("^(custom/|local)")
      - not result_authselect_custom_profile_present.stat.exists

    - name: 'Limit Password Reuse: system-auth - Create an authselect custom profile
        based on sssd profile'
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b sssd
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is match("local")
      - not result_authselect_custom_profile_present.stat.exists

    - name: 'Limit Password Reuse: system-auth - Ensure authselect changes are applied'
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: 'Limit Password Reuse: system-auth - Ensure the authselect custom profile
        is selected'
      ansible.builtin.command:
        cmd: authselect select {{ authselect_custom_profile }}
      register: result_pam_authselect_select_profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: 'Limit Password Reuse: system-auth - Restore the authselect features in
        the custom profile'
      ansible.builtin.command:
        cmd: authselect enable-feature {{ item }}
      loop: '{{ result_authselect_features.stdout_lines }}'
      register: result_pam_authselect_restore_features
      when:
      - result_authselect_profile is not skipped
      - result_authselect_features is not skipped
      - result_pam_authselect_select_profile is not skipped

    - name: 'Limit Password Reuse: system-auth - Ensure authselect changes are applied'
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - result_pam_authselect_restore_features is not skipped

    - name: 'Limit Password Reuse: system-auth - Change the PAM file to be edited
        according to the custom authselect profile'
      ansible.builtin.set_fact:
        pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
          | basename }}
      when:
      - authselect_custom_profile is defined
    when:
    - result_authselect_present.stat.exists

  - name: 'Limit Password Reuse: system-auth - Define a fact for control already filtered
      in case filters are used'
    ansible.builtin.set_fact:
      pam_module_control: requisite

  - name: 'Limit Password Reuse: system-auth - Check if expected PAM module line is
      present in {{ pam_file_path }}'
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwhistory.so\s*.*
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_line_present

  - name: 'Limit Password Reuse: system-auth - Include or update the PAM module line
      in {{ pam_file_path }}'
    block:

    - name: 'Limit Password Reuse: system-auth - Check if required PAM module line
        is present in {{ pam_file_path }} with different control'
      ansible.builtin.lineinfile:
        path: '{{ pam_file_path }}'
        regexp: ^\s*password\s+.*\s+pam_pwhistory.so\s*
        state: absent
      check_mode: true
      changed_when: false
      register: result_pam_line_other_control_present

    - name: 'Limit Password Reuse: system-auth - Ensure the correct control for the
        required PAM module line in {{ pam_file_path }}'
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: ^(\s*password\s+).*(\bpam_pwhistory.so.*)
        replace: \1{{ pam_module_control }} \2
      register: result_pam_module_edit
      when:
      - result_pam_line_other_control_present.found == 1

    - name: 'Limit Password Reuse: system-auth - Ensure the required PAM module line
        is included in {{ pam_file_path }}'
      ansible.builtin.lineinfile:
        dest: '{{ pam_file_path }}'
        line: password    {{ pam_module_control }}    pam_pwhistory.so
      register: result_pam_module_add
      when:
      - result_pam_line_other_control_present.found == 0 or result_pam_line_other_control_present.found
        &gt; 1

    - name: 'Limit Password Reuse: system-auth - Ensure authselect changes are applied'
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present is defined
      - result_authselect_present.stat.exists
      - |-
        (result_pam_module_add is defined and result_pam_module_add.changed)
         or (result_pam_module_edit is defined and result_pam_module_edit.changed)
    when:
    - result_pam_line_present.found is defined
    - result_pam_line_present.found == 0

  - name: 'Limit Password Reuse: system-auth - Define a fact for control already filtered
      in case filters are used'
    ansible.builtin.set_fact:
      pam_module_control: requisite

  - name: 'Limit Password Reuse: system-auth - Check if the required PAM module option
      is present in {{ pam_file_path }}'
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwhistory.so\s*.*\sremember\b
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_module_accounts_password_pam_pwhistory_remember_system_auth_option_present

  - name: 'Limit Password Reuse: system-auth - Ensure the "remember" PAM option for
      "pam_pwhistory.so" is included in {{ pam_file_path }}'
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      backrefs: true
      regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwhistory.so.*)
      line: \1 remember={{ var_password_pam_remember }}
      state: present
    register: result_pam_accounts_password_pam_pwhistory_remember_system_auth_add
    when:
    - result_pam_module_accounts_password_pam_pwhistory_remember_system_auth_option_present.found
      is defined
    - result_pam_module_accounts_password_pam_pwhistory_remember_system_auth_option_present.found
      == 0

  - name: 'Limit Password Reuse: system-auth - Ensure the required value for "remember"
      PAM option from "pam_pwhistory.so" in {{ pam_file_path }}'
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      backrefs: true
      regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwhistory.so\s+.*)(remember)=[0-9a-zA-Z]*\s*(.*)
      line: \1\2={{ var_password_pam_remember }} \3
    register: result_pam_accounts_password_pam_pwhistory_remember_system_auth_edit
    when:
    - result_pam_module_accounts_password_pam_pwhistory_remember_system_auth_option_present.found
      &gt; 0

  - name: 'Limit Password Reuse: system-auth - Ensure authselect changes are applied'
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_present.stat.exists
    - (result_pam_remember_add is defined and result_pam_remember_add.changed) or
      (result_pam_remember_edit is defined and result_pam_remember_edit.changed)
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_pwhistory_conf_check.stat.exists
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_pwhistory_remember_system_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_remember_control_flag:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_remember_control_flag"/>
                  <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_remember:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_remember"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_pwhistory_remember_system_auth:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_pwhistory_remember_system_auth_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwhistory_use_authtok" selected="false" severity="medium">
                <xccdf-1.2:title>Enforce Password History with use_authtok</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>use_authtok</html:code> option ensures the pam_pwhistory module uses the new
password provided by a previously stacked PAM module during password
changes, rather than prompting the user again.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.3.3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>use_authtok</html:code> option allows multiple PAM modules to validate the new
password before it is accepted, ensuring it meets all security requirements
without requiring the user to re-enter it multiple times.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix id="accounts_password_pam_pwhistory_use_authtok" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q pam; }; then

CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
# If not already in use, a custom profile is created preserving the enabled features.
if [[ ! $CURRENT_PROFILE == custom/* ]]; then
    ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
    # The "local" profile does not contain essential security features required by multiple Benchmarks.
    # If currently used, it is replaced by "sssd", which is the best option in this case.
    if [[ $CURRENT_PROFILE == local ]]; then
        CURRENT_PROFILE="sssd"
    fi
    authselect create-profile hardening -b $CURRENT_PROFILE
    CURRENT_PROFILE="custom/hardening"
    
    authselect apply-changes -b --backup=before-hardening-custom-profile
    authselect select $CURRENT_PROFILE
    for feature in $ENABLED_FEATURES; do
        authselect enable-feature $feature;
    done
    
    authselect apply-changes -b --backup=after-hardening-custom-profile
fi
pam_profile="$(head -1 /etc/authselect/authselect.conf)"
if grep -Pq -- '^custom\/' &lt;&lt;&lt; "$pam_profile"; then
    pam_profile_path="/etc/authselect/$pam_profile"
else
    pam_profile_path="/usr/share/authselect/default/$pam_profile"
fi

for authselect_file in "$pam_profile_path"/password-auth "$pam_profile_path"/system-auth; do
    if ! grep -Pq '^\h*password\h+([^#\n\r]+)\h+pam_pwhistory\.so\h+([^#\n\r]+\h+)?use_authtok\b' "$authselect_file"; then
        sed -ri 's/(^\s*password\s+(requisite|required|sufficient)\s+pam_pwhistory\.so\s+.*)$/&amp; use_authtok/g' "$authselect_file"
    fi
done

authselect apply-changes

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="accounts_password_pam_pwhistory_use_authtok" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - accounts_password_pam_pwhistory_use_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Enforce Password History with use_authtok - Check if system relies on authselect
    tool
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - accounts_password_pam_pwhistory_use_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Enforce Password History with use_authtok - Ensure authselect custom profile
    is used if authselect is present
  block:

  - name: Enforce Password History with use_authtok - Check integrity of authselect
      current profile
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: Enforce Password History with use_authtok - Informative message based on
      the authselect integrity check result
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: Enforce Password History with use_authtok - Get authselect current profile
    ansible.builtin.shell:
      cmd: authselect current -r | awk '{ print $1 }'
    register: result_authselect_profile
    changed_when: false
    when:
    - result_authselect_check_cmd is success

  - name: Enforce Password History with use_authtok - Define the current authselect
      profile as a local fact
    ansible.builtin.set_fact:
      authselect_current_profile: '{{ result_authselect_profile.stdout }}'
      authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
    when:
    - result_authselect_profile is not skipped
    - result_authselect_profile.stdout is match("custom/")

  - name: Enforce Password History with use_authtok - Define the new authselect custom
      profile as a local fact
    ansible.builtin.set_fact:
      authselect_current_profile: '{{ result_authselect_profile.stdout }}'
      authselect_custom_profile: custom/hardening
    when:
    - result_authselect_profile is not skipped
    - result_authselect_profile.stdout is not match("custom/")

  - name: Enforce Password History with use_authtok - Get authselect current features
      to also enable them in the custom profile
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_profile is not skipped
    - authselect_current_profile is not match("custom/")

  - name: Enforce Password History with use_authtok - Check if any custom profile
      with the same name was already created
    ansible.builtin.stat:
      path: /etc/authselect/{{ authselect_custom_profile }}
    register: result_authselect_custom_profile_present
    changed_when: false
    when:
    - result_authselect_profile is not skipped
    - authselect_current_profile is not match("custom/")

  - name: Enforce Password History with use_authtok - Create an authselect custom
      profile based on the current profile
    ansible.builtin.command:
      cmd: authselect create-profile hardening -b {{ authselect_current_profile }}
    when:
    - result_authselect_profile is not skipped
    - result_authselect_check_cmd is success
    - authselect_current_profile is not match("^(custom/|local)")
    - not result_authselect_custom_profile_present.stat.exists

  - name: Enforce Password History with use_authtok - Create an authselect custom
      profile based on sssd profile
    ansible.builtin.command:
      cmd: authselect create-profile hardening -b sssd
    when:
    - result_authselect_profile is not skipped
    - result_authselect_check_cmd is success
    - authselect_current_profile is match("local")
    - not result_authselect_custom_profile_present.stat.exists

  - name: Enforce Password History with use_authtok - Ensure authselect changes are
      applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
    when:
    - result_authselect_check_cmd is success
    - result_authselect_profile is not skipped
    - authselect_current_profile is not match("custom/")
    - authselect_custom_profile is not match(authselect_current_profile)

  - name: Enforce Password History with use_authtok - Ensure the authselect custom
      profile is selected
    ansible.builtin.command:
      cmd: authselect select {{ authselect_custom_profile }}
    register: result_pam_authselect_select_profile
    when:
    - result_authselect_check_cmd is success
    - result_authselect_profile is not skipped
    - authselect_current_profile is not match("custom/")
    - authselect_custom_profile is not match(authselect_current_profile)

  - name: Enforce Password History with use_authtok - Restore the authselect features
      in the custom profile
    ansible.builtin.command:
      cmd: authselect enable-feature {{ item }}
    loop: '{{ result_authselect_features.stdout_lines }}'
    register: result_pam_authselect_restore_features
    when:
    - result_authselect_profile is not skipped
    - result_authselect_features is not skipped
    - result_pam_authselect_select_profile is not skipped

  - name: Enforce Password History with use_authtok - Ensure authselect changes are
      applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
    when:
    - result_authselect_check_cmd is success
    - result_authselect_profile is not skipped
    - result_pam_authselect_restore_features is not skipped
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  tags:
  - accounts_password_pam_pwhistory_use_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Enforce Password History with use_authtok - Get authselect current profile
  ansible.builtin.shell:
    cmd: authselect current -r | awk '{ print $1 }'
  register: result_authselect_profile
  changed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_check_cmd is success
  tags:
  - accounts_password_pam_pwhistory_use_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Enforce Password History with use_authtok - Define the PAM profile path based
    on the authselect profile
  ansible.builtin.set_fact:
    pam_profile_path: '{%- if result_authselect_profile.stdout is match("^custom/")
      -%} /etc/authselect/{{ result_authselect_profile.stdout }} {%- else -%} /usr/share/authselect/default/{{
      result_authselect_profile.stdout }} {%- endif -%}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_check_cmd is success
  - result_authselect_profile is not skipped
  tags:
  - accounts_password_pam_pwhistory_use_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Enforce Password History with use_authtok - Check if "use_authtok" option
    is present in pam_pwhistory.so in /password-auth
  ansible.builtin.lineinfile:
    path: '{{ pam_profile_path }}/password-auth'
    regexp: ^\s*password\s+([^#\n\r]+)\s+pam_pwhistory\.so\s+([^#\n\r]+\s+)?use_authtok\b
    state: absent
  check_mode: true
  changed_when: false
  register: result_pam_pwhistory_password_auth_option_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_check_cmd is success
  - result_authselect_profile is not skipped
  - pam_profile_path is defined
  tags:
  - accounts_password_pam_pwhistory_use_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Enforce Password History with use_authtok - Ensure "use_authtok" option is
    added to pam_pwhistory.so in /password-auth
  ansible.builtin.replace:
    path: '{{ pam_profile_path }}/password-auth'
    regexp: (^\s*password\s+(requisite|required|sufficient)\s+pam_pwhistory\.so\s+.*)$
    replace: \1 use_authtok
  register: result_pam_pwhistory_password_auth_add
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_check_cmd is success
  - result_authselect_profile is not skipped
  - pam_profile_path is defined
  - result_pam_pwhistory_password_auth_option_present.found is defined
  - result_pam_pwhistory_password_auth_option_present.found == 0
  tags:
  - accounts_password_pam_pwhistory_use_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Enforce Password History with use_authtok - Check if "use_authtok" option
    is present in pam_pwhistory.so in /system-auth
  ansible.builtin.lineinfile:
    path: '{{ pam_profile_path }}/system-auth'
    regexp: ^\s*password\s+([^#\n\r]+)\s+pam_pwhistory\.so\s+([^#\n\r]+\s+)?use_authtok\b
    state: absent
  check_mode: true
  changed_when: false
  register: result_pam_pwhistory_system_auth_option_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_check_cmd is success
  - result_authselect_profile is not skipped
  - pam_profile_path is defined
  tags:
  - accounts_password_pam_pwhistory_use_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Enforce Password History with use_authtok - Ensure "use_authtok" option is
    added to pam_pwhistory.so in /system-auth
  ansible.builtin.replace:
    path: '{{ pam_profile_path }}/system-auth'
    regexp: (^\s*password\s+(requisite|required|sufficient)\s+pam_pwhistory\.so\s+.*)$
    replace: \1 use_authtok
  register: result_pam_pwhistory_system_auth_add
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_check_cmd is success
  - result_authselect_profile is not skipped
  - pam_profile_path is defined
  - result_pam_pwhistory_system_auth_option_present.found is defined
  - result_pam_pwhistory_system_auth_option_present.found == 0
  tags:
  - accounts_password_pam_pwhistory_use_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Enforce Password History with use_authtok - Ensure authselect changes are
    applied
  ansible.builtin.command:
    cmd: authselect apply-changes -b
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_check_cmd is success
  - result_authselect_profile is not skipped
  - |-
    (result_pam_pwhistory_password_auth_add is defined and result_pam_pwhistory_password_auth_add.changed)
     or (result_pam_pwhistory_system_auth_add is defined and result_pam_pwhistory_system_auth_add.changed)
  tags:
  - accounts_password_pam_pwhistory_use_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_pwhistory_use_authtok:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_authtok" selected="false" severity="medium">
                <xccdf-1.2:title>Require use_authtok for pam_unix.so</xccdf-1.2:title>
                <xccdf-1.2:description>When password changing enforce the module to set the new password to the one
provided by a previously stacked password module</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.4.4</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Require use_authtok in pam_unix.so configuration</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix id="accounts_password_pam_unix_authtok" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q pam; }; then

if ! grep -qP "^\s*password\s+sufficient\s+pam_unix.so\s*.*" "/etc/pam.d/system-auth"; then
    # Line matching group + control + module was not found. Check group + module.
    if [ "$(grep -cP '^\s*password\s+.*\s+pam_unix.so\s*' "/etc/pam.d/system-auth")" -eq 1 ]; then
        # The control is updated only if one single line matches.
        sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_unix.so.*)/\1sufficient \2/" "/etc/pam.d/system-auth"
    else
        echo "password    sufficient    pam_unix.so" &gt;&gt; "/etc/pam.d/system-auth"
    fi
fi
# Check the option
if ! grep -qP "^\s*password\s+sufficient\s+pam_unix.so\s*.*\suse_authtok\b" "/etc/pam.d/system-auth"; then
    sed -i -E --follow-symlinks "/\s*password\s+sufficient\s+pam_unix.so.*/ s/$/ use_authtok/" "/etc/pam.d/system-auth"
fi


if ! grep -qP "^\s*password\s+sufficient\s+pam_unix.so\s*.*" "/etc/pam.d/password-auth"; then
    # Line matching group + control + module was not found. Check group + module.
    if [ "$(grep -cP '^\s*password\s+.*\s+pam_unix.so\s*' "/etc/pam.d/password-auth")" -eq 1 ]; then
        # The control is updated only if one single line matches.
        sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_unix.so.*)/\1sufficient \2/" "/etc/pam.d/password-auth"
    else
        echo "password    sufficient    pam_unix.so" &gt;&gt; "/etc/pam.d/password-auth"
    fi
fi
# Check the option
if ! grep -qP "^\s*password\s+sufficient\s+pam_unix.so\s*.*\suse_authtok\b" "/etc/pam.d/password-auth"; then
    sed -i -E --follow-symlinks "/\s*password\s+sufficient\s+pam_unix.so.*/ s/$/ use_authtok/" "/etc/pam.d/password-auth"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="accounts_password_pam_unix_authtok" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - accounts_password_pam_unix_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Require use_authtok for pam_unix.so - Check if system relies on authselect
    tool
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - accounts_password_pam_unix_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Require use_authtok for pam_unix.so - Define a fact for control already filtered
    in case filters are used
  ansible.builtin.set_fact:
    pam_module_control: sufficient
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - accounts_password_pam_unix_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Require use_authtok for pam_unix.so - Check if expected PAM module line is
    present in /etc/pam.d/system-auth
  ansible.builtin.lineinfile:
    path: /etc/pam.d/system-auth
    regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so\s*.*
    state: absent
  check_mode: true
  changed_when: false
  register: result_pam_line_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - accounts_password_pam_unix_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Require use_authtok for pam_unix.so - Include or update the PAM module line
    in /etc/pam.d/system-auth
  block:

  - name: Require use_authtok for pam_unix.so - Check if required PAM module line
      is present in /etc/pam.d/system-auth with different control
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: ^\s*password\s+.*\s+pam_unix.so\s*
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_line_other_control_present

  - name: Require use_authtok for pam_unix.so - Ensure the correct control for the
      required PAM module line in /etc/pam.d/system-auth
    ansible.builtin.replace:
      dest: /etc/pam.d/system-auth
      regexp: ^(\s*password\s+).*(\bpam_unix.so.*)
      replace: \1{{ pam_module_control }} \2
    register: result_pam_module_edit
    when:
    - result_pam_line_other_control_present.found == 1

  - name: Require use_authtok for pam_unix.so - Ensure the required PAM module line
      is included in /etc/pam.d/system-auth
    ansible.builtin.lineinfile:
      dest: /etc/pam.d/system-auth
      line: password    {{ pam_module_control }}    pam_unix.so
    register: result_pam_module_add
    when:
    - result_pam_line_other_control_present.found == 0 or result_pam_line_other_control_present.found
      &gt; 1

  - name: Require use_authtok for pam_unix.so - Ensure authselect changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_present is defined
    - result_authselect_present.stat.exists
    - |-
      (result_pam_module_add is defined and result_pam_module_add.changed)
       or (result_pam_module_edit is defined and result_pam_module_edit.changed)
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_pam_line_present.found is defined
  - result_pam_line_present.found == 0
  tags:
  - accounts_password_pam_unix_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Require use_authtok for pam_unix.so - Define a fact for control already filtered
    in case filters are used
  ansible.builtin.set_fact:
    pam_module_control: sufficient
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - accounts_password_pam_unix_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Require use_authtok for pam_unix.so - Check if the required PAM module option
    is present in /etc/pam.d/system-auth
  ansible.builtin.lineinfile:
    path: /etc/pam.d/system-auth
    regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so\s*.*\suse_authtok\b
    state: absent
  check_mode: true
  changed_when: false
  register: result_pam_module_accounts_password_pam_unix_authtok_option_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - accounts_password_pam_unix_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Require use_authtok for pam_unix.so - Ensure the "use_authtok" PAM option
    for "pam_unix.so" is included in /etc/pam.d/system-auth
  ansible.builtin.lineinfile:
    path: /etc/pam.d/system-auth
    backrefs: true
    regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so.*)
    line: \1 use_authtok
    state: present
  register: result_pam_accounts_password_pam_unix_authtok_add
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_pam_module_accounts_password_pam_unix_authtok_option_present.found is defined
  - result_pam_module_accounts_password_pam_unix_authtok_option_present.found == 0
  tags:
  - accounts_password_pam_unix_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Require use_authtok for pam_unix.so - Define a fact for control already filtered
    in case filters are used
  ansible.builtin.set_fact:
    pam_module_control: sufficient
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - accounts_password_pam_unix_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Require use_authtok for pam_unix.so - Check if expected PAM module line is
    present in /etc/pam.d/password-auth
  ansible.builtin.lineinfile:
    path: /etc/pam.d/password-auth
    regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so\s*.*
    state: absent
  check_mode: true
  changed_when: false
  register: result_pam_line_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - accounts_password_pam_unix_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Require use_authtok for pam_unix.so - Include or update the PAM module line
    in /etc/pam.d/password-auth
  block:

  - name: Require use_authtok for pam_unix.so - Check if required PAM module line
      is present in /etc/pam.d/password-auth with different control
    ansible.builtin.lineinfile:
      path: /etc/pam.d/password-auth
      regexp: ^\s*password\s+.*\s+pam_unix.so\s*
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_line_other_control_present

  - name: Require use_authtok for pam_unix.so - Ensure the correct control for the
      required PAM module line in /etc/pam.d/password-auth
    ansible.builtin.replace:
      dest: /etc/pam.d/password-auth
      regexp: ^(\s*password\s+).*(\bpam_unix.so.*)
      replace: \1{{ pam_module_control }} \2
    register: result_pam_module_edit
    when:
    - result_pam_line_other_control_present.found == 1

  - name: Require use_authtok for pam_unix.so - Ensure the required PAM module line
      is included in /etc/pam.d/password-auth
    ansible.builtin.lineinfile:
      dest: /etc/pam.d/password-auth
      line: password    {{ pam_module_control }}    pam_unix.so
    register: result_pam_module_add
    when:
    - result_pam_line_other_control_present.found == 0 or result_pam_line_other_control_present.found
      &gt; 1

  - name: Require use_authtok for pam_unix.so - Ensure authselect changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_present is defined
    - result_authselect_present.stat.exists
    - |-
      (result_pam_module_add is defined and result_pam_module_add.changed)
       or (result_pam_module_edit is defined and result_pam_module_edit.changed)
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_pam_line_present.found is defined
  - result_pam_line_present.found == 0
  tags:
  - accounts_password_pam_unix_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Require use_authtok for pam_unix.so - Define a fact for control already filtered
    in case filters are used
  ansible.builtin.set_fact:
    pam_module_control: sufficient
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - accounts_password_pam_unix_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Require use_authtok for pam_unix.so - Check if the required PAM module option
    is present in /etc/pam.d/password-auth
  ansible.builtin.lineinfile:
    path: /etc/pam.d/password-auth
    regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so\s*.*\suse_authtok\b
    state: absent
  check_mode: true
  changed_when: false
  register: result_pam_module_accounts_password_pam_unix_authtok_option_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - accounts_password_pam_unix_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Require use_authtok for pam_unix.so - Ensure the "use_authtok" PAM option
    for "pam_unix.so" is included in /etc/pam.d/password-auth
  ansible.builtin.lineinfile:
    path: /etc/pam.d/password-auth
    backrefs: true
    regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so.*)
    line: \1 use_authtok
    state: present
  register: result_pam_accounts_password_pam_unix_authtok_add
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_pam_module_accounts_password_pam_unix_authtok_option_present.found is defined
  - result_pam_module_accounts_password_pam_unix_authtok_option_present.found == 0
  tags:
  - accounts_password_pam_unix_authtok
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_unix_authtok:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_unix_authtok_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_remember" selected="false" severity="medium">
                <xccdf-1.2:title>Limit Password Reuse</xccdf-1.2:title>
                <xccdf-1.2:description>Do not allow users to reuse recent passwords. This can be accomplished by using the
<html:code>remember</html:code> option for the <html:code>pam_unix</html:code> or <html:code>pam_pwhistory</html:code> PAM modules.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">If the system relies on <html:code>authselect</html:code> tool to manage PAM settings, the remediation
will also use <html:code>authselect</html:code> tool. However, if any manual modification was made in
PAM files, the <html:code>authselect</html:code> integrity check will fail and the remediation will be
aborted in order to preserve intentional changes. In this case, an informative message will
be shown in the remediation report.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="general">Newer versions of <html:code>authselect</html:code> contain an authselect feature to easily and properly
enable <html:code>pam_pwhistory.so</html:code> module. If this feature is not yet available in your
system, an authselect custom profile must be used to avoid integrity issues in PAM files.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.6.2.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(f)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(e)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000077-GPOS-00045</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R31</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Preventing reuse of previous passwords helps ensure that a compromised password is not
reused by a user.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_libpwquality"/>
                <xccdf-1.2:fix id="accounts_password_pam_unix_remember" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libpwquality; }; then

var_password_pam_unix_remember='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_remember" use="legacy"/>'






if [ -f /usr/bin/authselect ]; then
    if authselect list-features sssd | grep -q with-pwhistory; then
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi
        authselect enable-feature with-pwhistory

        authselect apply-changes -b
    else
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "/etc/pam.d/system-auth")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
        
        if ! grep -qP "^\s*password\s+requisite\s+pam_pwhistory.so\s*.*" "$PAM_FILE_PATH"; then
            # Line matching group + control + module was not found. Check group + module.
            if [ "$(grep -cP '^\s*password\s+.*\s+pam_pwhistory.so\s*' "$PAM_FILE_PATH")" -eq 1 ]; then
                # The control is updated only if one single line matches.
                sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_pwhistory.so.*)/\1requisite \2/" "$PAM_FILE_PATH"
            else
                LAST_MATCH_LINE=$(grep -nP "^password.*requisite.*pam_pwquality\.so" "$PAM_FILE_PATH" | tail -n 1 | cut -d: -f 1)
                if [ ! -z $LAST_MATCH_LINE ]; then
                    sed -i --follow-symlinks $LAST_MATCH_LINE" a password     requisite    pam_pwhistory.so" "$PAM_FILE_PATH"
                else
                    echo "password    requisite    pam_pwhistory.so" &gt;&gt; "$PAM_FILE_PATH"
                fi
            fi
        fi
    fi
else

    
    if ! grep -qP "^\s*password\s+requisite\s+pam_pwhistory.so\s*.*" "/etc/pam.d/system-auth"; then
        # Line matching group + control + module was not found. Check group + module.
        if [ "$(grep -cP '^\s*password\s+.*\s+pam_pwhistory.so\s*' "/etc/pam.d/system-auth")" -eq 1 ]; then
            # The control is updated only if one single line matches.
            sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_pwhistory.so.*)/\1requisite \2/" "/etc/pam.d/system-auth"
        else
            LAST_MATCH_LINE=$(grep -nP "^password.*requisite.*pam_pwquality\.so" "/etc/pam.d/system-auth" | tail -n 1 | cut -d: -f 1)
            if [ ! -z $LAST_MATCH_LINE ]; then
                sed -i --follow-symlinks $LAST_MATCH_LINE" a password     requisite    pam_pwhistory.so" "/etc/pam.d/system-auth"
            else
                echo "password    requisite    pam_pwhistory.so" &gt;&gt; "/etc/pam.d/system-auth"
            fi
        fi
    fi

fi

PWHISTORY_CONF="/etc/security/pwhistory.conf"
if [ -f $PWHISTORY_CONF ]; then
    regex="^\s*remember\s*="
    line="remember = $var_password_pam_unix_remember"
    if ! grep -q $regex $PWHISTORY_CONF; then
        echo $line &gt;&gt; $PWHISTORY_CONF
    else
        sed -i --follow-symlinks 's|^\s*\(remember\s*=\s*\)\(\S\+\)|\1'"$var_password_pam_unix_remember"'|g' $PWHISTORY_CONF
    fi
    if [ -e "/etc/pam.d/system-auth" ] ; then
        PAM_FILE_PATH="/etc/pam.d/system-auth"
        if [ -f /usr/bin/authselect ]; then
            
            if ! authselect check; then
            echo "
            authselect integrity check failed. Remediation aborted!
            This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
            It is not recommended to manually edit the PAM files when authselect tool is available.
            In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
            exit 1
            fi

            CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
            # If not already in use, a custom profile is created preserving the enabled features.
            if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                # The "local" profile does not contain essential security features required by multiple Benchmarks.
                # If currently used, it is replaced by "sssd", which is the best option in this case.
                if [[ $CURRENT_PROFILE == local ]]; then
                    CURRENT_PROFILE="sssd"
                fi
                authselect create-profile hardening -b $CURRENT_PROFILE
                CURRENT_PROFILE="custom/hardening"
                
                authselect apply-changes -b --backup=before-hardening-custom-profile
                authselect select $CURRENT_PROFILE
                for feature in $ENABLED_FEATURES; do
                    authselect enable-feature $feature;
                done
                
                authselect apply-changes -b --backup=after-hardening-custom-profile
            fi
            PAM_FILE_NAME=$(basename "/etc/pam.d/system-auth")
            PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

            authselect apply-changes -b
        fi
        
    if grep -qP "^\s*password\s.*\bpam_pwhistory.so\s.*\bremember\b" "$PAM_FILE_PATH"; then
        sed -i -E --follow-symlinks "s/(.*password.*pam_pwhistory.so.*)\bremember\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
    fi
        if [ -f /usr/bin/authselect ]; then
            
            authselect apply-changes -b
        fi
    else
        echo "/etc/pam.d/system-auth was not found" &gt;&amp;2
    fi
else
    PAM_FILE_PATH="/etc/pam.d/system-auth"
    if [ -f /usr/bin/authselect ]; then
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "/etc/pam.d/system-auth")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
    fi
    

    if ! grep -qP "^\s*password\s+requisite\s+pam_pwhistory.so\s*.*" "$PAM_FILE_PATH"; then
        # Line matching group + control + module was not found. Check group + module.
        if [ "$(grep -cP '^\s*password\s+.*\s+pam_pwhistory.so\s*' "$PAM_FILE_PATH")" -eq 1 ]; then
            # The control is updated only if one single line matches.
            sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_pwhistory.so.*)/\1requisite \2/" "$PAM_FILE_PATH"
        else
            echo "password    requisite    pam_pwhistory.so" &gt;&gt; "$PAM_FILE_PATH"
        fi
    fi
    # Check the option
    if ! grep -qP "^\s*password\s+requisite\s+pam_pwhistory.so\s*.*\sremember\b" "$PAM_FILE_PATH"; then
        sed -i -E --follow-symlinks "/\s*password\s+requisite\s+pam_pwhistory.so.*/ s/$/ remember=$var_password_pam_unix_remember/" "$PAM_FILE_PATH"
    else
        sed -i -E --follow-symlinks "s/(\s*password\s+requisite\s+pam_pwhistory.so\s+.*)(remember=)[[:alnum:]]*\s*(.*)/\1\2$var_password_pam_unix_remember \3/" "$PAM_FILE_PATH"
    fi
    if [ -f /usr/bin/authselect ]; then
        
        authselect apply-changes -b
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="accounts_password_pam_unix_remember" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_unix_remember
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
- name: XCCDF Value var_password_pam_unix_remember # promote to variable
  set_fact:
    var_password_pam_unix_remember: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_remember" use="legacy"/>
  tags:
    - always

- name: Limit Password Reuse - Check if system relies on authselect tool
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_unix_remember
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Limit Password Reuse - Collect the available authselect features
  ansible.builtin.command:
    cmd: authselect list-features sssd
  register: result_authselect_available_features
  changed_when: false
  check_mode: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_unix_remember
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Limit Password Reuse - Enable pam_pwhistory.so using authselect feature
  block:

  - name: Limit Password Reuse - Check integrity of authselect current profile
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: Limit Password Reuse - Informative message based on the authselect integrity
      check result
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: Limit Password Reuse - Get authselect current features
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: Limit Password Reuse - Ensure "with-pwhistory" feature is enabled using
      authselect tool
    ansible.builtin.command:
      cmd: authselect enable-feature with-pwhistory
    register: result_authselect_enable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is not search("with-pwhistory")

  - name: Limit Password Reuse - Ensure authselect changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_enable_feature_cmd is not skipped
    - result_authselect_enable_feature_cmd is success
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  - result_authselect_available_features.stdout is search("with-pwhistory")
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_unix_remember
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Limit Password Reuse - Enable pam_pwhistory.so in appropriate PAM files
  block:

  - name: Limit Password Reuse - Define the PAM file to be edited as a local fact
    ansible.builtin.set_fact:
      pam_file_path: /etc/pam.d/system-auth

  - name: Limit Password Reuse - Check if system relies on authselect tool
    ansible.builtin.stat:
      path: /usr/bin/authselect
    register: result_authselect_present

  - name: Limit Password Reuse - Ensure authselect custom profile is used if authselect
      is present
    block:

    - name: Limit Password Reuse - Check integrity of authselect current profile
      ansible.builtin.command:
        cmd: authselect check
      register: result_authselect_check_cmd
      changed_when: false
      check_mode: false
      failed_when: false

    - name: Limit Password Reuse - Informative message based on the authselect integrity
        check result
      ansible.builtin.assert:
        that:
        - ansible_check_mode or result_authselect_check_cmd.rc == 0
        fail_msg:
        - authselect integrity check failed. Remediation aborted!
        - This remediation could not be applied because an authselect profile was
          not selected or the selected profile is not intact.
        - It is not recommended to manually edit the PAM files when authselect tool
          is available.
        - In cases where the default authselect profile does not cover a specific
          demand, a custom authselect profile is recommended.
        success_msg:
        - authselect integrity check passed

    - name: Limit Password Reuse - Get authselect current profile
      ansible.builtin.shell:
        cmd: authselect current -r | awk '{ print $1 }'
      register: result_authselect_profile
      changed_when: false
      when:
      - result_authselect_check_cmd is success

    - name: Limit Password Reuse - Define the current authselect profile as a local
        fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is match("custom/")

    - name: Limit Password Reuse - Define the new authselect custom profile as a local
        fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: custom/hardening
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is not match("custom/")

    - name: Limit Password Reuse - Get authselect current features to also enable
        them in the custom profile
      ansible.builtin.shell:
        cmd: authselect current | tail -n+3 | awk '{ print $2 }'
      register: result_authselect_features
      changed_when: false
      check_mode: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Limit Password Reuse - Check if any custom profile with the same name
        was already created
      ansible.builtin.stat:
        path: /etc/authselect/{{ authselect_custom_profile }}
      register: result_authselect_custom_profile_present
      changed_when: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Limit Password Reuse - Create an authselect custom profile based on the
        current profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b {{ authselect_current_profile
          }}
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is not match("^(custom/|local)")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Limit Password Reuse - Create an authselect custom profile based on sssd
        profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b sssd
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is match("local")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Limit Password Reuse - Ensure authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Limit Password Reuse - Ensure the authselect custom profile is selected
      ansible.builtin.command:
        cmd: authselect select {{ authselect_custom_profile }}
      register: result_pam_authselect_select_profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Limit Password Reuse - Restore the authselect features in the custom profile
      ansible.builtin.command:
        cmd: authselect enable-feature {{ item }}
      loop: '{{ result_authselect_features.stdout_lines }}'
      register: result_pam_authselect_restore_features
      when:
      - result_authselect_profile is not skipped
      - result_authselect_features is not skipped
      - result_pam_authselect_select_profile is not skipped

    - name: Limit Password Reuse - Ensure authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - result_pam_authselect_restore_features is not skipped

    - name: Limit Password Reuse - Change the PAM file to be edited according to the
        custom authselect profile
      ansible.builtin.set_fact:
        pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
          | basename }}
      when:
      - authselect_custom_profile is defined
    when:
    - result_authselect_present.stat.exists

  - name: Limit Password Reuse - Define a fact for control already filtered in case
      filters are used
    ansible.builtin.set_fact:
      pam_module_control: requisite

  - name: Limit Password Reuse - Check if expected PAM module line is present in {{
      pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwhistory.so\s*.*
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_line_present

  - name: Limit Password Reuse - Include or update the PAM module line in {{ pam_file_path
      }}
    block:

    - name: Limit Password Reuse - Check if required PAM module line is present in
        {{ pam_file_path }} with different control
      ansible.builtin.lineinfile:
        path: '{{ pam_file_path }}'
        regexp: ^\s*password\s+.*\s+pam_pwhistory.so\s*
        state: absent
      check_mode: true
      changed_when: false
      register: result_pam_line_other_control_present

    - name: Limit Password Reuse - Ensure the correct control for the required PAM
        module line in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: ^(\s*password\s+).*(\bpam_pwhistory.so.*)
        replace: \1{{ pam_module_control }} \2
      register: result_pam_module_edit
      when:
      - result_pam_line_other_control_present.found == 1

    - name: Limit Password Reuse - Ensure the required PAM module line is included
        in {{ pam_file_path }}
      ansible.builtin.lineinfile:
        dest: '{{ pam_file_path }}'
        insertafter: ^password.*requisite.*pam_pwquality\.so
        line: password    {{ pam_module_control }}    pam_pwhistory.so
      register: result_pam_module_add
      when:
      - result_pam_line_other_control_present.found == 0 or result_pam_line_other_control_present.found
        &gt; 1

    - name: Limit Password Reuse - Ensure authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present is defined
      - result_authselect_present.stat.exists
      - |-
        (result_pam_module_add is defined and result_pam_module_add.changed)
         or (result_pam_module_edit is defined and result_pam_module_edit.changed)
    when:
    - result_pam_line_present.found is defined
    - result_pam_line_present.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  - |
    (result_authselect_available_features.stdout is defined and result_authselect_available_features.stdout is not search("with-pwhistory")) or result_authselect_available_features is not defined
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_unix_remember
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Limit Password Reuse - Check the presence of /etc/security/pwhistory.conf
    file
  ansible.builtin.stat:
    path: /etc/security/pwhistory.conf
  register: result_pwhistory_conf_check
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_unix_remember
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Limit Password Reuse - pam_pwhistory.so parameters are configured in /etc/security/pwhistory.conf
    file
  block:

  - name: Limit Password Reuse - Ensure the pam_pwhistory.so remember parameter in
      /etc/security/pwhistory.conf
    ansible.builtin.lineinfile:
      path: /etc/security/pwhistory.conf
      regexp: ^\s*remember\s*=
      line: remember = {{ var_password_pam_unix_remember }}
      state: present

  - name: Limit Password Reuse - Ensure the pam_pwhistory.so remember parameter is
      removed from PAM files
    block:

    - name: Limit Password Reuse - Check if /etc/pam.d/system-auth file is present
      ansible.builtin.stat:
        path: /etc/pam.d/system-auth
      register: result_pam_auth_file_present

    - name: Limit Password Reuse - Check the proper remediation for the system
      block:

      - name: Limit Password Reuse - Define the PAM file to be edited as a local fact
        ansible.builtin.set_fact:
          pam_file_path: /etc/pam.d/system-auth

      - name: Limit Password Reuse - Check if system relies on authselect tool
        ansible.builtin.stat:
          path: /usr/bin/authselect
        register: result_authselect_present

      - name: Limit Password Reuse - Ensure authselect custom profile is used if authselect
          is present
        block:

        - name: Limit Password Reuse - Check integrity of authselect current profile
          ansible.builtin.command:
            cmd: authselect check
          register: result_authselect_check_cmd
          changed_when: false
          check_mode: false
          failed_when: false

        - name: Limit Password Reuse - Informative message based on the authselect
            integrity check result
          ansible.builtin.assert:
            that:
            - ansible_check_mode or result_authselect_check_cmd.rc == 0
            fail_msg:
            - authselect integrity check failed. Remediation aborted!
            - This remediation could not be applied because an authselect profile
              was not selected or the selected profile is not intact.
            - It is not recommended to manually edit the PAM files when authselect
              tool is available.
            - In cases where the default authselect profile does not cover a specific
              demand, a custom authselect profile is recommended.
            success_msg:
            - authselect integrity check passed

        - name: Limit Password Reuse - Get authselect current profile
          ansible.builtin.shell:
            cmd: authselect current -r | awk '{ print $1 }'
          register: result_authselect_profile
          changed_when: false
          when:
          - result_authselect_check_cmd is success

        - name: Limit Password Reuse - Define the current authselect profile as a
            local fact
          ansible.builtin.set_fact:
            authselect_current_profile: '{{ result_authselect_profile.stdout }}'
            authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
          when:
          - result_authselect_profile is not skipped
          - result_authselect_profile.stdout is match("custom/")

        - name: Limit Password Reuse - Define the new authselect custom profile as
            a local fact
          ansible.builtin.set_fact:
            authselect_current_profile: '{{ result_authselect_profile.stdout }}'
            authselect_custom_profile: custom/hardening
          when:
          - result_authselect_profile is not skipped
          - result_authselect_profile.stdout is not match("custom/")

        - name: Limit Password Reuse - Get authselect current features to also enable
            them in the custom profile
          ansible.builtin.shell:
            cmd: authselect current | tail -n+3 | awk '{ print $2 }'
          register: result_authselect_features
          changed_when: false
          check_mode: false
          when:
          - result_authselect_profile is not skipped
          - authselect_current_profile is not match("custom/")

        - name: Limit Password Reuse - Check if any custom profile with the same name
            was already created
          ansible.builtin.stat:
            path: /etc/authselect/{{ authselect_custom_profile }}
          register: result_authselect_custom_profile_present
          changed_when: false
          when:
          - result_authselect_profile is not skipped
          - authselect_current_profile is not match("custom/")

        - name: Limit Password Reuse - Create an authselect custom profile based on
            the current profile
          ansible.builtin.command:
            cmd: authselect create-profile hardening -b {{ authselect_current_profile
              }}
          when:
          - result_authselect_profile is not skipped
          - result_authselect_check_cmd is success
          - authselect_current_profile is not match("^(custom/|local)")
          - not result_authselect_custom_profile_present.stat.exists

        - name: Limit Password Reuse - Create an authselect custom profile based on
            sssd profile
          ansible.builtin.command:
            cmd: authselect create-profile hardening -b sssd
          when:
          - result_authselect_profile is not skipped
          - result_authselect_check_cmd is success
          - authselect_current_profile is match("local")
          - not result_authselect_custom_profile_present.stat.exists

        - name: Limit Password Reuse - Ensure authselect changes are applied
          ansible.builtin.command:
            cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
          when:
          - result_authselect_check_cmd is success
          - result_authselect_profile is not skipped
          - authselect_current_profile is not match("custom/")
          - authselect_custom_profile is not match(authselect_current_profile)

        - name: Limit Password Reuse - Ensure the authselect custom profile is selected
          ansible.builtin.command:
            cmd: authselect select {{ authselect_custom_profile }}
          register: result_pam_authselect_select_profile
          when:
          - result_authselect_check_cmd is success
          - result_authselect_profile is not skipped
          - authselect_current_profile is not match("custom/")
          - authselect_custom_profile is not match(authselect_current_profile)

        - name: Limit Password Reuse - Restore the authselect features in the custom
            profile
          ansible.builtin.command:
            cmd: authselect enable-feature {{ item }}
          loop: '{{ result_authselect_features.stdout_lines }}'
          register: result_pam_authselect_restore_features
          when:
          - result_authselect_profile is not skipped
          - result_authselect_features is not skipped
          - result_pam_authselect_select_profile is not skipped

        - name: Limit Password Reuse - Ensure authselect changes are applied
          ansible.builtin.command:
            cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
          when:
          - result_authselect_check_cmd is success
          - result_authselect_profile is not skipped
          - result_pam_authselect_restore_features is not skipped

        - name: Limit Password Reuse - Change the PAM file to be edited according
            to the custom authselect profile
          ansible.builtin.set_fact:
            pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
              | basename }}
          when:
          - authselect_custom_profile is defined
        when:
        - result_authselect_present.stat.exists

      - name: Limit Password Reuse - Define a fact for control already filtered in
          case filters are used
        ansible.builtin.set_fact:
          pam_module_control: ''

      - name: Limit Password Reuse - Check if {{ pam_file_path }} file is present
        ansible.builtin.stat:
          path: '{{ pam_file_path }}'
        register: result_pam_file_present

      - name: Limit Password Reuse - Ensure the "remember" option from "pam_pwhistory.so"
          is not present in {{ pam_file_path }}
        ansible.builtin.replace:
          dest: '{{ pam_file_path }}'
          regexp: (.*password.*pam_pwhistory.so.*)\bremember\b=?[0-9a-zA-Z]*(.*)
          replace: \1\2
        register: result_pam_option_removal
        when:
        - result_pam_file_present.stat.exists

      - name: Limit Password Reuse - Ensure authselect changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b
        when:
        - result_authselect_present.stat.exists
        - result_pam_option_removal is changed
      when:
      - result_pam_auth_file_present.stat.exists
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  - result_pwhistory_conf_check.stat.exists
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_unix_remember
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Limit Password Reuse - pam_pwhistory.so parameters are configured in PAM files
  block:

  - name: Limit Password Reuse - Define the PAM file to be edited as a local fact
    ansible.builtin.set_fact:
      pam_file_path: /etc/pam.d/system-auth

  - name: Limit Password Reuse - Check if system relies on authselect tool
    ansible.builtin.stat:
      path: /usr/bin/authselect
    register: result_authselect_present

  - name: Limit Password Reuse - Ensure authselect custom profile is used if authselect
      is present
    block:

    - name: Limit Password Reuse - Check integrity of authselect current profile
      ansible.builtin.command:
        cmd: authselect check
      register: result_authselect_check_cmd
      changed_when: false
      check_mode: false
      failed_when: false

    - name: Limit Password Reuse - Informative message based on the authselect integrity
        check result
      ansible.builtin.assert:
        that:
        - ansible_check_mode or result_authselect_check_cmd.rc == 0
        fail_msg:
        - authselect integrity check failed. Remediation aborted!
        - This remediation could not be applied because an authselect profile was
          not selected or the selected profile is not intact.
        - It is not recommended to manually edit the PAM files when authselect tool
          is available.
        - In cases where the default authselect profile does not cover a specific
          demand, a custom authselect profile is recommended.
        success_msg:
        - authselect integrity check passed

    - name: Limit Password Reuse - Get authselect current profile
      ansible.builtin.shell:
        cmd: authselect current -r | awk '{ print $1 }'
      register: result_authselect_profile
      changed_when: false
      when:
      - result_authselect_check_cmd is success

    - name: Limit Password Reuse - Define the current authselect profile as a local
        fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is match("custom/")

    - name: Limit Password Reuse - Define the new authselect custom profile as a local
        fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: custom/hardening
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is not match("custom/")

    - name: Limit Password Reuse - Get authselect current features to also enable
        them in the custom profile
      ansible.builtin.shell:
        cmd: authselect current | tail -n+3 | awk '{ print $2 }'
      register: result_authselect_features
      changed_when: false
      check_mode: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Limit Password Reuse - Check if any custom profile with the same name
        was already created
      ansible.builtin.stat:
        path: /etc/authselect/{{ authselect_custom_profile }}
      register: result_authselect_custom_profile_present
      changed_when: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Limit Password Reuse - Create an authselect custom profile based on the
        current profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b {{ authselect_current_profile
          }}
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is not match("^(custom/|local)")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Limit Password Reuse - Create an authselect custom profile based on sssd
        profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b sssd
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is match("local")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Limit Password Reuse - Ensure authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Limit Password Reuse - Ensure the authselect custom profile is selected
      ansible.builtin.command:
        cmd: authselect select {{ authselect_custom_profile }}
      register: result_pam_authselect_select_profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Limit Password Reuse - Restore the authselect features in the custom profile
      ansible.builtin.command:
        cmd: authselect enable-feature {{ item }}
      loop: '{{ result_authselect_features.stdout_lines }}'
      register: result_pam_authselect_restore_features
      when:
      - result_authselect_profile is not skipped
      - result_authselect_features is not skipped
      - result_pam_authselect_select_profile is not skipped

    - name: Limit Password Reuse - Ensure authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - result_pam_authselect_restore_features is not skipped

    - name: Limit Password Reuse - Change the PAM file to be edited according to the
        custom authselect profile
      ansible.builtin.set_fact:
        pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
          | basename }}
      when:
      - authselect_custom_profile is defined
    when:
    - result_authselect_present.stat.exists

  - name: Limit Password Reuse - Define a fact for control already filtered in case
      filters are used
    ansible.builtin.set_fact:
      pam_module_control: requisite

  - name: Limit Password Reuse - Check if expected PAM module line is present in {{
      pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwhistory.so\s*.*
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_line_present

  - name: Limit Password Reuse - Include or update the PAM module line in {{ pam_file_path
      }}
    block:

    - name: Limit Password Reuse - Check if required PAM module line is present in
        {{ pam_file_path }} with different control
      ansible.builtin.lineinfile:
        path: '{{ pam_file_path }}'
        regexp: ^\s*password\s+.*\s+pam_pwhistory.so\s*
        state: absent
      check_mode: true
      changed_when: false
      register: result_pam_line_other_control_present

    - name: Limit Password Reuse - Ensure the correct control for the required PAM
        module line in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: ^(\s*password\s+).*(\bpam_pwhistory.so.*)
        replace: \1{{ pam_module_control }} \2
      register: result_pam_module_edit
      when:
      - result_pam_line_other_control_present.found == 1

    - name: Limit Password Reuse - Ensure the required PAM module line is included
        in {{ pam_file_path }}
      ansible.builtin.lineinfile:
        dest: '{{ pam_file_path }}'
        line: password    {{ pam_module_control }}    pam_pwhistory.so
      register: result_pam_module_add
      when:
      - result_pam_line_other_control_present.found == 0 or result_pam_line_other_control_present.found
        &gt; 1

    - name: Limit Password Reuse - Ensure authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present is defined
      - result_authselect_present.stat.exists
      - |-
        (result_pam_module_add is defined and result_pam_module_add.changed)
         or (result_pam_module_edit is defined and result_pam_module_edit.changed)
    when:
    - result_pam_line_present.found is defined
    - result_pam_line_present.found == 0

  - name: Limit Password Reuse - Define a fact for control already filtered in case
      filters are used
    ansible.builtin.set_fact:
      pam_module_control: requisite

  - name: Limit Password Reuse - Check if the required PAM module option is present
      in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwhistory.so\s*.*\sremember\b
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_module_accounts_password_pam_unix_remember_option_present

  - name: Limit Password Reuse - Ensure the "remember" PAM option for "pam_pwhistory.so"
      is included in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      backrefs: true
      regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwhistory.so.*)
      line: \1 remember={{ var_password_pam_unix_remember }}
      state: present
    register: result_pam_accounts_password_pam_unix_remember_add
    when:
    - result_pam_module_accounts_password_pam_unix_remember_option_present.found is
      defined
    - result_pam_module_accounts_password_pam_unix_remember_option_present.found ==
      0

  - name: Limit Password Reuse - Ensure the required value for "remember" PAM option
      from "pam_pwhistory.so" in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      backrefs: true
      regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwhistory.so\s+.*)(remember)=[0-9a-zA-Z]*\s*(.*)
      line: \1\2={{ var_password_pam_unix_remember }} \3
    register: result_pam_accounts_password_pam_unix_remember_edit
    when:
    - result_pam_module_accounts_password_pam_unix_remember_option_present.found &gt;
      0

  - name: Limit Password Reuse - Ensure authselect changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_present.stat.exists
    - (result_pam_remember_add is defined and result_pam_remember_add.changed) or
      (result_pam_remember_edit is defined and result_pam_remember_edit.changed)
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  - not result_pwhistory_conf_check.stat.exists
  tags:
  - CJIS-5.6.2.1.1
  - NIST-800-171-3.5.8
  - NIST-800-53-IA-5(1)(e)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.5
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.7
  - accounts_password_pam_unix_remember
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_unix_remember:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_unix_remember"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_unix_remember:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_unix_remember_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_audit" selected="false" severity="medium">
                <xccdf-1.2:title>Account Lockouts Must Be Logged</xccdf-1.2:title>
                <xccdf-1.2:description>PAM faillock locks an account due to excessive password failures, this event must be logged.</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-7 (a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000021-GPOS-00005</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020021</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230343r1017155_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Without auditing of these events it may be harder or impossible to identify what an attacker did after an attack.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#os_linux_rhel_gt_or_eq_8_2_and_package_pam"/>
                <xccdf-1.2:fix id="accounts_passwords_pam_faillock_audit" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { ( ( grep -qP "^ID=[\"']?rhel[\"']?$" "/etc/os-release" &amp;&amp; { real="$(grep -P "^VERSION_ID=[\"']?[\w.]+[\"']?$" /etc/os-release | sed "s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")"; expected="8.2"; printf "%s\n%s" "$expected" "$real" | sort -VC; } &amp;&amp; rpm --quiet -q pam ) ); }; then

if [ -f /usr/bin/authselect ]; then
    if ! authselect check; then
echo "
authselect integrity check failed. Remediation aborted!
This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
It is not recommended to manually edit the PAM files when authselect tool is available.
In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
exit 1
fi
authselect enable-feature with-faillock

authselect apply-changes -b
else
    
AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
for pam_file in "${AUTH_FILES[@]}"
do
    if ! grep -qE '^\s*auth\s+required\s+pam_faillock\.so\s+(preauth silent|authfail).*$' "$pam_file" ; then
        sed -i --follow-symlinks '/^auth.*sufficient.*pam_unix\.so.*/i auth        required      pam_faillock.so preauth silent' "$pam_file"
        sed -i --follow-symlinks '/^auth.*required.*pam_deny\.so.*/i auth        required      pam_faillock.so authfail' "$pam_file"
        sed -i --follow-symlinks '/^account.*required.*pam_unix\.so.*/i account     required      pam_faillock.so' "$pam_file"
    fi
    sed -Ei 's/(auth.*)(\[default=die\])(.*pam_faillock\.so)/\1required     \3/g' "$pam_file"
done

fi

AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
SKIP_FAILLOCK_CHECK=false

FAILLOCK_CONF="/etc/security/faillock.conf"
if [ -f $FAILLOCK_CONF ] || [ "$SKIP_FAILLOCK_CHECK" = "true" ]; then
    regex="^\s*audit"
    line="audit"
    if ! grep -q $regex $FAILLOCK_CONF; then
        echo $line &gt;&gt; $FAILLOCK_CONF
    fi
    
    for pam_file in "${AUTH_FILES[@]}"
    do
        if [ -e "$pam_file" ] ; then
            PAM_FILE_PATH="$pam_file"
            if [ -f /usr/bin/authselect ]; then
                
                if ! authselect check; then
                echo "
                authselect integrity check failed. Remediation aborted!
                This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
                It is not recommended to manually edit the PAM files when authselect tool is available.
                In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
                exit 1
                fi

                CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
                # If not already in use, a custom profile is created preserving the enabled features.
                if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                    ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                    # The "local" profile does not contain essential security features required by multiple Benchmarks.
                    # If currently used, it is replaced by "sssd", which is the best option in this case.
                    if [[ $CURRENT_PROFILE == local ]]; then
                        CURRENT_PROFILE="sssd"
                    fi
                    authselect create-profile hardening -b $CURRENT_PROFILE
                    CURRENT_PROFILE="custom/hardening"
                    
                    authselect apply-changes -b --backup=before-hardening-custom-profile
                    authselect select $CURRENT_PROFILE
                    for feature in $ENABLED_FEATURES; do
                        authselect enable-feature $feature;
                    done
                    
                    authselect apply-changes -b --backup=after-hardening-custom-profile
                fi
                PAM_FILE_NAME=$(basename "$pam_file")
                PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

                authselect apply-changes -b
            fi
            
        if grep -qP "^\s*auth\s.*\bpam_faillock.so\s.*\baudit\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "s/(.*auth.*pam_faillock.so.*)\baudit\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
        fi
            if [ -f /usr/bin/authselect ]; then
                
                authselect apply-changes -b
            fi
        else
            echo "$pam_file was not found" &gt;&amp;2
        fi
    done
    
else
    for pam_file in "${AUTH_FILES[@]}"
    do
        if ! grep -qE '^\s*auth.*pam_faillock\.so\s+(preauth|authfail).*audit' "$pam_file"; then
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*preauth.*/ s/$/ audit/' "$pam_file"
        fi
    done
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_passwords_pam_faillock_audit" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020021
  - NIST-800-53-AC-7 (a)
  - accounts_passwords_pam_faillock_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Account Lockouts Must Be Logged - Check if system relies on authselect tool
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.2',
    '&gt;=') and "pam" in ansible_facts.packages )
  tags:
  - DISA-STIG-RHEL-08-020021
  - NIST-800-53-AC-7 (a)
  - accounts_passwords_pam_faillock_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Account Lockouts Must Be Logged - Remediation where authselect tool is present
  block:

  - name: Account Lockouts Must Be Logged - Check integrity of authselect current
      profile
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: Account Lockouts Must Be Logged - Informative message based on the authselect
      integrity check result
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: Account Lockouts Must Be Logged - Get authselect current features
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: Account Lockouts Must Be Logged - Ensure "with-faillock" feature is enabled
      using authselect tool
    ansible.builtin.command:
      cmd: authselect enable-feature with-faillock
    register: result_authselect_enable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is not search("with-faillock")

  - name: Account Lockouts Must Be Logged - Ensure authselect changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_enable_feature_cmd is not skipped
    - result_authselect_enable_feature_cmd is success
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.2',
    '&gt;=') and "pam" in ansible_facts.packages )
  - result_authselect_present.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020021
  - NIST-800-53-AC-7 (a)
  - accounts_passwords_pam_faillock_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Account Lockouts Must Be Logged - Remediation where authselect tool is not
    present
  block:

  - name: Account Lockouts Must Be Logged - Check if pam_faillock.so is already enabled
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail)
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_is_enabled

  - name: Account Lockouts Must Be Logged - Enable pam_faillock.so preauth editing
      PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so preauth
      insertbefore: ^auth.*sufficient.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Account Lockouts Must Be Logged - Enable pam_faillock.so authfail editing
      PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so authfail
      insertbefore: ^auth.*required.*pam_deny\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Account Lockouts Must Be Logged - Enable pam_faillock.so account section
      editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: account     required      pam_faillock.so
      insertbefore: ^account.*required.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.2',
    '&gt;=') and "pam" in ansible_facts.packages )
  - not result_authselect_present.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020021
  - NIST-800-53-AC-7 (a)
  - accounts_passwords_pam_faillock_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Account Lockouts Must Be Logged - Check the presence of /etc/security/faillock.conf
    file
  ansible.builtin.stat:
    path: /etc/security/faillock.conf
  register: result_faillock_conf_check
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.2',
    '&gt;=') and "pam" in ansible_facts.packages )
  tags:
  - DISA-STIG-RHEL-08-020021
  - NIST-800-53-AC-7 (a)
  - accounts_passwords_pam_faillock_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Account Lockouts Must Be Logged - Ensure the pam_faillock.so audit parameter
    in /etc/security/faillock.conf
  ansible.builtin.lineinfile:
    path: /etc/security/faillock.conf
    regexp: ^\s*audit
    line: audit
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.2',
    '&gt;=') and "pam" in ansible_facts.packages )
  - result_faillock_conf_check.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020021
  - NIST-800-53-AC-7 (a)
  - accounts_passwords_pam_faillock_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Account Lockouts Must Be Logged - Ensure the pam_faillock.so audit parameter
    not in PAM files
  block:

  - name: Account Lockouts Must Be Logged - Check if /etc/pam.d/system-auth file is
      present
    ansible.builtin.stat:
      path: /etc/pam.d/system-auth
    register: result_pam_auth_file_present

  - name: Account Lockouts Must Be Logged - Check the proper remediation for the system
    block:

    - name: Account Lockouts Must Be Logged - Define the PAM file to be edited as
        a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/system-auth

    - name: Account Lockouts Must Be Logged - Check if system relies on authselect
        tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Account Lockouts Must Be Logged - Ensure authselect custom profile is
        used if authselect is present
      block:

      - name: Account Lockouts Must Be Logged - Check integrity of authselect current
          profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Account Lockouts Must Be Logged - Informative message based on the authselect
          integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Account Lockouts Must Be Logged - Get authselect current profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Account Lockouts Must Be Logged - Define the current authselect profile
          as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Account Lockouts Must Be Logged - Define the new authselect custom profile
          as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Account Lockouts Must Be Logged - Get authselect current features to
          also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Account Lockouts Must Be Logged - Check if any custom profile with the
          same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Account Lockouts Must Be Logged - Create an authselect custom profile
          based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Account Lockouts Must Be Logged - Create an authselect custom profile
          based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Account Lockouts Must Be Logged - Ensure authselect changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Account Lockouts Must Be Logged - Ensure the authselect custom profile
          is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Account Lockouts Must Be Logged - Restore the authselect features in
          the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Account Lockouts Must Be Logged - Ensure authselect changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Account Lockouts Must Be Logged - Change the PAM file to be edited according
          to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Account Lockouts Must Be Logged - Define a fact for control already filtered
        in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Account Lockouts Must Be Logged - Check if {{ pam_file_path }} file is
        present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Account Lockouts Must Be Logged - Ensure the "audit" option from "pam_faillock.so"
        is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\baudit\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Account Lockouts Must Be Logged - Ensure authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_auth_file_present.stat.exists

  - name: Account Lockouts Must Be Logged - Check if /etc/pam.d/password-auth file
      is present
    ansible.builtin.stat:
      path: /etc/pam.d/password-auth
    register: result_pam_password_auth_file_present

  - name: Account Lockouts Must Be Logged - Check the proper remediation for the system
    block:

    - name: Account Lockouts Must Be Logged - Define the PAM file to be edited as
        a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/password-auth

    - name: Account Lockouts Must Be Logged - Check if system relies on authselect
        tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Account Lockouts Must Be Logged - Ensure authselect custom profile is
        used if authselect is present
      block:

      - name: Account Lockouts Must Be Logged - Check integrity of authselect current
          profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Account Lockouts Must Be Logged - Informative message based on the authselect
          integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Account Lockouts Must Be Logged - Get authselect current profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Account Lockouts Must Be Logged - Define the current authselect profile
          as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Account Lockouts Must Be Logged - Define the new authselect custom profile
          as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Account Lockouts Must Be Logged - Get authselect current features to
          also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Account Lockouts Must Be Logged - Check if any custom profile with the
          same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Account Lockouts Must Be Logged - Create an authselect custom profile
          based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Account Lockouts Must Be Logged - Create an authselect custom profile
          based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Account Lockouts Must Be Logged - Ensure authselect changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Account Lockouts Must Be Logged - Ensure the authselect custom profile
          is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Account Lockouts Must Be Logged - Restore the authselect features in
          the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Account Lockouts Must Be Logged - Ensure authselect changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Account Lockouts Must Be Logged - Change the PAM file to be edited according
          to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Account Lockouts Must Be Logged - Define a fact for control already filtered
        in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Account Lockouts Must Be Logged - Check if {{ pam_file_path }} file is
        present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Account Lockouts Must Be Logged - Ensure the "audit" option from "pam_faillock.so"
        is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\baudit\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Account Lockouts Must Be Logged - Ensure authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_password_auth_file_present.stat.exists
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.2',
    '&gt;=') and "pam" in ansible_facts.packages )
  - result_faillock_conf_check.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020021
  - NIST-800-53-AC-7 (a)
  - accounts_passwords_pam_faillock_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Account Lockouts Must Be Logged - Ensure the pam_faillock.so audit parameter
    in PAM files
  block:

  - name: Account Lockouts Must Be Logged - Check if pam_faillock.so audit parameter
      is already enabled in pam files
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail).*audit
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_audit_parameter_is_present

  - name: Account Lockouts Must Be Logged - Ensure the inclusion of pam_faillock.so
      preauth audit parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so preauth.*)
      line: \1required\3 audit
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_audit_parameter_is_present.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.2',
    '&gt;=') and "pam" in ansible_facts.packages )
  - not result_faillock_conf_check.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020021
  - NIST-800-53-AC-7 (a)
  - accounts_passwords_pam_faillock_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_passwords_pam_faillock_audit:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_passwords_pam_faillock_audit_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny" selected="false" severity="medium">
                <xccdf-1.2:title>Lock Accounts After Failed Password Attempts</xccdf-1.2:title>
                <xccdf-1.2:description>This rule configures the system to lock out accounts after a number of incorrect login attempts
using <html:code>pam_faillock.so</html:code>.
pam_faillock.so module requires multiple entries in pam files. These entries must be carefully
defined to work as expected.
Ensure that the file <html:code>/etc/security/faillock.conf</html:code> contains the following entry:
<html:code>deny = &lt;count&gt;</html:code>
Where count should be less than or equal to
<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" use="legacy"/> and greater than 0.

In order to avoid errors when manually editing these files, it is
recommended to use the appropriate tools, such as <html:code>authselect</html:code> or <html:code>authconfig</html:code>,
depending on the OS version.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">If the system relies on <html:code>authselect</html:code> tool to manage PAM settings, the remediation
will also use <html:code>authselect</html:code> tool. However, if any manual modification was made in
PAM files, the <html:code>authselect</html:code> integrity check will fail and the remediation will be
aborted in order to preserve intentional changes. In this case, an informative message will
be shown in the remediation report.
If the system supports the <html:code>/etc/security/faillock.conf</html:code> file, the pam_faillock
parameters should be defined in <html:code>faillock.conf</html:code> file.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_AFL.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000329-GPOS-00128</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000021-GPOS-00005</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R31</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020011</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230333r1017145_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>By limiting the number of failed logon attempts, the risk of unauthorized system access via
user password guessing, also known as brute-forcing, is reduced. Limits are imposed by locking
the account.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix id="accounts_passwords_pam_faillock_deny" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q pam; }; then

var_accounts_passwords_pam_faillock_deny='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" use="legacy"/>'


if [ -f /usr/bin/authselect ]; then
    if ! authselect check; then
echo "
authselect integrity check failed. Remediation aborted!
This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
It is not recommended to manually edit the PAM files when authselect tool is available.
In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
exit 1
fi
authselect enable-feature with-faillock

authselect apply-changes -b
else
    
AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
for pam_file in "${AUTH_FILES[@]}"
do
    if ! grep -qE '^\s*auth\s+required\s+pam_faillock\.so\s+(preauth silent|authfail).*$' "$pam_file" ; then
        sed -i --follow-symlinks '/^auth.*sufficient.*pam_unix\.so.*/i auth        required      pam_faillock.so preauth silent' "$pam_file"
        sed -i --follow-symlinks '/^auth.*required.*pam_deny\.so.*/i auth        required      pam_faillock.so authfail' "$pam_file"
        sed -i --follow-symlinks '/^account.*required.*pam_unix\.so.*/i account     required      pam_faillock.so' "$pam_file"
    fi
    sed -Ei 's/(auth.*)(\[default=die\])(.*pam_faillock\.so)/\1required     \3/g' "$pam_file"
done

fi

AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
SKIP_FAILLOCK_CHECK=false

FAILLOCK_CONF="/etc/security/faillock.conf"
if [ -f $FAILLOCK_CONF ] || [ "$SKIP_FAILLOCK_CHECK" = "true" ]; then
    regex="^\s*deny\s*="
    line="deny = $var_accounts_passwords_pam_faillock_deny"
    if ! grep -q $regex $FAILLOCK_CONF; then
        echo $line &gt;&gt; $FAILLOCK_CONF
    else
        sed -i --follow-symlinks 's|^\s*\(deny\s*=\s*\)\(\S\+\)|\1'"$var_accounts_passwords_pam_faillock_deny"'|g' $FAILLOCK_CONF
    fi
    
    for pam_file in "${AUTH_FILES[@]}"
    do
        if [ -e "$pam_file" ] ; then
            PAM_FILE_PATH="$pam_file"
            if [ -f /usr/bin/authselect ]; then
                
                if ! authselect check; then
                echo "
                authselect integrity check failed. Remediation aborted!
                This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
                It is not recommended to manually edit the PAM files when authselect tool is available.
                In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
                exit 1
                fi

                CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
                # If not already in use, a custom profile is created preserving the enabled features.
                if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                    ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                    # The "local" profile does not contain essential security features required by multiple Benchmarks.
                    # If currently used, it is replaced by "sssd", which is the best option in this case.
                    if [[ $CURRENT_PROFILE == local ]]; then
                        CURRENT_PROFILE="sssd"
                    fi
                    authselect create-profile hardening -b $CURRENT_PROFILE
                    CURRENT_PROFILE="custom/hardening"
                    
                    authselect apply-changes -b --backup=before-hardening-custom-profile
                    authselect select $CURRENT_PROFILE
                    for feature in $ENABLED_FEATURES; do
                        authselect enable-feature $feature;
                    done
                    
                    authselect apply-changes -b --backup=after-hardening-custom-profile
                fi
                PAM_FILE_NAME=$(basename "$pam_file")
                PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

                authselect apply-changes -b
            fi
            
        if grep -qP "^\s*auth\s.*\bpam_faillock.so\s.*\bdeny\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "s/(.*auth.*pam_faillock.so.*)\bdeny\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
        fi
            if [ -f /usr/bin/authselect ]; then
                
                authselect apply-changes -b
            fi
        else
            echo "$pam_file was not found" &gt;&amp;2
        fi
    done
    
else
    for pam_file in "${AUTH_FILES[@]}"
    do
        if ! grep -qE '^\s*auth.*pam_faillock\.so\s+(preauth|authfail).*deny' "$pam_file"; then
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*preauth.*/ s/$/ deny='"$var_accounts_passwords_pam_faillock_deny"'/' "$pam_file"
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*authfail.*/ s/$/ deny='"$var_accounts_passwords_pam_faillock_deny"'/' "$pam_file"
        else
            sed -i --follow-symlinks 's/\(^auth.*required.*pam_faillock\.so.*preauth.*\)\('"deny"'=\)\S\+\b\(.*\)/\1\2'"$var_accounts_passwords_pam_faillock_deny"'\3/' "$pam_file"
            sed -i --follow-symlinks 's/\(^auth.*required.*pam_faillock\.so.*authfail.*\)\('"deny"'=\)\S\+\b\(.*\)/\1\2'"$var_accounts_passwords_pam_faillock_deny"'\3/' "$pam_file"
        fi
    done
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_passwords_pam_faillock_deny" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020011
  - NIST-800-171-3.1.8
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.6
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - accounts_passwords_pam_faillock_deny
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Lock Accounts After Failed Password Attempts - Check if system relies on authselect
    tool
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020011
  - NIST-800-171-3.1.8
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.6
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - accounts_passwords_pam_faillock_deny
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Lock Accounts After Failed Password Attempts - Remediation where authselect
    tool is present
  block:

  - name: Lock Accounts After Failed Password Attempts - Check integrity of authselect
      current profile
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: Lock Accounts After Failed Password Attempts - Informative message based
      on the authselect integrity check result
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: Lock Accounts After Failed Password Attempts - Get authselect current features
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: Lock Accounts After Failed Password Attempts - Ensure "with-faillock" feature
      is enabled using authselect tool
    ansible.builtin.command:
      cmd: authselect enable-feature with-faillock
    register: result_authselect_enable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is not search("with-faillock")

  - name: Lock Accounts After Failed Password Attempts - Ensure authselect changes
      are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_enable_feature_cmd is not skipped
    - result_authselect_enable_feature_cmd is success
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020011
  - NIST-800-171-3.1.8
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.6
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - accounts_passwords_pam_faillock_deny
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Lock Accounts After Failed Password Attempts - Remediation where authselect
    tool is not present
  block:

  - name: Lock Accounts After Failed Password Attempts - Check if pam_faillock.so
      is already enabled
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail)
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_is_enabled

  - name: Lock Accounts After Failed Password Attempts - Enable pam_faillock.so preauth
      editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so preauth
      insertbefore: ^auth.*sufficient.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Lock Accounts After Failed Password Attempts - Enable pam_faillock.so authfail
      editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so authfail
      insertbefore: ^auth.*required.*pam_deny\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Lock Accounts After Failed Password Attempts - Enable pam_faillock.so account
      section editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: account     required      pam_faillock.so
      insertbefore: ^account.*required.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_authselect_present.stat.exists
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020011
  - NIST-800-171-3.1.8
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.6
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - accounts_passwords_pam_faillock_deny
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_accounts_passwords_pam_faillock_deny # promote to variable
  set_fact:
    var_accounts_passwords_pam_faillock_deny: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" use="legacy"/>
  tags:
    - always

- name: Lock Accounts After Failed Password Attempts - Check the presence of /etc/security/faillock.conf
    file
  ansible.builtin.stat:
    path: /etc/security/faillock.conf
  register: result_faillock_conf_check
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020011
  - NIST-800-171-3.1.8
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.6
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - accounts_passwords_pam_faillock_deny
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Lock Accounts After Failed Password Attempts - Ensure the pam_faillock.so
    deny parameter in /etc/security/faillock.conf
  ansible.builtin.lineinfile:
    path: /etc/security/faillock.conf
    regexp: ^\s*deny\s*=
    line: deny = {{ var_accounts_passwords_pam_faillock_deny }}
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020011
  - NIST-800-171-3.1.8
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.6
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - accounts_passwords_pam_faillock_deny
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Lock Accounts After Failed Password Attempts - Ensure the pam_faillock.so
    deny parameter not in PAM files
  block:

  - name: Lock Accounts After Failed Password Attempts - Check if /etc/pam.d/system-auth
      file is present
    ansible.builtin.stat:
      path: /etc/pam.d/system-auth
    register: result_pam_auth_file_present

  - name: Lock Accounts After Failed Password Attempts - Check the proper remediation
      for the system
    block:

    - name: Lock Accounts After Failed Password Attempts - Define the PAM file to
        be edited as a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/system-auth

    - name: Lock Accounts After Failed Password Attempts - Check if system relies
        on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Lock Accounts After Failed Password Attempts - Ensure authselect custom
        profile is used if authselect is present
      block:

      - name: Lock Accounts After Failed Password Attempts - Check integrity of authselect
          current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Lock Accounts After Failed Password Attempts - Informative message based
          on the authselect integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Lock Accounts After Failed Password Attempts - Get authselect current
          profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Lock Accounts After Failed Password Attempts - Define the current authselect
          profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Lock Accounts After Failed Password Attempts - Define the new authselect
          custom profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Lock Accounts After Failed Password Attempts - Get authselect current
          features to also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Lock Accounts After Failed Password Attempts - Check if any custom profile
          with the same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Lock Accounts After Failed Password Attempts - Create an authselect
          custom profile based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Lock Accounts After Failed Password Attempts - Create an authselect
          custom profile based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Lock Accounts After Failed Password Attempts - Ensure authselect changes
          are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Lock Accounts After Failed Password Attempts - Ensure the authselect
          custom profile is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Lock Accounts After Failed Password Attempts - Restore the authselect
          features in the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Lock Accounts After Failed Password Attempts - Ensure authselect changes
          are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Lock Accounts After Failed Password Attempts - Change the PAM file to
          be edited according to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Lock Accounts After Failed Password Attempts - Define a fact for control
        already filtered in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Lock Accounts After Failed Password Attempts - Check if {{ pam_file_path
        }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Lock Accounts After Failed Password Attempts - Ensure the "deny" option
        from "pam_faillock.so" is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\bdeny\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Lock Accounts After Failed Password Attempts - Ensure authselect changes
        are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_auth_file_present.stat.exists

  - name: Lock Accounts After Failed Password Attempts - Check if /etc/pam.d/password-auth
      file is present
    ansible.builtin.stat:
      path: /etc/pam.d/password-auth
    register: result_pam_password_auth_file_present

  - name: Lock Accounts After Failed Password Attempts - Check the proper remediation
      for the system
    block:

    - name: Lock Accounts After Failed Password Attempts - Define the PAM file to
        be edited as a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/password-auth

    - name: Lock Accounts After Failed Password Attempts - Check if system relies
        on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Lock Accounts After Failed Password Attempts - Ensure authselect custom
        profile is used if authselect is present
      block:

      - name: Lock Accounts After Failed Password Attempts - Check integrity of authselect
          current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Lock Accounts After Failed Password Attempts - Informative message based
          on the authselect integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Lock Accounts After Failed Password Attempts - Get authselect current
          profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Lock Accounts After Failed Password Attempts - Define the current authselect
          profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Lock Accounts After Failed Password Attempts - Define the new authselect
          custom profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Lock Accounts After Failed Password Attempts - Get authselect current
          features to also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Lock Accounts After Failed Password Attempts - Check if any custom profile
          with the same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Lock Accounts After Failed Password Attempts - Create an authselect
          custom profile based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Lock Accounts After Failed Password Attempts - Create an authselect
          custom profile based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Lock Accounts After Failed Password Attempts - Ensure authselect changes
          are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Lock Accounts After Failed Password Attempts - Ensure the authselect
          custom profile is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Lock Accounts After Failed Password Attempts - Restore the authselect
          features in the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Lock Accounts After Failed Password Attempts - Ensure authselect changes
          are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Lock Accounts After Failed Password Attempts - Change the PAM file to
          be edited according to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Lock Accounts After Failed Password Attempts - Define a fact for control
        already filtered in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Lock Accounts After Failed Password Attempts - Check if {{ pam_file_path
        }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Lock Accounts After Failed Password Attempts - Ensure the "deny" option
        from "pam_faillock.so" is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\bdeny\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Lock Accounts After Failed Password Attempts - Ensure authselect changes
        are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_password_auth_file_present.stat.exists
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020011
  - NIST-800-171-3.1.8
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.6
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - accounts_passwords_pam_faillock_deny
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Lock Accounts After Failed Password Attempts - Ensure the pam_faillock.so
    deny parameter in PAM files
  block:

  - name: Lock Accounts After Failed Password Attempts - Check if pam_faillock.so
      deny parameter is already enabled in pam files
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail).*deny
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_deny_parameter_is_present

  - name: Lock Accounts After Failed Password Attempts - Ensure the inclusion of pam_faillock.so
      preauth deny parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so preauth.*)
      line: \1required\3 deny={{ var_accounts_passwords_pam_faillock_deny }}
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_deny_parameter_is_present.found == 0

  - name: Lock Accounts After Failed Password Attempts - Ensure the inclusion of pam_faillock.so
      authfail deny parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so authfail.*)
      line: \1required\3 deny={{ var_accounts_passwords_pam_faillock_deny }}
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_deny_parameter_is_present.found == 0

  - name: Lock Accounts After Failed Password Attempts - Ensure the desired value
      for pam_faillock.so preauth deny parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so preauth.*)(deny)=[0-9]+(.*)
      line: \1required\3\4={{ var_accounts_passwords_pam_faillock_deny }}\5
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_deny_parameter_is_present.found &gt; 0

  - name: Lock Accounts After Failed Password Attempts - Ensure the desired value
      for pam_faillock.so authfail deny parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so authfail.*)(deny)=[0-9]+(.*)
      line: \1required\3\4={{ var_accounts_passwords_pam_faillock_deny }}\5
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_deny_parameter_is_present.found &gt; 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_faillock_conf_check.stat.exists
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020011
  - NIST-800-171-3.1.8
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.6
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - accounts_passwords_pam_faillock_deny
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_passwords_pam_faillock_deny:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_passwords_pam_faillock_deny:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_passwords_pam_faillock_deny_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny_root" selected="false" severity="medium">
                <xccdf-1.2:title>Configure the root Account for Failed Password Attempts</xccdf-1.2:title>
                <xccdf-1.2:description>This rule configures the system to lock out the <html:code>root</html:code> account after a number of
incorrect login attempts using <html:code>pam_faillock.so</html:code>.

pam_faillock.so module requires multiple entries in pam files. These entries must be carefully
defined to work as expected. In order to avoid errors when manually editing these files, it is
recommended to use the appropriate tools, such as <html:code>authselect</html:code> or <html:code>authconfig</html:code>,
depending on the OS version.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">If the system relies on <html:code>authselect</html:code> tool to manage PAM settings, the remediation
will also use <html:code>authselect</html:code> tool. However, if any manual modification was made in
PAM files, the <html:code>authselect</html:code> integrity check will fail and the remediation will be
aborted in order to preserve intentional changes. In this case, an informative message will
be shown in the remediation report.
If the system supports the <html:code>/etc/security/faillock.conf</html:code> file, the pam_faillock
parameters should be defined in <html:code>faillock.conf</html:code> file.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000329-GPOS-00128</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000021-GPOS-00005</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R31</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020023</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230345r1017157_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>By limiting the number of failed logon attempts, the risk of unauthorized system access via
user password guessing, also known as brute-forcing, is reduced. Limits are imposed by locking
the account.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#os_linux_rhel_gt_or_eq_8_2_and_package_pam"/>
                <xccdf-1.2:fix id="accounts_passwords_pam_faillock_deny_root" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { ( ( grep -qP "^ID=[\"']?rhel[\"']?$" "/etc/os-release" &amp;&amp; { real="$(grep -P "^VERSION_ID=[\"']?[\w.]+[\"']?$" /etc/os-release | sed "s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")"; expected="8.2"; printf "%s\n%s" "$expected" "$real" | sort -VC; } &amp;&amp; rpm --quiet -q pam ) ); }; then

if [ -f /usr/bin/authselect ]; then
    if ! authselect check; then
echo "
authselect integrity check failed. Remediation aborted!
This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
It is not recommended to manually edit the PAM files when authselect tool is available.
In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
exit 1
fi
authselect enable-feature with-faillock

authselect apply-changes -b
else
    
AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
for pam_file in "${AUTH_FILES[@]}"
do
    if ! grep -qE '^\s*auth\s+required\s+pam_faillock\.so\s+(preauth silent|authfail).*$' "$pam_file" ; then
        sed -i --follow-symlinks '/^auth.*sufficient.*pam_unix\.so.*/i auth        required      pam_faillock.so preauth silent' "$pam_file"
        sed -i --follow-symlinks '/^auth.*required.*pam_deny\.so.*/i auth        required      pam_faillock.so authfail' "$pam_file"
        sed -i --follow-symlinks '/^account.*required.*pam_unix\.so.*/i account     required      pam_faillock.so' "$pam_file"
    fi
    sed -Ei 's/(auth.*)(\[default=die\])(.*pam_faillock\.so)/\1required     \3/g' "$pam_file"
done

fi

AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
SKIP_FAILLOCK_CHECK=false

FAILLOCK_CONF="/etc/security/faillock.conf"
if [ -f $FAILLOCK_CONF ] || [ "$SKIP_FAILLOCK_CHECK" = "true" ]; then
    regex="^\s*even_deny_root"
    line="even_deny_root"
    if ! grep -q $regex $FAILLOCK_CONF; then
        echo $line &gt;&gt; $FAILLOCK_CONF
    fi
    
    for pam_file in "${AUTH_FILES[@]}"
    do
        if [ -e "$pam_file" ] ; then
            PAM_FILE_PATH="$pam_file"
            if [ -f /usr/bin/authselect ]; then
                
                if ! authselect check; then
                echo "
                authselect integrity check failed. Remediation aborted!
                This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
                It is not recommended to manually edit the PAM files when authselect tool is available.
                In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
                exit 1
                fi

                CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
                # If not already in use, a custom profile is created preserving the enabled features.
                if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                    ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                    # The "local" profile does not contain essential security features required by multiple Benchmarks.
                    # If currently used, it is replaced by "sssd", which is the best option in this case.
                    if [[ $CURRENT_PROFILE == local ]]; then
                        CURRENT_PROFILE="sssd"
                    fi
                    authselect create-profile hardening -b $CURRENT_PROFILE
                    CURRENT_PROFILE="custom/hardening"
                    
                    authselect apply-changes -b --backup=before-hardening-custom-profile
                    authselect select $CURRENT_PROFILE
                    for feature in $ENABLED_FEATURES; do
                        authselect enable-feature $feature;
                    done
                    
                    authselect apply-changes -b --backup=after-hardening-custom-profile
                fi
                PAM_FILE_NAME=$(basename "$pam_file")
                PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

                authselect apply-changes -b
            fi
            
        if grep -qP "^\s*auth\s.*\bpam_faillock.so\s.*\beven_deny_root\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "s/(.*auth.*pam_faillock.so.*)\beven_deny_root\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
        fi
            if [ -f /usr/bin/authselect ]; then
                
                authselect apply-changes -b
            fi
        else
            echo "$pam_file was not found" &gt;&amp;2
        fi
    done
    
else
    for pam_file in "${AUTH_FILES[@]}"
    do
        if ! grep -qE '^\s*auth.*pam_faillock\.so\s+(preauth|authfail).*even_deny_root' "$pam_file"; then
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*preauth.*/ s/$/ even_deny_root/' "$pam_file"
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*authfail.*/ s/$/ even_deny_root/' "$pam_file"
        fi
    done
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_passwords_pam_faillock_deny_root" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020023
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(c)
  - accounts_passwords_pam_faillock_deny_root
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure the root Account for Failed Password Attempts - Check if system
    relies on authselect tool
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.2',
    '&gt;=') and "pam" in ansible_facts.packages )
  tags:
  - DISA-STIG-RHEL-08-020023
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(c)
  - accounts_passwords_pam_faillock_deny_root
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure the root Account for Failed Password Attempts - Remediation where
    authselect tool is present
  block:

  - name: Configure the root Account for Failed Password Attempts - Check integrity
      of authselect current profile
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: Configure the root Account for Failed Password Attempts - Informative message
      based on the authselect integrity check result
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: Configure the root Account for Failed Password Attempts - Get authselect
      current features
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: Configure the root Account for Failed Password Attempts - Ensure "with-faillock"
      feature is enabled using authselect tool
    ansible.builtin.command:
      cmd: authselect enable-feature with-faillock
    register: result_authselect_enable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is not search("with-faillock")

  - name: Configure the root Account for Failed Password Attempts - Ensure authselect
      changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_enable_feature_cmd is not skipped
    - result_authselect_enable_feature_cmd is success
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.2',
    '&gt;=') and "pam" in ansible_facts.packages )
  - result_authselect_present.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020023
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(c)
  - accounts_passwords_pam_faillock_deny_root
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure the root Account for Failed Password Attempts - Remediation where
    authselect tool is not present
  block:

  - name: Configure the root Account for Failed Password Attempts - Check if pam_faillock.so
      is already enabled
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail)
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_is_enabled

  - name: Configure the root Account for Failed Password Attempts - Enable pam_faillock.so
      preauth editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so preauth
      insertbefore: ^auth.*sufficient.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Configure the root Account for Failed Password Attempts - Enable pam_faillock.so
      authfail editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so authfail
      insertbefore: ^auth.*required.*pam_deny\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Configure the root Account for Failed Password Attempts - Enable pam_faillock.so
      account section editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: account     required      pam_faillock.so
      insertbefore: ^account.*required.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.2',
    '&gt;=') and "pam" in ansible_facts.packages )
  - not result_authselect_present.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020023
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(c)
  - accounts_passwords_pam_faillock_deny_root
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure the root Account for Failed Password Attempts - Check the presence
    of /etc/security/faillock.conf file
  ansible.builtin.stat:
    path: /etc/security/faillock.conf
  register: result_faillock_conf_check
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.2',
    '&gt;=') and "pam" in ansible_facts.packages )
  tags:
  - DISA-STIG-RHEL-08-020023
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(c)
  - accounts_passwords_pam_faillock_deny_root
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure the root Account for Failed Password Attempts - Ensure the pam_faillock.so
    even_deny_root parameter in /etc/security/faillock.conf
  ansible.builtin.lineinfile:
    path: /etc/security/faillock.conf
    regexp: ^\s*even_deny_root
    line: even_deny_root
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.2',
    '&gt;=') and "pam" in ansible_facts.packages )
  - result_faillock_conf_check.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020023
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(c)
  - accounts_passwords_pam_faillock_deny_root
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure the root Account for Failed Password Attempts - Ensure the pam_faillock.so
    even_deny_root parameter not in PAM files
  block:

  - name: Configure the root Account for Failed Password Attempts - Check if /etc/pam.d/system-auth
      file is present
    ansible.builtin.stat:
      path: /etc/pam.d/system-auth
    register: result_pam_auth_file_present

  - name: Configure the root Account for Failed Password Attempts - Check the proper
      remediation for the system
    block:

    - name: Configure the root Account for Failed Password Attempts - Define the PAM
        file to be edited as a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/system-auth

    - name: Configure the root Account for Failed Password Attempts - Check if system
        relies on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Configure the root Account for Failed Password Attempts - Ensure authselect
        custom profile is used if authselect is present
      block:

      - name: Configure the root Account for Failed Password Attempts - Check integrity
          of authselect current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Configure the root Account for Failed Password Attempts - Informative
          message based on the authselect integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Configure the root Account for Failed Password Attempts - Get authselect
          current profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Configure the root Account for Failed Password Attempts - Define the
          current authselect profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Configure the root Account for Failed Password Attempts - Define the
          new authselect custom profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Configure the root Account for Failed Password Attempts - Get authselect
          current features to also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Configure the root Account for Failed Password Attempts - Check if any
          custom profile with the same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Configure the root Account for Failed Password Attempts - Create an
          authselect custom profile based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Configure the root Account for Failed Password Attempts - Create an
          authselect custom profile based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Configure the root Account for Failed Password Attempts - Ensure authselect
          changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Configure the root Account for Failed Password Attempts - Ensure the
          authselect custom profile is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Configure the root Account for Failed Password Attempts - Restore the
          authselect features in the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Configure the root Account for Failed Password Attempts - Ensure authselect
          changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Configure the root Account for Failed Password Attempts - Change the
          PAM file to be edited according to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Configure the root Account for Failed Password Attempts - Define a fact
        for control already filtered in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Configure the root Account for Failed Password Attempts - Check if {{
        pam_file_path }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Configure the root Account for Failed Password Attempts - Ensure the "even_deny_root"
        option from "pam_faillock.so" is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\beven_deny_root\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Configure the root Account for Failed Password Attempts - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_auth_file_present.stat.exists

  - name: Configure the root Account for Failed Password Attempts - Check if /etc/pam.d/password-auth
      file is present
    ansible.builtin.stat:
      path: /etc/pam.d/password-auth
    register: result_pam_password_auth_file_present

  - name: Configure the root Account for Failed Password Attempts - Check the proper
      remediation for the system
    block:

    - name: Configure the root Account for Failed Password Attempts - Define the PAM
        file to be edited as a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/password-auth

    - name: Configure the root Account for Failed Password Attempts - Check if system
        relies on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Configure the root Account for Failed Password Attempts - Ensure authselect
        custom profile is used if authselect is present
      block:

      - name: Configure the root Account for Failed Password Attempts - Check integrity
          of authselect current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Configure the root Account for Failed Password Attempts - Informative
          message based on the authselect integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Configure the root Account for Failed Password Attempts - Get authselect
          current profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Configure the root Account for Failed Password Attempts - Define the
          current authselect profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Configure the root Account for Failed Password Attempts - Define the
          new authselect custom profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Configure the root Account for Failed Password Attempts - Get authselect
          current features to also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Configure the root Account for Failed Password Attempts - Check if any
          custom profile with the same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Configure the root Account for Failed Password Attempts - Create an
          authselect custom profile based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Configure the root Account for Failed Password Attempts - Create an
          authselect custom profile based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Configure the root Account for Failed Password Attempts - Ensure authselect
          changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Configure the root Account for Failed Password Attempts - Ensure the
          authselect custom profile is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Configure the root Account for Failed Password Attempts - Restore the
          authselect features in the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Configure the root Account for Failed Password Attempts - Ensure authselect
          changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Configure the root Account for Failed Password Attempts - Change the
          PAM file to be edited according to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Configure the root Account for Failed Password Attempts - Define a fact
        for control already filtered in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Configure the root Account for Failed Password Attempts - Check if {{
        pam_file_path }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Configure the root Account for Failed Password Attempts - Ensure the "even_deny_root"
        option from "pam_faillock.so" is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\beven_deny_root\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Configure the root Account for Failed Password Attempts - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_password_auth_file_present.stat.exists
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.2',
    '&gt;=') and "pam" in ansible_facts.packages )
  - result_faillock_conf_check.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020023
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(c)
  - accounts_passwords_pam_faillock_deny_root
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure the root Account for Failed Password Attempts - Ensure the pam_faillock.so
    even_deny_root parameter in PAM files
  block:

  - name: Configure the root Account for Failed Password Attempts - Check if pam_faillock.so
      even_deny_root parameter is already enabled in pam files
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail).*even_deny_root
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_even_deny_root_parameter_is_present

  - name: Configure the root Account for Failed Password Attempts - Ensure the inclusion
      of pam_faillock.so preauth even_deny_root parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so preauth.*)
      line: \1required\3 even_deny_root
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_even_deny_root_parameter_is_present.found == 0

  - name: Configure the root Account for Failed Password Attempts - Ensure the inclusion
      of pam_faillock.so authfail even_deny_root parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so authfail.*)
      line: \1required\3 even_deny_root
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_even_deny_root_parameter_is_present.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.2',
    '&gt;=') and "pam" in ansible_facts.packages )
  - not result_faillock_conf_check.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020023
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(c)
  - accounts_passwords_pam_faillock_deny_root
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_passwords_pam_faillock_deny_root:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_passwords_pam_faillock_deny_root_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_dir" selected="false" severity="medium">
                <xccdf-1.2:title>Lock Accounts Must Persist</xccdf-1.2:title>
                <xccdf-1.2:description>This rule ensures that the system lock out accounts using <html:code>pam_faillock.so</html:code> persist
after system reboot. From "pam_faillock" man pages:
<html:pre>Note that the default directory that "pam_faillock" uses is usually cleared on system
boot so the access will be re-enabled after system reboot. If that is undesirable, a different
tally directory must be set with the "dir" option.</html:pre>

pam_faillock.so module requires multiple entries in pam files. These entries must be carefully
defined to work as expected. In order to avoid errors when manually editing these files, it is
recommended to use the appropriate tools, such as <html:code>authselect</html:code> or <html:code>authconfig</html:code>,
depending on the OS version.

The chosen profile expects the directory to be <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir" use="legacy"/></html:code>.

To configure the tally directory, add the following line to <html:code>/etc/security/faillock.conf</html:code>:
<html:pre>dir = <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir" use="legacy"/></html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">If the system relies on <html:code>authselect</html:code> tool to manage PAM settings, the remediation
will also use <html:code>authselect</html:code> tool. However, if any manual modification was made in
PAM files, the <html:code>authselect</html:code> integrity check will fail and the remediation will be
aborted in order to preserve intentional changes. In this case, an informative message will
be shown in the remediation report.
If the system supports the <html:code>/etc/security/faillock.conf</html:code> file, the pam_faillock
parameters should be defined in <html:code>faillock.conf</html:code> file.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-7.1(ii)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000021-GPOS-00005</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000329-GPOS-00128</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020016</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020017</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230338r1017150_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230339r1017151_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Locking out user accounts after a number of incorrect attempts prevents direct password
guessing attacks. In combination with the <html:code>silent</html:code> option, user enumeration attacks
are also mitigated.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_passwords_pam_faillock_dir" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q pam; }; then

var_accounts_passwords_pam_faillock_dir='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir" use="legacy"/>'


if [ -f /usr/bin/authselect ]; then
    if ! authselect check; then
echo "
authselect integrity check failed. Remediation aborted!
This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
It is not recommended to manually edit the PAM files when authselect tool is available.
In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
exit 1
fi
authselect enable-feature with-faillock

authselect apply-changes -b
else
    
AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
for pam_file in "${AUTH_FILES[@]}"
do
    if ! grep -qE '^\s*auth\s+required\s+pam_faillock\.so\s+(preauth silent|authfail).*$' "$pam_file" ; then
        sed -i --follow-symlinks '/^auth.*sufficient.*pam_unix\.so.*/i auth        required      pam_faillock.so preauth silent' "$pam_file"
        sed -i --follow-symlinks '/^auth.*required.*pam_deny\.so.*/i auth        required      pam_faillock.so authfail' "$pam_file"
        sed -i --follow-symlinks '/^account.*required.*pam_unix\.so.*/i account     required      pam_faillock.so' "$pam_file"
    fi
    sed -Ei 's/(auth.*)(\[default=die\])(.*pam_faillock\.so)/\1required     \3/g' "$pam_file"
done

fi

AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
SKIP_FAILLOCK_CHECK=false

FAILLOCK_CONF="/etc/security/faillock.conf"
if [ -f $FAILLOCK_CONF ] || [ "$SKIP_FAILLOCK_CHECK" = "true" ]; then
    regex="^\s*dir\s*="
    line="dir = $var_accounts_passwords_pam_faillock_dir"
    if ! grep -q $regex $FAILLOCK_CONF; then
        echo $line &gt;&gt; $FAILLOCK_CONF
    else
        sed -i --follow-symlinks 's|^\s*\(dir\s*=\s*\)\(\S\+\)|\1'"$var_accounts_passwords_pam_faillock_dir"'|g' $FAILLOCK_CONF
    fi
    
    for pam_file in "${AUTH_FILES[@]}"
    do
        if [ -e "$pam_file" ] ; then
            PAM_FILE_PATH="$pam_file"
            if [ -f /usr/bin/authselect ]; then
                
                if ! authselect check; then
                echo "
                authselect integrity check failed. Remediation aborted!
                This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
                It is not recommended to manually edit the PAM files when authselect tool is available.
                In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
                exit 1
                fi

                CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
                # If not already in use, a custom profile is created preserving the enabled features.
                if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                    ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                    # The "local" profile does not contain essential security features required by multiple Benchmarks.
                    # If currently used, it is replaced by "sssd", which is the best option in this case.
                    if [[ $CURRENT_PROFILE == local ]]; then
                        CURRENT_PROFILE="sssd"
                    fi
                    authselect create-profile hardening -b $CURRENT_PROFILE
                    CURRENT_PROFILE="custom/hardening"
                    
                    authselect apply-changes -b --backup=before-hardening-custom-profile
                    authselect select $CURRENT_PROFILE
                    for feature in $ENABLED_FEATURES; do
                        authselect enable-feature $feature;
                    done
                    
                    authselect apply-changes -b --backup=after-hardening-custom-profile
                fi
                PAM_FILE_NAME=$(basename "$pam_file")
                PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

                authselect apply-changes -b
            fi
            
        if grep -qP "^\s*auth\s.*\bpam_faillock.so\s.*\bdir\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "s/(.*auth.*pam_faillock.so.*)\bdir\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
        fi
            if [ -f /usr/bin/authselect ]; then
                
                authselect apply-changes -b
            fi
        else
            echo "$pam_file was not found" &gt;&amp;2
        fi
    done
    
else
    for pam_file in "${AUTH_FILES[@]}"
    do
        if ! grep -qE '^\s*auth.*pam_faillock\.so\s+(preauth|authfail).*dir' "$pam_file"; then
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*preauth.*/ s/$/ dir='"$var_accounts_passwords_pam_faillock_dir"'/' "$pam_file"
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*authfail.*/ s/$/ dir='"$var_accounts_passwords_pam_faillock_dir"'/' "$pam_file"
        else
            sed -i --follow-symlinks 's/\(^auth.*required.*pam_faillock\.so.*preauth.*\)\('"dir"'=\)\S\+\b\(.*\)/\1\2'"$var_accounts_passwords_pam_faillock_dir"'\3/' "$pam_file"
            sed -i --follow-symlinks 's/\(^auth.*required.*pam_faillock\.so.*authfail.*\)\('"dir"'=\)\S\+\b\(.*\)/\1\2'"$var_accounts_passwords_pam_faillock_dir"'\3/' "$pam_file"
        fi
    done
fi

if ! rpm -q --quiet "python3-libselinux" ; then
    yum install -y "python3-libselinux"
fi
if ! rpm -q --quiet "python3-policycoreutils" ; then
    yum install -y "python3-policycoreutils"
fi
if ! rpm -q --quiet "policycoreutils-python-utils" ; then
    yum install -y "policycoreutils-python-utils"
fi

mkdir -p "$var_accounts_passwords_pam_faillock_dir"
# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to semanage and restorecon commands to avoid the issue with the command
# not being found.
/usr/sbin/semanage fcontext -a -t faillog_t "$var_accounts_passwords_pam_faillock_dir(/.*)?"
/usr/sbin/restorecon -R -v "$var_accounts_passwords_pam_faillock_dir"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_passwords_pam_faillock_dir" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020016
  - DISA-STIG-RHEL-08-020017
  - NIST-800-53-AC-7(a)
  - NIST-800-53-AC-7(b)
  - NIST-800-53-AC-7.1(ii)
  - accounts_passwords_pam_faillock_dir
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Lock Accounts Must Persist - Check if system relies on authselect tool
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020016
  - DISA-STIG-RHEL-08-020017
  - NIST-800-53-AC-7(a)
  - NIST-800-53-AC-7(b)
  - NIST-800-53-AC-7.1(ii)
  - accounts_passwords_pam_faillock_dir
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Lock Accounts Must Persist - Remediation where authselect tool is present
  block:

  - name: Lock Accounts Must Persist - Check integrity of authselect current profile
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: Lock Accounts Must Persist - Informative message based on the authselect
      integrity check result
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: Lock Accounts Must Persist - Get authselect current features
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: Lock Accounts Must Persist - Ensure "with-faillock" feature is enabled using
      authselect tool
    ansible.builtin.command:
      cmd: authselect enable-feature with-faillock
    register: result_authselect_enable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is not search("with-faillock")

  - name: Lock Accounts Must Persist - Ensure authselect changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_enable_feature_cmd is not skipped
    - result_authselect_enable_feature_cmd is success
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020016
  - DISA-STIG-RHEL-08-020017
  - NIST-800-53-AC-7(a)
  - NIST-800-53-AC-7(b)
  - NIST-800-53-AC-7.1(ii)
  - accounts_passwords_pam_faillock_dir
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Lock Accounts Must Persist - Remediation where authselect tool is not present
  block:

  - name: Lock Accounts Must Persist - Check if pam_faillock.so is already enabled
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail)
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_is_enabled

  - name: Lock Accounts Must Persist - Enable pam_faillock.so preauth editing PAM
      files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so preauth
      insertbefore: ^auth.*sufficient.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Lock Accounts Must Persist - Enable pam_faillock.so authfail editing PAM
      files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so authfail
      insertbefore: ^auth.*required.*pam_deny\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Lock Accounts Must Persist - Enable pam_faillock.so account section editing
      PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: account     required      pam_faillock.so
      insertbefore: ^account.*required.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_authselect_present.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020016
  - DISA-STIG-RHEL-08-020017
  - NIST-800-53-AC-7(a)
  - NIST-800-53-AC-7(b)
  - NIST-800-53-AC-7.1(ii)
  - accounts_passwords_pam_faillock_dir
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
- name: XCCDF Value var_accounts_passwords_pam_faillock_dir # promote to variable
  set_fact:
    var_accounts_passwords_pam_faillock_dir: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir" use="legacy"/>
  tags:
    - always

- name: Lock Accounts Must Persist - Check the presence of /etc/security/faillock.conf
    file
  ansible.builtin.stat:
    path: /etc/security/faillock.conf
  register: result_faillock_conf_check
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020016
  - DISA-STIG-RHEL-08-020017
  - NIST-800-53-AC-7(a)
  - NIST-800-53-AC-7(b)
  - NIST-800-53-AC-7.1(ii)
  - accounts_passwords_pam_faillock_dir
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Lock Accounts Must Persist - Ensure the pam_faillock.so dir parameter in /etc/security/faillock.conf
  ansible.builtin.lineinfile:
    path: /etc/security/faillock.conf
    regexp: ^\s*dir\s*=
    line: dir = {{ var_accounts_passwords_pam_faillock_dir }}
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020016
  - DISA-STIG-RHEL-08-020017
  - NIST-800-53-AC-7(a)
  - NIST-800-53-AC-7(b)
  - NIST-800-53-AC-7.1(ii)
  - accounts_passwords_pam_faillock_dir
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Lock Accounts Must Persist - Ensure the pam_faillock.so dir parameter not
    in PAM files
  block:

  - name: Lock Accounts Must Persist - Check if /etc/pam.d/system-auth file is present
    ansible.builtin.stat:
      path: /etc/pam.d/system-auth
    register: result_pam_auth_file_present

  - name: Lock Accounts Must Persist - Check the proper remediation for the system
    block:

    - name: Lock Accounts Must Persist - Define the PAM file to be edited as a local
        fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/system-auth

    - name: Lock Accounts Must Persist - Check if system relies on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Lock Accounts Must Persist - Ensure authselect custom profile is used
        if authselect is present
      block:

      - name: Lock Accounts Must Persist - Check integrity of authselect current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Lock Accounts Must Persist - Informative message based on the authselect
          integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Lock Accounts Must Persist - Get authselect current profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Lock Accounts Must Persist - Define the current authselect profile as
          a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Lock Accounts Must Persist - Define the new authselect custom profile
          as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Lock Accounts Must Persist - Get authselect current features to also
          enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Lock Accounts Must Persist - Check if any custom profile with the same
          name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Lock Accounts Must Persist - Create an authselect custom profile based
          on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Lock Accounts Must Persist - Create an authselect custom profile based
          on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Lock Accounts Must Persist - Ensure authselect changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Lock Accounts Must Persist - Ensure the authselect custom profile is
          selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Lock Accounts Must Persist - Restore the authselect features in the
          custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Lock Accounts Must Persist - Ensure authselect changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Lock Accounts Must Persist - Change the PAM file to be edited according
          to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Lock Accounts Must Persist - Define a fact for control already filtered
        in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Lock Accounts Must Persist - Check if {{ pam_file_path }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Lock Accounts Must Persist - Ensure the "dir" option from "pam_faillock.so"
        is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\bdir\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Lock Accounts Must Persist - Ensure authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_auth_file_present.stat.exists

  - name: Lock Accounts Must Persist - Check if /etc/pam.d/password-auth file is present
    ansible.builtin.stat:
      path: /etc/pam.d/password-auth
    register: result_pam_password_auth_file_present

  - name: Lock Accounts Must Persist - Check the proper remediation for the system
    block:

    - name: Lock Accounts Must Persist - Define the PAM file to be edited as a local
        fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/password-auth

    - name: Lock Accounts Must Persist - Check if system relies on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Lock Accounts Must Persist - Ensure authselect custom profile is used
        if authselect is present
      block:

      - name: Lock Accounts Must Persist - Check integrity of authselect current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Lock Accounts Must Persist - Informative message based on the authselect
          integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Lock Accounts Must Persist - Get authselect current profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Lock Accounts Must Persist - Define the current authselect profile as
          a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Lock Accounts Must Persist - Define the new authselect custom profile
          as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Lock Accounts Must Persist - Get authselect current features to also
          enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Lock Accounts Must Persist - Check if any custom profile with the same
          name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Lock Accounts Must Persist - Create an authselect custom profile based
          on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Lock Accounts Must Persist - Create an authselect custom profile based
          on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Lock Accounts Must Persist - Ensure authselect changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Lock Accounts Must Persist - Ensure the authselect custom profile is
          selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Lock Accounts Must Persist - Restore the authselect features in the
          custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Lock Accounts Must Persist - Ensure authselect changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Lock Accounts Must Persist - Change the PAM file to be edited according
          to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Lock Accounts Must Persist - Define a fact for control already filtered
        in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Lock Accounts Must Persist - Check if {{ pam_file_path }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Lock Accounts Must Persist - Ensure the "dir" option from "pam_faillock.so"
        is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\bdir\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Lock Accounts Must Persist - Ensure authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_password_auth_file_present.stat.exists
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020016
  - DISA-STIG-RHEL-08-020017
  - NIST-800-53-AC-7(a)
  - NIST-800-53-AC-7(b)
  - NIST-800-53-AC-7.1(ii)
  - accounts_passwords_pam_faillock_dir
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Lock Accounts Must Persist - Ensure the pam_faillock.so dir parameter in PAM
    files
  block:

  - name: Lock Accounts Must Persist - Check if pam_faillock.so dir parameter is already
      enabled in pam files
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail).*dir
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_dir_parameter_is_present

  - name: Lock Accounts Must Persist - Ensure the inclusion of pam_faillock.so preauth
      dir parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so preauth.*)
      line: \1required\3 dir={{ var_accounts_passwords_pam_faillock_dir }}
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_dir_parameter_is_present.found == 0

  - name: Lock Accounts Must Persist - Ensure the inclusion of pam_faillock.so authfail
      dir parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so authfail.*)
      line: \1required\3 dir={{ var_accounts_passwords_pam_faillock_dir }}
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_dir_parameter_is_present.found == 0

  - name: Lock Accounts Must Persist - Ensure the desired value for pam_faillock.so
      preauth dir parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so preauth.*)(dir)=[0-9]+(.*)
      line: \1required\3\4={{ var_accounts_passwords_pam_faillock_dir }}\5
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_dir_parameter_is_present.found &gt; 0

  - name: Lock Accounts Must Persist - Ensure the desired value for pam_faillock.so
      authfail dir parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so authfail.*)(dir)=[0-9]+(.*)
      line: \1required\3\4={{ var_accounts_passwords_pam_faillock_dir }}\5
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_dir_parameter_is_present.found &gt; 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_faillock_conf_check.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020016
  - DISA-STIG-RHEL-08-020017
  - NIST-800-53-AC-7(a)
  - NIST-800-53-AC-7(b)
  - NIST-800-53-AC-7.1(ii)
  - accounts_passwords_pam_faillock_dir
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Lock Accounts Must Persist - Ensure necessary SELinux packages are installed
  ansible.builtin.package:
    name: '{{ item }}'
    state: present
  with_items:
  - python3-libselinux
  - python3-policycoreutils
  - policycoreutils-python-utils
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020016
  - DISA-STIG-RHEL-08-020017
  - NIST-800-53-AC-7(a)
  - NIST-800-53-AC-7(b)
  - NIST-800-53-AC-7.1(ii)
  - accounts_passwords_pam_faillock_dir
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Lock Accounts Must Persist - Create the faillock directory if it does not
    exist
  ansible.builtin.file:
    path: '{{ var_accounts_passwords_pam_faillock_dir }}'
    state: directory
    setype: faillog_t
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020016
  - DISA-STIG-RHEL-08-020017
  - NIST-800-53-AC-7(a)
  - NIST-800-53-AC-7(b)
  - NIST-800-53-AC-7.1(ii)
  - accounts_passwords_pam_faillock_dir
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Lock Accounts Must Persist - Get SELinux context for faillock directory
  ansible.builtin.command:
    cmd: ls -dZ {{ var_accounts_passwords_pam_faillock_dir }}
  register: faillock_selinux_context
  changed_when: false
  check_mode: false
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020016
  - DISA-STIG-RHEL-08-020017
  - NIST-800-53-AC-7(a)
  - NIST-800-53-AC-7(b)
  - NIST-800-53-AC-7.1(ii)
  - accounts_passwords_pam_faillock_dir
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Lock Accounts Must Persist - Ensure SELinux file context is permanently set
  ansible.builtin.command:
    cmd: semanage fcontext -a -t faillog_t "{{ var_accounts_passwords_pam_faillock_dir
      }}(/.*)?"
  register: result_accounts_passwords_pam_faillock_dir_semanage
  failed_when: false
  changed_when:
  - result_accounts_passwords_pam_faillock_dir_semanage.rc == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - '"faillog_t" not in faillock_selinux_context.stdout'
  tags:
  - DISA-STIG-RHEL-08-020016
  - DISA-STIG-RHEL-08-020017
  - NIST-800-53-AC-7(a)
  - NIST-800-53-AC-7(b)
  - NIST-800-53-AC-7.1(ii)
  - accounts_passwords_pam_faillock_dir
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Lock Accounts Must Persist - Ensure SELinux file context is applied
  ansible.builtin.command:
    cmd: restorecon -R "{{ var_accounts_passwords_pam_faillock_dir }}"
  register: result_accounts_passwords_pam_faillock_dir_restorecon
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - '"faillog_t" not in faillock_selinux_context.stdout'
  tags:
  - DISA-STIG-RHEL-08-020016
  - DISA-STIG-RHEL-08-020017
  - NIST-800-53-AC-7(a)
  - NIST-800-53-AC-7(b)
  - NIST-800-53-AC-7.1(ii)
  - accounts_passwords_pam_faillock_dir
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_passwords_pam_faillock_dir:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_passwords_pam_faillock_dir_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_enforce_local" selected="false" severity="medium">
                <xccdf-1.2:title>Enforce pam_faillock for Local Accounts Only</xccdf-1.2:title>
                <xccdf-1.2:description>The pam_faillock module's <html:code>local_users_only</html:code> parameter controls requirements for
enforcing failed lockout attempts only for local user accounts and ignoring centralized user
account management failed attempt configurations.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">If the system relies on <html:code>authselect</html:code> tool to manage PAM settings, the remediation
will also use <html:code>authselect</html:code> tool. However, if any manual modification was made in
PAM files, the <html:code>authselect</html:code> integrity check will fail and the remediation will be
aborted in order to preserve intentional changes. In this case, an informative message will
be shown in the remediation report.
If the system supports the <html:code>/etc/security/faillock.conf</html:code> file, the pam_faillock
parameters should be defined in <html:code>faillock.conf</html:code> file.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="management">Using this rule bypasses pam_faillock's functionality and should be used in cases
where centralized management such as LDAP or Active Directory is in use.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000001-GPOS-00001</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The operating system must provide automated mechanisms for supporting account management
functions. Enterprise environments make application account management challenging and
complex. A manual process for account management functions adds the risk of a potential
oversight or other error. Locking out remote accounts may cause unintentional DoS.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix id="accounts_passwords_pam_faillock_enforce_local" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q pam; }; then

if [ -f /usr/bin/authselect ]; then
    if ! authselect check; then
echo "
authselect integrity check failed. Remediation aborted!
This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
It is not recommended to manually edit the PAM files when authselect tool is available.
In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
exit 1
fi
authselect enable-feature with-faillock

authselect apply-changes -b
else
    
AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
for pam_file in "${AUTH_FILES[@]}"
do
    if ! grep -qE '^\s*auth\s+required\s+pam_faillock\.so\s+(preauth silent|authfail).*$' "$pam_file" ; then
        sed -i --follow-symlinks '/^auth.*sufficient.*pam_unix\.so.*/i auth        required      pam_faillock.so preauth silent' "$pam_file"
        sed -i --follow-symlinks '/^auth.*required.*pam_deny\.so.*/i auth        required      pam_faillock.so authfail' "$pam_file"
        sed -i --follow-symlinks '/^account.*required.*pam_unix\.so.*/i account     required      pam_faillock.so' "$pam_file"
    fi
    sed -Ei 's/(auth.*)(\[default=die\])(.*pam_faillock\.so)/\1required     \3/g' "$pam_file"
done

fi

AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
SKIP_FAILLOCK_CHECK=false

FAILLOCK_CONF="/etc/security/faillock.conf"
if [ -f $FAILLOCK_CONF ] || [ "$SKIP_FAILLOCK_CHECK" = "true" ]; then
    regex="^\s*local_users_only"
    line="local_users_only"
    if ! grep -q $regex $FAILLOCK_CONF; then
        echo $line &gt;&gt; $FAILLOCK_CONF
    fi
    
    for pam_file in "${AUTH_FILES[@]}"
    do
        if [ -e "$pam_file" ] ; then
            PAM_FILE_PATH="$pam_file"
            if [ -f /usr/bin/authselect ]; then
                
                if ! authselect check; then
                echo "
                authselect integrity check failed. Remediation aborted!
                This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
                It is not recommended to manually edit the PAM files when authselect tool is available.
                In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
                exit 1
                fi

                CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
                # If not already in use, a custom profile is created preserving the enabled features.
                if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                    ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                    # The "local" profile does not contain essential security features required by multiple Benchmarks.
                    # If currently used, it is replaced by "sssd", which is the best option in this case.
                    if [[ $CURRENT_PROFILE == local ]]; then
                        CURRENT_PROFILE="sssd"
                    fi
                    authselect create-profile hardening -b $CURRENT_PROFILE
                    CURRENT_PROFILE="custom/hardening"
                    
                    authselect apply-changes -b --backup=before-hardening-custom-profile
                    authselect select $CURRENT_PROFILE
                    for feature in $ENABLED_FEATURES; do
                        authselect enable-feature $feature;
                    done
                    
                    authselect apply-changes -b --backup=after-hardening-custom-profile
                fi
                PAM_FILE_NAME=$(basename "$pam_file")
                PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

                authselect apply-changes -b
            fi
            
        if grep -qP "^\s*auth\s.*\bpam_faillock.so\s.*\blocal_users_only\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "s/(.*auth.*pam_faillock.so.*)\blocal_users_only\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
        fi
            if [ -f /usr/bin/authselect ]; then
                
                authselect apply-changes -b
            fi
        else
            echo "$pam_file was not found" &gt;&amp;2
        fi
    done
    
else
    for pam_file in "${AUTH_FILES[@]}"
    do
        if ! grep -qE '^\s*auth.*pam_faillock\.so\s+(preauth|authfail).*local_users_only' "$pam_file"; then
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*preauth.*/ s/$/ local_users_only/' "$pam_file"
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*authfail.*/ s/$/ local_users_only/' "$pam_file"
        fi
    done
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_passwords_pam_faillock_enforce_local" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-2(1)
  - accounts_passwords_pam_faillock_enforce_local
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Enforce pam_faillock for Local Accounts Only - Check if system relies on authselect
    tool
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-2(1)
  - accounts_passwords_pam_faillock_enforce_local
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Enforce pam_faillock for Local Accounts Only - Remediation where authselect
    tool is present
  block:

  - name: Enforce pam_faillock for Local Accounts Only - Check integrity of authselect
      current profile
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: Enforce pam_faillock for Local Accounts Only - Informative message based
      on the authselect integrity check result
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: Enforce pam_faillock for Local Accounts Only - Get authselect current features
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: Enforce pam_faillock for Local Accounts Only - Ensure "with-faillock" feature
      is enabled using authselect tool
    ansible.builtin.command:
      cmd: authselect enable-feature with-faillock
    register: result_authselect_enable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is not search("with-faillock")

  - name: Enforce pam_faillock for Local Accounts Only - Ensure authselect changes
      are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_enable_feature_cmd is not skipped
    - result_authselect_enable_feature_cmd is success
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  tags:
  - NIST-800-53-AC-2(1)
  - accounts_passwords_pam_faillock_enforce_local
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Enforce pam_faillock for Local Accounts Only - Remediation where authselect
    tool is not present
  block:

  - name: Enforce pam_faillock for Local Accounts Only - Check if pam_faillock.so
      is already enabled
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail)
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_is_enabled

  - name: Enforce pam_faillock for Local Accounts Only - Enable pam_faillock.so preauth
      editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so preauth
      insertbefore: ^auth.*sufficient.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Enforce pam_faillock for Local Accounts Only - Enable pam_faillock.so authfail
      editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so authfail
      insertbefore: ^auth.*required.*pam_deny\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Enforce pam_faillock for Local Accounts Only - Enable pam_faillock.so account
      section editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: account     required      pam_faillock.so
      insertbefore: ^account.*required.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_authselect_present.stat.exists
  tags:
  - NIST-800-53-AC-2(1)
  - accounts_passwords_pam_faillock_enforce_local
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Enforce pam_faillock for Local Accounts Only - Check the presence of /etc/security/faillock.conf
    file
  ansible.builtin.stat:
    path: /etc/security/faillock.conf
  register: result_faillock_conf_check
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-2(1)
  - accounts_passwords_pam_faillock_enforce_local
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Enforce pam_faillock for Local Accounts Only - Ensure the pam_faillock.so
    local_users_only parameter in /etc/security/faillock.conf
  ansible.builtin.lineinfile:
    path: /etc/security/faillock.conf
    regexp: ^\s*local_users_only
    line: local_users_only
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - NIST-800-53-AC-2(1)
  - accounts_passwords_pam_faillock_enforce_local
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Enforce pam_faillock for Local Accounts Only - Ensure the pam_faillock.so
    local_users_only parameter not in PAM files
  block:

  - name: Enforce pam_faillock for Local Accounts Only - Check if /etc/pam.d/system-auth
      file is present
    ansible.builtin.stat:
      path: /etc/pam.d/system-auth
    register: result_pam_auth_file_present

  - name: Enforce pam_faillock for Local Accounts Only - Check the proper remediation
      for the system
    block:

    - name: Enforce pam_faillock for Local Accounts Only - Define the PAM file to
        be edited as a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/system-auth

    - name: Enforce pam_faillock for Local Accounts Only - Check if system relies
        on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Enforce pam_faillock for Local Accounts Only - Ensure authselect custom
        profile is used if authselect is present
      block:

      - name: Enforce pam_faillock for Local Accounts Only - Check integrity of authselect
          current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Enforce pam_faillock for Local Accounts Only - Informative message based
          on the authselect integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Enforce pam_faillock for Local Accounts Only - Get authselect current
          profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Enforce pam_faillock for Local Accounts Only - Define the current authselect
          profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Enforce pam_faillock for Local Accounts Only - Define the new authselect
          custom profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Enforce pam_faillock for Local Accounts Only - Get authselect current
          features to also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Enforce pam_faillock for Local Accounts Only - Check if any custom profile
          with the same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Enforce pam_faillock for Local Accounts Only - Create an authselect
          custom profile based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Enforce pam_faillock for Local Accounts Only - Create an authselect
          custom profile based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Enforce pam_faillock for Local Accounts Only - Ensure authselect changes
          are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Enforce pam_faillock for Local Accounts Only - Ensure the authselect
          custom profile is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Enforce pam_faillock for Local Accounts Only - Restore the authselect
          features in the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Enforce pam_faillock for Local Accounts Only - Ensure authselect changes
          are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Enforce pam_faillock for Local Accounts Only - Change the PAM file to
          be edited according to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Enforce pam_faillock for Local Accounts Only - Define a fact for control
        already filtered in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Enforce pam_faillock for Local Accounts Only - Check if {{ pam_file_path
        }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Enforce pam_faillock for Local Accounts Only - Ensure the "local_users_only"
        option from "pam_faillock.so" is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\blocal_users_only\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Enforce pam_faillock for Local Accounts Only - Ensure authselect changes
        are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_auth_file_present.stat.exists

  - name: Enforce pam_faillock for Local Accounts Only - Check if /etc/pam.d/password-auth
      file is present
    ansible.builtin.stat:
      path: /etc/pam.d/password-auth
    register: result_pam_password_auth_file_present

  - name: Enforce pam_faillock for Local Accounts Only - Check the proper remediation
      for the system
    block:

    - name: Enforce pam_faillock for Local Accounts Only - Define the PAM file to
        be edited as a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/password-auth

    - name: Enforce pam_faillock for Local Accounts Only - Check if system relies
        on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Enforce pam_faillock for Local Accounts Only - Ensure authselect custom
        profile is used if authselect is present
      block:

      - name: Enforce pam_faillock for Local Accounts Only - Check integrity of authselect
          current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Enforce pam_faillock for Local Accounts Only - Informative message based
          on the authselect integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Enforce pam_faillock for Local Accounts Only - Get authselect current
          profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Enforce pam_faillock for Local Accounts Only - Define the current authselect
          profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Enforce pam_faillock for Local Accounts Only - Define the new authselect
          custom profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Enforce pam_faillock for Local Accounts Only - Get authselect current
          features to also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Enforce pam_faillock for Local Accounts Only - Check if any custom profile
          with the same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Enforce pam_faillock for Local Accounts Only - Create an authselect
          custom profile based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Enforce pam_faillock for Local Accounts Only - Create an authselect
          custom profile based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Enforce pam_faillock for Local Accounts Only - Ensure authselect changes
          are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Enforce pam_faillock for Local Accounts Only - Ensure the authselect
          custom profile is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Enforce pam_faillock for Local Accounts Only - Restore the authselect
          features in the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Enforce pam_faillock for Local Accounts Only - Ensure authselect changes
          are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Enforce pam_faillock for Local Accounts Only - Change the PAM file to
          be edited according to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Enforce pam_faillock for Local Accounts Only - Define a fact for control
        already filtered in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Enforce pam_faillock for Local Accounts Only - Check if {{ pam_file_path
        }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Enforce pam_faillock for Local Accounts Only - Ensure the "local_users_only"
        option from "pam_faillock.so" is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\blocal_users_only\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Enforce pam_faillock for Local Accounts Only - Ensure authselect changes
        are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_password_auth_file_present.stat.exists
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - NIST-800-53-AC-2(1)
  - accounts_passwords_pam_faillock_enforce_local
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Enforce pam_faillock for Local Accounts Only - Ensure the pam_faillock.so
    local_users_only parameter in PAM files
  block:

  - name: Enforce pam_faillock for Local Accounts Only - Check if pam_faillock.so
      local_users_only parameter is already enabled in pam files
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail).*local_users_only
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_local_users_only_parameter_is_present

  - name: Enforce pam_faillock for Local Accounts Only - Ensure the inclusion of pam_faillock.so
      preauth local_users_only parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so preauth.*)
      line: \1required\3 local_users_only
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_local_users_only_parameter_is_present.found == 0

  - name: Enforce pam_faillock for Local Accounts Only - Ensure the inclusion of pam_faillock.so
      authfail local_users_only parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so authfail.*)
      line: \1required\3 local_users_only
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_local_users_only_parameter_is_present.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_faillock_conf_check.stat.exists
  tags:
  - NIST-800-53-AC-2(1)
  - accounts_passwords_pam_faillock_enforce_local
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_passwords_pam_faillock_enforce_local:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_passwords_pam_faillock_enforce_local_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure Root Account Lockout on Failed Password Attempts</xccdf-1.2:title>
                <xccdf-1.2:description>This rule configures the system to include the <html:code>root</html:code> account in the account lockout policy using <html:code>pam_faillock.so</html:code>. The system must have either the <html:code>even_deny_root</html:code> option enabled or <html:code>root_unlock_time</html:code> set to <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_root_unlock_time" use="legacy"/></html:code> seconds or greater in <html:code>/etc/security/faillock.conf</html:code>.
pam_faillock.so module requires multiple entries in pam files. These entries must be carefully defined to work as expected. In order to avoid errors when manually editing these files, it is recommended to use the appropriate tools, such as <html:code>authselect</html:code> or <html:code>authconfig</html:code>, depending on the OS version.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">If the system relies on <html:code>authselect</html:code> tool to manage PAM settings, the remediation will also use <html:code>authselect</html:code> tool. However, if any manual modification was made in PAM files, the <html:code>authselect</html:code> integrity check will fail and the remediation will be aborted in order to preserve intentional changes. In this case, an informative message will be shown in the remediation report. If the system supports the <html:code>/etc/security/faillock.conf</html:code> file, the pam_faillock parameters should be defined in <html:code>faillock.conf</html:code> file.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.1.3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>By limiting the number of failed logon attempts, the risk of unauthorized system access via user password guessing, also known as brute-forcing, is reduced. Limits are imposed by locking the account.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix id="accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q pam; }; then

if [ -f /usr/bin/authselect ]; then
    if ! authselect check; then
echo "
authselect integrity check failed. Remediation aborted!
This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
It is not recommended to manually edit the PAM files when authselect tool is available.
In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
exit 1
fi
authselect enable-feature with-faillock

authselect apply-changes -b
else
    
AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
for pam_file in "${AUTH_FILES[@]}"
do
    if ! grep -qE '^\s*auth\s+required\s+pam_faillock\.so\s+(preauth silent|authfail).*$' "$pam_file" ; then
        sed -i --follow-symlinks '/^auth.*sufficient.*pam_unix\.so.*/i auth        required      pam_faillock.so preauth silent' "$pam_file"
        sed -i --follow-symlinks '/^auth.*required.*pam_deny\.so.*/i auth        required      pam_faillock.so authfail' "$pam_file"
        sed -i --follow-symlinks '/^account.*required.*pam_unix\.so.*/i account     required      pam_faillock.so' "$pam_file"
    fi
    sed -Ei 's/(auth.*)(\[default=die\])(.*pam_faillock\.so)/\1required     \3/g' "$pam_file"
done

fi

AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
SKIP_FAILLOCK_CHECK=false

FAILLOCK_CONF="/etc/security/faillock.conf"
if [ -f $FAILLOCK_CONF ] || [ "$SKIP_FAILLOCK_CHECK" = "true" ]; then
    regex="^\s*even_deny_root"
    line="even_deny_root"
    if ! grep -q $regex $FAILLOCK_CONF; then
        echo $line &gt;&gt; $FAILLOCK_CONF
    fi
    
    for pam_file in "${AUTH_FILES[@]}"
    do
        if [ -e "$pam_file" ] ; then
            PAM_FILE_PATH="$pam_file"
            if [ -f /usr/bin/authselect ]; then
                
                if ! authselect check; then
                echo "
                authselect integrity check failed. Remediation aborted!
                This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
                It is not recommended to manually edit the PAM files when authselect tool is available.
                In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
                exit 1
                fi

                CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
                # If not already in use, a custom profile is created preserving the enabled features.
                if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                    ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                    # The "local" profile does not contain essential security features required by multiple Benchmarks.
                    # If currently used, it is replaced by "sssd", which is the best option in this case.
                    if [[ $CURRENT_PROFILE == local ]]; then
                        CURRENT_PROFILE="sssd"
                    fi
                    authselect create-profile hardening -b $CURRENT_PROFILE
                    CURRENT_PROFILE="custom/hardening"
                    
                    authselect apply-changes -b --backup=before-hardening-custom-profile
                    authselect select $CURRENT_PROFILE
                    for feature in $ENABLED_FEATURES; do
                        authselect enable-feature $feature;
                    done
                    
                    authselect apply-changes -b --backup=after-hardening-custom-profile
                fi
                PAM_FILE_NAME=$(basename "$pam_file")
                PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

                authselect apply-changes -b
            fi
            
        if grep -qP "^\s*auth\s.*\bpam_faillock.so\s.*\beven_deny_root\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "s/(.*auth.*pam_faillock.so.*)\beven_deny_root\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
        fi
            if [ -f /usr/bin/authselect ]; then
                
                authselect apply-changes -b
            fi
        else
            echo "$pam_file was not found" &gt;&amp;2
        fi
    done
    
else
    for pam_file in "${AUTH_FILES[@]}"
    do
        if ! grep -qE '^\s*auth.*pam_faillock\.so\s+(preauth|authfail).*even_deny_root' "$pam_file"; then
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*preauth.*/ s/$/ even_deny_root/' "$pam_file"
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*authfail.*/ s/$/ even_deny_root/' "$pam_file"
        fi
    done
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Root Account Lockout on Failed Password Attempts - Check if system
    relies on authselect tool
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Root Account Lockout on Failed Password Attempts - Remediation where
    authselect tool is present
  block:

  - name: Ensure Root Account Lockout on Failed Password Attempts - Check integrity
      of authselect current profile
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: Ensure Root Account Lockout on Failed Password Attempts - Informative message
      based on the authselect integrity check result
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: Ensure Root Account Lockout on Failed Password Attempts - Get authselect
      current features
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: Ensure Root Account Lockout on Failed Password Attempts - Ensure "with-faillock"
      feature is enabled using authselect tool
    ansible.builtin.command:
      cmd: authselect enable-feature with-faillock
    register: result_authselect_enable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is not search("with-faillock")

  - name: Ensure Root Account Lockout on Failed Password Attempts - Ensure authselect
      changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_enable_feature_cmd is not skipped
    - result_authselect_enable_feature_cmd is success
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  tags:
  - accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Root Account Lockout on Failed Password Attempts - Remediation where
    authselect tool is not present
  block:

  - name: Ensure Root Account Lockout on Failed Password Attempts - Check if pam_faillock.so
      is already enabled
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail)
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_is_enabled

  - name: Ensure Root Account Lockout on Failed Password Attempts - Enable pam_faillock.so
      preauth editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so preauth
      insertbefore: ^auth.*sufficient.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Ensure Root Account Lockout on Failed Password Attempts - Enable pam_faillock.so
      authfail editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so authfail
      insertbefore: ^auth.*required.*pam_deny\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Ensure Root Account Lockout on Failed Password Attempts - Enable pam_faillock.so
      account section editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: account     required      pam_faillock.so
      insertbefore: ^account.*required.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_authselect_present.stat.exists
  tags:
  - accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Root Account Lockout on Failed Password Attempts - Check the presence
    of /etc/security/faillock.conf file
  ansible.builtin.stat:
    path: /etc/security/faillock.conf
  register: result_faillock_conf_check
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Root Account Lockout on Failed Password Attempts - Ensure the pam_faillock.so
    even_deny_root parameter in /etc/security/faillock.conf
  ansible.builtin.lineinfile:
    path: /etc/security/faillock.conf
    regexp: ^\s*even_deny_root
    line: even_deny_root
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Root Account Lockout on Failed Password Attempts - Ensure the pam_faillock.so
    even_deny_root parameter not in PAM files
  block:

  - name: Ensure Root Account Lockout on Failed Password Attempts - Check if /etc/pam.d/system-auth
      file is present
    ansible.builtin.stat:
      path: /etc/pam.d/system-auth
    register: result_pam_auth_file_present

  - name: Ensure Root Account Lockout on Failed Password Attempts - Check the proper
      remediation for the system
    block:

    - name: Ensure Root Account Lockout on Failed Password Attempts - Define the PAM
        file to be edited as a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/system-auth

    - name: Ensure Root Account Lockout on Failed Password Attempts - Check if system
        relies on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Ensure Root Account Lockout on Failed Password Attempts - Ensure authselect
        custom profile is used if authselect is present
      block:

      - name: Ensure Root Account Lockout on Failed Password Attempts - Check integrity
          of authselect current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Ensure Root Account Lockout on Failed Password Attempts - Informative
          message based on the authselect integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Ensure Root Account Lockout on Failed Password Attempts - Get authselect
          current profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Ensure Root Account Lockout on Failed Password Attempts - Define the
          current authselect profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Ensure Root Account Lockout on Failed Password Attempts - Define the
          new authselect custom profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Ensure Root Account Lockout on Failed Password Attempts - Get authselect
          current features to also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Ensure Root Account Lockout on Failed Password Attempts - Check if any
          custom profile with the same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Ensure Root Account Lockout on Failed Password Attempts - Create an
          authselect custom profile based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Ensure Root Account Lockout on Failed Password Attempts - Create an
          authselect custom profile based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Ensure Root Account Lockout on Failed Password Attempts - Ensure authselect
          changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Ensure Root Account Lockout on Failed Password Attempts - Ensure the
          authselect custom profile is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Ensure Root Account Lockout on Failed Password Attempts - Restore the
          authselect features in the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Ensure Root Account Lockout on Failed Password Attempts - Ensure authselect
          changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Ensure Root Account Lockout on Failed Password Attempts - Change the
          PAM file to be edited according to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Ensure Root Account Lockout on Failed Password Attempts - Define a fact
        for control already filtered in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Ensure Root Account Lockout on Failed Password Attempts - Check if {{
        pam_file_path }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Ensure Root Account Lockout on Failed Password Attempts - Ensure the "even_deny_root"
        option from "pam_faillock.so" is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\beven_deny_root\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Ensure Root Account Lockout on Failed Password Attempts - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_auth_file_present.stat.exists

  - name: Ensure Root Account Lockout on Failed Password Attempts - Check if /etc/pam.d/password-auth
      file is present
    ansible.builtin.stat:
      path: /etc/pam.d/password-auth
    register: result_pam_password_auth_file_present

  - name: Ensure Root Account Lockout on Failed Password Attempts - Check the proper
      remediation for the system
    block:

    - name: Ensure Root Account Lockout on Failed Password Attempts - Define the PAM
        file to be edited as a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/password-auth

    - name: Ensure Root Account Lockout on Failed Password Attempts - Check if system
        relies on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Ensure Root Account Lockout on Failed Password Attempts - Ensure authselect
        custom profile is used if authselect is present
      block:

      - name: Ensure Root Account Lockout on Failed Password Attempts - Check integrity
          of authselect current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Ensure Root Account Lockout on Failed Password Attempts - Informative
          message based on the authselect integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Ensure Root Account Lockout on Failed Password Attempts - Get authselect
          current profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Ensure Root Account Lockout on Failed Password Attempts - Define the
          current authselect profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Ensure Root Account Lockout on Failed Password Attempts - Define the
          new authselect custom profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Ensure Root Account Lockout on Failed Password Attempts - Get authselect
          current features to also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Ensure Root Account Lockout on Failed Password Attempts - Check if any
          custom profile with the same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Ensure Root Account Lockout on Failed Password Attempts - Create an
          authselect custom profile based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Ensure Root Account Lockout on Failed Password Attempts - Create an
          authselect custom profile based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Ensure Root Account Lockout on Failed Password Attempts - Ensure authselect
          changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Ensure Root Account Lockout on Failed Password Attempts - Ensure the
          authselect custom profile is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Ensure Root Account Lockout on Failed Password Attempts - Restore the
          authselect features in the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Ensure Root Account Lockout on Failed Password Attempts - Ensure authselect
          changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Ensure Root Account Lockout on Failed Password Attempts - Change the
          PAM file to be edited according to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Ensure Root Account Lockout on Failed Password Attempts - Define a fact
        for control already filtered in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Ensure Root Account Lockout on Failed Password Attempts - Check if {{
        pam_file_path }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Ensure Root Account Lockout on Failed Password Attempts - Ensure the "even_deny_root"
        option from "pam_faillock.so" is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\beven_deny_root\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Ensure Root Account Lockout on Failed Password Attempts - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_password_auth_file_present.stat.exists
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure Root Account Lockout on Failed Password Attempts - Ensure the pam_faillock.so
    even_deny_root parameter in PAM files
  block:

  - name: Ensure Root Account Lockout on Failed Password Attempts - Check if pam_faillock.so
      even_deny_root parameter is already enabled in pam files
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail).*even_deny_root
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_even_deny_root_parameter_is_present

  - name: Ensure Root Account Lockout on Failed Password Attempts - Ensure the inclusion
      of pam_faillock.so preauth even_deny_root parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so preauth.*)
      line: \1required\3 even_deny_root
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_even_deny_root_parameter_is_present.found == 0

  - name: Ensure Root Account Lockout on Failed Password Attempts - Ensure the inclusion
      of pam_faillock.so authfail even_deny_root parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so authfail.*)
      line: \1required\3 even_deny_root
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_even_deny_root_parameter_is_present.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_faillock_conf_check.stat.exists
  tags:
  - accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_passwords_pam_faillock_root_unlock_time:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_root_unlock_time"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_interval" selected="false" severity="medium">
                <xccdf-1.2:title>Set Interval For Counting Failed Password Attempts</xccdf-1.2:title>
                <xccdf-1.2:description>Utilizing <html:code>pam_faillock.so</html:code>, the <html:code>fail_interval</html:code> directive configures the system
to lock out an account after a number of incorrect login attempts within a specified time
period.

Ensure that the file <html:code>/etc/security/faillock.conf</html:code> contains the following entry:
<html:code>fail_interval = &lt;interval-in-seconds&gt;</html:code> where <html:code>interval-in-seconds</html:code> is <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_fail_interval" use="legacy"/></html:code> or greater.


In order to avoid errors when manually editing these files, it is
recommended to use the appropriate tools, such as <html:code>authselect</html:code> or <html:code>authconfig</html:code>,
depending on the OS version.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">If the system relies on <html:code>authselect</html:code> tool to manage PAM settings, the remediation
will also use <html:code>authselect</html:code> tool. However, if any manual modification was made in
PAM files, the <html:code>authselect</html:code> integrity check will fail and the remediation will be
aborted in order to preserve intentional changes. In this case, an informative message will
be shown in the remediation report.
If the system supports the <html:code>/etc/security/faillock.conf</html:code> file, the pam_faillock
parameters should be defined in <html:code>faillock.conf</html:code> file.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_AFL.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000329-GPOS-00128</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000021-GPOS-00005</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R31</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020012</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020013</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230334r1017146_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230335r1017147_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>By limiting the number of failed logon attempts the risk of unauthorized system
access via user password guessing, otherwise known as brute-forcing, is reduced.
Limits are imposed by locking the account.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix id="accounts_passwords_pam_faillock_interval" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q pam; }; then

var_accounts_passwords_pam_faillock_fail_interval='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_fail_interval" use="legacy"/>'


if [ -f /usr/bin/authselect ]; then
    if ! authselect check; then
echo "
authselect integrity check failed. Remediation aborted!
This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
It is not recommended to manually edit the PAM files when authselect tool is available.
In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
exit 1
fi
authselect enable-feature with-faillock

authselect apply-changes -b
else
    
AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
for pam_file in "${AUTH_FILES[@]}"
do
    if ! grep -qE '^\s*auth\s+required\s+pam_faillock\.so\s+(preauth silent|authfail).*$' "$pam_file" ; then
        sed -i --follow-symlinks '/^auth.*sufficient.*pam_unix\.so.*/i auth        required      pam_faillock.so preauth silent' "$pam_file"
        sed -i --follow-symlinks '/^auth.*required.*pam_deny\.so.*/i auth        required      pam_faillock.so authfail' "$pam_file"
        sed -i --follow-symlinks '/^account.*required.*pam_unix\.so.*/i account     required      pam_faillock.so' "$pam_file"
    fi
    sed -Ei 's/(auth.*)(\[default=die\])(.*pam_faillock\.so)/\1required     \3/g' "$pam_file"
done

fi

AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
SKIP_FAILLOCK_CHECK=false

FAILLOCK_CONF="/etc/security/faillock.conf"
if [ -f $FAILLOCK_CONF ] || [ "$SKIP_FAILLOCK_CHECK" = "true" ]; then
    regex="^\s*fail_interval\s*="
    line="fail_interval = $var_accounts_passwords_pam_faillock_fail_interval"
    if ! grep -q $regex $FAILLOCK_CONF; then
        echo $line &gt;&gt; $FAILLOCK_CONF
    else
        sed -i --follow-symlinks 's|^\s*\(fail_interval\s*=\s*\)\(\S\+\)|\1'"$var_accounts_passwords_pam_faillock_fail_interval"'|g' $FAILLOCK_CONF
    fi
    
    for pam_file in "${AUTH_FILES[@]}"
    do
        if [ -e "$pam_file" ] ; then
            PAM_FILE_PATH="$pam_file"
            if [ -f /usr/bin/authselect ]; then
                
                if ! authselect check; then
                echo "
                authselect integrity check failed. Remediation aborted!
                This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
                It is not recommended to manually edit the PAM files when authselect tool is available.
                In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
                exit 1
                fi

                CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
                # If not already in use, a custom profile is created preserving the enabled features.
                if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                    ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                    # The "local" profile does not contain essential security features required by multiple Benchmarks.
                    # If currently used, it is replaced by "sssd", which is the best option in this case.
                    if [[ $CURRENT_PROFILE == local ]]; then
                        CURRENT_PROFILE="sssd"
                    fi
                    authselect create-profile hardening -b $CURRENT_PROFILE
                    CURRENT_PROFILE="custom/hardening"
                    
                    authselect apply-changes -b --backup=before-hardening-custom-profile
                    authselect select $CURRENT_PROFILE
                    for feature in $ENABLED_FEATURES; do
                        authselect enable-feature $feature;
                    done
                    
                    authselect apply-changes -b --backup=after-hardening-custom-profile
                fi
                PAM_FILE_NAME=$(basename "$pam_file")
                PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

                authselect apply-changes -b
            fi
            
        if grep -qP "^\s*auth\s.*\bpam_faillock.so\s.*\bfail_interval\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "s/(.*auth.*pam_faillock.so.*)\bfail_interval\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
        fi
            if [ -f /usr/bin/authselect ]; then
                
                authselect apply-changes -b
            fi
        else
            echo "$pam_file was not found" &gt;&amp;2
        fi
    done
    
else
    for pam_file in "${AUTH_FILES[@]}"
    do
        if ! grep -qE '^\s*auth.*pam_faillock\.so\s+(preauth|authfail).*fail_interval' "$pam_file"; then
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*preauth.*/ s/$/ fail_interval='"$var_accounts_passwords_pam_faillock_fail_interval"'/' "$pam_file"
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*authfail.*/ s/$/ fail_interval='"$var_accounts_passwords_pam_faillock_fail_interval"'/' "$pam_file"
        else
            sed -i --follow-symlinks 's/\(^auth.*required.*pam_faillock\.so.*preauth.*\)\('"fail_interval"'=\)\S\+\b\(.*\)/\1\2'"$var_accounts_passwords_pam_faillock_fail_interval"'\3/' "$pam_file"
            sed -i --follow-symlinks 's/\(^auth.*required.*pam_faillock\.so.*authfail.*\)\('"fail_interval"'=\)\S\+\b\(.*\)/\1\2'"$var_accounts_passwords_pam_faillock_fail_interval"'\3/' "$pam_file"
        fi
    done
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_passwords_pam_faillock_interval" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020012
  - DISA-STIG-RHEL-08-020013
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - accounts_passwords_pam_faillock_interval
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Interval For Counting Failed Password Attempts - Check if system relies
    on authselect tool
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020012
  - DISA-STIG-RHEL-08-020013
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - accounts_passwords_pam_faillock_interval
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Interval For Counting Failed Password Attempts - Remediation where authselect
    tool is present
  block:

  - name: Set Interval For Counting Failed Password Attempts - Check integrity of
      authselect current profile
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: Set Interval For Counting Failed Password Attempts - Informative message
      based on the authselect integrity check result
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: Set Interval For Counting Failed Password Attempts - Get authselect current
      features
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: Set Interval For Counting Failed Password Attempts - Ensure "with-faillock"
      feature is enabled using authselect tool
    ansible.builtin.command:
      cmd: authselect enable-feature with-faillock
    register: result_authselect_enable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is not search("with-faillock")

  - name: Set Interval For Counting Failed Password Attempts - Ensure authselect changes
      are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_enable_feature_cmd is not skipped
    - result_authselect_enable_feature_cmd is success
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020012
  - DISA-STIG-RHEL-08-020013
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - accounts_passwords_pam_faillock_interval
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Interval For Counting Failed Password Attempts - Remediation where authselect
    tool is not present
  block:

  - name: Set Interval For Counting Failed Password Attempts - Check if pam_faillock.so
      is already enabled
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail)
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_is_enabled

  - name: Set Interval For Counting Failed Password Attempts - Enable pam_faillock.so
      preauth editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so preauth
      insertbefore: ^auth.*sufficient.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Set Interval For Counting Failed Password Attempts - Enable pam_faillock.so
      authfail editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so authfail
      insertbefore: ^auth.*required.*pam_deny\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Set Interval For Counting Failed Password Attempts - Enable pam_faillock.so
      account section editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: account     required      pam_faillock.so
      insertbefore: ^account.*required.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_authselect_present.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020012
  - DISA-STIG-RHEL-08-020013
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - accounts_passwords_pam_faillock_interval
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_accounts_passwords_pam_faillock_fail_interval # promote to variable
  set_fact:
    var_accounts_passwords_pam_faillock_fail_interval: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_fail_interval" use="legacy"/>
  tags:
    - always

- name: Set Interval For Counting Failed Password Attempts - Check the presence of
    /etc/security/faillock.conf file
  ansible.builtin.stat:
    path: /etc/security/faillock.conf
  register: result_faillock_conf_check
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020012
  - DISA-STIG-RHEL-08-020013
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - accounts_passwords_pam_faillock_interval
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Interval For Counting Failed Password Attempts - Ensure the pam_faillock.so
    fail_interval parameter in /etc/security/faillock.conf
  ansible.builtin.lineinfile:
    path: /etc/security/faillock.conf
    regexp: ^\s*fail_interval\s*=
    line: fail_interval = {{ var_accounts_passwords_pam_faillock_fail_interval }}
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020012
  - DISA-STIG-RHEL-08-020013
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - accounts_passwords_pam_faillock_interval
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Interval For Counting Failed Password Attempts - Ensure the pam_faillock.so
    fail_interval parameter not in PAM files
  block:

  - name: Set Interval For Counting Failed Password Attempts - Check if /etc/pam.d/system-auth
      file is present
    ansible.builtin.stat:
      path: /etc/pam.d/system-auth
    register: result_pam_auth_file_present

  - name: Set Interval For Counting Failed Password Attempts - Check the proper remediation
      for the system
    block:

    - name: Set Interval For Counting Failed Password Attempts - Define the PAM file
        to be edited as a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/system-auth

    - name: Set Interval For Counting Failed Password Attempts - Check if system relies
        on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Set Interval For Counting Failed Password Attempts - Ensure authselect
        custom profile is used if authselect is present
      block:

      - name: Set Interval For Counting Failed Password Attempts - Check integrity
          of authselect current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Set Interval For Counting Failed Password Attempts - Informative message
          based on the authselect integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Set Interval For Counting Failed Password Attempts - Get authselect
          current profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Set Interval For Counting Failed Password Attempts - Define the current
          authselect profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Set Interval For Counting Failed Password Attempts - Define the new
          authselect custom profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Set Interval For Counting Failed Password Attempts - Get authselect
          current features to also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Set Interval For Counting Failed Password Attempts - Check if any custom
          profile with the same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Set Interval For Counting Failed Password Attempts - Create an authselect
          custom profile based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Set Interval For Counting Failed Password Attempts - Create an authselect
          custom profile based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Set Interval For Counting Failed Password Attempts - Ensure authselect
          changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Set Interval For Counting Failed Password Attempts - Ensure the authselect
          custom profile is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Set Interval For Counting Failed Password Attempts - Restore the authselect
          features in the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Set Interval For Counting Failed Password Attempts - Ensure authselect
          changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Set Interval For Counting Failed Password Attempts - Change the PAM
          file to be edited according to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Set Interval For Counting Failed Password Attempts - Define a fact for
        control already filtered in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Set Interval For Counting Failed Password Attempts - Check if {{ pam_file_path
        }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Set Interval For Counting Failed Password Attempts - Ensure the "fail_interval"
        option from "pam_faillock.so" is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\bfail_interval\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Set Interval For Counting Failed Password Attempts - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_auth_file_present.stat.exists

  - name: Set Interval For Counting Failed Password Attempts - Check if /etc/pam.d/password-auth
      file is present
    ansible.builtin.stat:
      path: /etc/pam.d/password-auth
    register: result_pam_password_auth_file_present

  - name: Set Interval For Counting Failed Password Attempts - Check the proper remediation
      for the system
    block:

    - name: Set Interval For Counting Failed Password Attempts - Define the PAM file
        to be edited as a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/password-auth

    - name: Set Interval For Counting Failed Password Attempts - Check if system relies
        on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Set Interval For Counting Failed Password Attempts - Ensure authselect
        custom profile is used if authselect is present
      block:

      - name: Set Interval For Counting Failed Password Attempts - Check integrity
          of authselect current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Set Interval For Counting Failed Password Attempts - Informative message
          based on the authselect integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Set Interval For Counting Failed Password Attempts - Get authselect
          current profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Set Interval For Counting Failed Password Attempts - Define the current
          authselect profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Set Interval For Counting Failed Password Attempts - Define the new
          authselect custom profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Set Interval For Counting Failed Password Attempts - Get authselect
          current features to also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Set Interval For Counting Failed Password Attempts - Check if any custom
          profile with the same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Set Interval For Counting Failed Password Attempts - Create an authselect
          custom profile based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Set Interval For Counting Failed Password Attempts - Create an authselect
          custom profile based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Set Interval For Counting Failed Password Attempts - Ensure authselect
          changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Set Interval For Counting Failed Password Attempts - Ensure the authselect
          custom profile is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Set Interval For Counting Failed Password Attempts - Restore the authselect
          features in the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Set Interval For Counting Failed Password Attempts - Ensure authselect
          changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Set Interval For Counting Failed Password Attempts - Change the PAM
          file to be edited according to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Set Interval For Counting Failed Password Attempts - Define a fact for
        control already filtered in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Set Interval For Counting Failed Password Attempts - Check if {{ pam_file_path
        }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Set Interval For Counting Failed Password Attempts - Ensure the "fail_interval"
        option from "pam_faillock.so" is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\bfail_interval\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Set Interval For Counting Failed Password Attempts - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_password_auth_file_present.stat.exists
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020012
  - DISA-STIG-RHEL-08-020013
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - accounts_passwords_pam_faillock_interval
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Interval For Counting Failed Password Attempts - Ensure the pam_faillock.so
    fail_interval parameter in PAM files
  block:

  - name: Set Interval For Counting Failed Password Attempts - Check if pam_faillock.so
      fail_interval parameter is already enabled in pam files
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail).*fail_interval
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_fail_interval_parameter_is_present

  - name: Set Interval For Counting Failed Password Attempts - Ensure the inclusion
      of pam_faillock.so preauth fail_interval parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so preauth.*)
      line: \1required\3 fail_interval={{ var_accounts_passwords_pam_faillock_fail_interval
        }}
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_fail_interval_parameter_is_present.found == 0

  - name: Set Interval For Counting Failed Password Attempts - Ensure the inclusion
      of pam_faillock.so authfail fail_interval parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so authfail.*)
      line: \1required\3 fail_interval={{ var_accounts_passwords_pam_faillock_fail_interval
        }}
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_fail_interval_parameter_is_present.found == 0

  - name: Set Interval For Counting Failed Password Attempts - Ensure the desired
      value for pam_faillock.so preauth fail_interval parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so preauth.*)(fail_interval)=[0-9]+(.*)
      line: \1required\3\4={{ var_accounts_passwords_pam_faillock_fail_interval }}\5
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_fail_interval_parameter_is_present.found &gt; 0

  - name: Set Interval For Counting Failed Password Attempts - Ensure the desired
      value for pam_faillock.so authfail fail_interval parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so authfail.*)(fail_interval)=[0-9]+(.*)
      line: \1required\3\4={{ var_accounts_passwords_pam_faillock_fail_interval }}\5
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_fail_interval_parameter_is_present.found &gt; 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_faillock_conf_check.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020012
  - DISA-STIG-RHEL-08-020013
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - accounts_passwords_pam_faillock_interval
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_fail_interval"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_passwords_pam_faillock_interval:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_passwords_pam_faillock_interval_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_silent" selected="false" severity="medium">
                <xccdf-1.2:title>Do Not Show System Messages When Unsuccessful Logon Attempts Occur</xccdf-1.2:title>
                <xccdf-1.2:description>This rule ensures the system prevents informative messages from being presented to the user
pertaining to logon information after a number of incorrect login attempts using
<html:code>pam_faillock.so</html:code>.

pam_faillock.so module requires multiple entries in pam files. These entries must be carefully
defined to work as expected. In order to avoid errors when manually editing these files, it is
recommended to use the appropriate tools, such as <html:code>authselect</html:code> or <html:code>authconfig</html:code>,
depending on the OS version.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">If the system relies on <html:code>authselect</html:code> tool to manage PAM settings, the remediation
will also use <html:code>authselect</html:code> tool. However, if any manual modification was made in
PAM files, the <html:code>authselect</html:code> integrity check will fail and the remediation will be
aborted in order to preserve intentional changes. In this case, an informative message will
be shown in the remediation report.
If the system supports the <html:code>/etc/security/faillock.conf</html:code> file, the pam_faillock
parameters should be defined in <html:code>faillock.conf</html:code> file.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000329-GPOS-00128</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000021-GPOS-00005</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020018</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020019</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230340r1017152_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230341r1017153_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The pam_faillock module without the silent option will leak information about the existence or
non-existence of a user account in the system because the failures are not recorded for unknown
users. The message about the user account being locked is never displayed for non-existing user
accounts allowing the adversary to infer that a particular account exists or not on the system.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix id="accounts_passwords_pam_faillock_silent" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q pam; }; then

if [ -f /usr/bin/authselect ]; then
    if ! authselect check; then
echo "
authselect integrity check failed. Remediation aborted!
This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
It is not recommended to manually edit the PAM files when authselect tool is available.
In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
exit 1
fi
authselect enable-feature with-faillock

authselect apply-changes -b
else
    
AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
for pam_file in "${AUTH_FILES[@]}"
do
    if ! grep -qE '^\s*auth\s+required\s+pam_faillock\.so\s+(preauth silent|authfail).*$' "$pam_file" ; then
        sed -i --follow-symlinks '/^auth.*sufficient.*pam_unix\.so.*/i auth        required      pam_faillock.so preauth silent' "$pam_file"
        sed -i --follow-symlinks '/^auth.*required.*pam_deny\.so.*/i auth        required      pam_faillock.so authfail' "$pam_file"
        sed -i --follow-symlinks '/^account.*required.*pam_unix\.so.*/i account     required      pam_faillock.so' "$pam_file"
    fi
    sed -Ei 's/(auth.*)(\[default=die\])(.*pam_faillock\.so)/\1required     \3/g' "$pam_file"
done

fi

AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
SKIP_FAILLOCK_CHECK=false

FAILLOCK_CONF="/etc/security/faillock.conf"
if [ -f $FAILLOCK_CONF ] || [ "$SKIP_FAILLOCK_CHECK" = "true" ]; then
    regex="^\s*silent"
    line="silent"
    if ! grep -q $regex $FAILLOCK_CONF; then
        echo $line &gt;&gt; $FAILLOCK_CONF
    fi
    
    for pam_file in "${AUTH_FILES[@]}"
    do
        if [ -e "$pam_file" ] ; then
            PAM_FILE_PATH="$pam_file"
            if [ -f /usr/bin/authselect ]; then
                
                if ! authselect check; then
                echo "
                authselect integrity check failed. Remediation aborted!
                This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
                It is not recommended to manually edit the PAM files when authselect tool is available.
                In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
                exit 1
                fi

                CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
                # If not already in use, a custom profile is created preserving the enabled features.
                if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                    ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                    # The "local" profile does not contain essential security features required by multiple Benchmarks.
                    # If currently used, it is replaced by "sssd", which is the best option in this case.
                    if [[ $CURRENT_PROFILE == local ]]; then
                        CURRENT_PROFILE="sssd"
                    fi
                    authselect create-profile hardening -b $CURRENT_PROFILE
                    CURRENT_PROFILE="custom/hardening"
                    
                    authselect apply-changes -b --backup=before-hardening-custom-profile
                    authselect select $CURRENT_PROFILE
                    for feature in $ENABLED_FEATURES; do
                        authselect enable-feature $feature;
                    done
                    
                    authselect apply-changes -b --backup=after-hardening-custom-profile
                fi
                PAM_FILE_NAME=$(basename "$pam_file")
                PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

                authselect apply-changes -b
            fi
            
        if grep -qP "^\s*auth\s.*\bpam_faillock.so\s.*\bsilent\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "s/(.*auth.*pam_faillock.so.*)\bsilent\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
        fi
            if [ -f /usr/bin/authselect ]; then
                
                authselect apply-changes -b
            fi
        else
            echo "$pam_file was not found" &gt;&amp;2
        fi
    done
    
else
    for pam_file in "${AUTH_FILES[@]}"
    do
        if ! grep -qE '^\s*auth.*pam_faillock\.so\s+(preauth|authfail).*silent' "$pam_file"; then
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*preauth.*/ s/$/ silent/' "$pam_file"
        fi
    done
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_passwords_pam_faillock_silent" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020018
  - DISA-STIG-RHEL-08-020019
  - accounts_passwords_pam_faillock_silent
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Check
    if system relies on authselect tool
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020018
  - DISA-STIG-RHEL-08-020019
  - accounts_passwords_pam_faillock_silent
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Remediation
    where authselect tool is present
  block:

  - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Check
      integrity of authselect current profile
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Informative
      message based on the authselect integrity check result
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Get
      authselect current features
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Ensure
      "with-faillock" feature is enabled using authselect tool
    ansible.builtin.command:
      cmd: authselect enable-feature with-faillock
    register: result_authselect_enable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is not search("with-faillock")

  - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Ensure
      authselect changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_enable_feature_cmd is not skipped
    - result_authselect_enable_feature_cmd is success
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020018
  - DISA-STIG-RHEL-08-020019
  - accounts_passwords_pam_faillock_silent
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Remediation
    where authselect tool is not present
  block:

  - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Check
      if pam_faillock.so is already enabled
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail)
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_is_enabled

  - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Enable
      pam_faillock.so preauth editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so preauth
      insertbefore: ^auth.*sufficient.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Enable
      pam_faillock.so authfail editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so authfail
      insertbefore: ^auth.*required.*pam_deny\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Enable
      pam_faillock.so account section editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: account     required      pam_faillock.so
      insertbefore: ^account.*required.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_authselect_present.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020018
  - DISA-STIG-RHEL-08-020019
  - accounts_passwords_pam_faillock_silent
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Check
    the presence of /etc/security/faillock.conf file
  ansible.builtin.stat:
    path: /etc/security/faillock.conf
  register: result_faillock_conf_check
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020018
  - DISA-STIG-RHEL-08-020019
  - accounts_passwords_pam_faillock_silent
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Ensure
    the pam_faillock.so silent parameter in /etc/security/faillock.conf
  ansible.builtin.lineinfile:
    path: /etc/security/faillock.conf
    regexp: ^\s*silent
    line: silent
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020018
  - DISA-STIG-RHEL-08-020019
  - accounts_passwords_pam_faillock_silent
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Ensure
    the pam_faillock.so silent parameter not in PAM files
  block:

  - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Check
      if /etc/pam.d/system-auth file is present
    ansible.builtin.stat:
      path: /etc/pam.d/system-auth
    register: result_pam_auth_file_present

  - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Check
      the proper remediation for the system
    block:

    - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Define
        the PAM file to be edited as a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/system-auth

    - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Check
        if system relies on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Ensure
        authselect custom profile is used if authselect is present
      block:

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Check integrity of authselect current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Informative message based on the authselect integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Get authselect current profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Define the current authselect profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Define the new authselect custom profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Get authselect current features to also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Check if any custom profile with the same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Create an authselect custom profile based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Create an authselect custom profile based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Ensure authselect changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Ensure the authselect custom profile is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Restore the authselect features in the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Ensure authselect changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Change the PAM file to be edited according to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Define
        a fact for control already filtered in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Check
        if {{ pam_file_path }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Ensure
        the "silent" option from "pam_faillock.so" is not present in {{ pam_file_path
        }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\bsilent\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Ensure
        authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_auth_file_present.stat.exists

  - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Check
      if /etc/pam.d/password-auth file is present
    ansible.builtin.stat:
      path: /etc/pam.d/password-auth
    register: result_pam_password_auth_file_present

  - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Check
      the proper remediation for the system
    block:

    - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Define
        the PAM file to be edited as a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/password-auth

    - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Check
        if system relies on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Ensure
        authselect custom profile is used if authselect is present
      block:

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Check integrity of authselect current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Informative message based on the authselect integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Get authselect current profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Define the current authselect profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Define the new authselect custom profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Get authselect current features to also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Check if any custom profile with the same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Create an authselect custom profile based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Create an authselect custom profile based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Ensure authselect changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Ensure the authselect custom profile is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Restore the authselect features in the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Ensure authselect changes are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur -
          Change the PAM file to be edited according to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Define
        a fact for control already filtered in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Check
        if {{ pam_file_path }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Ensure
        the "silent" option from "pam_faillock.so" is not present in {{ pam_file_path
        }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\bsilent\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Ensure
        authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_password_auth_file_present.stat.exists
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020018
  - DISA-STIG-RHEL-08-020019
  - accounts_passwords_pam_faillock_silent
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Ensure
    the pam_faillock.so silent parameter in PAM files
  block:

  - name: Do Not Show System Messages When Unsuccessful Logon Attempts Occur - Ensure
      the inclusion of pam_faillock.so preauth silent parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so preauth(:?(?!silent).)*)
      line: \1required\3 silent
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_faillock_conf_check.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020018
  - DISA-STIG-RHEL-08-020019
  - accounts_passwords_pam_faillock_silent
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_passwords_pam_faillock_silent:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_passwords_pam_faillock_silent_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time" selected="false" severity="medium">
                <xccdf-1.2:title>Set Lockout Time for Failed Password Attempts</xccdf-1.2:title>
                <xccdf-1.2:description>This rule configures the system to lock out accounts during a specified time period after a
number of incorrect login attempts using <html:code>pam_faillock.so</html:code>.

Ensure that the file <html:code>/etc/security/faillock.conf</html:code> contains the following entry:
<html:code>unlock_time=&lt;interval-in-seconds&gt;</html:code> where
<html:code>interval-in-seconds</html:code> is <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" use="legacy"/></html:code> or greater.

pam_faillock.so module requires multiple entries in pam files. These entries must be carefully
defined to work as expected. In order to avoid any errors when manually editing these files,
it is recommended to use the appropriate tools, such as <html:code>authselect</html:code> or <html:code>authconfig</html:code>,
depending on the OS version.

If <html:code>unlock_time</html:code> is set to <html:code>0</html:code>, manual intervention by an administrator is required
to unlock a user. This should be done using the <html:code>faillock</html:code> tool.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">If the system supports the new <html:code>/etc/security/faillock.conf</html:code> file but the
pam_faillock.so parameters are defined directly in <html:code>/etc/pam.d/system-auth</html:code> and
<html:code>/etc/pam.d/password-auth</html:code>, the remediation will migrate the <html:code>unlock_time</html:code> parameter
to <html:code>/etc/security/faillock.conf</html:code> to ensure compatibility with <html:code>authselect</html:code> tool.
The parameters <html:code>deny</html:code> and <html:code>fail_interval</html:code>, if used, also have to be migrated
by their respective remediation.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="general">If the system relies on <html:code>authselect</html:code> tool to manage PAM settings, the remediation
will also use <html:code>authselect</html:code> tool. However, if any manual modification was made in
PAM files, the <html:code>authselect</html:code> integrity check will fail and the remediation will be
aborted in order to preserve intentional changes. In this case, an informative message will
be shown in the remediation report.
If the system supports the <html:code>/etc/security/faillock.conf</html:code> file, the pam_faillock
parameters should be defined in <html:code>faillock.conf</html:code> file.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_AFL.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000329-GPOS-00128</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000021-GPOS-00005</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R31</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020014</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020015</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230336r1017148_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230337r1134885_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>By limiting the number of failed logon attempts the risk of unauthorized system
access via user password guessing, otherwise known as brute-forcing, is reduced.
Limits are imposed by locking the account.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix id="accounts_passwords_pam_faillock_unlock_time" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q pam; }; then

var_accounts_passwords_pam_faillock_unlock_time='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" use="legacy"/>'


if [ -f /usr/bin/authselect ]; then
    if ! authselect check; then
echo "
authselect integrity check failed. Remediation aborted!
This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
It is not recommended to manually edit the PAM files when authselect tool is available.
In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
exit 1
fi
authselect enable-feature with-faillock

authselect apply-changes -b
else
    
AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
for pam_file in "${AUTH_FILES[@]}"
do
    if ! grep -qE '^\s*auth\s+required\s+pam_faillock\.so\s+(preauth silent|authfail).*$' "$pam_file" ; then
        sed -i --follow-symlinks '/^auth.*sufficient.*pam_unix\.so.*/i auth        required      pam_faillock.so preauth silent' "$pam_file"
        sed -i --follow-symlinks '/^auth.*required.*pam_deny\.so.*/i auth        required      pam_faillock.so authfail' "$pam_file"
        sed -i --follow-symlinks '/^account.*required.*pam_unix\.so.*/i account     required      pam_faillock.so' "$pam_file"
    fi
    sed -Ei 's/(auth.*)(\[default=die\])(.*pam_faillock\.so)/\1required     \3/g' "$pam_file"
done

fi

AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
SKIP_FAILLOCK_CHECK=false

FAILLOCK_CONF="/etc/security/faillock.conf"
if [ -f $FAILLOCK_CONF ] || [ "$SKIP_FAILLOCK_CHECK" = "true" ]; then
    regex="^\s*unlock_time\s*="
    line="unlock_time = $var_accounts_passwords_pam_faillock_unlock_time"
    if ! grep -q $regex $FAILLOCK_CONF; then
        echo $line &gt;&gt; $FAILLOCK_CONF
    else
        sed -i --follow-symlinks 's|^\s*\(unlock_time\s*=\s*\)\(\S\+\)|\1'"$var_accounts_passwords_pam_faillock_unlock_time"'|g' $FAILLOCK_CONF
    fi
    
    for pam_file in "${AUTH_FILES[@]}"
    do
        if [ -e "$pam_file" ] ; then
            PAM_FILE_PATH="$pam_file"
            if [ -f /usr/bin/authselect ]; then
                
                if ! authselect check; then
                echo "
                authselect integrity check failed. Remediation aborted!
                This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
                It is not recommended to manually edit the PAM files when authselect tool is available.
                In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
                exit 1
                fi

                CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
                # If not already in use, a custom profile is created preserving the enabled features.
                if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                    ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                    # The "local" profile does not contain essential security features required by multiple Benchmarks.
                    # If currently used, it is replaced by "sssd", which is the best option in this case.
                    if [[ $CURRENT_PROFILE == local ]]; then
                        CURRENT_PROFILE="sssd"
                    fi
                    authselect create-profile hardening -b $CURRENT_PROFILE
                    CURRENT_PROFILE="custom/hardening"
                    
                    authselect apply-changes -b --backup=before-hardening-custom-profile
                    authselect select $CURRENT_PROFILE
                    for feature in $ENABLED_FEATURES; do
                        authselect enable-feature $feature;
                    done
                    
                    authselect apply-changes -b --backup=after-hardening-custom-profile
                fi
                PAM_FILE_NAME=$(basename "$pam_file")
                PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

                authselect apply-changes -b
            fi
            
        if grep -qP "^\s*auth\s.*\bpam_faillock.so\s.*\bunlock_time\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "s/(.*auth.*pam_faillock.so.*)\bunlock_time\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
        fi
            if [ -f /usr/bin/authselect ]; then
                
                authselect apply-changes -b
            fi
        else
            echo "$pam_file was not found" &gt;&amp;2
        fi
    done
    
else
    for pam_file in "${AUTH_FILES[@]}"
    do
        if ! grep -qE '^\s*auth.*pam_faillock\.so\s+(preauth|authfail).*unlock_time' "$pam_file"; then
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*preauth.*/ s/$/ unlock_time='"$var_accounts_passwords_pam_faillock_unlock_time"'/' "$pam_file"
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*authfail.*/ s/$/ unlock_time='"$var_accounts_passwords_pam_faillock_unlock_time"'/' "$pam_file"
        else
            sed -i --follow-symlinks 's/\(^auth.*required.*pam_faillock\.so.*preauth.*\)\('"unlock_time"'=\)\S\+\b\(.*\)/\1\2'"$var_accounts_passwords_pam_faillock_unlock_time"'\3/' "$pam_file"
            sed -i --follow-symlinks 's/\(^auth.*required.*pam_faillock\.so.*authfail.*\)\('"unlock_time"'=\)\S\+\b\(.*\)/\1\2'"$var_accounts_passwords_pam_faillock_unlock_time"'\3/' "$pam_file"
        fi
    done
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_passwords_pam_faillock_unlock_time" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020014
  - DISA-STIG-RHEL-08-020015
  - NIST-800-171-3.1.8
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.7
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - accounts_passwords_pam_faillock_unlock_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Lockout Time for Failed Password Attempts - Check if system relies on
    authselect tool
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020014
  - DISA-STIG-RHEL-08-020015
  - NIST-800-171-3.1.8
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.7
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - accounts_passwords_pam_faillock_unlock_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Lockout Time for Failed Password Attempts - Remediation where authselect
    tool is present
  block:

  - name: Set Lockout Time for Failed Password Attempts - Check integrity of authselect
      current profile
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: Set Lockout Time for Failed Password Attempts - Informative message based
      on the authselect integrity check result
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: Set Lockout Time for Failed Password Attempts - Get authselect current features
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: Set Lockout Time for Failed Password Attempts - Ensure "with-faillock" feature
      is enabled using authselect tool
    ansible.builtin.command:
      cmd: authselect enable-feature with-faillock
    register: result_authselect_enable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is not search("with-faillock")

  - name: Set Lockout Time for Failed Password Attempts - Ensure authselect changes
      are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_enable_feature_cmd is not skipped
    - result_authselect_enable_feature_cmd is success
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020014
  - DISA-STIG-RHEL-08-020015
  - NIST-800-171-3.1.8
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.7
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - accounts_passwords_pam_faillock_unlock_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Lockout Time for Failed Password Attempts - Remediation where authselect
    tool is not present
  block:

  - name: Set Lockout Time for Failed Password Attempts - Check if pam_faillock.so
      is already enabled
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail)
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_is_enabled

  - name: Set Lockout Time for Failed Password Attempts - Enable pam_faillock.so preauth
      editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so preauth
      insertbefore: ^auth.*sufficient.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Set Lockout Time for Failed Password Attempts - Enable pam_faillock.so authfail
      editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so authfail
      insertbefore: ^auth.*required.*pam_deny\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Set Lockout Time for Failed Password Attempts - Enable pam_faillock.so account
      section editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: account     required      pam_faillock.so
      insertbefore: ^account.*required.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_authselect_present.stat.exists
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020014
  - DISA-STIG-RHEL-08-020015
  - NIST-800-171-3.1.8
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.7
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - accounts_passwords_pam_faillock_unlock_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_accounts_passwords_pam_faillock_unlock_time # promote to variable
  set_fact:
    var_accounts_passwords_pam_faillock_unlock_time: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" use="legacy"/>
  tags:
    - always

- name: Set Lockout Time for Failed Password Attempts - Check the presence of /etc/security/faillock.conf
    file
  ansible.builtin.stat:
    path: /etc/security/faillock.conf
  register: result_faillock_conf_check
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020014
  - DISA-STIG-RHEL-08-020015
  - NIST-800-171-3.1.8
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.7
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - accounts_passwords_pam_faillock_unlock_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Lockout Time for Failed Password Attempts - Ensure the pam_faillock.so
    unlock_time parameter in /etc/security/faillock.conf
  ansible.builtin.lineinfile:
    path: /etc/security/faillock.conf
    regexp: ^\s*unlock_time\s*=
    line: unlock_time = {{ var_accounts_passwords_pam_faillock_unlock_time }}
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020014
  - DISA-STIG-RHEL-08-020015
  - NIST-800-171-3.1.8
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.7
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - accounts_passwords_pam_faillock_unlock_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Lockout Time for Failed Password Attempts - Ensure the pam_faillock.so
    unlock_time parameter not in PAM files
  block:

  - name: Set Lockout Time for Failed Password Attempts - Check if /etc/pam.d/system-auth
      file is present
    ansible.builtin.stat:
      path: /etc/pam.d/system-auth
    register: result_pam_auth_file_present

  - name: Set Lockout Time for Failed Password Attempts - Check the proper remediation
      for the system
    block:

    - name: Set Lockout Time for Failed Password Attempts - Define the PAM file to
        be edited as a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/system-auth

    - name: Set Lockout Time for Failed Password Attempts - Check if system relies
        on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Set Lockout Time for Failed Password Attempts - Ensure authselect custom
        profile is used if authselect is present
      block:

      - name: Set Lockout Time for Failed Password Attempts - Check integrity of authselect
          current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Set Lockout Time for Failed Password Attempts - Informative message
          based on the authselect integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Set Lockout Time for Failed Password Attempts - Get authselect current
          profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Set Lockout Time for Failed Password Attempts - Define the current authselect
          profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Set Lockout Time for Failed Password Attempts - Define the new authselect
          custom profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Set Lockout Time for Failed Password Attempts - Get authselect current
          features to also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Set Lockout Time for Failed Password Attempts - Check if any custom
          profile with the same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Set Lockout Time for Failed Password Attempts - Create an authselect
          custom profile based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Set Lockout Time for Failed Password Attempts - Create an authselect
          custom profile based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Set Lockout Time for Failed Password Attempts - Ensure authselect changes
          are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Set Lockout Time for Failed Password Attempts - Ensure the authselect
          custom profile is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Set Lockout Time for Failed Password Attempts - Restore the authselect
          features in the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Set Lockout Time for Failed Password Attempts - Ensure authselect changes
          are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Set Lockout Time for Failed Password Attempts - Change the PAM file
          to be edited according to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Set Lockout Time for Failed Password Attempts - Define a fact for control
        already filtered in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Set Lockout Time for Failed Password Attempts - Check if {{ pam_file_path
        }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Set Lockout Time for Failed Password Attempts - Ensure the "unlock_time"
        option from "pam_faillock.so" is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\bunlock_time\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Set Lockout Time for Failed Password Attempts - Ensure authselect changes
        are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_auth_file_present.stat.exists

  - name: Set Lockout Time for Failed Password Attempts - Check if /etc/pam.d/password-auth
      file is present
    ansible.builtin.stat:
      path: /etc/pam.d/password-auth
    register: result_pam_password_auth_file_present

  - name: Set Lockout Time for Failed Password Attempts - Check the proper remediation
      for the system
    block:

    - name: Set Lockout Time for Failed Password Attempts - Define the PAM file to
        be edited as a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/password-auth

    - name: Set Lockout Time for Failed Password Attempts - Check if system relies
        on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Set Lockout Time for Failed Password Attempts - Ensure authselect custom
        profile is used if authselect is present
      block:

      - name: Set Lockout Time for Failed Password Attempts - Check integrity of authselect
          current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Set Lockout Time for Failed Password Attempts - Informative message
          based on the authselect integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Set Lockout Time for Failed Password Attempts - Get authselect current
          profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Set Lockout Time for Failed Password Attempts - Define the current authselect
          profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Set Lockout Time for Failed Password Attempts - Define the new authselect
          custom profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Set Lockout Time for Failed Password Attempts - Get authselect current
          features to also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Set Lockout Time for Failed Password Attempts - Check if any custom
          profile with the same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Set Lockout Time for Failed Password Attempts - Create an authselect
          custom profile based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Set Lockout Time for Failed Password Attempts - Create an authselect
          custom profile based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Set Lockout Time for Failed Password Attempts - Ensure authselect changes
          are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Set Lockout Time for Failed Password Attempts - Ensure the authselect
          custom profile is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Set Lockout Time for Failed Password Attempts - Restore the authselect
          features in the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Set Lockout Time for Failed Password Attempts - Ensure authselect changes
          are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Set Lockout Time for Failed Password Attempts - Change the PAM file
          to be edited according to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Set Lockout Time for Failed Password Attempts - Define a fact for control
        already filtered in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Set Lockout Time for Failed Password Attempts - Check if {{ pam_file_path
        }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Set Lockout Time for Failed Password Attempts - Ensure the "unlock_time"
        option from "pam_faillock.so" is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\bunlock_time\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Set Lockout Time for Failed Password Attempts - Ensure authselect changes
        are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_password_auth_file_present.stat.exists
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020014
  - DISA-STIG-RHEL-08-020015
  - NIST-800-171-3.1.8
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.7
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - accounts_passwords_pam_faillock_unlock_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Lockout Time for Failed Password Attempts - Ensure the pam_faillock.so
    unlock_time parameter in PAM files
  block:

  - name: Set Lockout Time for Failed Password Attempts - Check if pam_faillock.so
      unlock_time parameter is already enabled in pam files
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail).*unlock_time
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_unlock_time_parameter_is_present

  - name: Set Lockout Time for Failed Password Attempts - Ensure the inclusion of
      pam_faillock.so preauth unlock_time parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so preauth.*)
      line: \1required\3 unlock_time={{ var_accounts_passwords_pam_faillock_unlock_time
        }}
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_unlock_time_parameter_is_present.found == 0

  - name: Set Lockout Time for Failed Password Attempts - Ensure the inclusion of
      pam_faillock.so authfail unlock_time parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so authfail.*)
      line: \1required\3 unlock_time={{ var_accounts_passwords_pam_faillock_unlock_time
        }}
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_unlock_time_parameter_is_present.found == 0

  - name: Set Lockout Time for Failed Password Attempts - Ensure the desired value
      for pam_faillock.so preauth unlock_time parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so preauth.*)(unlock_time)=[0-9]+(.*)
      line: \1required\3\4={{ var_accounts_passwords_pam_faillock_unlock_time }}\5
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_unlock_time_parameter_is_present.found &gt; 0

  - name: Set Lockout Time for Failed Password Attempts - Ensure the desired value
      for pam_faillock.so authfail unlock_time parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so authfail.*)(unlock_time)=[0-9]+(.*)
      line: \1required\3\4={{ var_accounts_passwords_pam_faillock_unlock_time }}\5
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_unlock_time_parameter_is_present.found &gt; 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_faillock_conf_check.stat.exists
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020014
  - DISA-STIG-RHEL-08-020015
  - NIST-800-171-3.1.8
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.1.7
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.4
  - accounts_passwords_pam_faillock_unlock_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_passwords_pam_faillock_unlock_time:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time_with_zero" selected="false" severity="medium">
                <xccdf-1.2:title>Set Lockout Time for Failed Password Attempts</xccdf-1.2:title>
                <xccdf-1.2:description>This rule configures the system to lock out accounts during a specified time period after a
number of incorrect login attempts using <html:code>pam_faillock.so</html:code>.

Ensure that the file <html:code>/etc/security/faillock.conf</html:code> contains the following entry:
<html:code>unlock_time=&lt;interval-in-seconds&gt;</html:code> where
<html:code>interval-in-seconds</html:code> is set to <html:code>0</html:code> or is set to
<html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" use="legacy"/></html:code> or greater.

pam_faillock.so module requires multiple entries in pam files. These entries must be carefully
defined to work as expected. In order to avoid any errors when manually editing these files,
it is recommended to use the appropriate tools, such as <html:code>authselect</html:code> or <html:code>authconfig</html:code>,
depending on the OS version.

If <html:code>unlock_time</html:code> is set to <html:code>0</html:code>, manual intervention by an administrator is required
to unlock a user. This should be done using the <html:code>faillock</html:code> tool.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">If the system supports the new <html:code>/etc/security/faillock.conf</html:code> file but the
pam_faillock.so parameters are defined directly in <html:code>/etc/pam.d/system-auth</html:code> and
<html:code>/etc/pam.d/password-auth</html:code>, the remediation will migrate the <html:code>unlock_time</html:code> parameter
to <html:code>/etc/security/faillock.conf</html:code> to ensure compatibility with <html:code>authselect</html:code> tool.
The parameters <html:code>deny</html:code> and <html:code>fail_interval</html:code>, if used, also have to be migrated
by their respective remediation.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="general">If the system relies on <html:code>authselect</html:code> tool to manage PAM settings, the remediation
will also use <html:code>authselect</html:code> tool. However, if any manual modification was made in
PAM files, the <html:code>authselect</html:code> integrity check will fail and the remediation will be
aborted in order to preserve intentional changes. In this case, an informative message will
be shown in the remediation report.
If the system supports the <html:code>/etc/security/faillock.conf</html:code> file, the pam_faillock
parameters should be defined in <html:code>faillock.conf</html:code> file.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.1.2</xccdf-1.2:reference>
                <xccdf-1.2:rationale>By limiting the number of failed logon attempts the risk of unauthorized system
access via user password guessing, otherwise known as brute-forcing, is reduced.
Limits are imposed by locking the account.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix id="accounts_passwords_pam_faillock_unlock_time_with_zero" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q pam; }; then

var_accounts_passwords_pam_faillock_unlock_time='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" use="legacy"/>'


if [ -f /usr/bin/authselect ]; then
    if ! authselect check; then
echo "
authselect integrity check failed. Remediation aborted!
This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
It is not recommended to manually edit the PAM files when authselect tool is available.
In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
exit 1
fi
authselect enable-feature with-faillock

authselect apply-changes -b
else
    
AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
for pam_file in "${AUTH_FILES[@]}"
do
    if ! grep -qE '^\s*auth\s+required\s+pam_faillock\.so\s+(preauth silent|authfail).*$' "$pam_file" ; then
        sed -i --follow-symlinks '/^auth.*sufficient.*pam_unix\.so.*/i auth        required      pam_faillock.so preauth silent' "$pam_file"
        sed -i --follow-symlinks '/^auth.*required.*pam_deny\.so.*/i auth        required      pam_faillock.so authfail' "$pam_file"
        sed -i --follow-symlinks '/^account.*required.*pam_unix\.so.*/i account     required      pam_faillock.so' "$pam_file"
    fi
    sed -Ei 's/(auth.*)(\[default=die\])(.*pam_faillock\.so)/\1required     \3/g' "$pam_file"
done

fi

AUTH_FILES=("/etc/pam.d/system-auth" "/etc/pam.d/password-auth")
SKIP_FAILLOCK_CHECK=false

FAILLOCK_CONF="/etc/security/faillock.conf"
if [ -f $FAILLOCK_CONF ] || [ "$SKIP_FAILLOCK_CHECK" = "true" ]; then
    regex="^\s*unlock_time\s*="
    line="unlock_time = $var_accounts_passwords_pam_faillock_unlock_time"
    if ! grep -q $regex $FAILLOCK_CONF; then
        echo $line &gt;&gt; $FAILLOCK_CONF
    else
        sed -i --follow-symlinks 's|^\s*\(unlock_time\s*=\s*\)\(\S\+\)|\1'"$var_accounts_passwords_pam_faillock_unlock_time"'|g' $FAILLOCK_CONF
    fi
    
    for pam_file in "${AUTH_FILES[@]}"
    do
        if [ -e "$pam_file" ] ; then
            PAM_FILE_PATH="$pam_file"
            if [ -f /usr/bin/authselect ]; then
                
                if ! authselect check; then
                echo "
                authselect integrity check failed. Remediation aborted!
                This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
                It is not recommended to manually edit the PAM files when authselect tool is available.
                In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
                exit 1
                fi

                CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
                # If not already in use, a custom profile is created preserving the enabled features.
                if [[ ! $CURRENT_PROFILE == custom/* ]]; then
                    ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
                    # The "local" profile does not contain essential security features required by multiple Benchmarks.
                    # If currently used, it is replaced by "sssd", which is the best option in this case.
                    if [[ $CURRENT_PROFILE == local ]]; then
                        CURRENT_PROFILE="sssd"
                    fi
                    authselect create-profile hardening -b $CURRENT_PROFILE
                    CURRENT_PROFILE="custom/hardening"
                    
                    authselect apply-changes -b --backup=before-hardening-custom-profile
                    authselect select $CURRENT_PROFILE
                    for feature in $ENABLED_FEATURES; do
                        authselect enable-feature $feature;
                    done
                    
                    authselect apply-changes -b --backup=after-hardening-custom-profile
                fi
                PAM_FILE_NAME=$(basename "$pam_file")
                PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

                authselect apply-changes -b
            fi
            
        if grep -qP "^\s*auth\s.*\bpam_faillock.so\s.*\bunlock_time\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "s/(.*auth.*pam_faillock.so.*)\bunlock_time\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
        fi
            if [ -f /usr/bin/authselect ]; then
                
                authselect apply-changes -b
            fi
        else
            echo "$pam_file was not found" &gt;&amp;2
        fi
    done
    
else
    for pam_file in "${AUTH_FILES[@]}"
    do
        if ! grep -qE '^\s*auth.*pam_faillock\.so\s+(preauth|authfail).*unlock_time' "$pam_file"; then
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*preauth.*/ s/$/ unlock_time='"$var_accounts_passwords_pam_faillock_unlock_time"'/' "$pam_file"
            sed -i --follow-symlinks '/^auth.*required.*pam_faillock\.so.*authfail.*/ s/$/ unlock_time='"$var_accounts_passwords_pam_faillock_unlock_time"'/' "$pam_file"
        else
            sed -i --follow-symlinks 's/\(^auth.*required.*pam_faillock\.so.*preauth.*\)\('"unlock_time"'=\)\S\+\b\(.*\)/\1\2'"$var_accounts_passwords_pam_faillock_unlock_time"'\3/' "$pam_file"
            sed -i --follow-symlinks 's/\(^auth.*required.*pam_faillock\.so.*authfail.*\)\('"unlock_time"'=\)\S\+\b\(.*\)/\1\2'"$var_accounts_passwords_pam_faillock_unlock_time"'\3/' "$pam_file"
        fi
    done
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_passwords_pam_faillock_unlock_time_with_zero" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - accounts_passwords_pam_faillock_unlock_time_with_zero
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Lockout Time for Failed Password Attempts - Check if system relies on
    authselect tool
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - accounts_passwords_pam_faillock_unlock_time_with_zero
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Lockout Time for Failed Password Attempts - Remediation where authselect
    tool is present
  block:

  - name: Set Lockout Time for Failed Password Attempts - Check integrity of authselect
      current profile
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: Set Lockout Time for Failed Password Attempts - Informative message based
      on the authselect integrity check result
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: Set Lockout Time for Failed Password Attempts - Get authselect current features
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: Set Lockout Time for Failed Password Attempts - Ensure "with-faillock" feature
      is enabled using authselect tool
    ansible.builtin.command:
      cmd: authselect enable-feature with-faillock
    register: result_authselect_enable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is not search("with-faillock")

  - name: Set Lockout Time for Failed Password Attempts - Ensure authselect changes
      are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_enable_feature_cmd is not skipped
    - result_authselect_enable_feature_cmd is success
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  tags:
  - accounts_passwords_pam_faillock_unlock_time_with_zero
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Lockout Time for Failed Password Attempts - Remediation where authselect
    tool is not present
  block:

  - name: Set Lockout Time for Failed Password Attempts - Check if pam_faillock.so
      is already enabled
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail)
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_is_enabled

  - name: Set Lockout Time for Failed Password Attempts - Enable pam_faillock.so preauth
      editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so preauth
      insertbefore: ^auth.*sufficient.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Set Lockout Time for Failed Password Attempts - Enable pam_faillock.so authfail
      editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: auth        required      pam_faillock.so authfail
      insertbefore: ^auth.*required.*pam_deny\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0

  - name: Set Lockout Time for Failed Password Attempts - Enable pam_faillock.so account
      section editing PAM files
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      line: account     required      pam_faillock.so
      insertbefore: ^account.*required.*pam_unix\.so.*
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_is_enabled.found == 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_authselect_present.stat.exists
  tags:
  - accounts_passwords_pam_faillock_unlock_time_with_zero
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_accounts_passwords_pam_faillock_unlock_time # promote to variable
  set_fact:
    var_accounts_passwords_pam_faillock_unlock_time: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" use="legacy"/>
  tags:
    - always

- name: Set Lockout Time for Failed Password Attempts - Check the presence of /etc/security/faillock.conf
    file
  ansible.builtin.stat:
    path: /etc/security/faillock.conf
  register: result_faillock_conf_check
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - accounts_passwords_pam_faillock_unlock_time_with_zero
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Lockout Time for Failed Password Attempts - Ensure the pam_faillock.so
    unlock_time parameter in /etc/security/faillock.conf
  ansible.builtin.lineinfile:
    path: /etc/security/faillock.conf
    regexp: ^\s*unlock_time\s*=
    line: unlock_time = {{ var_accounts_passwords_pam_faillock_unlock_time }}
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - accounts_passwords_pam_faillock_unlock_time_with_zero
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Lockout Time for Failed Password Attempts - Ensure the pam_faillock.so
    unlock_time parameter not in PAM files
  block:

  - name: Set Lockout Time for Failed Password Attempts - Check if /etc/pam.d/system-auth
      file is present
    ansible.builtin.stat:
      path: /etc/pam.d/system-auth
    register: result_pam_auth_file_present

  - name: Set Lockout Time for Failed Password Attempts - Check the proper remediation
      for the system
    block:

    - name: Set Lockout Time for Failed Password Attempts - Define the PAM file to
        be edited as a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/system-auth

    - name: Set Lockout Time for Failed Password Attempts - Check if system relies
        on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Set Lockout Time for Failed Password Attempts - Ensure authselect custom
        profile is used if authselect is present
      block:

      - name: Set Lockout Time for Failed Password Attempts - Check integrity of authselect
          current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Set Lockout Time for Failed Password Attempts - Informative message
          based on the authselect integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Set Lockout Time for Failed Password Attempts - Get authselect current
          profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Set Lockout Time for Failed Password Attempts - Define the current authselect
          profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Set Lockout Time for Failed Password Attempts - Define the new authselect
          custom profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Set Lockout Time for Failed Password Attempts - Get authselect current
          features to also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Set Lockout Time for Failed Password Attempts - Check if any custom
          profile with the same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Set Lockout Time for Failed Password Attempts - Create an authselect
          custom profile based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Set Lockout Time for Failed Password Attempts - Create an authselect
          custom profile based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Set Lockout Time for Failed Password Attempts - Ensure authselect changes
          are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Set Lockout Time for Failed Password Attempts - Ensure the authselect
          custom profile is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Set Lockout Time for Failed Password Attempts - Restore the authselect
          features in the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Set Lockout Time for Failed Password Attempts - Ensure authselect changes
          are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Set Lockout Time for Failed Password Attempts - Change the PAM file
          to be edited according to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Set Lockout Time for Failed Password Attempts - Define a fact for control
        already filtered in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Set Lockout Time for Failed Password Attempts - Check if {{ pam_file_path
        }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Set Lockout Time for Failed Password Attempts - Ensure the "unlock_time"
        option from "pam_faillock.so" is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\bunlock_time\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Set Lockout Time for Failed Password Attempts - Ensure authselect changes
        are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_auth_file_present.stat.exists

  - name: Set Lockout Time for Failed Password Attempts - Check if /etc/pam.d/password-auth
      file is present
    ansible.builtin.stat:
      path: /etc/pam.d/password-auth
    register: result_pam_password_auth_file_present

  - name: Set Lockout Time for Failed Password Attempts - Check the proper remediation
      for the system
    block:

    - name: Set Lockout Time for Failed Password Attempts - Define the PAM file to
        be edited as a local fact
      ansible.builtin.set_fact:
        pam_file_path: /etc/pam.d/password-auth

    - name: Set Lockout Time for Failed Password Attempts - Check if system relies
        on authselect tool
      ansible.builtin.stat:
        path: /usr/bin/authselect
      register: result_authselect_present

    - name: Set Lockout Time for Failed Password Attempts - Ensure authselect custom
        profile is used if authselect is present
      block:

      - name: Set Lockout Time for Failed Password Attempts - Check integrity of authselect
          current profile
        ansible.builtin.command:
          cmd: authselect check
        register: result_authselect_check_cmd
        changed_when: false
        check_mode: false
        failed_when: false

      - name: Set Lockout Time for Failed Password Attempts - Informative message
          based on the authselect integrity check result
        ansible.builtin.assert:
          that:
          - ansible_check_mode or result_authselect_check_cmd.rc == 0
          fail_msg:
          - authselect integrity check failed. Remediation aborted!
          - This remediation could not be applied because an authselect profile was
            not selected or the selected profile is not intact.
          - It is not recommended to manually edit the PAM files when authselect tool
            is available.
          - In cases where the default authselect profile does not cover a specific
            demand, a custom authselect profile is recommended.
          success_msg:
          - authselect integrity check passed

      - name: Set Lockout Time for Failed Password Attempts - Get authselect current
          profile
        ansible.builtin.shell:
          cmd: authselect current -r | awk '{ print $1 }'
        register: result_authselect_profile
        changed_when: false
        when:
        - result_authselect_check_cmd is success

      - name: Set Lockout Time for Failed Password Attempts - Define the current authselect
          profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is match("custom/")

      - name: Set Lockout Time for Failed Password Attempts - Define the new authselect
          custom profile as a local fact
        ansible.builtin.set_fact:
          authselect_current_profile: '{{ result_authselect_profile.stdout }}'
          authselect_custom_profile: custom/hardening
        when:
        - result_authselect_profile is not skipped
        - result_authselect_profile.stdout is not match("custom/")

      - name: Set Lockout Time for Failed Password Attempts - Get authselect current
          features to also enable them in the custom profile
        ansible.builtin.shell:
          cmd: authselect current | tail -n+3 | awk '{ print $2 }'
        register: result_authselect_features
        changed_when: false
        check_mode: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Set Lockout Time for Failed Password Attempts - Check if any custom
          profile with the same name was already created
        ansible.builtin.stat:
          path: /etc/authselect/{{ authselect_custom_profile }}
        register: result_authselect_custom_profile_present
        changed_when: false
        when:
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")

      - name: Set Lockout Time for Failed Password Attempts - Create an authselect
          custom profile based on the current profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b {{ authselect_current_profile
            }}
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is not match("^(custom/|local)")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Set Lockout Time for Failed Password Attempts - Create an authselect
          custom profile based on sssd profile
        ansible.builtin.command:
          cmd: authselect create-profile hardening -b sssd
        when:
        - result_authselect_profile is not skipped
        - result_authselect_check_cmd is success
        - authselect_current_profile is match("local")
        - not result_authselect_custom_profile_present.stat.exists

      - name: Set Lockout Time for Failed Password Attempts - Ensure authselect changes
          are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Set Lockout Time for Failed Password Attempts - Ensure the authselect
          custom profile is selected
        ansible.builtin.command:
          cmd: authselect select {{ authselect_custom_profile }}
        register: result_pam_authselect_select_profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - authselect_current_profile is not match("custom/")
        - authselect_custom_profile is not match(authselect_current_profile)

      - name: Set Lockout Time for Failed Password Attempts - Restore the authselect
          features in the custom profile
        ansible.builtin.command:
          cmd: authselect enable-feature {{ item }}
        loop: '{{ result_authselect_features.stdout_lines }}'
        register: result_pam_authselect_restore_features
        when:
        - result_authselect_profile is not skipped
        - result_authselect_features is not skipped
        - result_pam_authselect_select_profile is not skipped

      - name: Set Lockout Time for Failed Password Attempts - Ensure authselect changes
          are applied
        ansible.builtin.command:
          cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
        when:
        - result_authselect_check_cmd is success
        - result_authselect_profile is not skipped
        - result_pam_authselect_restore_features is not skipped

      - name: Set Lockout Time for Failed Password Attempts - Change the PAM file
          to be edited according to the custom authselect profile
        ansible.builtin.set_fact:
          pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
            | basename }}
        when:
        - authselect_custom_profile is defined
      when:
      - result_authselect_present.stat.exists

    - name: Set Lockout Time for Failed Password Attempts - Define a fact for control
        already filtered in case filters are used
      ansible.builtin.set_fact:
        pam_module_control: ''

    - name: Set Lockout Time for Failed Password Attempts - Check if {{ pam_file_path
        }} file is present
      ansible.builtin.stat:
        path: '{{ pam_file_path }}'
      register: result_pam_file_present

    - name: Set Lockout Time for Failed Password Attempts - Ensure the "unlock_time"
        option from "pam_faillock.so" is not present in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: (.*auth.*pam_faillock.so.*)\bunlock_time\b=?[0-9a-zA-Z]*(.*)
        replace: \1\2
      register: result_pam_option_removal
      when:
      - result_pam_file_present.stat.exists

    - name: Set Lockout Time for Failed Password Attempts - Ensure authselect changes
        are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present.stat.exists
      - result_pam_option_removal is changed
    when:
    - result_pam_password_auth_file_present.stat.exists
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_faillock_conf_check.stat.exists
  tags:
  - accounts_passwords_pam_faillock_unlock_time_with_zero
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Lockout Time for Failed Password Attempts - Ensure the pam_faillock.so
    unlock_time parameter in PAM files
  block:

  - name: Set Lockout Time for Failed Password Attempts - Check if pam_faillock.so
      unlock_time parameter is already enabled in pam files
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: .*auth.*pam_faillock\.so (preauth|authfail).*unlock_time
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_faillock_unlock_time_parameter_is_present

  - name: Set Lockout Time for Failed Password Attempts - Ensure the inclusion of
      pam_faillock.so preauth unlock_time parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so preauth.*)
      line: \1required\3 unlock_time={{ var_accounts_passwords_pam_faillock_unlock_time
        }}
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_unlock_time_parameter_is_present.found == 0

  - name: Set Lockout Time for Failed Password Attempts - Ensure the inclusion of
      pam_faillock.so authfail unlock_time parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so authfail.*)
      line: \1required\3 unlock_time={{ var_accounts_passwords_pam_faillock_unlock_time
        }}
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_unlock_time_parameter_is_present.found == 0

  - name: Set Lockout Time for Failed Password Attempts - Ensure the desired value
      for pam_faillock.so preauth unlock_time parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so preauth.*)(unlock_time)=[0-9]+(.*)
      line: \1required\3\4={{ var_accounts_passwords_pam_faillock_unlock_time }}\5
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_unlock_time_parameter_is_present.found &gt; 0

  - name: Set Lockout Time for Failed Password Attempts - Ensure the desired value
      for pam_faillock.so authfail unlock_time parameter in auth section
    ansible.builtin.lineinfile:
      path: '{{ item }}'
      backrefs: true
      regexp: (^\s*auth\s+)([\w\[].*\b)(\s+pam_faillock.so authfail.*)(unlock_time)=[0-9]+(.*)
      line: \1required\3\4={{ var_accounts_passwords_pam_faillock_unlock_time }}\5
      state: present
    loop:
    - /etc/pam.d/system-auth
    - /etc/pam.d/password-auth
    when:
    - result_pam_faillock_unlock_time_parameter_is_present.found &gt; 0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not result_faillock_conf_check.stat.exists
  tags:
  - accounts_passwords_pam_faillock_unlock_time_with_zero
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_passwords_pam_faillock_unlock_time_with_zero:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_with_zero_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_password_quality">
              <xccdf-1.2:title>Set Password Quality Requirements</xccdf-1.2:title>
              <xccdf-1.2:description>The default <html:code>pam_pwquality</html:code> PAM module provides strength
checking for passwords. It performs a number of checks, such as
making sure passwords are not similar to dictionary words, are of
at least a certain length, are not the previous password reversed,
and are not simply a change of case from the previous password. It
can also require passwords to be in certain character classes. The
<html:code>pam_pwquality</html:code> module is the preferred way of configuring
password requirements.
<html:br/><html:br/>
The man pages <html:code>pam_pwquality(8)</html:code>
provide information on the capabilities and configuration of
each.</xccdf-1.2:description>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_password_quality_pwquality">
                <xccdf-1.2:title>Set Password Quality Requirements with pam_pwquality</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>pam_pwquality</html:code> PAM module can be configured to meet
requirements for a variety of policies.
<html:br/><html:br/>
For example, to configure <html:code>pam_pwquality</html:code> to require at least one uppercase
character, lowercase character, digit, and other (special)
character, make sure that <html:code>pam_pwquality</html:code> exists in <html:code>/etc/pam.d/system-auth</html:code>:
<html:pre>password    requisite     pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type=</html:pre>
If no such line exists, add one as the first line of the password section in <html:code>/etc/pam.d/system-auth</html:code>.
Next, modify the settings in <html:code>/etc/security/pwquality.conf</html:code> to match the following:
<html:pre>difok = 4
minlen = 14
dcredit = -1
ucredit = -1
lcredit = -1
ocredit = -1
maxrepeat = 3</html:pre>
The arguments can be modified to ensure compliance with
your organization's security policy. Discussion of each parameter follows.</xccdf-1.2:description>
                <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_pam_dcredit" type="number">
                  <xccdf-1.2:title>dcredit</xccdf-1.2:title>
                  <xccdf-1.2:description>Minimum number of digits in password</xccdf-1.2:description>
                  <xccdf-1.2:value selector="0">0</xccdf-1.2:value>
                  <xccdf-1.2:value selector="1">-1</xccdf-1.2:value>
                  <xccdf-1.2:value selector="2">-2</xccdf-1.2:value>
                  <xccdf-1.2:value>-1</xccdf-1.2:value>
                </xccdf-1.2:Value>
                <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_pam_dictcheck" type="number">
                  <xccdf-1.2:title>dictcheck</xccdf-1.2:title>
                  <xccdf-1.2:description>Prevent the use of dictionary words for passwords.</xccdf-1.2:description>
                  <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
                  <xccdf-1.2:value>1</xccdf-1.2:value>
                </xccdf-1.2:Value>
                <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_pam_difok" type="number">
                  <xccdf-1.2:title>difok</xccdf-1.2:title>
                  <xccdf-1.2:description>Minimum number of characters not present in old
password</xccdf-1.2:description>
                  <xccdf-1.2:value selector="15">15</xccdf-1.2:value>
                  <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
                  <xccdf-1.2:value selector="2">2</xccdf-1.2:value>
                  <xccdf-1.2:value selector="3">3</xccdf-1.2:value>
                  <xccdf-1.2:value selector="4">4</xccdf-1.2:value>
                  <xccdf-1.2:value selector="5">5</xccdf-1.2:value>
                  <xccdf-1.2:value selector="6">6</xccdf-1.2:value>
                  <xccdf-1.2:value selector="7">7</xccdf-1.2:value>
                  <xccdf-1.2:value selector="8">8</xccdf-1.2:value>
                  <xccdf-1.2:value>8</xccdf-1.2:value>
                </xccdf-1.2:Value>
                <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_pam_lcredit" type="number">
                  <xccdf-1.2:title>lcredit</xccdf-1.2:title>
                  <xccdf-1.2:description>Minimum number of lower case in password</xccdf-1.2:description>
                  <xccdf-1.2:value selector="0">0</xccdf-1.2:value>
                  <xccdf-1.2:value selector="1">-1</xccdf-1.2:value>
                  <xccdf-1.2:value selector="2">-2</xccdf-1.2:value>
                  <xccdf-1.2:value>-1</xccdf-1.2:value>
                </xccdf-1.2:Value>
                <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_pam_maxclassrepeat" type="number">
                  <xccdf-1.2:title>maxclassrepeat</xccdf-1.2:title>
                  <xccdf-1.2:description>Maximum Number of Consecutive Repeating Characters in a Password From the Same Character Class</xccdf-1.2:description>
                  <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
                  <xccdf-1.2:value selector="2">2</xccdf-1.2:value>
                  <xccdf-1.2:value selector="3">3</xccdf-1.2:value>
                  <xccdf-1.2:value selector="4">4</xccdf-1.2:value>
                  <xccdf-1.2:value>4</xccdf-1.2:value>
                </xccdf-1.2:Value>
                <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_pam_maxrepeat" type="number">
                  <xccdf-1.2:title>maxrepeat</xccdf-1.2:title>
                  <xccdf-1.2:description>Maximum Number of Consecutive Repeating Characters in a Password</xccdf-1.2:description>
                  <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
                  <xccdf-1.2:value selector="2">2</xccdf-1.2:value>
                  <xccdf-1.2:value selector="3">3</xccdf-1.2:value>
                  <xccdf-1.2:value>3</xccdf-1.2:value>
                </xccdf-1.2:Value>
                <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_pam_maxsequence" type="number">
                  <xccdf-1.2:title>maxsequence</xccdf-1.2:title>
                  <xccdf-1.2:description>Maximum Number of Consecutive Character Sequences in a Password</xccdf-1.2:description>
                  <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
                  <xccdf-1.2:value selector="2">2</xccdf-1.2:value>
                  <xccdf-1.2:value selector="3">3</xccdf-1.2:value>
                  <xccdf-1.2:value>3</xccdf-1.2:value>
                </xccdf-1.2:Value>
                <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_pam_minclass" type="number">
                  <xccdf-1.2:title>minclass</xccdf-1.2:title>
                  <xccdf-1.2:description>Minimum number of categories of characters that must exist in a password</xccdf-1.2:description>
                  <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
                  <xccdf-1.2:value selector="2">2</xccdf-1.2:value>
                  <xccdf-1.2:value selector="3">3</xccdf-1.2:value>
                  <xccdf-1.2:value selector="4">4</xccdf-1.2:value>
                  <xccdf-1.2:value>3</xccdf-1.2:value>
                </xccdf-1.2:Value>
                <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_pam_minlen" type="number">
                  <xccdf-1.2:title>minlen</xccdf-1.2:title>
                  <xccdf-1.2:description>Minimum number of characters in password</xccdf-1.2:description>
                  <xccdf-1.2:value selector="10">10</xccdf-1.2:value>
                  <xccdf-1.2:value selector="12">12</xccdf-1.2:value>
                  <xccdf-1.2:value selector="14">14</xccdf-1.2:value>
                  <xccdf-1.2:value selector="15">15</xccdf-1.2:value>
                  <xccdf-1.2:value selector="17">17</xccdf-1.2:value>
                  <xccdf-1.2:value selector="18">18</xccdf-1.2:value>
                  <xccdf-1.2:value selector="20">20</xccdf-1.2:value>
                  <xccdf-1.2:value selector="6">6</xccdf-1.2:value>
                  <xccdf-1.2:value selector="7">7</xccdf-1.2:value>
                  <xccdf-1.2:value selector="8">8</xccdf-1.2:value>
                  <xccdf-1.2:value>15</xccdf-1.2:value>
                </xccdf-1.2:Value>
                <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_pam_ocredit" type="number">
                  <xccdf-1.2:title>ocredit</xccdf-1.2:title>
                  <xccdf-1.2:description>Minimum number of other (special characters) in
password</xccdf-1.2:description>
                  <xccdf-1.2:value selector="0">0</xccdf-1.2:value>
                  <xccdf-1.2:value selector="1">-1</xccdf-1.2:value>
                  <xccdf-1.2:value selector="2">-2</xccdf-1.2:value>
                  <xccdf-1.2:value>-1</xccdf-1.2:value>
                </xccdf-1.2:Value>
                <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_pam_retry" type="number">
                  <xccdf-1.2:title>retry</xccdf-1.2:title>
                  <xccdf-1.2:description>Number of retry attempts before erroring out</xccdf-1.2:description>
                  <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
                  <xccdf-1.2:value selector="2">2</xccdf-1.2:value>
                  <xccdf-1.2:value selector="3">3</xccdf-1.2:value>
                  <xccdf-1.2:value selector="4">4</xccdf-1.2:value>
                  <xccdf-1.2:value selector="5">5</xccdf-1.2:value>
                  <xccdf-1.2:value>3</xccdf-1.2:value>
                </xccdf-1.2:Value>
                <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_pam_ucredit" type="number">
                  <xccdf-1.2:title>ucredit</xccdf-1.2:title>
                  <xccdf-1.2:description>Minimum number of upper case in password</xccdf-1.2:description>
                  <xccdf-1.2:value selector="0">0</xccdf-1.2:value>
                  <xccdf-1.2:value selector="1">-1</xccdf-1.2:value>
                  <xccdf-1.2:value selector="2">-2</xccdf-1.2:value>
                  <xccdf-1.2:value>-1</xccdf-1.2:value>
                </xccdf-1.2:Value>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_dcredit" selected="false" severity="medium">
                  <xccdf-1.2:title>Ensure PAM Enforces Password Requirements - Minimum Digit Characters</xccdf-1.2:title>
                  <xccdf-1.2:description>The pam_pwquality module's <html:code>dcredit</html:code> parameter controls requirements for
usage of digits in a password. When set to a negative number, any password will be required to
contain that many digits. When set to a positive number, pam_pwquality will grant +1 additional
length credit for each digit. Modify the <html:code>dcredit</html:code> setting in
<html:code>/etc/security/pwquality.conf</html:code> to require the use of a digit in passwords.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(c)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(4)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000071-GPOS-00039</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R31</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020130</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230359r1017171_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Use of a complex password helps to increase the time and resources required
to compromise the password. Password complexity, or strength, is a measure of
the effectiveness of a password in resisting attempts at guessing and brute-force
attacks.
<html:br/><html:br/>
Password complexity is one factor of several that determines how long it takes
to crack a password. The more complex the password, the greater the number of
possible combinations that need to be tested before the password is compromised.
Requiring digits makes password guessing attacks more difficult by ensuring a larger
search space.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_libpwquality"/>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_dcredit" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libpwquality; }; then

var_password_pam_dcredit='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_dcredit" use="legacy"/>'












# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^dcredit")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_password_pam_dcredit"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^dcredit\\&gt;" "/etc/security/pwquality.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^dcredit\\&gt;.*/$escaped_formatted_output/gi" "/etc/security/pwquality.conf"
else
    if [[ -s "/etc/security/pwquality.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/security/pwquality.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/security/pwquality.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/security/pwquality.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_dcredit" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020130
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.3
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.6
  - accounts_password_pam_dcredit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_password_pam_dcredit # promote to variable
  set_fact:
    var_password_pam_dcredit: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_dcredit" use="legacy"/>
  tags:
    - always

- name: Ensure PAM Enforces Password Requirements - Minimum Digit Characters - Ensure
    PAM variable dcredit is set accordingly
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/security/pwquality.conf
    regexp: ^#?\s*dcredit
    line: dcredit = {{ var_password_pam_dcredit }}
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020130
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.3
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.6
  - accounts_password_pam_dcredit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_dcredit:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_dcredit"/>
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_dcredit:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_dcredit_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_dictcheck" selected="false" severity="medium">
                  <xccdf-1.2:title>Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words</xccdf-1.2:title>
                  <xccdf-1.2:description>The pam_pwquality module's <html:code>dictcheck</html:code> check if passwords contains dictionary words. When
<html:code>dictcheck</html:code> is set to <html:code>1</html:code> passwords will be checked for dictionary words.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(c)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(4)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00225</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000072-GPOS-00040</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.2.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020300</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230377r1017188_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Use of a complex password helps to increase the time and resources required to compromise the password.
Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at
guessing and brute-force attacks.
<html:br/><html:br/>
Password complexity is one factor of several that determines how long it takes to crack a password. The more
complex the password, the greater the number of possible combinations that need to be tested before the
password is compromised.
<html:br/><html:br/>
Passwords with dictionary words may be more vulnerable to password-guessing attacks.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_libpwquality"/>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_dictcheck" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libpwquality; }; then

var_password_pam_dictcheck='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_dictcheck" use="legacy"/>'












# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^dictcheck")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_password_pam_dictcheck"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^dictcheck\\&gt;" "/etc/security/pwquality.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^dictcheck\\&gt;.*/$escaped_formatted_output/gi" "/etc/security/pwquality.conf"
else
    if [[ -s "/etc/security/pwquality.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/security/pwquality.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/security/pwquality.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/security/pwquality.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_dictcheck" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020300
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - accounts_password_pam_dictcheck
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_password_pam_dictcheck # promote to variable
  set_fact:
    var_password_pam_dictcheck: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_dictcheck" use="legacy"/>
  tags:
    - always

- name: Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary
    Words - Ensure PAM variable dictcheck is set accordingly
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/security/pwquality.conf
    regexp: ^#?\s*dictcheck
    line: dictcheck = {{ var_password_pam_dictcheck }}
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020300
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - accounts_password_pam_dictcheck
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_dictcheck:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_dictcheck"/>
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_dictcheck:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_dictcheck_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_difok" selected="false" severity="medium">
                  <xccdf-1.2:title>Ensure PAM Enforces Password Requirements - Minimum Different Characters</xccdf-1.2:title>
                  <xccdf-1.2:description>The pam_pwquality module's <html:code>difok</html:code> parameter sets the number of characters
in a password that must not be present in and old password during a password change.
<html:br/><html:br/>
Modify the <html:code>difok</html:code> setting in <html:code>/etc/security/pwquality.conf</html:code>
to equal <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_difok" use="legacy"/> to require differing characters
when changing passwords.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.6.2.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(c)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(b)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(4)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000072-GPOS-00040</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020170</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230363r1017175_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Use of a complex password helps to increase the time and resources
required to compromise the password. Password complexity, or strength,
is a measure of the effectiveness of a password in resisting attempts
at guessing and brute–force attacks.
<html:br/><html:br/>
Password complexity is one factor of several that determines how long
it takes to crack a password. The more complex the password, the
greater the number of possible combinations that need to be tested
before the password is compromised.
<html:br/><html:br/>
Requiring a minimum number of different characters during password changes ensures that
newly changed passwords should not resemble previously compromised ones.
Note that passwords which are changed on compromised systems will still be compromised, however.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_libpwquality"/>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_difok" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libpwquality; }; then

var_password_pam_difok='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_difok" use="legacy"/>'












# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^difok")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_password_pam_difok"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^difok\\&gt;" "/etc/security/pwquality.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^difok\\&gt;.*/$escaped_formatted_output/gi" "/etc/security/pwquality.conf"
else
    if [[ -s "/etc/security/pwquality.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/security/pwquality.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/security/pwquality.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/security/pwquality.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_difok" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.6.2.1.1
  - DISA-STIG-RHEL-08-020170
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(b)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - accounts_password_pam_difok
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_password_pam_difok # promote to variable
  set_fact:
    var_password_pam_difok: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_difok" use="legacy"/>
  tags:
    - always

- name: Ensure PAM Enforces Password Requirements - Minimum Different Characters -
    Ensure PAM variable difok is set accordingly
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/security/pwquality.conf
    regexp: ^#?\s*difok
    line: difok = {{ var_password_pam_difok }}
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.1.1
  - DISA-STIG-RHEL-08-020170
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(b)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - accounts_password_pam_difok
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_difok:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_difok"/>
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_difok:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_difok_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_enforce_local" selected="false" severity="medium">
                  <xccdf-1.2:title>Ensure PAM Enforces Password Requirements - Enforce for Local Accounts Only</xccdf-1.2:title>
                  <xccdf-1.2:description>The pam_pwquality module's <html:code>local_users_only</html:code> parameter controls requirements for
enforcing password complexity by pam_pwquality only for local user accounts and ignoring
centralized user account management password complexity configurations. Enable the <html:code>local_users_only</html:code>
setting in <html:code>/etc/security/pwquality.conf</html:code> to require password complexity enforcement
for only local user accounts.</xccdf-1.2:description>
                  <xccdf-1.2:warning category="management">Using this rule bypasses pam_faillock's functionality and should be used in cases
where centralized management such as LDAP or Active Directory is in use.</xccdf-1.2:warning>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(1)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000001-GPOS-00001</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>The operating system must provide automated mechanisms for supporting account management
functions. Enterprise environments make application account management challenging and
complex. A manual process for account management functions adds the risk of a potential
oversight or other error.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_libpwquality"/>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_enforce_local" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libpwquality; }; then

if [ -e "/etc/security/pwquality.conf" ] ; then
    
    LC_ALL=C sed -i "/^\s*local_users_only/Id" "/etc/security/pwquality.conf"
else
    touch "/etc/security/pwquality.conf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/security/pwquality.conf"

cp "/etc/security/pwquality.conf" "/etc/security/pwquality.conf.bak"
# Insert at the end of the file
printf '%s\n' "local_users_only" &gt;&gt; "/etc/security/pwquality.conf"
# Clean up after ourselves.
rm "/etc/security/pwquality.conf.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_enforce_local" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-2(1)
  - accounts_password_pam_enforce_local
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure PAM Enforces Password Requirements - Enforce for Local Accounts Only
  ansible.builtin.lineinfile:
    path: /etc/security/pwquality.conf
    create: true
    regexp: ''
    line: local_users_only
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-2(1)
  - accounts_password_pam_enforce_local
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_enforce_local:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_enforce_local_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_enforce_root" selected="false" severity="medium">
                  <xccdf-1.2:title>Ensure PAM Enforces Password Requirements - Enforce for root User</xccdf-1.2:title>
                  <xccdf-1.2:description>The pam_pwquality module's <html:code>enforce_for_root</html:code> parameter controls requirements for
enforcing password complexity for the root user. Enable the <html:code>enforce_for_root</html:code>
setting in <html:code>/etc/security/pwquality.conf</html:code> to require the <html:code>root</html:code> user
to use complex passwords.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(c)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(4)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000072-GPOS-00040</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000071-GPOS-00039</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000070-GPOS-00038</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000266-GPOS-00101</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000078-GPOS-00046</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00225</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000069-GPOS-00037</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.2.7</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Use of a complex password helps to increase the time and resources required to compromise
the password. Password complexity, or strength, is a measure of the effectiveness of a
password in resisting attempts at guessing and brute-force attacks.

Password complexity is one factor of several that determines how long it takes to crack a
password. The more complex the password, the greater the number of possible combinations
that need to be tested before the password is compromised.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_libpwquality"/>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_enforce_root" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libpwquality; }; then

if [ -e "/etc/security/pwquality.conf" ] ; then
    
    LC_ALL=C sed -i "/^\s*enforce_for_root/Id" "/etc/security/pwquality.conf"
else
    touch "/etc/security/pwquality.conf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/security/pwquality.conf"

cp "/etc/security/pwquality.conf" "/etc/security/pwquality.conf.bak"
# Insert at the end of the file
printf '%s\n' "enforce_for_root" &gt;&gt; "/etc/security/pwquality.conf"
# Clean up after ourselves.
rm "/etc/security/pwquality.conf.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_enforce_root" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - accounts_password_pam_enforce_root
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure PAM Enforces Password Requirements - Enforce for root User
  ansible.builtin.lineinfile:
    path: /etc/security/pwquality.conf
    create: true
    regexp: ''
    line: enforce_for_root
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - accounts_password_pam_enforce_root
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_enforce_root:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_enforce_root_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_lcredit" selected="false" severity="medium">
                  <xccdf-1.2:title>Ensure PAM Enforces Password Requirements - Minimum Lowercase Characters</xccdf-1.2:title>
                  <xccdf-1.2:description>The pam_pwquality module's <html:code>lcredit</html:code> parameter controls requirements for
usage of lowercase letters in a password. When set to a negative number, any password will be required to
contain that many lowercase characters. When set to a positive number, pam_pwquality will grant +1 additional
length credit for each lowercase character. Modify the <html:code>lcredit</html:code> setting in
<html:code>/etc/security/pwquality.conf</html:code> to require the use of a lowercase character in passwords.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(c)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(4)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000070-GPOS-00038</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R31</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020120</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230358r1017170_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Use of a complex password helps to increase the time and resources required
to compromise the password. Password complexity, or strength, is a measure of
the effectiveness of a password in resisting attempts at guessing and brute-force
attacks.
<html:br/>
Password complexity is one factor of several that determines how long it takes
to crack a password. The more complex the password, the greater the number of
possible combinations that need to be tested before the password is compromised.
Requiring a minimum number of lowercase characters makes password guessing attacks
more difficult by ensuring a larger search space.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_libpwquality"/>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_lcredit" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libpwquality; }; then

var_password_pam_lcredit='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_lcredit" use="legacy"/>'












# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^lcredit")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_password_pam_lcredit"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^lcredit\\&gt;" "/etc/security/pwquality.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^lcredit\\&gt;.*/$escaped_formatted_output/gi" "/etc/security/pwquality.conf"
else
    if [[ -s "/etc/security/pwquality.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/security/pwquality.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/security/pwquality.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/security/pwquality.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_lcredit" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020120
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.3
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.6
  - accounts_password_pam_lcredit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_password_pam_lcredit # promote to variable
  set_fact:
    var_password_pam_lcredit: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_lcredit" use="legacy"/>
  tags:
    - always

- name: Ensure PAM Enforces Password Requirements - Minimum Lowercase Characters -
    Ensure PAM variable lcredit is set accordingly
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/security/pwquality.conf
    regexp: ^#?\s*lcredit
    line: lcredit = {{ var_password_pam_lcredit }}
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020120
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.3
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.6
  - accounts_password_pam_lcredit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_lcredit:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_lcredit"/>
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_lcredit:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_lcredit_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxclassrepeat" selected="false" severity="medium">
                  <xccdf-1.2:title>Ensure PAM Enforces Password Requirements - Maximum Consecutive Repeating Characters from Same Character Class</xccdf-1.2:title>
                  <xccdf-1.2:description>The pam_pwquality module's <html:code>maxclassrepeat</html:code> parameter controls requirements for
consecutive repeating characters from the same character class. When set to a positive number, it will reject passwords
which contain more than that number of consecutive characters from the same character class. Modify the
<html:code>maxclassrepeat</html:code> setting in <html:code>/etc/security/pwquality.conf</html:code> to equal <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_maxclassrepeat" use="legacy"/>
to prevent a run of (<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_maxclassrepeat" use="legacy"/> + 1) or more identical characters.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(c)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(4)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000072-GPOS-00040</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000730-GPOS-00190</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020140</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230360r1017172_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Use of a complex password helps to increase the time and resources required to compromise the password.
Password complexity, or strength, is a measure of the effectiveness of a password in resisting
attempts at guessing and brute-force attacks.
<html:br/>
Password complexity is one factor of several that determines how long it takes to crack a password. The
more complex a password, the greater the number of possible combinations that need to be tested before the
password is compromised.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_libpwquality"/>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_maxclassrepeat" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libpwquality; }; then

var_password_pam_maxclassrepeat='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_maxclassrepeat" use="legacy"/>'












# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^maxclassrepeat")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_password_pam_maxclassrepeat"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^maxclassrepeat\\&gt;" "/etc/security/pwquality.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^maxclassrepeat\\&gt;.*/$escaped_formatted_output/gi" "/etc/security/pwquality.conf"
else
    if [[ -s "/etc/security/pwquality.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/security/pwquality.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/security/pwquality.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/security/pwquality.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_maxclassrepeat" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020140
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - accounts_password_pam_maxclassrepeat
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_password_pam_maxclassrepeat # promote to variable
  set_fact:
    var_password_pam_maxclassrepeat: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_maxclassrepeat" use="legacy"/>
  tags:
    - always

- name: Ensure PAM Enforces Password Requirements - Maximum Consecutive Repeating
    Characters from Same Character Class - Ensure PAM variable maxclassrepeat is set
    accordingly
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/security/pwquality.conf
    regexp: ^#?\s*maxclassrepeat
    line: maxclassrepeat = {{ var_password_pam_maxclassrepeat }}
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020140
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - accounts_password_pam_maxclassrepeat
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_maxclassrepeat:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_maxclassrepeat"/>
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_maxclassrepeat:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_maxclassrepeat_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxrepeat" selected="false" severity="medium">
                  <xccdf-1.2:title>Set Password Maximum Consecutive Repeating Characters</xccdf-1.2:title>
                  <xccdf-1.2:description>The pam_pwquality module's <html:code>maxrepeat</html:code> parameter controls requirements for
consecutive repeating characters. When set to a positive number, it will reject passwords
which contain more than that number of consecutive characters. Modify the <html:code>maxrepeat</html:code> setting
in <html:code>/etc/security/pwquality.conf</html:code> to equal <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_maxrepeat" use="legacy"/> to prevent a
run of (<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_maxrepeat" use="legacy"/> + 1) or more identical characters.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(c)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(4)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000072-GPOS-00040</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020150</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230361r1017173_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Use of a complex password helps to increase the time and resources required to compromise the password.
Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at
guessing and brute-force attacks.
<html:br/><html:br/>
Password complexity is one factor of several that determines how long it takes to crack a password. The more
complex the password, the greater the number of possible combinations that need to be tested before the
password is compromised.
<html:br/><html:br/>
Passwords with excessive repeating characters may be more vulnerable to password-guessing attacks.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_libpwquality"/>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_maxrepeat" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libpwquality; }; then

var_password_pam_maxrepeat='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_maxrepeat" use="legacy"/>'












# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^maxrepeat")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_password_pam_maxrepeat"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^maxrepeat\\&gt;" "/etc/security/pwquality.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^maxrepeat\\&gt;.*/$escaped_formatted_output/gi" "/etc/security/pwquality.conf"
else
    if [[ -s "/etc/security/pwquality.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/security/pwquality.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/security/pwquality.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/security/pwquality.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_maxrepeat" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020150
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - accounts_password_pam_maxrepeat
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_password_pam_maxrepeat # promote to variable
  set_fact:
    var_password_pam_maxrepeat: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_maxrepeat" use="legacy"/>
  tags:
    - always

- name: Set Password Maximum Consecutive Repeating Characters - Ensure PAM variable
    maxrepeat is set accordingly
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/security/pwquality.conf
    regexp: ^#?\s*maxrepeat
    line: maxrepeat = {{ var_password_pam_maxrepeat }}
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020150
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - accounts_password_pam_maxrepeat
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_maxrepeat:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_maxrepeat"/>
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_maxrepeat:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_maxrepeat_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxsequence" selected="false" severity="medium">
                  <xccdf-1.2:title>Limit the maximum number of sequential characters in passwords</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>pwquality maxsequence</html:code> setting defines the maximum allowable length for consecutive 
character sequences in a new password. Such sequences can be, e.g., 123 or abc. If the value is 
set to 0, this check will be turned off.
<html:br/><html:br/>
Note: Passwords that consist mainly of such sequences are unlikely to meet the simplicity criteria 
unless the sequence constitutes only a small portion of the overall password.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.2.5</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Use of a strong password helps to increase the time and resources required to
compromise the password. Password complexity, or strength, is a measure of the
effectiveness of a password in resisting attempts at guessing and brute-force attacks.
<html:br/><html:br/>
Password complexity is one important factor that determines the duration required to crack it.
A more intricate password results in a larger number of potential combinations that must be 
tested before successfully compromising the password.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_libpwquality"/>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_maxsequence" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libpwquality; }; then

var_password_pam_maxsequence='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_maxsequence" use="legacy"/>'












# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^maxsequence")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_password_pam_maxsequence"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^maxsequence\\&gt;" "/etc/security/pwquality.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^maxsequence\\&gt;.*/$escaped_formatted_output/gi" "/etc/security/pwquality.conf"
else
    if [[ -s "/etc/security/pwquality.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/security/pwquality.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/security/pwquality.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/security/pwquality.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_maxsequence" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - accounts_password_pam_maxsequence
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_password_pam_maxsequence # promote to variable
  set_fact:
    var_password_pam_maxsequence: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_maxsequence" use="legacy"/>
  tags:
    - always

- name: Limit the maximum number of sequential characters in passwords - Ensure PAM
    variable maxsequence is set accordingly
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/security/pwquality.conf
    regexp: ^#?\s*maxsequence
    line: maxsequence = {{ var_password_pam_maxsequence }}
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - accounts_password_pam_maxsequence
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_maxsequence:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_maxsequence"/>
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_maxsequence:def:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_minclass" selected="false" severity="medium">
                  <xccdf-1.2:title>Ensure PAM Enforces Password Requirements - Minimum Different Categories</xccdf-1.2:title>
                  <xccdf-1.2:description>The pam_pwquality module's <html:code>minclass</html:code> parameter controls
requirements for usage of different character classes, or types, of character
that must exist in a password before it is considered valid. For example,
setting this value to three (3) requires that any password must have characters
from at least three different categories in order to be approved. The default
value is zero (0), meaning there are no required classes. There are four
categories available:
<html:pre>
* Upper-case characters
* Lower-case characters
* Digits
* Special characters (for example, punctuation)
</html:pre>
Modify the <html:code>minclass</html:code> setting in <html:code>/etc/security/pwquality.conf</html:code> entry
to require <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_minclass" use="legacy"/>
differing categories of characters when changing passwords.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(c)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(4)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000072-GPOS-00040</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R68</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020160</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230362r1017174_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Use of a complex password helps to increase the time and resources required to compromise the password.
Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts
at guessing and brute-force attacks.
<html:br/><html:br/>
Password complexity is one factor of several that determines how long it takes to crack a password. The
more complex the password, the greater the number of possible combinations that need to be tested before
the password is compromised.
<html:br/><html:br/>
Requiring a minimum number of character categories makes password guessing attacks more difficult
by ensuring a larger search space.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_libpwquality"/>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_minclass" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libpwquality; }; then

var_password_pam_minclass='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_minclass" use="legacy"/>'












# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^minclass")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_password_pam_minclass"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^minclass\\&gt;" "/etc/security/pwquality.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^minclass\\&gt;.*/$escaped_formatted_output/gi" "/etc/security/pwquality.conf"
else
    if [[ -s "/etc/security/pwquality.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/security/pwquality.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/security/pwquality.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/security/pwquality.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_minclass" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020160
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - accounts_password_pam_minclass
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_password_pam_minclass # promote to variable
  set_fact:
    var_password_pam_minclass: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_minclass" use="legacy"/>
  tags:
    - always

- name: Ensure PAM Enforces Password Requirements - Minimum Different Categories -
    Ensure PAM variable minclass is set accordingly
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/security/pwquality.conf
    regexp: ^#?\s*minclass
    line: minclass = {{ var_password_pam_minclass }}
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020160
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - accounts_password_pam_minclass
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_minclass:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_minclass"/>
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_minclass:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_minclass_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_minlen" selected="false" severity="medium">
                  <xccdf-1.2:title>Ensure PAM Enforces Password Requirements - Minimum Length</xccdf-1.2:title>
                  <xccdf-1.2:description>The pam_pwquality module's <html:code>minlen</html:code> parameter controls requirements for
minimum characters required in a password. Add <html:code>minlen=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" use="legacy"/></html:code>
after pam_pwquality to set minimum password length requirements.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.6.2.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(c)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(4)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000078-GPOS-00046</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R31</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R68</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020230</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230369r1017181_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>The shorter the password, the lower the number of possible combinations
that need to be tested before the password is compromised.
<html:br/>
Password complexity, or strength, is a measure of the effectiveness of a
password in resisting attempts at guessing and brute-force attacks.
Password length is one factor of several that helps to determine strength
and how long it takes to crack a password. Use of more characters in a password
helps to exponentially increase the time and/or resources required to
compromise the password.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_libpwquality"/>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_minlen" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libpwquality; }; then

var_password_pam_minlen='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" use="legacy"/>'












# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^minlen")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_password_pam_minlen"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^minlen\\&gt;" "/etc/security/pwquality.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^minlen\\&gt;.*/$escaped_formatted_output/gi" "/etc/security/pwquality.conf"
else
    if [[ -s "/etc/security/pwquality.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/security/pwquality.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/security/pwquality.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/security/pwquality.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_minlen" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.6.2.1.1
  - DISA-STIG-RHEL-08-020230
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.3
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.6
  - accounts_password_pam_minlen
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_password_pam_minlen # promote to variable
  set_fact:
    var_password_pam_minlen: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" use="legacy"/>
  tags:
    - always

- name: Ensure PAM Enforces Password Requirements - Minimum Length - Ensure PAM variable
    minlen is set accordingly
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/security/pwquality.conf
    regexp: ^#?\s*minlen
    line: minlen = {{ var_password_pam_minlen }}
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.1.1
  - DISA-STIG-RHEL-08-020230
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.3
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.6
  - accounts_password_pam_minlen
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_minlen:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_minlen"/>
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_minlen:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_minlen_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_ocredit" selected="false" severity="medium">
                  <xccdf-1.2:title>Ensure PAM Enforces Password Requirements - Minimum Special Characters</xccdf-1.2:title>
                  <xccdf-1.2:description>The pam_pwquality module's <html:code>ocredit=</html:code> parameter controls requirements for
usage of special (or "other") characters in a password. When set to a negative number,
any password will be required to contain that many special characters.
When set to a positive number, pam_pwquality will grant +1
additional length credit for each special character. Modify the <html:code>ocredit</html:code> setting
in <html:code>/etc/security/pwquality.conf</html:code> to equal <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_ocredit" use="legacy"/>
to require use of a special character in passwords.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(c)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(4)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000266-GPOS-00101</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R31</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020280</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230375r1017187_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Use of a complex password helps to increase the time and resources required
to compromise the password. Password complexity, or strength, is a measure of
the effectiveness of a password in resisting attempts at guessing and brute-force
attacks.
<html:br/><html:br/>
Password complexity is one factor of several that determines how long it takes
to crack a password. The more complex the password, the greater the number of
possible combinations that need to be tested before the password is compromised.
Requiring a minimum number of special characters makes password guessing attacks
more difficult by ensuring a larger search space.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_libpwquality"/>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_ocredit" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libpwquality; }; then

var_password_pam_ocredit='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_ocredit" use="legacy"/>'












# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^ocredit")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_password_pam_ocredit"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^ocredit\\&gt;" "/etc/security/pwquality.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^ocredit\\&gt;.*/$escaped_formatted_output/gi" "/etc/security/pwquality.conf"
else
    if [[ -s "/etc/security/pwquality.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/security/pwquality.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/security/pwquality.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/security/pwquality.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_ocredit" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020280
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - accounts_password_pam_ocredit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_password_pam_ocredit # promote to variable
  set_fact:
    var_password_pam_ocredit: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_ocredit" use="legacy"/>
  tags:
    - always

- name: Ensure PAM Enforces Password Requirements - Minimum Special Characters - Ensure
    PAM variable ocredit is set accordingly
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/security/pwquality.conf
    regexp: ^#?\s*ocredit
    line: ocredit = {{ var_password_pam_ocredit }}
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020280
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - accounts_password_pam_ocredit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_ocredit:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_ocredit"/>
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_ocredit:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_ocredit_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwquality_password_auth" selected="false" severity="medium">
                  <xccdf-1.2:title>Ensure PAM password complexity module is enabled in password-auth</xccdf-1.2:title>
                  <xccdf-1.2:description>To enable PAM password complexity in password-auth file:
Edit the <html:code>password</html:code> section in
<html:code>/etc/pam.d/password-auth</html:code> to show
<html:code>password    requisite                                    pam_pwquality.so</html:code>.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000069-GPOS-00037</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000070-GPOS-00038</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020100</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230356r982195_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Enabling PAM password complexity permits to enforce strong passwords and consequently
makes the system less prone to dictionary attacks.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_libpwquality"/>
                  <xccdf-1.2:fix id="accounts_password_pam_pwquality_password_auth" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libpwquality; }; then

if [ -e "/etc/pam.d/password-auth" ] ; then
    PAM_FILE_PATH="/etc/pam.d/password-auth"
    if [ -f /usr/bin/authselect ]; then
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "/etc/pam.d/password-auth")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
    fi
    
if ! grep -qP "^\s*password\s+requisite\s+pam_pwquality.so\s*.*" "$PAM_FILE_PATH"; then
    # Line matching group + control + module was not found. Check group + module.
    if [ "$(grep -cP '^\s*password\s+.*\s+pam_pwquality.so\s*' "$PAM_FILE_PATH")" -eq 1 ]; then
        # The control is updated only if one single line matches.
        sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_pwquality.so.*)/\1requisite \2/" "$PAM_FILE_PATH"
    else
        LAST_MATCH_LINE=$(grep -nP "^account.*required.*pam_permit\.so" "$PAM_FILE_PATH" | tail -n 1 | cut -d: -f 1)
        if [ ! -z $LAST_MATCH_LINE ]; then
            sed -i --follow-symlinks $LAST_MATCH_LINE" a password     requisite    pam_pwquality.so" "$PAM_FILE_PATH"
        else
            echo "password    requisite    pam_pwquality.so" &gt;&gt; "$PAM_FILE_PATH"
        fi
    fi
fi
    if [ -f /usr/bin/authselect ]; then
        
        authselect apply-changes -b
    fi
else
    echo "/etc/pam.d/password-auth was not found" &gt;&amp;2
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="medium" id="accounts_password_pam_pwquality_password_auth" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020100
  - accounts_password_pam_pwquality_password_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure PAM password complexity module is enabled in password-auth - Check
    if /etc/pam.d/password-auth file is present
  ansible.builtin.stat:
    path: /etc/pam.d/password-auth
  register: result_pam_password_auth_file_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020100
  - accounts_password_pam_pwquality_password_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure PAM password complexity module is enabled in password-auth - Check
    the proper remediation for the system
  block:

  - name: Ensure PAM password complexity module is enabled in password-auth - Define
      the PAM file to be edited as a local fact
    ansible.builtin.set_fact:
      pam_file_path: /etc/pam.d/password-auth

  - name: Ensure PAM password complexity module is enabled in password-auth - Check
      if system relies on authselect tool
    ansible.builtin.stat:
      path: /usr/bin/authselect
    register: result_authselect_present

  - name: Ensure PAM password complexity module is enabled in password-auth - Ensure
      authselect custom profile is used if authselect is present
    block:

    - name: Ensure PAM password complexity module is enabled in password-auth - Check
        integrity of authselect current profile
      ansible.builtin.command:
        cmd: authselect check
      register: result_authselect_check_cmd
      changed_when: false
      check_mode: false
      failed_when: false

    - name: Ensure PAM password complexity module is enabled in password-auth - Informative
        message based on the authselect integrity check result
      ansible.builtin.assert:
        that:
        - ansible_check_mode or result_authselect_check_cmd.rc == 0
        fail_msg:
        - authselect integrity check failed. Remediation aborted!
        - This remediation could not be applied because an authselect profile was
          not selected or the selected profile is not intact.
        - It is not recommended to manually edit the PAM files when authselect tool
          is available.
        - In cases where the default authselect profile does not cover a specific
          demand, a custom authselect profile is recommended.
        success_msg:
        - authselect integrity check passed

    - name: Ensure PAM password complexity module is enabled in password-auth - Get
        authselect current profile
      ansible.builtin.shell:
        cmd: authselect current -r | awk '{ print $1 }'
      register: result_authselect_profile
      changed_when: false
      when:
      - result_authselect_check_cmd is success

    - name: Ensure PAM password complexity module is enabled in password-auth - Define
        the current authselect profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is match("custom/")

    - name: Ensure PAM password complexity module is enabled in password-auth - Define
        the new authselect custom profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: custom/hardening
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is not match("custom/")

    - name: Ensure PAM password complexity module is enabled in password-auth - Get
        authselect current features to also enable them in the custom profile
      ansible.builtin.shell:
        cmd: authselect current | tail -n+3 | awk '{ print $2 }'
      register: result_authselect_features
      changed_when: false
      check_mode: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Ensure PAM password complexity module is enabled in password-auth - Check
        if any custom profile with the same name was already created
      ansible.builtin.stat:
        path: /etc/authselect/{{ authselect_custom_profile }}
      register: result_authselect_custom_profile_present
      changed_when: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Ensure PAM password complexity module is enabled in password-auth - Create
        an authselect custom profile based on the current profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b {{ authselect_current_profile
          }}
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is not match("^(custom/|local)")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Ensure PAM password complexity module is enabled in password-auth - Create
        an authselect custom profile based on sssd profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b sssd
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is match("local")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Ensure PAM password complexity module is enabled in password-auth - Ensure
        authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Ensure PAM password complexity module is enabled in password-auth - Ensure
        the authselect custom profile is selected
      ansible.builtin.command:
        cmd: authselect select {{ authselect_custom_profile }}
      register: result_pam_authselect_select_profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Ensure PAM password complexity module is enabled in password-auth - Restore
        the authselect features in the custom profile
      ansible.builtin.command:
        cmd: authselect enable-feature {{ item }}
      loop: '{{ result_authselect_features.stdout_lines }}'
      register: result_pam_authselect_restore_features
      when:
      - result_authselect_profile is not skipped
      - result_authselect_features is not skipped
      - result_pam_authselect_select_profile is not skipped

    - name: Ensure PAM password complexity module is enabled in password-auth - Ensure
        authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - result_pam_authselect_restore_features is not skipped

    - name: Ensure PAM password complexity module is enabled in password-auth - Change
        the PAM file to be edited according to the custom authselect profile
      ansible.builtin.set_fact:
        pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
          | basename }}
      when:
      - authselect_custom_profile is defined
    when:
    - result_authselect_present.stat.exists

  - name: Ensure PAM password complexity module is enabled in password-auth - Define
      a fact for control already filtered in case filters are used
    ansible.builtin.set_fact:
      pam_module_control: requisite

  - name: Ensure PAM password complexity module is enabled in password-auth - Check
      if expected PAM module line is present in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwquality.so\s*.*
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_line_present

  - name: Ensure PAM password complexity module is enabled in password-auth - Include
      or update the PAM module line in {{ pam_file_path }}
    block:

    - name: Ensure PAM password complexity module is enabled in password-auth - Check
        if required PAM module line is present in {{ pam_file_path }} with different
        control
      ansible.builtin.lineinfile:
        path: '{{ pam_file_path }}'
        regexp: ^\s*password\s+.*\s+pam_pwquality.so\s*
        state: absent
      check_mode: true
      changed_when: false
      register: result_pam_line_other_control_present

    - name: Ensure PAM password complexity module is enabled in password-auth - Ensure
        the correct control for the required PAM module line in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: ^(\s*password\s+).*(\bpam_pwquality.so.*)
        replace: \1{{ pam_module_control }} \2
      register: result_pam_module_edit
      when:
      - result_pam_line_other_control_present.found == 1

    - name: Ensure PAM password complexity module is enabled in password-auth - Ensure
        the required PAM module line is included in {{ pam_file_path }}
      ansible.builtin.lineinfile:
        dest: '{{ pam_file_path }}'
        insertafter: ^account.*required.*pam_permit\.so
        line: password    {{ pam_module_control }}    pam_pwquality.so
      register: result_pam_module_add
      when:
      - result_pam_line_other_control_present.found == 0 or result_pam_line_other_control_present.found
        &gt; 1

    - name: Ensure PAM password complexity module is enabled in password-auth - Ensure
        authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present is defined
      - result_authselect_present.stat.exists
      - |-
        (result_pam_module_add is defined and result_pam_module_add.changed)
         or (result_pam_module_edit is defined and result_pam_module_edit.changed)
    when:
    - result_pam_line_present.found is defined
    - result_pam_line_present.found == 0

  - name: Ensure PAM password complexity module is enabled in password-auth - Ensure
      authselect changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_present.stat.exists
    - |-
      (result_pam_accounts_password_pam_pwquality_password_auth_add is defined and result_pam_accounts_password_pam_pwquality_password_auth_add.changed)
       or (result_pam_accounts_password_pam_pwquality_password_auth_edit is defined and result_pam_accounts_password_pam_pwquality_password_auth_edit.changed)
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  - result_pam_password_auth_file_present.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020100
  - accounts_password_pam_pwquality_password_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_pwquality_password_auth:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_pwquality_password_auth_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_pwquality_system_auth" selected="false" severity="medium">
                  <xccdf-1.2:title>Ensure PAM password complexity module is enabled in system-auth</xccdf-1.2:title>
                  <xccdf-1.2:description>To enable PAM password complexity in system-auth file:
Edit the <html:code>password</html:code> section in
<html:code>/etc/pam.d/system-auth</html:code> to show
<html:code>password    requisite                                    pam_pwquality.so</html:code>.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020101</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-251713r1017366_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Enabling PAM password complexity permits to enforce strong passwords and consequently
makes the system less prone to dictionary attacks.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_libpwquality"/>
                  <xccdf-1.2:fix id="accounts_password_pam_pwquality_system_auth" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libpwquality; }; then

if [ -e "/etc/pam.d/system-auth" ] ; then
    PAM_FILE_PATH="/etc/pam.d/system-auth"
    if [ -f /usr/bin/authselect ]; then
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "/etc/pam.d/system-auth")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
    fi
    
if ! grep -qP "^\s*password\s+requisite\s+pam_pwquality.so\s*.*" "$PAM_FILE_PATH"; then
    # Line matching group + control + module was not found. Check group + module.
    if [ "$(grep -cP '^\s*password\s+.*\s+pam_pwquality.so\s*' "$PAM_FILE_PATH")" -eq 1 ]; then
        # The control is updated only if one single line matches.
        sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_pwquality.so.*)/\1requisite \2/" "$PAM_FILE_PATH"
    else
        LAST_MATCH_LINE=$(grep -nP "^account.*required.*pam_permit\.so" "$PAM_FILE_PATH" | tail -n 1 | cut -d: -f 1)
        if [ ! -z $LAST_MATCH_LINE ]; then
            sed -i --follow-symlinks $LAST_MATCH_LINE" a password     requisite    pam_pwquality.so" "$PAM_FILE_PATH"
        else
            echo "password    requisite    pam_pwquality.so" &gt;&gt; "$PAM_FILE_PATH"
        fi
    fi
fi
    if [ -f /usr/bin/authselect ]; then
        
        authselect apply-changes -b
    fi
else
    echo "/etc/pam.d/system-auth was not found" &gt;&amp;2
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="medium" id="accounts_password_pam_pwquality_system_auth" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020101
  - accounts_password_pam_pwquality_system_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure PAM password complexity module is enabled in system-auth - Check if
    /etc/pam.d/system-auth file is present
  ansible.builtin.stat:
    path: /etc/pam.d/system-auth
  register: result_pam_auth_file_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020101
  - accounts_password_pam_pwquality_system_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure PAM password complexity module is enabled in system-auth - Check the
    proper remediation for the system
  block:

  - name: Ensure PAM password complexity module is enabled in system-auth - Define
      the PAM file to be edited as a local fact
    ansible.builtin.set_fact:
      pam_file_path: /etc/pam.d/system-auth

  - name: Ensure PAM password complexity module is enabled in system-auth - Check
      if system relies on authselect tool
    ansible.builtin.stat:
      path: /usr/bin/authselect
    register: result_authselect_present

  - name: Ensure PAM password complexity module is enabled in system-auth - Ensure
      authselect custom profile is used if authselect is present
    block:

    - name: Ensure PAM password complexity module is enabled in system-auth - Check
        integrity of authselect current profile
      ansible.builtin.command:
        cmd: authselect check
      register: result_authselect_check_cmd
      changed_when: false
      check_mode: false
      failed_when: false

    - name: Ensure PAM password complexity module is enabled in system-auth - Informative
        message based on the authselect integrity check result
      ansible.builtin.assert:
        that:
        - ansible_check_mode or result_authselect_check_cmd.rc == 0
        fail_msg:
        - authselect integrity check failed. Remediation aborted!
        - This remediation could not be applied because an authselect profile was
          not selected or the selected profile is not intact.
        - It is not recommended to manually edit the PAM files when authselect tool
          is available.
        - In cases where the default authselect profile does not cover a specific
          demand, a custom authselect profile is recommended.
        success_msg:
        - authselect integrity check passed

    - name: Ensure PAM password complexity module is enabled in system-auth - Get
        authselect current profile
      ansible.builtin.shell:
        cmd: authselect current -r | awk '{ print $1 }'
      register: result_authselect_profile
      changed_when: false
      when:
      - result_authselect_check_cmd is success

    - name: Ensure PAM password complexity module is enabled in system-auth - Define
        the current authselect profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is match("custom/")

    - name: Ensure PAM password complexity module is enabled in system-auth - Define
        the new authselect custom profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: custom/hardening
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is not match("custom/")

    - name: Ensure PAM password complexity module is enabled in system-auth - Get
        authselect current features to also enable them in the custom profile
      ansible.builtin.shell:
        cmd: authselect current | tail -n+3 | awk '{ print $2 }'
      register: result_authselect_features
      changed_when: false
      check_mode: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Ensure PAM password complexity module is enabled in system-auth - Check
        if any custom profile with the same name was already created
      ansible.builtin.stat:
        path: /etc/authselect/{{ authselect_custom_profile }}
      register: result_authselect_custom_profile_present
      changed_when: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Ensure PAM password complexity module is enabled in system-auth - Create
        an authselect custom profile based on the current profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b {{ authselect_current_profile
          }}
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is not match("^(custom/|local)")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Ensure PAM password complexity module is enabled in system-auth - Create
        an authselect custom profile based on sssd profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b sssd
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is match("local")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Ensure PAM password complexity module is enabled in system-auth - Ensure
        authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Ensure PAM password complexity module is enabled in system-auth - Ensure
        the authselect custom profile is selected
      ansible.builtin.command:
        cmd: authselect select {{ authselect_custom_profile }}
      register: result_pam_authselect_select_profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Ensure PAM password complexity module is enabled in system-auth - Restore
        the authselect features in the custom profile
      ansible.builtin.command:
        cmd: authselect enable-feature {{ item }}
      loop: '{{ result_authselect_features.stdout_lines }}'
      register: result_pam_authselect_restore_features
      when:
      - result_authselect_profile is not skipped
      - result_authselect_features is not skipped
      - result_pam_authselect_select_profile is not skipped

    - name: Ensure PAM password complexity module is enabled in system-auth - Ensure
        authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - result_pam_authselect_restore_features is not skipped

    - name: Ensure PAM password complexity module is enabled in system-auth - Change
        the PAM file to be edited according to the custom authselect profile
      ansible.builtin.set_fact:
        pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
          | basename }}
      when:
      - authselect_custom_profile is defined
    when:
    - result_authselect_present.stat.exists

  - name: Ensure PAM password complexity module is enabled in system-auth - Define
      a fact for control already filtered in case filters are used
    ansible.builtin.set_fact:
      pam_module_control: requisite

  - name: Ensure PAM password complexity module is enabled in system-auth - Check
      if expected PAM module line is present in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwquality.so\s*.*
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_line_present

  - name: Ensure PAM password complexity module is enabled in system-auth - Include
      or update the PAM module line in {{ pam_file_path }}
    block:

    - name: Ensure PAM password complexity module is enabled in system-auth - Check
        if required PAM module line is present in {{ pam_file_path }} with different
        control
      ansible.builtin.lineinfile:
        path: '{{ pam_file_path }}'
        regexp: ^\s*password\s+.*\s+pam_pwquality.so\s*
        state: absent
      check_mode: true
      changed_when: false
      register: result_pam_line_other_control_present

    - name: Ensure PAM password complexity module is enabled in system-auth - Ensure
        the correct control for the required PAM module line in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: ^(\s*password\s+).*(\bpam_pwquality.so.*)
        replace: \1{{ pam_module_control }} \2
      register: result_pam_module_edit
      when:
      - result_pam_line_other_control_present.found == 1

    - name: Ensure PAM password complexity module is enabled in system-auth - Ensure
        the required PAM module line is included in {{ pam_file_path }}
      ansible.builtin.lineinfile:
        dest: '{{ pam_file_path }}'
        insertafter: ^account.*required.*pam_permit\.so
        line: password    {{ pam_module_control }}    pam_pwquality.so
      register: result_pam_module_add
      when:
      - result_pam_line_other_control_present.found == 0 or result_pam_line_other_control_present.found
        &gt; 1

    - name: Ensure PAM password complexity module is enabled in system-auth - Ensure
        authselect changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present is defined
      - result_authselect_present.stat.exists
      - |-
        (result_pam_module_add is defined and result_pam_module_add.changed)
         or (result_pam_module_edit is defined and result_pam_module_edit.changed)
    when:
    - result_pam_line_present.found is defined
    - result_pam_line_present.found == 0

  - name: Ensure PAM password complexity module is enabled in system-auth - Ensure
      authselect changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_present.stat.exists
    - |-
      (result_pam_accounts_password_pam_pwquality_system_auth_add is defined and result_pam_accounts_password_pam_pwquality_system_auth_add.changed)
       or (result_pam_accounts_password_pam_pwquality_system_auth_edit is defined and result_pam_accounts_password_pam_pwquality_system_auth_edit.changed)
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  - result_pam_auth_file_present.stat.exists
  tags:
  - DISA-STIG-RHEL-08-020101
  - accounts_password_pam_pwquality_system_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_pwquality_system_auth:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_pwquality_system_auth_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_retry" selected="false" severity="medium">
                  <xccdf-1.2:title>Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted Per-Session</xccdf-1.2:title>
                  <xccdf-1.2:description>To configure the number of retry prompts that are permitted per-session:

Edit the <html:code>pam_pwquality.so</html:code> statement in

<html:code>/etc/pam.d/system-auth</html:code> to show


<html:code>retry=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_retry" use="legacy"/></html:code>, or a lower value if site
policy is more restrictive. The profile requirement is a maximum of <html:code>retry=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_retry" use="legacy"/></html:code> prompts
per session.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-7(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(4)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000069-GPOS-00037</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R68</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020104</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-251716r1069329_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Setting the password retry prompts that are permitted on a per-session basis to a low value
requires some software, such as SSH, to re-connect. This can slow down and
draw additional attention to some types of password-guessing attacks. Note that this
is different from account lockout, which is provided by the pam_faillock module.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_libpwquality"/>
                  <xccdf-1.2:fix id="accounts_password_pam_retry" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libpwquality; }; then

var_password_pam_retry='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_retry" use="legacy"/>'





	
		if [ -e "/etc/pam.d/system-auth" ] ; then
    PAM_FILE_PATH="/etc/pam.d/system-auth"
    if [ -f /usr/bin/authselect ]; then
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "/etc/pam.d/system-auth")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
    fi
    

        if ! grep -qP "^\s*password\s+requisite\s+pam_pwquality.so\s*.*" "$PAM_FILE_PATH"; then
            # Line matching group + control + module was not found. Check group + module.
            if [ "$(grep -cP '^\s*password\s+.*\s+pam_pwquality.so\s*' "$PAM_FILE_PATH")" -eq 1 ]; then
                # The control is updated only if one single line matches.
                sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_pwquality.so.*)/\1requisite \2/" "$PAM_FILE_PATH"
            else
                LAST_MATCH_LINE=$(grep -nP "^\s*account" "$PAM_FILE_PATH" | tail -n 1 | cut -d: -f 1)
                if [ ! -z $LAST_MATCH_LINE ]; then
                    sed -i --follow-symlinks $LAST_MATCH_LINE" a password     requisite    pam_pwquality.so" "$PAM_FILE_PATH"
                else
                    echo "password    requisite    pam_pwquality.so" &gt;&gt; "$PAM_FILE_PATH"
                fi
            fi
        fi
        # Check the option
        if ! grep -qP "^\s*password\s+requisite\s+pam_pwquality.so\s*.*\sretry\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "/\s*password\s+requisite\s+pam_pwquality.so.*/ s/$/ retry=$var_password_pam_retry/" "$PAM_FILE_PATH"
        else
            sed -i -E --follow-symlinks "s/(\s*password\s+requisite\s+pam_pwquality.so\s+.*)(retry=)[[:alnum:]]*\s*(.*)/\1\2$var_password_pam_retry \3/" "$PAM_FILE_PATH"
        fi
    if [ -f /usr/bin/authselect ]; then
        
        authselect apply-changes -b
    fi
else
    echo "/etc/pam.d/system-auth was not found" &gt;&amp;2
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="medium" id="accounts_password_pam_retry" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020104
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(4)
  - accounts_password_pam_retry
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
- name: XCCDF Value var_password_pam_retry # promote to variable
  set_fact:
    var_password_pam_retry: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_retry" use="legacy"/>
  tags:
    - always

- name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted
    Per-Session - Define a fact for control already filtered in case filters are used
  ansible.builtin.set_fact:
    pam_module_control: requisite
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020104
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(4)
  - accounts_password_pam_retry
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted
    Per-Session - Check if expected PAM module line is present in /etc/pam.d/password-auth
  ansible.builtin.lineinfile:
    path: /etc/pam.d/password-auth
    regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwquality.so\s*.*
    state: absent
  check_mode: true
  changed_when: false
  register: result_pam_line_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020104
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(4)
  - accounts_password_pam_retry
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted
    Per-Session - Include or update the PAM module line in /etc/pam.d/password-auth
  block:

  - name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts
      Permitted Per-Session - Check if required PAM module line is present in /etc/pam.d/password-auth
      with different control
    ansible.builtin.lineinfile:
      path: /etc/pam.d/password-auth
      regexp: ^\s*password\s+.*\s+pam_pwquality.so\s*
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_line_other_control_present

  - name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts
      Permitted Per-Session - Ensure the correct control for the required PAM module
      line in /etc/pam.d/password-auth
    ansible.builtin.replace:
      dest: /etc/pam.d/password-auth
      regexp: ^(\s*password\s+).*(\bpam_pwquality.so.*)
      replace: \1{{ pam_module_control }} \2
    register: result_pam_module_edit
    when:
    - result_pam_line_other_control_present.found == 1

  - name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts
      Permitted Per-Session - Ensure the required PAM module line is included in /etc/pam.d/password-auth
    ansible.builtin.lineinfile:
      dest: /etc/pam.d/password-auth
      insertafter: ^\s*account
      line: password    {{ pam_module_control }}    pam_pwquality.so
    register: result_pam_module_add
    when:
    - result_pam_line_other_control_present.found == 0 or result_pam_line_other_control_present.found
      &gt; 1

  - name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts
      Permitted Per-Session - Ensure authselect changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_present is defined
    - result_authselect_present.stat.exists
    - |-
      (result_pam_module_add is defined and result_pam_module_add.changed)
       or (result_pam_module_edit is defined and result_pam_module_edit.changed)
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  - result_pam_line_present.found is defined
  - result_pam_line_present.found == 0
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020104
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(4)
  - accounts_password_pam_retry
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted
    Per-Session - Define a fact for control already filtered in case filters are used
  ansible.builtin.set_fact:
    pam_module_control: requisite
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020104
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(4)
  - accounts_password_pam_retry
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted
    Per-Session - Check if the required PAM module option is present in /etc/pam.d/password-auth
  ansible.builtin.lineinfile:
    path: /etc/pam.d/password-auth
    regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwquality.so\s*.*\sretry\b
    state: absent
  check_mode: true
  changed_when: false
  register: result_pam_module_accounts_password_pam_retry_option_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020104
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(4)
  - accounts_password_pam_retry
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted
    Per-Session - Ensure the "retry" PAM option for "pam_pwquality.so" is included
    in /etc/pam.d/password-auth
  ansible.builtin.lineinfile:
    path: /etc/pam.d/password-auth
    backrefs: true
    regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwquality.so.*)
    line: \1 retry={{ var_password_pam_retry }}
    state: present
  register: result_pam_accounts_password_pam_retry_add
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  - result_pam_module_accounts_password_pam_retry_option_present.found is defined
  - result_pam_module_accounts_password_pam_retry_option_present.found == 0
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020104
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(4)
  - accounts_password_pam_retry
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted
    Per-Session - Ensure the required value for "retry" PAM option from "pam_pwquality.so"
    in /etc/pam.d/password-auth
  ansible.builtin.lineinfile:
    path: /etc/pam.d/password-auth
    backrefs: true
    regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwquality.so\s+.*)(retry)=[0-9a-zA-Z]*\s*(.*)
    line: \1\2={{ var_password_pam_retry }} \3
  register: result_pam_accounts_password_pam_retry_edit
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  - result_pam_module_accounts_password_pam_retry_option_present.found &gt; 0
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020104
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(4)
  - accounts_password_pam_retry
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted
    Per-Session - Define a fact for control already filtered in case filters are used
  ansible.builtin.set_fact:
    pam_module_control: requisite
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020104
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(4)
  - accounts_password_pam_retry
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted
    Per-Session - Check if expected PAM module line is present in /etc/pam.d/system-auth
  ansible.builtin.lineinfile:
    path: /etc/pam.d/system-auth
    regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwquality.so\s*.*
    state: absent
  check_mode: true
  changed_when: false
  register: result_pam_line_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020104
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(4)
  - accounts_password_pam_retry
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted
    Per-Session - Include or update the PAM module line in /etc/pam.d/system-auth
  block:

  - name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts
      Permitted Per-Session - Check if required PAM module line is present in /etc/pam.d/system-auth
      with different control
    ansible.builtin.lineinfile:
      path: /etc/pam.d/system-auth
      regexp: ^\s*password\s+.*\s+pam_pwquality.so\s*
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_line_other_control_present

  - name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts
      Permitted Per-Session - Ensure the correct control for the required PAM module
      line in /etc/pam.d/system-auth
    ansible.builtin.replace:
      dest: /etc/pam.d/system-auth
      regexp: ^(\s*password\s+).*(\bpam_pwquality.so.*)
      replace: \1{{ pam_module_control }} \2
    register: result_pam_module_edit
    when:
    - result_pam_line_other_control_present.found == 1

  - name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts
      Permitted Per-Session - Ensure the required PAM module line is included in /etc/pam.d/system-auth
    ansible.builtin.lineinfile:
      dest: /etc/pam.d/system-auth
      insertafter: ^\s*account
      line: password    {{ pam_module_control }}    pam_pwquality.so
    register: result_pam_module_add
    when:
    - result_pam_line_other_control_present.found == 0 or result_pam_line_other_control_present.found
      &gt; 1

  - name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts
      Permitted Per-Session - Ensure authselect changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_present is defined
    - result_authselect_present.stat.exists
    - |-
      (result_pam_module_add is defined and result_pam_module_add.changed)
       or (result_pam_module_edit is defined and result_pam_module_edit.changed)
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  - result_pam_line_present.found is defined
  - result_pam_line_present.found == 0
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020104
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(4)
  - accounts_password_pam_retry
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted
    Per-Session - Define a fact for control already filtered in case filters are used
  ansible.builtin.set_fact:
    pam_module_control: requisite
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020104
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(4)
  - accounts_password_pam_retry
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted
    Per-Session - Check if the required PAM module option is present in /etc/pam.d/system-auth
  ansible.builtin.lineinfile:
    path: /etc/pam.d/system-auth
    regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwquality.so\s*.*\sretry\b
    state: absent
  check_mode: true
  changed_when: false
  register: result_pam_module_accounts_password_pam_retry_option_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020104
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(4)
  - accounts_password_pam_retry
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted
    Per-Session - Ensure the "retry" PAM option for "pam_pwquality.so" is included
    in /etc/pam.d/system-auth
  ansible.builtin.lineinfile:
    path: /etc/pam.d/system-auth
    backrefs: true
    regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwquality.so.*)
    line: \1 retry={{ var_password_pam_retry }}
    state: present
  register: result_pam_accounts_password_pam_retry_add
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  - result_pam_module_accounts_password_pam_retry_option_present.found is defined
  - result_pam_module_accounts_password_pam_retry_option_present.found == 0
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020104
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(4)
  - accounts_password_pam_retry
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted
    Per-Session - Ensure the required value for "retry" PAM option from "pam_pwquality.so"
    in /etc/pam.d/system-auth
  ansible.builtin.lineinfile:
    path: /etc/pam.d/system-auth
    backrefs: true
    regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_pwquality.so\s+.*)(retry)=[0-9a-zA-Z]*\s*(.*)
    line: \1\2={{ var_password_pam_retry }} \3
  register: result_pam_accounts_password_pam_retry_edit
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  - result_pam_module_accounts_password_pam_retry_option_present.found &gt; 0
  tags:
  - CJIS-5.5.3
  - DISA-STIG-RHEL-08-020104
  - NIST-800-53-AC-7(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(4)
  - accounts_password_pam_retry
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_retry:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_retry"/>
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_retry:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_retry_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_ucredit" selected="false" severity="medium">
                  <xccdf-1.2:title>Ensure PAM Enforces Password Requirements - Minimum Uppercase Characters</xccdf-1.2:title>
                  <xccdf-1.2:description>The pam_pwquality module's <html:code>ucredit=</html:code> parameter controls requirements for
usage of uppercase letters in a password. When set to a negative number, any password will be required to
contain that many uppercase characters. When set to a positive number, pam_pwquality will grant +1 additional
length credit for each uppercase character. Modify the <html:code>ucredit</html:code> setting in
<html:code>/etc/security/pwquality.conf</html:code> to require the use of an uppercase character in passwords.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(c)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(4)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000069-GPOS-00037</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000070-GPOS-00038</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R31</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020110</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230357r1017169_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Use of a complex password helps to increase the time and resources required to compromise the password.
Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts
at guessing and brute-force attacks.
<html:br/><html:br/>
Password complexity is one factor of several that determines how long it takes to crack a password. The more
complex the password, the greater the number of possible combinations that need to be tested before
the password is compromised.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_libpwquality"/>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_ucredit" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libpwquality; }; then

var_password_pam_ucredit='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_ucredit" use="legacy"/>'












# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^ucredit")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_password_pam_ucredit"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^ucredit\\&gt;" "/etc/security/pwquality.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^ucredit\\&gt;.*/$escaped_formatted_output/gi" "/etc/security/pwquality.conf"
else
    if [[ -s "/etc/security/pwquality.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/security/pwquality.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/security/pwquality.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/security/pwquality.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_pam_ucredit" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020110
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.3
  - accounts_password_pam_ucredit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_password_pam_ucredit # promote to variable
  set_fact:
    var_password_pam_ucredit: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_ucredit" use="legacy"/>
  tags:
    - always

- name: Ensure PAM Enforces Password Requirements - Minimum Uppercase Characters -
    Ensure PAM variable ucredit is set accordingly
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/security/pwquality.conf
    regexp: ^#?\s*ucredit
    line: ucredit = {{ var_password_pam_ucredit }}
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libpwquality" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020110
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(4)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.3
  - accounts_password_pam_ucredit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_ucredit:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_ucredit"/>
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_ucredit:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_ucredit_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
              </xccdf-1.2:Group>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_set_password_hashing_algorithm">
              <xccdf-1.2:title>Set Password Hashing Algorithm</xccdf-1.2:title>
              <xccdf-1.2:description>The system's default algorithm for storing password hashes in
<html:code>/etc/shadow</html:code> is SHA-512. This can be configured in several
locations.</xccdf-1.2:description>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_hashing_min_rounds_login_defs" type="number">
                <xccdf-1.2:title>Minimum number of password hashing rounds configured through /etc/login.defs</xccdf-1.2:title>
                <xccdf-1.2:description>Minimum number of password hashing rounds configured through /etc/login.defs</xccdf-1.2:description>
                <xccdf-1.2:value>5000</xccdf-1.2:value>
                <xccdf-1.2:value selector="5000">5000</xccdf-1.2:value>
                <xccdf-1.2:value selector="100000">100000</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_libuserconf" selected="false" severity="medium">
                <xccdf-1.2:title>Set Password Hashing Algorithm in /etc/libuser.conf</xccdf-1.2:title>
                <xccdf-1.2:description>In <html:code>/etc/libuser.conf</html:code>, add or correct the following line in its <html:code>[defaults]</html:code>
section to ensure the system will use the <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" use="legacy"/>
algorithm for password hashing:
<html:pre>crypt_style = <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" use="legacy"/></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.6.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.13.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000073-GPOS-00041</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0418</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1055</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1402</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Passwords need to be protected at all times, and encryption is the standard method for
protecting passwords. If passwords are not encrypted, they can be plainly read
(i.e., clear text) and easily compromised. Passwords that are encrypted with a weak algorithm
are no more protected than if they are kept in plain text.
<html:br/><html:br/>
This setting ensures user and group account administration utilities are configured to store
only encrypted representations of passwords. Additionally, the <html:code>crypt_style</html:code>
configuration option in <html:code>/etc/libuser.conf</html:code> ensures the use of a strong hashing
algorithm that makes password cracking attacks more difficult.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_libuser"/>
                <xccdf-1.2:fix id="set_password_hashing_algorithm_libuserconf" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q libuser; }; then

var_password_hashing_algorithm_pam='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" use="legacy"/>'

LIBUSER_CONF="/etc/libuser.conf"
CRYPT_STYLE_REGEX='[[:space:]]*\[defaults](.*(\n)+)+?[[:space:]]*crypt_style[[:space:]]*'

# Try find crypt_style in [defaults] section. If it is here, then change algorithm to sha512.
# If it isn't here, then add it to [defaults] section.
if grep -qzosP $CRYPT_STYLE_REGEX $LIBUSER_CONF ; then
        sed -i "s/\(crypt_style[[:space:]]*=[[:space:]]*\).*/\1$var_password_hashing_algorithm_pam/g" $LIBUSER_CONF
elif grep -qs "\[defaults]" $LIBUSER_CONF ; then
        sed -i "/[[:space:]]*\[defaults]/a crypt_style = $var_password_hashing_algorithm_pam" $LIBUSER_CONF
else
        echo -e "[defaults]\ncrypt_style = $var_password_hashing_algorithm_pam" &gt;&gt; $LIBUSER_CONF
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="set_password_hashing_algorithm_libuserconf" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.6.2.2
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.1
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.2
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - set_password_hashing_algorithm_libuserconf
- name: XCCDF Value var_password_hashing_algorithm_pam # promote to variable
  set_fact:
    var_password_hashing_algorithm_pam: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" use="legacy"/>
  tags:
    - always

- name: Set Password Hashing Algorithm in /etc/libuser.conf - Set Password Hashing
    Algorithm in /etc/libuser.conf
  ansible.builtin.lineinfile:
    dest: /etc/libuser.conf
    insertafter: ^\s*\[defaults]
    regexp: ^#?crypt_style
    line: crypt_style = {{ var_password_hashing_algorithm_pam }}
    state: present
    create: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"libuser" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.2
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.1
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.2
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - set_password_hashing_algorithm_libuserconf
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_password_hashing_algorithm_pam:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-set_password_hashing_algorithm_libuserconf:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-set_password_hashing_algorithm_libuserconf_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_logindefs" selected="false" severity="medium">
                <xccdf-1.2:title>Set Password Hashing Algorithm in /etc/login.defs</xccdf-1.2:title>
                <xccdf-1.2:description>In <html:code>/etc/login.defs</html:code>, add or update the following line to ensure the system will use
<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm" use="legacy"/> as the hashing algorithm:
<html:pre>ENCRYPT_METHOD <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm" use="legacy"/></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.6.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.13.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000073-GPOS-00041</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0418</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1055</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1402</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010110</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230231r1017050_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Passwords need to be protected at all times, and encryption is the standard method for
protecting passwords. If passwords are not encrypted, they can be plainly read
(i.e., clear text) and easily compromised. Passwords that are encrypted with a weak algorithm
are no more protected than if they are kept in plain text.
<html:br/><html:br/>
Using a stronger hashing algorithm makes password cracking attacks more difficult.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_shadow-utils"/>
                <xccdf-1.2:fix id="set_password_hashing_algorithm_logindefs" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q shadow-utils; }; then

var_password_hashing_algorithm='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm" use="legacy"/>'


# Allow multiple algorithms, but choose the first one for remediation
#
var_password_hashing_algorithm="$(echo $var_password_hashing_algorithm | cut -d \| -f 1)"


# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^ENCRYPT_METHOD")

# shellcheck disable=SC2059
printf -v formatted_output "%s %s" "$stripped_key" "$var_password_hashing_algorithm"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^ENCRYPT_METHOD\\&gt;" "/etc/login.defs"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^ENCRYPT_METHOD\\&gt;.*/$escaped_formatted_output/gi" "/etc/login.defs"
else
    if [[ -s "/etc/login.defs" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/login.defs" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/login.defs"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/login.defs"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="set_password_hashing_algorithm_logindefs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.6.2.2
  - DISA-STIG-RHEL-08-010110
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.1
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.2
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - set_password_hashing_algorithm_logindefs
- name: XCCDF Value var_password_hashing_algorithm # promote to variable
  set_fact:
    var_password_hashing_algorithm: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm" use="legacy"/>
  tags:
    - always

- name: Set Password Hashing Algorithm in /etc/login.defs
  ansible.builtin.lineinfile:
    dest: /etc/login.defs
    regexp: ^#?ENCRYPT_METHOD
    line: ENCRYPT_METHOD {{ var_password_hashing_algorithm.split('|')[0] }}
    state: present
    create: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"shadow-utils" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.2
  - DISA-STIG-RHEL-08-010110
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.1
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.2
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - set_password_hashing_algorithm_logindefs
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_password_hashing_algorithm:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-set_password_hashing_algorithm_logindefs:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-set_password_hashing_algorithm_logindefs_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_passwordauth" selected="false" severity="medium">
                <xccdf-1.2:title>Set PAM Password Hashing Algorithm - password-auth</xccdf-1.2:title>
                <xccdf-1.2:description>The PAM system service can be configured to only store encrypted representations of passwords.
In <html:code>/etc/pam.d/password-auth</html:code>, the <html:code>password</html:code> section of the file controls which
PAM modules to execute during a password change.

Set the <html:code>pam_unix.so</html:code> module in the <html:code>password</html:code> section to include the option
<html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" use="legacy"/></html:code> and no other hashing
algorithms as shown below:
<html:br/>
<html:pre>password    sufficient    pam_unix.so <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" use="legacy"/> <html:i>other arguments...</html:i></html:pre>
<html:br/>
This will help ensure that new passwords for local users will be stored using the
<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" use="legacy"/> algorithm.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">The hashing algorithms to be used with pam_unix.so are defined with independent module
options. There are at least 7 possible algorithms and likely more algorithms will be
introduced along the time. Due the the number of options and its possible combinations,
the use of multiple hashing algorithm options may bring unexpected behaviors to the
system. For this reason the check will pass only when one hashing algorithm option is
defined and is aligned to the "var_password_hashing_algorithm_pam" variable. The
remediation will ensure the correct option and remove any other extra hashing algorithm
option.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.6.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.13.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000073-GPOS-00041</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000120-GPOS-00061</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0418</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1055</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1402</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010160</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230237r1017056_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Passwords need to be protected at all times, and encryption is the standard method for
protecting passwords. If passwords are not encrypted, they can be plainly read
(i.e., clear text) and easily compromised. Passwords that are encrypted with a weak algorithm
are no more protected than if they are kept in plain text.
<html:br/><html:br/>
This setting ensures user and group account administration utilities are configured to store
only encrypted representations of passwords. Additionally, the <html:code>crypt_style</html:code>
configuration option in <html:code>/etc/libuser.conf</html:code> ensures the use of a strong hashing
algorithm that makes password cracking attacks more difficult.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix id="set_password_hashing_algorithm_passwordauth" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q pam; }; then

var_password_hashing_algorithm_pam='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" use="legacy"/>'


# Allow multiple algorithms, but choose the first one for remediation
var_password_hashing_algorithm_pam="$(echo $var_password_hashing_algorithm_pam | cut -d \| -f 1)"

PAM_FILE_PATH="/etc/pam.d/password-auth"

if [ -e "$PAM_FILE_PATH" ] ; then
    PAM_FILE_PATH="$PAM_FILE_PATH"
    if [ -f /usr/bin/authselect ]; then
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "$PAM_FILE_PATH")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
    fi
    

        if ! grep -qP "^\s*password\s+sufficient\s+pam_unix.so\s*.*" "$PAM_FILE_PATH"; then
            # Line matching group + control + module was not found. Check group + module.
            if [ "$(grep -cP '^\s*password\s+.*\s+pam_unix.so\s*' "$PAM_FILE_PATH")" -eq 1 ]; then
                # The control is updated only if one single line matches.
                sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_unix.so.*)/\1sufficient \2/" "$PAM_FILE_PATH"
            else
                echo "password    sufficient    pam_unix.so" &gt;&gt; "$PAM_FILE_PATH"
            fi
        fi
        # Check the option
        if ! grep -qP "^\s*password\s+sufficient\s+pam_unix.so\s*.*\s$var_password_hashing_algorithm_pam\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "/\s*password\s+sufficient\s+pam_unix.so.*/ s/$/ $var_password_hashing_algorithm_pam/" "$PAM_FILE_PATH"
        fi
    if [ -f /usr/bin/authselect ]; then
        
        authselect apply-changes -b
    fi
else
    echo "$PAM_FILE_PATH was not found" &gt;&amp;2
fi

# Ensure only the correct hashing algorithm option is used.
declare -a HASHING_ALGORITHMS_OPTIONS=("sha512" "yescrypt" "gost_yescrypt" "blowfish" "sha256" "md5" "bigcrypt")

for hash_option in "${HASHING_ALGORITHMS_OPTIONS[@]}"; do
  if [ "$hash_option" != "$var_password_hashing_algorithm_pam" ]; then
    if grep -qP "^\s*password\s+.*\s+pam_unix.so\s+.*\b$hash_option\b" "$PAM_FILE_PATH"; then
      if [ -e "$PAM_FILE_PATH" ] ; then
    PAM_FILE_PATH="$PAM_FILE_PATH"
    if [ -f /usr/bin/authselect ]; then
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "$PAM_FILE_PATH")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
    fi
    
if grep -qP "^\s*password\s+.*\s+pam_unix.so\s.*\b$hash_option\b" "$PAM_FILE_PATH"; then
    sed -i -E --follow-symlinks "s/(.*password.*.*.*pam_unix.so.*)\b$hash_option\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
fi
    if [ -f /usr/bin/authselect ]; then
        
        authselect apply-changes -b
    fi
else
    echo "$PAM_FILE_PATH was not found" &gt;&amp;2
fi
    fi
  fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="set_password_hashing_algorithm_passwordauth" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.6.2.2
  - DISA-STIG-RHEL-08-010160
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.1
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - set_password_hashing_algorithm_passwordauth
- name: XCCDF Value var_password_hashing_algorithm_pam # promote to variable
  set_fact:
    var_password_hashing_algorithm_pam: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" use="legacy"/>
  tags:
    - always

- name: Set PAM Password Hashing Algorithm - password-auth - Check if /etc/pam.d/password-auth
    file is present
  ansible.builtin.stat:
    path: /etc/pam.d/password-auth
  register: result_pam_password_auth_file_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.2
  - DISA-STIG-RHEL-08-010160
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.1
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - set_password_hashing_algorithm_passwordauth

- name: Set PAM Password Hashing Algorithm - password-auth - Check the proper remediation
    for the system
  block:

  - name: Set PAM Password Hashing Algorithm - password-auth - Define the PAM file
      to be edited as a local fact
    ansible.builtin.set_fact:
      pam_file_path: /etc/pam.d/password-auth

  - name: Set PAM Password Hashing Algorithm - password-auth - Check if system relies
      on authselect tool
    ansible.builtin.stat:
      path: /usr/bin/authselect
    register: result_authselect_present

  - name: Set PAM Password Hashing Algorithm - password-auth - Ensure authselect custom
      profile is used if authselect is present
    block:

    - name: Set PAM Password Hashing Algorithm - password-auth - Check integrity of
        authselect current profile
      ansible.builtin.command:
        cmd: authselect check
      register: result_authselect_check_cmd
      changed_when: false
      check_mode: false
      failed_when: false

    - name: Set PAM Password Hashing Algorithm - password-auth - Informative message
        based on the authselect integrity check result
      ansible.builtin.assert:
        that:
        - ansible_check_mode or result_authselect_check_cmd.rc == 0
        fail_msg:
        - authselect integrity check failed. Remediation aborted!
        - This remediation could not be applied because an authselect profile was
          not selected or the selected profile is not intact.
        - It is not recommended to manually edit the PAM files when authselect tool
          is available.
        - In cases where the default authselect profile does not cover a specific
          demand, a custom authselect profile is recommended.
        success_msg:
        - authselect integrity check passed

    - name: Set PAM Password Hashing Algorithm - password-auth - Get authselect current
        profile
      ansible.builtin.shell:
        cmd: authselect current -r | awk '{ print $1 }'
      register: result_authselect_profile
      changed_when: false
      when:
      - result_authselect_check_cmd is success

    - name: Set PAM Password Hashing Algorithm - password-auth - Define the current
        authselect profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is match("custom/")

    - name: Set PAM Password Hashing Algorithm - password-auth - Define the new authselect
        custom profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: custom/hardening
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is not match("custom/")

    - name: Set PAM Password Hashing Algorithm - password-auth - Get authselect current
        features to also enable them in the custom profile
      ansible.builtin.shell:
        cmd: authselect current | tail -n+3 | awk '{ print $2 }'
      register: result_authselect_features
      changed_when: false
      check_mode: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Set PAM Password Hashing Algorithm - password-auth - Check if any custom
        profile with the same name was already created
      ansible.builtin.stat:
        path: /etc/authselect/{{ authselect_custom_profile }}
      register: result_authselect_custom_profile_present
      changed_when: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Set PAM Password Hashing Algorithm - password-auth - Create an authselect
        custom profile based on the current profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b {{ authselect_current_profile
          }}
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is not match("^(custom/|local)")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Set PAM Password Hashing Algorithm - password-auth - Create an authselect
        custom profile based on sssd profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b sssd
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is match("local")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Set PAM Password Hashing Algorithm - password-auth - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Set PAM Password Hashing Algorithm - password-auth - Ensure the authselect
        custom profile is selected
      ansible.builtin.command:
        cmd: authselect select {{ authselect_custom_profile }}
      register: result_pam_authselect_select_profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Set PAM Password Hashing Algorithm - password-auth - Restore the authselect
        features in the custom profile
      ansible.builtin.command:
        cmd: authselect enable-feature {{ item }}
      loop: '{{ result_authselect_features.stdout_lines }}'
      register: result_pam_authselect_restore_features
      when:
      - result_authselect_profile is not skipped
      - result_authselect_features is not skipped
      - result_pam_authselect_select_profile is not skipped

    - name: Set PAM Password Hashing Algorithm - password-auth - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - result_pam_authselect_restore_features is not skipped

    - name: Set PAM Password Hashing Algorithm - password-auth - Change the PAM file
        to be edited according to the custom authselect profile
      ansible.builtin.set_fact:
        pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
          | basename }}
      when:
      - authselect_custom_profile is defined
    when:
    - result_authselect_present.stat.exists

  - name: Set PAM Password Hashing Algorithm - password-auth - Define a fact for control
      already filtered in case filters are used
    ansible.builtin.set_fact:
      pam_module_control: sufficient

  - name: Set PAM Password Hashing Algorithm - password-auth - Check if expected PAM
      module line is present in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so\s*.*
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_line_present

  - name: Set PAM Password Hashing Algorithm - password-auth - Include or update the
      PAM module line in {{ pam_file_path }}
    block:

    - name: Set PAM Password Hashing Algorithm - password-auth - Check if required
        PAM module line is present in {{ pam_file_path }} with different control
      ansible.builtin.lineinfile:
        path: '{{ pam_file_path }}'
        regexp: ^\s*password\s+.*\s+pam_unix.so\s*
        state: absent
      check_mode: true
      changed_when: false
      register: result_pam_line_other_control_present

    - name: Set PAM Password Hashing Algorithm - password-auth - Ensure the correct
        control for the required PAM module line in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: ^(\s*password\s+).*(\bpam_unix.so.*)
        replace: \1{{ pam_module_control }} \2
      register: result_pam_module_edit
      when:
      - result_pam_line_other_control_present.found == 1

    - name: Set PAM Password Hashing Algorithm - password-auth - Ensure the required
        PAM module line is included in {{ pam_file_path }}
      ansible.builtin.lineinfile:
        dest: '{{ pam_file_path }}'
        line: password    {{ pam_module_control }}    pam_unix.so
      register: result_pam_module_add
      when:
      - result_pam_line_other_control_present.found == 0 or result_pam_line_other_control_present.found
        &gt; 1

    - name: Set PAM Password Hashing Algorithm - password-auth - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present is defined
      - result_authselect_present.stat.exists
      - |-
        (result_pam_module_add is defined and result_pam_module_add.changed)
         or (result_pam_module_edit is defined and result_pam_module_edit.changed)
    when:
    - result_pam_line_present.found is defined
    - result_pam_line_present.found == 0

  - name: Set PAM Password Hashing Algorithm - password-auth - Define a fact for control
      already filtered in case filters are used
    ansible.builtin.set_fact:
      pam_module_control: sufficient

  - name: Set PAM Password Hashing Algorithm - password-auth - Check if the required
      PAM module option is present in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so\s*.*\s{{
        var_password_hashing_algorithm_pam.split("|")[0] }}\b
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_module_set_password_hashing_algorithm_passwordauth_option_present

  - name: Set PAM Password Hashing Algorithm - password-auth - Ensure the "{{ var_password_hashing_algorithm_pam.split("|")[0]
      }}" PAM option for "pam_unix.so" is included in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      backrefs: true
      regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so.*)
      line: \1 {{ var_password_hashing_algorithm_pam.split("|")[0] }}
      state: present
    register: result_pam_set_password_hashing_algorithm_passwordauth_add
    when:
    - result_pam_module_set_password_hashing_algorithm_passwordauth_option_present.found
      is defined
    - result_pam_module_set_password_hashing_algorithm_passwordauth_option_present.found
      == 0

  - name: Set PAM Password Hashing Algorithm - password-auth - Ensure authselect changes
      are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_present.stat.exists
    - |-
      (result_pam_set_password_hashing_algorithm_passwordauth_add is defined and result_pam_set_password_hashing_algorithm_passwordauth_add.changed)
       or (result_pam_set_password_hashing_algorithm_passwordauth_edit is defined and result_pam_set_password_hashing_algorithm_passwordauth_edit.changed)
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_pam_password_auth_file_present.stat.exists
  tags:
  - CJIS-5.6.2.2
  - DISA-STIG-RHEL-08-010160
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.1
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - set_password_hashing_algorithm_passwordauth

- name: Set PAM Password Hashing Algorithm - password-auth - Check if /etc/pam.d/password-auth
    File is Present
  ansible.builtin.stat:
    path: /etc/pam.d/password-auth
  register: result_pam_password_auth_file_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.2
  - DISA-STIG-RHEL-08-010160
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.1
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - set_password_hashing_algorithm_passwordauth

- name: Set PAM Password Hashing Algorithm - password-auth - Check The Proper Remediation
    For The System
  block:

  - name: Set PAM Password Hashing Algorithm - password-auth - Define the PAM file
      to be edited as a local fact
    ansible.builtin.set_fact:
      pam_file_path: /etc/pam.d/password-auth

  - name: Set PAM Password Hashing Algorithm - password-auth - Check if system relies
      on authselect tool
    ansible.builtin.stat:
      path: /usr/bin/authselect
    register: result_authselect_present

  - name: Set PAM Password Hashing Algorithm - password-auth - Ensure authselect custom
      profile is used if authselect is present
    block:

    - name: Set PAM Password Hashing Algorithm - password-auth - Check integrity of
        authselect current profile
      ansible.builtin.command:
        cmd: authselect check
      register: result_authselect_check_cmd
      changed_when: false
      check_mode: false
      failed_when: false

    - name: Set PAM Password Hashing Algorithm - password-auth - Informative message
        based on the authselect integrity check result
      ansible.builtin.assert:
        that:
        - ansible_check_mode or result_authselect_check_cmd.rc == 0
        fail_msg:
        - authselect integrity check failed. Remediation aborted!
        - This remediation could not be applied because an authselect profile was
          not selected or the selected profile is not intact.
        - It is not recommended to manually edit the PAM files when authselect tool
          is available.
        - In cases where the default authselect profile does not cover a specific
          demand, a custom authselect profile is recommended.
        success_msg:
        - authselect integrity check passed

    - name: Set PAM Password Hashing Algorithm - password-auth - Get authselect current
        profile
      ansible.builtin.shell:
        cmd: authselect current -r | awk '{ print $1 }'
      register: result_authselect_profile
      changed_when: false
      when:
      - result_authselect_check_cmd is success

    - name: Set PAM Password Hashing Algorithm - password-auth - Define the current
        authselect profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is match("custom/")

    - name: Set PAM Password Hashing Algorithm - password-auth - Define the new authselect
        custom profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: custom/hardening
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is not match("custom/")

    - name: Set PAM Password Hashing Algorithm - password-auth - Get authselect current
        features to also enable them in the custom profile
      ansible.builtin.shell:
        cmd: authselect current | tail -n+3 | awk '{ print $2 }'
      register: result_authselect_features
      changed_when: false
      check_mode: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Set PAM Password Hashing Algorithm - password-auth - Check if any custom
        profile with the same name was already created
      ansible.builtin.stat:
        path: /etc/authselect/{{ authselect_custom_profile }}
      register: result_authselect_custom_profile_present
      changed_when: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Set PAM Password Hashing Algorithm - password-auth - Create an authselect
        custom profile based on the current profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b {{ authselect_current_profile
          }}
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is not match("^(custom/|local)")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Set PAM Password Hashing Algorithm - password-auth - Create an authselect
        custom profile based on sssd profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b sssd
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is match("local")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Set PAM Password Hashing Algorithm - password-auth - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Set PAM Password Hashing Algorithm - password-auth - Ensure the authselect
        custom profile is selected
      ansible.builtin.command:
        cmd: authselect select {{ authselect_custom_profile }}
      register: result_pam_authselect_select_profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Set PAM Password Hashing Algorithm - password-auth - Restore the authselect
        features in the custom profile
      ansible.builtin.command:
        cmd: authselect enable-feature {{ item }}
      loop: '{{ result_authselect_features.stdout_lines }}'
      register: result_pam_authselect_restore_features
      when:
      - result_authselect_profile is not skipped
      - result_authselect_features is not skipped
      - result_pam_authselect_select_profile is not skipped

    - name: Set PAM Password Hashing Algorithm - password-auth - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - result_pam_authselect_restore_features is not skipped

    - name: Set PAM Password Hashing Algorithm - password-auth - Change the PAM file
        to be edited according to the custom authselect profile
      ansible.builtin.set_fact:
        pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
          | basename }}
      when:
      - authselect_custom_profile is defined
    when:
    - result_authselect_present.stat.exists

  - name: Set PAM Password Hashing Algorithm - password-auth - Check if "{{ pam_file_path
      }}" File is Present
    ansible.builtin.stat:
      path: '{{ pam_file_path }}'
    register: pam_file_path_present

  - name: Set PAM Password Hashing Algorithm - password-auth - Ensure That Only the
      Correct Hashing Algorithm Option For pam_unix.so Is Used in {{ pam_file_path
      }}
    ansible.builtin.replace:
      dest: '{{ pam_file_path }}'
      regexp: (^\s*password.*pam_unix\.so.*)\b{{ item }}\b\s*(.*)
      replace: \1\2
    when:
    - item != var_password_hashing_algorithm_pam.split('|')[0]
    - pam_file_path_present.stat.exists
    loop:
    - sha512
    - yescrypt
    - gost_yescrypt
    - blowfish
    - sha256
    - md5
    - bigcrypt
    register: result_pam_hashing_options_removal

  - name: Set PAM Password Hashing Algorithm - password-auth - Ensure authselect changes
      are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_present.stat.exists
    - result_pam_hashing_options_removal is changed
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_pam_password_auth_file_present.stat.exists
  tags:
  - CJIS-5.6.2.2
  - DISA-STIG-RHEL-08-010160
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.1
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - set_password_hashing_algorithm_passwordauth
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_password_hashing_algorithm_pam:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-set_password_hashing_algorithm_passwordauth:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-set_password_hashing_algorithm_passwordauth_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_systemauth" selected="false" severity="medium">
                <xccdf-1.2:title>Set PAM Password Hashing Algorithm - system-auth</xccdf-1.2:title>
                <xccdf-1.2:description>The PAM system service can be configured to only store encrypted representations of passwords.
In "/etc/pam.d/system-auth", the <html:code>password</html:code> section of the file controls which
PAM modules to execute during a password change.

Set the <html:code>pam_unix.so</html:code> module in the <html:code>password</html:code> section to include the option
<html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" use="legacy"/></html:code> and no other hashing
algorithms as shown below:
<html:br/>

<html:pre>password    sufficient    pam_unix.so <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" use="legacy"/> <html:i>other arguments...</html:i></html:pre>

<html:br/>
This will help ensure that new passwords for local users will be stored using the
<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" use="legacy"/> algorithm.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">The hashing algorithms to be used with pam_unix.so are defined with independent module
options. There are at least 7 possible algorithms and likely more algorithms will be
introduced along the time. Due the the number of options and its possible combinations,
the use of multiple hashing algorithm options may bring unexpected behaviors to the
system. For this reason the check will pass only when one hashing algorithm option is
defined and is aligned to the "var_password_hashing_algorithm_pam" variable. The
remediation will ensure the correct option and remove any other extra hashing algorithm
option.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.6.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.13.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000073-GPOS-00041</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000120-GPOS-00061</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R68</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0418</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1055</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1402</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010159</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244524r1017330_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Passwords need to be protected at all times, and encryption is the standard method for
protecting passwords. If passwords are not encrypted, they can be plainly read
(i.e., clear text) and easily compromised. Passwords that are encrypted with a weak algorithm
are no more protected than if they are kept in plain text.
<html:br/><html:br/>
This setting ensures user and group account administration utilities are configured to store
only encrypted representations of passwords. Additionally, the <html:code>crypt_style</html:code>
configuration option in <html:code>/etc/libuser.conf</html:code> ensures the use of a strong hashing
algorithm that makes password cracking attacks more difficult.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix id="set_password_hashing_algorithm_systemauth" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q pam; }; then

var_password_hashing_algorithm_pam='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" use="legacy"/>'


# Allow multiple algorithms, but choose the first one for remediation
var_password_hashing_algorithm_pam="$(echo $var_password_hashing_algorithm_pam | cut -d \| -f 1)"

PAM_FILE_PATH="/etc/pam.d/system-auth"


# Ensure all the hashing algorithm option is removed.
declare -a HASHING_ALGORITHMS_OPTIONS=("sha512" "yescrypt" "gost_yescrypt" "blowfish" "sha256" "md5" "bigcrypt")

for hash_option in "${HASHING_ALGORITHMS_OPTIONS[@]}"; do
  if grep -qP "^\s*password\s+.*\s+pam_unix.so\s+.*\b$hash_option\b" "$PAM_FILE_PATH"; then
    if [ -e "$PAM_FILE_PATH" ] ; then
    PAM_FILE_PATH="$PAM_FILE_PATH"
    if [ -f /usr/bin/authselect ]; then
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "$PAM_FILE_PATH")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
    fi
    
if grep -qP "^\s*password\s+.*\s+pam_unix.so\s.*\b$hash_option\b" "$PAM_FILE_PATH"; then
    sed -i -E --follow-symlinks "s/(.*password.*.*.*pam_unix.so.*)\b$hash_option\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
fi
    if [ -f /usr/bin/authselect ]; then
        
        authselect apply-changes -b
    fi
else
    echo "$PAM_FILE_PATH was not found" &gt;&amp;2
fi
  fi
done

if [ -e "$PAM_FILE_PATH" ] ; then
    PAM_FILE_PATH="$PAM_FILE_PATH"
    if [ -f /usr/bin/authselect ]; then
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "$PAM_FILE_PATH")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
    fi
    

        if ! grep -qP "^\s*password\s+sufficient\s+pam_unix.so\s*.*" "$PAM_FILE_PATH"; then
            # Line matching group + control + module was not found. Check group + module.
            if [ "$(grep -cP '^\s*password\s+.*\s+pam_unix.so\s*' "$PAM_FILE_PATH")" -eq 1 ]; then
                # The control is updated only if one single line matches.
                sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_unix.so.*)/\1sufficient \2/" "$PAM_FILE_PATH"
            else
                echo "password    sufficient    pam_unix.so" &gt;&gt; "$PAM_FILE_PATH"
            fi
        fi
        # Check the option
        if ! grep -qP "^\s*password\s+sufficient\s+pam_unix.so\s*.*\s$var_password_hashing_algorithm_pam\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "/\s*password\s+sufficient\s+pam_unix.so.*/ s/$/ $var_password_hashing_algorithm_pam/" "$PAM_FILE_PATH"
        fi
    if [ -f /usr/bin/authselect ]; then
        
        authselect apply-changes -b
    fi
else
    echo "$PAM_FILE_PATH was not found" &gt;&amp;2
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="set_password_hashing_algorithm_systemauth" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.6.2.2
  - DISA-STIG-RHEL-08-010159
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.1
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - set_password_hashing_algorithm_systemauth
- name: XCCDF Value var_password_hashing_algorithm_pam # promote to variable
  set_fact:
    var_password_hashing_algorithm_pam: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam" use="legacy"/>
  tags:
    - always

- name: Set PAM Password Hashing Algorithm - system-auth - Check if /etc/pam.d/system-auth
    file is present
  ansible.builtin.stat:
    path: /etc/pam.d/system-auth
  register: result_pam_auth_file_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.2
  - DISA-STIG-RHEL-08-010159
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.1
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - set_password_hashing_algorithm_systemauth

- name: Set PAM Password Hashing Algorithm - system-auth - Check the proper remediation
    for the system
  block:

  - name: Set PAM Password Hashing Algorithm - system-auth - Define the PAM file to
      be edited as a local fact
    ansible.builtin.set_fact:
      pam_file_path: /etc/pam.d/system-auth

  - name: Set PAM Password Hashing Algorithm - system-auth - Check if system relies
      on authselect tool
    ansible.builtin.stat:
      path: /usr/bin/authselect
    register: result_authselect_present

  - name: Set PAM Password Hashing Algorithm - system-auth - Ensure authselect custom
      profile is used if authselect is present
    block:

    - name: Set PAM Password Hashing Algorithm - system-auth - Check integrity of
        authselect current profile
      ansible.builtin.command:
        cmd: authselect check
      register: result_authselect_check_cmd
      changed_when: false
      check_mode: false
      failed_when: false

    - name: Set PAM Password Hashing Algorithm - system-auth - Informative message
        based on the authselect integrity check result
      ansible.builtin.assert:
        that:
        - ansible_check_mode or result_authselect_check_cmd.rc == 0
        fail_msg:
        - authselect integrity check failed. Remediation aborted!
        - This remediation could not be applied because an authselect profile was
          not selected or the selected profile is not intact.
        - It is not recommended to manually edit the PAM files when authselect tool
          is available.
        - In cases where the default authselect profile does not cover a specific
          demand, a custom authselect profile is recommended.
        success_msg:
        - authselect integrity check passed

    - name: Set PAM Password Hashing Algorithm - system-auth - Get authselect current
        profile
      ansible.builtin.shell:
        cmd: authselect current -r | awk '{ print $1 }'
      register: result_authselect_profile
      changed_when: false
      when:
      - result_authselect_check_cmd is success

    - name: Set PAM Password Hashing Algorithm - system-auth - Define the current
        authselect profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is match("custom/")

    - name: Set PAM Password Hashing Algorithm - system-auth - Define the new authselect
        custom profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: custom/hardening
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is not match("custom/")

    - name: Set PAM Password Hashing Algorithm - system-auth - Get authselect current
        features to also enable them in the custom profile
      ansible.builtin.shell:
        cmd: authselect current | tail -n+3 | awk '{ print $2 }'
      register: result_authselect_features
      changed_when: false
      check_mode: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Set PAM Password Hashing Algorithm - system-auth - Check if any custom
        profile with the same name was already created
      ansible.builtin.stat:
        path: /etc/authselect/{{ authselect_custom_profile }}
      register: result_authselect_custom_profile_present
      changed_when: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Set PAM Password Hashing Algorithm - system-auth - Create an authselect
        custom profile based on the current profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b {{ authselect_current_profile
          }}
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is not match("^(custom/|local)")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Set PAM Password Hashing Algorithm - system-auth - Create an authselect
        custom profile based on sssd profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b sssd
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is match("local")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Set PAM Password Hashing Algorithm - system-auth - Ensure authselect changes
        are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Set PAM Password Hashing Algorithm - system-auth - Ensure the authselect
        custom profile is selected
      ansible.builtin.command:
        cmd: authselect select {{ authselect_custom_profile }}
      register: result_pam_authselect_select_profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Set PAM Password Hashing Algorithm - system-auth - Restore the authselect
        features in the custom profile
      ansible.builtin.command:
        cmd: authselect enable-feature {{ item }}
      loop: '{{ result_authselect_features.stdout_lines }}'
      register: result_pam_authselect_restore_features
      when:
      - result_authselect_profile is not skipped
      - result_authselect_features is not skipped
      - result_pam_authselect_select_profile is not skipped

    - name: Set PAM Password Hashing Algorithm - system-auth - Ensure authselect changes
        are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - result_pam_authselect_restore_features is not skipped

    - name: Set PAM Password Hashing Algorithm - system-auth - Change the PAM file
        to be edited according to the custom authselect profile
      ansible.builtin.set_fact:
        pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
          | basename }}
      when:
      - authselect_custom_profile is defined
    when:
    - result_authselect_present.stat.exists

  - name: Set PAM Password Hashing Algorithm - system-auth - Define a fact for control
      already filtered in case filters are used
    ansible.builtin.set_fact:
      pam_module_control: sufficient

  - name: Set PAM Password Hashing Algorithm - system-auth - Check if expected PAM
      module line is present in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so\s*.*
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_line_present

  - name: Set PAM Password Hashing Algorithm - system-auth - Include or update the
      PAM module line in {{ pam_file_path }}
    block:

    - name: Set PAM Password Hashing Algorithm - system-auth - Check if required PAM
        module line is present in {{ pam_file_path }} with different control
      ansible.builtin.lineinfile:
        path: '{{ pam_file_path }}'
        regexp: ^\s*password\s+.*\s+pam_unix.so\s*
        state: absent
      check_mode: true
      changed_when: false
      register: result_pam_line_other_control_present

    - name: Set PAM Password Hashing Algorithm - system-auth - Ensure the correct
        control for the required PAM module line in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: ^(\s*password\s+).*(\bpam_unix.so.*)
        replace: \1{{ pam_module_control }} \2
      register: result_pam_module_edit
      when:
      - result_pam_line_other_control_present.found == 1

    - name: Set PAM Password Hashing Algorithm - system-auth - Ensure the required
        PAM module line is included in {{ pam_file_path }}
      ansible.builtin.lineinfile:
        dest: '{{ pam_file_path }}'
        line: password    {{ pam_module_control }}    pam_unix.so
      register: result_pam_module_add
      when:
      - result_pam_line_other_control_present.found == 0 or result_pam_line_other_control_present.found
        &gt; 1

    - name: Set PAM Password Hashing Algorithm - system-auth - Ensure authselect changes
        are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present is defined
      - result_authselect_present.stat.exists
      - |-
        (result_pam_module_add is defined and result_pam_module_add.changed)
         or (result_pam_module_edit is defined and result_pam_module_edit.changed)
    when:
    - result_pam_line_present.found is defined
    - result_pam_line_present.found == 0

  - name: Set PAM Password Hashing Algorithm - system-auth - Define a fact for control
      already filtered in case filters are used
    ansible.builtin.set_fact:
      pam_module_control: sufficient

  - name: Set PAM Password Hashing Algorithm - system-auth - Check if the required
      PAM module option is present in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so\s*.*\s{{
        var_password_hashing_algorithm_pam.split("|")[0] }}\b
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_module_set_password_hashing_algorithm_systemauth_option_present

  - name: Set PAM Password Hashing Algorithm - system-auth - Ensure the "{{ var_password_hashing_algorithm_pam.split("|")[0]
      }}" PAM option for "pam_unix.so" is included in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      backrefs: true
      regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so.*)
      line: \1 {{ var_password_hashing_algorithm_pam.split("|")[0] }}
      state: present
    register: result_pam_set_password_hashing_algorithm_systemauth_add
    when:
    - result_pam_module_set_password_hashing_algorithm_systemauth_option_present.found
      is defined
    - result_pam_module_set_password_hashing_algorithm_systemauth_option_present.found
      == 0

  - name: Set PAM Password Hashing Algorithm - system-auth - Ensure authselect changes
      are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_present.stat.exists
    - |-
      (result_pam_set_password_hashing_algorithm_systemauth_add is defined and result_pam_set_password_hashing_algorithm_systemauth_add.changed)
       or (result_pam_set_password_hashing_algorithm_systemauth_edit is defined and result_pam_set_password_hashing_algorithm_systemauth_edit.changed)
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_pam_auth_file_present.stat.exists
  tags:
  - CJIS-5.6.2.2
  - DISA-STIG-RHEL-08-010159
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.1
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - set_password_hashing_algorithm_systemauth

- name: Set PAM Password Hashing Algorithm - system-auth - Check if /etc/pam.d/system-auth
    File is Present
  ansible.builtin.stat:
    path: /etc/pam.d/system-auth
  register: result_pam_auth_file_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.2
  - DISA-STIG-RHEL-08-010159
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.1
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - set_password_hashing_algorithm_systemauth

- name: Set PAM Password Hashing Algorithm - system-auth - Check The Proper Remediation
    For The System
  block:

  - name: Set PAM Password Hashing Algorithm - system-auth - Define the PAM file to
      be edited as a local fact
    ansible.builtin.set_fact:
      pam_file_path: /etc/pam.d/system-auth

  - name: Set PAM Password Hashing Algorithm - system-auth - Check if system relies
      on authselect tool
    ansible.builtin.stat:
      path: /usr/bin/authselect
    register: result_authselect_present

  - name: Set PAM Password Hashing Algorithm - system-auth - Ensure authselect custom
      profile is used if authselect is present
    block:

    - name: Set PAM Password Hashing Algorithm - system-auth - Check integrity of
        authselect current profile
      ansible.builtin.command:
        cmd: authselect check
      register: result_authselect_check_cmd
      changed_when: false
      check_mode: false
      failed_when: false

    - name: Set PAM Password Hashing Algorithm - system-auth - Informative message
        based on the authselect integrity check result
      ansible.builtin.assert:
        that:
        - ansible_check_mode or result_authselect_check_cmd.rc == 0
        fail_msg:
        - authselect integrity check failed. Remediation aborted!
        - This remediation could not be applied because an authselect profile was
          not selected or the selected profile is not intact.
        - It is not recommended to manually edit the PAM files when authselect tool
          is available.
        - In cases where the default authselect profile does not cover a specific
          demand, a custom authselect profile is recommended.
        success_msg:
        - authselect integrity check passed

    - name: Set PAM Password Hashing Algorithm - system-auth - Get authselect current
        profile
      ansible.builtin.shell:
        cmd: authselect current -r | awk '{ print $1 }'
      register: result_authselect_profile
      changed_when: false
      when:
      - result_authselect_check_cmd is success

    - name: Set PAM Password Hashing Algorithm - system-auth - Define the current
        authselect profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is match("custom/")

    - name: Set PAM Password Hashing Algorithm - system-auth - Define the new authselect
        custom profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: custom/hardening
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is not match("custom/")

    - name: Set PAM Password Hashing Algorithm - system-auth - Get authselect current
        features to also enable them in the custom profile
      ansible.builtin.shell:
        cmd: authselect current | tail -n+3 | awk '{ print $2 }'
      register: result_authselect_features
      changed_when: false
      check_mode: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Set PAM Password Hashing Algorithm - system-auth - Check if any custom
        profile with the same name was already created
      ansible.builtin.stat:
        path: /etc/authselect/{{ authselect_custom_profile }}
      register: result_authselect_custom_profile_present
      changed_when: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Set PAM Password Hashing Algorithm - system-auth - Create an authselect
        custom profile based on the current profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b {{ authselect_current_profile
          }}
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is not match("^(custom/|local)")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Set PAM Password Hashing Algorithm - system-auth - Create an authselect
        custom profile based on sssd profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b sssd
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is match("local")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Set PAM Password Hashing Algorithm - system-auth - Ensure authselect changes
        are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Set PAM Password Hashing Algorithm - system-auth - Ensure the authselect
        custom profile is selected
      ansible.builtin.command:
        cmd: authselect select {{ authselect_custom_profile }}
      register: result_pam_authselect_select_profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Set PAM Password Hashing Algorithm - system-auth - Restore the authselect
        features in the custom profile
      ansible.builtin.command:
        cmd: authselect enable-feature {{ item }}
      loop: '{{ result_authselect_features.stdout_lines }}'
      register: result_pam_authselect_restore_features
      when:
      - result_authselect_profile is not skipped
      - result_authselect_features is not skipped
      - result_pam_authselect_select_profile is not skipped

    - name: Set PAM Password Hashing Algorithm - system-auth - Ensure authselect changes
        are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - result_pam_authselect_restore_features is not skipped

    - name: Set PAM Password Hashing Algorithm - system-auth - Change the PAM file
        to be edited according to the custom authselect profile
      ansible.builtin.set_fact:
        pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
          | basename }}
      when:
      - authselect_custom_profile is defined
    when:
    - result_authselect_present.stat.exists

  - name: Set PAM Password Hashing Algorithm - system-auth - Check if "{{ pam_file_path
      }}" File is Present
    ansible.builtin.stat:
      path: '{{ pam_file_path }}'
    register: pam_file_path_present

  - name: Set PAM Password Hashing Algorithm - system-auth - Ensure That Only the
      Correct Hashing Algorithm Option For pam_unix.so Is Used in {{ pam_file_path
      }}
    ansible.builtin.replace:
      dest: '{{ pam_file_path }}'
      regexp: (^\s*password.*pam_unix\.so.*)\b{{ item }}\b\s*(.*)
      replace: \1\2
    when:
    - item != var_password_hashing_algorithm_pam.split('|')[0]
    - pam_file_path_present.stat.exists
    loop:
    - sha512
    - yescrypt
    - gost_yescrypt
    - blowfish
    - sha256
    - md5
    - bigcrypt
    register: result_pam_hashing_options_removal

  - name: Set PAM Password Hashing Algorithm - system-auth - Ensure authselect changes
      are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_present.stat.exists
    - result_pam_hashing_options_removal is changed
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - result_pam_auth_file_present.stat.exists
  tags:
  - CJIS-5.6.2.2
  - DISA-STIG-RHEL-08-010159
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.1
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - set_password_hashing_algorithm_systemauth
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_password_hashing_algorithm_pam:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_hashing_algorithm_pam"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-set_password_hashing_algorithm_systemauth:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_set_password_hashing_min_rounds_logindefs" selected="false" severity="medium">
                <xccdf-1.2:title>Set Password Hashing Rounds in /etc/login.defs</xccdf-1.2:title>
                <xccdf-1.2:description>In <html:code>/etc/login.defs</html:code>, ensure <html:code>SHA_CRYPT_MIN_ROUNDS</html:code> and
<html:code>SHA_CRYPT_MAX_ROUNDS</html:code> has the minimum value of <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_min_rounds_login_defs" use="legacy"/></html:code>.
For example:
<html:pre>SHA_CRYPT_MIN_ROUNDS <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_min_rounds_login_defs" use="legacy"/>
SHA_CRYPT_MAX_ROUNDS <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_min_rounds_login_defs" use="legacy"/></html:pre>
Notice that if neither are set, they already have the default value of 5000.
If either is set, they must have the minimum value of <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_min_rounds_login_defs" use="legacy"/>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000073-GPOS-00041</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000120-GPOS-00061</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010130</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230233r1044790_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Passwords need to be protected at all times, and hashing is the standard
method for protecting passwords. If passwords are not hashed, they can
be plainly read (i.e., clear text) and easily compromised. Passwords
that are hashed with a weak algorithm are no more protected than if
they are kept in plain text.
<html:br/><html:br/>
Using more hashing rounds makes password cracking attacks more difficult.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="set_password_hashing_min_rounds_logindefs" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_password_hashing_min_rounds_login_defs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_min_rounds_login_defs" use="legacy"/>'




config_file=/etc/login.defs
current_min_rounds=$(grep -Po '^\s*SHA_CRYPT_MIN_ROUNDS\s+\K\d+' "$config_file")
current_max_rounds=$(grep -Po '^\s*SHA_CRYPT_MAX_ROUNDS\s+\K\d+' "$config_file")

if [[ -z "$current_min_rounds" || "$current_min_rounds" -le "$var_password_hashing_min_rounds_login_defs" ]]; then
    if [ -e "/etc/login.defs" ] ; then
        
        LC_ALL=C sed -i "/^\s*SHA_CRYPT_MIN_ROUNDS\s*/Id" "/etc/login.defs"
    else
        printf '%s\n' "Path '/etc/login.defs' wasn't found on this system. Refusing to continue." &gt;&amp;2
        return 1
    fi
    # make sure file has newline at the end
    sed -i -e '$a\' "/etc/login.defs"

    cp "/etc/login.defs" "/etc/login.defs.bak"
    # Insert at the end of the file
    printf '%s\n' "SHA_CRYPT_MIN_ROUNDS $var_password_hashing_min_rounds_login_defs" &gt;&gt; "/etc/login.defs"
    # Clean up after ourselves.
    rm "/etc/login.defs.bak"
fi

if [[ -n "$current_max_rounds" &amp;&amp; "$current_max_rounds" -le "$var_password_hashing_min_rounds_login_defs" ]]; then
    if [ -e "/etc/login.defs" ] ; then
        
        LC_ALL=C sed -i "/^\s*SHA_CRYPT_MAX_ROUNDS\s*/Id" "/etc/login.defs"
    else
        printf '%s\n' "Path '/etc/login.defs' wasn't found on this system. Refusing to continue." &gt;&amp;2
        return 1
    fi
    # make sure file has newline at the end
    sed -i -e '$a\' "/etc/login.defs"

    cp "/etc/login.defs" "/etc/login.defs.bak"
    # Insert at the end of the file
    printf '%s\n' "SHA_CRYPT_MAX_ROUNDS $var_password_hashing_min_rounds_login_defs" &gt;&gt; "/etc/login.defs"
    # Clean up after ourselves.
    rm "/etc/login.defs.bak"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="set_password_hashing_min_rounds_logindefs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010130
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - set_password_hashing_min_rounds_logindefs
- name: XCCDF Value var_password_hashing_min_rounds_login_defs # promote to variable
  set_fact:
    var_password_hashing_min_rounds_login_defs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_hashing_min_rounds_login_defs" use="legacy"/>
  tags:
    - always

- name: Set Password Hashing Rounds in /etc/login.defs - extract contents of the file
    /etc/login.defs
  ansible.builtin.slurp:
    src: /etc/login.defs
  register: etc_login_defs
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010130
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - set_password_hashing_min_rounds_logindefs

- name: Set Password Hashing Rounds in /etc/login.defs - extract the value of SHA_CRYPT_MIN_ROUNDS
    if present
  ansible.builtin.set_fact:
    etc_login_defs_sha_crypt_min_rounds: '{{ etc_login_defs[''content''] | b64decode
      | regex_search(''^\s*SHA_CRYPT_MIN_ROUNDS\s+(\d+)'', ''\1'', multiline=True)
      | default([], true) }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010130
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - set_password_hashing_min_rounds_logindefs

- name: Set Password Hashing Rounds in /etc/login.defs - extract the value of SHA_CRYPT_MAX_ROUNDS
    if present
  ansible.builtin.set_fact:
    etc_login_defs_sha_crypt_max_rounds: '{{ etc_login_defs[''content''] | b64decode
      | regex_search(''^\s*SHA_CRYPT_MAX_ROUNDS\s+(\d+)'', ''\1'', multiline=True)
      | default([], true) }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010130
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - set_password_hashing_min_rounds_logindefs

- name: Set Password Hashing Rounds in /etc/login.defs - Ensure SHA_CRYPT_MIN_ROUNDS
    has Minimum Value of 5000
  ansible.builtin.replace:
    path: /etc/login.defs
    regexp: (^\s*SHA_CRYPT_MIN_ROUNDS\s+)(?:\d+)(.*$)
    replace: \g&lt;1&gt;{{ var_password_hashing_min_rounds_login_defs }}\g&lt;2&gt;
    backup: false
  when:
  - '"kernel" in ansible_facts.packages'
  - etc_login_defs_sha_crypt_min_rounds is defined and etc_login_defs_sha_crypt_min_rounds
    | length &gt; 0 and etc_login_defs_sha_crypt_min_rounds | first | int &lt; var_password_hashing_min_rounds_login_defs
    | int
  tags:
  - DISA-STIG-RHEL-08-010130
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - set_password_hashing_min_rounds_logindefs

- name: Set Password Hashing Rounds in /etc/login.defs - Ensure SHA_CRYPT_MAX_ROUNDS
    has Minimum Value of 5000
  ansible.builtin.replace:
    path: /etc/login.defs
    regexp: (^\s*SHA_CRYPT_MAX_ROUNDS\s+)(?:\d+)(.*$)
    replace: \g&lt;1&gt;{{ var_password_hashing_min_rounds_login_defs }}\g&lt;2&gt;
    backup: false
  when:
  - '"kernel" in ansible_facts.packages'
  - etc_login_defs_sha_crypt_max_rounds is defined and etc_login_defs_sha_crypt_max_rounds
    | length &gt; 0 and etc_login_defs_sha_crypt_max_rounds | first | int &lt; var_password_hashing_min_rounds_login_defs
    | int
  tags:
  - DISA-STIG-RHEL-08-010130
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - set_password_hashing_min_rounds_logindefs

- name: Set Password Hashing Rounds in /etc/login.defs - SHA_CRYPT_MIN_ROUNDS add
    configuration if not found
  ansible.builtin.lineinfile:
    line: SHA_CRYPT_MIN_ROUNDS {{ var_password_hashing_min_rounds_login_defs }}
    path: /etc/login.defs
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - etc_login_defs_sha_crypt_min_rounds | length == 0
  tags:
  - DISA-STIG-RHEL-08-010130
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - set_password_hashing_min_rounds_logindefs

- name: Set Password Hashing Rounds in /etc/login.defs - SHA_CRYPT_MAX_ROUNDS add
    configuration if not found
  ansible.builtin.lineinfile:
    line: SHA_CRYPT_MAX_ROUNDS {{ var_password_hashing_min_rounds_login_defs }}
    path: /etc/login.defs
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - etc_login_defs_sha_crypt_max_rounds | length == 0
  tags:
  - DISA-STIG-RHEL-08-010130
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - set_password_hashing_min_rounds_logindefs
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_password_hashing_min_rounds_login_defs:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_hashing_min_rounds_login_defs"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-set_password_hashing_min_rounds_logindefs:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-set_password_hashing_min_rounds_logindefs_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_accounts-physical">
            <xccdf-1.2:title>Protect Physical Console Access</xccdf-1.2:title>
            <xccdf-1.2:description>It is impossible to fully protect a system from an
attacker with physical access, so securing the space in which the
system is located should be considered a necessary step. However,
there are some steps which, if taken, make it more difficult for an
attacker to quickly or undetectably modify a system from its
console.</xccdf-1.2:description>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_logind_session_timeout" type="number">
              <xccdf-1.2:title>Login timeout for idle sessions</xccdf-1.2:title>
              <xccdf-1.2:description>Specify duration of allowed idle time.</xccdf-1.2:description>
              <xccdf-1.2:value selector="10_minutes">600</xccdf-1.2:value>
              <xccdf-1.2:value selector="120_minutes">7200</xccdf-1.2:value>
              <xccdf-1.2:value selector="14_minutes">840</xccdf-1.2:value>
              <xccdf-1.2:value selector="15_minutes">900</xccdf-1.2:value>
              <xccdf-1.2:value selector="30_minutes">1800</xccdf-1.2:value>
              <xccdf-1.2:value selector="5_minutes">300</xccdf-1.2:value>
              <xccdf-1.2:value selector="60_minutes">3600</xccdf-1.2:value>
              <xccdf-1.2:value>300</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_debug-shell_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable debug-shell SystemD Service</xccdf-1.2:title>
              <xccdf-1.2:description>SystemD's <html:code>debug-shell</html:code> service is intended to
diagnose SystemD related boot issues with various <html:code>systemctl</html:code>
commands. Once enabled and following a system reboot, the root shell
will be available on <html:code>tty9</html:code> which is access by pressing
<html:code>CTRL-ALT-F9</html:code>. The <html:code>debug-shell</html:code> service should only be used
for SystemD related issues and should otherwise be disabled.
<html:br/><html:br/>
By default, the <html:code>debug-shell</html:code> SystemD service is already disabled.

The <html:code>debug-shell</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now debug-shell.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_UAU.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000324-GPOS-00125</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040180</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230532r1017294_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>This prevents attackers with physical access from trivially bypassing security
on the machine through valid troubleshooting configurations and gaining root
access when the system is rebooted.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_debug-shell_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'debug-shell.service'
fi
"$SYSTEMCTL_EXEC" disable 'debug-shell.service'
"$SYSTEMCTL_EXEC" mask 'debug-shell.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files debug-shell.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'debug-shell.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'debug-shell.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'debug-shell.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_debug-shell_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040180
  - NIST-800-171-3.4.5
  - NIST-800-53-CM-6
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_debug-shell_disabled

- name: Disable debug-shell SystemD Service - Disable service debug-shell
  block:

  - name: Disable debug-shell SystemD Service - Collect systemd Services Present in
      the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable debug-shell SystemD Service - Ensure debug-shell.service is Masked
    ansible.builtin.systemd:
      name: debug-shell.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("debug-shell.service", multiline=True)

  - name: Unit Socket Exists - debug-shell.socket
    ansible.builtin.command: systemctl -q list-unit-files debug-shell.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable debug-shell SystemD Service - Disable Socket debug-shell
    ansible.builtin.systemd:
      name: debug-shell.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("debug-shell.socket", multiline=True)
  tags:
  - DISA-STIG-RHEL-08-040180
  - NIST-800-171-3.4.5
  - NIST-800-53-CM-6
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_debug-shell_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_debug-shell_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_debug-shell

class disable_debug-shell {
  service {'debug-shell':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_debug-shell_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: debug-shell.service
        enabled: false
        mask: true
      - name: debug-shell.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_debug-shell_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["debug-shell"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_debug-shell_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable debug-shell
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_debug-shell_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_debug-shell_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_burstaction" selected="false" severity="high">
              <xccdf-1.2:title>Disable Ctrl-Alt-Del Burst Action</xccdf-1.2:title>
              <xccdf-1.2:description>By default, <html:code>SystemD</html:code> will reboot the system if the <html:code>Ctrl-Alt-Del</html:code>
key sequence is pressed Ctrl-Alt-Delete more than 7 times in 2 seconds.
<html:br/><html:br/>
To configure the system to ignore the <html:code>CtrlAltDelBurstAction</html:code>

setting, add or modify the following to <html:code>/etc/systemd/system.conf</html:code>:
<html:pre>CtrlAltDelBurstAction=none</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="functionality">Disabling the <html:code>Ctrl-Alt-Del</html:code> key sequence
in <html:code>/etc/init/control-alt-delete.conf</html:code> DOES NOT disable the <html:code>Ctrl-Alt-Del</html:code>
key sequence if running in <html:code>runlevel 6</html:code> (e.g. in GNOME, KDE, etc.)! The
<html:code>Ctrl-Alt-Del</html:code> key sequence will only be disabled if running in
the non-graphical <html:code>runlevel 3</html:code>.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000324-GPOS-00125</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230531r1155396_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>A locally logged-in user who presses Ctrl-Alt-Del, when at the console,
can reboot the system. If accidentally pressed, as could happen in
the case of mixed OS environment, this can create the risk of short-term
loss of availability of systems due to unintentional reboot.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_systemd"/>
              <xccdf-1.2:fix id="disable_ctrlaltdel_burstaction" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q systemd; }; then

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^CtrlAltDelBurstAction=")

# shellcheck disable=SC2059
printf -v formatted_output "%s=%s" "$stripped_key" "none"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^CtrlAltDelBurstAction=\\&gt;" "/etc/systemd/system.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^CtrlAltDelBurstAction=\\&gt;.*/$escaped_formatted_output/gi" "/etc/systemd/system.conf"
else
    if [[ -s "/etc/systemd/system.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/systemd/system.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/systemd/system.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/systemd/system.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="disable_ctrlaltdel_burstaction" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040172
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(a)
  - disable_ctrlaltdel_burstaction
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed

- name: Disable Ctrl-Alt-Del Burst Action
  ansible.builtin.lineinfile:
    dest: /etc/systemd/system.conf
    state: present
    regexp: ^CtrlAltDelBurstAction
    line: CtrlAltDelBurstAction=none
    create: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"systemd" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040172
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(a)
  - disable_ctrlaltdel_burstaction
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="disable_ctrlaltdel_burstaction" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,CtrlAltDelBurstAction%3Dnone
        mode: 0644
        path: /etc/systemd/system.conf.d/disable_ctrlaltdelete_burstaction.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-disable_ctrlaltdel_burstaction:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-disable_ctrlaltdel_burstaction_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_reboot" selected="false" severity="high">
              <xccdf-1.2:title>Disable Ctrl-Alt-Del Reboot Activation</xccdf-1.2:title>
              <xccdf-1.2:description>By default, <html:code>SystemD</html:code> will reboot the system if the <html:code>Ctrl-Alt-Del</html:code>
key sequence is pressed.
<html:br/><html:br/>
To configure the system to ignore the <html:code>Ctrl-Alt-Del</html:code> key sequence from the

command line instead of rebooting the system, do either of the following:
<html:pre>ln -sf /dev/null /etc/systemd/system/ctrl-alt-del.target</html:pre>
or
<html:pre>systemctl mask ctrl-alt-del.target</html:pre>
<html:br/><html:br/>
Do not simply delete the <html:code>/usr/lib/systemd/system/ctrl-alt-del.service</html:code> file,
as this file may be restored during future system updates.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000324-GPOS-00125</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040170</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230529r1017289_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>A locally logged-in user who presses Ctrl-Alt-Del, when at the console,
can reboot the system. If accidentally pressed, as could happen in
the case of mixed OS environment, this can create the risk of short-term
loss of availability of systems due to unintentional reboot.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="disable_ctrlaltdel_reboot" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    systemctl disable ctrl-alt-del.target
    systemctl mask ctrl-alt-del.target
else
    systemctl disable --now ctrl-alt-del.target
    systemctl mask --now ctrl-alt-del.target
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="disable_ctrlaltdel_reboot" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040170
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - disable_ctrlaltdel_reboot
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed

- name: Disable Ctrl-Alt-Del Reboot Activation
  ansible.builtin.systemd:
    name: ctrl-alt-del.target
    force: true
    masked: true
    state: stopped
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040170
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - disable_ctrlaltdel_reboot
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="disable_ctrlaltdel_reboot" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: ctrl-alt-del.target
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-disable_ctrlaltdel_reboot:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-disable_ctrlaltdel_reboot_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_disable_interactive_boot" selected="false" severity="medium">
              <xccdf-1.2:title>Verify that Interactive Boot is Disabled</xccdf-1.2:title>
              <xccdf-1.2:description>AlmaLinux OS 8 systems support an "interactive boot" option that can
be used to prevent services from being started. On a AlmaLinux OS 8
system, interactive boot can be enabled by providing a <html:code>1</html:code>,
<html:code>yes</html:code>, <html:code>true</html:code>, or <html:code>on</html:code> value to the
<html:code>systemd.confirm_spawn</html:code> kernel argument in <html:code>/etc/default/grub</html:code>.
Remove any instance of <html:pre>systemd.confirm_spawn=(1|yes|true|on)</html:pre> from
the kernel arguments in that file to disable interactive boot.
Recovery booting must also be disabled. Confirm that
<html:code>GRUB_DISABLE_RECOVERY=true</html:code> is set in  <html:code>/etc/default/grub</html:code>.
It is also required to change the runtime configuration, run:

<html:pre>/sbin/grubby --update-kernel=ALL --remove-args="systemd.confirm_spawn"</html:pre>

<html:pre>grub2-mkconfig -o /boot/grub2/grub.cfg</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-2(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Using interactive or recovery boot, the console user could disable auditing, firewalls,
or other services, weakening system security.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#grub2"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="grub2_disable_interactive_boot" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q grub2-common; }; then

# Verify that Interactive Boot is Disabled in /etc/default/grub
CONFIRM_SPAWN_YES="systemd.confirm_spawn\(=\(1\|yes\|true\|on\)\|\b\)"
CONFIRM_SPAWN_NO="systemd.confirm_spawn=no"

if grep -q "\(GRUB_CMDLINE_LINUX\|GRUB_CMDLINE_LINUX_DEFAULT\)" /etc/default/grub
then
	sed -i "s/${CONFIRM_SPAWN_YES}/${CONFIRM_SPAWN_NO}/" /etc/default/grub
fi

# make sure GRUB_DISABLE_RECOVERY=true
if grep -q '^GRUB_DISABLE_RECOVERY=.*'  '/etc/default/grub' ; then
       # modify the GRUB command-line if an GRUB_DISABLE_RECOVERY= arg already exists
       sed -i 's/GRUB_DISABLE_RECOVERY=.*/GRUB_DISABLE_RECOVERY=true/' /etc/default/grub
else
       # no GRUB_DISABLE_RECOVERY=arg is present, append it to file
       echo "GRUB_DISABLE_RECOVERY=true"  &gt;&gt; '/etc/default/grub'
fi



# Remove 'systemd.confirm_spawn' kernel argument also from runtime settings
/sbin/grubby --update-kernel=ALL --remove-args="systemd.confirm_spawn"


#Regen grub.cfg handle updated GRUB_DISABLE_RECOVERY and confirm_spawn
grub2-mkconfig -o /boot/grub2/grub.cfg

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="grub2_disable_interactive_boot" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.2
  - NIST-800-171-3.4.5
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-2(1)
  - grub2_disable_interactive_boot
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Verify that Interactive Boot is Disabled - Verify GRUB_DISABLE_RECOVERY=true
  ansible.builtin.lineinfile:
    path: /etc/default/grub
    regexp: ^GRUB_DISABLE_RECOVERY=.*
    line: GRUB_DISABLE_RECOVERY=true
    state: present
  register: grub_disable_recovery_changed
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.2
  - NIST-800-171-3.4.5
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-2(1)
  - grub2_disable_interactive_boot
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Verify that Interactive Boot is Disabled - Verify that Interactive Boot is
    Disabled in /etc/default/grub
  ansible.builtin.replace:
    dest: /etc/default/grub
    regexp: systemd.confirm_spawn(=(1|yes|true|on)|\b)
    replace: systemd.confirm_spawn=no
  register: grub_confirm_spawn_changed
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.2
  - NIST-800-171-3.4.5
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-2(1)
  - grub2_disable_interactive_boot
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Verify that Interactive Boot is Disabled - Verify that Interactive Boot is
    Disabled (runtime)
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --remove-args="systemd.confirm_spawn"
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  - grub_confirm_spawn_changed is changed
  tags:
  - NIST-800-171-3.1.2
  - NIST-800-171-3.4.5
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-2(1)
  - grub2_disable_interactive_boot
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Verify that Interactive Boot is Disabled - Regen grub.cfg handle updated GRUB_DISABLE_RECOVERY
    and confirm_spawn
  ansible.builtin.command: grub2-mkconfig -o  /boot/grub2/grub.cfg
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  - grub_disable_recovery_changed is changed or grub_confirm_spawn_changed is changed
  tags:
  - NIST-800-171-3.1.2
  - NIST-800-171-3.4.5
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-2(1)
  - grub2_disable_interactive_boot
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_disable_interactive_boot:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_disable_interactive_boot_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_logind_session_timeout" selected="false" severity="medium">
              <xccdf-1.2:title>Configure Logind to terminate idle sessions after certain time of inactivity</xccdf-1.2:title>
              <xccdf-1.2:description>To configure <html:code>logind</html:code> service to terminate inactive user sessions
after <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_logind_session_timeout" use="legacy"/> seconds, edit the file
<html:code>/etc/systemd/logind.conf</html:code>. Ensure that there is a section
<html:pre>[Login]</html:pre> which contains the configuration
<html:pre>StopIdleSessionSec=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_logind_session_timeout" use="legacy"/></html:pre>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(5)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000163-GPOS-00072</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R32</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020035</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-257258r1069328_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Terminating an idle session within a short time period reduces the window of
opportunity for unauthorized personnel to take control of a management
session enabled on the console or console port that has been let unattended.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#os_linux_ol_gt_or_eq_8_7"/>
              <xccdf-1.2:platform idref="#os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0"/>
              <xccdf-1.2:platform idref="#os_linux_sles_gt_or_eq_15"/>
              <xccdf-1.2:fix id="logind_session_timeout" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { ( ( grep -qP "^ID=[\"']?rhel[\"']?$" "/etc/os-release" &amp;&amp; { real="$(grep -P "^VERSION_ID=[\"']?[\w.]+[\"']?$" /etc/os-release | sed "s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")"; expected="8.7"; printf "%s\n%s" "$expected" "$real" | sort -VC; } &amp;&amp; grep -qP "^ID=[\"']?rhel[\"']?$" "/etc/os-release" &amp;&amp; { real="$(grep -P "^VERSION_ID=[\"']?[\w.]+[\"']?$" /etc/os-release | sed "s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")"; expected="9.0"; [[ "$real" != "$expected" ]]; } ) ) || ( grep -qP "^ID=[\"']?ol[\"']?$" "/etc/os-release" &amp;&amp; { real="$(grep -P "^VERSION_ID=[\"']?[\w.]+[\"']?$" /etc/os-release | sed "s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")"; expected="8.7"; printf "%s\n%s" "$expected" "$real" | sort -VC; } ) || ( grep -qP "^ID=[\"']?sles[\"']?$" "/etc/os-release" &amp;&amp; { real="$(grep -P "^VERSION_ID=[\"']?[\w.]+[\"']?$" /etc/os-release | sed "s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")"; expected="15"; printf "%s\n%s" "$expected" "$real" | sort -VC; } ); }; then

var_logind_session_timeout='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_logind_session_timeout" use="legacy"/>'


# Remove StopIdleSessionSec from main config

LC_ALL=C sed -i "/^\s*StopIdleSessionSec\s*=/Id" "/etc/systemd/logind.conf"







# Try find '[Login]' and 'StopIdleSessionSec' in '/etc/systemd/logind.conf', if it exists, set
# to '$var_logind_session_timeout', if it isn't here, add it, if '[Login]' doesn't exist, add it there
if grep -qzosP '[[:space:]]*\[Login]([^\n\[]*\n+)+?[[:space:]]*StopIdleSessionSec' '/etc/systemd/logind.conf'; then
    
    sed -i "s/StopIdleSessionSec[^(\n)]*/StopIdleSessionSec=$var_logind_session_timeout/" '/etc/systemd/logind.conf'
elif grep -qs '[[:space:]]*\[Login]' '/etc/systemd/logind.conf'; then
    sed -i "/[[:space:]]*\[Login]/a StopIdleSessionSec=$var_logind_session_timeout" '/etc/systemd/logind.conf'
else
    if test -d "/etc/systemd"; then
        printf '%s\n' '[Login]' "StopIdleSessionSec=$var_logind_session_timeout" &gt;&gt; '/etc/systemd/logind.conf'
    else
        echo "Config file directory '/etc/systemd' doesnt exist, not remediating, assuming non-applicability." &gt;&amp;2
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="logind_session_timeout" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.6
  - DISA-STIG-RHEL-08-020035
  - NIST-800-171-3.1.11
  - NIST-800-53-AC-12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-2(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-10
  - PCI-DSS-Req-8.1.8
  - logind_session_timeout
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
- name: XCCDF Value var_logind_session_timeout # promote to variable
  set_fact:
    var_logind_session_timeout: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_logind_session_timeout" use="legacy"/>
  tags:
    - always

- name: Remove StopIdleSessionSec from main config
  ansible.builtin.lineinfile:
    path: /etc/systemd/logind.conf
    regexp: ^\s*StopIdleSessionSec\s*=
    state: absent
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.7',
    '&gt;=') and ansible_distribution == 'RedHat' and ansible_distribution_version is
    version('9.0', '!=') ) or ansible_distribution == 'OracleLinux' and ansible_distribution_version
    is version('8.7', '&gt;=') or ansible_distribution == 'SLES' and ansible_distribution_version
    is version('15', '&gt;=')
  tags:
  - CJIS-5.5.6
  - DISA-STIG-RHEL-08-020035
  - NIST-800-171-3.1.11
  - NIST-800-53-AC-12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-2(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-10
  - PCI-DSS-Req-8.1.8
  - logind_session_timeout
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set 'StopIdleSessionSec' to '{{ var_logind_session_timeout }}' in the [Login]
    section of '/etc/systemd/logind.conf'
  community.general.ini_file:
    path: /etc/systemd/logind.conf
    section: Login
    option: StopIdleSessionSec
    value: '{{ var_logind_session_timeout }}'
    create: true
    mode: 420
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.7',
    '&gt;=') and ansible_distribution == 'RedHat' and ansible_distribution_version is
    version('9.0', '!=') ) or ansible_distribution == 'OracleLinux' and ansible_distribution_version
    is version('8.7', '&gt;=') or ansible_distribution == 'SLES' and ansible_distribution_version
    is version('15', '&gt;=')
  tags:
  - CJIS-5.5.6
  - DISA-STIG-RHEL-08-020035
  - NIST-800-171-3.1.11
  - NIST-800-53-AC-12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-2(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-10
  - PCI-DSS-Req-8.1.8
  - logind_session_timeout
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_logind_session_timeout:var:1" value-id="xccdf_org.ssgproject.content_value_var_logind_session_timeout"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-logind_session_timeout:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-logind_session_timeout_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_require_emergency_target_auth" selected="false" severity="medium">
              <xccdf-1.2:title>Require Authentication for Emergency Systemd Target</xccdf-1.2:title>
              <xccdf-1.2:description>Emergency mode is intended as a system recovery
method, providing a single user root access to the system
during a failed boot sequence.
<html:br/><html:br/>
By default, Emergency mode is protected by requiring a password and is set
in <html:code>/usr/lib/systemd/system/emergency.service</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000080-GPOS-00048</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010152</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244523r1137691_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>This prevents attackers with physical access from trivially bypassing security
on the machine and gaining root access. Such accesses are further prevented
by configuring the bootloader password.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="require_emergency_target_auth" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

service_file="/usr/lib/systemd/system/emergency.service"


sulogin='/bin/sh -c "/sbin/sulogin; /usr/bin/systemctl --fail --no-block default"'


if grep "^ExecStart=.*" "$service_file" ; then
    sed -i "s%^ExecStart=.*%ExecStart=-$sulogin%" "$service_file"
else
    echo "ExecStart=-$sulogin" &gt;&gt; "$service_file"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="require_emergency_target_auth" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010152
  - NIST-800-171-3.1.1
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-3
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - require_emergency_target_auth
  - restrict_strategy

- name: Require emergency mode password
  ansible.builtin.lineinfile:
    create: true
    dest: /usr/lib/systemd/system/emergency.service
    regexp: ^#?ExecStart=
    line: ExecStart=-/bin/sh -c "/sbin/sulogin; /usr/bin/systemctl --fail --no-block
      default"
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010152
  - NIST-800-171-3.1.1
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-3
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - require_emergency_target_auth
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-require_emergency_target_auth:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-require_emergency_target_auth_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_require_singleuser_auth" selected="false" severity="medium">
              <xccdf-1.2:title>Require Authentication for Single User Mode</xccdf-1.2:title>
              <xccdf-1.2:description>Single-user mode is intended as a system recovery
method, providing a single user root access to the system by
providing a boot option at startup.
<html:br/><html:br/>
By default, single-user mode is protected by requiring a password and is set
in <html:code>/usr/lib/systemd/system/rescue.service</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_UAU.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000080-GPOS-00048</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010151</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230236r1137691_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>This prevents attackers with physical access from trivially bypassing security
on the machine and gaining root access. Such accesses are further prevented
by configuring the bootloader password.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="require_singleuser_auth" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

found=false

# set value in all files if they contain section or key
for f in $(echo -n "/etc/systemd/system/rescue.service.d/10-oscap.conf /etc/systemd/system/rescue.service.d/*.conf"); do
    if [ ! -e "$f" ]; then
        continue
    fi

    # find key in section and change value
    if grep -qzosP "(?m)^[[:space:]]*\[Service\]([^\n\[]*\n+)+?[[:space:]]*ExecStart" "$f"; then
        if ! grep -qzosP "(?m)^[[:space:]]*ExecStart[[:space:]]*=[[:space:]]*-/bin/sh -c "/sbin/sulogin; /usr/bin/systemctl --fail --no-block default"" "$f"; then

            sed -i "/^[[:space:]]*ExecStart/s/\([[:blank:]]*=[[:blank:]]*\).*/\1-\/bin\/sh -c "\/sbin\/sulogin; \/usr\/bin\/systemctl --fail --no-block default"/" "$f"

        fi

        found=true

    # find section and add key = value to it
    elif grep -qs "^[[:space:]]*\[Service\]" "$f"; then

            sed -i "/^[[:space:]]*\[Service\]/a ExecStart=-\/bin\/sh -c "\/sbin\/sulogin; \/usr\/bin\/systemctl --fail --no-block default"" "$f"

            found=true
    fi
done

# if section not in any file, append section with key = value to FIRST file in files parameter
if ! $found ; then
    file=$(echo "/etc/systemd/system/rescue.service.d/10-oscap.conf /etc/systemd/system/rescue.service.d/*.conf" | cut -f1 -d ' ')
    mkdir -p "$(dirname "$file")"

    echo -e "[Service]\nExecStart=-/bin/sh -c "/sbin/sulogin; /usr/bin/systemctl --fail --no-block default"" &gt;&gt; "$file"

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="require_singleuser_auth" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010151
  - NIST-800-171-3.1.1
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-3
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - require_singleuser_auth
  - restrict_strategy

- name: Require Authentication for Single User Mode - Require single user mode password
  ansible.builtin.lineinfile:
    create: true
    dest: /usr/lib/systemd/system/rescue.service
    regexp: ^#?ExecStart=
    line: ExecStart=-/bin/sh -c "/sbin/sulogin; /usr/bin/systemctl --fail --no-block
      default"
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010151
  - NIST-800-171-3.1.1
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-3
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - require_singleuser_auth
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-require_singleuser_auth:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-require_singleuser_auth_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_screen_locking">
              <xccdf-1.2:title>Configure Screen Locking</xccdf-1.2:title>
              <xccdf-1.2:description>When a user must temporarily leave an account
logged-in, screen locking should be employed to prevent passersby
from abusing the account. User education and training is
particularly important for screen locking to be effective, and policies
can be implemented to reinforce this.
<html:br/><html:br/>
Automatic screen locking is only meant as a safeguard for
those cases where a user forgot to lock the screen.</xccdf-1.2:description>
              <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_console_screen_locking">
                <xccdf-1.2:title>Configure Console Screen Locking</xccdf-1.2:title>
                <xccdf-1.2:description>A console screen locking mechanism is a temporary action taken when a user
stops work and moves away from the immediate physical vicinity of the
information system but does not logout because of the temporary nature of
the absence. Rather than relying on the user to manually lock their
operation system session prior to vacating the vicinity, operating systems
need to be able to identify when a user's session has idled and take action
to initiate the session lock.</xccdf-1.2:description>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_tmux_installed" selected="false" severity="medium">
                  <xccdf-1.2:title>Install the tmux Package</xccdf-1.2:title>
                  <xccdf-1.2:description>To enable console screen locking, install the <html:code>tmux</html:code> package.
The <html:code>tmux</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install tmux</html:pre>
A session lock is a temporary action taken when a user stops work and moves away from the immediate physical vicinity of the information system but does not want to log out because of the temporary nature of the absence.
The session lock is implemented at the point where session activity can be determined.
Rather than be forced to wait for a period of time to expire before the user session can be locked, AlmaLinux OS 8 needs to provide users with the ability to manually invoke a session lock so users can secure their session if it is necessary to temporarily vacate the immediate physical vicinity.
Instruct users to begin new terminal sessions with the following command:
<html:pre>$ tmux</html:pre>
The console can now be locked with the following key combination:
<html:pre>ctrl+b :lock-session</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_MOF_EXT.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FTA_SSL.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000030-GPOS-00011</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000028-GPOS-00009</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>A session time-out lock is a temporary action taken when a user stops work and moves away from the immediate
physical vicinity of the information system but does not logout because of the temporary nature of the absence.
Rather than relying on the user to manually lock their operation system session prior to vacating the vicinity,
operating systems need to be able to identify when a user's session has idled and take action to initiate the
session lock.
<html:br/><html:br/>
The <html:code>tmux</html:code> package allows for a session lock to be implemented and configured.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_tmux_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "tmux" ; then
    yum install -y "tmux"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_tmux_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_tmux_installed

- name: Ensure tmux is installed
  ansible.builtin.package:
    name: tmux
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.10
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_tmux_installed
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_tmux_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_tmux

class install_tmux {
  package { 'tmux':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_tmux_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=tmux
</xccdf-1.2:fix>
                  <xccdf-1.2:fix id="package_tmux_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "tmux"
version = "*"
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_tmux_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install tmux
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_tmux_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install tmux
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_tmux_installed:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_tmux_installed_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_bashrc_exec_tmux" selected="false" severity="medium">
                  <xccdf-1.2:title>Support session locking with tmux</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>tmux</html:code> terminal multiplexer is used to implement
automatic session locking. It should be started from
<html:code>/etc/bashrc</html:code> or drop-in files within <html:code>/etc/profile.d/</html:code>.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_MOF_EXT.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FTA_SSL.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000031-GPOS-00012</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000028-GPOS-00009</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000030-GPOS-00011</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Unlike <html:code>bash</html:code> itself, the <html:code>tmux</html:code> terminal multiplexer
provides a mechanism to lock sessions after period of inactivity.
A session lock is a temporary action taken when a user stops work and moves away from the
immediate physical vicinity of the information system but does not want to
log out because of the temporary nature of the absence.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_tmux"/>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="configure_bashrc_exec_tmux" reboot="true" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q tmux; }; then

if ! grep -x '  case "$name" in (sshd|login) exec tmux ;; esac' /etc/bashrc; then
    cat &gt;&gt; /etc/profile.d/tmux.sh &lt;&lt;'EOF'
if [ "$PS1" ]; then
  parent=$(ps -o ppid= -p $$)
  name=$(ps -o comm= -p $parent)
  case "$name" in (sshd|login) exec tmux ;; esac
fi
EOF
    chmod 0644 /etc/profile.d/tmux.sh
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="configure_bashrc_exec_tmux" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_bashrc_exec_tmux
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Support session locking with tmux: Determine If the Tmux Launch Script Is
    Present in /etc/bashrc'
  ansible.builtin.find:
    paths: /etc
    patterns: bashrc
    contains: .*case "$name" in sshd|login\) exec tmux ;; esac.*
  register: tmux_in_bashrc
  when:
  - '"kernel" in ansible_facts.packages'
  - '"tmux" in ansible_facts.packages'
  tags:
  - configure_bashrc_exec_tmux
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Support session locking with tmux: Determine If the Tmux Launch Script Is
    Present in /etc/profile.d/*.sh'
  ansible.builtin.find:
    paths: /etc/profile.d
    patterns: '*.sh'
    contains: .*case "$name" in sshd|login\) exec tmux ;; esac.*
  register: tmux_in_profile_d
  when:
  - '"kernel" in ansible_facts.packages'
  - '"tmux" in ansible_facts.packages'
  tags:
  - configure_bashrc_exec_tmux
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Support session locking with tmux: Insert the Correct Script into /etc/profile.d/tmux.sh'
  ansible.builtin.blockinfile:
    path: /etc/profile.d/tmux.sh
    block: |
      if [ "$PS1" ]; then
        parent=$(ps -o ppid= -p $$)
        name=$(ps -o comm= -p $parent)
        case "$name" in sshd|login) exec tmux ;; esac
      fi
    create: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"tmux" in ansible_facts.packages'
  - tmux_in_bashrc is defined and tmux_in_bashrc.matched == 0
  - tmux_in_profile_d is defined and tmux_in_profile_d.matched == 0
  tags:
  - configure_bashrc_exec_tmux
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-configure_bashrc_exec_tmux:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_bashrc_exec_tmux_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_bashrc_tmux" selected="false" severity="medium">
                  <xccdf-1.2:title>Support session locking with tmux (not enforcing)</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>tmux</html:code> terminal multiplexer is used to implement
automatic session locking. It should be started from
<html:code>/etc/bashrc</html:code> or drop-in files within <html:code>/etc/profile.d/</html:code>.</xccdf-1.2:description>
                  <xccdf-1.2:warning category="general">This rule configures Tmux to be executed in a way that exiting Tmux
drops the user into a regular shell instead of logging them out, therefore the session locking mechanism is not enforced on the user.</xccdf-1.2:warning>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000031-GPOS-00012</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000028-GPOS-00009</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000030-GPOS-00011</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Unlike <html:code>bash</html:code> itself, the <html:code>tmux</html:code> terminal multiplexer
provides a mechanism to lock sessions after period of inactivity.
A session lock is a temporary action taken when a user stops work and moves away from the
immediate physical vicinity of the information system but does not want to
log out because of the temporary nature of the absence.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_tmux"/>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="configure_bashrc_tmux" reboot="true" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q tmux; }; then

if ! grep -x '  case "$name" in (sshd|login) tmux ;; esac' /etc/bashrc /etc/profile.d/*.sh; then
    cat &gt;&gt; /etc/profile.d/tmux.sh &lt;&lt;'EOF'
if [ "$PS1" ]; then
  parent=$(ps -o ppid= -p $$)
  name=$(ps -o comm= -p $parent)
  case "$name" in (sshd|login) tmux ;; esac
fi
EOF
    chmod 0644 /etc/profile.d/tmux.sh
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="configure_bashrc_tmux" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_bashrc_tmux
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Support session locking with tmux (not enforcing): Determine if the Tmux
    launch script is present in /etc/bashrc'
  ansible.builtin.find:
    paths: /etc
    patterns: bashrc
    contains: .*case "$name" in \(sshd|login\) tmux ;; esac.*
  register: tmux_in_bashrc
  when:
  - '"kernel" in ansible_facts.packages'
  - '"tmux" in ansible_facts.packages'
  tags:
  - configure_bashrc_tmux
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Support session locking with tmux (not enforcing): Determine if the Tmux
    launch script is present in /etc/profile.d/*.sh'
  ansible.builtin.find:
    paths: /etc/profile.d
    patterns: '*.sh'
    contains: .*case "$name" in \(sshd|login\) tmux ;; esac.*
  register: tmux_in_profile_d
  when:
  - '"kernel" in ansible_facts.packages'
  - '"tmux" in ansible_facts.packages'
  tags:
  - configure_bashrc_tmux
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: 'Support session locking with tmux (not enforcing): Insert the correct script
    into /etc/profile.d/tmux.sh'
  ansible.builtin.blockinfile:
    path: /etc/profile.d/tmux.sh
    block: |
      if [ "$PS1" ]; then
        parent=$(ps -o ppid= -p $$)
        name=$(ps -o comm= -p $parent)
        case "$name" in (sshd|login) tmux ;; esac
      fi
    create: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"tmux" in ansible_facts.packages'
  - tmux_in_bashrc is defined and tmux_in_bashrc.matched == 0
  - tmux_in_profile_d is defined and tmux_in_profile_d.matched == 0
  tags:
  - configure_bashrc_tmux
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-configure_bashrc_tmux:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_bashrc_tmux_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_tmux_lock_after_time" selected="false" severity="medium">
                  <xccdf-1.2:title>Configure tmux to lock session after inactivity</xccdf-1.2:title>
                  <xccdf-1.2:description>To enable console screen locking in <html:code>tmux</html:code> terminal multiplexer
after a period of inactivity,
the <html:code>lock-after-time</html:code> option has to be set to a value greater than 0 and less than
or equal to 900 in <html:code>/etc/tmux.conf</html:code>.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_MOF_EXT.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FTA_SSL.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000029-GPOS-00010</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000031-GPOS-00012</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Locking the session after a period of inactivity limits the
potential exposure if the session is left unattended.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_tmux"/>
                  <xccdf-1.2:fix id="configure_tmux_lock_after_time" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q tmux; }; then

tmux_conf="/etc/tmux.conf"

if grep -qP '^\s*set\s+-g\s+lock-after-time' "$tmux_conf" ; then
    sed -i 's/^\s*set\s\+-g\s\+lock-after-time.*$/set -g lock-after-time 900/' "$tmux_conf"
else
    echo "set -g lock-after-time 900" &gt;&gt; "$tmux_conf"
fi
chmod 0644 "$tmux_conf"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="configure_tmux_lock_after_time" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_tmux_lock_after_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure tmux to lock session after inactivity
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/tmux.conf
      create: true
      regexp: (?i)^\s*set -g lock-after-time\s+
      mode: '0644'
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/tmux.conf
    ansible.builtin.lineinfile:
      path: /etc/tmux.conf
      create: true
      regexp: (?i)^\s*set -g lock-after-time\s+
      mode: '0644'
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/tmux.conf
    ansible.builtin.lineinfile:
      path: /etc/tmux.conf
      create: true
      regexp: (?i)^\s*set -g lock-after-time\s+
      mode: '0644'
      line: set -g lock-after-time 900
      state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"tmux" in ansible_facts.packages'
  tags:
  - configure_tmux_lock_after_time
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-configure_tmux_lock_after_time:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_tmux_lock_after_time_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_tmux_lock_command" selected="false" severity="medium">
                  <xccdf-1.2:title>Configure the tmux Lock Command</xccdf-1.2:title>
                  <xccdf-1.2:description>To enable console screen locking in <html:code>tmux</html:code> terminal multiplexer,
the <html:code>vlock</html:code> command must be configured to be used as a locking
mechanism.
Add the following line to <html:code>/etc/tmux.conf</html:code>:
<html:pre>set -g lock-command vlock</html:pre>.
The console can now be locked with the following key combination:
<html:pre>ctrl+b :lock-session</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-11(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-11(b)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_MOF_EXT.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FTA_SSL.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000028-GPOS-00009</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000030-GPOS-00011</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>The <html:code>tmux</html:code> package allows for a session lock to be implemented and configured.
However, the session lock is implemented by an external command. The <html:code>tmux</html:code>
default configuration does not contain an effective session lock.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_tmux"/>
                  <xccdf-1.2:fix id="configure_tmux_lock_command" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q tmux; }; then

tmux_conf="/etc/tmux.conf"

if grep -qP '^\s*set\s+-g\s+lock-command' "$tmux_conf" ; then
    sed -i 's/^\s*set\s\+-g\s\+lock-command.*$/set -g lock-command vlock/' "$tmux_conf"
else
    echo "set -g lock-command vlock" &gt;&gt; "$tmux_conf"
fi
chmod 0644 "$tmux_conf"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="configure_tmux_lock_command" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-11(a)
  - NIST-800-53-AC-11(b)
  - NIST-800-53-CM-6(a)
  - configure_tmux_lock_command
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure the tmux Lock Command
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/tmux.conf
      create: true
      regexp: (?i)^\s*set -g lock-command\s+
      mode: '0644'
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/tmux.conf
    ansible.builtin.lineinfile:
      path: /etc/tmux.conf
      create: true
      regexp: (?i)^\s*set -g lock-command\s+
      mode: '0644'
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/tmux.conf
    ansible.builtin.lineinfile:
      path: /etc/tmux.conf
      create: true
      regexp: (?i)^\s*set -g lock-command\s+
      mode: '0644'
      line: set -g lock-command vlock
      state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"tmux" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-11(a)
  - NIST-800-53-AC-11(b)
  - NIST-800-53-CM-6(a)
  - configure_tmux_lock_command
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-configure_tmux_lock_command:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_tmux_lock_command_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_tmux_lock_keybinding" selected="false" severity="low">
                  <xccdf-1.2:title>Configure the tmux lock session key binding</xccdf-1.2:title>
                  <xccdf-1.2:description>To set a key binding for the screen locking in <html:code>tmux</html:code> terminal multiplexer,
the <html:code>session-lock</html:code> command must be bound to a key.
Add the following line to <html:code>/etc/tmux.conf</html:code>:
<html:pre>bind X lock-session</html:pre>.
The console can now be locked with the following key combination:
<html:pre>Ctrl+b Shift+x</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000028-GPOS-00009</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000030-GPOS-00011</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>The <html:code>tmux</html:code> package allows for a session lock to be implemented and configured.
However, the session lock is implemented by an external command. The <html:code>tmux</html:code>
default configuration does not contain an effective session lock.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_tmux"/>
                  <xccdf-1.2:fix id="configure_tmux_lock_keybinding" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q tmux; }; then

tmux_conf="/etc/tmux.conf"

if ! grep -qP '^\s*bind\s+\w\s+lock-session' "$tmux_conf" ; then
    echo "bind X lock-session" &gt;&gt; "$tmux_conf"
fi
chmod 0644 "$tmux_conf"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="configure_tmux_lock_keybinding" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - configure_tmux_lock_keybinding
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed

- name: Check for duplicate values
  ansible.builtin.lineinfile:
    path: /etc/tmux.conf
    create: true
    regexp: (?i)\s*bind\s+\w\s+lock-session.*$
    mode: '0644'
    state: absent
  check_mode: true
  changed_when: false
  register: dupes
  when:
  - '"kernel" in ansible_facts.packages'
  - '"tmux" in ansible_facts.packages'
  tags:
  - configure_strategy
  - configure_tmux_lock_keybinding
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed

- name: Deduplicate values from /etc/tmux.conf
  ansible.builtin.lineinfile:
    path: /etc/tmux.conf
    create: true
    regexp: (?i)\s*bind\s+\w\s+lock-session.*$
    mode: '0644'
    state: absent
  when:
  - '"kernel" in ansible_facts.packages'
  - '"tmux" in ansible_facts.packages'
  - dupes.found is defined and dupes.found &gt; 1
  tags:
  - configure_strategy
  - configure_tmux_lock_keybinding
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed

- name: Insert correct line into /etc/tmux.conf
  ansible.builtin.lineinfile:
    path: /etc/tmux.conf
    create: true
    regexp: (?i)\s*bind\s+\w\s+lock-session.*$
    mode: '0644'
    line: bind X lock-session
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"tmux" in ansible_facts.packages'
  tags:
  - configure_strategy
  - configure_tmux_lock_keybinding
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-configure_tmux_lock_keybinding:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_tmux_lock_keybinding_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_tmux_in_shells" selected="false" severity="low">
                  <xccdf-1.2:title>Prevent user from disabling the screen lock</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>tmux</html:code> terminal multiplexer is used to implement
automatic session locking. It should not be listed in
<html:code>/etc/shells</html:code>.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_MOF_EXT.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FTA_SSL.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000324-GPOS-00125</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000028-GPOS-00009</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000030-GPOS-00011</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Not listing <html:code>tmux</html:code> among permitted shells
prevents malicious program running as user
from lowering security by disabling the screen lock.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix id="no_tmux_in_shells" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if grep -q 'tmux\s*$' /etc/shells ; then
	sed -i '/tmux\s*$/d' /etc/shells
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="no_tmux_in_shells" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - no_tmux_in_shells
  - restrict_strategy

- name: Prevent user from disabling the screen lock - Ensure tmux line not exists
  ansible.builtin.lineinfile:
    path: /etc/shells
    regex: tmux\s*$
    state: absent
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - no_tmux_in_shells
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:fix id="no_tmux_in_shells" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,/bin/sh%0A/bin/bash%0A/usr/bin/sh%0A/usr/bin/bash%0A
        mode: 0644
        path: /etc/shells
        overwrite: true
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_tmux_in_shells:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_tmux_in_shells_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
              </xccdf-1.2:Group>
              <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_smart_card_login">
                <xccdf-1.2:title>Hardware Tokens for Authentication</xccdf-1.2:title>
                <xccdf-1.2:description>The use of hardware tokens such as smart cards for system login
provides stronger, two-factor authentication than using a username and password.

In Red Hat Enterprise Linux servers and workstations, hardware token login

is not enabled by default and must be enabled in the system settings.</xccdf-1.2:description>
                <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_smartcard_drivers" interactive="true" type="string">
                  <xccdf-1.2:title>OpenSC Smart Card Drivers</xccdf-1.2:title>
                  <xccdf-1.2:description>Choose the Smart Card Driver in use by your organization.
<html:br/>For DoD, choose the <html:code>cac</html:code> driver.
<html:br/>If your driver is not listed and you don't want to use the
<html:code>default</html:code> driver, use the <html:code>other</html:code> option and
manually specify your driver.</xccdf-1.2:description>
                  <xccdf-1.2:value>default</xccdf-1.2:value>
                  <xccdf-1.2:value selector="acos5">acos5</xccdf-1.2:value>
                  <xccdf-1.2:value selector="akis">akis</xccdf-1.2:value>
                  <xccdf-1.2:value selector="asepcos">asepcos</xccdf-1.2:value>
                  <xccdf-1.2:value selector="atrust-acos">atrust-acos</xccdf-1.2:value>
                  <xccdf-1.2:value selector="authentic">authentic</xccdf-1.2:value>
                  <xccdf-1.2:value selector="belpic">belpic</xccdf-1.2:value>
                  <xccdf-1.2:value selector="cac">cac</xccdf-1.2:value>
                  <xccdf-1.2:value selector="cardos">cardos</xccdf-1.2:value>
                  <xccdf-1.2:value selector="coolkey">coolkey</xccdf-1.2:value>
                  <xccdf-1.2:value selector="cyberflex">cyberflex</xccdf-1.2:value>
                  <xccdf-1.2:value selector="dnie">dnie</xccdf-1.2:value>
                  <xccdf-1.2:value selector="entersafe">entersafe</xccdf-1.2:value>
                  <xccdf-1.2:value selector="epass2003">epass2003</xccdf-1.2:value>
                  <xccdf-1.2:value selector="flex">flex</xccdf-1.2:value>
                  <xccdf-1.2:value selector="gemsafeV1">gemsafeV1</xccdf-1.2:value>
                  <xccdf-1.2:value selector="gids">gids</xccdf-1.2:value>
                  <xccdf-1.2:value selector="gpk">gpk</xccdf-1.2:value>
                  <xccdf-1.2:value selector="iasecc">iasecc</xccdf-1.2:value>
                  <xccdf-1.2:value selector="incrypto34">incrypto34</xccdf-1.2:value>
                  <xccdf-1.2:value selector="isoApplet">isoApplet</xccdf-1.2:value>
                  <xccdf-1.2:value selector="itacns">itacns</xccdf-1.2:value>
                  <xccdf-1.2:value selector="jpki">jpki</xccdf-1.2:value>
                  <xccdf-1.2:value selector="MaskTech">MaskTech</xccdf-1.2:value>
                  <xccdf-1.2:value selector="mcrd">mcrd</xccdf-1.2:value>
                  <xccdf-1.2:value selector="muscle">muscle</xccdf-1.2:value>
                  <xccdf-1.2:value selector="myeid">myeid</xccdf-1.2:value>
                  <xccdf-1.2:value selector="npa">npa</xccdf-1.2:value>
                  <xccdf-1.2:value selector="oberthur">oberthur</xccdf-1.2:value>
                  <xccdf-1.2:value selector="openpgp">openpgp</xccdf-1.2:value>
                  <xccdf-1.2:value selector="other">None</xccdf-1.2:value>
                  <xccdf-1.2:value selector="PIV-II">PIV-II</xccdf-1.2:value>
                  <xccdf-1.2:value selector="rutoken_ecp">rutoken_ecp</xccdf-1.2:value>
                  <xccdf-1.2:value selector="rutoken">rutoken</xccdf-1.2:value>
                  <xccdf-1.2:value selector="sc-hsm">sc-hsm</xccdf-1.2:value>
                  <xccdf-1.2:value selector="setcos">setcos</xccdf-1.2:value>
                  <xccdf-1.2:value selector="starcos">starcos</xccdf-1.2:value>
                  <xccdf-1.2:value selector="tcos">tcos</xccdf-1.2:value>
                  <xccdf-1.2:value selector="westcos">westcos</xccdf-1.2:value>
                </xccdf-1.2:Value>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_opensc_installed" selected="false" severity="medium">
                  <xccdf-1.2:title>Install the opensc Package For Multifactor Authentication</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>opensc</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install opensc</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000375-GPOS-00160</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000376-GPOS-00161</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1386</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010410</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230275r958816_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Using an authentication device, such as a CAC or token that is separate from
the information system, ensures that even if the information system is
compromised, that compromise will not affect credentials stored on the
authentication device.
<html:br/><html:br/>
Multifactor solutions that require devices separate from
information systems gaining access include, for example, hardware tokens
providing time-based or challenge-response authenticators and smart cards
or similar secure authentication devices issued by an organization or identity provider.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_opensc_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "opensc" ; then
    yum install -y "opensc"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_opensc_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010410
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_opensc_installed

- name: Ensure opensc is installed
  ansible.builtin.package:
    name: opensc
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010410
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_opensc_installed
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_opensc_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_opensc

class install_opensc {
  package { 'opensc':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_opensc_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=opensc
</xccdf-1.2:fix>
                  <xccdf-1.2:fix id="package_opensc_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "opensc"
version = "*"
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_opensc_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install opensc
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_opensc_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install opensc
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_opensc_installed:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_opensc_installed_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed" selected="false" severity="medium">
                  <xccdf-1.2:title>Install the pcsc-lite package</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>pcsc-lite</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install pcsc-lite</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000375-GPOS-00160</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1386</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>The pcsc-lite package must be installed if it is to be available for
multifactor authentication using smartcards.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_pcsc-lite_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "pcsc-lite" ; then
    yum install -y "pcsc-lite"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_pcsc-lite_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_pcsc-lite_installed

- name: Ensure pcsc-lite is installed
  ansible.builtin.package:
    name: pcsc-lite
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_pcsc-lite_installed
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_pcsc-lite_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_pcsc-lite

class install_pcsc-lite {
  package { 'pcsc-lite':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_pcsc-lite_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=pcsc-lite
</xccdf-1.2:fix>
                  <xccdf-1.2:fix id="package_pcsc-lite_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "pcsc-lite"
version = "*"
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_pcsc-lite_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install pcsc-lite
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="package_pcsc-lite_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install pcsc-lite
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_pcsc-lite_installed:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_pcsc-lite_installed_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_install_smartcard_packages" selected="false" severity="medium">
                  <xccdf-1.2:title>Install Smart Card Packages For Multifactor Authentication</xccdf-1.2:title>
                  <xccdf-1.2:description>Configure the operating system to implement multifactor authentication by
installing the required package with the following command:

The <html:code>openssl-pkcs11</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install openssl-pkcs11</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000105-GPOS-00052</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000375-GPOS-00160</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000375-GPOS-00161</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000377-GPOS-00162</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010390</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230273r1017381_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Using an authentication device, such as a CAC or token that is separate from
the information system, ensures that even if the information system is
compromised, that compromise will not affect credentials stored on the
authentication device.
<html:br/><html:br/>
Multifactor solutions that require devices separate from
information systems gaining access include, for example, hardware tokens
providing time-based or challenge-response authenticators and smart cards
or similar secure authentication devices issued by an organization or identity provider.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#not_s390x_arch"/>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="install_smartcard_packages" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { ( ! ( grep -sqE "^.*\.s390x$" /proc/sys/kernel/osrelease || grep -sqE "^s390x$" /proc/sys/kernel/arch; ) ); }; then

if ! rpm -q --quiet "openssl-pkcs11" ; then
    yum install -y "openssl-pkcs11"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="install_smartcard_packages" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010390
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.3
  - enable_strategy
  - install_smartcard_packages
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure openssl-pkcs11 is installed
  ansible.builtin.package:
    name: openssl-pkcs11
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture != "s390x"
  tags:
  - DISA-STIG-RHEL-08-010390
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.3
  - enable_strategy
  - install_smartcard_packages
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="install_smartcard_packages" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_openssl-pkcs11

class install_openssl-pkcs11 {
  package { 'openssl-pkcs11':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="install_smartcard_packages" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=openssl-pkcs11
</xccdf-1.2:fix>
                  <xccdf-1.2:fix id="install_smartcard_packages" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "openssl-pkcs11"
version = "*"
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="install_smartcard_packages" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install openssl-pkcs11
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="install_smartcard_packages" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install openssl-pkcs11
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-install_smartcard_packages:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-install_smartcard_packages_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_pcscd_enabled" selected="false" severity="medium">
                  <xccdf-1.2:title>Enable the pcscd Service</xccdf-1.2:title>
                  <xccdf-1.2:description>
The <html:code>pcscd</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable pcscd.service</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(1)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(2)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(3)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(4)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(6)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(7)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(11)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000375-GPOS-00160</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1386</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Using an authentication device, such as a CAC or token that is separate from
the information system, ensures that even if the information system is
compromised, that compromise will not affect credentials stored on the
authentication device.
<html:br/><html:br/>
Multifactor solutions that require devices separate from
information systems gaining access include, for example, hardware tokens
providing time-based or challenge-response authenticators and smart cards
or similar secure authentication devices issued by an organization or identity provider.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="service_pcscd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'pcscd.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'pcscd.service'
fi
"$SYSTEMCTL_EXEC" enable 'pcscd.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="service_pcscd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2(1)
  - NIST-800-53-IA-2(11)
  - NIST-800-53-IA-2(2)
  - NIST-800-53-IA-2(3)
  - NIST-800-53-IA-2(4)
  - NIST-800-53-IA-2(6)
  - NIST-800-53-IA-2(7)
  - PCI-DSS-Req-8.3
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_pcscd_enabled

- name: Enable the pcscd Service - Enable service pcscd
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable the pcscd Service - Enable Service pcscd
    ansible.builtin.systemd:
      name: pcscd
      enabled: true
      state: started
      masked: false
    when:
    - '"pcsc-lite" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2(1)
  - NIST-800-53-IA-2(11)
  - NIST-800-53-IA-2(2)
  - NIST-800-53-IA-2(3)
  - NIST-800-53-IA-2(4)
  - NIST-800-53-IA-2(6)
  - NIST-800-53-IA-2(7)
  - PCI-DSS-Req-8.3
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_pcscd_enabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="service_pcscd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_pcscd

class enable_pcscd {
  service {'pcscd':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
                  <xccdf-1.2:fix id="service_pcscd_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["pcscd"]
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="service_pcscd_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable pcscd
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_pcscd_enabled:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_pcscd_enabled_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_opensc_card_drivers" selected="false" severity="medium">
                  <xccdf-1.2:title>Configure opensc Smart Card Drivers</xccdf-1.2:title>
                  <xccdf-1.2:description>The OpenSC smart card tool can auto-detect smart card drivers; however,
setting the smart card drivers in use by your organization helps to prevent
users from using unauthorized smart cards. The default smart card driver for this
profile is <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_smartcard_drivers" use="legacy"/></html:code>.
To configure the OpenSC driver, edit the <html:code>/etc/opensc.conf</html:code>
and add the following line into the file in the <html:code>app default</html:code> block,
so it will look like:

<html:pre>
app default {
   ...
   card_drivers = <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_smartcard_drivers" use="legacy"/>;
}
</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(1)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(2)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(3)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(4)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(6)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(7)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(11)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000104-GPOS-00051</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000106-GPOS-00053</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000107-GPOS-00054</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000109-GPOS-00056</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000108-GPOS-00055</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000108-GPOS-00057</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000108-GPOS-00058</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1386</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Smart card login provides two-factor authentication stronger than
that provided by a username and password combination. Smart cards leverage PKI
(public key infrastructure) in order to provide and verify credentials.
Configuring the smart card driver in use by your organization helps to prevent
users from using unauthorized smart cards.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="configure_opensc_card_drivers" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_smartcard_drivers='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_smartcard_drivers" use="legacy"/>'


OPENSC_TOOL="/usr/bin/opensc-tool"

if [ -f "${OPENSC_TOOL}" ]; then
    ${OPENSC_TOOL} -S app:default:card_drivers:$var_smartcard_drivers
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="configure_opensc_card_drivers" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2(1)
  - NIST-800-53-IA-2(11)
  - NIST-800-53-IA-2(2)
  - NIST-800-53-IA-2(3)
  - NIST-800-53-IA-2(4)
  - NIST-800-53-IA-2(6)
  - NIST-800-53-IA-2(7)
  - PCI-DSS-Req-8.3
  - configure_opensc_card_drivers
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
- name: XCCDF Value var_smartcard_drivers # promote to variable
  set_fact:
    var_smartcard_drivers: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_smartcard_drivers" use="legacy"/>
  tags:
    - always

- name: Check existence of opensc conf
  ansible.builtin.stat:
    path: /etc/opensc-{{ ansible_architecture }}.conf
  register: opensc_conf_cd
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2(1)
  - NIST-800-53-IA-2(11)
  - NIST-800-53-IA-2(2)
  - NIST-800-53-IA-2(3)
  - NIST-800-53-IA-2(4)
  - NIST-800-53-IA-2(6)
  - NIST-800-53-IA-2(7)
  - PCI-DSS-Req-8.3
  - configure_opensc_card_drivers
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure smartcard driver block
  block:

  - name: Check if card_drivers is defined
    ansible.builtin.command: /usr/bin/opensc-tool -G app:default:card_drivers
    changed_when: false
    register: card_drivers

  - name: Configure opensc Smart Card Drivers
    ansible.builtin.command: |
      /usr/bin/opensc-tool -S app:default:card_drivers:{{ var_smartcard_drivers }}
    when:
    - card_drivers.stdout != var_smartcard_drivers
  when:
  - '"kernel" in ansible_facts.packages'
  - opensc_conf_cd.stat.exists
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2(1)
  - NIST-800-53-IA-2(11)
  - NIST-800-53-IA-2(2)
  - NIST-800-53-IA-2(3)
  - NIST-800-53-IA-2(4)
  - NIST-800-53-IA-2(6)
  - NIST-800-53-IA-2(7)
  - PCI-DSS-Req-8.3
  - configure_opensc_card_drivers
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-export export-name="oval:ssg-var_smartcard_drivers:var:1" value-id="xccdf_org.ssgproject.content_value_var_smartcard_drivers"/>
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-configure_opensc_card_drivers:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_opensc_card_drivers_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_force_opensc_card_drivers" selected="false" severity="medium">
                  <xccdf-1.2:title>Force opensc To Use Defined Smart Card Driver</xccdf-1.2:title>
                  <xccdf-1.2:description>The OpenSC smart card middleware can auto-detect smart card drivers; however by
forcing the smart card driver in use by your organization, opensc will no longer
autodetect or use other drivers unless specified. This helps to prevent
users from using unauthorized smart cards. The default smart card driver for this
profile is <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_smartcard_drivers" use="legacy"/></html:code>.
To force the OpenSC driver, edit the <html:code>/etc/opensc.conf</html:code>.
Look for a line similar to:
<html:pre># force_card_driver = customcos;</html:pre>
and change it to:
<html:pre>force_card_driver = <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_smartcard_drivers" use="legacy"/>;</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(1)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(2)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(3)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(4)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(6)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(7)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(11)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000104-GPOS-00051</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000106-GPOS-00053</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000107-GPOS-00054</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000109-GPOS-00056</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000108-GPOS-00055</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000108-GPOS-00057</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000108-GPOS-00058</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1386</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Smart card login provides two-factor authentication stronger than
that provided by a username and password combination. Smart cards leverage PKI
(public key infrastructure) in order to provide and verify credentials.
Forcing the smart card driver in use by your organization helps to prevent
users from using unauthorized smart cards.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="force_opensc_card_drivers" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_smartcard_drivers='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_smartcard_drivers" use="legacy"/>'


OPENSC_TOOL="/usr/bin/opensc-tool"

if [ -f "${OPENSC_TOOL}" ]; then
    ${OPENSC_TOOL} -S app:default:force_card_driver:$var_smartcard_drivers
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="force_opensc_card_drivers" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2(1)
  - NIST-800-53-IA-2(11)
  - NIST-800-53-IA-2(2)
  - NIST-800-53-IA-2(3)
  - NIST-800-53-IA-2(4)
  - NIST-800-53-IA-2(6)
  - NIST-800-53-IA-2(7)
  - PCI-DSS-Req-8.3
  - configure_strategy
  - force_opensc_card_drivers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
- name: XCCDF Value var_smartcard_drivers # promote to variable
  set_fact:
    var_smartcard_drivers: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_smartcard_drivers" use="legacy"/>
  tags:
    - always

- name: Check existence of opensc conf
  ansible.builtin.stat:
    path: /etc/opensc-{{ ansible_architecture }}.conf
  register: opensc_conf_fcd
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2(1)
  - NIST-800-53-IA-2(11)
  - NIST-800-53-IA-2(2)
  - NIST-800-53-IA-2(3)
  - NIST-800-53-IA-2(4)
  - NIST-800-53-IA-2(6)
  - NIST-800-53-IA-2(7)
  - PCI-DSS-Req-8.3
  - configure_strategy
  - force_opensc_card_drivers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Force smartcard driver block
  block:

  - name: Check if force_card_driver is defined
    ansible.builtin.command: /usr/bin/opensc-tool -G app:default:force_card_driver
    changed_when: false
    register: force_card_driver

  - name: Force opensc To Use Defined Smart Card Driver
    ansible.builtin.command: |
      /usr/bin/opensc-tool -S app:default:force_card_driver:{{ var_smartcard_drivers }}
    when:
    - force_card_driver.stdout != var_smartcard_drivers
  when:
  - '"kernel" in ansible_facts.packages'
  - opensc_conf_fcd.stat.exists
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2(1)
  - NIST-800-53-IA-2(11)
  - NIST-800-53-IA-2(2)
  - NIST-800-53-IA-2(3)
  - NIST-800-53-IA-2(4)
  - NIST-800-53-IA-2(6)
  - NIST-800-53-IA-2(7)
  - PCI-DSS-Req-8.3
  - configure_strategy
  - force_opensc_card_drivers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-export export-name="oval:ssg-var_smartcard_drivers:var:1" value-id="xccdf_org.ssgproject.content_value_var_smartcard_drivers"/>
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-force_opensc_card_drivers:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-force_opensc_card_drivers_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
              </xccdf-1.2:Group>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_accounts-restrictions">
            <xccdf-1.2:title>Protect Accounts by Restricting Password-Based Login</xccdf-1.2:title>
            <xccdf-1.2:description>Conventionally, Unix shell accounts are accessed by
providing a username and password to a login program, which tests
these values for correctness using the <html:code>/etc/passwd</html:code> and
<html:code>/etc/shadow</html:code> files. Password-based login is vulnerable to
guessing of weak passwords, and to sniffing and man-in-the-middle
attacks against passwords entered over a network or at an insecure
console. Therefore, mechanisms for accessing accounts by entering
usernames and passwords should be restricted to those which are
operationally necessary.</xccdf-1.2:description>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_accounts_authorized_local_users_regex" interactive="true" operator="pattern match" type="string">
              <xccdf-1.2:title>Accounts Authorized Local Users on the Operating System</xccdf-1.2:title>
              <xccdf-1.2:description>List the user accounts that are authorized locally on the operating system. This list
includes both users required by the operating system and by the installed applications.
Depending on the Operating System distribution, version, software groups and applications,
the user list is different and can be customized with scap-workbench.
OVAL regular expression is used for the user list.
The list starts with '^' and ends with '$' so that it matches exactly the
username, not any string that includes the username. Users are separated with '|'.
For example, three users: bin, oracle and sapadm are allowed, then the list is
<html:code>^(bin|oracle|sapadm)$</html:code>. The user <html:code>root</html:code> is the only user that is hard coded
in OVAL that is always allowed on the operating system.</xccdf-1.2:description>
              <xccdf-1.2:value selector="ol7">^(abrt|adm|avahi|bin|chrony|clevis|cockpit-ws|cockpit-wsinstance|colord|daemon|dbus|dnsmasq|flatpak|ftp|games|gdm|geoclue|gluster|gnome-initial-setup|halt|libstoragemgmt|lp|mail|nfsnobody|nobody|ntp|operator|oprofile|oracle|pcp|pegasus|pipewire|polkitd|postfix|pulse|qemu|radvd|rngd|root|rpc|rpcuser|rtkit|saned|saslauth|setroubleshoot|shutdown|sshd|sssd|sync|systemd-bus-proxy|systemd-coredump|systemd-network|systemd-resolve|tcpdump|tss|unbound|usbmuxd$|uuidd)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="ol8">^(abrt|adm|avahi|bin|chrony|clevis|cockpit-ws|cockpit-wsinstance|colord|daemon|dbus|dnsmasq|flatpak|ftp|games|gdm|geoclue|gluster|gnome-initial-setup|halt|libstoragemgmt|lp|mail|nfsnobody|nobody|ntp|operator|oprofile|oracle|pcp|pegasus|pipewire|polkitd|postfix|pulse|qemu|radvd|rngd|root|rpc|rpcuser|rtkit|saned|saslauth|setroubleshoot|shutdown|sshd|sssd|sync|systemd-bus-proxy|systemd-coredump|systemd-network|systemd-resolve|tcpdump|tss|unbound|usbmuxd$|uuidd)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="ol9">^(abrt|adm|avahi|bin|chrony|clevis|cockpit-ws|cockpit-wsinstance|colord|daemon|dbus|dnsmasq|fapolicyd|flatpak|ftp|games|gdm|geoclue|gluster|gnome-initial-setup|halt|libstoragemgmt|lp|mail|nfsnobody|nobody|ntp|operator|oprofile|oracle|pcp|pegasus|pipewire|polkitd|postfix|pulse|qemu|radvd|rngd|root|rpc|rpcuser|rtkit|saned|saslauth|setroubleshoot|shutdown|sshd|sssd|sync|systemd-bus-proxy|systemd-coredump|systemd-network|systemd-oom|systemd-resolve|tcpdump|tss|unbound|usbmuxd$|uuidd)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="ol7forsap">^(root|bin|daemon|adm|lp|sync|shutdown|halt|mail|operator|games|ftp|nobody|pegasus|systemd-bus-proxy|systemd-network|dbus|polkitd|abrt|unbound|tss|libstoragemgmt|rpc|colord|usbmuxd$|pcp|saslauth|geoclue|setroubleshoot|rtkit|chrony|qemu|radvd|rpcuser|nfsnobody|pulse|gdm|gnome-initial-setup|postfix|avahi|ntp|sshd|tcpdump|oprofile|uuidd)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="rhel8">^(root|bin|daemon|adm|lp|sync|shutdown|halt|mail|operator|games|ftp|nobody|pegasus|systemd-bus-proxy|systemd-network|dbus|polkitd|abrt|unbound|tss|libstoragemgmt|rpc|colord|usbmuxd$|pcp|saslauth|geoclue|setroubleshoot|rtkit|chrony|qemu|radvd|rpcuser|nfsnobody|pulse|gdm|gnome-initial-setup|postfix|avahi|ntp|sshd|tcpdump|oprofile|uuidd|systemd-resolve|systemd-coredump|sssd|rngd)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="rhel9">^(root|bin|daemon|adm|lp|sync|shutdown|halt|mail|operator|games|ftp|nobody|tss|systemd-coredump|dbus|polkitd|avahi|colord|rtkit|pipewire|clevis|sssd|geoclue|flatpak|setroubleshoot|libstoragemgmt|systemd-oom|gdm|cockpit-ws|cockpit-wsinstance|gnome-initial-setup|sshd|chrony|dnsmasq|tcpdump|admin)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="sle12">^(root|bin|daemon|adm|lp|sync|shutdown|halt|mail|operator|games|ftp|nobody|pegasus|systemd-bus-proxy|systemd-network|dbus|polkitd|abrt|unbound|tss|libstoragemgmt|rpc|colord|usbmuxd$|pcp|saslauth|geoclue|setroubleshoot|rtkit|chrony|qemu|radvd|rpcuser|nfsnobody|pulse|gdm|gnome-initial-setup|postfix|avahi|ntp|sshd|tcpdump|oprofile|uuidd|systemd-resolve|systemd-coredump|sssd|rngd|man|systemd-timesync|scard|hacluster|statd|at|dockremap|vnc)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="sle15">^(root|bin|daemon|adm|lp|sync|shutdown|halt|mail|operator|games|ftp|nobody|pegasus|systemd-bus-proxy|systemd-network|dbus|polkitd|abrt|unbound|tss|libstoragemgmt|rpc|colord|usbmuxd$|pcp|saslauth|geoclue|setroubleshoot|rtkit|chrony|qemu|radvd|rpcuser|nfsnobody|pulse|gdm|gnome-initial-setup|postfix|avahi|ntp|sshd|tcpdump|oprofile|uuidd|systemd-resolve|systemd-coredump|sssd|rngd|man|systemd-timesync|scard|hacluster|statd|at|dockremap|vnc|messagebus|nscd|flatpak|srvGeoClue|tftp|wsdd|dnsmasq|usbmux|brltty)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="slmicro5">^(root|bin|daemon|adm|lp|sync|shutdown|halt|mail|operator|games|ftp|nobody|pegasus|systemd-bus-proxy|systemd-network|dbus|polkitd|abrt|unbound|tss|libstoragemgmt|rpc|colord|usbmuxd$|pcp|saslauth|geoclue|setroubleshoot|rtkit|chrony|qemu|radvd|rpcuser|nfsnobody|pulse|gdm|gnome-initial-setup|postfix|avahi|ntp|sshd|tcpdump|oprofile|uuidd|systemd-resolve|systemd-coredump|sssd|rngd|man|systemd-timesync|scard|hacluster|statd|at|dockremap|vnc|messagebus|nscd|flatpak|srvGeoClue|tftp|wsdd|dnsmasq|usbmux|brltty|salt|cockpit-ws|cockpit-wsinstance)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="slmicro6">^(root|bin|daemon|adm|lp|sync|shutdown|halt|mail|operator|games|ftp|nobody|pegasus|systemd-bus-proxy|systemd-network|dbus|polkitd|abrt|unbound|tss|libstoragemgmt|rpc|colord|usbmuxd$|pcp|saslauth|geoclue|setroubleshoot|rtkit|chrony|qemu|radvd|rpcuser|nfsnobody|pulse|gdm|gnome-initial-setup|postfix|avahi|ntp|sshd|tcpdump|oprofile|uuidd|systemd-resolve|systemd-coredump|sssd|rngd|man|systemd-timesync|scard|hacluster|statd|at|dockremap|vnc|messagebus|nscd|flatpak|srvGeoClue|tftp|wsdd|dnsmasq|usbmux|brltty|salt|cockpit-ws|cockpit-wsinstance)$</xccdf-1.2:value>
              <xccdf-1.2:value>^(root|bin|daemon|adm|lp|sync|shutdown|halt|mail|operator|games|ftp|nobody|tss|systemd-coredump|dbus|polkitd|avahi|colord|rtkit|pipewire|clevis|sssd|geoclue|flatpak|setroubleshoot|libstoragemgmt|systemd-oom|gdm|cockpit-ws|cockpit-wsinstance|gnome-initial-setup|sshd|chrony|dnsmasq|tcpdump|admin)$</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_account_unique_id" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure All Accounts on the System Have Unique User IDs</xccdf-1.2:title>
              <xccdf-1.2:description>Change user IDs (UIDs), or delete accounts, so each has a unique name.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Automatic remediation of this control is not available due to unique requirements of each
system.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000104-GPOS-00051</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000121-GPOS-00062</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020240</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230371r1017183_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>To assure accountability and prevent unauthenticated access, interactive users must be identified and authenticated to prevent potential misuse and compromise of the system.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-account_unique_id:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-account_unique_id_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_authorized_local_users" selected="false" severity="medium">
              <xccdf-1.2:title>Only Authorized Local User Accounts Exist on Operating System</xccdf-1.2:title>
              <xccdf-1.2:description>Enterprise Application tends to use the server or virtual machine exclusively.
Besides the default operating system user, there should be only authorized local
users required by the installed software groups and applications that exist on
the operating system. The authorized user list can be customized in the refine
value variable <html:code>var_accounts_authorized_local_users_regex</html:code>.
OVAL regular expression is used for the user list.
Configure the system so all accounts on the system are assigned to an active system,
application, or user account. Remove accounts that do not support approved system
activities or that allow for a normal user to perform administrative-level actions.
To remove unauthorized system accounts, use the following command:
<html:pre>$ sudo userdel <html:i>unauthorized_user</html:i></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020320</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230379r1017190_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Accounts providing no operational purpose provide additional opportunities for
system compromise. Unnecessary accounts include user accounts for individuals not
requiring access to the system and application accounts for applications not installed
on the system.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_authorized_local_users_regex:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_authorized_local_users_regex"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_authorized_local_users:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_authorized_local_users_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_group_unique_id" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure All Groups on the System Have Unique Group ID</xccdf-1.2:title>
              <xccdf-1.2:description>Change the group name or delete groups, so each has a unique id.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Automatic remediation of this control is not available due to the unique requirements of each system.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000104-GPOS-00051</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.2.5</xccdf-1.2:reference>
              <xccdf-1.2:rationale>To assure accountability and prevent unauthenticated access, groups must be identified uniquely to prevent potential misuse and compromise of the system.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-group_unique_id:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-group_unique_id_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_group_unique_name" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure All Groups on the System Have Unique Group Names</xccdf-1.2:title>
              <xccdf-1.2:description>Change the group name or delete groups, so each has a unique name.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Automatic remediation of this control is not available due to the unique requirements of each system.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.2.7</xccdf-1.2:reference>
              <xccdf-1.2:rationale>To assure accountability and prevent unauthenticated access, groups must be identified uniquely to prevent potential misuse and compromise of the system.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-group_unique_name:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-group_unique_name_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_nologin_in_shells" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure nologin Shell is Not Listed in /etc/shells</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>/sbin/nologin</html:code> shell is used to restrict accounts from having login access
and should not be listed as a valid login shell in <html:code>/etc/shells</html:code>.
To verify that nologin is not listed in /etc/shells, run:
<html:pre>$ grep nologin /etc/shells</html:pre>
The command should return no output.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.3.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>/etc/shells</html:code> is consulted by various programs to evaluate
whether the user is somehow restricted. For example, the chsh utility will
consult the file to determine if the user is allowed to change their shell. </xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="no_nologin_in_shells" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
if grep -q -E "^[^#]*/nologin\b.*$" /etc/shells; then
  sed -i --follow-symlinks 's/^[^#]*\/nologin\b.*$/#&amp;/g' /etc/shells
fi
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_nologin_in_shells:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_nologin_in_shells_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_account_expiration">
              <xccdf-1.2:title>Set Account Expiration Parameters</xccdf-1.2:title>
              <xccdf-1.2:description>Accounts can be configured to be automatically disabled
after a certain time period,
meaning that they will require administrator interaction to become usable again.
Expiration of accounts after inactivity can be set for all accounts by default
and also on a per-account basis, such as for accounts that are known to be temporary.
To configure automatic expiration of an account following
the expiration of its password (that is, after the password has expired and not been changed),
run the following command, substituting <html:code><html:i>NUM_DAYS</html:i></html:code> and <html:code><html:i>USER</html:i></html:code> appropriately:
<html:pre>$ sudo chage -I <html:i>NUM_DAYS USER</html:i></html:pre>
Accounts, such as temporary accounts, can also be configured to expire on an explicitly-set date with the
<html:code>-E</html:code> option.
The file <html:code>/etc/default/useradd</html:code> controls
default settings for all newly-created accounts created with the system's
normal command line utilities.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This will only apply to newly created accounts</xccdf-1.2:warning>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration" type="number">
                <xccdf-1.2:title>number of days after a password expires until the account is permanently disabled</xccdf-1.2:title>
                <xccdf-1.2:description>The number of days to wait after a password expires, until the account will be permanently disabled.</xccdf-1.2:description>
                <xccdf-1.2:value selector="0">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="180">180</xccdf-1.2:value>
                <xccdf-1.2:value selector="30">30</xccdf-1.2:value>
                <xccdf-1.2:value selector="35">35</xccdf-1.2:value>
                <xccdf-1.2:value selector="40">40</xccdf-1.2:value>
                <xccdf-1.2:value selector="45">45</xccdf-1.2:value>
                <xccdf-1.2:value selector="60">60</xccdf-1.2:value>
                <xccdf-1.2:value selector="90">90</xccdf-1.2:value>
                <xccdf-1.2:value>35</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_account_disable_post_pw_expiration" selected="false" severity="medium">
                <xccdf-1.2:title>Set Account Expiration Following Inactivity</xccdf-1.2:title>
                <xccdf-1.2:description>To specify the number of days after a password expires (which
signifies inactivity) until an account is permanently disabled, add or correct
the following line in <html:code>/etc/default/useradd</html:code>:
<html:pre>INACTIVE=<html:i><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration" use="legacy"/></html:i></html:pre>
If a password is currently on the verge of expiration, then
<html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration" use="legacy"/></html:code>
day(s) remain(s) until the account is automatically
disabled. However, if the password will not expire for another 60 days, then 60
days plus <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration" use="legacy"/></html:code> day(s) could
elapse until the account would be automatically disabled. See the
<html:code>useradd</html:code> man page for more information.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.6.2.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-4(e)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000118-GPOS-00060</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020260</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230373r1017185_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Inactive identifiers pose a risk to systems and applications because attackers may exploit an inactive identifier and potentially obtain undetected access to the system.
Disabling inactive accounts ensures that accounts which may not have been responsibly removed are not available to attackers who may have compromised their credentials.
Owners of inactive accounts will not notice if unauthorized access to their user account has been obtained.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_shadow-utils"/>
                <xccdf-1.2:fix id="account_disable_post_pw_expiration" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q shadow-utils; }; then

var_account_disable_post_pw_expiration='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration" use="legacy"/>'


# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^INACTIVE")

# shellcheck disable=SC2059
printf -v formatted_output "%s=%s" "$stripped_key" "$var_account_disable_post_pw_expiration"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^INACTIVE\\&gt;" "/etc/default/useradd"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^INACTIVE\\&gt;.*/$escaped_formatted_output/gi" "/etc/default/useradd"
else
    if [[ -s "/etc/default/useradd" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/default/useradd" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/default/useradd"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/default/useradd"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="account_disable_post_pw_expiration" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.6.2.1.1
  - DISA-STIG-RHEL-08-020260
  - NIST-800-171-3.5.6
  - NIST-800-53-AC-2(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-4(e)
  - PCI-DSS-Req-8.1.4
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.6
  - account_disable_post_pw_expiration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_account_disable_post_pw_expiration # promote to variable
  set_fact:
    var_account_disable_post_pw_expiration: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration" use="legacy"/>
  tags:
    - always

- name: Set Account Expiration Following Inactivity
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/default/useradd
    regexp: ^INACTIVE
    line: INACTIVE={{ var_account_disable_post_pw_expiration }}
  when:
  - '"kernel" in ansible_facts.packages'
  - '"shadow-utils" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.1.1
  - DISA-STIG-RHEL-08-020260
  - NIST-800-171-3.5.6
  - NIST-800-53-AC-2(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-4(e)
  - PCI-DSS-Req-8.1.4
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.6
  - account_disable_post_pw_expiration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_account_disable_post_pw_expiration:var:1" value-id="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-account_disable_post_pw_expiration:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-account_disable_post_pw_expiration_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_account_emergency_expire_date" selected="false" severity="medium">
                <xccdf-1.2:title>Assign Expiration Date to Emergency Accounts</xccdf-1.2:title>
                <xccdf-1.2:description>Emergency accounts are privileged accounts established in response to
crisis situations where the need for rapid account activation is required.
In the event emergency accounts are required, configure the system to
terminate them after a documented time period. For every emergency account,
run the following command to set an expiration date on it, substituting
<html:code><html:i>ACCOUNT_NAME</html:i></html:code> and <html:code><html:i>YYYY-MM-DD</html:i></html:code>
appropriately:
<html:pre>$ sudo chage -E <html:i>YYYY-MM-DD ACCOUNT_NAME</html:i></html:pre>
<html:code><html:i>YYYY-MM-DD</html:i></html:code> indicates the documented expiration date for the
account. For U.S. Government systems, the operating system must be
configured to automatically terminate these types of accounts after a
period of 72 hours.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">Due to the unique requirements of each system, automated
remediation is not available for this configuration check.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="general">This rule is deprecated in favor of the <html:code>account_temp_expire_date</html:code> rule.Please consider replacing this rule in your files as it is not expected to receive
updates as of version <html:code>0.1.69</html:code>.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000123-GPOS-00064</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000002-GPOS-00002</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If emergency user accounts remain active when no longer needed or for
an excessive period, these accounts may be used to gain unauthorized access.
To mitigate this risk, automated termination of all emergency accounts
must be set upon account creation.
<html:br/></xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-account_emergency_expire_date_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_account_temp_expire_date" selected="false" severity="medium">
                <xccdf-1.2:title>Assign Expiration Date to Temporary Accounts</xccdf-1.2:title>
                <xccdf-1.2:description>Temporary accounts are established as part of normal account activation
procedures when there is a need for short-term accounts. In the event
temporary accounts are required, configure the system to
terminate them after a documented time period. For every temporary account, run the following command to set an expiration date on
it, substituting <html:code><html:i>USER</html:i></html:code> and <html:code><html:i>YYYY-MM-DD</html:i></html:code>
appropriately:
<html:pre>$ sudo chage -E <html:i>YYYY-MM-DD USER</html:i></html:pre>
<html:code><html:i>YYYY-MM-DD</html:i></html:code> indicates the documented expiration date for the
account. For U.S. Government systems, the operating system must be
configured to automatically terminate these types of accounts after a
period of 72 hours.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000123-GPOS-00064</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000002-GPOS-00002</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020000</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020270</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230374r1069293_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If temporary user accounts remain active when no longer needed or for
an excessive period, these accounts may be used to gain unauthorized access.
To mitigate this risk, automated termination of all temporary accounts
must be set upon account creation.
<html:br/></xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-account_temp_expire_date_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_account_unique_name" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure All Accounts on the System Have Unique Names</xccdf-1.2:title>
                <xccdf-1.2:description>Ensure accounts on the system have unique names.

To ensure all accounts have unique names, run the following command:
<html:pre>$ sudo getent passwd | awk -F: '{ print $1}' | uniq -d</html:pre>
If a username is returned, change or delete the username.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.2.6</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Unique usernames allow for accountability on the system.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-account_unique_name:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-account_unique_name_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_account_use_centralized_automated_auth" selected="false" severity="medium">
                <xccdf-1.2:title>Use Centralized and Automated Authentication</xccdf-1.2:title>
                <xccdf-1.2:description>Implement an automated system for managing user accounts that minimizes the
risk of errors, either intentional or deliberate. This system
should integrate with an existing enterprise user management system, such as
one based on Identity Management tools such as Active Directory, Kerberos,
Directory Server, etc.</xccdf-1.2:description>
                <xccdf-1.2:rationale>A comprehensive account management process that includes automation helps to
ensure the accounts designated as requiring attention are consistently and
promptly addressed. Enterprise environments make user account management
challenging and complex. A user management process requiring administrators to
manually address account management functions adds risk of potential
oversight.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-account_use_centralized_automated_auth_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_password_expiration">
              <xccdf-1.2:title>Set Password Expiration Parameters</xccdf-1.2:title>
              <xccdf-1.2:description>The file <html:code>/etc/login.defs</html:code> controls several
password-related settings. Programs such as <html:code>passwd</html:code>,
<html:code>su</html:code>, and
<html:code>login</html:code> consult <html:code>/etc/login.defs</html:code> to determine
behavior with regard to password aging, expiration warnings,
and length. See the man page <html:code>login.defs(5)</html:code> for more information.
<html:br/><html:br/>
Users should be forced to change their passwords, in order to
decrease the utility of compromised passwords. However, the need to
change passwords often should be balanced against the risk that
users will reuse or write down passwords if forced to change them
too often. Forcing password changes every 90-360 days, depending on
the environment, is recommended. Set the appropriate value as
<html:code>PASS_MAX_DAYS</html:code> and apply it to existing accounts with the
<html:code>-M</html:code> flag.
<html:br/><html:br/>
The <html:code>PASS_MIN_DAYS</html:code> (<html:code>-m</html:code>) setting prevents password
changes for 7 days after the first change, to discourage password
cycling. If you use this setting, train users to contact an administrator
for an emergency password change in case a new password becomes
compromised. The <html:code>PASS_WARN_AGE</html:code> (<html:code>-W</html:code>) setting gives
users 7 days of warnings at login time that their passwords are about to expire.
<html:br/><html:br/>
For example, for each existing human user <html:i>USER</html:i>, expiration parameters
could be adjusted to a 180 day maximum password age, 7 day minimum password
age, and 7 day warning period with the following command:
<html:pre>$ sudo chage -M 180 -m 7 -W 7 USER</html:pre></xccdf-1.2:description>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" type="number">
                <xccdf-1.2:title>maximum password age</xccdf-1.2:title>
                <xccdf-1.2:description>Maximum age of password in days</xccdf-1.2:description>
                <xccdf-1.2:value selector="365">365</xccdf-1.2:value>
                <xccdf-1.2:value selector="120">120</xccdf-1.2:value>
                <xccdf-1.2:value selector="180">180</xccdf-1.2:value>
                <xccdf-1.2:value selector="90">90</xccdf-1.2:value>
                <xccdf-1.2:value selector="60">60</xccdf-1.2:value>
                <xccdf-1.2:value selector="45">45</xccdf-1.2:value>
                <xccdf-1.2:value>60</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_root" type="number">
                <xccdf-1.2:title>Maximum Root Password Age</xccdf-1.2:title>
                <xccdf-1.2:description>Maximum age of password in days for the root account</xccdf-1.2:description>
                <xccdf-1.2:value selector="365">365</xccdf-1.2:value>
                <xccdf-1.2:value>99999</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_accounts_minimum_age_login_defs" type="number">
                <xccdf-1.2:title>minimum password age</xccdf-1.2:title>
                <xccdf-1.2:description>Minimum age of password in days</xccdf-1.2:description>
                <xccdf-1.2:value selector="0">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
                <xccdf-1.2:value selector="2">2</xccdf-1.2:value>
                <xccdf-1.2:value selector="3">3</xccdf-1.2:value>
                <xccdf-1.2:value selector="4">4</xccdf-1.2:value>
                <xccdf-1.2:value selector="5">5</xccdf-1.2:value>
                <xccdf-1.2:value selector="6">6</xccdf-1.2:value>
                <xccdf-1.2:value selector="7">7</xccdf-1.2:value>
                <xccdf-1.2:value>7</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_accounts_password_minlen_login_defs" type="number">
                <xccdf-1.2:title>minimum password length</xccdf-1.2:title>
                <xccdf-1.2:description>Minimum number of characters in password</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">This will only check new passwords</xccdf-1.2:warning>
                <xccdf-1.2:value selector="10">10</xccdf-1.2:value>
                <xccdf-1.2:value selector="12">12</xccdf-1.2:value>
                <xccdf-1.2:value selector="14">14</xccdf-1.2:value>
                <xccdf-1.2:value selector="15">15</xccdf-1.2:value>
                <xccdf-1.2:value selector="17">17</xccdf-1.2:value>
                <xccdf-1.2:value selector="18">18</xccdf-1.2:value>
                <xccdf-1.2:value selector="20">20</xccdf-1.2:value>
                <xccdf-1.2:value selector="6">6</xccdf-1.2:value>
                <xccdf-1.2:value selector="8">8</xccdf-1.2:value>
                <xccdf-1.2:value>15</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_accounts_password_warn_age_login_defs" type="number">
                <xccdf-1.2:title>warning days before password expires</xccdf-1.2:title>
                <xccdf-1.2:description>The number of days' warning given before a password expires.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">This will only apply to newly created accounts</xccdf-1.2:warning>
                <xccdf-1.2:value selector="0">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="14">14</xccdf-1.2:value>
                <xccdf-1.2:value selector="10">10</xccdf-1.2:value>
                <xccdf-1.2:value selector="7">7</xccdf-1.2:value>
                <xccdf-1.2:value>7</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_maximum_age_login_defs" selected="false" severity="medium">
                <xccdf-1.2:title>Set Password Maximum Age</xccdf-1.2:title>
                <xccdf-1.2:description>To specify password maximum age for new accounts,
edit the file <html:code>/etc/login.defs</html:code>
and add or correct the following line:
<html:pre>PASS_MAX_DAYS <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" use="legacy"/></html:pre>
The profile requirement is <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" use="legacy"/></html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.6.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(f)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(d)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000076-GPOS-00044</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0418</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1055</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1402</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020200</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230366r1038967_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Any password, no matter how complex, can eventually be cracked. Therefore, passwords
need to be changed periodically. If the operating system does not limit the lifetime
of passwords and force users to change their passwords, there is the risk that the
operating system passwords could be compromised.
<html:br/><html:br/>
Setting the password maximum age ensures users are required to
periodically change their passwords. Requiring shorter password lifetimes
increases the risk of users writing down the password in a convenient
location subject to physical compromise.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_shadow-utils"/>
                <xccdf-1.2:fix id="accounts_maximum_age_login_defs" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q shadow-utils; }; then

var_accounts_maximum_age_login_defs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" use="legacy"/>'

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^PASS_MAX_DAYS")

# shellcheck disable=SC2059
printf -v formatted_output "%s %s" "$stripped_key" "$var_accounts_maximum_age_login_defs"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^PASS_MAX_DAYS\\&gt;" "/etc/login.defs"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^PASS_MAX_DAYS\\&gt;.*/$escaped_formatted_output/gi" "/etc/login.defs"
else
    if [[ -s "/etc/login.defs" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/login.defs" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/login.defs"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/login.defs"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_maximum_age_login_defs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.6.2.1
  - DISA-STIG-RHEL-08-020200
  - NIST-800-171-3.5.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(d)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.4
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.9
  - accounts_maximum_age_login_defs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_accounts_maximum_age_login_defs # promote to variable
  set_fact:
    var_accounts_maximum_age_login_defs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" use="legacy"/>
  tags:
    - always

- name: Set Password Maximum Age
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/login.defs
    regexp: ^#?PASS_MAX_DAYS
    line: PASS_MAX_DAYS {{ var_accounts_maximum_age_login_defs }}
  when:
  - '"kernel" in ansible_facts.packages'
  - '"shadow-utils" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.1
  - DISA-STIG-RHEL-08-020200
  - NIST-800-171-3.5.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(d)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.4
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.9
  - accounts_maximum_age_login_defs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_maximum_age_login_defs:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_maximum_age_login_defs:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_maximum_age_login_defs_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_minimum_age_login_defs" selected="false" severity="medium">
                <xccdf-1.2:title>Set Password Minimum Age</xccdf-1.2:title>
                <xccdf-1.2:description>To specify password minimum age for new accounts,
edit the file <html:code>/etc/login.defs</html:code>
and add or correct the following line:
<html:pre>PASS_MIN_DAYS <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_minimum_age_login_defs" use="legacy"/></html:pre>
A value of 1 day is considered sufficient for many
environments.
The profile requirement is <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_minimum_age_login_defs" use="legacy"/></html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.6.2.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(f)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(d)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000075-GPOS-00043</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0418</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1055</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1402</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020190</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230365r1017177_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Enforcing a minimum password lifetime helps to prevent repeated password
changes to defeat the password reuse or history enforcement requirement. If
users are allowed to immediately and continually change their password,
then the password could be repeatedly changed in a short period of time to
defeat the organization's policy regarding password reuse.
<html:br/><html:br/>
Setting the minimum password age protects against users cycling back to a
favorite password after satisfying the password reuse requirement.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_shadow-utils"/>
                <xccdf-1.2:fix id="accounts_minimum_age_login_defs" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q shadow-utils; }; then

var_accounts_minimum_age_login_defs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_minimum_age_login_defs" use="legacy"/>'

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^PASS_MIN_DAYS")

# shellcheck disable=SC2059
printf -v formatted_output "%s %s" "$stripped_key" "$var_accounts_minimum_age_login_defs"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^PASS_MIN_DAYS\\&gt;" "/etc/login.defs"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^PASS_MIN_DAYS\\&gt;.*/$escaped_formatted_output/gi" "/etc/login.defs"
else
    if [[ -s "/etc/login.defs" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/login.defs" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/login.defs"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/login.defs"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_minimum_age_login_defs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.6.2.1.1
  - DISA-STIG-RHEL-08-020190
  - NIST-800-171-3.5.8
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(d)
  - NIST-800-53-IA-5(f)
  - accounts_minimum_age_login_defs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_accounts_minimum_age_login_defs # promote to variable
  set_fact:
    var_accounts_minimum_age_login_defs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_minimum_age_login_defs" use="legacy"/>
  tags:
    - always

- name: Set Password Minimum Age
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/login.defs
    regexp: ^#?PASS_MIN_DAYS
    line: PASS_MIN_DAYS {{ var_accounts_minimum_age_login_defs }}
  when:
  - '"kernel" in ansible_facts.packages'
  - '"shadow-utils" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.1.1
  - DISA-STIG-RHEL-08-020190
  - NIST-800-171-3.5.8
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(d)
  - NIST-800-53-IA-5(f)
  - accounts_minimum_age_login_defs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_minimum_age_login_defs:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_minimum_age_login_defs"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_minimum_age_login_defs:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_minlen_login_defs" selected="false" severity="medium">
                <xccdf-1.2:title>Set Password Minimum Length in login.defs</xccdf-1.2:title>
                <xccdf-1.2:description>To specify password length requirements for new accounts, edit the file
<html:code>/etc/login.defs</html:code> and add or correct the following line:
<html:pre>PASS_MIN_LEN <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_password_minlen_login_defs" use="legacy"/></html:pre>
<html:br/><html:br/>
The profile requirement is
<html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_password_minlen_login_defs" use="legacy"/></html:code>.
If a program consults <html:code>/etc/login.defs</html:code> and also another PAM module
(such as <html:code>pam_pwquality</html:code>) during a password change operation, then
the most restrictive must be satisfied. See PAM section for more
information about enforcing password quality requirements.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.6.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(f)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000078-GPOS-00046</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R31</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020231</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230370r1017182_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Requiring a minimum password length makes password
cracking attacks more difficult by ensuring a larger
search space. However, any security benefit from an onerous requirement
must be carefully weighed against usability problems, support costs, or counterproductive
behavior that may result.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_shadow-utils"/>
                <xccdf-1.2:fix id="accounts_password_minlen_login_defs" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q shadow-utils; }; then

var_accounts_password_minlen_login_defs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_password_minlen_login_defs" use="legacy"/>'

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^PASS_MIN_LEN")

# shellcheck disable=SC2059
printf -v formatted_output "%s %s" "$stripped_key" "$var_accounts_password_minlen_login_defs"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^PASS_MIN_LEN\\&gt;" "/etc/login.defs"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^PASS_MIN_LEN\\&gt;.*/$escaped_formatted_output/gi" "/etc/login.defs"
else
    if [[ -s "/etc/login.defs" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/login.defs" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/login.defs"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/login.defs"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_minlen_login_defs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.6.2.1
  - DISA-STIG-RHEL-08-020231
  - NIST-800-171-3.5.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(f)
  - accounts_password_minlen_login_defs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_accounts_password_minlen_login_defs # promote to variable
  set_fact:
    var_accounts_password_minlen_login_defs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_password_minlen_login_defs" use="legacy"/>
  tags:
    - always

- name: Set Password Minimum Length in login.defs
  ansible.builtin.lineinfile:
    dest: /etc/login.defs
    regexp: ^PASS_MIN_LEN *[0-9]*
    state: present
    line: PASS_MIN_LEN        {{ var_accounts_password_minlen_login_defs }}
    create: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"shadow-utils" in ansible_facts.packages'
  tags:
  - CJIS-5.6.2.1
  - DISA-STIG-RHEL-08-020231
  - NIST-800-171-3.5.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(f)
  - accounts_password_minlen_login_defs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_password_minlen_login_defs:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_password_minlen_login_defs"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_minlen_login_defs:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_minlen_login_defs_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_set_max_life_existing" selected="false" severity="medium">
                <xccdf-1.2:title>Set Existing Passwords Maximum Age</xccdf-1.2:title>
                <xccdf-1.2:description>Configure non-compliant accounts to enforce a <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" use="legacy"/>-day maximum password lifetime
restriction by running the following command:

<html:pre>$ sudo chage -M <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" use="legacy"/> <html:i>USER</html:i></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(f)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(d)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000076-GPOS-00044</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020210</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230367r1038967_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Any password, no matter how complex, can eventually be cracked. Therefore,
passwords need to be changed periodically. If the operating system does
not limit the lifetime of passwords and force users to change their
passwords, there is the risk that the operating system passwords could be
compromised.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_set_max_life_existing" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_accounts_maximum_age_login_defs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" use="legacy"/>'


while IFS= read -r i; do
    
    chage -M $var_accounts_maximum_age_login_defs $i

done &lt;   &lt;(awk -v var="$var_accounts_maximum_age_login_defs" -F: '(/^[^:]+:[^!*]/ &amp;&amp; ($5 &gt; var || $5 == "")) {print $1}' /etc/shadow)

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_set_max_life_existing" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020210
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(d)
  - NIST-800-53-IA-5(f)
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.9
  - accounts_password_set_max_life_existing
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_accounts_maximum_age_login_defs # promote to variable
  set_fact:
    var_accounts_maximum_age_login_defs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" use="legacy"/>
  tags:
    - always

- name: Collect users with not correct maximum time period between password changes
  ansible.builtin.command:
    cmd: awk -F':' '(/^[^:]+:[^!*]/ &amp;&amp; ($5 &gt; {{ var_accounts_maximum_age_login_defs
      }} || $5 == "")) {print $1}' /etc/shadow
  register: user_names
  changed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020210
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(d)
  - NIST-800-53-IA-5(f)
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.9
  - accounts_password_set_max_life_existing
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Change the maximum time period between password changes
  ansible.builtin.user:
    user: '{{ item }}'
    password_expire_max: '{{ var_accounts_maximum_age_login_defs }}'
  with_items: '{{ user_names.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - user_names.stdout_lines | length &gt; 0
  tags:
  - DISA-STIG-RHEL-08-020210
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(d)
  - NIST-800-53-IA-5(f)
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.9
  - accounts_password_set_max_life_existing
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_minimum_age_login_defs:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_minimum_age_login_defs"/>
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_maximum_age_login_defs:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_set_max_life_existing:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_set_max_life_existing_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_set_max_life_root" selected="false" severity="medium">
                <xccdf-1.2:title>Set Root Account Password Maximum Age</xccdf-1.2:title>
                <xccdf-1.2:description>Configure the root account to enforce a <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_root" use="legacy"/>-day maximum password lifetime restriction by running the following command:
<html:pre>$ sudo chage -M <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_root" use="legacy"/> root</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R31</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Any password, no matter how complex, can eventually be cracked. Therefore,
passwords need to be changed periodically. If the operating system does
not limit the lifetime of passwords and force users to change their
passwords, there is the risk that the operating system passwords could be
compromised.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_set_max_life_root" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_accounts_maximum_age_root='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_root" use="legacy"/>'

chage -M $var_accounts_maximum_age_root root

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_set_max_life_root" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - accounts_password_set_max_life_root
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_accounts_maximum_age_root # promote to variable
  set_fact:
    var_accounts_maximum_age_root: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_root" use="legacy"/>
  tags:
    - always

- name: Change the maximum time period between password changes
  ansible.builtin.user:
    user: root
    password_expire_max: '{{ var_accounts_maximum_age_root }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - accounts_password_set_max_life_root
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_maximum_age_root:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_root"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_set_max_life_root:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_set_max_life_root_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_set_min_life_existing" selected="false" severity="medium">
                <xccdf-1.2:title>Set Existing Passwords Minimum Age</xccdf-1.2:title>
                <xccdf-1.2:description>Configure non-compliant accounts to enforce a 24 hours/1 day minimum password
lifetime by running the following command:
<html:pre>$ sudo chage -m 1 <html:i>USER</html:i></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(f)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(d)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000075-GPOS-00043</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020180</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230364r1017176_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Enforcing a minimum password lifetime helps to prevent repeated password
changes to defeat the password reuse or history enforcement requirement. If
users are allowed to immediately and continually change their password, the
password could be repeatedly changed in a short period of time to defeat the
organization's policy regarding password reuse.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_set_min_life_existing" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_accounts_minimum_age_login_defs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_minimum_age_login_defs" use="legacy"/>'


while IFS= read -r i; do
    
    chage -m $var_accounts_minimum_age_login_defs $i

done &lt;   &lt;(awk -v var="$var_accounts_minimum_age_login_defs" -F: '(/^[^:]+:[^!*]/ &amp;&amp; ($4 &lt; var || $4 == "")) {print $1}' /etc/shadow)

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_set_min_life_existing" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020180
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(d)
  - NIST-800-53-IA-5(f)
  - accounts_password_set_min_life_existing
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_accounts_minimum_age_login_defs # promote to variable
  set_fact:
    var_accounts_minimum_age_login_defs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_minimum_age_login_defs" use="legacy"/>
  tags:
    - always

- name: Collect users with not correct minimum time period between password changes
  ansible.builtin.command: |
    awk -F':' '(/^[^:]+:[^!*]/ &amp;&amp; ($4 &lt; {{ var_accounts_minimum_age_login_defs }} || $4 == "")) {print $1}' /etc/shadow
  register: user_names
  changed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020180
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(d)
  - NIST-800-53-IA-5(f)
  - accounts_password_set_min_life_existing
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Change the minimum time period between password changes
  ansible.builtin.command: |
    chage -m {{ var_accounts_minimum_age_login_defs }} {{ item }}
  with_items: '{{ user_names.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - user_names.stdout_lines | length &gt; 0
  tags:
  - DISA-STIG-RHEL-08-020180
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(d)
  - NIST-800-53-IA-5(f)
  - accounts_password_set_min_life_existing
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_minimum_age_login_defs:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_minimum_age_login_defs"/>
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_maximum_age_login_defs:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_set_min_life_existing:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_set_min_life_existing_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_set_warn_age_existing" selected="false" severity="medium">
                <xccdf-1.2:title>Set Existing Passwords Warning Age</xccdf-1.2:title>
                <xccdf-1.2:description>To configure how many days prior to password expiration that a warning will be issued to
users, run the command:
<html:pre>$ sudo chage --warndays <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_password_warn_age_login_defs" use="legacy"/> <html:i>USER</html:i></html:pre>
This profile requirement is <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_password_warn_age_login_defs" use="legacy"/></html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(f)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(d)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.1.3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Providing an advance warning that a password will be expiring gives users
time to think of a secure password. Users caught unaware may choose a simple
password or write it down where it may be discovered.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_set_warn_age_existing" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_accounts_password_warn_age_login_defs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_password_warn_age_login_defs" use="legacy"/>'


while IFS= read -r i; do
    chage --warndays $var_accounts_password_warn_age_login_defs $i
done &lt;   &lt;(awk -v var="$var_accounts_password_warn_age_login_defs" -F: '(($6 &lt; var || $6 == "") &amp;&amp; $2 ~ /^\$/) {print $1}' /etc/shadow)

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_set_warn_age_existing" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(d)
  - NIST-800-53-IA-5(f)
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.9
  - accounts_password_set_warn_age_existing
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
- name: XCCDF Value var_accounts_password_warn_age_login_defs # promote to variable
  set_fact:
    var_accounts_password_warn_age_login_defs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_password_warn_age_login_defs" use="legacy"/>
  tags:
    - always

- name: Set Existing Passwords Warning Age - Collect Users With Incorrect Number of
    Days of Warning Before Password Expires
  ansible.builtin.command:
    cmd: awk -F':' '(($6 &lt; {{ var_accounts_password_warn_age_login_defs }} || $6 ==
      "") &amp;&amp; $2 ~ /^\$/) {print $1}' /etc/shadow
  register: result_pass_warn_age_user_names
  changed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(d)
  - NIST-800-53-IA-5(f)
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.9
  - accounts_password_set_warn_age_existing
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set Existing Passwords Warning Age - Ensure the Number of Days of Warning
    Before Password Expires
  ansible.builtin.command:
    cmd: chage --warndays {{ var_accounts_password_warn_age_login_defs }} {{ item
      }}
  with_items: '{{ result_pass_warn_age_user_names.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - result_pass_warn_age_user_names is not skipped and result_pass_warn_age_user_names.stdout_lines
    | length &gt; 0
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(d)
  - NIST-800-53-IA-5(f)
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.9
  - accounts_password_set_warn_age_existing
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_password_warn_age_login_defs:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_password_warn_age_login_defs"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_set_warn_age_existing:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_set_warn_age_existing_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_warn_age_login_defs" selected="false" severity="medium">
                <xccdf-1.2:title>Set Password Warning Age</xccdf-1.2:title>
                <xccdf-1.2:description>To specify how many days prior to password
expiration that a warning will be issued to users,
edit the file <html:code>/etc/login.defs</html:code> and add or correct
 the following line:
<html:pre>PASS_WARN_AGE <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_password_warn_age_login_defs" use="legacy"/></html:pre>
The profile requirement is <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_password_warn_age_login_defs" use="legacy"/></html:code>.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(f)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(d)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0418</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1055</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1402</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.1.3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Setting the password warning age enables users to
make the change at a practical time.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_shadow-utils"/>
                <xccdf-1.2:fix id="accounts_password_warn_age_login_defs" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q shadow-utils; }; then

var_accounts_password_warn_age_login_defs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_password_warn_age_login_defs" use="legacy"/>'


# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^PASS_WARN_AGE")

# shellcheck disable=SC2059
printf -v formatted_output "%s %s" "$stripped_key" "$var_accounts_password_warn_age_login_defs"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^PASS_WARN_AGE\\&gt;" "/etc/login.defs"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^PASS_WARN_AGE\\&gt;.*/$escaped_formatted_output/gi" "/etc/login.defs"
else
    if [[ -s "/etc/login.defs" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/login.defs" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/login.defs"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/login.defs"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_password_warn_age_login_defs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.5.8
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(d)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.4
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.9
  - accounts_password_warn_age_login_defs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_accounts_password_warn_age_login_defs # promote to variable
  set_fact:
    var_accounts_password_warn_age_login_defs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_password_warn_age_login_defs" use="legacy"/>
  tags:
    - always

- name: Set Password Warning Age
  ansible.builtin.lineinfile:
    dest: /etc/login.defs
    regexp: ^PASS_WARN_AGE *[0-9]*
    state: present
    line: PASS_WARN_AGE        {{ var_accounts_password_warn_age_login_defs }}
    create: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"shadow-utils" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.5.8
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(d)
  - NIST-800-53-IA-5(f)
  - PCI-DSS-Req-8.2.4
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.9
  - accounts_password_warn_age_login_defs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_password_warn_age_login_defs:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_password_warn_age_login_defs"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_warn_age_login_defs:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_warn_age_login_defs_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_set_post_pw_existing" selected="false" severity="medium">
                <xccdf-1.2:title>Set existing passwords a period of inactivity before they been locked</xccdf-1.2:title>
                <xccdf-1.2:description>Configure user accounts that have been inactive for over a given period of time
to be automatically disabled by running the following command:
<html:pre>$ sudo chage --inactive 30 USER</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-4(e)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000118-GPOS-00060</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.1.5</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Inactive accounts pose a threat to system security since the users are not logging in to
notice failed login attempts or other anomalies.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_set_post_pw_existing" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_account_disable_post_pw_expiration='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration" use="legacy"/>'


while IFS= read -r i; do
    chage --inactive $var_account_disable_post_pw_expiration $i
done &lt;   &lt;(awk -v var="$var_account_disable_post_pw_expiration" -F: '(($7 &gt; var || $7 == "") &amp;&amp; $2 ~ /^\$/) {print $1}' /etc/shadow)

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_set_post_pw_existing" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.5.6
  - NIST-800-53-AC-2(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-4(e)
  - PCI-DSS-Req-8.1.4
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.6
  - accounts_set_post_pw_existing
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_account_disable_post_pw_expiration # promote to variable
  set_fact:
    var_account_disable_post_pw_expiration: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration" use="legacy"/>
  tags:
    - always

- name: Collect users with not correct INACTIVE parameter set
  ansible.builtin.command:
    cmd: awk -F':' '(($7 &gt; {{ var_account_disable_post_pw_expiration }} || $7 == "")
      &amp;&amp; $2 ~ /^\$/) {print $1}' /etc/shadow
  register: user_names
  changed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.5.6
  - NIST-800-53-AC-2(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-4(e)
  - PCI-DSS-Req-8.1.4
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.6
  - accounts_set_post_pw_existing
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Change the period of inactivity
  ansible.builtin.command:
    cmd: chage --inactive {{ var_account_disable_post_pw_expiration }} {{ item }}
  with_items: '{{ user_names.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - user_names is not skipped and user_names.stdout_lines | length &gt; 0
  tags:
  - NIST-800-171-3.5.6
  - NIST-800-53-AC-2(3)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-4(e)
  - PCI-DSS-Req-8.1.4
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.6
  - accounts_set_post_pw_existing
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_account_disable_post_pw_expiration:var:1" value-id="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_set_post_pw_existing:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_set_post_pw_existing_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_password_storage">
              <xccdf-1.2:title>Verify Proper Storage and Existence of Password
Hashes</xccdf-1.2:title>
              <xccdf-1.2:description>By default, password hashes for local accounts are stored
in the second field (colon-separated) in
<html:code>/etc/shadow</html:code>. This file should be readable only by
processes running with root credentials, preventing users from
casually accessing others' password hashes and attempting
to crack them.
However, it remains possible to misconfigure the system
and store password hashes
in world-readable files such as <html:code>/etc/passwd</html:code>, or
to even store passwords themselves in plaintext on the system.
Using system-provided tools for password change/creation
should allow administrators to avoid such misconfiguration.</xccdf-1.2:description>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_password_pam_unix_rounds" type="number">
                <xccdf-1.2:title>Password Hashing algorithm</xccdf-1.2:title>
                <xccdf-1.2:description>Specify the number of rounds for the system password encryption algorithm.
Defines the value set in <html:code>/etc/pam.d/system-auth</html:code> and <html:code>/etc/pam.d/password-auth</html:code></xccdf-1.2:description>
                <xccdf-1.2:value>5000</xccdf-1.2:value>
                <xccdf-1.2:value selector="5000">5000</xccdf-1.2:value>
                <xccdf-1.2:value selector="65536">65536</xccdf-1.2:value>
                <xccdf-1.2:value selector="100000">100000</xccdf-1.2:value>
                <xccdf-1.2:value selector="11">11</xccdf-1.2:value>
                <xccdf-1.2:value selector="5">5</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_all_shadowed" selected="false" severity="medium">
                <xccdf-1.2:title>Verify All Account Password Hashes are Shadowed</xccdf-1.2:title>
                <xccdf-1.2:description>If any password hashes are stored in <html:code>/etc/passwd</html:code> (in the second field,
instead of an <html:code>x</html:code> or <html:code>*</html:code>), the cause of this misconfiguration should be
investigated. The account should have its password reset and the hash should be
properly stored, or the account should be deleted entirely.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.5.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(h)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1402</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.2.1</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The hashes for all user account passwords should be stored in
the file <html:code>/etc/shadow</html:code> and never in <html:code>/etc/passwd</html:code>,
which is readable by all users.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_all_shadowed:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_all_shadowed_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_all_shadowed_sha512" selected="false" severity="medium">
                <xccdf-1.2:title>Verify All Account Password Hashes are Shadowed with SHA512</xccdf-1.2:title>
                <xccdf-1.2:description>Verify the operating system requires the shadow password suite
configuration be set to encrypt interactive user passwords using a strong
cryptographic hash.
Check that the interactive user account passwords are using a strong
password hash with the following command:
<html:pre>$ sudo cut -d: -f2 /etc/shadow
$6$kcOnRq/5$NUEYPuyL.wghQwWssXRcLRFiiru7f5JPV6GaJhNC2aK5F3PZpE/BCCtwrxRc/AInKMNX3CdMw11m9STiql12f/</html:pre>
Password hashes <html:code>!</html:code> or <html:code>*</html:code> indicate inactive accounts not
available for logon and are not evaluated.
If any interactive user password hash does not begin with <html:code>$6</html:code>,
this is a finding.</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1).1(v)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000073-GPOS-00041</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000120-GPOS-00061</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010120</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230232r1017051_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Passwords need to be protected at all times, and encryption is the standard method for
protecting passwords. If passwords are not encrypted, they can be plainly read
(i.e., clear text) and easily compromised.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_all_shadowed_sha512:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_all_shadowed_sha512_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_last_change_is_in_past" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure all users last password change date is in the past</xccdf-1.2:title>
                <xccdf-1.2:description>All users should have a password change date in the past.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">Automatic remediation is not available, in order to avoid any system disruption.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.1.6</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If a user recorded password change date is in the future then they could
bypass any set password expiration.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_last_change_is_in_past:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_last_change_is_in_past_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_no_remember" selected="false" severity="medium">
                <xccdf-1.2:title>Avoid using remember in pam_unix module</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>remember</html:code> option stores the last n passwords for each user in <html:code>/etc/security/opasswd</html:code>,
enforcing password history and preventing users from reusing the same passwords. However, this feature
relies on the MD5 password hash algorithm, which is less secure. Instead, the <html:code>pam_pwhistory</html:code>
module should be used. This module also stores the last n passwords in <html:code>/etc/security/opasswd</html:code>
and it uses the password hash algorithm configured in the pam_unix module, such as yescrypt or SHA512,
offering enhanced security.

<html:br/><html:br/>
The <html:code>remember</html:code> option should be removed from the PAM configuration
in <html:code>/etc/pam.d/system-auth</html:code> and <html:code>/etc/pam.d/password-auth</html:code> files.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">If the system relies on <html:code>authselect</html:code> tool to manage PAM settings, the remediation
will also use <html:code>authselect</html:code> tool. However, if any manual modification was made in
PAM files, the <html:code>authselect</html:code> integrity check will fail and the remediation will be
aborted in order to preserve intentional changes. In this case, an informative message will
be shown in the remediation report.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.4.2</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Removing the <html:code>remember</html:code> argument ensures the use of a stronger password hashing algorithm.
A more robust hash algorithm increases the difficulty for attackers to crack stored
passwords in <html:code>/etc/security/opasswd</html:code>, thereby improving system security and
protecting user credentials.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="accounts_password_pam_unix_no_remember" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q pam; then

# RHEL-based systems: Use authselect-aware approach
if [ -f /usr/bin/authselect ]; then
    if [ -e "/etc/pam.d/system-auth" ] ; then
    PAM_FILE_PATH="/etc/pam.d/system-auth"
    if [ -f /usr/bin/authselect ]; then
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "/etc/pam.d/system-auth")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
    fi
    
if grep -qP "^\s*password\s+.*\s+pam_unix.so\s.*\bremember\b" "$PAM_FILE_PATH"; then
    sed -i -E --follow-symlinks "s/(.*password.*.*.*pam_unix.so.*)\bremember\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
fi
    if [ -f /usr/bin/authselect ]; then
        
        authselect apply-changes -b
    fi
else
    echo "/etc/pam.d/system-auth was not found" &gt;&amp;2
fi
    if [ -e "/etc/pam.d/password-auth" ] ; then
    PAM_FILE_PATH="/etc/pam.d/password-auth"
    if [ -f /usr/bin/authselect ]; then
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "/etc/pam.d/password-auth")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
    fi
    
if grep -qP "^\s*password\s+.*\s+pam_unix.so\s.*\bremember\b" "$PAM_FILE_PATH"; then
    sed -i -E --follow-symlinks "s/(.*password.*.*.*pam_unix.so.*)\bremember\b=?[[:alnum:]]*(.*)/\1\2/g" "$PAM_FILE_PATH"
fi
    if [ -f /usr/bin/authselect ]; then
        
        authselect apply-changes -b
    fi
else
    echo "/etc/pam.d/password-auth was not found" &gt;&amp;2
fi
else
    
if grep -qP "^\s*password\s+.*\s+pam_unix.so\s.*\bremember\b" "/etc/pam.d/system-auth"; then
    sed -i -E --follow-symlinks "s/(.*password.*.*.*pam_unix.so.*)\bremember\b=?[[:alnum:]]*(.*)/\1\2/g" "/etc/pam.d/system-auth"
fi
    
if grep -qP "^\s*password\s+.*\s+pam_unix.so\s.*\bremember\b" "/etc/pam.d/password-auth"; then
    sed -i -E --follow-symlinks "s/(.*password.*.*.*pam_unix.so.*)\bremember\b=?[[:alnum:]]*(.*)/\1\2/g" "/etc/pam.d/password-auth"
fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="accounts_password_pam_unix_no_remember" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - accounts_password_pam_unix_no_remember
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Avoid using remember in pam_unix module - Check if /etc/pam.d/system-auth
    file is present
  ansible.builtin.stat:
    path: /etc/pam.d/system-auth
  register: result_pam_auth_file_present
  when: '"pam" in ansible_facts.packages'
  tags:
  - accounts_password_pam_unix_no_remember
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Avoid using remember in pam_unix module - Check the proper remediation for
    the system
  block:

  - name: Avoid using remember in pam_unix module - Define the PAM file to be edited
      as a local fact
    ansible.builtin.set_fact:
      pam_file_path: /etc/pam.d/system-auth

  - name: Avoid using remember in pam_unix module - Check if system relies on authselect
      tool
    ansible.builtin.stat:
      path: /usr/bin/authselect
    register: result_authselect_present

  - name: Avoid using remember in pam_unix module - Ensure authselect custom profile
      is used if authselect is present
    block:

    - name: Avoid using remember in pam_unix module - Check integrity of authselect
        current profile
      ansible.builtin.command:
        cmd: authselect check
      register: result_authselect_check_cmd
      changed_when: false
      check_mode: false
      failed_when: false

    - name: Avoid using remember in pam_unix module - Informative message based on
        the authselect integrity check result
      ansible.builtin.assert:
        that:
        - ansible_check_mode or result_authselect_check_cmd.rc == 0
        fail_msg:
        - authselect integrity check failed. Remediation aborted!
        - This remediation could not be applied because an authselect profile was
          not selected or the selected profile is not intact.
        - It is not recommended to manually edit the PAM files when authselect tool
          is available.
        - In cases where the default authselect profile does not cover a specific
          demand, a custom authselect profile is recommended.
        success_msg:
        - authselect integrity check passed

    - name: Avoid using remember in pam_unix module - Get authselect current profile
      ansible.builtin.shell:
        cmd: authselect current -r | awk '{ print $1 }'
      register: result_authselect_profile
      changed_when: false
      when:
      - result_authselect_check_cmd is success

    - name: Avoid using remember in pam_unix module - Define the current authselect
        profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is match("custom/")

    - name: Avoid using remember in pam_unix module - Define the new authselect custom
        profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: custom/hardening
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is not match("custom/")

    - name: Avoid using remember in pam_unix module - Get authselect current features
        to also enable them in the custom profile
      ansible.builtin.shell:
        cmd: authselect current | tail -n+3 | awk '{ print $2 }'
      register: result_authselect_features
      changed_when: false
      check_mode: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Avoid using remember in pam_unix module - Check if any custom profile
        with the same name was already created
      ansible.builtin.stat:
        path: /etc/authselect/{{ authselect_custom_profile }}
      register: result_authselect_custom_profile_present
      changed_when: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Avoid using remember in pam_unix module - Create an authselect custom
        profile based on the current profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b {{ authselect_current_profile
          }}
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is not match("^(custom/|local)")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Avoid using remember in pam_unix module - Create an authselect custom
        profile based on sssd profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b sssd
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is match("local")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Avoid using remember in pam_unix module - Ensure authselect changes are
        applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Avoid using remember in pam_unix module - Ensure the authselect custom
        profile is selected
      ansible.builtin.command:
        cmd: authselect select {{ authselect_custom_profile }}
      register: result_pam_authselect_select_profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Avoid using remember in pam_unix module - Restore the authselect features
        in the custom profile
      ansible.builtin.command:
        cmd: authselect enable-feature {{ item }}
      loop: '{{ result_authselect_features.stdout_lines }}'
      register: result_pam_authselect_restore_features
      when:
      - result_authselect_profile is not skipped
      - result_authselect_features is not skipped
      - result_pam_authselect_select_profile is not skipped

    - name: Avoid using remember in pam_unix module - Ensure authselect changes are
        applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - result_pam_authselect_restore_features is not skipped

    - name: Avoid using remember in pam_unix module - Change the PAM file to be edited
        according to the custom authselect profile
      ansible.builtin.set_fact:
        pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
          | basename }}
      when:
      - authselect_custom_profile is defined
    when:
    - result_authselect_present.stat.exists

  - name: Avoid using remember in pam_unix module - Define a fact for control already
      filtered in case filters are used
    ansible.builtin.set_fact:
      pam_module_control: ''

  - name: Avoid using remember in pam_unix module - Check if {{ pam_file_path }} file
      is present
    ansible.builtin.stat:
      path: '{{ pam_file_path }}'
    register: result_pam_file_present

  - name: Avoid using remember in pam_unix module - Ensure the "remember" option from
      "pam_unix.so" is not present in {{ pam_file_path }}
    ansible.builtin.replace:
      dest: '{{ pam_file_path }}'
      regexp: (.*password.*pam_unix.so.*)\bremember\b=?[0-9a-zA-Z]*(.*)
      replace: \1\2
    register: result_pam_option_removal
    when:
    - result_pam_file_present.stat.exists

  - name: Avoid using remember in pam_unix module - Ensure authselect changes are
      applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_present.stat.exists
    - result_pam_option_removal is changed
  when:
  - '"pam" in ansible_facts.packages'
  - result_pam_auth_file_present.stat.exists
  tags:
  - accounts_password_pam_unix_no_remember
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Avoid using remember in pam_unix module - Check if /etc/pam.d/password-auth
    file is present
  ansible.builtin.stat:
    path: /etc/pam.d/password-auth
  register: result_pam_password_auth_file_present
  when: '"pam" in ansible_facts.packages'
  tags:
  - accounts_password_pam_unix_no_remember
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Avoid using remember in pam_unix module - Check the proper remediation for
    the system
  block:

  - name: Avoid using remember in pam_unix module - Define the PAM file to be edited
      as a local fact
    ansible.builtin.set_fact:
      pam_file_path: /etc/pam.d/password-auth

  - name: Avoid using remember in pam_unix module - Check if system relies on authselect
      tool
    ansible.builtin.stat:
      path: /usr/bin/authselect
    register: result_authselect_present

  - name: Avoid using remember in pam_unix module - Ensure authselect custom profile
      is used if authselect is present
    block:

    - name: Avoid using remember in pam_unix module - Check integrity of authselect
        current profile
      ansible.builtin.command:
        cmd: authselect check
      register: result_authselect_check_cmd
      changed_when: false
      check_mode: false
      failed_when: false

    - name: Avoid using remember in pam_unix module - Informative message based on
        the authselect integrity check result
      ansible.builtin.assert:
        that:
        - ansible_check_mode or result_authselect_check_cmd.rc == 0
        fail_msg:
        - authselect integrity check failed. Remediation aborted!
        - This remediation could not be applied because an authselect profile was
          not selected or the selected profile is not intact.
        - It is not recommended to manually edit the PAM files when authselect tool
          is available.
        - In cases where the default authselect profile does not cover a specific
          demand, a custom authselect profile is recommended.
        success_msg:
        - authselect integrity check passed

    - name: Avoid using remember in pam_unix module - Get authselect current profile
      ansible.builtin.shell:
        cmd: authselect current -r | awk '{ print $1 }'
      register: result_authselect_profile
      changed_when: false
      when:
      - result_authselect_check_cmd is success

    - name: Avoid using remember in pam_unix module - Define the current authselect
        profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is match("custom/")

    - name: Avoid using remember in pam_unix module - Define the new authselect custom
        profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: custom/hardening
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is not match("custom/")

    - name: Avoid using remember in pam_unix module - Get authselect current features
        to also enable them in the custom profile
      ansible.builtin.shell:
        cmd: authselect current | tail -n+3 | awk '{ print $2 }'
      register: result_authselect_features
      changed_when: false
      check_mode: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Avoid using remember in pam_unix module - Check if any custom profile
        with the same name was already created
      ansible.builtin.stat:
        path: /etc/authselect/{{ authselect_custom_profile }}
      register: result_authselect_custom_profile_present
      changed_when: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Avoid using remember in pam_unix module - Create an authselect custom
        profile based on the current profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b {{ authselect_current_profile
          }}
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is not match("^(custom/|local)")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Avoid using remember in pam_unix module - Create an authselect custom
        profile based on sssd profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b sssd
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is match("local")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Avoid using remember in pam_unix module - Ensure authselect changes are
        applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Avoid using remember in pam_unix module - Ensure the authselect custom
        profile is selected
      ansible.builtin.command:
        cmd: authselect select {{ authselect_custom_profile }}
      register: result_pam_authselect_select_profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Avoid using remember in pam_unix module - Restore the authselect features
        in the custom profile
      ansible.builtin.command:
        cmd: authselect enable-feature {{ item }}
      loop: '{{ result_authselect_features.stdout_lines }}'
      register: result_pam_authselect_restore_features
      when:
      - result_authselect_profile is not skipped
      - result_authselect_features is not skipped
      - result_pam_authselect_select_profile is not skipped

    - name: Avoid using remember in pam_unix module - Ensure authselect changes are
        applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - result_pam_authselect_restore_features is not skipped

    - name: Avoid using remember in pam_unix module - Change the PAM file to be edited
        according to the custom authselect profile
      ansible.builtin.set_fact:
        pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
          | basename }}
      when:
      - authselect_custom_profile is defined
    when:
    - result_authselect_present.stat.exists

  - name: Avoid using remember in pam_unix module - Define a fact for control already
      filtered in case filters are used
    ansible.builtin.set_fact:
      pam_module_control: ''

  - name: Avoid using remember in pam_unix module - Check if {{ pam_file_path }} file
      is present
    ansible.builtin.stat:
      path: '{{ pam_file_path }}'
    register: result_pam_file_present

  - name: Avoid using remember in pam_unix module - Ensure the "remember" option from
      "pam_unix.so" is not present in {{ pam_file_path }}
    ansible.builtin.replace:
      dest: '{{ pam_file_path }}'
      regexp: (.*password.*pam_unix.so.*)\bremember\b=?[0-9a-zA-Z]*(.*)
      replace: \1\2
    register: result_pam_option_removal
    when:
    - result_pam_file_present.stat.exists

  - name: Avoid using remember in pam_unix module - Ensure authselect changes are
      applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_present.stat.exists
    - result_pam_option_removal is changed
  when:
  - '"pam" in ansible_facts.packages'
  - result_pam_password_auth_file_present.stat.exists
  tags:
  - accounts_password_pam_unix_no_remember
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_unix_no_remember:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_unix_no_remember_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_rounds_password_auth" selected="false" severity="medium">
                <xccdf-1.2:title>Set number of Password Hashing Rounds - password-auth</xccdf-1.2:title>
                <xccdf-1.2:description>Configure the number or rounds for the password hashing algorithm. This can be
accomplished by using the <html:code>rounds</html:code> option for the <html:code>pam_unix</html:code> PAM module.
<html:br/><html:br/>
In file <html:code>/etc/pam.d/password-auth</html:code> append <html:code>rounds=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_rounds" use="legacy"/></html:code>
to the <html:code>pam_unix.so</html:code> entry, as shown below:

<html:pre>password sufficient pam_unix.so <html:i>...existing_options...</html:i> rounds=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_rounds" use="legacy"/></html:pre>

The system's default number of rounds is 5000.</xccdf-1.2:description>
                <xccdf-1.2:warning category="performance">Setting a high number of hashing rounds makes it more difficult to brute force the password,
but requires more CPU resources to authenticate users.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000073-GPOS-00041</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R68</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Using a higher number of rounds makes password cracking attacks more difficult.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam_and_system_with_kernel"/>
                <xccdf-1.2:fix id="accounts_password_pam_unix_rounds_password_auth" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q pam &amp;&amp; rpm --quiet -q kernel ) ); then

var_password_pam_unix_rounds='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_rounds" use="legacy"/>'



if [ -e "/etc/pam.d/password-auth" ] ; then
    PAM_FILE_PATH="/etc/pam.d/password-auth"
    if [ -f /usr/bin/authselect ]; then
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "/etc/pam.d/password-auth")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
    fi
    

        if ! grep -qP "^\s*password\s+sufficient\s+pam_unix.so\s*.*" "$PAM_FILE_PATH"; then
            # Line matching group + control + module was not found. Check group + module.
            if [ "$(grep -cP '^\s*password\s+.*\s+pam_unix.so\s*' "$PAM_FILE_PATH")" -eq 1 ]; then
                # The control is updated only if one single line matches.
                sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_unix.so.*)/\1sufficient \2/" "$PAM_FILE_PATH"
            else
                echo "password    sufficient    pam_unix.so" &gt;&gt; "$PAM_FILE_PATH"
            fi
        fi
        # Check the option
        if ! grep -qP "^\s*password\s+sufficient\s+pam_unix.so\s*.*\srounds\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "/\s*password\s+sufficient\s+pam_unix.so.*/ s/$/ rounds=$var_password_pam_unix_rounds/" "$PAM_FILE_PATH"
        else
            sed -i -E --follow-symlinks "s/(\s*password\s+sufficient\s+pam_unix.so\s+.*)(rounds=)[[:alnum:]]*\s*(.*)/\1\2$var_password_pam_unix_rounds \3/" "$PAM_FILE_PATH"
        fi
    if [ -f /usr/bin/authselect ]; then
        
        authselect apply-changes -b
    fi
else
    echo "/etc/pam.d/password-auth was not found" &gt;&amp;2
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="accounts_password_pam_unix_rounds_password_auth" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - accounts_password_pam_unix_rounds_password_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
- name: XCCDF Value var_password_pam_unix_rounds # promote to variable
  set_fact:
    var_password_pam_unix_rounds: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_rounds" use="legacy"/>
  tags:
    - always

- name: Set number of Password Hashing Rounds - password-auth - Check if /etc/pam.d/password-auth
    file is present
  ansible.builtin.stat:
    path: /etc/pam.d/password-auth
  register: result_pam_password_auth_file_present
  when: ( "pam" in ansible_facts.packages and "kernel" in ansible_facts.packages )
  tags:
  - accounts_password_pam_unix_rounds_password_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Set number of Password Hashing Rounds - password-auth - Check the proper remediation
    for the system
  block:

  - name: Set number of Password Hashing Rounds - password-auth - Define the PAM file
      to be edited as a local fact
    ansible.builtin.set_fact:
      pam_file_path: /etc/pam.d/password-auth

  - name: Set number of Password Hashing Rounds - password-auth - Check if system
      relies on authselect tool
    ansible.builtin.stat:
      path: /usr/bin/authselect
    register: result_authselect_present

  - name: Set number of Password Hashing Rounds - password-auth - Ensure authselect
      custom profile is used if authselect is present
    block:

    - name: Set number of Password Hashing Rounds - password-auth - Check integrity
        of authselect current profile
      ansible.builtin.command:
        cmd: authselect check
      register: result_authselect_check_cmd
      changed_when: false
      check_mode: false
      failed_when: false

    - name: Set number of Password Hashing Rounds - password-auth - Informative message
        based on the authselect integrity check result
      ansible.builtin.assert:
        that:
        - ansible_check_mode or result_authselect_check_cmd.rc == 0
        fail_msg:
        - authselect integrity check failed. Remediation aborted!
        - This remediation could not be applied because an authselect profile was
          not selected or the selected profile is not intact.
        - It is not recommended to manually edit the PAM files when authselect tool
          is available.
        - In cases where the default authselect profile does not cover a specific
          demand, a custom authselect profile is recommended.
        success_msg:
        - authselect integrity check passed

    - name: Set number of Password Hashing Rounds - password-auth - Get authselect
        current profile
      ansible.builtin.shell:
        cmd: authselect current -r | awk '{ print $1 }'
      register: result_authselect_profile
      changed_when: false
      when:
      - result_authselect_check_cmd is success

    - name: Set number of Password Hashing Rounds - password-auth - Define the current
        authselect profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is match("custom/")

    - name: Set number of Password Hashing Rounds - password-auth - Define the new
        authselect custom profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: custom/hardening
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is not match("custom/")

    - name: Set number of Password Hashing Rounds - password-auth - Get authselect
        current features to also enable them in the custom profile
      ansible.builtin.shell:
        cmd: authselect current | tail -n+3 | awk '{ print $2 }'
      register: result_authselect_features
      changed_when: false
      check_mode: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Set number of Password Hashing Rounds - password-auth - Check if any custom
        profile with the same name was already created
      ansible.builtin.stat:
        path: /etc/authselect/{{ authselect_custom_profile }}
      register: result_authselect_custom_profile_present
      changed_when: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Set number of Password Hashing Rounds - password-auth - Create an authselect
        custom profile based on the current profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b {{ authselect_current_profile
          }}
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is not match("^(custom/|local)")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Set number of Password Hashing Rounds - password-auth - Create an authselect
        custom profile based on sssd profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b sssd
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is match("local")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Set number of Password Hashing Rounds - password-auth - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Set number of Password Hashing Rounds - password-auth - Ensure the authselect
        custom profile is selected
      ansible.builtin.command:
        cmd: authselect select {{ authselect_custom_profile }}
      register: result_pam_authselect_select_profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Set number of Password Hashing Rounds - password-auth - Restore the authselect
        features in the custom profile
      ansible.builtin.command:
        cmd: authselect enable-feature {{ item }}
      loop: '{{ result_authselect_features.stdout_lines }}'
      register: result_pam_authselect_restore_features
      when:
      - result_authselect_profile is not skipped
      - result_authselect_features is not skipped
      - result_pam_authselect_select_profile is not skipped

    - name: Set number of Password Hashing Rounds - password-auth - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - result_pam_authselect_restore_features is not skipped

    - name: Set number of Password Hashing Rounds - password-auth - Change the PAM
        file to be edited according to the custom authselect profile
      ansible.builtin.set_fact:
        pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
          | basename }}
      when:
      - authselect_custom_profile is defined
    when:
    - result_authselect_present.stat.exists

  - name: Set number of Password Hashing Rounds - password-auth - Define a fact for
      control already filtered in case filters are used
    ansible.builtin.set_fact:
      pam_module_control: sufficient

  - name: Set number of Password Hashing Rounds - password-auth - Check if expected
      PAM module line is present in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so\s*.*
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_line_present

  - name: Set number of Password Hashing Rounds - password-auth - Include or update
      the PAM module line in {{ pam_file_path }}
    block:

    - name: Set number of Password Hashing Rounds - password-auth - Check if required
        PAM module line is present in {{ pam_file_path }} with different control
      ansible.builtin.lineinfile:
        path: '{{ pam_file_path }}'
        regexp: ^\s*password\s+.*\s+pam_unix.so\s*
        state: absent
      check_mode: true
      changed_when: false
      register: result_pam_line_other_control_present

    - name: Set number of Password Hashing Rounds - password-auth - Ensure the correct
        control for the required PAM module line in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: ^(\s*password\s+).*(\bpam_unix.so.*)
        replace: \1{{ pam_module_control }} \2
      register: result_pam_module_edit
      when:
      - result_pam_line_other_control_present.found == 1

    - name: Set number of Password Hashing Rounds - password-auth - Ensure the required
        PAM module line is included in {{ pam_file_path }}
      ansible.builtin.lineinfile:
        dest: '{{ pam_file_path }}'
        line: password    {{ pam_module_control }}    pam_unix.so
      register: result_pam_module_add
      when:
      - result_pam_line_other_control_present.found == 0 or result_pam_line_other_control_present.found
        &gt; 1

    - name: Set number of Password Hashing Rounds - password-auth - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present is defined
      - result_authselect_present.stat.exists
      - |-
        (result_pam_module_add is defined and result_pam_module_add.changed)
         or (result_pam_module_edit is defined and result_pam_module_edit.changed)
    when:
    - result_pam_line_present.found is defined
    - result_pam_line_present.found == 0

  - name: Set number of Password Hashing Rounds - password-auth - Define a fact for
      control already filtered in case filters are used
    ansible.builtin.set_fact:
      pam_module_control: sufficient

  - name: Set number of Password Hashing Rounds - password-auth - Check if the required
      PAM module option is present in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so\s*.*\srounds\b
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_module_accounts_password_pam_unix_rounds_password_auth_option_present

  - name: Set number of Password Hashing Rounds - password-auth - Ensure the "rounds"
      PAM option for "pam_unix.so" is included in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      backrefs: true
      regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so.*)
      line: \1 rounds={{ var_password_pam_unix_rounds }}
      state: present
    register: result_pam_accounts_password_pam_unix_rounds_password_auth_add
    when:
    - result_pam_module_accounts_password_pam_unix_rounds_password_auth_option_present.found
      is defined
    - result_pam_module_accounts_password_pam_unix_rounds_password_auth_option_present.found
      == 0

  - name: Set number of Password Hashing Rounds - password-auth - Ensure the required
      value for "rounds" PAM option from "pam_unix.so" in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      backrefs: true
      regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so\s+.*)(rounds)=[0-9a-zA-Z]*\s*(.*)
      line: \1\2={{ var_password_pam_unix_rounds }} \3
    register: result_pam_accounts_password_pam_unix_rounds_password_auth_edit
    when:
    - result_pam_module_accounts_password_pam_unix_rounds_password_auth_option_present.found
      &gt; 0

  - name: Set number of Password Hashing Rounds - password-auth - Ensure authselect
      changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_present.stat.exists
    - |-
      (result_pam_accounts_password_pam_unix_rounds_password_auth_add is defined and result_pam_accounts_password_pam_unix_rounds_password_auth_add.changed)
       or (result_pam_accounts_password_pam_unix_rounds_password_auth_edit is defined and result_pam_accounts_password_pam_unix_rounds_password_auth_edit.changed)
  when:
  - ( "pam" in ansible_facts.packages and "kernel" in ansible_facts.packages )
  - result_pam_password_auth_file_present.stat.exists
  tags:
  - accounts_password_pam_unix_rounds_password_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_unix_rounds:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_unix_rounds"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_unix_rounds_password_auth:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_unix_rounds_password_auth_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_rounds_system_auth" selected="false" severity="medium">
                <xccdf-1.2:title>Set number of Password Hashing Rounds - system-auth</xccdf-1.2:title>
                <xccdf-1.2:description>Configure the number or rounds for the password hashing algorithm. This can be
accomplished by using the <html:code>rounds</html:code> option for the <html:code>pam_unix</html:code> PAM module.
<html:br/><html:br/>
In file <html:code>/etc/pam.d/system-auth</html:code> append <html:code>rounds=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_rounds" use="legacy"/></html:code>
to the <html:code>pam_unix.so</html:code> entry, as shown below:
<html:pre>password sufficient pam_unix.so <html:i>...existing_options...</html:i> rounds=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_rounds" use="legacy"/></html:pre>
The system's default number of rounds is 5000.</xccdf-1.2:description>
                <xccdf-1.2:warning category="performance">Setting a high number of hashing rounds makes it more difficult to brute force the password,
but requires more CPU resources to authenticate users.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000073-GPOS-00041</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R68</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Using a higher number of rounds makes password cracking attacks more difficult.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam_and_system_with_kernel"/>
                <xccdf-1.2:fix id="accounts_password_pam_unix_rounds_system_auth" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q pam &amp;&amp; rpm --quiet -q kernel ) ); then

var_password_pam_unix_rounds='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_rounds" use="legacy"/>'


if [ -e "/etc/pam.d/system-auth" ] ; then
    PAM_FILE_PATH="/etc/pam.d/system-auth"
    if [ -f /usr/bin/authselect ]; then
        
        if ! authselect check; then
        echo "
        authselect integrity check failed. Remediation aborted!
        This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
        It is not recommended to manually edit the PAM files when authselect tool is available.
        In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
        exit 1
        fi

        CURRENT_PROFILE=$(authselect current -r | awk '{ print $1 }')
        # If not already in use, a custom profile is created preserving the enabled features.
        if [[ ! $CURRENT_PROFILE == custom/* ]]; then
            ENABLED_FEATURES=$(authselect current | tail -n+3 | awk '{ print $2 }')
            # The "local" profile does not contain essential security features required by multiple Benchmarks.
            # If currently used, it is replaced by "sssd", which is the best option in this case.
            if [[ $CURRENT_PROFILE == local ]]; then
                CURRENT_PROFILE="sssd"
            fi
            authselect create-profile hardening -b $CURRENT_PROFILE
            CURRENT_PROFILE="custom/hardening"
            
            authselect apply-changes -b --backup=before-hardening-custom-profile
            authselect select $CURRENT_PROFILE
            for feature in $ENABLED_FEATURES; do
                authselect enable-feature $feature;
            done
            
            authselect apply-changes -b --backup=after-hardening-custom-profile
        fi
        PAM_FILE_NAME=$(basename "/etc/pam.d/system-auth")
        PAM_FILE_PATH="/etc/authselect/$CURRENT_PROFILE/$PAM_FILE_NAME"

        authselect apply-changes -b
    fi
    

        if ! grep -qP "^\s*password\s+sufficient\s+pam_unix.so\s*.*" "$PAM_FILE_PATH"; then
            # Line matching group + control + module was not found. Check group + module.
            if [ "$(grep -cP '^\s*password\s+.*\s+pam_unix.so\s*' "$PAM_FILE_PATH")" -eq 1 ]; then
                # The control is updated only if one single line matches.
                sed -i -E --follow-symlinks "s/^(\s*password\s+).*(\bpam_unix.so.*)/\1sufficient \2/" "$PAM_FILE_PATH"
            else
                echo "password    sufficient    pam_unix.so" &gt;&gt; "$PAM_FILE_PATH"
            fi
        fi
        # Check the option
        if ! grep -qP "^\s*password\s+sufficient\s+pam_unix.so\s*.*\srounds\b" "$PAM_FILE_PATH"; then
            sed -i -E --follow-symlinks "/\s*password\s+sufficient\s+pam_unix.so.*/ s/$/ rounds=$var_password_pam_unix_rounds/" "$PAM_FILE_PATH"
        else
            sed -i -E --follow-symlinks "s/(\s*password\s+sufficient\s+pam_unix.so\s+.*)(rounds=)[[:alnum:]]*\s*(.*)/\1\2$var_password_pam_unix_rounds \3/" "$PAM_FILE_PATH"
        fi
    if [ -f /usr/bin/authselect ]; then
        
        authselect apply-changes -b
    fi
else
    echo "/etc/pam.d/system-auth was not found" &gt;&amp;2
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="accounts_password_pam_unix_rounds_system_auth" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - accounts_password_pam_unix_rounds_system_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
- name: XCCDF Value var_password_pam_unix_rounds # promote to variable
  set_fact:
    var_password_pam_unix_rounds: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_rounds" use="legacy"/>
  tags:
    - always

- name: Set number of Password Hashing Rounds - system-auth - Check if /etc/pam.d/system-auth
    file is present
  ansible.builtin.stat:
    path: /etc/pam.d/system-auth
  register: result_pam_auth_file_present
  when: ( "pam" in ansible_facts.packages and "kernel" in ansible_facts.packages )
  tags:
  - accounts_password_pam_unix_rounds_system_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed

- name: Set number of Password Hashing Rounds - system-auth - Check the proper remediation
    for the system
  block:

  - name: Set number of Password Hashing Rounds - system-auth - Define the PAM file
      to be edited as a local fact
    ansible.builtin.set_fact:
      pam_file_path: /etc/pam.d/system-auth

  - name: Set number of Password Hashing Rounds - system-auth - Check if system relies
      on authselect tool
    ansible.builtin.stat:
      path: /usr/bin/authselect
    register: result_authselect_present

  - name: Set number of Password Hashing Rounds - system-auth - Ensure authselect
      custom profile is used if authselect is present
    block:

    - name: Set number of Password Hashing Rounds - system-auth - Check integrity
        of authselect current profile
      ansible.builtin.command:
        cmd: authselect check
      register: result_authselect_check_cmd
      changed_when: false
      check_mode: false
      failed_when: false

    - name: Set number of Password Hashing Rounds - system-auth - Informative message
        based on the authselect integrity check result
      ansible.builtin.assert:
        that:
        - ansible_check_mode or result_authselect_check_cmd.rc == 0
        fail_msg:
        - authselect integrity check failed. Remediation aborted!
        - This remediation could not be applied because an authselect profile was
          not selected or the selected profile is not intact.
        - It is not recommended to manually edit the PAM files when authselect tool
          is available.
        - In cases where the default authselect profile does not cover a specific
          demand, a custom authselect profile is recommended.
        success_msg:
        - authselect integrity check passed

    - name: Set number of Password Hashing Rounds - system-auth - Get authselect current
        profile
      ansible.builtin.shell:
        cmd: authselect current -r | awk '{ print $1 }'
      register: result_authselect_profile
      changed_when: false
      when:
      - result_authselect_check_cmd is success

    - name: Set number of Password Hashing Rounds - system-auth - Define the current
        authselect profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: '{{ result_authselect_profile.stdout }}'
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is match("custom/")

    - name: Set number of Password Hashing Rounds - system-auth - Define the new authselect
        custom profile as a local fact
      ansible.builtin.set_fact:
        authselect_current_profile: '{{ result_authselect_profile.stdout }}'
        authselect_custom_profile: custom/hardening
      when:
      - result_authselect_profile is not skipped
      - result_authselect_profile.stdout is not match("custom/")

    - name: Set number of Password Hashing Rounds - system-auth - Get authselect current
        features to also enable them in the custom profile
      ansible.builtin.shell:
        cmd: authselect current | tail -n+3 | awk '{ print $2 }'
      register: result_authselect_features
      changed_when: false
      check_mode: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Set number of Password Hashing Rounds - system-auth - Check if any custom
        profile with the same name was already created
      ansible.builtin.stat:
        path: /etc/authselect/{{ authselect_custom_profile }}
      register: result_authselect_custom_profile_present
      changed_when: false
      when:
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")

    - name: Set number of Password Hashing Rounds - system-auth - Create an authselect
        custom profile based on the current profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b {{ authselect_current_profile
          }}
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is not match("^(custom/|local)")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Set number of Password Hashing Rounds - system-auth - Create an authselect
        custom profile based on sssd profile
      ansible.builtin.command:
        cmd: authselect create-profile hardening -b sssd
      when:
      - result_authselect_profile is not skipped
      - result_authselect_check_cmd is success
      - authselect_current_profile is match("local")
      - not result_authselect_custom_profile_present.stat.exists

    - name: Set number of Password Hashing Rounds - system-auth - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=before-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Set number of Password Hashing Rounds - system-auth - Ensure the authselect
        custom profile is selected
      ansible.builtin.command:
        cmd: authselect select {{ authselect_custom_profile }}
      register: result_pam_authselect_select_profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - authselect_current_profile is not match("custom/")
      - authselect_custom_profile is not match(authselect_current_profile)

    - name: Set number of Password Hashing Rounds - system-auth - Restore the authselect
        features in the custom profile
      ansible.builtin.command:
        cmd: authselect enable-feature {{ item }}
      loop: '{{ result_authselect_features.stdout_lines }}'
      register: result_pam_authselect_restore_features
      when:
      - result_authselect_profile is not skipped
      - result_authselect_features is not skipped
      - result_pam_authselect_select_profile is not skipped

    - name: Set number of Password Hashing Rounds - system-auth - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b --backup=after-hardening-custom-profile
      when:
      - result_authselect_check_cmd is success
      - result_authselect_profile is not skipped
      - result_pam_authselect_restore_features is not skipped

    - name: Set number of Password Hashing Rounds - system-auth - Change the PAM file
        to be edited according to the custom authselect profile
      ansible.builtin.set_fact:
        pam_file_path: /etc/authselect/{{ authselect_custom_profile }}/{{ pam_file_path
          | basename }}
      when:
      - authselect_custom_profile is defined
    when:
    - result_authselect_present.stat.exists

  - name: Set number of Password Hashing Rounds - system-auth - Define a fact for
      control already filtered in case filters are used
    ansible.builtin.set_fact:
      pam_module_control: sufficient

  - name: Set number of Password Hashing Rounds - system-auth - Check if expected
      PAM module line is present in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so\s*.*
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_line_present

  - name: Set number of Password Hashing Rounds - system-auth - Include or update
      the PAM module line in {{ pam_file_path }}
    block:

    - name: Set number of Password Hashing Rounds - system-auth - Check if required
        PAM module line is present in {{ pam_file_path }} with different control
      ansible.builtin.lineinfile:
        path: '{{ pam_file_path }}'
        regexp: ^\s*password\s+.*\s+pam_unix.so\s*
        state: absent
      check_mode: true
      changed_when: false
      register: result_pam_line_other_control_present

    - name: Set number of Password Hashing Rounds - system-auth - Ensure the correct
        control for the required PAM module line in {{ pam_file_path }}
      ansible.builtin.replace:
        dest: '{{ pam_file_path }}'
        regexp: ^(\s*password\s+).*(\bpam_unix.so.*)
        replace: \1{{ pam_module_control }} \2
      register: result_pam_module_edit
      when:
      - result_pam_line_other_control_present.found == 1

    - name: Set number of Password Hashing Rounds - system-auth - Ensure the required
        PAM module line is included in {{ pam_file_path }}
      ansible.builtin.lineinfile:
        dest: '{{ pam_file_path }}'
        line: password    {{ pam_module_control }}    pam_unix.so
      register: result_pam_module_add
      when:
      - result_pam_line_other_control_present.found == 0 or result_pam_line_other_control_present.found
        &gt; 1

    - name: Set number of Password Hashing Rounds - system-auth - Ensure authselect
        changes are applied
      ansible.builtin.command:
        cmd: authselect apply-changes -b
      when:
      - result_authselect_present is defined
      - result_authselect_present.stat.exists
      - |-
        (result_pam_module_add is defined and result_pam_module_add.changed)
         or (result_pam_module_edit is defined and result_pam_module_edit.changed)
    when:
    - result_pam_line_present.found is defined
    - result_pam_line_present.found == 0

  - name: Set number of Password Hashing Rounds - system-auth - Define a fact for
      control already filtered in case filters are used
    ansible.builtin.set_fact:
      pam_module_control: sufficient

  - name: Set number of Password Hashing Rounds - system-auth - Check if the required
      PAM module option is present in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      regexp: ^\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so\s*.*\srounds\b
      state: absent
    check_mode: true
    changed_when: false
    register: result_pam_module_accounts_password_pam_unix_rounds_system_auth_option_present

  - name: Set number of Password Hashing Rounds - system-auth - Ensure the "rounds"
      PAM option for "pam_unix.so" is included in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      backrefs: true
      regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so.*)
      line: \1 rounds={{ var_password_pam_unix_rounds }}
      state: present
    register: result_pam_accounts_password_pam_unix_rounds_system_auth_add
    when:
    - result_pam_module_accounts_password_pam_unix_rounds_system_auth_option_present.found
      is defined
    - result_pam_module_accounts_password_pam_unix_rounds_system_auth_option_present.found
      == 0

  - name: Set number of Password Hashing Rounds - system-auth - Ensure the required
      value for "rounds" PAM option from "pam_unix.so" in {{ pam_file_path }}
    ansible.builtin.lineinfile:
      path: '{{ pam_file_path }}'
      backrefs: true
      regexp: ^(\s*password\s+{{ pam_module_control | regex_escape() }}\s+pam_unix.so\s+.*)(rounds)=[0-9a-zA-Z]*\s*(.*)
      line: \1\2={{ var_password_pam_unix_rounds }} \3
    register: result_pam_accounts_password_pam_unix_rounds_system_auth_edit
    when:
    - result_pam_module_accounts_password_pam_unix_rounds_system_auth_option_present.found
      &gt; 0

  - name: Set number of Password Hashing Rounds - system-auth - Ensure authselect
      changes are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_present.stat.exists
    - |-
      (result_pam_accounts_password_pam_unix_rounds_system_auth_add is defined and result_pam_accounts_password_pam_unix_rounds_system_auth_add.changed)
       or (result_pam_accounts_password_pam_unix_rounds_system_auth_edit is defined and result_pam_accounts_password_pam_unix_rounds_system_auth_edit.changed)
  when:
  - ( "pam" in ansible_facts.packages and "kernel" in ansible_facts.packages )
  - result_pam_auth_file_present.stat.exists
  tags:
  - accounts_password_pam_unix_rounds_system_auth
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_password_pam_unix_rounds:var:1" value-id="xccdf_org.ssgproject.content_value_var_password_pam_unix_rounds"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_password_pam_unix_rounds_system_auth:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_password_pam_unix_rounds_system_auth_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_gid_passwd_group_same" selected="false" severity="low">
                <xccdf-1.2:title>All GIDs referenced in /etc/passwd must be defined in /etc/group</xccdf-1.2:title>
                <xccdf-1.2:description>Add a group to the system for each GID referenced without a corresponding group.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.5.a</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000104-GPOS-00051</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.2.3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If a user is assigned the Group Identifier (GID) of a group not existing on the system, and a group
with the Group Identifier (GID) is subsequently created, the user may have unintended rights to
any files associated with the group.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-gid_passwd_group_same:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-gid_passwd_group_same_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_empty_passwords" selected="false" severity="high">
                <xccdf-1.2:title>Prevent Login to Accounts With Empty Password</xccdf-1.2:title>
                <xccdf-1.2:description>If an account is configured for password authentication
but does not have an assigned password, it may be possible to log
into the account without authentication. Remove any instances of the
<html:code>nullok</html:code> in

<html:code>/etc/pam.d/system-auth</html:code> and
<html:code>/etc/pam.d/password-auth</html:code>

to prevent logins with empty passwords.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">If the system relies on <html:code>authselect</html:code> tool to manage PAM settings, the remediation
will also use <html:code>authselect</html:code> tool. However, if any manual modification was made in
PAM files, the <html:code>authselect</html:code> integrity check will fail and the remediation will be
aborted in order to preserve intentional changes. In this case, an informative message will
be shown in the remediation report.
Note that this rule is not applicable for systems running within a
container. Having user with empty password within a container is not
considered a risk, because it should not be possible to directly login into
a container anyway.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_UAU.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.3.3.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020332</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020331</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244541r1017347_rule</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-268322r1017568_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If an account has an empty password, anyone could log in and
run commands with the privileges of that account. Accounts with
empty passwords should never be used in operational environments.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="no_empty_passwords" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -f /usr/bin/authselect ]; then
    if ! authselect check; then
echo "
authselect integrity check failed. Remediation aborted!
This remediation could not be applied because an authselect profile was not selected or the selected profile is not intact.
It is not recommended to manually edit the PAM files when authselect tool is available.
In cases where the default authselect profile does not cover a specific demand, a custom authselect profile is recommended."
exit 1
fi
authselect enable-feature without-nullok

authselect apply-changes -b
else
    
if grep -qP "^\s*auth\s+sufficient\s+pam_unix.so\s.*\bnullok\b" "/etc/pam.d/system-auth"; then
    sed -i -E --follow-symlinks "s/(.*auth.*sufficient.*pam_unix.so.*)\bnullok\b=?[[:alnum:]]*(.*)/\1\2/g" "/etc/pam.d/system-auth"
fi
    
if grep -qP "^\s*password\s+sufficient\s+pam_unix.so\s.*\bnullok\b" "/etc/pam.d/system-auth"; then
    sed -i -E --follow-symlinks "s/(.*password.*sufficient.*pam_unix.so.*)\bnullok\b=?[[:alnum:]]*(.*)/\1\2/g" "/etc/pam.d/system-auth"
fi
    
if grep -qP "^\s*auth\s+sufficient\s+pam_unix.so\s.*\bnullok\b" "/etc/pam.d/password-auth"; then
    sed -i -E --follow-symlinks "s/(.*auth.*sufficient.*pam_unix.so.*)\bnullok\b=?[[:alnum:]]*(.*)/\1\2/g" "/etc/pam.d/password-auth"
fi
    
if grep -qP "^\s*password\s+sufficient\s+pam_unix.so\s.*\bnullok\b" "/etc/pam.d/password-auth"; then
    sed -i -E --follow-symlinks "s/(.*password.*sufficient.*pam_unix.so.*)\bnullok\b=?[[:alnum:]]*(.*)/\1\2/g" "/etc/pam.d/password-auth"
fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="no_empty_passwords" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.2
  - DISA-STIG-RHEL-08-020331
  - DISA-STIG-RHEL-08-020332
  - NIST-800-171-3.1.1
  - NIST-800-171-3.1.5
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.3
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.1
  - configure_strategy
  - high_severity
  - low_complexity
  - medium_disruption
  - no_empty_passwords
  - no_reboot_needed

- name: Prevent Login to Accounts With Empty Password - Check if system relies on
    authselect
  ansible.builtin.stat:
    path: /usr/bin/authselect
  register: result_authselect_present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.5.2
  - DISA-STIG-RHEL-08-020331
  - DISA-STIG-RHEL-08-020332
  - NIST-800-171-3.1.1
  - NIST-800-171-3.1.5
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.3
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.1
  - configure_strategy
  - high_severity
  - low_complexity
  - medium_disruption
  - no_empty_passwords
  - no_reboot_needed

- name: Prevent Login to Accounts With Empty Password - Remediate using authselect
  block:

  - name: Prevent Login to Accounts With Empty Password - Check integrity of authselect
      current profile
    ansible.builtin.command:
      cmd: authselect check
    register: result_authselect_check_cmd
    changed_when: false
    check_mode: false
    failed_when: false

  - name: Prevent Login to Accounts With Empty Password - Informative message based
      on the authselect integrity check result
    ansible.builtin.assert:
      that:
      - ansible_check_mode or result_authselect_check_cmd.rc == 0
      fail_msg:
      - authselect integrity check failed. Remediation aborted!
      - This remediation could not be applied because an authselect profile was not
        selected or the selected profile is not intact.
      - It is not recommended to manually edit the PAM files when authselect tool
        is available.
      - In cases where the default authselect profile does not cover a specific demand,
        a custom authselect profile is recommended.
      success_msg:
      - authselect integrity check passed

  - name: Prevent Login to Accounts With Empty Password - Get authselect current features
    ansible.builtin.shell:
      cmd: authselect current | tail -n+3 | awk '{ print $2 }'
    register: result_authselect_features
    changed_when: false
    check_mode: false
    when:
    - result_authselect_check_cmd is success

  - name: Prevent Login to Accounts With Empty Password - Ensure "without-nullok"
      feature is enabled using authselect tool
    ansible.builtin.command:
      cmd: authselect enable-feature without-nullok
    register: result_authselect_enable_feature_cmd
    when:
    - result_authselect_check_cmd is success
    - result_authselect_features.stdout is not search("without-nullok")

  - name: Prevent Login to Accounts With Empty Password - Ensure authselect changes
      are applied
    ansible.builtin.command:
      cmd: authselect apply-changes -b
    when:
    - result_authselect_enable_feature_cmd is not skipped
    - result_authselect_enable_feature_cmd is success
  when:
  - '"kernel" in ansible_facts.packages'
  - result_authselect_present.stat.exists
  tags:
  - CJIS-5.5.2
  - DISA-STIG-RHEL-08-020331
  - DISA-STIG-RHEL-08-020332
  - NIST-800-171-3.1.1
  - NIST-800-171-3.1.5
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.3
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.1
  - configure_strategy
  - high_severity
  - low_complexity
  - medium_disruption
  - no_empty_passwords
  - no_reboot_needed

- name: Prevent Login to Accounts With Empty Password - Remediate directly editing
    PAM files
  ansible.builtin.replace:
    dest: '{{ item }}'
    regexp: nullok
  loop:
  - /etc/pam.d/system-auth
  - /etc/pam.d/password-auth
  when:
  - '"kernel" in ansible_facts.packages'
  - not result_authselect_present.stat.exists
  tags:
  - CJIS-5.5.2
  - DISA-STIG-RHEL-08-020331
  - DISA-STIG-RHEL-08-020332
  - NIST-800-171-3.1.1
  - NIST-800-171-3.1.5
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(a)
  - NIST-800-53-IA-5(c)
  - PCI-DSS-Req-8.2.3
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.1
  - configure_strategy
  - high_severity
  - low_complexity
  - medium_disruption
  - no_empty_passwords
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="no_empty_passwords" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
        mode: 0644
        path: /etc/pam.d/password-auth
        overwrite: true
      - contents:
          source: data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
        mode: 0644
        path: /etc/pam.d/system-auth
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_empty_passwords:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_empty_passwords_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_empty_passwords_etc_shadow" selected="false" severity="high">
                <xccdf-1.2:title>Ensure There Are No Accounts With Blank or Null Passwords</xccdf-1.2:title>
                <xccdf-1.2:description>Check the "/etc/shadow" file for blank passwords with the
following command:
<html:pre>$ sudo awk -F: '!$2 {print $1}' /etc/shadow</html:pre>
If the command returns any results, this is a finding.
Configure all accounts on the system to have a password or lock
the account with the following commands:
Perform a password reset:
<html:pre>$ sudo passwd [username]</html:pre>
Lock an account:
<html:pre>$ sudo passwd -l [username]</html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">Note that this rule is not applicable for systems running within a container. Having user with empty password within a container is not considered a risk, because it should not be possible to directly login into a container anyway.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6.1(iv)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010121</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-251706r1017359_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If an account has an empty password, anyone could log in and
run commands with the privileges of that account. Accounts with
empty passwords should never be used in operational environments.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix id="no_empty_passwords_etc_shadow" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

readarray -t users_with_empty_pass &lt; &lt;(awk -F: '!$2 {print $1}' /etc/shadow)

for user_with_empty_pass in "${users_with_empty_pass[@]}"
do
    passwd -l $user_with_empty_pass
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="no_empty_passwords_etc_shadow" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010121
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.2
  - high_severity
  - low_complexity
  - low_disruption
  - no_empty_passwords_etc_shadow
  - no_reboot_needed
  - restrict_strategy

- name: Collect users with no password
  ansible.builtin.command: |
    awk -F: '!$2 {print $1}' /etc/shadow
  register: users_nopasswd
  changed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010121
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.2
  - high_severity
  - low_complexity
  - low_disruption
  - no_empty_passwords_etc_shadow
  - no_reboot_needed
  - restrict_strategy

- name: Lock users with no password
  ansible.builtin.command: |
    passwd -l {{ item }}
  with_items: '{{ users_nopasswd.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - users_nopasswd is not skipped and users_nopasswd.stdout_lines | length &gt; 0
  tags:
  - DISA-STIG-RHEL-08-010121
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.2
  - high_severity
  - low_complexity
  - low_disruption
  - no_empty_passwords_etc_shadow
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_empty_passwords_etc_shadow:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_empty_passwords_etc_shadow_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_forward_files" selected="false" severity="medium">
                <xccdf-1.2:title>Verify No .forward Files Exist</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>.forward</html:code> file specifies an email address to forward the user's mail to.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.2.9</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Use of the <html:code>.forward</html:code> file poses a security risk in that sensitive data may
be inadvertently transferred outside the organization. The .forward file
also poses a risk as it can be used to execute commands that may perform
unintended actions.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_forward_files:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_forward_files_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_legacy_plus_entries_etc_group" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure there are no legacy + NIS entries in /etc/group</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>+</html:code> character in <html:code>/etc/group</html:code> file marks a place where
entries from a network information service (NIS) should be directly inserted.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Using this method to include entries into <html:code>/etc/group</html:code> is considered legacy
and should be avoided. These entries may provide a way for an attacker
to gain access to the system.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="no_legacy_plus_entries_etc_group" system="urn:xccdf:fix:script:sh">
if grep -q '^\+' /etc/group; then
# backup old file to /etc/group-
	cp /etc/group /etc/group-
	sed -i '/^\+.*$/d' /etc/group
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="no_legacy_plus_entries_etc_group" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Ensure there are no legacy + NIS entries in /etc/group - Backup the Old /etc/group
    File
  ansible.builtin.copy:
    src: /etc/group
    dest: /etc/group-
    remote_src: true
  tags:
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_legacy_plus_entries_etc_group
  - no_reboot_needed
  - restrict_strategy

- name: Ensure there are no legacy + NIS entries in /etc/group - Remove Lines Starting
    with + From /etc/group
  ansible.builtin.lineinfile:
    regexp: ^\+.*$
    state: absent
    path: /etc/group
  tags:
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_legacy_plus_entries_etc_group
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_legacy_plus_entries_etc_group:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_legacy_plus_entries_etc_group_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_legacy_plus_entries_etc_passwd" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure there are no legacy + NIS entries in /etc/passwd</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>+</html:code> character in <html:code>/etc/passwd</html:code> file marks a place where
entries from a network information service (NIS) should be directly inserted.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Using this method to include entries into <html:code>/etc/passwd</html:code> is considered legacy
and should be avoided. These entries may provide a way for an attacker
to gain access to the system.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="no_legacy_plus_entries_etc_passwd" system="urn:xccdf:fix:script:sh">
if grep -q '^\+' /etc/passwd; then
# backup old file to /etc/passwd-
	cp /etc/passwd /etc/passwd-
	sed -i '/^\+.*$/d' /etc/passwd
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="no_legacy_plus_entries_etc_passwd" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Ensure there are no legacy + NIS entries in /etc/passwd - Backup the Old /etc/passwd
    File
  ansible.builtin.copy:
    src: /etc/passwd
    dest: /etc/passwd-
    remote_src: true
  tags:
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_legacy_plus_entries_etc_passwd
  - no_reboot_needed
  - restrict_strategy

- name: Ensure there are no legacy + NIS entries in /etc/passwd - Remove Lines Starting
    with + From /etc/passwd
  ansible.builtin.lineinfile:
    regexp: ^\+.*$
    state: absent
    path: /etc/passwd
  tags:
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_legacy_plus_entries_etc_passwd
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_legacy_plus_entries_etc_passwd:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_legacy_plus_entries_etc_passwd_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_legacy_plus_entries_etc_shadow" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure there are no legacy + NIS entries in /etc/shadow</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>+</html:code> character in <html:code>/etc/shadow</html:code> file marks a place where
entries from a network information service (NIS) should be directly inserted.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Using this method to include entries into <html:code>/etc/shadow</html:code> is considered legacy
and should be avoided. These entries may provide a way for an attacker
to gain access to the system.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="no_legacy_plus_entries_etc_shadow" system="urn:xccdf:fix:script:sh">
if grep -q '^\+' /etc/shadow; then
# backup old file to /etc/shadow-
	cp /etc/shadow /etc/shadow-
	sed -i '/^\+.*$/d' /etc/shadow
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="no_legacy_plus_entries_etc_shadow" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Ensure there are no legacy + NIS entries in /etc/shadow - Backup the Old /etc/shadow
    File
  ansible.builtin.copy:
    src: /etc/shadow
    dest: /etc/shadow-
    remote_src: true
  tags:
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_legacy_plus_entries_etc_shadow
  - no_reboot_needed
  - restrict_strategy

- name: Ensure there are no legacy + NIS entries in /etc/shadow - Remove Lines Starting
    with + From /etc/shadow
  ansible.builtin.lineinfile:
    regexp: ^\+.*$
    state: absent
    path: /etc/shadow
  tags:
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_legacy_plus_entries_etc_shadow
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_legacy_plus_entries_etc_shadow:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_legacy_plus_entries_etc_shadow_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_netrc_files" selected="false" severity="medium">
                <xccdf-1.2:title>Verify No netrc Files Exist</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>.netrc</html:code> files contain login information
used to auto-login into FTP servers and reside in the user's home
directory. These files may contain unencrypted passwords to
remote FTP servers making them susceptible to access by unauthorized
users and should not be used.  Any <html:code>.netrc</html:code> files should be removed.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(h)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(7)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.2.9</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Unencrypted passwords for remote FTP servers may be stored in <html:code>.netrc</html:code>
files.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_netrc_files:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_netrc_files_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_rhost_files" selected="false" severity="medium">
                <xccdf-1.2:title>Verify No .rhost Files Exist</xccdf-1.2:title>
                <xccdf-1.2:description>Local system users should not have a <html:code>.rhost</html:code> file in their home directory.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">Automatic remediation of this rule is not available due to the unique
requirements of each system. Any .rhost files should be investigated
and removed manually.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.2.9</xccdf-1.2:reference>
                <xccdf-1.2:rationale>User configuration files with excessive or incorrect access may enable malicious users
to steal or modify other users' data or to gain another user's system privileges.
The <html:code>.rhost</html:code> file provides the "remote authentication" database for the rcp, rlogin, and
rsh commands and the rcmd() function. These files bypass the standard
password-based user authentication mechanism. They specify remote hosts and
users that are considered trusted (i.e. are allowed to access the local system
without supplying a password).</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_rhost_files:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_rhost_files_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_root_logins">
              <xccdf-1.2:title>Restrict Root Logins</xccdf-1.2:title>
              <xccdf-1.2:description>Direct root logins should be allowed only for emergency use.
In normal situations, the administrator should access the system
via a unique unprivileged account, and then use <html:code>su</html:code> or <html:code>sudo</html:code> to execute
privileged commands. Discouraging administrators from accessing the
root account directly ensures an audit trail in organizations with
multiple administrators. Locking down the channels through which
root can connect directly also reduces opportunities for
password-guessing against the root account. The <html:code>login</html:code> program
uses the file <html:code>/etc/securetty</html:code> to determine which interfaces
should allow root logins.

The virtual devices <html:code>/dev/console</html:code>
and <html:code>/dev/tty*</html:code> represent the system consoles (accessible via
the Ctrl-Alt-F1 through Ctrl-Alt-F6 keyboard sequences on a default
installation). The default securetty file also contains <html:code>/dev/vc/*</html:code>.
These are likely to be deprecated in most environments, but may be retained
for compatibility. Root should also be prohibited from connecting
via network protocols. Other sections of this document
include guidance describing how to prevent root from logging in via SSH.</xccdf-1.2:description>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_pam_wheel_group_for_su" type="string">
                <xccdf-1.2:title>Group Name Used by pam_wheel Group Parameter</xccdf-1.2:title>
                <xccdf-1.2:description>pam_wheel module has a parameter called group, which controls which groups
can access the su command.
This variable holds the valid value for the parameter.</xccdf-1.2:description>
                <xccdf-1.2:value>sugroup</xccdf-1.2:value>
                <xccdf-1.2:value selector="cis">sugroup</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_no_uid_except_zero" selected="false" severity="high">
                <xccdf-1.2:title>Verify Only Root Has UID 0</xccdf-1.2:title>
                <xccdf-1.2:description>If any account other than root has a UID of 0, this misconfiguration should
be investigated and the accounts other than root should be removed, locked
or have their UID changed.
<html:br/>
If the account is associated with system commands or applications the UID
should be changed to one greater than "0" but less than "1000."
Otherwise assign a UID greater than "1000" that has not already been
assigned.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(5)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-4(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040200</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230534r1017296_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>An account has root authority if it has a UID of 0. Multiple accounts
with a UID of 0 afford more opportunity for potential intruders to
guess a password for a privileged account. Proper configuration of
sudo is recommended to afford multiple system administrators
access to root privileges in an accountable manner.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix id="accounts_no_uid_except_zero" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

awk -F: '$3 == 0 &amp;&amp; $1 != "root" { print $1 }' /etc/passwd | xargs --no-run-if-empty --max-lines=1 passwd -l

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_no_uid_except_zero" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040200
  - NIST-800-171-3.1.1
  - NIST-800-171-3.1.5
  - NIST-800-53-AC-6(5)
  - NIST-800-53-IA-2
  - NIST-800-53-IA-4(b)
  - PCI-DSS-Req-8.5
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.1
  - accounts_no_uid_except_zero
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy

- name: Get all /etc/passwd file entries
  ansible.builtin.getent:
    database: passwd
    split: ':'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040200
  - NIST-800-171-3.1.1
  - NIST-800-171-3.1.5
  - NIST-800-53-AC-6(5)
  - NIST-800-53-IA-2
  - NIST-800-53-IA-4(b)
  - PCI-DSS-Req-8.5
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.1
  - accounts_no_uid_except_zero
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy

- name: Lock the password of the user accounts other than root with uid 0
  ansible.builtin.command: passwd -l {{ item.key }}
  loop: '{{ getent_passwd | dict2items | rejectattr(''key'', ''equalto'', ''root'')
    | list }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.value.1  == '0'
  tags:
  - DISA-STIG-RHEL-08-040200
  - NIST-800-171-3.1.1
  - NIST-800-171-3.1.5
  - NIST-800-53-AC-6(5)
  - NIST-800-53-IA-2
  - NIST-800-53-IA-4(b)
  - PCI-DSS-Req-8.5
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.1
  - accounts_no_uid_except_zero
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_no_uid_except_zero:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_root_gid_zero" selected="false" severity="high">
                <xccdf-1.2:title>Verify Root Has A Primary GID 0</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>root</html:code> user should have a primary group of 0.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.2.2</xccdf-1.2:reference>
                <xccdf-1.2:rationale>To help ensure that root-owned files are not inadvertently exposed to other users.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_root_gid_zero:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_root_gid_zero_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ensure_pam_wheel_group_empty" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty</xccdf-1.2:title>
                <xccdf-1.2:description>Ensure that the group <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_pam_wheel_group_for_su" use="legacy"/></html:code> referenced by
<html:code>var_pam_wheel_group_for_su</html:code> variable and used as value for the <html:code>pam_wheel.so</html:code>
<html:code>group</html:code> option exists and has no members. This empty group used by
<html:code>pam_wheel.so</html:code> in <html:code>/etc/pam.d/su</html:code> ensures that no user can run commands with
altered privileges through the <html:code>su</html:code> command.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">Note that this rule just ensures the group exists and has no members. This rule does not
configure <html:code>pam_wheel.so</html:code> module. The <html:code>pam_wheel.so</html:code> module configuration is
accomplished by <html:code>use_pam_wheel_group_for_su</html:code> rule.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.2.7</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>su</html:code> program allows to run commands with a substitute user and group ID.
It is commonly used to run commands as the root user.
Limiting access to such command is considered a good security practice.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix id="ensure_pam_wheel_group_empty" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_pam_wheel_group_for_su='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_pam_wheel_group_for_su" use="legacy"/>'


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to groupadd command to avoid the issue with the command not being found.
if ! grep -q "^${var_pam_wheel_group_for_su}:[^:]*:[^:]*:[^:]*" /etc/group; then
    /usr/sbin/groupadd ${var_pam_wheel_group_for_su}
fi

# group must be empty
gpasswd -M '' ${var_pam_wheel_group_for_su}

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="ensure_pam_wheel_group_empty" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - ensure_pam_wheel_group_empty
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_pam_wheel_group_for_su # promote to variable
  set_fact:
    var_pam_wheel_group_for_su: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_pam_wheel_group_for_su" use="legacy"/>
  tags:
    - always

- name: Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty
    - Ensure {{ var_pam_wheel_group_for_su }} Group Exists
  ansible.builtin.group:
    name: '{{ var_pam_wheel_group_for_su }}'
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - ensure_pam_wheel_group_empty
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty
    - Ensure {{ var_pam_wheel_group_for_su }} Group is Empty
  ansible.builtin.lineinfile:
    path: /etc/group
    regexp: ^({{ var_pam_wheel_group_for_su }}:[^:]+:[0-9]+:).*$
    line: \1
    backrefs: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - ensure_pam_wheel_group_empty
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_pam_wheel_group_for_su:var:1" value-id="xccdf_org.ssgproject.content_value_var_pam_wheel_group_for_su"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ensure_pam_wheel_group_empty:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ensure_pam_wheel_group_empty_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ensure_root_password_configured" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure Authentication Required for Single User Mode</xccdf-1.2:title>
                <xccdf-1.2:description>Single user mode is used for recovery when the system detects an
issue during boot or by manual selection from the bootloader.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.2.4</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Requiring authentication in single user mode prevents an unauthorized
user from rebooting the system into single user to gain root privileges
without credentials.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ensure_root_password_configured:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ensure_root_password_configured_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_groups_no_zero_gid_except_root" selected="false" severity="high">
                <xccdf-1.2:title>Verify Only Group Root Has GID 0</xccdf-1.2:title>
                <xccdf-1.2:description>If any group other than root has a GID of 0, this misconfiguration should
be investigated and the groups other than root should be removed or have
their GID changed.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">This rule doesn't come with a remediation. The removal of groups from a system
or reassigning the GID is considered too disruptive.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.2.3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Ensuring that only the <html:code>root</html:code> group has a GID of 0 helps prevent
root group owned files from becoming accidentally accessible to
non-privileged users.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-groups_no_zero_gid_except_root:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-groups_no_zero_gid_except_root_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_direct_root_logins" selected="false" severity="medium">
                <xccdf-1.2:title>Direct root Logins Not Allowed</xccdf-1.2:title>
                <xccdf-1.2:description>To further limit access to the <html:code>root</html:code> account, administrators
can disable root logins at the console by editing the <html:code>/etc/securetty</html:code> file.
This file lists all devices the root user is allowed to login to. If the file does
not exist at all, the root user can login through any communication device on the
system, whether via the console or via a raw network interface. This is dangerous
as user can login to the system as root via Telnet, which sends the password in
plain text over the network. By default, AlmaLinux OS 8's
<html:code>/etc/securetty</html:code> file only allows the root user to login at the console
physically attached to the system. To prevent root from logging in, remove the
contents of this file. To prevent direct root logins, remove the contents of this
file by typing the following command:
<html:pre>
$ sudo echo &gt; /etc/securetty
</html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">This rule only checks the <html:code>/etc/securetty</html:code> file existence and its content.
If you need to restrict user access using the <html:code>/etc/securetty</html:code> file, make sure
the <html:code>pam_securetty.so</html:code> PAM module is properly enabled in relevant PAM files.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R33</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.6</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Disabling direct root logins ensures proper accountability and multifactor
authentication to privileged accounts. Users will first login, then escalate
to privileged (root) access via su / sudo. This is required for FISMA Low
and FISMA Moderate systems.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix id="no_direct_root_logins" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

echo &gt; /etc/securetty

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="no_direct_root_logins" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.1
  - NIST-800-171-3.1.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2
  - PCI-DSSv4-8.6
  - PCI-DSSv4-8.6.1
  - low_complexity
  - low_disruption
  - medium_severity
  - no_direct_root_logins
  - no_reboot_needed
  - restrict_strategy

- name: Direct root Logins Not Allowed
  ansible.builtin.copy:
    dest: /etc/securetty
    content: ''
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.1
  - NIST-800-171-3.1.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2
  - PCI-DSSv4-8.6
  - PCI-DSSv4-8.6.1
  - low_complexity
  - low_disruption
  - medium_severity
  - no_direct_root_logins
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="no_direct_root_logins" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,
        mode: 0600
        path: /etc/securetty
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_direct_root_logins:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_direct_root_logins_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_invalid_shell_accounts_unlocked" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Non-Interactive Accounts Are Locked</xccdf-1.2:title>
                <xccdf-1.2:description>Accounts meant for non-interactive purposes should be locked to prevent
unauthorized access. Accounts with non-standard shells (those not defined in
<html:code>/etc/shells</html:code>) should be locked using <html:code>usermod -L</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">Automatic remediation of this control is not recommended. Locking system accounts
could be highly disruptive.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.2.8</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Locking non-interactive accounts improves security by preventing potential
misuse. While many systems configure these accounts with invalid strings,
setting the shell field to <html:code>nologin</html:code> is also suggested</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_invalid_shell_accounts_unlocked:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_password_auth_for_systemaccounts" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure that System Accounts Are Locked</xccdf-1.2:title>
                <xccdf-1.2:description>Some accounts are not associated with a human user of the system, and exist to perform some
administrative functions. An attacker should not be able to log into these accounts.
<html:br/><html:br/>
System accounts are those user accounts with a user ID less than <html:code>1000</html:code>.
If any system account other than <html:code>root</html:code>, <html:code>halt</html:code>, <html:code>sync</html:code>, <html:code>shutdown</html:code>
and <html:code>nfsnobody</html:code> has an unlocked password, disable it with the command:
<html:pre>$ sudo usermod -L <html:i>account</html:i></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.2.7</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Disabling authentication for default system accounts makes it more difficult for attackers
to make use of them to compromise a system.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="no_password_auth_for_systemaccounts" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

readarray -t systemaccounts &lt; &lt;(awk -F: \
  '($3 &lt; 1000 &amp;&amp; $3 != root &amp;&amp; $3 != halt &amp;&amp; $3 != sync &amp;&amp; $3 != shutdown \
  &amp;&amp; $3 != nfsnobody) { print $1 }' /etc/passwd)

for systemaccount in "${systemaccounts[@]}"; do
    usermod -L "$systemaccount"
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="no_password_auth_for_systemaccounts" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.2
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_password_auth_for_systemaccounts
  - no_reboot_needed
  - restrict_strategy

- name: Ensure that System Accounts Are Locked - Get All Local Users From /etc/passwd
  ansible.builtin.getent:
    database: passwd
    split: ':'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.2
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_password_auth_for_systemaccounts
  - no_reboot_needed
  - restrict_strategy

- name: Ensure that System Accounts Are Locked - Create local_users Variable From
    getent_passwd Facts
  ansible.builtin.set_fact:
    local_users: '{{ ansible_facts.getent_passwd | dict2items }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.2
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_password_auth_for_systemaccounts
  - no_reboot_needed
  - restrict_strategy

- name: Ensure that System Accounts Are Locked - Lock System Accounts
  ansible.builtin.user:
    name: '{{ item.key }}'
    password_lock: true
  loop: '{{ local_users }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.value[1]|int &lt; 1000
  - item.key not in ['root', 'halt', 'sync', 'shutdown', 'nfsnobody']
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.2
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_password_auth_for_systemaccounts
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_password_auth_for_systemaccounts:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_password_auth_for_systemaccounts_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_root_webbrowsing" selected="false" severity="unknown">
                <xccdf-1.2:title>Restrict Web Browser Use for Administrative Accounts</xccdf-1.2:title>
                <xccdf-1.2:description>Enforce policy requiring administrative accounts use web browsers only for
local service administration.</xccdf-1.2:description>
                <xccdf-1.2:rationale>If a browser vulnerability is exploited while running with administrative privileges,
the entire system could be compromised. Specific exceptions for local service
administration should be documented in site-defined policy.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_root_webbrowsing_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_shelllogin_for_systemaccounts" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure that System Accounts Do Not Run a Shell Upon Login</xccdf-1.2:title>
                <xccdf-1.2:description>Some accounts are not associated with a human user of the system, and exist to perform some
administrative functions. Should an attacker be able to log into these accounts, they should
not be granted access to a shell.
<html:br/><html:br/>
The login shell for each local account is stored in the last field of each line in
<html:code>/etc/passwd</html:code>. System accounts are those user accounts with a user ID less than
<html:code>1000</html:code>. The user ID is stored in the third field. If any system account
other than <html:code>root</html:code> has a login shell, disable it with the command:
<html:pre>$ sudo usermod -s /sbin/nologin <html:i>account</html:i></html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="functionality">Do not perform the steps in this section on the root account. Doing so might cause the
system to become inaccessible.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6.1(iv)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1491</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.2.7</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Ensuring shells are not given to system accounts upon login makes it more difficult for
attackers to make use of system accounts.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="no_shelllogin_for_systemaccounts" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

readarray -t systemaccounts &lt; &lt;(awk -F: '($3 &lt; 1000 &amp;&amp; $1 != "root" \
  &amp;&amp; $7 != "\/sbin\/shutdown" &amp;&amp; $7 != "\/sbin\/halt" &amp;&amp; $7 != "\/bin\/sync") \
  { print $1 }' /etc/passwd)

for systemaccount in "${systemaccounts[@]}"; do
    usermod -s /sbin/nologin "$systemaccount"
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="no_shelllogin_for_systemaccounts" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.2
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - no_shelllogin_for_systemaccounts
  - restrict_strategy

- name: Ensure that System Accounts Do Not Run a Shell Upon Login - Get All Local
    Users From /etc/passwd
  ansible.builtin.getent:
    database: passwd
    split: ':'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.2
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - no_shelllogin_for_systemaccounts
  - restrict_strategy

- name: Ensure that System Accounts Do Not Run a Shell Upon Login - Create local_users
    Variable From getent_passwd Facts
  ansible.builtin.set_fact:
    local_users: '{{ ansible_facts.getent_passwd | dict2items }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.2
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - no_shelllogin_for_systemaccounts
  - restrict_strategy

- name: Ensure that System Accounts Do Not Run a Shell Upon Login -  Disable Login
    Shell for System Accounts
  ansible.builtin.user:
    name: '{{ item.key }}'
    shell: /sbin/nologin
  loop: '{{ local_users }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.key not in ['root']
  - item.value[1]|int &lt; 1000
  - item.value[5] not in ['/sbin/shutdown', '/sbin/halt', '/bin/sync']
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.2
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - no_shelllogin_for_systemaccounts
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_shelllogin_for_systemaccounts:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_shelllogin_for_systemaccounts_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_restrict_serial_port_logins" selected="false" severity="medium">
                <xccdf-1.2:title>Restrict Serial Port Root Logins</xccdf-1.2:title>
                <xccdf-1.2:description>To restrict root logins on serial ports,
ensure lines of this form do not appear in <html:code>/etc/securetty</html:code>:
<html:pre>ttyS0
ttyS1</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Preventing direct root login to serial port interfaces
helps ensure accountability for actions taken on the systems
using the root account.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix id="restrict_serial_port_logins" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

sed -i '/ttyS/d' /etc/securetty

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="restrict_serial_port_logins" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.1
  - NIST-800-171-3.1.5
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(a)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_serial_port_logins
  - restrict_strategy

- name: Restrict Serial Port Root Logins
  ansible.builtin.lineinfile:
    dest: /etc/securetty
    regexp: ttyS[0-9]
    state: absent
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.1
  - NIST-800-171-3.1.5
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(a)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_serial_port_logins
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-restrict_serial_port_logins:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-restrict_serial_port_logins_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_root_path_default" selected="false" severity="unknown">
                <xccdf-1.2:title>Root Path Must Be Vendor Default</xccdf-1.2:title>
                <xccdf-1.2:description>Assuming root shell is bash, edit the following files:
<html:pre>~/.profile</html:pre>
<html:pre>~/.bashrc</html:pre>
Change any <html:code>PATH</html:code> variables to the vendor default for root and remove any
empty <html:code>PATH</html:code> entries or references to relative paths.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-2</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The root account's executable search path must be the vendor default, and must
contain only absolute paths.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-root_path_default_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_securetty_root_login_console_only" selected="false" severity="medium">
                <xccdf-1.2:title>Restrict Virtual Console Root Logins</xccdf-1.2:title>
                <xccdf-1.2:description>To restrict root logins through the (deprecated) virtual console devices,
ensure lines of this form do not appear in <html:code>/etc/securetty</html:code>:
<html:pre>vc/1
vc/2
vc/3
vc/4</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000324-GPOS-00125</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.6</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Preventing direct root login to virtual console devices
helps ensure accountability for actions taken on the system
using the root account.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix id="securetty_root_login_console_only" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

sed -i '/^vc\/[0-9]/d' /etc/securetty

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="securetty_root_login_console_only" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.1
  - NIST-800-171-3.1.5
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-8.6
  - PCI-DSSv4-8.6.1
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - securetty_root_login_console_only

- name: Restrict Virtual Console Root Logins
  ansible.builtin.lineinfile:
    dest: /etc/securetty
    regexp: ^vc/[0-9]
    state: absent
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.1
  - NIST-800-171-3.1.5
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-8.6
  - PCI-DSSv4-8.6.1
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - securetty_root_login_console_only
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-securetty_root_login_console_only:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-securetty_root_login_console_only_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_use_pam_wheel_for_su" selected="false" severity="medium">
                <xccdf-1.2:title>Enforce usage of pam_wheel for su authentication</xccdf-1.2:title>
                <xccdf-1.2:description>To ensure that only users who are members of the <html:code>wheel</html:code> group can
run commands with altered privileges through the <html:code>su</html:code> command, make
sure that the following line exists in the file <html:code>/etc/pam.d/su</html:code>:
<html:pre>auth required pam_wheel.so use_uid</html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">Members of "wheel" or GID 0 groups are checked by default if the group option is not set
for pam_wheel.so module. Therefore, members of these groups should be manually checked or
a different group should be informed according to the site policy.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000373-GPOS-00156</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000312-GPOS-00123</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>su</html:code> program allows to run commands with a substitute user and
group ID. It is commonly used to run commands as the root user. Limiting
access to such command is considered a good security practice.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="use_pam_wheel_for_su" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q pam; then

declare -a VALUES=()
declare -a VALUE_NAMES=()
declare -a ARGS=()
declare -a NEW_ARGS=()
declare -a DEL_ARGS=()




VALUES+=("")
VALUE_NAMES+=("")
ARGS+=("use_uid")
NEW_ARGS+=("use_uid")


for idx in "${!VALUES[@]}"
do
    if [ -e "/etc/pam.d/su" ] ; then
        valueRegex="${VALUES[$idx]}" defaultValue="${VALUES[$idx]}"
        # non-empty values need to be preceded by an equals sign
        [ -n "${valueRegex}" ] &amp;&amp; valueRegex="=${valueRegex}"
        # add an equals sign to non-empty values
        [ -n "${defaultValue}" ] &amp;&amp; defaultValue="=${defaultValue}"

        # fix the value for 'option' if one exists but does not match 'valueRegex'
        if grep -q -P "^\\s*auth\\s+required\\s+pam_wheel.so(\\s.+)?\\s+${VALUE_NAMES[$idx]}(?"'!'"${valueRegex}(\\s|\$))" &lt; "/etc/pam.d/su" ; then
            sed --follow-symlinks -i -E -e "s/^(\\s*auth\\s+required\\s+pam_wheel.so(\\s.+)?\\s)${VALUE_NAMES[$idx]}=[^[:space:]]*/\\1${VALUE_NAMES[$idx]}${defaultValue}/" "/etc/pam.d/su"

        # add 'option=default' if option is not set
        elif grep -q -E "^\\s*auth\\s+required\\s+pam_wheel.so" &lt; "/etc/pam.d/su" &amp;&amp;
                grep    -E "^\\s*auth\\s+required\\s+pam_wheel.so" &lt; "/etc/pam.d/su" | grep -q -E -v "\\s${VALUE_NAMES[$idx]}(=|\\s|\$)" ; then

            sed --follow-symlinks -i -E -e "s/^(\\s*auth\\s+required\\s+pam_wheel.so[^\\n]*)/\\1 ${VALUE_NAMES[$idx]}${defaultValue}/" "/etc/pam.d/su"
        # add a new entry if none exists
        elif ! grep -q -P "^\\s*auth\\s+required\\s+pam_wheel.so(\\s.+)?\\s+${VALUE_NAMES[$idx]}${valueRegex}(\\s|\$)" &lt; "/etc/pam.d/su" ; then
            echo "auth required pam_wheel.so ${VALUE_NAMES[$idx]}${defaultValue}" &gt;&gt; "/etc/pam.d/su"
        fi
    else
        echo "/etc/pam.d/su doesn't exist" &gt;&amp;2
    fi
done

for idx in "${!ARGS[@]}"
do
    if ! grep -q -P "^\s*auth\s+required\s+pam_wheel.so.*\s+${ARGS[$idx]}\s*$" /etc/pam.d/su ; then
        sed --follow-symlinks -i -E -e "s/^\\s*auth\\s+required\\s+pam_wheel.so.*\$/&amp; ${NEW_ARGS[$idx]}/" /etc/pam.d/su
        if [ -n "${DEL_ARGS[$idx]}" ]; then
            sed --follow-symlinks -i -E -e "s/\s+${DEL_ARGS[$idx]}\S+\s+/ /g" /etc/pam.d/su
        fi
    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-use_pam_wheel_for_su:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-use_pam_wheel_for_su_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_use_pam_wheel_group_for_su" selected="false" severity="medium">
                <xccdf-1.2:title>Enforce Usage of pam_wheel with Group Parameter for su Authentication</xccdf-1.2:title>
                <xccdf-1.2:description>To ensure that only users who are members of the group set in the <html:code>group</html:code> option of
<html:code>pam_wheel.so</html:code> module can run commands with altered privileges through the <html:code>su</html:code>
command, make sure that the following line exists in the file <html:code>/etc/pam.d/su</html:code>:
<html:pre>auth required pam_wheel.so use_uid group=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_pam_wheel_group_for_su" use="legacy"/></html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">Note that <html:code>ensure_pam_wheel_group_empty</html:code> rule complements this requirement by
ensuring the referenced group exists and has no members.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.2.7</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>su</html:code> program allows to run commands with a substitute user and group ID.
It is commonly used to run commands as the root user.
Limiting access to such command is considered a good security practice.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="use_pam_wheel_group_for_su" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q pam; then

declare -a VALUES=()
declare -a VALUE_NAMES=()
declare -a ARGS=()
declare -a NEW_ARGS=()
declare -a DEL_ARGS=()






var_pam_wheel_group_for_su='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_pam_wheel_group_for_su" use="legacy"/>'

VALUES+=("$var_pam_wheel_group_for_su")
VALUE_NAMES+=("group")
ARGS+=("")
NEW_ARGS+=("")

VALUES+=("")
VALUE_NAMES+=("")
ARGS+=("use_uid")
NEW_ARGS+=("use_uid")


for idx in "${!VALUES[@]}"
do
    if [ -e "/etc/pam.d/su" ] ; then
        valueRegex="${VALUES[$idx]}" defaultValue="${VALUES[$idx]}"
        # non-empty values need to be preceded by an equals sign
        [ -n "${valueRegex}" ] &amp;&amp; valueRegex="=${valueRegex}"
        # add an equals sign to non-empty values
        [ -n "${defaultValue}" ] &amp;&amp; defaultValue="=${defaultValue}"

        # fix the value for 'option' if one exists but does not match 'valueRegex'
        if grep -q -P "^\\s*auth\\s+required\\s+pam_wheel.so(\\s.+)?\\s+${VALUE_NAMES[$idx]}(?"'!'"${valueRegex}(\\s|\$))" &lt; "/etc/pam.d/su" ; then
            sed --follow-symlinks -i -E -e "s/^(\\s*auth\\s+required\\s+pam_wheel.so(\\s.+)?\\s)${VALUE_NAMES[$idx]}=[^[:space:]]*/\\1${VALUE_NAMES[$idx]}${defaultValue}/" "/etc/pam.d/su"

        # add 'option=default' if option is not set
        elif grep -q -E "^\\s*auth\\s+required\\s+pam_wheel.so" &lt; "/etc/pam.d/su" &amp;&amp;
                grep    -E "^\\s*auth\\s+required\\s+pam_wheel.so" &lt; "/etc/pam.d/su" | grep -q -E -v "\\s${VALUE_NAMES[$idx]}(=|\\s|\$)" ; then

            sed --follow-symlinks -i -E -e "s/^(\\s*auth\\s+required\\s+pam_wheel.so[^\\n]*)/\\1 ${VALUE_NAMES[$idx]}${defaultValue}/" "/etc/pam.d/su"
        # add a new entry if none exists
        elif ! grep -q -P "^\\s*auth\\s+required\\s+pam_wheel.so(\\s.+)?\\s+${VALUE_NAMES[$idx]}${valueRegex}(\\s|\$)" &lt; "/etc/pam.d/su" ; then
            echo "auth required pam_wheel.so ${VALUE_NAMES[$idx]}${defaultValue}" &gt;&gt; "/etc/pam.d/su"
        fi
    else
        echo "/etc/pam.d/su doesn't exist" &gt;&amp;2
    fi
done

for idx in "${!ARGS[@]}"
do
    if ! grep -q -P "^\s*auth\s+required\s+pam_wheel.so.*\s+${ARGS[$idx]}\s*$" /etc/pam.d/su ; then
        sed --follow-symlinks -i -E -e "s/^\\s*auth\\s+required\\s+pam_wheel.so.*\$/&amp; ${NEW_ARGS[$idx]}/" /etc/pam.d/su
        if [ -n "${DEL_ARGS[$idx]}" ]; then
            sed --follow-symlinks -i -E -e "s/\s+${DEL_ARGS[$idx]}\S+\s+/ /g" /etc/pam.d/su
        fi
    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_pam_wheel_group_for_su:var:1" value-id="xccdf_org.ssgproject.content_value_var_pam_wheel_group_for_su"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-use_pam_wheel_group_for_su:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-use_pam_wheel_group_for_su_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_accounts-session">
            <xccdf-1.2:title>Secure Session Configuration Files for Login Accounts</xccdf-1.2:title>
            <xccdf-1.2:description>When a user logs into a Unix account, the system
configures the user's session by reading a number of files. Many of
these files are located in the user's home directory, and may have
weak permissions as a result of user error or misconfiguration. If
an attacker can modify or even read certain types of account
configuration information, they can often gain full access to the
affected user's account. Therefore, it is important to test and
correct configuration file permissions for interactive accounts,
particularly those of privileged users such as root or system
administrators.</xccdf-1.2:description>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_accounts_fail_delay" type="number">
              <xccdf-1.2:title>Maximum login attempts delay</xccdf-1.2:title>
              <xccdf-1.2:description>Maximum time in seconds between fail login attempts before re-prompting.</xccdf-1.2:description>
              <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
              <xccdf-1.2:value selector="2">2</xccdf-1.2:value>
              <xccdf-1.2:value selector="3">3</xccdf-1.2:value>
              <xccdf-1.2:value selector="4">4</xccdf-1.2:value>
              <xccdf-1.2:value selector="5">5</xccdf-1.2:value>
              <xccdf-1.2:value>4</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_accounts_max_concurrent_login_sessions" type="number">
              <xccdf-1.2:title>Maximum concurrent login sessions</xccdf-1.2:title>
              <xccdf-1.2:description>Maximum number of concurrent sessions by a user</xccdf-1.2:description>
              <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
              <xccdf-1.2:value selector="10">10</xccdf-1.2:value>
              <xccdf-1.2:value selector="15">15</xccdf-1.2:value>
              <xccdf-1.2:value selector="20">20</xccdf-1.2:value>
              <xccdf-1.2:value selector="3">3</xccdf-1.2:value>
              <xccdf-1.2:value selector="5">5</xccdf-1.2:value>
              <xccdf-1.2:value>1</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_accounts_tmout" type="number">
              <xccdf-1.2:title>Account Inactivity Timeout (seconds)</xccdf-1.2:title>
              <xccdf-1.2:description>In an interactive shell, the value is interpreted as the
number of seconds to wait for input after issuing the primary prompt.
Bash terminates after waiting for that number of seconds if input does
not arrive.</xccdf-1.2:description>
              <xccdf-1.2:value selector="30_min">1800</xccdf-1.2:value>
              <xccdf-1.2:value selector="10_min">600</xccdf-1.2:value>
              <xccdf-1.2:value selector="15_min">900</xccdf-1.2:value>
              <xccdf-1.2:value selector="5_min">300</xccdf-1.2:value>
              <xccdf-1.2:value>600</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_user_initialization_files_regex" type="string">
              <xccdf-1.2:title>Interactive users initialization files</xccdf-1.2:title>
              <xccdf-1.2:description>'A regular expression describing a list of file names
for files that are sourced at login time for interactive users'</xccdf-1.2:description>
              <xccdf-1.2:value>^(\.bashrc|\.zshrc|\.cshrc|\.profile|\.bash_login|\.bash_profile)$</xccdf-1.2:value>
              <xccdf-1.2:value selector="all_dotfiles">^\.[\w\- ]+$</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_have_homedir_login_defs" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Home Directories are Created for New Users</xccdf-1.2:title>
              <xccdf-1.2:description>All local interactive user accounts, upon creation, should be assigned a home directory.
<html:br/><html:br/>
Configure the operating system to assign home directories to all new local interactive users by setting the <html:code>CREATE_HOME</html:code>
parameter in <html:code>/etc/login.defs</html:code> to <html:code>yes</html:code> as follows:
<html:br/><html:br/>
<html:pre>CREATE_HOME yes</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010760</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230324r1017135_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If local interactive users are not assigned a valid home directory, there is no place
for the storage and control of files they should own.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_shadow-utils_and_system_with_kernel"/>
              <xccdf-1.2:fix id="accounts_have_homedir_login_defs" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q shadow-utils &amp;&amp; rpm --quiet -q kernel ) ); then

if [ -e "/etc/login.defs" ] ; then
    
    LC_ALL=C sed -i "/^\s*CREATE_HOME\s\+/Id" "/etc/login.defs"
else
    touch "/etc/login.defs"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/login.defs"

cp "/etc/login.defs" "/etc/login.defs.bak"
# Insert before the line matching the regex '^\s*CREATE_HOME'.
line_number="$(LC_ALL=C grep -n "^\s*CREATE_HOME" "/etc/login.defs.bak" | LC_ALL=C sed 's/:.*//g')"
if [ -z "$line_number" ]; then
    # There was no match of '^\s*CREATE_HOME', insert at
    # the end of the file.
    printf '%s\n' "CREATE_HOME yes" &gt;&gt; "/etc/login.defs"
else
    head -n "$(( line_number - 1 ))" "/etc/login.defs.bak" &gt; "/etc/login.defs"
    printf '%s\n' "CREATE_HOME yes" &gt;&gt; "/etc/login.defs"
    tail -n "+$(( line_number ))" "/etc/login.defs.bak" &gt;&gt; "/etc/login.defs"
fi
# Clean up after ourselves.
rm "/etc/login.defs.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_have_homedir_login_defs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010760
  - accounts_have_homedir_login_defs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure new users receive home directories
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/login.defs
      create: true
      regexp: (?i)^\s*CREATE_HOME\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/login.defs
    ansible.builtin.lineinfile:
      path: /etc/login.defs
      create: true
      regexp: (?i)^\s*CREATE_HOME\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/login.defs
    ansible.builtin.lineinfile:
      path: /etc/login.defs
      create: true
      regexp: (?i)^\s*CREATE_HOME\s+
      line: CREATE_HOME yes
      state: present
  when: ( "shadow-utils" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - DISA-STIG-RHEL-08-010760
  - accounts_have_homedir_login_defs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_have_homedir_login_defs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_have_homedir_login_defs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure the Logon Failure Delay is Set Correctly in login.defs</xccdf-1.2:title>
              <xccdf-1.2:description>To ensure the logon failure delay controlled by <html:code>/etc/login.defs</html:code> is set properly,
add or correct the <html:code>FAIL_DELAY</html:code> setting in <html:code>/etc/login.defs</html:code> to read as follows:
<html:pre>FAIL_DELAY <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_fail_delay" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00226</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020310</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230378r1017189_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Increasing the time between a failed authentication attempt and re-prompting to
enter credentials helps to slow a single-threaded brute force attack.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_shadow-utils_and_system_with_kernel"/>
              <xccdf-1.2:fix id="accounts_logon_fail_delay" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q shadow-utils &amp;&amp; rpm --quiet -q kernel ) ); then

var_accounts_fail_delay='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_fail_delay" use="legacy"/>'


# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^FAIL_DELAY")

# shellcheck disable=SC2059
printf -v formatted_output "%s %s" "$stripped_key" "$var_accounts_fail_delay"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^FAIL_DELAY\\&gt;" "/etc/login.defs"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^FAIL_DELAY\\&gt;.*/$escaped_formatted_output/gi" "/etc/login.defs"
else
    if [[ -s "/etc/login.defs" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/login.defs" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/login.defs"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/login.defs"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_logon_fail_delay" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020310
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - accounts_logon_fail_delay
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
- name: XCCDF Value var_accounts_fail_delay # promote to variable
  set_fact:
    var_accounts_fail_delay: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_fail_delay" use="legacy"/>
  tags:
    - always

- name: Set accounts logon fail delay
  ansible.builtin.lineinfile:
    dest: /etc/login.defs
    regexp: ^FAIL_DELAY
    line: FAIL_DELAY {{ var_accounts_fail_delay }}
    create: true
  when: ( "shadow-utils" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - DISA-STIG-RHEL-08-020310
  - NIST-800-53-AC-7(b)
  - NIST-800-53-CM-6(a)
  - accounts_logon_fail_delay
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_fail_delay:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_fail_delay"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_logon_fail_delay:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_logon_fail_delay_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions" selected="false" severity="low">
              <xccdf-1.2:title>Limit the Number of Concurrent Login Sessions Allowed Per User</xccdf-1.2:title>
              <xccdf-1.2:description>Limiting the number of allowed users and sessions per user can limit risks related to Denial of
Service attacks. This addresses concurrent sessions for a single account and does not address
concurrent sessions by a single user via multiple accounts. To set the number of concurrent
sessions per user add the following line in <html:code>/etc/security/limits.conf</html:code> or
a file under <html:code>/etc/security/limits.d/</html:code>:
<html:pre>* hard maxlogins <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_max_concurrent_login_sessions" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000027-GPOS-00008</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020024</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230346r1069306_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Limiting simultaneous user logins can insulate the system from denial of service
problems caused by excessive logins. Automated login processes operating improperly or
maliciously may result in an exceptional number of simultaneous login sessions.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_pam_and_system_with_kernel"/>
              <xccdf-1.2:fix id="accounts_max_concurrent_login_sessions" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q pam &amp;&amp; rpm --quiet -q kernel ) ); then

var_accounts_max_concurrent_login_sessions='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_max_concurrent_login_sessions" use="legacy"/>'


if grep -q '^[^#]*\&lt;maxlogins\&gt;' /etc/security/limits.d/*.conf; then
	sed -i "/^[^#]*\&lt;maxlogins\&gt;/ s/maxlogins.*/maxlogins $var_accounts_max_concurrent_login_sessions/" /etc/security/limits.d/*.conf
elif grep -q '^[^#]*\&lt;maxlogins\&gt;' /etc/security/limits.conf; then
	sed -i "/^[^#]*\&lt;maxlogins\&gt;/ s/maxlogins.*/maxlogins $var_accounts_max_concurrent_login_sessions/" /etc/security/limits.conf
else
	echo "*	hard	maxlogins	$var_accounts_max_concurrent_login_sessions" &gt;&gt; /etc/security/limits.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_max_concurrent_login_sessions" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.2.2
  - DISA-STIG-RHEL-08-020024
  - NIST-800-53-AC-10
  - NIST-800-53-CM-6(a)
  - accounts_max_concurrent_login_sessions
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_accounts_max_concurrent_login_sessions # promote to variable
  set_fact:
    var_accounts_max_concurrent_login_sessions: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_max_concurrent_login_sessions" use="legacy"/>
  tags:
    - always

- name: Find /etc/security/limits.d files containing maxlogins configuration
  ansible.builtin.find:
    paths: /etc/security/limits.d
    contains: ^[\s]*\*[\s]+(?:(?:hard)|(?:-))[\s]+maxlogins
    patterns: '*.conf'
  register: maxlogins
  when: ( "pam" in ansible_facts.packages and "kernel" in ansible_facts.packages )
  tags:
  - CJIS-5.5.2.2
  - DISA-STIG-RHEL-08-020024
  - NIST-800-53-AC-10
  - NIST-800-53-CM-6(a)
  - accounts_max_concurrent_login_sessions
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy

- name: Limit the Number of Concurrent Login Sessions Allowed Per User in files from
    limits.d
  ansible.builtin.replace:
    dest: '{{ item.path }}'
    regexp: ^#?\*.*maxlogins.*
    replace: '*          hard    maxlogins     {{ var_accounts_max_concurrent_login_sessions
      }}'
  with_items:
  - '{{ maxlogins.files }}'
  when: ( "pam" in ansible_facts.packages and "kernel" in ansible_facts.packages )
  tags:
  - CJIS-5.5.2.2
  - DISA-STIG-RHEL-08-020024
  - NIST-800-53-AC-10
  - NIST-800-53-CM-6(a)
  - accounts_max_concurrent_login_sessions
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy

- name: Limit the Number of Concurrent Login Sessions Allowed Per User
  ansible.builtin.lineinfile:
    state: present
    dest: /etc/security/limits.conf
    insertbefore: ^# End of file
    regexp: ^#?\*.*maxlogins
    line: '*          hard    maxlogins     {{ var_accounts_max_concurrent_login_sessions
      }}'
    create: true
  when:
  - ( "pam" in ansible_facts.packages and "kernel" in ansible_facts.packages )
  - maxlogins.matched == 0
  tags:
  - CJIS-5.5.2.2
  - DISA-STIG-RHEL-08-020024
  - NIST-800-53-AC-10
  - NIST-800-53-CM-6(a)
  - accounts_max_concurrent_login_sessions
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_max_concurrent_login_sessions:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_max_concurrent_login_sessions"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_max_concurrent_login_sessions:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_max_concurrent_login_sessions_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_polyinstantiated_tmp" selected="false" severity="low">
              <xccdf-1.2:title>Configure Polyinstantiation of /tmp Directories</xccdf-1.2:title>
              <xccdf-1.2:description>To configure polyinstantiated /tmp directories, first create the parent directories
which will hold the polyinstantiation child directories. Use the following command:
<html:pre>$ sudo mkdir --mode 000 /tmp/tmp-inst</html:pre>
Then, add the following entry to <html:code>/etc/security/namespace.conf</html:code>:
<html:pre>/tmp     /tmp/tmp-inst/            level      root,adm</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R55</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Polyinstantiation of temporary directories is a proactive security measure
which reduces chances of attacks that are made possible by /tmp
directories being world-writable.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix id="accounts_polyinstantiated_tmp" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# shellcheck disable=SC2174
mkdir -p --mode 000 /tmp/tmp-inst
chmod 000 /tmp/tmp-inst
chcon --reference=/tmp /tmp/tmp-inst

if ! grep -Eq '^\s*/tmp\s+/tmp/tmp-inst/\s+level\s+root,adm$' /etc/security/namespace.conf ; then
    if grep -Eq '^\s*/tmp\s+' /etc/security/namespace.conf ; then
        sed -i '/^\s*\/tmp/d' /etc/security/namespace.conf
    fi
    echo "/tmp     /tmp/tmp-inst/        level      root,adm" &gt;&gt; /etc/security/namespace.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_polyinstantiated_tmp" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - accounts_polyinstantiated_tmp
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy

- name: Create /tmp/tmp-inst directory
  ansible.builtin.file:
    path: /tmp/tmp-inst
    state: directory
    mode: '000'
    seuser: system_u
    serole: object_r
    setype: tmp_t
  when: '"kernel" in ansible_facts.packages'
  tags:
  - accounts_polyinstantiated_tmp
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy

- name: Make changes to /etc/security/namespace.conf
  ansible.builtin.lineinfile:
    path: /etc/security/namespace.conf
    create: false
    regexp: ^\s*/tmp\s+/tmp/tmp-inst/\s+level\s+root,adm$
    line: /tmp     /tmp/tmp-inst/        level      root,adm
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - accounts_polyinstantiated_tmp
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_polyinstantiated_tmp:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_polyinstantiated_var_tmp" selected="false" severity="low">
              <xccdf-1.2:title>Configure Polyinstantiation of /var/tmp Directories</xccdf-1.2:title>
              <xccdf-1.2:description>To configure polyinstantiated /tmp directories, first create the parent directories
which will hold the polyinstantiation child directories. Use the following command:
<html:pre>$ sudo mkdir --mode 000 /var/tmp/tmp-inst</html:pre>
Then, add the following entry to <html:code>/etc/security/namespace.conf</html:code>:
<html:pre>/var/tmp /var/tmp/tmp-inst/    level      root,adm</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R55</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Polyinstantiation of temporary directories is a proactive security measure
which reduces chances of attacks that are made possible by /var/tmp
directories being world-writable.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix id="accounts_polyinstantiated_var_tmp" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# shellcheck disable=SC2174
mkdir -p --mode 000 /var/tmp/tmp-inst
chmod 000 /var/tmp/tmp-inst
chcon --reference=/var/tmp /var/tmp/tmp-inst

if ! grep -Eq '^\s*/var/tmp\s+/var/tmp/tmp-inst/\s+level\s+root,adm$' /etc/security/namespace.conf ; then
    if grep -Eq '^\s*/var/tmp\s+' /etc/security/namespace.conf ; then
        sed -i '/^\s*\/var\/tmp/d' /etc/security/namespace.conf
    fi
    echo "/var/tmp /var/tmp/tmp-inst/    level      root,adm" &gt;&gt; /etc/security/namespace.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_polyinstantiated_var_tmp" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - accounts_polyinstantiated_var_tmp
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy

- name: Create /var/tmp/tmp-inst directory
  ansible.builtin.file:
    path: /var/tmp/tmp-inst
    state: directory
    mode: '000'
    seuser: system_u
    serole: object_r
    setype: tmp_t
  when: '"kernel" in ansible_facts.packages'
  tags:
  - accounts_polyinstantiated_var_tmp
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy

- name: Make changes to /etc/security/namespace.conf
  ansible.builtin.lineinfile:
    path: /etc/security/namespace.conf
    create: false
    regexp: ^\s*/var/tmp\s+/var/tmp/tmp-inst/\s+level\s+root,adm$
    line: /var/tmp /var/tmp/tmp-inst/    level      root,adm
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - accounts_polyinstantiated_var_tmp
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_polyinstantiated_var_tmp:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_tmout" selected="false" severity="medium">
              <xccdf-1.2:title>Set Interactive Session Timeout</xccdf-1.2:title>
              <xccdf-1.2:description>Setting the <html:code>TMOUT</html:code> option in <html:code>/etc/profile</html:code> ensures that
all user sessions will terminate based on inactivity. A value of <html:code>0</html:code> (zero)
disables the automatic logout feature and is therefore not a compliant setting.
The value of TMOUT should be a positive integer, exported, and read only.
The <html:code>TMOUT</html:code>

setting in a file loaded by <html:code>/etc/profile</html:code>, e.g.
<html:code>/etc/profile.d/tmout.sh</html:code> should read as follows:
<html:pre>typeset -xr TMOUT=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_tmout" use="legacy"/></html:pre>
or
<html:pre>declare -xr TMOUT=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_tmout" use="legacy"/></html:pre>
Using the <html:code>typeset</html:code> keyword is preferred for wider compatibility with ksh and other shells.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(5)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000163-GPOS-00072</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000029-GPOS-00010</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R32</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020353</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230385r1017194_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Terminating an idle session within a short time period reduces
the window of opportunity for unauthorized personnel to take control of a
management session enabled on the console or console port that has been
left unattended.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix id="accounts_tmout" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_accounts_tmout='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_tmout" use="legacy"/>'


# if 0, no occurrence of tmout found, if 1, occurrence found
tmout_found=0


for f in /etc/profile /etc/profile.d/*.sh; do

    if grep --silent '^[^#].*TMOUT' $f; then
        sed -i -E "s/^(.*)TMOUT\s*=\s*(\w|\$)*(.*)$/typeset -xr TMOUT=$var_accounts_tmout\3/g" $f
        tmout_found=1
    fi
done

if [ $tmout_found -eq 0 ]; then
        echo -e "\n# Set TMOUT to $var_accounts_tmout per security requirements" &gt;&gt; /etc/profile.d/tmout.sh
        echo "typeset -xr TMOUT=$var_accounts_tmout" &gt;&gt; /etc/profile.d/tmout.sh
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_tmout" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020353
  - NIST-800-171-3.1.11
  - NIST-800-53-AC-12
  - NIST-800-53-AC-2(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-10
  - PCI-DSSv4-8.6
  - PCI-DSSv4-8.6.1
  - accounts_tmout
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_accounts_tmout # promote to variable
  set_fact:
    var_accounts_tmout: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_tmout" use="legacy"/>
  tags:
    - always

- name: Correct any occurrence of TMOUT in /etc/profile
  ansible.builtin.replace:
    path: /etc/profile
    regexp: ^[^#].*TMOUT=.*
    replace: typeset -xr TMOUT={{ var_accounts_tmout }}
  register: profile_replaced
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020353
  - NIST-800-171-3.1.11
  - NIST-800-53-AC-12
  - NIST-800-53-AC-2(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-10
  - PCI-DSSv4-8.6
  - PCI-DSSv4-8.6.1
  - accounts_tmout
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set Interactive Session Timeout
  ansible.builtin.lineinfile:
    path: /etc/profile.d/tmout.sh
    create: true
    regexp: TMOUT=
    line: typeset -xr TMOUT={{ var_accounts_tmout }}
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020353
  - NIST-800-171-3.1.11
  - NIST-800-53-AC-12
  - NIST-800-53-AC-2(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-10
  - PCI-DSSv4-8.6
  - PCI-DSSv4-8.6.1
  - accounts_tmout
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_tmout:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_tmout"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_tmout:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_tmout_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_user_dot_group_ownership" selected="false" severity="medium">
              <xccdf-1.2:title>User Initialization Files Must Be Group-Owned By The Primary Group</xccdf-1.2:title>
              <xccdf-1.2:description>Change the group owner of interactive users files to the group found
in <html:pre>/etc/passwd</html:pre> for the user. To change the group owner of a local
interactive user home directory, use the following command:
<html:pre>$ sudo chgrp <html:i>USER_GROUP</html:i> /home/<html:i>USER</html:i>/.<html:i>INIT_FILE</html:i></html:pre>

This rule ensures every initialization file related to an interactive user
is group-owned by an interactive user.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Due to OVAL limitation, this rule can report a false negative in a
specific situation where two interactive users swap the group-ownership
of their respective initialization files.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.2.9</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Local initialization files for interactive users are used to configure the
user's shell environment upon logon. Malicious modification of these files could
compromise accounts upon logon.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_user_dot_group_ownership" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

awk -F: '{if ($4 &gt;= 1000 &amp;&amp; $4 != 65534) print $4":"$6}' /etc/passwd | while IFS=: read -r gid home; do find -P "$home" -maxdepth 1 -type f -name "\.[^.]*" -exec chgrp -f --no-dereference -- $gid "{}" \;; done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_user_dot_group_ownership" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - accounts_user_dot_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: User Initialization Files Must Be Group-Owned By The Primary Group - Get interactive
    users from passwd file
  ansible.builtin.getent:
    database: passwd
  register: passwd_entries
  when: '"kernel" in ansible_facts.packages'
  tags:
  - accounts_user_dot_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: User Initialization Files Must Be Group-Owned By The Primary Group - Create
    list of interactive users with GID and home directory
  ansible.builtin.set_fact:
    interactive_users: '{{ interactive_users | default([]) + [{''home'': item.value[4],
      ''gid'': item.value[2]}] }}'
  loop: '{{ passwd_entries.ansible_facts.getent_passwd | dict2items }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.value[2] | int &gt;= 1000 | int
  - item.value[2] | int != 65534 | int
  - item.value[4] != ""
  tags:
  - accounts_user_dot_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: User Initialization Files Must Be Group-Owned By The Primary Group - Find
    dot files in interactive user home directories
  ansible.builtin.find:
    paths: '{{ item.home }}'
    patterns: .*
    file_type: file
    hidden: true
    depth: 1
    follow: false
  register: user_dotfiles
  loop: '{{ interactive_users | default([]) }}'
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - item.home != ""
  tags:
  - accounts_user_dot_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: User Initialization Files Must Be Group-Owned By The Primary Group - Set correct
    group ownership for user initialization files
  ansible.builtin.file:
    path: '{{ item.1.path }}'
    group: '{{ item.0.item.gid }}'
    follow: false
  loop: '{{ user_dotfiles.results | subelements(''files'', skip_missing=True) }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.0 is not skipped
  - item.1.path is defined
  tags:
  - accounts_user_dot_group_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_user_dot_group_ownership:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_user_dot_group_ownership_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_user_dot_no_world_writable_programs" selected="false" severity="medium">
              <xccdf-1.2:title>User Initialization Files Must Not Run World-Writable Programs</xccdf-1.2:title>
              <xccdf-1.2:description>Set the mode on files being executed by the user initialization files with the
following command:
<html:pre>$ sudo chmod o-w <html:i>FILE</html:i></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If user start-up files execute world-writable programs, especially in
unprotected directories, they could be maliciously modified to destroy user
files or otherwise compromise the system at the user level. If the system is
compromised at the user level, it is easier to elevate privileges to eventually
compromise the system at the root and network level.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_user_dot_no_world_writable_programs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

readarray -t world_writable_files &lt; &lt;(find / -xdev -type f -perm -0002 2&gt; /dev/null)
readarray -t interactive_home_dirs &lt; &lt;(awk -F':' '{ if ($3 &gt;= 1000 &amp;&amp; $3 != 65534) print $6 }' /etc/passwd)

for world_writable in "${world_writable_files[@]}"; do
    for homedir in "${interactive_home_dirs[@]}"; do
        if grep -q -d skip "$world_writable" "$homedir"/.*; then
            chmod o-w $world_writable
            break
        fi
    done
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_user_dot_no_world_writable_programs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - accounts_user_dot_no_world_writable_programs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: User Initialization Files Must Not Run World-Writable Programs - Initialize
    variables
  ansible.builtin.set_fact:
    home_user_dirs: []
    world_writable_files: []
  when: '"kernel" in ansible_facts.packages'
  tags:
  - accounts_user_dot_no_world_writable_programs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: User Initialization Files Must Not Run World-Writable Programs - Get user's
    home dir list
  ansible.builtin.getent:
    database: passwd
  register: passwd_database
  when: '"kernel" in ansible_facts.packages'
  tags:
  - accounts_user_dot_no_world_writable_programs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: User Initialization Files Must Not Run World-Writable Programs - Fill home_user_dirs
  ansible.builtin.set_fact:
    home_user_dirs: '{{ home_user_dirs + [item.data[4]] }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.data[4] is defined and item.data[2]|int &gt;= 1000 and item.data[2]|int != 65534
  with_items: '{{ passwd_database.ansible_facts.getent_passwd | dict2items(key_name=''user'',
    value_name=''data'')}}'
  tags:
  - accounts_user_dot_no_world_writable_programs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: User Initialization Files Must Not Run World-Writable Programs - Get world
    writable files
  ansible.builtin.shell: |
    find / -xdev -type f -perm -0002 2&gt; /dev/null
  register: world_writable_files
  changed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - accounts_user_dot_no_world_writable_programs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: User Initialization Files Must Not Run World-Writable Programs - Find referenced_files
    in init files
  ansible.builtin.find:
    paths: '{{ home_user_dirs }}'
    contains: '{{ item }}'
    hidden: true
    read_whole_file: true
    recurse: true
  with_items: '{{ world_writable_files.stdout_lines }}'
  register: referenced_files
  when: '"kernel" in ansible_facts.packages'
  tags:
  - accounts_user_dot_no_world_writable_programs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: User Initialization Files Must Not Run World-Writable Programs - Remove world
    writable permissions
  ansible.builtin.file:
    path: '{{ item.item }}'
    mode: o-w
  when:
  - '"kernel" in ansible_facts.packages'
  - item.matched &gt; 0
  with_items: '{{ referenced_files.results }}'
  tags:
  - accounts_user_dot_no_world_writable_programs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_user_initialization_files_regex:var:1" value-id="xccdf_org.ssgproject.content_value_var_user_initialization_files_regex"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_user_dot_no_world_writable_programs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_user_dot_no_world_writable_programs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_user_dot_user_ownership" selected="false" severity="medium">
              <xccdf-1.2:title>User Initialization Files Must Be Owned By the Primary User</xccdf-1.2:title>
              <xccdf-1.2:description>Set the owner of the user initialization files for interactive users to
the primary owner with the following command:
<html:pre>$ sudo chown <html:i>USER</html:i> /home/<html:i>USER</html:i>/.*</html:pre>

This rule ensures every initialization file related to an interactive user
is owned by an interactive user.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Due to OVAL limitation, this rule can report a false negative in a
specific situation where two interactive users swap the ownership of
their respective initialization files.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.2.9</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Local initialization files are used to configure the user's shell environment
upon logon. Malicious modification of these files could compromise accounts upon
logon.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_user_dot_user_ownership" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

awk -F: '{if ($3 &gt;= 1000 &amp;&amp; $3 != 65534) print $3":"$6}' /etc/passwd | while IFS=: read -r uid home; do find -P "$home" -maxdepth 1 -type f -name "\.[^.]*" -exec chown -f --no-dereference -- $uid "{}" \;; done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_user_dot_user_ownership" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - accounts_user_dot_user_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: User Initialization Files Must Be Owned By the Primary User - Get interactive
    users from passwd file
  ansible.builtin.getent:
    database: passwd
  register: passwd_entries
  when: '"kernel" in ansible_facts.packages'
  tags:
  - accounts_user_dot_user_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: User Initialization Files Must Be Owned By the Primary User - Create list
    of interactive users with UID and home directory
  ansible.builtin.set_fact:
    interactive_users: '{{ interactive_users | default([]) + [{''uid'': item.value[1],
      ''home'': item.value[4], ''username'': item.key}] }}'
  loop: '{{ passwd_entries.ansible_facts.getent_passwd | dict2items }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.value[1] | int &gt;= 1000 | int
  - item.value[1] | int != 65534 | int
  - item.value[4] != ""
  tags:
  - accounts_user_dot_user_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: User Initialization Files Must Be Owned By the Primary User - Find dot files
    in interactive user home directories
  ansible.builtin.find:
    paths: '{{ item.home }}'
    patterns: .*
    file_type: file
    hidden: true
    depth: 1
    follow: false
  register: user_dotfiles
  loop: '{{ interactive_users | default([]) }}'
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - item.home != ""
  tags:
  - accounts_user_dot_user_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: User Initialization Files Must Be Owned By the Primary User - Set correct
    ownership for user initialization files
  ansible.builtin.file:
    path: '{{ item.1.path }}'
    owner: '{{ item.0.item.username }}'
    follow: false
  loop: '{{ user_dotfiles.results | subelements(''files'', skip_missing=True) }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.0 is not skipped
  - item.0 is not failed
  - item.0.item is defined
  - item.0.item.username is defined
  - item.1.path is defined
  tags:
  - accounts_user_dot_user_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_user_dot_user_ownership:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_user_dot_user_ownership_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_user_home_paths_only" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure that Users Path Contains Only Local Directories</xccdf-1.2:title>
              <xccdf-1.2:description>Ensure that all interactive user initialization files executable search
path statements do not contain statements that will reference a working
directory other than the users home directory.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010690</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230317r1069320_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The executable search path (typically the PATH environment variable) contains a
list of directories for the shell to search to find executables. If this path
includes the current working directory (other than the users home directory),
executables in these directories may be executed instead of system commands.
This variable is formatted as a colon-separated list of directories. If there is
an empty entry, such as a leading or trailing colon or two consecutive colons,
this is interpreted as the current working directory. If deviations from the
default system search path for the local interactive user are required, they
must be documented with the Information System Security Officer (ISSO).</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_user_home_paths_only_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_user_interactive_home_directory_defined" selected="false" severity="medium">
              <xccdf-1.2:title>All Interactive Users Must Have A Home Directory Defined</xccdf-1.2:title>
              <xccdf-1.2:description>Assign home directories to all interactive users that currently do not
have a home directory assigned.

This rule checks if the home directory is properly defined in a folder which has
at least one parent folder, like "user" in "/home/user" or "/remote/users/user".
Therefore, this rule will report a finding for home directories like <html:code>/users</html:code>,
<html:code>/tmp</html:code> or <html:code>/</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010720</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230320r1017131_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If local interactive users are not assigned a valid home directory, there is no
place for the storage and control of files they should own.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_user_interactive_home_directory_defined" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

for user in $(awk -F':' '{ if ($3 &gt;= 1000 &amp;&amp; $3 != 65534) print $1 }' /etc/passwd); do
    # This follows the same logic of evaluation of home directories as used in OVAL.
    if ! grep -q $user /etc/passwd | cut -d: -f6 | grep '^\/\w*\/\w\{1,\}'; then
        sed -i "s/\($user:x:[0-9]*:[0-9]*:.*:\).*\(:.*\)$/\1\/home\/$user\2/g" /etc/passwd;
    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_user_interactive_home_directory_defined" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010720
  - accounts_user_interactive_home_directory_defined
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Get all local users from /etc/passwd
  ansible.builtin.getent:
    database: passwd
    split: ':'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010720
  - accounts_user_interactive_home_directory_defined
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Create local_users variable from the getent output
  ansible.builtin.set_fact:
    local_users: '{{ ansible_facts.getent_passwd|dict2items }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010720
  - accounts_user_interactive_home_directory_defined
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure interactive users have an exclusive home directory defined
  ansible.builtin.user:
    name: '{{ item.key }}'
    home: /home/{{ item.key }}
    create_home: false
  loop: '{{ local_users }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.value[2]|int &gt;= 1000
  - item.value[2]|int != 65534
  - item.value[2]|int &lt; 61184 or item.value[2]|int &gt; 65519
  - not item.value[4] | regex_search('^\/\w*\/\w{1,}')
  tags:
  - DISA-STIG-RHEL-08-010720
  - accounts_user_interactive_home_directory_defined
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_user_interactive_home_directory_defined:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_user_interactive_home_directory_defined_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_user_interactive_home_directory_exists" selected="false" severity="medium">
              <xccdf-1.2:title>All Interactive Users Home Directories Must Exist</xccdf-1.2:title>
              <xccdf-1.2:description>Create home directories to all local interactive users that currently do not
have a home directory assigned. Use the following commands to create the user
home directory assigned in <html:code>/etc/passwd</html:code>:
<html:pre>$ sudo mkdir /home/<html:i>USER</html:i></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010750</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230323r1017134_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If a local interactive user has a home directory defined that does not exist,
the user may be given access to the / directory as the current working directory
upon logon. This could create a Denial of Service because the user would not be
able to access their logon configuration files, and it may give them visibility
to system files they normally would not be able to access.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_user_interactive_home_directory_exists" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

for user in $(awk -F':' '{ if ($3 &gt;= 1000 &amp;&amp; $3 != 65534) print $1}' /etc/passwd); do
    mkhomedir_helper $user 0077;
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_user_interactive_home_directory_exists" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010750
  - accounts_user_interactive_home_directory_exists
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Get all local users from /etc/passwd
  ansible.builtin.getent:
    database: passwd
    split: ':'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010750
  - accounts_user_interactive_home_directory_exists
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Create local_users variable from the getent output
  ansible.builtin.set_fact:
    local_users: '{{ ansible_facts.getent_passwd|dict2items }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010750
  - accounts_user_interactive_home_directory_exists
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure interactive users have a home directory exists
  ansible.builtin.user:
    name: '{{ item.key }}'
    create_home: true
  loop: '{{ local_users }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.value[1]|int &gt;= 1000
  - item.value[1]|int != 65534
  tags:
  - DISA-STIG-RHEL-08-010750
  - accounts_user_interactive_home_directory_exists
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_user_interactive_home_directory_exists:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_user_interactive_home_directory_exists_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_user_interactive_home_directory_on_separate_partition" selected="false" severity="medium">
              <xccdf-1.2:title>All Interactive User Home Directories Must Reside On a Separate Partition</xccdf-1.2:title>
              <xccdf-1.2:description>All interactive user home directories must be located on a file system
partition separate from the root (<html:code>/</html:code>) partition. If any interactive
user's home directory resides directly on the root file system, a failure
of that file system or a user filling it up could impact system operation.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010800</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230328r1155410_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Ensuring that interactive user home directories are on a separate
partition from the root file system prevents users from filling the root
partition, which could result in system instability or denial of service.
It also allows administrators to apply more restrictive mount options
such as <html:code>noexec</html:code>, <html:code>nosuid</html:code>, and <html:code>nodev</html:code> to the
partition containing user home directories.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#machine"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_user_interactive_home_directory_on_separate_partition:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_user_interactive_home_directory_on_separate_partition_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_users_home_files_groupownership" selected="false" severity="medium">
              <xccdf-1.2:title>All User Files and Directories In The Home Directory Must Be Group-Owned By The Primary Group</xccdf-1.2:title>
              <xccdf-1.2:description>Change the group of a local interactive users files and directories to a
group that the interactive user is a member of. To change the group owner of a
local interactive users files and directories, use the following command:
<html:pre>$ sudo chgrp <html:i>USER_GROUP</html:i> /home/<html:i>USER</html:i>/<html:i>FILE_DIR</html:i></html:pre>

This rule ensures every file or directory under the home directory related
to an interactive user is group-owned by an interactive user.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Due to OVAL limitation, this rule can report a false negative in a
specific situation where two interactive users swap the group-ownership
of folders or files in their respective home directories.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010741</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244532r1101906_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If a local interactive users files are group-owned by a group of which the
user is not a member, unintended users may be able to access them.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_users_home_files_groupownership" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

for user in $(awk -F':' '{ if ($3 &gt;= 1000 &amp;&amp; $3 != 65534 &amp;&amp; $6 != "/") print $1 }' /etc/passwd); do
    home_dir=$(getent passwd $user | cut -d: -f6)
    group=$(getent passwd $user | cut -d: -f4)
    # Only update the group-ownership when necessary. This will avoid changing the inode timestamp
    # when the group is already defined as expected, therefore not impacting in possible integrity
    # check systems that also check inodes timestamps.
    find $home_dir -not -group $group -exec chgrp -f --no-dereference $group {} \;
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_users_home_files_groupownership" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010741
  - accounts_users_home_files_groupownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Get all local users from /etc/passwd
  ansible.builtin.getent:
    database: passwd
    split: ':'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010741
  - accounts_users_home_files_groupownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Create local_users variable from the getent output
  ansible.builtin.set_fact:
    local_users: '{{ ansible_facts.getent_passwd|dict2items }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010741
  - accounts_users_home_files_groupownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Test for existence of home directories to avoid creating them, but only fixing
    ownership
  ansible.builtin.stat:
    path: '{{ item.value[4] }}'
  register: path_exists
  loop: '{{ local_users }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.value[1]|int &gt;= 1000
  - item.value[1]|int != 65534
  - item.value[4] != "/"
  tags:
  - DISA-STIG-RHEL-08-010741
  - accounts_users_home_files_groupownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure interactive local users are the owners of their respective home directories
  ansible.builtin.file:
    path: '{{ item.0.value[4] }}'
    group: '{{ item.0.value[2] }}'
    recurse: true
  loop: '{{ local_users|zip(path_exists.results)|list }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.1.stat is defined and item.1.stat.exists
  tags:
  - DISA-STIG-RHEL-08-010741
  - accounts_users_home_files_groupownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_users_home_files_groupownership:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_users_home_files_groupownership_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_users_home_files_ownership" selected="false" severity="medium">
              <xccdf-1.2:title>All User Files and Directories In The Home Directory Must Have a Valid Owner</xccdf-1.2:title>
              <xccdf-1.2:description>Either remove all files and directories from the system that
do not have a valid user, or assign a valid user to all unowned
files and directories. To assign a valid owner to a local
interactive user's files and directories, use the following command:
<html:pre>$ sudo chown -R <html:i>USER</html:i> /home/<html:i>USER</html:i></html:pre>

This rule ensures every file or directory under the home directory related
to an interactive user is owned by an interactive user.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Due to OVAL limitation, this rule can report a false negative in a
specific situation where two interactive users swap the ownership of
folders or files in their respective home directories.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If local interactive users do not own the files in their directories,
unauthorized users may be able to access them. Additionally, if files are not
owned by the user, this could be an indication of system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_users_home_files_ownership" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

for user in $(awk -F':' '{ if ($3 &gt;= 1000 &amp;&amp; $3 != 65534 &amp;&amp; $6 != "/") print $1 }' /etc/passwd); do
    home_dir=$(getent passwd $user | cut -d: -f6)
    # Only update the ownership when necessary. This will avoid changing the inode timestamp
    # when the owner is already defined as expected, therefore not impacting in possible integrity
    # check systems that also check inodes timestamps.
    find $home_dir -not -user $user -exec chown -f --no-dereference $user {} \;
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_users_home_files_ownership" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - accounts_users_home_files_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Get all local users from /etc/passwd
  ansible.builtin.getent:
    database: passwd
    split: ':'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - accounts_users_home_files_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Create local_users variable from the getent output
  ansible.builtin.set_fact:
    local_users: '{{ ansible_facts.getent_passwd|dict2items }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - accounts_users_home_files_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Test for existence of home directories to avoid creating them, but only fixing
    ownership
  ansible.builtin.stat:
    path: '{{ item.value[4] }}'
  register: path_exists
  loop: '{{ local_users }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.value[1]|int &gt;= 1000
  - item.value[1]|int != 65534
  - item.value[4] != "/"
  tags:
  - accounts_users_home_files_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure interactive local users are the owners of their respective home directories
  ansible.builtin.file:
    path: '{{ item.0.value[4] }}'
    owner: '{{ item.0.value[1] }}'
    recurse: true
  loop: '{{ local_users|zip(path_exists.results)|list }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.1.stat is defined and item.1.stat.exists
  tags:
  - accounts_users_home_files_ownership
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_users_home_files_ownership:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_users_home_files_ownership_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_users_home_files_permissions" selected="false" severity="medium">
              <xccdf-1.2:title>All User Files and Directories In The Home Directory Must Have Mode 0750 Or Less Permissive</xccdf-1.2:title>
              <xccdf-1.2:description>Set the mode on files and directories in the local interactive user home
directory with the following command:
<html:pre>$ sudo chmod 0750 /home/<html:i>USER</html:i>/<html:i>FILE_DIR</html:i></html:pre>
Files that begin with a "." are excluded from this requirement.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010731</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244531r1017338_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If a local interactive user files have excessive permissions, unintended users
may be able to access or modify them.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_users_home_files_permissions" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

for home_dir in $(awk -F':' '{ if ($3 &gt;= 1000 &amp;&amp; $3 != 65534 &amp;&amp; $6 != "/") print $6 }' /etc/passwd); do
    # Only update the permissions when necessary. This will avoid changing the inode timestamp when
    # the permission is already defined as expected, therefore not impacting in possible integrity
    # check systems that also check inodes timestamps.
    find "$home_dir" -perm /7027 \! -type l -exec chmod u-s,g-w-s,o=- {} \;
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_users_home_files_permissions" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010731
  - accounts_users_home_files_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Get all local users from /etc/passwd
  ansible.builtin.getent:
    database: passwd
    split: ':'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010731
  - accounts_users_home_files_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Create local_users variable from the getent output
  ansible.builtin.set_fact:
    local_users: '{{ ansible_facts.getent_passwd|dict2items }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010731
  - accounts_users_home_files_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Test for existence home directories to avoid creating them.
  ansible.builtin.stat:
    path: '{{ item.value[4] }}'
  register: path_exists
  loop: '{{ local_users }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.value[1]|int &gt;= 1000
  - item.value[1]|int != 65534
  - item.value[4] != "/"
  tags:
  - DISA-STIG-RHEL-08-010731
  - accounts_users_home_files_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure interactive local users have proper permissions on their respective
    home directories
  ansible.builtin.file:
    path: '{{ item.0.value[4] }}'
    mode: u-s,g-w-s,o=-
    follow: false
    recurse: true
  loop: '{{ local_users|zip(path_exists.results)|list }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.1.stat is defined and item.1.stat.exists
  tags:
  - DISA-STIG-RHEL-08-010731
  - accounts_users_home_files_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_users_home_files_permissions:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_users_home_files_permissions_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_users_netrc_file_permissions" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure users' .netrc Files are not group or world accessible</xccdf-1.2:title>
              <xccdf-1.2:description>While the system administrator can establish secure permissions for users' .netrc files, the
users can easily override these.

This rule ensures every .netrc file or directory under the home directory related
to an interactive user is not group or world accessible</xccdf-1.2:description>
              <xccdf-1.2:rationale>.netrc files may contain unencrypted passwords that may be used to attack other systems.
Note: While the complete removal of .netrc files is recommended, if any are required on the
      system, secure permissions must be applied.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_users_netrc_file_permissions" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh">
for user in $(awk -F':' '{ if ($3 &gt;= 1000 &amp;&amp; $3 != 65534) print $1 }' /etc/passwd); do
    home_dir=$(getent passwd "$user" | cut -d: -f6)
    find "${home_dir}/.netrc" -exec chmod 0600 {} \;
done
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_users_netrc_file_permissions" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Get all local users from /etc/passwd
  ansible.builtin.getent:
    database: passwd
    split: ':'
  tags:
  - accounts_users_netrc_file_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Create local_users variable from the getent output
  ansible.builtin.set_fact:
    local_users: '{{ ansible_facts.getent_passwd|dict2items }}'
  tags:
  - accounts_users_netrc_file_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Test for existence of .netrc file in home directories to avoid creating them,
    but only fixing permissions
  ansible.builtin.stat:
    path: '{{ item.value[4] }}/.netrc'
  register: path_exists
  loop: '{{ local_users }}'
  when:
  - item.value[1]|int &gt;= 1000
  - item.value[1]|int != 65534
  tags:
  - accounts_users_netrc_file_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure group and world cannot access respective .netrc files
  ansible.builtin.file:
    path: '{{ item.item.value[4] }}/.netrc'
    mode: '0600'
    state: file
  loop: '{{ path_exists.results }}'
  when: item.stat is defined and item.stat.exists
  tags:
  - accounts_users_netrc_file_permissions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_users_netrc_file_permissions:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_users_netrc_file_permissions_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupownership_home_directories" selected="false" severity="medium">
              <xccdf-1.2:title>All Interactive User Home Directories Must Be Group-Owned By The Primary Group</xccdf-1.2:title>
              <xccdf-1.2:description>Change the group owner of interactive users home directory to the
group found in <html:code>/etc/passwd</html:code>. To change the group owner of
interactive users home directory, use the following command:
<html:pre>$ sudo chgrp <html:i>USER_GROUP</html:i> /home/<html:i>USER</html:i></html:pre>

This rule ensures every home directory related to an interactive user is
group-owned by an interactive user. It also ensures that interactive users
are group-owners of one and only one home directory.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Due to OVAL limitation, this rule can report a false negative in a
specific situation where two interactive users swap the group-ownership
of their respective home directories.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010740</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230322r1017133_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If the Group Identifier (GID) of a local interactive users home directory is
not the same as the primary GID of the user, this would allow unauthorized
access to the users files, and users that share the same group may not be
able to access files that they legitimately should.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupownership_home_directories" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh">
awk -F':' '{ if ($3 &gt;= 1000 &amp;&amp; $3 != 65534) system("chgrp -f " $4" "$6) }' /etc/passwd
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupownership_home_directories" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Get all local users from /etc/passwd
  ansible.builtin.getent:
    database: passwd
    split: ':'
  tags:
  - DISA-STIG-RHEL-08-010740
  - file_groupownership_home_directories
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Create local_users variable from the getent output
  ansible.builtin.set_fact:
    local_users: '{{ ansible_facts.getent_passwd|dict2items }}'
  tags:
  - DISA-STIG-RHEL-08-010740
  - file_groupownership_home_directories
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Test for existence of home directories to avoid creating them, but only fixing
    group ownership
  ansible.builtin.stat:
    path: '{{ item.value[4] }}'
  register: path_exists
  loop: '{{ local_users }}'
  when:
  - item.value[1]|int &gt;= 1000
  - item.value[1]|int != 65534
  tags:
  - DISA-STIG-RHEL-08-010740
  - file_groupownership_home_directories
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure interactive local users are the group-owners of their respective home
    directories
  ansible.builtin.file:
    path: '{{ item.0.value[4] }}'
    group: '{{ item.0.value[2] }}'
  loop: '{{ local_users|zip(path_exists.results)|list }}'
  when: item.1.stat is defined and item.1.stat.exists
  tags:
  - DISA-STIG-RHEL-08-010740
  - file_groupownership_home_directories
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupownership_home_directories:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupownership_home_directories_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_ownership_home_directories" selected="false" severity="medium">
              <xccdf-1.2:title>All Interactive User Home Directories Must Be Owned By The Primary User</xccdf-1.2:title>
              <xccdf-1.2:description>Change the owner of interactive users home directories to that correct
owner. To change the owner of a interactive users home directory, use
the following command:
<html:pre>$ sudo chown <html:i>USER</html:i> /home/<html:i>USER</html:i></html:pre>

This rule ensures every home directory related to an interactive user is
owned by an interactive user. It also ensures that interactive users are
owners of one and only one home directory.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Due to OVAL limitation, this rule can report a false negative in a
specific situation where two interactive users swap the ownership of
their respective home directories.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.2.8</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If a local interactive user does not own their home directory, unauthorized
users could access or modify the user's files, and the users may not be able to
access their own files.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_ownership_home_directories" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh">
awk -F':' '{ if ($3 &gt;= 1000 &amp;&amp; $3 != 65534) system("chown -f " $3" "$6) }' /etc/passwd
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_ownership_home_directories" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Get all local users from /etc/passwd
  ansible.builtin.getent:
    database: passwd
    split: ':'
  tags:
  - file_ownership_home_directories
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Create local_users variable from the getent output
  ansible.builtin.set_fact:
    local_users: '{{ ansible_facts.getent_passwd|dict2items }}'
  tags:
  - file_ownership_home_directories
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Test for existence of home directories to avoid creating them, but only fixing
    ownership
  ansible.builtin.stat:
    path: '{{ item.value[4] }}'
  register: path_exists
  loop: '{{ local_users }}'
  when:
  - item.value[1]|int &gt;= 1000
  - item.value[1]|int != 65534
  tags:
  - file_ownership_home_directories
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure interactive local users are the owners of their respective home directories
  ansible.builtin.file:
    path: '{{ item.0.value[4] }}'
    owner: '{{ item.0.value[1] }}'
  loop: '{{ local_users|zip(path_exists.results)|list }}'
  when: item.1.stat is defined and item.1.stat.exists
  tags:
  - file_ownership_home_directories
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_ownership_home_directories:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_ownership_home_directories_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permission_user_bash_history" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure User Bash History File Has Correct Permissions</xccdf-1.2:title>
              <xccdf-1.2:description>Set the mode of the bash history file to <html:code>0600</html:code> with the
following command:
<html:pre>$ sudo chmod 0600 /home/<html:i>USER</html:i>/.bash_history</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.2.9</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Incorrect permissions may enable malicious users to recover
other users' command history.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_bash"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permission_user_bash_history" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q bash; then

readarray -t interactive_users &lt; &lt;(awk -F: '$3&gt;=1000   {print $1}' /etc/passwd)
readarray -t interactive_users_home &lt; &lt;(awk -F: '$3&gt;=1000   {print $6}' /etc/passwd)
readarray -t interactive_users_shell &lt; &lt;(awk -F: '$3&gt;=1000   {print $7}' /etc/passwd)

USERS_IGNORED_REGEX='nobody|nfsnobody'

for (( i=0; i&lt;"${#interactive_users[@]}"; i++ )); do
    if ! grep -qP "$USERS_IGNORED_REGEX" &lt;&lt;&lt; "${interactive_users[$i]}" &amp;&amp; \
        [ "${interactive_users_shell[$i]}" != "/sbin/nologin" ]; then

        chmod u-sx,go= "${interactive_users_home[$i]}/.bash_history"
    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permission_user_bash_history" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - file_permission_user_bash_history
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure User Bash History File Has Correct Permissions - Gather User Info
  ansible.builtin.getent:
    database: passwd
  when: '"bash" in ansible_facts.packages'
  tags:
  - file_permission_user_bash_history
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure User Bash History File Has Correct Permissions - Check Bash History
    Files Existence
  ansible.builtin.stat:
    path: '{{ item.value[4] }}/.bash_history'
  register: bash_history_files
  with_dict: '{{ ansible_facts.getent_passwd }}'
  when:
  - '"bash" in ansible_facts.packages'
  - item.value[4] != "/sbin/nologin"
  - item.key not in ["nobody", "nfsnobody"]
  - item.value[1] | int &gt;= 1000
  tags:
  - file_permission_user_bash_history
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure User Bash History File Has Correct Permissions - Fix Bash History Files
    Permissions
  ansible.builtin.file:
    path: '{{ item.stat.path }}'
    mode: u-sx,go=
  with_items: '{{ bash_history_files.results }}'
  when:
  - '"bash" in ansible_facts.packages'
  - item.stat is defined
  - item.stat.exists
  tags:
  - file_permission_user_bash_history
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permission_user_bash_history:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permission_user_bash_history_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permission_user_init_files" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure All User Initialization Files Have Mode 0740 Or Less Permissive</xccdf-1.2:title>
              <xccdf-1.2:description>Set the mode of the user initialization files to <html:code>0740</html:code> or less permissisive with the
following command:
<html:pre>$ sudo chmod u-s,g-wxs,o= /home/<html:i>USER</html:i>/.<html:i>INIT_FILE</html:i></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.2.9</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Local initialization files are used to configure the user's shell environment
upon logon. Malicious modification of these files could compromise accounts upon
logon.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permission_user_init_files" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh">
var_user_initialization_files_regex='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_user_initialization_files_regex" use="legacy"/>'


readarray -t interactive_users &lt; &lt;(awk -F: '$3&gt;=1000   {print $1}' /etc/passwd)
readarray -t interactive_users_home &lt; &lt;(awk -F: '$3&gt;=1000   {print $6}' /etc/passwd)
readarray -t interactive_users_shell &lt; &lt;(awk -F: '$3&gt;=1000   {print $7}' /etc/passwd)

USERS_IGNORED_REGEX='nobody|nfsnobody'

for (( i=0; i&lt;"${#interactive_users[@]}"; i++ )); do
    if ! grep -qP "$USERS_IGNORED_REGEX" &lt;&lt;&lt; "${interactive_users[$i]}" &amp;&amp; \
        [ "${interactive_users_shell[$i]}" != "/sbin/nologin" ]; then
        
        readarray -t init_files &lt; &lt;(find "${interactive_users_home[$i]}" -maxdepth 1 \
            -exec basename {} \; | grep -P "$var_user_initialization_files_regex")
        for file in "${init_files[@]}"; do
            chmod u-s,g-wxs,o= "${interactive_users_home[$i]}/$file"
        done
    fi
done
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permission_user_init_files" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: XCCDF Value var_user_initialization_files_regex # promote to variable
  set_fact:
    var_user_initialization_files_regex: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_user_initialization_files_regex" use="legacy"/>
  tags:
    - always

- name: Ensure All User Initialization Files Have Mode 0740 Or Less Permissive - Gather
    User Info
  ansible.builtin.getent:
    database: passwd
  tags:
  - file_permission_user_init_files
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure All User Initialization Files Have Mode 0740 Or Less Permissive - Find
    Init Files
  ansible.builtin.find:
    paths: '{{ item.value[4] }}'
    pattern: '{{ var_user_initialization_files_regex }}'
    hidden: true
    use_regex: true
  with_dict: '{{ ansible_facts.getent_passwd }}'
  when:
  - item.value[4] != "/sbin/nologin"
  - item.key not in ["nobody", "nfsnobody"]
  - item.value[1] | int &gt;= 1000
  register: found_init_files
  tags:
  - file_permission_user_init_files
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure All User Initialization Files Have Mode 0740 Or Less Permissive - Fix
    Init Files Permissions
  ansible.builtin.file:
    path: '{{ item.1.path }}'
    mode: u-s,g-wxs,o=
  loop: '{{ q(''ansible.builtin.subelements'', found_init_files.results, ''files'',
    {''skip_missing'': True}) }}'
  tags:
  - file_permission_user_init_files
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_user_initialization_files_regex:var:1" value-id="xccdf_org.ssgproject.content_value_var_user_initialization_files_regex"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permission_user_init_files:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permission_user_init_files_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permission_user_init_files_root" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure All User Initialization Files Have Mode 0740 Or Less Permissive</xccdf-1.2:title>
              <xccdf-1.2:description>Set the mode of the user initialization files, including the <html:code>root</html:code> user,
to <html:code>0740</html:code> or less permissisive with the following commands:
<html:pre>
$ sudo chmod u-s,g-wxs,o= /root/.<html:i>INIT_FILE</html:i>
$ sudo chmod u-s,g-wxs,o= /home/<html:i>USER</html:i>/.<html:i>INIT_FILE</html:i>
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010770</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230325r1017136_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Local initialization files are used to configure the user's shell environment
upon logon. Malicious modification of these files could compromise accounts upon
logon.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permission_user_init_files_root" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh">
var_user_initialization_files_regex='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_user_initialization_files_regex" use="legacy"/>'


readarray -t interactive_users &lt; &lt;(awk -F: '$3==0 || $3&gt;=1000   {print $1}' /etc/passwd)
readarray -t interactive_users_home &lt; &lt;(awk -F: '$3==0 || $3&gt;=1000   {print $6}' /etc/passwd)
readarray -t interactive_users_shell &lt; &lt;(awk -F: '$3==0 || $3&gt;=1000   {print $7}' /etc/passwd)

USERS_IGNORED_REGEX='nobody|nfsnobody'

for (( i=0; i&lt;"${#interactive_users[@]}"; i++ )); do
    if ! grep -qP "$USERS_IGNORED_REGEX" &lt;&lt;&lt; "${interactive_users[$i]}" &amp;&amp; \
        [ "${interactive_users_shell[$i]}" != "/sbin/nologin" ]; then

        readarray -t init_files &lt; &lt;(find "${interactive_users_home[$i]}" -maxdepth 1 \
            -exec basename {} \; | grep -P "$var_user_initialization_files_regex")
        for file in "${init_files[@]}"; do
            chmod u-s,g-wxs,o= "${interactive_users_home[$i]}/$file"
        done
    fi
done
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permission_user_init_files_root" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: XCCDF Value var_user_initialization_files_regex # promote to variable
  set_fact:
    var_user_initialization_files_regex: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_user_initialization_files_regex" use="legacy"/>
  tags:
    - always

- name: Ensure All User Initialization Files Have Mode 0740 Or Less Permissive - Gather
    User Info
  ansible.builtin.getent:
    database: passwd
  tags:
  - DISA-STIG-RHEL-08-010770
  - file_permission_user_init_files_root
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure All User Initialization Files Have Mode 0740 Or Less Permissive - Find
    Init Files
  ansible.builtin.find:
    paths: '{{ item.value[4] }}'
    pattern: '{{ var_user_initialization_files_regex }}'
    hidden: true
    use_regex: true
  with_dict: '{{ ansible_facts.getent_passwd }}'
  when:
  - item.value[4] != "/sbin/nologin"
  - item.key not in ["nobody", "nfsnobody"]
  - item.value[1] | int &gt;= 1000 or item.key == "root"
  register: found_init_files
  tags:
  - DISA-STIG-RHEL-08-010770
  - file_permission_user_init_files_root
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure All User Initialization Files Have Mode 0740 Or Less Permissive - Fix
    Init Files Permissions
  ansible.builtin.file:
    path: '{{ item.1.path }}'
    mode: u-s,g-wxs,o=
  loop: '{{ q(''ansible.builtin.subelements'', found_init_files.results, ''files'',
    {''skip_missing'': True}) }}'
  tags:
  - DISA-STIG-RHEL-08-010770
  - file_permission_user_init_files_root
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_user_initialization_files_regex:var:1" value-id="xccdf_org.ssgproject.content_value_var_user_initialization_files_regex"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permission_user_init_files_root:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permission_user_init_files_root_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_home_directories" selected="false" severity="medium">
              <xccdf-1.2:title>All Interactive User Home Directories Must Have mode 0750 Or Less Permissive</xccdf-1.2:title>
              <xccdf-1.2:description>Change the mode of interactive users home directories to <html:code>0750</html:code>. To
change the mode of interactive users home directory, use the
following command:
<html:pre>$ sudo chmod 0750 /home/<html:i>USER</html:i></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010730</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230321r1017132_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Excessive permissions on local interactive user home directories may allow
unauthorized access to user files by other users.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_home_directories" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh">
for home_dir in $(awk -F':' '{ if ($3 &gt;= 1000 &amp;&amp; $3 != 65534 &amp;&amp; $6 != "/") print $6 }' /etc/passwd); do
    # Only update the permissions when necessary. This will avoid changing the inode timestamp when
    # the permission is already defined as expected, therefore not impacting in possible integrity
    # check systems that also check inodes timestamps.
    find "$home_dir" -maxdepth 0 -perm /7027 \! -type l -exec chmod u-s,g-w-s,o=- {} \;
done
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_home_directories" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Get all local users from /etc/passwd
  ansible.builtin.getent:
    database: passwd
    split: ':'
  tags:
  - DISA-STIG-RHEL-08-010730
  - file_permissions_home_directories
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Create local_users variable from the getent output
  ansible.builtin.set_fact:
    local_users: '{{ ansible_facts.getent_passwd|dict2items }}'
  tags:
  - DISA-STIG-RHEL-08-010730
  - file_permissions_home_directories
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Test for existence home directories to avoid creating them.
  ansible.builtin.stat:
    path: '{{ item.value[4] }}'
  register: path_exists
  loop: '{{ local_users }}'
  when:
  - item.value[1]|int &gt;= 1000
  - item.value[1]|int != 65534
  - item.value[4] != "/"
  tags:
  - DISA-STIG-RHEL-08-010730
  - file_permissions_home_directories
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure interactive local users have proper permissions on their respective
    home directories
  ansible.builtin.file:
    path: '{{ item.0.value[4] }}'
    mode: u-s,g-w-s,o=-
    follow: false
    recurse: false
  loop: '{{ local_users|zip(path_exists.results)|list }}'
  when: item.1.stat is defined and item.1.stat.exists
  tags:
  - DISA-STIG-RHEL-08-010730
  - file_permissions_home_directories
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_home_directories:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_home_directories_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_home_dirs" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure that User Home Directories are not Group-Writable or World-Readable</xccdf-1.2:title>
              <xccdf-1.2:description>For each human user of the system, view the
permissions of the user's home directory:
<html:pre># ls -ld /home/<html:i>USER</html:i></html:pre>
Ensure that the directory is not group-writable and that it
is not world-readable. If necessary, repair the permissions:
<html:pre># chmod g-w /home/<html:i>USER</html:i>
# chmod o-rwx /home/<html:i>USER</html:i></html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="functionality">This action may involve modifying user home directories.
Notify your user community, and solicit input if appropriate,
before making this type of change.</xccdf-1.2:warning>
              <xccdf-1.2:warning category="general">This rule is deprecated in favor of the <html:code>file_permissions_home_directories</html:code> rule.Please consider replacing this rule in your files as it is not expected to receive
updates as of version <html:code>0.1.62</html:code>.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:rationale>User home directories contain many configuration files which
affect the behavior of a user's account. No user should ever have
write permission to another user's home directory. Group shared
directories can be configured in sub-directories or elsewhere in the
filesystem if they are needed. Typically, user home directories
should not be world-readable, as it would disclose file names
to other users. If a subset of users need read access
to one another's home directories, this can be provided using
groups or ACLs.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_home_dirs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh">
for home_dir in $(awk -F':' '{ if ($3 &gt;= 1000 &amp;&amp; $3 != 65534 &amp;&amp; $6 != "/") print $6 }' /etc/passwd); do
    # Only update the permissions when necessary. This will avoid changing the inode timestamp when
    # the permission is already defined as expected, therefore not impacting in possible integrity
    # check systems that also check inodes timestamps.
    find "$home_dir" -maxdepth 0 -perm /7027 \! -type l -exec chmod u-s,g-w-s,o=- {} \;
done
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_home_dirs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Get all local users from /etc/passwd
  ansible.builtin.getent:
    database: passwd
    split: ':'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(a)
  - file_permissions_home_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Create local_users variable from the getent output
  ansible.builtin.set_fact:
    local_users: '{{ ansible_facts.getent_passwd|dict2items }}'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(a)
  - file_permissions_home_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Test for existence home directories to avoid creating them.
  ansible.builtin.stat:
    path: '{{ item.value[4] }}'
  register: path_exists
  loop: '{{ local_users }}'
  when:
  - item.value[1]|int &gt;= 1000
  - item.value[1]|int != 65534
  - item.value[4] != "/"
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(a)
  - file_permissions_home_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure interactive local users have proper permissions on their respective
    home directories
  ansible.builtin.file:
    path: '{{ item.0.value[4] }}'
    mode: u-s,g-w-s,o=-
    follow: false
    recurse: false
  loop: '{{ local_users|zip(path_exists.results)|list }}'
  when: item.1.stat is defined and item.1.stat.exists
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(a)
  - file_permissions_home_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_home_dirs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_home_dirs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_root_paths">
              <xccdf-1.2:title>Ensure that No Dangerous Directories Exist in Root's Path</xccdf-1.2:title>
              <xccdf-1.2:description>The active path of the root account can be obtained by
starting a new root shell and running:
<html:pre># echo $PATH</html:pre>
This will produce a colon-separated list of
directories in the path.
<html:br/><html:br/>
Certain path elements could be considered dangerous, as they could lead
to root executing unknown or
untrusted programs, which could contain malicious
code.
Since root may sometimes work inside
untrusted directories, the <html:code>.</html:code> character, which represents the
current directory, should never be in the root path, nor should any
directory which can be written to by an unprivileged or
semi-privileged (system) user.
<html:br/><html:br/>
It is a good practice for administrators to always execute
privileged commands by typing the full path to the
command.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_root_path_dirs_no_write" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure that Root's Path Does Not Include World or Group-Writable Directories</xccdf-1.2:title>
                <xccdf-1.2:description>For each element in root's path, run:
<html:pre># ls -ld <html:i>DIR</html:i></html:pre>
and ensure that write permissions are disabled for group and
other.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.2.5</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Such entries increase the risk that root could
execute code provided by unprivileged users,
and potentially malicious code.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="accounts_root_path_dirs_no_write" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Get root paths which are not symbolic links
  ansible.builtin.stat:
    path: '{{ item }}'
  changed_when: false
  failed_when: false
  register: root_paths
  with_items: '{{ ansible_env.PATH.split('':'') }}'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(a)
  - accounts_root_path_dirs_no_write
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable writability to root directories
  ansible.builtin.file:
    path: '{{ item.item }}'
    mode: g-w,o-w
  with_items: '{{ root_paths.results }}'
  when:
  - root_paths.results is defined
  - item.stat.exists
  - not item.stat.islnk
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(a)
  - accounts_root_path_dirs_no_write
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_root_path_dirs_no_write:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_root_path_dirs_no_write_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_root_path_no_dot" selected="false" severity="unknown">
                <xccdf-1.2:title>Ensure that Root's Path Does Not Include Relative Paths or Null Directories</xccdf-1.2:title>
                <xccdf-1.2:description>Ensure that none of the directories in root's path is equal to a single
<html:code>.</html:code> character, or
that it contains any instances that lead to relative path traversal, such as
<html:code>..</html:code> or beginning a path without the slash (<html:code>/</html:code>) character.
Also ensure that there are no "empty" elements in the path, such as in these examples:
<html:pre>PATH=:/bin
PATH=/bin:
PATH=/bin::/sbin</html:pre>
These empty elements have the same effect as a single <html:code>.</html:code> character.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.2.5</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Including these entries increases the risk that root could
execute code from an untrusted location.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-root_path_no_dot:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_user_umask">
              <xccdf-1.2:title>Ensure that Users Have Sensible Umask Values</xccdf-1.2:title>
              <xccdf-1.2:description>The umask setting controls the default permissions
for the creation of new files.
With a default <html:code>umask</html:code> setting of 077, files and directories
created by users will not be readable by any other user on the
system. Users who wish to make specific files group- or
world-readable can accomplish this by using the chmod command.
Additionally, users can make all their files readable to their
group by default by setting a <html:code>umask</html:code> of 027 in their shell
configuration files. If default per-user groups exist (that is, if
every user has a default group whose name is the same as that
user's username and whose only member is the user), then it may
even be safe for users to select a <html:code>umask</html:code> of 007, making it very
easy to intentionally share files with groups of which the user is
a member.
<html:br/><html:br/></xccdf-1.2:description>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_accounts_user_umask" type="string">
                <xccdf-1.2:title>Sensible umask</xccdf-1.2:title>
                <xccdf-1.2:description>Enter default user umask</xccdf-1.2:description>
                <xccdf-1.2:value selector="007">007</xccdf-1.2:value>
                <xccdf-1.2:value selector="022">022</xccdf-1.2:value>
                <xccdf-1.2:value selector="027">027</xccdf-1.2:value>
                <xccdf-1.2:value selector="077">077</xccdf-1.2:value>
                <xccdf-1.2:value>027</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_umask_etc_bashrc" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure the Default Bash Umask is Set Correctly</xccdf-1.2:title>
                <xccdf-1.2:description>To ensure the default umask for users of the Bash shell is set properly,
add or correct the <html:code>umask</html:code> setting in <html:code>/etc/bashrc</html:code> to read
as follows:
<html:pre>umask <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" use="legacy"/></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00228</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R36</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The umask value influences the permissions assigned to files when they are created.
A misconfigured umask value could result in files with excessive permissions that can be read or
written to by unauthorized users.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_bash"/>
                <xccdf-1.2:fix id="accounts_umask_etc_bashrc" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q bash; then

var_accounts_user_umask='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" use="legacy"/>'






grep -q "^[^#]*\bumask" /etc/bashrc &amp;&amp; \
  sed -i -E -e "s/^([^#]*\bumask)[[:space:]]+[[:digit:]]+/\1 $var_accounts_user_umask/g" /etc/bashrc
if ! [ $? -eq 0 ]; then
    echo "umask $var_accounts_user_umask" &gt;&gt; /etc/bashrc
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_umask_etc_bashrc" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - accounts_umask_etc_bashrc
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_accounts_user_umask # promote to variable
  set_fact:
    var_accounts_user_umask: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" use="legacy"/>
  tags:
    - always

- name: Check if umask in /etc/bashrc is already set
  ansible.builtin.lineinfile:
    path: /etc/bashrc
    regexp: ^[^#]*\bumask\s+\d+$
    state: absent
  check_mode: true
  changed_when: false
  register: umask_replace
  when: '"bash" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - accounts_umask_etc_bashrc
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Replace user umask in /etc/bashrc
  ansible.builtin.replace:
    path: /etc/bashrc
    regexp: ^([^#]*\b)umask\s+\d+$
    replace: \g&lt;1&gt;umask {{ var_accounts_user_umask }}
  when:
  - '"bash" in ansible_facts.packages'
  - umask_replace.found &gt; 0
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - accounts_umask_etc_bashrc
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure the Default umask is Appended Correctly
  ansible.builtin.lineinfile:
    create: true
    path: /etc/bashrc
    line: umask {{ var_accounts_user_umask }}
  when:
  - '"bash" in ansible_facts.packages'
  - umask_replace.found == 0
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - accounts_umask_etc_bashrc
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_user_umask:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_user_umask"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_umask_etc_bashrc:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_umask_etc_csh_cshrc" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure the Default C Shell Umask is Set Correctly</xccdf-1.2:title>
                <xccdf-1.2:description>To ensure the default umask for users of the C shell is set properly,
add or correct the <html:code>umask</html:code> setting in <html:code>/etc/csh.cshrc</html:code> to read as follows:
<html:pre>umask <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" use="legacy"/></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00228</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The umask value influences the permissions assigned to files when they are created.
A misconfigured umask value could result in files with excessive permissions that can be read or
written to by unauthorized users.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_tcsh"/>
                <xccdf-1.2:fix id="accounts_umask_etc_csh_cshrc" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q tcsh; then

var_accounts_user_umask='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" use="legacy"/>'


grep -q "^\s*umask" /etc/csh.cshrc &amp;&amp; \
  sed -i -E -e "s/^(\s*umask).*/\1 $var_accounts_user_umask/g" /etc/csh.cshrc
if ! [ $? -eq 0 ]; then
    echo "umask $var_accounts_user_umask" &gt;&gt; /etc/csh.cshrc
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_umask_etc_csh_cshrc" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - accounts_umask_etc_csh_cshrc
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_accounts_user_umask # promote to variable
  set_fact:
    var_accounts_user_umask: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" use="legacy"/>
  tags:
    - always

- name: Check if umask in /etc/csh.cshrc is already set
  ansible.builtin.lineinfile:
    path: /etc/csh.cshrc
    regexp: ^(\s*)umask\s+.*
    state: absent
  check_mode: true
  changed_when: false
  register: umask_replace
  when: '"tcsh" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - accounts_umask_etc_csh_cshrc
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Replace user umask in /etc/csh.cshrc
  ansible.builtin.replace:
    path: /etc/csh.cshrc
    regexp: ^(\s*)umask(\s+).*
    replace: \g&lt;1&gt;umask\g&lt;2&gt;{{ var_accounts_user_umask }}
  when:
  - '"tcsh" in ansible_facts.packages'
  - umask_replace.found &gt; 0
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - accounts_umask_etc_csh_cshrc
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure the Default umask is Appended Correctly
  ansible.builtin.lineinfile:
    create: true
    path: /etc/csh.cshrc
    line: umask {{ var_accounts_user_umask }}
  when:
  - '"tcsh" in ansible_facts.packages'
  - umask_replace.found == 0
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - accounts_umask_etc_csh_cshrc
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_user_umask:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_user_umask"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_umask_etc_csh_cshrc:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_umask_etc_csh_cshrc_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_umask_etc_login_defs" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure the Default Umask is Set Correctly in login.defs</xccdf-1.2:title>
                <xccdf-1.2:description>To ensure the default umask controlled by <html:code>/etc/login.defs</html:code> is set properly,
add or correct the <html:code>UMASK</html:code> setting in <html:code>/etc/login.defs</html:code> to read as follows:
<html:pre>UMASK <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" use="legacy"/></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00228</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R36</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020351</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230383r1017192_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The umask value influences the permissions assigned to files when they are created.
A misconfigured umask value could result in files with excessive permissions that can be read and
written to by unauthorized users.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_shadow-utils_and_system_with_kernel"/>
                <xccdf-1.2:fix id="accounts_umask_etc_login_defs" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q shadow-utils &amp;&amp; rpm --quiet -q kernel ) ); then

var_accounts_user_umask='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" use="legacy"/>'


# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^UMASK")

# shellcheck disable=SC2059
printf -v formatted_output "%s %s" "$stripped_key" "$var_accounts_user_umask"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^UMASK\\&gt;" "/etc/login.defs"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^UMASK\\&gt;.*/$escaped_formatted_output/gi" "/etc/login.defs"
else
    if [[ -s "/etc/login.defs" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/login.defs" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/login.defs"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/login.defs"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_umask_etc_login_defs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020351
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - accounts_umask_etc_login_defs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_accounts_user_umask # promote to variable
  set_fact:
    var_accounts_user_umask: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" use="legacy"/>
  tags:
    - always

- name: Check if UMASK is already set
  ansible.builtin.lineinfile:
    path: /etc/login.defs
    regexp: ^(\s*)UMASK\s+.*
    state: absent
  check_mode: true
  changed_when: false
  register: result_umask_is_set
  when: ( "shadow-utils" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - DISA-STIG-RHEL-08-020351
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - accounts_umask_etc_login_defs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Replace user UMASK in /etc/login.defs
  ansible.builtin.replace:
    path: /etc/login.defs
    regexp: ^(\s*)UMASK(\s+).*
    replace: \g&lt;1&gt;UMASK\g&lt;2&gt;{{ var_accounts_user_umask }}
  when:
  - ( "shadow-utils" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - result_umask_is_set.found &gt; 0
  tags:
  - DISA-STIG-RHEL-08-020351
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - accounts_umask_etc_login_defs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure the Default UMASK is Appended Correctly
  ansible.builtin.lineinfile:
    create: true
    path: /etc/login.defs
    line: UMASK {{ var_accounts_user_umask }}
  when:
  - ( "shadow-utils" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - result_umask_is_set.found == 0
  tags:
  - DISA-STIG-RHEL-08-020351
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - accounts_umask_etc_login_defs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_user_umask:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_user_umask"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_umask_etc_login_defs:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_umask_etc_profile" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure the Default Umask is Set Correctly in /etc/profile</xccdf-1.2:title>
                <xccdf-1.2:description>To ensure the default umask controlled by <html:code>/etc/profile</html:code> is set properly,
add or correct the <html:code>umask</html:code> setting in <html:code>/etc/profile</html:code> to read as follows:
<html:pre>umask <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" use="legacy"/></html:pre>

Note that <html:code>/etc/profile</html:code> also reads scripts within <html:code>/etc/profile.d</html:code> directory.
These scripts are also valid files to set umask value. Therefore, they should also be
considered during the check and properly remediated, if necessary.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00228</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R36</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The umask value influences the permissions assigned to files when they are created.
A misconfigured umask value could result in files with excessive permissions that can be read or
written to by unauthorized users.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_umask_etc_profile" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh">
var_accounts_user_umask='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" use="legacy"/>'


readarray -t profile_files &lt; &lt;(find /etc/profile.d/ -type f -name '*.sh' -or -name 'sh.local')

for file in "${profile_files[@]}" /etc/profile; do
  grep -qE '^[^#]*umask' "$file" &amp;&amp; sed -i -E "s/^(\s*umask\s*)[0-7]+/\1$var_accounts_user_umask/g" "$file"
done

if ! grep -qrE '^[^#]*umask' /etc/profile*; then
  echo "umask $var_accounts_user_umask" &gt;&gt; /etc/profile
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_umask_etc_profile" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: XCCDF Value var_accounts_user_umask # promote to variable
  set_fact:
    var_accounts_user_umask: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_user_umask" use="legacy"/>
  tags:
    - always

- name: Ensure the Default Umask is Set Correctly in /etc/profile - Locate Profile
    Configuration Files Where umask Is Defined
  ansible.builtin.find:
    paths:
    - /etc/profile.d
    patterns:
    - sh.local
    - '*.sh'
    contains: ^[\s]*umask\s+\d+
  register: result_profile_d_files
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - accounts_umask_etc_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure the Default Umask is Set Correctly in /etc/profile - Replace Existing
    umask Value in Files From /etc/profile.d
  ansible.builtin.replace:
    path: '{{ item.path }}'
    regexp: ^(\s*)umask\s+\d+
    replace: \1umask {{ var_accounts_user_umask }}
  loop: '{{ result_profile_d_files.files }}'
  register: result_umask_replaced_profile_d
  when: result_profile_d_files.matched
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - accounts_umask_etc_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure the Default Umask is Set Correctly in /etc/profile - Ensure umask Is
    Set in /etc/profile if Not Already Set Elsewhere
  ansible.builtin.lineinfile:
    create: true
    mode: 420
    path: /etc/profile
    line: umask {{ var_accounts_user_umask }}
  when: not result_profile_d_files.matched
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - accounts_umask_etc_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure the Default Umask is Set Correctly in /etc/profile - Ensure umask Value
    For All Existing umask Definition in /etc/profile
  ansible.builtin.replace:
    path: /etc/profile
    regexp: ^(\s*)umask\s+\d+
    replace: \1umask {{ var_accounts_user_umask }}
  register: result_umask_replaced_profile
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - accounts_umask_etc_profile
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_user_umask:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_user_umask"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_umask_etc_profile:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_umask_interactive_users" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure the Default Umask is Set Correctly For Interactive Users</xccdf-1.2:title>
                <xccdf-1.2:description>Remove the <html:code>UMASK</html:code> environment variable from all interactive users initialization files.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00228</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020352</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230384r1017193_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The umask controls the default access mode assigned to newly created files. A
umask of 077 limits new files to mode 700 or less permissive. Although umask can
be represented as a four-digit number, the first digit representing special
access modes is typically ignored or required to be 0. This requirement
applies to the globally configured system defaults and the local interactive
user defaults for each account on the system.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_umask_interactive_users" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

while IFS= read -r dir; do
    while IFS= read -r -d '' file; do
        if [ "$(basename $file)" != ".bash_history" ]; then
            sed -i 's/^\(\s*umask\s*\)/#\1/g' "$file"
        fi
    done &lt;   &lt;(find $dir -maxdepth 1 -type f -name ".*" -print0)
done &lt;   &lt;(awk -F':' '{ if ($3 &gt;= 1000 &amp;&amp; $3 != 65534) print $6}' /etc/passwd)

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="accounts_umask_interactive_users" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020352
  - accounts_umask_interactive_users
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure the Default Umask is Set Correctly For Interactive Users - Get interactive
    users from passwd file
  ansible.builtin.getent:
    database: passwd
  register: passwd_entries
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020352
  - accounts_umask_interactive_users
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure the Default Umask is Set Correctly For Interactive Users - Filter interactive
    users and get home directories
  ansible.builtin.set_fact:
    interactive_user_homes: '{{ interactive_user_homes | default([]) + [item.value[4]]
      }}'
  loop: '{{ passwd_entries.ansible_facts.getent_passwd | dict2items }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - item.value[2] | int &gt;= 1000 | int
  - item.value[2] | int != 65534 | int
  - item.value[4] != ""
  tags:
  - DISA-STIG-RHEL-08-020352
  - accounts_umask_interactive_users
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure the Default Umask is Set Correctly For Interactive Users - Find dot
    files in interactive user home directories
  ansible.builtin.find:
    paths: '{{ item }}'
    patterns: .*
    file_type: file
    hidden: true
    depth: 1
  register: user_dotfiles
  with_items: '{{ interactive_user_homes | default([]) }}'
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - item != ""
  tags:
  - DISA-STIG-RHEL-08-020352
  - accounts_umask_interactive_users
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure the Default Umask is Set Correctly For Interactive Users - Comment
    out umask statements in user initialization files
  ansible.builtin.replace:
    path: '{{ item.1.path }}'
    regexp: ^\s*umask\s+
    replace: '#\g&lt;0&gt;'
    backup: false
  with_subelements:
  - '{{ user_dotfiles.results }}'
  - files
  when:
  - '"kernel" in ansible_facts.packages'
  - item.0 is not skipped
  - item.1.path is defined
  - '''.bash_history'' not in item.1.path'
  tags:
  - DISA-STIG-RHEL-08-020352
  - accounts_umask_interactive_users
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_umask_interactive_users:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-accounts_umask_interactive_users_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_accounts_umask_root" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure the Root Bash Umask is Set Correctly</xccdf-1.2:title>
                <xccdf-1.2:description>To ensure the root user's umask of the Bash shell is set properly,
add or correct the <html:code>umask</html:code> setting in <html:code>/root/.bashrc</html:code>
or <html:code>/root/.profile</html:code> to read as follows:
<html:pre>umask 0027</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.4.2.6</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The umask value influences the permissions assigned to files when they are created.
A misconfigured umask value could result in files with excessive permissions that can be read or
written to by unauthorized users.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_bash"/>
                <xccdf-1.2:fix id="accounts_umask_root" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q bash; then

for file in /root/.bashrc /root/.profile; do
    if [ -f "$file" ]; then
        sed -i -E -e "s/^([^#]*\bumask)[[:space:]]+[[:digit:]]+/\1 0027/g" "$file"
    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-accounts_umask_root:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_bootloader-grub2">
          <xccdf-1.2:title>GRUB2 bootloader configuration</xccdf-1.2:title>
          <xccdf-1.2:description>During the boot process, the boot loader is
responsible for starting the execution of the kernel and passing
options to it. The boot loader allows for the selection of
different kernels - possibly on different partitions or media.
The default AlmaLinux OS 8 boot loader for x86 systems is called GRUB2.
Options it can pass to the kernel include <html:i>single-user mode</html:i>, which
provides root access without any authentication, and the ability to
disable SELinux. To prevent local users from modifying the boot
parameters and endangering security, protect the boot loader configuration
with a password and ensure its configuration file's permissions
are set properly.</xccdf-1.2:description>
          <xccdf-1.2:platform idref="#grub2_and_system_with_kernel"/>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_l1tf_options" type="string">
            <xccdf-1.2:title>L1TF vulnerability mitigation</xccdf-1.2:title>
            <xccdf-1.2:description>Defines the L1TF vulneratility mitigations to employ.</xccdf-1.2:description>
            <xccdf-1.2:value>flush</xccdf-1.2:value>
            <xccdf-1.2:value selector="full">full</xccdf-1.2:value>
            <xccdf-1.2:value selector="full_force">full,force</xccdf-1.2:value>
            <xccdf-1.2:value selector="flush">flush</xccdf-1.2:value>
            <xccdf-1.2:value selector="flush_nosmt">flush,nosmt</xccdf-1.2:value>
            <xccdf-1.2:value selector="flush_nowarn">flush,nowarn</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mds_options" type="string">
            <xccdf-1.2:title>MDS vulnerability mitigation</xccdf-1.2:title>
            <xccdf-1.2:description>Defines the MDS vulneratility mitigation to employ.</xccdf-1.2:description>
            <xccdf-1.2:value>full</xccdf-1.2:value>
            <xccdf-1.2:value selector="full">full</xccdf-1.2:value>
            <xccdf-1.2:value selector="full_nosmt">full,nosmt</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_rng_core_default_quality" interactive="true" type="string">
            <xccdf-1.2:title>Confidence level on Hardware Random Number Generator</xccdf-1.2:title>
            <xccdf-1.2:description>Defines the level of trust on the hardware random number generators available in the
system and the percentage of entropy to credit.</xccdf-1.2:description>
            <xccdf-1.2:value>500</xccdf-1.2:value>
            <xccdf-1.2:value selector="500">500</xccdf-1.2:value>
            <xccdf-1.2:value selector="512">512</xccdf-1.2:value>
            <xccdf-1.2:value selector="1000">1000</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_spec_store_bypass_disable_options" type="string">
            <xccdf-1.2:title>Spec Store Bypass Mitigation</xccdf-1.2:title>
            <xccdf-1.2:description>This controls how the Speculative Store Bypass (SSB) vulnerability is mitigated.</xccdf-1.2:description>
            <xccdf-1.2:value>prctl</xccdf-1.2:value>
            <xccdf-1.2:value selector="on">on</xccdf-1.2:value>
            <xccdf-1.2:value selector="auto">auto</xccdf-1.2:value>
            <xccdf-1.2:value selector="prctl">prctl</xccdf-1.2:value>
            <xccdf-1.2:value selector="seccomp">seccomp</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_disable_recovery" selected="false" severity="medium">
            <xccdf-1.2:title>Disable Recovery Booting</xccdf-1.2:title>
            <xccdf-1.2:description>AlmaLinux OS 8 systems support an "recovery boot" option that can be used
to prevent services from being started. The <html:code>GRUB_DISABLE_RECOVERY</html:code>
configuration option in <html:code>/etc/default/grub</html:code> should be set to
<html:code>true</html:code> to disable the generation of recovery mode menu entries. It is
also required to change the runtime configuration, run:
<html:pre>$ sudo grubby --update-kernel=ALL --env=/boot/grub2/grubenv</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_UAU.1</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Using recovery boot, the console user could disable auditing, firewalls,
or other services, weakening system security.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="grub2_disable_recovery" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ); then

if grep -q '^GRUB_DISABLE_RECOVERY=.*'  '/etc/default/grub' ; then
    sed -i 's/GRUB_DISABLE_RECOVERY=.*/GRUB_DISABLE_RECOVERY=true/' "/etc/default/grub"
else
    echo "GRUB_DISABLE_RECOVERY=true" &gt;&gt; '/etc/default/grub'
fi

grubby --update-kernel=ALL --env=/boot/grub2/grubenv

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="grub2_disable_recovery" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - grub2_disable_recovery
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Disable Recovery Booting - Verify GRUB_DISABLE_RECOVERY=true
  ansible.builtin.lineinfile:
    path: /etc/default/grub
    regexp: ^GRUB_DISABLE_RECOVERY=.*
    line: GRUB_DISABLE_RECOVERY=true
    state: present
  register: grub_config_changed
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_disable_recovery
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Disable Recovery Booting - Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - grub_config_changed is changed
  tags:
  - grub2_disable_recovery
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_disable_recovery:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_disable_recovery_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_enable_iommu_force" selected="false" severity="unknown">
            <xccdf-1.2:title>IOMMU configuration directive</xccdf-1.2:title>
            <xccdf-1.2:description>On x86 architecture supporting VT-d, the IOMMU manages the access control policy between the hardware devices and some
    of the system critical units such as the memory.
Configure the default Grub2 kernel command line to contain iommu=force as follows:
<html:pre># grub2-editenv - set "$(grub2-editenv - list | grep kernelopts) iommu=force"</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="functionality">Depending on the hardware, devices and operating system used, enabling IOMMU can cause hardware instabilities. Proper function and stability should be assessed before applying remediation to production systems.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R7</xccdf-1.2:reference>
            <xccdf-1.2:rationale>On x86 architectures, activating the I/OMMU prevents the system from arbitrary accesses potentially made by
    hardware devices.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="grub2_enable_iommu_force" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ); then

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    KARGS_DIR="/usr/lib/bootc/kargs.d/"
    if grep -q -E "iommu" "$KARGS_DIR/*.toml" ; then
        sed -i -E "s/^(\s*kargs\s*=\s*\[.*)\"iommu=[^\"]*\"(.*]\s*)/\1\"iommu=force\"\2/" "$KARGS_DIR/*.toml"
    else
        echo "kargs = [\"iommu=force\"]" &gt;&gt; "$KARGS_DIR/10-iommu.toml"
    fi
else

    grubby --update-kernel=ALL --args=iommu=force --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_enable_iommu_force" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - grub2_enable_iommu_force
  - low_disruption
  - medium_complexity
  - reboot_required
  - restrict_strategy
  - unknown_severity

- name: Check if iommu argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_enable_iommu_force
  - low_disruption
  - medium_complexity
  - reboot_required
  - restrict_strategy
  - unknown_severity

- name: Check if iommu argument is already present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_enable_iommu_force
  - low_disruption
  - medium_complexity
  - reboot_required
  - restrict_strategy
  - unknown_severity

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --args="iommu=force"
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - (grubby_info.stdout is not search('iommu=force')) or ((etc_default_grub['content']
    | b64decode) is not search('iommu=force'))
  tags:
  - grub2_enable_iommu_force
  - low_disruption
  - medium_complexity
  - reboot_required
  - restrict_strategy
  - unknown_severity
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="grub2_enable_iommu_force" system="urn:redhat:osbuild:blueprint">[customizations.kernel]
append = "iommu=force"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_enable_iommu_force" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kickstart">
bootloader iommu=force
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_enable_iommu_force:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_init_on_free" selected="false" severity="medium">
            <xccdf-1.2:title>The system must booted with init_on_free=1</xccdf-1.2:title>
            <xccdf-1.2:description>Setting <html:code>init_on_free=1</html:code> on boot guarantees that pages and heap objects are initialized right after they're freed, so it won't be possible to access stale data by using a dangling pointer.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000134-GPOS-00068</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010423</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230279r1069286_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale><html:code>init_on_free</html:code> is a Linux kernel boot parameter that enhances security by initializing memory regions when they are freed, preventing data leakage.
This process ensures that stale data in freed memory cannot be accessed by malicious programs.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#grub2"/>
            <xccdf-1.2:fix id="grub2_init_on_free" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ) &amp;&amp; { rpm --quiet -q grub2-common; }; then

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    KARGS_DIR="/usr/lib/bootc/kargs.d/"
    if grep -q -E "init_on_free" "$KARGS_DIR/*.toml" ; then
        sed -i -E "s/^(\s*kargs\s*=\s*\[.*)\"init_on_free=[^\"]*\"(.*]\s*)/\1\"init_on_free=1\"\2/" "$KARGS_DIR/*.toml"
    else
        echo "kargs = [\"init_on_free=1\"]" &gt;&gt; "$KARGS_DIR/10-init_on_free.toml"
    fi
else

    grubby --update-kernel=ALL --args=init_on_free=1 --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_init_on_free" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010423
  - NIST-800-53-SC-3
  - grub2_init_on_free
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if init_on_free argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - '"grub2-common" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010423
  - NIST-800-53-SC-3
  - grub2_init_on_free
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if init_on_free argument is already present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - '"grub2-common" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010423
  - NIST-800-53-SC-3
  - grub2_init_on_free
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --args="init_on_free=1"
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - '"grub2-common" in ansible_facts.packages'
  - (grubby_info.stdout is not search('init_on_free=1')) or ((etc_default_grub['content']
    | b64decode) is not search('init_on_free=1'))
  tags:
  - DISA-STIG-RHEL-08-010423
  - NIST-800-53-SC-3
  - grub2_init_on_free
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="grub2_init_on_free" system="urn:redhat:osbuild:blueprint">[customizations.kernel]
append = "init_on_free=1"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_init_on_free" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kickstart">
bootloader init_on_free=1
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_init_on_free:def:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_kernel_trust_cpu_rng" selected="false" severity="medium">
            <xccdf-1.2:title>Configure kernel to trust the CPU random number generator</xccdf-1.2:title>
            <xccdf-1.2:description>There exist two ways how to ensure that the Linux kernel trusts the CPU
hardware random number generator. If the option is configured during kernel
compilation, e.g. the option <html:code>CONFIG_RANDOM_TRUST_CPU</html:code> is set to
<html:code>Y</html:code>, make sure that it is not overridden with the boot parameter.
There must not exist the boot parameter <html:code>random.trust_cpu=off</html:code>. If
the option is not compiled in, make sure that <html:code>random.trust_cpu=on</html:code>
is configured as a boot parameter.
Configure the default Grub2 kernel command line to contain random.trust_cpu=on as follows:
<html:pre># grub2-editenv - set "$(grub2-editenv - list | grep kernelopts) random.trust_cpu=on"</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The Linux kernel offers an option which signifies if the kernel should trust
data provided by CPU hardware random number generator. Hardware random
number generators can provide random data very quickly and are used to generate random cryptographic keys. They can
be useful during boot time when other means of getting random data can be
slow because there is not yet enough entropy in the system.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="grub2_kernel_trust_cpu_rng" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ); then

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    KARGS_DIR="/usr/lib/bootc/kargs.d/"
    if grep -q -E "random.trust_cpu" "$KARGS_DIR/*.toml" ; then
        sed -i -E "s/^(\s*kargs\s*=\s*\[.*)\"random.trust_cpu=[^\"]*\"(.*]\s*)/\1\"random.trust_cpu=on\"\2/" "$KARGS_DIR/*.toml"
    else
        echo "kargs = [\"random.trust_cpu=on\"]" &gt;&gt; "$KARGS_DIR/10-random_trust_cpu.toml"
    fi
else

    grubby --update-kernel=ALL --args=random.trust_cpu=on --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_kernel_trust_cpu_rng" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - grub2_kernel_trust_cpu_rng
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if random.trust_cpu argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_kernel_trust_cpu_rng
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if random.trust_cpu argument is already present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_kernel_trust_cpu_rng
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --args="random.trust_cpu=on"
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - (grubby_info.stdout is not search('random.trust_cpu=on')) or ((etc_default_grub['content']
    | b64decode) is not search('random.trust_cpu=on'))
  tags:
  - grub2_kernel_trust_cpu_rng
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="grub2_kernel_trust_cpu_rng" system="urn:redhat:osbuild:blueprint">[customizations.kernel]
append = "random.trust_cpu=on"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_kernel_trust_cpu_rng" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kickstart">
bootloader random.trust_cpu=on
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_kernel_trust_cpu_rng:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_kernel_trust_cpu_rng_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_l1tf_argument" selected="false" severity="high">
            <xccdf-1.2:title>Configure L1 Terminal Fault mitigations</xccdf-1.2:title>
            <xccdf-1.2:description>L1 Terminal Fault (L1TF) is a hardware vulnerability which allows unprivileged
speculative access to data which is available in the Level 1 Data Cache when
the page table entry isn't present.

Select the appropriate mitigation by adding the argument
<html:code>l1tf=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_l1tf_options" use="legacy"/></html:code> to the default
GRUB 2 command line for the Linux operating system.
Configure the default Grub2 kernel command line to contain l1tf=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_l1tf_options" use="legacy"/> as follows:
<html:pre># grub2-editenv - set "$(grub2-editenv - list | grep kernelopts) l1tf=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_l1tf_options" use="legacy"/>"</html:pre>

Since Linux Kernel 4.19 you can check the L1TF vulnerability state with the
following command:
<html:code>cat /sys/devices/system/cpu/vulnerabilities/l1tf</html:code></xccdf-1.2:description>
            <xccdf-1.2:warning category="performance">Enabling L1TF mitigations may impact performance of the system.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R8</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The L1TF vulnerability allows an attacker to bypass memory access security controls imposed
by the system or hypervisor. The L1TF vulnerability allows read access to any physical memory
location that is cached in the L1 Data Cache.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="grub2_l1tf_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ); then

var_l1tf_options='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_l1tf_options" use="legacy"/>'



if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    KARGS_DIR="/usr/lib/bootc/kargs.d/"
    if grep -q -E "l1tf" "$KARGS_DIR/*.toml" ; then
        sed -i -E "s/^(\s*kargs\s*=\s*\[.*)\"l1tf=[^\"]*\"(.*]\s*)/\1\"l1tf=$var_l1tf_options\"\2/" "$KARGS_DIR/*.toml"
    else
        echo "kargs = [\"l1tf=$var_l1tf_options\"]" &gt;&gt; "$KARGS_DIR/10-l1tf.toml"
    fi
else

    grubby --update-kernel=ALL --args=l1tf=$var_l1tf_options --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_l1tf_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - grub2_l1tf_argument
  - high_severity
  - low_disruption
  - medium_complexity
  - reboot_required
  - restrict_strategy
- name: XCCDF Value var_l1tf_options # promote to variable
  set_fact:
    var_l1tf_options: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_l1tf_options" use="legacy"/>
  tags:
    - always

- name: Check if l1tf argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_l1tf_argument
  - high_severity
  - low_disruption
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Check if l1tf argument is already present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_l1tf_argument
  - high_severity
  - low_disruption
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --args="l1tf={{ var_l1tf_options
    }}"
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - (grubby_info.stdout is not search('l1tf=' ~ var_l1tf_options)) or ((etc_default_grub['content']
    | b64decode) is not search('l1tf=' ~ var_l1tf_options))
  tags:
  - grub2_l1tf_argument
  - high_severity
  - low_disruption
  - medium_complexity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="grub2_l1tf_argument" system="urn:redhat:osbuild:blueprint">[customizations.kernel]
append = "l1tf=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_l1tf_options" use="legacy"/>"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_l1tf_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kickstart">
bootloader l1tf=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_l1tf_options" use="legacy"/>
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_l1tf_options:var:1" value-id="xccdf_org.ssgproject.content_value_var_l1tf_options"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_l1tf_argument:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_mce_argument" selected="false" severity="medium">
            <xccdf-1.2:title>Force kernel panic on uncorrected MCEs</xccdf-1.2:title>
            <xccdf-1.2:description>A Machine Check Exception is an error generated by the CPU itdetects an error
in itself, memory or I/O devices.
These errors may be corrected and generate a check log entry, if an error
cannot be corrected the kernel may panic or SIGBUS.

To force the kernel to panic on any uncorrected error reported by Machine Check
set the MCE tolerance to zero by adding <html:code>mce=0</html:code>
to the default GRUB 2 command line for the Linux operating system.
Configure the default Grub2 kernel command line to contain mce=0 as follows:
<html:pre># grub2-editenv - set "$(grub2-editenv - list | grep kernelopts) mce=0"</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R8</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Allowing uncorrected errors to result on a SIGBUS may allow an attacker to continue
trying to exploit a vulnerability such as Rowhammer.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="grub2_mce_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ); then

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    KARGS_DIR="/usr/lib/bootc/kargs.d/"
    if grep -q -E "mce" "$KARGS_DIR/*.toml" ; then
        sed -i -E "s/^(\s*kargs\s*=\s*\[.*)\"mce=[^\"]*\"(.*]\s*)/\1\"mce=0\"\2/" "$KARGS_DIR/*.toml"
    else
        echo "kargs = [\"mce=0\"]" &gt;&gt; "$KARGS_DIR/10-mce.toml"
    fi
else

    grubby --update-kernel=ALL --args=mce=0 --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_mce_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - grub2_mce_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if mce argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_mce_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if mce argument is already present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_mce_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --args="mce=0"
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - (grubby_info.stdout is not search('mce=0')) or ((etc_default_grub['content'] |
    b64decode) is not search('mce=0'))
  tags:
  - grub2_mce_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="grub2_mce_argument" system="urn:redhat:osbuild:blueprint">[customizations.kernel]
append = "mce=0"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_mce_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kickstart">
bootloader mce=0
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_mce_argument:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_mce_argument_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_nosmap_argument_absent" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure SMAP is not disabled during boot</xccdf-1.2:title>
            <xccdf-1.2:description>The SMAP is used to prevent the supervisor mode from unintentionally reading/writing into
memory pages in the user space, it is enabled by default since Linux kernel 3.7.
But it could be disabled through kernel boot parameters.

Ensure that Supervisor Mode Access Prevention (SMAP) is not disabled by
the <html:code>nosmap</html:code> boot parameter option.

Check that the line <html:pre>GRUB_CMDLINE_LINUX="..."</html:pre> within <html:code>/etc/default/grub</html:code>
doesn't contain the argument <html:code>nosmap</html:code>.
Run the following command to update command line for already installed kernels:
<html:pre># grubby --update-kernel=ALL --remove-args="nosmap"</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R1</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Disabling SMAP can facilitate exploitation of vulnerabilities caused by unintended access and
manipulation of data in the user space.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="grub2_nosmap_argument_absent" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ); then

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    sed -i -E "/kargs\s*=\s*\[\s*\"nosmap=[^\"]*\"\s*]/{:a;N;/^\n$/ba;N;/match-architectures.*/d;}" "$KARGS_DIR/*.toml"
    sed -i -E -e "s/^(\s*kargs\s*=\s*\[.*)\"nosmap=[^\"]*\"[,[:space:]]*(.*]\s*)/\1\2/" -e "s/^(\s*kargs.*),\s*\]$/\1\]/" "$KARGS_DIR/*.toml"
else

grubby --update-kernel=ALL --remove-args=nosmap --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_nosmap_argument_absent" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - grub2_nosmap_argument_absent
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if nosmap argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_nosmap_argument_absent
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if nosmap argument is present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_nosmap_argument_absent
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --remove-args="nosmap"
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - (grubby_info.stdout is search('nosmap')) or ((etc_default_grub['content'] | b64decode)
    is search('nosmap'))
  tags:
  - grub2_nosmap_argument_absent
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_nosmap_argument_absent:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_nosmap_argument_absent_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_nosmep_argument_absent" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure SMEP is not disabled during boot</xccdf-1.2:title>
            <xccdf-1.2:description>The SMEP is used to prevent the supervisor mode from executing user space code,
it is enabled by default since Linux kernel 3.0. But it could be disabled through
kernel boot parameters.

Ensure that Supervisor Mode Execution Prevention (SMEP) is not disabled by
the <html:code>nosmep</html:code> boot parameter option.

Check that the line <html:pre>GRUB_CMDLINE_LINUX="..."</html:pre> within <html:code>/etc/default/grub</html:code>
doesn't contain the argument <html:code>nosmep</html:code>.
Run the following command to update command line for already installed kernels:
<html:pre># grubby --update-kernel=ALL --remove-args="nosmep"</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R1</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Disabling SMEP can facilitate exploitation of certain vulnerabilities because it allows
the kernel to unintentionally execute code in less privileged memory space.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="grub2_nosmep_argument_absent" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ); then

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    sed -i -E "/kargs\s*=\s*\[\s*\"nosmep=[^\"]*\"\s*]/{:a;N;/^\n$/ba;N;/match-architectures.*/d;}" "$KARGS_DIR/*.toml"
    sed -i -E -e "s/^(\s*kargs\s*=\s*\[.*)\"nosmep=[^\"]*\"[,[:space:]]*(.*]\s*)/\1\2/" -e "s/^(\s*kargs.*),\s*\]$/\1\]/" "$KARGS_DIR/*.toml"
else

grubby --update-kernel=ALL --remove-args=nosmep --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_nosmep_argument_absent" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - grub2_nosmep_argument_absent
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if nosmep argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_nosmep_argument_absent
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if nosmep argument is present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_nosmep_argument_absent
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --remove-args="nosmep"
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - (grubby_info.stdout is search('nosmep')) or ((etc_default_grub['content'] | b64decode)
    is search('nosmep'))
  tags:
  - grub2_nosmep_argument_absent
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_nosmep_argument_absent:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_nosmep_argument_absent_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_pti_argument" selected="false" severity="low">
            <xccdf-1.2:title>Enable Kernel Page-Table Isolation (KPTI)</xccdf-1.2:title>
            <xccdf-1.2:description>To enable Kernel page-table isolation,
add the argument <html:code>pti=on</html:code> to the default
GRUB 2 command line for the Linux operating system.
Configure the default Grub2 kernel command line to contain pti=on as follows:
<html:pre># grub2-editenv - set "$(grub2-editenv - list | grep kernelopts) pti=on"</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000433-GPOS-00193</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040004</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230491r1017274_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Kernel page-table isolation is a kernel feature that mitigates
the Meltdown security vulnerability and hardens the kernel
against attempts to bypass kernel address space layout
randomization (KASLR).</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="grub2_pti_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ); then

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    KARGS_DIR="/usr/lib/bootc/kargs.d/"
    if grep -q -E "pti" "$KARGS_DIR/*.toml" ; then
        sed -i -E "s/^(\s*kargs\s*=\s*\[.*)\"pti=[^\"]*\"(.*]\s*)/\1\"pti=on\"\2/" "$KARGS_DIR/*.toml"
    else
        echo "kargs = [\"pti=on\"]" &gt;&gt; "$KARGS_DIR/10-pti.toml"
    fi
else

    grubby --update-kernel=ALL --args=pti=on --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_pti_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040004
  - NIST-800-53-SI-16
  - grub2_pti_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Check if pti argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - DISA-STIG-RHEL-08-040004
  - NIST-800-53-SI-16
  - grub2_pti_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Check if pti argument is already present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - DISA-STIG-RHEL-08-040004
  - NIST-800-53-SI-16
  - grub2_pti_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --args="pti=on"
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - (grubby_info.stdout is not search('pti=on')) or ((etc_default_grub['content']
    | b64decode) is not search('pti=on'))
  tags:
  - DISA-STIG-RHEL-08-040004
  - NIST-800-53-SI-16
  - grub2_pti_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="grub2_pti_argument" system="urn:redhat:osbuild:blueprint">[customizations.kernel]
append = "pti=on"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_pti_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kickstart">
bootloader pti=on
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_pti_argument:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_pti_argument_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_rng_core_default_quality_argument" selected="false" severity="low">
            <xccdf-1.2:title>Configure the confidence in TPM for entropy</xccdf-1.2:title>
            <xccdf-1.2:description>The TPM security chip that is available in most modern systems has a hardware RNG.
It is also used to feed the entropy pool, but generally not credited entropy.

Use <html:code>rng_core.default_quality</html:code> in the kernel command line to set the trust
level on the hardware generators. The trust level defines the amount of entropy to credit.
A value of <html:code>0</html:code> tells the system not to trust the hardware random number generators
available, and doesn't credit any entropy to the pool.
A value of <html:code>1000</html:code> assigns full confidence in the generators, and credits all the
entropy it provides to the pool.

Note that the value of <html:code>rng_core.default_quality</html:code> is global, affecting the trust
on all hardware random number generators.

Select the appropriate confidence by adding the argument
<html:code>rng_core.default_quality=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rng_core_default_quality" use="legacy"/></html:code> to the default
GRUB 2 command line for the Linux operating system.
Configure the default Grub2 kernel command line to contain rng_core.default_quality=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rng_core_default_quality" use="legacy"/> as follows:
<html:pre># grub2-editenv - set "$(grub2-editenv - list | grep kernelopts) rng_core.default_quality=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rng_core_default_quality" use="legacy"/>"</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R8</xccdf-1.2:reference>
            <xccdf-1.2:rationale>A system may struggle to initialize its entropy pool and end up starving. Crediting entropy
from the hardware number generators available in the system helps fill up the entropy pool.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="grub2_rng_core_default_quality_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ); then

var_rng_core_default_quality='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rng_core_default_quality" use="legacy"/>'



if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    KARGS_DIR="/usr/lib/bootc/kargs.d/"
    if grep -q -E "rng_core.default_quality" "$KARGS_DIR/*.toml" ; then
        sed -i -E "s/^(\s*kargs\s*=\s*\[.*)\"rng_core.default_quality=[^\"]*\"(.*]\s*)/\1\"rng_core.default_quality=$var_rng_core_default_quality\"\2/" "$KARGS_DIR/*.toml"
    else
        echo "kargs = [\"rng_core.default_quality=$var_rng_core_default_quality\"]" &gt;&gt; "$KARGS_DIR/10-rng_core_default_quality.toml"
    fi
else

    grubby --update-kernel=ALL --args=rng_core.default_quality=$var_rng_core_default_quality --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_rng_core_default_quality_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - grub2_rng_core_default_quality_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy
- name: XCCDF Value var_rng_core_default_quality # promote to variable
  set_fact:
    var_rng_core_default_quality: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rng_core_default_quality" use="legacy"/>
  tags:
    - always

- name: Check if rng_core.default_quality argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_rng_core_default_quality_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Check if rng_core.default_quality argument is already present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_rng_core_default_quality_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --args="rng_core.default_quality={{
    var_rng_core_default_quality }}"
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - (grubby_info.stdout is not search('rng_core.default_quality=' ~ var_rng_core_default_quality))
    or ((etc_default_grub['content'] | b64decode) is not search('rng_core.default_quality='
    ~ var_rng_core_default_quality))
  tags:
  - grub2_rng_core_default_quality_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="grub2_rng_core_default_quality_argument" system="urn:redhat:osbuild:blueprint">[customizations.kernel]
append = "rng_core.default_quality=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rng_core_default_quality" use="legacy"/>"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_rng_core_default_quality_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kickstart">
bootloader rng_core.default_quality=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rng_core_default_quality" use="legacy"/>
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_rng_core_default_quality:var:1" value-id="xccdf_org.ssgproject.content_value_var_rng_core_default_quality"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_rng_core_default_quality_argument:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_rng_core_default_quality_argument_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_slab_nomerge_argument" selected="false" severity="medium">
            <xccdf-1.2:title>Disable merging of slabs with similar size</xccdf-1.2:title>
            <xccdf-1.2:description>The kernel may merge similar slabs together to reduce overhead and increase
cache hotness of objects.
Disabling merging of slabs keeps the slabs separate and reduces the risk of
kernel heap overflows overwriting objects in merged caches.

To disable merging of slabs in the Kernel add the argument <html:code>slab_nomerge=yes</html:code>
to the default GRUB 2 command line for the Linux operating system.
Configure the default Grub2 kernel command line to contain slab_nomerge=yes as follows:
<html:pre># grub2-editenv - set "$(grub2-editenv - list | grep kernelopts) slab_nomerge=yes"</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="performance">Disabling merge of slabs will slightly increase kernel memory utilization.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R8</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Disabling the merge of slabs of similar sizes prevents the kernel from
merging a seemingly useless but vulnerable slab with a useful and valuable slab.
This increase the risk that a heap overflow could overwrite objects from merged caches,
with unmerged caches the heap overflow would only affect the objects in the same cache.
Overall, this reduces the kernel attack surface area by isolating slabs from each other.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="grub2_slab_nomerge_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ); then

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    KARGS_DIR="/usr/lib/bootc/kargs.d/"
    if grep -q -E "slab_nomerge" "$KARGS_DIR/*.toml" ; then
        sed -i -E "s/^(\s*kargs\s*=\s*\[.*)\"slab_nomerge=[^\"]*\"(.*]\s*)/\1\"slab_nomerge=yes\"\2/" "$KARGS_DIR/*.toml"
    else
        echo "kargs = [\"slab_nomerge=yes\"]" &gt;&gt; "$KARGS_DIR/10-slab_nomerge.toml"
    fi
else

    grubby --update-kernel=ALL --args=slab_nomerge=yes --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_slab_nomerge_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - grub2_slab_nomerge_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if slab_nomerge argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_slab_nomerge_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if slab_nomerge argument is already present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_slab_nomerge_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --args="slab_nomerge=yes"
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - (grubby_info.stdout is not search('slab_nomerge=yes')) or ((etc_default_grub['content']
    | b64decode) is not search('slab_nomerge=yes'))
  tags:
  - grub2_slab_nomerge_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="grub2_slab_nomerge_argument" system="urn:redhat:osbuild:blueprint">[customizations.kernel]
append = "slab_nomerge=yes"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_slab_nomerge_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kickstart">
bootloader slab_nomerge=yes
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_slab_nomerge_argument:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_spec_store_bypass_disable_argument" selected="false" severity="medium">
            <xccdf-1.2:title>Configure Speculative Store Bypass Mitigation</xccdf-1.2:title>
            <xccdf-1.2:description>Certain CPUs are vulnerable to an exploit against a common wide industry wide performance
optimization known as Speculative Store Bypass (SSB).

In such cases, recent stores to the same memory location cannot always be observed by later
loads during speculative execution. However, such stores are unlikely and thus they can be
detected prior to instruction retirement at the end of a particular speculation execution
window.

Since Linux Kernel 4.17 you can check the SSB mitigation state with the following command:
<html:code>cat /sys/devices/system/cpu/vulnerabilities/spec_store_bypass</html:code>

Select the appropriate SSB state by adding the argument
<html:code>spec_store_bypass_disable=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_spec_store_bypass_disable_options" use="legacy"/></html:code> to the default
GRUB 2 command line for the Linux operating system.
Configure the default Grub2 kernel command line to contain spec_store_bypass_disable=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_spec_store_bypass_disable_options" use="legacy"/> as follows:
<html:pre># grub2-editenv - set "$(grub2-editenv - list | grep kernelopts) spec_store_bypass_disable=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_spec_store_bypass_disable_options" use="legacy"/>"</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="performance">Disabling Speculative Store Bypass may impact performance of the system.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R8</xccdf-1.2:reference>
            <xccdf-1.2:rationale>In vulnerable processors, the speculatively forwarded store can be used in a cache side channel
attack. An example of this is reading memory to which the attacker does not directly have access,
for example inside the sandboxed code.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="grub2_spec_store_bypass_disable_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ); then

var_spec_store_bypass_disable_options='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_spec_store_bypass_disable_options" use="legacy"/>'



if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    KARGS_DIR="/usr/lib/bootc/kargs.d/"
    if grep -q -E "spec_store_bypass_disable" "$KARGS_DIR/*.toml" ; then
        sed -i -E "s/^(\s*kargs\s*=\s*\[.*)\"spec_store_bypass_disable=[^\"]*\"(.*]\s*)/\1\"spec_store_bypass_disable=$var_spec_store_bypass_disable_options\"\2/" "$KARGS_DIR/*.toml"
    else
        echo "kargs = [\"spec_store_bypass_disable=$var_spec_store_bypass_disable_options\"]" &gt;&gt; "$KARGS_DIR/10-spec_store_bypass_disable.toml"
    fi
else

    grubby --update-kernel=ALL --args=spec_store_bypass_disable=$var_spec_store_bypass_disable_options --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_spec_store_bypass_disable_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - grub2_spec_store_bypass_disable_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy
- name: XCCDF Value var_spec_store_bypass_disable_options # promote to variable
  set_fact:
    var_spec_store_bypass_disable_options: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_spec_store_bypass_disable_options" use="legacy"/>
  tags:
    - always

- name: Check if spec_store_bypass_disable argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_spec_store_bypass_disable_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if spec_store_bypass_disable argument is already present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_spec_store_bypass_disable_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --args="spec_store_bypass_disable={{
    var_spec_store_bypass_disable_options }}"
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - (grubby_info.stdout is not search('spec_store_bypass_disable=' ~ var_spec_store_bypass_disable_options))
    or ((etc_default_grub['content'] | b64decode) is not search('spec_store_bypass_disable='
    ~ var_spec_store_bypass_disable_options))
  tags:
  - grub2_spec_store_bypass_disable_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="grub2_spec_store_bypass_disable_argument" system="urn:redhat:osbuild:blueprint">[customizations.kernel]
append = "spec_store_bypass_disable=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_spec_store_bypass_disable_options" use="legacy"/>"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_spec_store_bypass_disable_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kickstart">
bootloader spec_store_bypass_disable=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_spec_store_bypass_disable_options" use="legacy"/>
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_spec_store_bypass_disable_options:var:1" value-id="xccdf_org.ssgproject.content_value_var_spec_store_bypass_disable_options"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_spec_store_bypass_disable_argument:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_spectre_v2_argument" selected="false" severity="high">
            <xccdf-1.2:title>Enforce Spectre v2 mitigation</xccdf-1.2:title>
            <xccdf-1.2:description>Spectre V2 is an indirect branch poisoning attack that can lead to data leakage.
An exploit for Spectre V2 tricks the indirect branch predictor into executing
code from a future indirect branch chosen by the attacker, even if the privilege
level is different.

Since Linux Kernel 4.15 you can check the Spectre V2 mitigation state with the following command:
<html:code>cat /sys/devices/system/cpu/vulnerabilities/spectre_v2</html:code>

Enforce the Spectre V2 mitigation by adding the argument
<html:code>spectre_v2=on</html:code> to the default
GRUB 2 command line for the Linux operating system.
Configure the default Grub2 kernel command line to contain spectre_v2=on as follows:
<html:pre># grub2-editenv - set "$(grub2-editenv - list | grep kernelopts) spectre_v2=on"</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R8</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The Spectre V2 vulnerability allows an attacker to read memory that he should not have
access to.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="grub2_spectre_v2_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ); then

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    KARGS_DIR="/usr/lib/bootc/kargs.d/"
    if grep -q -E "spectre_v2" "$KARGS_DIR/*.toml" ; then
        sed -i -E "s/^(\s*kargs\s*=\s*\[.*)\"spectre_v2=[^\"]*\"(.*]\s*)/\1\"spectre_v2=on\"\2/" "$KARGS_DIR/*.toml"
    else
        echo "kargs = [\"spectre_v2=on\"]" &gt;&gt; "$KARGS_DIR/10-spectre_v2.toml"
    fi
else

    grubby --update-kernel=ALL --args=spectre_v2=on --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_spectre_v2_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - grub2_spectre_v2_argument
  - high_severity
  - low_disruption
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Check if spectre_v2 argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_spectre_v2_argument
  - high_severity
  - low_disruption
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Check if spectre_v2 argument is already present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_spectre_v2_argument
  - high_severity
  - low_disruption
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --args="spectre_v2=on"
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - (grubby_info.stdout is not search('spectre_v2=on')) or ((etc_default_grub['content']
    | b64decode) is not search('spectre_v2=on'))
  tags:
  - grub2_spectre_v2_argument
  - high_severity
  - low_disruption
  - medium_complexity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="grub2_spectre_v2_argument" system="urn:redhat:osbuild:blueprint">[customizations.kernel]
append = "spectre_v2=on"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_spectre_v2_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kickstart">
bootloader spectre_v2=on
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_spectre_v2_argument:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_spectre_v2_argument_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_systemd_debug-shell_argument_absent" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure debug-shell service is not enabled during boot</xccdf-1.2:title>
            <xccdf-1.2:description>systemd's <html:code>debug-shell</html:code> service is intended to
diagnose systemd related boot issues with various <html:code>systemctl</html:code>
commands. Once enabled and following a system reboot, the root shell
will be available on <html:code>tty9</html:code> which is access by pressing
<html:code>CTRL-ALT-F9</html:code>. The <html:code>debug-shell</html:code> service should only be used
for systemd related issues and should otherwise be disabled.
<html:br/><html:br/>
By default, the <html:code>debug-shell</html:code> systemd service is already disabled.

Ensure the debug-shell is not enabled by the <html:code>systemd.debug-shel=1</html:code>
boot parameter option.

Check that the line <html:pre>GRUB_CMDLINE_LINUX="..."</html:pre> within <html:code>/etc/default/grub</html:code>
doesn't contain the argument <html:code>systemd.debug-shell</html:code>.
Run the following command to update command line for already installed kernels:
<html:pre># grubby --update-kernel=ALL --remove-args="systemd.debug-shell"</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_UAU.1</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This prevents attackers with physical access from trivially bypassing security
on the machine through valid troubleshooting configurations and gaining root
access when the system is rebooted.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="grub2_systemd_debug-shell_argument_absent" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ); then

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    sed -i -E "/kargs\s*=\s*\[\s*\"systemd.debug-shell=[^\"]*\"\s*]/{:a;N;/^\n$/ba;N;/match-architectures.*/d;}" "$KARGS_DIR/*.toml"
    sed -i -E -e "s/^(\s*kargs\s*=\s*\[.*)\"systemd.debug-shell=[^\"]*\"[,[:space:]]*(.*]\s*)/\1\2/" -e "s/^(\s*kargs.*),\s*\]$/\1\]/" "$KARGS_DIR/*.toml"
else

grubby --update-kernel=ALL --remove-args=systemd.debug-shell --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_systemd_debug-shell_argument_absent" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - grub2_systemd_debug-shell_argument_absent
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if systemd.debug-shell argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_systemd_debug-shell_argument_absent
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if systemd.debug-shell argument is present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when: ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - grub2_systemd_debug-shell_argument_absent
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --remove-args="systemd.debug-shell"
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - (grubby_info.stdout is search('systemd.debug-shell')) or ((etc_default_grub['content']
    | b64decode) is search('systemd.debug-shell'))
  tags:
  - grub2_systemd_debug-shell_argument_absent
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_systemd_debug-shell_argument_absent:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_systemd_debug-shell_argument_absent_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_vsyscall_argument" selected="false" severity="medium">
            <xccdf-1.2:title>Disable vsyscalls</xccdf-1.2:title>
            <xccdf-1.2:description>To disable use of virtual syscalls,
add the argument <html:code>vsyscall=none</html:code> to the default
GRUB 2 command line for the Linux operating system.
Configure the default Grub2 kernel command line to contain vsyscall=none as follows:
<html:pre># grub2-editenv - set "$(grub2-editenv - list | grep kernelopts) vsyscall=none"</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">The vsyscall emulation is only available on x86_64 architecture
(CONFIG_X86_VSYSCALL_EMULATION) making this rule not applicable
to other CPU architectures.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_ASLR_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000134-GPOS-00068</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010422</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230278r1017091_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Virtual Syscalls provide an opportunity of attack for a user who has control
of the return instruction pointer.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#x86_64_arch"/>
            <xccdf-1.2:fix id="grub2_vsyscall_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ) &amp;&amp; { ( ( grep -sqE "^.*\.x86_64$" /proc/sys/kernel/osrelease || grep -sqE "^x86_64$" /proc/sys/kernel/arch; ) ); }; then

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    KARGS_DIR="/usr/lib/bootc/kargs.d/"
    if grep -q -E "vsyscall" "$KARGS_DIR/*.toml" ; then
        sed -i -E "s/^(\s*kargs\s*=\s*\[.*)\"vsyscall=[^\"]*\"(.*]\s*)/\1\"vsyscall=none\"\2/" "$KARGS_DIR/*.toml"
    else
        echo "kargs = [\"vsyscall=none\"]" &gt;&gt; "$KARGS_DIR/10-vsyscall.toml"
    fi
else

    grubby --update-kernel=ALL --args=vsyscall=none --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_vsyscall_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010422
  - NIST-800-53-CM-7(a)
  - grub2_vsyscall_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if vsyscall argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - ansible_architecture == "x86_64"
  tags:
  - DISA-STIG-RHEL-08-010422
  - NIST-800-53-CM-7(a)
  - grub2_vsyscall_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if vsyscall argument is already present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - ansible_architecture == "x86_64"
  tags:
  - DISA-STIG-RHEL-08-010422
  - NIST-800-53-CM-7(a)
  - grub2_vsyscall_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --args="vsyscall=none"
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - ansible_architecture == "x86_64"
  - (grubby_info.stdout is not search('vsyscall=none')) or ((etc_default_grub['content']
    | b64decode) is not search('vsyscall=none'))
  tags:
  - DISA-STIG-RHEL-08-010422
  - NIST-800-53-CM-7(a)
  - grub2_vsyscall_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="grub2_vsyscall_argument" system="urn:redhat:osbuild:blueprint">[customizations.kernel]
append = "vsyscall=none"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_vsyscall_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kickstart">
bootloader vsyscall=none
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_vsyscall_argument:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_vsyscall_argument_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_non-uefi">
            <xccdf-1.2:title>Non-UEFI GRUB2 bootloader configuration</xccdf-1.2:title>
            <xccdf-1.2:description>Non-UEFI GRUB2 bootloader configuration</xccdf-1.2:description>
            <xccdf-1.2:platform idref="#non-uefi"/>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg" selected="false" severity="medium">
              <xccdf-1.2:title>Verify /boot/grub2/grub.cfg Group Ownership</xccdf-1.2:title>
              <xccdf-1.2:description>The file <html:code>/boot/grub2/grub.cfg</html:code> should
be group-owned by the <html:code>root</html:code> group to prevent
destruction or modification of the file.
To properly set the group owner of <html:code>/boot/grub2/grub.cfg</html:code>, run the command:

  <html:pre>$ sudo chgrp root /boot/grub2/grub.cfg</html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R29</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.4.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>root</html:code> group is a highly-privileged group. Furthermore, the group-owner of this
file should not have any access privileges anyway.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_container"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_grub2_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ) &amp;&amp; [ ! -d /sys/firmware/efi ] &amp;&amp; { ( ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); }; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/boot/grub2/grub.cfg" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /boot/grub2/grub.cfg
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_grub2_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_grub2_cfg_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_grub2_cfg_newgroup: '0'
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - not ('/sys/firmware/efi' is directory)
  - not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman", "container"]
    )
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /boot/grub2/grub.cfg
  ansible.builtin.stat:
    path: /boot/grub2/grub.cfg
  register: file_exists
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - not ('/sys/firmware/efi' is directory)
  - not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman", "container"]
    )
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /boot/grub2/grub.cfg
  ansible.builtin.file:
    path: /boot/grub2/grub.cfg
    follow: false
    group: '{{ file_groupowner_grub2_cfg_newgroup }}'
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - not ('/sys/firmware/efi' is directory)
  - not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman", "container"]
    )
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_grub2_cfg:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_grub2_cfg_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_user_cfg" selected="false" severity="medium">
              <xccdf-1.2:title>Verify /boot/grub2/user.cfg Group Ownership</xccdf-1.2:title>
              <xccdf-1.2:description>The file <html:code>/boot/grub2/user.cfg</html:code> should be group-owned by the <html:code>root</html:code>
group to prevent reading or modification of the file.
To properly set the group owner of <html:code>/boot/grub2/user.cfg</html:code>, run the command:

  <html:pre>$ sudo chgrp root /boot/grub2/user.cfg</html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R29</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.4.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>root</html:code> group is a highly-privileged group. Furthermore, the group-owner of this
file should not have any access privileges anyway. Non-root users who read the boot parameters
may be able to identify weaknesses in security upon boot and be able to exploit them.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_container"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_user_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ) &amp;&amp; [ ! -d /sys/firmware/efi ] &amp;&amp; { ( ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); }; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/boot/grub2/user.cfg" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /boot/grub2/user.cfg
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_user_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_user_cfg_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_user_cfg_newgroup: '0'
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - not ('/sys/firmware/efi' is directory)
  - not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman", "container"]
    )
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /boot/grub2/user.cfg
  ansible.builtin.stat:
    path: /boot/grub2/user.cfg
  register: file_exists
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - not ('/sys/firmware/efi' is directory)
  - not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman", "container"]
    )
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /boot/grub2/user.cfg
  ansible.builtin.file:
    path: /boot/grub2/user.cfg
    follow: false
    group: '{{ file_groupowner_user_cfg_newgroup }}'
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - not ('/sys/firmware/efi' is directory)
  - not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman", "container"]
    )
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_user_cfg:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_user_cfg_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_grub2_cfg" selected="false" severity="medium">
              <xccdf-1.2:title>Verify /boot/grub2/grub.cfg User Ownership</xccdf-1.2:title>
              <xccdf-1.2:description>The file <html:code>/boot/grub2/grub.cfg</html:code> should
be owned by the <html:code>root</html:code> user to prevent destruction
or modification of the file.
To properly set the owner of <html:code>/boot/grub2/grub.cfg</html:code>, run the command:

  <html:pre>$ sudo chown root /boot/grub2/grub.cfg </html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R29</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.4.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Only root should be able to modify important boot parameters.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_container"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_grub2_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ) &amp;&amp; [ ! -d /sys/firmware/efi ] &amp;&amp; { ( ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); }; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/boot/grub2/grub.cfg" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /boot/grub2/grub.cfg
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_grub2_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_grub2_cfg_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_grub2_cfg_newown: '0'
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - not ('/sys/firmware/efi' is directory)
  - not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman", "container"]
    )
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /boot/grub2/grub.cfg
  ansible.builtin.stat:
    path: /boot/grub2/grub.cfg
  register: file_exists
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - not ('/sys/firmware/efi' is directory)
  - not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman", "container"]
    )
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /boot/grub2/grub.cfg
  ansible.builtin.file:
    path: /boot/grub2/grub.cfg
    follow: false
    owner: '{{ file_owner_grub2_cfg_newown }}'
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - not ('/sys/firmware/efi' is directory)
  - not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman", "container"]
    )
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_grub2_cfg:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_grub2_cfg_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_user_cfg" selected="false" severity="medium">
              <xccdf-1.2:title>Verify /boot/grub2/user.cfg User Ownership</xccdf-1.2:title>
              <xccdf-1.2:description>The file <html:code>/boot/grub2/user.cfg</html:code> should be owned by the <html:code>root</html:code>
user to prevent reading or modification of the file.
To properly set the owner of <html:code>/boot/grub2/user.cfg</html:code>, run the command:

  <html:pre>$ sudo chown root /boot/grub2/user.cfg </html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R29</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.4.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Only root should be able to modify important boot parameters. Also, non-root users who read
the boot parameters may be able to identify weaknesses in security upon boot and be able to
exploit them.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_container"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_user_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ) &amp;&amp; [ ! -d /sys/firmware/efi ] &amp;&amp; { ( ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); }; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/boot/grub2/user.cfg" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /boot/grub2/user.cfg
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_user_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_user_cfg_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_user_cfg_newown: '0'
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - not ('/sys/firmware/efi' is directory)
  - not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman", "container"]
    )
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /boot/grub2/user.cfg
  ansible.builtin.stat:
    path: /boot/grub2/user.cfg
  register: file_exists
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - not ('/sys/firmware/efi' is directory)
  - not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman", "container"]
    )
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /boot/grub2/user.cfg
  ansible.builtin.file:
    path: /boot/grub2/user.cfg
    follow: false
    owner: '{{ file_owner_user_cfg_newown }}'
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - not ('/sys/firmware/efi' is directory)
  - not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman", "container"]
    )
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_user_cfg:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_user_cfg_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_grub2_cfg" selected="false" severity="medium">
              <xccdf-1.2:title>Verify /boot/grub2/grub.cfg Permissions</xccdf-1.2:title>
              <xccdf-1.2:description>File permissions for <html:code>/boot/grub2/grub.cfg</html:code> should be set to 600.
To properly set the permissions of <html:code>/boot/grub2/grub.cfg</html:code>, run the command:
<html:pre>$ sudo chmod 600 /boot/grub2/grub.cfg</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R29</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.4.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Proper permissions ensure that only the root user can modify important boot
parameters.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_container"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_grub2_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ) &amp;&amp; [ ! -d /sys/firmware/efi ] &amp;&amp; { ( ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); }; then

chmod u-xs,g-xwrs,o-xwrt /boot/grub2/grub.cfg

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_grub2_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /boot/grub2/grub.cfg
  ansible.builtin.stat:
    path: /boot/grub2/grub.cfg
  register: file_exists
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - not ('/sys/firmware/efi' is directory)
  - not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman", "container"]
    )
  tags:
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xwrs,o-xwrt on /boot/grub2/grub.cfg
  ansible.builtin.file:
    path: /boot/grub2/grub.cfg
    mode: u-xs,g-xwrs,o-xwrt
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - not ('/sys/firmware/efi' is directory)
  - not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman", "container"]
    )
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_grub2_cfg:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_grub2_cfg_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_user_cfg" selected="false" severity="medium">
              <xccdf-1.2:title>Verify /boot/grub2/user.cfg Permissions</xccdf-1.2:title>
              <xccdf-1.2:description>File permissions for <html:code>/boot/grub2/user.cfg</html:code> should be set to 600.
To properly set the permissions of <html:code>/boot/grub2/user.cfg</html:code>, run the command:
<html:pre>$ sudo chmod 600 /boot/grub2/user.cfg</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R29</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.4.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Proper permissions ensure that only the root user can read or modify important boot
parameters.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_container"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_user_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ) &amp;&amp; [ ! -d /sys/firmware/efi ] &amp;&amp; { ( ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); }; then

chmod u-xs,g-xwrs,o-xwrt /boot/grub2/user.cfg

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_user_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /boot/grub2/user.cfg
  ansible.builtin.stat:
    path: /boot/grub2/user.cfg
  register: file_exists
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - not ('/sys/firmware/efi' is directory)
  - not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman", "container"]
    )
  tags:
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xwrs,o-xwrt on /boot/grub2/user.cfg
  ansible.builtin.file:
    path: /boot/grub2/user.cfg
    mode: u-xs,g-xwrs,o-xwrt
  when:
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - not ('/sys/firmware/efi' is directory)
  - not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman", "container"]
    )
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_user_cfg:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_user_cfg_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_admin_username" selected="false" severity="high">
              <xccdf-1.2:title>Set the Boot Loader Admin Username to a Non-Default Value</xccdf-1.2:title>
              <xccdf-1.2:description>The grub2 boot loader should have a superuser account and password
protection enabled to protect boot-time settings.
<html:br/><html:br/>
To maximize the protection, select a password-protected superuser account with unique name, and modify the
<html:code>/etc/grub.d/01_users</html:code> configuration file to reflect the account name change.
<html:br/><html:br/>
Do not to use common administrator account names like root,
admin, or administrator for the grub2 superuser account.
<html:br/><html:br/>
Change the superuser to a different username (The default is 'root').
<html:pre>$ sed -i 's/\(set superusers=\).*/\1"&lt;unique user ID&gt;"/g' /etc/grub.d/01_users</html:pre>
The line mentioned above must be followed by the line
<html:pre>export superusers</html:pre>
so that the <html:code>superusers</html:code> is honored.
<html:br/><html:br/>
Once the superuser account has been added,
update the
<html:code>grub.cfg</html:code> file by running:
<html:pre>grubby --update-kernel=ALL --env=/boot/grub2/grubenv</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">To prevent hard-coded admin usernames, automatic remediation of this control is not available. Remediation
must be automated as a component of machine provisioning, or followed manually as outlined above.

Also, do NOT manually add the superuser account and password to the
<html:code>grub.cfg</html:code> file as the grub2-mkconfig command overwrites this file.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000080-GPOS-00048</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010149</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244522r1137691_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Having a non-default grub superuser username makes password-guessing attacks less effective.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_admin_username:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_admin_username_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_no_removeable_media" selected="false" severity="medium">
              <xccdf-1.2:title>Boot Loader Is Not Installed On Removable Media</xccdf-1.2:title>
              <xccdf-1.2:description>The system must not allow removable media to be used as the boot loader.
Remove alternate methods of booting the system from removable media.
<html:code>usb0</html:code>, <html:code>cd</html:code>, <html:code>fd0</html:code>, etc. are some examples of removable
media which should not exist in the lines:
<html:pre>set root='hd0,msdos1'</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000364-GPOS-00151</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Malicious users with removable boot media can gain access to a system
configured to use removable media as the boot loader.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_no_removeable_media:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_no_removeable_media_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_password" selected="false" severity="high">
              <xccdf-1.2:title>Set Boot Loader Password in grub2</xccdf-1.2:title>
              <xccdf-1.2:description>The grub2 boot loader should have a superuser account and password
protection enabled to protect boot-time settings.
<html:br/><html:br/>
Since plaintext passwords are a security risk, generate a hash for the password
by running the following command:

<html:pre># grub2-setpassword</html:pre>

When prompted, enter the password that was selected.
<html:br/><html:br/></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">To prevent hard-coded passwords, automatic remediation of this control is not available. Remediation
must be automated as a component of machine provisioning, or followed manually as outlined above.

Also, do NOT manually add the superuser account and password to the
<html:code>grub.cfg</html:code> file as the grub2-mkconfig command overwrites this file.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_UAU.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000080-GPOS-00048</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010150</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230235r1137691_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Password protection on the boot loader configuration ensures
users with physical access cannot trivially alter
important bootloader settings. These include which kernel to use,
and whether to enter single-user mode.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_container"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_password:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_password_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_uefi">
            <xccdf-1.2:title>UEFI GRUB2 bootloader configuration</xccdf-1.2:title>
            <xccdf-1.2:description>UEFI GRUB2 bootloader configuration</xccdf-1.2:description>
            <xccdf-1.2:warning category="functionality">UEFI generally uses vfat file systems, which does not support Unix-style permissions
managed by chmod command. In this case, in order to change file permissions for files
within /boot/efi it is necessary to update the mount options in /etc/fstab file and
reboot the system.</xccdf-1.2:warning>
            <xccdf-1.2:platform idref="#uefi"/>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_efi_grub2_cfg" selected="false" severity="medium">
              <xccdf-1.2:title>Verify the UEFI Boot Loader grub.cfg Group Ownership</xccdf-1.2:title>
              <xccdf-1.2:description>The file <html:code>/boot/efi/EFI/almalinux/grub.cfg</html:code> should
be group-owned by the <html:code>root</html:code> group to prevent
destruction or modification of the file.
To properly set the group owner of <html:code>/boot/efi/EFI/almalinux/grub.cfg</html:code>, run the command:

  <html:pre>$ sudo chgrp root /boot/efi/EFI/almalinux/grub.cfg</html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R29</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.4.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>root</html:code> group is a highly-privileged group. Furthermore, the group-owner of this
file should not have any access privileges anyway.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_efi_grub2_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ) &amp;&amp; [ -d /sys/firmware/efi ]; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/boot/efi/EFI/almalinux/grub.cfg" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /boot/efi/EFI/almalinux/grub.cfg
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_efi_grub2_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - configure_strategy
  - file_groupowner_efi_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_efi_grub2_cfg_newgroup variable if represented by
    gid
  ansible.builtin.set_fact:
    file_groupowner_efi_grub2_cfg_newgroup: '0'
  when:
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - configure_strategy
  - file_groupowner_efi_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /boot/efi/EFI/almalinux/grub.cfg
  ansible.builtin.stat:
    path: /boot/efi/EFI/almalinux/grub.cfg
  register: file_exists
  when:
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - configure_strategy
  - file_groupowner_efi_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /boot/efi/EFI/almalinux/grub.cfg
  ansible.builtin.file:
    path: /boot/efi/EFI/almalinux/grub.cfg
    follow: false
    group: '{{ file_groupowner_efi_grub2_cfg_newgroup }}'
  when:
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - configure_strategy
  - file_groupowner_efi_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_efi_grub2_cfg:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_efi_grub2_cfg_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_efi_user_cfg" selected="false" severity="medium">
              <xccdf-1.2:title>Verify /boot/efi/EFI/almalinux/user.cfg Group Ownership</xccdf-1.2:title>
              <xccdf-1.2:description>The file <html:code>/boot/efi/EFI/almalinux/user.cfg</html:code> should be group-owned by the
<html:code>root</html:code> group to prevent reading or modification of the file.
To properly set the group owner of <html:code>/boot/efi/EFI/almalinux/user.cfg</html:code>, run the command:

  <html:pre>$ sudo chgrp root /boot/efi/EFI/almalinux/user.cfg</html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R29</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.4.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>root</html:code> group is a highly-privileged group. Furthermore, the group-owner of this
file should not have any access privileges anyway. Non-root users who read the boot parameters
may be able to identify weaknesses in security upon boot and be able to exploit them.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_efi_user_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ) &amp;&amp; [ -d /sys/firmware/efi ]; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/boot/efi/EFI/almalinux/user.cfg" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /boot/efi/EFI/almalinux/user.cfg
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_efi_user_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - configure_strategy
  - file_groupowner_efi_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_efi_user_cfg_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_efi_user_cfg_newgroup: '0'
  when:
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - configure_strategy
  - file_groupowner_efi_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /boot/efi/EFI/almalinux/user.cfg
  ansible.builtin.stat:
    path: /boot/efi/EFI/almalinux/user.cfg
  register: file_exists
  when:
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - configure_strategy
  - file_groupowner_efi_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /boot/efi/EFI/almalinux/user.cfg
  ansible.builtin.file:
    path: /boot/efi/EFI/almalinux/user.cfg
    follow: false
    group: '{{ file_groupowner_efi_user_cfg_newgroup }}'
  when:
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - configure_strategy
  - file_groupowner_efi_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_efi_user_cfg:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_efi_user_cfg_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_efi_grub2_cfg" selected="false" severity="medium">
              <xccdf-1.2:title>Verify the UEFI Boot Loader grub.cfg User Ownership</xccdf-1.2:title>
              <xccdf-1.2:description>The file <html:code>/boot/efi/EFI/almalinux/grub.cfg</html:code> should
be owned by the <html:code>root</html:code> user to prevent destruction
or modification of the file.
To properly set the owner of <html:code>/boot/efi/EFI/almalinux/grub.cfg</html:code>, run the command:

  <html:pre>$ sudo chown root /boot/efi/EFI/almalinux/grub.cfg </html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R29</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.4.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Only root should be able to modify important boot parameters.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_efi_grub2_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ) &amp;&amp; [ -d /sys/firmware/efi ]; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/boot/efi/EFI/almalinux/grub.cfg" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /boot/efi/EFI/almalinux/grub.cfg
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_efi_grub2_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - configure_strategy
  - file_owner_efi_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_efi_grub2_cfg_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_efi_grub2_cfg_newown: '0'
  when:
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - configure_strategy
  - file_owner_efi_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /boot/efi/EFI/almalinux/grub.cfg
  ansible.builtin.stat:
    path: /boot/efi/EFI/almalinux/grub.cfg
  register: file_exists
  when:
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - configure_strategy
  - file_owner_efi_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /boot/efi/EFI/almalinux/grub.cfg
  ansible.builtin.file:
    path: /boot/efi/EFI/almalinux/grub.cfg
    follow: false
    owner: '{{ file_owner_efi_grub2_cfg_newown }}'
  when:
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - configure_strategy
  - file_owner_efi_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_efi_grub2_cfg:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_efi_grub2_cfg_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_efi_user_cfg" selected="false" severity="medium">
              <xccdf-1.2:title>Verify /boot/efi/EFI/almalinux/user.cfg User Ownership</xccdf-1.2:title>
              <xccdf-1.2:description>The file <html:code>/boot/efi/EFI/almalinux/user.cfg</html:code> should be owned by the <html:code>root</html:code>
user to prevent reading or modification of the file.
To properly set the owner of <html:code>/boot/efi/EFI/almalinux/user.cfg</html:code>, run the command:

  <html:pre>$ sudo chown root /boot/efi/EFI/almalinux/user.cfg </html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R29</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.4.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Only root should be able to modify important boot parameters. Also, non-root users who read
the boot parameters may be able to identify weaknesses in security upon boot and be able to
exploit them.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_efi_user_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ) &amp;&amp; [ -d /sys/firmware/efi ]; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/boot/efi/EFI/almalinux/user.cfg" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /boot/efi/EFI/almalinux/user.cfg
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_efi_user_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - configure_strategy
  - file_owner_efi_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_efi_user_cfg_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_efi_user_cfg_newown: '0'
  when:
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - configure_strategy
  - file_owner_efi_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /boot/efi/EFI/almalinux/user.cfg
  ansible.builtin.stat:
    path: /boot/efi/EFI/almalinux/user.cfg
  register: file_exists
  when:
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - configure_strategy
  - file_owner_efi_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /boot/efi/EFI/almalinux/user.cfg
  ansible.builtin.file:
    path: /boot/efi/EFI/almalinux/user.cfg
    follow: false
    owner: '{{ file_owner_efi_user_cfg_newown }}'
  when:
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-7.1
  - configure_strategy
  - file_owner_efi_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_efi_user_cfg:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_efi_user_cfg_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_efi_grub2_cfg" selected="false" severity="medium">
              <xccdf-1.2:title>Verify the UEFI Boot Loader grub.cfg Permissions</xccdf-1.2:title>
              <xccdf-1.2:description>File permissions for <html:code>/boot/efi/EFI/almalinux/grub.cfg</html:code> should be set to 700.
To properly set the permissions of <html:code>/boot/efi/EFI/almalinux/grub.cfg</html:code>, run the command:
<html:pre>$ sudo chmod 700 /boot/efi/EFI/almalinux/grub.cfg</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R29</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.4.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Proper permissions ensure that only the root user can modify important boot
parameters.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_efi_grub2_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ) &amp;&amp; [ -d /sys/firmware/efi ]; then

chmod u-s,g-xwrs,o-xwrt /boot/efi/EFI/almalinux/grub.cfg

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_efi_grub2_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_efi_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /boot/efi/EFI/almalinux/grub.cfg
  ansible.builtin.stat:
    path: /boot/efi/EFI/almalinux/grub.cfg
  register: file_exists
  when:
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_efi_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-s,g-xwrs,o-xwrt on /boot/efi/EFI/almalinux/grub.cfg
  ansible.builtin.file:
    path: /boot/efi/EFI/almalinux/grub.cfg
    mode: u-s,g-xwrs,o-xwrt
  when:
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_efi_grub2_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_efi_grub2_cfg:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_efi_grub2_cfg_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_efi_user_cfg" selected="false" severity="medium">
              <xccdf-1.2:title>Verify /boot/efi/EFI/almalinux/user.cfg Permissions</xccdf-1.2:title>
              <xccdf-1.2:description>File permissions for <html:code>/boot/efi/EFI/almalinux/user.cfg</html:code> should be set to 600.
To properly set the permissions of <html:code>/boot/efi/EFI/almalinux/user.cfg</html:code>, run the command:
<html:pre>$ sudo chmod 600 /boot/efi/EFI/almalinux/user.cfg</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R29</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.4.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Proper permissions ensure that only the root user can read or modify important boot
parameters.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_efi_user_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( rpm --quiet -q grub2-common &amp;&amp; rpm --quiet -q kernel ) &amp;&amp; [ -d /sys/firmware/efi ]; then

chmod u-s,g-xwrs,o-xwrt /boot/efi/EFI/almalinux/user.cfg

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_efi_user_cfg" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_efi_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /boot/efi/EFI/almalinux/user.cfg
  ansible.builtin.stat:
    path: /boot/efi/EFI/almalinux/user.cfg
  register: file_exists
  when:
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  tags:
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_efi_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-s,g-xwrs,o-xwrt on /boot/efi/EFI/almalinux/user.cfg
  ansible.builtin.file:
    path: /boot/efi/EFI/almalinux/user.cfg
    mode: u-s,g-xwrs,o-xwrt
  when:
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - ( "grub2-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-171-3.4.5
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_efi_user_cfg
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_efi_user_cfg:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_efi_user_cfg_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_uefi_admin_username" selected="false" severity="medium">
              <xccdf-1.2:title>Set the UEFI Boot Loader Admin Username to a Non-Default Value</xccdf-1.2:title>
              <xccdf-1.2:description>The grub2 boot loader should have a superuser account and password
protection enabled to protect boot-time settings.
<html:br/><html:br/>
To maximize the protection, select a password-protected superuser account with unique name, and modify the
<html:code>/etc/grub.d/01_users</html:code> configuration file to reflect the account name change.
<html:br/><html:br/>
It is highly suggested not to use common administrator account names like root,
admin, or administrator for the grub2 superuser account.
<html:br/><html:br/>
Change the superuser to a different username (The default is 'root').
<html:pre>$ sed -i 's/\(set superusers=\).*/\1"&lt;unique user ID&gt;"/g' /etc/grub.d/01_users</html:pre>
The line mentioned above must be followed by the line
<html:pre>export superusers</html:pre>
so that the <html:code>superusers</html:code> is honored.
<html:br/><html:br/>
Once the superuser account has been added,
update the
<html:code>grub.cfg</html:code> file by running:
<html:pre>grubby --update-kernel=ALL --env=/boot/grub2/grubenv</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">To prevent hard-coded admin usernames, automatic remediation of this control is not available. Remediation
must be automated as a component of machine provisioning, or followed manually as outlined above.

Also, do NOT manually add the superuser account and password to the
<html:code>grub.cfg</html:code> file as the grub2-mkconfig command overwrites this file.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000080-GPOS-00048</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010141</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244521r1137691_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Having a non-default grub superuser username makes password-guessing attacks less effective.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_uefi_admin_username:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_uefi_admin_username_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_uefi_password" selected="false" severity="high">
              <xccdf-1.2:title>Set the UEFI Boot Loader Password</xccdf-1.2:title>
              <xccdf-1.2:description>The grub2 boot loader should have a superuser account and password
protection enabled to protect boot-time settings.
<html:br/><html:br/>
Since plaintext passwords are a security risk, generate a hash for the password
by running the following command:

<html:pre># grub2-setpassword</html:pre>

When prompted, enter the password that was selected.
<html:br/><html:br/></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">To prevent hard-coded passwords, automatic remediation of this control is not available. Remediation
must be automated as a component of machine provisioning, or followed manually as outlined above.

Also, do NOT manually add the superuser account and password to the
<html:code>grub.cfg</html:code> file as the grub2-mkconfig command overwrites this file.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(7)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_UAU.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000080-GPOS-00048</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010140</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230234r1137691_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Password protection on the boot loader configuration ensures
users with physical access cannot trivially alter
important bootloader settings. These include which kernel to use,
and whether to enter single-user mode.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_uefi_password:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_uefi_no_removeable_media" selected="false" severity="medium">
              <xccdf-1.2:title>UEFI Boot Loader Is Not Installed On Removable Media</xccdf-1.2:title>
              <xccdf-1.2:description>The system must not allow removable media to be used as the boot loader.
Remove alternate methods of booting the system from removable media.
<html:code>usb0</html:code>, <html:code>cd</html:code>, <html:code>fd0</html:code>, etc. are some examples of removable
media which should not exist in the lines:
<html:pre>set root='hd0,msdos1'</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000364-GPOS-00151</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Malicious users with removable boot media can gain access to a system
configured to use removable media as the boot loader.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-uefi_no_removeable_media:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-uefi_no_removeable_media_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_bootloader-zipl">
          <xccdf-1.2:title>zIPL bootloader configuration</xccdf-1.2:title>
          <xccdf-1.2:description>During the boot process, the bootloader is
responsible for starting the execution of the kernel and passing
options to it.
The default AlmaLinux OS 8 boot loader for s390x systems is called zIPL.</xccdf-1.2:description>
          <xccdf-1.2:platform idref="#s390x_arch"/>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_zipl_audit_argument" selected="false" severity="medium">
            <xccdf-1.2:title>Enable Auditing to Start Prior to the Audit Daemon in zIPL</xccdf-1.2:title>
            <xccdf-1.2:description>To ensure all processes can be audited, even those which start prior to the audit daemon,
check that all boot entries in <html:code>/boot/loader/entries/*.conf</html:code> have <html:code>audit=1</html:code>
included in its options.<html:br/>

To ensure that new kernels and boot entries continue to enable audit,
add <html:code>audit=1</html:code> to <html:code>/etc/kernel/cmdline</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Each process on the system carries an "auditable" flag which indicates whether
its activities can be audited. Although <html:code>auditd</html:code> takes care of enabling
this for all processes which launch after it does, adding the kernel argument
ensures it is set for every process during boot.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#machine"/>
            <xccdf-1.2:fix id="zipl_audit_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( grep -sqE "^.*\.s390x$" /proc/sys/kernel/osrelease || grep -sqE "^s390x$" /proc/sys/kernel/arch; ) &amp;&amp; { ( [ ! -f /.dockerenv ] &amp;&amp; [ ! -f /run/.containerenv ] ); }; then

# Correct BLS option using grubby, which is a thin wrapper around BLS operations
grubby --update-kernel=ALL --args="audit=1"

# Ensure new kernels and boot entries retain the boot option
if [ ! -f /etc/kernel/cmdline ]; then
    echo "audit=1" &gt; /etc/kernel/cmdline
elif ! grep -q '^(.*\s)?audit=1(\s.*)?$' /etc/kernel/cmdline; then
    
    sed -Ei 's/^(.*)$/\1 audit=1/' /etc/kernel/cmdline
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="zipl_audit_argument" reboot="true" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Ensure BLS boot entries options contain audit=1
  block:

  - name: 'Check how many boot entries exist '
    ansible.builtin.find:
      paths: /boot/loader/entries/
      patterns: '*.conf'
    register: n_entries

  - name: Check how many boot entries set audit=1
    ansible.builtin.find:
      paths: /boot/loader/entries/
      contains: ^options .*audit=1.*$
      patterns: '*.conf'
    register: n_entries_options

  - name: Update boot entries options
    ansible.builtin.command: grubby --update-kernel=ALL --args="audit=1"
    when: n_entries is defined and n_entries_options is defined and n_entries.matched
      != n_entries_options.matched

  - name: Check if /etc/kernel/cmdline exists
    ansible.builtin.stat:
      path: /etc/kernel/cmdline
    register: cmdline_stat

  - name: Check if /etc/kernel/cmdline contains audit=1
    ansible.builtin.find:
      paths: /etc/kernel/
      patterns: cmdline
      contains: ^.*audit=1.*$
    register: cmdline_find

  - name: Add /etc/kernel/cmdline contains audit=1
    ansible.builtin.lineinfile:
      create: true
      path: /etc/kernel/cmdline
      line: audit=1
    when: cmdline_stat is defined and not cmdline_stat.stat.exists

  - name: Append /etc/kernel/cmdline contains audit=1
    ansible.builtin.lineinfile:
      path: /etc/kernel/cmdline
      backrefs: true
      regexp: ^(.*)$
      line: \1 audit=1
    when: cmdline_stat is defined and cmdline_stat.stat.exists and cmdline_find is
      defined and cmdline_find.matched == 0
  when:
  - ansible_architecture == "s390x"
  - ansible_virtualization_type not in ["docker", "lxc", "openvz", "podman", "container"]
  tags:
  - configure_strategy
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - zipl_audit_argument
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-zipl_audit_argument:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-zipl_audit_argument_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_zipl_audit_backlog_limit_argument" selected="false" severity="medium">
            <xccdf-1.2:title>Extend Audit Backlog Limit for the Audit Daemon in zIPL</xccdf-1.2:title>
            <xccdf-1.2:description>To improve the kernel capacity to queue all log events, even those which start prior to the audit daemon,
check that all boot entries in <html:code>/boot/loader/entries/*.conf</html:code> have <html:code>audit_backlog_limit=8192</html:code>
included in its options.<html:br/>
To ensure that new kernels and boot entries continue to extend the audit log events queue,
add <html:code>audit_backlog_limit=8192</html:code> to <html:code>/etc/kernel/cmdline</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_STG.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_STG.3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>audit_backlog_limit sets the queue length for audit events awaiting transfer
to the audit daemon. Until the audit daemon is up and running, all log messages
are stored in this queue.  If the queue is overrun during boot process, the action
defined by audit failure flag is taken.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#machine"/>
            <xccdf-1.2:fix id="zipl_audit_backlog_limit_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( grep -sqE "^.*\.s390x$" /proc/sys/kernel/osrelease || grep -sqE "^s390x$" /proc/sys/kernel/arch; ) &amp;&amp; { ( [ ! -f /.dockerenv ] &amp;&amp; [ ! -f /run/.containerenv ] ); }; then

# Correct BLS option using grubby, which is a thin wrapper around BLS operations
grubby --update-kernel=ALL --args="audit_backlog_limit=8192"

# Ensure new kernels and boot entries retain the boot option
if [ ! -f /etc/kernel/cmdline ]; then
    echo "audit_backlog_limit=8192" &gt; /etc/kernel/cmdline
elif ! grep -q '^(.*\s)?audit_backlog_limit=8192(\s.*)?$' /etc/kernel/cmdline; then
    
    sed -Ei 's/^(.*)$/\1 audit_backlog_limit=8192/' /etc/kernel/cmdline
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="zipl_audit_backlog_limit_argument" reboot="true" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Ensure BLS boot entries options contain audit_backlog_limit=8192
  block:

  - name: 'Check how many boot entries exist '
    ansible.builtin.find:
      paths: /boot/loader/entries/
      patterns: '*.conf'
    register: n_entries

  - name: Check how many boot entries set audit_backlog_limit=8192
    ansible.builtin.find:
      paths: /boot/loader/entries/
      contains: ^options .*audit_backlog_limit=8192.*$
      patterns: '*.conf'
    register: n_entries_options

  - name: Update boot entries options
    ansible.builtin.command: grubby --update-kernel=ALL --args="audit_backlog_limit=8192"
    when: n_entries is defined and n_entries_options is defined and n_entries.matched
      != n_entries_options.matched

  - name: Check if /etc/kernel/cmdline exists
    ansible.builtin.stat:
      path: /etc/kernel/cmdline
    register: cmdline_stat

  - name: Check if /etc/kernel/cmdline contains audit_backlog_limit=8192
    ansible.builtin.find:
      paths: /etc/kernel/
      patterns: cmdline
      contains: ^.*audit_backlog_limit=8192.*$
    register: cmdline_find

  - name: Add /etc/kernel/cmdline contains audit_backlog_limit=8192
    ansible.builtin.lineinfile:
      create: true
      path: /etc/kernel/cmdline
      line: audit_backlog_limit=8192
    when: cmdline_stat is defined and not cmdline_stat.stat.exists

  - name: Append /etc/kernel/cmdline contains audit_backlog_limit=8192
    ansible.builtin.lineinfile:
      path: /etc/kernel/cmdline
      backrefs: true
      regexp: ^(.*)$
      line: \1 audit_backlog_limit=8192
    when: cmdline_stat is defined and cmdline_stat.stat.exists and cmdline_find is
      defined and cmdline_find.matched == 0
  when:
  - ansible_architecture == "s390x"
  - ansible_virtualization_type not in ["docker", "lxc", "openvz", "podman", "container"]
  tags:
  - configure_strategy
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - zipl_audit_backlog_limit_argument
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-zipl_audit_backlog_limit_argument:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-zipl_audit_backlog_limit_argument_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_zipl_page_poison_argument" selected="false" severity="medium">
            <xccdf-1.2:title>Enable page allocator poisoning in zIPL</xccdf-1.2:title>
            <xccdf-1.2:description>To enable poisoning of free pages,
check that all boot entries in <html:code>/boot/loader/entries/*.conf</html:code> have <html:code>page_poison=1</html:code>
included in its options.<html:br/>
To ensure that new kernels and boot entries continue to enable page poisoning,
add <html:code>page_poison=1</html:code> to <html:code>/etc/kernel/cmdline</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:rationale>Poisoning writes an arbitrary value to freed pages, so any modification or
reference to that page after being freed or before being initialized will be
detected and prevented.
This prevents many types of use-after-free vulnerabilities at little performance cost.
Also prevents leak of data and detection of corrupted memory.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#machine"/>
            <xccdf-1.2:fix id="zipl_page_poison_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( grep -sqE "^.*\.s390x$" /proc/sys/kernel/osrelease || grep -sqE "^s390x$" /proc/sys/kernel/arch; ) &amp;&amp; { ( [ ! -f /.dockerenv ] &amp;&amp; [ ! -f /run/.containerenv ] ); }; then

# Correct BLS option using grubby, which is a thin wrapper around BLS operations
grubby --update-kernel=ALL --args="page_poison=1"

# Ensure new kernels and boot entries retain the boot option
if [ ! -f /etc/kernel/cmdline ]; then
    echo "page_poison=1" &gt; /etc/kernel/cmdline
elif ! grep -q '^(.*\s)?page_poison=1(\s.*)?$' /etc/kernel/cmdline; then
    
    sed -Ei 's/^(.*)$/\1 page_poison=1/' /etc/kernel/cmdline
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="zipl_page_poison_argument" reboot="true" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Ensure BLS boot entries options contain page_poison=1
  block:

  - name: 'Check how many boot entries exist '
    ansible.builtin.find:
      paths: /boot/loader/entries/
      patterns: '*.conf'
    register: n_entries

  - name: Check how many boot entries set page_poison=1
    ansible.builtin.find:
      paths: /boot/loader/entries/
      contains: ^options .*page_poison=1.*$
      patterns: '*.conf'
    register: n_entries_options

  - name: Update boot entries options
    ansible.builtin.command: grubby --update-kernel=ALL --args="page_poison=1"
    when: n_entries is defined and n_entries_options is defined and n_entries.matched
      != n_entries_options.matched

  - name: Check if /etc/kernel/cmdline exists
    ansible.builtin.stat:
      path: /etc/kernel/cmdline
    register: cmdline_stat

  - name: Check if /etc/kernel/cmdline contains page_poison=1
    ansible.builtin.find:
      paths: /etc/kernel/
      patterns: cmdline
      contains: ^.*page_poison=1.*$
    register: cmdline_find

  - name: Add /etc/kernel/cmdline contains page_poison=1
    ansible.builtin.lineinfile:
      create: true
      path: /etc/kernel/cmdline
      line: page_poison=1
    when: cmdline_stat is defined and not cmdline_stat.stat.exists

  - name: Append /etc/kernel/cmdline contains page_poison=1
    ansible.builtin.lineinfile:
      path: /etc/kernel/cmdline
      backrefs: true
      regexp: ^(.*)$
      line: \1 page_poison=1
    when: cmdline_stat is defined and cmdline_stat.stat.exists and cmdline_find is
      defined and cmdline_find.matched == 0
  when:
  - ansible_architecture == "s390x"
  - ansible_virtualization_type not in ["docker", "lxc", "openvz", "podman", "container"]
  tags:
  - configure_strategy
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - zipl_page_poison_argument
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-zipl_page_poison_argument:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-zipl_page_poison_argument_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_zipl_slub_debug_argument" selected="false" severity="medium">
            <xccdf-1.2:title>Enable SLUB/SLAB allocator poisoning in zIPL</xccdf-1.2:title>
            <xccdf-1.2:description>To enable poisoning of SLUB/SLAB objects,
check that all boot entries in <html:code>/boot/loader/entries/*.conf</html:code> have <html:code>slub_debug=P</html:code>
included in its options.<html:br/>
To ensure that new kernels and boot entries continue to enable poisoning of SLUB/SLAB objects,
add <html:code>slub_debug=P</html:code> to <html:code>/etc/kernel/cmdline</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:rationale>Poisoning writes an arbitrary value to freed objects, so any modification or
reference to that object after being freed or before being initialized will be
detected and prevented.
This prevents many types of use-after-free vulnerabilities at little performance cost.
Also prevents leak of data and detection of corrupted memory.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#machine"/>
            <xccdf-1.2:fix id="zipl_slub_debug_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( grep -sqE "^.*\.s390x$" /proc/sys/kernel/osrelease || grep -sqE "^s390x$" /proc/sys/kernel/arch; ) &amp;&amp; { ( [ ! -f /.dockerenv ] &amp;&amp; [ ! -f /run/.containerenv ] ); }; then

# Correct BLS option using grubby, which is a thin wrapper around BLS operations
grubby --update-kernel=ALL --args="slub_debug=P"

# Ensure new kernels and boot entries retain the boot option
if [ ! -f /etc/kernel/cmdline ]; then
    echo "slub_debug=P" &gt; /etc/kernel/cmdline
elif ! grep -q '^(.*\s)?slub_debug=P(\s.*)?$' /etc/kernel/cmdline; then
    
    sed -Ei 's/^(.*)$/\1 slub_debug=P/' /etc/kernel/cmdline
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="zipl_slub_debug_argument" reboot="true" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Ensure BLS boot entries options contain slub_debug=P
  block:

  - name: 'Check how many boot entries exist '
    ansible.builtin.find:
      paths: /boot/loader/entries/
      patterns: '*.conf'
    register: n_entries

  - name: Check how many boot entries set slub_debug=P
    ansible.builtin.find:
      paths: /boot/loader/entries/
      contains: ^options .*slub_debug=P.*$
      patterns: '*.conf'
    register: n_entries_options

  - name: Update boot entries options
    ansible.builtin.command: grubby --update-kernel=ALL --args="slub_debug=P"
    when: n_entries is defined and n_entries_options is defined and n_entries.matched
      != n_entries_options.matched

  - name: Check if /etc/kernel/cmdline exists
    ansible.builtin.stat:
      path: /etc/kernel/cmdline
    register: cmdline_stat

  - name: Check if /etc/kernel/cmdline contains slub_debug=P
    ansible.builtin.find:
      paths: /etc/kernel/
      patterns: cmdline
      contains: ^.*slub_debug=P.*$
    register: cmdline_find

  - name: Add /etc/kernel/cmdline contains slub_debug=P
    ansible.builtin.lineinfile:
      create: true
      path: /etc/kernel/cmdline
      line: slub_debug=P
    when: cmdline_stat is defined and not cmdline_stat.stat.exists

  - name: Append /etc/kernel/cmdline contains slub_debug=P
    ansible.builtin.lineinfile:
      path: /etc/kernel/cmdline
      backrefs: true
      regexp: ^(.*)$
      line: \1 slub_debug=P
    when: cmdline_stat is defined and cmdline_stat.stat.exists and cmdline_find is
      defined and cmdline_find.matched == 0
  when:
  - ansible_architecture == "s390x"
  - ansible_virtualization_type not in ["docker", "lxc", "openvz", "podman", "container"]
  tags:
  - configure_strategy
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - zipl_slub_debug_argument
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-zipl_slub_debug_argument:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-zipl_slub_debug_argument_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_zipl_systemd_debug-shell_argument_absent" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure debug-shell service is not enabled in zIPL</xccdf-1.2:title>
            <xccdf-1.2:description>systemd's <html:code>debug-shell</html:code> service is intended to
diagnose systemd related boot issues with various <html:code>systemctl</html:code>
commands. Once enabled and following a system reboot, the root shell
will be available on <html:code>tty9</html:code> which is access by pressing
<html:code>CTRL-ALT-F9</html:code>. The <html:code>debug-shell</html:code> service should only be used
for systemd related issues and should otherwise be disabled.
<html:br/><html:br/>
By default, the <html:code>debug-shell</html:code> systemd service is already disabled.

Ensure the debug-shell is not enabled by the <html:code>systemd.debug-shel=1</html:code>
boot parameter option.

Check that not boot entries in <html:code>/boot/loader/entries/*.conf</html:code> have
<html:code>systemd.debug-shell=1</html:code> included in its options.<html:br/>
To ensure that new kernels and boot entries don't enable the debug-shell, check
that <html:code>systemd.debug-shell=1</html:code> is not present in <html:code>/etc/kernel/cmdline</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_UAU.1</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This prevents attackers with physical access from trivially bypassing security
on the machine through valid troubleshooting configurations and gaining root
access when the system is rebooted.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#machine"/>
            <xccdf-1.2:fix id="zipl_systemd_debug-shell_argument_absent" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( grep -sqE "^.*\.s390x$" /proc/sys/kernel/osrelease || grep -sqE "^s390x$" /proc/sys/kernel/arch; ) &amp;&amp; { ( [ ! -f /.dockerenv ] &amp;&amp; [ ! -f /run/.containerenv ] ); }; then

# Correct BLS option using grubby, which is a thin wrapper around BLS operations
grubby --update-kernel=ALL --remove-args="systemd.debug-shell"

# Ensure new kernels and boot entries retain the boot option
if grep -q '\bsystemd.debug-shell\b' /etc/kernel/cmdline; then
    sed -Ei 's/^(.*)\s*systemd.debug-shell\b\S*(.*)/\1\2/' /etc/kernel/cmdline
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="zipl_systemd_debug-shell_argument_absent" reboot="true" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Ensure BLS boot entries options contain systemd.debug-shell
  block:

  - name: Check how many boot entries set systemd.debug-shell
    ansible.builtin.find:
      paths: /boot/loader/entries/
      contains: ^options .*systemd\.debug-shell.*$
      patterns: '*.conf'
    register: n_entries

  - name: Remove systemd.debug-shell from boot entries
    ansible.builtin.command: grubby --update-kernel=ALL --remove-args="systemd.debug-shell"
    when: n_entries is defined and n_entries.matched &gt;= 1

  - name: Check if /etc/kernel/cmdline exists
    ansible.builtin.stat:
      path: /etc/kernel/cmdline
    register: cmdline_stat

  - name: Check if /etc/kernel/cmdline contains systemd.debug-shell
    ansible.builtin.find:
      paths: /etc/kernel/
      patterns: cmdline
      contains: ^.*systemd\.debug-shell.*$
    register: cmdline_find

  - name: Remove systemd.debug-shell from /etc/kernel/cmdline
    ansible.builtin.lineinfile:
      path: /etc/kernel/cmdline
      backrefs: true
      regexp: ^(.*)\s*systemd.debug-shell\b\S*(.*)$
      line: \1\2
    when: cmdline_stat is defined and cmdline_stat.stat.exists and cmdline_find is
      defined and cmdline_find.matched &gt;= 1
  when:
  - ansible_architecture == "s390x"
  - ansible_virtualization_type not in ["docker", "lxc", "openvz", "podman", "container"]
  tags:
  - configure_strategy
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - zipl_systemd_debug-shell_argument_absent
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-zipl_systemd_debug-shell_argument_absent:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-zipl_systemd_debug-shell_argument_absent_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_zipl_vsyscall_argument" selected="false" severity="medium">
            <xccdf-1.2:title>Disable vsyscalls in zIPL</xccdf-1.2:title>
            <xccdf-1.2:description>To disable use of virtual syscalls,
check that all boot entries in <html:code>/boot/loader/entries/*.conf</html:code> have <html:code>vsyscall=none</html:code>
included in its options.<html:br/>
To ensure that new kernels and boot entries continue to disable virtual syscalls,
add <html:code>vsyscall=none</html:code> to <html:code>/etc/kernel/cmdline</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_ASLR_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Virtual Syscalls provide an opportunity of attack for a user who has control
of the return instruction pointer.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#machine"/>
            <xccdf-1.2:fix id="zipl_vsyscall_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( grep -sqE "^.*\.s390x$" /proc/sys/kernel/osrelease || grep -sqE "^s390x$" /proc/sys/kernel/arch; ) &amp;&amp; { ( [ ! -f /.dockerenv ] &amp;&amp; [ ! -f /run/.containerenv ] ); }; then

# Correct BLS option using grubby, which is a thin wrapper around BLS operations
grubby --update-kernel=ALL --args="vsyscall=none"

# Ensure new kernels and boot entries retain the boot option
if [ ! -f /etc/kernel/cmdline ]; then
    echo "vsyscall=none" &gt; /etc/kernel/cmdline
elif ! grep -q '^(.*\s)?vsyscall=none(\s.*)?$' /etc/kernel/cmdline; then
    
    sed -Ei 's/^(.*)$/\1 vsyscall=none/' /etc/kernel/cmdline
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="medium" disruption="low" id="zipl_vsyscall_argument" reboot="true" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Ensure BLS boot entries options contain vsyscall=none
  block:

  - name: 'Check how many boot entries exist '
    ansible.builtin.find:
      paths: /boot/loader/entries/
      patterns: '*.conf'
    register: n_entries

  - name: Check how many boot entries set vsyscall=none
    ansible.builtin.find:
      paths: /boot/loader/entries/
      contains: ^options .*vsyscall=none.*$
      patterns: '*.conf'
    register: n_entries_options

  - name: Update boot entries options
    ansible.builtin.command: grubby --update-kernel=ALL --args="vsyscall=none"
    when: n_entries is defined and n_entries_options is defined and n_entries.matched
      != n_entries_options.matched

  - name: Check if /etc/kernel/cmdline exists
    ansible.builtin.stat:
      path: /etc/kernel/cmdline
    register: cmdline_stat

  - name: Check if /etc/kernel/cmdline contains vsyscall=none
    ansible.builtin.find:
      paths: /etc/kernel/
      patterns: cmdline
      contains: ^.*vsyscall=none.*$
    register: cmdline_find

  - name: Add /etc/kernel/cmdline contains vsyscall=none
    ansible.builtin.lineinfile:
      create: true
      path: /etc/kernel/cmdline
      line: vsyscall=none
    when: cmdline_stat is defined and not cmdline_stat.stat.exists

  - name: Append /etc/kernel/cmdline contains vsyscall=none
    ansible.builtin.lineinfile:
      path: /etc/kernel/cmdline
      backrefs: true
      regexp: ^(.*)$
      line: \1 vsyscall=none
    when: cmdline_stat is defined and cmdline_stat.stat.exists and cmdline_find is
      defined and cmdline_find.matched == 0
  when:
  - ansible_architecture == "s390x"
  - ansible_virtualization_type not in ["docker", "lxc", "openvz", "podman", "container"]
  tags:
  - configure_strategy
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - zipl_vsyscall_argument
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-zipl_vsyscall_argument:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-zipl_vsyscall_argument_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_zipl_bls_entries_only" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure all zIPL boot entries are BLS compliant</xccdf-1.2:title>
            <xccdf-1.2:description>Ensure that zIPL boot entries fully adheres to Boot Loader Specification (BLS)
by checking that <html:code>/etc/zipl.conf</html:code> doesn't contain <html:code>image = </html:code>.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">To prevent breakage or removal of all boot entries oconfigured in /etc/zipl.conf
automated remediation for this rule is not available.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_TST_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:rationale>AlmaLinux OS 8 adheres to Boot Loader Specification (BLS) and is the preferred method of
configuration.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#machine"/>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-zipl_bls_entries_only:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-zipl_bls_entries_only_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_zipl_bootmap_is_up_to_date" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure zIPL bootmap is up to date</xccdf-1.2:title>
            <xccdf-1.2:description>Make sure that <html:code>/boot/bootmap</html:code> is up to date.<html:br/>
Every time a boot entry or zIPL configuration is changed <html:code>/boot/bootmap</html:code> needs to
be updated to reflect the changes.<html:br/>
Run <html:code>zipl</html:code> command to generate an updated <html:code>/boot/bootmap</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FPT_TST_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The file <html:code>/boot/bootmap</html:code> contains all boot data, keeping it up to date is crucial to
boot correct kernel and options.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#machine"/>
            <xccdf-1.2:fix id="zipl_bootmap_is_up_to_date" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( grep -sqE "^.*\.s390x$" /proc/sys/kernel/osrelease || grep -sqE "^s390x$" /proc/sys/kernel/arch; ) &amp;&amp; { ( [ ! -f /.dockerenv ] &amp;&amp; [ ! -f /run/.containerenv ] ); }; then

/usr/sbin/zipl

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="zipl_bootmap_is_up_to_date" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Ensure zIPL bootmap is up to date
  block:

  - name: Obtain stats of /boot/bootmap
    ansible.builtin.stat:
      path: /boot/bootmap
    register: boot_bootmap

  - name: Obtain stats of /etc/zipl.conf
    ansible.builtin.stat:
      path: /etc/zipl.conf
    register: zipl_conf

  - name: Obtain stats of /boot/loader/entries
    ansible.builtin.stat:
      path: /boot/loader/entries
    register: boot_loader_entries

  - name: Update zIPL bootmap
    ansible.builtin.command: /usr/sbin/zipl
    changed_when: true
    when:
    - boot_bootmap.stat.mtime is defined
    - zipl_conf.stat.mtime is defined
    - boot_loader_entries.stat.mtime is defined
    - boot_bootmap.stat.mtime &lt; zipl_conf.stat.mtime or boot_bootmap.stat.mtime &lt;
      boot_loader_entries.stat.mtime
  when:
  - ansible_architecture == "s390x"
  - ansible_virtualization_type not in ["docker", "lxc", "openvz", "podman", "container"]
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - zipl_bootmap_is_up_to_date
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-zipl_bootmap_is_up_to_date:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-zipl_bootmap_is_up_to_date_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_zipl_enable_selinux" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure SELinux Not Disabled in zIPL</xccdf-1.2:title>
            <xccdf-1.2:description>To ensure SELinux is not disabled at boot time,
check that no boot entry in <html:code>/boot/loader/entries/*.conf</html:code> has <html:code>selinux=0</html:code>
included in its options.<html:br/></xccdf-1.2:description>
            <xccdf-1.2:rationale>Disabling a major host protection feature, such as SELinux, at boot time prevents
it from confining system services at boot time.  Further, it increases
the chances that it will remain off during system operation.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#machine"/>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-zipl_enable_selinux_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_entropy">
          <xccdf-1.2:title>Protect Random-Number Entropy Pool</xccdf-1.2:title>
          <xccdf-1.2:description>The I/O operations of the Linux kernel block layer due to their inherently
unpredictable execution times have been traditionally considered as a reliable
source to contribute to random-number entropy pool of the Linux kernel. This
has changed with introduction of solid-state storage devices (SSDs) though.</xccdf-1.2:description>
          <xccdf-1.2:platform idref="#machine"/>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_disable_entropy_contribution_for_solid_state_drives" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure Solid State Drives Do Not Contribute To Random-Number Entropy Pool</xccdf-1.2:title>
            <xccdf-1.2:description>For each solid-state drive on the system, run:
<html:pre> # echo 0 &gt; /sys/block/DRIVE/queue/add_random</html:pre></xccdf-1.2:description>
            <xccdf-1.2:rationale>In contrast to traditional electromechanical magnetic disks, containing
spinning disks and / or movable read / write heads, the solid-state storage
devices (SSDs) do not contain moving / mechanical components. Therefore the
I/O operation completion times are much more predictable for them.</xccdf-1.2:rationale>
          </xccdf-1.2:Rule>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_kernel_build_config">
          <xccdf-1.2:title>Kernel Configuration</xccdf-1.2:title>
          <xccdf-1.2:description>Contains rules that check the kernel configuration that was used to build it.</xccdf-1.2:description>
          <xccdf-1.2:platform idref="#system_with_kernel"/>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_kernel_config_module_sig_hash" type="string">
            <xccdf-1.2:title>Hash function for kernel module signing</xccdf-1.2:title>
            <xccdf-1.2:description>The hash function to use when signing modules during kernel build process.</xccdf-1.2:description>
            <xccdf-1.2:value>sha512</xccdf-1.2:value>
            <xccdf-1.2:value selector="sha1">sha1</xccdf-1.2:value>
            <xccdf-1.2:value selector="sha224">sha224</xccdf-1.2:value>
            <xccdf-1.2:value selector="sha256">sha256</xccdf-1.2:value>
            <xccdf-1.2:value selector="sha384">sha384</xccdf-1.2:value>
            <xccdf-1.2:value selector="sha512">sha512</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_kernel_config_module_sig_key" interactive="true" type="string">
            <xccdf-1.2:title>Key and certificate for kernel module signing</xccdf-1.2:title>
            <xccdf-1.2:description>The private key and certificate to use when signing modules during kernel build process.
On systems where the OpenSSL ENGINE_pkcs11 is functional — a PKCS#11 URI as defined by RFC7512
In the latter case, the PKCS#11 URI should reference both a certificate and a private key.</xccdf-1.2:description>
            <xccdf-1.2:value>certs/signing_key.pem</xccdf-1.2:value>
            <xccdf-1.2:value selector="kernel_default">certs/signing_key.pem</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_kernel_config_panic_timeout" interactive="true" type="string">
            <xccdf-1.2:title>Kernel panic timeout</xccdf-1.2:title>
            <xccdf-1.2:description>The time, in seconds, to wait until a reboot occurs.
If the value is <html:code>0</html:code> the system never reboots.
If the value is less than <html:code>0</html:code> the system reboots immediately.</xccdf-1.2:description>
            <xccdf-1.2:value>0</xccdf-1.2:value>
            <xccdf-1.2:value selector="never">0</xccdf-1.2:value>
            <xccdf-1.2:value selector="5_minutes">300</xccdf-1.2:value>
            <xccdf-1.2:value selector="1_minute">60</xccdf-1.2:value>
            <xccdf-1.2:value selector="immediately">-1</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_acpi_custom_method" selected="false" severity="low">
            <xccdf-1.2:title>Do not allow ACPI methods to be inserted/replaced at run time</xccdf-1.2:title>
            <xccdf-1.2:description>This debug facility allows ACPI AML methods to be inserted and/or replaced without rebooting
the system.
This configuration is available from kernel 3.0.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_ACPI_CUSTOM_METHOD</html:code>, run the following command:
    <html:code>grep CONFIG_ACPI_CUSTOM_METHOD /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Enabling this feature allows arbitrary kernel memory to be written to by root (uid=0) users,
allowing them to bypass certain security measures</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_acpi_custom_method:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_acpi_custom_method_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_arm64_sw_ttbr0_pan" selected="false" severity="medium">
            <xccdf-1.2:title>Emulate Privileged Access Never (PAN)</xccdf-1.2:title>
            <xccdf-1.2:description>Enabling this option prevents the kernel from accessing user-space memory directly by pointing
TTBR0_EL1 to a reserved zeroed area and reserved ASID.
The user access routines restore the valid TTBR0_EL1 temporarily.
This configuration is available from kernel 4.10, but may be available if backported
by distros.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_ARM64_SW_TTBR0_PAN</html:code>, run the following command:
    <html:code>grep CONFIG_ARM64_SW_TTBR0_PAN /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R27</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The Privileged Access Never (PAN) is the ARM equivalent of the x86 Supervisor Mode Access
Prevention (SMAP), and it prevents privileged access to user data unless explicitly enabled.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#aarch64_arch"/>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_arm64_sw_ttbr0_pan:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_binfmt_misc" selected="false" severity="medium">
            <xccdf-1.2:title>Disable kernel support for MISC binaries</xccdf-1.2:title>
            <xccdf-1.2:description>Enabling <html:code>CONFIG_BINFMT_MISC</html:code> makes it possible to plug wrapper-driven binary formats
into the kernel. This is specially useful for programs that need an interpreter to run like
Java, Python and DOS emulators. Once you have registered such a binary class with the kernel,
you can start one of those programs simply by typing in its name at a shell prompt.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_BINFMT_MISC</html:code>, run the following command:
    <html:code>grep CONFIG_BINFMT_MISC /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R23</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This disables arbitrary binary format support and helps reduce attack surface.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_binfmt_misc:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_bug" selected="false" severity="medium">
            <xccdf-1.2:title>Enable support for BUG()</xccdf-1.2:title>
            <xccdf-1.2:description>Disabling this option eliminates support for BUG and WARN, reducing the size of your kernel
image and potentially quietly ignoring numerous fatal conditions. You should only consider
disabling this option for embedded systems with no facilities for reporting errors.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_BUG</html:code>, run the following command:
    <html:code>grep CONFIG_BUG /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R19</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Not setting this variable may hide a number of critical errors.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_bug:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_bug_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_bug_on_data_corruption" selected="false" severity="low">
            <xccdf-1.2:title>Trigger a kernel BUG when data corruption is detected</xccdf-1.2:title>
            <xccdf-1.2:description>This option makes the kernel BUG when it encounters data corruption in kernel memory structures
when they get checked for validity.
This configuration is available from kernel 4.10.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_BUG_ON_DATA_CORRUPTION</html:code>, run the following command:
    <html:code>grep CONFIG_BUG_ON_DATA_CORRUPTION /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R16</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This helps detect data corruptions early and stop with a BUG() error message.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_bug_on_data_corruption:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_bug_on_data_corruption_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_compat_brk" selected="false" severity="medium">
            <xccdf-1.2:title>Disable compatibility with brk()</xccdf-1.2:title>
            <xccdf-1.2:description>Enabling compatiliby with <html:code>brk()</html:code> allows legacy binaries to run (i.e. those linked
against libc5). But this compatibility comes at the cost of not being able to randomize
the heap placement (ASLR).

Unless legacy binaries need to run on the system, set <html:code>CONFIG_COMPAT_BRK</html:code> to <html:code>"n"</html:code>.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_COMPAT_BRK</html:code>, run the following command:
    <html:code>grep CONFIG_COMPAT_BRK /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R17</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Enabling compatibility with brk() disables support for ASLR.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_compat_brk:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_compat_brk_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_compat_vdso" selected="false" severity="low">
            <xccdf-1.2:title>Disable the 32-bit vDSO</xccdf-1.2:title>
            <xccdf-1.2:description>Certain buggy versions of glibc (2.3.3) will crash if they are presented with a 32-bit vDSO
that is not mapped at the address indicated in its segment table.
Setting <html:code>CONFIG_COMPAT_VDSO</html:code> to <html:code>y</html:code> turns off the 32-bit VDSO and works
around the glibc bug.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_COMPAT_VDSO</html:code>, run the following command:
    <html:code>grep CONFIG_COMPAT_VDSO /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Enabling VDSO compatibility hurts performance and disables ASLR.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_compat_vdso:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_compat_vdso_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_debug_credentials" selected="false" severity="low">
            <xccdf-1.2:title>Enable checks on credential management</xccdf-1.2:title>
            <xccdf-1.2:description>Enable this to turn on some debug checking for credential management. The additional code keeps
track of the number of pointers from task_structs to any given cred struct, and checks to see
that this number never exceeds the usage count of the cred struct.

Furthermore, if SELinux is enabled, this also checks that the security pointer in the cred
struct is never seen to be invalid.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_DEBUG_CREDENTIALS</html:code>, run the following command:
    <html:code>grep CONFIG_DEBUG_CREDENTIALS /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R16</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This adds sanity checks and validations to credential data structures.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_debug_credentials:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_debug_credentials_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_debug_fs" selected="false" severity="low">
            <xccdf-1.2:title>Disable kernel debugfs</xccdf-1.2:title>
            <xccdf-1.2:description><html:code>debugfs</html:code> is a virtual file system that kernel developers use to put debugging files
into. Enable this option to be able to read and write to these files.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_DEBUG_FS</html:code>, run the following command:
    <html:code>grep CONFIG_DEBUG_FS /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>To reduce the attack surface, this file system should be disabled if not in use.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_debug_fs:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_debug_list" selected="false" severity="low">
            <xccdf-1.2:title>Enable checks on linked list manipulation</xccdf-1.2:title>
            <xccdf-1.2:description>Enable this to turn on extended checks in the linked-list walking routines.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_DEBUG_LIST</html:code>, run the following command:
    <html:code>grep CONFIG_DEBUG_LIST /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R16</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This add sanity checks to manipulation of linked lists structures in the kernel and may
prevent exploits such as CVE-2017-1661, where a race condition and simultaneous operations
caused a list to corrupt.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_debug_list:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_debug_list_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_debug_notifiers" selected="false" severity="low">
            <xccdf-1.2:title>Enable checks on notifier call chains</xccdf-1.2:title>
            <xccdf-1.2:description>Enable this to turn on sanity checking for notifier call chains. This is most useful for kernel
developers to make sure that modules properly unregister themselves from notifier chains.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_DEBUG_NOTIFIERS</html:code>, run the following command:
    <html:code>grep CONFIG_DEBUG_NOTIFIERS /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R16</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This provides validation of notifier chains, it checks whether the notifiers are from the
kernel or a module that is still loaded prior to being invoked.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_debug_notifiers:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_debug_notifiers_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_debug_sg" selected="false" severity="low">
            <xccdf-1.2:title>Enable checks on scatter-gather (SG) table operations</xccdf-1.2:title>
            <xccdf-1.2:description>Scatter-gather tables are mechanism used for high performance I/O on DMA devices.
Enable this to turn on checks on scatter-gather tables.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_DEBUG_SG</html:code>, run the following command:
    <html:code>grep CONFIG_DEBUG_SG /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R16</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This can help find problems with drivers that do not properly initialize their SG tables.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_debug_sg:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_debug_sg_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_debug_wx" selected="false" severity="medium">
            <xccdf-1.2:title>Warn on W+X mappings found at boot</xccdf-1.2:title>
            <xccdf-1.2:description>Generate a warning if any W+X mappings are found at boot.
This configuration is available from kernel 5.8.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_DEBUG_WX</html:code>, run the following command:
    <html:code>grep CONFIG_DEBUG_WX /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This is useful for discovering cases where the kernel is leaving W+X mappings after applying NX,
as such mappings are a security risk.
Note that even if the check fails, your kernel is possibly still fine, as W+X mappings are not
a security hole in themselves, what they do is that they make the exploitation of other unfixed
kernel bugs easier.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_debug_wx:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_debug_wx_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_default_mmap_min_addr" selected="false" severity="medium">
            <xccdf-1.2:title>Configure Low Address Space To Protect From User Allocation</xccdf-1.2:title>
            <xccdf-1.2:description>This is the portion of low virtual memory which should be protected from userspace allocation.
This configuration is available from kernel 3.14, but may be available if backported
by distros.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
To check the configuration value for <html:code>CONFIG_DEFAULT_MMAP_MIN_ADDR</html:code>, run the following command:
<html:code>grep CONFIG_DEFAULT_MMAP_MIN_ADDR /boot/config-*</html:code>
For each kernel installed, a line with value should be returned.
If the system architecture is x86_64, the value should be 65536.
If the system architecture is aarch64, the value should be 32768.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R25</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R27</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Keeping a user from writing to low pages can help reduce the impact of kernel NULL pointer bugs.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#aarch64_arch_or_x86_64_arch"/>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_default_mmap_min_addr:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_default_mmap_min_addr_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_devkmem" selected="false" severity="low">
            <xccdf-1.2:title>Disable /dev/kmem virtual device support</xccdf-1.2:title>
            <xccdf-1.2:description>Disable support for the /dev/kmem device.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_DEVKMEM</html:code>, run the following command:
    <html:code>grep CONFIG_DEVKMEM /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The /dev/kmem device is rarely used, but can be used for certain kind of kernel debugging
operations.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_devkmem:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_devkmem_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_fortify_source" selected="false" severity="medium">
            <xccdf-1.2:title>Harden common str/mem functions against buffer overflows</xccdf-1.2:title>
            <xccdf-1.2:description>Detect overflows of buffers in common string and memory functions where the compiler can
determine and validate the buffer sizes.
This configuration is available from kernel 4.13, but may be available if backported by distros.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_FORTIFY_SOURCE</html:code>, run the following command:
    <html:code>grep CONFIG_FORTIFY_SOURCE /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This features helps reduce likelihood of memory corruption of kernel structures.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_fortify_source:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_fortify_source_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_hardened_usercopy" selected="false" severity="high">
            <xccdf-1.2:title>Harden memory copies between kernel and userspace</xccdf-1.2:title>
            <xccdf-1.2:description>This option checks for obviously wrong memory regions when copying memory to/from the kernel
(via copy_to_user() and copy_from_user() functions) by rejecting memory ranges that are larger
than the specified heap object, span multiple separately allocated pages, are not on the
process stack, or are part of the kernel text.
This configuration is available from kernel 4.8, and may be available if backported by distros.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_HARDENED_USERCOPY</html:code>, run the following command:
    <html:code>grep CONFIG_HARDENED_USERCOPY /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This config prevents entire classes of heap overflow exploits and similar kernel memory exposures.
</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_hardened_usercopy:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_hardened_usercopy_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_hardened_usercopy_fallback" selected="false" severity="high">
            <xccdf-1.2:title>Do not allow usercopy whitelist violations to fallback to object size</xccdf-1.2:title>
            <xccdf-1.2:description>This is a temporary option that allows missing usercopy whitelists to be discovered via a WARN()
to the kernel log, instead of rejecting the copy, falling back to non-whitelisted hardened
usercopy that checks the slab allocation size instead of the whitelist size.
This configuration is available from kernel 4.16.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_HARDENED_USERCOPY_FALLBACK</html:code>, run the following command:
    <html:code>grep CONFIG_HARDENED_USERCOPY_FALLBACK /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This config prevents entire classes of heap overflow exploits and similar kernel memory exposures.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_hardened_usercopy_fallback:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_hardened_usercopy_fallback_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_hibernation" selected="false" severity="medium">
            <xccdf-1.2:title>Disable hibernation</xccdf-1.2:title>
            <xccdf-1.2:description>Enable the suspend to disk (STD) functionality, which is usually called "hibernation" in user
interfaces. STD checkpoints the system and powers it off; and restores that checkpoint on
reboot.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_HIBERNATION</html:code>, run the following command:
    <html:code>grep CONFIG_HIBERNATION /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R23</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Suspending to disk allows one to replace the running kernel.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_hibernation:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_hibernation_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_ia32_emulation" selected="false" severity="medium">
            <xccdf-1.2:title>Disable IA32 emulation</xccdf-1.2:title>
            <xccdf-1.2:description>Disables support for legacy 32-bit programs under a 64-bit kernel.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_IA32_EMULATION</html:code>, run the following command:
    <html:code>grep CONFIG_IA32_EMULATION /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:warning category="general">Only disable support for 32-bit programs if you are sure you don't need any 32-bit program.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R25</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Disabling 32-bit backwards compatibility helps reduce the attack surface.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#x86_64_arch"/>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_ia32_emulation:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_ipv6" selected="false" severity="medium">
            <xccdf-1.2:title>Disable the IPv6 protocol</xccdf-1.2:title>
            <xccdf-1.2:description>Disable support for IP version 6 (IPv6).

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_IPV6</html:code>, run the following command:
    <html:code>grep CONFIG_IPV6 /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:rationale>Any unnecessary network stacks, including IPv6, should be disabled to reduce
the vulnerability to exploitation.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_ipv6:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_ipv6_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_kexec" selected="false" severity="low">
            <xccdf-1.2:title>Disable kexec system call</xccdf-1.2:title>
            <xccdf-1.2:description><html:code>kexec</html:code> is a system call that implements the ability to shutdown your current kernel,
and to start another kernel. It is like a reboot but it is independent of the system firmware.
And like a reboot you can start any kernel with it, not just Linux.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_KEXEC</html:code>, run the following command:
    <html:code>grep CONFIG_KEXEC /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R23</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Prohibits the execution of a new kernel image after reboot.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_kexec:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_kexec_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_legacy_ptys" selected="false" severity="medium">
            <xccdf-1.2:title>Disable legacy (BSD) PTY support</xccdf-1.2:title>
            <xccdf-1.2:description>Disable the Linux traditional BSD-like terminal names /dev/ptyxx for masters and /dev/ttyxx for
slaves of pseudo terminals, and use only the modern ptys (devpts) interface.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_LEGACY_PTYS</html:code>, run the following command:
    <html:code>grep CONFIG_LEGACY_PTYS /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R23</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The legacy scheme has a number of security problems.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_legacy_ptys:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_legacy_ptys_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_legacy_vsyscall_emulate" selected="false" severity="medium">
            <xccdf-1.2:title>Disable vsyscall emulation</xccdf-1.2:title>
            <xccdf-1.2:description>The kernel traps and emulates calls into the fixed vsyscall address mapping.
This configuration is available from kernel 5.3, but may be available if backported by distros.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_LEGACY_VSYSCALL_EMULATE</html:code>, run the following command:
    <html:code>grep CONFIG_LEGACY_VSYSCALL_EMULATE /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The mapping is non-executable, but it still contains known contents, which could be
used in certain rare security vulnerability exploits.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_legacy_vsyscall_emulate:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_legacy_vsyscall_emulate_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_legacy_vsyscall_none" selected="false" severity="medium">
            <xccdf-1.2:title>Disable vsyscall mapping</xccdf-1.2:title>
            <xccdf-1.2:description>This config disables the vsyscall mapping at all. Attempts to use the vsyscalls will be reported to
dmesg, so that either old or malicious userspace programs can be identified.
This configuration is available from kernel 4.4.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_LEGACY_VSYSCALL_NONE</html:code>, run the following command:
    <html:code>grep CONFIG_LEGACY_VSYSCALL_NONE /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This will eliminate any risk of ASLR bypass due to the vsyscall fixed address mapping.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_legacy_vsyscall_none:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_legacy_vsyscall_none_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_modify_ldt_syscall" selected="false" severity="medium">
            <xccdf-1.2:title>Disable the LDT (local descriptor table)</xccdf-1.2:title>
            <xccdf-1.2:description>Linux can allow user programs to install a per-process x86 Local Descriptor Table (LDT) using
the modify_ldt(2) system call. This is required to run 16-bit or segmented code such as DOSEMU
or some Wine programs. It is also used by some very old threading libraries.
This configuration is available from kernel 4.3, but may be available if backported
by distros.

Disable LDT if 16-bit program emulation is not necessary.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_MODIFY_LDT_SYSCALL</html:code>, run the following command:
    <html:code>grep CONFIG_MODIFY_LDT_SYSCALL /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R25</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Disabling support for unnecessary code reduces attack surface.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#x86_64_arch"/>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_modify_ldt_syscall:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_modify_ldt_syscall_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_module_sig" selected="false" severity="medium">
            <xccdf-1.2:title>Enable module signature verification</xccdf-1.2:title>
            <xccdf-1.2:description>Check modules for valid signatures upon load.
Note that this option adds the OpenSSL development packages as a kernel build dependency so
that the signing tool can use its crypto library.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_MODULE_SIG</html:code>, run the following command:
    <html:code>grep CONFIG_MODULE_SIG /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R18</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Loaded modules must be signed.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_module_sig:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_module_sig_all" selected="false" severity="medium">
            <xccdf-1.2:title>Enable automatic signing of all modules</xccdf-1.2:title>
            <xccdf-1.2:description>Sign all modules during make modules_install. Without this option, modules must be signed
manually, using the scripts/sign-file tool.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_MODULE_SIG_ALL</html:code>, run the following command:
    <html:code>grep CONFIG_MODULE_SIG_ALL /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R18</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This ensures the modules are signed during install process.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_module_sig_all:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_module_sig_all_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_module_sig_force" selected="false" severity="medium">
            <xccdf-1.2:title>Require modules to be validly signed</xccdf-1.2:title>
            <xccdf-1.2:description>Reject unsigned modules or signed modules with an unknown key.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_MODULE_SIG_FORCE</html:code>, run the following command:
    <html:code>grep CONFIG_MODULE_SIG_FORCE /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R18</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Prevent loading modules that are unsigned or signed with an unknown key.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_module_sig_force:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_module_sig_force_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_module_sig_hash" selected="false" severity="medium">
            <xccdf-1.2:title>Specify the hash to use when signing modules</xccdf-1.2:title>
            <xccdf-1.2:description>This configures the kernel to build and sign modules using
<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_kernel_config_module_sig_hash" use="legacy"/> as the hash function.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_MODULE_SIG_HASH</html:code>, run the following command:
    <html:code>grep CONFIG_MODULE_SIG_HASH /boot/config-*</html:code>
    
    For each kernel installed, a line with value "<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_kernel_config_module_sig_hash" use="legacy"/>" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R18</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Use of strong hash function is important to secure the module against counterfeit signatures.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_kernel_config_module_sig_hash:var:1" value-id="xccdf_org.ssgproject.content_value_var_kernel_config_module_sig_hash"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_module_sig_hash:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_module_sig_key" selected="false" severity="medium">
            <xccdf-1.2:title>Specify module signing key to use</xccdf-1.2:title>
            <xccdf-1.2:description>Setting this option to something other than its default of <html:code>certs/signing_key.pem</html:code> will
disable the autogeneration of signing keys and allow the kernel modules to be signed with a key
of your choosing.

The string provided should identify a file containing both a private key and
its corresponding X.509 certificate in PEM form, or — on systems where the OpenSSL ENGINE_pkcs11
is functional — a PKCS#11 URI as defined by RFC7512. In the latter case, the PKCS#11 URI should
reference both a certificate and a private key.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_MODULE_SIG_KEY</html:code>, run the following command:
    <html:code>grep CONFIG_MODULE_SIG_KEY /boot/config-*</html:code>
    
    For each kernel installed, a line with value "<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_kernel_config_module_sig_key" use="legacy"/>" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R18</xccdf-1.2:reference>
            <xccdf-1.2:rationale>A key and certificate is required to sign the built modules.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_kernel_config_module_sig_key:var:1" value-id="xccdf_org.ssgproject.content_value_var_kernel_config_module_sig_key"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_module_sig_key:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_module_sig_sha512" selected="false" severity="medium">
            <xccdf-1.2:title>Sign kernel modules with SHA-512</xccdf-1.2:title>
            <xccdf-1.2:description>This configures the kernel to build and sign modules using SHA512 as the hash function.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_MODULE_SIG_SHA512</html:code>, run the following command:
    <html:code>grep CONFIG_MODULE_SIG_SHA512 /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R18</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Use of strong hash function is important to secure the module against counterfeit signatures.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_module_sig_sha512:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_module_sig_sha512_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_page_poisoning" selected="false" severity="medium">
            <xccdf-1.2:title>Enable poison of pages after freeing</xccdf-1.2:title>
            <xccdf-1.2:description>Fill the pages with poison patterns after free_pages() and verify the patterns before
alloc_pages. This does have a potential performance impact if enabled with the "page_poison=1"
kernel boot option.
This configuration is available from kernel 4.6.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_PAGE_POISONING</html:code>, run the following command:
    <html:code>grep CONFIG_PAGE_POISONING /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R17</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The filling of the memory helps reduce the risk of information leaks from freed data.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_page_poisoning:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_page_poisoning_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_page_poisoning_no_sanity" selected="false" severity="medium">
            <xccdf-1.2:title>Enable poison without sanity check</xccdf-1.2:title>
            <xccdf-1.2:description>Skip the sanity checking on alloc, only fill the pages with poison on free. This reduces some
of the overhead of the poisoning feature.
This configuration is available from kernel 4.6.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_PAGE_POISONING_NO_SANITY</html:code>, run the following command:
    <html:code>grep CONFIG_PAGE_POISONING_NO_SANITY /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R17</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This configuration helps alleviates the performance impact of poisonining.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_page_poisoning_no_sanity:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_page_poisoning_no_sanity_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_page_poisoning_zero" selected="false" severity="medium">
            <xccdf-1.2:title>Use zero for poisoning instead of debugging value</xccdf-1.2:title>
            <xccdf-1.2:description>Instead of using the existing poison value, fill the pages with zeros. This makes it harder to
detect when errors are occurring due to sanitization but the zeroing at free means that it is
no longer necessary to write zeros when GFP_ZERO is used on allocation.
This configuration is available from kernel 4.19.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_PAGE_POISONING_ZERO</html:code>, run the following command:
    <html:code>grep CONFIG_PAGE_POISONING_ZERO /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R17</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This configuration helps alleviates the performance impact of poisonining.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_page_poisoning_zero:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_page_table_isolation" selected="false" severity="high">
            <xccdf-1.2:title>Remove the kernel mapping in user mode</xccdf-1.2:title>
            <xccdf-1.2:description>This feature reduces the number of hardware side channels by ensuring that the majority of
kernel addresses are not mapped into userspace.
This configuration is available from kernel 4.15, but may be available if backported
by distros.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_PAGE_TABLE_ISOLATION</html:code>, run the following command:
    <html:code>grep CONFIG_PAGE_TABLE_ISOLATION /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R25</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This is a countermeasure to the Meltdown attack.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#x86_64_arch"/>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_page_table_isolation:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_page_table_isolation_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_panic_on_oops" selected="false" severity="medium">
            <xccdf-1.2:title>Kernel panic oops</xccdf-1.2:title>
            <xccdf-1.2:description>Enable the kernel to panic when it oopses.
This has the same effect as setting oops=panic on the kernel command line.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_PANIC_ON_OOPS</html:code>, run the following command:
    <html:code>grep CONFIG_PANIC_ON_OOPS /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R19</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This feature ensures that the kernel does not do anything erroneous after an oops which
could result in data corruption or other issues.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_panic_on_oops:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_panic_on_oops_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_panic_timeout" selected="false" severity="medium">
            <xccdf-1.2:title>Kernel panic timeout</xccdf-1.2:title>
            <xccdf-1.2:description>Set the timeout value (in seconds) until a reboot occurs when the kernel panics.
A timeout of 0 configures the system to wait forever. With a timeout value greater than 0,
the system will wait the specified amount of seconds before rebooting. While a timeout value
less than 0 makes the system reboot immediately.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_PANIC_TIMEOUT</html:code>, run the following command:
    <html:code>grep CONFIG_PANIC_TIMEOUT /boot/config-*</html:code>
    
    For each kernel installed, a line with value "<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_kernel_config_panic_timeout" use="legacy"/>" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R19</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This is required to enable protection against Spectre v2.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_kernel_config_panic_timeout:var:1" value-id="xccdf_org.ssgproject.content_value_var_kernel_config_panic_timeout"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_panic_timeout:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_panic_timeout_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_proc_kcore" selected="false" severity="low">
            <xccdf-1.2:title>Disable support for /proc/kkcore</xccdf-1.2:title>
            <xccdf-1.2:description>Provides a virtual ELF core file of the live kernel.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_PROC_KCORE</html:code>, run the following command:
    <html:code>grep CONFIG_PROC_KCORE /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This feature exposes the memory to the userspace and can assist an attacker in discovering
attack vectors.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_proc_kcore:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_proc_kcore_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_randomize_base" selected="false" severity="medium">
            <xccdf-1.2:title>Randomize the address of the kernel image (KASLR)</xccdf-1.2:title>
            <xccdf-1.2:description>In support of Kernel Address Space Layout Randomization (KASLR), this randomizes the physical
address at which the kernel image is decompressed and the virtual address where the kernel
image is mapped.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_RANDOMIZE_BASE</html:code>, run the following command:
    <html:code>grep CONFIG_RANDOMIZE_BASE /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R25</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R27</xccdf-1.2:reference>
            <xccdf-1.2:rationale>An unpredictable kernel address makes it more difficult to succeed with exploits that rely on
knowledge of the location of kernel code internals.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_randomize_base:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_randomize_base_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_randomize_memory" selected="false" severity="medium">
            <xccdf-1.2:title>Randomize the kernel memory sections</xccdf-1.2:title>
            <xccdf-1.2:description>Randomizes the base virtual address of kernel memory sections (physical memory mapping,
vmalloc &amp; vmemmap).
This configuration is available from kernel 4.8, but may be available if backported
by distros.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_RANDOMIZE_MEMORY</html:code>, run the following command:
    <html:code>grep CONFIG_RANDOMIZE_MEMORY /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R25</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This security feature makes exploits relying on predictable memory locations less reliable.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#x86_64_arch"/>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_randomize_memory:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_refcount_full" selected="false" severity="medium">
            <xccdf-1.2:title>Perform full reference count validation</xccdf-1.2:title>
            <xccdf-1.2:description>Enabling this switches the refcounting infrastructure from a fast unchecked atomic_t
implementation to a fully state checked implementation, which can have a slight
impact in performance.
This configuration is available from kernel 4.13, but may be available if backported
by distros.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_REFCOUNT_FULL</html:code>, run the following command:
    <html:code>grep CONFIG_REFCOUNT_FULL /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Refcounting provides protections against various use-after-free conditions that can be
used in security flaw exploits.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_refcount_full:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_refcount_full_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_retpoline" selected="false" severity="medium">
            <xccdf-1.2:title>Avoid speculative indirect branches in kernel</xccdf-1.2:title>
            <xccdf-1.2:description>Compile kernel with the retpoline compiler options to guard against kernel-to-user data leaks
by avoiding speculative indirect branches.
Requires a compiler with -mindirect-branch=thunk-extern support for full protection.
The kernel may run slower.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_RETPOLINE</html:code>, run the following command:
    <html:code>grep CONFIG_RETPOLINE /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This is required to enable protection against Spectre v2.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_retpoline:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_retpoline_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_sched_stack_end_check" selected="false" severity="medium">
            <xccdf-1.2:title>Detect stack corruption on calls to schedule()</xccdf-1.2:title>
            <xccdf-1.2:description>This option checks for a stack overrun on calls to schedule(). If the stack end location is
found to be overwritten always panic as the content of the corrupted region can no longer
be trusted.
This configuration is available from kernel 3.18.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_SCHED_STACK_END_CHECK</html:code>, run the following command:
    <html:code>grep CONFIG_SCHED_STACK_END_CHECK /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This ensures no erroneous behaviour occurs which could result in data corruption or a
sporadic crash at a later stage once the region is examined.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_sched_stack_end_check:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_sched_stack_end_check_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_seccomp" selected="false" severity="medium">
            <xccdf-1.2:title>Enable seccomp to safely compute untrusted bytecode</xccdf-1.2:title>
            <xccdf-1.2:description>This kernel feature is useful for number crunching applications that may need to compute
untrusted bytecode during their execution. By using pipes or other transports made available
to the process as file descriptors supporting the read/write syscalls, it's possible to isolate
those applications in their own address space using seccomp.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_SECCOMP</html:code>, run the following command:
    <html:code>grep CONFIG_SECCOMP /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R20</xccdf-1.2:reference>
            <xccdf-1.2:rationale><html:code>seccomp</html:code> enables the ability to filter system calls made by an application, effectively
isolating the system's resources from it.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_seccomp:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_seccomp_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_seccomp_filter" selected="false" severity="medium">
            <xccdf-1.2:title>Enable use of Berkeley Packet Filter with seccomp</xccdf-1.2:title>
            <xccdf-1.2:description>Enable tasks to build secure computing environments defined in terms of Berkeley Packet Filter
programs which implement task-defined system call filtering polices.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_SECCOMP_FILTER</html:code>, run the following command:
    <html:code>grep CONFIG_SECCOMP_FILTER /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R20</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Use of BPF filters allows for expressive filtering of system calls using a filter program
language with a long history of being exposed to userland.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_seccomp_filter:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_seccomp_filter_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_security" selected="false" severity="medium">
            <xccdf-1.2:title>Enable different security models</xccdf-1.2:title>
            <xccdf-1.2:description>This allows you to choose different security modules to be configured into your kernel.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_SECURITY</html:code>, run the following command:
    <html:code>grep CONFIG_SECURITY /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R20</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This is enables kernel security primitives required by the LSM framework.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_security:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_security_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_security_dmesg_restrict" selected="false" severity="medium">
            <xccdf-1.2:title>Restrict unprivileged access to the kernel syslog</xccdf-1.2:title>
            <xccdf-1.2:description>Enforce restrictions on unprivileged users reading the kernel syslog via dmesg(8).

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_SECURITY_DMESG_RESTRICT</html:code>, run the following command:
    <html:code>grep CONFIG_SECURITY_DMESG_RESTRICT /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Prevents unprivileged users from retrieving kernel addresses with dmesg.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_security_dmesg_restrict:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_security_dmesg_restrict_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_security_writable_hooks" selected="false" severity="medium">
            <xccdf-1.2:title>Disable mutable hooks</xccdf-1.2:title>
            <xccdf-1.2:description>Ensure kernel structures associated with LSMs are always mapped as read-only after system boot.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_SECURITY_WRITABLE_HOOKS</html:code>, run the following command:
    <html:code>grep CONFIG_SECURITY_WRITABLE_HOOKS /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R20</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If CONFIG_SECURITY_WRITABLE_HOOKS is enabled, then hooks can be loaded at runtime and
being able to manipulate hooks is a way to bypass all LSMs.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_security_writable_hooks:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_security_writable_hooks_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_security_yama" selected="false" severity="medium">
            <xccdf-1.2:title>Enable Yama support</xccdf-1.2:title>
            <xccdf-1.2:description>This enables support for LSM module Yama, which extends DAC support with additional system-wide
security settings beyond regular Linux discretionary access controls. The module will limit the
use of the system call <html:code>ptrace()</html:code>.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_SECURITY_YAMA</html:code>, run the following command:
    <html:code>grep CONFIG_SECURITY_YAMA /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R20</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Unrestricted usage of ptrace allows compromised binaries to run ptrace
on another processes of the user.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_security_yama:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_slab_freelist_hardened" selected="false" severity="medium">
            <xccdf-1.2:title>Harden slab freelist metadata</xccdf-1.2:title>
            <xccdf-1.2:description>This feature protects integrity of the allocator's metadata.
This configuration is available from kernel 4.14.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_SLAB_FREELIST_HARDENED</html:code>, run the following command:
    <html:code>grep CONFIG_SLAB_FREELIST_HARDENED /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R17</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Many kernel heap attacks try to target slab cache metadata and other infrastructure.
This options makes minor performance sacrifices to harden the kernel slab allocator against
common freelist exploit methods.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_slab_freelist_hardened:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_slab_freelist_hardened_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_slab_freelist_random" selected="false" severity="medium">
            <xccdf-1.2:title>Randomize slab freelist</xccdf-1.2:title>
            <xccdf-1.2:description>Randomizes the freelist order used on creating new pages.
This configuration is available from kernel 5.9, but may be available if backported by distros.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_SLAB_FREELIST_RANDOM</html:code>, run the following command:
    <html:code>grep CONFIG_SLAB_FREELIST_RANDOM /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R17</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This security feature reduces the predictability of the kernel slab allocator against heap overflows.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_slab_freelist_random:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_slab_freelist_random_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_slab_merge_default" selected="false" severity="medium">
            <xccdf-1.2:title>Disallow merge of slab caches</xccdf-1.2:title>
            <xccdf-1.2:description>For reduced kernel memory fragmentation, slab caches can be merged when they share the same
size and other characteristics. This carries a risk of kernel heap overflows being able to
overwrite objects from merged caches (and more easily control cache layout), which makes such
heap attacks easier to exploit by attackers.
This configuration is available from kernel 4.13.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_SLAB_MERGE_DEFAULT</html:code>, run the following command:
    <html:code>grep CONFIG_SLAB_MERGE_DEFAULT /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R17</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Disabling the merge of slabs of similar sizes prevents the kernel from
merging a seemingly useless but vulnerable slab with a useful and valuable slab.
This increase the risk that a heap overflow could overwrite objects from merged caches,
with unmerged caches the heap overflow would only affect the objects in the same cache.
Overall, this reduces the kernel attack surface area by isolating slabs from each other.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_slab_merge_default:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_slab_merge_default_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_slub_debug" selected="false" severity="medium">
            <xccdf-1.2:title>Enable SLUB debugging support</xccdf-1.2:title>
            <xccdf-1.2:description>SLUB has extensive debug support features and this allows the allocator validation checking to
be enabled.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_SLUB_DEBUG</html:code>, run the following command:
    <html:code>grep CONFIG_SLUB_DEBUG /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R17</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This activates the checking of the memory allocator structures and resets to zero the zones
allocated when they are released.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_slub_debug:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_slub_debug_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_stackprotector" selected="false" severity="medium">
            <xccdf-1.2:title>Stack Protector buffer overflow detection</xccdf-1.2:title>
            <xccdf-1.2:description>This feature puts, at the beginning of functions, a canary value on the stack just before the
return address, and validates the value just before actually returning.
This configuration is available from kernel 4.18.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_STACKPROTECTOR</html:code>, run the following command:
    <html:code>grep CONFIG_STACKPROTECTOR /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This halts the program when a stack overflow is detected, potentially reducing the impact of
exploits.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_stackprotector:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_stackprotector_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_stackprotector_strong" selected="false" severity="medium">
            <xccdf-1.2:title>Strong Stack Protector</xccdf-1.2:title>
            <xccdf-1.2:description>This features adds canary logic protection to more kinds of vulnerable functions than
CONFIG_STACKPROTECTOR, but not to all functions so that performance is not severily impacted.
This configuration is available from kernel 4.18.
This config requires gcc version 4.9 or above, or a distribution gcc with the feature
backported ("-fstack-protector-strong").

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_STACKPROTECTOR_STRONG</html:code>, run the following command:
    <html:code>grep CONFIG_STACKPROTECTOR_STRONG /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This provides a mechanism that protects more vulnerable functions than CONFIG_STACKPROTECTOR,
balancing between security and performance.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_stackprotector_strong:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_stackprotector_strong_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_strict_kernel_rwx" selected="false" severity="medium">
            <xccdf-1.2:title>Make the kernel text and rodata read-only</xccdf-1.2:title>
            <xccdf-1.2:description>When set, kernel text and rodata memory will be made read-only, and non-text memory will be made non-executable.
This configuration is available from kernel 4.11.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_STRICT_KERNEL_RWX</html:code>, run the following command:
    <html:code>grep CONFIG_STRICT_KERNEL_RWX /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This provides protection against certain security exploits (e.g. executing the heap or modifying text)</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_strict_kernel_rwx:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_strict_kernel_rwx_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_strict_module_rwx" selected="false" severity="medium">
            <xccdf-1.2:title>Make the module text and rodata read-only</xccdf-1.2:title>
            <xccdf-1.2:description>When set, module text and rodata memory will be made read-only, and non-text memory will be made non-executable.
This configuration is available from kernel 4.11.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_STRICT_MODULE_RWX</html:code>, run the following command:
    <html:code>grep CONFIG_STRICT_MODULE_RWX /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R18</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This provides protection against certain security exploits (e.g. executing the heap or modifying text)</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_strict_module_rwx:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_strict_module_rwx_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_syn_cookies" selected="false" severity="medium">
            <xccdf-1.2:title>Enable TCP/IP syncookie support</xccdf-1.2:title>
            <xccdf-1.2:description>Normal TCP/IP networking is open to an attack known as SYN flooding.
It is denial-of-service attack that prevents legitimate remote users from being able to connect
to your computer during an ongoing attack.

When enabled the TCP/IP stack will use a cryptographic challenge protocol known as SYN cookies
to enable legitimate users to continue to connect, even when your machine is under attack.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_SYN_COOKIES</html:code>, run the following command:
    <html:code>grep CONFIG_SYN_COOKIES /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R22</xccdf-1.2:reference>
            <xccdf-1.2:rationale>SYN cookies provide protection against SYN flooding attacks.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_syn_cookies:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_syn_cookies_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_unmap_kernel_at_el0" selected="false" severity="medium">
            <xccdf-1.2:title>Unmap kernel when running in userspace (aka KAISER)</xccdf-1.2:title>
            <xccdf-1.2:description>Speculation attacks against some high-performance processors can be used to bypass MMU
permission checks and leak kernel data to userspace. This can be defended against by unmapping
the kernel when running in userspace, mapping it back in on exception entry via a trampoline
page in the vector table.
This configuration is available from kernel 4.16, but may be available if backported
by distros.
The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_UNMAP_KERNEL_AT_EL0</html:code>, run the following command:
    <html:code>grep CONFIG_UNMAP_KERNEL_AT_EL0 /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R27</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This is a countermeasure to the Meltdown attack.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#aarch64_arch"/>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_unmap_kernel_at_el0:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_unmap_kernel_at_el0_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_vmap_stack" selected="false" severity="medium">
            <xccdf-1.2:title>User a virtually-mapped stack</xccdf-1.2:title>
            <xccdf-1.2:description>Enable this to use virtually-mapped kernel stacks with guard pages.
This configuration is available from kernel 4.9.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_VMAP_STACK</html:code>, run the following command:
    <html:code>grep CONFIG_VMAP_STACK /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This causes kernel stack overflows to be caught immediately rather than causing difficult-to-diagnose corruption.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_vmap_stack:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_vmap_stack_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_x86_vsyscall_emulation" selected="false" severity="low">
            <xccdf-1.2:title>Disable x86 vsyscall emulation</xccdf-1.2:title>
            <xccdf-1.2:description>Disabling it is roughly equivalent to booting with vsyscall=none, except that it will also
disable the helpful warning if a program tries to use a vsyscall. With this option set to N,
offending programs will just segfault, citing addresses of the form 0xffffffffff600?00.
This configuration is available from kernel 3.19.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_X86_VSYSCALL_EMULATION</html:code>, run the following command:
    <html:code>grep CONFIG_X86_VSYSCALL_EMULATION /boot/config-*</html:code>
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    </xccdf-1.2:description>
            <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R15</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The vsyscall table is no longer required and is a potential source of ROP gadgets.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_x86_vsyscall_emulation:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_x86_vsyscall_emulation_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_gcc_plugin">
            <xccdf-1.2:title>Kernel GCC plugin configuration</xccdf-1.2:title>
            <xccdf-1.2:description>Contains rules that check the configuration of GCC plugins used by the compiler</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_gcc_plugin_latent_entropy" selected="false" severity="medium">
              <xccdf-1.2:title>Generate some entropy during boot and runtime</xccdf-1.2:title>
              <xccdf-1.2:description>Instrument some kernel code to extract some entropy from both original and artificially created
program state. This will help especially embedded systems where there is little 'natural' source
of entropy normally.

This configuration is available from kernel 4.9, but may be available if backported
by distros.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_GCC_PLUGIN_LATENT_ENTROPY</html:code>, run the following command:
    <html:code>grep CONFIG_GCC_PLUGIN_LATENT_ENTROPY /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
              <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
              <xccdf-1.2:warning category="general">Note that entropy extracted this way is not cryptographically secure!</xccdf-1.2:warning>
              <xccdf-1.2:warning category="performance">There is a performance cost during the boot process (about 0.5%) and fork and irq processing.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R21</xccdf-1.2:reference>
              <xccdf-1.2:rationale>This helps generate entropy during startup and is particularly relevant for devices with
inappropriate entropy sources.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_gcc_plugin_latent_entropy:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_gcc_plugin_latent_entropy_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_config_gcc_plugin_structleak" selected="false" severity="medium">
              <xccdf-1.2:title>Force initialization of variables containing userspace addresses</xccdf-1.2:title>
              <xccdf-1.2:description>While the kernel is built with warnings enabled for any missed stack variable initializations,
this warning is silenced for anything passed by reference to another function, under the
occasionally misguided assumption that the function will do the initialization. As this
regularly leads to exploitable flaws, this plugin is available to identify and zero-initialize
such variables, depending on the chosen level of coverage.
This configuration is available from kernel 4.11, but may be available if backported
by distros.

The configuration that was used to build kernel is available at <html:code>/boot/config-*</html:code>.
    To check the configuration value for <html:code>CONFIG_GCC_PLUGIN_STRUCTLEAK</html:code>, run the following command:
    <html:code>grep CONFIG_GCC_PLUGIN_STRUCTLEAK /boot/config-*</html:code>
    
    For each kernel installed, a line with value "y" should be returned.
    </xccdf-1.2:description>
              <xccdf-1.2:warning category="general">There is no remediation for this besides re-compiling the kernel with the appropriate value for the config.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R21</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Initializing structures from userspace can prevent some classes of information exposure.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_config_gcc_plugin_structleak:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_config_gcc_plugin_structleak_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_logging">
          <xccdf-1.2:title>Configure Syslog</xccdf-1.2:title>
          <xccdf-1.2:description>The syslog service has been the default Unix logging mechanism for
many years. It has a number of downsides, including inconsistent log format,
lack of authentication for received messages, and lack of authentication,
encryption, or reliable transport for messages sent over a network. However,
due to its long history, syslog is a de facto standard which is supported by
almost all Unix applications.
<html:br/>
<html:br/>
In AlmaLinux OS 8, rsyslog has replaced ksyslogd as the
syslog daemon of choice, and it includes some additional security features
such as reliable, connection-oriented (i.e. TCP) transmission of logs, the
option to log to database formats, and the encryption of log data en route to
a central logging server.
This section discusses how to configure rsyslog for
best effect, and how to use tools provided with the system to maintain and
monitor logs.</xccdf-1.2:description>
          <xccdf-1.2:platform idref="#system_with_kernel"/>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_rsyslog-gnutls_installed" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure rsyslog-gnutls is installed</xccdf-1.2:title>
            <xccdf-1.2:description>TLS protocol support for rsyslog is installed.
The <html:code>rsyslog-gnutls</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install rsyslog-gnutls</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000120-GPOS-00061</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R71</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030680</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230478r1017268_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The rsyslog-gnutls package provides Transport Layer Security (TLS) support
for the rsyslog daemon, which enables secure remote logging.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsyslog-gnutls_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "rsyslog-gnutls" ; then
    yum install -y "rsyslog-gnutls"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsyslog-gnutls_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030680
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_rsyslog-gnutls_installed

- name: Ensure rsyslog-gnutls is installed
  ansible.builtin.package:
    name: rsyslog-gnutls
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030680
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_rsyslog-gnutls_installed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsyslog-gnutls_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_rsyslog-gnutls

class install_rsyslog-gnutls {
  package { 'rsyslog-gnutls':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsyslog-gnutls_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=rsyslog-gnutls
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_rsyslog-gnutls_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "rsyslog-gnutls"
version = "*"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsyslog-gnutls_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install rsyslog-gnutls
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsyslog-gnutls_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install rsyslog-gnutls
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_rsyslog-gnutls_installed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_rsyslog-gnutls_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_rsyslog_installed" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure rsyslog is Installed</xccdf-1.2:title>
            <xccdf-1.2:description>Rsyslog is installed by default. The <html:code>rsyslog</html:code> package can be installed with the following command: <html:pre> $ sudo yum install rsyslog</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(ii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000479-GPOS-00224</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000051-GPOS-00024</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.2.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030670</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230477r1017267_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The rsyslog package provides the rsyslog daemon, which provides
system logging services.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsyslog_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "rsyslog" ; then
    yum install -y "rsyslog"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsyslog_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030670
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_rsyslog_installed

- name: Ensure rsyslog is installed
  ansible.builtin.package:
    name: rsyslog
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030670
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_rsyslog_installed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsyslog_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_rsyslog

class install_rsyslog {
  package { 'rsyslog':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsyslog_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=rsyslog
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_rsyslog_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "rsyslog"
version = "*"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsyslog_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install rsyslog
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsyslog_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install rsyslog
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_rsyslog_installed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_rsyslog_enabled" selected="false" severity="medium">
            <xccdf-1.2:title>Enable rsyslog Service</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>rsyslog</html:code> service provides syslog-style logging by default on AlmaLinux OS 8.

The <html:code>rsyslog</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable rsyslog.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(ii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-4(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010561</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230298r1017108_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The <html:code>rsyslog</html:code> service must be running in order to provide
logging services, which are essential to system administration.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rsyslog_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'rsyslog.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'rsyslog.service'
fi
"$SYSTEMCTL_EXEC" enable 'rsyslog.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rsyslog_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010561
  - NIST-800-53-AU-4(1)
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_rsyslog_enabled

- name: Enable rsyslog Service - Enable service rsyslog
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable rsyslog Service - Enable Service rsyslog
    ansible.builtin.systemd:
      name: rsyslog
      enabled: true
      state: started
      masked: false
    when:
    - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010561
  - NIST-800-53-AU-4(1)
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_rsyslog_enabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rsyslog_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_rsyslog

class enable_rsyslog {
  service {'rsyslog':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_rsyslog_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["rsyslog"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rsyslog_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable rsyslog
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_rsyslog_enabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_rsyslog_enabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_disable_logwatch_for_logserver" selected="false" severity="unknown">
            <xccdf-1.2:title>Disable Logwatch on Clients if a Logserver Exists</xccdf-1.2:title>
            <xccdf-1.2:description>Does your site have a central logserver which has been configured to report
on logs received from all systems? If so:
<html:pre>$ sudo rm /etc/cron.daily/0logwatch</html:pre>
If no logserver exists, it will be necessary for each system to run
Logwatch individually. Using a central logserver provides the security and
reliability benefits discussed earlier, and also makes monitoring logs
easier and less time-intensive for administrators.</xccdf-1.2:description>
            <xccdf-1.2:rationale/>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rsyslog_filecreatemode" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure rsyslog Default File Permissions Configured</xccdf-1.2:title>
            <xccdf-1.2:description>rsyslog will create logfiles that do not already exist on the system.
This settings controls what permissions will be applied to these newly
created files.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.2.2.4</xccdf-1.2:reference>
            <xccdf-1.2:rationale>It is important to ensure that log files have the correct permissions
to ensure that sensitive data is archived and protected.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="rsyslog_filecreatemode" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

sed -i '/^\s*$FileCreateMode/d' /etc/rsyslog.d/*

if ! grep -qE '^\s*\$FileCreateMode\s+0640' /etc/rsyslog.conf; then
    if grep -qE '^\s*\$FileCreateMode' /etc/rsyslog.conf; then
        sed -i '/^\s*\$FileCreateMode/ s/^/#/' /etc/rsyslog.conf
    fi
    ## Assume there is no filter named as 00-, otherwise those filters might be included before this configuration and create file with different permissions
    echo '$FileCreateMode 0640' &gt; /etc/rsyslog.d/00-rsyslog_filecreatemode.conf
fi

systemctl restart rsyslog.service

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="rsyslog_filecreatemode" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_filecreatemode

- name: Ensure rsyslog Default File Permissions Configured - Search for $FileCreateMode
    Parameter in rsyslog Main Config File
  ansible.builtin.find:
    paths: /etc
    pattern: rsyslog.conf
    contains: ^\s*\$FileCreateMode\s*\d+
  register: rsyslog_main_file_with_filecreatemode
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_filecreatemode

- name: Ensure rsyslog Default File Permissions Configured - Search for $FileCreateMode
    Parameter in rsyslog Include Files
  ansible.builtin.find:
    paths: /etc/rsyslog.d/
    pattern: '*.conf'
    contains: ^\s*\$FileCreateMode\s*\d+
  register: rsyslog_includes_with_filecreatemode
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_filecreatemode

- name: Ensure rsyslog Default File Permissions Configured - Assemble List of rsyslog
    Configuration Files with $FileCreateMode Parameter
  ansible.builtin.set_fact:
    rsyslog_filecreatemode_files: '{{ rsyslog_main_file_with_filecreatemode.files
      | map(attribute=''path'') | list + rsyslog_includes_with_filecreatemode.files
      | map(attribute=''path'') | list }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_filecreatemode

- name: Ensure rsyslog Default File Permissions Configured - Remove $FileCreateMode
    Parameter from Multiple Files to Avoid Conflicts
  ansible.builtin.lineinfile:
    path: '{{ item }}'
    regexp: \$FileCreateMode.*
    state: absent
  register: result_rsyslog_filecreatemode_removed
  loop: '{{ rsyslog_filecreatemode_files }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - rsyslog_filecreatemode_files | length &gt; 1
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_filecreatemode

- name: Ensure rsyslog Default File Permissions Configured - Add $FileCreateMode Parameter
    and Expected Value
  ansible.builtin.lineinfile:
    path: /etc/rsyslog.d/00-rsyslog_filecreatemode.conf
    line: $FileCreateMode 0640
    mode: 416
    create: true
  when:
  - '"kernel" in ansible_facts.packages'
  - rsyslog_filecreatemode_files | length == 0 or result_rsyslog_filecreatemode_removed
    is not skipped
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_filecreatemode

- name: Ensure rsyslog Default File Permissions Configured - Ensure Correct Value
    of Existing $FileCreateMode Parameter
  ansible.builtin.lineinfile:
    path: '{{ item }}'
    regexp: ^\$FileCreateMode
    line: $FileCreateMode 0640
  loop: '{{ rsyslog_filecreatemode_files }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - rsyslog_filecreatemode_files | length == 1
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_filecreatemode
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rsyslog_filecreatemode:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rsyslog_filecreatemode_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver">
            <xccdf-1.2:title>Configure Logwatch on the Central Log Server</xccdf-1.2:title>
            <xccdf-1.2:description>Is this system the central log server? If so, edit the file <html:code>/etc/logwatch/conf/logwatch.conf</html:code> as shown below.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_logwatch_configured_hostlimit" selected="false" severity="unknown">
              <xccdf-1.2:title>Configure Logwatch HostLimit Line</xccdf-1.2:title>
              <xccdf-1.2:description>On a central logserver, you want Logwatch to summarize all syslog entries,
including those which did not originate on the logserver itself. The
<html:code>HostLimit</html:code> setting tells Logwatch to report on all hosts, not just
the one on which it is running.
<html:pre> HostLimit = no </html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-logwatch_configured_hostlimit:def:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_logwatch_configured_splithosts" selected="false" severity="unknown">
              <xccdf-1.2:title>Configure Logwatch SplitHosts Line</xccdf-1.2:title>
              <xccdf-1.2:description>If <html:code>SplitHosts</html:code> is set, Logwatch will separate entries by hostname.
This makes the report longer but significantly more usable. If it is not
set, then Logwatch will not report which host generated a given log entry,
and that information is almost always necessary
<html:pre> SplitHosts = yes </html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-logwatch_configured_splithosts:def:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_ensure_rsyslog_log_file_configuration">
            <xccdf-1.2:title>Ensure Proper Configuration of Log Files</xccdf-1.2:title>
            <xccdf-1.2:description>The file <html:code>/etc/rsyslog.conf</html:code> controls where log message are written.
These are controlled by lines called <html:i>rules</html:i>, which consist of a
<html:i>selector</html:i> and an <html:i>action</html:i>.
These rules are often customized depending on the role of the system, the
requirements of the environment, and whatever may enable
the administrator to most effectively make use of log data.
The default rules in AlmaLinux OS 8 are:
<html:pre>*.info;mail.none;authpriv.none;cron.none                /var/log/messages
authpriv.*                                              /var/log/secure
mail.*                                                  -/var/log/maillog
cron.*                                                  /var/log/cron
*.emerg                                                 *
uucp,news.crit                                          /var/log/spooler
local7.*                                                /var/log/boot.log</html:pre>
See the man page <html:code>rsyslog.conf(5)</html:code> for more information.
<html:i>Note that the <html:code>rsyslog</html:code> daemon can be configured to use a timestamp format that
some log processing programs may not understand. If this occurs,
edit the file <html:code>/etc/rsyslog.conf</html:code> and add or edit the following line:</html:i>
<html:pre>$ ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat</html:pre></xccdf-1.2:description>
            <xccdf-1.2:platform idref="#package_rsyslog"/>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rsyslog_cron_logging" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure cron Is Logging To Rsyslog</xccdf-1.2:title>
              <xccdf-1.2:description>Cron logging must be implemented to spot intrusions or trace
cron job status. If <html:code>cron</html:code> is not logging to <html:code>rsyslog</html:code>, it
can be implemented by adding the following to the <html:i>RULES</html:i> section of
<html:code>/etc/rsyslog.conf</html:code>:
If the legacy syntax is used:
<html:pre>cron.*                                                  /var/log/cron</html:pre>
If the modern syntax (RainerScript) is used:
<html:pre>cron.* action(type="omfile" file="/var/log/cron")</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0988</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1405</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030010</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230387r1017195_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Cron logging can be used to trace the successful or unsuccessful execution
of cron jobs. It can also be used to spot intrusions into the use of the cron
facility by unauthorized and malicious users.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="rsyslog_cron_logging" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; rpm --quiet -q rsyslog; then

RSYSLOG_CONF='/etc/rsyslog.conf'
RSYSLOG_D_FOLDER='/etc/rsyslog.d'
RSYSLOG_D_CONF='/etc/rsyslog.d/encrypt.conf'
test -f $RSYSLOG_CONF || touch $RSYSLOG_CONF
mkdir -p $RSYSLOG_D_FOLDER
# remove all multilined cron.* entries
sed -i '/^[[:space:]]*cron\.\*.*action(/,/)/d' $RSYSLOG_CONF
find $RSYSLOG_D_FOLDER -type f -name "*.conf" -exec sed -i '/^[[:space:]]*cron\.\*.*action(/,/)/d' {} +
# remove all legacy format and one line cron.* entries
sed -i '/^\s*\*\.\*\s+/var/log/cron\s*$/d' $RSYSLOG_CONF
find $RSYSLOG_D_FOLDER -type f -name "*.conf" -exec sed -i '/^\s*\*\.\*\s+/var/log/cron\s*$/d' {} +
sed -i '/^[[:space:]]*cron\.\*/d' $RSYSLOG_CONF
find $RSYSLOG_D_FOLDER -type f -name "*.conf" -exec sed -i '/^[[:space:]]*cron\.\*/d' {} +

echo "cron.*	/var/log/cron" &gt;&gt; $RSYSLOG_D_CONF

if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    systemctl restart rsyslog.service
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="rsyslog_cron_logging" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030010
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_cron_logging

- name: Ensure cron Is Logging To Rsyslog - Ensure /etc/rsyslog.conf exists
  ansible.builtin.file:
    path: /etc/rsyslog.conf
    state: touch
    modification_time: preserve
    access_time: preserve
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030010
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_cron_logging

- name: Ensure cron Is Logging To Rsyslog - Ensure /etc/rsyslog.d directory exists
  ansible.builtin.file:
    path: /etc/rsyslog.d
    state: directory
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030010
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_cron_logging

- name: Ensure cron Is Logging To Rsyslog - Remove multilined cron.* action() entries
    from rsyslog.conf
  ansible.builtin.shell: sed -i '/^[[:space:]]*cron\.\*.*action(/,/)/d' /etc/rsyslog.conf
  changed_when: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030010
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_cron_logging

- name: Ensure cron Is Logging To Rsyslog - Remove multilined cron.* action() entries
    from rsyslog.d/*.conf
  ansible.builtin.shell: find /etc/rsyslog.d -type f -name "*.conf" -exec sed -i '/^[[:space:]]*cron\.\*.*action(/,/)/d'
    {} +
  changed_when: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030010
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_cron_logging

- name: Remove *.* entries pointing to /var/log/cron from rsyslog.conf
  ansible.builtin.lineinfile:
    path: /etc/rsyslog.conf
    create: false
    regexp: (?i)^\s*\*\.\*\s+/var/log/cron\s*$
    state: absent
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030010
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_cron_logging

- name: Ensure cron Is Logging To Rsyslog - Remove *.* entries pointing to /var/log/cron
    from rsyslog.d/*.conf
  ansible.builtin.shell: find /etc/rsyslog.d -type f -name "*.conf" -exec sed -i '\|^\s*\*\.\*\s\+/var/log/cron\s*$|d'
    {} +
  changed_when: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030010
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_cron_logging

- name: Ensure cron Is Logging To Rsyslog - Check if the parameter cron.* is configured
    in /etc/rsyslog.conf
  ansible.builtin.lineinfile:
    path: /etc/rsyslog.conf
    regexp: ^\s*{{ "cron.*"| regex_escape }}
    state: absent
  check_mode: true
  changed_when: false
  register: _config_file_has_parameter
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030010
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_cron_logging

- name: Ensure cron Is Logging To Rsyslog - Check if the parameter cron.* is configured
    in /etc/rsyslog.d
  ansible.builtin.find:
    paths:
    - /etc/rsyslog.d
    contains: ^\s*{{ "cron.*"| regex_escape }}
  register: _config_dir_has_parameter
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030010
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_cron_logging

- name: Ensure cron Is Logging To Rsyslog - Check if the parameter cron.* is configured
    correctly in /etc/rsyslog.conf
  ansible.builtin.lineinfile:
    path: /etc/rsyslog.conf
    regexp: ^\s*{{ "cron.*"| regex_escape }}/var/log/cron$
    state: absent
  check_mode: true
  changed_when: false
  register: _config_file_correctly
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030010
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_cron_logging

- name: Ensure cron Is Logging To Rsyslog - Check if the parameter cron.* is configured
    correctly in /etc/rsyslog.d
  ansible.builtin.find:
    paths:
    - /etc/rsyslog.d
    contains: ^\s*{{ "cron.*"| regex_escape }}/var/log/cron$
  register: _config_dir_correctly
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030010
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_cron_logging

- name: Ensure cron Is Logging To Rsyslog
  block:

  - name: Deduplicate values from /etc/rsyslog.conf
    ansible.builtin.lineinfile:
      path: /etc/rsyslog.conf
      create: false
      regexp: (?i)^\s*{{ "cron.*"| regex_escape }}
      state: absent

  - name: Check if /etc/rsyslog.d exists
    ansible.builtin.stat:
      path: /etc/rsyslog.d
    register: _etc_rsyslog_d_exists

  - name: Check if the parameter cron.* is present in /etc/rsyslog.d
    ansible.builtin.find:
      paths: /etc/rsyslog.d
      recurse: 'yes'
      follow: 'no'
      contains: ^\s*{{ "cron.*"| regex_escape }}
    register: _etc_rsyslog_d_has_parameter
    when: _etc_rsyslog_d_exists.stat.isdir is defined and _etc_rsyslog_d_exists.stat.isdir

  - name: Remove parameter from files in /etc/rsyslog.d
    ansible.builtin.lineinfile:
      path: '{{ item.path }}'
      create: false
      regexp: (?i)^\s*{{ "cron.*"| regex_escape }}
      state: absent
    with_items: '{{ _etc_rsyslog_d_has_parameter.files | default([]) }}'
    when: _etc_rsyslog_d_has_parameter.matched &gt; 0

  - name: Insert correct line to /etc/rsyslog.d/cron.conf
    ansible.builtin.lineinfile:
      path: /etc/rsyslog.d/cron.conf
      create: true
      regexp: (?i)^\s*{{ "cron.*"| regex_escape }}
      line: cron.* /var/log/cron
      state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - (_config_file_correctly.found == 0 and _config_dir_correctly.matched == 0) or
    ((_config_file_has_parameter.found | int) + (_config_dir_has_parameter.matched
    | int)) != 1
  tags:
  - DISA-STIG-RHEL-08-030010
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_cron_logging

- name: Ensure cron Is Logging To Rsyslog - Restart the rsyslog service now
  ansible.builtin.service:
    name: rsyslog
    state: restarted
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030010
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_cron_logging
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rsyslog_cron_logging:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rsyslog_cron_logging_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rsyslog_encrypt_offload_actionsendstreamdriverauthmode" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Rsyslog Authenticates Off-Loaded Audit Records</xccdf-1.2:title>
              <xccdf-1.2:description>Rsyslogd is a system utility providing support for message logging. Support
for both internet and UNIX domain sockets enables this utility to support both local
and remote logging.  Couple this utility with <html:code>gnutls</html:code> (which is a secure communications
library implementing the SSL, TLS and DTLS protocols), and you have a method to securely
encrypt and off-load auditing.

When using <html:code>rsyslogd</html:code> to off-load logs the remote system must be authenticated.

Set the following configuration option in /etc/rsyslog.conf or in a file in /etc/rsyslog.d (using legacy syntax):
<html:pre>$ActionSendStreamDriverAuthMode x509/name</html:pre>
Alternatively, use the RainerScript syntax:
<html:pre>action(type="omfwd" Target="some.example.com" StreamDriverAuthMode="x509/name")</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-4(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000342-GPOS-00133</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000479-GPOS-00224</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030720</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230482r1069330_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The audit records generated by Rsyslog contain valuable information regarding system
configuration, user authentication, and other such information. Audit records should be
protected from unauthorized access.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="rsyslog_encrypt_offload_actionsendstreamdriverauthmode" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; rpm --quiet -q rsyslog; then

RSYSLOG_CONF='/etc/rsyslog.conf'
RSYSLOG_D_FOLDER='/etc/rsyslog.d'
RSYSLOG_D_CONF='/etc/rsyslog.d/encrypt.conf'
test -f $RSYSLOG_CONF || touch $RSYSLOG_CONF
mkdir -p $RSYSLOG_D_FOLDER
# remove legacy entries
sed -i '/^[[:space:]]*\$ActionSendStreamDriverAuthMode/d' $RSYSLOG_CONF
find $RSYSLOG_D_FOLDER -type f -name "*.conf" -exec sed -i '/^[[:space:]]*\$ActionSendStreamDriverAuthMode/d' {} +
# remove all multilined and onelined RainerScript entries
sed -i '/^[[:space:]]*action(/ { :a; N; /)/!ba; /StreamDriverAuthMode/d }' $RSYSLOG_CONF
find $RSYSLOG_D_FOLDER -type f -name "*.conf" -exec sed -i '/^[[:space:]]*action(/ { :a; N; /)/!ba; /StreamDriverAuthMode/d }' {} +

if [ -e "$RSYSLOG_D_CONF" ] ; then
    
    LC_ALL=C sed -i "/^\s*\$ActionSendStreamDriverAuthMode\s\+/Id" "$RSYSLOG_D_CONF"
else
    touch "$RSYSLOG_D_CONF"
fi
# make sure file has newline at the end
sed -i -e '$a\' "$RSYSLOG_D_CONF"

cp "$RSYSLOG_D_CONF" "$RSYSLOG_D_CONF.bak"
# Insert at the end of the file
printf '%s\n' "\$ActionSendStreamDriverAuthMode x509/name" &gt;&gt; "$RSYSLOG_D_CONF"
# Clean up after ourselves.
rm "$RSYSLOG_D_CONF.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="rsyslog_encrypt_offload_actionsendstreamdriverauthmode" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030720
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdriverauthmode

- name: Ensure Rsyslog Authenticates Off-Loaded Audit Records - Ensure /etc/rsyslog.conf
    exists
  ansible.builtin.file:
    path: /etc/rsyslog.conf
    state: touch
    modification_time: preserve
    access_time: preserve
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030720
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdriverauthmode

- name: Ensure Rsyslog Authenticates Off-Loaded Audit Records - Ensure /etc/rsyslog.d
    directory exists
  ansible.builtin.file:
    path: /etc/rsyslog.d
    state: directory
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030720
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdriverauthmode

- name: Ensure Rsyslog Authenticates Off-Loaded Audit Records - Remove RainerScript
    action() entries with StreamDriverAuthMode from rsyslog.conf
  ansible.builtin.shell: |
    sed -i '/^[[:space:]]*action(/ { :a; N; /)/!ba; /StreamDriverAuthMode/d }' /etc/rsyslog.conf
  changed_when: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030720
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdriverauthmode

- name: Ensure Rsyslog Authenticates Off-Loaded Audit Records - Remove RainerScript
    action() entries with StreamDriverAuthMode from rsyslog.d/*.conf
  ansible.builtin.shell: |
    find /etc/rsyslog.d -type f -name "*.conf" -exec sed -i '/^[[:space:]]*action(/ { :a; N; /)/!ba; /StreamDriverAuthMode/d }' {} +
  changed_when: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030720
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdriverauthmode

- name: Ensure Rsyslog Authenticates Off-Loaded Audit Records - Check if the parameter
    $ActionSendStreamDriverAuthMode is configured in /etc/rsyslog.conf
  ansible.builtin.lineinfile:
    path: /etc/rsyslog.conf
    regexp: ^\s*{{ "$ActionSendStreamDriverAuthMode"| regex_escape }}\s+
    state: absent
  check_mode: true
  changed_when: false
  register: _config_file_has_parameter
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030720
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdriverauthmode

- name: Ensure Rsyslog Authenticates Off-Loaded Audit Records - Check if the parameter
    $ActionSendStreamDriverAuthMode is configured in /etc/rsyslog.d
  ansible.builtin.find:
    paths:
    - /etc/rsyslog.d
    contains: ^\s*{{ "$ActionSendStreamDriverAuthMode"| regex_escape }}\s+
  register: _config_dir_has_parameter
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030720
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdriverauthmode

- name: Ensure Rsyslog Authenticates Off-Loaded Audit Records - Check if the parameter
    $ActionSendStreamDriverAuthMode is configured correctly in /etc/rsyslog.conf
  ansible.builtin.lineinfile:
    path: /etc/rsyslog.conf
    regexp: ^\s*{{ "$ActionSendStreamDriverAuthMode"| regex_escape }}\s+x509/name$
    state: absent
  check_mode: true
  changed_when: false
  register: _config_file_correctly
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030720
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdriverauthmode

- name: Ensure Rsyslog Authenticates Off-Loaded Audit Records - Check if the parameter
    $ActionSendStreamDriverAuthMode is configured correctly in /etc/rsyslog.d
  ansible.builtin.find:
    paths:
    - /etc/rsyslog.d
    contains: ^\s*{{ "$ActionSendStreamDriverAuthMode"| regex_escape }}\s+x509/name$
  register: _config_dir_correctly
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030720
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdriverauthmode

- name: Ensure Rsyslog Authenticates Off-Loaded Audit Records
  block:

  - name: Deduplicate values from /etc/rsyslog.conf
    ansible.builtin.lineinfile:
      path: /etc/rsyslog.conf
      create: false
      regexp: (?i)^\s*{{ "$ActionSendStreamDriverAuthMode"| regex_escape }}\s+
      state: absent

  - name: Check if /etc/rsyslog.d exists
    ansible.builtin.stat:
      path: /etc/rsyslog.d
    register: _etc_rsyslog_d_exists

  - name: Check if the parameter $ActionSendStreamDriverAuthMode is present in /etc/rsyslog.d
    ansible.builtin.find:
      paths: /etc/rsyslog.d
      recurse: 'yes'
      follow: 'no'
      contains: ^\s*{{ "$ActionSendStreamDriverAuthMode"| regex_escape }}\s+
    register: _etc_rsyslog_d_has_parameter
    when: _etc_rsyslog_d_exists.stat.isdir is defined and _etc_rsyslog_d_exists.stat.isdir

  - name: Remove parameter from files in /etc/rsyslog.d
    ansible.builtin.lineinfile:
      path: '{{ item.path }}'
      create: false
      regexp: (?i)^\s*{{ "$ActionSendStreamDriverAuthMode"| regex_escape }}\s+
      state: absent
    with_items: '{{ _etc_rsyslog_d_has_parameter.files | default([]) }}'
    when: _etc_rsyslog_d_has_parameter.matched &gt; 0

  - name: Insert correct line to /etc/rsyslog.conf
    ansible.builtin.lineinfile:
      path: /etc/rsyslog.conf
      create: true
      regexp: (?i)^\s*{{ "$ActionSendStreamDriverAuthMode"| regex_escape }}\s+
      line: $ActionSendStreamDriverAuthMode x509/name
      state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - (_config_file_correctly.found == 0 and _config_dir_correctly.matched == 0) or
    ((_config_file_has_parameter.found | int) + (_config_dir_has_parameter.matched
    | int)) != 1
  tags:
  - DISA-STIG-RHEL-08-030720
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdriverauthmode
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rsyslog_encrypt_offload_actionsendstreamdrivermode" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Rsyslog Encrypts Off-Loaded Audit Records</xccdf-1.2:title>
              <xccdf-1.2:description>Rsyslogd is a system utility providing support for message logging. Support
for both internet and UNIX domain sockets enables this utility to support both local
and remote logging.  Couple this utility with <html:code>gnutls</html:code> (which is a secure communications
library implementing the SSL, TLS and DTLS protocols), and you have a method to securely
encrypt and off-load auditing.

When using <html:code>rsyslogd</html:code> to off-load logs off a encryption system must be used.

Set the following configuration option in /etc/rsyslog.conf or in a file in /etc/rsyslog.d (using legacy syntax):
<html:pre>$ActionSendStreamDriverMode 1</html:pre>

Alternatively, use the RainerScript syntax:
<html:pre>action(type="omfwd" ... StreamDriverMode="1")</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-4(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000342-GPOS-00133</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000479-GPOS-00224</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030710</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230481r958754_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The audit records generated by Rsyslog contain valuable information regarding system
configuration, user authentication, and other such information. Audit records should be
protected from unauthorized access.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="rsyslog_encrypt_offload_actionsendstreamdrivermode" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; rpm --quiet -q rsyslog; then

RSYSLOG_CONF='/etc/rsyslog.conf'
RSYSLOG_D_FOLDER='/etc/rsyslog.d'
RSYSLOG_D_CONF='/etc/rsyslog.d/encrypt.conf'
test -f $RSYSLOG_CONF || touch $RSYSLOG_CONF
mkdir -p $RSYSLOG_D_FOLDER
# remove ActionSendStreamDriverMode entries
sed -i '/^[[:space:]]*\$ActionSendStreamDriverMode/d' $RSYSLOG_CONF
find $RSYSLOG_D_FOLDER -type f -name "*.conf" -exec sed -i '/^[[:space:]]*\$ActionSendStreamDriverMode/d' {} +
# remove all multilined and onelined RainerScript entries
sed -i '/^[[:space:]]*action(/ { :a; N; /)/!ba; /StreamDriverMode/d }' $RSYSLOG_CONF
find $RSYSLOG_D_FOLDER -type f -name "*.conf" -exec sed -i '/^[[:space:]]*action(/ { :a; N; /)/!ba; /StreamDriverMode/d }' {} +

if [ -e "$RSYSLOG_D_CONF" ] ; then
    
    LC_ALL=C sed -i "/^\s*\$ActionSendStreamDriverMode\s\+/Id" "$RSYSLOG_D_CONF"
else
    touch "$RSYSLOG_D_CONF"
fi
# make sure file has newline at the end
sed -i -e '$a\' "$RSYSLOG_D_CONF"

cp "$RSYSLOG_D_CONF" "$RSYSLOG_D_CONF.bak"
# Insert at the end of the file
printf '%s\n' "\$ActionSendStreamDriverMode 1" &gt;&gt; "$RSYSLOG_D_CONF"
# Clean up after ourselves.
rm "$RSYSLOG_D_CONF.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="rsyslog_encrypt_offload_actionsendstreamdrivermode" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdrivermode

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records - Ensure /etc/rsyslog.conf
    exists
  ansible.builtin.file:
    path: /etc/rsyslog.conf
    state: touch
    modification_time: preserve
    access_time: preserve
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdrivermode

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records - Ensure /etc/rsyslog.d directory
    exists
  ansible.builtin.file:
    path: /etc/rsyslog.d
    state: directory
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdrivermode

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records - Remove RainerScript action()
    entries with StreamDriverMode from rsyslog.conf
  ansible.builtin.shell: |
    sed -i '/^[[:space:]]*action(/ { :a; N; /)/!ba; /StreamDriverMode/d }' /etc/rsyslog.conf
  changed_when: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdrivermode

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records - Remove RainerScript action()
    entries with StreamDriverMode from rsyslog.d/*.conf
  ansible.builtin.shell: |
    find /etc/rsyslog.d -type f -name "*.conf" -exec sed -i '/^[[:space:]]*action(/ { :a; N; /)/!ba; /StreamDriverMode/d }' {} +
  changed_when: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdrivermode

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records - Check if the parameter
    $ActionSendStreamDriverMode is configured in /etc/rsyslog.conf
  ansible.builtin.lineinfile:
    path: /etc/rsyslog.conf
    regexp: ^\s*{{ "$ActionSendStreamDriverMode"| regex_escape }}\s+
    state: absent
  check_mode: true
  changed_when: false
  register: _config_file_has_parameter
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdrivermode

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records - Check if the parameter
    $ActionSendStreamDriverMode is configured in /etc/rsyslog.d
  ansible.builtin.find:
    paths:
    - /etc/rsyslog.d
    contains: ^\s*{{ "$ActionSendStreamDriverMode"| regex_escape }}\s+
  register: _config_dir_has_parameter
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdrivermode

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records - Check if the parameter
    $ActionSendStreamDriverMode is configured correctly in /etc/rsyslog.conf
  ansible.builtin.lineinfile:
    path: /etc/rsyslog.conf
    regexp: ^\s*{{ "$ActionSendStreamDriverMode"| regex_escape }}\s+1$
    state: absent
  check_mode: true
  changed_when: false
  register: _config_file_correctly
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdrivermode

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records - Check if the parameter
    $ActionSendStreamDriverMode is configured correctly in /etc/rsyslog.d
  ansible.builtin.find:
    paths:
    - /etc/rsyslog.d
    contains: ^\s*{{ "$ActionSendStreamDriverMode"| regex_escape }}\s+1$
  register: _config_dir_correctly
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdrivermode

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records
  block:

  - name: Deduplicate values from /etc/rsyslog.conf
    ansible.builtin.lineinfile:
      path: /etc/rsyslog.conf
      create: false
      regexp: (?i)^\s*{{ "$ActionSendStreamDriverMode"| regex_escape }}\s+
      state: absent

  - name: Check if /etc/rsyslog.d exists
    ansible.builtin.stat:
      path: /etc/rsyslog.d
    register: _etc_rsyslog_d_exists

  - name: Check if the parameter $ActionSendStreamDriverMode is present in /etc/rsyslog.d
    ansible.builtin.find:
      paths: /etc/rsyslog.d
      recurse: 'yes'
      follow: 'no'
      contains: ^\s*{{ "$ActionSendStreamDriverMode"| regex_escape }}\s+
    register: _etc_rsyslog_d_has_parameter
    when: _etc_rsyslog_d_exists.stat.isdir is defined and _etc_rsyslog_d_exists.stat.isdir

  - name: Remove parameter from files in /etc/rsyslog.d
    ansible.builtin.lineinfile:
      path: '{{ item.path }}'
      create: false
      regexp: (?i)^\s*{{ "$ActionSendStreamDriverMode"| regex_escape }}\s+
      state: absent
    with_items: '{{ _etc_rsyslog_d_has_parameter.files | default([]) }}'
    when: _etc_rsyslog_d_has_parameter.matched &gt; 0

  - name: Insert correct line to /etc/rsyslog.conf
    ansible.builtin.lineinfile:
      path: /etc/rsyslog.conf
      create: true
      regexp: (?i)^\s*{{ "$ActionSendStreamDriverMode"| regex_escape }}\s+
      line: $ActionSendStreamDriverMode 1
      state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - (_config_file_correctly.found == 0 and _config_dir_correctly.matched == 0) or
    ((_config_file_has_parameter.found | int) + (_config_dir_has_parameter.matched
    | int)) != 1
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_actionsendstreamdrivermode
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rsyslog_encrypt_offload_defaultnetstreamdriver" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Rsyslog Encrypts Off-Loaded Audit Records</xccdf-1.2:title>
              <xccdf-1.2:description>Rsyslogd is a system utility providing support for message logging. Support
for both internet and UNIX domain sockets enables this utility to support both local
and remote logging.  Couple this utility with <html:code>gnutls</html:code> (which is a secure communications
library implementing the SSL, TLS and DTLS protocols), and you have a method to securely
encrypt and off-load auditing.

When using <html:code>rsyslogd</html:code> to off-load logs off an encryption system must be used.

Set the following configuration option in /etc/rsyslog.conf or in a file in /etc/rsyslog.d (using legacy syntax):
<html:pre>$DefaultNetstreamDriver gtls</html:pre>

Alternatively, use the RainerScript syntax:
<html:pre>global(DefaultNetstreamDriver="gtls")</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-4(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000342-GPOS-00133</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000479-GPOS-00224</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030710</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230481r958754_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The audit records generated by Rsyslog contain valuable information regarding system
configuration, user authentication, and other such information. Audit records should be
protected from unauthorized access.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="rsyslog_encrypt_offload_defaultnetstreamdriver" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; rpm --quiet -q rsyslog; then

RSYSLOG_CONF='/etc/rsyslog.conf'
RSYSLOG_D_FOLDER='/etc/rsyslog.d'
RSYSLOG_D_CONF='/etc/rsyslog.d/encrypt.conf'
test -f $RSYSLOG_CONF || touch $RSYSLOG_CONF
mkdir -p $RSYSLOG_D_FOLDER
# remove DefaultNetstreamDriver entries
sed -i '/^[[:space:]]*\$DefaultNetstreamDriver/d' $RSYSLOG_CONF
find $RSYSLOG_D_FOLDER -type f -name "*.conf" -exec sed -i '/^[[:space:]]*\$DefaultNetstreamDriver/d' {} +
# remove all multilined and onelined RainerScript entries
sed -i '/^[[:space:]]*global(/ { :a; N; /)/!ba; /DefaultNetstreamDriver/d }' $RSYSLOG_CONF
find $RSYSLOG_D_FOLDER -type f -name "*.conf" -exec sed -i '/^[[:space:]]*global(/ { :a; N; /)/!ba; /DefaultNetstreamDriver/d }' {} +

if [ -e "$RSYSLOG_D_CONF" ] ; then
    
    LC_ALL=C sed -i "/^\s*\$DefaultNetstreamDriver\s\+/Id" "$RSYSLOG_D_CONF"
else
    touch "$RSYSLOG_D_CONF"
fi
# make sure file has newline at the end
sed -i -e '$a\' "$RSYSLOG_D_CONF"

cp "$RSYSLOG_D_CONF" "$RSYSLOG_D_CONF.bak"
# Insert at the end of the file
printf '%s\n' "\$DefaultNetstreamDriver gtls" &gt;&gt; "$RSYSLOG_D_CONF"
# Clean up after ourselves.
rm "$RSYSLOG_D_CONF.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="rsyslog_encrypt_offload_defaultnetstreamdriver" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_defaultnetstreamdriver

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records - Ensure /etc/rsyslog.conf
    exists
  ansible.builtin.file:
    path: /etc/rsyslog.conf
    state: touch
    modification_time: preserve
    access_time: preserve
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_defaultnetstreamdriver

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records - Ensure /etc/rsyslog.d directory
    exists
  ansible.builtin.file:
    path: /etc/rsyslog.d
    state: directory
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_defaultnetstreamdriver

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records - Remove RainerScript global()
    entries with DefaultNetstreamDriver from rsyslog.conf
  ansible.builtin.shell: |
    sed -i '/^[[:space:]]*global(/ { :a; N; /)/!ba; /DefaultNetstreamDriver/d }' /etc/rsyslog.conf
  changed_when: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_defaultnetstreamdriver

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records - Remove RainerScript global()
    entries with DefaultNetstreamDriver from rsyslog.d/*.conf
  ansible.builtin.shell: |
    find /etc/rsyslog.d -type f -name "*.conf" -exec sed -i '/^[[:space:]]*global(/ { :a; N; /)/!ba; /DefaultNetstreamDriver/d }' {} +
  changed_when: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_defaultnetstreamdriver

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records - Check if the parameter
    $DefaultNetstreamDriver is configured in /etc/rsyslog.conf
  ansible.builtin.lineinfile:
    path: /etc/rsyslog.conf
    regexp: ^\s*{{ "$DefaultNetstreamDriver"| regex_escape }}\s+
    state: absent
  check_mode: true
  changed_when: false
  register: _config_file_has_parameter
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_defaultnetstreamdriver

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records - Check if the parameter
    $DefaultNetstreamDriver is configured in /etc/rsyslog.d
  ansible.builtin.find:
    paths:
    - /etc/rsyslog.d
    contains: ^\s*{{ "$DefaultNetstreamDriver"| regex_escape }}\s+
  register: _config_dir_has_parameter
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_defaultnetstreamdriver

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records - Check if the parameter
    $DefaultNetstreamDriver is configured correctly in /etc/rsyslog.conf
  ansible.builtin.lineinfile:
    path: /etc/rsyslog.conf
    regexp: ^\s*{{ "$DefaultNetstreamDriver"| regex_escape }}\s+gtls$
    state: absent
  check_mode: true
  changed_when: false
  register: _config_file_correctly
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_defaultnetstreamdriver

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records - Check if the parameter
    $DefaultNetstreamDriver is configured correctly in /etc/rsyslog.d
  ansible.builtin.find:
    paths:
    - /etc/rsyslog.d
    contains: ^\s*{{ "$DefaultNetstreamDriver"| regex_escape }}\s+gtls$
  register: _config_dir_correctly
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_defaultnetstreamdriver

- name: Ensure Rsyslog Encrypts Off-Loaded Audit Records
  block:

  - name: Deduplicate values from /etc/rsyslog.conf
    ansible.builtin.lineinfile:
      path: /etc/rsyslog.conf
      create: false
      regexp: (?i)^\s*{{ "$DefaultNetstreamDriver"| regex_escape }}\s+
      state: absent

  - name: Check if /etc/rsyslog.d exists
    ansible.builtin.stat:
      path: /etc/rsyslog.d
    register: _etc_rsyslog_d_exists

  - name: Check if the parameter $DefaultNetstreamDriver is present in /etc/rsyslog.d
    ansible.builtin.find:
      paths: /etc/rsyslog.d
      recurse: 'yes'
      follow: 'no'
      contains: ^\s*{{ "$DefaultNetstreamDriver"| regex_escape }}\s+
    register: _etc_rsyslog_d_has_parameter
    when: _etc_rsyslog_d_exists.stat.isdir is defined and _etc_rsyslog_d_exists.stat.isdir

  - name: Remove parameter from files in /etc/rsyslog.d
    ansible.builtin.lineinfile:
      path: '{{ item.path }}'
      create: false
      regexp: (?i)^\s*{{ "$DefaultNetstreamDriver"| regex_escape }}\s+
      state: absent
    with_items: '{{ _etc_rsyslog_d_has_parameter.files | default([]) }}'
    when: _etc_rsyslog_d_has_parameter.matched &gt; 0

  - name: Insert correct line to /etc/rsyslog.conf
    ansible.builtin.lineinfile:
      path: /etc/rsyslog.conf
      create: true
      regexp: (?i)^\s*{{ "$DefaultNetstreamDriver"| regex_escape }}\s+
      line: $DefaultNetstreamDriver gtls
      state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - (_config_file_correctly.found == 0 and _config_dir_correctly.matched == 0) or
    ((_config_file_has_parameter.found | int) + (_config_dir_has_parameter.matched
    | int)) != 1
  tags:
  - DISA-STIG-RHEL-08-030710
  - NIST-800-53-AU-4(1)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_encrypt_offload_defaultnetstreamdriver
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rsyslog_files_groupownership" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Log Files Are Owned By Appropriate Group</xccdf-1.2:title>
              <xccdf-1.2:description>The group-owner of all log files written by
<html:code>rsyslog</html:code> should be <html:code>root</html:code>.
These log files are determined by the second part of each Rule line in
<html:code>/etc/rsyslog.conf</html:code> and typically all appear in <html:code>/var/log</html:code>.
For each log file <html:i>LOGFILE</html:i> referenced in <html:code>/etc/rsyslog.conf</html:code>,
run the following command to inspect the file's group owner:
<html:pre>$ ls -l <html:i>LOGFILE</html:i></html:pre>
If the owner is not <html:code>root</html:code>,
run the following command to
correct this:
<html:pre>$ sudo chgrp root <html:i>LOGFILE</html:i></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R71</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0988</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1405</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.2.3.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The log files generated by rsyslog contain valuable information regarding system
configuration, user authentication, and other such information. Log files should be
protected from unauthorized access.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="rsyslog_files_groupownership" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; rpm --quiet -q rsyslog; then

# List of log file paths to be inspected for correct permissions
# * Primarily inspect log file paths listed in /etc/rsyslog.conf
RSYSLOG_ETC_CONFIG="/etc/rsyslog.conf"
# * And also the log file paths listed after rsyslog's $IncludeConfig directive
#   (store the result into array for the case there's shell glob used as value of IncludeConfig)
readarray -t OLD_INC &lt; &lt;(grep -e "\$IncludeConfig[[:space:]]\+[^[:space:];]\+" /etc/rsyslog.conf | cut -d ' ' -f 2)
readarray -t RSYSLOG_INCLUDE_CONFIG &lt; &lt;(for INCPATH in "${OLD_INC[@]}"; do eval printf '%s\\n' "${INCPATH}"; done)
readarray -t NEW_INC &lt; &lt;(sed -n '/^\s*include(/,/)/Ip' /etc/rsyslog.conf | sed -n 's@.*file\s*=\s*"\([/[:alnum:][:punct:]]*\)".*@\1@Ip')
readarray -t RSYSLOG_INCLUDE &lt; &lt;(for INCPATH in "${NEW_INC[@]}"; do eval printf '%s\\n' "${INCPATH}"; done)

# Declare an array to hold the final list of different log file paths
declare -a LOG_FILE_PATHS

# Array to hold all rsyslog config entries
RSYSLOG_CONFIGS=()
RSYSLOG_CONFIGS=("${RSYSLOG_ETC_CONFIG}" "${RSYSLOG_INCLUDE_CONFIG[@]}" "${RSYSLOG_INCLUDE[@]}")

# Get full list of files to be checked
# RSYSLOG_CONFIGS may contain globs such as
# /etc/rsyslog.d/*.conf /etc/rsyslog.d/*.frule
# So, loop over the entries in RSYSLOG_CONFIGS and use find to get the list of included files.
RSYSLOG_CONFIG_FILES=()
for ENTRY in "${RSYSLOG_CONFIGS[@]}"
do
	# If directory, rsyslog will search for config files in recursively.
	# However, files in hidden sub-directories or hidden files will be ignored.
	if [ -d "${ENTRY}" ]
	then
		readarray -t FINDOUT &lt; &lt;(find "${ENTRY}" -not -path '*/.*' -type f)
		RSYSLOG_CONFIG_FILES+=("${FINDOUT[@]}")
	elif [ -f "${ENTRY}" ]
	then
		RSYSLOG_CONFIG_FILES+=("${ENTRY}")
	else
		echo "Invalid include object: ${ENTRY}"
	fi
done

# Browse each file selected above as containing paths of log files
# ('/etc/rsyslog.conf' and '/etc/rsyslog.d/*.conf' in the default configuration)
for LOG_FILE in "${RSYSLOG_CONFIG_FILES[@]}"
do
	# From each of these files extract just particular log file path(s), thus:
	# * Ignore lines starting with space (' '), comment ('#"), or variable syntax ('$') characters,
	# * Ignore empty lines,
	# * Strip quotes and closing brackets from paths.
	# * Ignore paths that match /dev|/etc.*\.conf, as those are paths, but likely not log files
	# * From the remaining valid rows select only fields constituting a log file path
	# Text file column is understood to represent a log file path if and only if all of the
	# following are met:
	# * it contains at least one slash '/' character,
	# * it is preceded by space
	# * it doesn't contain space (' '), colon (':'), and semicolon (';') characters
	# Search log file for path(s) only in case it exists!
	if [[ -f "${LOG_FILE}" ]]
	then
		NORMALIZED_CONFIG_FILE_LINES=$(sed -e "/^[#|$]/d" "${LOG_FILE}")
		LINES_WITH_PATHS=$(grep '[^/]*\s\+\S*/\S\+$' &lt;&lt;&lt; "${NORMALIZED_CONFIG_FILE_LINES}")
		FILTERED_PATHS=$(awk '{if(NF&gt;=2&amp;&amp;($NF~/^\//||$NF~/^-\//)){sub(/^-\//,"/",$NF);print $NF}}' &lt;&lt;&lt; "${LINES_WITH_PATHS}")
		CLEANED_PATHS=$(sed -e "s/[\"')]//g; /\\/etc.*\.conf/d; /\\/dev\\//d" &lt;&lt;&lt; "${FILTERED_PATHS}")
		MATCHED_ITEMS=$(sed -e "/^$/d" &lt;&lt;&lt; "${CLEANED_PATHS}")
		# Since above sed command might return more than one item (delimited by newline), split
		# the particular matches entries into new array specific for this log file
		readarray -t ARRAY_FOR_LOG_FILE &lt;&lt;&lt; "$MATCHED_ITEMS"
		# Concatenate the two arrays - previous content of $LOG_FILE_PATHS array with
		# items from newly created array for this log file
		LOG_FILE_PATHS+=("${ARRAY_FOR_LOG_FILE[@]}")
		# Delete the temporary array
		unset ARRAY_FOR_LOG_FILE
	fi
done

# Check for RainerScript action log format which might be also multiline so grep regex is a bit
# curly:
# extract possibly multiline action omfile expressions
# extract File="logfile" expression
# match only "logfile" expression
# exclude /dev/* paths (e.g., /dev/console)
for LOG_FILE in "${RSYSLOG_CONFIG_FILES[@]}"
do
	ACTION_OMFILE_LINES=$(grep -iozP "action\s*\(\s*type\s*=\s*\"omfile\"[^\)]*\)" "${LOG_FILE}")
	OMFILE_LINES=$(echo "${ACTION_OMFILE_LINES}"| grep -iaoP "\bFile\s*=\s*\"([/[:alnum:][:punct:]]*)\"\s*\)")
	LOG_FILE_PATHS+=("$(echo "${OMFILE_LINES}"| grep -oE "\"([/[:alnum:][:punct:]]*)\""|tr -d "\"" | grep -v "^/dev/")")
done

# Ensure the correct attribute if file exists
FILE_CMD="chgrp"
for LOG_FILE_PATH in "${LOG_FILE_PATHS[@]}"
do
	# Sanity check - if particular $LOG_FILE_PATH is empty string, skip it from further processing
	if [ -z "$LOG_FILE_PATH" ]
	then
		continue
	fi
	$FILE_CMD "root" "$LOG_FILE_PATH"
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="rsyslog_files_groupownership" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_groupownership

- name: Ensure Log Files Are Owned By Appropriate Group - Set rsyslog logfile configuration
    facts
  ansible.builtin.set_fact:
    rsyslog_etc_config: /etc/rsyslog.conf
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_groupownership

- name: Ensure Log Files Are Owned By Appropriate Group - Get IncludeConfig directive
  ansible.builtin.shell: |
    set -o pipefail
    grep -e '$IncludeConfig' {{ rsyslog_etc_config }} | cut -d ' ' -f 2 || true
  register: rsyslog_old_inc
  changed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_groupownership

- name: Ensure Log Files Are Owned By Appropriate Group - Get include files directives
  ansible.builtin.shell: |
    set -o pipefail
    awk '/)/{f=0} /include\(/{f=1} f{ nf=gensub("^(include\\(|\\s*)file=\"(\\S+)\".*","\\2",1); if($0!=nf){ print nf }}' {{ rsyslog_etc_config }} || true
  register: rsyslog_new_inc
  changed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_groupownership

- name: Ensure Log Files Are Owned By Appropriate Group - Aggregate rsyslog includes
  ansible.builtin.set_fact:
    include_config_output: '{{ rsyslog_old_inc.stdout_lines + rsyslog_new_inc.stdout_lines
      }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - rsyslog_old_inc is not skipped and rsyslog_new_inc is not skipped
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_groupownership

- name: Ensure Log Files Are Owned By Appropriate Group - List all config files
  ansible.builtin.find:
    paths: '{{ item | dirname }}'
    patterns: '{{ item | basename }}'
    hidden: false
    follow: true
  loop: '{{ include_config_output | list + [rsyslog_etc_config] }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - include_config_output is defined
  register: rsyslog_config_files
  failed_when: false
  changed_when: false
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_groupownership

- name: Ensure Log Files Are Owned By Appropriate Group - Extract log files old format
  ansible.builtin.shell: |
    set -o pipefail
    grep -oP '^[^(\s|#|\$)]+[\s]*.*[\s]+-?(/+[^:;\s]+);*\.*$' {{ item.1.path }} | \
    awk '{print $NF}' | \
    sed -e 's/^-//' || true
  loop: '{{ rsyslog_config_files.results | default([]) | subelements(''files'') }}'
  register: log_files_old
  changed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - rsyslog_config_files is not skipped
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_groupownership

- name: Ensure Log Files Are Owned By Appropriate Group - Extract log files new format
  ansible.builtin.shell: |
    set -o pipefail
    grep -iozP "action\s*\(\s*type\s*=\s*\"omfile\"[^\)]*\)" {{ item.1.path }} | \
    grep -iaoP "\bFile\s*=\s*\"([/[:alnum:][:punct:]]*)\"\s*\)" | \
    grep -oE "\"([/[:alnum:][:punct:]]*)\"" | \
    tr -d "\"" | \
    grep -v '^/dev/' || true
  loop: '{{ rsyslog_config_files.results | default([]) | subelements(''files'') }}'
  register: log_files_new
  changed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - rsyslog_config_files is not skipped
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_groupownership

- name: Ensure Log Files Are Owned By Appropriate Group - Sum all log files found
  ansible.builtin.set_fact:
    log_files: '{{ log_files_new.results | map(attribute=''stdout_lines'') | list
      | flatten | unique + log_files_old.results | map(attribute=''stdout_lines'')
      | list | flatten | unique }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_groupownership

- name: Ensure Log Files Are Owned By Appropriate Group -Setup log files attribute
  ansible.builtin.file:
    path: '{{ item }}'
    group: root
    state: file
  loop: '{{ log_files | list | flatten | unique }}'
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_groupownership
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rsyslog_files_groupownership:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rsyslog_files_ownership" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Log Files Are Owned By Appropriate User</xccdf-1.2:title>
              <xccdf-1.2:description>The owner of all log files written by
<html:code>rsyslog</html:code> should be

<html:code>root</html:code>.

These log files are determined by the second part of each Rule line in
<html:code>/etc/rsyslog.conf</html:code> and typically all appear in <html:code>/var/log</html:code>.
For each log file <html:i>LOGFILE</html:i> referenced in <html:code>/etc/rsyslog.conf</html:code>,
run the following command to inspect the file's owner:
<html:pre>$ ls -l <html:i>LOGFILE</html:i></html:pre>
If the owner is not

<html:code>root</html:code>,

run the following command to
correct this:

<html:pre>$ sudo chown root <html:i>LOGFILE</html:i></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R71</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0988</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1405</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.2.3.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The log files generated by rsyslog contain valuable information regarding system
configuration, user authentication, and other such information. Log files should be
protected from unauthorized access.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="rsyslog_files_ownership" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; rpm --quiet -q rsyslog; then

# List of log file paths to be inspected for correct permissions
# * Primarily inspect log file paths listed in /etc/rsyslog.conf
RSYSLOG_ETC_CONFIG="/etc/rsyslog.conf"
# * And also the log file paths listed after rsyslog's $IncludeConfig directive
#   (store the result into array for the case there's shell glob used as value of IncludeConfig)
readarray -t OLD_INC &lt; &lt;(grep -e "\$IncludeConfig[[:space:]]\+[^[:space:];]\+" /etc/rsyslog.conf | cut -d ' ' -f 2)
readarray -t RSYSLOG_INCLUDE_CONFIG &lt; &lt;(for INCPATH in "${OLD_INC[@]}"; do eval printf '%s\\n' "${INCPATH}"; done)
readarray -t NEW_INC &lt; &lt;(sed -n '/^\s*include(/,/)/Ip' /etc/rsyslog.conf | sed -n 's@.*file\s*=\s*"\([/[:alnum:][:punct:]]*\)".*@\1@Ip')
readarray -t RSYSLOG_INCLUDE &lt; &lt;(for INCPATH in "${NEW_INC[@]}"; do eval printf '%s\\n' "${INCPATH}"; done)

# Declare an array to hold the final list of different log file paths
declare -a LOG_FILE_PATHS

# Array to hold all rsyslog config entries
RSYSLOG_CONFIGS=()
RSYSLOG_CONFIGS=("${RSYSLOG_ETC_CONFIG}" "${RSYSLOG_INCLUDE_CONFIG[@]}" "${RSYSLOG_INCLUDE[@]}")

# Get full list of files to be checked
# RSYSLOG_CONFIGS may contain globs such as
# /etc/rsyslog.d/*.conf /etc/rsyslog.d/*.frule
# So, loop over the entries in RSYSLOG_CONFIGS and use find to get the list of included files.
RSYSLOG_CONFIG_FILES=()
for ENTRY in "${RSYSLOG_CONFIGS[@]}"
do
	# If directory, rsyslog will search for config files in recursively.
	# However, files in hidden sub-directories or hidden files will be ignored.
	if [ -d "${ENTRY}" ]
	then
		readarray -t FINDOUT &lt; &lt;(find "${ENTRY}" -not -path '*/.*' -type f)
		RSYSLOG_CONFIG_FILES+=("${FINDOUT[@]}")
	elif [ -f "${ENTRY}" ]
	then
		RSYSLOG_CONFIG_FILES+=("${ENTRY}")
	else
		echo "Invalid include object: ${ENTRY}"
	fi
done

# Browse each file selected above as containing paths of log files
# ('/etc/rsyslog.conf' and '/etc/rsyslog.d/*.conf' in the default configuration)
for LOG_FILE in "${RSYSLOG_CONFIG_FILES[@]}"
do
	# From each of these files extract just particular log file path(s), thus:
	# * Ignore lines starting with space (' '), comment ('#"), or variable syntax ('$') characters,
	# * Ignore empty lines,
	# * Strip quotes and closing brackets from paths.
	# * Ignore paths that match /dev|/etc.*\.conf, as those are paths, but likely not log files
	# * From the remaining valid rows select only fields constituting a log file path
	# Text file column is understood to represent a log file path if and only if all of the
	# following are met:
	# * it contains at least one slash '/' character,
	# * it is preceded by space
	# * it doesn't contain space (' '), colon (':'), and semicolon (';') characters
	# Search log file for path(s) only in case it exists!
	if [[ -f "${LOG_FILE}" ]]
	then
		NORMALIZED_CONFIG_FILE_LINES=$(sed -e "/^[#|$]/d" "${LOG_FILE}")
		LINES_WITH_PATHS=$(grep '[^/]*\s\+\S*/\S\+$' &lt;&lt;&lt; "${NORMALIZED_CONFIG_FILE_LINES}")
		FILTERED_PATHS=$(awk '{if(NF&gt;=2&amp;&amp;($NF~/^\//||$NF~/^-\//)){sub(/^-\//,"/",$NF);print $NF}}' &lt;&lt;&lt; "${LINES_WITH_PATHS}")
		CLEANED_PATHS=$(sed -e "s/[\"')]//g; /\\/etc.*\.conf/d; /\\/dev\\//d" &lt;&lt;&lt; "${FILTERED_PATHS}")
		MATCHED_ITEMS=$(sed -e "/^$/d" &lt;&lt;&lt; "${CLEANED_PATHS}")
		# Since above sed command might return more than one item (delimited by newline), split
		# the particular matches entries into new array specific for this log file
		readarray -t ARRAY_FOR_LOG_FILE &lt;&lt;&lt; "$MATCHED_ITEMS"
		# Concatenate the two arrays - previous content of $LOG_FILE_PATHS array with
		# items from newly created array for this log file
		LOG_FILE_PATHS+=("${ARRAY_FOR_LOG_FILE[@]}")
		# Delete the temporary array
		unset ARRAY_FOR_LOG_FILE
	fi
done

# Check for RainerScript action log format which might be also multiline so grep regex is a bit
# curly:
# extract possibly multiline action omfile expressions
# extract File="logfile" expression
# match only "logfile" expression
# exclude /dev/* paths (e.g., /dev/console)
for LOG_FILE in "${RSYSLOG_CONFIG_FILES[@]}"
do
	ACTION_OMFILE_LINES=$(grep -iozP "action\s*\(\s*type\s*=\s*\"omfile\"[^\)]*\)" "${LOG_FILE}")
	OMFILE_LINES=$(echo "${ACTION_OMFILE_LINES}"| grep -iaoP "\bFile\s*=\s*\"([/[:alnum:][:punct:]]*)\"\s*\)")
	LOG_FILE_PATHS+=("$(echo "${OMFILE_LINES}"| grep -oE "\"([/[:alnum:][:punct:]]*)\""|tr -d "\"" | grep -v "^/dev/")")
done

# Ensure the correct attribute if file exists
FILE_CMD="chown"
for LOG_FILE_PATH in "${LOG_FILE_PATHS[@]}"
do
	# Sanity check - if particular $LOG_FILE_PATH is empty string, skip it from further processing
	if [ -z "$LOG_FILE_PATH" ]
	then
		continue
	fi
	$FILE_CMD "root" "$LOG_FILE_PATH"
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="rsyslog_files_ownership" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_ownership

- name: Ensure Log Files Are Owned By Appropriate User - Set rsyslog logfile configuration
    facts
  ansible.builtin.set_fact:
    rsyslog_etc_config: /etc/rsyslog.conf
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_ownership

- name: Ensure Log Files Are Owned By Appropriate User - Get IncludeConfig directive
  ansible.builtin.shell: |
    set -o pipefail
    grep -e '$IncludeConfig' {{ rsyslog_etc_config }} | cut -d ' ' -f 2 || true
  register: rsyslog_old_inc
  changed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_ownership

- name: Ensure Log Files Are Owned By Appropriate User - Get include files directives
  ansible.builtin.shell: |
    set -o pipefail
    awk '/)/{f=0} /include\(/{f=1} f{ nf=gensub("^(include\\(|\\s*)file=\"(\\S+)\".*","\\2",1); if($0!=nf){ print nf }}' {{ rsyslog_etc_config }} || true
  register: rsyslog_new_inc
  changed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_ownership

- name: Ensure Log Files Are Owned By Appropriate User - Aggregate rsyslog includes
  ansible.builtin.set_fact:
    include_config_output: '{{ rsyslog_old_inc.stdout_lines + rsyslog_new_inc.stdout_lines
      }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - rsyslog_old_inc is not skipped and rsyslog_new_inc is not skipped
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_ownership

- name: Ensure Log Files Are Owned By Appropriate User - List all config files
  ansible.builtin.find:
    paths: '{{ item | dirname }}'
    patterns: '{{ item | basename }}'
    hidden: false
    follow: true
  loop: '{{ include_config_output | list + [rsyslog_etc_config] }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - include_config_output is defined
  register: rsyslog_config_files
  failed_when: false
  changed_when: false
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_ownership

- name: Ensure Log Files Are Owned By Appropriate User - Extract log files old format
  ansible.builtin.shell: |
    set -o pipefail
    grep -oP '^[^(\s|#|\$)]+[\s]*.*[\s]+-?(/+[^:;\s]+);*\.*$' {{ item.1.path }} | \
    awk '{print $NF}' | \
    sed -e 's/^-//' || true
  loop: '{{ rsyslog_config_files.results | default([]) | subelements(''files'') }}'
  register: log_files_old
  changed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - rsyslog_config_files is not skipped
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_ownership

- name: Ensure Log Files Are Owned By Appropriate User - Extract log files new format
  ansible.builtin.shell: |
    set -o pipefail
    grep -iozP "action\s*\(\s*type\s*=\s*\"omfile\"[^\)]*\)" {{ item.1.path }} | \
    grep -iaoP "\bFile\s*=\s*\"([/[:alnum:][:punct:]]*)\"\s*\)" | \
    grep -oE "\"([/[:alnum:][:punct:]]*)\"" | \
    tr -d "\"" | \
    grep -v '^/dev/' || true
  loop: '{{ rsyslog_config_files.results | default([]) | subelements(''files'') }}'
  register: log_files_new
  changed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - rsyslog_config_files is not skipped
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_ownership

- name: Ensure Log Files Are Owned By Appropriate User - Sum all log files found
  ansible.builtin.set_fact:
    log_files: '{{ log_files_new.results | map(attribute=''stdout_lines'') | list
      | flatten | unique + log_files_old.results | map(attribute=''stdout_lines'')
      | list | flatten | unique }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_ownership

- name: Ensure Log Files Are Owned By Appropriate User -Setup log files attribute
  ansible.builtin.file:
    path: '{{ item }}'
    owner: root
    state: file
  loop: '{{ log_files | list | flatten | unique }}'
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_ownership
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rsyslog_files_ownership:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rsyslog_files_ownership_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rsyslog_files_permissions" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure System Log Files Have Correct Permissions</xccdf-1.2:title>
              <xccdf-1.2:description>The file permissions for all log files written by <html:code>rsyslog</html:code> should
be set to 640, or more restrictive. These log files are determined by the
second part of each Rule line in <html:code>/etc/rsyslog.conf</html:code> and typically
all appear in <html:code>/var/log</html:code>. For each log file <html:i>LOGFILE</html:i>
referenced in <html:code>/etc/rsyslog.conf</html:code>, run the following command to
inspect the file's permissions:
<html:pre>$ ls -l <html:i>LOGFILE</html:i></html:pre>
If the permissions are not 640 or more restrictive, run the following
command to correct this:
<html:pre>$ sudo chmod 640 <html:i>LOGFILE</html:i></html:pre>"</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R71</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0988</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1405</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.2.3.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Log files can contain valuable information regarding system
configuration. If the system log files are not protected unauthorized
users could change the logged data, eliminating their forensic value.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="rsyslog_files_permissions" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; rpm --quiet -q rsyslog; then

# List of log file paths to be inspected for correct permissions
# * Primarily inspect log file paths listed in /etc/rsyslog.conf
RSYSLOG_ETC_CONFIG="/etc/rsyslog.conf"
# * And also the log file paths listed after rsyslog's $IncludeConfig directive
#   (store the result into array for the case there's shell glob used as value of IncludeConfig)
readarray -t OLD_INC &lt; &lt;(grep -e "\$IncludeConfig[[:space:]]\+[^[:space:];]\+" /etc/rsyslog.conf | cut -d ' ' -f 2)
readarray -t RSYSLOG_INCLUDE_CONFIG &lt; &lt;(for INCPATH in "${OLD_INC[@]}"; do eval printf '%s\\n' "${INCPATH}"; done)
readarray -t NEW_INC &lt; &lt;(sed -n '/^\s*include(/,/)/Ip' /etc/rsyslog.conf | sed -n 's@.*file\s*=\s*"\([/[:alnum:][:punct:]]*\)".*@\1@Ip')
readarray -t RSYSLOG_INCLUDE &lt; &lt;(for INCPATH in "${NEW_INC[@]}"; do eval printf '%s\\n' "${INCPATH}"; done)

# Declare an array to hold the final list of different log file paths
declare -a LOG_FILE_PATHS

# Array to hold all rsyslog config entries
RSYSLOG_CONFIGS=()
RSYSLOG_CONFIGS=("${RSYSLOG_ETC_CONFIG}" "${RSYSLOG_INCLUDE_CONFIG[@]}" "${RSYSLOG_INCLUDE[@]}")

# Get full list of files to be checked
# RSYSLOG_CONFIGS may contain globs such as
# /etc/rsyslog.d/*.conf /etc/rsyslog.d/*.frule
# So, loop over the entries in RSYSLOG_CONFIGS and use find to get the list of included files.
RSYSLOG_CONFIG_FILES=()
for ENTRY in "${RSYSLOG_CONFIGS[@]}"
do
	# If directory, rsyslog will search for config files in recursively.
	# However, files in hidden sub-directories or hidden files will be ignored.
	if [ -d "${ENTRY}" ]
	then
		readarray -t FINDOUT &lt; &lt;(find "${ENTRY}" -not -path '*/.*' -type f)
		RSYSLOG_CONFIG_FILES+=("${FINDOUT[@]}")
	elif [ -f "${ENTRY}" ]
	then
		RSYSLOG_CONFIG_FILES+=("${ENTRY}")
	else
		echo "Invalid include object: ${ENTRY}"
	fi
done

# Browse each file selected above as containing paths of log files
# ('/etc/rsyslog.conf' and '/etc/rsyslog.d/*.conf' in the default configuration)
for LOG_FILE in "${RSYSLOG_CONFIG_FILES[@]}"
do
	# From each of these files extract just particular log file path(s), thus:
	# * Ignore lines starting with space (' '), comment ('#"), or variable syntax ('$') characters,
	# * Ignore empty lines,
	# * Strip quotes and closing brackets from paths.
	# * Ignore paths that match /dev|/etc.*\.conf, as those are paths, but likely not log files
	# * From the remaining valid rows select only fields constituting a log file path
	# Text file column is understood to represent a log file path if and only if all of the
	# following are met:
	# * it contains at least one slash '/' character,
	# * it is preceded by space
	# * it doesn't contain space (' '), colon (':'), and semicolon (';') characters
	# Search log file for path(s) only in case it exists!
	if [[ -f "${LOG_FILE}" ]]
	then
		NORMALIZED_CONFIG_FILE_LINES=$(sed -e "/^[#|$]/d" "${LOG_FILE}")
		LINES_WITH_PATHS=$(grep '[^/]*\s\+\S*/\S\+$' &lt;&lt;&lt; "${NORMALIZED_CONFIG_FILE_LINES}")
		FILTERED_PATHS=$(awk '{if(NF&gt;=2&amp;&amp;($NF~/^\//||$NF~/^-\//)){sub(/^-\//,"/",$NF);print $NF}}' &lt;&lt;&lt; "${LINES_WITH_PATHS}")
		CLEANED_PATHS=$(sed -e "s/[\"')]//g; /\\/etc.*\.conf/d; /\\/dev\\//d" &lt;&lt;&lt; "${FILTERED_PATHS}")
		MATCHED_ITEMS=$(sed -e "/^$/d" &lt;&lt;&lt; "${CLEANED_PATHS}")
		# Since above sed command might return more than one item (delimited by newline), split
		# the particular matches entries into new array specific for this log file
		readarray -t ARRAY_FOR_LOG_FILE &lt;&lt;&lt; "$MATCHED_ITEMS"
		# Concatenate the two arrays - previous content of $LOG_FILE_PATHS array with
		# items from newly created array for this log file
		LOG_FILE_PATHS+=("${ARRAY_FOR_LOG_FILE[@]}")
		# Delete the temporary array
		unset ARRAY_FOR_LOG_FILE
	fi
done

# Check for RainerScript action log format which might be also multiline so grep regex is a bit
# curly:
# extract possibly multiline action omfile expressions
# extract File="logfile" expression
# match only "logfile" expression
# exclude /dev/* paths (e.g., /dev/console)
for LOG_FILE in "${RSYSLOG_CONFIG_FILES[@]}"
do
	ACTION_OMFILE_LINES=$(grep -iozP "action\s*\(\s*type\s*=\s*\"omfile\"[^\)]*\)" "${LOG_FILE}")
	OMFILE_LINES=$(echo "${ACTION_OMFILE_LINES}"| grep -iaoP "\bFile\s*=\s*\"([/[:alnum:][:punct:]]*)\"\s*\)")
	LOG_FILE_PATHS+=("$(echo "${OMFILE_LINES}"| grep -oE "\"([/[:alnum:][:punct:]]*)\""|tr -d "\"" | grep -v "^/dev/")")
done

# Ensure the correct attribute if file exists
FILE_CMD="chmod"
for LOG_FILE_PATH in "${LOG_FILE_PATHS[@]}"
do
	# Sanity check - if particular $LOG_FILE_PATH is empty string, skip it from further processing
	if [ -z "$LOG_FILE_PATH" ]
	then
		continue
	fi
	$FILE_CMD "0640" "$LOG_FILE_PATH"
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="rsyslog_files_permissions" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_permissions

- name: Ensure System Log Files Have Correct Permissions - Set rsyslog logfile configuration
    facts
  ansible.builtin.set_fact:
    rsyslog_etc_config: /etc/rsyslog.conf
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_permissions

- name: Ensure System Log Files Have Correct Permissions - Get IncludeConfig directive
  ansible.builtin.shell: |
    set -o pipefail
    grep -e '$IncludeConfig' {{ rsyslog_etc_config }} | cut -d ' ' -f 2 || true
  register: rsyslog_old_inc
  changed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_permissions

- name: Ensure System Log Files Have Correct Permissions - Get include files directives
  ansible.builtin.shell: |
    set -o pipefail
    awk '/)/{f=0} /include\(/{f=1} f{ nf=gensub("^(include\\(|\\s*)file=\"(\\S+)\".*","\\2",1); if($0!=nf){ print nf }}' {{ rsyslog_etc_config }} || true
  register: rsyslog_new_inc
  changed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_permissions

- name: Ensure System Log Files Have Correct Permissions - Aggregate rsyslog includes
  ansible.builtin.set_fact:
    include_config_output: '{{ rsyslog_old_inc.stdout_lines + rsyslog_new_inc.stdout_lines
      }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - rsyslog_old_inc is not skipped and rsyslog_new_inc is not skipped
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_permissions

- name: Ensure System Log Files Have Correct Permissions - List all config files
  ansible.builtin.find:
    paths: '{{ item | dirname }}'
    patterns: '{{ item | basename }}'
    hidden: false
    follow: true
  loop: '{{ include_config_output | list + [rsyslog_etc_config] }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - include_config_output is defined
  register: rsyslog_config_files
  failed_when: false
  changed_when: false
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_permissions

- name: Ensure System Log Files Have Correct Permissions - Extract log files old format
  ansible.builtin.shell: |
    set -o pipefail
    grep -oP '^[^(\s|#|\$)]+[\s]*.*[\s]+-?(/+[^:;\s]+);*\.*$' {{ item.1.path }} | \
    awk '{print $NF}' | \
    sed -e 's/^-//' || true
  loop: '{{ rsyslog_config_files.results | default([]) | subelements(''files'') }}'
  register: log_files_old
  changed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - rsyslog_config_files is not skipped
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_permissions

- name: Ensure System Log Files Have Correct Permissions - Extract log files new format
  ansible.builtin.shell: |
    set -o pipefail
    grep -iozP "action\s*\(\s*type\s*=\s*\"omfile\"[^\)]*\)" {{ item.1.path }} | \
    grep -iaoP "\bFile\s*=\s*\"([/[:alnum:][:punct:]]*)\"\s*\)" | \
    grep -oE "\"([/[:alnum:][:punct:]]*)\"" | \
    tr -d "\"" | \
    grep -v '^/dev/' || true
  loop: '{{ rsyslog_config_files.results | default([]) | subelements(''files'') }}'
  register: log_files_new
  changed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - rsyslog_config_files is not skipped
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_permissions

- name: Ensure System Log Files Have Correct Permissions - Sum all log files found
  ansible.builtin.set_fact:
    log_files: '{{ log_files_new.results | map(attribute=''stdout_lines'') | list
      | flatten | unique + log_files_old.results | map(attribute=''stdout_lines'')
      | list | flatten | unique }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_permissions

- name: Ensure System Log Files Have Correct Permissions -Setup log files attribute
  ansible.builtin.file:
    path: '{{ item }}'
    mode: '0640'
    state: file
  loop: '{{ log_files | list | flatten | unique }}'
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_files_permissions
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rsyslog_files_permissions:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rsyslog_files_permissions_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rsyslog_logging_configured" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure logging is configured</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>/etc/rsyslog.conf</html:code> and <html:code>/etc/rsyslog.d/*.conf</html:code> files
specifies rules for logging and which files are to be used to log certain
classes of messages.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule does not come with remediation as there is no one way to solve the problem, and
the requirement from CIS specification does not require one particular way, but persuades
the system administrator to perform configuration suitable for the specific environment.
This also means that the OVAL check is too generic, and the user most probably should
perform additional manual verification.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>A great deal of important security-related information is sent via
rsyslog (e.g., successful and failed su attempts, failed login attempts,
root login attempts, etc.).</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rsyslog_logging_configured:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rsyslog_logging_configured_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rsyslog_remote_access_monitoring" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure remote access methods are monitored in Rsyslog</xccdf-1.2:title>
              <xccdf-1.2:description>Logging of remote access methods must be implemented to help identify cyber
attacks and ensure ongoing compliance with remote access policies are being
audited and upheld. An examples of a remote access method is the use of the
Remote Desktop Protocol (RDP) from an external, non-organization controlled
network. The <html:code>/etc/rsyslog.conf</html:code> or
<html:code>/etc/rsyslog.d/*.conf</html:code> file should contain a match for the following
selectors: <html:code>auth.*</html:code>, <html:code>authpriv.*</html:code>, and <html:code>daemon.*</html:code>. If
not, use the following as an example configuration:
<html:code>
    auth.*;authpriv.*                              /var/log/secure
    daemon.*                                       /var/log/messages
</html:code></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000032-GPOS-00013</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010070</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230228r1069299_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Logging remote access methods can be used to trace the decrease the risks
associated with remote user access management. It can also be used to spot
cyber attacks and ensure ongoing compliance with organizational policies
surrounding the use of remote access methods.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="rsyslog_remote_access_monitoring" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; rpm --quiet -q rsyslog; then

declare -A REMOTE_METHODS=( ['auth.*']='^[^#]*auth\.\*.*$' ['authpriv.*']='^[^#]*authpriv\.\*.*$' ['daemon.*']='^[^#]*daemon\.\*.*$' )
declare -A LOCATIONS=( ['auth.*']='/var/log/secure' ['authpriv.*']='/var/log/secure' ['daemon.*']='/var/log/messages' )

if [[ ! -f /etc/rsyslog.conf ]]; then
	# Something is not right, create the file
	touch /etc/rsyslog.conf
fi


# Loop through the remote methods associative array
for K in "${!REMOTE_METHODS[@]}"
do
	# Check to see if selector/value exists
	if ! grep -rq "${REMOTE_METHODS[$K]}" /etc/rsyslog.*; then
        APPEND_LINE=$(sed -rn "/^\S+\s+\${LOCATIONS[$K]}$/p" /etc/rsyslog.conf)
		# Make sure we have a line to insert after, otherwise append to end
		if [[ ! -z ${APPEND_LINE} ]]; then
			# Add selector to file
			sed -r -i "0,/^(\S+\s+\/var\/log\/secure$)/s//\1\n${K} \/var\/log\/secure/" /etc/rsyslog.conf
		else
			echo "${K} ${LOCATIONS[$K]}" &gt;&gt; /etc/rsyslog.conf
		fi
	fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="rsyslog_remote_access_monitoring" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010070
  - NIST-800-53-AC-17(1)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_remote_access_monitoring

- name: 'Ensure remote access methods are monitored in Rsyslog: Set facts'
  ansible.builtin.set_fact:
    conf_files:
    - /etc/rsyslog.conf
    remote_methods:
    - selector: auth.*
      regexp: ^[^#]*auth\.\*.*$
      location: /var/log/secure
    - selector: authpriv.*
      regexp: ^[^#]*authpriv\.\*.*$
      location: /var/log/secure
    - selector: daemon.*
      regexp: ^[^#]*daemon\.\*.*$
      location: /var/log/messages
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010070
  - NIST-800-53-AC-17(1)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_remote_access_monitoring

- name: 'Ensure remote access methods are monitored in Rsyslog: Ensure rsyslog.conf
    exists'
  ansible.builtin.file:
    path: '{{ conf_files.0 }}'
    state: touch
    access_time: preserve
    modification_time: preserve
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010070
  - NIST-800-53-AC-17(1)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_remote_access_monitoring

- name: 'Ensure remote access methods are monitored in Rsyslog: Gather conf.d files'
  ansible.builtin.find:
    patterns:
    - '*.conf'
    paths:
    - /etc/rsyslog.d
  register: rsyslogd
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010070
  - NIST-800-53-AC-17(1)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_remote_access_monitoring

- name: 'Ensure remote access methods are monitored in Rsyslog: Set conf file(s)'
  ansible.builtin.set_fact:
    conf_files: '{{ conf_files + [item.path] }}'
  loop: '{{ rsyslogd.files }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - rsyslogd.matched &gt; 0
  tags:
  - DISA-STIG-RHEL-08-010070
  - NIST-800-53-AC-17(1)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_remote_access_monitoring

- name: 'Ensure remote access methods are monitored in Rsyslog: Check for existing
    values'
  ansible.builtin.lineinfile:
    path: '{{ item.1 }}'
    regexp: '{{ item.0.regexp }}'
    state: absent
  check_mode: true
  changed_when: false
  register: remote_method_values
  loop: '{{ remote_methods|product(conf_files)|list }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010070
  - NIST-800-53-AC-17(1)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_remote_access_monitoring

- name: 'Ensure remote access methods are monitored in Rsyslog: Configure'
  ansible.builtin.lineinfile:
    path: /etc/rsyslog.conf
    line: '{{ item.item.0.selector }} {{ item.item.0.location }}'
    insertafter: ^.*\/var\/log\/secure.*$
    create: true
  loop: '{{ remote_method_values.results }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"rsyslog" in ansible_facts.packages'
  - item.found == 0
  tags:
  - DISA-STIG-RHEL-08-010070
  - NIST-800-53-AC-17(1)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_remote_access_monitoring
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rsyslog_remote_access_monitoring:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rsyslog_remote_access_monitoring_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_journald">
            <xccdf-1.2:title>systemd-journald</xccdf-1.2:title>
            <xccdf-1.2:description>systemd-journald is a system service that collects and stores
logging data. It creates and maintains structured, indexed
journals based on logging information that is received from a
variety of sources.

For more information on <html:code>systemd-journald </html:code> and additional <html:code>systemd-journald</html:code> configuration options, see
<html:b><html:a href="https://systemd.io/">https://systemd.io/</html:a></html:b>.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_systemd-journal-remote_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install systemd-journal-remote Package</xccdf-1.2:title>
              <xccdf-1.2:description>Journald (via systemd-journal-remote ) supports the ability to send
log events it gathers to a remote log host or to receive messages
from remote hosts, thus enabling centralised log management.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000479-GPOS-00224</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.2.1.2.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Storing log data on a remote host protects log integrity from local
attacks. If an attacker gains root access on the local system, they
could tamper with or remove log data that is stored on the local system.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_systemd-journal-remote_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "systemd-journal-remote" ; then
    yum install -y "systemd-journal-remote"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_systemd-journal-remote_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_systemd-journal-remote_installed

- name: Ensure systemd-journal-remote is installed
  ansible.builtin.package:
    name: systemd-journal-remote
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_systemd-journal-remote_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_systemd-journal-remote_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_systemd-journal-remote

class install_systemd-journal-remote {
  package { 'systemd-journal-remote':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_systemd-journal-remote_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=systemd-journal-remote
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_systemd-journal-remote_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "systemd-journal-remote"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_systemd-journal-remote_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install systemd-journal-remote
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_systemd-journal-remote_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install systemd-journal-remote
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_systemd-journal-remote_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_systemd-journal-remote_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_systemd-journal-upload_enabled" selected="false" severity="medium">
              <xccdf-1.2:title>Enable systemd-journal-upload Service</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>systemd-journal-upload</html:code> service is part of the <html:code>systemd-journal-remote</html:code> package
and enables centralized logging by uploading local systemd journal entries to a remote log
server via HTTPS. This service acts as a client that pushes journal data to a remote host
running the <html:code>systemd-journal-remote</html:code> receiver service.

The <html:code>systemd-journal-upload</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable systemd-journal-upload.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">The <html:code>systemd-journal-upload</html:code> service will fail to start if the remote server URL is not configured.
Edit <html:code>/etc/systemd/journal-upload.conf</html:code> to configure the remote server URL.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000479-GPOS-00224</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.2.1.2.3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Centralized logging through <html:code>systemd-journal-upload</html:code> is essential for security monitoring,
incident response, and compliance requirements. Storing log data on a remote host protects log
integrity from local attacks. If an attacker gains root access on the local system, they could
tamper with or remove log data stored locally to hide their activities. Remote logging ensures
that audit trails remain intact even if the local system is compromised. Additionally,
centralized logs facilitate correlation of events across multiple systems, enabling better
detection of distributed attacks and security incidents.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#machine_and_package_systemd-journal-remote"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_systemd-journal-upload_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { ( ( [ ! -f /.dockerenv ] &amp;&amp; [ ! -f /run/.containerenv ] &amp;&amp; rpm --quiet -q systemd-journal-remote ) ); }; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'systemd-journal-upload.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'systemd-journal-upload.service'
fi
"$SYSTEMCTL_EXEC" enable 'systemd-journal-upload.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_systemd-journal-upload_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_systemd-journal-upload_enabled

- name: Enable systemd-journal-upload Service - Enable service systemd-journal-upload
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable systemd-journal-upload Service - Enable Service systemd-journal-upload
    ansible.builtin.systemd:
      name: systemd-journal-upload
      enabled: true
      state: started
      masked: false
    when:
    - '"systemd-journal-remote" in ansible_facts.packages'
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_systemd-journal-upload_enabled
  - special_service_block
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_virtualization_type not in ["docker", "lxc", "openvz", "podman", "container"]
    and "systemd-journal-remote" in ansible_facts.packages )
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_systemd-journal-upload_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_systemd-journal-upload

class enable_systemd-journal-upload {
  service {'systemd-journal-upload':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_systemd-journal-upload_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["systemd-journal-upload"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_systemd-journal-upload_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable systemd-journal-upload
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_systemd-journal-upload_enabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_systemd-journal-upload_enabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_systemd-journald_enabled" selected="false" severity="medium">
              <xccdf-1.2:title>Enable systemd-journald Service</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>systemd-journald</html:code> service is an essential component of
systemd.

The <html:code>systemd-journald</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable systemd-journald.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-24</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000269-GPOS-00103</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.2.1.1.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>In the event of a system failure, AlmaLinux OS 8 must preserve any information necessary to determine cause of failure and any information necessary to return to operations with least disruption to system processes.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_systemd-journald_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'systemd-journald.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'systemd-journald.service'
fi
"$SYSTEMCTL_EXEC" enable 'systemd-journald.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_systemd-journald_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-SC-24
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_systemd-journald_enabled

- name: Enable systemd-journald Service - Enable service systemd-journald
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable systemd-journald Service - Enable Service systemd-journald
    ansible.builtin.systemd:
      name: systemd-journald
      enabled: true
      state: started
      masked: false
    when:
    - '"systemd" in ansible_facts.packages'
  tags:
  - NIST-800-53-SC-24
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_systemd-journald_enabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_systemd-journald_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_systemd-journald

class enable_systemd-journald {
  service {'systemd-journald':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_systemd-journald_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["systemd-journald"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_systemd-journald_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable systemd-journald
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_systemd-journald_enabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_journald_compress" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure journald is configured to compress large log files</xccdf-1.2:title>
              <xccdf-1.2:description>The journald system can compress large log files to avoid fill the system disk.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.2.1.1.6</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Log files that are not properly compressed run the risk of growing so large that they fill up the log partition. Valuable logging information could be lost if the log partition becomes full.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="journald_compress" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/systemd/journald.conf" ] ; then
    
    LC_ALL=C sed -i "/^\s*Compress\s*=\s*/d" "/etc/systemd/journald.conf"
else
    touch "/etc/systemd/journald.conf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/systemd/journald.conf"

cp "/etc/systemd/journald.conf" "/etc/systemd/journald.conf.bak"
# Insert before the line matching the regex '^#\s*Compress'.
line_number="$(LC_ALL=C grep -n "^#\s*Compress" "/etc/systemd/journald.conf.bak" | LC_ALL=C sed 's/:.*//g')"
if [ -z "$line_number" ]; then
    # There was no match of '^#\s*Compress', insert at
    # the end of the file.
    printf '%s\n' "Compress=yes" &gt;&gt; "/etc/systemd/journald.conf"
else
    head -n "$(( line_number - 1 ))" "/etc/systemd/journald.conf.bak" &gt; "/etc/systemd/journald.conf"
    printf '%s\n' "Compress=yes" &gt;&gt; "/etc/systemd/journald.conf"
    tail -n "+$(( line_number ))" "/etc/systemd/journald.conf.bak" &gt;&gt; "/etc/systemd/journald.conf"
fi
# Clean up after ourselves.
rm "/etc/systemd/journald.conf.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="journald_compress" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - journald_compress
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Setting unquoted shell-style assignment of 'Compress' to 'yes' in '/etc/systemd/journald.conf'
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/systemd/journald.conf
      create: true
      regexp: (?i)^\s*Compress=
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/systemd/journald.conf
    ansible.builtin.lineinfile:
      path: /etc/systemd/journald.conf
      create: true
      regexp: (?i)^\s*Compress=
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/systemd/journald.conf
    ansible.builtin.lineinfile:
      path: /etc/systemd/journald.conf
      create: true
      regexp: (?i)^\s*Compress=
      line: Compress=yes
      state: present
      insertbefore: ^# Compress
      validate: /usr/bin/bash -n %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - journald_compress
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-journald_compress:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-journald_compress_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_journald_disable_forward_to_syslog" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure journald ForwardToSyslog is disabled</xccdf-1.2:title>
              <xccdf-1.2:description>Data from journald should be kept in the confines of the service and not forwarded to other services.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.2.1.1.4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If journald is the method for capturing logs, all logs of the system should be handled by journald and not forwarded to other logging mechanisms.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_systemd"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="journald_disable_forward_to_syslog" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q systemd; }; then

if [ -e "/etc/systemd/journald.conf" ] ; then
    
    LC_ALL=C sed -i "/^\s*ForwardToSyslog\s*=\s*/d" "/etc/systemd/journald.conf"
else
    touch "/etc/systemd/journald.conf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/systemd/journald.conf"

cp "/etc/systemd/journald.conf" "/etc/systemd/journald.conf.bak"
# Insert before the line matching the regex '^#\s*ForwardToSyslog'.
line_number="$(LC_ALL=C grep -n "^#\s*ForwardToSyslog" "/etc/systemd/journald.conf.bak" | LC_ALL=C sed 's/:.*//g')"
if [ -z "$line_number" ]; then
    # There was no match of '^#\s*ForwardToSyslog', insert at
    # the end of the file.
    printf '%s\n' "ForwardToSyslog=no" &gt;&gt; "/etc/systemd/journald.conf"
else
    head -n "$(( line_number - 1 ))" "/etc/systemd/journald.conf.bak" &gt; "/etc/systemd/journald.conf"
    printf '%s\n' "ForwardToSyslog=no" &gt;&gt; "/etc/systemd/journald.conf"
    tail -n "+$(( line_number ))" "/etc/systemd/journald.conf.bak" &gt;&gt; "/etc/systemd/journald.conf"
fi
# Clean up after ourselves.
rm "/etc/systemd/journald.conf.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="journald_disable_forward_to_syslog" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - journald_disable_forward_to_syslog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Setting unquoted shell-style assignment of 'ForwardToSyslog' to 'no' in '/etc/systemd/journald.conf'
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/systemd/journald.conf
      create: true
      regexp: (?i)^\s*ForwardToSyslog=
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/systemd/journald.conf
    ansible.builtin.lineinfile:
      path: /etc/systemd/journald.conf
      create: true
      regexp: (?i)^\s*ForwardToSyslog=
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/systemd/journald.conf
    ansible.builtin.lineinfile:
      path: /etc/systemd/journald.conf
      create: true
      regexp: (?i)^\s*ForwardToSyslog=
      line: ForwardToSyslog=no
      state: present
      insertbefore: ^# ForwardToSyslog
      validate: /usr/bin/bash -n %s
  when:
  - '"kernel" in ansible_facts.packages'
  - '"systemd" in ansible_facts.packages'
  tags:
  - journald_disable_forward_to_syslog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-journald_disable_forward_to_syslog:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-journald_disable_forward_to_syslog_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_journald_forward_to_syslog" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure journald is configured to send logs to rsyslog</xccdf-1.2:title>
              <xccdf-1.2:description>Data from journald may be stored in volatile memory or persisted locally.
Utilities exist to accept remote export of journald logs.</xccdf-1.2:description>
              <xccdf-1.2:rationale>Storing log data on a remote host protects log integrity from local attacks. If an attacker gains root access on the local system, they could tamper with or remove log data that is stored on the local system.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="journald_forward_to_syslog" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/systemd/journald.conf" ] ; then
    
    LC_ALL=C sed -i "/^\s*ForwardToSyslog\s*=\s*/d" "/etc/systemd/journald.conf"
else
    touch "/etc/systemd/journald.conf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/systemd/journald.conf"

cp "/etc/systemd/journald.conf" "/etc/systemd/journald.conf.bak"
# Insert before the line matching the regex '^#\s*ForwardToSyslog'.
line_number="$(LC_ALL=C grep -n "^#\s*ForwardToSyslog" "/etc/systemd/journald.conf.bak" | LC_ALL=C sed 's/:.*//g')"
if [ -z "$line_number" ]; then
    # There was no match of '^#\s*ForwardToSyslog', insert at
    # the end of the file.
    printf '%s\n' "ForwardToSyslog=yes" &gt;&gt; "/etc/systemd/journald.conf"
else
    head -n "$(( line_number - 1 ))" "/etc/systemd/journald.conf.bak" &gt; "/etc/systemd/journald.conf"
    printf '%s\n' "ForwardToSyslog=yes" &gt;&gt; "/etc/systemd/journald.conf"
    tail -n "+$(( line_number ))" "/etc/systemd/journald.conf.bak" &gt;&gt; "/etc/systemd/journald.conf"
fi
# Clean up after ourselves.
rm "/etc/systemd/journald.conf.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="journald_forward_to_syslog" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - journald_forward_to_syslog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Setting unquoted shell-style assignment of 'ForwardToSyslog' to 'yes' in '/etc/systemd/journald.conf'
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/systemd/journald.conf
      create: true
      regexp: (?i)^\s*ForwardToSyslog=
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/systemd/journald.conf
    ansible.builtin.lineinfile:
      path: /etc/systemd/journald.conf
      create: true
      regexp: (?i)^\s*ForwardToSyslog=
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/systemd/journald.conf
    ansible.builtin.lineinfile:
      path: /etc/systemd/journald.conf
      create: true
      regexp: (?i)^\s*ForwardToSyslog=
      line: ForwardToSyslog=yes
      state: present
      insertbefore: ^# ForwardToSyslog
      validate: /usr/bin/bash -n %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - journald_forward_to_syslog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-journald_forward_to_syslog:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-journald_forward_to_syslog_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_journald_storage" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure journald is configured to write log files to persistent disk</xccdf-1.2:title>
              <xccdf-1.2:description>The journald system may store log files in volatile memory or locally on disk.
If the logs are only stored in volatile memory they will be lost upon reboot.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.2.1.1.5</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Log files contain valuable data and need to be persistent to aid in possible investigations.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="journald_storage" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/systemd/journald.conf" ] ; then
    
    LC_ALL=C sed -i "/^\s*Storage\s*=\s*/d" "/etc/systemd/journald.conf"
else
    touch "/etc/systemd/journald.conf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/systemd/journald.conf"

cp "/etc/systemd/journald.conf" "/etc/systemd/journald.conf.bak"
# Insert before the line matching the regex '^#\s*Storage'.
line_number="$(LC_ALL=C grep -n "^#\s*Storage" "/etc/systemd/journald.conf.bak" | LC_ALL=C sed 's/:.*//g')"
if [ -z "$line_number" ]; then
    # There was no match of '^#\s*Storage', insert at
    # the end of the file.
    printf '%s\n' "Storage=persistent" &gt;&gt; "/etc/systemd/journald.conf"
else
    head -n "$(( line_number - 1 ))" "/etc/systemd/journald.conf.bak" &gt; "/etc/systemd/journald.conf"
    printf '%s\n' "Storage=persistent" &gt;&gt; "/etc/systemd/journald.conf"
    tail -n "+$(( line_number ))" "/etc/systemd/journald.conf.bak" &gt;&gt; "/etc/systemd/journald.conf"
fi
# Clean up after ourselves.
rm "/etc/systemd/journald.conf.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="journald_storage" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - journald_storage
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Setting unquoted shell-style assignment of 'Storage' to 'persistent' in '/etc/systemd/journald.conf'
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/systemd/journald.conf
      create: true
      regexp: (?i)^\s*Storage=
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/systemd/journald.conf
    ansible.builtin.lineinfile:
      path: /etc/systemd/journald.conf
      create: true
      regexp: (?i)^\s*Storage=
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/systemd/journald.conf
    ansible.builtin.lineinfile:
      path: /etc/systemd/journald.conf
      create: true
      regexp: (?i)^\s*Storage=
      line: Storage=persistent
      state: present
      insertbefore: ^# Storage
      validate: /usr/bin/bash -n %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - journald_storage
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-journald_storage:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-journald_storage_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_socket_systemd-journal-remote_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable systemd-journal-remote Socket</xccdf-1.2:title>
              <xccdf-1.2:description>Journald supports the ability to receive messages from remote hosts,
thus acting as a log server. Clients should not receive data from
other hosts.
NOTE:
    The same package, systemd-journal-remote , is used for both sending
    logs to remote hosts and receiving incoming logs.
    With regards to receiving logs, there are two Systemd unit files;
    systemd-journal-remote.socket and systemd-journal-remote.service.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.2.1.2.4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If a client is configured to also receive data, thus turning it into
a server, the client system is acting outside it's operational boundary.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="socket_systemd-journal-remote_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SOCKET_NAME="systemd-journal-remote.socket"
SYSTEMCTL_EXEC='/usr/bin/systemctl'

if "$SYSTEMCTL_EXEC" -q list-unit-files --type socket | grep -q "$SOCKET_NAME"; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop "$SOCKET_NAME"
    fi
    "$SYSTEMCTL_EXEC" mask "$SOCKET_NAME"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="socket_systemd-journal-remote_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - socket_systemd-journal-remote_disabled

- name: Disable systemd-journal-remote Socket - Collect systemd Socket Units Present
    in the System
  ansible.builtin.command:
    cmd: systemctl -q list-unit-files --type socket
  register: result_systemd_unit_files
  changed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - socket_systemd-journal-remote_disabled

- name: Disable systemd-journal-remote Socket - Ensure systemd-journal-remote.socket
    is Masked
  ansible.builtin.systemd:
    name: systemd-journal-remote.socket
    state: stopped
    enabled: false
    masked: true
  when:
  - '"kernel" in ansible_facts.packages'
  - result_systemd_unit_files.stdout_lines is search("systemd-journal-remote.socket")
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - socket_systemd-journal-remote_disabled
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-socket_systemd-journal-remote_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-socket_systemd-journal-remote_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_log_rotation">
            <xccdf-1.2:title>Ensure All Logs are Rotated by logrotate</xccdf-1.2:title>
            <xccdf-1.2:description>Edit the file <html:code>/etc/logrotate.d/syslog</html:code>. Find the first
line, which should look like this (wrapped for clarity):
<html:pre>/var/log/messages /var/log/secure /var/log/maillog /var/log/spooler \
  /var/log/boot.log /var/log/cron {</html:pre>
Edit this line so that it contains a one-space-separated
listing of each log file referenced in <html:code>/etc/rsyslog.conf</html:code>.
<html:br/><html:br/>
All logs in use on a system must be rotated regularly, or the
log files will consume disk space over time, eventually interfering
with system operation. The file <html:code>/etc/logrotate.d/syslog</html:code> is the
configuration file used by the <html:code>logrotate</html:code> program to maintain all
log files written by <html:code>syslog</html:code>. By default, it rotates logs weekly and
stores four archival copies of each log. These settings can be
modified by editing <html:code>/etc/logrotate.conf</html:code>, but the defaults are
sufficient for purposes of this guide.
<html:br/><html:br/>
Note that <html:code>logrotate</html:code> is run nightly by the cron job
<html:code>/etc/cron.daily/logrotate</html:code>. If particularly active logs need to be
rotated more often than once a day, some other mechanism must be
used.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_logrotate_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure logrotate is Installed</xccdf-1.2:title>
              <xccdf-1.2:description>logrotate is installed by default. The <html:code>logrotate</html:code> package can be installed with the following command: <html:pre> $ sudo yum install logrotate</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R71</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.5</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The logrotate package provides the logrotate services.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_logrotate_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "logrotate" ; then
    yum install -y "logrotate"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_logrotate_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - PCI-DSSv4-10.5
  - PCI-DSSv4-10.5.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_logrotate_installed

- name: Ensure logrotate is installed
  ansible.builtin.package:
    name: logrotate
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - PCI-DSSv4-10.5
  - PCI-DSSv4-10.5.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_logrotate_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_logrotate_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_logrotate

class install_logrotate {
  package { 'logrotate':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_logrotate_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=logrotate
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_logrotate_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "logrotate"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_logrotate_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install logrotate
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_logrotate_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install logrotate
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_logrotate_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ensure_logrotate_activated" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Logrotate Runs Periodically</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>logrotate</html:code> utility allows for the automatic rotation of
log files.  The frequency of rotation is specified in <html:code>/etc/logrotate.conf</html:code>,
which triggers a cron task or a timer.  To configure logrotate to run daily, add or correct
the following line in <html:code>/etc/logrotate.conf</html:code>:
<html:pre># rotate log files <html:i>frequency</html:i>
daily</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R71</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Log files that are not properly rotated run the risk of growing so large
that they fill up the /var/log partition. Valuable logging information could be lost
if the /var/log partition becomes full.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_logrotate"/>
              <xccdf-1.2:fix id="ensure_logrotate_activated" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q logrotate; }; then

LOGROTATE_CONF_FILE='/etc/logrotate.conf'




if ! rpm -q --quiet "crontabs" ; then
    yum install -y "crontabs"
fi
CRON_DAILY_LOGROTATE_FILE="/etc/cron.daily/logrotate"


# daily rotation is configured
grep -q "^daily$" $LOGROTATE_CONF_FILE|| sed -i '1i daily' "$LOGROTATE_CONF_FILE"

# remove any line configuring weekly, monthly or yearly rotation
sed -i '/^\s*\(weekly\|monthly\|yearly\).*$/d' $LOGROTATE_CONF_FILE


# configure cron.daily if not already
if ! grep -q "^[[:space:]]*/usr/sbin/logrotate[[:alnum:][:blank:][:punct:]]*$LOGROTATE_CONF_FILE$" $CRON_DAILY_LOGROTATE_FILE; then
	echo '#!/bin/sh' &gt; $CRON_DAILY_LOGROTATE_FILE
	echo "/usr/sbin/logrotate $LOGROTATE_CONF_FILE" &gt;&gt; $CRON_DAILY_LOGROTATE_FILE
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="ensure_logrotate_activated" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - configure_strategy
  - ensure_logrotate_activated
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure daily log rotation in /etc/logrotate.conf
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/logrotate.conf
    regexp: ^\s*(weekly|monthly|yearly)$
    line: daily
    state: present
    insertbefore: BOF
  when:
  - '"kernel" in ansible_facts.packages'
  - '"logrotate" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - configure_strategy
  - ensure_logrotate_activated
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Make sure daily log rotation setting is not overridden in /etc/logrotate.conf
  ansible.builtin.lineinfile:
    create: false
    dest: /etc/logrotate.conf
    regexp: ^[\s]*(weekly|monthly|yearly)$
    state: absent
  when:
  - '"kernel" in ansible_facts.packages'
  - '"logrotate" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - configure_strategy
  - ensure_logrotate_activated
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure cron.daily if not already
  block:

  - name: Add shebang
    ansible.builtin.lineinfile:
      path: /etc/cron.daily/logrotate
      line: '#!/bin/sh'
      insertbefore: BOF
      create: true

  - name: Add logrotate call
    ansible.builtin.lineinfile:
      path: /etc/cron.daily/logrotate
      line: /usr/sbin/logrotate /etc/logrotate.conf
      regexp: ^[\s]*/usr/sbin/logrotate[\s\S]*/etc/logrotate.conf$
      create: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"logrotate" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - configure_strategy
  - ensure_logrotate_activated
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="ensure_logrotate_activated" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%20see%20%22man%20logrotate%22%20for%20details%0A%23%20rotate%20log%20files%20daily%0Adaily%0A%0A%23%20keep%204%20weeks%20worth%20of%20backlogs%0Arotate%2030%0A%0A%23%20create%20new%20%28empty%29%20log%20files%20after%20rotating%20old%20ones%0Acreate%0A%0A%23%20use%20date%20as%20a%20suffix%20of%20the%20rotated%20file%0Adateext%0A%0A%23%20uncomment%20this%20if%20you%20want%20your%20log%20files%20compressed%0A%23compress%0A%0A%23%20RPM%20packages%20drop%20log%20rotation%20information%20into%20this%20directory%0Ainclude%20/etc/logrotate.d%0A%0A%23%20system-specific%20logs%20may%20be%20also%20be%20configured%20here. }}
        mode: 0644
        path: /etc/logrotate.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ensure_logrotate_activated:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ensure_logrotate_activated_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_timer_logrotate_enabled" selected="false" severity="medium">
              <xccdf-1.2:title>Enable logrotate Timer</xccdf-1.2:title>
              <xccdf-1.2:description>
The <html:code>logrotate</html:code> timer can be enabled with the following command:
<html:pre>$ sudo systemctl enable logrotate.timer</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">The Systemd unit <html:code>logrotate.timer</html:code> does not exist in AlmaLinux OS 8. The rule <html:code>ensure_logrotate_activated</html:code> is suggested instead.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R71</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.5</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Log files that are not properly rotated run the risk of growing so large
that they fill up the /var/log partition. Valuable logging information could be lost
if the /var/log partition becomes full.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_logrotate"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="timer_logrotate_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q logrotate; }; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'logrotate.timer'
fi
"$SYSTEMCTL_EXEC" enable 'logrotate.timer'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="timer_logrotate_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - PCI-DSSv4-10.5
  - PCI-DSSv4-10.5.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - timer_logrotate_enabled

- name: Enable timer logrotate
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable timer logrotate
    ansible.builtin.systemd:
      name: logrotate.timer
      enabled: 'yes'
      state: started
    when:
    - '"logrotate" in ansible_facts.packages'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"logrotate" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - PCI-DSSv4-10.5
  - PCI-DSSv4-10.5.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - timer_logrotate_enabled
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-timer_logrotate_enabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-timer_logrotate_enabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_rsyslog_accepting_remote_messages">
            <xccdf-1.2:title>Configure rsyslogd to Accept Remote Messages If Acting as a Log Server</xccdf-1.2:title>
            <xccdf-1.2:description>By default, <html:code>rsyslog</html:code> does not listen over the network
for log messages. If needed, modules can be enabled to allow
the rsyslog daemon to receive messages from other systems and for the system
thus to act as a log server.
If the system is not a log server, then lines concerning these modules
should remain commented out.
<html:br/><html:br/></xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_syslogng_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure syslog-ng is Installed</xccdf-1.2:title>
              <xccdf-1.2:description>syslog-ng can be installed in replacement of rsyslog.
The <html:code>syslog-ng-core</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install syslog-ng-core</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The syslog-ng-core package provides the syslog-ng daemon, which provides
system logging services.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_syslogng_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "syslog-ng" ; then
    yum install -y "syslog-ng"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_syslogng_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_syslogng_installed

- name: Ensure syslog-ng is installed
  ansible.builtin.package:
    name: syslog-ng
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_syslogng_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_syslogng_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_syslog-ng

class install_syslog-ng {
  package { 'syslog-ng':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_syslogng_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=syslog-ng
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_syslogng_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "syslog-ng"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_syslogng_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install syslog-ng
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_syslogng_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install syslog-ng
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_syslogng_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_syslogng_enabled" selected="false" severity="medium">
              <xccdf-1.2:title>Enable syslog-ng Service</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>syslog-ng</html:code> service (in replacement of rsyslog) provides syslog-style logging by default on Debian.

The <html:code>syslog-ng</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable syslog-ng.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-4(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>syslog-ng</html:code> service must be running in order to provide
logging services, which are essential to system administration.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_syslogng_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'syslog-ng.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'syslog-ng.service'
fi
"$SYSTEMCTL_EXEC" enable 'syslog-ng.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_syslogng_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-4(1)
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_syslogng_enabled

- name: Enable syslog-ng Service - Enable service syslog-ng
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable syslog-ng Service - Enable Service syslog-ng
    ansible.builtin.systemd:
      name: syslog-ng
      enabled: true
      state: started
      masked: false
    when:
    - '"syslog-ng" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-4(1)
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_syslogng_enabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_syslogng_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_syslog-ng

class enable_syslog-ng {
  service {'syslog-ng':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_syslogng_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["syslog-ng"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_syslogng_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable syslog-ng
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_syslogng_enabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_syslogng_enabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rsyslog_accept_remote_messages_tcp" selected="false" severity="unknown">
              <xccdf-1.2:title>Enable rsyslog to Accept Messages via TCP, if Acting As Log Server</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>rsyslog</html:code> daemon should not accept remote messages
unless the system acts as a log server.
If the system needs to act as a central log server, add the following lines to
<html:code>/etc/rsyslog.conf</html:code> to enable reception of messages over TCP:
<html:pre>$ModLoad imtcp
$InputTCPServerRun 514</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-6(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-6(4)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If the system needs to act as a log server, this ensures that it can receive
messages over a reliable TCP connection.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rsyslog_accept_remote_messages_udp" selected="false" severity="unknown">
              <xccdf-1.2:title>Enable rsyslog to Accept Messages via UDP, if Acting As Log Server</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>rsyslog</html:code> daemon should not accept remote messages
unless the system acts as a log server.
If the system needs to act as a central log server, add the following lines to
<html:code>/etc/rsyslog.conf</html:code> to enable reception of messages over UDP:
<html:pre>$ModLoad imudp
$UDPServerRun 514</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-6(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-6(4)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Many devices, such as switches, routers, and other Unix-like systems, may only support
the traditional syslog transmission over UDP. If the system must act as a log server,
this enables it to receive their messages as well.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rsyslog_nolisten" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure rsyslog Does Not Accept Remote Messages Unless Acting As Log Server</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>rsyslog</html:code> daemon should not accept remote messages unless the system acts as a log
server. To ensure that it is not listening on the network, ensure any of the following lines
are <html:i>not</html:i> found in <html:code>rsyslog</html:code> configuration files.

If using legacy syntax:
<html:pre>$ModLoad imtcp
$InputTCPServerRun <html:i>port</html:i>
$ModLoad imudp
$UDPServerRun <html:i>port</html:i>
$ModLoad imrelp
$InputRELPServerRun <html:i>port</html:i></html:pre>

If using RainerScript syntax:
<html:pre>module(load="imtcp")
module(load="imudp")
input(type="imtcp" port="514")
input(type="imudp" port="514")
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0988</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1405</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.2.2.7</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Any process which receives messages from the network incurs some risk of receiving malicious
messages. This risk can be eliminated for rsyslog by configuring it not to listen on the
network.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="rsyslog_nolisten" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

legacy_regex='^\s*\$(((Input(TCP|RELP)|UDP)ServerRun)|ModLoad\s+(imtcp|imudp|imrelp))'
rainer_regex='^\s*(module|input)\((load|type)="(imtcp|imudp)".*$'

readarray -t legacy_targets &lt; &lt;(grep -l -E -r "${legacy_regex[@]}" /etc/rsyslog.conf /etc/rsyslog.d/)
readarray -t rainer_targets &lt; &lt;(grep -l -E -r "${rainer_regex[@]}" /etc/rsyslog.conf /etc/rsyslog.d/)

config_changed=false
if [ ${#legacy_targets[@]} -gt 0 ]; then
    for target in "${legacy_targets[@]}"; do
        sed -E -i "/$legacy_regex/ s/^/# /" "$target"
    done
    config_changed=true
fi

if [ ${#rainer_targets[@]} -gt 0 ]; then
    for target in "${rainer_targets[@]}"; do
        sed -E -i "/$rainer_regex/ s/^/# /" "$target"
    done
    config_changed=true
fi

if $config_changed; then
    systemctl restart rsyslog.service
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="rsyslog_nolisten" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_nolisten

- name: Ensure rsyslog Does Not Accept Remote Messages Unless Acting As Log Server
    - Define Rsyslog Config Lines Regex in Legacy Syntax
  ansible.builtin.set_fact:
    rsyslog_listen_legacy_regex: ^\s*\$(((Input(TCP|RELP)|UDP)ServerRun)|ModLoad\s+(imtcp|imudp|imrelp))
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_nolisten

- name: Ensure rsyslog Does Not Accept Remote Messages Unless Acting As Log Server
    - Search for Legacy Config Lines in Rsyslog Main Config File
  ansible.builtin.find:
    paths: /etc
    pattern: rsyslog.conf
    contains: '{{ rsyslog_listen_legacy_regex }}'
  register: rsyslog_listen_legacy_main_file
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_nolisten

- name: Ensure rsyslog Does Not Accept Remote Messages Unless Acting As Log Server
    - Search for Legacy Config Lines in Rsyslog Include Files
  ansible.builtin.find:
    paths: /etc/rsyslog.d/
    pattern: '*.conf'
    contains: '{{ rsyslog_listen_legacy_regex }}'
  register: rsyslog_listen_legacy_include_files
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_nolisten

- name: Ensure rsyslog Does Not Accept Remote Messages Unless Acting As Log Server
    - Assemble List of Config Files With Listen Lines in Legacy Syntax
  ansible.builtin.set_fact:
    rsyslog_legacy_remote_listen_files: '{{ rsyslog_listen_legacy_main_file.files
      | map(attribute=''path'') | list + rsyslog_listen_legacy_include_files.files
      | map(attribute=''path'') | list }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_nolisten

- name: Ensure rsyslog Does Not Accept Remote Messages Unless Acting As Log Server
    - Comment Listen Config Lines Wherever Defined Using Legacy Syntax
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: '{{ rsyslog_listen_legacy_regex }}'
    replace: '# \1'
  loop: '{{ rsyslog_legacy_remote_listen_files }}'
  register: rsyslog_listen_legacy_comment
  when:
  - '"kernel" in ansible_facts.packages'
  - rsyslog_legacy_remote_listen_files | length &gt; 0
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_nolisten

- name: Ensure rsyslog Does Not Accept Remote Messages Unless Acting As Log Server
    - Define Rsyslog Config Lines Regex in RainerScript Syntax
  ansible.builtin.set_fact:
    rsyslog_listen_rainer_regex: ^\s*(module|input)\((load|type)="(imtcp|imudp)".*$
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_nolisten

- name: Ensure rsyslog Does Not Accept Remote Messages Unless Acting As Log Server
    - Search for RainerScript Config Lines in Rsyslog Main Config File
  ansible.builtin.find:
    paths: /etc
    pattern: rsyslog.conf
    contains: '{{ rsyslog_listen_rainer_regex }}'
  register: rsyslog_rainer_remote_main_file
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_nolisten

- name: Ensure rsyslog Does Not Accept Remote Messages Unless Acting As Log Server
    - Search for RainerScript Config Lines in Rsyslog Include Files
  ansible.builtin.find:
    paths: /etc/rsyslog.d/
    pattern: '*.conf'
    contains: '{{ rsyslog_listen_rainer_regex }}'
  register: rsyslog_rainer_remote_include_files
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_nolisten

- name: Ensure rsyslog Does Not Accept Remote Messages Unless Acting As Log Server
    - Assemble List of Config Files With Listen Lines in RainerScript
  ansible.builtin.set_fact:
    rsyslog_rainer_remote_listen_files: '{{ rsyslog_rainer_remote_main_file.files
      | map(attribute=''path'') | list + rsyslog_rainer_remote_include_files.files
      | map(attribute=''path'') | list }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_nolisten

- name: Ensure rsyslog Does Not Accept Remote Messages Unless Acting As Log Server
    - Comment Listen Config Lines Wherever Defined Using RainerScript
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: '{{ rsyslog_listen_rainer_regex }}'
    replace: '# \1'
  loop: '{{ rsyslog_rainer_remote_listen_files }}'
  register: rsyslog_listen_rainer_comment
  when:
  - '"kernel" in ansible_facts.packages'
  - rsyslog_rainer_remote_listen_files | length &gt; 0
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_nolisten

- name: Ensure rsyslog Does Not Accept Remote Messages Unless Acting As Log Server
    - Restart Rsyslog if Any Line Were Commented Out
  ansible.builtin.service:
    name: rsyslog
    state: restarted
  when:
  - '"kernel" in ansible_facts.packages'
  - rsyslog_listen_legacy_comment is changed or rsyslog_listen_rainer_comment is changed
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_nolisten
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rsyslog_nolisten:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rsyslog_nolisten_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_rsyslog_sending_messages">
            <xccdf-1.2:title>Rsyslog Logs Sent To Remote Host</xccdf-1.2:title>
            <xccdf-1.2:description>If system logs are to be useful in detecting malicious
activities, it is necessary to send logs to a remote server. An
intruder who has compromised the root account on a system may
delete the log entries which indicate that the system was attacked
before they are seen by an administrator.
<html:br/><html:br/>
However, it is recommended that logs be stored on the local
host in addition to being sent to the loghost, especially if
<html:code>rsyslog</html:code> has been configured to use the UDP protocol to send
messages over a network. UDP does not guarantee reliable delivery,
and moderately busy sites will lose log messages occasionally,
especially in periods of high traffic which may be the result of an
attack. In addition, remote <html:code>rsyslog</html:code> messages are not
authenticated in any way by default, so it is easy for an attacker to
introduce spurious messages to the central log server. Also, some
problems cause loss of network connectivity, which will prevent the
sending of messages to the central server. For all of these reasons, it is
better to store log messages both centrally and on each host, so
that they can be correlated if necessary.</xccdf-1.2:description>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_rsyslog_remote_loghost_address" interactive="true" type="string">
              <xccdf-1.2:title>Remote Log Server</xccdf-1.2:title>
              <xccdf-1.2:description>Specify an URI or IP address of a remote host where the log messages will be sent and stored.</xccdf-1.2:description>
              <xccdf-1.2:value>logcollector</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rsyslog_remote_loghost" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Logs Sent To Remote Host</xccdf-1.2:title>
              <xccdf-1.2:description>To configure rsyslog to send logs to a remote log server,
open <html:code>/etc/rsyslog.conf</html:code> and read and understand the last section of the file,
which describes the multiple directives necessary to activate remote
logging.
Along with these other directives, the system can be configured
to forward its logs to a particular log server by
adding or correcting one of the following lines,
substituting <html:code><html:i><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_rsyslog_remote_loghost_address" use="legacy"/></html:i></html:code> appropriately.
The choice of protocol depends on the environment of the system;
although TCP and RELP provide more reliable message delivery,
they may not be supported in all environments.
<html:br/>
To use UDP for log message delivery:
<html:pre>*.* @<html:i><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_rsyslog_remote_loghost_address" use="legacy"/></html:i></html:pre>
<html:br/>
Or in RainerScript:
<html:pre>*.* action(type="omfwd" ... target="<html:i><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_rsyslog_remote_loghost_address" use="legacy"/></html:i>" protocol="udp")</html:pre>
<html:br/>
To use TCP for log message delivery:
<html:pre>*.* @@<html:i><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_rsyslog_remote_loghost_address" use="legacy"/></html:i></html:pre>
<html:br/>
Or in RainerScript:
<html:pre>*.* action(type="omfwd" ... target="<html:i><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_rsyslog_remote_loghost_address" use="legacy"/></html:i>" protocol="tcp")</html:pre>
<html:br/>
To use RELP for log message delivery:
<html:pre>*.* :omrelp:<html:i><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_rsyslog_remote_loghost_address" use="legacy"/></html:i></html:pre>
<html:br/>
Or in RainerScript:
<html:pre>*.* action(type="omfwd" ... target="<html:i><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_rsyslog_remote_loghost_address" use="legacy"/></html:i>" protocol="relp")</html:pre>
<html:br/>
There must be a resolvable DNS CNAME or Alias record set to "<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_rsyslog_remote_loghost_address" use="legacy"/>" for logs to be sent correctly to the centralized logging utility.</xccdf-1.2:description>
              <xccdf-1.2:warning category="functionality">It is important to configure queues in case the client is sending log
messages to a remote server. If queues are not configured,
the system will stop functioning when the connection
to the remote server is not available. Please consult Rsyslog
documentation for more information about configuration of queues. The
example configuration which should go into <html:code>/etc/rsyslog.conf</html:code>
can look like the following lines:
<html:pre>
$ActionQueueType LinkedList
$ActionQueueFileName queuefilename
$ActionQueueMaxDiskSpace 1g
$ActionQueueSaveOnShutdown on
$ActionResumeRetryCount -1
</html:pre>
Or if using Rainer Script syntax, it could be:
<html:pre>*.* action(type="omfwd" queue.type="linkedlist" queue.filename="example_fwd" action.resumeRetryCount="-1" queue.saveOnShutdown="on" target="example.com" port="30514" protocol="tcp")</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(B)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(6)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(8)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.314(a)(2)(i)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.314(a)(2)(iii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-4(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000479-GPOS-00224</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000342-GPOS-00133</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R71</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0988</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1405</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030690</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230479r958754_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>A log server (loghost) receives syslog messages from one or more
systems. This data can be used as an additional log source in the event a
system is compromised and its local logs are suspect. Forwarding log messages
to a remote loghost also provides system administrators with a centralized
place to view the status of multiple hosts within the enterprise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="rsyslog_remote_loghost" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

rsyslog_remote_loghost_address='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_rsyslog_remote_loghost_address" use="legacy"/>'


# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^\*\.\*")

# shellcheck disable=SC2059
printf -v formatted_output "%s %s" "$stripped_key" "@@$rsyslog_remote_loghost_address"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^\*\.\*\\&gt;" "/etc/rsyslog.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^\*\.\*\\&gt;.*/$escaped_formatted_output/gi" "/etc/rsyslog.conf"
else
    if [[ -s "/etc/rsyslog.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/rsyslog.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/rsyslog.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/rsyslog.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="rsyslog_remote_loghost" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030690
  - NIST-800-53-AU-4(1)
  - NIST-800-53-AU-9(2)
  - NIST-800-53-CM-6(a)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - rsyslog_remote_loghost
- name: XCCDF Value rsyslog_remote_loghost_address # promote to variable
  set_fact:
    rsyslog_remote_loghost_address: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_rsyslog_remote_loghost_address" use="legacy"/>
  tags:
    - always

- name: Set rsyslog remote loghost
  ansible.builtin.lineinfile:
    dest: /etc/rsyslog.conf
    regexp: ^\*\.\*
    line: '*.* @@{{ rsyslog_remote_loghost_address }}'
    create: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030690
  - NIST-800-53-AU-4(1)
  - NIST-800-53-AU-9(2)
  - NIST-800-53-CM-6(a)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - rsyslog_remote_loghost
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rsyslog_remote_loghost:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rsyslog_remote_tls" selected="false" severity="medium">
              <xccdf-1.2:title>Configure TLS for rsyslog remote logging</xccdf-1.2:title>
              <xccdf-1.2:description>Configure <html:code>rsyslog</html:code> to use Transport Layer
Security (TLS) support for logging to remote server
for the Forwarding Output Module in <html:code>/etc/rsyslog.conf</html:code>
using action. You can use the following command:
<html:pre>echo 'action(type="omfwd" protocol="tcp" Target="&lt;remote system&gt;" port="6514"
    StreamDriver="gtls" StreamDriverMode="1" StreamDriverAuthMode="x509/name" streamdriver.CheckExtendedKeyPurpose="on")' &gt;&gt; /etc/rsyslog.conf
</html:pre>
Replace the <html:code>&lt;remote system&gt;</html:code> in the above command with an IP address or a host name of the remote logging server.</xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000120-GPOS-00061</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R71</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0988</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1405</xccdf-1.2:reference>
              <xccdf-1.2:rationale>For protection of data being logged, the connection to the
remote logging server needs to be authenticated and encrypted.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="rsyslog_remote_tls" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

rsyslog_remote_loghost_address='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_rsyslog_remote_loghost_address" use="legacy"/>'

params_to_add_if_missing=("protocol" "target" "port" "StreamDriver" "StreamDriverMode" "StreamDriverAuthMode" "streamdriver.CheckExtendedKeyPurpose")
values_to_add_if_missing=("tcp" "$rsyslog_remote_loghost_address" "6514" "gtls" "1" "x509/name" "on")
params_to_replace_if_wrong_value=("protocol" "StreamDriver" "StreamDriverMode" "StreamDriverAuthMode" "streamdriver.CheckExtendedKeyPurpose")
values_to_replace_if_wrong_value=("tcp" "gtls" "1" "x509/name" "on")

files_containing_omfwd=("$(grep -ilE '^[^#]*\s*action\s*\(\s*type\s*=\s*"omfwd".*' /etc/rsyslog.conf /etc/rsyslog.d/*.conf)")
if [ -n "${files_containing_omfwd[*]}" ]; then
    for file in "${files_containing_omfwd[@]}"; do
        for ((i=0; i&lt;${#params_to_replace_if_wrong_value[@]}; i++)); do
            sed -i -E -e 'H;$!d;x;s/^\n//' -e "s|(\s*action\s*\(\s*type\s*=\s*[\"]omfwd[\"].*?)${params_to_replace_if_wrong_value[$i]}\s*=\s*[\"]\S*[\"](.*\))|\1${params_to_replace_if_wrong_value[$i]}=\"${values_to_replace_if_wrong_value[$i]}\"\2|gI" "$file"
        done
        for ((i=0; i&lt;${#params_to_add_if_missing[@]}; i++)); do
            if ! grep -qPzi "(?s)\s*action\s*\(\s*type\s*=\s*[\"]omfwd[\"].*?${params_to_add_if_missing[$i]}.*?\).*" "$file"; then
                sed -i -E -e 'H;$!d;x;s/^\n//' -e "s|(\s*action\s*\(\s*type\s*=\s*[\"]omfwd[\"])|\1\n${params_to_add_if_missing[$i]}=\"${values_to_add_if_missing[$i]}\"|gI" "$file"
            fi
        done
    done
else
    echo "action(type=\"omfwd\" protocol=\"tcp\" Target=\"$rsyslog_remote_loghost_address\" port=\"6514\" StreamDriver=\"gtls\" StreamDriverMode=\"1\" StreamDriverAuthMode=\"x509/name\" streamdriver.CheckExtendedKeyPurpose=\"on\")"  &gt;&gt; /etc/rsyslog.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="rsyslog_remote_tls" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_remote_tls
- name: XCCDF Value rsyslog_remote_loghost_address # promote to variable
  set_fact:
    rsyslog_remote_loghost_address: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_rsyslog_remote_loghost_address" use="legacy"/>
  tags:
    - always

- name: 'Configure TLS for rsyslog remote logging: search for omfwd action directive
    in rsyslog include files'
  ansible.builtin.find:
    paths: /etc/rsyslog.d/
    pattern: '*.conf'
    contains: ^\s*action\s*\(\s*type\s*=\s*"omfwd".*
  register: rsyslog_includes_with_directive
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_remote_tls

- name: 'Configure TLS for rsyslog remote logging: search for omfwd action directive
    in rsyslog main config file'
  ansible.builtin.find:
    paths: /etc
    pattern: rsyslog.conf
    contains: ^\s*action\s*\(\s*type\s*=\s*"omfwd".*
  register: rsyslog_main_file_with_directive
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_remote_tls

- name: 'Configure TLS for rsyslog remote logging: declare Rsyslog option parameters
    to be inserted if entirely missing'
  ansible.builtin.set_fact:
    rsyslog_parameters_to_add_if_missing:
    - protocol
    - target
    - port
    - StreamDriver
    - StreamDriverMode
    - StreamDriverAuthMode
    - streamdriver.CheckExtendedKeyPurpose
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_remote_tls

- name: 'Configure TLS for rsyslog remote logging: declare Rsyslog option values to
    be inserted if entirely missing'
  ansible.builtin.set_fact:
    rsyslog_values_to_add_if_missing:
    - tcp
    - '{{ rsyslog_remote_loghost_address }}'
    - '6514'
    - gtls
    - '1'
    - x509/name
    - 'on'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_remote_tls

- name: 'Configure TLS for rsyslog remote logging: declare Rsyslog option parameters
    to be replaced if defined with wrong values'
  ansible.builtin.set_fact:
    rsyslog_parameters_to_replace_if_wrong_value:
    - protocol
    - StreamDriver
    - StreamDriverMode
    - StreamDriverAuthMode
    - streamdriver.CheckExtendedKeyPurpose
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_remote_tls

- name: 'Configure TLS for rsyslog remote logging: declare Rsyslog option values to
    be replaced when having wrong value'
  ansible.builtin.set_fact:
    rsyslog_values_to_replace_if_wrong_value:
    - tcp
    - gtls
    - '1'
    - x509/name
    - 'on'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_remote_tls

- name: 'Configure TLS for rsyslog remote logging: assemble list of files with existing
    directives'
  ansible.builtin.set_fact:
    rsyslog_files: '{{ rsyslog_includes_with_directive.files | map(attribute=''path'')
      | list + rsyslog_main_file_with_directive.files | map(attribute=''path'') |
      list }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_remote_tls

- name: 'Configure TLS for rsyslog remote logging: try to fix existing directives'
  block:

  - name: 'Configure TLS for rsyslog remote logging: Fix existing omfwd directives
      by adjusting the value'
    ansible.builtin.replace:
      path: '{{ item[0] }}'
      regexp: (?i)^(\s*action\s*\(\s*type\s*=\s*"omfwd"[\s\S]*)({{ item[1][0] | regex_escape()
        }}\s*=\s*"\S*")([\s\S]*\))$
      replace: \1{{ item[1][0] }}="{{ item[1][1] }}"\3
    loop: '{{ rsyslog_files | product (rsyslog_parameters_to_replace_if_wrong_value
      | zip(rsyslog_values_to_replace_if_wrong_value)) | list }}'

  - name: 'Configure TLS for rsyslog remote logging: Fix existing omfwd directives
      by adding parameter and value'
    ansible.builtin.replace:
      path: '{{ item[0] }}'
      regexp: (?i)^(\s*action\s*\(\s*type\s*=\s*"omfwd"(?:[\s\S](?!{{ item[1][0] |
        regex_escape() }}))*.)(\))$
      replace: \1 {{ item[1][0] }}="{{ item[1][1] }}" \2
    loop: '{{ rsyslog_files | product (rsyslog_parameters_to_add_if_missing | zip(rsyslog_values_to_add_if_missing))
      | list }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - rsyslog_includes_with_directive.matched or rsyslog_main_file_with_directive.matched
  tags:
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_remote_tls

- name: 'Configure TLS for rsyslog remote logging: Add missing rsyslog directive'
  ansible.builtin.lineinfile:
    dest: /etc/rsyslog.conf
    line: action(type="omfwd" protocol="tcp" Target="{{ rsyslog_remote_loghost_address
      }}" port="6514" StreamDriver="gtls" StreamDriverMode="1" StreamDriverAuthMode="x509/name"
      streamdriver.CheckExtendedKeyPurpose="on")
    create: true
  when:
  - '"kernel" in ansible_facts.packages'
  - not rsyslog_includes_with_directive.matched and not rsyslog_main_file_with_directive.matched
  tags:
  - NIST-800-53-AU-9(3)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rsyslog_remote_tls
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rsyslog_remote_tls:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rsyslog_remote_tls_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rsyslog_remote_tls_cacert" selected="false" severity="medium">
              <xccdf-1.2:title>Configure CA certificate for rsyslog remote logging</xccdf-1.2:title>
              <xccdf-1.2:description>Configure CA certificate for <html:code>rsyslog</html:code> logging
to remote server using Transport Layer Security (TLS)
using correct path for the <html:code>DefaultNetstreamDriverCAFile</html:code>
global option in <html:code>/etc/rsyslog.conf</html:code>, for example with the following command:
<html:pre>echo 'global(DefaultNetstreamDriverCAFile="/etc/pki/tls/cert.pem")' &gt;&gt; /etc/rsyslog.conf</html:pre>
Replace the <html:code>/etc/pki/tls/cert.pem</html:code> in the above command with the path to the file with CA certificate generated for the purpose of remote logging.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Automatic remediation is not available as each organization has unique requirements. </xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R71</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0988</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1405</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The CA certificate needs to be set or <html:code>rsyslog.service</html:code>
fails to start with
<html:pre>error: ca certificate is not set, cannot continue</html:pre></xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rsyslog_remote_tls_cacert:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rsyslog_remote_tls_cacert_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_network">
          <xccdf-1.2:title>Network Configuration and Firewalls</xccdf-1.2:title>
          <xccdf-1.2:description>Most systems must be connected to a network of some
sort, and this brings with it the substantial risk of network
attack. This section discusses the security impact of decisions
about networking which must be made when configuring a system.
<html:br/><html:br/>
This section also discusses firewalls, network access
controls, and other network security frameworks, which allow
system-level rules to be written that can limit an attackers' ability
to connect to your system. These rules can specify that network
traffic should be allowed or denied from certain IP addresses,
hosts, and networks. The rules can also specify which of the
system's network services are available to particular hosts or
networks.</xccdf-1.2:description>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_network_configure_name_resolution" selected="false" severity="medium">
            <xccdf-1.2:title>Configure Multiple DNS Servers in /etc/resolv.conf</xccdf-1.2:title>
            <xccdf-1.2:description>
Multiple Domain Name System (DNS) Servers should be configured
in <html:code>/etc/resolv.conf</html:code>. This provides redundant name resolution services
in the event that a domain server crashes. To configure the system to contain
as least <html:code>2</html:code> DNS servers, add a corresponding <html:code>nameserver
<html:i>ip_address</html:i></html:code> entry in <html:code>/etc/resolv.conf</html:code> for each DNS
server where <html:i>ip_address</html:i> is the IP address of a valid DNS server.
For example:
<html:pre>search example.com
nameserver 192.168.0.1
nameserver 192.168.0.2</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">This rule doesn't come with a remediation, the IP addresses of local authoritative name servers need to be added by the administrator.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-20(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010680</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230316r1044801_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>To provide availability for name resolution services, multiple redundant
name servers are mandated. A failure in name resolution could lead to the
failure of security functions requiring name resolution, which may include
time synchronization, centralized authentication, and remote system logging.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-network_configure_name_resolution:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-network_configure_name_resolution_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_network_disable_ddns_interfaces" selected="false" severity="medium">
            <xccdf-1.2:title>Disable Client Dynamic DNS Updates</xccdf-1.2:title>
            <xccdf-1.2:description>Dynamic DNS allows clients to dynamically update their own DNS records.
The updates are transmitted by unencrypted means which can reveal information
to a potential malicious user. If the system does not require Dynamic DNS,
remove all <html:code>DHCP_HOSTNAME</html:code> references from the
<html:code>/etc/sysconfig/network-scripts/ifcfg-<html:i>interface</html:i></html:code> scripts. If
<html:code>dhclient</html:code> is used, remove all <html:code>send host-name <html:i>hostname</html:i></html:code>
references from the <html:code>/etc/dhclient.conf</html:code> configuration file and/or any
reference from the <html:code>/etc/dhcp</html:code> directory.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Dynamic DNS updates transmit unencrypted information about a system
including its name and address and should not be used unless needed.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-network_disable_ddns_interfaces:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-network_disable_ddns_interfaces_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_network_disable_zeroconf" selected="false" severity="unknown">
            <xccdf-1.2:title>Disable Zeroconf Networking</xccdf-1.2:title>
            <xccdf-1.2:description>Zeroconf networking allows the system to assign itself an IP
address and engage in IP communication without a statically-assigned address or
even a DHCP server. Automatic address assignment via Zeroconf (or DHCP) is not
recommended. To disable Zeroconf automatic route assignment in the 169.254.0.0
subnet, add or correct the following line in <html:code>/etc/sysconfig/network</html:code>:
<html:pre>NOZEROCONF=yes</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Zeroconf addresses are in the network 169.254.0.0. The networking
scripts add entries to the system's routing table for these addresses. Zeroconf
address assignment commonly occurs when the system is configured to use DHCP
but fails to receive an address assignment from the DHCP server.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="network_disable_zeroconf" system="urn:xccdf:fix:script:sh">echo "NOZEROCONF=yes" &gt;&gt; /etc/sysconfig/network
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-network_disable_zeroconf:def:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_network_nmcli_permissions" selected="false" severity="medium">
            <xccdf-1.2:title>Prevent non-Privileged Users from Modifying Network Interfaces using nmcli</xccdf-1.2:title>
            <xccdf-1.2:description>By default, non-privileged users are given permissions to modify networking
interfaces and configurations using the <html:code>nmcli</html:code> command. Non-privileged
users should not be making configuration changes to network configurations. To
ensure that non-privileged users do not have permissions to make changes to the
network configuration using <html:code>nmcli</html:code>, create the following configuration in
<html:code>/etc/polkit-1/localauthority/20-org.d/10-nm-harden-access.pkla</html:code>:
<html:pre>
[Disable General User Access to NetworkManager]
Identity=default
Action=org.freedesktop.NetworkManager.*
ResultAny=no
ResultInactive=no
ResultActive=auth_admin
</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0418</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1055</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1402</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Allowing non-privileged users to make changes to network settings can allow
untrusted access, prevent system availability, and/or can lead to a compromise or
attack.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#package_polkit"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="network_nmcli_permissions" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q polkit; then

if ! rpm -q --quiet "polkit-pkla-compat" ; then
    yum install -y "polkit-pkla-compat"
fi
printf "[Disable General User Access to NetworkManager]\nIdentity=default\nAction=org.freedesktop.NetworkManager.*\nResultAny=no\nResultInactive=no\nResultActive=auth_admin\n" &gt; /etc/polkit-1/localauthority/20-org.d/10-nm-harden-access.pkla

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="network_nmcli_permissions" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.16
  - NIST-800-53-AC-18(4)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.8
  - low_complexity
  - low_disruption
  - medium_severity
  - network_nmcli_permissions
  - no_reboot_needed
  - restrict_strategy

- name: Prevent non-Privileged Users from Modifying Network Interfaces using nmcli
    - Ensure polkit-pkla-compat is installed
  ansible.builtin.package:
    name: polkit-pkla-compat
    state: present
  when: '"polkit" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.16
  - NIST-800-53-AC-18(4)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.8
  - low_complexity
  - low_disruption
  - medium_severity
  - network_nmcli_permissions
  - no_reboot_needed
  - restrict_strategy

- name: Prevent non-Privileged Users from Modifying Network Interfaces using nmcli
    - Ensure non-privileged users do not have access to nmcli
  community.general.ini_file:
    path: /etc/polkit-1/localauthority/20-org.d/10-nm-harden-access.pkla
    section: Disable General User Access to NetworkManager
    option: '{{ item.option }}'
    value: '{{ item.value }}'
    no_extra_spaces: true
    create: true
  loop:
  - option: Identity
    value: default
  - option: Action
    value: org.freedesktop.NetworkManager.*
  - option: ResultAny
    value: 'no'
  - option: ResultInactive
    value: 'no'
  - option: ResultActive
    value: auth_admin
  when: '"polkit" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.16
  - NIST-800-53-AC-18(4)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.8
  - low_complexity
  - low_disruption
  - medium_severity
  - network_nmcli_permissions
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-network_nmcli_permissions:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-network_nmcli_permissions_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_network_sniffer_disabled" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure System is Not Acting as a Network Sniffer</xccdf-1.2:title>
            <xccdf-1.2:description>The system should not be acting as a network sniffer, which can
capture all traffic on the network to which it is connected. Run the following
to determine if any interface is running in promiscuous mode:
<html:pre>$ ip link | grep PROMISC</html:pre>
Promiscuous mode of an interface can be disabled with the following command:
<html:pre>$ sudo ip link set dev <html:code>device_name</html:code> multicast off promisc off</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI09.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI09.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI09.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS04.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MA-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.MA-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040330</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230554r1017316_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Network interfaces in promiscuous mode allow for the capture of all network traffic
visible to the system. If unauthorized individuals can access these applications, it
may allow them to collect information such as logon IDs, passwords, and key exchanges
between systems.
<html:br/><html:br/>
If the system is being used to perform a network troubleshooting function, the use of these
tools must be documented with the Information Systems Security Manager (ISSM) and restricted
to only authorized personnel.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#machine"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="network_sniffer_disabled" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( [ ! -f /.dockerenv ] &amp;&amp; [ ! -f /run/.containerenv ] ); then

for interface in $(ip -o link show | cut -d ":" -f 2); do
    ip link set dev $interface multicast off promisc off
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="network_sniffer_disabled" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Ensure System is Not Acting as a Network Sniffer - Gather network interfaces
  ansible.builtin.command:
    cmd: ip -o link show
  register: network_interfaces
  when: ansible_virtualization_type not in ["docker", "lxc", "openvz", "podman", "container"]
  tags:
  - DISA-STIG-RHEL-08-040330
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(2)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MA-3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.5
  - low_complexity
  - low_disruption
  - medium_severity
  - network_sniffer_disabled
  - no_reboot_needed
  - restrict_strategy

- name: Ensure System is Not Acting as a Network Sniffer - Disable promiscuous mode
  ansible.builtin.command:
    cmd: ip link set dev {{ (item.split(':')[1] | trim).split('@')[0] }} multicast
      off promisc off
  loop: '{{ network_interfaces.stdout_lines }}'
  when:
  - ansible_virtualization_type not in ["docker", "lxc", "openvz", "podman", "container"]
  - network_interfaces.stdout_lines is defined and item.split(':') | length &gt;= 3
  tags:
  - DISA-STIG-RHEL-08-040330
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(2)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MA-3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.5
  - low_complexity
  - low_disruption
  - medium_severity
  - network_sniffer_disabled
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-network_sniffer_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-network_sniffer_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_network-firewalld">
            <xccdf-1.2:title>firewalld</xccdf-1.2:title>
            <xccdf-1.2:description>The dynamic firewall daemon <html:code>firewalld</html:code> provides a
dynamically managed firewall with support for network “zones” to assign
a level of trust to a network and its associated connections and interfaces.
It has support for IPv4 and IPv6 firewall settings. It supports Ethernet
bridges and has a separation of runtime and permanent configuration options.
It also has an interface for services or applications to add firewall rules
directly.
<html:br/>
A graphical configuration tool, <html:code>firewall-config</html:code>, is used to configure
<html:code>firewalld</html:code>, which in turn uses <html:code>iptables</html:code> tool to communicate
with <html:code>Netfilter</html:code> in the kernel which implements packet filtering.
<html:br/>
The firewall service provided by <html:code>firewalld</html:code> is dynamic rather than
static because changes to the configuration can be made at anytime and are
immediately implemented. There is no need to save or apply the changes. No
unintended disruption of existing network connections occurs as no part of
the firewall has to be reloaded.</xccdf-1.2:description>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firewalld-backend" selected="false" severity="medium">
              <xccdf-1.2:title>Configure Firewalld to Use the Nftables Backend</xccdf-1.2:title>
              <xccdf-1.2:description>Firewalld can be configured with many backends, such as nftables.</xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000420-GPOS-00186</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">4.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040150</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230525r958902_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Nftables is modern kernel module for controlling network connections coming into a system.
Utilizing the limit statement in "nftables" can help to mitigate DoS attacks.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_firewalld"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="firewalld-backend" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q firewalld; }; then

if [ -e "/etc/firewalld/firewalld.conf" ] ; then
    
    LC_ALL=C sed -i "/^\s*FirewallBackend\s*=\s*/d" "/etc/firewalld/firewalld.conf"
else
    touch "/etc/firewalld/firewalld.conf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/firewalld/firewalld.conf"

cp "/etc/firewalld/firewalld.conf" "/etc/firewalld/firewalld.conf.bak"
# Insert before the line matching the regex '^#\s*FirewallBackend'.
line_number="$(LC_ALL=C grep -n "^#\s*FirewallBackend" "/etc/firewalld/firewalld.conf.bak" | LC_ALL=C sed 's/:.*//g')"
if [ -z "$line_number" ]; then
    # There was no match of '^#\s*FirewallBackend', insert at
    # the end of the file.
    printf '%s\n' "FirewallBackend=nftables" &gt;&gt; "/etc/firewalld/firewalld.conf"
else
    head -n "$(( line_number - 1 ))" "/etc/firewalld/firewalld.conf.bak" &gt; "/etc/firewalld/firewalld.conf"
    printf '%s\n' "FirewallBackend=nftables" &gt;&gt; "/etc/firewalld/firewalld.conf"
    tail -n "+$(( line_number ))" "/etc/firewalld/firewalld.conf.bak" &gt;&gt; "/etc/firewalld/firewalld.conf"
fi
# Clean up after ourselves.
rm "/etc/firewalld/firewalld.conf.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="firewalld-backend" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040150
  - NIST-800-53-SC-5
  - firewalld-backend
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Setting unquoted shell-style assignment of 'FirewallBackend' to 'nftables'
    in '/etc/firewalld/firewalld.conf'
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/firewalld/firewalld.conf
      create: true
      regexp: (?i)^\s*FirewallBackend=
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/firewalld/firewalld.conf
    ansible.builtin.lineinfile:
      path: /etc/firewalld/firewalld.conf
      create: true
      regexp: (?i)^\s*FirewallBackend=
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/firewalld/firewalld.conf
    ansible.builtin.lineinfile:
      path: /etc/firewalld/firewalld.conf
      create: true
      regexp: (?i)^\s*FirewallBackend=
      line: FirewallBackend=nftables
      state: present
      insertbefore: ^# FirewallBackend
      validate: /usr/bin/bash -n %s
  when:
  - '"kernel" in ansible_facts.packages'
  - '"firewalld" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040150
  - NIST-800-53-SC-5
  - firewalld-backend
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-firewalld-backend:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-firewalld-backend_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_set_firewalld_appropriate_zone" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure network interfaces are assigned to appropriate zone</xccdf-1.2:title>
              <xccdf-1.2:description>Firewall zones define the trust level of network connections or interfaces.
Note: Changing firewall settings while connected over network can result in 
being locked out of the system.</xccdf-1.2:description>
              <xccdf-1.2:rationale>A network interface not assigned to the appropriate zone can allow unexpected or
undesired network traffic to be accepted on the interface.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_firewalld"/>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-set_firewalld_appropriate_zone_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_firewalld_activation">
              <xccdf-1.2:title>Inspect and Activate Default firewalld Rules</xccdf-1.2:title>
              <xccdf-1.2:description>Firewalls can be used to separate networks into different zones
based on the level of trust the user has decided to place on the devices and
traffic within that network. <html:code>NetworkManager</html:code> informs firewalld to which
zone an interface belongs. An interface's assigned zone can be changed by
<html:code>NetworkManager</html:code> or via the <html:code>firewall-config</html:code> tool.
<html:br/>
The zone settings in <html:code>/etc/firewalld/</html:code> are a range of preset settings
which can be quickly applied to a network interface. These are the zones
provided by firewalld sorted according to the default trust level of the
zones from untrusted to trusted:
<html:ul><html:li><html:code>drop</html:code><html:br/><html:p>Any incoming network packets are dropped, there is no
reply. Only outgoing network connections are possible.</html:p></html:li><html:li><html:code>block</html:code><html:br/><html:p>Any incoming network connections are rejected with an
<html:code>icmp-host-prohibited</html:code> message for IPv4 and <html:code>icmp6-adm-prohibited</html:code>
for IPv6. Only network connections initiated from within the system are
possible.</html:p></html:li><html:li><html:code>public</html:code><html:br/><html:p>For use in public areas. You do not trust the other
computers on the network to not harm your computer. Only selected incoming
connections are accepted.</html:p></html:li><html:li><html:code>external</html:code><html:br/><html:p>For use on external networks with masquerading enabled
especially for routers. You do not trust the other computers on the network to
not harm your computer. Only selected incoming connections are accepted.</html:p></html:li><html:li><html:code>dmz</html:code><html:br/><html:p>For computers in your demilitarized zone that are
publicly-accessible with limited access to your internal network. Only selected
incoming connections are accepted.</html:p></html:li><html:li><html:code>work</html:code><html:br/><html:p>For use in work areas. You mostly trust the other computers
on networks to not harm your computer. Only selected incoming connections are
accepted.</html:p></html:li><html:li><html:code>home</html:code><html:br/><html:p>For use in home areas. You mostly trust the other computers
on networks to not harm your computer. Only selected incoming connections are
accepted.</html:p></html:li><html:li><html:code>internal</html:code><html:br/><html:p>For use on internal networks. You mostly trust the
other computers on the networks to not harm your computer. Only selected
incoming connections are accepted.</html:p></html:li><html:li><html:code>trusted</html:code><html:br/><html:p>All network connections are accepted.</html:p></html:li></html:ul>
<html:br/>
It is possible to designate one of these zones to be the default zone. When
interface connections are added to <html:code>NetworkManager</html:code>, they are assigned
to the default zone. On installation, the default zone in firewalld is set to
be the public zone.
<html:br/>
To find out all the settings of a zone, for example the <html:code>public zone,</html:code>
enter the following command as root:
<html:pre># firewall-cmd --zone=public --list-all</html:pre>
Example output of this command might look like the following:
<html:pre>
# firewall-cmd --zone=public --list-all
public
  interfaces:
  services: mdns dhcpv6-client ssh
  ports:
  forward-ports:
  icmp-blocks: source-quench
</html:pre>
To view the network zones currently active, enter the following command as root:
<html:pre># firewall-cmd --get-service</html:pre>
The following listing displays the result of this command
on common AlmaLinux OS 8 system:
<html:pre>
# firewall-cmd --get-service
amanda-client bacula bacula-client dhcp dhcpv6 dhcpv6-client dns ftp
high-availability http https imaps ipp ipp-client ipsec kerberos kpasswd
ldap ldaps libvirt libvirt-tls mdns mountd ms-wbt mysql nfs ntp openvpn
pmcd pmproxy pmwebapi pmwebapis pop3s postgresql proxy-dhcp radius rpc-bind
samba samba-client smtp ssh telnet tftp tftp-client transmission-client
vnc-server wbem-https
</html:pre>
Finally to view the network zones that will be active after the next firewalld
service reload, enter the following command as root:
<html:pre># firewall-cmd --get-service --permanent</html:pre></xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_firewalld_installed" selected="false" severity="medium">
                <xccdf-1.2:title>Install firewalld Package</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>firewalld</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install firewalld</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000096-GPOS-00050</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000297-GPOS-00115</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000298-GPOS-00116</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00232</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">4.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040100</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230505r958672_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>"Firewalld" provides an easy and effective way to block/limit remote access to the system via ports, services, and protocols.

Remote access services, such as those providing remote access to network devices and information systems, which lack automated control capabilities, increase risk and make remote user access management difficult at best.

Remote access is access to nonpublic information systems by an authorized user (or an information system) communicating through an external, non-organization-controlled network. Remote access methods include, for example, dial-up, broadband, and wireless.

AlmaLinux OS 8 functionality (e.g., SSH) must be capable of taking enforcement action if the audit reveals unauthorized activity.
Automated control of remote access sessions allows organizations to ensure ongoing compliance with remote access policies by enforcing connection rules of remote access applications on a variety of information system components (e.g., servers, workstations, notebook computers, smartphones, and tablets)."</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_firewalld_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "firewalld" ; then
    yum install -y "firewalld"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_firewalld_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040100
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_firewalld_installed

- name: Ensure firewalld is installed
  ansible.builtin.package:
    name: firewalld
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040100
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_firewalld_installed
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_firewalld_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_firewalld

class install_firewalld {
  package { 'firewalld':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_firewalld_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=firewalld
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="package_firewalld_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "firewalld"
version = "*"
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_firewalld_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install firewalld
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_firewalld_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install firewalld
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_firewalld_installed:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_firewalld_installed_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_firewalld_enabled" selected="false" severity="medium">
                <xccdf-1.2:title>Verify firewalld Enabled</xccdf-1.2:title>
                <xccdf-1.2:description>
The <html:code>firewalld</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable firewalld.service</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CA-3(5)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(21)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000096-GPOS-00050</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000297-GPOS-00115</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00231</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00232</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf">SYS.1.6.A5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf">SYS.1.6.A21</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">4.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040101</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244544r958672_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Access control methods provide the ability to enhance system security posture
by restricting services and known good IP addresses and address ranges. This
prevents connections from unknown hosts and protocols.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_firewalld"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_firewalld_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q firewalld; }; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'firewalld.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'firewalld.service'
fi
"$SYSTEMCTL_EXEC" enable 'firewalld.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_firewalld_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040101
  - NIST-800-171-3.1.3
  - NIST-800-171-3.4.7
  - NIST-800-53-AC-4
  - NIST-800-53-CA-3(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(21)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_firewalld_enabled

- name: Verify firewalld Enabled - Enable service firewalld
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Verify firewalld Enabled - Enable Service firewalld
    ansible.builtin.systemd:
      name: firewalld
      enabled: true
      state: started
      masked: false
    when:
    - '"firewalld" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040101
  - NIST-800-171-3.1.3
  - NIST-800-171-3.4.7
  - NIST-800-53-AC-4
  - NIST-800-53-CA-3(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(21)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_firewalld_enabled
  - special_service_block
  when:
  - '"kernel" in ansible_facts.packages'
  - '"firewalld" in ansible_facts.packages'
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_firewalld_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_firewalld

class enable_firewalld {
  service {'firewalld':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="service_firewalld_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["firewalld"]
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_firewalld_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable firewalld
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_firewalld_enabled:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_firewalld_enabled_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_ruleset_modifications">
              <xccdf-1.2:title>Strengthen the Default Ruleset</xccdf-1.2:title>
              <xccdf-1.2:description>The default rules can be strengthened. The system
scripts that activate the firewall rules expect them to be defined
in configuration files under the <html:code>/etc/firewalld/services</html:code>
and <html:code>/etc/firewalld/zones</html:code> directories.
<html:br/><html:br/>
The following recommendations describe how to strengthen the
default ruleset configuration file. An alternative to editing this
configuration file is to create a shell script that makes calls to
the <html:code>firewall-cmd</html:code> program to load in rules under the <html:code>/etc/firewalld/services</html:code>
and <html:code>/etc/firewalld/zones</html:code> directories.
<html:br/><html:br/>
Instructions apply to both unless otherwise noted. Language and address
conventions for regular firewalld rules are used throughout this section.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">The program <html:code>firewall-config</html:code>
allows additional services to penetrate the default firewall rules
and automatically adjusts the <html:code>firewalld</html:code> ruleset(s).</xccdf-1.2:warning>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_firewalld_ports" selected="false" severity="medium">
                <xccdf-1.2:title>Configure the Firewalld Ports</xccdf-1.2:title>
                <xccdf-1.2:description>Configure the <html:code>firewalld</html:code> ports to allow approved services to have access to the system.
To configure <html:code>firewalld</html:code> to open ports, run the following command:
<html:pre>firewall-cmd --permanent --add-port=<html:i>port_number/tcp</html:i></html:pre>
To configure <html:code>firewalld</html:code> to allow access for pre-defined services, run the following
command:
<html:pre>firewall-cmd --permanent --add-service=<html:i>service_name</html:i></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CA-3(5)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(21)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000096-GPOS-00050</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000297-GPOS-00115</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1416</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040030</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230500r1101900_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>In order to prevent unauthorized connection of devices, unauthorized transfer of information,
or unauthorized tunneling (i.e., embedding of data types within data types), organizations must
disable or restrict unused or unnecessary physical and logical ports/protocols on information
systems.
<html:br/><html:br/>
Operating systems are capable of providing a wide variety of functions and services.
Some of the functions and services provided by default may not be necessary to support
essential organizational operations.
Additionally, it is sometimes convenient to provide multiple services from a single component
(e.g., VPN and IPS); however, doing so increases risk over limiting the services provided by
one component.
<html:br/><html:br/>
To support the requirements and principles of least functionality, the operating system must
support the organizational requirements, providing only essential capabilities and limiting the
use of ports, protocols, and/or services to only those required, authorized, and approved to
conduct official business.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_firewalld_ports_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configured_firewalld_default_deny" selected="false" severity="medium">
                <xccdf-1.2:title>Firewalld Must Employ a Deny-all, Allow-by-exception Policy for Allowing Connections to Other Systems</xccdf-1.2:title>
                <xccdf-1.2:description>AlmaLinux OS 8 incorporates the "firewalld" daemon, which allows for many different configurations. One of these configurations is zones.
Zones can be utilized to a deny-all, allow-by-exception approach.
The default "drop" zone will drop all incoming network packets unless it is explicitly allowed by the configuration file or is related to an outgoing network connection.</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17 (1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000297-GPOS-00115</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040090</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230504r958672_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Failure to restrict network connectivity only to authorized systems permits inbound connections from malicious systems.
It also permits outbound connections that may facilitate exfiltration of data.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configured_firewalld_default_deny_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firewalld_loopback_traffic_restricted" selected="false" severity="medium">
                <xccdf-1.2:title>Configure Firewalld to Restrict Loopback Traffic</xccdf-1.2:title>
                <xccdf-1.2:description>Configure <html:code>firewalld</html:code> to restrict loopback traffic to the <html:code>lo</html:code> interface.

The loopback traffic must be trusted by assigning the <html:code>lo</html:code> interface to the
<html:code>firewalld</html:code> <html:code>trusted</html:code> zone. However, the loopback traffic must be restricted
to the loopback interface as an anti-spoofing measure.

To configure <html:code>firewalld</html:code> to restrict loopback traffic to the <html:code>lo</html:code> interface,
run the following commands:
<html:pre>
sudo firewall-cmd --permanent --zone=trusted --add-rich-rule='rule family=ipv4 source address="127.0.0.1" destination not address="127.0.0.1" drop'
sudo firewall-cmd --permanent --zone=trusted --add-rich-rule='rule family=ipv6 source address="::1" destination not address="::1" drop'
</html:pre>

To ensure <html:code>firewalld</html:code> settings are applied in runtime, run the following command:
<html:pre>firewall-cmd --reload</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Loopback traffic is generated between processes on machine and is typically critical to
operation of the system. The loopback interface is the only place that loopback network
traffic should be seen, all other interfaces should ignore traffic on this network as an
anti-spoofing measure.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="firewalld_loopback_traffic_restricted" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "firewalld" ; then
    yum install -y "firewalld"
fi

ipv4_rule='rule family=ipv4 source address="127.0.0.1" destination not address="127.0.0.1" drop'
ipv6_rule='rule family=ipv6 source address="::1" destination not address="::1" drop'

if test "$(stat -c %d:%i /)" != "$(stat -c %d:%i /proc/1/root/.)" || { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; }; then
    firewall-offline-cmd --zone=trusted --add-rich-rule="${ipv4_rule}"
    firewall-offline-cmd --zone=trusted --add-rich-rule="${ipv6_rule}"
elif systemctl is-active firewalld; then
    firewall-cmd --permanent --zone=trusted --add-rich-rule="${ipv4_rule}"
    firewall-cmd --permanent --zone=trusted --add-rich-rule="${ipv6_rule}"
    firewall-cmd --reload
else
    echo "
    firewalld service is not active. Remediation aborted!
    This remediation could not be applied because it depends on firewalld service running.
    The service is not started by this remediation in order to prevent connection issues."
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="firewalld_loopback_traffic_restricted" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.1
  - configure_strategy
  - firewalld_loopback_traffic_restricted
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure Firewalld to Restrict Loopback Traffic - Ensure firewalld Package
    is Installed
  ansible.builtin.package:
    name: '{{ item }}'
    state: present
  with_items:
  - firewalld
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.1
  - configure_strategy
  - firewalld_loopback_traffic_restricted
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure Firewalld to Restrict Loopback Traffic - Collect Facts About System
    Services
  ansible.builtin.service_facts: null
  register: result_services_states
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.1
  - configure_strategy
  - firewalld_loopback_traffic_restricted
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure Firewalld to Restrict Loopback Traffic - Remediation is Applicable
    if firewalld Service is Running
  block:

  - name: Configure Firewalld to Restrict Loopback Traffic - Ensure firewalld trusted
      Zone Restricts IPv4 Loopback Traffic
    ansible.builtin.command:
      cmd: firewall-cmd --permanent --zone=trusted --add-rich-rule='rule family=ipv4
        source address="127.0.0.1" destination not address="127.0.0.1" drop'
    register: result_trusted_ipv4_restriction
    changed_when:
    - '''ALREADY_ENABLED'' not in result_trusted_ipv4_restriction.stderr'

  - name: Configure Firewalld to Restrict Loopback Traffic - Ensure firewalld trusted
      Zone Restricts IPv6 Loopback Traffic
    ansible.builtin.command:
      cmd: firewall-cmd --permanent --zone=trusted --add-rich-rule='rule family=ipv6
        source address="::1" destination not address="::1" drop'
    register: result_trusted_ipv6_restriction
    changed_when:
    - '''ALREADY_ENABLED'' not in result_trusted_ipv6_restriction.stderr'

  - name: Configure Firewalld to Restrict Loopback Traffic - Ensure firewalld Changes
      are Applied
    ansible.builtin.service:
      name: firewalld
      state: reloaded
    when:
    - result_trusted_ipv4_restriction is changed or result_trusted_ipv6_restriction
      is changed
  when:
  - '"kernel" in ansible_facts.packages'
  - ('firewalld.service' in ansible_facts.services and ansible_facts.services['firewalld.service'].state
    == 'running')
  tags:
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.1
  - configure_strategy
  - firewalld_loopback_traffic_restricted
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure Firewalld to Restrict Loopback Traffic - Informative Message Based
    on Service State
  ansible.builtin.assert:
    that:
    - (ansible_check_mode or ('firewalld.service' in ansible_facts.services and ansible_facts.services['firewalld.service'].state
      == 'running'))
    fail_msg:
    - firewalld service is not active. Remediation aborted!
    - This remediation could not be applied because it depends on firewalld service
      running.
    - The service is not started by this remediation in order to prevent connection
      issues.
    success_msg:
    - Configure Firewalld to Restrict Loopback Traffic remediation successfully executed
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.1
  - configure_strategy
  - firewalld_loopback_traffic_restricted
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-firewalld_loopback_traffic_restricted:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-firewalld_loopback_traffic_restricted_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firewalld_loopback_traffic_trusted" selected="false" severity="medium">
                <xccdf-1.2:title>Configure Firewalld to Trust Loopback Traffic</xccdf-1.2:title>
                <xccdf-1.2:description>Assign loopback interface to the <html:code>firewalld</html:code> <html:code>trusted</html:code> zone in order to
explicitly allow the loopback traffic in the system.

To configure <html:code>firewalld</html:code> to trust loopback traffic, run the following command:
<html:pre>sudo firewall-cmd --permanent --zone=trusted --add-interface=lo</html:pre>
To ensure <html:code>firewalld</html:code> settings are applied in runtime, run the following command:
<html:pre>firewall-cmd --reload</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Loopback traffic is generated between processes on machine and is typically critical to
operation of the system. The loopback interface is the only place that loopback network
traffic should be seen, all other interfaces should ignore traffic on this network as an
anti-spoofing measure.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="firewalld_loopback_traffic_trusted" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "firewalld" ; then
    yum install -y "firewalld"
fi

if test "$(stat -c %d:%i /)" != "$(stat -c %d:%i /proc/1/root/.)" || { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; }; then
    firewall-offline-cmd --zone=trusted --add-interface=lo
elif systemctl is-active firewalld; then
    firewall-cmd --permanent --zone=trusted --add-interface=lo
    firewall-cmd --reload
else
    echo "
    firewalld service is not active. Remediation aborted!
    This remediation could not be applied because it depends on firewalld service running.
    The service is not started by this remediation in order to prevent connection issues."
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="firewalld_loopback_traffic_trusted" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.1
  - configure_strategy
  - firewalld_loopback_traffic_trusted
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure Firewalld to Trust Loopback Traffic - Ensure firewalld Package is
    Installed
  ansible.builtin.package:
    name: '{{ item }}'
    state: present
  with_items:
  - firewalld
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.1
  - configure_strategy
  - firewalld_loopback_traffic_trusted
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure Firewalld to Trust Loopback Traffic - Collect Facts About System
    Services
  ansible.builtin.service_facts: null
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.1
  - configure_strategy
  - firewalld_loopback_traffic_trusted
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure Firewalld to Trust Loopback Traffic - Remediation is Applicable
    if firewalld Service is Running
  block:

  - name: Configure Firewalld to Trust Loopback Traffic - Ensure firewalld trusted
      Zone Includes lo Interface
    ansible.builtin.command:
      cmd: firewall-cmd --permanent --zone=trusted --add-interface=lo
    register: result_lo_interface_assignment
    changed_when:
    - '''ALREADY_ENABLED'' not in result_lo_interface_assignment.stderr'

  - name: Configure Firewalld to Trust Loopback Traffic - Ensure firewalld Changes
      are Applied
    ansible.builtin.service:
      name: firewalld
      state: reloaded
    when:
    - result_lo_interface_assignment is changed
  when:
  - '"kernel" in ansible_facts.packages'
  - ('firewalld.service' in ansible_facts.services and ansible_facts.services['firewalld.service'].state
    == 'running')
  tags:
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.1
  - configure_strategy
  - firewalld_loopback_traffic_trusted
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure Firewalld to Trust Loopback Traffic - Informative Message Based
    on Service State
  ansible.builtin.assert:
    that:
    - (ansible_check_mode or ('firewalld.service' in ansible_facts.services and ansible_facts.services['firewalld.service'].state
      == 'running'))
    fail_msg:
    - firewalld service is not active. Remediation aborted!
    - This remediation could not be applied because it depends on firewalld service
      running.
    - The service is not started by this remediation in order to prevent connection
      issues.
    success_msg:
    - Configure Firewalld to Trust Loopback Traffic remediation successfully executed
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.1
  - configure_strategy
  - firewalld_loopback_traffic_trusted
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-firewalld_loopback_traffic_trusted:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-firewalld_loopback_traffic_trusted_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_set_firewalld_default_zone" selected="false" severity="medium">
                <xccdf-1.2:title>Set Default firewalld Zone for Incoming Packets</xccdf-1.2:title>
                <xccdf-1.2:description>To set the default zone to <html:code>drop</html:code> for
the built-in default zone which processes incoming IPv4 and IPv6 packets,
modify the following line in
<html:code>/etc/firewalld/firewalld.conf</html:code> to be:
<html:pre>DefaultZone=drop</html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">To prevent denying any access to the system, automatic remediation
of this control is not available. Remediation must be automated as
a component of machine provisioning, or followed manually as outlined
above.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.13.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CA-3(5)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(23)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1416</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040090</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230504r958672_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>In <html:code>firewalld</html:code> the default zone is applied only after all
the applicable rules in the table are examined for a match. Setting the
default zone to <html:code>drop</html:code> implements proper design for a firewall, i.e.
any packets which are not explicitly permitted should not be
accepted.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_firewalld"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-set_firewalld_default_zone:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-set_firewalld_default_zone_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_network-ipsec">
            <xccdf-1.2:title>IPSec Support</xccdf-1.2:title>
            <xccdf-1.2:description>Support for Internet Protocol Security (IPsec)
is provided with Libreswan.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_libreswan_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install libreswan Package</xccdf-1.2:title>
              <xccdf-1.2:description>The libreswan package provides an implementation of IPsec
and IKE, which permits the creation of secure tunnels over
untrusted networks. The <html:code>libreswan</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install libreswan</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.MA-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000120-GPOS-00061</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Providing the ability for remote users or systems
to initiate a secure VPN connection protects information when it is
transmitted over a wide area network.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreswan_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "libreswan" ; then
    yum install -y "libreswan"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreswan_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-4.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_libreswan_installed

- name: Ensure libreswan is installed
  ansible.builtin.package:
    name: libreswan
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-4.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_libreswan_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreswan_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_libreswan

class install_libreswan {
  package { 'libreswan':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreswan_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=libreswan
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_libreswan_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "libreswan"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreswan_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install libreswan
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_libreswan_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install libreswan
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_libreswan_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_libreswan_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_ipsecd" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Group Who Owns /etc/ipsec.d Directory</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/ipsec.d</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/ipsec.d</html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The ownership of the /etc/ipsec.d directory by the root group is important
because this directory hosts Libreswan configuration. Protection of this
file is critical for system security. Assigning the ownership to root
ensures exclusive control of the Libreswan configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_libreswan"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_groupowner_etc_ipsecd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q libreswan; then

newgroup=""
if getent group "root" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="root"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "root is not a defined group on the system"
else
find -P /etc/ipsec.d/ -maxdepth 0 -type d  ! -group root -exec chgrp --no-dereference "$newgroup" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_groupowner_etc_ipsecd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_groupowner_etc_ipsecd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Check that the root group is defined
  ansible.builtin.getent:
    database: group
    key: root
  ignore_errors: true
  when:
  - '"libreswan" in ansible_facts.packages'
  - directory_groupowner_etc_ipsecd_newgroup is undefined
  tags:
  - configure_strategy
  - directory_groupowner_etc_ipsecd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the directory_groupowner_etc_ipsecd_newgroup variable if root found
  ansible.builtin.set_fact:
    directory_groupowner_etc_ipsecd_newgroup: root
  when:
  - '"libreswan" in ansible_facts.packages'
  - ansible_facts.getent_group["root"] is defined
  tags:
  - configure_strategy
  - directory_groupowner_etc_ipsecd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/ipsec.d/
  ansible.builtin.file:
    path: /etc/ipsec.d/
    follow: false
    state: directory
    group: '{{ directory_groupowner_etc_ipsecd_newgroup }}'
  when: '"libreswan" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_groupowner_etc_ipsecd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_groupowner_etc_ipsecd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_groupowner_etc_ipsecd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_owner_etc_ipsecd" selected="false" severity="medium">
              <xccdf-1.2:title>Verify User Who Owns /etc/ipsec.d Directory</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the owner of <html:code>/etc/ipsec.d</html:code>, run the command:
<html:pre>$ sudo chown root /etc/ipsec.d </html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The ownership of the /etc/ipsec.d directory by the root user is important
because this directory hosts Libreswan configuration. Protection of this
file is critical for system security. Assigning the ownership to root
ensures exclusive control of the Libreswan configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_libreswan"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_owner_etc_ipsecd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q libreswan; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
find -P /etc/ipsec.d/ -maxdepth 0 -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_owner_etc_ipsecd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_owner_etc_ipsecd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the directory_owner_etc_ipsecd_newown variable if represented by uid
  ansible.builtin.set_fact:
    directory_owner_etc_ipsecd_newown: '0'
  when: '"libreswan" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_owner_etc_ipsecd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /etc/ipsec.d/
  ansible.builtin.file:
    path: /etc/ipsec.d/
    follow: false
    state: directory
    owner: '{{ directory_owner_etc_ipsecd_newown }}'
  when: '"libreswan" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_owner_etc_ipsecd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_owner_etc_ipsecd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_owner_etc_ipsecd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_permissions_etc_ipsecd" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Permissions On /etc/ipsec.d Directory</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/ipsec.d</html:code>, run the command: <html:pre>$ sudo chmod 0700 /etc/ipsec.d</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Setting correct permissions on the /etc/ipsec.d directory is important
because this directory hosts Libreswan configuration. Protection of this
directory is critical for system security. Restricting the permissions
ensures exclusive control of the Libreswan configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_libreswan"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_permissions_etc_ipsecd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q libreswan; then

find -H /etc/ipsec.d/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt -type d -exec chmod u-s,g-xwrs,o-xwrt {} \;

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_permissions_etc_ipsecd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_permissions_etc_ipsecd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/ipsec.d/ file(s)
  ansible.builtin.command: 'find -P /etc/ipsec.d/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt  -type
    d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"libreswan" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_permissions_etc_ipsecd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /etc/ipsec.d/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-xwrs,o-xwrt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"libreswan" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_permissions_etc_ipsecd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_permissions_etc_ipsecd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_permissions_etc_ipsecd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_etc_ipsec_conf" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Group Who Owns /etc/ipsec.conf File</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/ipsec.conf</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/ipsec.conf</html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The ownership of the /etc/ipsec.conf file by the root group is important
because this file hosts Libreswan configuration. Protection of this
file is critical for system security. Assigning the ownership to root
ensures exclusive control of the Libreswan configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_libreswan"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_ipsec_conf" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q libreswan; then

newgroup=""
if getent group "root" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="root"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "root is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/ipsec.conf" | grep -E -w -q "root"; then
    chgrp --no-dereference "$newgroup" /etc/ipsec.conf
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_ipsec_conf" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_groupowner_etc_ipsec_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Check that the root group is defined
  ansible.builtin.getent:
    database: group
    key: root
  ignore_errors: true
  when:
  - '"libreswan" in ansible_facts.packages'
  - file_groupowner_etc_ipsec_conf_newgroup is undefined
  tags:
  - configure_strategy
  - file_groupowner_etc_ipsec_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_etc_ipsec_conf_newgroup variable if root found
  ansible.builtin.set_fact:
    file_groupowner_etc_ipsec_conf_newgroup: root
  when:
  - '"libreswan" in ansible_facts.packages'
  - ansible_facts.getent_group["root"] is defined
  tags:
  - configure_strategy
  - file_groupowner_etc_ipsec_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/ipsec.conf
  ansible.builtin.stat:
    path: /etc/ipsec.conf
  register: file_exists
  when: '"libreswan" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupowner_etc_ipsec_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/ipsec.conf
  ansible.builtin.file:
    path: /etc/ipsec.conf
    follow: false
    group: '{{ file_groupowner_etc_ipsec_conf_newgroup }}'
  when:
  - '"libreswan" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupowner_etc_ipsec_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_etc_ipsec_conf:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_etc_ipsec_conf_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_etc_ipsec_secrets" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Group Who Owns /etc/ipsec.secrets File</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/ipsec.secrets</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/ipsec.secrets</html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The ownership of the /etc/ipsec.secrets file by the root group is important
because this file hosts Libreswan configuration. Protection of this
file is critical for system security. Assigning the ownership to root
ensures exclusive control of the Libreswan configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_libreswan"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_ipsec_secrets" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q libreswan; then

newgroup=""
if getent group "root" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="root"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "root is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/ipsec.secrets" | grep -E -w -q "root"; then
    chgrp --no-dereference "$newgroup" /etc/ipsec.secrets
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_ipsec_secrets" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_groupowner_etc_ipsec_secrets
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Check that the root group is defined
  ansible.builtin.getent:
    database: group
    key: root
  ignore_errors: true
  when:
  - '"libreswan" in ansible_facts.packages'
  - file_groupowner_etc_ipsec_secrets_newgroup is undefined
  tags:
  - configure_strategy
  - file_groupowner_etc_ipsec_secrets
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_etc_ipsec_secrets_newgroup variable if root found
  ansible.builtin.set_fact:
    file_groupowner_etc_ipsec_secrets_newgroup: root
  when:
  - '"libreswan" in ansible_facts.packages'
  - ansible_facts.getent_group["root"] is defined
  tags:
  - configure_strategy
  - file_groupowner_etc_ipsec_secrets
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/ipsec.secrets
  ansible.builtin.stat:
    path: /etc/ipsec.secrets
  register: file_exists
  when: '"libreswan" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupowner_etc_ipsec_secrets
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/ipsec.secrets
  ansible.builtin.file:
    path: /etc/ipsec.secrets
    follow: false
    group: '{{ file_groupowner_etc_ipsec_secrets_newgroup }}'
  when:
  - '"libreswan" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupowner_etc_ipsec_secrets
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_etc_ipsec_secrets:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_etc_ipsec_secrets_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_etc_ipsec_conf" selected="false" severity="medium">
              <xccdf-1.2:title>Verify User Who Owns /etc/ipsec.conf File</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the owner of <html:code>/etc/ipsec.conf</html:code>, run the command:
<html:pre>$ sudo chown root /etc/ipsec.conf </html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The ownership of the /etc/ipsec.conf file by the root user is important
because this file hosts Libreswan configuration. Protection of this
file is critical for system security. Assigning the ownership to root
ensures exclusive control of the Libreswan configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_libreswan"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_ipsec_conf" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q libreswan; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/ipsec.conf" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/ipsec.conf
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_ipsec_conf" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_owner_etc_ipsec_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_etc_ipsec_conf_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_etc_ipsec_conf_newown: '0'
  when: '"libreswan" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_etc_ipsec_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/ipsec.conf
  ansible.builtin.stat:
    path: /etc/ipsec.conf
  register: file_exists
  when: '"libreswan" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_etc_ipsec_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/ipsec.conf
  ansible.builtin.file:
    path: /etc/ipsec.conf
    follow: false
    owner: '{{ file_owner_etc_ipsec_conf_newown }}'
  when:
  - '"libreswan" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_owner_etc_ipsec_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_etc_ipsec_conf:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_etc_ipsec_conf_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_etc_ipsec_secrets" selected="false" severity="medium">
              <xccdf-1.2:title>Verify User Who Owns /etc/ipsec.secrets File</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the owner of <html:code>/etc/ipsec.secrets</html:code>, run the command:
<html:pre>$ sudo chown root /etc/ipsec.secrets </html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The ownership of the /etc/ipsec.secrets file by the root user is important
because this file hosts Libreswan configuration. Protection of this
file is critical for system security. Assigning the ownership to root
ensures exclusive control of the Libreswan configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_libreswan"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_ipsec_secrets" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q libreswan; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/ipsec.secrets" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/ipsec.secrets
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_ipsec_secrets" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_owner_etc_ipsec_secrets
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_etc_ipsec_secrets_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_etc_ipsec_secrets_newown: '0'
  when: '"libreswan" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_etc_ipsec_secrets
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/ipsec.secrets
  ansible.builtin.stat:
    path: /etc/ipsec.secrets
  register: file_exists
  when: '"libreswan" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_etc_ipsec_secrets
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/ipsec.secrets
  ansible.builtin.file:
    path: /etc/ipsec.secrets
    follow: false
    owner: '{{ file_owner_etc_ipsec_secrets_newown }}'
  when:
  - '"libreswan" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_owner_etc_ipsec_secrets
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_etc_ipsec_secrets:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_etc_ipsec_secrets_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_ipsec_conf" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Permissions On /etc/ipsec.conf File</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/ipsec.conf</html:code>, run the command: <html:pre>$ sudo chmod 0644 /etc/ipsec.conf</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Setting correct permissions on the /etc/ipsec.conf file is important
because this file hosts Libreswan configuration. Protection of this
file is critical for system security. Restricting the permissions
ensures exclusive control of the Libreswan configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_libreswan"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_ipsec_conf" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q libreswan; then

chmod u-xs,g-xws,o-xwt /etc/ipsec.conf

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_ipsec_conf" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_permissions_etc_ipsec_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/ipsec.conf
  ansible.builtin.stat:
    path: /etc/ipsec.conf
  register: file_exists
  when: '"libreswan" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_permissions_etc_ipsec_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xws,o-xwt on /etc/ipsec.conf
  ansible.builtin.file:
    path: /etc/ipsec.conf
    mode: u-xs,g-xws,o-xwt
  when:
  - '"libreswan" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_etc_ipsec_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_ipsec_conf:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_ipsec_conf_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_ipsec_secrets" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Permissions On /etc/ipsec.secrets File</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/ipsec.secrets</html:code>, run the command: <html:pre>$ sudo chmod 0644 /etc/ipsec.secrets</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Setting correct permissions on the /etc/ipsec.secrets file is important
because this file hosts Libreswan configuration. Protection of this
file is critical for system security. Restricting the permissions
ensures exclusive control of the Libreswan configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_libreswan"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_ipsec_secrets" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q libreswan; then

chmod u-xs,g-xws,o-xwt /etc/ipsec.secrets

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_ipsec_secrets" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_permissions_etc_ipsec_secrets
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/ipsec.secrets
  ansible.builtin.stat:
    path: /etc/ipsec.secrets
  register: file_exists
  when: '"libreswan" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_permissions_etc_ipsec_secrets
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xws,o-xwt on /etc/ipsec.secrets
  ansible.builtin.file:
    path: /etc/ipsec.secrets
    mode: u-xs,g-xws,o-xwt
  when:
  - '"libreswan" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_etc_ipsec_secrets
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_ipsec_secrets:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_ipsec_secrets_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_libreswan_approved_tunnels" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Any Configured IPSec Tunnel Connections</xccdf-1.2:title>
              <xccdf-1.2:description>Libreswan provides an implementation of IPsec
and IKE, which permits the creation of secure tunnels over
untrusted networks. As such, IPsec can be used to circumvent certain
network requirements such as filtering. Verify that if any IPsec connection

(<html:code>conn</html:code>) configured in <html:code>/etc/ipsec.conf</html:code> and <html:code>/etc/ipsec.d</html:code>

exists is an approved organizational connection.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Automatic remediation of this control is not available due to the unique
requirements of each system.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MA-4(6)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>IP tunneling mechanisms can be used to bypass network filtering.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-libreswan_approved_tunnels_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_network-iptables">
            <xccdf-1.2:title>iptables and ip6tables</xccdf-1.2:title>
            <xccdf-1.2:description>A host-based firewall called <html:code>netfilter</html:code> is included as
part of the Linux kernel distributed with the system. It is
activated by default. This firewall is controlled by the program
<html:code>iptables</html:code>, and the entire capability is frequently referred to by
this name. An analogous program called <html:code>ip6tables</html:code> handles filtering
for IPv6.
<html:br/><html:br/>
Unlike TCP Wrappers, which depends on the network server
program to support and respect the rules written, <html:code>netfilter</html:code>
filtering occurs at the kernel level, before a program can even
process the data from the network packet. As such, any program on
the system is affected by the rules written.
<html:br/><html:br/>
This section provides basic information about strengthening
the <html:code>iptables</html:code> and <html:code>ip6tables</html:code> configurations included with the system.
For more complete information that may allow the construction of a
sophisticated ruleset tailored to your environment, please consult
the references at the end of this section.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_iptables-services_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install iptables-services Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>iptables-services</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install iptables-services</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>iptables-services</html:code> provides the services iptables and ip6tables that have been split
out of the base package since they are not active by default anymore.
These services load the iptables rules during the system startup and also allow one to reload
the iptables rules during runtime.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_iptables"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables-services_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q iptables; then

if ! rpm -q --quiet "iptables-services" ; then
    yum install -y "iptables-services"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables-services_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_iptables-services_installed

- name: Ensure iptables-services is installed
  ansible.builtin.package:
    name: iptables-services
    state: present
  when: '"iptables" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_iptables-services_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables-services_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_iptables-services

class install_iptables-services {
  package { 'iptables-services':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables-services_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=iptables-services
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_iptables-services_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "iptables-services"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables-services_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install iptables-services
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables-services_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install iptables-services
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_iptables-services_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_iptables-services_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_iptables_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install iptables Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>iptables</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install iptables</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>iptables</html:code> controls the Linux kernel network packet filtering
code. <html:code>iptables</html:code> allows system operators to set up firewalls and IP
masquerading, etc.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_rhcos4-rhel9_and_service_disabled_nftables_and_service_disabled_ufw_and_system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( ! (systemctl is-active nftables &amp;&gt;/dev/null) &amp;&amp; ! (systemctl is-active ufw &amp;&gt;/dev/null) &amp;&amp; rpm --quiet -q kernel ) ); then

if ! rpm -q --quiet "iptables" ; then
    yum install -y "iptables"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-1.4.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_iptables_installed

- name: Ensure iptables is installed
  ansible.builtin.package:
    name: iptables
    state: present
  when: ( "kernel" in ansible_facts.packages )
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-1.4.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_iptables_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_iptables

class install_iptables {
  package { 'iptables':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=iptables
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_iptables_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "iptables"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install iptables
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install iptables
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_iptables_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_iptables_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_iptables-services_removed" selected="false" severity="medium">
              <xccdf-1.2:title>Remove iptables-services Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>iptables-services</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase iptables-services</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale><html:code>iptables-services</html:code> provides the services iptables and ip6tables that have been split
out of the base package since they are not active by default anymore. These services load the
iptables rules during the system startup and also allow one to reload the iptables rules
during runtime. Those iptables services conflicts with firewalld so they should be removed if
firewalld is used.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_iptables"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables-services_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q iptables; then

# CAUTION: This remediation script will remove iptables-services
# from the system, and may remove any packages
# that depend on iptables-services. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "iptables-services" ; then
yum remove -y "iptables-services"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables-services_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_iptables-services_removed

- name: 'Remove iptables-services Package: Ensure iptables-services is removed'
  ansible.builtin.package:
    name: iptables-services
    state: absent
  when: '"iptables" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_iptables-services_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables-services_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_iptables-services

class remove_iptables-services {
  package { 'iptables-services':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables-services_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=iptables-services
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables-services_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove iptables-services
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_iptables-services_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove iptables-services
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_iptables-services_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_iptables-services_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_iptables" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Group Who Owns /etc/iptables Directory</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/iptables</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/iptables</html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The ownership of the /etc/iptables directory by the root group is important
because this directory hosts iptables configuration. Protection of this
file is critical for system security. Assigning the ownership to root
ensures exclusive control of the iptables configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_iptables"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_groupowner_etc_iptables" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q iptables; then

newgroup=""
if getent group "root" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="root"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "root is not a defined group on the system"
else
find -P /etc/iptables/ -maxdepth 0 -type d  ! -group root -exec chgrp --no-dereference "$newgroup" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_groupowner_etc_iptables" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_groupowner_etc_iptables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Check that the root group is defined
  ansible.builtin.getent:
    database: group
    key: root
  ignore_errors: true
  when:
  - '"iptables" in ansible_facts.packages'
  - directory_groupowner_etc_iptables_newgroup is undefined
  tags:
  - configure_strategy
  - directory_groupowner_etc_iptables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the directory_groupowner_etc_iptables_newgroup variable if root found
  ansible.builtin.set_fact:
    directory_groupowner_etc_iptables_newgroup: root
  when:
  - '"iptables" in ansible_facts.packages'
  - ansible_facts.getent_group["root"] is defined
  tags:
  - configure_strategy
  - directory_groupowner_etc_iptables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/iptables/
  ansible.builtin.file:
    path: /etc/iptables/
    follow: false
    state: directory
    group: '{{ directory_groupowner_etc_iptables_newgroup }}'
  when: '"iptables" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_groupowner_etc_iptables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_groupowner_etc_iptables:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_groupowner_etc_iptables_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_owner_etc_iptables" selected="false" severity="medium">
              <xccdf-1.2:title>Verify User Who Owns /etc/iptables Directory</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the owner of <html:code>/etc/iptables</html:code>, run the command:
<html:pre>$ sudo chown root /etc/iptables </html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The ownership of the /etc/iptables directory by the root user is important
because this directory hosts iptables configuration. Protection of this
file is critical for system security. Assigning the ownership to root
ensures exclusive control of the iptables configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_iptables"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_owner_etc_iptables" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q iptables; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
find -P /etc/iptables/ -maxdepth 0 -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_owner_etc_iptables" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_owner_etc_iptables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the directory_owner_etc_iptables_newown variable if represented by uid
  ansible.builtin.set_fact:
    directory_owner_etc_iptables_newown: '0'
  when: '"iptables" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_owner_etc_iptables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /etc/iptables/
  ansible.builtin.file:
    path: /etc/iptables/
    follow: false
    state: directory
    owner: '{{ directory_owner_etc_iptables_newown }}'
  when: '"iptables" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_owner_etc_iptables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_owner_etc_iptables:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_owner_etc_iptables_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_permissions_etc_iptables" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Permissions On /etc/iptables Directory</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/iptables</html:code>, run the command: <html:pre>$ sudo chmod 0700 /etc/iptables</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Setting correct permissions on the /etc/iptables directory is important
because this directory hosts iptables configuration. Protection of this
directory is critical for system security. Restricting the permissions
ensures exclusive control of the iptables configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_iptables"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_permissions_etc_iptables" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q iptables; then

find -H /etc/iptables/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt -type d -exec chmod u-s,g-xwrs,o-xwrt {} \;

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_permissions_etc_iptables" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_permissions_etc_iptables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/iptables/ file(s)
  ansible.builtin.command: 'find -P /etc/iptables/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt  -type
    d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"iptables" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_permissions_etc_iptables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /etc/iptables/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-xwrs,o-xwrt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"iptables" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_permissions_etc_iptables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_permissions_etc_iptables:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_permissions_etc_iptables_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_iptables_activation">
              <xccdf-1.2:title>Inspect and Activate Default Rules</xccdf-1.2:title>
              <xccdf-1.2:description>View the currently-enforced <html:code>iptables</html:code> rules by running
the command:
<html:pre>$ sudo iptables -nL --line-numbers</html:pre>
The command is analogous for <html:code>ip6tables</html:code>.
<html:br/><html:br/>
If the firewall does not appear to be active (i.e., no rules
appear), activate it and ensure that it starts at boot by issuing
the following commands (and analogously for <html:code>ip6tables</html:code>):
<html:pre>$ sudo service iptables restart</html:pre>
The default iptables rules are:
<html:pre>Chain INPUT (policy ACCEPT)
num  target     prot opt source       destination
1    ACCEPT     all  --  0.0.0.0/0    0.0.0.0/0    state RELATED,ESTABLISHED 
2    ACCEPT     icmp --  0.0.0.0/0    0.0.0.0/0
3    ACCEPT     all  --  0.0.0.0/0    0.0.0.0/0
4    ACCEPT     tcp  --  0.0.0.0/0    0.0.0.0/0    state NEW tcp dpt:22 
5    REJECT     all  --  0.0.0.0/0    0.0.0.0/0    reject-with icmp-host-prohibited 

Chain FORWARD (policy ACCEPT)
num  target     prot opt source       destination
1    REJECT     all  --  0.0.0.0/0    0.0.0.0/0    reject-with icmp-host-prohibited 

Chain OUTPUT (policy ACCEPT)
num  target     prot opt source       destination</html:pre>
The <html:code>ip6tables</html:code> default rules are essentially the same.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_ip6tables_enabled" selected="false" severity="medium">
                <xccdf-1.2:title>Verify ip6tables Enabled if Using IPv6</xccdf-1.2:title>
                <xccdf-1.2:description>
The <html:code>ip6tables</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable ip6tables.service</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CA-3(5)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(21)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>ip6tables</html:code> service provides the system's host-based firewalling
capability for IPv6 and ICMPv6.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_ip6tables_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'ip6tables.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'ip6tables.service'
fi
"$SYSTEMCTL_EXEC" enable 'ip6tables.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_ip6tables_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-4
  - NIST-800-53-CA-3(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(21)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_ip6tables_enabled

- name: Verify ip6tables Enabled if Using IPv6 - Enable service ip6tables
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Verify ip6tables Enabled if Using IPv6 - Enable Service ip6tables
    ansible.builtin.systemd:
      name: ip6tables
      enabled: true
      state: started
      masked: false
    when:
    - '"iptables-ipv6" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-4
  - NIST-800-53-CA-3(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(21)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_ip6tables_enabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_ip6tables_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_ip6tables

class enable_ip6tables {
  service {'ip6tables':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="service_ip6tables_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["ip6tables"]
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_ip6tables_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable ip6tables
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_ip6tables_enabled:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_ip6tables_enabled_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_iptables_enabled" selected="false" severity="medium">
                <xccdf-1.2:title>Verify iptables Enabled</xccdf-1.2:title>
                <xccdf-1.2:description>
The <html:code>iptables</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable iptables.service</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CA-3(5)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(21)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>iptables</html:code> service provides the system's host-based firewalling
capability for IPv4 and ICMP.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_iptables_and_service_disabled_firewalld_and_system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_iptables_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q iptables &amp;&amp; ! (systemctl is-active firewalld &amp;&gt;/dev/null) &amp;&amp; rpm --quiet -q kernel ) ); then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'iptables.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'iptables.service'
fi
"$SYSTEMCTL_EXEC" enable 'iptables.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_iptables_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-4
  - NIST-800-53-CA-3(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(21)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_iptables_enabled

- name: Verify iptables Enabled - Enable service iptables
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Verify iptables Enabled - Enable Service iptables
    ansible.builtin.systemd:
      name: iptables
      enabled: true
      state: started
      masked: false
    when:
    - '"iptables" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-4
  - NIST-800-53-CA-3(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(21)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_iptables_enabled
  - special_service_block
  when: ( "iptables" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_iptables_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_iptables

class enable_iptables {
  service {'iptables':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="service_iptables_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["iptables"]
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_iptables_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable iptables
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_iptables_enabled:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_set_ip6tables_default_rule" selected="false" severity="medium">
                <xccdf-1.2:title>Set Default ip6tables Policy for Incoming Packets</xccdf-1.2:title>
                <xccdf-1.2:description>To set the default policy to DROP (instead of ACCEPT) for
the built-in INPUT chain which processes incoming packets,
add or correct the following line in

<html:code>/etc/sysconfig/ip6tables</html:code>:

<html:pre>:INPUT DROP [0:0]</html:pre>
If changes were required, reload the ip6tables rules:
<html:pre>$ sudo service ip6tables reload</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CA-3(5)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(21)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
                <xccdf-1.2:rationale>In <html:code>ip6tables</html:code>, the default policy is applied only after all
the applicable rules in the table are examined for a match. Setting the
default policy to <html:code>DROP</html:code> implements proper design for a firewall, i.e.
any packets which are not explicitly permitted should not be
accepted.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#not_package_nftables_and_not_package_ufw_and_package_iptables"/>
                <xccdf-1.2:fix id="set_ip6tables_default_rule" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( ! ( rpm --quiet -q nftables ) &amp;&amp; ! ( rpm --quiet -q ufw ) &amp;&amp; rpm --quiet -q iptables ) ); then

sed -i 's/^:INPUT ACCEPT.*/:INPUT DROP [0:0]/g' /etc/sysconfig/ip6tables

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-set_ip6tables_default_rule_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_set_ipv6_loopback_traffic" selected="false" severity="medium">
                <xccdf-1.2:title>Set configuration for IPv6 loopback traffic</xccdf-1.2:title>
                <xccdf-1.2:description>Configure the loopback interface to accept traffic.
Configure all other interfaces to deny traffic to the loopback
network.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">Changing firewall settings while connected over network can
result in being locked out of the system.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Loopback traffic is generated between processes on machine and is
typically critical to operation of the system. The loopback interface
is the only place that loopback network traffic should be seen,
all other interfaces should ignore traffic on this network as an
anti-spoofing measure.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#not_package_nftables_and_not_package_ufw_and_package_iptables"/>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-set_ipv6_loopback_traffic_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_set_loopback_traffic" selected="false" severity="medium">
                <xccdf-1.2:title>Set configuration for loopback traffic</xccdf-1.2:title>
                <xccdf-1.2:description>Configure the loopback interface to accept traffic.
Configure all other interfaces to deny traffic to the loopback
network.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">Changing firewall settings while connected over network can
result in being locked out of the system.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Loopback traffic is generated between processes on machine and is
typically critical to operation of the system. The loopback interface
is the only place that loopback network traffic should be seen, all
other interfaces should ignore traffic on this network as an
anti-spoofing measure.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#not_package_nftables_and_not_package_ufw_and_package_iptables"/>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-set_loopback_traffic_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications">
              <xccdf-1.2:title>Strengthen the Default Ruleset</xccdf-1.2:title>
              <xccdf-1.2:description>The default rules can be strengthened. The system
scripts that activate the firewall rules expect them to be defined
in the configuration files <html:code>iptables</html:code> and <html:code>ip6tables</html:code> in the directory
<html:code>/etc/sysconfig</html:code>. Many of the lines in these files are similar
to the command line arguments that would be provided to the programs
<html:code>/sbin/iptables</html:code> or <html:code>/sbin/ip6tables</html:code> - but some are quite
different.
<html:br/><html:br/>
The following recommendations describe how to strengthen the
default ruleset configuration file. An alternative to editing this
configuration file is to create a shell script that makes calls to
the iptables program to load in rules, and then invokes service
iptables save to write those loaded rules to
<html:code>/etc/sysconfig/iptables.</html:code>
<html:br/><html:br/>
The following alterations can be made directly to
<html:code>/etc/sysconfig/iptables</html:code> and <html:code>/etc/sysconfig/ip6tables</html:code>.
Instructions apply to both unless otherwise noted. Language and address
conventions for regular iptables are used throughout this section;
configuration for ip6tables will be either analogous or explicitly
covered.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">The program <html:code>system-config-securitylevel</html:code>
allows additional services to penetrate the default firewall rules
and automatically adjusts <html:code>/etc/sysconfig/iptables</html:code>. This program
is only useful if the default ruleset meets your security
requirements. Otherwise, this program should not be used to make
changes to the firewall configuration because it re-writes the
saved configuration file.</xccdf-1.2:warning>
              <xccdf-1.2:platform idref="#package_iptables"/>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ip6tables_rules_for_open_ports" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure ip6tables Firewall Rules Exist for All Open Ports</xccdf-1.2:title>
                <xccdf-1.2:description>Any ports that have been opened on non-loopback addresses
need firewall rules to govern traffic.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">Changing firewall settings while connected over network can
result in being locked out of the system.</xccdf-1.2:warning>
                <xccdf-1.2:rationale>Without a firewall rule configured for open ports default
firewall policy will drop all packets to these ports.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#not_package_nftables_and_not_package_ufw"/>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ip6tables_rules_for_open_ports_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_iptables_rules_for_open_ports" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure iptables Firewall Rules Exist for All Open Ports</xccdf-1.2:title>
                <xccdf-1.2:description>Any ports that have been opened on non-loopback addresses
need firewall rules to govern traffic.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">Changing firewall settings while connected over network can
result in being locked out of the system.</xccdf-1.2:warning>
                <xccdf-1.2:rationale>Without a firewall rule configured for open ports default
firewall policy will drop all packets to these ports.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#not_package_nftables_and_not_package_ufw"/>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-iptables_rules_for_open_ports_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_set_iptables_default_rule" selected="false" severity="medium">
                <xccdf-1.2:title>Set Default iptables Policy for Incoming Packets</xccdf-1.2:title>
                <xccdf-1.2:description>To set the default policy to DROP (instead of ACCEPT) for
the built-in INPUT chain which processes incoming packets,
add or correct the following line in

<html:code>/etc/sysconfig/iptables</html:code>:

<html:pre>:INPUT DROP [0:0]</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CA-3(5)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(23)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>In <html:code>iptables</html:code> the default policy is applied only after all
the applicable rules in the table are examined for a match. Setting the
default policy to <html:code>DROP</html:code> implements proper design for a firewall, i.e.
any packets which are not explicitly permitted should not be
accepted.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#not_package_nftables_and_not_package_ufw"/>
                <xccdf-1.2:fix id="set_iptables_default_rule" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q iptables &amp;&amp; { ( ( ! ( rpm --quiet -q nftables ) &amp;&amp; ! ( rpm --quiet -q ufw ) ) ); }; then

sed -i 's/^:INPUT ACCEPT.*/:INPUT DROP [0:0]/g' /etc/sysconfig/iptables

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_set_iptables_default_rule_forward" selected="false" severity="medium">
                <xccdf-1.2:title>Set Default iptables Policy for Forwarded Packets</xccdf-1.2:title>
                <xccdf-1.2:description>To set the default policy to DROP (instead of ACCEPT) for
the built-in FORWARD chain which processes packets that will be forwarded from
one interface to another,
add or correct the following line in
<html:code>/etc/sysconfig/iptables</html:code>:
<html:pre>:FORWARD DROP [0:0]</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CA-3(5)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(23)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>In <html:code>iptables</html:code>, the default policy is applied only after all
the applicable rules in the table are examined for a match. Setting the
default policy to <html:code>DROP</html:code> implements proper design for a firewall, i.e.
any packets which are not explicitly permitted should not be
accepted.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="set_iptables_default_rule_forward" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q iptables; then

sed -i 's/^:FORWARD ACCEPT.*/:FORWARD DROP [0:0]/g' /etc/sysconfig/iptables

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-set_iptables_default_rule_forward_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_network-ipv6">
            <xccdf-1.2:title>IPv6</xccdf-1.2:title>
            <xccdf-1.2:description>The system includes support for Internet Protocol
version 6. A major and often-mentioned improvement over IPv4 is its
enormous increase in the number of available addresses. Another
important feature is its support for automatic configuration of
many network settings.</xccdf-1.2:description>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_ipv6">
              <xccdf-1.2:title>Disable Support for IPv6 Unless Needed</xccdf-1.2:title>
              <xccdf-1.2:description>Despite configuration that suggests support for IPv6 has
been disabled, link-local IPv6 address auto-configuration occurs
even when only an IPv4 address is assigned. The only way to
effectively prevent execution of the IPv6 networking stack is to
instruct the system not to activate the IPv6 kernel module.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_ipv6_disable_argument" selected="false" severity="low">
                <xccdf-1.2:title>Ensure IPv6 is disabled through kernel boot parameter</xccdf-1.2:title>
                <xccdf-1.2:description>To disable IPv6 protocol support in the Linux kernel,
add the argument <html:code>ipv6.disable=1</html:code> to the default
GRUB2 command line for the Linux operating system.
Configure the default Grub2 kernel command line to contain ipv6.disable=1 as follows:
<html:pre># grub2-editenv - set "$(grub2-editenv - list | grep kernelopts) ipv6.disable=1"</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.3.2</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Any unnecessary network stacks, including IPv6, should be disabled to reduce
the vulnerability to exploitation.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#grub2"/>
                <xccdf-1.2:fix id="grub2_ipv6_disable_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q grub2-common; then

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    KARGS_DIR="/usr/lib/bootc/kargs.d/"
    if grep -q -E "ipv6.disable" "$KARGS_DIR/*.toml" ; then
        sed -i -E "s/^(\s*kargs\s*=\s*\[.*)\"ipv6.disable=[^\"]*\"(.*]\s*)/\1\"ipv6.disable=1\"\2/" "$KARGS_DIR/*.toml"
    else
        echo "kargs = [\"ipv6.disable=1\"]" &gt;&gt; "$KARGS_DIR/10-ipv6_disable.toml"
    fi
else

    grubby --update-kernel=ALL --args=ipv6.disable=1 --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_ipv6_disable_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSS-Req-1.3.1
  - PCI-DSS-Req-1.3.2
  - grub2_ipv6_disable_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Check if ipv6.disable argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when: '"grub2-common" in ansible_facts.packages'
  tags:
  - PCI-DSS-Req-1.3.1
  - PCI-DSS-Req-1.3.2
  - grub2_ipv6_disable_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Check if ipv6.disable argument is already present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"grub2-common" in ansible_facts.packages'
  tags:
  - PCI-DSS-Req-1.3.1
  - PCI-DSS-Req-1.3.2
  - grub2_ipv6_disable_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --args="ipv6.disable=1"
  when:
  - '"grub2-common" in ansible_facts.packages'
  - (grubby_info.stdout is not search('ipv6.disable=1')) or ((etc_default_grub['content']
    | b64decode) is not search('ipv6.disable=1'))
  tags:
  - PCI-DSS-Req-1.3.1
  - PCI-DSS-Req-1.3.2
  - grub2_ipv6_disable_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="grub2_ipv6_disable_argument" system="urn:redhat:osbuild:blueprint">[customizations.kernel]
append = "ipv6.disable=1"
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_ipv6_disable_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kickstart">
bootloader ipv6.disable=1
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_ipv6_disable_argument:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_ipv6_disable_argument_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_ipv6_option_disabled" selected="false" severity="medium">
                <xccdf-1.2:title>Disable IPv6 Networking Support Automatic Loading</xccdf-1.2:title>
                <xccdf-1.2:description>To prevent the IPv6 kernel module (<html:code>ipv6</html:code>) from binding to the
IPv6 networking stack, add the following line to
<html:code>/etc/modprobe.d/disabled.conf</html:code> (or another file in
<html:code>/etc/modprobe.d</html:code>):
<html:pre>options ipv6 disable=1</html:pre>
This permits the IPv6 module to be loaded (and thus satisfy other modules that
depend on it), while disabling support for the IPv6 protocol.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Any unnecessary network stacks - including IPv6 - should be disabled, to reduce
the vulnerability to exploitation.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix id="kernel_module_ipv6_option_disabled" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Prevent the IPv6 kernel module (ipv6) from loading the IPv6 networking stack
echo "options ipv6 disable=1" &gt; /etc/modprobe.d/ipv6.conf

# Since according to: https://access.redhat.com/solutions/72733
# "ipv6 disable=1" options doesn't always disable the IPv6 networking stack from
# loading, instruct also sysctl configuration to disable IPv6 according to:
# https://access.redhat.com/solutions/8709#rhel6disable

declare -a IPV6_SETTINGS=("net.ipv6.conf.all.disable_ipv6" "net.ipv6.conf.default.disable_ipv6")

for setting in "${IPV6_SETTINGS[@]}"
do
	# Set runtime =1 for setting
	/sbin/sysctl -q -n -w "$setting=1"

	# If setting is present in /etc/sysctl.conf, change value to "1"
	# else, add "$setting = 1" to /etc/sysctl.conf
	if grep -q ^"$setting" /etc/sysctl.conf ; then
		sed -i "s/^$setting.*/$setting = 1/g" /etc/sysctl.conf
	else
		echo "" &gt;&gt; /etc/sysctl.conf
		echo "# Set $setting = 1 per security requirements" &gt;&gt; /etc/sysctl.conf
		echo "$setting = 1" &gt;&gt; /etc/sysctl.conf
	fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_ipv6_option_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_ipv6_option_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required

- name: Disable IPv6 Networking kernel module
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/ipv6.conf
    regexp: ^options\s+ipv6\s+disable=\d
    line: options ipv6 disable=1
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_ipv6_option_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required

- name: Ensure disable_ipv6 (all and default) is set to 1
  ansible.posix.sysctl:
    name: '{{ item }}'
    value: '1'
    state: present
    reload: true
  with_items:
  - net.ipv6.conf.all.disable_ipv6
  - net.ipv6.conf.default.disable_ipv6
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_ipv6_option_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_ipv6_option_disabled:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_module_ipv6_option_disabled_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_network_ipv6_disable_interfaces" selected="false" severity="unknown">
                <xccdf-1.2:title>Disable Interface Usage of IPv6</xccdf-1.2:title>
                <xccdf-1.2:description>To disable interface usage of IPv6, add or correct the following lines in <html:code>/etc/sysconfig/network</html:code>:
<html:pre>NETWORKING_IPV6=no
IPV6INIT=no</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale/>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_network_ipv6_disable_rpc" selected="false" severity="unknown">
                <xccdf-1.2:title>Disable Support for RPC IPv6</xccdf-1.2:title>
                <xccdf-1.2:description>RPC services for NFSv4 try to load transport modules for
<html:code>udp6</html:code> and <html:code>tcp6</html:code> by default, even if IPv6 has been disabled in
<html:code>/etc/modprobe.d</html:code>. To prevent RPC services such as <html:code>rpc.mountd</html:code>
from attempting to start IPv6 network listeners, remove or comment out the
following two lines in <html:code>/etc/netconfig</html:code>:
<html:pre>udp6       tpi_clts      v     inet6    udp     -       -
tcp6       tpi_cots_ord  v     inet6    tcp     -       -</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:rationale/>
                <xccdf-1.2:fix id="network_ipv6_disable_rpc" system="urn:xccdf:fix:script:sh">
# Drop 'tcp6' and 'udp6' entries from /etc/netconfig to prevent RPC
# services for NFSv4 from attempting to start IPv6 network listeners
declare -a IPV6_RPC_ENTRIES=("tcp6" "udp6")

for rpc_entry in "${IPV6_RPC_ENTRIES[@]}"
do
	sed -i "/^${rpc_entry}[[:space:]]\\+tpi\\_.*inet6.*/d" /etc/netconfig
done
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-network_ipv6_disable_rpc:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_disable_ipv6" selected="false" severity="medium">
                <xccdf-1.2:title>Disable IPv6 Addressing on All IPv6 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To disable support for (<html:code>ipv6</html:code>) addressing on all interface add the following line to
<html:code>/etc/sysctl.d/ipv6.conf</html:code> (or another file in <html:code>/etc/sysctl.d</html:code>):
<html:pre>net.ipv6.conf.all.disable_ipv6 = 1</html:pre>
This disables IPv6 on all network interfaces as other services and system
functionality require the IPv6 stack loaded to work.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Any unnecessary network stacks - including IPv6 - should be disabled, to reduce
the vulnerability to exploitation.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_disable_ipv6" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.all.disable_ipv6 from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.all.disable_ipv6.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.all.disable_ipv6" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_all_disable_ipv6.conf'


#
# Set runtime for net.ipv6.conf.all.disable_ipv6
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.all.disable_ipv6="1"
fi

#
# If net.ipv6.conf.all.disable_ipv6 present in /etc/sysctl.conf, change value to "1"
#	else, add "net.ipv6.conf.all.disable_ipv6 = 1" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.all.disable_ipv6")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "1"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.all.disable_ipv6\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.all.disable_ipv6\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_disable_ipv6" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_disable_ipv6

- name: Disable IPv6 Addressing on All IPv6 Interfaces - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_disable_ipv6

- name: Disable IPv6 Addressing on All IPv6 Interfaces - Find all files that contain
    net.ipv6.conf.all.disable_ipv6
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.disable_ipv6\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_disable_ipv6

- name: Disable IPv6 Addressing on All IPv6 Interfaces - Find all files that set net.ipv6.conf.all.disable_ipv6
    to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.disable_ipv6\s*=\s*1$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_disable_ipv6

- name: Disable IPv6 Addressing on All IPv6 Interfaces - Comment out any occurrences
    of net.ipv6.conf.all.disable_ipv6 from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.all.disable_ipv6
    replace: '#net.ipv6.conf.all.disable_ipv6'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_disable_ipv6

- name: Disable IPv6 Addressing on All IPv6 Interfaces - Comment out any occurrences
    of net.ipv6.conf.all.disable_ipv6 from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.all.disable_ipv6
    replace: '#net.ipv6.conf.all.disable_ipv6'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_disable_ipv6

- name: Disable IPv6 Addressing on All IPv6 Interfaces - Ensure sysctl net.ipv6.conf.all.disable_ipv6
    is set to 1
  ansible.posix.sysctl:
    name: net.ipv6.conf.all.disable_ipv6
    value: '1'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_all_disable_ipv6.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_disable_ipv6
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_all_disable_ipv6:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_disable_ipv6" selected="false" severity="medium">
                <xccdf-1.2:title>Disable IPv6 Addressing on IPv6 Interfaces by Default</xccdf-1.2:title>
                <xccdf-1.2:description>To disable support for (<html:code>ipv6</html:code>) addressing on interfaces by default add the following line to
<html:code>/etc/sysctl.d/ipv6.conf</html:code> (or another file in <html:code>/etc/sysctl.d</html:code>):
<html:pre>net.ipv6.conf.default.disable_ipv6 = 1</html:pre>
This disables IPv6 on network interfaces by default as other services and system
functionality require the IPv6 stack loaded to work.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Any unnecessary network stacks - including IPv6 - should be disabled, to reduce
the vulnerability to exploitation.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_disable_ipv6" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.default.disable_ipv6 from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.default.disable_ipv6.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.default.disable_ipv6" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_default_disable_ipv6.conf'


#
# Set runtime for net.ipv6.conf.default.disable_ipv6
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.default.disable_ipv6="1"
fi

#
# If net.ipv6.conf.default.disable_ipv6 present in /etc/sysctl.conf, change value to "1"
#	else, add "net.ipv6.conf.default.disable_ipv6 = 1" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.default.disable_ipv6")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "1"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.default.disable_ipv6\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.default.disable_ipv6\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_disable_ipv6" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_disable_ipv6

- name: Disable IPv6 Addressing on IPv6 Interfaces by Default - Set fact for sysctl
    paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_disable_ipv6

- name: Disable IPv6 Addressing on IPv6 Interfaces by Default - Find all files that
    contain net.ipv6.conf.default.disable_ipv6
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.disable_ipv6\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_disable_ipv6

- name: Disable IPv6 Addressing on IPv6 Interfaces by Default - Find all files that
    set net.ipv6.conf.default.disable_ipv6 to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.disable_ipv6\s*=\s*1$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_disable_ipv6

- name: Disable IPv6 Addressing on IPv6 Interfaces by Default - Comment out any occurrences
    of net.ipv6.conf.default.disable_ipv6 from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.default.disable_ipv6
    replace: '#net.ipv6.conf.default.disable_ipv6'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_disable_ipv6

- name: Disable IPv6 Addressing on IPv6 Interfaces by Default - Comment out any occurrences
    of net.ipv6.conf.default.disable_ipv6 from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.default.disable_ipv6
    replace: '#net.ipv6.conf.default.disable_ipv6'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_disable_ipv6

- name: Disable IPv6 Addressing on IPv6 Interfaces by Default - Ensure sysctl net.ipv6.conf.default.disable_ipv6
    is set to 1
  ansible.posix.sysctl:
    name: net.ipv6.conf.default.disable_ipv6
    value: '1'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_default_disable_ipv6.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_disable_ipv6
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_default_disable_ipv6:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_configuring_ipv6">
              <xccdf-1.2:title>Configure IPv6 Settings if Necessary</xccdf-1.2:title>
              <xccdf-1.2:description>A major feature of IPv6 is the extent to which systems
implementing it can automatically configure their networking
devices using information from the network. From a security
perspective, manually configuring important configuration
information is preferable to accepting it from the network
in an unauthenticated fashion.</xccdf-1.2:description>
              <xccdf-1.2:platform idref="#ipv6_enabled"/>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_defrtr_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.all.accept_ra_defrtr</xccdf-1.2:title>
                <xccdf-1.2:description>Accept default router in router advertisements?</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_pinfo_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.all.accept_ra_pinfo</xccdf-1.2:title>
                <xccdf-1.2:description>Accept prefix information in router advertisements?</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.all.accept_ra_rtr_pref</xccdf-1.2:title>
                <xccdf-1.2:description>Accept router preference in router advertisements?</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.all.accept_ra</xccdf-1.2:title>
                <xccdf-1.2:description>Accept all router advertisements?</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_redirects_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.all.accept_redirects</xccdf-1.2:title>
                <xccdf-1.2:description>Toggle ICMP Redirect Acceptance</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_source_route_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.all.accept_source_route</xccdf-1.2:title>
                <xccdf-1.2:description>Trackers could be using source-routed packets to
generate traffic that seems to be intra-net, but actually was
created outside and has been redirected.</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_autoconf_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.all.autoconf</xccdf-1.2:title>
                <xccdf-1.2:description>Enable auto configuration on IPv6 interfaces</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_forwarding_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.all.forwarding</xccdf-1.2:title>
                <xccdf-1.2:description>Toggle IPv6 Forwarding</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_max_addresses_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.all.max_addresses</xccdf-1.2:title>
                <xccdf-1.2:description>Maximum number of autoconfigured IPv6 addresses</xccdf-1.2:description>
                <xccdf-1.2:value>1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_router_solicitations_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.all.router_solicitations</xccdf-1.2:title>
                <xccdf-1.2:description>Accept all router solicitations?</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_defrtr_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.default.accept_ra_defrtr</xccdf-1.2:title>
                <xccdf-1.2:description>Accept default router in router advertisements?</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_pinfo_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.default.accept_ra_pinfo</xccdf-1.2:title>
                <xccdf-1.2:description>Accept prefix information in router advertisements?</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.default.accept_ra_rtr_pref</xccdf-1.2:title>
                <xccdf-1.2:description>Accept router preference in router advertisements?</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.default.accept_ra</xccdf-1.2:title>
                <xccdf-1.2:description>Accept default router advertisements by default?</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_redirects_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.default.accept_redirects</xccdf-1.2:title>
                <xccdf-1.2:description>Toggle ICMP Redirect Acceptance By Default</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_source_route_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.default.accept_source_route</xccdf-1.2:title>
                <xccdf-1.2:description>Trackers could be using source-routed packets to
generate traffic that seems to be intra-net, but actually was
created outside and has been redirected.</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_autoconf_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.default.autoconf</xccdf-1.2:title>
                <xccdf-1.2:description>Enable auto configuration on IPv6 interfaces</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_forwarding_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.default.forwarding</xccdf-1.2:title>
                <xccdf-1.2:description>Toggle IPv6 default Forwarding</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_max_addresses_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.default.max_addresses</xccdf-1.2:title>
                <xccdf-1.2:description>Maximum number of autoconfigured IPv6 addresses</xccdf-1.2:description>
                <xccdf-1.2:value>1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_router_solicitations_value" type="number">
                <xccdf-1.2:title>net.ipv6.conf.default.router_solicitations</xccdf-1.2:title>
                <xccdf-1.2:description>Accept all router solicitations by default?</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_network_ipv6_default_gateway" selected="false" severity="unknown">
                <xccdf-1.2:title>Manually Assign IPv6 Router Address</xccdf-1.2:title>
                <xccdf-1.2:description>Edit the file
<html:code>/etc/sysconfig/network-scripts/ifcfg-<html:i>interface</html:i></html:code>, and add or correct
the following line (substituting your gateway IP as appropriate):
<html:pre>IPV6_DEFAULTGW=2001:0DB8::0001</html:pre>
Router addresses should be manually set and not accepted via any
auto-configuration or router advertisement.</xccdf-1.2:description>
                <xccdf-1.2:rationale/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-network_ipv6_default_gateway:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_network_ipv6_privacy_extensions" selected="false" severity="unknown">
                <xccdf-1.2:title>Use Privacy Extensions for Address</xccdf-1.2:title>
                <xccdf-1.2:description>To introduce randomness into the automatic generation of IPv6
addresses, add or correct the following line in
<html:code>/etc/sysconfig/network-scripts/ifcfg-<html:i>interface</html:i></html:code>:
<html:pre>IPV6_PRIVACY=rfc3041</html:pre>
Automatically-generated IPv6 addresses are based on the underlying hardware
(e.g. Ethernet) address, and so it becomes possible to track a piece of
hardware over its lifetime using its traffic. If it is important for a system's
IP address to not trivially reveal its hardware address, this setting should be
applied.</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:rationale/>
                <xccdf-1.2:fix id="network_ipv6_privacy_extensions" system="urn:xccdf:fix:script:sh">
APPLY_STRING="IPV6_PRIVACY=rfc3041"

# enable randomness in ipv6 address generation
for interface in /etc/sysconfig/network-scripts/ifcfg-*
do
    if ! grep -q "^IPV6_PRIVACY=" "$interface"; then
        echo "$APPLY_STRING" &gt;&gt; "$interface"
    else
        sed -i "s/^IPV6_PRIVACY=.*/$APPLY_STRING/" "$interface"
    fi
done
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-network_ipv6_privacy_extensions:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_network_ipv6_static_address" selected="false" severity="unknown">
                <xccdf-1.2:title>Manually Assign Global IPv6 Address</xccdf-1.2:title>
                <xccdf-1.2:description>To manually assign an IP address for an interface, edit the
file <html:code>/etc/sysconfig/network-scripts/ifcfg-<html:i>interface</html:i></html:code>. Add or correct the
following line (substituting the correct IPv6 address):
<html:pre>IPV6ADDR=2001:0DB8::ABCD/64</html:pre>
Manually assigning an IP address is preferable to accepting one from routers or
from the network otherwise. The example address here is an IPv6 address
reserved for documentation purposes, as defined by RFC3849.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1315</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1319</xccdf-1.2:reference>
                <xccdf-1.2:rationale/>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-network_ipv6_static_address:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra" selected="false" severity="medium">
                <xccdf-1.2:title>Configure Accepting Router Advertisements on All IPv6 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.all.accept_ra</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.all.accept_ra=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.all.accept_ra = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040261</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230541r1017303_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>An illicit router advertisement message could result in a man-in-the-middle attack.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_accept_ra" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.all.accept_ra from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.all.accept_ra.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.all.accept_ra" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_all_accept_ra.conf'

sysctl_net_ipv6_conf_all_accept_ra_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.all.accept_ra
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.all.accept_ra="$sysctl_net_ipv6_conf_all_accept_ra_value"
fi

#
# If net.ipv6.conf.all.accept_ra present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.all.accept_ra = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.all.accept_ra")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_all_accept_ra_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.all.accept_ra\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.all.accept_ra\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_accept_ra" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040261
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra
- name: XCCDF Value sysctl_net_ipv6_conf_all_accept_ra_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_all_accept_ra_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_value" use="legacy"/>
  tags:
    - always

- name: Configure Accepting Router Advertisements on All IPv6 Interfaces - Set fact
    for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040261
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra

- name: Configure Accepting Router Advertisements on All IPv6 Interfaces - Find all
    files that contain net.ipv6.conf.all.accept_ra
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.accept_ra\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040261
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra

- name: Configure Accepting Router Advertisements on All IPv6 Interfaces - Find all
    files that set net.ipv6.conf.all.accept_ra to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.accept_ra\s*=\s*{{ sysctl_net_ipv6_conf_all_accept_ra_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040261
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra

- name: Configure Accepting Router Advertisements on All IPv6 Interfaces - Comment
    out any occurrences of net.ipv6.conf.all.accept_ra from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.all.accept_ra
    replace: '#net.ipv6.conf.all.accept_ra'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-040261
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra

- name: Configure Accepting Router Advertisements on All IPv6 Interfaces - Comment
    out any occurrences of net.ipv6.conf.all.accept_ra from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.all.accept_ra
    replace: '#net.ipv6.conf.all.accept_ra'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040261
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra

- name: Configure Accepting Router Advertisements on All IPv6 Interfaces - Ensure
    sysctl net.ipv6.conf.all.accept_ra is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.all.accept_ra
    value: '{{ sysctl_net_ipv6_conf_all_accept_ra_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_all_accept_ra.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040261
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv6_conf_all_accept_ra" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv6.conf.all.accept_ra%3D0%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv6_conf_all_accept_ra.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra_defrtr" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.all.accept_ra_defrtr</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.all.accept_ra_defrtr=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.all.accept_ra_defrtr = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R13</xccdf-1.2:reference>
                <xccdf-1.2:rationale>An illicit router advertisement message could result in a man-in-the-middle attack.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_accept_ra_defrtr" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.all.accept_ra_defrtr from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.all.accept_ra_defrtr.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.all.accept_ra_defrtr" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_all_accept_ra_defrtr.conf'

sysctl_net_ipv6_conf_all_accept_ra_defrtr_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_defrtr_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.all.accept_ra_defrtr
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.all.accept_ra_defrtr="$sysctl_net_ipv6_conf_all_accept_ra_defrtr_value"
fi

#
# If net.ipv6.conf.all.accept_ra_defrtr present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.all.accept_ra_defrtr = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.all.accept_ra_defrtr")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_all_accept_ra_defrtr_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.all.accept_ra_defrtr\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.all.accept_ra_defrtr\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_accept_ra_defrtr" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_defrtr
  - unknown_severity
- name: XCCDF Value sysctl_net_ipv6_conf_all_accept_ra_defrtr_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_all_accept_ra_defrtr_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_defrtr_value" use="legacy"/>
  tags:
    - always

- name: Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces
    - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_defrtr
  - unknown_severity

- name: Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces
    - Find all files that contain net.ipv6.conf.all.accept_ra_defrtr
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.accept_ra_defrtr\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_defrtr
  - unknown_severity

- name: Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces
    - Find all files that set net.ipv6.conf.all.accept_ra_defrtr to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.accept_ra_defrtr\s*=\s*{{ sysctl_net_ipv6_conf_all_accept_ra_defrtr_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_defrtr
  - unknown_severity

- name: Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces
    - Comment out any occurrences of net.ipv6.conf.all.accept_ra_defrtr from config
    files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.all.accept_ra_defrtr
    replace: '#net.ipv6.conf.all.accept_ra_defrtr'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_defrtr
  - unknown_severity

- name: Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces
    - Comment out any occurrences of net.ipv6.conf.all.accept_ra_defrtr from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.all.accept_ra_defrtr
    replace: '#net.ipv6.conf.all.accept_ra_defrtr'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_defrtr
  - unknown_severity

- name: Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces
    - Ensure sysctl net.ipv6.conf.all.accept_ra_defrtr is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.all.accept_ra_defrtr
    value: '{{ sysctl_net_ipv6_conf_all_accept_ra_defrtr_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_all_accept_ra_defrtr.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_defrtr
  - unknown_severity
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_defrtr_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra_pinfo" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure Accepting Prefix Information in Router Advertisements on All IPv6 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.all.accept_ra_pinfo</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.all.accept_ra_pinfo=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.all.accept_ra_pinfo = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R13</xccdf-1.2:reference>
                <xccdf-1.2:rationale>An illicit router advertisement message could result in a man-in-the-middle attack.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_accept_ra_pinfo" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.all.accept_ra_pinfo from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.all.accept_ra_pinfo.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.all.accept_ra_pinfo" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_all_accept_ra_pinfo.conf'

sysctl_net_ipv6_conf_all_accept_ra_pinfo_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_pinfo_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.all.accept_ra_pinfo
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.all.accept_ra_pinfo="$sysctl_net_ipv6_conf_all_accept_ra_pinfo_value"
fi

#
# If net.ipv6.conf.all.accept_ra_pinfo present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.all.accept_ra_pinfo = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.all.accept_ra_pinfo")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_all_accept_ra_pinfo_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.all.accept_ra_pinfo\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.all.accept_ra_pinfo\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_accept_ra_pinfo" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_pinfo
  - unknown_severity
- name: XCCDF Value sysctl_net_ipv6_conf_all_accept_ra_pinfo_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_all_accept_ra_pinfo_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_pinfo_value" use="legacy"/>
  tags:
    - always

- name: Configure Accepting Prefix Information in Router Advertisements on All IPv6
    Interfaces - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_pinfo
  - unknown_severity

- name: Configure Accepting Prefix Information in Router Advertisements on All IPv6
    Interfaces - Find all files that contain net.ipv6.conf.all.accept_ra_pinfo
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.accept_ra_pinfo\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_pinfo
  - unknown_severity

- name: Configure Accepting Prefix Information in Router Advertisements on All IPv6
    Interfaces - Find all files that set net.ipv6.conf.all.accept_ra_pinfo to correct
    value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.accept_ra_pinfo\s*=\s*{{ sysctl_net_ipv6_conf_all_accept_ra_pinfo_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_pinfo
  - unknown_severity

- name: Configure Accepting Prefix Information in Router Advertisements on All IPv6
    Interfaces - Comment out any occurrences of net.ipv6.conf.all.accept_ra_pinfo
    from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.all.accept_ra_pinfo
    replace: '#net.ipv6.conf.all.accept_ra_pinfo'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_pinfo
  - unknown_severity

- name: Configure Accepting Prefix Information in Router Advertisements on All IPv6
    Interfaces - Comment out any occurrences of net.ipv6.conf.all.accept_ra_pinfo
    from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.all.accept_ra_pinfo
    replace: '#net.ipv6.conf.all.accept_ra_pinfo'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_pinfo
  - unknown_severity

- name: Configure Accepting Prefix Information in Router Advertisements on All IPv6
    Interfaces - Ensure sysctl net.ipv6.conf.all.accept_ra_pinfo is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.all.accept_ra_pinfo
    value: '{{ sysctl_net_ipv6_conf_all_accept_ra_pinfo_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_all_accept_ra_pinfo.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_pinfo
  - unknown_severity
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_pinfo_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure Accepting Router Preference in Router Advertisements on All IPv6 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.all.accept_ra_rtr_pref</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.all.accept_ra_rtr_pref=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.all.accept_ra_rtr_pref = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R13</xccdf-1.2:reference>
                <xccdf-1.2:rationale>An illicit router advertisement message could result in a man-in-the-middle attack.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_accept_ra_rtr_pref" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.all.accept_ra_rtr_pref from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.all.accept_ra_rtr_pref.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.all.accept_ra_rtr_pref" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_all_accept_ra_rtr_pref.conf'

sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.all.accept_ra_rtr_pref
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.all.accept_ra_rtr_pref="$sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_value"
fi

#
# If net.ipv6.conf.all.accept_ra_rtr_pref present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.all.accept_ra_rtr_pref = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.all.accept_ra_rtr_pref")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.all.accept_ra_rtr_pref\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.all.accept_ra_rtr_pref\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_accept_ra_rtr_pref" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_rtr_pref
  - unknown_severity
- name: XCCDF Value sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_value" use="legacy"/>
  tags:
    - always

- name: Configure Accepting Router Preference in Router Advertisements on All IPv6
    Interfaces - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_rtr_pref
  - unknown_severity

- name: Configure Accepting Router Preference in Router Advertisements on All IPv6
    Interfaces - Find all files that contain net.ipv6.conf.all.accept_ra_rtr_pref
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.accept_ra_rtr_pref\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_rtr_pref
  - unknown_severity

- name: Configure Accepting Router Preference in Router Advertisements on All IPv6
    Interfaces - Find all files that set net.ipv6.conf.all.accept_ra_rtr_pref to correct
    value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.accept_ra_rtr_pref\s*=\s*{{ sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_rtr_pref
  - unknown_severity

- name: Configure Accepting Router Preference in Router Advertisements on All IPv6
    Interfaces - Comment out any occurrences of net.ipv6.conf.all.accept_ra_rtr_pref
    from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.all.accept_ra_rtr_pref
    replace: '#net.ipv6.conf.all.accept_ra_rtr_pref'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_rtr_pref
  - unknown_severity

- name: Configure Accepting Router Preference in Router Advertisements on All IPv6
    Interfaces - Comment out any occurrences of net.ipv6.conf.all.accept_ra_rtr_pref
    from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.all.accept_ra_rtr_pref
    replace: '#net.ipv6.conf.all.accept_ra_rtr_pref'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_rtr_pref
  - unknown_severity

- name: Configure Accepting Router Preference in Router Advertisements on All IPv6
    Interfaces - Ensure sysctl net.ipv6.conf.all.accept_ra_rtr_pref is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.all.accept_ra_rtr_pref
    value: '{{ sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_all_accept_ra_rtr_pref.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_ra_rtr_pref
  - unknown_severity
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_redirects" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Accepting ICMP Redirects for All IPv6 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.all.accept_redirects</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.all.accept_redirects=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.all.accept_redirects = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6.1(iv)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040280</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230544r1017306_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>An illicit ICMP redirect message could result in a man-in-the-middle attack.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_accept_redirects" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.all.accept_redirects from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.all.accept_redirects.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.all.accept_redirects" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_all_accept_redirects.conf'

sysctl_net_ipv6_conf_all_accept_redirects_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_redirects_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.all.accept_redirects
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.all.accept_redirects="$sysctl_net_ipv6_conf_all_accept_redirects_value"
fi

#
# If net.ipv6.conf.all.accept_redirects present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.all.accept_redirects = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.all.accept_redirects")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_all_accept_redirects_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.all.accept_redirects\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.all.accept_redirects\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_accept_redirects" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040280
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_redirects
- name: XCCDF Value sysctl_net_ipv6_conf_all_accept_redirects_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_all_accept_redirects_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_redirects_value" use="legacy"/>
  tags:
    - always

- name: Disable Accepting ICMP Redirects for All IPv6 Interfaces - Set fact for sysctl
    paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040280
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_redirects

- name: Disable Accepting ICMP Redirects for All IPv6 Interfaces - Find all files
    that contain net.ipv6.conf.all.accept_redirects
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.accept_redirects\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040280
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_redirects

- name: Disable Accepting ICMP Redirects for All IPv6 Interfaces - Find all files
    that set net.ipv6.conf.all.accept_redirects to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.accept_redirects\s*=\s*{{ sysctl_net_ipv6_conf_all_accept_redirects_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040280
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_redirects

- name: Disable Accepting ICMP Redirects for All IPv6 Interfaces - Comment out any
    occurrences of net.ipv6.conf.all.accept_redirects from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.all.accept_redirects
    replace: '#net.ipv6.conf.all.accept_redirects'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-040280
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_redirects

- name: Disable Accepting ICMP Redirects for All IPv6 Interfaces - Comment out any
    occurrences of net.ipv6.conf.all.accept_redirects from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.all.accept_redirects
    replace: '#net.ipv6.conf.all.accept_redirects'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040280
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_redirects

- name: Disable Accepting ICMP Redirects for All IPv6 Interfaces - Ensure sysctl net.ipv6.conf.all.accept_redirects
    is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.all.accept_redirects
    value: '{{ sysctl_net_ipv6_conf_all_accept_redirects_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_all_accept_redirects.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040280
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_redirects
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv6_conf_all_accept_redirects" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv6.conf.all.accept_redirects%3D0%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv6_conf_all_accept_redirects.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_all_accept_redirects_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_redirects_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_all_accept_redirects:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_source_route" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.all.accept_source_route</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.all.accept_source_route=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.all.accept_source_route = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040240</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230538r1017300_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Source-routed packets allow the source of the packet to suggest routers
forward the packet along a different path than configured on the router, which can
be used to bypass network security measures. This requirement applies only to the
forwarding of source-routerd traffic, such as when IPv6 forwarding is enabled and
the system is functioning as a router.
<html:br/><html:br/>
Accepting source-routed packets in the IPv6 protocol has few legitimate
uses. It should be disabled unless it is absolutely required.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_accept_source_route" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.all.accept_source_route from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.all.accept_source_route.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.all.accept_source_route" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_all_accept_source_route.conf'

sysctl_net_ipv6_conf_all_accept_source_route_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_source_route_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.all.accept_source_route
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.all.accept_source_route="$sysctl_net_ipv6_conf_all_accept_source_route_value"
fi

#
# If net.ipv6.conf.all.accept_source_route present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.all.accept_source_route = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.all.accept_source_route")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_all_accept_source_route_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.all.accept_source_route\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.all.accept_source_route\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_accept_source_route" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040240
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_source_route
- name: XCCDF Value sysctl_net_ipv6_conf_all_accept_source_route_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_all_accept_source_route_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_source_route_value" use="legacy"/>
  tags:
    - always

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces
    - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040240
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces
    - Find all files that contain net.ipv6.conf.all.accept_source_route
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.accept_source_route\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040240
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces
    - Find all files that set net.ipv6.conf.all.accept_source_route to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.accept_source_route\s*=\s*{{ sysctl_net_ipv6_conf_all_accept_source_route_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040240
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces
    - Comment out any occurrences of net.ipv6.conf.all.accept_source_route from config
    files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.all.accept_source_route
    replace: '#net.ipv6.conf.all.accept_source_route'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-040240
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces
    - Comment out any occurrences of net.ipv6.conf.all.accept_source_route from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.all.accept_source_route
    replace: '#net.ipv6.conf.all.accept_source_route'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040240
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces
    - Ensure sysctl net.ipv6.conf.all.accept_source_route is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.all.accept_source_route
    value: '{{ sysctl_net_ipv6_conf_all_accept_source_route_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_all_accept_source_route.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040240
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_accept_source_route
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv6_conf_all_accept_source_route" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv6.conf.all.accept_source_route%3D0%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv6_conf_all_accept_source_route.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_all_accept_source_route_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_accept_source_route_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_all_accept_source_route:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_autoconf" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure Auto Configuration on All IPv6 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.all.autoconf</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.all.autoconf=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.all.autoconf = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R13</xccdf-1.2:reference>
                <xccdf-1.2:rationale>An illicit router advertisement message could result in a man-in-the-middle attack.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_autoconf" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.all.autoconf from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.all.autoconf.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.all.autoconf" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_all_autoconf.conf'

sysctl_net_ipv6_conf_all_autoconf_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_autoconf_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.all.autoconf
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.all.autoconf="$sysctl_net_ipv6_conf_all_autoconf_value"
fi

#
# If net.ipv6.conf.all.autoconf present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.all.autoconf = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.all.autoconf")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_all_autoconf_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.all.autoconf\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.all.autoconf\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_autoconf" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_autoconf
  - unknown_severity
- name: XCCDF Value sysctl_net_ipv6_conf_all_autoconf_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_all_autoconf_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_autoconf_value" use="legacy"/>
  tags:
    - always

- name: Configure Auto Configuration on All IPv6 Interfaces - Set fact for sysctl
    paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_autoconf
  - unknown_severity

- name: Configure Auto Configuration on All IPv6 Interfaces - Find all files that
    contain net.ipv6.conf.all.autoconf
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.autoconf\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_autoconf
  - unknown_severity

- name: Configure Auto Configuration on All IPv6 Interfaces - Find all files that
    set net.ipv6.conf.all.autoconf to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.autoconf\s*=\s*{{ sysctl_net_ipv6_conf_all_autoconf_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_autoconf
  - unknown_severity

- name: Configure Auto Configuration on All IPv6 Interfaces - Comment out any occurrences
    of net.ipv6.conf.all.autoconf from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.all.autoconf
    replace: '#net.ipv6.conf.all.autoconf'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_autoconf
  - unknown_severity

- name: Configure Auto Configuration on All IPv6 Interfaces - Comment out any occurrences
    of net.ipv6.conf.all.autoconf from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.all.autoconf
    replace: '#net.ipv6.conf.all.autoconf'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_autoconf
  - unknown_severity

- name: Configure Auto Configuration on All IPv6 Interfaces - Ensure sysctl net.ipv6.conf.all.autoconf
    is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.all.autoconf
    value: '{{ sysctl_net_ipv6_conf_all_autoconf_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_all_autoconf.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_autoconf
  - unknown_severity
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_all_autoconf_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_autoconf_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_all_autoconf:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_forwarding" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel Parameter for IPv6 Forwarding</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.all.forwarding</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.all.forwarding=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.all.forwarding = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6.1(iv)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040260</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230540r1017302_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>IP forwarding permits the kernel to forward packets from one network
interface to another. The ability to forward packets between two networks is
only appropriate for systems acting as routers.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_forwarding" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.all.forwarding from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.all.forwarding.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.all.forwarding" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_all_forwarding.conf'

sysctl_net_ipv6_conf_all_forwarding_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_forwarding_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.all.forwarding
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.all.forwarding="$sysctl_net_ipv6_conf_all_forwarding_value"
fi

#
# If net.ipv6.conf.all.forwarding present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.all.forwarding = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.all.forwarding")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_all_forwarding_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.all.forwarding\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.all.forwarding\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_forwarding" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040260
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_forwarding
- name: XCCDF Value sysctl_net_ipv6_conf_all_forwarding_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_all_forwarding_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_forwarding_value" use="legacy"/>
  tags:
    - always

- name: Disable Kernel Parameter for IPv6 Forwarding - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040260
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_forwarding

- name: Disable Kernel Parameter for IPv6 Forwarding - Find all files that contain
    net.ipv6.conf.all.forwarding
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.forwarding\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040260
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_forwarding

- name: Disable Kernel Parameter for IPv6 Forwarding - Find all files that set net.ipv6.conf.all.forwarding
    to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.forwarding\s*=\s*{{ sysctl_net_ipv6_conf_all_forwarding_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040260
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_forwarding

- name: Disable Kernel Parameter for IPv6 Forwarding - Comment out any occurrences
    of net.ipv6.conf.all.forwarding from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.all.forwarding
    replace: '#net.ipv6.conf.all.forwarding'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-040260
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_forwarding

- name: Disable Kernel Parameter for IPv6 Forwarding - Comment out any occurrences
    of net.ipv6.conf.all.forwarding from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.all.forwarding
    replace: '#net.ipv6.conf.all.forwarding'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040260
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_forwarding

- name: Disable Kernel Parameter for IPv6 Forwarding - Ensure sysctl net.ipv6.conf.all.forwarding
    is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.all.forwarding
    value: '{{ sysctl_net_ipv6_conf_all_forwarding_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_all_forwarding.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040260
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_all_forwarding
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_all_forwarding_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_forwarding_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_all_forwarding:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_max_addresses" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.all.max_addresses</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.all.max_addresses=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.all.max_addresses = 1</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R13</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The number of global unicast IPv6 addresses for each interface should be limited exactly to the number of statically configured addresses.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_max_addresses" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.all.max_addresses from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.all.max_addresses.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.all.max_addresses" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_all_max_addresses.conf'

sysctl_net_ipv6_conf_all_max_addresses_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_max_addresses_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.all.max_addresses
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.all.max_addresses="$sysctl_net_ipv6_conf_all_max_addresses_value"
fi

#
# If net.ipv6.conf.all.max_addresses present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.all.max_addresses = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.all.max_addresses")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_all_max_addresses_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.all.max_addresses\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.all.max_addresses\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_max_addresses" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_max_addresses
  - unknown_severity
- name: XCCDF Value sysctl_net_ipv6_conf_all_max_addresses_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_all_max_addresses_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_max_addresses_value" use="legacy"/>
  tags:
    - always

- name: Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces
    - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_max_addresses
  - unknown_severity

- name: Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces
    - Find all files that contain net.ipv6.conf.all.max_addresses
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.max_addresses\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_max_addresses
  - unknown_severity

- name: Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces
    - Find all files that set net.ipv6.conf.all.max_addresses to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.max_addresses\s*=\s*{{ sysctl_net_ipv6_conf_all_max_addresses_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_max_addresses
  - unknown_severity

- name: Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces
    - Comment out any occurrences of net.ipv6.conf.all.max_addresses from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.all.max_addresses
    replace: '#net.ipv6.conf.all.max_addresses'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_max_addresses
  - unknown_severity

- name: Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces
    - Comment out any occurrences of net.ipv6.conf.all.max_addresses from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.all.max_addresses
    replace: '#net.ipv6.conf.all.max_addresses'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_max_addresses
  - unknown_severity

- name: Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces
    - Ensure sysctl net.ipv6.conf.all.max_addresses is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.all.max_addresses
    value: '{{ sysctl_net_ipv6_conf_all_max_addresses_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_all_max_addresses.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_max_addresses
  - unknown_severity
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_all_max_addresses_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_max_addresses_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_all_max_addresses:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_all_max_addresses_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_router_solicitations" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure Denying Router Solicitations on All IPv6 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.all.router_solicitations</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.all.router_solicitations=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.all.router_solicitations = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R13</xccdf-1.2:reference>
                <xccdf-1.2:rationale>To prevent discovery of the system by other systems, router solicitation requests should be denied.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_router_solicitations" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.all.router_solicitations from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.all.router_solicitations.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.all.router_solicitations" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_all_router_solicitations.conf'

sysctl_net_ipv6_conf_all_router_solicitations_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_router_solicitations_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.all.router_solicitations
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.all.router_solicitations="$sysctl_net_ipv6_conf_all_router_solicitations_value"
fi

#
# If net.ipv6.conf.all.router_solicitations present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.all.router_solicitations = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.all.router_solicitations")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_all_router_solicitations_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.all.router_solicitations\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.all.router_solicitations\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_all_router_solicitations" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_router_solicitations
  - unknown_severity
- name: XCCDF Value sysctl_net_ipv6_conf_all_router_solicitations_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_all_router_solicitations_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_router_solicitations_value" use="legacy"/>
  tags:
    - always

- name: Configure Denying Router Solicitations on All IPv6 Interfaces - Set fact for
    sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_router_solicitations
  - unknown_severity

- name: Configure Denying Router Solicitations on All IPv6 Interfaces - Find all files
    that contain net.ipv6.conf.all.router_solicitations
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.router_solicitations\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_router_solicitations
  - unknown_severity

- name: Configure Denying Router Solicitations on All IPv6 Interfaces - Find all files
    that set net.ipv6.conf.all.router_solicitations to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.all.router_solicitations\s*=\s*{{ sysctl_net_ipv6_conf_all_router_solicitations_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_router_solicitations
  - unknown_severity

- name: Configure Denying Router Solicitations on All IPv6 Interfaces - Comment out
    any occurrences of net.ipv6.conf.all.router_solicitations from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.all.router_solicitations
    replace: '#net.ipv6.conf.all.router_solicitations'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_router_solicitations
  - unknown_severity

- name: Configure Denying Router Solicitations on All IPv6 Interfaces - Comment out
    any occurrences of net.ipv6.conf.all.router_solicitations from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.all.router_solicitations
    replace: '#net.ipv6.conf.all.router_solicitations'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_router_solicitations
  - unknown_severity

- name: Configure Denying Router Solicitations on All IPv6 Interfaces - Ensure sysctl
    net.ipv6.conf.all.router_solicitations is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.all.router_solicitations
    value: '{{ sysctl_net_ipv6_conf_all_router_solicitations_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_all_router_solicitations.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_all_router_solicitations
  - unknown_severity
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_all_router_solicitations_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_all_router_solicitations_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_all_router_solicitations:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_all_router_solicitations_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Accepting Router Advertisements on all IPv6 Interfaces by Default</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.default.accept_ra</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.default.accept_ra=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.default.accept_ra = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.2.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040262</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230542r1017304_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>An illicit router advertisement message could result in a man-in-the-middle attack.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_accept_ra" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.default.accept_ra from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.default.accept_ra.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.default.accept_ra" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_default_accept_ra.conf'

sysctl_net_ipv6_conf_default_accept_ra_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.default.accept_ra
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.default.accept_ra="$sysctl_net_ipv6_conf_default_accept_ra_value"
fi

#
# If net.ipv6.conf.default.accept_ra present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.default.accept_ra = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.default.accept_ra")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_default_accept_ra_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.default.accept_ra\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.default.accept_ra\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_accept_ra" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040262
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra
- name: XCCDF Value sysctl_net_ipv6_conf_default_accept_ra_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_default_accept_ra_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_value" use="legacy"/>
  tags:
    - always

- name: Disable Accepting Router Advertisements on all IPv6 Interfaces by Default
    - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040262
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra

- name: Disable Accepting Router Advertisements on all IPv6 Interfaces by Default
    - Find all files that contain net.ipv6.conf.default.accept_ra
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.accept_ra\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040262
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra

- name: Disable Accepting Router Advertisements on all IPv6 Interfaces by Default
    - Find all files that set net.ipv6.conf.default.accept_ra to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.accept_ra\s*=\s*{{ sysctl_net_ipv6_conf_default_accept_ra_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040262
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra

- name: Disable Accepting Router Advertisements on all IPv6 Interfaces by Default
    - Comment out any occurrences of net.ipv6.conf.default.accept_ra from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.default.accept_ra
    replace: '#net.ipv6.conf.default.accept_ra'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-040262
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra

- name: Disable Accepting Router Advertisements on all IPv6 Interfaces by Default
    - Comment out any occurrences of net.ipv6.conf.default.accept_ra from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.default.accept_ra
    replace: '#net.ipv6.conf.default.accept_ra'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040262
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra

- name: Disable Accepting Router Advertisements on all IPv6 Interfaces by Default
    - Ensure sysctl net.ipv6.conf.default.accept_ra is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.default.accept_ra
    value: '{{ sysctl_net_ipv6_conf_default_accept_ra_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_default_accept_ra.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040262
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv6_conf_default_accept_ra" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv6.conf.default.accept_ra%3D0%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv6_conf_default_accept_ra.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra_defrtr" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces By Default</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.default.accept_ra_defrtr</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.default.accept_ra_defrtr=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.default.accept_ra_defrtr = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R13</xccdf-1.2:reference>
                <xccdf-1.2:rationale>An illicit router advertisement message could result in a man-in-the-middle attack.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_accept_ra_defrtr" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.default.accept_ra_defrtr from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.default.accept_ra_defrtr.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.default.accept_ra_defrtr" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_default_accept_ra_defrtr.conf'

sysctl_net_ipv6_conf_default_accept_ra_defrtr_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_defrtr_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.default.accept_ra_defrtr
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.default.accept_ra_defrtr="$sysctl_net_ipv6_conf_default_accept_ra_defrtr_value"
fi

#
# If net.ipv6.conf.default.accept_ra_defrtr present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.default.accept_ra_defrtr = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.default.accept_ra_defrtr")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_default_accept_ra_defrtr_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.default.accept_ra_defrtr\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.default.accept_ra_defrtr\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_accept_ra_defrtr" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_defrtr
  - unknown_severity
- name: XCCDF Value sysctl_net_ipv6_conf_default_accept_ra_defrtr_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_default_accept_ra_defrtr_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_defrtr_value" use="legacy"/>
  tags:
    - always

- name: Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces
    By Default - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_defrtr
  - unknown_severity

- name: Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces
    By Default - Find all files that contain net.ipv6.conf.default.accept_ra_defrtr
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.accept_ra_defrtr\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_defrtr
  - unknown_severity

- name: Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces
    By Default - Find all files that set net.ipv6.conf.default.accept_ra_defrtr to
    correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.accept_ra_defrtr\s*=\s*{{ sysctl_net_ipv6_conf_default_accept_ra_defrtr_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_defrtr
  - unknown_severity

- name: Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces
    By Default - Comment out any occurrences of net.ipv6.conf.default.accept_ra_defrtr
    from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.default.accept_ra_defrtr
    replace: '#net.ipv6.conf.default.accept_ra_defrtr'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_defrtr
  - unknown_severity

- name: Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces
    By Default - Comment out any occurrences of net.ipv6.conf.default.accept_ra_defrtr
    from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.default.accept_ra_defrtr
    replace: '#net.ipv6.conf.default.accept_ra_defrtr'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_defrtr
  - unknown_severity

- name: Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces
    By Default - Ensure sysctl net.ipv6.conf.default.accept_ra_defrtr is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.default.accept_ra_defrtr
    value: '{{ sysctl_net_ipv6_conf_default_accept_ra_defrtr_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_default_accept_ra_defrtr.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_defrtr
  - unknown_severity
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_defrtr_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra_pinfo" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure Accepting Prefix Information in Router Advertisements on All IPv6 Interfaces By Default</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.default.accept_ra_pinfo</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.default.accept_ra_pinfo=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.default.accept_ra_pinfo = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R13</xccdf-1.2:reference>
                <xccdf-1.2:rationale>An illicit router advertisement message could result in a man-in-the-middle attack.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_accept_ra_pinfo" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.default.accept_ra_pinfo from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.default.accept_ra_pinfo.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.default.accept_ra_pinfo" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_default_accept_ra_pinfo.conf'

sysctl_net_ipv6_conf_default_accept_ra_pinfo_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_pinfo_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.default.accept_ra_pinfo
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.default.accept_ra_pinfo="$sysctl_net_ipv6_conf_default_accept_ra_pinfo_value"
fi

#
# If net.ipv6.conf.default.accept_ra_pinfo present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.default.accept_ra_pinfo = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.default.accept_ra_pinfo")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_default_accept_ra_pinfo_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.default.accept_ra_pinfo\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.default.accept_ra_pinfo\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_accept_ra_pinfo" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_pinfo
  - unknown_severity
- name: XCCDF Value sysctl_net_ipv6_conf_default_accept_ra_pinfo_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_default_accept_ra_pinfo_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_pinfo_value" use="legacy"/>
  tags:
    - always

- name: Configure Accepting Prefix Information in Router Advertisements on All IPv6
    Interfaces By Default - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_pinfo
  - unknown_severity

- name: Configure Accepting Prefix Information in Router Advertisements on All IPv6
    Interfaces By Default - Find all files that contain net.ipv6.conf.default.accept_ra_pinfo
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.accept_ra_pinfo\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_pinfo
  - unknown_severity

- name: Configure Accepting Prefix Information in Router Advertisements on All IPv6
    Interfaces By Default - Find all files that set net.ipv6.conf.default.accept_ra_pinfo
    to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.accept_ra_pinfo\s*=\s*{{ sysctl_net_ipv6_conf_default_accept_ra_pinfo_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_pinfo
  - unknown_severity

- name: Configure Accepting Prefix Information in Router Advertisements on All IPv6
    Interfaces By Default - Comment out any occurrences of net.ipv6.conf.default.accept_ra_pinfo
    from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.default.accept_ra_pinfo
    replace: '#net.ipv6.conf.default.accept_ra_pinfo'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_pinfo
  - unknown_severity

- name: Configure Accepting Prefix Information in Router Advertisements on All IPv6
    Interfaces By Default - Comment out any occurrences of net.ipv6.conf.default.accept_ra_pinfo
    from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.default.accept_ra_pinfo
    replace: '#net.ipv6.conf.default.accept_ra_pinfo'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_pinfo
  - unknown_severity

- name: Configure Accepting Prefix Information in Router Advertisements on All IPv6
    Interfaces By Default - Ensure sysctl net.ipv6.conf.default.accept_ra_pinfo is
    set
  ansible.posix.sysctl:
    name: net.ipv6.conf.default.accept_ra_pinfo
    value: '{{ sysctl_net_ipv6_conf_default_accept_ra_pinfo_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_default_accept_ra_pinfo.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_pinfo
  - unknown_severity
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_pinfo_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure Accepting Router Preference in Router Advertisements on All IPv6 Interfaces By Default</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.default.accept_ra_rtr_pref</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.default.accept_ra_rtr_pref=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.default.accept_ra_rtr_pref = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R13</xccdf-1.2:reference>
                <xccdf-1.2:rationale>An illicit router advertisement message could result in a man-in-the-middle attack.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_accept_ra_rtr_pref" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.default.accept_ra_rtr_pref from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.default.accept_ra_rtr_pref.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.default.accept_ra_rtr_pref" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_default_accept_ra_rtr_pref.conf'

sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.default.accept_ra_rtr_pref
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.default.accept_ra_rtr_pref="$sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_value"
fi

#
# If net.ipv6.conf.default.accept_ra_rtr_pref present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.default.accept_ra_rtr_pref = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.default.accept_ra_rtr_pref")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.default.accept_ra_rtr_pref\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.default.accept_ra_rtr_pref\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_accept_ra_rtr_pref" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_rtr_pref
  - unknown_severity
- name: XCCDF Value sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_value" use="legacy"/>
  tags:
    - always

- name: Configure Accepting Router Preference in Router Advertisements on All IPv6
    Interfaces By Default - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_rtr_pref
  - unknown_severity

- name: Configure Accepting Router Preference in Router Advertisements on All IPv6
    Interfaces By Default - Find all files that contain net.ipv6.conf.default.accept_ra_rtr_pref
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.accept_ra_rtr_pref\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_rtr_pref
  - unknown_severity

- name: Configure Accepting Router Preference in Router Advertisements on All IPv6
    Interfaces By Default - Find all files that set net.ipv6.conf.default.accept_ra_rtr_pref
    to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.accept_ra_rtr_pref\s*=\s*{{ sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_rtr_pref
  - unknown_severity

- name: Configure Accepting Router Preference in Router Advertisements on All IPv6
    Interfaces By Default - Comment out any occurrences of net.ipv6.conf.default.accept_ra_rtr_pref
    from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.default.accept_ra_rtr_pref
    replace: '#net.ipv6.conf.default.accept_ra_rtr_pref'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_rtr_pref
  - unknown_severity

- name: Configure Accepting Router Preference in Router Advertisements on All IPv6
    Interfaces By Default - Comment out any occurrences of net.ipv6.conf.default.accept_ra_rtr_pref
    from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.default.accept_ra_rtr_pref
    replace: '#net.ipv6.conf.default.accept_ra_rtr_pref'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_rtr_pref
  - unknown_severity

- name: Configure Accepting Router Preference in Router Advertisements on All IPv6
    Interfaces By Default - Ensure sysctl net.ipv6.conf.default.accept_ra_rtr_pref
    is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.default.accept_ra_rtr_pref
    value: '{{ sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_default_accept_ra_rtr_pref.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_ra_rtr_pref
  - unknown_severity
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_redirects" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.default.accept_redirects</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.default.accept_redirects=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.default.accept_redirects = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040210</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230535r1017297_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>An illicit ICMP redirect message could result in a man-in-the-middle attack.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_accept_redirects" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.default.accept_redirects from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.default.accept_redirects.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.default.accept_redirects" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_default_accept_redirects.conf'

sysctl_net_ipv6_conf_default_accept_redirects_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_redirects_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.default.accept_redirects
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.default.accept_redirects="$sysctl_net_ipv6_conf_default_accept_redirects_value"
fi

#
# If net.ipv6.conf.default.accept_redirects present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.default.accept_redirects = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.default.accept_redirects")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_default_accept_redirects_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.default.accept_redirects\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.default.accept_redirects\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_accept_redirects" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040210
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_redirects
- name: XCCDF Value sysctl_net_ipv6_conf_default_accept_redirects_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_default_accept_redirects_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_redirects_value" use="legacy"/>
  tags:
    - always

- name: Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces
    - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040210
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_redirects

- name: Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces
    - Find all files that contain net.ipv6.conf.default.accept_redirects
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.accept_redirects\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040210
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_redirects

- name: Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces
    - Find all files that set net.ipv6.conf.default.accept_redirects to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.accept_redirects\s*=\s*{{ sysctl_net_ipv6_conf_default_accept_redirects_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040210
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_redirects

- name: Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces
    - Comment out any occurrences of net.ipv6.conf.default.accept_redirects from config
    files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.default.accept_redirects
    replace: '#net.ipv6.conf.default.accept_redirects'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-040210
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_redirects

- name: Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces
    - Comment out any occurrences of net.ipv6.conf.default.accept_redirects from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.default.accept_redirects
    replace: '#net.ipv6.conf.default.accept_redirects'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040210
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_redirects

- name: Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces
    - Ensure sysctl net.ipv6.conf.default.accept_redirects is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.default.accept_redirects
    value: '{{ sysctl_net_ipv6_conf_default_accept_redirects_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_default_accept_redirects.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040210
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_redirects
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv6_conf_default_accept_redirects" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv6.conf.default.accept_redirects%20%3D%200%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv6_conf_default_accept_redirects.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_default_accept_redirects_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_redirects_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_default_accept_redirects:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_source_route" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.default.accept_source_route</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.default.accept_source_route=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.default.accept_source_route = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6.1(iv)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040250</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230539r1017301_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Source-routed packets allow the source of the packet to suggest routers
forward the packet along a different path than configured on the router, which can
be used to bypass network security measures. This requirement applies only to the
forwarding of source-routerd traffic, such as when IPv6 forwarding is enabled and
the system is functioning as a router.

Accepting source-routed packets in the IPv6 protocol has few legitimate
uses. It should be disabled unless it is absolutely required.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_accept_source_route" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.default.accept_source_route from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.default.accept_source_route.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.default.accept_source_route" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_default_accept_source_route.conf'

sysctl_net_ipv6_conf_default_accept_source_route_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_source_route_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.default.accept_source_route
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.default.accept_source_route="$sysctl_net_ipv6_conf_default_accept_source_route_value"
fi

#
# If net.ipv6.conf.default.accept_source_route present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.default.accept_source_route = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.default.accept_source_route")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_default_accept_source_route_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.default.accept_source_route\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.default.accept_source_route\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_accept_source_route" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040250
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_source_route
- name: XCCDF Value sysctl_net_ipv6_conf_default_accept_source_route_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_default_accept_source_route_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_source_route_value" use="legacy"/>
  tags:
    - always

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces
    by Default - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040250
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces
    by Default - Find all files that contain net.ipv6.conf.default.accept_source_route
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.accept_source_route\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040250
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces
    by Default - Find all files that set net.ipv6.conf.default.accept_source_route
    to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.accept_source_route\s*=\s*{{ sysctl_net_ipv6_conf_default_accept_source_route_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040250
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces
    by Default - Comment out any occurrences of net.ipv6.conf.default.accept_source_route
    from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.default.accept_source_route
    replace: '#net.ipv6.conf.default.accept_source_route'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-040250
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces
    by Default - Comment out any occurrences of net.ipv6.conf.default.accept_source_route
    from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.default.accept_source_route
    replace: '#net.ipv6.conf.default.accept_source_route'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040250
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces
    by Default - Ensure sysctl net.ipv6.conf.default.accept_source_route is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.default.accept_source_route
    value: '{{ sysctl_net_ipv6_conf_default_accept_source_route_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_default_accept_source_route.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040250
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_accept_source_route
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv6_conf_default_accept_source_route" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv6.conf.default.accept_source_route%3D0%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv6_conf_default_accept_source_route.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_default_accept_source_route_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_accept_source_route_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_default_accept_source_route:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_autoconf" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure Auto Configuration on All IPv6 Interfaces By Default</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.default.autoconf</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.default.autoconf=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.default.autoconf = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R13</xccdf-1.2:reference>
                <xccdf-1.2:rationale>An illicit router advertisement message could result in a man-in-the-middle attack.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_autoconf" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.default.autoconf from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.default.autoconf.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.default.autoconf" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_default_autoconf.conf'

sysctl_net_ipv6_conf_default_autoconf_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_autoconf_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.default.autoconf
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.default.autoconf="$sysctl_net_ipv6_conf_default_autoconf_value"
fi

#
# If net.ipv6.conf.default.autoconf present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.default.autoconf = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.default.autoconf")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_default_autoconf_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.default.autoconf\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.default.autoconf\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_autoconf" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_autoconf
  - unknown_severity
- name: XCCDF Value sysctl_net_ipv6_conf_default_autoconf_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_default_autoconf_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_autoconf_value" use="legacy"/>
  tags:
    - always

- name: Configure Auto Configuration on All IPv6 Interfaces By Default - Set fact
    for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_autoconf
  - unknown_severity

- name: Configure Auto Configuration on All IPv6 Interfaces By Default - Find all
    files that contain net.ipv6.conf.default.autoconf
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.autoconf\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_autoconf
  - unknown_severity

- name: Configure Auto Configuration on All IPv6 Interfaces By Default - Find all
    files that set net.ipv6.conf.default.autoconf to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.autoconf\s*=\s*{{ sysctl_net_ipv6_conf_default_autoconf_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_autoconf
  - unknown_severity

- name: Configure Auto Configuration on All IPv6 Interfaces By Default - Comment out
    any occurrences of net.ipv6.conf.default.autoconf from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.default.autoconf
    replace: '#net.ipv6.conf.default.autoconf'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_autoconf
  - unknown_severity

- name: Configure Auto Configuration on All IPv6 Interfaces By Default - Comment out
    any occurrences of net.ipv6.conf.default.autoconf from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.default.autoconf
    replace: '#net.ipv6.conf.default.autoconf'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_autoconf
  - unknown_severity

- name: Configure Auto Configuration on All IPv6 Interfaces By Default - Ensure sysctl
    net.ipv6.conf.default.autoconf is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.default.autoconf
    value: '{{ sysctl_net_ipv6_conf_default_autoconf_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_default_autoconf.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_autoconf
  - unknown_severity
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_default_autoconf_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_autoconf_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_default_autoconf:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_default_autoconf_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_forwarding" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel Parameter for IPv6 Forwarding by default</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.default.forwarding</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.default.forwarding=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.default.forwarding = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6.1(iv)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:rationale>IP forwarding permits the kernel to forward packets from one network
interface to another. The ability to forward packets between two networks is
only appropriate for systems acting as routers.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_forwarding" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.default.forwarding from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.default.forwarding.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.default.forwarding" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_default_forwarding.conf'

sysctl_net_ipv6_conf_default_forwarding_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_forwarding_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.default.forwarding
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.default.forwarding="$sysctl_net_ipv6_conf_default_forwarding_value"
fi

#
# If net.ipv6.conf.default.forwarding present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.default.forwarding = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.default.forwarding")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_default_forwarding_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.default.forwarding\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.default.forwarding\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_forwarding" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_forwarding
- name: XCCDF Value sysctl_net_ipv6_conf_default_forwarding_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_default_forwarding_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_forwarding_value" use="legacy"/>
  tags:
    - always

- name: Disable Kernel Parameter for IPv6 Forwarding by default - Set fact for sysctl
    paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_forwarding

- name: Disable Kernel Parameter for IPv6 Forwarding by default - Find all files that
    contain net.ipv6.conf.default.forwarding
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.forwarding\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_forwarding

- name: Disable Kernel Parameter for IPv6 Forwarding by default - Find all files that
    set net.ipv6.conf.default.forwarding to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.forwarding\s*=\s*{{ sysctl_net_ipv6_conf_default_forwarding_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_forwarding

- name: Disable Kernel Parameter for IPv6 Forwarding by default - Comment out any
    occurrences of net.ipv6.conf.default.forwarding from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.default.forwarding
    replace: '#net.ipv6.conf.default.forwarding'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_forwarding

- name: Disable Kernel Parameter for IPv6 Forwarding by default - Comment out any
    occurrences of net.ipv6.conf.default.forwarding from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.default.forwarding
    replace: '#net.ipv6.conf.default.forwarding'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_forwarding

- name: Disable Kernel Parameter for IPv6 Forwarding by default - Ensure sysctl net.ipv6.conf.default.forwarding
    is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.default.forwarding
    value: '{{ sysctl_net_ipv6_conf_default_forwarding_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_default_forwarding.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv6_conf_default_forwarding
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_default_forwarding_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_forwarding_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_default_forwarding:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_default_forwarding_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_max_addresses" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces By Default</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.default.max_addresses</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.default.max_addresses=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.default.max_addresses = 1</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R13</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The number of global unicast IPv6 addresses for each interface should be limited exactly to the number of statically configured addresses.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_max_addresses" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.default.max_addresses from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.default.max_addresses.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.default.max_addresses" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_default_max_addresses.conf'

sysctl_net_ipv6_conf_default_max_addresses_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_max_addresses_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.default.max_addresses
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.default.max_addresses="$sysctl_net_ipv6_conf_default_max_addresses_value"
fi

#
# If net.ipv6.conf.default.max_addresses present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.default.max_addresses = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.default.max_addresses")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_default_max_addresses_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.default.max_addresses\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.default.max_addresses\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_max_addresses" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_max_addresses
  - unknown_severity
- name: XCCDF Value sysctl_net_ipv6_conf_default_max_addresses_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_default_max_addresses_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_max_addresses_value" use="legacy"/>
  tags:
    - always

- name: Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces
    By Default - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_max_addresses
  - unknown_severity

- name: Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces
    By Default - Find all files that contain net.ipv6.conf.default.max_addresses
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.max_addresses\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_max_addresses
  - unknown_severity

- name: Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces
    By Default - Find all files that set net.ipv6.conf.default.max_addresses to correct
    value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.max_addresses\s*=\s*{{ sysctl_net_ipv6_conf_default_max_addresses_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_max_addresses
  - unknown_severity

- name: Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces
    By Default - Comment out any occurrences of net.ipv6.conf.default.max_addresses
    from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.default.max_addresses
    replace: '#net.ipv6.conf.default.max_addresses'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_max_addresses
  - unknown_severity

- name: Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces
    By Default - Comment out any occurrences of net.ipv6.conf.default.max_addresses
    from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.default.max_addresses
    replace: '#net.ipv6.conf.default.max_addresses'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_max_addresses
  - unknown_severity

- name: Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces
    By Default - Ensure sysctl net.ipv6.conf.default.max_addresses is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.default.max_addresses
    value: '{{ sysctl_net_ipv6_conf_default_max_addresses_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_default_max_addresses.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_max_addresses
  - unknown_severity
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_default_max_addresses_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_max_addresses_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_default_max_addresses:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_default_max_addresses_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_router_solicitations" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure Denying Router Solicitations on All IPv6 Interfaces By Default</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv6.conf.default.router_solicitations</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv6.conf.default.router_solicitations=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv6.conf.default.router_solicitations = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R13</xccdf-1.2:reference>
                <xccdf-1.2:rationale>To prevent discovery of the system by other systems, router solicitation requests should be denied.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_router_solicitations" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv6.conf.default.router_solicitations from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv6.conf.default.router_solicitations.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv6.conf.default.router_solicitations" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv6_conf_default_router_solicitations.conf'

sysctl_net_ipv6_conf_default_router_solicitations_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_router_solicitations_value" use="legacy"/>'


#
# Set runtime for net.ipv6.conf.default.router_solicitations
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv6.conf.default.router_solicitations="$sysctl_net_ipv6_conf_default_router_solicitations_value"
fi

#
# If net.ipv6.conf.default.router_solicitations present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv6.conf.default.router_solicitations = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv6.conf.default.router_solicitations")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv6_conf_default_router_solicitations_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv6.conf.default.router_solicitations\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv6.conf.default.router_solicitations\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv6_conf_default_router_solicitations" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_router_solicitations
  - unknown_severity
- name: XCCDF Value sysctl_net_ipv6_conf_default_router_solicitations_value # promote to variable
  set_fact:
    sysctl_net_ipv6_conf_default_router_solicitations_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_router_solicitations_value" use="legacy"/>
  tags:
    - always

- name: Configure Denying Router Solicitations on All IPv6 Interfaces By Default -
    Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_router_solicitations
  - unknown_severity

- name: Configure Denying Router Solicitations on All IPv6 Interfaces By Default -
    Find all files that contain net.ipv6.conf.default.router_solicitations
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.router_solicitations\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_router_solicitations
  - unknown_severity

- name: Configure Denying Router Solicitations on All IPv6 Interfaces By Default -
    Find all files that set net.ipv6.conf.default.router_solicitations to correct
    value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv6.conf.default.router_solicitations\s*=\s*{{ sysctl_net_ipv6_conf_default_router_solicitations_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_router_solicitations
  - unknown_severity

- name: Configure Denying Router Solicitations on All IPv6 Interfaces By Default -
    Comment out any occurrences of net.ipv6.conf.default.router_solicitations from
    config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv6.conf.default.router_solicitations
    replace: '#net.ipv6.conf.default.router_solicitations'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_router_solicitations
  - unknown_severity

- name: Configure Denying Router Solicitations on All IPv6 Interfaces By Default -
    Comment out any occurrences of net.ipv6.conf.default.router_solicitations from
    /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv6.conf.default.router_solicitations
    replace: '#net.ipv6.conf.default.router_solicitations'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_router_solicitations
  - unknown_severity

- name: Configure Denying Router Solicitations on All IPv6 Interfaces By Default -
    Ensure sysctl net.ipv6.conf.default.router_solicitations is set
  ansible.posix.sysctl:
    name: net.ipv6.conf.default.router_solicitations
    value: '{{ sysctl_net_ipv6_conf_default_router_solicitations_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv6_conf_default_router_solicitations.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv6_conf_default_router_solicitations
  - unknown_severity
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv6_conf_default_router_solicitations_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv6_conf_default_router_solicitations_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv6_conf_default_router_solicitations:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv6_conf_default_router_solicitations_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_network-kernel">
            <xccdf-1.2:title>Kernel Parameters Which Affect Networking</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>sysctl</html:code> utility is used to set
parameters which affect the operation of the Linux kernel. Kernel parameters
which affect networking and have security implications are described here.</xccdf-1.2:description>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_network_host_and_router_parameters">
              <xccdf-1.2:title>Network Related Kernel Runtime Parameters for Hosts and Routers</xccdf-1.2:title>
              <xccdf-1.2:description>Certain kernel parameters should be set for systems which are
acting as either hosts or routers to improve the system's ability defend
against certain types of IPv4 protocol attacks.</xccdf-1.2:description>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_redirects_value" type="number">
                <xccdf-1.2:title>net.ipv4.conf.all.accept_redirects</xccdf-1.2:title>
                <xccdf-1.2:description>Disable ICMP Redirect Acceptance</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_source_route_value" type="number">
                <xccdf-1.2:title>net.ipv4.conf.all.accept_source_route</xccdf-1.2:title>
                <xccdf-1.2:description>Trackers could be using source-routed packets to
generate traffic that seems to be intra-net, but actually was
created outside and has been redirected.</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_arp_filter_value" type="number">
                <xccdf-1.2:title>net.ipv4.conf.default.arp_filter</xccdf-1.2:title>
                <xccdf-1.2:description>Controls whether the ARP filter is enabled or not.

1 - Allows you to have multiple network interfaces on the same subnet, and have the ARPs for each
interface be answered based on whether or not the kernel would route a packet from the ARP’d IP out that interface.
In other words it allows control of which cards (usually 1) will respond to an ARP request.

0 - (default) The kernel can respond to arp requests with addresses from other interfaces.
This may seem wrong but it usually makes sense, because it increases the chance of successful communication.
IP addresses are owned by the complete host on Linux, not by particular interfaces.</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_arp_ignore_value" type="number">
                <xccdf-1.2:title>net.ipv4.conf.default.arp_ignore</xccdf-1.2:title>
                <xccdf-1.2:description>Control the response modes for ARP queries that resolve local target IP addresses:

0 - (default): reply for any local target IP address, configured on any interface
1 - reply only if the target IP address is local address configured on the incoming interface
2 - reply only if the target IP address is local address configured on the incoming interface and both with the sender’s IP address are part from same subnet on this interface
3 - do not reply for local addresses configured with scope host, only resolutions for global and link addresses are replied
4-7 - reserved
8 - do not reply for all local addresses</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="0">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
                <xccdf-1.2:value selector="2">2</xccdf-1.2:value>
                <xccdf-1.2:value selector="3">3</xccdf-1.2:value>
                <xccdf-1.2:value selector="8">8</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_forwarding_value" type="number">
                <xccdf-1.2:title>net.ipv4.conf.all.forwarding</xccdf-1.2:title>
                <xccdf-1.2:description>Toggle IPv4 Forwarding</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_log_martians_value" type="number">
                <xccdf-1.2:title>net.ipv4.conf.all.log_martians</xccdf-1.2:title>
                <xccdf-1.2:description>Disable so you don't Log Spoofed Packets, Source
Routed Packets, Redirect Packets</xccdf-1.2:description>
                <xccdf-1.2:value>1</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_rp_filter_value" type="number">
                <xccdf-1.2:title>net.ipv4.conf.all.rp_filter</xccdf-1.2:title>
                <xccdf-1.2:description>Enable to enforce sanity checking, also called ingress
filtering or egress filtering. The point is to drop a packet if the
source and destination IP addresses in the IP header do not make
sense when considered in light of the physical interface on which
it arrived.</xccdf-1.2:description>
                <xccdf-1.2:value>1</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
                <xccdf-1.2:value selector="loose">2</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_secure_redirects_value" type="number">
                <xccdf-1.2:title>net.ipv4.conf.all.secure_redirects</xccdf-1.2:title>
                <xccdf-1.2:description>Enable to prevent hijacking of routing path by only
allowing redirects from gateways known in routing
table. Disable to refuse acceptance of secure ICMP redirected packets on all interfaces.</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_shared_media_value" type="number">
                <xccdf-1.2:title>net.ipv4.conf.all.shared_media</xccdf-1.2:title>
                <xccdf-1.2:description>Controls whether the system can send (router) or accept (host) RFC1620 shared media redirects.
<html:code>shared_media</html:code> for the interface will be enabled if at least one of conf/{all,interface}/shared_media
is set to TRUE, it will be disabled otherwise.</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_redirects_value" type="number">
                <xccdf-1.2:title>net.ipv4.conf.default.accept_redirects</xccdf-1.2:title>
                <xccdf-1.2:description>Disable ICMP Redirect Acceptance?</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_source_route_value" type="number">
                <xccdf-1.2:title>net.ipv4.conf.default.accept_source_route</xccdf-1.2:title>
                <xccdf-1.2:description>Disable IP source routing?</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_forwarding_value" type="number">
                <xccdf-1.2:title>net.ipv4.conf.default.forwarding</xccdf-1.2:title>
                <xccdf-1.2:description>Toggle IPv4 Forwarding</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_log_martians_value" type="number">
                <xccdf-1.2:title>net.ipv4.conf.default.log_martians</xccdf-1.2:title>
                <xccdf-1.2:description>Disable so you don't Log Spoofed Packets, Source
Routed Packets, Redirect Packets</xccdf-1.2:description>
                <xccdf-1.2:value>1</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_rp_filter_value" type="number">
                <xccdf-1.2:title>net.ipv4.conf.default.rp_filter</xccdf-1.2:title>
                <xccdf-1.2:description>Enables source route verification</xccdf-1.2:description>
                <xccdf-1.2:value>1</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_secure_redirects_value" type="number">
                <xccdf-1.2:title>net.ipv4.conf.default.secure_redirects</xccdf-1.2:title>
                <xccdf-1.2:description>Enable to prevent hijacking of routing path by only
allowing redirects from gateways known in routing
table. Disable to refuse acceptance of secure ICMP redirected packages by default.</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_shared_media_value" type="number">
                <xccdf-1.2:title>net.ipv4.conf.default.shared_media</xccdf-1.2:title>
                <xccdf-1.2:description>Controls whether the system can send(router) or accept(host) RFC1620 shared media redirects.
<html:code>shared_media</html:code> for the interface will be enabled if at least one of conf/{all,interface}/shared_media
is set to TRUE, it will be disabled otherwise.</xccdf-1.2:description>
                <xccdf-1.2:value>0</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value" type="number">
                <xccdf-1.2:title>net.ipv4.icmp_echo_ignore_broadcasts</xccdf-1.2:title>
                <xccdf-1.2:description>Ignore all ICMP ECHO and TIMESTAMP requests sent to it
via broadcast/multicast</xccdf-1.2:description>
                <xccdf-1.2:value>1</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value" type="number">
                <xccdf-1.2:title>net.ipv4.icmp_ignore_bogus_error_responses</xccdf-1.2:title>
                <xccdf-1.2:description>Enable to prevent unnecessary logging</xccdf-1.2:description>
                <xccdf-1.2:value>1</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_tcp_invalid_ratelimit_value" type="number">
                <xccdf-1.2:title>net.ipv4.tcp_invalid_ratelimit</xccdf-1.2:title>
                <xccdf-1.2:description>Configure  the maximal rate for sending duplicate acknowledgments in
response to incoming invalid TCP packets.</xccdf-1.2:description>
                <xccdf-1.2:value>500</xccdf-1.2:value>
                <xccdf-1.2:value selector="one_thousand">1000</xccdf-1.2:value>
                <xccdf-1.2:value selector="five_hundred">500</xccdf-1.2:value>
                <xccdf-1.2:value selector="two_hundred_fifty">250</xccdf-1.2:value>
                <xccdf-1.2:value selector="one_hundred">100</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_tcp_rfc1337_value" type="number">
                <xccdf-1.2:title>net.ipv4.tcp_rfc1337</xccdf-1.2:title>
                <xccdf-1.2:description>Enable to enable TCP behavior conformant with RFC 1337</xccdf-1.2:description>
                <xccdf-1.2:value>1</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_tcp_syncookies_value" type="number">
                <xccdf-1.2:title>net.ipv4.tcp_syncookies</xccdf-1.2:title>
                <xccdf-1.2:description>Enable to turn on TCP SYN Cookie
Protection</xccdf-1.2:description>
                <xccdf-1.2:value>1</xccdf-1.2:value>
                <xccdf-1.2:value selector="disabled">0</xccdf-1.2:value>
                <xccdf-1.2:value selector="enabled">1</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_local" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Accepting Packets Routed Between Local Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.all.accept_local</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.all.accept_local=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.all.accept_local = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Configure <html:code>net.ipv4.conf.all.accept_local=0</html:code> to consider as invalid the packets
received from outside whose source is the 127.0.0.0/8 address block.
In combination with suitable routing, this can be used to direct packets between two
local interfaces over the wire and have them accepted properly.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_accept_local" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.all.accept_local from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.all.accept_local.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.all.accept_local" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_all_accept_local.conf'


#
# Set runtime for net.ipv4.conf.all.accept_local
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.all.accept_local="0"
fi

#
# If net.ipv4.conf.all.accept_local present in /etc/sysctl.conf, change value to "0"
#	else, add "net.ipv4.conf.all.accept_local = 0" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.all.accept_local")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "0"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.all.accept_local\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.all.accept_local\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_accept_local" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_local

- name: Disable Accepting Packets Routed Between Local Interfaces - Set fact for sysctl
    paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_local

- name: Disable Accepting Packets Routed Between Local Interfaces - Find all files
    that contain net.ipv4.conf.all.accept_local
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.accept_local\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_local

- name: Disable Accepting Packets Routed Between Local Interfaces - Find all files
    that set net.ipv4.conf.all.accept_local to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.accept_local\s*=\s*0$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_local

- name: Disable Accepting Packets Routed Between Local Interfaces - Comment out any
    occurrences of net.ipv4.conf.all.accept_local from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.all.accept_local
    replace: '#net.ipv4.conf.all.accept_local'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_local

- name: Disable Accepting Packets Routed Between Local Interfaces - Comment out any
    occurrences of net.ipv4.conf.all.accept_local from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.all.accept_local
    replace: '#net.ipv4.conf.all.accept_local'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_local

- name: Disable Accepting Packets Routed Between Local Interfaces - Ensure sysctl
    net.ipv4.conf.all.accept_local is set to 0
  ansible.posix.sysctl:
    name: net.ipv4.conf.all.accept_local
    value: '0'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_all_accept_local.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_local
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_all_accept_local:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_redirects" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Accepting ICMP Redirects for All IPv4 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.all.accept_redirects</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.all.accept_redirects=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.all.accept_redirects = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040279</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244553r1017353_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>ICMP redirect messages are used by routers to inform hosts that a more
direct route exists for a particular destination. These messages modify the
host's route table and are unauthenticated. An illicit ICMP redirect
message could result in a man-in-the-middle attack.
<html:br/>
This feature of the IPv4 protocol has few legitimate uses. It should be
disabled unless absolutely required."</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_accept_redirects" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.all.accept_redirects from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.all.accept_redirects.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.all.accept_redirects" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_all_accept_redirects.conf'

sysctl_net_ipv4_conf_all_accept_redirects_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_redirects_value" use="legacy"/>'


#
# Set runtime for net.ipv4.conf.all.accept_redirects
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.all.accept_redirects="$sysctl_net_ipv4_conf_all_accept_redirects_value"
fi

#
# If net.ipv4.conf.all.accept_redirects present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.conf.all.accept_redirects = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.all.accept_redirects")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_conf_all_accept_redirects_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.all.accept_redirects\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.all.accept_redirects\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_accept_redirects" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040279
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_redirects
- name: XCCDF Value sysctl_net_ipv4_conf_all_accept_redirects_value # promote to variable
  set_fact:
    sysctl_net_ipv4_conf_all_accept_redirects_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_redirects_value" use="legacy"/>
  tags:
    - always

- name: Disable Accepting ICMP Redirects for All IPv4 Interfaces - Set fact for sysctl
    paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040279
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_redirects

- name: Disable Accepting ICMP Redirects for All IPv4 Interfaces - Find all files
    that contain net.ipv4.conf.all.accept_redirects
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.accept_redirects\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040279
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_redirects

- name: Disable Accepting ICMP Redirects for All IPv4 Interfaces - Find all files
    that set net.ipv4.conf.all.accept_redirects to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.accept_redirects\s*=\s*{{ sysctl_net_ipv4_conf_all_accept_redirects_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040279
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_redirects

- name: Disable Accepting ICMP Redirects for All IPv4 Interfaces - Comment out any
    occurrences of net.ipv4.conf.all.accept_redirects from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.all.accept_redirects
    replace: '#net.ipv4.conf.all.accept_redirects'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040279
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_redirects

- name: Disable Accepting ICMP Redirects for All IPv4 Interfaces - Comment out any
    occurrences of net.ipv4.conf.all.accept_redirects from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.all.accept_redirects
    replace: '#net.ipv4.conf.all.accept_redirects'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040279
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_redirects

- name: Disable Accepting ICMP Redirects for All IPv4 Interfaces - Ensure sysctl net.ipv4.conf.all.accept_redirects
    is set
  ansible.posix.sysctl:
    name: net.ipv4.conf.all.accept_redirects
    value: '{{ sysctl_net_ipv4_conf_all_accept_redirects_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_all_accept_redirects.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040279
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_redirects
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv4_conf_all_accept_redirects" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv4.conf.all.accept_redirects%3D0%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv4_conf_all_accept_redirects.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_conf_all_accept_redirects_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_redirects_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_all_accept_redirects:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_source_route" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.all.accept_source_route</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.all.accept_source_route=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.all.accept_source_route = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040239</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244551r1017351_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Source-routed packets allow the source of the packet to suggest routers
forward the packet along a different path than configured on the router,
which can be used to bypass network security measures. This requirement
applies only to the forwarding of source-routerd traffic, such as when IPv4
forwarding is enabled and the system is functioning as a router.
<html:br/><html:br/>
Accepting source-routed packets in the IPv4 protocol has few legitimate
uses. It should be disabled unless it is absolutely required.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_accept_source_route" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.all.accept_source_route from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.all.accept_source_route.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.all.accept_source_route" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_all_accept_source_route.conf'

sysctl_net_ipv4_conf_all_accept_source_route_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_source_route_value" use="legacy"/>'


#
# Set runtime for net.ipv4.conf.all.accept_source_route
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.all.accept_source_route="$sysctl_net_ipv4_conf_all_accept_source_route_value"
fi

#
# If net.ipv4.conf.all.accept_source_route present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.conf.all.accept_source_route = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.all.accept_source_route")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_conf_all_accept_source_route_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.all.accept_source_route\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.all.accept_source_route\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_accept_source_route" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040239
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_source_route
- name: XCCDF Value sysctl_net_ipv4_conf_all_accept_source_route_value # promote to variable
  set_fact:
    sysctl_net_ipv4_conf_all_accept_source_route_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_source_route_value" use="legacy"/>
  tags:
    - always

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces
    - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040239
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces
    - Find all files that contain net.ipv4.conf.all.accept_source_route
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.accept_source_route\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040239
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces
    - Find all files that set net.ipv4.conf.all.accept_source_route to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.accept_source_route\s*=\s*{{ sysctl_net_ipv4_conf_all_accept_source_route_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040239
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.conf.all.accept_source_route from config
    files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.all.accept_source_route
    replace: '#net.ipv4.conf.all.accept_source_route'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-040239
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.conf.all.accept_source_route from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.all.accept_source_route
    replace: '#net.ipv4.conf.all.accept_source_route'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040239
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces
    - Ensure sysctl net.ipv4.conf.all.accept_source_route is set
  ansible.posix.sysctl:
    name: net.ipv4.conf.all.accept_source_route
    value: '{{ sysctl_net_ipv4_conf_all_accept_source_route_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_all_accept_source_route.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040239
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_accept_source_route
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv4_conf_all_accept_source_route" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv4.conf.all.accept_source_route%3D0%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv4_conf_all_accept_source_route.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_conf_all_accept_source_route_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_accept_source_route_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_all_accept_source_route:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_arp_filter" selected="false" severity="medium">
                <xccdf-1.2:title>Configure ARP filtering for All IPv4 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.all.arp_filter</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.all.arp_filter=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_arp_filter_value" use="legacy"/></html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.all.arp_filter = <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_arp_filter_value" use="legacy"/></html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="functionality">This behaviour may cause problems to system on a high availability or load balancing configuration.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Prevents the Linux Kernel from handling the ARP table globally.
By default, the kernel may respond to an ARP request from a certain interface with information
from another interface.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_arp_filter" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.all.arp_filter from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.all.arp_filter.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.all.arp_filter" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_all_arp_filter.conf'

sysctl_net_ipv4_conf_all_arp_filter_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_arp_filter_value" use="legacy"/>'


#
# Set runtime for net.ipv4.conf.all.arp_filter
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.all.arp_filter="$sysctl_net_ipv4_conf_all_arp_filter_value"
fi

#
# If net.ipv4.conf.all.arp_filter present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.conf.all.arp_filter = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.all.arp_filter")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_conf_all_arp_filter_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.all.arp_filter\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.all.arp_filter\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_arp_filter" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_arp_filter
- name: XCCDF Value sysctl_net_ipv4_conf_all_arp_filter_value # promote to variable
  set_fact:
    sysctl_net_ipv4_conf_all_arp_filter_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_arp_filter_value" use="legacy"/>
  tags:
    - always

- name: Configure ARP filtering for All IPv4 Interfaces - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_arp_filter

- name: Configure ARP filtering for All IPv4 Interfaces - Find all files that contain
    net.ipv4.conf.all.arp_filter
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.arp_filter\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_arp_filter

- name: Configure ARP filtering for All IPv4 Interfaces - Find all files that set
    net.ipv4.conf.all.arp_filter to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.arp_filter\s*=\s*{{ sysctl_net_ipv4_conf_all_arp_filter_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_arp_filter

- name: Configure ARP filtering for All IPv4 Interfaces - Comment out any occurrences
    of net.ipv4.conf.all.arp_filter from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.all.arp_filter
    replace: '#net.ipv4.conf.all.arp_filter'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_arp_filter

- name: Configure ARP filtering for All IPv4 Interfaces - Comment out any occurrences
    of net.ipv4.conf.all.arp_filter from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.all.arp_filter
    replace: '#net.ipv4.conf.all.arp_filter'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_arp_filter

- name: Configure ARP filtering for All IPv4 Interfaces - Ensure sysctl net.ipv4.conf.all.arp_filter
    is set
  ansible.posix.sysctl:
    name: net.ipv4.conf.all.arp_filter
    value: '{{ sysctl_net_ipv4_conf_all_arp_filter_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_all_arp_filter.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_arp_filter
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_conf_all_arp_filter_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_arp_filter_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_all_arp_filter:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_arp_ignore" selected="false" severity="medium">
                <xccdf-1.2:title>Configure Response Mode of ARP Requests for All IPv4 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.all.arp_ignore</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.all.arp_ignore=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_arp_ignore_value" use="legacy"/></html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.all.arp_ignore = <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_arp_ignore_value" use="legacy"/></html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="functionality">The ARP response mode may impact behaviour of workloads and firewalls on the system.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Avoids ARP Flux on system that have more than one interface on the same subnet.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_arp_ignore" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.all.arp_ignore from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.all.arp_ignore.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.all.arp_ignore" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_all_arp_ignore.conf'

sysctl_net_ipv4_conf_all_arp_ignore_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_arp_ignore_value" use="legacy"/>'


#
# Set runtime for net.ipv4.conf.all.arp_ignore
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.all.arp_ignore="$sysctl_net_ipv4_conf_all_arp_ignore_value"
fi

#
# If net.ipv4.conf.all.arp_ignore present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.conf.all.arp_ignore = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.all.arp_ignore")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_conf_all_arp_ignore_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.all.arp_ignore\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.all.arp_ignore\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_arp_ignore" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_arp_ignore
- name: XCCDF Value sysctl_net_ipv4_conf_all_arp_ignore_value # promote to variable
  set_fact:
    sysctl_net_ipv4_conf_all_arp_ignore_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_arp_ignore_value" use="legacy"/>
  tags:
    - always

- name: Configure Response Mode of ARP Requests for All IPv4 Interfaces - Set fact
    for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_arp_ignore

- name: Configure Response Mode of ARP Requests for All IPv4 Interfaces - Find all
    files that contain net.ipv4.conf.all.arp_ignore
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.arp_ignore\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_arp_ignore

- name: Configure Response Mode of ARP Requests for All IPv4 Interfaces - Find all
    files that set net.ipv4.conf.all.arp_ignore to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.arp_ignore\s*=\s*{{ sysctl_net_ipv4_conf_all_arp_ignore_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_arp_ignore

- name: Configure Response Mode of ARP Requests for All IPv4 Interfaces - Comment
    out any occurrences of net.ipv4.conf.all.arp_ignore from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.all.arp_ignore
    replace: '#net.ipv4.conf.all.arp_ignore'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_arp_ignore

- name: Configure Response Mode of ARP Requests for All IPv4 Interfaces - Comment
    out any occurrences of net.ipv4.conf.all.arp_ignore from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.all.arp_ignore
    replace: '#net.ipv4.conf.all.arp_ignore'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_arp_ignore

- name: Configure Response Mode of ARP Requests for All IPv4 Interfaces - Ensure sysctl
    net.ipv4.conf.all.arp_ignore is set
  ansible.posix.sysctl:
    name: net.ipv4.conf.all.arp_ignore
    value: '{{ sysctl_net_ipv4_conf_all_arp_ignore_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_all_arp_ignore.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_arp_ignore
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_conf_all_arp_ignore_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_arp_ignore_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_all_arp_ignore:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_drop_gratuitous_arp" selected="false" severity="medium">
                <xccdf-1.2:title>Drop Gratuitous ARP frames on All IPv4 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.all.drop_gratuitous_arp</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.all.drop_gratuitous_arp=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.all.drop_gratuitous_arp = 1</html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="functionality">This can cause problems if ARP proxies are used in the network.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Drop Gratuitous ARP frames to prevent ARP poisoning.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_drop_gratuitous_arp" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.all.drop_gratuitous_arp from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.all.drop_gratuitous_arp.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.all.drop_gratuitous_arp" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_all_drop_gratuitous_arp.conf'


#
# Set runtime for net.ipv4.conf.all.drop_gratuitous_arp
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.all.drop_gratuitous_arp="1"
fi

#
# If net.ipv4.conf.all.drop_gratuitous_arp present in /etc/sysctl.conf, change value to "1"
#	else, add "net.ipv4.conf.all.drop_gratuitous_arp = 1" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.all.drop_gratuitous_arp")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "1"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.all.drop_gratuitous_arp\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.all.drop_gratuitous_arp\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_drop_gratuitous_arp" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_drop_gratuitous_arp

- name: Drop Gratuitous ARP frames on All IPv4 Interfaces - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_drop_gratuitous_arp

- name: Drop Gratuitous ARP frames on All IPv4 Interfaces - Find all files that contain
    net.ipv4.conf.all.drop_gratuitous_arp
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.drop_gratuitous_arp\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_drop_gratuitous_arp

- name: Drop Gratuitous ARP frames on All IPv4 Interfaces - Find all files that set
    net.ipv4.conf.all.drop_gratuitous_arp to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.drop_gratuitous_arp\s*=\s*1$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_drop_gratuitous_arp

- name: Drop Gratuitous ARP frames on All IPv4 Interfaces - Comment out any occurrences
    of net.ipv4.conf.all.drop_gratuitous_arp from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.all.drop_gratuitous_arp
    replace: '#net.ipv4.conf.all.drop_gratuitous_arp'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_drop_gratuitous_arp

- name: Drop Gratuitous ARP frames on All IPv4 Interfaces - Comment out any occurrences
    of net.ipv4.conf.all.drop_gratuitous_arp from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.all.drop_gratuitous_arp
    replace: '#net.ipv4.conf.all.drop_gratuitous_arp'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_drop_gratuitous_arp

- name: Drop Gratuitous ARP frames on All IPv4 Interfaces - Ensure sysctl net.ipv4.conf.all.drop_gratuitous_arp
    is set to 1
  ansible.posix.sysctl:
    name: net.ipv4.conf.all.drop_gratuitous_arp
    value: '1'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_all_drop_gratuitous_arp.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_drop_gratuitous_arp
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_all_drop_gratuitous_arp:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_all_drop_gratuitous_arp_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_forwarding" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.all.forwarding</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.all.forwarding=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.all.forwarding = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">There might be cases when certain applications can systematically override this option.
One such case is <html:a href="https://libvirt.org/">Libvirt</html:a>; a toolkit for managing of virtualization platforms.
By default, Libvirt requires IP forwarding to be enabled to facilitate
network communication between the virtualization host and guest
machines. It enables IP forwarding after every reboot.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040259</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-250317r1017358_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>IP forwarding permits the kernel to forward packets from one network
interface to another. The ability to forward packets between two networks is
only appropriate for systems acting as routers.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_forwarding" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.all.forwarding from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.all.forwarding.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.all.forwarding" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_all_forwarding.conf'

sysctl_net_ipv4_conf_all_forwarding_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_forwarding_value" use="legacy"/>'


#
# Set runtime for net.ipv4.conf.all.forwarding
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.all.forwarding="$sysctl_net_ipv4_conf_all_forwarding_value"
fi

#
# If net.ipv4.conf.all.forwarding present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.conf.all.forwarding = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.all.forwarding")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_conf_all_forwarding_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.all.forwarding\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.all.forwarding\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_forwarding" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040259
  - NIST-800-53-CM-6(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_forwarding
- name: XCCDF Value sysctl_net_ipv4_conf_all_forwarding_value # promote to variable
  set_fact:
    sysctl_net_ipv4_conf_all_forwarding_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_forwarding_value" use="legacy"/>
  tags:
    - always

- name: Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces - Set
    fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040259
  - NIST-800-53-CM-6(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_forwarding

- name: Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces - Find
    all files that contain net.ipv4.conf.all.forwarding
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.forwarding\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040259
  - NIST-800-53-CM-6(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_forwarding

- name: Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces - Find
    all files that set net.ipv4.conf.all.forwarding to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.forwarding\s*=\s*{{ sysctl_net_ipv4_conf_all_forwarding_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040259
  - NIST-800-53-CM-6(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_forwarding

- name: Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces - Comment
    out any occurrences of net.ipv4.conf.all.forwarding from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.all.forwarding
    replace: '#net.ipv4.conf.all.forwarding'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-040259
  - NIST-800-53-CM-6(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_forwarding

- name: Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces - Comment
    out any occurrences of net.ipv4.conf.all.forwarding from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.all.forwarding
    replace: '#net.ipv4.conf.all.forwarding'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040259
  - NIST-800-53-CM-6(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_forwarding

- name: Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces - Ensure
    sysctl net.ipv4.conf.all.forwarding is set
  ansible.posix.sysctl:
    name: net.ipv4.conf.all.forwarding
    value: '{{ sysctl_net_ipv4_conf_all_forwarding_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_all_forwarding.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040259
  - NIST-800-53-CM-6(b)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_forwarding
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_conf_all_forwarding_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_forwarding_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_all_forwarding:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_all_forwarding_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_log_martians" selected="false" severity="unknown">
                <xccdf-1.2:title>Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.all.log_martians</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.all.log_martians=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.all.log_martians = 1</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5(3)(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.16</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The presence of "martian" packets (which have impossible addresses)
as well as spoofed packets, source-routed packets, and redirects could be a
sign of nefarious network activity. Logging these packets enables this activity
to be detected.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_log_martians" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.all.log_martians from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.all.log_martians.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.all.log_martians" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_all_log_martians.conf'

sysctl_net_ipv4_conf_all_log_martians_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_log_martians_value" use="legacy"/>'


#
# Set runtime for net.ipv4.conf.all.log_martians
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.all.log_martians="$sysctl_net_ipv4_conf_all_log_martians_value"
fi

#
# If net.ipv4.conf.all.log_martians present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.conf.all.log_martians = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.all.log_martians")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_conf_all_log_martians_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.all.log_martians\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.all.log_martians\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_log_martians" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(3)(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_conf_all_log_martians
  - unknown_severity
- name: XCCDF Value sysctl_net_ipv4_conf_all_log_martians_value # promote to variable
  set_fact:
    sysctl_net_ipv4_conf_all_log_martians_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_log_martians_value" use="legacy"/>
  tags:
    - always

- name: Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces - Set
    fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(3)(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_conf_all_log_martians
  - unknown_severity

- name: Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces - Find
    all files that contain net.ipv4.conf.all.log_martians
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.log_martians\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(3)(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_conf_all_log_martians
  - unknown_severity

- name: Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces - Find
    all files that set net.ipv4.conf.all.log_martians to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.log_martians\s*=\s*{{ sysctl_net_ipv4_conf_all_log_martians_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(3)(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_conf_all_log_martians
  - unknown_severity

- name: Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces - Comment
    out any occurrences of net.ipv4.conf.all.log_martians from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.all.log_martians
    replace: '#net.ipv4.conf.all.log_martians'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(3)(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_conf_all_log_martians
  - unknown_severity

- name: Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces - Comment
    out any occurrences of net.ipv4.conf.all.log_martians from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.all.log_martians
    replace: '#net.ipv4.conf.all.log_martians'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(3)(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_conf_all_log_martians
  - unknown_severity

- name: Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces - Ensure
    sysctl net.ipv4.conf.all.log_martians is set
  ansible.posix.sysctl:
    name: net.ipv4.conf.all.log_martians
    value: '{{ sysctl_net_ipv4_conf_all_log_martians_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_all_log_martians.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(3)(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_conf_all_log_martians
  - unknown_severity
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv4_conf_all_log_martians" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv4.conf.all.log_martians%3D1%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv4_conf_all_log_martians.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_conf_all_log_martians_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_log_martians_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_all_log_martians:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_route_localnet" selected="false" severity="medium">
                <xccdf-1.2:title>Prevent Routing External Traffic to Local Loopback on All IPv4 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.all.route_localnet</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.all.route_localnet=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.all.route_localnet = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Refuse the routing of packets whose source or destination address is the local loopback.
This prohibits the use of network 127/8 for local routing purposes.
Enabling <html:code>route_localnet</html:code> can expose applications listening on localhost to external traffic.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_route_localnet" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.all.route_localnet from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.all.route_localnet.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.all.route_localnet" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_all_route_localnet.conf'


#
# Set runtime for net.ipv4.conf.all.route_localnet
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.all.route_localnet="0"
fi

#
# If net.ipv4.conf.all.route_localnet present in /etc/sysctl.conf, change value to "0"
#	else, add "net.ipv4.conf.all.route_localnet = 0" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.all.route_localnet")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "0"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.all.route_localnet\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.all.route_localnet\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_route_localnet" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_route_localnet

- name: Prevent Routing External Traffic to Local Loopback on All IPv4 Interfaces
    - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_route_localnet

- name: Prevent Routing External Traffic to Local Loopback on All IPv4 Interfaces
    - Find all files that contain net.ipv4.conf.all.route_localnet
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.route_localnet\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_route_localnet

- name: Prevent Routing External Traffic to Local Loopback on All IPv4 Interfaces
    - Find all files that set net.ipv4.conf.all.route_localnet to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.route_localnet\s*=\s*0$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_route_localnet

- name: Prevent Routing External Traffic to Local Loopback on All IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.conf.all.route_localnet from config
    files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.all.route_localnet
    replace: '#net.ipv4.conf.all.route_localnet'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_route_localnet

- name: Prevent Routing External Traffic to Local Loopback on All IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.conf.all.route_localnet from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.all.route_localnet
    replace: '#net.ipv4.conf.all.route_localnet'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_route_localnet

- name: Prevent Routing External Traffic to Local Loopback on All IPv4 Interfaces
    - Ensure sysctl net.ipv4.conf.all.route_localnet is set to 0
  ansible.posix.sysctl:
    name: net.ipv4.conf.all.route_localnet
    value: '0'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_all_route_localnet.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_route_localnet
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_all_route_localnet:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_rp_filter" selected="false" severity="medium">
                <xccdf-1.2:title>Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.all.rp_filter</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.all.rp_filter=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.all.rp_filter = 1</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040285</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230549r1155416_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Enabling reverse path filtering drops packets with source addresses
that should not have been able to be received on the interface they were
received on. It should not be used on systems which are routers for
complicated networks, but is helpful for end hosts and routers serving small
networks.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_rp_filter" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.all.rp_filter from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.all.rp_filter.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.all.rp_filter" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_all_rp_filter.conf'

sysctl_net_ipv4_conf_all_rp_filter_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_rp_filter_value" use="legacy"/>'


#
# Set runtime for net.ipv4.conf.all.rp_filter
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.all.rp_filter="$sysctl_net_ipv4_conf_all_rp_filter_value"
fi

#
# If net.ipv4.conf.all.rp_filter present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.conf.all.rp_filter = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.all.rp_filter")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_conf_all_rp_filter_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.all.rp_filter\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.all.rp_filter\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_rp_filter" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040285
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_rp_filter
- name: XCCDF Value sysctl_net_ipv4_conf_all_rp_filter_value # promote to variable
  set_fact:
    sysctl_net_ipv4_conf_all_rp_filter_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_rp_filter_value" use="legacy"/>
  tags:
    - always

- name: Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces
    - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040285
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_rp_filter

- name: Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces
    - Find all files that contain net.ipv4.conf.all.rp_filter
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.rp_filter\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040285
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_rp_filter

- name: Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces
    - Find all files that set net.ipv4.conf.all.rp_filter to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.rp_filter\s*=\s*{{ sysctl_net_ipv4_conf_all_rp_filter_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040285
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_rp_filter

- name: Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.conf.all.rp_filter from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.all.rp_filter
    replace: '#net.ipv4.conf.all.rp_filter'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-040285
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_rp_filter

- name: Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.conf.all.rp_filter from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.all.rp_filter
    replace: '#net.ipv4.conf.all.rp_filter'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040285
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_rp_filter

- name: Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces
    - Ensure sysctl net.ipv4.conf.all.rp_filter is set
  ansible.posix.sysctl:
    name: net.ipv4.conf.all.rp_filter
    value: '{{ sysctl_net_ipv4_conf_all_rp_filter_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_all_rp_filter.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040285
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_rp_filter
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv4_conf_all_rp_filter" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv4.conf.all.rp_filter%3D1%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv4_conf_all_rp_filter.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_conf_all_rp_filter_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_rp_filter_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_all_rp_filter:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_secure_redirects" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.all.secure_redirects</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.all.secure_redirects=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.all.secure_redirects = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.10</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Accepting "secure" ICMP redirects (from those gateways listed as
default gateways) has few legitimate uses. It should be disabled unless it is
absolutely required.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_secure_redirects" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.all.secure_redirects from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.all.secure_redirects.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.all.secure_redirects" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_all_secure_redirects.conf'

sysctl_net_ipv4_conf_all_secure_redirects_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_secure_redirects_value" use="legacy"/>'


#
# Set runtime for net.ipv4.conf.all.secure_redirects
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.all.secure_redirects="$sysctl_net_ipv4_conf_all_secure_redirects_value"
fi

#
# If net.ipv4.conf.all.secure_redirects present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.conf.all.secure_redirects = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.all.secure_redirects")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_conf_all_secure_redirects_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.all.secure_redirects\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.all.secure_redirects\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_secure_redirects" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_secure_redirects
- name: XCCDF Value sysctl_net_ipv4_conf_all_secure_redirects_value # promote to variable
  set_fact:
    sysctl_net_ipv4_conf_all_secure_redirects_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_secure_redirects_value" use="legacy"/>
  tags:
    - always

- name: Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces
    - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_secure_redirects

- name: Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces
    - Find all files that contain net.ipv4.conf.all.secure_redirects
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.secure_redirects\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_secure_redirects

- name: Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces
    - Find all files that set net.ipv4.conf.all.secure_redirects to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.secure_redirects\s*=\s*{{ sysctl_net_ipv4_conf_all_secure_redirects_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_secure_redirects

- name: Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.conf.all.secure_redirects from config
    files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.all.secure_redirects
    replace: '#net.ipv4.conf.all.secure_redirects'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_secure_redirects

- name: Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.conf.all.secure_redirects from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.all.secure_redirects
    replace: '#net.ipv4.conf.all.secure_redirects'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_secure_redirects

- name: Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces
    - Ensure sysctl net.ipv4.conf.all.secure_redirects is set
  ansible.posix.sysctl:
    name: net.ipv4.conf.all.secure_redirects
    value: '{{ sysctl_net_ipv4_conf_all_secure_redirects_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_all_secure_redirects.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_secure_redirects
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv4_conf_all_secure_redirects" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv4.conf.all.secure_redirects%3D0%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv4_conf_all_secure_redirects.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_conf_all_secure_redirects_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_secure_redirects_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_all_secure_redirects:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_shared_media" selected="false" severity="medium">
                <xccdf-1.2:title>Configure Sending and Accepting Shared Media Redirects for All IPv4 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.all.shared_media</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.all.shared_media=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_shared_media_value" use="legacy"/></html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.all.shared_media = <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_shared_media_value" use="legacy"/></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:rationale>This setting should be aligned with <html:code>net.ipv4.conf.all.secure_redirects</html:code> because it overrides it.
If <html:code>shared_media</html:code> is enabled for an interface <html:code>secure_redirects</html:code> will be enabled too.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_shared_media" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.all.shared_media from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.all.shared_media.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.all.shared_media" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_all_shared_media.conf'

sysctl_net_ipv4_conf_all_shared_media_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_shared_media_value" use="legacy"/>'


#
# Set runtime for net.ipv4.conf.all.shared_media
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.all.shared_media="$sysctl_net_ipv4_conf_all_shared_media_value"
fi

#
# If net.ipv4.conf.all.shared_media present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.conf.all.shared_media = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.all.shared_media")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_conf_all_shared_media_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.all.shared_media\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.all.shared_media\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_shared_media" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_shared_media
- name: XCCDF Value sysctl_net_ipv4_conf_all_shared_media_value # promote to variable
  set_fact:
    sysctl_net_ipv4_conf_all_shared_media_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_shared_media_value" use="legacy"/>
  tags:
    - always

- name: Configure Sending and Accepting Shared Media Redirects for All IPv4 Interfaces
    - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_shared_media

- name: Configure Sending and Accepting Shared Media Redirects for All IPv4 Interfaces
    - Find all files that contain net.ipv4.conf.all.shared_media
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.shared_media\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_shared_media

- name: Configure Sending and Accepting Shared Media Redirects for All IPv4 Interfaces
    - Find all files that set net.ipv4.conf.all.shared_media to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.shared_media\s*=\s*{{ sysctl_net_ipv4_conf_all_shared_media_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_shared_media

- name: Configure Sending and Accepting Shared Media Redirects for All IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.conf.all.shared_media from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.all.shared_media
    replace: '#net.ipv4.conf.all.shared_media'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_shared_media

- name: Configure Sending and Accepting Shared Media Redirects for All IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.conf.all.shared_media from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.all.shared_media
    replace: '#net.ipv4.conf.all.shared_media'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_shared_media

- name: Configure Sending and Accepting Shared Media Redirects for All IPv4 Interfaces
    - Ensure sysctl net.ipv4.conf.all.shared_media is set
  ansible.posix.sysctl:
    name: net.ipv4.conf.all.shared_media
    value: '{{ sysctl_net_ipv4_conf_all_shared_media_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_all_shared_media.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_shared_media
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_conf_all_shared_media_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_all_shared_media_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_all_shared_media:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_redirects" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.default.accept_redirects</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.default.accept_redirects=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.default.accept_redirects = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040209</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244550r1017350_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>ICMP redirect messages are used by routers to inform hosts that a more
direct route exists for a particular destination. These messages modify the
host's route table and are unauthenticated. An illicit ICMP redirect
message could result in a man-in-the-middle attack.
<html:br/>This feature of the IPv4 protocol has few legitimate uses. It should
be disabled unless absolutely required.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_default_accept_redirects" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.default.accept_redirects from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.default.accept_redirects.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.default.accept_redirects" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_default_accept_redirects.conf'

sysctl_net_ipv4_conf_default_accept_redirects_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_redirects_value" use="legacy"/>'


#
# Set runtime for net.ipv4.conf.default.accept_redirects
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.default.accept_redirects="$sysctl_net_ipv4_conf_default_accept_redirects_value"
fi

#
# If net.ipv4.conf.default.accept_redirects present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.conf.default.accept_redirects = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.default.accept_redirects")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_conf_default_accept_redirects_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.default.accept_redirects\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.default.accept_redirects\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_default_accept_redirects" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040209
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_accept_redirects
- name: XCCDF Value sysctl_net_ipv4_conf_default_accept_redirects_value # promote to variable
  set_fact:
    sysctl_net_ipv4_conf_default_accept_redirects_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_redirects_value" use="legacy"/>
  tags:
    - always

- name: Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces
    - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040209
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_accept_redirects

- name: Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces
    - Find all files that contain net.ipv4.conf.default.accept_redirects
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.default.accept_redirects\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040209
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_accept_redirects

- name: Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces
    - Find all files that set net.ipv4.conf.default.accept_redirects to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.default.accept_redirects\s*=\s*{{ sysctl_net_ipv4_conf_default_accept_redirects_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040209
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_accept_redirects

- name: Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.conf.default.accept_redirects from config
    files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.default.accept_redirects
    replace: '#net.ipv4.conf.default.accept_redirects'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040209
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_accept_redirects

- name: Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.conf.default.accept_redirects from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.default.accept_redirects
    replace: '#net.ipv4.conf.default.accept_redirects'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040209
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_accept_redirects

- name: Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces
    - Ensure sysctl net.ipv4.conf.default.accept_redirects is set
  ansible.posix.sysctl:
    name: net.ipv4.conf.default.accept_redirects
    value: '{{ sysctl_net_ipv4_conf_default_accept_redirects_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_default_accept_redirects.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040209
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_accept_redirects
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv4_conf_default_accept_redirects" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv4.conf.default.accept_redirects%3D0%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv4_conf_default_accept_redirects.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_conf_default_accept_redirects_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_redirects_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_default_accept_redirects:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_source_route" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.default.accept_source_route</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.default.accept_source_route=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.default.accept_source_route = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040249</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244552r1017352_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Source-routed packets allow the source of the packet to suggest routers
forward the packet along a different path than configured on the router,
which can be used to bypass network security measures.
<html:br/>
Accepting source-routed packets in the IPv4 protocol has few legitimate
uses. It should be disabled unless it is absolutely required, such as when
IPv4 forwarding is enabled and the system is legitimately functioning as a
router.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_default_accept_source_route" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.default.accept_source_route from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.default.accept_source_route.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.default.accept_source_route" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_default_accept_source_route.conf'

sysctl_net_ipv4_conf_default_accept_source_route_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_source_route_value" use="legacy"/>'


#
# Set runtime for net.ipv4.conf.default.accept_source_route
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.default.accept_source_route="$sysctl_net_ipv4_conf_default_accept_source_route_value"
fi

#
# If net.ipv4.conf.default.accept_source_route present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.conf.default.accept_source_route = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.default.accept_source_route")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_conf_default_accept_source_route_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.default.accept_source_route\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.default.accept_source_route\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_default_accept_source_route" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040249
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_accept_source_route
- name: XCCDF Value sysctl_net_ipv4_conf_default_accept_source_route_value # promote to variable
  set_fact:
    sysctl_net_ipv4_conf_default_accept_source_route_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_source_route_value" use="legacy"/>
  tags:
    - always

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces
    by Default - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040249
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces
    by Default - Find all files that contain net.ipv4.conf.default.accept_source_route
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.default.accept_source_route\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040249
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces
    by Default - Find all files that set net.ipv4.conf.default.accept_source_route
    to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.default.accept_source_route\s*=\s*{{ sysctl_net_ipv4_conf_default_accept_source_route_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040249
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces
    by Default - Comment out any occurrences of net.ipv4.conf.default.accept_source_route
    from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.default.accept_source_route
    replace: '#net.ipv4.conf.default.accept_source_route'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040249
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces
    by Default - Comment out any occurrences of net.ipv4.conf.default.accept_source_route
    from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.default.accept_source_route
    replace: '#net.ipv4.conf.default.accept_source_route'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040249
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_accept_source_route

- name: Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces
    by Default - Ensure sysctl net.ipv4.conf.default.accept_source_route is set
  ansible.posix.sysctl:
    name: net.ipv4.conf.default.accept_source_route
    value: '{{ sysctl_net_ipv4_conf_default_accept_source_route_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_default_accept_source_route.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040249
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_accept_source_route
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv4_conf_default_accept_source_route" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv4.conf.default.accept_source_route%3D0%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv4_conf_default_accept_source_route.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_conf_default_accept_source_route_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_accept_source_route_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_default_accept_source_route:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_forwarding" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel Parameter for IPv4 Forwarding By Default</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.default.forwarding</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.default.forwarding=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.default.forwarding = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="general">There might be cases when certain applications can systematically override this option.
One such case is <html:a href="https://libvirt.org/">Libvirt</html:a>; a toolkit for managing of virtualization platforms.
By default, Libvirt requires IP forwarding to be enabled to facilitate
network communication between the virtualization host and guest
machines. It enables IP forwarding after every reboot.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>IP forwarding permits the kernel to forward packets from one network
interface to another. The ability to forward packets between two networks is
only appropriate for systems acting as routers.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_default_forwarding" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.default.forwarding from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.default.forwarding.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.default.forwarding" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_default_forwarding.conf'

sysctl_net_ipv4_conf_default_forwarding_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_forwarding_value" use="legacy"/>'


#
# Set runtime for net.ipv4.conf.default.forwarding
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.default.forwarding="$sysctl_net_ipv4_conf_default_forwarding_value"
fi

#
# If net.ipv4.conf.default.forwarding present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.conf.default.forwarding = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.default.forwarding")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_conf_default_forwarding_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.default.forwarding\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.default.forwarding\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_default_forwarding" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_forwarding
- name: XCCDF Value sysctl_net_ipv4_conf_default_forwarding_value # promote to variable
  set_fact:
    sysctl_net_ipv4_conf_default_forwarding_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_forwarding_value" use="legacy"/>
  tags:
    - always

- name: Disable Kernel Parameter for IPv4 Forwarding By Default - Set fact for sysctl
    paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_forwarding

- name: Disable Kernel Parameter for IPv4 Forwarding By Default - Find all files that
    contain net.ipv4.conf.default.forwarding
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.default.forwarding\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_forwarding

- name: Disable Kernel Parameter for IPv4 Forwarding By Default - Find all files that
    set net.ipv4.conf.default.forwarding to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.default.forwarding\s*=\s*{{ sysctl_net_ipv4_conf_default_forwarding_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_forwarding

- name: Disable Kernel Parameter for IPv4 Forwarding By Default - Comment out any
    occurrences of net.ipv4.conf.default.forwarding from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.default.forwarding
    replace: '#net.ipv4.conf.default.forwarding'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_forwarding

- name: Disable Kernel Parameter for IPv4 Forwarding By Default - Comment out any
    occurrences of net.ipv4.conf.default.forwarding from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.default.forwarding
    replace: '#net.ipv4.conf.default.forwarding'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_forwarding

- name: Disable Kernel Parameter for IPv4 Forwarding By Default - Ensure sysctl net.ipv4.conf.default.forwarding
    is set
  ansible.posix.sysctl:
    name: net.ipv4.conf.default.forwarding
    value: '{{ sysctl_net_ipv4_conf_default_forwarding_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_default_forwarding.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_forwarding
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_conf_default_forwarding_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_forwarding_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_default_forwarding:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_default_forwarding_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_log_martians" selected="false" severity="unknown">
                <xccdf-1.2:title>Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces by Default</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.default.log_martians</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.default.log_martians=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.default.log_martians = 1</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5(3)(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.17</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The presence of "martian" packets (which have impossible addresses)
as well as spoofed packets, source-routed packets, and redirects could be a
sign of nefarious network activity. Logging these packets enables this activity
to be detected.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_default_log_martians" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.default.log_martians from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.default.log_martians.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.default.log_martians" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_default_log_martians.conf'

sysctl_net_ipv4_conf_default_log_martians_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_log_martians_value" use="legacy"/>'


#
# Set runtime for net.ipv4.conf.default.log_martians
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.default.log_martians="$sysctl_net_ipv4_conf_default_log_martians_value"
fi

#
# If net.ipv4.conf.default.log_martians present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.conf.default.log_martians = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.default.log_martians")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_conf_default_log_martians_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.default.log_martians\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.default.log_martians\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_default_log_martians" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(3)(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_conf_default_log_martians
  - unknown_severity
- name: XCCDF Value sysctl_net_ipv4_conf_default_log_martians_value # promote to variable
  set_fact:
    sysctl_net_ipv4_conf_default_log_martians_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_log_martians_value" use="legacy"/>
  tags:
    - always

- name: Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces by Default
    - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(3)(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_conf_default_log_martians
  - unknown_severity

- name: Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces by Default
    - Find all files that contain net.ipv4.conf.default.log_martians
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.default.log_martians\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(3)(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_conf_default_log_martians
  - unknown_severity

- name: Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces by Default
    - Find all files that set net.ipv4.conf.default.log_martians to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.default.log_martians\s*=\s*{{ sysctl_net_ipv4_conf_default_log_martians_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(3)(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_conf_default_log_martians
  - unknown_severity

- name: Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces by Default
    - Comment out any occurrences of net.ipv4.conf.default.log_martians from config
    files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.default.log_martians
    replace: '#net.ipv4.conf.default.log_martians'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(3)(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_conf_default_log_martians
  - unknown_severity

- name: Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces by Default
    - Comment out any occurrences of net.ipv4.conf.default.log_martians from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.default.log_martians
    replace: '#net.ipv4.conf.default.log_martians'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(3)(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_conf_default_log_martians
  - unknown_severity

- name: Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces by Default
    - Ensure sysctl net.ipv4.conf.default.log_martians is set
  ansible.posix.sysctl:
    name: net.ipv4.conf.default.log_martians
    value: '{{ sysctl_net_ipv4_conf_default_log_martians_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_default_log_martians.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(3)(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_conf_default_log_martians
  - unknown_severity
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv4_conf_default_log_martians" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv4.conf.default.log_martians%3D1%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv4_conf_default_log_martians.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_conf_default_log_martians_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_log_martians_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_default_log_martians:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_rp_filter" selected="false" severity="medium">
                <xccdf-1.2:title>Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.default.rp_filter</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.default.rp_filter=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.default.rp_filter = 1</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.13</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Enabling reverse path filtering drops packets with source addresses
that should not have been able to be received on the interface they were
received on. It should not be used on systems which are routers for
complicated networks, but is helpful for end hosts and routers serving small
networks.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_default_rp_filter" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.default.rp_filter from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.default.rp_filter.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.default.rp_filter" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_default_rp_filter.conf'

sysctl_net_ipv4_conf_default_rp_filter_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_rp_filter_value" use="legacy"/>'


#
# Set runtime for net.ipv4.conf.default.rp_filter
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.default.rp_filter="$sysctl_net_ipv4_conf_default_rp_filter_value"
fi

#
# If net.ipv4.conf.default.rp_filter present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.conf.default.rp_filter = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.default.rp_filter")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_conf_default_rp_filter_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.default.rp_filter\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.default.rp_filter\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_default_rp_filter" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_rp_filter
- name: XCCDF Value sysctl_net_ipv4_conf_default_rp_filter_value # promote to variable
  set_fact:
    sysctl_net_ipv4_conf_default_rp_filter_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_rp_filter_value" use="legacy"/>
  tags:
    - always

- name: Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces
    by Default - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_rp_filter

- name: Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces
    by Default - Find all files that contain net.ipv4.conf.default.rp_filter
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.default.rp_filter\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_rp_filter

- name: Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces
    by Default - Find all files that set net.ipv4.conf.default.rp_filter to correct
    value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.default.rp_filter\s*=\s*{{ sysctl_net_ipv4_conf_default_rp_filter_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_rp_filter

- name: Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces
    by Default - Comment out any occurrences of net.ipv4.conf.default.rp_filter from
    config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.default.rp_filter
    replace: '#net.ipv4.conf.default.rp_filter'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_rp_filter

- name: Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces
    by Default - Comment out any occurrences of net.ipv4.conf.default.rp_filter from
    /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.default.rp_filter
    replace: '#net.ipv4.conf.default.rp_filter'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_rp_filter

- name: Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces
    by Default - Ensure sysctl net.ipv4.conf.default.rp_filter is set
  ansible.posix.sysctl:
    name: net.ipv4.conf.default.rp_filter
    value: '{{ sysctl_net_ipv4_conf_default_rp_filter_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_default_rp_filter.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_rp_filter
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv4_conf_default_rp_filter" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv4.conf.default.rp_filter%3D1%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv4_conf_default_rp_filter.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_conf_default_rp_filter_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_rp_filter_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_default_rp_filter:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_secure_redirects" selected="false" severity="medium">
                <xccdf-1.2:title>Configure Kernel Parameter for Accepting Secure Redirects By Default</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.default.secure_redirects</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.default.secure_redirects=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.default.secure_redirects = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.11</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Accepting "secure" ICMP redirects (from those gateways listed as
default gateways) has few legitimate uses. It should be disabled unless it is
absolutely required.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_default_secure_redirects" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.default.secure_redirects from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.default.secure_redirects.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.default.secure_redirects" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_default_secure_redirects.conf'

sysctl_net_ipv4_conf_default_secure_redirects_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_secure_redirects_value" use="legacy"/>'


#
# Set runtime for net.ipv4.conf.default.secure_redirects
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.default.secure_redirects="$sysctl_net_ipv4_conf_default_secure_redirects_value"
fi

#
# If net.ipv4.conf.default.secure_redirects present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.conf.default.secure_redirects = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.default.secure_redirects")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_conf_default_secure_redirects_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.default.secure_redirects\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.default.secure_redirects\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_default_secure_redirects" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_secure_redirects
- name: XCCDF Value sysctl_net_ipv4_conf_default_secure_redirects_value # promote to variable
  set_fact:
    sysctl_net_ipv4_conf_default_secure_redirects_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_secure_redirects_value" use="legacy"/>
  tags:
    - always

- name: Configure Kernel Parameter for Accepting Secure Redirects By Default - Set
    fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_secure_redirects

- name: Configure Kernel Parameter for Accepting Secure Redirects By Default - Find
    all files that contain net.ipv4.conf.default.secure_redirects
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.default.secure_redirects\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_secure_redirects

- name: Configure Kernel Parameter for Accepting Secure Redirects By Default - Find
    all files that set net.ipv4.conf.default.secure_redirects to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.default.secure_redirects\s*=\s*{{ sysctl_net_ipv4_conf_default_secure_redirects_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_secure_redirects

- name: Configure Kernel Parameter for Accepting Secure Redirects By Default - Comment
    out any occurrences of net.ipv4.conf.default.secure_redirects from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.default.secure_redirects
    replace: '#net.ipv4.conf.default.secure_redirects'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_secure_redirects

- name: Configure Kernel Parameter for Accepting Secure Redirects By Default - Comment
    out any occurrences of net.ipv4.conf.default.secure_redirects from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.default.secure_redirects
    replace: '#net.ipv4.conf.default.secure_redirects'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_secure_redirects

- name: Configure Kernel Parameter for Accepting Secure Redirects By Default - Ensure
    sysctl net.ipv4.conf.default.secure_redirects is set
  ansible.posix.sysctl:
    name: net.ipv4.conf.default.secure_redirects
    value: '{{ sysctl_net_ipv4_conf_default_secure_redirects_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_default_secure_redirects.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_secure_redirects
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv4_conf_default_secure_redirects" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv4.conf.default.secure_redirects%3D0%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv4_conf_default_secure_redirects.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_conf_default_secure_redirects_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_secure_redirects_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_default_secure_redirects:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_shared_media" selected="false" severity="medium">
                <xccdf-1.2:title>Configure Sending and Accepting Shared Media Redirects by Default</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.default.shared_media</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.default.shared_media=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_shared_media_value" use="legacy"/></html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.default.shared_media = <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_shared_media_value" use="legacy"/></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:rationale>This setting should be aligned with <html:code>net.ipv4.conf.default.secure_redirects</html:code> because it overrides it.
If <html:code>shared_media</html:code> is enabled for an interface <html:code>secure_redirects</html:code> will be enabled too.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_default_shared_media" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.default.shared_media from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.default.shared_media.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.default.shared_media" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_default_shared_media.conf'

sysctl_net_ipv4_conf_default_shared_media_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_shared_media_value" use="legacy"/>'


#
# Set runtime for net.ipv4.conf.default.shared_media
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.default.shared_media="$sysctl_net_ipv4_conf_default_shared_media_value"
fi

#
# If net.ipv4.conf.default.shared_media present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.conf.default.shared_media = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.default.shared_media")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_conf_default_shared_media_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.default.shared_media\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.default.shared_media\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_default_shared_media" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_shared_media
- name: XCCDF Value sysctl_net_ipv4_conf_default_shared_media_value # promote to variable
  set_fact:
    sysctl_net_ipv4_conf_default_shared_media_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_shared_media_value" use="legacy"/>
  tags:
    - always

- name: Configure Sending and Accepting Shared Media Redirects by Default - Set fact
    for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_shared_media

- name: Configure Sending and Accepting Shared Media Redirects by Default - Find all
    files that contain net.ipv4.conf.default.shared_media
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.default.shared_media\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_shared_media

- name: Configure Sending and Accepting Shared Media Redirects by Default - Find all
    files that set net.ipv4.conf.default.shared_media to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.default.shared_media\s*=\s*{{ sysctl_net_ipv4_conf_default_shared_media_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_shared_media

- name: Configure Sending and Accepting Shared Media Redirects by Default - Comment
    out any occurrences of net.ipv4.conf.default.shared_media from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.default.shared_media
    replace: '#net.ipv4.conf.default.shared_media'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_shared_media

- name: Configure Sending and Accepting Shared Media Redirects by Default - Comment
    out any occurrences of net.ipv4.conf.default.shared_media from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.default.shared_media
    replace: '#net.ipv4.conf.default.shared_media'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_shared_media

- name: Configure Sending and Accepting Shared Media Redirects by Default - Ensure
    sysctl net.ipv4.conf.default.shared_media is set
  ansible.posix.sysctl:
    name: net.ipv4.conf.default.shared_media
    value: '{{ sysctl_net_ipv4_conf_default_shared_media_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_default_shared_media.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_shared_media
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_conf_default_shared_media_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_conf_default_shared_media_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_default_shared_media:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_echo_ignore_broadcasts" selected="false" severity="medium">
                <xccdf-1.2:title>Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.icmp_echo_ignore_broadcasts</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.icmp_echo_ignore_broadcasts=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.icmp_echo_ignore_broadcasts = 1</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040230</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230537r1017299_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Responding to broadcast (ICMP) echoes facilitates network mapping
and provides a vector for amplification attacks.
<html:br/>
Ignoring ICMP echo requests (pings) sent to broadcast or multicast
addresses makes the system slightly more difficult to enumerate on the network.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_icmp_echo_ignore_broadcasts" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.icmp_echo_ignore_broadcasts from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.icmp_echo_ignore_broadcasts.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.icmp_echo_ignore_broadcasts" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_icmp_echo_ignore_broadcasts.conf'

sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value" use="legacy"/>'


#
# Set runtime for net.ipv4.icmp_echo_ignore_broadcasts
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.icmp_echo_ignore_broadcasts="$sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value"
fi

#
# If net.ipv4.icmp_echo_ignore_broadcasts present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.icmp_echo_ignore_broadcasts = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.icmp_echo_ignore_broadcasts")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.icmp_echo_ignore_broadcasts\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.icmp_echo_ignore_broadcasts\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_icmp_echo_ignore_broadcasts" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040230
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_icmp_echo_ignore_broadcasts
- name: XCCDF Value sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value # promote to variable
  set_fact:
    sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value" use="legacy"/>
  tags:
    - always

- name: Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces
    - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040230
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_icmp_echo_ignore_broadcasts

- name: Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces
    - Find all files that contain net.ipv4.icmp_echo_ignore_broadcasts
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.icmp_echo_ignore_broadcasts\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040230
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_icmp_echo_ignore_broadcasts

- name: Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces
    - Find all files that set net.ipv4.icmp_echo_ignore_broadcasts to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.icmp_echo_ignore_broadcasts\s*=\s*{{ sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040230
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_icmp_echo_ignore_broadcasts

- name: Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.icmp_echo_ignore_broadcasts from config
    files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.icmp_echo_ignore_broadcasts
    replace: '#net.ipv4.icmp_echo_ignore_broadcasts'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040230
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_icmp_echo_ignore_broadcasts

- name: Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.icmp_echo_ignore_broadcasts from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.icmp_echo_ignore_broadcasts
    replace: '#net.ipv4.icmp_echo_ignore_broadcasts'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040230
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_icmp_echo_ignore_broadcasts

- name: Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces
    - Ensure sysctl net.ipv4.icmp_echo_ignore_broadcasts is set
  ansible.posix.sysctl:
    name: net.ipv4.icmp_echo_ignore_broadcasts
    value: '{{ sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_icmp_echo_ignore_broadcasts.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040230
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_icmp_echo_ignore_broadcasts
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv4_icmp_echo_ignore_broadcasts" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv4.icmp_echo_ignore_broadcasts%3D1%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv4_icmp_echo_ignore_broadcasts.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_ignore_bogus_error_responses" selected="false" severity="unknown">
                <xccdf-1.2:title>Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.icmp_ignore_bogus_error_responses</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.icmp_ignore_bogus_error_responses=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.icmp_ignore_bogus_error_responses = 1</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.6</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Ignoring bogus ICMP error responses reduces
log size, although some activity would not be logged.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_icmp_ignore_bogus_error_responses" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.icmp_ignore_bogus_error_responses from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.icmp_ignore_bogus_error_responses.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.icmp_ignore_bogus_error_responses" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_icmp_ignore_bogus_error_responses.conf'

sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value" use="legacy"/>'


#
# Set runtime for net.ipv4.icmp_ignore_bogus_error_responses
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.icmp_ignore_bogus_error_responses="$sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value"
fi

#
# If net.ipv4.icmp_ignore_bogus_error_responses present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.icmp_ignore_bogus_error_responses = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.icmp_ignore_bogus_error_responses")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.icmp_ignore_bogus_error_responses\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.icmp_ignore_bogus_error_responses\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_icmp_ignore_bogus_error_responses" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_icmp_ignore_bogus_error_responses
  - unknown_severity
- name: XCCDF Value sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value # promote to variable
  set_fact:
    sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value" use="legacy"/>
  tags:
    - always

- name: Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces
    - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_icmp_ignore_bogus_error_responses
  - unknown_severity

- name: Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces
    - Find all files that contain net.ipv4.icmp_ignore_bogus_error_responses
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.icmp_ignore_bogus_error_responses\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_icmp_ignore_bogus_error_responses
  - unknown_severity

- name: Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces
    - Find all files that set net.ipv4.icmp_ignore_bogus_error_responses to correct
    value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.icmp_ignore_bogus_error_responses\s*=\s*{{ sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_icmp_ignore_bogus_error_responses
  - unknown_severity

- name: Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.icmp_ignore_bogus_error_responses from
    config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.icmp_ignore_bogus_error_responses
    replace: '#net.ipv4.icmp_ignore_bogus_error_responses'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_icmp_ignore_bogus_error_responses
  - unknown_severity

- name: Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.icmp_ignore_bogus_error_responses from
    /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.icmp_ignore_bogus_error_responses
    replace: '#net.ipv4.icmp_ignore_bogus_error_responses'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_icmp_ignore_bogus_error_responses
  - unknown_severity

- name: Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces
    - Ensure sysctl net.ipv4.icmp_ignore_bogus_error_responses is set
  ansible.posix.sysctl:
    name: net.ipv4.icmp_ignore_bogus_error_responses
    value: '{{ sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_icmp_ignore_bogus_error_responses.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - PCI-DSS-Req-1.4.3
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - low_complexity
  - medium_disruption
  - reboot_required
  - sysctl_net_ipv4_icmp_ignore_bogus_error_responses
  - unknown_severity
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv4_icmp_ignore_bogus_error_responses" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv4.icmp_ignore_bogus_error_responses%3D1%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv4_icmp_ignore_bogus_error_responses.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_local_port_range" selected="false" severity="medium">
                <xccdf-1.2:title>Set Kernel Parameter to Increase Local Port Range</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.ip_local_port_range</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.ip_local_port_range=32768 65535</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.ip_local_port_range = 32768 65535</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:rationale>This setting defines the local port range that is used by TCP and UDP to
choose the local port. The first number is the first, the second the last
local port number.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_ip_local_port_range" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.ip_local_port_range from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.ip_local_port_range.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.ip_local_port_range" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_ip_local_port_range.conf'


#
# Set runtime for net.ipv4.ip_local_port_range
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.ip_local_port_range="32768 65535"
fi

#
# If net.ipv4.ip_local_port_range present in /etc/sysctl.conf, change value to "32768 65535"
#	else, add "net.ipv4.ip_local_port_range = 32768 65535" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.ip_local_port_range")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "32768 65535"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.ip_local_port_range\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.ip_local_port_range\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_ip_local_port_range" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_ip_local_port_range

- name: Set Kernel Parameter to Increase Local Port Range - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_ip_local_port_range

- name: Set Kernel Parameter to Increase Local Port Range - Find all files that contain
    net.ipv4.ip_local_port_range
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.ip_local_port_range\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_ip_local_port_range

- name: Set Kernel Parameter to Increase Local Port Range - Find all files that set
    net.ipv4.ip_local_port_range to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.ip_local_port_range\s*=\s*32768 65535$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_ip_local_port_range

- name: Set Kernel Parameter to Increase Local Port Range - Comment out any occurrences
    of net.ipv4.ip_local_port_range from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.ip_local_port_range
    replace: '#net.ipv4.ip_local_port_range'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_ip_local_port_range

- name: Set Kernel Parameter to Increase Local Port Range - Comment out any occurrences
    of net.ipv4.ip_local_port_range from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.ip_local_port_range
    replace: '#net.ipv4.ip_local_port_range'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_ip_local_port_range

- name: Set Kernel Parameter to Increase Local Port Range - Ensure sysctl net.ipv4.ip_local_port_range
    is set to 32768 65535
  ansible.posix.sysctl:
    name: net.ipv4.ip_local_port_range
    value: 32768 65535
    sysctl_file: /etc/sysctl.d/net_ipv4_ip_local_port_range.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_ip_local_port_range
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_ip_local_port_range:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_ip_local_port_range_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_invalid_ratelimit" selected="false" severity="medium">
                <xccdf-1.2:title>Configure Kernel to Rate Limit Sending of Duplicate TCP Acknowledgments</xccdf-1.2:title>
                <xccdf-1.2:description>Make sure that the system is configured to limit the maximal rate for sending
duplicate acknowledgments in response to incoming TCP packets that are for
an existing connection but that are invalid due to any of these reasons:

(a) out-of-window sequence number, (b) out-of-window acknowledgment number,
or (c) PAWS (Protection Against Wrapped Sequence numbers) check failure
This measure protects against or limits effects of DoS attacks against the system.
Set the system to implement rate-limiting measures by adding the following line to
<html:code>/etc/sysctl.conf</html:code> or a configuration file in the <html:code>/etc/sysctl.d/</html:code> directory
(or modify the line to have the required value):
<html:pre>net.ipv4.tcp_invalid_ratelimit = <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_tcp_invalid_ratelimit_value" use="legacy"/></html:pre>
Issue the following command to make the changes take effect:
<html:pre># sysctl --system</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000420-GPOS-00186</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Denial of Service (DoS) is a condition when a resource is not available for legitimate users. When
this occurs, the organization either cannot accomplish its mission or must
operate at degraded capacity.
<html:br/><html:br/>
This can help mitigate simple “ack loop” DoS attacks, wherein a buggy or
malicious middlebox or man-in-the-middle can rewrite TCP header fields in
manner that causes each endpoint to think that the other is sending invalid
TCP segments, thus causing each side to send an unterminating stream of
duplicate acknowledgments for invalid segments.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_tcp_invalid_ratelimit" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.tcp_invalid_ratelimit from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.tcp_invalid_ratelimit.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.tcp_invalid_ratelimit" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_tcp_invalid_ratelimit.conf'

sysctl_net_ipv4_tcp_invalid_ratelimit_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_tcp_invalid_ratelimit_value" use="legacy"/>'


#
# Set runtime for net.ipv4.tcp_invalid_ratelimit
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.tcp_invalid_ratelimit="$sysctl_net_ipv4_tcp_invalid_ratelimit_value"
fi

#
# If net.ipv4.tcp_invalid_ratelimit present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.tcp_invalid_ratelimit = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.tcp_invalid_ratelimit")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_tcp_invalid_ratelimit_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.tcp_invalid_ratelimit\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.tcp_invalid_ratelimit\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_tcp_invalid_ratelimit" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-SC-5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_invalid_ratelimit
- name: XCCDF Value sysctl_net_ipv4_tcp_invalid_ratelimit_value # promote to variable
  set_fact:
    sysctl_net_ipv4_tcp_invalid_ratelimit_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_tcp_invalid_ratelimit_value" use="legacy"/>
  tags:
    - always

- name: Configure Kernel to Rate Limit Sending of Duplicate TCP Acknowledgments -
    Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-SC-5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_invalid_ratelimit

- name: Configure Kernel to Rate Limit Sending of Duplicate TCP Acknowledgments -
    Find all files that contain net.ipv4.tcp_invalid_ratelimit
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.tcp_invalid_ratelimit\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-SC-5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_invalid_ratelimit

- name: Configure Kernel to Rate Limit Sending of Duplicate TCP Acknowledgments -
    Find all files that set net.ipv4.tcp_invalid_ratelimit to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.tcp_invalid_ratelimit\s*=\s*{{ sysctl_net_ipv4_tcp_invalid_ratelimit_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-SC-5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_invalid_ratelimit

- name: Configure Kernel to Rate Limit Sending of Duplicate TCP Acknowledgments -
    Comment out any occurrences of net.ipv4.tcp_invalid_ratelimit from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.tcp_invalid_ratelimit
    replace: '#net.ipv4.tcp_invalid_ratelimit'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - NIST-800-53-SC-5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_invalid_ratelimit

- name: Configure Kernel to Rate Limit Sending of Duplicate TCP Acknowledgments -
    Comment out any occurrences of net.ipv4.tcp_invalid_ratelimit from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.tcp_invalid_ratelimit
    replace: '#net.ipv4.tcp_invalid_ratelimit'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-SC-5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_invalid_ratelimit

- name: Configure Kernel to Rate Limit Sending of Duplicate TCP Acknowledgments -
    Ensure sysctl net.ipv4.tcp_invalid_ratelimit is set
  ansible.posix.sysctl:
    name: net.ipv4.tcp_invalid_ratelimit
    value: '{{ sysctl_net_ipv4_tcp_invalid_ratelimit_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_tcp_invalid_ratelimit.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-SC-5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_invalid_ratelimit
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_tcp_invalid_ratelimit_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_tcp_invalid_ratelimit_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_tcp_invalid_ratelimit:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_tcp_invalid_ratelimit_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_rfc1337" selected="false" severity="medium">
                <xccdf-1.2:title>Enable Kernel Parameter to Use TCP RFC 1337 on IPv4 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.tcp_rfc1337</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.tcp_rfc1337=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.tcp_rfc1337 = 1</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Enable TCP behavior conformant with RFC 1337. When disabled, if a RST is
received in TIME_WAIT state, we close the socket immediately without waiting
for the end of the TIME_WAIT period.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_tcp_rfc1337" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.tcp_rfc1337 from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.tcp_rfc1337.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.tcp_rfc1337" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_tcp_rfc1337.conf'

sysctl_net_ipv4_tcp_rfc1337_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_tcp_rfc1337_value" use="legacy"/>'


#
# Set runtime for net.ipv4.tcp_rfc1337
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.tcp_rfc1337="$sysctl_net_ipv4_tcp_rfc1337_value"
fi

#
# If net.ipv4.tcp_rfc1337 present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.tcp_rfc1337 = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.tcp_rfc1337")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_tcp_rfc1337_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.tcp_rfc1337\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.tcp_rfc1337\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_tcp_rfc1337" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_rfc1337
- name: XCCDF Value sysctl_net_ipv4_tcp_rfc1337_value # promote to variable
  set_fact:
    sysctl_net_ipv4_tcp_rfc1337_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_tcp_rfc1337_value" use="legacy"/>
  tags:
    - always

- name: Enable Kernel Parameter to Use TCP RFC 1337 on IPv4 Interfaces - Set fact
    for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_rfc1337

- name: Enable Kernel Parameter to Use TCP RFC 1337 on IPv4 Interfaces - Find all
    files that contain net.ipv4.tcp_rfc1337
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.tcp_rfc1337\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_rfc1337

- name: Enable Kernel Parameter to Use TCP RFC 1337 on IPv4 Interfaces - Find all
    files that set net.ipv4.tcp_rfc1337 to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.tcp_rfc1337\s*=\s*{{ sysctl_net_ipv4_tcp_rfc1337_value }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_rfc1337

- name: Enable Kernel Parameter to Use TCP RFC 1337 on IPv4 Interfaces - Comment out
    any occurrences of net.ipv4.tcp_rfc1337 from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.tcp_rfc1337
    replace: '#net.ipv4.tcp_rfc1337'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_rfc1337

- name: Enable Kernel Parameter to Use TCP RFC 1337 on IPv4 Interfaces - Comment out
    any occurrences of net.ipv4.tcp_rfc1337 from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.tcp_rfc1337
    replace: '#net.ipv4.tcp_rfc1337'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_rfc1337

- name: Enable Kernel Parameter to Use TCP RFC 1337 on IPv4 Interfaces - Ensure sysctl
    net.ipv4.tcp_rfc1337 is set
  ansible.posix.sysctl:
    name: net.ipv4.tcp_rfc1337
    value: '{{ sysctl_net_ipv4_tcp_rfc1337_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_tcp_rfc1337.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_rfc1337
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_tcp_rfc1337_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_tcp_rfc1337_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_tcp_rfc1337:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_tcp_rfc1337_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_syncookies" selected="false" severity="medium">
                <xccdf-1.2:title>Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.tcp_syncookies</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.tcp_syncookies=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.tcp_syncookies = 1</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5(3)(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000420-GPOS-00186</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000142-GPOS-00071</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.18</xccdf-1.2:reference>
                <xccdf-1.2:rationale>A TCP SYN flood attack can cause a denial of service by filling a
system's TCP connection table with connections in the SYN_RCVD state.
Syncookies can be used to track a connection when a subsequent ACK is received,
verifying the initiator is attempting a valid connection and is not a flood
source. This feature is activated when a flood condition is detected, and
enables the system to continue servicing valid connection requests.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_tcp_syncookies" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.tcp_syncookies from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.tcp_syncookies.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.tcp_syncookies" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_tcp_syncookies.conf'

sysctl_net_ipv4_tcp_syncookies_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_tcp_syncookies_value" use="legacy"/>'


#
# Set runtime for net.ipv4.tcp_syncookies
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.tcp_syncookies="$sysctl_net_ipv4_tcp_syncookies_value"
fi

#
# If net.ipv4.tcp_syncookies present in /etc/sysctl.conf, change value to appropriate value
#	else, add "net.ipv4.tcp_syncookies = value" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.tcp_syncookies")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$sysctl_net_ipv4_tcp_syncookies_value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.tcp_syncookies\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.tcp_syncookies\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_tcp_syncookies" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.10.1.1
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(1)
  - NIST-800-53-SC-5(2)
  - NIST-800-53-SC-5(3)(a)
  - PCI-DSS-Req-1.4.1
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_syncookies
- name: XCCDF Value sysctl_net_ipv4_tcp_syncookies_value # promote to variable
  set_fact:
    sysctl_net_ipv4_tcp_syncookies_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_tcp_syncookies_value" use="legacy"/>
  tags:
    - always

- name: Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces - Set
    fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(1)
  - NIST-800-53-SC-5(2)
  - NIST-800-53-SC-5(3)(a)
  - PCI-DSS-Req-1.4.1
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_syncookies

- name: Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces - Find
    all files that contain net.ipv4.tcp_syncookies
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.tcp_syncookies\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(1)
  - NIST-800-53-SC-5(2)
  - NIST-800-53-SC-5(3)(a)
  - PCI-DSS-Req-1.4.1
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_syncookies

- name: Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces - Find
    all files that set net.ipv4.tcp_syncookies to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.tcp_syncookies\s*=\s*{{ sysctl_net_ipv4_tcp_syncookies_value
      }}$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(1)
  - NIST-800-53-SC-5(2)
  - NIST-800-53-SC-5(3)(a)
  - PCI-DSS-Req-1.4.1
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_syncookies

- name: Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces - Comment
    out any occurrences of net.ipv4.tcp_syncookies from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.tcp_syncookies
    replace: '#net.ipv4.tcp_syncookies'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - CJIS-5.10.1.1
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(1)
  - NIST-800-53-SC-5(2)
  - NIST-800-53-SC-5(3)(a)
  - PCI-DSS-Req-1.4.1
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_syncookies

- name: Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces - Comment
    out any occurrences of net.ipv4.tcp_syncookies from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.tcp_syncookies
    replace: '#net.ipv4.tcp_syncookies'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(1)
  - NIST-800-53-SC-5(2)
  - NIST-800-53-SC-5(3)(a)
  - PCI-DSS-Req-1.4.1
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_syncookies

- name: Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces - Ensure
    sysctl net.ipv4.tcp_syncookies is set
  ansible.posix.sysctl:
    name: net.ipv4.tcp_syncookies
    value: '{{ sysctl_net_ipv4_tcp_syncookies_value }}'
    sysctl_file: /etc/sysctl.d/net_ipv4_tcp_syncookies.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5(1)
  - NIST-800-53-SC-5(2)
  - NIST-800-53-SC-5(3)(a)
  - PCI-DSS-Req-1.4.1
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_tcp_syncookies
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv4_tcp_syncookies" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv4.tcp_syncookies%3D1%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv4_tcp_syncookies.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-sysctl_net_ipv4_tcp_syncookies_value:var:1" value-id="xccdf_org.ssgproject.content_value_sysctl_net_ipv4_tcp_syncookies_value"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_tcp_syncookies:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_tcp_syncookies_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_network_host_parameters">
              <xccdf-1.2:title>Network Parameters for Hosts Only</xccdf-1.2:title>
              <xccdf-1.2:description>If the system is not going to be used as a router, then setting certain
kernel parameters ensure that the host will not perform routing
of network traffic.</xccdf-1.2:description>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_send_redirects" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.all.send_redirects</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.all.send_redirects=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.all.send_redirects = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040220</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230536r1017298_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>ICMP redirect messages are used by routers to inform hosts that a more
direct route exists for a particular destination. These messages contain information
from the system's route table possibly revealing portions of the network topology.
<html:br/>
The ability to send ICMP redirects is only appropriate for systems acting as routers.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_send_redirects" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.all.send_redirects from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.all.send_redirects.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.all.send_redirects" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_all_send_redirects.conf'


#
# Set runtime for net.ipv4.conf.all.send_redirects
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.all.send_redirects="0"
fi

#
# If net.ipv4.conf.all.send_redirects present in /etc/sysctl.conf, change value to "0"
#	else, add "net.ipv4.conf.all.send_redirects = 0" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.all.send_redirects")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "0"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.all.send_redirects\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.all.send_redirects\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_all_send_redirects" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040220
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_send_redirects

- name: Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces
    - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040220
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_send_redirects

- name: Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces
    - Find all files that contain net.ipv4.conf.all.send_redirects
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.send_redirects\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040220
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_send_redirects

- name: Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces
    - Find all files that set net.ipv4.conf.all.send_redirects to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.all.send_redirects\s*=\s*0$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040220
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_send_redirects

- name: Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.conf.all.send_redirects from config
    files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.all.send_redirects
    replace: '#net.ipv4.conf.all.send_redirects'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040220
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_send_redirects

- name: Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces
    - Comment out any occurrences of net.ipv4.conf.all.send_redirects from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.all.send_redirects
    replace: '#net.ipv4.conf.all.send_redirects'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040220
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_send_redirects

- name: Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces
    - Ensure sysctl net.ipv4.conf.all.send_redirects is set to 0
  ansible.posix.sysctl:
    name: net.ipv4.conf.all.send_redirects
    value: '0'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_all_send_redirects.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040220
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_all_send_redirects
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv4_conf_all_send_redirects" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv4.conf.all.send_redirects%3D0%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv4_conf_all_send_redirects.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_all_send_redirects:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_send_redirects" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.conf.default.send_redirects</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.conf.default.send_redirects=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.conf.default.send_redirects = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040270</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230543r1017305_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>ICMP redirect messages are used by routers to inform hosts that a more
direct route exists for a particular destination. These messages contain information
from the system's route table possibly revealing portions of the network topology.
<html:br/>
The ability to send ICMP redirects is only appropriate for systems acting as routers.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_default_send_redirects" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.conf.default.send_redirects from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.conf.default.send_redirects.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.conf.default.send_redirects" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_conf_default_send_redirects.conf'


#
# Set runtime for net.ipv4.conf.default.send_redirects
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.conf.default.send_redirects="0"
fi

#
# If net.ipv4.conf.default.send_redirects present in /etc/sysctl.conf, change value to "0"
#	else, add "net.ipv4.conf.default.send_redirects = 0" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.conf.default.send_redirects")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "0"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.conf.default.send_redirects\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.conf.default.send_redirects\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_conf_default_send_redirects" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040270
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_send_redirects

- name: Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces
    by Default - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040270
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_send_redirects

- name: Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces
    by Default - Find all files that contain net.ipv4.conf.default.send_redirects
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.default.send_redirects\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040270
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_send_redirects

- name: Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces
    by Default - Find all files that set net.ipv4.conf.default.send_redirects to correct
    value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.conf.default.send_redirects\s*=\s*0$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040270
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_send_redirects

- name: Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces
    by Default - Comment out any occurrences of net.ipv4.conf.default.send_redirects
    from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.conf.default.send_redirects
    replace: '#net.ipv4.conf.default.send_redirects'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040270
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_send_redirects

- name: Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces
    by Default - Comment out any occurrences of net.ipv4.conf.default.send_redirects
    from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.conf.default.send_redirects
    replace: '#net.ipv4.conf.default.send_redirects'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040270
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_send_redirects

- name: Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces
    by Default - Ensure sysctl net.ipv4.conf.default.send_redirects is set to 0
  ansible.posix.sysctl:
    name: net.ipv4.conf.default.send_redirects
    value: '0'
    sysctl_file: /etc/sysctl.d/net_ipv4_conf_default_send_redirects.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1.1
  - DISA-STIG-RHEL-08-040270
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.5
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_conf_default_send_redirects
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_net_ipv4_conf_default_send_redirects" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.ipv4.conf.default.send_redirects%3D0%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_ipv4_conf_default_send_redirects.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_conf_default_send_redirects:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_forward" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>net.ipv4.ip_forward</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.ipv4.ip_forward=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.ipv4.ip_forward = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="functionality">Certain technologies such as virtual machines, containers, etc. rely on IPv4 forwarding to enable and use networking.
Disabling IPv4 forwarding would cause those technologies to stop working. Therefore, this rule should not be used in
profiles or benchmarks that target usage of IPv4 forwarding.</xccdf-1.2:warning>
                <xccdf-1.2:warning category="general">This rule is disabled on Red Hat Virtualization Hosts and Managers, it will report not applicable.
RHV host requires IPv4 forwarding for the Hosted Engine bootstrap VM to reach network outside of the initial host.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.20</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.3.1.1</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Routing protocol daemons are typically used on routers to exchange
network topology information with other routers. If this capability is used when
not required, system network information may be unnecessarily transmitted across
the network.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#no_ovirt"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_ip_forward" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.ipv4.ip_forward from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.ipv4.ip_forward.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.ipv4.ip_forward" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_ipv4_ip_forward.conf'


#
# Set runtime for net.ipv4.ip_forward
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.ipv4.ip_forward="0"
fi

#
# If net.ipv4.ip_forward present in /etc/sysctl.conf, change value to "0"
#	else, add "net.ipv4.ip_forward = 0" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.ipv4.ip_forward")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "0"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.ipv4.ip_forward\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.ipv4.ip_forward\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_ipv4_ip_forward" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.3.1
  - PCI-DSS-Req-1.3.2
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_ip_forward

- name: Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces - Set fact for
    sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.3.1
  - PCI-DSS-Req-1.3.2
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_ip_forward

- name: Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces - Find all files
    that contain net.ipv4.ip_forward
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.ip_forward\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.3.1
  - PCI-DSS-Req-1.3.2
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_ip_forward

- name: Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces - Find all files
    that set net.ipv4.ip_forward to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.ipv4.ip_forward\s*=\s*0$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.3.1
  - PCI-DSS-Req-1.3.2
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_ip_forward

- name: Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces - Comment out
    any occurrences of net.ipv4.ip_forward from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.ipv4.ip_forward
    replace: '#net.ipv4.ip_forward'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.3.1
  - PCI-DSS-Req-1.3.2
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_ip_forward

- name: Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces - Comment out
    any occurrences of net.ipv4.ip_forward from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.ipv4.ip_forward
    replace: '#net.ipv4.ip_forward'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.3.1
  - PCI-DSS-Req-1.3.2
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_ip_forward

- name: Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces - Ensure sysctl
    net.ipv4.ip_forward is set to 0
  ansible.posix.sysctl:
    name: net.ipv4.ip_forward
    value: '0'
    sysctl_file: /etc/sysctl.d/net_ipv4_ip_forward.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.20
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-SC-5
  - NIST-800-53-SC-7(a)
  - PCI-DSS-Req-1.3.1
  - PCI-DSS-Req-1.3.2
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.3
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_ipv4_ip_forward
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_ipv4_ip_forward:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_ipv4_ip_forward_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_network-nftables">
            <xccdf-1.2:title>nftables</xccdf-1.2:title>
            <xccdf-1.2:description><html:code>If firewalld or iptables are being used in your environment, please follow the guidance in their
respective section and pass-over the guidance in this section.</html:code><html:br/><html:br/>
nftables is a subsystem of the Linux kernel providing filtering and classification of network
packets/datagrams/frames and is the successor to iptables. The biggest change with the
successor nftables is its simplicity. With iptables, we have to configure every single rule and
use the syntax which can be compared with normal commands. With nftables, the simpler
syntax, much like BPF (Berkely Packet Filter) means shorter lines and less repetition.
Support for nftables should also be compiled into the kernel, together with the related
nftables modules.
<html:br/><html:br/> 
It is available in Linux kernels &gt;= 3.13. <html:b>Please ensure that your kernel
supports nftables before choosing this option.</html:b></xccdf-1.2:description>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_nftables_family" interactive="true" type="string">
              <xccdf-1.2:title>Nftables Families</xccdf-1.2:title>
              <xccdf-1.2:description>Netfilter enables filtering at multiple networking levels. With iptables there 
is a separate tool for each level: iptables, ip6tables, arptables, ebtables. 
With nftables the multiple networking levels are abstracted into families, 
all of which are served  by the single tool nft. 
<html:code>ip</html:code>Tables of this family see IPv4 traffic/packets. 
<html:code>ip6</html:code>Tables of this family see IPv6 traffic/packets.
<html:code>inet</html:code>Tables of this family see both IPv4 and IPv6 traffic/packets, 
simplifying dual stack support. 
<html:code>arp</html:code>Tables of this family see ARP-level (i.e, L2) traffic, before 
any L3 handling is done by the kernel. 
<html:code>bridge</html:code>Tables of this family see traffic/packets traversing bridges 
(i.e. switching). No assumptions are made about L3 protocols. 
<html:code>netdev</html:code>The netdev family is different from the others in that it 
is used to create base chains attached to a single network interface. Such 
base chains see all network traffic on the specified interface, with no 
assumptions about L2 or L3 protocols. Therefore you can filter ARP traffic from here. </xccdf-1.2:description>
              <xccdf-1.2:value>inet</xccdf-1.2:value>
              <xccdf-1.2:value selector="ip">ip</xccdf-1.2:value>
              <xccdf-1.2:value selector="ip6">ip6</xccdf-1.2:value>
              <xccdf-1.2:value selector="inet">inet</xccdf-1.2:value>
              <xccdf-1.2:value selector="arp">arp</xccdf-1.2:value>
              <xccdf-1.2:value selector="bridge">bridge</xccdf-1.2:value>
              <xccdf-1.2:value selector="netdev">netdev</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_nftables_table" interactive="true" type="string">
              <xccdf-1.2:title>Nftables Tables</xccdf-1.2:title>
              <xccdf-1.2:description>Tables in nftables hold chains. Each table only has one address family and only applies 
to packets of this family. Tables can have one of six families.
 </xccdf-1.2:description>
              <xccdf-1.2:value>filter</xccdf-1.2:value>
              <xccdf-1.2:value selector="filter">filter</xccdf-1.2:value>
              <xccdf-1.2:value selector="firewalld">firewalld</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_nftables_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install nftables Package</xccdf-1.2:title>
              <xccdf-1.2:description>nftables provides a new in-kernel packet classification framework that is based on a
network-specific Virtual Machine (VM) and a new nft userspace command line tool.
nftables reuses the existing Netfilter subsystems such as the existing hook infrastructure,
the connection tracking system, NAT, userspace queuing and logging subsystem.
The <html:code>nftables</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install nftables</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale><html:code>nftables</html:code> is a subsystem of the Linux kernel that can protect against threats
originating from within a corporate network to include malicious mobile code and poorly
configured software on a host.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#service_disabled_iptables_and_service_disabled_ufw_and_system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nftables_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( ! (systemctl is-active iptables &amp;&gt;/dev/null) &amp;&amp; ! (systemctl is-active ufw &amp;&gt;/dev/null) &amp;&amp; rpm --quiet -q kernel ) ); then

if ! rpm -q --quiet "nftables" ; then
    yum install -y "nftables"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nftables_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_nftables_installed

- name: Ensure nftables is installed
  ansible.builtin.package:
    name: nftables
    state: present
  when: ( "kernel" in ansible_facts.packages )
  tags:
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_nftables_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nftables_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_nftables

class install_nftables {
  package { 'nftables':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nftables_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=nftables
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_nftables_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "nftables"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nftables_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install nftables
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nftables_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install nftables
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_nftables_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_nftables_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_nftables_enabled" selected="false" severity="medium">
              <xccdf-1.2:title>Verify nftables Service is Enabled</xccdf-1.2:title>
              <xccdf-1.2:description>The nftables service allows for the loading of nftables rulesets during boot,
or starting on the nftables service

The <html:code>nftables</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable nftables.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>The nftables service restores the nftables rules from the rules files referenced
in the <html:code>/etc/sysconfig/nftables.conf</html:code> file during boot or the starting of
the nftables service</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_nftables_and_service_disabled_firewalld_and_system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_nftables_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q nftables &amp;&amp; ! (systemctl is-active firewalld &amp;&gt;/dev/null) &amp;&amp; rpm --quiet -q kernel ) ); then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'nftables.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'nftables.service'
fi
"$SYSTEMCTL_EXEC" enable 'nftables.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_nftables_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_nftables_enabled

- name: Verify nftables Service is Enabled - Enable service nftables
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Verify nftables Service is Enabled - Enable Service nftables
    ansible.builtin.systemd:
      name: nftables
      enabled: true
      state: started
      masked: false
    when:
    - '"nftables" in ansible_facts.packages'
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_nftables_enabled
  - special_service_block
  when: ( "nftables" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_nftables_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_nftables

class enable_nftables {
  service {'nftables':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_nftables_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["nftables"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_nftables_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable nftables
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_nftables_enabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_nftables_enabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_nftables_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Verify nftables Service is Disabled</xccdf-1.2:title>
              <xccdf-1.2:description>nftables is a subsystem of the Linux kernel providing filtering and classification of network
packets/datagrams/frames and is the successor to iptables.
The <html:code>nftables</html:code> service can be disabled with the following command:
<html:pre>systemctl disable nftables</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Running both <html:code>firewalld</html:code> and <html:code>nftables</html:code> may lead to conflict. <html:code>nftables</html:code>
is actually one of the backends for <html:code>firewalld</html:code> management tools.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_firewalld_and_package_nftables_and_system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_nftables_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q firewalld &amp;&amp; rpm --quiet -q nftables &amp;&amp; rpm --quiet -q kernel ) ); then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'nftables.service'
fi
"$SYSTEMCTL_EXEC" disable 'nftables.service'
"$SYSTEMCTL_EXEC" mask 'nftables.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files nftables.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'nftables.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'nftables.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'nftables.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_nftables_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.1
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_nftables_disabled

- name: Verify nftables Service is Disabled - Disable service nftables
  block:

  - name: Verify nftables Service is Disabled - Collect systemd Services Present in
      the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Verify nftables Service is Disabled - Ensure nftables.service is Masked
    ansible.builtin.systemd:
      name: nftables.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("nftables.service", multiline=True)

  - name: Unit Socket Exists - nftables.socket
    ansible.builtin.command: systemctl -q list-unit-files nftables.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Verify nftables Service is Disabled - Disable Socket nftables
    ansible.builtin.systemd:
      name: nftables.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("nftables.socket", multiline=True)
  tags:
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.1
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_nftables_disabled
  - special_service_block
  when: ( "firewalld" in ansible_facts.packages and "nftables" in ansible_facts.packages
    and "kernel" in ansible_facts.packages )
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_nftables_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_nftables

class disable_nftables {
  service {'nftables':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_nftables_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: nftables.service
        enabled: false
        mask: true
      - name: nftables.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_nftables_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["nftables"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_nftables_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable nftables
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_nftables_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_nftables_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_nftables" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Group Who Owns /etc/nftables Directory</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/nftables</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/nftables</html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The ownership of the /etc/nftables directory by the root group is important
because this directory hosts nftables configuration. Protection of this
directory is critical for system security. Assigning the ownership to root
ensures exclusive control of the nftables configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_nftables"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_groupowner_etc_nftables" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q nftables; then

newgroup=""
if getent group "root" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="root"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "root is not a defined group on the system"
else
find -P /etc/nftables/ -maxdepth 0 -type d  ! -group root -exec chgrp --no-dereference "$newgroup" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_groupowner_etc_nftables" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_groupowner_etc_nftables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Check that the root group is defined
  ansible.builtin.getent:
    database: group
    key: root
  ignore_errors: true
  when:
  - '"nftables" in ansible_facts.packages'
  - directory_groupowner_etc_nftables_newgroup is undefined
  tags:
  - configure_strategy
  - directory_groupowner_etc_nftables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the directory_groupowner_etc_nftables_newgroup variable if root found
  ansible.builtin.set_fact:
    directory_groupowner_etc_nftables_newgroup: root
  when:
  - '"nftables" in ansible_facts.packages'
  - ansible_facts.getent_group["root"] is defined
  tags:
  - configure_strategy
  - directory_groupowner_etc_nftables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/nftables/
  ansible.builtin.file:
    path: /etc/nftables/
    follow: false
    state: directory
    group: '{{ directory_groupowner_etc_nftables_newgroup }}'
  when: '"nftables" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_groupowner_etc_nftables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_groupowner_etc_nftables:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_groupowner_etc_nftables_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_owner_etc_nftables" selected="false" severity="medium">
              <xccdf-1.2:title>Verify User Who Owns /etc/nftables Directory</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the owner of <html:code>/etc/nftables</html:code>, run the command:
<html:pre>$ sudo chown root /etc/nftables </html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The ownership of the /etc/nftables directory by the root user is important
because this directory hosts nftables configuration. Protection of this
directory is critical for system security. Assigning the ownership to root
ensures exclusive control of the nftables configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_nftables"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_owner_etc_nftables" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q nftables; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
find -P /etc/nftables/ -maxdepth 0 -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_owner_etc_nftables" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_owner_etc_nftables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the directory_owner_etc_nftables_newown variable if represented by uid
  ansible.builtin.set_fact:
    directory_owner_etc_nftables_newown: '0'
  when: '"nftables" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_owner_etc_nftables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /etc/nftables/
  ansible.builtin.file:
    path: /etc/nftables/
    follow: false
    state: directory
    owner: '{{ directory_owner_etc_nftables_newown }}'
  when: '"nftables" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_owner_etc_nftables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_owner_etc_nftables:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_owner_etc_nftables_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_permissions_etc_nftables" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Permissions On /etc/nftables Directory</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/nftables</html:code>, run the command: <html:pre>$ sudo chmod 0700 /etc/nftables</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Setting correct permissions on the /etc/nftables directory is important
because this directory hosts nftables configuration. Protection of this
directory is critical for system security. Restricting the permissions
ensures exclusive control of the nftables configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_nftables"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_permissions_etc_nftables" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q nftables; then

find -H /etc/nftables/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt -type d -exec chmod u-s,g-xwrs,o-xwrt {} \;

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="directory_permissions_etc_nftables" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_permissions_etc_nftables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/nftables/ file(s)
  ansible.builtin.command: 'find -P /etc/nftables/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt  -type
    d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"nftables" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_permissions_etc_nftables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /etc/nftables/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-xwrs,o-xwrt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"nftables" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_permissions_etc_nftables
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_permissions_etc_nftables:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_permissions_etc_nftables_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_set_nftables_table" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure a Table Exists for Nftables</xccdf-1.2:title>
              <xccdf-1.2:description>Tables in nftables hold chains. Each table only has one address family and only applies
to packets of this family. Tables can have one of six families.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Adding or editing rules in a running nftables can cause loss of connectivity to the system.</xccdf-1.2:warning>
              <xccdf-1.2:warning category="general">Both the SCE check and remediation for this rule only consider runtime settings.
There is no specific file to check as it depends on each site's policy. Therefore, check
and remediation use the nft command directly. The fix is not persistent across system
reboots.</xccdf-1.2:warning>
              <xccdf-1.2:warning category="functionality">SCE check does not support variables, therefore the SCE check in this rule only checks the
address family, regardless of the table name.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>Nftables doesn't have any default tables. Without a table being built, nftables will not
filter network traffic.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_nftables"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="set_nftables_table" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q nftables; then

var_nftables_family='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nftables_family" use="legacy"/>'

var_nftables_table='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nftables_table" use="legacy"/>'


if ! nft list table $var_nftables_family $var_nftables_table; then
  nft create table "$var_nftables_family" "$var_nftables_table"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="set_nftables_table" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - set_nftables_table
- name: XCCDF Value var_nftables_family # promote to variable
  set_fact:
    var_nftables_family: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nftables_family" use="legacy"/>
  tags:
    - always
- name: XCCDF Value var_nftables_table # promote to variable
  set_fact:
    var_nftables_table: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nftables_table" use="legacy"/>
  tags:
    - always

- name: Collect Existing Nftables
  ansible.builtin.command: nft list table {{ var_nftables_family }} {{ var_nftables_table
    }}
  register: result_nftables_table_family
  changed_when: false
  failed_when: result_nftables_table_family.rc not in [0, 1]
  when: '"nftables" in ansible_facts.packages'
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - set_nftables_table

- name: Set Nftable Table
  ansible.builtin.command: nft create table {{ var_nftables_family }} {{ var_nftables_table
    }}
  when:
  - '"nftables" in ansible_facts.packages'
  - result_nftables_table_family is not skipped
  - result_nftables_table_family.rc != 0
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - set_nftables_table
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-set_nftables_table_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_network-ufw">
            <xccdf-1.2:title>Uncomplicated Firewall (ufw)</xccdf-1.2:title>
            <xccdf-1.2:description>The Linux kernel in Ubuntu provides a packet filtering system called
netfilter, and the traditional interface for manipulating netfilter are
the iptables suite of commands. iptables provide a complete firewall
solution that is both highly configurable and highly flexible.

Becoming proficient in iptables takes time, and getting started with
netfilter firewalling using only iptables can be a daunting task. As a
result, many frontends for iptables have been created over the years,
each trying to achieve a different result and targeting a different
audience.

The Uncomplicated Firewall (ufw) is a frontend for iptables and is
particularly well-suited for host-based firewalls. ufw provides a
framework for managing netfilter, as well as a command-line interface
for manipulating the firewall. ufw aims to provide an easy to use
interface for people unfamiliar with firewall concepts, while at the
same time simplifies complicated iptables commands to help an
administrator who knows what he or she is doing. ufw is an upstream
for other distributions and graphical frontends.</xccdf-1.2:description>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_ufw_enabled" selected="false" severity="medium">
              <xccdf-1.2:title>Verify ufw Enabled</xccdf-1.2:title>
              <xccdf-1.2:description>
The <html:code>ufw</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable ufw.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000297-GPOS-00115</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The ufw service must be enabled and running in order for ufw to protect the system</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_ufw_and_system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_ufw_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { ( ( rpm --quiet -q ufw &amp;&amp; rpm --quiet -q kernel ) ); }; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'ufw.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'ufw.service'
fi
"$SYSTEMCTL_EXEC" enable 'ufw.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_ufw_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_ufw_enabled

- name: Verify ufw Enabled - Enable service ufw
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Verify ufw Enabled - Enable Service ufw
    ansible.builtin.systemd:
      name: ufw
      enabled: true
      state: started
      masked: false
    when:
    - '"ufw" in ansible_facts.packages'
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_ufw_enabled
  - special_service_block
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "ufw" in ansible_facts.packages and "kernel" in ansible_facts.packages )
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_ufw_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_ufw

class enable_ufw {
  service {'ufw':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_ufw_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["ufw"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_ufw_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable ufw
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_ufw_enabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_ufw_enabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_network-uncommon">
            <xccdf-1.2:title>Uncommon Network Protocols</xccdf-1.2:title>
            <xccdf-1.2:description>The system includes support for several network protocols which are not commonly used.
Although security vulnerabilities in kernel networking code are not frequently discovered,
the consequences can be dramatic. Ensuring uncommon network protocols are disabled
reduces the system's risk to attacks targeted at its implementation of those protocols.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Although these protocols are not commonly used, avoid disruption
in your network environment by ensuring they are not needed
prior to disabling them.</xccdf-1.2:warning>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_atm_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable ATM Support</xccdf-1.2:title>
              <xccdf-1.2:description>The Asynchronous Transfer Mode (ATM) is a protocol operating on
network, data link, and physical layers, based on virtual circuits
and virtual paths.

To configure the system to prevent the <html:code>atm</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/atm.conf</html:code>:
<html:pre>install atm /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>atm</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install atm /bin/true</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040021</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230494r1069310_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Disabling ATM protects the system against exploitation of any
flaws in its implementation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_atm_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install atm" /etc/modprobe.d/atm.conf ; then
	
	sed -i 's#^install atm.*#install atm /bin/false#g' /etc/modprobe.d/atm.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/atm.conf
	echo "install atm /bin/false" &gt;&gt; /etc/modprobe.d/atm.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_atm_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040021
  - NIST-800-53-AC-18
  - disable_strategy
  - kernel_module_atm_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required

- name: Ensure kernel module 'atm' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/atm.conf
    regexp: install\s+atm
    line: install atm /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040021
  - NIST-800-53-AC-18
  - disable_strategy
  - kernel_module_atm_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_atm_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20atm%20/bin/false%0Ablacklist%20atm%0A
        mode: 0644
        path: /etc/modprobe.d/atm.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_atm_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_module_atm_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_can_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable CAN Support</xccdf-1.2:title>
              <xccdf-1.2:description>The Controller Area Network (CAN) is a serial communications
protocol which was initially developed for automotive and
is now also used in marine, industrial, and medical applications.

To configure the system to prevent the <html:code>can</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/can.conf</html:code>:
<html:pre>install can /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>can</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install can /bin/true</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040022</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230495r1069311_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Disabling CAN protects the system against exploitation of any
flaws in its implementation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_can_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install can" /etc/modprobe.d/can.conf ; then
	
	sed -i 's#^install can.*#install can /bin/false#g' /etc/modprobe.d/can.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/can.conf
	echo "install can /bin/false" &gt;&gt; /etc/modprobe.d/can.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_can_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040022
  - NIST-800-53-AC-18
  - disable_strategy
  - kernel_module_can_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required

- name: Ensure kernel module 'can' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/can.conf
    regexp: install\s+can
    line: install can /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040022
  - NIST-800-53-AC-18
  - disable_strategy
  - kernel_module_can_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_can_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20can%20/bin/false%0Ablacklist%20can%0A
        mode: 0644
        path: /etc/modprobe.d/can.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_can_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_module_can_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_dccp_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable DCCP Support</xccdf-1.2:title>
              <xccdf-1.2:description>The Datagram Congestion Control Protocol (DCCP) is a
relatively new transport layer protocol, designed to support
streaming media and telephony.

To configure the system to prevent the <html:code>dccp</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/dccp.conf</html:code>:
<html:pre>install dccp /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>dccp</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install dccp /bin/true</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000096-GPOS-00050</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000378-GPOS-00163</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.2.3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Disabling DCCP protects
the system against exploitation of any flaws in its implementation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_dccp_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install dccp" /etc/modprobe.d/dccp.conf ; then
	
	sed -i 's#^install dccp.*#install dccp /bin/false#g' /etc/modprobe.d/dccp.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/dccp.conf
	echo "install dccp /bin/false" &gt;&gt; /etc/modprobe.d/dccp.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_dccp_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.10.1
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSS-Req-1.4.2
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - kernel_module_dccp_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required

- name: Ensure kernel module 'dccp' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/dccp.conf
    regexp: install\s+dccp
    line: install dccp /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSS-Req-1.4.2
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - kernel_module_dccp_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_dccp_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20dccp%20/bin/false%0Ablacklist%20dccp%0A
        mode: 0644
        path: /etc/modprobe.d/dccp.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_dccp_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_module_dccp_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_firewire-core_disabled" selected="false" severity="low">
              <xccdf-1.2:title>Disable IEEE 1394 (FireWire) Support</xccdf-1.2:title>
              <xccdf-1.2:description>The IEEE 1394 (FireWire) is a serial bus standard for
high-speed real-time communication.

To configure the system to prevent the <html:code>firewire-core</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/firewire-core.conf</html:code>:
<html:pre>install firewire-core /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>firewire-core</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install firewire-core /bin/true</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040026</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230499r1069315_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Disabling FireWire protects the system against exploitation of any
flaws in its implementation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_firewire-core_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install firewire-core" /etc/modprobe.d/firewire-core.conf ; then
	
	sed -i 's#^install firewire-core.*#install firewire-core /bin/false#g' /etc/modprobe.d/firewire-core.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/firewire-core.conf
	echo "install firewire-core /bin/false" &gt;&gt; /etc/modprobe.d/firewire-core.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_firewire-core_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040026
  - NIST-800-53-AC-18
  - disable_strategy
  - kernel_module_firewire-core_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required

- name: Ensure kernel module 'firewire-core' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/firewire-core.conf
    regexp: install\s+firewire-core
    line: install firewire-core /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040026
  - NIST-800-53-AC-18
  - disable_strategy
  - kernel_module_firewire-core_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_firewire-core_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20firewire-core%20/bin/false%0Ablacklist%20firewire-core%0A
        mode: 0644
        path: /etc/modprobe.d/firewire-core.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_firewire-core_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_module_firewire-core_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_rds_disabled" selected="false" severity="low">
              <xccdf-1.2:title>Disable RDS Support</xccdf-1.2:title>
              <xccdf-1.2:description>The Reliable Datagram Sockets (RDS) protocol is a transport
layer protocol designed to provide reliable high-bandwidth,
low-latency communications between nodes in a cluster.

To configure the system to prevent the <html:code>rds</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/rds.conf</html:code>:
<html:pre>install rds /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>rds</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install rds /bin/true</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.2.4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Disabling RDS protects
the system against exploitation of any flaws in its implementation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_rds_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install rds" /etc/modprobe.d/rds.conf ; then
	
	sed -i 's#^install rds.*#install rds /bin/false#g' /etc/modprobe.d/rds.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/rds.conf
	echo "install rds /bin/false" &gt;&gt; /etc/modprobe.d/rds.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_rds_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_rds_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required

- name: Ensure kernel module 'rds' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/rds.conf
    regexp: install\s+rds
    line: install rds /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_rds_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_rds_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20rds%20/bin/false%0Ablacklist%20rds%0A
        mode: 0644
        path: /etc/modprobe.d/rds.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_rds_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_module_rds_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_sctp_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable SCTP Support</xccdf-1.2:title>
              <xccdf-1.2:description>The Stream Control Transmission Protocol (SCTP) is a
transport layer protocol, designed to support the idea of
message-oriented communication, with several streams of messages
within one connection.

To configure the system to prevent the <html:code>sctp</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/sctp.conf</html:code>:
<html:pre>install sctp /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>sctp</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install sctp /bin/true</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.10.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040023</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230496r1069312_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Disabling SCTP protects
the system against exploitation of any flaws in its implementation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_sctp_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install sctp" /etc/modprobe.d/sctp.conf ; then
	
	sed -i 's#^install sctp.*#install sctp /bin/false#g' /etc/modprobe.d/sctp.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/sctp.conf
	echo "install sctp /bin/false" &gt;&gt; /etc/modprobe.d/sctp.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_sctp_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.10.1
  - DISA-STIG-RHEL-08-040023
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSS-Req-1.4.2
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - kernel_module_sctp_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required

- name: Ensure kernel module 'sctp' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/sctp.conf
    regexp: install\s+sctp
    line: install sctp /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.10.1
  - DISA-STIG-RHEL-08-040023
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSS-Req-1.4.2
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - disable_strategy
  - kernel_module_sctp_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_sctp_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20sctp%20/bin/false%0Ablacklist%20sctp%0A
        mode: 0644
        path: /etc/modprobe.d/sctp.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_sctp_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_module_sctp_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_tipc_disabled" selected="false" severity="low">
              <xccdf-1.2:title>Disable TIPC Support</xccdf-1.2:title>
              <xccdf-1.2:description>The Transparent Inter-Process Communication (TIPC) protocol
is designed to provide communications between nodes in a
cluster.

To configure the system to prevent the <html:code>tipc</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/tipc.conf</html:code>:
<html:pre>install tipc /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>tipc</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install tipc /bin/true</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This configuration baseline was created to deploy the base operating system for general purpose
workloads. When the operating system is configured for certain purposes, such as
a node in High Performance Computing cluster, it is expected that
the <html:code>tipc</html:code> kernel module will be loaded.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040024</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230497r1069313_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Disabling TIPC protects
the system against exploitation of any flaws in its implementation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_tipc_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install tipc" /etc/modprobe.d/tipc.conf ; then
	
	sed -i 's#^install tipc.*#install tipc /bin/false#g' /etc/modprobe.d/tipc.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/tipc.conf
	echo "install tipc /bin/false" &gt;&gt; /etc/modprobe.d/tipc.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_tipc_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040024
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_tipc_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required

- name: Ensure kernel module 'tipc' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/tipc.conf
    regexp: install\s+tipc
    line: install tipc /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040024
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_tipc_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_tipc_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20tipc%20/bin/false%0Ablacklist%20tipc%0A
        mode: 0644
        path: /etc/modprobe.d/tipc.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_tipc_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_network-wireless">
            <xccdf-1.2:title>Wireless Networking</xccdf-1.2:title>
            <xccdf-1.2:description>Wireless networking, such as 802.11
(WiFi) and Bluetooth, can present a security risk to sensitive or
classified systems and networks. Wireless networking hardware is
much more likely to be included in laptop or portable systems than
in desktops or servers. 
<html:br/><html:br/>
Removal of hardware provides the greatest assurance that the wireless
capability remains disabled. Acquisition policies often include provisions to
prevent the purchase of equipment that will be used in sensitive spaces and
includes wireless capabilities. If it is impractical to remove the wireless
hardware, and policy permits the device to enter sensitive spaces as long
as wireless is disabled, efforts should instead focus on disabling wireless capability
via software.</xccdf-1.2:description>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_wireless_software">
              <xccdf-1.2:title>Disable Wireless Through Software Configuration</xccdf-1.2:title>
              <xccdf-1.2:description>If it is impossible to remove the wireless hardware
from the device in question, disable as much of it as possible
through software. The following methods can disable software
support for wireless networking, but note that these methods do not
prevent malicious software or careless users from re-activating the
devices.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_bluetooth_disabled" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Bluetooth Service</xccdf-1.2:title>
                <xccdf-1.2:description>
The <html:code>bluetooth</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now bluetooth.service</html:pre>
<html:pre>$ sudo service bluetooth stop</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.1.3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Disabling the <html:code>bluetooth</html:code> service prevents the system from attempting
connections to Bluetooth devices, which entails some security risk.
Nevertheless, variation in this risk decision may be expected due to the
utility of Bluetooth connectivity and its limited range.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_bluetooth_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'bluetooth.service'
fi
"$SYSTEMCTL_EXEC" disable 'bluetooth.service'
"$SYSTEMCTL_EXEC" mask 'bluetooth.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files bluetooth.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'bluetooth.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'bluetooth.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'bluetooth.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_bluetooth_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.16
  - NIST-800-53-AC-18(3)
  - NIST-800-53-AC-18(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_bluetooth_disabled

- name: Disable Bluetooth Service - Disable service bluetooth
  block:

  - name: Disable Bluetooth Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Bluetooth Service - Ensure bluetooth.service is Masked
    ansible.builtin.systemd:
      name: bluetooth.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("bluetooth.service", multiline=True)

  - name: Unit Socket Exists - bluetooth.socket
    ansible.builtin.command: systemctl -q list-unit-files bluetooth.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Bluetooth Service - Disable Socket bluetooth
    ansible.builtin.systemd:
      name: bluetooth.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("bluetooth.socket", multiline=True)
  tags:
  - NIST-800-171-3.1.16
  - NIST-800-53-AC-18(3)
  - NIST-800-53-AC-18(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_bluetooth_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_bluetooth_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_bluetooth

class disable_bluetooth {
  service {'bluetooth':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="service_bluetooth_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: bluetooth.service
        enabled: false
        mask: true
      - name: bluetooth.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="service_bluetooth_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["bluetooth"]
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_bluetooth_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable bluetooth
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_bluetooth_disabled:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_bluetooth_disabled_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_bluetooth_disabled" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Bluetooth Kernel Module</xccdf-1.2:title>
                <xccdf-1.2:description>The kernel's module loading system can be configured to prevent
loading of the Bluetooth module. Add the following to
the appropriate <html:code>/etc/modprobe.d</html:code> configuration file
to prevent the loading of the Bluetooth module:
<html:pre>install bluetooth /bin/true</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000300-GPOS-00118</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040111</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230507r1017287_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If Bluetooth functionality must be disabled, preventing the kernel
from loading the kernel module provides an additional safeguard against its
activation.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_bluetooth_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install bluetooth" /etc/modprobe.d/bluetooth.conf ; then
	
	sed -i 's#^install bluetooth.*#install bluetooth /bin/false#g' /etc/modprobe.d/bluetooth.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/bluetooth.conf
	echo "install bluetooth /bin/false" &gt;&gt; /etc/modprobe.d/bluetooth.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_bluetooth_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.13.1.3
  - DISA-STIG-RHEL-08-040111
  - NIST-800-171-3.1.16
  - NIST-800-53-AC-18(3)
  - NIST-800-53-AC-18(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - disable_strategy
  - kernel_module_bluetooth_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required

- name: Ensure kernel module 'bluetooth' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/bluetooth.conf
    regexp: install\s+bluetooth
    line: install bluetooth /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.13.1.3
  - DISA-STIG-RHEL-08-040111
  - NIST-800-171-3.1.16
  - NIST-800-53-AC-18(3)
  - NIST-800-53-AC-18(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - disable_strategy
  - kernel_module_bluetooth_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_bluetooth_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20bluetooth%20/bin/false%0Ablacklist%20bluetooth%0A
        mode: 0644
        path: /etc/modprobe.d/bluetooth.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_bluetooth_disabled:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_module_bluetooth_disabled_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_cfg80211_disabled" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel cfg80211 Module</xccdf-1.2:title>
                <xccdf-1.2:description>
To configure the system to prevent the <html:code>cfg80211</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/cfg80211.conf</html:code>:
<html:pre>install cfg80211 /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>cfg80211</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install cfg80211 /bin/true</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(4)</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If Wireless functionality must be disabled, preventing the kernel
from loading the kernel module provides an additional safeguard against its
activation.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_cfg80211_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install cfg80211" /etc/modprobe.d/cfg80211.conf ; then
	
	sed -i 's#^install cfg80211.*#install cfg80211 /bin/false#g' /etc/modprobe.d/cfg80211.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/cfg80211.conf
	echo "install cfg80211 /bin/false" &gt;&gt; /etc/modprobe.d/cfg80211.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_cfg80211_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-18(3)
  - NIST-800-53-AC-18(4)
  - NIST-800-53-AC-18(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - disable_strategy
  - kernel_module_cfg80211_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required

- name: Ensure kernel module 'cfg80211' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/cfg80211.conf
    regexp: install\s+cfg80211
    line: install cfg80211 /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-18(3)
  - NIST-800-53-AC-18(4)
  - NIST-800-53-AC-18(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - disable_strategy
  - kernel_module_cfg80211_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_cfg80211_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20cfg80211%20/bin/false%0Ablacklist%20cfg80211%0A
        mode: 0644
        path: /etc/modprobe.d/cfg80211.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_cfg80211_disabled:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_module_cfg80211_disabled_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_iwlmvm_disabled" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel iwlmvm Module</xccdf-1.2:title>
                <xccdf-1.2:description>
To configure the system to prevent the <html:code>iwlmvm</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/iwlmvm.conf</html:code>:
<html:pre>install iwlmvm /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>iwlmvm</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install iwlmvm /bin/true</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(4)</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If Wireless functionality must be disabled, preventing the kernel
from loading the kernel module provides an additional safeguard against its
activation.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_iwlmvm_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install iwlmvm" /etc/modprobe.d/iwlmvm.conf ; then
	
	sed -i 's#^install iwlmvm.*#install iwlmvm /bin/false#g' /etc/modprobe.d/iwlmvm.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/iwlmvm.conf
	echo "install iwlmvm /bin/false" &gt;&gt; /etc/modprobe.d/iwlmvm.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_iwlmvm_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-18(3)
  - NIST-800-53-AC-18(4)
  - NIST-800-53-AC-18(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - disable_strategy
  - kernel_module_iwlmvm_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required

- name: Ensure kernel module 'iwlmvm' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/iwlmvm.conf
    regexp: install\s+iwlmvm
    line: install iwlmvm /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-18(3)
  - NIST-800-53-AC-18(4)
  - NIST-800-53-AC-18(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - disable_strategy
  - kernel_module_iwlmvm_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_iwlmvm_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20iwlmvm%20/bin/false%0Ablacklist%20iwlmvm%0A
        mode: 0644
        path: /etc/modprobe.d/iwlmvm.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_iwlmvm_disabled:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_module_iwlmvm_disabled_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_iwlwifi_disabled" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel iwlwifi Module</xccdf-1.2:title>
                <xccdf-1.2:description>
To configure the system to prevent the <html:code>iwlwifi</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/iwlwifi.conf</html:code>:
<html:pre>install iwlwifi /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>iwlwifi</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install iwlwifi /bin/true</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(4)</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If Wireless functionality must be disabled, preventing the kernel
from loading the kernel module provides an additional safeguard against its
activation.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_iwlwifi_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install iwlwifi" /etc/modprobe.d/iwlwifi.conf ; then
	
	sed -i 's#^install iwlwifi.*#install iwlwifi /bin/false#g' /etc/modprobe.d/iwlwifi.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/iwlwifi.conf
	echo "install iwlwifi /bin/false" &gt;&gt; /etc/modprobe.d/iwlwifi.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_iwlwifi_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-18(3)
  - NIST-800-53-AC-18(4)
  - NIST-800-53-AC-18(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - disable_strategy
  - kernel_module_iwlwifi_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required

- name: Ensure kernel module 'iwlwifi' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/iwlwifi.conf
    regexp: install\s+iwlwifi
    line: install iwlwifi /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-18(3)
  - NIST-800-53-AC-18(4)
  - NIST-800-53-AC-18(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - disable_strategy
  - kernel_module_iwlwifi_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_iwlwifi_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20iwlwifi%20/bin/false%0Ablacklist%20iwlwifi%0A
        mode: 0644
        path: /etc/modprobe.d/iwlwifi.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_iwlwifi_disabled:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_module_iwlwifi_disabled_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_mac80211_disabled" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Kernel mac80211 Module</xccdf-1.2:title>
                <xccdf-1.2:description>
To configure the system to prevent the <html:code>mac80211</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/mac80211.conf</html:code>:
<html:pre>install mac80211 /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>mac80211</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install mac80211 /bin/true</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(4)</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If Wireless functionality must be disabled, preventing the kernel
from loading the kernel module provides an additional safeguard against its
activation.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_mac80211_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install mac80211" /etc/modprobe.d/mac80211.conf ; then
	
	sed -i 's#^install mac80211.*#install mac80211 /bin/false#g' /etc/modprobe.d/mac80211.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/mac80211.conf
	echo "install mac80211 /bin/false" &gt;&gt; /etc/modprobe.d/mac80211.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_mac80211_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-18(3)
  - NIST-800-53-AC-18(4)
  - NIST-800-53-AC-18(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - disable_strategy
  - kernel_module_mac80211_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required

- name: Ensure kernel module 'mac80211' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/mac80211.conf
    regexp: install\s+mac80211
    line: install mac80211 /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-18(3)
  - NIST-800-53-AC-18(4)
  - NIST-800-53-AC-18(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - disable_strategy
  - kernel_module_mac80211_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_mac80211_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20mac80211%20/bin/false%0Ablacklist%20mac80211%0A
        mode: 0644
        path: /etc/modprobe.d/mac80211.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_mac80211_disabled:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_module_mac80211_disabled_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_wireless_disable_in_bios" selected="false" severity="unknown">
                <xccdf-1.2:title>Disable WiFi or Bluetooth in BIOS</xccdf-1.2:title>
                <xccdf-1.2:description>Some machines that include built-in wireless support offer the
ability to disable the device through the BIOS. This is hardware-specific;
consult your hardware manual or explore the BIOS setup during
boot.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Disabling wireless support in the BIOS prevents easy
activation of the wireless interface, generally requiring administrators
to reboot the system first.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-wireless_disable_in_bios_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_wireless_disable_interfaces" selected="false" severity="medium">
                <xccdf-1.2:title>Deactivate Wireless Network Interfaces</xccdf-1.2:title>
                <xccdf-1.2:description>Deactivating wireless network interfaces should prevent normal usage of the wireless
capability.
<html:br/><html:br/>

Configure the system to disable all wireless network interfaces with the following command:
<html:pre>$ sudo nmcli radio all off</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-18(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-1.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000299-GPOS-00117</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000300-GPOS-00118</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000424-GPOS-00188</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000481-GPOS-00481</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1315</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1319</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">3.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040110</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230506r1017286_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The use of wireless networking can introduce many different attack vectors into
the organization's network. Common attack vectors such as malicious association
and ad hoc networks will allow an attacker to spoof a wireless access point
(AP), allowing validated systems to connect to the malicious AP and enabling the
attacker to monitor and record network traffic. These malicious APs can also
serve to create a man-in-the-middle attack or be used to create a denial of
service to valid network resources.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#not_container_and_wifi-iface"/>
                <xccdf-1.2:fix id="wireless_disable_interfaces" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) ); then

if ! rpm -q --quiet "NetworkManager" ; then
    yum install -y "NetworkManager"
fi

if command -v nmcli &gt;/dev/null 2&gt;&amp;1 &amp;&amp; systemctl is-active NetworkManager &gt;/dev/null 2&gt;&amp;1; then
    nmcli radio all off
fi

if command -v wicked &gt;/dev/null 2&gt;&amp;1 &amp;&amp; systemctl is-active wickedd &gt;/dev/null 2&gt;&amp;1; then
  if [ -n "$(find /sys/class/net/*/ -type d -name wireless)" ]; then
    interfaces=$(find /sys/class/net/*/wireless -type d -name wireless | xargs -0 dirname | xargs basename)
    for iface in $interfaces; do
      wicked ifdown $iface
      sed -i 's/STARTMODE=.*/STARTMODE=off/' /etc/sysconfig/network/ifcfg-$iface
    done
  fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="wireless_disable_interfaces" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040110
  - NIST-800-171-3.1.16
  - NIST-800-53-AC-18(3)
  - NIST-800-53-AC-18(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - PCI-DSS-Req-1.3.3
  - PCI-DSSv4-1.3
  - PCI-DSSv4-1.3.3
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
  - wireless_disable_interfaces

- name: Deactivate Wireless Network Interfaces - Service facts
  ansible.builtin.service_facts: null
  when: ( not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman",
    "container"] ) )
  tags:
  - DISA-STIG-RHEL-08-040110
  - NIST-800-171-3.1.16
  - NIST-800-53-AC-18(3)
  - NIST-800-53-AC-18(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - PCI-DSS-Req-1.3.3
  - PCI-DSSv4-1.3
  - PCI-DSSv4-1.3.3
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
  - wireless_disable_interfaces

- name: Deactivate Wireless Network Interfaces - Ensure NetworkManager is installed
  ansible.builtin.package:
    name: '{{ item }}'
    state: present
  with_items:
  - NetworkManager
  when: ( not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman",
    "container"] ) )
  tags:
  - DISA-STIG-RHEL-08-040110
  - NIST-800-171-3.1.16
  - NIST-800-53-AC-18(3)
  - NIST-800-53-AC-18(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - PCI-DSS-Req-1.3.3
  - PCI-DSSv4-1.3
  - PCI-DSSv4-1.3.3
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
  - wireless_disable_interfaces

- name: Deactivate Wireless Network Interfaces - NetworkManager Deactivate Wireless
    Network Interfaces
  ansible.builtin.command: nmcli radio wifi off
  when:
  - ( not ( ansible_virtualization_type in ["docker", "lxc", "openvz", "podman", "container"]
    ) )
  - '''NetworkManager'' in ansible_facts.packages'
  - ('NetworkManager.service' in ansible_facts.services and ansible_facts.services['NetworkManager.service'].state
    == 'running')
  tags:
  - DISA-STIG-RHEL-08-040110
  - NIST-800-171-3.1.16
  - NIST-800-53-AC-18(3)
  - NIST-800-53-AC-18(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - PCI-DSS-Req-1.3.3
  - PCI-DSSv4-1.3
  - PCI-DSSv4-1.3.3
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - unknown_strategy
  - wireless_disable_interfaces
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-wireless_disable_interfaces:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-wireless_disable_interfaces_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_permissions">
          <xccdf-1.2:title>File Permissions and Masks</xccdf-1.2:title>
          <xccdf-1.2:description>Traditional Unix security relies heavily on file and
directory permissions to prevent unauthorized users from reading or
modifying files to which they should not have access.
<html:br/><html:br/>
Several of the commands in this section search filesystems
for files or directories with certain characteristics, and are
intended to be run on every local partition on a given system.
When the variable <html:i>PART</html:i> appears in one of the commands below,
it means that the command is intended to be run repeatedly, with the
name of each local partition substituted for <html:i>PART</html:i> in turn.
<html:br/><html:br/>
The following command prints a list of all xfs partitions on the local
system, which is the default filesystem for AlmaLinux OS 8
installations:
<html:pre>$ mount -t xfs | awk '{print $3}'</html:pre>
For any systems that use a different
local filesystem type, modify this command as appropriate.</xccdf-1.2:description>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_files">
            <xccdf-1.2:title>Verify Permissions on Important Files and
Directories</xccdf-1.2:title>
            <xccdf-1.2:description>Permissions for many files on a system must be set
restrictively to ensure sensitive information is properly protected.
This section discusses important
permission restrictions which can be verified
to ensure that no harmful discrepancies have
arisen.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_root_owned" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure All World-Writable Directories Are Owned by root User</xccdf-1.2:title>
              <xccdf-1.2:description>All directories in local partitions which are world-writable should be owned by root.
If any world-writable directories are not owned by root, this should be investigated.
Following this, the files should be deleted or assigned to root user.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000138-GPOS-00069</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R54</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010700</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230318r1155352_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Allowing a user account to own a world-writable directory is undesirable because it allows the
owner of that directory to remove or replace any files that may be placed in the directory by
other users.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="dir_perms_world_writable_root_owned" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh">
# At least under containerized env /proc can have files w/o possilibity to
# modify even as root. And touching /proc is not good idea anyways.
find / -path /proc -prune -o \
    -not -fstype afs -not -fstype autofs -not -fstype ceph -not -fstype cifs -not -fstype smb3 \
    -not -fstype smbfs -not -fstype sshfs -not -fstype ncpfs -not -fstype ncp -not -fstype nfs \
    -not -fstype nfs4 -not -fstype gfs -not -fstype gfs2 -not -fstype glusterfs -not -fstype gpfs \
    -not -fstype pvfs2 -not -fstype ocfs2 -not -fstype lustre -not -fstype davfs \
    -not -fstype fuse.sshfs -type d -perm -0002 -uid +0 -exec chown root {} \;
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="dir_perms_world_writable_root_owned" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Ensure All World-Writable Directories Are Owned by root User - Define Excluded
    (Non-Local) File Systems and Paths
  ansible.builtin.set_fact:
    excluded_fstypes:
    - afs
    - autofs
    - ceph
    - cifs
    - smb3
    - smbfs
    - sshfs
    - ncpfs
    - ncp
    - nfs
    - nfs4
    - gfs
    - gfs2
    - glusterfs
    - gpfs
    - pvfs2
    - ocfs2
    - lustre
    - davfs
    - fuse.sshfs
    excluded_paths:
    - dev
    - proc
    - run
    - sys
    search_paths: []
  tags:
  - DISA-STIG-RHEL-08-010700
  - dir_perms_world_writable_root_owned
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure All World-Writable Directories Are Owned by root User - Find Relevant
    Root Directories Ignoring Pre-Defined Excluded Paths
  ansible.builtin.find:
    paths: /
    file_type: directory
    excludes: '{{ excluded_paths }}'
    hidden: true
    recurse: false
  register: result_relevant_root_dirs
  tags:
  - DISA-STIG-RHEL-08-010700
  - dir_perms_world_writable_root_owned
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure All World-Writable Directories Are Owned by root User - Include Relevant
    Root Directories in a List of Paths to be Searched
  ansible.builtin.set_fact:
    search_paths: '{{ search_paths | union([item.path]) }}'
  loop: '{{ result_relevant_root_dirs.files }}'
  tags:
  - DISA-STIG-RHEL-08-010700
  - dir_perms_world_writable_root_owned
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure All World-Writable Directories Are Owned by root User - Increment Search
    Paths List with Local Partitions Mount Points
  ansible.builtin.set_fact:
    search_paths: '{{ search_paths | union([item.mount]) }}'
  loop: '{{ ansible_mounts }}'
  when:
  - item.fstype not in excluded_fstypes
  - item.mount != '/'
  tags:
  - DISA-STIG-RHEL-08-010700
  - dir_perms_world_writable_root_owned
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure All World-Writable Directories Are Owned by root User - Increment Search
    Paths List with Local NFS File System Targets
  ansible.builtin.set_fact:
    search_paths: '{{ search_paths | union([item.device.split('':'')[1]]) }}'
  loop: '{{ ansible_mounts }}'
  when: item.device is search("localhost:")
  tags:
  - DISA-STIG-RHEL-08-010700
  - dir_perms_world_writable_root_owned
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure All World-Writable Directories Are Owned by root User - Define Rule
    Specific Facts
  ansible.builtin.set_fact:
    world_writable_dirs: []
  tags:
  - DISA-STIG-RHEL-08-010700
  - dir_perms_world_writable_root_owned
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure All World-Writable Directories Are Owned by root User - Find All Uncompliant
    Directories in Local File Systems
  ansible.builtin.command:
    cmd: find {{ item }} -xdev -type d -perm -0002 -uid +0
  loop: '{{ search_paths }}'
  changed_when: false
  register: result_found_dirs
  tags:
  - DISA-STIG-RHEL-08-010700
  - dir_perms_world_writable_root_owned
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure All World-Writable Directories Are Owned by root User - Create List
    of World Writable Directories Not Owned by root
  ansible.builtin.set_fact:
    world_writable_dirs: '{{ world_writable_dirs | union(item.stdout_lines) | list
      }}'
  loop: '{{ result_found_dirs.results }}'
  when: item is not skipped
  tags:
  - DISA-STIG-RHEL-08-010700
  - dir_perms_world_writable_root_owned
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure All World-Writable Directories Are Owned by root User - Ensure root
    Ownership on Local World Writable Directories
  ansible.builtin.file:
    path: '{{ item }}'
    owner: root
  loop: '{{ world_writable_dirs }}'
  tags:
  - DISA-STIG-RHEL-08-010700
  - dir_perms_world_writable_root_owned
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dir_perms_world_writable_root_owned:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dir_perms_world_writable_root_owned_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="false" severity="medium">
              <xccdf-1.2:title>Verify that All World-Writable Directories Have Sticky Bits Set</xccdf-1.2:title>
              <xccdf-1.2:description>When the so-called 'sticky bit' is set on a directory, only the owner of a given file may
remove that file from the directory. Without the sticky bit, any user with write access to a
directory may remove any file in the directory. Setting the sticky bit prevents users from
removing each other's files. In cases where there is no reason for a directory to be
world-writable, a better solution is to remove that permission rather than to set the sticky
bit. However, if a directory is used by a particular application, consult that application's
documentation instead of blindly changing modes.
<html:br/>
To set the sticky bit on a world-writable directory <html:i>DIR</html:i>, run the following command:
<html:pre>$ sudo chmod +t <html:i>DIR</html:i></html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule can take a long time to perform the check and might consume a considerable
amount of resources depending on the number of directories present on the system. It is
not a problem in most cases, but especially systems with a large number of directories can
be affected. See <html:code>https://access.redhat.com/articles/6999111</html:code>.</xccdf-1.2:warning>
              <xccdf-1.2:warning category="general">Please note that there might be cases where the rule remediation cannot fix directory permissions.
This can happen for example when running on a system with some immutable parts.
These immutable parts cannot be remediated because they are read-only.
Example of such directories can be OStree deployments located at <html:code>/sysroot/ostree/deploy</html:code>.
In such case, it is needed to make modifications to the underlying ostree snapshot and this is out of scope of regular rule remediation.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000138-GPOS-00069</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R54</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010190</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230243r1137695_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Failing to set the sticky bit on public directories allows unauthorized users to delete files
in the directory structure.
<html:br/><html:br/>
The only authorized public directories are those temporary directories supplied with the
system, or those designed to be temporary file repositories. The setting is normally reserved
for directories used by the system, by users for temporary file storage (such as <html:code>/tmp</html:code>),
and for directories requiring global read/write access.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="dir_perms_world_writable_sticky_bits" system="urn:xccdf:fix:script:sh">df --local -P | awk '{if (NR!=1) print $6}' \
| xargs -I '$6' find '$6' -xdev -type d \
\( -perm -0002 -a ! -perm -1000 \) 2&gt;/dev/null \
-exec chmod a+t {} +
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="dir_perms_world_writable_sticky_bits" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Verify that All World-Writable Directories Have Sticky Bits Set - Define Excluded
    (Non-Local) File Systems and Paths
  ansible.builtin.set_fact:
    excluded_fstypes:
    - afs
    - autofs
    - ceph
    - cifs
    - smb3
    - smbfs
    - sshfs
    - ncpfs
    - ncp
    - nfs
    - nfs4
    - gfs
    - gfs2
    - glusterfs
    - gpfs
    - pvfs2
    - ocfs2
    - lustre
    - davfs
    - fuse.sshfs
    excluded_paths:
    - dev
    - proc
    - run
    - sys
    search_paths: []
  tags:
  - DISA-STIG-RHEL-08-010190
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - dir_perms_world_writable_sticky_bits
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Verify that All World-Writable Directories Have Sticky Bits Set - Find Relevant
    Root Directories Ignoring Pre-Defined Excluded Paths
  ansible.builtin.find:
    paths: /
    file_type: directory
    excludes: '{{ excluded_paths }}'
    hidden: true
    recurse: false
  register: result_relevant_root_dirs
  tags:
  - DISA-STIG-RHEL-08-010190
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - dir_perms_world_writable_sticky_bits
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Verify that All World-Writable Directories Have Sticky Bits Set - Include
    Relevant Root Directories in a List of Paths to be Searched
  ansible.builtin.set_fact:
    search_paths: '{{ search_paths | union([item.path]) }}'
  loop: '{{ result_relevant_root_dirs.files }}'
  tags:
  - DISA-STIG-RHEL-08-010190
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - dir_perms_world_writable_sticky_bits
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Verify that All World-Writable Directories Have Sticky Bits Set - Increment
    Search Paths List with Local Partitions Mount Points
  ansible.builtin.set_fact:
    search_paths: '{{ search_paths | union([item.mount]) }}'
  loop: '{{ ansible_mounts }}'
  when:
  - item.fstype not in excluded_fstypes
  - item.mount != '/'
  tags:
  - DISA-STIG-RHEL-08-010190
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - dir_perms_world_writable_sticky_bits
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Verify that All World-Writable Directories Have Sticky Bits Set - Increment
    Search Paths List with Local NFS File System Targets
  ansible.builtin.set_fact:
    search_paths: '{{ search_paths | union([item.device.split('':'')[1]]) }}'
  loop: '{{ ansible_mounts }}'
  when: item.device is search("localhost:")
  tags:
  - DISA-STIG-RHEL-08-010190
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - dir_perms_world_writable_sticky_bits
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Verify that All World-Writable Directories Have Sticky Bits Set - Define Rule
    Specific Facts
  ansible.builtin.set_fact:
    world_writable_dirs: []
  tags:
  - DISA-STIG-RHEL-08-010190
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - dir_perms_world_writable_sticky_bits
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Verify that All World-Writable Directories Have Sticky Bits Set - Find All
    Uncompliant Directories in Local File Systems
  ansible.builtin.command:
    cmd: find {{ item }} -xdev -type d ( -perm -0002 -a ! -perm -1000 )
  loop: '{{ search_paths }}'
  changed_when: false
  register: result_found_dirs
  tags:
  - DISA-STIG-RHEL-08-010190
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - dir_perms_world_writable_sticky_bits
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Verify that All World-Writable Directories Have Sticky Bits Set - Create List
    of World Writable Directories Without Sticky Bit
  ansible.builtin.set_fact:
    world_writable_dirs: '{{ world_writable_dirs | union(item.stdout_lines) | list
      }}'
  loop: '{{ result_found_dirs.results }}'
  when: result_found_dirs is not skipped and item is not skipped
  tags:
  - DISA-STIG-RHEL-08-010190
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - dir_perms_world_writable_sticky_bits
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Verify that All World-Writable Directories Have Sticky Bits Set - Ensure Sticky
    Bit is Set on Local World Writable Directories
  ansible.builtin.file:
    path: '{{ item }}'
    mode: a+t
  loop: '{{ world_writable_dirs }}'
  tags:
  - DISA-STIG-RHEL-08-010190
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - dir_perms_world_writable_sticky_bits
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dir_perms_world_writable_sticky_bits:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dir_perms_world_writable_sticky_bits_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_system_owned" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure All World-Writable Directories Are Owned by a System Account</xccdf-1.2:title>
              <xccdf-1.2:description>All directories in local partitions which are world-writable should be owned by root or
another system account. If any world-writable directories are not owned by a system account,
this should be investigated. Following this, the files should be deleted or assigned to an
appropriate owner.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule can take a long time to perform the check and might consume a considerable
amount of resources depending on the number of directories present on the system. It is
not a problem in most cases, but especially systems with a large number of directories can
be affected. See <html:code>https://access.redhat.com/articles/6999111</html:code>.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Allowing a user account to own a world-writable directory is undesirable because it allows the
owner of that directory to remove or replace any files that may be placed in the directory by
other users.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dir_perms_world_writable_system_owned:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dir_perms_world_writable_system_owned_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_system_owned_group" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure All World-Writable Directories Are Group Owned by a System Account</xccdf-1.2:title>
              <xccdf-1.2:description>All directories in local partitions which are
world-writable should be group owned by root or another
system account. If any world-writable directories are not
group owned by a system account, this should be investigated.
Following this, the files should be deleted or assigned to an
appropriate group.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010710</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230319r1017130_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Allowing a user account to group own a world-writable directory is
undesirable because it allows the owner of that directory to remove
or replace any files that may be placed in the directory by other
users.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dir_perms_world_writable_system_owned_group:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dir_perms_world_writable_system_owned_group_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dir_system_commands_group_root_owned" selected="false" severity="medium">
              <xccdf-1.2:title>Verify that system commands directories have root as a group owner</xccdf-1.2:title>
              <xccdf-1.2:description>System commands are stored in the following directories:
by default:
<html:pre>/bin 
/sbin 
/usr/bin 
/usr/sbin 
/usr/local/bin 
/usr/local/sbin
</html:pre>
All these directories should have <html:code>root</html:code> user as a group owner. 
If any system command directory is not group owned by a user other than root 
correct its ownership with the following command:
<html:pre>$ sudo chgrp root <html:i>DIR</html:i></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6).1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000259-GPOS-00100</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If the operating system were to allow any user to make changes to 
software libraries, then those changes might be implemented without 
undergoing the appropriate testing and approvals that are part of a 
robust change management process.

This requirement applies to operating systems with software libraries
that are accessible and configurable, as in the case of interpreted languages. 
Software libraries also include privileged programs which execute with escalated 
privileges. Only qualified and authorized individuals must be allowed to obtain 
access to information system components for purposes of initiating changes, 
including upgrades and modifications.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="dir_system_commands_group_root_owned" system="urn:xccdf:fix:script:sh">

for SYSCMDDIRS in /bin /sbin /usr/bin /usr/sbin /usr/local/bin /usr/local/sbin
do
     find -L $SYSCMDDIRS ! -group root -type d -exec chgrp root '{}' \; 
done
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="medium" disruption="medium" id="dir_system_commands_group_root_owned" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Verify that system commands directories have root as a group owner - Set group
    ownership of directories that contain system commands to root
  ansible.builtin.file:
    path: '{{ item }}'
    group: root
    recurse: 'yes'
    state: directory
    follow: 'yes'
  with_items:
  - /bin
  - /sbin
  - /usr/bin
  - /usr/sbin
  - /usr/local/bin
  - /usr/local/sbin
  tags:
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - dir_system_commands_group_root_owned
  - medium_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dir_system_commands_group_root_owned:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dir_system_commands_group_root_owned_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dir_system_commands_root_owned" selected="false" severity="medium">
              <xccdf-1.2:title>Verify that system commands directories have root ownership</xccdf-1.2:title>
              <xccdf-1.2:description>System commands are stored in the following directories by default:
<html:pre>/bin 
/sbin 
/usr/bin 
/usr/sbin 
/usr/local/bin 
/usr/local/sbin
</html:pre>
All these directories should be owned by the <html:code>root</html:code> user. 
If any system command directory is not owned by a user other than root 
correct its ownership with the following command:
<html:pre>$ sudo chown root <html:i>DIR</html:i></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6).1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000259-GPOS-00100</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If the operating system were to allow any user to make changes to 
software libraries, then those changes might be implemented without 
undergoing the appropriate testing and approvals that are part of a 
robust change management process.

This requirement applies to operating systems with software libraries
that are accessible and configurable, as in the case of interpreted languages. 
Software libraries also include privileged programs which execute with escalated 
privileges. Only qualified and authorized individuals must be allowed to obtain 
access to information system components for purposes of initiating changes, 
including upgrades and modifications.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="dir_system_commands_root_owned" system="urn:xccdf:fix:script:sh">
for SYSCMDDIRS in /bin /sbin /usr/bin /usr/sbin /usr/local/bin /usr/local/sbin
do
   find -L $SYSCMDDIRS \! -user root -type d -exec chown root {} \; 
done
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="medium" disruption="medium" id="dir_system_commands_root_owned" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Verify that system commands directories have root ownership - Set ownership
    of directories that contain system commands to root
  ansible.builtin.file:
    path: '{{ item }}'
    owner: root
    recurse: 'yes'
    state: directory
    follow: 'yes'
  with_items:
  - /bin
  - /sbin
  - /usr/bin
  - /usr/sbin
  - /usr/local/bin
  - /usr/local/sbin
  tags:
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - dir_system_commands_root_owned
  - medium_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dir_system_commands_root_owned:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dir_system_commands_root_owned_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_etc_crypttab" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Group Who Owns /etc/crypttab File</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/crypttab</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/crypttab</html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The ownership of the /etc/crypttab file by the root group is important
because this file hosts encrypted block devices configuration. Protection
of this file is critical for system security. Assigning the ownership to
root ensures exclusive control of the encrypted block devices
configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_crypttab" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "root" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="root"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "root is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/crypttab" | grep -E -w -q "root"; then
    chgrp --no-dereference "$newgroup" /etc/crypttab
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_crypttab" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_groupowner_etc_crypttab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Check that the root group is defined
  ansible.builtin.getent:
    database: group
    key: root
  ignore_errors: true
  when:
  - '"kernel" in ansible_facts.packages'
  - file_groupowner_etc_crypttab_newgroup is undefined
  tags:
  - configure_strategy
  - file_groupowner_etc_crypttab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_etc_crypttab_newgroup variable if root found
  ansible.builtin.set_fact:
    file_groupowner_etc_crypttab_newgroup: root
  when:
  - '"kernel" in ansible_facts.packages'
  - ansible_facts.getent_group["root"] is defined
  tags:
  - configure_strategy
  - file_groupowner_etc_crypttab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/crypttab
  ansible.builtin.stat:
    path: /etc/crypttab
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupowner_etc_crypttab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/crypttab
  ansible.builtin.file:
    path: /etc/crypttab
    follow: false
    group: '{{ file_groupowner_etc_crypttab_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupowner_etc_crypttab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_etc_crypttab:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_etc_crypttab_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_etc_sysconfig_sshd" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Group Who Owns /etc/sysconfig/sshd File</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/sysconfig/sshd</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/sysconfig/sshd</html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>/etc/sysconfig/sshd</html:code> file contains configuration options for the SSH daemon.
Protection of this file is important for system security. The file should be owned by the root
group to prevent unauthorized changes.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_sysconfig_sshd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/sysconfig/sshd" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/sysconfig/sshd
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_sysconfig_sshd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_groupowner_etc_sysconfig_sshd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_etc_sysconfig_sshd_newgroup variable if represented
    by gid
  ansible.builtin.set_fact:
    file_groupowner_etc_sysconfig_sshd_newgroup: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupowner_etc_sysconfig_sshd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/sysconfig/sshd
  ansible.builtin.stat:
    path: /etc/sysconfig/sshd
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupowner_etc_sysconfig_sshd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/sysconfig/sshd
  ansible.builtin.file:
    path: /etc/sysconfig/sshd
    follow: false
    group: '{{ file_groupowner_etc_sysconfig_sshd_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupowner_etc_sysconfig_sshd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_etc_sysconfig_sshd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_etc_sysconfig_sshd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_systemmap" selected="false" severity="low">
              <xccdf-1.2:title>Verify Group Who Owns System.map Files</xccdf-1.2:title>
              <xccdf-1.2:description>The System.map files are symbol map files generated during the compilation of the Linux
kernel. They contain the mapping between kernel symbols and their corresponding memory
addresses. These files must be group-owned by root.

To properly set the group owner of <html:code>/boot/System.map*</html:code>, run the command:

  <html:pre>$ sudo chgrp root /boot/System.map*</html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R29</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The purpose of <html:code>System.map</html:code> files is primarily for debugging and profiling the kernel.
Unrestricted access to these files might disclose information useful to attackers and
malicious software leading to more sophisticated exploitation.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_systemmap" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "root" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="root"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "root is not a defined group on the system"
else
find -P /boot/ -maxdepth 1 -type f  ! -group root -regextype posix-extended -regex '^.*System\.map.*$' -exec chgrp --no-dereference "$newgroup" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_systemmap" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_groupowner_systemmap
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed

- name: Check that the root group is defined
  ansible.builtin.getent:
    database: group
    key: root
  ignore_errors: true
  when:
  - '"kernel" in ansible_facts.packages'
  - file_groupowner_systemmap_newgroup is undefined
  tags:
  - configure_strategy
  - file_groupowner_systemmap
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed

- name: Set the file_groupowner_systemmap_newgroup variable if root found
  ansible.builtin.set_fact:
    file_groupowner_systemmap_newgroup: root
  when:
  - '"kernel" in ansible_facts.packages'
  - ansible_facts.getent_group["root"] is defined
  tags:
  - configure_strategy
  - file_groupowner_systemmap
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed

- name: Find /boot/ file(s) matching ^.*System\.map.*$
  ansible.builtin.command: find -P /boot/ -maxdepth 1 -type f  ! -group root -regextype
    posix-extended -regex "^.*System\.map.*$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupowner_systemmap
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed

- name: Ensure group owner on /boot/ file(s) matching ^.*System\.map.*$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    group: '{{ file_groupowner_systemmap_newgroup }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupowner_systemmap
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_systemmap:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_systemmap_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_etc_crypttab" selected="false" severity="medium">
              <xccdf-1.2:title>Verify User Who Owns /etc/crypttab File</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the owner of <html:code>/etc/crypttab</html:code>, run the command:
<html:pre>$ sudo chown root /etc/crypttab </html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The ownership of the /etc/crypttab file by the root user is important
because this file hosts encrypted block devices configuration. Protection
of this file is critical for system security. Assigning the ownership to
root ensures exclusive control of the encrypted block devices
configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_crypttab" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/crypttab" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/crypttab
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_crypttab" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_owner_etc_crypttab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_etc_crypttab_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_etc_crypttab_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_etc_crypttab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/crypttab
  ansible.builtin.stat:
    path: /etc/crypttab
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_etc_crypttab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/crypttab
  ansible.builtin.file:
    path: /etc/crypttab
    follow: false
    owner: '{{ file_owner_etc_crypttab_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_owner_etc_crypttab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_etc_crypttab:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_etc_crypttab_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_etc_sysconfig_sshd" selected="false" severity="medium">
              <xccdf-1.2:title>Verify User Who Owns /etc/sysconfig/sshd File</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the owner of <html:code>/etc/sysconfig/sshd</html:code>, run the command:
<html:pre>$ sudo chown root /etc/sysconfig/sshd </html:pre>
</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>/etc/sysconfig/sshd</html:code> file contains configuration options for the SSH daemon.
Protection of this file is important for system security. The file should be owned by root
to prevent unauthorized changes.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_sysconfig_sshd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/sysconfig/sshd" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/sysconfig/sshd
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_sysconfig_sshd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_owner_etc_sysconfig_sshd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_etc_sysconfig_sshd_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_etc_sysconfig_sshd_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_etc_sysconfig_sshd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/sysconfig/sshd
  ansible.builtin.stat:
    path: /etc/sysconfig/sshd
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_etc_sysconfig_sshd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/sysconfig/sshd
  ansible.builtin.file:
    path: /etc/sysconfig/sshd
    follow: false
    owner: '{{ file_owner_etc_sysconfig_sshd_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_owner_etc_sysconfig_sshd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_etc_sysconfig_sshd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_etc_sysconfig_sshd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_systemmap" selected="false" severity="low">
              <xccdf-1.2:title>Verify User Who Owns System.map Files</xccdf-1.2:title>
              <xccdf-1.2:description>The System.map files are symbol map files generated during the compilation of the Linux
kernel. They contain the mapping between kernel symbols and their corresponding memory
addresses. These files must be owned by root.

To properly set the owner of <html:code>/boot/System.map*</html:code>, run the command:

  <html:pre>$ sudo chown root /boot/System.map* </html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R29</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The purpose of <html:code>System.map</html:code> files is primarily for debugging and profiling the kernel.
Unrestricted access to these files might disclose information useful to attackers and
malicious software leading to more sophisticated exploitation.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_systemmap" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else

find -P /boot/ -maxdepth 1 -type f  ! -user 0 -regextype posix-extended -regex '^.*System\.map.*$' -exec chown --no-dereference "$newown" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_systemmap" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_owner_systemmap
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed

- name: Set the file_owner_systemmap_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_systemmap_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_systemmap
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed

- name: Find /boot/ file(s) matching ^.*System\.map.*$
  ansible.builtin.command: find -P /boot/ -maxdepth 1 -type f  ! -user 0 -regextype
    posix-extended -regex "^.*System\.map.*$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_systemmap
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed

- name: Ensure owner on /boot/ file(s) matching ^.*System\.map.*$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    owner: '{{ file_owner_systemmap_newown }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_systemmap
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_systemmap:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_systemmap_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_crypttab" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Permissions On /etc/crypttab File</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/crypttab</html:code>, run the command: <html:pre>$ sudo chmod 0600 /etc/crypttab</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Setting correct permissions on the /etc/crypttab file is important
because this file hosts encrypted block devices configuration. Protection
of this file is critical for system security. Assigning the ownership to
root ensures exclusive control of the encrypted block devices
configuration.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_crypttab" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

chmod u-xs,g-xwrs,o-xwrt /etc/crypttab

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_crypttab" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_permissions_etc_crypttab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/crypttab
  ansible.builtin.stat:
    path: /etc/crypttab
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_permissions_etc_crypttab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xwrs,o-xwrt on /etc/crypttab
  ansible.builtin.file:
    path: /etc/crypttab
    mode: u-xs,g-xwrs,o-xwrt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_etc_crypttab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_crypttab:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_crypttab_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_sysconfig_sshd" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Permissions on /etc/sysconfig/sshd File</xccdf-1.2:title>
              <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/sysconfig/sshd</html:code>, run the command:
<html:pre>$ sudo chmod 0640 /etc/sysconfig/sshd</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>/etc/sysconfig/sshd</html:code> file contains configuration options for the SSH daemon.
Protection of this file is important for system security. The file should have mode 0640
or more restrictive to prevent unauthorized access and modifications.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_sysconfig_sshd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

chmod u-xs,g-xws,o-xwrt /etc/sysconfig/sshd

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_sysconfig_sshd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_permissions_etc_sysconfig_sshd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/sysconfig/sshd
  ansible.builtin.stat:
    path: /etc/sysconfig/sshd
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_permissions_etc_sysconfig_sshd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xws,o-xwrt on /etc/sysconfig/sshd
  ansible.builtin.file:
    path: /etc/sysconfig/sshd
    mode: u-xs,g-xws,o-xwrt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_etc_sysconfig_sshd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_sysconfig_sshd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_sysconfig_sshd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_systemmap" selected="false" severity="low">
              <xccdf-1.2:title>Verify Permissions on System.map Files</xccdf-1.2:title>
              <xccdf-1.2:description>The System.map files are symbol map files generated during the compilation of the Linux
kernel. They contain the mapping between kernel symbols and their corresponding memory
addresses. In general, there is no need for non-root users to read these files.

To properly set the permissions of <html:code>/boot/System.map*</html:code>, run the command:
<html:pre>$ sudo chmod 0600 /boot/System.map*</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R29</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The purpose of <html:code>System.map</html:code> files is primarily for debugging and profiling the kernel.
Unrestricted access to these files might disclose information useful to attackers and
malicious software leading to more sophisticated exploitation.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_systemmap" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

find -P /boot/ -maxdepth 1 -perm /u+xs,g+xwrs,o+xwrt  -type f -regextype posix-extended -regex '^.*System\.map.*$' -exec chmod u-xs,g-xwrs,o-xwrt {} \;

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_systemmap" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_permissions_systemmap
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed

- name: Find /boot/ file(s)
  ansible.builtin.command: find -P /boot/ -maxdepth 1 -perm /u+xs,g+xwrs,o+xwrt  -type
    f -regextype posix-extended -regex "^.*System\.map.*$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_permissions_systemmap
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed

- name: Set permissions for /boot/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-xs,g-xwrs,o-xwrt
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_permissions_systemmap
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_systemmap:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_systemmap_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_sgid" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure All SGID Executables Are Authorized</xccdf-1.2:title>
              <xccdf-1.2:description>The SGID (set group id) bit should be set only on files that were installed via authorized
means. A straightforward means of identifying unauthorized SGID files is determine if any were
not installed as part of an RPM package, which is cryptographically verified. Investigate the
origin of any unpackaged SGID files. This configuration check considers authorized SGID files
those which were installed via RPM. It is assumed that when an individual has sudo access to
install an RPM and all packages are signed with an organizationally-recognized GPG key, the
software should be considered an approved package on the system. Any SGID file not deployed
through an RPM will be flagged for further review.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule can take a long time to perform the check and might consume a considerable
amount of resources depending on the number of files present on the system. It is not a
problem in most cases, but especially systems with a large number of files can be affected.
See <html:code>https://access.redhat.com/articles/6999111</html:code>.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R56</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Executable files with the SGID permission run with the privileges of the owner of the file.
SGID files of uncertain provenance could allow for unprivileged users to elevate privileges.
The presence of these files should be strictly controlled on the system.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_unauthorized_sgid:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_unauthorized_sgid_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_suid" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure All SUID Executables Are Authorized</xccdf-1.2:title>
              <xccdf-1.2:description>The SUID (set user id) bit should be set only on files that were installed via authorized
means. A straightforward means of identifying unauthorized SUID files is determine if any were
not installed as part of an RPM package, which is cryptographically verified. Investigate the
origin of any unpackaged SUID files. This configuration check considers authorized SUID files
those which were installed via RPM. It is assumed that when an individual has sudo access to
install an RPM and all packages are signed with an organizationally-recognized GPG key, the
software should be considered an approved package on the system. Any SUID file not deployed
through an RPM will be flagged for further review.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule can take a long time to perform the check and might consume a considerable
amount of resources depending on the number of files present on the system. It is not a
problem in most cases, but especially systems with a large number of files can be affected.
See <html:code>https://access.redhat.com/articles/6999111</html:code>.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R56</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Executable files with the SUID permission run with the privileges of the owner of the file.
SUID files of uncertain provenance could allow for unprivileged users to elevate privileges.
The presence of these files should be strictly controlled on the system.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_unauthorized_suid:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_unauthorized_suid_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_world_writable" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure No World-Writable Files Exist</xccdf-1.2:title>
              <xccdf-1.2:description>It is generally a good idea to remove global (other) write access to a file when it is
discovered. However, check with documentation for specific applications before making changes.
Also, monitor for recurring world-writable files, as these may be symptoms of a misconfigured
application or user account. Finally, this applies to real files and not virtual files that
are a part of pseudo file systems such as <html:code>sysfs</html:code> or <html:code>procfs</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule can take a long time to perform the check and might consume a considerable
amount of resources depending on the number of files present on the system. It is not a
problem in most cases, but especially systems with a large number of files can be affected.
See <html:code>https://access.redhat.com/articles/6999111</html:code>.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R54</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.11</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Data in world-writable files can be modified by any user on the system. In almost all
circumstances, files can be configured using a combination of user and group permissions to
support whatever legitimate access is needed without the risk caused by world-writable files.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_unauthorized_world_writable" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
FILTER_NODEV=$(awk '/nodev/ { print $2 }' /proc/filesystems | paste -sd,)

# Do not consider /sysroot partition because it contains only the physical
# read-only root on bootable containers.
PARTITIONS=$(findmnt -n -l -k -it $FILTER_NODEV | awk '{ print $1 }' | grep -v "/sysroot")

for PARTITION in $PARTITIONS; do
  find "${PARTITION}" -xdev -type f -perm -002 -exec chmod o-w {} \; 2&gt;/dev/null
done

# Ensure /tmp is also fixed when tmpfs is used.
if grep "^tmpfs /tmp" /proc/mounts; then
  find /tmp -xdev -type f -perm -002 -exec chmod o-w {} \; 2&gt;/dev/null
fi
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_unauthorized_world_writable:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_unauthorized_world_writable_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_ungroupowned" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure All Files Are Owned by a Group</xccdf-1.2:title>
              <xccdf-1.2:description>If any file is not group-owned by a valid defined group, the cause of the lack of
group-ownership must be investigated. Following this, those files should be deleted or
assigned to an appropriate group. The groups need to be defined in <html:code>/etc/group</html:code>
or in <html:code>/usr/lib/group</html:code> if <html:code>nss-altfiles</html:code> are configured to be used
in <html:code>/etc/nsswitch.conf</html:code>.

Locate the mount points related to local devices by the following command:
<html:pre>$ findmnt -n -l -k -it $(awk '/nodev/ { print $2 }' /proc/filesystems | paste -sd,)</html:pre>

For all mount points listed by the previous command, it is necessary to search for files which
do not belong to a valid group using the following command:
<html:pre>$ sudo find <html:i>MOUNTPOINT</html:i> -xdev -nogroup 2&gt;/dev/null</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule only considers local groups as valid groups.
If you have your groups defined outside <html:code>/etc/group</html:code> or <html:code>/usr/lib/group</html:code>, the rule won't consider those.</xccdf-1.2:warning>
              <xccdf-1.2:warning category="general">This rule can take a long time to perform the check and might consume a considerable
amount of resources depending on the number of files present on the system. It is not a
problem in most cases, but especially systems with a large number of files can be affected.
See <html:code>https://access.redhat.com/articles/6999111</html:code>.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R53</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010790</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230327r1069285_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unowned files do not directly imply a security problem, but they are generally a sign that
something is amiss. They may be caused by an intruder, by incorrect software installation or
draft software removal, or by failure to remove all files belonging to a deleted account, or
other similar cases. The files should be repaired so they will not cause problems when
accounts are created in the future, and the cause should be discovered and addressed.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_ungroupowned:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_ungroupowned_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_files_or_dirs_ungroupowned" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure All Files And Directories Are Owned by a Group</xccdf-1.2:title>
              <xccdf-1.2:description>If any files or directories are not group-owned by a valid defined group, the cause of the lack of
group-ownership must be investigated. Following this, those files should be deleted or
assigned to an appropriate group. The groups need to be defined in <html:code>/etc/group</html:code>
or in <html:code>/usr/lib/group</html:code> if <html:code>nss-altfiles</html:code> are configured to be used
in <html:code>/etc/nsswitch.conf</html:code>.

Locate the mount points related to local devices by the following command:
<html:pre>$ findmnt -n -l -k -it $(awk '/nodev/ { print $2 }' /proc/filesystems | paste -sd,)</html:pre>

For all mount points listed by the previous command, it is necessary to search for files and directories which
do not belong to a valid group using the following command:
<html:pre>$ sudo find <html:i>MOUNTPOINT</html:i> -xdev -nogroup 2&gt;/dev/null</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule only considers local groups as valid groups.
If you have your groups defined outside <html:code>/etc/group</html:code> or <html:code>/usr/lib/group</html:code>, the rule won't consider those.</xccdf-1.2:warning>
              <xccdf-1.2:warning category="general">This rule can take a long time to perform the check and might consume a considerable
amount of resources depending on the number of files present on the system. It is not a
problem in most cases, but especially systems with a large number of files can be affected.
See <html:code>https://access.redhat.com/articles/6999111</html:code>.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.12</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unowned files and directories do not directly imply a security problem, but they are generally a sign that
something is amiss. They may be caused by an intruder, by incorrect software installation or
draft software removal, or by failure to remove all files belonging to a deleted account, or
other similar cases. The files and directories should be repaired so they will not cause problems when
accounts are created in the future, and the cause should be discovered and addressed.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_files_or_dirs_ungroupowned:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_files_or_dirs_ungroupowned_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_files_or_dirs_unowned_by_user" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure All Files And Directories Are Owned by a User</xccdf-1.2:title>
              <xccdf-1.2:description>If any files or directories are not owned by a user, then the cause of their lack of ownership should be
investigated. Following this, the files should be deleted or assigned to an appropriate user.

Locate the mount points related to local devices by the following command:
<html:pre>$ findmnt -n -l -k -it $(awk '/nodev/ { print $2 }' /proc/filesystems | paste -sd,)</html:pre>

For all mount points listed by the previous command, it is necessary to search for files and directories which
do not belong to a valid user using the following command:
<html:pre>$ sudo find <html:i>MOUNTPOINT</html:i> -xdev -nouser 2&gt;/dev/null</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="functionality">For this rule to evaluate centralized user accounts, <html:code>getent</html:code> must be working properly
so that running the command <html:pre>getent passwd</html:pre> returns a list of all users in your organization.
If using the System Security Services Daemon (SSSD), <html:pre>enumerate = true</html:pre> must be configured
in your organization's domain to return a complete list of users</xccdf-1.2:warning>
              <xccdf-1.2:warning category="general">This rule can take a long time to perform the check and might consume a considerable
amount of resources depending on the number of files present on the system. It is not a
problem in most cases, but especially systems with a large number of files can be affected.
See <html:code>https://access.redhat.com/articles/6999111</html:code>.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.12</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unowned files and directories do not directly imply a security problem, but they are generally a sign that
something is amiss. They may be caused by an intruder, by incorrect software installation or
draft software removal, or by failure to remove all files belonging to a deleted account, or
other similar cases. The files and directories should be repaired so they will not cause problems when
accounts are created in the future, and the cause should be discovered and addressed.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_files_or_dirs_unowned_by_user:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_files_or_dirs_unowned_by_user_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_files_unowned_by_user" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure All Files Are Owned by a User</xccdf-1.2:title>
              <xccdf-1.2:description>If any files are not owned by a user, then the cause of their lack of ownership should be
investigated. Following this, the files should be deleted or assigned to an appropriate user.

Locate the mount points related to local devices by the following command:
<html:pre>$ findmnt -n -l -k -it $(awk '/nodev/ { print $2 }' /proc/filesystems | paste -sd,)</html:pre>

For all mount points listed by the previous command, it is necessary to search for files which
do not belong to a valid user using the following command:
<html:pre>$ sudo find <html:i>MOUNTPOINT</html:i> -xdev -nouser 2&gt;/dev/null</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="functionality">For this rule to evaluate centralized user accounts, <html:code>getent</html:code> must be working properly
so that running the command <html:pre>getent passwd</html:pre> returns a list of all users in your organization.
If using the System Security Services Daemon (SSSD), <html:pre>enumerate = true</html:pre> must be configured
in your organization's domain to return a complete list of users</xccdf-1.2:warning>
              <xccdf-1.2:warning category="general">This rule can take a long time to perform the check and might consume a considerable
amount of resources depending on the number of files present on the system. It is not a
problem in most cases, but especially systems with a large number of files can be affected.
See <html:code>https://access.redhat.com/articles/6999111</html:code>.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R53</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010780</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230326r1069284_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unowned files do not directly imply a security problem, but they are generally a sign that
something is amiss. They may be caused by an intruder, by incorrect software installation or
draft software removal, or by failure to remove all files belonging to a deleted account, or
other similar cases. The files should be repaired so they will not cause problems when
accounts are created in the future, and the cause should be discovered and addressed.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_files_unowned_by_user:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_files_unowned_by_user_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_hardlinks" selected="false" severity="medium">
              <xccdf-1.2:title>Enable Kernel Parameter to Enforce DAC on Hardlinks</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>fs.protected_hardlinks</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w fs.protected_hardlinks=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>fs.protected_hardlinks = 1</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000312-GPOS-00122</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000312-GPOS-00123</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000324-GPOS-00125</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010374</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230268r1017086_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>By enabling this kernel parameter, users can no longer create soft or hard links to
files which they do not own. Disallowing such hardlinks mitigate vulnerabilities
based on insecure file system accessed by privileged programs, avoiding an
exploitation vector exploiting unsafe use of <html:code>open()</html:code> or <html:code>creat()</html:code>.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_fs_protected_hardlinks" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of fs.protected_hardlinks from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*fs.protected_hardlinks.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "fs.protected_hardlinks" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/fs_protected_hardlinks.conf'


#
# Set runtime for fs.protected_hardlinks
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w fs.protected_hardlinks="1"
fi

#
# If fs.protected_hardlinks present in /etc/sysctl.conf, change value to "1"
#	else, add "fs.protected_hardlinks = 1" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^fs.protected_hardlinks")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "1"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^fs.protected_hardlinks\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^fs.protected_hardlinks\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_fs_protected_hardlinks" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010374
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_protected_hardlinks

- name: Enable Kernel Parameter to Enforce DAC on Hardlinks - Set fact for sysctl
    paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010374
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_protected_hardlinks

- name: Enable Kernel Parameter to Enforce DAC on Hardlinks - Find all files that
    contain fs.protected_hardlinks
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*fs.protected_hardlinks\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010374
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_protected_hardlinks

- name: Enable Kernel Parameter to Enforce DAC on Hardlinks - Find all files that
    set fs.protected_hardlinks to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*fs.protected_hardlinks\s*=\s*1$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010374
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_protected_hardlinks

- name: Enable Kernel Parameter to Enforce DAC on Hardlinks - Comment out any occurrences
    of fs.protected_hardlinks from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*fs.protected_hardlinks
    replace: '#fs.protected_hardlinks'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-010374
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_protected_hardlinks

- name: Enable Kernel Parameter to Enforce DAC on Hardlinks - Comment out any occurrences
    of fs.protected_hardlinks from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*fs.protected_hardlinks
    replace: '#fs.protected_hardlinks'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010374
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_protected_hardlinks

- name: Enable Kernel Parameter to Enforce DAC on Hardlinks - Ensure sysctl fs.protected_hardlinks
    is set to 1
  ansible.posix.sysctl:
    name: fs.protected_hardlinks
    value: '1'
    sysctl_file: /etc/sysctl.d/fs_protected_hardlinks.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010374
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_protected_hardlinks
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="sysctl_fs_protected_hardlinks" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,fs.protected_hardlinks%3D1%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_fs_protected_hardlinks.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_fs_protected_hardlinks:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_symlinks" selected="false" severity="medium">
              <xccdf-1.2:title>Enable Kernel Parameter to Enforce DAC on Symlinks</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>fs.protected_symlinks</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w fs.protected_symlinks=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>fs.protected_symlinks = 1</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000312-GPOS-00122</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000312-GPOS-00123</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000324-GPOS-00125</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010373</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230267r1017085_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>By enabling this kernel parameter, symbolic links are permitted to be followed
only when outside a sticky world-writable directory, or when the UID of the
link and follower match, or when the directory owner matches the symlink's owner.
Disallowing such symlinks helps mitigate vulnerabilities based on insecure file system
accessed by privileged programs, avoiding an exploitation vector exploiting unsafe use of
<html:code>open()</html:code> or <html:code>creat()</html:code>.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_fs_protected_symlinks" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of fs.protected_symlinks from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*fs.protected_symlinks.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "fs.protected_symlinks" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/fs_protected_symlinks.conf'


#
# Set runtime for fs.protected_symlinks
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w fs.protected_symlinks="1"
fi

#
# If fs.protected_symlinks present in /etc/sysctl.conf, change value to "1"
#	else, add "fs.protected_symlinks = 1" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^fs.protected_symlinks")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "1"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^fs.protected_symlinks\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^fs.protected_symlinks\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_fs_protected_symlinks" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010373
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_protected_symlinks

- name: Enable Kernel Parameter to Enforce DAC on Symlinks - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010373
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_protected_symlinks

- name: Enable Kernel Parameter to Enforce DAC on Symlinks - Find all files that contain
    fs.protected_symlinks
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*fs.protected_symlinks\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010373
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_protected_symlinks

- name: Enable Kernel Parameter to Enforce DAC on Symlinks - Find all files that set
    fs.protected_symlinks to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*fs.protected_symlinks\s*=\s*1$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010373
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_protected_symlinks

- name: Enable Kernel Parameter to Enforce DAC on Symlinks - Comment out any occurrences
    of fs.protected_symlinks from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*fs.protected_symlinks
    replace: '#fs.protected_symlinks'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-010373
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_protected_symlinks

- name: Enable Kernel Parameter to Enforce DAC on Symlinks - Comment out any occurrences
    of fs.protected_symlinks from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*fs.protected_symlinks
    replace: '#fs.protected_symlinks'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010373
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_protected_symlinks

- name: Enable Kernel Parameter to Enforce DAC on Symlinks - Ensure sysctl fs.protected_symlinks
    is set to 1
  ansible.posix.sysctl:
    name: fs.protected_symlinks
    value: '1'
    sysctl_file: /etc/sysctl.d/fs_protected_symlinks.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010373
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_protected_symlinks
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="sysctl_fs_protected_symlinks" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,fs.protected_symlinks%3D1%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_fs_protected_symlinks.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_fs_protected_symlinks:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_fs_protected_symlinks_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_permissions_important_account_files">
              <xccdf-1.2:title>Verify Permissions on Files with Local Account Information and Credentials</xccdf-1.2:title>
              <xccdf-1.2:description>The default restrictive permissions for files which act as
important security databases such as <html:code>passwd</html:code>, <html:code>shadow</html:code>,
<html:code>group</html:code>, and <html:code>gshadow</html:code> files must be maintained.  Many utilities
need read access to the <html:code>passwd</html:code> file in order to function properly, but
read access to the <html:code>shadow</html:code> file allows malicious attacks against system
passwords, and should never be enabled.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_etc_security_opasswd" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Permissions and Ownership of Old Passwords File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the owner of <html:code>/etc/security/opasswd</html:code>, run the command:
<html:pre>$ sudo chown root /etc/security/opasswd </html:pre>

To properly set the group owner of <html:code>/etc/security/opasswd</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/security/opasswd</html:pre>

To properly set the permissions of <html:code>/etc/security/opasswd</html:code>, run the command: <html:pre>$ sudo chmod 0600 /etc/security/opasswd</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000077-GPOS-00045</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/security/opasswd</html:code> file stores old passwords to prevent
password reuse. Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:fix id="file_etc_security_opasswd" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q pam; then

# Create /etc/security/opasswd if needed
# Owner group mode root.root 0600
[ -f  /etc/security/opasswd ] || touch /etc/security/opasswd
chown root:root /etc/security/opasswd
chmod 0600 /etc/security/opasswd

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_etc_security_opasswd" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - file_etc_security_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Verify Permissions and Ownership of Old Passwords File
  ansible.builtin.file:
    path: /etc/security/opasswd
    owner: root
    group: root
    mode: 384
    state: touch
    modification_time: preserve
    access_time: preserve
  when: '"pam" in ansible_facts.packages'
  tags:
  - file_etc_security_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_etc_security_opasswd:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_etc_security_opasswd_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_group" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Group Who Owns Backup group File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/group-</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/group-</html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6 (1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.4</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/group-</html:code> file is a backup file of <html:code>/etc/group</html:code>, and as such,
it contains information regarding groups that are configured on the system.
Protection of this file is important for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_backup_etc_group" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/group-" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/group-
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_backup_etc_group" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_groupowner_backup_etc_group_newgroup variable if represented
    by gid
  ansible.builtin.set_fact:
    file_groupowner_backup_etc_group_newgroup: '0'
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_backup_etc_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/group-
  ansible.builtin.stat:
    path: /etc/group-
  register: file_exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_backup_etc_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/group-
  ansible.builtin.file:
    path: /etc/group-
    follow: false
    group: '{{ file_groupowner_backup_etc_group_newgroup }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_backup_etc_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_backup_etc_group:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_gshadow" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Group Who Owns Backup gshadow File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/gshadow-</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/gshadow-</html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6 (1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.8</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/gshadow-</html:code> file is a backup of <html:code>/etc/gshadow</html:code>, and as such,
it contains group password hashes. Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_backup_etc_gshadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/gshadow-" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/gshadow-
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_backup_etc_gshadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_groupowner_backup_etc_gshadow_newgroup variable if represented
    by gid
  ansible.builtin.set_fact:
    file_groupowner_backup_etc_gshadow_newgroup: '0'
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7
  - configure_strategy
  - file_groupowner_backup_etc_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/gshadow-
  ansible.builtin.stat:
    path: /etc/gshadow-
  register: file_exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7
  - configure_strategy
  - file_groupowner_backup_etc_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/gshadow-
  ansible.builtin.file:
    path: /etc/gshadow-
    follow: false
    group: '{{ file_groupowner_backup_etc_gshadow_newgroup }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7
  - configure_strategy
  - file_groupowner_backup_etc_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_backup_etc_gshadow:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_backup_etc_gshadow_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_passwd" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Group Who Owns Backup passwd File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/passwd-</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/passwd-</html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6 (1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/passwd-</html:code> file is a backup file of <html:code>/etc/passwd</html:code>, and as such,
it contains information about the users that are configured on the system.
Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_backup_etc_passwd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/passwd-" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/passwd-
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_backup_etc_passwd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_groupowner_backup_etc_passwd_newgroup variable if represented
    by gid
  ansible.builtin.set_fact:
    file_groupowner_backup_etc_passwd_newgroup: '0'
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_backup_etc_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/passwd-
  ansible.builtin.stat:
    path: /etc/passwd-
  register: file_exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_backup_etc_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/passwd-
  ansible.builtin.file:
    path: /etc/passwd-
    follow: false
    group: '{{ file_groupowner_backup_etc_passwd_newgroup }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_backup_etc_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_backup_etc_passwd:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_backup_etc_passwd_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_backup_etc_shadow" selected="false" severity="medium">
                <xccdf-1.2:title>Verify User Who Owns Backup shadow File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/shadow-</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/shadow-</html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.6</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/shadow-</html:code> file is a backup file of <html:code>/etc/shadow</html:code>, and as such,
it contains the list of local system accounts and password hashes.
Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_backup_etc_shadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/shadow-" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/shadow-
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_backup_etc_shadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_groupowner_backup_etc_shadow_newgroup variable if represented
    by gid
  ansible.builtin.set_fact:
    file_groupowner_backup_etc_shadow_newgroup: '0'
  tags:
  - PCI-DSS-Req-8.7
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_backup_etc_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/shadow-
  ansible.builtin.stat:
    path: /etc/shadow-
  register: file_exists
  tags:
  - PCI-DSS-Req-8.7
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_backup_etc_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/shadow-
  ansible.builtin.file:
    path: /etc/shadow-
    follow: false
    group: '{{ file_groupowner_backup_etc_shadow_newgroup }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - PCI-DSS-Req-8.7
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_backup_etc_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_backup_etc_shadow:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_backup_etc_shadow_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_etc_group" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Group Who Owns group File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/group</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/group</html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7.c</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/group</html:code> file contains information regarding groups that are configured
on the system. Protection of this file is important for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_group" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/group" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/group
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_group" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_groupowner_etc_group_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_etc_group_newgroup: '0'
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_etc_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/group
  ansible.builtin.stat:
    path: /etc/group
  register: file_exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_etc_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/group
  ansible.builtin.file:
    path: /etc/group
    follow: false
    group: '{{ file_groupowner_etc_group_newgroup }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_etc_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_etc_group:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_etc_group_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_etc_gshadow" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Group Who Owns gshadow File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/gshadow</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/gshadow</html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.7</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/gshadow</html:code> file contains group password hashes. Protection of this file
is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_gshadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/gshadow" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/gshadow
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_gshadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_groupowner_etc_gshadow_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_etc_gshadow_newgroup: '0'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_groupowner_etc_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/gshadow
  ansible.builtin.stat:
    path: /etc/gshadow
  register: file_exists
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_groupowner_etc_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/gshadow
  ansible.builtin.file:
    path: /etc/gshadow
    follow: false
    group: '{{ file_groupowner_etc_gshadow_newgroup }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_groupowner_etc_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_etc_gshadow:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_etc_gshadow_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_etc_passwd" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Group Who Owns passwd File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/passwd</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/passwd</html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7.c</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/passwd</html:code> file contains information about the users that are configured on
the system. Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_passwd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/passwd" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/passwd
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_passwd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_groupowner_etc_passwd_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_etc_passwd_newgroup: '0'
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_etc_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/passwd
  ansible.builtin.stat:
    path: /etc/passwd
  register: file_exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_etc_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/passwd
  ansible.builtin.file:
    path: /etc/passwd
    follow: false
    group: '{{ file_groupowner_etc_passwd_newgroup }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_etc_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_etc_passwd:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_etc_security_opasswd" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Group Who Owns /etc/security/opasswd File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/security/opasswd</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/security/opasswd</html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.10</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/security/opasswd</html:code> file stores old passwords to prevent
password reuse. Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_security_opasswd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/security/opasswd" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/security/opasswd
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_security_opasswd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_groupowner_etc_security_opasswd_newgroup variable if represented
    by gid
  ansible.builtin.set_fact:
    file_groupowner_etc_security_opasswd_newgroup: '0'
  tags:
  - configure_strategy
  - file_groupowner_etc_security_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/security/opasswd
  ansible.builtin.stat:
    path: /etc/security/opasswd
  register: file_exists
  tags:
  - configure_strategy
  - file_groupowner_etc_security_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/security/opasswd
  ansible.builtin.file:
    path: /etc/security/opasswd
    follow: false
    group: '{{ file_groupowner_etc_security_opasswd_newgroup }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupowner_etc_security_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_etc_security_opasswd:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_etc_security_opasswd_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_etc_security_opasswd_old" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Group Who Owns /etc/security/opasswd.old File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/security/opasswd.old</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/security/opasswd.old</html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.10</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/security/opasswd.old</html:code> file stores backups of old passwords to prevent
password reuse. Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_security_opasswd_old" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/security/opasswd.old" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/security/opasswd.old
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_security_opasswd_old" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_groupowner_etc_security_opasswd_old_newgroup variable if represented
    by gid
  ansible.builtin.set_fact:
    file_groupowner_etc_security_opasswd_old_newgroup: '0'
  tags:
  - configure_strategy
  - file_groupowner_etc_security_opasswd_old
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/security/opasswd.old
  ansible.builtin.stat:
    path: /etc/security/opasswd.old
  register: file_exists
  tags:
  - configure_strategy
  - file_groupowner_etc_security_opasswd_old
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/security/opasswd.old
  ansible.builtin.file:
    path: /etc/security/opasswd.old
    follow: false
    group: '{{ file_groupowner_etc_security_opasswd_old_newgroup }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupowner_etc_security_opasswd_old
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_etc_security_opasswd_old:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_etc_security_opasswd_old_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shadow" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Group Who Owns shadow File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/shadow</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/shadow</html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7.c</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.5</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/shadow</html:code> file stores password hashes. Protection of this file is
critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_shadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/shadow" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/shadow
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_shadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_groupowner_etc_shadow_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_etc_shadow_newgroup: '0'
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_etc_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/shadow
  ansible.builtin.stat:
    path: /etc/shadow
  register: file_exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_etc_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/shadow
  ansible.builtin.file:
    path: /etc/shadow
    follow: false
    group: '{{ file_groupowner_etc_shadow_newgroup }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_etc_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_etc_shadow:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_etc_shadow_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shells" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Group Who Owns /etc/shells File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/shells</html:code>, run the command:

  <html:pre>$ sudo chgrp root /etc/shells</html:pre>
  </xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.9</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/shells</html:code> file contains the list of full pathnames to shells on the system.
Since this file is used by many system programs this file should be protected.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_shells" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/shells" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/shells
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_shells" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_groupowner_etc_shells_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_etc_shells_newgroup: '0'
  tags:
  - NIST-800-53-AC-3
  - NIST-800-53-MP-2
  - configure_strategy
  - file_groupowner_etc_shells
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/shells
  ansible.builtin.stat:
    path: /etc/shells
  register: file_exists
  tags:
  - NIST-800-53-AC-3
  - NIST-800-53-MP-2
  - configure_strategy
  - file_groupowner_etc_shells
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/shells
  ansible.builtin.file:
    path: /etc/shells
    follow: false
    group: '{{ file_groupowner_etc_shells_newgroup }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-3
  - NIST-800-53-MP-2
  - configure_strategy
  - file_groupowner_etc_shells
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_etc_shells:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_etc_shells_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_group" selected="false" severity="medium">
                <xccdf-1.2:title>Verify User Who Owns Backup group File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the owner of <html:code>/etc/group-</html:code>, run the command:
<html:pre>$ sudo chown root /etc/group- </html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6 (1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7.c</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.4</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/group-</html:code> file is a backup file of <html:code>/etc/group</html:code>, and as such,
it contains information regarding groups that are configured on the system.
Protection of this file is important for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_backup_etc_group" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/group-" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/group-
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_backup_etc_group" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_owner_backup_etc_group_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_backup_etc_group_newown: '0'
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_backup_etc_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/group-
  ansible.builtin.stat:
    path: /etc/group-
  register: file_exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_backup_etc_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/group-
  ansible.builtin.file:
    path: /etc/group-
    follow: false
    owner: '{{ file_owner_backup_etc_group_newown }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_backup_etc_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_backup_etc_group:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_backup_etc_group_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_gshadow" selected="false" severity="medium">
                <xccdf-1.2:title>Verify User Who Owns Backup gshadow File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the owner of <html:code>/etc/gshadow-</html:code>, run the command:
<html:pre>$ sudo chown root /etc/gshadow- </html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6 (1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.8</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/gshadow-</html:code> file is a backup of <html:code>/etc/gshadow</html:code>, and as such,
it contains group password hashes. Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_backup_etc_gshadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/gshadow-" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/gshadow-
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_backup_etc_gshadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_owner_backup_etc_gshadow_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_backup_etc_gshadow_newown: '0'
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7
  - configure_strategy
  - file_owner_backup_etc_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/gshadow-
  ansible.builtin.stat:
    path: /etc/gshadow-
  register: file_exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7
  - configure_strategy
  - file_owner_backup_etc_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/gshadow-
  ansible.builtin.file:
    path: /etc/gshadow-
    follow: false
    owner: '{{ file_owner_backup_etc_gshadow_newown }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7
  - configure_strategy
  - file_owner_backup_etc_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_backup_etc_gshadow:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_backup_etc_gshadow_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_passwd" selected="false" severity="medium">
                <xccdf-1.2:title>Verify User Who Owns Backup passwd File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the owner of <html:code>/etc/passwd-</html:code>, run the command:
<html:pre>$ sudo chown root /etc/passwd- </html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6 (1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7.c</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/passwd-</html:code> file is a backup file of <html:code>/etc/passwd</html:code>, and as such,
it contains information about the users that are configured on the system.
Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_backup_etc_passwd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/passwd-" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/passwd-
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_backup_etc_passwd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_owner_backup_etc_passwd_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_backup_etc_passwd_newown: '0'
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_backup_etc_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/passwd-
  ansible.builtin.stat:
    path: /etc/passwd-
  register: file_exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_backup_etc_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/passwd-
  ansible.builtin.file:
    path: /etc/passwd-
    follow: false
    owner: '{{ file_owner_backup_etc_passwd_newown }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_backup_etc_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_backup_etc_passwd:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_backup_etc_shadow" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Group Who Owns Backup shadow File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the owner of <html:code>/etc/shadow-</html:code>, run the command:
<html:pre>$ sudo chown root /etc/shadow- </html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6 (1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7.c</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.6</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/shadow-</html:code> file is a backup file of <html:code>/etc/shadow</html:code>, and as such,
it contains the list of local system accounts and password hashes.
Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_backup_etc_shadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/shadow-" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/shadow-
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_backup_etc_shadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_owner_backup_etc_shadow_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_backup_etc_shadow_newown: '0'
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_backup_etc_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/shadow-
  ansible.builtin.stat:
    path: /etc/shadow-
  register: file_exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_backup_etc_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/shadow-
  ansible.builtin.file:
    path: /etc/shadow-
    follow: false
    owner: '{{ file_owner_backup_etc_shadow_newown }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_backup_etc_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_backup_etc_shadow:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_etc_group" selected="false" severity="medium">
                <xccdf-1.2:title>Verify User Who Owns group File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the owner of <html:code>/etc/group</html:code>, run the command:
<html:pre>$ sudo chown root /etc/group </html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7.c</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/group</html:code> file contains information regarding groups that are configured
on the system. Protection of this file is important for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_group" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/group" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/group
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_group" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_owner_etc_group_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_etc_group_newown: '0'
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_etc_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/group
  ansible.builtin.stat:
    path: /etc/group
  register: file_exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_etc_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/group
  ansible.builtin.file:
    path: /etc/group
    follow: false
    owner: '{{ file_owner_etc_group_newown }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_etc_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_etc_group:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_etc_gshadow" selected="false" severity="medium">
                <xccdf-1.2:title>Verify User Who Owns gshadow File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the owner of <html:code>/etc/gshadow</html:code>, run the command:
<html:pre>$ sudo chown root /etc/gshadow </html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.7</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/gshadow</html:code> file contains group password hashes. Protection of this file
is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_gshadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/gshadow" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/gshadow
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_gshadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_owner_etc_gshadow_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_etc_gshadow_newown: '0'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_owner_etc_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/gshadow
  ansible.builtin.stat:
    path: /etc/gshadow
  register: file_exists
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_owner_etc_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/gshadow
  ansible.builtin.file:
    path: /etc/gshadow
    follow: false
    owner: '{{ file_owner_etc_gshadow_newown }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_owner_etc_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_etc_gshadow:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_etc_gshadow_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_etc_passwd" selected="false" severity="medium">
                <xccdf-1.2:title>Verify User Who Owns passwd File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the owner of <html:code>/etc/passwd</html:code>, run the command:
<html:pre>$ sudo chown root /etc/passwd </html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7.c</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/passwd</html:code> file contains information about the users that are configured on
the system. Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_passwd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/passwd" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/passwd
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_passwd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_owner_etc_passwd_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_etc_passwd_newown: '0'
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_etc_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/passwd
  ansible.builtin.stat:
    path: /etc/passwd
  register: file_exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_etc_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/passwd
  ansible.builtin.file:
    path: /etc/passwd
    follow: false
    owner: '{{ file_owner_etc_passwd_newown }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_etc_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_etc_passwd:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_etc_security_opasswd" selected="false" severity="medium">
                <xccdf-1.2:title>Verify User Who Owns /etc/security/opasswd File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the owner of <html:code>/etc/security/opasswd</html:code>, run the command:
<html:pre>$ sudo chown root /etc/security/opasswd </html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.10</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/security/opasswd</html:code> file stores old passwords to prevent
password reuse. Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_security_opasswd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/security/opasswd" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/security/opasswd
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_security_opasswd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_owner_etc_security_opasswd_newown variable if represented by
    uid
  ansible.builtin.set_fact:
    file_owner_etc_security_opasswd_newown: '0'
  tags:
  - configure_strategy
  - file_owner_etc_security_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/security/opasswd
  ansible.builtin.stat:
    path: /etc/security/opasswd
  register: file_exists
  tags:
  - configure_strategy
  - file_owner_etc_security_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/security/opasswd
  ansible.builtin.file:
    path: /etc/security/opasswd
    follow: false
    owner: '{{ file_owner_etc_security_opasswd_newown }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_owner_etc_security_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_etc_security_opasswd:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_etc_security_opasswd_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_etc_security_opasswd_old" selected="false" severity="medium">
                <xccdf-1.2:title>Verify User Who Owns /etc/security/opasswd.old File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the owner of <html:code>/etc/security/opasswd.old</html:code>, run the command:
<html:pre>$ sudo chown root /etc/security/opasswd.old </html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.10</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/security/opasswd.old</html:code> file stores backups of old passwords to prevent
password reuse. Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_security_opasswd_old" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/security/opasswd.old" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/security/opasswd.old
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_security_opasswd_old" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_owner_etc_security_opasswd_old_newown variable if represented
    by uid
  ansible.builtin.set_fact:
    file_owner_etc_security_opasswd_old_newown: '0'
  tags:
  - configure_strategy
  - file_owner_etc_security_opasswd_old
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/security/opasswd.old
  ansible.builtin.stat:
    path: /etc/security/opasswd.old
  register: file_exists
  tags:
  - configure_strategy
  - file_owner_etc_security_opasswd_old
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/security/opasswd.old
  ansible.builtin.file:
    path: /etc/security/opasswd.old
    follow: false
    owner: '{{ file_owner_etc_security_opasswd_old_newown }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_owner_etc_security_opasswd_old
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_etc_security_opasswd_old:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_etc_security_opasswd_old_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_etc_shadow" selected="false" severity="medium">
                <xccdf-1.2:title>Verify User Who Owns shadow File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the owner of <html:code>/etc/shadow</html:code>, run the command:
<html:pre>$ sudo chown root /etc/shadow </html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7.c</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.5</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/shadow</html:code> file contains the list of local
system accounts and stores password hashes. Protection of this file is
critical for system security. Failure to give ownership of this file
to root provides the designated owner with access to sensitive information
which could weaken the system security posture.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_shadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/shadow" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/shadow
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_shadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_owner_etc_shadow_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_etc_shadow_newown: '0'
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_etc_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/shadow
  ansible.builtin.stat:
    path: /etc/shadow
  register: file_exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_etc_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/shadow
  ansible.builtin.file:
    path: /etc/shadow
    follow: false
    owner: '{{ file_owner_etc_shadow_newown }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_etc_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_etc_shadow:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_etc_shadow_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_etc_shells" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Who Owns /etc/shells File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the owner of <html:code>/etc/shells</html:code>, run the command:

  <html:pre>$ sudo chown root /etc/shells </html:pre>
  </xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.9</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/shells</html:code> file contains the list of full pathnames to shells on the system.
Since this file is used by many system programs this file should be protected.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_shells" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/shells" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/shells
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_shells" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_owner_etc_shells_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_etc_shells_newown: '0'
  tags:
  - NIST-800-53-AC-3
  - NIST-800-53-MP-2
  - configure_strategy
  - file_owner_etc_shells
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/shells
  ansible.builtin.stat:
    path: /etc/shells
  register: file_exists
  tags:
  - NIST-800-53-AC-3
  - NIST-800-53-MP-2
  - configure_strategy
  - file_owner_etc_shells
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/shells
  ansible.builtin.file:
    path: /etc/shells
    follow: false
    owner: '{{ file_owner_etc_shells_newown }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-3
  - NIST-800-53-MP-2
  - configure_strategy
  - file_owner_etc_shells
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_etc_shells:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_etc_shells_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_group" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Permissions on Backup group File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/group-</html:code>, run the command:
<html:pre>$ sudo chmod 0644 /etc/group-</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6 (1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7.c</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.4</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/group-</html:code> file is a backup file of <html:code>/etc/group</html:code>, and as such,
it contains information regarding groups that are configured on the system.
Protection of this file is important for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_backup_etc_group" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



chmod u-xs,g-xws,o-xwt /etc/group-
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_backup_etc_group" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Test for existence /etc/group-
  ansible.builtin.stat:
    path: /etc/group-
  register: file_exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_backup_etc_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xws,o-xwt on /etc/group-
  ansible.builtin.file:
    path: /etc/group-
    mode: u-xs,g-xws,o-xwt
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_backup_etc_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_backup_etc_group:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_gshadow" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Permissions on Backup gshadow File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/gshadow-</html:code>, run the command:
<html:pre>$ sudo chmod 0000 /etc/gshadow-</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6 (1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.8</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/gshadow-</html:code> file is a backup of <html:code>/etc/gshadow</html:code>, and as such,
it contains group password hashes. Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_backup_etc_gshadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



chmod u-xwrs,g-xwrs,o-xwrt /etc/gshadow-
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_backup_etc_gshadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Test for existence /etc/gshadow-
  ansible.builtin.stat:
    path: /etc/gshadow-
  register: file_exists
  tags:
  - NIST-800-53-AC-6 (1)
  - configure_strategy
  - file_permissions_backup_etc_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xwrs,g-xwrs,o-xwrt on /etc/gshadow-
  ansible.builtin.file:
    path: /etc/gshadow-
    mode: u-xwrs,g-xwrs,o-xwrt
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6 (1)
  - configure_strategy
  - file_permissions_backup_etc_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_backup_etc_gshadow:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_passwd" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Permissions on Backup passwd File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/passwd-</html:code>, run the command:
<html:pre>$ sudo chmod 0644 /etc/passwd-</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6 (1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7.c</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/passwd-</html:code> file is a backup file of <html:code>/etc/passwd</html:code>, and as such,
it contains information about the users that are configured on the system.
Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_backup_etc_passwd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



chmod u-xs,g-xws,o-xwt /etc/passwd-
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_backup_etc_passwd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Test for existence /etc/passwd-
  ansible.builtin.stat:
    path: /etc/passwd-
  register: file_exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_backup_etc_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xws,o-xwt on /etc/passwd-
  ansible.builtin.file:
    path: /etc/passwd-
    mode: u-xs,g-xws,o-xwt
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_backup_etc_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_backup_etc_passwd:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_backup_etc_shadow" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Permissions on Backup shadow File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/shadow-</html:code>, run the command:
<html:pre>$ sudo chmod 0000 /etc/shadow-</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6 (1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7.c</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.6</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/shadow-</html:code> file is a backup file of <html:code>/etc/shadow</html:code>, and as such,
it contains the list of local system accounts and password hashes.
Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_backup_etc_shadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



chmod u-xwrs,g-xwrs,o-xwrt /etc/shadow-
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_backup_etc_shadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Test for existence /etc/shadow-
  ansible.builtin.stat:
    path: /etc/shadow-
  register: file_exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_backup_etc_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xwrs,g-xwrs,o-xwrt on /etc/shadow-
  ansible.builtin.file:
    path: /etc/shadow-
    mode: u-xwrs,g-xwrs,o-xwrt
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6 (1)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_backup_etc_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_backup_etc_shadow:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_group" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Permissions on group File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/group</html:code>, run the command:
<html:pre>$ sudo chmod 0644 /etc/group</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7.c</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/group</html:code> file contains information regarding groups that are configured
on the system. Protection of this file is important for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_group" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



chmod u-xs,g-xws,o-xwt /etc/group
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_group" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Test for existence /etc/group
  ansible.builtin.stat:
    path: /etc/group
  register: file_exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_etc_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xws,o-xwt on /etc/group
  ansible.builtin.file:
    path: /etc/group
    mode: u-xs,g-xws,o-xwt
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_etc_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_group:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_group_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_gshadow" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Permissions on gshadow File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/gshadow</html:code>, run the command:
<html:pre>$ sudo chmod 0000 /etc/gshadow</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.7</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/gshadow</html:code> file contains group password hashes. Protection of this file
is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_gshadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



chmod u-xwrs,g-xwrs,o-xwrt /etc/gshadow
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_gshadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Test for existence /etc/gshadow
  ansible.builtin.stat:
    path: /etc/gshadow
  register: file_exists
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_etc_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xwrs,g-xwrs,o-xwrt on /etc/gshadow
  ansible.builtin.file:
    path: /etc/gshadow
    mode: u-xwrs,g-xwrs,o-xwrt
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_etc_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_gshadow:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_gshadow_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_passwd" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Permissions on passwd File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/passwd</html:code>, run the command:
<html:pre>$ sudo chmod 0644 /etc/passwd</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7.c</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If the <html:code>/etc/passwd</html:code> file is writable by a group-owner or the
world the risk of its compromise is increased. The file contains the list of
accounts on the system and associated information, and protection of this file
is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_passwd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



chmod u-xs,g-xws,o-xwt /etc/passwd
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_passwd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Test for existence /etc/passwd
  ansible.builtin.stat:
    path: /etc/passwd
  register: file_exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_etc_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xws,o-xwt on /etc/passwd
  ansible.builtin.file:
    path: /etc/passwd
    mode: u-xs,g-xws,o-xwt
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_etc_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_passwd:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_security_opasswd" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Permissions on /etc/security/opasswd File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/security/opasswd</html:code>, run the command:
<html:pre>$ sudo chmod 0600 /etc/security/opasswd</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.10</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/security/opasswd</html:code> file stores old passwords to prevent
password reuse. Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_security_opasswd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



chmod u-xs,g-xwrs,o-xwrt /etc/security/opasswd
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_security_opasswd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Test for existence /etc/security/opasswd
  ansible.builtin.stat:
    path: /etc/security/opasswd
  register: file_exists
  tags:
  - configure_strategy
  - file_permissions_etc_security_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xwrs,o-xwrt on /etc/security/opasswd
  ansible.builtin.file:
    path: /etc/security/opasswd
    mode: u-xs,g-xwrs,o-xwrt
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_etc_security_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_security_opasswd:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_security_opasswd_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_security_opasswd_old" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Permissions on /etc/security/opasswd.old File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/security/opasswd.old</html:code>, run the command:
<html:pre>$ sudo chmod 0600 /etc/security/opasswd.old</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.10</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/security/opasswd.old</html:code> file stores backups of old passwords to prevent
password reuse. Protection of this file is critical for system security.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_security_opasswd_old" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



chmod u-xs,g-xwrs,o-xwrt /etc/security/opasswd.old
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_security_opasswd_old" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Test for existence /etc/security/opasswd.old
  ansible.builtin.stat:
    path: /etc/security/opasswd.old
  register: file_exists
  tags:
  - configure_strategy
  - file_permissions_etc_security_opasswd_old
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xwrs,o-xwrt on /etc/security/opasswd.old
  ansible.builtin.file:
    path: /etc/security/opasswd.old
    mode: u-xs,g-xwrs,o-xwrt
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_etc_security_opasswd_old
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_security_opasswd_old:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_security_opasswd_old_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_shadow" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Permissions on shadow File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/shadow</html:code>, run the command:
<html:pre>$ sudo chmod 0000 /etc/shadow</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.7.c</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.5</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/shadow</html:code> file contains the list of local
system accounts and stores password hashes. Protection of this file is
critical for system security. Failure to give ownership of this file
to root provides the designated owner with access to sensitive information
which could weaken the system security posture.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_shadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



chmod u-xwrs,g-xwrs,o-xwrt /etc/shadow
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_shadow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Test for existence /etc/shadow
  ansible.builtin.stat:
    path: /etc/shadow
  register: file_exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_etc_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xwrs,g-xwrs,o-xwrt on /etc/shadow
  ansible.builtin.file:
    path: /etc/shadow
    mode: u-xwrs,g-xwrs,o-xwrt
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - CJIS-5.5.2.2
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-8.7.c
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_etc_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_shadow:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_shadow_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_shells" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Permissions on /etc/shells File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/shells</html:code>, run the command:
<html:pre>$ sudo chmod 0644 /etc/shells</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">7.1.9</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/etc/shells</html:code> file contains the list of full pathnames to shells on the system.
Since this file is used by many system programs this file should be protected.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_shells" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



chmod u-xs,g-xws,o-xwt /etc/shells
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_shells" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Test for existence /etc/shells
  ansible.builtin.stat:
    path: /etc/shells
  register: file_exists
  tags:
  - NIST-800-53-AC-3
  - NIST-800-53-MP-2
  - configure_strategy
  - file_permissions_etc_shells
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xws,o-xwt on /etc/shells
  ansible.builtin.file:
    path: /etc/shells
    mode: u-xs,g-xws,o-xwt
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-3
  - NIST-800-53-MP-2
  - configure_strategy
  - file_permissions_etc_shells
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_shells:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_shells_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_permissions_var_log_dir">
              <xccdf-1.2:title>Verify Permissions on Files within /var/log Directory</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>/var/log</html:code> directory contains files with logs of error
messages in the system and should only be accessed by authorized
personnel.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_var_log" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Group Who Owns /var/log Directory</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the group owner of <html:code>/var/log</html:code>, run the command:
<html:pre>$ sudo chgrp root /var/log</html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000206-GPOS-00084</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000118-CTR-000240</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010260</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230250r1017068_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/var/log</html:code> directory contains files with logs of error
messages in the system and should only be accessed by authorized
personnel.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_var_log" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
find -P /var/log/ -maxdepth 0 -type d  ! -group 0 -exec chgrp --no-dereference "$newgroup" {} \;

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_var_log" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_groupowner_var_log_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_var_log_newgroup: '0'
  tags:
  - DISA-STIG-RHEL-08-010260
  - configure_strategy
  - file_groupowner_var_log
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /var/log/
  ansible.builtin.file:
    path: /var/log/
    follow: false
    state: directory
    group: '{{ file_groupowner_var_log_newgroup }}'
  tags:
  - DISA-STIG-RHEL-08-010260
  - configure_strategy
  - file_groupowner_var_log
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_var_log:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_var_log_messages" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Group Who Owns /var/log/messages File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the group owner of <html:code>/var/log/messages</html:code>, run the command:
<html:pre>$ sudo chgrp root /var/log/messages</html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000206-GPOS-00084</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010230</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230247r1017065_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/var/log/messages</html:code> file contains logs of error messages in
the system and should only be accessed by authorized personnel.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_var_log_messages" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/var/log/messages" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /var/log/messages
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_var_log_messages" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_groupowner_var_log_messages_newgroup variable if represented
    by gid
  ansible.builtin.set_fact:
    file_groupowner_var_log_messages_newgroup: '0'
  tags:
  - DISA-STIG-RHEL-08-010230
  - configure_strategy
  - file_groupowner_var_log_messages
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /var/log/messages
  ansible.builtin.stat:
    path: /var/log/messages
  register: file_exists
  tags:
  - DISA-STIG-RHEL-08-010230
  - configure_strategy
  - file_groupowner_var_log_messages
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /var/log/messages
  ansible.builtin.file:
    path: /var/log/messages
    follow: false
    group: '{{ file_groupowner_var_log_messages_newgroup }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-010230
  - configure_strategy
  - file_groupowner_var_log_messages
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_var_log_messages:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_var_log_messages_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_var_log_syslog" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Group Who Owns /var/log/syslog File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the group owner of <html:code>/var/log/syslog</html:code>, run the command:
<html:pre>$ sudo chgrp adm /var/log/syslog</html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000206-GPOS-00084</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/var/log/syslog</html:code> file contains logs of error messages in
the system and should only be accessed by authorized personnel.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_rsyslog"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_var_log_syslog" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q rsyslog; then

newgroup=""
if getent group "4" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="4"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "4 is not a defined group on the system"
else
if ! stat -c "%g %G" "/var/log/syslog" | grep -E -w -q "4"; then
    chgrp --no-dereference "$newgroup" /var/log/syslog
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_var_log_syslog" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_groupowner_var_log_syslog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_var_log_syslog_newgroup variable if represented by
    gid
  ansible.builtin.set_fact:
    file_groupowner_var_log_syslog_newgroup: '4'
  when: '"rsyslog" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupowner_var_log_syslog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /var/log/syslog
  ansible.builtin.stat:
    path: /var/log/syslog
  register: file_exists
  when: '"rsyslog" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupowner_var_log_syslog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /var/log/syslog
  ansible.builtin.file:
    path: /var/log/syslog
    follow: false
    group: '{{ file_groupowner_var_log_syslog_newgroup }}'
  when:
  - '"rsyslog" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupowner_var_log_syslog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_var_log_syslog:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_var_log_syslog_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_var_log" selected="false" severity="medium">
                <xccdf-1.2:title>Verify User Who Owns /var/log Directory</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the owner of <html:code>/var/log</html:code>, run the command:
<html:pre>$ sudo chown root /var/log </html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000206-GPOS-00084</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000118-CTR-000240</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010250</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230249r1017067_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/var/log</html:code> directory contains files with logs of error
messages in the system and should only be accessed by authorized
personnel.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_var_log" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
find -P /var/log/ -maxdepth 0 -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_var_log" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_owner_var_log_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_var_log_newown: '0'
  tags:
  - DISA-STIG-RHEL-08-010250
  - configure_strategy
  - file_owner_var_log
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /var/log/
  ansible.builtin.file:
    path: /var/log/
    follow: false
    state: directory
    owner: '{{ file_owner_var_log_newown }}'
  tags:
  - DISA-STIG-RHEL-08-010250
  - configure_strategy
  - file_owner_var_log
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_var_log:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_var_log_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_var_log_messages" selected="false" severity="medium">
                <xccdf-1.2:title>Verify User Who Owns /var/log/messages File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the owner of <html:code>/var/log/messages</html:code>, run the command:
<html:pre>$ sudo chown root /var/log/messages </html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000206-GPOS-00084</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010220</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230246r1017064_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/var/log/messages</html:code> file contains logs of error messages in
the system and should only be accessed by authorized personnel.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_var_log_messages" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/var/log/messages" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /var/log/messages
fi

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_var_log_messages" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_owner_var_log_messages_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_var_log_messages_newown: '0'
  tags:
  - DISA-STIG-RHEL-08-010220
  - configure_strategy
  - file_owner_var_log_messages
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /var/log/messages
  ansible.builtin.stat:
    path: /var/log/messages
  register: file_exists
  tags:
  - DISA-STIG-RHEL-08-010220
  - configure_strategy
  - file_owner_var_log_messages
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /var/log/messages
  ansible.builtin.file:
    path: /var/log/messages
    follow: false
    owner: '{{ file_owner_var_log_messages_newown }}'
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-010220
  - configure_strategy
  - file_owner_var_log_messages
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_var_log_messages:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_var_log_syslog" selected="false" severity="medium">
                <xccdf-1.2:title>Verify User Who Owns /var/log/syslog File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the owner of <html:code>/var/log/syslog</html:code>, run the command:
<html:pre>$ sudo chown syslog /var/log/syslog </html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000206-GPOS-00084</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/var/log/syslog</html:code> file contains logs of error messages in
the system and should only be accessed by authorized personnel.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_rsyslog"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_var_log_syslog" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q rsyslog; then

newown=""
if id "syslog" &gt;/dev/null 2&gt;&amp;1; then
  newown="syslog"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "syslog is not a defined user on the system"
else
if ! stat -c "%u %U" "/var/log/syslog" | grep -E -w -q "syslog"; then
    chown --no-dereference "$newown" /var/log/syslog
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_var_log_syslog" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_owner_var_log_syslog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Check that the syslog user is defined
  ansible.builtin.getent:
    database: passwd
    key: syslog
  ignore_errors: true
  when: '"rsyslog" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_var_log_syslog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_var_log_syslog_newown variable if syslog found
  ansible.builtin.set_fact:
    file_owner_var_log_syslog_newown: syslog
  when:
  - '"rsyslog" in ansible_facts.packages'
  - ansible_facts.getent_passwd["syslog"] is defined
  tags:
  - configure_strategy
  - file_owner_var_log_syslog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /var/log/syslog
  ansible.builtin.stat:
    path: /var/log/syslog
  register: file_exists
  when: '"rsyslog" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_var_log_syslog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /var/log/syslog
  ansible.builtin.file:
    path: /var/log/syslog
    follow: false
    owner: '{{ file_owner_var_log_syslog_newown }}'
  when:
  - '"rsyslog" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_owner_var_log_syslog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_var_log_syslog:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_var_log" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Permissions on /var/log Directory</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the permissions of <html:code>/var/log</html:code>, run the command:
<html:pre>$ sudo chmod 0755 /var/log</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000206-GPOS-00084</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000118-CTR-000240</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010240</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230248r1069291_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/var/log</html:code> directory contains files with logs of error
messages in the system and should only be accessed by authorized
personnel.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_var_log" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



find -H /var/log/ -maxdepth 0 -perm /u+s,g+ws,o+wt -type d -exec chmod u-s,g-ws,o-wt {} \;
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_var_log" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Find /var/log/ file(s)
  ansible.builtin.command: 'find -P /var/log/ -maxdepth 0 -perm /u+s,g+ws,o+wt  -type
    d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010240
  - configure_strategy
  - file_permissions_var_log
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /var/log/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-ws,o-wt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010240
  - configure_strategy
  - file_permissions_var_log
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_var_log:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_var_log_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_var_log_messages" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Permissions on /var/log/messages File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the permissions of <html:code>/var/log/messages</html:code>, run the command:
<html:pre>$ sudo chmod 0600 /var/log/messages</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000206-GPOS-00084</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010210</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230245r1017063_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/var/log/messages</html:code> file contains logs of error messages in
the system and should only be accessed by authorized personnel.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_var_log_messages" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



chmod u-xs,g-xwrs,o-xwrt /var/log/messages
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_var_log_messages" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Test for existence /var/log/messages
  ansible.builtin.stat:
    path: /var/log/messages
  register: file_exists
  tags:
  - DISA-STIG-RHEL-08-010210
  - configure_strategy
  - file_permissions_var_log_messages
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xwrs,o-xwrt on /var/log/messages
  ansible.builtin.file:
    path: /var/log/messages
    mode: u-xs,g-xwrs,o-xwrt
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-010210
  - configure_strategy
  - file_permissions_var_log_messages
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_var_log_messages:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_var_log_messages_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_var_log_syslog" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Permissions on /var/log/syslog File</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the permissions of <html:code>/var/log/syslog</html:code>, run the command:
<html:pre>$ sudo chmod 0640 /var/log/syslog</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000206-GPOS-00084</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The <html:code>/var/log/syslog</html:code> file contains logs of error messages in
the system and should only be accessed by authorized personnel.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_var_log_syslog" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



chmod u-xs,g-xws,o-xwrt /var/log/syslog
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_var_log_syslog" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Test for existence /var/log/syslog
  ansible.builtin.stat:
    path: /var/log/syslog
  register: file_exists
  tags:
  - configure_strategy
  - file_permissions_var_log_syslog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xws,o-xwrt on /var/log/syslog
  ansible.builtin.file:
    path: /var/log/syslog
    mode: u-xs,g-xws,o-xwrt
  when: file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_var_log_syslog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_var_log_syslog:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_var_log_syslog_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_permissions_within_important_dirs">
              <xccdf-1.2:title>Verify File Permissions Within Some Important Directories</xccdf-1.2:title>
              <xccdf-1.2:description>Some directories contain files whose confidentiality or integrity
is notably important and may also be susceptible to misconfiguration over time, particularly if
unpackaged software is installed. As such,
an argument exists to verify that files' permissions within these directories remain
configured correctly and restrictively.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dir_group_ownership_library_dirs" selected="false" severity="medium">
                <xccdf-1.2:title>Verify that Shared Library Directories Have Root Group Ownership</xccdf-1.2:title>
                <xccdf-1.2:description>System-wide shared library files, which are linked to executables
during process load time or run time, are stored in the following directories
by default:
<html:pre>/lib
/lib64
/usr/lib
/usr/lib64
</html:pre>

Kernel modules, which can be added to the kernel during runtime, are also
stored in <html:code>/lib/modules</html:code>.

All files in these directories should be group-owned by the <html:code>root</html:code> group.

If the directories are found to be owned by a group other than root correct
its ownership with the following command:
<html:pre>$ sudo chgrp root <html:i>DIR</html:i></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6).1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000259-GPOS-00100</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010351</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-251709r1017364_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Files from shared library directories are loaded into the address
space of processes (including privileged ones) or of the kernel itself at
runtime. Proper ownership of library directories is necessary to protect
the integrity of the system.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="dir_group_ownership_library_dirs" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
find -P /lib/  -type d  ! -group 0 -exec chgrp --no-dereference "$newgroup" {} \;
find -P /lib64/  -type d  ! -group 0 -exec chgrp --no-dereference "$newgroup" {} \;
find -P /usr/lib/  -type d  ! -group 0 -exec chgrp --no-dereference "$newgroup" {} \;
find -P /usr/lib64/  -type d  ! -group 0 -exec chgrp --no-dereference "$newgroup" {} \;

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="dir_group_ownership_library_dirs" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the dir_group_ownership_library_dirs_newgroup variable if represented
    by gid
  ansible.builtin.set_fact:
    dir_group_ownership_library_dirs_newgroup: '0'
  tags:
  - DISA-STIG-RHEL-08-010351
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_group_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /lib/ recursively
  ansible.builtin.file:
    path: /lib/
    follow: false
    state: directory
    recurse: true
    group: '{{ dir_group_ownership_library_dirs_newgroup }}'
  tags:
  - DISA-STIG-RHEL-08-010351
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_group_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /lib64/ recursively
  ansible.builtin.file:
    path: /lib64/
    follow: false
    state: directory
    recurse: true
    group: '{{ dir_group_ownership_library_dirs_newgroup }}'
  tags:
  - DISA-STIG-RHEL-08-010351
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_group_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /usr/lib/ recursively
  ansible.builtin.file:
    path: /usr/lib/
    follow: false
    state: directory
    recurse: true
    group: '{{ dir_group_ownership_library_dirs_newgroup }}'
  tags:
  - DISA-STIG-RHEL-08-010351
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_group_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /usr/lib64/ recursively
  ansible.builtin.file:
    path: /usr/lib64/
    follow: false
    state: directory
    recurse: true
    group: '{{ dir_group_ownership_library_dirs_newgroup }}'
  tags:
  - DISA-STIG-RHEL-08-010351
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_group_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dir_group_ownership_library_dirs:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dir_group_ownership_library_dirs_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dir_ownership_binary_dirs" selected="false" severity="medium">
                <xccdf-1.2:title>Verify that System Executable Have Root Ownership</xccdf-1.2:title>
                <xccdf-1.2:description><html:pre>/bin
/sbin
/usr/bin
/usr/sbin
/usr/local/bin
/usr/local/sbin</html:pre>
All these directories should be owned by the <html:code>root</html:code> user.
If any directory <html:i>DIR</html:i> in these directories is found
to be owned by a user other than root, correct its ownership with the
following command:
<html:pre>$ sudo chown root <html:i>DIR</html:i></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000258-GPOS-00099</xccdf-1.2:reference>
                <xccdf-1.2:rationale>System binaries are executed by privileged users as well as system services,
and restrictive permissions are necessary to ensure that their
execution of these programs cannot be co-opted.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="dir_ownership_binary_dirs" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
find -P /bin/  -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;
find -P /sbin/  -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;
find -P /usr/bin/  -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;
find -P /usr/sbin/  -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;
find -P /usr/local/bin/  -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;
find -P /usr/local/sbin/  -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="dir_ownership_binary_dirs" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the dir_ownership_binary_dirs_newown variable if represented by uid
  ansible.builtin.set_fact:
    dir_ownership_binary_dirs_newown: '0'
  tags:
  - configure_strategy
  - dir_ownership_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /bin/ recursively
  ansible.builtin.file:
    path: /bin/
    follow: false
    state: directory
    recurse: true
    owner: '{{ dir_ownership_binary_dirs_newown }}'
  tags:
  - configure_strategy
  - dir_ownership_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /sbin/ recursively
  ansible.builtin.file:
    path: /sbin/
    follow: false
    state: directory
    recurse: true
    owner: '{{ dir_ownership_binary_dirs_newown }}'
  tags:
  - configure_strategy
  - dir_ownership_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /usr/bin/ recursively
  ansible.builtin.file:
    path: /usr/bin/
    follow: false
    state: directory
    recurse: true
    owner: '{{ dir_ownership_binary_dirs_newown }}'
  tags:
  - configure_strategy
  - dir_ownership_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /usr/sbin/ recursively
  ansible.builtin.file:
    path: /usr/sbin/
    follow: false
    state: directory
    recurse: true
    owner: '{{ dir_ownership_binary_dirs_newown }}'
  tags:
  - configure_strategy
  - dir_ownership_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /usr/local/bin/ recursively
  ansible.builtin.file:
    path: /usr/local/bin/
    follow: false
    state: directory
    recurse: true
    owner: '{{ dir_ownership_binary_dirs_newown }}'
  tags:
  - configure_strategy
  - dir_ownership_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /usr/local/sbin/ recursively
  ansible.builtin.file:
    path: /usr/local/sbin/
    follow: false
    state: directory
    recurse: true
    owner: '{{ dir_ownership_binary_dirs_newown }}'
  tags:
  - configure_strategy
  - dir_ownership_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dir_ownership_binary_dirs:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dir_ownership_library_dirs" selected="false" severity="medium">
                <xccdf-1.2:title>Verify that Shared Library Directories Have Root Ownership</xccdf-1.2:title>
                <xccdf-1.2:description>System-wide shared library files, which are linked to executables
during process load time or run time, are stored in the following directories
by default:
<html:pre>/lib
/lib64
/usr/lib
/usr/lib64
</html:pre>

Kernel modules, which can be added to the kernel during runtime, are also
stored in <html:code>/lib/modules</html:code>.

All files in these directories should be owned by the <html:code>root</html:code> user.

If the directories are found to be owned by a user other than root correct
its ownership with the following command:
<html:pre>$ sudo chown root <html:i>DIR</html:i></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6).1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000259-GPOS-00100</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010341</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-251708r1017362_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Files from shared library directories are loaded into the address
space of processes (including privileged ones) or of the kernel itself at
runtime. Proper ownership of library directories is necessary to protect
the integrity of the system.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="dir_ownership_library_dirs" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
find -P /lib/  -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;
find -P /lib64/  -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;
find -P /usr/lib/  -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;
find -P /usr/lib64/  -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="dir_ownership_library_dirs" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the dir_ownership_library_dirs_newown variable if represented by uid
  ansible.builtin.set_fact:
    dir_ownership_library_dirs_newown: '0'
  tags:
  - DISA-STIG-RHEL-08-010341
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /lib/ recursively
  ansible.builtin.file:
    path: /lib/
    follow: false
    state: directory
    recurse: true
    owner: '{{ dir_ownership_library_dirs_newown }}'
  tags:
  - DISA-STIG-RHEL-08-010341
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /lib64/ recursively
  ansible.builtin.file:
    path: /lib64/
    follow: false
    state: directory
    recurse: true
    owner: '{{ dir_ownership_library_dirs_newown }}'
  tags:
  - DISA-STIG-RHEL-08-010341
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /usr/lib/ recursively
  ansible.builtin.file:
    path: /usr/lib/
    follow: false
    state: directory
    recurse: true
    owner: '{{ dir_ownership_library_dirs_newown }}'
  tags:
  - DISA-STIG-RHEL-08-010341
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /usr/lib64/ recursively
  ansible.builtin.file:
    path: /usr/lib64/
    follow: false
    state: directory
    recurse: true
    owner: '{{ dir_ownership_library_dirs_newown }}'
  tags:
  - DISA-STIG-RHEL-08-010341
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dir_ownership_library_dirs:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dir_ownership_library_dirs_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dir_permissions_binary_dirs" selected="false" severity="medium">
                <xccdf-1.2:title>Verify that System Executable Directories Have Restrictive Permissions</xccdf-1.2:title>
                <xccdf-1.2:description>System executables are stored in the following directories by default:
<html:pre>/bin
/sbin
/usr/bin
/usr/sbin
/usr/local/bin
/usr/local/sbin</html:pre>
These directories should not be group-writable or world-writable.
If any directory <html:i>DIR</html:i> in these directories is found to be
group-writable or world-writable, correct its permission with the
following command:
<html:pre>$ sudo chmod go-w <html:i>DIR</html:i></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000258-GPOS-00099</xccdf-1.2:reference>
                <xccdf-1.2:rationale>System binaries are executed by privileged users, as well as system services,
and restrictive permissions are necessary to ensure execution of these programs
cannot be co-opted.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="dir_permissions_binary_dirs" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



find -H /bin/  -perm /u+s,g+ws,o+wt -type d -exec chmod u-s,g-ws,o-wt {} \;

find -H /sbin/  -perm /u+s,g+ws,o+wt -type d -exec chmod u-s,g-ws,o-wt {} \;

find -H /usr/bin/  -perm /u+s,g+ws,o+wt -type d -exec chmod u-s,g-ws,o-wt {} \;

find -H /usr/sbin/  -perm /u+s,g+ws,o+wt -type d -exec chmod u-s,g-ws,o-wt {} \;

find -H /usr/local/bin/  -perm /u+s,g+ws,o+wt -type d -exec chmod u-s,g-ws,o-wt {} \;

find -H /usr/local/sbin/  -perm /u+s,g+ws,o+wt -type d -exec chmod u-s,g-ws,o-wt {} \;
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="dir_permissions_binary_dirs" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Find /bin/ file(s) recursively
  ansible.builtin.command: 'find -P /bin/  -perm /u+s,g+ws,o+wt  -type d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - configure_strategy
  - dir_permissions_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /bin/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-ws,o-wt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - configure_strategy
  - dir_permissions_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /sbin/ file(s) recursively
  ansible.builtin.command: 'find -P /sbin/  -perm /u+s,g+ws,o+wt  -type d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - configure_strategy
  - dir_permissions_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /sbin/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-ws,o-wt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - configure_strategy
  - dir_permissions_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /usr/bin/ file(s) recursively
  ansible.builtin.command: 'find -P /usr/bin/  -perm /u+s,g+ws,o+wt  -type d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - configure_strategy
  - dir_permissions_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /usr/bin/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-ws,o-wt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - configure_strategy
  - dir_permissions_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /usr/sbin/ file(s) recursively
  ansible.builtin.command: 'find -P /usr/sbin/  -perm /u+s,g+ws,o+wt  -type d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - configure_strategy
  - dir_permissions_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /usr/sbin/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-ws,o-wt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - configure_strategy
  - dir_permissions_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /usr/local/bin/ file(s) recursively
  ansible.builtin.command: 'find -P /usr/local/bin/  -perm /u+s,g+ws,o+wt  -type d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - configure_strategy
  - dir_permissions_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /usr/local/bin/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-ws,o-wt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - configure_strategy
  - dir_permissions_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /usr/local/sbin/ file(s) recursively
  ansible.builtin.command: 'find -P /usr/local/sbin/  -perm /u+s,g+ws,o+wt  -type
    d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - configure_strategy
  - dir_permissions_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /usr/local/sbin/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-ws,o-wt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - configure_strategy
  - dir_permissions_binary_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dir_permissions_binary_dirs:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dir_permissions_binary_dirs_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dir_permissions_library_dirs" selected="false" severity="medium">
                <xccdf-1.2:title>Verify that Shared Library Directories Have Restrictive Permissions</xccdf-1.2:title>
                <xccdf-1.2:description>System-wide shared library directories, which contain are linked to executables
during process load time or run time, are stored in the following directories
by default:
<html:pre>/lib
/lib64
/usr/lib
/usr/lib64
</html:pre>

Kernel modules, which can be added to the kernel during runtime, are
stored in <html:code>/lib/modules</html:code>.

All sub-directories in these directories should not be group-writable or world-writable.

If any file in these directories is found to be group-writable or world-writable, correct
its permission with the following command:
<html:pre>$ sudo chmod go-w <html:i>DIR</html:i></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6).1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000259-GPOS-00100</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010331</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-251707r1017360_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If the operating system were to allow any user to make changes to software libraries,
then those changes might be implemented without undergoing the appropriate testing
and approvals that are part of a robust change management process.

This requirement applies to operating systems with software libraries that are accessible
and configurable, as in the case of interpreted languages. Software libraries also include
privileged programs which execute with escalated privileges. Only qualified and authorized
individuals must be allowed to obtain access to information system components for purposes
of initiating changes, including upgrades and modifications.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="dir_permissions_library_dirs" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



find -H /lib/  -perm /g+w,o+w -type d -exec chmod g-w,o-w {} \;

find -H /lib64/  -perm /g+w,o+w -type d -exec chmod g-w,o-w {} \;

find -H /usr/lib/  -perm /g+w,o+w -type d -exec chmod g-w,o-w {} \;

find -H /usr/lib64/  -perm /g+w,o+w -type d -exec chmod g-w,o-w {} \;
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="dir_permissions_library_dirs" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Find /lib/ file(s) recursively
  ansible.builtin.command: 'find -P /lib/  -perm /g+w,o+w  -type d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010331
  - NIST-800-53-CM-5
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_permissions_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /lib/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: g-w,o-w
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010331
  - NIST-800-53-CM-5
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_permissions_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /lib64/ file(s) recursively
  ansible.builtin.command: 'find -P /lib64/  -perm /g+w,o+w  -type d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010331
  - NIST-800-53-CM-5
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_permissions_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /lib64/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: g-w,o-w
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010331
  - NIST-800-53-CM-5
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_permissions_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /usr/lib/ file(s) recursively
  ansible.builtin.command: 'find -P /usr/lib/  -perm /g+w,o+w  -type d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010331
  - NIST-800-53-CM-5
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_permissions_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /usr/lib/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: g-w,o-w
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010331
  - NIST-800-53-CM-5
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_permissions_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /usr/lib64/ file(s) recursively
  ansible.builtin.command: 'find -P /usr/lib64/  -perm /g+w,o+w  -type d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010331
  - NIST-800-53-CM-5
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_permissions_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /usr/lib64/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: g-w,o-w
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010331
  - NIST-800-53-CM-5
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - dir_permissions_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dir_permissions_library_dirs:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dir_permissions_library_dirs_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_sysctld" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Group Who Owns /etc/sysctl.d Directory</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/sysctl.d</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/sysctl.d</html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The ownership of the /etc/sysctl.d directory by the root group is important
because this directory hosts kernel configuration. Protection of this
directory is critical for system security. Assigning the ownership to root
ensures exclusive control of the kernel configuration.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="directory_groupowner_etc_sysctld" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "root" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="root"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "root is not a defined group on the system"
else
find -P /etc/sysctl.d/ -maxdepth 0 -type d  ! -group root -exec chgrp --no-dereference "$newgroup" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="directory_groupowner_etc_sysctld" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_groupowner_etc_sysctld
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Check that the root group is defined
  ansible.builtin.getent:
    database: group
    key: root
  ignore_errors: true
  when:
  - '"kernel" in ansible_facts.packages'
  - directory_groupowner_etc_sysctld_newgroup is undefined
  tags:
  - configure_strategy
  - directory_groupowner_etc_sysctld
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the directory_groupowner_etc_sysctld_newgroup variable if root found
  ansible.builtin.set_fact:
    directory_groupowner_etc_sysctld_newgroup: root
  when:
  - '"kernel" in ansible_facts.packages'
  - ansible_facts.getent_group["root"] is defined
  tags:
  - configure_strategy
  - directory_groupowner_etc_sysctld
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/sysctl.d/
  ansible.builtin.file:
    path: /etc/sysctl.d/
    follow: false
    state: directory
    group: '{{ directory_groupowner_etc_sysctld_newgroup }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_groupowner_etc_sysctld
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_groupowner_etc_sysctld:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_groupowner_etc_sysctld_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_owner_etc_sysctld" selected="false" severity="medium">
                <xccdf-1.2:title>Verify User Who Owns /etc/sysctl.d Directory</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the owner of <html:code>/etc/sysctl.d</html:code>, run the command:
<html:pre>$ sudo chown root /etc/sysctl.d </html:pre>
</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The ownership of the /etc/sysctl.d directory by the root user is important
because this directory hosts kernel configuration. Protection of this
directory is critical for system security. Assigning the ownership to root
ensures exclusive control of the kernel configuration.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="directory_owner_etc_sysctld" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
find -P /etc/sysctl.d/ -maxdepth 0 -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="directory_owner_etc_sysctld" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_owner_etc_sysctld
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the directory_owner_etc_sysctld_newown variable if represented by uid
  ansible.builtin.set_fact:
    directory_owner_etc_sysctld_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_owner_etc_sysctld
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /etc/sysctl.d/
  ansible.builtin.file:
    path: /etc/sysctl.d/
    follow: false
    state: directory
    owner: '{{ directory_owner_etc_sysctld_newown }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_owner_etc_sysctld
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_owner_etc_sysctld:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_owner_etc_sysctld_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_permissions_etc_sysctld" selected="false" severity="medium">
                <xccdf-1.2:title>Verify Permissions On /etc/sysctl.d Directory</xccdf-1.2:title>
                <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/sysctl.d</html:code>, run the command: <html:pre>$ sudo chmod 0755 /etc/sysctl.d</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Setting correct permissions on the /etc/sysctl.d directory is important
because this directory hosts kernel configuration. Protection of this
directory is critical for system security. Restricting the permissions
ensures exclusive control of the kernel configuration.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="directory_permissions_etc_sysctld" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

find -H /etc/sysctl.d/ -maxdepth 0 -perm /u+s,g+ws,o+wt -type d -exec chmod u-s,g-ws,o-wt {} \;

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="directory_permissions_etc_sysctld" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_permissions_etc_sysctld
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/sysctl.d/ file(s)
  ansible.builtin.command: 'find -P /etc/sysctl.d/ -maxdepth 0 -perm /u+s,g+ws,o+wt  -type
    d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_permissions_etc_sysctld
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /etc/sysctl.d/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-ws,o-wt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_permissions_etc_sysctld
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_permissions_etc_sysctld:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_permissions_etc_sysctld_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupownership_system_commands_dirs" selected="false" severity="medium">
                <xccdf-1.2:title>Verify that system commands files are group owned by root or a system account</xccdf-1.2:title>
                <xccdf-1.2:description>System commands files are stored in the following directories by default:
<html:pre>/bin
/sbin
/usr/bin
/usr/sbin
/usr/local/bin
/usr/local/sbin
</html:pre>
All files in these directories should be owned by the <html:code>root</html:code> group,
or a system account.
If the directory, or any file in these directories, is found to be owned
by a group other than root or a a system account correct its ownership
with the following command:
<html:pre>$ sudo chgrp root <html:i>FILE</html:i></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6).1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000259-GPOS-00100</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010320</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230259r1017079_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If the operating system allows any user to make changes to software
libraries, then those changes might be implemented without undergoing the
appropriate testing and approvals that are part of a robust change management
process.
This requirement applies to operating systems with software libraries
that are accessible and configurable, as in the case of interpreted languages.
Software libraries also include privileged programs which execute with
escalated privileges. Only qualified and authorized individuals must be
allowed to obtain access to information system components for purposes
of initiating changes, including upgrades and modifications.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="file_groupownership_system_commands_dirs" system="urn:xccdf:fix:script:sh">
find -P /bin /sbin /usr/bin /usr/sbin /usr/local/bin /usr/local/sbin \! -group root -type f -exec chgrp root '{}' \; || true
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="medium" disruption="medium" id="file_groupownership_system_commands_dirs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Verify that system commands files are group owned by root or a system account
    - Find system command files with incorrect group ownership
  ansible.builtin.find:
    paths: '{{ item }}'
    file_type: file
    follow: false
    recurse: false
  register: system_command_files_found
  with_items:
  - /bin
  - /sbin
  - /usr/bin
  - /usr/sbin
  - /usr/local/bin
  - /usr/local/sbin
  changed_when: false
  tags:
  - DISA-STIG-RHEL-08-010320
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - file_groupownership_system_commands_dirs
  - medium_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Verify that system commands files are group owned by root or a system account
    - Set group ownership to root for system command files
  ansible.builtin.file:
    path: '{{ item.path }}'
    group: root
  with_items: '{{ system_command_files_found.results | map(attribute=''files'') |
    flatten | rejectattr(''gr_name'', ''equalto'', ''root'') | list }}'
  tags:
  - DISA-STIG-RHEL-08-010320
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - file_groupownership_system_commands_dirs
  - medium_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupownership_system_commands_dirs:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupownership_system_commands_dirs_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_ownership_binary_dirs" selected="false" severity="medium">
                <xccdf-1.2:title>Verify that System Executables Have Root Ownership</xccdf-1.2:title>
                <xccdf-1.2:description>System executables are stored in the following directories by default:
<html:pre>/bin
/sbin
/usr/bin
/usr/libexec
/usr/local/bin
/usr/local/sbin
/usr/sbin</html:pre>
All files in these directories should be owned by the <html:code>root</html:code> user.
If any file <html:i>FILE</html:i> in these directories is found
to be owned by a user other than root, correct its ownership with the
following command:
<html:pre>$ sudo chown root <html:i>FILE</html:i></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6).1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000259-GPOS-00100</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010310</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230258r1017078_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>System binaries are executed by privileged users as well as system services,
and restrictive permissions are necessary to ensure that their
execution of these programs cannot be co-opted.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="file_ownership_binary_dirs" system="urn:xccdf:fix:script:sh">
find /bin/ /usr/bin/ /usr/local/bin/ /sbin/ /usr/sbin/ /usr/local/sbin/ /usr/libexec \! -user root -execdir chown root {} \;
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="medium" disruption="medium" id="file_ownership_binary_dirs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Read list of system executables without root ownership
  ansible.builtin.command: find /bin/ /usr/bin/ /usr/local/bin/ /sbin/ /usr/sbin/
    /usr/local/sbin/ /usr/libexec \! -user root
  register: no_root_system_executables
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010310
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - file_ownership_binary_dirs
  - medium_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set ownership to root of system executables
  ansible.builtin.file:
    path: '{{ item }}'
    owner: root
  with_items: '{{ no_root_system_executables.stdout_lines }}'
  when: no_root_system_executables.stdout_lines | length &gt; 0
  tags:
  - DISA-STIG-RHEL-08-010310
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - file_ownership_binary_dirs
  - medium_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_ownership_binary_dirs:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_ownership_binary_dirs_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_ownership_library_dirs" selected="false" severity="medium">
                <xccdf-1.2:title>Verify that Shared Library Files Have Root Ownership</xccdf-1.2:title>
                <xccdf-1.2:description>System-wide shared library files, which are linked to executables
during process load time or run time, are stored in the following directories
by default:
<html:pre>/lib
/lib64
/usr/lib
/usr/lib64
</html:pre>

Kernel modules, which can be added to the kernel during runtime, are also
stored in <html:code>/lib/modules</html:code>.

All files in these directories should be owned by the <html:code>root</html:code> user.

If the directory, or any file in these directories, is found to be owned
by a user other than root correct its ownership with the following command:
<html:pre>$ sudo chown root <html:i>FILE</html:i></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6).1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000259-GPOS-00100</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010340</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230261r1101891_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Files from shared library directories are loaded into the address
space of processes (including privileged ones) or of the kernel itself at
runtime. Proper ownership is necessary to protect the integrity of the system.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_ownership_library_dirs" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else

find -P /lib/  -type f  ! -user 0 -regextype posix-extended -regex '^.*$' -exec chown --no-dereference "$newown" {} \;

find -P /lib64/  -type f  ! -user 0 -regextype posix-extended -regex '^.*$' -exec chown --no-dereference "$newown" {} \;

find -P /usr/lib/  -type f  ! -user 0 -regextype posix-extended -regex '^.*$' -exec chown --no-dereference "$newown" {} \;

find -P /usr/lib64/  -type f  ! -user 0 -regextype posix-extended -regex '^.*$' -exec chown --no-dereference "$newown" {} \;

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_ownership_library_dirs" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the file_ownership_library_dirs_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_ownership_library_dirs_newown: '0'
  tags:
  - DISA-STIG-RHEL-08-010340
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /lib/ file(s) matching ^.*$ recursively
  ansible.builtin.command: find -P /lib/  -type f  ! -user 0 -regextype posix-extended
    -regex "^.*$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010340
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /lib/ file(s) matching ^.*$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    owner: '{{ file_ownership_library_dirs_newown }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010340
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /lib64/ file(s) matching ^.*$ recursively
  ansible.builtin.command: find -P /lib64/  -type f  ! -user 0 -regextype posix-extended
    -regex "^.*$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010340
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /lib64/ file(s) matching ^.*$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    owner: '{{ file_ownership_library_dirs_newown }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010340
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /usr/lib/ file(s) matching ^.*$ recursively
  ansible.builtin.command: find -P /usr/lib/  -type f  ! -user 0 -regextype posix-extended
    -regex "^.*$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010340
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /usr/lib/ file(s) matching ^.*$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    owner: '{{ file_ownership_library_dirs_newown }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010340
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /usr/lib64/ file(s) matching ^.*$ recursively
  ansible.builtin.command: find -P /usr/lib64/  -type f  ! -user 0 -regextype posix-extended
    -regex "^.*$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010340
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /usr/lib64/ file(s) matching ^.*$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    owner: '{{ file_ownership_library_dirs_newown }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010340
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_ownership_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_ownership_library_dirs:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_binary_dirs" selected="false" severity="medium">
                <xccdf-1.2:title>Verify that System Executables Have Restrictive Permissions</xccdf-1.2:title>
                <xccdf-1.2:description>System executables are stored in the following directories by default:
<html:pre>/bin
/sbin
/usr/bin
/usr/libexec
/usr/local/bin
/usr/local/sbin
/usr/sbin</html:pre>
All files in these directories should not be group-writable or world-writable.
If any file <html:i>FILE</html:i> in these directories is found
to be group-writable or world-writable, correct its permission with the
following command:
<html:pre>$ sudo chmod go-w <html:i>FILE</html:i></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6).1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000259-GPOS-00100</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010300</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230257r1017077_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>System binaries are executed by privileged users, as well as system services,
and restrictive permissions are necessary to ensure execution of these programs
cannot be co-opted.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="file_permissions_binary_dirs" system="urn:xccdf:fix:script:sh">DIRS="/bin /usr/bin /usr/local/bin /sbin /usr/sbin /usr/local/sbin /usr/libexec"
for dirPath in $DIRS; do
	find "$dirPath" -perm /022 -exec chmod go-w '{}' \;
done
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="medium" disruption="medium" id="file_permissions_binary_dirs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Read list of world and group writable system executables
  ansible.builtin.command: find -L /bin /usr/bin /usr/local/bin /sbin /usr/sbin /usr/local/sbin
    /usr/libexec -perm /022 \( -type l -o -type f \)
  register: world_writable_library_files
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010300
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - file_permissions_binary_dirs
  - medium_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Remove world/group writability of system executables
  ansible.builtin.file:
    path: '{{ item }}'
    mode: go-w
    state: file
  with_items: '{{ world_writable_library_files.stdout_lines }}'
  when: world_writable_library_files.stdout_lines | length &gt; 0
  tags:
  - DISA-STIG-RHEL-08-010300
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - file_permissions_binary_dirs
  - medium_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_binary_dirs:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_binary_dirs_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_library_dirs" selected="false" severity="medium">
                <xccdf-1.2:title>Verify that Shared Library Files Have Restrictive Permissions</xccdf-1.2:title>
                <xccdf-1.2:description>System-wide shared library files, which are linked to executables
during process load time or run time, are stored in the following directories
by default:
<html:pre>/lib
/lib64
/usr/lib
/usr/lib64
</html:pre>

Kernel modules, which can be added to the kernel during runtime, are
stored in <html:code>/lib/modules</html:code>.

All files in these directories should not be group-writable or world-writable.

If any file in these directories is found to be group-writable
or world-writable, correct its permission with the following command:
<html:pre>$ sudo chmod go-w <html:i>FILE</html:i></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6).1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000259-GPOS-00100</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010330</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230260r1101888_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Files from shared library directories are loaded into the address
space of processes (including privileged ones) or of the kernel itself at
runtime. Restrictive permissions are necessary to protect the integrity of the system.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_library_dirs" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



find -P /lib/  -perm /g+w,o+w  -type f -regextype posix-extended -regex '^.*$' -exec chmod g-w,o-w {} \;

find -P /lib64/  -perm /g+w,o+w  -type f -regextype posix-extended -regex '^.*$' -exec chmod g-w,o-w {} \;

find -P /usr/lib/  -perm /g+w,o+w  -type f -regextype posix-extended -regex '^.*$' -exec chmod g-w,o-w {} \;

find -P /usr/lib64/  -perm /g+w,o+w  -type f -regextype posix-extended -regex '^.*$' -exec chmod g-w,o-w {} \;
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_library_dirs" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Find /lib/ file(s) recursively
  ansible.builtin.command: find -P /lib/  -perm /g+w,o+w  -type f -regextype posix-extended
    -regex "^.*$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010330
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /lib/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: g-w,o-w
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010330
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /lib64/ file(s) recursively
  ansible.builtin.command: find -P /lib64/  -perm /g+w,o+w  -type f -regextype posix-extended
    -regex "^.*$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010330
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /lib64/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: g-w,o-w
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010330
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /usr/lib/ file(s) recursively
  ansible.builtin.command: find -P /usr/lib/  -perm /g+w,o+w  -type f -regextype posix-extended
    -regex "^.*$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010330
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /usr/lib/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: g-w,o-w
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010330
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /usr/lib64/ file(s) recursively
  ansible.builtin.command: find -P /usr/lib64/  -perm /g+w,o+w  -type f -regextype
    posix-extended -regex "^.*$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010330
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /usr/lib64/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: g-w,o-w
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010330
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_library_dirs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_library_dirs:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_library_dirs_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_root_permissions_syslibrary_files" selected="false" severity="medium">
                <xccdf-1.2:title>Verify the system-wide library files in directories
"/lib", "/lib64", "/usr/lib/" and "/usr/lib64" are group-owned by root.</xccdf-1.2:title>
                <xccdf-1.2:description>System-wide library files are stored in the following directories
by default:
<html:pre>/lib
/lib64
/usr/lib
/usr/lib64
</html:pre>
All system-wide shared library files should be protected from unauthorised
access. If any of these files is not group-owned by root,
correct its group-owner with the following command:
<html:pre>$ sudo chgrp root <html:i>FILE</html:i></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(6).1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000259-GPOS-00100</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010350</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230262r1155384_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If the operating system were to allow any user to make changes to software libraries,
then those changes might be implemented without undergoing the appropriate testing and
approvals that are part of a robust change management process.

This requirement applies to operating systems with software libraries that are
accessible and configurable, as in the case of interpreted languages. Software libraries
also include privileged programs which execute with escalated privileges. Only qualified
and authorized individuals must be allowed to obtain access to information system components
for purposes of initiating changes, including upgrades and modifications.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="root_permissions_syslibrary_files" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">
newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
find -P /lib/  -type f  ! -group 0 -regextype posix-extended -regex '^.*$' -exec chgrp --no-dereference "$newgroup" {} \;
find -P /lib64/  -type f  ! -group 0 -regextype posix-extended -regex '^.*$' -exec chgrp --no-dereference "$newgroup" {} \;
find -P /usr/lib/  -type f  ! -group 0 -regextype posix-extended -regex '^.*$' -exec chgrp --no-dereference "$newgroup" {} \;
find -P /usr/lib64/  -type f  ! -group 0 -regextype posix-extended -regex '^.*$' -exec chgrp --no-dereference "$newgroup" {} \;

fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="root_permissions_syslibrary_files" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Set the root_permissions_syslibrary_files_newgroup variable if represented
    by gid
  ansible.builtin.set_fact:
    root_permissions_syslibrary_files_newgroup: '0'
  tags:
  - DISA-STIG-RHEL-08-010350
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - root_permissions_syslibrary_files

- name: Find /lib/ file(s) matching ^.*$ recursively
  ansible.builtin.command: find -P /lib/  -type f  ! -group 0 -regextype posix-extended
    -regex "^.*$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010350
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - root_permissions_syslibrary_files

- name: Ensure group owner on /lib/ file(s) matching ^.*$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    group: '{{ root_permissions_syslibrary_files_newgroup }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010350
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - root_permissions_syslibrary_files

- name: Find /lib64/ file(s) matching ^.*$ recursively
  ansible.builtin.command: find -P /lib64/  -type f  ! -group 0 -regextype posix-extended
    -regex "^.*$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010350
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - root_permissions_syslibrary_files

- name: Ensure group owner on /lib64/ file(s) matching ^.*$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    group: '{{ root_permissions_syslibrary_files_newgroup }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010350
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - root_permissions_syslibrary_files

- name: Find /usr/lib/ file(s) matching ^.*$ recursively
  ansible.builtin.command: find -P /usr/lib/  -type f  ! -group 0 -regextype posix-extended
    -regex "^.*$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010350
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - root_permissions_syslibrary_files

- name: Ensure group owner on /usr/lib/ file(s) matching ^.*$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    group: '{{ root_permissions_syslibrary_files_newgroup }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010350
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - root_permissions_syslibrary_files

- name: Find /usr/lib64/ file(s) matching ^.*$ recursively
  ansible.builtin.command: find -P /usr/lib64/  -type f  ! -group 0 -regextype posix-extended
    -regex "^.*$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - DISA-STIG-RHEL-08-010350
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - root_permissions_syslibrary_files

- name: Ensure group owner on /usr/lib64/ file(s) matching ^.*$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    group: '{{ root_permissions_syslibrary_files_newgroup }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010350
  - NIST-800-53-CM-5(6)
  - NIST-800-53-CM-5(6).1
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - root_permissions_syslibrary_files
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-root_permissions_syslibrary_files:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-root_permissions_syslibrary_files_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_rootfiles">
              <xccdf-1.2:title>rootfiles</xccdf-1.2:title>
              <xccdf-1.2:description>Configure the rootfiles package so the root user's files are correctly secured.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_rootfiles_configured" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure rootfiles tmpfile.d is Configured Correctly</xccdf-1.2:title>
                <xccdf-1.2:description>To set the mode of the root user initialization file <html:code>/root/.bash_profile</html:code>,
ensure the following lines are is included in a file ending in <html:code>.conf</html:code> under
<html:code>/etc/tmpfiles.d/</html:code>.
<html:pre>
    C /root/.bash_logout   600 root root - /usr/share/rootfiles/.bash_logout
    C /root/.bash_profile  600 root root - /usr/share/rootfiles/.bash_profile
    C /root/.bashrc        600 root root - /usr/share/rootfiles/.bashrc
    C /root/.cshrc         600 root root - /usr/share/rootfiles/.cshrc
    C /root/.tcshrc        600 root root - /usr/share/rootfiles/.tcshrc
</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010770</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230325r1017136_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Local initialization files are used to configure the user's shell environment
upon logon. Malicious modification of these files could compromise accounts upon
logon.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_rootfiles"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="rootfiles_configured" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q rootfiles; then

find "/etc/tmpfiles.d/" -name "*.conf" -print0 | xargs -0 sed -i  "/C[[:space:]]*\/root\/.bash_logout/d"
    find "/etc/tmpfiles.d/" -name "*.conf" -print0 | xargs -0 sed -i  "/C[[:space:]]*\/root\/.bash_profile/d"
    find "/etc/tmpfiles.d/" -name "*.conf" -print0 | xargs -0 sed -i  "/C[[:space:]]*\/root\/.bashrc/d"
    find "/etc/tmpfiles.d/" -name "*.conf" -print0 | xargs -0 sed -i  "/C[[:space:]]*\/root\/.cshrc/d"
    find "/etc/tmpfiles.d/" -name "*.conf" -print0 | xargs -0 sed -i  "/C[[:space:]]*\/root\/.tcshrc/d"


cat &lt;&lt; 'EOF' &gt; /etc/tmpfiles.d/rootfiles.conf
C /root/.bash_logout 600 root root - /usr/share/rootfiles/.bash_logout
C /root/.bash_profile 600 root root - /usr/share/rootfiles/.bash_profile
C /root/.bashrc 600 root root - /usr/share/rootfiles/.bashrc
C /root/.cshrc 600 root root - /usr/share/rootfiles/.cshrc
C /root/.tcshrc 600 root root - /usr/share/rootfiles/.tcshrc

EOF

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="rootfiles_configured" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010770
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rootfiles_configured

- name: Ensure rootfiles tmpfile.d is Configured Correctly - Find configuration files
  ansible.builtin.find:
    paths: /etc/tmpfiles.d/
    file_type: file
    patterns: '*.conf'
  register: rootfiles_configured_bash_logout_found_files
  when: '"rootfiles" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010770
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rootfiles_configured

- name: Ensure rootfiles tmpfile.d is Configured Correctly - Remove existing configuration
  ansible.builtin.lineinfile:
    path: '{{ item.path }}'
    regexp: ^C\s+/root/\.bash_logout.+$
    state: absent
  loop: '{{ rootfiles_configured_bash_logout_found_files.files }}'
  when: '"rootfiles" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010770
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rootfiles_configured

- name: Ensure rootfiles tmpfile.d is Configured Correctly
  ansible.builtin.lineinfile:
    path: /etc/tmpfiles.d/rootfiles.conf
    create: true
    regexp: (?i)/usr/share/rootfiles/.bash_logout
    line: C /root/.bash_logout 600 root root - /usr/share/rootfiles/.bash_logout
    state: present
  when: '"rootfiles" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010770
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rootfiles_configured

- name: Ensure rootfiles tmpfile.d is Configured Correctly - Find configuration files
  ansible.builtin.find:
    paths: /etc/tmpfiles.d/
    file_type: file
    patterns: '*.conf'
  register: rootfiles_configured_bash_profile_found_files
  when: '"rootfiles" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010770
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rootfiles_configured

- name: Ensure rootfiles tmpfile.d is Configured Correctly - Remove existing configuration
  ansible.builtin.lineinfile:
    path: '{{ item.path }}'
    regexp: ^C\s+/root/\.bash_profile.+$
    state: absent
  loop: '{{ rootfiles_configured_bash_profile_found_files.files }}'
  when: '"rootfiles" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010770
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rootfiles_configured

- name: Ensure rootfiles tmpfile.d is Configured Correctly
  ansible.builtin.lineinfile:
    path: /etc/tmpfiles.d/rootfiles.conf
    create: true
    regexp: (?i)/usr/share/rootfiles/.bash_profile
    line: C /root/.bash_profile 600 root root - /usr/share/rootfiles/.bash_profile
    state: present
  when: '"rootfiles" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010770
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rootfiles_configured

- name: Ensure rootfiles tmpfile.d is Configured Correctly - Find configuration files
  ansible.builtin.find:
    paths: /etc/tmpfiles.d/
    file_type: file
    patterns: '*.conf'
  register: rootfiles_configured_bashrc_found_files
  when: '"rootfiles" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010770
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rootfiles_configured

- name: Ensure rootfiles tmpfile.d is Configured Correctly - Remove existing configuration
  ansible.builtin.lineinfile:
    path: '{{ item.path }}'
    regexp: ^C\s+/root/\.bashrc.+$
    state: absent
  loop: '{{ rootfiles_configured_bashrc_found_files.files }}'
  when: '"rootfiles" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010770
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rootfiles_configured

- name: Ensure rootfiles tmpfile.d is Configured Correctly
  ansible.builtin.lineinfile:
    path: /etc/tmpfiles.d/rootfiles.conf
    create: true
    regexp: (?i)/usr/share/rootfiles/.bashrc
    line: C /root/.bashrc 600 root root - /usr/share/rootfiles/.bashrc
    state: present
  when: '"rootfiles" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010770
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rootfiles_configured

- name: Ensure rootfiles tmpfile.d is Configured Correctly - Find configuration files
  ansible.builtin.find:
    paths: /etc/tmpfiles.d/
    file_type: file
    patterns: '*.conf'
  register: rootfiles_configured_cshrc_found_files
  when: '"rootfiles" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010770
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rootfiles_configured

- name: Ensure rootfiles tmpfile.d is Configured Correctly - Remove existing configuration
  ansible.builtin.lineinfile:
    path: '{{ item.path }}'
    regexp: ^C\s+/root/\.cshrc.+$
    state: absent
  loop: '{{ rootfiles_configured_cshrc_found_files.files }}'
  when: '"rootfiles" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010770
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rootfiles_configured

- name: Ensure rootfiles tmpfile.d is Configured Correctly
  ansible.builtin.lineinfile:
    path: /etc/tmpfiles.d/rootfiles.conf
    create: true
    regexp: (?i)/usr/share/rootfiles/.cshrc
    line: C /root/.cshrc 600 root root - /usr/share/rootfiles/.cshrc
    state: present
  when: '"rootfiles" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010770
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rootfiles_configured

- name: Ensure rootfiles tmpfile.d is Configured Correctly - Find configuration files
  ansible.builtin.find:
    paths: /etc/tmpfiles.d/
    file_type: file
    patterns: '*.conf'
  register: rootfiles_configured_tcshrc_found_files
  when: '"rootfiles" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010770
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rootfiles_configured

- name: Ensure rootfiles tmpfile.d is Configured Correctly - Remove existing configuration
  ansible.builtin.lineinfile:
    path: '{{ item.path }}'
    regexp: ^C\s+/root/\.tcshrc.+$
    state: absent
  loop: '{{ rootfiles_configured_tcshrc_found_files.files }}'
  when: '"rootfiles" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010770
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rootfiles_configured

- name: Ensure rootfiles tmpfile.d is Configured Correctly
  ansible.builtin.lineinfile:
    path: /etc/tmpfiles.d/rootfiles.conf
    create: true
    regexp: (?i)/usr/share/rootfiles/.tcshrc
    line: C /root/.tcshrc 600 root root - /usr/share/rootfiles/.tcshrc
    state: present
  when: '"rootfiles" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010770
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - rootfiles_configured
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-rootfiles_configured:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-rootfiles_configured_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_mounting">
            <xccdf-1.2:title>Restrict Dynamic Mounting and Unmounting of
Filesystems</xccdf-1.2:title>
            <xccdf-1.2:description>Linux includes a number of facilities for the automated addition
and removal of filesystems on a running system.  These facilities may be
necessary in many environments, but this capability also carries some risk -- whether direct
risk from allowing users to introduce arbitrary filesystems,
or risk that software flaws in the automated mount facility itself could
allow an attacker to compromise the system.
<html:br/><html:br/>
This command can be used to list the types of filesystems that are
available to the currently executing kernel:
<html:pre>$ find /lib/modules/`uname -r`/kernel/fs -type f -name '*.ko'</html:pre>
If these filesystems are not required then they can be explicitly disabled
in a configuratio file in  <html:code>/etc/modprobe.d</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_autofs_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the Automounter</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>autofs</html:code> daemon mounts and unmounts filesystems, such as user
home directories shared via NFS, on demand. In addition, autofs can be used to handle
removable media, and the default configuration provides the cdrom device as <html:code>/misc/cd</html:code>.
However, this method of providing access to removable media is not common, so autofs
can almost always be disabled if NFS is not in use. Even if NFS is required, it may be
possible to configure filesystem mounts statically by editing <html:code>/etc/fstab</html:code>
rather than relying on the automounter.
<html:br/><html:br/>

The <html:code>autofs</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now autofs.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(iv)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000114-GPOS-00059</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000378-GPOS-00163</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040070</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230502r1155393_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Disabling the automounter permits the administrator to
statically control filesystem mounting through <html:code>/etc/fstab</html:code>.
<html:br/><html:br/>
Additionally, automatically mounting filesystems permits easy introduction of
unknown devices, thereby facilitating malicious activity.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_autofs_and_system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_autofs_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q autofs &amp;&amp; rpm --quiet -q kernel ) ); then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'autofs.service'
fi
"$SYSTEMCTL_EXEC" disable 'autofs.service'
"$SYSTEMCTL_EXEC" mask 'autofs.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files autofs.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'autofs.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'autofs.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'autofs.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_autofs_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040070
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_autofs_disabled

- name: Disable the Automounter - Disable service autofs
  block:

  - name: Disable the Automounter - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable the Automounter - Ensure autofs.service is Masked
    ansible.builtin.systemd:
      name: autofs.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("autofs.service", multiline=True)

  - name: Unit Socket Exists - autofs.socket
    ansible.builtin.command: systemctl -q list-unit-files autofs.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable the Automounter - Disable Socket autofs
    ansible.builtin.systemd:
      name: autofs.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("autofs.socket", multiline=True)
  tags:
  - DISA-STIG-RHEL-08-040070
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_autofs_disabled
  - special_service_block
  when: ( "autofs" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_autofs_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_autofs

class disable_autofs {
  service {'autofs':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_autofs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: autofs.service
        enabled: false
        mask: true
      - name: autofs.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_autofs_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["autofs"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_autofs_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable autofs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_autofs_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_bios_assign_password" selected="false" severity="unknown">
              <xccdf-1.2:title>Assign Password to Prevent Changes to Boot Firmware Configuration</xccdf-1.2:title>
              <xccdf-1.2:description>Assign a password to the system boot firmware (historically called BIOS on PC
systems) to require a password for any configuration changes.</xccdf-1.2:description>
              <xccdf-1.2:rationale>Assigning a password to the system boot firmware prevents anyone
with physical access from configuring the system to boot
from local media and circumvent the operating system's access controls.
For systems in physically secure locations, such as
a data center or Sensitive Compartmented Information Facility (SCIF), this risk must be weighed
against the risk of administrative personnel being unable to conduct recovery operations in
a timely fashion.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_bios_disable_usb_boot" selected="false" severity="unknown">
              <xccdf-1.2:title>Disable Booting from USB Devices in Boot Firmware</xccdf-1.2:title>
              <xccdf-1.2:description>Configure the system boot firmware (historically called BIOS on PC
systems) to disallow booting from USB drives.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Booting a system from a USB device would allow an attacker to
circumvent any security measures provided by the operating system. Attackers
could mount partitions and modify the configuration of the OS.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-bios_disable_usb_boot_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_nousb_argument" selected="false" severity="unknown">
              <xccdf-1.2:title>Disable Kernel Support for USB via Bootloader Configuration</xccdf-1.2:title>
              <xccdf-1.2:description>All USB support can be disabled by adding the <html:code>nousb</html:code>
argument to the kernel's boot loader configuration. To do so,
add the argument <html:code>nousb</html:code> to the default
GRUB 2 command line for the Linux operating system.
Configure the default Grub2 kernel command line to contain nousb as follows:
<html:pre># grub2-editenv - set "$(grub2-editenv - list | grep kernelopts) nousb"</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="functionality">Disabling all kernel support for USB will cause problems for systems
with USB-based keyboards, mice, or printers. This configuration is
infeasible for systems which require USB devices, which is common.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(iv)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Disabling the USB subsystem within the Linux kernel at system boot will
protect against potentially malicious USB devices, although it is only practical
in specialized systems.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#grub2"/>
              <xccdf-1.2:fix id="grub2_nousb_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q grub2-common; then

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    KARGS_DIR="/usr/lib/bootc/kargs.d/"
    if grep -q -E "nousb" "$KARGS_DIR/*.toml" ; then
        sed -i -E "s/^(\s*kargs\s*=\s*\[.*)\"nousb=[^\"]*\"(.*]\s*)/\1\"nousb\"\2/" "$KARGS_DIR/*.toml"
    else
        echo "kargs = [\"nousb\"]" &gt;&gt; "$KARGS_DIR/10-nousb.toml"
    fi
else

    grubby --update-kernel=ALL --args=nousb --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_nousb_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MP-7
  - grub2_nousb_argument
  - low_disruption
  - medium_complexity
  - reboot_required
  - restrict_strategy
  - unknown_severity

- name: Check if nousb argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when: '"grub2-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MP-7
  - grub2_nousb_argument
  - low_disruption
  - medium_complexity
  - reboot_required
  - restrict_strategy
  - unknown_severity

- name: Check if nousb argument is already present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"grub2-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MP-7
  - grub2_nousb_argument
  - low_disruption
  - medium_complexity
  - reboot_required
  - restrict_strategy
  - unknown_severity

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --args="nousb"
  when:
  - '"grub2-common" in ansible_facts.packages'
  - (grubby_info.stdout is not search('nousb')) or ((etc_default_grub['content'] |
    b64decode) is not search('nousb'))
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MP-7
  - grub2_nousb_argument
  - low_disruption
  - medium_complexity
  - reboot_required
  - restrict_strategy
  - unknown_severity
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="grub2_nousb_argument" system="urn:redhat:osbuild:blueprint">[customizations.kernel]
append = "nousb"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_nousb_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kickstart">
bootloader nousb
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_nousb_argument:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_nousb_argument_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_cramfs_disabled" selected="false" severity="low">
              <xccdf-1.2:title>Disable Mounting of cramfs</xccdf-1.2:title>
              <xccdf-1.2:description>
To configure the system to prevent the <html:code>cramfs</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/cramfs.conf</html:code>:
<html:pre>install cramfs /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>cramfs</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install cramfs /bin/true</html:pre>

This effectively prevents usage of this uncommon filesystem.

The <html:code>cramfs</html:code> filesystem type is a compressed read-only
Linux filesystem embedded in small footprint systems. A
<html:code>cramfs</html:code> image can be used without having to first
decompress the image.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040025</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230498r1069314_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Removing support for unneeded filesystem types reduces the local attack surface
of the server.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_cramfs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install cramfs" /etc/modprobe.d/cramfs.conf ; then
	
	sed -i 's#^install cramfs.*#install cramfs /bin/false#g' /etc/modprobe.d/cramfs.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/cramfs.conf
	echo "install cramfs /bin/false" &gt;&gt; /etc/modprobe.d/cramfs.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_cramfs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040025
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_cramfs_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required

- name: Ensure kernel module 'cramfs' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/cramfs.conf
    regexp: install\s+cramfs
    line: install cramfs /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040025
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_cramfs_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_cramfs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20cramfs%20/bin/false%0Ablacklist%20cramfs%0A
        mode: 0644
        path: /etc/modprobe.d/cramfs.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_cramfs_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_module_cramfs_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_freevxfs_disabled" selected="false" severity="low">
              <xccdf-1.2:title>Disable Mounting of freevxfs</xccdf-1.2:title>
              <xccdf-1.2:description>
To configure the system to prevent the <html:code>freevxfs</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/freevxfs.conf</html:code>:
<html:pre>install freevxfs /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>freevxfs</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install freevxfs /bin/true</html:pre>

This effectively prevents usage of this uncommon filesystem.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.1.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Linux kernel modules which implement filesystems that are not needed by the
local system should be disabled.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_freevxfs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install freevxfs" /etc/modprobe.d/freevxfs.conf ; then
	
	sed -i 's#^install freevxfs.*#install freevxfs /bin/false#g' /etc/modprobe.d/freevxfs.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/freevxfs.conf
	echo "install freevxfs /bin/false" &gt;&gt; /etc/modprobe.d/freevxfs.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_freevxfs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_freevxfs_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required

- name: Ensure kernel module 'freevxfs' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/freevxfs.conf
    regexp: install\s+freevxfs
    line: install freevxfs /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_freevxfs_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_freevxfs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20freevxfs%20/bin/false%0Ablacklist%20freevxfs%0A
        mode: 0644
        path: /etc/modprobe.d/freevxfs.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_freevxfs_disabled:def:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_hfs_disabled" selected="false" severity="low">
              <xccdf-1.2:title>Disable Mounting of hfs</xccdf-1.2:title>
              <xccdf-1.2:description>
To configure the system to prevent the <html:code>hfs</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/hfs.conf</html:code>:
<html:pre>install hfs /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>hfs</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install hfs /bin/true</html:pre>

This effectively prevents usage of this uncommon filesystem.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.1.3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Linux kernel modules which implement filesystems that are not needed by the
local system should be disabled.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_hfs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install hfs" /etc/modprobe.d/hfs.conf ; then
	
	sed -i 's#^install hfs.*#install hfs /bin/false#g' /etc/modprobe.d/hfs.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/hfs.conf
	echo "install hfs /bin/false" &gt;&gt; /etc/modprobe.d/hfs.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_hfs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_hfs_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required

- name: Ensure kernel module 'hfs' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/hfs.conf
    regexp: install\s+hfs
    line: install hfs /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_hfs_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_hfs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20hfs%20/bin/false%0Ablacklist%20hfs%0A
        mode: 0644
        path: /etc/modprobe.d/hfs.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_hfs_disabled:def:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_hfsplus_disabled" selected="false" severity="low">
              <xccdf-1.2:title>Disable Mounting of hfsplus</xccdf-1.2:title>
              <xccdf-1.2:description>
To configure the system to prevent the <html:code>hfsplus</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/hfsplus.conf</html:code>:
<html:pre>install hfsplus /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>hfsplus</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install hfsplus /bin/true</html:pre>

This effectively prevents usage of this uncommon filesystem.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.1.4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Linux kernel modules which implement filesystems that are not needed by the
local system should be disabled.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_hfsplus_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install hfsplus" /etc/modprobe.d/hfsplus.conf ; then
	
	sed -i 's#^install hfsplus.*#install hfsplus /bin/false#g' /etc/modprobe.d/hfsplus.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/hfsplus.conf
	echo "install hfsplus /bin/false" &gt;&gt; /etc/modprobe.d/hfsplus.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_hfsplus_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_hfsplus_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required

- name: Ensure kernel module 'hfsplus' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/hfsplus.conf
    regexp: install\s+hfsplus
    line: install hfsplus /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_hfsplus_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_hfsplus_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20hfsplus%20/bin/false%0Ablacklist%20hfsplus%0A
        mode: 0644
        path: /etc/modprobe.d/hfsplus.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_hfsplus_disabled:def:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_jffs2_disabled" selected="false" severity="low">
              <xccdf-1.2:title>Disable Mounting of jffs2</xccdf-1.2:title>
              <xccdf-1.2:description>
To configure the system to prevent the <html:code>jffs2</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/jffs2.conf</html:code>:
<html:pre>install jffs2 /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>jffs2</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install jffs2 /bin/true</html:pre>

This effectively prevents usage of this uncommon filesystem.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.1.5</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Linux kernel modules which implement filesystems that are not needed by the
local system should be disabled.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_jffs2_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install jffs2" /etc/modprobe.d/jffs2.conf ; then
	
	sed -i 's#^install jffs2.*#install jffs2 /bin/false#g' /etc/modprobe.d/jffs2.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/jffs2.conf
	echo "install jffs2 /bin/false" &gt;&gt; /etc/modprobe.d/jffs2.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_jffs2_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_jffs2_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required

- name: Ensure kernel module 'jffs2' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/jffs2.conf
    regexp: install\s+jffs2
    line: install jffs2 /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_jffs2_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_jffs2_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20jffs2%20/bin/false%0Ablacklist%20jffs2%0A
        mode: 0644
        path: /etc/modprobe.d/jffs2.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_jffs2_disabled:def:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_overlayfs_disabled" selected="false" severity="low">
              <xccdf-1.2:title>Ensure overlayfs kernel module is not available</xccdf-1.2:title>
              <xccdf-1.2:description>
To configure the system to prevent the <html:code>overlayfs</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/overlayfs.conf</html:code>:
<html:pre>install overlayfs /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>overlayfs</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install overlayfs /bin/true</html:pre>

overlayfs is a Linux filesystem that layers multiple filesystems to create a single
unified view which allows a user to "merge" several mount points into a unified
filesystem.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.1.6</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The overlayfs has known CVE's. Disabling the overlayfs reduces the local attack 
surface by removing support for unnecessary filesystem types and mitigates potential
risks associated with unauthorized execution of setuid files, enhancing the overall
system security.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_overlayfs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install overlayfs" /etc/modprobe.d/overlayfs.conf ; then
	
	sed -i 's#^install overlayfs.*#install overlayfs /bin/false#g' /etc/modprobe.d/overlayfs.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/overlayfs.conf
	echo "install overlayfs /bin/false" &gt;&gt; /etc/modprobe.d/overlayfs.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_overlayfs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - kernel_module_overlayfs_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required

- name: Ensure kernel module 'overlayfs' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/overlayfs.conf
    regexp: install\s+overlayfs
    line: install overlayfs /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - kernel_module_overlayfs_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_overlayfs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20overlayfs%20/bin/false%0Ablacklist%20overlayfs%0A
        mode: 0644
        path: /etc/modprobe.d/overlayfs.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_overlayfs_disabled:def:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_squashfs_disabled" selected="false" severity="low">
              <xccdf-1.2:title>Disable Mounting of squashfs</xccdf-1.2:title>
              <xccdf-1.2:description>
To configure the system to prevent the <html:code>squashfs</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/squashfs.conf</html:code>:
<html:pre>install squashfs /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>squashfs</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install squashfs /bin/true</html:pre>

This effectively prevents usage of this uncommon filesystem.

The <html:code>squashfs</html:code> filesystem type is a compressed read-only Linux
filesystem embedded in small footprint systems (similar to
<html:code>cramfs</html:code>). A <html:code>squashfs</html:code> image can be used without having
to first decompress the image.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.1.7</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Removing support for unneeded filesystem types reduces the local attack
surface of the system.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_squashfs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install squashfs" /etc/modprobe.d/squashfs.conf ; then
	
	sed -i 's#^install squashfs.*#install squashfs /bin/false#g' /etc/modprobe.d/squashfs.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/squashfs.conf
	echo "install squashfs /bin/false" &gt;&gt; /etc/modprobe.d/squashfs.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_squashfs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_squashfs_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required

- name: Ensure kernel module 'squashfs' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/squashfs.conf
    regexp: install\s+squashfs
    line: install squashfs /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_squashfs_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_squashfs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20squashfs%20/bin/false%0Ablacklist%20squashfs%0A
        mode: 0644
        path: /etc/modprobe.d/squashfs.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_squashfs_disabled:def:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_udf_disabled" selected="false" severity="low">
              <xccdf-1.2:title>Disable Mounting of udf</xccdf-1.2:title>
              <xccdf-1.2:description>
To configure the system to prevent the <html:code>udf</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/udf.conf</html:code>:
<html:pre>install udf /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>udf</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install udf /bin/true</html:pre>

This effectively prevents usage of this uncommon filesystem.

The <html:code>udf</html:code> filesystem type is the universal disk format
used to implement the ISO/IEC 13346 and ECMA-167 specifications.
This is an open vendor filesystem type for data storage on a broad
range of media. This filesystem type is necessary to support
writing DVDs and newer optical disc formats.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.1.8</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Removing support for unneeded filesystem types reduces the local
attack surface of the system.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_udf_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install udf" /etc/modprobe.d/udf.conf ; then
	
	sed -i 's#^install udf.*#install udf /bin/false#g' /etc/modprobe.d/udf.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/udf.conf
	echo "install udf /bin/false" &gt;&gt; /etc/modprobe.d/udf.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_udf_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_udf_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required

- name: Ensure kernel module 'udf' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/udf.conf
    regexp: install\s+udf
    line: install udf /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_udf_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_udf_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20udf%20/bin/false%0Ablacklist%20udf%0A
        mode: 0644
        path: /etc/modprobe.d/udf.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_udf_disabled:def:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_usb-storage_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable Modprobe Loading of USB Storage Driver</xccdf-1.2:title>
              <xccdf-1.2:description>To prevent USB storage devices from being used, configure the kernel module loading system
to prevent automatic loading of the USB storage driver.

To configure the system to prevent the <html:code>usb-storage</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/usb-storage.conf</html:code>:
<html:pre>install usb-storage /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>usb-storage</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install usb-storage /bin/true</html:pre>

This will prevent the <html:code>modprobe</html:code> program from loading the <html:code>usb-storage</html:code>
module, but will not prevent an administrator (or another program) from using the
<html:code>insmod</html:code> program to load the module manually.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.21</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(iv)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000114-GPOS-00059</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000378-GPOS-00163</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000141-CTR-000315</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040080</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230503r1069316_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>USB storage devices such as thumb drives can be used to introduce
malicious software.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_usb-storage_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install usb-storage" /etc/modprobe.d/usb-storage.conf ; then
	
	sed -i 's#^install usb-storage.*#install usb-storage /bin/false#g' /etc/modprobe.d/usb-storage.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/usb-storage.conf
	echo "install usb-storage /bin/false" &gt;&gt; /etc/modprobe.d/usb-storage.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_usb-storage_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040080
  - NIST-800-171-3.1.21
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - PCI-DSSv4-3.4
  - PCI-DSSv4-3.4.2
  - disable_strategy
  - kernel_module_usb-storage_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required

- name: Ensure kernel module 'usb-storage' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/usb-storage.conf
    regexp: install\s+usb-storage
    line: install usb-storage /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040080
  - NIST-800-171-3.1.21
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - PCI-DSSv4-3.4
  - PCI-DSSv4-3.4.2
  - disable_strategy
  - kernel_module_usb-storage_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_usb-storage_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20usb-storage%20/bin/false%0Ablacklist%20usb-storage%0A
        mode: 0644
        path: /etc/modprobe.d/usb-storage.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_usb-storage_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_vfat_disabled" selected="false" severity="low">
              <xccdf-1.2:title>Disable Mounting of vFAT filesystems</xccdf-1.2:title>
              <xccdf-1.2:description>
To configure the system to prevent the <html:code>vfat</html:code>
kernel module from being loaded, add the following line to the file <html:code>/etc/modprobe.d/vfat.conf</html:code>:
<html:pre>install vfat /bin/false</html:pre>
This entry will cause a non-zero return value during a <html:code>vfat</html:code> module installation
and additionally convey the meaning of the entry to the user in form of an error message.
If you would like to omit a non-zero return value and an error message, you may want to add a different line instead
(both <html:code>/bin/true</html:code> and <html:code>/bin/false</html:code> are allowed by OVAL and will be accepted by the scan):
<html:pre>install vfat /bin/true</html:pre>

This effectively prevents usage of this uncommon filesystem.

The <html:code>vFAT</html:code> filesystem format is primarily used on older
windows systems and portable USB drives or flash modules. It comes
in three types <html:code>FAT12</html:code>, <html:code>FAT16</html:code>, and <html:code>FAT32</html:code>
all of which are supported by the <html:code>vfat</html:code> kernel module.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Removing support for unneeded filesystems reduces the local attack
surface of the system.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#non-uefi_and_system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_vfat_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( [ ! -d /sys/firmware/efi ] &amp;&amp; rpm --quiet -q kernel ) ); then

if LC_ALL=C grep -q -m 1 "^install vfat" /etc/modprobe.d/vfat.conf ; then
	
	sed -i 's#^install vfat.*#install vfat /bin/false#g' /etc/modprobe.d/vfat.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/vfat.conf
	echo "install vfat /bin/false" &gt;&gt; /etc/modprobe.d/vfat.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_vfat_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_vfat_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required

- name: Ensure kernel module 'vfat' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/vfat.conf
    regexp: install\s+vfat
    line: install vfat /bin/false
  when: ( not ('/sys/firmware/efi' is directory) and "kernel" in ansible_facts.packages
    )
  tags:
  - NIST-800-171-3.4.6
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - kernel_module_vfat_disabled
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_vfat_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20vfat%20/bin/false%0Ablacklist%20vfat%0A
        mode: 0644
        path: /etc/modprobe.d/vfat.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_vfat_disabled:def:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_partitions">
            <xccdf-1.2:title>Restrict Partition Mount Options</xccdf-1.2:title>
            <xccdf-1.2:description>System partitions can be mounted with certain options
that limit what files on those partitions can do. These options
are set in the <html:code>/etc/fstab</html:code> configuration file, and can be
used to make certain types of malicious behavior more difficult.</xccdf-1.2:description>
            <xccdf-1.2:platform idref="#not_bootc_and_not_container"/>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mount_option_proc_hidepid" type="string">
              <xccdf-1.2:title>Value for hidepid option</xccdf-1.2:title>
              <xccdf-1.2:description>The hidepid mount option is applicable to /proc and is used to control who can access
the information in /proc/[pid] directories. The option can have one of the following
values:
0: Everybody may access all /proc/[pid] directories.
1: Users may not access files and subdirectories inside any /proc/[pid] directories
   but their own. The /proc/[pid] directories themselves remain visible.
2: Same as for mode 1, but in addition the /proc/[pid] directories belonging to other
   users become invisible.</xccdf-1.2:description>
              <xccdf-1.2:value selector="0">0</xccdf-1.2:value>
              <xccdf-1.2:value selector="noaccess">noaccess</xccdf-1.2:value>
              <xccdf-1.2:value selector="invisible">invisible</xccdf-1.2:value>
              <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
              <xccdf-1.2:value selector="2">2</xccdf-1.2:value>
              <xccdf-1.2:value>2</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_removable_partition" type="string">
              <xccdf-1.2:title>Removable Partition</xccdf-1.2:title>
              <xccdf-1.2:description>This value is used by the checks mount_option_nodev_removable_partitions, mount_option_nodev_removable_partitions,
and mount_option_nodev_removable_partitions to ensure that the correct mount options are set on partitions mounted from
removable media such as CD-ROMs, USB keys, and floppy drives. This value should be modified to reflect any removable
partitions that are required on the local system.</xccdf-1.2:description>
              <xccdf-1.2:value selector="dev_cdrom">/dev/cdrom</xccdf-1.2:value>
              <xccdf-1.2:value>/dev/cdrom</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_boot_efi_nosuid" selected="false" severity="medium">
              <xccdf-1.2:title>Add nosuid Option to /boot/efi</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nosuid</html:code> mount option can be used to prevent
execution of setuid programs in <html:code>/boot/efi</html:code>. The SUID and SGID permissions
should not be required on the boot partition.
Add the <html:code>nosuid</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/boot/efi</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6.1(iv)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010572</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244530r1155403_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The presence of SUID and SGID executables should be tightly controlled. Users
should not be able to execute SUID or SGID binaries from boot partitions.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_boot-efi"/>
              <xccdf-1.2:fix id="mount_option_boot_efi_nosuid" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/boot/efi" &gt; /dev/null || findmnt --fstab "/boot/efi" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /boot/efi has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/boot/efi")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/boot/efi' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /boot/efi in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /boot/efi)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nosuid)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /boot/efi  defaults,${previous_mount_opts}nosuid 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nosuid"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nosuid|" /etc/fstab
    fi


    if mkdir -p "/boot/efi"; then
        if mountpoint -q "/boot/efi"; then
            mount -o remount --target "/boot/efi"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_boot_efi_nosuid" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010572
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_efi_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /boot/efi: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/boot/efi'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - DISA-STIG-RHEL-08-010572
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_efi_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /boot/efi: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-010572
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_efi_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /boot/efi: If /boot/efi not mounted, craft mount_info
    manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /boot/efi
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-010572
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_efi_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /boot/efi: Make sure nosuid option is part of the to
    /boot/efi options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nosuid''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "nosuid" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-010572
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_efi_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /boot/efi: Ensure /boot/efi is mounted with nosuid option'
  ansible.posix.mount:
    path: /boot/efi
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/boot/efi" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - DISA-STIG-RHEL-08-010572
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-6.1(iv)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_efi_nosuid
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_boot_efi_nosuid:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_boot_efi_nosuid_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_boot_noauto" selected="false" severity="medium">
              <xccdf-1.2:title>Add noauto Option to /boot</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>noauto</html:code> mount option is used to prevent automatic mounting of th
<html:code>/boot</html:code> partition. 
Add the <html:code>noauto</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/boot</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Although contents of the <html:code>/boot</html:code> partition should not be needed
during normal system operation, they might need to be accessible during
system maintenance and upgrades. Make sure that applying this rule will
not break upgrade or maintenance processes affecting the system.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>The <html:code>/boot</html:code> partition contains the kernel and the bootloader. Access
to the partition after the boot process finishes should not be needed. Files
contained within this partition can be analysed and gained information can
be used for exploit creation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="mount_option_boot_noauto" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); then

function perform_remediation {

    
        # the mount point /boot has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/boot")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/boot' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /boot in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /boot)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|noauto)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /boot  defaults,${previous_mount_opts}noauto 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "noauto"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,noauto|" /etc/fstab
    fi


    if mkdir -p "/boot"; then
        if mountpoint -q "/boot"; then
            mount -o remount --target "/boot"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_boot_noauto" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_noauto
  - no_reboot_needed

- name: 'Add noauto Option to /boot: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/boot'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_noauto
  - no_reboot_needed

- name: 'Add noauto Option to /boot: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_noauto
  - no_reboot_needed

- name: 'Add noauto Option to /boot: If /boot not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /boot
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_noauto
  - no_reboot_needed

- name: 'Add noauto Option to /boot: Make sure noauto option is part of the to /boot
    options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''noauto''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined and "noauto" not in (mount_info.options | default(''))
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_noauto
  - no_reboot_needed

- name: 'Add noauto Option to /boot: Ensure /boot is mounted with noauto option'
  ansible.posix.mount:
    path: /boot
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_noauto
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_boot_noauto" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /boot --mountoptions="noauto"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_boot_noauto:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_boot_noauto_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_boot_nodev" selected="false" severity="medium">
              <xccdf-1.2:title>Add nodev Option to /boot</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nodev</html:code> mount option can be used to prevent device files from
being created in <html:code>/boot</html:code>.
Legitimate character and block devices should exist only in
the <html:code>/dev</html:code> directory on the root partition or within chroot
jails built for system services.
Add the <html:code>nodev</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/boot</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The only legitimate location for device files is the <html:code>/dev</html:code> directory
located on the root partition. The only exception to this is chroot jails.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="mount_option_boot_nodev" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); then

function perform_remediation {

    
        # the mount point /boot has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/boot")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/boot' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /boot in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /boot)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nodev)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /boot  defaults,${previous_mount_opts}nodev 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nodev"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nodev|" /etc/fstab
    fi


    if mkdir -p "/boot"; then
        if mountpoint -q "/boot"; then
            mount -o remount --target "/boot"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_boot_nodev" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /boot: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/boot'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /boot: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /boot: If /boot not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /boot
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /boot: Make sure nodev option is part of the to /boot
    options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nodev''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined and "nodev" not in (mount_info.options | default(''))
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /boot: Ensure /boot is mounted with nodev option'
  ansible.posix.mount:
    path: /boot
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_nodev
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_boot_nodev" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /boot --mountoptions="nodev"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_boot_nodev:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_boot_nodev_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_boot_noexec" selected="false" severity="medium">
              <xccdf-1.2:title>Add noexec Option to /boot</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>noexec</html:code> mount option can be used to prevent binaries from being
executed out of <html:code>/boot</html:code>.
Add the <html:code>noexec</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/boot</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>/boot</html:code> partition contains the kernel and the bootloader. No
binaries should be executed from this partition after the booting process
finishes.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="mount_option_boot_noexec" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); then

function perform_remediation {

    
        # the mount point /boot has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/boot")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/boot' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /boot in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /boot)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|noexec)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /boot  defaults,${previous_mount_opts}noexec 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "noexec"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,noexec|" /etc/fstab
    fi


    if mkdir -p "/boot"; then
        if mountpoint -q "/boot"; then
            mount -o remount --target "/boot"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_boot_noexec" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /boot: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/boot'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /boot: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /boot: If /boot not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /boot
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /boot: Make sure noexec option is part of the to /boot
    options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''noexec''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined and "noexec" not in (mount_info.options | default(''))
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /boot: Ensure /boot is mounted with noexec option'
  ansible.posix.mount:
    path: /boot
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_noexec
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_boot_noexec" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /boot --mountoptions="noexec"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_boot_noexec:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_boot_noexec_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_boot_nosuid" selected="false" severity="medium">
              <xccdf-1.2:title>Add nosuid Option to /boot</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nosuid</html:code> mount option can be used to prevent
execution of setuid programs in <html:code>/boot</html:code>. The SUID and SGID permissions
should not be required on the boot partition.
Add the <html:code>nosuid</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/boot</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010571</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230300r1017110_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The presence of SUID and SGID executables should be tightly controlled. Users
should not be able to execute SUID or SGID binaries from boot partitions.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="mount_option_boot_nosuid" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); then

function perform_remediation {

    
        # the mount point /boot has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/boot")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/boot' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /boot in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /boot)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nosuid)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /boot  defaults,${previous_mount_opts}nosuid 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nosuid"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nosuid|" /etc/fstab
    fi


    if mkdir -p "/boot"; then
        if mountpoint -q "/boot"; then
            mount -o remount --target "/boot"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_boot_nosuid" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010571
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /boot: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/boot'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - DISA-STIG-RHEL-08-010571
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /boot: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-010571
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /boot: If /boot not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /boot
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-010571
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /boot: Make sure nosuid option is part of the to /boot
    options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nosuid''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined and "nosuid" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-010571
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /boot: Ensure /boot is mounted with nosuid option'
  ansible.posix.mount:
    path: /boot
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - DISA-STIG-RHEL-08-010571
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_boot_nosuid
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_boot_nosuid" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /boot --mountoptions="nosuid"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_boot_nosuid:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_boot_nosuid_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nodev" selected="false" severity="medium">
              <xccdf-1.2:title>Add nodev Option to /dev/shm</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nodev</html:code> mount option can be used to prevent creation of device
files in <html:code>/dev/shm</html:code>. Legitimate character and block devices should
not exist within temporary directories like <html:code>/dev/shm</html:code>.
Add the <html:code>nodev</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/dev/shm</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040120</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230508r958804_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The only legitimate location for device files is the <html:code>/dev</html:code> directory
located on the root partition. The only exception to this is chroot jails.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="mount_option_dev_shm_nodev" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); then

function perform_remediation {

    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /dev/shm)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nodev)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type="tmpfs"
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo "tmpfs /dev/shm tmpfs defaults,${previous_mount_opts}nodev 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nodev"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nodev|" /etc/fstab
    fi


    if mkdir -p "/dev/shm"; then
        if mountpoint -q "/dev/shm"; then
            mount -o remount --target "/dev/shm"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_dev_shm_nodev" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040120
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /dev/shm: Check information associated to mountpoint'
  ansible.builtin.command: findmnt  '/dev/shm'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - DISA-STIG-RHEL-08-040120
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /dev/shm: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-040120
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /dev/shm: If /dev/shm not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /dev/shm
    - tmpfs
    - tmpfs
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - ("" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040120
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /dev/shm: Make sure nodev option is part of the to /dev/shm
    options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nodev''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined and "nodev" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-040120
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /dev/shm: Ensure /dev/shm is mounted with nodev option'
  ansible.posix.mount:
    path: /dev/shm
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("" |
    length == 0)
  tags:
  - DISA-STIG-RHEL-08-040120
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_nodev
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_dev_shm_nodev:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_dev_shm_nodev_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_noexec" selected="false" severity="medium">
              <xccdf-1.2:title>Add noexec Option to /dev/shm</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>noexec</html:code> mount option can be used to prevent binaries
from being executed out of <html:code>/dev/shm</html:code>.
It can be dangerous to allow the execution of binaries
from world-writable temporary storage directories such as <html:code>/dev/shm</html:code>.
Add the <html:code>noexec</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/dev/shm</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040122</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230510r958804_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Allowing users to execute binaries from world-writable directories
such as <html:code>/dev/shm</html:code> can expose the system to potential compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="mount_option_dev_shm_noexec" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); then

function perform_remediation {

    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /dev/shm)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|noexec)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type="tmpfs"
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo "tmpfs /dev/shm tmpfs defaults,${previous_mount_opts}noexec 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "noexec"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,noexec|" /etc/fstab
    fi


    if mkdir -p "/dev/shm"; then
        if mountpoint -q "/dev/shm"; then
            mount -o remount --target "/dev/shm"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_dev_shm_noexec" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040122
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /dev/shm: Check information associated to mountpoint'
  ansible.builtin.command: findmnt  '/dev/shm'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - DISA-STIG-RHEL-08-040122
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /dev/shm: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-040122
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /dev/shm: If /dev/shm not mounted, craft mount_info
    manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /dev/shm
    - tmpfs
    - tmpfs
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - ("" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040122
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /dev/shm: Make sure noexec option is part of the to
    /dev/shm options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''noexec''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined and "noexec" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-040122
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /dev/shm: Ensure /dev/shm is mounted with noexec option'
  ansible.posix.mount:
    path: /dev/shm
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("" |
    length == 0)
  tags:
  - DISA-STIG-RHEL-08-040122
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_noexec
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_dev_shm_noexec:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_dev_shm_noexec_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nosuid" selected="false" severity="medium">
              <xccdf-1.2:title>Add nosuid Option to /dev/shm</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nosuid</html:code> mount option can be used to prevent execution
of setuid programs in <html:code>/dev/shm</html:code>.  The SUID and SGID permissions should not
be required in these world-writable directories.
Add the <html:code>nosuid</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/dev/shm</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040121</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230509r958804_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The presence of SUID and SGID executables should be tightly controlled. Users
should not be able to execute SUID or SGID binaries from temporary storage partitions.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="mount_option_dev_shm_nosuid" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); then

function perform_remediation {

    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /dev/shm)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nosuid)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type="tmpfs"
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo "tmpfs /dev/shm tmpfs defaults,${previous_mount_opts}nosuid 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nosuid"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nosuid|" /etc/fstab
    fi


    if mkdir -p "/dev/shm"; then
        if mountpoint -q "/dev/shm"; then
            mount -o remount --target "/dev/shm"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_dev_shm_nosuid" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040121
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /dev/shm: Check information associated to mountpoint'
  ansible.builtin.command: findmnt  '/dev/shm'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - DISA-STIG-RHEL-08-040121
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /dev/shm: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-040121
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /dev/shm: If /dev/shm not mounted, craft mount_info
    manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /dev/shm
    - tmpfs
    - tmpfs
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - ("" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040121
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /dev/shm: Make sure nosuid option is part of the to
    /dev/shm options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nosuid''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined and "nosuid" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-040121
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /dev/shm: Ensure /dev/shm is mounted with nosuid option'
  ansible.posix.mount:
    path: /dev/shm
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("" |
    length == 0)
  tags:
  - DISA-STIG-RHEL-08-040121
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_dev_shm_nosuid
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_dev_shm_nosuid:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_dev_shm_nosuid_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_home_grpquota" selected="false" severity="medium">
              <xccdf-1.2:title>Add grpquota Option to /home</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>grpquota</html:code> mount option allows for the filesystem to have disk quotas configured.
Add the <html:code>grpquota</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/home</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">The quota options for XFS file systems can only be activated when mounting the partition.
It is not possible to enable them by remounting an already mounted partition. Therefore,
if the desired options were not defined before mounting the partition, dismount and mount
it again to apply the quota options.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>To ensure the availability of disk space on /home, it is important to limit the impact a
single user or group can cause for other users (or the wider system) by intentionally or
accidentally filling up the partition. Quotas can also be applied to inodes for filesystems
where inode exhaustion is a concern.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_home"/>
              <xccdf-1.2:fix id="mount_option_home_grpquota" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/home" &gt; /dev/null || findmnt --fstab "/home" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /home has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/home")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/home' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /home in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /home)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|grpquota)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /home  defaults,${previous_mount_opts}grpquota 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "grpquota"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,grpquota|" /etc/fstab
    fi


    if mkdir -p "/home"; then
        if mountpoint -q "/home"; then
            mount -o remount --target "/home"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_home_grpquota" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_grpquota
  - no_reboot_needed

- name: 'Add grpquota Option to /home: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/home'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_grpquota
  - no_reboot_needed

- name: 'Add grpquota Option to /home: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_grpquota
  - no_reboot_needed

- name: 'Add grpquota Option to /home: If /home not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /home
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_grpquota
  - no_reboot_needed

- name: 'Add grpquota Option to /home: Make sure grpquota option is part of the to
    /home options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''grpquota''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "grpquota" not in (mount_info.options | default(''))
  tags:
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_grpquota
  - no_reboot_needed

- name: 'Add grpquota Option to /home: Ensure /home is mounted with grpquota option'
  ansible.posix.mount:
    path: /home
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_grpquota
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_home_grpquota" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /home --mountoptions="grpquota"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_home_grpquota:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_home_grpquota_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_home_nodev" selected="false" severity="unknown">
              <xccdf-1.2:title>Add nodev Option to /home</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nodev</html:code> mount option can be used to prevent device files from
being created in <html:code>/home</html:code>.
Legitimate character and block devices should exist only in
the <html:code>/dev</html:code> directory on the root partition or within chroot
jails built for system services.
Add the <html:code>nodev</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/home</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.3.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The only legitimate location for device files is the <html:code>/dev</html:code> directory
located on the root partition. The only exception to this is chroot jails.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_home"/>
              <xccdf-1.2:fix id="mount_option_home_nodev" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/home" &gt; /dev/null || findmnt --fstab "/home" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /home has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/home")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/home' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /home in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /home)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nodev)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /home  defaults,${previous_mount_opts}nodev 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nodev"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nodev|" /etc/fstab
    fi


    if mkdir -p "/home"; then
        if mountpoint -q "/home"; then
            mount -o remount --target "/home"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_home_nodev" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - mount_option_home_nodev
  - no_reboot_needed
  - unknown_severity

- name: 'Add nodev Option to /home: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/home'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - mount_option_home_nodev
  - no_reboot_needed
  - unknown_severity

- name: 'Add nodev Option to /home: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - mount_option_home_nodev
  - no_reboot_needed
  - unknown_severity

- name: 'Add nodev Option to /home: If /home not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /home
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - mount_option_home_nodev
  - no_reboot_needed
  - unknown_severity

- name: 'Add nodev Option to /home: Make sure nodev option is part of the to /home
    options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nodev''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "nodev" not in (mount_info.options | default(''))
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - mount_option_home_nodev
  - no_reboot_needed
  - unknown_severity

- name: 'Add nodev Option to /home: Ensure /home is mounted with nodev option'
  ansible.posix.mount:
    path: /home
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - mount_option_home_nodev
  - no_reboot_needed
  - unknown_severity
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_home_nodev" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /home --mountoptions="nodev"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_home_nodev:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_home_nodev_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_home_noexec" selected="false" severity="medium">
              <xccdf-1.2:title>Add noexec Option to /home</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>noexec</html:code> mount option can be used to prevent binaries from being
executed out of <html:code>/home</html:code>.
Add the <html:code>noexec</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/home</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010590</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230302r1017112_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>/home</html:code> directory contains data of individual users. Binaries in
this directory should not be considered as trusted and users should not be
able to execute them.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="mount_option_home_noexec" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); then

function perform_remediation {

    
        # the mount point /home has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/home")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/home' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /home in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /home)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|noexec)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /home  defaults,${previous_mount_opts}noexec 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "noexec"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,noexec|" /etc/fstab
    fi


    if mkdir -p "/home"; then
        if mountpoint -q "/home"; then
            mount -o remount --target "/home"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_home_noexec" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010590
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /home: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/home'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - DISA-STIG-RHEL-08-010590
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /home: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-010590
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /home: If /home not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /home
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-010590
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /home: Make sure noexec option is part of the to /home
    options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''noexec''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined and "noexec" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-010590
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /home: Ensure /home is mounted with noexec option'
  ansible.posix.mount:
    path: /home
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - DISA-STIG-RHEL-08-010590
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_noexec
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_home_noexec" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /home --mountoptions="noexec"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_home_noexec:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_home_noexec_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_home_nosuid" selected="false" severity="medium">
              <xccdf-1.2:title>Add nosuid Option to /home</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nosuid</html:code> mount option can be used to prevent
execution of setuid programs in <html:code>/home</html:code>. The SUID and SGID permissions
should not be required in these user data directories.
Add the <html:code>nosuid</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/home</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010570</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230299r1017109_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The presence of SUID and SGID executables should be tightly controlled. Users
should not be able to execute SUID or SGID binaries from user home directory partitions.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_home"/>
              <xccdf-1.2:fix id="mount_option_home_nosuid" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/home" &gt; /dev/null || findmnt --fstab "/home" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /home has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/home")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/home' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /home in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /home)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nosuid)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /home  defaults,${previous_mount_opts}nosuid 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nosuid"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nosuid|" /etc/fstab
    fi


    if mkdir -p "/home"; then
        if mountpoint -q "/home"; then
            mount -o remount --target "/home"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_home_nosuid" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010570
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /home: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/home'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - DISA-STIG-RHEL-08-010570
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /home: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-010570
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /home: If /home not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /home
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-010570
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /home: Make sure nosuid option is part of the to /home
    options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nosuid''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "nosuid" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-010570
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /home: Ensure /home is mounted with nosuid option'
  ansible.posix.mount:
    path: /home
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - DISA-STIG-RHEL-08-010570
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_nosuid
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_home_nosuid" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /home --mountoptions="nosuid"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_home_nosuid:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_home_nosuid_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_home_usrquota" selected="false" severity="medium">
              <xccdf-1.2:title>Add usrquota Option to /home</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>usrquota</html:code> mount option allows for the filesystem to have disk quotas configured.
Add the <html:code>usrquota</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/home</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">The quota options for XFS file systems can only be activated when mounting the partition.
It is not possible to enable them by remounting an already mounted partition. Therefore,
if the desired options were not defined before mounting the partition, dismount and mount
it again to apply the quota options.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>To ensure the availability of disk space on /home, it is important to limit the impact a
single user or group can cause for other users (or the wider system) by intentionally or
accidentally filling up the partition. Quotas can also be applied to inodes for filesystems
where inode exhaustion is a concern.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_home"/>
              <xccdf-1.2:fix id="mount_option_home_usrquota" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/home" &gt; /dev/null || findmnt --fstab "/home" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /home has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/home")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/home' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /home in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /home)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|usrquota)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /home  defaults,${previous_mount_opts}usrquota 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "usrquota"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,usrquota|" /etc/fstab
    fi


    if mkdir -p "/home"; then
        if mountpoint -q "/home"; then
            mount -o remount --target "/home"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_home_usrquota" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_usrquota
  - no_reboot_needed

- name: 'Add usrquota Option to /home: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/home'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_usrquota
  - no_reboot_needed

- name: 'Add usrquota Option to /home: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_usrquota
  - no_reboot_needed

- name: 'Add usrquota Option to /home: If /home not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /home
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_usrquota
  - no_reboot_needed

- name: 'Add usrquota Option to /home: Make sure usrquota option is part of the to
    /home options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''usrquota''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "usrquota" not in (mount_info.options | default(''))
  tags:
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_usrquota
  - no_reboot_needed

- name: 'Add usrquota Option to /home: Ensure /home is mounted with usrquota option'
  ansible.posix.mount:
    path: /home
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/home" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - NIST-800-53-CM-6(b)
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_home_usrquota
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_home_usrquota" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /home --mountoptions="usrquota"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_home_usrquota:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_home_usrquota_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_nodev_nonroot_local_partitions" selected="false" severity="medium">
              <xccdf-1.2:title>Add nodev Option to Non-Root Local Partitions</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nodev</html:code> mount option prevents files from being interpreted as
character or block devices. Legitimate character and block devices should
exist only in the <html:code>/dev</html:code> directory on the root partition or within
chroot jails built for system services.
Add the <html:code>nodev</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of

    any non-root local partitions.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule checks only local partitions, identified as those backed by
a device node in <html:code>/dev</html:code>. Network file systems such as NFS, CIFS,
GlusterFS and others are excluded because they do not expose local
device nodes. The <html:code>/boot</html:code> and <html:code>/efi</html:code> partitions are
excluded because they are special partitions usually handled by a
systemd mount unit, and enforcing <html:code>nodev</html:code> on them during
operating system installation causes issues.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010580</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230301r1155405_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>nodev</html:code> mount option prevents files from being
interpreted as character or block devices. The only legitimate location
for device files is the <html:code>/dev</html:code> directory located on the root partition.
The only exception to this is chroot jails, for which it is not advised
to set <html:code>nodev</html:code> on these filesystems.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="mount_option_nodev_nonroot_local_partitions" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); then

MOUNT_OPTION="nodev"
# Create array of local non-root partitions
readarray -t partitions_records &lt; &lt;(findmnt --mtab --raw --evaluate | grep "^/\w" | grep -v "^/proc" | grep "\s/dev/\w")

# Create array of polyinstantiated directories, in case one of them is found in mtab
readarray -t polyinstantiated_dirs &lt; \
    &lt;(grep -oP "^\s*[^#\s]+\s+\S+" /etc/security/namespace.conf | grep -oP "(?&lt;=\s)\S+?(?=/?\$)")

# Define excluded non-local file systems
excluded_fstypes=(
    afs
    autofs
    ceph
    cifs
    smb3
    smbfs
    sshfs
    ncpfs
    ncp
    nfs
    nfs4
    gfs
    gfs2
    glusterfs
    gpfs
    pvfs2
    ocfs2
    lustre
    davfs
    fuse.sshfs
)

for partition_record in "${partitions_records[@]}"; do
    # Get all important information for fstab
    mount_point="$(echo "${partition_record}" | cut -d " " -f1)"
    device="$(echo "${partition_record}" | cut -d " " -f2)"
    device_type="$(echo "${partition_record}" | cut -d " " -f3)"

    # Skip /boot and /efi partitions
    if [[ "$mount_point" =~ ^/(boot|efi) ]]; then
        continue
    fi

    # Skip polyinstantiated directories
    if printf '%s\0' "${polyinstantiated_dirs[@]}" | grep -qxzF "$mount_point"; then
        continue
    fi

    # Skip any non-local filesystem
    for excluded_fstype in "${excluded_fstypes[@]}"; do
        if [[ "$device_type" == "$excluded_fstype" ]]; then
            # jump out of both loops and move to next partition_record
            continue 2
        fi
    done

    # If we reach here, it's a local, non-root partition that isn't excluded.
    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" $mount_point)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|$MOUNT_OPTION)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type="$device_type"
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo "$device $mount_point $device_type defaults,${previous_mount_opts}$MOUNT_OPTION 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "$MOUNT_OPTION"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,$MOUNT_OPTION|" /etc/fstab
    fi
    if mkdir -p "$mount_point"; then
        if mountpoint -q "$mount_point"; then
            mount -o remount --target "$mount_point"
        fi
    fi
done

# Remediate unmounted /etc/fstab entries, excluding /boot and /efi partitions
sed -i -E '/nodev/! { /^\s*(\/dev\/\S+|UUID=\S+)\s+\/(boot|efi)/! s;^\s*(/dev/\S+|UUID=\S+)\s+(/\w\S*)\s+(\S+)\s+(\S+)(.*)$;\1 \2 \3 \4,nodev \5; }' /etc/fstab

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_nodev_nonroot_local_partitions" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010580
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_nodev_nonroot_local_partitions
  - no_reboot_needed

- name: 'Add nodev Option to Non-Root Local Partitions: Refresh facts'
  ansible.builtin.setup:
    gather_subset: mounts
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - DISA-STIG-RHEL-08-010580
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_nodev_nonroot_local_partitions
  - no_reboot_needed

- name: 'Add nodev Option to Non-Root Local Partitions: Define excluded (non-local)
    file systems'
  ansible.builtin.set_fact:
    excluded_fstypes:
    - afs
    - autofs
    - ceph
    - cifs
    - smb3
    - smbfs
    - sshfs
    - ncpfs
    - ncp
    - nfs
    - nfs4
    - gfs
    - gfs2
    - glusterfs
    - gpfs
    - pvfs2
    - ocfs2
    - lustre
    - davfs
    - fuse.sshfs
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - DISA-STIG-RHEL-08-010580
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_nodev_nonroot_local_partitions
  - no_reboot_needed

- name: 'Add nodev Option to Non-Root Local Partitions: Ensure non-root local partitions
    are mounted with nodev option'
  ansible.posix.mount:
    path: '{{ item.mount }}'
    src: '{{ item.device }}'
    opts: '{{ item.options }},nodev'
    state: mounted
    fstype: '{{ item.fstype }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - item.mount is match('/\w')
  - item.mount is not match('/(boot|efi)')
  - item.options is not search('nodev')
  - item.fstype not in excluded_fstypes
  - (not accounts_polyinstantiated_var_tmp | default(false)) or item.mount != '/var/tmp/tmp-inst'
  - (not accounts_polyinstantiated_tmp | default(false)) or item.mount != '/tmp/tmp-inst'
  with_items:
  - '{{ ansible_facts.mounts }}'
  tags:
  - DISA-STIG-RHEL-08-010580
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_nodev_nonroot_local_partitions
  - no_reboot_needed

- name: 'Add nodev Option to Non-Root Local Partitions: Ensure nodev option in /etc/fstab
    for non-root local partitions'
  ansible.builtin.replace:
    path: /etc/fstab
    regexp: ^\s*(?!#)(/dev/\S+|UUID=\S+)\s+(/(?!boot|efi)\w\S*)\s+(\S+)\s+(?!.*\bnodev\b)(\S+)(.*)$
    replace: \1 \2 \3 \4,nodev \5
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - DISA-STIG-RHEL-08-010580
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_nodev_nonroot_local_partitions
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_nodev_nonroot_local_partitions:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_nodev_nonroot_local_partitions_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_nodev_removable_partitions" selected="false" severity="medium">
              <xccdf-1.2:title>Add nodev Option to Removable Media Partitions</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nodev</html:code> mount option prevents files from being
interpreted as character or block devices.
Legitimate character and block devices should exist only in
the <html:code>/dev</html:code> directory on the root partition or within chroot
jails built for system services.
Add the <html:code>nodev</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of

    any removable media partitions.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010600</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230303r1017113_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The only legitimate location for device files is the <html:code>/dev</html:code> directory
located on the root partition. An exception to this is chroot jails, and it is
not advised to set <html:code>nodev</html:code> on partitions which contain their root
filesystems.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="mount_option_nodev_removable_partitions" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); then

var_removable_partition='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_removable_partition" use="legacy"/>'


device_regex="^\s*$var_removable_partition\s\+"
mount_option="nodev"

if grep -q $device_regex /etc/fstab ; then
    previous_opts=$(grep $device_regex /etc/fstab | awk '{print $4}')
    sed -i "s|\($device_regex.*$previous_opts\)|\1,$mount_option|" /etc/fstab
else
    echo "Not remediating, because there is no record of $var_removable_partition in /etc/fstab" &gt;&amp;2
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_nodev_removable_partitions" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010600
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_nodev_removable_partitions
  - no_reboot_needed
- name: XCCDF Value var_removable_partition # promote to variable
  set_fact:
    var_removable_partition: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_removable_partition" use="legacy"/>
  tags:
    - always

- name: Ensure permission nodev are set on var_removable_partition
  ansible.builtin.lineinfile:
    path: /etc/fstab
    regexp: ^\s*({{ var_removable_partition }})\s+([^\s]*)\s+([^\s]*)\s+([^\s]*)(.*)$
    backrefs: true
    line: \1 \2 \3 \4,nodev \5
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - DISA-STIG-RHEL-08-010600
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_nodev_removable_partitions
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_removable_partition:var:1" value-id="xccdf_org.ssgproject.content_value_var_removable_partition"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_nodev_removable_partitions:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_nodev_removable_partitions_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_noexec_removable_partitions" selected="false" severity="medium">
              <xccdf-1.2:title>Add noexec Option to Removable Media Partitions</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>noexec</html:code> mount option prevents the direct execution of binaries
on the mounted filesystem. Preventing the direct execution of binaries from
removable media (such as a USB key) provides a defense against malicious
software that may be present on such untrusted media.
Add the <html:code>noexec</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of

    any removable media partitions.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010610</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230304r1017114_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Allowing users to execute binaries from removable media such as USB keys exposes
the system to potential compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="mount_option_noexec_removable_partitions" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); then

var_removable_partition='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_removable_partition" use="legacy"/>'


device_regex="^\s*$var_removable_partition\s\+"
mount_option="noexec"

if grep -q $device_regex /etc/fstab ; then
    previous_opts=$(grep $device_regex /etc/fstab | awk '{print $4}')
    sed -i "s|\($device_regex.*$previous_opts\)|\1,$mount_option|" /etc/fstab
else
    echo "Not remediating, because there is no record of $var_removable_partition in /etc/fstab" &gt;&amp;2
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_noexec_removable_partitions" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010610
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_noexec_removable_partitions
  - no_reboot_needed
- name: XCCDF Value var_removable_partition # promote to variable
  set_fact:
    var_removable_partition: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_removable_partition" use="legacy"/>
  tags:
    - always

- name: Ensure permission noexec are set on var_removable_partition
  ansible.builtin.lineinfile:
    path: /etc/fstab
    regexp: ^\s*({{ var_removable_partition }})\s+([^\s]*)\s+([^\s]*)\s+([^\s]*)(.*)$
    backrefs: true
    line: \1 \2 \3 \4,noexec \5
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - DISA-STIG-RHEL-08-010610
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_noexec_removable_partitions
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_removable_partition:var:1" value-id="xccdf_org.ssgproject.content_value_var_removable_partition"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_noexec_removable_partitions:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_noexec_removable_partitions_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_nosuid_removable_partitions" selected="false" severity="medium">
              <xccdf-1.2:title>Add nosuid Option to Removable Media Partitions</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nosuid</html:code> mount option prevents set-user-identifier (SUID)
and set-group-identifier (SGID) permissions from taking effect. These permissions
allow users to execute binaries with the same permissions as the owner and group
of the file respectively. Users should not be allowed to introduce SUID and SGID
files into the system via partitions mounted from removable media.
Add the <html:code>nosuid</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of

    any removable media partitions.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010620</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230305r1017115_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The presence of SUID and SGID executables should be tightly controlled. Allowing
users to introduce SUID or SGID binaries from partitions mounted off of
removable media would allow them to introduce their own highly-privileged programs.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="mount_option_nosuid_removable_partitions" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); then

var_removable_partition='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_removable_partition" use="legacy"/>'


device_regex="^\s*$var_removable_partition\s\+"
mount_option="nosuid"

if grep -q $device_regex /etc/fstab ; then
    previous_opts=$(grep $device_regex /etc/fstab | awk '{print $4}')
    sed -i "s|\($device_regex.*$previous_opts\)|\1,$mount_option|" /etc/fstab
else
    echo "Not remediating, because there is no record of $var_removable_partition in /etc/fstab" &gt;&amp;2
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_nosuid_removable_partitions" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010620
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_nosuid_removable_partitions
  - no_reboot_needed
- name: XCCDF Value var_removable_partition # promote to variable
  set_fact:
    var_removable_partition: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_removable_partition" use="legacy"/>
  tags:
    - always

- name: Ensure permission nosuid are set on var_removable_partition
  ansible.builtin.lineinfile:
    path: /etc/fstab
    regexp: ^\s*({{ var_removable_partition }})\s+([^\s]*)\s+([^\s]*)\s+([^\s]*)(.*)$
    backrefs: true
    line: \1 \2 \3 \4,nosuid \5
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - DISA-STIG-RHEL-08-010620
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_nosuid_removable_partitions
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_removable_partition:var:1" value-id="xccdf_org.ssgproject.content_value_var_removable_partition"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_nosuid_removable_partitions:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_nosuid_removable_partitions_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_opt_nosuid" selected="false" severity="medium">
              <xccdf-1.2:title>Add nosuid Option to /opt</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nosuid</html:code> mount option can be used to prevent
execution of setuid programs in <html:code>/opt</html:code>. The SUID and SGID permissions
should not be required in this directory.
Add the <html:code>nosuid</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/opt</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The presence of SUID and SGID executables should be tightly controlled. The
<html:code>/opt</html:code> directory contains additional software packages. Users should
not be able to execute SUID or SGID binaries from this directory.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_opt"/>
              <xccdf-1.2:fix id="mount_option_opt_nosuid" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/opt" &gt; /dev/null || findmnt --fstab "/opt" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /opt has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/opt")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/opt' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /opt in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /opt)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nosuid)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /opt  defaults,${previous_mount_opts}nosuid 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nosuid"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nosuid|" /etc/fstab
    fi


    if mkdir -p "/opt"; then
        if mountpoint -q "/opt"; then
            mount -o remount --target "/opt"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_opt_nosuid" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_opt_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /opt: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/opt'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/opt" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_opt_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /opt: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/opt" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_opt_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /opt: If /opt not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /opt
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/opt" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_opt_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /opt: Make sure nosuid option is part of the to /opt
    options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nosuid''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/opt" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "nosuid" not in (mount_info.options | default(''))
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_opt_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /opt: Ensure /opt is mounted with nosuid option'
  ansible.posix.mount:
    path: /opt
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/opt" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_opt_nosuid
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_opt_nosuid" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /opt --mountoptions="nosuid"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_opt_nosuid:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_opt_nosuid_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_proc_hidepid" selected="false" severity="low">
              <xccdf-1.2:title>Add hidepid Option to /proc</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>hidepid</html:code> mount option is applicable to <html:code>/proc</html:code> and is used to
control who can access the information in <html:code>/proc/[pid]</html:code> directories.
The option can have one of the following values:
<html:pre>
0: Everybody may access all /proc/[pid] directories.
1: Users may not access files and subdirectories inside any /proc/[pid] directories
   but their own. The /proc/[pid] directories themselves remain visible.
2: Same as for mode 1, but in addition the /proc/[pid] directories belonging to other
   users become invisible.
</html:pre>
For example, if you choose the value 2:
Add the <html:code>hidepid=2</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/proc</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:warning category="functionality">Hiding the <html:code>pid</html:code> of processes may lead to problems with <html:code>PolicyKit</html:code> and <html:code>D-Bus</html:code>,
it may also convey a false sense of security.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>Users should not be able to see and access directories within /proc, which are not
related to their own processes in a system. Otherwise, sensitive information from
other users could be seem.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="mount_option_proc_hidepid" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ); then

function perform_remediation {

    


    var_mount_option_proc_hidepid='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mount_option_proc_hidepid" use="legacy"/>'

    mountoption="hidepid=$var_mount_option_proc_hidepid"
    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /proc)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|$mountoption)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type="proc"
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo "proc /proc proc defaults,${previous_mount_opts}$mountoption 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "$mountoption"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,$mountoption|" /etc/fstab
    fi


    if mkdir -p "/proc"; then
        if mountpoint -q "/proc"; then
            mount -o remount --target "/proc"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_proc_hidepid" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - low_severity
  - mount_option_proc_hidepid
  - no_reboot_needed
- name: XCCDF Value var_mount_option_proc_hidepid # promote to variable
  set_fact:
    var_mount_option_proc_hidepid: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mount_option_proc_hidepid" use="legacy"/>
  tags:
    - always

- name: 'Add hidepid Option to /proc: Check information associated to mountpoint'
  ansible.builtin.command: findmnt  '/proc'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when: ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - low_severity
  - mount_option_proc_hidepid
  - no_reboot_needed

- name: 'Add hidepid Option to /proc: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - low_severity
  - mount_option_proc_hidepid
  - no_reboot_needed

- name: 'Add hidepid Option to /proc: If /proc not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /proc
    - proc
    - proc
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - ("" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - low_severity
  - mount_option_proc_hidepid
  - no_reboot_needed

- name: 'Add hidepid Option to /proc: Make sure hidepid option is part of the to /proc
    options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''hidepid=''~var_mount_option_proc_hidepid~''''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined and "hidepid" not in (mount_info.options | default(''))
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - low_severity
  - mount_option_proc_hidepid
  - no_reboot_needed

- name: 'Add hidepid Option to /proc: Ensure /proc is mounted with hidepid option'
  ansible.posix.mount:
    path: /proc
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("" |
    length == 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - low_severity
  - mount_option_proc_hidepid
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mount_option_proc_hidepid:var:1" value-id="xccdf_org.ssgproject.content_value_var_mount_option_proc_hidepid"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_proc_hidepid:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_proc_hidepid_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_srv_nosuid" selected="false" severity="medium">
              <xccdf-1.2:title>Add nosuid Option to /srv</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nosuid</html:code> mount option can be used to prevent
execution of setuid programs in <html:code>/srv</html:code>. The SUID and SGID permissions
should not be required in this directory.
Add the <html:code>nosuid</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/srv</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The presence of SUID and SGID executables should be tightly controlled. The
<html:code>/srv</html:code> directory contains files served by various network services such as FTP. Users should
not be able to execute SUID or SGID binaries from this directory.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_srv"/>
              <xccdf-1.2:fix id="mount_option_srv_nosuid" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/srv" &gt; /dev/null || findmnt --fstab "/srv" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /srv has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/srv")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/srv' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /srv in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /srv)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nosuid)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /srv  defaults,${previous_mount_opts}nosuid 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nosuid"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nosuid|" /etc/fstab
    fi


    if mkdir -p "/srv"; then
        if mountpoint -q "/srv"; then
            mount -o remount --target "/srv"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_srv_nosuid" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_srv_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /srv: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/srv'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/srv" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_srv_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /srv: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/srv" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_srv_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /srv: If /srv not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /srv
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/srv" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_srv_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /srv: Make sure nosuid option is part of the to /srv
    options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nosuid''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/srv" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "nosuid" not in (mount_info.options | default(''))
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_srv_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /srv: Ensure /srv is mounted with nosuid option'
  ansible.posix.mount:
    path: /srv
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/srv" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_srv_nosuid
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_srv_nosuid" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /srv --mountoptions="nosuid"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_srv_nosuid:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_srv_nosuid_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_tmp_nodev" selected="false" severity="medium">
              <xccdf-1.2:title>Add nodev Option to /tmp</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nodev</html:code> mount option can be used to prevent device files from
being created in <html:code>/tmp</html:code>. Legitimate character and block devices
should not exist within temporary directories like <html:code>/tmp</html:code>.
Add the <html:code>nodev</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/tmp</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040123</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230511r958804_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The only legitimate location for device files is the <html:code>/dev</html:code> directory
located on the root partition. The only exception to this is chroot jails.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_tmp"/>
              <xccdf-1.2:fix id="mount_option_tmp_nodev" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/tmp" &gt; /dev/null || findmnt --fstab "/tmp" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /tmp has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/tmp")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/tmp' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /tmp in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /tmp)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nodev)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /tmp  defaults,${previous_mount_opts}nodev 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nodev"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nodev|" /etc/fstab
    fi


    if mkdir -p "/tmp"; then
        if mountpoint -q "/tmp"; then
            mount -o remount --target "/tmp"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_tmp_nodev" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040123
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /tmp: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/tmp'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/tmp" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - DISA-STIG-RHEL-08-040123
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /tmp: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/tmp" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-040123
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /tmp: If /tmp not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /tmp
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/tmp" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040123
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /tmp: Make sure nodev option is part of the to /tmp options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nodev''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/tmp" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "nodev" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-040123
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /tmp: Ensure /tmp is mounted with nodev option'
  ansible.posix.mount:
    path: /tmp
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/tmp" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040123
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_nodev
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_tmp_nodev" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /tmp --mountoptions="nodev"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_tmp_nodev:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_tmp_nodev_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_tmp_noexec" selected="false" severity="medium">
              <xccdf-1.2:title>Add noexec Option to /tmp</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>noexec</html:code> mount option can be used to prevent binaries
from being executed out of <html:code>/tmp</html:code>.
Add the <html:code>noexec</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/tmp</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040125</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230513r958804_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Allowing users to execute binaries from world-writable directories
such as <html:code>/tmp</html:code> should never be necessary in normal operation and
can expose the system to potential compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_tmp"/>
              <xccdf-1.2:fix id="mount_option_tmp_noexec" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/tmp" &gt; /dev/null || findmnt --fstab "/tmp" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /tmp has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/tmp")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/tmp' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /tmp in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /tmp)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|noexec)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /tmp  defaults,${previous_mount_opts}noexec 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "noexec"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,noexec|" /etc/fstab
    fi


    if mkdir -p "/tmp"; then
        if mountpoint -q "/tmp"; then
            mount -o remount --target "/tmp"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_tmp_noexec" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040125
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /tmp: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/tmp'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/tmp" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - DISA-STIG-RHEL-08-040125
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /tmp: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/tmp" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-040125
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /tmp: If /tmp not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /tmp
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/tmp" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040125
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /tmp: Make sure noexec option is part of the to /tmp
    options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''noexec''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/tmp" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "noexec" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-040125
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /tmp: Ensure /tmp is mounted with noexec option'
  ansible.posix.mount:
    path: /tmp
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/tmp" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040125
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_noexec
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_tmp_noexec" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /tmp --mountoptions="noexec"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_tmp_noexec:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_tmp_noexec_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_tmp_nosuid" selected="false" severity="medium">
              <xccdf-1.2:title>Add nosuid Option to /tmp</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nosuid</html:code> mount option can be used to prevent
execution of setuid programs in <html:code>/tmp</html:code>. The SUID and SGID permissions
should not be required in these world-writable directories.
Add the <html:code>nosuid</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/tmp</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040124</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230512r958804_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The presence of SUID and SGID executables should be tightly controlled. Users
should not be able to execute SUID or SGID binaries from temporary storage partitions.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_tmp"/>
              <xccdf-1.2:fix id="mount_option_tmp_nosuid" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/tmp" &gt; /dev/null || findmnt --fstab "/tmp" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /tmp has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/tmp")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/tmp' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /tmp in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /tmp)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nosuid)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /tmp  defaults,${previous_mount_opts}nosuid 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nosuid"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nosuid|" /etc/fstab
    fi


    if mkdir -p "/tmp"; then
        if mountpoint -q "/tmp"; then
            mount -o remount --target "/tmp"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_tmp_nosuid" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040124
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /tmp: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/tmp'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/tmp" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - DISA-STIG-RHEL-08-040124
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /tmp: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/tmp" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-040124
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /tmp: If /tmp not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /tmp
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/tmp" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040124
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /tmp: Make sure nosuid option is part of the to /tmp
    options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nosuid''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/tmp" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "nosuid" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-040124
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /tmp: Ensure /tmp is mounted with nosuid option'
  ansible.posix.mount:
    path: /tmp
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/tmp" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040124
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_tmp_nosuid
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_tmp_nosuid" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /tmp --mountoptions="nosuid"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_tmp_nosuid:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_tmp_nosuid_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nodev" selected="false" severity="medium">
              <xccdf-1.2:title>Add nodev Option to /var/log/audit</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nodev</html:code> mount option can be used to prevent device files from
being created in <html:code>/var/log/audit</html:code>.
Legitimate character and block devices should exist only in
the <html:code>/dev</html:code> directory on the root partition or within chroot
jails built for system services.
Add the <html:code>nodev</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/var/log/audit</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040129</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230517r958804_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The only legitimate location for device files is the <html:code>/dev</html:code> directory
located on the root partition. The only exception to this is chroot jails.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_var-log-audit"/>
              <xccdf-1.2:fix id="mount_option_var_log_audit_nodev" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/var/log/audit" &gt; /dev/null || findmnt --fstab "/var/log/audit" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /var/log/audit has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/var/log/audit")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/var/log/audit' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /var/log/audit in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /var/log/audit)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nodev)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /var/log/audit  defaults,${previous_mount_opts}nodev 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nodev"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nodev|" /etc/fstab
    fi


    if mkdir -p "/var/log/audit"; then
        if mountpoint -q "/var/log/audit"; then
            mount -o remount --target "/var/log/audit"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_log_audit_nodev" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040129
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var/log/audit: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/var/log/audit'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log/audit" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - DISA-STIG-RHEL-08-040129
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var/log/audit: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log/audit" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-040129
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var/log/audit: If /var/log/audit not mounted, craft
    mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /var/log/audit
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log/audit" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040129
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var/log/audit: Make sure nodev option is part of the
    to /var/log/audit options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nodev''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log/audit" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "nodev" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-040129
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var/log/audit: Ensure /var/log/audit is mounted with
    nodev option'
  ansible.posix.mount:
    path: /var/log/audit
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log/audit" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040129
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_nodev
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_log_audit_nodev" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /var/log/audit --mountoptions="nodev"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_var_log_audit_nodev:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_var_log_audit_nodev_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_noexec" selected="false" severity="medium">
              <xccdf-1.2:title>Add noexec Option to /var/log/audit</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>noexec</html:code> mount option can be used to prevent binaries
from being executed out of <html:code>/var/log/audit</html:code>.
Add the <html:code>noexec</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/var/log/audit</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040131</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230519r958804_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Allowing users to execute binaries from directories containing audit log files
such as <html:code>/var/log/audit</html:code> should never be necessary in normal operation and
can expose the system to potential compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_var-log-audit"/>
              <xccdf-1.2:fix id="mount_option_var_log_audit_noexec" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/var/log/audit" &gt; /dev/null || findmnt --fstab "/var/log/audit" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /var/log/audit has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/var/log/audit")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/var/log/audit' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /var/log/audit in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /var/log/audit)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|noexec)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /var/log/audit  defaults,${previous_mount_opts}noexec 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "noexec"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,noexec|" /etc/fstab
    fi


    if mkdir -p "/var/log/audit"; then
        if mountpoint -q "/var/log/audit"; then
            mount -o remount --target "/var/log/audit"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_log_audit_noexec" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040131
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var/log/audit: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/var/log/audit'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log/audit" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - DISA-STIG-RHEL-08-040131
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var/log/audit: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log/audit" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-040131
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var/log/audit: If /var/log/audit not mounted, craft
    mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /var/log/audit
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log/audit" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040131
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var/log/audit: Make sure noexec option is part of the
    to /var/log/audit options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''noexec''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log/audit" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "noexec" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-040131
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var/log/audit: Ensure /var/log/audit is mounted with
    noexec option'
  ansible.posix.mount:
    path: /var/log/audit
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log/audit" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040131
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_noexec
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_log_audit_noexec" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /var/log/audit --mountoptions="noexec"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_var_log_audit_noexec:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_var_log_audit_noexec_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_var_log_audit_nosuid" selected="false" severity="medium">
              <xccdf-1.2:title>Add nosuid Option to /var/log/audit</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nosuid</html:code> mount option can be used to prevent
execution of setuid programs in <html:code>/var/log/audit</html:code>. The SUID and SGID permissions
should not be required in directories containing audit log files.
Add the <html:code>nosuid</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/var/log/audit</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040130</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230518r958804_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The presence of SUID and SGID executables should be tightly controlled. Users
should not be able to execute SUID or SGID binaries from partitions
designated for audit log files.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_var-log-audit"/>
              <xccdf-1.2:fix id="mount_option_var_log_audit_nosuid" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/var/log/audit" &gt; /dev/null || findmnt --fstab "/var/log/audit" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /var/log/audit has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/var/log/audit")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/var/log/audit' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /var/log/audit in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /var/log/audit)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nosuid)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /var/log/audit  defaults,${previous_mount_opts}nosuid 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nosuid"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nosuid|" /etc/fstab
    fi


    if mkdir -p "/var/log/audit"; then
        if mountpoint -q "/var/log/audit"; then
            mount -o remount --target "/var/log/audit"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_log_audit_nosuid" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040130
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var/log/audit: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/var/log/audit'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log/audit" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - DISA-STIG-RHEL-08-040130
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var/log/audit: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log/audit" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-040130
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var/log/audit: If /var/log/audit not mounted, craft
    mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /var/log/audit
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log/audit" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040130
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var/log/audit: Make sure nosuid option is part of the
    to /var/log/audit options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nosuid''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log/audit" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "nosuid" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-040130
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var/log/audit: Ensure /var/log/audit is mounted with
    nosuid option'
  ansible.posix.mount:
    path: /var/log/audit
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log/audit" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040130
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_audit_nosuid
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_log_audit_nosuid" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /var/log/audit --mountoptions="nosuid"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_var_log_audit_nosuid:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_var_log_audit_nosuid_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_var_log_nodev" selected="false" severity="medium">
              <xccdf-1.2:title>Add nodev Option to /var/log</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nodev</html:code> mount option can be used to prevent device files from
being created in <html:code>/var/log</html:code>.
Legitimate character and block devices should exist only in
the <html:code>/dev</html:code> directory on the root partition or within chroot
jails built for system services.
Add the <html:code>nodev</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/var/log</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040126</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230514r958804_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The only legitimate location for device files is the <html:code>/dev</html:code> directory
located on the root partition. The only exception to this is chroot jails.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_var-log"/>
              <xccdf-1.2:fix id="mount_option_var_log_nodev" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/var/log" &gt; /dev/null || findmnt --fstab "/var/log" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /var/log has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/var/log")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/var/log' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /var/log in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /var/log)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nodev)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /var/log  defaults,${previous_mount_opts}nodev 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nodev"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nodev|" /etc/fstab
    fi


    if mkdir -p "/var/log"; then
        if mountpoint -q "/var/log"; then
            mount -o remount --target "/var/log"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_log_nodev" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040126
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var/log: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/var/log'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - DISA-STIG-RHEL-08-040126
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var/log: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-040126
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var/log: If /var/log not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /var/log
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040126
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var/log: Make sure nodev option is part of the to /var/log
    options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nodev''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "nodev" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-040126
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var/log: Ensure /var/log is mounted with nodev option'
  ansible.posix.mount:
    path: /var/log
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040126
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_nodev
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_log_nodev" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /var/log --mountoptions="nodev"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_var_log_nodev:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_var_log_nodev_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_var_log_noexec" selected="false" severity="medium">
              <xccdf-1.2:title>Add noexec Option to /var/log</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>noexec</html:code> mount option can be used to prevent binaries
from being executed out of <html:code>/var/log</html:code>.
Add the <html:code>noexec</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/var/log</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040128</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230516r958804_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Allowing users to execute binaries from directories containing log files
such as <html:code>/var/log</html:code> should never be necessary in normal operation and
can expose the system to potential compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_var-log"/>
              <xccdf-1.2:fix id="mount_option_var_log_noexec" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/var/log" &gt; /dev/null || findmnt --fstab "/var/log" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /var/log has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/var/log")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/var/log' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /var/log in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /var/log)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|noexec)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /var/log  defaults,${previous_mount_opts}noexec 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "noexec"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,noexec|" /etc/fstab
    fi


    if mkdir -p "/var/log"; then
        if mountpoint -q "/var/log"; then
            mount -o remount --target "/var/log"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_log_noexec" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040128
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var/log: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/var/log'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - DISA-STIG-RHEL-08-040128
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var/log: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-040128
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var/log: If /var/log not mounted, craft mount_info
    manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /var/log
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040128
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var/log: Make sure noexec option is part of the to
    /var/log options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''noexec''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "noexec" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-040128
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var/log: Ensure /var/log is mounted with noexec option'
  ansible.posix.mount:
    path: /var/log
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040128
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_noexec
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_log_noexec" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /var/log --mountoptions="noexec"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_var_log_noexec:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_var_log_noexec_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_var_log_nosuid" selected="false" severity="medium">
              <xccdf-1.2:title>Add nosuid Option to /var/log</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nosuid</html:code> mount option can be used to prevent
execution of setuid programs in <html:code>/var/log</html:code>. The SUID and SGID permissions
should not be required in directories containing log files.
Add the <html:code>nosuid</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/var/log</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040127</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230515r958804_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The presence of SUID and SGID executables should be tightly controlled. Users
should not be able to execute SUID or SGID binaries from partitions
designated for log files.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_var-log"/>
              <xccdf-1.2:fix id="mount_option_var_log_nosuid" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/var/log" &gt; /dev/null || findmnt --fstab "/var/log" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /var/log has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/var/log")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/var/log' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /var/log in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /var/log)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nosuid)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /var/log  defaults,${previous_mount_opts}nosuid 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nosuid"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nosuid|" /etc/fstab
    fi


    if mkdir -p "/var/log"; then
        if mountpoint -q "/var/log"; then
            mount -o remount --target "/var/log"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_log_nosuid" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040127
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var/log: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/var/log'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - DISA-STIG-RHEL-08-040127
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var/log: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-040127
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var/log: If /var/log not mounted, craft mount_info
    manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /var/log
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040127
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var/log: Make sure nosuid option is part of the to
    /var/log options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nosuid''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "nosuid" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-040127
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var/log: Ensure /var/log is mounted with nosuid option'
  ansible.posix.mount:
    path: /var/log
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/log" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040127
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_log_nosuid
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_log_nosuid" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /var/log --mountoptions="nosuid"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_var_log_nosuid:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_var_log_nosuid_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_var_nodev" selected="false" severity="medium">
              <xccdf-1.2:title>Add nodev Option to /var</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nodev</html:code> mount option can be used to prevent device files from
being created in <html:code>/var</html:code>.
Legitimate character and block devices should exist only in
the <html:code>/dev</html:code> directory on the root partition or within chroot
jails built for system services.
Add the <html:code>nodev</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/var</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.4.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The only legitimate location for device files is the <html:code>/dev</html:code> directory
located on the root partition. The only exception to this is chroot jails.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_var"/>
              <xccdf-1.2:fix id="mount_option_var_nodev" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/var" &gt; /dev/null || findmnt --fstab "/var" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /var has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/var")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/var' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /var in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /var)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nodev)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /var  defaults,${previous_mount_opts}nodev 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nodev"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nodev|" /etc/fstab
    fi


    if mkdir -p "/var"; then
        if mountpoint -q "/var"; then
            mount -o remount --target "/var"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_nodev" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/var'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var: If /var not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /var
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var: Make sure nodev option is part of the to /var options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nodev''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "nodev" not in (mount_info.options | default(''))
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var: Ensure /var is mounted with nodev option'
  ansible.posix.mount:
    path: /var
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-MP-7
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_nodev
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_nodev" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /var --mountoptions="nodev"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_var_nodev:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_var_nodev_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_var_noexec" selected="false" severity="medium">
              <xccdf-1.2:title>Add noexec Option to /var</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>noexec</html:code> mount option can be used to prevent binaries from being
executed out of <html:code>/var</html:code>.
Add the <html:code>noexec</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/var</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>/var</html:code> directory contains variable system data such as logs,
mails and caches. No binaries should be executed from this directory.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_var"/>
              <xccdf-1.2:fix id="mount_option_var_noexec" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/var" &gt; /dev/null || findmnt --fstab "/var" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /var has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/var")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/var' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /var in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /var)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|noexec)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /var  defaults,${previous_mount_opts}noexec 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "noexec"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,noexec|" /etc/fstab
    fi


    if mkdir -p "/var"; then
        if mountpoint -q "/var"; then
            mount -o remount --target "/var"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_noexec" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/var'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var: If /var not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /var
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var: Make sure noexec option is part of the to /var
    options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''noexec''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "noexec" not in (mount_info.options | default(''))
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var: Ensure /var is mounted with noexec option'
  ansible.posix.mount:
    path: /var
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_noexec
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_noexec" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /var --mountoptions="noexec"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_var_noexec:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_var_noexec_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_var_nosuid" selected="false" severity="medium">
              <xccdf-1.2:title>Add nosuid Option to /var</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nosuid</html:code> mount option can be used to prevent
execution of setuid programs in <html:code>/var</html:code>. The SUID and SGID permissions
should not be required for this directory.
Add the <html:code>nosuid</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/var</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.4.3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The presence of SUID and SGID executables should be tightly controlled.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_var"/>
              <xccdf-1.2:fix id="mount_option_var_nosuid" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/var" &gt; /dev/null || findmnt --fstab "/var" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /var has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/var")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/var' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /var in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /var)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nosuid)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /var  defaults,${previous_mount_opts}nosuid 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nosuid"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nosuid|" /etc/fstab
    fi


    if mkdir -p "/var"; then
        if mountpoint -q "/var"; then
            mount -o remount --target "/var"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_nosuid" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/var'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var: If /var not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /var
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var: Make sure nosuid option is part of the to /var
    options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nosuid''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "nosuid" not in (mount_info.options | default(''))
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var: Ensure /var is mounted with nosuid option'
  ansible.posix.mount:
    path: /var
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_nosuid
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_nosuid" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /var --mountoptions="nosuid"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_var_nosuid:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_var_nosuid_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_bind" selected="false" severity="unknown">
              <xccdf-1.2:title>Bind Mount /var/tmp To /tmp</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>/var/tmp</html:code> directory is a world-writable directory. Bind-mount
it to <html:code>/tmp</html:code> in order to consolidate temporary storage into one
location protected by the same techniques as <html:code>/tmp</html:code>. To do so, edit
<html:code>/etc/fstab</html:code> and add the following line:
<html:pre>/tmp     /var/tmp     none     rw,nodev,noexec,nosuid,bind     0 0</html:pre>
See the <html:code>mount(8)</html:code> man page for further explanation of bind mounting.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Having multiple locations for temporary storage is not required. Unless absolutely
necessary to meet requirements, the storage location <html:code>/var/tmp</html:code> should be bind mounted to
<html:code>/tmp</html:code> and thus share the same protections.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_var-tmp"/>
              <xccdf-1.2:fix id="mount_option_var_tmp_bind" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/var/tmp" &gt; /dev/null || findmnt --fstab "/var/tmp" &gt; /dev/null ); }; then

# Delete particular /etc/fstab's row if /var/tmp is already configured to
# represent a mount point (for some device or filesystem other than /tmp)
if grep -q -P '.*\/var\/tmp.*' /etc/fstab
then
  sed -i '/.*\/var\/tmp.*/d' /etc/fstab
fi
umount /var/tmp

# Bind-mount /var/tmp to /tmp via /etc/fstab (preserving the /etc/fstab form)
printf "%-24s%-24s%-8s%-32s%-3s\n" "/tmp" "/var/tmp" "none" "rw,nodev,noexec,nosuid,bind" "0 0" &gt;&gt; /etc/fstab

mkdir -p /var/tmp
mount -B /tmp /var/tmp

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_var_tmp_bind:def:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nodev" selected="false" severity="medium">
              <xccdf-1.2:title>Add nodev Option to /var/tmp</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nodev</html:code> mount option can be used to prevent device files from
being created in <html:code>/var/tmp</html:code>. Legitimate character and block devices
should not exist within temporary directories like <html:code>/var/tmp</html:code>.
Add the <html:code>nodev</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/var/tmp</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040132</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230520r958804_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The only legitimate location for device files is the <html:code>/dev</html:code> directory
located on the root partition. The only exception to this is chroot jails.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_var-tmp"/>
              <xccdf-1.2:fix id="mount_option_var_tmp_nodev" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/var/tmp" &gt; /dev/null || findmnt --fstab "/var/tmp" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /var/tmp has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/var/tmp")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/var/tmp' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /var/tmp in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /var/tmp)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nodev)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /var/tmp  defaults,${previous_mount_opts}nodev 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nodev"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nodev|" /etc/fstab
    fi


    if mkdir -p "/var/tmp"; then
        if mountpoint -q "/var/tmp"; then
            mount -o remount --target "/var/tmp"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_tmp_nodev" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040132
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var/tmp: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/var/tmp'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/tmp" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - DISA-STIG-RHEL-08-040132
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var/tmp: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/tmp" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-040132
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var/tmp: If /var/tmp not mounted, craft mount_info manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /var/tmp
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/tmp" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040132
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var/tmp: Make sure nodev option is part of the to /var/tmp
    options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nodev''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/tmp" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "nodev" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-040132
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_nodev
  - no_reboot_needed

- name: 'Add nodev Option to /var/tmp: Ensure /var/tmp is mounted with nodev option'
  ansible.posix.mount:
    path: /var/tmp
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/tmp" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040132
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_nodev
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_tmp_nodev" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /var/tmp --mountoptions="nodev"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_var_tmp_nodev:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_var_tmp_nodev_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_noexec" selected="false" severity="medium">
              <xccdf-1.2:title>Add noexec Option to /var/tmp</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>noexec</html:code> mount option can be used to prevent binaries
from being executed out of <html:code>/var/tmp</html:code>.
Add the <html:code>noexec</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/var/tmp</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040134</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230522r958804_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Allowing users to execute binaries from world-writable directories
such as <html:code>/var/tmp</html:code> should never be necessary in normal operation and
can expose the system to potential compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_var-tmp"/>
              <xccdf-1.2:fix id="mount_option_var_tmp_noexec" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/var/tmp" &gt; /dev/null || findmnt --fstab "/var/tmp" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /var/tmp has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/var/tmp")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/var/tmp' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /var/tmp in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /var/tmp)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|noexec)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /var/tmp  defaults,${previous_mount_opts}noexec 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "noexec"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,noexec|" /etc/fstab
    fi


    if mkdir -p "/var/tmp"; then
        if mountpoint -q "/var/tmp"; then
            mount -o remount --target "/var/tmp"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_tmp_noexec" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040134
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var/tmp: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/var/tmp'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/tmp" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - DISA-STIG-RHEL-08-040134
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var/tmp: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/tmp" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-040134
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var/tmp: If /var/tmp not mounted, craft mount_info
    manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /var/tmp
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/tmp" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040134
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var/tmp: Make sure noexec option is part of the to
    /var/tmp options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''noexec''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/tmp" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "noexec" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-040134
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_noexec
  - no_reboot_needed

- name: 'Add noexec Option to /var/tmp: Ensure /var/tmp is mounted with noexec option'
  ansible.posix.mount:
    path: /var/tmp
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/tmp" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040134
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_noexec
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_tmp_noexec" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /var/tmp --mountoptions="noexec"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_var_tmp_noexec:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_var_tmp_noexec_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nosuid" selected="false" severity="medium">
              <xccdf-1.2:title>Add nosuid Option to /var/tmp</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nosuid</html:code> mount option can be used to prevent
execution of setuid programs in <html:code>/var/tmp</html:code>. The SUID and SGID permissions
should not be required in these world-writable directories.
Add the <html:code>nosuid</html:code> option to the fourth column of
<html:code>/etc/fstab</html:code> for the line which controls mounting of
<html:code>/var/tmp</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R28</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.1.2.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040133</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230521r958804_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The presence of SUID and SGID executables should be tightly controlled. Users
should not be able to execute SUID or SGID binaries from temporary storage partitions.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#mount_var-tmp"/>
              <xccdf-1.2:fix id="mount_option_var_tmp_nosuid" reboot="false" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) ) &amp;&amp; ! ( [ -f /.dockerenv ] || [ -f /run/.containerenv ] ) ) &amp;&amp; { ( findmnt --kernel "/var/tmp" &gt; /dev/null || findmnt --fstab "/var/tmp" &gt; /dev/null ); }; then

function perform_remediation {

    
        # the mount point /var/tmp has to be defined in /etc/fstab
        # before this remediation can be executed. In case it is not defined, the
        # remediation aborts and no changes regarding the mount point are done.
        mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" "/var/tmp")"

    grep "$mount_point_match_regexp" -q /etc/fstab \
        || { echo "The mount point '/var/tmp' is not even in /etc/fstab, so we can't set up mount options" &gt;&amp;2;
                echo "Not remediating, because there is no record of /var/tmp in /etc/fstab" &gt;&amp;2; return 1; }
    


    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" /var/tmp)"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nosuid)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type=""
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " /var/tmp  defaults,${previous_mount_opts}nosuid 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nosuid"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nosuid|" /etc/fstab
    fi


    if mkdir -p "/var/tmp"; then
        if mountpoint -q "/var/tmp"; then
            mount -o remount --target "/var/tmp"
        fi
    fi
}

perform_remediation

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_tmp_nosuid" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040133
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var/tmp: Check information associated to mountpoint'
  ansible.builtin.command: findmnt --fstab '/var/tmp'
  register: device_name
  failed_when: device_name.rc &gt; 1
  changed_when: false
  check_mode: false
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/tmp" in ansible_mounts | map(attribute="mount") | list'
  tags:
  - DISA-STIG-RHEL-08-040133
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var/tmp: Create mount_info dictionary variable'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - '{{ device_name.stdout_lines[0].split() | map(''lower'') | list }}'
  - '{{ device_name.stdout_lines[1].split() | list }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/tmp" in ansible_mounts | map(attribute="mount") | list'
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-040133
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var/tmp: If /var/tmp not mounted, craft mount_info
    manually'
  set_fact:
    mount_info: '{{ mount_info|default({})|combine({item.0: item.1}) }}'
  with_together:
  - - target
    - source
    - fstype
    - options
  - - /var/tmp
    - ''
    - ''
    - defaults
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/tmp" in ansible_mounts | map(attribute="mount") | list'
  - ("--fstab" | length == 0)
  - device_name.stdout is defined and device_name.stdout_lines is defined
  - (device_name.stdout | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040133
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var/tmp: Make sure nosuid option is part of the to
    /var/tmp options'
  set_fact:
    mount_info: '{{ mount_info | combine( {''options'':''''~(mount_info.options |
      default(''''))~('','' if (mount_info.options | default('''')) else '''')~''nosuid''
      }) }}'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/tmp" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined and "nosuid" not in (mount_info.options | default(''))
  tags:
  - DISA-STIG-RHEL-08-040133
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_nosuid
  - no_reboot_needed

- name: 'Add nosuid Option to /var/tmp: Ensure /var/tmp is mounted with nosuid option'
  ansible.posix.mount:
    path: /var/tmp
    src: '{{ mount_info.source | default('''') }}'
    opts: '{{ mount_info.options | default('''') }}'
    state: mounted
    fstype: '{{ mount_info.fstype | default('''') }}'
  register: mount_result
  failed_when:
  - mount_result is failed
  - '''target is busy'' not in (mount_result.msg | default(''''))'
  - '''already mounted'' not in (mount_result.msg | default(''''))'
  when:
  - ( not ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline ) and not ( ansible_virtualization_type in
    ["docker", "lxc", "openvz", "podman", "container"] ) )
  - '"/var/tmp" in ansible_mounts | map(attribute="mount") | list'
  - mount_info is defined
  - (device_name.stdout is defined and (device_name.stdout | length &gt; 0)) or ("--fstab"
    | length == 0)
  tags:
  - DISA-STIG-RHEL-08-040133
  - configure_strategy
  - high_disruption
  - low_complexity
  - medium_severity
  - mount_option_var_tmp_nosuid
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="high" id="mount_option_var_tmp_nosuid" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
part /var/tmp --mountoptions="nosuid"
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_var_tmp_nosuid:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_var_tmp_nosuid_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_restrictions">
            <xccdf-1.2:title>Restrict Programs from Dangerous Execution Patterns</xccdf-1.2:title>
            <xccdf-1.2:description>The recommendations in this section are designed to
ensure that the system's features to protect against potentially
dangerous program execution are activated.
These protections are applied at the system initialization or
kernel level, and defend against certain types of badly-configured
or compromised programs.</xccdf-1.2:description>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_kernel_unprivileged_bpf_disabled_value" type="number">
              <xccdf-1.2:title>kernel.unprivileged_bpf_disabled</xccdf-1.2:title>
              <xccdf-1.2:description>Prevent unprivileged processes from using the bpf() syscall.</xccdf-1.2:description>
              <xccdf-1.2:value>2</xccdf-1.2:value>
              <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
              <xccdf-1.2:value selector="2">2</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kernel_module_uvcvideo_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the uvcvideo module</xccdf-1.2:title>
              <xccdf-1.2:description>If the device contains a camera it should be covered or disabled when not in use.</xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7 (a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7 (5) (b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000370-GPOS-00155</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230493r1017276_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Failing to disconnect from collaborative computing devices (i.e., cameras) can result in subsequent compromises of organizational information.
Providing easy methods to physically disconnect from such devices after a collaborative computing session helps to ensure participants actually carry out the disconnect activity without having to go through complex and tedious procedures.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_uvcvideo_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if LC_ALL=C grep -q -m 1 "^install uvcvideo" /etc/modprobe.d/uvcvideo.conf ; then
	
	sed -i 's#^install uvcvideo.*#install uvcvideo /bin/false#g' /etc/modprobe.d/uvcvideo.conf
else
	echo -e "\n# Disable per security requirements" &gt;&gt; /etc/modprobe.d/uvcvideo.conf
	echo "install uvcvideo /bin/false" &gt;&gt; /etc/modprobe.d/uvcvideo.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_uvcvideo_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040020
  - NIST-800-53-CM-7 (5) (b)
  - NIST-800-53-CM-7 (a)
  - disable_strategy
  - kernel_module_uvcvideo_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required

- name: Ensure kernel module 'uvcvideo' is disabled
  ansible.builtin.lineinfile:
    create: true
    dest: /etc/modprobe.d/uvcvideo.conf
    regexp: install\s+uvcvideo
    line: install uvcvideo /bin/false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040020
  - NIST-800-53-CM-7 (5) (b)
  - NIST-800-53-CM-7 (a)
  - disable_strategy
  - kernel_module_uvcvideo_disabled
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="kernel_module_uvcvideo_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,install%20uvcvideo%20/bin/false%0Ablacklist%20uvcvideo%0A
        mode: 0644
        path: /etc/modprobe.d/uvcvideo.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kernel_module_uvcvideo_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kernel_module_uvcvideo_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_kernel_core_pattern" selected="false" severity="medium">
              <xccdf-1.2:title>Disable storing core dumps</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>kernel.core_pattern</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w kernel.core_pattern=|/bin/false</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>kernel.core_pattern = |/bin/false</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(10)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010671</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230311r1155408_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>A core dump includes a memory image taken at the time the operating system
terminates an application. The memory image could contain sensitive data and is generally useful
only for developers trying to debug problems.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_core_pattern" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of kernel.core_pattern from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*kernel.core_pattern.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "kernel.core_pattern" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/kernel_core_pattern.conf'


#
# Set runtime for kernel.core_pattern
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w kernel.core_pattern="|/bin/false"
fi

#
# If kernel.core_pattern present in /etc/sysctl.conf, change value to "|/bin/false"
#	else, add "kernel.core_pattern = |/bin/false" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^kernel.core_pattern")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "|/bin/false"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^kernel.core_pattern\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^kernel.core_pattern\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_core_pattern" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010671
  - NIST-800-53-SC-7(10)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_core_pattern

- name: Disable storing core dumps - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010671
  - NIST-800-53-SC-7(10)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_core_pattern

- name: Disable storing core dumps - Find all files that contain kernel.core_pattern
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.core_pattern\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010671
  - NIST-800-53-SC-7(10)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_core_pattern

- name: Disable storing core dumps - Find all files that set kernel.core_pattern to
    correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.core_pattern\s*=\s*\|/bin/false$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010671
  - NIST-800-53-SC-7(10)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_core_pattern

- name: Disable storing core dumps - Comment out any occurrences of kernel.core_pattern
    from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*kernel.core_pattern
    replace: '#kernel.core_pattern'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-010671
  - NIST-800-53-SC-7(10)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_core_pattern

- name: Disable storing core dumps - Comment out any occurrences of kernel.core_pattern
    from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*kernel.core_pattern
    replace: '#kernel.core_pattern'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010671
  - NIST-800-53-SC-7(10)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_core_pattern

- name: Disable storing core dumps - Ensure sysctl kernel.core_pattern is set to |/bin/false
  ansible.posix.sysctl:
    name: kernel.core_pattern
    value: '|/bin/false'
    sysctl_file: /etc/sysctl.d/kernel_core_pattern.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010671
  - NIST-800-53-SC-7(10)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_core_pattern
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="sysctl_kernel_core_pattern" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,kernel.core_pattern%20%3D%20%7C/bin/false%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_kernel_core_pattern.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_kernel_core_pattern:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_kernel_core_pattern_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_kernel_core_uses_pid" selected="false" severity="medium">
              <xccdf-1.2:title>Configure file name of core dumps</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>kernel.core_uses_pid</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w kernel.core_uses_pid=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>kernel.core_uses_pid = 0</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The default coredump filename is <html:code>core</html:code>. By setting
<html:code>core_uses_pid</html:code> to <html:code>1</html:code>, the coredump filename becomes
<html:code>core.PID</html:code>. If <html:code>core_pattern</html:code> does not include
<html:code>%p</html:code> (default does not) and <html:code>core_uses_pid</html:code> is set, then
<html:code>.PID</html:code> will be appended to the filename.
When combined with <html:code>kernel.core_pattern = ""</html:code> configuration, it
is ensured that no core dumps are generated and also no confusing error
messages are printed by a shell.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_core_uses_pid" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of kernel.core_uses_pid from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*kernel.core_uses_pid.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "kernel.core_uses_pid" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/kernel_core_uses_pid.conf'


#
# Set runtime for kernel.core_uses_pid
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w kernel.core_uses_pid="0"
fi

#
# If kernel.core_uses_pid present in /etc/sysctl.conf, change value to "0"
#	else, add "kernel.core_uses_pid = 0" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^kernel.core_uses_pid")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "0"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^kernel.core_uses_pid\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^kernel.core_uses_pid\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_core_uses_pid" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_core_uses_pid

- name: Configure file name of core dumps - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_core_uses_pid

- name: Configure file name of core dumps - Find all files that contain kernel.core_uses_pid
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.core_uses_pid\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_core_uses_pid

- name: Configure file name of core dumps - Find all files that set kernel.core_uses_pid
    to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.core_uses_pid\s*=\s*0$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_core_uses_pid

- name: Configure file name of core dumps - Comment out any occurrences of kernel.core_uses_pid
    from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*kernel.core_uses_pid
    replace: '#kernel.core_uses_pid'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_core_uses_pid

- name: Configure file name of core dumps - Comment out any occurrences of kernel.core_uses_pid
    from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*kernel.core_uses_pid
    replace: '#kernel.core_uses_pid'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_core_uses_pid

- name: Configure file name of core dumps - Ensure sysctl kernel.core_uses_pid is
    set to 0
  ansible.posix.sysctl:
    name: kernel.core_uses_pid
    value: '0'
    sysctl_file: /etc/sysctl.d/kernel_core_uses_pid.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_core_uses_pid
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_kernel_core_uses_pid:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_kernel_core_uses_pid_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict" selected="false" severity="low">
              <xccdf-1.2:title>Restrict Access to Kernel Message Buffer</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>kernel.dmesg_restrict</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w kernel.dmesg_restrict=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>kernel.dmesg_restrict = 1</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-11(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-11(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000132-GPOS-00067</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000138-GPOS-00069</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000243-CTR-000600</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010375</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230269r1137695_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unprivileged access to the kernel syslog can expose sensitive kernel
address information.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_dmesg_restrict" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of kernel.dmesg_restrict from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*kernel.dmesg_restrict.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "kernel.dmesg_restrict" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/kernel_dmesg_restrict.conf'


#
# Set runtime for kernel.dmesg_restrict
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w kernel.dmesg_restrict="1"
fi

#
# If kernel.dmesg_restrict present in /etc/sysctl.conf, change value to "1"
#	else, add "kernel.dmesg_restrict = 1" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^kernel.dmesg_restrict")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "1"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^kernel.dmesg_restrict\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^kernel.dmesg_restrict\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_dmesg_restrict" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010375
  - NIST-800-171-3.1.5
  - NIST-800-53-SI-11(a)
  - NIST-800-53-SI-11(b)
  - disable_strategy
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
  - sysctl_kernel_dmesg_restrict

- name: Restrict Access to Kernel Message Buffer - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010375
  - NIST-800-171-3.1.5
  - NIST-800-53-SI-11(a)
  - NIST-800-53-SI-11(b)
  - disable_strategy
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
  - sysctl_kernel_dmesg_restrict

- name: Restrict Access to Kernel Message Buffer - Find all files that contain kernel.dmesg_restrict
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.dmesg_restrict\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010375
  - NIST-800-171-3.1.5
  - NIST-800-53-SI-11(a)
  - NIST-800-53-SI-11(b)
  - disable_strategy
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
  - sysctl_kernel_dmesg_restrict

- name: Restrict Access to Kernel Message Buffer - Find all files that set kernel.dmesg_restrict
    to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.dmesg_restrict\s*=\s*1$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010375
  - NIST-800-171-3.1.5
  - NIST-800-53-SI-11(a)
  - NIST-800-53-SI-11(b)
  - disable_strategy
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
  - sysctl_kernel_dmesg_restrict

- name: Restrict Access to Kernel Message Buffer - Comment out any occurrences of
    kernel.dmesg_restrict from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*kernel.dmesg_restrict
    replace: '#kernel.dmesg_restrict'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-010375
  - NIST-800-171-3.1.5
  - NIST-800-53-SI-11(a)
  - NIST-800-53-SI-11(b)
  - disable_strategy
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
  - sysctl_kernel_dmesg_restrict

- name: Restrict Access to Kernel Message Buffer - Comment out any occurrences of
    kernel.dmesg_restrict from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*kernel.dmesg_restrict
    replace: '#kernel.dmesg_restrict'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010375
  - NIST-800-171-3.1.5
  - NIST-800-53-SI-11(a)
  - NIST-800-53-SI-11(b)
  - disable_strategy
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
  - sysctl_kernel_dmesg_restrict

- name: Restrict Access to Kernel Message Buffer - Ensure sysctl kernel.dmesg_restrict
    is set to 1
  ansible.posix.sysctl:
    name: kernel.dmesg_restrict
    value: '1'
    sysctl_file: /etc/sysctl.d/kernel_dmesg_restrict.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010375
  - NIST-800-171-3.1.5
  - NIST-800-53-SI-11(a)
  - NIST-800-53-SI-11(b)
  - disable_strategy
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
  - sysctl_kernel_dmesg_restrict
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="sysctl_kernel_dmesg_restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,kernel.dmesg_restrict%3D1%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_kernel_dmesg_restrict.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_kernel_dmesg_restrict:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_kernel_dmesg_restrict_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_kernel_kexec_load_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable Kernel Image Loading</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>kernel.kexec_load_disabled</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w kernel.kexec_load_disabled=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>kernel.kexec_load_disabled = 1</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000366-GPOS-00153</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010372</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230266r1017084_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Disabling kexec_load allows greater control of the kernel memory.
It makes it impossible to load another kernel image after it has been disabled.
</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_kexec_load_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of kernel.kexec_load_disabled from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*kernel.kexec_load_disabled.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "kernel.kexec_load_disabled" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/kernel_kexec_load_disabled.conf'


#
# Set runtime for kernel.kexec_load_disabled
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w kernel.kexec_load_disabled="1"
fi

#
# If kernel.kexec_load_disabled present in /etc/sysctl.conf, change value to "1"
#	else, add "kernel.kexec_load_disabled = 1" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^kernel.kexec_load_disabled")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "1"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^kernel.kexec_load_disabled\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^kernel.kexec_load_disabled\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_kexec_load_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010372
  - NIST-800-53-CM-6
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_kexec_load_disabled

- name: Disable Kernel Image Loading - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010372
  - NIST-800-53-CM-6
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_kexec_load_disabled

- name: Disable Kernel Image Loading - Find all files that contain kernel.kexec_load_disabled
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.kexec_load_disabled\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010372
  - NIST-800-53-CM-6
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_kexec_load_disabled

- name: Disable Kernel Image Loading - Find all files that set kernel.kexec_load_disabled
    to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.kexec_load_disabled\s*=\s*1$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010372
  - NIST-800-53-CM-6
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_kexec_load_disabled

- name: Disable Kernel Image Loading - Comment out any occurrences of kernel.kexec_load_disabled
    from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*kernel.kexec_load_disabled
    replace: '#kernel.kexec_load_disabled'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-010372
  - NIST-800-53-CM-6
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_kexec_load_disabled

- name: Disable Kernel Image Loading - Comment out any occurrences of kernel.kexec_load_disabled
    from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*kernel.kexec_load_disabled
    replace: '#kernel.kexec_load_disabled'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010372
  - NIST-800-53-CM-6
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_kexec_load_disabled

- name: Disable Kernel Image Loading - Ensure sysctl kernel.kexec_load_disabled is
    set to 1
  ansible.posix.sysctl:
    name: kernel.kexec_load_disabled
    value: '1'
    sysctl_file: /etc/sysctl.d/kernel_kexec_load_disabled.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010372
  - NIST-800-53-CM-6
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_kexec_load_disabled
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="sysctl_kernel_kexec_load_disabled" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,kernel.kexec_load_disabled%3D1%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_kernel_kexec_load_disabled.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_kernel_kexec_load_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_kernel_kexec_load_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_kernel_modules_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable loading and unloading of kernel modules</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>kernel.modules_disabled</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w kernel.modules_disabled=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>kernel.modules_disabled = 1</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule doesn't come with remediation. Remediating this rule during the installation process disrupts the install and boot process.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R10</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Malicious kernel modules can have a significant impact on system security and
availability. Disabling loading of kernel modules prevents this threat. Note
that once this option has been set, it cannot be reverted without doing a
system reboot. Make sure that all needed kernel modules are loaded before
setting this option.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_kernel_modules_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_kernel_modules_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_kernel_panic_on_oops" selected="false" severity="medium">
              <xccdf-1.2:title>Kernel panic on oops</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>kernel.panic_on_oops</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w kernel.panic_on_oops=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>kernel.panic_on_oops = 1</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="functionality">The system may start to panic when it normally wouldn't. A non-catastrophic error that
would have allowed the system to continue operating will now result in a panic.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R9</xccdf-1.2:reference>
              <xccdf-1.2:rationale>An attacker trying to exploit the kernel may trigger kernel OOPSes,
panicking the system will impede them from continuing.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_panic_on_oops" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of kernel.panic_on_oops from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*kernel.panic_on_oops.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "kernel.panic_on_oops" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/kernel_panic_on_oops.conf'


#
# Set runtime for kernel.panic_on_oops
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w kernel.panic_on_oops="1"
fi

#
# If kernel.panic_on_oops present in /etc/sysctl.conf, change value to "1"
#	else, add "kernel.panic_on_oops = 1" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^kernel.panic_on_oops")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "1"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^kernel.panic_on_oops\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^kernel.panic_on_oops\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_panic_on_oops" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_panic_on_oops

- name: Kernel panic on oops - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_panic_on_oops

- name: Kernel panic on oops - Find all files that contain kernel.panic_on_oops
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.panic_on_oops\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_panic_on_oops

- name: Kernel panic on oops - Find all files that set kernel.panic_on_oops to correct
    value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.panic_on_oops\s*=\s*1$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_panic_on_oops

- name: Kernel panic on oops - Comment out any occurrences of kernel.panic_on_oops
    from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*kernel.panic_on_oops
    replace: '#kernel.panic_on_oops'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_panic_on_oops

- name: Kernel panic on oops - Comment out any occurrences of kernel.panic_on_oops
    from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*kernel.panic_on_oops
    replace: '#kernel.panic_on_oops'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_panic_on_oops

- name: Kernel panic on oops - Ensure sysctl kernel.panic_on_oops is set to 1
  ansible.posix.sysctl:
    name: kernel.panic_on_oops
    value: '1'
    sysctl_file: /etc/sysctl.d/kernel_panic_on_oops.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_panic_on_oops
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_kernel_panic_on_oops:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_kernel_panic_on_oops_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_kernel_perf_cpu_time_max_percent" selected="false" severity="medium">
              <xccdf-1.2:title>Limit CPU consumption of the Perf system</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>kernel.perf_cpu_time_max_percent</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w kernel.perf_cpu_time_max_percent=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>kernel.perf_cpu_time_max_percent = 1</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R9</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>kernel.perf_cpu_time_max_percent</html:code> configures a threshold of
maximum percentile of CPU that can be used by Perf system. Restricting usage
of <html:code>Perf</html:code> system decreases risk of potential availability problems.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_perf_cpu_time_max_percent" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of kernel.perf_cpu_time_max_percent from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*kernel.perf_cpu_time_max_percent.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "kernel.perf_cpu_time_max_percent" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/kernel_perf_cpu_time_max_percent.conf'


#
# Set runtime for kernel.perf_cpu_time_max_percent
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w kernel.perf_cpu_time_max_percent="1"
fi

#
# If kernel.perf_cpu_time_max_percent present in /etc/sysctl.conf, change value to "1"
#	else, add "kernel.perf_cpu_time_max_percent = 1" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^kernel.perf_cpu_time_max_percent")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "1"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^kernel.perf_cpu_time_max_percent\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^kernel.perf_cpu_time_max_percent\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_perf_cpu_time_max_percent" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_perf_cpu_time_max_percent

- name: Limit CPU consumption of the Perf system - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_perf_cpu_time_max_percent

- name: Limit CPU consumption of the Perf system - Find all files that contain kernel.perf_cpu_time_max_percent
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.perf_cpu_time_max_percent\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_perf_cpu_time_max_percent

- name: Limit CPU consumption of the Perf system - Find all files that set kernel.perf_cpu_time_max_percent
    to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.perf_cpu_time_max_percent\s*=\s*1$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_perf_cpu_time_max_percent

- name: Limit CPU consumption of the Perf system - Comment out any occurrences of
    kernel.perf_cpu_time_max_percent from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*kernel.perf_cpu_time_max_percent
    replace: '#kernel.perf_cpu_time_max_percent'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_perf_cpu_time_max_percent

- name: Limit CPU consumption of the Perf system - Comment out any occurrences of
    kernel.perf_cpu_time_max_percent from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*kernel.perf_cpu_time_max_percent
    replace: '#kernel.perf_cpu_time_max_percent'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_perf_cpu_time_max_percent

- name: Limit CPU consumption of the Perf system - Ensure sysctl kernel.perf_cpu_time_max_percent
    is set to 1
  ansible.posix.sysctl:
    name: kernel.perf_cpu_time_max_percent
    value: '1'
    sysctl_file: /etc/sysctl.d/kernel_perf_cpu_time_max_percent.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_perf_cpu_time_max_percent
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_kernel_perf_cpu_time_max_percent:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_kernel_perf_cpu_time_max_percent_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_kernel_perf_event_max_sample_rate" selected="false" severity="medium">
              <xccdf-1.2:title>Limit sampling frequency of the Perf system</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>kernel.perf_event_max_sample_rate</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w kernel.perf_event_max_sample_rate=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>kernel.perf_event_max_sample_rate = 1</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R9</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>kernel.perf_event_max_sample_rate</html:code> parameter configures maximum
frequency of collecting of samples for the Perf system. It is expressed in
samples per second. Restricting usage of <html:code>Perf</html:code> system decreases risk
of potential availability problems.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_perf_event_max_sample_rate" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of kernel.perf_event_max_sample_rate from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*kernel.perf_event_max_sample_rate.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "kernel.perf_event_max_sample_rate" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/kernel_perf_event_max_sample_rate.conf'


#
# Set runtime for kernel.perf_event_max_sample_rate
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w kernel.perf_event_max_sample_rate="1"
fi

#
# If kernel.perf_event_max_sample_rate present in /etc/sysctl.conf, change value to "1"
#	else, add "kernel.perf_event_max_sample_rate = 1" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^kernel.perf_event_max_sample_rate")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "1"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^kernel.perf_event_max_sample_rate\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^kernel.perf_event_max_sample_rate\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_perf_event_max_sample_rate" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_perf_event_max_sample_rate

- name: Limit sampling frequency of the Perf system - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_perf_event_max_sample_rate

- name: Limit sampling frequency of the Perf system - Find all files that contain
    kernel.perf_event_max_sample_rate
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.perf_event_max_sample_rate\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_perf_event_max_sample_rate

- name: Limit sampling frequency of the Perf system - Find all files that set kernel.perf_event_max_sample_rate
    to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.perf_event_max_sample_rate\s*=\s*1$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_perf_event_max_sample_rate

- name: Limit sampling frequency of the Perf system - Comment out any occurrences
    of kernel.perf_event_max_sample_rate from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*kernel.perf_event_max_sample_rate
    replace: '#kernel.perf_event_max_sample_rate'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_perf_event_max_sample_rate

- name: Limit sampling frequency of the Perf system - Comment out any occurrences
    of kernel.perf_event_max_sample_rate from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*kernel.perf_event_max_sample_rate
    replace: '#kernel.perf_event_max_sample_rate'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_perf_event_max_sample_rate

- name: Limit sampling frequency of the Perf system - Ensure sysctl kernel.perf_event_max_sample_rate
    is set to 1
  ansible.posix.sysctl:
    name: kernel.perf_event_max_sample_rate
    value: '1'
    sysctl_file: /etc/sysctl.d/kernel_perf_event_max_sample_rate.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_perf_event_max_sample_rate
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_kernel_perf_event_max_sample_rate:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_kernel_perf_event_max_sample_rate_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_kernel_perf_event_paranoid" selected="false" severity="low">
              <xccdf-1.2:title>Disallow kernel profiling by unprivileged users</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>kernel.perf_event_paranoid</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w kernel.perf_event_paranoid=2</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>kernel.perf_event_paranoid = 2</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000132-GPOS-00067</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000138-GPOS-00069</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000243-CTR-000600</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010376</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230270r1137695_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Kernel profiling can reveal sensitive information about kernel behaviour.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_perf_event_paranoid" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of kernel.perf_event_paranoid from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*kernel.perf_event_paranoid.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "kernel.perf_event_paranoid" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/kernel_perf_event_paranoid.conf'


#
# Set runtime for kernel.perf_event_paranoid
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w kernel.perf_event_paranoid="2"
fi

#
# If kernel.perf_event_paranoid present in /etc/sysctl.conf, change value to "2"
#	else, add "kernel.perf_event_paranoid = 2" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^kernel.perf_event_paranoid")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "2"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^kernel.perf_event_paranoid\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^kernel.perf_event_paranoid\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_perf_event_paranoid" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010376
  - NIST-800-53-AC-6
  - disable_strategy
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
  - sysctl_kernel_perf_event_paranoid

- name: Disallow kernel profiling by unprivileged users - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010376
  - NIST-800-53-AC-6
  - disable_strategy
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
  - sysctl_kernel_perf_event_paranoid

- name: Disallow kernel profiling by unprivileged users - Find all files that contain
    kernel.perf_event_paranoid
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.perf_event_paranoid\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010376
  - NIST-800-53-AC-6
  - disable_strategy
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
  - sysctl_kernel_perf_event_paranoid

- name: Disallow kernel profiling by unprivileged users - Find all files that set
    kernel.perf_event_paranoid to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.perf_event_paranoid\s*=\s*2$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010376
  - NIST-800-53-AC-6
  - disable_strategy
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
  - sysctl_kernel_perf_event_paranoid

- name: Disallow kernel profiling by unprivileged users - Comment out any occurrences
    of kernel.perf_event_paranoid from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*kernel.perf_event_paranoid
    replace: '#kernel.perf_event_paranoid'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-010376
  - NIST-800-53-AC-6
  - disable_strategy
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
  - sysctl_kernel_perf_event_paranoid

- name: Disallow kernel profiling by unprivileged users - Comment out any occurrences
    of kernel.perf_event_paranoid from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*kernel.perf_event_paranoid
    replace: '#kernel.perf_event_paranoid'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010376
  - NIST-800-53-AC-6
  - disable_strategy
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
  - sysctl_kernel_perf_event_paranoid

- name: Disallow kernel profiling by unprivileged users - Ensure sysctl kernel.perf_event_paranoid
    is set to 2
  ansible.posix.sysctl:
    name: kernel.perf_event_paranoid
    value: '2'
    sysctl_file: /etc/sysctl.d/kernel_perf_event_paranoid.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010376
  - NIST-800-53-AC-6
  - disable_strategy
  - low_complexity
  - low_severity
  - medium_disruption
  - reboot_required
  - sysctl_kernel_perf_event_paranoid
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="sysctl_kernel_perf_event_paranoid" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,kernel.perf_event_paranoid%3D2%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_kernel_perf_event_paranoid.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_kernel_perf_event_paranoid:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_kernel_perf_event_paranoid_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_kernel_pid_max" selected="false" severity="medium">
              <xccdf-1.2:title>Configure maximum number of process identifiers</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>kernel.pid_max</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w kernel.pid_max=65536</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>kernel.pid_max = 65536</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R9</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>kernel.pid_max</html:code> parameter configures upper limit on process
identifiers (PID). If this number is not high enough, it might happen that
forking of new processes is not possible, because all available PIDs are
exhausted. Increasing this number enhances availability.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_pid_max" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of kernel.pid_max from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*kernel.pid_max.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "kernel.pid_max" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/kernel_pid_max.conf'


#
# Set runtime for kernel.pid_max
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w kernel.pid_max="65536"
fi

#
# If kernel.pid_max present in /etc/sysctl.conf, change value to "65536"
#	else, add "kernel.pid_max = 65536" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^kernel.pid_max")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "65536"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^kernel.pid_max\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^kernel.pid_max\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_pid_max" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_pid_max

- name: Configure maximum number of process identifiers - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_pid_max

- name: Configure maximum number of process identifiers - Find all files that contain
    kernel.pid_max
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.pid_max\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_pid_max

- name: Configure maximum number of process identifiers - Find all files that set
    kernel.pid_max to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.pid_max\s*=\s*65536$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_pid_max

- name: Configure maximum number of process identifiers - Comment out any occurrences
    of kernel.pid_max from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*kernel.pid_max
    replace: '#kernel.pid_max'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_pid_max

- name: Configure maximum number of process identifiers - Comment out any occurrences
    of kernel.pid_max from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*kernel.pid_max
    replace: '#kernel.pid_max'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_pid_max

- name: Configure maximum number of process identifiers - Ensure sysctl kernel.pid_max
    is set to 65536
  ansible.posix.sysctl:
    name: kernel.pid_max
    value: '65536'
    sysctl_file: /etc/sysctl.d/kernel_pid_max.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_pid_max
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_kernel_pid_max:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_kernel_pid_max_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_kernel_sysrq" selected="false" severity="medium">
              <xccdf-1.2:title>Disallow magic SysRq key</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>kernel.sysrq</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w kernel.sysrq=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>kernel.sysrq = 0</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R9</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The Magic SysRq key allows sending certain commands directly to the running
kernel. It can dump various system and process information, potentially
revealing sensitive information. It can also reboot or shutdown the machine,
disturbing its availability.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_sysrq" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of kernel.sysrq from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*kernel.sysrq.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "kernel.sysrq" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/kernel_sysrq.conf'


#
# Set runtime for kernel.sysrq
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w kernel.sysrq="0"
fi

#
# If kernel.sysrq present in /etc/sysctl.conf, change value to "0"
#	else, add "kernel.sysrq = 0" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^kernel.sysrq")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "0"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^kernel.sysrq\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^kernel.sysrq\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_sysrq" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_sysrq

- name: Disallow magic SysRq key - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_sysrq

- name: Disallow magic SysRq key - Find all files that contain kernel.sysrq
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.sysrq\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_sysrq

- name: Disallow magic SysRq key - Find all files that set kernel.sysrq to correct
    value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.sysrq\s*=\s*0$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_sysrq

- name: Disallow magic SysRq key - Comment out any occurrences of kernel.sysrq from
    config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*kernel.sysrq
    replace: '#kernel.sysrq'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_sysrq

- name: Disallow magic SysRq key - Comment out any occurrences of kernel.sysrq from
    /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*kernel.sysrq
    replace: '#kernel.sysrq'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_sysrq

- name: Disallow magic SysRq key - Ensure sysctl kernel.sysrq is set to 0
  ansible.posix.sysctl:
    name: kernel.sysrq
    value: '0'
    sysctl_file: /etc/sysctl.d/kernel_sysrq.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_sysrq
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_kernel_sysrq:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_kernel_sysrq_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_kernel_unprivileged_bpf_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable Access to Network bpf() Syscall From Unprivileged Processes</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>kernel.unprivileged_bpf_disabled</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w kernel.unprivileged_bpf_disabled=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>kernel.unprivileged_bpf_disabled = 1</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(10)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000132-GPOS-00067</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040281</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230545r1017307_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Loading and accessing the packet filters programs and maps using the bpf()
syscall has the potential of revealing sensitive information about the kernel state.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_unprivileged_bpf_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of kernel.unprivileged_bpf_disabled from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*kernel.unprivileged_bpf_disabled.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "kernel.unprivileged_bpf_disabled" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/kernel_unprivileged_bpf_disabled.conf'


#
# Set runtime for kernel.unprivileged_bpf_disabled
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w kernel.unprivileged_bpf_disabled="1"
fi

#
# If kernel.unprivileged_bpf_disabled present in /etc/sysctl.conf, change value to "1"
#	else, add "kernel.unprivileged_bpf_disabled = 1" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^kernel.unprivileged_bpf_disabled")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "1"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^kernel.unprivileged_bpf_disabled\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^kernel.unprivileged_bpf_disabled\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_unprivileged_bpf_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040281
  - NIST-800-53-AC-6
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_unprivileged_bpf_disabled

- name: Disable Access to Network bpf() Syscall From Unprivileged Processes - Set
    fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040281
  - NIST-800-53-AC-6
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_unprivileged_bpf_disabled

- name: Disable Access to Network bpf() Syscall From Unprivileged Processes - Find
    all files that contain kernel.unprivileged_bpf_disabled
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.unprivileged_bpf_disabled\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040281
  - NIST-800-53-AC-6
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_unprivileged_bpf_disabled

- name: Disable Access to Network bpf() Syscall From Unprivileged Processes - Find
    all files that set kernel.unprivileged_bpf_disabled to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.unprivileged_bpf_disabled\s*=\s*1$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040281
  - NIST-800-53-AC-6
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_unprivileged_bpf_disabled

- name: Disable Access to Network bpf() Syscall From Unprivileged Processes - Comment
    out any occurrences of kernel.unprivileged_bpf_disabled from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*kernel.unprivileged_bpf_disabled
    replace: '#kernel.unprivileged_bpf_disabled'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-040281
  - NIST-800-53-AC-6
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_unprivileged_bpf_disabled

- name: Disable Access to Network bpf() Syscall From Unprivileged Processes - Comment
    out any occurrences of kernel.unprivileged_bpf_disabled from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*kernel.unprivileged_bpf_disabled
    replace: '#kernel.unprivileged_bpf_disabled'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040281
  - NIST-800-53-AC-6
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_unprivileged_bpf_disabled

- name: Disable Access to Network bpf() Syscall From Unprivileged Processes - Ensure
    sysctl kernel.unprivileged_bpf_disabled is set to 1
  ansible.posix.sysctl:
    name: kernel.unprivileged_bpf_disabled
    value: '1'
    sysctl_file: /etc/sysctl.d/kernel_unprivileged_bpf_disabled.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040281
  - NIST-800-53-AC-6
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_unprivileged_bpf_disabled
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="sysctl_kernel_unprivileged_bpf_disabled" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,kernel.unprivileged_bpf_disabled%3D1%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_kernel_unprivileged_bpf_disabled.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_kernel_unprivileged_bpf_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_kernel_unprivileged_bpf_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_kernel_yama_ptrace_scope" selected="false" severity="medium">
              <xccdf-1.2:title>Restrict usage of ptrace to descendant processes</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>kernel.yama.ptrace_scope</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w kernel.yama.ptrace_scope=1</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>kernel.yama.ptrace_scope = 1</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(10)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000132-GPOS-00067</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040282</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230546r1155413_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unrestricted usage of ptrace allows compromised binaries to run ptrace
on another processes of the user. Like this, the attacker can steal
sensitive information from the target processes (e.g. SSH sessions, web browser, ...)
without any additional assistance from the user (i.e. without resorting to phishing).
</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_yama_ptrace_scope" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of kernel.yama.ptrace_scope from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*kernel.yama.ptrace_scope.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "kernel.yama.ptrace_scope" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/kernel_yama_ptrace_scope.conf'


#
# Set runtime for kernel.yama.ptrace_scope
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w kernel.yama.ptrace_scope="1"
fi

#
# If kernel.yama.ptrace_scope present in /etc/sysctl.conf, change value to "1"
#	else, add "kernel.yama.ptrace_scope = 1" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^kernel.yama.ptrace_scope")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "1"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^kernel.yama.ptrace_scope\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^kernel.yama.ptrace_scope\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_yama_ptrace_scope" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040282
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_yama_ptrace_scope

- name: Restrict usage of ptrace to descendant processes - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040282
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_yama_ptrace_scope

- name: Restrict usage of ptrace to descendant processes - Find all files that contain
    kernel.yama.ptrace_scope
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.yama.ptrace_scope\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040282
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_yama_ptrace_scope

- name: Restrict usage of ptrace to descendant processes - Find all files that set
    kernel.yama.ptrace_scope to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.yama.ptrace_scope\s*=\s*1$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040282
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_yama_ptrace_scope

- name: Restrict usage of ptrace to descendant processes - Comment out any occurrences
    of kernel.yama.ptrace_scope from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*kernel.yama.ptrace_scope
    replace: '#kernel.yama.ptrace_scope'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-040282
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_yama_ptrace_scope

- name: Restrict usage of ptrace to descendant processes - Comment out any occurrences
    of kernel.yama.ptrace_scope from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*kernel.yama.ptrace_scope
    replace: '#kernel.yama.ptrace_scope'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040282
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_yama_ptrace_scope

- name: Restrict usage of ptrace to descendant processes - Ensure sysctl kernel.yama.ptrace_scope
    is set to 1
  ansible.posix.sysctl:
    name: kernel.yama.ptrace_scope
    value: '1'
    sysctl_file: /etc/sysctl.d/kernel_yama_ptrace_scope.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040282
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_yama_ptrace_scope
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="sysctl_kernel_yama_ptrace_scope" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,kernel.yama.ptrace_scope%3D1%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_kernel_yama_ptrace_scope.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_kernel_yama_ptrace_scope:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_kernel_yama_ptrace_scope_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_net_core_bpf_jit_harden" selected="false" severity="medium">
              <xccdf-1.2:title>Harden the operation of the BPF just-in-time compiler</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>net.core.bpf_jit_harden</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w net.core.bpf_jit_harden=2</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>net.core.bpf_jit_harden = 2</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(10)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040286</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244554r1017354_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>When hardened, the extended Berkeley Packet Filter just-in-time compiler
will randomize any kernel addresses in the BPF programs and maps,
and will not expose the JIT addresses in <html:code>/proc/kallsyms</html:code>.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_core_bpf_jit_harden" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of net.core.bpf_jit_harden from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*net.core.bpf_jit_harden.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "net.core.bpf_jit_harden" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/net_core_bpf_jit_harden.conf'


#
# Set runtime for net.core.bpf_jit_harden
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w net.core.bpf_jit_harden="2"
fi

#
# If net.core.bpf_jit_harden present in /etc/sysctl.conf, change value to "2"
#	else, add "net.core.bpf_jit_harden = 2" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^net.core.bpf_jit_harden")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "2"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^net.core.bpf_jit_harden\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^net.core.bpf_jit_harden\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_net_core_bpf_jit_harden" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040286
  - NIST-800-53-CM-6
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_core_bpf_jit_harden

- name: Harden the operation of the BPF just-in-time compiler - Set fact for sysctl
    paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040286
  - NIST-800-53-CM-6
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_core_bpf_jit_harden

- name: Harden the operation of the BPF just-in-time compiler - Find all files that
    contain net.core.bpf_jit_harden
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.core.bpf_jit_harden\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040286
  - NIST-800-53-CM-6
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_core_bpf_jit_harden

- name: Harden the operation of the BPF just-in-time compiler - Find all files that
    set net.core.bpf_jit_harden to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*net.core.bpf_jit_harden\s*=\s*2$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040286
  - NIST-800-53-CM-6
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_core_bpf_jit_harden

- name: Harden the operation of the BPF just-in-time compiler - Comment out any occurrences
    of net.core.bpf_jit_harden from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*net.core.bpf_jit_harden
    replace: '#net.core.bpf_jit_harden'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-040286
  - NIST-800-53-CM-6
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_core_bpf_jit_harden

- name: Harden the operation of the BPF just-in-time compiler - Comment out any occurrences
    of net.core.bpf_jit_harden from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*net.core.bpf_jit_harden
    replace: '#net.core.bpf_jit_harden'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040286
  - NIST-800-53-CM-6
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_core_bpf_jit_harden

- name: Harden the operation of the BPF just-in-time compiler - Ensure sysctl net.core.bpf_jit_harden
    is set to 2
  ansible.posix.sysctl:
    name: net.core.bpf_jit_harden
    value: '2'
    sysctl_file: /etc/sysctl.d/net_core_bpf_jit_harden.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040286
  - NIST-800-53-CM-6
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_net_core_bpf_jit_harden
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="sysctl_net_core_bpf_jit_harden" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,net.core.bpf_jit_harden%3D2%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_net_core_bpf_jit_harden.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_net_core_bpf_jit_harden:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_net_core_bpf_jit_harden_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_user_max_user_namespaces" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the use of user namespaces</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>user.max_user_namespaces</html:code> kernel parameter,
run the following command:
<html:pre>$ sudo sysctl -w user.max_user_namespaces=0</html:pre>

To make sure that the setting is persistent,
add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>:
<html:pre>user.max_user_namespaces = 0</html:pre>
When containers are deployed on the machine, the value should be set
to large non-zero value.</xccdf-1.2:description>
              <xccdf-1.2:warning category="functionality">Remediation of this rule might impair or prevent functionality of certain applications.
This stands especially for general container usage and for certain desktop applications.
There is an alternative rule which performs the same check but it intentionally lacks the remediation part.
If needed, you can use the rule <html:code>sysctl_user_max_user_namespaces_no_remediation</html:code>.
In that case, ensure that such use case is properly documented.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-39</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>It is detrimental for operating systems to provide, or install by default, functionality exceeding requirements or system objectives.
These unnecessary capabilities or services are often overlooked and therefore may remain unsecured.
They increase the risk to the platform by providing additional attack vectors.
User namespaces are used primarily for Linux containers. The value 0
disallows the use of user namespaces.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_user_max_user_namespaces" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of user.max_user_namespaces from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*user.max_user_namespaces.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "user.max_user_namespaces" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/user_max_user_namespaces.conf'


#
# Set runtime for user.max_user_namespaces
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w user.max_user_namespaces="0"
fi

#
# If user.max_user_namespaces present in /etc/sysctl.conf, change value to "0"
#	else, add "user.max_user_namespaces = 0" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^user.max_user_namespaces")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "0"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^user.max_user_namespaces\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^user.max_user_namespaces\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_user_max_user_namespaces" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-39
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_user_max_user_namespaces

- name: Disable the use of user namespaces - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-39
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_user_max_user_namespaces

- name: Disable the use of user namespaces - Find all files that contain user.max_user_namespaces
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*user.max_user_namespaces\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-39
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_user_max_user_namespaces

- name: Disable the use of user namespaces - Find all files that set user.max_user_namespaces
    to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*user.max_user_namespaces\s*=\s*0$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-39
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_user_max_user_namespaces

- name: Disable the use of user namespaces - Comment out any occurrences of user.max_user_namespaces
    from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*user.max_user_namespaces
    replace: '#user.max_user_namespaces'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-39
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_user_max_user_namespaces

- name: Disable the use of user namespaces - Comment out any occurrences of user.max_user_namespaces
    from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*user.max_user_namespaces
    replace: '#user.max_user_namespaces'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-39
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_user_max_user_namespaces

- name: Disable the use of user namespaces - Ensure sysctl user.max_user_namespaces
    is set to 0
  ansible.posix.sysctl:
    name: user.max_user_namespaces
    value: '0'
    sysctl_file: /etc/sysctl.d/user_max_user_namespaces.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-39
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_user_max_user_namespaces
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="sysctl_user_max_user_namespaces" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,user.max_user_namespaces%20%3D%200%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_user_max_user_namespaces.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_user_max_user_namespaces:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_user_max_user_namespaces_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_user_max_user_namespaces_no_remediation" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the use of user namespaces</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>user.max_user_namespaces</html:code> kernel parameter,
run the following command:
<html:pre>$ sudo sysctl -w user.max_user_namespaces=0</html:pre>

To make sure that the setting is persistent,
add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>:
<html:pre>user.max_user_namespaces = 0</html:pre>
When containers are deployed on the machine, the value should be set
to large non-zero value.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This configuration baseline was created to deploy the base operating system for general purpose
workloads. When the operating system is configured for certain purposes, such as to host Linux Containers,
it is expected that <html:code>user.max_user_namespaces</html:code> will be enabled.
 Note that this rule deliberately does not have remediations attached.
Use the <html:code>sysctl_user_max_user_namespaces</html:code> if you want to utilize remediation for this rule.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040284</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230548r1017310_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>It is detrimental for operating systems to provide, or install by default, functionality exceeding requirements or system objectives.
These unnecessary capabilities or services are often overlooked and therefore may remain unsecured.
They increase the risk to the platform by providing additional attack vectors.
User namespaces are used primarily for Linux containers. The value 0
disallows the use of user namespaces.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_user_max_user_namespaces_no_remediation:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_user_max_user_namespaces_no_remediation_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_vm_mmap_min_addr" selected="false" severity="medium">
              <xccdf-1.2:title>Prevent applications from mapping low portion of virtual memory</xccdf-1.2:title>
              <xccdf-1.2:description>To set the runtime status of the <html:code>vm.mmap_min_addr</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w vm.mmap_min_addr=65536</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>vm.mmap_min_addr = 65536</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R8</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>vm.mmap_min_addr</html:code> parameter specifies the minimum virtual
address that a process is allowed to mmap. Allowing a process to mmap low
portion of virtual memory can have security implications such as such as
heightened risk of kernel null pointer dereference defects.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_vm_mmap_min_addr" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of vm.mmap_min_addr from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*vm.mmap_min_addr.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "vm.mmap_min_addr" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/vm_mmap_min_addr.conf'


#
# Set runtime for vm.mmap_min_addr
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w vm.mmap_min_addr="65536"
fi

#
# If vm.mmap_min_addr present in /etc/sysctl.conf, change value to "65536"
#	else, add "vm.mmap_min_addr = 65536" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^vm.mmap_min_addr")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "65536"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^vm.mmap_min_addr\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^vm.mmap_min_addr\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_vm_mmap_min_addr" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_vm_mmap_min_addr

- name: Prevent applications from mapping low portion of virtual memory - Set fact
    for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_vm_mmap_min_addr

- name: Prevent applications from mapping low portion of virtual memory - Find all
    files that contain vm.mmap_min_addr
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*vm.mmap_min_addr\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_vm_mmap_min_addr

- name: Prevent applications from mapping low portion of virtual memory - Find all
    files that set vm.mmap_min_addr to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*vm.mmap_min_addr\s*=\s*65536$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_vm_mmap_min_addr

- name: Prevent applications from mapping low portion of virtual memory - Comment
    out any occurrences of vm.mmap_min_addr from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*vm.mmap_min_addr
    replace: '#vm.mmap_min_addr'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_vm_mmap_min_addr

- name: Prevent applications from mapping low portion of virtual memory - Comment
    out any occurrences of vm.mmap_min_addr from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*vm.mmap_min_addr
    replace: '#vm.mmap_min_addr'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_vm_mmap_min_addr

- name: Prevent applications from mapping low portion of virtual memory - Ensure sysctl
    vm.mmap_min_addr is set to 65536
  ansible.posix.sysctl:
    name: vm.mmap_min_addr
    value: '65536'
    sysctl_file: /etc/sysctl.d/vm_mmap_min_addr.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_vm_mmap_min_addr
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_vm_mmap_min_addr:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_vm_mmap_min_addr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_coredumps">
              <xccdf-1.2:title>Disable Core Dumps</xccdf-1.2:title>
              <xccdf-1.2:description>A core dump file is the memory image of an executable
program when it was terminated by the operating system due to
errant behavior. In most cases, only software developers
legitimately need to access these files. The core dump files may
also contain sensitive information, or unnecessarily occupy large
amounts of disk space.
<html:br/><html:br/>
Once a hard limit is set in <html:code>/etc/security/limits.conf</html:code>, or
to a file within the <html:code>/etc/security/limits.d/</html:code> directory, a
user cannot increase that limit within his or her own session. If access
to core dumps is required, consider restricting them to only
certain users or groups. See the <html:code>limits.conf</html:code> man page for more
information.
<html:br/><html:br/>
The core dumps of setuid programs are further protected. The
<html:code>sysctl</html:code> variable <html:code>fs.suid_dumpable</html:code> controls whether
the kernel allows core dumps from these programs at all. The default
value of 0 is recommended.</xccdf-1.2:description>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_systemd-coredump_disabled" selected="false" severity="medium">
                <xccdf-1.2:title>Disable acquiring, saving, and processing core dumps</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>systemd-coredump.socket</html:code> unit is a socket activation of
the <html:code>systemd-coredump@.service</html:code> which processes core dumps.
By masking the unit, core dump processing is disabled.</xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(10)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010672</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230312r1134877_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>A core dump includes a memory image taken at the time the operating system
terminates an application. The memory image could contain sensitive data
and is generally useful only for developers trying to debug problems.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:conflicts idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_core_pattern"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_systemd-coredump_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SOCKET_NAME="systemd-coredump.socket"
SYSTEMCTL_EXEC='/usr/bin/systemctl'

if "$SYSTEMCTL_EXEC" -q list-unit-files --type socket | grep -q "$SOCKET_NAME"; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop "$SOCKET_NAME"
    fi
    "$SYSTEMCTL_EXEC" mask "$SOCKET_NAME"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_systemd-coredump_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010672
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_systemd-coredump_disabled

- name: Disable acquiring, saving, and processing core dumps - Collect systemd Socket
    Units Present in the System
  ansible.builtin.command:
    cmd: systemctl -q list-unit-files --type socket
  register: result_systemd_unit_files
  changed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010672
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_systemd-coredump_disabled

- name: Disable acquiring, saving, and processing core dumps - Ensure systemd-coredump.socket
    is Masked
  ansible.builtin.systemd:
    name: systemd-coredump.socket
    state: stopped
    enabled: false
    masked: true
  when:
  - '"kernel" in ansible_facts.packages'
  - result_systemd_unit_files.stdout_lines is search("systemd-coredump.socket")
  tags:
  - DISA-STIG-RHEL-08-010672
  - NIST-800-53-SC-7(10)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_systemd-coredump_disabled
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_systemd-coredump_disabled:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_systemd-coredump_disabled_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_coredump_disable_backtraces" selected="false" severity="medium">
                <xccdf-1.2:title>Disable core dump backtraces</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>ProcessSizeMax</html:code> option in <html:code>[Coredump]</html:code> section
of <html:code>/etc/systemd/coredump.conf</html:code> or in a drop-in file under
<html:code>/etc/systemd/coredump.conf.d/</html:code> specifies the maximum size in bytes
of a core which will be processed. Core dumps exceeding this size may be
stored, but the backtrace will not be generated.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">If the <html:code>/etc/systemd/coredump.conf</html:code> file or a drop-in file under <html:code>/etc/systemd/coredump.conf.d/</html:code>
does not already contain the <html:code>[Coredump]</html:code> section,
the value will not be configured correctly.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.5.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010675</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230315r1134883_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>A core dump includes a memory image taken at the time the operating system
terminates an application. The memory image could contain sensitive data
and is generally useful only for developers or system operators trying to
debug problems.

Enabling core dumps on production systems is not recommended,
however there may be overriding operational requirements to enable advanced
debugging. Permitting temporary enablement of core dumps during such situations
should be reviewed through local needs and policy.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_systemd"/>
                <xccdf-1.2:conflicts idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_core_pattern"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="coredump_disable_backtraces" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q systemd; }; then

found=false

# set value in all files if they contain section or key
for f in $(echo -n "/etc/systemd/coredump.conf.d/complianceascode_hardening.conf /etc/systemd/coredump.conf.d/*.conf /etc/systemd/coredump.conf"); do
    if [ ! -e "$f" ]; then
        continue
    fi

    # find key in section and change value
    if grep -qzosP "(?m)^[[:space:]]*\[Coredump\]([^\n\[]*\n+)+?[[:space:]]*ProcessSizeMax" "$f"; then
        if ! grep -qzosP "(?m)^[[:space:]]*ProcessSizeMax[[:space:]]*=[[:space:]]*0" "$f"; then

            sed -i "/^[[:space:]]*ProcessSizeMax/s/\([[:blank:]]*=[[:blank:]]*\).*/\10/" "$f"

        fi

        found=true

    # find section and add key = value to it
    elif grep -qs "^[[:space:]]*\[Coredump\]" "$f"; then

            sed -i "/^[[:space:]]*\[Coredump\]/a ProcessSizeMax=0" "$f"

            found=true
    fi
done

# if section not in any file, append section with key = value to FIRST file in files parameter
if ! $found ; then
    file=$(echo "/etc/systemd/coredump.conf.d/complianceascode_hardening.conf /etc/systemd/coredump.conf.d/*.conf /etc/systemd/coredump.conf" | cut -f1 -d ' ')
    mkdir -p "$(dirname "$file")"

    echo -e "[Coredump]\nProcessSizeMax=0" &gt;&gt; "$file"

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="coredump_disable_backtraces" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010675
  - NIST-800-53-CM-6
  - PCI-DSS-Req-3.2
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - coredump_disable_backtraces
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable core dump backtraces - Search for a section in files
  ansible.builtin.find:
    paths: '{{item.path}}'
    patterns: '{{item.pattern}}'
    contains: ^\s*\[Coredump\]
    read_whole_file: true
    use_regex: true
  register: systemd_dropin_files_with_section
  loop:
  - path: '{{ ''/etc/systemd/coredump.conf'' | dirname }}'
    pattern: '{{ ''/etc/systemd/coredump.conf'' | basename | regex_escape }}'
  - path: /etc/systemd/coredump.conf.d
    pattern: .*\.conf
  when:
  - '"kernel" in ansible_facts.packages'
  - '"systemd" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010675
  - NIST-800-53-CM-6
  - PCI-DSS-Req-3.2
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - coredump_disable_backtraces
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable core dump backtraces - Count number of files which contain the correct
    section
  ansible.builtin.set_fact:
    count_of_systemd_dropin_files_with_section: '{{systemd_dropin_files_with_section.results
      | map(attribute=''matched'') | list | map(''int'') | sum}}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"systemd" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010675
  - NIST-800-53-CM-6
  - PCI-DSS-Req-3.2
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - coredump_disable_backtraces
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable core dump backtraces - Add missing configuration to correct section
  community.general.ini_file:
    path: '{{item}}'
    section: Coredump
    option: ProcessSizeMax
    value: '0'
    state: present
    no_extra_spaces: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"systemd" in ansible_facts.packages'
  - count_of_systemd_dropin_files_with_section | int &gt; 0
  loop: '{{systemd_dropin_files_with_section.results | sum(attribute=''files'', start=[])
    | map(attribute=''path'') | list }}'
  tags:
  - DISA-STIG-RHEL-08-010675
  - NIST-800-53-CM-6
  - PCI-DSS-Req-3.2
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - coredump_disable_backtraces
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable core dump backtraces - Add configuration to new remediation file
  community.general.ini_file:
    path: /etc/systemd/coredump.conf.d/complianceascode_hardening.conf
    section: Coredump
    option: ProcessSizeMax
    value: '0'
    state: present
    no_extra_spaces: true
    create: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"systemd" in ansible_facts.packages'
  - count_of_systemd_dropin_files_with_section | int == 0
  tags:
  - DISA-STIG-RHEL-08-010675
  - NIST-800-53-CM-6
  - PCI-DSS-Req-3.2
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - coredump_disable_backtraces
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="coredump_disable_backtraces" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,%23%20%20This%20file%20is%20part%20of%20systemd.%0A%23%0A%23%20%20systemd%20is%20free%20software%3B%20you%20can%20redistribute%20it%20and/or%20modify%20it%0A%23%20%20under%20the%20terms%20of%20the%20GNU%20Lesser%20General%20Public%20License%20as%20published%20by%0A%23%20%20the%20Free%20Software%20Foundation%3B%20either%20version%202.1%20of%20the%20License%2C%20or%0A%23%20%20%28at%20your%20option%29%20any%20later%20version.%0A%23%0A%23%20Entries%20in%20this%20file%20show%20the%20compile%20time%20defaults.%0A%23%20You%20can%20change%20settings%20by%20editing%20this%20file.%0A%23%20Defaults%20can%20be%20restored%20by%20simply%20deleting%20this%20file.%0A%23%0A%23%20See%20coredump.conf%285%29%20for%20details.%0A%0A%5BCoredump%5D%0A%23Storage%3Dexternal%0A%23Compress%3Dyes%0A%23ProcessSizeMax%3D2G%0A%23ExternalSizeMax%3D2G%0A%23JournalSizeMax%3D767M%0A%23MaxUse%3D%0A%23KeepFree%3D%0AStorage%3Dnone%0AProcessSizeMax%3D0%0A
        mode: 0644
        path: /etc/systemd/coredump.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-coredump_disable_backtraces:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-coredump_disable_backtraces_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_coredump_disable_storage" selected="false" severity="medium">
                <xccdf-1.2:title>Disable storing core dump</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>Storage</html:code> option in <html:code>[Coredump]</html:code> section
of <html:code>/etc/systemd/coredump.conf</html:code> or a drop-in file in
<html:code>/etc/systemd/coredump.conf.d/*.conf</html:code>
can be set to <html:code>none</html:code> to disable storing core dumps permanently.</xccdf-1.2:description>
                <xccdf-1.2:warning category="general">If the <html:code>/etc/systemd/coredump.conf</html:code> file or a drop-in file under <html:code>/etc/systemd/coredump.conf.d/</html:code>
does not already contain the <html:code>[Coredump]</html:code> section,
the value will not be configured correctly.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.5.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010674</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230314r1134881_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>A core dump includes a memory image taken at the time the operating system
terminates an application. The memory image could contain sensitive data
and is generally useful only for developers or system operators trying to
debug problems. Enabling core dumps on production systems is not recommended,
however there may be overriding operational requirements to enable advanced
debugging. Permitting temporary enablement of core dumps during such situations
should be reviewed through local needs and policy.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_systemd"/>
                <xccdf-1.2:conflicts idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_core_pattern"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="coredump_disable_storage" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q systemd; }; then

found=false

# set value in all files if they contain section or key
for f in $(echo -n "/etc/systemd/coredump.conf.d/complianceascode_hardening.conf /etc/systemd/coredump.conf.d/*.conf /etc/systemd/coredump.conf"); do
    if [ ! -e "$f" ]; then
        continue
    fi

    # find key in section and change value
    if grep -qzosP "(?m)^[[:space:]]*\[Coredump\]([^\n\[]*\n+)+?[[:space:]]*Storage" "$f"; then
        if ! grep -qzosP "(?m)^[[:space:]]*Storage[[:space:]]*=[[:space:]]*none" "$f"; then

            sed -i "/^[[:space:]]*Storage/s/\([[:blank:]]*=[[:blank:]]*\).*/\1none/" "$f"

        fi

        found=true

    # find section and add key = value to it
    elif grep -qs "^[[:space:]]*\[Coredump\]" "$f"; then

            sed -i "/^[[:space:]]*\[Coredump\]/a Storage=none" "$f"

            found=true
    fi
done

# if section not in any file, append section with key = value to FIRST file in files parameter
if ! $found ; then
    file=$(echo "/etc/systemd/coredump.conf.d/complianceascode_hardening.conf /etc/systemd/coredump.conf.d/*.conf /etc/systemd/coredump.conf" | cut -f1 -d ' ')
    mkdir -p "$(dirname "$file")"

    echo -e "[Coredump]\nStorage=none" &gt;&gt; "$file"

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="coredump_disable_storage" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010674
  - NIST-800-53-CM-6
  - PCI-DSS-Req-3.2
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - coredump_disable_storage
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable storing core dump - Search for a section in files
  ansible.builtin.find:
    paths: '{{item.path}}'
    patterns: '{{item.pattern}}'
    contains: ^\s*\[Coredump\]
    read_whole_file: true
    use_regex: true
  register: systemd_dropin_files_with_section
  loop:
  - path: '{{ ''/etc/systemd/coredump.conf'' | dirname }}'
    pattern: '{{ ''/etc/systemd/coredump.conf'' | basename | regex_escape }}'
  - path: /etc/systemd/coredump.conf.d
    pattern: .*\.conf
  when:
  - '"kernel" in ansible_facts.packages'
  - '"systemd" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010674
  - NIST-800-53-CM-6
  - PCI-DSS-Req-3.2
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - coredump_disable_storage
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable storing core dump - Count number of files which contain the correct
    section
  ansible.builtin.set_fact:
    count_of_systemd_dropin_files_with_section: '{{systemd_dropin_files_with_section.results
      | map(attribute=''matched'') | list | map(''int'') | sum}}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"systemd" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010674
  - NIST-800-53-CM-6
  - PCI-DSS-Req-3.2
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - coredump_disable_storage
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable storing core dump - Add missing configuration to correct section
  community.general.ini_file:
    path: '{{item}}'
    section: Coredump
    option: Storage
    value: none
    state: present
    no_extra_spaces: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"systemd" in ansible_facts.packages'
  - count_of_systemd_dropin_files_with_section | int &gt; 0
  loop: '{{systemd_dropin_files_with_section.results | sum(attribute=''files'', start=[])
    | map(attribute=''path'') | list }}'
  tags:
  - DISA-STIG-RHEL-08-010674
  - NIST-800-53-CM-6
  - PCI-DSS-Req-3.2
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - coredump_disable_storage
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable storing core dump - Add configuration to new remediation file
  community.general.ini_file:
    path: /etc/systemd/coredump.conf.d/complianceascode_hardening.conf
    section: Coredump
    option: Storage
    value: none
    state: present
    no_extra_spaces: true
    create: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"systemd" in ansible_facts.packages'
  - count_of_systemd_dropin_files_with_section | int == 0
  tags:
  - DISA-STIG-RHEL-08-010674
  - NIST-800-53-CM-6
  - PCI-DSS-Req-3.2
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - coredump_disable_storage
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="coredump_disable_storage" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,%23%20%20This%20file%20is%20part%20of%20systemd.%0A%23%0A%23%20%20systemd%20is%20free%20software%3B%20you%20can%20redistribute%20it%20and/or%20modify%20it%0A%23%20%20under%20the%20terms%20of%20the%20GNU%20Lesser%20General%20Public%20License%20as%20published%20by%0A%23%20%20the%20Free%20Software%20Foundation%3B%20either%20version%202.1%20of%20the%20License%2C%20or%0A%23%20%20%28at%20your%20option%29%20any%20later%20version.%0A%23%0A%23%20Entries%20in%20this%20file%20show%20the%20compile%20time%20defaults.%0A%23%20You%20can%20change%20settings%20by%20editing%20this%20file.%0A%23%20Defaults%20can%20be%20restored%20by%20simply%20deleting%20this%20file.%0A%23%0A%23%20See%20coredump.conf%285%29%20for%20details.%0A%0A%5BCoredump%5D%0A%23Storage%3Dexternal%0A%23Compress%3Dyes%0A%23ProcessSizeMax%3D2G%0A%23ExternalSizeMax%3D2G%0A%23JournalSizeMax%3D767M%0A%23MaxUse%3D%0A%23KeepFree%3D%0AStorage%3Dnone%0AProcessSizeMax%3D0%0A
        mode: 0644
        path: /etc/systemd/coredump.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-coredump_disable_storage:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-coredump_disable_storage_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_disable_users_coredumps" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Core Dumps for All Users</xccdf-1.2:title>
                <xccdf-1.2:description>To disable core dumps for all users, add the following line to
<html:code>/etc/security/limits.conf</html:code>, or to a file within the
<html:code>/etc/security/limits.d/</html:code> directory:
<html:pre>*     hard   core    0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(10)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010673</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230313r1155379_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>A core dump includes a memory image taken at the time the operating system
terminates an application. The memory image could contain sensitive data and is generally useful
only for developers trying to debug problems.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#package_pam"/>
                <xccdf-1.2:conflicts idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_core_pattern"/>
                <xccdf-1.2:fix id="disable_users_coredumps" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q pam; }; then

SECURITY_LIMITS_FILE="/etc/security/limits.conf"
DROPIN_DIR="/etc/security/limits.d"
DROPIN_FILE="$DROPIN_DIR/10-ssg-hardening.conf"
REGEX_CORRECT_VALUE="^\s*\*\s+hard\s+core\s+0\s*$"

# Remove bad configuration in drop-ins
if [ -d "$DROPIN_DIR" ]; then
    for override in "$DROPIN_DIR"/*.conf; do
        if [ -f "$override" ] &amp;&amp; ! grep -qE "$REGEX_CORRECT_VALUE" "$override"; then
            sed -ir -E '/^[[:space:]]*\*[[:space:]]+hard[[:space:]]+core[[:space:]]+/ s/^/#/' "$override"
        fi
    done
fi

if [ -d "$DROPIN_DIR" ] &amp;&amp; grep -qEr "$REGEX_CORRECT_VALUE" "$DROPIN_DIR"; then
    exit 0
elif [ ! -d "$DROPIN_DIR" ] &amp;&amp; grep -qE "$REGEX_CORRECT_VALUE" "$SECURITY_LIMITS_FILE"; then
    exit 0
else
    mkdir -p "$DROPIN_DIR"
    echo "*     hard   core    0" &gt;&gt; $DROPIN_FILE
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="disable_users_coredumps" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010673
  - NIST-800-53-CM-6
  - NIST-800-53-SC-7(10)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_users_coredumps
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable Core Dumps for All Users - Set dirs, files and regex variables
  ansible.builtin.set_fact:
    limits_dropin_dir: /etc/security/limits.d
    limits_dropin_file: /etc/security/limits.d/10-ssg-hardening.conf
    limits_main_file: /etc/security/limits.conf
    limits_correct_regex: ^\s*\*\s+hard\s+core\s+0\s*$
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010673
  - NIST-800-53-CM-6
  - NIST-800-53-SC-7(10)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_users_coredumps
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable Core Dumps for All Users - Find valid drop-ins for core limit
  ansible.builtin.find:
    paths: '{{ limits_dropin_dir }}'
    patterns: '*.conf'
    contains: '{{ limits_correct_regex }}'
    file_type: file
  register: valid_dropins
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010673
  - NIST-800-53-CM-6
  - NIST-800-53-SC-7(10)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_users_coredumps
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable Core Dumps for All Users - Find all drop-ins with any core limit
  ansible.builtin.find:
    paths: '{{ limits_dropin_dir }}'
    patterns: '*.conf'
    contains: ^\s*\*\s+hard\s+core\s+
    file_type: file
  register: all_dropins
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010673
  - NIST-800-53-CM-6
  - NIST-800-53-SC-7(10)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_users_coredumps
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable Core Dumps for All Users - Get invalid drop-ins
  ansible.builtin.set_fact:
    invalid_dropins: '{{ all_dropins.files | rejectattr(''path'', ''in'', valid_dropins.files
      | map(attribute=''path'') | list) | map(attribute=''path'') | list }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010673
  - NIST-800-53-CM-6
  - NIST-800-53-SC-7(10)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_users_coredumps
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable Core Dumps for All Users - Comment invalid * hard core lines in drop-ins
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: (^\s*\*\s+hard\s+core\s+.*$)
    replace: '#\1'
  loop: '{{ invalid_dropins }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - invalid_dropins | length &gt; 0
  tags:
  - DISA-STIG-RHEL-08-010673
  - NIST-800-53-CM-6
  - NIST-800-53-SC-7(10)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_users_coredumps
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable Core Dumps for All Users - Check if main limits.conf contains correct
    core limit
  ansible.builtin.find:
    paths: /etc/security
    patterns: limits.conf
    contains: '{{ limits_correct_regex }}'
    file_type: file
  register: main_valid
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not (valid_dropins.matched | default(0) &gt; 0)
  tags:
  - DISA-STIG-RHEL-08-010673
  - NIST-800-53-CM-6
  - NIST-800-53-SC-7(10)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_users_coredumps
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable Core Dumps for All Users - Set fact if configuration is valid
  ansible.builtin.set_fact:
    core_limit_valid: '{{ (valid_dropins.matched | default(0)) &gt; 0 or (main_valid.matched
      | default(0)) &gt; 0 }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010673
  - NIST-800-53-CM-6
  - NIST-800-53-SC-7(10)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_users_coredumps
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable Core Dumps for All Users - Ensure drop-in directory exists
  ansible.builtin.file:
    path: '{{ limits_dropin_dir }}'
    state: directory
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not core_limit_valid
  tags:
  - DISA-STIG-RHEL-08-010673
  - NIST-800-53-CM-6
  - NIST-800-53-SC-7(10)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_users_coredumps
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable Core Dumps for All Users - Deploy 10-ssg-hardening.conf drop-in with
    correct core limit
  ansible.builtin.copy:
    dest: '{{ limits_dropin_file }}'
    content: |
      *     hard   core    0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"pam" in ansible_facts.packages'
  - not core_limit_valid
  tags:
  - DISA-STIG-RHEL-08-010673
  - NIST-800-53-CM-6
  - NIST-800-53-SC-7(10)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_users_coredumps
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="disable_users_coredumps" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,%2A%20%20%20%20%20hard%20%20%20core%20%20%20%200
        mode: 0644
        path: /etc/security/limits.d/75-disable_users_coredumps.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-disable_users_coredumps:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_fs_suid_dumpable" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Core Dumps for SUID programs</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>fs.suid_dumpable</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w fs.suid_dumpable=0</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>fs.suid_dumpable = 0</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-11(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-11(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.5.4</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The core dump of a setuid program is more likely to contain
sensitive data, as the program itself runs with greater privileges than the
user who initiated execution of the program.  Disabling the ability for any
setuid program to write a core file decreases the risk of unauthorized access
of such data.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_fs_suid_dumpable" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of fs.suid_dumpable from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*fs.suid_dumpable.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "fs.suid_dumpable" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/fs_suid_dumpable.conf'


#
# Set runtime for fs.suid_dumpable
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w fs.suid_dumpable="0"
fi

#
# If fs.suid_dumpable present in /etc/sysctl.conf, change value to "0"
#	else, add "fs.suid_dumpable = 0" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^fs.suid_dumpable")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "0"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^fs.suid_dumpable\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^fs.suid_dumpable\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_fs_suid_dumpable" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-SI-11(a)
  - NIST-800-53-SI-11(b)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_suid_dumpable

- name: Disable Core Dumps for SUID programs - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-SI-11(a)
  - NIST-800-53-SI-11(b)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_suid_dumpable

- name: Disable Core Dumps for SUID programs - Find all files that contain fs.suid_dumpable
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*fs.suid_dumpable\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-SI-11(a)
  - NIST-800-53-SI-11(b)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_suid_dumpable

- name: Disable Core Dumps for SUID programs - Find all files that set fs.suid_dumpable
    to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*fs.suid_dumpable\s*=\s*0$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-SI-11(a)
  - NIST-800-53-SI-11(b)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_suid_dumpable

- name: Disable Core Dumps for SUID programs - Comment out any occurrences of fs.suid_dumpable
    from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*fs.suid_dumpable
    replace: '#fs.suid_dumpable'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - NIST-800-53-SI-11(a)
  - NIST-800-53-SI-11(b)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_suid_dumpable

- name: Disable Core Dumps for SUID programs - Comment out any occurrences of fs.suid_dumpable
    from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*fs.suid_dumpable
    replace: '#fs.suid_dumpable'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-SI-11(a)
  - NIST-800-53-SI-11(b)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_suid_dumpable

- name: Disable Core Dumps for SUID programs - Ensure sysctl fs.suid_dumpable is set
    to 0
  ansible.posix.sysctl:
    name: fs.suid_dumpable
    value: '0'
    sysctl_file: /etc/sysctl.d/fs_suid_dumpable.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-SI-11(a)
  - NIST-800-53-SI-11(b)
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_fs_suid_dumpable
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_fs_suid_dumpable:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_daemon_umask">
              <xccdf-1.2:title>Daemon Umask</xccdf-1.2:title>
              <xccdf-1.2:description>The umask is a per-process setting which limits
the default permissions for creation of new files and directories.
The system includes initialization scripts which set the default umask
for system daemons.</xccdf-1.2:description>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_umask_for_daemons" type="string">
                <xccdf-1.2:title>daemon umask</xccdf-1.2:title>
                <xccdf-1.2:description>Enter umask for daemons</xccdf-1.2:description>
                <xccdf-1.2:value selector="022">022</xccdf-1.2:value>
                <xccdf-1.2:value selector="027">027</xccdf-1.2:value>
                <xccdf-1.2:value>022</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_umask_for_daemons" selected="false" severity="unknown">
                <xccdf-1.2:title>Set Daemon Umask</xccdf-1.2:title>
                <xccdf-1.2:description>The file <html:code>/etc/init.d/functions</html:code> includes initialization
parameters for most or all daemons started at boot time. Many daemons
on the system already individually restrict themselves to
a umask of <html:code>077</html:code> in their own init scripts. By default, the umask of
<html:code>022</html:code> is set which prevents creation of group- or world-writable files.
To set the umask for daemons expected by the profile, edit the following line:
<html:pre>umask <html:i><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_umask_for_daemons" use="legacy"/></html:i></html:pre></xccdf-1.2:description>
                <xccdf-1.2:warning category="functionality">Setting the umask to too restrictive a setting can cause serious errors at
runtime.</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The umask influences the permissions assigned to files created by a
process at run time. An unnecessarily permissive umask could result in files
being created with insecure permissions.</xccdf-1.2:rationale>
                <xccdf-1.2:fix id="umask_for_daemons" system="urn:xccdf:fix:script:sh">
var_umask_for_daemons='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_umask_for_daemons" use="legacy"/>'


grep -q ^umask /etc/init.d/functions &amp;&amp; \
  sed -i "s/umask.*/umask $var_umask_for_daemons/g" /etc/init.d/functions
if ! [ $? -eq 0 ]; then
    echo "umask $var_umask_for_daemons" &gt;&gt; /etc/init.d/functions
fi
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_umask_for_daemons:var:1" value-id="xccdf_org.ssgproject.content_value_var_umask_for_daemons"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-umask_for_daemons:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-umask_for_daemons_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_enable_execshield_settings">
              <xccdf-1.2:title>Enable ExecShield</xccdf-1.2:title>
              <xccdf-1.2:description>ExecShield describes kernel features that provide
protection against exploitation of memory corruption errors such as buffer
overflows. These features include random placement of the stack and other
memory regions, prevention of execution in memory that should only hold data,
and special handling of text buffers. These protections are enabled by default
on 32-bit systems and controlled through <html:code>sysctl</html:code> variables 
<html:code>kernel.exec-shield</html:code> and <html:code>kernel.randomize_va_space</html:code>. On the latest
64-bit systems, <html:code>kernel.exec-shield</html:code> cannot be enabled or disabled with 
<html:code>sysctl</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sysctl_kernel_kptr_restrict_value" type="number">
                <xccdf-1.2:title>kernel.kptr_restrict</xccdf-1.2:title>
                <xccdf-1.2:description>Configure exposition of kernel pointer addresses </xccdf-1.2:description>
                <xccdf-1.2:value>1</xccdf-1.2:value>
                <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
                <xccdf-1.2:value selector="2">2</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_kernel_exec_shield" selected="false" severity="medium">
                <xccdf-1.2:title>Enable ExecShield via sysctl</xccdf-1.2:title>
                <xccdf-1.2:description>By default on AlmaLinux OS 8 64-bit systems, ExecShield is
enabled and can only be disabled if the hardware does not support
ExecShield or is disabled in <html:code>/etc/default/grub</html:code>.



For AlmaLinux OS 8  32-bit systems, <html:code>sysctl</html:code> can be used to enable
ExecShield.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-39</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000433-GPOS-00192</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
                <xccdf-1.2:rationale>ExecShield uses the segmentation feature on all x86 systems to prevent
execution in memory higher than a certain address. It writes an address as
a limit in the code segment descriptor, to control where code can be
executed, on a per-process basis. When the kernel places a process's memory
regions such as the stack and heap higher than this address, the hardware
prevents execution in that address range. This is enabled by default on the
latest Red Hat and Fedora systems if supported by the hardware.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel_and_x86_64_arch"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="sysctl_kernel_exec_shield" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q kernel &amp;&amp; ( grep -sqE "^.*\.x86_64$" /proc/sys/kernel/osrelease || grep -sqE "^x86_64$" /proc/sys/kernel/arch; ) ) ); then

if [ "$(getconf LONG_BIT)" = "32" ] ; then
  #
  # Set runtime for kernel.exec-shield
  #
  sysctl -q -n -w kernel.exec-shield=1

  #
  # If kernel.exec-shield present in /etc/sysctl.conf, change value to "1"
  #	else, add "kernel.exec-shield = 1" to /etc/sysctl.conf
  #
  # Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^kernel.exec-shield")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "1"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^kernel.exec-shield\\&gt;" "/etc/sysctl.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^kernel.exec-shield\\&gt;.*/$escaped_formatted_output/gi" "/etc/sysctl.conf"
else
    if [[ -s "/etc/sysctl.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/sysctl.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/sysctl.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/sysctl.conf"
fi
fi

if [ "$(getconf LONG_BIT)" = "64" ] ; then
    
grubby --update-kernel=ALL --remove-args=noexec --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="sysctl_kernel_exec_shield" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-39
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
  - sysctl_kernel_exec_shield

- name: Set 32bit architecture for kernel exec-shield tasks
  ansible.builtin.set_fact:
    kexec_arch: b32
  when: ( "kernel" in ansible_facts.packages and ansible_architecture == "x86_64"
    )
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-39
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
  - sysctl_kernel_exec_shield

- name: Set 64bit architecture for kernel exec-shield tasks
  ansible.builtin.set_fact:
    kexec_arch: b64
  when:
  - ( "kernel" in ansible_facts.packages and ansible_architecture == "x86_64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-39
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
  - sysctl_kernel_exec_shield

- name: Ensure sysctl kernel.exec-shield is set to 1
  ansible.posix.sysctl:
    name: kernel.exec-shield
    value: '1'
    state: present
    reload: true
  when:
  - ( "kernel" in ansible_facts.packages and ansible_architecture == "x86_64" )
  - kexec_arch == "b32"
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-39
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
  - sysctl_kernel_exec_shield

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --remove-args="noexec"
  when:
  - ( "kernel" in ansible_facts.packages and ansible_architecture == "x86_64" )
  - kexec_arch == "b64"
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-39
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
  - sysctl_kernel_exec_shield
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_kernel_exec_shield:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_kernel_exec_shield_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict" selected="false" severity="medium">
                <xccdf-1.2:title>Restrict Exposed Kernel Pointer Addresses Access</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>kernel.kptr_restrict</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w kernel.kptr_restrict=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_kernel_kptr_restrict_value" use="legacy"/></html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>kernel.kptr_restrict = <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sysctl_kernel_kptr_restrict_value" use="legacy"/></html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-002-5 R1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-002-5 R1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-005-6 R1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-005-6 R1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-005-6 R1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R8.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-009-6 R.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-009-6 R4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-30</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-30(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-30(5)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000132-GPOS-00067</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000433-GPOS-00192</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040283</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230547r1017309_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Exposing kernel pointers (through procfs or <html:code>seq_printf()</html:code>) exposes kernel
writeable structures which may contain functions pointers. If a write vulnerability
occurs in the kernel, allowing write access to any of this structure, the kernel can
be compromised. This option disallow any program without the CAP_SYSLOG capability
to get the addresses of kernel pointers by replacing them with 0.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_kptr_restrict" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of kernel.kptr_restrict from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*kernel.kptr_restrict.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "kernel.kptr_restrict" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/kernel_kptr_restrict.conf'


#
# Set runtime for kernel.kptr_restrict
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w kernel.kptr_restrict="1"
fi

#
# If kernel.kptr_restrict present in /etc/sysctl.conf, change value to "1"
#	else, add "kernel.kptr_restrict = 1" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^kernel.kptr_restrict")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "1"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^kernel.kptr_restrict\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^kernel.kptr_restrict\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_kptr_restrict" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040283
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-30
  - NIST-800-53-SC-30(2)
  - NIST-800-53-SC-30(5)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_kptr_restrict

- name: Restrict Exposed Kernel Pointer Addresses Access - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040283
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-30
  - NIST-800-53-SC-30(2)
  - NIST-800-53-SC-30(5)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_kptr_restrict

- name: Restrict Exposed Kernel Pointer Addresses Access - Find all files that contain
    kernel.kptr_restrict
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.kptr_restrict\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040283
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-30
  - NIST-800-53-SC-30(2)
  - NIST-800-53-SC-30(5)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_kptr_restrict

- name: Restrict Exposed Kernel Pointer Addresses Access - Find all files that set
    kernel.kptr_restrict to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.kptr_restrict\s*=\s*1$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040283
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-30
  - NIST-800-53-SC-30(2)
  - NIST-800-53-SC-30(5)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_kptr_restrict

- name: Restrict Exposed Kernel Pointer Addresses Access - Comment out any occurrences
    of kernel.kptr_restrict from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*kernel.kptr_restrict
    replace: '#kernel.kptr_restrict'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-040283
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-30
  - NIST-800-53-SC-30(2)
  - NIST-800-53-SC-30(5)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_kptr_restrict

- name: Restrict Exposed Kernel Pointer Addresses Access - Comment out any occurrences
    of kernel.kptr_restrict from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*kernel.kptr_restrict
    replace: '#kernel.kptr_restrict'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040283
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-30
  - NIST-800-53-SC-30(2)
  - NIST-800-53-SC-30(5)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_kptr_restrict

- name: Restrict Exposed Kernel Pointer Addresses Access - Ensure sysctl kernel.kptr_restrict
    is set to 1
  ansible.posix.sysctl:
    name: kernel.kptr_restrict
    value: '1'
    sysctl_file: /etc/sysctl.d/kernel_kptr_restrict.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040283
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-30
  - NIST-800-53-SC-30(2)
  - NIST-800-53-SC-30(5)
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_kptr_restrict
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_kernel_kptr_restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,kernel.kptr_restrict%3D1%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_kernel_kptr_restrict.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_kernel_kptr_restrict:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_kernel_kptr_restrict_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space" selected="false" severity="medium">
                <xccdf-1.2:title>Enable Randomized Layout of Virtual Address Space</xccdf-1.2:title>
                <xccdf-1.2:description>To set the runtime status of the <html:code>kernel.randomize_va_space</html:code> kernel parameter, run the following command: <html:pre>$ sudo sysctl -w kernel.randomize_va_space=2</html:pre>
To make sure that the setting is persistent, add the following line to a file in the directory <html:code>/etc/sysctl.d</html:code>: <html:pre>kernel.randomize_va_space = 2</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-002-5 R1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-002-5 R1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-005-6 R1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-005-6 R1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-005-6 R1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R8.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-009-6 R.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-009-6 R4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-30</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-30(2)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-2.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000433-GPOS-00193</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000450-CTR-001105</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010430</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230280r1017093_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Address space layout randomization (ASLR) makes it more difficult for an
attacker to predict the location of attack code they have introduced into a
process's address space during an attempt at exploitation. Additionally,
ASLR makes it more difficult for an attacker to know the location of
existing code in order to re-purpose it using return oriented programming
(ROP) techniques.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_randomize_va_space" reboot="true" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Comment out any occurrences of kernel.randomize_va_space from /etc/sysctl.d/*.conf files

for f in /etc/sysctl.d/*.conf /run/sysctl.d/*.conf /usr/local/lib/sysctl.d/*.conf /usr/lib/sysctl.d/*.conf; do


  # skip systemd-sysctl symlink (/etc/sysctl.d/99-sysctl.conf -&gt; /etc/sysctl.conf)
  if [[ "$(readlink -f "$f")" == "/etc/sysctl.conf" ]]; then continue; fi

  matching_list=$(grep -P '^(?!#).*[\s]*kernel.randomize_va_space.*$' $f | uniq )
  if ! test -z "$matching_list"; then
    while IFS= read -r entry; do
      escaped_entry=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$entry")
      # comment out "kernel.randomize_va_space" matches to preserve user data
      sed -i --follow-symlinks "s/^${escaped_entry}$/# &amp;/g" $f
    done &lt;&lt;&lt; "$matching_list"
  fi
done

#
# Set sysctl config file which to save the desired value
#

SYSCONFIG_FILE='/etc/sysctl.d/kernel_randomize_va_space.conf'


#
# Set runtime for kernel.randomize_va_space
#
if ! { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    /sbin/sysctl -q -n -w kernel.randomize_va_space="2"
fi

#
# If kernel.randomize_va_space present in /etc/sysctl.conf, change value to "2"
#	else, add "kernel.randomize_va_space = 2" to /etc/sysctl.conf
#

sed -i "/^$SYSCONFIG_VAR/d" /etc/sysctl.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^kernel.randomize_va_space")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "2"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^kernel.randomize_va_space\\&gt;" "${SYSCONFIG_FILE}"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^kernel.randomize_va_space\\&gt;.*/$escaped_formatted_output/gi" "${SYSCONFIG_FILE}"
else
    if [[ -s "${SYSCONFIG_FILE}" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "${SYSCONFIG_FILE}" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "${SYSCONFIG_FILE}"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "${SYSCONFIG_FILE}"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="sysctl_kernel_randomize_va_space" reboot="true" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010430
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-30
  - NIST-800-53-SC-30(2)
  - PCI-DSS-Req-2.2.1
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_randomize_va_space

- name: Enable Randomized Layout of Virtual Address Space - Set fact for sysctl paths
  ansible.builtin.set_fact:
    sysctl_paths:
    - /etc/sysctl.d/
    - /run/sysctl.d/
    - /usr/local/lib/sysctl.d/
    - /usr/lib/sysctl.d/
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010430
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-30
  - NIST-800-53-SC-30(2)
  - PCI-DSS-Req-2.2.1
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_randomize_va_space

- name: Enable Randomized Layout of Virtual Address Space - Find all files that contain
    kernel.randomize_va_space
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.randomize_va_space\s*=\s*.*$'
  register: find_all_values
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010430
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-30
  - NIST-800-53-SC-30(2)
  - PCI-DSS-Req-2.2.1
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_randomize_va_space

- name: Enable Randomized Layout of Virtual Address Space - Find all files that set
    kernel.randomize_va_space to correct value
  ansible.builtin.shell:
    cmd: find -L {{ sysctl_paths | join(" ") }} -type f -name '*.conf' | xargs grep
      -HP '^\s*kernel.randomize_va_space\s*=\s*2$'
  register: find_correct_value
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010430
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-30
  - NIST-800-53-SC-30(2)
  - PCI-DSS-Req-2.2.1
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_randomize_va_space

- name: Enable Randomized Layout of Virtual Address Space - Comment out any occurrences
    of kernel.randomize_va_space from config files
  ansible.builtin.replace:
    path: '{{ item | split(":") | first }}'
    regexp: ^[\s]*kernel.randomize_va_space
    replace: '#kernel.randomize_va_space'
  loop: '{{ find_all_values.stdout_lines }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - find_correct_value.stdout_lines | length == 0 or find_all_values.stdout_lines
    | length &gt; find_correct_value.stdout_lines | length
  tags:
  - DISA-STIG-RHEL-08-010430
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-30
  - NIST-800-53-SC-30(2)
  - PCI-DSS-Req-2.2.1
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_randomize_va_space

- name: Enable Randomized Layout of Virtual Address Space - Comment out any occurrences
    of kernel.randomize_va_space from /etc/sysctl.conf
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^[\s]*kernel.randomize_va_space
    replace: '#kernel.randomize_va_space'
  with_fileglob:
  - /etc/sysctl.conf
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010430
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-30
  - NIST-800-53-SC-30(2)
  - PCI-DSS-Req-2.2.1
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_randomize_va_space

- name: Enable Randomized Layout of Virtual Address Space - Ensure sysctl kernel.randomize_va_space
    is set to 2
  ansible.posix.sysctl:
    name: kernel.randomize_va_space
    value: '2'
    sysctl_file: /etc/sysctl.d/kernel_randomize_va_space.conf
    state: present
    reload: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010430
  - NIST-800-171-3.1.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-30
  - NIST-800-53-SC-30(2)
  - PCI-DSS-Req-2.2.1
  - PCI-DSSv4-3.3
  - PCI-DSSv4-3.3.1
  - PCI-DSSv4-3.3.1.1
  - disable_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - reboot_required
  - sysctl_kernel_randomize_va_space
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="sysctl_kernel_randomize_va_space" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,kernel.randomize_va_space%3D2%0A
        mode: 0644
        path: /etc/sysctl.d/75-sysctl_kernel_randomize_va_space.conf
        overwrite: true
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysctl_kernel_randomize_va_space:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_enable_nx">
              <xccdf-1.2:title>Enable Execute Disable (XD) or No Execute (NX) Support on
x86 Systems</xccdf-1.2:title>
              <xccdf-1.2:description>Recent processors in the x86 family support the
ability to prevent code execution on a per memory page basis.
Generically and on AMD processors, this ability is called No
Execute (NX), while on Intel processors it is called Execute
Disable (XD). This ability can help prevent exploitation of buffer
overflow vulnerabilities and should be activated whenever possible.
Extra steps must be taken to ensure that this protection is
enabled, particularly on 32-bit x86 systems. Other processors, such
as Itanium and POWER, have included such support since inception
and the standard kernel for those platforms supports the
feature. This is enabled by default on the latest Oracle Linux, Red Hat and
Fedora systems if supported by the hardware.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_bios_enable_execution_restrictions" selected="false" severity="medium">
                <xccdf-1.2:title>Enable NX or XD Support in the BIOS</xccdf-1.2:title>
                <xccdf-1.2:description>Reboot the system and enter the BIOS or Setup configuration menu.
Navigate the BIOS configuration menu and make sure that the option is enabled. The setting may be located
under a Security section. Look for Execute Disable (XD) on Intel-based systems and No Execute (NX)
on AMD-based systems.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-39</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000433-GPOS-00192</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000450-CTR-001105</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010420</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230276r958928_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Computers with the ability to prevent this type of code execution frequently put an option in the BIOS that will
allow users to turn the feature on or off at will.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#machine"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-bios_enable_execution_restrictions:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-bios_enable_execution_restrictions_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_install_PAE_kernel_on_x86-32" selected="false" severity="unknown">
                <xccdf-1.2:title>Install PAE Kernel on Supported 32-bit x86 Systems</xccdf-1.2:title>
                <xccdf-1.2:description>Systems that are using the 64-bit x86 kernel package
do not need to install the kernel-PAE package because the 64-bit
x86 kernel already includes this support. However, if the system is
32-bit and also supports the PAE and NX features as
determined in the previous section, the kernel-PAE package should
be installed to enable XD or NX support.
The <html:code>kernel-PAE</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install kernel-PAE</html:pre>
The installation process should also have configured the
bootloader to load the new kernel at boot. Verify this after reboot
and modify <html:code>/etc/default/grub</html:code> if necessary.</xccdf-1.2:description>
                <xccdf-1.2:warning category="hardware">The kernel-PAE package should not be
installed on older systems that do not support the XD or NX bit, as
8this may prevent them from booting.8</xccdf-1.2:warning>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:rationale>On 32-bit systems that support the XD or NX bit, the vendor-supplied
PAE kernel is required to enable either Execute Disable (XD) or No Execute (NX) support.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-install_PAE_kernel_on_x86-32:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_poisoning">
              <xccdf-1.2:title>Memory Poisoning</xccdf-1.2:title>
              <xccdf-1.2:description>Memory Poisoning consists of writing a special value to uninitialized or freed memory.
Poisoning can be used as a mechanism to prevent leak of information and detection of
corrupted memory.</xccdf-1.2:description>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_slub_debug_options" interactive="true" type="string">
                <xccdf-1.2:title>slub_debug - debug options</xccdf-1.2:title>
                <xccdf-1.2:description>Defines the debug options to use in <html:code>slub_debug</html:code> kernel command line argument.</xccdf-1.2:description>
                <xccdf-1.2:value>P</xccdf-1.2:value>
                <xccdf-1.2:value selector="F">F</xccdf-1.2:value>
                <xccdf-1.2:value selector="Z">Z</xccdf-1.2:value>
                <xccdf-1.2:value selector="P">P</xccdf-1.2:value>
                <xccdf-1.2:value selector="FZ">FZ</xccdf-1.2:value>
                <xccdf-1.2:value selector="FZP">FZP</xccdf-1.2:value>
              </xccdf-1.2:Value>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_page_poison_argument" selected="false" severity="medium">
                <xccdf-1.2:title>Enable page allocator poisoning</xccdf-1.2:title>
                <xccdf-1.2:description>To enable poisoning of free pages,
add the argument <html:code>page_poison=1</html:code> to the default
GRUB 2 command line for the Linux operating system.
Configure the default Grub2 kernel command line to contain page_poison=1 as follows:
<html:pre># grub2-editenv - set "$(grub2-editenv - list | grep kernelopts) page_poison=1"</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000134-GPOS-00068</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010421</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230277r1017090_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Poisoning writes an arbitrary value to freed pages, so any modification or
reference to that page after being freed or before being initialized will be
detected and prevented.
This prevents many types of use-after-free vulnerabilities at little performance cost.
Also prevents leak of data and detection of corrupted memory.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#grub2"/>
                <xccdf-1.2:fix id="grub2_page_poison_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q grub2-common; }; then

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    KARGS_DIR="/usr/lib/bootc/kargs.d/"
    if grep -q -E "page_poison" "$KARGS_DIR/*.toml" ; then
        sed -i -E "s/^(\s*kargs\s*=\s*\[.*)\"page_poison=[^\"]*\"(.*]\s*)/\1\"page_poison=1\"\2/" "$KARGS_DIR/*.toml"
    else
        echo "kargs = [\"page_poison=1\"]" &gt;&gt; "$KARGS_DIR/10-page_poison.toml"
    fi
else

    grubby --update-kernel=ALL --args=page_poison=1 --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_page_poison_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010421
  - NIST-800-53-CM-6(a)
  - grub2_page_poison_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if page_poison argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010421
  - NIST-800-53-CM-6(a)
  - grub2_page_poison_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if page_poison argument is already present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010421
  - NIST-800-53-CM-6(a)
  - grub2_page_poison_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --args="page_poison=1"
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  - (grubby_info.stdout is not search('page_poison=1')) or ((etc_default_grub['content']
    | b64decode) is not search('page_poison=1'))
  tags:
  - DISA-STIG-RHEL-08-010421
  - NIST-800-53-CM-6(a)
  - grub2_page_poison_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="grub2_page_poison_argument" system="urn:redhat:osbuild:blueprint">[customizations.kernel]
append = "page_poison=1"
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_page_poison_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kickstart">
bootloader page_poison=1
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_page_poison_argument:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_page_poison_argument_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_slub_debug_argument" selected="false" severity="medium">
                <xccdf-1.2:title>Enable SLUB/SLAB allocator poisoning</xccdf-1.2:title>
                <xccdf-1.2:description>To enable poisoning of SLUB/SLAB objects,
add the argument <html:code>slub_debug=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_slub_debug_options" use="legacy"/></html:code> to the default
GRUB 2 command line for the Linux operating system.
Configure the default Grub2 kernel command line to contain slub_debug=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_slub_debug_options" use="legacy"/> as follows:
<html:pre># grub2-editenv - set "$(grub2-editenv - list | grep kernelopts) slub_debug=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_slub_debug_options" use="legacy"/>"</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000433-GPOS-00192</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000134-GPOS-00068</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R8</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Poisoning writes an arbitrary value to freed objects, so any modification or
reference to that object after being freed or before being initialized will be
detected and prevented.
This prevents many types of use-after-free vulnerabilities at little performance cost.
Also prevents leak of data and detection of corrupted memory.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#grub2"/>
                <xccdf-1.2:fix id="grub2_slub_debug_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q grub2-common; }; then

var_slub_debug_options='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_slub_debug_options" use="legacy"/>'



if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    KARGS_DIR="/usr/lib/bootc/kargs.d/"
    if grep -q -E "slub_debug" "$KARGS_DIR/*.toml" ; then
        sed -i -E "s/^(\s*kargs\s*=\s*\[.*)\"slub_debug=[^\"]*\"(.*]\s*)/\1\"slub_debug=$var_slub_debug_options\"\2/" "$KARGS_DIR/*.toml"
    else
        echo "kargs = [\"slub_debug=$var_slub_debug_options\"]" &gt;&gt; "$KARGS_DIR/10-slub_debug.toml"
    fi
else

    grubby --update-kernel=ALL --args=slub_debug=$var_slub_debug_options --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_slub_debug_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - grub2_slub_debug_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy
- name: XCCDF Value var_slub_debug_options # promote to variable
  set_fact:
    var_slub_debug_options: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_slub_debug_options" use="legacy"/>
  tags:
    - always

- name: Check if slub_debug argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - grub2_slub_debug_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Check if slub_debug argument is already present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - grub2_slub_debug_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --args="slub_debug={{
    var_slub_debug_options }}"
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  - (grubby_info.stdout is not search('slub_debug=' ~ var_slub_debug_options)) or
    ((etc_default_grub['content'] | b64decode) is not search('slub_debug=' ~ var_slub_debug_options))
  tags:
  - NIST-800-53-CM-6(a)
  - grub2_slub_debug_argument
  - low_disruption
  - medium_complexity
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="grub2_slub_debug_argument" system="urn:redhat:osbuild:blueprint">[customizations.kernel]
append = "slub_debug=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_slub_debug_options" use="legacy"/>"
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_slub_debug_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kickstart">
bootloader slub_debug=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_slub_debug_options" use="legacy"/>
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-export export-name="oval:ssg-var_slub_debug_options:var:1" value-id="xccdf_org.ssgproject.content_value_var_slub_debug_options"/>
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_slub_debug_argument:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_slub_debug_argument_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_selinux">
          <xccdf-1.2:title>SELinux</xccdf-1.2:title>
          <xccdf-1.2:description>SELinux is a feature of the Linux kernel which can be
used to guard against misconfigured or compromised programs.
SELinux enforces the idea that programs should be limited in what
files they can access and what actions they can take.
<html:br/><html:br/>
The default SELinux policy, as configured on AlmaLinux OS 8, has been
sufficiently developed and debugged that it should be usable on
almost any system with minimal configuration and a small
amount of system administrator training. This policy prevents
system services - including most of the common network-visible
services such as mail servers, FTP servers, and DNS servers - from
accessing files which those services have no valid reason to
access. This action alone prevents a huge amount of possible damage
from network attacks against services, from trojaned software, and
so forth.
<html:br/><html:br/>
This guide recommends that SELinux be enabled using the
default (targeted) policy on every AlmaLinux OS 8 system, unless that
system has unusual requirements which make a stronger policy
appropriate.

<html:br/><html:br/>
For more information on SELinux, see <html:b><html:a href="https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/using_selinux">https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/using_selinux</html:a></html:b>.</xccdf-1.2:description>
          <xccdf-1.2:platform idref="#system_with_kernel"/>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_selinux_policy_name" type="string">
            <xccdf-1.2:title>SELinux policy</xccdf-1.2:title>
            <xccdf-1.2:description>Type of policy in use. Possible values are:
<html:br/>targeted - Only targeted network daemons are protected.
<html:br/>strict - Full SELinux protection.
<html:br/>mls - Multiple levels of security</xccdf-1.2:description>
            <xccdf-1.2:value>targeted</xccdf-1.2:value>
            <xccdf-1.2:value selector="mls">mls</xccdf-1.2:value>
            <xccdf-1.2:value selector="targeted">targeted</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_selinux_state" type="string">
            <xccdf-1.2:title>SELinux state</xccdf-1.2:title>
            <xccdf-1.2:description>enforcing - SELinux security policy is enforced.
<html:br/>permissive - SELinux prints warnings instead of enforcing.
<html:br/>disabled - SELinux is fully disabled.</xccdf-1.2:description>
            <xccdf-1.2:value>enforcing</xccdf-1.2:value>
            <xccdf-1.2:value selector="disabled">disabled</xccdf-1.2:value>
            <xccdf-1.2:value selector="enforcing">enforcing</xccdf-1.2:value>
            <xccdf-1.2:value selector="permissive">permissive</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_libselinux_installed" selected="false" severity="high">
            <xccdf-1.2:title>Install libselinux Package</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>libselinux</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install libselinux</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.3.1.1</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Security-enhanced Linux is a feature of the Linux kernel and a number of utilities
with enhanced security functionality designed to add mandatory access controls to Linux.

The <html:code>libselinux</html:code> package contains the core library of the Security-enhanced Linux system.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_libselinux_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "libselinux" ; then
    yum install -y "libselinux"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_libselinux_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.6
  - enable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_libselinux_installed

- name: Ensure libselinux is installed
  ansible.builtin.package:
    name: libselinux
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.6
  - enable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_libselinux_installed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_libselinux_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_libselinux

class install_libselinux {
  package { 'libselinux':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_libselinux_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=libselinux
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_libselinux_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "libselinux"
version = "*"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_libselinux_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install libselinux
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_libselinux_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install libselinux
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_libselinux_installed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_libselinux_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_policycoreutils-python-utils_installed" selected="false" severity="medium">
            <xccdf-1.2:title>Install policycoreutils-python-utils package</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>policycoreutils-python-utils</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install policycoreutils-python-utils</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This package is required to operate and manage an SELinux environment and its policies.
It provides utilities such as semanage, audit2allow, audit2why, chcat and sandbox.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_policycoreutils-python-utils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "policycoreutils-python-utils" ; then
    yum install -y "policycoreutils-python-utils"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_policycoreutils-python-utils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_policycoreutils-python-utils_installed

- name: Ensure policycoreutils-python-utils is installed
  ansible.builtin.package:
    name: policycoreutils-python-utils
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_policycoreutils-python-utils_installed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_policycoreutils-python-utils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_policycoreutils-python-utils

class install_policycoreutils-python-utils {
  package { 'policycoreutils-python-utils':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_policycoreutils-python-utils_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=policycoreutils-python-utils
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_policycoreutils-python-utils_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "policycoreutils-python-utils"
version = "*"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_policycoreutils-python-utils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install policycoreutils-python-utils
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_policycoreutils-python-utils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install policycoreutils-python-utils
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_policycoreutils-python-utils_installed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_policycoreutils-python-utils_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_policycoreutils_installed" selected="false" severity="low">
            <xccdf-1.2:title>Install policycoreutils Package</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>policycoreutils</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install policycoreutils</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000134-GPOS-00068</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010171</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230241r1017060_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Security-enhanced Linux is a feature of the Linux kernel and a number of utilities
with enhanced security functionality designed to add mandatory access controls to Linux.
The Security-enhanced Linux kernel contains new architectural components originally
developed to improve security of the Flask operating system. These architectural components
provide general support for the enforcement of many kinds of mandatory access control
policies, including those based on the concepts of Type Enforcement, Role-based Access
Control, and Multi-level Security.

<html:code>policycoreutils</html:code> contains the policy core utilities that are required for
basic operation of an SELinux-enabled system. These utilities include <html:code>load_policy</html:code>
to load SELinux policies, <html:code>setfiles</html:code> to label filesystems, <html:code>newrole</html:code> to
switch roles, and so on.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_policycoreutils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "policycoreutils" ; then
    yum install -y "policycoreutils"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_policycoreutils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010171
  - enable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_policycoreutils_installed

- name: Ensure policycoreutils is installed
  ansible.builtin.package:
    name: policycoreutils
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010171
  - enable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_policycoreutils_installed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_policycoreutils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_policycoreutils

class install_policycoreutils {
  package { 'policycoreutils':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_policycoreutils_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=policycoreutils
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_policycoreutils_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "policycoreutils"
version = "*"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_policycoreutils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install policycoreutils
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_policycoreutils_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install policycoreutils
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_policycoreutils_installed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_policycoreutils_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_mcstrans_removed" selected="false" severity="low">
            <xccdf-1.2:title>Uninstall mcstrans Package</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>mcstransd</html:code> daemon provides category label information
to client processes requesting information. The label translations are defined
in <html:code>/etc/selinux/targeted/setrans.conf</html:code>.
The <html:code>mcstrans</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase mcstrans</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.3.1.7</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Since this service is not used very often, disable it to reduce the
amount of potentially vulnerable code running on the system.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_mcstrans_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# CAUTION: This remediation script will remove mcstrans
# from the system, and may remove any packages
# that depend on mcstrans. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "mcstrans" ; then
yum remove -y "mcstrans"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_mcstrans_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_mcstrans_removed

- name: 'Uninstall mcstrans Package: Ensure mcstrans is removed'
  ansible.builtin.package:
    name: mcstrans
    state: absent
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_mcstrans_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_mcstrans_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_mcstrans

class remove_mcstrans {
  package { 'mcstrans':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_mcstrans_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=mcstrans
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_mcstrans_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove mcstrans
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_mcstrans_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove mcstrans
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_mcstrans_removed:def:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_setroubleshoot-plugins_removed" selected="false" severity="low">
            <xccdf-1.2:title>Uninstall setroubleshoot-plugins Package</xccdf-1.2:title>
            <xccdf-1.2:description>The SETroubleshoot plugins are used to analyze SELinux AVC data. The service provides information around configuration errors,
unauthorized intrusions, and other potential errors.
The <html:code>setroubleshoot-plugins</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase setroubleshoot-plugins</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R49</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The SETroubleshoot service is an unnecessary daemon to
have running on a server.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot-plugins_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# CAUTION: This remediation script will remove setroubleshoot-plugins
# from the system, and may remove any packages
# that depend on setroubleshoot-plugins. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "setroubleshoot-plugins" ; then
yum remove -y "setroubleshoot-plugins"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot-plugins_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_setroubleshoot-plugins_removed

- name: 'Uninstall setroubleshoot-plugins Package: Ensure setroubleshoot-plugins is
    removed'
  ansible.builtin.package:
    name: setroubleshoot-plugins
    state: absent
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_setroubleshoot-plugins_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot-plugins_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_setroubleshoot-plugins

class remove_setroubleshoot-plugins {
  package { 'setroubleshoot-plugins':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot-plugins_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=setroubleshoot-plugins
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot-plugins_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove setroubleshoot-plugins
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot-plugins_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove setroubleshoot-plugins
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_setroubleshoot-plugins_removed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_setroubleshoot-plugins_removed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_setroubleshoot-server_removed" selected="false" severity="low">
            <xccdf-1.2:title>Uninstall setroubleshoot-server Package</xccdf-1.2:title>
            <xccdf-1.2:description>The SETroubleshoot service notifies desktop users of SELinux
denials. The service provides information around configuration errors,
unauthorized intrusions, and other potential errors.
The <html:code>setroubleshoot-server</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase setroubleshoot-server</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R49</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The SETroubleshoot service is an unnecessary daemon to have
running on a server.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# CAUTION: This remediation script will remove setroubleshoot-server
# from the system, and may remove any packages
# that depend on setroubleshoot-server. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "setroubleshoot-server" ; then
yum remove -y "setroubleshoot-server"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_setroubleshoot-server_removed

- name: 'Uninstall setroubleshoot-server Package: Ensure setroubleshoot-server is
    removed'
  ansible.builtin.package:
    name: setroubleshoot-server
    state: absent
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_setroubleshoot-server_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_setroubleshoot-server

class remove_setroubleshoot-server {
  package { 'setroubleshoot-server':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot-server_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=setroubleshoot-server
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove setroubleshoot-server
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove setroubleshoot-server
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_setroubleshoot-server_removed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_setroubleshoot-server_removed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_setroubleshoot_removed" selected="false" severity="low">
            <xccdf-1.2:title>Uninstall setroubleshoot Package</xccdf-1.2:title>
            <xccdf-1.2:description>The SETroubleshoot service notifies desktop users of SELinux
denials. The service provides information around configuration errors,
unauthorized intrusions, and other potential errors.
The <html:code>setroubleshoot</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase setroubleshoot</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R49</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.3.1.8</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The SETroubleshoot service is an unnecessary daemon to
have running on a server, especially if
X Windows is removed or disabled.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# CAUTION: This remediation script will remove setroubleshoot
# from the system, and may remove any packages
# that depend on setroubleshoot. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "setroubleshoot" ; then
yum remove -y "setroubleshoot"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_setroubleshoot_removed

- name: 'Uninstall setroubleshoot Package: Ensure setroubleshoot is removed'
  ansible.builtin.package:
    name: setroubleshoot
    state: absent
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_setroubleshoot_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_setroubleshoot

class remove_setroubleshoot {
  package { 'setroubleshoot':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=setroubleshoot
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove setroubleshoot
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_setroubleshoot_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove setroubleshoot
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_setroubleshoot_removed:def:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_coreos_enable_selinux_kernel_argument" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure SELinux Not Disabled in the kernel arguments</xccdf-1.2:title>
            <xccdf-1.2:description>SELinux can be disabled at boot time by disabling it via a kernel argument.
Remove any instances of <html:code>selinux=0</html:code> from the kernel arguments in that
file to prevent SELinux from being disabled at boot.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3(3)(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000233-CTR-000585</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf">APP.4.4.A4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf">SYS.1.6.A3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf">SYS.1.6.A18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf">SYS.1.6.A21</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Disabling a major host protection feature, such as SELinux, at boot time prevents
it from confining system services at boot time.  Further, it increases
the chances that it will remain off during system operation.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-coreos_enable_selinux_kernel_argument:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-coreos_enable_selinux_kernel_argument_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_groupowner_etc_selinux" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Group Who Owns /etc/selinux Directory</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/selinux</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/selinux</html:pre>
</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The ownership of the /etc/selinux directory by the root group is important
because this directory hosts SELinux configuration. Protection of this
directory is critical for system security. Assigning the ownership to root
ensures exclusive control of the SELinux configuration.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="directory_groupowner_etc_selinux" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "root" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="root"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "root is not a defined group on the system"
else
find -P /etc/selinux/ -maxdepth 0 -type d  ! -group root -exec chgrp --no-dereference "$newgroup" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="directory_groupowner_etc_selinux" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_groupowner_etc_selinux
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Check that the root group is defined
  ansible.builtin.getent:
    database: group
    key: root
  ignore_errors: true
  when:
  - '"kernel" in ansible_facts.packages'
  - directory_groupowner_etc_selinux_newgroup is undefined
  tags:
  - configure_strategy
  - directory_groupowner_etc_selinux
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the directory_groupowner_etc_selinux_newgroup variable if root found
  ansible.builtin.set_fact:
    directory_groupowner_etc_selinux_newgroup: root
  when:
  - '"kernel" in ansible_facts.packages'
  - ansible_facts.getent_group["root"] is defined
  tags:
  - configure_strategy
  - directory_groupowner_etc_selinux
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/selinux/
  ansible.builtin.file:
    path: /etc/selinux/
    follow: false
    state: directory
    group: '{{ directory_groupowner_etc_selinux_newgroup }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_groupowner_etc_selinux
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_groupowner_etc_selinux:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_groupowner_etc_selinux_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_owner_etc_selinux" selected="false" severity="medium">
            <xccdf-1.2:title>Verify User Who Owns /etc/selinux Directory</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the owner of <html:code>/etc/selinux</html:code>, run the command:
<html:pre>$ sudo chown root /etc/selinux </html:pre>
</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The ownership of the /etc/selinux directory by the root user is important
because this directory hosts SELinux configuration. Protection of this
directory is critical for system security. Assigning the ownership to root
ensures exclusive control of the SELinux configuration.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="directory_owner_etc_selinux" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
find -P /etc/selinux/ -maxdepth 0 -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="directory_owner_etc_selinux" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_owner_etc_selinux
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the directory_owner_etc_selinux_newown variable if represented by uid
  ansible.builtin.set_fact:
    directory_owner_etc_selinux_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_owner_etc_selinux
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /etc/selinux/
  ansible.builtin.file:
    path: /etc/selinux/
    follow: false
    state: directory
    owner: '{{ directory_owner_etc_selinux_newown }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_owner_etc_selinux
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_owner_etc_selinux:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_owner_etc_selinux_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_permissions_etc_selinux" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Permissions On /etc/selinux Directory</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/selinux</html:code>, run the command: <html:pre>$ sudo chmod 0755 /etc/selinux</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Setting correct permissions on the /etc/selinux directory is important
because this directory hosts SELinux configuration. Protection of this
directory is critical for system security. Restricting the permissions
ensures exclusive control of the SELinux configuration.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="directory_permissions_etc_selinux" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

find -H /etc/selinux/ -maxdepth 0 -perm /u+s,g+ws,o+wt -type d -exec chmod u-s,g-ws,o-wt {} \;

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="directory_permissions_etc_selinux" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - directory_permissions_etc_selinux
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/selinux/ file(s)
  ansible.builtin.command: 'find -P /etc/selinux/ -maxdepth 0 -perm /u+s,g+ws,o+wt  -type
    d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_permissions_etc_selinux
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /etc/selinux/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-ws,o-wt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - directory_permissions_etc_selinux
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_permissions_etc_selinux:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_permissions_etc_selinux_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_etc_sestatus_conf" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Group Who Owns /etc/sestatus.conf File</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/sestatus.conf</html:code>, run the command:
<html:pre>$ sudo chgrp root /etc/sestatus.conf</html:pre>
</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The ownership of the /etc/sestatus.conf file by the root group is important
because this file hosts SELinux configuration. Protection of this
file is critical for system security. Assigning the ownership to root
ensures exclusive control of the SELinux configuration.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_sestatus_conf" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "root" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="root"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "root is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/sestatus.conf" | grep -E -w -q "root"; then
    chgrp --no-dereference "$newgroup" /etc/sestatus.conf
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_sestatus_conf" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_groupowner_etc_sestatus_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Check that the root group is defined
  ansible.builtin.getent:
    database: group
    key: root
  ignore_errors: true
  when:
  - '"kernel" in ansible_facts.packages'
  - file_groupowner_etc_sestatus_conf_newgroup is undefined
  tags:
  - configure_strategy
  - file_groupowner_etc_sestatus_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_etc_sestatus_conf_newgroup variable if root found
  ansible.builtin.set_fact:
    file_groupowner_etc_sestatus_conf_newgroup: root
  when:
  - '"kernel" in ansible_facts.packages'
  - ansible_facts.getent_group["root"] is defined
  tags:
  - configure_strategy
  - file_groupowner_etc_sestatus_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/sestatus.conf
  ansible.builtin.stat:
    path: /etc/sestatus.conf
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupowner_etc_sestatus_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/sestatus.conf
  ansible.builtin.file:
    path: /etc/sestatus.conf
    follow: false
    group: '{{ file_groupowner_etc_sestatus_conf_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupowner_etc_sestatus_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_etc_sestatus_conf:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_etc_sestatus_conf_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_etc_sestatus_conf" selected="false" severity="medium">
            <xccdf-1.2:title>Verify User Who Owns /etc/sestatus.conf File</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the owner of <html:code>/etc/sestatus.conf</html:code>, run the command:
<html:pre>$ sudo chown root /etc/sestatus.conf </html:pre>
</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The ownership of the /etc/sestatus.conf file by the root user is important
because this file hosts SELinux configuration. Protection of this
file is critical for system security. Assigning the ownership to root
ensures exclusive control of the SELinux configuration.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_sestatus_conf" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/sestatus.conf" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/sestatus.conf
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_sestatus_conf" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_owner_etc_sestatus_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_etc_sestatus_conf_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_etc_sestatus_conf_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_etc_sestatus_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/sestatus.conf
  ansible.builtin.stat:
    path: /etc/sestatus.conf
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_etc_sestatus_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/sestatus.conf
  ansible.builtin.file:
    path: /etc/sestatus.conf
    follow: false
    owner: '{{ file_owner_etc_sestatus_conf_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_owner_etc_sestatus_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_etc_sestatus_conf:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_etc_sestatus_conf_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_sestatus_conf" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Permissions On /etc/sestatus.conf File</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/sestatus.conf</html:code>, run the command: <html:pre>$ sudo chmod 0644 /etc/sestatus.conf</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Setting correct permissions on the /etc/sestatus.conf file is important
because this file hosts SELinux configuration. Protection of this
file is critical for system security. Restricting the permissions
ensures exclusive control of the SELinux configuration.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_sestatus_conf" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

chmod u-xs,g-xws,o-xwt /etc/sestatus.conf

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_sestatus_conf" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_permissions_etc_sestatus_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/sestatus.conf
  ansible.builtin.stat:
    path: /etc/sestatus.conf
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_permissions_etc_sestatus_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xws,o-xwt on /etc/sestatus.conf
  ansible.builtin.file:
    path: /etc/sestatus.conf
    mode: u-xs,g-xws,o-xwt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_etc_sestatus_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_sestatus_conf:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_sestatus_conf_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_enable_selinux" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure SELinux Not Disabled in /etc/default/grub</xccdf-1.2:title>
            <xccdf-1.2:description>SELinux can be disabled at boot time by an argument in
<html:code>/etc/default/grub</html:code>.
Remove any instances of <html:code>selinux=0</html:code> from the kernel arguments in that
file to prevent SELinux from being disabled at boot.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3(3)(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.3.1.2</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Disabling a major host protection feature, such as SELinux, at boot time prevents
it from confining system services at boot time.  Further, it increases
the chances that it will remain off during system operation.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#grub2"/>
            <xccdf-1.2:fix id="grub2_enable_selinux" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q grub2-common; }; then

sed -i --follow-symlinks "s/selinux=0//gI" /etc/default/grub /etc/grub2.cfg /etc/grub.d/*
sed -i --follow-symlinks "s/enforcing=0//gI" /etc/default/grub /etc/grub2.cfg /etc/grub.d/*

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="grub2_enable_selinux" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.2
  - NIST-800-171-3.7.2
  - NIST-800-53-AC-3
  - NIST-800-53-AC-3(3)(a)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.6
  - grub2_enable_selinux
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure SELinux Not Disabled in /etc/default/grub - Find /etc/grub.d/ files
  ansible.builtin.find:
    paths:
    - /etc/grub.d/
    follow: true
  register: result_grub_d
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.2
  - NIST-800-171-3.7.2
  - NIST-800-53-AC-3
  - NIST-800-53-AC-3(3)(a)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.6
  - grub2_enable_selinux
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure SELinux Not Disabled in /etc/default/grub - Ensure SELinux Not Disabled
    in /etc/grub.d/ files
  ansible.builtin.replace:
    dest: '{{ item.path }}'
    regexp: (selinux|enforcing)=0
  with_items:
  - '{{ result_grub_d.files }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.2
  - NIST-800-171-3.7.2
  - NIST-800-53-AC-3
  - NIST-800-53-AC-3(3)(a)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.6
  - grub2_enable_selinux
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure SELinux Not Disabled in /etc/default/grub - Check if /etc/grub2.cfg
    exists
  ansible.builtin.stat:
    path: /etc/grub2.cfg
  register: result_grub2_cfg_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.2
  - NIST-800-171-3.7.2
  - NIST-800-53-AC-3
  - NIST-800-53-AC-3(3)(a)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.6
  - grub2_enable_selinux
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure SELinux Not Disabled in /etc/default/grub - Check if /etc/default/grub
    exists
  ansible.builtin.stat:
    path: /etc/default/grub
  register: result_default_grub_present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.2
  - NIST-800-171-3.7.2
  - NIST-800-53-AC-3
  - NIST-800-53-AC-3(3)(a)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.6
  - grub2_enable_selinux
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure SELinux Not Disabled in /etc/default/grub - Ensure SELinux Not Disabled
    in /etc/grub2.cfg
  ansible.builtin.replace:
    dest: /etc/grub2.cfg
    regexp: (selinux|enforcing)=0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  - result_grub2_cfg_present.stat.exists
  tags:
  - NIST-800-171-3.1.2
  - NIST-800-171-3.7.2
  - NIST-800-53-AC-3
  - NIST-800-53-AC-3(3)(a)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.6
  - grub2_enable_selinux
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure SELinux Not Disabled in /etc/default/grub - Ensure SELinux Not Disabled
    in /etc/default/grub
  ansible.builtin.replace:
    dest: /etc/default/grub
    regexp: (selinux|enforcing)=0
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  - result_default_grub_present.stat.exists
  tags:
  - NIST-800-171-3.1.2
  - NIST-800-171-3.7.2
  - NIST-800-53-AC-3
  - NIST-800-53-AC-3(3)(a)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.6
  - grub2_enable_selinux
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_enable_selinux:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_enable_selinux_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_selinux_all_devicefiles_labeled" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure No Device Files are Unlabeled by SELinux</xccdf-1.2:title>
            <xccdf-1.2:description>Device files, which are used for communication with important system
resources, should be labeled with proper SELinux types. If any device files
carry the SELinux type <html:code>device_t</html:code> or <html:code>unlabeled_t</html:code>, report the
bug so that policy can be corrected. Supply information about what the
device is and what programs use it.
<html:br/><html:br/>
To check for incorrectly labeled device files, run following commands:
<html:pre>$ sudo find /dev -context *:device_t:* \( -type c -o -type b \) -printf "%p %Z\n"</html:pre>
<html:pre>$ sudo find /dev -context *:unlabeled_t:* \( -type c -o -type b \) -printf "%p %Z\n"</html:pre>
It should produce no output in a well-configured system.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Automatic remediation of this control is not available. The remediation
can be achieved by amending SELinux policy.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI06.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3(3)(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If a device file carries the SELinux type <html:code>device_t</html:code> or
<html:code>unlabeled_t</html:code>, then SELinux cannot properly restrict access to the
device file.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-selinux_all_devicefiles_labeled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-selinux_all_devicefiles_labeled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_selinux_confinement_of_daemons" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure No Daemons are Unconfined by SELinux</xccdf-1.2:title>
            <xccdf-1.2:description>Daemons for which the SELinux policy does not contain rules will inherit the
context of the parent process. Because daemons are launched during
startup and descend from the <html:code>init</html:code> process, they inherit the <html:code>unconfined_service_t</html:code> context.
<html:br/>
<html:br/>
To check for unconfined daemons, run the following command:
<html:pre>$ sudo ps -eZ | grep "unconfined_service_t"</html:pre>
It should produce no output in a well-configured system.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Automatic remediation of this control is not available. Remediation
can be achieved by amending SELinux policy or stopping the unconfined
daemons as outlined above.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3(3)(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Daemons which run with the <html:code>unconfined_service_t</html:code> context may cause AVC denials,
or allow privileges that the daemon does not require.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-selinux_confinement_of_daemons:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-selinux_confinement_of_daemons_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_selinux_context_elevation_for_sudo" selected="false" severity="medium">
            <xccdf-1.2:title>Elevate The SELinux Context When An Administrator Calls The Sudo Command</xccdf-1.2:title>
            <xccdf-1.2:description>Configure the operating system to elevate the SELinux context when an administrator calls
the sudo command.
Edit a file in the /etc/sudoers.d directory with the following command:
<html:pre>sudo visudo -f /etc/sudoers.d/<html:i>CUSTOM_FILE</html:i></html:pre>
Use the following example to build the <html:i>CUSTOM_FILE</html:i> in the /etc/sudoers.d directory
to allow any administrator belonging to a designated sudoers admin group to elevate their
SELinux context with the use of the sudo command:
<html:pre>%wheel ALL=(ALL) TYPE=sysadm_t ROLE=sysadm_r ALL</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(10)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000324-GPOS-00125</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010455</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-272484r1134875_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Preventing non-privileged users from executing privileged functions mitigates
the risk that unauthorized individuals or processes may gain unnecessary access
to information or privileges.
<html:br/><html:br/>
Privileged functions include, for example,
establishing accounts, performing system integrity checks, or administering
cryptographic key management activities. Non-privileged users are individuals
who do not possess appropriate authorizations. Circumventing intrusion detection
and prevention mechanisms or malicious code protection mechanisms are examples
of privileged functions that require protection from non-privileged users.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-selinux_context_elevation_for_sudo:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-selinux_context_elevation_for_sudo_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_selinux_not_disabled" selected="false" severity="high">
            <xccdf-1.2:title>Ensure SELinux is Not Disabled</xccdf-1.2:title>
            <xccdf-1.2:description>The SELinux state should be set to <html:code>enforcing</html:code> or <html:code>permissive</html:code> at system boot
time. In the file <html:code>/etc/selinux/config</html:code>, add or correct the following line to configure
the system to boot into enforcing or permissive mode:
<html:pre>SELINUX=enforcing</html:pre>
OR
<html:pre>SELINUX=permissive</html:pre>
If SELinux is currently disabled or not configured, ensure that all files have correct SELinux
labels by running:
<html:pre>fixfiles onboot</html:pre>
Then reboot the system.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">The automated remediation checks the SELinux configuration in /etc/selinux/config.
If SELinux is already set to "enforcing" or "permissive", the current state is preserved
and no changes are made. If SELinux is "disabled" or not configured, the remediation will
adopt a conservative approach and set it to "permissive" in order to avoid any system
disruption and give the administrator the opportunity to assess the impact and necessary
efforts before setting it to "enforcing", which is strongly recommended.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.3.1.4</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Running SELinux in disabled mode is strongly discouraged. It prevents enforcing the SELinux
controls without a system reboot. It also avoids labeling any persistent objects such as
files, making it difficult to enable SELinux in the future.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="selinux_not_disabled" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# Check current SELinux state in config file
selinux_current_state=""
if [ -f "/etc/selinux/config" ]; then
    selinux_current_state=$(grep -oP '^\s*SELINUX=\K(enforcing|permissive|disabled)' /etc/selinux/config || true)
fi

# Only remediate if SELinux is disabled or not configured
# If already set to enforcing or permissive, it's compliant - preserve the current state
if [ "$selinux_current_state" != "enforcing" ] &amp;&amp; [ "$selinux_current_state" != "permissive" ]; then
    # SELinux is disabled or not configured, set to permissive as a conservative approach
    if [ -e "/etc/selinux/config" ] ; then
    
    LC_ALL=C sed -i "/^SELINUX=/Id" "/etc/selinux/config"
else
    touch "/etc/selinux/config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/selinux/config"

cp "/etc/selinux/config" "/etc/selinux/config.bak"
# Insert at the end of the file
printf '%s\n' "SELINUX=permissive" &gt;&gt; "/etc/selinux/config"
# Clean up after ourselves.
rm "/etc/selinux/config.bak"
    fixfiles onboot
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="selinux_not_disabled" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - high_severity
  - low_complexity
  - low_disruption
  - reboot_required
  - restrict_strategy
  - selinux_not_disabled

- name: Ensure SELinux is Not Disabled - Check current SELinux configuration
  ansible.builtin.command:
    cmd: grep -oP '^\s*SELINUX=\K(enforcing|permissive|disabled)' /etc/selinux/config
  register: selinux_config_state
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - high_severity
  - low_complexity
  - low_disruption
  - reboot_required
  - restrict_strategy
  - selinux_not_disabled

- name: Ensure SELinux is Not Disabled - Set SELinux state to permissive if disabled
    or not configured
  block:

  - name: Ensure SELinux is Not Disabled
    block:

    - name: Check for duplicate values
      ansible.builtin.lineinfile:
        path: /etc/selinux/config
        create: true
        regexp: (?i)^SELINUX=
        state: absent
      check_mode: true
      changed_when: false
      register: dupes

    - name: Deduplicate values from /etc/selinux/config
      ansible.builtin.lineinfile:
        path: /etc/selinux/config
        create: true
        regexp: (?i)^SELINUX=
        state: absent
      when: dupes.found is defined and dupes.found &gt; 1

    - name: Insert correct line to /etc/selinux/config
      ansible.builtin.lineinfile:
        path: /etc/selinux/config
        create: true
        regexp: (?i)^SELINUX=
        line: SELINUX=permissive
        state: present

  - name: Ensure SELinux is Not Disabled - Mark system to relabel SELinux on next
      boot
    ansible.builtin.file:
      path: /.autorelabel
      state: touch
      access_time: preserve
      modification_time: preserve
  when:
  - '"kernel" in ansible_facts.packages'
  - selinux_config_state.stdout not in ['enforcing', 'permissive']
  tags:
  - high_severity
  - low_complexity
  - low_disruption
  - reboot_required
  - restrict_strategy
  - selinux_not_disabled
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-selinux_not_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-selinux_not_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_selinux_policytype" selected="false" severity="medium">
            <xccdf-1.2:title>Configure SELinux Policy</xccdf-1.2:title>
            <xccdf-1.2:description>The SELinux <html:code>targeted</html:code> policy is appropriate for
general-purpose desktops and servers, as well as systems in many other roles.
To configure the system to use this policy, add or correct the following line
in <html:code>/etc/selinux/config</html:code>:
<html:pre>SELINUXTYPE=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" use="legacy"/></html:pre>
Other policies, such as <html:code>mls</html:code>, provide additional security labeling
and greater confinement but are not compatible with many general-purpose
use cases.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3(3)(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(21)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_MOF_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000445-GPOS-00199</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000233-CTR-000585</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R46</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R64</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf">APP.4.4.A4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf">SYS.1.6.A3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf">SYS.1.6.A18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf">SYS.1.6.A21</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.3.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010450</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230282r958944_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Setting the SELinux policy to <html:code>targeted</html:code> or a more specialized policy
ensures the system will confine processes that are likely to be
targeted for exploitation, such as network or system services.
<html:br/><html:br/>
Note: During the development or debugging of SELinux modules, it is common to
temporarily place non-production systems in <html:code>permissive</html:code> mode. In such
temporary cases, SELinux policies should be developed, and once work
is completed, the system should be reconfigured to
<html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" use="legacy"/></html:code>.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="selinux_policytype" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_selinux_policy_name='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" use="legacy"/>'

if [ -e "/etc/selinux/config" ] ; then
    
    LC_ALL=C sed -i "/^SELINUXTYPE=/Id" "/etc/selinux/config"
else
    touch "/etc/selinux/config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/selinux/config"

cp "/etc/selinux/config" "/etc/selinux/config.bak"
# Insert at the end of the file
printf '%s\n' "SELINUXTYPE=$var_selinux_policy_name" &gt;&gt; "/etc/selinux/config"
# Clean up after ourselves.
rm "/etc/selinux/config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="selinux_policytype" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010450
  - NIST-800-171-3.1.2
  - NIST-800-171-3.7.2
  - NIST-800-53-AC-3
  - NIST-800-53-AC-3(3)(a)
  - NIST-800-53-AU-9
  - NIST-800-53-SC-7(21)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.6
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - selinux_policytype
- name: XCCDF Value var_selinux_policy_name # promote to variable
  set_fact:
    var_selinux_policy_name: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinux_policy_name" use="legacy"/>
  tags:
    - always

- name: Configure SELinux Policy
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/selinux/config
      create: true
      regexp: (?i)^SELINUXTYPE=
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/selinux/config
    ansible.builtin.lineinfile:
      path: /etc/selinux/config
      create: true
      regexp: (?i)^SELINUXTYPE=
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/selinux/config
    ansible.builtin.lineinfile:
      path: /etc/selinux/config
      create: true
      regexp: (?i)^SELINUXTYPE=
      line: SELINUXTYPE={{ var_selinux_policy_name }}
      state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010450
  - NIST-800-171-3.1.2
  - NIST-800-171-3.7.2
  - NIST-800-53-AC-3
  - NIST-800-53-AC-3(3)(a)
  - NIST-800-53-AU-9
  - NIST-800-53-SC-7(21)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.6
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - selinux_policytype
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_selinux_policy_name:var:1" value-id="xccdf_org.ssgproject.content_value_var_selinux_policy_name"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-selinux_policytype:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-selinux_policytype_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_selinux_state" selected="false" severity="high">
            <xccdf-1.2:title>Ensure SELinux State is Enforcing</xccdf-1.2:title>
            <xccdf-1.2:description>The SELinux state should be set to <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinux_state" use="legacy"/></html:code> at
system boot time.  In the file <html:code>/etc/selinux/config</html:code>, add or correct the
following line to configure the system to boot into enforcing mode:
<html:pre>SELINUX=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinux_state" use="legacy"/></html:pre>
Ensure that all files have correct SELinux labels by running:
<html:pre>fixfiles onboot</html:pre>
Then reboot the system.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3(3)(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-7(21)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_MOF_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000445-GPOS-00199</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000134-GPOS-00068</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R37</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R79</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf">APP.4.4.A4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf">SYS.1.6.A3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf">SYS.1.6.A18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf">SYS.1.6.A21</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">1.3.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010170</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230240r1017059_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Setting the SELinux state to enforcing ensures SELinux is able to confine
potentially compromised processes to the security policy, which is designed to
prevent them from causing damage to the system or further elevating their
privileges.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="selinux_state" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_selinux_state='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinux_state" use="legacy"/>'


if [ -e "/etc/selinux/config" ] ; then
    
    LC_ALL=C sed -i "/^SELINUX=/Id" "/etc/selinux/config"
else
    touch "/etc/selinux/config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/selinux/config"

cp "/etc/selinux/config" "/etc/selinux/config.bak"
# Insert at the end of the file
printf '%s\n' "SELINUX=$var_selinux_state" &gt;&gt; "/etc/selinux/config"
# Clean up after ourselves.
rm "/etc/selinux/config.bak"

fixfiles onboot

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="selinux_state" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010170
  - NIST-800-171-3.1.2
  - NIST-800-171-3.7.2
  - NIST-800-53-AC-3
  - NIST-800-53-AC-3(3)(a)
  - NIST-800-53-AU-9
  - NIST-800-53-SC-7(21)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.6
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy
  - selinux_state
- name: XCCDF Value var_selinux_state # promote to variable
  set_fact:
    var_selinux_state: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinux_state" use="legacy"/>
  tags:
    - always

- name: Ensure SELinux State is Enforcing - Check current SELinux state
  ansible.builtin.command:
    cmd: getenforce
  register: current_selinux_state
  check_mode: false
  changed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010170
  - NIST-800-171-3.1.2
  - NIST-800-171-3.7.2
  - NIST-800-53-AC-3
  - NIST-800-53-AC-3(3)(a)
  - NIST-800-53-AU-9
  - NIST-800-53-SC-7(21)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.6
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy
  - selinux_state

- name: Ensure SELinux State is Enforcing
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/selinux/config
      create: true
      regexp: (?i)^SELINUX=
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/selinux/config
    ansible.builtin.lineinfile:
      path: /etc/selinux/config
      create: true
      regexp: (?i)^SELINUX=
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/selinux/config
    ansible.builtin.lineinfile:
      path: /etc/selinux/config
      create: true
      regexp: (?i)^SELINUX=
      line: SELINUX={{ var_selinux_state }}
      state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010170
  - NIST-800-171-3.1.2
  - NIST-800-171-3.7.2
  - NIST-800-53-AC-3
  - NIST-800-53-AC-3(3)(a)
  - NIST-800-53-AU-9
  - NIST-800-53-SC-7(21)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.6
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy
  - selinux_state

- name: Ensure SELinux State is Enforcing - Mark system to relabel SELinux on next
    boot
  ansible.builtin.file:
    path: /.autorelabel
    state: touch
    access_time: preserve
    modification_time: preserve
  when:
  - '"kernel" in ansible_facts.packages'
  - current_selinux_state.stdout | lower != var_selinux_state
  tags:
  - DISA-STIG-RHEL-08-010170
  - NIST-800-171-3.1.2
  - NIST-800-171-3.7.2
  - NIST-800-53-AC-3
  - NIST-800-53-AC-3(3)(a)
  - NIST-800-53-AU-9
  - NIST-800-53-SC-7(21)
  - PCI-DSSv4-1.2
  - PCI-DSSv4-1.2.6
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy
  - selinux_state
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_selinux_state:var:1" value-id="xccdf_org.ssgproject.content_value_var_selinux_state"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-selinux_state:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-selinux_state_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_selinux_user_login_roles" selected="false" severity="medium">
            <xccdf-1.2:title>Map System Users To The Appropriate SELinux Role</xccdf-1.2:title>
            <xccdf-1.2:description>Configure the operating system to prevent non-privileged users from executing
privileged functions to include disabling, circumventing, or altering
implemented security safeguards/countermeasures. All administrators must be
mapped to the <html:code>sysadm_u</html:code> or <html:code>staff_u</html:code> users with the
appropriate domains (<html:code>sysadm_t</html:code> and <html:code>staff_t</html:code>).
<html:pre>$ sudo semanage login -m -s sysadm_u <html:i>USER</html:i></html:pre> or
<html:pre>$ sudo semanage login -m -s staff_u <html:i>USER</html:i></html:pre>
<html:br/><html:br/>
All authorized non-administrative
users must be mapped to the <html:code>user_u</html:code> role or the appropriate domain
(user_t).
<html:pre>$ sudo semanage login -m -s user_u <html:i>USER</html:i></html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000324-GPOS-00125</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040400</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-254520r1069331_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Preventing non-privileged users from executing privileged functions mitigates
the risk that unauthorized individuals or processes may gain unnecessary access
to information or privileges.
<html:br/><html:br/>
Privileged functions include, for example,
establishing accounts, performing system integrity checks, or administering
cryptographic key management activities. Non-privileged users are individuals
who do not possess appropriate authorizations. Circumventing intrusion detection
and prevention mechanisms or malicious code protection mechanisms are examples
of privileged functions that require protection from non-privileged users.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-selinux_user_login_roles_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_selinux-booleans">
            <xccdf-1.2:title>SELinux - Booleans</xccdf-1.2:title>
            <xccdf-1.2:description>Enable or Disable runtime customization of SELinux system policies
without having to reload or recompile the SELinux policy.</xccdf-1.2:description>
            <xccdf-1.2:platform idref="#bootc_or_osbuild_or_selinux"/>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_abrt_anon_write" type="boolean">
              <xccdf-1.2:title>abrt_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_abrt_handle_event" type="boolean">
              <xccdf-1.2:title>abrt_handle_event SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_abrt_upload_watch_anon_write" type="boolean">
              <xccdf-1.2:title>abrt_upload_watch_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_antivirus_can_scan_system" type="boolean">
              <xccdf-1.2:title>antivirus_can_scan_system SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_antivirus_use_jit" type="boolean">
              <xccdf-1.2:title>antivirus_use_jit SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_auditadm_exec_content" type="boolean">
              <xccdf-1.2:title>auditadm_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_authlogin_nsswitch_use_ldap" type="boolean">
              <xccdf-1.2:title>authlogin_nsswitch_use_ldap SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_authlogin_radius" type="boolean">
              <xccdf-1.2:title>authlogin_radius SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_authlogin_yubikey" type="boolean">
              <xccdf-1.2:title>authlogin_yubikey SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_awstats_purge_apache_log_files" type="boolean">
              <xccdf-1.2:title>awstats_purge_apache_log_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_boinc_execmem" type="boolean">
              <xccdf-1.2:title>boinc_execmem SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_cdrecord_read_content" type="boolean">
              <xccdf-1.2:title>cdrecord_read_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_cluster_can_network_connect" type="boolean">
              <xccdf-1.2:title>cluster_can_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_cluster_manage_all_files" type="boolean">
              <xccdf-1.2:title>cluster_manage_all_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_cluster_use_execmem" type="boolean">
              <xccdf-1.2:title>cluster_use_execmem SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_cobbler_anon_write" type="boolean">
              <xccdf-1.2:title>cobbler_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_cobbler_can_network_connect" type="boolean">
              <xccdf-1.2:title>cobbler_can_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_cobbler_use_cifs" type="boolean">
              <xccdf-1.2:title>cobbler_use_cifs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_cobbler_use_nfs" type="boolean">
              <xccdf-1.2:title>cobbler_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_collectd_tcp_network_connect" type="boolean">
              <xccdf-1.2:title>collectd_tcp_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_condor_tcp_network_connect" type="boolean">
              <xccdf-1.2:title>condor_tcp_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_conman_can_network" type="boolean">
              <xccdf-1.2:title>conman_can_network SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_container_connect_any" type="boolean">
              <xccdf-1.2:title>container_connect_any SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_cron_can_relabel" type="boolean">
              <xccdf-1.2:title>cron_can_relabel SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_cron_system_cronjob_use_shares" type="boolean">
              <xccdf-1.2:title>cron_system_cronjob_use_shares SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_cron_userdomain_transition" type="boolean">
              <xccdf-1.2:title>cron_userdomain_transition SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_cups_execmem" type="boolean">
              <xccdf-1.2:title>cups_execmem SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_cvs_read_shadow" type="boolean">
              <xccdf-1.2:title>cvs_read_shadow SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_daemons_dump_core" type="boolean">
              <xccdf-1.2:title>daemons_dump_core SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_daemons_enable_cluster_mode" type="boolean">
              <xccdf-1.2:title>daemons_enable_cluster_mode SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_daemons_use_tcp_wrapper" type="boolean">
              <xccdf-1.2:title>daemons_use_tcp_wrapper SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_daemons_use_tty" type="boolean">
              <xccdf-1.2:title>daemons_use_tty SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_dbadm_exec_content" type="boolean">
              <xccdf-1.2:title>dbadm_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_dbadm_manage_user_files" type="boolean">
              <xccdf-1.2:title>dbadm_manage_user_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_dbadm_read_user_files" type="boolean">
              <xccdf-1.2:title>dbadm_read_user_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_deny_execmem" type="boolean">
              <xccdf-1.2:title>deny_execmem SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_deny_ptrace" type="boolean">
              <xccdf-1.2:title>deny_ptrace SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_dhcpc_exec_iptables" type="boolean">
              <xccdf-1.2:title>dhcpc_exec_iptables SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_dhcpd_use_ldap" type="boolean">
              <xccdf-1.2:title>dhcpd_use_ldap SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_domain_fd_use" type="boolean">
              <xccdf-1.2:title>domain_fd_use SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_domain_kernel_load_modules" type="boolean">
              <xccdf-1.2:title>domain_kernel_load_modules SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_entropyd_use_audio" type="boolean">
              <xccdf-1.2:title>entropyd_use_audio SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_exim_can_connect_db" type="boolean">
              <xccdf-1.2:title>exim_can_connect_db SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_exim_manage_user_files" type="boolean">
              <xccdf-1.2:title>exim_manage_user_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_exim_read_user_files" type="boolean">
              <xccdf-1.2:title>exim_read_user_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_fcron_crond" type="boolean">
              <xccdf-1.2:title>fcron_crond SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_fenced_can_network_connect" type="boolean">
              <xccdf-1.2:title>fenced_can_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_fenced_can_ssh" type="boolean">
              <xccdf-1.2:title>fenced_can_ssh SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_fips_mode" type="boolean">
              <xccdf-1.2:title>fips_mode SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_ftpd_anon_write" type="boolean">
              <xccdf-1.2:title>ftpd_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_ftpd_connect_all_unreserved" type="boolean">
              <xccdf-1.2:title>ftpd_connect_all_unreserved SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_ftpd_connect_db" type="boolean">
              <xccdf-1.2:title>ftpd_connect_db SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_ftpd_full_access" type="boolean">
              <xccdf-1.2:title>ftpd_full_access SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_ftpd_use_cifs" type="boolean">
              <xccdf-1.2:title>ftpd_use_cifs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_ftpd_use_fusefs" type="boolean">
              <xccdf-1.2:title>ftpd_use_fusefs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_ftpd_use_nfs" type="boolean">
              <xccdf-1.2:title>ftpd_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_ftpd_use_passive_mode" type="boolean">
              <xccdf-1.2:title>ftpd_use_passive_mode SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_git_cgi_enable_homedirs" type="boolean">
              <xccdf-1.2:title>git_cgi_enable_homedirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_git_cgi_use_cifs" type="boolean">
              <xccdf-1.2:title>git_cgi_use_cifs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_git_cgi_use_nfs" type="boolean">
              <xccdf-1.2:title>git_cgi_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_git_session_bind_all_unreserved_ports" type="boolean">
              <xccdf-1.2:title>git_session_bind_all_unreserved_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_git_session_users" type="boolean">
              <xccdf-1.2:title>git_session_users SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_git_system_enable_homedirs" type="boolean">
              <xccdf-1.2:title>git_system_enable_homedirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_git_system_use_cifs" type="boolean">
              <xccdf-1.2:title>git_system_use_cifs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_git_system_use_nfs" type="boolean">
              <xccdf-1.2:title>git_system_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_gitosis_can_sendmail" type="boolean">
              <xccdf-1.2:title>gitosis_can_sendmail SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_glance_api_can_network" type="boolean">
              <xccdf-1.2:title>glance_api_can_network SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_glance_use_execmem" type="boolean">
              <xccdf-1.2:title>glance_use_execmem SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_glance_use_fusefs" type="boolean">
              <xccdf-1.2:title>glance_use_fusefs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_global_ssp" type="boolean">
              <xccdf-1.2:title>global_ssp SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_gluster_anon_write" type="boolean">
              <xccdf-1.2:title>gluster_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_gluster_export_all_ro" type="boolean">
              <xccdf-1.2:title>gluster_export_all_ro SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_gluster_export_all_rw" type="boolean">
              <xccdf-1.2:title>gluster_export_all_rw SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_gpg_web_anon_write" type="boolean">
              <xccdf-1.2:title>gpg_web_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_gssd_read_tmp" type="boolean">
              <xccdf-1.2:title>gssd_read_tmp SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_guest_exec_content" type="boolean">
              <xccdf-1.2:title>guest_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_haproxy_connect_any" type="boolean">
              <xccdf-1.2:title>haproxy_connect_any SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_anon_write" type="boolean">
              <xccdf-1.2:title>httpd_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_builtin_scripting" type="boolean">
              <xccdf-1.2:title>httpd_builtin_scripting SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_can_check_spam" type="boolean">
              <xccdf-1.2:title>httpd_can_check_spam SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_can_connect_ftp" type="boolean">
              <xccdf-1.2:title>httpd_can_connect_ftp SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_can_connect_ldap" type="boolean">
              <xccdf-1.2:title>httpd_can_connect_ldap SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_can_connect_mythtv" type="boolean">
              <xccdf-1.2:title>httpd_can_connect_mythtv SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_can_connect_zabbix" type="boolean">
              <xccdf-1.2:title>httpd_can_connect_zabbix SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_can_network_connect" type="boolean">
              <xccdf-1.2:title>httpd_can_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_can_network_connect_cobbler" type="boolean">
              <xccdf-1.2:title>httpd_can_network_connect_cobbler SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_can_network_connect_db" type="boolean">
              <xccdf-1.2:title>httpd_can_network_connect_db SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_can_network_memcache" type="boolean">
              <xccdf-1.2:title>httpd_can_network_memcache SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_can_network_relay" type="boolean">
              <xccdf-1.2:title>httpd_can_network_relay SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_can_sendmail" type="boolean">
              <xccdf-1.2:title>httpd_can_sendmail SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_dbus_avahi" type="boolean">
              <xccdf-1.2:title>httpd_dbus_avahi SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_dbus_sssd" type="boolean">
              <xccdf-1.2:title>httpd_dbus_sssd SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_dontaudit_search_dirs" type="boolean">
              <xccdf-1.2:title>httpd_dontaudit_search_dirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_enable_cgi" type="boolean">
              <xccdf-1.2:title>httpd_enable_cgi SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_enable_ftp_server" type="boolean">
              <xccdf-1.2:title>httpd_enable_ftp_server SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_enable_homedirs" type="boolean">
              <xccdf-1.2:title>httpd_enable_homedirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_execmem" type="boolean">
              <xccdf-1.2:title>httpd_execmem SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_graceful_shutdown" type="boolean">
              <xccdf-1.2:title>httpd_graceful_shutdown SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_manage_ipa" type="boolean">
              <xccdf-1.2:title>httpd_manage_ipa SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_mod_auth_ntlm_winbind" type="boolean">
              <xccdf-1.2:title>httpd_mod_auth_ntlm_winbind SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_mod_auth_pam" type="boolean">
              <xccdf-1.2:title>httpd_mod_auth_pam SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_read_user_content" type="boolean">
              <xccdf-1.2:title>httpd_read_user_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_run_ipa" type="boolean">
              <xccdf-1.2:title>httpd_run_ipa SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_run_preupgrade" type="boolean">
              <xccdf-1.2:title>httpd_run_preupgrade SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_run_stickshift" type="boolean">
              <xccdf-1.2:title>httpd_run_stickshift SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_serve_cobbler_files" type="boolean">
              <xccdf-1.2:title>httpd_serve_cobbler_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_setrlimit" type="boolean">
              <xccdf-1.2:title>httpd_setrlimit SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_ssi_exec" type="boolean">
              <xccdf-1.2:title>httpd_ssi_exec SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_sys_script_anon_write" type="boolean">
              <xccdf-1.2:title>httpd_sys_script_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_tmp_exec" type="boolean">
              <xccdf-1.2:title>httpd_tmp_exec SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_tty_comm" type="boolean">
              <xccdf-1.2:title>httpd_tty_comm SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_unified" type="boolean">
              <xccdf-1.2:title>httpd_unified SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_use_cifs" type="boolean">
              <xccdf-1.2:title>httpd_use_cifs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_use_fusefs" type="boolean">
              <xccdf-1.2:title>httpd_use_fusefs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_use_gpg" type="boolean">
              <xccdf-1.2:title>httpd_use_gpg SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_use_nfs" type="boolean">
              <xccdf-1.2:title>httpd_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_use_openstack" type="boolean">
              <xccdf-1.2:title>httpd_use_openstack SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_use_sasl" type="boolean">
              <xccdf-1.2:title>httpd_use_sasl SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_verify_dns" type="boolean">
              <xccdf-1.2:title>httpd_verify_dns SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_icecast_use_any_tcp_ports" type="boolean">
              <xccdf-1.2:title>icecast_use_any_tcp_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_irc_use_any_tcp_ports" type="boolean">
              <xccdf-1.2:title>irc_use_any_tcp_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_irssi_use_full_network" type="boolean">
              <xccdf-1.2:title>irssi_use_full_network SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_kdumpgui_run_bootloader" type="boolean">
              <xccdf-1.2:title>kdumpgui_run_bootloader SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_kerberos_enabled" type="boolean">
              <xccdf-1.2:title>kerberos_enabled SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_ksmtuned_use_cifs" type="boolean">
              <xccdf-1.2:title>ksmtuned_use_cifs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_ksmtuned_use_nfs" type="boolean">
              <xccdf-1.2:title>ksmtuned_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_logadm_exec_content" type="boolean">
              <xccdf-1.2:title>logadm_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_logging_syslogd_can_sendmail" type="boolean">
              <xccdf-1.2:title>logging_syslogd_can_sendmail SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_logging_syslogd_run_nagios_plugins" type="boolean">
              <xccdf-1.2:title>logging_syslogd_run_nagios_plugins SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_logging_syslogd_use_tty" type="boolean">
              <xccdf-1.2:title>logging_syslogd_use_tty SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_login_console_enabled" type="boolean">
              <xccdf-1.2:title>login_console_enabled SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_logrotate_use_nfs" type="boolean">
              <xccdf-1.2:title>logrotate_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_logwatch_can_network_connect_mail" type="boolean">
              <xccdf-1.2:title>logwatch_can_network_connect_mail SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_lsmd_plugin_connect_any" type="boolean">
              <xccdf-1.2:title>lsmd_plugin_connect_any SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mailman_use_fusefs" type="boolean">
              <xccdf-1.2:title>mailman_use_fusefs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mcelog_client" type="boolean">
              <xccdf-1.2:title>mcelog_client SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mcelog_exec_scripts" type="boolean">
              <xccdf-1.2:title>mcelog_exec_scripts SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mcelog_foreground" type="boolean">
              <xccdf-1.2:title>mcelog_foreground SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mcelog_server" type="boolean">
              <xccdf-1.2:title>mcelog_server SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_minidlna_read_generic_user_content" type="boolean">
              <xccdf-1.2:title>minidlna_read_generic_user_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mmap_low_allowed" type="boolean">
              <xccdf-1.2:title>mmap_low_allowed SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mock_enable_homedirs" type="boolean">
              <xccdf-1.2:title>mock_enable_homedirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mount_anyfile" type="boolean">
              <xccdf-1.2:title>mount_anyfile SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mozilla_plugin_bind_unreserved_ports" type="boolean">
              <xccdf-1.2:title>mozilla_plugin_bind_unreserved_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mozilla_plugin_can_network_connect" type="boolean">
              <xccdf-1.2:title>mozilla_plugin_can_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mozilla_plugin_use_bluejeans" type="boolean">
              <xccdf-1.2:title>mozilla_plugin_use_bluejeans SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mozilla_plugin_use_gps" type="boolean">
              <xccdf-1.2:title>mozilla_plugin_use_gps SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mozilla_plugin_use_spice" type="boolean">
              <xccdf-1.2:title>mozilla_plugin_use_spice SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mozilla_read_content" type="boolean">
              <xccdf-1.2:title>mozilla_read_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mpd_enable_homedirs" type="boolean">
              <xccdf-1.2:title>mpd_enable_homedirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mpd_use_cifs" type="boolean">
              <xccdf-1.2:title>mpd_use_cifs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mpd_use_nfs" type="boolean">
              <xccdf-1.2:title>mpd_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mplayer_execstack" type="boolean">
              <xccdf-1.2:title>mplayer_execstack SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_mysql_connect_any" type="boolean">
              <xccdf-1.2:title>mysql_connect_any SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_nagios_run_pnp4nagios" type="boolean">
              <xccdf-1.2:title>nagios_run_pnp4nagios SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_nagios_run_sudo" type="boolean">
              <xccdf-1.2:title>nagios_run_sudo SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_named_tcp_bind_http_port" type="boolean">
              <xccdf-1.2:title>named_tcp_bind_http_port SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_named_write_master_zones" type="boolean">
              <xccdf-1.2:title>named_write_master_zones SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_neutron_can_network" type="boolean">
              <xccdf-1.2:title>neutron_can_network SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_nfs_export_all_ro" type="boolean">
              <xccdf-1.2:title>nfs_export_all_ro SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_nfs_export_all_rw" type="boolean">
              <xccdf-1.2:title>nfs_export_all_rw SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_nfsd_anon_write" type="boolean">
              <xccdf-1.2:title>nfsd_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_nis_enabled" type="boolean">
              <xccdf-1.2:title>nis_enabled SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_nscd_use_shm" type="boolean">
              <xccdf-1.2:title>nscd_use_shm SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_openshift_use_nfs" type="boolean">
              <xccdf-1.2:title>openshift_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_openvpn_can_network_connect" type="boolean">
              <xccdf-1.2:title>openvpn_can_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_openvpn_enable_homedirs" type="boolean">
              <xccdf-1.2:title>openvpn_enable_homedirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_openvpn_run_unconfined" type="boolean">
              <xccdf-1.2:title>openvpn_run_unconfined SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_pcp_bind_all_unreserved_ports" type="boolean">
              <xccdf-1.2:title>pcp_bind_all_unreserved_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_pcp_read_generic_logs" type="boolean">
              <xccdf-1.2:title>pcp_read_generic_logs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_piranha_lvs_can_network_connect" type="boolean">
              <xccdf-1.2:title>piranha_lvs_can_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_polipo_connect_all_unreserved" type="boolean">
              <xccdf-1.2:title>polipo_connect_all_unreserved SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_polipo_session_bind_all_unreserved_ports" type="boolean">
              <xccdf-1.2:title>polipo_session_bind_all_unreserved_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_polipo_session_users" type="boolean">
              <xccdf-1.2:title>polipo_session_users SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_polipo_use_cifs" type="boolean">
              <xccdf-1.2:title>polipo_use_cifs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_polipo_use_nfs" type="boolean">
              <xccdf-1.2:title>polipo_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_polyinstantiation_enabled" type="boolean">
              <xccdf-1.2:title>polyinstantiation_enabled SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_postfix_local_write_mail_spool" type="boolean">
              <xccdf-1.2:title>postfix_local_write_mail_spool SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_postgresql_can_rsync" type="boolean">
              <xccdf-1.2:title>postgresql_can_rsync SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_postgresql_selinux_transmit_client_label" type="boolean">
              <xccdf-1.2:title>postgresql_selinux_transmit_client_label SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_postgresql_selinux_unconfined_dbadm" type="boolean">
              <xccdf-1.2:title>postgresql_selinux_unconfined_dbadm SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_postgresql_selinux_users_ddl" type="boolean">
              <xccdf-1.2:title>postgresql_selinux_users_ddl SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_pppd_can_insmod" type="boolean">
              <xccdf-1.2:title>pppd_can_insmod SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_pppd_for_user" type="boolean">
              <xccdf-1.2:title>pppd_for_user SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_privoxy_connect_any" type="boolean">
              <xccdf-1.2:title>privoxy_connect_any SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_prosody_bind_http_port" type="boolean">
              <xccdf-1.2:title>prosody_bind_http_port SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_puppetagent_manage_all_files" type="boolean">
              <xccdf-1.2:title>puppetagent_manage_all_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_puppetmaster_use_db" type="boolean">
              <xccdf-1.2:title>puppetmaster_use_db SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_racoon_read_shadow" type="boolean">
              <xccdf-1.2:title>racoon_read_shadow SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_rsync_anon_write" type="boolean">
              <xccdf-1.2:title>rsync_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_rsync_client" type="boolean">
              <xccdf-1.2:title>rsync_client SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_rsync_export_all_ro" type="boolean">
              <xccdf-1.2:title>rsync_export_all_ro SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_rsync_full_access" type="boolean">
              <xccdf-1.2:title>rsync_full_access SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_samba_create_home_dirs" type="boolean">
              <xccdf-1.2:title>samba_create_home_dirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_samba_domain_controller" type="boolean">
              <xccdf-1.2:title>samba_domain_controller SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_samba_enable_home_dirs" type="boolean">
              <xccdf-1.2:title>samba_enable_home_dirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_samba_export_all_ro" type="boolean">
              <xccdf-1.2:title>samba_export_all_ro SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_samba_export_all_rw" type="boolean">
              <xccdf-1.2:title>samba_export_all_rw SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_samba_load_libgfapi" type="boolean">
              <xccdf-1.2:title>samba_load_libgfapi SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_samba_portmapper" type="boolean">
              <xccdf-1.2:title>samba_portmapper SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_samba_run_unconfined" type="boolean">
              <xccdf-1.2:title>samba_run_unconfined SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_samba_share_fusefs" type="boolean">
              <xccdf-1.2:title>samba_share_fusefs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_samba_share_nfs" type="boolean">
              <xccdf-1.2:title>samba_share_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sanlock_use_fusefs" type="boolean">
              <xccdf-1.2:title>sanlock_use_fusefs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sanlock_use_nfs" type="boolean">
              <xccdf-1.2:title>sanlock_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sanlock_use_samba" type="boolean">
              <xccdf-1.2:title>sanlock_use_samba SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_saslauthd_read_shadow" type="boolean">
              <xccdf-1.2:title>saslauthd_read_shadow SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_secadm_exec_content" type="boolean">
              <xccdf-1.2:title>secadm_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_secure_mode" type="boolean">
              <xccdf-1.2:title>secure_mode SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_secure_mode_insmod" type="boolean">
              <xccdf-1.2:title>secure_mode_insmod SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_secure_mode_policyload" type="boolean">
              <xccdf-1.2:title>secure_mode_policyload SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_selinuxuser_direct_dri_enabled" type="boolean">
              <xccdf-1.2:title>selinuxuser_direct_dri_enabled SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_selinuxuser_execheap" type="boolean">
              <xccdf-1.2:title>selinuxuser_execheap SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_selinuxuser_execmod" type="boolean">
              <xccdf-1.2:title>selinuxuser_execmod SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_selinuxuser_execstack" type="boolean">
              <xccdf-1.2:title>selinuxuser_execstack SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_selinuxuser_mysql_connect_enabled" type="boolean">
              <xccdf-1.2:title>selinuxuser_mysql_connect_enabled SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_selinuxuser_ping" type="boolean">
              <xccdf-1.2:title>selinuxuser_ping SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_selinuxuser_postgresql_connect_enabled" type="boolean">
              <xccdf-1.2:title>selinuxuser_postgresql_connect_enabled SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_selinuxuser_rw_noexattrfile" type="boolean">
              <xccdf-1.2:title>selinuxuser_rw_noexattrfile SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_selinuxuser_share_music" type="boolean">
              <xccdf-1.2:title>selinuxuser_share_music SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_selinuxuser_tcp_server" type="boolean">
              <xccdf-1.2:title>selinuxuser_tcp_server SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_selinuxuser_udp_server" type="boolean">
              <xccdf-1.2:title>selinuxuser_udp_server SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_selinuxuser_use_ssh_chroot" type="boolean">
              <xccdf-1.2:title>selinuxuser_use_ssh_chroot SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sge_domain_can_network_connect" type="boolean">
              <xccdf-1.2:title>sge_domain_can_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sge_use_nfs" type="boolean">
              <xccdf-1.2:title>sge_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_smartmon_3ware" type="boolean">
              <xccdf-1.2:title>smartmon_3ware SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_smbd_anon_write" type="boolean">
              <xccdf-1.2:title>smbd_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_spamassassin_can_network" type="boolean">
              <xccdf-1.2:title>spamassassin_can_network SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_spamd_enable_home_dirs" type="boolean">
              <xccdf-1.2:title>spamd_enable_home_dirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_squid_connect_any" type="boolean">
              <xccdf-1.2:title>squid_connect_any SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_squid_use_tproxy" type="boolean">
              <xccdf-1.2:title>squid_use_tproxy SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_ssh_chroot_rw_homedirs" type="boolean">
              <xccdf-1.2:title>ssh_chroot_rw_homedirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_ssh_keysign" type="boolean">
              <xccdf-1.2:title>ssh_keysign SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_ssh_sysadm_login" type="boolean">
              <xccdf-1.2:title>ssh_sysadm_login SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_staff_exec_content" type="boolean">
              <xccdf-1.2:title>staff_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_staff_use_svirt" type="boolean">
              <xccdf-1.2:title>staff_use_svirt SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_swift_can_network" type="boolean">
              <xccdf-1.2:title>swift_can_network SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sysadm_exec_content" type="boolean">
              <xccdf-1.2:title>sysadm_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_telepathy_connect_all_ports" type="boolean">
              <xccdf-1.2:title>telepathy_connect_all_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_telepathy_tcp_connect_generic_network_ports" type="boolean">
              <xccdf-1.2:title>telepathy_tcp_connect_generic_network_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_tftp_anon_write" type="boolean">
              <xccdf-1.2:title>tftp_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_tftp_home_dir" type="boolean">
              <xccdf-1.2:title>tftp_home_dir SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_tmpreaper_use_nfs" type="boolean">
              <xccdf-1.2:title>tmpreaper_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_tmpreaper_use_samba" type="boolean">
              <xccdf-1.2:title>tmpreaper_use_samba SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_tor_bind_all_unreserved_ports" type="boolean">
              <xccdf-1.2:title>tor_bind_all_unreserved_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_tor_can_network_relay" type="boolean">
              <xccdf-1.2:title>tor_can_network_relay SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_unconfined_chrome_sandbox_transition" type="boolean">
              <xccdf-1.2:title>unconfined_chrome_sandbox_transition SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_unconfined_login" type="boolean">
              <xccdf-1.2:title>unconfined_login SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_unconfined_mozilla_plugin_transition" type="boolean">
              <xccdf-1.2:title>unconfined_mozilla_plugin_transition SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_unprivuser_use_svirt" type="boolean">
              <xccdf-1.2:title>unprivuser_use_svirt SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_use_ecryptfs_home_dirs" type="boolean">
              <xccdf-1.2:title>use_ecryptfs_home_dirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_use_fusefs_home_dirs" type="boolean">
              <xccdf-1.2:title>use_fusefs_home_dirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_use_lpd_server" type="boolean">
              <xccdf-1.2:title>use_lpd_server SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_use_nfs_home_dirs" type="boolean">
              <xccdf-1.2:title>use_nfs_home_dirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_use_samba_home_dirs" type="boolean">
              <xccdf-1.2:title>use_samba_home_dirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_user_exec_content" type="boolean">
              <xccdf-1.2:title>user_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_varnishd_connect_any" type="boolean">
              <xccdf-1.2:title>varnishd_connect_any SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_virt_read_qemu_ga_data" type="boolean">
              <xccdf-1.2:title>virt_read_qemu_ga_data SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_virt_rw_qemu_ga_data" type="boolean">
              <xccdf-1.2:title>virt_rw_qemu_ga_data SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_all_caps" type="boolean">
              <xccdf-1.2:title>virt_sandbox_use_all_caps SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_audit" type="boolean">
              <xccdf-1.2:title>virt_sandbox_use_audit SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_mknod" type="boolean">
              <xccdf-1.2:title>virt_sandbox_use_mknod SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_netlink" type="boolean">
              <xccdf-1.2:title>virt_sandbox_use_netlink SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_sys_admin" type="boolean">
              <xccdf-1.2:title>virt_sandbox_use_sys_admin SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_virt_transition_userdomain" type="boolean">
              <xccdf-1.2:title>virt_transition_userdomain SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_virt_use_comm" type="boolean">
              <xccdf-1.2:title>virt_use_comm SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_virt_use_execmem" type="boolean">
              <xccdf-1.2:title>virt_use_execmem SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_virt_use_fusefs" type="boolean">
              <xccdf-1.2:title>virt_use_fusefs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_virt_use_nfs" type="boolean">
              <xccdf-1.2:title>virt_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_virt_use_rawip" type="boolean">
              <xccdf-1.2:title>virt_use_rawip SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_virt_use_samba" type="boolean">
              <xccdf-1.2:title>virt_use_samba SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_virt_use_sanlock" type="boolean">
              <xccdf-1.2:title>virt_use_sanlock SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_virt_use_usb" type="boolean">
              <xccdf-1.2:title>virt_use_usb SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_virt_use_xserver" type="boolean">
              <xccdf-1.2:title>virt_use_xserver SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_webadm_manage_user_files" type="boolean">
              <xccdf-1.2:title>webadm_manage_user_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_webadm_read_user_files" type="boolean">
              <xccdf-1.2:title>webadm_read_user_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_wine_mmap_zero_ignore" type="boolean">
              <xccdf-1.2:title>wine_mmap_zero_ignore SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_xdm_bind_vnc_tcp_port" type="boolean">
              <xccdf-1.2:title>xdm_bind_vnc_tcp_port SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_xdm_exec_bootloader" type="boolean">
              <xccdf-1.2:title>xdm_exec_bootloader SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_xdm_sysadm_login" type="boolean">
              <xccdf-1.2:title>xdm_sysadm_login SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_xdm_write_home" type="boolean">
              <xccdf-1.2:title>xdm_write_home SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_xen_use_nfs" type="boolean">
              <xccdf-1.2:title>xen_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_xend_run_blktap" type="boolean">
              <xccdf-1.2:title>xend_run_blktap SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_xend_run_qemu" type="boolean">
              <xccdf-1.2:title>xend_run_qemu SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_xguest_connect_network" type="boolean">
              <xccdf-1.2:title>xguest_connect_network SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_xguest_exec_content" type="boolean">
              <xccdf-1.2:title>xguest_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_xguest_mount_media" type="boolean">
              <xccdf-1.2:title>xguest_mount_media SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_xguest_use_bluetooth" type="boolean">
              <xccdf-1.2:title>xguest_use_bluetooth SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>true</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_xserver_clients_write_xshm" type="boolean">
              <xccdf-1.2:title>xserver_clients_write_xshm SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_xserver_execmem" type="boolean">
              <xccdf-1.2:title>xserver_execmem SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_xserver_object_manager" type="boolean">
              <xccdf-1.2:title>xserver_object_manager SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_zabbix_can_network" type="boolean">
              <xccdf-1.2:title>zabbix_can_network SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_zarafa_setrlimit" type="boolean">
              <xccdf-1.2:title>zarafa_setrlimit SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_zebra_write_config" type="boolean">
              <xccdf-1.2:title>zebra_write_config SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_zoneminder_anon_write" type="boolean">
              <xccdf-1.2:title>zoneminder_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_zoneminder_run_sudo" type="boolean">
              <xccdf-1.2:title>zoneminder_run_sudo SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>default - Default SELinux boolean setting.
<html:br/>on - SELinux boolean is enabled.
<html:br/>off - SELinux boolean is disabled.</xccdf-1.2:description>
              <xccdf-1.2:value>false</xccdf-1.2:value>
              <xccdf-1.2:value selector="off">false</xccdf-1.2:value>
              <xccdf-1.2:value selector="on">true</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_abrt_anon_write" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the abrt_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>abrt_anon_write</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>abrt_anon_write</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P abrt_anon_write off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_abrt_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_abrt_anon_write='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_abrt_anon_write" use="legacy"/>'

    /usr/sbin/setsebool -P abrt_anon_write $var_abrt_anon_write

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_abrt_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_abrt_anon_write

- name: Disable the abrt_anon_write SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_abrt_anon_write
- name: XCCDF Value var_abrt_anon_write # promote to variable
  set_fact:
    var_abrt_anon_write: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_abrt_anon_write" use="legacy"/>
  tags:
    - always

- name: Disable the abrt_anon_write SELinux Boolean - Set SELinux Boolean abrt_anon_write
    Accordingly
  ansible.posix.seboolean:
    name: abrt_anon_write
    state: '{{ var_abrt_anon_write }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_abrt_anon_write
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_abrt_anon_write:var:1" value-id="xccdf_org.ssgproject.content_value_var_abrt_anon_write"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_abrt_anon_write:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_abrt_anon_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_abrt_handle_event" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the abrt_handle_event SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>abrt_handle_event</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>abrt_handle_event</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P abrt_handle_event off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_abrt_handle_event" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_abrt_handle_event='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_abrt_handle_event" use="legacy"/>'

    /usr/sbin/setsebool -P abrt_handle_event $var_abrt_handle_event

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_abrt_handle_event" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_abrt_handle_event

- name: Disable the abrt_handle_event SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_abrt_handle_event
- name: XCCDF Value var_abrt_handle_event # promote to variable
  set_fact:
    var_abrt_handle_event: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_abrt_handle_event" use="legacy"/>
  tags:
    - always

- name: Disable the abrt_handle_event SELinux Boolean - Set SELinux Boolean abrt_handle_event
    Accordingly
  ansible.posix.seboolean:
    name: abrt_handle_event
    state: '{{ var_abrt_handle_event }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_abrt_handle_event
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_abrt_handle_event:var:1" value-id="xccdf_org.ssgproject.content_value_var_abrt_handle_event"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_abrt_handle_event:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_abrt_handle_event_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_abrt_upload_watch_anon_write" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the abrt_upload_watch_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>abrt_upload_watch_anon_write</html:code> is enabled.
This setting should be disabled as it allows the Automatic Bug Report Tool (ABRT)
to modify public files used for public file transfer services.

To disable the <html:code>abrt_upload_watch_anon_write</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P abrt_upload_watch_anon_write off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_abrt_upload_watch_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_abrt_upload_watch_anon_write='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_abrt_upload_watch_anon_write" use="legacy"/>'

    /usr/sbin/setsebool -P abrt_upload_watch_anon_write $var_abrt_upload_watch_anon_write

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_abrt_upload_watch_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_abrt_upload_watch_anon_write

- name: Disable the abrt_upload_watch_anon_write SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_abrt_upload_watch_anon_write
- name: XCCDF Value var_abrt_upload_watch_anon_write # promote to variable
  set_fact:
    var_abrt_upload_watch_anon_write: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_abrt_upload_watch_anon_write" use="legacy"/>
  tags:
    - always

- name: Disable the abrt_upload_watch_anon_write SELinux Boolean - Set SELinux Boolean
    abrt_upload_watch_anon_write Accordingly
  ansible.posix.seboolean:
    name: abrt_upload_watch_anon_write
    state: '{{ var_abrt_upload_watch_anon_write }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_abrt_upload_watch_anon_write
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_abrt_upload_watch_anon_write:var:1" value-id="xccdf_org.ssgproject.content_value_var_abrt_upload_watch_anon_write"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_abrt_upload_watch_anon_write:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_abrt_upload_watch_anon_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_antivirus_can_scan_system" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the antivirus_can_scan_system SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>antivirus_can_scan_system</html:code> is disabled.
This setting should be enabled as it allows antivirus programs to read non-security
files on a system.

To enable the <html:code>antivirus_can_scan_system</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P antivirus_can_scan_system on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_antivirus_can_scan_system" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_antivirus_can_scan_system='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_antivirus_can_scan_system" use="legacy"/>'

    /usr/sbin/setsebool -P antivirus_can_scan_system $var_antivirus_can_scan_system

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_antivirus_can_scan_system" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_antivirus_can_scan_system

- name: Enable the antivirus_can_scan_system SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_antivirus_can_scan_system
- name: XCCDF Value var_antivirus_can_scan_system # promote to variable
  set_fact:
    var_antivirus_can_scan_system: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_antivirus_can_scan_system" use="legacy"/>
  tags:
    - always

- name: Enable the antivirus_can_scan_system SELinux Boolean - Set SELinux Boolean
    antivirus_can_scan_system Accordingly
  ansible.posix.seboolean:
    name: antivirus_can_scan_system
    state: '{{ var_antivirus_can_scan_system }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_antivirus_can_scan_system
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_antivirus_can_scan_system:var:1" value-id="xccdf_org.ssgproject.content_value_var_antivirus_can_scan_system"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_antivirus_can_scan_system:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_antivirus_can_scan_system_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_antivirus_use_jit" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the antivirus_use_jit SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>antivirus_use_jit</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>antivirus_use_jit</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P antivirus_use_jit off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_antivirus_use_jit" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_antivirus_use_jit='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_antivirus_use_jit" use="legacy"/>'

    /usr/sbin/setsebool -P antivirus_use_jit $var_antivirus_use_jit

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_antivirus_use_jit" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_antivirus_use_jit

- name: Disable the antivirus_use_jit SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_antivirus_use_jit
- name: XCCDF Value var_antivirus_use_jit # promote to variable
  set_fact:
    var_antivirus_use_jit: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_antivirus_use_jit" use="legacy"/>
  tags:
    - always

- name: Disable the antivirus_use_jit SELinux Boolean - Set SELinux Boolean antivirus_use_jit
    Accordingly
  ansible.posix.seboolean:
    name: antivirus_use_jit
    state: '{{ var_antivirus_use_jit }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_antivirus_use_jit
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_antivirus_use_jit:var:1" value-id="xccdf_org.ssgproject.content_value_var_antivirus_use_jit"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_antivirus_use_jit:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_antivirus_use_jit_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_auditadm_exec_content" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the auditadm_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>auditadm_exec_content</html:code> is enabled.
If this setting is disabled, it should be enabled.

To enable the <html:code>auditadm_exec_content</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P auditadm_exec_content on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">80424-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0846</xccdf-1.2:reference>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_auditadm_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_auditadm_exec_content='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditadm_exec_content" use="legacy"/>'

    /usr/sbin/setsebool -P auditadm_exec_content $var_auditadm_exec_content

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_auditadm_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-80424-5
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_auditadm_exec_content

- name: Enable the auditadm_exec_content SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-80424-5
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_auditadm_exec_content
- name: XCCDF Value var_auditadm_exec_content # promote to variable
  set_fact:
    var_auditadm_exec_content: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditadm_exec_content" use="legacy"/>
  tags:
    - always

- name: Enable the auditadm_exec_content SELinux Boolean - Set SELinux Boolean auditadm_exec_content
    Accordingly
  ansible.posix.seboolean:
    name: auditadm_exec_content
    state: '{{ var_auditadm_exec_content }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-80424-5
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_auditadm_exec_content
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_auditadm_exec_content:var:1" value-id="xccdf_org.ssgproject.content_value_var_auditadm_exec_content"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_auditadm_exec_content:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_auditadm_exec_content_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_authlogin_nsswitch_use_ldap" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the authlogin_nsswitch_use_ldap SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>authlogin_nsswitch_use_ldap</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>authlogin_nsswitch_use_ldap</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P authlogin_nsswitch_use_ldap off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_authlogin_nsswitch_use_ldap" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_authlogin_nsswitch_use_ldap='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_authlogin_nsswitch_use_ldap" use="legacy"/>'

    /usr/sbin/setsebool -P authlogin_nsswitch_use_ldap $var_authlogin_nsswitch_use_ldap

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_authlogin_nsswitch_use_ldap" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_authlogin_nsswitch_use_ldap

- name: Disable the authlogin_nsswitch_use_ldap SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_authlogin_nsswitch_use_ldap
- name: XCCDF Value var_authlogin_nsswitch_use_ldap # promote to variable
  set_fact:
    var_authlogin_nsswitch_use_ldap: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_authlogin_nsswitch_use_ldap" use="legacy"/>
  tags:
    - always

- name: Disable the authlogin_nsswitch_use_ldap SELinux Boolean - Set SELinux Boolean
    authlogin_nsswitch_use_ldap Accordingly
  ansible.posix.seboolean:
    name: authlogin_nsswitch_use_ldap
    state: '{{ var_authlogin_nsswitch_use_ldap }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_authlogin_nsswitch_use_ldap
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_authlogin_nsswitch_use_ldap:var:1" value-id="xccdf_org.ssgproject.content_value_var_authlogin_nsswitch_use_ldap"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_authlogin_nsswitch_use_ldap:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_authlogin_nsswitch_use_ldap_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_authlogin_radius" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the authlogin_radius SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>authlogin_radius</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>authlogin_radius</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P authlogin_radius off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_authlogin_radius" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_authlogin_radius='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_authlogin_radius" use="legacy"/>'

    /usr/sbin/setsebool -P authlogin_radius $var_authlogin_radius

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_authlogin_radius" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_authlogin_radius

- name: Disable the authlogin_radius SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_authlogin_radius
- name: XCCDF Value var_authlogin_radius # promote to variable
  set_fact:
    var_authlogin_radius: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_authlogin_radius" use="legacy"/>
  tags:
    - always

- name: Disable the authlogin_radius SELinux Boolean - Set SELinux Boolean authlogin_radius
    Accordingly
  ansible.posix.seboolean:
    name: authlogin_radius
    state: '{{ var_authlogin_radius }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_authlogin_radius
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_authlogin_radius:var:1" value-id="xccdf_org.ssgproject.content_value_var_authlogin_radius"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_authlogin_radius:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_authlogin_radius_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_authlogin_yubikey" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the authlogin_yubikey SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>authlogin_yubikey</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>authlogin_yubikey</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P authlogin_yubikey off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_authlogin_yubikey" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_authlogin_yubikey='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_authlogin_yubikey" use="legacy"/>'

    /usr/sbin/setsebool -P authlogin_yubikey $var_authlogin_yubikey

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_authlogin_yubikey" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_authlogin_yubikey

- name: Disable the authlogin_yubikey SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_authlogin_yubikey
- name: XCCDF Value var_authlogin_yubikey # promote to variable
  set_fact:
    var_authlogin_yubikey: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_authlogin_yubikey" use="legacy"/>
  tags:
    - always

- name: Disable the authlogin_yubikey SELinux Boolean - Set SELinux Boolean authlogin_yubikey
    Accordingly
  ansible.posix.seboolean:
    name: authlogin_yubikey
    state: '{{ var_authlogin_yubikey }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_authlogin_yubikey
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_authlogin_yubikey:var:1" value-id="xccdf_org.ssgproject.content_value_var_authlogin_yubikey"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_authlogin_yubikey:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_authlogin_yubikey_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_awstats_purge_apache_log_files" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the awstats_purge_apache_log_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>awstats_purge_apache_log_files</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>awstats_purge_apache_log_files</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P awstats_purge_apache_log_files off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_awstats_purge_apache_log_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_awstats_purge_apache_log_files='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_awstats_purge_apache_log_files" use="legacy"/>'

    /usr/sbin/setsebool -P awstats_purge_apache_log_files $var_awstats_purge_apache_log_files

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_awstats_purge_apache_log_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_awstats_purge_apache_log_files

- name: Disable the awstats_purge_apache_log_files SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_awstats_purge_apache_log_files
- name: XCCDF Value var_awstats_purge_apache_log_files # promote to variable
  set_fact:
    var_awstats_purge_apache_log_files: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_awstats_purge_apache_log_files" use="legacy"/>
  tags:
    - always

- name: Disable the awstats_purge_apache_log_files SELinux Boolean - Set SELinux Boolean
    awstats_purge_apache_log_files Accordingly
  ansible.posix.seboolean:
    name: awstats_purge_apache_log_files
    state: '{{ var_awstats_purge_apache_log_files }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_awstats_purge_apache_log_files
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_awstats_purge_apache_log_files:var:1" value-id="xccdf_org.ssgproject.content_value_var_awstats_purge_apache_log_files"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_awstats_purge_apache_log_files:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_awstats_purge_apache_log_files_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_boinc_execmem" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the boinc_execmem SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>boinc_execmem</html:code> is enabled.
This setting should be disabled.

To disable the <html:code>boinc_execmem</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P boinc_execmem off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_boinc_execmem" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_boinc_execmem='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_boinc_execmem" use="legacy"/>'

    /usr/sbin/setsebool -P boinc_execmem $var_boinc_execmem

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_boinc_execmem" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_boinc_execmem

- name: Disable the boinc_execmem SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_boinc_execmem
- name: XCCDF Value var_boinc_execmem # promote to variable
  set_fact:
    var_boinc_execmem: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_boinc_execmem" use="legacy"/>
  tags:
    - always

- name: Disable the boinc_execmem SELinux Boolean - Set SELinux Boolean boinc_execmem
    Accordingly
  ansible.posix.seboolean:
    name: boinc_execmem
    state: '{{ var_boinc_execmem }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.7.2
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_boinc_execmem
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_boinc_execmem:var:1" value-id="xccdf_org.ssgproject.content_value_var_boinc_execmem"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_boinc_execmem:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_boinc_execmem_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_cdrecord_read_content" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the cdrecord_read_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>cdrecord_read_content</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>cdrecord_read_content</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P cdrecord_read_content off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cdrecord_read_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_cdrecord_read_content='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cdrecord_read_content" use="legacy"/>'

    /usr/sbin/setsebool -P cdrecord_read_content $var_cdrecord_read_content

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cdrecord_read_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cdrecord_read_content

- name: Disable the cdrecord_read_content SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cdrecord_read_content
- name: XCCDF Value var_cdrecord_read_content # promote to variable
  set_fact:
    var_cdrecord_read_content: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cdrecord_read_content" use="legacy"/>
  tags:
    - always

- name: Disable the cdrecord_read_content SELinux Boolean - Set SELinux Boolean cdrecord_read_content
    Accordingly
  ansible.posix.seboolean:
    name: cdrecord_read_content
    state: '{{ var_cdrecord_read_content }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cdrecord_read_content
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_cdrecord_read_content:var:1" value-id="xccdf_org.ssgproject.content_value_var_cdrecord_read_content"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_cdrecord_read_content:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_cdrecord_read_content_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_cluster_can_network_connect" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the cluster_can_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>cluster_can_network_connect</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>cluster_can_network_connect</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P cluster_can_network_connect off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cluster_can_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_cluster_can_network_connect='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cluster_can_network_connect" use="legacy"/>'

    /usr/sbin/setsebool -P cluster_can_network_connect $var_cluster_can_network_connect

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cluster_can_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cluster_can_network_connect

- name: Disable the cluster_can_network_connect SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cluster_can_network_connect
- name: XCCDF Value var_cluster_can_network_connect # promote to variable
  set_fact:
    var_cluster_can_network_connect: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cluster_can_network_connect" use="legacy"/>
  tags:
    - always

- name: Disable the cluster_can_network_connect SELinux Boolean - Set SELinux Boolean
    cluster_can_network_connect Accordingly
  ansible.posix.seboolean:
    name: cluster_can_network_connect
    state: '{{ var_cluster_can_network_connect }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cluster_can_network_connect
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_cluster_can_network_connect:var:1" value-id="xccdf_org.ssgproject.content_value_var_cluster_can_network_connect"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_cluster_can_network_connect:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_cluster_can_network_connect_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_cluster_manage_all_files" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the cluster_manage_all_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>cluster_manage_all_files</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>cluster_manage_all_files</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P cluster_manage_all_files off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cluster_manage_all_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_cluster_manage_all_files='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cluster_manage_all_files" use="legacy"/>'

    /usr/sbin/setsebool -P cluster_manage_all_files $var_cluster_manage_all_files

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cluster_manage_all_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cluster_manage_all_files

- name: Disable the cluster_manage_all_files SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cluster_manage_all_files
- name: XCCDF Value var_cluster_manage_all_files # promote to variable
  set_fact:
    var_cluster_manage_all_files: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cluster_manage_all_files" use="legacy"/>
  tags:
    - always

- name: Disable the cluster_manage_all_files SELinux Boolean - Set SELinux Boolean
    cluster_manage_all_files Accordingly
  ansible.posix.seboolean:
    name: cluster_manage_all_files
    state: '{{ var_cluster_manage_all_files }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cluster_manage_all_files
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_cluster_manage_all_files:var:1" value-id="xccdf_org.ssgproject.content_value_var_cluster_manage_all_files"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_cluster_manage_all_files:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_cluster_manage_all_files_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_cluster_use_execmem" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the cluster_use_execmem SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>cluster_use_execmem</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>cluster_use_execmem</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P cluster_use_execmem off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cluster_use_execmem" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_cluster_use_execmem='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cluster_use_execmem" use="legacy"/>'

    /usr/sbin/setsebool -P cluster_use_execmem $var_cluster_use_execmem

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cluster_use_execmem" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cluster_use_execmem

- name: Disable the cluster_use_execmem SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cluster_use_execmem
- name: XCCDF Value var_cluster_use_execmem # promote to variable
  set_fact:
    var_cluster_use_execmem: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cluster_use_execmem" use="legacy"/>
  tags:
    - always

- name: Disable the cluster_use_execmem SELinux Boolean - Set SELinux Boolean cluster_use_execmem
    Accordingly
  ansible.posix.seboolean:
    name: cluster_use_execmem
    state: '{{ var_cluster_use_execmem }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cluster_use_execmem
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_cluster_use_execmem:var:1" value-id="xccdf_org.ssgproject.content_value_var_cluster_use_execmem"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_cluster_use_execmem:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_cluster_use_execmem_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_cobbler_anon_write" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the cobbler_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>cobbler_anon_write</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>cobbler_anon_write</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P cobbler_anon_write off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cobbler_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_cobbler_anon_write='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cobbler_anon_write" use="legacy"/>'

    /usr/sbin/setsebool -P cobbler_anon_write $var_cobbler_anon_write

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cobbler_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cobbler_anon_write

- name: Disable the cobbler_anon_write SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cobbler_anon_write
- name: XCCDF Value var_cobbler_anon_write # promote to variable
  set_fact:
    var_cobbler_anon_write: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cobbler_anon_write" use="legacy"/>
  tags:
    - always

- name: Disable the cobbler_anon_write SELinux Boolean - Set SELinux Boolean cobbler_anon_write
    Accordingly
  ansible.posix.seboolean:
    name: cobbler_anon_write
    state: '{{ var_cobbler_anon_write }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cobbler_anon_write
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_cobbler_anon_write:var:1" value-id="xccdf_org.ssgproject.content_value_var_cobbler_anon_write"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_cobbler_anon_write:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_cobbler_anon_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_cobbler_can_network_connect" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the cobbler_can_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>cobbler_can_network_connect</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>cobbler_can_network_connect</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P cobbler_can_network_connect off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cobbler_can_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_cobbler_can_network_connect='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cobbler_can_network_connect" use="legacy"/>'

    /usr/sbin/setsebool -P cobbler_can_network_connect $var_cobbler_can_network_connect

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cobbler_can_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cobbler_can_network_connect

- name: Disable the cobbler_can_network_connect SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cobbler_can_network_connect
- name: XCCDF Value var_cobbler_can_network_connect # promote to variable
  set_fact:
    var_cobbler_can_network_connect: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cobbler_can_network_connect" use="legacy"/>
  tags:
    - always

- name: Disable the cobbler_can_network_connect SELinux Boolean - Set SELinux Boolean
    cobbler_can_network_connect Accordingly
  ansible.posix.seboolean:
    name: cobbler_can_network_connect
    state: '{{ var_cobbler_can_network_connect }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cobbler_can_network_connect
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_cobbler_can_network_connect:var:1" value-id="xccdf_org.ssgproject.content_value_var_cobbler_can_network_connect"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_cobbler_can_network_connect:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_cobbler_can_network_connect_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_cobbler_use_cifs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the cobbler_use_cifs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>cobbler_use_cifs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>cobbler_use_cifs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P cobbler_use_cifs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cobbler_use_cifs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_cobbler_use_cifs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cobbler_use_cifs" use="legacy"/>'

    /usr/sbin/setsebool -P cobbler_use_cifs $var_cobbler_use_cifs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cobbler_use_cifs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cobbler_use_cifs

- name: Disable the cobbler_use_cifs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cobbler_use_cifs
- name: XCCDF Value var_cobbler_use_cifs # promote to variable
  set_fact:
    var_cobbler_use_cifs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cobbler_use_cifs" use="legacy"/>
  tags:
    - always

- name: Disable the cobbler_use_cifs SELinux Boolean - Set SELinux Boolean cobbler_use_cifs
    Accordingly
  ansible.posix.seboolean:
    name: cobbler_use_cifs
    state: '{{ var_cobbler_use_cifs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cobbler_use_cifs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_cobbler_use_cifs:var:1" value-id="xccdf_org.ssgproject.content_value_var_cobbler_use_cifs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_cobbler_use_cifs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_cobbler_use_cifs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_cobbler_use_nfs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the cobbler_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>cobbler_use_nfs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>cobbler_use_nfs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P cobbler_use_nfs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cobbler_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_cobbler_use_nfs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cobbler_use_nfs" use="legacy"/>'

    /usr/sbin/setsebool -P cobbler_use_nfs $var_cobbler_use_nfs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cobbler_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cobbler_use_nfs

- name: Disable the cobbler_use_nfs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cobbler_use_nfs
- name: XCCDF Value var_cobbler_use_nfs # promote to variable
  set_fact:
    var_cobbler_use_nfs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cobbler_use_nfs" use="legacy"/>
  tags:
    - always

- name: Disable the cobbler_use_nfs SELinux Boolean - Set SELinux Boolean cobbler_use_nfs
    Accordingly
  ansible.posix.seboolean:
    name: cobbler_use_nfs
    state: '{{ var_cobbler_use_nfs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cobbler_use_nfs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_cobbler_use_nfs:var:1" value-id="xccdf_org.ssgproject.content_value_var_cobbler_use_nfs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_cobbler_use_nfs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_cobbler_use_nfs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_collectd_tcp_network_connect" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the collectd_tcp_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>collectd_tcp_network_connect</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>collectd_tcp_network_connect</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P collectd_tcp_network_connect off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_collectd_tcp_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_collectd_tcp_network_connect='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_collectd_tcp_network_connect" use="legacy"/>'

    /usr/sbin/setsebool -P collectd_tcp_network_connect $var_collectd_tcp_network_connect

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_collectd_tcp_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_collectd_tcp_network_connect

- name: Disable the collectd_tcp_network_connect SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_collectd_tcp_network_connect
- name: XCCDF Value var_collectd_tcp_network_connect # promote to variable
  set_fact:
    var_collectd_tcp_network_connect: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_collectd_tcp_network_connect" use="legacy"/>
  tags:
    - always

- name: Disable the collectd_tcp_network_connect SELinux Boolean - Set SELinux Boolean
    collectd_tcp_network_connect Accordingly
  ansible.posix.seboolean:
    name: collectd_tcp_network_connect
    state: '{{ var_collectd_tcp_network_connect }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_collectd_tcp_network_connect
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_collectd_tcp_network_connect:var:1" value-id="xccdf_org.ssgproject.content_value_var_collectd_tcp_network_connect"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_collectd_tcp_network_connect:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_collectd_tcp_network_connect_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_condor_tcp_network_connect" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the condor_tcp_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>condor_tcp_network_connect</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>condor_tcp_network_connect</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P condor_tcp_network_connect off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_condor_tcp_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_condor_tcp_network_connect='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_condor_tcp_network_connect" use="legacy"/>'

    /usr/sbin/setsebool -P condor_tcp_network_connect $var_condor_tcp_network_connect

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_condor_tcp_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_condor_tcp_network_connect

- name: Disable the condor_tcp_network_connect SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_condor_tcp_network_connect
- name: XCCDF Value var_condor_tcp_network_connect # promote to variable
  set_fact:
    var_condor_tcp_network_connect: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_condor_tcp_network_connect" use="legacy"/>
  tags:
    - always

- name: Disable the condor_tcp_network_connect SELinux Boolean - Set SELinux Boolean
    condor_tcp_network_connect Accordingly
  ansible.posix.seboolean:
    name: condor_tcp_network_connect
    state: '{{ var_condor_tcp_network_connect }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_condor_tcp_network_connect
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_condor_tcp_network_connect:var:1" value-id="xccdf_org.ssgproject.content_value_var_condor_tcp_network_connect"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_condor_tcp_network_connect:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_condor_tcp_network_connect_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_conman_can_network" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the conman_can_network SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>conman_can_network</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>conman_can_network</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P conman_can_network off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_conman_can_network" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_conman_can_network='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_conman_can_network" use="legacy"/>'

    /usr/sbin/setsebool -P conman_can_network $var_conman_can_network

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_conman_can_network" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_conman_can_network

- name: Disable the conman_can_network SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_conman_can_network
- name: XCCDF Value var_conman_can_network # promote to variable
  set_fact:
    var_conman_can_network: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_conman_can_network" use="legacy"/>
  tags:
    - always

- name: Disable the conman_can_network SELinux Boolean - Set SELinux Boolean conman_can_network
    Accordingly
  ansible.posix.seboolean:
    name: conman_can_network
    state: '{{ var_conman_can_network }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_conman_can_network
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_conman_can_network:var:1" value-id="xccdf_org.ssgproject.content_value_var_conman_can_network"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_conman_can_network:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_conman_can_network_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_container_connect_any" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the container_connect_any SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>container_connect_any</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>container_connect_any</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P container_connect_any off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_container_connect_any" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_container_connect_any='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_container_connect_any" use="legacy"/>'

    /usr/sbin/setsebool -P container_connect_any $var_container_connect_any

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_container_connect_any" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_container_connect_any

- name: Disable the container_connect_any SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_container_connect_any
- name: XCCDF Value var_container_connect_any # promote to variable
  set_fact:
    var_container_connect_any: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_container_connect_any" use="legacy"/>
  tags:
    - always

- name: Disable the container_connect_any SELinux Boolean - Set SELinux Boolean container_connect_any
    Accordingly
  ansible.posix.seboolean:
    name: container_connect_any
    state: '{{ var_container_connect_any }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_container_connect_any
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_container_connect_any:var:1" value-id="xccdf_org.ssgproject.content_value_var_container_connect_any"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_container_connect_any:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_container_connect_any_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_cron_can_relabel" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the cron_can_relabel SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>cron_can_relabel</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>cron_can_relabel</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P cron_can_relabel off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cron_can_relabel" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_cron_can_relabel='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cron_can_relabel" use="legacy"/>'

    /usr/sbin/setsebool -P cron_can_relabel $var_cron_can_relabel

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cron_can_relabel" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cron_can_relabel

- name: Disable the cron_can_relabel SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cron_can_relabel
- name: XCCDF Value var_cron_can_relabel # promote to variable
  set_fact:
    var_cron_can_relabel: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cron_can_relabel" use="legacy"/>
  tags:
    - always

- name: Disable the cron_can_relabel SELinux Boolean - Set SELinux Boolean cron_can_relabel
    Accordingly
  ansible.posix.seboolean:
    name: cron_can_relabel
    state: '{{ var_cron_can_relabel }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cron_can_relabel
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_cron_can_relabel:var:1" value-id="xccdf_org.ssgproject.content_value_var_cron_can_relabel"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_cron_can_relabel:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_cron_can_relabel_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_cron_system_cronjob_use_shares" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the cron_system_cronjob_use_shares SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>cron_system_cronjob_use_shares</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>cron_system_cronjob_use_shares</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P cron_system_cronjob_use_shares off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cron_system_cronjob_use_shares" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_cron_system_cronjob_use_shares='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cron_system_cronjob_use_shares" use="legacy"/>'

    /usr/sbin/setsebool -P cron_system_cronjob_use_shares $var_cron_system_cronjob_use_shares

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cron_system_cronjob_use_shares" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cron_system_cronjob_use_shares

- name: Disable the cron_system_cronjob_use_shares SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cron_system_cronjob_use_shares
- name: XCCDF Value var_cron_system_cronjob_use_shares # promote to variable
  set_fact:
    var_cron_system_cronjob_use_shares: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cron_system_cronjob_use_shares" use="legacy"/>
  tags:
    - always

- name: Disable the cron_system_cronjob_use_shares SELinux Boolean - Set SELinux Boolean
    cron_system_cronjob_use_shares Accordingly
  ansible.posix.seboolean:
    name: cron_system_cronjob_use_shares
    state: '{{ var_cron_system_cronjob_use_shares }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cron_system_cronjob_use_shares
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_cron_system_cronjob_use_shares:var:1" value-id="xccdf_org.ssgproject.content_value_var_cron_system_cronjob_use_shares"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_cron_system_cronjob_use_shares:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_cron_system_cronjob_use_shares_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_cron_userdomain_transition" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the cron_userdomain_transition SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>cron_userdomain_transition</html:code> is enabled.
This setting should be enabled as end user cron jobs run in their default
associated user domain(s) instead of the general cronjob domain.

To enable the <html:code>cron_userdomain_transition</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P cron_userdomain_transition on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cron_userdomain_transition" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_cron_userdomain_transition='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cron_userdomain_transition" use="legacy"/>'

    /usr/sbin/setsebool -P cron_userdomain_transition $var_cron_userdomain_transition

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cron_userdomain_transition" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cron_userdomain_transition

- name: Enable the cron_userdomain_transition SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cron_userdomain_transition
- name: XCCDF Value var_cron_userdomain_transition # promote to variable
  set_fact:
    var_cron_userdomain_transition: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cron_userdomain_transition" use="legacy"/>
  tags:
    - always

- name: Enable the cron_userdomain_transition SELinux Boolean - Set SELinux Boolean
    cron_userdomain_transition Accordingly
  ansible.posix.seboolean:
    name: cron_userdomain_transition
    state: '{{ var_cron_userdomain_transition }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cron_userdomain_transition
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_cron_userdomain_transition:var:1" value-id="xccdf_org.ssgproject.content_value_var_cron_userdomain_transition"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_cron_userdomain_transition:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_cron_userdomain_transition_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_cups_execmem" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the cups_execmem SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>cups_execmem</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>cups_execmem</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P cups_execmem off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cups_execmem" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_cups_execmem='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cups_execmem" use="legacy"/>'

    /usr/sbin/setsebool -P cups_execmem $var_cups_execmem

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cups_execmem" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cups_execmem

- name: Disable the cups_execmem SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cups_execmem
- name: XCCDF Value var_cups_execmem # promote to variable
  set_fact:
    var_cups_execmem: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cups_execmem" use="legacy"/>
  tags:
    - always

- name: Disable the cups_execmem SELinux Boolean - Set SELinux Boolean cups_execmem
    Accordingly
  ansible.posix.seboolean:
    name: cups_execmem
    state: '{{ var_cups_execmem }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cups_execmem
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_cups_execmem:var:1" value-id="xccdf_org.ssgproject.content_value_var_cups_execmem"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_cups_execmem:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_cups_execmem_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_cvs_read_shadow" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the cvs_read_shadow SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>cvs_read_shadow</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>cvs_read_shadow</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P cvs_read_shadow off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cvs_read_shadow" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_cvs_read_shadow='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cvs_read_shadow" use="legacy"/>'

    /usr/sbin/setsebool -P cvs_read_shadow $var_cvs_read_shadow

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_cvs_read_shadow" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cvs_read_shadow

- name: Disable the cvs_read_shadow SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cvs_read_shadow
- name: XCCDF Value var_cvs_read_shadow # promote to variable
  set_fact:
    var_cvs_read_shadow: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_cvs_read_shadow" use="legacy"/>
  tags:
    - always

- name: Disable the cvs_read_shadow SELinux Boolean - Set SELinux Boolean cvs_read_shadow
    Accordingly
  ansible.posix.seboolean:
    name: cvs_read_shadow
    state: '{{ var_cvs_read_shadow }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_cvs_read_shadow
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_cvs_read_shadow:var:1" value-id="xccdf_org.ssgproject.content_value_var_cvs_read_shadow"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_cvs_read_shadow:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_cvs_read_shadow_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_daemons_dump_core" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the daemons_dump_core SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>daemons_dump_core</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>daemons_dump_core</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P daemons_dump_core off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_daemons_dump_core" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_daemons_dump_core='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_daemons_dump_core" use="legacy"/>'

    /usr/sbin/setsebool -P daemons_dump_core $var_daemons_dump_core

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_daemons_dump_core" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_daemons_dump_core

- name: Disable the daemons_dump_core SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_daemons_dump_core
- name: XCCDF Value var_daemons_dump_core # promote to variable
  set_fact:
    var_daemons_dump_core: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_daemons_dump_core" use="legacy"/>
  tags:
    - always

- name: Disable the daemons_dump_core SELinux Boolean - Set SELinux Boolean daemons_dump_core
    Accordingly
  ansible.posix.seboolean:
    name: daemons_dump_core
    state: '{{ var_daemons_dump_core }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_daemons_dump_core
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_daemons_dump_core:var:1" value-id="xccdf_org.ssgproject.content_value_var_daemons_dump_core"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_daemons_dump_core:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_daemons_dump_core_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_daemons_enable_cluster_mode" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the daemons_enable_cluster_mode SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>daemons_enable_cluster_mode</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>daemons_enable_cluster_mode</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P daemons_enable_cluster_mode off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_daemons_enable_cluster_mode" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_daemons_enable_cluster_mode='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_daemons_enable_cluster_mode" use="legacy"/>'

    /usr/sbin/setsebool -P daemons_enable_cluster_mode $var_daemons_enable_cluster_mode

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_daemons_enable_cluster_mode" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_daemons_enable_cluster_mode

- name: Disable the daemons_enable_cluster_mode SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_daemons_enable_cluster_mode
- name: XCCDF Value var_daemons_enable_cluster_mode # promote to variable
  set_fact:
    var_daemons_enable_cluster_mode: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_daemons_enable_cluster_mode" use="legacy"/>
  tags:
    - always

- name: Disable the daemons_enable_cluster_mode SELinux Boolean - Set SELinux Boolean
    daemons_enable_cluster_mode Accordingly
  ansible.posix.seboolean:
    name: daemons_enable_cluster_mode
    state: '{{ var_daemons_enable_cluster_mode }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_daemons_enable_cluster_mode
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_daemons_enable_cluster_mode:var:1" value-id="xccdf_org.ssgproject.content_value_var_daemons_enable_cluster_mode"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_daemons_enable_cluster_mode:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_daemons_enable_cluster_mode_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_daemons_use_tcp_wrapper" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the daemons_use_tcp_wrapper SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>daemons_use_tcp_wrapper</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>daemons_use_tcp_wrapper</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P daemons_use_tcp_wrapper off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_daemons_use_tcp_wrapper" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_daemons_use_tcp_wrapper='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_daemons_use_tcp_wrapper" use="legacy"/>'

    /usr/sbin/setsebool -P daemons_use_tcp_wrapper $var_daemons_use_tcp_wrapper

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_daemons_use_tcp_wrapper" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_daemons_use_tcp_wrapper

- name: Disable the daemons_use_tcp_wrapper SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_daemons_use_tcp_wrapper
- name: XCCDF Value var_daemons_use_tcp_wrapper # promote to variable
  set_fact:
    var_daemons_use_tcp_wrapper: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_daemons_use_tcp_wrapper" use="legacy"/>
  tags:
    - always

- name: Disable the daemons_use_tcp_wrapper SELinux Boolean - Set SELinux Boolean
    daemons_use_tcp_wrapper Accordingly
  ansible.posix.seboolean:
    name: daemons_use_tcp_wrapper
    state: '{{ var_daemons_use_tcp_wrapper }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_daemons_use_tcp_wrapper
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_daemons_use_tcp_wrapper:var:1" value-id="xccdf_org.ssgproject.content_value_var_daemons_use_tcp_wrapper"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_daemons_use_tcp_wrapper:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_daemons_use_tcp_wrapper_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_daemons_use_tty" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the daemons_use_tty SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>daemons_use_tty</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>daemons_use_tty</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P daemons_use_tty off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_daemons_use_tty" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_daemons_use_tty='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_daemons_use_tty" use="legacy"/>'

    /usr/sbin/setsebool -P daemons_use_tty $var_daemons_use_tty

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_daemons_use_tty" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_daemons_use_tty

- name: Disable the daemons_use_tty SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_daemons_use_tty
- name: XCCDF Value var_daemons_use_tty # promote to variable
  set_fact:
    var_daemons_use_tty: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_daemons_use_tty" use="legacy"/>
  tags:
    - always

- name: Disable the daemons_use_tty SELinux Boolean - Set SELinux Boolean daemons_use_tty
    Accordingly
  ansible.posix.seboolean:
    name: daemons_use_tty
    state: '{{ var_daemons_use_tty }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_daemons_use_tty
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_daemons_use_tty:var:1" value-id="xccdf_org.ssgproject.content_value_var_daemons_use_tty"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_daemons_use_tty:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_daemons_use_tty_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_dbadm_exec_content" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the dbadm_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>dbadm_exec_content</html:code> is enabled.
If this setting is disabled, it should be enabled.

To enable the <html:code>dbadm_exec_content</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P dbadm_exec_content on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_dbadm_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_dbadm_exec_content='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_dbadm_exec_content" use="legacy"/>'

    /usr/sbin/setsebool -P dbadm_exec_content $var_dbadm_exec_content

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_dbadm_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_dbadm_exec_content

- name: Enable the dbadm_exec_content SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_dbadm_exec_content
- name: XCCDF Value var_dbadm_exec_content # promote to variable
  set_fact:
    var_dbadm_exec_content: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_dbadm_exec_content" use="legacy"/>
  tags:
    - always

- name: Enable the dbadm_exec_content SELinux Boolean - Set SELinux Boolean dbadm_exec_content
    Accordingly
  ansible.posix.seboolean:
    name: dbadm_exec_content
    state: '{{ var_dbadm_exec_content }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_dbadm_exec_content
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_dbadm_exec_content:var:1" value-id="xccdf_org.ssgproject.content_value_var_dbadm_exec_content"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_dbadm_exec_content:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_dbadm_exec_content_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_dbadm_manage_user_files" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the dbadm_manage_user_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>dbadm_manage_user_files</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>dbadm_manage_user_files</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P dbadm_manage_user_files off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_dbadm_manage_user_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_dbadm_manage_user_files='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_dbadm_manage_user_files" use="legacy"/>'

    /usr/sbin/setsebool -P dbadm_manage_user_files $var_dbadm_manage_user_files

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_dbadm_manage_user_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_dbadm_manage_user_files

- name: Disable the dbadm_manage_user_files SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_dbadm_manage_user_files
- name: XCCDF Value var_dbadm_manage_user_files # promote to variable
  set_fact:
    var_dbadm_manage_user_files: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_dbadm_manage_user_files" use="legacy"/>
  tags:
    - always

- name: Disable the dbadm_manage_user_files SELinux Boolean - Set SELinux Boolean
    dbadm_manage_user_files Accordingly
  ansible.posix.seboolean:
    name: dbadm_manage_user_files
    state: '{{ var_dbadm_manage_user_files }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_dbadm_manage_user_files
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_dbadm_manage_user_files:var:1" value-id="xccdf_org.ssgproject.content_value_var_dbadm_manage_user_files"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_dbadm_manage_user_files:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_dbadm_manage_user_files_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_dbadm_read_user_files" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the dbadm_read_user_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>dbadm_read_user_files</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>dbadm_read_user_files</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P dbadm_read_user_files off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_dbadm_read_user_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_dbadm_read_user_files='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_dbadm_read_user_files" use="legacy"/>'

    /usr/sbin/setsebool -P dbadm_read_user_files $var_dbadm_read_user_files

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_dbadm_read_user_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_dbadm_read_user_files

- name: Disable the dbadm_read_user_files SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_dbadm_read_user_files
- name: XCCDF Value var_dbadm_read_user_files # promote to variable
  set_fact:
    var_dbadm_read_user_files: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_dbadm_read_user_files" use="legacy"/>
  tags:
    - always

- name: Disable the dbadm_read_user_files SELinux Boolean - Set SELinux Boolean dbadm_read_user_files
    Accordingly
  ansible.posix.seboolean:
    name: dbadm_read_user_files
    state: '{{ var_dbadm_read_user_files }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_dbadm_read_user_files
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_dbadm_read_user_files:var:1" value-id="xccdf_org.ssgproject.content_value_var_dbadm_read_user_files"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_dbadm_read_user_files:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_dbadm_read_user_files_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_deny_execmem" selected="false" severity="medium">
              <xccdf-1.2:title>Configure the deny_execmem SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>deny_execmem</html:code> is disabled.
This setting should be configured to <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_deny_execmem" use="legacy"/>.
<html:br/>
To set the <html:code>deny_execmem</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P deny_execmem <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_deny_execmem" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule doesn't come with a remediation, as enabling this SELinux boolean can cause
applications to malfunction, for example Graphical login managers and Firefox.</xccdf-1.2:warning>
              <xccdf-1.2:warning category="functionality">Proper function and stability should be assessed before applying enabling the SELinux
boolean in production systems.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R48</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Allowing user domain applications to map a memory region as both writable and
executable makes them more susceptible to data execution attacks.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_deny_execmem:var:1" value-id="xccdf_org.ssgproject.content_value_var_deny_execmem"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_deny_execmem:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_deny_execmem_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_deny_ptrace" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the deny_ptrace SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>deny_ptrace</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>deny_ptrace</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P deny_ptrace off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_deny_ptrace" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_deny_ptrace='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_deny_ptrace" use="legacy"/>'

    /usr/sbin/setsebool -P deny_ptrace $var_deny_ptrace

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_deny_ptrace" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_deny_ptrace

- name: Disable the deny_ptrace SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_deny_ptrace
- name: XCCDF Value var_deny_ptrace # promote to variable
  set_fact:
    var_deny_ptrace: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_deny_ptrace" use="legacy"/>
  tags:
    - always

- name: Disable the deny_ptrace SELinux Boolean - Set SELinux Boolean deny_ptrace
    Accordingly
  ansible.posix.seboolean:
    name: deny_ptrace
    state: '{{ var_deny_ptrace }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_deny_ptrace
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_deny_ptrace:var:1" value-id="xccdf_org.ssgproject.content_value_var_deny_ptrace"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_deny_ptrace:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_deny_ptrace_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_dhcpc_exec_iptables" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the dhcpc_exec_iptables SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>dhcpc_exec_iptables</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>dhcpc_exec_iptables</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P dhcpc_exec_iptables off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_dhcpc_exec_iptables" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_dhcpc_exec_iptables='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_dhcpc_exec_iptables" use="legacy"/>'

    /usr/sbin/setsebool -P dhcpc_exec_iptables $var_dhcpc_exec_iptables

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_dhcpc_exec_iptables" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_dhcpc_exec_iptables

- name: Disable the dhcpc_exec_iptables SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_dhcpc_exec_iptables
- name: XCCDF Value var_dhcpc_exec_iptables # promote to variable
  set_fact:
    var_dhcpc_exec_iptables: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_dhcpc_exec_iptables" use="legacy"/>
  tags:
    - always

- name: Disable the dhcpc_exec_iptables SELinux Boolean - Set SELinux Boolean dhcpc_exec_iptables
    Accordingly
  ansible.posix.seboolean:
    name: dhcpc_exec_iptables
    state: '{{ var_dhcpc_exec_iptables }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_dhcpc_exec_iptables
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_dhcpc_exec_iptables:var:1" value-id="xccdf_org.ssgproject.content_value_var_dhcpc_exec_iptables"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_dhcpc_exec_iptables:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_dhcpc_exec_iptables_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_dhcpd_use_ldap" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the dhcpd_use_ldap SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>dhcpd_use_ldap</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>dhcpd_use_ldap</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P dhcpd_use_ldap off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_dhcpd_use_ldap" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_dhcpd_use_ldap='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_dhcpd_use_ldap" use="legacy"/>'

    /usr/sbin/setsebool -P dhcpd_use_ldap $var_dhcpd_use_ldap

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_dhcpd_use_ldap" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_dhcpd_use_ldap

- name: Disable the dhcpd_use_ldap SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_dhcpd_use_ldap
- name: XCCDF Value var_dhcpd_use_ldap # promote to variable
  set_fact:
    var_dhcpd_use_ldap: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_dhcpd_use_ldap" use="legacy"/>
  tags:
    - always

- name: Disable the dhcpd_use_ldap SELinux Boolean - Set SELinux Boolean dhcpd_use_ldap
    Accordingly
  ansible.posix.seboolean:
    name: dhcpd_use_ldap
    state: '{{ var_dhcpd_use_ldap }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_dhcpd_use_ldap
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_dhcpd_use_ldap:var:1" value-id="xccdf_org.ssgproject.content_value_var_dhcpd_use_ldap"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_dhcpd_use_ldap:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_dhcpd_use_ldap_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_domain_fd_use" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the domain_fd_use SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>domain_fd_use</html:code> is enabled.
If this setting is disabled, it should be enabled.

To enable the <html:code>domain_fd_use</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P domain_fd_use on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_domain_fd_use" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_domain_fd_use='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_domain_fd_use" use="legacy"/>'

    /usr/sbin/setsebool -P domain_fd_use $var_domain_fd_use

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_domain_fd_use" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_domain_fd_use

- name: Enable the domain_fd_use SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_domain_fd_use
- name: XCCDF Value var_domain_fd_use # promote to variable
  set_fact:
    var_domain_fd_use: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_domain_fd_use" use="legacy"/>
  tags:
    - always

- name: Enable the domain_fd_use SELinux Boolean - Set SELinux Boolean domain_fd_use
    Accordingly
  ansible.posix.seboolean:
    name: domain_fd_use
    state: '{{ var_domain_fd_use }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_domain_fd_use
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_domain_fd_use:var:1" value-id="xccdf_org.ssgproject.content_value_var_domain_fd_use"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_domain_fd_use:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_domain_fd_use_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_domain_kernel_load_modules" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the domain_kernel_load_modules SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>domain_kernel_load_modules</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>domain_kernel_load_modules</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P domain_kernel_load_modules off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_domain_kernel_load_modules" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_domain_kernel_load_modules='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_domain_kernel_load_modules" use="legacy"/>'

    /usr/sbin/setsebool -P domain_kernel_load_modules $var_domain_kernel_load_modules

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_domain_kernel_load_modules" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_domain_kernel_load_modules

- name: Disable the domain_kernel_load_modules SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_domain_kernel_load_modules
- name: XCCDF Value var_domain_kernel_load_modules # promote to variable
  set_fact:
    var_domain_kernel_load_modules: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_domain_kernel_load_modules" use="legacy"/>
  tags:
    - always

- name: Disable the domain_kernel_load_modules SELinux Boolean - Set SELinux Boolean
    domain_kernel_load_modules Accordingly
  ansible.posix.seboolean:
    name: domain_kernel_load_modules
    state: '{{ var_domain_kernel_load_modules }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_domain_kernel_load_modules
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_domain_kernel_load_modules:var:1" value-id="xccdf_org.ssgproject.content_value_var_domain_kernel_load_modules"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_domain_kernel_load_modules:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_domain_kernel_load_modules_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_entropyd_use_audio" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the entropyd_use_audio SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>entropyd_use_audio</html:code> is enabled.
This setting should be disabled as it uses audit input to generate entropy.

To disable the <html:code>entropyd_use_audio</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P entropyd_use_audio off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_entropyd_use_audio" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_entropyd_use_audio='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_entropyd_use_audio" use="legacy"/>'

    /usr/sbin/setsebool -P entropyd_use_audio $var_entropyd_use_audio

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_entropyd_use_audio" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_entropyd_use_audio

- name: Disable the entropyd_use_audio SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_entropyd_use_audio
- name: XCCDF Value var_entropyd_use_audio # promote to variable
  set_fact:
    var_entropyd_use_audio: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_entropyd_use_audio" use="legacy"/>
  tags:
    - always

- name: Disable the entropyd_use_audio SELinux Boolean - Set SELinux Boolean entropyd_use_audio
    Accordingly
  ansible.posix.seboolean:
    name: entropyd_use_audio
    state: '{{ var_entropyd_use_audio }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_entropyd_use_audio
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_entropyd_use_audio:var:1" value-id="xccdf_org.ssgproject.content_value_var_entropyd_use_audio"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_entropyd_use_audio:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_entropyd_use_audio_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_exim_can_connect_db" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the exim_can_connect_db SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>exim_can_connect_db</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>exim_can_connect_db</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P exim_can_connect_db off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_exim_can_connect_db" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_exim_can_connect_db='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_exim_can_connect_db" use="legacy"/>'

    /usr/sbin/setsebool -P exim_can_connect_db $var_exim_can_connect_db

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_exim_can_connect_db" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_exim_can_connect_db

- name: Disable the exim_can_connect_db SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_exim_can_connect_db
- name: XCCDF Value var_exim_can_connect_db # promote to variable
  set_fact:
    var_exim_can_connect_db: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_exim_can_connect_db" use="legacy"/>
  tags:
    - always

- name: Disable the exim_can_connect_db SELinux Boolean - Set SELinux Boolean exim_can_connect_db
    Accordingly
  ansible.posix.seboolean:
    name: exim_can_connect_db
    state: '{{ var_exim_can_connect_db }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_exim_can_connect_db
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_exim_can_connect_db:var:1" value-id="xccdf_org.ssgproject.content_value_var_exim_can_connect_db"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_exim_can_connect_db:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_exim_can_connect_db_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_exim_manage_user_files" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the exim_manage_user_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>exim_manage_user_files</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>exim_manage_user_files</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P exim_manage_user_files off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_exim_manage_user_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_exim_manage_user_files='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_exim_manage_user_files" use="legacy"/>'

    /usr/sbin/setsebool -P exim_manage_user_files $var_exim_manage_user_files

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_exim_manage_user_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_exim_manage_user_files

- name: Disable the exim_manage_user_files SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_exim_manage_user_files
- name: XCCDF Value var_exim_manage_user_files # promote to variable
  set_fact:
    var_exim_manage_user_files: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_exim_manage_user_files" use="legacy"/>
  tags:
    - always

- name: Disable the exim_manage_user_files SELinux Boolean - Set SELinux Boolean exim_manage_user_files
    Accordingly
  ansible.posix.seboolean:
    name: exim_manage_user_files
    state: '{{ var_exim_manage_user_files }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_exim_manage_user_files
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_exim_manage_user_files:var:1" value-id="xccdf_org.ssgproject.content_value_var_exim_manage_user_files"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_exim_manage_user_files:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_exim_manage_user_files_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_exim_read_user_files" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the exim_read_user_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>exim_read_user_files</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>exim_read_user_files</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P exim_read_user_files off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_exim_read_user_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_exim_read_user_files='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_exim_read_user_files" use="legacy"/>'

    /usr/sbin/setsebool -P exim_read_user_files $var_exim_read_user_files

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_exim_read_user_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_exim_read_user_files

- name: Disable the exim_read_user_files SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_exim_read_user_files
- name: XCCDF Value var_exim_read_user_files # promote to variable
  set_fact:
    var_exim_read_user_files: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_exim_read_user_files" use="legacy"/>
  tags:
    - always

- name: Disable the exim_read_user_files SELinux Boolean - Set SELinux Boolean exim_read_user_files
    Accordingly
  ansible.posix.seboolean:
    name: exim_read_user_files
    state: '{{ var_exim_read_user_files }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_exim_read_user_files
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_exim_read_user_files:var:1" value-id="xccdf_org.ssgproject.content_value_var_exim_read_user_files"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_exim_read_user_files:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_exim_read_user_files_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_fcron_crond" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the fcron_crond SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>fcron_crond</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>fcron_crond</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P fcron_crond off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_fcron_crond" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_fcron_crond='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_fcron_crond" use="legacy"/>'

    /usr/sbin/setsebool -P fcron_crond $var_fcron_crond

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_fcron_crond" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_fcron_crond

- name: Disable the fcron_crond SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_fcron_crond
- name: XCCDF Value var_fcron_crond # promote to variable
  set_fact:
    var_fcron_crond: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_fcron_crond" use="legacy"/>
  tags:
    - always

- name: Disable the fcron_crond SELinux Boolean - Set SELinux Boolean fcron_crond
    Accordingly
  ansible.posix.seboolean:
    name: fcron_crond
    state: '{{ var_fcron_crond }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_fcron_crond
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_fcron_crond:var:1" value-id="xccdf_org.ssgproject.content_value_var_fcron_crond"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_fcron_crond:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_fcron_crond_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_fenced_can_network_connect" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the fenced_can_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>fenced_can_network_connect</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>fenced_can_network_connect</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P fenced_can_network_connect off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_fenced_can_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_fenced_can_network_connect='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_fenced_can_network_connect" use="legacy"/>'

    /usr/sbin/setsebool -P fenced_can_network_connect $var_fenced_can_network_connect

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_fenced_can_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_fenced_can_network_connect

- name: Disable the fenced_can_network_connect SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_fenced_can_network_connect
- name: XCCDF Value var_fenced_can_network_connect # promote to variable
  set_fact:
    var_fenced_can_network_connect: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_fenced_can_network_connect" use="legacy"/>
  tags:
    - always

- name: Disable the fenced_can_network_connect SELinux Boolean - Set SELinux Boolean
    fenced_can_network_connect Accordingly
  ansible.posix.seboolean:
    name: fenced_can_network_connect
    state: '{{ var_fenced_can_network_connect }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_fenced_can_network_connect
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_fenced_can_network_connect:var:1" value-id="xccdf_org.ssgproject.content_value_var_fenced_can_network_connect"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_fenced_can_network_connect:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_fenced_can_network_connect_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_fenced_can_ssh" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the fenced_can_ssh SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>fenced_can_ssh</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>fenced_can_ssh</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P fenced_can_ssh off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_fenced_can_ssh" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_fenced_can_ssh='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_fenced_can_ssh" use="legacy"/>'

    /usr/sbin/setsebool -P fenced_can_ssh $var_fenced_can_ssh

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_fenced_can_ssh" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_fenced_can_ssh

- name: Disable the fenced_can_ssh SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_fenced_can_ssh
- name: XCCDF Value var_fenced_can_ssh # promote to variable
  set_fact:
    var_fenced_can_ssh: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_fenced_can_ssh" use="legacy"/>
  tags:
    - always

- name: Disable the fenced_can_ssh SELinux Boolean - Set SELinux Boolean fenced_can_ssh
    Accordingly
  ansible.posix.seboolean:
    name: fenced_can_ssh
    state: '{{ var_fenced_can_ssh }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_fenced_can_ssh
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_fenced_can_ssh:var:1" value-id="xccdf_org.ssgproject.content_value_var_fenced_can_ssh"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_fenced_can_ssh:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_fenced_can_ssh_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_fips_mode" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the fips_mode SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>fips_mode</html:code> is enabled.
This allows all SELinux domains to execute in <html:code>fips_mode</html:code>.
If this setting is disabled, it should be enabled.

To enable the <html:code>fips_mode</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P fips_mode on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.13.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_fips_mode" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_fips_mode='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_fips_mode" use="legacy"/>'

    /usr/sbin/setsebool -P fips_mode $var_fips_mode

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_fips_mode" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-7
  - NIST-800-53-SC-12
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_fips_mode

- name: Enable the fips_mode SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-7
  - NIST-800-53-SC-12
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_fips_mode
- name: XCCDF Value var_fips_mode # promote to variable
  set_fact:
    var_fips_mode: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_fips_mode" use="legacy"/>
  tags:
    - always

- name: Enable the fips_mode SELinux Boolean - Set SELinux Boolean fips_mode Accordingly
  ansible.posix.seboolean:
    name: fips_mode
    state: '{{ var_fips_mode }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - NIST-800-171-3.13.11
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-7
  - NIST-800-53-SC-12
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_fips_mode
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_fips_mode:var:1" value-id="xccdf_org.ssgproject.content_value_var_fips_mode"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_fips_mode:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_fips_mode_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_ftpd_anon_write" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the ftpd_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>ftpd_anon_write</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>ftpd_anon_write</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P ftpd_anon_write off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ftpd_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_ftpd_anon_write='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ftpd_anon_write" use="legacy"/>'

    /usr/sbin/setsebool -P ftpd_anon_write $var_ftpd_anon_write

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ftpd_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_anon_write

- name: Disable the ftpd_anon_write SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_anon_write
- name: XCCDF Value var_ftpd_anon_write # promote to variable
  set_fact:
    var_ftpd_anon_write: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ftpd_anon_write" use="legacy"/>
  tags:
    - always

- name: Disable the ftpd_anon_write SELinux Boolean - Set SELinux Boolean ftpd_anon_write
    Accordingly
  ansible.posix.seboolean:
    name: ftpd_anon_write
    state: '{{ var_ftpd_anon_write }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_anon_write
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_ftpd_anon_write:var:1" value-id="xccdf_org.ssgproject.content_value_var_ftpd_anon_write"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_ftpd_anon_write:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_ftpd_anon_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_ftpd_connect_all_unreserved" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the ftpd_connect_all_unreserved SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>ftpd_connect_all_unreserved</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>ftpd_connect_all_unreserved</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P ftpd_connect_all_unreserved off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ftpd_connect_all_unreserved" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_ftpd_connect_all_unreserved='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ftpd_connect_all_unreserved" use="legacy"/>'

    /usr/sbin/setsebool -P ftpd_connect_all_unreserved $var_ftpd_connect_all_unreserved

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ftpd_connect_all_unreserved" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_connect_all_unreserved

- name: Disable the ftpd_connect_all_unreserved SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_connect_all_unreserved
- name: XCCDF Value var_ftpd_connect_all_unreserved # promote to variable
  set_fact:
    var_ftpd_connect_all_unreserved: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ftpd_connect_all_unreserved" use="legacy"/>
  tags:
    - always

- name: Disable the ftpd_connect_all_unreserved SELinux Boolean - Set SELinux Boolean
    ftpd_connect_all_unreserved Accordingly
  ansible.posix.seboolean:
    name: ftpd_connect_all_unreserved
    state: '{{ var_ftpd_connect_all_unreserved }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_connect_all_unreserved
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_ftpd_connect_all_unreserved:var:1" value-id="xccdf_org.ssgproject.content_value_var_ftpd_connect_all_unreserved"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_ftpd_connect_all_unreserved:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_ftpd_connect_all_unreserved_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_ftpd_connect_db" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the ftpd_connect_db SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>ftpd_connect_db</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>ftpd_connect_db</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P ftpd_connect_db off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ftpd_connect_db" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_ftpd_connect_db='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ftpd_connect_db" use="legacy"/>'

    /usr/sbin/setsebool -P ftpd_connect_db $var_ftpd_connect_db

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ftpd_connect_db" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_connect_db

- name: Disable the ftpd_connect_db SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_connect_db
- name: XCCDF Value var_ftpd_connect_db # promote to variable
  set_fact:
    var_ftpd_connect_db: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ftpd_connect_db" use="legacy"/>
  tags:
    - always

- name: Disable the ftpd_connect_db SELinux Boolean - Set SELinux Boolean ftpd_connect_db
    Accordingly
  ansible.posix.seboolean:
    name: ftpd_connect_db
    state: '{{ var_ftpd_connect_db }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_connect_db
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_ftpd_connect_db:var:1" value-id="xccdf_org.ssgproject.content_value_var_ftpd_connect_db"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_ftpd_connect_db:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_ftpd_connect_db_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_ftpd_full_access" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the ftpd_full_access SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>ftpd_full_access</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>ftpd_full_access</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P ftpd_full_access off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ftpd_full_access" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_ftpd_full_access='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ftpd_full_access" use="legacy"/>'

    /usr/sbin/setsebool -P ftpd_full_access $var_ftpd_full_access

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ftpd_full_access" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_full_access

- name: Disable the ftpd_full_access SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_full_access
- name: XCCDF Value var_ftpd_full_access # promote to variable
  set_fact:
    var_ftpd_full_access: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ftpd_full_access" use="legacy"/>
  tags:
    - always

- name: Disable the ftpd_full_access SELinux Boolean - Set SELinux Boolean ftpd_full_access
    Accordingly
  ansible.posix.seboolean:
    name: ftpd_full_access
    state: '{{ var_ftpd_full_access }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_full_access
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_ftpd_full_access:var:1" value-id="xccdf_org.ssgproject.content_value_var_ftpd_full_access"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_ftpd_full_access:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_ftpd_full_access_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_ftpd_use_cifs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the ftpd_use_cifs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>ftpd_use_cifs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>ftpd_use_cifs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P ftpd_use_cifs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ftpd_use_cifs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_ftpd_use_cifs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ftpd_use_cifs" use="legacy"/>'

    /usr/sbin/setsebool -P ftpd_use_cifs $var_ftpd_use_cifs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ftpd_use_cifs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_use_cifs

- name: Disable the ftpd_use_cifs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_use_cifs
- name: XCCDF Value var_ftpd_use_cifs # promote to variable
  set_fact:
    var_ftpd_use_cifs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ftpd_use_cifs" use="legacy"/>
  tags:
    - always

- name: Disable the ftpd_use_cifs SELinux Boolean - Set SELinux Boolean ftpd_use_cifs
    Accordingly
  ansible.posix.seboolean:
    name: ftpd_use_cifs
    state: '{{ var_ftpd_use_cifs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_use_cifs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_ftpd_use_cifs:var:1" value-id="xccdf_org.ssgproject.content_value_var_ftpd_use_cifs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_ftpd_use_cifs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_ftpd_use_cifs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_ftpd_use_fusefs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the ftpd_use_fusefs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>ftpd_use_fusefs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>ftpd_use_fusefs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P ftpd_use_fusefs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ftpd_use_fusefs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_ftpd_use_fusefs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ftpd_use_fusefs" use="legacy"/>'

    /usr/sbin/setsebool -P ftpd_use_fusefs $var_ftpd_use_fusefs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ftpd_use_fusefs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_use_fusefs

- name: Disable the ftpd_use_fusefs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_use_fusefs
- name: XCCDF Value var_ftpd_use_fusefs # promote to variable
  set_fact:
    var_ftpd_use_fusefs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ftpd_use_fusefs" use="legacy"/>
  tags:
    - always

- name: Disable the ftpd_use_fusefs SELinux Boolean - Set SELinux Boolean ftpd_use_fusefs
    Accordingly
  ansible.posix.seboolean:
    name: ftpd_use_fusefs
    state: '{{ var_ftpd_use_fusefs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_use_fusefs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_ftpd_use_fusefs:var:1" value-id="xccdf_org.ssgproject.content_value_var_ftpd_use_fusefs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_ftpd_use_fusefs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_ftpd_use_fusefs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_ftpd_use_nfs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the ftpd_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>ftpd_use_nfs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>ftpd_use_nfs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P ftpd_use_nfs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ftpd_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_ftpd_use_nfs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ftpd_use_nfs" use="legacy"/>'

    /usr/sbin/setsebool -P ftpd_use_nfs $var_ftpd_use_nfs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ftpd_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_use_nfs

- name: Disable the ftpd_use_nfs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_use_nfs
- name: XCCDF Value var_ftpd_use_nfs # promote to variable
  set_fact:
    var_ftpd_use_nfs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ftpd_use_nfs" use="legacy"/>
  tags:
    - always

- name: Disable the ftpd_use_nfs SELinux Boolean - Set SELinux Boolean ftpd_use_nfs
    Accordingly
  ansible.posix.seboolean:
    name: ftpd_use_nfs
    state: '{{ var_ftpd_use_nfs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_use_nfs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_ftpd_use_nfs:var:1" value-id="xccdf_org.ssgproject.content_value_var_ftpd_use_nfs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_ftpd_use_nfs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_ftpd_use_nfs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_ftpd_use_passive_mode" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the ftpd_use_passive_mode SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>ftpd_use_passive_mode</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>ftpd_use_passive_mode</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P ftpd_use_passive_mode off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ftpd_use_passive_mode" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_ftpd_use_passive_mode='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ftpd_use_passive_mode" use="legacy"/>'

    /usr/sbin/setsebool -P ftpd_use_passive_mode $var_ftpd_use_passive_mode

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ftpd_use_passive_mode" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_use_passive_mode

- name: Disable the ftpd_use_passive_mode SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_use_passive_mode
- name: XCCDF Value var_ftpd_use_passive_mode # promote to variable
  set_fact:
    var_ftpd_use_passive_mode: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ftpd_use_passive_mode" use="legacy"/>
  tags:
    - always

- name: Disable the ftpd_use_passive_mode SELinux Boolean - Set SELinux Boolean ftpd_use_passive_mode
    Accordingly
  ansible.posix.seboolean:
    name: ftpd_use_passive_mode
    state: '{{ var_ftpd_use_passive_mode }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ftpd_use_passive_mode
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_ftpd_use_passive_mode:var:1" value-id="xccdf_org.ssgproject.content_value_var_ftpd_use_passive_mode"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_ftpd_use_passive_mode:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_ftpd_use_passive_mode_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_git_cgi_enable_homedirs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the git_cgi_enable_homedirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>git_cgi_enable_homedirs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>git_cgi_enable_homedirs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P git_cgi_enable_homedirs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_git_cgi_enable_homedirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_git_cgi_enable_homedirs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_git_cgi_enable_homedirs" use="legacy"/>'

    /usr/sbin/setsebool -P git_cgi_enable_homedirs $var_git_cgi_enable_homedirs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_git_cgi_enable_homedirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_cgi_enable_homedirs

- name: Disable the git_cgi_enable_homedirs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_cgi_enable_homedirs
- name: XCCDF Value var_git_cgi_enable_homedirs # promote to variable
  set_fact:
    var_git_cgi_enable_homedirs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_git_cgi_enable_homedirs" use="legacy"/>
  tags:
    - always

- name: Disable the git_cgi_enable_homedirs SELinux Boolean - Set SELinux Boolean
    git_cgi_enable_homedirs Accordingly
  ansible.posix.seboolean:
    name: git_cgi_enable_homedirs
    state: '{{ var_git_cgi_enable_homedirs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_cgi_enable_homedirs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_git_cgi_enable_homedirs:var:1" value-id="xccdf_org.ssgproject.content_value_var_git_cgi_enable_homedirs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_git_cgi_enable_homedirs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_git_cgi_enable_homedirs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_git_cgi_use_cifs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the git_cgi_use_cifs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>git_cgi_use_cifs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>git_cgi_use_cifs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P git_cgi_use_cifs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_git_cgi_use_cifs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_git_cgi_use_cifs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_git_cgi_use_cifs" use="legacy"/>'

    /usr/sbin/setsebool -P git_cgi_use_cifs $var_git_cgi_use_cifs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_git_cgi_use_cifs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_cgi_use_cifs

- name: Disable the git_cgi_use_cifs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_cgi_use_cifs
- name: XCCDF Value var_git_cgi_use_cifs # promote to variable
  set_fact:
    var_git_cgi_use_cifs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_git_cgi_use_cifs" use="legacy"/>
  tags:
    - always

- name: Disable the git_cgi_use_cifs SELinux Boolean - Set SELinux Boolean git_cgi_use_cifs
    Accordingly
  ansible.posix.seboolean:
    name: git_cgi_use_cifs
    state: '{{ var_git_cgi_use_cifs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_cgi_use_cifs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_git_cgi_use_cifs:var:1" value-id="xccdf_org.ssgproject.content_value_var_git_cgi_use_cifs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_git_cgi_use_cifs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_git_cgi_use_cifs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_git_cgi_use_nfs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the git_cgi_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>git_cgi_use_nfs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>git_cgi_use_nfs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P git_cgi_use_nfs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_git_cgi_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_git_cgi_use_nfs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_git_cgi_use_nfs" use="legacy"/>'

    /usr/sbin/setsebool -P git_cgi_use_nfs $var_git_cgi_use_nfs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_git_cgi_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_cgi_use_nfs

- name: Disable the git_cgi_use_nfs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_cgi_use_nfs
- name: XCCDF Value var_git_cgi_use_nfs # promote to variable
  set_fact:
    var_git_cgi_use_nfs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_git_cgi_use_nfs" use="legacy"/>
  tags:
    - always

- name: Disable the git_cgi_use_nfs SELinux Boolean - Set SELinux Boolean git_cgi_use_nfs
    Accordingly
  ansible.posix.seboolean:
    name: git_cgi_use_nfs
    state: '{{ var_git_cgi_use_nfs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_cgi_use_nfs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_git_cgi_use_nfs:var:1" value-id="xccdf_org.ssgproject.content_value_var_git_cgi_use_nfs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_git_cgi_use_nfs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_git_cgi_use_nfs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_git_session_bind_all_unreserved_ports" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the git_session_bind_all_unreserved_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>git_session_bind_all_unreserved_ports</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>git_session_bind_all_unreserved_ports</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P git_session_bind_all_unreserved_ports off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_git_session_bind_all_unreserved_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_git_session_bind_all_unreserved_ports='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_git_session_bind_all_unreserved_ports" use="legacy"/>'

    /usr/sbin/setsebool -P git_session_bind_all_unreserved_ports $var_git_session_bind_all_unreserved_ports

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_git_session_bind_all_unreserved_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_session_bind_all_unreserved_ports

- name: Disable the git_session_bind_all_unreserved_ports SELinux Boolean - Ensure
    libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_session_bind_all_unreserved_ports
- name: XCCDF Value var_git_session_bind_all_unreserved_ports # promote to variable
  set_fact:
    var_git_session_bind_all_unreserved_ports: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_git_session_bind_all_unreserved_ports" use="legacy"/>
  tags:
    - always

- name: Disable the git_session_bind_all_unreserved_ports SELinux Boolean - Set SELinux
    Boolean git_session_bind_all_unreserved_ports Accordingly
  ansible.posix.seboolean:
    name: git_session_bind_all_unreserved_ports
    state: '{{ var_git_session_bind_all_unreserved_ports }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_session_bind_all_unreserved_ports
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_git_session_bind_all_unreserved_ports:var:1" value-id="xccdf_org.ssgproject.content_value_var_git_session_bind_all_unreserved_ports"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_git_session_bind_all_unreserved_ports:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_git_session_bind_all_unreserved_ports_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_git_session_users" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the git_session_users SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>git_session_users</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>git_session_users</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P git_session_users off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_git_session_users" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_git_session_users='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_git_session_users" use="legacy"/>'

    /usr/sbin/setsebool -P git_session_users $var_git_session_users

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_git_session_users" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_session_users

- name: Disable the git_session_users SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_session_users
- name: XCCDF Value var_git_session_users # promote to variable
  set_fact:
    var_git_session_users: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_git_session_users" use="legacy"/>
  tags:
    - always

- name: Disable the git_session_users SELinux Boolean - Set SELinux Boolean git_session_users
    Accordingly
  ansible.posix.seboolean:
    name: git_session_users
    state: '{{ var_git_session_users }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_session_users
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_git_session_users:var:1" value-id="xccdf_org.ssgproject.content_value_var_git_session_users"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_git_session_users:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_git_session_users_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_git_system_enable_homedirs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the git_system_enable_homedirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>git_system_enable_homedirs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>git_system_enable_homedirs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P git_system_enable_homedirs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_git_system_enable_homedirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_git_system_enable_homedirs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_git_system_enable_homedirs" use="legacy"/>'

    /usr/sbin/setsebool -P git_system_enable_homedirs $var_git_system_enable_homedirs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_git_system_enable_homedirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_system_enable_homedirs

- name: Disable the git_system_enable_homedirs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_system_enable_homedirs
- name: XCCDF Value var_git_system_enable_homedirs # promote to variable
  set_fact:
    var_git_system_enable_homedirs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_git_system_enable_homedirs" use="legacy"/>
  tags:
    - always

- name: Disable the git_system_enable_homedirs SELinux Boolean - Set SELinux Boolean
    git_system_enable_homedirs Accordingly
  ansible.posix.seboolean:
    name: git_system_enable_homedirs
    state: '{{ var_git_system_enable_homedirs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_system_enable_homedirs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_git_system_enable_homedirs:var:1" value-id="xccdf_org.ssgproject.content_value_var_git_system_enable_homedirs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_git_system_enable_homedirs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_git_system_enable_homedirs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_git_system_use_cifs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the git_system_use_cifs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>git_system_use_cifs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>git_system_use_cifs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P git_system_use_cifs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_git_system_use_cifs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_git_system_use_cifs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_git_system_use_cifs" use="legacy"/>'

    /usr/sbin/setsebool -P git_system_use_cifs $var_git_system_use_cifs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_git_system_use_cifs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_system_use_cifs

- name: Disable the git_system_use_cifs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_system_use_cifs
- name: XCCDF Value var_git_system_use_cifs # promote to variable
  set_fact:
    var_git_system_use_cifs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_git_system_use_cifs" use="legacy"/>
  tags:
    - always

- name: Disable the git_system_use_cifs SELinux Boolean - Set SELinux Boolean git_system_use_cifs
    Accordingly
  ansible.posix.seboolean:
    name: git_system_use_cifs
    state: '{{ var_git_system_use_cifs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_system_use_cifs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_git_system_use_cifs:var:1" value-id="xccdf_org.ssgproject.content_value_var_git_system_use_cifs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_git_system_use_cifs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_git_system_use_cifs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_git_system_use_nfs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the git_system_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>git_system_use_nfs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>git_system_use_nfs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P git_system_use_nfs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_git_system_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_git_system_use_nfs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_git_system_use_nfs" use="legacy"/>'

    /usr/sbin/setsebool -P git_system_use_nfs $var_git_system_use_nfs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_git_system_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_system_use_nfs

- name: Disable the git_system_use_nfs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_system_use_nfs
- name: XCCDF Value var_git_system_use_nfs # promote to variable
  set_fact:
    var_git_system_use_nfs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_git_system_use_nfs" use="legacy"/>
  tags:
    - always

- name: Disable the git_system_use_nfs SELinux Boolean - Set SELinux Boolean git_system_use_nfs
    Accordingly
  ansible.posix.seboolean:
    name: git_system_use_nfs
    state: '{{ var_git_system_use_nfs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_git_system_use_nfs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_git_system_use_nfs:var:1" value-id="xccdf_org.ssgproject.content_value_var_git_system_use_nfs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_git_system_use_nfs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_git_system_use_nfs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_gitosis_can_sendmail" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the gitosis_can_sendmail SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>gitosis_can_sendmail</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>gitosis_can_sendmail</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P gitosis_can_sendmail off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_gitosis_can_sendmail" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_gitosis_can_sendmail='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_gitosis_can_sendmail" use="legacy"/>'

    /usr/sbin/setsebool -P gitosis_can_sendmail $var_gitosis_can_sendmail

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_gitosis_can_sendmail" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gitosis_can_sendmail

- name: Disable the gitosis_can_sendmail SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gitosis_can_sendmail
- name: XCCDF Value var_gitosis_can_sendmail # promote to variable
  set_fact:
    var_gitosis_can_sendmail: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_gitosis_can_sendmail" use="legacy"/>
  tags:
    - always

- name: Disable the gitosis_can_sendmail SELinux Boolean - Set SELinux Boolean gitosis_can_sendmail
    Accordingly
  ansible.posix.seboolean:
    name: gitosis_can_sendmail
    state: '{{ var_gitosis_can_sendmail }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gitosis_can_sendmail
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_gitosis_can_sendmail:var:1" value-id="xccdf_org.ssgproject.content_value_var_gitosis_can_sendmail"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_gitosis_can_sendmail:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_gitosis_can_sendmail_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_glance_api_can_network" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the glance_api_can_network SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>glance_api_can_network</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>glance_api_can_network</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P glance_api_can_network off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_glance_api_can_network" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_glance_api_can_network='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_glance_api_can_network" use="legacy"/>'

    /usr/sbin/setsebool -P glance_api_can_network $var_glance_api_can_network

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_glance_api_can_network" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_glance_api_can_network

- name: Disable the glance_api_can_network SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_glance_api_can_network
- name: XCCDF Value var_glance_api_can_network # promote to variable
  set_fact:
    var_glance_api_can_network: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_glance_api_can_network" use="legacy"/>
  tags:
    - always

- name: Disable the glance_api_can_network SELinux Boolean - Set SELinux Boolean glance_api_can_network
    Accordingly
  ansible.posix.seboolean:
    name: glance_api_can_network
    state: '{{ var_glance_api_can_network }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_glance_api_can_network
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_glance_api_can_network:var:1" value-id="xccdf_org.ssgproject.content_value_var_glance_api_can_network"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_glance_api_can_network:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_glance_api_can_network_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_glance_use_execmem" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the glance_use_execmem SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>glance_use_execmem</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>glance_use_execmem</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P glance_use_execmem off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_glance_use_execmem" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_glance_use_execmem='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_glance_use_execmem" use="legacy"/>'

    /usr/sbin/setsebool -P glance_use_execmem $var_glance_use_execmem

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_glance_use_execmem" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_glance_use_execmem

- name: Disable the glance_use_execmem SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_glance_use_execmem
- name: XCCDF Value var_glance_use_execmem # promote to variable
  set_fact:
    var_glance_use_execmem: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_glance_use_execmem" use="legacy"/>
  tags:
    - always

- name: Disable the glance_use_execmem SELinux Boolean - Set SELinux Boolean glance_use_execmem
    Accordingly
  ansible.posix.seboolean:
    name: glance_use_execmem
    state: '{{ var_glance_use_execmem }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_glance_use_execmem
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_glance_use_execmem:var:1" value-id="xccdf_org.ssgproject.content_value_var_glance_use_execmem"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_glance_use_execmem:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_glance_use_execmem_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_glance_use_fusefs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the glance_use_fusefs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>glance_use_fusefs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>glance_use_fusefs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P glance_use_fusefs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_glance_use_fusefs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_glance_use_fusefs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_glance_use_fusefs" use="legacy"/>'

    /usr/sbin/setsebool -P glance_use_fusefs $var_glance_use_fusefs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_glance_use_fusefs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_glance_use_fusefs

- name: Disable the glance_use_fusefs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_glance_use_fusefs
- name: XCCDF Value var_glance_use_fusefs # promote to variable
  set_fact:
    var_glance_use_fusefs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_glance_use_fusefs" use="legacy"/>
  tags:
    - always

- name: Disable the glance_use_fusefs SELinux Boolean - Set SELinux Boolean glance_use_fusefs
    Accordingly
  ansible.posix.seboolean:
    name: glance_use_fusefs
    state: '{{ var_glance_use_fusefs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_glance_use_fusefs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_glance_use_fusefs:var:1" value-id="xccdf_org.ssgproject.content_value_var_glance_use_fusefs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_glance_use_fusefs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_glance_use_fusefs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_global_ssp" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the global_ssp SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>global_ssp</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>global_ssp</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P global_ssp off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_global_ssp" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_global_ssp='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_global_ssp" use="legacy"/>'

    /usr/sbin/setsebool -P global_ssp $var_global_ssp

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_global_ssp" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_global_ssp

- name: Disable the global_ssp SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_global_ssp
- name: XCCDF Value var_global_ssp # promote to variable
  set_fact:
    var_global_ssp: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_global_ssp" use="legacy"/>
  tags:
    - always

- name: Disable the global_ssp SELinux Boolean - Set SELinux Boolean global_ssp Accordingly
  ansible.posix.seboolean:
    name: global_ssp
    state: '{{ var_global_ssp }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_global_ssp
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_global_ssp:var:1" value-id="xccdf_org.ssgproject.content_value_var_global_ssp"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_global_ssp:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_global_ssp_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_gluster_anon_write" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the gluster_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>gluster_anon_write</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>gluster_anon_write</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P gluster_anon_write off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_gluster_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_gluster_anon_write='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_gluster_anon_write" use="legacy"/>'

    /usr/sbin/setsebool -P gluster_anon_write $var_gluster_anon_write

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_gluster_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gluster_anon_write

- name: Disable the gluster_anon_write SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gluster_anon_write
- name: XCCDF Value var_gluster_anon_write # promote to variable
  set_fact:
    var_gluster_anon_write: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_gluster_anon_write" use="legacy"/>
  tags:
    - always

- name: Disable the gluster_anon_write SELinux Boolean - Set SELinux Boolean gluster_anon_write
    Accordingly
  ansible.posix.seboolean:
    name: gluster_anon_write
    state: '{{ var_gluster_anon_write }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gluster_anon_write
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_gluster_anon_write:var:1" value-id="xccdf_org.ssgproject.content_value_var_gluster_anon_write"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_gluster_anon_write:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_gluster_anon_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_gluster_export_all_ro" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the gluster_export_all_ro SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>gluster_export_all_ro</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>gluster_export_all_ro</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P gluster_export_all_ro off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_gluster_export_all_ro" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_gluster_export_all_ro='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_gluster_export_all_ro" use="legacy"/>'

    /usr/sbin/setsebool -P gluster_export_all_ro $var_gluster_export_all_ro

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_gluster_export_all_ro" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gluster_export_all_ro

- name: Disable the gluster_export_all_ro SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gluster_export_all_ro
- name: XCCDF Value var_gluster_export_all_ro # promote to variable
  set_fact:
    var_gluster_export_all_ro: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_gluster_export_all_ro" use="legacy"/>
  tags:
    - always

- name: Disable the gluster_export_all_ro SELinux Boolean - Set SELinux Boolean gluster_export_all_ro
    Accordingly
  ansible.posix.seboolean:
    name: gluster_export_all_ro
    state: '{{ var_gluster_export_all_ro }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gluster_export_all_ro
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_gluster_export_all_ro:var:1" value-id="xccdf_org.ssgproject.content_value_var_gluster_export_all_ro"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_gluster_export_all_ro:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_gluster_export_all_ro_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_gluster_export_all_rw" selected="false" severity="medium">
              <xccdf-1.2:title>Configure the gluster_export_all_rw SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>gluster_export_all_rw</html:code> is enabled.
If <html:code>GlusterFS</html:code> is in use, this setting should be enabled. Otherwise,
disable it.

To disable the <html:code>gluster_export_all_rw</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P gluster_export_all_rw off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_gluster_export_all_rw" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_gluster_export_all_rw='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_gluster_export_all_rw" use="legacy"/>'

    /usr/sbin/setsebool -P gluster_export_all_rw $var_gluster_export_all_rw

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_gluster_export_all_rw" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gluster_export_all_rw

- name: Configure the gluster_export_all_rw SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gluster_export_all_rw
- name: XCCDF Value var_gluster_export_all_rw # promote to variable
  set_fact:
    var_gluster_export_all_rw: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_gluster_export_all_rw" use="legacy"/>
  tags:
    - always

- name: Configure the gluster_export_all_rw SELinux Boolean - Set SELinux Boolean
    gluster_export_all_rw Accordingly
  ansible.posix.seboolean:
    name: gluster_export_all_rw
    state: '{{ var_gluster_export_all_rw }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gluster_export_all_rw
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_gluster_export_all_rw:var:1" value-id="xccdf_org.ssgproject.content_value_var_gluster_export_all_rw"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_gluster_export_all_rw:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_gluster_export_all_rw_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_gpg_web_anon_write" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the gpg_web_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>gpg_web_anon_write</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>gpg_web_anon_write</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P gpg_web_anon_write off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_gpg_web_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_gpg_web_anon_write='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_gpg_web_anon_write" use="legacy"/>'

    /usr/sbin/setsebool -P gpg_web_anon_write $var_gpg_web_anon_write

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_gpg_web_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gpg_web_anon_write

- name: Disable the gpg_web_anon_write SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gpg_web_anon_write
- name: XCCDF Value var_gpg_web_anon_write # promote to variable
  set_fact:
    var_gpg_web_anon_write: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_gpg_web_anon_write" use="legacy"/>
  tags:
    - always

- name: Disable the gpg_web_anon_write SELinux Boolean - Set SELinux Boolean gpg_web_anon_write
    Accordingly
  ansible.posix.seboolean:
    name: gpg_web_anon_write
    state: '{{ var_gpg_web_anon_write }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gpg_web_anon_write
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_gpg_web_anon_write:var:1" value-id="xccdf_org.ssgproject.content_value_var_gpg_web_anon_write"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_gpg_web_anon_write:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_gpg_web_anon_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_gssd_read_tmp" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the gssd_read_tmp SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>gssd_read_tmp</html:code> is enabled.
This setting allows <html:code>gssd</html:code> processes to access Kerberos to read
TGTs in the temp directory. If this setting is disabled, it should
be enabled.

To enable the <html:code>gssd_read_tmp</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P gssd_read_tmp on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_gssd_read_tmp" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_gssd_read_tmp='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_gssd_read_tmp" use="legacy"/>'

    /usr/sbin/setsebool -P gssd_read_tmp $var_gssd_read_tmp

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_gssd_read_tmp" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gssd_read_tmp

- name: Enable the gssd_read_tmp SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gssd_read_tmp
- name: XCCDF Value var_gssd_read_tmp # promote to variable
  set_fact:
    var_gssd_read_tmp: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_gssd_read_tmp" use="legacy"/>
  tags:
    - always

- name: Enable the gssd_read_tmp SELinux Boolean - Set SELinux Boolean gssd_read_tmp
    Accordingly
  ansible.posix.seboolean:
    name: gssd_read_tmp
    state: '{{ var_gssd_read_tmp }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_gssd_read_tmp
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_gssd_read_tmp:var:1" value-id="xccdf_org.ssgproject.content_value_var_gssd_read_tmp"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_gssd_read_tmp:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_gssd_read_tmp_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_guest_exec_content" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the guest_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>guest_exec_content</html:code> is enabled.
This setting should be disabled as no guest accounts should be used.

To disable the <html:code>guest_exec_content</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P guest_exec_content off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_guest_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_guest_exec_content='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_guest_exec_content" use="legacy"/>'

    /usr/sbin/setsebool -P guest_exec_content $var_guest_exec_content

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_guest_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_guest_exec_content

- name: Disable the guest_exec_content SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_guest_exec_content
- name: XCCDF Value var_guest_exec_content # promote to variable
  set_fact:
    var_guest_exec_content: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_guest_exec_content" use="legacy"/>
  tags:
    - always

- name: Disable the guest_exec_content SELinux Boolean - Set SELinux Boolean guest_exec_content
    Accordingly
  ansible.posix.seboolean:
    name: guest_exec_content
    state: '{{ var_guest_exec_content }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_guest_exec_content
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_guest_exec_content:var:1" value-id="xccdf_org.ssgproject.content_value_var_guest_exec_content"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_guest_exec_content:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_guest_exec_content_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_haproxy_connect_any" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the haproxy_connect_any SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>haproxy_connect_any</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>haproxy_connect_any</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P haproxy_connect_any off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_haproxy_connect_any" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_haproxy_connect_any='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_haproxy_connect_any" use="legacy"/>'

    /usr/sbin/setsebool -P haproxy_connect_any $var_haproxy_connect_any

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_haproxy_connect_any" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_haproxy_connect_any

- name: Disable the haproxy_connect_any SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_haproxy_connect_any
- name: XCCDF Value var_haproxy_connect_any # promote to variable
  set_fact:
    var_haproxy_connect_any: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_haproxy_connect_any" use="legacy"/>
  tags:
    - always

- name: Disable the haproxy_connect_any SELinux Boolean - Set SELinux Boolean haproxy_connect_any
    Accordingly
  ansible.posix.seboolean:
    name: haproxy_connect_any
    state: '{{ var_haproxy_connect_any }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_haproxy_connect_any
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_haproxy_connect_any:var:1" value-id="xccdf_org.ssgproject.content_value_var_haproxy_connect_any"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_haproxy_connect_any:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_haproxy_connect_any_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_anon_write" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_anon_write</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_anon_write</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_anon_write off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_anon_write='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_anon_write" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_anon_write $var_httpd_anon_write

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_anon_write

- name: Disable the httpd_anon_write SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_anon_write
- name: XCCDF Value var_httpd_anon_write # promote to variable
  set_fact:
    var_httpd_anon_write: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_anon_write" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_anon_write SELinux Boolean - Set SELinux Boolean httpd_anon_write
    Accordingly
  ansible.posix.seboolean:
    name: httpd_anon_write
    state: '{{ var_httpd_anon_write }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_anon_write
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_anon_write:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_anon_write"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_anon_write:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_anon_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_builtin_scripting" selected="false" severity="medium">
              <xccdf-1.2:title>Configure the httpd_builtin_scripting SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_builtin_scripting</html:code> is enabled.
This setting should be disabled if <html:code>httpd</html:code> is not running <html:code>php</html:code>
or some similarly scripting language.

To disable the <html:code>httpd_builtin_scripting</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_builtin_scripting off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_builtin_scripting" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_builtin_scripting='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_builtin_scripting" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_builtin_scripting $var_httpd_builtin_scripting

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_builtin_scripting" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_builtin_scripting

- name: Configure the httpd_builtin_scripting SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_builtin_scripting
- name: XCCDF Value var_httpd_builtin_scripting # promote to variable
  set_fact:
    var_httpd_builtin_scripting: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_builtin_scripting" use="legacy"/>
  tags:
    - always

- name: Configure the httpd_builtin_scripting SELinux Boolean - Set SELinux Boolean
    httpd_builtin_scripting Accordingly
  ansible.posix.seboolean:
    name: httpd_builtin_scripting
    state: '{{ var_httpd_builtin_scripting }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_builtin_scripting
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_builtin_scripting:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_builtin_scripting"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_builtin_scripting:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_builtin_scripting_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_can_check_spam" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_can_check_spam SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_can_check_spam</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_can_check_spam</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_can_check_spam off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_check_spam" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_can_check_spam='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_check_spam" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_can_check_spam $var_httpd_can_check_spam

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_check_spam" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_check_spam

- name: Disable the httpd_can_check_spam SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_check_spam
- name: XCCDF Value var_httpd_can_check_spam # promote to variable
  set_fact:
    var_httpd_can_check_spam: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_check_spam" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_can_check_spam SELinux Boolean - Set SELinux Boolean httpd_can_check_spam
    Accordingly
  ansible.posix.seboolean:
    name: httpd_can_check_spam
    state: '{{ var_httpd_can_check_spam }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_check_spam
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_can_check_spam:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_can_check_spam"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_can_check_spam:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_can_check_spam_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_can_connect_ftp" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_can_connect_ftp SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_can_connect_ftp</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_can_connect_ftp</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_can_connect_ftp off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_connect_ftp" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_can_connect_ftp='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_connect_ftp" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_can_connect_ftp $var_httpd_can_connect_ftp

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_connect_ftp" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_connect_ftp

- name: Disable the httpd_can_connect_ftp SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_connect_ftp
- name: XCCDF Value var_httpd_can_connect_ftp # promote to variable
  set_fact:
    var_httpd_can_connect_ftp: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_connect_ftp" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_can_connect_ftp SELinux Boolean - Set SELinux Boolean httpd_can_connect_ftp
    Accordingly
  ansible.posix.seboolean:
    name: httpd_can_connect_ftp
    state: '{{ var_httpd_can_connect_ftp }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_connect_ftp
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_can_connect_ftp:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_can_connect_ftp"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_can_connect_ftp:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_can_connect_ftp_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_can_connect_ldap" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_can_connect_ldap SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_can_connect_ldap</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_can_connect_ldap</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_can_connect_ldap off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_connect_ldap" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_can_connect_ldap='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_connect_ldap" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_can_connect_ldap $var_httpd_can_connect_ldap

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_connect_ldap" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_connect_ldap

- name: Disable the httpd_can_connect_ldap SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_connect_ldap
- name: XCCDF Value var_httpd_can_connect_ldap # promote to variable
  set_fact:
    var_httpd_can_connect_ldap: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_connect_ldap" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_can_connect_ldap SELinux Boolean - Set SELinux Boolean httpd_can_connect_ldap
    Accordingly
  ansible.posix.seboolean:
    name: httpd_can_connect_ldap
    state: '{{ var_httpd_can_connect_ldap }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_connect_ldap
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_can_connect_ldap:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_can_connect_ldap"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_can_connect_ldap:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_can_connect_ldap_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_can_connect_mythtv" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_can_connect_mythtv SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_can_connect_mythtv</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_can_connect_mythtv</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_can_connect_mythtv off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_connect_mythtv" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_can_connect_mythtv='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_connect_mythtv" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_can_connect_mythtv $var_httpd_can_connect_mythtv

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_connect_mythtv" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_connect_mythtv

- name: Disable the httpd_can_connect_mythtv SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_connect_mythtv
- name: XCCDF Value var_httpd_can_connect_mythtv # promote to variable
  set_fact:
    var_httpd_can_connect_mythtv: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_connect_mythtv" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_can_connect_mythtv SELinux Boolean - Set SELinux Boolean
    httpd_can_connect_mythtv Accordingly
  ansible.posix.seboolean:
    name: httpd_can_connect_mythtv
    state: '{{ var_httpd_can_connect_mythtv }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_connect_mythtv
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_can_connect_mythtv:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_can_connect_mythtv"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_can_connect_mythtv:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_can_connect_mythtv_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_can_connect_zabbix" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_can_connect_zabbix SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_can_connect_zabbix</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_can_connect_zabbix</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_can_connect_zabbix off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_connect_zabbix" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_can_connect_zabbix='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_connect_zabbix" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_can_connect_zabbix $var_httpd_can_connect_zabbix

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_connect_zabbix" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_connect_zabbix

- name: Disable the httpd_can_connect_zabbix SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_connect_zabbix
- name: XCCDF Value var_httpd_can_connect_zabbix # promote to variable
  set_fact:
    var_httpd_can_connect_zabbix: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_connect_zabbix" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_can_connect_zabbix SELinux Boolean - Set SELinux Boolean
    httpd_can_connect_zabbix Accordingly
  ansible.posix.seboolean:
    name: httpd_can_connect_zabbix
    state: '{{ var_httpd_can_connect_zabbix }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_connect_zabbix
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_can_connect_zabbix:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_can_connect_zabbix"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_can_connect_zabbix:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_can_connect_zabbix_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_can_network_connect" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_can_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_can_network_connect</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_can_network_connect</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_can_network_connect off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_can_network_connect='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_network_connect" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_can_network_connect $var_httpd_can_network_connect

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_network_connect

- name: Disable the httpd_can_network_connect SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_network_connect
- name: XCCDF Value var_httpd_can_network_connect # promote to variable
  set_fact:
    var_httpd_can_network_connect: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_network_connect" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_can_network_connect SELinux Boolean - Set SELinux Boolean
    httpd_can_network_connect Accordingly
  ansible.posix.seboolean:
    name: httpd_can_network_connect
    state: '{{ var_httpd_can_network_connect }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_network_connect
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_can_network_connect:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_can_network_connect"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_can_network_connect:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_can_network_connect_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_can_network_connect_cobbler" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_can_network_connect_cobbler SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_can_network_connect_cobbler</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_can_network_connect_cobbler</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_can_network_connect_cobbler off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_network_connect_cobbler" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_can_network_connect_cobbler='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_network_connect_cobbler" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_can_network_connect_cobbler $var_httpd_can_network_connect_cobbler

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_network_connect_cobbler" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_network_connect_cobbler

- name: Disable the httpd_can_network_connect_cobbler SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_network_connect_cobbler
- name: XCCDF Value var_httpd_can_network_connect_cobbler # promote to variable
  set_fact:
    var_httpd_can_network_connect_cobbler: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_network_connect_cobbler" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_can_network_connect_cobbler SELinux Boolean - Set SELinux
    Boolean httpd_can_network_connect_cobbler Accordingly
  ansible.posix.seboolean:
    name: httpd_can_network_connect_cobbler
    state: '{{ var_httpd_can_network_connect_cobbler }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_network_connect_cobbler
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_can_network_connect_cobbler:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_can_network_connect_cobbler"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_can_network_connect_cobbler:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_can_network_connect_cobbler_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_can_network_connect_db" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_can_network_connect_db SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_can_network_connect_db</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_can_network_connect_db</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_can_network_connect_db off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_network_connect_db" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_can_network_connect_db='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_network_connect_db" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_can_network_connect_db $var_httpd_can_network_connect_db

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_network_connect_db" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_network_connect_db

- name: Disable the httpd_can_network_connect_db SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_network_connect_db
- name: XCCDF Value var_httpd_can_network_connect_db # promote to variable
  set_fact:
    var_httpd_can_network_connect_db: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_network_connect_db" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_can_network_connect_db SELinux Boolean - Set SELinux Boolean
    httpd_can_network_connect_db Accordingly
  ansible.posix.seboolean:
    name: httpd_can_network_connect_db
    state: '{{ var_httpd_can_network_connect_db }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_network_connect_db
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_can_network_connect_db:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_can_network_connect_db"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_can_network_connect_db:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_can_network_connect_db_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_can_network_memcache" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_can_network_memcache SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_can_network_memcache</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_can_network_memcache</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_can_network_memcache off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_network_memcache" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_can_network_memcache='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_network_memcache" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_can_network_memcache $var_httpd_can_network_memcache

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_network_memcache" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_network_memcache

- name: Disable the httpd_can_network_memcache SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_network_memcache
- name: XCCDF Value var_httpd_can_network_memcache # promote to variable
  set_fact:
    var_httpd_can_network_memcache: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_network_memcache" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_can_network_memcache SELinux Boolean - Set SELinux Boolean
    httpd_can_network_memcache Accordingly
  ansible.posix.seboolean:
    name: httpd_can_network_memcache
    state: '{{ var_httpd_can_network_memcache }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_network_memcache
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_can_network_memcache:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_can_network_memcache"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_can_network_memcache:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_can_network_memcache_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_can_network_relay" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_can_network_relay SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_can_network_relay</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_can_network_relay</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_can_network_relay off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_network_relay" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_can_network_relay='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_network_relay" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_can_network_relay $var_httpd_can_network_relay

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_network_relay" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_network_relay

- name: Disable the httpd_can_network_relay SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_network_relay
- name: XCCDF Value var_httpd_can_network_relay # promote to variable
  set_fact:
    var_httpd_can_network_relay: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_network_relay" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_can_network_relay SELinux Boolean - Set SELinux Boolean
    httpd_can_network_relay Accordingly
  ansible.posix.seboolean:
    name: httpd_can_network_relay
    state: '{{ var_httpd_can_network_relay }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_network_relay
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_can_network_relay:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_can_network_relay"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_can_network_relay:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_can_network_relay_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_can_sendmail" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_can_sendmail SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_can_sendmail</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_can_sendmail</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_can_sendmail off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_sendmail" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_can_sendmail='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_sendmail" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_can_sendmail $var_httpd_can_sendmail

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_can_sendmail" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_sendmail

- name: Disable the httpd_can_sendmail SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_sendmail
- name: XCCDF Value var_httpd_can_sendmail # promote to variable
  set_fact:
    var_httpd_can_sendmail: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_can_sendmail" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_can_sendmail SELinux Boolean - Set SELinux Boolean httpd_can_sendmail
    Accordingly
  ansible.posix.seboolean:
    name: httpd_can_sendmail
    state: '{{ var_httpd_can_sendmail }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_can_sendmail
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_can_sendmail:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_can_sendmail"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_can_sendmail:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_can_sendmail_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_dbus_avahi" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_dbus_avahi SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_dbus_avahi</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_dbus_avahi</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_dbus_avahi off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_dbus_avahi" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_dbus_avahi='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_dbus_avahi" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_dbus_avahi $var_httpd_dbus_avahi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_dbus_avahi" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_dbus_avahi

- name: Disable the httpd_dbus_avahi SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_dbus_avahi
- name: XCCDF Value var_httpd_dbus_avahi # promote to variable
  set_fact:
    var_httpd_dbus_avahi: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_dbus_avahi" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_dbus_avahi SELinux Boolean - Set SELinux Boolean httpd_dbus_avahi
    Accordingly
  ansible.posix.seboolean:
    name: httpd_dbus_avahi
    state: '{{ var_httpd_dbus_avahi }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_dbus_avahi
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_dbus_avahi:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_dbus_avahi"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_dbus_avahi:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_dbus_avahi_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_dbus_sssd" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_dbus_sssd SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_dbus_sssd</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_dbus_sssd</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_dbus_sssd off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_dbus_sssd" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_dbus_sssd='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_dbus_sssd" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_dbus_sssd $var_httpd_dbus_sssd

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_dbus_sssd" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_dbus_sssd

- name: Disable the httpd_dbus_sssd SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_dbus_sssd
- name: XCCDF Value var_httpd_dbus_sssd # promote to variable
  set_fact:
    var_httpd_dbus_sssd: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_dbus_sssd" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_dbus_sssd SELinux Boolean - Set SELinux Boolean httpd_dbus_sssd
    Accordingly
  ansible.posix.seboolean:
    name: httpd_dbus_sssd
    state: '{{ var_httpd_dbus_sssd }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_dbus_sssd
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_dbus_sssd:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_dbus_sssd"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_dbus_sssd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_dbus_sssd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_dontaudit_search_dirs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_dontaudit_search_dirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_dontaudit_search_dirs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_dontaudit_search_dirs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_dontaudit_search_dirs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_dontaudit_search_dirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_dontaudit_search_dirs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_dontaudit_search_dirs" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_dontaudit_search_dirs $var_httpd_dontaudit_search_dirs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_dontaudit_search_dirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_dontaudit_search_dirs

- name: Disable the httpd_dontaudit_search_dirs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_dontaudit_search_dirs
- name: XCCDF Value var_httpd_dontaudit_search_dirs # promote to variable
  set_fact:
    var_httpd_dontaudit_search_dirs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_dontaudit_search_dirs" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_dontaudit_search_dirs SELinux Boolean - Set SELinux Boolean
    httpd_dontaudit_search_dirs Accordingly
  ansible.posix.seboolean:
    name: httpd_dontaudit_search_dirs
    state: '{{ var_httpd_dontaudit_search_dirs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_dontaudit_search_dirs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_dontaudit_search_dirs:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_dontaudit_search_dirs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_dontaudit_search_dirs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_dontaudit_search_dirs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_enable_cgi" selected="false" severity="medium">
              <xccdf-1.2:title>Configure the httpd_enable_cgi SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_enable_cgi</html:code> is enabled.
This setting should be disabled unless <html:code>httpd</html:code> is used with <html:code>CGI</html:code>
scripting.

To disable the <html:code>httpd_enable_cgi</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_enable_cgi off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_enable_cgi" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_enable_cgi='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_enable_cgi" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_enable_cgi $var_httpd_enable_cgi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_enable_cgi" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_enable_cgi

- name: Configure the httpd_enable_cgi SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_enable_cgi
- name: XCCDF Value var_httpd_enable_cgi # promote to variable
  set_fact:
    var_httpd_enable_cgi: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_enable_cgi" use="legacy"/>
  tags:
    - always

- name: Configure the httpd_enable_cgi SELinux Boolean - Set SELinux Boolean httpd_enable_cgi
    Accordingly
  ansible.posix.seboolean:
    name: httpd_enable_cgi
    state: '{{ var_httpd_enable_cgi }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_enable_cgi
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_enable_cgi:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_enable_cgi"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_enable_cgi:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_enable_cgi_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_enable_ftp_server" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_enable_ftp_server SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_enable_ftp_server</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_enable_ftp_server</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_enable_ftp_server off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_enable_ftp_server" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_enable_ftp_server='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_enable_ftp_server" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_enable_ftp_server $var_httpd_enable_ftp_server

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_enable_ftp_server" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_enable_ftp_server

- name: Disable the httpd_enable_ftp_server SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_enable_ftp_server
- name: XCCDF Value var_httpd_enable_ftp_server # promote to variable
  set_fact:
    var_httpd_enable_ftp_server: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_enable_ftp_server" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_enable_ftp_server SELinux Boolean - Set SELinux Boolean
    httpd_enable_ftp_server Accordingly
  ansible.posix.seboolean:
    name: httpd_enable_ftp_server
    state: '{{ var_httpd_enable_ftp_server }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_enable_ftp_server
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_enable_ftp_server:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_enable_ftp_server"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_enable_ftp_server:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_enable_ftp_server_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_enable_homedirs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_enable_homedirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_enable_homedirs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_enable_homedirs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_enable_homedirs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_enable_homedirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_enable_homedirs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_enable_homedirs" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_enable_homedirs $var_httpd_enable_homedirs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_enable_homedirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_enable_homedirs

- name: Disable the httpd_enable_homedirs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_enable_homedirs
- name: XCCDF Value var_httpd_enable_homedirs # promote to variable
  set_fact:
    var_httpd_enable_homedirs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_enable_homedirs" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_enable_homedirs SELinux Boolean - Set SELinux Boolean httpd_enable_homedirs
    Accordingly
  ansible.posix.seboolean:
    name: httpd_enable_homedirs
    state: '{{ var_httpd_enable_homedirs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_enable_homedirs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_enable_homedirs:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_enable_homedirs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_enable_homedirs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_enable_homedirs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_execmem" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_execmem SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_execmem</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_execmem</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_execmem off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_execmem" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_execmem='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_execmem" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_execmem $var_httpd_execmem

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_execmem" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_execmem

- name: Disable the httpd_execmem SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_execmem
- name: XCCDF Value var_httpd_execmem # promote to variable
  set_fact:
    var_httpd_execmem: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_execmem" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_execmem SELinux Boolean - Set SELinux Boolean httpd_execmem
    Accordingly
  ansible.posix.seboolean:
    name: httpd_execmem
    state: '{{ var_httpd_execmem }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_execmem
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_execmem:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_execmem"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_execmem:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_execmem_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_graceful_shutdown" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the httpd_graceful_shutdown SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_graceful_shutdown</html:code> is enabled.
If this setting is disabled, it should be enabled.

To enable the <html:code>httpd_graceful_shutdown</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_graceful_shutdown on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_graceful_shutdown" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_graceful_shutdown='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_graceful_shutdown" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_graceful_shutdown $var_httpd_graceful_shutdown

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_graceful_shutdown" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_graceful_shutdown

- name: Enable the httpd_graceful_shutdown SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_graceful_shutdown
- name: XCCDF Value var_httpd_graceful_shutdown # promote to variable
  set_fact:
    var_httpd_graceful_shutdown: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_graceful_shutdown" use="legacy"/>
  tags:
    - always

- name: Enable the httpd_graceful_shutdown SELinux Boolean - Set SELinux Boolean httpd_graceful_shutdown
    Accordingly
  ansible.posix.seboolean:
    name: httpd_graceful_shutdown
    state: '{{ var_httpd_graceful_shutdown }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_graceful_shutdown
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_graceful_shutdown:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_graceful_shutdown"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_graceful_shutdown:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_graceful_shutdown_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_manage_ipa" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_manage_ipa SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_manage_ipa</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_manage_ipa</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_manage_ipa off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_manage_ipa" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_manage_ipa='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_manage_ipa" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_manage_ipa $var_httpd_manage_ipa

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_manage_ipa" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_manage_ipa

- name: Disable the httpd_manage_ipa SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_manage_ipa
- name: XCCDF Value var_httpd_manage_ipa # promote to variable
  set_fact:
    var_httpd_manage_ipa: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_manage_ipa" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_manage_ipa SELinux Boolean - Set SELinux Boolean httpd_manage_ipa
    Accordingly
  ansible.posix.seboolean:
    name: httpd_manage_ipa
    state: '{{ var_httpd_manage_ipa }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_manage_ipa
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_manage_ipa:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_manage_ipa"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_manage_ipa:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_manage_ipa_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_mod_auth_ntlm_winbind" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_mod_auth_ntlm_winbind SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_mod_auth_ntlm_winbind</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_mod_auth_ntlm_winbind</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_mod_auth_ntlm_winbind off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_mod_auth_ntlm_winbind" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_mod_auth_ntlm_winbind='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_mod_auth_ntlm_winbind" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_mod_auth_ntlm_winbind $var_httpd_mod_auth_ntlm_winbind

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_mod_auth_ntlm_winbind" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_mod_auth_ntlm_winbind

- name: Disable the httpd_mod_auth_ntlm_winbind SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_mod_auth_ntlm_winbind
- name: XCCDF Value var_httpd_mod_auth_ntlm_winbind # promote to variable
  set_fact:
    var_httpd_mod_auth_ntlm_winbind: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_mod_auth_ntlm_winbind" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_mod_auth_ntlm_winbind SELinux Boolean - Set SELinux Boolean
    httpd_mod_auth_ntlm_winbind Accordingly
  ansible.posix.seboolean:
    name: httpd_mod_auth_ntlm_winbind
    state: '{{ var_httpd_mod_auth_ntlm_winbind }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_mod_auth_ntlm_winbind
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_mod_auth_ntlm_winbind:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_mod_auth_ntlm_winbind"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_mod_auth_ntlm_winbind:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_mod_auth_ntlm_winbind_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_mod_auth_pam" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_mod_auth_pam SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_mod_auth_pam</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_mod_auth_pam</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_mod_auth_pam off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_mod_auth_pam" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_mod_auth_pam='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_mod_auth_pam" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_mod_auth_pam $var_httpd_mod_auth_pam

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_mod_auth_pam" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_mod_auth_pam

- name: Disable the httpd_mod_auth_pam SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_mod_auth_pam
- name: XCCDF Value var_httpd_mod_auth_pam # promote to variable
  set_fact:
    var_httpd_mod_auth_pam: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_mod_auth_pam" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_mod_auth_pam SELinux Boolean - Set SELinux Boolean httpd_mod_auth_pam
    Accordingly
  ansible.posix.seboolean:
    name: httpd_mod_auth_pam
    state: '{{ var_httpd_mod_auth_pam }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_mod_auth_pam
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_mod_auth_pam:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_mod_auth_pam"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_mod_auth_pam:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_mod_auth_pam_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_read_user_content" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_read_user_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_read_user_content</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_read_user_content</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_read_user_content off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_read_user_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_read_user_content='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_read_user_content" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_read_user_content $var_httpd_read_user_content

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_read_user_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_read_user_content

- name: Disable the httpd_read_user_content SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_read_user_content
- name: XCCDF Value var_httpd_read_user_content # promote to variable
  set_fact:
    var_httpd_read_user_content: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_read_user_content" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_read_user_content SELinux Boolean - Set SELinux Boolean
    httpd_read_user_content Accordingly
  ansible.posix.seboolean:
    name: httpd_read_user_content
    state: '{{ var_httpd_read_user_content }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_read_user_content
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_read_user_content:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_read_user_content"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_read_user_content:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_read_user_content_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_run_ipa" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_run_ipa SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_run_ipa</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_run_ipa</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_run_ipa off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_run_ipa" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_run_ipa='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_run_ipa" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_run_ipa $var_httpd_run_ipa

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_run_ipa" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_run_ipa

- name: Disable the httpd_run_ipa SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_run_ipa
- name: XCCDF Value var_httpd_run_ipa # promote to variable
  set_fact:
    var_httpd_run_ipa: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_run_ipa" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_run_ipa SELinux Boolean - Set SELinux Boolean httpd_run_ipa
    Accordingly
  ansible.posix.seboolean:
    name: httpd_run_ipa
    state: '{{ var_httpd_run_ipa }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_run_ipa
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_run_ipa:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_run_ipa"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_run_ipa:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_run_ipa_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_run_preupgrade" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_run_preupgrade SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_run_preupgrade</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_run_preupgrade</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_run_preupgrade off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_run_preupgrade" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_run_preupgrade='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_run_preupgrade" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_run_preupgrade $var_httpd_run_preupgrade

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_run_preupgrade" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_run_preupgrade

- name: Disable the httpd_run_preupgrade SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_run_preupgrade
- name: XCCDF Value var_httpd_run_preupgrade # promote to variable
  set_fact:
    var_httpd_run_preupgrade: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_run_preupgrade" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_run_preupgrade SELinux Boolean - Set SELinux Boolean httpd_run_preupgrade
    Accordingly
  ansible.posix.seboolean:
    name: httpd_run_preupgrade
    state: '{{ var_httpd_run_preupgrade }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_run_preupgrade
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_run_preupgrade:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_run_preupgrade"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_run_preupgrade:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_run_preupgrade_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_run_stickshift" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_run_stickshift SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_run_stickshift</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_run_stickshift</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_run_stickshift off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_run_stickshift" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_run_stickshift='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_run_stickshift" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_run_stickshift $var_httpd_run_stickshift

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_run_stickshift" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_run_stickshift

- name: Disable the httpd_run_stickshift SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_run_stickshift
- name: XCCDF Value var_httpd_run_stickshift # promote to variable
  set_fact:
    var_httpd_run_stickshift: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_run_stickshift" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_run_stickshift SELinux Boolean - Set SELinux Boolean httpd_run_stickshift
    Accordingly
  ansible.posix.seboolean:
    name: httpd_run_stickshift
    state: '{{ var_httpd_run_stickshift }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_run_stickshift
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_run_stickshift:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_run_stickshift"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_run_stickshift:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_run_stickshift_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_serve_cobbler_files" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_serve_cobbler_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_serve_cobbler_files</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_serve_cobbler_files</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_serve_cobbler_files off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_serve_cobbler_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_serve_cobbler_files='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_serve_cobbler_files" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_serve_cobbler_files $var_httpd_serve_cobbler_files

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_serve_cobbler_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_serve_cobbler_files

- name: Disable the httpd_serve_cobbler_files SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_serve_cobbler_files
- name: XCCDF Value var_httpd_serve_cobbler_files # promote to variable
  set_fact:
    var_httpd_serve_cobbler_files: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_serve_cobbler_files" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_serve_cobbler_files SELinux Boolean - Set SELinux Boolean
    httpd_serve_cobbler_files Accordingly
  ansible.posix.seboolean:
    name: httpd_serve_cobbler_files
    state: '{{ var_httpd_serve_cobbler_files }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_serve_cobbler_files
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_serve_cobbler_files:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_serve_cobbler_files"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_serve_cobbler_files:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_serve_cobbler_files_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_setrlimit" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_setrlimit SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_setrlimit</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_setrlimit</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_setrlimit off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_setrlimit" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_setrlimit='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_setrlimit" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_setrlimit $var_httpd_setrlimit

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_setrlimit" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_setrlimit

- name: Disable the httpd_setrlimit SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_setrlimit
- name: XCCDF Value var_httpd_setrlimit # promote to variable
  set_fact:
    var_httpd_setrlimit: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_setrlimit" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_setrlimit SELinux Boolean - Set SELinux Boolean httpd_setrlimit
    Accordingly
  ansible.posix.seboolean:
    name: httpd_setrlimit
    state: '{{ var_httpd_setrlimit }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_setrlimit
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_setrlimit:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_setrlimit"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_setrlimit:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_setrlimit_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_ssi_exec" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_ssi_exec SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_ssi_exec</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_ssi_exec</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_ssi_exec off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_ssi_exec" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_ssi_exec='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_ssi_exec" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_ssi_exec $var_httpd_ssi_exec

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_ssi_exec" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_ssi_exec

- name: Disable the httpd_ssi_exec SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_ssi_exec
- name: XCCDF Value var_httpd_ssi_exec # promote to variable
  set_fact:
    var_httpd_ssi_exec: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_ssi_exec" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_ssi_exec SELinux Boolean - Set SELinux Boolean httpd_ssi_exec
    Accordingly
  ansible.posix.seboolean:
    name: httpd_ssi_exec
    state: '{{ var_httpd_ssi_exec }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_ssi_exec
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_ssi_exec:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_ssi_exec"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_ssi_exec:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_ssi_exec_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_sys_script_anon_write" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_sys_script_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_sys_script_anon_write</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_sys_script_anon_write</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_sys_script_anon_write off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_sys_script_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_sys_script_anon_write='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_sys_script_anon_write" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_sys_script_anon_write $var_httpd_sys_script_anon_write

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_sys_script_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_sys_script_anon_write

- name: Disable the httpd_sys_script_anon_write SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_sys_script_anon_write
- name: XCCDF Value var_httpd_sys_script_anon_write # promote to variable
  set_fact:
    var_httpd_sys_script_anon_write: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_sys_script_anon_write" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_sys_script_anon_write SELinux Boolean - Set SELinux Boolean
    httpd_sys_script_anon_write Accordingly
  ansible.posix.seboolean:
    name: httpd_sys_script_anon_write
    state: '{{ var_httpd_sys_script_anon_write }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_sys_script_anon_write
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_sys_script_anon_write:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_sys_script_anon_write"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_sys_script_anon_write:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_sys_script_anon_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_tmp_exec" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_tmp_exec SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_tmp_exec</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_tmp_exec</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_tmp_exec off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_tmp_exec" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_tmp_exec='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_tmp_exec" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_tmp_exec $var_httpd_tmp_exec

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_tmp_exec" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_tmp_exec

- name: Disable the httpd_tmp_exec SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_tmp_exec
- name: XCCDF Value var_httpd_tmp_exec # promote to variable
  set_fact:
    var_httpd_tmp_exec: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_tmp_exec" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_tmp_exec SELinux Boolean - Set SELinux Boolean httpd_tmp_exec
    Accordingly
  ansible.posix.seboolean:
    name: httpd_tmp_exec
    state: '{{ var_httpd_tmp_exec }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_tmp_exec
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_tmp_exec:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_tmp_exec"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_tmp_exec:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_tmp_exec_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_tty_comm" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_tty_comm SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_tty_comm</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_tty_comm</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_tty_comm off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_tty_comm" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_tty_comm='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_tty_comm" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_tty_comm $var_httpd_tty_comm

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_tty_comm" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_tty_comm

- name: Disable the httpd_tty_comm SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_tty_comm
- name: XCCDF Value var_httpd_tty_comm # promote to variable
  set_fact:
    var_httpd_tty_comm: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_tty_comm" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_tty_comm SELinux Boolean - Set SELinux Boolean httpd_tty_comm
    Accordingly
  ansible.posix.seboolean:
    name: httpd_tty_comm
    state: '{{ var_httpd_tty_comm }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_tty_comm
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_tty_comm:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_tty_comm"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_tty_comm:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_tty_comm_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_unified" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_unified SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_unified</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_unified</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_unified off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_unified" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_unified='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_unified" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_unified $var_httpd_unified

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_unified" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_unified

- name: Disable the httpd_unified SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_unified
- name: XCCDF Value var_httpd_unified # promote to variable
  set_fact:
    var_httpd_unified: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_unified" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_unified SELinux Boolean - Set SELinux Boolean httpd_unified
    Accordingly
  ansible.posix.seboolean:
    name: httpd_unified
    state: '{{ var_httpd_unified }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_unified
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_unified:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_unified"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_unified:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_unified_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_use_cifs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_use_cifs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_use_cifs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_use_cifs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_use_cifs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_use_cifs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_use_cifs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_use_cifs" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_use_cifs $var_httpd_use_cifs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_use_cifs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_cifs

- name: Disable the httpd_use_cifs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_cifs
- name: XCCDF Value var_httpd_use_cifs # promote to variable
  set_fact:
    var_httpd_use_cifs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_use_cifs" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_use_cifs SELinux Boolean - Set SELinux Boolean httpd_use_cifs
    Accordingly
  ansible.posix.seboolean:
    name: httpd_use_cifs
    state: '{{ var_httpd_use_cifs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_cifs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_use_cifs:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_use_cifs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_use_cifs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_use_cifs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_use_fusefs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_use_fusefs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_use_fusefs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_use_fusefs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_use_fusefs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_use_fusefs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_use_fusefs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_use_fusefs" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_use_fusefs $var_httpd_use_fusefs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_use_fusefs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_fusefs

- name: Disable the httpd_use_fusefs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_fusefs
- name: XCCDF Value var_httpd_use_fusefs # promote to variable
  set_fact:
    var_httpd_use_fusefs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_use_fusefs" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_use_fusefs SELinux Boolean - Set SELinux Boolean httpd_use_fusefs
    Accordingly
  ansible.posix.seboolean:
    name: httpd_use_fusefs
    state: '{{ var_httpd_use_fusefs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_fusefs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_use_fusefs:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_use_fusefs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_use_fusefs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_use_fusefs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_use_gpg" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_use_gpg SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_use_gpg</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_use_gpg</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_use_gpg off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_use_gpg" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_use_gpg='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_use_gpg" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_use_gpg $var_httpd_use_gpg

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_use_gpg" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_gpg

- name: Disable the httpd_use_gpg SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_gpg
- name: XCCDF Value var_httpd_use_gpg # promote to variable
  set_fact:
    var_httpd_use_gpg: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_use_gpg" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_use_gpg SELinux Boolean - Set SELinux Boolean httpd_use_gpg
    Accordingly
  ansible.posix.seboolean:
    name: httpd_use_gpg
    state: '{{ var_httpd_use_gpg }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_gpg
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_use_gpg:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_use_gpg"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_use_gpg:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_use_gpg_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_use_nfs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_use_nfs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_use_nfs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_use_nfs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_use_nfs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_use_nfs" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_use_nfs $var_httpd_use_nfs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_nfs

- name: Disable the httpd_use_nfs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_nfs
- name: XCCDF Value var_httpd_use_nfs # promote to variable
  set_fact:
    var_httpd_use_nfs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_use_nfs" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_use_nfs SELinux Boolean - Set SELinux Boolean httpd_use_nfs
    Accordingly
  ansible.posix.seboolean:
    name: httpd_use_nfs
    state: '{{ var_httpd_use_nfs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_nfs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_use_nfs:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_use_nfs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_use_nfs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_use_nfs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_use_openstack" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_use_openstack SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_use_openstack</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_use_openstack</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_use_openstack off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_use_openstack" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_use_openstack='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_use_openstack" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_use_openstack $var_httpd_use_openstack

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_use_openstack" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_openstack

- name: Disable the httpd_use_openstack SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_openstack
- name: XCCDF Value var_httpd_use_openstack # promote to variable
  set_fact:
    var_httpd_use_openstack: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_use_openstack" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_use_openstack SELinux Boolean - Set SELinux Boolean httpd_use_openstack
    Accordingly
  ansible.posix.seboolean:
    name: httpd_use_openstack
    state: '{{ var_httpd_use_openstack }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_openstack
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_use_openstack:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_use_openstack"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_use_openstack:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_use_openstack_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_use_sasl" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_use_sasl SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_use_sasl</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_use_sasl</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_use_sasl off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_use_sasl" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_use_sasl='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_use_sasl" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_use_sasl $var_httpd_use_sasl

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_use_sasl" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_sasl

- name: Disable the httpd_use_sasl SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_sasl
- name: XCCDF Value var_httpd_use_sasl # promote to variable
  set_fact:
    var_httpd_use_sasl: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_use_sasl" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_use_sasl SELinux Boolean - Set SELinux Boolean httpd_use_sasl
    Accordingly
  ansible.posix.seboolean:
    name: httpd_use_sasl
    state: '{{ var_httpd_use_sasl }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_use_sasl
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_use_sasl:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_use_sasl"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_use_sasl:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_use_sasl_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_httpd_verify_dns" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the httpd_verify_dns SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>httpd_verify_dns</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>httpd_verify_dns</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P httpd_verify_dns off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_verify_dns" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_httpd_verify_dns='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_verify_dns" use="legacy"/>'

    /usr/sbin/setsebool -P httpd_verify_dns $var_httpd_verify_dns

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_httpd_verify_dns" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_verify_dns

- name: Disable the httpd_verify_dns SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_verify_dns
- name: XCCDF Value var_httpd_verify_dns # promote to variable
  set_fact:
    var_httpd_verify_dns: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_verify_dns" use="legacy"/>
  tags:
    - always

- name: Disable the httpd_verify_dns SELinux Boolean - Set SELinux Boolean httpd_verify_dns
    Accordingly
  ansible.posix.seboolean:
    name: httpd_verify_dns
    state: '{{ var_httpd_verify_dns }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_httpd_verify_dns
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_httpd_verify_dns:var:1" value-id="xccdf_org.ssgproject.content_value_var_httpd_verify_dns"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_httpd_verify_dns:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_httpd_verify_dns_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_icecast_use_any_tcp_ports" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the icecast_use_any_tcp_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>icecast_use_any_tcp_ports</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>icecast_use_any_tcp_ports</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P icecast_use_any_tcp_ports off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_icecast_use_any_tcp_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_icecast_use_any_tcp_ports='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_icecast_use_any_tcp_ports" use="legacy"/>'

    /usr/sbin/setsebool -P icecast_use_any_tcp_ports $var_icecast_use_any_tcp_ports

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_icecast_use_any_tcp_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_icecast_use_any_tcp_ports

- name: Disable the icecast_use_any_tcp_ports SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_icecast_use_any_tcp_ports
- name: XCCDF Value var_icecast_use_any_tcp_ports # promote to variable
  set_fact:
    var_icecast_use_any_tcp_ports: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_icecast_use_any_tcp_ports" use="legacy"/>
  tags:
    - always

- name: Disable the icecast_use_any_tcp_ports SELinux Boolean - Set SELinux Boolean
    icecast_use_any_tcp_ports Accordingly
  ansible.posix.seboolean:
    name: icecast_use_any_tcp_ports
    state: '{{ var_icecast_use_any_tcp_ports }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_icecast_use_any_tcp_ports
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_icecast_use_any_tcp_ports:var:1" value-id="xccdf_org.ssgproject.content_value_var_icecast_use_any_tcp_ports"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_icecast_use_any_tcp_ports:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_icecast_use_any_tcp_ports_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_irc_use_any_tcp_ports" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the irc_use_any_tcp_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>irc_use_any_tcp_ports</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>irc_use_any_tcp_ports</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P irc_use_any_tcp_ports off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_irc_use_any_tcp_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_irc_use_any_tcp_ports='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_irc_use_any_tcp_ports" use="legacy"/>'

    /usr/sbin/setsebool -P irc_use_any_tcp_ports $var_irc_use_any_tcp_ports

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_irc_use_any_tcp_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_irc_use_any_tcp_ports

- name: Disable the irc_use_any_tcp_ports SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_irc_use_any_tcp_ports
- name: XCCDF Value var_irc_use_any_tcp_ports # promote to variable
  set_fact:
    var_irc_use_any_tcp_ports: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_irc_use_any_tcp_ports" use="legacy"/>
  tags:
    - always

- name: Disable the irc_use_any_tcp_ports SELinux Boolean - Set SELinux Boolean irc_use_any_tcp_ports
    Accordingly
  ansible.posix.seboolean:
    name: irc_use_any_tcp_ports
    state: '{{ var_irc_use_any_tcp_ports }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_irc_use_any_tcp_ports
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_irc_use_any_tcp_ports:var:1" value-id="xccdf_org.ssgproject.content_value_var_irc_use_any_tcp_ports"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_irc_use_any_tcp_ports:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_irc_use_any_tcp_ports_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_irssi_use_full_network" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the irssi_use_full_network SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>irssi_use_full_network</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>irssi_use_full_network</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P irssi_use_full_network off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_irssi_use_full_network" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_irssi_use_full_network='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_irssi_use_full_network" use="legacy"/>'

    /usr/sbin/setsebool -P irssi_use_full_network $var_irssi_use_full_network

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_irssi_use_full_network" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_irssi_use_full_network

- name: Disable the irssi_use_full_network SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_irssi_use_full_network
- name: XCCDF Value var_irssi_use_full_network # promote to variable
  set_fact:
    var_irssi_use_full_network: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_irssi_use_full_network" use="legacy"/>
  tags:
    - always

- name: Disable the irssi_use_full_network SELinux Boolean - Set SELinux Boolean irssi_use_full_network
    Accordingly
  ansible.posix.seboolean:
    name: irssi_use_full_network
    state: '{{ var_irssi_use_full_network }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_irssi_use_full_network
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_irssi_use_full_network:var:1" value-id="xccdf_org.ssgproject.content_value_var_irssi_use_full_network"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_irssi_use_full_network:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_irssi_use_full_network_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_kdumpgui_run_bootloader" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the kdumpgui_run_bootloader SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>kdumpgui_run_bootloader</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>kdumpgui_run_bootloader</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P kdumpgui_run_bootloader off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_kdumpgui_run_bootloader" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_kdumpgui_run_bootloader='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_kdumpgui_run_bootloader" use="legacy"/>'

    /usr/sbin/setsebool -P kdumpgui_run_bootloader $var_kdumpgui_run_bootloader

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_kdumpgui_run_bootloader" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_kdumpgui_run_bootloader

- name: Disable the kdumpgui_run_bootloader SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_kdumpgui_run_bootloader
- name: XCCDF Value var_kdumpgui_run_bootloader # promote to variable
  set_fact:
    var_kdumpgui_run_bootloader: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_kdumpgui_run_bootloader" use="legacy"/>
  tags:
    - always

- name: Disable the kdumpgui_run_bootloader SELinux Boolean - Set SELinux Boolean
    kdumpgui_run_bootloader Accordingly
  ansible.posix.seboolean:
    name: kdumpgui_run_bootloader
    state: '{{ var_kdumpgui_run_bootloader }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_kdumpgui_run_bootloader
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_kdumpgui_run_bootloader:var:1" value-id="xccdf_org.ssgproject.content_value_var_kdumpgui_run_bootloader"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_kdumpgui_run_bootloader:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_kdumpgui_run_bootloader_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_kerberos_enabled" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the kerberos_enabled SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>kerberos_enabled</html:code> is enabled.
If this setting is disabled, it should be enabled to allow confined
applications to run with Kerberos.

To enable the <html:code>kerberos_enabled</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P kerberos_enabled on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0418</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1055</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1402</xccdf-1.2:reference>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_kerberos_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_kerberos_enabled='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_kerberos_enabled" use="legacy"/>'

    /usr/sbin/setsebool -P kerberos_enabled $var_kerberos_enabled

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_kerberos_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_kerberos_enabled

- name: Enable the kerberos_enabled SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_kerberos_enabled
- name: XCCDF Value var_kerberos_enabled # promote to variable
  set_fact:
    var_kerberos_enabled: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_kerberos_enabled" use="legacy"/>
  tags:
    - always

- name: Enable the kerberos_enabled SELinux Boolean - Set SELinux Boolean kerberos_enabled
    Accordingly
  ansible.posix.seboolean:
    name: kerberos_enabled
    state: '{{ var_kerberos_enabled }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_kerberos_enabled
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_kerberos_enabled:var:1" value-id="xccdf_org.ssgproject.content_value_var_kerberos_enabled"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_kerberos_enabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_kerberos_enabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_ksmtuned_use_cifs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the ksmtuned_use_cifs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>ksmtuned_use_cifs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>ksmtuned_use_cifs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P ksmtuned_use_cifs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ksmtuned_use_cifs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_ksmtuned_use_cifs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ksmtuned_use_cifs" use="legacy"/>'

    /usr/sbin/setsebool -P ksmtuned_use_cifs $var_ksmtuned_use_cifs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ksmtuned_use_cifs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ksmtuned_use_cifs

- name: Disable the ksmtuned_use_cifs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ksmtuned_use_cifs
- name: XCCDF Value var_ksmtuned_use_cifs # promote to variable
  set_fact:
    var_ksmtuned_use_cifs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ksmtuned_use_cifs" use="legacy"/>
  tags:
    - always

- name: Disable the ksmtuned_use_cifs SELinux Boolean - Set SELinux Boolean ksmtuned_use_cifs
    Accordingly
  ansible.posix.seboolean:
    name: ksmtuned_use_cifs
    state: '{{ var_ksmtuned_use_cifs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ksmtuned_use_cifs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_ksmtuned_use_cifs:var:1" value-id="xccdf_org.ssgproject.content_value_var_ksmtuned_use_cifs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_ksmtuned_use_cifs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_ksmtuned_use_cifs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_ksmtuned_use_nfs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the ksmtuned_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>ksmtuned_use_nfs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>ksmtuned_use_nfs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P ksmtuned_use_nfs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ksmtuned_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_ksmtuned_use_nfs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ksmtuned_use_nfs" use="legacy"/>'

    /usr/sbin/setsebool -P ksmtuned_use_nfs $var_ksmtuned_use_nfs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ksmtuned_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ksmtuned_use_nfs

- name: Disable the ksmtuned_use_nfs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ksmtuned_use_nfs
- name: XCCDF Value var_ksmtuned_use_nfs # promote to variable
  set_fact:
    var_ksmtuned_use_nfs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ksmtuned_use_nfs" use="legacy"/>
  tags:
    - always

- name: Disable the ksmtuned_use_nfs SELinux Boolean - Set SELinux Boolean ksmtuned_use_nfs
    Accordingly
  ansible.posix.seboolean:
    name: ksmtuned_use_nfs
    state: '{{ var_ksmtuned_use_nfs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ksmtuned_use_nfs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_ksmtuned_use_nfs:var:1" value-id="xccdf_org.ssgproject.content_value_var_ksmtuned_use_nfs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_ksmtuned_use_nfs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_ksmtuned_use_nfs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_logadm_exec_content" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the logadm_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>logadm_exec_content</html:code> is enabled.
If this setting is disabled, it should be enabled.

To enable the <html:code>logadm_exec_content</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P logadm_exec_content on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_logadm_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_logadm_exec_content='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_logadm_exec_content" use="legacy"/>'

    /usr/sbin/setsebool -P logadm_exec_content $var_logadm_exec_content

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_logadm_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logadm_exec_content

- name: Enable the logadm_exec_content SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logadm_exec_content
- name: XCCDF Value var_logadm_exec_content # promote to variable
  set_fact:
    var_logadm_exec_content: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_logadm_exec_content" use="legacy"/>
  tags:
    - always

- name: Enable the logadm_exec_content SELinux Boolean - Set SELinux Boolean logadm_exec_content
    Accordingly
  ansible.posix.seboolean:
    name: logadm_exec_content
    state: '{{ var_logadm_exec_content }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logadm_exec_content
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_logadm_exec_content:var:1" value-id="xccdf_org.ssgproject.content_value_var_logadm_exec_content"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_logadm_exec_content:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_logadm_exec_content_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_logging_syslogd_can_sendmail" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the logging_syslogd_can_sendmail SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>logging_syslogd_can_sendmail</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>logging_syslogd_can_sendmail</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P logging_syslogd_can_sendmail off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_logging_syslogd_can_sendmail" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_logging_syslogd_can_sendmail='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_logging_syslogd_can_sendmail" use="legacy"/>'

    /usr/sbin/setsebool -P logging_syslogd_can_sendmail $var_logging_syslogd_can_sendmail

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_logging_syslogd_can_sendmail" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logging_syslogd_can_sendmail

- name: Disable the logging_syslogd_can_sendmail SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logging_syslogd_can_sendmail
- name: XCCDF Value var_logging_syslogd_can_sendmail # promote to variable
  set_fact:
    var_logging_syslogd_can_sendmail: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_logging_syslogd_can_sendmail" use="legacy"/>
  tags:
    - always

- name: Disable the logging_syslogd_can_sendmail SELinux Boolean - Set SELinux Boolean
    logging_syslogd_can_sendmail Accordingly
  ansible.posix.seboolean:
    name: logging_syslogd_can_sendmail
    state: '{{ var_logging_syslogd_can_sendmail }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logging_syslogd_can_sendmail
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_logging_syslogd_can_sendmail:var:1" value-id="xccdf_org.ssgproject.content_value_var_logging_syslogd_can_sendmail"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_logging_syslogd_can_sendmail:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_logging_syslogd_can_sendmail_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_logging_syslogd_run_nagios_plugins" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the logging_syslogd_run_nagios_plugins SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>logging_syslogd_run_nagios_plugins</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>logging_syslogd_run_nagios_plugins</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P logging_syslogd_run_nagios_plugins off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_logging_syslogd_run_nagios_plugins" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_logging_syslogd_run_nagios_plugins='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_logging_syslogd_run_nagios_plugins" use="legacy"/>'

    /usr/sbin/setsebool -P logging_syslogd_run_nagios_plugins $var_logging_syslogd_run_nagios_plugins

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_logging_syslogd_run_nagios_plugins" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logging_syslogd_run_nagios_plugins

- name: Disable the logging_syslogd_run_nagios_plugins SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logging_syslogd_run_nagios_plugins
- name: XCCDF Value var_logging_syslogd_run_nagios_plugins # promote to variable
  set_fact:
    var_logging_syslogd_run_nagios_plugins: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_logging_syslogd_run_nagios_plugins" use="legacy"/>
  tags:
    - always

- name: Disable the logging_syslogd_run_nagios_plugins SELinux Boolean - Set SELinux
    Boolean logging_syslogd_run_nagios_plugins Accordingly
  ansible.posix.seboolean:
    name: logging_syslogd_run_nagios_plugins
    state: '{{ var_logging_syslogd_run_nagios_plugins }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logging_syslogd_run_nagios_plugins
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_logging_syslogd_run_nagios_plugins:var:1" value-id="xccdf_org.ssgproject.content_value_var_logging_syslogd_run_nagios_plugins"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_logging_syslogd_run_nagios_plugins:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_logging_syslogd_run_nagios_plugins_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_logging_syslogd_use_tty" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the logging_syslogd_use_tty SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>logging_syslogd_use_tty</html:code> is enabled.
If this setting is disabled, it should be enabled as it allows <html:code>syslog</html:code>
the ability to read/write to terminal.

To enable the <html:code>logging_syslogd_use_tty</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P logging_syslogd_use_tty on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_logging_syslogd_use_tty" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_logging_syslogd_use_tty='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_logging_syslogd_use_tty" use="legacy"/>'

    /usr/sbin/setsebool -P logging_syslogd_use_tty $var_logging_syslogd_use_tty

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_logging_syslogd_use_tty" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logging_syslogd_use_tty

- name: Enable the logging_syslogd_use_tty SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logging_syslogd_use_tty
- name: XCCDF Value var_logging_syslogd_use_tty # promote to variable
  set_fact:
    var_logging_syslogd_use_tty: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_logging_syslogd_use_tty" use="legacy"/>
  tags:
    - always

- name: Enable the logging_syslogd_use_tty SELinux Boolean - Set SELinux Boolean logging_syslogd_use_tty
    Accordingly
  ansible.posix.seboolean:
    name: logging_syslogd_use_tty
    state: '{{ var_logging_syslogd_use_tty }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logging_syslogd_use_tty
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_logging_syslogd_use_tty:var:1" value-id="xccdf_org.ssgproject.content_value_var_logging_syslogd_use_tty"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_logging_syslogd_use_tty:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_logging_syslogd_use_tty_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_login_console_enabled" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the login_console_enabled SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>login_console_enabled</html:code> is enabled.
If this setting is disabled, it should be enabled as it allows login from
<html:code>/dev/console</html:code> to a console session.

To enable the <html:code>login_console_enabled</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P login_console_enabled on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_login_console_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_login_console_enabled='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_login_console_enabled" use="legacy"/>'

    /usr/sbin/setsebool -P login_console_enabled $var_login_console_enabled

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_login_console_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_login_console_enabled

- name: Enable the login_console_enabled SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_login_console_enabled
- name: XCCDF Value var_login_console_enabled # promote to variable
  set_fact:
    var_login_console_enabled: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_login_console_enabled" use="legacy"/>
  tags:
    - always

- name: Enable the login_console_enabled SELinux Boolean - Set SELinux Boolean login_console_enabled
    Accordingly
  ansible.posix.seboolean:
    name: login_console_enabled
    state: '{{ var_login_console_enabled }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_login_console_enabled
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_login_console_enabled:var:1" value-id="xccdf_org.ssgproject.content_value_var_login_console_enabled"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_login_console_enabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_login_console_enabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_logrotate_use_nfs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the logrotate_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>logrotate_use_nfs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>logrotate_use_nfs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P logrotate_use_nfs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_logrotate_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_logrotate_use_nfs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_logrotate_use_nfs" use="legacy"/>'

    /usr/sbin/setsebool -P logrotate_use_nfs $var_logrotate_use_nfs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_logrotate_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logrotate_use_nfs

- name: Disable the logrotate_use_nfs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logrotate_use_nfs
- name: XCCDF Value var_logrotate_use_nfs # promote to variable
  set_fact:
    var_logrotate_use_nfs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_logrotate_use_nfs" use="legacy"/>
  tags:
    - always

- name: Disable the logrotate_use_nfs SELinux Boolean - Set SELinux Boolean logrotate_use_nfs
    Accordingly
  ansible.posix.seboolean:
    name: logrotate_use_nfs
    state: '{{ var_logrotate_use_nfs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logrotate_use_nfs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_logrotate_use_nfs:var:1" value-id="xccdf_org.ssgproject.content_value_var_logrotate_use_nfs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_logrotate_use_nfs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_logrotate_use_nfs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_logwatch_can_network_connect_mail" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the logwatch_can_network_connect_mail SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>logwatch_can_network_connect_mail</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>logwatch_can_network_connect_mail</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P logwatch_can_network_connect_mail off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_logwatch_can_network_connect_mail" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_logwatch_can_network_connect_mail='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_logwatch_can_network_connect_mail" use="legacy"/>'

    /usr/sbin/setsebool -P logwatch_can_network_connect_mail $var_logwatch_can_network_connect_mail

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_logwatch_can_network_connect_mail" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logwatch_can_network_connect_mail

- name: Disable the logwatch_can_network_connect_mail SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logwatch_can_network_connect_mail
- name: XCCDF Value var_logwatch_can_network_connect_mail # promote to variable
  set_fact:
    var_logwatch_can_network_connect_mail: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_logwatch_can_network_connect_mail" use="legacy"/>
  tags:
    - always

- name: Disable the logwatch_can_network_connect_mail SELinux Boolean - Set SELinux
    Boolean logwatch_can_network_connect_mail Accordingly
  ansible.posix.seboolean:
    name: logwatch_can_network_connect_mail
    state: '{{ var_logwatch_can_network_connect_mail }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_logwatch_can_network_connect_mail
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_logwatch_can_network_connect_mail:var:1" value-id="xccdf_org.ssgproject.content_value_var_logwatch_can_network_connect_mail"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_logwatch_can_network_connect_mail:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_logwatch_can_network_connect_mail_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_lsmd_plugin_connect_any" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the lsmd_plugin_connect_any SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>lsmd_plugin_connect_any</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>lsmd_plugin_connect_any</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P lsmd_plugin_connect_any off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_lsmd_plugin_connect_any" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_lsmd_plugin_connect_any='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_lsmd_plugin_connect_any" use="legacy"/>'

    /usr/sbin/setsebool -P lsmd_plugin_connect_any $var_lsmd_plugin_connect_any

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_lsmd_plugin_connect_any" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_lsmd_plugin_connect_any

- name: Disable the lsmd_plugin_connect_any SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_lsmd_plugin_connect_any
- name: XCCDF Value var_lsmd_plugin_connect_any # promote to variable
  set_fact:
    var_lsmd_plugin_connect_any: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_lsmd_plugin_connect_any" use="legacy"/>
  tags:
    - always

- name: Disable the lsmd_plugin_connect_any SELinux Boolean - Set SELinux Boolean
    lsmd_plugin_connect_any Accordingly
  ansible.posix.seboolean:
    name: lsmd_plugin_connect_any
    state: '{{ var_lsmd_plugin_connect_any }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_lsmd_plugin_connect_any
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_lsmd_plugin_connect_any:var:1" value-id="xccdf_org.ssgproject.content_value_var_lsmd_plugin_connect_any"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_lsmd_plugin_connect_any:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_lsmd_plugin_connect_any_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mailman_use_fusefs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the mailman_use_fusefs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mailman_use_fusefs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>mailman_use_fusefs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mailman_use_fusefs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mailman_use_fusefs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mailman_use_fusefs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mailman_use_fusefs" use="legacy"/>'

    /usr/sbin/setsebool -P mailman_use_fusefs $var_mailman_use_fusefs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mailman_use_fusefs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mailman_use_fusefs

- name: Disable the mailman_use_fusefs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mailman_use_fusefs
- name: XCCDF Value var_mailman_use_fusefs # promote to variable
  set_fact:
    var_mailman_use_fusefs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mailman_use_fusefs" use="legacy"/>
  tags:
    - always

- name: Disable the mailman_use_fusefs SELinux Boolean - Set SELinux Boolean mailman_use_fusefs
    Accordingly
  ansible.posix.seboolean:
    name: mailman_use_fusefs
    state: '{{ var_mailman_use_fusefs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mailman_use_fusefs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mailman_use_fusefs:var:1" value-id="xccdf_org.ssgproject.content_value_var_mailman_use_fusefs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mailman_use_fusefs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mailman_use_fusefs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mcelog_client" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the mcelog_client SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mcelog_client</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>mcelog_client</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mcelog_client off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mcelog_client" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mcelog_client='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mcelog_client" use="legacy"/>'

    /usr/sbin/setsebool -P mcelog_client $var_mcelog_client

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mcelog_client" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mcelog_client

- name: Disable the mcelog_client SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mcelog_client
- name: XCCDF Value var_mcelog_client # promote to variable
  set_fact:
    var_mcelog_client: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mcelog_client" use="legacy"/>
  tags:
    - always

- name: Disable the mcelog_client SELinux Boolean - Set SELinux Boolean mcelog_client
    Accordingly
  ansible.posix.seboolean:
    name: mcelog_client
    state: '{{ var_mcelog_client }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mcelog_client
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mcelog_client:var:1" value-id="xccdf_org.ssgproject.content_value_var_mcelog_client"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mcelog_client:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mcelog_client_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mcelog_exec_scripts" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the mcelog_exec_scripts SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mcelog_exec_scripts</html:code> is enabled.
If this setting is disabled, it should be enabled.

To enable the <html:code>mcelog_exec_scripts</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mcelog_exec_scripts on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mcelog_exec_scripts" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mcelog_exec_scripts='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mcelog_exec_scripts" use="legacy"/>'

    /usr/sbin/setsebool -P mcelog_exec_scripts $var_mcelog_exec_scripts

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mcelog_exec_scripts" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mcelog_exec_scripts

- name: Enable the mcelog_exec_scripts SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mcelog_exec_scripts
- name: XCCDF Value var_mcelog_exec_scripts # promote to variable
  set_fact:
    var_mcelog_exec_scripts: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mcelog_exec_scripts" use="legacy"/>
  tags:
    - always

- name: Enable the mcelog_exec_scripts SELinux Boolean - Set SELinux Boolean mcelog_exec_scripts
    Accordingly
  ansible.posix.seboolean:
    name: mcelog_exec_scripts
    state: '{{ var_mcelog_exec_scripts }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mcelog_exec_scripts
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mcelog_exec_scripts:var:1" value-id="xccdf_org.ssgproject.content_value_var_mcelog_exec_scripts"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mcelog_exec_scripts:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mcelog_exec_scripts_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mcelog_foreground" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the mcelog_foreground SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mcelog_foreground</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>mcelog_foreground</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mcelog_foreground off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mcelog_foreground" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mcelog_foreground='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mcelog_foreground" use="legacy"/>'

    /usr/sbin/setsebool -P mcelog_foreground $var_mcelog_foreground

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mcelog_foreground" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mcelog_foreground

- name: Disable the mcelog_foreground SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mcelog_foreground
- name: XCCDF Value var_mcelog_foreground # promote to variable
  set_fact:
    var_mcelog_foreground: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mcelog_foreground" use="legacy"/>
  tags:
    - always

- name: Disable the mcelog_foreground SELinux Boolean - Set SELinux Boolean mcelog_foreground
    Accordingly
  ansible.posix.seboolean:
    name: mcelog_foreground
    state: '{{ var_mcelog_foreground }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mcelog_foreground
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mcelog_foreground:var:1" value-id="xccdf_org.ssgproject.content_value_var_mcelog_foreground"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mcelog_foreground:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mcelog_foreground_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mcelog_server" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the mcelog_server SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mcelog_server</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>mcelog_server</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mcelog_server off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mcelog_server" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mcelog_server='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mcelog_server" use="legacy"/>'

    /usr/sbin/setsebool -P mcelog_server $var_mcelog_server

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mcelog_server" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mcelog_server

- name: Disable the mcelog_server SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mcelog_server
- name: XCCDF Value var_mcelog_server # promote to variable
  set_fact:
    var_mcelog_server: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mcelog_server" use="legacy"/>
  tags:
    - always

- name: Disable the mcelog_server SELinux Boolean - Set SELinux Boolean mcelog_server
    Accordingly
  ansible.posix.seboolean:
    name: mcelog_server
    state: '{{ var_mcelog_server }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mcelog_server
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mcelog_server:var:1" value-id="xccdf_org.ssgproject.content_value_var_mcelog_server"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mcelog_server:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mcelog_server_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_minidlna_read_generic_user_content" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the minidlna_read_generic_user_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>minidlna_read_generic_user_content</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>minidlna_read_generic_user_content</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P minidlna_read_generic_user_content off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_minidlna_read_generic_user_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_minidlna_read_generic_user_content='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_minidlna_read_generic_user_content" use="legacy"/>'

    /usr/sbin/setsebool -P minidlna_read_generic_user_content $var_minidlna_read_generic_user_content

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_minidlna_read_generic_user_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_minidlna_read_generic_user_content

- name: Disable the minidlna_read_generic_user_content SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_minidlna_read_generic_user_content
- name: XCCDF Value var_minidlna_read_generic_user_content # promote to variable
  set_fact:
    var_minidlna_read_generic_user_content: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_minidlna_read_generic_user_content" use="legacy"/>
  tags:
    - always

- name: Disable the minidlna_read_generic_user_content SELinux Boolean - Set SELinux
    Boolean minidlna_read_generic_user_content Accordingly
  ansible.posix.seboolean:
    name: minidlna_read_generic_user_content
    state: '{{ var_minidlna_read_generic_user_content }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_minidlna_read_generic_user_content
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_minidlna_read_generic_user_content:var:1" value-id="xccdf_org.ssgproject.content_value_var_minidlna_read_generic_user_content"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_minidlna_read_generic_user_content:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_minidlna_read_generic_user_content_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mmap_low_allowed" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the mmap_low_allowed SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mmap_low_allowed</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>mmap_low_allowed</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mmap_low_allowed off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mmap_low_allowed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mmap_low_allowed='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mmap_low_allowed" use="legacy"/>'

    /usr/sbin/setsebool -P mmap_low_allowed $var_mmap_low_allowed

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mmap_low_allowed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mmap_low_allowed

- name: Disable the mmap_low_allowed SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mmap_low_allowed
- name: XCCDF Value var_mmap_low_allowed # promote to variable
  set_fact:
    var_mmap_low_allowed: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mmap_low_allowed" use="legacy"/>
  tags:
    - always

- name: Disable the mmap_low_allowed SELinux Boolean - Set SELinux Boolean mmap_low_allowed
    Accordingly
  ansible.posix.seboolean:
    name: mmap_low_allowed
    state: '{{ var_mmap_low_allowed }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mmap_low_allowed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mmap_low_allowed:var:1" value-id="xccdf_org.ssgproject.content_value_var_mmap_low_allowed"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mmap_low_allowed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mmap_low_allowed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mock_enable_homedirs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the mock_enable_homedirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mock_enable_homedirs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>mock_enable_homedirs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mock_enable_homedirs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mock_enable_homedirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mock_enable_homedirs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mock_enable_homedirs" use="legacy"/>'

    /usr/sbin/setsebool -P mock_enable_homedirs $var_mock_enable_homedirs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mock_enable_homedirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mock_enable_homedirs

- name: Disable the mock_enable_homedirs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mock_enable_homedirs
- name: XCCDF Value var_mock_enable_homedirs # promote to variable
  set_fact:
    var_mock_enable_homedirs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mock_enable_homedirs" use="legacy"/>
  tags:
    - always

- name: Disable the mock_enable_homedirs SELinux Boolean - Set SELinux Boolean mock_enable_homedirs
    Accordingly
  ansible.posix.seboolean:
    name: mock_enable_homedirs
    state: '{{ var_mock_enable_homedirs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mock_enable_homedirs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mock_enable_homedirs:var:1" value-id="xccdf_org.ssgproject.content_value_var_mock_enable_homedirs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mock_enable_homedirs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mock_enable_homedirs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mount_anyfile" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the mount_anyfile SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mount_anyfile</html:code> is enabled.
If this setting is disabled, it should be enabled to allow any file
or directory to be mounted.

To enable the <html:code>mount_anyfile</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mount_anyfile on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mount_anyfile" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mount_anyfile='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mount_anyfile" use="legacy"/>'

    /usr/sbin/setsebool -P mount_anyfile $var_mount_anyfile

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mount_anyfile" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mount_anyfile

- name: Enable the mount_anyfile SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mount_anyfile
- name: XCCDF Value var_mount_anyfile # promote to variable
  set_fact:
    var_mount_anyfile: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mount_anyfile" use="legacy"/>
  tags:
    - always

- name: Enable the mount_anyfile SELinux Boolean - Set SELinux Boolean mount_anyfile
    Accordingly
  ansible.posix.seboolean:
    name: mount_anyfile
    state: '{{ var_mount_anyfile }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mount_anyfile
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mount_anyfile:var:1" value-id="xccdf_org.ssgproject.content_value_var_mount_anyfile"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mount_anyfile:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mount_anyfile_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mozilla_plugin_bind_unreserved_ports" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the mozilla_plugin_bind_unreserved_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mozilla_plugin_bind_unreserved_ports</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>mozilla_plugin_bind_unreserved_ports</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mozilla_plugin_bind_unreserved_ports off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mozilla_plugin_bind_unreserved_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mozilla_plugin_bind_unreserved_ports='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mozilla_plugin_bind_unreserved_ports" use="legacy"/>'

    /usr/sbin/setsebool -P mozilla_plugin_bind_unreserved_ports $var_mozilla_plugin_bind_unreserved_ports

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mozilla_plugin_bind_unreserved_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_plugin_bind_unreserved_ports

- name: Disable the mozilla_plugin_bind_unreserved_ports SELinux Boolean - Ensure
    libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_plugin_bind_unreserved_ports
- name: XCCDF Value var_mozilla_plugin_bind_unreserved_ports # promote to variable
  set_fact:
    var_mozilla_plugin_bind_unreserved_ports: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mozilla_plugin_bind_unreserved_ports" use="legacy"/>
  tags:
    - always

- name: Disable the mozilla_plugin_bind_unreserved_ports SELinux Boolean - Set SELinux
    Boolean mozilla_plugin_bind_unreserved_ports Accordingly
  ansible.posix.seboolean:
    name: mozilla_plugin_bind_unreserved_ports
    state: '{{ var_mozilla_plugin_bind_unreserved_ports }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_plugin_bind_unreserved_ports
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mozilla_plugin_bind_unreserved_ports:var:1" value-id="xccdf_org.ssgproject.content_value_var_mozilla_plugin_bind_unreserved_ports"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mozilla_plugin_bind_unreserved_ports:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mozilla_plugin_bind_unreserved_ports_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mozilla_plugin_can_network_connect" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the mozilla_plugin_can_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mozilla_plugin_can_network_connect</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>mozilla_plugin_can_network_connect</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mozilla_plugin_can_network_connect off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mozilla_plugin_can_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mozilla_plugin_can_network_connect='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mozilla_plugin_can_network_connect" use="legacy"/>'

    /usr/sbin/setsebool -P mozilla_plugin_can_network_connect $var_mozilla_plugin_can_network_connect

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mozilla_plugin_can_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_plugin_can_network_connect

- name: Disable the mozilla_plugin_can_network_connect SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_plugin_can_network_connect
- name: XCCDF Value var_mozilla_plugin_can_network_connect # promote to variable
  set_fact:
    var_mozilla_plugin_can_network_connect: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mozilla_plugin_can_network_connect" use="legacy"/>
  tags:
    - always

- name: Disable the mozilla_plugin_can_network_connect SELinux Boolean - Set SELinux
    Boolean mozilla_plugin_can_network_connect Accordingly
  ansible.posix.seboolean:
    name: mozilla_plugin_can_network_connect
    state: '{{ var_mozilla_plugin_can_network_connect }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_plugin_can_network_connect
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mozilla_plugin_can_network_connect:var:1" value-id="xccdf_org.ssgproject.content_value_var_mozilla_plugin_can_network_connect"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mozilla_plugin_can_network_connect:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mozilla_plugin_can_network_connect_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mozilla_plugin_use_bluejeans" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the mozilla_plugin_use_bluejeans SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mozilla_plugin_use_bluejeans</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>mozilla_plugin_use_bluejeans</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mozilla_plugin_use_bluejeans off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mozilla_plugin_use_bluejeans" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mozilla_plugin_use_bluejeans='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mozilla_plugin_use_bluejeans" use="legacy"/>'

    /usr/sbin/setsebool -P mozilla_plugin_use_bluejeans $var_mozilla_plugin_use_bluejeans

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mozilla_plugin_use_bluejeans" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_plugin_use_bluejeans

- name: Disable the mozilla_plugin_use_bluejeans SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_plugin_use_bluejeans
- name: XCCDF Value var_mozilla_plugin_use_bluejeans # promote to variable
  set_fact:
    var_mozilla_plugin_use_bluejeans: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mozilla_plugin_use_bluejeans" use="legacy"/>
  tags:
    - always

- name: Disable the mozilla_plugin_use_bluejeans SELinux Boolean - Set SELinux Boolean
    mozilla_plugin_use_bluejeans Accordingly
  ansible.posix.seboolean:
    name: mozilla_plugin_use_bluejeans
    state: '{{ var_mozilla_plugin_use_bluejeans }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_plugin_use_bluejeans
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mozilla_plugin_use_bluejeans:var:1" value-id="xccdf_org.ssgproject.content_value_var_mozilla_plugin_use_bluejeans"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mozilla_plugin_use_bluejeans:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mozilla_plugin_use_bluejeans_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mozilla_plugin_use_gps" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the mozilla_plugin_use_gps SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mozilla_plugin_use_gps</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>mozilla_plugin_use_gps</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mozilla_plugin_use_gps off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mozilla_plugin_use_gps" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mozilla_plugin_use_gps='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mozilla_plugin_use_gps" use="legacy"/>'

    /usr/sbin/setsebool -P mozilla_plugin_use_gps $var_mozilla_plugin_use_gps

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mozilla_plugin_use_gps" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_plugin_use_gps

- name: Disable the mozilla_plugin_use_gps SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_plugin_use_gps
- name: XCCDF Value var_mozilla_plugin_use_gps # promote to variable
  set_fact:
    var_mozilla_plugin_use_gps: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mozilla_plugin_use_gps" use="legacy"/>
  tags:
    - always

- name: Disable the mozilla_plugin_use_gps SELinux Boolean - Set SELinux Boolean mozilla_plugin_use_gps
    Accordingly
  ansible.posix.seboolean:
    name: mozilla_plugin_use_gps
    state: '{{ var_mozilla_plugin_use_gps }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_plugin_use_gps
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mozilla_plugin_use_gps:var:1" value-id="xccdf_org.ssgproject.content_value_var_mozilla_plugin_use_gps"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mozilla_plugin_use_gps:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mozilla_plugin_use_gps_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mozilla_plugin_use_spice" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the mozilla_plugin_use_spice SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mozilla_plugin_use_spice</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>mozilla_plugin_use_spice</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mozilla_plugin_use_spice off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mozilla_plugin_use_spice" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mozilla_plugin_use_spice='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mozilla_plugin_use_spice" use="legacy"/>'

    /usr/sbin/setsebool -P mozilla_plugin_use_spice $var_mozilla_plugin_use_spice

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mozilla_plugin_use_spice" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_plugin_use_spice

- name: Disable the mozilla_plugin_use_spice SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_plugin_use_spice
- name: XCCDF Value var_mozilla_plugin_use_spice # promote to variable
  set_fact:
    var_mozilla_plugin_use_spice: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mozilla_plugin_use_spice" use="legacy"/>
  tags:
    - always

- name: Disable the mozilla_plugin_use_spice SELinux Boolean - Set SELinux Boolean
    mozilla_plugin_use_spice Accordingly
  ansible.posix.seboolean:
    name: mozilla_plugin_use_spice
    state: '{{ var_mozilla_plugin_use_spice }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_plugin_use_spice
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mozilla_plugin_use_spice:var:1" value-id="xccdf_org.ssgproject.content_value_var_mozilla_plugin_use_spice"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mozilla_plugin_use_spice:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mozilla_plugin_use_spice_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mozilla_read_content" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the mozilla_read_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mozilla_read_content</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>mozilla_read_content</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mozilla_read_content off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mozilla_read_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mozilla_read_content='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mozilla_read_content" use="legacy"/>'

    /usr/sbin/setsebool -P mozilla_read_content $var_mozilla_read_content

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mozilla_read_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_read_content

- name: Disable the mozilla_read_content SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_read_content
- name: XCCDF Value var_mozilla_read_content # promote to variable
  set_fact:
    var_mozilla_read_content: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mozilla_read_content" use="legacy"/>
  tags:
    - always

- name: Disable the mozilla_read_content SELinux Boolean - Set SELinux Boolean mozilla_read_content
    Accordingly
  ansible.posix.seboolean:
    name: mozilla_read_content
    state: '{{ var_mozilla_read_content }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mozilla_read_content
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mozilla_read_content:var:1" value-id="xccdf_org.ssgproject.content_value_var_mozilla_read_content"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mozilla_read_content:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mozilla_read_content_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mpd_enable_homedirs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the mpd_enable_homedirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mpd_enable_homedirs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>mpd_enable_homedirs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mpd_enable_homedirs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mpd_enable_homedirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mpd_enable_homedirs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mpd_enable_homedirs" use="legacy"/>'

    /usr/sbin/setsebool -P mpd_enable_homedirs $var_mpd_enable_homedirs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mpd_enable_homedirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mpd_enable_homedirs

- name: Disable the mpd_enable_homedirs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mpd_enable_homedirs
- name: XCCDF Value var_mpd_enable_homedirs # promote to variable
  set_fact:
    var_mpd_enable_homedirs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mpd_enable_homedirs" use="legacy"/>
  tags:
    - always

- name: Disable the mpd_enable_homedirs SELinux Boolean - Set SELinux Boolean mpd_enable_homedirs
    Accordingly
  ansible.posix.seboolean:
    name: mpd_enable_homedirs
    state: '{{ var_mpd_enable_homedirs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mpd_enable_homedirs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mpd_enable_homedirs:var:1" value-id="xccdf_org.ssgproject.content_value_var_mpd_enable_homedirs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mpd_enable_homedirs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mpd_enable_homedirs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mpd_use_cifs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the mpd_use_cifs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mpd_use_cifs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>mpd_use_cifs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mpd_use_cifs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mpd_use_cifs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mpd_use_cifs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mpd_use_cifs" use="legacy"/>'

    /usr/sbin/setsebool -P mpd_use_cifs $var_mpd_use_cifs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mpd_use_cifs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mpd_use_cifs

- name: Disable the mpd_use_cifs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mpd_use_cifs
- name: XCCDF Value var_mpd_use_cifs # promote to variable
  set_fact:
    var_mpd_use_cifs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mpd_use_cifs" use="legacy"/>
  tags:
    - always

- name: Disable the mpd_use_cifs SELinux Boolean - Set SELinux Boolean mpd_use_cifs
    Accordingly
  ansible.posix.seboolean:
    name: mpd_use_cifs
    state: '{{ var_mpd_use_cifs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mpd_use_cifs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mpd_use_cifs:var:1" value-id="xccdf_org.ssgproject.content_value_var_mpd_use_cifs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mpd_use_cifs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mpd_use_cifs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mpd_use_nfs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the mpd_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mpd_use_nfs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>mpd_use_nfs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mpd_use_nfs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mpd_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mpd_use_nfs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mpd_use_nfs" use="legacy"/>'

    /usr/sbin/setsebool -P mpd_use_nfs $var_mpd_use_nfs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mpd_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mpd_use_nfs

- name: Disable the mpd_use_nfs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mpd_use_nfs
- name: XCCDF Value var_mpd_use_nfs # promote to variable
  set_fact:
    var_mpd_use_nfs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mpd_use_nfs" use="legacy"/>
  tags:
    - always

- name: Disable the mpd_use_nfs SELinux Boolean - Set SELinux Boolean mpd_use_nfs
    Accordingly
  ansible.posix.seboolean:
    name: mpd_use_nfs
    state: '{{ var_mpd_use_nfs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mpd_use_nfs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mpd_use_nfs:var:1" value-id="xccdf_org.ssgproject.content_value_var_mpd_use_nfs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mpd_use_nfs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mpd_use_nfs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mplayer_execstack" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the mplayer_execstack SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mplayer_execstack</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>mplayer_execstack</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mplayer_execstack off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mplayer_execstack" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mplayer_execstack='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mplayer_execstack" use="legacy"/>'

    /usr/sbin/setsebool -P mplayer_execstack $var_mplayer_execstack

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mplayer_execstack" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mplayer_execstack

- name: Disable the mplayer_execstack SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mplayer_execstack
- name: XCCDF Value var_mplayer_execstack # promote to variable
  set_fact:
    var_mplayer_execstack: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mplayer_execstack" use="legacy"/>
  tags:
    - always

- name: Disable the mplayer_execstack SELinux Boolean - Set SELinux Boolean mplayer_execstack
    Accordingly
  ansible.posix.seboolean:
    name: mplayer_execstack
    state: '{{ var_mplayer_execstack }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mplayer_execstack
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mplayer_execstack:var:1" value-id="xccdf_org.ssgproject.content_value_var_mplayer_execstack"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mplayer_execstack:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mplayer_execstack_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_mysql_connect_any" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the mysql_connect_any SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>mysql_connect_any</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>mysql_connect_any</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P mysql_connect_any off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mysql_connect_any" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_mysql_connect_any='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mysql_connect_any" use="legacy"/>'

    /usr/sbin/setsebool -P mysql_connect_any $var_mysql_connect_any

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_mysql_connect_any" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mysql_connect_any

- name: Disable the mysql_connect_any SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mysql_connect_any
- name: XCCDF Value var_mysql_connect_any # promote to variable
  set_fact:
    var_mysql_connect_any: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_mysql_connect_any" use="legacy"/>
  tags:
    - always

- name: Disable the mysql_connect_any SELinux Boolean - Set SELinux Boolean mysql_connect_any
    Accordingly
  ansible.posix.seboolean:
    name: mysql_connect_any
    state: '{{ var_mysql_connect_any }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_mysql_connect_any
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_mysql_connect_any:var:1" value-id="xccdf_org.ssgproject.content_value_var_mysql_connect_any"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_mysql_connect_any:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_mysql_connect_any_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_nagios_run_pnp4nagios" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the nagios_run_pnp4nagios SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>nagios_run_pnp4nagios</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>nagios_run_pnp4nagios</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P nagios_run_pnp4nagios off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_nagios_run_pnp4nagios" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_nagios_run_pnp4nagios='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nagios_run_pnp4nagios" use="legacy"/>'

    /usr/sbin/setsebool -P nagios_run_pnp4nagios $var_nagios_run_pnp4nagios

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_nagios_run_pnp4nagios" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nagios_run_pnp4nagios

- name: Disable the nagios_run_pnp4nagios SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nagios_run_pnp4nagios
- name: XCCDF Value var_nagios_run_pnp4nagios # promote to variable
  set_fact:
    var_nagios_run_pnp4nagios: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nagios_run_pnp4nagios" use="legacy"/>
  tags:
    - always

- name: Disable the nagios_run_pnp4nagios SELinux Boolean - Set SELinux Boolean nagios_run_pnp4nagios
    Accordingly
  ansible.posix.seboolean:
    name: nagios_run_pnp4nagios
    state: '{{ var_nagios_run_pnp4nagios }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nagios_run_pnp4nagios
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_nagios_run_pnp4nagios:var:1" value-id="xccdf_org.ssgproject.content_value_var_nagios_run_pnp4nagios"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_nagios_run_pnp4nagios:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_nagios_run_pnp4nagios_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_nagios_run_sudo" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the nagios_run_sudo SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>nagios_run_sudo</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>nagios_run_sudo</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P nagios_run_sudo off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_nagios_run_sudo" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_nagios_run_sudo='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nagios_run_sudo" use="legacy"/>'

    /usr/sbin/setsebool -P nagios_run_sudo $var_nagios_run_sudo

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_nagios_run_sudo" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nagios_run_sudo

- name: Disable the nagios_run_sudo SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nagios_run_sudo
- name: XCCDF Value var_nagios_run_sudo # promote to variable
  set_fact:
    var_nagios_run_sudo: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nagios_run_sudo" use="legacy"/>
  tags:
    - always

- name: Disable the nagios_run_sudo SELinux Boolean - Set SELinux Boolean nagios_run_sudo
    Accordingly
  ansible.posix.seboolean:
    name: nagios_run_sudo
    state: '{{ var_nagios_run_sudo }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nagios_run_sudo
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_nagios_run_sudo:var:1" value-id="xccdf_org.ssgproject.content_value_var_nagios_run_sudo"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_nagios_run_sudo:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_nagios_run_sudo_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_named_tcp_bind_http_port" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the named_tcp_bind_http_port SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>named_tcp_bind_http_port</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>named_tcp_bind_http_port</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P named_tcp_bind_http_port off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_named_tcp_bind_http_port" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_named_tcp_bind_http_port='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_named_tcp_bind_http_port" use="legacy"/>'

    /usr/sbin/setsebool -P named_tcp_bind_http_port $var_named_tcp_bind_http_port

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_named_tcp_bind_http_port" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_named_tcp_bind_http_port

- name: Disable the named_tcp_bind_http_port SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_named_tcp_bind_http_port
- name: XCCDF Value var_named_tcp_bind_http_port # promote to variable
  set_fact:
    var_named_tcp_bind_http_port: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_named_tcp_bind_http_port" use="legacy"/>
  tags:
    - always

- name: Disable the named_tcp_bind_http_port SELinux Boolean - Set SELinux Boolean
    named_tcp_bind_http_port Accordingly
  ansible.posix.seboolean:
    name: named_tcp_bind_http_port
    state: '{{ var_named_tcp_bind_http_port }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_named_tcp_bind_http_port
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_named_tcp_bind_http_port:var:1" value-id="xccdf_org.ssgproject.content_value_var_named_tcp_bind_http_port"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_named_tcp_bind_http_port:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_named_tcp_bind_http_port_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_named_write_master_zones" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the named_write_master_zones SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>named_write_master_zones</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>named_write_master_zones</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P named_write_master_zones off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_named_write_master_zones" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_named_write_master_zones='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_named_write_master_zones" use="legacy"/>'

    /usr/sbin/setsebool -P named_write_master_zones $var_named_write_master_zones

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_named_write_master_zones" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_named_write_master_zones

- name: Disable the named_write_master_zones SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_named_write_master_zones
- name: XCCDF Value var_named_write_master_zones # promote to variable
  set_fact:
    var_named_write_master_zones: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_named_write_master_zones" use="legacy"/>
  tags:
    - always

- name: Disable the named_write_master_zones SELinux Boolean - Set SELinux Boolean
    named_write_master_zones Accordingly
  ansible.posix.seboolean:
    name: named_write_master_zones
    state: '{{ var_named_write_master_zones }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_named_write_master_zones
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_named_write_master_zones:var:1" value-id="xccdf_org.ssgproject.content_value_var_named_write_master_zones"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_named_write_master_zones:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_named_write_master_zones_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_neutron_can_network" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the neutron_can_network SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>neutron_can_network</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>neutron_can_network</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P neutron_can_network off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_neutron_can_network" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_neutron_can_network='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_neutron_can_network" use="legacy"/>'

    /usr/sbin/setsebool -P neutron_can_network $var_neutron_can_network

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_neutron_can_network" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_neutron_can_network

- name: Disable the neutron_can_network SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_neutron_can_network
- name: XCCDF Value var_neutron_can_network # promote to variable
  set_fact:
    var_neutron_can_network: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_neutron_can_network" use="legacy"/>
  tags:
    - always

- name: Disable the neutron_can_network SELinux Boolean - Set SELinux Boolean neutron_can_network
    Accordingly
  ansible.posix.seboolean:
    name: neutron_can_network
    state: '{{ var_neutron_can_network }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_neutron_can_network
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_neutron_can_network:var:1" value-id="xccdf_org.ssgproject.content_value_var_neutron_can_network"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_neutron_can_network:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_neutron_can_network_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_nfs_export_all_ro" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the nfs_export_all_ro SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>nfs_export_all_ro</html:code> is enabled.
If this setting is disabled, it should be enabled as it allows NFS to
export read-only mounts.

To enable the <html:code>nfs_export_all_ro</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P nfs_export_all_ro on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_nfs_export_all_ro" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_nfs_export_all_ro='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nfs_export_all_ro" use="legacy"/>'

    /usr/sbin/setsebool -P nfs_export_all_ro $var_nfs_export_all_ro

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_nfs_export_all_ro" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nfs_export_all_ro

- name: Enable the nfs_export_all_ro SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nfs_export_all_ro
- name: XCCDF Value var_nfs_export_all_ro # promote to variable
  set_fact:
    var_nfs_export_all_ro: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nfs_export_all_ro" use="legacy"/>
  tags:
    - always

- name: Enable the nfs_export_all_ro SELinux Boolean - Set SELinux Boolean nfs_export_all_ro
    Accordingly
  ansible.posix.seboolean:
    name: nfs_export_all_ro
    state: '{{ var_nfs_export_all_ro }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nfs_export_all_ro
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_nfs_export_all_ro:var:1" value-id="xccdf_org.ssgproject.content_value_var_nfs_export_all_ro"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_nfs_export_all_ro:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_nfs_export_all_ro_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_nfs_export_all_rw" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the nfs_export_all_rw SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>nfs_export_all_rw</html:code> is enabled.
If this setting is disabled, it should be enabled as it allows NFS to
export read/write mounts.

To enable the <html:code>nfs_export_all_rw</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P nfs_export_all_rw on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_nfs_export_all_rw" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_nfs_export_all_rw='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nfs_export_all_rw" use="legacy"/>'

    /usr/sbin/setsebool -P nfs_export_all_rw $var_nfs_export_all_rw

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_nfs_export_all_rw" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nfs_export_all_rw

- name: Enable the nfs_export_all_rw SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nfs_export_all_rw
- name: XCCDF Value var_nfs_export_all_rw # promote to variable
  set_fact:
    var_nfs_export_all_rw: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nfs_export_all_rw" use="legacy"/>
  tags:
    - always

- name: Enable the nfs_export_all_rw SELinux Boolean - Set SELinux Boolean nfs_export_all_rw
    Accordingly
  ansible.posix.seboolean:
    name: nfs_export_all_rw
    state: '{{ var_nfs_export_all_rw }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nfs_export_all_rw
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_nfs_export_all_rw:var:1" value-id="xccdf_org.ssgproject.content_value_var_nfs_export_all_rw"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_nfs_export_all_rw:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_nfs_export_all_rw_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_nfsd_anon_write" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the nfsd_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>nfsd_anon_write</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>nfsd_anon_write</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P nfsd_anon_write off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_nfsd_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_nfsd_anon_write='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nfsd_anon_write" use="legacy"/>'

    /usr/sbin/setsebool -P nfsd_anon_write $var_nfsd_anon_write

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_nfsd_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nfsd_anon_write

- name: Disable the nfsd_anon_write SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nfsd_anon_write
- name: XCCDF Value var_nfsd_anon_write # promote to variable
  set_fact:
    var_nfsd_anon_write: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nfsd_anon_write" use="legacy"/>
  tags:
    - always

- name: Disable the nfsd_anon_write SELinux Boolean - Set SELinux Boolean nfsd_anon_write
    Accordingly
  ansible.posix.seboolean:
    name: nfsd_anon_write
    state: '{{ var_nfsd_anon_write }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nfsd_anon_write
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_nfsd_anon_write:var:1" value-id="xccdf_org.ssgproject.content_value_var_nfsd_anon_write"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_nfsd_anon_write:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_nfsd_anon_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_nis_enabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the nis_enabled SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>nis_enabled</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>nis_enabled</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P nis_enabled off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_nis_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_nis_enabled='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nis_enabled" use="legacy"/>'

    /usr/sbin/setsebool -P nis_enabled $var_nis_enabled

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_nis_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nis_enabled

- name: Disable the nis_enabled SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nis_enabled
- name: XCCDF Value var_nis_enabled # promote to variable
  set_fact:
    var_nis_enabled: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nis_enabled" use="legacy"/>
  tags:
    - always

- name: Disable the nis_enabled SELinux Boolean - Set SELinux Boolean nis_enabled
    Accordingly
  ansible.posix.seboolean:
    name: nis_enabled
    state: '{{ var_nis_enabled }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nis_enabled
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_nis_enabled:var:1" value-id="xccdf_org.ssgproject.content_value_var_nis_enabled"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_nis_enabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_nis_enabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_nscd_use_shm" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the nscd_use_shm SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>nscd_use_shm</html:code> is enabled.
If this setting is disabled, it should be enabled to allow <html:code>nscd</html:code>
to use shared memory.

To enable the <html:code>nscd_use_shm</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P nscd_use_shm on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_nscd_use_shm" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_nscd_use_shm='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nscd_use_shm" use="legacy"/>'

    /usr/sbin/setsebool -P nscd_use_shm $var_nscd_use_shm

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_nscd_use_shm" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nscd_use_shm

- name: Enable the nscd_use_shm SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nscd_use_shm
- name: XCCDF Value var_nscd_use_shm # promote to variable
  set_fact:
    var_nscd_use_shm: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_nscd_use_shm" use="legacy"/>
  tags:
    - always

- name: Enable the nscd_use_shm SELinux Boolean - Set SELinux Boolean nscd_use_shm
    Accordingly
  ansible.posix.seboolean:
    name: nscd_use_shm
    state: '{{ var_nscd_use_shm }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_nscd_use_shm
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_nscd_use_shm:var:1" value-id="xccdf_org.ssgproject.content_value_var_nscd_use_shm"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_nscd_use_shm:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_nscd_use_shm_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_openshift_use_nfs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the openshift_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>openshift_use_nfs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>openshift_use_nfs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P openshift_use_nfs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_openshift_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_openshift_use_nfs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_openshift_use_nfs" use="legacy"/>'

    /usr/sbin/setsebool -P openshift_use_nfs $var_openshift_use_nfs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_openshift_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_openshift_use_nfs

- name: Disable the openshift_use_nfs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_openshift_use_nfs
- name: XCCDF Value var_openshift_use_nfs # promote to variable
  set_fact:
    var_openshift_use_nfs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_openshift_use_nfs" use="legacy"/>
  tags:
    - always

- name: Disable the openshift_use_nfs SELinux Boolean - Set SELinux Boolean openshift_use_nfs
    Accordingly
  ansible.posix.seboolean:
    name: openshift_use_nfs
    state: '{{ var_openshift_use_nfs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_openshift_use_nfs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_openshift_use_nfs:var:1" value-id="xccdf_org.ssgproject.content_value_var_openshift_use_nfs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_openshift_use_nfs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_openshift_use_nfs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_openvpn_can_network_connect" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the openvpn_can_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>openvpn_can_network_connect</html:code> is enabled.
This setting should be disabled.

To disable the <html:code>openvpn_can_network_connect</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P openvpn_can_network_connect off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_openvpn_can_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_openvpn_can_network_connect='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_openvpn_can_network_connect" use="legacy"/>'

    /usr/sbin/setsebool -P openvpn_can_network_connect $var_openvpn_can_network_connect

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_openvpn_can_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_openvpn_can_network_connect

- name: Disable the openvpn_can_network_connect SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_openvpn_can_network_connect
- name: XCCDF Value var_openvpn_can_network_connect # promote to variable
  set_fact:
    var_openvpn_can_network_connect: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_openvpn_can_network_connect" use="legacy"/>
  tags:
    - always

- name: Disable the openvpn_can_network_connect SELinux Boolean - Set SELinux Boolean
    openvpn_can_network_connect Accordingly
  ansible.posix.seboolean:
    name: openvpn_can_network_connect
    state: '{{ var_openvpn_can_network_connect }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_openvpn_can_network_connect
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_openvpn_can_network_connect:var:1" value-id="xccdf_org.ssgproject.content_value_var_openvpn_can_network_connect"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_openvpn_can_network_connect:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_openvpn_can_network_connect_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_openvpn_enable_homedirs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the openvpn_enable_homedirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>openvpn_enable_homedirs</html:code> is enabled.
This setting should be disabled.

To disable the <html:code>openvpn_enable_homedirs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P openvpn_enable_homedirs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_openvpn_enable_homedirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_openvpn_enable_homedirs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_openvpn_enable_homedirs" use="legacy"/>'

    /usr/sbin/setsebool -P openvpn_enable_homedirs $var_openvpn_enable_homedirs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_openvpn_enable_homedirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_openvpn_enable_homedirs

- name: Disable the openvpn_enable_homedirs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_openvpn_enable_homedirs
- name: XCCDF Value var_openvpn_enable_homedirs # promote to variable
  set_fact:
    var_openvpn_enable_homedirs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_openvpn_enable_homedirs" use="legacy"/>
  tags:
    - always

- name: Disable the openvpn_enable_homedirs SELinux Boolean - Set SELinux Boolean
    openvpn_enable_homedirs Accordingly
  ansible.posix.seboolean:
    name: openvpn_enable_homedirs
    state: '{{ var_openvpn_enable_homedirs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_openvpn_enable_homedirs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_openvpn_enable_homedirs:var:1" value-id="xccdf_org.ssgproject.content_value_var_openvpn_enable_homedirs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_openvpn_enable_homedirs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_openvpn_enable_homedirs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_openvpn_run_unconfined" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the openvpn_run_unconfined SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>openvpn_run_unconfined</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>openvpn_run_unconfined</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P openvpn_run_unconfined off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_openvpn_run_unconfined" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_openvpn_run_unconfined='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_openvpn_run_unconfined" use="legacy"/>'

    /usr/sbin/setsebool -P openvpn_run_unconfined $var_openvpn_run_unconfined

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_openvpn_run_unconfined" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_openvpn_run_unconfined

- name: Disable the openvpn_run_unconfined SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_openvpn_run_unconfined
- name: XCCDF Value var_openvpn_run_unconfined # promote to variable
  set_fact:
    var_openvpn_run_unconfined: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_openvpn_run_unconfined" use="legacy"/>
  tags:
    - always

- name: Disable the openvpn_run_unconfined SELinux Boolean - Set SELinux Boolean openvpn_run_unconfined
    Accordingly
  ansible.posix.seboolean:
    name: openvpn_run_unconfined
    state: '{{ var_openvpn_run_unconfined }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_openvpn_run_unconfined
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_openvpn_run_unconfined:var:1" value-id="xccdf_org.ssgproject.content_value_var_openvpn_run_unconfined"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_openvpn_run_unconfined:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_openvpn_run_unconfined_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_pcp_bind_all_unreserved_ports" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the pcp_bind_all_unreserved_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>pcp_bind_all_unreserved_ports</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>pcp_bind_all_unreserved_ports</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P pcp_bind_all_unreserved_ports off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_pcp_bind_all_unreserved_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_pcp_bind_all_unreserved_ports='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_pcp_bind_all_unreserved_ports" use="legacy"/>'

    /usr/sbin/setsebool -P pcp_bind_all_unreserved_ports $var_pcp_bind_all_unreserved_ports

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_pcp_bind_all_unreserved_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_pcp_bind_all_unreserved_ports

- name: Disable the pcp_bind_all_unreserved_ports SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_pcp_bind_all_unreserved_ports
- name: XCCDF Value var_pcp_bind_all_unreserved_ports # promote to variable
  set_fact:
    var_pcp_bind_all_unreserved_ports: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_pcp_bind_all_unreserved_ports" use="legacy"/>
  tags:
    - always

- name: Disable the pcp_bind_all_unreserved_ports SELinux Boolean - Set SELinux Boolean
    pcp_bind_all_unreserved_ports Accordingly
  ansible.posix.seboolean:
    name: pcp_bind_all_unreserved_ports
    state: '{{ var_pcp_bind_all_unreserved_ports }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_pcp_bind_all_unreserved_ports
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_pcp_bind_all_unreserved_ports:var:1" value-id="xccdf_org.ssgproject.content_value_var_pcp_bind_all_unreserved_ports"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_pcp_bind_all_unreserved_ports:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_pcp_bind_all_unreserved_ports_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_pcp_read_generic_logs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the pcp_read_generic_logs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>pcp_read_generic_logs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>pcp_read_generic_logs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P pcp_read_generic_logs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_pcp_read_generic_logs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_pcp_read_generic_logs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_pcp_read_generic_logs" use="legacy"/>'

    /usr/sbin/setsebool -P pcp_read_generic_logs $var_pcp_read_generic_logs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_pcp_read_generic_logs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_pcp_read_generic_logs

- name: Disable the pcp_read_generic_logs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_pcp_read_generic_logs
- name: XCCDF Value var_pcp_read_generic_logs # promote to variable
  set_fact:
    var_pcp_read_generic_logs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_pcp_read_generic_logs" use="legacy"/>
  tags:
    - always

- name: Disable the pcp_read_generic_logs SELinux Boolean - Set SELinux Boolean pcp_read_generic_logs
    Accordingly
  ansible.posix.seboolean:
    name: pcp_read_generic_logs
    state: '{{ var_pcp_read_generic_logs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_pcp_read_generic_logs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_pcp_read_generic_logs:var:1" value-id="xccdf_org.ssgproject.content_value_var_pcp_read_generic_logs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_pcp_read_generic_logs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_pcp_read_generic_logs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_piranha_lvs_can_network_connect" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the piranha_lvs_can_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>piranha_lvs_can_network_connect</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>piranha_lvs_can_network_connect</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P piranha_lvs_can_network_connect off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_piranha_lvs_can_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_piranha_lvs_can_network_connect='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_piranha_lvs_can_network_connect" use="legacy"/>'

    /usr/sbin/setsebool -P piranha_lvs_can_network_connect $var_piranha_lvs_can_network_connect

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_piranha_lvs_can_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_piranha_lvs_can_network_connect

- name: Disable the piranha_lvs_can_network_connect SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_piranha_lvs_can_network_connect
- name: XCCDF Value var_piranha_lvs_can_network_connect # promote to variable
  set_fact:
    var_piranha_lvs_can_network_connect: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_piranha_lvs_can_network_connect" use="legacy"/>
  tags:
    - always

- name: Disable the piranha_lvs_can_network_connect SELinux Boolean - Set SELinux
    Boolean piranha_lvs_can_network_connect Accordingly
  ansible.posix.seboolean:
    name: piranha_lvs_can_network_connect
    state: '{{ var_piranha_lvs_can_network_connect }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_piranha_lvs_can_network_connect
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_piranha_lvs_can_network_connect:var:1" value-id="xccdf_org.ssgproject.content_value_var_piranha_lvs_can_network_connect"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_piranha_lvs_can_network_connect:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_piranha_lvs_can_network_connect_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_polipo_connect_all_unreserved" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the polipo_connect_all_unreserved SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>polipo_connect_all_unreserved</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>polipo_connect_all_unreserved</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P polipo_connect_all_unreserved off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_polipo_connect_all_unreserved" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_polipo_connect_all_unreserved='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_polipo_connect_all_unreserved" use="legacy"/>'

    /usr/sbin/setsebool -P polipo_connect_all_unreserved $var_polipo_connect_all_unreserved

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_polipo_connect_all_unreserved" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polipo_connect_all_unreserved

- name: Disable the polipo_connect_all_unreserved SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polipo_connect_all_unreserved
- name: XCCDF Value var_polipo_connect_all_unreserved # promote to variable
  set_fact:
    var_polipo_connect_all_unreserved: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_polipo_connect_all_unreserved" use="legacy"/>
  tags:
    - always

- name: Disable the polipo_connect_all_unreserved SELinux Boolean - Set SELinux Boolean
    polipo_connect_all_unreserved Accordingly
  ansible.posix.seboolean:
    name: polipo_connect_all_unreserved
    state: '{{ var_polipo_connect_all_unreserved }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polipo_connect_all_unreserved
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_polipo_connect_all_unreserved:var:1" value-id="xccdf_org.ssgproject.content_value_var_polipo_connect_all_unreserved"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_polipo_connect_all_unreserved:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_polipo_connect_all_unreserved_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_polipo_session_bind_all_unreserved_ports" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the polipo_session_bind_all_unreserved_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>polipo_session_bind_all_unreserved_ports</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>polipo_session_bind_all_unreserved_ports</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P polipo_session_bind_all_unreserved_ports off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_polipo_session_bind_all_unreserved_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_polipo_session_bind_all_unreserved_ports='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_polipo_session_bind_all_unreserved_ports" use="legacy"/>'

    /usr/sbin/setsebool -P polipo_session_bind_all_unreserved_ports $var_polipo_session_bind_all_unreserved_ports

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_polipo_session_bind_all_unreserved_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polipo_session_bind_all_unreserved_ports

- name: Disable the polipo_session_bind_all_unreserved_ports SELinux Boolean - Ensure
    libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polipo_session_bind_all_unreserved_ports
- name: XCCDF Value var_polipo_session_bind_all_unreserved_ports # promote to variable
  set_fact:
    var_polipo_session_bind_all_unreserved_ports: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_polipo_session_bind_all_unreserved_ports" use="legacy"/>
  tags:
    - always

- name: Disable the polipo_session_bind_all_unreserved_ports SELinux Boolean - Set
    SELinux Boolean polipo_session_bind_all_unreserved_ports Accordingly
  ansible.posix.seboolean:
    name: polipo_session_bind_all_unreserved_ports
    state: '{{ var_polipo_session_bind_all_unreserved_ports }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polipo_session_bind_all_unreserved_ports
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_polipo_session_bind_all_unreserved_ports:var:1" value-id="xccdf_org.ssgproject.content_value_var_polipo_session_bind_all_unreserved_ports"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_polipo_session_bind_all_unreserved_ports:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_polipo_session_bind_all_unreserved_ports_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_polipo_session_users" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the polipo_session_users SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>polipo_session_users</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>polipo_session_users</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P polipo_session_users off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_polipo_session_users" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_polipo_session_users='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_polipo_session_users" use="legacy"/>'

    /usr/sbin/setsebool -P polipo_session_users $var_polipo_session_users

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_polipo_session_users" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polipo_session_users

- name: Disable the polipo_session_users SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polipo_session_users
- name: XCCDF Value var_polipo_session_users # promote to variable
  set_fact:
    var_polipo_session_users: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_polipo_session_users" use="legacy"/>
  tags:
    - always

- name: Disable the polipo_session_users SELinux Boolean - Set SELinux Boolean polipo_session_users
    Accordingly
  ansible.posix.seboolean:
    name: polipo_session_users
    state: '{{ var_polipo_session_users }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polipo_session_users
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_polipo_session_users:var:1" value-id="xccdf_org.ssgproject.content_value_var_polipo_session_users"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_polipo_session_users:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_polipo_session_users_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_polipo_use_cifs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the polipo_use_cifs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>polipo_use_cifs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>polipo_use_cifs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P polipo_use_cifs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_polipo_use_cifs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_polipo_use_cifs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_polipo_use_cifs" use="legacy"/>'

    /usr/sbin/setsebool -P polipo_use_cifs $var_polipo_use_cifs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_polipo_use_cifs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polipo_use_cifs

- name: Disable the polipo_use_cifs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polipo_use_cifs
- name: XCCDF Value var_polipo_use_cifs # promote to variable
  set_fact:
    var_polipo_use_cifs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_polipo_use_cifs" use="legacy"/>
  tags:
    - always

- name: Disable the polipo_use_cifs SELinux Boolean - Set SELinux Boolean polipo_use_cifs
    Accordingly
  ansible.posix.seboolean:
    name: polipo_use_cifs
    state: '{{ var_polipo_use_cifs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polipo_use_cifs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_polipo_use_cifs:var:1" value-id="xccdf_org.ssgproject.content_value_var_polipo_use_cifs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_polipo_use_cifs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_polipo_use_cifs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_polipo_use_nfs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the polipo_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>polipo_use_nfs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>polipo_use_nfs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P polipo_use_nfs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_polipo_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_polipo_use_nfs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_polipo_use_nfs" use="legacy"/>'

    /usr/sbin/setsebool -P polipo_use_nfs $var_polipo_use_nfs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_polipo_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polipo_use_nfs

- name: Disable the polipo_use_nfs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polipo_use_nfs
- name: XCCDF Value var_polipo_use_nfs # promote to variable
  set_fact:
    var_polipo_use_nfs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_polipo_use_nfs" use="legacy"/>
  tags:
    - always

- name: Disable the polipo_use_nfs SELinux Boolean - Set SELinux Boolean polipo_use_nfs
    Accordingly
  ansible.posix.seboolean:
    name: polipo_use_nfs
    state: '{{ var_polipo_use_nfs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polipo_use_nfs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_polipo_use_nfs:var:1" value-id="xccdf_org.ssgproject.content_value_var_polipo_use_nfs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_polipo_use_nfs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_polipo_use_nfs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_polyinstantiation_enabled" selected="false" severity="medium">
              <xccdf-1.2:title>Configure the polyinstantiation_enabled SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>polyinstantiation_enabled</html:code> is disabled.
This setting should be configured to <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_polyinstantiation_enabled" use="legacy"/>.
<html:br/>
To set the <html:code>polyinstantiation_enabled</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P polyinstantiation_enabled <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_polyinstantiation_enabled" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R55</xccdf-1.2:reference>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_polyinstantiation_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_polyinstantiation_enabled='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_polyinstantiation_enabled" use="legacy"/>'

    /usr/sbin/setsebool -P polyinstantiation_enabled $var_polyinstantiation_enabled

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_polyinstantiation_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polyinstantiation_enabled

- name: Configure the polyinstantiation_enabled SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polyinstantiation_enabled
- name: XCCDF Value var_polyinstantiation_enabled # promote to variable
  set_fact:
    var_polyinstantiation_enabled: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_polyinstantiation_enabled" use="legacy"/>
  tags:
    - always

- name: Configure the polyinstantiation_enabled SELinux Boolean - Set SELinux Boolean
    polyinstantiation_enabled Accordingly
  ansible.posix.seboolean:
    name: polyinstantiation_enabled
    state: '{{ var_polyinstantiation_enabled }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_polyinstantiation_enabled
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_polyinstantiation_enabled:var:1" value-id="xccdf_org.ssgproject.content_value_var_polyinstantiation_enabled"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_polyinstantiation_enabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_polyinstantiation_enabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_postfix_local_write_mail_spool" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the postfix_local_write_mail_spool SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>postfix_local_write_mail_spool</html:code> is enabled.
If this setting is disabled, it should be enabled as it allows Postfix to write
to the mail spool directories.

To enable the <html:code>postfix_local_write_mail_spool</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P postfix_local_write_mail_spool on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_postfix_local_write_mail_spool" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_postfix_local_write_mail_spool='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postfix_local_write_mail_spool" use="legacy"/>'

    /usr/sbin/setsebool -P postfix_local_write_mail_spool $var_postfix_local_write_mail_spool

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_postfix_local_write_mail_spool" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_postfix_local_write_mail_spool

- name: Enable the postfix_local_write_mail_spool SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_postfix_local_write_mail_spool
- name: XCCDF Value var_postfix_local_write_mail_spool # promote to variable
  set_fact:
    var_postfix_local_write_mail_spool: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postfix_local_write_mail_spool" use="legacy"/>
  tags:
    - always

- name: Enable the postfix_local_write_mail_spool SELinux Boolean - Set SELinux Boolean
    postfix_local_write_mail_spool Accordingly
  ansible.posix.seboolean:
    name: postfix_local_write_mail_spool
    state: '{{ var_postfix_local_write_mail_spool }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_postfix_local_write_mail_spool
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_postfix_local_write_mail_spool:var:1" value-id="xccdf_org.ssgproject.content_value_var_postfix_local_write_mail_spool"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_postfix_local_write_mail_spool:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_postfix_local_write_mail_spool_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_postgresql_can_rsync" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the postgresql_can_rsync SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>postgresql_can_rsync</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>postgresql_can_rsync</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P postgresql_can_rsync off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_postgresql_can_rsync" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_postgresql_can_rsync='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postgresql_can_rsync" use="legacy"/>'

    /usr/sbin/setsebool -P postgresql_can_rsync $var_postgresql_can_rsync

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_postgresql_can_rsync" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_postgresql_can_rsync

- name: Disable the postgresql_can_rsync SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_postgresql_can_rsync
- name: XCCDF Value var_postgresql_can_rsync # promote to variable
  set_fact:
    var_postgresql_can_rsync: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postgresql_can_rsync" use="legacy"/>
  tags:
    - always

- name: Disable the postgresql_can_rsync SELinux Boolean - Set SELinux Boolean postgresql_can_rsync
    Accordingly
  ansible.posix.seboolean:
    name: postgresql_can_rsync
    state: '{{ var_postgresql_can_rsync }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_postgresql_can_rsync
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_postgresql_can_rsync:var:1" value-id="xccdf_org.ssgproject.content_value_var_postgresql_can_rsync"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_postgresql_can_rsync:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_postgresql_can_rsync_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_postgresql_selinux_transmit_client_label" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the postgresql_selinux_transmit_client_label SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>postgresql_selinux_transmit_client_label</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>postgresql_selinux_transmit_client_label</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P postgresql_selinux_transmit_client_label off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_postgresql_selinux_transmit_client_label" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_postgresql_selinux_transmit_client_label='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postgresql_selinux_transmit_client_label" use="legacy"/>'

    /usr/sbin/setsebool -P postgresql_selinux_transmit_client_label $var_postgresql_selinux_transmit_client_label

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_postgresql_selinux_transmit_client_label" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_postgresql_selinux_transmit_client_label

- name: Disable the postgresql_selinux_transmit_client_label SELinux Boolean - Ensure
    libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_postgresql_selinux_transmit_client_label
- name: XCCDF Value var_postgresql_selinux_transmit_client_label # promote to variable
  set_fact:
    var_postgresql_selinux_transmit_client_label: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postgresql_selinux_transmit_client_label" use="legacy"/>
  tags:
    - always

- name: Disable the postgresql_selinux_transmit_client_label SELinux Boolean - Set
    SELinux Boolean postgresql_selinux_transmit_client_label Accordingly
  ansible.posix.seboolean:
    name: postgresql_selinux_transmit_client_label
    state: '{{ var_postgresql_selinux_transmit_client_label }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_postgresql_selinux_transmit_client_label
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_postgresql_selinux_transmit_client_label:var:1" value-id="xccdf_org.ssgproject.content_value_var_postgresql_selinux_transmit_client_label"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_postgresql_selinux_transmit_client_label:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_postgresql_selinux_transmit_client_label_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_postgresql_selinux_unconfined_dbadm" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the postgresql_selinux_unconfined_dbadm SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>postgresql_selinux_unconfined_dbadm</html:code> is enabled.
If this setting is disabled, it should be enabled as it allows Database Administrators to
execute Data Manipulation Language (DML) statements.

To enable the <html:code>postgresql_selinux_unconfined_dbadm</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P postgresql_selinux_unconfined_dbadm on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_postgresql_selinux_unconfined_dbadm" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_postgresql_selinux_unconfined_dbadm='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postgresql_selinux_unconfined_dbadm" use="legacy"/>'

    /usr/sbin/setsebool -P postgresql_selinux_unconfined_dbadm $var_postgresql_selinux_unconfined_dbadm

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_postgresql_selinux_unconfined_dbadm" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_postgresql_selinux_unconfined_dbadm

- name: Enable the postgresql_selinux_unconfined_dbadm SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_postgresql_selinux_unconfined_dbadm
- name: XCCDF Value var_postgresql_selinux_unconfined_dbadm # promote to variable
  set_fact:
    var_postgresql_selinux_unconfined_dbadm: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postgresql_selinux_unconfined_dbadm" use="legacy"/>
  tags:
    - always

- name: Enable the postgresql_selinux_unconfined_dbadm SELinux Boolean - Set SELinux
    Boolean postgresql_selinux_unconfined_dbadm Accordingly
  ansible.posix.seboolean:
    name: postgresql_selinux_unconfined_dbadm
    state: '{{ var_postgresql_selinux_unconfined_dbadm }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_postgresql_selinux_unconfined_dbadm
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_postgresql_selinux_unconfined_dbadm:var:1" value-id="xccdf_org.ssgproject.content_value_var_postgresql_selinux_unconfined_dbadm"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_postgresql_selinux_unconfined_dbadm:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_postgresql_selinux_unconfined_dbadm_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_postgresql_selinux_users_ddl" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the postgresql_selinux_users_ddl SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>postgresql_selinux_users_ddl</html:code> is enabled.
If this setting is disabled, it should be enabled as it allows Database Administrators to
execute Data Definition Language (DDL) statements.

To enable the <html:code>postgresql_selinux_users_ddl</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P postgresql_selinux_users_ddl on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_postgresql_selinux_users_ddl" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_postgresql_selinux_users_ddl='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postgresql_selinux_users_ddl" use="legacy"/>'

    /usr/sbin/setsebool -P postgresql_selinux_users_ddl $var_postgresql_selinux_users_ddl

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_postgresql_selinux_users_ddl" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_postgresql_selinux_users_ddl

- name: Enable the postgresql_selinux_users_ddl SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_postgresql_selinux_users_ddl
- name: XCCDF Value var_postgresql_selinux_users_ddl # promote to variable
  set_fact:
    var_postgresql_selinux_users_ddl: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postgresql_selinux_users_ddl" use="legacy"/>
  tags:
    - always

- name: Enable the postgresql_selinux_users_ddl SELinux Boolean - Set SELinux Boolean
    postgresql_selinux_users_ddl Accordingly
  ansible.posix.seboolean:
    name: postgresql_selinux_users_ddl
    state: '{{ var_postgresql_selinux_users_ddl }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_postgresql_selinux_users_ddl
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_postgresql_selinux_users_ddl:var:1" value-id="xccdf_org.ssgproject.content_value_var_postgresql_selinux_users_ddl"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_postgresql_selinux_users_ddl:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_postgresql_selinux_users_ddl_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_pppd_can_insmod" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the pppd_can_insmod SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>pppd_can_insmod</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>pppd_can_insmod</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P pppd_can_insmod off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_pppd_can_insmod" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_pppd_can_insmod='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_pppd_can_insmod" use="legacy"/>'

    /usr/sbin/setsebool -P pppd_can_insmod $var_pppd_can_insmod

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_pppd_can_insmod" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_pppd_can_insmod

- name: Disable the pppd_can_insmod SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_pppd_can_insmod
- name: XCCDF Value var_pppd_can_insmod # promote to variable
  set_fact:
    var_pppd_can_insmod: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_pppd_can_insmod" use="legacy"/>
  tags:
    - always

- name: Disable the pppd_can_insmod SELinux Boolean - Set SELinux Boolean pppd_can_insmod
    Accordingly
  ansible.posix.seboolean:
    name: pppd_can_insmod
    state: '{{ var_pppd_can_insmod }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_pppd_can_insmod
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_pppd_can_insmod:var:1" value-id="xccdf_org.ssgproject.content_value_var_pppd_can_insmod"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_pppd_can_insmod:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_pppd_can_insmod_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_pppd_for_user" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the pppd_for_user SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>pppd_for_user</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>pppd_for_user</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P pppd_for_user off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_pppd_for_user" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_pppd_for_user='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_pppd_for_user" use="legacy"/>'

    /usr/sbin/setsebool -P pppd_for_user $var_pppd_for_user

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_pppd_for_user" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_pppd_for_user

- name: Disable the pppd_for_user SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_pppd_for_user
- name: XCCDF Value var_pppd_for_user # promote to variable
  set_fact:
    var_pppd_for_user: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_pppd_for_user" use="legacy"/>
  tags:
    - always

- name: Disable the pppd_for_user SELinux Boolean - Set SELinux Boolean pppd_for_user
    Accordingly
  ansible.posix.seboolean:
    name: pppd_for_user
    state: '{{ var_pppd_for_user }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_pppd_for_user
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_pppd_for_user:var:1" value-id="xccdf_org.ssgproject.content_value_var_pppd_for_user"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_pppd_for_user:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_pppd_for_user_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_privoxy_connect_any" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the privoxy_connect_any SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>privoxy_connect_any</html:code> is enabled.
This setting should be disabled.

To disable the <html:code>privoxy_connect_any</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P privoxy_connect_any off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_privoxy_connect_any" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_privoxy_connect_any='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_privoxy_connect_any" use="legacy"/>'

    /usr/sbin/setsebool -P privoxy_connect_any $var_privoxy_connect_any

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_privoxy_connect_any" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_privoxy_connect_any

- name: Disable the privoxy_connect_any SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_privoxy_connect_any
- name: XCCDF Value var_privoxy_connect_any # promote to variable
  set_fact:
    var_privoxy_connect_any: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_privoxy_connect_any" use="legacy"/>
  tags:
    - always

- name: Disable the privoxy_connect_any SELinux Boolean - Set SELinux Boolean privoxy_connect_any
    Accordingly
  ansible.posix.seboolean:
    name: privoxy_connect_any
    state: '{{ var_privoxy_connect_any }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_privoxy_connect_any
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_privoxy_connect_any:var:1" value-id="xccdf_org.ssgproject.content_value_var_privoxy_connect_any"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_privoxy_connect_any:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_privoxy_connect_any_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_prosody_bind_http_port" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the prosody_bind_http_port SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>prosody_bind_http_port</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>prosody_bind_http_port</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P prosody_bind_http_port off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_prosody_bind_http_port" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_prosody_bind_http_port='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_prosody_bind_http_port" use="legacy"/>'

    /usr/sbin/setsebool -P prosody_bind_http_port $var_prosody_bind_http_port

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_prosody_bind_http_port" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_prosody_bind_http_port

- name: Disable the prosody_bind_http_port SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_prosody_bind_http_port
- name: XCCDF Value var_prosody_bind_http_port # promote to variable
  set_fact:
    var_prosody_bind_http_port: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_prosody_bind_http_port" use="legacy"/>
  tags:
    - always

- name: Disable the prosody_bind_http_port SELinux Boolean - Set SELinux Boolean prosody_bind_http_port
    Accordingly
  ansible.posix.seboolean:
    name: prosody_bind_http_port
    state: '{{ var_prosody_bind_http_port }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_prosody_bind_http_port
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_prosody_bind_http_port:var:1" value-id="xccdf_org.ssgproject.content_value_var_prosody_bind_http_port"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_prosody_bind_http_port:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_prosody_bind_http_port_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_puppetagent_manage_all_files" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the puppetagent_manage_all_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>puppetagent_manage_all_files</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>puppetagent_manage_all_files</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P puppetagent_manage_all_files off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_puppetagent_manage_all_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_puppetagent_manage_all_files='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_puppetagent_manage_all_files" use="legacy"/>'

    /usr/sbin/setsebool -P puppetagent_manage_all_files $var_puppetagent_manage_all_files

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_puppetagent_manage_all_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_puppetagent_manage_all_files

- name: Disable the puppetagent_manage_all_files SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_puppetagent_manage_all_files
- name: XCCDF Value var_puppetagent_manage_all_files # promote to variable
  set_fact:
    var_puppetagent_manage_all_files: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_puppetagent_manage_all_files" use="legacy"/>
  tags:
    - always

- name: Disable the puppetagent_manage_all_files SELinux Boolean - Set SELinux Boolean
    puppetagent_manage_all_files Accordingly
  ansible.posix.seboolean:
    name: puppetagent_manage_all_files
    state: '{{ var_puppetagent_manage_all_files }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_puppetagent_manage_all_files
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_puppetagent_manage_all_files:var:1" value-id="xccdf_org.ssgproject.content_value_var_puppetagent_manage_all_files"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_puppetagent_manage_all_files:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_puppetagent_manage_all_files_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_puppetmaster_use_db" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the puppetmaster_use_db SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>puppetmaster_use_db</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>puppetmaster_use_db</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P puppetmaster_use_db off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_puppetmaster_use_db" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_puppetmaster_use_db='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_puppetmaster_use_db" use="legacy"/>'

    /usr/sbin/setsebool -P puppetmaster_use_db $var_puppetmaster_use_db

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_puppetmaster_use_db" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_puppetmaster_use_db

- name: Disable the puppetmaster_use_db SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_puppetmaster_use_db
- name: XCCDF Value var_puppetmaster_use_db # promote to variable
  set_fact:
    var_puppetmaster_use_db: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_puppetmaster_use_db" use="legacy"/>
  tags:
    - always

- name: Disable the puppetmaster_use_db SELinux Boolean - Set SELinux Boolean puppetmaster_use_db
    Accordingly
  ansible.posix.seboolean:
    name: puppetmaster_use_db
    state: '{{ var_puppetmaster_use_db }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_puppetmaster_use_db
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_puppetmaster_use_db:var:1" value-id="xccdf_org.ssgproject.content_value_var_puppetmaster_use_db"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_puppetmaster_use_db:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_puppetmaster_use_db_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_racoon_read_shadow" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the racoon_read_shadow SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>racoon_read_shadow</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>racoon_read_shadow</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P racoon_read_shadow off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_racoon_read_shadow" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_racoon_read_shadow='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_racoon_read_shadow" use="legacy"/>'

    /usr/sbin/setsebool -P racoon_read_shadow $var_racoon_read_shadow

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_racoon_read_shadow" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_racoon_read_shadow

- name: Disable the racoon_read_shadow SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_racoon_read_shadow
- name: XCCDF Value var_racoon_read_shadow # promote to variable
  set_fact:
    var_racoon_read_shadow: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_racoon_read_shadow" use="legacy"/>
  tags:
    - always

- name: Disable the racoon_read_shadow SELinux Boolean - Set SELinux Boolean racoon_read_shadow
    Accordingly
  ansible.posix.seboolean:
    name: racoon_read_shadow
    state: '{{ var_racoon_read_shadow }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_racoon_read_shadow
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_racoon_read_shadow:var:1" value-id="xccdf_org.ssgproject.content_value_var_racoon_read_shadow"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_racoon_read_shadow:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_racoon_read_shadow_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_rsync_anon_write" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the rsync_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>rsync_anon_write</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>rsync_anon_write</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P rsync_anon_write off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_rsync_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_rsync_anon_write='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rsync_anon_write" use="legacy"/>'

    /usr/sbin/setsebool -P rsync_anon_write $var_rsync_anon_write

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_rsync_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_rsync_anon_write

- name: Disable the rsync_anon_write SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_rsync_anon_write
- name: XCCDF Value var_rsync_anon_write # promote to variable
  set_fact:
    var_rsync_anon_write: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rsync_anon_write" use="legacy"/>
  tags:
    - always

- name: Disable the rsync_anon_write SELinux Boolean - Set SELinux Boolean rsync_anon_write
    Accordingly
  ansible.posix.seboolean:
    name: rsync_anon_write
    state: '{{ var_rsync_anon_write }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_rsync_anon_write
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_rsync_anon_write:var:1" value-id="xccdf_org.ssgproject.content_value_var_rsync_anon_write"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_rsync_anon_write:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_rsync_anon_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_rsync_client" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the rsync_client SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>rsync_client</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>rsync_client</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P rsync_client off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_rsync_client" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_rsync_client='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rsync_client" use="legacy"/>'

    /usr/sbin/setsebool -P rsync_client $var_rsync_client

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_rsync_client" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_rsync_client

- name: Disable the rsync_client SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_rsync_client
- name: XCCDF Value var_rsync_client # promote to variable
  set_fact:
    var_rsync_client: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rsync_client" use="legacy"/>
  tags:
    - always

- name: Disable the rsync_client SELinux Boolean - Set SELinux Boolean rsync_client
    Accordingly
  ansible.posix.seboolean:
    name: rsync_client
    state: '{{ var_rsync_client }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_rsync_client
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_rsync_client:var:1" value-id="xccdf_org.ssgproject.content_value_var_rsync_client"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_rsync_client:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_rsync_client_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_rsync_export_all_ro" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the rsync_export_all_ro SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>rsync_export_all_ro</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>rsync_export_all_ro</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P rsync_export_all_ro off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_rsync_export_all_ro" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_rsync_export_all_ro='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rsync_export_all_ro" use="legacy"/>'

    /usr/sbin/setsebool -P rsync_export_all_ro $var_rsync_export_all_ro

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_rsync_export_all_ro" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_rsync_export_all_ro

- name: Disable the rsync_export_all_ro SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_rsync_export_all_ro
- name: XCCDF Value var_rsync_export_all_ro # promote to variable
  set_fact:
    var_rsync_export_all_ro: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rsync_export_all_ro" use="legacy"/>
  tags:
    - always

- name: Disable the rsync_export_all_ro SELinux Boolean - Set SELinux Boolean rsync_export_all_ro
    Accordingly
  ansible.posix.seboolean:
    name: rsync_export_all_ro
    state: '{{ var_rsync_export_all_ro }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_rsync_export_all_ro
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_rsync_export_all_ro:var:1" value-id="xccdf_org.ssgproject.content_value_var_rsync_export_all_ro"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_rsync_export_all_ro:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_rsync_export_all_ro_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_rsync_full_access" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the rsync_full_access SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>rsync_full_access</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>rsync_full_access</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P rsync_full_access off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_rsync_full_access" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_rsync_full_access='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rsync_full_access" use="legacy"/>'

    /usr/sbin/setsebool -P rsync_full_access $var_rsync_full_access

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_rsync_full_access" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_rsync_full_access

- name: Disable the rsync_full_access SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_rsync_full_access
- name: XCCDF Value var_rsync_full_access # promote to variable
  set_fact:
    var_rsync_full_access: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rsync_full_access" use="legacy"/>
  tags:
    - always

- name: Disable the rsync_full_access SELinux Boolean - Set SELinux Boolean rsync_full_access
    Accordingly
  ansible.posix.seboolean:
    name: rsync_full_access
    state: '{{ var_rsync_full_access }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_rsync_full_access
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_rsync_full_access:var:1" value-id="xccdf_org.ssgproject.content_value_var_rsync_full_access"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_rsync_full_access:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_rsync_full_access_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_samba_create_home_dirs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the samba_create_home_dirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>samba_create_home_dirs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>samba_create_home_dirs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P samba_create_home_dirs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_create_home_dirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_samba_create_home_dirs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_create_home_dirs" use="legacy"/>'

    /usr/sbin/setsebool -P samba_create_home_dirs $var_samba_create_home_dirs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_create_home_dirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_create_home_dirs

- name: Disable the samba_create_home_dirs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_create_home_dirs
- name: XCCDF Value var_samba_create_home_dirs # promote to variable
  set_fact:
    var_samba_create_home_dirs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_create_home_dirs" use="legacy"/>
  tags:
    - always

- name: Disable the samba_create_home_dirs SELinux Boolean - Set SELinux Boolean samba_create_home_dirs
    Accordingly
  ansible.posix.seboolean:
    name: samba_create_home_dirs
    state: '{{ var_samba_create_home_dirs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_create_home_dirs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_samba_create_home_dirs:var:1" value-id="xccdf_org.ssgproject.content_value_var_samba_create_home_dirs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_samba_create_home_dirs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_samba_create_home_dirs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_samba_domain_controller" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the samba_domain_controller SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>samba_domain_controller</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>samba_domain_controller</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P samba_domain_controller off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_domain_controller" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_samba_domain_controller='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_domain_controller" use="legacy"/>'

    /usr/sbin/setsebool -P samba_domain_controller $var_samba_domain_controller

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_domain_controller" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_domain_controller

- name: Disable the samba_domain_controller SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_domain_controller
- name: XCCDF Value var_samba_domain_controller # promote to variable
  set_fact:
    var_samba_domain_controller: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_domain_controller" use="legacy"/>
  tags:
    - always

- name: Disable the samba_domain_controller SELinux Boolean - Set SELinux Boolean
    samba_domain_controller Accordingly
  ansible.posix.seboolean:
    name: samba_domain_controller
    state: '{{ var_samba_domain_controller }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_domain_controller
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_samba_domain_controller:var:1" value-id="xccdf_org.ssgproject.content_value_var_samba_domain_controller"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_samba_domain_controller:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_samba_domain_controller_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_samba_enable_home_dirs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the samba_enable_home_dirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>samba_enable_home_dirs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>samba_enable_home_dirs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P samba_enable_home_dirs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_enable_home_dirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_samba_enable_home_dirs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_enable_home_dirs" use="legacy"/>'

    /usr/sbin/setsebool -P samba_enable_home_dirs $var_samba_enable_home_dirs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_enable_home_dirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_enable_home_dirs

- name: Disable the samba_enable_home_dirs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_enable_home_dirs
- name: XCCDF Value var_samba_enable_home_dirs # promote to variable
  set_fact:
    var_samba_enable_home_dirs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_enable_home_dirs" use="legacy"/>
  tags:
    - always

- name: Disable the samba_enable_home_dirs SELinux Boolean - Set SELinux Boolean samba_enable_home_dirs
    Accordingly
  ansible.posix.seboolean:
    name: samba_enable_home_dirs
    state: '{{ var_samba_enable_home_dirs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_enable_home_dirs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_samba_enable_home_dirs:var:1" value-id="xccdf_org.ssgproject.content_value_var_samba_enable_home_dirs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_samba_enable_home_dirs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_samba_enable_home_dirs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_samba_export_all_ro" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the samba_export_all_ro SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>samba_export_all_ro</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>samba_export_all_ro</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P samba_export_all_ro off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_export_all_ro" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_samba_export_all_ro='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_export_all_ro" use="legacy"/>'

    /usr/sbin/setsebool -P samba_export_all_ro $var_samba_export_all_ro

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_export_all_ro" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_export_all_ro

- name: Disable the samba_export_all_ro SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_export_all_ro
- name: XCCDF Value var_samba_export_all_ro # promote to variable
  set_fact:
    var_samba_export_all_ro: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_export_all_ro" use="legacy"/>
  tags:
    - always

- name: Disable the samba_export_all_ro SELinux Boolean - Set SELinux Boolean samba_export_all_ro
    Accordingly
  ansible.posix.seboolean:
    name: samba_export_all_ro
    state: '{{ var_samba_export_all_ro }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_export_all_ro
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_samba_export_all_ro:var:1" value-id="xccdf_org.ssgproject.content_value_var_samba_export_all_ro"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_samba_export_all_ro:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_samba_export_all_ro_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_samba_export_all_rw" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the samba_export_all_rw SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>samba_export_all_rw</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>samba_export_all_rw</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P samba_export_all_rw off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_export_all_rw" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_samba_export_all_rw='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_export_all_rw" use="legacy"/>'

    /usr/sbin/setsebool -P samba_export_all_rw $var_samba_export_all_rw

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_export_all_rw" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_export_all_rw

- name: Disable the samba_export_all_rw SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_export_all_rw
- name: XCCDF Value var_samba_export_all_rw # promote to variable
  set_fact:
    var_samba_export_all_rw: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_export_all_rw" use="legacy"/>
  tags:
    - always

- name: Disable the samba_export_all_rw SELinux Boolean - Set SELinux Boolean samba_export_all_rw
    Accordingly
  ansible.posix.seboolean:
    name: samba_export_all_rw
    state: '{{ var_samba_export_all_rw }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_export_all_rw
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_samba_export_all_rw:var:1" value-id="xccdf_org.ssgproject.content_value_var_samba_export_all_rw"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_samba_export_all_rw:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_samba_export_all_rw_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_samba_load_libgfapi" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the samba_load_libgfapi SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>samba_load_libgfapi</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>samba_load_libgfapi</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P samba_load_libgfapi off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_load_libgfapi" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_samba_load_libgfapi='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_load_libgfapi" use="legacy"/>'

    /usr/sbin/setsebool -P samba_load_libgfapi $var_samba_load_libgfapi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_load_libgfapi" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_load_libgfapi

- name: Disable the samba_load_libgfapi SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_load_libgfapi
- name: XCCDF Value var_samba_load_libgfapi # promote to variable
  set_fact:
    var_samba_load_libgfapi: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_load_libgfapi" use="legacy"/>
  tags:
    - always

- name: Disable the samba_load_libgfapi SELinux Boolean - Set SELinux Boolean samba_load_libgfapi
    Accordingly
  ansible.posix.seboolean:
    name: samba_load_libgfapi
    state: '{{ var_samba_load_libgfapi }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_load_libgfapi
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_samba_load_libgfapi:var:1" value-id="xccdf_org.ssgproject.content_value_var_samba_load_libgfapi"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_samba_load_libgfapi:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_samba_load_libgfapi_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_samba_portmapper" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the samba_portmapper SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>samba_portmapper</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>samba_portmapper</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P samba_portmapper off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_portmapper" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_samba_portmapper='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_portmapper" use="legacy"/>'

    /usr/sbin/setsebool -P samba_portmapper $var_samba_portmapper

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_portmapper" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_portmapper

- name: Disable the samba_portmapper SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_portmapper
- name: XCCDF Value var_samba_portmapper # promote to variable
  set_fact:
    var_samba_portmapper: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_portmapper" use="legacy"/>
  tags:
    - always

- name: Disable the samba_portmapper SELinux Boolean - Set SELinux Boolean samba_portmapper
    Accordingly
  ansible.posix.seboolean:
    name: samba_portmapper
    state: '{{ var_samba_portmapper }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_portmapper
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_samba_portmapper:var:1" value-id="xccdf_org.ssgproject.content_value_var_samba_portmapper"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_samba_portmapper:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_samba_portmapper_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_samba_run_unconfined" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the samba_run_unconfined SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>samba_run_unconfined</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>samba_run_unconfined</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P samba_run_unconfined off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_run_unconfined" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_samba_run_unconfined='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_run_unconfined" use="legacy"/>'

    /usr/sbin/setsebool -P samba_run_unconfined $var_samba_run_unconfined

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_run_unconfined" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_run_unconfined

- name: Disable the samba_run_unconfined SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_run_unconfined
- name: XCCDF Value var_samba_run_unconfined # promote to variable
  set_fact:
    var_samba_run_unconfined: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_run_unconfined" use="legacy"/>
  tags:
    - always

- name: Disable the samba_run_unconfined SELinux Boolean - Set SELinux Boolean samba_run_unconfined
    Accordingly
  ansible.posix.seboolean:
    name: samba_run_unconfined
    state: '{{ var_samba_run_unconfined }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_run_unconfined
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_samba_run_unconfined:var:1" value-id="xccdf_org.ssgproject.content_value_var_samba_run_unconfined"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_samba_run_unconfined:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_samba_run_unconfined_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_samba_share_fusefs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the samba_share_fusefs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>samba_share_fusefs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>samba_share_fusefs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P samba_share_fusefs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_share_fusefs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_samba_share_fusefs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_share_fusefs" use="legacy"/>'

    /usr/sbin/setsebool -P samba_share_fusefs $var_samba_share_fusefs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_share_fusefs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_share_fusefs

- name: Disable the samba_share_fusefs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_share_fusefs
- name: XCCDF Value var_samba_share_fusefs # promote to variable
  set_fact:
    var_samba_share_fusefs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_share_fusefs" use="legacy"/>
  tags:
    - always

- name: Disable the samba_share_fusefs SELinux Boolean - Set SELinux Boolean samba_share_fusefs
    Accordingly
  ansible.posix.seboolean:
    name: samba_share_fusefs
    state: '{{ var_samba_share_fusefs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_share_fusefs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_samba_share_fusefs:var:1" value-id="xccdf_org.ssgproject.content_value_var_samba_share_fusefs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_samba_share_fusefs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_samba_share_fusefs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_samba_share_nfs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the samba_share_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>samba_share_nfs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>samba_share_nfs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P samba_share_nfs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_share_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_samba_share_nfs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_share_nfs" use="legacy"/>'

    /usr/sbin/setsebool -P samba_share_nfs $var_samba_share_nfs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_samba_share_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_share_nfs

- name: Disable the samba_share_nfs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_share_nfs
- name: XCCDF Value var_samba_share_nfs # promote to variable
  set_fact:
    var_samba_share_nfs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_samba_share_nfs" use="legacy"/>
  tags:
    - always

- name: Disable the samba_share_nfs SELinux Boolean - Set SELinux Boolean samba_share_nfs
    Accordingly
  ansible.posix.seboolean:
    name: samba_share_nfs
    state: '{{ var_samba_share_nfs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_samba_share_nfs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_samba_share_nfs:var:1" value-id="xccdf_org.ssgproject.content_value_var_samba_share_nfs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_samba_share_nfs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_samba_share_nfs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_sanlock_use_fusefs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the sanlock_use_fusefs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>sanlock_use_fusefs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>sanlock_use_fusefs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P sanlock_use_fusefs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_sanlock_use_fusefs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_sanlock_use_fusefs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sanlock_use_fusefs" use="legacy"/>'

    /usr/sbin/setsebool -P sanlock_use_fusefs $var_sanlock_use_fusefs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_sanlock_use_fusefs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sanlock_use_fusefs

- name: Disable the sanlock_use_fusefs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sanlock_use_fusefs
- name: XCCDF Value var_sanlock_use_fusefs # promote to variable
  set_fact:
    var_sanlock_use_fusefs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sanlock_use_fusefs" use="legacy"/>
  tags:
    - always

- name: Disable the sanlock_use_fusefs SELinux Boolean - Set SELinux Boolean sanlock_use_fusefs
    Accordingly
  ansible.posix.seboolean:
    name: sanlock_use_fusefs
    state: '{{ var_sanlock_use_fusefs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sanlock_use_fusefs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sanlock_use_fusefs:var:1" value-id="xccdf_org.ssgproject.content_value_var_sanlock_use_fusefs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_sanlock_use_fusefs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_sanlock_use_fusefs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_sanlock_use_nfs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the sanlock_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>sanlock_use_nfs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>sanlock_use_nfs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P sanlock_use_nfs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_sanlock_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_sanlock_use_nfs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sanlock_use_nfs" use="legacy"/>'

    /usr/sbin/setsebool -P sanlock_use_nfs $var_sanlock_use_nfs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_sanlock_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sanlock_use_nfs

- name: Disable the sanlock_use_nfs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sanlock_use_nfs
- name: XCCDF Value var_sanlock_use_nfs # promote to variable
  set_fact:
    var_sanlock_use_nfs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sanlock_use_nfs" use="legacy"/>
  tags:
    - always

- name: Disable the sanlock_use_nfs SELinux Boolean - Set SELinux Boolean sanlock_use_nfs
    Accordingly
  ansible.posix.seboolean:
    name: sanlock_use_nfs
    state: '{{ var_sanlock_use_nfs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sanlock_use_nfs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sanlock_use_nfs:var:1" value-id="xccdf_org.ssgproject.content_value_var_sanlock_use_nfs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_sanlock_use_nfs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_sanlock_use_nfs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_sanlock_use_samba" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the sanlock_use_samba SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>sanlock_use_samba</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>sanlock_use_samba</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P sanlock_use_samba off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_sanlock_use_samba" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_sanlock_use_samba='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sanlock_use_samba" use="legacy"/>'

    /usr/sbin/setsebool -P sanlock_use_samba $var_sanlock_use_samba

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_sanlock_use_samba" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sanlock_use_samba

- name: Disable the sanlock_use_samba SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sanlock_use_samba
- name: XCCDF Value var_sanlock_use_samba # promote to variable
  set_fact:
    var_sanlock_use_samba: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sanlock_use_samba" use="legacy"/>
  tags:
    - always

- name: Disable the sanlock_use_samba SELinux Boolean - Set SELinux Boolean sanlock_use_samba
    Accordingly
  ansible.posix.seboolean:
    name: sanlock_use_samba
    state: '{{ var_sanlock_use_samba }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sanlock_use_samba
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sanlock_use_samba:var:1" value-id="xccdf_org.ssgproject.content_value_var_sanlock_use_samba"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_sanlock_use_samba:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_sanlock_use_samba_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_saslauthd_read_shadow" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the saslauthd_read_shadow SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>saslauthd_read_shadow</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>saslauthd_read_shadow</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P saslauthd_read_shadow off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_saslauthd_read_shadow" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_saslauthd_read_shadow='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_saslauthd_read_shadow" use="legacy"/>'

    /usr/sbin/setsebool -P saslauthd_read_shadow $var_saslauthd_read_shadow

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_saslauthd_read_shadow" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_saslauthd_read_shadow

- name: Disable the saslauthd_read_shadow SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_saslauthd_read_shadow
- name: XCCDF Value var_saslauthd_read_shadow # promote to variable
  set_fact:
    var_saslauthd_read_shadow: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_saslauthd_read_shadow" use="legacy"/>
  tags:
    - always

- name: Disable the saslauthd_read_shadow SELinux Boolean - Set SELinux Boolean saslauthd_read_shadow
    Accordingly
  ansible.posix.seboolean:
    name: saslauthd_read_shadow
    state: '{{ var_saslauthd_read_shadow }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_saslauthd_read_shadow
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_saslauthd_read_shadow:var:1" value-id="xccdf_org.ssgproject.content_value_var_saslauthd_read_shadow"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_saslauthd_read_shadow:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_saslauthd_read_shadow_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_secadm_exec_content" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the secadm_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>secadm_exec_content</html:code> is enabled.
If this setting is disabled, it should be enabled.

To enable the <html:code>secadm_exec_content</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P secadm_exec_content on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_secadm_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_secadm_exec_content='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_secadm_exec_content" use="legacy"/>'

    /usr/sbin/setsebool -P secadm_exec_content $var_secadm_exec_content

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_secadm_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_secadm_exec_content

- name: Enable the secadm_exec_content SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_secadm_exec_content
- name: XCCDF Value var_secadm_exec_content # promote to variable
  set_fact:
    var_secadm_exec_content: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_secadm_exec_content" use="legacy"/>
  tags:
    - always

- name: Enable the secadm_exec_content SELinux Boolean - Set SELinux Boolean secadm_exec_content
    Accordingly
  ansible.posix.seboolean:
    name: secadm_exec_content
    state: '{{ var_secadm_exec_content }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_secadm_exec_content
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_secadm_exec_content:var:1" value-id="xccdf_org.ssgproject.content_value_var_secadm_exec_content"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_secadm_exec_content:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_secadm_exec_content_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_secure_mode" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the secure_mode SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>secure_mode</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>secure_mode</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P secure_mode off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_secure_mode" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_secure_mode='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_secure_mode" use="legacy"/>'

    /usr/sbin/setsebool -P secure_mode $var_secure_mode

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_secure_mode" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_secure_mode

- name: Disable the secure_mode SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_secure_mode
- name: XCCDF Value var_secure_mode # promote to variable
  set_fact:
    var_secure_mode: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_secure_mode" use="legacy"/>
  tags:
    - always

- name: Disable the secure_mode SELinux Boolean - Set SELinux Boolean secure_mode
    Accordingly
  ansible.posix.seboolean:
    name: secure_mode
    state: '{{ var_secure_mode }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_secure_mode
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_secure_mode:var:1" value-id="xccdf_org.ssgproject.content_value_var_secure_mode"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_secure_mode:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_secure_mode_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_secure_mode_insmod" selected="false" severity="medium">
              <xccdf-1.2:title>Configure the secure_mode_insmod SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>secure_mode_insmod</html:code> is disabled.
This setting should be configured to <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_secure_mode_insmod" use="legacy"/>.
<html:br/>
To set the <html:code>secure_mode_insmod</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P secure_mode_insmod <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_secure_mode_insmod" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R48</xccdf-1.2:reference>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_secure_mode_insmod" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_secure_mode_insmod='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_secure_mode_insmod" use="legacy"/>'

    /usr/sbin/setsebool -P secure_mode_insmod $var_secure_mode_insmod

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_secure_mode_insmod" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_secure_mode_insmod

- name: Configure the secure_mode_insmod SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_secure_mode_insmod
- name: XCCDF Value var_secure_mode_insmod # promote to variable
  set_fact:
    var_secure_mode_insmod: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_secure_mode_insmod" use="legacy"/>
  tags:
    - always

- name: Configure the secure_mode_insmod SELinux Boolean - Set SELinux Boolean secure_mode_insmod
    Accordingly
  ansible.posix.seboolean:
    name: secure_mode_insmod
    state: '{{ var_secure_mode_insmod }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_secure_mode_insmod
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_secure_mode_insmod:var:1" value-id="xccdf_org.ssgproject.content_value_var_secure_mode_insmod"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_secure_mode_insmod:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_secure_mode_insmod_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_secure_mode_policyload" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the secure_mode_policyload SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>secure_mode_policyload</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>secure_mode_policyload</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P secure_mode_policyload off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_secure_mode_policyload" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_secure_mode_policyload='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_secure_mode_policyload" use="legacy"/>'

    /usr/sbin/setsebool -P secure_mode_policyload $var_secure_mode_policyload

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_secure_mode_policyload" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_secure_mode_policyload

- name: Disable the secure_mode_policyload SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_secure_mode_policyload
- name: XCCDF Value var_secure_mode_policyload # promote to variable
  set_fact:
    var_secure_mode_policyload: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_secure_mode_policyload" use="legacy"/>
  tags:
    - always

- name: Disable the secure_mode_policyload SELinux Boolean - Set SELinux Boolean secure_mode_policyload
    Accordingly
  ansible.posix.seboolean:
    name: secure_mode_policyload
    state: '{{ var_secure_mode_policyload }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_secure_mode_policyload
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_secure_mode_policyload:var:1" value-id="xccdf_org.ssgproject.content_value_var_secure_mode_policyload"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_secure_mode_policyload:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_secure_mode_policyload_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_direct_dri_enabled" selected="false" severity="medium">
              <xccdf-1.2:title>Configure the selinuxuser_direct_dri_enabled SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>selinuxuser_direct_dri_enabled</html:code> is enabled.
If XWindows is not installed or used on the system, this setting should be disabled.
Otherwise, enable it.

To disable the <html:code>selinuxuser_direct_dri_enabled</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P selinuxuser_direct_dri_enabled off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_direct_dri_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_selinuxuser_direct_dri_enabled='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_direct_dri_enabled" use="legacy"/>'

    /usr/sbin/setsebool -P selinuxuser_direct_dri_enabled $var_selinuxuser_direct_dri_enabled

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_direct_dri_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_direct_dri_enabled

- name: Configure the selinuxuser_direct_dri_enabled SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_direct_dri_enabled
- name: XCCDF Value var_selinuxuser_direct_dri_enabled # promote to variable
  set_fact:
    var_selinuxuser_direct_dri_enabled: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_direct_dri_enabled" use="legacy"/>
  tags:
    - always

- name: Configure the selinuxuser_direct_dri_enabled SELinux Boolean - Set SELinux
    Boolean selinuxuser_direct_dri_enabled Accordingly
  ansible.posix.seboolean:
    name: selinuxuser_direct_dri_enabled
    state: '{{ var_selinuxuser_direct_dri_enabled }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_direct_dri_enabled
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_selinuxuser_direct_dri_enabled:var:1" value-id="xccdf_org.ssgproject.content_value_var_selinuxuser_direct_dri_enabled"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_selinuxuser_direct_dri_enabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_selinuxuser_direct_dri_enabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_execheap" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the selinuxuser_execheap SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>selinuxuser_execheap</html:code> is disabled.
When enabled this boolean is enabled it allows selinuxusers to execute code from the heap.
If this setting is enabled, it should be disabled.

To disable the <html:code>selinuxuser_execheap</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P selinuxuser_execheap off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R48</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Disabling code execution from the heap blocks buffer overflow attacks.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_execheap" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_selinuxuser_execheap='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_execheap" use="legacy"/>'

    /usr/sbin/setsebool -P selinuxuser_execheap $var_selinuxuser_execheap

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_execheap" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_execheap

- name: Disable the selinuxuser_execheap SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_execheap
- name: XCCDF Value var_selinuxuser_execheap # promote to variable
  set_fact:
    var_selinuxuser_execheap: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_execheap" use="legacy"/>
  tags:
    - always

- name: Disable the selinuxuser_execheap SELinux Boolean - Set SELinux Boolean selinuxuser_execheap
    Accordingly
  ansible.posix.seboolean:
    name: selinuxuser_execheap
    state: '{{ var_selinuxuser_execheap }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_execheap
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_selinuxuser_execheap:var:1" value-id="xccdf_org.ssgproject.content_value_var_selinuxuser_execheap"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_selinuxuser_execheap:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_selinuxuser_execheap_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_execmod" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the selinuxuser_execmod SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>selinuxuser_execmod</html:code> is enabled.
If this setting is disabled, it should be enabled.

To enable the <html:code>selinuxuser_execmod</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P selinuxuser_execmod on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_execmod" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_selinuxuser_execmod='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_execmod" use="legacy"/>'

    /usr/sbin/setsebool -P selinuxuser_execmod $var_selinuxuser_execmod

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_execmod" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_execmod

- name: Enable the selinuxuser_execmod SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_execmod
- name: XCCDF Value var_selinuxuser_execmod # promote to variable
  set_fact:
    var_selinuxuser_execmod: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_execmod" use="legacy"/>
  tags:
    - always

- name: Enable the selinuxuser_execmod SELinux Boolean - Set SELinux Boolean selinuxuser_execmod
    Accordingly
  ansible.posix.seboolean:
    name: selinuxuser_execmod
    state: '{{ var_selinuxuser_execmod }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_execmod
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_selinuxuser_execmod:var:1" value-id="xccdf_org.ssgproject.content_value_var_selinuxuser_execmod"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_selinuxuser_execmod:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_selinuxuser_execmod_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_execstack" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the selinuxuser_execstack SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>selinuxuser_execstack</html:code> is enabled.
This setting should be disabled as unconfined executables should not be able
to make their stack executable.

To disable the <html:code>selinuxuser_execstack</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P selinuxuser_execstack off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R48</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Disabling code execution from the stack blocks buffer overflow attacks.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_execstack" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_selinuxuser_execstack='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_execstack" use="legacy"/>'

    /usr/sbin/setsebool -P selinuxuser_execstack $var_selinuxuser_execstack

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_execstack" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_execstack

- name: Disable the selinuxuser_execstack SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_execstack
- name: XCCDF Value var_selinuxuser_execstack # promote to variable
  set_fact:
    var_selinuxuser_execstack: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_execstack" use="legacy"/>
  tags:
    - always

- name: Disable the selinuxuser_execstack SELinux Boolean - Set SELinux Boolean selinuxuser_execstack
    Accordingly
  ansible.posix.seboolean:
    name: selinuxuser_execstack
    state: '{{ var_selinuxuser_execstack }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_execstack
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_selinuxuser_execstack:var:1" value-id="xccdf_org.ssgproject.content_value_var_selinuxuser_execstack"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_selinuxuser_execstack:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_selinuxuser_execstack_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_mysql_connect_enabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the selinuxuser_mysql_connect_enabled SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>selinuxuser_mysql_connect_enabled</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>selinuxuser_mysql_connect_enabled</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P selinuxuser_mysql_connect_enabled off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_mysql_connect_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_selinuxuser_mysql_connect_enabled='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_mysql_connect_enabled" use="legacy"/>'

    /usr/sbin/setsebool -P selinuxuser_mysql_connect_enabled $var_selinuxuser_mysql_connect_enabled

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_mysql_connect_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_mysql_connect_enabled

- name: Disable the selinuxuser_mysql_connect_enabled SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_mysql_connect_enabled
- name: XCCDF Value var_selinuxuser_mysql_connect_enabled # promote to variable
  set_fact:
    var_selinuxuser_mysql_connect_enabled: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_mysql_connect_enabled" use="legacy"/>
  tags:
    - always

- name: Disable the selinuxuser_mysql_connect_enabled SELinux Boolean - Set SELinux
    Boolean selinuxuser_mysql_connect_enabled Accordingly
  ansible.posix.seboolean:
    name: selinuxuser_mysql_connect_enabled
    state: '{{ var_selinuxuser_mysql_connect_enabled }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_mysql_connect_enabled
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_selinuxuser_mysql_connect_enabled:var:1" value-id="xccdf_org.ssgproject.content_value_var_selinuxuser_mysql_connect_enabled"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_selinuxuser_mysql_connect_enabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_selinuxuser_mysql_connect_enabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_ping" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the selinuxuser_ping SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>selinuxuser_ping</html:code> is enabled.
If this setting is disabled, it should be enabled as it allows confined users
to use ping and traceroute which is helpful for network troubleshooting.

To enable the <html:code>selinuxuser_ping</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P selinuxuser_ping on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_ping" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_selinuxuser_ping='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_ping" use="legacy"/>'

    /usr/sbin/setsebool -P selinuxuser_ping $var_selinuxuser_ping

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_ping" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_ping

- name: Enable the selinuxuser_ping SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_ping
- name: XCCDF Value var_selinuxuser_ping # promote to variable
  set_fact:
    var_selinuxuser_ping: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_ping" use="legacy"/>
  tags:
    - always

- name: Enable the selinuxuser_ping SELinux Boolean - Set SELinux Boolean selinuxuser_ping
    Accordingly
  ansible.posix.seboolean:
    name: selinuxuser_ping
    state: '{{ var_selinuxuser_ping }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_ping
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_selinuxuser_ping:var:1" value-id="xccdf_org.ssgproject.content_value_var_selinuxuser_ping"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_selinuxuser_ping:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_selinuxuser_ping_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_postgresql_connect_enabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the selinuxuser_postgresql_connect_enabled SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>selinuxuser_postgresql_connect_enabled</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>selinuxuser_postgresql_connect_enabled</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P selinuxuser_postgresql_connect_enabled off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_postgresql_connect_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_selinuxuser_postgresql_connect_enabled='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_postgresql_connect_enabled" use="legacy"/>'

    /usr/sbin/setsebool -P selinuxuser_postgresql_connect_enabled $var_selinuxuser_postgresql_connect_enabled

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_postgresql_connect_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_postgresql_connect_enabled

- name: Disable the selinuxuser_postgresql_connect_enabled SELinux Boolean - Ensure
    libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_postgresql_connect_enabled
- name: XCCDF Value var_selinuxuser_postgresql_connect_enabled # promote to variable
  set_fact:
    var_selinuxuser_postgresql_connect_enabled: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_postgresql_connect_enabled" use="legacy"/>
  tags:
    - always

- name: Disable the selinuxuser_postgresql_connect_enabled SELinux Boolean - Set SELinux
    Boolean selinuxuser_postgresql_connect_enabled Accordingly
  ansible.posix.seboolean:
    name: selinuxuser_postgresql_connect_enabled
    state: '{{ var_selinuxuser_postgresql_connect_enabled }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_postgresql_connect_enabled
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_selinuxuser_postgresql_connect_enabled:var:1" value-id="xccdf_org.ssgproject.content_value_var_selinuxuser_postgresql_connect_enabled"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_selinuxuser_postgresql_connect_enabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_selinuxuser_postgresql_connect_enabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_rw_noexattrfile" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the selinuxuser_rw_noexattrfile SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>selinuxuser_rw_noexattrfile</html:code> is enabled.
This setting should be disabled as users should not be able to read/write files
on filesystems that do not have extended attributes e.g. FAT, CDROM, FLOPPY, etc.

To disable the <html:code>selinuxuser_rw_noexattrfile</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P selinuxuser_rw_noexattrfile off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_rw_noexattrfile" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_selinuxuser_rw_noexattrfile='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_rw_noexattrfile" use="legacy"/>'

    /usr/sbin/setsebool -P selinuxuser_rw_noexattrfile $var_selinuxuser_rw_noexattrfile

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_rw_noexattrfile" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_rw_noexattrfile

- name: Disable the selinuxuser_rw_noexattrfile SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_rw_noexattrfile
- name: XCCDF Value var_selinuxuser_rw_noexattrfile # promote to variable
  set_fact:
    var_selinuxuser_rw_noexattrfile: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_rw_noexattrfile" use="legacy"/>
  tags:
    - always

- name: Disable the selinuxuser_rw_noexattrfile SELinux Boolean - Set SELinux Boolean
    selinuxuser_rw_noexattrfile Accordingly
  ansible.posix.seboolean:
    name: selinuxuser_rw_noexattrfile
    state: '{{ var_selinuxuser_rw_noexattrfile }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_rw_noexattrfile
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_selinuxuser_rw_noexattrfile:var:1" value-id="xccdf_org.ssgproject.content_value_var_selinuxuser_rw_noexattrfile"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_selinuxuser_rw_noexattrfile:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_selinuxuser_rw_noexattrfile_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_share_music" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the selinuxuser_share_music SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>selinuxuser_share_music</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>selinuxuser_share_music</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P selinuxuser_share_music off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_share_music" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_selinuxuser_share_music='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_share_music" use="legacy"/>'

    /usr/sbin/setsebool -P selinuxuser_share_music $var_selinuxuser_share_music

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_share_music" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_share_music

- name: Disable the selinuxuser_share_music SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_share_music
- name: XCCDF Value var_selinuxuser_share_music # promote to variable
  set_fact:
    var_selinuxuser_share_music: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_share_music" use="legacy"/>
  tags:
    - always

- name: Disable the selinuxuser_share_music SELinux Boolean - Set SELinux Boolean
    selinuxuser_share_music Accordingly
  ansible.posix.seboolean:
    name: selinuxuser_share_music
    state: '{{ var_selinuxuser_share_music }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_share_music
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_selinuxuser_share_music:var:1" value-id="xccdf_org.ssgproject.content_value_var_selinuxuser_share_music"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_selinuxuser_share_music:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_selinuxuser_share_music_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_tcp_server" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the selinuxuser_tcp_server SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>selinuxuser_tcp_server</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>selinuxuser_tcp_server</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P selinuxuser_tcp_server off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_tcp_server" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_selinuxuser_tcp_server='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_tcp_server" use="legacy"/>'

    /usr/sbin/setsebool -P selinuxuser_tcp_server $var_selinuxuser_tcp_server

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_tcp_server" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_tcp_server

- name: Disable the selinuxuser_tcp_server SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_tcp_server
- name: XCCDF Value var_selinuxuser_tcp_server # promote to variable
  set_fact:
    var_selinuxuser_tcp_server: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_tcp_server" use="legacy"/>
  tags:
    - always

- name: Disable the selinuxuser_tcp_server SELinux Boolean - Set SELinux Boolean selinuxuser_tcp_server
    Accordingly
  ansible.posix.seboolean:
    name: selinuxuser_tcp_server
    state: '{{ var_selinuxuser_tcp_server }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_tcp_server
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_selinuxuser_tcp_server:var:1" value-id="xccdf_org.ssgproject.content_value_var_selinuxuser_tcp_server"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_selinuxuser_tcp_server:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_selinuxuser_tcp_server_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_udp_server" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the selinuxuser_udp_server SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>selinuxuser_udp_server</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>selinuxuser_udp_server</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P selinuxuser_udp_server off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_udp_server" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_selinuxuser_udp_server='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_udp_server" use="legacy"/>'

    /usr/sbin/setsebool -P selinuxuser_udp_server $var_selinuxuser_udp_server

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_udp_server" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_udp_server

- name: Disable the selinuxuser_udp_server SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_udp_server
- name: XCCDF Value var_selinuxuser_udp_server # promote to variable
  set_fact:
    var_selinuxuser_udp_server: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_udp_server" use="legacy"/>
  tags:
    - always

- name: Disable the selinuxuser_udp_server SELinux Boolean - Set SELinux Boolean selinuxuser_udp_server
    Accordingly
  ansible.posix.seboolean:
    name: selinuxuser_udp_server
    state: '{{ var_selinuxuser_udp_server }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_udp_server
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_selinuxuser_udp_server:var:1" value-id="xccdf_org.ssgproject.content_value_var_selinuxuser_udp_server"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_selinuxuser_udp_server:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_selinuxuser_udp_server_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_use_ssh_chroot" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the selinuxuser_use_ssh_chroot SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>selinuxuser_use_ssh_chroot</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>selinuxuser_use_ssh_chroot</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P selinuxuser_use_ssh_chroot off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_use_ssh_chroot" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_selinuxuser_use_ssh_chroot='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_use_ssh_chroot" use="legacy"/>'

    /usr/sbin/setsebool -P selinuxuser_use_ssh_chroot $var_selinuxuser_use_ssh_chroot

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_selinuxuser_use_ssh_chroot" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_use_ssh_chroot

- name: Disable the selinuxuser_use_ssh_chroot SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_use_ssh_chroot
- name: XCCDF Value var_selinuxuser_use_ssh_chroot # promote to variable
  set_fact:
    var_selinuxuser_use_ssh_chroot: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_selinuxuser_use_ssh_chroot" use="legacy"/>
  tags:
    - always

- name: Disable the selinuxuser_use_ssh_chroot SELinux Boolean - Set SELinux Boolean
    selinuxuser_use_ssh_chroot Accordingly
  ansible.posix.seboolean:
    name: selinuxuser_use_ssh_chroot
    state: '{{ var_selinuxuser_use_ssh_chroot }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_selinuxuser_use_ssh_chroot
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_selinuxuser_use_ssh_chroot:var:1" value-id="xccdf_org.ssgproject.content_value_var_selinuxuser_use_ssh_chroot"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_selinuxuser_use_ssh_chroot:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_selinuxuser_use_ssh_chroot_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_sge_domain_can_network_connect" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the sge_domain_can_network_connect SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>sge_domain_can_network_connect</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>sge_domain_can_network_connect</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P sge_domain_can_network_connect off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_sge_domain_can_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_sge_domain_can_network_connect='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sge_domain_can_network_connect" use="legacy"/>'

    /usr/sbin/setsebool -P sge_domain_can_network_connect $var_sge_domain_can_network_connect

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_sge_domain_can_network_connect" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sge_domain_can_network_connect

- name: Disable the sge_domain_can_network_connect SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sge_domain_can_network_connect
- name: XCCDF Value var_sge_domain_can_network_connect # promote to variable
  set_fact:
    var_sge_domain_can_network_connect: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sge_domain_can_network_connect" use="legacy"/>
  tags:
    - always

- name: Disable the sge_domain_can_network_connect SELinux Boolean - Set SELinux Boolean
    sge_domain_can_network_connect Accordingly
  ansible.posix.seboolean:
    name: sge_domain_can_network_connect
    state: '{{ var_sge_domain_can_network_connect }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sge_domain_can_network_connect
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sge_domain_can_network_connect:var:1" value-id="xccdf_org.ssgproject.content_value_var_sge_domain_can_network_connect"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_sge_domain_can_network_connect:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_sge_domain_can_network_connect_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_sge_use_nfs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the sge_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>sge_use_nfs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>sge_use_nfs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P sge_use_nfs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_sge_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_sge_use_nfs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sge_use_nfs" use="legacy"/>'

    /usr/sbin/setsebool -P sge_use_nfs $var_sge_use_nfs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_sge_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sge_use_nfs

- name: Disable the sge_use_nfs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sge_use_nfs
- name: XCCDF Value var_sge_use_nfs # promote to variable
  set_fact:
    var_sge_use_nfs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sge_use_nfs" use="legacy"/>
  tags:
    - always

- name: Disable the sge_use_nfs SELinux Boolean - Set SELinux Boolean sge_use_nfs
    Accordingly
  ansible.posix.seboolean:
    name: sge_use_nfs
    state: '{{ var_sge_use_nfs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sge_use_nfs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sge_use_nfs:var:1" value-id="xccdf_org.ssgproject.content_value_var_sge_use_nfs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_sge_use_nfs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_sge_use_nfs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_smartmon_3ware" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the smartmon_3ware SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>smartmon_3ware</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>smartmon_3ware</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P smartmon_3ware off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_smartmon_3ware" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_smartmon_3ware='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_smartmon_3ware" use="legacy"/>'

    /usr/sbin/setsebool -P smartmon_3ware $var_smartmon_3ware

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_smartmon_3ware" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_smartmon_3ware

- name: Disable the smartmon_3ware SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_smartmon_3ware
- name: XCCDF Value var_smartmon_3ware # promote to variable
  set_fact:
    var_smartmon_3ware: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_smartmon_3ware" use="legacy"/>
  tags:
    - always

- name: Disable the smartmon_3ware SELinux Boolean - Set SELinux Boolean smartmon_3ware
    Accordingly
  ansible.posix.seboolean:
    name: smartmon_3ware
    state: '{{ var_smartmon_3ware }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_smartmon_3ware
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_smartmon_3ware:var:1" value-id="xccdf_org.ssgproject.content_value_var_smartmon_3ware"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_smartmon_3ware:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_smartmon_3ware_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_smbd_anon_write" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the smbd_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>smbd_anon_write</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>smbd_anon_write</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P smbd_anon_write off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_smbd_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_smbd_anon_write='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_smbd_anon_write" use="legacy"/>'

    /usr/sbin/setsebool -P smbd_anon_write $var_smbd_anon_write

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_smbd_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_smbd_anon_write

- name: Disable the smbd_anon_write SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_smbd_anon_write
- name: XCCDF Value var_smbd_anon_write # promote to variable
  set_fact:
    var_smbd_anon_write: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_smbd_anon_write" use="legacy"/>
  tags:
    - always

- name: Disable the smbd_anon_write SELinux Boolean - Set SELinux Boolean smbd_anon_write
    Accordingly
  ansible.posix.seboolean:
    name: smbd_anon_write
    state: '{{ var_smbd_anon_write }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_smbd_anon_write
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_smbd_anon_write:var:1" value-id="xccdf_org.ssgproject.content_value_var_smbd_anon_write"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_smbd_anon_write:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_smbd_anon_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_spamassassin_can_network" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the spamassassin_can_network SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>spamassassin_can_network</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>spamassassin_can_network</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P spamassassin_can_network off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_spamassassin_can_network" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_spamassassin_can_network='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_spamassassin_can_network" use="legacy"/>'

    /usr/sbin/setsebool -P spamassassin_can_network $var_spamassassin_can_network

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_spamassassin_can_network" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_spamassassin_can_network

- name: Disable the spamassassin_can_network SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_spamassassin_can_network
- name: XCCDF Value var_spamassassin_can_network # promote to variable
  set_fact:
    var_spamassassin_can_network: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_spamassassin_can_network" use="legacy"/>
  tags:
    - always

- name: Disable the spamassassin_can_network SELinux Boolean - Set SELinux Boolean
    spamassassin_can_network Accordingly
  ansible.posix.seboolean:
    name: spamassassin_can_network
    state: '{{ var_spamassassin_can_network }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_spamassassin_can_network
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_spamassassin_can_network:var:1" value-id="xccdf_org.ssgproject.content_value_var_spamassassin_can_network"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_spamassassin_can_network:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_spamassassin_can_network_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_spamd_enable_home_dirs" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the spamd_enable_home_dirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>spamd_enable_home_dirs</html:code> is enabled.
If this setting is disabled, it should be enabled.

To enable the <html:code>spamd_enable_home_dirs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P spamd_enable_home_dirs on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_spamd_enable_home_dirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_spamd_enable_home_dirs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_spamd_enable_home_dirs" use="legacy"/>'

    /usr/sbin/setsebool -P spamd_enable_home_dirs $var_spamd_enable_home_dirs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_spamd_enable_home_dirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_spamd_enable_home_dirs

- name: Enable the spamd_enable_home_dirs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_spamd_enable_home_dirs
- name: XCCDF Value var_spamd_enable_home_dirs # promote to variable
  set_fact:
    var_spamd_enable_home_dirs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_spamd_enable_home_dirs" use="legacy"/>
  tags:
    - always

- name: Enable the spamd_enable_home_dirs SELinux Boolean - Set SELinux Boolean spamd_enable_home_dirs
    Accordingly
  ansible.posix.seboolean:
    name: spamd_enable_home_dirs
    state: '{{ var_spamd_enable_home_dirs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_spamd_enable_home_dirs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_spamd_enable_home_dirs:var:1" value-id="xccdf_org.ssgproject.content_value_var_spamd_enable_home_dirs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_spamd_enable_home_dirs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_spamd_enable_home_dirs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_squid_connect_any" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the squid_connect_any SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>squid_connect_any</html:code> is enabled.
This setting should be disabled as squid should only connect on specified
ports.

To disable the <html:code>squid_connect_any</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P squid_connect_any off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_squid_connect_any" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_squid_connect_any='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_squid_connect_any" use="legacy"/>'

    /usr/sbin/setsebool -P squid_connect_any $var_squid_connect_any

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_squid_connect_any" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_squid_connect_any

- name: Disable the squid_connect_any SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_squid_connect_any
- name: XCCDF Value var_squid_connect_any # promote to variable
  set_fact:
    var_squid_connect_any: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_squid_connect_any" use="legacy"/>
  tags:
    - always

- name: Disable the squid_connect_any SELinux Boolean - Set SELinux Boolean squid_connect_any
    Accordingly
  ansible.posix.seboolean:
    name: squid_connect_any
    state: '{{ var_squid_connect_any }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_squid_connect_any
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_squid_connect_any:var:1" value-id="xccdf_org.ssgproject.content_value_var_squid_connect_any"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_squid_connect_any:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_squid_connect_any_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_squid_use_tproxy" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the squid_use_tproxy SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>squid_use_tproxy</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>squid_use_tproxy</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P squid_use_tproxy off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_squid_use_tproxy" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_squid_use_tproxy='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_squid_use_tproxy" use="legacy"/>'

    /usr/sbin/setsebool -P squid_use_tproxy $var_squid_use_tproxy

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_squid_use_tproxy" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_squid_use_tproxy

- name: Disable the squid_use_tproxy SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_squid_use_tproxy
- name: XCCDF Value var_squid_use_tproxy # promote to variable
  set_fact:
    var_squid_use_tproxy: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_squid_use_tproxy" use="legacy"/>
  tags:
    - always

- name: Disable the squid_use_tproxy SELinux Boolean - Set SELinux Boolean squid_use_tproxy
    Accordingly
  ansible.posix.seboolean:
    name: squid_use_tproxy
    state: '{{ var_squid_use_tproxy }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_squid_use_tproxy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_squid_use_tproxy:var:1" value-id="xccdf_org.ssgproject.content_value_var_squid_use_tproxy"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_squid_use_tproxy:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_squid_use_tproxy_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_ssh_chroot_rw_homedirs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the ssh_chroot_rw_homedirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>ssh_chroot_rw_homedirs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>ssh_chroot_rw_homedirs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P ssh_chroot_rw_homedirs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ssh_chroot_rw_homedirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_ssh_chroot_rw_homedirs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ssh_chroot_rw_homedirs" use="legacy"/>'

    /usr/sbin/setsebool -P ssh_chroot_rw_homedirs $var_ssh_chroot_rw_homedirs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ssh_chroot_rw_homedirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ssh_chroot_rw_homedirs

- name: Disable the ssh_chroot_rw_homedirs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ssh_chroot_rw_homedirs
- name: XCCDF Value var_ssh_chroot_rw_homedirs # promote to variable
  set_fact:
    var_ssh_chroot_rw_homedirs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ssh_chroot_rw_homedirs" use="legacy"/>
  tags:
    - always

- name: Disable the ssh_chroot_rw_homedirs SELinux Boolean - Set SELinux Boolean ssh_chroot_rw_homedirs
    Accordingly
  ansible.posix.seboolean:
    name: ssh_chroot_rw_homedirs
    state: '{{ var_ssh_chroot_rw_homedirs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ssh_chroot_rw_homedirs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_ssh_chroot_rw_homedirs:var:1" value-id="xccdf_org.ssgproject.content_value_var_ssh_chroot_rw_homedirs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_ssh_chroot_rw_homedirs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_ssh_chroot_rw_homedirs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_ssh_keysign" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the ssh_keysign SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>ssh_keysign</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>ssh_keysign</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P ssh_keysign off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ssh_keysign" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_ssh_keysign='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ssh_keysign" use="legacy"/>'

    /usr/sbin/setsebool -P ssh_keysign $var_ssh_keysign

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ssh_keysign" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ssh_keysign

- name: Disable the ssh_keysign SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ssh_keysign
- name: XCCDF Value var_ssh_keysign # promote to variable
  set_fact:
    var_ssh_keysign: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ssh_keysign" use="legacy"/>
  tags:
    - always

- name: Disable the ssh_keysign SELinux Boolean - Set SELinux Boolean ssh_keysign
    Accordingly
  ansible.posix.seboolean:
    name: ssh_keysign
    state: '{{ var_ssh_keysign }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ssh_keysign
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_ssh_keysign:var:1" value-id="xccdf_org.ssgproject.content_value_var_ssh_keysign"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_ssh_keysign:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_ssh_keysign_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_ssh_sysadm_login" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the ssh_sysadm_login SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>ssh_sysadm_login</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>ssh_sysadm_login</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P ssh_sysadm_login off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000324-GPOS-00125</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R48</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Preventing non-privileged users from executing privileged functions mitigates
the risk that unauthorized individuals or processes may gain unnecessary access
to information or privileges.

Privileged functions include, for example, establishing accounts, performing
system integrity checks, or administering cryptographic key management
activities. Non-privileged users are individuals who do not possess appropriate
authorizations. Circumventing intrusion detection and prevention mechanisms or
malicious code protection mechanisms are examples of privileged functions that
require protection from non-privileged users.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ssh_sysadm_login" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_ssh_sysadm_login='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ssh_sysadm_login" use="legacy"/>'

    /usr/sbin/setsebool -P ssh_sysadm_login $var_ssh_sysadm_login

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_ssh_sysadm_login" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ssh_sysadm_login

- name: Disable the ssh_sysadm_login SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ssh_sysadm_login
- name: XCCDF Value var_ssh_sysadm_login # promote to variable
  set_fact:
    var_ssh_sysadm_login: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ssh_sysadm_login" use="legacy"/>
  tags:
    - always

- name: Disable the ssh_sysadm_login SELinux Boolean - Set SELinux Boolean ssh_sysadm_login
    Accordingly
  ansible.posix.seboolean:
    name: ssh_sysadm_login
    state: '{{ var_ssh_sysadm_login }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_ssh_sysadm_login
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_ssh_sysadm_login:var:1" value-id="xccdf_org.ssgproject.content_value_var_ssh_sysadm_login"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_ssh_sysadm_login:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_ssh_sysadm_login_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_staff_exec_content" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the staff_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>staff_exec_content</html:code> is enabled.
If this setting is disabled, it should be enabled.

To enable the <html:code>staff_exec_content</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P staff_exec_content on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_staff_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_staff_exec_content='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_staff_exec_content" use="legacy"/>'

    /usr/sbin/setsebool -P staff_exec_content $var_staff_exec_content

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_staff_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_staff_exec_content

- name: Enable the staff_exec_content SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_staff_exec_content
- name: XCCDF Value var_staff_exec_content # promote to variable
  set_fact:
    var_staff_exec_content: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_staff_exec_content" use="legacy"/>
  tags:
    - always

- name: Enable the staff_exec_content SELinux Boolean - Set SELinux Boolean staff_exec_content
    Accordingly
  ansible.posix.seboolean:
    name: staff_exec_content
    state: '{{ var_staff_exec_content }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_staff_exec_content
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_staff_exec_content:var:1" value-id="xccdf_org.ssgproject.content_value_var_staff_exec_content"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_staff_exec_content:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_staff_exec_content_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_staff_use_svirt" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the staff_use_svirt SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>staff_use_svirt</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>staff_use_svirt</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P staff_use_svirt off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_staff_use_svirt" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_staff_use_svirt='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_staff_use_svirt" use="legacy"/>'

    /usr/sbin/setsebool -P staff_use_svirt $var_staff_use_svirt

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_staff_use_svirt" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_staff_use_svirt

- name: Disable the staff_use_svirt SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_staff_use_svirt
- name: XCCDF Value var_staff_use_svirt # promote to variable
  set_fact:
    var_staff_use_svirt: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_staff_use_svirt" use="legacy"/>
  tags:
    - always

- name: Disable the staff_use_svirt SELinux Boolean - Set SELinux Boolean staff_use_svirt
    Accordingly
  ansible.posix.seboolean:
    name: staff_use_svirt
    state: '{{ var_staff_use_svirt }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_staff_use_svirt
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_staff_use_svirt:var:1" value-id="xccdf_org.ssgproject.content_value_var_staff_use_svirt"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_staff_use_svirt:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_staff_use_svirt_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_swift_can_network" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the swift_can_network SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>swift_can_network</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>swift_can_network</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P swift_can_network off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_swift_can_network" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_swift_can_network='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_swift_can_network" use="legacy"/>'

    /usr/sbin/setsebool -P swift_can_network $var_swift_can_network

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_swift_can_network" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_swift_can_network

- name: Disable the swift_can_network SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_swift_can_network
- name: XCCDF Value var_swift_can_network # promote to variable
  set_fact:
    var_swift_can_network: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_swift_can_network" use="legacy"/>
  tags:
    - always

- name: Disable the swift_can_network SELinux Boolean - Set SELinux Boolean swift_can_network
    Accordingly
  ansible.posix.seboolean:
    name: swift_can_network
    state: '{{ var_swift_can_network }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_swift_can_network
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_swift_can_network:var:1" value-id="xccdf_org.ssgproject.content_value_var_swift_can_network"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_swift_can_network:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_swift_can_network_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_sysadm_exec_content" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the sysadm_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>sysadm_exec_content</html:code> is enabled.
If this setting is disabled, it should be enabled.

To enable the <html:code>sysadm_exec_content</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P sysadm_exec_content on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_sysadm_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_sysadm_exec_content='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sysadm_exec_content" use="legacy"/>'

    /usr/sbin/setsebool -P sysadm_exec_content $var_sysadm_exec_content

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_sysadm_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sysadm_exec_content

- name: Enable the sysadm_exec_content SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sysadm_exec_content
- name: XCCDF Value var_sysadm_exec_content # promote to variable
  set_fact:
    var_sysadm_exec_content: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sysadm_exec_content" use="legacy"/>
  tags:
    - always

- name: Enable the sysadm_exec_content SELinux Boolean - Set SELinux Boolean sysadm_exec_content
    Accordingly
  ansible.posix.seboolean:
    name: sysadm_exec_content
    state: '{{ var_sysadm_exec_content }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_sysadm_exec_content
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sysadm_exec_content:var:1" value-id="xccdf_org.ssgproject.content_value_var_sysadm_exec_content"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_sysadm_exec_content:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_sysadm_exec_content_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_telepathy_connect_all_ports" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the telepathy_connect_all_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>telepathy_connect_all_ports</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>telepathy_connect_all_ports</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P telepathy_connect_all_ports off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_telepathy_connect_all_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_telepathy_connect_all_ports='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_telepathy_connect_all_ports" use="legacy"/>'

    /usr/sbin/setsebool -P telepathy_connect_all_ports $var_telepathy_connect_all_ports

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_telepathy_connect_all_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_telepathy_connect_all_ports

- name: Disable the telepathy_connect_all_ports SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_telepathy_connect_all_ports
- name: XCCDF Value var_telepathy_connect_all_ports # promote to variable
  set_fact:
    var_telepathy_connect_all_ports: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_telepathy_connect_all_ports" use="legacy"/>
  tags:
    - always

- name: Disable the telepathy_connect_all_ports SELinux Boolean - Set SELinux Boolean
    telepathy_connect_all_ports Accordingly
  ansible.posix.seboolean:
    name: telepathy_connect_all_ports
    state: '{{ var_telepathy_connect_all_ports }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_telepathy_connect_all_ports
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_telepathy_connect_all_ports:var:1" value-id="xccdf_org.ssgproject.content_value_var_telepathy_connect_all_ports"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_telepathy_connect_all_ports:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_telepathy_connect_all_ports_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_telepathy_tcp_connect_generic_network_ports" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the telepathy_tcp_connect_generic_network_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>telepathy_tcp_connect_generic_network_ports</html:code> is enabled.
This setting should be disabled as <html:code>telepathy</html:code> should not connect to any generic network
ports.

To disable the <html:code>telepathy_tcp_connect_generic_network_ports</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P telepathy_tcp_connect_generic_network_ports off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_telepathy_tcp_connect_generic_network_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_telepathy_tcp_connect_generic_network_ports='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_telepathy_tcp_connect_generic_network_ports" use="legacy"/>'

    /usr/sbin/setsebool -P telepathy_tcp_connect_generic_network_ports $var_telepathy_tcp_connect_generic_network_ports

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_telepathy_tcp_connect_generic_network_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_telepathy_tcp_connect_generic_network_ports

- name: Disable the telepathy_tcp_connect_generic_network_ports SELinux Boolean -
    Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_telepathy_tcp_connect_generic_network_ports
- name: XCCDF Value var_telepathy_tcp_connect_generic_network_ports # promote to variable
  set_fact:
    var_telepathy_tcp_connect_generic_network_ports: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_telepathy_tcp_connect_generic_network_ports" use="legacy"/>
  tags:
    - always

- name: Disable the telepathy_tcp_connect_generic_network_ports SELinux Boolean -
    Set SELinux Boolean telepathy_tcp_connect_generic_network_ports Accordingly
  ansible.posix.seboolean:
    name: telepathy_tcp_connect_generic_network_ports
    state: '{{ var_telepathy_tcp_connect_generic_network_ports }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_telepathy_tcp_connect_generic_network_ports
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_telepathy_tcp_connect_generic_network_ports:var:1" value-id="xccdf_org.ssgproject.content_value_var_telepathy_tcp_connect_generic_network_ports"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_telepathy_tcp_connect_generic_network_ports:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_telepathy_tcp_connect_generic_network_ports_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_tftp_anon_write" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the tftp_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>tftp_anon_write</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>tftp_anon_write</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P tftp_anon_write off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_tftp_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_tftp_anon_write='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tftp_anon_write" use="legacy"/>'

    /usr/sbin/setsebool -P tftp_anon_write $var_tftp_anon_write

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_tftp_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tftp_anon_write

- name: Disable the tftp_anon_write SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tftp_anon_write
- name: XCCDF Value var_tftp_anon_write # promote to variable
  set_fact:
    var_tftp_anon_write: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tftp_anon_write" use="legacy"/>
  tags:
    - always

- name: Disable the tftp_anon_write SELinux Boolean - Set SELinux Boolean tftp_anon_write
    Accordingly
  ansible.posix.seboolean:
    name: tftp_anon_write
    state: '{{ var_tftp_anon_write }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tftp_anon_write
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_tftp_anon_write:var:1" value-id="xccdf_org.ssgproject.content_value_var_tftp_anon_write"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_tftp_anon_write:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_tftp_anon_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_tftp_home_dir" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the tftp_home_dir SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>tftp_home_dir</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>tftp_home_dir</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P tftp_home_dir off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_tftp_home_dir" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_tftp_home_dir='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tftp_home_dir" use="legacy"/>'

    /usr/sbin/setsebool -P tftp_home_dir $var_tftp_home_dir

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_tftp_home_dir" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tftp_home_dir

- name: Disable the tftp_home_dir SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tftp_home_dir
- name: XCCDF Value var_tftp_home_dir # promote to variable
  set_fact:
    var_tftp_home_dir: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tftp_home_dir" use="legacy"/>
  tags:
    - always

- name: Disable the tftp_home_dir SELinux Boolean - Set SELinux Boolean tftp_home_dir
    Accordingly
  ansible.posix.seboolean:
    name: tftp_home_dir
    state: '{{ var_tftp_home_dir }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tftp_home_dir
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_tftp_home_dir:var:1" value-id="xccdf_org.ssgproject.content_value_var_tftp_home_dir"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_tftp_home_dir:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_tftp_home_dir_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_tmpreaper_use_nfs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the tmpreaper_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>tmpreaper_use_nfs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>tmpreaper_use_nfs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P tmpreaper_use_nfs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_tmpreaper_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_tmpreaper_use_nfs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tmpreaper_use_nfs" use="legacy"/>'

    /usr/sbin/setsebool -P tmpreaper_use_nfs $var_tmpreaper_use_nfs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_tmpreaper_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tmpreaper_use_nfs

- name: Disable the tmpreaper_use_nfs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tmpreaper_use_nfs
- name: XCCDF Value var_tmpreaper_use_nfs # promote to variable
  set_fact:
    var_tmpreaper_use_nfs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tmpreaper_use_nfs" use="legacy"/>
  tags:
    - always

- name: Disable the tmpreaper_use_nfs SELinux Boolean - Set SELinux Boolean tmpreaper_use_nfs
    Accordingly
  ansible.posix.seboolean:
    name: tmpreaper_use_nfs
    state: '{{ var_tmpreaper_use_nfs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tmpreaper_use_nfs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_tmpreaper_use_nfs:var:1" value-id="xccdf_org.ssgproject.content_value_var_tmpreaper_use_nfs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_tmpreaper_use_nfs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_tmpreaper_use_nfs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_tmpreaper_use_samba" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the tmpreaper_use_samba SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>tmpreaper_use_samba</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>tmpreaper_use_samba</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P tmpreaper_use_samba off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_tmpreaper_use_samba" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_tmpreaper_use_samba='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tmpreaper_use_samba" use="legacy"/>'

    /usr/sbin/setsebool -P tmpreaper_use_samba $var_tmpreaper_use_samba

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_tmpreaper_use_samba" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tmpreaper_use_samba

- name: Disable the tmpreaper_use_samba SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tmpreaper_use_samba
- name: XCCDF Value var_tmpreaper_use_samba # promote to variable
  set_fact:
    var_tmpreaper_use_samba: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tmpreaper_use_samba" use="legacy"/>
  tags:
    - always

- name: Disable the tmpreaper_use_samba SELinux Boolean - Set SELinux Boolean tmpreaper_use_samba
    Accordingly
  ansible.posix.seboolean:
    name: tmpreaper_use_samba
    state: '{{ var_tmpreaper_use_samba }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tmpreaper_use_samba
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_tmpreaper_use_samba:var:1" value-id="xccdf_org.ssgproject.content_value_var_tmpreaper_use_samba"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_tmpreaper_use_samba:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_tmpreaper_use_samba_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_tor_bind_all_unreserved_ports" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the tor_bind_all_unreserved_ports SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>tor_bind_all_unreserved_ports</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>tor_bind_all_unreserved_ports</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P tor_bind_all_unreserved_ports off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_tor_bind_all_unreserved_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_tor_bind_all_unreserved_ports='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tor_bind_all_unreserved_ports" use="legacy"/>'

    /usr/sbin/setsebool -P tor_bind_all_unreserved_ports $var_tor_bind_all_unreserved_ports

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_tor_bind_all_unreserved_ports" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tor_bind_all_unreserved_ports

- name: Disable the tor_bind_all_unreserved_ports SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tor_bind_all_unreserved_ports
- name: XCCDF Value var_tor_bind_all_unreserved_ports # promote to variable
  set_fact:
    var_tor_bind_all_unreserved_ports: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tor_bind_all_unreserved_ports" use="legacy"/>
  tags:
    - always

- name: Disable the tor_bind_all_unreserved_ports SELinux Boolean - Set SELinux Boolean
    tor_bind_all_unreserved_ports Accordingly
  ansible.posix.seboolean:
    name: tor_bind_all_unreserved_ports
    state: '{{ var_tor_bind_all_unreserved_ports }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tor_bind_all_unreserved_ports
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_tor_bind_all_unreserved_ports:var:1" value-id="xccdf_org.ssgproject.content_value_var_tor_bind_all_unreserved_ports"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_tor_bind_all_unreserved_ports:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_tor_bind_all_unreserved_ports_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_tor_can_network_relay" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the tor_can_network_relay SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>tor_can_network_relay</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>tor_can_network_relay</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P tor_can_network_relay off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_tor_can_network_relay" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_tor_can_network_relay='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tor_can_network_relay" use="legacy"/>'

    /usr/sbin/setsebool -P tor_can_network_relay $var_tor_can_network_relay

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_tor_can_network_relay" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tor_can_network_relay

- name: Disable the tor_can_network_relay SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tor_can_network_relay
- name: XCCDF Value var_tor_can_network_relay # promote to variable
  set_fact:
    var_tor_can_network_relay: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tor_can_network_relay" use="legacy"/>
  tags:
    - always

- name: Disable the tor_can_network_relay SELinux Boolean - Set SELinux Boolean tor_can_network_relay
    Accordingly
  ansible.posix.seboolean:
    name: tor_can_network_relay
    state: '{{ var_tor_can_network_relay }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_tor_can_network_relay
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_tor_can_network_relay:var:1" value-id="xccdf_org.ssgproject.content_value_var_tor_can_network_relay"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_tor_can_network_relay:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_tor_can_network_relay_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_unconfined_chrome_sandbox_transition" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the unconfined_chrome_sandbox_transition SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>unconfined_chrome_sandbox_transition</html:code> is enabled.
If this setting is disabled, it should be enabled.

To enable the <html:code>unconfined_chrome_sandbox_transition</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P unconfined_chrome_sandbox_transition on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_unconfined_chrome_sandbox_transition" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_unconfined_chrome_sandbox_transition='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_unconfined_chrome_sandbox_transition" use="legacy"/>'

    /usr/sbin/setsebool -P unconfined_chrome_sandbox_transition $var_unconfined_chrome_sandbox_transition

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_unconfined_chrome_sandbox_transition" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_unconfined_chrome_sandbox_transition

- name: Enable the unconfined_chrome_sandbox_transition SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_unconfined_chrome_sandbox_transition
- name: XCCDF Value var_unconfined_chrome_sandbox_transition # promote to variable
  set_fact:
    var_unconfined_chrome_sandbox_transition: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_unconfined_chrome_sandbox_transition" use="legacy"/>
  tags:
    - always

- name: Enable the unconfined_chrome_sandbox_transition SELinux Boolean - Set SELinux
    Boolean unconfined_chrome_sandbox_transition Accordingly
  ansible.posix.seboolean:
    name: unconfined_chrome_sandbox_transition
    state: '{{ var_unconfined_chrome_sandbox_transition }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_unconfined_chrome_sandbox_transition
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_unconfined_chrome_sandbox_transition:var:1" value-id="xccdf_org.ssgproject.content_value_var_unconfined_chrome_sandbox_transition"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_unconfined_chrome_sandbox_transition:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_unconfined_chrome_sandbox_transition_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_unconfined_login" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the unconfined_login SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>unconfined_login</html:code> is enabled.
If this setting is disabled, it should be enabled.

To enable the <html:code>unconfined_login</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P unconfined_login on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_unconfined_login" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_unconfined_login='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_unconfined_login" use="legacy"/>'

    /usr/sbin/setsebool -P unconfined_login $var_unconfined_login

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_unconfined_login" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_unconfined_login

- name: Enable the unconfined_login SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_unconfined_login
- name: XCCDF Value var_unconfined_login # promote to variable
  set_fact:
    var_unconfined_login: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_unconfined_login" use="legacy"/>
  tags:
    - always

- name: Enable the unconfined_login SELinux Boolean - Set SELinux Boolean unconfined_login
    Accordingly
  ansible.posix.seboolean:
    name: unconfined_login
    state: '{{ var_unconfined_login }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_unconfined_login
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_unconfined_login:var:1" value-id="xccdf_org.ssgproject.content_value_var_unconfined_login"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_unconfined_login:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_unconfined_login_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_unconfined_mozilla_plugin_transition" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the unconfined_mozilla_plugin_transition SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>unconfined_mozilla_plugin_transition</html:code> is enabled.
If this setting is disabled, it should be enabled.

To enable the <html:code>unconfined_mozilla_plugin_transition</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P unconfined_mozilla_plugin_transition on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_unconfined_mozilla_plugin_transition" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_unconfined_mozilla_plugin_transition='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_unconfined_mozilla_plugin_transition" use="legacy"/>'

    /usr/sbin/setsebool -P unconfined_mozilla_plugin_transition $var_unconfined_mozilla_plugin_transition

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_unconfined_mozilla_plugin_transition" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_unconfined_mozilla_plugin_transition

- name: Enable the unconfined_mozilla_plugin_transition SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_unconfined_mozilla_plugin_transition
- name: XCCDF Value var_unconfined_mozilla_plugin_transition # promote to variable
  set_fact:
    var_unconfined_mozilla_plugin_transition: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_unconfined_mozilla_plugin_transition" use="legacy"/>
  tags:
    - always

- name: Enable the unconfined_mozilla_plugin_transition SELinux Boolean - Set SELinux
    Boolean unconfined_mozilla_plugin_transition Accordingly
  ansible.posix.seboolean:
    name: unconfined_mozilla_plugin_transition
    state: '{{ var_unconfined_mozilla_plugin_transition }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_unconfined_mozilla_plugin_transition
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_unconfined_mozilla_plugin_transition:var:1" value-id="xccdf_org.ssgproject.content_value_var_unconfined_mozilla_plugin_transition"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_unconfined_mozilla_plugin_transition:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_unconfined_mozilla_plugin_transition_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_unprivuser_use_svirt" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the unprivuser_use_svirt SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>unprivuser_use_svirt</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>unprivuser_use_svirt</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P unprivuser_use_svirt off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_unprivuser_use_svirt" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_unprivuser_use_svirt='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_unprivuser_use_svirt" use="legacy"/>'

    /usr/sbin/setsebool -P unprivuser_use_svirt $var_unprivuser_use_svirt

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_unprivuser_use_svirt" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_unprivuser_use_svirt

- name: Disable the unprivuser_use_svirt SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_unprivuser_use_svirt
- name: XCCDF Value var_unprivuser_use_svirt # promote to variable
  set_fact:
    var_unprivuser_use_svirt: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_unprivuser_use_svirt" use="legacy"/>
  tags:
    - always

- name: Disable the unprivuser_use_svirt SELinux Boolean - Set SELinux Boolean unprivuser_use_svirt
    Accordingly
  ansible.posix.seboolean:
    name: unprivuser_use_svirt
    state: '{{ var_unprivuser_use_svirt }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_unprivuser_use_svirt
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_unprivuser_use_svirt:var:1" value-id="xccdf_org.ssgproject.content_value_var_unprivuser_use_svirt"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_unprivuser_use_svirt:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_unprivuser_use_svirt_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_use_ecryptfs_home_dirs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the use_ecryptfs_home_dirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>use_ecryptfs_home_dirs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>use_ecryptfs_home_dirs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P use_ecryptfs_home_dirs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_use_ecryptfs_home_dirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_use_ecryptfs_home_dirs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_use_ecryptfs_home_dirs" use="legacy"/>'

    /usr/sbin/setsebool -P use_ecryptfs_home_dirs $var_use_ecryptfs_home_dirs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_use_ecryptfs_home_dirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_use_ecryptfs_home_dirs

- name: Disable the use_ecryptfs_home_dirs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_use_ecryptfs_home_dirs
- name: XCCDF Value var_use_ecryptfs_home_dirs # promote to variable
  set_fact:
    var_use_ecryptfs_home_dirs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_use_ecryptfs_home_dirs" use="legacy"/>
  tags:
    - always

- name: Disable the use_ecryptfs_home_dirs SELinux Boolean - Set SELinux Boolean use_ecryptfs_home_dirs
    Accordingly
  ansible.posix.seboolean:
    name: use_ecryptfs_home_dirs
    state: '{{ var_use_ecryptfs_home_dirs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_use_ecryptfs_home_dirs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_use_ecryptfs_home_dirs:var:1" value-id="xccdf_org.ssgproject.content_value_var_use_ecryptfs_home_dirs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_use_ecryptfs_home_dirs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_use_ecryptfs_home_dirs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_use_fusefs_home_dirs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the use_fusefs_home_dirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>use_fusefs_home_dirs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>use_fusefs_home_dirs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P use_fusefs_home_dirs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_use_fusefs_home_dirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_use_fusefs_home_dirs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_use_fusefs_home_dirs" use="legacy"/>'

    /usr/sbin/setsebool -P use_fusefs_home_dirs $var_use_fusefs_home_dirs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_use_fusefs_home_dirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_use_fusefs_home_dirs

- name: Disable the use_fusefs_home_dirs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_use_fusefs_home_dirs
- name: XCCDF Value var_use_fusefs_home_dirs # promote to variable
  set_fact:
    var_use_fusefs_home_dirs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_use_fusefs_home_dirs" use="legacy"/>
  tags:
    - always

- name: Disable the use_fusefs_home_dirs SELinux Boolean - Set SELinux Boolean use_fusefs_home_dirs
    Accordingly
  ansible.posix.seboolean:
    name: use_fusefs_home_dirs
    state: '{{ var_use_fusefs_home_dirs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_use_fusefs_home_dirs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_use_fusefs_home_dirs:var:1" value-id="xccdf_org.ssgproject.content_value_var_use_fusefs_home_dirs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_use_fusefs_home_dirs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_use_fusefs_home_dirs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_use_lpd_server" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the use_lpd_server SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>use_lpd_server</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>use_lpd_server</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P use_lpd_server off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_use_lpd_server" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_use_lpd_server='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_use_lpd_server" use="legacy"/>'

    /usr/sbin/setsebool -P use_lpd_server $var_use_lpd_server

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_use_lpd_server" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_use_lpd_server

- name: Disable the use_lpd_server SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_use_lpd_server
- name: XCCDF Value var_use_lpd_server # promote to variable
  set_fact:
    var_use_lpd_server: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_use_lpd_server" use="legacy"/>
  tags:
    - always

- name: Disable the use_lpd_server SELinux Boolean - Set SELinux Boolean use_lpd_server
    Accordingly
  ansible.posix.seboolean:
    name: use_lpd_server
    state: '{{ var_use_lpd_server }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_use_lpd_server
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_use_lpd_server:var:1" value-id="xccdf_org.ssgproject.content_value_var_use_lpd_server"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_use_lpd_server:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_use_lpd_server_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_use_nfs_home_dirs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the use_nfs_home_dirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>use_nfs_home_dirs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>use_nfs_home_dirs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P use_nfs_home_dirs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_use_nfs_home_dirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_use_nfs_home_dirs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_use_nfs_home_dirs" use="legacy"/>'

    /usr/sbin/setsebool -P use_nfs_home_dirs $var_use_nfs_home_dirs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_use_nfs_home_dirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_use_nfs_home_dirs

- name: Disable the use_nfs_home_dirs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_use_nfs_home_dirs
- name: XCCDF Value var_use_nfs_home_dirs # promote to variable
  set_fact:
    var_use_nfs_home_dirs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_use_nfs_home_dirs" use="legacy"/>
  tags:
    - always

- name: Disable the use_nfs_home_dirs SELinux Boolean - Set SELinux Boolean use_nfs_home_dirs
    Accordingly
  ansible.posix.seboolean:
    name: use_nfs_home_dirs
    state: '{{ var_use_nfs_home_dirs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_use_nfs_home_dirs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_use_nfs_home_dirs:var:1" value-id="xccdf_org.ssgproject.content_value_var_use_nfs_home_dirs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_use_nfs_home_dirs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_use_nfs_home_dirs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_use_samba_home_dirs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the use_samba_home_dirs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>use_samba_home_dirs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>use_samba_home_dirs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P use_samba_home_dirs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_use_samba_home_dirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_use_samba_home_dirs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_use_samba_home_dirs" use="legacy"/>'

    /usr/sbin/setsebool -P use_samba_home_dirs $var_use_samba_home_dirs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_use_samba_home_dirs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_use_samba_home_dirs

- name: Disable the use_samba_home_dirs SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_use_samba_home_dirs
- name: XCCDF Value var_use_samba_home_dirs # promote to variable
  set_fact:
    var_use_samba_home_dirs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_use_samba_home_dirs" use="legacy"/>
  tags:
    - always

- name: Disable the use_samba_home_dirs SELinux Boolean - Set SELinux Boolean use_samba_home_dirs
    Accordingly
  ansible.posix.seboolean:
    name: use_samba_home_dirs
    state: '{{ var_use_samba_home_dirs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_use_samba_home_dirs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_use_samba_home_dirs:var:1" value-id="xccdf_org.ssgproject.content_value_var_use_samba_home_dirs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_use_samba_home_dirs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_use_samba_home_dirs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_user_exec_content" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the user_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>user_exec_content</html:code> is enabled.
If this setting is disabled, it should be enabled.

To enable the <html:code>user_exec_content</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P user_exec_content on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_user_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_user_exec_content='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_user_exec_content" use="legacy"/>'

    /usr/sbin/setsebool -P user_exec_content $var_user_exec_content

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_user_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_user_exec_content

- name: Enable the user_exec_content SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_user_exec_content
- name: XCCDF Value var_user_exec_content # promote to variable
  set_fact:
    var_user_exec_content: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_user_exec_content" use="legacy"/>
  tags:
    - always

- name: Enable the user_exec_content SELinux Boolean - Set SELinux Boolean user_exec_content
    Accordingly
  ansible.posix.seboolean:
    name: user_exec_content
    state: '{{ var_user_exec_content }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_user_exec_content
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_user_exec_content:var:1" value-id="xccdf_org.ssgproject.content_value_var_user_exec_content"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_user_exec_content:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_user_exec_content_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_varnishd_connect_any" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the varnishd_connect_any SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>varnishd_connect_any</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>varnishd_connect_any</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P varnishd_connect_any off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_varnishd_connect_any" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_varnishd_connect_any='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_varnishd_connect_any" use="legacy"/>'

    /usr/sbin/setsebool -P varnishd_connect_any $var_varnishd_connect_any

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_varnishd_connect_any" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_varnishd_connect_any

- name: Disable the varnishd_connect_any SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_varnishd_connect_any
- name: XCCDF Value var_varnishd_connect_any # promote to variable
  set_fact:
    var_varnishd_connect_any: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_varnishd_connect_any" use="legacy"/>
  tags:
    - always

- name: Disable the varnishd_connect_any SELinux Boolean - Set SELinux Boolean varnishd_connect_any
    Accordingly
  ansible.posix.seboolean:
    name: varnishd_connect_any
    state: '{{ var_varnishd_connect_any }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_varnishd_connect_any
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_varnishd_connect_any:var:1" value-id="xccdf_org.ssgproject.content_value_var_varnishd_connect_any"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_varnishd_connect_any:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_varnishd_connect_any_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_virt_read_qemu_ga_data" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the virt_read_qemu_ga_data SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>virt_read_qemu_ga_data</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>virt_read_qemu_ga_data</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P virt_read_qemu_ga_data off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_read_qemu_ga_data" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_virt_read_qemu_ga_data='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_read_qemu_ga_data" use="legacy"/>'

    /usr/sbin/setsebool -P virt_read_qemu_ga_data $var_virt_read_qemu_ga_data

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_read_qemu_ga_data" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_read_qemu_ga_data

- name: Disable the virt_read_qemu_ga_data SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_read_qemu_ga_data
- name: XCCDF Value var_virt_read_qemu_ga_data # promote to variable
  set_fact:
    var_virt_read_qemu_ga_data: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_read_qemu_ga_data" use="legacy"/>
  tags:
    - always

- name: Disable the virt_read_qemu_ga_data SELinux Boolean - Set SELinux Boolean virt_read_qemu_ga_data
    Accordingly
  ansible.posix.seboolean:
    name: virt_read_qemu_ga_data
    state: '{{ var_virt_read_qemu_ga_data }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_read_qemu_ga_data
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_virt_read_qemu_ga_data:var:1" value-id="xccdf_org.ssgproject.content_value_var_virt_read_qemu_ga_data"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_virt_read_qemu_ga_data:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_virt_read_qemu_ga_data_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_virt_rw_qemu_ga_data" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the virt_rw_qemu_ga_data SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>virt_rw_qemu_ga_data</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>virt_rw_qemu_ga_data</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P virt_rw_qemu_ga_data off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_rw_qemu_ga_data" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_virt_rw_qemu_ga_data='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_rw_qemu_ga_data" use="legacy"/>'

    /usr/sbin/setsebool -P virt_rw_qemu_ga_data $var_virt_rw_qemu_ga_data

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_rw_qemu_ga_data" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_rw_qemu_ga_data

- name: Disable the virt_rw_qemu_ga_data SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_rw_qemu_ga_data
- name: XCCDF Value var_virt_rw_qemu_ga_data # promote to variable
  set_fact:
    var_virt_rw_qemu_ga_data: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_rw_qemu_ga_data" use="legacy"/>
  tags:
    - always

- name: Disable the virt_rw_qemu_ga_data SELinux Boolean - Set SELinux Boolean virt_rw_qemu_ga_data
    Accordingly
  ansible.posix.seboolean:
    name: virt_rw_qemu_ga_data
    state: '{{ var_virt_rw_qemu_ga_data }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_rw_qemu_ga_data
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_virt_rw_qemu_ga_data:var:1" value-id="xccdf_org.ssgproject.content_value_var_virt_rw_qemu_ga_data"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_virt_rw_qemu_ga_data:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_virt_rw_qemu_ga_data_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_virt_sandbox_use_all_caps" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the virt_sandbox_use_all_caps SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>virt_sandbox_use_all_caps</html:code> is enabled.
This setting is disabled as containers should not run with privileges.

To disable the <html:code>virt_sandbox_use_all_caps</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P virt_sandbox_use_all_caps off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_sandbox_use_all_caps" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_virt_sandbox_use_all_caps='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_all_caps" use="legacy"/>'

    /usr/sbin/setsebool -P virt_sandbox_use_all_caps $var_virt_sandbox_use_all_caps

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_sandbox_use_all_caps" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_sandbox_use_all_caps

- name: Disable the virt_sandbox_use_all_caps SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_sandbox_use_all_caps
- name: XCCDF Value var_virt_sandbox_use_all_caps # promote to variable
  set_fact:
    var_virt_sandbox_use_all_caps: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_all_caps" use="legacy"/>
  tags:
    - always

- name: Disable the virt_sandbox_use_all_caps SELinux Boolean - Set SELinux Boolean
    virt_sandbox_use_all_caps Accordingly
  ansible.posix.seboolean:
    name: virt_sandbox_use_all_caps
    state: '{{ var_virt_sandbox_use_all_caps }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_sandbox_use_all_caps
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_virt_sandbox_use_all_caps:var:1" value-id="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_all_caps"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_virt_sandbox_use_all_caps:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_virt_sandbox_use_all_caps_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_virt_sandbox_use_audit" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the virt_sandbox_use_audit SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>virt_sandbox_use_audit</html:code> is enabled.
If this setting is disabled, it should be enabled to allow sandboxed containers
to send audit messages.

To enable the <html:code>virt_sandbox_use_audit</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P virt_sandbox_use_audit on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_sandbox_use_audit" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_virt_sandbox_use_audit='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_audit" use="legacy"/>'

    /usr/sbin/setsebool -P virt_sandbox_use_audit $var_virt_sandbox_use_audit

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_sandbox_use_audit" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_sandbox_use_audit

- name: Enable the virt_sandbox_use_audit SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_sandbox_use_audit
- name: XCCDF Value var_virt_sandbox_use_audit # promote to variable
  set_fact:
    var_virt_sandbox_use_audit: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_audit" use="legacy"/>
  tags:
    - always

- name: Enable the virt_sandbox_use_audit SELinux Boolean - Set SELinux Boolean virt_sandbox_use_audit
    Accordingly
  ansible.posix.seboolean:
    name: virt_sandbox_use_audit
    state: '{{ var_virt_sandbox_use_audit }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_sandbox_use_audit
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_virt_sandbox_use_audit:var:1" value-id="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_audit"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_virt_sandbox_use_audit:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_virt_sandbox_use_audit_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_virt_sandbox_use_mknod" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the virt_sandbox_use_mknod SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>virt_sandbox_use_mknod</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>virt_sandbox_use_mknod</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P virt_sandbox_use_mknod off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_sandbox_use_mknod" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_virt_sandbox_use_mknod='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_mknod" use="legacy"/>'

    /usr/sbin/setsebool -P virt_sandbox_use_mknod $var_virt_sandbox_use_mknod

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_sandbox_use_mknod" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_sandbox_use_mknod

- name: Disable the virt_sandbox_use_mknod SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_sandbox_use_mknod
- name: XCCDF Value var_virt_sandbox_use_mknod # promote to variable
  set_fact:
    var_virt_sandbox_use_mknod: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_mknod" use="legacy"/>
  tags:
    - always

- name: Disable the virt_sandbox_use_mknod SELinux Boolean - Set SELinux Boolean virt_sandbox_use_mknod
    Accordingly
  ansible.posix.seboolean:
    name: virt_sandbox_use_mknod
    state: '{{ var_virt_sandbox_use_mknod }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_sandbox_use_mknod
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_virt_sandbox_use_mknod:var:1" value-id="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_mknod"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_virt_sandbox_use_mknod:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_virt_sandbox_use_mknod_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_virt_sandbox_use_netlink" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the virt_sandbox_use_netlink SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>virt_sandbox_use_netlink</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>virt_sandbox_use_netlink</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P virt_sandbox_use_netlink off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_sandbox_use_netlink" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_virt_sandbox_use_netlink='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_netlink" use="legacy"/>'

    /usr/sbin/setsebool -P virt_sandbox_use_netlink $var_virt_sandbox_use_netlink

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_sandbox_use_netlink" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_sandbox_use_netlink

- name: Disable the virt_sandbox_use_netlink SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_sandbox_use_netlink
- name: XCCDF Value var_virt_sandbox_use_netlink # promote to variable
  set_fact:
    var_virt_sandbox_use_netlink: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_netlink" use="legacy"/>
  tags:
    - always

- name: Disable the virt_sandbox_use_netlink SELinux Boolean - Set SELinux Boolean
    virt_sandbox_use_netlink Accordingly
  ansible.posix.seboolean:
    name: virt_sandbox_use_netlink
    state: '{{ var_virt_sandbox_use_netlink }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_sandbox_use_netlink
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_virt_sandbox_use_netlink:var:1" value-id="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_netlink"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_virt_sandbox_use_netlink:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_virt_sandbox_use_netlink_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_virt_sandbox_use_sys_admin" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the virt_sandbox_use_sys_admin SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>virt_sandbox_use_sys_admin</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>virt_sandbox_use_sys_admin</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P virt_sandbox_use_sys_admin off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_sandbox_use_sys_admin" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_virt_sandbox_use_sys_admin='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_sys_admin" use="legacy"/>'

    /usr/sbin/setsebool -P virt_sandbox_use_sys_admin $var_virt_sandbox_use_sys_admin

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_sandbox_use_sys_admin" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_sandbox_use_sys_admin

- name: Disable the virt_sandbox_use_sys_admin SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_sandbox_use_sys_admin
- name: XCCDF Value var_virt_sandbox_use_sys_admin # promote to variable
  set_fact:
    var_virt_sandbox_use_sys_admin: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_sys_admin" use="legacy"/>
  tags:
    - always

- name: Disable the virt_sandbox_use_sys_admin SELinux Boolean - Set SELinux Boolean
    virt_sandbox_use_sys_admin Accordingly
  ansible.posix.seboolean:
    name: virt_sandbox_use_sys_admin
    state: '{{ var_virt_sandbox_use_sys_admin }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_sandbox_use_sys_admin
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_virt_sandbox_use_sys_admin:var:1" value-id="xccdf_org.ssgproject.content_value_var_virt_sandbox_use_sys_admin"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_virt_sandbox_use_sys_admin:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_virt_sandbox_use_sys_admin_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_virt_transition_userdomain" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the virt_transition_userdomain SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>virt_transition_userdomain</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>virt_transition_userdomain</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P virt_transition_userdomain off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_transition_userdomain" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_virt_transition_userdomain='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_transition_userdomain" use="legacy"/>'

    /usr/sbin/setsebool -P virt_transition_userdomain $var_virt_transition_userdomain

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_transition_userdomain" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_transition_userdomain

- name: Disable the virt_transition_userdomain SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_transition_userdomain
- name: XCCDF Value var_virt_transition_userdomain # promote to variable
  set_fact:
    var_virt_transition_userdomain: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_transition_userdomain" use="legacy"/>
  tags:
    - always

- name: Disable the virt_transition_userdomain SELinux Boolean - Set SELinux Boolean
    virt_transition_userdomain Accordingly
  ansible.posix.seboolean:
    name: virt_transition_userdomain
    state: '{{ var_virt_transition_userdomain }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_transition_userdomain
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_virt_transition_userdomain:var:1" value-id="xccdf_org.ssgproject.content_value_var_virt_transition_userdomain"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_virt_transition_userdomain:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_virt_transition_userdomain_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_virt_use_comm" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the virt_use_comm SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>virt_use_comm</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>virt_use_comm</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P virt_use_comm off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_comm" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_virt_use_comm='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_comm" use="legacy"/>'

    /usr/sbin/setsebool -P virt_use_comm $var_virt_use_comm

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_comm" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_comm

- name: Disable the virt_use_comm SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_comm
- name: XCCDF Value var_virt_use_comm # promote to variable
  set_fact:
    var_virt_use_comm: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_comm" use="legacy"/>
  tags:
    - always

- name: Disable the virt_use_comm SELinux Boolean - Set SELinux Boolean virt_use_comm
    Accordingly
  ansible.posix.seboolean:
    name: virt_use_comm
    state: '{{ var_virt_use_comm }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_comm
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_virt_use_comm:var:1" value-id="xccdf_org.ssgproject.content_value_var_virt_use_comm"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_virt_use_comm:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_virt_use_comm_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_virt_use_execmem" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the virt_use_execmem SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>virt_use_execmem</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>virt_use_execmem</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P virt_use_execmem off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_execmem" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_virt_use_execmem='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_execmem" use="legacy"/>'

    /usr/sbin/setsebool -P virt_use_execmem $var_virt_use_execmem

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_execmem" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_execmem

- name: Disable the virt_use_execmem SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_execmem
- name: XCCDF Value var_virt_use_execmem # promote to variable
  set_fact:
    var_virt_use_execmem: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_execmem" use="legacy"/>
  tags:
    - always

- name: Disable the virt_use_execmem SELinux Boolean - Set SELinux Boolean virt_use_execmem
    Accordingly
  ansible.posix.seboolean:
    name: virt_use_execmem
    state: '{{ var_virt_use_execmem }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_execmem
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_virt_use_execmem:var:1" value-id="xccdf_org.ssgproject.content_value_var_virt_use_execmem"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_virt_use_execmem:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_virt_use_execmem_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_virt_use_fusefs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the virt_use_fusefs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>virt_use_fusefs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>virt_use_fusefs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P virt_use_fusefs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_fusefs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_virt_use_fusefs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_fusefs" use="legacy"/>'

    /usr/sbin/setsebool -P virt_use_fusefs $var_virt_use_fusefs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_fusefs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_fusefs

- name: Disable the virt_use_fusefs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_fusefs
- name: XCCDF Value var_virt_use_fusefs # promote to variable
  set_fact:
    var_virt_use_fusefs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_fusefs" use="legacy"/>
  tags:
    - always

- name: Disable the virt_use_fusefs SELinux Boolean - Set SELinux Boolean virt_use_fusefs
    Accordingly
  ansible.posix.seboolean:
    name: virt_use_fusefs
    state: '{{ var_virt_use_fusefs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_fusefs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_virt_use_fusefs:var:1" value-id="xccdf_org.ssgproject.content_value_var_virt_use_fusefs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_virt_use_fusefs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_virt_use_fusefs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_virt_use_nfs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the virt_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>virt_use_nfs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>virt_use_nfs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P virt_use_nfs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_virt_use_nfs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_nfs" use="legacy"/>'

    /usr/sbin/setsebool -P virt_use_nfs $var_virt_use_nfs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_nfs

- name: Disable the virt_use_nfs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_nfs
- name: XCCDF Value var_virt_use_nfs # promote to variable
  set_fact:
    var_virt_use_nfs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_nfs" use="legacy"/>
  tags:
    - always

- name: Disable the virt_use_nfs SELinux Boolean - Set SELinux Boolean virt_use_nfs
    Accordingly
  ansible.posix.seboolean:
    name: virt_use_nfs
    state: '{{ var_virt_use_nfs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_nfs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_virt_use_nfs:var:1" value-id="xccdf_org.ssgproject.content_value_var_virt_use_nfs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_virt_use_nfs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_virt_use_nfs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_virt_use_rawip" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the virt_use_rawip SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>virt_use_rawip</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>virt_use_rawip</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P virt_use_rawip off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_rawip" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_virt_use_rawip='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_rawip" use="legacy"/>'

    /usr/sbin/setsebool -P virt_use_rawip $var_virt_use_rawip

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_rawip" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_rawip

- name: Disable the virt_use_rawip SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_rawip
- name: XCCDF Value var_virt_use_rawip # promote to variable
  set_fact:
    var_virt_use_rawip: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_rawip" use="legacy"/>
  tags:
    - always

- name: Disable the virt_use_rawip SELinux Boolean - Set SELinux Boolean virt_use_rawip
    Accordingly
  ansible.posix.seboolean:
    name: virt_use_rawip
    state: '{{ var_virt_use_rawip }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_rawip
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_virt_use_rawip:var:1" value-id="xccdf_org.ssgproject.content_value_var_virt_use_rawip"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_virt_use_rawip:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_virt_use_rawip_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_virt_use_samba" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the virt_use_samba SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>virt_use_samba</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>virt_use_samba</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P virt_use_samba off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_samba" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_virt_use_samba='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_samba" use="legacy"/>'

    /usr/sbin/setsebool -P virt_use_samba $var_virt_use_samba

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_samba" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_samba

- name: Disable the virt_use_samba SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_samba
- name: XCCDF Value var_virt_use_samba # promote to variable
  set_fact:
    var_virt_use_samba: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_samba" use="legacy"/>
  tags:
    - always

- name: Disable the virt_use_samba SELinux Boolean - Set SELinux Boolean virt_use_samba
    Accordingly
  ansible.posix.seboolean:
    name: virt_use_samba
    state: '{{ var_virt_use_samba }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_samba
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_virt_use_samba:var:1" value-id="xccdf_org.ssgproject.content_value_var_virt_use_samba"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_virt_use_samba:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_virt_use_samba_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_virt_use_sanlock" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the virt_use_sanlock SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>virt_use_sanlock</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>virt_use_sanlock</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P virt_use_sanlock off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_sanlock" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_virt_use_sanlock='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_sanlock" use="legacy"/>'

    /usr/sbin/setsebool -P virt_use_sanlock $var_virt_use_sanlock

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_sanlock" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_sanlock

- name: Disable the virt_use_sanlock SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_sanlock
- name: XCCDF Value var_virt_use_sanlock # promote to variable
  set_fact:
    var_virt_use_sanlock: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_sanlock" use="legacy"/>
  tags:
    - always

- name: Disable the virt_use_sanlock SELinux Boolean - Set SELinux Boolean virt_use_sanlock
    Accordingly
  ansible.posix.seboolean:
    name: virt_use_sanlock
    state: '{{ var_virt_use_sanlock }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_sanlock
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_virt_use_sanlock:var:1" value-id="xccdf_org.ssgproject.content_value_var_virt_use_sanlock"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_virt_use_sanlock:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_virt_use_sanlock_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_virt_use_usb" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the virt_use_usb SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>virt_use_usb</html:code> is enabled.
This setting should be disabled.

To disable the <html:code>virt_use_usb</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P virt_use_usb off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_usb" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_virt_use_usb='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_usb" use="legacy"/>'

    /usr/sbin/setsebool -P virt_use_usb $var_virt_use_usb

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_usb" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_usb

- name: Disable the virt_use_usb SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_usb
- name: XCCDF Value var_virt_use_usb # promote to variable
  set_fact:
    var_virt_use_usb: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_usb" use="legacy"/>
  tags:
    - always

- name: Disable the virt_use_usb SELinux Boolean - Set SELinux Boolean virt_use_usb
    Accordingly
  ansible.posix.seboolean:
    name: virt_use_usb
    state: '{{ var_virt_use_usb }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_usb
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_virt_use_usb:var:1" value-id="xccdf_org.ssgproject.content_value_var_virt_use_usb"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_virt_use_usb:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_virt_use_usb_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_virt_use_xserver" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the virt_use_xserver SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>virt_use_xserver</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>virt_use_xserver</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P virt_use_xserver off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_xserver" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_virt_use_xserver='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_xserver" use="legacy"/>'

    /usr/sbin/setsebool -P virt_use_xserver $var_virt_use_xserver

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_virt_use_xserver" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_xserver

- name: Disable the virt_use_xserver SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_xserver
- name: XCCDF Value var_virt_use_xserver # promote to variable
  set_fact:
    var_virt_use_xserver: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_virt_use_xserver" use="legacy"/>
  tags:
    - always

- name: Disable the virt_use_xserver SELinux Boolean - Set SELinux Boolean virt_use_xserver
    Accordingly
  ansible.posix.seboolean:
    name: virt_use_xserver
    state: '{{ var_virt_use_xserver }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_virt_use_xserver
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_virt_use_xserver:var:1" value-id="xccdf_org.ssgproject.content_value_var_virt_use_xserver"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_virt_use_xserver:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_virt_use_xserver_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_webadm_manage_user_files" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the webadm_manage_user_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>webadm_manage_user_files</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>webadm_manage_user_files</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P webadm_manage_user_files off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_webadm_manage_user_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_webadm_manage_user_files='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_webadm_manage_user_files" use="legacy"/>'

    /usr/sbin/setsebool -P webadm_manage_user_files $var_webadm_manage_user_files

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_webadm_manage_user_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_webadm_manage_user_files

- name: Disable the webadm_manage_user_files SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_webadm_manage_user_files
- name: XCCDF Value var_webadm_manage_user_files # promote to variable
  set_fact:
    var_webadm_manage_user_files: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_webadm_manage_user_files" use="legacy"/>
  tags:
    - always

- name: Disable the webadm_manage_user_files SELinux Boolean - Set SELinux Boolean
    webadm_manage_user_files Accordingly
  ansible.posix.seboolean:
    name: webadm_manage_user_files
    state: '{{ var_webadm_manage_user_files }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_webadm_manage_user_files
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_webadm_manage_user_files:var:1" value-id="xccdf_org.ssgproject.content_value_var_webadm_manage_user_files"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_webadm_manage_user_files:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_webadm_manage_user_files_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_webadm_read_user_files" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the webadm_read_user_files SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>webadm_read_user_files</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>webadm_read_user_files</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P webadm_read_user_files off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_webadm_read_user_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_webadm_read_user_files='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_webadm_read_user_files" use="legacy"/>'

    /usr/sbin/setsebool -P webadm_read_user_files $var_webadm_read_user_files

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_webadm_read_user_files" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_webadm_read_user_files

- name: Disable the webadm_read_user_files SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_webadm_read_user_files
- name: XCCDF Value var_webadm_read_user_files # promote to variable
  set_fact:
    var_webadm_read_user_files: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_webadm_read_user_files" use="legacy"/>
  tags:
    - always

- name: Disable the webadm_read_user_files SELinux Boolean - Set SELinux Boolean webadm_read_user_files
    Accordingly
  ansible.posix.seboolean:
    name: webadm_read_user_files
    state: '{{ var_webadm_read_user_files }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_webadm_read_user_files
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_webadm_read_user_files:var:1" value-id="xccdf_org.ssgproject.content_value_var_webadm_read_user_files"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_webadm_read_user_files:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_webadm_read_user_files_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_wine_mmap_zero_ignore" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the wine_mmap_zero_ignore SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>wine_mmap_zero_ignore</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>wine_mmap_zero_ignore</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P wine_mmap_zero_ignore off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_wine_mmap_zero_ignore" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_wine_mmap_zero_ignore='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_wine_mmap_zero_ignore" use="legacy"/>'

    /usr/sbin/setsebool -P wine_mmap_zero_ignore $var_wine_mmap_zero_ignore

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_wine_mmap_zero_ignore" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_wine_mmap_zero_ignore

- name: Disable the wine_mmap_zero_ignore SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_wine_mmap_zero_ignore
- name: XCCDF Value var_wine_mmap_zero_ignore # promote to variable
  set_fact:
    var_wine_mmap_zero_ignore: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_wine_mmap_zero_ignore" use="legacy"/>
  tags:
    - always

- name: Disable the wine_mmap_zero_ignore SELinux Boolean - Set SELinux Boolean wine_mmap_zero_ignore
    Accordingly
  ansible.posix.seboolean:
    name: wine_mmap_zero_ignore
    state: '{{ var_wine_mmap_zero_ignore }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_wine_mmap_zero_ignore
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_wine_mmap_zero_ignore:var:1" value-id="xccdf_org.ssgproject.content_value_var_wine_mmap_zero_ignore"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_wine_mmap_zero_ignore:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_wine_mmap_zero_ignore_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_xdm_bind_vnc_tcp_port" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the xdm_bind_vnc_tcp_port SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>xdm_bind_vnc_tcp_port</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>xdm_bind_vnc_tcp_port</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P xdm_bind_vnc_tcp_port off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xdm_bind_vnc_tcp_port" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_xdm_bind_vnc_tcp_port='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xdm_bind_vnc_tcp_port" use="legacy"/>'

    /usr/sbin/setsebool -P xdm_bind_vnc_tcp_port $var_xdm_bind_vnc_tcp_port

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xdm_bind_vnc_tcp_port" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xdm_bind_vnc_tcp_port

- name: Disable the xdm_bind_vnc_tcp_port SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xdm_bind_vnc_tcp_port
- name: XCCDF Value var_xdm_bind_vnc_tcp_port # promote to variable
  set_fact:
    var_xdm_bind_vnc_tcp_port: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xdm_bind_vnc_tcp_port" use="legacy"/>
  tags:
    - always

- name: Disable the xdm_bind_vnc_tcp_port SELinux Boolean - Set SELinux Boolean xdm_bind_vnc_tcp_port
    Accordingly
  ansible.posix.seboolean:
    name: xdm_bind_vnc_tcp_port
    state: '{{ var_xdm_bind_vnc_tcp_port }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xdm_bind_vnc_tcp_port
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_xdm_bind_vnc_tcp_port:var:1" value-id="xccdf_org.ssgproject.content_value_var_xdm_bind_vnc_tcp_port"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_xdm_bind_vnc_tcp_port:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_xdm_bind_vnc_tcp_port_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_xdm_exec_bootloader" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the xdm_exec_bootloader SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>xdm_exec_bootloader</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>xdm_exec_bootloader</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P xdm_exec_bootloader off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xdm_exec_bootloader" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_xdm_exec_bootloader='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xdm_exec_bootloader" use="legacy"/>'

    /usr/sbin/setsebool -P xdm_exec_bootloader $var_xdm_exec_bootloader

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xdm_exec_bootloader" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xdm_exec_bootloader

- name: Disable the xdm_exec_bootloader SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xdm_exec_bootloader
- name: XCCDF Value var_xdm_exec_bootloader # promote to variable
  set_fact:
    var_xdm_exec_bootloader: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xdm_exec_bootloader" use="legacy"/>
  tags:
    - always

- name: Disable the xdm_exec_bootloader SELinux Boolean - Set SELinux Boolean xdm_exec_bootloader
    Accordingly
  ansible.posix.seboolean:
    name: xdm_exec_bootloader
    state: '{{ var_xdm_exec_bootloader }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xdm_exec_bootloader
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_xdm_exec_bootloader:var:1" value-id="xccdf_org.ssgproject.content_value_var_xdm_exec_bootloader"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_xdm_exec_bootloader:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_xdm_exec_bootloader_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_xdm_sysadm_login" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the xdm_sysadm_login SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>xdm_sysadm_login</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>xdm_sysadm_login</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P xdm_sysadm_login off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xdm_sysadm_login" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_xdm_sysadm_login='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xdm_sysadm_login" use="legacy"/>'

    /usr/sbin/setsebool -P xdm_sysadm_login $var_xdm_sysadm_login

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xdm_sysadm_login" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xdm_sysadm_login

- name: Disable the xdm_sysadm_login SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xdm_sysadm_login
- name: XCCDF Value var_xdm_sysadm_login # promote to variable
  set_fact:
    var_xdm_sysadm_login: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xdm_sysadm_login" use="legacy"/>
  tags:
    - always

- name: Disable the xdm_sysadm_login SELinux Boolean - Set SELinux Boolean xdm_sysadm_login
    Accordingly
  ansible.posix.seboolean:
    name: xdm_sysadm_login
    state: '{{ var_xdm_sysadm_login }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xdm_sysadm_login
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_xdm_sysadm_login:var:1" value-id="xccdf_org.ssgproject.content_value_var_xdm_sysadm_login"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_xdm_sysadm_login:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_xdm_sysadm_login_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_xdm_write_home" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the xdm_write_home SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>xdm_write_home</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>xdm_write_home</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P xdm_write_home off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xdm_write_home" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_xdm_write_home='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xdm_write_home" use="legacy"/>'

    /usr/sbin/setsebool -P xdm_write_home $var_xdm_write_home

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xdm_write_home" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xdm_write_home

- name: Disable the xdm_write_home SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xdm_write_home
- name: XCCDF Value var_xdm_write_home # promote to variable
  set_fact:
    var_xdm_write_home: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xdm_write_home" use="legacy"/>
  tags:
    - always

- name: Disable the xdm_write_home SELinux Boolean - Set SELinux Boolean xdm_write_home
    Accordingly
  ansible.posix.seboolean:
    name: xdm_write_home
    state: '{{ var_xdm_write_home }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xdm_write_home
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_xdm_write_home:var:1" value-id="xccdf_org.ssgproject.content_value_var_xdm_write_home"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_xdm_write_home:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_xdm_write_home_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_xen_use_nfs" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the xen_use_nfs SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>xen_use_nfs</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>xen_use_nfs</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P xen_use_nfs off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xen_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_xen_use_nfs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xen_use_nfs" use="legacy"/>'

    /usr/sbin/setsebool -P xen_use_nfs $var_xen_use_nfs

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xen_use_nfs" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xen_use_nfs

- name: Disable the xen_use_nfs SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xen_use_nfs
- name: XCCDF Value var_xen_use_nfs # promote to variable
  set_fact:
    var_xen_use_nfs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xen_use_nfs" use="legacy"/>
  tags:
    - always

- name: Disable the xen_use_nfs SELinux Boolean - Set SELinux Boolean xen_use_nfs
    Accordingly
  ansible.posix.seboolean:
    name: xen_use_nfs
    state: '{{ var_xen_use_nfs }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xen_use_nfs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_xen_use_nfs:var:1" value-id="xccdf_org.ssgproject.content_value_var_xen_use_nfs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_xen_use_nfs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_xen_use_nfs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_xend_run_blktap" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the xend_run_blktap SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>xend_run_blktap</html:code> is enabled.
If this setting is disabled, it should be enabled.

To enable the <html:code>xend_run_blktap</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P xend_run_blktap on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xend_run_blktap" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_xend_run_blktap='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xend_run_blktap" use="legacy"/>'

    /usr/sbin/setsebool -P xend_run_blktap $var_xend_run_blktap

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xend_run_blktap" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xend_run_blktap

- name: Enable the xend_run_blktap SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xend_run_blktap
- name: XCCDF Value var_xend_run_blktap # promote to variable
  set_fact:
    var_xend_run_blktap: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xend_run_blktap" use="legacy"/>
  tags:
    - always

- name: Enable the xend_run_blktap SELinux Boolean - Set SELinux Boolean xend_run_blktap
    Accordingly
  ansible.posix.seboolean:
    name: xend_run_blktap
    state: '{{ var_xend_run_blktap }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xend_run_blktap
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_xend_run_blktap:var:1" value-id="xccdf_org.ssgproject.content_value_var_xend_run_blktap"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_xend_run_blktap:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_xend_run_blktap_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_xend_run_qemu" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the xend_run_qemu SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>xend_run_qemu</html:code> is enabled.
If this setting is disabled, it should be enabled.

To enable the <html:code>xend_run_qemu</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P xend_run_qemu on</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xend_run_qemu" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_xend_run_qemu='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xend_run_qemu" use="legacy"/>'

    /usr/sbin/setsebool -P xend_run_qemu $var_xend_run_qemu

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xend_run_qemu" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xend_run_qemu

- name: Enable the xend_run_qemu SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xend_run_qemu
- name: XCCDF Value var_xend_run_qemu # promote to variable
  set_fact:
    var_xend_run_qemu: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xend_run_qemu" use="legacy"/>
  tags:
    - always

- name: Enable the xend_run_qemu SELinux Boolean - Set SELinux Boolean xend_run_qemu
    Accordingly
  ansible.posix.seboolean:
    name: xend_run_qemu
    state: '{{ var_xend_run_qemu }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xend_run_qemu
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_xend_run_qemu:var:1" value-id="xccdf_org.ssgproject.content_value_var_xend_run_qemu"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_xend_run_qemu:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_xend_run_qemu_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_xguest_connect_network" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the xguest_connect_network SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>xguest_connect_network</html:code> is enabled.
This setting should be disabled as guest users should not be able to configure
<html:code>NetworkManager</html:code>.

To disable the <html:code>xguest_connect_network</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P xguest_connect_network off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xguest_connect_network" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_xguest_connect_network='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xguest_connect_network" use="legacy"/>'

    /usr/sbin/setsebool -P xguest_connect_network $var_xguest_connect_network

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xguest_connect_network" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xguest_connect_network

- name: Disable the xguest_connect_network SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xguest_connect_network
- name: XCCDF Value var_xguest_connect_network # promote to variable
  set_fact:
    var_xguest_connect_network: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xguest_connect_network" use="legacy"/>
  tags:
    - always

- name: Disable the xguest_connect_network SELinux Boolean - Set SELinux Boolean xguest_connect_network
    Accordingly
  ansible.posix.seboolean:
    name: xguest_connect_network
    state: '{{ var_xguest_connect_network }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xguest_connect_network
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_xguest_connect_network:var:1" value-id="xccdf_org.ssgproject.content_value_var_xguest_connect_network"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_xguest_connect_network:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_xguest_connect_network_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_xguest_exec_content" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the xguest_exec_content SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>xguest_exec_content</html:code> is enabled.
This setting should be disabled as guest users should not be able to run
executables.

To disable the <html:code>xguest_exec_content</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P xguest_exec_content off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xguest_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_xguest_exec_content='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xguest_exec_content" use="legacy"/>'

    /usr/sbin/setsebool -P xguest_exec_content $var_xguest_exec_content

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xguest_exec_content" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xguest_exec_content

- name: Disable the xguest_exec_content SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xguest_exec_content
- name: XCCDF Value var_xguest_exec_content # promote to variable
  set_fact:
    var_xguest_exec_content: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xguest_exec_content" use="legacy"/>
  tags:
    - always

- name: Disable the xguest_exec_content SELinux Boolean - Set SELinux Boolean xguest_exec_content
    Accordingly
  ansible.posix.seboolean:
    name: xguest_exec_content
    state: '{{ var_xguest_exec_content }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xguest_exec_content
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_xguest_exec_content:var:1" value-id="xccdf_org.ssgproject.content_value_var_xguest_exec_content"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_xguest_exec_content:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_xguest_exec_content_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_xguest_mount_media" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the xguest_mount_media SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>xguest_mount_media</html:code> is enabled.
This setting should be disabled as guest users should not be able to mount
any media.

To disable the <html:code>xguest_mount_media</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P xguest_mount_media off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xguest_mount_media" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_xguest_mount_media='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xguest_mount_media" use="legacy"/>'

    /usr/sbin/setsebool -P xguest_mount_media $var_xguest_mount_media

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xguest_mount_media" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xguest_mount_media

- name: Disable the xguest_mount_media SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xguest_mount_media
- name: XCCDF Value var_xguest_mount_media # promote to variable
  set_fact:
    var_xguest_mount_media: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xguest_mount_media" use="legacy"/>
  tags:
    - always

- name: Disable the xguest_mount_media SELinux Boolean - Set SELinux Boolean xguest_mount_media
    Accordingly
  ansible.posix.seboolean:
    name: xguest_mount_media
    state: '{{ var_xguest_mount_media }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xguest_mount_media
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_xguest_mount_media:var:1" value-id="xccdf_org.ssgproject.content_value_var_xguest_mount_media"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_xguest_mount_media:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_xguest_mount_media_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_xguest_use_bluetooth" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the xguest_use_bluetooth SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>xguest_use_bluetooth</html:code> is enabled.
This setting should be disabled as guests users should not be able to access
or use bluetooth.

To disable the <html:code>xguest_use_bluetooth</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P xguest_use_bluetooth off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xguest_use_bluetooth" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_xguest_use_bluetooth='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xguest_use_bluetooth" use="legacy"/>'

    /usr/sbin/setsebool -P xguest_use_bluetooth $var_xguest_use_bluetooth

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xguest_use_bluetooth" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xguest_use_bluetooth

- name: Disable the xguest_use_bluetooth SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xguest_use_bluetooth
- name: XCCDF Value var_xguest_use_bluetooth # promote to variable
  set_fact:
    var_xguest_use_bluetooth: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xguest_use_bluetooth" use="legacy"/>
  tags:
    - always

- name: Disable the xguest_use_bluetooth SELinux Boolean - Set SELinux Boolean xguest_use_bluetooth
    Accordingly
  ansible.posix.seboolean:
    name: xguest_use_bluetooth
    state: '{{ var_xguest_use_bluetooth }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xguest_use_bluetooth
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_xguest_use_bluetooth:var:1" value-id="xccdf_org.ssgproject.content_value_var_xguest_use_bluetooth"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_xguest_use_bluetooth:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_xguest_use_bluetooth_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_xserver_clients_write_xshm" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the xserver_clients_write_xshm SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>xserver_clients_write_xshm</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>xserver_clients_write_xshm</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P xserver_clients_write_xshm off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xserver_clients_write_xshm" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_xserver_clients_write_xshm='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xserver_clients_write_xshm" use="legacy"/>'

    /usr/sbin/setsebool -P xserver_clients_write_xshm $var_xserver_clients_write_xshm

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xserver_clients_write_xshm" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xserver_clients_write_xshm

- name: Disable the xserver_clients_write_xshm SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xserver_clients_write_xshm
- name: XCCDF Value var_xserver_clients_write_xshm # promote to variable
  set_fact:
    var_xserver_clients_write_xshm: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xserver_clients_write_xshm" use="legacy"/>
  tags:
    - always

- name: Disable the xserver_clients_write_xshm SELinux Boolean - Set SELinux Boolean
    xserver_clients_write_xshm Accordingly
  ansible.posix.seboolean:
    name: xserver_clients_write_xshm
    state: '{{ var_xserver_clients_write_xshm }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xserver_clients_write_xshm
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_xserver_clients_write_xshm:var:1" value-id="xccdf_org.ssgproject.content_value_var_xserver_clients_write_xshm"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_xserver_clients_write_xshm:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_xserver_clients_write_xshm_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_xserver_execmem" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the xserver_execmem SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>xserver_execmem</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>xserver_execmem</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P xserver_execmem off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xserver_execmem" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_xserver_execmem='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xserver_execmem" use="legacy"/>'

    /usr/sbin/setsebool -P xserver_execmem $var_xserver_execmem

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xserver_execmem" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xserver_execmem

- name: Disable the xserver_execmem SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xserver_execmem
- name: XCCDF Value var_xserver_execmem # promote to variable
  set_fact:
    var_xserver_execmem: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xserver_execmem" use="legacy"/>
  tags:
    - always

- name: Disable the xserver_execmem SELinux Boolean - Set SELinux Boolean xserver_execmem
    Accordingly
  ansible.posix.seboolean:
    name: xserver_execmem
    state: '{{ var_xserver_execmem }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xserver_execmem
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_xserver_execmem:var:1" value-id="xccdf_org.ssgproject.content_value_var_xserver_execmem"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_xserver_execmem:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_xserver_execmem_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_xserver_object_manager" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the xserver_object_manager SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>xserver_object_manager</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>xserver_object_manager</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P xserver_object_manager off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xserver_object_manager" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_xserver_object_manager='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xserver_object_manager" use="legacy"/>'

    /usr/sbin/setsebool -P xserver_object_manager $var_xserver_object_manager

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_xserver_object_manager" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xserver_object_manager

- name: Disable the xserver_object_manager SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xserver_object_manager
- name: XCCDF Value var_xserver_object_manager # promote to variable
  set_fact:
    var_xserver_object_manager: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_xserver_object_manager" use="legacy"/>
  tags:
    - always

- name: Disable the xserver_object_manager SELinux Boolean - Set SELinux Boolean xserver_object_manager
    Accordingly
  ansible.posix.seboolean:
    name: xserver_object_manager
    state: '{{ var_xserver_object_manager }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_xserver_object_manager
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_xserver_object_manager:var:1" value-id="xccdf_org.ssgproject.content_value_var_xserver_object_manager"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_xserver_object_manager:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_xserver_object_manager_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_zabbix_can_network" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the zabbix_can_network SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>zabbix_can_network</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>zabbix_can_network</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P zabbix_can_network off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_zabbix_can_network" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_zabbix_can_network='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_zabbix_can_network" use="legacy"/>'

    /usr/sbin/setsebool -P zabbix_can_network $var_zabbix_can_network

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_zabbix_can_network" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_zabbix_can_network

- name: Disable the zabbix_can_network SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_zabbix_can_network
- name: XCCDF Value var_zabbix_can_network # promote to variable
  set_fact:
    var_zabbix_can_network: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_zabbix_can_network" use="legacy"/>
  tags:
    - always

- name: Disable the zabbix_can_network SELinux Boolean - Set SELinux Boolean zabbix_can_network
    Accordingly
  ansible.posix.seboolean:
    name: zabbix_can_network
    state: '{{ var_zabbix_can_network }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_zabbix_can_network
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_zabbix_can_network:var:1" value-id="xccdf_org.ssgproject.content_value_var_zabbix_can_network"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_zabbix_can_network:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_zabbix_can_network_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_zarafa_setrlimit" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the zarafa_setrlimit SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>zarafa_setrlimit</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>zarafa_setrlimit</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P zarafa_setrlimit off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_zarafa_setrlimit" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_zarafa_setrlimit='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_zarafa_setrlimit" use="legacy"/>'

    /usr/sbin/setsebool -P zarafa_setrlimit $var_zarafa_setrlimit

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_zarafa_setrlimit" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_zarafa_setrlimit

- name: Disable the zarafa_setrlimit SELinux Boolean - Ensure libsemanage-python Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_zarafa_setrlimit
- name: XCCDF Value var_zarafa_setrlimit # promote to variable
  set_fact:
    var_zarafa_setrlimit: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_zarafa_setrlimit" use="legacy"/>
  tags:
    - always

- name: Disable the zarafa_setrlimit SELinux Boolean - Set SELinux Boolean zarafa_setrlimit
    Accordingly
  ansible.posix.seboolean:
    name: zarafa_setrlimit
    state: '{{ var_zarafa_setrlimit }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_zarafa_setrlimit
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_zarafa_setrlimit:var:1" value-id="xccdf_org.ssgproject.content_value_var_zarafa_setrlimit"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_zarafa_setrlimit:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_zarafa_setrlimit_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_zebra_write_config" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the zebra_write_config SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>zebra_write_config</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>zebra_write_config</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P zebra_write_config off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_zebra_write_config" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_zebra_write_config='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_zebra_write_config" use="legacy"/>'

    /usr/sbin/setsebool -P zebra_write_config $var_zebra_write_config

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_zebra_write_config" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_zebra_write_config

- name: Disable the zebra_write_config SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_zebra_write_config
- name: XCCDF Value var_zebra_write_config # promote to variable
  set_fact:
    var_zebra_write_config: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_zebra_write_config" use="legacy"/>
  tags:
    - always

- name: Disable the zebra_write_config SELinux Boolean - Set SELinux Boolean zebra_write_config
    Accordingly
  ansible.posix.seboolean:
    name: zebra_write_config
    state: '{{ var_zebra_write_config }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_zebra_write_config
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_zebra_write_config:var:1" value-id="xccdf_org.ssgproject.content_value_var_zebra_write_config"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_zebra_write_config:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_zebra_write_config_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_zoneminder_anon_write" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the zoneminder_anon_write SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>zoneminder_anon_write</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>zoneminder_anon_write</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P zoneminder_anon_write off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_zoneminder_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_zoneminder_anon_write='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_zoneminder_anon_write" use="legacy"/>'

    /usr/sbin/setsebool -P zoneminder_anon_write $var_zoneminder_anon_write

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_zoneminder_anon_write" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_zoneminder_anon_write

- name: Disable the zoneminder_anon_write SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_zoneminder_anon_write
- name: XCCDF Value var_zoneminder_anon_write # promote to variable
  set_fact:
    var_zoneminder_anon_write: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_zoneminder_anon_write" use="legacy"/>
  tags:
    - always

- name: Disable the zoneminder_anon_write SELinux Boolean - Set SELinux Boolean zoneminder_anon_write
    Accordingly
  ansible.posix.seboolean:
    name: zoneminder_anon_write
    state: '{{ var_zoneminder_anon_write }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_zoneminder_anon_write
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_zoneminder_anon_write:var:1" value-id="xccdf_org.ssgproject.content_value_var_zoneminder_anon_write"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_zoneminder_anon_write:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_zoneminder_anon_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sebool_zoneminder_run_sudo" selected="false" severity="medium">
              <xccdf-1.2:title>Disable the zoneminder_run_sudo SELinux Boolean</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SELinux boolean <html:code>zoneminder_run_sudo</html:code> is disabled.
If this setting is enabled, it should be disabled.

To disable the <html:code>zoneminder_run_sudo</html:code> SELinux boolean, run the following command:
<html:pre>$ sudo setsebool -P zoneminder_run_sudo off</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_zoneminder_run_sudo" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( { rpm --quiet -q kernel ;} &amp;&amp; { rpm --quiet -q rpm-ostree ;} &amp;&amp; { rpm --quiet -q bootc ;} &amp;&amp; { ! rpm --quiet -q openshift-kubelet ;} &amp;&amp; ([ -f /run/ostree-booted ] || [ -L /ostree ]) || [ "${container:-}" == "bwrap-osbuild" ] || selinuxenabled ) &amp;&amp; rpm --quiet -q kernel; then

if ! rpm -q --quiet "libsemanage-python" ; then
    yum install -y "libsemanage-python"
fi


# Workaround for https://github.com/OpenSCAP/openscap/issues/2242: Use full
# path to setsebool command to avoid the issue with the command not being
# found.

    var_zoneminder_run_sudo='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_zoneminder_run_sudo" use="legacy"/>'

    /usr/sbin/setsebool -P zoneminder_run_sudo $var_zoneminder_run_sudo

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sebool_zoneminder_run_sudo" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_zoneminder_run_sudo

- name: Disable the zoneminder_run_sudo SELinux Boolean - Ensure libsemanage-python
    Installed
  ansible.builtin.package:
    name: libsemanage-python
    state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_zoneminder_run_sudo
- name: XCCDF Value var_zoneminder_run_sudo # promote to variable
  set_fact:
    var_zoneminder_run_sudo: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_zoneminder_run_sudo" use="legacy"/>
  tags:
    - always

- name: Disable the zoneminder_run_sudo SELinux Boolean - Set SELinux Boolean zoneminder_run_sudo
    Accordingly
  ansible.posix.seboolean:
    name: zoneminder_run_sudo
    state: '{{ var_zoneminder_run_sudo }}'
    persistent: true
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "kernel" in ansible_facts.packages and "rpm-ostree" in ansible_facts.packages
    and "bootc" in ansible_facts.packages and not "openshift-kubelet" in ansible_facts.packages
    and "ostree" in ansible_proc_cmdline or lookup("env", "container") == "bwrap-osbuild"
    or ansible_facts.selinux.status != "disabled" )
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sebool_zoneminder_run_sudo
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_zoneminder_run_sudo:var:1" value-id="xccdf_org.ssgproject.content_value_var_zoneminder_run_sudo"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sebool_zoneminder_run_sudo:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sebool_zoneminder_run_sudo_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
      </xccdf-1.2:Group>
      <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_services">
        <xccdf-1.2:title>Services</xccdf-1.2:title>
        <xccdf-1.2:description>The best protection against vulnerable software is running less software. This section describes how to review
the software which AlmaLinux OS 8 installs on a system and disable software which is not needed. It
then enumerates the software packages installed on a default AlmaLinux OS 8 system and provides guidance about which
ones can be safely disabled.
<html:br/><html:br/>
AlmaLinux OS 8 provides a convenient minimal install option that essentially installs the bare necessities for a functional
system. When building AlmaLinux OS 8 systems, it is highly recommended to select the minimal packages and then build up
the system from there.</xccdf-1.2:description>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_avahi">
          <xccdf-1.2:title>Avahi Server</xccdf-1.2:title>
          <xccdf-1.2:description>The Avahi daemon implements the DNS Service Discovery
and Multicast DNS protocols, which provide service and host
discovery on a network. It allows a system to automatically
identify resources on the network, such as printers or web servers.
This capability is also known as mDNSresponder and is a major part
of Zeroconf networking.</xccdf-1.2:description>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_avahi_configuration">
            <xccdf-1.2:title>Configure Avahi if Necessary</xccdf-1.2:title>
            <xccdf-1.2:description>If your system requires the Avahi daemon, its configuration can be restricted
to improve security. The Avahi daemon configuration file is
<html:code>/etc/avahi/avahi-daemon.conf</html:code>. The following security recommendations
should be applied to this file:
See the <html:code>avahi-daemon.conf(5)</html:code> man page, or documentation at

    <html:a href="http://www.avahi.org">http://www.avahi.org</html:a>, for more detailed information
about the configuration options.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_avahi_check_ttl" selected="false" severity="low">
              <xccdf-1.2:title>Check Avahi Responses' TTL Field</xccdf-1.2:title>
              <xccdf-1.2:description>To make Avahi ignore packets unless the TTL field is 255, edit
<html:code>/etc/avahi/avahi-daemon.conf</html:code> and ensure the following line
appears in the <html:code>[server]</html:code> section:
<html:pre>check-response-ttl=yes</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>This helps to ensure that only mDNS responses from the local network are
processed, because the TTL field in a packet is decremented from its initial
value of 255 whenever it is routed from one network to another. Although a
properly-configured router or firewall should not allow mDNS packets into
the local network at all, this option provides another check to ensure they
are not permitted.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_avahi_disable_publishing" selected="false" severity="low">
              <xccdf-1.2:title>Disable Avahi Publishing</xccdf-1.2:title>
              <xccdf-1.2:description>To prevent Avahi from publishing its records, edit <html:code>/etc/avahi/avahi-daemon.conf</html:code>
and ensure the following line appears in the <html:code>[publish]</html:code> section:
<html:pre>disable-publishing=yes</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>This helps ensure that no record will be published by Avahi.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_avahi_ip_only" selected="false" severity="low">
              <xccdf-1.2:title>Serve Avahi Only via Required Protocol</xccdf-1.2:title>
              <xccdf-1.2:description>If you are using only IPv4, edit <html:code>/etc/avahi/avahi-daemon.conf</html:code> and ensure
the following line exists in the <html:code>[server]</html:code> section:
<html:pre>use-ipv6=no</html:pre>
Similarly, if you are using only IPv6, disable IPv4 sockets with the line:
<html:pre>use-ipv4=no</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale/>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_avahi_prevent_port_sharing" selected="false" severity="medium">
              <xccdf-1.2:title>Prevent Other Programs from Using Avahi's Port</xccdf-1.2:title>
              <xccdf-1.2:description>To prevent other mDNS stacks from running, edit <html:code>/etc/avahi/avahi-daemon.conf</html:code>
and ensure the following line appears in the <html:code>[server]</html:code> section:
<html:pre>disallow-other-stacks=yes</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>This helps ensure that only Avahi is responsible for mDNS traffic coming from
that port on the system.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_avahi_restrict_published_information" selected="false" severity="low">
              <xccdf-1.2:title>Restrict Information Published by Avahi</xccdf-1.2:title>
              <xccdf-1.2:description>If it is necessary to publish some information to the network, it should not be joined
by any extraneous information, or by information supplied by a non-trusted source
on the system.
Prevent user applications from using Avahi to publish services by adding or
correcting the following line in the <html:code>[publish]</html:code> section:
<html:pre>disable-user-service-publishing=yes</html:pre>
Implement as many of the following lines as possible, to restrict the information
published by Avahi.
<html:pre>publish-addresses=no
publish-hinfo=no
publish-workstation=no
publish-domain=no</html:pre>
Inspect the files in the directory <html:code>/etc/avahi/services/</html:code>. Unless there
is an operational need to publish information about each of these services,
delete the corresponding file.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>These options prevent publishing attempts from succeeding,
and can be applied even if publishing is disabled entirely via
disable-publishing. Alternatively, these can be used to restrict
the types of published information in the event that some information
must be published.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disable_avahi_group">
            <xccdf-1.2:title>Disable Avahi Server if Possible</xccdf-1.2:title>
            <xccdf-1.2:description>Because the Avahi daemon service keeps an open network
port, it is subject to network attacks.
Disabling it can reduce the system's vulnerability to such attacks.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_avahi-autoipd_removed" selected="false" severity="medium">
              <xccdf-1.2:title>Uninstall avahi-autoipd Server Package</xccdf-1.2:title>
              <xccdf-1.2:description>If the system does not need to have an Avahi server which implements 
the DNS Service Discovery and Multicast DNS protocols,
the avahi-autoipd and avahi packages can be uninstalled.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Automatic discovery of network services is not normally required for 
system functionality. It is recommended to remove this package to reduce 
the potential attack surface.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_avahi-autoipd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove avahi-autoipd
# from the system, and may remove any packages
# that depend on avahi-autoipd. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "avahi-autoipd" ; then
yum remove -y "avahi-autoipd"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_avahi-autoipd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall avahi-autoipd Server Package: Ensure avahi-autoipd is removed'
  ansible.builtin.package:
    name: avahi-autoipd
    state: absent
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_avahi-autoipd_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_avahi-autoipd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_avahi-autoipd

class remove_avahi-autoipd {
  package { 'avahi-autoipd':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_avahi-autoipd_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=avahi-autoipd
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_avahi-autoipd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove avahi-autoipd
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_avahi-autoipd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove avahi-autoipd
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_avahi-autoipd_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_avahi-autoipd_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_avahi_removed" selected="false" severity="medium">
              <xccdf-1.2:title>Uninstall avahi Server Package</xccdf-1.2:title>
              <xccdf-1.2:description>If the system does not need to have an Avahi server which implements
the DNS Service Discovery and Multicast DNS protocols,
the avahi-autoipd and avahi packages can be uninstalled.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Automatic discovery of network services is not normally required for
system functionality. It is recommended to remove this package to reduce
the potential attack surface.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_avahi_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove avahi
# from the system, and may remove any packages
# that depend on avahi. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "avahi" ; then
yum remove -y "avahi"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_avahi_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall avahi Server Package: Ensure avahi is removed'
  ansible.builtin.package:
    name: avahi
    state: absent
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_avahi_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_avahi_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_avahi

class remove_avahi {
  package { 'avahi':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_avahi_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=avahi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_avahi_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove avahi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_avahi_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove avahi
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_avahi_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_avahi_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_avahi-daemon_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable Avahi Server Software</xccdf-1.2:title>
              <xccdf-1.2:description>
The <html:code>avahi-daemon</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now avahi-daemon.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Because the Avahi daemon service keeps an open network
port, it is subject to network attacks. Its functionality
is convenient but is only appropriate if the local network
can be trusted.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_avahi_and_system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_avahi-daemon_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q avahi &amp;&amp; rpm --quiet -q kernel ) ); then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'avahi-daemon.service'
fi
"$SYSTEMCTL_EXEC" disable 'avahi-daemon.service'
"$SYSTEMCTL_EXEC" mask 'avahi-daemon.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files avahi-daemon.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'avahi-daemon.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'avahi-daemon.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'avahi-daemon.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_avahi-daemon_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_avahi-daemon_disabled

- name: Disable Avahi Server Software - Disable service avahi-daemon
  block:

  - name: Disable Avahi Server Software - Collect systemd Services Present in the
      System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Avahi Server Software - Ensure avahi-daemon.service is Masked
    ansible.builtin.systemd:
      name: avahi-daemon.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("avahi-daemon.service", multiline=True)

  - name: Unit Socket Exists - avahi-daemon.socket
    ansible.builtin.command: systemctl -q list-unit-files avahi-daemon.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Avahi Server Software - Disable Socket avahi-daemon
    ansible.builtin.systemd:
      name: avahi-daemon.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("avahi-daemon.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_avahi-daemon_disabled
  - special_service_block
  when: ( "avahi" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_avahi-daemon_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_avahi-daemon

class disable_avahi-daemon {
  service {'avahi-daemon':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_avahi-daemon_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: avahi-daemon.service
        enabled: false
        mask: true
      - name: avahi-daemon.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_avahi-daemon_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["avahi-daemon"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_avahi-daemon_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable avahi-daemon
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_avahi-daemon_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_avahi-daemon_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_base">
          <xccdf-1.2:title>Base Services</xccdf-1.2:title>
          <xccdf-1.2:description>This section addresses the base services that are installed on a
AlmaLinux OS 8 default installation which are not covered in other
sections. Some of these services listen on the network and
should be treated with particular discretion. Other services are local
system utilities that may or may not be extraneous. In general, system services
should be disabled if not required.</xccdf-1.2:description>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_psacct_installed" selected="false" severity="low">
            <xccdf-1.2:title>Install the psacct package</xccdf-1.2:title>
            <xccdf-1.2:description>The process accounting service, <html:code>psacct</html:code>, works with programs
including <html:code>acct</html:code> and <html:code>ac</html:code> to allow system administrators to view
user activity, such as commands issued by users of the system.
The <html:code>psacct</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install psacct</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The <html:code>psacct</html:code> service can provide administrators a convenient
view into some user activities. However, it should be noted that the auditing
system and its audit records provide more authoritative and comprehensive
records.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_psacct_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh">
if ! rpm -q --quiet "psacct" ; then
    yum install -y "psacct"
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_psacct_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Ensure psacct is installed
  ansible.builtin.package:
    name: psacct
    state: present
  tags:
  - NIST-800-53-AU-12(a)
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_psacct_installed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_psacct_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_psacct

class install_psacct {
  package { 'psacct':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_psacct_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=psacct
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_psacct_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "psacct"
version = "*"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_psacct_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install psacct
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_psacct_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install psacct
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_psacct_installed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_psacct_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_abrt_removed" selected="false" severity="medium">
            <xccdf-1.2:title>Uninstall Automatic Bug Reporting Tool (abrt)</xccdf-1.2:title>
            <xccdf-1.2:description>The Automatic Bug Reporting Tool (<html:code>abrt</html:code>) collects
and reports crash data when an application crash is detected. Using a variety
of plugins, abrt can email crash reports to system administrators, log crash
reports to files, or forward crash reports to a centralized issue tracking
system such as RHTSupport.
The <html:code>abrt</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase abrt</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040001</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230488r1017272_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Mishandling crash data could expose sensitive information about
vulnerabilities in software executing on the system, as well as sensitive
information from within a process's address space or registers.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove abrt
# from the system, and may remove any packages
# that depend on abrt. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "abrt" ; then
yum remove -y "abrt"
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall Automatic Bug Reporting Tool (abrt): Ensure abrt is removed'
  ansible.builtin.package:
    name: abrt
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040001
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_abrt_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_abrt

class remove_abrt {
  package { 'abrt':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=abrt
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove abrt
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_abrt_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove abrt
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_abrt_removed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_abrt_removed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_psacct_enabled" selected="false" severity="low">
            <xccdf-1.2:title>Enable Process Accounting (psacct)</xccdf-1.2:title>
            <xccdf-1.2:description>The process accounting service, <html:code>psacct</html:code>, works with programs
including <html:code>acct</html:code> and <html:code>ac</html:code> to allow system administrators to view
user activity, such as commands issued by users of the system.

The <html:code>psacct</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable psacct.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The <html:code>psacct</html:code> service can provide administrators a convenient
view into some user activities. However, it should be noted that the auditing
system and its audit records provide more authoritative and comprehensive
records.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_psacct_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'psacct.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'psacct.service'
fi
"$SYSTEMCTL_EXEC" enable 'psacct.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_psacct_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(a)
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_psacct_enabled

- name: Enable Process Accounting (psacct) - Enable service psacct
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable Process Accounting (psacct) - Enable Service psacct
    ansible.builtin.systemd:
      name: psacct
      enabled: true
      state: started
      masked: false
    when:
    - '"psacct" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(a)
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_psacct_enabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_psacct_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_psacct

class enable_psacct {
  service {'psacct':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_psacct_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["psacct"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_psacct_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable psacct
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_psacct_enabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_psacct_enabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_abrtd_disabled" selected="false" severity="medium">
            <xccdf-1.2:title>Disable Automatic Bug Reporting Tool (abrtd)</xccdf-1.2:title>
            <xccdf-1.2:description>The Automatic Bug Reporting Tool (<html:code>abrtd</html:code>) daemon collects
and reports crash data when an application crash is detected. Using a variety
of plugins, abrtd can email crash reports to system administrators, log crash
reports to files, or forward crash reports to a centralized issue tracking
system such as RHTSupport.

The <html:code>abrtd</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now abrtd.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Mishandling crash data could expose sensitive information about
vulnerabilities in software executing on the system, as well as sensitive
information from within a process's address space or registers.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_abrtd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'abrtd.service'
fi
"$SYSTEMCTL_EXEC" disable 'abrtd.service'
"$SYSTEMCTL_EXEC" mask 'abrtd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files abrtd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'abrtd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'abrtd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'abrtd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_abrtd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_abrtd_disabled

- name: Disable Automatic Bug Reporting Tool (abrtd) - Disable service abrtd
  block:

  - name: Disable Automatic Bug Reporting Tool (abrtd) - Collect systemd Services
      Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Automatic Bug Reporting Tool (abrtd) - Ensure abrtd.service is Masked
    ansible.builtin.systemd:
      name: abrtd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("abrtd.service", multiline=True)

  - name: Unit Socket Exists - abrtd.socket
    ansible.builtin.command: systemctl -q list-unit-files abrtd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Automatic Bug Reporting Tool (abrtd) - Disable Socket abrtd
    ansible.builtin.systemd:
      name: abrtd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("abrtd.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_abrtd_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_abrtd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_abrtd

class disable_abrtd {
  service {'abrtd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_abrtd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: abrtd.service
        enabled: false
        mask: true
      - name: abrtd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_abrtd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["abrtd"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_abrtd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable abrtd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_abrtd_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_abrtd_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_acpid_disabled" selected="false" severity="medium">
            <xccdf-1.2:title>Disable Advanced Configuration and Power Interface (acpid)</xccdf-1.2:title>
            <xccdf-1.2:description>The Advanced Configuration and Power Interface Daemon (<html:code>acpid</html:code>)
dispatches ACPI events (such as power/reset button depressed) to userspace
programs.

The <html:code>acpid</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now acpid.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>ACPI support is highly desirable for systems in some network roles,
such as laptops or desktops. For other systems, such as servers, it may permit
accidental or trivially achievable denial of service situations and disabling
it is appropriate.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_acpid_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'acpid.service'
fi
"$SYSTEMCTL_EXEC" disable 'acpid.service'
"$SYSTEMCTL_EXEC" mask 'acpid.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files acpid.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'acpid.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'acpid.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'acpid.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_acpid_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_acpid_disabled

- name: Disable Advanced Configuration and Power Interface (acpid) - Disable service
    acpid
  block:

  - name: Disable Advanced Configuration and Power Interface (acpid) - Collect systemd
      Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Advanced Configuration and Power Interface (acpid) - Ensure acpid.service
      is Masked
    ansible.builtin.systemd:
      name: acpid.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("acpid.service", multiline=True)

  - name: Unit Socket Exists - acpid.socket
    ansible.builtin.command: systemctl -q list-unit-files acpid.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Advanced Configuration and Power Interface (acpid) - Disable Socket
      acpid
    ansible.builtin.systemd:
      name: acpid.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("acpid.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_acpid_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_acpid_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_acpid

class disable_acpid {
  service {'acpid':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_acpid_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: acpid.service
        enabled: false
        mask: true
      - name: acpid.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_acpid_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["acpid"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_acpid_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable acpid
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_acpid_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_acpid_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_certmonger_disabled" selected="false" severity="low">
            <xccdf-1.2:title>Disable Certmonger Service (certmonger)</xccdf-1.2:title>
            <xccdf-1.2:description>Certmonger is a D-Bus based service that attempts to simplify interaction
with certifying authorities on networks which use public-key infrastructure. It is often
combined with Red Hat's IPA (Identity Policy Audit) security information management
solution to aid in the management of certificates.

The <html:code>certmonger</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now certmonger.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The services provided by certmonger may be essential for systems
fulfilling some roles a PKI infrastructure, but its functionality is not necessary
for many other use cases.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_certmonger_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'certmonger.service'
fi
"$SYSTEMCTL_EXEC" disable 'certmonger.service'
"$SYSTEMCTL_EXEC" mask 'certmonger.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files certmonger.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'certmonger.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'certmonger.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'certmonger.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_certmonger_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_certmonger_disabled

- name: Disable Certmonger Service (certmonger) - Disable service certmonger
  block:

  - name: Disable Certmonger Service (certmonger) - Collect systemd Services Present
      in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Certmonger Service (certmonger) - Ensure certmonger.service is Masked
    ansible.builtin.systemd:
      name: certmonger.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("certmonger.service", multiline=True)

  - name: Unit Socket Exists - certmonger.socket
    ansible.builtin.command: systemctl -q list-unit-files certmonger.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Certmonger Service (certmonger) - Disable Socket certmonger
    ansible.builtin.systemd:
      name: certmonger.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("certmonger.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_certmonger_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_certmonger_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_certmonger

class disable_certmonger {
  service {'certmonger':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_certmonger_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: certmonger.service
        enabled: false
        mask: true
      - name: certmonger.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_certmonger_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["certmonger"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_certmonger_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable certmonger
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_certmonger_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_certmonger_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_cockpit_disabled" selected="false" severity="medium">
            <xccdf-1.2:title>Disable Cockpit Management Server</xccdf-1.2:title>
            <xccdf-1.2:description>The Cockpit Management Server (<html:code>cockpit</html:code>) provides a web based
login and management framework.

The <html:code>cockpit</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now cockpit.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Cockpit provides a form of remote login.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_cockpit_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'cockpit.service'
fi
"$SYSTEMCTL_EXEC" disable 'cockpit.service'
"$SYSTEMCTL_EXEC" mask 'cockpit.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files cockpit.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'cockpit.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'cockpit.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'cockpit.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_cockpit_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_cockpit_disabled

- name: Disable Cockpit Management Server - Disable service cockpit
  block:

  - name: Disable Cockpit Management Server - Collect systemd Services Present in
      the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Cockpit Management Server - Ensure cockpit.service is Masked
    ansible.builtin.systemd:
      name: cockpit.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("cockpit.service", multiline=True)

  - name: Unit Socket Exists - cockpit.socket
    ansible.builtin.command: systemctl -q list-unit-files cockpit.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Cockpit Management Server - Disable Socket cockpit
    ansible.builtin.systemd:
      name: cockpit.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("cockpit.socket", multiline=True)
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_cockpit_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_cockpit_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_cockpit

class disable_cockpit {
  service {'cockpit':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_cockpit_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: cockpit.service
        enabled: false
        mask: true
      - name: cockpit.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_cockpit_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["cockpit"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_cockpit_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable cockpit
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_cockpit_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_cockpit_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_cpupower_disabled" selected="false" severity="low">
            <xccdf-1.2:title>Disable CPU Speed (cpupower)</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>cpupower</html:code> service can adjust the clock speed of supported CPUs based upon
the current processing load thereby conserving power and reducing heat.

The <html:code>cpupower</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now cpupower.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The <html:code>cpupower</html:code> service is only necessary if adjusting the CPU clock speed
provides benefit. Traditionally this has included laptops (to enhance battery life),
but may also apply to server or desktop environments where conserving power is
highly desirable or necessary.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_cpupower_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'cpupower.service'
fi
"$SYSTEMCTL_EXEC" disable 'cpupower.service'
"$SYSTEMCTL_EXEC" mask 'cpupower.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files cpupower.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'cpupower.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'cpupower.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'cpupower.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_cpupower_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_cpupower_disabled

- name: Disable CPU Speed (cpupower) - Disable service cpupower
  block:

  - name: Disable CPU Speed (cpupower) - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable CPU Speed (cpupower) - Ensure cpupower.service is Masked
    ansible.builtin.systemd:
      name: cpupower.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("cpupower.service", multiline=True)

  - name: Unit Socket Exists - cpupower.socket
    ansible.builtin.command: systemctl -q list-unit-files cpupower.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable CPU Speed (cpupower) - Disable Socket cpupower
    ansible.builtin.systemd:
      name: cpupower.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("cpupower.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_cpupower_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_cpupower_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_cpupower

class disable_cpupower {
  service {'cpupower':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_cpupower_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: cpupower.service
        enabled: false
        mask: true
      - name: cpupower.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_cpupower_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["cpupower"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_cpupower_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable cpupower
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_cpupower_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_cpupower_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_kdump_disabled" selected="false" severity="medium">
            <xccdf-1.2:title>Disable KDump Kernel Crash Analyzer (kdump)</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>kdump</html:code> service provides a kernel crash dump analyzer. It uses the <html:code>kexec</html:code>
system call to boot a secondary kernel ("capture" kernel) following a system
crash, which can load information from the crashed kernel for analysis.

The <html:code>kdump</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now kdump.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000269-GPOS-00103</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010670</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230310r1155383_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Kernel core dumps may contain the full contents of system memory at the
time of the crash. Kernel core dumps consume a considerable amount of disk
space and may result in denial of service by exhausting the available space
on the target file system partition. Unless the system is used for kernel
development or testing, there is little need to run the kdump service.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_kdump_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'kdump.service'
fi
"$SYSTEMCTL_EXEC" disable 'kdump.service'
"$SYSTEMCTL_EXEC" mask 'kdump.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files kdump.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'kdump.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'kdump.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'kdump.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_kdump_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010670
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_kdump_disabled

- name: Disable KDump Kernel Crash Analyzer (kdump) - Disable service kdump
  block:

  - name: Disable KDump Kernel Crash Analyzer (kdump) - Collect systemd Services Present
      in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable KDump Kernel Crash Analyzer (kdump) - Ensure kdump.service is Masked
    ansible.builtin.systemd:
      name: kdump.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("kdump.service", multiline=True)

  - name: Unit Socket Exists - kdump.socket
    ansible.builtin.command: systemctl -q list-unit-files kdump.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable KDump Kernel Crash Analyzer (kdump) - Disable Socket kdump
    ansible.builtin.systemd:
      name: kdump.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("kdump.socket", multiline=True)
  tags:
  - DISA-STIG-RHEL-08-010670
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_kdump_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_kdump_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_kdump

class disable_kdump {
  service {'kdump':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_kdump_disabled" system="urn:redhat:anaconda:pre">
kdump --disable
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_kdump_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: kdump.service
        enabled: false
        mask: true
      - name: kdump.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_kdump_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["kdump"]
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_kdump_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_kdump_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_mdmonitor_disabled" selected="false" severity="low">
            <xccdf-1.2:title>Disable Software RAID Monitor (mdmonitor)</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>mdmonitor</html:code> service is used for monitoring a software RAID array; hardware
RAID setups do not use this service.

The <html:code>mdmonitor</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now mdmonitor.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If software RAID monitoring is not required,
there is no need to run this service.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_mdmonitor_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'mdmonitor.service'
fi
"$SYSTEMCTL_EXEC" disable 'mdmonitor.service'
"$SYSTEMCTL_EXEC" mask 'mdmonitor.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files mdmonitor.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'mdmonitor.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'mdmonitor.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'mdmonitor.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_mdmonitor_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_mdmonitor_disabled

- name: Disable Software RAID Monitor (mdmonitor) - Disable service mdmonitor
  block:

  - name: Disable Software RAID Monitor (mdmonitor) - Collect systemd Services Present
      in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Software RAID Monitor (mdmonitor) - Ensure mdmonitor.service is
      Masked
    ansible.builtin.systemd:
      name: mdmonitor.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("mdmonitor.service", multiline=True)

  - name: Unit Socket Exists - mdmonitor.socket
    ansible.builtin.command: systemctl -q list-unit-files mdmonitor.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Software RAID Monitor (mdmonitor) - Disable Socket mdmonitor
    ansible.builtin.systemd:
      name: mdmonitor.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("mdmonitor.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_mdmonitor_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_mdmonitor_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_mdmonitor

class disable_mdmonitor {
  service {'mdmonitor':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_mdmonitor_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: mdmonitor.service
        enabled: false
        mask: true
      - name: mdmonitor.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_mdmonitor_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["mdmonitor"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_mdmonitor_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable mdmonitor
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_mdmonitor_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_mdmonitor_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_netconsole_disabled" selected="false" severity="low">
            <xccdf-1.2:title>Disable Network Console (netconsole)</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>netconsole</html:code> service is responsible for loading the
netconsole kernel module, which logs kernel printk messages over UDP to a
syslog server. This allows debugging of problems where disk logging fails and
serial consoles are impractical.

The <html:code>netconsole</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now netconsole.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The <html:code>netconsole</html:code> service is not necessary unless there is a need to debug
kernel panics, which is not common.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_netconsole_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'netconsole.service'
fi
"$SYSTEMCTL_EXEC" disable 'netconsole.service'
"$SYSTEMCTL_EXEC" mask 'netconsole.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files netconsole.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'netconsole.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'netconsole.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'netconsole.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_netconsole_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_netconsole_disabled

- name: Disable Network Console (netconsole) - Disable service netconsole
  block:

  - name: Disable Network Console (netconsole) - Collect systemd Services Present
      in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Network Console (netconsole) - Ensure netconsole.service is Masked
    ansible.builtin.systemd:
      name: netconsole.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("netconsole.service", multiline=True)

  - name: Unit Socket Exists - netconsole.socket
    ansible.builtin.command: systemctl -q list-unit-files netconsole.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Network Console (netconsole) - Disable Socket netconsole
    ansible.builtin.systemd:
      name: netconsole.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("netconsole.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_netconsole_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_netconsole_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_netconsole

class disable_netconsole {
  service {'netconsole':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_netconsole_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: netconsole.service
        enabled: false
        mask: true
      - name: netconsole.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_netconsole_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["netconsole"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_netconsole_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable netconsole
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_netconsole_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_netconsole_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_ntpdate_disabled" selected="false" severity="low">
            <xccdf-1.2:title>Disable ntpdate Service (ntpdate)</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>ntpdate</html:code> service sets the local hardware clock by polling NTP servers
when the system boots. It synchronizes to the NTP servers listed in
<html:code>/etc/ntp/step-tickers</html:code> or <html:code>/etc/ntp.conf</html:code>
and then sets the local hardware clock to the newly synchronized
system time.

The <html:code>ntpdate</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now ntpdate.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The <html:code>ntpdate</html:code> service may only be suitable for systems which
are rebooted frequently enough that clock drift does not cause problems between
reboots. In any event, the functionality of the ntpdate service is now
available in the ntpd program and should be considered deprecated.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_ntpdate_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'ntpdate.service'
fi
"$SYSTEMCTL_EXEC" disable 'ntpdate.service'
"$SYSTEMCTL_EXEC" mask 'ntpdate.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files ntpdate.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'ntpdate.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'ntpdate.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'ntpdate.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_ntpdate_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_ntpdate_disabled

- name: Disable ntpdate Service (ntpdate) - Disable service ntpdate
  block:

  - name: Disable ntpdate Service (ntpdate) - Collect systemd Services Present in
      the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable ntpdate Service (ntpdate) - Ensure ntpdate.service is Masked
    ansible.builtin.systemd:
      name: ntpdate.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("ntpdate.service", multiline=True)

  - name: Unit Socket Exists - ntpdate.socket
    ansible.builtin.command: systemctl -q list-unit-files ntpdate.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable ntpdate Service (ntpdate) - Disable Socket ntpdate
    ansible.builtin.systemd:
      name: ntpdate.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("ntpdate.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_ntpdate_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_ntpdate_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_ntpdate

class disable_ntpdate {
  service {'ntpdate':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_ntpdate_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: ntpdate.service
        enabled: false
        mask: true
      - name: ntpdate.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_ntpdate_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["ntpdate"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_ntpdate_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable ntpdate
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_ntpdate_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_ntpdate_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_oddjobd_disabled" selected="false" severity="medium">
            <xccdf-1.2:title>Disable Odd Job Daemon (oddjobd)</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>oddjobd</html:code> service exists to provide an interface and
access control mechanism through which
specified privileged tasks can run tasks for unprivileged client
applications. Communication with <html:code>oddjobd</html:code> through the system message bus.

The <html:code>oddjobd</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now oddjobd.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The <html:code>oddjobd</html:code> service may provide necessary functionality in
some environments, and can be disabled if it is not needed. Execution of
tasks by privileged programs, on behalf of unprivileged ones, has traditionally
been a source of privilege escalation security issues.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_oddjobd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'oddjobd.service'
fi
"$SYSTEMCTL_EXEC" disable 'oddjobd.service'
"$SYSTEMCTL_EXEC" mask 'oddjobd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files oddjobd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'oddjobd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'oddjobd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'oddjobd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_oddjobd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_oddjobd_disabled

- name: Disable Odd Job Daemon (oddjobd) - Disable service oddjobd
  block:

  - name: Disable Odd Job Daemon (oddjobd) - Collect systemd Services Present in the
      System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Odd Job Daemon (oddjobd) - Ensure oddjobd.service is Masked
    ansible.builtin.systemd:
      name: oddjobd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("oddjobd.service", multiline=True)

  - name: Unit Socket Exists - oddjobd.socket
    ansible.builtin.command: systemctl -q list-unit-files oddjobd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Odd Job Daemon (oddjobd) - Disable Socket oddjobd
    ansible.builtin.systemd:
      name: oddjobd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("oddjobd.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_oddjobd_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_oddjobd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_oddjobd

class disable_oddjobd {
  service {'oddjobd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_oddjobd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: oddjobd.service
        enabled: false
        mask: true
      - name: oddjobd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_oddjobd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["oddjobd"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_oddjobd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable oddjobd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_oddjobd_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_oddjobd_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_portreserve_disabled" selected="false" severity="low">
            <xccdf-1.2:title>Disable Portreserve (portreserve)</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>portreserve</html:code> service is a TCP port reservation utility that can
be used to prevent portmap from binding to well known TCP ports that are
required for other services.

The <html:code>portreserve</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now portreserve.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The <html:code>portreserve</html:code> service provides helpful functionality by
preventing conflicting usage of ports in the reserved port range, but it can be
disabled if not needed.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_portreserve_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'portreserve.service'
fi
"$SYSTEMCTL_EXEC" disable 'portreserve.service'
"$SYSTEMCTL_EXEC" mask 'portreserve.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files portreserve.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'portreserve.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'portreserve.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'portreserve.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_portreserve_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_portreserve_disabled

- name: Disable Portreserve (portreserve) - Disable service portreserve
  block:

  - name: Disable Portreserve (portreserve) - Collect systemd Services Present in
      the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Portreserve (portreserve) - Ensure portreserve.service is Masked
    ansible.builtin.systemd:
      name: portreserve.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("portreserve.service", multiline=True)

  - name: Unit Socket Exists - portreserve.socket
    ansible.builtin.command: systemctl -q list-unit-files portreserve.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Portreserve (portreserve) - Disable Socket portreserve
    ansible.builtin.systemd:
      name: portreserve.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("portreserve.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_portreserve_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_portreserve_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_portreserve

class disable_portreserve {
  service {'portreserve':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_portreserve_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: portreserve.service
        enabled: false
        mask: true
      - name: portreserve.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_portreserve_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["portreserve"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_portreserve_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable portreserve
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_portreserve_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_portreserve_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_qpidd_disabled" selected="false" severity="low">
            <xccdf-1.2:title>Disable Apache Qpid (qpidd)</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>qpidd</html:code> service provides high speed, secure,
guaranteed delivery services.  It is an implementation of the Advanced Message
Queuing Protocol.  By default the qpidd service will bind to port 5672 and
listen for connection attempts.

The <html:code>qpidd</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now qpidd.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The qpidd service is automatically installed when the <html:code>base</html:code> package
selection is selected during installation. The qpidd service listens for
network connections, which increases the attack surface of the system. If
the system is not intended to receive AMQP traffic, then the <html:code>qpidd</html:code>
service is not needed and should be disabled or removed.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_qpidd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'qpidd.service'
fi
"$SYSTEMCTL_EXEC" disable 'qpidd.service'
"$SYSTEMCTL_EXEC" mask 'qpidd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files qpidd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'qpidd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'qpidd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'qpidd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_qpidd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_qpidd_disabled

- name: Disable Apache Qpid (qpidd) - Disable service qpidd
  block:

  - name: Disable Apache Qpid (qpidd) - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Apache Qpid (qpidd) - Ensure qpidd.service is Masked
    ansible.builtin.systemd:
      name: qpidd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("qpidd.service", multiline=True)

  - name: Unit Socket Exists - qpidd.socket
    ansible.builtin.command: systemctl -q list-unit-files qpidd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Apache Qpid (qpidd) - Disable Socket qpidd
    ansible.builtin.systemd:
      name: qpidd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("qpidd.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_qpidd_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_qpidd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_qpidd

class disable_qpidd {
  service {'qpidd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_qpidd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: qpidd.service
        enabled: false
        mask: true
      - name: qpidd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_qpidd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["qpidd"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_qpidd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable qpidd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_qpidd_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_qpidd_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_quota_nld_disabled" selected="false" severity="low">
            <xccdf-1.2:title>Disable Quota Netlink (quota_nld)</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>quota_nld</html:code> service provides notifications to
users of disk space quota violations. It listens to the kernel via a netlink
socket for disk quota violations and notifies the appropriate user of the
violation using D-Bus or by sending a message to the terminal that the user has
last accessed.

The <html:code>quota_nld</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now quota_nld.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If disk quotas are enforced on the local system, then the
<html:code>quota_nld</html:code> service likely provides useful functionality and should
remain enabled. However, if disk quotas are not used or user notification of
disk quota violation is not desired then there is no need to run this
service.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_quota_nld_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'quota_nld.service'
fi
"$SYSTEMCTL_EXEC" disable 'quota_nld.service'
"$SYSTEMCTL_EXEC" mask 'quota_nld.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files quota_nld.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'quota_nld.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'quota_nld.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'quota_nld.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_quota_nld_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_quota_nld_disabled

- name: Disable Quota Netlink (quota_nld) - Disable service quota_nld
  block:

  - name: Disable Quota Netlink (quota_nld) - Collect systemd Services Present in
      the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Quota Netlink (quota_nld) - Ensure quota_nld.service is Masked
    ansible.builtin.systemd:
      name: quota_nld.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("quota_nld.service", multiline=True)

  - name: Unit Socket Exists - quota_nld.socket
    ansible.builtin.command: systemctl -q list-unit-files quota_nld.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Quota Netlink (quota_nld) - Disable Socket quota_nld
    ansible.builtin.systemd:
      name: quota_nld.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("quota_nld.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_quota_nld_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_quota_nld_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_quota_nld

class disable_quota_nld {
  service {'quota_nld':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_quota_nld_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: quota_nld.service
        enabled: false
        mask: true
      - name: quota_nld.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_quota_nld_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["quota_nld"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_quota_nld_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable quota_nld
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_quota_nld_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_quota_nld_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_rdisc_disabled" selected="false" severity="medium">
            <xccdf-1.2:title>Disable Network Router Discovery Daemon (rdisc)</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>rdisc</html:code> service implements the client side of the ICMP
Internet Router Discovery Protocol (IRDP), which allows discovery of routers on
the local subnet. If a router is discovered then the local routing table is
updated with a corresponding default route. By default this daemon is disabled.

The <html:code>rdisc</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now rdisc.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.AM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:rationale>General-purpose systems typically have their network and routing
information configured statically by a system administrator. Workstations or
some special-purpose systems often use DHCP (instead of IRDP) to retrieve
dynamic network configuration information.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rdisc_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'rdisc.service'
fi
"$SYSTEMCTL_EXEC" disable 'rdisc.service'
"$SYSTEMCTL_EXEC" mask 'rdisc.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files rdisc.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'rdisc.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'rdisc.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'rdisc.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rdisc_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-4
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_rdisc_disabled

- name: Disable Network Router Discovery Daemon (rdisc) - Disable service rdisc
  block:

  - name: Disable Network Router Discovery Daemon (rdisc) - Collect systemd Services
      Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Network Router Discovery Daemon (rdisc) - Ensure rdisc.service is
      Masked
    ansible.builtin.systemd:
      name: rdisc.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("rdisc.service", multiline=True)

  - name: Unit Socket Exists - rdisc.socket
    ansible.builtin.command: systemctl -q list-unit-files rdisc.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Network Router Discovery Daemon (rdisc) - Disable Socket rdisc
    ansible.builtin.systemd:
      name: rdisc.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("rdisc.socket", multiline=True)
  tags:
  - NIST-800-53-AC-4
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_rdisc_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rdisc_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_rdisc

class disable_rdisc {
  service {'rdisc':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_rdisc_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: rdisc.service
        enabled: false
        mask: true
      - name: rdisc.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_rdisc_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["rdisc"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rdisc_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable rdisc
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_rdisc_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_rdisc_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_rhnsd_disabled" selected="false" severity="low">
            <xccdf-1.2:title>Disable Red Hat Network Service (rhnsd)</xccdf-1.2:title>
            <xccdf-1.2:description>The Red Hat Network service automatically queries Red Hat Network
servers to determine whether there are any actions that should be executed,
such as package updates. This only occurs if the system was registered to an
RHN server or satellite and managed as such.

The <html:code>rhnsd</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now rhnsd.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Although systems management and patching is extremely important to
system security, management by a system outside the enterprise enclave is not
desirable for some environments.  However, if the system is being managed by RHN or
 RHN Satellite Server the <html:code>rhnsd</html:code> daemon can remain on.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rhnsd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'rhnsd.service'
fi
"$SYSTEMCTL_EXEC" disable 'rhnsd.service'
"$SYSTEMCTL_EXEC" mask 'rhnsd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files rhnsd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'rhnsd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'rhnsd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'rhnsd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rhnsd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_rhnsd_disabled

- name: Disable Red Hat Network Service (rhnsd) - Disable service rhnsd
  block:

  - name: Disable Red Hat Network Service (rhnsd) - Collect systemd Services Present
      in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Red Hat Network Service (rhnsd) - Ensure rhnsd.service is Masked
    ansible.builtin.systemd:
      name: rhnsd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("rhnsd.service", multiline=True)

  - name: Unit Socket Exists - rhnsd.socket
    ansible.builtin.command: systemctl -q list-unit-files rhnsd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Red Hat Network Service (rhnsd) - Disable Socket rhnsd
    ansible.builtin.systemd:
      name: rhnsd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("rhnsd.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_rhnsd_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rhnsd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_rhnsd

class disable_rhnsd {
  service {'rhnsd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_rhnsd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: rhnsd.service
        enabled: false
        mask: true
      - name: rhnsd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_rhnsd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["rhnsd"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rhnsd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable rhnsd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_rhnsd_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_rhnsd_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_rhsmcertd_disabled" selected="false" severity="low">
            <xccdf-1.2:title>Disable Red Hat Subscription Manager Daemon (rhsmcertd)</xccdf-1.2:title>
            <xccdf-1.2:description>The Red Hat Subscription Manager (rhsmcertd) periodically checks for
changes in the entitlement certificates for a registered system and updates it
accordingly.

The <html:code>rhsmcertd</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now rhsmcertd.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The <html:code>rhsmcertd</html:code> service can provide administrators with some
additional control over which of their systems are entitled to particular
subscriptions. However, for systems that are managed locally or which are not
expected to require remote changes to their subscription status, it is
unnecessary and can be disabled.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rhsmcertd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'rhsmcertd.service'
fi
"$SYSTEMCTL_EXEC" disable 'rhsmcertd.service'
"$SYSTEMCTL_EXEC" mask 'rhsmcertd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files rhsmcertd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'rhsmcertd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'rhsmcertd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'rhsmcertd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rhsmcertd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_rhsmcertd_disabled

- name: Disable Red Hat Subscription Manager Daemon (rhsmcertd) - Disable service
    rhsmcertd
  block:

  - name: Disable Red Hat Subscription Manager Daemon (rhsmcertd) - Collect systemd
      Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Red Hat Subscription Manager Daemon (rhsmcertd) - Ensure rhsmcertd.service
      is Masked
    ansible.builtin.systemd:
      name: rhsmcertd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("rhsmcertd.service", multiline=True)

  - name: Unit Socket Exists - rhsmcertd.socket
    ansible.builtin.command: systemctl -q list-unit-files rhsmcertd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Red Hat Subscription Manager Daemon (rhsmcertd) - Disable Socket
      rhsmcertd
    ansible.builtin.systemd:
      name: rhsmcertd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("rhsmcertd.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_rhsmcertd_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rhsmcertd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_rhsmcertd

class disable_rhsmcertd {
  service {'rhsmcertd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_rhsmcertd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: rhsmcertd.service
        enabled: false
        mask: true
      - name: rhsmcertd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_rhsmcertd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["rhsmcertd"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rhsmcertd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable rhsmcertd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_rhsmcertd_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_rhsmcertd_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_saslauthd_disabled" selected="false" severity="low">
            <xccdf-1.2:title>Disable Cyrus SASL Authentication Daemon (saslauthd)</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>saslauthd</html:code> service handles plaintext authentication requests on
behalf of the SASL library. The service isolates all code requiring superuser
privileges for SASL authentication into a single process, and can also be used
to provide proxy authentication services to clients that do not understand SASL
based authentication.

The <html:code>saslauthd</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now saslauthd.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The <html:code>saslauthd</html:code> service provides essential functionality for
performing authentication in some directory environments, such as those which
use Kerberos and LDAP. For others, however, in which only local files may be
consulted, it is not necessary and should be disabled.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_saslauthd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'saslauthd.service'
fi
"$SYSTEMCTL_EXEC" disable 'saslauthd.service'
"$SYSTEMCTL_EXEC" mask 'saslauthd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files saslauthd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'saslauthd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'saslauthd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'saslauthd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_saslauthd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_saslauthd_disabled

- name: Disable Cyrus SASL Authentication Daemon (saslauthd) - Disable service saslauthd
  block:

  - name: Disable Cyrus SASL Authentication Daemon (saslauthd) - Collect systemd Services
      Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Cyrus SASL Authentication Daemon (saslauthd) - Ensure saslauthd.service
      is Masked
    ansible.builtin.systemd:
      name: saslauthd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("saslauthd.service", multiline=True)

  - name: Unit Socket Exists - saslauthd.socket
    ansible.builtin.command: systemctl -q list-unit-files saslauthd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Cyrus SASL Authentication Daemon (saslauthd) - Disable Socket saslauthd
    ansible.builtin.systemd:
      name: saslauthd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("saslauthd.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_saslauthd_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_saslauthd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_saslauthd

class disable_saslauthd {
  service {'saslauthd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_saslauthd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: saslauthd.service
        enabled: false
        mask: true
      - name: saslauthd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_saslauthd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["saslauthd"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_saslauthd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable saslauthd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_saslauthd_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_saslauthd_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_sysstat_disabled" selected="false" severity="low">
            <xccdf-1.2:title>Disable System Statistics Reset Service (sysstat)</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>sysstat</html:code> service resets various I/O and CPU
performance statistics to zero in order to begin counting from a fresh state
at boot time.

The <html:code>sysstat</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now sysstat.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>By default the <html:code>sysstat</html:code> service runs a program at
boot to reset performance statistics. This data can be retrieved using programs such as
<html:code>sar</html:code> and <html:code>sadc</html:code>. While the <html:code>sysstat</html:code> service may provide useful
insight into system operation, through the lens of providing only essential system services,
this service should be disabled. </xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_sysstat_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'sysstat.service'
fi
"$SYSTEMCTL_EXEC" disable 'sysstat.service'
"$SYSTEMCTL_EXEC" mask 'sysstat.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files sysstat.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'sysstat.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'sysstat.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'sysstat.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_sysstat_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_sysstat_disabled

- name: Disable System Statistics Reset Service (sysstat) - Disable service sysstat
  block:

  - name: Disable System Statistics Reset Service (sysstat) - Collect systemd Services
      Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable System Statistics Reset Service (sysstat) - Ensure sysstat.service
      is Masked
    ansible.builtin.systemd:
      name: sysstat.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("sysstat.service", multiline=True)

  - name: Unit Socket Exists - sysstat.socket
    ansible.builtin.command: systemctl -q list-unit-files sysstat.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable System Statistics Reset Service (sysstat) - Disable Socket sysstat
    ansible.builtin.systemd:
      name: sysstat.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("sysstat.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_sysstat_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_sysstat_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_sysstat

class disable_sysstat {
  service {'sysstat':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_sysstat_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: sysstat.service
        enabled: false
        mask: true
      - name: sysstat.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_sysstat_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["sysstat"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_sysstat_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable sysstat
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_sysstat_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_sysstat_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_cron_and_at">
          <xccdf-1.2:title>Cron and At Daemons</xccdf-1.2:title>
          <xccdf-1.2:description>The cron and at services are used to allow commands to
be executed at a later time. The cron service is required by almost
all systems to perform necessary maintenance tasks, while at may or
may not be required on a given system. Both daemons should be
configured defensively.</xccdf-1.2:description>
          <xccdf-1.2:platform idref="#system_with_kernel"/>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_cron_installed" selected="false" severity="medium">
            <xccdf-1.2:title>Install the cron service</xccdf-1.2:title>
            <xccdf-1.2:description>The Cron service should be installed.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The cron service allow periodic job execution, needed for almost all administrative tasks and services (software update, log rotating, etc.). Access to cron service should be restricted to administrative accounts only.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_cron_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "cron" ; then
    yum install -y "cron"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_cron_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_cron_installed

- name: Ensure cron is installed
  ansible.builtin.package:
    name: cron
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_cron_installed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_cron_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_cron

class install_cron {
  package { 'cron':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_cron_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=cron
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_cron_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "cron"
version = "*"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_cron_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install cron
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_cron_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install cron
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_cron_installed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_cron_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_cron_enabled" selected="false" severity="medium">
            <xccdf-1.2:title>Enable cron Service</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>crond</html:code> service is used to execute commands at
preconfigured times. It is required by almost all systems to perform necessary
maintenance tasks, such as notifying root of system activity.

The <html:code>crond</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable crond.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Due to its usage for maintenance and security-supporting tasks,
enabling the cron daemon is essential.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_cron_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'cron.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'cron.service'
fi
"$SYSTEMCTL_EXEC" enable 'cron.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_cron_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_cron_enabled

- name: Enable cron Service - Enable service cron
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable cron Service - Enable Service cron
    ansible.builtin.systemd:
      name: cron
      enabled: true
      state: started
      masked: false
    when:
    - '"cron" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_cron_enabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_cron_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_cron

class enable_cron {
  service {'cron':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_cron_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["cron"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_cron_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable cron
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_cron_enabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_cron_enabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_crond_enabled" selected="false" severity="medium">
            <xccdf-1.2:title>Enable cron Service</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>crond</html:code> service is used to execute commands at
preconfigured times. It is required by almost all systems to perform necessary
maintenance tasks, such as notifying root of system activity.

The <html:code>crond</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable crond.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Due to its usage for maintenance and security-supporting tasks,
enabling the cron daemon is essential.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_crond_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'crond.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'crond.service'
fi
"$SYSTEMCTL_EXEC" enable 'crond.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_crond_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_crond_enabled

- name: Enable cron Service - Enable service crond
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable cron Service - Enable Service crond
    ansible.builtin.systemd:
      name: crond
      enabled: true
      state: started
      masked: false
    when:
    - '"cronie" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_crond_enabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_crond_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_crond

class enable_crond {
  service {'crond':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_crond_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["crond"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_crond_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable crond
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_crond_enabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_crond_enabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_atd_disabled" selected="false" severity="medium">
            <xccdf-1.2:title>Disable At Service (atd)</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>at</html:code> and <html:code>batch</html:code> commands can be used to
schedule tasks that are meant to be executed only once. This allows delayed
execution in a manner similar to cron, except that it is not
recurring. The daemon <html:code>atd</html:code> keeps track of tasks scheduled via
<html:code>at</html:code> and <html:code>batch</html:code>, and executes them at the specified time.

The <html:code>atd</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now atd.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The <html:code>atd</html:code> service could be used by an unsophisticated insider to carry
out activities outside of a normal login session, which could complicate
accountability. Furthermore, the need to schedule tasks with <html:code>at</html:code> or
<html:code>batch</html:code> is not common.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_atd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'atd.service'
fi
"$SYSTEMCTL_EXEC" disable 'atd.service'
"$SYSTEMCTL_EXEC" mask 'atd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files atd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'atd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'atd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'atd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_atd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_atd_disabled

- name: Disable At Service (atd) - Disable service atd
  block:

  - name: Disable At Service (atd) - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable At Service (atd) - Ensure atd.service is Masked
    ansible.builtin.systemd:
      name: atd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("atd.service", multiline=True)

  - name: Unit Socket Exists - atd.socket
    ansible.builtin.command: systemctl -q list-unit-files atd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable At Service (atd) - Disable Socket atd
    ansible.builtin.systemd:
      name: atd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("atd.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_atd_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_atd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_atd

class disable_atd {
  service {'atd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_atd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: atd.service
        enabled: false
        mask: true
      - name: atd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_atd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["atd"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_atd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable atd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_atd_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_atd_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_disable_anacron" selected="false" severity="unknown">
            <xccdf-1.2:title>Disable anacron Service</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>cronie-anacron</html:code> package, which provides <html:code>anacron</html:code>
functionality, is installed by default.
The <html:code>cronie-anacron</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase cronie-anacron</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The <html:code>anacron</html:code> service provides <html:code>cron</html:code> functionality for systems
such as laptops and workstations that may be shut down during the normal times
that <html:code>cron</html:code> jobs are scheduled to run. On systems which do not require this
additional functionality, <html:code>anacron</html:code> could needlessly increase the possible
attack surface for an intruder.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-disable_anacron_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_cron_d" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Group Who Owns cron.d</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/cron.d</html:code>, run the command:

  <html:pre>$ sudo chgrp root /etc/cron.d</html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.8</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should be owned by the
correct group to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_cron_d" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
find -P /etc/cron.d/ -maxdepth 0 -type d  ! -group 0 -exec chgrp --no-dereference "$newgroup" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_cron_d" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_cron_d_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_cron_d_newgroup: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/cron.d/
  ansible.builtin.file:
    path: /etc/cron.d/
    follow: false
    state: directory
    group: '{{ file_groupowner_cron_d_newgroup }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_cron_d:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_cron_d_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_cron_daily" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Group Who Owns cron.daily</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/cron.daily</html:code>, run the command:

  <html:pre>$ sudo chgrp root /etc/cron.daily</html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.4</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should be owned by the
correct group to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_cron_daily" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
find -P /etc/cron.daily/ -maxdepth 0 -type d  ! -group 0 -exec chgrp --no-dereference "$newgroup" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_cron_daily" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_daily
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_cron_daily_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_cron_daily_newgroup: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_daily
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/cron.daily/
  ansible.builtin.file:
    path: /etc/cron.daily/
    follow: false
    state: directory
    group: '{{ file_groupowner_cron_daily_newgroup }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_daily
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_cron_daily:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_cron_daily_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_cron_hourly" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Group Who Owns cron.hourly</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/cron.hourly</html:code>, run the command:

  <html:pre>$ sudo chgrp root /etc/cron.hourly</html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should be owned by the
correct group to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_cron_hourly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
find -P /etc/cron.hourly/ -maxdepth 0 -type d  ! -group 0 -exec chgrp --no-dereference "$newgroup" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_cron_hourly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_hourly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_cron_hourly_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_cron_hourly_newgroup: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_hourly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/cron.hourly/
  ansible.builtin.file:
    path: /etc/cron.hourly/
    follow: false
    state: directory
    group: '{{ file_groupowner_cron_hourly_newgroup }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_hourly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_cron_hourly:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_cron_hourly_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_cron_monthly" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Group Who Owns cron.monthly</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/cron.monthly</html:code>, run the command:

  <html:pre>$ sudo chgrp root /etc/cron.monthly</html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.6</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should be owned by the
correct group to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_cron_monthly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
find -P /etc/cron.monthly/ -maxdepth 0 -type d  ! -group 0 -exec chgrp --no-dereference "$newgroup" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_cron_monthly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_monthly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_cron_monthly_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_cron_monthly_newgroup: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_monthly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/cron.monthly/
  ansible.builtin.file:
    path: /etc/cron.monthly/
    follow: false
    state: directory
    group: '{{ file_groupowner_cron_monthly_newgroup }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_monthly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_cron_monthly:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_cron_monthly_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_cron_weekly" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Group Who Owns cron.weekly</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/cron.weekly</html:code>, run the command:

  <html:pre>$ sudo chgrp root /etc/cron.weekly</html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.5</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should be owned by the
correct group to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_cron_weekly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
find -P /etc/cron.weekly/ -maxdepth 0 -type d  ! -group 0 -exec chgrp --no-dereference "$newgroup" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_cron_weekly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_weekly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_cron_weekly_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_cron_weekly_newgroup: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_weekly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/cron.weekly/
  ansible.builtin.file:
    path: /etc/cron.weekly/
    follow: false
    state: directory
    group: '{{ file_groupowner_cron_weekly_newgroup }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_weekly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_cron_weekly:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_cron_weekly_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_cron_yearly" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Group Who Owns cron.yearly</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/cron.yearly</html:code>, run the command:

  <html:pre>$ sudo chgrp root /etc/cron.yearly</html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.7</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should be owned by the
correct group to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_cron_yearly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
find -P /etc/cron.yearly/ -maxdepth 0 -type d  ! -group 0 -exec chgrp --no-dereference "$newgroup" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_cron_yearly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_groupowner_cron_yearly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_cron_yearly_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_cron_yearly_newgroup: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_groupowner_cron_yearly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/cron.yearly/
  ansible.builtin.file:
    path: /etc/cron.yearly/
    follow: false
    state: directory
    group: '{{ file_groupowner_cron_yearly_newgroup }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_groupowner_cron_yearly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_cron_yearly:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_cron_yearly_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_crontab" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Group Who Owns Crontab</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/crontab</html:code>, run the command:

  <html:pre>$ sudo chgrp root /etc/crontab</html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.2</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should be owned by the
correct group to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_crontab" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/crontab" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/crontab
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_crontab" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_crontab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_crontab_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_crontab_newgroup: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_crontab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/crontab
  ansible.builtin.stat:
    path: /etc/crontab
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_crontab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/crontab
  ansible.builtin.file:
    path: /etc/crontab
    follow: false
    group: '{{ file_groupowner_crontab_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_crontab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_crontab:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_crontab_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_cron_d" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Owner on cron.d</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the owner of <html:code>/etc/cron.d</html:code>, run the command:

  <html:pre>$ sudo chown root /etc/cron.d </html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.8</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should be owned by the
correct user to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_cron_d" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
find -P /etc/cron.d/ -maxdepth 0 -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_cron_d" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_cron_d_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_cron_d_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /etc/cron.d/
  ansible.builtin.file:
    path: /etc/cron.d/
    follow: false
    state: directory
    owner: '{{ file_owner_cron_d_newown }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_cron_d:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_cron_d_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_cron_daily" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Owner on cron.daily</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the owner of <html:code>/etc/cron.daily</html:code>, run the command:

  <html:pre>$ sudo chown root /etc/cron.daily </html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.4</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should be owned by the
correct user to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_cron_daily" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
find -P /etc/cron.daily/ -maxdepth 0 -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_cron_daily" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_daily
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_cron_daily_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_cron_daily_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_daily
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /etc/cron.daily/
  ansible.builtin.file:
    path: /etc/cron.daily/
    follow: false
    state: directory
    owner: '{{ file_owner_cron_daily_newown }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_daily
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_cron_daily:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_cron_daily_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_cron_hourly" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Owner on cron.hourly</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the owner of <html:code>/etc/cron.hourly</html:code>, run the command:

  <html:pre>$ sudo chown root /etc/cron.hourly </html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should be owned by the
correct user to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_cron_hourly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
find -P /etc/cron.hourly/ -maxdepth 0 -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_cron_hourly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_hourly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_cron_hourly_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_cron_hourly_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_hourly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /etc/cron.hourly/
  ansible.builtin.file:
    path: /etc/cron.hourly/
    follow: false
    state: directory
    owner: '{{ file_owner_cron_hourly_newown }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_hourly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_cron_hourly:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_cron_hourly_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_cron_monthly" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Owner on cron.monthly</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the owner of <html:code>/etc/cron.monthly</html:code>, run the command:

  <html:pre>$ sudo chown root /etc/cron.monthly </html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.6</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should be owned by the
correct user to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_cron_monthly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
find -P /etc/cron.monthly/ -maxdepth 0 -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_cron_monthly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_monthly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_cron_monthly_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_cron_monthly_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_monthly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /etc/cron.monthly/
  ansible.builtin.file:
    path: /etc/cron.monthly/
    follow: false
    state: directory
    owner: '{{ file_owner_cron_monthly_newown }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_monthly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_cron_monthly:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_cron_weekly" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Owner on cron.weekly</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the owner of <html:code>/etc/cron.weekly</html:code>, run the command:

  <html:pre>$ sudo chown root /etc/cron.weekly </html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.5</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should be owned by the
correct user to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_cron_weekly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
find -P /etc/cron.weekly/ -maxdepth 0 -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_cron_weekly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_weekly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_cron_weekly_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_cron_weekly_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_weekly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /etc/cron.weekly/
  ansible.builtin.file:
    path: /etc/cron.weekly/
    follow: false
    state: directory
    owner: '{{ file_owner_cron_weekly_newown }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_weekly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_cron_weekly:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_cron_weekly_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_cron_yearly" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Owner on cron.yearly</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the owner of <html:code>/etc/cron.yearly</html:code>, run the command:

  <html:pre>$ sudo chown root /etc/cron.yearly </html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.7</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should be owned by the
correct user to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_cron_yearly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
find -P /etc/cron.yearly/ -maxdepth 0 -type d  ! -user 0 -exec chown --no-dereference "$newown" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_cron_yearly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_owner_cron_yearly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_cron_yearly_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_cron_yearly_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_owner_cron_yearly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on directory /etc/cron.yearly/
  ansible.builtin.file:
    path: /etc/cron.yearly/
    follow: false
    state: directory
    owner: '{{ file_owner_cron_yearly_newown }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_owner_cron_yearly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_cron_yearly:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_cron_yearly_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_crontab" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Owner on crontab</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the owner of <html:code>/etc/crontab</html:code>, run the command:

  <html:pre>$ sudo chown root /etc/crontab </html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.2</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should be owned by the
correct user to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_crontab" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/crontab" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/crontab
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_crontab" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_crontab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_crontab_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_crontab_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_crontab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/crontab
  ansible.builtin.stat:
    path: /etc/crontab
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_crontab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/crontab
  ansible.builtin.file:
    path: /etc/crontab
    follow: false
    owner: '{{ file_owner_crontab_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_crontab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_crontab:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_crontab_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_cron_d" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Permissions on cron.d</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/cron.d</html:code>, run the command:
<html:pre>$ sudo chmod 0700 /etc/cron.d</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.8</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should have the
correct access rights to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_cron_d" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

find -H /etc/cron.d/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt -type d -exec chmod u-s,g-xwrs,o-xwrt {} \;

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_cron_d" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/cron.d/ file(s)
  ansible.builtin.command: 'find -P /etc/cron.d/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt  -type
    d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /etc/cron.d/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-xwrs,o-xwrt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_cron_d:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_cron_d_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_cron_daily" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Permissions on cron.daily</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/cron.daily</html:code>, run the command:
<html:pre>$ sudo chmod 0700 /etc/cron.daily</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.4</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should have the
correct access rights to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_cron_daily" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

find -H /etc/cron.daily/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt -type d -exec chmod u-s,g-xwrs,o-xwrt {} \;

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_cron_daily" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_daily
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/cron.daily/ file(s)
  ansible.builtin.command: 'find -P /etc/cron.daily/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt  -type
    d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_daily
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /etc/cron.daily/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-xwrs,o-xwrt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_daily
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_cron_daily:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_cron_daily_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_cron_hourly" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Permissions on cron.hourly</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/cron.hourly</html:code>, run the command:
<html:pre>$ sudo chmod 0700 /etc/cron.hourly</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should have the
correct access rights to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_cron_hourly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

find -H /etc/cron.hourly/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt -type d -exec chmod u-s,g-xwrs,o-xwrt {} \;

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_cron_hourly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_hourly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/cron.hourly/ file(s)
  ansible.builtin.command: 'find -P /etc/cron.hourly/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt  -type
    d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_hourly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /etc/cron.hourly/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-xwrs,o-xwrt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_hourly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_cron_hourly:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_cron_hourly_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_cron_monthly" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Permissions on cron.monthly</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/cron.monthly</html:code>, run the command:
<html:pre>$ sudo chmod 0700 /etc/cron.monthly</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.6</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should have the
correct access rights to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_cron_monthly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

find -H /etc/cron.monthly/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt -type d -exec chmod u-s,g-xwrs,o-xwrt {} \;

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_cron_monthly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_monthly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/cron.monthly/ file(s)
  ansible.builtin.command: 'find -P /etc/cron.monthly/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt  -type
    d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_monthly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /etc/cron.monthly/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-xwrs,o-xwrt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_monthly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_cron_monthly:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_cron_monthly_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_cron_weekly" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Permissions on cron.weekly</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/cron.weekly</html:code>, run the command:
<html:pre>$ sudo chmod 0700 /etc/cron.weekly</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.5</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should have the
correct access rights to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_cron_weekly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

find -H /etc/cron.weekly/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt -type d -exec chmod u-s,g-xwrs,o-xwrt {} \;

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_cron_weekly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_weekly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/cron.weekly/ file(s)
  ansible.builtin.command: 'find -P /etc/cron.weekly/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt  -type
    d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_weekly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /etc/cron.weekly/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-xwrs,o-xwrt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_weekly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_cron_weekly:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_cron_weekly_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_cron_yearly" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Permissions on cron.yearly</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/cron.yearly</html:code>, run the command:
<html:pre>$ sudo chmod 0700 /etc/cron.yearly</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.7</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should have the
correct access rights to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_cron_yearly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

find -H /etc/cron.yearly/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt -type d -exec chmod u-s,g-xwrs,o-xwrt {} \;

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_cron_yearly" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_cron_yearly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/cron.yearly/ file(s)
  ansible.builtin.command: 'find -P /etc/cron.yearly/ -maxdepth 0 -perm /u+s,g+xwrs,o+xwrt  -type
    d '
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_cron_yearly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /etc/cron.yearly/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-s,g-xwrs,o-xwrt
    state: directory
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_permissions_cron_yearly
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_cron_yearly:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_cron_yearly_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_crontab" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Permissions on crontab</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/crontab</html:code>, run the command:
<html:pre>$ sudo chmod 0600 /etc/crontab</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.2</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective services that if configured incorrectly
can lead to insecure and vulnerable configurations. Therefore, service configuration files should have the
correct access rights to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_crontab" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

chmod u-xs,g-xwrs,o-xwrt /etc/crontab

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_crontab" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_crontab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/crontab
  ansible.builtin.stat:
    path: /etc/crontab
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_crontab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xwrs,o-xwrt on /etc/crontab
  ansible.builtin.file:
    path: /etc/crontab
    mode: u-xs,g-xwrs,o-xwrt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_crontab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_crontab:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_restrict_at_cron_users">
            <xccdf-1.2:title>Restrict at and cron to Authorized Users if Necessary</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>/etc/cron.allow</html:code> and <html:code>/etc/at.allow</html:code> files contain lists of
users who are allowed to use <html:code>cron</html:code> and at to delay execution of
processes. If these files exist and if the corresponding files
<html:code>/etc/cron.deny</html:code> and <html:code>/etc/at.deny</html:code> do not exist, then only users
listed in the relevant allow files can run the crontab and <html:code>at</html:code> commands
to submit jobs to be run at scheduled intervals. On many systems, only the
system administrator needs the ability to schedule jobs. Note that even if a
given user is not listed in <html:code>cron.allow</html:code>, cron jobs can still be run as
that user. The <html:code>cron.allow</html:code> file controls only administrative access
to the crontab command for scheduling and modifying cron jobs.
<html:br/>
<html:br/>
To restrict <html:code>at</html:code> and <html:code>cron</html:code> to only authorized users:
<html:ul><html:li>Remove the <html:code>cron.deny</html:code> file:<html:pre>$ sudo rm /etc/cron.deny</html:pre></html:li><html:li>Edit <html:code>/etc/cron.allow</html:code>, adding one line for each user allowed to use
the crontab command to create cron jobs.</html:li><html:li>Remove the <html:code>at.deny</html:code> file:<html:pre>$ sudo rm /etc/at.deny</html:pre></html:li><html:li>Edit <html:code>/etc/at.allow</html:code>, adding one line for each user allowed to use
the at command to create at jobs.</html:li></html:ul></xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_at_allow_exists" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure that /etc/at.allow exists</xccdf-1.2:title>
              <xccdf-1.2:description>The file <html:code>/etc/at.allow</html:code> should exist and should be used instead
of <html:code>/etc/at.deny</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Using the at.allow file to control who can run at jobs enforces this who can schedule jobs.
It is easier to manage an allow list than a deny list. </xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_at_allow_exists" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

touch /etc/at.allow
    chown 0 /etc/at.allow
    chmod 0640 /etc/at.allow

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_at_allow_exists" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - file_at_allow_exists
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure that /etc/at.allow exists - Add empty /etc/at.allow
  ansible.builtin.file:
    path: /etc/at.allow
    state: touch
    owner: '0'
    mode: '0640'
    modification_time: preserve
    access_time: preserve
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - file_at_allow_exists
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_at_allow_exists:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_at_allow_exists_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_at_deny_not_exist" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure that /etc/at.deny does not exist</xccdf-1.2:title>
              <xccdf-1.2:description>The file <html:code>/etc/at.deny</html:code> should not exist.
Use <html:code>/etc/at.allow</html:code> instead.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Access to <html:code>at</html:code> should be restricted.
It is easier to manage an allow list than a deny list.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_at_deny_not_exist" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [[ -f  /etc/at.deny ]]; then
        rm /etc/at.deny
    fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_at_deny_not_exist" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - disable_strategy
  - file_at_deny_not_exist
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure that /etc/at.deny does not exist - Remove /etc/at.deny
  ansible.builtin.file:
    path: /etc/at.deny
    state: absent
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - disable_strategy
  - file_at_deny_not_exist
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_at_deny_not_exist:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_cron_allow_exists" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure that /etc/cron.allow exists</xccdf-1.2:title>
              <xccdf-1.2:description>The file <html:code>/etc/cron.allow</html:code> should exist and should be used instead
of <html:code>/etc/cron.deny</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.9</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Access to <html:code>crontab</html:code> should be restricted.
It is easier to manage an allow list than a deny list.
Therefore, <html:code>/etc/cron.allow</html:code> needs to be created and used instead of <html:code>/etc/cron.deny</html:code>.
Regardless of the existence of any of these files, the root administrative user is always allowed to setup a crontab.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_cron_allow_exists" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

touch /etc/cron.allow
    chown 0 /etc/cron.allow
    chmod 0640 /etc/cron.allow

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_cron_allow_exists" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - file_cron_allow_exists
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure that /etc/cron.allow exists - Add empty /etc/cron.allow
  ansible.builtin.file:
    path: /etc/cron.allow
    state: touch
    owner: '0'
    mode: '0640'
    modification_time: preserve
    access_time: preserve
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - file_cron_allow_exists
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_cron_allow_exists:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_cron_allow_exists_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_cron_deny_not_exist" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure that /etc/cron.deny does not exist</xccdf-1.2:title>
              <xccdf-1.2:description>The file <html:code>/etc/cron.deny</html:code> should not exist.
Use <html:code>/etc/cron.allow</html:code> instead.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.9</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Access to <html:code>cron</html:code> should be restricted.
It is easier to manage an allow list than a deny list.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_cron_deny_not_exist" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [[ -f  /etc/cron.deny ]]; then
        rm /etc/cron.deny
    fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_cron_deny_not_exist" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - disable_strategy
  - file_cron_deny_not_exist
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure that /etc/cron.deny does not exist - Remove /etc/cron.deny
  ansible.builtin.file:
    path: /etc/cron.deny
    state: absent
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - disable_strategy
  - file_cron_deny_not_exist
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_cron_deny_not_exist:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_cron_deny_not_exist_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_at_allow" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Group Who Owns /etc/at.allow file</xccdf-1.2:title>
              <xccdf-1.2:description>If <html:code>/etc/at.allow</html:code> exists, it must be group-owned by <html:code>root</html:code>.
To properly set the group owner of <html:code>/etc/at.allow</html:code>, run the command:

  <html:pre>$ sudo chgrp root /etc/at.allow</html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If the owner of the at.allow file is not set to root, the possibility exists for an
unauthorized user to view or edit sensitive information.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_at_allow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/at.allow" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/at.allow
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_at_allow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_at_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_at_allow_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_at_allow_newgroup: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_at_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/at.allow
  ansible.builtin.stat:
    path: /etc/at.allow
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_at_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/at.allow
  ansible.builtin.file:
    path: /etc/at.allow
    follow: false
    group: '{{ file_groupowner_at_allow_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_at_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_at_allow:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_at_allow_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_cron_allow" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Group Who Owns /etc/cron.allow file</xccdf-1.2:title>
              <xccdf-1.2:description>If <html:code>/etc/cron.allow</html:code> exists, it must be group-owned by <html:code>root</html:code>.
To properly set the group owner of <html:code>/etc/cron.allow</html:code>, run the command:

  <html:pre>$ sudo chgrp root /etc/cron.allow</html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.9</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If the owner of the cron.allow file is not set to root, the possibility exists for an
unauthorized user to view or edit sensitive information.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_cron_allow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/cron.allow" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/cron.allow
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_cron_allow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_cron_allow_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_cron_allow_newgroup: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/cron.allow
  ansible.builtin.stat:
    path: /etc/cron.allow
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/cron.allow
  ansible.builtin.file:
    path: /etc/cron.allow
    follow: false
    group: '{{ file_groupowner_cron_allow_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_groupowner_cron_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_cron_allow:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_cron_allow_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_at_allow" selected="false" severity="medium">
              <xccdf-1.2:title>Verify User Who Owns /etc/at.allow file</xccdf-1.2:title>
              <xccdf-1.2:description>If <html:code>/etc/at.allow</html:code> exists, it must be owned by <html:code>root</html:code>.
To properly set the owner of <html:code>/etc/at.allow</html:code>, run the command:

  <html:pre>$ sudo chown root /etc/at.allow </html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If the owner of the at.allow file is not set to root, the possibility exists for an
unauthorized user to view or edit sensitive information.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_at_allow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/at.allow" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/at.allow
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_at_allow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_at_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_at_allow_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_at_allow_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_at_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/at.allow
  ansible.builtin.stat:
    path: /etc/at.allow
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_at_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/at.allow
  ansible.builtin.file:
    path: /etc/at.allow
    follow: false
    owner: '{{ file_owner_at_allow_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_at_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_at_allow:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_at_allow_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_cron_allow" selected="false" severity="medium">
              <xccdf-1.2:title>Verify User Who Owns /etc/cron.allow file</xccdf-1.2:title>
              <xccdf-1.2:description>If <html:code>/etc/cron.allow</html:code> exists, it must be owned by <html:code>root</html:code>.
To properly set the owner of <html:code>/etc/cron.allow</html:code>, run the command:

  <html:pre>$ sudo chown root /etc/cron.allow </html:pre>
  </xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.9</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If the owner of the cron.allow file is not set to root, the possibility exists for an
unauthorized user to view or edit sensitive information.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_cron_allow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/cron.allow" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/cron.allow
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_cron_allow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_cron_allow_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_cron_allow_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/cron.allow
  ansible.builtin.stat:
    path: /etc/cron.allow
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/cron.allow
  ansible.builtin.file:
    path: /etc/cron.allow
    follow: false
    owner: '{{ file_owner_cron_allow_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_owner_cron_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_cron_allow:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_cron_allow_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_at_allow" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Permissions on /etc/at.allow file</xccdf-1.2:title>
              <xccdf-1.2:description>If <html:code>/etc/at.allow</html:code> exists, it must have permissions <html:code>0640</html:code>
or more restrictive.

To properly set the permissions of <html:code>/etc/at.allow</html:code>, run the command:
<html:pre>$ sudo chmod 0640 /etc/at.allow</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If the permissions of the at.allow file are not set to 0640 or more restrictive,
the possibility exists for an unauthorized user to view or edit sensitive information.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_at_allow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

chmod u-xs,g-xws,o-xwrt /etc/at.allow

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_at_allow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_at_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/at.allow
  ansible.builtin.stat:
    path: /etc/at.allow
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_at_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xws,o-xwrt on /etc/at.allow
  ansible.builtin.file:
    path: /etc/at.allow
    mode: u-xs,g-xws,o-xwrt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_at_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_at_allow:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_cron_allow" selected="false" severity="medium">
              <xccdf-1.2:title>Verify Permissions on /etc/cron.allow file</xccdf-1.2:title>
              <xccdf-1.2:description>If <html:code>/etc/cron.allow</html:code> exists, it must have permissions <html:code>0640</html:code>
or more restrictive.

To properly set the permissions of <html:code>/etc/cron.allow</html:code>, run the command:
<html:pre>$ sudo chmod 0640 /etc/cron.allow</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.4.1.9</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If the permissions of the cron.allow file are not set to 0640 or more restrictive,
the possibility exists for an unauthorized user to view or edit sensitive information.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_cron_allow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

chmod u-xs,g-xws,o-xwrt /etc/cron.allow

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_cron_allow" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/cron.allow
  ansible.builtin.stat:
    path: /etc/cron.allow
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xws,o-xwrt on /etc/cron.allow
  ansible.builtin.file:
    path: /etc/cron.allow
    mode: u-xs,g-xws,o-xwrt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_cron_allow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_cron_allow:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_cron_allow_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_deprecated">
          <xccdf-1.2:title>Deprecated services</xccdf-1.2:title>
          <xccdf-1.2:description>Some deprecated software services impact the overall system security due to their behavior (leak of
confidentiality in network exchange, usage as uncontrolled communication channel, risk associated with the service due to its old age, etc.</xccdf-1.2:description>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_inetutils-telnetd_removed" selected="false" severity="high">
            <xccdf-1.2:title>Uninstall the inet-based telnet server</xccdf-1.2:title>
            <xccdf-1.2:description>The inet-based telnet daemon should be uninstalled.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:rationale><html:code>telnet</html:code> allows clear text communications, and does not protect any
data transmission between client and server. Any confidential data can be
listened and no integrity checking is made.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_inetutils-telnetd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove inetutils-telnetd
# from the system, and may remove any packages
# that depend on inetutils-telnetd. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "inetutils-telnetd" ; then
yum remove -y "inetutils-telnetd"
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_inetutils-telnetd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall the inet-based telnet server: Ensure inetutils-telnetd is removed'
  ansible.builtin.package:
    name: inetutils-telnetd
    state: absent
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_inetutils-telnetd_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_inetutils-telnetd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_inetutils-telnetd

class remove_inetutils-telnetd {
  package { 'inetutils-telnetd':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_inetutils-telnetd_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=inetutils-telnetd
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_inetutils-telnetd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove inetutils-telnetd
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_inetutils-telnetd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove inetutils-telnetd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_inetutils-telnetd_removed:def:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_nis_removed" selected="false" severity="low">
            <xccdf-1.2:title>Uninstall the nis package</xccdf-1.2:title>
            <xccdf-1.2:description>The support for Yellowpages should not be installed unless it is required.</xccdf-1.2:description>
            <xccdf-1.2:rationale>NIS is the historical SUN service for central account management, more and more replaced by LDAP.
NIS does not support efficiently security constraints, ACL, etc. and should not be used.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_nis_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove nis
# from the system, and may remove any packages
# that depend on nis. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "nis" ; then
yum remove -y "nis"
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_nis_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall the nis package: Ensure nis is removed'
  ansible.builtin.package:
    name: nis
    state: absent
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_nis_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_nis_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_nis

class remove_nis {
  package { 'nis':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_nis_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=nis
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_nis_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove nis
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_nis_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove nis
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_nis_removed:def:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_ntpdate_removed" selected="false" severity="low">
            <xccdf-1.2:title>Uninstall the ntpdate package</xccdf-1.2:title>
            <xccdf-1.2:description>ntpdate is a historical ntp synchronization client for unixes. It should be uninstalled.</xccdf-1.2:description>
            <xccdf-1.2:rationale>ntpdate is an old not security-compliant ntp client. It should be replaced by modern ntp clients such as ntpd, able to use cryptographic mechanisms integrated in NTP.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ntpdate_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove ntpdate
# from the system, and may remove any packages
# that depend on ntpdate. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "ntpdate" ; then
yum remove -y "ntpdate"
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ntpdate_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall the ntpdate package: Ensure ntpdate is removed'
  ansible.builtin.package:
    name: ntpdate
    state: absent
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_ntpdate_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ntpdate_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_ntpdate

class remove_ntpdate {
  package { 'ntpdate':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ntpdate_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=ntpdate
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ntpdate_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove ntpdate
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ntpdate_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove ntpdate
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_ntpdate_removed:def:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_telnetd-ssl_removed" selected="false" severity="high">
            <xccdf-1.2:title>Uninstall the ssl compliant telnet server</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>telnet</html:code> daemon, even with ssl support, should be uninstalled.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:rationale><html:code>telnet</html:code>, even with ssl support, should not be installed.
When remote shell is required, up-to-date ssh daemon can be used.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnetd-ssl_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove telnetd-ssl
# from the system, and may remove any packages
# that depend on telnetd-ssl. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "telnetd-ssl" ; then
yum remove -y "telnetd-ssl"
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnetd-ssl_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall the ssl compliant telnet server: Ensure telnetd-ssl is removed'
  ansible.builtin.package:
    name: telnetd-ssl
    state: absent
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_telnetd-ssl_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnetd-ssl_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_telnetd-ssl

class remove_telnetd-ssl {
  package { 'telnetd-ssl':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnetd-ssl_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=telnetd-ssl
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnetd-ssl_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove telnetd-ssl
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnetd-ssl_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove telnetd-ssl
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_telnetd-ssl_removed:def:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_telnetd_removed" selected="false" severity="high">
            <xccdf-1.2:title>Uninstall the telnet server</xccdf-1.2:title>
            <xccdf-1.2:description>The telnet daemon should be uninstalled.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:rationale><html:code>telnet</html:code> allows clear text communications, and does not protect
any data transmission between client and server. Any confidential data
can be listened and no integrity checking is made.'</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnetd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove telnetd
# from the system, and may remove any packages
# that depend on telnetd. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "telnetd" ; then
yum remove -y "telnetd"
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnetd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall the telnet server: Ensure telnetd is removed'
  ansible.builtin.package:
    name: telnetd
    state: absent
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_telnetd_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnetd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_telnetd

class remove_telnetd {
  package { 'telnetd':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnetd_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=telnetd
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnetd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove telnetd
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnetd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove telnetd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_telnetd_removed:def:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_dhcp">
          <xccdf-1.2:title>DHCP</xccdf-1.2:title>
          <xccdf-1.2:description>The Dynamic Host Configuration Protocol (DHCP) allows
systems to request and obtain an IP address and other configuration
parameters from a server.
<html:br/><html:br/>
This guide recommends configuring networking on clients by manually editing
the appropriate files under <html:code>/etc/sysconfig</html:code>.  Use of DHCP can make client 
systems vulnerable to compromise by rogue DHCP servers, and should be avoided 
unless necessary.  If using DHCP is necessary, however, there are best practices 
that should be followed to minimize security risk.</xccdf-1.2:description>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_dhcp_client_configuration">
            <xccdf-1.2:title>Configure DHCP Client if Necessary</xccdf-1.2:title>
            <xccdf-1.2:description>If DHCP must be used, then certain configuration changes can
minimize the amount of information it receives and applies from the network,
and thus the amount of incorrect information a rogue DHCP server could
successfully distribute.  For more information on configuring dhclient, see the
<html:code>dhclient(8)</html:code> and <html:code>dhclient.conf(5)</html:code> man pages.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dhcp_client_restrict_options" selected="false" severity="unknown">
              <xccdf-1.2:title>Minimize the DHCP-Configured Options</xccdf-1.2:title>
              <xccdf-1.2:description>Create the file <html:code>/etc/dhcp/dhclient.conf</html:code>, and add an
appropriate setting for each of the ten configuration settings which can be
obtained via DHCP. For each setting, do one of the following:
<html:br/>
If the setting should <html:i>not</html:i> be configured remotely by the DHCP server,
select an appropriate static value, and add the line:
<html:pre>supersede <html:code>setting value</html:code>;</html:pre>
If the setting should be configured remotely by the DHCP server, add the lines:
<html:pre>request <html:code>setting</html:code>;
require <html:code>setting</html:code>;</html:pre>
For example, suppose the DHCP server should provide only the IP address itself
and the subnet mask. Then the entire file should look like:
<html:pre>supersede domain-name "example.com";
supersede domain-name-servers 192.168.1.2;
supersede nis-domain "";
supersede nis-servers "";
supersede ntp-servers "ntp.example.com ";
supersede routers 192.168.1.1;
supersede time-offset -18000;
request subnet-mask;
require subnet-mask;</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">In this example, the options nis-servers and
nis-domain are set to empty strings, on the assumption that the deprecated NIS
protocol is not in use. It is necessary to supersede settings for unused
services so that they cannot be set by a hostile DHCP server. If an option is
set to an empty string, dhclient will typically not attempt to configure the
service.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>By default, the DHCP client program, dhclient, requests and applies
ten configuration options (in addition to the IP address) from the DHCP server.
subnet-mask, broadcast-address, time-offset, routers, domain-name,
domain-name-servers, host-name, nis-domain, nis-servers, and ntp-servers.  Many
of the options requested and applied by dhclient may be the same for every
system on a network. It is recommended that almost all configuration options be
assigned statically, and only options which must vary on a host-by-host basis
be assigned via DHCP. This limits the damage which can be done by a rogue DHCP
server.  If appropriate for your site, it is also possible to supersede the
host-name directive in <html:code>/etc/dhcp/dhclient.conf</html:code>, establishing a static
hostname for the system. However, dhclient does not use the host name option
provided by the DHCP server (instead using the value provided by a reverse DNS
lookup).</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_dhcp_server_configuration">
            <xccdf-1.2:title>Configure DHCP Server</xccdf-1.2:title>
            <xccdf-1.2:description>If the system must act as a DHCP server, the configuration
information it serves should be minimized. Also, support for other protocols
and DNS-updating schemes should be explicitly disabled unless needed. The
configuration file for dhcpd is called <html:code>/etc/dhcp/dhcpd.conf</html:code>. The file
begins with a number of global configuration options. The remainder of the file
is divided into sections, one for each block of addresses offered by dhcpd,
each of which contains configuration options specific to that address
block.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dhcp_server_configure_logging" selected="false" severity="unknown">
              <xccdf-1.2:title>Configure Logging</xccdf-1.2:title>
              <xccdf-1.2:description>Ensure that the following line exists in
<html:code>/etc/rsyslog.conf</html:code>:
<html:pre>daemon.*           /var/log/daemon.log</html:pre>
Configure logwatch or other log monitoring tools to summarize error conditions
reported by the dhcpd process.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>By default, dhcpd logs notices to the daemon facility. Sending all
daemon messages to a dedicated log file is part of the syslog configuration
outlined in the Logging and Auditing section</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dhcp_server_deny_bootp" selected="false" severity="unknown">
              <xccdf-1.2:title>Deny BOOTP Queries</xccdf-1.2:title>
              <xccdf-1.2:description>Unless your network needs to support older BOOTP clients, disable
support for the bootp protocol by adding or correcting the global option:
<html:pre>deny bootp;</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The bootp option tells dhcpd to respond to BOOTP queries. If support
for this simpler protocol is not needed, it should be disabled to remove attack
vectors against the DHCP server.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dhcp_server_deny_decline" selected="false" severity="unknown">
              <xccdf-1.2:title>Deny Decline Messages</xccdf-1.2:title>
              <xccdf-1.2:description>Edit <html:code>/etc/dhcp/dhcpd.conf</html:code> and add or correct the following
global option to prevent the DHCP server from responding the DHCPDECLINE
messages, if possible: <html:pre>deny declines;</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The DHCPDECLINE message can be sent by a DHCP client to indicate
that it does not consider the lease offered by the server to be valid. By
issuing many DHCPDECLINE messages, a malicious client can exhaust the DHCP
server's pool of IP addresses, causing the DHCP server to forget old address
allocations.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dhcp_server_disable_ddns" selected="false" severity="unknown">
              <xccdf-1.2:title>Do Not Use Dynamic DNS</xccdf-1.2:title>
              <xccdf-1.2:description>To prevent the DHCP server from receiving DNS information from
clients, edit <html:code>/etc/dhcp/dhcpd.conf</html:code>, and add or correct the following global
option: <html:pre>ddns-update-style none;</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">The ddns-update-style option controls only whether
the DHCP server will attempt to act as a Dynamic DNS client. As long as the DNS
server itself is correctly configured to reject DDNS attempts, an incorrect
ddns-update-style setting on the client is harmless (but should be fixed as a
best practice).</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The Dynamic DNS protocol is used to remotely update the data served
by a DNS server. DHCP servers can use Dynamic DNS to publish information about
their clients. This setup carries security risks, and its use is not
recommended.  If Dynamic DNS must be used despite the risks it poses, it is
critical that Dynamic DNS transactions be protected using TSIG or some other
cryptographic authentication mechanism. See dhcpd.conf(5) for more information
about protecting the DHCP server from passing along malicious DNS data from its
clients.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dhcp_server_minimize_served_info" selected="false" severity="unknown">
              <xccdf-1.2:title>Minimize Served Information</xccdf-1.2:title>
              <xccdf-1.2:description>Edit /etc/dhcp/dhcpd.conf. Examine each address range section within
the file, and ensure that the following options are not defined unless there is
an operational need to provide this information via DHCP:
<html:pre>option domain-name
option domain-name-servers
option nis-domain
option nis-servers
option ntp-servers
option routers
option time-offset</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">By default, the Red Hat Enterprise Linux client installation uses DHCP
to request much of the above information from the DHCP server. In particular,
domain-name, domain-name-servers, and routers are configured via DHCP.  These
settings are typically necessary for proper network functionality, but are also
usually static across systems at a given site.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Because the configuration information provided by the DHCP server
could be maliciously provided to clients by a rogue DHCP server, the amount of
information provided via DHCP should be minimized. Remove these definitions
from the DHCP server configuration to ensure that legitimate clients do not
unnecessarily rely on DHCP for this information.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_dhcp_client">
            <xccdf-1.2:title>Disable DHCP Client</xccdf-1.2:title>
            <xccdf-1.2:description>DHCP is the default network configuration method provided by the system
installer, and common on many networks. Nevertheless, manual management
of IP addresses for systems implies a greater degree of management and
accountability for network activity.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sysconfig_networking_bootproto_ifcfg" selected="false" severity="unknown">
              <xccdf-1.2:title>Disable DHCP Client in ifcfg</xccdf-1.2:title>
              <xccdf-1.2:description>For each interface on the system (e.g. eth0), edit
<html:code>/etc/sysconfig/network-scripts/ifcfg-<html:i>interface</html:i></html:code> and make the
following changes:
<html:ul><html:li> Correct the BOOTPROTO line to read:
<html:pre>BOOTPROTO=none</html:pre>
</html:li><html:li> Add or correct the following lines, substituting the appropriate
values based on your site's addressing scheme:
<html:pre>NETMASK=255.255.255.0
IPADDR=192.168.1.2
GATEWAY=192.168.1.1</html:pre>
</html:li></html:ul></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>DHCP relies on trusting the local network. If the local network is not trusted,
then it should not be used.  However, the automatic configuration provided by
DHCP is commonly used and the alternative, manual configuration, presents an
unacceptable burden in many circumstances.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="sysconfig_networking_bootproto_ifcfg" system="urn:xccdf:fix:script:sh">
for config_file in /etc/sysconfig/network-scripts/ifcfg-*; do
	if grep -q ^BOOTPROTO= $config_file; then
		sed -i 's/^BOOTPROTO=.*/BOOTPROTO=none/' $config_file
	else
		echo BOOTPROTO=none &gt;&gt;$config_file
	fi
done
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sysconfig_networking_bootproto_ifcfg:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sysconfig_networking_bootproto_ifcfg_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_dhcp_server">
            <xccdf-1.2:title>Disable DHCP Server</xccdf-1.2:title>
            <xccdf-1.2:description>The DHCP server <html:code>dhcpd</html:code> is not installed or activated by
default. If the software was installed and activated, but the
system does not need to act as a DHCP server, it should be disabled
and removed.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_dhcp_removed" selected="false" severity="medium">
              <xccdf-1.2:title>Uninstall DHCP Server Package</xccdf-1.2:title>
              <xccdf-1.2:description>If the system does not need to act as a DHCP server,
the dhcp package can be uninstalled.
The <html:code>dhcp</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase dhcp</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R62</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Removing the DHCP server ensures that it cannot be easily or
accidentally reactivated and disrupt network operation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dhcp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove dhcp
# from the system, and may remove any packages
# that depend on dhcp. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "dhcp" ; then
yum remove -y "dhcp"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dhcp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall DHCP Server Package: Ensure dhcp is removed'
  ansible.builtin.package:
    name: dhcp
    state: absent
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_dhcp_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dhcp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_dhcp

class remove_dhcp {
  package { 'dhcp':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dhcp_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=dhcp
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dhcp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove dhcp
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dhcp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove dhcp
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_dhcp_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_dhcp_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_dhcpd_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable DHCP Service</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>dhcpd</html:code> service should be disabled on
any system that does not need to act as a DHCP server.


The <html:code>dhcpd</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now dhcpd.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unmanaged or unintentionally activated DHCP servers may provide faulty information
to clients, interfering with the operation of a legitimate site
DHCP server if there is one.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_dhcpd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'dhcpd.service'
fi
"$SYSTEMCTL_EXEC" disable 'dhcpd.service'
"$SYSTEMCTL_EXEC" mask 'dhcpd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files dhcpd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'dhcpd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'dhcpd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'dhcpd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_dhcpd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_dhcpd_disabled

- name: Disable DHCP Service - Disable service dhcpd
  block:

  - name: Disable DHCP Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable DHCP Service - Ensure dhcpd.service is Masked
    ansible.builtin.systemd:
      name: dhcpd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("dhcpd.service", multiline=True)

  - name: Unit Socket Exists - dhcpd.socket
    ansible.builtin.command: systemctl -q list-unit-files dhcpd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable DHCP Service - Disable Socket dhcpd
    ansible.builtin.systemd:
      name: dhcpd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("dhcpd.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_dhcpd_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_dhcpd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_dhcpd

class disable_dhcpd {
  service {'dhcpd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_dhcpd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: dhcpd.service
        enabled: false
        mask: true
      - name: dhcpd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_dhcpd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["dhcpd"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_dhcpd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable dhcpd
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_dhcpd_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_dhcpd_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_dns">
          <xccdf-1.2:title>DNS Server</xccdf-1.2:title>
          <xccdf-1.2:description>Most organizations have an operational need to run at
least one nameserver. However, there are many common attacks
involving DNS server software, and this server software should
be disabled on any system
on which it is not needed.</xccdf-1.2:description>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_dnsmasq_removed" selected="false" severity="low">
            <xccdf-1.2:title>Uninstall dnsmasq Package</xccdf-1.2:title>
            <xccdf-1.2:description>dnsmasq is a lightweight tool that provides DNS caching, DNS forwarding and
DHCP (Dynamic Host Configuration Protocol) services.
<html:br/>
The <html:code>dnsmasq</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase dnsmasq</html:pre></xccdf-1.2:description>
            <xccdf-1.2:rationale>Unless a system is specifically designated to act as a DNS
caching, DNS forwarding and/or DHCP server, it is recommended that the
package be removed to reduce the potential attack surface.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnsmasq_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove dnsmasq
# from the system, and may remove any packages
# that depend on dnsmasq. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "dnsmasq" ; then
yum remove -y "dnsmasq"
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnsmasq_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall dnsmasq Package: Ensure dnsmasq is removed'
  ansible.builtin.package:
    name: dnsmasq
    state: absent
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_dnsmasq_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnsmasq_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_dnsmasq

class remove_dnsmasq {
  package { 'dnsmasq':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnsmasq_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=dnsmasq
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnsmasq_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove dnsmasq
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_dnsmasq_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove dnsmasq
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_dnsmasq_removed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_dnsmasq_removed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_dnsmasq_disabled" selected="false" severity="medium">
            <xccdf-1.2:title>Disable dnsmasq Service</xccdf-1.2:title>
            <xccdf-1.2:description>
The <html:code>dnsmasq</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now dnsmasq.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.6</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Unless a system is specifically designated to act as a DNS
caching, DNS forwarding and/or DHCP server, it is recommended
that the package be removed to reduce the potential attack surface.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_dnsmasq_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'dnsmasq.service'
fi
"$SYSTEMCTL_EXEC" disable 'dnsmasq.service'
"$SYSTEMCTL_EXEC" mask 'dnsmasq.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files dnsmasq.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'dnsmasq.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'dnsmasq.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'dnsmasq.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_dnsmasq_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_dnsmasq_disabled

- name: Disable dnsmasq Service - Disable service dnsmasq
  block:

  - name: Disable dnsmasq Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable dnsmasq Service - Ensure dnsmasq.service is Masked
    ansible.builtin.systemd:
      name: dnsmasq.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("dnsmasq.service", multiline=True)

  - name: Unit Socket Exists - dnsmasq.socket
    ansible.builtin.command: systemctl -q list-unit-files dnsmasq.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable dnsmasq Service - Disable Socket dnsmasq
    ansible.builtin.systemd:
      name: dnsmasq.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("dnsmasq.socket", multiline=True)
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_dnsmasq_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_dnsmasq_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_dnsmasq

class disable_dnsmasq {
  service {'dnsmasq':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_dnsmasq_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: dnsmasq.service
        enabled: false
        mask: true
      - name: dnsmasq.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_dnsmasq_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["dnsmasq"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_dnsmasq_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable dnsmasq
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_dnsmasq_disabled:def:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_dns_server">
            <xccdf-1.2:title>Disable DNS Server</xccdf-1.2:title>
            <xccdf-1.2:description>DNS software should be disabled on any systems which does not
need to be a nameserver. Note that the BIND DNS server software is
not installed on AlmaLinux OS 8 by default. The remainder of this section
discusses secure configuration of systems which must be
nameservers.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_bind_removed" selected="false" severity="low">
              <xccdf-1.2:title>Uninstall bind Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>named</html:code> service is provided by the <html:code>bind</html:code> package.
The <html:code>bind</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase bind</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.5</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If there is no need to make DNS server software available,
removing it provides a safeguard against its activation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_bind_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove bind
# from the system, and may remove any packages
# that depend on bind. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "bind" ; then
yum remove -y "bind"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_bind_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall bind Package: Ensure bind is removed'
  ansible.builtin.package:
    name: bind
    state: absent
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_bind_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_bind_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_bind

class remove_bind {
  package { 'bind':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_bind_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=bind
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_bind_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove bind
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_bind_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove bind
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_bind_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_bind_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_named_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable named Service</xccdf-1.2:title>
              <xccdf-1.2:description>
The <html:code>named</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now named.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>All network services involve some risk of compromise due to
implementation flaws and should be disabled if possible.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_named_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'named.service'
fi
"$SYSTEMCTL_EXEC" disable 'named.service'
"$SYSTEMCTL_EXEC" mask 'named.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files named.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'named.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'named.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'named.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_named_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_named_disabled

- name: Disable named Service - Disable service named
  block:

  - name: Disable named Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable named Service - Ensure named.service is Masked
    ansible.builtin.systemd:
      name: named.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("named.service", multiline=True)

  - name: Unit Socket Exists - named.socket
    ansible.builtin.command: systemctl -q list-unit-files named.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable named Service - Disable Socket named
    ansible.builtin.systemd:
      name: named.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("named.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_named_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_named_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_named

class disable_named {
  service {'named':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_named_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: named.service
        enabled: false
        mask: true
      - name: named.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_named_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["named"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_named_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable named
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_named_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_named_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_dns_server_protection">
            <xccdf-1.2:title>Protect DNS Data from Tampering or Attack</xccdf-1.2:title>
            <xccdf-1.2:description>This section discusses DNS configuration options which make it
more difficult for attackers to gain access to private DNS data or to modify
DNS data.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dns_server_authenticate_zone_transfers" selected="false" severity="medium">
              <xccdf-1.2:title>Authenticate Zone Transfers</xccdf-1.2:title>
              <xccdf-1.2:description>If it is necessary for a secondary nameserver to receive zone data
via zone transfer from the primary server, follow the instructions here.  Use
dnssec-keygen to create a symmetric key file in the current directory:
<html:pre>$ cd /tmp
$ sudo dnssec-keygen -a HMAC-MD5 -b 128 -n HOST dns.example.com
Kdns.example.com .+aaa +iiiii</html:pre>
This output is the name of a file containing the new key. Read the file to find
the base64-encoded key string:
<html:pre>$ sudo cat Kdns.example.com .+NNN +MMMMM .key
dns.example.com IN KEY 512 3 157 base64-key-string</html:pre>
Add the directives to <html:code>/etc/named.conf</html:code> on the primary server:
<html:pre>key zone-transfer-key {
  algorithm hmac-md5;
  secret "base64-key-string ";
};
zone "example.com " IN {
  type master;
  allow-transfer { key zone-transfer-key; };
  ...
};</html:pre>
Add the directives below to <html:code>/etc/named.conf</html:code> on the secondary nameserver:
<html:pre>key zone-transfer-key {
  algorithm hmac-md5;
  secret "base64-key-string ";
};

server IP-OF-MASTER {
  keys { zone-transfer-key; };
};

zone "example.com " IN {
  type slave;
  masters { IP-OF-MASTER ; };
  ...
};</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">The purpose of the dnssec-keygen command is to
create the shared secret string base64-key-string. Once this secret has been
obtained and inserted into named.conf on the primary and secondary servers, the
key files Kdns.example.com .+NNN +MMMMM .key and Kdns.example.com .+NNN +MMMMM
.private are no longer needed, and may safely be deleted.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The BIND transaction signature (TSIG) functionality allows primary
and secondary nameservers to use a shared secret to verify authorization to
perform zone transfers. This method is more secure than using IP-based limiting
to restrict nameserver access, since IP addresses can be easily spoofed.
However, if you cannot configure TSIG between your servers because, for
instance, the secondary nameserver is not under your control and its
administrators are unwilling to configure TSIG, you can configure an
allow-transfer directive with numerical IP addresses or ACLs as a last resort.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dns_server_disable_dynamic_updates" selected="false" severity="unknown">
              <xccdf-1.2:title>Disable Dynamic Updates</xccdf-1.2:title>
              <xccdf-1.2:description>Is there a mission-critical reason to enable the risky dynamic
update functionality? If not, edit <html:code>/etc/named.conf</html:code>. For each zone
specification, correct the following directive if necessary:
<html:pre>zone "example.com " IN {
  allow-update { none; };
  ...
};</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>Dynamic updates allow remote servers to add, delete, or modify any
entries in your zone file. Therefore, they should be considered highly risky,
and disabled unless there is a very good reason for their use. If dynamic
updates must be allowed, IP-based ACLs are insufficient protection, since they
are easily spoofed. Instead, use TSIG keys (see the previous section for an
example), and consider using the update-policy directive to restrict changes to
only the precise type of change needed.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dns_server_disable_zone_transfers" selected="false" severity="unknown">
              <xccdf-1.2:title>Disable Zone Transfers from the Nameserver</xccdf-1.2:title>
              <xccdf-1.2:description>Is it necessary for a secondary nameserver to receive zone data
via zone transfer from the primary server?  If not, follow the instructions in
this section. If so, see the next section for instructions on protecting zone
transfers.
Add or correct the following directive within <html:code>/etc/named.conf</html:code>:
<html:pre>options {
  allow-transfer { none; };
  ...
}</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>If both the primary and secondary nameserver are under your control,
or if you have only one nameserver, it may be possible to use an external
configuration management mechanism to distribute zone updates. In that case, it
is not necessary to allow zone transfers within BIND itself, so they should be
disabled to avoid the potential for abuse.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_fapolicyd">
          <xccdf-1.2:title>Application Whitelisting Daemon</xccdf-1.2:title>
          <xccdf-1.2:description>Fapolicyd (File Access Policy Daemon) implements application whitelisting
to decide file access rights. Applications that are known via a reputation
source are allowed access while unknown applications are not. The daemon
makes use of the kernel's <html:code>fanotify</html:code> interface to determine file access rights.</xccdf-1.2:description>
          <xccdf-1.2:platform idref="#system_with_kernel"/>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_fapolicyd_installed" selected="false" severity="medium">
            <xccdf-1.2:title>Install fapolicyd Package</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>fapolicyd</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install fapolicyd</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-4(22)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000370-GPOS-00155</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00230</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040135</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230523r958804_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale><html:code>fapolicyd</html:code> (File Access Policy Daemon)
implements application whitelisting to decide file access rights.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_fapolicyd_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "fapolicyd" ; then
    yum install -y "fapolicyd"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_fapolicyd_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040135
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-4(22)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_fapolicyd_installed

- name: Ensure fapolicyd is installed
  ansible.builtin.package:
    name: fapolicyd
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040135
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-4(22)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_fapolicyd_installed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_fapolicyd_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_fapolicyd

class install_fapolicyd {
  package { 'fapolicyd':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_fapolicyd_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=fapolicyd
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_fapolicyd_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "fapolicyd"
version = "*"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_fapolicyd_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install fapolicyd
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_fapolicyd_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install fapolicyd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_fapolicyd_installed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_fapolicyd_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_fapolicyd_enabled" selected="false" severity="medium">
            <xccdf-1.2:title>Enable the File Access Policy Service</xccdf-1.2:title>
            <xccdf-1.2:description>The File Access Policy service should be enabled.

The <html:code>fapolicyd</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable fapolicyd.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-4(22)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000370-GPOS-00155</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00230</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040136</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244545r958804_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The <html:code>fapolicyd</html:code> service (File Access Policy Daemon)
implements application whitelisting to decide file access rights.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_fapolicyd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'fapolicyd.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'fapolicyd.service'
fi
"$SYSTEMCTL_EXEC" enable 'fapolicyd.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_fapolicyd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040136
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-4(22)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_fapolicyd_enabled

- name: Enable the File Access Policy Service - Enable service fapolicyd
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable the File Access Policy Service - Enable Service fapolicyd
    ansible.builtin.systemd:
      name: fapolicyd
      enabled: true
      state: started
      masked: false
    when:
    - '"fapolicyd" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040136
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-4(22)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_fapolicyd_enabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_fapolicyd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_fapolicyd

class enable_fapolicyd {
  service {'fapolicyd':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_fapolicyd_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["fapolicyd"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_fapolicyd_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable fapolicyd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_fapolicyd_enabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_fapolicyd_enabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_fapolicy_default_deny" selected="false" severity="medium">
            <xccdf-1.2:title>Configure Fapolicy Module to Employ a Deny-all, Permit-by-exception Policy to Allow the Execution of Authorized Software Programs.</xccdf-1.2:title>
            <xccdf-1.2:description>The Fapolicy module must be configured to employ a deny-all, permit-by-exception policy to
allow the execution of authorized software programs and to prevent unauthorized software from
running.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7 (2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7 (5) (b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6 b</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000368-GPOS-00154</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000370-GPOS-00155</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00232</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040137</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244546r1017349_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Utilizing a whitelist provides a configuration management method for allowing the execution of
only authorized software.
Using only authorized software decreases risk by limiting the number of potential
vulnerabilities.
Verification of whitelisted software occurs prior to execution or at system startup.

Proceed with caution with enforcing the use of this daemon.
Improper configuration may render the system non-functional.
The "fapolicyd" API is not namespace aware and can cause issues when launching or running
containers.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="fapolicy_default_deny" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &gt; /etc/fapolicyd/rules.d/99-deny-everything.rules &lt;&lt; EOF
# Red Hat KCS 7003854 (https://access.redhat.com/solutions/7003854)
deny perm=any all : all
EOF

chmod 644 /etc/fapolicyd/rules.d/99-deny-everything.rules
chgrp fapolicyd /etc/fapolicyd/rules.d/99-deny-everything.rules

if [ -e "/etc/fapolicyd/fapolicyd.conf" ] ; then
    
    LC_ALL=C sed -i "/^\s*permissive\s*=\s*/Id" "/etc/fapolicyd/fapolicyd.conf"
else
    touch "/etc/fapolicyd/fapolicyd.conf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/fapolicyd/fapolicyd.conf"

cp "/etc/fapolicyd/fapolicyd.conf" "/etc/fapolicyd/fapolicyd.conf.bak"
# Insert at the end of the file
printf '%s\n' "permissive = 0" &gt;&gt; "/etc/fapolicyd/fapolicyd.conf"
# Clean up after ourselves.
rm "/etc/fapolicyd/fapolicyd.conf.bak"

systemctl restart fapolicyd

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="fapolicy_default_deny" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040137
  - NIST-800-53-CM-6 b
  - NIST-800-53-CM-7 (2)
  - NIST-800-53-CM-7 (5) (b)
  - fapolicy_default_deny
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Fapolicy Module to Employ a Deny-all, Permit-by-exception Policy
    to Allow the Execution of Authorized Software Programs. - Gather the package facts
  ansible.builtin.package_facts:
    manager: auto
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040137
  - NIST-800-53-CM-6 b
  - NIST-800-53-CM-7 (2)
  - NIST-800-53-CM-7 (5) (b)
  - fapolicy_default_deny
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Fapolicy Module to Employ a Deny-all, Permit-by-exception Policy
    to Allow the Execution of Authorized Software Programs. - Ensure a Final Rule
    Denying Everything
  ansible.builtin.copy:
    content: |
      # Red Hat KCS 7003854 (https://access.redhat.com/solutions/7003854)
      deny perm=any all : all
    dest: /etc/fapolicyd/rules.d/99-deny-everything.rules
    owner: root
    group: fapolicyd
    mode: '0644'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"fapolicyd" in ansible_facts.packages'
  register: result_fapolicyd_final_rule
  tags:
  - DISA-STIG-RHEL-08-040137
  - NIST-800-53-CM-6 b
  - NIST-800-53-CM-7 (2)
  - NIST-800-53-CM-7 (5) (b)
  - fapolicy_default_deny
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Fapolicy Module to Employ a Deny-all, Permit-by-exception Policy
    to Allow the Execution of Authorized Software Programs. - Ensure fapolicyd is
    Not Permissive
  ansible.builtin.lineinfile:
    path: /etc/fapolicyd/fapolicyd.conf
    regexp: ^(permissive\s*=).*$
    line: \1 0
    backrefs: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"fapolicyd" in ansible_facts.packages'
  register: result_fapolicyd_enforced
  tags:
  - DISA-STIG-RHEL-08-040137
  - NIST-800-53-CM-6 b
  - NIST-800-53-CM-7 (2)
  - NIST-800-53-CM-7 (5) (b)
  - fapolicy_default_deny
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Fapolicy Module to Employ a Deny-all, Permit-by-exception Policy
    to Allow the Execution of Authorized Software Programs. - Restart fapolicyd If
    Permissive Mode or Final Rule is Changed
  ansible.builtin.service:
    name: fapolicyd
    state: restarted
  when:
  - '"kernel" in ansible_facts.packages'
  - '"fapolicyd" in ansible_facts.packages'
  - result_fapolicyd_final_rule is changed or result_fapolicyd_enforced is changed
  tags:
  - DISA-STIG-RHEL-08-040137
  - NIST-800-53-CM-6 b
  - NIST-800-53-CM-7 (2)
  - NIST-800-53-CM-7 (5) (b)
  - fapolicy_default_deny
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-fapolicy_default_deny:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-fapolicy_default_deny_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_fapolicyd_prevent_home_folder_access" selected="false" severity="medium">
            <xccdf-1.2:title>fapolicyd Must be Configured to Limit Access to Users Home Folders</xccdf-1.2:title>
            <xccdf-1.2:description>fapolicyd needs be configured so that users cannot give access to their home folders to other users.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">This rule is deprecated and there is no replacement at this time.
Previous versions of this rule provided fixtext that would cause fapolicyd not to start.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6 b</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00230</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Users' home directories/folders may contain information of a sensitive nature.
Non-privileged users should coordinate any sharing of information with a System Administrator (SA) through shared resources.
fapolicyd can confine users to their home directory, not allowing them to make any changes outside of their own home directories.
Confining users to their home directory will minimize the risk of sharing information.</xccdf-1.2:rationale>
          </xccdf-1.2:Rule>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_ftp">
          <xccdf-1.2:title>FTP Server</xccdf-1.2:title>
          <xccdf-1.2:description>FTP is a common method for allowing remote access to
files. Like telnet, the FTP protocol is unencrypted, which means
that passwords and other data transmitted during the session can be
captured and that the session is vulnerable to hijacking.
Therefore, running the FTP server software is not recommended.
<html:br/><html:br/>
However, there are some FTP server configurations which may
be appropriate for some environments, particularly those which
allow only read-only anonymous access as a means of downloading
data available to the public.</xccdf-1.2:description>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_ftp_removed" selected="false" severity="low">
            <xccdf-1.2:title>Remove ftp Package</xccdf-1.2:title>
            <xccdf-1.2:description>FTP (File Transfer Protocol) is a traditional and widely used standard tool for
transferring files between a server and clients over a network, especially where no
authentication is necessary (permits anonymous users to connect to a server).
<html:br/>
The <html:code>ftp</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase ftp</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.2.1</xccdf-1.2:reference>
            <xccdf-1.2:rationale>FTP does not protect the confidentiality of data or authentication credentials. It
is recommended SFTP be used if file transfer is required. Unless there is a need
to run the system as a FTP server (for example, to allow anonymous downloads), it is
recommended that the package be removed to reduce the potential attack surface.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ftp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove ftp
# from the system, and may remove any packages
# that depend on ftp. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "ftp" ; then
yum remove -y "ftp"
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ftp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Remove ftp Package: Ensure ftp is removed'
  ansible.builtin.package:
    name: ftp
    state: absent
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_ftp_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ftp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_ftp

class remove_ftp {
  package { 'ftp':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ftp_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=ftp
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ftp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove ftp
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ftp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove ftp
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_ftp_removed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_ftp_removed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_vsftpd">
            <xccdf-1.2:title>Disable vsftpd if Possible</xccdf-1.2:title>
            <xccdf-1.2:description>To minimize attack surface, disable vsftpd if at all
possible.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_vsftpd_removed" selected="false" severity="high">
              <xccdf-1.2:title>Uninstall vsftpd Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>vsftpd</html:code> package can be removed with the following command: <html:pre> $ sudo yum erase vsftpd</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1).1(v)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7.1(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000074-GPOS-00042</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040360</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230558r1017320_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Removing the <html:code>vsftpd</html:code> package decreases the risk of its
accidental activation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vsftpd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove vsftpd
# from the system, and may remove any packages
# that depend on vsftpd. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "vsftpd" ; then
yum remove -y "vsftpd"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vsftpd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall vsftpd Package: Ensure vsftpd is removed'
  ansible.builtin.package:
    name: vsftpd
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040360
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-CM-7.1(ii)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-IA-5(1).1(v)
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_vsftpd_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vsftpd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_vsftpd

class remove_vsftpd {
  package { 'vsftpd':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vsftpd_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=vsftpd
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vsftpd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove vsftpd
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vsftpd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove vsftpd
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_vsftpd_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_vsftpd_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_vsftpd_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable vsftpd Service</xccdf-1.2:title>
              <xccdf-1.2:description>
The <html:code>vsftpd</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now vsftpd.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Running FTP server software provides a network-based avenue
of attack, and should be disabled if not needed.
Furthermore, the FTP protocol is unencrypted and creates
a risk of compromising sensitive information.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_vsftpd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'vsftpd.service'
fi
"$SYSTEMCTL_EXEC" disable 'vsftpd.service'
"$SYSTEMCTL_EXEC" mask 'vsftpd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files vsftpd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'vsftpd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'vsftpd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'vsftpd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_vsftpd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_vsftpd_disabled

- name: Disable vsftpd Service - Disable service vsftpd
  block:

  - name: Disable vsftpd Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable vsftpd Service - Ensure vsftpd.service is Masked
    ansible.builtin.systemd:
      name: vsftpd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("vsftpd.service", multiline=True)

  - name: Unit Socket Exists - vsftpd.socket
    ansible.builtin.command: systemctl -q list-unit-files vsftpd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable vsftpd Service - Disable Socket vsftpd
    ansible.builtin.systemd:
      name: vsftpd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("vsftpd.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_vsftpd_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_vsftpd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_vsftpd

class disable_vsftpd {
  service {'vsftpd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_vsftpd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: vsftpd.service
        enabled: false
        mask: true
      - name: vsftpd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_vsftpd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["vsftpd"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_vsftpd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable vsftpd
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_vsftpd_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_vsftpd_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd">
            <xccdf-1.2:title>Configure vsftpd to Provide FTP Service if Necessary</xccdf-1.2:title>
            <xccdf-1.2:description>The primary vsftpd configuration file is
<html:code>/etc/vsftpd.conf</html:code>, if that file exists, or
<html:code>/etc/vsftpd/vsftpd.conf</html:code> if it does not.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ftp_configure_firewall" selected="false" severity="unknown">
              <xccdf-1.2:title>Configure Firewalls to Protect the FTP Server</xccdf-1.2:title>
              <xccdf-1.2:description>By default, <html:code>iptables</html:code>
blocks access to the ports used by the web server.

To configure <html:code>iptables</html:code> to allow port 21 traffic, one must edit
<html:code>/etc/sysconfig/iptables</html:code> and
<html:code>/etc/sysconfig/ip6tables</html:code> (if IPv6 is in use).
Add the following line, ensuring that it appears before the final LOG and DROP lines for the INPUT chain:
<html:pre>-A INPUT -m state --state NEW -p tcp --dport 21 -j ACCEPT</html:pre>
Edit the file <html:code>/etc/sysconfig/iptables-config</html:code>. Ensure that the space-separated list of modules contains
the FTP connection tracking module:
<html:pre>IPTABLES_MODULES="ip_conntrack_ftp"</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>These settings configure the firewall to allow connections to an FTP server.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ftp_disable_uploads" selected="false" severity="unknown">
              <xccdf-1.2:title>Disable FTP Uploads if Possible</xccdf-1.2:title>
              <xccdf-1.2:description>Is there a mission-critical reason for users to upload files via FTP? If not,
edit the vsftpd configuration file to add or correct the following configuration options:
<html:pre>write_enable=NO</html:pre>
If FTP uploads are necessary, follow the guidance in the remainder of this section to secure these transactions
as much as possible.</xccdf-1.2:description>
              <xccdf-1.2:rationale>Anonymous FTP can be a convenient way to make files available for universal download. However, it is less
common to have a need to allow unauthenticated users to place files on the FTP server. If this must be done, it
is necessary to ensure that files cannot be uploaded and downloaded from the same directory.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ftp_home_partition" selected="false" severity="unknown">
              <xccdf-1.2:title>Place the FTP Home Directory on its Own Partition</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the anonymous FTP root is the home directory of the FTP user account. The df command can
be used to verify that this directory is on its own partition.</xccdf-1.2:description>
              <xccdf-1.2:rationale>If there is a mission-critical reason for anonymous users to upload files, precautions must be taken to prevent
these users from filling a disk used by other services.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ftp_log_transactions" selected="false" severity="unknown">
              <xccdf-1.2:title>Enable Logging of All FTP Transactions</xccdf-1.2:title>
              <xccdf-1.2:description>Add or correct the following configuration options within the <html:code>vsftpd</html:code>
configuration file, located at <html:code>/etc/vsftpd/vsftpd.conf</html:code>:
<html:pre>xferlog_enable=YES
xferlog_std_format=NO
log_ftp_protocol=YES</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">If verbose logging to <html:code>vsftpd.log</html:code> is done, sparse logging of
downloads to <html:code>/var/log/xferlog</html:code> will not also occur. However,
the information about what files were downloaded is included in the
information logged to <html:code>vsftpd.log</html:code>.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>To trace malicious activity facilitated by the FTP service, it must be configured to ensure that all commands sent to
the FTP server are logged using the verbose vsftpd log
format. The default vsftpd log file is <html:code>/var/log/vsftpd.log</html:code>.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ftp_log_transactions:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ftp_log_transactions_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ftp_present_banner" selected="false" severity="medium">
              <xccdf-1.2:title>Create Warning Banners for All FTP Users</xccdf-1.2:title>
              <xccdf-1.2:description>
Edit the vsftpd configuration file, which resides at <html:code>/etc/vsftpd/vsftpd.conf</html:code>

by default. Add or correct the following configuration options:
<html:pre>banner_file=/etc/issue</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>This setting will cause the system greeting banner to be used for FTP connections as well.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ftp_present_banner:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ftp_present_banner_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_ftp_restrict_users">
              <xccdf-1.2:title>Restrict the Set of Users Allowed to Access FTP</xccdf-1.2:title>
              <xccdf-1.2:description>This section describes how to disable non-anonymous (password-based) FTP logins, or, if it is not possible to
do this entirely due to legacy applications, how to restrict insecure FTP login to only those users who have an
identified need for this access.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ftp_limit_users" selected="false" severity="unknown">
                <xccdf-1.2:title>Limit Users Allowed FTP Access if Necessary</xccdf-1.2:title>
                <xccdf-1.2:description>If there is a mission-critical reason for users to access their accounts via the insecure FTP protocol, limit the set of users who are allowed this access. Edit the vsftpd configuration file. Add or correct the following configuration options:
<html:pre>userlist_enable=YES
userlist_file=/etc/vsftp.ftpusers
userlist_deny=NO</html:pre>
Edit the file <html:code>/etc/vsftp.ftpusers</html:code>. For each user USERNAME who should be allowed to access the system via FTP, add a line containing that user's name:
<html:pre>USERNAME</html:pre>
If anonymous access is also required, add the anonymous usernames to <html:code>/etc/vsftp.ftpusers</html:code> as well.
<html:pre>anonymous
ftp</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale>Historically, the file <html:code>/etc/ftpusers</html:code> contained a list of users who were not allowed to access the system via FTP. It was used to prevent system users such as the root user from logging in via the insecure FTP protocol. However, when the configuration option <html:code>userlist deny=NO</html:code> is set, vsftpd interprets ftpusers as the set of users who are allowed to login via FTP. Since it should be possible for most users to access their accounts via secure protocols, it is recommended that this setting be used, so that non-anonymous FTP access can be limited to legacy users who have been explicitly identified.</xccdf-1.2:rationale>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ftp_restrict_to_anon" selected="false" severity="medium">
                <xccdf-1.2:title>Restrict Access to Anonymous Users if Possible</xccdf-1.2:title>
                <xccdf-1.2:description>Is there a mission-critical reason for users to transfer files to/from their own accounts
using FTP, rather than using a secure protocol like SCP/SFTP? If not, edit the vsftpd
configuration file. Add or correct the following configuration option:

<html:pre>local_enable=NO</html:pre>

If non-anonymous FTP logins are necessary, follow the guidance in the remainder of
this section to secure these logins as much as possible.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The use of non-anonymous FTP logins is strongly discouraged. Since SSH clients 
and servers are widely available, and since SSH provides support for a transfer
mode which resembles FTP in user interface, there is no good reason to allow
password-based FTP access.'</xccdf-1.2:rationale>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_ftp_use_vsftpd">
            <xccdf-1.2:title>Use vsftpd to Provide FTP Service if Necessary</xccdf-1.2:title>
            <xccdf-1.2:description>If your use-case requires FTP service, install and
set-up vsftpd to provide it.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_vsftpd_installed" selected="false" severity="low">
              <xccdf-1.2:title>Install vsftpd Package</xccdf-1.2:title>
              <xccdf-1.2:description>If this system must operate as an FTP server, install the <html:code>vsftpd</html:code> package via the standard channels.
The <html:code>vsftpd</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install vsftpd</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>After Red Hat Enterprise Linux 2.1, Red Hat switched from distributing <html:code>wu-ftpd</html:code> with
Red Hat Enterprise Linux to distributing <html:code>vsftpd</html:code>. For security
and for consistency with future Red Hat releases, the use of <html:code>vsftpd</html:code> is recommended.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vsftpd_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh">
if ! rpm -q --quiet "vsftpd" ; then
    yum install -y "vsftpd"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vsftpd_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Ensure vsftpd is installed
  ansible.builtin.package:
    name: vsftpd
    state: present
  tags:
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_vsftpd_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vsftpd_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_vsftpd

class install_vsftpd {
  package { 'vsftpd':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vsftpd_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=vsftpd
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_vsftpd_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "vsftpd"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vsftpd_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install vsftpd
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_vsftpd_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install vsftpd
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_vsftpd_installed:def:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_http">
          <xccdf-1.2:title>Web Server</xccdf-1.2:title>
          <xccdf-1.2:description>The web server is responsible for providing access to
content via the HTTP protocol. Web servers represent a significant
security risk because:
<html:br/><html:br/>
<html:ul><html:li>The HTTP port is commonly probed by malicious sources</html:li><html:li>Web server software is very complex, and includes a long
history of vulnerabilities</html:li><html:li>The HTTP protocol is unencrypted and vulnerable to passive
monitoring</html:li></html:ul>
<html:br/><html:br/>
The system's default web server software is Apache 2 and is
provided in the RPM package <html:code>httpd</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_httpd">
            <xccdf-1.2:title>Disable Apache if Possible</xccdf-1.2:title>
            <xccdf-1.2:description>If Apache was installed and activated, but the system
does not need to act as a web server, then it should be disabled
and removed from the system.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_httpd_removed" selected="false" severity="unknown">
              <xccdf-1.2:title>Uninstall httpd Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>httpd</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase httpd</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.19</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If there is no need to make the web server software available,
removing it provides a safeguard against its activation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_httpd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove httpd
# from the system, and may remove any packages
# that depend on httpd. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "httpd" ; then
yum remove -y "httpd"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_httpd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall httpd Package: Ensure httpd is removed'
  ansible.builtin.package:
    name: httpd
    state: absent
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_httpd_removed
  - unknown_severity
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_httpd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_httpd

class remove_httpd {
  package { 'httpd':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_httpd_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=httpd
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_httpd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove httpd
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_httpd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove httpd
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_httpd_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_httpd_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_httpd_disabled" selected="false" severity="unknown">
              <xccdf-1.2:title>Disable httpd Service</xccdf-1.2:title>
              <xccdf-1.2:description>
The <html:code>httpd</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now httpd.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Running web server software provides a network-based avenue
of attack, and should be disabled if not needed.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_httpd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'httpd.service'
fi
"$SYSTEMCTL_EXEC" disable 'httpd.service'
"$SYSTEMCTL_EXEC" mask 'httpd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files httpd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'httpd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'httpd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'httpd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_httpd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_httpd_disabled
  - unknown_severity

- name: Disable httpd Service - Disable service httpd
  block:

  - name: Disable httpd Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable httpd Service - Ensure httpd.service is Masked
    ansible.builtin.systemd:
      name: httpd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("httpd.service", multiline=True)

  - name: Unit Socket Exists - httpd.socket
    ansible.builtin.command: systemctl -q list-unit-files httpd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable httpd Service - Disable Socket httpd
    ansible.builtin.systemd:
      name: httpd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("httpd.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_httpd_disabled
  - special_service_block
  - unknown_severity
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_httpd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_httpd

class disable_httpd {
  service {'httpd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_httpd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: httpd.service
        enabled: false
        mask: true
      - name: httpd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_httpd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["httpd"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_httpd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable httpd
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_httpd_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_httpd_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_nginx">
            <xccdf-1.2:title>Disable NGINX if Possible</xccdf-1.2:title>
            <xccdf-1.2:description>If NGINX was installed and activated, but the system does not need to act as a web server,
then it should be removed from the system.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_nginx_removed" selected="false" severity="unknown">
              <xccdf-1.2:title>Uninstall nginx Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>nginx</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase nginx</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.19</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If there is no need to make the web server software available,
removing it provides a safeguard against its activation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nginx_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove nginx
# from the system, and may remove any packages
# that depend on nginx. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "nginx" ; then
yum remove -y "nginx"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nginx_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall nginx Package: Ensure nginx is removed'
  ansible.builtin.package:
    name: nginx
    state: absent
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_nginx_removed
  - unknown_severity
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nginx_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_nginx

class remove_nginx {
  package { 'nginx':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nginx_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=nginx
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nginx_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove nginx
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_nginx_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove nginx
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_nginx_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_nginx_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_securing_httpd">
            <xccdf-1.2:title>Secure Apache Configuration</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>httpd</html:code> configuration file is
<html:code>/etc/httpd/conf/httpd.conf</html:code>. Apply the recommendations in the remainder
of this section to this file.</xccdf-1.2:description>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_httpd_loglevel" type="string">
              <xccdf-1.2:title>HTTPD Log Level</xccdf-1.2:title>
              <xccdf-1.2:description>The setting for LogLevel in /etc/httpd/conf/httpd.conf</xccdf-1.2:description>
              <xccdf-1.2:value selector="alert">alert</xccdf-1.2:value>
              <xccdf-1.2:value selector="crit">crit</xccdf-1.2:value>
              <xccdf-1.2:value>warn</xccdf-1.2:value>
              <xccdf-1.2:value selector="emerg">emerg</xccdf-1.2:value>
              <xccdf-1.2:value selector="error">error</xccdf-1.2:value>
              <xccdf-1.2:value selector="warn">warn</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_max_keepalive_requests" type="number">
              <xccdf-1.2:title>Maximum KeepAlive Requests for HTTPD</xccdf-1.2:title>
              <xccdf-1.2:description>The setting for MaxKeepAliveRequests in httpd.conf</xccdf-1.2:description>
              <xccdf-1.2:value selector="100">100</xccdf-1.2:value>
              <xccdf-1.2:value selector="1000">1000</xccdf-1.2:value>
              <xccdf-1.2:value selector="10000">10000</xccdf-1.2:value>
              <xccdf-1.2:value selector="100000">100000</xccdf-1.2:value>
              <xccdf-1.2:value selector="500">500</xccdf-1.2:value>
              <xccdf-1.2:value>100</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_configure_log_format" selected="false" severity="medium">
              <xccdf-1.2:title>Configure Error Log Format</xccdf-1.2:title>
              <xccdf-1.2:description><html:code>LogFormat</html:code> should be enabled and set to the following in
<html:code>/etc/httpd/conf/httpd.conf</html:code>:
<html:pre>LogFormat "a %A %h %H %l %m %s %t %u %U \"%{Referer}i\" \"%{User-Agent}i\"" combined</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>The server error logs are invaluable because they can also be used to identify
potential problems and enable proactive remediation. Log data can reveal
anomalous behavior such as "not found" or "unauthorized" errors that may
be an evidence of attack attempts. Failure to enable error logging can
significantly reduce the ability of Web Administrators to detect or remediate
problems. The LogFormat directive defines the format and information to be
included in the access log entries.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_configure_log_format_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_configure_max_keepalive_requests" selected="false" severity="medium">
              <xccdf-1.2:title>Configure The Number of Allowed Simultaneous Requests</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>MaxKeepAliveRequests</html:code> directive should be set and configured to
<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_max_keepalive_requests" use="legacy"/> or greater by setting the following
in <html:code>/etc/httpd/conf/httpd.conf</html:code>:
<html:pre>MaxKeepAliveRequests <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_max_keepalive_requests" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>Resource exhaustion can occur when an unlimited number of concurrent requests
are allowed on a web site, facilitating a denial of service attack. Mitigating
this kind of attack will include limiting the number of concurrent HTTP/HTTPS
requests per IP address and may include, where feasible, limiting parameter
values associated with keepalive, (i.e., a parameter used to limit the amount of
time a connection may be inactive).</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_configure_max_keepalive_requests_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_disable_mime_types" selected="false" severity="medium">
              <xccdf-1.2:title>MIME types for csh or sh shell programs must be disabled</xccdf-1.2:title>
              <xccdf-1.2:description>Users must not be allowed to access the shell programs.</xccdf-1.2:description>
              <xccdf-1.2:rationale>Shell programs might execute shell escapes and could then perform
unauthorized activities that could damage the security posture of the web
server. A shell is a program that serves as the basic interface between the
user and the operating system. In this regard, there are shells that are
security risks in the context of a web server and shells that are
unauthorized.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_disable_mime_types_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_enable_error_logging" selected="false" severity="medium">
              <xccdf-1.2:title>Enable HTTPD Error Logging</xccdf-1.2:title>
              <xccdf-1.2:description><html:code>ErrorLog</html:code> should be enabled and set to the following in
<html:code>/etc/httpd/conf/httpd.conf</html:code>:
<html:pre>ErrorLog "logs/error_log"</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>The server error logs are invaluable because they can also be used to identify
potential problems and enable proactive remediation. Log data can reveal
anomalous behavior such as "not found" or "unauthorized" errors that may
be an evidence of attack attempts. Failure to enable error logging can
significantly reduce the ability of Web Administrators to detect or remediate
problems.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_enable_error_logging_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_enable_loglevel" selected="false" severity="medium">
              <xccdf-1.2:title>Enable HTTPD LogLevel</xccdf-1.2:title>
              <xccdf-1.2:description><html:code>LogLevel</html:code> should be enabled and set to <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_loglevel" use="legacy"/>.
Add or edit the following in <html:code>/etc/httpd/conf/httpd.conf</html:code>:
<html:pre>LogLevel <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_httpd_loglevel" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>The server error logs are invaluable because they can also be used to identify
potential problems and enable proactive remediation. Log data can reveal
anomalous behavior such as "not found" or "unauthorized" errors that may
be an evidence of attack attempts. Failure to enable error logging can
significantly reduce the ability of Web Administrators to detect or remediate
problems. While the ErrorLog directive configures the error log file name, the
LogLevel directive is used to configure the severity level for the error logs.
The log level values are the standard syslog levels: emerg, alert, crit, error,
warn, notice, info and debug.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_enable_loglevel_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_enable_system_logging" selected="false" severity="medium">
              <xccdf-1.2:title>Enable HTTPD System Logging</xccdf-1.2:title>
              <xccdf-1.2:description><html:code>CustomLog</html:code> should be enabled and set to the following in
<html:code>/etc/httpd/conf/httpd.conf</html:code>:
<html:pre>CustomLog "logs/access_log" combined</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>The server error logs are invaluable because they can also be used to identify
potential problems and enable proactive remediation. Log data can reveal
anomalous behavior such as "not found" or "unauthorized" errors that may
be an evidence of attack attempts. Failure to enable error logging can
significantly reduce the ability of Web Administrators to detect or remediate
problems. The CustomLog directive specifies the log file, syslog facility, or
piped logging utility.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_enable_system_logging_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_entrust_passwords" selected="false" severity="medium">
              <xccdf-1.2:title>The web server password(s) must be entrusted to the SA or Web Manager</xccdf-1.2:title>
              <xccdf-1.2:description>Normally, a service account is established for the web server. This is
because a privileged account is not desirable and the server is designed to
run for long uninterrupted periods of time. The SA or Web Manager will need
password access to the web server to restart the service in the event or an
emergency as the web server is not to restart automatically after an
unscheduled interruption.</xccdf-1.2:description>
              <xccdf-1.2:rationale>If the password is not entrusted to an SA or web manager the ability to
ensure the availability of the web server is compromised.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_entrust_passwords_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_nipr_accredited_dmz" selected="false" severity="medium">
              <xccdf-1.2:title>A public web server, if hosted on the NIPRNet, must be isolated in an accredited DoD DMZ extension</xccdf-1.2:title>
              <xccdf-1.2:description>To minimize exposure of private assets to unnecessary risk by attackers,
public web servers must be isolated from internal systems.

Logically relocate public web servers to be isolated from internal
systems. In addition, ensure the public web server does not have
trusted connections with assets outside the confines of the
demilitarizez done (DMZ) other than application and/or database servers
that are a part of the same system as the web server.</xccdf-1.2:description>
              <xccdf-1.2:rationale>Public web servers are by nature more vulnerabile to attack from publicly
based sources, such as the public Internet. Once compromised, a public
server might be used as a base for further attack on private resources,
unless additional layers of protection are implemented. Public web servers
must be located in a DoD DMZ Extension, if hosted on the NIPRNet, with
carefully controlled access. Failure to isolate resources in this way
increase risk that private assets are exposed to attacks from public
sources. An improperly located public web server is a potential
threat to the entire network.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_nipr_accredited_dmz_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_no_compilers_in_prod" selected="false" severity="medium">
              <xccdf-1.2:title>Installation of a compiler on production web server is prohibited</xccdf-1.2:title>
              <xccdf-1.2:description>The presence of a compiler on a production server facilitates the malicious
user's task of creating custom versions of programs and installing Trojan
Horses or viruses.</xccdf-1.2:description>
              <xccdf-1.2:rationale>An attacker's code could be uploaded and compiled on the server
under attack.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_no_compilers_in_prod_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_private_server_on_separate_subnet" selected="false" severity="medium">
              <xccdf-1.2:title>A private web server must be located on a separate controlled access subnet</xccdf-1.2:title>
              <xccdf-1.2:description>Private web servers, which host sites that serve controlled access data,
must be protected from outside threats in addition to insider threats.

Isolate the private web server from the public DMZ and separate it from the
internal general population LAN.</xccdf-1.2:description>
              <xccdf-1.2:rationale>Insider threat may be accidental or intentional but, in either case, can
cause a disruption in service of the web server. To protect the private
web server from these threats, it must be located on a separate controlled
access subnet and must not be part of the public DMZ that houses the public
web servers. it also cannot be located inside the enclave as part of the
local general population LAN.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_private_server_on_separate_subnet_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_public_resources_not_shared" selected="false" severity="medium">
              <xccdf-1.2:title>Public web server resources must not be shared with private assets</xccdf-1.2:title>
              <xccdf-1.2:description>It is important to segregate public web server resources from private
resources located behind a DMZ in order to protect private
assets.</xccdf-1.2:description>
              <xccdf-1.2:rationale>When folders, drives, or other resources are directly shared between the
public web server and private servers the intent of data and resource
segregation can be compromised.

In addition to the requirements of the DoD Internet-NIPRNet DMZ STIG that
isolates inbound traffic from external network to the internal network,
resources such as printers, files, and folders/directories will not be
shared between public web servers and assets located within the internal
network.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_public_resources_not_shared_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_remove_backups" selected="false" severity="medium">
              <xccdf-1.2:title>Backup interactive scripts on the production web server are prohibited</xccdf-1.2:title>
              <xccdf-1.2:description>Copies of backup files will not execute on the server, but they can be
read by the anonymous user if special precautions are not taken.</xccdf-1.2:description>
              <xccdf-1.2:rationale>Such backup copies contain the same sensitive information as the actual
scripts being executed and, as such, are useful to malicious users.
Techniques and systems exist today that search web servers for such files
and are able to exploit the information contained in them.

Backup copies of files are automatically created by some text editors such
such as emacs and VIM. Editors may write a backup file with an extension
~ added to the name of the original file. The edit plus editor will
create a .bak file. Of course, this would imply the presence and use of
development tools on the web server, which is a finding under WG130. Having
backup scripts on the web server provides one more opportunity for
malicious persons to view these scripts and use the information found in
them.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_remove_backups_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server">
              <xccdf-1.2:title>Configure Operating System to Protect Web Server</xccdf-1.2:title>
              <xccdf-1.2:description>The following configuration steps should be taken on the system which hosts the
web server, in order to provide as safe an environment as possible for the web server.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_antivirus_scan_uploads" selected="false" severity="medium">
                <xccdf-1.2:title>Scan All Uploaded Content for Malicious Software</xccdf-1.2:title>
                <xccdf-1.2:description>Install anti-virus software on the system and set it to automatically scan new
files that are introduced to the web server.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Remote web authors should not be able to upload files to the Document Root
directory structure without virus checking and checking for malicious or mobile
code. A remote web user, whose agency has a Memorandum of Agreement (MOA) with
the hosting agency and has submitted a DoD form 2875 (System Authorization
Access Request (SAAR)) or an equivalent document, will be allowed to post files
to a temporary location on the server. All posted files to this temporary
location will be scanned for viruses and content checked for malicious or mobile
code. Only files free of viruses and malicious or mobile code will be posted to
the appropriate DocumentRoot directory.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_antivirus_scan_uploads_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_configure_firewall" selected="false" severity="low">
                <xccdf-1.2:title>Configure firewall to Allow Access to the Web Server</xccdf-1.2:title>
                <xccdf-1.2:description>By default, <html:code>iptables</html:code>
blocks access to the ports used by the web server.
To configure <html:code>iptables</html:code> to allow port 80 traffic, one must edit
<html:code>/etc/sysconfig/iptables</html:code> and
<html:code>/etc/sysconfig/ip6tables</html:code> (if IPv6 is in use).
Add the following line, ensuring that it appears before the final LOG and DROP lines for the INPUT chain:
<html:pre>-A INPUT -m state --state NEW -p tcp --dport 80 -j ACCEPT</html:pre>
To configure <html:code>iptables</html:code> to allow port 443 traffic, one must edit
<html:code>/etc/sysconfig/iptables</html:code> and
<html:code>/etc/sysconfig/ip6tables</html:code> (if IPv6 is in use).
Add the following line, ensuring that it appears before the final LOG and DROP lines for the INPUT chain:
<html:pre>-A INPUT -m state --state NEW -p tcp --dport 443 -j ACCEPT</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale>Failure to properly manage and restricts ports, protocols, and services (PPS)
can result in compromise of enclave boundary protections and/or functionality
of the AIS.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_configure_firewall_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_configure_remote_session_encryption" selected="false" severity="high">
                <xccdf-1.2:title>Ensure Remote Administrative Access Is Encrypted</xccdf-1.2:title>
                <xccdf-1.2:description>Ensure that the SSH server service is enabled.

The <html:code>sshd</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable sshd.service</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale>Logging into a web server remotely using an unencrypted protocol or service
when performing updates and maintenance is a major risk. Data, such as user
account, is transmitted in plaintext and can easily be compromised. When
performing remote administrative tasks, a protocol or service that encrypts the
communication channel must be used.
<html:br/><html:br/>
An alternative to remote administration of
the web server is to perform web server administration locally at the console.
Local administration at the console implies physical access to the server.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_configure_remote_session_encryption_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access">
                <xccdf-1.2:title>Restrict File and Directory Access</xccdf-1.2:title>
                <xccdf-1.2:description>Minimize access to critical <html:code>httpd</html:code> files and directories.</xccdf-1.2:description>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dir_perms_etc_httpd_conf" selected="false" severity="unknown">
                  <xccdf-1.2:title>Set Permissions on the /etc/httpd/conf/ Directory</xccdf-1.2:title>
                  <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/http/conf</html:code>, run the command: <html:pre>$ sudo chmod 0750 /etc/http/conf</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:rationale>Access to the web server's configuration files may allow an unauthorized user or attacker
to access information about the web server or alter the server's configuration files.</xccdf-1.2:rationale>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dir_perms_etc_httpd_conf:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dir_perms_etc_httpd_conf_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dir_perms_var_log_httpd" selected="false" severity="medium">
                  <xccdf-1.2:title>Set Permissions on the /var/log/httpd/ Directory</xccdf-1.2:title>
                  <xccdf-1.2:description>Ensure that the permissions on the web server log directory is set to 700:
<html:pre>$ sudo chmod 700 /var/log/httpd/</html:pre>
This is its default setting.</xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>A major tool in exploring the web site use, attempted use, unusual conditions,
and problems are the access and error logs. In the event of a security incident,
these logs can provide the SA and the web manager with valuable information. To
ensure the integrity of the log files and protect the SA and the web manager
from a conflict of interest related to the maintenance of these files, only the
members of the Auditors group will be granted permissions to move, copy, and
delete these files in the course of their duties related to the archiving of
these files.</xccdf-1.2:rationale>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dir_perms_var_log_httpd:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-dir_perms_var_log_httpd_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_httpd_server_conf_d_files" selected="false" severity="unknown">
                  <xccdf-1.2:title>Set Permissions on All Configuration Files Inside /etc/httpd/conf.d/</xccdf-1.2:title>
                  <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/http/conf.d/*</html:code>, run the command: <html:pre>$ sudo chmod 0640 /etc/http/conf.d/*</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Access to the web server's configuration files may allow an unauthorized user or attacker
to access information about the web server or to alter the server's configuration files.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_httpd_server_conf_d_files" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



find -P /etc/httpd/conf.d/ -maxdepth 1 -perm /u+xs,g+xws,o+xwrt  -type f -regextype posix-extended -regex '^.*$' -exec chmod u-xs,g-xws,o-xwrt {} \;
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_httpd_server_conf_d_files" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Find /etc/httpd/conf.d/ file(s)
  ansible.builtin.command: find -P /etc/httpd/conf.d/ -maxdepth 1 -perm /u+xs,g+xws,o+xwrt  -type
    f -regextype posix-extended -regex "^.*$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - file_permissions_httpd_server_conf_d_files
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - unknown_severity

- name: Set permissions for /etc/httpd/conf.d/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-xs,g-xws,o-xwrt
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - file_permissions_httpd_server_conf_d_files
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - unknown_severity
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_httpd_server_conf_d_files:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_httpd_server_conf_d_files_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_httpd_server_conf_files" selected="false" severity="unknown">
                  <xccdf-1.2:title>Set Permissions on All Configuration Files Inside /etc/httpd/conf/</xccdf-1.2:title>
                  <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/http/conf/*</html:code>, run the command: <html:pre>$ sudo chmod 0640 /etc/http/conf/*</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Access to the web server's configuration files may allow an unauthorized user or attacker
to access information about the web server or to alter the server's configuration files.</xccdf-1.2:rationale>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_httpd_server_conf_files" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh">



find -P /etc/httpd/conf/ -maxdepth 1 -perm /u+xs,g+xws,o+xwrt  -type f -regextype posix-extended -regex '^.*$' -exec chmod u-xs,g-xws,o-xwrt {} \;
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_httpd_server_conf_files" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Find /etc/httpd/conf/ file(s)
  ansible.builtin.command: find -P /etc/httpd/conf/ -maxdepth 1 -perm /u+xs,g+xws,o+xwrt  -type
    f -regextype posix-extended -regex "^.*$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - file_permissions_httpd_server_conf_files
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - unknown_severity

- name: Set permissions for /etc/httpd/conf/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-xs,g-xws,o-xwrt
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  tags:
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - file_permissions_httpd_server_conf_files
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - unknown_severity
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_httpd_server_conf_files:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_httpd_server_conf_files_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_httpd_server_modules_files" selected="false" severity="unknown">
                  <xccdf-1.2:title>Set Permissions on All Configuration Files Inside /etc/httpd/conf.modules.d/</xccdf-1.2:title>
                  <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/http/conf.modules.d/*</html:code>, run the command: <html:pre>$ sudo chmod 0640 /etc/http/conf.modules.d/*</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>Access to the web server's configuration files may allow an unauthorized user or attacker
to access information about the web server or to alter the server's configuration files.</xccdf-1.2:rationale>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_httpd_server_modules_files:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_httpd_server_modules_files_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_http_configure_log_file_ownership" selected="false" severity="medium">
                  <xccdf-1.2:title>HTTPD Log Files Must Be Owned By Root</xccdf-1.2:title>
                  <xccdf-1.2:description>All <html:code>httpd</html:code> logs must be owned by root user and group. By default,
the path for httpd logs is <html:code>/var/log/httpd/</html:code>
To properly set the owner of <html:code>/var/log/httpd</html:code>, run the command:

  <html:pre>$ sudo chown root /var/log/httpd </html:pre>
  

To properly set the owner of <html:code>/var/log/httpd/*</html:code>, run the command:

  <html:pre>$ sudo chown root /var/log/httpd/* </html:pre>
  </xccdf-1.2:description>
                  <xccdf-1.2:rationale>A major tool in exploring the web site use, attempted use, unusual conditions,
and problems are the access and error logs. In the event of a security incident,
these logs can provide the SA and the web administrator with valuable
information. Because of the information that is captured in the logs, it is
critical that only authorized individuals have access to the logs.</xccdf-1.2:rationale>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-http_configure_log_file_ownership_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
              </xccdf-1.2:Group>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely">
              <xccdf-1.2:title>Configure PERL Securely</xccdf-1.2:title>
              <xccdf-1.2:description>PERL (Practical Extraction and Report Language) is an interpreted language
optimized for scanning arbitrary text files, extracting information from those
text files, and printing reports based on that information. The language is
often used in shell scripting and is intended to be practical, easy to use, and
efficient means of generating interactive web pages for the user.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_configure_perl_taint" selected="false" severity="medium">
                <xccdf-1.2:title>Configure HTTP PERL Scripts To Use TAINT Option</xccdf-1.2:title>
                <xccdf-1.2:description>If the <html:code>mod_perl</html:code> module is installed, enable Perl Taint checking in
<html:code>/etc/httpd/conf/httpd.conf</html:code>. To enable Perl Taint
checking, add or uncomment the following to <html:code>/etc/httpd/conf.d/perl.conf</html:code>:
<html:pre>PerlSwitches -T</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale>PERL (Practical Extraction and Report Language) is an interpreted language
optimized for scanning arbitrary text files, extracting information from those
text files, and printing reports based on that information. The language is
often used in shell scripting and is intended to be practical, easy to use, and
efficient means of generating interactive web pages for the user. Unfortunately,
many widely available freeware PERL programs (scripts) are extremely insecure.
This is most readily accomplished by a malicious user substituting input to a
PERL script during a POST or a GET operation.
<html:br/><html:br/>
Consequently, the founders of
PERL have developed a mechanism named TAINT that protects the system from
malicious input sent from outside the program. When the data is tainted, it
cannot be used in programs or functions such as eval(), system(), exec(), pipes,
or popen(). The script will exit with a warning message.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_configure_perl_taint_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_httpd_directory_restrictions">
              <xccdf-1.2:title>Directory Restrictions</xccdf-1.2:title>
              <xccdf-1.2:description>The Directory tags in the web server configuration file allow finer grained access
control for a specified directory. All web directories should be configured on a
case-by-case basis, allowing access only where needed.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_anonymous_content_sharing" selected="false" severity="medium">
                <xccdf-1.2:title>Web Content Directories Must Not Be Shared Anonymously</xccdf-1.2:title>
                <xccdf-1.2:description>Web content directories should not be shared anonymously over remote filesystems
such as <html:code>nfs</html:code> and <html:code>smb</html:code>. Remove the shares from the applicable
directories.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Sharing web content is a security risk when a web server is involved. Users
accessing the share anonymously could experience privileged access to the
content of such directories. Network sharable directories expose those
directories and their contents to unnecessary access. Any unnecessary exposure
increases the risk that someone could exploit that access and either compromises
the web content or cause web server performance problems.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_anonymous_content_sharing_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_configure_script_permissions" selected="false" severity="high">
                <xccdf-1.2:title>Remove Write Permissions From Filesystem Paths And Server Scripts</xccdf-1.2:title>
                <xccdf-1.2:description>Configure permissions for each instance of <html:code>Alias</html:code>,
<html:code>ScriptAlias</html:code>, and <html:code>ScriptAliasMatch</html:code> that exist.
<html:pre>$ sudo find <html:i>DIR</html:i> -type d -exec chmod 755 {} \;
$ sudo find <html:i>DIR</html:i> -type f -exec chmod 555 {} \;</html:pre>
Where <html:i>DIR</html:i> matches the paths from <html:code>Alias</html:code>,
<html:code>ScriptAlias</html:code>, and <html:code>ScriptAliasMatch</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Excessive permissions for the anonymous web user account are one of the most
common faults contributing to the compromise of a web server. If this user is
able to upload and execute files on the web server, the organization or owner of
the server will no longer have control of the asset.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_configure_script_permissions_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_disable_anonymous_ftp_access" selected="false" severity="medium">
                <xccdf-1.2:title>Disable Anonymous FTP Access</xccdf-1.2:title>
                <xccdf-1.2:description>If any directories that contain dynamic scripts can be accessed via FTP by
any group or user that does not require access, remove permissions to such
directories that allow anonymous access. Also, ensure that any such
access employs an encrypted connection.</xccdf-1.2:description>
                <xccdf-1.2:rationale>The directories containing the CGI scripts, such as PERL, must not be
accessible to anonymous users via FTP. This applies to all directories that
contain scripts that can dynamically produce web pages in an interactive manner
(i.e., scripts based upon user-provided input). Such scripts contain information
that could be used to compromise a web service, access system resources, or
deface a web site.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_disable_anonymous_ftp_access_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_ignore_htaccess_files" selected="false" severity="medium">
                <xccdf-1.2:title>Ignore HTTPD .htaccess Files</xccdf-1.2:title>
                <xccdf-1.2:description>Set <html:code>AllowOverride</html:code> to <html:code>none</html:code> for each instant of
<html:code>&lt;Directory&gt;</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:rationale>CGI scripts represents one of the most common and exploitable means of
compromising a web server. By definition, CGI are executable by the operating
system of the host server. While access control is provided via the web service,
the execution of CGI programs is not otherwise limited unless the SA or Web
Manager takes specific measures. CGI programs can access and alter data files,
launch other programs and use the network. CGI programs can be written in any
available programming language. C, PERL, PHP, Javascript, VBScript and shell
(sh, ksh, bash) are popular choices.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_ignore_htaccess_files_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_limit_available_methods" selected="false" severity="unknown">
                <xccdf-1.2:title>Limit Available Methods</xccdf-1.2:title>
                <xccdf-1.2:description>Web server methods are defined in section 9 of RFC 2616 (
    <html:a href="http://www.ietf.org/rfc/rfc2616.txt">http://www.ietf.org/rfc/rfc2616.txt</html:a>).
If a web server does not require the implementation of all available methods,
they should be disabled.
<html:br/><html:br/>
Note: <html:code>GET</html:code> and <html:code>POST</html:code> are the most common methods. A majority of the others
are limited to the WebDAV protocol.
<html:pre>&lt;Directory /var/www/html&gt;
# ...
   # Only allow specific methods (this command is case-sensitive!)
   &lt;LimitExcept GET POST&gt;
      Order allow,deny
   &lt;/LimitExcept&gt;
# ...
&lt;/Directory&gt;</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale>Minimizing the number of available methods to the web client reduces risk
by limiting the capabilities allowed by the web server.</xccdf-1.2:rationale>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_restrict_critical_directories" selected="false" severity="unknown">
                <xccdf-1.2:title>Restrict Other Critical Directories</xccdf-1.2:title>
                <xccdf-1.2:description>All accessible web directories should be configured with similarly restrictive settings.
The <html:code>Options</html:code> directive should be limited to necessary functionality and the <html:code>AllowOverride</html:code>
directive should be used only if needed. The <html:code>Order</html:code> and <html:code>Deny</html:code> access control tags
should be used to deny access by default, allowing access only where necessary.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Directories accessible from a web client should be configured with the least amount of
access possible in order to avoid unauthorized access to restricted content or server information.</xccdf-1.2:rationale>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_restrict_root_directory" selected="false" severity="unknown">
                <xccdf-1.2:title>Restrict Root Directory</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>httpd</html:code> root directory should always have the most restrictive configuration enabled.
<html:pre>&lt;Directory / &gt;
   Options None
   AllowOverride None
   Order allow,deny
&lt;/Directory&gt;</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale>The Web Server's root directory content should be protected from unauthorized access
by web clients.</xccdf-1.2:rationale>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_restrict_web_directory" selected="false" severity="unknown">
                <xccdf-1.2:title>Restrict Web Directory</xccdf-1.2:title>
                <xccdf-1.2:description>The default configuration for the web (<html:code>/var/www/html</html:code>) Directory allows directory
indexing (<html:code>Indexes</html:code>) and the following of symbolic links (<html:code>FollowSymLinks</html:code>).
Neither of these is recommended.
<html:br/><html:br/>
The <html:code>/var/www/html</html:code> directory hierarchy should not be viewable via the web, and
symlinks should only be followed if the owner of the symlink also owns the linked file.
<html:br/><html:br/>
Ensure that this policy is adhered to by altering the related section of the configuration:
<html:pre>&lt;Directory "/var/www/html"&gt;
#  ...
   Options SymLinksIfOwnerMatch
#  ...
&lt;/Directory&gt;</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale>Access to the web server's directory hierarchy could allow access to unauthorized files
by web clients. Following symbolic links could also allow such access.</xccdf-1.2:rationale>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules">
              <xccdf-1.2:title>Minimize Web Server Loadable Modules</xccdf-1.2:title>
              <xccdf-1.2:description>A default installation of <html:code>httpd</html:code> includes a plethora of dynamically shared objects (DSO)
that are loaded at run-time. Unlike the aforementioned compiled-in modules, a DSO can be
disabled in the configuration file by removing the corresponding LoadModule directive.
<html:br/><html:br/>
Note: A DSO only provides additional functionality if associated directives are included
in the <html:code>httpd</html:code> configuration file. It should also be noted that removing a DSO will produce
errors on <html:code>httpd</html:code> startup if the configuration file contains directives that apply to that
module. Refer to <html:code><html:a href="http://httpd.apache.org/docs/">http://httpd.apache.org/docs/</html:a></html:code> for details on which directives
are associated with each DSO.
<html:br/><html:br/>
Following each DSO removal, the configuration can be tested with the following command
to check if everything still works:
<html:pre>$ sudo service httpd configtest</html:pre>
The purpose of each of the modules loaded by default will now be addressed one at a time.
If none of a module's directives are being used, remove it.</xccdf-1.2:description>
              <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_httpd_core_modules">
                <xccdf-1.2:title>httpd Core Modules</xccdf-1.2:title>
                <xccdf-1.2:description>These modules comprise a basic subset of modules that are likely needed for base <html:code>httpd</html:code>
functionality; ensure they are not commented out in <html:code>/etc/httpd/conf/httpd.conf</html:code>:
<html:pre>LoadModule auth_basic_module modules/mod_auth_basic.so
LoadModule authn_default_module modules/mod_authn_default.so
LoadModule authz_host_module modules/mod_authz_host.so
LoadModule authz_user_module modules/mod_authz_user.so
LoadModule authz_groupfile_module modules/mod_authz_groupfile.so
LoadModule authz_default_module modules/mod_authz_default.so
LoadModule log_config_module modules/mod_log_config.so
LoadModule logio_module modules/mod_logio.so
LoadModule setenvif_module modules/mod_setenvif.so
LoadModule mime_module modules/mod_mome.so
LoadModule autoindex_module modules/mod_autoindex.so
LoadModule negotiation_module modules/mod_negotiation.so
LoadModule dir_module modules/mod_dir.so
LoadModule alias_module modules/mod_alias.so</html:pre>
Minimizing the number of loadable modules available to the web server reduces risk
by limiting the capabilities allowed by the web server.</xccdf-1.2:description>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_cache_support" selected="false" severity="unknown">
                  <xccdf-1.2:title>Disable Cache Support</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>cache</html:code> module allows <html:code>httpd</html:code> to cache data, optimizing access to
frequently accessed content. However, it introduces potential security flaws
such as the possibility of circumventing <html:code>Allow</html:code> and
<html:code>Deny</html:code> directives.
<html:br/><html:br/> If this functionality is
unnecessary, comment out the module:
<html:pre>#LoadModule cache_module modules/mod_cache.so</html:pre>
If caching is required, it should not be enabled for any limited-access content.</xccdf-1.2:description>
                  <xccdf-1.2:rationale>Minimizing the number of loadable modules available to the web server reduces risk
by limiting the capabilities allowed by the web server.</xccdf-1.2:rationale>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_cgi_support" selected="false" severity="unknown">
                  <xccdf-1.2:title>Disable CGI Support</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>cgi</html:code> module allows HTML to interact with the CGI web programming language.
<html:br/><html:br/>
If this functionality is unnecessary, comment out the module:
<html:pre>#LoadModule cgi_module modules/mod_cgi.so</html:pre>

If the web server requires the use of CGI, enable <html:code>mod_cgi</html:code>.</xccdf-1.2:description>
                  <xccdf-1.2:rationale>Minimizing the number of loadable modules available to the web server reduces risk
by limiting the capabilities allowed by the web server.</xccdf-1.2:rationale>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_digest_authentication" selected="false" severity="unknown">
                  <xccdf-1.2:title>Disable HTTP Digest Authentication</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>auth_digest</html:code> module provides encrypted authentication sessions.
If this functionality is unnecessary, comment out the related module:
<html:pre>#LoadModule auth_digest_module modules/mod_auth_digest.so</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:rationale>Minimizing the number of loadable modules available to the web server reduces risk
by limiting the capabilities allowed by the web server.</xccdf-1.2:rationale>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_enable_log_config" selected="false" severity="medium">
                  <xccdf-1.2:title>Enable log_config_module For HTTPD Logging</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>log_config_module</html:code> should exist and be configured in
the <html:code>/etc/httpd/conf/httpd.conf</html:code> file by adding the following module to
configure logging:
<html:pre>log_config_module</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:rationale>A major tool in exploring the web site use, attempted use, unusual conditions,
and problems are reported in the access and error logs. In the event of a
security incident, these logs can provide the SA and the web manager with
valuable information. Without these log files, SAs and web managers are
seriously hindered in their efforts to respond appropriately to suspicious or
criminal actions targeted at the web site.</xccdf-1.2:rationale>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_enable_log_config_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_ldap_support" selected="false" severity="unknown">
                  <xccdf-1.2:title>Disable LDAP Support</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>ldap</html:code> module provides HTTP authentication via an LDAP directory.
If its functionality is unnecessary, comment out the related modules:
<html:pre>#LoadModule ldap_module modules/mod_ldap.so
#LoadModule authnz_ldap_module modules/mod_authnz_ldap.so</html:pre>
If LDAP is to be used, SSL encryption should be used as well.</xccdf-1.2:description>
                  <xccdf-1.2:rationale>Minimizing the number of loadable modules available to the web server reduces risk
by limiting the capabilities allowed by the web server.</xccdf-1.2:rationale>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_mime_magic" selected="false" severity="unknown">
                  <xccdf-1.2:title>Disable MIME Magic</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>mime_magic</html:code> module provides a second layer of MIME support that in most configurations
is likely extraneous. If its functionality is unnecessary, comment out the related module:
<html:pre>#LoadModule mime_magic_module modules/mod_mime_magic.so</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:rationale>Minimizing the number of loadable modules available to the web server reduces risk
by limiting the capabilities allowed by the web server.</xccdf-1.2:rationale>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_mod_rewrite" selected="false" severity="unknown">
                  <xccdf-1.2:title>Disable HTTP mod_rewrite</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>mod_rewrite</html:code> module is very powerful and can protect against
certain classes of web attacks. However, it is also very complex and has a
significant history of vulnerabilities itself. If its functionality is
unnecessary, comment out the related module:
<html:pre>#LoadModule rewrite_module modules/mod_rewrite.so</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:rationale>Minimizing the number of loadable modules available to the web server reduces risk
by limiting the capabilities allowed by the web server.</xccdf-1.2:rationale>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_proxy_support" selected="false" severity="unknown">
                  <xccdf-1.2:title>Disable Proxy Support</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>proxy</html:code> module provides proxying support, allowing <html:code>httpd</html:code> to forward requests and
serve as a gateway for other servers. If its functionality is unnecessary, comment out the module:
<html:pre>#LoadModule proxy_module modules/mod_proxy.so</html:pre>

If proxy support is needed, load <html:code>mod_proxy</html:code> and the appropriate proxy protocol handler
module (one of <html:code>mod_proxy_http</html:code>, <html:code>mod_proxy_ftp</html:code>, or <html:code>mod_proxy_connect</html:code>). Additionally,
make certain that a server is secure before enabling proxying, as open proxy servers
are a security risk. <html:code>mod_proxy_balancer</html:code> enables load balancing, but requires that
<html:code>mod status</html:code> be enabled.</xccdf-1.2:description>
                  <xccdf-1.2:rationale>Minimizing the number of loadable modules available to the web server reduces risk
by limiting the capabilities allowed by the web server.</xccdf-1.2:rationale>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_server_activity_status" selected="false" severity="unknown">
                  <xccdf-1.2:title>Disable Server Activity Status</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>status</html:code> module provides real-time access to statistics on the internal operation of
the web server. This may constitute an unnecessary information leak and should be disabled
unless necessary. To do so, comment out the related module:
<html:pre>#LoadModule status_module modules/mod_status.so</html:pre>
If there is a critical need for this module, ensure that access to the status
page is properly restricted to a limited set of hosts in the status handler
configuration.</xccdf-1.2:description>
                  <xccdf-1.2:rationale>Minimizing the number of loadable modules available to the web server reduces risk
by limiting the capabilities allowed by the web server.</xccdf-1.2:rationale>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_server_configuration_display" selected="false" severity="unknown">
                  <xccdf-1.2:title>Disable Web Server Configuration Display</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>info</html:code> module creates a web page illustrating the configuration of the web server. This
can create an unnecessary security leak and should be disabled.
If its functionality is unnecessary, comment out the module:
<html:pre>#LoadModule info_module modules/mod_info.so</html:pre>
If there is a critical need for this module, use the <html:code>Location</html:code> directive to provide
an access control list to restrict access to the information.</xccdf-1.2:description>
                  <xccdf-1.2:rationale>Minimizing the number of loadable modules available to the web server reduces risk
by limiting the capabilities allowed by the web server.</xccdf-1.2:rationale>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_server_side_includes" selected="false" severity="unknown">
                  <xccdf-1.2:title>Disable Server Side Includes</xccdf-1.2:title>
                  <xccdf-1.2:description>Server Side Includes provide a method of dynamically generating web pages through the
insertion of server-side code. However, the technology is also deprecated and
introduces significant security concerns.
If this functionality is unnecessary, comment out the related module:
<html:pre>#LoadModule include_module modules/mod_include.so</html:pre>
If there is a critical need for Server Side Includes, they should be enabled with the
option <html:code>IncludesNoExec</html:code> to prevent arbitrary code execution. Additionally, user
supplied data should be encoded to prevent cross-site scripting vulnerabilities.</xccdf-1.2:description>
                  <xccdf-1.2:rationale>Minimizing the number of loadable modules available to the web server reduces risk
by limiting the capabilities allowed by the web server.</xccdf-1.2:rationale>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_url_correction" selected="false" severity="unknown">
                  <xccdf-1.2:title>Disable URL Correction on Misspelled Entries</xccdf-1.2:title>
                  <xccdf-1.2:description>The <html:code>speling</html:code> module attempts to find a document match by allowing one misspelling in an
otherwise failed request. If this functionality is unnecessary, comment out the module:
<html:pre>#LoadModule speling_module modules/mod_speling.so</html:pre>
This functionality weakens server security by making site enumeration easier.</xccdf-1.2:description>
                  <xccdf-1.2:rationale>Minimizing the number of loadable modules available to the web server reduces risk
by limiting the capabilities allowed by the web server.</xccdf-1.2:rationale>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_webdav" selected="false" severity="unknown">
                  <xccdf-1.2:title>Disable WebDAV (Distributed Authoring and Versioning)</xccdf-1.2:title>
                  <xccdf-1.2:description>WebDAV is an extension of the HTTP protocol that provides distributed and
collaborative access to web content. If its functionality is unnecessary,
comment out the related modules:
<html:pre>#LoadModule dav_module modules/mod_dav.so
#LoadModule dav_fs_module modules/mod_dav_fs.so</html:pre>
If there is a critical need for WebDAV, extra care should be taken in its configuration.
Since DAV access allows remote clients to manipulate server files, any location on the
server that is DAV enabled should be protected by access controls.</xccdf-1.2:description>
                  <xccdf-1.2:rationale>Minimizing the number of loadable modules available to the web server, reduces risk
by limiting the capabilities allowed by the web server.</xccdf-1.2:rationale>
                </xccdf-1.2:Rule>
              </xccdf-1.2:Group>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_httpd_modules_improve_security">
              <xccdf-1.2:title>Use Appropriate Modules to Improve httpd's Security</xccdf-1.2:title>
              <xccdf-1.2:description>Among the modules available for <html:code>httpd</html:code> are several whose use may improve the
security of the web server installation. This section recommends and discusses
the deployment of security-relevant modules.</xccdf-1.2:description>
              <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security">
                <xccdf-1.2:title>Deploy mod_security</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>security</html:code> module provides an application level firewall for <html:code>httpd</html:code>.
Following its installation with the base ruleset, specific configuration advice can be found at

    <html:a href="http://www.modsecurity.org/">http://www.modsecurity.org/</html:a> to design a policy that best matches the security needs of
the web applications. Usage of <html:code>mod_security</html:code> is highly recommended for some environments,
but it should be noted this module does not ship with Red Hat Enterprise Linux itself,
and instead is provided via Extra Packages for Enterprise Linux (EPEL).
For more information on EPEL please refer to 
    <html:a href="http://fedoraproject.org/wiki/EPEL">http://fedoraproject.org/wiki/EPEL</html:a>.</xccdf-1.2:description>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_install_mod_security" selected="false" severity="unknown">
                  <xccdf-1.2:title>Install mod_security</xccdf-1.2:title>
                  <xccdf-1.2:description>Install the <html:code>security</html:code> module:
The <html:code>mod_security</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install mod_security</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:rationale><html:code>mod_security</html:code> provides an additional level of protection for the web server by
enabling the administrator to implement content access policies and filters at the
application layer.</xccdf-1.2:rationale>
                </xccdf-1.2:Rule>
              </xccdf-1.2:Group>
              <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl">
                <xccdf-1.2:title>Deploy mod_ssl</xccdf-1.2:title>
                <xccdf-1.2:description>Because HTTP is a plain text protocol, all traffic is susceptible to passive
monitoring. If there is a need for confidentiality, SSL should be configured
and enabled to encrypt content.
<html:br/><html:br/>
Note: <html:code>mod_nss</html:code> is a FIPS 140-2 certified alternative to <html:code>mod_ssl</html:code>.
The modules share a considerable amount of code and should be nearly identical
in functionality. If FIPS 140-2 validation is required, then <html:code>mod_nss</html:code> should
be used. If it provides some feature or its greater compatibility is required,
then <html:code>mod_ssl</html:code> should be used.</xccdf-1.2:description>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_configure_tls" selected="false" severity="medium">
                  <xccdf-1.2:title>Enable Transport Layer Security (TLS) Encryption</xccdf-1.2:title>
                  <xccdf-1.2:description>Disable old SSL and TLS version and enable the latest TLS encryption by setting
the following in <html:code>/etc/httpd/conf.modules.d/ssl.conf</html:code>:
<html:pre>SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1</html:pre>
Make sure to also set <html:code>SSLEngine</html:code> to <html:code>on</html:code> in
<html:code>/etc/httpd/conf.modules.d/ssl.conf</html:code> like the following:
<html:pre>SSLEngine on</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:rationale>Transport Layer Security (TLS) encryption is a required security setting for a
private web server. Encryption of private information is essential to ensuring
data confidentiality. If private information is not encrypted, it can be
intercepted and easily read by an unauthorized party. A web server must
use a FIPS 140-2 approved TLS version, and all non-FIPS-approved SSL versions
must be disabled.</xccdf-1.2:rationale>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_configure_tls_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_configure_valid_server_cert" selected="false" severity="medium">
                  <xccdf-1.2:title>Configure A Valid Server Certificate</xccdf-1.2:title>
                  <xccdf-1.2:description>Configure the web site to use a valid organizationally defined certificate.
For DoD, this is a DoD server certificate issued by the DoD CA.</xccdf-1.2:description>
                  <xccdf-1.2:rationale>This check verifies that DoD is a hosted web site's CA. The certificate is
actually a DoD-issued server certificate used by the organization being
reviewed. This is used to verify the authenticity of the web site to the user.
If the certificate is not for the server (Certificate belongs to), if the
certificate is not issued by DoD (Certificate was issued by), or if the current
date is not included in the valid date (Certificate is valid from), then there
is no assurance that the use of the certificate is valid. The entire purpose of
using a certificate is, therefore, compromised.</xccdf-1.2:rationale>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_configure_valid_server_cert_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_install_mod_ssl" selected="false" severity="unknown">
                  <xccdf-1.2:title>Install mod_ssl</xccdf-1.2:title>
                  <xccdf-1.2:description>Install the <html:code>mod_ssl</html:code> module:
The <html:code>mod_ssl</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install mod_ssl</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:rationale><html:code>mod_ssl</html:code> provides encryption capabilities for the <html:code>httpd</html:code> Web server. Unencrypted
content is transmitted in plain text which could be passively monitored and accessed by
unauthorized parties.</xccdf-1.2:rationale>
                </xccdf-1.2:Rule>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_require_client_certs" selected="false" severity="medium">
                  <xccdf-1.2:title>Require Client Certificates</xccdf-1.2:title>
                  <xccdf-1.2:description><html:code>SSLVerifyClient</html:code> should be set and configured to <html:code>require</html:code> by
setting the following in <html:code>/etc/httpd/conf/httpd.conf</html:code>:
<html:pre>SSLVerifyClient require</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:rationale>Web sites requiring authentication must utilize PKI as an
authentication mechanism for web users. Information systems residing behind web
servers requiring authorization based on individual identity must use the
identity provided by certificate-based authentication to support access control
decisions.</xccdf-1.2:rationale>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_require_client_certs_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
              </xccdf-1.2:Group>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage">
              <xccdf-1.2:title>Restrict Web Server Information Leakage</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>ServerTokens</html:code> and <html:code>ServerSignature</html:code> directives determine how
much information the web server discloses about the configuration of the
system.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_serversignature_off" selected="false" severity="unknown">
                <xccdf-1.2:title>Set httpd ServerSignature Directive to Off</xccdf-1.2:title>
                <xccdf-1.2:description><html:code>ServerSignature Off</html:code> restricts <html:code>httpd</html:code> from displaying server version number
on error pages.
<html:br/><html:br/>
Add or correct the following directive in <html:code>/etc/httpd/conf/httpd.conf</html:code>:
<html:pre>ServerSignature Off</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Information disclosed to clients about the configuration of the web server and system could be used
to plan an attack on the given system. This information disclosure should be restricted to a minimum.</xccdf-1.2:rationale>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_servertokens_prod" selected="false" severity="unknown">
                <xccdf-1.2:title>Set httpd ServerTokens Directive to Prod</xccdf-1.2:title>
                <xccdf-1.2:description><html:code>ServerTokens Prod</html:code> restricts information in page headers, returning only the word "Apache."
<html:br/><html:br/>
Add or correct the following directive in <html:code>/etc/httpd/conf/httpd.conf</html:code>:
<html:pre>ServerTokens Prod</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Information disclosed to clients about the configuration of the web server and system could be used
to plan an attack on the given system. This information disclosure should be restricted to a minimum.</xccdf-1.2:rationale>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_httpd_secure_content">
              <xccdf-1.2:title>Configure HTTPD-Served Web Content Securely</xccdf-1.2:title>
              <xccdf-1.2:description>Running <html:code>httpd</html:code> inside a <html:code>chroot</html:code> jail is designed to isolate the
web server process to a small section of the filesystem, limiting the damage if
it is compromised. Versions of Apache greater than 2.2.10 (such as the one
included with Red Hat Enterprise Linux 7) provide the <html:code>ChrootDir</html:code> directive. To run Apache
inside a chroot jail in <html:code>/chroot/apache</html:code>, add the following line to
<html:code>/etc/httpd/conf/httpd.conf</html:code>: <html:pre>ChrootDir /chroot/apache</html:pre> This
necessitates placing all files required by <html:code>httpd</html:code> inside
<html:code>/chroot/apache</html:code> , including <html:code>httpd</html:code>'s binaries, modules,
configuration files, and served web pages. The details of this configuration
are beyond the scope of this guide. This may also require additional SELinux
configuration.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_configure_banner_page" selected="false" severity="low">
                <xccdf-1.2:title>Configure A Banner Page For Each Website</xccdf-1.2:title>
                <xccdf-1.2:description>Configure a login banner for each website when authentication is required for
user access.</xccdf-1.2:description>
                <xccdf-1.2:rationale>A consent banner will be in place to make prospective entrants aware that the
website they are about to enter is a DoD web site and their activity is subject
to monitoring. The document, DoDI 8500.01, establishes the policy on the use of
DoD information systems. It requires the use of a standard Notice and Consent
Banner and standard text to be included in user agreements. The requirement for
the banner is for websites with security and access controls. These are
restricted and not publicly accessible. If the website does not require
authentication/authorization for use, then the banner does not need to be
present. A manual check of the document root directory for a banner page file
(such as banner.html) or navigation to the website via a browser can be used to
confirm the information provided from interviewing the web staff.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_configure_banner_page_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_configure_documentroot" selected="false" severity="low">
                <xccdf-1.2:title>Each Web Content Directory Must Contain An index.html File</xccdf-1.2:title>
                <xccdf-1.2:description>Every <html:code>DocumentRoot</html:code> that is configured should have an
<html:code>index.html</html:code> file that exists. Add an <html:code>index.html</html:code> file to every
configured <html:code>DocumentRoot</html:code>.</xccdf-1.2:description>
                <xccdf-1.2:rationale>The goal is to completely control the web users experience in navigating any
portion of the web document root directories. Ensuring all web content
directories have at least the equivalent of an index.html file is a significant
factor to accomplish this end. Also, enumeration techniques, such as URL
parameter manipulation, rely upon being able to obtain information about the web
server's directory structure by locating directories with default pages. This
practice helps ensure that the anonymous web user will not obtain directory
browsing information or an error message that reveals the server type and
version.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_configure_documentroot_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_disable_content_symlinks" selected="false" severity="high">
                <xccdf-1.2:title>Disable Web Content Symbolic Links</xccdf-1.2:title>
                <xccdf-1.2:description>For each <html:code>&lt;Directory&gt;</html:code> instance, remove the following:
<html:pre>FollowSymLinks</html:pre>
If symbolic links are allowed, the following can be added for each
<html:code>&lt;Directory&gt;</html:code> instance:
<html:pre>Options SymLinksIfOwnerMatchDisable</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale>A symbolic link allows a file or a directory to be referenced using a symbolic
name raising a potential hazard if symbolic linkage is made to a sensitive area.
When web scripts are executed and symbolic links are allowed, the web user could
be allowed to access locations on the web server that are outside the scope of
the web document root or home directory.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_disable_content_symlinks_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_encrypt_file_uploads" selected="false" severity="high">
                <xccdf-1.2:title>Encrypt All File Uploads</xccdf-1.2:title>
                <xccdf-1.2:description>Use only secure encrypted logons and connections for uploading files to the web
site.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Logging in to a web server via an unencrypted protocol or service, to upload
documents to the web site, is a risk if proper encryption is not utilized to
protect the data being transmitted. An encrypted protocol or service must be
used for remote access to web administration tasks.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_encrypt_file_uploads_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_limit_java_files" selected="false" severity="low">
                <xccdf-1.2:title>Remove .java And .jpp Files</xccdf-1.2:title>
                <xccdf-1.2:description><html:code>.java</html:code> and <html:code>.jpp</html:code> files should not exist and should be removed
from the web server.</xccdf-1.2:description>
                <xccdf-1.2:rationale>From the source code in a .java or a .jpp file, the Java compiler produces a
binary file with an extension of .class. The .java or .jpp file would,
therefore, reveal sensitive information regarding an application's logic and
permissions to resources on the server. By contrast, the .class file, because it
is intended to be machine independent, is referred to as bytecode. Bytecodes are
run by the Java Virtual Machine (JVM), or the Java Runtime Environment (JRE),
via a browser configured to permit Java code.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_limit_java_files_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_httpd_remove_robots_file" selected="false" severity="medium">
                <xccdf-1.2:title>The robots.txt Files Must Not Exist</xccdf-1.2:title>
                <xccdf-1.2:description>Remove any <html:code>robots.txt</html:code> files that may exist with any web content.
Other methods must be employed if there is information on the web site that
needs protection from search engines and public view. Inspect all instances of
<html:code>DocumentRoot</html:code> and <html:code>Alias</html:code> and remove any <html:code>robots.txt</html:code> file.
<html:pre>$ sudo rm -f path/to/robots.txt</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale>Search engines are constantly at work on the Internet. Search engines are
augmented by agents, often referred to as spiders or bots, which endeavor to
capture and catalog web-site content. In turn, these search engines make the
content they obtain and catalog available to any public web user.
<html:br/><html:br/>
To request
that a well behaved search engine not crawl and catalog a site, the web site may
contain a file called robots.txt. This file contains directories and files that
the web server SA desires not be crawled or cataloged, but this file can also be
used, by an attacker or poorly coded search engine, as a directory and file
index to a site. This information may be used to reduce an attacker's time
searching and traversing the web site to find files that might be relevant. If
information on the web site needs to be protected from search engines and public
view, other methods must be used.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-httpd_remove_robots_file_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_partition_for_web_content" selected="false" severity="medium">
                <xccdf-1.2:title>Ensure Web Content Located on Separate partition</xccdf-1.2:title>
                <xccdf-1.2:description>The <html:code>DocumentRoot</html:code> directory is used for storing web content and data.
Ensure that the <html:code>DocumentRoot</html:code> directory exists on a separate logical
volume at installation time, or migrate it using LVM.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Application partitioning enables an additional security measure by securing
user traffic under one security context, while managing system and application
files under another. Web content is can be to an anonymous web user. For such
an account to have access to system files of any type is a major security risk
that is avoidable and desirable. Failure to partition the system files from the
web site documents increases risk of attack via directory traversal, or impede
web site availability due to drive space exhaustion.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#not_bootc_and_not_container"/>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-partition_for_web_content_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_imap">
          <xccdf-1.2:title>IMAP and POP3 Server</xccdf-1.2:title>
          <xccdf-1.2:description>Dovecot provides IMAP and POP3 services. It is not
installed by default. The project page at 
    <html:a href="http://www.dovecot.org">http://www.dovecot.org</html:a>
contains more detailed information about Dovecot
configuration.</xccdf-1.2:description>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_configure_dovecot">
            <xccdf-1.2:title>Configure Dovecot if Necessary</xccdf-1.2:title>
            <xccdf-1.2:description>If the system will operate as an IMAP or
POP3 server, the dovecot software should be configured securely by following
the recommendations below.</xccdf-1.2:description>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl">
              <xccdf-1.2:title>Enable SSL Support</xccdf-1.2:title>
              <xccdf-1.2:description>SSL should be used to encrypt network traffic between the 
Dovecot server and its clients. Users must authenticate to the Dovecot 
server in order to read their mail, and passwords should never be 
transmitted in clear text. In addition, protecting mail as it is 
downloaded is a privacy measure, and clients may use SSL certificates 
to authenticate the server, preventing another system from impersonating 
the server.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dovecot_configure_ssl_cert" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure Dovecot to Use the SSL Certificate file</xccdf-1.2:title>
                <xccdf-1.2:description>This option tells Dovecot where to find the mail server's SSL
Certificate.
<html:br/><html:br/>
Edit <html:code>/etc/dovecot/conf.d/10-ssl.conf</html:code> and add or correct the
following line (<html:i>note: the path below is the default path set by the
Dovecot installation. If you are using a different path, ensure you
reference the appropriate file</html:i>):
<html:pre>ssl_cert = &lt;/etc/pki/dovecot/certs/dovecot.pem</html:pre>"</xccdf-1.2:description>
                <xccdf-1.2:rationale>SSL certificates are used by the client to authenticate the identity of the
server, as well as to encrypt credentials and message traffic. Not using
SSL to encrypt mail server traffic could allow unauthorized access to
credentials and mail messages since they are sent in plain text over the
network.</xccdf-1.2:rationale>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dovecot_configure_ssl_key" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure Dovecot to Use the SSL Key file</xccdf-1.2:title>
                <xccdf-1.2:description>This option tells Dovecot where to find the mail server's SSL Key.
<html:br/><html:br/>
Edit <html:code>/etc/dovecot/conf.d/10-ssl.conf</html:code> and add or correct the
following line (<html:i>note: the path below is the default path set by the
Dovecot installation. If you are using a different path, ensure you
reference the appropriate file</html:i>):
<html:pre>ssl_key = &lt;/etc/pki/dovecot/private/dovecot.pem</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale>SSL certificates are used by the client to authenticate the identity of the
server, as well as to encrypt credentials and message traffic. Not using
SSL to encrypt mail server traffic could allow unauthorized access to
credentials and mail messages since they are sent in plain text over the
network.</xccdf-1.2:rationale>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dovecot_disable_plaintext_auth" selected="false" severity="unknown">
                <xccdf-1.2:title>Disable Plaintext Authentication</xccdf-1.2:title>
                <xccdf-1.2:description>To prevent Dovecot from attempting plaintext authentication of clients,
edit <html:code>/etc/dovecot/conf.d/10-auth.conf</html:code> and add\or correct the
following line:
<html:pre>disable_plaintext_auth = yes</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale>Using plain text authentication to the mail server could allow an attacker
access to credentials by monitoring network traffic.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dovecot_disable_plaintext_auth:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_dovecot_enable_ssl" selected="false" severity="unknown">
                <xccdf-1.2:title>Enable the SSL flag in /etc/dovecot.conf</xccdf-1.2:title>
                <xccdf-1.2:description>To allow clients to make encrypted connections the <html:code>ssl</html:code>
flag in Dovecot's configuration file needs to be set to <html:code>yes</html:code>.
<html:br/><html:br/>
Edit <html:code>/etc/dovecot/conf.d/10-ssl.conf</html:code> and add or correct the following line:
<html:pre>ssl = yes</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale>SSL encrypt network traffic between the Dovecot server and its clients 
protecting user credentials, mail as it is downloaded, and clients may use
SSL certificates to authenticate the server, preventing another system from
impersonating the server.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-dovecot_enable_ssl:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_cyrus-imapd">
            <xccdf-1.2:title>Disable Cyrus IMAP</xccdf-1.2:title>
            <xccdf-1.2:description>If the system does not need to operate as an IMAP or
POP3 server, the Cyrus IMAP software should be removed.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_cyrus-imapd_removed" selected="false" severity="unknown">
              <xccdf-1.2:title>Uninstall cyrus-imapd Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>cyrus-imapd</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase cyrus-imapd</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.8</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If there is no need to make the cyrus-imapd software available,
removing it provides a safeguard against its activation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_cyrus-imapd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove cyrus-imapd
# from the system, and may remove any packages
# that depend on cyrus-imapd. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "cyrus-imapd" ; then
yum remove -y "cyrus-imapd"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_cyrus-imapd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall cyrus-imapd Package: Ensure cyrus-imapd is removed'
  ansible.builtin.package:
    name: cyrus-imapd
    state: absent
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_cyrus-imapd_removed
  - unknown_severity
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_cyrus-imapd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_cyrus-imapd

class remove_cyrus-imapd {
  package { 'cyrus-imapd':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_cyrus-imapd_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=cyrus-imapd
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_cyrus-imapd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove cyrus-imapd
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_cyrus-imapd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove cyrus-imapd
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_cyrus-imapd_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_cyrus-imapd_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_dovecot">
            <xccdf-1.2:title>Disable Dovecot</xccdf-1.2:title>
            <xccdf-1.2:description>If the system does not need to operate as an IMAP or
POP3 server, the dovecot software should be disabled and removed.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_dovecot_removed" selected="false" severity="unknown">
              <xccdf-1.2:title>Uninstall dovecot Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>dovecot</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase dovecot</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.8</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If there is no need to make the Dovecot software available,
removing it provides a safeguard against its activation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dovecot_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove dovecot
# from the system, and may remove any packages
# that depend on dovecot. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "dovecot" ; then
yum remove -y "dovecot"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dovecot_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall dovecot Package: Ensure dovecot is removed'
  ansible.builtin.package:
    name: dovecot
    state: absent
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_dovecot_removed
  - unknown_severity
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dovecot_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_dovecot

class remove_dovecot {
  package { 'dovecot':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dovecot_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=dovecot
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dovecot_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove dovecot
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_dovecot_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove dovecot
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_dovecot_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_dovecot_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_dovecot_disabled" selected="false" severity="unknown">
              <xccdf-1.2:title>Disable Dovecot Service</xccdf-1.2:title>
              <xccdf-1.2:description>
The <html:code>dovecot</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now dovecot.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>Running an IMAP or POP3 server provides a network-based
avenue of attack, and should be disabled if not needed.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_dovecot_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'dovecot.service'
fi
"$SYSTEMCTL_EXEC" disable 'dovecot.service'
"$SYSTEMCTL_EXEC" mask 'dovecot.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files dovecot.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'dovecot.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'dovecot.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'dovecot.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_dovecot_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_dovecot_disabled
  - unknown_severity

- name: Disable Dovecot Service - Disable service dovecot
  block:

  - name: Disable Dovecot Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Dovecot Service - Ensure dovecot.service is Masked
    ansible.builtin.systemd:
      name: dovecot.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("dovecot.service", multiline=True)

  - name: Unit Socket Exists - dovecot.socket
    ansible.builtin.command: systemctl -q list-unit-files dovecot.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Dovecot Service - Disable Socket dovecot
    ansible.builtin.systemd:
      name: dovecot.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("dovecot.socket", multiline=True)
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_dovecot_disabled
  - special_service_block
  - unknown_severity
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_dovecot_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_dovecot

class disable_dovecot {
  service {'dovecot':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_dovecot_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: dovecot.service
        enabled: false
        mask: true
      - name: dovecot.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_dovecot_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["dovecot"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_dovecot_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable dovecot
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_dovecot_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_dovecot_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_kerberos">
          <xccdf-1.2:title>Kerberos</xccdf-1.2:title>
          <xccdf-1.2:description>The Kerberos protocol is used for authentication across
non-secure network. Authentication can happen between
various types of principals -- users, service, or hosts.
Their identity and encryption keys can be stored in keytab
files.</xccdf-1.2:description>
          <xccdf-1.2:platform idref="#system_with_kernel"/>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_krb5-server_removed" selected="false" severity="medium">
            <xccdf-1.2:title>Remove the Kerberos Server Package</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>krb5-server</html:code> package should be removed if not in use.
Is this system the Kerberos server? If not, remove the package.
The <html:code>krb5-server</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase krb5-server</html:pre>
The krb5-server RPM is not installed by default on a AlmaLinux OS 8
system. It is needed only by the Kerberos servers, not by the
clients which use Kerberos for authentication. If the system is not
intended for use as a Kerberos Server it should be removed.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000120-GPOS-00061</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010163</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-237640r1017323_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Unnecessary packages should not be installed to decrease the attack
surface of the system.  While this software is clearly essential on an KDC
server, it is not necessary on typical desktop or workstation systems.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#krb5_server_older_than_1_17-18"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_krb5-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# CAUTION: This remediation script will remove krb5-server
# from the system, and may remove any packages
# that depend on krb5-server. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "krb5-server" ; then
yum remove -y "krb5-server"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_krb5-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010163
  - NIST-800-53-IA-7
  - NIST-800-53-IA-7.1
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_krb5-server_removed

- name: 'Remove the Kerberos Server Package: Ensure krb5-server is removed'
  ansible.builtin.package:
    name: krb5-server
    state: absent
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010163
  - NIST-800-53-IA-7
  - NIST-800-53-IA-7.1
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_krb5-server_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_krb5-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_krb5-server

class remove_krb5-server {
  package { 'krb5-server':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_krb5-server_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=krb5-server
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_krb5-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove krb5-server
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_krb5-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove krb5-server
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_krb5-server_removed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_krb5-server_removed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_kerberos_disable_no_keytab" selected="false" severity="medium">
            <xccdf-1.2:title>Disable Kerberos by removing host keytab</xccdf-1.2:title>
            <xccdf-1.2:description>Kerberos may rely on key distribution functions unapproved by Common Criteria.
To prevent using Kerberos by system daemons, remove the Kerberos keytab files, especially
<html:code>/etc/krb5.keytab</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000120-GPOS-00061</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0418</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1055</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1402</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010161</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230238r1017057_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Some key derivation functions (KDF) in Kerberos are not FIPS-compatible</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#krb5_server_older_than_1_17-18_and_krb5_workstation_older_than_1_17-18"/>
            <xccdf-1.2:fix id="kerberos_disable_no_keytab" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

rm -f /etc/*.keytab

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="kerberos_disable_no_keytab" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010161
  - disable_strategy
  - kerberos_disable_no_keytab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find keytab files
  ansible.builtin.find:
    paths: /etc/
    patterns: '*.keytab'
  register: keytab_files
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010161
  - disable_strategy
  - kerberos_disable_no_keytab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Remove keytab files
  ansible.builtin.file:
    path: '{{ item.path }}'
    state: absent
  with_items: '{{ keytab_files.files }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010161
  - disable_strategy
  - kerberos_disable_no_keytab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-kerberos_disable_no_keytab:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-kerberos_disable_no_keytab_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_ldap">
          <xccdf-1.2:title>LDAP</xccdf-1.2:title>
          <xccdf-1.2:description>LDAP is a popular directory service, that is, a
standardized way of looking up information from a central database.
AlmaLinux OS 8 includes software that enables a system to act as both
an LDAP client and server.</xccdf-1.2:description>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_389_ds">
            <xccdf-1.2:title>389 Directory Server</xccdf-1.2:title>
            <xccdf-1.2:description>389 Directory Server is a popular open-source LDAP server for Linux.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_389-ds-base_removed" selected="false" severity="low">
              <xccdf-1.2:title>Uninstall 389-ds-base Package</xccdf-1.2:title>
              <xccdf-1.2:description>The 389-ds-base RPM is not installed by default on a AlmaLinux OS 8
system. It is needed only by the 389-ds server, not by the
clients which use LDAP for authentication. If the system is not
intended for use as an LDAP Server it should be removed.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unnecessary packages should not be installed to decrease the attack
surface of the system.  While this software is clearly essential on an LDAP
server, it is not necessary on typical desktop or workstation systems.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_389-ds-base_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove 389-ds-base
# from the system, and may remove any packages
# that depend on 389-ds-base. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "389-ds-base" ; then
yum remove -y "389-ds-base"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_389-ds-base_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall 389-ds-base Package: Ensure 389-ds-base is removed'
  ansible.builtin.package:
    name: 389-ds-base
    state: absent
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_389-ds-base_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_389-ds-base_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_389-ds-base

class remove_389-ds-base {
  package { '389-ds-base':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_389-ds-base_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=389-ds-base
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_389-ds-base_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove 389-ds-base
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_389-ds-base_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove 389-ds-base
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_389-ds-base_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_389-ds-base_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_openldap_client">
            <xccdf-1.2:title>Configure OpenLDAP Clients</xccdf-1.2:title>
            <xccdf-1.2:description>This section provides information on which security settings are
important to configure in OpenLDAP clients by manually editing the appropriate
configuration files.  AlmaLinux OS 8 provides an automated configuration tool called
authconfig and a graphical wrapper for authconfig called
<html:code>system-config-authentication</html:code>. However, these tools do not provide as
much control over configuration as manual editing of configuration files. The
authconfig tools do not allow you to specify locations of SSL certificate
files, which is useful when trying to use SSL cleanly across several protocols.
Installation and configuration of OpenLDAP on AlmaLinux OS 8 is available at</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Before configuring any system to be an
LDAP client, ensure that a working LDAP server is present on the
network.</xccdf-1.2:warning>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_openldap-clients_removed" selected="false" severity="low">
              <xccdf-1.2:title>Ensure LDAP client is not installed</xccdf-1.2:title>
              <xccdf-1.2:description>The Lightweight Directory Access Protocol (LDAP) is a service that provides
a method for looking up information from a central database.
The <html:code>openldap-clients</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase openldap-clients</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.2.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If the system does not need to act as an LDAP client, it is recommended that the software is removed to reduce the potential attack surface.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openldap-clients_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove openldap-clients
# from the system, and may remove any packages
# that depend on openldap-clients. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "openldap-clients" ; then
yum remove -y "openldap-clients"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openldap-clients_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Ensure LDAP client is not installed: Ensure openldap-clients is removed'
  ansible.builtin.package:
    name: openldap-clients
    state: absent
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_openldap-clients_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openldap-clients_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_openldap-clients

class remove_openldap-clients {
  package { 'openldap-clients':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openldap-clients_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=openldap-clients
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openldap-clients_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove openldap-clients
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openldap-clients_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove openldap-clients
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_openldap-clients_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_enable_ldap_client" selected="false" severity="medium">
              <xccdf-1.2:title>Enable the LDAP Client For Use in Authconfig</xccdf-1.2:title>
              <xccdf-1.2:description>To determine if LDAP is being used for authentication, use the following
command:
<html:pre>$ sudo grep -i useldapauth /etc/sysconfig/authconfig</html:pre>
<html:br/><html:br/>
If <html:code>USELDAPAUTH=yes</html:code>, then LDAP is being used. If not, set <html:code>USELDAPAUTH</html:code>
to <html:code>yes</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0418</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1055</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1402</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Without cryptographic integrity protections, information can be
altered by unauthorized users without detection. The ssl directive specifies
whether to use TLS or not. If not specified it will default to no.
It should be set to start_tls rather than doing LDAP over SSL.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-enable_ldap_client:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-enable_ldap_client_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ldap_client_start_tls" selected="false" severity="medium">
              <xccdf-1.2:title>Configure LDAP Client to Use TLS For All Transactions</xccdf-1.2:title>
              <xccdf-1.2:description>This check verifies cryptography has been implemented
to protect the integrity of remote LDAP authentication sessions.
<html:br/><html:br/>
To determine if LDAP is being used for authentication, use the following
command:
<html:pre>$ sudo grep -i useldapauth /etc/sysconfig/authconfig</html:pre>
<html:br/><html:br/>
If <html:code>USELDAPAUTH=yes</html:code>, then LDAP is being used. To check if LDAP is
configured to use TLS, use the following command:
<html:pre>$ sudo grep -i ssl /etc/pam_ldap.conf</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R67</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Without cryptographic integrity protections, information can be altered by
unauthorized users without detection. The ssl directive specifies whether
to use TLS or not. If not specified it will default to no. It should be set
to start_tls rather than doing LDAP over SSL.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_nss-pam-ldapd"/>
              <xccdf-1.2:fix id="ldap_client_start_tls" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q nss-pam-ldapd; then

# Use LDAP for authentication
# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^USELDAPAUTH")

# shellcheck disable=SC2059
printf -v formatted_output "%s=%s" "$stripped_key" "yes"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^USELDAPAUTH\\&gt;" "/etc/sysconfig/authconfig"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^USELDAPAUTH\\&gt;.*/$escaped_formatted_output/gi" "/etc/sysconfig/authconfig"
else
    if [[ -s "/etc/sysconfig/authconfig" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/sysconfig/authconfig" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/sysconfig/authconfig"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/sysconfig/authconfig"
fi

# Configure client to use TLS for all authentications
# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^ssl")

# shellcheck disable=SC2059
printf -v formatted_output "%s %s" "$stripped_key" "start_tls"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^ssl\\&gt;" "/etc/nslcd.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^ssl\\&gt;.*/$escaped_formatted_output/gi" "/etc/nslcd.conf"
else
    if [[ -s "/etc/nslcd.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/nslcd.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/nslcd.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/nslcd.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ldap_client_start_tls:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ldap_client_start_tls_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ldap_client_tls_cacertpath" selected="false" severity="medium">
              <xccdf-1.2:title>Configure Certificate Directives for LDAP Use of TLS</xccdf-1.2:title>
              <xccdf-1.2:description>Ensure a copy of a trusted CA certificate has been placed in the file
<html:code>/etc/pki/tls/CA/cacert.pem</html:code>. Configure LDAP to enforce TLS use and
to trust certificates signed by that CA. First, edit the file
<html:code>/etc/nslcd.conf</html:code>, and add or correct either of the following lines:
<html:pre>tls_cacertdir /etc/pki/tls/CA</html:pre> or 
<html:pre>tls_cacertfile /etc/pki/tls/CA/cacert.pem</html:pre>
Then review the LDAP server and ensure TLS has been configured.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R67</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The tls_cacertdir or tls_cacertfile directives are required when
tls_checkpeer is configured (which is the default for openldap versions 2.1 and
up). These directives define the path to the trust certificates signed by the
site CA.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_nss-pam-ldapd"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ldap_client_tls_cacertpath:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ldap_client_tls_cacertpath_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_openldap_server">
            <xccdf-1.2:title>Configure OpenLDAP Server</xccdf-1.2:title>
            <xccdf-1.2:description>This section details some security-relevant settings
for an OpenLDAP server.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_openldap-servers_removed" selected="false" severity="low">
              <xccdf-1.2:title>Uninstall openldap-servers Package</xccdf-1.2:title>
              <xccdf-1.2:description>The openldap-servers package is not installed by default on a AlmaLinux OS 8
system. It is needed only by the OpenLDAP server, not by the
clients which use LDAP for authentication. If the system is not
intended for use as an LDAP Server it should be removed.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unnecessary packages should not be installed to decrease the attack
surface of the system.  While this software is clearly essential on an LDAP
server, it is not necessary on typical desktop or workstation systems.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openldap-servers_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove openldap-servers
# from the system, and may remove any packages
# that depend on openldap-servers. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "openldap-servers" ; then
yum remove -y "openldap-servers"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openldap-servers_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall openldap-servers Package: Ensure openldap-servers is removed'
  ansible.builtin.package:
    name: openldap-servers
    state: absent
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_openldap-servers_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openldap-servers_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_openldap-servers

class remove_openldap-servers {
  package { 'openldap-servers':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openldap-servers_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=openldap-servers
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openldap-servers_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove openldap-servers
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_openldap-servers_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove openldap-servers
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_openldap-servers_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_openldap-servers_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_slapd_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable LDAP Server (slapd)</xccdf-1.2:title>
              <xccdf-1.2:description>The Lightweight Directory Access Protocol (LDAP) is a service that
provides a method for looking up information from a central database.</xccdf-1.2:description>
              <xccdf-1.2:rationale>If the system will not need to act as an LDAP server, it is recommended
that the software be disabled to reduce the potential attack surface.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_slapd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'slapd.service'
fi
"$SYSTEMCTL_EXEC" disable 'slapd.service'
"$SYSTEMCTL_EXEC" mask 'slapd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files slapd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'slapd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'slapd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'slapd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_slapd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_slapd_disabled

- name: Disable LDAP Server (slapd) - Disable service slapd
  block:

  - name: Disable LDAP Server (slapd) - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable LDAP Server (slapd) - Ensure slapd.service is Masked
    ansible.builtin.systemd:
      name: slapd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("slapd.service", multiline=True)

  - name: Unit Socket Exists - slapd.socket
    ansible.builtin.command: systemctl -q list-unit-files slapd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable LDAP Server (slapd) - Disable Socket slapd
    ansible.builtin.systemd:
      name: slapd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("slapd.socket", multiline=True)
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_slapd_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_slapd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_slapd

class disable_slapd {
  service {'slapd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_slapd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: slapd.service
        enabled: false
        mask: true
      - name: slapd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_slapd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["slapd"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_slapd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable slapd
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_slapd_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_slapd_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_mail">
          <xccdf-1.2:title>Mail Server Software</xccdf-1.2:title>
          <xccdf-1.2:description>Mail servers are used to send and receive email over the network.
Mail is a very common service, and Mail Transfer Agents (MTAs) are obvious
targets of network attack.
Ensure that systems are not running MTAs unnecessarily,
and configure needed MTAs as defensively as possible.
<html:br/><html:br/>
Very few systems at any site should be configured to directly receive email over the
network. Users should instead use mail client programs to retrieve email
from a central server that supports protocols such as IMAP or POP3.
However, it is normal for most systems to be independently capable of sending email,
for instance so that cron jobs can report output to an administrator.
Most MTAs, including Postfix, support a submission-only mode in which mail can be sent from
the local system to a central site MTA (or directly delivered to a local account),
but the system still cannot receive mail directly over a network.
<html:br/><html:br/>
The <html:code>alternatives</html:code> program in AlmaLinux OS 8 permits selection of other mail server software
(such as Sendmail), but Postfix is the default and is preferred.
Postfix was coded with security in mind and can also be more effectively contained by
SELinux as its modular design has resulted in separate processes performing specific actions.
More information is available on its website, 
    <html:a href="http://www.postfix.org">http://www.postfix.org</html:a>.</xccdf-1.2:description>
          <xccdf-1.2:platform idref="#system_with_kernel"/>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_mailx_installed" selected="false" severity="medium">
            <xccdf-1.2:title>The mailx Package Is Installed</xccdf-1.2:title>
            <xccdf-1.2:description>A mail server is required for sending emails.
The <html:code>mailx</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install mailx</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-3(5)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000363-GPOS-00150</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010358</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-256974r1069321_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Emails can be used to notify designated personnel about important
system events such as failures or warnings.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_mailx_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "mailx" ; then
    yum install -y "mailx"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_mailx_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010358
  - NIST-800-53-CM-3(5)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_mailx_installed

- name: Ensure mailx is installed
  ansible.builtin.package:
    name: mailx
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010358
  - NIST-800-53-CM-3(5)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_mailx_installed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_mailx_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_mailx

class install_mailx {
  package { 'mailx':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_mailx_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=mailx
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_mailx_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "mailx"
version = "*"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_mailx_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install mailx
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_mailx_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install mailx
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_mailx_installed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_mailx_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_postfix_installed" selected="false" severity="medium">
            <xccdf-1.2:title>The Postfix package is installed</xccdf-1.2:title>
            <xccdf-1.2:description>A mail server is required for sending emails.
The <html:code>postfix</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install postfix</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(ii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000046-GPOS-00022</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030030</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230389r1017197_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Emails can be used to notify designated personnel about important
system events such as failures or warnings.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_postfix_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "postfix" ; then
    yum install -y "postfix"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_postfix_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030030
  - PCI-DSSv4-10.5
  - PCI-DSSv4-10.5.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_postfix_installed

- name: Ensure postfix is installed
  ansible.builtin.package:
    name: postfix
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030030
  - PCI-DSSv4-10.5
  - PCI-DSSv4-10.5.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_postfix_installed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_postfix_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_postfix

class install_postfix {
  package { 'postfix':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_postfix_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=postfix
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_postfix_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "postfix"
version = "*"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_postfix_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install postfix
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_postfix_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install postfix
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_postfix_installed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_postfix_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_sendmail_removed" selected="false" severity="medium">
            <xccdf-1.2:title>Uninstall Sendmail Package</xccdf-1.2:title>
            <xccdf-1.2:description>Sendmail is not the default mail transfer agent and is
not installed by default.
The <html:code>sendmail</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase sendmail</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R62</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040002</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230489r1017273_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The sendmail software was not developed with security in mind and
its design prevents it from being effectively contained by SELinux.  Postfix
should be used instead.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sendmail_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# CAUTION: This remediation script will remove sendmail
# from the system, and may remove any packages
# that depend on sendmail. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "sendmail" ; then
yum remove -y "sendmail"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sendmail_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040002
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_sendmail_removed

- name: 'Uninstall Sendmail Package: Ensure sendmail is removed'
  ansible.builtin.package:
    name: sendmail
    state: absent
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040002
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_sendmail_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sendmail_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_sendmail

class remove_sendmail {
  package { 'sendmail':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sendmail_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=sendmail
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sendmail_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove sendmail
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sendmail_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove sendmail
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_sendmail_removed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_sendmail_removed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_postfix_enabled" selected="false" severity="unknown">
            <xccdf-1.2:title>Enable Postfix Service</xccdf-1.2:title>
            <xccdf-1.2:description>The Postfix mail transfer agent is used for local mail delivery
within the system. The default configuration only listens for connections to
the default SMTP port (port 25) on the loopback interface (127.0.0.1).  It is
recommended to leave this service enabled for local mail delivery.

The <html:code>postfix</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable postfix.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:rationale>Local mail delivery is essential to some system maintenance and
notification tasks.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_postfix_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'postfix.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'postfix.service'
fi
"$SYSTEMCTL_EXEC" enable 'postfix.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_postfix_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_postfix_enabled
  - unknown_severity

- name: Enable Postfix Service - Enable service postfix
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable Postfix Service - Enable Service postfix
    ansible.builtin.systemd:
      name: postfix
      enabled: true
      state: started
      masked: false
    when:
    - '"postfix" in ansible_facts.packages'
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_postfix_enabled
  - special_service_block
  - unknown_severity
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_postfix_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_postfix

class enable_postfix {
  service {'postfix':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_postfix_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["postfix"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_postfix_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable postfix
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_postfix_enabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_postfix_enabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_has_nonlocal_mta" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure Mail Transfer Agent is not Listening on any non-loopback Address</xccdf-1.2:title>
            <xccdf-1.2:description>Mail Transfer Agents (MTA), such as sendmail and Postfix, are used to
listen for incoming mail and transfer the messages to the appropriate
user or mail server. If the system is not intended to be a mail server,
it is recommended that the MTA be configured to only process local mail.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.23</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The software for all Mail Transfer Agents is complex and most have a
long history of security issues. While it is important to ensure that
the system can process local mail messages, it is not necessary to have
the MTA's daemon listening on a port unless the server is intended to
be a mail server that receives and processes mail from other systems.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-has_nonlocal_mta:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-has_nonlocal_mta_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_postfix_client">
            <xccdf-1.2:title>Configure SMTP For Mail Clients</xccdf-1.2:title>
            <xccdf-1.2:description>This section discusses settings for Postfix in a submission-only
e-mail configuration.</xccdf-1.2:description>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_postfix_inet_interfaces" type="string">
              <xccdf-1.2:title>Postfix Network Interfaces</xccdf-1.2:title>
              <xccdf-1.2:description>The setting for inet_interfaces in /etc/postfix/main.cf</xccdf-1.2:description>
              <xccdf-1.2:value selector="loopback-only">loopback-only</xccdf-1.2:value>
              <xccdf-1.2:value>loopback-only</xccdf-1.2:value>
              <xccdf-1.2:value selector="localhost">localhost</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_postfix_relayhost" type="string">
              <xccdf-1.2:title>Postfix relayhost</xccdf-1.2:title>
              <xccdf-1.2:description>Specify the host all outbound email should be routed into.</xccdf-1.2:description>
              <xccdf-1.2:value>smtp.$mydomain</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_postfix_root_mail_alias" interactive="true" type="string">
              <xccdf-1.2:title>Postfix Root Mail Alias</xccdf-1.2:title>
              <xccdf-1.2:description>Specify an email address (string) for a root mail alias.</xccdf-1.2:description>
              <xccdf-1.2:value>change_me@localhost</xccdf-1.2:value>
              <xccdf-1.2:value selector="mil_sysadmin">system.administrator@mail.mil</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_postfix_client_configure_mail_alias" selected="false" severity="medium">
              <xccdf-1.2:title>Configure System to Forward All Mail For The Root Account</xccdf-1.2:title>
              <xccdf-1.2:description>Make sure that mails delivered to root user are forwarded to a monitored
email address. Make sure that the address
<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postfix_root_mail_alias" use="legacy"/> is a valid email address
reachable from the system in question. Use the following command to
configure the alias:
<html:pre>$ sudo echo "root: <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postfix_root_mail_alias" use="legacy"/>" &gt;&gt; /etc/aliases
$ sudo newaliases</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000046-GPOS-00022</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R75</xccdf-1.2:reference>
              <xccdf-1.2:rationale>A number of system services utilize email messages sent to the root user to
notify system administrators of active or impending issues.  These messages must
be forwarded to at least one monitored email address.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="postfix_client_configure_mail_alias" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_postfix_root_mail_alias='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postfix_root_mail_alias" use="legacy"/>'


# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^root")

# shellcheck disable=SC2059
printf -v formatted_output "%s: %s" "$stripped_key" "$var_postfix_root_mail_alias"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^root\\&gt;" "/etc/aliases"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^root\\&gt;.*/$escaped_formatted_output/gi" "/etc/aliases"
else
    if [[ -s "/etc/aliases" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/aliases" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/aliases"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/aliases"
fi

if [ -f /usr/bin/newaliases ]; then
    newaliases
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="postfix_client_configure_mail_alias" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - postfix_client_configure_mail_alias
- name: XCCDF Value var_postfix_root_mail_alias # promote to variable
  set_fact:
    var_postfix_root_mail_alias: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postfix_root_mail_alias" use="legacy"/>
  tags:
    - always

- name: Configure System to Forward All Mail For The Root Account - Make sure that
    "/etc/aliases" has a defined value for root
  ansible.builtin.lineinfile:
    path: /etc/aliases
    line: 'root: {{ var_postfix_root_mail_alias }}'
    regexp: ^(?:[rR][oO][oO][tT]|"[rR][oO][oO][tT]")\s*:\s*(.+)$
    create: true
    state: present
  register: aliases_root_mail_alias_changed
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - postfix_client_configure_mail_alias

- name: Configure System to Forward All Mail For The Root Account - Check if newaliases
    command is available
  ansible.builtin.stat:
    path: /usr/bin/newaliases
  register: result_newaliases_present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - postfix_client_configure_mail_alias

- name: Configure System to Forward All Mail For The Root Account - Update postfix
    aliases
  ansible.builtin.command:
    cmd: newaliases
  when:
  - '"kernel" in ansible_facts.packages'
  - aliases_root_mail_alias_changed is changed
  - result_newaliases_present.stat.exists
  tags:
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - postfix_client_configure_mail_alias
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_postfix_root_mail_alias:var:1" value-id="xccdf_org.ssgproject.content_value_var_postfix_root_mail_alias"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-postfix_client_configure_mail_alias:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_postfix_client_configure_mail_alias_postmaster" selected="false" severity="medium">
              <xccdf-1.2:title>Configure System to Forward All Mail From Postmaster to The Root Account</xccdf-1.2:title>
              <xccdf-1.2:description>Verify the administrators are notified in the event of an audit processing failure.
Check that the "/etc/aliases" file has a defined value for "root".
<html:pre>$ sudo grep "postmaster:\s*root$" /etc/aliases

postmaster: root</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5.1(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000046-GPOS-00022</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030030</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230389r1017197_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>It is critical for the appropriate personnel to be aware if a system is at risk of failing to
process audit logs as required. Without this notification, the security personnel may be
unaware of an impending failure of the audit capability, and system operation may be adversely
affected.

Audit processing failures include software/hardware errors, failures in the audit capturing
mechanisms, and audit storage capacity being reached or exceeded.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="postfix_client_configure_mail_alias_postmaster" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/aliases" ] ; then
    
    LC_ALL=C sed -i "/^\s*postmaster\s*:\s*/Id" "/etc/aliases"
else
    touch "/etc/aliases"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/aliases"

cp "/etc/aliases" "/etc/aliases.bak"
# Insert at the end of the file
printf '%s\n' "postmaster: root" &gt;&gt; "/etc/aliases"
# Clean up after ourselves.
rm "/etc/aliases.bak"

if [ -f /usr/bin/newaliases ]; then
    newaliases
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="postfix_client_configure_mail_alias_postmaster" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030030
  - NIST-800-53-AU-5(a)
  - NIST-800-53-AU-5.1(ii)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - postfix_client_configure_mail_alias_postmaster

- name: Configure System to Forward All Mail From Postmaster to The Root Account
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/aliases
      create: true
      regexp: (?i)^\s*postmaster\s*:\s*
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/aliases
    ansible.builtin.lineinfile:
      path: /etc/aliases
      create: true
      regexp: (?i)^\s*postmaster\s*:\s*
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/aliases
    ansible.builtin.lineinfile:
      path: /etc/aliases
      create: true
      regexp: (?i)^\s*postmaster\s*:\s*
      line: 'postmaster: root'
      state: present
    register: aliases_postmaster_changed
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030030
  - NIST-800-53-AU-5(a)
  - NIST-800-53-AU-5.1(ii)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - postfix_client_configure_mail_alias_postmaster

- name: Configure System to Forward All Mail From Postmaster to The Root Account -
    Check if newaliases command is available
  ansible.builtin.stat:
    path: /usr/bin/newaliases
  register: result_newaliases_present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030030
  - NIST-800-53-AU-5(a)
  - NIST-800-53-AU-5.1(ii)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - postfix_client_configure_mail_alias_postmaster

- name: Configure System to Forward All Mail From Postmaster to The Root Account -
    Update postfix aliases
  ansible.builtin.command:
    cmd: newaliases
  when:
  - '"kernel" in ansible_facts.packages'
  - result_newaliases_present.stat.exists
  - aliases_postmaster_changed is changed
  tags:
  - DISA-STIG-RHEL-08-030030
  - NIST-800-53-AU-5(a)
  - NIST-800-53-AU-5.1(ii)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - postfix_client_configure_mail_alias_postmaster
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-postfix_client_configure_mail_alias_postmaster:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-postfix_client_configure_mail_alias_postmaster_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_postfix_client_configure_relayhost" selected="false" severity="medium">
              <xccdf-1.2:title>Configure System to Forward All Mail through a specific host</xccdf-1.2:title>
              <xccdf-1.2:description>Set up a relay host that will act as a gateway for all outbound email.
Edit the file <html:code>/etc/postfix/main.cf</html:code> to ensure that only the following
<html:code>relayhost</html:code> line appears:
<html:pre>relayhost = <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postfix_relayhost" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>A central outbound email location ensures messages sent from any network host
can be audited for potential unexpected content.  Tooling on the central server
may help prevent spam or viruses from being delivered.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_postfix"/>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-postfix_client_configure_relayhost_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_postfix_network_listening_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable Postfix Network Listening</xccdf-1.2:title>
              <xccdf-1.2:description>Edit the file <html:code>/etc/postfix/main.cf</html:code> to ensure that only the following
<html:code>inet_interfaces</html:code> line appears:
<html:pre>inet_interfaces = <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postfix_inet_interfaces" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R74</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.23</xccdf-1.2:reference>
              <xccdf-1.2:rationale>This ensures <html:code>postfix</html:code> accepts mail messages
(such as cron job reports) from the local system only,
and not from the network, which protects it from network attack.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_postfix"/>
              <xccdf-1.2:fix id="postfix_network_listening_disabled" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q postfix; }; then

var_postfix_inet_interfaces='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postfix_inet_interfaces" use="legacy"/>'


if [ -e "/etc/postfix/main.cf" ] ; then
    
    LC_ALL=C sed -i "/^\s*inet_interfaces\s\+=\s\+/Id" "/etc/postfix/main.cf"
else
    touch "/etc/postfix/main.cf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/postfix/main.cf"

cp "/etc/postfix/main.cf" "/etc/postfix/main.cf.bak"
# Insert at the end of the file
printf '%s\n' "inet_interfaces=$var_postfix_inet_interfaces" &gt;&gt; "/etc/postfix/main.cf"
# Clean up after ourselves.
rm "/etc/postfix/main.cf.bak"

systemctl restart postfix

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="postfix_network_listening_disabled" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - postfix_network_listening_disabled
  - restrict_strategy
- name: XCCDF Value var_postfix_inet_interfaces # promote to variable
  set_fact:
    var_postfix_inet_interfaces: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_postfix_inet_interfaces" use="legacy"/>
  tags:
    - always

- name: Make changes to Postfix configuration file
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/postfix/main.cf
      create: false
      regexp: (?i)^inet_interfaces\s*=\s*.*$
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/postfix/main.cf
    ansible.builtin.lineinfile:
      path: /etc/postfix/main.cf
      create: false
      regexp: (?i)^inet_interfaces\s*=\s*.*$
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/postfix/main.cf
    ansible.builtin.lineinfile:
      path: /etc/postfix/main.cf
      create: false
      regexp: (?i)^inet_interfaces\s*=\s*.*$
      line: inet_interfaces = {{ var_postfix_inet_interfaces }}
      state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"postfix" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-1.4
  - PCI-DSSv4-1.4.2
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - postfix_network_listening_disabled
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_postfix_inet_interfaces:var:1" value-id="xccdf_org.ssgproject.content_value_var_postfix_inet_interfaces"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-postfix_network_listening_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-postfix_network_listening_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_postfix_harden_os">
            <xccdf-1.2:title>Configure Operating System to Protect Mail Server</xccdf-1.2:title>
            <xccdf-1.2:description>The guidance in this section is appropriate for any host which is
operating as a site MTA, whether the mail server runs using Sendmail, Postfix,
or some other software.</xccdf-1.2:description>
            <xccdf-1.2:platform idref="#package_postfix"/>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_postfix_server_cfg">
              <xccdf-1.2:title>Configure Postfix if Necessary</xccdf-1.2:title>
              <xccdf-1.2:description>Postfix stores its configuration files in the directory
/etc/postfix by default. The primary configuration file is
<html:code>/etc/postfix/main.cf</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_postfix_server_banner" selected="false" severity="low">
                <xccdf-1.2:title>Configure SMTP Greeting Banner</xccdf-1.2:title>
                <xccdf-1.2:description>Edit <html:code>/etc/postfix/main.cf</html:code>, and add or correct the
following line, substituting some other wording for the banner information if
you prefer:
<html:pre>smtpd_banner = $myhostname ESMTP</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-8(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-8(c)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The default greeting banner discloses that the listening mail
process is Postfix.  When remote mail senders connect to the MTA on port 25,
they are greeted by an initial banner as part of the SMTP dialogue. This banner
is necessary, but it frequently gives away too much information, including the
MTA software which is in use, and sometimes also its version number. Remote
mail senders do not need this information in order to send mail, so the banner
should be changed to reveal only the hostname (which is already known and may
be useful) and the word ESMTP, to indicate that the modern SMTP protocol
variant is supported.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-postfix_server_banner:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_postfix_server_relay">
                <xccdf-1.2:title>Control Mail Relaying</xccdf-1.2:title>
                <xccdf-1.2:description>Postfix's mail relay controls are implemented with the help of the
smtpd recipient restrictions option, which controls the restrictions placed on
the SMTP dialogue once the sender and recipient envelope addresses are known.
The guidance in the following sections should be applied to all systems. If
there are systems which must be allowed to relay mail, but which cannot be
trusted to relay unconditionally, configure SMTP AUTH with SSL support.</xccdf-1.2:description>
                <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_postfix_prevent_unrestricted_relay" selected="false" severity="medium">
                  <xccdf-1.2:title>Prevent Unrestricted Mail Relaying</xccdf-1.2:title>
                  <xccdf-1.2:description>Modify the <html:pre>/etc/postfix/main.cf</html:pre> file to restrict client connections
to the local network with the following command:
<html:pre>$ sudo postconf -e 'smtpd_client_restrictions = permit_mynetworks,reject'</html:pre></xccdf-1.2:description>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040290</xccdf-1.2:reference>
                  <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230550r1017312_rule</xccdf-1.2:reference>
                  <xccdf-1.2:rationale>If unrestricted mail relaying is permitted, unauthorized senders could use this
host as a mail relay for the purpose of sending spam or other unauthorized
activity.</xccdf-1.2:rationale>
                  <xccdf-1.2:platform idref="#package_postfix"/>
                  <xccdf-1.2:fix id="postfix_prevent_unrestricted_relay" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; rpm --quiet -q postfix; then

if ! grep -q ^smtpd_client_restrictions /etc/postfix/main.cf; then
	echo "smtpd_client_restrictions = permit_mynetworks,reject" &gt;&gt; /etc/postfix/main.cf
else
	sed -i "s/^smtpd_client_restrictions.*/smtpd_client_restrictions = permit_mynetworks,reject/g" /etc/postfix/main.cf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                  <xccdf-1.2:fix complexity="low" disruption="low" id="postfix_prevent_unrestricted_relay" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040290
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - postfix_prevent_unrestricted_relay
  - restrict_strategy

- name: Prevent Unrestricted Mail Relaying
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/postfix/main.cf
      create: true
      regexp: (?i)^[ \t]*smtpd_client_restrictions\s*=\s*
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/postfix/main.cf
    ansible.builtin.lineinfile:
      path: /etc/postfix/main.cf
      create: true
      regexp: (?i)^[ \t]*smtpd_client_restrictions\s*=\s*
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/postfix/main.cf
    ansible.builtin.lineinfile:
      path: /etc/postfix/main.cf
      create: true
      regexp: (?i)^[ \t]*smtpd_client_restrictions\s*=\s*
      line: smtpd_client_restrictions = permit_mynetworks,reject
      state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"postfix" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040290
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - postfix_prevent_unrestricted_relay
  - restrict_strategy
</xccdf-1.2:fix>
                  <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-postfix_prevent_unrestricted_relay:def:1"/>
                  </xccdf-1.2:check>
                  <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                    <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-postfix_prevent_unrestricted_relay_ocil:questionnaire:1"/>
                  </xccdf-1.2:check>
                </xccdf-1.2:Rule>
              </xccdf-1.2:Group>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_nfs_and_rpc">
          <xccdf-1.2:title>NFS and RPC</xccdf-1.2:title>
          <xccdf-1.2:description>The Network File System is a popular distributed filesystem for
the Unix environment, and is very widely deployed.  This section discusses the
circumstances under which it is possible to disable NFS and its dependencies,
and then details steps which should be taken to secure
NFS's configuration. This section is relevant to systems operating as NFS
clients, as well as to those operating as NFS servers.</xccdf-1.2:description>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_nfs-utils_removed" selected="false" severity="low">
            <xccdf-1.2:title>Uninstall nfs-utils Package</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>nfs-utils</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase nfs-utils</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
            <xccdf-1.2:rationale><html:code>nfs-utils</html:code> provides a daemon for the kernel NFS server and related tools. This
package also contains the <html:code>showmount</html:code> program. <html:code>showmount</html:code> queries the mount
daemon on a remote host for information about the Network File System (NFS) server on the
remote host. For example, <html:code>showmount</html:code> can display the clients which are mounted on
that host.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_nfs-utils_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove nfs-utils
# from the system, and may remove any packages
# that depend on nfs-utils. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "nfs-utils" ; then
yum remove -y "nfs-utils"
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_nfs-utils_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall nfs-utils Package: Ensure nfs-utils is removed'
  ansible.builtin.package:
    name: nfs-utils
    state: absent
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_nfs-utils_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_nfs-utils_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_nfs-utils

class remove_nfs-utils {
  package { 'nfs-utils':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_nfs-utils_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=nfs-utils
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_nfs-utils_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove nfs-utils
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_nfs-utils_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove nfs-utils
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_nfs-utils_removed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_nfs-utils_removed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_nfs">
            <xccdf-1.2:title>Disable All NFS Services if Possible</xccdf-1.2:title>
            <xccdf-1.2:description>If there is not a reason for the system to operate as either an
NFS client or an NFS server, follow all instructions in this section to disable
subsystems required by NFS.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">The steps in this section will prevent a system
from operating as either an NFS client or an NFS server. Only perform these
steps on systems which do not need NFS at all.</xccdf-1.2:warning>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_netfs">
              <xccdf-1.2:title>Disable netfs if Possible</xccdf-1.2:title>
              <xccdf-1.2:description>To determine if any network filesystems handled by netfs are
currently mounted on the system execute the following command:
<html:pre>$ mount -t nfs,nfs4,smbfs,cifs,ncpfs</html:pre>
If the command did not return any output then disable netfs.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_netfs_disabled" selected="false" severity="unknown">
                <xccdf-1.2:title>Disable Network File Systems (netfs)</xccdf-1.2:title>
                <xccdf-1.2:description>The netfs script manages the boot-time mounting of several types
of networked filesystems, of which NFS and Samba are the most common. If these
filesystem types are not in use, the script can be disabled, protecting the
system somewhat against accidental or malicious changes to <html:code>/etc/fstab</html:code>
and against flaws in the netfs script itself.

The <html:code>netfs</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now netfs.service</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_netfs_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'netfs.service'
fi
"$SYSTEMCTL_EXEC" disable 'netfs.service'
"$SYSTEMCTL_EXEC" mask 'netfs.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files netfs.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'netfs.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'netfs.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'netfs.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_netfs_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_netfs_disabled
  - unknown_severity

- name: Disable Network File Systems (netfs) - Disable service netfs
  block:

  - name: Disable Network File Systems (netfs) - Collect systemd Services Present
      in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Network File Systems (netfs) - Ensure netfs.service is Masked
    ansible.builtin.systemd:
      name: netfs.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("netfs.service", multiline=True)

  - name: Unit Socket Exists - netfs.socket
    ansible.builtin.command: systemctl -q list-unit-files netfs.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Network File Systems (netfs) - Disable Socket netfs
    ansible.builtin.systemd:
      name: netfs.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("netfs.socket", multiline=True)
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_netfs_disabled
  - special_service_block
  - unknown_severity
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_netfs_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_netfs

class disable_netfs {
  service {'netfs':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="service_netfs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: netfs.service
        enabled: false
        mask: true
      - name: netfs.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="service_netfs_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["netfs"]
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_netfs_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable netfs
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_netfs_disabled:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_nfs_services">
              <xccdf-1.2:title>Disable Services Used Only by NFS</xccdf-1.2:title>
              <xccdf-1.2:description>If NFS is not needed, disable the NFS client daemons nfslock, rpcgssd, and rpcidmapd.
<html:br/><html:br/>
All of these daemons run with elevated privileges, and many listen for network
connections. If they are not needed, they should be disabled to improve system
security posture.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_rpcbind_removed" selected="false" severity="low">
                <xccdf-1.2:title>Uninstall rpcbind Package</xccdf-1.2:title>
                <xccdf-1.2:description>The rpcbind utility maps RPC services to the ports on which they listen.
RPC processes notify rpcbind when they start, registering the ports they
are listening on and the RPC program numbers they expect to serve. The
rpcbind service redirects the client to the proper port number so it can
communicate with the requested service. If the system does not require RPC
(such as for NFS servers) then this service should be disabled.
The <html:code>rpcbind</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase rpcbind</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale>If the system does not require rpc based services, it is recommended that
rpcbind be disabled to reduce the attack surface.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_rpcbind_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# CAUTION: This remediation script will remove rpcbind
# from the system, and may remove any packages
# that depend on rpcbind. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "rpcbind" ; then
yum remove -y "rpcbind"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_rpcbind_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_rpcbind_removed

- name: 'Uninstall rpcbind Package: Ensure rpcbind is removed'
  ansible.builtin.package:
    name: rpcbind
    state: absent
  when: '"kernel" in ansible_facts.packages'
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_rpcbind_removed
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_rpcbind_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_rpcbind

class remove_rpcbind {
  package { 'rpcbind':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_rpcbind_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=rpcbind
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_rpcbind_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove rpcbind
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="package_rpcbind_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove rpcbind
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_rpcbind_removed:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_rpcbind_removed_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_nfslock_disabled" selected="false" severity="unknown">
                <xccdf-1.2:title>Disable Network File System Lock Service (nfslock)</xccdf-1.2:title>
                <xccdf-1.2:description>The Network File System Lock (nfslock) service starts the required
remote procedure call (RPC) processes which allow clients to lock files on the
server. If the local system is not configured to mount NFS filesystems then
this service should be disabled.

The <html:code>nfslock</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now nfslock.service</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_nfslock_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'nfslock.service'
fi
"$SYSTEMCTL_EXEC" disable 'nfslock.service'
"$SYSTEMCTL_EXEC" mask 'nfslock.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files nfslock.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'nfslock.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'nfslock.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'nfslock.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_nfslock_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_nfslock_disabled
  - unknown_severity

- name: Disable Network File System Lock Service (nfslock) - Disable service nfslock
  block:

  - name: Disable Network File System Lock Service (nfslock) - Collect systemd Services
      Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Network File System Lock Service (nfslock) - Ensure nfslock.service
      is Masked
    ansible.builtin.systemd:
      name: nfslock.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("nfslock.service", multiline=True)

  - name: Unit Socket Exists - nfslock.socket
    ansible.builtin.command: systemctl -q list-unit-files nfslock.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Network File System Lock Service (nfslock) - Disable Socket nfslock
    ansible.builtin.systemd:
      name: nfslock.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("nfslock.socket", multiline=True)
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_nfslock_disabled
  - special_service_block
  - unknown_severity
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_nfslock_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_nfslock

class disable_nfslock {
  service {'nfslock':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="service_nfslock_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: nfslock.service
        enabled: false
        mask: true
      - name: nfslock.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="service_nfslock_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["nfslock"]
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_nfslock_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable nfslock
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_nfslock_disabled:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_rpcbind_disabled" selected="false" severity="low">
                <xccdf-1.2:title>Disable rpcbind Service</xccdf-1.2:title>
                <xccdf-1.2:description>The rpcbind utility maps RPC services to the ports on which they listen.
RPC processes notify rpcbind when they start, registering the ports they
are listening on and the RPC program numbers they expect to serve. The
rpcbind service redirects the client to the proper port number so it can
communicate with the requested service. If the system does not require RPC
(such as for NFS servers) then this service should be disabled.

The <html:code>rpcbind</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now rpcbind.service</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.12</xccdf-1.2:reference>
                <xccdf-1.2:rationale>If the system does not require rpc based services, it is recommended that
rpcbind be disabled to reduce the attack surface.</xccdf-1.2:rationale>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_rpcbind_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'rpcbind.service'
fi
"$SYSTEMCTL_EXEC" disable 'rpcbind.service'
"$SYSTEMCTL_EXEC" mask 'rpcbind.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files rpcbind.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'rpcbind.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'rpcbind.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'rpcbind.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_rpcbind_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_rpcbind_disabled

- name: Disable rpcbind Service - Disable service rpcbind
  block:

  - name: Disable rpcbind Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable rpcbind Service - Ensure rpcbind.service is Masked
    ansible.builtin.systemd:
      name: rpcbind.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("rpcbind.service", multiline=True)

  - name: Unit Socket Exists - rpcbind.socket
    ansible.builtin.command: systemctl -q list-unit-files rpcbind.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable rpcbind Service - Disable Socket rpcbind
    ansible.builtin.systemd:
      name: rpcbind.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("rpcbind.socket", multiline=True)
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_rpcbind_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_rpcbind_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_rpcbind

class disable_rpcbind {
  service {'rpcbind':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="service_rpcbind_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: rpcbind.service
        enabled: false
        mask: true
      - name: rpcbind.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="service_rpcbind_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["rpcbind"]
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_rpcbind_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable rpcbind
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_rpcbind_disabled:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_rpcgssd_disabled" selected="false" severity="unknown">
                <xccdf-1.2:title>Disable Secure RPC Client Service (rpcgssd)</xccdf-1.2:title>
                <xccdf-1.2:description>The rpcgssd service manages RPCSEC GSS contexts required to secure protocols
that use RPC (most often Kerberos and NFS). The rpcgssd service is the
client-side of RPCSEC GSS. If the system does not require secure RPC then this
service should be disabled.

The <html:code>rpcgssd</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now rpcgssd.service</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_rpcgssd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'rpcgssd.service'
fi
"$SYSTEMCTL_EXEC" disable 'rpcgssd.service'
"$SYSTEMCTL_EXEC" mask 'rpcgssd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files rpcgssd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'rpcgssd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'rpcgssd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'rpcgssd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_rpcgssd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_rpcgssd_disabled
  - unknown_severity

- name: Disable Secure RPC Client Service (rpcgssd) - Disable service rpcgssd
  block:

  - name: Disable Secure RPC Client Service (rpcgssd) - Collect systemd Services Present
      in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Secure RPC Client Service (rpcgssd) - Ensure rpcgssd.service is
      Masked
    ansible.builtin.systemd:
      name: rpcgssd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("rpcgssd.service", multiline=True)

  - name: Unit Socket Exists - rpcgssd.socket
    ansible.builtin.command: systemctl -q list-unit-files rpcgssd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Secure RPC Client Service (rpcgssd) - Disable Socket rpcgssd
    ansible.builtin.systemd:
      name: rpcgssd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("rpcgssd.socket", multiline=True)
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_rpcgssd_disabled
  - special_service_block
  - unknown_severity
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_rpcgssd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_rpcgssd

class disable_rpcgssd {
  service {'rpcgssd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="service_rpcgssd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: rpcgssd.service
        enabled: false
        mask: true
      - name: rpcgssd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="service_rpcgssd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["rpcgssd"]
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_rpcgssd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable rpcgssd
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_rpcgssd_disabled:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_rpcidmapd_disabled" selected="false" severity="unknown">
                <xccdf-1.2:title>Disable RPC ID Mapping Service (rpcidmapd)</xccdf-1.2:title>
                <xccdf-1.2:description>The rpcidmapd service is used to map user names and groups to UID
and GID numbers on NFSv4 mounts. If NFS is not in use on the local system then
this service should be disabled.

The <html:code>rpcidmapd</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now rpcidmapd.service</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_rpcidmapd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'rpcidmapd.service'
fi
"$SYSTEMCTL_EXEC" disable 'rpcidmapd.service'
"$SYSTEMCTL_EXEC" mask 'rpcidmapd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files rpcidmapd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'rpcidmapd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'rpcidmapd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'rpcidmapd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_rpcidmapd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_rpcidmapd_disabled
  - unknown_severity

- name: Disable RPC ID Mapping Service (rpcidmapd) - Disable service rpcidmapd
  block:

  - name: Disable RPC ID Mapping Service (rpcidmapd) - Collect systemd Services Present
      in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable RPC ID Mapping Service (rpcidmapd) - Ensure rpcidmapd.service is
      Masked
    ansible.builtin.systemd:
      name: rpcidmapd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("rpcidmapd.service", multiline=True)

  - name: Unit Socket Exists - rpcidmapd.socket
    ansible.builtin.command: systemctl -q list-unit-files rpcidmapd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable RPC ID Mapping Service (rpcidmapd) - Disable Socket rpcidmapd
    ansible.builtin.systemd:
      name: rpcidmapd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("rpcidmapd.socket", multiline=True)
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_rpcidmapd_disabled
  - special_service_block
  - unknown_severity
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_rpcidmapd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_rpcidmapd

class disable_rpcidmapd {
  service {'rpcidmapd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="service_rpcidmapd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: rpcidmapd.service
        enabled: false
        mask: true
      - name: rpcidmapd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="service_rpcidmapd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["rpcidmapd"]
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_rpcidmapd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable rpcidmapd
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_rpcidmapd_disabled:def:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines">
            <xccdf-1.2:title>Configure All Systems which Use NFS</xccdf-1.2:title>
            <xccdf-1.2:description>The steps in this section are appropriate for all systems which
run NFS, whether they operate as clients or as servers.</xccdf-1.2:description>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports">
              <xccdf-1.2:title>Configure NFS Services to Use Fixed Ports (NFSv3 and NFSv2)</xccdf-1.2:title>
              <xccdf-1.2:description>Firewalling should be done at each host and at the border
firewalls to protect the NFS daemons from remote access, since NFS servers
should never be accessible from outside the organization. However, by default
for NFSv3 and NFSv2, the RPC Bind service assigns each NFS service to a port
dynamically at service startup time. Dynamic ports cannot be protected by port
filtering firewalls such as <html:code>iptables</html:code>.
<html:br/><html:br/>
Therefore, restrict each service to always use a given port, so that
firewalling can be done effectively. Note that, because of the way RPC is
implemented, it is not possible to disable the RPC Bind service even if ports
are assigned statically to all RPC services.
<html:br/><html:br/>
In NFSv4, the mounting and locking protocols have been incorporated into the
protocol, and the server listens on the the well-known TCP port 2049. As such,
NFSv4 does not need to interact with the <html:code>rpcbind, lockd, and rpc.statd</html:code>
daemons, which can and should be disabled in a pure NFSv4 environment. The
<html:code>rpc.mountd</html:code> daemon is still required on the NFS server to setup
exports, but is not involved in any over-the-wire operations.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_nfs_fixed_lockd_tcp_port" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure lockd to use static TCP port</xccdf-1.2:title>
                <xccdf-1.2:description>Configure the <html:code>lockd</html:code> daemon to use a static TCP port as
opposed to letting the RPC Bind service dynamically assign a port. Edit the
file <html:code>/etc/sysconfig/nfs</html:code>. Add or correct the following line:
<html:pre>LOCKD_TCPPORT=lockd-port</html:pre>
Where <html:code>lockd-port</html:code> is a port which is not used by any other service on
your network.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Restrict service to always use a given port, so that firewalling can be done
effectively.</xccdf-1.2:rationale>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_nfs_fixed_lockd_udp_port" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure lockd to use static UDP port</xccdf-1.2:title>
                <xccdf-1.2:description>Configure the <html:code>lockd</html:code> daemon to use a static UDP port as
opposed to letting the RPC Bind service dynamically assign a port. Edit the
file <html:code>/etc/sysconfig/nfs</html:code>. Add or correct the following line:
<html:pre>LOCKD_UDPPORT=lockd-port</html:pre>
Where <html:code>lockd-port</html:code> is a port which is not used by any other service on
your network.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Restricting services to always use a given port enables firewalling
to be done more effectively.</xccdf-1.2:rationale>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_nfs_fixed_mountd_port" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure mountd to use static port</xccdf-1.2:title>
                <xccdf-1.2:description>Configure the <html:code>mountd</html:code> daemon to use a static port as
opposed to letting the RPC Bind service dynamically assign a port. Edit the
file <html:code>/etc/sysconfig/nfs</html:code>. Add or correct the following line:
<html:pre>MOUNTD_PORT=statd-port</html:pre>
Where <html:code>mountd-port</html:code> is a port which is not used by any other service on your network.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Restricting services to always use a given port enables firewalling
to be done more effectively.</xccdf-1.2:rationale>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_nfs_fixed_statd_port" selected="false" severity="unknown">
                <xccdf-1.2:title>Configure statd to use static port</xccdf-1.2:title>
                <xccdf-1.2:description>Configure the <html:code>statd</html:code> daemon to use a static port as
opposed to letting the RPC Bind service dynamically assign a port. Edit the
file <html:code>/etc/sysconfig/nfs</html:code>. Add or correct the following line:
<html:pre>STATD_PORT=statd-port</html:pre>
Where <html:code>statd-port</html:code> is a port which is not used by any other service on your network.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Restricting services to always use a given port enables firewalling
to be done more effectively.</xccdf-1.2:rationale>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_nfs_configuring_clients">
            <xccdf-1.2:title>Configure NFS Clients</xccdf-1.2:title>
            <xccdf-1.2:description>The steps in this section are appropriate for systems which operate as NFS clients.</xccdf-1.2:description>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_nfsd">
              <xccdf-1.2:title>Disable NFS Server Daemons</xccdf-1.2:title>
              <xccdf-1.2:description>There is no need to run the NFS server daemons <html:code>nfs</html:code> and
<html:code>rpcsvcgssd</html:code> except on a small number of properly secured systems
designated as NFS servers. Ensure that these daemons are turned off on
clients.</xccdf-1.2:description>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_nfs_disabled" selected="false" severity="unknown">
                <xccdf-1.2:title>Disable Network File System (nfs)</xccdf-1.2:title>
                <xccdf-1.2:description>The Network File System (NFS) service allows remote hosts to mount
and interact with shared filesystems on the local system. If the local system
is not designated as a NFS server then this service should be disabled.

The <html:code>nfs-server</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now nfs-server.service</html:pre></xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.9</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Unnecessary services should be disabled to decrease the attack surface of the system.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_nfs_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'nfs-server.service'
fi
"$SYSTEMCTL_EXEC" disable 'nfs-server.service'
"$SYSTEMCTL_EXEC" mask 'nfs-server.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files nfs-server.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'nfs-server.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'nfs-server.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'nfs-server.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_nfs_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_nfs_disabled
  - unknown_severity

- name: Disable Network File System (nfs) - Disable service nfs-server
  block:

  - name: Disable Network File System (nfs) - Collect systemd Services Present in
      the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Network File System (nfs) - Ensure nfs-server.service is Masked
    ansible.builtin.systemd:
      name: nfs-server.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("nfs-server.service", multiline=True)

  - name: Unit Socket Exists - nfs-server.socket
    ansible.builtin.command: systemctl -q list-unit-files nfs-server.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Network File System (nfs) - Disable Socket nfs-server
    ansible.builtin.systemd:
      name: nfs-server.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("nfs-server.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_nfs_disabled
  - special_service_block
  - unknown_severity
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_nfs_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_nfs-server

class disable_nfs-server {
  service {'nfs-server':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="service_nfs_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: nfs-server.service
        enabled: false
        mask: true
      - name: nfs-server.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="service_nfs_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["nfs-server"]
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_nfs_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable nfs-server
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_nfs_disabled:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_nfs_disabled_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_rpcsvcgssd_disabled" selected="false" severity="unknown">
                <xccdf-1.2:title>Disable Secure RPC Server Service (rpcsvcgssd)</xccdf-1.2:title>
                <xccdf-1.2:description>The rpcsvcgssd service manages RPCSEC GSS contexts required to
secure protocols that use RPC (most often Kerberos and NFS). The rpcsvcgssd
service is the server-side of RPCSEC GSS. If the system does not require secure
RPC then this service should be disabled.

The <html:code>rpcsvcgssd</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now rpcsvcgssd.service</html:pre></xccdf-1.2:description>
                <xccdf-1.2:rationale>Unnecessary services should be disabled to decrease the attack surface of the system.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#system_with_kernel"/>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_rpcsvcgssd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'rpcsvcgssd.service'
fi
"$SYSTEMCTL_EXEC" disable 'rpcsvcgssd.service'
"$SYSTEMCTL_EXEC" mask 'rpcsvcgssd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files rpcsvcgssd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'rpcsvcgssd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'rpcsvcgssd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'rpcsvcgssd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_rpcsvcgssd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_rpcsvcgssd_disabled
  - unknown_severity

- name: Disable Secure RPC Server Service (rpcsvcgssd) - Disable service rpcsvcgssd
  block:

  - name: Disable Secure RPC Server Service (rpcsvcgssd) - Collect systemd Services
      Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Secure RPC Server Service (rpcsvcgssd) - Ensure rpcsvcgssd.service
      is Masked
    ansible.builtin.systemd:
      name: rpcsvcgssd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("rpcsvcgssd.service", multiline=True)

  - name: Unit Socket Exists - rpcsvcgssd.socket
    ansible.builtin.command: systemctl -q list-unit-files rpcsvcgssd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Secure RPC Server Service (rpcsvcgssd) - Disable Socket rpcsvcgssd
    ansible.builtin.systemd:
      name: rpcsvcgssd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("rpcsvcgssd.socket", multiline=True)
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_rpcsvcgssd_disabled
  - special_service_block
  - unknown_severity
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_rpcsvcgssd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_rpcsvcgssd

class disable_rpcsvcgssd {
  service {'rpcsvcgssd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="service_rpcsvcgssd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: rpcsvcgssd.service
        enabled: false
        mask: true
      - name: rpcsvcgssd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
                <xccdf-1.2:fix id="service_rpcsvcgssd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["rpcsvcgssd"]
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="low" id="service_rpcsvcgssd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable rpcsvcgssd
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_rpcsvcgssd_disabled:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_rpcsvcgssd_disabled_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_nfs_no_anonymous" selected="false" severity="unknown">
                <xccdf-1.2:title>Specify UID and GID for Anonymous NFS Connections</xccdf-1.2:title>
                <xccdf-1.2:description>To specify the UID and GID for remote root users, edit the <html:code>/etc/exports</html:code> file and add the following for each export:
<html:pre>
anonuid=<html:code>value greater than UID_MAX from /etc/login.defs</html:code>
anongid=<html:code>value greater than GID_MAX from /etc/login.defs</html:code>
</html:pre>
Note that a value of "-1" is technically acceptable as this will randomize the <html:code>anonuid</html:code> and
<html:code>anongid</html:code> values on a Red Hat Enterprise Linux based NFS server. While acceptable from a security perspective,
a value of <html:code>-1</html:code>  may cause interoperability issues, particularly with Red Hat Enterprise Linux 7 client systems.
Alternatively, functionally equivalent values of 60001, 65534, 65535 may be used.</xccdf-1.2:description>
                <xccdf-1.2:rationale>Specifying the anonymous UID and GID ensures that the remote root user is mapped
to a local account which has no permissions on the system.</xccdf-1.2:rationale>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-nfs_no_anonymous_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
            <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_mounting_remote_filesystems">
              <xccdf-1.2:title>Mount Remote Filesystems with Restrictive Options</xccdf-1.2:title>
              <xccdf-1.2:description>Edit the file <html:code>/etc/fstab</html:code>. For each filesystem whose type
(column 3) is <html:code>nfs</html:code> or <html:code>nfs4</html:code>, add the text
<html:code>,nodev,nosuid</html:code> to the list of mount options in column 4. If
appropriate, also add <html:code>,noexec</html:code>.
<html:br/><html:br/>
See the section titled "Restrict Partition Mount Options" for a description of
the effects of these options. In general, execution of files mounted via NFS
should be considered risky because of the possibility that an adversary could
intercept the request and substitute a malicious file. Allowing setuid files to
be executed from remote servers is particularly risky, both for this reason and
because it requires the clients to extend root-level trust to the NFS
server.</xccdf-1.2:description>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_krb_sec_remote_filesystems" selected="false" severity="medium">
                <xccdf-1.2:title>Mount Remote Filesystems with Kerberos Security</xccdf-1.2:title>
                <xccdf-1.2:description>Add the <html:code>sec=krb5:krb5i:krb5p</html:code> option to the fourth column of <html:code>/etc/fstab</html:code> for the line which controls mounting of
any NFS mounts.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(8)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(9)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:rationale>When an NFS server is configured to use AUTH_SYS a selected userid and groupid are used to handle
requests from the remote user. The userid and groupid could mistakenly or maliciously be set
incorrectly. The AUTH_GSS method of authentication uses certificates on the server and client
systems to more securely authenticate the remote mount request.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#nfs_mount_defined"/>
                <xccdf-1.2:fix id="mount_option_krb_sec_remote_filesystems" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

vfstype_points=()
readarray -t vfstype_points &lt; &lt;(grep -E "[[:space:]]nfs[4]?[[:space:]]" /etc/fstab | awk '{print $2}')

for vfstype_point in "${vfstype_points[@]}"
do
    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" ${vfstype_point//\\/\\\\})"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|sec=krb5:krb5i:krb5p)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type="nfs4"
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " ${vfstype_point//\\/\\\\} nfs4 defaults,${previous_mount_opts}sec=krb5:krb5i:krb5p 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "sec=krb5:krb5i:krb5p"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,sec=krb5:krb5i:krb5p|" /etc/fstab
    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="mount_option_krb_sec_remote_filesystems" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-2
  - NIST-800-53-IA-2(8)
  - NIST-800-53-IA-2(9)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - mount_option_krb_sec_remote_filesystems
  - no_reboot_needed

- name: Get nfs and nfs4 mount points, that don't have sec=krb5:krb5i:krb5p
  ansible.builtin.command: findmnt --fstab --types nfs,nfs4 -O nosec=krb5:krb5i:krb5p
    -n -P
  register: points_register
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-2
  - NIST-800-53-IA-2(8)
  - NIST-800-53-IA-2(9)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - mount_option_krb_sec_remote_filesystems
  - no_reboot_needed

- name: Add sec=krb5:krb5i:krb5p to nfs and nfs4 mount points
  ansible.posix.mount:
    path: '{{ item | regex_search(''TARGET="([^"]+)"'',''\1'') | first }}'
    src: '{{ item | regex_search(''SOURCE="([^"]+)"'',''\1'') | first }}'
    fstype: '{{ item | regex_search(''FSTYPE="([^"]+)"'',''\1'') | first }}'
    state: present
    opts: '{{ item | regex_search(''OPTIONS="([^"]+)"'',''\1'') | first }},sec=krb5:krb5i:krb5p'
  when:
  - '"kernel" in ansible_facts.packages'
  - (points_register.stdout | length &gt; 0) and '\\x09' not in item
  with_items: '{{ points_register.stdout_lines }}'
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-2
  - NIST-800-53-IA-2(8)
  - NIST-800-53-IA-2(9)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - mount_option_krb_sec_remote_filesystems
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_krb_sec_remote_filesystems:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_krb_sec_remote_filesystems_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_nodev_remote_filesystems" selected="false" severity="medium">
                <xccdf-1.2:title>Mount Remote Filesystems with nodev</xccdf-1.2:title>
                <xccdf-1.2:description>Add the <html:code>nodev</html:code> option to the fourth column of <html:code>/etc/fstab</html:code> for the line which controls mounting of
any NFS mounts.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.9</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.3.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MP-2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010640</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230307r1155388_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>Legitimate device files should only exist in the /dev directory. NFS mounts
should not present device files to users.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#nfs_mount_defined"/>
                <xccdf-1.2:fix id="mount_option_nodev_remote_filesystems" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

vfstype_points=()
readarray -t vfstype_points &lt; &lt;(grep -E "[[:space:]]nfs[4]?[[:space:]]" /etc/fstab | awk '{print $2}')

for vfstype_point in "${vfstype_points[@]}"
do
    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" ${vfstype_point//\\/\\\\})"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nodev)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type="nfs4"
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " ${vfstype_point//\\/\\\\} nfs4 defaults,${previous_mount_opts}nodev 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nodev"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nodev|" /etc/fstab
    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="mount_option_nodev_remote_filesystems" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010640
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MP-2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - mount_option_nodev_remote_filesystems
  - no_reboot_needed

- name: Get nfs and nfs4 mount points, that don't have nodev
  ansible.builtin.command: findmnt --fstab --types nfs,nfs4 -O nonodev -n -P
  register: points_register
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010640
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MP-2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - mount_option_nodev_remote_filesystems
  - no_reboot_needed

- name: Add nodev to nfs and nfs4 mount points
  ansible.posix.mount:
    path: '{{ item | regex_search(''TARGET="([^"]+)"'',''\1'') | first }}'
    src: '{{ item | regex_search(''SOURCE="([^"]+)"'',''\1'') | first }}'
    fstype: '{{ item | regex_search(''FSTYPE="([^"]+)"'',''\1'') | first }}'
    state: present
    opts: '{{ item | regex_search(''OPTIONS="([^"]+)"'',''\1'') | first }},nodev'
  when:
  - '"kernel" in ansible_facts.packages'
  - (points_register.stdout | length &gt; 0) and '\\x09' not in item
  with_items: '{{ points_register.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010640
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MP-2
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - mount_option_nodev_remote_filesystems
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_nodev_remote_filesystems:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_nodev_remote_filesystems_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_noexec_remote_filesystems" selected="false" severity="medium">
                <xccdf-1.2:title>Mount Remote Filesystems with noexec</xccdf-1.2:title>
                <xccdf-1.2:description>Add the <html:code>noexec</html:code> option to the fourth column of <html:code>/etc/fstab</html:code> for the line which controls mounting of
any NFS mounts.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(8)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(10)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010630</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230306r1155386_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>The noexec mount option causes the system not to execute binary files. This option must be used
for mounting any file system not containing approved binary files as they may be incompatible. Executing
files from untrusted file systems increases the opportunity for unprivileged users to attain unauthorized
administrative access.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#nfs_mount_defined"/>
                <xccdf-1.2:fix id="mount_option_noexec_remote_filesystems" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

vfstype_points=()
readarray -t vfstype_points &lt; &lt;(grep -E "[[:space:]]nfs[4]?[[:space:]]" /etc/fstab | awk '{print $2}')

for vfstype_point in "${vfstype_points[@]}"
do
    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" ${vfstype_point//\\/\\\\})"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|noexec)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type="nfs4"
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " ${vfstype_point//\\/\\\\} nfs4 defaults,${previous_mount_opts}noexec 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "noexec"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,noexec|" /etc/fstab
    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="mount_option_noexec_remote_filesystems" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010630
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(10)
  - NIST-800-53-AC-6(8)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - mount_option_noexec_remote_filesystems
  - no_reboot_needed

- name: Get nfs and nfs4 mount points, that don't have noexec
  ansible.builtin.command: findmnt --fstab --types nfs,nfs4 -O nonoexec -n -P
  register: points_register
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010630
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(10)
  - NIST-800-53-AC-6(8)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - mount_option_noexec_remote_filesystems
  - no_reboot_needed

- name: Add noexec to nfs and nfs4 mount points
  ansible.posix.mount:
    path: '{{ item | regex_search(''TARGET="([^"]+)"'',''\1'') | first }}'
    src: '{{ item | regex_search(''SOURCE="([^"]+)"'',''\1'') | first }}'
    fstype: '{{ item | regex_search(''FSTYPE="([^"]+)"'',''\1'') | first }}'
    state: present
    opts: '{{ item | regex_search(''OPTIONS="([^"]+)"'',''\1'') | first }},noexec'
  when:
  - '"kernel" in ansible_facts.packages'
  - (points_register.stdout | length &gt; 0) and '\\x09' not in item
  with_items: '{{ points_register.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010630
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(10)
  - NIST-800-53-AC-6(8)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - mount_option_noexec_remote_filesystems
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_noexec_remote_filesystems:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_noexec_remote_filesystems_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
              <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_nosuid_remote_filesystems" selected="false" severity="medium">
                <xccdf-1.2:title>Mount Remote Filesystems with nosuid</xccdf-1.2:title>
                <xccdf-1.2:description>Add the <html:code>nosuid</html:code> option to the fourth column of <html:code>/etc/fstab</html:code> for the line which controls mounting of
any NFS mounts.</xccdf-1.2:description>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM6(a)</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010650</xccdf-1.2:reference>
                <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230308r1155390_rule</xccdf-1.2:reference>
                <xccdf-1.2:rationale>NFS mounts should not present suid binaries to users. Only vendor-supplied suid executables
should be installed to their default location on the local filesystem.</xccdf-1.2:rationale>
                <xccdf-1.2:platform idref="#nfs_mount_defined"/>
                <xccdf-1.2:fix id="mount_option_nosuid_remote_filesystems" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

vfstype_points=()
readarray -t vfstype_points &lt; &lt;(grep -E "[[:space:]]nfs[4]?[[:space:]]" /etc/fstab | awk '{print $2}')

for vfstype_point in "${vfstype_points[@]}"
do
    mount_point_match_regexp="$(printf "^[[:space:]]*[^#].*[[:space:]]%s[[:space:]]" ${vfstype_point//\\/\\\\})"

    # If the mount point is not in /etc/fstab, get previous mount options from /etc/mtab
    if ! grep -q "$mount_point_match_regexp" /etc/fstab; then
        # runtime opts without some automatic kernel/userspace-added defaults
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/mtab | head -1 |  awk '{print $4}' \
                    | sed -E "s/(rw|defaults|seclabel|nosuid)(,|$)//g;s/,$//")
        [ "$previous_mount_opts" ] &amp;&amp; previous_mount_opts+=","
        # In iso9660 filesystems mtab could describe a "blocksize" value, this should be reflected in
        # fstab as "block".  The next variable is to satisfy shellcheck SC2050.
        fs_type="nfs4"
        if [  "$fs_type" == "iso9660" ] ; then
            previous_mount_opts=$(sed 's/blocksize=/block=/' &lt;&lt;&lt; "$previous_mount_opts")
        fi
        echo " ${vfstype_point//\\/\\\\} nfs4 defaults,${previous_mount_opts}nosuid 0 0" &gt;&gt; /etc/fstab
    # If the mount_opt option is not already in the mount point's /etc/fstab entry, add it
    elif ! grep "$mount_point_match_regexp" /etc/fstab | grep -q "nosuid"; then
        previous_mount_opts=$(grep "$mount_point_match_regexp" /etc/fstab | awk '{print $4}')
        sed -i "s|\(${mount_point_match_regexp}.*${previous_mount_opts}\)|\1,nosuid|" /etc/fstab
    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
                <xccdf-1.2:fix complexity="low" disruption="medium" id="mount_option_nosuid_remote_filesystems" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010650
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM6(a)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - mount_option_nosuid_remote_filesystems
  - no_reboot_needed

- name: Get nfs and nfs4 mount points, that don't have nosuid
  ansible.builtin.command: findmnt --fstab --types nfs,nfs4 -O nonosuid -n -P
  register: points_register
  check_mode: false
  changed_when: false
  failed_when: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010650
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM6(a)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - mount_option_nosuid_remote_filesystems
  - no_reboot_needed

- name: Add nosuid to nfs and nfs4 mount points
  ansible.posix.mount:
    path: '{{ item | regex_search(''TARGET="([^"]+)"'',''\1'') | first }}'
    src: '{{ item | regex_search(''SOURCE="([^"]+)"'',''\1'') | first }}'
    fstype: '{{ item | regex_search(''FSTYPE="([^"]+)"'',''\1'') | first }}'
    state: present
    opts: '{{ item | regex_search(''OPTIONS="([^"]+)"'',''\1'') | first }},nosuid'
  when:
  - '"kernel" in ansible_facts.packages'
  - (points_register.stdout | length &gt; 0) and '\\x09' not in item
  with_items: '{{ points_register.stdout_lines }}'
  tags:
  - DISA-STIG-RHEL-08-010650
  - NIST-800-53-AC-6
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM6(a)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - mount_option_nosuid_remote_filesystems
  - no_reboot_needed
</xccdf-1.2:fix>
                <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_nosuid_remote_filesystems:def:1"/>
                </xccdf-1.2:check>
                <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                  <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_nosuid_remote_filesystems_ocil:questionnaire:1"/>
                </xccdf-1.2:check>
              </xccdf-1.2:Rule>
            </xccdf-1.2:Group>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_nfs_configuring_servers">
            <xccdf-1.2:title>Configure NFS Servers</xccdf-1.2:title>
            <xccdf-1.2:description>The steps in this section are appropriate for systems which operate as NFS servers.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_all_squash_exports" selected="false" severity="low">
              <xccdf-1.2:title>Ensure All-Squashing Disabled On All Exports</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>all_squash</html:code> maps all uids and gids to an anonymous user.
This should be disabled by removing any instances of the
<html:code>all_squash</html:code> option from the file <html:code>/etc/exports</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:rationale>The all_squash option maps all client requests to a single anonymous
uid/gid on the NFS server, negating the ability to track file access
by user ID.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_all_squash_exports_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_insecure_locks_exports" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure Insecure File Locking is Not Allowed</xccdf-1.2:title>
              <xccdf-1.2:description>By default the NFS server requires secure file-lock requests, which require
credentials from the client in order to lock a file. Most NFS clients send
credentials with file lock requests, however, there are a few clients that
do not send credentials when requesting a file-lock, allowing the client to
only be able to lock world-readable files. To get around this, the
<html:code>insecure_locks</html:code> option can be used so these clients can access the
desired export. This poses a security risk by potentially allowing the
client access to data for which it does not have authorization. Remove any
instances of the <html:code>insecure_locks</html:code> option from the file
<html:code>/etc/exports</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:rationale>Allowing insecure file locking could allow for sensitive data to be
viewed or edited by an unauthorized user.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_insecure_locks_exports:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_insecure_locks_exports_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_restrict_nfs_clients_to_privileged_ports" selected="false" severity="unknown">
              <xccdf-1.2:title>Restrict NFS Clients to Privileged Ports</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the server NFS implementation requires that all client requests be made
from ports less than 1024. If your organization has control over systems connected to its
network, and if NFS requests are prohibited at the border firewall, this offers some protection
against malicious requests from unprivileged users. Therefore, the default should not be changed.
<html:br/><html:br/>
To ensure that the default has not been changed, ensure no line in
<html:code>/etc/exports</html:code> contains the option <html:code>insecure</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Allowing client requests to be made from ports higher than 1024 could allow a unprivileged
user to initiate an NFS connection. If the unprivileged user account has been compromised, an
attacker could gain access to data on the NFS server.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_use_kerberos_security_all_exports" selected="false" severity="medium">
              <xccdf-1.2:title>Use Kerberos Security on All Exports</xccdf-1.2:title>
              <xccdf-1.2:description>Using Kerberos on all exported mounts prevents a malicious client or user from
impersonating a system user. To cryptography authenticate users to the NFS server,
add <html:code>sec=krb5:krb5i:krb5p</html:code> to each export in <html:code>/etc/exports</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(8)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>When an NFS server is configured to use AUTH_SYS a selected userid and groupid are used to handle
requests from the remote user. The userid and groupid could mistakenly or maliciously be set
incorrectly. The AUTH_GSS method of authentication uses certificates on the server and client
systems to more securely authenticate the remote mount request.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="use_kerberos_security_all_exports" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

nfs_exports=()
readarray -t nfs_exports &lt; &lt;(grep -E "^/.*[[:space:]]+ .*\(.*\)[[:space:]]*$" /etc/exports | awk '{print $2}')

for nfs_export in "${nfs_exports[@]}"
do
    correct_export=""
    if [ "$(grep -c "sec=" &lt;&lt;&lt;"$nfs_export")" -eq 0 ]; then
        correct_export="$(echo $nfs_export|sed  -e 's/).*$/,sec=krb5\:krb5i\:krb5p)/')"
    else
        correct_export="$(echo $nfs_export|sed  -e 's/sec=[^\,\)]*/sec=krb5\:krb5i\:krb5p/')"
    fi
    sed -i "s|$nfs_export|$correct_export|g" /etc/exports
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="use_kerberos_security_all_exports" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-2
  - NIST-800-53-IA-2(8)
  - NIST-800-53-IA-2(9)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - use_kerberos_security_all_exports

- name: Drop any security clause for every export
  ansible.builtin.replace:
    path: /etc/exports
    regexp: ^(/.*\w+.*\(.*),sec=[^,]*(.*\)\w*$)
    replace: \1\2
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-2
  - NIST-800-53-IA-2(8)
  - NIST-800-53-IA-2(9)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - use_kerberos_security_all_exports

- name: Add kerberos security when no security is defined for an export
  ansible.builtin.replace:
    path: /etc/exports
    regexp: ^(/.*\w+.*\(.*)(\)\w*$)
    replace: \1,sec=krb5:krb5i:krb5p\2
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-2
  - NIST-800-53-IA-2(8)
  - NIST-800-53-IA-2(9)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - use_kerberos_security_all_exports
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-use_kerberos_security_all_exports:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-use_kerberos_security_all_exports_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_use_root_squashing_all_exports" selected="false" severity="unknown">
              <xccdf-1.2:title>Use Root-Squashing on All Exports</xccdf-1.2:title>
              <xccdf-1.2:description>If a filesystem is exported using root squashing, requests from root on the client
are considered to be unprivileged (mapped to a user such as nobody). This provides some mild
protection against remote abuse of an NFS server. Root squashing is enabled by default, and
should not be disabled.
<html:br/><html:br/>
Ensure that no line in <html:code>/etc/exports</html:code> contains the option <html:code>no_root_squash</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:rationale>If the NFS server allows root access to local file systems from remote hosts, this
access could be used to compromise the system.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_ntp">
          <xccdf-1.2:title>Network Time Protocol</xccdf-1.2:title>
          <xccdf-1.2:description>The Network Time Protocol is used to manage the system
clock over a network. Computer clocks are not very accurate, so
time will drift unpredictably on unmanaged systems. Central time
protocols can be used both to ensure that time is consistent among
a network of systems, and that their time is consistent with the
outside world.
<html:br/><html:br/>
If every system on a network reliably reports the same time, then it is much
easier to correlate log messages in case of an attack. In addition, a number of
cryptographic protocols (such as Kerberos) use timestamps to prevent certain
types of attacks. If your network does not have synchronized time, these
protocols may be unreliable or even unusable.
<html:br/><html:br/>
Depending on the specifics of the network, global time accuracy may be just as
important as local synchronization, or not very important at all. If your
network is connected to the Internet, using a public timeserver (or one
provided by your enterprise) provides globally accurate timestamps which may be
essential in investigating or responding to an attack which originated outside
of your network.
<html:br/><html:br/>
A typical network setup involves a small number of internal systems operating
as NTP servers, and the remainder obtaining time information from those
internal servers.
<html:br/><html:br/>
There is a choice between the daemons <html:code>ntpd</html:code> and <html:code>chronyd</html:code>, which
are available from the repositories in the <html:code>ntp</html:code> and <html:code>chrony</html:code>
packages respectively.
<html:br/><html:br/>
The default <html:code>chronyd</html:code> daemon can work well when external time references
are only intermittently accessible, can perform well even when the network is
congested for longer periods of time, can usually synchronize the clock faster
and with better time accuracy, and quickly adapts to sudden changes in the rate
of the clock, for example, due to changes in the temperature of the crystal
oscillator. <html:code>Chronyd</html:code> should be considered for all systems which are
frequently suspended or otherwise intermittently disconnected and reconnected
to a network. Mobile and virtual systems for example.
<html:br/><html:br/>
The <html:code>ntpd</html:code> NTP daemon fully supports NTP protocol version 4 (RFC 5905),
including broadcast, multicast, manycast clients and servers, and the orphan
mode. It also supports extra authentication schemes based on public-key
cryptography (RFC 5906). The NTP daemon (<html:code>ntpd</html:code>) should be considered
for systems which are normally kept permanently on. Systems which are required
to use broadcast or multicast IP, or to perform authentication of packets with
the <html:code>Autokey</html:code> protocol, should consider using <html:code>ntpd</html:code>.
<html:br/><html:br/>
Refer to

    
    <html:a href="https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/configuring_basic_system_settings/configuring-time-synchronization_configuring-basic-system-settings">https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/configuring_basic_system_settings/configuring-time-synchronization_configuring-basic-system-settings</html:a>

for more detailed comparison of features of <html:code>chronyd</html:code>
and <html:code>ntpd</html:code> daemon features respectively, and for further guidance how to
choose between the two NTP daemons.
<html:br/><html:br/>
The upstream manual pages at 
    <html:a href="https://chrony-project.org/documentation.html">https://chrony-project.org/documentation.html</html:a> for
<html:code>chronyd</html:code> and 
    <html:a href="http://www.ntp.org">http://www.ntp.org</html:a> for <html:code>ntpd</html:code> provide additional
information on the capabilities and configuration of each of the NTP daemons.</xccdf-1.2:description>
          <xccdf-1.2:platform idref="#system_with_kernel"/>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_multiple_time_servers" interactive="true" type="string">
            <xccdf-1.2:title>Vendor Approved Time Servers</xccdf-1.2:title>
            <xccdf-1.2:description>The list of vendor-approved time servers</xccdf-1.2:description>
            <xccdf-1.2:value>0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org</xccdf-1.2:value>
            <xccdf-1.2:value selector="generic">0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org</xccdf-1.2:value>
            <xccdf-1.2:value selector="stig">0.us.pool.ntp.mil</xccdf-1.2:value>
            <xccdf-1.2:value selector="fedora">0.fedora.pool.ntp.org,1.fedora.pool.ntp.org,2.fedora.pool.ntp.org,3.fedora.pool.ntp.org</xccdf-1.2:value>
            <xccdf-1.2:value selector="rhel">0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org</xccdf-1.2:value>
            <xccdf-1.2:value selector="ol">0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org</xccdf-1.2:value>
            <xccdf-1.2:value selector="suse">0.suse.pool.ntp.org,1.suse.pool.ntp.org,2.suse.pool.ntp.org,3.suse.pool.ntp.org</xccdf-1.2:value>
            <xccdf-1.2:value selector="alinux">0.ntp.cloud.aliyuncs.com,1.ntp.aliyun.com,2.ntp1.aliyun.com,3.ntp1.cloud.aliyuncs.com</xccdf-1.2:value>
            <xccdf-1.2:value selector="amazon">0.rhel.pool.ntp.org,1.rhel.pool.ntp.org,2.rhel.pool.ntp.org,3.rhel.pool.ntp.org</xccdf-1.2:value>
            <xccdf-1.2:value selector="ubuntu">0.ubuntu.pool.ntp.org,1.ubuntu.pool.ntp.org,2.ubuntu.pool.ntp.org,3.ubuntu.pool.ntp.org</xccdf-1.2:value>
            <xccdf-1.2:value selector="almalinux">0.almalinux.pool.ntp.org,1.almalinux.pool.ntp.org,2.almalinux.pool.ntp.org,3.almalinux.pool.ntp.org</xccdf-1.2:value>
            <xccdf-1.2:value selector="debian">0.debian.pool.ntp.org,1.debian.pool.ntp.org,2.debian.pool.ntp.org,3.debian.pool.ntp.org</xccdf-1.2:value>
            <xccdf-1.2:value selector="nist">time.nist.gov,time-a-g.nist.gov,time-b-g.nist.gov,time-c-g.nist.gov</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_time_service_set_maxpoll" type="number">
            <xccdf-1.2:title>Maximum NTP or Chrony Poll</xccdf-1.2:title>
            <xccdf-1.2:description>The maximum NTP or Chrony poll interval number in seconds specified as a power of two.</xccdf-1.2:description>
            <xccdf-1.2:value selector="36_hours">17</xccdf-1.2:value>
            <xccdf-1.2:value selector="18_hours">16</xccdf-1.2:value>
            <xccdf-1.2:value>10</xccdf-1.2:value>
            <xccdf-1.2:value selector="system_default">10</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_chrony_installed" selected="false" severity="medium">
            <xccdf-1.2:title>The Chrony package is installed</xccdf-1.2:title>
            <xccdf-1.2:description>System time should be synchronized between all systems in an environment. This is
typically done by establishing an authoritative time server or set of servers and having all
systems synchronize their clocks to them.
The <html:code>chrony</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install chrony</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000355-GPOS-00143</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R71</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0988</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1405</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.3.1</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Time synchronization is important to support time sensitive security mechanisms like
Kerberos and also ensures log files have consistent time records across the enterprise,
which aids in forensic investigations.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_chrony_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "chrony" ; then
    yum install -y "chrony"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_chrony_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSS-Req-10.4
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_chrony_installed

- name: Ensure chrony is installed
  ansible.builtin.package:
    name: chrony
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSS-Req-10.4
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_chrony_installed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_chrony_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_chrony

class install_chrony {
  package { 'chrony':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_chrony_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=chrony
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_chrony_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "chrony"
version = "*"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_chrony_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install chrony
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_chrony_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install chrony
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_chrony_installed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_chrony_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_ntp_installed" selected="false" severity="high">
            <xccdf-1.2:title>Install the ntp service</xccdf-1.2:title>
            <xccdf-1.2:description>The ntpd service should be installed.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.4</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Time synchronization (using NTP) is required by almost all network and administrative tasks (syslog, cryptographic based services (authentication, etc.), etc.). Ntpd is regularly maintained and updated, supporting security features such as RFC 5906.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ntp_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "ntp" ; then
    yum install -y "ntp"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ntp_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4
  - enable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_ntp_installed

- name: Ensure ntp is installed
  ansible.builtin.package:
    name: ntp
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4
  - enable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_ntp_installed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ntp_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_ntp

class install_ntp {
  package { 'ntp':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ntp_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=ntp
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_ntp_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "ntp"
version = "*"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ntp_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install ntp
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_ntp_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install ntp
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_ntp_installed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_ntp_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_chronyd_enabled" selected="false" severity="medium">
            <xccdf-1.2:title>The Chronyd service is enabled</xccdf-1.2:title>
            <xccdf-1.2:description>chrony is a daemon which implements the Network Time Protocol (NTP) is designed to
synchronize system clocks across a variety of systems and use a source that is highly
accurate. More information on chrony can be found at

    <html:a href="https://chrony-project.org/">https://chrony-project.org/</html:a>.
Chrony can be configured to be a client and/or a server.
To enable Chronyd service, you can run:
<html:code># systemctl enable chronyd.service</html:code>
This recommendation only applies if chrony is in use on the system.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000355-GPOS-00143</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R71</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0988</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1405</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If chrony is in use on the system proper configuration is vital to ensuring time
synchronization is working properly.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#package_chrony"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_chronyd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q chrony; }; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'chronyd.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'chronyd.service'
fi
"$SYSTEMCTL_EXEC" enable 'chronyd.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_chronyd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_chronyd_enabled

- name: The Chronyd service is enabled - Enable service chronyd
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: The Chronyd service is enabled - Enable Service chronyd
    ansible.builtin.systemd:
      name: chronyd
      enabled: true
      state: started
      masked: false
    when:
    - '"chrony" in ansible_facts.packages'
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_chronyd_enabled
  - special_service_block
  when:
  - '"kernel" in ansible_facts.packages'
  - '"chrony" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_chronyd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_chronyd

class enable_chronyd {
  service {'chronyd':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_chronyd_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["chronyd"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_chronyd_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable chronyd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_chronyd_enabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_chronyd_enabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_chronyd_or_ntpd_enabled" selected="false" severity="medium">
            <xccdf-1.2:title>Enable the NTP Daemon</xccdf-1.2:title>
            <xccdf-1.2:description>


Run the following command to determine the current status of the
<html:code>chronyd</html:code> service:
<html:pre>$ sudo systemctl is-active chronyd</html:pre>
If the service is running, it should return the following: <html:pre>active</html:pre>

Note: The <html:code>chronyd</html:code> daemon is enabled by default.
<html:br/><html:br/>


Run the following command to determine the current status of the
<html:code>ntpd</html:code> service:
<html:pre>$ sudo systemctl is-active ntpd</html:pre>
If the service is running, it should return the following: <html:pre>active</html:pre>
Note: The <html:code>ntpd</html:code> daemon is not enabled by default. Though as mentioned
in the previous sections in certain environments the <html:code>ntpd</html:code> daemon might
be preferred to be used rather than the <html:code>chronyd</html:code> one. Refer to:

for guidance which NTP daemon to choose depending on the environment used.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-8(1)(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000116-CTR-000235</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R71</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0988</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1405</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Enabling some of <html:code>chronyd</html:code> or <html:code>ntpd</html:code> services ensures
that the NTP daemon will be running and that the system will synchronize its
time to any servers specified. This is important whether the system is
configured to be a client (and synchronize only its own clock) or it is also
acting as an NTP server to other systems.  Synchronizing time is essential for
authentication services such as Kerberos, but it is also important for
maintaining accurate logs and auditing possible security breaches.
<html:br/><html:br/>
The <html:code>chronyd</html:code> and <html:code>ntpd</html:code> NTP daemons offer all of the
functionality of <html:code>ntpdate</html:code>, which is now deprecated.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_chronyd_or_ntpd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if rpm --quiet -q "chrony" ; then
    if ! /usr/sbin/pidof ntpd ; then
        /usr/bin/systemctl enable "chronyd"
        if [[ $(/usr/bin/systemctl is-system-running) != "offline" ]]; then
        /usr/bin/systemctl start "chronyd"
        fi
        # The service may not be running because it has been started and failed,
        # so let's reset the state so OVAL checks pass.
        # Service should be 'inactive', not 'failed' after reboot though.
        if /usr/bin/systemctl --failed | grep -q "chronyd"; then
            /usr/bin/systemctl reset-failed "chronyd"
        fi
    fi
elif rpm --quiet -q "ntp" ; then
    /usr/bin/systemctl enable "ntpd"
    if [[ $(/usr/bin/systemctl is-system-running) != "offline" ]]; then
    /usr/bin/systemctl start "ntpd"
    fi
    # The service may not be running because it has been started and failed,
    # so let's reset the state so OVAL checks pass.
    # Service should be 'inactive', not 'failed' after reboot though.
    if /usr/bin/systemctl --failed | grep -q "ntpd"; then
        /usr/bin/systemctl reset-failed "ntpd"
    fi
else
    if ! rpm -q --quiet "chrony" ; then
        yum install -y "chrony"
    fi
    /usr/bin/systemctl enable "chronyd"
    if [[ $(/usr/bin/systemctl is-system-running) != "offline" ]]; then
    /usr/bin/systemctl start "chronyd"
    fi
    # The service may not be running because it has been started and failed,
    # so let's reset the state so OVAL checks pass.
    # Service should be 'inactive', not 'failed' after reboot though.
    if /usr/bin/systemctl --failed | grep -q "chronyd"; then
        /usr/bin/systemctl reset-failed "chronyd"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_chronyd_or_ntpd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.3.7
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.1
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_chronyd_or_ntpd_enabled

- name: Gather the package facts
  ansible.builtin.package_facts:
    manager: auto
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.3.7
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.1
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_chronyd_or_ntpd_enabled

- name: Start ntpd service if ntp installed
  ansible.builtin.systemd:
    name: ntpd
    enabled: 'yes'
    state: started
    masked: 'no'
  when:
  - '"kernel" in ansible_facts.packages'
  - '''ntp'' in ansible_facts.packages'
  tags:
  - NIST-800-171-3.3.7
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.1
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_chronyd_or_ntpd_enabled

- name: Start chronyd service if chrony or chronyd installed
  ansible.builtin.systemd:
    name: chronyd
    enabled: 'yes'
    state: started
    masked: 'no'
  when:
  - '"kernel" in ansible_facts.packages'
  - ('chrony' in ansible_facts.packages) or ('chronyd' in ansible_facts.packages)
  tags:
  - NIST-800-171-3.3.7
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.1
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_chronyd_or_ntpd_enabled
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_chronyd_or_ntpd_enabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_chronyd_or_ntpd_enabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_ntp_enabled" selected="false" severity="high">
            <xccdf-1.2:title>Enable the NTP Daemon</xccdf-1.2:title>
            <xccdf-1.2:description>
The <html:code>ntp</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable ntp.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-8(1)(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Enabling the <html:code>ntp</html:code> service ensures that the <html:code>ntp</html:code>
service will be running and that the system will synchronize its time to
any servers specified. This is important whether the system is configured to be
a client (and synchronize only its own clock) or it is also acting as an NTP
server to other systems.  Synchronizing time is essential for authentication
services such as Kerberos, but it is also important for maintaining accurate
logs and auditing possible security breaches.
<html:br/><html:br/>
The NTP daemon offers all of the functionality of <html:code>ntpdate</html:code>, which is now
deprecated.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#package_ntp"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_ntp_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q ntp; }; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'ntp.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'ntp.service'
fi
"$SYSTEMCTL_EXEC" enable 'ntp.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_ntp_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.1
  - enable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_ntp_enabled

- name: Enable the NTP Daemon - Enable service ntp
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable the NTP Daemon - Enable Service ntp
    ansible.builtin.systemd:
      name: ntp
      enabled: true
      state: started
      masked: false
    when:
    - '"ntp" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.1
  - enable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_ntp_enabled
  - special_service_block
  when:
  - '"kernel" in ansible_facts.packages'
  - '"ntp" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_ntp_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_ntp

class enable_ntp {
  service {'ntp':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_ntp_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["ntp"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_ntp_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable ntp
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_ntp_enabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_ntp_enabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_ntpd_enabled" selected="false" severity="medium">
            <xccdf-1.2:title>Enable the NTP Daemon</xccdf-1.2:title>
            <xccdf-1.2:description>
The <html:code>ntpd</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable ntpd.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">The <html:pre>ntp</html:pre> package is not available in AlmaLinux OS 8. Please consider the <html:pre>chrony</html:pre> package instead together with the respective <html:pre>service_chronyd_enabled</html:pre> rule.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-8(1)(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Enabling the <html:code>ntpd</html:code> service ensures that the <html:code>ntpd</html:code>
service will be running and that the system will synchronize its time to
any servers specified. This is important whether the system is configured to be
a client (and synchronize only its own clock) or it is also acting as an NTP
server to other systems.  Synchronizing time is essential for authentication
services such as Kerberos, but it is also important for maintaining accurate
logs and auditing possible security breaches.
<html:br/><html:br/>
The NTP daemon offers all of the functionality of <html:code>ntpdate</html:code>, which is now
deprecated.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#package_ntp"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_ntpd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q ntp; }; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'ntpd.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'ntpd.service'
fi
"$SYSTEMCTL_EXEC" enable 'ntpd.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_ntpd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_ntpd_enabled

- name: Enable the NTP Daemon - Enable service ntpd
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable the NTP Daemon - Enable Service ntpd
    ansible.builtin.systemd:
      name: ntpd
      enabled: true
      state: started
      masked: false
    when:
    - '"ntp" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_ntpd_enabled
  - special_service_block
  when:
  - '"kernel" in ansible_facts.packages'
  - '"ntp" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_ntpd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_ntpd

class enable_ntpd {
  service {'ntpd':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_ntpd_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["ntpd"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_ntpd_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable ntpd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_ntpd_enabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_ntpd_enabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_chronyd_specify_remote_server" selected="false" severity="medium">
            <xccdf-1.2:title>A remote time server for Chrony is configured</xccdf-1.2:title>
            <xccdf-1.2:description><html:code>Chrony</html:code> is a daemon which implements the Network Time Protocol (NTP). It is designed
to synchronize system clocks across a variety of systems and use a source that is highly
accurate. More information on <html:code>chrony</html:code> can be found at

    <html:a href="https://chrony-project.org/">https://chrony-project.org/</html:a>.
<html:code>Chrony</html:code> can be configured to be a client and/or a server.
Add or edit server or pool lines to <html:code>/etc/chrony.conf</html:code> as appropriate:
<html:pre>server &lt;remote-server&gt;</html:pre>
Alternatively, server or pool directives can be specified in files included via
<html:code>sourcedir</html:code> or <html:code>confdir</html:code> directives in <html:code>/etc/chrony.conf</html:code>.
When using <html:code>sourcedir</html:code>, create <html:code>.sources</html:code> files in the specified directory:
<html:pre># In /etc/chrony.conf:
sourcedir /etc/chrony/sources.d

# In /etc/chrony/sources.d/ntp.sources:
server 0.pool.ntp.org</html:pre>
When using <html:code>confdir</html:code>, create <html:code>.conf</html:code> files in the specified directory:
<html:pre># In /etc/chrony.conf:
confdir /etc/chrony/conf.d

# In /etc/chrony/conf.d/ntp-servers.conf:
pool 1.pool.ntp.org</html:pre>
Multiple servers may be configured.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-8(1)(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000355-GPOS-00143</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R71</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0988</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1405</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030740</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230484r1038944_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If <html:code>chrony</html:code> is in use on the system proper configuration is vital to ensuring time
synchronization is working properly.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#package_chrony"/>
            <xccdf-1.2:fix id="chronyd_specify_remote_server" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q chrony; }; then

var_multiple_time_servers='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_multiple_time_servers" use="legacy"/>'


config_file="/etc/chrony.conf"

if ! grep -q '^[[:space:]]*\(server\|pool\)[[:space:]]\+[[:graph:]]\+' "$config_file" ; then
  if ! grep -q '#[[:space:]]*server' "$config_file" ; then
    for server in $(echo "$var_multiple_time_servers" | tr ',' '\n') ; do
      printf '\nserver %s' "$server" &gt;&gt; "$config_file"
    done
  else
    sed -i 's/#[ \t]*server/server/g' "$config_file"
  fi
  if [[ -s "$config_file" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "$config_file" || true)" ]]; then
      LC_ALL=C sed -i --follow-symlinks '$a'\\ "$config_file"
  fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="chronyd_specify_remote_server" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.3
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.2
  - chronyd_specify_remote_server
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
- name: XCCDF Value var_multiple_time_servers # promote to variable
  set_fact:
    var_multiple_time_servers: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_multiple_time_servers" use="legacy"/>
  tags:
    - always

- name: Check if chrony main config has active server/pool entries
  ansible.builtin.command:
    cmd: grep -q '^[[:space:]]*\(server\|pool\)[[:space:]]\+[[:graph:]]\+' /etc/chrony.conf
  register: chrony_conf_has_servers
  changed_when: false
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"chrony" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.3
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.2
  - chronyd_specify_remote_server
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Extract sourcedir paths from chrony configuration
  ansible.builtin.shell:
    cmd: grep '^[[:space:]]*sourcedir[[:space:]]\+' /etc/chrony.conf | awk '{print
      $2}'
  register: chrony_sourcedir_paths
  changed_when: false
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"chrony" in ansible_facts.packages'
  - chrony_conf_has_servers.rc != 0
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.3
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.2
  - chronyd_specify_remote_server
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Check for server/pool entries in sourcedir .sources files
  ansible.builtin.shell:
    cmd: |
      for dir in {{ chrony_sourcedir_paths.stdout_lines | join(' ') }}; do
        if [ -d "$dir" ]; then
          grep -q '^[[:space:]]*\(server\|pool\)[[:space:]]\+[[:graph:]]\+' "$dir"/*.sources 2&gt;/dev/null &amp;&amp; exit 0
        fi
      done
      exit 1
  register: chrony_sourcedir_has_servers
  changed_when: false
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"chrony" in ansible_facts.packages'
  - chrony_conf_has_servers.rc != 0
  - chrony_sourcedir_paths.stdout_lines | length &gt; 0
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.3
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.2
  - chronyd_specify_remote_server
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Extract confdir paths from chrony configuration
  ansible.builtin.shell:
    cmd: grep '^[[:space:]]*confdir[[:space:]]\+' /etc/chrony.conf | awk '{print $2}'
  register: chrony_confdir_paths
  changed_when: false
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"chrony" in ansible_facts.packages'
  - chrony_conf_has_servers.rc != 0
  - (chrony_sourcedir_paths.stdout_lines | default([]) | length == 0 or chrony_sourcedir_has_servers.rc
    != 0)
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.3
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.2
  - chronyd_specify_remote_server
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Check for server/pool entries in confdir .conf files
  ansible.builtin.shell:
    cmd: |
      for dir in {{ chrony_confdir_paths.stdout_lines | join(' ') }}; do
        if [ -d "$dir" ]; then
          grep -q '^[[:space:]]*\(server\|pool\)[[:space:]]\+[[:graph:]]\+' "$dir"/*.conf 2&gt;/dev/null &amp;&amp; exit 0
        fi
      done
      exit 1
  register: chrony_confdir_has_servers
  changed_when: false
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"chrony" in ansible_facts.packages'
  - chrony_conf_has_servers.rc != 0
  - chrony_confdir_paths.stdout_lines | default([]) | length &gt; 0
  - (chrony_sourcedir_paths.stdout_lines | default([]) | length == 0 or chrony_sourcedir_has_servers.rc
    != 0)
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.3
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.2
  - chronyd_specify_remote_server
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Create sourcedir directory if needed
  ansible.builtin.file:
    path: '{{ chrony_sourcedir_paths.stdout_lines[0] }}'
    state: directory
    mode: '0755'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"chrony" in ansible_facts.packages'
  - chrony_conf_has_servers.rc != 0
  - chrony_sourcedir_paths.stdout_lines | default([]) | length &gt; 0
  - chrony_sourcedir_has_servers.rc != 0
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.3
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.2
  - chronyd_specify_remote_server
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Add remote time servers to sourcedir .sources file
  ansible.builtin.lineinfile:
    path: '{{ chrony_sourcedir_paths.stdout_lines[0] }}/ntp-servers.sources'
    line: server {{ item }}
    state: present
    create: true
    mode: '0644'
  loop: '{{ var_multiple_time_servers.split(",") }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"chrony" in ansible_facts.packages'
  - chrony_conf_has_servers.rc != 0
  - chrony_sourcedir_paths.stdout_lines | default([]) | length &gt; 0
  - chrony_sourcedir_has_servers.rc != 0
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.3
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.2
  - chronyd_specify_remote_server
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Create confdir directory if needed
  ansible.builtin.file:
    path: '{{ chrony_confdir_paths.stdout_lines[0] }}'
    state: directory
    mode: '0755'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"chrony" in ansible_facts.packages'
  - chrony_conf_has_servers.rc != 0
  - (chrony_sourcedir_paths.stdout_lines | default([]) | length == 0 or chrony_sourcedir_has_servers.rc
    != 0)
  - chrony_confdir_paths.stdout_lines | default([]) | length &gt; 0
  - chrony_confdir_has_servers.rc != 0
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.3
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.2
  - chronyd_specify_remote_server
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Add remote time servers to confdir .conf file
  ansible.builtin.lineinfile:
    path: '{{ chrony_confdir_paths.stdout_lines[0] }}/ntp-servers.conf'
    line: server {{ item }}
    state: present
    create: true
    mode: '0644'
  loop: '{{ var_multiple_time_servers.split(",") }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"chrony" in ansible_facts.packages'
  - chrony_conf_has_servers.rc != 0
  - (chrony_sourcedir_paths.stdout_lines | default([]) | length == 0 or chrony_sourcedir_has_servers.rc
    != 0)
  - chrony_confdir_paths.stdout_lines | default([]) | length &gt; 0
  - chrony_confdir_has_servers.rc != 0
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.3
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.2
  - chronyd_specify_remote_server
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Add remote time servers to main chrony configuration
  ansible.builtin.lineinfile:
    path: /etc/chrony.conf
    line: server {{ item }}
    state: present
    create: true
  loop: '{{ var_multiple_time_servers.split(",") }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"chrony" in ansible_facts.packages'
  - chrony_conf_has_servers.rc != 0
  - (chrony_sourcedir_paths.stdout_lines | default([]) | length == 0 or chrony_sourcedir_has_servers.rc
    != 0)
  - (chrony_confdir_paths.stdout_lines | default([]) | length == 0 or chrony_confdir_has_servers.rc
    != 0)
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.3
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.2
  - chronyd_specify_remote_server
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-chronyd_specify_remote_server:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_chronyd_client_only" selected="false" severity="low">
            <xccdf-1.2:title>Disable chrony daemon from acting as server</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>port</html:code> option in <html:code>/etc/chrony.conf</html:code> can be set to
<html:code>0</html:code> to make chrony daemon to never open any listening port
for server operation and to operate strictly in a client-only mode.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-8(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000096-GPOS-00050</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030741</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230485r1017269_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>In order to prevent unauthorized connection of devices, unauthorized transfer of information, or unauthorized tunneling (i.e., embedding of data types within data types), organizations must disable or restrict unused or unnecessary physical and logical ports/protocols on information systems.
Operating systems are capable of providing a wide variety of functions and services. Some of the functions and services provided by default may not be necessary to support essential organizational operations. Additionally, it is sometimes convenient to provide multiple services from a single component (e.g., VPN and IPS); however, doing so increases risk over limiting the services provided by any one component.
To support the requirements and principles of least functionality, the operating system must support the organizational requirements, providing only essential capabilities and limiting the use of ports, protocols, and/or services to only those required, authorized, and approved to conduct official business or to address authorized quality of life issues.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#package_chrony"/>
            <xccdf-1.2:fix id="chronyd_client_only" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q chrony; }; then

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^port")

# shellcheck disable=SC2059
printf -v formatted_output "%s %s" "$stripped_key" "0"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^port\\&gt;" "/etc/chrony.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^port\\&gt;.*/$escaped_formatted_output/gi" "/etc/chrony.conf"
else
    if [[ -s "/etc/chrony.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/chrony.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/chrony.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/chrony.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="chronyd_client_only" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030741
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)
  - chronyd_client_only
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable chrony daemon from acting as server
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/chrony.conf
      create: true
      regexp: (?i)^\s*port\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/chrony.conf
    ansible.builtin.lineinfile:
      path: /etc/chrony.conf
      create: true
      regexp: (?i)^\s*port\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/chrony.conf
    ansible.builtin.lineinfile:
      path: /etc/chrony.conf
      create: true
      regexp: (?i)^\s*port\s+
      line: port 0
      state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"chrony" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030741
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)
  - chronyd_client_only
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="chronyd_client_only" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%20Allow%20for%20extra%20configuration%20files.%20This%20is%20useful%0A%23%20for%20admins%20specifying%20their%20own%20NTP%20servers%0Aconfdir%20/etc/chrony.d%0A%0A%23%20Set%20chronyd%20as%20client-only.%0Aport%200%0A%0A%23%20Disable%20chronyc%20from%20the%20network%0Acmdport%200%0A%0A%23%20Record%20the%20rate%20at%20which%20the%20system%20clock%20gains/losses%20time.%0Adriftfile%20/var/lib/chrony/drift%0A%0A%23%20Allow%20the%20system%20clock%20to%20be%20stepped%20in%20the%20first%20three%20updates%0A%23%20if%20its%20offset%20is%20larger%20than%201%20second.%0Amakestep%201.0%203%0A%0A%23%20Enable%20kernel%20synchronization%20of%20the%20real-time%20clock%20%28RTC%29.%0Artcsync%0A%0A%23%20Enable%20hardware%20timestamping%20on%20all%20interfaces%20that%20support%20it.%0A%23hwtimestamp%20%2A%0A%0A%23%20Increase%20the%20minimum%20number%20of%20selectable%20sources%20required%20to%20adjust%0A%23%20the%20system%20clock.%0A%23minsources%202%0A%0A%23%20Allow%20NTP%20client%20access%20from%20local%20network.%0A%23allow%20192.168.0.0/16%0A%0A%23%20Serve%20time%20even%20if%20not%20synchronized%20to%20a%20time%20source.%0A%23local%20stratum%2010%0A%0A%23%20Require%20authentication%20%28nts%20or%20key%20option%29%20for%20all%20NTP%20sources.%0A%23authselectmode%20require%0A%0A%23%20Specify%20file%20containing%20keys%20for%20NTP%20authentication.%0Akeyfile%20/etc/chrony.keys%0A%0A%23%20Insert/delete%20leap%20seconds%20by%20slewing%20instead%20of%20stepping.%0A%23leapsecmode%20slew%0A%0A%23%20Get%20TAI-UTC%20offset%20and%20leap%20seconds%20from%20the%20system%20tz%20database.%0Aleapsectz%20right/UTC%0A%0A%23%20Specify%20directory%20for%20log%20files.%0Alogdir%20/var/log/chrony%0A%0A%23%20Select%20which%20information%20is%20logged.%0A%23log%20measurements%20statistics%20tracking }}
        mode: 420
        overwrite: true
        path: /etc/chrony.conf
      - contents:
          source: data:,
        mode: 420
        overwrite: true
        path: /etc/chrony.d/.mco-keep
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20ntp%20server%0A%23%20%7B%7B.var_multiple_time_servers%7D%7D%20we%20have%20to%20put%20variable%20array%20name%20here%20for%20mutilines%20remediation%0A%7B%7B%24var_time_service_set_maxpoll%3A%3D.var_time_service_set_maxpoll%7D%7D%0A%7B%7Brange%20%24element%3A%3D.var_multiple_time_servers%7CtoArrayByComma%7D%7Dserver%20%7B%7B%24element%7D%7D%20minpoll%204%20maxpoll%20%7B%7B%24var_time_service_set_maxpoll%7D%7D%0A%7B%7Bend%7D%7D }}
        mode: 420
        overwrite: true
        path: /etc/chrony.d/ntp-server.conf
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-chronyd_client_only:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-chronyd_client_only_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_chronyd_configure_local_socket" selected="false" severity="low">
            <xccdf-1.2:title>Configure chrony-wait.service to use Unix socket</xccdf-1.2:title>
            <xccdf-1.2:description>The default <html:code>chrony-wait.service</html:code> attempts to connect via network (127.0.0.1, ::1)
which fails when <html:code>cmdport</html:code> is set to <html:code>0</html:code>. The service unit must be replaced
to use chronyc without network address specification, allowing it to use the Unix socket
for local communication with chronyd.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000096-GPOS-00050</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030742</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230486r1017270_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>When network access to the chrony daemon command port is disabled for security hardening,
the chrony-wait.service must be configured to use the Unix domain socket instead of
network addresses. This ensures the service can still check chrony synchronization status
without requiring network command access.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#package_chrony"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="chronyd_configure_local_socket" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
metadata:
  annotations:
    complianceascode.io/ocp-version: '&lt;4.13.0'
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,%5BUnit%5D%0ADescription%3DWait%20for%20chrony%20to%20synchronize%20system%20clock%20%28KCS%207064388%29%0ADocumentation%3Dman%3Achronyc%281%29%0AAfter%3Dchronyd.service%0ARequires%3Dchronyd.service%0ABefore%3Dtime-sync.target%0AWants%3Dtime-sync.target%0A%0A%5BService%5D%0AType%3Doneshot%0AExecStart%3D%2Fusr%2Fbin%2Fchronyc%20waitsync%200%200.1%200.0%201%0ATimeoutStartSec%3D180%0ARemainAfterExit%3Dyes%0AStandardOutput%3Dnull%0A%0A%5BInstall%5D%0AWantedBy%3Dmulti-user.target%0A
        mode: 420
        overwrite: true
        path: /etc/systemd/system/chrony-wait.service
---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
metadata:
  annotations:
    complianceascode.io/ocp-version: '&gt;=4.13.0'
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,%5BUnit%5D%0ADescription%3DWait%20for%20chrony%20to%20synchronize%20system%20clock%20%28KCS%207064388%29%0ADocumentation%3Dman%3Achronyc%281%29%0AAfter%3Dchronyd.service%0ARequires%3Dchronyd.service%0ABefore%3Dtime-sync.target%0AWants%3Dtime-sync.target%0A%0A%5BService%5D%0AType%3Doneshot%0AExecStart%3D%2Fusr%2Fbin%2Fchronyc%20waitsync%200%200.1%200.0%201%0ATimeoutStartSec%3D180%0ARemainAfterExit%3Dyes%0AStandardOutput%3Dnull%0A%0ACapabilityBoundingSet%3D~CAP_AUDIT_CONTROL%20CAP_AUDIT_READ%20CAP_AUDIT_WRITE%0ACapabilityBoundingSet%3D~CAP_BLOCK_SUSPEND%20CAP_KILL%20CAP_LEASE%20CAP_LINUX_IMMUTABLE%0ACapabilityBoundingSet%3D~CAP_MAC_ADMIN%20CAP_MAC_OVERRIDE%20CAP_MKNOD%20CAP_SYS_ADMIN%0ACapabilityBoundingSet%3D~CAP_SYS_BOOT%20CAP_SYS_CHROOT%20CAP_SYS_MODULE%20CAP_SYS_PACCT%0ACapabilityBoundingSet%3D~CAP_SYS_PTRACE%20CAP_SYS_RAWIO%20CAP_SYS_TTY_CONFIG%20CAP_WAKE_ALARM%0ADevicePolicy%3Dclosed%0AIPAddressAllow%3Dlocalhost%0AIPAddressDeny%3Dany%0ALockPersonality%3Dyes%0AMemoryDenyWriteExecute%3Dyes%0APrivateDevices%3Dyes%0AProcSubset%3Dpid%0AProtectClock%3Dyes%0AProtectControlGroups%3Dyes%0AProtectHome%3Dyes%0AProtectHostname%3Dyes%0AProtectKernelLogs%3Dyes%0AProtectKernelModules%3Dyes%0AProtectKernelTunables%3Dyes%0AProtectProc%3Dinvisible%0AProtectSystem%3Dstrict%0ARestrictAddressFamilies%3DAF_UNIX%0ARestrictNamespaces%3Dyes%0ARestrictRealtime%3Dyes%0ASystemCallArchitectures%3Dnative%0ASystemCallFilter%3D%40system-service%0ASystemCallFilter%3D~%40privileged%20%40resources%0AUMask%3D0777%0A%0A%5BInstall%5D%0AWantedBy%3Dmulti-user.target%0A
        mode: 420
        overwrite: true
        path: /etc/systemd/system/chrony-wait.service
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-chronyd_configure_local_socket:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-chronyd_configure_local_socket_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_chronyd_no_chronyc_network" selected="false" severity="low">
            <xccdf-1.2:title>Disable network management of chrony daemon</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>cmdport</html:code> option in <html:code>/etc/chrony.conf</html:code> can be set to
<html:code>0</html:code> to stop chrony daemon from listening on the UDP port 323
for management connections made by chronyc.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000096-GPOS-00050</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030742</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230486r1017270_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Minimizing the exposure of the server functionality of the chrony
daemon diminishes the attack surface.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#package_chrony"/>
            <xccdf-1.2:fix id="chronyd_no_chronyc_network" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q chrony; }; then

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^cmdport")

# shellcheck disable=SC2059
printf -v formatted_output "%s %s" "$stripped_key" "0"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^cmdport\\&gt;" "/etc/chrony.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^cmdport\\&gt;.*/$escaped_formatted_output/gi" "/etc/chrony.conf"
else
    if [[ -s "/etc/chrony.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/chrony.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/chrony.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/chrony.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="chronyd_no_chronyc_network" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030742
  - NIST-800-53-CM-7(1)
  - chronyd_no_chronyc_network
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable network management of chrony daemon
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/chrony.conf
      create: true
      regexp: (?i)^\s*cmdport\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/chrony.conf
    ansible.builtin.lineinfile:
      path: /etc/chrony.conf
      create: true
      regexp: (?i)^\s*cmdport\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/chrony.conf
    ansible.builtin.lineinfile:
      path: /etc/chrony.conf
      create: true
      regexp: (?i)^\s*cmdport\s+
      line: cmdport 0
      state: present
  when:
  - '"kernel" in ansible_facts.packages'
  - '"chrony" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030742
  - NIST-800-53-CM-7(1)
  - chronyd_no_chronyc_network
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="chronyd_no_chronyc_network" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%20Allow%20for%20extra%20configuration%20files.%20This%20is%20useful%0A%23%20for%20admins%20specifying%20their%20own%20NTP%20servers%0Aconfdir%20/etc/chrony.d%0A%0A%23%20Set%20chronyd%20as%20client-only.%0Aport%200%0A%0A%23%20Disable%20chronyc%20from%20the%20network%0Acmdport%200%0A%0A%23%20Record%20the%20rate%20at%20which%20the%20system%20clock%20gains/losses%20time.%0Adriftfile%20/var/lib/chrony/drift%0A%0A%23%20Allow%20the%20system%20clock%20to%20be%20stepped%20in%20the%20first%20three%20updates%0A%23%20if%20its%20offset%20is%20larger%20than%201%20second.%0Amakestep%201.0%203%0A%0A%23%20Enable%20kernel%20synchronization%20of%20the%20real-time%20clock%20%28RTC%29.%0Artcsync%0A%0A%23%20Enable%20hardware%20timestamping%20on%20all%20interfaces%20that%20support%20it.%0A%23hwtimestamp%20%2A%0A%0A%23%20Increase%20the%20minimum%20number%20of%20selectable%20sources%20required%20to%20adjust%0A%23%20the%20system%20clock.%0A%23minsources%202%0A%0A%23%20Allow%20NTP%20client%20access%20from%20local%20network.%0A%23allow%20192.168.0.0/16%0A%0A%23%20Serve%20time%20even%20if%20not%20synchronized%20to%20a%20time%20source.%0A%23local%20stratum%2010%0A%0A%23%20Require%20authentication%20%28nts%20or%20key%20option%29%20for%20all%20NTP%20sources.%0A%23authselectmode%20require%0A%0A%23%20Specify%20file%20containing%20keys%20for%20NTP%20authentication.%0Akeyfile%20/etc/chrony.keys%0A%0A%23%20Insert/delete%20leap%20seconds%20by%20slewing%20instead%20of%20stepping.%0A%23leapsecmode%20slew%0A%0A%23%20Get%20TAI-UTC%20offset%20and%20leap%20seconds%20from%20the%20system%20tz%20database.%0Aleapsectz%20right/UTC%0A%0A%23%20Specify%20directory%20for%20log%20files.%0Alogdir%20/var/log/chrony%0A%0A%23%20Select%20which%20information%20is%20logged.%0A%23log%20measurements%20statistics%20tracking }}
        mode: 420
        overwrite: true
        path: /etc/chrony.conf
      - contents:
          source: data:,
        mode: 420
        overwrite: true
        path: /etc/chrony.d/.mco-keep
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20ntp%20server%0A%23%20%7B%7B.var_multiple_time_servers%7D%7D%20we%20have%20to%20put%20variable%20array%20name%20here%20for%20mutilines%20remediation%0A%7B%7B%24var_time_service_set_maxpoll%3A%3D.var_time_service_set_maxpoll%7D%7D%0A%7B%7Brange%20%24element%3A%3D.var_multiple_time_servers%7CtoArrayByComma%7D%7Dserver%20%7B%7B%24element%7D%7D%20minpoll%204%20maxpoll%20%7B%7B%24var_time_service_set_maxpoll%7D%7D%0A%7B%7Bend%7D%7D }}
        mode: 420
        overwrite: true
        path: /etc/chrony.d/ntp-server.conf
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-chronyd_no_chronyc_network:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-chronyd_no_chronyc_network_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_chronyd_or_ntpd_set_maxpoll" selected="false" severity="medium">
            <xccdf-1.2:title>Configure Time Service Maxpoll Interval</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>maxpoll</html:code> should be configured to
<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_time_service_set_maxpoll" use="legacy"/> in <html:code>/etc/ntp.conf</html:code> or
<html:code>/etc/chrony.conf</html:code> (or <html:code>/etc/chrony.d/</html:code>) to continuously poll time servers. To configure
<html:code>maxpoll</html:code> in <html:code>/etc/ntp.conf</html:code> or <html:code>/etc/chrony.conf</html:code> (or <html:code>/etc/chrony.d/</html:code>)
add the following after each <html:code>server</html:code>, <html:code>pool</html:code> or <html:code>peer</html:code> entry:
<html:pre>maxpoll <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_time_service_set_maxpoll" use="legacy"/></html:pre>
to <html:code>server</html:code> directives. If using chrony, any <html:code>pool</html:code> directives
should be configured too.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-8(1)(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000355-GPOS-00143</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000356-GPOS-00144</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000359-GPOS-00146</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030740</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230484r1038944_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Inaccurate time stamps make it more difficult to correlate events and can lead to an inaccurate analysis. Determining the correct time a particular event occurred on a system is critical when conducting forensic analysis and investigating system events. Sources outside the configured acceptable allowance (drift) may be inaccurate.
Synchronizing internal information system clocks provides uniformity of time stamps for information systems with multiple system clocks and systems connected over a network.
Organizations should consider endpoints that may not have regular access to the authoritative time server (e.g., mobile, teleworking, and tactical endpoints).</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#package_chrony_or_package_ntp"/>
            <xccdf-1.2:fix id="chronyd_or_ntpd_set_maxpoll" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { ( ( rpm --quiet -q chrony || rpm --quiet -q ntp ) ); }; then

var_time_service_set_maxpoll='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_time_service_set_maxpoll" use="legacy"/>'




pof="/usr/sbin/pidof"


CONFIG_FILES="/etc/ntp.conf"
$pof ntpd || {
    CHRONY_D_PATH=/etc/chrony.d/
    if [ -d "${CHRONY_D_PATH}" ]; then
        mapfile -t CONFIG_FILES &lt; &lt;(find ${CHRONY_D_PATH} -type f -name '*.conf')
    else
        CONFIG_FILES=()
    fi
    CONFIG_FILES+=(/etc/chrony.conf)
}

# get list of ntp files

for config_file in "${CONFIG_FILES[@]}" ; do
    # Set maxpoll values to var_time_service_set_maxpoll
    sed -i "s/^\(\(server\|pool\|peer\).*maxpoll\) [0-9,-][0-9]*\(.*\)$/\1 $var_time_service_set_maxpoll \3/" "$config_file"
done

for config_file in "${CONFIG_FILES[@]}" ; do
    # Add maxpoll to server, pool or peer entries without maxpoll
    grep "^\(server\|pool\|peer\)" "$config_file" | grep -v maxpoll | while read -r line ; do
        sed -i "s/$line/&amp; maxpoll $var_time_service_set_maxpoll/" "$config_file"
    done
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="chronyd_or_ntpd_set_maxpoll" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(b)
  - NIST-800-53-CM-6(a)
  - chronyd_or_ntpd_set_maxpoll
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_time_service_set_maxpoll # promote to variable
  set_fact:
    var_time_service_set_maxpoll: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_time_service_set_maxpoll" use="legacy"/>
  tags:
    - always

- name: Configure Time Service Maxpoll Interval - Check That /etc/ntp.conf Exist
  ansible.builtin.stat:
    path: /etc/ntp.conf
  register: ntp_conf_exist_result
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "chrony" in ansible_facts.packages or "ntp" in ansible_facts.packages )
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(b)
  - NIST-800-53-CM-6(a)
  - chronyd_or_ntpd_set_maxpoll
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Time Service Maxpoll Interval - Update the maxpoll Values in /etc/ntp.conf
  ansible.builtin.replace:
    path: /etc/ntp.conf
    regexp: ^(server.*maxpoll)[ ]+[0-9]+(.*)$
    replace: \1 {{ var_time_service_set_maxpoll }}\2
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "chrony" in ansible_facts.packages or "ntp" in ansible_facts.packages )
  - ntp_conf_exist_result.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(b)
  - NIST-800-53-CM-6(a)
  - chronyd_or_ntpd_set_maxpoll
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Time Service Maxpoll Interval - Set the maxpoll Values in /etc/ntp.conf
  ansible.builtin.replace:
    path: /etc/ntp.conf
    regexp: (^server\s+((?!maxpoll).)*)$
    replace: \1 maxpoll {{ var_time_service_set_maxpoll }}\n
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "chrony" in ansible_facts.packages or "ntp" in ansible_facts.packages )
  - ntp_conf_exist_result.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(b)
  - NIST-800-53-CM-6(a)
  - chronyd_or_ntpd_set_maxpoll
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Time Service Maxpoll Interval - Check That /etc/chrony.conf Exist
  ansible.builtin.stat:
    path: /etc/chrony.conf
  register: chrony_conf_exist_result
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "chrony" in ansible_facts.packages or "ntp" in ansible_facts.packages )
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(b)
  - NIST-800-53-CM-6(a)
  - chronyd_or_ntpd_set_maxpoll
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Time Service Maxpoll Interval - Update the maxpoll Values in /etc/chrony.conf
  ansible.builtin.replace:
    path: /etc/chrony.conf
    regexp: ^((?:server|pool|peer).*maxpoll)[ ]+[0-9]+(.*)$
    replace: \1 {{ var_time_service_set_maxpoll }}\2
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "chrony" in ansible_facts.packages or "ntp" in ansible_facts.packages )
  - chrony_conf_exist_result.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(b)
  - NIST-800-53-CM-6(a)
  - chronyd_or_ntpd_set_maxpoll
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Time Service Maxpoll Interval - Set the maxpoll Values in /etc/chrony.conf
  ansible.builtin.replace:
    path: /etc/chrony.conf
    regexp: (^(?:server|pool|peer)\s+((?!maxpoll).)*)$
    replace: \1 maxpoll {{ var_time_service_set_maxpoll }}\n
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "chrony" in ansible_facts.packages or "ntp" in ansible_facts.packages )
  - chrony_conf_exist_result.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(b)
  - NIST-800-53-CM-6(a)
  - chronyd_or_ntpd_set_maxpoll
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Time Service Maxpoll Interval - Check That /etc/chrony.d/ Exist
  ansible.builtin.stat:
    path: /etc/chrony.d/
  register: chrony_d_path_exists
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "chrony" in ansible_facts.packages or "ntp" in ansible_facts.packages )
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(b)
  - NIST-800-53-CM-6(a)
  - chronyd_or_ntpd_set_maxpoll
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Time Service Maxpoll Interval - Get Conf Files from /etc/chrony.d/
  ansible.builtin.find:
    path: /etc/chrony.d/
    patterns: '*.conf'
    file_type: file
  register: chrony_d_conf_files
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "chrony" in ansible_facts.packages or "ntp" in ansible_facts.packages )
  - chrony_d_path_exists.stat.exists and chrony_d_path_exists.stat.isdir
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(b)
  - NIST-800-53-CM-6(a)
  - chronyd_or_ntpd_set_maxpoll
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Time Service Maxpoll Interval - Update the maxpoll Values in /etc/chrony.d/
  ansible.builtin.replace:
    path: '{{ item.path }}'
    regexp: ^((?:server|pool|peer).*maxpoll)[ ]+[0-9,-]+(.*)$
    replace: \1 {{ var_time_service_set_maxpoll }}\2
  loop: '{{ chrony_d_conf_files.files | default([]) }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "chrony" in ansible_facts.packages or "ntp" in ansible_facts.packages )
  - chrony_d_conf_files is defined and chrony_d_conf_files.matched
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(b)
  - NIST-800-53-CM-6(a)
  - chronyd_or_ntpd_set_maxpoll
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure Time Service Maxpoll Interval - Set the maxpoll Values in /etc/chrony.d/
  ansible.builtin.replace:
    path: '{{ item.path }}'
    regexp: (^(?:server|pool|peer)\s+((?!maxpoll).)*)$
    replace: \1 maxpoll {{ var_time_service_set_maxpoll }}\n
  loop: '{{ chrony_d_conf_files.files | default([]) }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "chrony" in ansible_facts.packages or "ntp" in ansible_facts.packages )
  - chrony_d_conf_files is defined and chrony_d_conf_files.matched
  tags:
  - DISA-STIG-RHEL-08-030740
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(b)
  - NIST-800-53-CM-6(a)
  - chronyd_or_ntpd_set_maxpoll
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="chronyd_or_ntpd_set_maxpoll" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%20Allow%20for%20extra%20configuration%20files.%20This%20is%20useful%0A%23%20for%20admins%20specifying%20their%20own%20NTP%20servers%0Aconfdir%20/etc/chrony.d%0A%0A%23%20Set%20chronyd%20as%20client-only.%0Aport%200%0A%0A%23%20Disable%20chronyc%20from%20the%20network%0Acmdport%200%0A%0A%23%20Record%20the%20rate%20at%20which%20the%20system%20clock%20gains/losses%20time.%0Adriftfile%20/var/lib/chrony/drift%0A%0A%23%20Allow%20the%20system%20clock%20to%20be%20stepped%20in%20the%20first%20three%20updates%0A%23%20if%20its%20offset%20is%20larger%20than%201%20second.%0Amakestep%201.0%203%0A%0A%23%20Enable%20kernel%20synchronization%20of%20the%20real-time%20clock%20%28RTC%29.%0Artcsync%0A%0A%23%20Enable%20hardware%20timestamping%20on%20all%20interfaces%20that%20support%20it.%0A%23hwtimestamp%20%2A%0A%0A%23%20Increase%20the%20minimum%20number%20of%20selectable%20sources%20required%20to%20adjust%0A%23%20the%20system%20clock.%0A%23minsources%202%0A%0A%23%20Allow%20NTP%20client%20access%20from%20local%20network.%0A%23allow%20192.168.0.0/16%0A%0A%23%20Serve%20time%20even%20if%20not%20synchronized%20to%20a%20time%20source.%0A%23local%20stratum%2010%0A%0A%23%20Require%20authentication%20%28nts%20or%20key%20option%29%20for%20all%20NTP%20sources.%0A%23authselectmode%20require%0A%0A%23%20Specify%20file%20containing%20keys%20for%20NTP%20authentication.%0Akeyfile%20/etc/chrony.keys%0A%0A%23%20Insert/delete%20leap%20seconds%20by%20slewing%20instead%20of%20stepping.%0A%23leapsecmode%20slew%0A%0A%23%20Get%20TAI-UTC%20offset%20and%20leap%20seconds%20from%20the%20system%20tz%20database.%0Aleapsectz%20right/UTC%0A%0A%23%20Specify%20directory%20for%20log%20files.%0Alogdir%20/var/log/chrony%0A%0A%23%20Select%20which%20information%20is%20logged.%0A%23log%20measurements%20statistics%20tracking }}
        mode: 420
        overwrite: true
        path: /etc/chrony.conf
      - contents:
          source: data:,
        mode: 420
        overwrite: true
        path: /etc/chrony.d/.mco-keep
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20ntp%20server%0A%23%20%7B%7B.var_multiple_time_servers%7D%7D%20we%20have%20to%20put%20variable%20array%20name%20here%20for%20mutilines%20remediation%0A%7B%7B%24var_time_service_set_maxpoll%3A%3D.var_time_service_set_maxpoll%7D%7D%0A%7B%7Brange%20%24element%3A%3D.var_multiple_time_servers%7CtoArrayByComma%7D%7Dserver%20%7B%7B%24element%7D%7D%20minpoll%204%20maxpoll%20%7B%7B%24var_time_service_set_maxpoll%7D%7D%0A%7B%7Bend%7D%7D }}
        mode: 420
        overwrite: true
        path: /etc/chrony.d/ntp-server.conf
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_time_service_set_maxpoll:var:1" value-id="xccdf_org.ssgproject.content_value_var_time_service_set_maxpoll"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-chronyd_or_ntpd_set_maxpoll:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-chronyd_or_ntpd_set_maxpoll_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_chronyd_or_ntpd_specify_multiple_servers" selected="false" severity="medium">
            <xccdf-1.2:title>Specify Additional Remote NTP Servers</xccdf-1.2:title>
            <xccdf-1.2:description>Depending on specific functional requirements of a concrete
production environment, the AlmaLinux OS 8 system can be
configured to utilize the services of the <html:code>chronyd</html:code> NTP daemon (the
default), or services of the <html:code>ntpd</html:code> NTP daemon. Refer to

for more detailed comparison of the features of both of the choices, and for
further guidance how to choose between the two NTP daemons.
<html:br/>
Additional NTP servers can be specified for time synchronization. To do so,
perform the following:
<html:ul><html:li> if the system is configured to use the <html:code>chronyd</html:code> as the NTP daemon
(the default), edit the file <html:code>/etc/chrony.conf</html:code> as follows,</html:li><html:li> if the system is configured to use the <html:code>ntpd</html:code> as the NTP daemon,
edit the file <html:code>/etc/ntp.conf</html:code> as documented below.</html:li></html:ul>
Add additional lines of the following form, substituting the IP address or
hostname of a remote NTP server for <html:em>ntpserver</html:em>:
<html:pre>server <html:i>ntpserver</html:i></html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-8(1)(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-8(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0988</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1405</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Specifying additional NTP servers increases the availability of
accurate time data, in the event that one of the specified servers becomes
unavailable. This is typical for a system acting as an NTP server for
other systems.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#package_chrony_or_package_ntp"/>
            <xccdf-1.2:fix id="chronyd_or_ntpd_specify_multiple_servers" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { ( ( rpm --quiet -q chrony || rpm --quiet -q ntp ) ); }; then

var_multiple_time_servers='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_multiple_time_servers" use="legacy"/>'


config_file="/etc/ntp.conf"
/usr/sbin/pidof ntpd || config_file="/etc/chrony.conf"

if ! [ "$(grep -c '^server' "$config_file")" -gt 1 ] ; then
  if ! grep -q '#[[:space:]]*server' "$config_file" ; then
    for server in $(echo "$var_multiple_time_servers" | tr ',' '\n') ; do
      printf '\nserver %s' "$server" &gt;&gt; "$config_file"
    done
  else
    sed -i 's/#[ \t]*server/server/g' "$config_file"
  fi
  if [[ -s "$config_file" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "$config_file" || true)" ]]; then
      LC_ALL=C sed -i --follow-symlinks '$a'\\ "$config_file"
  fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="chronyd_or_ntpd_specify_multiple_servers" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-AU-8(2)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.3
  - chronyd_or_ntpd_specify_multiple_servers
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
- name: XCCDF Value var_multiple_time_servers # promote to variable
  set_fact:
    var_multiple_time_servers: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_multiple_time_servers" use="legacy"/>
  tags:
    - always

- name: Detect if chrony configuration file is present
  ansible.builtin.find:
    path: /etc
    patterns: chrony.conf
  register: chrony_server_config
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "chrony" in ansible_facts.packages or "ntp" in ansible_facts.packages )
  tags:
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-AU-8(2)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.3
  - chronyd_or_ntpd_specify_multiple_servers
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure multiple time servers in chrony config
  ansible.builtin.lineinfile:
    path: /etc/chrony.conf
    line: server {{ item }}
    state: present
    create: true
  loop: '{{ var_multiple_time_servers.split(",") }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "chrony" in ansible_facts.packages or "ntp" in ansible_facts.packages )
  - chrony_server_config.matched == 1
  tags:
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-AU-8(2)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.3
  - chronyd_or_ntpd_specify_multiple_servers
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Detect if NTP configuration file is present
  ansible.builtin.find:
    path: /etc
    patterns: ntp.conf
  register: ntp_server_config
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "chrony" in ansible_facts.packages or "ntp" in ansible_facts.packages )
  tags:
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-AU-8(2)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.3
  - chronyd_or_ntpd_specify_multiple_servers
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Configure multiple time servers in NTP config
  ansible.builtin.lineinfile:
    path: /etc/chrony.conf
    line: pool {{ item }}
    state: present
    create: true
  loop: '{{ var_multiple_time_servers.split(",") }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - ( "chrony" in ansible_facts.packages or "ntp" in ansible_facts.packages )
  - ntp_server_config.matched == 1
  tags:
  - NIST-800-53-AU-12(1)
  - NIST-800-53-AU-8(1)(a)
  - NIST-800-53-AU-8(2)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.3
  - chronyd_or_ntpd_specify_multiple_servers
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="chronyd_or_ntpd_specify_multiple_servers" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%20Allow%20for%20extra%20configuration%20files.%20This%20is%20useful%0A%23%20for%20admins%20specifying%20their%20own%20NTP%20servers%0Aconfdir%20/etc/chrony.d%0A%0A%23%20Set%20chronyd%20as%20client-only.%0Aport%200%0A%0A%23%20Disable%20chronyc%20from%20the%20network%0Acmdport%200%0A%0A%23%20Record%20the%20rate%20at%20which%20the%20system%20clock%20gains/losses%20time.%0Adriftfile%20/var/lib/chrony/drift%0A%0A%23%20Allow%20the%20system%20clock%20to%20be%20stepped%20in%20the%20first%20three%20updates%0A%23%20if%20its%20offset%20is%20larger%20than%201%20second.%0Amakestep%201.0%203%0A%0A%23%20Enable%20kernel%20synchronization%20of%20the%20real-time%20clock%20%28RTC%29.%0Artcsync%0A%0A%23%20Enable%20hardware%20timestamping%20on%20all%20interfaces%20that%20support%20it.%0A%23hwtimestamp%20%2A%0A%0A%23%20Increase%20the%20minimum%20number%20of%20selectable%20sources%20required%20to%20adjust%0A%23%20the%20system%20clock.%0A%23minsources%202%0A%0A%23%20Allow%20NTP%20client%20access%20from%20local%20network.%0A%23allow%20192.168.0.0/16%0A%0A%23%20Serve%20time%20even%20if%20not%20synchronized%20to%20a%20time%20source.%0A%23local%20stratum%2010%0A%0A%23%20Require%20authentication%20%28nts%20or%20key%20option%29%20for%20all%20NTP%20sources.%0A%23authselectmode%20require%0A%0A%23%20Specify%20file%20containing%20keys%20for%20NTP%20authentication.%0Akeyfile%20/etc/chrony.keys%0A%0A%23%20Insert/delete%20leap%20seconds%20by%20slewing%20instead%20of%20stepping.%0A%23leapsecmode%20slew%0A%0A%23%20Get%20TAI-UTC%20offset%20and%20leap%20seconds%20from%20the%20system%20tz%20database.%0Aleapsectz%20right/UTC%0A%0A%23%20Specify%20directory%20for%20log%20files.%0Alogdir%20/var/log/chrony%0A%0A%23%20Select%20which%20information%20is%20logged.%0A%23log%20measurements%20statistics%20tracking }}
        mode: 420
        overwrite: true
        path: /etc/chrony.conf
      - contents:
          source: data:,
        mode: 420
        overwrite: true
        path: /etc/chrony.d/.mco-keep
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20ntp%20server%0A%23%20%7B%7B.var_multiple_time_servers%7D%7D%20we%20have%20to%20put%20variable%20array%20name%20here%20for%20mutilines%20remediation%0A%7B%7B%24var_time_service_set_maxpoll%3A%3D.var_time_service_set_maxpoll%7D%7D%0A%7B%7Brange%20%24element%3A%3D.var_multiple_time_servers%7CtoArrayByComma%7D%7Dserver%20%7B%7B%24element%7D%7D%20minpoll%204%20maxpoll%20%7B%7B%24var_time_service_set_maxpoll%7D%7D%0A%7B%7Bend%7D%7D }}
        mode: 420
        overwrite: true
        path: /etc/chrony.d/ntp-server.conf
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-chronyd_or_ntpd_specify_multiple_servers:def:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_chronyd_or_ntpd_specify_remote_server" selected="false" severity="medium">
            <xccdf-1.2:title>Specify a Remote NTP Server</xccdf-1.2:title>
            <xccdf-1.2:description>Depending on specific functional requirements of a concrete
production environment, the AlmaLinux OS 8 system can be
configured to utilize the services of the <html:code>chronyd</html:code> NTP daemon (the
default), or services of the <html:code>ntpd</html:code> NTP daemon. Refer to

for more detailed comparison of the features of both of the choices, and for
further guidance how to choose between the two NTP daemons.
<html:br/>
To specify a remote NTP server for time synchronization, perform the following:
<html:ul><html:li> if the system is configured to use the <html:code>chronyd</html:code> as the NTP daemon (the
default), edit the file <html:code>/etc/chrony.conf</html:code> as follows,</html:li><html:li> if the system is configured to use the <html:code>ntpd</html:code> as the NTP daemon,
edit the file <html:code>/etc/ntp.conf</html:code> as documented below.</html:li></html:ul>
Add or correct the following lines, substituting the IP or hostname of a remote
NTP server for <html:em>ntpserver</html:em>:
<html:pre>server <html:i>ntpserver</html:i></html:pre>
This instructs the NTP software to contact that remote server to obtain time
data.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-8(1)(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-8(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000116-CTR-000235</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Synchronizing with an NTP server makes it possible to collate system
logs from multiple sources or correlate computer events with real time events.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#package_chrony_or_package_ntp"/>
            <xccdf-1.2:fix id="chronyd_or_ntpd_specify_remote_server" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { ( ( rpm --quiet -q chrony || rpm --quiet -q ntp ) ); }; then

var_multiple_time_servers='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_multiple_time_servers" use="legacy"/>'


config_file="/etc/ntp.conf"
/usr/sbin/pidof ntpd || config_file="/etc/chrony.conf"

if ! grep -q ^server "$config_file" ; then
  if ! grep -q '#[[:space:]]*server' "$config_file" ; then
    for server in $(echo "$var_multiple_time_servers" | tr ',' '\n') ; do
      printf '\nserver %s' "$server" &gt;&gt; "$config_file"
    done
  else
    sed -i 's/#[ \t]*server/server/g' "$config_file"
  fi
  if [[ -s "$config_file" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "$config_file" || true)" ]]; then
      LC_ALL=C sed -i --follow-symlinks '$a'\\ "$config_file"
  fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="chronyd_or_ntpd_specify_remote_server" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%20Allow%20for%20extra%20configuration%20files.%20This%20is%20useful%0A%23%20for%20admins%20specifying%20their%20own%20NTP%20servers%0Aconfdir%20/etc/chrony.d%0A%0A%23%20Set%20chronyd%20as%20client-only.%0Aport%200%0A%0A%23%20Disable%20chronyc%20from%20the%20network%0Acmdport%200%0A%0A%23%20Record%20the%20rate%20at%20which%20the%20system%20clock%20gains/losses%20time.%0Adriftfile%20/var/lib/chrony/drift%0A%0A%23%20Allow%20the%20system%20clock%20to%20be%20stepped%20in%20the%20first%20three%20updates%0A%23%20if%20its%20offset%20is%20larger%20than%201%20second.%0Amakestep%201.0%203%0A%0A%23%20Enable%20kernel%20synchronization%20of%20the%20real-time%20clock%20%28RTC%29.%0Artcsync%0A%0A%23%20Enable%20hardware%20timestamping%20on%20all%20interfaces%20that%20support%20it.%0A%23hwtimestamp%20%2A%0A%0A%23%20Increase%20the%20minimum%20number%20of%20selectable%20sources%20required%20to%20adjust%0A%23%20the%20system%20clock.%0A%23minsources%202%0A%0A%23%20Allow%20NTP%20client%20access%20from%20local%20network.%0A%23allow%20192.168.0.0/16%0A%0A%23%20Serve%20time%20even%20if%20not%20synchronized%20to%20a%20time%20source.%0A%23local%20stratum%2010%0A%0A%23%20Require%20authentication%20%28nts%20or%20key%20option%29%20for%20all%20NTP%20sources.%0A%23authselectmode%20require%0A%0A%23%20Specify%20file%20containing%20keys%20for%20NTP%20authentication.%0Akeyfile%20/etc/chrony.keys%0A%0A%23%20Insert/delete%20leap%20seconds%20by%20slewing%20instead%20of%20stepping.%0A%23leapsecmode%20slew%0A%0A%23%20Get%20TAI-UTC%20offset%20and%20leap%20seconds%20from%20the%20system%20tz%20database.%0Aleapsectz%20right/UTC%0A%0A%23%20Specify%20directory%20for%20log%20files.%0Alogdir%20/var/log/chrony%0A%0A%23%20Select%20which%20information%20is%20logged.%0A%23log%20measurements%20statistics%20tracking }}
        mode: 420
        overwrite: true
        path: /etc/chrony.conf
      - contents:
          source: data:,
        mode: 420
        overwrite: true
        path: /etc/chrony.d/.mco-keep
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20ntp%20server%0A%23%20%7B%7B.var_multiple_time_servers%7D%7D%20we%20have%20to%20put%20variable%20array%20name%20here%20for%20mutilines%20remediation%0A%7B%7B%24var_time_service_set_maxpoll%3A%3D.var_time_service_set_maxpoll%7D%7D%0A%7B%7Brange%20%24element%3A%3D.var_multiple_time_servers%7CtoArrayByComma%7D%7Dserver%20%7B%7B%24element%7D%7D%20minpoll%204%20maxpoll%20%7B%7B%24var_time_service_set_maxpoll%7D%7D%0A%7B%7Bend%7D%7D }}
        mode: 420
        overwrite: true
        path: /etc/chrony.d/ntp-server.conf
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-chronyd_or_ntpd_specify_remote_server:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-chronyd_or_ntpd_specify_remote_server_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_chronyd_run_as_chrony_user" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure that chronyd is running under chrony user account</xccdf-1.2:title>
            <xccdf-1.2:description>chrony is a daemon which implements the Network Time Protocol (NTP). It is designed to
synchronize system clocks across a variety of systems and use a source that is highly
accurate. More information on chrony can be found at

    <html:a href="https://chrony-project.org/">https://chrony-project.org/</html:a>.
Chrony can be configured to be a client and/or a server.
To ensure that chronyd is running under chrony user account,
add or edit the
<html:code>OPTIONS</html:code> variable in <html:code>/etc/sysconfig/chronyd</html:code> to include <html:code>-u chrony</html:code>:
<html:pre>OPTIONS="-u chrony"</html:pre>

This recommendation only applies if chrony is in use on the system.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.3.3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If chrony is in use on the system proper configuration is vital to ensuring time synchronization
is working properly.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#package_chrony"/>
            <xccdf-1.2:fix id="chronyd_run_as_chrony_user" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q chrony; }; then

if grep -q 'OPTIONS=.*' /etc/sysconfig/chronyd; then
	# trying to solve cases where the parameter after OPTIONS
	#may or may not be enclosed in quotes
	sed -i -E -e 's/\s*-u\s*\w+\s*/ /' -e 's/^([\s]*OPTIONS=["]?[^"]*)("?)/\1 -u chrony\2/' /etc/sysconfig/chronyd
else
	echo 'OPTIONS="-u chrony"' &gt;&gt; /etc/sysconfig/chronyd
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="chronyd_run_as_chrony_user" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - chronyd_run_as_chrony_user
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Detect if file /etc/sysconfig/chronyd is not empty or missing
  ansible.builtin.find:
    path: /etc/sysconfig/
    patterns: chronyd
    contains: ^([\s]*OPTIONS=["]?[^"]*)("?)
  register: chronyd_file
  when:
  - '"kernel" in ansible_facts.packages'
  - '"chrony" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - chronyd_run_as_chrony_user
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Remove any previous configuration of user used to run chronyd process
  ansible.builtin.replace:
    path: /etc/sysconfig/chronyd
    regexp: \s*-u\s*\w+\s*
    replace: ' '
  when:
  - '"kernel" in ansible_facts.packages'
  - '"chrony" in ansible_facts.packages'
  - chronyd_file is defined and chronyd_file.matched &gt; 0
  tags:
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - chronyd_run_as_chrony_user
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Correct existing line in /etc/sysconfig/chronyd to run chronyd as chrony user
  ansible.builtin.lineinfile:
    path: /etc/sysconfig/chronyd
    regexp: ^([\s]*OPTIONS=["]?[^"]*)("?)
    line: \1 -u chrony\2
    state: present
    backrefs: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"chrony" in ansible_facts.packages'
  - chronyd_file is defined and chronyd_file.matched &gt; 0
  tags:
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - chronyd_run_as_chrony_user
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Insert correct line into /etc/sysconfig/chronyd ensuring chronyd runs as chrony
    user
  ansible.builtin.lineinfile:
    path: /etc/sysconfig/chronyd
    line: OPTIONS="-u chrony"
    state: present
    create: true
  when:
  - '"kernel" in ansible_facts.packages'
  - '"chrony" in ansible_facts.packages'
  - chronyd_file is defined and chronyd_file.matched == 0
  tags:
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - chronyd_run_as_chrony_user
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-chronyd_run_as_chrony_user:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-chronyd_run_as_chrony_user_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_chronyd_server_directive" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure Chrony is only configured with the server directive</xccdf-1.2:title>
            <xccdf-1.2:description>Check that Chrony only has time sources configured with the <html:code>server</html:code> directive.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">This rule doesn't come with a remediation, the time source needs to be added by the administrator.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000355-GPOS-00143</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000356-GPOS-00144</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000359-GPOS-00146</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030740</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230484r1038944_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Depending on the infrastructure being used the <html:code>pool</html:code> directive may not be supported.
Using the <html:code>server</html:code> directive allows for better control of where the system gets time data from.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#package_chrony"/>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-chronyd_server_directive:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-chronyd_server_directive_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_etc_chrony_keys" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Group Who Owns /etc/chrony.keys File</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/chrony.keys</html:code>, run the command:
<html:pre>$ sudo chgrp chrony /etc/chrony.keys</html:pre>
</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The ownership of the /etc/chrony.keys file by the chrony group is important
because this file hosts chrony cryptographic keys. Protection
of this file is critical for system security. Assigning the ownership to
chrony ensures exclusive control of the chrony cryptography keys.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_chrony_keys" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "chrony" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="chrony"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "chrony is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/chrony.keys" | grep -E -w -q "chrony"; then
    chgrp --no-dereference "$newgroup" /etc/chrony.keys
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_etc_chrony_keys" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_groupowner_etc_chrony_keys
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Check that the chrony group is defined
  ansible.builtin.getent:
    database: group
    key: chrony
  ignore_errors: true
  when:
  - '"kernel" in ansible_facts.packages'
  - file_groupowner_etc_chrony_keys_newgroup is undefined
  tags:
  - configure_strategy
  - file_groupowner_etc_chrony_keys
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_etc_chrony_keys_newgroup variable if chrony found
  ansible.builtin.set_fact:
    file_groupowner_etc_chrony_keys_newgroup: chrony
  when:
  - '"kernel" in ansible_facts.packages'
  - ansible_facts.getent_group["chrony"] is defined
  tags:
  - configure_strategy
  - file_groupowner_etc_chrony_keys
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/chrony.keys
  ansible.builtin.stat:
    path: /etc/chrony.keys
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupowner_etc_chrony_keys
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/chrony.keys
  ansible.builtin.file:
    path: /etc/chrony.keys
    follow: false
    group: '{{ file_groupowner_etc_chrony_keys_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupowner_etc_chrony_keys
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_etc_chrony_keys:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_etc_chrony_keys_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_etc_chrony_keys" selected="false" severity="medium">
            <xccdf-1.2:title>Verify User Who Owns /etc/chrony.keys File</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the owner of <html:code>/etc/chrony.keys</html:code>, run the command:
<html:pre>$ sudo chown root /etc/chrony.keys </html:pre>
</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The ownership of the /etc/chrony.keys file by the chrony user is important
because this file hosts chrony cryptographic keys. Protection
of this file is critical for system security. Assigning the ownership to
chrony ensures exclusive control of the chrony cryptographic keys.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_chrony_keys" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/chrony.keys" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/chrony.keys
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_etc_chrony_keys" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_owner_etc_chrony_keys
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_etc_chrony_keys_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_etc_chrony_keys_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_etc_chrony_keys
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/chrony.keys
  ansible.builtin.stat:
    path: /etc/chrony.keys
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_owner_etc_chrony_keys
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/chrony.keys
  ansible.builtin.file:
    path: /etc/chrony.keys
    follow: false
    owner: '{{ file_owner_etc_chrony_keys_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_owner_etc_chrony_keys
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_etc_chrony_keys:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_etc_chrony_keys_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_chrony_keys" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Permissions On /etc/chrony.keys File</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/chrony.keys</html:code>, run the command: <html:pre>$ sudo chmod 0640 /etc/chrony.keys</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Setting correct permissions on the /etc/chrony.keys file is important
because this file hosts chrony cryptographic keys. Protection
of this file is critical for system security. Assigning the correct mode
ensures exclusive control of the chrony cryptographic keys.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_chrony_keys" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

chmod u-xs,g-xws,o-xwrt /etc/chrony.keys

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_chrony_keys" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_permissions_etc_chrony_keys
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/chrony.keys
  ansible.builtin.stat:
    path: /etc/chrony.keys
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_permissions_etc_chrony_keys
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xws,o-xwrt on /etc/chrony.keys
  ansible.builtin.file:
    path: /etc/chrony.keys
    mode: u-xs,g-xws,o-xwrt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_etc_chrony_keys
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_chrony_keys:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_chrony_keys_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ntpd_specify_multiple_servers" selected="false" severity="unknown">
            <xccdf-1.2:title>Specify Additional Remote NTP Servers</xccdf-1.2:title>
            <xccdf-1.2:description>Additional NTP servers can be specified for time synchronization
in the file <html:code>/etc/ntp.conf</html:code>.  To do so, add additional lines of the
following form, substituting the IP address or hostname of a remote NTP server for
<html:em>ntpserver</html:em>:
<html:pre>server <html:i>ntpserver</html:i></html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-8(1)(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-8(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Specifying additional NTP servers increases the availability of
accurate time data, in the event that one of the specified servers becomes
unavailable. This is typical for a system acting as an NTP server for
other systems.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ntpd_specify_multiple_servers:def:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ntpd_specify_remote_server" selected="false" severity="medium">
            <xccdf-1.2:title>Specify a Remote NTP Server</xccdf-1.2:title>
            <xccdf-1.2:description>To specify a remote NTP server for time synchronization, edit
the file <html:code>/etc/ntp.conf</html:code>. Add or correct the following lines,
substituting the IP or hostname of a remote NTP server for <html:em>ntpserver</html:em>:
<html:pre>server <html:i>ntpserver</html:i></html:pre>
This instructs the NTP software to contact that remote server to obtain time
data.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-8(1)(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Synchronizing with an NTP server makes it possible
to collate system logs from multiple sources or correlate computer events with
real time events.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#package_ntp"/>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ntpd_specify_remote_server:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ntpd_specify_remote_server_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_obsolete">
          <xccdf-1.2:title>Obsolete Services</xccdf-1.2:title>
          <xccdf-1.2:description>This section discusses a number of network-visible
services which have historically caused problems for system
security, and for which disabling or severely limiting the service
has been the best available guidance for some time. As a result of
this, many of these services are not installed as part of AlmaLinux OS 8
by default.
<html:br/><html:br/>
Organizations which are running these services should
switch to more secure equivalents as soon as possible.
If it remains absolutely necessary to run one of
these services for legacy reasons, care should be taken to restrict
the service as much as possible, for instance by configuring host

firewall software such as <html:code>iptables</html:code> to restrict access to the

vulnerable service to only those remote hosts which have a known
need to use it.</xccdf-1.2:description>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_rsync_removed" selected="false" severity="medium">
            <xccdf-1.2:title>Uninstall rsync Package</xccdf-1.2:title>
            <xccdf-1.2:description>The rsyncd service can be used to synchronize files between systems over network links.
The <html:code>rsync</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase rsync</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.13</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The rsyncd service presents a security risk as it uses unencrypted protocols for
communication.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsync_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove rsync
# from the system, and may remove any packages
# that depend on rsync. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "rsync" ; then
yum remove -y "rsync"
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsync_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall rsync Package: Ensure rsync is removed'
  ansible.builtin.package:
    name: rsync
    state: absent
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_rsync_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsync_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_rsync

class remove_rsync {
  package { 'rsync':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsync_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=rsync
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsync_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove rsync
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsync_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove rsync
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_rsync_removed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_rsync_removed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_rsyncd_disabled" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure rsyncd service is disabled</xccdf-1.2:title>
            <xccdf-1.2:description>
The <html:code>rsyncd</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now rsyncd.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The rsyncd service presents a security risk as it uses unencrypted protocols for
communication.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rsyncd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'rsyncd.service'
fi
"$SYSTEMCTL_EXEC" disable 'rsyncd.service'
"$SYSTEMCTL_EXEC" mask 'rsyncd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files rsyncd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'rsyncd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'rsyncd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'rsyncd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rsyncd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_rsyncd_disabled

- name: Ensure rsyncd service is disabled - Disable service rsyncd
  block:

  - name: Ensure rsyncd service is disabled - Collect systemd Services Present in
      the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Ensure rsyncd service is disabled - Ensure rsyncd.service is Masked
    ansible.builtin.systemd:
      name: rsyncd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("rsyncd.service", multiline=True)

  - name: Unit Socket Exists - rsyncd.socket
    ansible.builtin.command: systemctl -q list-unit-files rsyncd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Ensure rsyncd service is disabled - Disable Socket rsyncd
    ansible.builtin.systemd:
      name: rsyncd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("rsyncd.socket", multiline=True)
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_rsyncd_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rsyncd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_rsyncd

class disable_rsyncd {
  service {'rsyncd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_rsyncd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: rsyncd.service
        enabled: false
        mask: true
      - name: rsyncd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_rsyncd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["rsyncd"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rsyncd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable rsyncd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_rsyncd_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_rsyncd_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_inetd_and_xinetd">
            <xccdf-1.2:title>Xinetd</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>xinetd</html:code> service acts as a dedicated listener for some
network services (mostly, obsolete ones) and can be used to provide access
controls and perform some logging. It has been largely obsoleted by other
features, and it is not installed by default. The older Inetd service
is not even available as part of AlmaLinux OS 8.</xccdf-1.2:description>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_xinetd_removed" selected="false" severity="low">
              <xccdf-1.2:title>Uninstall xinetd package if not used by network services</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>xinetd</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase xinetd</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R62</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.20</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Removing the <html:code>xinetd</html:code> package decreases the risk of the
xinetd service's accidental (or intentional) activation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xinetd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

# CAUTION: This remediation script will remove xinetd
# from the system, and may remove any packages
# that depend on xinetd. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "xinetd" ; then
yum remove -y "xinetd"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xinetd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_xinetd_removed

- name: 'Uninstall xinetd package if not used by network services: Ensure xinetd is
    removed'
  ansible.builtin.package:
    name: xinetd
    state: absent
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_xinetd_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xinetd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_xinetd

class remove_xinetd {
  package { 'xinetd':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xinetd_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=xinetd
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xinetd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove xinetd
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xinetd_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove xinetd
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_xinetd_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_xinetd_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_xinetd_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable xinetd Service</xccdf-1.2:title>
              <xccdf-1.2:description>
The <html:code>xinetd</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now xinetd.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The xinetd service provides a dedicated listener service for some programs,
which is no longer necessary for commonly-used network services. Disabling
it ensures that these uncommon services are not running, and also prevents
attacks against xinetd itself.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_xinetd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'xinetd.service'
fi
"$SYSTEMCTL_EXEC" disable 'xinetd.service'
"$SYSTEMCTL_EXEC" mask 'xinetd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files xinetd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'xinetd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'xinetd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'xinetd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_xinetd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.4.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_xinetd_disabled

- name: Disable xinetd Service - Disable service xinetd
  block:

  - name: Disable xinetd Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable xinetd Service - Ensure xinetd.service is Masked
    ansible.builtin.systemd:
      name: xinetd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("xinetd.service", multiline=True)

  - name: Unit Socket Exists - xinetd.socket
    ansible.builtin.command: systemctl -q list-unit-files xinetd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable xinetd Service - Disable Socket xinetd
    ansible.builtin.systemd:
      name: xinetd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("xinetd.socket", multiline=True)
  tags:
  - NIST-800-171-3.4.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_xinetd_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_xinetd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_xinetd

class disable_xinetd {
  service {'xinetd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_xinetd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: xinetd.service
        enabled: false
        mask: true
      - name: xinetd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_xinetd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["xinetd"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_xinetd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable xinetd
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_xinetd_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_xinetd_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_nis">
            <xccdf-1.2:title>NIS</xccdf-1.2:title>
            <xccdf-1.2:description>The Network Information Service (NIS), also known as 'Yellow
Pages' (YP), and its successor NIS+ have been made obsolete by
Kerberos, LDAP, and other modern centralized authentication
services. NIS should not be used because it suffers from security
problems inherent in its design, such as inadequate protection of
important authentication information.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_ypbind_removed" selected="false" severity="unknown">
              <xccdf-1.2:title>Remove NIS Client</xccdf-1.2:title>
              <xccdf-1.2:description>The Network Information Service (NIS), formerly known as Yellow Pages,
is a client-server directory service protocol used to distribute system configuration
files. The NIS client (<html:code>ypbind</html:code>) was used to bind a system to an NIS server
and receive the distributed configuration files.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R62</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The NIS service is inherently an insecure system that has been vulnerable
to DOS attacks, buffer overflows and has poor authentication for querying
NIS maps. NIS generally has been replaced by such protocols as Lightweight
Directory Access Protocol (LDAP). It is recommended that the service be
removed.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_ypbind_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove ypbind
# from the system, and may remove any packages
# that depend on ypbind. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "ypbind" ; then
yum remove -y "ypbind"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_ypbind_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Remove NIS Client: Ensure ypbind is removed'
  ansible.builtin.package:
    name: ypbind
    state: absent
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_ypbind_removed
  - unknown_severity
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_ypbind_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_ypbind

class remove_ypbind {
  package { 'ypbind':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_ypbind_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=ypbind
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_ypbind_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove ypbind
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_ypbind_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove ypbind
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_ypbind_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_ypserv_removed" selected="false" severity="high">
              <xccdf-1.2:title>Uninstall ypserv Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>ypserv</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase ypserv</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-2.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R62</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.10</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The NIS service provides an unencrypted authentication service which does
not provide for the confidentiality and integrity of user passwords or the
remote session.

Removing the <html:code>ypserv</html:code> package decreases the risk of the accidental
(or intentional) activation of NIS or NIS+ services.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_ypserv_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove ypserv
# from the system, and may remove any packages
# that depend on ypserv. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "ypserv" ; then
yum remove -y "ypserv"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_ypserv_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall ypserv Package: Ensure ypserv is removed'
  ansible.builtin.package:
    name: ypserv
    state: absent
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-5(1)(c)
  - PCI-DSS-Req-2.2.2
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_ypserv_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_ypserv_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_ypserv

class remove_ypserv {
  package { 'ypserv':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_ypserv_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=ypserv
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_ypserv_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove ypserv
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_ypserv_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove ypserv
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_ypserv_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_ypserv_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_ypbind_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable ypbind Service</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>ypbind</html:code> service, which allows the system to act as a client in
a NIS or NIS+ domain, should be disabled.

The <html:code>ypbind</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now ypbind.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Disabling the <html:code>ypbind</html:code> service ensures the system is not acting
as a client in a NIS or NIS+ domain. This service should be disabled
unless in use.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_ypbind_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'ypbind.service'
fi
"$SYSTEMCTL_EXEC" disable 'ypbind.service'
"$SYSTEMCTL_EXEC" mask 'ypbind.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files ypbind.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'ypbind.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'ypbind.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'ypbind.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_ypbind_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-5(1)(c)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_ypbind_disabled

- name: Disable ypbind Service - Disable service ypbind
  block:

  - name: Disable ypbind Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable ypbind Service - Ensure ypbind.service is Masked
    ansible.builtin.systemd:
      name: ypbind.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("ypbind.service", multiline=True)

  - name: Unit Socket Exists - ypbind.socket
    ansible.builtin.command: systemctl -q list-unit-files ypbind.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable ypbind Service - Disable Socket ypbind
    ansible.builtin.systemd:
      name: ypbind.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("ypbind.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-5(1)(c)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_ypbind_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_ypbind_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_ypbind

class disable_ypbind {
  service {'ypbind':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_ypbind_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: ypbind.service
        enabled: false
        mask: true
      - name: ypbind.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_ypbind_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["ypbind"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_ypbind_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable ypbind
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_ypbind_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_ypbind_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_ypserv_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable ypserv Service</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>ypserv</html:code> service, which allows the system to act as a client in
a NIS or NIS+ domain, should be disabled.

The <html:code>ypserv</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now ypserv.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>Disabling the <html:code>ypserv</html:code> service ensures the system is not acting
as a client in a NIS or NIS+ domain. This service should be disabled
unless in use.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_ypserv_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'ypserv.service'
fi
"$SYSTEMCTL_EXEC" disable 'ypserv.service'
"$SYSTEMCTL_EXEC" mask 'ypserv.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files ypserv.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'ypserv.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'ypserv.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'ypserv.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_ypserv_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_ypserv_disabled

- name: Disable ypserv Service - Disable service ypserv
  block:

  - name: Disable ypserv Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable ypserv Service - Ensure ypserv.service is Masked
    ansible.builtin.systemd:
      name: ypserv.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("ypserv.service", multiline=True)

  - name: Unit Socket Exists - ypserv.socket
    ansible.builtin.command: systemctl -q list-unit-files ypserv.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable ypserv Service - Disable Socket ypserv
    ansible.builtin.systemd:
      name: ypserv.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("ypserv.socket", multiline=True)
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_ypserv_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_ypserv_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_ypserv

class disable_ypserv {
  service {'ypserv':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_ypserv_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: ypserv.service
        enabled: false
        mask: true
      - name: ypserv.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_ypserv_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["ypserv"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_ypserv_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable ypserv
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_ypserv_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_ypserv_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_nis_in_nsswitch" selected="false" severity="medium">
              <xccdf-1.2:title>Name Service Switch does not use NIS</xccdf-1.2:title>
              <xccdf-1.2:description>Each call to a function which retrieves data from a system database like the
password or group database is handled by the Name Service Switch
implementation in the GNU C library.  The various services provided are
implemented by independent modules, each of which naturally varies widely
from the other. One of such modules is the <html:code>nis</html:code> module, which allows
to get information from NIS servers.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule does not have remediation. Editing the <html:code>/etc/nsswitch.conf</html:code> incorrectly can disrupt access to the system.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R69</xccdf-1.2:reference>
              <xccdf-1.2:rationale>NIS service is insecure and should not be used.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_nis_in_nsswitch:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_nis_in_nsswitch_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_r_services">
            <xccdf-1.2:title>Rlogin, Rsh, and Rexec</xccdf-1.2:title>
            <xccdf-1.2:description>The Berkeley r-commands are legacy services which
allow cleartext remote access and have an insecure trust
model.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_rsh-server_removed" selected="false" severity="high">
              <xccdf-1.2:title>Uninstall rsh-server Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>rsh-server</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase rsh-server</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">The package is not available in AlmaLinux OS 8.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R62</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>rsh-server</html:code> service provides unencrypted remote access service which does not
provide for the confidentiality and integrity of user passwords or the remote session and has very weak
authentication. If a privileged user were to login using this service, the privileged user password
could be compromised. The <html:code>rsh-server</html:code> package provides several obsolete and insecure
network services. Removing it decreases the risk of those services' accidental (or intentional)
activation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsh-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove rsh-server
# from the system, and may remove any packages
# that depend on rsh-server. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "rsh-server" ; then
yum remove -y "rsh-server"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsh-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall rsh-server Package: Ensure rsh-server is removed'
  ansible.builtin.package:
    name: rsh-server
    state: absent
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-5(1)(c)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_rsh-server_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsh-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_rsh-server

class remove_rsh-server {
  package { 'rsh-server':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsh-server_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=rsh-server
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsh-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove rsh-server
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsh-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove rsh-server
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_rsh-server_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_rsh_removed" selected="false" severity="unknown">
              <xccdf-1.2:title>Uninstall rsh Package</xccdf-1.2:title>
              <xccdf-1.2:description>
The <html:code>rsh</html:code> package contains the client commands

for the rsh services</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">The package is not available in AlmaLinux OS 8.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R62</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>These legacy clients contain numerous security exposures and have
been replaced with the more secure SSH package. Even if the server is removed,
it is best to ensure the clients are also removed to prevent users from
inadvertently attempting to use these commands and therefore exposing

their credentials. Note that removing the <html:code>rsh</html:code> package removes

the clients for <html:code>rsh</html:code>,<html:code>rcp</html:code>, and <html:code>rlogin</html:code>.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsh_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove rsh
# from the system, and may remove any packages
# that depend on rsh. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "rsh" ; then
yum remove -y "rsh"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsh_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall rsh Package: Ensure rsh is removed'
  ansible.builtin.package:
    name: rsh
    state: absent
  tags:
  - NIST-800-171-3.1.13
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_rsh_removed
  - unknown_severity
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsh_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_rsh

class remove_rsh {
  package { 'rsh':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsh_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=rsh
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsh_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove rsh
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_rsh_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove rsh
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_rsh_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_rsh_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_rexec_disabled" selected="false" severity="high">
              <xccdf-1.2:title>Disable rexec Service</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>rexec</html:code> service, which is available with the <html:code>rsh-server</html:code> package
and runs as a service through xinetd or separately as a systemd socket, should be disabled.
If using xinetd, set <html:code>disable</html:code> to <html:code>yes</html:code> in <html:code>/etc/xinetd.d/rexec</html:code>.

The <html:code>rexec</html:code> socket can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now rexec.socket</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The rexec service uses unencrypted network communications, which
means that data from the login session, including passwords and
all other information transmitted during the session, can be
stolen by eavesdroppers on the network.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_rexec_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'rexec.service'
fi
"$SYSTEMCTL_EXEC" disable 'rexec.service'
"$SYSTEMCTL_EXEC" mask 'rexec.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files rexec.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'rexec.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'rexec.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'rexec.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_rexec_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.13
  - NIST-800-171-3.4.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-5(1)(c)
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_rexec_disabled

- name: Disable rexec Service - Disable service rexec
  block:

  - name: Disable rexec Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable rexec Service - Ensure rexec.service is Masked
    ansible.builtin.systemd:
      name: rexec.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("rexec.service", multiline=True)

  - name: Unit Socket Exists - rexec.socket
    ansible.builtin.command: systemctl -q list-unit-files rexec.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable rexec Service - Disable Socket rexec
    ansible.builtin.systemd:
      name: rexec.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("rexec.socket", multiline=True)
  tags:
  - NIST-800-171-3.1.13
  - NIST-800-171-3.4.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-5(1)(c)
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_rexec_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_rexec_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_rexec

class disable_rexec {
  service {'rexec':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_rexec_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: rexec.service
        enabled: false
        mask: true
      - name: rexec.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_rexec_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["rexec"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_rexec_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable rexec
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_rexec_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_rexec_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_rlogin_disabled" selected="false" severity="high">
              <xccdf-1.2:title>Disable rlogin Service</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>rlogin</html:code> service, which is available with
the <html:code>rsh-server</html:code> package and runs as a service through xinetd or separately
as a systemd socket, should be disabled.
If using xinetd, set <html:code>disable</html:code> to <html:code>yes</html:code> in <html:code>/etc/xinetd.d/rlogin</html:code>.

The <html:code>rlogin</html:code> socket can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now rlogin.socket</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The rlogin service uses unencrypted network communications, which
means that data from the login session, including passwords and
all other information transmitted during the session, can be
stolen by eavesdroppers on the network.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_rlogin_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'rlogin.service'
fi
"$SYSTEMCTL_EXEC" disable 'rlogin.service'
"$SYSTEMCTL_EXEC" mask 'rlogin.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files rlogin.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'rlogin.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'rlogin.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'rlogin.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_rlogin_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.13
  - NIST-800-171-3.4.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-5(1)(c)
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_rlogin_disabled

- name: Disable rlogin Service - Disable service rlogin
  block:

  - name: Disable rlogin Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable rlogin Service - Ensure rlogin.service is Masked
    ansible.builtin.systemd:
      name: rlogin.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("rlogin.service", multiline=True)

  - name: Unit Socket Exists - rlogin.socket
    ansible.builtin.command: systemctl -q list-unit-files rlogin.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable rlogin Service - Disable Socket rlogin
    ansible.builtin.systemd:
      name: rlogin.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("rlogin.socket", multiline=True)
  tags:
  - NIST-800-171-3.1.13
  - NIST-800-171-3.4.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-5(1)(c)
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_rlogin_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_rlogin_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_rlogin

class disable_rlogin {
  service {'rlogin':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_rlogin_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: rlogin.service
        enabled: false
        mask: true
      - name: rlogin.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_rlogin_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["rlogin"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_rlogin_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable rlogin
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_rlogin_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_rlogin_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_rsh_disabled" selected="false" severity="high">
              <xccdf-1.2:title>Disable rsh Service</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>rsh</html:code> service, which is available with
the <html:code>rsh-server</html:code> package and runs as a service through xinetd or separately
as a systemd socket, should be disabled.
If using xinetd, set <html:code>disable</html:code> to <html:code>yes</html:code> in <html:code>/etc/xinetd.d/rsh</html:code>.

The <html:code>rsh</html:code> socket can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now rsh.socket</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The rsh service uses unencrypted network communications, which
means that data from the login session, including passwords and
all other information transmitted during the session, can be
stolen by eavesdroppers on the network.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_rsh_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'rsh.service'
fi
"$SYSTEMCTL_EXEC" disable 'rsh.service'
"$SYSTEMCTL_EXEC" mask 'rsh.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files rsh.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'rsh.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'rsh.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'rsh.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_rsh_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.13
  - NIST-800-171-3.4.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-5(1)(c)
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_rsh_disabled

- name: Disable rsh Service - Disable service rsh
  block:

  - name: Disable rsh Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable rsh Service - Ensure rsh.service is Masked
    ansible.builtin.systemd:
      name: rsh.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("rsh.service", multiline=True)

  - name: Unit Socket Exists - rsh.socket
    ansible.builtin.command: systemctl -q list-unit-files rsh.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable rsh Service - Disable Socket rsh
    ansible.builtin.systemd:
      name: rsh.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("rsh.socket", multiline=True)
  tags:
  - NIST-800-171-3.1.13
  - NIST-800-171-3.4.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-5(1)(c)
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_rsh_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_rsh_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_rsh

class disable_rsh {
  service {'rsh':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_rsh_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: rsh.service
        enabled: false
        mask: true
      - name: rsh.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_rsh_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["rsh"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_rsh_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable rsh
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_rsh_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_rsh_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_host_based_files" selected="false" severity="high">
              <xccdf-1.2:title>Remove Host-Based Authentication Files</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>shosts.equiv</html:code> file lists remote hosts and users that are trusted by the local
system. To remove these files, run the following command to delete them from any location:
<html:pre>$ sudo rm /[path]/[to]/[file]/shosts.equiv</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010460</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230283r1017094_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The shosts.equiv files are used to configure host-based authentication for the system via SSH.
Host-based authentication is not sufficient for preventing unauthorized access to the system,
as it does not require interactive identification and authentication of a connection request,
or for the use of two-factor authentication.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="no_host_based_files" system="urn:xccdf:fix:script:sh">
# Identify local mounts
MOUNT_LIST=$(df --local | awk '{ print $6 }')

# Find file on each listed mount point
for cur_mount in ${MOUNT_LIST}
do
	find ${cur_mount} -xdev -type f -name "shosts.equiv" -exec rm -f {} \;
done
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="no_host_based_files" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Remove Host-Based Authentication Files - Define Excluded (Non-Local) File
    Systems and Paths
  ansible.builtin.set_fact:
    excluded_fstypes:
    - afs
    - autofs
    - ceph
    - cifs
    - smb3
    - smbfs
    - sshfs
    - ncpfs
    - ncp
    - nfs
    - nfs4
    - gfs
    - gfs2
    - glusterfs
    - gpfs
    - pvfs2
    - ocfs2
    - lustre
    - davfs
    - fuse.sshfs
    excluded_paths:
    - dev
    - proc
    - run
    - sys
    search_paths: []
  tags:
  - DISA-STIG-RHEL-08-010460
  - high_severity
  - low_complexity
  - low_disruption
  - no_host_based_files
  - no_reboot_needed
  - restrict_strategy

- name: Remove Host-Based Authentication Files - Find Relevant Root Directories Ignoring
    Pre-Defined Excluded Paths
  ansible.builtin.find:
    paths: /
    file_type: directory
    excludes: '{{ excluded_paths }}'
    hidden: true
    recurse: false
  register: result_relevant_root_dirs
  tags:
  - DISA-STIG-RHEL-08-010460
  - high_severity
  - low_complexity
  - low_disruption
  - no_host_based_files
  - no_reboot_needed
  - restrict_strategy

- name: Remove Host-Based Authentication Files - Include Relevant Root Directories
    in a List of Paths to be Searched
  ansible.builtin.set_fact:
    search_paths: '{{ search_paths | union([item.path]) }}'
  loop: '{{ result_relevant_root_dirs.files }}'
  tags:
  - DISA-STIG-RHEL-08-010460
  - high_severity
  - low_complexity
  - low_disruption
  - no_host_based_files
  - no_reboot_needed
  - restrict_strategy

- name: Remove Host-Based Authentication Files - Increment Search Paths List with
    Local Partitions Mount Points
  ansible.builtin.set_fact:
    search_paths: '{{ search_paths | union([item.mount]) }}'
  loop: '{{ ansible_mounts }}'
  when:
  - item.fstype not in excluded_fstypes
  - item.mount != '/'
  tags:
  - DISA-STIG-RHEL-08-010460
  - high_severity
  - low_complexity
  - low_disruption
  - no_host_based_files
  - no_reboot_needed
  - restrict_strategy

- name: Remove Host-Based Authentication Files - Increment Search Paths List with
    Local NFS File System Targets
  ansible.builtin.set_fact:
    search_paths: '{{ search_paths | union([item.device.split('':'')[1]]) }}'
  loop: '{{ ansible_mounts }}'
  when: item.device is search("localhost:")
  tags:
  - DISA-STIG-RHEL-08-010460
  - high_severity
  - low_complexity
  - low_disruption
  - no_host_based_files
  - no_reboot_needed
  - restrict_strategy

- name: Remove Host-Based Authentication Files - Define Rule Specific Facts
  ansible.builtin.set_fact:
    shosts_equiv_files:
    - /shosts.equiv
  tags:
  - DISA-STIG-RHEL-08-010460
  - high_severity
  - low_complexity
  - low_disruption
  - no_host_based_files
  - no_reboot_needed
  - restrict_strategy

- name: Remove Host-Based Authentication Files - Find All shosts.equiv Files in Local
    File Systems
  ansible.builtin.command:
    cmd: find {{ item }} -xdev -type f -name "shosts.equiv"
  loop: '{{ search_paths }}'
  changed_when: false
  register: result_found_shosts_equiv_files
  tags:
  - DISA-STIG-RHEL-08-010460
  - high_severity
  - low_complexity
  - low_disruption
  - no_host_based_files
  - no_reboot_needed
  - restrict_strategy

- name: Remove Host-Based Authentication Files - Create List of shosts.equiv Files
    Present in Local File Systems
  ansible.builtin.set_fact:
    shosts_equiv_files: '{{ shosts_equiv_files | union(item.stdout_lines) | list }}'
  loop: '{{ result_found_shosts_equiv_files.results }}'
  tags:
  - DISA-STIG-RHEL-08-010460
  - high_severity
  - low_complexity
  - low_disruption
  - no_host_based_files
  - no_reboot_needed
  - restrict_strategy

- name: Remove Host-Based Authentication Files - Ensure No shosts.equiv Files Are
    Present in the System
  ansible.builtin.file:
    path: '{{ item }}'
    state: absent
  loop: '{{ shosts_equiv_files }}'
  tags:
  - DISA-STIG-RHEL-08-010460
  - high_severity
  - low_complexity
  - low_disruption
  - no_host_based_files
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_host_based_files:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_host_based_files_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_rsh_trust_files" selected="false" severity="high">
              <xccdf-1.2:title>Remove Rsh Trust Files</xccdf-1.2:title>
              <xccdf-1.2:description>The files <html:code>/etc/hosts.equiv</html:code> and <html:code>~/.rhosts</html:code> (in
each user's home directory) list remote hosts and users that are trusted by the
local system when using the rshd daemon.
To remove these files, run the following command to delete them from any
location:
<html:pre>$ sudo rm /etc/hosts.equiv</html:pre>
<html:pre>$ rm ~/.rhosts</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>This action is only meaningful if <html:code>.rhosts</html:code> support is permitted
through PAM. Trust files are convenient, but when used in conjunction with
the R-services, they can allow unauthenticated access to a system.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_rsh-server"/>
              <xccdf-1.2:fix id="no_rsh_trust_files" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q rsh-server; then

find /root -xdev -type f -name ".rhosts" -exec rm -f {} \;
find /home -maxdepth 2 -xdev -type f -name ".rhosts" -exec rm -f {} \;
rm -f /etc/hosts.equiv

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="no_rsh_trust_files" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - no_rsh_trust_files
  - restrict_strategy

- name: Detect .rhosts files in users home directories
  ansible.builtin.find:
    paths:
    - /root
    - /home
    recurse: true
    patterns: .rhosts
    hidden: true
    file_type: file
  check_mode: false
  register: rhosts_locations
  when: '"rsh-server" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - no_rsh_trust_files
  - restrict_strategy

- name: Remove .rhosts files
  ansible.builtin.file:
    path: '{{ item }}'
    state: absent
  with_items: '{{ rhosts_locations.files | map(attribute=''path'') | list }}'
  when:
  - '"rsh-server" in ansible_facts.packages'
  - rhosts_locations is success
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - no_rsh_trust_files
  - restrict_strategy

- name: Remove /etc/hosts.equiv file
  ansible.builtin.file:
    path: /etc/hosts.equiv
    state: absent
  when: '"rsh-server" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - no_rsh_trust_files
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_rsh_trust_files:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_rsh_trust_files_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_no_user_host_based_files" selected="false" severity="high">
              <xccdf-1.2:title>Remove User Host-Based Authentication Files</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>~/.shosts</html:code> (in each user's home directory) files
list remote hosts and users that are trusted by the
local system. To remove these files, run the following command
to delete them from any location:
<html:pre>$ sudo find / -name '.shosts' -type f -delete</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010470</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230284r1017095_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The .shosts files are used to configure host-based authentication for
individual users or the system via SSH. Host-based authentication is not
sufficient for preventing unauthorized access to the system, as it does not
require interactive identification and authentication of a connection request,
or for the use of two-factor authentication.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="no_user_host_based_files" system="urn:xccdf:fix:script:sh">
# Identify local mounts
MOUNT_LIST=$(df --local | awk '{ print $6 }')

# Find file on each listed mount point
for cur_mount in ${MOUNT_LIST}
do
	find ${cur_mount} -xdev -type f -name ".shosts" -exec rm -f {} \;
done
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="no_user_host_based_files" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Remove User Host-Based Authentication Files - Define Excluded (Non-Local)
    File Systems and Paths
  ansible.builtin.set_fact:
    excluded_fstypes:
    - afs
    - autofs
    - ceph
    - cifs
    - smb3
    - smbfs
    - sshfs
    - ncpfs
    - ncp
    - nfs
    - nfs4
    - gfs
    - gfs2
    - glusterfs
    - gpfs
    - pvfs2
    - ocfs2
    - lustre
    - davfs
    - fuse.sshfs
    excluded_paths:
    - dev
    - proc
    - run
    - sys
    search_paths: []
  tags:
  - DISA-STIG-RHEL-08-010470
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - no_user_host_based_files
  - restrict_strategy

- name: Remove User Host-Based Authentication Files - Find Relevant Root Directories
    Ignoring Pre-Defined Excluded Paths
  ansible.builtin.find:
    paths: /
    file_type: directory
    excludes: '{{ excluded_paths }}'
    hidden: true
    recurse: false
  register: result_relevant_root_dirs
  tags:
  - DISA-STIG-RHEL-08-010470
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - no_user_host_based_files
  - restrict_strategy

- name: Remove User Host-Based Authentication Files - Include Relevant Root Directories
    in a List of Paths to be Searched
  ansible.builtin.set_fact:
    search_paths: '{{ search_paths | union([item.path]) }}'
  loop: '{{ result_relevant_root_dirs.files }}'
  tags:
  - DISA-STIG-RHEL-08-010470
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - no_user_host_based_files
  - restrict_strategy

- name: Remove User Host-Based Authentication Files - Increment Search Paths List
    with Local Partitions Mount Points
  ansible.builtin.set_fact:
    search_paths: '{{ search_paths | union([item.mount]) }}'
  loop: '{{ ansible_mounts }}'
  when:
  - item.fstype not in excluded_fstypes
  - item.mount != '/'
  tags:
  - DISA-STIG-RHEL-08-010470
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - no_user_host_based_files
  - restrict_strategy

- name: Remove User Host-Based Authentication Files - Increment Search Paths List
    with Local NFS File System Targets
  ansible.builtin.set_fact:
    search_paths: '{{ search_paths | union([item.device.split('':'')[1]]) }}'
  loop: '{{ ansible_mounts }}'
  when: item.device is search("localhost:")
  tags:
  - DISA-STIG-RHEL-08-010470
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - no_user_host_based_files
  - restrict_strategy

- name: Remove User Host-Based Authentication Files - Define Rule Specific Facts
  ansible.builtin.set_fact:
    user_shosts_files:
    - /.shosts
  tags:
  - DISA-STIG-RHEL-08-010470
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - no_user_host_based_files
  - restrict_strategy

- name: Remove User Host-Based Authentication Files - Find All .shosts Files in Local
    File Systems
  ansible.builtin.command:
    cmd: find {{ item }} -xdev -type f -name ".shosts"
  loop: '{{ search_paths }}'
  changed_when: false
  register: result_found_shosts_files
  tags:
  - DISA-STIG-RHEL-08-010470
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - no_user_host_based_files
  - restrict_strategy

- name: Remove User Host-Based Authentication Files - Create List of .shosts Files
    Present in Local File Systems
  ansible.builtin.set_fact:
    user_shosts_files: '{{ user_shosts_files | union(item.stdout_lines) | list }}'
  loop: '{{ result_found_shosts_files.results }}'
  tags:
  - DISA-STIG-RHEL-08-010470
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - no_user_host_based_files
  - restrict_strategy

- name: Remove User Host-Based Authentication Files - Ensure No .shosts Files Are
    Present in the System
  ansible.builtin.file:
    path: '{{ item }}'
    state: absent
  loop: '{{ user_shosts_files }}'
  tags:
  - DISA-STIG-RHEL-08-010470
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - no_user_host_based_files
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-no_user_host_based_files:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-no_user_host_based_files_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_talk">
            <xccdf-1.2:title>Chat/Messaging Services</xccdf-1.2:title>
            <xccdf-1.2:description>The talk software makes it possible for users to send and receive messages
across systems through a terminal session.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_talk-server_removed" selected="false" severity="medium">
              <xccdf-1.2:title>Uninstall talk-server Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>talk-server</html:code> package can be removed with the following command: <html:pre> $ sudo yum erase talk-server</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">The package is not available in AlmaLinux OS 8.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R62</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The talk software presents a security risk as it uses unencrypted protocols
for communications. Removing the <html:code>talk-server</html:code> package decreases the
risk of the accidental (or intentional) activation of talk services.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_talk-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove talk-server
# from the system, and may remove any packages
# that depend on talk-server. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "talk-server" ; then
yum remove -y "talk-server"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_talk-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall talk-server Package: Ensure talk-server is removed'
  ansible.builtin.package:
    name: talk-server
    state: absent
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_talk-server_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_talk-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_talk-server

class remove_talk-server {
  package { 'talk-server':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_talk-server_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=talk-server
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_talk-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove talk-server
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_talk-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove talk-server
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_talk-server_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_talk-server_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_talk_removed" selected="false" severity="medium">
              <xccdf-1.2:title>Uninstall talk Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>talk</html:code> package contains the client program for the
Internet talk protocol, which allows the user to chat with other users on
different systems. Talk is a communication program which copies lines from one
terminal to the terminal of another user.
The <html:code>talk</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase talk</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">The package is not available in AlmaLinux OS 8.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R62</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The talk software presents a security risk as it uses unencrypted protocols
for communications. Removing the <html:code>talk</html:code> package decreases the
risk of the accidental (or intentional) activation of talk client program.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_talk_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove talk
# from the system, and may remove any packages
# that depend on talk. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "talk" ; then
yum remove -y "talk"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_talk_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall talk Package: Ensure talk is removed'
  ansible.builtin.package:
    name: talk
    state: absent
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_talk_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_talk_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_talk

class remove_talk {
  package { 'talk':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_talk_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=talk
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_talk_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove talk
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_talk_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove talk
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_talk_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_talk_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_telnet">
            <xccdf-1.2:title>Telnet</xccdf-1.2:title>
            <xccdf-1.2:description>The telnet protocol does not provide confidentiality or integrity
for information transmitted on the network. This includes authentication
information such as passwords. Organizations which use telnet should be
actively working to migrate to a more secure protocol.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_telnet-server_removed" selected="false" severity="high">
              <xccdf-1.2:title>Uninstall telnet-server Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>telnet-server</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase telnet-server</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-2.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000095-GPOS-00049</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R62</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040000</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230487r1017271_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>It is detrimental for operating systems to provide, or install by default,
functionality exceeding requirements or mission objectives. These
unnecessary capabilities are often overlooked and therefore may remain
insecure. They increase the risk to the platform by providing additional
attack vectors.
<html:br/>
The telnet service provides an unencrypted remote access service which does
not provide for the confidentiality and integrity of user passwords or the
remote session. If a privileged user were to login using this service, the
privileged user password could be compromised.
<html:br/>
Removing the <html:code>telnet-server</html:code> package decreases the risk of the
telnet service's accidental (or intentional) activation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnet-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove telnet-server
# from the system, and may remove any packages
# that depend on telnet-server. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "telnet-server" ; then
yum remove -y "telnet-server"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnet-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall telnet-server Package: Ensure telnet-server is removed'
  ansible.builtin.package:
    name: telnet-server
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040000
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSS-Req-2.2.2
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_telnet-server_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnet-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_telnet-server

class remove_telnet-server {
  package { 'telnet-server':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnet-server_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=telnet-server
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnet-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove telnet-server
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnet-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove telnet-server
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_telnet-server_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_telnet-server_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_telnet_removed" selected="false" severity="low">
              <xccdf-1.2:title>Remove telnet Clients</xccdf-1.2:title>
              <xccdf-1.2:description>The telnet client allows users to start connections to other systems via
the telnet protocol.</xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R62</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The <html:code>telnet</html:code> protocol is insecure and unencrypted. The use
of an unencrypted transmission medium could allow an unauthorized user
to steal credentials. The <html:code>ssh</html:code> package provides an
encrypted session and stronger security and is included in AlmaLinux OS 8.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnet_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove telnet
# from the system, and may remove any packages
# that depend on telnet. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "telnet" ; then
yum remove -y "telnet"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnet_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Remove telnet Clients: Ensure telnet is removed'
  ansible.builtin.package:
    name: telnet
    state: absent
  tags:
  - NIST-800-171-3.1.13
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_telnet_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnet_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_telnet

class remove_telnet {
  package { 'telnet':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnet_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=telnet
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnet_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove telnet
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_telnet_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove telnet
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_telnet_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_telnet_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_telnet_disabled" selected="false" severity="high">
              <xccdf-1.2:title>Disable telnet Service</xccdf-1.2:title>
              <xccdf-1.2:description>Make sure that the activation of the <html:code>telnet</html:code> service on system boot is disabled.

The <html:code>telnet</html:code> socket can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now telnet.socket</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">If the system relies on <html:code>xinetd</html:code> to manage telnet sessions, ensure the telnet service
is disabled by the following line: <html:code>disable = yes</html:code>. Note that the xinetd file for
telnet is not created automatically, therefore it might have different names.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The telnet protocol uses unencrypted network communication, which means that data from the
login session, including passwords and all other information transmitted during the session,
can be stolen by eavesdroppers on the network. The telnet protocol is also subject to
man-in-the-middle attacks.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_telnet-server_and_system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_telnet_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q telnet-server &amp;&amp; rpm --quiet -q kernel ) ); then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'telnet.service'
fi
"$SYSTEMCTL_EXEC" disable 'telnet.service'
"$SYSTEMCTL_EXEC" mask 'telnet.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files telnet.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'telnet.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'telnet.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'telnet.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_telnet_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.13
  - NIST-800-171-3.4.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-5(1)(c)
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_telnet_disabled

- name: Disable telnet Service - Disable service telnet
  block:

  - name: Disable telnet Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable telnet Service - Ensure telnet.service is Masked
    ansible.builtin.systemd:
      name: telnet.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("telnet.service", multiline=True)

  - name: Unit Socket Exists - telnet.socket
    ansible.builtin.command: systemctl -q list-unit-files telnet.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable telnet Service - Disable Socket telnet
    ansible.builtin.systemd:
      name: telnet.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("telnet.socket", multiline=True)
  tags:
  - NIST-800-171-3.1.13
  - NIST-800-171-3.4.7
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-5(1)(c)
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_telnet_disabled
  - special_service_block
  when: ( "telnet-server" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_telnet_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_telnet

class disable_telnet {
  service {'telnet':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_telnet_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: telnet.service
        enabled: false
        mask: true
      - name: telnet.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_telnet_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["telnet"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_telnet_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable telnet
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_telnet_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_telnet_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_tftp">
            <xccdf-1.2:title>TFTP Server</xccdf-1.2:title>
            <xccdf-1.2:description>TFTP is a lightweight version of the FTP protocol which has
traditionally been used to configure networking equipment. However,
TFTP provides little security, and modern versions of networking
operating systems frequently support configuration via SSH or other
more secure protocols. A TFTP server should be run only if no more
secure method of supporting existing equipment can be
found.</xccdf-1.2:description>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_tftpd_secure_directory" interactive="true" type="string">
              <xccdf-1.2:title>TFTP server secure directory</xccdf-1.2:title>
              <xccdf-1.2:description>Specify the directory which is used by TFTP server as a root directory when running in secure mode.</xccdf-1.2:description>
              <xccdf-1.2:value>/var/lib/tftpboot</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_tftp-server_removed" selected="false" severity="high">
              <xccdf-1.2:title>Uninstall tftp-server Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>tftp-server</html:code> package can be removed with the following command: <html:pre> $ sudo yum erase tftp-server</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R62</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.17</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040190</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230533r1017295_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Removing the <html:code>tftp-server</html:code> package decreases the risk of the accidental
(or intentional) activation of tftp services.
<html:br/><html:br/>
If TFTP is required for operational support (such as transmission of router
configurations), its use must be documented with the Information Systems
Security Manager (ISSM), restricted to only authorized personnel, and have
access control rules established.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tftp-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove tftp-server
# from the system, and may remove any packages
# that depend on tftp-server. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "tftp-server" ; then
yum remove -y "tftp-server"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tftp-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall tftp-server Package: Ensure tftp-server is removed'
  ansible.builtin.package:
    name: tftp-server
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040190
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_tftp-server_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tftp-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_tftp-server

class remove_tftp-server {
  package { 'tftp-server':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tftp-server_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=tftp-server
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tftp-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove tftp-server
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tftp-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove tftp-server
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_tftp-server_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_tftp-server_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_tftp_removed" selected="false" severity="low">
              <xccdf-1.2:title>Remove tftp Daemon</xccdf-1.2:title>
              <xccdf-1.2:description>Trivial File Transfer Protocol (TFTP) is a simple file transfer protocol,
typically used to automatically transfer configuration or boot files between systems.
TFTP does not support authentication and can be easily hacked. The package
<html:code>tftp</html:code> is a client program that allows for connections to a <html:code>tftp</html:code> server.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000074-GPOS-00042</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R62</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.2.5</xccdf-1.2:reference>
              <xccdf-1.2:rationale>It is recommended that TFTP be removed, unless there is a specific need
for TFTP (such as a boot server). In that case, use extreme caution when configuring
the services.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tftp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove tftp
# from the system, and may remove any packages
# that depend on tftp. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "tftp" ; then
yum remove -y "tftp"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tftp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Remove tftp Daemon: Ensure tftp is removed'
  ansible.builtin.package:
    name: tftp
    state: absent
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_tftp_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tftp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_tftp

class remove_tftp {
  package { 'tftp':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tftp_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=tftp
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tftp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove tftp
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_tftp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove tftp
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_tftp_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_tftp_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_tftp_disabled" selected="false" severity="high">
              <xccdf-1.2:title>Disable tftp Service</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>tftp</html:code> service should be disabled.

The <html:code>tftp</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now tftp.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Disabling the <html:code>tftp</html:code> service ensures the system is not acting
as a TFTP server, which does not provide encryption or authentication.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_tftp_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'tftp.service'
fi
"$SYSTEMCTL_EXEC" disable 'tftp.service'
"$SYSTEMCTL_EXEC" mask 'tftp.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files tftp.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'tftp.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'tftp.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'tftp.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_tftp_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_tftp_disabled

- name: Disable tftp Service - Disable service tftp
  block:

  - name: Disable tftp Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable tftp Service - Ensure tftp.service is Masked
    ansible.builtin.systemd:
      name: tftp.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("tftp.service", multiline=True)

  - name: Unit Socket Exists - tftp.socket
    ansible.builtin.command: systemctl -q list-unit-files tftp.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable tftp Service - Disable Socket tftp
    ansible.builtin.systemd:
      name: tftp.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("tftp.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_tftp_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_tftp_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_tftp

class disable_tftp {
  service {'tftp':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_tftp_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: tftp.service
        enabled: false
        mask: true
      - name: tftp.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_tftp_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["tftp"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_tftp_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable tftp
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_tftp_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_tftp_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_tftp_uses_secure_mode_systemd" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure tftp systemd Service Uses Secure Mode</xccdf-1.2:title>
              <xccdf-1.2:description>If running the Trivial File Transfer Protocol (TFTP) service is necessary,
it should be configured to change its root directory at startup. To do so,
find the path for the <html:code>tftp</html:code> systemd service:
<html:pre>$ sudo systemctl show tftp | grep ExecStart=
ExecStart={ path=/usr/sbin/in.tftpd ; argv[]=/usr/sbin/in.tftpd -s /var/lib/tftpboot ; ignore_errors=no ; start_time=[n/a] ; stop_time=[n/a] ; pid=0 ; code=(null) ; status=0/0 }e
</html:pre>

and ensure the <html:code>ExecStart</html:code> line on that file includes the <html:code>-s</html:code> option with a subdirectory:
<html:pre>ExecStart=/usr/sbin/in.tftpd -s <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tftpd_secure_directory" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5 (1) (c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000074-GPOS-00042</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040350</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230557r1088855_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Using the <html:code>-s</html:code> option causes the TFTP service to only serve files from the
given directory. Serving files from an intentionally-specified directory
reduces the risk of sharing files which should remain private.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_tftp-server"/>
              <xccdf-1.2:fix id="tftp_uses_secure_mode_systemd" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q tftp-server; then

var_tftpd_secure_directory='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tftpd_secure_directory" use="legacy"/>'


DROPIN_DIR="/etc/systemd/system/tftp.service.d"
DROPIN_FILE="$DROPIN_DIR/10-ssg-hardening.conf"
TFTP_SERVICE_FILE="/usr/lib/systemd/system/tftp.service"
REGEX_TFTP_SERVICE_FILE="^\s*ExecStart\s*=\s*/\S+\s+-s\s+(/\S+).*$"
REGEX_DROP_IN="(?s)\s*ExecStart=\s*.*(\s*ExecStart=\s*/\S+\s+-s\s+/\S+.*)"

# Remove bad configuration in drop-ins
if [ -d "$DROPIN_DIR" ]; then
    for override in "$DROPIN_DIR"/*.conf; do
        if [ -f "$override" ] &amp;&amp; ! grep -qPzo "$REGEX_DROP_IN" "$override"; then
            sed -i '/^[[:space:]]*ExecStart=/ s/^/#/' "$override"
        fi
    done
fi

if [ -d "$DROPIN_DIR" ] &amp;&amp; grep -qPzor "$REGEX_DROP_IN" "$DROPIN_DIR"; then
    exit 0
elif [ ! -d "$DROPIN_DIR" ] &amp;&amp; grep -qE "$REGEX_TFTP_SERVICE_FILE" "$TFTP_SERVICE_FILE"; then
    exit 0
else
    mkdir -p "$DROPIN_DIR"

    cat &gt; "$DROPIN_FILE" &lt;&lt; EOF
[Service]
# clear any existing ExecStart in the original unit
ExecStart=
ExecStart=/usr/sbin/in.tftpd -s $var_tftpd_secure_directory
EOF
    systemctl daemon-reload
    systemctl restart tftp.service
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="medium" disruption="low" id="tftp_uses_secure_mode_systemd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040350
  - NIST-800-53-IA-5 (1) (c)
  - configure_strategy
  - low_disruption
  - medium_complexity
  - medium_severity
  - no_reboot_needed
  - tftp_uses_secure_mode_systemd
- name: XCCDF Value var_tftpd_secure_directory # promote to variable
  set_fact:
    var_tftpd_secure_directory: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tftpd_secure_directory" use="legacy"/>
  tags:
    - always

- name: Ensure tftp systemd Service Uses Secure Mode - Find valid drop-ins
  ansible.builtin.find:
    paths: /etc/systemd/system/tftp.service.d
    patterns: '*.conf'
    contains: ^\s*ExecStart\s*=\s*/\S+\s+-s\s+/\S+$
  register: valid_dropins
  failed_when: false
  when: '"tftp-server" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040350
  - NIST-800-53-IA-5 (1) (c)
  - configure_strategy
  - low_disruption
  - medium_complexity
  - medium_severity
  - no_reboot_needed
  - tftp_uses_secure_mode_systemd

- name: Ensure tftp systemd Service Uses Secure Mode - Find all drop-in files
  ansible.builtin.find:
    paths: /etc/systemd/system/tftp.service.d
    patterns: '*.conf'
    contains: ^\s*ExecStart\s*=.*$
    file_type: file
  register: all_dropins
  failed_when: false
  when: '"tftp-server" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040350
  - NIST-800-53-IA-5 (1) (c)
  - configure_strategy
  - low_disruption
  - medium_complexity
  - medium_severity
  - no_reboot_needed
  - tftp_uses_secure_mode_systemd

- name: Ensure tftp systemd Service Uses Secure Mode - Get invalid drop-ins
  ansible.builtin.set_fact:
    invalid_dropins: '{{ all_dropins.files | rejectattr(''path'', ''in'', valid_dropins.files
      | map(attribute=''path'') | list) | map(attribute=''path'') | list }}'
  when: '"tftp-server" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040350
  - NIST-800-53-IA-5 (1) (c)
  - configure_strategy
  - low_disruption
  - medium_complexity
  - medium_severity
  - no_reboot_needed
  - tftp_uses_secure_mode_systemd

- name: Ensure tftp systemd Service Uses Secure Mode - Comment all ExecStart in invalid
    drop-ins
  ansible.builtin.lineinfile:
    path: '{{ item }}'
    regexp: ^\s*ExecStart\s*=.*
    state: absent
  loop: '{{ invalid_dropins }}'
  when:
  - '"tftp-server" in ansible_facts.packages'
  - invalid_dropins | length &gt; 0
  tags:
  - DISA-STIG-RHEL-08-040350
  - NIST-800-53-IA-5 (1) (c)
  - configure_strategy
  - low_disruption
  - medium_complexity
  - medium_severity
  - no_reboot_needed
  - tftp_uses_secure_mode_systemd

- name: Ensure tftp systemd Service Uses Secure Mode - Check if a valid drop-in exists
  ansible.builtin.set_fact:
    tftp_config_valid: '{{ (valid_dropins.matched | default(0)) &gt; 0 }}'
  when: '"tftp-server" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040350
  - NIST-800-53-IA-5 (1) (c)
  - configure_strategy
  - low_disruption
  - medium_complexity
  - medium_severity
  - no_reboot_needed
  - tftp_uses_secure_mode_systemd

- name: Ensure tftp systemd Service Uses Secure Mode - Check if tftp.service contains
    valid ExecStart
  ansible.builtin.find:
    paths: /usr/lib/systemd/system
    patterns: tftp.service
    contains: ^\s*ExecStart\s*=\s*/\S+\s+-s\s+/\S+
  register: valid_tftp_service
  when:
  - '"tftp-server" in ansible_facts.packages'
  - not tftp_config_valid
  tags:
  - DISA-STIG-RHEL-08-040350
  - NIST-800-53-IA-5 (1) (c)
  - configure_strategy
  - low_disruption
  - medium_complexity
  - medium_severity
  - no_reboot_needed
  - tftp_uses_secure_mode_systemd

- name: Ensure tftp systemd Service Uses Secure Mode - Check if a valid tftp.service
    exists
  ansible.builtin.set_fact:
    original_valid: '{{ (valid_tftp_service.matched | default(0)) &gt; 0 }}'
  when:
  - '"tftp-server" in ansible_facts.packages'
  - not tftp_config_valid
  tags:
  - DISA-STIG-RHEL-08-040350
  - NIST-800-53-IA-5 (1) (c)
  - configure_strategy
  - low_disruption
  - medium_complexity
  - medium_severity
  - no_reboot_needed
  - tftp_uses_secure_mode_systemd

- name: Ensure tftp systemd Service Uses Secure Mode - Recalculate global config validity
  ansible.builtin.set_fact:
    tftp_config_valid: '{{ tftp_config_valid or original_valid | default(false) }}'
  when: '"tftp-server" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040350
  - NIST-800-53-IA-5 (1) (c)
  - configure_strategy
  - low_disruption
  - medium_complexity
  - medium_severity
  - no_reboot_needed
  - tftp_uses_secure_mode_systemd

- name: Ensure tftp systemd Service Uses Secure Mode - Remediate only if necessary
  block:

  - name: Ensure drop-in directory exists
    ansible.builtin.file:
      path: /etc/systemd/system/tftp.service.d
      state: directory

  - name: Deploy 10-ssg-hardening.conf drop-in
    ansible.builtin.copy:
      dest: /etc/systemd/system/tftp.service.d/10-ssg-hardening.conf
      content: |-
        [Service]
        # clear any existing ExecStart in the original unit
        ExecStart=
        ExecStart=/usr/sbin/in.tftpd -s {{ var_tftpd_secure_directory }}

  - name: Reload systemd and restart tftp service
    ansible.builtin.systemd:
      daemon_reload: true
      name: tftp
      state: restarted
      enabled: true
  when:
  - '"tftp-server" in ansible_facts.packages'
  - not tftp_config_valid
  tags:
  - DISA-STIG-RHEL-08-040350
  - NIST-800-53-IA-5 (1) (c)
  - configure_strategy
  - low_disruption
  - medium_complexity
  - medium_severity
  - no_reboot_needed
  - tftp_uses_secure_mode_systemd
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-tftp_uses_secure_mode_systemd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-tftp_uses_secure_mode_systemd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_tftpd_uses_secure_mode" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure tftp Daemon Uses Secure Mode</xccdf-1.2:title>
              <xccdf-1.2:description>If running the Trivial File Transfer Protocol (TFTP) service is necessary,
it should be configured to change its root directory at startup. To do so,
ensure <html:code>/etc/xinetd.d/tftp</html:code> includes <html:code>-s</html:code> as a command line argument,
as shown in the following example:
<html:pre>server_args = -s <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tftpd_secure_directory" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Using the <html:code>-s</html:code> option causes the TFTP service to only serve files from the
given directory. Serving files from an intentionally-specified directory
reduces the risk of sharing files which should remain private.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_tftp-server"/>
              <xccdf-1.2:fix id="tftpd_uses_secure_mode" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q tftp-server; then

var_tftpd_secure_directory='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tftpd_secure_directory" use="legacy"/>'


if grep -q 'server_args' /etc/xinetd.d/tftp; then
    sed -i -E "s;^([[:blank:]]*server_args[[:blank:]]+=[[:blank:]]+.*?)(-s[[:blank:]]+[[:graph:]]+)*(.*)$;\1 -s $var_tftpd_secure_directory \3;" /etc/xinetd.d/tftp
else
    echo "server_args = -s $var_tftpd_secure_directory" &gt;&gt; /etc/xinetd.d/tftp
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="tftpd_uses_secure_mode" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-7(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - tftpd_uses_secure_mode
- name: XCCDF Value var_tftpd_secure_directory # promote to variable
  set_fact:
    var_tftpd_secure_directory: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_tftpd_secure_directory" use="legacy"/>
  tags:
    - always

- name: Find out if the file exists and contains the line configuring server arguments
  ansible.builtin.find:
    path: /etc/xinetd.d
    patterns: tftp
    contains: ^[\s]+server_args.*$
  register: tftpd_secure_config_line
  when: '"tftp-server" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-7(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - tftpd_uses_secure_mode

- name: Ensure that TFTP server is configured to start with secure directory
  ansible.builtin.lineinfile:
    path: /etc/xinetd.d/tftp
    regexp: ^[\s]*(server_args[\s]+=[\s]+.*?)(-s[\s]+[/\.\w]+)*(.*)$
    line: \1 -s {{ var_tftpd_secure_directory }} \3
    state: present
    backrefs: true
  when:
  - '"tftp-server" in ansible_facts.packages'
  - tftpd_secure_config_line is defined and tftpd_secure_config_line.matched &gt; 0
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-7(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - tftpd_uses_secure_mode

- name: Insert correct config line to start TFTP server with secure directory
  ansible.builtin.lineinfile:
    path: /etc/xinetd.d/tftp
    line: server_args = -s {{ var_tftpd_secure_directory }}
    state: present
    create: true
  when:
  - '"tftp-server" in ansible_facts.packages'
  - tftpd_secure_config_line is defined and tftpd_secure_config_line.matched == 0
  tags:
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-7(a)
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - tftpd_uses_secure_mode
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_tftpd_secure_directory:var:1" value-id="xccdf_org.ssgproject.content_value_var_tftpd_secure_directory"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-tftpd_uses_secure_mode:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-tftpd_uses_secure_mode_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_printing">
          <xccdf-1.2:title>Print Support</xccdf-1.2:title>
          <xccdf-1.2:description>The Common Unix Printing System (CUPS) service provides both local
and network printing support. A system running the CUPS service can accept
print jobs from other systems, process them, and send them to the appropriate
printer. It also provides an interface for remote administration through a web
browser. The CUPS service is installed and activated by default. The project
homepage and more detailed documentation are available at

    <html:a href="http://www.cups.org">http://www.cups.org</html:a>.
<html:br/><html:br/></xccdf-1.2:description>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_cups_removed" selected="false" severity="unknown">
            <xccdf-1.2:title>Uninstall CUPS Package</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>cups</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase cups</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If the system does not need to print jobs or accept print jobs from other systems, it is
recommended that CUPS be removed to reduce the potential attack surface.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_cups_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove cups
# from the system, and may remove any packages
# that depend on cups. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "cups" ; then
yum remove -y "cups"
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_cups_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall CUPS Package: Ensure cups is removed'
  ansible.builtin.package:
    name: cups
    state: absent
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_cups_removed
  - unknown_severity
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_cups_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_cups

class remove_cups {
  package { 'cups':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_cups_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=cups
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_cups_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove cups
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_cups_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove cups
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_cups_removed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_cups_removed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_cups_disabled" selected="false" severity="unknown">
            <xccdf-1.2:title>Disable the CUPS Service</xccdf-1.2:title>
            <xccdf-1.2:description>
The <html:code>cups</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now cups.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.11</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Turn off unneeded services to reduce attack surface.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_cups_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'cups.service'
fi
"$SYSTEMCTL_EXEC" disable 'cups.service'
"$SYSTEMCTL_EXEC" mask 'cups.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files cups.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'cups.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'cups.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'cups.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_cups_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_cups_disabled
  - unknown_severity

- name: Disable the CUPS Service - Disable service cups
  block:

  - name: Disable the CUPS Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable the CUPS Service - Ensure cups.service is Masked
    ansible.builtin.systemd:
      name: cups.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("cups.service", multiline=True)

  - name: Unit Socket Exists - cups.socket
    ansible.builtin.command: systemctl -q list-unit-files cups.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable the CUPS Service - Disable Socket cups
    ansible.builtin.systemd:
      name: cups.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("cups.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_cups_disabled
  - special_service_block
  - unknown_severity
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_cups_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_cups

class disable_cups {
  service {'cups':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_cups_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: cups.service
        enabled: false
        mask: true
      - name: cups.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_cups_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["cups"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_cups_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable cups
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_cups_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_cups_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_configure_printing">
            <xccdf-1.2:title>Configure the CUPS Service if Necessary</xccdf-1.2:title>
            <xccdf-1.2:description>CUPS provides the ability to easily share local printers with
other systems over the network. It does this by allowing systems to share
lists of available printers. Additionally, each system that runs the CUPS
service can potentially act as a print server. Whenever possible, the printer
sharing and print server capabilities of CUPS should be limited or disabled.
The following recommendations should demonstrate how to do just that.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_cups_disable_browsing" selected="false" severity="unknown">
              <xccdf-1.2:title>Disable Printer Browsing Entirely if Possible</xccdf-1.2:title>
              <xccdf-1.2:description>By default, CUPS listens on the network for printer list
broadcasts on UDP port 631. This functionality is called printer browsing.
To disable printer browsing entirely, edit the CUPS configuration
file, located at <html:code>/etc/cups/cupsd.conf</html:code>, to include the following:
<html:pre>Browsing Off
BrowseAllow none</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The CUPS print service can be configured to broadcast a list of
available printers to the network. Other systems on the network, also running
the CUPS print service, can be configured to listen to these broadcasts and add
and configure these printers for immediate use. By disabling this browsing
capability, the system will no longer generate or receive such broadcasts.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-cups_disable_browsing:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-cups_disable_browsing_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_cups_disable_printserver" selected="false" severity="unknown">
              <xccdf-1.2:title>Disable Print Server Capabilities</xccdf-1.2:title>
              <xccdf-1.2:description>To prevent remote users from potentially connecting to and using
locally configured printers, disable the CUPS print server sharing
capabilities. To do so, limit how the server will listen for print jobs by
removing the more generic port directive from /etc/cups/cupsd.conf:
<html:pre>Port 631</html:pre>
and replacing it with the <html:code>Listen</html:code> directive:
<html:pre>Listen localhost:631</html:pre>
This will prevent remote users from printing to locally configured printers
while still allowing local users on the system to print normally.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>By default, locally configured printers will not be shared over the
network, but if this functionality has somehow been enabled, these
recommendations will disable it again. Be sure to disable outgoing printer list
broadcasts, or remote users will still be able to see the locally configured
printers, even if they cannot actually print to them. To limit print serving to
a particular set of users, use the Policy directive.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-cups_disable_printserver:def:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_proxy">
          <xccdf-1.2:title>Proxy Server</xccdf-1.2:title>
          <xccdf-1.2:description>A proxy server is a very desirable target for a
potential adversary because much (or all) sensitive data for a
given infrastructure may flow through it. Therefore, if one is
required, the system acting as a proxy server should be dedicated
to that purpose alone and be stored in a physically secure
location. The system's default proxy server software is Squid, and
provided in an RPM package of the same name.</xccdf-1.2:description>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_squid">
            <xccdf-1.2:title>Disable Squid if Possible</xccdf-1.2:title>
            <xccdf-1.2:description>If Squid was installed and activated, but the system
does not need to act as a proxy server, then it should be disabled
and removed.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_squid_removed" selected="false" severity="unknown">
              <xccdf-1.2:title>Uninstall squid Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>squid</html:code> package can be removed with the following command: <html:pre> $ sudo yum erase squid</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.18</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If there is no need to make the proxy server software available,
removing it provides a safeguard against its activation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_squid_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove squid
# from the system, and may remove any packages
# that depend on squid. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "squid" ; then
yum remove -y "squid"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_squid_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall squid Package: Ensure squid is removed'
  ansible.builtin.package:
    name: squid
    state: absent
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_squid_removed
  - unknown_severity
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_squid_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_squid

class remove_squid {
  package { 'squid':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_squid_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=squid
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_squid_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove squid
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_squid_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove squid
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_squid_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_squid_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_squid_disabled" selected="false" severity="unknown">
              <xccdf-1.2:title>Disable Squid</xccdf-1.2:title>
              <xccdf-1.2:description>
The <html:code>squid</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now squid.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Running proxy server software provides a network-based avenue
of attack, and should be removed if not needed.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_squid_and_system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_squid_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q squid &amp;&amp; rpm --quiet -q kernel ) ); then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'squid.service'
fi
"$SYSTEMCTL_EXEC" disable 'squid.service'
"$SYSTEMCTL_EXEC" mask 'squid.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files squid.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'squid.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'squid.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'squid.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_squid_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_squid_disabled
  - unknown_severity

- name: Disable Squid - Disable service squid
  block:

  - name: Disable Squid - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Squid - Ensure squid.service is Masked
    ansible.builtin.systemd:
      name: squid.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("squid.service", multiline=True)

  - name: Unit Socket Exists - squid.socket
    ansible.builtin.command: systemctl -q list-unit-files squid.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Squid - Disable Socket squid
    ansible.builtin.systemd:
      name: squid.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("squid.socket", multiline=True)
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_squid_disabled
  - special_service_block
  - unknown_severity
  when: ( "squid" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_squid_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_squid

class disable_squid {
  service {'squid':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_squid_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: squid.service
        enabled: false
        mask: true
      - name: squid.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_squid_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["squid"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_squid_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable squid
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_squid_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_squid_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_radius">
          <xccdf-1.2:title>Remote Authentication Dial-In User Service (RADIUS)</xccdf-1.2:title>
          <xccdf-1.2:description>Remote Authentication Dial-In User Service (RADIUS) is a networking
protocol, operating on port 1812 that provides centralized
Authentication, Authorization, and Accounting (AAA or Triple A)
management for users who connect and use a network service. </xccdf-1.2:description>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_freeradius_removed" selected="false" severity="low">
            <xccdf-1.2:title>Remove the FreeRadius Server Package</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>freeradius</html:code> package should be removed if not in use.
Is this system a RADIUS server? If not, remove the package.
The <html:code>freeradius</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase freeradius</html:pre>
The freeradius RPM is not installed by default on a AlmaLinux OS 8
system. It is needed only by the RADIUS servers, not by the
clients which use RADIUS for authentication. If the system is not
intended for use as a RADIUS Server it should be removed.</xccdf-1.2:description>
            <xccdf-1.2:rationale>Unnecessary packages should not be installed to decrease the attack
surface of the system.  While this software is clearly essential on a
RADIUS server, it is not necessary on typical desktop or workstation systems.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_freeradius_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove freeradius
# from the system, and may remove any packages
# that depend on freeradius. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "freeradius" ; then
yum remove -y "freeradius"
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_freeradius_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Remove the FreeRadius Server Package: Ensure freeradius is removed'
  ansible.builtin.package:
    name: freeradius
    state: absent
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_freeradius_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_freeradius_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_freeradius

class remove_freeradius {
  package { 'freeradius':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_freeradius_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=freeradius
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_freeradius_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove freeradius
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_freeradius_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove freeradius
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_freeradius_removed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_freeradius_removed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_rng">
          <xccdf-1.2:title>Hardware RNG Entropy Gatherer Daemon</xccdf-1.2:title>
          <xccdf-1.2:description>The rngd feeds random data from hardware device to kernel random device.</xccdf-1.2:description>
          <xccdf-1.2:platform idref="#system_with_kernel"/>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_rngd_enabled" selected="false" severity="low">
            <xccdf-1.2:title>Enable the Hardware RNG Entropy Gatherer Service</xccdf-1.2:title>
            <xccdf-1.2:description>The Hardware RNG Entropy Gatherer service should be enabled.

The <html:code>rngd</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable rngd.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">For RHEL versions 8.4 and above running with kernel FIPS mode enabled this rule is not applicable.
The in-kernel deterministic random bit generator (DRBG) is used in FIPS mode instead.
Consequently, the rngd service can't be started in FIPS mode.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010471</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230285r1017096_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The <html:code>rngd</html:code> service
feeds random data from hardware device to kernel random device.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#os_linux_rhel_le_or_eq_8_3_or_os_linux_rhel_gt_or_eq_8_4_and_not_runtime_kernel_fips_enabled"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rngd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { ( ( grep -qP "^ID=[\"']?rhel[\"']?$" "/etc/os-release" &amp;&amp; { real="$(grep -P "^VERSION_ID=[\"']?[\w.]+[\"']?$" /etc/os-release | sed "s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")"; expected="8.3"; printf "%s\n%s" "$real" "$expected" | sort -VC; } || ( grep -qP "^ID=[\"']?rhel[\"']?$" "/etc/os-release" &amp;&amp; { real="$(grep -P "^VERSION_ID=[\"']?[\w.]+[\"']?$" /etc/os-release | sed "s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")"; expected="8.4"; printf "%s\n%s" "$expected" "$real" | sort -VC; } &amp;&amp; ! ( [ "$(sysctl -a | grep -c 'fips_enabled.*1')" -eq 1 ] ) ) ) ); }; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'rngd.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'rngd.service'
fi
"$SYSTEMCTL_EXEC" enable 'rngd.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rngd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010471
  - enable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_rngd_enabled

- name: Enable the Hardware RNG Entropy Gatherer Service - Enable service rngd
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable the Hardware RNG Entropy Gatherer Service - Enable Service rngd
    ansible.builtin.systemd:
      name: rngd
      enabled: true
      state: started
      masked: false
    when:
    - '"rng-tools" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010471
  - enable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_rngd_enabled
  - special_service_block
  when:
  - '"kernel" in ansible_facts.packages'
  - ( ansible_distribution == 'RedHat' and ansible_distribution_version is version('8.3',
    '&lt;=') or ( ansible_distribution == 'RedHat' and ansible_distribution_version is
    version('8.4', '&gt;=') ) )
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rngd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_rngd

class enable_rngd {
  service {'rngd':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_rngd_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["rngd"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_rngd_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable rngd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_rngd_enabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_rngd_enabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_routing">
          <xccdf-1.2:title>Network Routing</xccdf-1.2:title>
          <xccdf-1.2:description>A router is a very desirable target for a
potential adversary because they fulfill a variety of 
infrastructure networking roles such as access to network segments,
gateways to other networks, filtering, etc. Therefore, if one is
required, the system acting as a router should be dedicated
to that purpose alone and be stored in a physically secure
location. The system's default routing software is Quagga, and
provided in an RPM package of the same name.</xccdf-1.2:description>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_quagga">
            <xccdf-1.2:title>Disable Quagga if Possible</xccdf-1.2:title>
            <xccdf-1.2:description>If Quagga was installed and activated, but the system
does not need to act as a router, then it should be disabled
and removed.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_quagga_removed" selected="false" severity="low">
              <xccdf-1.2:title>Uninstall quagga Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>quagga</html:code> package can be removed with the following command: <html:pre> $ sudo yum erase quagga</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Routing software is typically used on routers to exchange network topology information
with other routers. If routing software is used when not required, system network
information may be unnecessarily transmitted across the network.
<html:br/>
If there is no need to make the router software available,
removing it provides a safeguard against its activation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_quagga_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove quagga
# from the system, and may remove any packages
# that depend on quagga. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "quagga" ; then
yum remove -y "quagga"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_quagga_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall quagga Package: Ensure quagga is removed'
  ansible.builtin.package:
    name: quagga
    state: absent
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - package_quagga_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_quagga_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_quagga

class remove_quagga {
  package { 'quagga':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_quagga_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=quagga
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_quagga_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove quagga
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_quagga_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove quagga
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_quagga_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_quagga_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_zebra_disabled" selected="false" severity="medium">
              <xccdf-1.2:title>Disable Quagga Service</xccdf-1.2:title>
              <xccdf-1.2:description>
The <html:code>zebra</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now zebra.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Routing protocol daemons are typically used on routers to exchange network
topology information with other routers. If routing daemons are used when not
required, system network information may be unnecessarily transmitted across
the network.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_zebra_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'zebra.service'
fi
"$SYSTEMCTL_EXEC" disable 'zebra.service'
"$SYSTEMCTL_EXEC" mask 'zebra.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files zebra.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'zebra.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'zebra.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'zebra.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_zebra_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_zebra_disabled

- name: Disable Quagga Service - Disable service zebra
  block:

  - name: Disable Quagga Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Quagga Service - Ensure zebra.service is Masked
    ansible.builtin.systemd:
      name: zebra.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("zebra.service", multiline=True)

  - name: Unit Socket Exists - zebra.socket
    ansible.builtin.command: systemctl -q list-unit-files zebra.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Quagga Service - Disable Socket zebra
    ansible.builtin.systemd:
      name: zebra.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("zebra.socket", multiline=True)
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_zebra_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_zebra_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_zebra

class disable_zebra {
  service {'zebra':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_zebra_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: zebra.service
        enabled: false
        mask: true
      - name: zebra.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_zebra_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["zebra"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_zebra_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable zebra
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_zebra_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_zebra_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_smb">
          <xccdf-1.2:title>Samba(SMB) Microsoft Windows File Sharing Server</xccdf-1.2:title>
          <xccdf-1.2:description>When properly configured, the Samba service allows
Linux systems to provide file and print sharing to Microsoft
Windows systems. There are two software packages that provide
Samba support. The first, <html:code>samba-client</html:code>, provides a series of
command line tools that enable a client system to access Samba
shares. The second, simply labeled <html:code>samba</html:code>, provides the Samba
service. It is this second package that allows a Linux system to
act as an Active Directory server, a domain controller, or as a
domain member. Only the <html:code>samba-client</html:code> package is installed by
default.</xccdf-1.2:description>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_configuring_samba">
            <xccdf-1.2:title>Configure Samba if Necessary</xccdf-1.2:title>
            <xccdf-1.2:description>All settings for the Samba daemon can be found in
<html:code>/etc/samba/smb.conf</html:code>. Settings are divided between a
<html:code>[global]</html:code> configuration section and a series of user
created share definition sections meant to describe file or print
shares on the system. By default, Samba will operate in user mode
and allow client systems to access local home directories and
printers. It is recommended that these settings be changed or that
additional limitations be set in place.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_samba-common_installed" selected="false" severity="medium">
              <xccdf-1.2:title>Install the Samba Common Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>samba-common</html:code> package should be installed.
The <html:code>samba-common</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install samba-common</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>If the samba-common package is not installed, samba cannot be configured.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_samba-common_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh">
if ! rpm -q --quiet "samba-common" ; then
    yum install -y "samba-common"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_samba-common_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Ensure samba-common is installed
  ansible.builtin.package:
    name: samba-common
    state: present
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_samba-common_installed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_samba-common_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_samba-common

class install_samba-common {
  package { 'samba-common':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_samba-common_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=samba-common
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="package_samba-common_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "samba-common"
version = "*"
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_samba-common_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install samba-common
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_samba-common_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install samba-common
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_samba-common_installed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_samba-common_installed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_mount_option_smb_client_signing" selected="false" severity="unknown">
              <xccdf-1.2:title>Require Client SMB Packet Signing, if using mount.cifs</xccdf-1.2:title>
              <xccdf-1.2:description>Require packet signing of clients who mount Samba
shares using the <html:code>mount.cifs</html:code> program (e.g., those who specify shares
in <html:code>/etc/fstab</html:code>). To do so, ensure signing options (either
<html:code>sec=krb5i</html:code> or <html:code>sec=ntlmv2i</html:code>) are used.
<html:br/><html:br/>
See the <html:code>mount.cifs(8)</html:code> man page for more information. A Samba
client should only communicate with servers who can support SMB
packet signing.</xccdf-1.2:description>
              <xccdf-1.2:rationale>Packet signing can prevent man-in-the-middle
attacks which modify SMB packets in transit.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#machine"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-mount_option_smb_client_signing:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-mount_option_smb_client_signing_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_require_smb_client_signing" selected="false" severity="unknown">
              <xccdf-1.2:title>Require Client SMB Packet Signing, if using smbclient</xccdf-1.2:title>
              <xccdf-1.2:description>To require samba clients running <html:code>smbclient</html:code> to use
packet signing, add the following to the <html:code>[global]</html:code> section
of the Samba configuration file, <html:code>/etc/samba/smb.conf</html:code>:
<html:pre>client signing = mandatory</html:pre>
Requiring samba clients such as <html:code>smbclient</html:code> to use packet
signing ensures they can
only communicate with servers that support packet signing.</xccdf-1.2:description>
              <xccdf-1.2:rationale>Packet signing can prevent
man-in-the-middle attacks which modify SMB packets in
transit.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="require_smb_client_signing" system="urn:xccdf:fix:script:sh">######################################################################
#By Luke "Brisk-OH" Brisk
#luke.brisk@boeing.com or luke.brisk@gmail.com
######################################################################

CLIENTSIGNING=$( grep -ic 'client signing' /etc/samba/smb.conf )

if [ "$CLIENTSIGNING" -eq 0 ];  then
	# Add to global section
	sed -i 's/\[global\]/\[global\]\n\n\tclient signing = mandatory/g' /etc/samba/smb.conf
else
	sed -i 's/[[:blank:]]*client[[:blank:]]signing[[:blank:]]*=[[:blank:]]*no/        client signing = mandatory/g' /etc/samba/smb.conf
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="require_smb_client_signing" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Check if /etc/samba/smb.conf exists
  ansible.builtin.stat:
    path: /etc/samba/smb.conf
  register: st_smb
  tags:
  - configure_strategy
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - require_smb_client_signing
  - unknown_severity

- name: Require Client SMB Packet Signing, if using smbclient
  ansible.builtin.lineinfile:
    dest: /etc/samba/smb.conf
    line: client signing = mandatory
    state: present
    insertafter:
    - global
  when: st_smb.stat.exists
  tags:
  - configure_strategy
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - require_smb_client_signing
  - unknown_severity
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-require_smb_client_signing:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-require_smb_client_signing_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_smb_server_disable_root" selected="false" severity="unknown">
              <xccdf-1.2:title>Disable Root Access to SMB Shares</xccdf-1.2:title>
              <xccdf-1.2:description>Administrators should not use administrator accounts to access
Samba file and printer shares. Disable the root user and the wheel
administrator group:
<html:pre>[<html:i>share</html:i>]
  invalid users = root @wheel</html:pre>
If administrator accounts cannot be disabled, ensure that local system
passwords and Samba service passwords do not match.</xccdf-1.2:description>
              <xccdf-1.2:rationale>Typically, administrator access is required when Samba must create user and
system accounts and shares. Domain member servers and standalone servers may
not need administrator access at all. If that is the case, add the invalid
users parameter to <html:code>[global]</html:code> instead.</xccdf-1.2:rationale>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_samba">
            <xccdf-1.2:title>Disable Samba if Possible</xccdf-1.2:title>
            <xccdf-1.2:description>Even after the Samba server package has been installed, it
will remain disabled. Do not enable this service unless it is
absolutely necessary to provide Microsoft Windows file and print
sharing functionality.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_samba_removed" selected="false" severity="unknown">
              <xccdf-1.2:title>Uninstall Samba Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>samba</html:code> package can be removed with the following command: <html:pre> $ sudo yum erase samba</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.14</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If there is no need to make the Samba software available,
removing it provides a safeguard against its activation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_samba_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove samba
# from the system, and may remove any packages
# that depend on samba. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "samba" ; then
yum remove -y "samba"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_samba_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall Samba Package: Ensure samba is removed'
  ansible.builtin.package:
    name: samba
    state: absent
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_samba_removed
  - unknown_severity
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_samba_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_samba

class remove_samba {
  package { 'samba':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_samba_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=samba
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_samba_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove samba
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_samba_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove samba
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_samba_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_samba_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_smb_disabled" selected="false" severity="low">
              <xccdf-1.2:title>Disable Samba</xccdf-1.2:title>
              <xccdf-1.2:description>
The <html:code>smb</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now smb.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>Running a Samba server provides a network-based avenue of attack, and
should be disabled if not needed.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_smb_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'smb.service'
fi
"$SYSTEMCTL_EXEC" disable 'smb.service'
"$SYSTEMCTL_EXEC" mask 'smb.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files smb.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'smb.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'smb.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'smb.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_smb_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_smb_disabled

- name: Disable Samba - Disable service smb
  block:

  - name: Disable Samba - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Samba - Ensure smb.service is Masked
    ansible.builtin.systemd:
      name: smb.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("smb.service", multiline=True)

  - name: Unit Socket Exists - smb.socket
    ansible.builtin.command: systemctl -q list-unit-files smb.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable Samba - Disable Socket smb
    ansible.builtin.systemd:
      name: smb.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("smb.socket", multiline=True)
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_smb_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_smb_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_smb

class disable_smb {
  service {'smb':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_smb_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: smb.service
        enabled: false
        mask: true
      - name: smb.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_smb_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["smb"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_smb_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable smb
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_smb_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_smb_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_snmp">
          <xccdf-1.2:title>SNMP Server</xccdf-1.2:title>
          <xccdf-1.2:description>The Simple Network Management Protocol allows
administrators to monitor the state of network devices, including
computers. Older versions of SNMP were well-known for weak
security, such as plaintext transmission of the community string
(used for authentication) and usage of easily-guessable
choices for the community string.</xccdf-1.2:description>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_snmp_service">
            <xccdf-1.2:title>Disable SNMP Server if Possible</xccdf-1.2:title>
            <xccdf-1.2:description>The system includes an SNMP daemon that allows for its remote
monitoring, though it not installed by default. If it was installed and
activated but is not needed, the software should be disabled and removed.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_net-snmp_removed" selected="false" severity="unknown">
              <xccdf-1.2:title>Uninstall net-snmp Package</xccdf-1.2:title>
              <xccdf-1.2:description>
The <html:code>net-snmp</html:code> package provides the snmpd service.
The <html:code>net-snmp</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase net-snmp</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.15</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If there is no need to run SNMP server software,
removing the package provides a safeguard against its
activation.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_net-snmp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove net-snmp
# from the system, and may remove any packages
# that depend on net-snmp. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "net-snmp" ; then
yum remove -y "net-snmp"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_net-snmp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Uninstall net-snmp Package: Ensure net-snmp is removed'
  ansible.builtin.package:
    name: net-snmp
    state: absent
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.4
  - disable_strategy
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - package_net-snmp_removed
  - unknown_severity
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_net-snmp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_net-snmp

class remove_net-snmp {
  package { 'net-snmp':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_net-snmp_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=net-snmp
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_net-snmp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove net-snmp
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_net-snmp_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove net-snmp
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_net-snmp_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_net-snmp_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_snmpd_disabled" selected="false" severity="low">
              <xccdf-1.2:title>Disable snmpd Service</xccdf-1.2:title>
              <xccdf-1.2:description>
The <html:code>snmpd</html:code> service can be disabled with the following command:
<html:pre>$ sudo systemctl mask --now snmpd.service</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1311</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Running SNMP software provides a network-based avenue of attack, and
should be disabled if not needed.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_snmpd_and_system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_snmpd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ( rpm --quiet -q net-snmp &amp;&amp; rpm --quiet -q kernel ) ); then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'snmpd.service'
fi
"$SYSTEMCTL_EXEC" disable 'snmpd.service'
"$SYSTEMCTL_EXEC" mask 'snmpd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files snmpd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'snmpd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'snmpd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'snmpd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_snmpd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_snmpd_disabled

- name: Disable snmpd Service - Disable service snmpd
  block:

  - name: Disable snmpd Service - Collect systemd Services Present in the System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable snmpd Service - Ensure snmpd.service is Masked
    ansible.builtin.systemd:
      name: snmpd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("snmpd.service", multiline=True)

  - name: Unit Socket Exists - snmpd.socket
    ansible.builtin.command: systemctl -q list-unit-files snmpd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable snmpd Service - Disable Socket snmpd
    ansible.builtin.systemd:
      name: snmpd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("snmpd.socket", multiline=True)
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - service_snmpd_disabled
  - special_service_block
  when: ( "net-snmp" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_snmpd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_snmpd

class disable_snmpd {
  service {'snmpd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="service_snmpd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: snmpd.service
        enabled: false
        mask: true
      - name: snmpd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="service_snmpd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["snmpd"]
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="service_snmpd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable snmpd
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_snmpd_disabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_snmpd_disabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_snmp_configure_server">
            <xccdf-1.2:title>Configure SNMP Server if Necessary</xccdf-1.2:title>
            <xccdf-1.2:description>If it is necessary to run the snmpd agent on the system, some best
practices should be followed to minimize the security risk from the
installation. The multiple security models implemented by SNMP cannot be fully
covered here so only the following general configuration advice can be offered:
<html:ul><html:li>use only SNMP version 3 security models and enable the use of authentication and encryption</html:li><html:li>write access to the MIB (Management Information Base) should be allowed only if necessary</html:li><html:li>all access to the MIB should be restricted following a principle of least privilege</html:li><html:li>network access should be limited to the maximum extent possible including restricting to expected network
addresses both in the configuration files and in the system firewall rules</html:li><html:li>ensure SNMP agents send traps only to, and accept SNMP queries only from, authorized management
stations</html:li><html:li>ensure that permissions on the <html:code>snmpd.conf</html:code> configuration file (by default, in <html:code>/etc/snmp</html:code>) are 640 or more restrictive</html:li><html:li>ensure that any MIB files' permissions are also 640 or more restrictive</html:li></html:ul></xccdf-1.2:description>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_snmpd_ro_string" interactive="true" type="string">
              <xccdf-1.2:title>SNMP read-only community string</xccdf-1.2:title>
              <xccdf-1.2:description>Specify the SNMP community string used for read-only access.</xccdf-1.2:description>
              <xccdf-1.2:value>changemero</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_snmpd_rw_string" interactive="true" type="string">
              <xccdf-1.2:title>SNMP read-write community string</xccdf-1.2:title>
              <xccdf-1.2:description>Specify the SNMP community string used for read-write access.</xccdf-1.2:description>
              <xccdf-1.2:value>changemerw</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_snmpd_no_rwusers" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure SNMP Read Write is disabled</xccdf-1.2:title>
              <xccdf-1.2:description>Edit <html:code>/etc/snmp/snmpd.conf</html:code>, remove any <html:code>rwuser</html:code> entries.
Once the read write users have been removed, restart the SNMP service:
<html:pre>$ sudo systemctl restart snmpd</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>Certain SNMP settings can permit users to execute system behaviors from user
writes to the community strings.
This may permit a compromised account to execute commands on a remote system.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_net-snmp"/>
              <xccdf-1.2:fix id="snmpd_no_rwusers" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q net-snmp; then

if grep -s "rwuser" /etc/snmp/snmpd.conf | grep -qv "^#"; then
	sed -i "/^\s*#/b;/rwuser/ s/^/#/" /etc/snmp/snmpd.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-snmpd_no_rwusers_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_snmpd_not_default_password" selected="false" severity="high">
              <xccdf-1.2:title>Ensure Default SNMP Password Is Not Used</xccdf-1.2:title>
              <xccdf-1.2:description>Edit <html:code>/etc/snmp/snmpd.conf</html:code>, remove or change the default community strings of
<html:code>public</html:code> and <html:code>private</html:code>.
This profile configures new read-only community string to <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_snmpd_ro_string" use="legacy"/></html:code> and read-write community string to <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_snmpd_rw_string" use="legacy"/></html:code>.
Once the default community strings have been changed, restart the SNMP service:
<html:pre>$ sudo systemctl restart snmpd</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Whether active or not, default simple network management protocol (SNMP) community
strings must be changed to maintain security. If the service is running with the
default authenticators, then anyone can gather data about the system and the network
and use the information to potentially compromise the integrity of the system and
network(s).</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_net-snmp"/>
              <xccdf-1.2:fix id="snmpd_not_default_password" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q net-snmp; then

var_snmpd_ro_string='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_snmpd_ro_string" use="legacy"/>'
var_snmpd_rw_string='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_snmpd_rw_string" use="legacy"/>'


# remediate read-only community string
if grep -q 'public' /etc/snmp/snmpd.conf; then
    sed -i "s/public/$var_snmpd_ro_string/" /etc/snmp/snmpd.conf
fi

# remediate read-write community string
if grep -q 'private' /etc/snmp/snmpd.conf; then
    sed -i "s/private/$var_snmpd_rw_string/" /etc/snmp/snmpd.conf
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="snmpd_not_default_password" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-IA-5(e)
  - configure_strategy
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - snmpd_not_default_password
- name: XCCDF Value var_snmpd_ro_string # promote to variable
  set_fact:
    var_snmpd_ro_string: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_snmpd_ro_string" use="legacy"/>
  tags:
    - always
- name: XCCDF Value var_snmpd_rw_string # promote to variable
  set_fact:
    var_snmpd_rw_string: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_snmpd_rw_string" use="legacy"/>
  tags:
    - always

- name: Check if file /etc/snmp/snmpd.conf exists
  ansible.builtin.stat:
    path: /etc/snmp/snmpd.conf
  register: snmpd
  when: '"net-snmp" in ansible_facts.packages'
  tags:
  - NIST-800-53-IA-5(e)
  - configure_strategy
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - snmpd_not_default_password

- name: Replace all instances of SNMP RO strings
  ansible.builtin.replace:
    path: /etc/snmp/snmpd.conf
    regexp: public
    replace: '{{ var_snmpd_ro_string }}'
  when:
  - '"net-snmp" in ansible_facts.packages'
  - (snmpd.stat.exists is defined and snmpd.stat.exists)
  tags:
  - NIST-800-53-IA-5(e)
  - configure_strategy
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - snmpd_not_default_password

- name: Replace all instances of SNMP RW strings
  ansible.builtin.replace:
    path: /etc/snmp/snmpd.conf
    regexp: private
    replace: '{{ var_snmpd_rw_string }}'
  when:
  - '"net-snmp" in ansible_facts.packages'
  - (snmpd.stat.exists is defined and snmpd.stat.exists)
  tags:
  - NIST-800-53-IA-5(e)
  - configure_strategy
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - snmpd_not_default_password
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-snmpd_not_default_password:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-snmpd_not_default_password_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_snmpd_use_newer_protocol" selected="false" severity="medium">
              <xccdf-1.2:title>Configure SNMP Service to Use Only SNMPv3 or Newer</xccdf-1.2:title>
              <xccdf-1.2:description>Edit <html:code>/etc/snmp/snmpd.conf</html:code>, removing any references to <html:code>rocommunity</html:code>, <html:code>rwcommunity</html:code>, or <html:code>com2sec</html:code>.
Upon doing that, restart the SNMP service:
<html:pre>$ sudo systemctl restart snmpd</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1311</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Earlier versions of SNMP are considered insecure, as they potentially allow
unauthorized access to detailed system management information.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_net-snmp"/>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-snmpd_use_newer_protocol:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-snmpd_use_newer_protocol_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_ssh">
          <xccdf-1.2:title>SSH Server</xccdf-1.2:title>
          <xccdf-1.2:description>The SSH protocol is recommended for remote login and
remote file transfer. SSH provides confidentiality and integrity
for data exchanged between two systems, as well as server
authentication, through the use of public key cryptography. The
implementation included with the system is called OpenSSH, and more
detailed documentation is available from its website,

    <html:a href="https://www.openssh.com">https://www.openssh.com</html:a>.
Its server program is called <html:code>sshd</html:code> and provided by the RPM package
<html:code>openssh-server</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_firewalld_sshd_zone" type="string">
            <xccdf-1.2:title>SSH enabled firewalld zone</xccdf-1.2:title>
            <xccdf-1.2:description>Specify firewalld zone to enable SSH service. This value is used only for remediation purposes.</xccdf-1.2:description>
            <xccdf-1.2:value selector="block">block</xccdf-1.2:value>
            <xccdf-1.2:value>public</xccdf-1.2:value>
            <xccdf-1.2:value selector="dmz">dmz</xccdf-1.2:value>
            <xccdf-1.2:value selector="drop">drop</xccdf-1.2:value>
            <xccdf-1.2:value selector="external">external</xccdf-1.2:value>
            <xccdf-1.2:value selector="home">home</xccdf-1.2:value>
            <xccdf-1.2:value selector="internal">internal</xccdf-1.2:value>
            <xccdf-1.2:value selector="public">public</xccdf-1.2:value>
            <xccdf-1.2:value selector="trusted">trusted</xccdf-1.2:value>
            <xccdf-1.2:value selector="work">work</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sshd_approved_ciphers" type="string">
            <xccdf-1.2:title>SSH Approved ciphers by FIPS</xccdf-1.2:title>
            <xccdf-1.2:description>Specify the FIPS approved ciphers that are used for data integrity protection by the SSH server.</xccdf-1.2:description>
            <xccdf-1.2:value selector="stig">aes256-ctr,aes192-ctr,aes128-ctr</xccdf-1.2:value>
            <xccdf-1.2:value selector="stig_extended">aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes128-ctr</xccdf-1.2:value>
            <xccdf-1.2:value selector="stig_rhel9">aes256-gcm@openssh.com,aes256-ctr,aes128-gcm@openssh.com,aes128-ctr</xccdf-1.2:value>
            <xccdf-1.2:value>aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,3des-cbc,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel8">-3des-cbc,aes128-cbc,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel9">-3des-cbc,aes128-cbc,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_sle12">chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_sle15">chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_ubuntu">chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com</xccdf-1.2:value>
            <xccdf-1.2:value selector="stig_ubuntu2204">aes256-ctr,aes256-gcm@openssh.com,aes128-ctr,aes128-gcm@openssh.com</xccdf-1.2:value>
            <xccdf-1.2:value selector="stig_ol9">aes256-gcm@openssh.com,aes256-ctr,aes128-gcm@openssh.com,aes128-ctr</xccdf-1.2:value>
            <xccdf-1.2:value selector="stig_ol8">aes256-gcm@openssh.com,aes256-ctr,aes128-gcm@openssh.com,aes128-ctr</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sshd_approved_macs" type="string">
            <xccdf-1.2:title>SSH Approved MACs by FIPS</xccdf-1.2:title>
            <xccdf-1.2:description>Specify the FIPS approved MACs (message authentication code) algorithms
	that are used for data integrity protection by the SSH server.</xccdf-1.2:description>
            <xccdf-1.2:value selector="stig">hmac-sha2-512,hmac-sha2-256</xccdf-1.2:value>
            <xccdf-1.2:value selector="stig_extended">hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256</xccdf-1.2:value>
            <xccdf-1.2:value selector="stig_rhel9">hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512</xccdf-1.2:value>
            <xccdf-1.2:value>hmac-sha2-512,hmac-sha2-256,hmac-sha1,hmac-sha1-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_sle12">hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_sle15">hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_ubuntu">hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256</xccdf-1.2:value>
            <xccdf-1.2:value selector="stig_ubuntu2204">hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com</xccdf-1.2:value>
            <xccdf-1.2:value selector="stig_ol9">hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sshd_idle_timeout_value" type="number">
            <xccdf-1.2:title>SSH session Idle time</xccdf-1.2:title>
            <xccdf-1.2:description>Specify duration of allowed idle time.</xccdf-1.2:description>
            <xccdf-1.2:value selector="10_minutes">600</xccdf-1.2:value>
            <xccdf-1.2:value selector="120_minutes">7200</xccdf-1.2:value>
            <xccdf-1.2:value selector="14_minutes">840</xccdf-1.2:value>
            <xccdf-1.2:value selector="15_minutes">900</xccdf-1.2:value>
            <xccdf-1.2:value selector="30_minutes">1800</xccdf-1.2:value>
            <xccdf-1.2:value selector="5_minutes">300</xccdf-1.2:value>
            <xccdf-1.2:value selector="60_minutes">3600</xccdf-1.2:value>
            <xccdf-1.2:value>300</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sshd_listening_port" type="number">
            <xccdf-1.2:title>SSH Server Listening Port</xccdf-1.2:title>
            <xccdf-1.2:description>Specify port the SSH server is listening.</xccdf-1.2:description>
            <xccdf-1.2:value>22</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sshd_max_auth_tries_value" type="number">
            <xccdf-1.2:title>SSH Max authentication attempts</xccdf-1.2:title>
            <xccdf-1.2:description>Specify the maximum number of authentication attempts per connection.</xccdf-1.2:description>
            <xccdf-1.2:value selector="10">10</xccdf-1.2:value>
            <xccdf-1.2:value selector="3">3</xccdf-1.2:value>
            <xccdf-1.2:value selector="4">4</xccdf-1.2:value>
            <xccdf-1.2:value selector="5">5</xccdf-1.2:value>
            <xccdf-1.2:value>4</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sshd_required" type="number">
            <xccdf-1.2:title>SSH is required to be installed</xccdf-1.2:title>
            <xccdf-1.2:description>Specify if the Policy requires SSH to be installed. Used by SSH Rules
to determine if SSH should be uninstalled or configured.<html:br/>
A value of 0 means that the policy doesn't care if OpenSSH server is installed or not. If it is installed, scanner will check for it's configuration, if it's not installed, the check will pass.<html:br/>
A value of 1 indicates that OpenSSH server package is not required by the policy;<html:br/>
A value of 2 indicates that OpenSSH server package is required by the policy.<html:br/></xccdf-1.2:description>
            <xccdf-1.2:value>0</xccdf-1.2:value>
            <xccdf-1.2:value selector="no">1</xccdf-1.2:value>
            <xccdf-1.2:value selector="yes">2</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sshd_strong_kex" type="string">
            <xccdf-1.2:title>SSH Strong KEX by FIPS</xccdf-1.2:title>
            <xccdf-1.2:description>Specify the FIPS approved KEXs (Key Exchange Algorithms) algorithms
	that are used for methods in cryptography by which cryptographic keys are exchanged between two parties</xccdf-1.2:description>
            <xccdf-1.2:value>ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256</xccdf-1.2:value>
            <xccdf-1.2:value selector="pcidss">ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel8">-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel9">-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel10">-diffie-hellman-group1-sha1,diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_sle12">curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_sle15">curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_ubuntu2204">curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_ubuntu2404">sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256</xccdf-1.2:value>
            <xccdf-1.2:value selector="std_openeuler">curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_debian12">sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_sshd_strong_macs" type="string">
            <xccdf-1.2:title>SSH Strong MACs by FIPS</xccdf-1.2:title>
            <xccdf-1.2:description>Specify the FIPS approved MACs (Message Authentication Code) algorithms
	that are used for data integrity protection by the SSH server.</xccdf-1.2:description>
            <xccdf-1.2:value>hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel8">-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel9">-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel10">-hmac-md5,hmac-md5-96,hmac-ripemd160,hmac-sha1-96,umac-64@openssh.com,hmac-md5-etm@openssh.com,hmac-md5-96-etm@openssh.com,hmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com,umac-64-etm@openssh.com</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_sle12">hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_sle15">hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_tencentos4">hmac-sha2-512,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-256-etm@openssh.com</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_ubuntu2204">hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_ubuntu2404">hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256</xccdf-1.2:value>
            <xccdf-1.2:value selector="stig_rhel9">hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512</xccdf-1.2:value>
            <xccdf-1.2:value selector="stig_ol9">hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha2-256,hmac-sha2-512</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_debian12">hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sshd_max_sessions" type="number">
            <xccdf-1.2:title>SSH Max Sessions Count</xccdf-1.2:title>
            <xccdf-1.2:description>Specify the maximum number of open sessions permitted.</xccdf-1.2:description>
            <xccdf-1.2:value selector="10">10</xccdf-1.2:value>
            <xccdf-1.2:value selector="4">4</xccdf-1.2:value>
            <xccdf-1.2:value selector="3">3</xccdf-1.2:value>
            <xccdf-1.2:value selector="2">2</xccdf-1.2:value>
            <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
            <xccdf-1.2:value selector="0">0</xccdf-1.2:value>
            <xccdf-1.2:value>10</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sshd_set_keepalive" type="number">
            <xccdf-1.2:title>SSH Max Keep Alive Count</xccdf-1.2:title>
            <xccdf-1.2:description>Specify the maximum number of idle message counts before session is terminated.</xccdf-1.2:description>
            <xccdf-1.2:value selector="10">10</xccdf-1.2:value>
            <xccdf-1.2:value selector="3">3</xccdf-1.2:value>
            <xccdf-1.2:value selector="5">5</xccdf-1.2:value>
            <xccdf-1.2:value selector="0">0</xccdf-1.2:value>
            <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
            <xccdf-1.2:value>0</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_openssh-clients_installed" selected="false" severity="medium">
            <xccdf-1.2:title>Install OpenSSH client software</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>openssh-clients</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install openssh-clients</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_UAU.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FTP_ITC_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_SSH_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_SSHC_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:rationale>This package includes utilities to make encrypted connections and transfer
files securely to SSH servers.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-clients_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "openssh-clients" ; then
    yum install -y "openssh-clients"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-clients_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_openssh-clients_installed

- name: Ensure openssh-clients is installed
  ansible.builtin.package:
    name: openssh-clients
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_openssh-clients_installed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-clients_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_openssh-clients

class install_openssh-clients {
  package { 'openssh-clients':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-clients_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=openssh-clients
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_openssh-clients_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "openssh-clients"
version = "*"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-clients_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install openssh-clients
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-clients_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install openssh-clients
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_openssh-clients_installed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_openssh-clients_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_openssh-server_installed" selected="false" severity="medium">
            <xccdf-1.2:title>Install the OpenSSH Server Package</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>openssh-server</html:code> package should be installed.
The <html:code>openssh-server</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install openssh-server</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_UAU.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FTP_ITC_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_SSH_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_SSHS_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000423-GPOS-00187</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000424-GPOS-00188</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000425-GPOS-00189</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000426-GPOS-00190</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040159</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244549r958908_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Without protection of the transmitted information, confidentiality, and
integrity may be compromised because unprotected communications can be
intercepted and either read or altered.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-server_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "openssh-server" ; then
    yum install -y "openssh-server"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-server_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040159
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_openssh-server_installed

- name: Ensure openssh-server is installed
  ansible.builtin.package:
    name: openssh-server
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040159
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_openssh-server_installed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-server_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_openssh-server

class install_openssh-server {
  package { 'openssh-server':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-server_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=openssh-server
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_openssh-server_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "openssh-server"
version = "*"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-server_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install openssh-server
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-server_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install openssh-server
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_openssh-server_installed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_openssh-server_removed" selected="false" severity="medium">
            <xccdf-1.2:title>Remove the OpenSSH Server Package</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>openssh-server</html:code> package should be removed.
The <html:code>openssh-server</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase openssh-server</html:pre></xccdf-1.2:description>
            <xccdf-1.2:rationale>Without protection of the transmitted information, confidentiality, and
integrity may be compromised because unprotected communications can be
intercepted and either read or altered.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove openssh-server
# from the system, and may remove any packages
# that depend on openssh-server. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "openssh-server" ; then
yum remove -y "openssh-server"
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Remove the OpenSSH Server Package: Ensure openssh-server is removed'
  ansible.builtin.package:
    name: openssh-server
    state: absent
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_openssh-server_removed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_openssh-server

class remove_openssh-server {
  package { 'openssh-server':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-server_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=openssh-server
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove openssh-server
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_openssh-server_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove openssh-server
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_openssh-server_removed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_openssh-server_removed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_sshd_enabled" selected="false" severity="medium">
            <xccdf-1.2:title>Enable the OpenSSH Service</xccdf-1.2:title>
            <xccdf-1.2:description>The SSH server service, sshd, is commonly needed.

The <html:code>sshd</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable sshd.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.5.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.13.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-8(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-8(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-8(3)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-8(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000423-GPOS-00187</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000424-GPOS-00188</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000425-GPOS-00189</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000426-GPOS-00190</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040160</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230526r958908_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Without protection of the transmitted information, confidentiality, and
integrity may be compromised because unprotected communications can be
intercepted and either read or altered.
<html:br/><html:br/>
This checklist item applies to both internal and external networks and all types
of information system components from which information can be transmitted (e.g., servers,
mobile devices, notebook computers, printers, copiers, scanners, etc). Communication paths
outside the physical protection of a controlled boundary are exposed to the possibility
of interception and modification.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_sshd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'sshd.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'sshd.service'
fi
"$SYSTEMCTL_EXEC" enable 'sshd.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_sshd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040160
  - NIST-800-171-3.1.13
  - NIST-800-171-3.13.8
  - NIST-800-171-3.5.4
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-8
  - NIST-800-53-SC-8(1)
  - NIST-800-53-SC-8(2)
  - NIST-800-53-SC-8(3)
  - NIST-800-53-SC-8(4)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_sshd_enabled

- name: Enable the OpenSSH Service - Enable service sshd
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable the OpenSSH Service - Enable Service sshd
    ansible.builtin.systemd:
      name: sshd
      enabled: true
      state: started
      masked: false
    when:
    - '"openssh-server" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040160
  - NIST-800-171-3.1.13
  - NIST-800-171-3.13.8
  - NIST-800-171-3.5.4
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-8
  - NIST-800-53-SC-8(1)
  - NIST-800-53-SC-8(2)
  - NIST-800-53-SC-8(3)
  - NIST-800-53-SC-8(4)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_sshd_enabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_sshd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_sshd

class enable_sshd {
  service {'sshd':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_sshd_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["sshd"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_sshd_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable sshd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_sshd_enabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_sshd_enabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_sshd_disabled" selected="false" severity="high">
            <xccdf-1.2:title>Disable SSH Server If Possible</xccdf-1.2:title>
            <xccdf-1.2:description>
The SSH server service, sshd, is commonly needed.
However, if it can be disabled, do so.
This is unusual, as SSH is a common method for encrypted and authenticated
remote access.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-3(6)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000185-CTR-000490</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000141-CTR-000315</xccdf-1.2:reference>
            <xccdf-1.2:rationale/>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_sshd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" stop 'sshd.service'
fi
"$SYSTEMCTL_EXEC" disable 'sshd.service'
"$SYSTEMCTL_EXEC" mask 'sshd.service'
# Disable socket activation if we have a unit file for it
if "$SYSTEMCTL_EXEC" -q list-unit-files sshd.socket; then
    if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
      "$SYSTEMCTL_EXEC" stop 'sshd.socket'
    fi
    "$SYSTEMCTL_EXEC" mask 'sshd.socket'
fi
# The service may not be running because it has been started and failed,
# so let's reset the state so OVAL checks pass.
# Service should be 'inactive', not 'failed' after reboot though.
"$SYSTEMCTL_EXEC" reset-failed 'sshd.service' || true

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_sshd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-3(6)
  - NIST-800-53-IA-2(4)
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_sshd_disabled

- name: Disable SSH Server If Possible - Disable service sshd
  block:

  - name: Disable SSH Server If Possible - Collect systemd Services Present in the
      System
    ansible.builtin.command: systemctl -q list-unit-files --type service
    register: service_exists
    changed_when: false
    failed_when: service_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable SSH Server If Possible - Ensure sshd.service is Masked
    ansible.builtin.systemd:
      name: sshd.service
      state: stopped
      enabled: false
      masked: true
    when: service_exists.stdout_lines is search("sshd.service", multiline=True)

  - name: Unit Socket Exists - sshd.socket
    ansible.builtin.command: systemctl -q list-unit-files sshd.socket
    register: socket_file_exists
    changed_when: false
    failed_when: socket_file_exists.rc not in [0, 1]
    check_mode: false

  - name: Disable SSH Server If Possible - Disable Socket sshd
    ansible.builtin.systemd:
      name: sshd.socket
      enabled: false
      state: stopped
      masked: true
    when: socket_file_exists.stdout_lines is search("sshd.socket", multiline=True)
  tags:
  - NIST-800-53-CM-3(6)
  - NIST-800-53-IA-2(4)
  - disable_strategy
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - service_sshd_disabled
  - special_service_block
  when: '"kernel" in ansible_facts.packages'
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_sshd_disabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include disable_sshd

class disable_sshd {
  service {'sshd':
    enable =&gt; false,
    ensure =&gt; 'stopped',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="service_sshd_disabled" reboot="true" strategy="disable" system="urn:xccdf:fix:script:kubernetes">apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: sshd.service
        enabled: false
        mask: true
      - name: sshd.socket
        enabled: false
        mask: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_sshd_disabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
masked = ["sshd"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_sshd_disabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service disable sshd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_sshd_disabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_sshd_disabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupowner_sshd_config" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Group Who Owns SSH Server config file</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the group owner of <html:code>/etc/ssh/sshd_config</html:code>, run the command:

  <html:pre>$ sudo chgrp root /etc/ssh/sshd_config</html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.2</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective
services that if configured incorrectly can lead to insecure and vulnerable
configurations. Therefore, service configuration files should be owned by the
correct group to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_sshd_config" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/etc/ssh/sshd_config" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /etc/ssh/sshd_config
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupowner_sshd_config" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_groupowner_sshd_config
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupowner_sshd_config_newgroup variable if represented by gid
  ansible.builtin.set_fact:
    file_groupowner_sshd_config_newgroup: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_groupowner_sshd_config
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/ssh/sshd_config
  ansible.builtin.stat:
    path: /etc/ssh/sshd_config
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_groupowner_sshd_config
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/ssh/sshd_config
  ansible.builtin.file:
    path: /etc/ssh/sshd_config
    follow: false
    group: '{{ file_groupowner_sshd_config_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_groupowner_sshd_config
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupowner_sshd_config:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupowner_sshd_config_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupownership_sshd_private_key" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Group Ownership on SSH Server Private *_key Key Files</xccdf-1.2:title>
            <xccdf-1.2:description>SSH server private keys, files that match the <html:code>/etc/ssh/*_key</html:code> glob, must be
group-owned by <html:code>ssh_keys</html:code> group.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Remediation is not possible at bootable container build time because SSH host
keys are generated post-deployment.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.4</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If an unauthorized user obtains the private SSH host key file, the host could be impersonated.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupownership_sshd_private_key" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "ssh_keys" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="ssh_keys"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "ssh_keys is not a defined group on the system"
else
find -P /etc/ssh/ -maxdepth 1 -type f  ! -group ssh_keys -regextype posix-extended -regex '^.*_key$' -exec chgrp --no-dereference "$newgroup" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupownership_sshd_private_key" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_groupownership_sshd_private_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Check that the ssh_keys group is defined
  ansible.builtin.getent:
    database: group
    key: ssh_keys
  ignore_errors: true
  when:
  - '"kernel" in ansible_facts.packages'
  - file_groupownership_sshd_private_key_newgroup is undefined
  tags:
  - configure_strategy
  - file_groupownership_sshd_private_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupownership_sshd_private_key_newgroup variable if ssh_keys
    found
  ansible.builtin.set_fact:
    file_groupownership_sshd_private_key_newgroup: ssh_keys
  when:
  - '"kernel" in ansible_facts.packages'
  - ansible_facts.getent_group["ssh_keys"] is defined
  tags:
  - configure_strategy
  - file_groupownership_sshd_private_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/ssh/ file(s) matching ^.*_key$
  ansible.builtin.command: find -P /etc/ssh/ -maxdepth 1 -type f  ! -group ssh_keys
    -regextype posix-extended -regex "^.*_key$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_sshd_private_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/ssh/ file(s) matching ^.*_key$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    group: '{{ file_groupownership_sshd_private_key_newgroup }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_sshd_private_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupownership_sshd_private_key:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupownership_sshd_private_key_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupownership_sshd_pub_key" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Group Ownership on SSH Server Public *.pub Key Files</xccdf-1.2:title>
            <xccdf-1.2:description>SSH server public keys, files that match the <html:code>/etc/ssh/*.pub</html:code> glob, must be
group-owned by <html:code>root</html:code> group.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Remediation is not possible at bootable container build time because SSH host
keys are generated post-deployment.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.5</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If a public host key file is modified by an unauthorized user, the SSH service
may be compromised.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupownership_sshd_pub_key" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
find -P /etc/ssh/ -maxdepth 1 -type f  ! -group 0 -regextype posix-extended -regex '^.*\.pub$' -exec chgrp --no-dereference "$newgroup" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupownership_sshd_pub_key" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_groupownership_sshd_pub_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupownership_sshd_pub_key_newgroup variable if represented
    by gid
  ansible.builtin.set_fact:
    file_groupownership_sshd_pub_key_newgroup: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_sshd_pub_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/ssh/ file(s) matching ^.*\.pub$
  ansible.builtin.command: find -P /etc/ssh/ -maxdepth 1 -type f  ! -group 0 -regextype
    posix-extended -regex "^.*\.pub$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_sshd_pub_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/ssh/ file(s) matching ^.*\.pub$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    group: '{{ file_groupownership_sshd_pub_key_newgroup }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_sshd_pub_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupownership_sshd_pub_key:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupownership_sshd_pub_key_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_owner_sshd_config" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Owner on SSH Server config file</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the owner of <html:code>/etc/ssh/sshd_config</html:code>, run the command:

  <html:pre>$ sudo chown root /etc/ssh/sshd_config </html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.2</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective
services that if configured incorrectly can lead to insecure and vulnerable
configurations. Therefore, service configuration files should be owned by the
correct group to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_sshd_config" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/etc/ssh/sshd_config" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /etc/ssh/sshd_config
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_owner_sshd_config" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_owner_sshd_config
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_owner_sshd_config_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_owner_sshd_config_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_owner_sshd_config
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/ssh/sshd_config
  ansible.builtin.stat:
    path: /etc/ssh/sshd_config
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_owner_sshd_config
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/ssh/sshd_config
  ansible.builtin.file:
    path: /etc/ssh/sshd_config
    follow: false
    owner: '{{ file_owner_sshd_config_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - configure_strategy
  - file_owner_sshd_config
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_owner_sshd_config:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_owner_sshd_config_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_ownership_sshd_private_key" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Ownership on SSH Server Private *_key Key Files</xccdf-1.2:title>
            <xccdf-1.2:description>SSH server private keys, files that match the <html:code>/etc/ssh/*_key</html:code> glob, must be owned
by <html:code>root</html:code> user.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Remediation is not possible at bootable container build time because SSH host
keys are generated post-deployment.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.4</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If an unauthorized user obtains the private SSH host key file, the host could be impersonated.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_ownership_sshd_private_key" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else

find -P /etc/ssh/ -maxdepth 1 -type f  ! -user 0 -regextype posix-extended -regex '^.*_key$' -exec chown --no-dereference "$newown" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_ownership_sshd_private_key" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_ownership_sshd_private_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_ownership_sshd_private_key_newown variable if represented by
    uid
  ansible.builtin.set_fact:
    file_ownership_sshd_private_key_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_sshd_private_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/ssh/ file(s) matching ^.*_key$
  ansible.builtin.command: find -P /etc/ssh/ -maxdepth 1 -type f  ! -user 0 -regextype
    posix-extended -regex "^.*_key$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_sshd_private_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/ssh/ file(s) matching ^.*_key$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    owner: '{{ file_ownership_sshd_private_key_newown }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_sshd_private_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_ownership_sshd_private_key:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_ownership_sshd_private_key_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_ownership_sshd_pub_key" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Ownership on SSH Server Public *.pub Key Files</xccdf-1.2:title>
            <xccdf-1.2:description>SSH server public keys, files that match the <html:code>/etc/ssh/*.pub</html:code> glob, must be owned
by <html:code>root</html:code> user.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Remediation is not possible at bootable container build time because SSH host
keys are generated post-deployment.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.5</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If a public host key file is modified by an unauthorized user, the SSH service
may be compromised.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_ownership_sshd_pub_key" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else

find -P /etc/ssh/ -maxdepth 1 -type f  ! -user 0 -regextype posix-extended -regex '^.*\.pub$' -exec chown --no-dereference "$newown" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_ownership_sshd_pub_key" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_ownership_sshd_pub_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_ownership_sshd_pub_key_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_ownership_sshd_pub_key_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_sshd_pub_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/ssh/ file(s) matching ^.*\.pub$
  ansible.builtin.command: find -P /etc/ssh/ -maxdepth 1 -type f  ! -user 0 -regextype
    posix-extended -regex "^.*\.pub$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_sshd_pub_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/ssh/ file(s) matching ^.*\.pub$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    owner: '{{ file_ownership_sshd_pub_key_newown }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_sshd_pub_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_ownership_sshd_pub_key:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_sshd_config" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Permissions on SSH Server config file</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/ssh/sshd_config</html:code>, run the command:
<html:pre>$ sudo chmod 0600 /etc/ssh/sshd_config</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.2</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Service configuration files enable or disable features of their respective
services that if configured incorrectly can lead to insecure and vulnerable
configurations. Therefore, service configuration files should be owned by the
correct group to prevent unauthorized changes.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_sshd_config" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

chmod u-xs,g-xwrs,o-xwrt /etc/ssh/sshd_config

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_sshd_config" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_sshd_config
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/ssh/sshd_config
  ansible.builtin.stat:
    path: /etc/ssh/sshd_config
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_sshd_config
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xwrs,o-xwrt on /etc/ssh/sshd_config
  ansible.builtin.file:
    path: /etc/ssh/sshd_config
    mode: u-xs,g-xwrs,o-xwrt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_sshd_config
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_sshd_config:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_sshd_config_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_sshd_private_key" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Permissions on SSH Server Private *_key Key Files</xccdf-1.2:title>
            <xccdf-1.2:description>SSH server private keys - files that match the <html:code>/etc/ssh/*_key</html:code> glob, have to have restricted permissions.
If those files are owned by the <html:code>root</html:code> user and the <html:code>root</html:code> group, they have to have the <html:code>0600</html:code> permission or stricter.
If they are owned by the <html:code>root</html:code> user, but by a dedicated group <html:code>ssh_keys</html:code>, they can have the <html:code>0640</html:code> permission or stricter.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Remediation is not possible at bootable container build time because SSH host
keys are generated post-deployment.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.13.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-2.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1449</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010490</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230287r1017098_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If an unauthorized user obtains the private SSH host key file, the host could be
impersonated.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix id="file_permissions_sshd_private_key" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

for keyfile in /etc/ssh/*_key; do
    test -f "$keyfile" || continue
    if test root:root = "$(stat -c "%U:%G" "$keyfile")"; then
    
	chmod u-xs,g-xwrs,o-xwrt "$keyfile"
    
    elif test root:ssh_keys = "$(stat -c "%U:%G" "$keyfile")"; then
	chmod u-xs,g-xws,o-xwrt "$keyfile"
    else
        echo "Key-like file '$keyfile' is owned by an unexpected user:group combination"
    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_sshd_private_key" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010490
  - NIST-800-171-3.1.13
  - NIST-800-171-3.13.10
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-2.2.4
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_sshd_private_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find root:root-owned keys
  ansible.builtin.command: find -H /etc/ssh/ -maxdepth 1 -user root -regex ".*_key$"
    -type f -group root -perm /u+xs,g+xwrs,o+xwrt
  register: root_owned_keys
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010490
  - NIST-800-171-3.1.13
  - NIST-800-171-3.13.10
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-2.2.4
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_sshd_private_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for root:root-owned keys
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-xs,g-xwrs,o-xwrt
    state: file
  with_items:
  - '{{ root_owned_keys.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010490
  - NIST-800-171-3.1.13
  - NIST-800-171-3.13.10
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-2.2.4
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_sshd_private_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find root:ssh_keys-owned keys
  ansible.builtin.command: find -H /etc/ssh/ -maxdepth 1 -user root -regex ".*_key$"
    -type f -group ssh_keys -perm /u+xs,g+xws,o+xwrt
  register: dedicated_group_owned_keys
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010490
  - NIST-800-171-3.1.13
  - NIST-800-171-3.13.10
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-2.2.4
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_sshd_private_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for root:ssh_keys-owned keys
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-xs,g-xws,o-xwrt
    state: file
  with_items:
  - '{{ dedicated_group_owned_keys.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010490
  - NIST-800-171-3.1.13
  - NIST-800-171-3.13.10
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-2.2.4
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_sshd_private_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="file_permissions_sshd_private_key" system="urn:xccdf:fix:script:puppet">include ssh_private_key_perms

class ssh_private_key_perms {
  exec { 'sshd_priv_key':
    command =&gt; "chmod 0640 /etc/ssh/*_key",
    path    =&gt; '/bin:/usr/bin'
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_sshd_private_key:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_sshd_private_key_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_sshd_pub_key" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Permissions on SSH Server Public *.pub Key Files</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/ssh/*.pub</html:code>, run the command: <html:pre>$ sudo chmod 0644 /etc/ssh/*.pub</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Remediation is not possible at bootable container build time because SSH host
keys are generated post-deployment.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.13.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-2.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R50</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010480</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230286r1017097_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If a public host key file is modified by an unauthorized user, the SSH service
may be compromised.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_sshd_pub_key" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

find -P /etc/ssh/ -maxdepth 1 -perm /u+xs,g+xws,o+xwt  -type f -regextype posix-extended -regex '^.*\.pub$' -exec chmod u-xs,g-xws,o-xwt {} \;

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_sshd_pub_key" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010480
  - NIST-800-171-3.1.13
  - NIST-800-171-3.13.10
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-2.2.4
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_sshd_pub_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/ssh/ file(s)
  ansible.builtin.command: find -P /etc/ssh/ -maxdepth 1 -perm /u+xs,g+xws,o+xwt  -type
    f -regextype posix-extended -regex "^.*\.pub$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010480
  - NIST-800-171-3.1.13
  - NIST-800-171-3.13.10
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-2.2.4
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_sshd_pub_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /etc/ssh/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-xs,g-xws,o-xwt
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010480
  - NIST-800-171-3.1.13
  - NIST-800-171-3.13.10
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-2.2.4
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - configure_strategy
  - file_permissions_sshd_pub_key
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="file_permissions_sshd_pub_key" system="urn:xccdf:fix:script:puppet">include ssh_public_key_perms

class ssh_public_key_perms {
  exec { 'sshd_pub_key':
    command =&gt; "chmod 0644 /etc/ssh/*.pub",
    path    =&gt; '/bin:/usr/bin'
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_sshd_pub_key:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firewalld_sshd_disabled" selected="false" severity="unknown">
            <xccdf-1.2:title>Remove SSH Server firewalld Firewall exception (Unusual)</xccdf-1.2:title>
            <xccdf-1.2:description>By default, inbound connections to SSH's port are allowed. If
the SSH server is not being used, this exception should be removed from the
firewall configuration.
<html:br/><html:br/>

To configure <html:code>firewalld</html:code> to prevent access, run the following command(s):
<html:code>firewall-cmd --permanent --remove-service=ssh</html:code></xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.12</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If inbound SSH connections are not expected, disallowing access to the SSH port will
avoid possible exploitation of the port by an attacker.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-firewalld_sshd_disabled:def:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_iptables_sshd_disabled" selected="false" severity="unknown">
            <xccdf-1.2:title>Remove SSH Server iptables Firewall exception (Unusual)</xccdf-1.2:title>
            <xccdf-1.2:description>By default, inbound connections to SSH's port are allowed. If the SSH
server is not being used, this exception should be removed from the
firewall configuration.
<html:br/><html:br/>
Edit the files <html:code>/etc/sysconfig/iptables</html:code> and
<html:code>/etc/sysconfig/ip6tables</html:code> (if IPv6 is in use). In each file, locate
and delete the line:
<html:pre>-A INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT</html:pre>
This is unusual, as SSH is a common method for encrypted and authenticated
remote access.</xccdf-1.2:description>
            <xccdf-1.2:rationale>If inbound SSH connections are not expected, disallowing access to the SSH
port will avoid possible exploitation of the port by an attacker.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_ssh_client">
            <xccdf-1.2:title>Configure OpenSSH Client if Necessary</xccdf-1.2:title>
            <xccdf-1.2:description>The following configuration changes apply to the SSH client. They can
improve security parameters relwevant to the client user, e.g. increasing
entropy while generating initialization vectors. Note that these changes
influence only the default SSH client configuration. Changes in this group
can be overridden by the client user by modifying files within the
<html:pre>~/.ssh</html:pre> directory or by supplying parameters on the command line.</xccdf-1.2:description>
            <xccdf-1.2:platform idref="#package_openssh-clients"/>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ssh_client_rekey_limit" selected="false" severity="medium">
              <xccdf-1.2:title>Configure session renegotiation for SSH client</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>RekeyLimit</html:code> parameter specifies how often
the session key is renegotiated, both in terms of
amount of data that may be transmitted and the time
elapsed. To decrease the default limits, put line
<html:code>RekeyLimit <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_size" use="legacy"/> <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_time" use="legacy"/></html:code> to file <html:code>/etc/ssh/ssh_config.d/02-rekey-limit.conf</html:code>.
Make sure that there is no other <html:code>RekeyLimit</html:code> configuration preceding
the <html:code>include</html:code> directive in the main config file
<html:code>/etc/ssh/ssh_config</html:code>. Check also other files in
<html:code>/etc/ssh/ssh_config.d</html:code> directory. Files are processed according to
lexicographical order of file names. Make sure that there is no file
processed before <html:code>02-rekey-limit.conf</html:code> containing definition of
<html:code>RekeyLimit</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_SSH_EXT.1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000423-GPOS-00187</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000033-GPOS-00014</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000424-GPOS-00188</xccdf-1.2:reference>
              <xccdf-1.2:rationale>By decreasing the limit based on the amount of data and enabling
time-based limit, effects of potential attacks against
encryption keys are limited.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="ssh_client_rekey_limit" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q openssh-clients; then

var_ssh_client_rekey_limit_size='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_size" use="legacy"/>'
var_ssh_client_rekey_limit_time='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_time" use="legacy"/>'
main_config="/etc/ssh/ssh_config"
include_directory="/etc/ssh/ssh_config.d"

if grep -q '^[\s]*RekeyLimit.*$' "$main_config"; then
  sed -i '/^[\s]*RekeyLimit.*/d' "$main_config"
fi

for file in "$include_directory"/*.conf; do
  if grep -q '^[\s]*RekeyLimit.*$' "$file"; then
    sed -i '/^[\s]*RekeyLimit.*/d' "$file"
  fi
done

if [ -e "/etc/ssh/ssh_config.d/02-rekey-limit.conf" ] ; then
    
    LC_ALL=C sed -i "/^\s*RekeyLimit\s\+/d" "/etc/ssh/ssh_config.d/02-rekey-limit.conf"
else
    touch "/etc/ssh/ssh_config.d/02-rekey-limit.conf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/ssh_config.d/02-rekey-limit.conf"

cp "/etc/ssh/ssh_config.d/02-rekey-limit.conf" "/etc/ssh/ssh_config.d/02-rekey-limit.conf.bak"
# Insert at the end of the file
printf '%s\n' "RekeyLimit $var_ssh_client_rekey_limit_size $var_ssh_client_rekey_limit_time" &gt;&gt; "/etc/ssh/ssh_config.d/02-rekey-limit.conf"
# Clean up after ourselves.
rm "/etc/ssh/ssh_config.d/02-rekey-limit.conf.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="ssh_client_rekey_limit" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - ssh_client_rekey_limit
- name: XCCDF Value var_ssh_client_rekey_limit_size # promote to variable
  set_fact:
    var_ssh_client_rekey_limit_size: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_size" use="legacy"/>
  tags:
    - always
- name: XCCDF Value var_ssh_client_rekey_limit_time # promote to variable
  set_fact:
    var_ssh_client_rekey_limit_time: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_time" use="legacy"/>
  tags:
    - always

- name: Ensure RekeyLimit is not configured in /etc/ssh/ssh_config
  ansible.builtin.lineinfile:
    path: /etc/ssh/ssh_config
    create: false
    regexp: ^\s*RekeyLimit.*$
    state: absent
  when: '"openssh-clients" in ansible_facts.packages'
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - ssh_client_rekey_limit

- name: Collect all include config files for ssh client which configure RekeyLimit
  ansible.builtin.find:
    paths: /etc/ssh/ssh_config.d
    contains: ^[\s]*RekeyLimit.*$
    patterns: '*.config'
  register: ssh_config_include_files
  when: '"openssh-clients" in ansible_facts.packages'
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - ssh_client_rekey_limit

- name: Remove all occurrences of RekeyLimit configuration from include config files
    of ssh client
  ansible.builtin.lineinfile:
    path: '{{ item }}'
    regexp: ^[\s]*RekeyLimit.*$
    state: absent
  loop: '{{ ssh_config_include_files.files }}'
  when: '"openssh-clients" in ansible_facts.packages'
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - ssh_client_rekey_limit

- name: Ensure that rekey limit is set to {{ var_ssh_client_rekey_limit_size }} {{
    var_ssh_client_rekey_limit_time }} in /etc/ssh/ssh_config.d/02-rekey-limit.conf
  ansible.builtin.lineinfile:
    path: /etc/ssh/ssh_config.d/02-rekey-limit.conf
    create: true
    regexp: ^\s*RekeyLimit.*$
    line: RekeyLimit {{ var_ssh_client_rekey_limit_size }} {{ var_ssh_client_rekey_limit_time
      }}
    state: present
  when: '"openssh-clients" in ansible_facts.packages'
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - ssh_client_rekey_limit
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_ssh_client_rekey_limit_time:var:1" value-id="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_time"/>
                <xccdf-1.2:check-export export-name="oval:ssg-var_ssh_client_rekey_limit_size:var:1" value-id="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_size"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ssh_client_rekey_limit:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ssh_client_rekey_limit_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ssh_client_use_strong_rng_csh" selected="false" severity="medium">
              <xccdf-1.2:title>SSH client uses strong entropy to seed (for CSH like shells)</xccdf-1.2:title>
              <xccdf-1.2:description>To set up SSH client to use entropy from a high-quality source, make sure
that the appropriate shell environment variable is configured. The
<html:code>SSH_USE_STRONG_RNG</html:code> environment variable determines how many bytes
of entropy to use. Make sure that the file
<html:code>/etc/profile.d/cc-ssh-strong-rng.csh</html:code> contains line
<html:pre>setenv SSH_USE_STRONG_RNG 32</html:pre>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Some SSH implementations use the openssl library for entropy, which by default, doesn't use high-entropy sources.
Randomness is needed to generate considerably more secure data-encryption keys. Plaintext padding, initialization vectors
in encryption algorithms, and high-quality entropy eliminates the possibility that the output of
the random number generator used by SSH would be known to potential attackers.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="ssh_client_use_strong_rng_csh" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q openssh-clients; then

# put line into the file
echo "setenv SSH_USE_STRONG_RNG 32" &gt; /etc/profile.d/cc-ssh-strong-rng.csh

# remove eventual override in /etc/profile
sed -i '/^[[:space:]]*setenv[[:space:]]\+SSH_USE_STRONG_RNG.*$/d' /etc/profile

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="ssh_client_use_strong_rng_csh" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - ssh_client_use_strong_rng_csh

- name: Ensure that correct variable is exported in /etc/profile.d/cc-ssh-strong-rng.csh
  ansible.builtin.lineinfile:
    path: /etc/profile.d/cc-ssh-strong-rng.csh
    regexp: ^[\s]*setenv[\s]+SSH_USE_STRONG_RNG.*$
    line: setenv SSH_USE_STRONG_RNG 32
    state: present
    create: true
  when: '"openssh-clients" in ansible_facts.packages'
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - ssh_client_use_strong_rng_csh

- name: Ensure that the configuration is not overridden in /etc/profile
  ansible.builtin.lineinfile:
    path: /etc/profile
    regexp: ^[\s]*setenv[\s]+SSH_USE_STRONG_RNG.*$
    state: absent
  when: '"openssh-clients" in ansible_facts.packages'
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - ssh_client_use_strong_rng_csh
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ssh_client_use_strong_rng_csh:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ssh_client_use_strong_rng_csh_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ssh_client_use_strong_rng_sh" selected="false" severity="medium">
              <xccdf-1.2:title>SSH client uses strong entropy to seed (Bash-like shells)</xccdf-1.2:title>
              <xccdf-1.2:description>To set up SSH client to use entropy from a high-quality source, make sure
that the appropriate shell environment variable is configured. The
<html:code>SSH_USE_STRONG_RNG</html:code> environment variable determines how many bytes
of entropy to use. Make sure that the file
<html:code>/etc/profile.d/cc-ssh-strong-rng.sh</html:code> contains line
<html:pre>export SSH_USE_STRONG_RNG=32</html:pre>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Some SSH implementations use the openssl library for entropy, which by default, doesn't use high-entropy sources.
Randomness is needed to generate considerably more secure data-encryption keys. Plaintext padding, initialization vectors
in encryption algorithms, and high-quality entropy eliminates the possibility that the output of
the random number generator used by SSH would be known to potential attackers.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="ssh_client_use_strong_rng_sh" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q openssh-clients; then

# put line into the file
echo "export SSH_USE_STRONG_RNG=32" &gt; /etc/profile.d/cc-ssh-strong-rng.sh

# remove eventual override in /etc/profile
sed -i '/^[[:space:]]*export[[:space:]]\+SSH_USE_STRONG_RNG=.*$/d' /etc/profile

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="ssh_client_use_strong_rng_sh" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - ssh_client_use_strong_rng_sh

- name: Ensure that correct variable is exported in /etc/profile.d/cc-ssh-strong-rng.sh
  ansible.builtin.lineinfile:
    path: /etc/profile.d/cc-ssh-strong-rng.sh
    regexp: ^[\s]*export[\s]+SSH_USE_STRONG_RNG=.*$
    line: export SSH_USE_STRONG_RNG=32
    state: present
    create: true
  when: '"openssh-clients" in ansible_facts.packages'
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - ssh_client_use_strong_rng_sh

- name: Ensure that the configuration is not overridden in /etc/profile
  ansible.builtin.lineinfile:
    path: /etc/profile
    regexp: ^[\s]*export[\s]+SSH_USE_STRONG_RNG=.*$
    state: absent
  when: '"openssh-clients" in ansible_facts.packages'
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - ssh_client_use_strong_rng_sh
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-ssh_client_use_strong_rng_sh:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ssh_client_use_strong_rng_sh_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_ssh_keys_passphrase_protected" selected="false" severity="medium">
              <xccdf-1.2:title>Verify the SSH Private Key Files Have a Passcode</xccdf-1.2:title>
              <xccdf-1.2:description>When creating SSH key pairs, always use a passcode.
<html:br/>
You can create such keys with the following command:
<html:pre>$ sudo ssh-keygen -n [passphrase]</html:pre>
AlmaLinux OS 8, for certificate-based authentication, must enforce authorized access to the corresponding private key.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000067-GPOS-00035</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010100</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230230r1069287_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If an unauthorized user obtains access to a private key without a passcode,
that user would have unauthorized access to any system where the associated
public key has been installed.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-ssh_keys_passphrase_protected_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_ssh_server">
            <xccdf-1.2:title>Configure OpenSSH Server if Necessary</xccdf-1.2:title>
            <xccdf-1.2:description>If the system needs to act as an SSH server, then
certain changes should be made to the OpenSSH daemon configuration
file <html:code>/etc/ssh/sshd_config</html:code>. The following recommendations can be
applied to this file. See the <html:code>sshd_config(5)</html:code> man page for more
detailed information.</xccdf-1.2:description>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_rekey_limit_size" type="string">
              <xccdf-1.2:title>SSH RekeyLimit - size</xccdf-1.2:title>
              <xccdf-1.2:description>Specify the size component of the rekey limit.</xccdf-1.2:description>
              <xccdf-1.2:value selector="sshd_default">default</xccdf-1.2:value>
              <xccdf-1.2:value>512M</xccdf-1.2:value>
              <xccdf-1.2:value selector="512M">512M</xccdf-1.2:value>
              <xccdf-1.2:value selector="1G">1G</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_rekey_limit_time" type="string">
              <xccdf-1.2:title>SSH RekeyLimit - size</xccdf-1.2:title>
              <xccdf-1.2:description>Specify the size component of the rekey limit.</xccdf-1.2:description>
              <xccdf-1.2:value selector="sshd_default">none</xccdf-1.2:value>
              <xccdf-1.2:value>1h</xccdf-1.2:value>
              <xccdf-1.2:value selector="1hour">1h</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sshd_disable_compression" type="string">
              <xccdf-1.2:title>SSH Compression Setting</xccdf-1.2:title>
              <xccdf-1.2:description>Specify the compression setting for SSH connections.</xccdf-1.2:description>
              <xccdf-1.2:value selector="no">no</xccdf-1.2:value>
              <xccdf-1.2:value selector="delayed">delayed</xccdf-1.2:value>
              <xccdf-1.2:value>no</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sshd_priv_separation" type="string">
              <xccdf-1.2:title>SSH Privilege Separation Setting</xccdf-1.2:title>
              <xccdf-1.2:description>Specify whether and how sshd separates privileges when handling incoming network connections.</xccdf-1.2:description>
              <xccdf-1.2:value selector="no">no</xccdf-1.2:value>
              <xccdf-1.2:value selector="yes">yes</xccdf-1.2:value>
              <xccdf-1.2:value selector="sandbox">sandbox</xccdf-1.2:value>
              <xccdf-1.2:value>sandbox</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sshd_set_login_grace_time" interactive="true" type="number">
              <xccdf-1.2:title>SSH LoginGraceTime setting</xccdf-1.2:title>
              <xccdf-1.2:description>Configure parameters for how long the servers stays connected before the user has successfully logged in</xccdf-1.2:description>
              <xccdf-1.2:value>60</xccdf-1.2:value>
              <xccdf-1.2:value selector="60">60</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sshd_set_maxstartups" interactive="true" type="string">
              <xccdf-1.2:title>SSH MaxStartups setting</xccdf-1.2:title>
              <xccdf-1.2:description>Configure parameters for maximum concurrent unauthenticated connections to the SSH daemon.</xccdf-1.2:description>
              <xccdf-1.2:value>10:30:100</xccdf-1.2:value>
              <xccdf-1.2:value selector="10:30:60">10:30:60</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_set_keepalive_0" selected="false" severity="medium">
              <xccdf-1.2:title>Set SSH Client Alive Count Max to zero</xccdf-1.2:title>
              <xccdf-1.2:description>The SSH server sends at most <html:code>ClientAliveCountMax</html:code> messages
during a SSH session and waits for a response from the SSH client.
The option <html:code>ClientAliveInterval</html:code> configures timeout after
each <html:code>ClientAliveCountMax</html:code> message. If the SSH server does not
receive a response from the client, then the connection is considered unresponsive
and terminated.

To ensure the SSH timeout occurs precisely when the
<html:code>ClientAliveInterval</html:code> is set, set the <html:code>ClientAliveCountMax</html:code> to
value of <html:code>0</html:code> in




<html:code>/etc/ssh/sshd_config</html:code>:</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(5)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000126-GPOS-00066</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000163-GPOS-00072</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000279-GPOS-00109</xccdf-1.2:reference>
              <xccdf-1.2:rationale>This ensures a user login will be terminated as soon as the <html:code>ClientAliveInterval</html:code>
is reached.</xccdf-1.2:rationale>
              <xccdf-1.2:requires idref="xccdf_org.ssgproject.content_rule_sshd_set_idle_timeout"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_keepalive_0" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*ClientAliveCountMax\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "ClientAliveCountMax 0" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_keepalive_0" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.6
  - NIST-800-171-3.1.11
  - NIST-800-53-AC-12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-2(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-10
  - PCI-DSS-Req-8.1.8
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_keepalive_0

- name: Set SSH Client Alive Count Max to zero
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*ClientAliveCountMax\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*ClientAliveCountMax\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*ClientAliveCountMax\s+
      line: ClientAliveCountMax 0
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.5.6
  - NIST-800-171-3.1.11
  - NIST-800-53-AC-12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-2(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-10
  - PCI-DSS-Req-8.1.8
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_keepalive_0
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_set_keepalive_0:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_set_keepalive_0_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_set_keepalive" selected="false" severity="medium">
              <xccdf-1.2:title>Set SSH Client Alive Count Max</xccdf-1.2:title>
              <xccdf-1.2:description>The SSH server sends at most <html:code>ClientAliveCountMax</html:code> messages
during a SSH session and waits for a response from the SSH client.
The option <html:code>ClientAliveInterval</html:code> configures timeout after
each <html:code>ClientAliveCountMax</html:code> message. If the SSH server does not
receive a response from the client, then the connection is considered unresponsive
and terminated.
For SSH earlier than v8.2, a <html:code>ClientAliveCountMax</html:code> value of <html:code>0</html:code>
causes a timeout precisely when the <html:code>ClientAliveInterval</html:code> is set.
Starting with v8.2, a value of <html:code>0</html:code> disables the timeout functionality
completely. If the option is set to a number greater than <html:code>0</html:code>, then
the session will be disconnected after
<html:code>ClientAliveInterval * ClientAliveCountMax</html:code> seconds without receiving
a keep alive message.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(5)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000163-GPOS-00072</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000279-GPOS-00109</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010200</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230244r1069300_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>This ensures a user login will be terminated as soon as the <html:code>ClientAliveInterval</html:code>
is reached.</xccdf-1.2:rationale>
              <xccdf-1.2:requires idref="xccdf_org.ssgproject.content_rule_sshd_set_idle_timeout"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_keepalive" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_sshd_set_keepalive='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sshd_set_keepalive" use="legacy"/>'

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*ClientAliveCountMax\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "ClientAliveCountMax $var_sshd_set_keepalive" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_keepalive" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.6
  - DISA-STIG-RHEL-08-010200
  - NIST-800-171-3.1.11
  - NIST-800-53-AC-12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-2(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-10
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_keepalive
- name: XCCDF Value var_sshd_set_keepalive # promote to variable
  set_fact:
    var_sshd_set_keepalive: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sshd_set_keepalive" use="legacy"/>
  tags:
    - always

- name: Set SSH Client Alive Count Max
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*ClientAliveCountMax\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*ClientAliveCountMax\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*ClientAliveCountMax\s+
      line: ClientAliveCountMax {{ var_sshd_set_keepalive }}
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.5.6
  - DISA-STIG-RHEL-08-010200
  - NIST-800-171-3.1.11
  - NIST-800-53-AC-12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-2(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-10
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_keepalive
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sshd_set_keepalive:var:1" value-id="xccdf_org.ssgproject.content_value_var_sshd_set_keepalive"/>
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_set_keepalive:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_set_idle_timeout" selected="false" severity="medium">
              <xccdf-1.2:title>Set SSH Client Alive Interval</xccdf-1.2:title>
              <xccdf-1.2:description>SSH allows administrators to set a network responsiveness timeout interval.
After this interval has passed, the unresponsive client will be automatically logged out.
<html:br/><html:br/>
To set this timeout interval, edit the following line in <html:code>/etc/ssh/sshd_config</html:code> as
follows:
<html:pre>ClientAliveInterval <html:b><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_idle_timeout_value" use="legacy"/></html:b></html:pre>
<html:br/><html:br/>
The timeout <html:b>interval</html:b> is given in seconds. For example, have a timeout
of 10 minutes, set <html:b>interval</html:b> to 600.
<html:br/><html:br/>
If a shorter timeout has already been set for the login shell, that value will
preempt any SSH setting made in <html:code>/etc/ssh/sshd_config</html:code>. Keep in mind that
some processes may stop SSH from correctly detecting that the user is idle.</xccdf-1.2:description>
              <xccdf-1.2:warning category="dependency">SSH disconnecting unresponsive clients will not have desired effect without also
configuring ClientAliveCountMax in the SSH service configuration.</xccdf-1.2:warning>
              <xccdf-1.2:warning category="general">Following conditions may prevent the SSH session to time out:
<html:ul><html:li>Remote processes on the remote machine generates output. As the output has to be transferred over the network to the client, the timeout is reset every time such transfer happens.</html:li><html:li>Any <html:code>scp</html:code> or <html:code>sftp</html:code> activity by the same user to the host resets the timeout.</html:li></html:ul></xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(5)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000126-GPOS-00066</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000163-GPOS-00072</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000279-GPOS-00109</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000395-GPOS-00175</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010201</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244525r1017331_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Terminating an idle ssh session within a short time period reduces the window of
opportunity for unauthorized personnel to take control of a management session
enabled on the console or console port that has been let unattended.</xccdf-1.2:rationale>
              <xccdf-1.2:requires idref="xccdf_org.ssgproject.content_rule_sshd_set_keepalive"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_idle_timeout" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

sshd_idle_timeout_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_idle_timeout_value" use="legacy"/>'

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*ClientAliveInterval\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "ClientAliveInterval $sshd_idle_timeout_value" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_idle_timeout" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.6
  - DISA-STIG-RHEL-08-010201
  - NIST-800-171-3.1.11
  - NIST-800-53-AC-12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-2(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-10
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_idle_timeout
- name: XCCDF Value sshd_idle_timeout_value # promote to variable
  set_fact:
    sshd_idle_timeout_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_idle_timeout_value" use="legacy"/>
  tags:
    - always

- name: Set SSH Client Alive Interval
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*ClientAliveInterval\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*ClientAliveInterval\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*ClientAliveInterval\s+
      line: ClientAliveInterval {{ sshd_idle_timeout_value }}
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.5.6
  - DISA-STIG-RHEL-08-010201
  - NIST-800-171-3.1.11
  - NIST-800-53-AC-12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-2(5)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-10
  - PCI-DSS-Req-8.1.8
  - PCI-DSSv4-8.2
  - PCI-DSSv4-8.2.8
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_idle_timeout
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sshd_set_keepalive:var:1" value-id="xccdf_org.ssgproject.content_value_var_sshd_set_keepalive"/>
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_idle_timeout_value:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_idle_timeout_value"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_set_idle_timeout:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_set_idle_timeout_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_disable_host_auth" selected="false" severity="medium">
              <xccdf-1.2:title>Disable Host-Based Authentication</xccdf-1.2:title>
              <xccdf-1.2:description>SSH's cryptographic host-based authentication is
more secure than <html:code>.rhosts</html:code> authentication. However, it is
not recommended that hosts unilaterally trust one another, even
within an organization.
<html:br/>
The default SSH configuration disables host-based authentication. The appropriate
configuration is used if no value is set for <html:code>HostbasedAuthentication</html:code>.
<html:br/>
To explicitly disable host-based authentication, add or correct the
following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>HostbasedAuthentication no</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_UAU.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00229</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0484</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">8.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.12</xccdf-1.2:reference>
              <xccdf-1.2:rationale>SSH trust relationships mean a compromise on one host
can allow an attacker to move trivially to other hosts.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="disable_host_auth" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*HostbasedAuthentication\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "HostbasedAuthentication no" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="disable_host_auth" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.6
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-3
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.1
  - disable_host_auth
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Disable Host-Based Authentication
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*HostbasedAuthentication\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*HostbasedAuthentication\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*HostbasedAuthentication\s+
      line: HostbasedAuthentication no
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.5.6
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-3
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-8.3
  - PCI-DSSv4-8.3.1
  - disable_host_auth
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="disable_host_auth" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
metadata:
  annotations:
    complianceascode.io/ocp-version: '&lt;=4.12'
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,%23%09%24OpenBSD%3A%20sshd_config%2Cv%201.103%202018%2F04%2F09%2020%3A41%3A22%20tj%20Exp%20%24%0A%0A%23%20This%20is%20the%20sshd%20server%20system-wide%20configuration%20file.%20%20See%0A%23%20sshd_config%285%29%20for%20more%20information.%0A%0A%23%20This%20sshd%20was%20compiled%20with%20PATH%3D%2Fusr%2Flocal%2Fbin%3A%2Fusr%2Fbin%3A%2Fusr%2Flocal%2Fsbin%3A%2Fusr%2Fsbin%0A%0A%23%20The%20strategy%20used%20for%20options%20in%20the%20default%20sshd_config%20shipped%20with%0A%23%20OpenSSH%20is%20to%20specify%20options%20with%20their%20default%20value%20where%0A%23%20possible%2C%20but%20leave%20them%20commented.%20%20Uncommented%20options%20override%20the%0A%23%20default%20value.%0A%0A%23%20If%20you%20want%20to%20change%20the%20port%20on%20a%20SELinux%20system%2C%20you%20have%20to%20tell%0A%23%20SELinux%20about%20this%20change.%0A%23%20semanage%20port%20-a%20-t%20ssh_port_t%20-p%20tcp%20%23PORTNUMBER%0A%23%0A%23Port%2022%0A%23AddressFamily%20any%0A%23ListenAddress%200.0.0.0%0A%23ListenAddress%20%3A%3A%0A%0AHostKey%20%2Fetc%2Fssh%2Fssh_host_rsa_key%0AHostKey%20%2Fetc%2Fssh%2Fssh_host_ecdsa_key%0AHostKey%20%2Fetc%2Fssh%2Fssh_host_ed25519_key%0A%0A%23%20Ciphers%20and%20keying%0ARekeyLimit%20512M%201h%0A%0A%23%20System-wide%20Crypto%20policy%3A%0A%23%20This%20system%20is%20following%20system-wide%20crypto%20policy.%20The%20changes%20to%0A%23%20Ciphers%2C%20MACs%2C%20KexAlgoritms%20and%20GSSAPIKexAlgorithsm%20will%20not%20have%20any%0A%23%20effect%20here.%20They%20will%20be%20overridden%20by%20command-line%20options%20passed%20on%0A%23%20the%20server%20start%20up.%0A%23%20To%20opt%20out%2C%20uncomment%20a%20line%20with%20redefinition%20of%20%20CRYPTO_POLICY%3D%0A%23%20variable%20in%20%20%2Fetc%2Fsysconfig%2Fsshd%20%20to%20overwrite%20the%20policy.%0A%23%20For%20more%20information%2C%20see%20manual%20page%20for%20update-crypto-policies%288%29.%0A%0A%23%20Logging%0A%23SyslogFacility%20AUTH%0ASyslogFacility%20AUTHPRIV%0A%23LogLevel%20INFO%0A%0A%23%20Authentication%3A%0A%0A%23LoginGraceTime%202m%0APermitRootLogin%20no%0AStrictModes%20yes%0A%23MaxAuthTries%206%0A%23MaxSessions%2010%0A%0APubkeyAuthentication%20yes%0A%0A%23%20The%20default%20is%20to%20check%20both%20.ssh%2Fauthorized_keys%20and%20.ssh%2Fauthorized_keys2%0A%23%20but%20this%20is%20overridden%20so%20installations%20will%20only%20check%20.ssh%2Fauthorized_keys%0AAuthorizedKeysFile%09.ssh%2Fauthorized_keys%0A%0A%23AuthorizedPrincipalsFile%20none%0A%0A%23AuthorizedKeysCommand%20none%0A%23AuthorizedKeysCommandUser%20nobody%0A%0A%23%20For%20this%20to%20work%20you%20will%20also%20need%20host%20keys%20in%20%2Fetc%2Fssh%2Fssh_known_hosts%0AHostbasedAuthentication%20no%0A%23%20Change%20to%20yes%20if%20you%20don%27t%20trust%20~%2F.ssh%2Fknown_hosts%20for%0A%23%20HostbasedAuthentication%0AIgnoreUserKnownHosts%20yes%0A%23%20Don%27t%20read%20the%20user%27s%20~%2F.rhosts%20and%20~%2F.shosts%20files%0AIgnoreRhosts%20yes%0A%0A%23%20To%20disable%20tunneled%20clear%20text%20passwords%2C%20change%20to%20no%20here%21%0A%23PasswordAuthentication%20yes%0APermitEmptyPasswords%20no%0APasswordAuthentication%20no%0A%0A%23%20Change%20to%20no%20to%20disable%20s%2Fkey%20passwords%0A%23ChallengeResponseAuthentication%20yes%0AChallengeResponseAuthentication%20no%0A%0A%23%20Kerberos%20options%0AKerberosAuthentication%20no%0A%23KerberosOrLocalPasswd%20yes%0A%23KerberosTicketCleanup%20yes%0A%23KerberosGetAFSToken%20no%0A%23KerberosUseKuserok%20yes%0A%0A%23%20GSSAPI%20options%0AGSSAPIAuthentication%20no%0AGSSAPICleanupCredentials%20no%0A%23GSSAPIStrictAcceptorCheck%20yes%0A%23GSSAPIKeyExchange%20no%0A%23GSSAPIEnablek5users%20no%0A%0A%23%20Set%20this%20to%20%27yes%27%20to%20enable%20PAM%20authentication%2C%20account%20processing%2C%0A%23%20and%20session%20processing.%20If%20this%20is%20enabled%2C%20PAM%20authentication%20will%0A%23%20be%20allowed%20through%20the%20ChallengeResponseAuthentication%20and%0A%23%20PasswordAuthentication.%20%20Depending%20on%20your%20PAM%20configuration%2C%0A%23%20PAM%20authentication%20via%20ChallengeResponseAuthentication%20may%20bypass%0A%23%20the%20setting%20of%20%22PermitRootLogin%20without-password%22.%0A%23%20If%20you%20just%20want%20the%20PAM%20account%20and%20session%20checks%20to%20run%20without%0A%23%20PAM%20authentication%2C%20then%20enable%20this%20but%20set%20PasswordAuthentication%0A%23%20and%20ChallengeResponseAuthentication%20to%20%27no%27.%0A%23%20WARNING%3A%20%27UsePAM%20no%27%20is%20not%20supported%20in%20Fedora%20and%20may%20cause%20several%0A%23%20problems.%0AUsePAM%20yes%0A%0A%23AllowAgentForwarding%20yes%0A%23AllowTcpForwarding%20yes%0A%23GatewayPorts%20no%0AX11Forwarding%20yes%0A%23X11DisplayOffset%2010%0A%23X11UseLocalhost%20yes%0A%23PermitTTY%20yes%0A%0A%23%20It%20is%20recommended%20to%20use%20pam_motd%20in%20%2Fetc%2Fpam.d%2Fsshd%20instead%20of%20PrintMotd%2C%0A%23%20as%20it%20is%20more%20configurable%20and%20versatile%20than%20the%20built-in%20version.%0APrintMotd%20no%0A%0APrintLastLog%20yes%0A%23TCPKeepAlive%20yes%0APermitUserEnvironment%20no%0ACompression%20no%0AClientAliveInterval%20600%0AClientAliveCountMax%200%0A%23UseDNS%20no%0A%23PidFile%20%2Fvar%2Frun%2Fsshd.pid%0A%23MaxStartups%2010%3A30%3A100%0A%23PermitTunnel%20no%0A%23ChrootDirectory%20none%0A%23VersionAddendum%20none%0A%0A%23%20no%20default%20banner%20path%0ABanner%20%2Fetc%2Fissue%0A%0A%23%20Accept%20locale-related%20environment%20variables%0AAcceptEnv%20LANG%20LC_CTYPE%20LC_NUMERIC%20LC_TIME%20LC_COLLATE%20LC_MONETARY%20LC_MESSAGES%0AAcceptEnv%20LC_PAPER%20LC_NAME%20LC_ADDRESS%20LC_TELEPHONE%20LC_MEASUREMENT%0AAcceptEnv%20LC_IDENTIFICATION%20LC_ALL%20LANGUAGE%0AAcceptEnv%20XMODIFIERS%0A%0A%23%20override%20default%20of%20no%20subsystems%0ASubsystem%09sftp%09%2Fusr%2Flibexec%2Fopenssh%2Fsftp-server%0A%0A%23%20Example%20of%20overriding%20settings%20on%20a%20per-user%20basis%0A%23Match%20User%20anoncvs%0A%23%09X11Forwarding%20no%0A%23%09AllowTcpForwarding%20no%0A%23%09PermitTTY%20no%0A%23%09ForceCommand%20cvs%20server%0A%0AUsePrivilegeSeparation%20sandbox
        mode: 0600
        path: /etc/ssh/sshd_config
        overwrite: true
---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
metadata:
  annotations:
    complianceascode.io/ocp-version: '&gt;=4.13.0'
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ HostbasedAuthentication%20no }}
        mode: 0600
        path: /etc/ssh/sshd_config.d/00-complianceascode-disable_host_auth.conf
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-disable_host_auth:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-disable_host_auth_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_firewalld_sshd_port_enabled" selected="false" severity="medium">
              <xccdf-1.2:title>Enable SSH Server firewalld Firewall Exception</xccdf-1.2:title>
              <xccdf-1.2:description>If the SSH server is in use, inbound connections to SSH's port should be allowed to permit
remote access through SSH. In more restrictive firewalld settings, the SSH port should be
added to the proper firewalld zone in order to allow SSH remote access.
<html:br/><html:br/>

To configure <html:code>firewalld</html:code> to allow <html:code>ssh</html:code> access, run the following command(s):
<html:pre>firewall-cmd --permanent --add-service=ssh</html:pre>
Then run the following command to load the newly created rule(s):
<html:pre>firewall-cmd --reload</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">The remediation for this rule uses <html:code>firewall-cmd</html:code> and <html:code>nmcli</html:code> tools.
Therefore, it will only be executed if <html:code>firewalld</html:code> and <html:code>NetworkManager</html:code>
services are running. Otherwise, the remediation will be aborted and a informative message
will be shown in the remediation report.
These respective services will not be started in order to preserve any intentional change
in network components related to firewall and network interfaces.</xccdf-1.2:warning>
              <xccdf-1.2:warning category="general">This rule also checks if the SSH port was modified by the administrator in the firewalld
services definitions and is reflecting the expected port number. Although this is checked,
fixing the custom ssh.xml file placed by the administrator at /etc/firewalld/services it
is not in the scope of the remediation since there is no reliable way to manually change
the respective file. If the default SSH port is modified, it is on the administrator
responsibility to ensure the firewalld customizations in the service port level are
properly configured.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000096-GPOS-00050</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1416</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If inbound SSH connections are expected, adding the SSH port to the proper firewalld zone
will allow remote access through the SSH port.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="firewalld_sshd_port_enabled" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "firewalld" ; then
    yum install -y "firewalld"
fi
if ! rpm -q --quiet "NetworkManager" ; then
    yum install -y "NetworkManager"
fi
firewalld_sshd_zone='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_firewalld_sshd_zone" use="legacy"/>'


if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; }; then
    # By default, NetworkManager interfaces are created only once
    # container image is booted so we do not have information about
    # what interfaces will be created during container build time.
    # Therefore, we will rely on NetworkManager to automatically assign
    # interfaces to the default firewalld zone. For more details see:
    # https://firewalld.org/documentation/man-pages/firewalld.zone.html
    # https://firewalld.org/documentation/zone/connections-interfaces-and-sources.html
    # That also means this remediation only works if zone defined in
    # the firewalld_sshd_zone variable equals to the default zone of firewalld.
    default_zone=$(firewall-offline-cmd --get-default-zone)
    if [ "$firewalld_sshd_zone" != "$default_zone" ]; then
        echo "Firewalld default zone ($default_zone) and pre-set zone for sshd ($firewalld_sshd_zone) differ. Remediation aborted!" &gt;&amp;2
        exit 1
    fi

    # Make sure default zone is set in all existing NetworkManager keyfiles.
    while IFS= read -r -d '' file; do
        sed "s|^\s*zone=.*$|zone=$firewalld_sshd_zone|g" "$file"
    done &lt; &lt;(find /etc/NetworkManager/system-connections -maxdepth 1 -name "*.nmconnection" -print0)

    firewall-offline-cmd --zone="$firewalld_sshd_zone" --add-service=ssh
else
    if test "$(stat -c %d:%i /)" != "$(stat -c %d:%i /proc/1/root/.)"; then
        # TODO: NM (nmcli) now has --offline mode support, and it could operate without NM service.
        # See: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/1183
        # The feature is not quite straightforward (and probably incomplete), though.
        echo "Not applicable in offline mode. Remediation aborted!"
    else
        if systemctl is-active NetworkManager &amp;&amp; systemctl is-active firewalld; then
            # First make sure the SSH service is enabled in run-time for the proper zone.
            # This is to avoid connection issues when new interfaces are addeded to this zone.
            firewall-cmd --zone="$firewalld_sshd_zone" --add-service=ssh

            # This will collect all NetworkManager connections names
            readarray -t nm_connections &lt; &lt;(nmcli -g UUID,TYPE con | grep -v loopback | awk -F ':' '{ print $1 }')
            # If the connection is not yet assigned to a firewalld zone, assign it to the proper zone.
            # This will not change connections which are already assigned to any firewalld zone.
            for connection in "${nm_connections[@]}"; do
                current_zone=$(nmcli -f connection.zone connection show "$connection" | awk '{ print $2}')
                if [ $current_zone = "--" ]; then
                    nmcli connection modify "$connection" connection.zone $firewalld_sshd_zone
                fi
            done
            systemctl restart NetworkManager

            # Active zones are zones with at least one interface assigned to it.
            # It is possible that traffic is coming by any active interface and consequently any
            # active zone. So, this make sure all active zones are permanently allowing SSH service.
            readarray -t firewalld_active_zones &lt; &lt;(firewall-cmd --get-active-zones | grep -v "^ " | cut -d " " -f 1)
            for zone in "${firewalld_active_zones[@]}"; do
                firewall-cmd --permanent --zone="$zone" --add-service=ssh
            done
            firewall-cmd --reload
        else
            echo "The firewalld or NetworkManager service is not active. Remediation aborted!"
        fi
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="firewalld_sshd_port_enabled" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - firewalld_sshd_port_enabled
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
- name: XCCDF Value firewalld_sshd_zone # promote to variable
  set_fact:
    firewalld_sshd_zone: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_firewalld_sshd_zone" use="legacy"/>
  tags:
    - always

- name: Enable SSH Server firewalld Firewall Exception - Ensure firewalld and NetworkManager
    packages are installed
  ansible.builtin.package:
    name: '{{ item }}'
    state: present
  with_items:
  - firewalld
  - NetworkManager
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - firewalld_sshd_port_enabled
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Enable SSH Server firewalld Firewall Exception - Collect facts about system
    services
  ansible.builtin.service_facts: null
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - firewalld_sshd_port_enabled
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Enable SSH Server firewalld Firewall Exception - Remediation is applicable
    if firewalld and NetworkManager services are running
  block:

  - name: Enable SSH Server firewalld Firewall Exception - Collect NetworkManager
      connections names
    ansible.builtin.shell:
      cmd: nmcli -g UUID,TYPE con | grep -v loopback | awk -F ':' '{ print $1 }'
    register: result_nmcli_cmd_connections_names
    check_mode: false
    changed_when: false
    failed_when: false

  - name: Enable SSH Server firewalld Firewall Exception - Collect NetworkManager
      connections zones
    ansible.builtin.shell:
      cmd: nmcli -f connection.zone connection show {{ item | trim }} | awk '{ print
        $2}'
    register: result_nmcli_cmd_connections_zones
    changed_when: false
    failed_when: false
    with_items:
    - '{{ result_nmcli_cmd_connections_names.stdout_lines | default([]) }}'
    when:
    - result_nmcli_cmd_connections_names.stdout_lines is defined
    - result_nmcli_cmd_connections_names.stdout_lines | length &gt; 0

  - name: Enable SSH Server firewalld Firewall Exception - Ensure NetworkManager connections
      are assigned to a firewalld zone
    ansible.builtin.command:
      cmd: nmcli connection modify {{ item.0 }} connection.zone {{ firewalld_sshd_zone
        }}
    register: result_nmcli_cmd_zone_assignment
    changed_when: true
    with_together:
    - '{{ result_nmcli_cmd_connections_names.stdout_lines | default([]) }}'
    - '{{ result_nmcli_cmd_connections_zones.stdout_lines | default([]) }}'
    when:
    - result_nmcli_cmd_connections_zones.stdout_lines is defined
    - result_nmcli_cmd_connections_zones.stdout_lines | length &gt; 0
    - item.1.stdout == '--' or item.1.stdout != firewalld_sshd_zone

  - name: Enable SSH Server firewalld Firewall Exception - Ensure NetworkManager connections
      changes are applied
    ansible.builtin.service:
      name: NetworkManager
      state: restarted
    when:
    - result_nmcli_cmd_zone_assignment is defined
    - result_nmcli_cmd_zone_assignment is changed
    - (result_nmcli_cmd_zone_assignment.results | selectattr('changed', 'equalto',
      true) | list | length &gt; 0)

  - name: Enable SSH Server firewalld Firewall Exception - Collect firewalld active
      zones
    ansible.builtin.shell:
      cmd: firewall-cmd --get-active-zones | grep -v "^ " | cut -d " " -f 1
    register: result_firewall_cmd_zones_names
    changed_when: false
    failed_when: false

  - name: Enable SSH Server firewalld Firewall Exception - Ensure firewalld zones
      allow SSH
    ansible.posix.firewalld:
      zone: '{{ item }}'
      service: ssh
      permanent: true
      state: enabled
      immediate: true
    register: result_firewall_ssh_service_assignment
    with_items:
    - '{{ result_firewall_cmd_zones_names.stdout_lines | default([]) }}'
    when:
    - result_firewall_cmd_zones_names.stdout_lines is defined
    - result_firewall_cmd_zones_names.stdout_lines | length &gt; 0
  when:
  - '"kernel" in ansible_facts.packages'
  - ('firewalld.service' in ansible_facts.services and ansible_facts.services['firewalld.service'].state
    == 'running')
  - ('NetworkManager.service' in ansible_facts.services and ansible_facts.services['NetworkManager.service'].state
    == 'running')
  tags:
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - firewalld_sshd_port_enabled
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Enable SSH Server firewalld Firewall Exception - Informative message based
    on services states
  ansible.builtin.assert:
    that:
    - (ansible_check_mode or ('firewalld.service' in ansible_facts.services and ansible_facts.services['firewalld.service'].state
      == 'running'))
    - (ansible_check_mode or ('NetworkManager.service' in ansible_facts.services and
      ansible_facts.services['NetworkManager.service'].state == 'running'))
    fail_msg:
    - firewalld and NetworkManager services are not active. Remediation aborted!
    - This remediation could not be applied because it depends on firewalld
    - and NetworkManager services running.
    - The service is not started by this remediation in order to prevent connection
      issues.
    success_msg:
    - Enable SSH Server firewalld Firewall Exception remediation successfully executed
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(b)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - configure_strategy
  - firewalld_sshd_port_enabled
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_listening_port:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_listening_port"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-firewalld_sshd_port_enabled:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-firewalld_sshd_port_enabled_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_allow_only_protocol2" selected="false" severity="high">
              <xccdf-1.2:title>Allow Only SSH Protocol 2</xccdf-1.2:title>
              <xccdf-1.2:description>Only SSH protocol version 2 connections should be
permitted. The default setting in
<html:code>/etc/ssh/sshd_config</html:code> is correct, and can be
verified by ensuring that the following
line appears:
<html:pre>Protocol 2</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">As of <html:code>openssh-server</html:code> version <html:code>7.4</html:code> and above, the only protocol
supported is version 2, and line <html:pre>Protocol 2</html:pre> in
<html:code>/etc/ssh/sshd_config</html:code> is not necessary.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MA-4(6)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000074-GPOS-00042</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1483</xccdf-1.2:reference>
              <xccdf-1.2:rationale>SSH protocol version 1 is an insecure implementation of the SSH protocol and
has many well-known vulnerability exploits. Exploits of the SSH daemon could provide
immediate root access to the system.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_openssh-server_le_7_0"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_allow_only_protocol2" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { ( rpm --quiet -q openssh-server &amp;&amp; { real="$(epoch=$(rpm -q --queryformat '%{EPOCH}' openssh-server); version=$(rpm -q --queryformat '%{VERSION}' openssh-server); [ "$epoch" = "(none)" ] &amp;&amp; echo "0:$version" || echo "$epoch:$version")"; expected="0:7.0"; [[ "$real" != "$expected" ]] &amp;&amp; printf "%s\n%s" "$real" "$expected" | sort -VC; } ); }; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*Protocol\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "Protocol 2" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_allow_only_protocol2" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.6
  - NIST-800-171-3.1.13
  - NIST-800-171-3.5.4
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-13
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy
  - sshd_allow_only_protocol2

- name: Allow Only SSH Protocol 2
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*Protocol\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*Protocol\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*Protocol\s+
      line: Protocol 2
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when:
  - '"kernel" in ansible_facts.packages'
  - '"openssh-server" in ansible_facts.packages and (((((ansible_facts.packages["openssh-server"]
    | last)["epoch"]) != None) | ternary((ansible_facts.packages["openssh-server"]
    | last)["epoch"] ~ ":", "0:")) + ((ansible_facts.packages["openssh-server"] |
    last)["version"] | split("-") | first)) is version("0:7.0", "&lt;")'
  tags:
  - CJIS-5.5.6
  - NIST-800-171-3.1.13
  - NIST-800-171-3.5.4
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-13
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy
  - sshd_allow_only_protocol2
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_allow_only_protocol2:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_allow_only_protocol2_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_disable_compression" selected="false" severity="medium">
              <xccdf-1.2:title>Disable Compression Or Set Compression to delayed</xccdf-1.2:title>
              <xccdf-1.2:description>Compression is useful for slow network connections over long
distances but can cause performance issues on local LANs. If use of compression
is required, it should be enabled only after a user has authenticated; otherwise,
it should be disabled. To disable compression or delay compression until after
a user has successfully authenticated, add or correct the following line in the
<html:code>/etc/ssh/sshd_config</html:code> file:
<html:pre>Compression <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sshd_disable_compression" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If compression is allowed in an SSH connection prior to authentication,
vulnerabilities in the compression software could result in compromise of the
system from an unauthenticated connection, potentially with root privileges.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_compression" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_sshd_disable_compression='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sshd_disable_compression" use="legacy"/>'

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*Compression\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "Compression $var_sshd_disable_compression" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_compression" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_compression
- name: XCCDF Value var_sshd_disable_compression # promote to variable
  set_fact:
    var_sshd_disable_compression: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sshd_disable_compression" use="legacy"/>
  tags:
    - always

- name: Disable Compression Or Set Compression to delayed
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*Compression\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*Compression\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*Compression\s+
      line: Compression {{ var_sshd_disable_compression }}
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_compression
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sshd_disable_compression:var:1" value-id="xccdf_org.ssgproject.content_value_var_sshd_disable_compression"/>
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_disable_compression:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_disable_empty_passwords" selected="false" severity="high">
              <xccdf-1.2:title>Disable SSH Access via Empty Passwords</xccdf-1.2:title>
              <xccdf-1.2:description>Disallow SSH login with empty passwords.
The default SSH configuration disables logins with empty passwords. The appropriate
configuration is used if no value is set for <html:code>PermitEmptyPasswords</html:code>.
<html:br/>
To explicitly disallow SSH login from accounts with empty passwords,
add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:br/>
<html:pre>PermitEmptyPasswords no</html:pre>
Any accounts with empty passwords should be disabled immediately, and PAM configuration
should prevent users from being able to assign themselves empty passwords.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FIA_UAU.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000106-GPOS-00053</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00229</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.21</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020330</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230380r1069308_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Configuring this setting for the SSH daemon provides additional assurance
that remote login via SSH will require a password, even in the event of
misconfiguration elsewhere.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_empty_passwords" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*PermitEmptyPasswords\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "PermitEmptyPasswords no" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_empty_passwords" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.6
  - DISA-STIG-RHEL-08-020330
  - NIST-800-171-3.1.1
  - NIST-800-171-3.1.5
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSS-Req-2.2.4
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_empty_passwords

- name: Disable SSH Access via Empty Passwords
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PermitEmptyPasswords\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PermitEmptyPasswords\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PermitEmptyPasswords\s+
      line: PermitEmptyPasswords no
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.5.6
  - DISA-STIG-RHEL-08-020330
  - NIST-800-171-3.1.1
  - NIST-800-171-3.1.5
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSS-Req-2.2.4
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_empty_passwords
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_disable_empty_passwords:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_disable_forwarding" selected="false" severity="medium">
              <xccdf-1.2:title>Disable SSH Forwarding</xccdf-1.2:title>
              <xccdf-1.2:description>The DisableForwarding parameter disables all forwarding features, including X11,
ssh-agent(1), TCP and StreamLocal. This option overrides all other forwarding-related
options and may simplify restricted configurations.
<html:br/>
To explicitly disable SSHD forwarding, add or correct the following line in 



<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>DisableForwarding yes</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.10</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Disable ssh forwarding unless there is an operational requirement to use it. 
Leaving port forwarding enabled can expose the organization to security risks.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_forwarding" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*DisableForwarding\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "DisableForwarding yes" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_forwarding" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_forwarding

- name: Disable SSH Forwarding
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*DisableForwarding\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*DisableForwarding\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*DisableForwarding\s+
      line: DisableForwarding yes
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_forwarding
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_disable_forwarding:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_disable_forwarding_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth" selected="false" severity="medium">
              <xccdf-1.2:title>Disable GSSAPI Authentication</xccdf-1.2:title>
              <xccdf-1.2:description>Unless needed, SSH should not permit extraneous or unnecessary
authentication mechanisms like GSSAPI.
<html:br/>
The default SSH configuration disallows authentications based on GSSAPI. The appropriate
configuration is used if no value is set for <html:code>GSSAPIAuthentication</html:code>.
<html:br/>
To explicitly disable GSSAPI authentication, add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>GSSAPIAuthentication no</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FTP_ITC_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_SSH_EXT.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000364-GPOS-00151</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0418</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1055</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1402</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010522</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244528r1017335_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>GSSAPI authentication is used to provide additional authentication mechanisms to
applications. Allowing GSSAPI authentication through SSH exposes the system's
GSSAPI to remote hosts, increasing the attack surface of the system.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_gssapi_auth" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*GSSAPIAuthentication\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "GSSAPIAuthentication no" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_gssapi_auth" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010522
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_gssapi_auth

- name: Disable GSSAPI Authentication
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*GSSAPIAuthentication\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*GSSAPIAuthentication\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*GSSAPIAuthentication\s+
      line: GSSAPIAuthentication no
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010522
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_gssapi_auth
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_disable_gssapi_auth:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_disable_gssapi_auth_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_disable_kerb_auth" selected="false" severity="medium">
              <xccdf-1.2:title>Disable Kerberos Authentication</xccdf-1.2:title>
              <xccdf-1.2:description>Unless needed, SSH should not permit extraneous or unnecessary
authentication mechanisms like Kerberos.
<html:br/>
The default SSH configuration disallows authentication validation through Kerberos.
The appropriate configuration is used if no value is set for <html:code>KerberosAuthentication</html:code>.
<html:br/>
To explicitly disable Kerberos authentication, add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>KerberosAuthentication no</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FTP_ITC_EXT.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_SSH_EXT.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000364-GPOS-00151</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010521</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230291r1069303_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Kerberos authentication for SSH is often implemented using GSSAPI. If Kerberos
is enabled through SSH, the SSH daemon provides a means of access to the
system's Kerberos implementation.
Configuring these settings for the SSH daemon provides additional assurance that remote logon via SSH will not use unused methods of authentication, even in the event of misconfiguration elsewhere.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_kerb_auth" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*KerberosAuthentication\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "KerberosAuthentication no" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_kerb_auth" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010521
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_kerb_auth

- name: Disable Kerberos Authentication
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*KerberosAuthentication\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*KerberosAuthentication\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*KerberosAuthentication\s+
      line: KerberosAuthentication no
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010521
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_kerb_auth
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_disable_kerb_auth:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_disable_pubkey_auth" selected="false" severity="medium">
              <xccdf-1.2:title>Disable PubkeyAuthentication Authentication</xccdf-1.2:title>
              <xccdf-1.2:description>Unless needed, SSH should not permit extraneous or unnecessary
authentication mechanisms. To disable PubkeyAuthentication authentication, add or
correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>PubkeyAuthentication no</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>PubkeyAuthentication authentication is used to provide additional authentication mechanisms to
applications. Allowing PubkeyAuthentication authentication through SSH allows users to
generate their own authentication tokens, increasing the attack surface of the system.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_pubkey_auth" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*PubkeyAuthentication\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "PubkeyAuthentication no" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_pubkey_auth" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_pubkey_auth

- name: Disable PubkeyAuthentication Authentication
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PubkeyAuthentication\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PubkeyAuthentication\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PubkeyAuthentication\s+
      line: PubkeyAuthentication no
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_pubkey_auth
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_disable_pubkey_auth:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_disable_rhosts" selected="false" severity="medium">
              <xccdf-1.2:title>Disable SSH Support for .rhosts Files</xccdf-1.2:title>
              <xccdf-1.2:description>SSH can emulate the behavior of the obsolete rsh
command in allowing users to enable insecure access to their
accounts via <html:code>.rhosts</html:code> files.
<html:br/>
The default SSH configuration disables support for <html:code>.rhosts</html:code>. The appropriate
configuration is used if no value is set for <html:code>IgnoreRhosts</html:code>.
<html:br/>
To explicitly disable support for .rhosts files, add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>IgnoreRhosts yes</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.13</xccdf-1.2:reference>
              <xccdf-1.2:rationale>SSH trust relationships mean a compromise on one host
can allow an attacker to move trivially to other hosts.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_rhosts" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*IgnoreRhosts\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "IgnoreRhosts yes" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_rhosts" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.6
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_rhosts

- name: Disable SSH Support for .rhosts Files
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*IgnoreRhosts\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*IgnoreRhosts\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*IgnoreRhosts\s+
      line: IgnoreRhosts yes
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.5.6
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_rhosts
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_disable_rhosts:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_disable_rhosts_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_disable_rhosts_rsa" selected="false" severity="medium">
              <xccdf-1.2:title>Disable SSH Support for Rhosts RSA Authentication</xccdf-1.2:title>
              <xccdf-1.2:description>SSH can allow authentication through the obsolete rsh
command through the use of the authenticating user's SSH keys. This should be disabled.
<html:br/><html:br/>
To ensure this behavior is disabled, add or correct the
following line in <html:code>/etc/ssh/sshd_config</html:code>:
<html:pre>RhostsRSAAuthentication no</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">As of <html:code>openssh-server</html:code> version <html:code>7.4</html:code> and above,
the <html:code>RhostsRSAAuthentication</html:code> option has been deprecated, and the line
<html:pre>RhostsRSAAuthentication no</html:pre> in <html:code>/etc/ssh/sshd_config</html:code> is not
necessary.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Configuring this setting for the SSH daemon provides additional
assurance that remote login via SSH will require a password, even
in the event of misconfiguration elsewhere.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_rhosts_rsa" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*RhostsRSAAuthentication\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "RhostsRSAAuthentication no" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_rhosts_rsa" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_rhosts_rsa

- name: Disable SSH Support for Rhosts RSA Authentication
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*RhostsRSAAuthentication\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*RhostsRSAAuthentication\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*RhostsRSAAuthentication\s+
      line: RhostsRSAAuthentication no
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_rhosts_rsa
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_disable_rhosts_rsa:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="false" severity="medium">
              <xccdf-1.2:title>Disable SSH Root Login</xccdf-1.2:title>
              <xccdf-1.2:description>The root user should never be allowed to login to a
system directly over a network.
To disable root login via SSH, add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>PermitRootLogin no</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule is disabled on Red Hat Virtualization Hosts and Managers, it will report not applicable.
RHV hosts require root access to be managed by RHV Manager.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(5)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000109-GPOS-00056</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000148-CTR-000335</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000190-CTR-000500</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R33</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.22</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010550</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230296r1069322_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Even though the communications channel may be encrypted, an additional layer of
security is gained by extending the policy of not logging directly on as root.
In addition, logging in with a user-specific account provides individual
accountability of actions performed on the system and also helps to minimize
direct attack attempts on root's password.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#no_ovirt"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_root_login" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*PermitRootLogin\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "PermitRootLogin no" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_root_login" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.6
  - DISA-STIG-RHEL-08-010550
  - NIST-800-171-3.1.1
  - NIST-800-171-3.1.5
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(2)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-2
  - NIST-800-53-IA-2(5)
  - PCI-DSS-Req-2.2.4
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_root_login

- name: Disable SSH Root Login
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PermitRootLogin\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PermitRootLogin\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PermitRootLogin\s+
      line: PermitRootLogin no
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.5.6
  - DISA-STIG-RHEL-08-010550
  - NIST-800-171-3.1.1
  - NIST-800-171-3.1.5
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6(2)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - NIST-800-53-IA-2
  - NIST-800-53-IA-2(5)
  - PCI-DSS-Req-2.2.4
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_root_login
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_disable_root_login:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_disable_root_password_login" selected="false" severity="medium">
              <xccdf-1.2:title>Disable SSH root Login with a Password (Insecure)</xccdf-1.2:title>
              <xccdf-1.2:description>To disable password-based root logins over SSH, add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>PermitRootLogin prohibit-password</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">While this disables password-based root logins, direct root logins
through other means such as through SSH keys or GSSAPI will still be
permitted. Permitting any sort of root login remotely opens up the
root account to attack.
To fully disable direct root logins over SSH (which is considered a
best practice) and prevent remote attacks against the root account,
see CCE-27100-7, CCE-27445-6, CCE-80901-2, and similar.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>Even though the communications channel may be encrypted, an additional
layer of security is gained by preventing use of a password.
This also helps to minimize direct attack attempts on root's password.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_root_password_login" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*PermitRootLogin\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "PermitRootLogin prohibit-password" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_root_password_login" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_root_password_login

- name: Disable SSH root Login with a Password (Insecure)
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PermitRootLogin\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PermitRootLogin\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PermitRootLogin\s+
      line: PermitRootLogin prohibit-password
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_root_password_login
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_disable_root_password_login:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_disable_root_password_login_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_disable_tcp_forwarding" selected="false" severity="medium">
              <xccdf-1.2:title>Disable SSH TCP Forwarding</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>AllowTcpForwarding</html:code> parameter specifies whether TCP forwarding is permitted.
To disable TCP forwarding, add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>AllowTcpForwarding no</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Leaving port forwarding enabled can expose the organization to security risks and back-doors.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_tcp_forwarding" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*AllowTcpForwarding\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "AllowTcpForwarding no" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_tcp_forwarding" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_tcp_forwarding

- name: Disable SSH TCP Forwarding
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*AllowTcpForwarding\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*AllowTcpForwarding\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*AllowTcpForwarding\s+
      line: AllowTcpForwarding no
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_tcp_forwarding
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_disable_tcp_forwarding:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_disable_user_known_hosts" selected="false" severity="medium">
              <xccdf-1.2:title>Disable SSH Support for User Known Hosts</xccdf-1.2:title>
              <xccdf-1.2:description>SSH can allow system users to connect to systems if a cache of the remote
systems public keys is available.  This should be disabled.
<html:br/><html:br/>
To ensure this behavior is disabled, add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>IgnoreUserKnownHosts yes</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010520</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230290r1069302_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Configuring this setting for the SSH daemon provides additional
assurance that remote login via SSH will require a password, even
in the event of misconfiguration elsewhere.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_user_known_hosts" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*IgnoreUserKnownHosts\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "IgnoreUserKnownHosts yes" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_user_known_hosts" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010520
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_user_known_hosts

- name: Disable SSH Support for User Known Hosts
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*IgnoreUserKnownHosts\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*IgnoreUserKnownHosts\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*IgnoreUserKnownHosts\s+
      line: IgnoreUserKnownHosts yes
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010520
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_user_known_hosts
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_disable_user_known_hosts:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_disable_x11_forwarding" selected="false" severity="medium">
              <xccdf-1.2:title>Disable X11 Forwarding</xccdf-1.2:title>
              <xccdf-1.2:description>The X11Forwarding parameter provides the ability to tunnel X11 traffic
through the connection to enable remote graphic connections.
SSH has the capability to encrypt remote X11 connections when SSH's
<html:code>X11Forwarding</html:code> option is enabled.
<html:br/>
The default SSH configuration disables X11Forwarding. The appropriate
configuration is used if no value is set for <html:code>X11Forwarding</html:code>.
<html:br/>
To explicitly disable X11 Forwarding, add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>X11Forwarding no</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0484</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040340</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230555r1017317_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Disable X11 forwarding unless there is an operational requirement to use X11
applications directly. There is a small risk that the remote X11 servers of
users who are logged in via SSH with X11 forwarding could be compromised by
other users on the X11 server. Note that even if X11 forwarding is disabled,
users can always install their own forwarders.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_x11_forwarding" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*X11Forwarding\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "X11Forwarding no" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_disable_x11_forwarding" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040340
  - NIST-800-53-CM-6(b)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_x11_forwarding

- name: Disable X11 Forwarding
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*X11Forwarding\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*X11Forwarding\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*X11Forwarding\s+
      line: X11Forwarding no
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040340
  - NIST-800-53-CM-6(b)
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_disable_x11_forwarding
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_disable_x11_forwarding:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_do_not_permit_user_env" selected="false" severity="medium">
              <xccdf-1.2:title>Do Not Allow SSH Environment Options</xccdf-1.2:title>
              <xccdf-1.2:description>Ensure that users are not able to override environment variables of the SSH daemon.
<html:br/>
The default SSH configuration disables environment processing. The appropriate
configuration is used if no value is set for <html:code>PermitUserEnvironment</html:code>.
<html:br/>
To explicitly disable Environment options, add or correct the following




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>PermitUserEnvironment no</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00229</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.23</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010830</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230330r1069305_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>SSH environment options potentially allow users to bypass
access restriction in some configurations.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_do_not_permit_user_env" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*PermitUserEnvironment\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "PermitUserEnvironment no" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_do_not_permit_user_env" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.6
  - DISA-STIG-RHEL-08-010830
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSS-Req-2.2.4
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_do_not_permit_user_env

- name: Do Not Allow SSH Environment Options
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PermitUserEnvironment\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PermitUserEnvironment\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PermitUserEnvironment\s+
      line: PermitUserEnvironment no
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.5.6
  - DISA-STIG-RHEL-08-010830
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - PCI-DSS-Req-2.2.4
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_do_not_permit_user_env
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_do_not_permit_user_env:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_enable_gssapi_auth" selected="false" severity="medium">
              <xccdf-1.2:title>Enable GSSAPI Authentication</xccdf-1.2:title>
              <xccdf-1.2:description>Sites setup to use Kerberos or other GSSAPI Authentication require setting
sshd to accept this authentication.
To enable GSSAPI authentication, add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>GSSAPIAuthentication yes</html:pre></xccdf-1.2:description>
              <xccdf-1.2:rationale>Kerberos authentication for SSH is often implemented using GSSAPI. If
Kerberos is enabled through SSH, the SSH daemon provides a means of access
to the system's Kerberos implementation. Vulnerabilities in the system's
Kerberos implementations may be subject to exploitation.

For enterprises, Kerberos is often enabled and used with GSSAPI for 
centralized user account management which may necessitate enabling of
GSSAPI functionality in SSH. </xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_enable_gssapi_auth" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*GSSAPIAuthentication\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "GSSAPIAuthentication yes" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_enable_gssapi_auth" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_enable_gssapi_auth

- name: Enable GSSAPI Authentication
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*GSSAPIAuthentication\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*GSSAPIAuthentication\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*GSSAPIAuthentication\s+
      line: GSSAPIAuthentication yes
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_enable_gssapi_auth
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_enable_gssapi_auth:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_enable_gssapi_auth_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_enable_pam" selected="false" severity="medium">
              <xccdf-1.2:title>Enable PAM</xccdf-1.2:title>
              <xccdf-1.2:description>UsePAM Enables the Pluggable Authentication Module interface. If set to “yes” this will
enable PAM authentication using ChallengeResponseAuthentication and
PasswordAuthentication in addition to PAM account and session module processing for all
authentication types.

To enable PAM authentication, add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>UsePAM yes</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000125-GPOS-00065</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.24</xccdf-1.2:reference>
              <xccdf-1.2:rationale>When UsePAM is set to yes, PAM runs through account and session types properly. This is
important if you want to restrict access to services based off of IP, time or other factors of
the account. Additionally, you can make sure users inherit certain environment variables
on login or disallow access to the server.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_enable_pam" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*UsePAM\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "UsePAM yes" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_enable_pam" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_enable_pam

- name: Enable PAM
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*UsePAM\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*UsePAM\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*UsePAM\s+
      line: UsePAM yes
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_enable_pam
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_enable_pam:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_enable_pam_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_enable_pubkey_auth" selected="false" severity="medium">
              <xccdf-1.2:title>Enable Public Key Authentication</xccdf-1.2:title>
              <xccdf-1.2:description>Enable SSH login with public keys.
<html:br/>
The default SSH configuration enables authentication based on public keys. The appropriate
configuration is used if no value is set for <html:code>PubkeyAuthentication</html:code>.
<html:br/>
To explicitly enable Public Key Authentication, add or correct the following




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>PubkeyAuthentication yes</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000105-GPOS-00052</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000106-GPOS-00053</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000107-GPOS-00054</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000108-GPOS-00055</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Without the use of multifactor authentication, the ease of access to
privileged functions is greatly increased. Multifactor authentication
requires using two or more factors to achieve authentication.
A privileged account is defined as an information system account with
authorizations of a privileged user. 
Smart cards or hardware tokens paired with digital certificates are
common examples of multifactor implementations.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_enable_pubkey_auth" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*PubkeyAuthentication\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "PubkeyAuthentication yes" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_enable_pubkey_auth" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_enable_pubkey_auth

- name: Enable Public Key Authentication
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PubkeyAuthentication\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PubkeyAuthentication\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PubkeyAuthentication\s+
      line: PubkeyAuthentication yes
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_enable_pubkey_auth
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_enable_pubkey_auth:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_enable_pubkey_auth_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_enable_strictmodes" selected="false" severity="medium">
              <xccdf-1.2:title>Enable Use of Strict Mode Checking</xccdf-1.2:title>
              <xccdf-1.2:description>SSHs <html:code>StrictModes</html:code> option checks file and ownership permissions in
the user's home directory <html:code>.ssh</html:code> folder before accepting login. If world-
writable permissions are found, logon is rejected.
<html:br/>
The default SSH configuration has <html:code>StrictModes</html:code> enabled. The appropriate
configuration is used if no value is set for <html:code>StrictModes</html:code>.
<html:br/>
To explicitly enable <html:code>StrictModes</html:code> in SSH, add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>StrictModes yes</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010500</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230288r1069301_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>If other users have access to modify user-specific SSH configuration files, they
may be able to log into the system as another user.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_enable_strictmodes" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*StrictModes\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "StrictModes yes" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_enable_strictmodes" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010500
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(a)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_enable_strictmodes

- name: Enable Use of Strict Mode Checking
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*StrictModes\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*StrictModes\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*StrictModes\s+
      line: StrictModes yes
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010500
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(a)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_enable_strictmodes
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_enable_strictmodes:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_enable_warning_banner" selected="false" severity="medium">
              <xccdf-1.2:title>Enable SSH Warning Banner</xccdf-1.2:title>
              <xccdf-1.2:description>To enable the warning banner and ensure it is consistent
across the system, add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>Banner /etc/issue</html:pre>
Another section contains information on how to create an
appropriate system-wide warning banner.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-8(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-8(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FTA_TAB.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000023-GPOS-00006</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000228-GPOS-00088</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0484</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010040</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230225r1069297_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The warning message reinforces policy awareness during the logon process and
facilitates possible legal action against attackers. Alternatively, systems
whose ownership should not be obvious should ensure usage of a banner that does
not provide easy attribution.</xccdf-1.2:rationale>
              <xccdf-1.2:conflicts idref="xccdf_org.ssgproject.content_rule_sshd_enable_warning_banner_net"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_enable_warning_banner" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*Banner\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "Banner /etc/issue" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_enable_warning_banner" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.6
  - DISA-STIG-RHEL-08-010040
  - NIST-800-171-3.1.9
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-8(a)
  - NIST-800-53-AC-8(c)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-2.2.4
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_enable_warning_banner

- name: Enable SSH Warning Banner
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*Banner\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*Banner\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*Banner\s+
      line: Banner /etc/issue
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.5.6
  - DISA-STIG-RHEL-08-010040
  - NIST-800-171-3.1.9
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-8(a)
  - NIST-800-53-AC-8(c)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-2.2.4
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_enable_warning_banner
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_enable_warning_banner:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_enable_warning_banner_net" selected="false" severity="medium">
              <xccdf-1.2:title>Enable SSH Warning Banner</xccdf-1.2:title>
              <xccdf-1.2:description>To enable the warning banner and ensure it is consistent
across the system, add or correct the following line in

<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>Banner /etc/issue.net</html:pre>
Another section contains information on how to create an
appropriate system-wide warning banner.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-8(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-8(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000023-GPOS-00006</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000228-GPOS-00088</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.7</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The warning message reinforces policy awareness during the logon process and
facilitates possible legal action against attackers. Alternatively, systems
whose ownership should not be obvious should ensure usage of a banner that does
not provide easy attribution.</xccdf-1.2:rationale>
              <xccdf-1.2:conflicts idref="xccdf_org.ssgproject.content_rule_sshd_enable_warning_banner"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_enable_warning_banner_net" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*Banner\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "Banner /etc/issue.net" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_enable_warning_banner_net" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.6
  - NIST-800-171-3.1.9
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-8(a)
  - NIST-800-53-AC-8(c)
  - NIST-800-53-CM-6(a)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_enable_warning_banner_net

- name: Enable SSH Warning Banner
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*Banner\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*Banner\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*Banner\s+
      line: Banner /etc/issue.net
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.5.6
  - NIST-800-171-3.1.9
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-8(a)
  - NIST-800-53-AC-8(c)
  - NIST-800-53-CM-6(a)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_enable_warning_banner_net
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_enable_warning_banner_net:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_enable_x11_forwarding" selected="false" severity="high">
              <xccdf-1.2:title>Enable Encrypted X11 Forwarding</xccdf-1.2:title>
              <xccdf-1.2:description>By default, remote X11 connections are not encrypted when initiated
by users. SSH has the capability to encrypt remote X11 connections when SSH's
<html:code>X11Forwarding</html:code> option is enabled.
<html:br/><html:br/>
To enable X11 Forwarding, add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>X11Forwarding yes</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">20</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.08</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI07.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Non-encrypted X displays allow an attacker to capture keystrokes and to execute commands
remotely.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_enable_x11_forwarding" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*X11Forwarding\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "X11Forwarding yes" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_enable_x11_forwarding" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.13
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy
  - sshd_enable_x11_forwarding

- name: Enable Encrypted X11 Forwarding
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*X11Forwarding\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*X11Forwarding\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*X11Forwarding\s+
      line: X11Forwarding yes
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.13
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - high_severity
  - low_complexity
  - low_disruption
  - no_reboot_needed
  - restrict_strategy
  - sshd_enable_x11_forwarding
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_enable_x11_forwarding:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_enable_x11_forwarding_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_limit_user_access" selected="false" severity="unknown">
              <xccdf-1.2:title>Limit Users' SSH Access</xccdf-1.2:title>
              <xccdf-1.2:description>By default, the SSH configuration allows any user with an account
to access the system. There are several options available to limit
which users and group can access the system via SSH. It is
recommended that at least one of the following options be leveraged:
- AllowUsers variable gives the system administrator the option of
  allowing specific users to ssh into the system. The list consists of
  space separated user names. Numeric user IDs are not recognized with
  this variable. If a system administrator wants to restrict user
  access further by specifically allowing a user's access only from a
  particular host, the entry can be specified in the form of user@host.
- AllowGroups variable gives the system administrator the option of
  allowing specific groups of users to ssh into the system. The list
  consists of space separated group names. Numeric group IDs are not
  recognized with this variable.
- DenyUsers variable gives the system administrator the option of
  denying specific users to ssh into the system. The list consists of
  space separated user names. Numeric user IDs are not recognized with
  this variable. If a system administrator wants to restrict user
  access further by specifically denying a user's access from a
  particular host, the entry can be specified in the form of user@host.
- DenyGroups variable gives the system administrator the option of
  denying specific groups of users to ssh into the system. The list
  consists of space separated group names. Numeric group IDs are not
  recognized with this variable.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Automated remediation is not available for this configuration check
because each system has unique user names and group names.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.6</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Specifying which accounts are allowed SSH access into the system reduces the
possibility of unauthorized access to the system.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_limit_user_access:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_print_last_log" selected="false" severity="medium">
              <xccdf-1.2:title>Enable SSH Print Last Log</xccdf-1.2:title>
              <xccdf-1.2:description>Ensure that SSH will display the date and time of the last successful account logon.
<html:br/>
The default SSH configuration enables print of the date and time of the last login.
The appropriate configuration is used if no value is set for <html:code>PrintLastLog</html:code>.
<html:br/>
To explicitly enable LastLog in SSH, add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>PrintLastLog yes</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-9(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0846</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020350</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230382r1069309_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Providing users feedback on when account accesses last occurred facilitates user
recognition and reporting of unauthorized account use.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_print_last_log" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*PrintLastLog\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "PrintLastLog yes" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_print_last_log" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020350
  - NIST-800-53-AC-9
  - NIST-800-53-AC-9(1)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_print_last_log

- name: Enable SSH Print Last Log
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PrintLastLog\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PrintLastLog\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*PrintLastLog\s+
      line: PrintLastLog yes
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020350
  - NIST-800-53-AC-9
  - NIST-800-53-AC-9(1)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_print_last_log
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_print_last_log:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_print_last_log_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_rekey_limit" selected="false" severity="medium">
              <xccdf-1.2:title>Force frequent session key renegotiation</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>RekeyLimit</html:code> parameter specifies how often
the session key of the is renegotiated, both in terms of
amount of data that may be transmitted and the time
elapsed.<html:br/>
To decrease the default limits, add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>RekeyLimit <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rekey_limit_size" use="legacy"/> <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rekey_limit_time" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FCS_SSH_EXT.1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000033-GPOS-00014</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040161</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230527r1017288_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>By decreasing the limit based on the amount of data and enabling
time-based limit, effects of potential attacks against
encryption keys are limited.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="sshd_rekey_limit" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_rekey_limit_size='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rekey_limit_size" use="legacy"/>'
var_rekey_limit_time='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rekey_limit_time" use="legacy"/>'



if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*RekeyLimit\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "RekeyLimit $var_rekey_limit_size $var_rekey_limit_time" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_rekey_limit" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040161
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sshd_rekey_limit
- name: XCCDF Value var_rekey_limit_size # promote to variable
  set_fact:
    var_rekey_limit_size: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rekey_limit_size" use="legacy"/>
  tags:
    - always
- name: XCCDF Value var_rekey_limit_time # promote to variable
  set_fact:
    var_rekey_limit_time: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_rekey_limit_time" use="legacy"/>
  tags:
    - always

- name: Force frequent session key renegotiation
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*RekeyLimit\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*RekeyLimit\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*RekeyLimit\s+
      line: RekeyLimit {{ var_rekey_limit_size }} {{ var_rekey_limit_time }}
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040161
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - sshd_rekey_limit
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_rekey_limit_time:var:1" value-id="xccdf_org.ssgproject.content_value_var_rekey_limit_time"/>
                <xccdf-1.2:check-export export-name="oval:ssg-var_rekey_limit_size:var:1" value-id="xccdf_org.ssgproject.content_value_var_rekey_limit_size"/>
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_rekey_limit:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_rekey_limit_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_set_login_grace_time" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure SSH LoginGraceTime is configured</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>LoginGraceTime</html:code> parameter to the SSH server specifies the time allowed for successful authentication to
the SSH server. The longer the Grace period is the more open unauthenticated connections
can exist. Like other session controls in this session the Grace Period should be limited to
appropriate limits to ensure the service is available for needed access.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.15</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Setting the <html:code>LoginGraceTime</html:code> parameter to a low number will minimize the risk of successful
brute force attacks to the SSH server. It will also limit the number of concurrent
unauthenticated connections.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_login_grace_time" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_sshd_set_login_grace_time='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sshd_set_login_grace_time" use="legacy"/>'

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*LoginGraceTime\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "LoginGraceTime $var_sshd_set_login_grace_time" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_login_grace_time" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_login_grace_time
- name: XCCDF Value var_sshd_set_login_grace_time # promote to variable
  set_fact:
    var_sshd_set_login_grace_time: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sshd_set_login_grace_time" use="legacy"/>
  tags:
    - always

- name: Ensure SSH LoginGraceTime is configured
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*LoginGraceTime\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*LoginGraceTime\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*LoginGraceTime\s+
      line: LoginGraceTime {{ var_sshd_set_login_grace_time }}
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_login_grace_time
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sshd_set_login_grace_time:var:1" value-id="xccdf_org.ssgproject.content_value_var_sshd_set_login_grace_time"/>
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_set_login_grace_time:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_set_loglevel_info" selected="false" severity="low">
              <xccdf-1.2:title>Set LogLevel to INFO</xccdf-1.2:title>
              <xccdf-1.2:description>The INFO parameter specifies that record login and logout activity will be logged.
<html:br/>
The default SSH configuration sets the log level to INFO. The appropriate
configuration is used if no value is set for <html:code>LogLevel</html:code>.
<html:br/>
To explicitly specify the log level in SSH, add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>LogLevel INFO</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
              <xccdf-1.2:rationale>SSH provides several logging levels with varying amounts of verbosity. <html:code>DEBUG</html:code> is specifically
not recommended other than strictly for debugging SSH communications since it provides
so much data that it is difficult to identify important security information. <html:code>INFO</html:code> level is the
basic level that only records login activity of SSH users. In many situations, such as Incident
Response, it is important to determine when a particular user was active on a system. The
logout record can eliminate those users who disconnected, which helps narrow the field.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_loglevel_info" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*LogLevel\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "LogLevel INFO" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_loglevel_info" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_loglevel_info

- name: Set LogLevel to INFO
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*LogLevel\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*LogLevel\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*LogLevel\s+
      line: LogLevel INFO
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_loglevel_info
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_set_loglevel_info:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_set_loglevel_info_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_set_loglevel_verbose" selected="false" severity="medium">
              <xccdf-1.2:title>Set SSH Daemon LogLevel to VERBOSE</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>VERBOSE</html:code> parameter configures the SSH daemon to record login and logout activity.
To specify the log level in
SSH, add or correct the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:pre>LogLevel VERBOSE</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-2.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000032-GPOS-00013</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.16</xccdf-1.2:reference>
              <xccdf-1.2:rationale>SSH provides several logging levels with varying amounts of verbosity. <html:code>DEBUG</html:code> is specifically
not recommended other than strictly for debugging SSH communications since it provides
so much data that it is difficult to identify important security information. <html:code>INFO</html:code> or
<html:code>VERBOSE</html:code> level is the basic level that only records login activity of SSH users. In many
situations, such as Incident Response, it is important to determine when a particular user was active
on a system. The logout record can eliminate those users who disconnected, which helps narrow the
field.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_loglevel_verbose" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*LogLevel\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "LogLevel VERBOSE" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_loglevel_verbose" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-17(1)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-2.2.4
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_loglevel_verbose

- name: Set SSH Daemon LogLevel to VERBOSE
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*LogLevel\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*LogLevel\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*LogLevel\s+
      line: LogLevel VERBOSE
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17(1)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-2.2.4
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_loglevel_verbose
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_set_loglevel_verbose:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_set_max_auth_tries" selected="false" severity="medium">
              <xccdf-1.2:title>Set SSH authentication attempt limit</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>MaxAuthTries</html:code> parameter specifies the maximum number of authentication attempts
permitted per connection. Once the number of failures reaches half this value, additional failures are logged.
to set MaxAUthTries edit <html:code>/etc/ssh/sshd_config</html:code> as follows:
<html:pre>MaxAuthTries <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_max_auth_tries_value" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.18</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Setting the MaxAuthTries parameter to a low number will minimize the risk of successful
brute force attacks to the SSH server.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_max_auth_tries" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

sshd_max_auth_tries_value='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_max_auth_tries_value" use="legacy"/>'

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*MaxAuthTries\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "MaxAuthTries $sshd_max_auth_tries_value" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_max_auth_tries" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_max_auth_tries
- name: XCCDF Value sshd_max_auth_tries_value # promote to variable
  set_fact:
    sshd_max_auth_tries_value: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_max_auth_tries_value" use="legacy"/>
  tags:
    - always

- name: Set SSH authentication attempt limit
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*MaxAuthTries\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*MaxAuthTries\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*MaxAuthTries\s+
      line: MaxAuthTries {{ sshd_max_auth_tries_value }}
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_max_auth_tries
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_max_auth_tries_value:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_max_auth_tries_value"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_set_max_auth_tries:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_set_max_sessions" selected="false" severity="medium">
              <xccdf-1.2:title>Set SSH MaxSessions limit</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>MaxSessions</html:code> parameter specifies the maximum number of open sessions permitted
from a given connection. To set MaxSessions edit
<html:code>/etc/ssh/sshd_config</html:code> as follows: <html:pre>MaxSessions <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sshd_max_sessions" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.19</xccdf-1.2:reference>
              <xccdf-1.2:rationale>To protect a system from denial of service due to a large number of concurrent
sessions, use the rate limiting function of MaxSessions to protect availability
of sshd logins and prevent overwhelming the daemon.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_max_sessions" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_sshd_max_sessions='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sshd_max_sessions" use="legacy"/>'

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*MaxSessions\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "MaxSessions $var_sshd_max_sessions" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_max_sessions" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_max_sessions
- name: XCCDF Value var_sshd_max_sessions # promote to variable
  set_fact:
    var_sshd_max_sessions: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sshd_max_sessions" use="legacy"/>
  tags:
    - always

- name: Set SSH MaxSessions limit
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*MaxSessions\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*MaxSessions\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*MaxSessions\s+
      line: MaxSessions {{ var_sshd_max_sessions }}
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_max_sessions
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sshd_max_sessions:var:1" value-id="xccdf_org.ssgproject.content_value_var_sshd_max_sessions"/>
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_set_max_sessions:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_set_max_sessions_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_set_maxstartups" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure SSH MaxStartups is configured</xccdf-1.2:title>
              <xccdf-1.2:description>The MaxStartups parameter specifies the maximum number of concurrent unauthenticated
connections to the SSH daemon. Additional connections will be dropped until authentication
succeeds or the LoginGraceTime expires for a connection. To configure MaxStartups, you should
add or edit the following line in the <html:code>/etc/ssh/sshd_config</html:code> file:
<html:pre>MaxStartups <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sshd_set_maxstartups" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">5.1.20</xccdf-1.2:reference>
              <xccdf-1.2:rationale>To protect a system from denial of service due to a large number of pending authentication
connection attempts, use the rate limiting function of MaxStartups to protect availability of
sshd logins and prevent overwhelming the daemon.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_maxstartups" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

var_sshd_set_maxstartups='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sshd_set_maxstartups" use="legacy"/>'

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*MaxStartups\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "MaxStartups $var_sshd_set_maxstartups" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_set_maxstartups" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_maxstartups
- name: XCCDF Value var_sshd_set_maxstartups # promote to variable
  set_fact:
    var_sshd_set_maxstartups: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sshd_set_maxstartups" use="legacy"/>
  tags:
    - always

- name: Ensure SSH MaxStartups is configured
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*MaxStartups\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*MaxStartups\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*MaxStartups\s+
      line: MaxStartups {{ var_sshd_set_maxstartups }}
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.6
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_set_maxstartups
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sshd_set_maxstartups:var:1" value-id="xccdf_org.ssgproject.content_value_var_sshd_set_maxstartups"/>
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_set_maxstartups:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_set_maxstartups_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_use_approved_ciphers" selected="false" severity="medium">
              <xccdf-1.2:title>Use Only FIPS 140-2 Validated Ciphers</xccdf-1.2:title>
              <xccdf-1.2:description>Limit the ciphers to those algorithms which are FIPS-approved.
Counter (CTR) mode is also preferred over cipher-block chaining (CBC) mode.
The following line in <html:code>/etc/ssh/sshd_config</html:code>
demonstrates use of FIPS-approved ciphers:
<html:pre>Ciphers aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,3des-cbc,aes192-cbc,aes256-cbc</html:pre>
The man page <html:code>sshd_config(5)</html:code> contains a list of supported ciphers.

The rule is parametrized to use the following ciphers: <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_approved_ciphers" use="legacy"/></html:code>.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">The system needs to be rebooted for these changes to take effect.</xccdf-1.2:warning>
              <xccdf-1.2:warning category="regulatory">System Crypto Modules must be provided by a vendor that undergoes
FIPS-140 certifications.
FIPS-140 is applicable to all Federal agencies that use
cryptographic-based security systems to protect sensitive information
in computer and telecommunication systems (including voice systems) as
defined in Section 5131 of the Information Technology Management Reform
Act of 1996, Public Law 104-106. This standard shall be used in
designing and implementing cryptographic modules that Federal
departments and agencies operate or are operated for them under
contract. See <html:b><html:a href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf">https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf</html:a></html:b>
To meet this, the system has to have cryptographic software provided by
a vendor that has undergone this certification. This means providing
documentation, test results, design information, and independent third
party review by an accredited lab. While open source software is
capable of meeting this, it does not meet FIPS-140 unless the vendor
submits to this process.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.13.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.13.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.314(b)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MA-4(6)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000033-GPOS-00014</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000120-GPOS-00061</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000125-GPOS-00065</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000393-GPOS-00173</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000394-GPOS-00174</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unapproved mechanisms that are used for authentication to the cryptographic module are not verified and therefore
cannot be relied upon to provide confidentiality or integrity, and system data may be compromised.
<html:br/>
Operating systems utilizing encryption are required to use FIPS-compliant mechanisms for authenticating to
cryptographic modules.
<html:br/>
FIPS 140-2 is the current standard for validating that mechanisms used to access cryptographic modules
utilize authentication that meets industry and government requirements. For government systems, this allows
Security Levels 1, 2, 3, or 4 for use on AlmaLinux OS 8.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="sshd_use_approved_ciphers" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

sshd_approved_ciphers='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_approved_ciphers" use="legacy"/>'



if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*Ciphers\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "Ciphers $sshd_approved_ciphers" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_use_approved_ciphers" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.5.6
  - NIST-800-171-3.1.13
  - NIST-800-171-3.13.11
  - NIST-800-171-3.13.8
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.7
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_use_approved_ciphers
- name: XCCDF Value sshd_approved_ciphers # promote to variable
  set_fact:
    sshd_approved_ciphers: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_approved_ciphers" use="legacy"/>
  tags:
    - always

- name: Use Only FIPS 140-2 Validated Ciphers
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*Ciphers\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*Ciphers\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*Ciphers\s+
      line: Ciphers {{ sshd_approved_ciphers }}
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.5.6
  - NIST-800-171-3.1.13
  - NIST-800-171-3.13.11
  - NIST-800-171-3.13.8
  - NIST-800-53-AC-17(2)
  - NIST-800-53-AC-17(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)(c)
  - NIST-800-53-MA-4(6)
  - NIST-800-53-SC-12(2)
  - NIST-800-53-SC-12(3)
  - NIST-800-53-SC-13
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.7
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_use_approved_ciphers
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_approved_ciphers:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_approved_ciphers"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_use_approved_ciphers:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_use_approved_ciphers_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_use_approved_kex_ordered_stig" selected="false" severity="medium">
              <xccdf-1.2:title>Use Only FIPS 140-2 Validated Key Exchange Algorithms</xccdf-1.2:title>
              <xccdf-1.2:description>Limit the key exchange algorithms to those  which are FIPS-approved.
Add or modify the following line in <html:code/>
<html:pre/>
This rule ensures that only the key exchange algorithms mentioned
above (or their subset) are configured for use, keeping the given
order of algorithms.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">The system needs to be rebooted for these changes to take effect.</xccdf-1.2:warning>
              <xccdf-1.2:warning category="regulatory">System crypto modules must be provided by a vendor that undergoes
FIPS-140 certifications.
FIPS-140 is applicable to all Federal agencies that use
cryptographic-based security systems to protect sensitive information
in computer and telecommunication systems (including voice systems) as
defined in Section 5131 of the Information Technology Management Reform
Act of 1996, Public Law 104-106. This standard shall be used in
designing and implementing cryptographic modules that Federal
departments and agencies operate or are operated for them under
contract. See <html:b><html:a href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf">https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf</html:a></html:b>
To meet this requirements, the system has to have cryptographic software
provided by a vendor that has undergone this certification. This means
providing documentation, test results, design information, and independent
third party review by an accredited lab. While open source software is
capable of meeting this, it does not meet FIPS-140 unless the vendor
submits to this process.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
              <xccdf-1.2:rationale>FIPS-approved key exchange algorithms are required to be used.
The system will attempt to use the first algorithm presented by the client that matches
the server list. Listing the values "strongest to weakest" is a method to ensure the use
of the strongest algorithm available to secure the SSH connection.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_use_approved_kex_ordered_stig:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_use_approved_kex_ordered_stig_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_use_approved_macs" selected="false" severity="medium">
              <xccdf-1.2:title>Use Only FIPS 140-2 Validated MACs</xccdf-1.2:title>
              <xccdf-1.2:description>Limit the MACs to those hash algorithms which are FIPS-approved.
The following line in <html:code>/etc/ssh/sshd_config</html:code>
demonstrates use of FIPS-approved MACs:

<html:pre>MACs hmac-sha2-512,hmac-sha2-256,hmac-sha1</html:pre>

The man page <html:code>sshd_config(5)</html:code> contains a list of supported MACs.

The rule is parametrized to use the following MACs: <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_approved_macs" use="legacy"/></html:code>.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">The system needs to be rebooted for these changes to take effect.</xccdf-1.2:warning>
              <xccdf-1.2:warning category="regulatory">System Crypto Modules must be provided by a vendor that undergoes
FIPS-140 certifications.
FIPS-140 is applicable to all Federal agencies that use
cryptographic-based security systems to protect sensitive information
in computer and telecommunication systems (including voice systems) as
defined in Section 5131 of the Information Technology Management Reform
Act of 1996, Public Law 104-106. This standard shall be used in
designing and implementing cryptographic modules that Federal
departments and agencies operate or are operated for them under
contract. See <html:b><html:a href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf">https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf</html:a></html:b>
To meet this, the system has to have cryptographic software provided by
a vendor that has undergone this certification. This means providing
documentation, test results, design information, and independent third
party review by an accredited lab. While open source software is
capable of meeting this, it does not meet FIPS-140 unless the vendor
submits to this process.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.13.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.13.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.314(b)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MA-4(6)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000125-GPOS-00065</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000394-GPOS-00174</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>FIPS-approved cryptographic hash functions are required to be used.
The only SSHv2 hash algorithms meeting this requirement is SHA2.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_approved_macs:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_approved_macs"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_use_approved_macs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_use_approved_macs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_use_priv_separation" selected="false" severity="medium">
              <xccdf-1.2:title>Enable Use of Privilege Separation</xccdf-1.2:title>
              <xccdf-1.2:description>When enabled, SSH will create an unprivileged child process that
has the privilege of the authenticated user. To enable privilege separation in
SSH, add or correct the following line in the <html:code>/etc/ssh/sshd_config</html:code> file:
<html:pre>UsePrivilegeSeparation <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sshd_priv_separation" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(4)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(b)(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(1)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)(2)(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>SSH daemon privilege separation causes the SSH process to drop root privileges
when not needed which would decrease the impact of software vulnerabilities in
the unprivileged section.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#package_openssh-server_le_7_5"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_use_priv_separation" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { ( rpm --quiet -q openssh-server &amp;&amp; { real="$(epoch=$(rpm -q --queryformat '%{EPOCH}' openssh-server); version=$(rpm -q --queryformat '%{VERSION}' openssh-server); [ "$epoch" = "(none)" ] &amp;&amp; echo "0:$version" || echo "$epoch:$version")"; expected="0:7.5"; [[ "$real" != "$expected" ]] &amp;&amp; printf "%s\n%s" "$real" "$expected" | sort -VC; } ); }; then

var_sshd_priv_separation='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sshd_priv_separation" use="legacy"/>'

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*UsePrivilegeSeparation\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "UsePrivilegeSeparation $var_sshd_priv_separation" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_use_priv_separation" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(a)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_use_priv_separation
- name: XCCDF Value var_sshd_priv_separation # promote to variable
  set_fact:
    var_sshd_priv_separation: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sshd_priv_separation" use="legacy"/>
  tags:
    - always

- name: Enable Use of Privilege Separation
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*UsePrivilegeSeparation\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*UsePrivilegeSeparation\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*UsePrivilegeSeparation\s+
      line: UsePrivilegeSeparation {{ var_sshd_priv_separation }}
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when:
  - '"kernel" in ansible_facts.packages'
  - '"openssh-server" in ansible_facts.packages and (((((ansible_facts.packages["openssh-server"]
    | last)["epoch"]) != None) | ternary((ansible_facts.packages["openssh-server"]
    | last)["epoch"] ~ ":", "0:")) + ((ansible_facts.packages["openssh-server"] |
    last)["version"] | split("-") | first)) is version("0:7.5", "&lt;")'
  tags:
  - NIST-800-171-3.1.12
  - NIST-800-53-AC-17(a)
  - NIST-800-53-AC-6
  - NIST-800-53-CM-6(a)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_use_priv_separation
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sshd_priv_separation:var:1" value-id="xccdf_org.ssgproject.content_value_var_sshd_priv_separation"/>
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_use_priv_separation:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_use_priv_separation_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_use_strong_kex" selected="false" severity="medium">
              <xccdf-1.2:title>Use Only Strong Key Exchange algorithms</xccdf-1.2:title>
              <xccdf-1.2:description>Limit the Key Exchange to strong algorithms.
The following line in <html:code>/etc/ssh/sshd_config</html:code> demonstrates use
of those:
<html:pre>KexAlgorithms <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_strong_kex" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">2.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Key exchange is any method in cryptography by which cryptographic keys are exchanged
between two parties, allowing use of a cryptographic algorithm. If the sender and receiver
wish to exchange encrypted messages, each must be equipped to encrypt messages to be
sent and decrypt messages received</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_use_strong_kex" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

sshd_strong_kex='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_strong_kex" use="legacy"/>'

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*KexAlgorithms\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "KexAlgorithms $sshd_strong_kex" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_use_strong_kex" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSS-Req-2.3
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.7
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_use_strong_kex
- name: XCCDF Value sshd_strong_kex # promote to variable
  set_fact:
    sshd_strong_kex: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_strong_kex" use="legacy"/>
  tags:
    - always

- name: Use Only Strong Key Exchange algorithms
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*KexAlgorithms\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*KexAlgorithms\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*KexAlgorithms\s+
      line: KexAlgorithms {{ sshd_strong_kex }}
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSS-Req-2.3
  - PCI-DSSv4-2.2
  - PCI-DSSv4-2.2.7
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_use_strong_kex
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_strong_kex:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_strong_kex"/>
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_use_strong_kex:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_use_strong_kex_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_use_strong_macs" selected="false" severity="medium">
              <xccdf-1.2:title>Use Only Strong MACs</xccdf-1.2:title>
              <xccdf-1.2:description>Limit the MACs to strong hash algorithms.
The following line in <html:code>/etc/ssh/sshd_config</html:code> demonstrates use
of those MACs:
<html:pre>MACs <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_strong_macs" use="legacy"/></html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17 (2)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
              <xccdf-1.2:rationale>MD5 and 96-bit MAC algorithms are considered weak and have been shown to increase
exploitability in SSH downgrade attacks. Weak algorithms continue to have a great deal of
attention as a weak spot that can be exploited with expanded computing power. An
attacker that breaks the algorithm could take advantage of a MiTM position to decrypt the
SSH tunnel and capture credentials and information</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="sshd_use_strong_macs" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

sshd_strong_macs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_strong_macs" use="legacy"/>'



if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*MACs\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "MACs $sshd_strong_macs" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_use_strong_macs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-17 (2)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_use_strong_macs
- name: XCCDF Value sshd_strong_macs # promote to variable
  set_fact:
    sshd_strong_macs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_sshd_strong_macs" use="legacy"/>
  tags:
    - always

- name: Use Only Strong MACs
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*MACs\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*MACs\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*MACs\s+
      line: MACs {{ sshd_strong_macs }}
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-17 (2)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_use_strong_macs
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_strong_macs:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_strong_macs"/>
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_use_strong_macs:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_use_strong_macs_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_use_strong_rng" selected="false" severity="low">
              <xccdf-1.2:title>SSH server uses strong entropy to seed</xccdf-1.2:title>
              <xccdf-1.2:description>To set up SSH server to use entropy from a high-quality source, edit the <html:code>/etc/sysconfig/sshd</html:code> file.
The <html:code>SSH_USE_STRONG_RNG</html:code> configuration value determines how many bytes of entropy to use, so
make sure that the file contains line
<html:pre>SSH_USE_STRONG_RNG=32</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This setting can cause problems on computers without the hardware random generator, because insufficient entropy causes the connection to be blocked until enough entropy is available.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00232</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010292</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230253r1044799_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>SSH implementation in AlmaLinux OS 8 uses the openssl library, which doesn't use
high-entropy sources by default. Randomness is needed to generate data-encryption keys, and as
plaintext padding and initialization vectors in encryption algorithms, and high-quality
entropy eliminates the possibility that the output of the random number generator used by SSH
would be known to potential attackers.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_use_strong_rng" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/sysconfig/sshd" ] ; then
    
    LC_ALL=C sed -i "/^\s*SSH_USE_STRONG_RNG\s*=\s*/d" "/etc/sysconfig/sshd"
else
    touch "/etc/sysconfig/sshd"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/sysconfig/sshd"

cp "/etc/sysconfig/sshd" "/etc/sysconfig/sshd.bak"
# Insert before the line matching the regex '^#\s*SSH_USE_STRONG_RNG'.
line_number="$(LC_ALL=C grep -n "^#\s*SSH_USE_STRONG_RNG" "/etc/sysconfig/sshd.bak" | LC_ALL=C sed 's/:.*//g')"
if [ -z "$line_number" ]; then
    # There was no match of '^#\s*SSH_USE_STRONG_RNG', insert at
    # the end of the file.
    printf '%s\n' "SSH_USE_STRONG_RNG=32" &gt;&gt; "/etc/sysconfig/sshd"
else
    head -n "$(( line_number - 1 ))" "/etc/sysconfig/sshd.bak" &gt; "/etc/sysconfig/sshd"
    printf '%s\n' "SSH_USE_STRONG_RNG=32" &gt;&gt; "/etc/sysconfig/sshd"
    tail -n "+$(( line_number ))" "/etc/sysconfig/sshd.bak" &gt;&gt; "/etc/sysconfig/sshd"
fi
# Clean up after ourselves.
rm "/etc/sysconfig/sshd.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_use_strong_rng" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010292
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_use_strong_rng

- name: Setting unquoted shell-style assignment of 'SSH_USE_STRONG_RNG' to '32' in
    '/etc/sysconfig/sshd'
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/sysconfig/sshd
      create: true
      regexp: (?i)^\s*SSH_USE_STRONG_RNG=
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/sysconfig/sshd
    ansible.builtin.lineinfile:
      path: /etc/sysconfig/sshd
      create: true
      regexp: (?i)^\s*SSH_USE_STRONG_RNG=
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/sysconfig/sshd
    ansible.builtin.lineinfile:
      path: /etc/sysconfig/sshd
      create: true
      regexp: (?i)^\s*SSH_USE_STRONG_RNG=
      line: SSH_USE_STRONG_RNG=32
      state: present
      insertbefore: ^# SSH_USE_STRONG_RNG
      validate: /usr/bin/bash -n %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010292
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_use_strong_rng
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_use_strong_rng:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_use_strong_rng_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sshd_x11_use_localhost" selected="false" severity="medium">
              <xccdf-1.2:title>Prevent remote hosts from connecting to the proxy display</xccdf-1.2:title>
              <xccdf-1.2:description>The SSH daemon should prevent remote hosts from connecting to the proxy
display.
<html:br/>
The default SSH configuration for <html:code>X11UseLocalhost</html:code> is <html:code>yes</html:code>,
which prevents remote hosts from connecting to the proxy display.
<html:br/>
To explicitly prevent remote connections to the proxy display, add or correct
the following line in




<html:code>/etc/ssh/sshd_config</html:code>:

<html:code>X11UseLocalhost yes</html:code></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040341</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230556r1017318_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>When X11 forwarding is enabled, there may be additional exposure to the
server and client displays if the sshd proxy display is configured to listen
on the wildcard address. By default, sshd binds the forwarding server to the
loopback address and sets the hostname part of the <html:code>DISPLAY</html:code>
environment variable to localhost. This prevents remote hosts from
connecting to the proxy display.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_x11_use_localhost" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if [ -e "/etc/ssh/sshd_config" ] ; then
    
    LC_ALL=C sed -i "/^\s*X11UseLocalhost\s\+/Id" "/etc/ssh/sshd_config"
else
    touch "/etc/ssh/sshd_config"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/ssh/sshd_config"

cp "/etc/ssh/sshd_config" "/etc/ssh/sshd_config.bak"
# Insert at the beginning of the file
printf '%s\n' "X11UseLocalhost yes" &gt; "/etc/ssh/sshd_config"
cat "/etc/ssh/sshd_config.bak" &gt;&gt; "/etc/ssh/sshd_config"
# Clean up after ourselves.
rm "/etc/ssh/sshd_config.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="sshd_x11_use_localhost" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040341
  - NIST-800-53-CM-6(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_x11_use_localhost

- name: Prevent remote hosts from connecting to the proxy display
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*X11UseLocalhost\s+
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*X11UseLocalhost\s+
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/ssh/sshd_config
    ansible.builtin.lineinfile:
      path: /etc/ssh/sshd_config
      create: true
      regexp: (?i)(?i)^\s*X11UseLocalhost\s+
      line: X11UseLocalhost yes
      state: present
      insertbefore: BOF
      validate: /usr/sbin/sshd -t -f %s
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040341
  - NIST-800-53-CM-6(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
  - sshd_x11_use_localhost
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-sshd_required:var:1" value-id="xccdf_org.ssgproject.content_value_sshd_required"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sshd_x11_use_localhost:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sshd_x11_use_localhost_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_sssd">
          <xccdf-1.2:title>System Security Services Daemon</xccdf-1.2:title>
          <xccdf-1.2:description>The System Security Services Daemon (SSSD) is a system daemon that provides access
to different identity and authentication providers such as Red Hat's IdM, Microsoft's AD,
openLDAP, MIT Kerberos, etc. It uses a common framework that can provide caching and offline
support to systems utilizing SSSD. SSSD using caching to reduce load on authentication
servers permit offline authentication as well as store extended user data.
<html:br/><html:br/>
For more information, see
    <html:a href="https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html-single/installing_identity_management/index#assembly_installing-an-idm-client_installing-identity-management">https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html-single/installing_identity_management/index#assembly_installing-an-idm-client_installing-identity-management</html:a></xccdf-1.2:description>
          <xccdf-1.2:platform idref="#package_sssd"/>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sssd_certificate_verification_digest_function" interactive="true" type="string">
            <xccdf-1.2:title>SSSD certificate_verification option</xccdf-1.2:title>
            <xccdf-1.2:description>Value of the certificate_verification option in
the SSSD config.</xccdf-1.2:description>
            <xccdf-1.2:value selector="sha1">sha1</xccdf-1.2:value>
            <xccdf-1.2:value selector="sha256">sha256</xccdf-1.2:value>
            <xccdf-1.2:value selector="sha384">sha384</xccdf-1.2:value>
            <xccdf-1.2:value selector="sha512">sha512</xccdf-1.2:value>
            <xccdf-1.2:value>sha1</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sssd_memcache_timeout" type="number">
            <xccdf-1.2:title>SSSD memcache_timeout option</xccdf-1.2:title>
            <xccdf-1.2:description>Value of the memcache_timeout option in the [nss] section
of SSSD config /etc/sssd/sssd.conf.</xccdf-1.2:description>
            <xccdf-1.2:value selector="3_minutes">180</xccdf-1.2:value>
            <xccdf-1.2:value selector="5_minutes">300</xccdf-1.2:value>
            <xccdf-1.2:value selector="10_minutes">600</xccdf-1.2:value>
            <xccdf-1.2:value selector="15_minutes">900</xccdf-1.2:value>
            <xccdf-1.2:value selector="30_minutes">1800</xccdf-1.2:value>
            <xccdf-1.2:value selector="1_day">86400</xccdf-1.2:value>
            <xccdf-1.2:value>300</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sssd_ssh_known_hosts_timeout" type="number">
            <xccdf-1.2:title>SSSD ssh_known_hosts_timeout option</xccdf-1.2:title>
            <xccdf-1.2:description>Value of the ssh_known_hosts_timeout option in the [ssh] section
of SSSD configuration file /etc/sssd/sssd.conf.</xccdf-1.2:description>
            <xccdf-1.2:value selector="3_minutes">180</xccdf-1.2:value>
            <xccdf-1.2:value selector="5_minutes">300</xccdf-1.2:value>
            <xccdf-1.2:value selector="10_minutes">600</xccdf-1.2:value>
            <xccdf-1.2:value selector="15_minutes">900</xccdf-1.2:value>
            <xccdf-1.2:value selector="30_minutes">1800</xccdf-1.2:value>
            <xccdf-1.2:value selector="1_day">86400</xccdf-1.2:value>
            <xccdf-1.2:value>180</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_sssd-ipa_installed" selected="false" severity="medium">
            <xccdf-1.2:title>Install sssd-ipa Package</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>sssd-ipa</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install sssd-ipa</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:rationale><html:code>sssd-ipa</html:code> provides the IPA back end that the SSSD can utilize to
fetch identity data from and authenticate against an IPA server.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sssd-ipa_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q sssd-common; then

if ! rpm -q --quiet "sssd-ipa" ; then
    yum install -y "sssd-ipa"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sssd-ipa_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_sssd-ipa_installed

- name: Ensure sssd-ipa is installed
  ansible.builtin.package:
    name: sssd-ipa
    state: present
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_sssd-ipa_installed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sssd-ipa_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_sssd-ipa

class install_sssd-ipa {
  package { 'sssd-ipa':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sssd-ipa_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=sssd-ipa
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_sssd-ipa_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "sssd-ipa"
version = "*"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sssd-ipa_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install sssd-ipa
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sssd-ipa_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install sssd-ipa
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_sssd-ipa_installed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_sssd-ipa_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_sssd_installed" selected="false" severity="medium">
            <xccdf-1.2:title>Install the SSSD Package</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>sssd</html:code> package should be installed.
The <html:code>sssd</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install sssd</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000375-GPOS-00160</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R67</xccdf-1.2:reference>
            <xccdf-1.2:rationale/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sssd_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q sssd-common; then

if ! rpm -q --quiet "sssd" ; then
    yum install -y "sssd"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sssd_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_sssd_installed

- name: Ensure sssd is installed
  ansible.builtin.package:
    name: sssd
    state: present
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_sssd_installed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sssd_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_sssd

class install_sssd {
  package { 'sssd':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sssd_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=sssd
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_sssd_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "sssd"
version = "*"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sssd_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install sssd
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_sssd_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install sssd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_sssd_installed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_sssd_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_sssd_enabled" selected="false" severity="medium">
            <xccdf-1.2:title>Enable the SSSD Service</xccdf-1.2:title>
            <xccdf-1.2:description>The SSSD service should be enabled.

The <html:code>sssd</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable sssd.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">The service requires a valid sssd configuration. If the configuration is not present, the service will fail to start and consequently this rule will be reported as failing. The configuration shipped in your distribution package might not be sufficient. Manual modification of configuration files might be required.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(10)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000375-GPOS-00160</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R67</xccdf-1.2:reference>
            <xccdf-1.2:rationale/>
            <xccdf-1.2:platform idref="#package_sssd_and_system_with_kernel"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_sssd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q sssd-common &amp;&amp; { ( ( rpm --quiet -q sssd-common &amp;&amp; rpm --quiet -q kernel ) ); }; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'sssd.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'sssd.service'
fi
"$SYSTEMCTL_EXEC" enable 'sssd.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_sssd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(10)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_sssd_enabled

- name: Enable the SSSD Service - Enable service sssd
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable the SSSD Service - Enable Service sssd
    ansible.builtin.systemd:
      name: sssd
      enabled: true
      state: started
      masked: false
    when:
    - '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(10)
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_sssd_enabled
  - special_service_block
  when:
  - '"sssd-common" in ansible_facts.packages'
  - ( "sssd-common" in ansible_facts.packages and "kernel" in ansible_facts.packages
    )
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_sssd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_sssd

class enable_sssd {
  service {'sssd':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_sssd_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["sssd"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_sssd_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable sssd
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_sssd_enabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_sssd_enabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sssd_certificate_verification" selected="false" severity="medium">
            <xccdf-1.2:title>Certificate status checking in SSSD</xccdf-1.2:title>
            <xccdf-1.2:description>Multifactor solutions that require devices separate from information systems gaining access include,
for example, hardware tokens providing time-based or challenge-response authenticators and smart cards.
Configuring <html:code>certificate_verification</html:code> to <html:code>ocsp_dgst=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sssd_certificate_verification_digest_function" use="legacy"/></html:code> ensures that certificates for
multifactor solutions are checked via Online Certificate Status Protocol (OCSP).</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(11)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000375-GPOS-00160</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000377-GPOS-00162</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010400</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230274r1017089_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Ensuring that multifactor solutions certificates are checked via Online Certificate Status Protocol (OCSP)
ensures the security of the system.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="sssd_certificate_verification" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q sssd-common; then

var_sssd_certificate_verification_digest_function='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sssd_certificate_verification_digest_function" use="legacy"/>'


# sssd configuration files must be created with 600 permissions if they don't exist
# otherwise the sssd module fails to start
OLD_UMASK=$(umask)
umask u=rw,go=

MAIN_CONF="/etc/sssd/conf.d/certificate_verification.conf"

found=false

# set value in all files if they contain section or key
for f in $(echo -n "$MAIN_CONF /etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf"); do
    if [ ! -e "$f" ]; then
        continue
    fi

    # find key in section and change value
    if grep -qzosP "(?m)^[[:space:]]*\[sssd\]([^\n\[]*\n+)+?[[:space:]]*certificate_verification" "$f"; then
        if ! grep -qzosP "(?m)^[[:space:]]*certificate_verification[[:space:]]*=[[:space:]]*ocsp_dgst=$var_sssd_certificate_verification_digest_function" "$f"; then

            sed -i "/^[[:space:]]*certificate_verification/s/\([[:blank:]]*=[[:blank:]]*\).*/\1ocsp_dgst=$var_sssd_certificate_verification_digest_function/" "$f"

        fi

        found=true

    # find section and add key = value to it
    elif grep -qs "^[[:space:]]*\[sssd\]" "$f"; then

            sed -i "/^[[:space:]]*\[sssd\]/a certificate_verification=ocsp_dgst=$var_sssd_certificate_verification_digest_function" "$f"

            found=true
    fi
done

# if section not in any file, append section with key = value to FIRST file in files parameter
if ! $found ; then
    file=$(echo "$MAIN_CONF /etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf" | cut -f1 -d ' ')
    mkdir -p "$(dirname "$file")"

    echo -e "[sssd]\ncertificate_verification=ocsp_dgst=$var_sssd_certificate_verification_digest_function" &gt;&gt; "$file"

fi

umask $OLD_UMASK

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="sssd_certificate_verification" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-010400
  - NIST-800-53-IA-2(11)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_certificate_verification
- name: XCCDF Value var_sssd_certificate_verification_digest_function # promote to variable
  set_fact:
    var_sssd_certificate_verification_digest_function: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sssd_certificate_verification_digest_function" use="legacy"/>
  tags:
    - always

- name: Ensure that "certificate_verification" is not set in /etc/sssd/sssd.conf
  community.general.ini_file:
    path: /etc/sssd/sssd.conf
    section: sssd
    option: certificate_verification
    state: absent
    mode: 384
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010400
  - NIST-800-53-IA-2(11)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_certificate_verification

- name: Ensure that "certificate_verification" is not set in  /etc/sssd/conf.d/*.conf
  community.general.ini_file:
    path: /etc/sssd/conf.d/*.conf
    section: sssd
    option: certificate_verification
    state: absent
    mode: 384
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010400
  - NIST-800-53-IA-2(11)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_certificate_verification

- name: Ensure that "certificate_verification" is set
  community.general.ini_file:
    path: /etc/sssd/conf.d/certificate_verification.conf
    section: sssd
    option: certificate_verification
    value: ocsp_dgst={{ var_sssd_certificate_verification_digest_function }}
    state: present
    mode: 384
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-010400
  - NIST-800-53-IA-2(11)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_certificate_verification
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_sssd_certificate_verification_digest_function:var:1" value-id="xccdf_org.ssgproject.content_value_var_sssd_certificate_verification_digest_function"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sssd_certificate_verification:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sssd_certificate_verification_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sssd_enable_certmap" selected="false" severity="medium">
            <xccdf-1.2:title>Enable Certmap in SSSD</xccdf-1.2:title>
            <xccdf-1.2:description>SSSD should be configured to verify the certificate of the user or group. To set this up
 ensure that section like <html:code>certmap/testing.test/rule_name</html:code> is setup in
<html:code>/etc/sssd/sssd.conf</html:code>. For example
<html:pre>
[certmap/testing.test/rule_name]
matchrule =&lt;SAN&gt;.*EDIPI@mil
maprule = (userCertificate;binary={cert!bin})
domains = testing.test
</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Automatic remediation of this control is not available, since all of the settings in
in the certmap need to be customized.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5 (2) (c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000068-GPOS-00036</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020090</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230355r1017168_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Without mapping the certificate used to authenticate to the user account, the ability to
determine the identity of the individual user or group will not be available for forensic
analysis.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sssd_enable_certmap:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sssd_enable_certmap_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sssd_enable_pam_services" selected="false" severity="medium">
            <xccdf-1.2:title>Configure PAM in SSSD Services</xccdf-1.2:title>
            <xccdf-1.2:description>SSSD should be configured to run SSSD <html:code>pam</html:code> services.
To configure SSSD to known SSH hosts, add <html:code>pam</html:code>
to <html:code>services</html:code> under the <html:code>[sssd]</html:code> section in
<html:code>/etc/sssd/sssd.conf</html:code>. For example:
<html:pre>[sssd]
services = sudo, autofs, pam
</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-2(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000375-GPOS-00160</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000376-GPOS-00161</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000377-GPOS-00162</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R67</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Using an authentication device, such as a CAC or token that is separate from
the information system, ensures that even if the information system is
compromised, that compromise will not affect credentials stored on the
authentication device.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="sssd_enable_pam_services" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q sssd-common; then

# sssd configuration files must be created with 600 permissions if they don't exist
# otherwise the sssd module fails to start
OLD_UMASK=$(umask)
umask u=rw,go=

SSSD_CONF="/etc/sssd/sssd.conf"
SSSD_CONF_DIR="/etc/sssd/conf.d/*.conf"

if [ ! -f "$SSSD_CONF" ] &amp;&amp; [ ! -f "$SSSD_CONF_DIR" ]; then
    mkdir -p /etc/sssd
    touch "$SSSD_CONF"
fi

# Flag to check if there is already services with pam
service_already_exist=false
for f in $SSSD_CONF $SSSD_CONF_DIR; do
	if [ ! -e "$f" ]; then
		continue
	fi
	# finds all services entries under [sssd] configuration category, get a unique list so it doesn't add redundant fix
	services_list=$( awk '/^\s*\[/{f=0} /^\s*\[sssd\]/{f=1}f' $f | grep -P '^services[ \t]*=' | uniq )
    if [ -z "$services_list" ]; then
        continue
    fi

	while IFS= read -r services; do
		if [[ ! $services =~ "pam" ]]; then
			sed -i "s/$services$/&amp;, pam/" $f
		fi
        # Either pam service was already there or got added now
        service_already_exist=true
	done &lt;&lt;&lt; "$services_list"

done

# If there was no service in [sssd], add it to first config
if [ "$service_already_exist" = false ]; then
    for f in $SSSD_CONF $SSSD_CONF_DIR; do
        cat &lt;&lt; EOF &gt;&gt; "$f"
[sssd]
services = pam
EOF
        break
    done
fi

umask $OLD_UMASK

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="sssd_enable_pam_services" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2(1)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_enable_pam_services

- name: Configure PAM in SSSD Services - Find all the conf files inside the /etc/sssd/conf.d/
    directory
  ansible.builtin.find:
    paths:
    - /etc/sssd/conf.d/
    patterns: '*.conf'
  register: sssd_conf_d_files
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2(1)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_enable_pam_services

- name: Configure PAM in SSSD Services - Modify lines in files in the /etc/sssd/conf.d/
    directory
  ansible.builtin.replace:
    path: '{{ item }}'
    regexp: ^(\s*\[sssd\].*(?:\n\s*[^[\s].*)*\n\s*services\s*=(?!.*\bpam\b).*)$
    replace: \1,pam
  with_items: '{{ sssd_conf_d_files.files | map(attribute=''path'') }}'
  register: modify_lines_sssd_conf_d_files
  when:
  - '"sssd-common" in ansible_facts.packages'
  - sssd_conf_d_files.matched is defined and sssd_conf_d_files.matched &gt;= 1
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2(1)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_enable_pam_services

- name: Configure PAM in SSSD Services - Find /etc/sssd/sssd.conf
  ansible.builtin.stat:
    path: /etc/sssd/sssd.conf
  register: sssd_conf_file
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2(1)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_enable_pam_services

- name: Configure PAM in SSSD Services - Modify lines in /etc/sssd/sssd.conf
  ansible.builtin.replace:
    path: /etc/sssd/sssd.conf
    regexp: ^(\s*\[sssd\].*(?:\n\s*[^[\s].*)*\n\s*services\s*=(?!.*\bpam\b).*)$
    replace: \1,pam
  register: modify_lines_sssd_conf_file
  when:
  - '"sssd-common" in ansible_facts.packages'
  - sssd_conf_file.stat.exists
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2(1)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_enable_pam_services

- name: Configure PAM in SSSD Services - Find services key in /etc/sssd/sssd.conf
  ansible.builtin.replace:
    path: /etc/sssd/sssd.conf
    regexp: ^\s*\[sssd\][^\[\]]*?(?:\n(?!\[)[^\n]*?services\s*=)+
    replace: ''
  changed_when: false
  check_mode: true
  register: sssd_conf_file_services
  when:
  - '"sssd-common" in ansible_facts.packages'
  - sssd_conf_file.stat.exists
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2(1)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_enable_pam_services

- name: Configure PAM in SSSD Services - Insert entry to /etc/sssd/sssd.conf
  community.general.ini_file:
    path: /etc/sssd/sssd.conf
    section: sssd
    option: services
    value: pam
  when:
  - '"sssd-common" in ansible_facts.packages'
  - not modify_lines_sssd_conf_d_files.changed
  - not modify_lines_sssd_conf_file.changed
  - (sssd_conf_file_services.msg is defined and "replacements" not in sssd_conf_file_services.msg)
    or not sssd_conf_file.stat.exists
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-2(1)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_enable_pam_services
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sssd_enable_pam_services:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sssd_enable_pam_services_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sssd_enable_smartcards" selected="false" severity="medium">
            <xccdf-1.2:title>Enable Smartcards in SSSD</xccdf-1.2:title>
            <xccdf-1.2:description>SSSD should be configured to authenticate access to the system using smart cards.
To enable smart cards in SSSD, set <html:code>pam_cert_auth</html:code> to <html:code>True</html:code> under the
<html:code>[pam]</html:code> section in <html:code>/etc/sssd/sssd.conf</html:code>. For example:
<html:pre>[pam]
pam_cert_auth = True
</html:pre>

Add or update "pam_sss.so" line in auth section of "/etc/pam.d/system-auth" file to include
"try_cert_auth" or "require_cert_auth" option, like in the following example:
<html:pre>
/etc/pam.d/system-auth:auth [success=done authinfo_unavail=ignore ignore=ignore default=die] pam_sss.so try_cert_auth
</html:pre>
Also add or update "pam_sss.so" line in auth section of "/etc/pam.d/smartcard-auth" file to
include the "allow_missing_name" option, like in the following example:
<html:pre>/etc/pam.d/smartcard-auth:auth sufficient pam_sss.so allow_missing_name</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-8.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000375-GPOS-00160</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000105-GPOS-00052</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000106-GPOS-00053</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000107-GPOS-00054</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000108-GPOS-00055</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0421</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0422</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0974</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1173</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1401</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1504</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1505</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1546</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1557</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1558</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1559</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1560</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1561</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020250</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230372r1017184_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Using an authentication device, such as a CAC or token that is separate from
the information system, ensures that even if the information system is
compromised, that compromise will not affect credentials stored on the
authentication device.
<html:br/><html:br/>
Multi-Factor Authentication (MFA) solutions that require devices separate from
information systems gaining access include, for example, hardware tokens
providing time-based or challenge-response authenticators and smart cards
or similar secure authentication devices issued by an organization or identity provider.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="sssd_enable_smartcards" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q sssd-common; then

# sssd configuration files must be created with 600 permissions if they don't exist
# otherwise the sssd module fails to start
OLD_UMASK=$(umask)
umask u=rw,go=

found=false

# set value in all files if they contain section or key
for f in $(echo -n "/etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf"); do
    if [ ! -e "$f" ]; then
        continue
    fi

    # find key in section and change value
    if grep -qzosP "(?m)^[[:space:]]*\[pam\]([^\n\[]*\n+)+?[[:space:]]*pam_cert_auth" "$f"; then
        if ! grep -qzosP "(?m)^[[:space:]]*pam_cert_auth[[:space:]]*=[[:space:]]*True" "$f"; then

            sed -i "/^[[:space:]]*pam_cert_auth/s/\([[:blank:]]*=[[:blank:]]*\).*/\1True/" "$f"

        fi

        found=true

    # find section and add key = value to it
    elif grep -qs "^[[:space:]]*\[pam\]" "$f"; then

            sed -i "/^[[:space:]]*\[pam\]/a pam_cert_auth=True" "$f"

            found=true
    fi
done

# if section not in any file, append section with key = value to FIRST file in files parameter
if ! $found ; then
    file=$(echo "/etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf" | cut -f1 -d ' ')
    mkdir -p "$(dirname "$file")"

    echo -e "[pam]\npam_cert_auth=True" &gt;&gt; "$file"

fi

umask $OLD_UMASK

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="sssd_enable_smartcards" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020250
  - PCI-DSS-Req-8.3
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_enable_smartcards

- name: Test for domain group
  ansible.builtin.command: grep '^\s*\[domain\/[^]]*]' /etc/sssd/sssd.conf
  register: test_grep_domain
  failed_when: false
  changed_when: false
  check_mode: false
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020250
  - PCI-DSS-Req-8.3
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_enable_smartcards

- name: Add default domain group (if no domain there)
  community.general.ini_file:
    path: /etc/sssd/sssd.conf
    section: '{{ item.section }}'
    option: '{{ item.option }}'
    value: '{{ item.value }}'
    create: true
    mode: 384
  with_items:
  - section: sssd
    option: domains
    value: default
  - section: domain/default
    option: id_provider
    value: files
  when:
  - '"sssd-common" in ansible_facts.packages'
  - test_grep_domain.stdout is defined
  - test_grep_domain.stdout | length &lt; 1
  tags:
  - DISA-STIG-RHEL-08-020250
  - PCI-DSS-Req-8.3
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_enable_smartcards

- name: Enable Smartcards in SSSD
  community.general.ini_file:
    dest: /etc/sssd/sssd.conf
    section: pam
    option: pam_cert_auth
    value: 'True'
    create: true
    mode: 384
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020250
  - PCI-DSS-Req-8.3
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_enable_smartcards

- name: Find all the conf files inside /etc/sssd/conf.d/
  ansible.builtin.find:
    paths: /etc/sssd/conf.d/
    patterns: '*.conf'
  register: sssd_conf_d_files
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020250
  - PCI-DSS-Req-8.3
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_enable_smartcards

- name: Fix pam_cert_auth configuration in /etc/sssd/conf.d/
  ansible.builtin.replace:
    path: '{{ item.path }}'
    regexp: '[^#]*pam_cert_auth.*'
    replace: pam_cert_auth = True
  with_items: '{{ sssd_conf_d_files.files }}'
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020250
  - PCI-DSS-Req-8.3
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_enable_smartcards
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sssd_enable_smartcards:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sssd_enable_smartcards_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sssd_has_trust_anchor" selected="false" severity="medium">
            <xccdf-1.2:title>SSSD Has a Correct Trust Anchor</xccdf-1.2:title>
            <xccdf-1.2:description>SSSD must have acceptable trust anchor present.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Automatic remediation of this control is not available.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5 (2) (a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000066-GPOS-00034</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000384-GPOS-00167</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-010090</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230229r1017048_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Without path validation, an informed trust decision by the relying party cannot be made when
presented with any certificate not already explicitly trusted.

A trust anchor is an authoritative entity represented via a public key and associated data. It
is used in the context of public key infrastructures, X.509 digital certificates, and DNSSEC.

When there is a chain of trust, usually the top entity to be trusted becomes the trust anchor;
it can be, for example, a Certification Authority (CA). A certification path starts with the
subject certificate and proceeds through a number of intermediate certificates up to a trusted
root certificate, typically issued by a trusted CA.

This requirement verifies that a certification path to an accepted trust anchor is used for
certificate validation and that the path includes status information. Path validation is
necessary for a relying party to make an informed trust decision when presented with any
certificate not already explicitly trusted. Status information for certification paths includes
certificate revocation lists or online certificate status protocol responses.
Validation of the certificate status information is out of scope for this requirement.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sssd_has_trust_anchor_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sssd_memcache_timeout" selected="false" severity="medium">
            <xccdf-1.2:title>Configure SSSD's Memory Cache to Expire</xccdf-1.2:title>
            <xccdf-1.2:description>SSSD's memory cache should be configured to set to expire records after
<html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sssd_memcache_timeout" use="legacy"/></html:code> seconds.
To configure SSSD to expire memory cache, set <html:code>memcache_timeout</html:code> to
<html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sssd_memcache_timeout" use="legacy"/></html:code> under the
<html:code>[nss]</html:code> section in <html:code>/etc/sssd/sssd.conf</html:code>.

For example:
<html:pre>[nss]
memcache_timeout = <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sssd_memcache_timeout" use="legacy"/>
</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(13)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000383-GPOS-00166</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If cached authentication information is out-of-date, the validity of the
authentication information may be questionable.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="sssd_memcache_timeout" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q sssd-common; then

var_sssd_memcache_timeout='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sssd_memcache_timeout" use="legacy"/>'


# sssd configuration files must be created with 600 permissions if they don't exist
# otherwise the sssd module fails to start
OLD_UMASK=$(umask)
umask u=rw,go=

found=false

# set value in all files if they contain section or key
for f in $(echo -n "/etc/sssd/sssd.conf"); do
    if [ ! -e "$f" ]; then
        continue
    fi

    # find key in section and change value
    if grep -qzosP "(?m)^[[:space:]]*\[nss\]([^\n\[]*\n+)+?[[:space:]]*memcache_timeout" "$f"; then
        if ! grep -qzosP "(?m)^[[:space:]]*memcache_timeout[[:space:]]*=[[:space:]]*$var_sssd_memcache_timeout" "$f"; then

            sed -i "/^[[:space:]]*memcache_timeout/s/\([[:blank:]]*=[[:blank:]]*\).*/\1$var_sssd_memcache_timeout/" "$f"

        fi

        found=true

    # find section and add key = value to it
    elif grep -qs "^[[:space:]]*\[nss\]" "$f"; then

            sed -i "/^[[:space:]]*\[nss\]/a memcache_timeout=$var_sssd_memcache_timeout" "$f"

            found=true
    fi
done

# if section not in any file, append section with key = value to FIRST file in files parameter
if ! $found ; then
    file=$(echo "/etc/sssd/sssd.conf" | cut -f1 -d ' ')
    mkdir -p "$(dirname "$file")"

    echo -e "[nss]\nmemcache_timeout=$var_sssd_memcache_timeout" &gt;&gt; "$file"

fi

umask $OLD_UMASK

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="sssd_memcache_timeout" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(13)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_memcache_timeout
  - unknown_strategy
- name: XCCDF Value var_sssd_memcache_timeout # promote to variable
  set_fact:
    var_sssd_memcache_timeout: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sssd_memcache_timeout" use="legacy"/>
  tags:
    - always

- name: Test for domain group
  ansible.builtin.command: grep '\s*\[domain\/[^]]*]' /etc/sssd/sssd.conf
  register: test_grep_domain
  failed_when: false
  changed_when: false
  check_mode: false
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(13)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_memcache_timeout
  - unknown_strategy

- name: Add default domain group (if no domain there)
  community.general.ini_file:
    path: /etc/sssd/sssd.conf
    section: '{{ item.section }}'
    option: '{{ item.option }}'
    value: '{{ item.value }}'
    create: true
    mode: 384
  with_items:
  - section: sssd
    option: domains
    value: default
  - section: domain/default
    option: id_provider
    value: files
  when:
  - '"sssd-common" in ansible_facts.packages'
  - test_grep_domain.stdout is defined
  - test_grep_domain.stdout | length &lt; 1
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(13)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_memcache_timeout
  - unknown_strategy

- name: Configure SSSD's Memory Cache to Expire
  community.general.ini_file:
    dest: /etc/sssd/sssd.conf
    section: nss
    option: memcache_timeout
    value: '{{ var_sssd_memcache_timeout }}'
    create: true
    mode: 384
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(13)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_memcache_timeout
  - unknown_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_sssd_memcache_timeout:var:1" value-id="xccdf_org.ssgproject.content_value_var_sssd_memcache_timeout"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sssd_memcache_timeout:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sssd_memcache_timeout_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sssd_offline_cred_expiration" selected="false" severity="medium">
            <xccdf-1.2:title>Configure SSSD to Expire Offline Credentials</xccdf-1.2:title>
            <xccdf-1.2:description>SSSD should be configured to expire offline credentials after 1 day.

Check if SSSD allows cached authentications with the following command:
<html:pre>
$ sudo grep cache_credentials /etc/sssd/sssd.conf
cache_credentials = true
</html:pre>
If "cache_credentials" is set to "false" or is missing no further checks are required.<html:br/>

To configure SSSD to expire offline credentials, set
<html:code>offline_credentials_expiration</html:code> to <html:code>1</html:code> under the <html:code>[pam]</html:code>
section in <html:code>/etc/sssd/sssd.conf</html:code>. For example:
<html:pre>[pam]
offline_credentials_expiration = 1
</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(13)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000383-GPOS-00166</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-020290</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230376r1069307_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If cached authentication information is out-of-date, the validity of the
authentication information may be questionable.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="sssd_offline_cred_expiration" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q sssd-common; then

# sssd configuration files must be created with 600 permissions if they don't exist
# otherwise the sssd module fails to start
OLD_UMASK=$(umask)
umask u=rw,go=

found=false

# set value in all files if they contain section or key
for f in $(echo -n "/etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf"); do
    if [ ! -e "$f" ]; then
        continue
    fi

    # find key in section and change value
    if grep -qzosP "(?m)^[[:space:]]*\[pam\]([^\n\[]*\n+)+?[[:space:]]*offline_credentials_expiration" "$f"; then
        if ! grep -qzosP "(?m)^[[:space:]]*offline_credentials_expiration[[:space:]]*=[[:space:]]*1" "$f"; then

            sed -i "/^[[:space:]]*offline_credentials_expiration/s/\([[:blank:]]*=[[:blank:]]*\).*/\11/" "$f"

        fi

        found=true

    # find section and add key = value to it
    elif grep -qs "^[[:space:]]*\[pam\]" "$f"; then

            sed -i "/^[[:space:]]*\[pam\]/a offline_credentials_expiration=1" "$f"

            found=true
    fi
done

# if section not in any file, append section with key = value to FIRST file in files parameter
if ! $found ; then
    file=$(echo "/etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf" | cut -f1 -d ' ')
    mkdir -p "$(dirname "$file")"

    echo -e "[pam]\noffline_credentials_expiration=1" &gt;&gt; "$file"

fi

umask $OLD_UMASK

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="sssd_offline_cred_expiration" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-020290
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(13)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_offline_cred_expiration

- name: Test for domain group
  ansible.builtin.command: grep '\s*\[domain\/[^]]*]' /etc/sssd/sssd.conf
  register: test_grep_domain
  failed_when: false
  changed_when: false
  check_mode: false
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020290
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(13)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_offline_cred_expiration

- name: Add default domain group (if no domain there)
  community.general.ini_file:
    path: /etc/sssd/sssd.conf
    section: '{{ item.section }}'
    option: '{{ item.option }}'
    value: '{{ item.value }}'
    create: true
    mode: 384
  with_items:
  - section: sssd
    option: domains
    value: default
  - section: domain/default
    option: id_provider
    value: files
  when:
  - '"sssd-common" in ansible_facts.packages'
  - test_grep_domain.stdout is defined
  - test_grep_domain.stdout | length &lt; 1
  tags:
  - DISA-STIG-RHEL-08-020290
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(13)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_offline_cred_expiration

- name: Configure SSD to Expire Offline Credentials
  community.general.ini_file:
    dest: /etc/sssd/sssd.conf
    section: pam
    option: offline_credentials_expiration
    value: 1
    create: true
    mode: 384
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020290
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(13)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_offline_cred_expiration

- name: Find all the conf files inside /etc/sssd/conf.d/
  ansible.builtin.find:
    paths: /etc/sssd/conf.d/
    patterns: '*.conf'
  register: sssd_conf_d_files
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020290
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(13)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_offline_cred_expiration

- name: Fix offline_credentials_expiration configuration in /etc/sssd/conf.d/
  ansible.builtin.replace:
    path: '{{ item.path }}'
    regexp: '[^#]*offline_credentials_expiration.*'
    replace: offline_credentials_expiration = 1
  with_items: '{{ sssd_conf_d_files.files }}'
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-020290
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(13)
  - configure_strategy
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_offline_cred_expiration
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sssd_offline_cred_expiration:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sssd_offline_cred_expiration_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sssd_run_as_sssd_user" selected="false" severity="medium">
            <xccdf-1.2:title>Configure SSSD to run as user sssd</xccdf-1.2:title>
            <xccdf-1.2:description>SSSD processes should be configured to run as user sssd, not root.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:rationale>To minimize privileges of SSSD processes, they are configured to
run as non-root user.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="sssd_run_as_sssd_user" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q sssd-common; then

MAIN_CONF="/etc/sssd/conf.d/ospp.conf"

# sssd configuration files must be created with 600 permissions if they don't exist
# otherwise the sssd module fails to start
OLD_UMASK=$(umask)
umask u=rw,go=

found=false

# set value in all files if they contain section or key
for f in $(echo -n "$MAIN_CONF /etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf"); do
    if [ ! -e "$f" ]; then
        continue
    fi

    # find key in section and change value
    if grep -qzosP "(?m)^[[:space:]]*\[sssd\]([^\n\[]*\n+)+?[[:space:]]*user" "$f"; then
        if ! grep -qzosP "(?m)^[[:space:]]*user[[:space:]]*=[[:space:]]*sssd" "$f"; then

            sed -i "/^[[:space:]]*user/s/\([[:blank:]]*=[[:blank:]]*\).*/\1sssd/" "$f"

        fi

        found=true

    # find section and add key = value to it
    elif grep -qs "^[[:space:]]*\[sssd\]" "$f"; then

            sed -i "/^[[:space:]]*\[sssd\]/a user=sssd" "$f"

            found=true
    fi
done

# if section not in any file, append section with key = value to FIRST file in files parameter
if ! $found ; then
    file=$(echo "$MAIN_CONF /etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf" | cut -f1 -d ' ')
    mkdir -p "$(dirname "$file")"

    echo -e "[sssd]\nuser=sssd" &gt;&gt; "$file"

fi

umask $OLD_UMASK

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sssd_run_as_sssd_user:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sssd_run_as_sssd_user_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sssd_ssh_known_hosts_timeout" selected="false" severity="medium">
            <xccdf-1.2:title>Configure SSSD to Expire SSH Known Hosts</xccdf-1.2:title>
            <xccdf-1.2:description>SSSD should be configured to expire keys from known SSH hosts after
<html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sssd_ssh_known_hosts_timeout" use="legacy"/></html:code> seconds.
To configure SSSD to known SSH hosts, set <html:code>ssh_known_hosts_timeout</html:code>
to <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sssd_ssh_known_hosts_timeout" use="legacy"/></html:code> under the
<html:code>[ssh]</html:code> section in <html:code>/etc/sssd/sssd.conf</html:code>. For example:
<html:pre>[ssh]
ssh_known_hosts_timeout = <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sssd_ssh_known_hosts_timeout" use="legacy"/>
</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.18.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(13)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000383-GPOS-00166</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If cached authentication information is out-of-date, the validity of the
authentication information may be questionable.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="sssd_ssh_known_hosts_timeout" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q sssd-common; then

var_sssd_ssh_known_hosts_timeout='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sssd_ssh_known_hosts_timeout" use="legacy"/>'


# sssd configuration files must be created with 600 permissions if they don't exist
# otherwise the sssd module fails to start
OLD_UMASK=$(umask)
umask u=rw,go=

found=false

# set value in all files if they contain section or key
for f in $(echo -n "/etc/sssd/sssd.conf"); do
    if [ ! -e "$f" ]; then
        continue
    fi

    # find key in section and change value
    if grep -qzosP "(?m)^[[:space:]]*\[ssh\]([^\n\[]*\n+)+?[[:space:]]*ssh_known_hosts_timeout" "$f"; then
        if ! grep -qzosP "(?m)^[[:space:]]*ssh_known_hosts_timeout[[:space:]]*=[[:space:]]*$var_sssd_ssh_known_hosts_timeout" "$f"; then

            sed -i "/^[[:space:]]*ssh_known_hosts_timeout/s/\([[:blank:]]*=[[:blank:]]*\).*/\1$var_sssd_ssh_known_hosts_timeout/" "$f"

        fi

        found=true

    # find section and add key = value to it
    elif grep -qs "^[[:space:]]*\[ssh\]" "$f"; then

            sed -i "/^[[:space:]]*\[ssh\]/a ssh_known_hosts_timeout=$var_sssd_ssh_known_hosts_timeout" "$f"

            found=true
    fi
done

# if section not in any file, append section with key = value to FIRST file in files parameter
if ! $found ; then
    file=$(echo "/etc/sssd/sssd.conf" | cut -f1 -d ' ')
    mkdir -p "$(dirname "$file")"

    echo -e "[ssh]\nssh_known_hosts_timeout=$var_sssd_ssh_known_hosts_timeout" &gt;&gt; "$file"

fi

umask $OLD_UMASK

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="medium" id="sssd_ssh_known_hosts_timeout" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(13)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ssh_known_hosts_timeout
  - unknown_strategy
- name: XCCDF Value var_sssd_ssh_known_hosts_timeout # promote to variable
  set_fact:
    var_sssd_ssh_known_hosts_timeout: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sssd_ssh_known_hosts_timeout" use="legacy"/>
  tags:
    - always

- name: Test for domain group
  ansible.builtin.command: grep '\s*\[domain\/[^]]*]' /etc/sssd/sssd.conf
  register: test_grep_domain
  failed_when: false
  changed_when: false
  check_mode: false
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(13)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ssh_known_hosts_timeout
  - unknown_strategy

- name: Add default domain group (if no domain there)
  community.general.ini_file:
    path: /etc/sssd/sssd.conf
    section: '{{ item.section }}'
    option: '{{ item.option }}'
    value: '{{ item.value }}'
    create: true
    mode: 384
  with_items:
  - section: sssd
    option: domains
    value: default
  - section: domain/default
    option: id_provider
    value: files
  when:
  - '"sssd-common" in ansible_facts.packages'
  - test_grep_domain.stdout is defined
  - test_grep_domain.stdout | length &lt; 1
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(13)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ssh_known_hosts_timeout
  - unknown_strategy

- name: Configure SSSD to Expire SSH Known Hosts
  community.general.ini_file:
    dest: /etc/sssd/sssd.conf
    section: ssh
    option: ssh_known_hosts_timeout
    value: '{{ var_sssd_ssh_known_hosts_timeout }}'
    create: true
    mode: 384
  when: '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(13)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ssh_known_hosts_timeout
  - unknown_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_sssd_ssh_known_hosts_timeout:var:1" value-id="xccdf_org.ssgproject.content_value_var_sssd_ssh_known_hosts_timeout"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sssd_ssh_known_hosts_timeout:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sssd_ssh_known_hosts_timeout_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_sssd-ldap">
            <xccdf-1.2:title>System Security Services Daemon (SSSD) - LDAP</xccdf-1.2:title>
            <xccdf-1.2:description>The System Security Services Daemon (SSSD) is a system daemon that provides access
to different identity and authentication providers such as Red Hat's IdM, Microsoft's AD,
openLDAP, MIT Kerberos, etc. It uses a common framework that can provide caching and offline
support to systems utilizing SSSD. SSSD using caching to reduce load on authentication
servers permit offline authentication as well as store extended user data.
<html:br/><html:br/>
SSSD can support many backends including LDAP. The <html:code>sssd-ldap</html:code> backend
allows SSSD to fetch identity information from an LDAP server.</xccdf-1.2:description>
            <xccdf-1.2:platform idref="#system_with_kernel"/>
            <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_sssd_ldap_tls_ca_dir" type="string">
              <xccdf-1.2:title>SSSD LDAP Backend Client CA Certificate Location</xccdf-1.2:title>
              <xccdf-1.2:description>Path of a directory that contains Certificate Authority certificates.</xccdf-1.2:description>
              <xccdf-1.2:value>/etc/openldap/cacerts</xccdf-1.2:value>
            </xccdf-1.2:Value>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sssd_ldap_configure_tls_ca" selected="false" severity="medium">
              <xccdf-1.2:title>Configure SSSD LDAP Backend Client CA Certificate</xccdf-1.2:title>
              <xccdf-1.2:description>Configure SSSD to implement cryptography to protect the
integrity of LDAP remote access sessions. By setting
the <html:pre>ldap_tls_cacert</html:pre> option in <html:pre>/etc/sssd/sssd.conf</html:pre>
to point to the path for the X.509 certificates used for peer authentication.
<html:pre>ldap_tls_cacert /path/to/tls/ca.cert</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">A remediation is not provided for this rule as each system has unique requirements.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Without cryptographic integrity protections, information can be altered by
unauthorized users without detection.
<html:br/><html:br/>
Cryptographic mechanisms used for
protecting the integrity of information include, for example, signed hash
functions using asymmetric cryptography enabling distribution of the public key
to verify the hash information while maintaining the confidentiality of the key
used to generate the hash.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#sssd-ldap"/>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sssd_ldap_configure_tls_ca_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sssd_ldap_configure_tls_ca_dir" selected="false" severity="medium">
              <xccdf-1.2:title>Configure SSSD LDAP Backend Client CA Certificate Location</xccdf-1.2:title>
              <xccdf-1.2:description>Configure SSSD to implement cryptography to protect the
integrity of LDAP remote access sessions. By setting
the <html:pre>ldap_tls_cacertdir</html:pre> option in <html:pre>/etc/sssd/sssd.conf</html:pre>
to point to the path for the X.509 certificates used for peer authentication.
<html:pre>ldap_tls_cacertdir /path/to/tls/cacert</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Without cryptographic integrity protections, information can be altered by
unauthorized users without detection.
<html:br/><html:br/>
Cryptographic mechanisms used for
protecting the integrity of information include, for example, signed hash
functions using asymmetric cryptography enabling distribution of the public key
to verify the hash information while maintaining the confidentiality of the key
used to generate the hash.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#sssd-ldap"/>
              <xccdf-1.2:fix id="sssd_ldap_configure_tls_ca_dir" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; rpm --quiet -q sssd-common; then

var_sssd_ldap_tls_ca_dir='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sssd_ldap_tls_ca_dir" use="legacy"/>'


SSSD_CONF="/etc/sssd/sssd.conf"
LDAP_REGEX='[[:space:]]*\[domain\/[^]]*]([^(\n)]*(\n)+)+?[[:space:]]*ldap_tls_cacertdir'
AD_REGEX='[[:space:]]*\[domain\/[^]]*]([^(\n)]*(\n)+)+?[[:space:]]*id_provider[[:space:]]*=[[:space:]]*((?i)ad)[[:space:]]*$'
DOMAIN_REGEX="[[:space:]]*\[domain\/[^]]*]"

# Check if id_provider is not set to ad (Active Directory) which makes start_tls not applicable, note the -v option to invert the grep.
# Try to find [domain/..] and ldap_tls_cacertdir in sssd.conf, if it exists, set to '$var_sssd_ldap_tls_ca_dir'
# if ldap_tls_cacertdir isn't here, add it
# if [domain/..] doesn't exist, add it here for default domain
if grep -qvzosP $AD_REGEX $SSSD_CONF; then
        if grep -qzosP $LDAP_REGEX $SSSD_CONF; then
                
                sed -i "s#ldap_tls_cacertdir[^(\n)]*#ldap_tls_cacertdir = $var_sssd_ldap_tls_ca_dir#" $SSSD_CONF
        elif grep -qs $DOMAIN_REGEX $SSSD_CONF; then
                sed -i "/$DOMAIN_REGEX/a ldap_tls_cacertdir = $var_sssd_ldap_tls_ca_dir" $SSSD_CONF
        else
                if test -f "$SSSD_CONF"; then
                        echo -e "[domain/default]\nldap_tls_cacertdir = $var_sssd_ldap_tls_ca_dir" &gt;&gt; $SSSD_CONF
                else
                        echo "Config file '$SSSD_CONF' doesnt exist, not remediating, assuming non-applicability." &gt;&amp;2
                fi
        fi
fi

readarray -t SSSD_CONF_D_FILES &lt; &lt;(find /etc/sssd/conf.d/ -name "*.conf")
for SSSD_CONF_D_FILE in "${SSSD_CONF_D_FILES[@]}"; do
    sed -i "s#ldap_tls_cacertdir[^(\n)]*#ldap_tls_cacertdir = $var_sssd_ldap_tls_ca_dir#" "$SSSD_CONF_D_FILE"
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sssd_ldap_configure_tls_ca_dir" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12(3)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ldap_configure_tls_ca_dir
  - unknown_strategy
- name: XCCDF Value var_sssd_ldap_tls_ca_dir # promote to variable
  set_fact:
    var_sssd_ldap_tls_ca_dir: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_sssd_ldap_tls_ca_dir" use="legacy"/>
  tags:
    - always

- name: Test for id_provider different than Active Directory (ad)
  ansible.builtin.command: grep -qzosP '[[:space:]]*\[domain\/[^]]*]([^(\n)]*(\n)+)+?[[:space:]]*id_provider[[:space:]]*=[[:space:]]*((?i)ad)[[:space:]]*$'
    /etc/sssd/sssd.conf
  register: test_id_provider
  failed_when: false
  changed_when: false
  check_mode: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12(3)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ldap_configure_tls_ca_dir
  - unknown_strategy

- name: Test for domain group
  ansible.builtin.command: grep '\s*\[domain\/[^]]*]' /etc/sssd/sssd.conf
  register: test_grep_domain
  failed_when: false
  changed_when: false
  check_mode: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12(3)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ldap_configure_tls_ca_dir
  - unknown_strategy

- name: Add default domain group and set ldap_tls_cacertdir in sssd configuration
    (if no domain there)
  community.general.ini_file:
    path: /etc/sssd/sssd.conf
    section: '{{ item.section }}'
    option: '{{ item.option }}'
    value: '{{ item.value }}'
    mode: 384
  with_items:
  - section: sssd
    option: domains
    value: default
  - section: domain/default
    option: ldap_tls_cacertdir
    value: '{{ var_sssd_ldap_tls_ca_dir }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  - test_grep_domain.stdout is defined
  - test_grep_domain.stdout | length &lt; 1
  - test_id_provider.stdout is defined
  - test_id_provider.stdout | length &lt; 1
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12(3)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ldap_configure_tls_ca_dir
  - unknown_strategy

- name: Set ldap_tls_cacertdir in sssd configuration
  community.general.ini_file:
    path: /etc/sssd/sssd.conf
    section: '{{ test_grep_domain.stdout | regex_replace(''\[(.*)\]'',''\1'') }}'
    option: ldap_tls_cacertdir
    value: '{{ var_sssd_ldap_tls_ca_dir }}'
    mode: 384
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  - test_grep_domain.stdout is defined
  - test_grep_domain.stdout | length &gt; 0
  - test_id_provider.stdout is defined
  - test_id_provider.stdout | length &lt; 1
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12(3)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ldap_configure_tls_ca_dir
  - unknown_strategy

- name: Find all the conf files inside /etc/sssd/conf.d/
  ansible.builtin.find:
    paths: /etc/sssd/conf.d/
    patterns: '*.conf'
  register: sssd_conf_d_files
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12(3)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ldap_configure_tls_ca_dir
  - unknown_strategy

- name: Set ldap_tls_cacertdir to {{ var_sssd_ldap_tls_ca_dir }} in /etc/sssd/conf.d/
    if exists
  ansible.builtin.replace:
    path: '{{ item.path }}'
    regexp: '[^#]*ldap_tls_cacertdir.*'
    replace: ldap_tls_cacertdir = {{ var_sssd_ldap_tls_ca_dir }}
  with_items: '{{ sssd_conf_d_files.files }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12(3)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ldap_configure_tls_ca_dir
  - unknown_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_sssd_ldap_tls_ca_dir:var:1" value-id="xccdf_org.ssgproject.content_value_var_sssd_ldap_tls_ca_dir"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sssd_ldap_configure_tls_ca_dir:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sssd_ldap_configure_tls_ca_dir_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sssd_ldap_configure_tls_reqcert" selected="false" severity="medium">
              <xccdf-1.2:title>Configure SSSD LDAP Backend Client to Demand a Valid Certificate from the Server</xccdf-1.2:title>
              <xccdf-1.2:description>Configure SSSD to demand a valid certificate from the server to
protect the integrity of LDAP remote access sessions by setting
the <html:pre>ldap_tls_reqcert</html:pre> option in <html:pre>/etc/sssd/sssd.conf</html:pre>
to <html:code>demand</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-12(3)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R67</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Without a valid certificate presented to the LDAP client backend, the identity of a
server can be forged compromising LDAP remote access sessions.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#sssd-ldap"/>
              <xccdf-1.2:fix id="sssd_ldap_configure_tls_reqcert" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; rpm --quiet -q sssd-common; then

SSSD_CONF="/etc/sssd/sssd.conf"
LDAP_REGEX='[[:space:]]*\[domain\/[^]]*]([^(\n)]*(\n)+)+?[[:space:]]*ldap_tls_reqcert'
AD_REGEX='[[:space:]]*\[domain\/[^]]*]([^(\n)]*(\n)+)+?[[:space:]]*id_provider[[:space:]]*=[[:space:]]*((?i)ad)[[:space:]]*$'
DOMAIN_REGEX="[[:space:]]*\[domain\/[^]]*]"

# Check if id_provider is not set to ad (Active Directory) which makes start_tls not applicable, note the -v option to invert the grep.
# Try to find [domain/..] and ldap_tls_reqcert in sssd.conf, if it exists, set to 'demand'
# if ldap_tls_reqcert isn't here, add it
# if [domain/..] doesn't exist, add it here for default domain
if grep -qvzosP $AD_REGEX $SSSD_CONF; then
        if grep -qzosP $LDAP_REGEX $SSSD_CONF; then
                
                sed -i "s#ldap_tls_reqcert[^(\n)]*#ldap_tls_reqcert = demand#" $SSSD_CONF
        elif grep -qs $DOMAIN_REGEX $SSSD_CONF; then
                sed -i "/$DOMAIN_REGEX/a ldap_tls_reqcert = demand" $SSSD_CONF
        else
                if test -f "$SSSD_CONF"; then
                        echo -e "[domain/default]\nldap_tls_reqcert = demand" &gt;&gt; $SSSD_CONF
                else
                        echo "Config file '$SSSD_CONF' doesnt exist, not remediating, assuming non-applicability." &gt;&amp;2
                fi
        fi
fi

readarray -t SSSD_CONF_D_FILES &lt; &lt;(find /etc/sssd/conf.d/ -name "*.conf")
for SSSD_CONF_D_FILE in "${SSSD_CONF_D_FILES[@]}"; do
    sed -i "s#ldap_tls_reqcert[^(\n)]*#ldap_tls_reqcert = demand#" "$SSSD_CONF_D_FILE"
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sssd_ldap_configure_tls_reqcert" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12(3)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ldap_configure_tls_reqcert
  - unknown_strategy

- name: Test for id_provider different than Active Directory (ad)
  ansible.builtin.command: grep -qzosP '[[:space:]]*\[domain\/[^]]*]([^(\n)]*(\n)+)+?[[:space:]]*id_provider[[:space:]]*=[[:space:]]*((?i)ad)[[:space:]]*$'
    /etc/sssd/sssd.conf
  register: test_id_provider
  failed_when: false
  changed_when: false
  check_mode: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12(3)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ldap_configure_tls_reqcert
  - unknown_strategy

- name: Test for domain group
  ansible.builtin.command: grep '\s*\[domain\/[^]]*]' /etc/sssd/sssd.conf
  register: test_grep_domain
  failed_when: false
  changed_when: false
  check_mode: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12(3)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ldap_configure_tls_reqcert
  - unknown_strategy

- name: Add default domain group and set ldap_tls_reqcert in sssd configuration (if
    no domain there)
  community.general.ini_file:
    path: /etc/sssd/sssd.conf
    section: '{{ item.section }}'
    option: '{{ item.option }}'
    value: '{{ item.value }}'
    mode: 384
  with_items:
  - section: sssd
    option: domains
    value: default
  - section: domain/default
    option: ldap_tls_reqcert
    value: demand
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  - test_grep_domain.stdout is defined
  - test_grep_domain.stdout | length &lt; 1
  - test_id_provider.stdout is defined
  - test_id_provider.stdout | length &lt; 1
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12(3)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ldap_configure_tls_reqcert
  - unknown_strategy

- name: Set ldap_tls_reqcert in sssd configuration
  community.general.ini_file:
    path: /etc/sssd/sssd.conf
    section: '{{ test_grep_domain.stdout | regex_replace(''\[(.*)\]'',''\1'') }}'
    option: ldap_tls_reqcert
    value: demand
    mode: 384
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  - test_grep_domain.stdout is defined
  - test_grep_domain.stdout | length &gt; 0
  - test_id_provider.stdout is defined
  - test_id_provider.stdout | length &lt; 1
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12(3)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ldap_configure_tls_reqcert
  - unknown_strategy

- name: Find all the conf files inside /etc/sssd/conf.d/
  ansible.builtin.find:
    paths: /etc/sssd/conf.d/
    patterns: '*.conf'
  register: sssd_conf_d_files
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12(3)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ldap_configure_tls_reqcert
  - unknown_strategy

- name: Set ldap_tls_reqcert to demand in /etc/sssd/conf.d/ if exists
  ansible.builtin.replace:
    path: '{{ item.path }}'
    regexp: '[^#]*ldap_tls_reqcert.*'
    replace: ldap_tls_reqcert = demand
  with_items: '{{ sssd_conf_d_files.files }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-12(3)
  - low_complexity
  - medium_disruption
  - medium_severity
  - no_reboot_needed
  - sssd_ldap_configure_tls_reqcert
  - unknown_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sssd_ldap_configure_tls_reqcert:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sssd_ldap_configure_tls_reqcert_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_sssd_ldap_start_tls" selected="false" severity="high">
              <xccdf-1.2:title>Configure SSSD LDAP Backend to Use TLS For All Transactions</xccdf-1.2:title>
              <xccdf-1.2:description>The LDAP client should be configured to implement TLS for the integrity
of all remote LDAP authentication sessions. If the <html:code>id_provider</html:code> is
set to <html:code>ldap</html:code> or <html:code>ipa</html:code> in <html:code>/etc/sssd/sssd.conf</html:code> or any of the
<html:code>/etc/sssd/sssd.conf.d</html:code> configuration files, <html:code>ldap_id_use_start_tls</html:code>
must be set to <html:code>true</html:code>.
<html:br/><html:br/>
To check if LDAP is configured to use TLS when <html:code>id_provider</html:code> is
set to <html:code>ldap</html:code> or <html:code>ipa</html:code>, use the following command:
<html:pre>$ sudo grep -i ldap_id_use_start_tls /etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.3.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000250-GPOS-00093</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R67</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Without cryptographic integrity protections, information can be
altered by unauthorized users without detection. The ssl directive specifies
whether to use TLS or not. If not specified it will default to no.
It should be set to start_tls rather than doing LDAP over SSL.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#sssd-ldap"/>
              <xccdf-1.2:fix id="sssd_ldap_start_tls" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; rpm --quiet -q sssd-common; then

SSSD_CONF="/etc/sssd/sssd.conf"
LDAP_REGEX='[[:space:]]*\[domain\/[^]]*]([^(\n)]*(\n)+)+?[[:space:]]*ldap_id_use_start_tls'
AD_REGEX='[[:space:]]*\[domain\/[^]]*]([^(\n)]*(\n)+)+?[[:space:]]*id_provider[[:space:]]*=[[:space:]]*((?i)ad)[[:space:]]*$'
DOMAIN_REGEX="[[:space:]]*\[domain\/[^]]*]"

# Check if id_provider is not set to ad (Active Directory) which makes start_tls not applicable, note the -v option to invert the grep.
# Try to find [domain/..] and ldap_id_use_start_tls in sssd.conf, if it exists, set to 'true'
# if ldap_id_use_start_tls isn't here, add it
# if [domain/..] doesn't exist, add it here for default domain
if grep -qvzosP $AD_REGEX $SSSD_CONF; then
        if grep -qzosP $LDAP_REGEX $SSSD_CONF; then
                
                sed -i "s#ldap_id_use_start_tls[^(\n)]*#ldap_id_use_start_tls = true#" $SSSD_CONF
        elif grep -qs $DOMAIN_REGEX $SSSD_CONF; then
                sed -i "/$DOMAIN_REGEX/a ldap_id_use_start_tls = true" $SSSD_CONF
        else
                if test -f "$SSSD_CONF"; then
                        echo -e "[domain/default]\nldap_id_use_start_tls = true" &gt;&gt; $SSSD_CONF
                else
                        echo "Config file '$SSSD_CONF' doesnt exist, not remediating, assuming non-applicability." &gt;&amp;2
                fi
        fi
fi

readarray -t SSSD_CONF_D_FILES &lt; &lt;(find /etc/sssd/conf.d/ -name "*.conf")
for SSSD_CONF_D_FILE in "${SSSD_CONF_D_FILES[@]}"; do
    sed -i "s#ldap_id_use_start_tls[^(\n)]*#ldap_id_use_start_tls = true#" "$SSSD_CONF_D_FILE"
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="medium" id="sssd_ldap_start_tls" reboot="false" strategy="unknown" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - sssd_ldap_start_tls
  - unknown_strategy

- name: Test for id_provider different than Active Directory (ad)
  ansible.builtin.command: grep -qzosP '[[:space:]]*\[domain\/[^]]*]([^(\n)]*(\n)+)+?[[:space:]]*id_provider[[:space:]]*=[[:space:]]*((?i)ad)[[:space:]]*$'
    /etc/sssd/sssd.conf
  register: test_id_provider
  failed_when: false
  changed_when: false
  check_mode: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - sssd_ldap_start_tls
  - unknown_strategy

- name: Test for domain group
  ansible.builtin.command: grep '\s*\[domain\/[^]]*]' /etc/sssd/sssd.conf
  register: test_grep_domain
  failed_when: false
  changed_when: false
  check_mode: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - sssd_ldap_start_tls
  - unknown_strategy

- name: Add default domain group and set ldap_id_use_start_tls in sssd configuration
    (if no domain there)
  community.general.ini_file:
    path: /etc/sssd/sssd.conf
    section: '{{ item.section }}'
    option: '{{ item.option }}'
    value: '{{ item.value }}'
    mode: 384
  with_items:
  - section: sssd
    option: domains
    value: default
  - section: domain/default
    option: ldap_id_use_start_tls
    value: 'true'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  - test_grep_domain.stdout is defined
  - test_grep_domain.stdout | length &lt; 1
  - test_id_provider.stdout is defined
  - test_id_provider.stdout | length &lt; 1
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - sssd_ldap_start_tls
  - unknown_strategy

- name: Set ldap_id_use_start_tls in sssd configuration
  community.general.ini_file:
    path: /etc/sssd/sssd.conf
    section: '{{ test_grep_domain.stdout | regex_replace(''\[(.*)\]'',''\1'') }}'
    option: ldap_id_use_start_tls
    value: 'true'
    mode: 384
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  - test_grep_domain.stdout is defined
  - test_grep_domain.stdout | length &gt; 0
  - test_id_provider.stdout is defined
  - test_id_provider.stdout | length &lt; 1
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - sssd_ldap_start_tls
  - unknown_strategy

- name: Find all the conf files inside /etc/sssd/conf.d/
  ansible.builtin.find:
    paths: /etc/sssd/conf.d/
    patterns: '*.conf'
  register: sssd_conf_d_files
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - sssd_ldap_start_tls
  - unknown_strategy

- name: Set ldap_id_use_start_tls to true in /etc/sssd/conf.d/ if exists
  ansible.builtin.replace:
    path: '{{ item.path }}'
    regexp: '[^#]*ldap_id_use_start_tls.*'
    replace: ldap_id_use_start_tls = true
  with_items: '{{ sssd_conf_d_files.files }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - '"sssd-common" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - high_severity
  - low_complexity
  - medium_disruption
  - no_reboot_needed
  - sssd_ldap_start_tls
  - unknown_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-sssd_ldap_start_tls:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-sssd_ldap_start_tls_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_usbguard">
          <xccdf-1.2:title>USBGuard daemon</xccdf-1.2:title>
          <xccdf-1.2:description>The USBGuard daemon enforces the USB device authorization policy for all USB devices.</xccdf-1.2:description>
          <xccdf-1.2:platform idref="#not_s390x_arch_and_system_with_kernel"/>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_usbguard_installed" selected="false" severity="medium">
            <xccdf-1.2:title>Install usbguard Package</xccdf-1.2:title>
            <xccdf-1.2:description>
The <html:code>usbguard</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install usbguard</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-8(3)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000378-GPOS-00163</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000141-CTR-000315</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1418</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040139</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244547r1014811_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale><html:code>usbguard</html:code> is a software framework that helps to protect
against rogue USB devices by implementing basic whitelisting/blacklisting
capabilities based on USB device attributes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_usbguard_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( grep -sqE "^.*\.s390x$" /proc/sys/kernel/osrelease || grep -sqE "^s390x$" /proc/sys/kernel/arch; ) &amp;&amp; rpm --quiet -q kernel ); then

if ! rpm -q --quiet "usbguard" ; then
    yum install -y "usbguard"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_usbguard_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040139
  - NIST-800-53-CM-8(3)
  - NIST-800-53-IA-3
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_usbguard_installed

- name: Ensure usbguard is installed
  ansible.builtin.package:
    name: usbguard
    state: present
  when: ( ansible_architecture != "s390x" and "kernel" in ansible_facts.packages )
  tags:
  - DISA-STIG-RHEL-08-040139
  - NIST-800-53-CM-8(3)
  - NIST-800-53-IA-3
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_usbguard_installed
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_usbguard_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_usbguard

class install_usbguard {
  package { 'usbguard':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_usbguard_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=usbguard
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_usbguard_installed" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
  extensions:
    - usbguard
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="package_usbguard_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "usbguard"
version = "*"
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_usbguard_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install usbguard
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="package_usbguard_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install usbguard
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_usbguard_installed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_usbguard_installed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_usbguard_enabled" selected="false" severity="medium">
            <xccdf-1.2:title>Enable the USBGuard Service</xccdf-1.2:title>
            <xccdf-1.2:description>The USBGuard service should be enabled.

The <html:code>usbguard</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable usbguard.service</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-8(3)(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000378-GPOS-00163</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000141-CTR-000315</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1418</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040141</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244548r1014815_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The <html:code>usbguard</html:code> service must be running in order to
enforce the USB device authorization policy for all USB devices.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_usbguard_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( grep -sqE "^.*\.s390x$" /proc/sys/kernel/osrelease || grep -sqE "^s390x$" /proc/sys/kernel/arch; ) &amp;&amp; rpm --quiet -q kernel ); then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'usbguard.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'usbguard.service'
fi
"$SYSTEMCTL_EXEC" enable 'usbguard.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_usbguard_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040141
  - NIST-800-53-CM-8(3)(a)
  - NIST-800-53-IA-3
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_usbguard_enabled

- name: Enable the USBGuard Service - Enable service usbguard
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable the USBGuard Service - Enable Service usbguard
    ansible.builtin.systemd:
      name: usbguard
      enabled: true
      state: started
      masked: false
    when:
    - '"usbguard" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040141
  - NIST-800-53-CM-8(3)(a)
  - NIST-800-53-IA-3
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_usbguard_enabled
  - special_service_block
  when: ( ansible_architecture != "s390x" and "kernel" in ansible_facts.packages )
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_usbguard_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_usbguard

class enable_usbguard {
  service {'usbguard':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_usbguard_enabled" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
metadata:
  annotations:
    complianceascode.io/depends-on: xccdf_org.ssgproject.content_rule_package_usbguard_installed
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: usbguard.service
        enabled: true
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="service_usbguard_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["usbguard"]
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="service_usbguard_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable usbguard
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_usbguard_enabled:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_usbguard_enabled_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_configure_usbguard_auditbackend" selected="false" severity="low">
            <xccdf-1.2:title>Log USBGuard daemon audit events using Linux Audit</xccdf-1.2:title>
            <xccdf-1.2:description>To configure USBGuard daemon to log via Linux Audit
(as opposed directly to a file),
<html:code>AuditBackend</html:code> option in <html:code>/etc/usbguard/usbguard-daemon.conf</html:code>
needs to be set to <html:code>LinuxAudit</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-8(3)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000141-CTR-000315</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030603</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230470r1017261_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Using the Linux Audit logging allows for centralized trace
of events.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#package_usbguard"/>
            <xccdf-1.2:fix complexity="low" disruption="low" id="configure_usbguard_auditbackend" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( grep -sqE "^.*\.s390x$" /proc/sys/kernel/osrelease || grep -sqE "^s390x$" /proc/sys/kernel/arch; ) &amp;&amp; rpm --quiet -q kernel ) &amp;&amp; { rpm --quiet -q usbguard; }; then

if [ -e "/etc/usbguard/usbguard-daemon.conf" ] ; then
    
    LC_ALL=C sed -i "/^[ \\t]*AuditBackend=/Id" "/etc/usbguard/usbguard-daemon.conf"
else
    touch "/etc/usbguard/usbguard-daemon.conf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/usbguard/usbguard-daemon.conf"

cp "/etc/usbguard/usbguard-daemon.conf" "/etc/usbguard/usbguard-daemon.conf.bak"
# Insert at the end of the file
printf '%s\n' "AuditBackend=LinuxAudit" &gt;&gt; "/etc/usbguard/usbguard-daemon.conf"
# Clean up after ourselves.
rm "/etc/usbguard/usbguard-daemon.conf.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="configure_usbguard_auditbackend" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030603
  - NIST-800-53-AU-2
  - NIST-800-53-CM-8(3)
  - NIST-800-53-IA-3
  - configure_strategy
  - configure_usbguard_auditbackend
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed

- name: Log USBGuard daemon audit events using Linux Audit
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/usbguard/usbguard-daemon.conf
      create: true
      regexp: (?i)^[ \\t]*AuditBackend=
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/usbguard/usbguard-daemon.conf
    ansible.builtin.lineinfile:
      path: /etc/usbguard/usbguard-daemon.conf
      create: true
      regexp: (?i)^[ \\t]*AuditBackend=
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/usbguard/usbguard-daemon.conf
    ansible.builtin.lineinfile:
      path: /etc/usbguard/usbguard-daemon.conf
      create: true
      regexp: (?i)^[ \\t]*AuditBackend=
      line: AuditBackend=LinuxAudit
      state: present
  when:
  - ( ansible_architecture != "s390x" and "kernel" in ansible_facts.packages )
  - '"usbguard" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030603
  - NIST-800-53-AU-2
  - NIST-800-53-CM-8(3)
  - NIST-800-53-IA-3
  - configure_strategy
  - configure_usbguard_auditbackend
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="configure_usbguard_auditbackend" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
metadata:
  annotations:
    complianceascode.io/depends-on: xccdf_org.ssgproject.content_rule_package_usbguard_installed
    complianceascode.io/ocp-version: '&gt;=4.7.0'
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %0A%23%0A%23%20Rule%20set%20file%20path.%0A%23%0A%23%20The%20USBGuard%20daemon%20will%20use%20this%20file%20to%20load%20the%20policy%0A%23%20rule%20set%20from%20it%20and%20to%20write%20new%20rules%20received%20via%20the%0A%23%20IPC%20interface.%0A%23%0A%23%20RuleFile%3D/path/to/rules.conf%0A%23%0ARuleFile%3D/etc/usbguard/rules.conf%0A%0A%23%0A%23%20Rule%20set%20folder%20path.%0A%23%0A%23%20The%20USBGuard%20daemon%20will%20use%20this%20folder%20to%20load%20the%20policy%0A%23%20rule%20set%20from%20it%20and%20to%20write%20new%20rules%20received%20via%20the%0A%23%20IPC%20interface.%20Usually%2C%20we%20set%20the%20option%20to%0A%23%20/etc/usbguard/rules.d/.%20The%20USBGuard%20daemon%20is%20supposed%20to%0A%23%20behave%20like%20any%20other%20standard%20Linux%20daemon%20therefore%20it%0A%23%20loads%20rule%20files%20in%20alpha-numeric%20order.%20File%20names%20inside%0A%23%20RuleFolder%20directory%20should%20start%20with%20a%20two-digit%20number%0A%23%20prefix%20indicating%20the%20position%2C%20in%20which%20the%20rules%20are%0A%23%20scanned%20by%20the%20daemon.%0A%23%0A%23%20RuleFolder%3D/path/to/rulesfolder/%0A%23%0ARuleFolder%3D/etc/usbguard/rules.d/%0A%0A%23%0A%23%20Implicit%20policy%20target.%0A%23%0A%23%20How%20to%20treat%20devices%20that%20don%27t%20match%20any%20rule%20in%20the%0A%23%20policy.%20One%20of%3A%0A%23%0A%23%20%2A%20allow%20%20-%20authorize%20the%20device%0A%23%20%2A%20block%20%20-%20block%20the%20device%0A%23%20%2A%20reject%20-%20remove%20the%20device%0A%23%0AImplicitPolicyTarget%3Dblock%0A%0A%23%0A%23%20Present%20device%20policy.%0A%23%0A%23%20How%20to%20treat%20devices%20that%20are%20already%20connected%20when%20the%0A%23%20daemon%20starts.%20One%20of%3A%0A%23%0A%23%20%2A%20allow%20%20%20%20%20%20%20%20-%20authorize%20every%20present%20device%0A%23%20%2A%20block%20%20%20%20%20%20%20%20-%20deauthorize%20every%20present%20device%0A%23%20%2A%20reject%20%20%20%20%20%20%20-%20remove%20every%20present%20device%0A%23%20%2A%20keep%20%20%20%20%20%20%20%20%20-%20just%20sync%20the%20internal%20state%20and%20leave%20it%0A%23%20%2A%20apply-policy%20-%20evaluate%20the%20ruleset%20for%20every%20present%0A%23%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20device%0A%23%0APresentDevicePolicy%3Dapply-policy%0A%0A%23%0A%23%20Present%20controller%20policy.%0A%23%0A%23%20How%20to%20treat%20USB%20controllers%20that%20are%20already%20connected%0A%23%20when%20the%20daemon%20starts.%20One%20of%3A%0A%23%0A%23%20%2A%20allow%20%20%20%20%20%20%20%20-%20authorize%20every%20present%20device%0A%23%20%2A%20block%20%20%20%20%20%20%20%20-%20deauthorize%20every%20present%20device%0A%23%20%2A%20reject%20%20%20%20%20%20%20-%20remove%20every%20present%20device%0A%23%20%2A%20keep%20%20%20%20%20%20%20%20%20-%20just%20sync%20the%20internal%20state%20and%20leave%20it%0A%23%20%2A%20apply-policy%20-%20evaluate%20the%20ruleset%20for%20every%20present%0A%23%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20device%0A%23%0APresentControllerPolicy%3Dkeep%0A%0A%23%0A%23%20Inserted%20device%20policy.%0A%23%0A%23%20How%20to%20treat%20USB%20devices%20that%20are%20already%20connected%0A%23%20%2Aafter%2A%20the%20daemon%20starts.%20One%20of%3A%0A%23%0A%23%20%2A%20block%20%20%20%20%20%20%20%20-%20deauthorize%20every%20present%20device%0A%23%20%2A%20reject%20%20%20%20%20%20%20-%20remove%20every%20present%20device%0A%23%20%2A%20apply-policy%20-%20evaluate%20the%20ruleset%20for%20every%20present%0A%23%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20device%0A%23%0AInsertedDevicePolicy%3Dapply-policy%0A%0A%23%0A%23%20Control%20which%20devices%20are%20authorized%20by%20default.%0A%23%0A%23%20The%20USBGuard%20daemon%20modifies%20some%20the%20default%20authorization%20state%20attributes%0A%23%20of%20controller%20devices.%20This%20setting%2C%20enables%20you%20to%20define%20what%20value%20the%0A%23%20default%20authorization%20is%20set%20to.%0A%23%0A%23%20%2A%20keep%20%20%20%20%20%20%20%20%20-%20do%20not%20change%20the%20authorization%20state%0A%23%20%2A%20none%20%20%20%20%20%20%20%20%20-%20every%20new%20device%20starts%20out%20deauthorized%0A%23%20%2A%20all%20%20%20%20%20%20%20%20%20%20-%20every%20new%20device%20starts%20out%20authorized%0A%23%20%2A%20internal%20%20%20%20%20-%20internal%20devices%20start%20out%20authorized%2C%20external%20devices%20start%0A%23%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20out%20deauthorized%20%28this%20requires%20the%20ACPI%20tables%20to%20properly%0A%23%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20label%20internal%20devices%2C%20and%20kernel%20support%29%0A%23%0A%23AuthorizedDefault%3Dnone%0A%0A%23%0A%23%20Restore%20controller%20device%20state.%0A%23%0A%23%20The%20USBGuard%20daemon%20modifies%20some%20attributes%20of%20controller%0A%23%20devices%20like%20the%20default%20authorization%20state%20of%20new%20child%20device%0A%23%20instances.%20Using%20this%20setting%2C%20you%20can%20control%20whether%20the%0A%23%20daemon%20will%20try%20to%20restore%20the%20attribute%20values%20to%20the%20state%0A%23%20before%20modification%20on%20shutdown.%0A%23%0A%23%20SECURITY%20CONSIDERATIONS%3A%20If%20set%20to%20true%2C%20the%20USB%20authorization%0A%23%20policy%20could%20be%20bypassed%20by%20performing%20some%20sort%20of%20attack%20on%20the%0A%23%20daemon%20%28via%20a%20local%20exploit%20or%20via%20a%20USB%20device%29%20to%20make%20it%20shutdown%0A%23%20and%20restore%20to%20the%20operating-system%20default%20state%20%28known%20to%20be%20permissive%29.%0A%23%0ARestoreControllerDeviceState%3Dfalse%0A%0A%23%0A%23%20Device%20manager%20backend%0A%23%0A%23%20Which%20device%20manager%20backend%20implementation%20to%20use.%20One%20of%3A%0A%23%0A%23%20%2A%20uevent%20%20%20-%20Netlink%20based%20implementation%20which%20uses%20sysfs%20to%20scan%20for%20present%0A%23%20%20%20%20%20%20%20%20%20%20%20%20%20%20devices%20and%20an%20uevent%20netlink%20socket%20for%20receiving%20USB%20device%0A%23%20%20%20%20%20%20%20%20%20%20%20%20%20%20related%20events.%0A%23%20%2A%20umockdev%20-%20umockdev%20based%20device%20manager%20capable%20of%20simulating%20devices%20based%0A%23%20%20%20%20%20%20%20%20%20%20%20%20%20%20on%20umockdev-record%20files.%20Useful%20for%20testing.%0A%23%0ADeviceManagerBackend%3Duevent%0A%0A%23%21%21%21%20WARNING%3A%20It%27s%20good%20practice%20to%20set%20at%20least%20one%20of%20the%20%21%21%21%0A%23%21%21%21%20%20%20%20%20%20%20%20%20%20two%20options%20bellow.%20If%20none%20of%20them%20are%20set%2C%20%20%21%21%21%0A%23%21%21%21%20%20%20%20%20%20%20%20%20%20the%20daemon%20will%20accept%20IPC%20connections%20from%20%20%20%21%21%21%0A%23%21%21%21%20%20%20%20%20%20%20%20%20%20anyone%2C%20thus%20allowing%20anyone%20to%20modify%20the%20%20%20%20%21%21%21%0A%23%21%21%21%20%20%20%20%20%20%20%20%20%20rule%20set%20and%20%28de%29authorize%20USB%20devices.%20%20%20%20%20%20%20%21%21%21%0A%0A%23%0A%23%20Users%20allowed%20to%20use%20the%20IPC%20interface.%0A%23%0A%23%20A%20space%20delimited%20list%20of%20usernames%20that%20the%20daemon%20will%0A%23%20accept%20IPC%20connections%20from.%0A%23%0A%23%20IPCAllowedUsers%3Dusername1%20username2%20...%0A%23%0AIPCAllowedUsers%3Droot%0A%0A%23%0A%23%20Groups%20allowed%20to%20use%20the%20IPC%20interface.%0A%23%0A%23%20A%20space%20delimited%20list%20of%20groupnames%20that%20the%20daemon%20will%0A%23%20accept%20IPC%20connections%20from.%0A%23%0A%23%20IPCAllowedGroups%3Dgroupname1%20groupname2%20...%0A%23%0AIPCAllowedGroups%3Dwheel%0A%0A%23%0A%23%20IPC%20access%20control%20definition%20files%20path.%0A%23%0A%23%20The%20files%20at%20this%20location%20will%20be%20interpreted%20by%20the%20daemon%0A%23%20as%20access%20control%20definition%20files.%20The%20%28base%29name%20of%20a%20file%0A%23%20should%20be%20in%20the%20form%3A%0A%23%0A%23%20%20%20%5Buser%5D%5B%3A%3Cgroup%3E%5D%0A%23%0A%23%20and%20should%20contain%20lines%20in%20the%20form%3A%0A%23%0A%23%20%20%20%3Csection%3E%3D%5Bprivilege%5D%20...%0A%23%0A%23%20This%20way%20each%20file%20defines%20who%20is%20able%20to%20connect%20to%20the%20IPC%0A%23%20bus%20and%20what%20privileges%20he%20has.%0A%23%0AIPCAccessControlFiles%3D/etc/usbguard/IPCAccessControl.d/%0A%0A%23%0A%23%20Generate%20device%20specific%20rules%20including%20the%20%22via-port%22%0A%23%20attribute.%0A%23%0A%23%20This%20option%20modifies%20the%20behavior%20of%20the%20allowDevice%0A%23%20action.%20When%20instructed%20to%20generate%20a%20permanent%20rule%2C%0A%23%20the%20action%20can%20generate%20a%20port%20specific%20rule.%20Because%0A%23%20some%20systems%20have%20unstable%20port%20numbering%2C%20the%20generated%0A%23%20rule%20might%20not%20match%20the%20device%20after%20rebooting%20the%20system.%0A%23%0A%23%20If%20set%20to%20false%2C%20the%20generated%20rule%20will%20still%20contain%0A%23%20the%20%22parent-hash%22%20attribute%20which%20also%20defines%20an%20association%0A%23%20to%20the%20parent%20device.%20See%20usbguard-rules.conf%285%29%20for%20more%0A%23%20details.%0A%23%0ADeviceRulesWithPort%3Dfalse%0A%0A%23%0A%23%20USBGuard%20Audit%20events%20log%20backend%0A%23%0A%23%20One%20of%3A%0A%23%0A%23%20%2A%20FileAudit%20-%20Log%20audit%20events%20into%20a%20file%20specified%20by%0A%23%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20AuditFilePath%20setting%20%28see%20below%29%0A%23%20%2A%20LinuxAudit%20-%20Log%20audit%20events%20using%20the%20Linux%20Audit%0A%23%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20subsystem%20%28using%20audit_log_user_message%29%0A%23%0AAuditBackend%3DLinuxAudit%0A%0A%23%0A%23%20USBGuard%20audit%20events%20log%20file%20path.%0A%23%0A%23AuditFilePath%3D/var/log/usbguard/usbguard-audit.log%0A%0A%23%0A%23%20Hides%20personally%20identifiable%20information%20such%20as%20device%20serial%20numbers%20and%0A%23%20hashes%20of%20descriptors%20%28which%20include%20the%20serial%20number%29%20from%20audit%20entries.%0A%23%0A%23HidePII%3Dfalse }}
        mode: 0600
        path: /etc/usbguard/usbguard-daemon.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-configure_usbguard_auditbackend:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-configure_usbguard_auditbackend_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_usbguard_allow_hid" selected="false" severity="medium">
            <xccdf-1.2:title>Authorize Human Interface Devices in USBGuard daemon</xccdf-1.2:title>
            <xccdf-1.2:description>To allow authorization of Human Interface Devices (keyboard, mouse)
by USBGuard daemon,
add the line
<html:code>allow with-interface match-all { 03:*:* }</html:code>
to <html:code>/etc/usbguard/rules.conf</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">This rule should be understood primarily as a convenience administration feature. This rule ensures that if the USBGuard default rules.conf file is present, it will alter it so that USB human interface devices are allowed. However, if the rules.conf file is altered by system administrator, the rule does not check if USB human interface devices are allowed. This assumes that an administrator modified the file with some purpose in mind.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000114-GPOS-00059</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Without allowing Human Interface Devices, it might not be possible
to interact with the system.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="usbguard_allow_hid" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( grep -sqE "^.*\.s390x$" /proc/sys/kernel/osrelease || grep -sqE "^s390x$" /proc/sys/kernel/arch; ) &amp;&amp; rpm --quiet -q kernel ); then

# path of file with Usbguard rules
rulesfile="/etc/usbguard/rules.conf"

echo "allow with-interface match-all { 03:*:* }" &gt;&gt; $rulesfile

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="usbguard_allow_hid" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - usbguard_allow_hid

- name: Allow HID devices
  ansible.builtin.lineinfile:
    path: /etc/usbguard/rules.conf
    create: true
    regexp: ''
    line: allow with-interface match-all { 03:*:* }
    state: present
  when: ( ansible_architecture != "s390x" and "kernel" in ansible_facts.packages )
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - usbguard_allow_hid
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-usbguard_allow_hid:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-usbguard_allow_hid_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_usbguard_allow_hid_and_hub" selected="false" severity="medium">
            <xccdf-1.2:title>Authorize Human Interface Devices and USB hubs in USBGuard daemon</xccdf-1.2:title>
            <xccdf-1.2:description>To allow authorization of USB devices combining human interface device and hub capabilities
by USBGuard daemon,
add the line
<html:code>allow with-interface match-all { 03:*:* 09:00:* }</html:code>
to <html:code>/etc/usbguard/rules.conf</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">This rule should be understood primarily as a convenience administration feature. This rule ensures that if the USBGuard default rules.conf file is present, it will alter it so that USB human interface devices and hubs are allowed. However, if the rules.conf file is altered by system administrator, the rule does not check if USB human interface devices and hubs are allowed. This assumes that an administrator modified the file with some purpose in mind.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-8(3)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FMT_SMF_EXT.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000114-GPOS-00059</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000092-CTR-000165</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1418</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Without allowing Human Interface Devices, it might not be possible
to interact with the system. Without allowing hubs, it might not be possible to use any
USB devices on the system.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="usbguard_allow_hid_and_hub" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( grep -sqE "^.*\.s390x$" /proc/sys/kernel/osrelease || grep -sqE "^s390x$" /proc/sys/kernel/arch; ) &amp;&amp; rpm --quiet -q kernel ); then

echo "allow with-interface match-all { 03:*:* 09:00:* }" &gt;&gt; /etc/usbguard/rules.conf

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="usbguard_allow_hid_and_hub" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-8(3)
  - NIST-800-53-IA-3
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - usbguard_allow_hid_and_hub

- name: Allow HID devices and hubs
  ansible.builtin.lineinfile:
    path: /etc/usbguard/rules.conf
    create: true
    regexp: ''
    line: allow with-interface match-all { 03:*:* 09:00:* }
    state: present
  when: ( ansible_architecture != "s390x" and "kernel" in ansible_facts.packages )
  tags:
  - NIST-800-53-CM-8(3)
  - NIST-800-53-IA-3
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - usbguard_allow_hid_and_hub
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="usbguard_allow_hid_and_hub" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
metadata:
  annotations:
    complianceascode.io/depends-on: xccdf_org.ssgproject.content_rule_package_usbguard_installed
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %0Aallow%20with-interface%20match-all%20%7B%2003%3A%2A%3A%2A%2009%3A00%3A%2A%20%7D }}
        mode: 0600
        path: /etc/usbguard/rules.d/75-hid-and-hub.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-usbguard_allow_hid_and_hub:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-usbguard_allow_hid_and_hub_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_usbguard_allow_hub" selected="false" severity="medium">
            <xccdf-1.2:title>Authorize USB hubs in USBGuard daemon</xccdf-1.2:title>
            <xccdf-1.2:description>To allow authorization of USB hub devices by USBGuard daemon,
add line
<html:code>allow with-interface match-all { 09:00:* }</html:code>
to <html:code>/etc/usbguard/rules.conf</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">This rule should be understood primarily as a convenience administration feature. This rule ensures that if the USBGuard default rules.conf file is present, it will alter it so that USB hub devices are allowed. However, if the rules.conf file is altered by system administrator, the rule does not check if USB hub devices are allowed. This assumes that an administrator modified the file with some purpose in mind.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000114-GPOS-00059</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Without allowing hubs, it might not be possible to use any
USB devices on the system.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="usbguard_allow_hub" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( grep -sqE "^.*\.s390x$" /proc/sys/kernel/osrelease || grep -sqE "^s390x$" /proc/sys/kernel/arch; ) &amp;&amp; rpm --quiet -q kernel ); then

echo "allow with-interface match-all { 09:00:* }" &gt;&gt; /etc/usbguard/rules.conf

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="usbguard_allow_hub" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - usbguard_allow_hub

- name: Allow hubs
  ansible.builtin.lineinfile:
    path: /etc/usbguard/rules.conf
    create: true
    regexp: ''
    line: allow with-interface match-all { 09:00:* }
    state: present
  when: ( ansible_architecture != "s390x" and "kernel" in ansible_facts.packages )
  tags:
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - usbguard_allow_hub
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-usbguard_allow_hub:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-usbguard_allow_hub_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_usbguard_generate_policy" selected="false" severity="medium">
            <xccdf-1.2:title>Generate USBGuard Policy</xccdf-1.2:title>
            <xccdf-1.2:description>By default USBGuard when enabled prevents access to all USB devices and this lead
to inaccessible system if they use USB mouse/keyboard. To prevent this scenario,
the initial policy configuration must be generated based on current connected USB
devices.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-8(3)(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000378-GPOS-00163</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040140</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230524r1155418_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The <html:code>usbguard</html:code> must be configured to allow connected USB devices to work
properly, avoiding the system to become inaccessible.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="usbguard_generate_policy" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ( ! ( grep -sqE "^.*\.s390x$" /proc/sys/kernel/osrelease || grep -sqE "^s390x$" /proc/sys/kernel/arch; ) &amp;&amp; rpm --quiet -q kernel ); then

if rpm --quiet -q usbguard
then
    USBGUARD_CONF=/etc/usbguard/rules.conf
    if [ ! -f "$USBGUARD_CONF" ] || [ ! -s "$USBGUARD_CONF" ]; then
        usbguard generate-policy &gt; $USBGUARD_CONF
        if [ ! -s "$USBGUARD_CONF" ]; then
            # make sure OVAL check doesn't fail on systems where
            # generate-policy doesn't find any USB devices (for
            # example a system might not have a USB bus)
            echo "# No USB devices found" &gt; $USBGUARD_CONF
        fi
        # make sure it has correct permissions
        chmod 600 $USBGUARD_CONF

        SYSTEMCTL_EXEC='/usr/bin/systemctl'
        "$SYSTEMCTL_EXEC" unmask 'usbguard.service'
        "$SYSTEMCTL_EXEC" restart 'usbguard.service'
        "$SYSTEMCTL_EXEC" enable 'usbguard.service'
    fi
else
    echo "USBGuard is not installed. No remediation was applied!"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="usbguard_generate_policy" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040140
  - NIST-800-53-CM-8(3)(a)
  - NIST-800-53-IA-3
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - usbguard_generate_policy

- name: Generate USBGuard Policy
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Check that the /etc/usbguard/rules.conf exists
    ansible.builtin.stat:
      path: /etc/usbguard/rules.conf
    register: policy_file

  - name: Create USBGuard Policy configuration
    ansible.builtin.command: usbguard generate-policy
    register: policy
    when: not policy_file.stat.exists or policy_file.stat.size == 0

  - name: Copy the Generated Policy configuration to a persistent file
    ansible.builtin.copy:
      content: '{{ policy.stdout }}'
      dest: /etc/usbguard/rules.conf
      mode: 384
    when: not policy_file.stat.exists or policy_file.stat.size == 0

  - name: Add comment into /etc/usbguard/rules.conf when system has no USB devices
    ansible.builtin.lineinfile:
      path: /etc/usbguard/rules.conf
      line: '# No USB devices found'
      state: present
    when: not policy_file.stat.exists or policy_file.stat.size == 0

  - name: Enable service usbguard
    ansible.builtin.systemd:
      name: usbguard
      enabled: 'yes'
      state: started
      masked: 'no'
  when:
  - ( ansible_architecture != "s390x" and "kernel" in ansible_facts.packages )
  - '"usbguard" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040140
  - NIST-800-53-CM-8(3)(a)
  - NIST-800-53-IA-3
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - usbguard_generate_policy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-usbguard_generate_policy:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-usbguard_generate_policy_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_xwindows">
          <xccdf-1.2:title>X Window System</xccdf-1.2:title>
          <xccdf-1.2:description>The X Window System implementation included with the
system is called X.org.</xccdf-1.2:description>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_disabling_xwindows">
            <xccdf-1.2:title>Disable X Windows</xccdf-1.2:title>
            <xccdf-1.2:description>Unless there is a mission-critical reason for the
system to run a graphical user interface, ensure X is not set to start
automatically at boot and remove the X Windows software packages.
There is usually no reason to run X Windows
on a dedicated server system, as it increases the system's attack surface and consumes
system resources. Administrators of server systems should instead login via
SSH or on the text console.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_xorg-x11-server-Xwayland_removed" selected="false" severity="medium">
              <xccdf-1.2:title>Remove the X Windows Xwayland Package</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>xorg-x11-server-Xwayland</html:code> package can be removed with the following command:
<html:pre>
$ sudo yum erase xorg-x11-server-Xwayland</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">2.1.22</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unnecessary service packages must not be installed to decrease the attack
surface of the system. X Windows has a long history of security
vulnerabilities and should not be installed unless approved and documented.
Unless your organization specifically requires graphical login access via
X Windows, remove it to reduce the potential attack surface.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_package_gdm"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xorg-x11-server-Xwayland_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if ! ( rpm --quiet -q gdm ); then

# CAUTION: This remediation script will remove xorg-x11-server-Xwayland
# from the system, and may remove any packages
# that depend on xorg-x11-server-Xwayland. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "xorg-x11-server-Xwayland" ; then
yum remove -y "xorg-x11-server-Xwayland"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xorg-x11-server-Xwayland_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_xorg-x11-server-Xwayland_removed

- name: 'Remove the X Windows Xwayland Package: Ensure xorg-x11-server-Xwayland is
    removed'
  ansible.builtin.package:
    name: xorg-x11-server-Xwayland
    state: absent
  when: not ( "gdm" in ansible_facts.packages )
  tags:
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_xorg-x11-server-Xwayland_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xorg-x11-server-Xwayland_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_xorg-x11-server-Xwayland

class remove_xorg-x11-server-Xwayland {
  package { 'xorg-x11-server-Xwayland':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xorg-x11-server-Xwayland_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=xorg-x11-server-Xwayland
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xorg-x11-server-Xwayland_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove xorg-x11-server-Xwayland
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xorg-x11-server-Xwayland_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove xorg-x11-server-Xwayland
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_xorg-x11-server-Xwayland_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_xorg-x11-server-Xwayland_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_xorg-x11-server-common_removed" selected="false" severity="medium">
              <xccdf-1.2:title>Remove the X Windows Package Group</xccdf-1.2:title>
              <xccdf-1.2:description>By removing the xorg-x11-server-common package, the system no longer has X Windows
installed. If X Windows is not installed then the system cannot boot into graphical user mode.
This prevents the system from being accidentally or maliciously booted into a <html:code>graphical.target</html:code>
mode. To do so, run the following command:
<html:pre>$ sudo yum groupremove "X Window System"</html:pre>
<html:pre>$ sudo yum remove xorg-x11-server-common</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="functionality">The installation and use of a Graphical User Interface (GUI) increases your attack vector and decreases your
overall security posture. Removing the package xorg-x11-server-common package will remove the graphical target
which might bring your system to an inconsistent state requiring additional configuration to access the system
again. If a GUI is an operational requirement, a tailored profile that removes this rule should used before
continuing installation.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unnecessary service packages must not be installed to decrease the attack surface of the system. X windows has a long history of security
vulnerabilities and should not be installed unless approved and documented.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xorg-x11-server-common_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:sh">
# CAUTION: This remediation script will remove xorg-x11-server-common
# from the system, and may remove any packages
# that depend on xorg-x11-server-common. Execute this
# remediation AFTER testing on a non-production
# system!


if rpm -q --quiet "xorg-x11-server-common" ; then
yum remove -y "xorg-x11-server-common"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xorg-x11-server-common_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:ansible">- name: 'Remove the X Windows Package Group: Ensure xorg-x11-server-common is removed'
  ansible.builtin.package:
    name: xorg-x11-server-common
    state: absent
  tags:
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - disable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_xorg-x11-server-common_removed
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xorg-x11-server-common_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:puppet">
include remove_xorg-x11-server-common

class remove_xorg-x11-server-common {
  package { 'xorg-x11-server-common':
    ensure =&gt; 'purged',
  }
}
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xorg-x11-server-common_removed" reboot="false" strategy="disable" system="urn:redhat:anaconda:pre">

package --remove=xorg-x11-server-common
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xorg-x11-server-common_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">

package remove xorg-x11-server-common
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="package_xorg-x11-server-common_removed" reboot="false" strategy="disable" system="urn:xccdf:fix:script:bootc">

dnf remove xorg-x11-server-common
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_xorg-x11-server-common_removed:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_xorg-x11-server-common_removed_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_xwindows_remove_packages" selected="false" severity="medium">
              <xccdf-1.2:title>Disable graphical user interface</xccdf-1.2:title>
              <xccdf-1.2:description>By removing the following packages, the system no longer has X Windows installed.
 <html:code>xorg-x11-server-Xorg</html:code>
 <html:code>xorg-x11-server-common</html:code>
 <html:code>xorg-x11-server-utils</html:code>
 <html:code>xorg-x11-server-Xwayland</html:code>

If X Windows is not installed then the system cannot boot into graphical user mode.
This prevents the system from being accidentally or maliciously booted into a <html:code>graphical.target</html:code>
mode. To do so, run the following command:
<html:pre>sudo yum remove xorg-x11-server-Xorg xorg-x11-server-common xorg-x11-server-utils xorg-x11-server-Xwayland</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="functionality">The installation and use of a Graphical User Interface (GUI) increases your attack vector and decreases your
overall security posture. Removing the package xorg-x11-server-common package will remove the graphical target
which might bring your system to an inconsistent state requiring additional configuration to access the system
again.
The rule <html:code>xwindows_runlevel_target</html:code> can be used to configure the system to boot into the multi-user.target.
If a GUI is an operational requirement, a tailored profile that removes this rule should be used before
continuing installation.</xccdf-1.2:warning>
              <xccdf-1.2:warning category="general">This rule is disabled on Red Hat Virtualization Hosts and Managers, it will report not applicable.
X11 graphic libraries are dependency of OpenStack Cinderlib storage provider.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040320</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230553r1017315_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unnecessary service packages must not be installed to decrease the attack surface of the system.
X windows has a long history of security vulnerabilities and should not be installed unless approved and documented.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#no_ovirt"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="xwindows_remove_packages" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:sh">
# remove packages

if rpm -q --quiet "xorg-x11-server-Xorg" ; then
yum remove -y "xorg-x11-server-Xorg"
fi

if rpm -q --quiet "xorg-x11-server-common" ; then
yum remove -y "xorg-x11-server-common"
fi

if rpm -q --quiet "xorg-x11-server-utils" ; then
yum remove -y "xorg-x11-server-utils"
fi

if rpm -q --quiet "xorg-x11-server-Xwayland" ; then
yum remove -y "xorg-x11-server-Xwayland"
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="xwindows_remove_packages" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Disable graphical user interface - Ensure xorg-x11-server-Xorg is removed
  ansible.builtin.package:
    name: xorg-x11-server-Xorg
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040320
  - NIST-800-53-CM-6(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
  - xwindows_remove_packages

- name: Disable graphical user interface - Ensure xorg-x11-server-common is removed
  ansible.builtin.package:
    name: xorg-x11-server-common
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040320
  - NIST-800-53-CM-6(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
  - xwindows_remove_packages

- name: Disable graphical user interface - Ensure xorg-x11-server-utils is removed
  ansible.builtin.package:
    name: xorg-x11-server-utils
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040320
  - NIST-800-53-CM-6(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
  - xwindows_remove_packages

- name: Disable graphical user interface - Ensure xorg-x11-server-Xwayland is removed
  ansible.builtin.package:
    name: xorg-x11-server-Xwayland
    state: absent
  tags:
  - DISA-STIG-RHEL-08-040320
  - NIST-800-53-CM-6(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
  - xwindows_remove_packages
</xccdf-1.2:fix>
              <xccdf-1.2:fix id="xwindows_remove_packages" system="urn:redhat:anaconda:pre">
# remove packages

package --remove=xorg-x11-server-Xorg

package --remove=xorg-x11-server-common

package --remove=xorg-x11-server-utils

package --remove=xorg-x11-server-Xwayland
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-xwindows_remove_packages:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-xwindows_remove_packages_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_xwindows_runlevel_target" selected="false" severity="medium">
              <xccdf-1.2:title>Disable Graphical Environment Startup By Setting Default Target</xccdf-1.2:title>
              <xccdf-1.2:description>Systems that do not require a graphical user interface should only boot by
default into <html:code>multi-user.target</html:code> mode. This prevents accidental booting of the system
into a <html:code>graphical.target</html:code> mode. Setting the system's default target to
<html:code>multi-user.target</html:code> will prevent automatic startup of the graphical environment.
To do so, run:
<html:pre>$ systemctl set-default multi-user.target</html:pre>
You should see the following output:
<html:pre>Removed symlink /etc/systemd/system/default.target.
Created symlink from /etc/systemd/system/default.target to /usr/lib/systemd/system/multi-user.target.</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-7(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-040321</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-251718r1017371_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Services that are not required for system and application processes
must not be active to decrease the attack surface of the system.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#system_with_kernel"/>
              <xccdf-1.2:fix complexity="low" disruption="low" id="xwindows_runlevel_target" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

systemctl set-default multi-user.target

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="xwindows_runlevel_target" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-040321
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
  - xwindows_runlevel_target

- name: Switch to multi-user runlevel
  ansible.builtin.file:
    src: /usr/lib/systemd/system/multi-user.target
    dest: /etc/systemd/system/default.target
    state: link
    force: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-040321
  - NIST-800-53-CM-6(a)
  - NIST-800-53-CM-7(a)
  - NIST-800-53-CM-7(b)
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
  - xwindows_runlevel_target
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-xwindows_runlevel_target:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-xwindows_runlevel_target_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
      </xccdf-1.2:Group>
      <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_auditing">
        <xccdf-1.2:title>System Accounting with auditd</xccdf-1.2:title>
        <xccdf-1.2:description>The audit service provides substantial capabilities
for recording system activities. By default, the service audits about
SELinux AVC denials and certain types of security-relevant events
such as system logins, account modifications, and authentication
events performed by programs such as sudo.
Under its default configuration, <html:code>auditd</html:code> has modest disk space
requirements, and should not noticeably impact system performance.
<html:br/><html:br/>
NOTE: The Linux Audit daemon <html:code>auditd</html:code> can be configured to use
the <html:code>augenrules</html:code> program to read audit rules files (<html:code>*.rules</html:code>)
located in <html:code>/etc/audit/rules.d</html:code> location and compile them to create
the resulting form of the <html:code>/etc/audit/audit.rules</html:code> configuration file
during the daemon startup (default configuration). Alternatively, the <html:code>auditd</html:code>
daemon can use the <html:code>auditctl</html:code> utility to read audit rules from the
<html:code>/etc/audit/audit.rules</html:code> configuration file during daemon startup,
and load them into the kernel. The expected behavior is configured via the
appropriate <html:code>ExecStartPost</html:code> directive setting in the
<html:code>/usr/lib/systemd/system/auditd.service</html:code> configuration file.
To instruct the <html:code>auditd</html:code> daemon to use the <html:code>augenrules</html:code> program
to read audit rules (default configuration), use the following setting:
<html:br/> <html:pre>ExecStartPost=-/sbin/augenrules --load</html:pre>
in the <html:code>/usr/lib/systemd/system/auditd.service</html:code> configuration file.
In order to instruct the <html:code>auditd</html:code> daemon to use the <html:code>auditctl</html:code>
utility to read audit rules, use the following setting:
<html:br/> <html:pre>ExecStartPost=-/sbin/auditctl -R /etc/audit/audit.rules</html:pre>
in the <html:code>/usr/lib/systemd/system/auditd.service</html:code> configuration file.
Refer to <html:code>[Service]</html:code> section of the <html:code>/usr/lib/systemd/system/auditd.service</html:code>
configuration file for further details.
<html:br/><html:br/>
Government networks often have substantial auditing
requirements and <html:code>auditd</html:code> can be configured to meet these
requirements.
Examining some example audit records demonstrates how the Linux audit system
satisfies common requirements.
The following example from Red Hat Enterprise Linux 7 Documentation available at
<html:code><html:a href="https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html-single/selinux_users_and_administrators_guide/index#sect-Security-Enhanced_Linux-Fixing_Problems-Raw_Audit_Messages">https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html-single/selinux_users_and_administrators_guide/index#sect-Security-Enhanced_Linux-Fixing_Problems-Raw_Audit_Messages</html:a></html:code>
shows the substantial amount of information captured in a
two typical "raw" audit messages, followed by a breakdown of the most important
fields. In this example the message is SELinux-related and reports an AVC
denial (and the associated system call) that occurred when the Apache HTTP
Server attempted to access the <html:code>/var/www/html/file1</html:code> file (labeled with
the <html:code>samba_share_t</html:code> type):
<html:pre>type=AVC msg=audit(1226874073.147:96): avc:  denied  { getattr } for pid=2465 comm="httpd"
path="/var/www/html/file1" dev=dm-0 ino=284133 scontext=unconfined_u:system_r:httpd_t:s0
tcontext=unconfined_u:object_r:samba_share_t:s0 tclass=file

type=SYSCALL msg=audit(1226874073.147:96): arch=40000003 syscall=196 success=no exit=-13
a0=b98df198 a1=bfec85dc a2=54dff4 a3=2008171 items=0 ppid=2463 pid=2465 auid=502 uid=48
gid=48 euid=48 suid=48 fsuid=48 egid=48 sgid=48 fsgid=48 tty=(none) ses=6 comm="httpd"
exe="/usr/sbin/httpd" subj=unconfined_u:system_r:httpd_t:s0 key=(null)
</html:pre>
<html:ul><html:li><html:code>msg=audit(1226874073.147:96)</html:code><html:ul><html:li>The number in parentheses is the unformatted time stamp (Epoch time)
for the event, which can be converted to standard time by using the
<html:code>date</html:code> command.
</html:li></html:ul></html:li><html:li><html:code>{ getattr }</html:code><html:ul><html:li>The item in braces indicates the permission that was denied. <html:code>getattr</html:code>
indicates the source process was trying to read the target file's status information.
This occurs before reading files. This action is denied due to the file being
accessed having the wrong label. Commonly seen permissions include <html:code>getattr</html:code>,
<html:code>read</html:code>, and <html:code>write</html:code>.</html:li></html:ul></html:li><html:li><html:code>comm="httpd"</html:code><html:ul><html:li>The executable that launched the process. The full path of the executable is
found in the <html:code>exe=</html:code> section of the system call (<html:code>SYSCALL</html:code>) message,
which in this case, is <html:code>exe="/usr/sbin/httpd"</html:code>.
</html:li></html:ul></html:li><html:li><html:code>path="/var/www/html/file1"</html:code><html:ul><html:li>The path to the object (target) the process attempted to access.
</html:li></html:ul></html:li><html:li><html:code>scontext="unconfined_u:system_r:httpd_t:s0"</html:code><html:ul><html:li>The SELinux context of the process that attempted the denied action. In
this case, it is the SELinux context of the Apache HTTP Server, which is running
in the <html:code>httpd_t</html:code> domain.
</html:li></html:ul></html:li><html:li><html:code>tcontext="unconfined_u:object_r:samba_share_t:s0"</html:code><html:ul><html:li>The SELinux context of the object (target) the process attempted to access.
In this case, it is the SELinux context of <html:code>file1</html:code>. Note: the <html:code>samba_share_t</html:code>
type is not accessible to processes running in the <html:code>httpd_t</html:code> domain.</html:li></html:ul></html:li><html:li> From the system call (<html:code>SYSCALL</html:code>) message, two items are of interest:
<html:ul><html:li><html:code>success=no</html:code>: indicates whether the denial (AVC) was enforced or not.
<html:code>success=no</html:code> indicates the system call was not successful (SELinux denied
access). <html:code>success=yes</html:code> indicates the system call was successful - this can
be seen for permissive domains or unconfined domains, such as <html:code>initrc_t</html:code>
and <html:code>kernel_t</html:code>.
</html:li><html:li><html:code>exe="/usr/sbin/httpd"</html:code>: the full path to the executable that launched
the process, which in this case, is <html:code>exe="/usr/sbin/httpd"</html:code>.
</html:li></html:ul>
</html:li></html:ul></xccdf-1.2:description>
        <xccdf-1.2:platform idref="#system_with_kernel"/>
        <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_audit_backlog_limit" interactive="true" type="string">
          <xccdf-1.2:title>Audit backlog limit</xccdf-1.2:title>
          <xccdf-1.2:description>Value of the audit_backlog_limit argument in GRUB 2 configuration.
The audit_backlog_limit parameter determines how auditd records can
be held in the auditd backlog.</xccdf-1.2:description>
          <xccdf-1.2:value>8192</xccdf-1.2:value>
          <xccdf-1.2:value selector="8192">8192</xccdf-1.2:value>
        </xccdf-1.2:Value>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_audispd-plugins_installed" selected="false" severity="medium">
          <xccdf-1.2:title>Install audispd-plugins Package</xccdf-1.2:title>
          <xccdf-1.2:description>The <html:code>audispd-plugins</html:code> package can be installed with the following command:
<html:pre>
$ sudo yum install audispd-plugins</html:pre></xccdf-1.2:description>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000342-GPOS-00133</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
          <xccdf-1.2:rationale><html:code>audispd-plugins</html:code> provides plugins for the real-time interface to the
audit subsystem, <html:code>audispd</html:code>. These plugins can do things like relay events
to remote machines or analyze events for suspicious behavior.</xccdf-1.2:rationale>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audispd-plugins_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "audispd-plugins" ; then
    yum install -y "audispd-plugins"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audispd-plugins_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.3
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_audispd-plugins_installed

- name: Ensure audispd-plugins is installed
  ansible.builtin.package:
    name: audispd-plugins
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.3
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_audispd-plugins_installed
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audispd-plugins_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_audispd-plugins

class install_audispd-plugins {
  package { 'audispd-plugins':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audispd-plugins_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=audispd-plugins
</xccdf-1.2:fix>
          <xccdf-1.2:fix id="package_audispd-plugins_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "audispd-plugins"
version = "*"
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audispd-plugins_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install audispd-plugins
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audispd-plugins_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install audispd-plugins
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_audispd-plugins_installed:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_audispd-plugins_installed_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_audit-audispd-plugins_installed" selected="false" severity="medium">
          <xccdf-1.2:title>Ensure the default plugins for the audit dispatcher are Installed</xccdf-1.2:title>
          <xccdf-1.2:description>The audit-audispd-plugins package should be installed.</xccdf-1.2:description>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iv)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000342-GPOS-00133</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Off-loading is a common process in information systems with limited audit storage capacity.</xccdf-1.2:rationale>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit-audispd-plugins_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "audit-audispd-plugins" ; then
    yum install -y "audit-audispd-plugins"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit-audispd-plugins_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSS-Req-10.5.3
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.3
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_audit-audispd-plugins_installed

- name: Ensure audit-audispd-plugins is installed
  ansible.builtin.package:
    name: audit-audispd-plugins
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSS-Req-10.5.3
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.3
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_audit-audispd-plugins_installed
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit-audispd-plugins_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_audit-audispd-plugins

class install_audit-audispd-plugins {
  package { 'audit-audispd-plugins':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit-audispd-plugins_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=audit-audispd-plugins
</xccdf-1.2:fix>
          <xccdf-1.2:fix id="package_audit-audispd-plugins_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "audit-audispd-plugins"
version = "*"
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit-audispd-plugins_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install audit-audispd-plugins
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit-audispd-plugins_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install audit-audispd-plugins
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_audit-audispd-plugins_installed:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_audit-audispd-plugins_installed_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_audit-libs_installed" selected="false" severity="medium">
          <xccdf-1.2:title>Ensure the audit-libs package as a part of audit Subsystem is Installed</xccdf-1.2:title>
          <xccdf-1.2:description>The audit-libs package should be installed.</xccdf-1.2:description>
          <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R3.3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R6.5</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-7(a)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-7(1)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-7(2)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-14</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(2)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000038-GPOS-00016</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000039-GPOS-00017</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000040-GPOS-00018</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000041-GPOS-00019</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00021</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000051-GPOS-00024</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000054-GPOS-00025</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000122-GPOS-00063</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000254-GPOS-00095</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000255-GPOS-00096</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000337-GPOS-00129</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000348-GPOS-00136</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000349-GPOS-00137</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000350-GPOS-00138</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000351-GPOS-00139</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000352-GPOS-00140</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000353-GPOS-00141</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000354-GPOS-00142</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000358-GPOS-00145</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000365-GPOS-00152</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.1.1</xccdf-1.2:reference>
          <xccdf-1.2:rationale>The auditd service is an access monitoring and accounting daemon, watching system calls to audit any access, in comparison with potential local access control policy such as SELinux policy.</xccdf-1.2:rationale>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit-libs_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "audit-libs" ; then
    yum install -y "audit-libs"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit-libs_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-7(a)
  - NIST-800-53-AU-12(2)
  - NIST-800-53-AU-14
  - NIST-800-53-AU-2(a)
  - NIST-800-53-AU-7(1)
  - NIST-800-53-AU-7(2)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_audit-libs_installed

- name: Ensure audit-libs is installed
  ansible.builtin.package:
    name: audit-libs
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-7(a)
  - NIST-800-53-AU-12(2)
  - NIST-800-53-AU-14
  - NIST-800-53-AU-2(a)
  - NIST-800-53-AU-7(1)
  - NIST-800-53-AU-7(2)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_audit-libs_installed
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit-libs_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_audit-libs

class install_audit-libs {
  package { 'audit-libs':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit-libs_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=audit-libs
</xccdf-1.2:fix>
          <xccdf-1.2:fix id="package_audit-libs_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "audit-libs"
version = "*"
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit-libs_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install audit-libs
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit-libs_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install audit-libs
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_audit-libs_installed:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_audit-libs_installed_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_package_audit_installed" selected="false" severity="medium">
          <xccdf-1.2:title>Ensure the audit Subsystem is Installed</xccdf-1.2:title>
          <xccdf-1.2:description>The audit package should be installed.</xccdf-1.2:description>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iv)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R3.3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R6.5</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-7(a)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-7(1)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-7(2)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-14</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(2)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000038-GPOS-00016</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000039-GPOS-00017</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000040-GPOS-00018</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000041-GPOS-00019</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00021</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000051-GPOS-00024</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000054-GPOS-00025</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000122-GPOS-00063</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000254-GPOS-00095</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000255-GPOS-00096</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000337-GPOS-00129</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000348-GPOS-00136</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000349-GPOS-00137</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000350-GPOS-00138</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000351-GPOS-00139</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000352-GPOS-00140</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000353-GPOS-00141</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000354-GPOS-00142</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000358-GPOS-00145</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000365-GPOS-00152</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R33</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0846</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.1.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030180</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230411r1017217_rule</xccdf-1.2:reference>
          <xccdf-1.2:rationale>The auditd service is an access monitoring and accounting daemon, watching system calls to audit any access, in comparison with potential local access control policy such as SELinux policy.</xccdf-1.2:rationale>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

if ! rpm -q --quiet "audit" ; then
    yum install -y "audit"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030180
  - NIST-800-53-AC-7(a)
  - NIST-800-53-AU-12(2)
  - NIST-800-53-AU-14
  - NIST-800-53-AU-2(a)
  - NIST-800-53-AU-7(1)
  - NIST-800-53-AU-7(2)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.1
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_audit_installed

- name: Ensure audit is installed
  ansible.builtin.package:
    name: audit
    state: present
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030180
  - NIST-800-53-AC-7(a)
  - NIST-800-53-AU-12(2)
  - NIST-800-53-AU-14
  - NIST-800-53-AU-2(a)
  - NIST-800-53-AU-7(1)
  - NIST-800-53-AU-7(2)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.1
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - package_audit_installed
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include install_audit

class install_audit {
  package { 'audit':
    ensure =&gt; 'installed',
  }
}
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit_installed" reboot="false" strategy="enable" system="urn:redhat:anaconda:pre">
package --add=audit
</xccdf-1.2:fix>
          <xccdf-1.2:fix id="package_audit_installed" system="urn:redhat:osbuild:blueprint">
[[packages]]
name = "audit"
version = "*"
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:kickstart">
package install audit
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="package_audit_installed" reboot="false" strategy="enable" system="urn:xccdf:fix:script:bootc">
dnf install audit
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-package_audit_installed:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-package_audit_installed_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_service_auditd_enabled" selected="false" severity="medium">
          <xccdf-1.2:title>Enable auditd Service</xccdf-1.2:title>
          <xccdf-1.2:description>The <html:code>auditd</html:code> service is an essential userspace component of
the Linux Auditing System, as it is responsible for writing audit records to
disk.

The <html:code>auditd</html:code> service can be enabled with the following command:
<html:pre>$ sudo systemctl enable auditd.service</html:pre></xccdf-1.2:description>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.6</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iv)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R3.3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R6.5</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(g)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-10</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-14(1)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SI-4(23)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000038-GPOS-00016</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000039-GPOS-00017</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000040-GPOS-00018</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000041-GPOS-00019</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00021</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000051-GPOS-00024</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000054-GPOS-00025</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000122-GPOS-00063</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000254-GPOS-00095</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000255-GPOS-00096</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000337-GPOS-00129</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000348-GPOS-00136</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000349-GPOS-00137</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000350-GPOS-00138</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000351-GPOS-00139</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000352-GPOS-00140</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000353-GPOS-00141</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000354-GPOS-00142</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000358-GPOS-00145</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000365-GPOS-00152</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000095-CTR-000170</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000409-CTR-000990</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000508-CTR-001300</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000510-CTR-001310</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R33</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">1409</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.1.4</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030181</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244542r1017348_rule</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Without establishing what type of events occurred, it would be difficult
to establish, correlate, and investigate the events leading up to an outage or attack.
Ensuring the <html:code>auditd</html:code> service is active ensures audit records
generated by the kernel are appropriately recorded.
<html:br/><html:br/>
Additionally, a properly configured audit subsystem ensures that actions of
individual system users can be uniquely traced to those users so they
can be held accountable for their actions.</xccdf-1.2:rationale>
          <xccdf-1.2:platform idref="#package_audit"/>
          <xccdf-1.2:requires idref="xccdf_org.ssgproject.content_rule_package_audit_installed"/>
          <xccdf-1.2:fix complexity="low" disruption="low" id="service_auditd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q audit; }; then

SYSTEMCTL_EXEC='/usr/bin/systemctl'
"$SYSTEMCTL_EXEC" unmask 'auditd.service'
if [[ $("$SYSTEMCTL_EXEC" is-system-running) != "offline" ]]; then
  "$SYSTEMCTL_EXEC" start 'auditd.service'
fi
"$SYSTEMCTL_EXEC" enable 'auditd.service'

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="service_auditd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030181
  - NIST-800-171-3.3.1
  - NIST-800-171-3.3.2
  - NIST-800-171-3.3.6
  - NIST-800-53-AC-2(g)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-10
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-14(1)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-AU-3
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-4(23)
  - PCI-DSS-Req-10.1
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_auditd_enabled

- name: Enable auditd Service - Enable service auditd
  block:

  - name: Gather the package facts
    ansible.builtin.package_facts:
      manager: auto

  - name: Enable auditd Service - Enable Service auditd
    ansible.builtin.systemd:
      name: auditd
      enabled: true
      state: started
      masked: false
    when:
    - '"audit" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030181
  - NIST-800-171-3.3.1
  - NIST-800-171-3.3.2
  - NIST-800-171-3.3.6
  - NIST-800-53-AC-2(g)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-10
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-14(1)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-AU-3
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SI-4(23)
  - PCI-DSS-Req-10.1
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - enable_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - service_auditd_enabled
  - special_service_block
  when:
  - '"kernel" in ansible_facts.packages'
  - '"audit" in ansible_facts.packages'
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="service_auditd_enabled" reboot="false" strategy="enable" system="urn:xccdf:fix:script:puppet">include enable_auditd

class enable_auditd {
  service {'auditd':
    enable =&gt; true,
    ensure =&gt; 'running',
  }
}
</xccdf-1.2:fix>
          <xccdf-1.2:fix id="service_auditd_enabled" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    systemd:
      units:
      - name: auditd.service
        enabled: true
</xccdf-1.2:fix>
          <xccdf-1.2:fix id="service_auditd_enabled" system="urn:redhat:osbuild:blueprint">
[customizations.services]
enabled = ["auditd"]
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="low" disruption="low" id="service_auditd_enabled" reboot="false" strategy="disable" system="urn:xccdf:fix:script:kickstart">
service enable auditd
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-service_auditd_enabled:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_audit_argument" selected="false" severity="low">
          <xccdf-1.2:title>Enable Auditing for Processes Which Start Prior to the Audit Daemon</xccdf-1.2:title>
          <xccdf-1.2:description>To ensure all processes can be audited, even those which start
prior to the audit daemon, add the argument <html:code>audit=1</html:code> to the default
GRUB 2 command line for the Linux operating system.
Configure the default Grub2 kernel command line to contain audit=1 as follows:
<html:pre># grub2-editenv - set "$(grub2-editenv - list | grep kernelopts) audit=1"</html:pre></xccdf-1.2:description>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iv)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-17(1)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-14(1)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-10</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IR-5(1)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000473-GPOS-00218</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000254-GPOS-00095</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.7.2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.1.2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030601</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230468r1017260_rule</xccdf-1.2:reference>
          <xccdf-1.2:rationale>Each process on the system carries an "auditable" flag which indicates whether
its activities can be audited. Although <html:code>auditd</html:code> takes care of enabling
this for all processes which launch after it does, adding the kernel argument
ensures it is set for every process during boot.</xccdf-1.2:rationale>
          <xccdf-1.2:platform idref="#grub2"/>
          <xccdf-1.2:fix id="grub2_audit_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q grub2-common; }; then

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    KARGS_DIR="/usr/lib/bootc/kargs.d/"
    if grep -q -E "audit" "$KARGS_DIR/*.toml" ; then
        sed -i -E "s/^(\s*kargs\s*=\s*\[.*)\"audit=[^\"]*\"(.*]\s*)/\1\"audit=1\"\2/" "$KARGS_DIR/*.toml"
    else
        echo "kargs = [\"audit=1\"]" &gt;&gt; "$KARGS_DIR/10-audit.toml"
    fi
else

    grubby --update-kernel=ALL --args=audit=1 --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_audit_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030601
  - NIST-800-171-3.3.1
  - NIST-800-53-AC-17(1)
  - NIST-800-53-AU-10
  - NIST-800-53-AU-14(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IR-5(1)
  - PCI-DSS-Req-10.3
  - PCI-DSSv4-10.7
  - PCI-DSSv4-10.7.2
  - grub2_audit_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Check if audit argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030601
  - NIST-800-171-3.3.1
  - NIST-800-53-AC-17(1)
  - NIST-800-53-AU-10
  - NIST-800-53-AU-14(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IR-5(1)
  - PCI-DSS-Req-10.3
  - PCI-DSSv4-10.7
  - PCI-DSSv4-10.7.2
  - grub2_audit_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Check if audit argument is already present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030601
  - NIST-800-171-3.3.1
  - NIST-800-53-AC-17(1)
  - NIST-800-53-AU-10
  - NIST-800-53-AU-14(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IR-5(1)
  - PCI-DSS-Req-10.3
  - PCI-DSSv4-10.7
  - PCI-DSSv4-10.7.2
  - grub2_audit_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --args="audit=1"
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  - (grubby_info.stdout is not search('audit=1')) or ((etc_default_grub['content']
    | b64decode) is not search('audit=1'))
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030601
  - NIST-800-171-3.3.1
  - NIST-800-53-AC-17(1)
  - NIST-800-53-AU-10
  - NIST-800-53-AU-14(1)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IR-5(1)
  - PCI-DSS-Req-10.3
  - PCI-DSSv4-10.7
  - PCI-DSSv4-10.7.2
  - grub2_audit_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
          <xccdf-1.2:fix id="grub2_audit_argument" system="urn:redhat:osbuild:blueprint">[customizations.kernel]
append = "audit=1"
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_audit_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kickstart">
bootloader audit=1
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_audit_argument:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_audit_argument_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_grub2_audit_backlog_limit_argument" selected="false" severity="low">
          <xccdf-1.2:title>Extend Audit Backlog Limit for the Audit Daemon</xccdf-1.2:title>
          <xccdf-1.2:description>To improve the kernel capacity to queue all log events, even those which occurred
prior to the audit daemon, add the argument <html:code>audit_backlog_limit=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audit_backlog_limit" use="legacy"/></html:code> to the default
GRUB 2 command line for the Linux operating system.
Configure the default Grub2 kernel command line to contain audit_backlog_limit=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audit_backlog_limit" use="legacy"/> as follows:
<html:pre># grub2-editenv - set "$(grub2-editenv - list | grep kernelopts) audit_backlog_limit=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audit_backlog_limit" use="legacy"/>"</html:pre></xccdf-1.2:description>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iv)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_STG.1</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_STG.3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000254-GPOS-00095</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000341-GPOS-00132</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.7.2</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.7</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.1.3</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030602</xccdf-1.2:reference>
          <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230469r958752_rule</xccdf-1.2:reference>
          <xccdf-1.2:rationale>audit_backlog_limit sets the queue length for audit events awaiting transfer
to the audit daemon. Until the audit daemon is up and running, all log messages
are stored in this queue.  If the queue is overrun during boot process, the action
defined by audit failure flag is taken.</xccdf-1.2:rationale>
          <xccdf-1.2:platform idref="#grub2"/>
          <xccdf-1.2:fix id="grub2_audit_backlog_limit_argument" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel &amp;&amp; { rpm --quiet -q grub2-common; }; then

var_audit_backlog_limit='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audit_backlog_limit" use="legacy"/>'



if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
    KARGS_DIR="/usr/lib/bootc/kargs.d/"
    if grep -q -E "audit_backlog_limit" "$KARGS_DIR/*.toml" ; then
        sed -i -E "s/^(\s*kargs\s*=\s*\[.*)\"audit_backlog_limit=[^\"]*\"(.*]\s*)/\1\"audit_backlog_limit=$var_audit_backlog_limit\"\2/" "$KARGS_DIR/*.toml"
    else
        echo "kargs = [\"audit_backlog_limit=$var_audit_backlog_limit\"]" &gt;&gt; "$KARGS_DIR/10-audit_backlog_limit.toml"
    fi
else

    grubby --update-kernel=ALL --args=audit_backlog_limit=$var_audit_backlog_limit --env=/boot/grub2/grubenv

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_audit_backlog_limit_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030602
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-10.7
  - PCI-DSSv4-10.7.2
  - grub2_audit_backlog_limit_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy
- name: XCCDF Value var_audit_backlog_limit # promote to variable
  set_fact:
    var_audit_backlog_limit: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audit_backlog_limit" use="legacy"/>
  tags:
    - always

- name: Check if audit_backlog_limit argument is already present in /etc/default/grub
  ansible.builtin.slurp:
    src: /etc/default/grub
  register: etc_default_grub
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030602
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-10.7
  - PCI-DSSv4-10.7.2
  - grub2_audit_backlog_limit_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Check if audit_backlog_limit argument is already present
  ansible.builtin.command: /sbin/grubby --info=ALL
  register: grubby_info
  check_mode: false
  changed_when: false
  failed_when: false
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030602
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-10.7
  - PCI-DSSv4-10.7.2
  - grub2_audit_backlog_limit_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy

- name: Update grub defaults and the bootloader menu
  ansible.builtin.command: /sbin/grubby --update-kernel=ALL --args="audit_backlog_limit={{
    var_audit_backlog_limit }}"
  when:
  - '"kernel" in ansible_facts.packages'
  - '"grub2-common" in ansible_facts.packages'
  - (grubby_info.stdout is not search('audit_backlog_limit=' ~ var_audit_backlog_limit))
    or ((etc_default_grub['content'] | b64decode) is not search('audit_backlog_limit='
    ~ var_audit_backlog_limit))
  tags:
  - DISA-STIG-RHEL-08-030602
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-10.7
  - PCI-DSSv4-10.7.2
  - grub2_audit_backlog_limit_argument
  - low_disruption
  - low_severity
  - medium_complexity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
          <xccdf-1.2:fix id="grub2_audit_backlog_limit_argument" system="urn:redhat:osbuild:blueprint">[customizations.kernel]
append = "audit_backlog_limit=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audit_backlog_limit" use="legacy"/>"
</xccdf-1.2:fix>
          <xccdf-1.2:fix complexity="medium" disruption="low" id="grub2_audit_backlog_limit_argument" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kickstart">
bootloader audit_backlog_limit=<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audit_backlog_limit" use="legacy"/>
</xccdf-1.2:fix>
          <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
            <xccdf-1.2:check-export export-name="oval:ssg-var_audit_backlog_limit:var:1" value-id="xccdf_org.ssgproject.content_value_var_audit_backlog_limit"/>
            <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-grub2_audit_backlog_limit_argument:def:1"/>
          </xccdf-1.2:check>
          <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
            <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-grub2_audit_backlog_limit_argument_ocil:questionnaire:1"/>
          </xccdf-1.2:check>
        </xccdf-1.2:Rule>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_auditd_configure_rules">
          <xccdf-1.2:title>Configure auditd Rules for Comprehensive Auditing</xccdf-1.2:title>
          <xccdf-1.2:description>The <html:code>auditd</html:code> program can perform comprehensive
monitoring of system activity. This section describes recommended
configuration settings for comprehensive auditing, but a full
description of the auditing system's capabilities is beyond the
scope of this guide. The mailing list <html:i>linux-audit@redhat.com</html:i> exists
to facilitate community discussion of the auditing system.
<html:br/><html:br/>
The audit subsystem supports extensive collection of events, including:
<html:br/>
<html:ul><html:li>Tracing of arbitrary system calls (identified by name or number)
on entry or exit.</html:li><html:li>Filtering by PID, UID, call success, system call argument (with
some limitations), etc.</html:li><html:li>Monitoring of specific files for modifications to the file's
contents or metadata.</html:li></html:ul>
<html:br/>
Auditing rules at startup are controlled by the file <html:code>/etc/audit/audit.rules</html:code>.
Add rules to it to meet the auditing requirements for your organization.
Each line in <html:code>/etc/audit/audit.rules</html:code> represents a series of arguments
that can be passed to <html:code>auditctl</html:code> and can be individually tested
during runtime. See documentation in <html:code>/usr/share/doc/audit-<html:i>VERSION</html:i></html:code> and
in the related man pages for more details.
<html:br/><html:br/>
If copying any example audit rulesets from <html:code>/usr/share/doc/audit-VERSION</html:code>,
be sure to comment out the
lines containing <html:code>arch=</html:code> which are not appropriate for your system's
architecture. Then review and understand the following rules,
ensuring rules are activated as needed for the appropriate
architecture.
<html:br/><html:br/>
After reviewing all the rules, reading the following sections, and
editing as needed, the new rules can be activated as follows:
<html:pre>$ sudo service auditd restart</html:pre></xccdf-1.2:description>
          <xccdf-1.2:platform idref="#package_audit"/>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_audit_failure_mode" interactive="true" type="string">
            <xccdf-1.2:title>Audit failure mode</xccdf-1.2:title>
            <xccdf-1.2:description>This variable is the setting for the -f option in Audit configuration which sets the failure mode of audit.
This option lets you determine how you want the kernel to handle critical errors.
Possible values are: 0=silent, 1=printk, 2=panic.
If the value is set to "2", the system is configured to panic (shut down) in the event of an auditing failure.
If the value is set to "1", the system is configured to only send information to the kernel log regarding the failure.</xccdf-1.2:description>
            <xccdf-1.2:value>2</xccdf-1.2:value>
            <xccdf-1.2:value selector="silent">0</xccdf-1.2:value>
            <xccdf-1.2:value selector="printk">1</xccdf-1.2:value>
            <xccdf-1.2:value selector="panic">2</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_continue_loading" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure the Audit Configuration is Loaded Regardless of Errors</xccdf-1.2:title>
            <xccdf-1.2:description>Set <html:code>-c</html:code> flag so that auditctl will continue loading rules in spite of an error. The exit
code will not be success if any rule fails to load.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.20</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The default behaviour of <html:code>auditctl</html:code> is to stop loading any further rules if it encounters an
error in the rules (for example a file watcher referencing a non-existent file). This can
lead to auditd running without valid rules being present. It is best to have all valid rules
loaded and active rather than a subset</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_continue_loading" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Traverse all of:
#
# /etc/audit/audit.rules,			(for auditctl case)
# /etc/audit/rules.d/*.rules			(for augenrules case)
#
# files to check if '-c' setting is present in that '*.rules' file already.
# If found, delete such occurrence
find /etc/audit /etc/audit/rules.d -maxdepth 1 -type f -name '*.rules' -exec sed -i '/-c[[:space:]]\+.*/d' {} ';'

# Insert '-c' requirement at the beginning of both:
# * /etc/audit/audit.rules file 		(for auditctl case)
# * /etc/audit/rules.d/01-initialize.rules		(for augenrules case)

for AUDIT_FILE in "/etc/audit/audit.rules" "/etc/audit/rules.d/01-initialize.rules"
do
	{
		echo '# Set the audit.rules configuration to continue loading rules in spite of an error'
		echo '-c'
		echo ''
		cat "$AUDIT_FILE"
	} &gt; "${AUDIT_FILE}.tmp"
	mv "${AUDIT_FILE}.tmp" "$AUDIT_FILE"
	chmod o-rwx $AUDIT_FILE
	chmod g-rwx $AUDIT_FILE
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_continue_loading" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - audit_rules_continue_loading
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Ensure the Audit Configuration is Loaded Regardless of Errors - Collect all
    files from /etc/audit/rules.d with .rules extension
  ansible.builtin.find:
    paths: /etc/audit/rules.d/
    patterns: '*.rules'
  register: find_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - audit_rules_continue_loading
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Ensure the Audit Configuration is Loaded Regardless of Errors - Check if target
    files exist and get their content
  ansible.builtin.stat:
    path: '{{ item }}'
  register: audit_files_stat
  loop:
  - /etc/audit/audit.rules
  - /etc/audit/rules.d/01-initialize.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - audit_rules_continue_loading
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Ensure the Audit Configuration is Loaded Regardless of Errors - Read content
    of existing audit files
  ansible.builtin.slurp:
    src: '{{ item.item }}'
  register: audit_files_content
  loop: '{{ audit_files_stat.results }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - item.stat.exists
  tags:
  - audit_rules_continue_loading
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Ensure the Audit Configuration is Loaded Regardless of Errors - Check if -c
    is already correctly set in target files
  ansible.builtin.set_fact:
    continue_loading_correctly_set: |-
      {{
        audit_files_content.results
        | selectattr('content', 'defined')
        | map(attribute='content')
        | map('b64decode')
        | select('search', '^-c$', multiline=True)
        | list
        | length == 2
      }}
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - audit_rules_continue_loading
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Ensure the Audit Configuration is Loaded Regardless of Errors - Remove any
    existing -c option from all Audit config files
  ansible.builtin.lineinfile:
    path: '{{ item }}'
    regexp: ^\s*-c\s*.*$
    state: absent
  loop: '{{ find_rules_d.files | map(attribute=''path'') | list + [''/etc/audit/audit.rules'']
    }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not continue_loading_correctly_set
  tags:
  - audit_rules_continue_loading
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Ensure the Audit Configuration is Loaded Regardless of Errors - Ensure target
    directories exist
  ansible.builtin.file:
    path: '{{ item | dirname }}'
    state: directory
    mode: '0750'
  loop:
  - /etc/audit/audit.rules
  - /etc/audit/rules.d/01-initialize.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not continue_loading_correctly_set
  tags:
  - audit_rules_continue_loading
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Ensure the Audit Configuration is Loaded Regardless of Errors - Add Audit
    -c option to make rules continue loading
  ansible.builtin.lineinfile:
    path: '{{ item }}'
    create: true
    line: -c
    regexp: ^\s*-c\s*.*$
    insertbefore: BOF
    mode: g-rwx,o-rwx
  loop:
  - /etc/audit/audit.rules
  - /etc/audit/rules.d/01-initialize.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not continue_loading_correctly_set
  tags:
  - audit_rules_continue_loading
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_continue_loading:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_continue_loading_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_etc_cron_d" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure auditd Collects Changes to Cron Jobs - /etc/cron.d/</xccdf-1.2:title>
            <xccdf-1.2:description>At a minimum, the audit system should collect administrator actions
for all users and root.




If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /etc/cron.d/ -p wa -k cronjobs</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /etc/cron.d/ -p wa -k cronjobs</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030655</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-274877r1155381_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The actions taken by system administrators should be audited to keep a record
of what was executed on the system, as well as, for accountability purposes.
Editing the sudoers file may be sign of an attacker trying to
establish persistent methods to a system, auditing the editing of the sudoers
files mitigates this risk.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_etc_cron_d" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/cron.d/" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/cron.d/ $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/cron.d/$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/cron.d/ -p wa -k cronjobs" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/cronjobs.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/cron.d/" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/cronjobs.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/cronjobs.rules"
    # If the cronjobs.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/cron.d/" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/cron.d/ $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/cron.d/$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/cron.d/ -p wa -k cronjobs" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_etc_cron_d" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030655
  - audit_rules_etc_cron_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Changes to Cron Jobs - /etc/cron.d/ - Check if watch
    rule for /etc/cron.d/ already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/cron.d/\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030655
  - audit_rules_etc_cron_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Changes to Cron Jobs - /etc/cron.d/ - Search /etc/audit/rules.d
    for other rules with specified key cronjobs
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)cronjobs$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030655
  - audit_rules_etc_cron_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Changes to Cron Jobs - /etc/cron.d/ - Use /etc/audit/rules.d/cronjobs.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/cronjobs.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - DISA-STIG-RHEL-08-030655
  - audit_rules_etc_cron_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Changes to Cron Jobs - /etc/cron.d/ - Use matched file
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - DISA-STIG-RHEL-08-030655
  - audit_rules_etc_cron_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Changes to Cron Jobs - /etc/cron.d/ - Add watch rule
    for /etc/cron.d/ in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/cron.d/ -p wa -k cronjobs
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030655
  - audit_rules_etc_cron_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Changes to Cron Jobs - /etc/cron.d/ - Check if watch
    rule for /etc/cron.d/ already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/cron.d/\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030655
  - audit_rules_etc_cron_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Changes to Cron Jobs - /etc/cron.d/ - Add watch rule
    for /etc/cron.d/ in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/cron.d/ -p wa -k cronjobs
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030655
  - audit_rules_etc_cron_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_etc_cron_d:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_etc_cron_d_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_etc_group_open" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information via open syscall - /etc/group</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system should collect write events to /etc/group file for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S open -F a1&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre></xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Creation of groups through direct edition of /etc/group could be an indicator of malicious activity on a system.
Auditing these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#not_aarch64_arch"/>
            <xccdf-1.2:fix id="audit_rules_etc_group_open" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F a1&amp;03 -F path=/etc/group"
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="open"
	KEY="user-modify"
	SYSCALL_GROUPING=""
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_etc_group_open" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_group_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit open tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_group_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping: []

  - name: Check existence of open in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a1&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a1&amp;03 -F path=/etc/group -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a1&amp;03 -F path=/etc/group
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping: []

  - name: Check existence of open in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a1&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a1&amp;03 -F path=/etc/group -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a1&amp;03 -F path=/etc/group
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_group_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping: []

  - name: Check existence of open in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a1&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a1&amp;03 -F path=/etc/group -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a1&amp;03 -F path=/etc/group
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping: []

  - name: Check existence of open in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a1&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a1&amp;03 -F path=/etc/group -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a1&amp;03 -F path=/etc/group
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_group_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_etc_group_open:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_etc_group_open_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_etc_group_open_by_handle_at" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/group</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system should collect write events to /etc/group file for all group and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre></xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Creation of groups through direct edition of /etc/group could be an indicator of malicious activity on a system.
Auditing these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_etc_group_open_by_handle_at" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F a2&amp;03 -F path=/etc/group"
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="open_by_handle_at"
	KEY="user-modify"
	SYSCALL_GROUPING=""
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_etc_group_open_by_handle_at" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_group_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit open_by_handle_at tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_group_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open_by_handle_at for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping: []

  - name: Check existence of open_by_handle_at in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/group
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping: []

  - name: Check existence of open_by_handle_at in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/group
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_group_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open_by_handle_at for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping: []

  - name: Check existence of open_by_handle_at in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/group
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping: []

  - name: Check existence of open_by_handle_at in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/group
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_group_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_etc_group_open_by_handle_at:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_etc_group_open_by_handle_at_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_etc_group_openat" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information via openat syscall - /etc/group</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system should collect write events to /etc/group file for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S openat -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S openat -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S openat -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre></xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Creation of groups through direct edition of /etc/group could be an indicator of malicious activity on a system.
Auditing these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_etc_group_openat" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F a2&amp;03 -F path=/etc/group"
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="openat"
	KEY="user-modify"
	SYSCALL_GROUPING=""
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_etc_group_openat" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_group_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit openat tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_group_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for openat for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping: []

  - name: Check existence of openat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/group
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping: []

  - name: Check existence of openat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/group
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_group_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for openat for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping: []

  - name: Check existence of openat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/group
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping: []

  - name: Check existence of openat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/group -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/group
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_group_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_etc_group_openat:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_etc_group_openat_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_etc_gshadow_open" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information via open syscall - /etc/gshadow</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system should collect write events to /etc/gshadow file for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S open -F a1&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre></xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Creation of users through direct edition of /etc/gshadow could be an indicator of malicious activity on a system.
Auditing these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#not_aarch64_arch"/>
            <xccdf-1.2:fix id="audit_rules_etc_gshadow_open" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F a1&amp;03 -F path=/etc/gshadow"
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="open"
	KEY="user-modify"
	SYSCALL_GROUPING=""
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_etc_gshadow_open" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_gshadow_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit open tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_gshadow_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping: []

  - name: Check existence of open in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a1&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a1&amp;03 -F path=/etc/gshadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a1&amp;03 -F path=/etc/gshadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping: []

  - name: Check existence of open in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a1&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a1&amp;03 -F path=/etc/gshadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a1&amp;03 -F path=/etc/gshadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_gshadow_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping: []

  - name: Check existence of open in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a1&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a1&amp;03 -F path=/etc/gshadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a1&amp;03 -F path=/etc/gshadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping: []

  - name: Check existence of open in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a1&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a1&amp;03 -F path=/etc/gshadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a1&amp;03 -F path=/etc/gshadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_gshadow_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_etc_gshadow_open:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_etc_gshadow_open_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_etc_gshadow_open_by_handle_at" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/gshadow</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system should collect write events to /etc/gshadow file for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre></xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Creation of users through direct edition of /etc/gshadow could be an indicator of malicious activity on a system.
Auditing these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_etc_gshadow_open_by_handle_at" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F a2&amp;03 -F path=/etc/gshadow"
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="open_by_handle_at"
	KEY="user-modify"
	SYSCALL_GROUPING=""
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_etc_gshadow_open_by_handle_at" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_gshadow_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit open_by_handle_at tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_gshadow_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open_by_handle_at for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping: []

  - name: Check existence of open_by_handle_at in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/gshadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping: []

  - name: Check existence of open_by_handle_at in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/gshadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_gshadow_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open_by_handle_at for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping: []

  - name: Check existence of open_by_handle_at in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/gshadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping: []

  - name: Check existence of open_by_handle_at in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/gshadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_gshadow_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_etc_gshadow_open_by_handle_at:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_etc_gshadow_open_by_handle_at_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_etc_gshadow_openat" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information via openat syscall - /etc/gshadow</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system should collect write events to /etc/gshadow file for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S openat -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S openat -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S openat -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre></xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Creation of users through direct edition of /etc/gshadow could be an indicator of malicious activity on a system.
Auditing these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_etc_gshadow_openat" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F a2&amp;03 -F path=/etc/gshadow"
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="openat"
	KEY="user-modify"
	SYSCALL_GROUPING=""
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_etc_gshadow_openat" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_gshadow_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit openat tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_gshadow_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for openat for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping: []

  - name: Check existence of openat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/gshadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping: []

  - name: Check existence of openat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/gshadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_gshadow_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for openat for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping: []

  - name: Check existence of openat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/gshadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping: []

  - name: Check existence of openat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/gshadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/gshadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_gshadow_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_etc_gshadow_openat:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_etc_gshadow_openat_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_etc_passwd_open" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information via open syscall - /etc/passwd</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system should collect write events to /etc/passwd file for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S open -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre></xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Creation of users through direct edition of /etc/passwd could be an indicator of malicious activity on a system.
Auditing these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#not_aarch64_arch"/>
            <xccdf-1.2:fix id="audit_rules_etc_passwd_open" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F a1&amp;03 -F path=/etc/passwd"
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="open"
	KEY="user-modify"
	SYSCALL_GROUPING=""
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_etc_passwd_open" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_passwd_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit open tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_passwd_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping: []

  - name: Check existence of open in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a1&amp;03 -F path=/etc/passwd
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping: []

  - name: Check existence of open in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a1&amp;03 -F path=/etc/passwd
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_passwd_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping: []

  - name: Check existence of open in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a1&amp;03 -F path=/etc/passwd
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping: []

  - name: Check existence of open in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a1&amp;03 -F path=/etc/passwd
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_passwd_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_etc_passwd_open:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_etc_passwd_open_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_etc_passwd_open_by_handle_at" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/passwd</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system should collect write events to /etc/passwd file for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre></xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Creation of users through direct edition of /etc/passwd could be an indicator of malicious activity on a system.
Auditing these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_etc_passwd_open_by_handle_at" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F a2&amp;03 -F path=/etc/passwd"
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="open_by_handle_at"
	KEY="user-modify"
	SYSCALL_GROUPING=""
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_etc_passwd_open_by_handle_at" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_passwd_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit open_by_handle_at tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_passwd_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open_by_handle_at for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping: []

  - name: Check existence of open_by_handle_at in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/passwd
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping: []

  - name: Check existence of open_by_handle_at in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/passwd
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_passwd_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open_by_handle_at for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping: []

  - name: Check existence of open_by_handle_at in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/passwd
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping: []

  - name: Check existence of open_by_handle_at in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/passwd
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_passwd_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_etc_passwd_open_by_handle_at:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_etc_passwd_open_by_handle_at_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_etc_passwd_openat" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information via openat syscall - /etc/passwd</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system should collect write events to /etc/passwd file for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S openat -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S openat -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S openat -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=modify</html:pre></xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Creation of users through direct edition of /etc/passwd could be an indicator of malicious activity on a system.
Auditing these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_etc_passwd_openat" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F a2&amp;03 -F path=/etc/passwd"
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="openat"
	KEY="user-modify"
	SYSCALL_GROUPING=""
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_etc_passwd_openat" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_passwd_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit openat tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_passwd_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for openat for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping: []

  - name: Check existence of openat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/passwd
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping: []

  - name: Check existence of openat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/passwd
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_passwd_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for openat for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping: []

  - name: Check existence of openat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/passwd
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping: []

  - name: Check existence of openat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/passwd
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_passwd_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_etc_passwd_openat:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_etc_passwd_openat_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_etc_shadow_open" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information via open syscall - /etc/shadow</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system should collect write events to /etc/shadow file for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S open -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S open,openat,open_by_handle_at -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre></xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Creation of users through direct edition of /etc/shadow could be an indicator of malicious activity on a system.
Auditing these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
            <xccdf-1.2:platform idref="#not_aarch64_arch"/>
            <xccdf-1.2:fix id="audit_rules_etc_shadow_open" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F a1&amp;03 -F path=/etc/shadow"
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="open"
	KEY="user-modify"
	SYSCALL_GROUPING=""
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_etc_shadow_open" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_shadow_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit open tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_shadow_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping: []

  - name: Check existence of open in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a1&amp;03 -F path=/etc/shadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping: []

  - name: Check existence of open in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a1&amp;03 -F path=/etc/shadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_shadow_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping: []

  - name: Check existence of open in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a1&amp;03 -F path=/etc/shadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping: []

  - name: Check existence of open in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a1&amp;03 -F path=/etc/shadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_shadow_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_etc_shadow_open:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_etc_shadow_open_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_etc_shadow_open_by_handle_at" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/shadow</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system should collect write events to /etc/shadow file for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S open,openat,open_by_handle_at -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre></xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Creation of users through direct edition of /etc/shadow could be an indicator of malicious activity on a system.
Auditing these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_etc_shadow_open_by_handle_at" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F a2&amp;03 -F path=/etc/shadow"
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="open_by_handle_at"
	KEY="user-modify"
	SYSCALL_GROUPING=""
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_etc_shadow_open_by_handle_at" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_shadow_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit open_by_handle_at tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_shadow_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open_by_handle_at for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping: []

  - name: Check existence of open_by_handle_at in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/shadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping: []

  - name: Check existence of open_by_handle_at in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/shadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_shadow_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open_by_handle_at for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping: []

  - name: Check existence of open_by_handle_at in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/shadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping: []

  - name: Check existence of open_by_handle_at in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/shadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_shadow_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_etc_shadow_open_by_handle_at:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_etc_shadow_open_by_handle_at_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_etc_shadow_openat" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information via openat syscall - /etc/shadow</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system should collect write events to /etc/shadow file for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S openat -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S openat -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S openat -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S open,openat,open_by_handle_at -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify</html:pre></xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Creation of users through direct edition of /etc/shadow could be an indicator of malicious activity on a system.
Auditing these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_etc_shadow_openat" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F a2&amp;03 -F path=/etc/shadow"
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="openat"
	KEY="user-modify"
	SYSCALL_GROUPING=""
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_etc_shadow_openat" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_shadow_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit openat tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_shadow_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for openat for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping: []

  - name: Check existence of openat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/shadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping: []

  - name: Check existence of openat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/shadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_shadow_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for openat for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping: []

  - name: Check existence of openat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modify.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modify.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/shadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping: []

  - name: Check existence of openat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a2&amp;03 -F path=/etc/shadow
        -F auid&gt;=1000 -F auid!=unset -F key=modify
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_etc_shadow_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_etc_shadow_openat:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_etc_shadow_openat_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_immutable" selected="false" severity="medium">
            <xccdf-1.2:title>Make the auditd Configuration Immutable</xccdf-1.2:title>
            <xccdf-1.2:description>If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following line to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code> in order to make the auditd configuration
immutable:
<html:pre>-e 2</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file in order to make the auditd configuration
immutable:
<html:pre>-e 2</html:pre>
With this setting, a reboot will be required to change any audit rules.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(a)(2)(iv)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000057-GPOS-00027</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000058-GPOS-00028</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000059-GPOS-00029</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000119-CTR-000245</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000120-CTR-000250</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.21</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030121</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230402r1017208_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Making the audit configuration immutable prevents accidental as
well as malicious modification of the audit rules, although it may be
problematic if legitimate changes are needed during system
operation.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_immutable" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Traverse all of:
#
# /etc/audit/audit.rules,			(for auditctl case)
# /etc/audit/rules.d/*.rules			(for augenrules case)
#
# files to check if '-e .*' setting is present in that '*.rules' file already.
# If found, delete such occurrence since auditctl(8) manual page instructs the
# '-e 2' rule should be placed as the last rule in the configuration
find /etc/audit /etc/audit/rules.d -maxdepth 1 -type f -name '*.rules' -exec sed -i '/-e[[:space:]]\+.*/d' {} ';'

# Append '-e 2' requirement at the end of both:
# * /etc/audit/audit.rules file 		(for auditctl case)
# * /etc/audit/rules.d/immutable.rules		(for augenrules case)

for AUDIT_FILE in "/etc/audit/audit.rules" "/etc/audit/rules.d/immutable.rules"
do
	echo '' &gt;&gt; $AUDIT_FILE
	echo '# Set the audit.rules configuration immutable per security requirements' &gt;&gt; $AUDIT_FILE
	echo '# Reboot is required to change audit rules once this setting is applied' &gt;&gt; $AUDIT_FILE
	echo '-e 2' &gt;&gt; $AUDIT_FILE
	chmod o-rwx $AUDIT_FILE
	chmod g-rwx $AUDIT_FILE
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_immutable" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030121
  - NIST-800-171-3.3.1
  - NIST-800-171-3.4.3
  - NIST-800-53-AC-6(9)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - audit_rules_immutable
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Make the auditd Configuration Immutable - Collect all files from /etc/audit/rules.d
    with .rules extension
  ansible.builtin.find:
    paths: /etc/audit/rules.d/
    patterns: '*.rules'
  register: find_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030121
  - NIST-800-171-3.3.1
  - NIST-800-171-3.4.3
  - NIST-800-53-AC-6(9)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - audit_rules_immutable
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Make the auditd Configuration Immutable - Check if target files exist and
    get their content
  ansible.builtin.stat:
    path: '{{ item }}'
  register: audit_files_stat
  loop:
  - /etc/audit/audit.rules
  - /etc/audit/rules.d/immutable.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030121
  - NIST-800-171-3.3.1
  - NIST-800-171-3.4.3
  - NIST-800-53-AC-6(9)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - audit_rules_immutable
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Make the auditd Configuration Immutable - Read content of existing audit files
  ansible.builtin.slurp:
    src: '{{ item.item }}'
  register: audit_files_content
  loop: '{{ audit_files_stat.results }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - item.stat.exists
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030121
  - NIST-800-171-3.3.1
  - NIST-800-171-3.4.3
  - NIST-800-53-AC-6(9)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - audit_rules_immutable
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Make the auditd Configuration Immutable - Check if -e 2 is already correctly
    set in target files
  ansible.builtin.set_fact:
    immutable_correctly_set: |-
      {{
        audit_files_content.results
        | selectattr('content', 'defined')
        | map(attribute='content')
        | map('b64decode')
        | select('search', '^-e 2$', multiline=True)
        | list
        | length == 2
      }}
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030121
  - NIST-800-171-3.3.1
  - NIST-800-171-3.4.3
  - NIST-800-53-AC-6(9)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - audit_rules_immutable
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Make the auditd Configuration Immutable - Remove any existing -e option from
    all Audit config files
  ansible.builtin.lineinfile:
    path: '{{ item }}'
    regexp: ^\s*-e\s+.*$
    state: absent
  loop: '{{ find_rules_d.files | map(attribute=''path'') | list + [''/etc/audit/audit.rules'']
    }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not immutable_correctly_set
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030121
  - NIST-800-171-3.3.1
  - NIST-800-171-3.4.3
  - NIST-800-53-AC-6(9)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - audit_rules_immutable
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Make the auditd Configuration Immutable - Ensure target directories exist
  ansible.builtin.file:
    path: '{{ item | dirname }}'
    state: directory
    mode: '0750'
  loop:
  - /etc/audit/audit.rules
  - /etc/audit/rules.d/immutable.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not immutable_correctly_set
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030121
  - NIST-800-171-3.3.1
  - NIST-800-171-3.4.3
  - NIST-800-53-AC-6(9)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - audit_rules_immutable
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Make the auditd Configuration Immutable - Add Audit -e 2 option to make rules
    immutable
  ansible.builtin.lineinfile:
    path: '{{ item }}'
    create: true
    line: -e 2
    regexp: ^\s*-e\s+.*$
    mode: g-rwx,o-rwx
  loop:
  - /etc/audit/audit.rules
  - /etc/audit/rules.d/immutable.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not immutable_correctly_set
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030121
  - NIST-800-171-3.3.1
  - NIST-800-171-3.4.3
  - NIST-800-53-AC-6(9)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.2
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.2
  - audit_rules_immutable
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="audit_rules_immutable" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,-e%202%0A
        mode: 0600
        path: /etc/audit/rules.d/90-immutable.rules
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_immutable:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_immutable_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_immutable_login_uids" selected="false" severity="medium">
            <xccdf-1.2:title>Configure immutable Audit login UIDs</xccdf-1.2:title>
            <xccdf-1.2:description>Configure kernel to prevent modification of login UIDs once they are set.
Changing login UIDs while this configuration is enforced requires special capabilities which
are not available to unprivileged users.
If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following line to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code> in order to make login UIDs
immutable:
<html:pre>--loginuid-immutable</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file in order to make login UIDs
immutable:
<html:pre>--loginuid-immutable</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000057-GPOS-00027</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000058-GPOS-00028</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000059-GPOS-00029</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030122</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230403r1017209_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If modification of login UIDs is not prevented, they can be changed by unprivileged users and
make auditing complicated or impossible.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_immutable_login_uids" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# in case auditctl is used
if grep -q '^\s*ExecStartPost=-/sbin/auditctl' /usr/lib/systemd/system/auditd.service; then
  if ! grep -q '^\s*--loginuid-immutable\s*$' /etc/audit/audit.rules; then
    echo "--loginuid-immutable" &gt;&gt; /etc/audit/audit.rules
  fi
else
  immutable_found=0
  while IFS= read -r -d '' f; do
    if grep -q '^\s*--loginuid-immutable\s*$' "$f"; then
      immutable_found=1
    fi
  done &lt;    &lt;(find /etc/audit/rules.d -maxdepth 1 -name '*.rules' -print0)
  if [ $immutable_found -eq 0 ]; then
    echo "--loginuid-immutable" &gt;&gt; /etc/audit/rules.d/immutable.rules
  fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_immutable_login_uids" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030122
  - audit_rules_immutable_login_uids
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: 'Configure immutable Audit login UIDs: Determine if rules are loaded by auditctl'
  ansible.builtin.find:
    paths: /usr/lib/systemd/system
    patterns: auditd.service
    contains: ^\s*ExecStartPost=-/sbin/auditctl
  register: auditctl_used
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030122
  - audit_rules_immutable_login_uids
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: 'Configure immutable Audit login UIDs: Configure immutable login UIDs in /etc/audit/audit.rules'
  ansible.builtin.lineinfile:
    path: /etc/audit/audit.rules
    line: --loginuid-immutable
    regexp: ^\s*--loginuid-immutable\s*$
    mode: '0600'
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - auditctl_used is defined and auditctl_used.matched &gt;= 1
  tags:
  - DISA-STIG-RHEL-08-030122
  - audit_rules_immutable_login_uids
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: 'Configure immutable Audit login UIDs: In case Augen-rules is used'
  block:

  - name: 'Configure immutable Audit login UIDs: Detect if immutable login UIDs are
      already defined in /etc/audit/rules.d/*.rules'
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      patterns: '*.rules'
      contains: ^\s*--loginuid-immutable\s*$
    register: immutable_found_in_rules_d

  - name: 'Configure immutable Audit login UIDs: set immutable login UIDS in /etc/audit/rules.d/immutable.rules'
    ansible.builtin.lineinfile:
      path: /etc/audit/rules.d/immutable.rules
      line: --loginuid-immutable
      regexp: ^\s*--loginuid-immutable\s*$
      mode: '0600'
      create: true
    when: immutable_found_in_rules_d is defined and immutable_found_in_rules_d.matched
      == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - auditctl_used is defined and auditctl_used.matched == 0
  tags:
  - DISA-STIG-RHEL-08-030122
  - audit_rules_immutable_login_uids
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_immutable_login_uids:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_immutable_login_uids_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_mac_modification" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify the System's Mandatory Access Controls</xccdf-1.2:title>
            <xccdf-1.2:description>If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following line to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /etc/selinux/ -p wa -k MAC-policy</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:

<html:pre>-w /etc/selinux/ -p wa -k MAC-policy</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.14</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The system's mandatory access policy (SELinux or Apparmor) should not be
arbitrarily changed by anything other than administrator action. All changes to
MAC policy should be audited.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_mac_modification" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/selinux/" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/selinux/ $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/selinux/$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/selinux/ -p wa -k MAC-policy" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/MAC-policy.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/selinux/" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/MAC-policy.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/MAC-policy.rules"
    # If the MAC-policy.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/selinux/" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/selinux/ $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/selinux/$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/selinux/ -p wa -k MAC-policy" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_mac_modification" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.8
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_mac_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Events that Modify the System's Mandatory Access Controls - Check if
    watch rule for /etc/selinux/ already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.8
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_mac_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Events that Modify the System's Mandatory Access Controls - Search
    /etc/audit/rules.d for other rules with specified key MAC-policy
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)MAC-policy$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.8
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_mac_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Events that Modify the System's Mandatory Access Controls - Use /etc/audit/rules.d/MAC-policy.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/MAC-policy.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.8
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_mac_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Events that Modify the System's Mandatory Access Controls - Use matched
    file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.8
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_mac_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Events that Modify the System's Mandatory Access Controls - Add watch
    rule for /etc/selinux/ in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/selinux/ -p wa -k MAC-policy
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.8
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_mac_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Events that Modify the System's Mandatory Access Controls - Check if
    watch rule for /etc/selinux/ already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/selinux/\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.8
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_mac_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Events that Modify the System's Mandatory Access Controls - Add watch
    rule for /etc/selinux/ in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/selinux/ -p wa -k MAC-policy
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.8
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_mac_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_mac_modification" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---

apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ -w%20/etc/selinux/%20-p%20wa%20-k%20MAC-policy%0A }}
        mode: 0600
        path: /etc/audit/rules.d/75-etcselinux-wa-MAC-policy.rules
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_mac_modification:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_mac_modification_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_mac_modification_usr_share" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify the System's Mandatory Access Controls in usr/share</xccdf-1.2:title>
            <xccdf-1.2:description>



If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /usr/share/selinux/ -p wa -k MAC-policy</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /usr/share/selinux/ -p wa -k MAC-policy</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.14</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The system's mandatory access policy (SELinux) should not be
arbitrarily changed by anything other than administrator action. All changes to
MAC policy should be audited.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_mac_modification_usr_share" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/usr/share/selinux/" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/usr/share/selinux/ $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/usr/share/selinux/$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /usr/share/selinux/ -p wa -k MAC-policy" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/MAC-policy.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/usr/share/selinux/" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/MAC-policy.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/MAC-policy.rules"
    # If the MAC-policy.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/usr/share/selinux/" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/usr/share/selinux/ $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/usr/share/selinux/$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /usr/share/selinux/ -p wa -k MAC-policy" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_mac_modification_usr_share" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.8
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - audit_rules_mac_modification_usr_share
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Mandatory Access Controls in usr/share
    - Check if watch rule for /usr/share/selinux/ already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/usr/share/selinux/\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.8
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - audit_rules_mac_modification_usr_share
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Mandatory Access Controls in usr/share
    - Search /etc/audit/rules.d for other rules with specified key MAC-policy
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)MAC-policy$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - NIST-800-171-3.1.8
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - audit_rules_mac_modification_usr_share
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Mandatory Access Controls in usr/share
    - Use /etc/audit/rules.d/MAC-policy.rules as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/MAC-policy.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - NIST-800-171-3.1.8
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - audit_rules_mac_modification_usr_share
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Mandatory Access Controls in usr/share
    - Use matched file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - NIST-800-171-3.1.8
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - audit_rules_mac_modification_usr_share
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Mandatory Access Controls in usr/share
    - Add watch rule for /usr/share/selinux/ in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /usr/share/selinux/ -p wa -k MAC-policy
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - NIST-800-171-3.1.8
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - audit_rules_mac_modification_usr_share
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Mandatory Access Controls in usr/share
    - Check if watch rule for /usr/share/selinux/ already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/usr/share/selinux/\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.8
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - audit_rules_mac_modification_usr_share
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Mandatory Access Controls in usr/share
    - Add watch rule for /usr/share/selinux/ in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /usr/share/selinux/ -p wa -k MAC-policy
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - NIST-800-171-3.1.8
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - audit_rules_mac_modification_usr_share
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_mac_modification_usr_share:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_mac_modification_usr_share_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_media_export" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure auditd Collects Information on Exporting to Media (successful)</xccdf-1.2:title>
            <xccdf-1.2:description>At a minimum, the audit system should collect media exportation
events for all users and root. If the <html:code>auditd</html:code> daemon is configured to
use the <html:code>augenrules</html:code> program to read audit rules during daemon startup
(the default), add the following line to a file with suffix <html:code>.rules</html:code> in
the directory <html:code>/etc/audit/rules.d</html:code>, setting ARCH to either b32 for
32-bit system, or having two lines for both b32 and b64 in case your
system is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S mount -F auid&gt;=1000 -F auid!=unset -F key=export</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file, setting ARCH to either b32 for
32-bit system, or having two lines for both b32 and b64 in case your
system is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S mount -F auid&gt;=1000 -F auid!=unset -F key=export</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030302</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230425r1017226_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The unauthorized exportation of data to external media could result in an information leak
where classified information, Privacy Act information, and intellectual property could be lost. An audit
trail should be created each time a filesystem is mounted to help identify and guard against information
loss.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_media_export" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="mount"
	KEY="export"
	SYSCALL_GROUPING=""

	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_media_export" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030302
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_media_export
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit mount tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030302
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_media_export
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for mount for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - mount
      syscall_grouping: []

  - name: Check existence of mount in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/export.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/export.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=export
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - mount
      syscall_grouping: []

  - name: Check existence of mount in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=export
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030302
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_media_export
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for mount for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - mount
      syscall_grouping: []

  - name: Check existence of mount in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/export.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/export.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=export
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - mount
      syscall_grouping: []

  - name: Check existence of mount in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=export
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030302
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_media_export
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_media_export:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_networkconfig_modification" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify the System's Network Environment</xccdf-1.2:title>
            <xccdf-1.2:description>If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>, setting ARCH to either b32 for
32-bit system, or having two lines for both b32 and b64 in case your system
is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S sethostname,setdomainname -F key=audit_rules_networkconfig_modification
-w /etc/issue -p wa -k audit_rules_networkconfig_modification
-w /etc/issue.net -p wa -k audit_rules_networkconfig_modification
-w /etc/hosts -p wa -k audit_rules_networkconfig_modification

-w /etc/sysconfig/network -p wa -k audit_rules_networkconfig_modification</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file, setting ARCH to either b32 for
32-bit system, or having two lines for both b32 and b64 in case your system
is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S sethostname,setdomainname -F key=audit_rules_networkconfig_modification
-w /etc/issue -p wa -k audit_rules_networkconfig_modification
-w /etc/issue.net -p wa -k audit_rules_networkconfig_modification
-w /etc/hosts -p wa -k audit_rules_networkconfig_modification
-w /etc/sysconfig/network -p wa -k audit_rules_networkconfig_modification</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.5</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The network environment should not be modified by anything other
than administrator action. Any change to network parameters should be
audited.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_networkconfig_modification" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS=""
	SYSCALL="sethostname setdomainname"
	KEY="audit_rules_networkconfig_modification"
	SYSCALL_GROUPING="sethostname setdomainname"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

# Then perform the remediations for the watch rules
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/issue" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/issue $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/issue$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/issue -p wa -k audit_rules_networkconfig_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_rules_networkconfig_modification.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/issue" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_rules_networkconfig_modification.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_rules_networkconfig_modification.rules"
    # If the audit_rules_networkconfig_modification.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/issue" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/issue $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/issue$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/issue -p wa -k audit_rules_networkconfig_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/issue.net" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/issue.net $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/issue.net$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/issue.net -p wa -k audit_rules_networkconfig_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_rules_networkconfig_modification.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/issue.net" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_rules_networkconfig_modification.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_rules_networkconfig_modification.rules"
    # If the audit_rules_networkconfig_modification.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/issue.net" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/issue.net $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/issue.net$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/issue.net -p wa -k audit_rules_networkconfig_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/hosts" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/hosts $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/hosts$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/hosts -p wa -k audit_rules_networkconfig_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_rules_networkconfig_modification.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/hosts" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_rules_networkconfig_modification.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_rules_networkconfig_modification.rules"
    # If the audit_rules_networkconfig_modification.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/hosts" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/hosts $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/hosts$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/hosts -p wa -k audit_rules_networkconfig_modification" &gt;&gt; "$audit_rules_file"

    fi
done

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/sysconfig/network" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/sysconfig/network $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/sysconfig/network$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/sysconfig/network -p wa -k audit_rules_networkconfig_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_rules_networkconfig_modification.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/sysconfig/network" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_rules_networkconfig_modification.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_rules_networkconfig_modification.rules"
    # If the audit_rules_networkconfig_modification.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/sysconfig/network" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/sysconfig/network $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/sysconfig/network$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/sysconfig/network -p wa -k audit_rules_networkconfig_modification" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_networkconfig_modification" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set architecture for audit tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Remediate audit rules for network configuration for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - sethostname
      - setdomainname
      syscall_grouping:
      - sethostname
      - setdomainname

  - name: Check existence of sethostname, setdomainname in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/audit_rules_networkconfig_modification.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/audit_rules_networkconfig_modification.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F key=audit_rules_networkconfig_modification
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - sethostname
      - setdomainname
      syscall_grouping:
      - sethostname
      - setdomainname

  - name: Check existence of sethostname, setdomainname in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F key=audit_rules_networkconfig_modification
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Remediate audit rules for network configuration for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - sethostname
      - setdomainname
      syscall_grouping:
      - sethostname
      - setdomainname

  - name: Check existence of sethostname, setdomainname in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/audit_rules_networkconfig_modification.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/audit_rules_networkconfig_modification.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F key=audit_rules_networkconfig_modification
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - sethostname
      - setdomainname
      syscall_grouping:
      - sethostname
      - setdomainname

  - name: Check existence of sethostname, setdomainname in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F key=audit_rules_networkconfig_modification
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Check if watch
    rule for /etc/issue already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Search /etc/audit/rules.d
    for other rules with specified key audit_rules_networkconfig_modification
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)audit_rules_networkconfig_modification$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Use /etc/audit/rules.d/audit_rules_networkconfig_modification.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/audit_rules_networkconfig_modification.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Use matched file
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Add watch rule
    for /etc/issue in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/issue -p wa -k audit_rules_networkconfig_modification
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Check if watch
    rule for /etc/issue already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/issue\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Add watch rule
    for /etc/issue in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/issue -p wa -k audit_rules_networkconfig_modification
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Check if watch
    rule for /etc/issue.net already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/issue.net\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Search /etc/audit/rules.d
    for other rules with specified key audit_rules_networkconfig_modification
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)audit_rules_networkconfig_modification$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Use /etc/audit/rules.d/audit_rules_networkconfig_modification.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/audit_rules_networkconfig_modification.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Use matched file
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Add watch rule
    for /etc/issue.net in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/issue.net -p wa -k audit_rules_networkconfig_modification
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Check if watch
    rule for /etc/issue.net already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/issue.net\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Add watch rule
    for /etc/issue.net in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/issue.net -p wa -k audit_rules_networkconfig_modification
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Check if watch
    rule for /etc/hosts already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/hosts\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Search /etc/audit/rules.d
    for other rules with specified key audit_rules_networkconfig_modification
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)audit_rules_networkconfig_modification$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Use /etc/audit/rules.d/audit_rules_networkconfig_modification.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/audit_rules_networkconfig_modification.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Use matched file
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Add watch rule
    for /etc/hosts in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/hosts -p wa -k audit_rules_networkconfig_modification
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Check if watch
    rule for /etc/hosts already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/hosts\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Add watch rule
    for /etc/hosts in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/hosts -p wa -k audit_rules_networkconfig_modification
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Check if watch
    rule for /etc/sysconfig/network already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/sysconfig/network\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Search /etc/audit/rules.d
    for other rules with specified key audit_rules_networkconfig_modification
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)audit_rules_networkconfig_modification$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Use /etc/audit/rules.d/audit_rules_networkconfig_modification.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/audit_rules_networkconfig_modification.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Use matched file
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Add watch rule
    for /etc/sysconfig/network in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/sysconfig/network -p wa -k audit_rules_networkconfig_modification
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Check if watch
    rule for /etc/sysconfig/network already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/sysconfig/network\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - Add watch rule
    for /etc/sysconfig/network in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/sysconfig/network -p wa -k audit_rules_networkconfig_modification
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_networkconfig_modification
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_networkconfig_modification:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_networkconfig_modification_network_scripts" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify the System's Network Environment - /etc/sysconfig/network-scripts</xccdf-1.2:title>
            <xccdf-1.2:description>



If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /etc/sysconfig/network-scripts -p wa -k system-locale</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /etc/sysconfig/network-scripts -p wa -k system-locale</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.5</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The network environment should not be modified by anything other
than administrator action. Any change to network parameters should be
audited.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_networkconfig_modification_network_scripts" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/sysconfig/network-scripts" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/sysconfig/network-scripts $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/sysconfig/network-scripts$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/sysconfig/network-scripts -p wa -k system-locale" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/system-locale.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/sysconfig/network-scripts" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/system-locale.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/system-locale.rules"
    # If the system-locale.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/sysconfig/network-scripts" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/sysconfig/network-scripts $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/sysconfig/network-scripts$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/sysconfig/network-scripts -p wa -k system-locale" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_networkconfig_modification_network_scripts" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - audit_rules_networkconfig_modification_network_scripts
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - /etc/sysconfig/network-scripts
    - Check if watch rule for /etc/sysconfig/network-scripts already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/sysconfig/network-scripts\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - audit_rules_networkconfig_modification_network_scripts
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - /etc/sysconfig/network-scripts
    - Search /etc/audit/rules.d for other rules with specified key system-locale
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)system-locale$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - audit_rules_networkconfig_modification_network_scripts
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - /etc/sysconfig/network-scripts
    - Use /etc/audit/rules.d/system-locale.rules as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/system-locale.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - audit_rules_networkconfig_modification_network_scripts
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - /etc/sysconfig/network-scripts
    - Use matched file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - audit_rules_networkconfig_modification_network_scripts
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - /etc/sysconfig/network-scripts
    - Add watch rule for /etc/sysconfig/network-scripts in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/sysconfig/network-scripts -p wa -k system-locale
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - audit_rules_networkconfig_modification_network_scripts
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - /etc/sysconfig/network-scripts
    - Check if watch rule for /etc/sysconfig/network-scripts already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/sysconfig/network-scripts\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - audit_rules_networkconfig_modification_network_scripts
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify the System's Network Environment - /etc/sysconfig/network-scripts
    - Add watch rule for /etc/sysconfig/network-scripts in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/sysconfig/network-scripts -p wa -k system-locale
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - audit_rules_networkconfig_modification_network_scripts
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_networkconfig_modification_network_scripts:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_networkconfig_modification_network_scripts_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_session_events" selected="false" severity="medium">
            <xccdf-1.2:title>Record Attempts to Alter Process and Session Initiation Information</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system already collects process information for all
users and root. If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code> in order to watch for attempted manual
edits of files involved in storing such process information:
<html:pre>-w /var/run/utmp -p wa -k session
-w /var/log/btmp -p wa -k session
-w /var/log/wtmp -p wa -k session</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file in order to watch for attempted manual
edits of files involved in storing such process information:
<html:pre>-w /var/run/utmp -p wa -k session
-w /var/log/btmp -p wa -k session
-w /var/log/wtmp -p wa -k session</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000505-CTR-001285</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Manual editing of these files may indicate nefarious activity, such
as an attacker attempting to remove evidence of an intrusion.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_session_events" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/run/utmp" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/run/utmp $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/run/utmp$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/run/utmp -p wa -k session" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/session.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/var/run/utmp" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/session.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/session.rules"
    # If the session.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/run/utmp" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/run/utmp $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/run/utmp$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/run/utmp -p wa -k session" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/btmp" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/btmp $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/btmp$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/btmp -p wa -k session" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/session.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/var/log/btmp" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/session.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/session.rules"
    # If the session.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/btmp" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/btmp $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/btmp$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/btmp -p wa -k session" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/wtmp" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/wtmp $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/wtmp$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/wtmp -p wa -k session" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/session.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/var/log/wtmp" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/session.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/session.rules"
    # If the session.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/wtmp" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/wtmp $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/wtmp$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/wtmp -p wa -k session" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_session_events" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Check
    if watch rule for /var/run/utmp already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/var/run/utmp\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Search
    /etc/audit/rules.d for other rules with specified key session
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)session$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Use
    /etc/audit/rules.d/session.rules as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/session.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Use
    matched file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Add
    watch rule for /var/run/utmp in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /var/run/utmp -p wa -k session
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Check
    if watch rule for /var/run/utmp already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/var/run/utmp\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Add
    watch rule for /var/run/utmp in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /var/run/utmp -p wa -k session
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Check
    if watch rule for /var/log/btmp already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/var/log/btmp\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Search
    /etc/audit/rules.d for other rules with specified key session
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)session$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Use
    /etc/audit/rules.d/session.rules as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/session.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Use
    matched file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Add
    watch rule for /var/log/btmp in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /var/log/btmp -p wa -k session
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Check
    if watch rule for /var/log/btmp already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/var/log/btmp\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Add
    watch rule for /var/log/btmp in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /var/log/btmp -p wa -k session
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Check
    if watch rule for /var/log/wtmp already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/var/log/wtmp\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Search
    /etc/audit/rules.d for other rules with specified key session
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)session$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Use
    /etc/audit/rules.d/session.rules as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/session.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Use
    matched file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Add
    watch rule for /var/log/wtmp in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /var/log/wtmp -p wa -k session
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Check
    if watch rule for /var/log/wtmp already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/var/log/wtmp\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information - Add
    watch rule for /var/log/wtmp in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /var/log/wtmp -p wa -k session
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - audit_rules_session_events
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_session_events" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---


apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %0A-w%20/var/run/utmp%20-p%20wa%20-k%20session%0A-w%20/var/log/btmp%20-p%20wa%20-k%20session%0A-w%20/var/log/wtmp%20-p%20wa%20-k%20session%0A }}
        mode: 0600
        path: /etc/audit/rules.d/75-audit-session-events.rules
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_session_events:def:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_session_events_btmp" selected="false" severity="medium">
            <xccdf-1.2:title>Record Attempts to Alter Process and Session Initiation Information btmp</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system already collects process information for all
users and root.




If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /var/log/btmp -p wa -k session</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /var/log/btmp -p wa -k session</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12.1(iv)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000472-GPOS-00217</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0846</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.11</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Manual editing of these files may indicate nefarious activity, such
as an attacker attempting to remove evidence of an intrusion.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_session_events_btmp" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/btmp" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/btmp $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/btmp$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/btmp -p wa -k session" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/session.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/var/log/btmp" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/session.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/session.rules"
    # If the session.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/btmp" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/btmp $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/btmp$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/btmp -p wa -k session" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_session_events_btmp" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_btmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information btmp -
    Check if watch rule for /var/log/btmp already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/var/log/btmp\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_btmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information btmp -
    Search /etc/audit/rules.d for other rules with specified key session
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)session$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_btmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information btmp -
    Use /etc/audit/rules.d/session.rules as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/session.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_btmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information btmp -
    Use matched file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_btmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information btmp -
    Add watch rule for /var/log/btmp in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /var/log/btmp -p wa -k session
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_btmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information btmp -
    Check if watch rule for /var/log/btmp already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/var/log/btmp\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_btmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information btmp -
    Add watch rule for /var/log/btmp in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /var/log/btmp -p wa -k session
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_btmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_session_events_btmp:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_session_events_btmp_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_session_events_utmp" selected="false" severity="medium">
            <xccdf-1.2:title>Record Attempts to Alter Process and Session Initiation Information utmp</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system already collects process information for all
users and root.




If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /var/run/utmp -p wa -k session</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /var/run/utmp -p wa -k session</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12.1(iv)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000472-GPOS-00217</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0846</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.11</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Manual editing of these files may indicate nefarious activity, such
as an attacker attempting to remove evidence of an intrusion.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_session_events_utmp" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/run/utmp" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/run/utmp $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/run/utmp$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/run/utmp -p wa -k session" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/session.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/var/run/utmp" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/session.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/session.rules"
    # If the session.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/run/utmp" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/run/utmp $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/run/utmp$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/run/utmp -p wa -k session" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_session_events_utmp" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_utmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information utmp -
    Check if watch rule for /var/run/utmp already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/var/run/utmp\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_utmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information utmp -
    Search /etc/audit/rules.d for other rules with specified key session
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)session$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_utmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information utmp -
    Use /etc/audit/rules.d/session.rules as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/session.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_utmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information utmp -
    Use matched file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_utmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information utmp -
    Add watch rule for /var/run/utmp in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /var/run/utmp -p wa -k session
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_utmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information utmp -
    Check if watch rule for /var/run/utmp already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/var/run/utmp\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_utmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information utmp -
    Add watch rule for /var/run/utmp in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /var/run/utmp -p wa -k session
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_utmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_session_events_utmp:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_session_events_utmp_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_session_events_wtmp" selected="false" severity="medium">
            <xccdf-1.2:title>Record Attempts to Alter Process and Session Initiation Information wtmp</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system already collects process information for all
users and root.




If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /var/log/wtmp -p wa -k session</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /var/log/wtmp -p wa -k session</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12.1(iv)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000472-GPOS-00217</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0846</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.11</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Manual editing of these files may indicate nefarious activity, such
as an attacker attempting to remove evidence of an intrusion.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_session_events_wtmp" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/wtmp" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/wtmp $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/wtmp$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/wtmp -p wa -k session" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/session.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/var/log/wtmp" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/session.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/session.rules"
    # If the session.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/wtmp" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/wtmp $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/wtmp$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/wtmp -p wa -k session" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_session_events_wtmp" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_wtmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information wtmp -
    Check if watch rule for /var/log/wtmp already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/var/log/wtmp\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_wtmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information wtmp -
    Search /etc/audit/rules.d for other rules with specified key session
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)session$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_wtmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information wtmp -
    Use /etc/audit/rules.d/session.rules as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/session.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_wtmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information wtmp -
    Use matched file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_wtmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information wtmp -
    Add watch rule for /var/log/wtmp in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /var/log/wtmp -p wa -k session
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_wtmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information wtmp -
    Check if watch rule for /var/log/wtmp already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/var/log/wtmp\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_wtmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Process and Session Initiation Information wtmp -
    Add watch rule for /var/log/wtmp in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /var/log/wtmp -p wa -k session
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(iv)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_session_events_wtmp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_session_events_wtmp:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_session_events_wtmp_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_sudoers" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure auditd Collects System Administrator Actions - /etc/sudoers</xccdf-1.2:title>
            <xccdf-1.2:description>At a minimum, the audit system should collect administrator actions
for all users and root.




If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /etc/sudoers -p wa -k actions</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /etc/sudoers -p wa -k actions</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000004-GPOS-00004</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000304-GPOS-00121</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000470-GPOS-00214</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000239-GPOS-00089</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000240-GPOS-00090</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000241-GPOS-00091</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000303-GPOS-00120</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000476-GPOS-00221</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000503-CTR-001275</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030171</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230409r1017215_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The actions taken by system administrators should be audited to keep a record
of what was executed on the system, as well as, for accountability purposes.
Editing the sudoers file may be sign of an attacker trying to
establish persistent methods to a system, auditing the editing of the sudoers
files mitigates this risk.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_sudoers" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/sudoers" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/sudoers $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/sudoers$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/sudoers -p wa -k actions" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/actions.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/sudoers" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/actions.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/actions.rules"
    # If the actions.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/sudoers" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/sudoers $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/sudoers$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/sudoers -p wa -k actions" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_sudoers" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030171
  - audit_rules_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - /etc/sudoers - Check
    if watch rule for /etc/sudoers already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030171
  - audit_rules_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - /etc/sudoers - Search
    /etc/audit/rules.d for other rules with specified key actions
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)actions$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030171
  - audit_rules_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - /etc/sudoers - Use /etc/audit/rules.d/actions.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/actions.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - DISA-STIG-RHEL-08-030171
  - audit_rules_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - /etc/sudoers - Use matched
    file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - DISA-STIG-RHEL-08-030171
  - audit_rules_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - /etc/sudoers - Add watch
    rule for /etc/sudoers in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/sudoers -p wa -k actions
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030171
  - audit_rules_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - /etc/sudoers - Check
    if watch rule for /etc/sudoers already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030171
  - audit_rules_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - /etc/sudoers - Add watch
    rule for /etc/sudoers in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/sudoers -p wa -k actions
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030171
  - audit_rules_sudoers
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_sudoers:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_sudoers_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_sudoers_d" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure auditd Collects System Administrator Actions - /etc/sudoers.d/</xccdf-1.2:title>
            <xccdf-1.2:description>At a minimum, the audit system should collect administrator actions
for all users and root.




If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /etc/sudoers.d/ -p wa -k actions</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /etc/sudoers.d/ -p wa -k actions</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000004-GPOS-00004</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000304-GPOS-00121</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000470-GPOS-00214</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000239-GPOS-00089</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000240-GPOS-00090</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000241-GPOS-00091</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000303-GPOS-00120</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000476-GPOS-00221</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000503-CTR-001275</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030172</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230410r1017216_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The actions taken by system administrators should be audited to keep a record
of what was executed on the system, as well as, for accountability purposes.
Editing the sudoers file may be sign of an attacker trying to
establish persistent methods to a system, auditing the editing of the sudoers
files mitigates this risk.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_sudoers_d" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/sudoers.d/" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/sudoers.d/ $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/sudoers.d/$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/sudoers.d/ -p wa -k actions" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/actions.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/sudoers.d/" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/actions.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/actions.rules"
    # If the actions.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/sudoers.d/" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/sudoers.d/ $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/sudoers.d/$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/sudoers.d/ -p wa -k actions" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_sudoers_d" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030172
  - audit_rules_sudoers_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - /etc/sudoers.d/ - Check
    if watch rule for /etc/sudoers.d/ already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/sudoers.d/\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030172
  - audit_rules_sudoers_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - /etc/sudoers.d/ - Search
    /etc/audit/rules.d for other rules with specified key actions
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)actions$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030172
  - audit_rules_sudoers_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - /etc/sudoers.d/ - Use
    /etc/audit/rules.d/actions.rules as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/actions.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - DISA-STIG-RHEL-08-030172
  - audit_rules_sudoers_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - /etc/sudoers.d/ - Use
    matched file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - DISA-STIG-RHEL-08-030172
  - audit_rules_sudoers_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - /etc/sudoers.d/ - Add
    watch rule for /etc/sudoers.d/ in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/sudoers.d/ -p wa -k actions
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030172
  - audit_rules_sudoers_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - /etc/sudoers.d/ - Check
    if watch rule for /etc/sudoers.d/ already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/sudoers.d/\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030172
  - audit_rules_sudoers_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - /etc/sudoers.d/ - Add
    watch rule for /etc/sudoers.d/ in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/sudoers.d/ -p wa -k actions
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030172
  - audit_rules_sudoers_d
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_sudoers_d:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_sudoers_d_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_suid_auid_privilege_function" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events When Executables Are Run As Another User</xccdf-1.2:title>
            <xccdf-1.2:description>Verify the system generates an audit record when actions are run as another user.
sudo provides users with temporary elevated privileges to perform operations, either as the superuser or another user.

If audit is using the "auditctl" tool to load the rules, run the following command:

<html:pre>$ sudo grep execve /etc/audit/audit.rules</html:pre>

If audit is using the "augenrules" tool to load the rules, run the following command:

<html:pre>$ sudo grep -r execve /etc/audit/rules.d</html:pre>
<html:pre>-a always,exit -F arch=b32 -S execve -C euid!=uid -F auid!=unset -k user_emulation</html:pre>
<html:pre>-a always,exit -F arch=b64  S execve -C euid!=uid -F auid!=unset -k user_emulation</html:pre>

If both the "b32" and "b64" audit rules for "SUID" files are not defined, this is a finding.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.2</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Creating an audit log of users with temporary elevated privileges and the
operation(s) they performed is essential to reporting. Administrators will
want to correlate the events written to the audit trail with the records
written to sudo's logfile to verify if unauthorized commands have
been executed.
Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have
compromised information system accounts, is a serious and ongoing concern
and can have significant adverse impacts on organizations. Auditing the use
of privileged functions is one way to detect such misuse and identify the
risk from insider threats and the advanced persistent threat.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_suid_auid_privilege_function" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-C euid!=uid"
	AUID_FILTERS="-F auid!=unset"
	SYSCALL="execve"
	KEY="user_emulation"
	SYSCALL_GROUPING=""
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_suid_auid_privilege_function" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - audit_rules_suid_auid_privilege_function
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Service facts
  ansible.builtin.service_facts: null
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - audit_rules_suid_auid_privilege_function
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Check the rules script being used
  ansible.builtin.command: grep '^ExecStartPost' /usr/lib/systemd/system/auditd.service
  register: check_rules_scripts_result
  changed_when: false
  failed_when: false
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - audit_rules_suid_auid_privilege_function
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set suid_audit_rules fact
  ansible.builtin.set_fact:
    suid_audit_rules:
    - rule: -a always,exit -F arch=b32 -S execve -C euid!=uid -F auid!=unset -k user_emulation
      regex: ^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32[\s]+-C[\s]+euid!=uid[\s]+-F[\s]+auid!=unset[\s]+-S[\s]+execve[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$
    - rule: -a always,exit -F arch=b64 -S execve -C euid!=uid -F auid!=unset -k user_emulation
      regex: ^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b64[\s]+-C[\s]+euid!=uid[\s]+-F[\s]+auid!=unset[\s]+-S[\s]+execve[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - audit_rules_suid_auid_privilege_function
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Update /etc/audit/rules.d/user_emulation.rules to audit privileged functions
  ansible.builtin.lineinfile:
    path: /etc/audit/rules.d/user_emulation.rules
    line: '{{  item.rule  }}'
    regexp: '{{ item.regex }}'
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - '"auditd.service" in ansible_facts.services'
  - '"augenrules" in check_rules_scripts_result.stdout'
  register: augenrules_audit_rules_privilege_function_update_result
  with_items: '{{ suid_audit_rules }}'
  tags:
  - audit_rules_suid_auid_privilege_function
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Update Update /etc/audit/audit.rules to audit privileged functions
  ansible.builtin.lineinfile:
    path: /etc/audit/audit.rules
    line: '{{  item.rule  }}'
    regexp: '{{ item.regex }}'
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - '"auditd.service" in ansible_facts.services'
  - '"auditctl" in check_rules_scripts_result.stdout'
  register: auditctl_audit_rules_privilege_function_update_result
  with_items: '{{ suid_audit_rules }}'
  tags:
  - audit_rules_suid_auid_privilege_function
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Restart Auditd
  ansible.builtin.command: /usr/sbin/service auditd restart
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - (augenrules_audit_rules_privilege_function_update_result.changed or auditctl_audit_rules_privilege_function_update_result.changed)
  - ("auditd.service" in ansible_facts.services and ansible_facts.services["auditd.service"].state
    == "running")
  tags:
  - audit_rules_suid_auid_privilege_function
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_suid_auid_privilege_function:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_suid_auid_privilege_function_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_suid_privilege_function" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events When Privileged Executables Are Run</xccdf-1.2:title>
            <xccdf-1.2:description>Verify the system generates an audit record when privileged functions are executed.

If audit is using the "auditctl" tool to load the rules, run the following command:

<html:pre>$ sudo grep execve /etc/audit/audit.rules</html:pre>

If audit is using the "augenrules" tool to load the rules, run the following command:

<html:pre>$ sudo grep -r execve /etc/audit/rules.d</html:pre>


<html:pre>-a always,exit -F arch=b32 -S execve -C uid!=euid -F euid=0 -k setuid</html:pre>
<html:pre>-a always,exit -F arch=b64 -S execve -C uid!=euid -F euid=0 -k setuid</html:pre>
<html:pre>-a always,exit -F arch=b32 -S execve -C gid!=egid -F egid=0 -k setgid</html:pre>
<html:pre>-a always,exit -F arch=b64 -S execve -C gid!=egid -F egid=0 -k setgid</html:pre>


If both the "b32" and "b64" audit rules for "SUID" files are not defined, this is a finding.
If both the "b32" and "b64" audit rules for "SGID" files are not defined, this is a finding.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-5(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-7(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-7(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-8(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(3)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000326-GPOS-00126</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000327-GPOS-00127</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000343-CTR-000780</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000381-CTR-000905</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000755-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030000</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230386r958730_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have
compromised information system accounts, is a serious and ongoing concern
and can have significant adverse impacts on organizations. Auditing the use
of privileged functions is one way to detect such misuse and identify the
risk from insider threats and the advanced persistent threat.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_suid_privilege_function" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-C uid!=euid -F euid=0"
	AUID_FILTERS=""
	SYSCALL="execve"
    
	KEY="setuid"
	
	SYSCALL_GROUPING=""
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-C gid!=egid -F egid=0"
	AUID_FILTERS=""
	SYSCALL="execve"
    
	KEY="setgid"
	
	SYSCALL_GROUPING=""
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_suid_privilege_function" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030000
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(3)
  - NIST-800-53-AU-7(a)
  - NIST-800-53-AU-7(b)
  - NIST-800-53-AU-8(b)
  - NIST-800-53-CM-5(1)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.2
  - audit_rules_suid_privilege_function
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Service facts
  ansible.builtin.service_facts: null
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030000
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(3)
  - NIST-800-53-AU-7(a)
  - NIST-800-53-AU-7(b)
  - NIST-800-53-AU-8(b)
  - NIST-800-53-CM-5(1)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.2
  - audit_rules_suid_privilege_function
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set suid_audit_rules fact
  ansible.builtin.set_fact:
    suid_audit_rules:
    - rule: -a always,exit -F arch=b32 -S execve -C gid!=egid -F egid=0 -k setgid
      regex: ^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32[\s]+-S[\s]+execve[\s]+-C[\s]+gid!=egid[\s]+-F[\s]+egid=0[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$
    - rule: -a always,exit -F arch=b64 -S execve -C gid!=egid -F egid=0 -k setgid
      regex: ^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b64[\s]+-S[\s]+execve[\s]+-C[\s]+gid!=egid[\s]+-F[\s]+egid=0[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$
    - rule: -a always,exit -F arch=b32 -S execve -C uid!=euid -F euid=0 -k setuid
      regex: ^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32[\s]+-S[\s]+execve[\s]+-C[\s]+uid!=euid[\s]+-F[\s]+euid=0[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$
    - rule: -a always,exit -F arch=b64 -S execve -C uid!=euid -F euid=0 -k setuid
      regex: ^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b64[\s]+-S[\s]+execve[\s]+-C[\s]+uid!=euid[\s]+-F[\s]+euid=0[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030000
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(3)
  - NIST-800-53-AU-7(a)
  - NIST-800-53-AU-7(b)
  - NIST-800-53-AU-8(b)
  - NIST-800-53-CM-5(1)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.2
  - audit_rules_suid_privilege_function
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Update /etc/audit/rules.d/privileged.rules to audit privileged functions
  ansible.builtin.lineinfile:
    path: /etc/audit/rules.d/privileged.rules
    line: '{{  item.rule  }}'
    regexp: '{{ item.regex }}'
    mode: '0600'
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ('"auditd.service" in ansible_facts.services' or '"augenrules.service" in ansible_facts.services')
  register: augenrules_audit_rules_privilege_function_update_result
  with_items: '{{ suid_audit_rules }}'
  tags:
  - DISA-STIG-RHEL-08-030000
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(3)
  - NIST-800-53-AU-7(a)
  - NIST-800-53-AU-7(b)
  - NIST-800-53-AU-8(b)
  - NIST-800-53-CM-5(1)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.2
  - audit_rules_suid_privilege_function
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Update /etc/audit/audit.rules to audit privileged functions
  ansible.builtin.lineinfile:
    path: /etc/audit/audit.rules
    line: '{{  item.rule  }}'
    regexp: '{{ item.regex }}'
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ('"auditd.service" in ansible_facts.services' or '"augenrules.service" in ansible_facts.services')
  register: auditctl_audit_rules_privilege_function_update_result
  with_items: '{{ suid_audit_rules }}'
  tags:
  - DISA-STIG-RHEL-08-030000
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(3)
  - NIST-800-53-AU-7(a)
  - NIST-800-53-AU-7(b)
  - NIST-800-53-AU-8(b)
  - NIST-800-53-CM-5(1)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.2
  - audit_rules_suid_privilege_function
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Restart Auditd
  ansible.builtin.command: /usr/sbin/service auditd restart
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - (augenrules_audit_rules_privilege_function_update_result.changed or auditctl_audit_rules_privilege_function_update_result.changed)
  - ("auditd.service" in ansible_facts.services and ansible_facts.services["auditd.service"].state
    == "running")
  tags:
  - DISA-STIG-RHEL-08-030000
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(3)
  - NIST-800-53-AU-7(a)
  - NIST-800-53-AU-7(b)
  - NIST-800-53-AU-8(b)
  - NIST-800-53-CM-5(1)
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.2
  - audit_rules_suid_privilege_function
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_suid_privilege_function" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ -a%20always%2Cexit%20-F%20arch%3Db32%20-S%20execve%20-C%20uid%21%3Deuid%20-F%20euid%3D0%20-k%20execpriv%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20execve%20-C%20uid%21%3Deuid%20-F%20euid%3D0%20-k%20execpriv%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20execve%20-C%20gid%21%3Degid%20-F%20egid%3D0%20-k%20execpriv%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20execve%20-C%20gid%21%3Degid%20-F%20egid%3D0%20-k%20execpriv%0A }}
        mode: 0600
        path: /etc/audit/rules.d/75-audit-suid-privilege-function.rules
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_suid_privilege_function:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_suid_privilege_function_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_sysadmin_actions" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure auditd Collects System Administrator Actions</xccdf-1.2:title>
            <xccdf-1.2:description>



If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /etc/sudoers -p wa -k actions</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /etc/sudoers -p wa -k actions</html:pre>






If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /etc/sudoers.d/ -p wa -k actions</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /etc/sudoers.d/ -p wa -k actions</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(7)(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.5.b</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000004-GPOS-00004</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000304-GPOS-00121</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000470-GPOS-00214</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000239-GPOS-00089</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000240-GPOS-00090</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000241-GPOS-00091</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000303-GPOS-00120</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000304-GPOS-00121</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000476-GPOS-00221</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000026-CTR-000070</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000027-CTR-000075</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000028-CTR-000080</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000291-CTR-000675</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000292-CTR-000680</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000293-CTR-000685</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000294-CTR-000690</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000319-CTR-000745</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000320-CTR-000750</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000509-CTR-001305</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.1</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The actions taken by system administrators should be audited to keep a record
of what was executed on the system, as well as, for accountability purposes.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_sysadmin_actions" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'


# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/sudoers" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/sudoers $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/sudoers$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/sudoers -p wa -k actions" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/actions.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/sudoers" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/actions.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/actions.rules"
    # If the actions.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/sudoers" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/sudoers $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/sudoers$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/sudoers -p wa -k actions" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/sudoers.d/" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/sudoers.d/ $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/sudoers.d/$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/sudoers.d/ -p wa -k actions" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/actions.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/sudoers.d/" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/actions.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/actions.rules"
    # If the actions.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/sudoers.d/" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/sudoers.d/ $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/sudoers.d/$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/sudoers.d/ -p wa -k actions" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_sysadmin_actions" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(7)(b)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_sysadmin_actions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - Check if watch rule
    for /etc/sudoers already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(7)(b)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_sysadmin_actions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - Add watch rule for /etc/sudoers
    in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/sudoers -p wa -k actions
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(7)(b)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_sysadmin_actions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - Check if watch rule
    for /etc/sudoers already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/sudoers\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(7)(b)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_sysadmin_actions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - Search /etc/audit/rules.d
    for other rules with specified key actions
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)actions$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(7)(b)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_sysadmin_actions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - Use /etc/audit/rules.d/actions.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/actions.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(7)(b)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_sysadmin_actions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - Use matched file as
    the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(7)(b)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_sysadmin_actions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - Add watch rule for /etc/sudoers
    in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/sudoers -p wa -k actions
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(7)(b)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_sysadmin_actions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - Check if watch rule
    for /etc/sudoers.d/ already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/sudoers.d/\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(7)(b)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_sysadmin_actions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - Add watch rule for /etc/sudoers.d/
    in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/sudoers.d/ -p wa -k actions
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(7)(b)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_sysadmin_actions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - Check if watch rule
    for /etc/sudoers.d/ already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/sudoers.d/\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(7)(b)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_sysadmin_actions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - Search /etc/audit/rules.d
    for other rules with specified key actions
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)actions$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(7)(b)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_sysadmin_actions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - Use /etc/audit/rules.d/actions.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/actions.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(7)(b)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_sysadmin_actions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - Use matched file as
    the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(7)(b)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_sysadmin_actions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects System Administrator Actions - Add watch rule for /etc/sudoers.d/
    in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/sudoers.d/ -p wa -k actions
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(7)(b)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_sysadmin_actions
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_sysadmin_actions" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ -w%20/etc/sudoers.d/%20-p%20wa%20-k%20actions%0A-w%20/etc/sudoers%20-p%20wa%20-k%20actions%0A }}
        mode: 0600
        path: /etc/audit/rules.d/75-audit-sysadmin-actions.rules
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_sysadmin_actions:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_sysadmin_actions_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_system_shutdown" selected="false" severity="medium">
            <xccdf-1.2:title>Shutdown System When Auditing Failures Occur</xccdf-1.2:title>
            <xccdf-1.2:description>If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following line to to the bottom of a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-f <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audit_failure_mode" use="legacy"/></html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to the
bottom of the <html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-f <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audit_failure_mode" use="legacy"/></html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">SC-24</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000046-GPOS-00022</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000047-GPOS-00023</xccdf-1.2:reference>
            <xccdf-1.2:rationale>It is critical for the appropriate personnel to be aware if a system
is at risk of failing to process audit logs as required. Without this
notification, the security personnel may be unaware of an impending failure of
the audit capability, and system operation may be adversely affected.
<html:br/><html:br/>
Audit processing failures include software/hardware errors, failures in the
audit capturing mechanisms, and audit storage capacity being reached or
exceeded.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_system_shutdown" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_audit_failure_mode='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audit_failure_mode" use="legacy"/>'


# Traverse all of:
#
# /etc/audit/audit.rules,			(for auditctl case)
# /etc/audit/rules.d/*.rules			(for augenrules case)
find /etc/audit /etc/audit/rules.d -maxdepth 1 -type f -name '*.rules' -exec sed -i '/-f[[:space:]]\+.*/d' {} ';'

for AUDIT_FILE in "/etc/audit/audit.rules" "/etc/audit/rules.d/immutable.rules"
do
	echo '' &gt;&gt; $AUDIT_FILE
	echo '# Set the audit.rules configuration to halt system upon audit failure per security requirements' &gt;&gt; $AUDIT_FILE
	echo "-f $var_audit_failure_mode" &gt;&gt; $AUDIT_FILE
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_system_shutdown" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.3.1
  - NIST-800-171-3.3.4
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-24
  - audit_rules_system_shutdown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
- name: XCCDF Value var_audit_failure_mode # promote to variable
  set_fact:
    var_audit_failure_mode: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audit_failure_mode" use="legacy"/>
  tags:
    - always

- name: Collect all files from /etc/audit/rules.d with .rules extension
  ansible.builtin.find:
    paths: /etc/audit/rules.d/
    patterns: '*.rules'
  register: find_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.3.1
  - NIST-800-171-3.3.4
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-24
  - audit_rules_system_shutdown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Remove the -f option from all Audit config files
  ansible.builtin.lineinfile:
    path: '{{ item }}'
    regexp: ^\s*(?:-f)\s+.*$
    state: absent
  loop: '{{ find_rules_d.files | map(attribute=''path'') | list + [''/etc/audit/audit.rules'']
    }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.3.1
  - NIST-800-171-3.3.4
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-24
  - audit_rules_system_shutdown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Add Audit -f option into /etc/audit/rules.d/immutable.rules and /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    path: '{{ item }}'
    create: true
    mode: '0600'
    line: -f {{ var_audit_failure_mode }}
  loop:
  - /etc/audit/audit.rules
  - /etc/audit/rules.d/immutable.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.3.1
  - NIST-800-171-3.3.4
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-SC-24
  - audit_rules_system_shutdown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_audit_failure_mode:var:1" value-id="xccdf_org.ssgproject.content_value_var_audit_failure_mode"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_system_shutdown:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_system_shutdown_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information</xccdf-1.2:title>
            <xccdf-1.2:description>If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>, in order to capture events that modify
account changes:
<html:pre>-w /etc/group -p wa -k audit_rules_usergroup_modification
-w /etc/passwd -p wa -k audit_rules_usergroup_modification
-w /etc/gshadow -p wa -k audit_rules_usergroup_modification
-w /etc/shadow -p wa -k audit_rules_usergroup_modification
-w /etc/security/opasswd -p wa -k audit_rules_usergroup_modification</html:pre>
<html:br/>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file, in order to capture events that modify
account changes:
<html:pre>-w /etc/group -p wa -k audit_rules_usergroup_modification
-w /etc/passwd -p wa -k audit_rules_usergroup_modification
-w /etc/gshadow -p wa -k audit_rules_usergroup_modification
-w /etc/shadow -p wa -k audit_rules_usergroup_modification
-w /etc/security/opasswd -p wa -k audit_rules_usergroup_modification</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="general">This rule checks for multiple syscalls related to account changes;
it was written with DISA STIG in mind. Other policies should use a
separate rule for each syscall that needs to be checked. For example:
<html:ul><html:li><html:code>audit_rules_usergroup_modification_group</html:code></html:li><html:li><html:code>audit_rules_usergroup_modification_gshadow</html:code></html:li><html:li><html:code>audit_rules_usergroup_modification_passwd</html:code></html:li></html:ul></xccdf-1.2:warning>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000004-GPOS-00004</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000239-GPOS-00089</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000241-GPOS-00090</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000241-GPOS-00091</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000303-GPOS-00120</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000476-GPOS-00221</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000026-CTR-000070</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000027-CTR-000075</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000028-CTR-000080</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000291-CTR-000675</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000292-CTR-000680</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000293-CTR-000685</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000294-CTR-000690</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000319-CTR-000745</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000320-CTR-000750</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000509-CTR-001305</xccdf-1.2:reference>
            <xccdf-1.2:rationale>In addition to auditing new user and group accounts, these watches
will alert the system administrator(s) to any modifications. Any unexpected
users, groups, or modifications should be investigated for legitimacy.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_usergroup_modification" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/group" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/group $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/group$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/group -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/group" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_rules_usergroup_modification.rules"
    # If the audit_rules_usergroup_modification.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/group" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/group $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/group$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/group -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/passwd" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/passwd $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/passwd$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/passwd -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/passwd" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_rules_usergroup_modification.rules"
    # If the audit_rules_usergroup_modification.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/passwd" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/passwd $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/passwd$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/passwd -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/gshadow" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/gshadow $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/gshadow$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/gshadow -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/gshadow" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_rules_usergroup_modification.rules"
    # If the audit_rules_usergroup_modification.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/gshadow" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/gshadow $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/gshadow$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/gshadow -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/shadow" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/shadow $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/shadow$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/shadow -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/shadow" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_rules_usergroup_modification.rules"
    # If the audit_rules_usergroup_modification.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/shadow" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/shadow $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/shadow$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/shadow -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/security/opasswd" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/security/opasswd $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/security/opasswd$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/security/opasswd -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/security/opasswd" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_rules_usergroup_modification.rules"
    # If the audit_rules_usergroup_modification.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/security/opasswd" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/security/opasswd $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/security/opasswd$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/security/opasswd -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_usergroup_modification:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_usergroup_modification_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_group" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information - /etc/group</xccdf-1.2:title>
            <xccdf-1.2:description>



If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /etc/group -p wa -k audit_rules_usergroup_modification</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /etc/group -p wa -k audit_rules_usergroup_modification</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000004-GPOS-00004</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000304-GPOS-00121</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000470-GPOS-00214</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000239-GPOS-00089</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000240-GPOS-00090</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000241-GPOS-00091</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000303-GPOS-00120</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000476-GPOS-00221</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000503-CTR-001275</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030170</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230408r1017214_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>In addition to auditing new user and group accounts, these watches
will alert the system administrator(s) to any modifications. Any unexpected
users, groups, or modifications should be investigated for legitimacy.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_usergroup_modification_group" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/group" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/group $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/group$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/group -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/group" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_rules_usergroup_modification.rules"
    # If the audit_rules_usergroup_modification.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/group" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/group $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/group$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/group -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_usergroup_modification_group" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030170
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/group - Check if watch
    rule for /etc/group already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/group\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030170
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/group - Search /etc/audit/rules.d
    for other rules with specified key audit_rules_usergroup_modification
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)audit_rules_usergroup_modification$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030170
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/group - Use /etc/audit/rules.d/audit_rules_usergroup_modification.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/audit_rules_usergroup_modification.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030170
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/group - Use matched
    file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030170
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/group - Add watch
    rule for /etc/group in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/group -p wa -k audit_rules_usergroup_modification
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030170
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/group - Check if watch
    rule for /etc/group already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/group\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030170
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/group - Add watch
    rule for /etc/group in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/group -p wa -k audit_rules_usergroup_modification
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030170
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_group
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_usergroup_modification_group:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_usergroup_modification_group_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_gshadow" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information - /etc/gshadow</xccdf-1.2:title>
            <xccdf-1.2:description>



If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /etc/gshadow -p wa -k audit_rules_usergroup_modification</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /etc/gshadow -p wa -k audit_rules_usergroup_modification</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000004-GPOS-00004</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000304-GPOS-00121</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000470-GPOS-00214</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000239-GPOS-00089</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000240-GPOS-00090</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000241-GPOS-00091</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000303-GPOS-00120</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000476-GPOS-00221</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000503-CTR-001275</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030160</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230407r1017213_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>In addition to auditing new user and group accounts, these watches
will alert the system administrator(s) to any modifications. Any unexpected
users, groups, or modifications should be investigated for legitimacy.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_usergroup_modification_gshadow" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/gshadow" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/gshadow $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/gshadow$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/gshadow -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/gshadow" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_rules_usergroup_modification.rules"
    # If the audit_rules_usergroup_modification.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/gshadow" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/gshadow $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/gshadow$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/gshadow -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_usergroup_modification_gshadow" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030160
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/gshadow - Check if
    watch rule for /etc/gshadow already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/gshadow\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030160
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/gshadow - Search /etc/audit/rules.d
    for other rules with specified key audit_rules_usergroup_modification
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)audit_rules_usergroup_modification$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030160
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/gshadow - Use /etc/audit/rules.d/audit_rules_usergroup_modification.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/audit_rules_usergroup_modification.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030160
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/gshadow - Use matched
    file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030160
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/gshadow - Add watch
    rule for /etc/gshadow in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/gshadow -p wa -k audit_rules_usergroup_modification
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030160
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/gshadow - Check if
    watch rule for /etc/gshadow already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/gshadow\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030160
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/gshadow - Add watch
    rule for /etc/gshadow in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/gshadow -p wa -k audit_rules_usergroup_modification
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030160
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_gshadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_usergroup_modification_gshadow:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_usergroup_modification_gshadow_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_nsswitch_conf" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information - /etc/nsswitch.conf</xccdf-1.2:title>
            <xccdf-1.2:description>



If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /etc/nsswitch.conf -p wa -k audit_rules_usergroup_modification</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /etc/nsswitch.conf -p wa -k audit_rules_usergroup_modification</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.8</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The nsswitch file defines how the system uses various databases and name
resolution mechanisms. Any unexpected changes to nsswitch configuration
should be investigated.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_usergroup_modification_nsswitch_conf" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/nsswitch.conf" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/nsswitch.conf $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/nsswitch.conf$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/nsswitch.conf -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/nsswitch.conf" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_rules_usergroup_modification.rules"
    # If the audit_rules_usergroup_modification.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/nsswitch.conf" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/nsswitch.conf $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/nsswitch.conf$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/nsswitch.conf -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_usergroup_modification_nsswitch_conf" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - audit_rules_usergroup_modification_nsswitch_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/nsswitch.conf - Check
    if watch rule for /etc/nsswitch.conf already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/nsswitch.conf\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - audit_rules_usergroup_modification_nsswitch_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/nsswitch.conf - Search
    /etc/audit/rules.d for other rules with specified key audit_rules_usergroup_modification
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)audit_rules_usergroup_modification$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - audit_rules_usergroup_modification_nsswitch_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/nsswitch.conf - Use
    /etc/audit/rules.d/audit_rules_usergroup_modification.rules as the recipient for
    the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/audit_rules_usergroup_modification.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - audit_rules_usergroup_modification_nsswitch_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/nsswitch.conf - Use
    matched file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - audit_rules_usergroup_modification_nsswitch_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/nsswitch.conf - Add
    watch rule for /etc/nsswitch.conf in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/nsswitch.conf -p wa -k audit_rules_usergroup_modification
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - audit_rules_usergroup_modification_nsswitch_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/nsswitch.conf - Check
    if watch rule for /etc/nsswitch.conf already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/nsswitch.conf\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - audit_rules_usergroup_modification_nsswitch_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/nsswitch.conf - Add
    watch rule for /etc/nsswitch.conf in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/nsswitch.conf -p wa -k audit_rules_usergroup_modification
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - audit_rules_usergroup_modification_nsswitch_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_usergroup_modification_nsswitch_conf:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_usergroup_modification_nsswitch_conf_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_opasswd" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information - /etc/security/opasswd</xccdf-1.2:title>
            <xccdf-1.2:description>



If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /etc/security/opasswd -p wa -k audit_rules_usergroup_modification</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /etc/security/opasswd -p wa -k audit_rules_usergroup_modification</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000004-GPOS-00004</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000304-GPOS-00121</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000470-GPOS-00214</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000239-GPOS-00089</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000240-GPOS-00090</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000241-GPOS-00091</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000303-GPOS-00120</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000476-GPOS-00221</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000496-CTR-001240</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000497-CTR-001245</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000498-CTR-001250</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000503-CTR-001275</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030140</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230405r1017211_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>In addition to auditing new user and group accounts, these watches
will alert the system administrator(s) to any modifications. Any unexpected
users, groups, or modifications should be investigated for legitimacy.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_usergroup_modification_opasswd" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/security/opasswd" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/security/opasswd $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/security/opasswd$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/security/opasswd -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/security/opasswd" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_rules_usergroup_modification.rules"
    # If the audit_rules_usergroup_modification.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/security/opasswd" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/security/opasswd $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/security/opasswd$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/security/opasswd -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_usergroup_modification_opasswd" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030140
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/security/opasswd -
    Check if watch rule for /etc/security/opasswd already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/security/opasswd\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030140
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/security/opasswd -
    Search /etc/audit/rules.d for other rules with specified key audit_rules_usergroup_modification
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)audit_rules_usergroup_modification$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030140
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/security/opasswd -
    Use /etc/audit/rules.d/audit_rules_usergroup_modification.rules as the recipient
    for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/audit_rules_usergroup_modification.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030140
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/security/opasswd -
    Use matched file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030140
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/security/opasswd -
    Add watch rule for /etc/security/opasswd in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/security/opasswd -p wa -k audit_rules_usergroup_modification
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030140
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/security/opasswd -
    Check if watch rule for /etc/security/opasswd already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/security/opasswd\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030140
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/security/opasswd -
    Add watch rule for /etc/security/opasswd in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/security/opasswd -p wa -k audit_rules_usergroup_modification
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030140
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_opasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_usergroup_modification_opasswd:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_usergroup_modification_opasswd_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_pam_conf" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information - /etc/pam.conf</xccdf-1.2:title>
            <xccdf-1.2:description>



If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /etc/pam.conf -p wa -k audit_rules_usergroup_modification</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /etc/pam.conf -p wa -k audit_rules_usergroup_modification</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.8</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The PAM configuration file defines the authentication mechanism
used by PAM-aware applications. Any unexpected changes to PAM configuration
should be investigated.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_usergroup_modification_pam_conf" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/pam.conf" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/pam.conf $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/pam.conf$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/pam.conf -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/pam.conf" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_rules_usergroup_modification.rules"
    # If the audit_rules_usergroup_modification.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/pam.conf" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/pam.conf $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/pam.conf$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/pam.conf -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_usergroup_modification_pam_conf" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - audit_rules_usergroup_modification_pam_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/pam.conf - Check if
    watch rule for /etc/pam.conf already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/pam.conf\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - audit_rules_usergroup_modification_pam_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/pam.conf - Search
    /etc/audit/rules.d for other rules with specified key audit_rules_usergroup_modification
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)audit_rules_usergroup_modification$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - audit_rules_usergroup_modification_pam_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/pam.conf - Use /etc/audit/rules.d/audit_rules_usergroup_modification.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/audit_rules_usergroup_modification.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - audit_rules_usergroup_modification_pam_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/pam.conf - Use matched
    file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - audit_rules_usergroup_modification_pam_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/pam.conf - Add watch
    rule for /etc/pam.conf in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/pam.conf -p wa -k audit_rules_usergroup_modification
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - audit_rules_usergroup_modification_pam_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/pam.conf - Check if
    watch rule for /etc/pam.conf already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/pam.conf\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - audit_rules_usergroup_modification_pam_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/pam.conf - Add watch
    rule for /etc/pam.conf in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/pam.conf -p wa -k audit_rules_usergroup_modification
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - audit_rules_usergroup_modification_pam_conf
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_usergroup_modification_pam_conf:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_usergroup_modification_pam_conf_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_pamd" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information - /etc/pam.d/</xccdf-1.2:title>
            <xccdf-1.2:description>



If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /etc/pam.d/ -p wa -k audit_rules_usergroup_modification</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /etc/pam.d/ -p wa -k audit_rules_usergroup_modification</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.8</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The PAM configuration files in /etc/pam.d define the authentication mechanism
used by PAM-aware applications. Any unexpected changes to PAM configuration
should be investigated.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_usergroup_modification_pamd" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/pam.d/" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/pam.d/ $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/pam.d/$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/pam.d/ -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/pam.d/" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_rules_usergroup_modification.rules"
    # If the audit_rules_usergroup_modification.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/pam.d/" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/pam.d/ $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/pam.d/$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/pam.d/ -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_usergroup_modification_pamd" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - audit_rules_usergroup_modification_pamd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/pam.d/ - Check if
    watch rule for /etc/pam.d/ already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/pam.d/\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - audit_rules_usergroup_modification_pamd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/pam.d/ - Search /etc/audit/rules.d
    for other rules with specified key audit_rules_usergroup_modification
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)audit_rules_usergroup_modification$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - audit_rules_usergroup_modification_pamd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/pam.d/ - Use /etc/audit/rules.d/audit_rules_usergroup_modification.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/audit_rules_usergroup_modification.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - audit_rules_usergroup_modification_pamd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/pam.d/ - Use matched
    file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - audit_rules_usergroup_modification_pamd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/pam.d/ - Add watch
    rule for /etc/pam.d/ in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/pam.d/ -p wa -k audit_rules_usergroup_modification
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - audit_rules_usergroup_modification_pamd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/pam.d/ - Check if
    watch rule for /etc/pam.d/ already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/pam.d/\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - audit_rules_usergroup_modification_pamd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/pam.d/ - Add watch
    rule for /etc/pam.d/ in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/pam.d/ -p wa -k audit_rules_usergroup_modification
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - audit_rules_usergroup_modification_pamd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_usergroup_modification_pamd:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_usergroup_modification_pamd_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_passwd" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information - /etc/passwd</xccdf-1.2:title>
            <xccdf-1.2:description>



If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /etc/passwd -p wa -k audit_rules_usergroup_modification</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /etc/passwd -p wa -k audit_rules_usergroup_modification</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000004-GPOS-00004</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000304-GPOS-00121</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000470-GPOS-00214</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000239-GPOS-00089</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000240-GPOS-00090</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000241-GPOS-00091</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000303-GPOS-00120</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000304-GPOS-00121</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000476-GPOS-00221</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000274-GPOS-00104</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000275-GPOS-00105</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000276-GPOS-00106</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000277-GPOS-00107</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000503-CTR-001275</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030150</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230406r1017212_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>In addition to auditing new user and group accounts, these watches
will alert the system administrator(s) to any modifications. Any unexpected
users, groups, or modifications should be investigated for legitimacy.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_usergroup_modification_passwd" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/passwd" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/passwd $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/passwd$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/passwd -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/passwd" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_rules_usergroup_modification.rules"
    # If the audit_rules_usergroup_modification.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/passwd" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/passwd $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/passwd$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/passwd -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_usergroup_modification_passwd" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030150
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/passwd - Check if
    watch rule for /etc/passwd already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/passwd\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030150
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/passwd - Search /etc/audit/rules.d
    for other rules with specified key audit_rules_usergroup_modification
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)audit_rules_usergroup_modification$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030150
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/passwd - Use /etc/audit/rules.d/audit_rules_usergroup_modification.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/audit_rules_usergroup_modification.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030150
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/passwd - Use matched
    file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030150
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/passwd - Add watch
    rule for /etc/passwd in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/passwd -p wa -k audit_rules_usergroup_modification
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030150
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/passwd - Check if
    watch rule for /etc/passwd already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/passwd\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030150
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/passwd - Add watch
    rule for /etc/passwd in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/passwd -p wa -k audit_rules_usergroup_modification
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030150
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_usergroup_modification_passwd:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_usergroup_modification_passwd_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_shadow" selected="false" severity="medium">
            <xccdf-1.2:title>Record Events that Modify User/Group Information - /etc/shadow</xccdf-1.2:title>
            <xccdf-1.2:description>



If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /etc/shadow -p wa -k audit_rules_usergroup_modification</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /etc/shadow -p wa -k audit_rules_usergroup_modification</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000004-GPOS-00004</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000304-GPOS-00121</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000470-GPOS-00214</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000239-GPOS-00089</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000240-GPOS-00090</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000241-GPOS-00091</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000303-GPOS-00120</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000476-GPOS-00221</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000503-CTR-001275</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030130</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230404r1017210_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>In addition to auditing new user and group accounts, these watches
will alert the system administrator(s) to any modifications. Any unexpected
users, groups, or modifications should be investigated for legitimacy.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_usergroup_modification_shadow" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/shadow" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/shadow $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/shadow$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/shadow -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/shadow" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_rules_usergroup_modification.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_rules_usergroup_modification.rules"
    # If the audit_rules_usergroup_modification.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/shadow" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/shadow $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/shadow$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/shadow -p wa -k audit_rules_usergroup_modification" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_usergroup_modification_shadow" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030130
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/shadow - Check if
    watch rule for /etc/shadow already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/shadow\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030130
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/shadow - Search /etc/audit/rules.d
    for other rules with specified key audit_rules_usergroup_modification
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)audit_rules_usergroup_modification$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030130
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/shadow - Use /etc/audit/rules.d/audit_rules_usergroup_modification.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/audit_rules_usergroup_modification.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030130
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/shadow - Use matched
    file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030130
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/shadow - Add watch
    rule for /etc/shadow in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/shadow -p wa -k audit_rules_usergroup_modification
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030130
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/shadow - Check if
    watch rule for /etc/shadow already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/shadow\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030130
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Events that Modify User/Group Information - /etc/shadow - Add watch
    rule for /etc/shadow in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/shadow -p wa -k audit_rules_usergroup_modification
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030130
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.5
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.5
  - audit_rules_usergroup_modification_shadow
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_usergroup_modification_shadow:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_usergroup_modification_shadow_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_var_spool_cron" selected="false" severity="medium">
            <xccdf-1.2:title>Ensure auditd Collects Changes to Cron Jobs - /var/spool/cron</xccdf-1.2:title>
            <xccdf-1.2:description>



If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /var/spool/cron -p wa -k cronjobs</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /var/spool/cron -p wa -k cronjobs</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000363-GPOS-00150</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000363-GPOS-00150</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000446-GPOS-00200</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000447-GPOS-00201</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030655</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-274877r1155381_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>In addition to auditing new user and group accounts, these watches
will alert the system administrator(s) to any modifications. Any unexpected
users, groups, or modifications should be investigated for legitimacy.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_var_spool_cron" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/spool/cron" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/spool/cron $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/spool/cron$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/spool/cron -p wa -k cronjobs" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/cronjobs.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/var/spool/cron" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/cronjobs.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/cronjobs.rules"
    # If the cronjobs.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/spool/cron" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/spool/cron $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/spool/cron$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/spool/cron -p wa -k cronjobs" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_var_spool_cron" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030655
  - audit_rules_var_spool_cron
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Changes to Cron Jobs - /var/spool/cron - Check if watch
    rule for /var/spool/cron already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/var/spool/cron\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030655
  - audit_rules_var_spool_cron
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Changes to Cron Jobs - /var/spool/cron - Search /etc/audit/rules.d
    for other rules with specified key cronjobs
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)cronjobs$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030655
  - audit_rules_var_spool_cron
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Changes to Cron Jobs - /var/spool/cron - Use /etc/audit/rules.d/cronjobs.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/cronjobs.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - DISA-STIG-RHEL-08-030655
  - audit_rules_var_spool_cron
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Changes to Cron Jobs - /var/spool/cron - Use matched
    file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - DISA-STIG-RHEL-08-030655
  - audit_rules_var_spool_cron
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Changes to Cron Jobs - /var/spool/cron - Add watch
    rule for /var/spool/cron in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /var/spool/cron -p wa -k cronjobs
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030655
  - audit_rules_var_spool_cron
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Changes to Cron Jobs - /var/spool/cron - Check if watch
    rule for /var/spool/cron already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/var/spool/cron\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030655
  - audit_rules_var_spool_cron
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Changes to Cron Jobs - /var/spool/cron - Add watch
    rule for /var/spool/cron in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /var/spool/cron -p wa -k cronjobs
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030655
  - audit_rules_var_spool_cron
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_var_spool_cron:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_var_spool_cron_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_sudo_log_events" selected="false" severity="medium">
            <xccdf-1.2:title>Record Attempts to perform maintenance activities</xccdf-1.2:title>
            <xccdf-1.2:description>The AlmaLinux OS 8 operating system must generate audit records for
privileged activities, nonlocal maintenance, diagnostic sessions and
other system-level access.

Verify the operating system audits activities performed during nonlocal
maintenance and diagnostic sessions. Run the following command:
<html:pre>$ sudo auditctl -l | grep sudo.log
-w /var/log/sudo.log -p wa -k maintenance</html:pre>





If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /var/log/sudo.log -p wa -k maintenance</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /var/log/sudo.log -p wa -k maintenance</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.5.b</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If events associated with nonlocal administrative access or diagnostic
sessions are not logged, a major tool for assessing and investigating
attacks would not be available.
This requirement addresses auditing-related issues associated with
maintenance tools used specifically for diagnostic and repair actions
on organizational information systems.
Nonlocal maintenance and diagnostic activities are those activities
conducted by individuals communicating through a network, either an
external network (e.g., the internet) or an internal network. Local
maintenance and diagnostic activities are those activities carried
out by individuals physically present at the information system or
information system component and not communicating across a network
connection.
This requirement applies to hardware/software diagnostic test
equipment or tools. This requirement does not cover hardware/software
components that may support information system maintenance, yet are a
part of the system, for example, the software implementing "ping,"
"ls," "ipconfig," or the hardware and software implementing the
monitoring port of an Ethernet switch.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_sudo_log_events" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/sudo.log" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/sudo.log $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/sudo.log$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/sudo.log -p wa -k maintenance" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/maintenance.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/var/log/sudo.log" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/maintenance.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/maintenance.rules"
    # If the maintenance.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/sudo.log" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/sudo.log $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/sudo.log$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/sudo.log -p wa -k maintenance" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_sudo_log_events" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_sudo_log_events
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to perform maintenance activities - Check if watch rule for
    /var/log/sudo.log already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/var/log/sudo.log\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_sudo_log_events
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to perform maintenance activities - Search /etc/audit/rules.d
    for other rules with specified key maintenance
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)maintenance$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_sudo_log_events
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to perform maintenance activities - Use /etc/audit/rules.d/maintenance.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/maintenance.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_sudo_log_events
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to perform maintenance activities - Use matched file as the
    recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_sudo_log_events
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to perform maintenance activities - Add watch rule for /var/log/sudo.log
    in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /var/log/sudo.log -p wa -k maintenance
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_sudo_log_events
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to perform maintenance activities - Check if watch rule for
    /var/log/sudo.log already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/var/log/sudo.log\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_sudo_log_events
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to perform maintenance activities - Add watch rule for /var/log/sudo.log
    in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /var/log/sudo.log -p wa -k maintenance
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - PCI-DSS-Req-10.2.2
  - PCI-DSS-Req-10.2.5.b
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_sudo_log_events
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_sudo_log_events:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_sudo_log_events_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_access_var_log_audit" selected="false" severity="medium">
            <xccdf-1.2:title>Record Access Events to Audit Log Directory</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system should collect access events to read audit log directory.
The following audit rule will assure that access to audit log directory are
collected.
Set ARCH to either b32 for 32-bit system, or have two lines for both b32 and b64 in case your system is 64-bit.
<html:pre>-a always,exit -F arch=ARCH -F dir=/var/log/audit/ -F perm=r -F auid&gt;=1000 -F auid!=unset -F key=access-audit-trail</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
rule to a file with suffix <html:code>.rules</html:code> in the directory
<html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the rule to
<html:code>/etc/audit/audit.rules</html:code> file.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Attempts to read the logs should be recorded, suspicious access to audit log files could be an indicator of malicious activity on a system.
Auditing these events could serve as evidence of potential system compromise.'</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="directory_access_var_log_audit" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

OTHER_FILTERS="-F dir=/var/log/audit/ -F perm=r"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="access-audit-trail"
SYSCALL_GROUPING=""
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
    ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
    unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
    unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="directory_access_var_log_audit" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - directory_access_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Access Events to Audit Log Directory - Set architecture for audit tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - directory_access_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Access Events to Audit Log Directory - Perform remediation of Audit
    rules for /var/log/audit
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F dir=/var/log/audit/ -F perm=r -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access-audit-trail.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access-audit-trail.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F dir=/var/log/audit/ -F perm=r -F
        auid&gt;=1000 -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32{{ syscalls | join(',') }} -F dir=/var/log/audit/
        -F perm=r -F auid&gt;=1000 -F auid!=unset -F key=access-audit-trail
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F dir=/var/log/audit/ -F perm=r -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F dir=/var/log/audit/ -F perm=r -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32{{ syscalls | join(',') }} -F dir=/var/log/audit/
        -F perm=r -F auid&gt;=1000 -F auid!=unset -F key=access-audit-trail
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - directory_access_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Access Events to Audit Log Directory - Perform remediation of Audit
    rules for /var/log/audit for x86_64 platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F dir=/var/log/audit/ -F perm=r -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access-audit-trail.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access-audit-trail.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F dir=/var/log/audit/ -F perm=r -F
        auid&gt;=1000 -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64{{ syscalls | join(',') }} -F dir=/var/log/audit/
        -F perm=r -F auid&gt;=1000 -F auid!=unset -F key=access-audit-trail
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F dir=/var/log/audit/ -F perm=r -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F dir=/var/log/audit/ -F perm=r -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64{{ syscalls | join(',') }} -F dir=/var/log/audit/
        -F perm=r -F auid&gt;=1000 -F auid!=unset -F key=access-audit-trail
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - directory_access_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_access_var_log_audit:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_access_var_log_audit_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_group_ownership_var_log_audit" selected="false" severity="medium">
            <xccdf-1.2:title>System Audit Directories Must Be Group Owned By Root</xccdf-1.2:title>
            <xccdf-1.2:description>All audit directories must be group owned by root user. By default, the path for audit log is <html:pre>/var/log/audit/</html:pre>.
To properly set the group owner of <html:code>/var/log/audit</html:code>, run the command:

  <html:pre>$ sudo chgrp root /var/log/audit</html:pre>
  


If <html:code>log_group</html:code> in <html:code>/etc/audit/auditd.conf</html:code> is set to a group other than the <html:code>root</html:code>
group account, change the group ownership of the audit directories to this specific group.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000057-GPOS-00027</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000058-GPOS-00028</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000059-GPOS-00029</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000206-GPOS-00084</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030110</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230400r1017206_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Unauthorized disclosure of audit records can reveal system and configuration data to
attackers, thus compromising its confidentiality.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="directory_group_ownership_var_log_audit" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

if LC_ALL=C grep -m 1 -q ^log_group /etc/audit/auditd.conf; then
  GROUP=$(awk -F "=" '/log_group/ {print $2}' /etc/audit/auditd.conf | tr -d ' ')
else
  GROUP=root
fi
if LC_ALL=C grep -iw ^log_file /etc/audit/auditd.conf; then
  DIR=$(awk -F "=" '/^log_file/ {print $2}' /etc/audit/auditd.conf | tr -d ' ' | rev | cut -d"/" -f2- | rev)
else
  DIR="/var/log/audit"
fi


find ${DIR} -type d -exec chgrp ${GROUP} {} \;

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="directory_group_ownership_var_log_audit" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030110
  - NIST-800-171-3.3.1
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9(4)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - configure_strategy
  - directory_group_ownership_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: System Audit Directories Must Be Group Owned By Root - Register Audit Configuration
    Text
  ansible.builtin.slurp:
    src: /etc/audit/auditd.conf
  register: auditd_config_slurp
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030110
  - NIST-800-171-3.3.1
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9(4)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - configure_strategy
  - directory_group_ownership_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: System Audit Directories Must Be Group Owned By Root - Set Permissions Custom
    Location
  ansible.builtin.file:
    group: |-
      {{ auditd_config_slurp['content'] | b64decode | regex_findall('
      log_group\s*=\s*(.+)') | default(['root',], boolean=True) | first }}
    path: |-
      {{ auditd_config_slurp['content'] | b64decode | regex_findall('
      log_file\s*=\s*(.+)') | default(['/var/log/audit/audit.log',], boolean=True) | first | dirname }}
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030110
  - NIST-800-171-3.3.1
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9(4)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - configure_strategy
  - directory_group_ownership_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_group_ownership_var_log_audit:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_group_ownership_var_log_audit_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_ownership_var_log_audit" selected="false" severity="medium">
            <xccdf-1.2:title>System Audit Directories Must Be Owned By Root</xccdf-1.2:title>
            <xccdf-1.2:description>All audit directories must be owned by root user. By default, the path for audit log is <html:pre>/var/log/audit/</html:pre>.
To properly set the owner of <html:code>/var/log/audit</html:code>, run the command:

  <html:pre>$ sudo chown root /var/log/audit </html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000057-GPOS-00027</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000058-GPOS-00028</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000059-GPOS-00029</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000206-GPOS-00084</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030100</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230399r1017205_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Unauthorized disclosure of audit records can reveal system and configuration data to
attackers, thus compromising its confidentiality.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="directory_ownership_var_log_audit" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

if LC_ALL=C grep -iw ^log_file /etc/audit/auditd.conf; then
    FILE=$(awk -F "=" '/^log_file/ {print $2}' /etc/audit/auditd.conf | tr -d ' ')
    LOGPATH="$(dirname "$FILE")"
    chown root $LOGPATH
else
    chown root /var/log/audit
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="directory_ownership_var_log_audit" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030100
  - NIST-800-171-3.3.1
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9(4)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - configure_strategy
  - directory_ownership_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: System Audit Directories Must Be Owned By Root - Register Audit Configuration
    Text
  ansible.builtin.slurp:
    src: /etc/audit/auditd.conf
  register: auditd_config_slurp
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030100
  - NIST-800-171-3.3.1
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9(4)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - configure_strategy
  - directory_ownership_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: System Audit Directories Must Be Owned By Root - Set Permissions Custom Location
  ansible.builtin.file:
    owner: root
    path: |-
      {{ auditd_config_slurp['content'] | b64decode | regex_findall('
      log_file\s*=\s*(.+)') | default(['/var/log/audit/audit.log',], boolean=True) | first | dirname }}
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030100
  - NIST-800-171-3.3.1
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9(4)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.1
  - configure_strategy
  - directory_ownership_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_ownership_var_log_audit:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_ownership_var_log_audit_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_directory_permissions_var_log_audit" selected="false" severity="medium">
            <xccdf-1.2:title>System Audit Logs Must Have Mode 0750 or Less Permissive</xccdf-1.2:title>
            <xccdf-1.2:description>Verify the audit log directories have a mode of "0750" or less permissive by first determining
where the audit logs are stored with the following command:
<html:pre>$ sudo grep -iw log_file /etc/audit/auditd.conf
log_file = /var/log/audit/audit.log</html:pre>
By default, the audit log directory is <html:code>/var/log/audit</html:code>.
<html:br/>
Configure the audit log directory to be protected from unauthorized read access by setting the
correct permissive mode.
<html:br/>
The appropriate directory permissions depend on the <html:code>log_group</html:code> setting in <html:code>/etc/audit/auditd.conf</html:code>:
<html:br/>
<html:ul><html:li>If <html:code>log_group</html:code> is set to <html:code>root</html:code> or is not set, the directory should have mode <html:code>0700</html:code>.
This restricts access to root only, which is the most secure configuration.</html:li><html:li>If <html:code>log_group</html:code> is set to a group other than <html:code>root</html:code>, the directory should have mode <html:code>0750</html:code>.
This is necessary because when <html:code>log_group</html:code> is set to a non-root group, the audit log files are
typically configured with mode <html:code>0640</html:code> (allowing group read access). For group members to access
these files, they need execute permission on the directory to traverse it. The <html:code>0750</html:code> mode allows
root full access and the specified group read and execute access, while preventing others from accessing
the directory.</html:li></html:ul>
<html:br/>
If <html:code>log_group</html:code> is set to a group other than <html:code>root</html:code>, change the mode of the audit log directory
with the following command:
<html:pre>$ sudo chmod 0750 audit_log_directory</html:pre>
Otherwise, change the mode of the audit log directory with the following command:
<html:pre>$ sudo chmod 0700 audit_log_directory</html:pre>
Replace <html:code><html:i>audit_log_directory</html:i></html:code> with the correct audit log directory path.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000057-GPOS-00027</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000058-GPOS-00028</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000059-GPOS-00029</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030120</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230401r1017207_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If users can write to audit logs, audit trails can be modified or destroyed.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="directory_permissions_var_log_audit" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

if LC_ALL=C grep -iw ^log_file /etc/audit/auditd.conf; then
  DIR=$(awk -F "=" '/^log_file/ {print $2}' /etc/audit/auditd.conf | tr -d ' ' | rev | cut -d"/" -f2- | rev)
else
  DIR="/var/log/audit"
fi

if LC_ALL=C grep -m 1 -q ^log_group /etc/audit/auditd.conf; then
  GROUP=$(awk -F "=" '/log_group/ {print $2}' /etc/audit/auditd.conf | tr -d ' ')
  if ! [ "$GROUP" == 'root' ] ; then
    chmod 0750 "$DIR"
  else
    chmod 0700 "$DIR"
  fi
else
  chmod 0700 "$DIR"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="directory_permissions_var_log_audit" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030120
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9
  - NIST-800-53-CM-6(a)
  - directory_permissions_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: System Audit Logs Must Have Mode 0750 or Less Permissive - Get audit log file
    from /etc/audit/auditd.conf
  ansible.builtin.command: grep -iw ^log_file /etc/audit/auditd.conf
  check_mode: false
  failed_when: false
  changed_when: false
  register: log_file_exists
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030120
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9
  - NIST-800-53-CM-6(a)
  - directory_permissions_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: System Audit Logs Must Have Mode 0750 or Less Permissive - Set audit log directory
    path
  ansible.builtin.set_fact:
    log_file_dir: '{{ (log_file_exists.stdout | default('''') | split('' '') | last
      | dirname) | default(''/var/log/audit'', true) }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030120
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9
  - NIST-800-53-CM-6(a)
  - directory_permissions_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: System Audit Logs Must Have Mode 0750 or Less Permissive - Get audit log group
    from /etc/audit/auditd.conf
  ansible.builtin.command: grep -iw ^log_group /etc/audit/auditd.conf
  check_mode: false
  failed_when: false
  changed_when: false
  register: log_group_exists
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030120
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9
  - NIST-800-53-CM-6(a)
  - directory_permissions_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: System Audit Logs Must Have Mode 0750 or Less Permissive - Set audit log group
  ansible.builtin.set_fact:
    log_group: '{{ (log_group_exists.stdout | default('''') | split('' '') | last)
      | default(''root'', true) }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030120
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9
  - NIST-800-53-CM-6(a)
  - directory_permissions_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: System Audit Logs Must Have Mode 0750 or Less Permissive - Set audit log directory
    permissions
  ansible.builtin.file:
    path: '{{ log_file_dir }}'
    state: directory
    mode: '{{ ''0700'' if log_group == ''root'' else ''0750'' }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030120
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9
  - NIST-800-53-CM-6(a)
  - directory_permissions_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-directory_permissions_var_log_audit:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-directory_permissions_var_log_audit_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_group_ownership_var_log_audit" selected="false" severity="medium">
            <xccdf-1.2:title>System Audit Logs Must Be Group Owned By Root</xccdf-1.2:title>
            <xccdf-1.2:description>All audit logs must be group owned by root user. The path for audit log can
be configured via <html:code>log_file</html:code> parameter in <html:pre>/etc/audit/auditd.conf</html:pre>
or, by default, the path for audit log is <html:pre>/var/log/audit/</html:pre>.
To properly set the group owner of <html:code>/var/log/audit/*</html:code>, run the command:

  <html:pre>$ sudo chgrp root /var/log/audit/*</html:pre>
  


If <html:code>log_group</html:code> in <html:code>/etc/audit/auditd.conf</html:code> is set to a group other
than the <html:code>root</html:code> group account, change the group ownership of the audit logs
to this specific group.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000057-GPOS-00027</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000058-GPOS-00028</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000059-GPOS-00029</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000206-GPOS-00084</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030090</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230398r1017204_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Unauthorized disclosure of audit records can reveal system and configuration data to
attackers, thus compromising its confidentiality.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="file_group_ownership_var_log_audit" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

if LC_ALL=C grep -iw log_file /etc/audit/auditd.conf; then
  FILE=$(awk -F "=" '/^log_file/ {print $2}' /etc/audit/auditd.conf | tr -d ' ')
else
  FILE="/var/log/audit/audit.log"
fi


if LC_ALL=C grep -m 1 -q ^log_group /etc/audit/auditd.conf; then
  GROUP=$(awk -F "=" '/log_group/ {print $2}' /etc/audit/auditd.conf | tr -d ' ')
    if ! [ "${GROUP}" == 'root' ]; then
      chgrp ${GROUP} $FILE*
    else
      chgrp root $FILE*
    fi
else
  chgrp root $FILE*
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_group_ownership_var_log_audit:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_group_ownership_var_log_audit_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupownership_audit_configuration" selected="false" severity="medium">
            <xccdf-1.2:title>Audit Configuration Files Must Be Owned By Group root</xccdf-1.2:title>
            <xccdf-1.2:description>All audit configuration files must be owned by group root.
<html:pre>chown :root /etc/audit/audit*.{rules,conf} /etc/audit/rules.d/*</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000063-GPOS-00032</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.4.7</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Without the capability to restrict which roles and individuals can
select which events are audited, unauthorized personnel may be able
to prevent the auditing of critical events.
Misconfigured audits may degrade the system's performance by
overwhelming the audit log. Misconfigured audits may also make it more
difficult to establish, correlate, and investigate the events relating
to an incident or identify those responsible for one.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupownership_audit_configuration" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
find -P /etc/audit/ -maxdepth 1 -type f  ! -group 0 -regextype posix-extended -regex '^.*audit(\.rules|d\.conf)$' -exec chgrp --no-dereference "$newgroup" {} \;
find -P /etc/audit/rules.d/ -maxdepth 1 -type f  ! -group 0 -regextype posix-extended -regex '^.*\.rules$' -exec chgrp --no-dereference "$newgroup" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupownership_audit_configuration" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_groupownership_audit_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupownership_audit_configuration_newgroup variable if represented
    by gid
  ansible.builtin.set_fact:
    file_groupownership_audit_configuration_newgroup: '0'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_audit_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/audit/ file(s) matching ^.*audit(\.rules|d\.conf)$
  ansible.builtin.command: find -P /etc/audit/ -maxdepth 1 -type f  ! -group 0 -regextype
    posix-extended -regex "^.*audit(\.rules|d\.conf)$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_audit_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/audit/ file(s) matching ^.*audit(\.rules|d\.conf)$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    group: '{{ file_groupownership_audit_configuration_newgroup }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_audit_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/audit/rules.d/ file(s) matching ^.*\.rules$
  ansible.builtin.command: find -P /etc/audit/rules.d/ -maxdepth 1 -type f  ! -group
    0 -regextype posix-extended -regex "^.*\.rules$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_audit_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /etc/audit/rules.d/ file(s) matching ^.*\.rules$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    group: '{{ file_groupownership_audit_configuration_newgroup }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_audit_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupownership_audit_configuration:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupownership_audit_configuration_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_ownership_audit_configuration" selected="false" severity="medium">
            <xccdf-1.2:title>Audit Configuration Files Must Be Owned By Root</xccdf-1.2:title>
            <xccdf-1.2:description>All audit configuration files must be owned by root user.
To properly set the owner of <html:code>/etc/audit/</html:code>, run the command:

  <html:pre>$ sudo chown root /etc/audit/ </html:pre>
  

To properly set the owner of <html:code>/etc/audit/rules.d/</html:code>, run the command:

  <html:pre>$ sudo chown root /etc/audit/rules.d/ </html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000063-GPOS-00032</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.4.6</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Without the capability to restrict which roles and individuals can
select which events are audited, unauthorized personnel may be able
to prevent the auditing of critical events.
Misconfigured audits may degrade the system's performance by
overwhelming the audit log. Misconfigured audits may also make it more
difficult to establish, correlate, and investigate the events relating
to an incident or identify those responsible for one.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_ownership_audit_configuration" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else

find -P /etc/audit/ -maxdepth 1 -type f  ! -user 0 -regextype posix-extended -regex '^.*audit(\.rules|d\.conf)$' -exec chown --no-dereference "$newown" {} \;

find -P /etc/audit/rules.d/ -maxdepth 1 -type f  ! -user 0 -regextype posix-extended -regex '^.*\.rules$' -exec chown --no-dereference "$newown" {} \;

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_ownership_audit_configuration" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_ownership_audit_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_ownership_audit_configuration_newown variable if represented
    by uid
  ansible.builtin.set_fact:
    file_ownership_audit_configuration_newown: '0'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_audit_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/audit/ file(s) matching ^.*audit(\.rules|d\.conf)$
  ansible.builtin.command: find -P /etc/audit/ -maxdepth 1 -type f  ! -user 0 -regextype
    posix-extended -regex "^.*audit(\.rules|d\.conf)$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_audit_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/audit/ file(s) matching ^.*audit(\.rules|d\.conf)$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    owner: '{{ file_ownership_audit_configuration_newown }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_audit_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/audit/rules.d/ file(s) matching ^.*\.rules$
  ansible.builtin.command: find -P /etc/audit/rules.d/ -maxdepth 1 -type f  ! -user
    0 -regextype posix-extended -regex "^.*\.rules$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_audit_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /etc/audit/rules.d/ file(s) matching ^.*\.rules$
  ansible.builtin.file:
    path: '{{ item }}'
    follow: false
    owner: '{{ file_ownership_audit_configuration_newown }}'
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_audit_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_ownership_audit_configuration:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_ownership_audit_configuration_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_ownership_var_log_audit" selected="false" severity="medium">
            <xccdf-1.2:title>System Audit Logs Must Be Owned By Root</xccdf-1.2:title>
            <xccdf-1.2:description>All audit logs must be owned by root user and group. By default, the path for audit log is <html:pre>/var/log/audit/</html:pre>.
To properly set the owner of <html:code>/var/log/audit</html:code>, run the command:

  <html:pre>$ sudo chown root /var/log/audit </html:pre>
  

To properly set the owner of <html:code>/var/log/audit/*</html:code>, run the command:

  <html:pre>$ sudo chown root /var/log/audit/* </html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000057-GPOS-00027</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000058-GPOS-00028</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000059-GPOS-00029</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000118-CTR-000240</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Unauthorized disclosure of audit records can reveal system and configuration data to
attackers, thus compromising its confidentiality.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="file_ownership_var_log_audit" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

if LC_ALL=C grep -m 1 -q ^log_group /etc/audit/auditd.conf; then
  GROUP=$(awk -F "=" '/log_group/ {print $2}' /etc/audit/auditd.conf | tr -d ' ')
  if ! [ "${GROUP}" == 'root' ] ; then
    chown root:${GROUP} /var/log/audit
    chown root:${GROUP} /var/log/audit/audit.log*
  else
    chown root:root /var/log/audit
    chown root:root /var/log/audit/audit.log*
  fi
else
  chown root:root /var/log/audit
  chown root:root /var/log/audit/audit.log*
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_ownership_var_log_audit:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_ownership_var_log_audit_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_ownership_var_log_audit_stig" selected="false" severity="medium">
            <xccdf-1.2:title>System Audit Logs Must Be Owned By Root</xccdf-1.2:title>
            <xccdf-1.2:description>All audit logs must be owned by root user. The path for audit log can be
configured via <html:code>log_file</html:code> parameter in <html:pre>/etc/audit/auditd.conf</html:pre>
or by default, the path for audit log is <html:pre>/var/log/audit/</html:pre>.
To properly set the owner of <html:code>/var/log/audit/*</html:code>, run the command:

  <html:pre>$ sudo chown root /var/log/audit/* </html:pre>
  </xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000057-GPOS-00027</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000058-GPOS-00028</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000059-GPOS-00029</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000206-GPOS-00084</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030080</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230397r1017203_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Unauthorized disclosure of audit records can reveal system and configuration data to
attackers, thus compromising its confidentiality.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="file_ownership_var_log_audit_stig" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

if LC_ALL=C grep -iw log_file /etc/audit/auditd.conf; then
    FILE=$(awk -F "=" '/^log_file/ {print $2}' /etc/audit/auditd.conf | tr -d ' ')
    chown root $FILE*
else
    chown root /var/log/audit/audit.log*
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_ownership_var_log_audit_stig:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_ownership_var_log_audit_stig_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_audit_configuration" selected="false" severity="medium">
            <xccdf-1.2:title>Audit Configuration Files Permissions are 640 or More Restrictive</xccdf-1.2:title>
            <xccdf-1.2:description>All audit configuration files permissions must be 640 or more restrictive.
<html:pre>chmod 0640 /etc/audit/audit*.{rules,conf} /etc/audit/rules.d/*</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12 b</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000063-GPOS-00032</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.4.5</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Without the capability to restrict which roles and individuals can
select which events are audited, unauthorized personnel may be able
to prevent the auditing of critical events.
Misconfigured audits may degrade the system's performance by
overwhelming the audit log. Misconfigured audits may also make it more
difficult to establish, correlate, and investigate the events relating
to an incident or identify those responsible for one.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_audit_configuration" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

find -P /etc/audit/ -maxdepth 1 -perm /u+xs,g+xws,o+xwrt  -type f -regextype posix-extended -regex '^.*audit(\.rules|d\.conf)$' -exec chmod u-xs,g-xws,o-xwrt {} \;

find -P /etc/audit/rules.d/ -maxdepth 1 -perm /u+xs,g+xws,o+xwrt  -type f -regextype posix-extended -regex '^.*\.rules$' -exec chmod u-xs,g-xws,o-xwrt {} \;

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_audit_configuration" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12 b
  - configure_strategy
  - file_permissions_audit_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/audit/ file(s)
  ansible.builtin.command: find -P /etc/audit/ -maxdepth 1 -perm /u+xs,g+xws,o+xwrt  -type
    f -regextype posix-extended -regex "^.*audit(\.rules|d\.conf)$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12 b
  - configure_strategy
  - file_permissions_audit_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /etc/audit/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-xs,g-xws,o-xwrt
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12 b
  - configure_strategy
  - file_permissions_audit_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/audit/rules.d/ file(s)
  ansible.builtin.command: find -P /etc/audit/rules.d/ -maxdepth 1 -perm /u+xs,g+xws,o+xwrt  -type
    f -regextype posix-extended -regex "^.*\.rules$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12 b
  - configure_strategy
  - file_permissions_audit_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /etc/audit/rules.d/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-xs,g-xws,o-xwrt
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12 b
  - configure_strategy
  - file_permissions_audit_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_audit_configuration:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_var_log_audit" selected="false" severity="medium">
            <xccdf-1.2:title>System Audit Logs Must Have Mode 0640 or Less Permissive</xccdf-1.2:title>
            <xccdf-1.2:description>Verify the audit log files have a mode of "0640" or less permissive by first determining
where the audit logs are stored with the following command:
<html:pre>$ sudo grep -iw log_file /etc/audit/auditd.conf
log_file = /var/log/audit/audit.log</html:pre>
By default, the audit log file is <html:code>/var/log/audit/audit.log</html:code>.
<html:br/>
Configure the audit log to be protected from unauthorized read access by setting the correct
permissive mode.
If <html:code>log_group</html:code> in <html:code>/etc/audit/auditd.conf</html:code> is set to a group other than the
<html:code>root</html:code> group account, change the mode of the audit log files with the following command:
<html:pre>$ sudo chmod 0640 <html:i>audit_log_file</html:i></html:pre>
<html:br/>
Otherwise, change the mode of the audit log files with the following command:
<html:pre>$ sudo chmod 0600 <html:i>audit_log_file</html:i></html:pre>
Replace <html:code><html:i>audit_log_file</html:i></html:code> with the correct audit log file path.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">18</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO01.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS06.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.7.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.10.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.7.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.8.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.9.4.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000057-GPOS-00027</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000058-GPOS-00028</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000059-GPOS-00029</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000206-GPOS-00084</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000118-CTR-000240</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030070</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230396r1017202_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If users can write to audit logs, audit trails can be modified or destroyed.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="file_permissions_var_log_audit" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

if LC_ALL=C grep -iw ^log_file /etc/audit/auditd.conf; then
    FILE=$(awk -F "=" '/^log_file/ {print $2}' /etc/audit/auditd.conf | tr -d ' ')
else
    FILE="/var/log/audit/audit.log"
fi

if LC_ALL=C grep -m 1 -q ^log_group /etc/audit/auditd.conf; then
    GROUP=$(awk -F "=" '/log_group/ {print $2}' /etc/audit/auditd.conf | tr -d ' ')
    if ! [ "$GROUP" == 'root' ] ; then
       chmod 0640 "$FILE"
    else
       chmod 0600 "$FILE"
    fi
else
    chmod 0600 "$FILE"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_var_log_audit" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030070
  - NIST-800-171-3.3.1
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9(4)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - file_permissions_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: System Audit Logs Must Have Mode 0640 or Less Permissive - Get audit log file
    from /etc/audit/auditd.conf
  ansible.builtin.command: grep -iw ^log_file /etc/audit/auditd.conf
  check_mode: false
  failed_when: false
  changed_when: false
  register: log_file_exists
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030070
  - NIST-800-171-3.3.1
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9(4)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - file_permissions_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: System Audit Logs Must Have Mode 0640 or Less Permissive - Set audit log file
    path
  ansible.builtin.set_fact:
    log_file_path: '{{ (log_file_exists.stdout | default('''') | split('' '') | last)
      | default(''/var/log/audit/audit.log'', true) }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030070
  - NIST-800-171-3.3.1
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9(4)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - file_permissions_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: System Audit Logs Must Have Mode 0640 or Less Permissive - Get audit log group
    from /etc/audit/auditd.conf
  ansible.builtin.command: grep -iw ^log_group /etc/audit/auditd.conf
  check_mode: false
  failed_when: false
  changed_when: false
  register: log_group_exists
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030070
  - NIST-800-171-3.3.1
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9(4)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - file_permissions_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: System Audit Logs Must Have Mode 0640 or Less Permissive - Set audit log group
  ansible.builtin.set_fact:
    log_group: '{{ (log_group_exists.stdout | default('''') | split('' '') | last)
      | default(''root'', true) }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030070
  - NIST-800-171-3.3.1
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9(4)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - file_permissions_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: System Audit Logs Must Have Mode 0640 or Less Permissive - Set audit log file
    permissions
  ansible.builtin.file:
    path: '{{ log_file_path }}'
    state: file
    mode: '{{ ''0600'' if log_group == ''root'' else ''0640'' }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030070
  - NIST-800-171-3.3.1
  - NIST-800-53-AC-6(1)
  - NIST-800-53-AU-9(4)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.1
  - file_permissions_var_log_audit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_var_log_audit:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_var_log_audit_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_audit_dac_actions">
            <xccdf-1.2:title>Record Events that Modify the System's Discretionary Access Controls</xccdf-1.2:title>
            <xccdf-1.2:description>At a minimum, the audit system should collect file permission
changes for all users and root. Note that the "-F arch=b32" lines should be
present even on a 64 bit system. These commands identify system calls for
auditing. Even if the system is 64 bit it can still execute 32 bit system
calls. Additionally, these rules can be configured in a number of ways while
still achieving the desired effect. An example of this is that the "-S" calls
could be split up and placed on separate lines, however, this is less efficient.
Add the following to <html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat -F auid&gt;=1000 -F auid!=unset -F key=perm_mod

    -a always,exit -F arch=b32 -S chown,fchown,fchownat,lchown -F auid&gt;=1000 -F auid!=unset -F key=perm_mod
    -a always,exit -F arch=b32 -S setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If your system is 64 bit then these lines should be duplicated and the
arch=b32 replaced with arch=b64 as follows:

<html:pre>-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat -F auid&gt;=1000 -F auid!=unset -F key=perm_mod

    -a always,exit -F arch=b64 -S chown,fchown,fchownat,lchown -F auid&gt;=1000 -F auid!=unset -F key=perm_mod
    -a always,exit -F arch=b64 -S setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre></xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod" selected="false" severity="medium">
              <xccdf-1.2:title>Record Events that Modify the System's Discretionary Access Controls - chmod</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission
changes for all users and root. If the <html:code>auditd</html:code> daemon is configured to
use the <html:code>augenrules</html:code> program to read audit rules during daemon startup
(the default), add the following line to a file with suffix <html:code>.rules</html:code> in
the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S chmod -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S chmod -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S chmod -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S chmod -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect.  Here the system calls
have been placed independent of other system calls.  Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000091-CTR-000160</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000492-CTR-001220</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000493-CTR-001225</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000494-CTR-001230</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000500-CTR-001260</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000507-CTR-001295</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030490</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230456r1017253_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The changing of file permissions could indicate that a user is attempting to
gain access to information that would otherwise be disallowed. Auditing DAC modifications
can facilitate the identification of patterns of abuse among both authorized and
unauthorized users.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_dac_modification_chmod" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="chmod"
	KEY="perm_mod"
	SYSCALL_GROUPING="chmod fchmod fchmodat"

	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_dac_modification_chmod" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030490
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_chmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit chmod tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030490
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_chmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for chmod for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat

  - name: Check existence of chmod in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat

  - name: Check existence of chmod in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030490
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_chmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for chmod for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat

  - name: Check existence of chmod in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat

  - name: Check existence of chmod in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030490
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_chmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_dac_modification_chmod:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_dac_modification_chmod_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown" selected="false" severity="medium">
              <xccdf-1.2:title>Record Events that Modify the System's Discretionary Access Controls - chown</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission
changes for all users and root. If the <html:code>auditd</html:code> daemon is configured to
use the <html:code>augenrules</html:code> program to read audit rules during daemon startup
(the default), add the following line to a file with suffix <html:code>.rules</html:code> in
the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S chown -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S chown -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S chown -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S chown -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect.  Here the system calls
have been placed independent of other system calls.  Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000091-CTR-000160</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000492-CTR-001220</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000493-CTR-001225</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000494-CTR-001230</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000500-CTR-001260</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000507-CTR-001295</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030480</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230455r1017251_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The changing of file permissions could indicate that a user is attempting to
gain access to information that would otherwise be disallowed. Auditing DAC modifications
can facilitate the identification of patterns of abuse among both authorized and
unauthorized users.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_dac_modification_chown" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="chown"
	KEY="perm_mod"
	SYSCALL_GROUPING="chown fchown fchownat lchown"

	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_dac_modification_chown" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030480
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_chown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit chown tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030480
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_chown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for chown for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of chown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of chown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030480
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_chown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for chown for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of chown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of chown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030480
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_chown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_dac_modification_chown:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmod" selected="false" severity="medium">
              <xccdf-1.2:title>Record Events that Modify the System's Discretionary Access Controls - fchmod</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission
changes for all users and root. If the <html:code>auditd</html:code> daemon is configured to
use the <html:code>augenrules</html:code> program to read audit rules during daemon startup
(the default), add the following line to a file with suffix <html:code>.rules</html:code> in
the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S fchmod -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S fchmod -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S fchmod -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S fchmod -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000091-CTR-000160</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000492-CTR-001220</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000493-CTR-001225</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000494-CTR-001230</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000500-CTR-001260</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000507-CTR-001295</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030490</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230456r1017253_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The changing of file permissions could indicate that a user is attempting to
gain access to information that would otherwise be disallowed. Auditing DAC modifications
can facilitate the identification of patterns of abuse among both authorized and
unauthorized users.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_dac_modification_fchmod" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="fchmod"
	KEY="perm_mod"
	SYSCALL_GROUPING="chmod fchmod fchmodat"

	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_dac_modification_fchmod" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030490
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fchmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit fchmod tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030490
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fchmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchmod for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat

  - name: Check existence of fchmod in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat

  - name: Check existence of fchmod in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030490
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fchmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchmod for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat

  - name: Check existence of fchmod in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat

  - name: Check existence of fchmod in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030490
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fchmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_dac_modification_fchmod:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmodat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Events that Modify the System's Discretionary Access Controls - fchmodat</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission
changes for all users and root. If the <html:code>auditd</html:code> daemon is configured to
use the <html:code>augenrules</html:code> program to read audit rules during daemon startup
(the default), add the following line to a file with suffix <html:code>.rules</html:code> in
the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S fchmodat -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S fchmodat -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S fchmodat -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S fchmodat -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000091-CTR-000160</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000492-CTR-001220</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000493-CTR-001225</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000494-CTR-001230</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000500-CTR-001260</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000507-CTR-001295</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030490</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230456r1017253_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The changing of file permissions could indicate that a user is attempting to
gain access to information that would otherwise be disallowed. Auditing DAC modifications
can facilitate the identification of patterns of abuse among both authorized and
unauthorized users.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_dac_modification_fchmodat" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="fchmodat"
	KEY="perm_mod"
	SYSCALL_GROUPING="chmod fchmod fchmodat"

	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_dac_modification_fchmodat" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030490
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fchmodat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit fchmodat tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030490
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fchmodat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchmodat for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmodat
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat

  - name: Check existence of fchmodat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmodat
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat

  - name: Check existence of fchmodat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030490
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fchmodat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchmodat for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmodat
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat

  - name: Check existence of fchmodat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmodat
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat

  - name: Check existence of fchmodat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030490
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fchmodat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_dac_modification_fchmodat:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_dac_modification_fchmodat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchown" selected="false" severity="medium">
              <xccdf-1.2:title>Record Events that Modify the System's Discretionary Access Controls - fchown</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission
changes for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following line to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S fchown -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>

If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S fchown -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S fchown -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>

If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S fchown -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000091-CTR-000160</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000492-CTR-001220</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000493-CTR-001225</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000494-CTR-001230</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000500-CTR-001260</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000507-CTR-001295</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030480</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230455r1017251_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The changing of file permissions could indicate that a user is attempting to
gain access to information that would otherwise be disallowed. Auditing DAC modifications
can facilitate the identification of patterns of abuse among both authorized and
unauthorized users.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_dac_modification_fchown" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="fchown"
	KEY="perm_mod"
	SYSCALL_GROUPING="chown fchown fchownat lchown"

	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_dac_modification_fchown" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030480
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit fchown tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030480
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchown for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030480
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchown for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030480
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_dac_modification_fchown:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchownat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Events that Modify the System's Discretionary Access Controls - fchownat</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission
changes for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following line to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S fchownat -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S fchownat -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S fchownat -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S fchownat -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000091-CTR-000160</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000492-CTR-001220</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000493-CTR-001225</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000494-CTR-001230</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000500-CTR-001260</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000507-CTR-001295</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030480</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230455r1017251_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The changing of file permissions could indicate that a user is attempting to
gain access to information that would otherwise be disallowed. Auditing DAC modifications
can facilitate the identification of patterns of abuse among both authorized and
unauthorized users.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_dac_modification_fchownat" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="fchownat"
	KEY="perm_mod"
	SYSCALL_GROUPING="chown fchown fchownat lchown"

	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_dac_modification_fchownat" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030480
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fchownat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit fchownat tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030480
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fchownat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchownat for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchownat
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchownat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchownat
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchownat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030480
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fchownat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchownat for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchownat
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchownat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchownat
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchownat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030480
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fchownat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_dac_modification_fchownat:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fremovexattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Events that Modify the System's Discretionary Access Controls - fremovexattr</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission
changes for all users and root.
<html:br/><html:br/>
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following line to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S fremovexattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
<html:br/><html:br/>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S fremovexattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
<html:br/><html:br/>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S fremovexattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
<html:br/><html:br/>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S fremovexattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000091-CTR-000160</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000492-CTR-001220</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000493-CTR-001225</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000494-CTR-001230</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000500-CTR-001260</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000507-CTR-001295</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000496-CTR-001240</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000497-CTR-001245</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000498-CTR-001250</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030200</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230413r1017219_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The changing of file permissions could indicate that a user is attempting to
gain access to information that would otherwise be disallowed. Auditing DAC modifications
can facilitate the identification of patterns of abuse among both authorized and
unauthorized users.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_dac_modification_fremovexattr" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="fremovexattr"
	KEY="perm_mod"
	SYSCALL_GROUPING="fremovexattr lremovexattr removexattr fsetxattr lsetxattr setxattr"

	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_dac_modification_fremovexattr" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit fremovexattr tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fremovexattr for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fremovexattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fremovexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fremovexattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fremovexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fremovexattr for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fremovexattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fremovexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fremovexattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fremovexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_dac_modification_fremovexattr:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fsetxattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Events that Modify the System's Discretionary Access Controls - fsetxattr</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission
changes for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following line to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S fsetxattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S fsetxattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S fsetxattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S fsetxattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000091-CTR-000160</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000492-CTR-001220</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000493-CTR-001225</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000494-CTR-001230</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000500-CTR-001260</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000507-CTR-001295</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000496-CTR-001240</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000497-CTR-001245</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000498-CTR-001250</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000501-CTR-001265</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000502-CTR-001270</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030200</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230413r1017219_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The changing of file permissions could indicate that a user is attempting to
gain access to information that would otherwise be disallowed. Auditing DAC modifications
can facilitate the identification of patterns of abuse among both authorized and
unauthorized users.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_dac_modification_fsetxattr" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="fsetxattr"
	KEY="perm_mod"
	SYSCALL_GROUPING="fremovexattr lremovexattr removexattr fsetxattr lsetxattr setxattr"

	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_dac_modification_fsetxattr" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit fsetxattr tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fsetxattr for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fsetxattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fsetxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fsetxattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fsetxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fsetxattr for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fsetxattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fsetxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fsetxattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fsetxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_fsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_dac_modification_fsetxattr:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_dac_modification_fsetxattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lchown" selected="false" severity="medium">
              <xccdf-1.2:title>Record Events that Modify the System's Discretionary Access Controls - lchown</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission
changes for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following line to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S lchown -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S lchown -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S lchown -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S lchown -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000091-CTR-000160</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000492-CTR-001220</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000493-CTR-001225</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000494-CTR-001230</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000500-CTR-001260</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000507-CTR-001295</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030480</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230455r1017251_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The changing of file permissions could indicate that a user is attempting to
gain access to information that would otherwise be disallowed. Auditing DAC modifications
can facilitate the identification of patterns of abuse among both authorized and
unauthorized users.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_dac_modification_lchown" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="lchown"
	KEY="perm_mod"
	SYSCALL_GROUPING="chown fchown fchownat lchown"

	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_dac_modification_lchown" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030480
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_lchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit lchown tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030480
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_lchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lchown for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of lchown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of lchown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030480
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_lchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lchown for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of lchown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of lchown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030480
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_lchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_dac_modification_lchown:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_dac_modification_lchown_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lremovexattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Events that Modify the System's Discretionary Access Controls - lremovexattr</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission
changes for all users and root.
<html:br/><html:br/>
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following line to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S lremovexattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
<html:br/><html:br/>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S lremovexattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
<html:br/><html:br/>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S lremovexattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
<html:br/><html:br/>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S lremovexattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000091-CTR-000160</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000492-CTR-001220</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000493-CTR-001225</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000494-CTR-001230</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000500-CTR-001260</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000507-CTR-001295</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000496-CTR-001240</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000497-CTR-001245</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000498-CTR-001250</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000501-CTR-001265</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000502-CTR-001270</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030200</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230413r1017219_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The changing of file permissions could indicate that a user is attempting to
gain access to information that would otherwise be disallowed. Auditing DAC modifications
can facilitate the identification of patterns of abuse among both authorized and
unauthorized users.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_dac_modification_lremovexattr" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="lremovexattr"
	KEY="perm_mod"
	SYSCALL_GROUPING="fremovexattr lremovexattr removexattr fsetxattr lsetxattr setxattr"

	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_dac_modification_lremovexattr" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_lremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit lremovexattr tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_lremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lremovexattr for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lremovexattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of lremovexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lremovexattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of lremovexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_lremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lremovexattr for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lremovexattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of lremovexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lremovexattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of lremovexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_lremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_dac_modification_lremovexattr:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lsetxattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Events that Modify the System's Discretionary Access Controls - lsetxattr</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission
changes for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following line to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S lsetxattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S lsetxattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S lsetxattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S lsetxattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000091-CTR-000160</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000492-CTR-001220</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000493-CTR-001225</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000494-CTR-001230</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000500-CTR-001260</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000507-CTR-001295</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000496-CTR-001240</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000497-CTR-001245</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000498-CTR-001250</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000501-CTR-001265</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000502-CTR-001270</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030200</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230413r1017219_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The changing of file permissions could indicate that a user is attempting to
gain access to information that would otherwise be disallowed. Auditing DAC modifications
can facilitate the identification of patterns of abuse among both authorized and
unauthorized users.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_dac_modification_lsetxattr" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="lsetxattr"
	KEY="perm_mod"
	SYSCALL_GROUPING="fremovexattr lremovexattr removexattr fsetxattr lsetxattr setxattr"

	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_dac_modification_lsetxattr" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_lsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit lsetxattr tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_lsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lsetxattr for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lsetxattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of lsetxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lsetxattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of lsetxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_lsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lsetxattr for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lsetxattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of lsetxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lsetxattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of lsetxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_lsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_dac_modification_lsetxattr:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_removexattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Events that Modify the System's Discretionary Access Controls - removexattr</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission
changes for all users and root.
<html:br/><html:br/>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following line to a file with suffix <html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S removexattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
<html:br/><html:br/>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S removexattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
<html:br/><html:br/>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S removexattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
<html:br/><html:br/>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S removexattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000091-CTR-000160</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000492-CTR-001220</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000493-CTR-001225</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000494-CTR-001230</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000500-CTR-001260</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000507-CTR-001295</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000496-CTR-001240</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000497-CTR-001245</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000498-CTR-001250</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000501-CTR-001265</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000502-CTR-001270</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030200</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230413r1017219_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The changing of file permissions could indicate that a user is attempting to
gain access to information that would otherwise be disallowed. Auditing DAC modifications
can facilitate the identification of patterns of abuse among both authorized and
unauthorized users.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_dac_modification_removexattr" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="removexattr"
	KEY="perm_mod"
	SYSCALL_GROUPING="fremovexattr lremovexattr removexattr fsetxattr lsetxattr setxattr"

	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_dac_modification_removexattr" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_removexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit removexattr tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_removexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for removexattr for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - removexattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of removexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - removexattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of removexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_removexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for removexattr for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - removexattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of removexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - removexattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of removexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_removexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_dac_modification_removexattr:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_setxattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Events that Modify the System's Discretionary Access Controls - setxattr</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission
changes for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following line to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S setxattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S setxattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S setxattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S setxattr -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000091-CTR-000160</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000492-CTR-001220</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000493-CTR-001225</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000494-CTR-001230</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000500-CTR-001260</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000507-CTR-001295</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030200</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230413r1017219_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The changing of file permissions could indicate that a user is attempting to
gain access to information that would otherwise be disallowed. Auditing DAC modifications
can facilitate the identification of patterns of abuse among both authorized and
unauthorized users.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_dac_modification_setxattr" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="setxattr"
	KEY="perm_mod"
	SYSCALL_GROUPING="fremovexattr lremovexattr removexattr fsetxattr lsetxattr setxattr"

	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_dac_modification_setxattr" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_setxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit setxattr tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_setxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for setxattr for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - setxattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of setxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - setxattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of setxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_setxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for setxattr for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - setxattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of setxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - setxattr
      syscall_grouping:
      - fremovexattr
      - lremovexattr
      - removexattr
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of setxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030200
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.5
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.4
  - audit_rules_dac_modification_setxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_dac_modification_setxattr:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_umount" selected="false" severity="medium">
              <xccdf-1.2:title>Record Events that Modify the System's Discretionary Access Controls - umount</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file system umount
changes. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following line to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S umount -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S umount -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The changing of file permissions could indicate that a user is attempting to
gain access to information that would otherwise be disallowed. Auditing DAC modifications
can facilitate the identification of patterns of abuse among both authorized and
unauthorized users.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_dac_modification_umount" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

ACTION_ARCH_FILTERS="-a always,exit -F arch=b32"
OTHER_FILTERS=""
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="umount"
KEY="perm_mod"
SYSCALL_GROUPING=""

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_dac_modification_umount" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - audit_rules_dac_modification_umount
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for umount for x86 platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - umount
      syscall_grouping: []

  - name: Check existence of umount in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - umount
      syscall_grouping: []

  - name: Check existence of umount in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - audit_rules_dac_modification_umount
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_dac_modification_umount:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_dac_modification_umount_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_umount2" selected="false" severity="medium">
              <xccdf-1.2:title>Record Events that Modify the System's Discretionary Access Controls - umount2</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file system umount2
changes. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following line to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S umount2 -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S umount2 -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S umount2 -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S umount2 -F auid&gt;=1000 -F auid!=unset -F key=perm_mod</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The changing of file permissions could indicate that a user is attempting to
gain access to information that would otherwise be disallowed. Auditing DAC modifications
can facilitate the identification of patterns of abuse among both authorized and
unauthorized users.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_dac_modification_umount2" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="umount2"
	KEY="perm_mod"
	SYSCALL_GROUPING=""

	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_dac_modification_umount2" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - audit_rules_dac_modification_umount2
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit umount2 tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - audit_rules_dac_modification_umount2
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for umount2 for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - umount2
      syscall_grouping: []

  - name: Check existence of umount2 in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - umount2
      syscall_grouping: []

  - name: Check existence of umount2 in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - audit_rules_dac_modification_umount2
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for umount2 for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - umount2
      syscall_grouping: []

  - name: Check existence of umount2 in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/perm_mod.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/perm_mod.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - umount2
      syscall_grouping: []

  - name: Check existence of umount2 in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=perm_mod
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - audit_rules_dac_modification_umount2
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_dac_modification_umount2:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_dac_modification_umount2_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_audit_execution_acl_commands">
            <xccdf-1.2:title>Record Execution Attempts to Run ACL Privileged Commands</xccdf-1.2:title>
            <xccdf-1.2:description>At a minimum, the audit system should collect the execution of
ACL privileged commands for all users and root.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_execution_chacl" selected="false" severity="medium">
              <xccdf-1.2:title>Record Any Attempts to Run chacl</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/chacl -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/chacl -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.17</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030570</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230464r1017256_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Without generating audit records that are specific to the security and
mission needs of the organization, it would be difficult to establish,
correlate, and investigate the events relating to an incident or identify
those responsible for one.
Audit records can be generated from various components within the
information system (e.g., module or policy filter).</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_execution_chacl" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/chacl"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_execution_chacl" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030570
  - audit_rules_execution_chacl
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Any Attempts to Run chacl - Perform remediation of Audit rules for
    /usr/bin/chacl
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/chacl -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/chacl -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/chacl -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/chacl -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/chacl -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/chacl -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030570
  - audit_rules_execution_chacl
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_execution_chacl:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_execution_chacl_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_execution_setfacl" selected="false" severity="medium">
              <xccdf-1.2:title>Record Any Attempts to Run setfacl</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/setfacl -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/setfacl -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030330</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230435r1017236_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Without generating audit records that are specific to the security and
mission needs of the organization, it would be difficult to establish,
correlate, and investigate the events relating to an incident or identify
those responsible for one.
Audit records can be generated from various components within the
information system (e.g., module or policy filter).</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_execution_setfacl" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/setfacl"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_execution_setfacl" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030330
  - audit_rules_execution_setfacl
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Any Attempts to Run setfacl - Perform remediation of Audit rules for
    /usr/bin/setfacl
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/setfacl -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/setfacl -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/setfacl -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/setfacl -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/setfacl -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/setfacl -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030330
  - audit_rules_execution_setfacl
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_execution_setfacl:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_execution_setfacl_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_audit_execution_selinux_commands">
            <xccdf-1.2:title>Record Execution Attempts to Run SELinux Privileged Commands</xccdf-1.2:title>
            <xccdf-1.2:description>At a minimum, the audit system should collect the execution of
SELinux privileged commands for all users and root.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_execution_chcon" selected="false" severity="medium">
              <xccdf-1.2:title>Record Any Attempts to Run chcon</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/chcon -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/chcon -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000496-CTR-001240</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000497-CTR-001245</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000498-CTR-001250</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000501-CTR-001265</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000502-CTR-001270</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030260</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230419r1017221_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_execution_chcon" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/chcon"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_execution_chcon" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030260
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_execution_chcon
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Any Attempts to Run chcon - Perform remediation of Audit rules for
    /usr/bin/chcon
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/chcon -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/chcon -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/chcon -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/chcon -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/chcon -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/chcon -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030260
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_execution_chcon
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_execution_chcon:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_execution_chcon_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_execution_restorecon" selected="false" severity="medium">
              <xccdf-1.2:title>Record Any Attempts to Run restorecon</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/restorecon -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/restorecon -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_execution_restorecon" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/sbin/restorecon"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_execution_restorecon" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_execution_restorecon
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Any Attempts to Run restorecon - Perform remediation of Audit rules
    for /usr/sbin/restorecon
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/restorecon -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/sbin/restorecon -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/restorecon
        -F auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/restorecon -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/sbin/restorecon -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/restorecon
        -F auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_execution_restorecon
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_execution_restorecon:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_execution_restorecon_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_execution_semanage" selected="false" severity="medium">
              <xccdf-1.2:title>Record Any Attempts to Run semanage</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/semanage -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/semanage -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000496-CTR-001240</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000497-CTR-001245</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000498-CTR-001250</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030313</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230429r1017230_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_execution_semanage" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/sbin/semanage"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_execution_semanage" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030313
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_execution_semanage
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Any Attempts to Run semanage - Perform remediation of Audit rules for
    /usr/sbin/semanage
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/semanage -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/sbin/semanage -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/semanage -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/semanage -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/sbin/semanage -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/semanage -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030313
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_execution_semanage
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_execution_semanage:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_execution_semanage_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_execution_setfiles" selected="false" severity="medium">
              <xccdf-1.2:title>Record Any Attempts to Run setfiles</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/setfiles -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/setfiles -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000496-CTR-001240</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000497-CTR-001245</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000498-CTR-001250</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030314</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230430r1017231_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_execution_setfiles" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/sbin/setfiles"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_execution_setfiles" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030314
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_execution_setfiles
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Any Attempts to Run setfiles - Perform remediation of Audit rules for
    /usr/sbin/setfiles
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/setfiles -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/sbin/setfiles -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/setfiles -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/setfiles -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/sbin/setfiles -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/setfiles -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030314
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_execution_setfiles
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_execution_setfiles:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_execution_setfiles_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_execution_setsebool" selected="false" severity="medium">
              <xccdf-1.2:title>Record Any Attempts to Run setsebool</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/setsebool -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/setsebool -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000496-CTR-001240</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000497-CTR-001245</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000498-CTR-001250</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030316</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230432r1017233_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_execution_setsebool" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/sbin/setsebool"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_execution_setsebool" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030316
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_execution_setsebool
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Any Attempts to Run setsebool - Perform remediation of Audit rules
    for /usr/sbin/setsebool
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/setsebool -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/sbin/setsebool -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/setsebool -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/setsebool -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/sbin/setsebool -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/setsebool -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030316
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_execution_setsebool
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_execution_setsebool:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_execution_setsebool_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_execution_seunshare" selected="false" severity="medium">
              <xccdf-1.2:title>Record Any Attempts to Run seunshare</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/seunshare -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/seunshare -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_execution_seunshare" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/sbin/seunshare"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_execution_seunshare" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_execution_seunshare
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Any Attempts to Run seunshare - Perform remediation of Audit rules
    for /usr/sbin/seunshare
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/seunshare -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/sbin/seunshare -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/seunshare -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/seunshare -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/sbin/seunshare -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/seunshare -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_execution_seunshare
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_execution_seunshare:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_execution_seunshare_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_audit_file_deletion_events">
            <xccdf-1.2:title>Record File Deletion Events by User</xccdf-1.2:title>
            <xccdf-1.2:description>At a minimum, the audit system should collect file deletion events
for all users and root. If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following line to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>, setting ARCH to either b32 for 32-bit
system, or having two lines for both b32 and b64 in case your system is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S rmdir,unlink,unlinkat,rename,renameat,renameat2 -F auid&gt;=1000 -F auid!=unset -F key=delete</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file, setting ARCH to either b32 for 32-bit
system, or having two lines for both b32 and b64 in case your system is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S rmdir,unlink,unlinkat,rename,renameat,renameat2 -F auid&gt;=1000 -F auid!=unset -F key=delete</html:pre></xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects File Deletion Events by User</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum the audit system should collect file deletion events
for all users and root. If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following line to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>, setting ARCH to either b32 for 32-bit
system, or having two lines for both b32 and b64 in case your system is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S rmdir,unlink,unlinkat,rename,renameat,renameat2 -F auid&gt;=1000 -F auid!=unset -F key=delete</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file, setting ARCH to either b32 for 32-bit
system, or having two lines for both b32 and b64 in case your system is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S rmdir,unlink,unlinkat,rename,renameat2 -S renameat -F auid&gt;=1000 -F auid!=unset -F key=delete</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule checks for multiple syscalls related to file deletion;
it was written with DISA STIG in mind. Other policies should use a
separate rule for each syscall that needs to be checked. For example:
<html:ul><html:li><html:code>audit_rules_file_deletion_events_rmdir</html:code></html:li><html:li><html:code>audit_rules_file_deletion_events_unlink</html:code></html:li><html:li><html:code>audit_rules_file_deletion_events_unlinkat</html:code></html:li><html:li><html:code>audit_rules_file_deletion_events_rename</html:code></html:li><html:li><html:code>audit_rules_file_deletion_events_renameat</html:code></html:li><html:li><html:code>audit_rules_file_deletion_events_renameat2</html:code></html:li></html:ul></xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.7</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Auditing file deletions will create an audit trail for files that are removed
from the system. The audit trail could aid in system troubleshooting, as well as, detecting
malicious processes that attempt to delete log files to conceal their presence.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_file_deletion_events" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="rmdir unlink unlinkat rename renameat renameat2"
	KEY="delete"
	SYSCALL_GROUPING="rmdir unlink unlinkat rename renameat renameat2"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_file_deletion_events:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_file_deletion_events_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rename" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects File Deletion Events by User - rename</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file deletion events
for all users and root. If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following line to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>, setting ARCH to either b32 for 32-bit
system, or having two lines for both b32 and b64 in case your system is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S rename -F auid&gt;=1000 -F auid!=unset -F key=delete</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file, setting ARCH to either b32 for 32-bit
system, or having two lines for both b32 and b64 in case your system is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S rename -F auid&gt;=1000 -F auid!=unset -F key=delete</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.MA-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000467-GPOS-00211</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000501-CTR-001265</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000502-CTR-001270</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030361</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230439r1017243_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Auditing file deletions will create an audit trail for files that are removed
from the system. The audit trail could aid in system troubleshooting, as well as, detecting
malicious processes that attempt to delete log files to conceal their presence.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_file_deletion_events_rename" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="rename"
	KEY="delete"
	SYSCALL_GROUPING="unlink unlinkat rename renameat renameat2 rmdir"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_file_deletion_events_rename" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_rename
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit rename tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_rename
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for rename for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - rename
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of rename in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/delete.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/delete.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - rename
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of rename in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_rename
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for rename for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - rename
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of rename in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/delete.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/delete.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - rename
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of rename in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_rename
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_file_deletion_events_rename:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_file_deletion_events_rename_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_renameat" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects File Deletion Events by User - renameat</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file deletion events
for all users and root. If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following line to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>, setting ARCH to either b32 for 32-bit
system, or having two lines for both b32 and b64 in case your system is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S renameat -F auid&gt;=1000 -F auid!=unset -F key=delete</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file, setting ARCH to either b32 for 32-bit
system, or having two lines for both b32 and b64 in case your system is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S renameat -F auid&gt;=1000 -F auid!=unset -F key=delete</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.MA-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000467-GPOS-00211</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000501-CTR-001265</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000502-CTR-001270</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030361</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230439r1017243_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Auditing file deletions will create an audit trail for files that are removed
from the system. The audit trail could aid in system troubleshooting, as well as, detecting
malicious processes that attempt to delete log files to conceal their presence.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_file_deletion_events_renameat" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="renameat"
	KEY="delete"
	SYSCALL_GROUPING="unlink unlinkat rename renameat renameat2 rmdir"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_file_deletion_events_renameat" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_renameat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit renameat tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_renameat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for renameat for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - renameat
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of renameat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/delete.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/delete.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - renameat
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of renameat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_renameat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for renameat for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - renameat
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of renameat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/delete.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/delete.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - renameat
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of renameat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_renameat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_file_deletion_events_renameat:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_file_deletion_events_renameat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rmdir" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects File Deletion Events by User - rmdir</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file deletion events
for all users and root. If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following line to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>, setting ARCH to either b32 for 32-bit
system, or having two lines for both b32 and b64 in case your system is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S rmdir -F auid&gt;=1000 -F auid!=unset -F key=delete</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file, setting ARCH to either b32 for 32-bit
system, or having two lines for both b32 and b64 in case your system is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S rmdir -F auid&gt;=1000 -F auid!=unset -F key=delete</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.MA-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000467-GPOS-00211</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000501-CTR-001265</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000502-CTR-001270</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030361</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230439r1017243_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Auditing file deletions will create an audit trail for files that are removed
from the system. The audit trail could aid in system troubleshooting, as well as, detecting
malicious processes that attempt to delete log files to conceal their presence.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_file_deletion_events_rmdir" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="rmdir"
	KEY="delete"
	SYSCALL_GROUPING="unlink unlinkat rename renameat renameat2 rmdir"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_file_deletion_events_rmdir" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_rmdir
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit rmdir tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_rmdir
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for rmdir for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - rmdir
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of rmdir in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/delete.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/delete.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - rmdir
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of rmdir in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_rmdir
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for rmdir for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - rmdir
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of rmdir in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/delete.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/delete.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - rmdir
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of rmdir in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_rmdir
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_file_deletion_events_rmdir:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_file_deletion_events_rmdir_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlink" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects File Deletion Events by User - unlink</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file deletion events
for all users and root. If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following line to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>, setting ARCH to either b32 for 32-bit
system, or having two lines for both b32 and b64 in case your system is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S unlink -F auid&gt;=1000 -F auid!=unset -F key=delete</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file, setting ARCH to either b32 for 32-bit
system, or having two lines for both b32 and b64 in case your system is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S unlink -F auid&gt;=1000 -F auid!=unset -F key=delete</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.MA-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000467-GPOS-00211</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000501-CTR-001265</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000502-CTR-001270</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030361</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230439r1017243_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Auditing file deletions will create an audit trail for files that are removed
from the system. The audit trail could aid in system troubleshooting, as well as, detecting
malicious processes that attempt to delete log files to conceal their presence.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_file_deletion_events_unlink" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="unlink"
	KEY="delete"
	SYSCALL_GROUPING="unlink unlinkat rename renameat renameat2 rmdir"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_file_deletion_events_unlink" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_unlink
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit unlink tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_unlink
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for unlink for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlink
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of unlink in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/delete.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/delete.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlink
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of unlink in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_unlink
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for unlink for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlink
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of unlink in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/delete.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/delete.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlink
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of unlink in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_unlink
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_file_deletion_events_unlink:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlinkat" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects File Deletion Events by User - unlinkat</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file deletion events
for all users and root. If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following line to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>, setting ARCH to either b32 for 32-bit
system, or having two lines for both b32 and b64 in case your system is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S unlinkat -F auid&gt;=1000 -F auid!=unset -F key=delete</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file, setting ARCH to either b32 for 32-bit
system, or having two lines for both b32 and b64 in case your system is 64-bit:
<html:pre>-a always,exit -F arch=ARCH -S unlinkat -F auid&gt;=1000 -F auid!=unset -F key=delete</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.MA-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000467-GPOS-00211</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000501-CTR-001265</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000502-CTR-001270</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030361</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230439r1017243_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Auditing file deletions will create an audit trail for files that are removed
from the system. The audit trail could aid in system troubleshooting, as well as, detecting
malicious processes that attempt to delete log files to conceal their presence.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_file_deletion_events_unlinkat" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="unlinkat"
	KEY="delete"
	SYSCALL_GROUPING="unlink unlinkat rename renameat renameat2 rmdir"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_file_deletion_events_unlinkat" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_unlinkat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit unlinkat tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_unlinkat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for unlinkat for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlinkat
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of unlinkat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/delete.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/delete.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlinkat
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of unlinkat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_unlinkat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for unlinkat for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlinkat
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of unlinkat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/delete.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/delete.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlinkat
      syscall_grouping:
      - unlink
      - unlinkat
      - rename
      - renameat
      - renameat2
      - rmdir

  - name: Check existence of unlinkat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=delete
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030361
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.7
  - audit_rules_file_deletion_events_unlinkat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_file_deletion_events_unlinkat:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_file_deletion_events_unlinkat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_audit_file_modification">
            <xccdf-1.2:title>Record Unauthorized Access Attempts Events to Files (unsuccessful)</xccdf-1.2:title>
            <xccdf-1.2:description>At a minimum, the audit system should collect unauthorized file
accesses for all users and root. Note that the "-F arch=b32" lines should be
present even on a 64 bit system. These commands identify system calls for
auditing. Even if the system is 64 bit it can still execute 32 bit system
calls. Additionally, these rules can be configured in a number of ways while
still achieving the desired effect. An example of this is that the "-S" calls
could be split up and placed on separate lines, however, this is less efficient.
Add the following to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F arch=b32 -S creat,open,openat,open_by_handle_at,truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
    -a always,exit -F arch=b32 -S creat,open,openat,open_by_handle_at,truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>
If your system is 64 bit then these lines should be duplicated and the
arch=b32 replaced with arch=b64 as follows:
<html:pre>-a always,exit -F arch=b64 -S creat,open,openat,open_by_handle_at,truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
    -a always,exit -F arch=b64 -S creat,open,openat,open_by_handle_at,truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre></xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_chmod" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Permission Changes to Files - chmod</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission changes
for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S chmod -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S chmod -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S chmod -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S chmod -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File permission changes could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_chmod_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_chown" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Ownership Changes to Files - chown</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file ownership changes
for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S chown -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S chown -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S chown -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S chown -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File ownership attempts could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_chown_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_creat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Access Attempts to Files - creat</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect unauthorized file
accesses for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S creat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S creat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S creat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S creat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File access attempts could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_creat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_fchmod" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Permission Changes to Files - fchmod</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission changes
for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S fchmod -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fchmod -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S fchmod -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fchmod -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File permission changes could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_fchmod_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_fchmodat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Permission Changes to Files - fchmodat</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission changes
for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S fchmodat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fchmodat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S fchmodat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fchmodat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File permission changes could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_fchmodat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_fchown" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Ownership Changes to Files - fchown</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file ownership changes
for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S fchown -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fchown -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S fchown -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fchown -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File ownership attempts could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_fchown_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_fchownat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Ownership Changes to Files - fchownat</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file ownership changes
for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S fchownat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fchownat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S fchownat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fchownat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File ownership attempts could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_fchownat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_fremovexattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Permission Changes to Files - fremovexattr</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission changes
for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S fremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S fremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File permission changes could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_fremovexattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_fsetxattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Permission Changes to Files - fsetxattr</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission changes
for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S fsetxattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fsetxattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S fsetxattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fsetxattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File permission changes could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_fsetxattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_ftruncate" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Access Attempts to Files - ftruncate</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect unauthorized file
accesses for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S ftruncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S ftruncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S ftruncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S ftruncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File access attempts could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_ftruncate_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_lchown" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Ownership Changes to Files - lchown</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file ownership changes
for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S lchown -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S lchown -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S lchown -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S lchown -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File ownership attempts could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_lchown_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_lremovexattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Permission Changes to Files - lremovexattr</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission changes
for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S lremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S lremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S lremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S lremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File permission changes could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_lremovexattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_lsetxattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Permission Changes to Files - lsetxattr</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission changes
for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S lsetxattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S lsetxattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S lsetxattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S lsetxattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File permission changes could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_lsetxattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_open" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Access Attempts to Files - open</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect unauthorized file
accesses for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S open -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S open -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S open -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S open -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File access attempts could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_open_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_open_by_handle_at" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Access Attempts to Files - open_by_handle_at</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect unauthorized file
accesses for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S open_by_handle_at -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S open_by_handle_at -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S open_by_handle_at -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S open_by_handle_at -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File access attempts could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_open_by_handle_at_o_creat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Creation Attempts to Files - open_by_handle_at O_CREAT</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>open_by_handle_at</html:code> syscall can be used to create new files
when O_CREAT flag is specified.

The following audit rules will assure that successful attempts to create a
file via <html:code>open_by_handle_at</html:code> syscall are collected.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
rules below to a file with suffix <html:code>.rules</html:code> in the directory
<html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the rules below to
<html:code>/etc/audit/audit.rules</html:code> file.

<html:pre>
-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S open_by_handle_at,open_by_handle_at -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:rationale>Successful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_o_creat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_open_by_handle_at_o_trunc_write" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Creation Attempts to Files - open_by_handle_at O_TRUNC_WRITE</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect detailed file access records for
all users and root. The <html:code>open_by_handle_at</html:code> syscall can be used to modify
files if called for write operation with the O_TRUNC_WRITE flag.

The following audit rules will assure that successful attempts to create a
file via <html:code>open_by_handle_at</html:code> syscall are collected.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
rules below to a file with suffix <html:code>.rules</html:code> in the directory
<html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the rules below to
<html:code>/etc/audit/audit.rules</html:code> file.

<html:pre>
-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S open,open_by_handle_at -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:rationale>Successful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_o_trunc_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_open_o_creat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Creation Attempts to Files - open O_CREAT</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>open</html:code> syscall can be used to create new files
when O_CREAT flag is specified.

The following audit rules will assure that successful attempts to create a
file via <html:code>open</html:code> syscall are collected.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
rules below to a file with suffix <html:code>.rules</html:code> in the directory
<html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the rules below to
<html:code>/etc/audit/audit.rules</html:code> file.

<html:pre>
-a always,exit -F arch=b32 -S open -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S open -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S open,open -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:rationale>Successful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_open_o_creat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_open_o_trunc_write" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Creation Attempts to Files - open O_TRUNC_WRITE</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect detailed file access records for
all users and root. The <html:code>open</html:code> syscall can be used to modify
files if called for write operation with the O_TRUNC_WRITE flag.

The following audit rules will assure that successful attempts to create a
file via <html:code>open</html:code> syscall are collected.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
rules below to a file with suffix <html:code>.rules</html:code> in the directory
<html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the rules below to
<html:code>/etc/audit/audit.rules</html:code> file.

<html:pre>
-a always,exit -F arch=b32 -S open -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S open -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S open,openat -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:rationale>Successful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_open_o_trunc_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_openat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Access Attempts to Files - openat</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect unauthorized file
accesses for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S openat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S openat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S openat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S openat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File access attempts could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_openat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_openat_o_creat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Creation Attempts to Files - openat O_CREAT</xccdf-1.2:title>
              <xccdf-1.2:description>The <html:code>openat</html:code> syscall can be used to create new files
when O_CREAT flag is specified.

The following audit rules will assure that successful attempts to create a
file via <html:code>openat</html:code> syscall are collected.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
rules below to a file with suffix <html:code>.rules</html:code> in the directory
<html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the rules below to
<html:code>/etc/audit/audit.rules</html:code> file.

<html:pre>
-a always,exit -F arch=b32 -S openat -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S openat -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:rationale>Successful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_openat_o_creat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_openat_o_trunc_write" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Creation Attempts to Files - openat O_TRUNC_WRITE</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect detailed file access records for
all users and root. The <html:code>openat</html:code> syscall can be used to modify
files if called for write operation with the O_TRUNC_WRITE flag.

The following audit rules will assure that successful attempts to create a
file via <html:code>openat</html:code> syscall are collected.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
rules below to a file with suffix <html:code>.rules</html:code> in the directory
<html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the rules below to
<html:code>/etc/audit/audit.rules</html:code> file.

<html:pre>
-a always,exit -F arch=b32 -S openat -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S openat -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S open,openat -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:rationale>Successful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_openat_o_trunc_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_removexattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Permission Changes to Files - removexattr</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission changes
for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S removexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S removexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S removexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S removexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File permission changes could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_removexattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_rename" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Delete Attempts to Files - rename</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file
deletion for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S rename -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S rename -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S rename -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S rename -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File deletion attempts could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_rename_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_renameat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Delete Attempts to Files - renameat</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file
deletion for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S renameat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S renameat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S renameat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S renameat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File deletion attempts could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_renameat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_setxattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Permission Changes to Files - setxattr</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file permission changes
for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S setxattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S setxattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S setxattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S setxattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File deletion attempts could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_setxattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_truncate" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Access Attempts to Files - truncate</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect unauthorized file
accesses for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S truncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S truncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S truncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S truncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File access attempts could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_truncate_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_unlink" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Delete Attempts to Files - unlink</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file
deletion for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S unlink -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S unlink -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S unlink -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S unlink -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File deletion attempts could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_unlink_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_successful_file_modification_unlinkat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Successful Delete Attempts to Files - unlinkat</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect file
deletion for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-a always,exit -F arch=b32 -S unlinkat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S unlinkat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S unlinkat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S unlinkat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:rationale>File deletion attempts could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_successful_file_modification_unlinkat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Unauthorized Access Attempts to Files (unsuccessful)</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum the audit system should collect unauthorized file
accesses for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S creat,open,openat,open_by_handle_at,truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b32 -S creat,open,openat,open_by_handle_at,truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S creat,open,openat,open_by_handle_at,truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b64 -S creat,open,openat,open_by_handle_at,truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S creat,open,openat,open_by_handle_at,truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b32 -S creat,open,openat,open_by_handle_at,truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S creat,open,openat,open_by_handle_at,truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b64 -S creat,open,openat,open_by_handle_at,truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule checks for multiple syscalls related to unsuccessful file modification;
it was written with DISA STIG in mind. Other policies should use a
separate rule for each syscall that needs to be checked. For example:
<html:ul><html:li><html:code>audit_rules_unsuccessful_file_modification_open</html:code></html:li><html:li><html:code>audit_rules_unsuccessful_file_modification_ftruncate</html:code></html:li><html:li><html:code>audit_rules_unsuccessful_file_modification_creat</html:code></html:li></html:ul></xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# Perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do

	# First fix the -EACCES requirement
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="creat open openat open_by_handle_at truncate ftruncate"
	KEY="access"
	SYSCALL_GROUPING="creat open openat open_by_handle_at truncate ftruncate"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

	# Then fix the -EPERM requirement
	# No need to change content of $GROUP variable - it's the same as for -EACCES case above
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
	SYSCALL="creat open openat open_by_handle_at truncate ftruncate"
	KEY="access"
	SYSCALL_GROUPING="creat open openat open_by_handle_at truncate ftruncate"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_chmod" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Permission Changes to Files - chmod</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect unsuccessful file permission change
attempts for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>-a always,exit -F arch=b32 -S chmod -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b32 -S chmod -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S chmod -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b64 -S chmod -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the audit rule checks a
system call independently of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to change permissions of files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_chmod" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="chmod"
KEY="access"
SYSCALL_GROUPING="chmod fchmod fchmodat fsetxattr lsetxattr setxattr"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_chmod" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_chmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit chmod tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_chmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for chmod EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of chmod in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of chmod in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_chmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for chmod EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of chmod in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of chmod in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_chmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for chmod EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of chmod in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of chmod in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_chmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for chmod EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of chmod in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of chmod in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_chmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_chmod:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_chmod_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_chown" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Ownership Changes to Files - chown</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect unsuccessful file ownership change
attempts for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>-a always,exit -F arch=b32 -S chown -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b32 -S chown -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S chown -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b64 -S chown -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the audit rule checks a
system call independently of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to change ownership of files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_chown" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="chown"
KEY="access"
SYSCALL_GROUPING="chown fchown fchownat lchown"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_chown" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_chown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit chown tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_chown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for chown EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of chown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of chown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_chown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for chown EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of chown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of chown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_chown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for chown EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of chown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of chown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_chown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for chown EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of chown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - chown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of chown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_chown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_chown:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_chown_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_creat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Access Attempts to Files - creat</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect unauthorized file
accesses for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0846</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030420</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230449r1017249_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_creat" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="creat"
KEY="access"
SYSCALL_GROUPING="creat ftruncate truncate open openat open_by_handle_at"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_creat" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_creat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit creat tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_creat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for creat EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - creat
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of creat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - creat
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of creat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_creat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for creat EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - creat
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of creat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - creat
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of creat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_creat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for creat EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - creat
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of creat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - creat
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of creat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_creat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for creat EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - creat
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of creat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - creat
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of creat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_creat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_creat:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_fchmod" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Permission Changes to Files - fchmod</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect unsuccessful file permission change
attempts for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>-a always,exit -F arch=b32 -S fchmod -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b32 -S fchmod -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fchmod -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b64 -S fchmod -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the audit rule checks a
system call independently of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to change permissions of files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_fchmod" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="fchmod"
KEY="access"
SYSCALL_GROUPING="chmod fchmod fchmodat fsetxattr lsetxattr setxattr"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_fchmod" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit fchmod tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchmod EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fchmod in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fchmod in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchmod EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fchmod in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fchmod in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchmod EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fchmod in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fchmod in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchmod EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fchmod in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmod
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fchmod in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchmod
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_fchmod:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_fchmod_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_fchmodat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Permission Changes to Files - fchmodat</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect unsuccessful file permission change
attempts for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>-a always,exit -F arch=b32 -S fchmodat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b32 -S fchmodat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fchmodat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b64 -S fchmodat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the audit rule checks a
system call independently of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to change permissions of files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_fchmodat" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="fchmodat"
KEY="access"
SYSCALL_GROUPING="chmod fchmod fchmodat fsetxattr lsetxattr setxattr"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_fchmodat" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchmodat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit fchmodat tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchmodat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchmodat EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmodat
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fchmodat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmodat
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fchmodat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchmodat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchmodat EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmodat
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fchmodat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmodat
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fchmodat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchmodat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchmodat EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmodat
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fchmodat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmodat
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fchmodat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchmodat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchmodat EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmodat
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fchmodat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchmodat
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fchmodat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchmodat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_fchmodat:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_fchmodat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_fchown" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Ownership Changes to Files - fchown</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect unsuccessful file ownership change
attempts for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>-a always,exit -F arch=b32 -S fchown -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b32 -S fchown -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fchown -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b64 -S fchown -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the audit rule checks a
system call independently of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to change ownership of files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_fchown" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="fchown"
KEY="access"
SYSCALL_GROUPING="chown fchown fchownat lchown"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_fchown" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit fchown tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchown EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchown EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchown EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchown EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_fchown:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_fchown_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_fchownat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Ownership Changes to Files - fchownat</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect unsuccessful file ownership change
attempts for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>-a always,exit -F arch=b32 -S fchownat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b32 -S fchownat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fchownat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b64 -S fchownat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the audit rule checks a
system call independently of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to change ownership of files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_fchownat" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="fchownat"
KEY="access"
SYSCALL_GROUPING="chown fchown fchownat lchown"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_fchownat" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchownat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit fchownat tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchownat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchownat EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchownat
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchownat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchownat
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchownat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchownat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchownat EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchownat
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchownat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchownat
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchownat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchownat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchownat EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchownat
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchownat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchownat
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchownat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchownat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fchownat EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchownat
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchownat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fchownat
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of fchownat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fchownat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_fchownat:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_fchownat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_fremovexattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Permission Changes to Files - fremovexattr</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect unsuccessful file permission change
attempts for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>-a always,exit -F arch=b32 -S fremovexattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b32 -S fremovexattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fremovexattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b64 -S fremovexattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the audit rule checks a
system call independently of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to change permissions of files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_fremovexattr" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="fremovexattr"
KEY="access"
SYSCALL_GROUPING=""

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_fremovexattr" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit fremovexattr tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fremovexattr EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fremovexattr
      syscall_grouping: []

  - name: Check existence of fremovexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fremovexattr
      syscall_grouping: []

  - name: Check existence of fremovexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fremovexattr EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fremovexattr
      syscall_grouping: []

  - name: Check existence of fremovexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fremovexattr
      syscall_grouping: []

  - name: Check existence of fremovexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fremovexattr EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fremovexattr
      syscall_grouping: []

  - name: Check existence of fremovexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fremovexattr
      syscall_grouping: []

  - name: Check existence of fremovexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fremovexattr EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fremovexattr
      syscall_grouping: []

  - name: Check existence of fremovexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fremovexattr
      syscall_grouping: []

  - name: Check existence of fremovexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_fremovexattr:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_fremovexattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_fsetxattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Permission Changes to Files - fsetxattr</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect unsuccessful file permission change
attempts for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>-a always,exit -F arch=b32 -S fsetxattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b32 -S fsetxattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S fsetxattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b64 -S fsetxattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the audit rule checks a
system call independently of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to change permissions of files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_fsetxattr" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="fsetxattr"
KEY="access"
SYSCALL_GROUPING="chmod fchmod fchmodat fsetxattr lsetxattr setxattr"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_fsetxattr" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit fsetxattr tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fsetxattr EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fsetxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fsetxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fsetxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fsetxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fsetxattr EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fsetxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fsetxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fsetxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fsetxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fsetxattr EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fsetxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fsetxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fsetxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fsetxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for fsetxattr EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fsetxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fsetxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - fsetxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of fsetxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_fsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_fsetxattr:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_fsetxattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_ftruncate" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Access Attempts to Files - ftruncate</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect unauthorized file
accesses for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b32 -S ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b64 -S ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b32 -S ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b64 -S ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0846</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030420</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230449r1017249_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_ftruncate" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="ftruncate"
KEY="access"
SYSCALL_GROUPING="creat ftruncate truncate open openat open_by_handle_at"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_ftruncate" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_ftruncate
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit ftruncate tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_ftruncate
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for ftruncate EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - ftruncate
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of ftruncate in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - ftruncate
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of ftruncate in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_ftruncate
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for ftruncate EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - ftruncate
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of ftruncate in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - ftruncate
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of ftruncate in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_ftruncate
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for ftruncate EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - ftruncate
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of ftruncate in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - ftruncate
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of ftruncate in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_ftruncate
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for ftruncate EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - ftruncate
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of ftruncate in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - ftruncate
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of ftruncate in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_ftruncate
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_ftruncate:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_lchown" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Ownership Changes to Files - lchown</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect unsuccessful file ownership change
attempts for all users and root.

If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file.

<html:pre>-a always,exit -F arch=b32 -S lchown -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b32 -S lchown -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S lchown -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b64 -S lchown -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the audit rule checks a
system call independently of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to change ownership of files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_lchown" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="lchown"
KEY="access"
SYSCALL_GROUPING="chown fchown fchownat lchown"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_lchown" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit lchown tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lchown EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of lchown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of lchown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lchown EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of lchown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of lchown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lchown EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of lchown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of lchown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lchown EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of lchown in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lchown
      syscall_grouping:
      - chown
      - fchown
      - fchownat
      - lchown

  - name: Check existence of lchown in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lchown
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_lchown:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_lchown_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_lremovexattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Permission Changes to Files - lremovexattr</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect unsuccessful file permission change
attempts for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>-a always,exit -F arch=b32 -S lremovexattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b32 -S lremovexattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S lremovexattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b64 -S lremovexattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the audit rule checks a
system call independently of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to change permissions of files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_lremovexattr" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="lremovexattr"
KEY="access"
SYSCALL_GROUPING=""

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_lremovexattr" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit lremovexattr tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lremovexattr EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lremovexattr
      syscall_grouping: []

  - name: Check existence of lremovexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lremovexattr
      syscall_grouping: []

  - name: Check existence of lremovexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lremovexattr EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lremovexattr
      syscall_grouping: []

  - name: Check existence of lremovexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lremovexattr
      syscall_grouping: []

  - name: Check existence of lremovexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lremovexattr EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lremovexattr
      syscall_grouping: []

  - name: Check existence of lremovexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lremovexattr
      syscall_grouping: []

  - name: Check existence of lremovexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lremovexattr EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lremovexattr
      syscall_grouping: []

  - name: Check existence of lremovexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lremovexattr
      syscall_grouping: []

  - name: Check existence of lremovexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lremovexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_lremovexattr:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_lremovexattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_lsetxattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Permission Changes to Files - lsetxattr</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect unsuccessful file permission change
attempts for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>-a always,exit -F arch=b32 -S lsetxattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b32 -S lsetxattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S lsetxattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b64 -S lsetxattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the audit rule checks a
system call independently of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to change permissions of files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_lsetxattr" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="lsetxattr"
KEY="access"
SYSCALL_GROUPING="chmod fchmod fchmodat fsetxattr lsetxattr setxattr"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_lsetxattr" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit lsetxattr tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lsetxattr EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lsetxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of lsetxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lsetxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of lsetxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lsetxattr EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lsetxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of lsetxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lsetxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of lsetxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lsetxattr EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lsetxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of lsetxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lsetxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of lsetxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for lsetxattr EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lsetxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of lsetxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - lsetxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of lsetxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_lsetxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_lsetxattr:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_lsetxattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Access Attempts to Files - open</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect unauthorized file
accesses for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S open -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b32 -S open -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S open -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b64 -S open -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S open -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b32 -S open -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S open -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b64 -S open -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0846</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030420</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230449r1017249_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_open" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="open"
KEY="access"
SYSCALL_GROUPING="creat ftruncate truncate open openat open_by_handle_at"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_open" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit open tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of open in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of open in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of open in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of open in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of open in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of open in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of open in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of open in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_open:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_open_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_by_handle_at" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Access Attempts to Files - open_by_handle_at</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect unauthorized file
accesses for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b32 -S open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b64 -S open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S open_by_handle_at,truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b32 -S open_by_handle_at,truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S open_by_handle_at,truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b64 -S open_by_handle_at,truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0846</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030420</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230449r1017249_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_open_by_handle_at" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="open_by_handle_at"
KEY="access"
SYSCALL_GROUPING="creat ftruncate truncate open openat open_by_handle_at"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_open_by_handle_at" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit open_by_handle_at tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open_by_handle_at EACCES for 32bit
    platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of open_by_handle_at in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of open_by_handle_at in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open_by_handle_at EACCES for 64bit
    platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of open_by_handle_at in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of open_by_handle_at in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open_by_handle_at EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of open_by_handle_at in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of open_by_handle_at in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for open_by_handle_at EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of open_by_handle_at in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - open_by_handle_at
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of open_by_handle_at in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open_by_handle_at
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Creation Attempts to Files - open_by_handle_at O_CREAT</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect unauthorized file accesses for
all users and root. The <html:code>open_by_handle_at</html:code> syscall can be used to create new files
when O_CREAT flag is specified.

The following auidt rules will assure that unsuccessful attempts to create a
file via <html:code>open_by_handle_at</html:code> syscall are collected.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
rules below to a file with suffix <html:code>.rules</html:code> in the directory
<html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the rules below to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>
-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

mkdir -p "$(dirname '/etc/audit/rules.d/30-ospp-v42-remediation.rules')"
cat &lt;&lt;EOF &gt; "/etc/audit/rules.d/30-ospp-v42-remediation.rules"
## This content is a section of an Audit config snapshot recommended for linux systems that target OSPP compliance.
## The following content has been retreived on 2019-03-11 from: https://github.com/linux-audit/audit-userspace/blob/master/rules/30-ospp-v42.rules

## The purpose of these rules is to meet the requirements for Operating
## System Protection Profile (OSPP)v4.2. These rules depends on having
## 10-base-config.rules, 11-loginuid.rules, and 43-module-load.rules installed.

## Unsuccessful file creation (open with O_CREAT)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create

## Unsuccessful file modifications (open for write or truncate)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification

## Unsuccessful file access (any other opens) This has to go last.
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
EOF

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Add unsuccessful file operations audit rules
  ansible.builtin.blockinfile:
    path: /etc/audit/rules.d/30-ospp-v42-remediation.rules
    create: true
    block: |-
      ## This content is a section of an Audit config snapshot recommended for AlmaLinux OS 8 systems that target OSPP compliance.
      ## The following content has been retreived on 2019-03-11 from: https://github.com/linux-audit/audit-userspace/blob/master/rules/30-ospp-v42.rules

      ## The purpose of these rules is to meet the requirements for Operating
      ## System Protection Profile (OSPP)v4.2. These rules depends on having
      ## 10-base-config.rules, 11-loginuid.rules, and 43-module-load.rules installed.

      ## Unsuccessful file creation (open with O_CREAT)
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create

      ## Unsuccessful file modifications (open for write or truncate)
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification

      ## Unsuccessful file access (any other opens) This has to go last.
      -a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_by_handle_at_o_trunc_write" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Modification Attempts to Files - open_by_handle_at O_TRUNC_WRITE</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect detailed unauthorized file accesses for
all users and root. The <html:code>open_by_handle_at</html:code> syscall can be used to modify files
if called for write operation of with O_TRUNC_WRITE flag.

The following auidt rules will assure that unsuccessful attempts to modify a
file via <html:code>open_by_handle_at</html:code> syscall are collected.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
rules below to a file with suffix <html:code>.rules</html:code> in the directory
<html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the rules below to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>
-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_open_by_handle_at_o_trunc_write" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

mkdir -p "$(dirname '/etc/audit/rules.d/30-ospp-v42-remediation.rules')"
cat &lt;&lt;EOF &gt; "/etc/audit/rules.d/30-ospp-v42-remediation.rules"
## This content is a section of an Audit config snapshot recommended for linux systems that target OSPP compliance.
## The following content has been retreived on 2019-03-11 from: https://github.com/linux-audit/audit-userspace/blob/master/rules/30-ospp-v42.rules

## The purpose of these rules is to meet the requirements for Operating
## System Protection Profile (OSPP)v4.2. These rules depends on having
## 10-base-config.rules, 11-loginuid.rules, and 43-module-load.rules installed.

## Unsuccessful file creation (open with O_CREAT)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create

## Unsuccessful file modifications (open for write or truncate)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification

## Unsuccessful file access (any other opens) This has to go last.
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
EOF

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_open_by_handle_at_o_trunc_write" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open_by_handle_at_o_trunc_write
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Add unsuccessful file operations audit rules
  ansible.builtin.blockinfile:
    path: /etc/audit/rules.d/30-ospp-v42-remediation.rules
    create: true
    block: |-
      ## This content is a section of an Audit config snapshot recommended for AlmaLinux OS 8 systems that target OSPP compliance.
      ## The following content has been retreived on 2019-03-11 from: https://github.com/linux-audit/audit-userspace/blob/master/rules/30-ospp-v42.rules

      ## The purpose of these rules is to meet the requirements for Operating
      ## System Protection Profile (OSPP)v4.2. These rules depends on having
      ## 10-base-config.rules, 11-loginuid.rules, and 43-module-load.rules installed.

      ## Unsuccessful file creation (open with O_CREAT)
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create

      ## Unsuccessful file modifications (open for write or truncate)
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification

      ## Unsuccessful file access (any other opens) This has to go last.
      -a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open_by_handle_at_o_trunc_write
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_trunc_write:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_trunc_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Unauthorized Access Attempts To open_by_handle_at Are Ordered Correctly</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect detailed unauthorized file
accesses for all users and root.
To correctly identify unsuccessful creation, unsuccessful modification and unsuccessful access
of files via <html:code>open_by_handle_at</html:code> syscall the audit rules collecting these events need to be in certain order.
The more specific rules need to come before the less specific rules. The reason for that is that more
specific rules cover a subset of events covered in the less specific rules, thus, they need to come
before to not be overshadowed by less specific rules, which match a bigger set of events.
Make sure that rules for unsuccessful calls of <html:code>open_by_handle_at</html:code> syscall are in the order shown below.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), check the order of
rules below in a file with suffix <html:code>.rules</html:code> in the directory
<html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, check the order of rules below in
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>
-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b32 -S open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The more specific rules cover a subset of events covered by the less specific rules.
By ordering them from more specific to less specific, it is assured that the less specific
rule will not catch events better recorded by the more specific rule.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

mkdir -p "$(dirname '/etc/audit/rules.d/30-ospp-v42-remediation.rules')"
cat &lt;&lt;EOF &gt; "/etc/audit/rules.d/30-ospp-v42-remediation.rules"
## This content is a section of an Audit config snapshot recommended for linux systems that target OSPP compliance.
## The following content has been retreived on 2019-03-11 from: https://github.com/linux-audit/audit-userspace/blob/master/rules/30-ospp-v42.rules

## The purpose of these rules is to meet the requirements for Operating
## System Protection Profile (OSPP)v4.2. These rules depends on having
## 10-base-config.rules, 11-loginuid.rules, and 43-module-load.rules installed.

## Unsuccessful file creation (open with O_CREAT)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create

## Unsuccessful file modifications (open for write or truncate)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification

## Unsuccessful file access (any other opens) This has to go last.
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
EOF

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_o_creat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Creation Attempts to Files - open O_CREAT</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect unauthorized file accesses for
all users and root. The <html:code>open</html:code> syscall can be used to create new files
when O_CREAT flag is specified.

The following auidt rules will assure that unsuccessful attempts to create a
file via <html:code>open</html:code> syscall are collected.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
rules below to a file with suffix <html:code>.rules</html:code> in the directory
<html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the rules below to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_open_o_creat" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

mkdir -p "$(dirname '/etc/audit/rules.d/30-ospp-v42-remediation.rules')"
cat &lt;&lt;EOF &gt; "/etc/audit/rules.d/30-ospp-v42-remediation.rules"
## This content is a section of an Audit config snapshot recommended for linux systems that target OSPP compliance.
## The following content has been retreived on 2019-03-11 from: https://github.com/linux-audit/audit-userspace/blob/master/rules/30-ospp-v42.rules

## The purpose of these rules is to meet the requirements for Operating
## System Protection Profile (OSPP)v4.2. These rules depends on having
## 10-base-config.rules, 11-loginuid.rules, and 43-module-load.rules installed.

## Unsuccessful file creation (open with O_CREAT)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create

## Unsuccessful file modifications (open for write or truncate)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification

## Unsuccessful file access (any other opens) This has to go last.
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
EOF

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_open_o_creat" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open_o_creat
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Add unsuccessful file operations audit rules
  ansible.builtin.blockinfile:
    path: /etc/audit/rules.d/30-ospp-v42-remediation.rules
    create: true
    block: |-
      ## This content is a section of an Audit config snapshot recommended for AlmaLinux OS 8 systems that target OSPP compliance.
      ## The following content has been retreived on 2019-03-11 from: https://github.com/linux-audit/audit-userspace/blob/master/rules/30-ospp-v42.rules

      ## The purpose of these rules is to meet the requirements for Operating
      ## System Protection Profile (OSPP)v4.2. These rules depends on having
      ## 10-base-config.rules, 11-loginuid.rules, and 43-module-load.rules installed.

      ## Unsuccessful file creation (open with O_CREAT)
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create

      ## Unsuccessful file modifications (open for write or truncate)
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification

      ## Unsuccessful file access (any other opens) This has to go last.
      -a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open_o_creat
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_open_o_creat:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_creat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_o_trunc_write" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Modification Attempts to Files - open O_TRUNC_WRITE</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect detailed unauthorized file accesses for
all users and root. The <html:code>open</html:code> syscall can be used to modify files
if called for write operation of with O_TRUNC_WRITE flag.
The following auidt rules will assure that unsuccessful attempts to modify a
file via <html:code>open</html:code> syscall are collected.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
rules below to a file with suffix <html:code>.rules</html:code> in the directory
<html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the rules below to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_open_o_trunc_write" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

mkdir -p "$(dirname '/etc/audit/rules.d/30-ospp-v42-remediation.rules')"
cat &lt;&lt;EOF &gt; "/etc/audit/rules.d/30-ospp-v42-remediation.rules"
## This content is a section of an Audit config snapshot recommended for linux systems that target OSPP compliance.
## The following content has been retreived on 2019-03-11 from: https://github.com/linux-audit/audit-userspace/blob/master/rules/30-ospp-v42.rules

## The purpose of these rules is to meet the requirements for Operating
## System Protection Profile (OSPP)v4.2. These rules depends on having
## 10-base-config.rules, 11-loginuid.rules, and 43-module-load.rules installed.

## Unsuccessful file creation (open with O_CREAT)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create

## Unsuccessful file modifications (open for write or truncate)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification

## Unsuccessful file access (any other opens) This has to go last.
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
EOF

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_open_o_trunc_write" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open_o_trunc_write
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Add unsuccessful file operations audit rules
  ansible.builtin.blockinfile:
    path: /etc/audit/rules.d/30-ospp-v42-remediation.rules
    create: true
    block: |-
      ## This content is a section of an Audit config snapshot recommended for AlmaLinux OS 8 systems that target OSPP compliance.
      ## The following content has been retreived on 2019-03-11 from: https://github.com/linux-audit/audit-userspace/blob/master/rules/30-ospp-v42.rules

      ## The purpose of these rules is to meet the requirements for Operating
      ## System Protection Profile (OSPP)v4.2. These rules depends on having
      ## 10-base-config.rules, 11-loginuid.rules, and 43-module-load.rules installed.

      ## Unsuccessful file creation (open with O_CREAT)
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create

      ## Unsuccessful file modifications (open for write or truncate)
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification

      ## Unsuccessful file access (any other opens) This has to go last.
      -a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_open_o_trunc_write
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_open_o_trunc_write:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_trunc_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_rule_order" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Rules For Unauthorized Attempts To open Are Ordered Correctly</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect detailed unauthorized file
accesses for all users and root.
To correctly identify unsuccessful creation, unsuccessful modification and unsuccessful access
of files via <html:code>open</html:code> syscall the audit rules collecting these events need to be in certain order.
The more specific rules need to come before the less specific rules. The reason for that is that more
specific rules cover a subset of events covered in the less specific rules, thus, they need to come
before to not be overshadowed by less specific rules, which match a bigger set of events.
Make sure that rules for unsuccessful calls of <html:code>open</html:code> syscall are in the order shown below.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), check the order of
rules below in a file with suffix <html:code>.rules</html:code> in the directory
<html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, check the order of rules below in
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b32 -S open -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The more specific rules cover a subset of events covered by the less specific rules.
By ordering them from more specific to less specific, it is assured that the less specific
rule will not catch events better recorded by the more specific rule.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_open_rule_order" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

mkdir -p "$(dirname '/etc/audit/rules.d/30-ospp-v42-remediation.rules')"
cat &lt;&lt;EOF &gt; "/etc/audit/rules.d/30-ospp-v42-remediation.rules"
## This content is a section of an Audit config snapshot recommended for linux systems that target OSPP compliance.
## The following content has been retreived on 2019-03-11 from: https://github.com/linux-audit/audit-userspace/blob/master/rules/30-ospp-v42.rules

## The purpose of these rules is to meet the requirements for Operating
## System Protection Profile (OSPP)v4.2. These rules depends on having
## 10-base-config.rules, 11-loginuid.rules, and 43-module-load.rules installed.

## Unsuccessful file creation (open with O_CREAT)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create

## Unsuccessful file modifications (open for write or truncate)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification

## Unsuccessful file access (any other opens) This has to go last.
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
EOF

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_open_rule_order:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_open_rule_order_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_openat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Access Attempts to Files - openat</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect unauthorized file
accesses for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S openat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b32 -S openat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S openat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b64 -S openat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S openat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b32 -S openat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S openat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b64 -S openat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0846</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030420</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230449r1017249_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_openat" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="openat"
KEY="access"
SYSCALL_GROUPING="creat ftruncate truncate open openat open_by_handle_at"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_openat" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit openat tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for openat EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of openat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of openat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for openat EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of openat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of openat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for openat EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of openat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of openat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for openat EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of openat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - openat
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of openat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_openat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_openat:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_openat_o_creat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Creation Attempts to Files - openat O_CREAT</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect unauthorized file accesses for
all users and root. The <html:code>openat</html:code> syscall can be used to create new files
when O_CREAT flag is specified.

The following auidt rules will assure that unsuccessful attempts to create a
file via <html:code>openat</html:code> syscall are collected.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
rules below to a file with suffix <html:code>.rules</html:code> in the directory
<html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the rules below to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>
-a always,exit -F arch=b32 -S openat -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S openat -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S openat -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_openat_o_creat" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

mkdir -p "$(dirname '/etc/audit/rules.d/30-ospp-v42-remediation.rules')"
cat &lt;&lt;EOF &gt; "/etc/audit/rules.d/30-ospp-v42-remediation.rules"
## This content is a section of an Audit config snapshot recommended for linux systems that target OSPP compliance.
## The following content has been retreived on 2019-03-11 from: https://github.com/linux-audit/audit-userspace/blob/master/rules/30-ospp-v42.rules

## The purpose of these rules is to meet the requirements for Operating
## System Protection Profile (OSPP)v4.2. These rules depends on having
## 10-base-config.rules, 11-loginuid.rules, and 43-module-load.rules installed.

## Unsuccessful file creation (open with O_CREAT)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create

## Unsuccessful file modifications (open for write or truncate)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification

## Unsuccessful file access (any other opens) This has to go last.
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
EOF

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_openat_o_creat" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_openat_o_creat
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Add unsuccessful file operations audit rules
  ansible.builtin.blockinfile:
    path: /etc/audit/rules.d/30-ospp-v42-remediation.rules
    create: true
    block: |-
      ## This content is a section of an Audit config snapshot recommended for AlmaLinux OS 8 systems that target OSPP compliance.
      ## The following content has been retreived on 2019-03-11 from: https://github.com/linux-audit/audit-userspace/blob/master/rules/30-ospp-v42.rules

      ## The purpose of these rules is to meet the requirements for Operating
      ## System Protection Profile (OSPP)v4.2. These rules depends on having
      ## 10-base-config.rules, 11-loginuid.rules, and 43-module-load.rules installed.

      ## Unsuccessful file creation (open with O_CREAT)
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create

      ## Unsuccessful file modifications (open for write or truncate)
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification

      ## Unsuccessful file access (any other opens) This has to go last.
      -a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_openat_o_creat
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_openat_o_creat:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_creat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_openat_o_trunc_write" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Modification Attempts to Files - openat O_TRUNC_WRITE</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect detailed unauthorized file accesses for
all users and root. The <html:code>openat</html:code> syscall can be used to modify files
if called for write operation of with O_TRUNC_WRITE flag.

The following auidt rules will assure that unsuccessful attempts to modify a
file via <html:code>openat</html:code> syscall are collected.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
rules below to a file with suffix <html:code>.rules</html:code> in the directory
<html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the rules below to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>
-a always,exit -F arch=b32 -S openat -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S openat -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S openat -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_openat_o_trunc_write" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

mkdir -p "$(dirname '/etc/audit/rules.d/30-ospp-v42-remediation.rules')"
cat &lt;&lt;EOF &gt; "/etc/audit/rules.d/30-ospp-v42-remediation.rules"
## This content is a section of an Audit config snapshot recommended for linux systems that target OSPP compliance.
## The following content has been retreived on 2019-03-11 from: https://github.com/linux-audit/audit-userspace/blob/master/rules/30-ospp-v42.rules

## The purpose of these rules is to meet the requirements for Operating
## System Protection Profile (OSPP)v4.2. These rules depends on having
## 10-base-config.rules, 11-loginuid.rules, and 43-module-load.rules installed.

## Unsuccessful file creation (open with O_CREAT)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create

## Unsuccessful file modifications (open for write or truncate)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification

## Unsuccessful file access (any other opens) This has to go last.
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
EOF

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_openat_o_trunc_write" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_openat_o_trunc_write
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Add unsuccessful file operations audit rules
  ansible.builtin.blockinfile:
    path: /etc/audit/rules.d/30-ospp-v42-remediation.rules
    create: true
    block: |-
      ## This content is a section of an Audit config snapshot recommended for AlmaLinux OS 8 systems that target OSPP compliance.
      ## The following content has been retreived on 2019-03-11 from: https://github.com/linux-audit/audit-userspace/blob/master/rules/30-ospp-v42.rules

      ## The purpose of these rules is to meet the requirements for Operating
      ## System Protection Profile (OSPP)v4.2. These rules depends on having
      ## 10-base-config.rules, 11-loginuid.rules, and 43-module-load.rules installed.

      ## Unsuccessful file creation (open with O_CREAT)
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      -a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create

      ## Unsuccessful file modifications (open for write or truncate)
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
      -a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification

      ## Unsuccessful file access (any other opens) This has to go last.
      -a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_openat_o_trunc_write
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_openat_o_trunc_write:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_trunc_write_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_openat_rule_order" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Rules For Unauthorized Attempts To openat Are Ordered Correctly</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect detailed unauthorized file
accesses for all users and root.
To correctly identify unsuccessful creation, unsuccessful modification and unsuccessful access
of files via <html:code>openat</html:code> syscall the audit rules collecting these events need to be in certain order.
The more specific rules need to come before the less specific rules. The reason for that is that more
specific rules cover a subset of events covered in the less specific rules, thus, they need to come
before to not be overshadowed by less specific rules, which match a bigger set of events.
Make sure that rules for unsuccessful calls of <html:code>openat</html:code> syscall are in the order shown below.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), check the order of
rules below in a file with suffix <html:code>.rules</html:code> in the directory
<html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, check the order of rules below in
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>
-a always,exit -F arch=b32 -S openat -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S openat -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S openat -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S openat -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S openat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b32 -S openat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S openat -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S openat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The more specific rules cover a subset of events covered by the less specific rules.
By ordering them from more specific to less specific, it is assured that the less specific
rule will not catch events better recorded by the more specific rule.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_openat_rule_order" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

mkdir -p "$(dirname '/etc/audit/rules.d/30-ospp-v42-remediation.rules')"
cat &lt;&lt;EOF &gt; "/etc/audit/rules.d/30-ospp-v42-remediation.rules"
## This content is a section of an Audit config snapshot recommended for linux systems that target OSPP compliance.
## The following content has been retreived on 2019-03-11 from: https://github.com/linux-audit/audit-userspace/blob/master/rules/30-ospp-v42.rules

## The purpose of these rules is to meet the requirements for Operating
## System Protection Profile (OSPP)v4.2. These rules depends on having
## 10-base-config.rules, 11-loginuid.rules, and 43-module-load.rules installed.

## Unsuccessful file creation (open with O_CREAT)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create

## Unsuccessful file modifications (open for write or truncate)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification

## Unsuccessful file access (any other opens) This has to go last.
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b32 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
-a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
EOF

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_openat_rule_order:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_rule_order_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_removexattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Permission Changes to Files - removexattr</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect unsuccessful file permission change
attempts for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>-a always,exit -F arch=b32 -S removexattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b32 -S removexattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S removexattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b64 -S removexattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the audit rule checks a
system call independently of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to change permissions of files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_removexattr" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="removexattr"
KEY="access"
SYSCALL_GROUPING=""

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_removexattr" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_removexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit removexattr tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_removexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for removexattr EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - removexattr
      syscall_grouping: []

  - name: Check existence of removexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - removexattr
      syscall_grouping: []

  - name: Check existence of removexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_removexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for removexattr EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - removexattr
      syscall_grouping: []

  - name: Check existence of removexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - removexattr
      syscall_grouping: []

  - name: Check existence of removexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_removexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for removexattr EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - removexattr
      syscall_grouping: []

  - name: Check existence of removexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - removexattr
      syscall_grouping: []

  - name: Check existence of removexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_removexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for removexattr EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - removexattr
      syscall_grouping: []

  - name: Check existence of removexattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - removexattr
      syscall_grouping: []

  - name: Check existence of removexattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_removexattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_removexattr:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_removexattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_rename" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Delete Attempts to Files - rename</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect unsuccessful file deletion
attempts for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>-a always,exit -F arch=b32 -S rename -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b32 -S rename -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S rename -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b64 -S rename -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-delete</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000501-CTR-001265</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000502-CTR-001270</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to delete files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_rename" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="rename"
KEY="access"
SYSCALL_GROUPING="rename renameat unlink unlinkat"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_rename" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_rename
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit rename tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_rename
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for rename EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - rename
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of rename in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - rename
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of rename in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_rename
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for rename EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - rename
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of rename in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - rename
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of rename in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_rename
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for rename EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - rename
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of rename in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - rename
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of rename in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_rename
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for rename EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - rename
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of rename in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - rename
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of rename in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_rename
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_rename:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_rename_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_renameat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Delete Attempts to Files - renameat</xccdf-1.2:title>
              <xccdf-1.2:description>
The audit system should collect unsuccessful file deletion
attempts for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>-a always,exit -F arch=b32 -S renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b32 -S renameat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b64 -S renameat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:

<html:pre>-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-delete</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000501-CTR-001265</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000502-CTR-001270</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to delete files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_renameat" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="renameat"
KEY="access"
SYSCALL_GROUPING="rename renameat unlink unlinkat"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_renameat" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_renameat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit renameat tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_renameat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for renameat EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - renameat
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of renameat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - renameat
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of renameat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_renameat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for renameat EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - renameat
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of renameat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - renameat
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of renameat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_renameat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for renameat EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - renameat
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of renameat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - renameat
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of renameat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_renameat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for renameat EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - renameat
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of renameat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - renameat
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of renameat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_renameat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_renameat:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_renameat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_setxattr" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Permission Changes to Files - setxattr</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect unsuccessful file permission change
attempts for all users and root.
If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>-a always,exit -F arch=b32 -S setxattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b32 -S setxattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre>
If the system is 64 bit then also add the following lines:
<html:pre>-a always,exit -F arch=b64 -S setxattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change
-a always,exit -F arch=b64 -S setxattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the audit rule checks a
system call independently of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:
<html:pre>-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-perm-change</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to change permissions of files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_setxattr" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="setxattr"
KEY="access"
SYSCALL_GROUPING="chmod fchmod fchmodat fsetxattr lsetxattr setxattr"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_setxattr" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_setxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit setxattr tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_setxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for setxattr EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - setxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of setxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - setxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of setxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_setxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for setxattr EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - setxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of setxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - setxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of setxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_setxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for setxattr EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - setxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of setxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - setxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of setxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_setxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for setxattr EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - setxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of setxattr in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - setxattr
      syscall_grouping:
      - chmod
      - fchmod
      - fchmodat
      - fsetxattr
      - lsetxattr
      - setxattr

  - name: Check existence of setxattr in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_unsuccessful_file_modification_setxattr
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_setxattr:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_setxattr_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_truncate" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Access Attempts to Files - truncate</xccdf-1.2:title>
              <xccdf-1.2:description>At a minimum, the audit system should collect unauthorized file
accesses for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S truncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b32 -S truncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S truncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b64 -S truncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S truncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b32 -S truncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S truncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=access
-a always,exit -F arch=b64 -S truncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=access</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping these system
calls with others as identifying earlier in this guide is more efficient.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0846</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030420</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230449r1017249_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to access files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_truncate" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="truncate"
KEY="access"
SYSCALL_GROUPING="creat ftruncate truncate open openat open_by_handle_at"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_truncate" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_truncate
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit truncate tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_truncate
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for truncate EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - truncate
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of truncate in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - truncate
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of truncate in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_truncate
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for truncate EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - truncate
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of truncate in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - truncate
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of truncate in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_truncate
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for truncate EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - truncate
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of truncate in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - truncate
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of truncate in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_truncate
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for truncate EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - truncate
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of truncate in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - truncate
      syscall_grouping:
      - creat
      - ftruncate
      - truncate
      - open
      - openat
      - open_by_handle_at

  - name: Check existence of truncate in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030420
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_truncate
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_truncate:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_unlink" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Delete Attempts to Files - unlink</xccdf-1.2:title>
              <xccdf-1.2:description>
The audit system should collect unsuccessful file deletion
attempts for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>-a always,exit -F arch=b32 -S unlink -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b32 -S unlink -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S unlink -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b64 -S unlink -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:

<html:pre>-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-delete</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000501-CTR-001265</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000502-CTR-001270</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to delete files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_unlink" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="unlink"
KEY="access"
SYSCALL_GROUPING="rename renameat unlink unlinkat"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_unlink" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_unlink
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit unlink tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_unlink
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for unlink EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlink
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of unlink in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlink
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of unlink in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_unlink
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for unlink EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlink
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of unlink in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlink
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of unlink in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_unlink
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for unlink EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlink
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of unlink in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlink
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of unlink in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_unlink
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for unlink EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlink
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of unlink in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlink
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of unlink in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_unlink
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_unlink:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_unlinkat" selected="false" severity="medium">
              <xccdf-1.2:title>Record Unsuccessful Delete Attempts to Files - unlinkat</xccdf-1.2:title>
              <xccdf-1.2:description>
The audit system should collect unsuccessful file deletion
attempts for all users and root. If the <html:code>auditd</html:code> daemon is configured
to use the <html:code>augenrules</html:code> program to read audit rules during daemon
startup (the default), add the following lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file.
<html:pre>-a always,exit -F arch=b32 -S unlinkat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b32 -S unlinkat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete</html:pre>

If the system is 64 bit then also add the following lines:
<html:pre>
-a always,exit -F arch=b64 -S unlinkat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b64 -S unlinkat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">Note that these rules can be configured in a
number of ways while still achieving the desired effect. Here the system calls
have been placed independent of other system calls. Grouping system calls related
to the same event is more efficient. See the following example:

<html:pre>-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-delete</html:pre></xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000501-CTR-001265</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000502-CTR-001270</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Unsuccessful attempts to delete files could be an indicator of malicious activity on a system. Auditing
these events could serve as evidence of potential system compromise.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_unsuccessful_file_modification_unlinkat" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL="unlinkat"
KEY="access"
SYSCALL_GROUPING="rename renameat unlink unlinkat"

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EACCES"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F exit=-EPERM"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_unsuccessful_file_modification_unlinkat" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_unlinkat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit unlinkat tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_unlinkat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for unlinkat EACCES for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlinkat
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of unlinkat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlinkat
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of unlinkat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_unlinkat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for unlinkat EACCES for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlinkat
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of unlinkat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlinkat
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of unlinkat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EACCES
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_unlinkat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for unlinkat EPERM for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlinkat
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of unlinkat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlinkat
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of unlinkat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_unlinkat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for unlinkat EPERM for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlinkat
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of unlinkat in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/access.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/access.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - unlinkat
      syscall_grouping:
      - rename
      - renameat
      - unlink
      - unlinkat

  - name: Check existence of unlinkat in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F exit=-EPERM
        -F auid&gt;=1000 -F auid!=unset -F key=access
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.1
  - PCI-DSS-Req-10.2.4
  - audit_rules_unsuccessful_file_modification_unlinkat
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_unsuccessful_file_modification_unlinkat:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_unsuccessful_file_modification_unlinkat_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_audit_kernel_module_loading">
            <xccdf-1.2:title>Record Information on Kernel Modules Loading and Unloading</xccdf-1.2:title>
            <xccdf-1.2:description>To capture kernel module loading and unloading events, use following lines, setting ARCH to
either b32 for 32-bit system, or having two lines for both b32 and b64 in case your system is 64-bit:
<html:pre>
-a always,exit -F arch=<html:i>ARCH</html:i> -S init_module,delete_module -F key=modules
</html:pre>

Place to add the lines depends on a way <html:code>auditd</html:code> daemon is configured. If it is configured
to use the <html:code>augenrules</html:code> program (the default), add the lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code> utility,
add the lines to file <html:code>/etc/audit/audit.rules</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on Kernel Module Loading and Unloading</xccdf-1.2:title>
              <xccdf-1.2:description>To capture kernel module loading and unloading events, use following lines, setting ARCH to
either b32 for 32-bit system, or having two lines for both b32 and b64 in case your system is 64-bit:
<html:pre>
-a always,exit -F arch=<html:i>ARCH</html:i> -S init_module,finit_module,delete_module -F key=modules
</html:pre>

The place to add the lines depends on a way <html:code>auditd</html:code> daemon is configured. If it is configured
to use the <html:code>augenrules</html:code> program (the default), add the lines to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code> utility,
add the lines to file <html:code>/etc/audit/audit.rules</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The addition/removal of kernel modules can be used to alter the behavior of
the kernel and potentially introduce malicious code into kernel space. It is important
to have an audit trail of modules that have been introduced into the kernel.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_kernel_module_loading" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
# Note: 32-bit and 64-bit kernel syscall numbers not always line up =&gt;
#       it's required on a 64-bit system to check also for the presence
#       of 32-bit's equivalent of the corresponding rule.
#       (See `man 7 audit.rules` for details )
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
        ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
        OTHER_FILTERS=""
        
        AUID_FILTERS=""
        
        SYSCALL="init_module finit_module delete_module"
        KEY="modules"
        SYSCALL_GROUPING="init_module finit_module delete_module"
        # Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
        unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
        unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_kernel_module_loading" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - audit_rules_kernel_module_loading
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Set architecture for audit tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - audit_rules_kernel_module_loading
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for kernel module loading for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - init_module
      - delete_module
      - finit_module
      syscall_grouping:
      - init_module
      - delete_module
      - finit_module

  - name: Check existence of init_module, delete_module, finit_module in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modules.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modules.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - init_module
      - delete_module
      - finit_module
      syscall_grouping:
      - init_module
      - delete_module
      - finit_module

  - name: Check existence of init_module, delete_module, finit_module in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - audit_rules_kernel_module_loading
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy

- name: Perform remediation of Audit rules for kernel module loading for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - init_module
      - delete_module
      - finit_module
      syscall_grouping:
      - init_module
      - delete_module
      - finit_module

  - name: Check existence of init_module, delete_module, finit_module in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modules.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modules.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - init_module
      - delete_module
      - finit_module
      syscall_grouping:
      - init_module
      - delete_module
      - finit_module

  - name: Check existence of init_module, delete_module, finit_module in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - audit_rules_kernel_module_loading
  - low_complexity
  - low_disruption
  - medium_severity
  - reboot_required
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_kernel_module_loading:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_create" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on Kernel Module Unloading - create_module</xccdf-1.2:title>
              <xccdf-1.2:description>
To capture kernel module loading and unloading events, use the following line, setting ARCH to
either b32 for 32-bit system, or having two lines for both b32 and b64 in case your system is 64-bit:

<html:pre>-a always,exit -F arch=<html:i>ARCH</html:i> -S create_module -F key=modules</html:pre>


Place to add the line depends on a way <html:code>auditd</html:code> daemon is configured. If it is configured
to use the <html:code>augenrules</html:code> program (the default), add the line to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code> utility,
add the line to file <html:code>/etc/audit/audit.rules</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00216</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000477-GPOS-00222</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.19</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The removal of kernel modules can be used to alter the behavior of
the kernel and potentially introduce malicious code into kernel space. It is important
to have an audit trail of modules that have been introduced into the kernel.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_kernel_module_loading_create" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
# Note: 32-bit and 64-bit kernel syscall numbers not always line up =&gt;
#       it's required on a 64-bit system to check also for the presence
#       of 32-bit's equivalent of the corresponding rule.
#       (See `man 7 audit.rules` for details )
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	
	AUID_FILTERS=""
	
	SYSCALL="create_module"
	KEY="modules"
	SYSCALL_GROUPING="create_module delete_module finit_module init_module query_module"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_kernel_module_loading_create" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - audit_rules_kernel_module_loading_create
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on Kernel Module Unloading - create_module
    - Set architecture for audit ['create_module'] tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - audit_rules_kernel_module_loading_create
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on Kernel Module Unloading - create_module
    - Perform remediation of Audit rules for ['create_module'] for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - create_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of create_module in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modules.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modules.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - create_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of create_module in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - audit_rules_kernel_module_loading_create
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on Kernel Module Unloading - create_module
    - Perform remediation of Audit rules for ['create_module'] for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - create_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of create_module in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modules.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modules.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - create_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of create_module in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - audit_rules_kernel_module_loading_create
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_kernel_module_loading_create:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_kernel_module_loading_create_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_delete" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on Kernel Module Unloading - delete_module</xccdf-1.2:title>
              <xccdf-1.2:description>
To capture kernel module loading and unloading events, use the following line, setting ARCH to
either b32 for 32-bit system, or having two lines for both b32 and b64 in case your system is 64-bit:

<html:pre>-a always,exit -F arch=<html:i>ARCH</html:i> -S delete_module -F key=modules</html:pre>


Place to add the line depends on a way <html:code>auditd</html:code> daemon is configured. If it is configured
to use the <html:code>augenrules</html:code> program (the default), add the line to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code> utility,
add the line to file <html:code>/etc/audit/audit.rules</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00216</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000477-GPOS-00222</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000504-CTR-001280</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030390</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230446r1017245_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The removal of kernel modules can be used to alter the behavior of
the kernel and potentially introduce malicious code into kernel space. It is important
to have an audit trail of modules that have been introduced into the kernel.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_kernel_module_loading_delete" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
# Note: 32-bit and 64-bit kernel syscall numbers not always line up =&gt;
#       it's required on a 64-bit system to check also for the presence
#       of 32-bit's equivalent of the corresponding rule.
#       (See `man 7 audit.rules` for details )
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	
	AUID_FILTERS=""
	
	SYSCALL="delete_module"
	KEY="modules"
	SYSCALL_GROUPING="create_module delete_module finit_module init_module query_module"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_kernel_module_loading_delete" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030390
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - audit_rules_kernel_module_loading_delete
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on Kernel Module Unloading - delete_module
    - Set architecture for audit ['delete_module'] tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - DISA-STIG-RHEL-08-030390
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - audit_rules_kernel_module_loading_delete
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on Kernel Module Unloading - delete_module
    - Perform remediation of Audit rules for ['delete_module'] for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - delete_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of delete_module in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modules.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modules.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - delete_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of delete_module in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030390
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - audit_rules_kernel_module_loading_delete
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on Kernel Module Unloading - delete_module
    - Perform remediation of Audit rules for ['delete_module'] for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - delete_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of delete_module in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modules.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modules.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - delete_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of delete_module in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030390
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - audit_rules_kernel_module_loading_delete
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_kernel_module_loading_delete:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_kernel_module_loading_delete_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_finit" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on Kernel Module Loading and Unloading - finit_module</xccdf-1.2:title>
              <xccdf-1.2:description>
To capture kernel module loading and unloading events, use the following line, setting ARCH to
either b32 for 32-bit system, or having two lines for both b32 and b64 in case your system is 64-bit:

<html:pre>-a always,exit -F arch=<html:i>ARCH</html:i> -S finit_module -F key=modules</html:pre>


Place to add the line depends on a way <html:code>auditd</html:code> daemon is configured. If it is configured
to use the <html:code>augenrules</html:code> program (the default), add the line to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code> utility,
add the line to file <html:code>/etc/audit/audit.rules</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00216</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000477-GPOS-00222</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000504-CTR-001280</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030360</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230438r1017241_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The addition/removal of kernel modules can be used to alter the behavior of
the kernel and potentially introduce malicious code into kernel space. It is important
to have an audit trail of modules that have been introduced into the kernel.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_kernel_module_loading_finit" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
# Note: 32-bit and 64-bit kernel syscall numbers not always line up =&gt;
#       it's required on a 64-bit system to check also for the presence
#       of 32-bit's equivalent of the corresponding rule.
#       (See `man 7 audit.rules` for details )
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	
	AUID_FILTERS=""
	
	SYSCALL="finit_module"
	KEY="modules"
	SYSCALL_GROUPING="create_module delete_module finit_module init_module query_module"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_kernel_module_loading_finit" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030360
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - audit_rules_kernel_module_loading_finit
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on Kernel Module Loading and Unloading
    - finit_module - Set architecture for audit ['finit_module'] tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - DISA-STIG-RHEL-08-030360
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - audit_rules_kernel_module_loading_finit
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on Kernel Module Loading and Unloading
    - finit_module - Perform remediation of Audit rules for ['finit_module'] for 32bit
    platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - finit_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of finit_module in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modules.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modules.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - finit_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of finit_module in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030360
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - audit_rules_kernel_module_loading_finit
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on Kernel Module Loading and Unloading
    - finit_module - Perform remediation of Audit rules for ['finit_module'] for 64bit
    platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - finit_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of finit_module in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modules.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modules.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - finit_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of finit_module in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030360
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - audit_rules_kernel_module_loading_finit
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_kernel_module_loading_finit:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_kernel_module_loading_finit_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_init" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on Kernel Module Loading - init_module</xccdf-1.2:title>
              <xccdf-1.2:description>
To capture kernel module loading and unloading events, use the following line, setting ARCH to
either b32 for 32-bit system, or having two lines for both b32 and b64 in case your system is 64-bit:

<html:pre>-a always,exit -F arch=<html:i>ARCH</html:i> -S init_module -F key=modules</html:pre>


Place to add the line depends on a way <html:code>auditd</html:code> daemon is configured. If it is configured
to use the <html:code>augenrules</html:code> program (the default), add the line to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code> utility,
add the line to file <html:code>/etc/audit/audit.rules</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00216</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000477-GPOS-00222</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000504-CTR-001280</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030360</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230438r1017241_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The addition of kernel modules can be used to alter the behavior of
the kernel and potentially introduce malicious code into kernel space. It is important
to have an audit trail of modules that have been introduced into the kernel.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_kernel_module_loading_init" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
# Note: 32-bit and 64-bit kernel syscall numbers not always line up =&gt;
#       it's required on a 64-bit system to check also for the presence
#       of 32-bit's equivalent of the corresponding rule.
#       (See `man 7 audit.rules` for details )
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	
	AUID_FILTERS=""
	
	SYSCALL="init_module"
	KEY="modules"
	SYSCALL_GROUPING="create_module delete_module finit_module init_module query_module"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_kernel_module_loading_init" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030360
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - audit_rules_kernel_module_loading_init
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on Kernel Module Loading - init_module
    - Set architecture for audit ['init_module'] tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - DISA-STIG-RHEL-08-030360
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - audit_rules_kernel_module_loading_init
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on Kernel Module Loading - init_module
    - Perform remediation of Audit rules for ['init_module'] for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - init_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of init_module in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modules.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modules.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - init_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of init_module in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030360
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - audit_rules_kernel_module_loading_init
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on Kernel Module Loading - init_module
    - Perform remediation of Audit rules for ['init_module'] for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - init_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of init_module in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modules.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modules.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - init_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of init_module in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - DISA-STIG-RHEL-08-030360
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.7
  - audit_rules_kernel_module_loading_init
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_kernel_module_loading_init:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_query" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on Kernel Module Loading and Unloading - query_module</xccdf-1.2:title>
              <xccdf-1.2:description>
To capture kernel module loading and unloading events, use the following line, setting ARCH to
either b32 for 32-bit system, or having two lines for both b32 and b64 in case your system is 64-bit:

<html:pre>-a always,exit -F arch=<html:i>ARCH</html:i> -S query_module -F key=modules</html:pre>


Place to add the line depends on a way <html:code>auditd</html:code> daemon is configured. If it is configured
to use the <html:code>augenrules</html:code> program (the default), add the line to a file with suffix
<html:code>.rules</html:code> in the directory <html:code>/etc/audit/rules.d</html:code>.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code> utility,
add the line to file <html:code>/etc/audit/audit.rules</html:code>.</xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.19</xccdf-1.2:reference>
              <xccdf-1.2:rationale>The addition/removal of kernel modules can be used to alter the behavior of
the kernel and potentially introduce malicious code into kernel space. It is important
to have an audit trail of modules that have been introduced into the kernel.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch"/>
              <xccdf-1.2:fix id="audit_rules_kernel_module_loading_query" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) ); }; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
# Note: 32-bit and 64-bit kernel syscall numbers not always line up =&gt;
#       it's required on a 64-bit system to check also for the presence
#       of 32-bit's equivalent of the corresponding rule.
#       (See `man 7 audit.rules` for details )
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS=""
	
	AUID_FILTERS=""
	
	SYSCALL="query_module"
	KEY="modules"
	SYSCALL_GROUPING="create_module delete_module finit_module init_module query_module"
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_kernel_module_loading_query" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - audit_rules_kernel_module_loading_query
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on Kernel Module Loading and Unloading
    - query_module - Set architecture for audit ['query_module'] tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - audit_rules_kernel_module_loading_query
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on Kernel Module Loading and Unloading
    - query_module - Perform remediation of Audit rules for ['query_module'] for 32bit
    platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - query_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of query_module in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modules.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modules.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - query_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of query_module in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  tags:
  - audit_rules_kernel_module_loading_query
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on Kernel Module Loading and Unloading
    - query_module - Perform remediation of Audit rules for ['query_module'] for 64bit
    platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - query_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of query_module in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/modules.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/modules.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - query_module
      syscall_grouping:
      - create_module
      - delete_module
      - finit_module
      - init_module
      - query_module

  - name: Check existence of query_module in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F auid&gt;=1000
        -F auid!=unset -F key=modules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - not ( ansible_architecture == "aarch64" )
  - audit_arch == "b64"
  tags:
  - audit_rules_kernel_module_loading_query
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_kernel_module_loading_query:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_kernel_module_loading_query_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_audit_login_events">
            <xccdf-1.2:title>Record Attempts to Alter Logon and Logout Events</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system already collects login information for all users
and root. If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code> in order to watch for attempted manual
edits of files involved in storing logon events:

<html:pre>-w /var/log/tallylog -p wa -k logins
-w <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir" use="legacy"/> -p wa -k logins
-w /var/log/lastlog -p wa -k logins</html:pre>


If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file in order to watch for unattempted manual
edits of files involved in storing logon events:

<html:pre>-w /var/log/tallylog -p wa -k logins
-w <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir" use="legacy"/> -p wa -k logins
-w /var/log/lastlog -p wa -k logins</html:pre></xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_login_events" selected="false" severity="medium">
              <xccdf-1.2:title>Record Attempts to Alter Logon and Logout Events</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system already collects login information for all users
and root. If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code> in order to watch for attempted manual
edits of files involved in storing logon events:
<html:pre>-w /var/log/tallylog -p wa -k logins
-w <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir" use="legacy"/> -p wa -k logins
-w /var/log/lastlog -p wa -k logins</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code> file in order to watch for unattempted manual
edits of files involved in storing logon events:
<html:pre>-w /var/log/tallylog -p wa -k logins
-w <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir" use="legacy"/> -p wa -k logins
-w /var/log/lastlog -p wa -k logins</html:pre></xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule checks for multiple syscalls related to login events;
it was written with DISA STIG in mind. Other policies should use a
separate rule for each syscall that needs to be checked. For example:
<html:ul><html:li><html:code>audit_rules_login_events_tallylog</html:code></html:li><html:li><html:code>audit_rules_login_events_faillock</html:code></html:li><html:li><html:code>audit_rules_login_events_lastlog</html:code></html:li></html:ul></xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.3</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Manual editing of these files may indicate nefarious activity, such
as an attacker attempting to remove evidence of an intrusion.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_login_events" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'

var_accounts_passwords_pam_faillock_dir='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir" use="legacy"/>'


# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/tallylog" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/tallylog $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/tallylog$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/tallylog -p wa -k logins" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/logins.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/var/log/tallylog" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/logins.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/logins.rules"
    # If the logins.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/tallylog" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/tallylog $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/tallylog$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/tallylog -p wa -k logins" &gt;&gt; "$audit_rules_file"

    fi
done

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+${var_accounts_passwords_pam_faillock_dir}" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+${var_accounts_passwords_pam_faillock_dir} $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+${var_accounts_passwords_pam_faillock_dir}$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w ${var_accounts_passwords_pam_faillock_dir} -p wa -k logins" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/logins.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+${var_accounts_passwords_pam_faillock_dir}" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/logins.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/logins.rules"
    # If the logins.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+${var_accounts_passwords_pam_faillock_dir}" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+${var_accounts_passwords_pam_faillock_dir} $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+${var_accounts_passwords_pam_faillock_dir}$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w ${var_accounts_passwords_pam_faillock_dir} -p wa -k logins" &gt;&gt; "$audit_rules_file"

    fi
done

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/lastlog" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/lastlog $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/lastlog$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/lastlog -p wa -k logins" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/logins.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/var/log/lastlog" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/logins.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/logins.rules"
    # If the logins.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/lastlog" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/lastlog $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/lastlog$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/lastlog -p wa -k logins" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_passwords_pam_faillock_dir:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_login_events:def:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_login_events_faillock" selected="false" severity="medium">
              <xccdf-1.2:title>Record Attempts to Alter Logon and Logout Events - faillock</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system already collects login information for all users
and root.




If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir" use="legacy"/> -p wa -k logins</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir" use="legacy"/> -p wa -k logins</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000470-GPOS-00214</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000473-GPOS-00218</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000503-CTR-001275</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000506-CTR-001290</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030590</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230466r1017258_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Manual editing of these files may indicate nefarious activity, such
as an attacker attempting to remove evidence of an intrusion.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_login_events_faillock" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'


var_accounts_passwords_pam_faillock_dir='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir" use="legacy"/>'





# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+${var_accounts_passwords_pam_faillock_dir}" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+${var_accounts_passwords_pam_faillock_dir} $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+${var_accounts_passwords_pam_faillock_dir}$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w ${var_accounts_passwords_pam_faillock_dir} -p wa -k logins" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/logins.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+${var_accounts_passwords_pam_faillock_dir}" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/logins.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/logins.rules"
    # If the logins.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+${var_accounts_passwords_pam_faillock_dir}" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+${var_accounts_passwords_pam_faillock_dir} $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+${var_accounts_passwords_pam_faillock_dir}$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w ${var_accounts_passwords_pam_faillock_dir} -p wa -k logins" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_login_events_faillock" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030590
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_faillock
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_accounts_passwords_pam_faillock_dir # promote to variable
  set_fact:
    var_accounts_passwords_pam_faillock_dir: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir" use="legacy"/>
  tags:
    - always

- name: Record Attempts to Alter Logon and Logout Events - faillock - Check if watch
    rule for {{ var_accounts_passwords_pam_faillock_dir }} already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+{{ var_accounts_passwords_pam_faillock_dir }}\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030590
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_faillock
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - faillock - Search /etc/audit/rules.d
    for other rules with specified key logins
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)logins$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030590
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_faillock
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - faillock - Use /etc/audit/rules.d/logins.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/logins.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - DISA-STIG-RHEL-08-030590
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_faillock
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - faillock - Use matched
    file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - DISA-STIG-RHEL-08-030590
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_faillock
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - faillock - Add watch rule
    for {{ var_accounts_passwords_pam_faillock_dir }} in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w {{ var_accounts_passwords_pam_faillock_dir }} -p wa -k logins
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030590
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_faillock
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - faillock - Check if watch
    rule for {{ var_accounts_passwords_pam_faillock_dir }} already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+{{ var_accounts_passwords_pam_faillock_dir }}\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030590
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_faillock
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - faillock - Add watch rule
    for {{ var_accounts_passwords_pam_faillock_dir }} in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w {{ var_accounts_passwords_pam_faillock_dir }} -p wa -k logins
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030590
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_faillock
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-export export-name="oval:ssg-var_accounts_passwords_pam_faillock_dir:var:1" value-id="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_dir"/>
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_login_events_faillock:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_login_events_faillock_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_login_events_lastlog" selected="false" severity="medium">
              <xccdf-1.2:title>Record Attempts to Alter Logon and Logout Events - lastlog</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system already collects login information for all users
and root.




If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /var/log/lastlog -p wa -k logins</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /var/log/lastlog -p wa -k logins</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000473-GPOS-00218</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000470-GPOS-00214</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000503-CTR-001275</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000506-CTR-001290</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030600</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230467r1017259_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Manual editing of these files may indicate nefarious activity, such
as an attacker attempting to remove evidence of an intrusion.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_login_events_lastlog" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/lastlog" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/lastlog $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/lastlog$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/lastlog -p wa -k logins" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/logins.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/var/log/lastlog" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/logins.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/logins.rules"
    # If the logins.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/lastlog" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/lastlog $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/lastlog$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/lastlog -p wa -k logins" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_login_events_lastlog" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030600
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_lastlog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - lastlog - Check if watch
    rule for /var/log/lastlog already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/var/log/lastlog\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030600
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_lastlog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - lastlog - Search /etc/audit/rules.d
    for other rules with specified key logins
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)logins$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030600
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_lastlog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - lastlog - Use /etc/audit/rules.d/logins.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/logins.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - DISA-STIG-RHEL-08-030600
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_lastlog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - lastlog - Use matched file
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - DISA-STIG-RHEL-08-030600
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_lastlog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - lastlog - Add watch rule
    for /var/log/lastlog in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /var/log/lastlog -p wa -k logins
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030600
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_lastlog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - lastlog - Check if watch
    rule for /var/log/lastlog already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/var/log/lastlog\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030600
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_lastlog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - lastlog - Add watch rule
    for /var/log/lastlog in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /var/log/lastlog -p wa -k logins
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - DISA-STIG-RHEL-08-030600
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_lastlog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_login_events_lastlog:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_login_events_lastlog_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_login_events_tallylog" selected="false" severity="medium">
              <xccdf-1.2:title>Record Attempts to Alter Logon and Logout Events - tallylog</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system already collects login information for all users
and root.




If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /var/log/tallylog -p wa -k logins</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /var/log/tallylog -p wa -k logins</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000470-GPOS-00214</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000473-GPOS-00218</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000503-CTR-001275</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Manual editing of these files may indicate nefarious activity, such
as an attacker attempting to remove evidence of an intrusion.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_login_events_tallylog" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/tallylog" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/tallylog $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/tallylog$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/tallylog -p wa -k logins" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/logins.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/var/log/tallylog" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/logins.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/logins.rules"
    # If the logins.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/var/log/tallylog" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/var/log/tallylog $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/var/log/tallylog$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /var/log/tallylog -p wa -k logins" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_login_events_tallylog" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_tallylog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - tallylog - Check if watch
    rule for /var/log/tallylog already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/var/log/tallylog\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_tallylog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - tallylog - Search /etc/audit/rules.d
    for other rules with specified key logins
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)logins$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_tallylog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - tallylog - Use /etc/audit/rules.d/logins.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/logins.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_tallylog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - tallylog - Use matched
    file as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_tallylog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - tallylog - Add watch rule
    for /var/log/tallylog in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /var/log/tallylog -p wa -k logins
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_tallylog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - tallylog - Check if watch
    rule for /var/log/tallylog already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/var/log/tallylog\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_tallylog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter Logon and Logout Events - tallylog - Add watch rule
    for /var/log/tallylog in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /var/log/tallylog -p wa -k logins
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.3
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.1
  - PCI-DSSv4-10.2.1.3
  - audit_rules_login_events_tallylog
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_login_events_tallylog:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_login_events_tallylog_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_audit_privileged_commands">
            <xccdf-1.2:title>Record Information on the Use of Privileged Commands</xccdf-1.2:title>
            <xccdf-1.2:description>At a minimum, the audit system should collect the execution of
privileged commands for all users and root.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_privileged_commands_init" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - init</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/init -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/init -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000477-GPOS-00222</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of the init command may cause availability issues for the system.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_privileged_commands_init" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/sbin/init"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_privileged_commands_init" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - audit_privileged_commands_init
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - init
    - Perform remediation of Audit rules for /usr/sbin/init
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/init -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/sbin/init -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/init -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/init -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/sbin/init -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/init -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - audit_privileged_commands_init
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_privileged_commands_init:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_privileged_commands_init_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_privileged_commands_poweroff" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - poweroff</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/poweroff -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/poweroff -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000477-GPOS-00222</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of the poweroff command may cause availability issues for the system.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_privileged_commands_poweroff" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/sbin/poweroff"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_privileged_commands_poweroff" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - audit_privileged_commands_poweroff
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - poweroff
    - Perform remediation of Audit rules for /usr/sbin/poweroff
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/poweroff -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/sbin/poweroff -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/poweroff -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/poweroff -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/sbin/poweroff -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/poweroff -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - audit_privileged_commands_poweroff
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_privileged_commands_poweroff:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_privileged_commands_poweroff_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_privileged_commands_reboot" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - reboot</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/reboot -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/reboot -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000477-GPOS-00222</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of the reboot command may cause availability issues for the system.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_privileged_commands_reboot" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/sbin/reboot"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_privileged_commands_reboot" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - audit_privileged_commands_reboot
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - reboot
    - Perform remediation of Audit rules for /usr/sbin/reboot
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/reboot -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/sbin/reboot -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/reboot -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/reboot -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/sbin/reboot -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/reboot -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - audit_privileged_commands_reboot
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_privileged_commands_reboot:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_privileged_commands_reboot_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_privileged_commands_shutdown" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - shutdown</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/shutdown -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/shutdown -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000477-GPOS-00222</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of the shutdown command may cause availability issues for the system.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_privileged_commands_shutdown" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/sbin/shutdown"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_privileged_commands_shutdown" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-12(c)
  - audit_privileged_commands_shutdown
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - shutdown
    - Perform remediation of Audit rules for /usr/sbin/shutdown
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/shutdown -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/sbin/shutdown -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/shutdown -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/shutdown -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/sbin/shutdown -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/shutdown -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-12(c)
  - audit_privileged_commands_shutdown
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_privileged_commands_shutdown:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_privileged_commands_shutdown_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands</xccdf-1.2:title>
              <xccdf-1.2:description>The audit system should collect information about usage of privileged commands for all users.
These are commands with suid or sgid bits on and they are specially risky in local block
device partitions not mounted with noexec and nosuid options. Therefore, these partitions
should be first identified by the following command:
<html:pre>findmnt -n -l -k -it $(awk '/nodev/ { print $2 }' /proc/filesystems | paste -sd,) | grep -Pv "noexec|nosuid"</html:pre>

For all partitions listed by the previous command, it is necessary to search for
setuid / setgid programs using the following command:
<html:pre>$ sudo find <html:i>PARTITION</html:i> -xdev -perm /6000 -type f 2&gt;/dev/null</html:pre>


For each setuid / setgid program identified by the previous command, an audit rule must be
present in the appropriate place using the following line structure:
<html:pre>-a always,exit -F path=<html:i>PROG_PATH</html:i> -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>


If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code> program to read
audit rules during daemon startup, add the line to a file with suffix <html:code>.rules</html:code> in the
<html:code>/etc/audit/rules.d</html:code> directory, replacing the <html:i>PROG_PATH</html:i> part with the full path
of that setuid / setgid identified program.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code> utility instead, add
the line to the <html:code>/etc/audit/audit.rules</html:code> file, also replacing the <html:i>PROG_PATH</html:i> part
with the full path of that setuid / setgid identified program.</xccdf-1.2:description>
              <xccdf-1.2:warning category="general">This rule checks for multiple syscalls related to privileged commands. If needed to check
specific privileged commands, other more specific rules should be considered. For example:
<html:ul><html:li><html:code>audit_rules_privileged_commands_su</html:code></html:li><html:li><html:code>audit_rules_privileged_commands_umount</html:code></html:li><html:li><html:code>audit_rules_privileged_commands_passwd</html:code></html:li></html:ul></xccdf-1.2:warning>
              <xccdf-1.2:warning category="general">Note that OVAL check and Bash / Ansible remediation of this rule
explicitly excludes file systems mounted at <html:code>/proc</html:code> directory
and its subdirectories. It is a virtual file system and it doesn't
contain executable applications. At the same time, interacting with this
file system during check or remediation caused undesirable errors.</xccdf-1.2:warning>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO08.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.DP-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.CO-2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000327-GPOS-00127</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0846</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.6</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by authorized users,
or by unauthorized external entities that have compromised system accounts, is a serious and
ongoing concern that can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify the
risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks, which attempt to subvert
their normal role of providing some necessary but limited capability. As such, motivation
exists to monitor these programs for unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

ACTION_ARCH_FILTERS="-a always,exit"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""

function add_audit_rule()
{
    local PRIV_CMD="$1"
    local OTHER_FILTERS="-F path=$PRIV_CMD -F perm=x"
    # Perform the remediation for both possible tools: 'auditctl' and 'augenrules'

    ACTION_ARCH_FILTERS="-a always,exit"
    unset syscall_a
    unset syscall_grouping
    unset syscall_string
    unset syscall
    unset file_to_edit
    unset rule_to_edit
    unset rule_syscalls_to_edit
    unset other_string
    unset auid_string
    unset full_rule

    # Load macro arguments into arrays
    read -a syscall_a &lt;&lt;&lt; $SYSCALL
    read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

    # Create a list of audit *.rules files that should be inspected for presence and correctness
    # of a particular audit rule. The scheme is as follows:
    #
    # -----------------------------------------------------------------------------------------
    #  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
    # -----------------------------------------------------------------------------------------
    #        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
    # -----------------------------------------------------------------------------------------
    #        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
    #        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
    # -----------------------------------------------------------------------------------------
    #
    files_to_inspect=()

    # If audit tool is 'augenrules', then check if the audit rule is defined
    # If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
    # If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
    default_file="/etc/audit/rules.d/$KEY.rules"
    # As other_filters may include paths, lets use a different delimiter for it
    # The "F" script expression tells sed to print the filenames where the expressions matched
    readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
    # Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
    if [ ${#files_to_inspect[@]} -eq "0" ]
    then
        file_to_inspect="/etc/audit/rules.d/$KEY.rules"
        files_to_inspect=("$file_to_inspect")
        if [ ! -e "$file_to_inspect" ]
        then
            touch "$file_to_inspect"
            chmod 0600 "$file_to_inspect"
        fi
    fi

    # After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
    skip=1

    for audit_file in "${files_to_inspect[@]}"
    do
        # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
        # i.e, collect rules that match:
        # * the action, list and arch, (2-nd argument)
        # * the other filters, (3-rd argument)
        # * the auid filters, (4-rd argument)
        readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

        candidate_rules=()
        # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
        for s_rule in "${similar_rules[@]}"
        do
            # Strip all the options and fields we know of,
            # than check if there was any field left over
            extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
            grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
        done

        if [[ ${#syscall_a[@]} -ge 1 ]]
        then
            # Check if the syscall we want is present in any of the similar existing rules
            for rule in "${candidate_rules[@]}"
            do
                rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
                all_syscalls_found=0
                for syscall in "${syscall_a[@]}"
                do
                    grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                       # A syscall was not found in the candidate rule
                       all_syscalls_found=1
                       }
                done
                if [[ $all_syscalls_found -eq 0 ]]
                then
                    # We found a rule with all the syscall(s) we want; skip rest of macro
                    skip=0
                    break
                fi

                # Check if this rule can be grouped with our target syscall and keep track of it
                for syscall_g in "${syscall_grouping[@]}"
                do
                    if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                    then
                        file_to_edit=${audit_file}
                        rule_to_edit=${rule}
                        rule_syscalls_to_edit=${rule_syscalls}
                    fi
                done
            done
        else
            # If there is any candidate rule, it is compliant; skip rest of macro
            if [ "${#candidate_rules[@]}" -gt 0 ]
            then
                skip=0
            fi
        fi

        if [ "$skip" -eq 0 ]; then
            break
        fi
    done

    if [ "$skip" -ne 0 ]; then
        # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
        # At this point we know if we need to either append the $full_rule or group
        # the syscall together with an exsiting rule

        # Append the full_rule if it cannot be grouped to any other rule
        if [ -z ${rule_to_edit+x} ]
        then
            # Build full_rule while avoid adding double spaces when other_filters is empty
            if [ "${#syscall_a[@]}" -gt 0 ]
            then
                syscall_string=""
                for syscall in "${syscall_a[@]}"
                do
                    syscall_string+=" -S $syscall"
                done
            fi
            other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
            auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
            full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
            echo "$full_rule" &gt;&gt; "$default_file"
            chmod 0600 ${default_file}
        else
            # Check if the syscalls are declared as a comma separated list or
            # as multiple -S parameters
            if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
            then
                delimiter=","
            else
                delimiter=" -S "
            fi
            new_grouped_syscalls="${rule_syscalls_to_edit}"
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
                   # A syscall was not found in the candidate rule
                   new_grouped_syscalls+="${delimiter}${syscall}"
                   }
            done

            # Group the syscall in the rule
            sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
        fi
    fi
    unset syscall_a
    unset syscall_grouping
    unset syscall_string
    unset syscall
    unset file_to_edit
    unset rule_to_edit
    unset rule_syscalls_to_edit
    unset other_string
    unset auid_string
    unset full_rule

    # Load macro arguments into arrays
    read -a syscall_a &lt;&lt;&lt; $SYSCALL
    read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

    # Create a list of audit *.rules files that should be inspected for presence and correctness
    # of a particular audit rule. The scheme is as follows:
    #
    # -----------------------------------------------------------------------------------------
    #  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
    # -----------------------------------------------------------------------------------------
    #        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
    # -----------------------------------------------------------------------------------------
    #        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
    #        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
    # -----------------------------------------------------------------------------------------
    #
    files_to_inspect=()


    # If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
    # file to the list of files to be inspected
    default_file="/etc/audit/audit.rules"
    files_to_inspect+=('/etc/audit/audit.rules' )

    # After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
    skip=1

    for audit_file in "${files_to_inspect[@]}"
    do
        # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
        # i.e, collect rules that match:
        # * the action, list and arch, (2-nd argument)
        # * the other filters, (3-rd argument)
        # * the auid filters, (4-rd argument)
        readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

        candidate_rules=()
        # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
        for s_rule in "${similar_rules[@]}"
        do
            # Strip all the options and fields we know of,
            # than check if there was any field left over
            extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
            grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
        done

        if [[ ${#syscall_a[@]} -ge 1 ]]
        then
            # Check if the syscall we want is present in any of the similar existing rules
            for rule in "${candidate_rules[@]}"
            do
                rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
                all_syscalls_found=0
                for syscall in "${syscall_a[@]}"
                do
                    grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                       # A syscall was not found in the candidate rule
                       all_syscalls_found=1
                       }
                done
                if [[ $all_syscalls_found -eq 0 ]]
                then
                    # We found a rule with all the syscall(s) we want; skip rest of macro
                    skip=0
                    break
                fi

                # Check if this rule can be grouped with our target syscall and keep track of it
                for syscall_g in "${syscall_grouping[@]}"
                do
                    if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                    then
                        file_to_edit=${audit_file}
                        rule_to_edit=${rule}
                        rule_syscalls_to_edit=${rule_syscalls}
                    fi
                done
            done
        else
            # If there is any candidate rule, it is compliant; skip rest of macro
            if [ "${#candidate_rules[@]}" -gt 0 ]
            then
                skip=0
            fi
        fi

        if [ "$skip" -eq 0 ]; then
            break
        fi
    done

    if [ "$skip" -ne 0 ]; then
        # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
        # At this point we know if we need to either append the $full_rule or group
        # the syscall together with an exsiting rule

        # Append the full_rule if it cannot be grouped to any other rule
        if [ -z ${rule_to_edit+x} ]
        then
            # Build full_rule while avoid adding double spaces when other_filters is empty
            if [ "${#syscall_a[@]}" -gt 0 ]
            then
                syscall_string=""
                for syscall in "${syscall_a[@]}"
                do
                    syscall_string+=" -S $syscall"
                done
            fi
            other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
            auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
            full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
            echo "$full_rule" &gt;&gt; "$default_file"
            chmod 0600 ${default_file}
        else
            # Check if the syscalls are declared as a comma separated list or
            # as multiple -S parameters
            if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
            then
                delimiter=","
            else
                delimiter=" -S "
            fi
            new_grouped_syscalls="${rule_syscalls_to_edit}"
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
                   # A syscall was not found in the candidate rule
                   new_grouped_syscalls+="${delimiter}${syscall}"
                   }
            done

            # Group the syscall in the rule
            sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
        fi
    fi


}

if { rpm --quiet -q kernel rpm-ostree bootc &amp;&amp; ! rpm --quiet -q openshift-kubelet &amp;&amp; { [ -f "/run/.containerenv" ] || [ -f "/.containerenv" ]; }; } ; then
  PRIV_CMDS=$(find / -perm /6000 -type f -not -path "/sysroot/*" 2&gt;/dev/null)
  for PRIV_CMD in $PRIV_CMDS; do
    add_audit_rule $PRIV_CMD
  done
else
  FILTER_NODEV=$(awk '/nodev/ { print $2 }' /proc/filesystems | paste -sd,)
  PARTITIONS=$(findmnt -n -l -k -it "$FILTER_NODEV" | grep -Pv "noexec|nosuid|/proc($|/.*$)" | awk '{ print $1 }')
  for PARTITION in $PARTITIONS; do
    PRIV_CMDS=$(find "${PARTITION}" -xdev -perm /6000 -type f 2&gt;/dev/null)
    for PRIV_CMD in $PRIV_CMDS; do
      add_audit_rule $PRIV_CMD
    done
  done
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - audit_rules_privileged_commands
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on the Use of Privileged Commands - Set
    List of Mount Points Which Permits Execution of Privileged Commands
  ansible.builtin.set_fact:
    privileged_mount_points: '{{ (ansible_facts.mounts | rejectattr(''options'', ''search'',
      ''noexec|nosuid'') | rejectattr(''mount'', ''match'', ''/proc($|/.*$)'') | map(attribute=''mount'')
      | list ) }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - audit_rules_privileged_commands
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on the Use of Privileged Commands - Search
    for Privileged Commands in Eligible Mount Points
  ansible.builtin.shell:
    cmd: find {{ item }} -xdev -perm /6000 -type f 2&gt;/dev/null
  register: result_privileged_commands_search
  changed_when: false
  failed_when: false
  with_items: '{{ privileged_mount_points }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - audit_rules_privileged_commands
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on the Use of Privileged Commands - Set
    List of Privileged Commands Found in Eligible Mount Points
  ansible.builtin.set_fact:
    privileged_commands: '{{ privileged_commands | default([]) + item.stdout_lines
      }}'
  loop: '{{ result_privileged_commands_search.results }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - item is not skipped
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - audit_rules_privileged_commands
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure auditd Collects Information on the Use of Privileged Commands - Privileged
    Commands are Present in the System
  block:

  - name: Ensure auditd Collects Information on the Use of Privileged Commands - Ensure
      Rules for All Privileged Commands in augenrules Format
    ansible.builtin.lineinfile:
      path: /etc/audit/rules.d/privileged.rules
      line: -a always,exit -F path={{ item }} -F perm=x -F auid&gt;=1000 -F auid!=unset
        -F key=privileged
      regexp: ^.*path={{ item | regex_escape() }} .*$
      create: true
    with_items:
    - '{{ privileged_commands }}'

  - name: Ensure auditd Collects Information on the Use of Privileged Commands - Ensure
      Rules for All Privileged Commands in auditctl Format
    ansible.builtin.lineinfile:
      path: /etc/audit/audit.rules
      line: -a always,exit -F path={{ item }} -F perm=x -F auid&gt;=1000 -F auid!=unset
        -F key=privileged
      regexp: ^.*path={{ item | regex_escape() }} .*$
      create: true
    with_items:
    - '{{ privileged_commands }}'

  - name: Ensure auditd Collects Information on the Use of Privileged Commands - Search
      for Duplicated Rules in Other Files
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      recurse: false
      contains: ^-a always,exit (-F arch=b32 |-F arch=b64 )?-F path={{ item | regex_escape()
        }} .*$
      patterns: '*.rules'
    with_items:
    - '{{ privileged_commands }}'
    register: result_augenrules_files

  - name: Ensure auditd Collects Information on the Use of Privileged Commands - Ensure
      Rules for Privileged Commands are Defined Only in One File
    ansible.builtin.lineinfile:
      path: '{{ item.1.path }}'
      regexp: ^-a always,exit (-F arch=b32 |-F arch=b64 )?-F path={{ item.0.item |
        regex_escape() }} .*$
      state: absent
    with_subelements:
    - '{{ result_augenrules_files.results }}'
    - files
    when:
    - item.1.path != '/etc/audit/rules.d/privileged.rules'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - privileged_commands is defined
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.2.2
  - audit_rules_privileged_commands
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_at" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - at</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/at -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/at -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_at" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/at"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_at" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_at
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - at
    - Perform remediation of Audit rules for /usr/bin/at
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/at -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/at -F auid&gt;=1000 -F
        auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/at -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/at -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/at -F auid&gt;=1000 -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/at -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_at
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_at:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_at_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_chage" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - chage</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/chage -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/chage -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000029-CTR-000085</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000501-CTR-001265</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000502-CTR-001270</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030250</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230418r1017220_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_chage" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/chage"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_chage" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030250
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_chage
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - chage
    - Perform remediation of Audit rules for /usr/bin/chage
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/chage -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/chage -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/chage -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/chage -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/chage -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/chage -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030250
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_chage
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_chage:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_chage_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_chsh" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - chsh</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/chsh -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/chsh -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030410</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230448r1017247_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_chsh" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/chsh"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_chsh" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030410
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_chsh
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - chsh
    - Perform remediation of Audit rules for /usr/bin/chsh
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/chsh -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/chsh -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/chsh -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/chsh -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/chsh -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/chsh -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030410
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_chsh
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_chsh:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_chsh_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_crontab" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - crontab</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/crontab -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/crontab -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030400</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230447r1017246_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_crontab" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/crontab"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_crontab" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030400
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_crontab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - crontab
    - Perform remediation of Audit rules for /usr/bin/crontab
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/crontab -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/crontab -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/crontab -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/crontab -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/crontab -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/crontab -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030400
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_crontab
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_crontab:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_crontab_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_gpasswd" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - gpasswd</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/gpasswd -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/gpasswd -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000029-CTR-000085</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030370</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230444r1017244_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_gpasswd" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/gpasswd"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_gpasswd" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030370
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_gpasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - gpasswd
    - Perform remediation of Audit rules for /usr/bin/gpasswd
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/gpasswd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/gpasswd -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/gpasswd -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/gpasswd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/gpasswd -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/gpasswd -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030370
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_gpasswd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_gpasswd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_gpasswd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_kmod" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - kmod</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/kmod -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/kmod -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12.1(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12.1(iv)AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MA-4(1)(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00216</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000477-GPOS-00222</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000504-CTR-001280</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030580</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230465r1017257_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Without generating audit records that are specific to the security and
mission needs of the organization, it would be difficult to establish,
correlate, and investigate the events relating to an incident or identify
those responsible for one.

Audit records can be generated from various components within the
information system (e.g., module or policy filter).</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_kmod" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/kmod"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_kmod" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030580
  - NIST-800-53-AU-12(a)
  - NIST-800-53-AU-12.1(ii)
  - NIST-800-53-AU-12.1(iv)AU-12(c)
  - NIST-800-53-AU-3
  - NIST-800-53-AU-3.1
  - NIST-800-53-MA-4(1)(a)
  - audit_rules_privileged_commands_kmod
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - kmod
    - Perform remediation of Audit rules for /usr/bin/kmod
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/kmod -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/kmod -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/kmod -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/kmod -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/kmod -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/kmod -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030580
  - NIST-800-53-AU-12(a)
  - NIST-800-53-AU-12.1(ii)
  - NIST-800-53-AU-12.1(iv)AU-12(c)
  - NIST-800-53-AU-3
  - NIST-800-53-AU-3.1
  - NIST-800-53-MA-4(1)(a)
  - audit_rules_privileged_commands_kmod
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_kmod:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_kmod_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_mount" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - mount</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/mount -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/mount -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000029-CTR-000085</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030300</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230423r1017224_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_mount" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/mount"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_mount" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030300
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_mount
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - mount
    - Perform remediation of Audit rules for /usr/bin/mount
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/mount -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/mount -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/mount -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/mount -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/mount -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/mount -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030300
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_mount
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_mount:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_mount_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_newgidmap" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - newgidmap</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/newgidmap -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/newgidmap -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_newgidmap" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/newgidmap"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_newgidmap" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_newgidmap
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - newgidmap
    - Perform remediation of Audit rules for /usr/bin/newgidmap
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/newgidmap -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/newgidmap -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/newgidmap -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/newgidmap -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/newgidmap -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/newgidmap -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_newgidmap
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_newgidmap:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_newgidmap_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_newgrp" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - newgrp</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/newgrp -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/newgrp -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000029-CTR-000085</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030350</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230437r1017238_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_newgrp" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/newgrp"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_newgrp" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030350
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_newgrp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - newgrp
    - Perform remediation of Audit rules for /usr/bin/newgrp
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/newgrp -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/newgrp -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/newgrp -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/newgrp -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/newgrp -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/newgrp -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030350
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_newgrp
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_newgrp:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_newgrp_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_newuidmap" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - newuidmap</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/newuidmap -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/newuidmap -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_newuidmap" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/newuidmap"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_newuidmap" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_newuidmap
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - newuidmap
    - Perform remediation of Audit rules for /usr/bin/newuidmap
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/newuidmap -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/newuidmap -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/newuidmap -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/newuidmap -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/newuidmap -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/newuidmap -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_newuidmap
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_newuidmap:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_newuidmap_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_pam_timestamp_check" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - pam_timestamp_check</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/pam_timestamp_check -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/pam_timestamp_check -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000029-CTR-000085</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030340</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230436r1017237_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_pam_timestamp_check" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/sbin/pam_timestamp_check"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_pam_timestamp_check" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030340
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_pam_timestamp_check
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - pam_timestamp_check
    - Perform remediation of Audit rules for /usr/sbin/pam_timestamp_check
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/pam_timestamp_check -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/sbin/pam_timestamp_check
        -F auid&gt;=1000 -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/pam_timestamp_check
        -F auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/pam_timestamp_check -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/sbin/pam_timestamp_check -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/pam_timestamp_check
        -F auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030340
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_pam_timestamp_check
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_pam_timestamp_check:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_pam_timestamp_check_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_passwd" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - passwd</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/passwd -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/passwd -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000029-CTR-000085</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030290</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230422r1017223_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_passwd" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/passwd"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_passwd" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030290
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - passwd
    - Perform remediation of Audit rules for /usr/bin/passwd
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/passwd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/passwd -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/passwd -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/passwd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/passwd -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/passwd -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030290
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_passwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_passwd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_passwd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_postdrop" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - postdrop</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/postdrop -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/postdrop -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030311</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230427r1017228_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_postdrop" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/sbin/postdrop"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_postdrop" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030311
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_postdrop
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - postdrop
    - Perform remediation of Audit rules for /usr/sbin/postdrop
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/postdrop -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/sbin/postdrop -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/postdrop -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/postdrop -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/sbin/postdrop -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/postdrop -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030311
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_postdrop
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_postdrop:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_postdrop_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_postqueue" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - postqueue</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/postqueue -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/postqueue -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030312</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230428r1017229_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_postqueue" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/sbin/postqueue"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_postqueue" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030312
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_postqueue
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - postqueue
    - Perform remediation of Audit rules for /usr/sbin/postqueue
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/postqueue -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/sbin/postqueue -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/postqueue -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/postqueue -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/sbin/postqueue -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/postqueue -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030312
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_postqueue
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_postqueue:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_postqueue_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_pt_chown" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - pt_chown</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/libexec/pt_chown -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/libexec/pt_chown -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000501-CTR-001265</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000502-CTR-001270</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_pt_chown" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/libexec/pt_chown"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_pt_chown" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_pt_chown
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - pt_chown
    - Perform remediation of Audit rules for /usr/libexec/pt_chown
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/libexec/pt_chown -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/libexec/pt_chown -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/libexec/pt_chown
        -F auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/libexec/pt_chown -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/libexec/pt_chown -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/libexec/pt_chown
        -F auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_pt_chown
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_pt_chown:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_pt_chown_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_ssh_agent" selected="false" severity="medium">
              <xccdf-1.2:title>Record Any Attempts to Run ssh-agent</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/ssh-agent -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/ssh-agent -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030280</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230421r1017222_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Without generating audit records that are specific to the security and
mission needs of the organization, it would be difficult to establish,
correlate, and investigate the events relating to an incident or identify
those responsible for one.

Audit records can be generated from various components within the
information system (e.g., module or policy filter).</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_ssh_agent" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/ssh-agent"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_ssh_agent" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030280
  - audit_rules_privileged_commands_ssh_agent
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Any Attempts to Run ssh-agent - Perform remediation of Audit rules
    for /usr/bin/ssh-agent
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/ssh-agent -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/ssh-agent -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/ssh-agent -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/ssh-agent -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/ssh-agent -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/ssh-agent -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030280
  - audit_rules_privileged_commands_ssh_agent
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_ssh_agent:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_ssh_agent_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_ssh_keysign" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - ssh-keysign</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/libexec/openssh/ssh-keysign -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/libexec/openssh/ssh-keysign -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000029-CTR-000085</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030320</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230434r1017235_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_ssh_keysign" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/libexec/openssh/ssh-keysign"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_ssh_keysign" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030320
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_ssh_keysign
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - ssh-keysign
    - Perform remediation of Audit rules for /usr/libexec/openssh/ssh-keysign
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/libexec/openssh/ssh-keysign -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/libexec/openssh/ssh-keysign
        -F auid&gt;=1000 -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/libexec/openssh/ssh-keysign
        -F auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/libexec/openssh/ssh-keysign -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/libexec/openssh/ssh-keysign -F auid&gt;=1000 -F auid!=unset
        (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/libexec/openssh/ssh-keysign
        -F auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030320
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_ssh_keysign
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_ssh_keysign:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_ssh_keysign_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_su" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - su</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/su -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/su -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000029-CTR-000085</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000755-GPOS-00220</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030190</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230412r1017218_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_su" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/su"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_su" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030190
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_su
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - su
    - Perform remediation of Audit rules for /usr/bin/su
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/su -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/su -F auid&gt;=1000 -F
        auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/su -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/su -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/su -F auid&gt;=1000 -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/su -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030190
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_su
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_su:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_su_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudo" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - sudo</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/sudo -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/sudo -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000029-CTR-000085</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000755-GPOS-00220</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R33</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030550</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230462r1017254_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_sudo" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/sudo"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_sudo" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030550
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_sudo
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - sudo
    - Perform remediation of Audit rules for /usr/bin/sudo
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/sudo -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/sudo -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/sudo -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/sudo -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/sudo -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/sudo -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030550
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_sudo
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_sudo:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_sudo_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudoedit" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - sudoedit</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/sudoedit -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/sudoedit -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000755-GPOS-00220</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_sudoedit" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/sudoedit"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_sudoedit" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_sudoedit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - sudoedit
    - Perform remediation of Audit rules for /usr/bin/sudoedit
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/sudoedit -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/sudoedit -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/sudoedit -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/sudoedit -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/sudoedit -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/sudoedit -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_sudoedit
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_sudoedit:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_sudoedit_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_umount" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - umount</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/umount -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/bin/umount -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000029-CTR-000085</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030301</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230424r1017225_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_umount" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/bin/umount"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_umount" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030301
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_umount
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - umount
    - Perform remediation of Audit rules for /usr/bin/umount
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/umount -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/bin/umount -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/umount -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/bin/umount -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/bin/umount -F auid&gt;=1000 -F auid!=unset (?:-k |-F
        key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/bin/umount -F auid&gt;=1000
        -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030301
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_umount
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_umount:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_umount_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_unix_chkpwd" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - unix_chkpwd</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/unix_chkpwd -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/unix_chkpwd -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R6.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12.1(ii)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12.1(iv)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">MA-4(1)(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000029-CTR-000085</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030317</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230433r1017234_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_unix_chkpwd" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/sbin/unix_chkpwd"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_unix_chkpwd" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030317
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(a)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(ii)
  - NIST-800-53-AU-12.1(iv)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-AU-3
  - NIST-800-53-AU-3.1
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MA-4(1)(a)
  - audit_rules_privileged_commands_unix_chkpwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - unix_chkpwd
    - Perform remediation of Audit rules for /usr/sbin/unix_chkpwd
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/unix_chkpwd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/sbin/unix_chkpwd -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/unix_chkpwd
        -F auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/unix_chkpwd -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/sbin/unix_chkpwd -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/unix_chkpwd
        -F auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030317
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(a)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-12.1(ii)
  - NIST-800-53-AU-12.1(iv)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-AU-3
  - NIST-800-53-AU-3.1
  - NIST-800-53-CM-6(a)
  - NIST-800-53-MA-4(1)(a)
  - audit_rules_privileged_commands_unix_chkpwd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_unix_chkpwd:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_unix_update" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - unix_update</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/unix_update -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/unix_update -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030310</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230426r1017227_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_unix_update" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/sbin/unix_update"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_unix_update" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030310
  - audit_rules_privileged_commands_unix_update
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - unix_update
    - Perform remediation of Audit rules for /usr/sbin/unix_update
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/unix_update -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/sbin/unix_update -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/unix_update
        -F auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/unix_update -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/sbin/unix_update -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/unix_update
        -F auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030310
  - audit_rules_privileged_commands_unix_update
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_unix_update:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_unix_update_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_userhelper" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - userhelper</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/userhelper -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/userhelper -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030315</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230431r1017232_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_userhelper" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/sbin/userhelper"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_userhelper" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030315
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_userhelper
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - userhelper
    - Perform remediation of Audit rules for /usr/sbin/userhelper
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/userhelper -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/sbin/userhelper -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/userhelper
        -F auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/userhelper -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/sbin/userhelper -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/userhelper
        -F auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030315
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_userhelper
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_userhelper:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_userhelper_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_usermod" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - usermod</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/usermod -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/usermod -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000037-GPOS-00015</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000042-GPOS-00020</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000392-GPOS-00172</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000499-CTR-001255</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.6.3.18</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030560</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230463r1017255_rule</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_usermod" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/sbin/usermod"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_usermod" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030560
  - audit_rules_privileged_commands_usermod
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - usermod
    - Perform remediation of Audit rules for /usr/sbin/usermod
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/usermod -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/sbin/usermod -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/usermod -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/usermod -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/sbin/usermod -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/usermod -F
        auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030560
  - audit_rules_privileged_commands_usermod
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_usermod:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_usermod_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_usernetctl" selected="false" severity="medium">
              <xccdf-1.2:title>Ensure auditd Collects Information on the Use of Privileged Commands - usernetctl</xccdf-1.2:title>
              <xccdf-1.2:description>


At a minimum, the audit system should collect the execution of privileged
commands for all users and root.

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add
a line of the following form to a file with suffix <html:code>.rules</html:code>
in the directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/usernetctl -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add a line of the
following form to <html:code>/etc/audit/audit.rules</html:code>:
<html:pre>-a always,exit -F path=/usr/sbin/usernetctl -F auid&gt;=1000 -F auid!=unset -F key=privileged</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-2(4)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Misuse of privileged functions, either intentionally or unintentionally by
authorized users, or by unauthorized external entities that have compromised system accounts,
is a serious and ongoing concern and can have significant adverse impacts on organizations.
Auditing the use of privileged functions is one way to detect such misuse and identify
the risk from insider and advanced persistent threats.
<html:br/><html:br/>
Privileged programs are subject to escalation-of-privilege attacks,
which attempt to subvert their normal role of providing some necessary but
limited capability. As such, motivation exists to monitor these programs for
unusual activity.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_privileged_commands_usernetctl" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
OTHER_FILTERS="-F path=/usr/sbin/usernetctl"
AUID_FILTERS="-F auid&gt;=1000 -F auid!=unset"
SYSCALL=""
KEY="privileged"
SYSCALL_GROUPING=""


ACTION_ARCH_FILTERS="-a always,exit"
# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_privileged_commands_usernetctl" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_usernetctl
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Ensure auditd Collects Information on the Use of Privileged Commands - usernetctl
    - Perform remediation of Audit rules for /usr/sbin/usernetctl
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/usernetctl -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/privileged.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/privileged.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F path=/usr/sbin/usernetctl -F auid&gt;=1000
        -F auid!=unset (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/usernetctl
        -F auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls: []
      syscall_grouping: []

  - name: Check existence of  in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit(( -S |,)\w+)*(( -S |,){{ item }})+(( -S |,)\w+)* -F
        path=/usr/sbin/usernetctl -F auid&gt;=1000 -F auid!=unset (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit)(?=.*(?:(?:-S |,)(?:{{ syscalls_found | join("|") }}))\b)((?:(
        -S |,)\w+)+)( -F path=/usr/sbin/usernetctl -F auid&gt;=1000 -F auid!=unset (?:-k
        |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit{{ syscalls | join(',') }} -F path=/usr/sbin/usernetctl
        -F auid&gt;=1000 -F auid!=unset -F key=privileged
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AC-2(4)
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - audit_rules_privileged_commands_usernetctl
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_privileged_commands_usernetctl:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_privileged_commands_usernetctl_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
          <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_audit_time_rules">
            <xccdf-1.2:title>Records Events that Modify Date and Time Information</xccdf-1.2:title>
            <xccdf-1.2:description>Arbitrary changes to the system time can be used to obfuscate
nefarious activities in log files, as well as to confuse network services that
are highly dependent upon an accurate system time. All changes to the system
time should be audited.</xccdf-1.2:description>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_time_adjtimex" selected="false" severity="medium">
              <xccdf-1.2:title>Record attempts to alter time through adjtimex</xccdf-1.2:title>
              <xccdf-1.2:description>If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following line to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S adjtimex -F key=audit_time_rules</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S adjtimex -F key=audit_time_rules</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S adjtimex -F key=audit_time_rules</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S adjtimex -F key=audit_time_rules</html:pre>
The -k option allows for the specification of a key in string form that can be
used for better reporting capability through ausearch and aureport. Multiple
system calls can be defined on the same line to save space if desired, but is
not required. See an example of multiple combined syscalls:
<html:pre>-a always,exit -F arch=b64 -S adjtimex,settimeofday -F key=audit_time_rules</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.4.2.b</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Arbitrary changes to the system time can be used to obfuscate
nefarious activities in log files, as well as to confuse network services that
are highly dependent upon an accurate system time (such as sshd). All changes
to the system time should be audited.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_time_adjtimex" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
    # Create expected audit group and audit rule form for particular system call &amp; architecture
    if [ ${ARCH} = "b32" ]
    then
        ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
        # stime system call is known at 32-bit arch (see e.g "$ ausyscall i386 stime" 's output)
        # so append it to the list of time group system calls to be audited
        SYSCALL="adjtimex settimeofday stime"
        SYSCALL_GROUPING="adjtimex settimeofday stime"
    elif [ ${ARCH} = "b64" ]
    then
        ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
        # stime system call isn't known at 64-bit arch (see "$ ausyscall x86_64 stime" 's output)
        # therefore don't add it to the list of time group system calls to be audited
        SYSCALL="adjtimex settimeofday"
        SYSCALL_GROUPING="adjtimex settimeofday"
    fi
    OTHER_FILTERS=""
    AUID_FILTERS=""
    KEY="audit_time_rules"
    # Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
    unset syscall_a
    unset syscall_grouping
    unset syscall_string
    unset syscall
    unset file_to_edit
    unset rule_to_edit
    unset rule_syscalls_to_edit
    unset other_string
    unset auid_string
    unset full_rule

    # Load macro arguments into arrays
    read -a syscall_a &lt;&lt;&lt; $SYSCALL
    read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

    # Create a list of audit *.rules files that should be inspected for presence and correctness
    # of a particular audit rule. The scheme is as follows:
    #
    # -----------------------------------------------------------------------------------------
    #  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
    # -----------------------------------------------------------------------------------------
    #        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
    # -----------------------------------------------------------------------------------------
    #        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
    #        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
    # -----------------------------------------------------------------------------------------
    #
    files_to_inspect=()

    # If audit tool is 'augenrules', then check if the audit rule is defined
    # If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
    # If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
    default_file="/etc/audit/rules.d/$KEY.rules"
    # As other_filters may include paths, lets use a different delimiter for it
    # The "F" script expression tells sed to print the filenames where the expressions matched
    readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
    # Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
    if [ ${#files_to_inspect[@]} -eq "0" ]
    then
        file_to_inspect="/etc/audit/rules.d/$KEY.rules"
        files_to_inspect=("$file_to_inspect")
        if [ ! -e "$file_to_inspect" ]
        then
            touch "$file_to_inspect"
            chmod 0600 "$file_to_inspect"
        fi
    fi

    # After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
    skip=1

    for audit_file in "${files_to_inspect[@]}"
    do
        # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
        # i.e, collect rules that match:
        # * the action, list and arch, (2-nd argument)
        # * the other filters, (3-rd argument)
        # * the auid filters, (4-rd argument)
        readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

        candidate_rules=()
        # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
        for s_rule in "${similar_rules[@]}"
        do
            # Strip all the options and fields we know of,
            # than check if there was any field left over
            extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
            grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
        done

        if [[ ${#syscall_a[@]} -ge 1 ]]
        then
            # Check if the syscall we want is present in any of the similar existing rules
            for rule in "${candidate_rules[@]}"
            do
                rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
                all_syscalls_found=0
                for syscall in "${syscall_a[@]}"
                do
                    grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                       # A syscall was not found in the candidate rule
                       all_syscalls_found=1
                       }
                done
                if [[ $all_syscalls_found -eq 0 ]]
                then
                    # We found a rule with all the syscall(s) we want; skip rest of macro
                    skip=0
                    break
                fi

                # Check if this rule can be grouped with our target syscall and keep track of it
                for syscall_g in "${syscall_grouping[@]}"
                do
                    if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                    then
                        file_to_edit=${audit_file}
                        rule_to_edit=${rule}
                        rule_syscalls_to_edit=${rule_syscalls}
                    fi
                done
            done
        else
            # If there is any candidate rule, it is compliant; skip rest of macro
            if [ "${#candidate_rules[@]}" -gt 0 ]
            then
                skip=0
            fi
        fi

        if [ "$skip" -eq 0 ]; then
            break
        fi
    done

    if [ "$skip" -ne 0 ]; then
        # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
        # At this point we know if we need to either append the $full_rule or group
        # the syscall together with an exsiting rule

        # Append the full_rule if it cannot be grouped to any other rule
        if [ -z ${rule_to_edit+x} ]
        then
            # Build full_rule while avoid adding double spaces when other_filters is empty
            if [ "${#syscall_a[@]}" -gt 0 ]
            then
                syscall_string=""
                for syscall in "${syscall_a[@]}"
                do
                    syscall_string+=" -S $syscall"
                done
            fi
            other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
            auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
            full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
            echo "$full_rule" &gt;&gt; "$default_file"
            chmod 0600 ${default_file}
        else
            # Check if the syscalls are declared as a comma separated list or
            # as multiple -S parameters
            if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
            then
                delimiter=","
            else
                delimiter=" -S "
            fi
            new_grouped_syscalls="${rule_syscalls_to_edit}"
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
                   # A syscall was not found in the candidate rule
                   new_grouped_syscalls+="${delimiter}${syscall}"
                   }
            done

            # Group the syscall in the rule
            sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
        fi
    fi
    unset syscall_a
    unset syscall_grouping
    unset syscall_string
    unset syscall
    unset file_to_edit
    unset rule_to_edit
    unset rule_syscalls_to_edit
    unset other_string
    unset auid_string
    unset full_rule

    # Load macro arguments into arrays
    read -a syscall_a &lt;&lt;&lt; $SYSCALL
    read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

    # Create a list of audit *.rules files that should be inspected for presence and correctness
    # of a particular audit rule. The scheme is as follows:
    #
    # -----------------------------------------------------------------------------------------
    #  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
    # -----------------------------------------------------------------------------------------
    #        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
    # -----------------------------------------------------------------------------------------
    #        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
    #        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
    # -----------------------------------------------------------------------------------------
    #
    files_to_inspect=()


    # If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
    # file to the list of files to be inspected
    default_file="/etc/audit/audit.rules"
    files_to_inspect+=('/etc/audit/audit.rules' )

    # After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
    skip=1

    for audit_file in "${files_to_inspect[@]}"
    do
        # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
        # i.e, collect rules that match:
        # * the action, list and arch, (2-nd argument)
        # * the other filters, (3-rd argument)
        # * the auid filters, (4-rd argument)
        readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

        candidate_rules=()
        # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
        for s_rule in "${similar_rules[@]}"
        do
            # Strip all the options and fields we know of,
            # than check if there was any field left over
            extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
            grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
        done

        if [[ ${#syscall_a[@]} -ge 1 ]]
        then
            # Check if the syscall we want is present in any of the similar existing rules
            for rule in "${candidate_rules[@]}"
            do
                rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
                all_syscalls_found=0
                for syscall in "${syscall_a[@]}"
                do
                    grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                       # A syscall was not found in the candidate rule
                       all_syscalls_found=1
                       }
                done
                if [[ $all_syscalls_found -eq 0 ]]
                then
                    # We found a rule with all the syscall(s) we want; skip rest of macro
                    skip=0
                    break
                fi

                # Check if this rule can be grouped with our target syscall and keep track of it
                for syscall_g in "${syscall_grouping[@]}"
                do
                    if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                    then
                        file_to_edit=${audit_file}
                        rule_to_edit=${rule}
                        rule_syscalls_to_edit=${rule_syscalls}
                    fi
                done
            done
        else
            # If there is any candidate rule, it is compliant; skip rest of macro
            if [ "${#candidate_rules[@]}" -gt 0 ]
            then
                skip=0
            fi
        fi

        if [ "$skip" -eq 0 ]; then
            break
        fi
    done

    if [ "$skip" -ne 0 ]; then
        # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
        # At this point we know if we need to either append the $full_rule or group
        # the syscall together with an exsiting rule

        # Append the full_rule if it cannot be grouped to any other rule
        if [ -z ${rule_to_edit+x} ]
        then
            # Build full_rule while avoid adding double spaces when other_filters is empty
            if [ "${#syscall_a[@]}" -gt 0 ]
            then
                syscall_string=""
                for syscall in "${syscall_a[@]}"
                do
                    syscall_string+=" -S $syscall"
                done
            fi
            other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
            auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
            full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
            echo "$full_rule" &gt;&gt; "$default_file"
            chmod 0600 ${default_file}
        else
            # Check if the syscalls are declared as a comma separated list or
            # as multiple -S parameters
            if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
            then
                delimiter=","
            else
                delimiter=" -S "
            fi
            new_grouped_syscalls="${rule_syscalls_to_edit}"
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
                   # A syscall was not found in the candidate rule
                   new_grouped_syscalls+="${delimiter}${syscall}"
                   }
            done

            # Group the syscall in the rule
            sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
        fi
    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_time_adjtimex" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_adjtimex
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set architecture for audit tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_adjtimex
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Perform remediation of Audit rules for adjtimex for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - adjtimex
      syscall_grouping:
      - adjtimex
      - settimeofday
      - stime

  - name: Check existence of adjtimex in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/audit_time_rules.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/audit_time_rules.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F key=audit_time_rules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - adjtimex
      syscall_grouping:
      - adjtimex
      - settimeofday
      - stime

  - name: Check existence of adjtimex in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F key=audit_time_rules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_adjtimex
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Perform remediation of Audit rules for adjtimex for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - adjtimex
      syscall_grouping:
      - adjtimex
      - settimeofday

  - name: Check existence of adjtimex in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/audit_time_rules.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/audit_time_rules.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F key=audit_time_rules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - adjtimex
      syscall_grouping:
      - adjtimex
      - settimeofday
      - stime

  - name: Check existence of adjtimex in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F key=audit_time_rules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_adjtimex
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_time_adjtimex" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ -a%20always%2Cexit%20-F%20arch%3Db64%20-S%20adjtimex%20-k%20audit_time_rules%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20adjtimex%20-k%20audit_time_rules%0A }}
        mode: 0600
        path: /etc/audit/rules.d/75-syscall-adjtimex.rules
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_time_adjtimex:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_time_adjtimex_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_time_clock_settime" selected="false" severity="medium">
              <xccdf-1.2:title>Record Attempts to Alter Time Through clock_settime</xccdf-1.2:title>
              <xccdf-1.2:description>If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following line to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S clock_settime -F a0=0x0 -F key=time-change</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S clock_settime -F a0=0x0 -F key=time-change</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S clock_settime -F a0=0x0 -F key=time-change</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S clock_settime -F a0=0x0 -F key=time-change</html:pre>
The -k option allows for the specification of a key in string form that can
be used for better reporting capability through ausearch and aureport.
Multiple system calls can be defined on the same line to save space if
desired, but is not required. See an example of multiple combined syscalls:
<html:pre>-a always,exit -F arch=b64 -S adjtimex,settimeofday -F key=audit_time_rules</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.4.2.b</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Arbitrary changes to the system time can be used to obfuscate
nefarious activities in log files, as well as to confuse network services that
are highly dependent upon an accurate system time (such as sshd). All changes
to the system time should be audited.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_time_clock_settime" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# First perform the remediation of the syscall rule
# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
	ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
	OTHER_FILTERS="-F a0=0x0"
	AUID_FILTERS=""
	SYSCALL="clock_settime"
	KEY="time-change"
	SYSCALL_GROUPING=""
	# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()

# If audit tool is 'augenrules', then check if the audit rule is defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
# If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
default_file="/etc/audit/rules.d/$KEY.rules"
# As other_filters may include paths, lets use a different delimiter for it
# The "F" script expression tells sed to print the filenames where the expressions matched
readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
# Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
if [ ${#files_to_inspect[@]} -eq "0" ]
then
    file_to_inspect="/etc/audit/rules.d/$KEY.rules"
    files_to_inspect=("$file_to_inspect")
    if [ ! -e "$file_to_inspect" ]
    then
        touch "$file_to_inspect"
        chmod 0600 "$file_to_inspect"
    fi
fi

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
	unset syscall_a
unset syscall_grouping
unset syscall_string
unset syscall
unset file_to_edit
unset rule_to_edit
unset rule_syscalls_to_edit
unset other_string
unset auid_string
unset full_rule

# Load macro arguments into arrays
read -a syscall_a &lt;&lt;&lt; $SYSCALL
read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
#  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
# -----------------------------------------------------------------------------------------
#        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
# -----------------------------------------------------------------------------------------
#        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
#        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
#
files_to_inspect=()


# If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# file to the list of files to be inspected
default_file="/etc/audit/audit.rules"
files_to_inspect+=('/etc/audit/audit.rules' )

# After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
skip=1

for audit_file in "${files_to_inspect[@]}"
do
    # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
    # i.e, collect rules that match:
    # * the action, list and arch, (2-nd argument)
    # * the other filters, (3-rd argument)
    # * the auid filters, (4-rd argument)
    readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

    candidate_rules=()
    # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
    for s_rule in "${similar_rules[@]}"
    do
        # Strip all the options and fields we know of,
        # than check if there was any field left over
        extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
        grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
    done

    if [[ ${#syscall_a[@]} -ge 1 ]]
    then
        # Check if the syscall we want is present in any of the similar existing rules
        for rule in "${candidate_rules[@]}"
        do
            rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
            all_syscalls_found=0
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                   # A syscall was not found in the candidate rule
                   all_syscalls_found=1
                   }
            done
            if [[ $all_syscalls_found -eq 0 ]]
            then
                # We found a rule with all the syscall(s) we want; skip rest of macro
                skip=0
                break
            fi

            # Check if this rule can be grouped with our target syscall and keep track of it
            for syscall_g in "${syscall_grouping[@]}"
            do
                if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                then
                    file_to_edit=${audit_file}
                    rule_to_edit=${rule}
                    rule_syscalls_to_edit=${rule_syscalls}
                fi
            done
        done
    else
        # If there is any candidate rule, it is compliant; skip rest of macro
        if [ "${#candidate_rules[@]}" -gt 0 ]
        then
            skip=0
        fi
    fi

    if [ "$skip" -eq 0 ]; then
        break
    fi
done

if [ "$skip" -ne 0 ]; then
    # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
    # At this point we know if we need to either append the $full_rule or group
    # the syscall together with an exsiting rule

    # Append the full_rule if it cannot be grouped to any other rule
    if [ -z ${rule_to_edit+x} ]
    then
        # Build full_rule while avoid adding double spaces when other_filters is empty
        if [ "${#syscall_a[@]}" -gt 0 ]
        then
            syscall_string=""
            for syscall in "${syscall_a[@]}"
            do
                syscall_string+=" -S $syscall"
            done
        fi
        other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
        auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
        full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
        echo "$full_rule" &gt;&gt; "$default_file"
        chmod 0600 ${default_file}
    else
        # Check if the syscalls are declared as a comma separated list or
        # as multiple -S parameters
        if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
        then
            delimiter=","
        else
            delimiter=" -S "
        fi
        new_grouped_syscalls="${rule_syscalls_to_edit}"
        for syscall in "${syscall_a[@]}"
        do
            grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
               # A syscall was not found in the candidate rule
               new_grouped_syscalls+="${delimiter}${syscall}"
               }
        done

        # Group the syscall in the rule
        sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
    fi
fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_time_clock_settime" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_clock_settime
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set architecture for audit tasks
  ansible.builtin.set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_clock_settime
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Perform remediation of Audit rules for clock_settime for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - clock_settime
      syscall_grouping: []

  - name: Check existence of clock_settime in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a0=0x0 (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/time-change.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/time-change.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a0=0x0 (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a0=0x0 -F
        key=time-change
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - clock_settime
      syscall_grouping: []

  - name: Check existence of clock_settime in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a0=0x0 (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a0=0x0 (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F a0=0x0 -F
        key=time-change
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_clock_settime
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Perform remediation of Audit rules for clock_settime for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - clock_settime
      syscall_grouping: []

  - name: Check existence of clock_settime in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a0=0x0 (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/time-change.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/time-change.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( -F a0=0x0 (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a0=0x0 -F
        key=time-change
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - clock_settime
      syscall_grouping: []

  - name: Check existence of clock_settime in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* -F a0=0x0 (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( -F a0=0x0 (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F a0=0x0 -F
        key=time-change
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_clock_settime
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_time_clock_settime" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ -a%20always%2Cexit%20-F%20arch%3Db64%20-S%20clock_settime%20-F%20a0%3D0x0%20-k%20time-change%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20clock_settime%20-F%20a0%3D0x0%20-k%20time-change%0A }}
        mode: 0600
        path: /etc/audit/rules.d/75-syscall-clock-settime.rules
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_time_clock_settime:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_time_clock_settime_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_time_settimeofday" selected="false" severity="medium">
              <xccdf-1.2:title>Record attempts to alter time through settimeofday</xccdf-1.2:title>
              <xccdf-1.2:description>If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following line to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:
<html:pre>-a always,exit -F arch=b32 -S settimeofday -F key=audit_time_rules</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S settimeofday -F key=audit_time_rules</html:pre>
If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file:
<html:pre>-a always,exit -F arch=b32 -S settimeofday -F key=audit_time_rules</html:pre>
If the system is 64 bit then also add the following line:
<html:pre>-a always,exit -F arch=b64 -S settimeofday -F key=audit_time_rules</html:pre>
The -k option allows for the specification of a key in string form that can be
used for better reporting capability through ausearch and aureport. Multiple
system calls can be defined on the same line to save space if desired, but is
not required. See an example of multiple combined syscalls:
<html:pre>-a always,exit -F arch=b64 -S adjtimex,settimeofday -F key=audit_time_rules</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.4.2.b</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Arbitrary changes to the system time can be used to obfuscate
nefarious activities in log files, as well as to confuse network services that
are highly dependent upon an accurate system time (such as sshd). All changes
to the system time should be audited.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_time_settimeofday" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
    # Create expected audit group and audit rule form for particular system call &amp; architecture
    if [ ${ARCH} = "b32" ]
    then
        ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
        # stime system call is known at 32-bit arch (see e.g "$ ausyscall i386 stime" 's output)
        # so append it to the list of time group system calls to be audited
        SYSCALL="adjtimex settimeofday stime"
        SYSCALL_GROUPING="adjtimex settimeofday stime"
    elif [ ${ARCH} = "b64" ]
    then
        ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
        # stime system call isn't known at 64-bit arch (see "$ ausyscall x86_64 stime" 's output)
        # therefore don't add it to the list of time group system calls to be audited
        SYSCALL="adjtimex settimeofday"
        SYSCALL_GROUPING="adjtimex settimeofday"
    fi
    OTHER_FILTERS=""
    AUID_FILTERS=""
    KEY="audit_time_rules"
    # Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
    unset syscall_a
    unset syscall_grouping
    unset syscall_string
    unset syscall
    unset file_to_edit
    unset rule_to_edit
    unset rule_syscalls_to_edit
    unset other_string
    unset auid_string
    unset full_rule

    # Load macro arguments into arrays
    read -a syscall_a &lt;&lt;&lt; $SYSCALL
    read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

    # Create a list of audit *.rules files that should be inspected for presence and correctness
    # of a particular audit rule. The scheme is as follows:
    #
    # -----------------------------------------------------------------------------------------
    #  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
    # -----------------------------------------------------------------------------------------
    #        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
    # -----------------------------------------------------------------------------------------
    #        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
    #        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
    # -----------------------------------------------------------------------------------------
    #
    files_to_inspect=()

    # If audit tool is 'augenrules', then check if the audit rule is defined
    # If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
    # If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
    default_file="/etc/audit/rules.d/$KEY.rules"
    # As other_filters may include paths, lets use a different delimiter for it
    # The "F" script expression tells sed to print the filenames where the expressions matched
    readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
    # Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
    if [ ${#files_to_inspect[@]} -eq "0" ]
    then
        file_to_inspect="/etc/audit/rules.d/$KEY.rules"
        files_to_inspect=("$file_to_inspect")
        if [ ! -e "$file_to_inspect" ]
        then
            touch "$file_to_inspect"
            chmod 0600 "$file_to_inspect"
        fi
    fi

    # After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
    skip=1

    for audit_file in "${files_to_inspect[@]}"
    do
        # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
        # i.e, collect rules that match:
        # * the action, list and arch, (2-nd argument)
        # * the other filters, (3-rd argument)
        # * the auid filters, (4-rd argument)
        readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

        candidate_rules=()
        # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
        for s_rule in "${similar_rules[@]}"
        do
            # Strip all the options and fields we know of,
            # than check if there was any field left over
            extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
            grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
        done

        if [[ ${#syscall_a[@]} -ge 1 ]]
        then
            # Check if the syscall we want is present in any of the similar existing rules
            for rule in "${candidate_rules[@]}"
            do
                rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
                all_syscalls_found=0
                for syscall in "${syscall_a[@]}"
                do
                    grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                       # A syscall was not found in the candidate rule
                       all_syscalls_found=1
                       }
                done
                if [[ $all_syscalls_found -eq 0 ]]
                then
                    # We found a rule with all the syscall(s) we want; skip rest of macro
                    skip=0
                    break
                fi

                # Check if this rule can be grouped with our target syscall and keep track of it
                for syscall_g in "${syscall_grouping[@]}"
                do
                    if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                    then
                        file_to_edit=${audit_file}
                        rule_to_edit=${rule}
                        rule_syscalls_to_edit=${rule_syscalls}
                    fi
                done
            done
        else
            # If there is any candidate rule, it is compliant; skip rest of macro
            if [ "${#candidate_rules[@]}" -gt 0 ]
            then
                skip=0
            fi
        fi

        if [ "$skip" -eq 0 ]; then
            break
        fi
    done

    if [ "$skip" -ne 0 ]; then
        # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
        # At this point we know if we need to either append the $full_rule or group
        # the syscall together with an exsiting rule

        # Append the full_rule if it cannot be grouped to any other rule
        if [ -z ${rule_to_edit+x} ]
        then
            # Build full_rule while avoid adding double spaces when other_filters is empty
            if [ "${#syscall_a[@]}" -gt 0 ]
            then
                syscall_string=""
                for syscall in "${syscall_a[@]}"
                do
                    syscall_string+=" -S $syscall"
                done
            fi
            other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
            auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
            full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
            echo "$full_rule" &gt;&gt; "$default_file"
            chmod 0600 ${default_file}
        else
            # Check if the syscalls are declared as a comma separated list or
            # as multiple -S parameters
            if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
            then
                delimiter=","
            else
                delimiter=" -S "
            fi
            new_grouped_syscalls="${rule_syscalls_to_edit}"
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
                   # A syscall was not found in the candidate rule
                   new_grouped_syscalls+="${delimiter}${syscall}"
                   }
            done

            # Group the syscall in the rule
            sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
        fi
    fi
    unset syscall_a
    unset syscall_grouping
    unset syscall_string
    unset syscall
    unset file_to_edit
    unset rule_to_edit
    unset rule_syscalls_to_edit
    unset other_string
    unset auid_string
    unset full_rule

    # Load macro arguments into arrays
    read -a syscall_a &lt;&lt;&lt; $SYSCALL
    read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

    # Create a list of audit *.rules files that should be inspected for presence and correctness
    # of a particular audit rule. The scheme is as follows:
    #
    # -----------------------------------------------------------------------------------------
    #  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
    # -----------------------------------------------------------------------------------------
    #        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
    # -----------------------------------------------------------------------------------------
    #        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
    #        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
    # -----------------------------------------------------------------------------------------
    #
    files_to_inspect=()


    # If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
    # file to the list of files to be inspected
    default_file="/etc/audit/audit.rules"
    files_to_inspect+=('/etc/audit/audit.rules' )

    # After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
    skip=1

    for audit_file in "${files_to_inspect[@]}"
    do
        # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
        # i.e, collect rules that match:
        # * the action, list and arch, (2-nd argument)
        # * the other filters, (3-rd argument)
        # * the auid filters, (4-rd argument)
        readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

        candidate_rules=()
        # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
        for s_rule in "${similar_rules[@]}"
        do
            # Strip all the options and fields we know of,
            # than check if there was any field left over
            extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
            grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
        done

        if [[ ${#syscall_a[@]} -ge 1 ]]
        then
            # Check if the syscall we want is present in any of the similar existing rules
            for rule in "${candidate_rules[@]}"
            do
                rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
                all_syscalls_found=0
                for syscall in "${syscall_a[@]}"
                do
                    grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                       # A syscall was not found in the candidate rule
                       all_syscalls_found=1
                       }
                done
                if [[ $all_syscalls_found -eq 0 ]]
                then
                    # We found a rule with all the syscall(s) we want; skip rest of macro
                    skip=0
                    break
                fi

                # Check if this rule can be grouped with our target syscall and keep track of it
                for syscall_g in "${syscall_grouping[@]}"
                do
                    if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                    then
                        file_to_edit=${audit_file}
                        rule_to_edit=${rule}
                        rule_syscalls_to_edit=${rule_syscalls}
                    fi
                done
            done
        else
            # If there is any candidate rule, it is compliant; skip rest of macro
            if [ "${#candidate_rules[@]}" -gt 0 ]
            then
                skip=0
            fi
        fi

        if [ "$skip" -eq 0 ]; then
            break
        fi
    done

    if [ "$skip" -ne 0 ]; then
        # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
        # At this point we know if we need to either append the $full_rule or group
        # the syscall together with an exsiting rule

        # Append the full_rule if it cannot be grouped to any other rule
        if [ -z ${rule_to_edit+x} ]
        then
            # Build full_rule while avoid adding double spaces when other_filters is empty
            if [ "${#syscall_a[@]}" -gt 0 ]
            then
                syscall_string=""
                for syscall in "${syscall_a[@]}"
                do
                    syscall_string+=" -S $syscall"
                done
            fi
            other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
            auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
            full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
            echo "$full_rule" &gt;&gt; "$default_file"
            chmod 0600 ${default_file}
        else
            # Check if the syscalls are declared as a comma separated list or
            # as multiple -S parameters
            if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
            then
                delimiter=","
            else
                delimiter=" -S "
            fi
            new_grouped_syscalls="${rule_syscalls_to_edit}"
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
                   # A syscall was not found in the candidate rule
                   new_grouped_syscalls+="${delimiter}${syscall}"
                   }
            done

            # Group the syscall in the rule
            sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
        fi
    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_time_settimeofday" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_settimeofday
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set architecture for audit tasks
  set_fact:
    audit_arch: b64
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ansible_architecture == "aarch64" or ansible_architecture == "ppc64" or ansible_architecture
    == "ppc64le" or ansible_architecture == "s390x" or ansible_architecture == "x86_64"
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_settimeofday
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Perform remediation of Audit rules for settimeofday for 32bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - settimeofday
      syscall_grouping:
      - adjtimex
      - settimeofday
      - stime

  - name: Check existence of settimeofday in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/audit_time_rules.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/audit_time_rules.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F key=audit_time_rules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - settimeofday
      syscall_grouping:
      - adjtimex
      - settimeofday
      - stime

  - name: Check existence of settimeofday in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F key=audit_time_rules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_settimeofday
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Perform remediation of Audit rules for settimeofday for 64bit platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - settimeofday
      syscall_grouping:
      - adjtimex
      - settimeofday
      - stime

  - name: Check existence of settimeofday in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/audit_time_rules.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/audit_time_rules.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F key=audit_time_rules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - settimeofday
      syscall_grouping:
      - adjtimex
      - settimeofday
      - stime

  - name: Check existence of settimeofday in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b64(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b64)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b64 -S {{ syscalls | join(',') }} -F key=audit_time_rules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - audit_arch == "b64"
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_settimeofday
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_time_settimeofday" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ -a%20always%2Cexit%20-F%20arch%3Db64%20-S%20settimeofday%20-k%20audit_time_rules%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20settimeofday%20-k%20audit_time_rules%0A }}
        mode: 0600
        path: /etc/audit/rules.d/75-syscall-settimeofday.rules
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_time_settimeofday:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_time_stime" selected="false" severity="medium">
              <xccdf-1.2:title>Record Attempts to Alter Time Through stime</xccdf-1.2:title>
              <xccdf-1.2:description>If the <html:code>auditd</html:code> daemon is configured to use the
<html:code>augenrules</html:code> program to read audit rules during daemon startup (the
default), add the following line to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code> for both 32 bit and 64 bit systems:
<html:pre>-a always,exit -F arch=b32 -S stime -F key=audit_time_rules</html:pre>
Since the 64 bit version of the "stime" system call is not defined in the audit
lookup table, the corresponding "-F arch=b64" form of this rule is not expected
to be defined on 64 bit systems (the aforementioned "-F arch=b32" stime rule
form itself is sufficient for both 32 bit and 64 bit systems). If the
<html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code> utility to
read audit rules during daemon startup, add the following line to
<html:code>/etc/audit/audit.rules</html:code> file for both 32 bit and 64 bit systems:
<html:pre>-a always,exit -F arch=b32 -S stime -F key=audit_time_rules</html:pre>
Since the 64 bit version of the "stime" system call is not defined in the audit
lookup table, the corresponding "-F arch=b64" form of this rule is not expected
to be defined on 64 bit systems (the aforementioned "-F arch=b32" stime rule
form itself is sufficient for both 32 bit and 64 bit systems). The -k option
allows for the specification of a key in string form that can be used for
better reporting capability through ausearch and aureport. Multiple system
calls can be defined on the same line to save space if desired, but is not
required. See an example of multiple combined system calls:
<html:pre>-a always,exit -F arch=b64 -S adjtimex,settimeofday -F key=audit_time_rules</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.4.2.b</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Arbitrary changes to the system time can be used to obfuscate
nefarious activities in log files, as well as to confuse network services that
are highly dependent upon an accurate system time (such as sshd). All changes
to the system time should be audited.</xccdf-1.2:rationale>
              <xccdf-1.2:platform idref="#not_aarch64_arch_and_not_s390x_arch"/>
              <xccdf-1.2:fix id="audit_rules_time_stime" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel &amp;&amp; { ( ( ! ( ( grep -sqE "^.*\.aarch64$" /proc/sys/kernel/osrelease || grep -sqE "^aarch64$" /proc/sys/kernel/arch; ) ) &amp;&amp; ! ( ( grep -sqE "^.*\.s390x$" /proc/sys/kernel/osrelease || grep -sqE "^s390x$" /proc/sys/kernel/arch; ) ) ) ); }; then

# Retrieve hardware architecture of the underlying system
[ "$(getconf LONG_BIT)" = "32" ] &amp;&amp; RULE_ARCHS=("b32") || RULE_ARCHS=("b32" "b64")

for ARCH in "${RULE_ARCHS[@]}"
do
    # Create expected audit group and audit rule form for particular system call &amp; architecture
    if [ ${ARCH} = "b32" ]
    then
        ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
        # stime system call is known at 32-bit arch (see e.g "$ ausyscall i386 stime" 's output)
        # so append it to the list of time group system calls to be audited
        SYSCALL="adjtimex settimeofday stime"
        SYSCALL_GROUPING="adjtimex settimeofday stime"
    elif [ ${ARCH} = "b64" ]
    then
        ACTION_ARCH_FILTERS="-a always,exit -F arch=$ARCH"
        # stime system call isn't known at 64-bit arch (see "$ ausyscall x86_64 stime" 's output)
        # therefore don't add it to the list of time group system calls to be audited
        SYSCALL="adjtimex settimeofday"
        SYSCALL_GROUPING="adjtimex settimeofday"
    fi
    OTHER_FILTERS=""
    AUID_FILTERS=""
    KEY="audit_time_rules"
    # Perform the remediation for both possible tools: 'auditctl' and 'augenrules'
    unset syscall_a
    unset syscall_grouping
    unset syscall_string
    unset syscall
    unset file_to_edit
    unset rule_to_edit
    unset rule_syscalls_to_edit
    unset other_string
    unset auid_string
    unset full_rule

    # Load macro arguments into arrays
    read -a syscall_a &lt;&lt;&lt; $SYSCALL
    read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

    # Create a list of audit *.rules files that should be inspected for presence and correctness
    # of a particular audit rule. The scheme is as follows:
    #
    # -----------------------------------------------------------------------------------------
    #  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
    # -----------------------------------------------------------------------------------------
    #        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
    # -----------------------------------------------------------------------------------------
    #        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
    #        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
    # -----------------------------------------------------------------------------------------
    #
    files_to_inspect=()

    # If audit tool is 'augenrules', then check if the audit rule is defined
    # If rule is defined, add '/etc/audit/rules.d/*.rules' to the list for inspection
    # If rule isn't defined yet, add '/etc/audit/rules.d/$key.rules' to the list for inspection
    default_file="/etc/audit/rules.d/$KEY.rules"
    # As other_filters may include paths, lets use a different delimiter for it
    # The "F" script expression tells sed to print the filenames where the expressions matched
    readarray -t files_to_inspect &lt; &lt;(sed -s -n -e "/^$ACTION_ARCH_FILTERS/!d" -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" -e "F" /etc/audit/rules.d/*.rules)
    # Case when particular rule isn't defined in /etc/audit/rules.d/*.rules yet
    if [ ${#files_to_inspect[@]} -eq "0" ]
    then
        file_to_inspect="/etc/audit/rules.d/$KEY.rules"
        files_to_inspect=("$file_to_inspect")
        if [ ! -e "$file_to_inspect" ]
        then
            touch "$file_to_inspect"
            chmod 0600 "$file_to_inspect"
        fi
    fi

    # After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
    skip=1

    for audit_file in "${files_to_inspect[@]}"
    do
        # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
        # i.e, collect rules that match:
        # * the action, list and arch, (2-nd argument)
        # * the other filters, (3-rd argument)
        # * the auid filters, (4-rd argument)
        readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

        candidate_rules=()
        # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
        for s_rule in "${similar_rules[@]}"
        do
            # Strip all the options and fields we know of,
            # than check if there was any field left over
            extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
            grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
        done

        if [[ ${#syscall_a[@]} -ge 1 ]]
        then
            # Check if the syscall we want is present in any of the similar existing rules
            for rule in "${candidate_rules[@]}"
            do
                rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
                all_syscalls_found=0
                for syscall in "${syscall_a[@]}"
                do
                    grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                       # A syscall was not found in the candidate rule
                       all_syscalls_found=1
                       }
                done
                if [[ $all_syscalls_found -eq 0 ]]
                then
                    # We found a rule with all the syscall(s) we want; skip rest of macro
                    skip=0
                    break
                fi

                # Check if this rule can be grouped with our target syscall and keep track of it
                for syscall_g in "${syscall_grouping[@]}"
                do
                    if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                    then
                        file_to_edit=${audit_file}
                        rule_to_edit=${rule}
                        rule_syscalls_to_edit=${rule_syscalls}
                    fi
                done
            done
        else
            # If there is any candidate rule, it is compliant; skip rest of macro
            if [ "${#candidate_rules[@]}" -gt 0 ]
            then
                skip=0
            fi
        fi

        if [ "$skip" -eq 0 ]; then
            break
        fi
    done

    if [ "$skip" -ne 0 ]; then
        # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
        # At this point we know if we need to either append the $full_rule or group
        # the syscall together with an exsiting rule

        # Append the full_rule if it cannot be grouped to any other rule
        if [ -z ${rule_to_edit+x} ]
        then
            # Build full_rule while avoid adding double spaces when other_filters is empty
            if [ "${#syscall_a[@]}" -gt 0 ]
            then
                syscall_string=""
                for syscall in "${syscall_a[@]}"
                do
                    syscall_string+=" -S $syscall"
                done
            fi
            other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
            auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
            full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
            echo "$full_rule" &gt;&gt; "$default_file"
            chmod 0600 ${default_file}
        else
            # Check if the syscalls are declared as a comma separated list or
            # as multiple -S parameters
            if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
            then
                delimiter=","
            else
                delimiter=" -S "
            fi
            new_grouped_syscalls="${rule_syscalls_to_edit}"
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
                   # A syscall was not found in the candidate rule
                   new_grouped_syscalls+="${delimiter}${syscall}"
                   }
            done

            # Group the syscall in the rule
            sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
        fi
    fi
    unset syscall_a
    unset syscall_grouping
    unset syscall_string
    unset syscall
    unset file_to_edit
    unset rule_to_edit
    unset rule_syscalls_to_edit
    unset other_string
    unset auid_string
    unset full_rule

    # Load macro arguments into arrays
    read -a syscall_a &lt;&lt;&lt; $SYSCALL
    read -a syscall_grouping &lt;&lt;&lt; $SYSCALL_GROUPING

    # Create a list of audit *.rules files that should be inspected for presence and correctness
    # of a particular audit rule. The scheme is as follows:
    #
    # -----------------------------------------------------------------------------------------
    #  Tool used to load audit rules | Rule already defined  |  Audit rules file to inspect    |
    # -----------------------------------------------------------------------------------------
    #        auditctl                |     Doesn't matter    |  /etc/audit/audit.rules         |
    # -----------------------------------------------------------------------------------------
    #        augenrules              |          Yes          |  /etc/audit/rules.d/*.rules     |
    #        augenrules              |          No           |  /etc/audit/rules.d/$key.rules  |
    # -----------------------------------------------------------------------------------------
    #
    files_to_inspect=()


    # If audit tool is 'auditctl', then add '/etc/audit/audit.rules'
    # file to the list of files to be inspected
    default_file="/etc/audit/audit.rules"
    files_to_inspect+=('/etc/audit/audit.rules' )

    # After converting to jinja, we cannot return; therefore we skip the rest of the macro if needed instead
    skip=1

    for audit_file in "${files_to_inspect[@]}"
    do
        # Filter existing $audit_file rules' definitions to select those that satisfy the rule pattern,
        # i.e, collect rules that match:
        # * the action, list and arch, (2-nd argument)
        # * the other filters, (3-rd argument)
        # * the auid filters, (4-rd argument)
        readarray -t similar_rules &lt; &lt;(sed -e "/^$ACTION_ARCH_FILTERS/!d"  -e "\#$OTHER_FILTERS#!d" -e "/$AUID_FILTERS/!d" "$audit_file")

        candidate_rules=()
        # Filter out rules that have more fields then required. This will remove rules more specific than the required scope
        for s_rule in "${similar_rules[@]}"
        do
            # Strip all the options and fields we know of,
            # than check if there was any field left over
            extra_fields=$(sed -E -e "s/^$ACTION_ARCH_FILTERS//"  -e "s#$OTHER_FILTERS##" -e "s/$AUID_FILTERS//" -e "s/((:?-S [[:alnum:],]+)+)//g" -e "s/-F key=\w+|-k \w+//"&lt;&lt;&lt; "$s_rule")
            grep -q -- "-F" &lt;&lt;&lt; "$extra_fields" || candidate_rules+=("$s_rule")
        done

        if [[ ${#syscall_a[@]} -ge 1 ]]
        then
            # Check if the syscall we want is present in any of the similar existing rules
            for rule in "${candidate_rules[@]}"
            do
                rule_syscalls=$(echo "$rule" | grep -o -P '(-S [\w,]+)+' | xargs)
                all_syscalls_found=0
                for syscall in "${syscall_a[@]}"
                do
                    grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "$rule_syscalls" || {
                       # A syscall was not found in the candidate rule
                       all_syscalls_found=1
                       }
                done
                if [[ $all_syscalls_found -eq 0 ]]
                then
                    # We found a rule with all the syscall(s) we want; skip rest of macro
                    skip=0
                    break
                fi

                # Check if this rule can be grouped with our target syscall and keep track of it
                for syscall_g in "${syscall_grouping[@]}"
                do
                    if grep -q -- "\b${syscall_g}\b" &lt;&lt;&lt; "$rule_syscalls"
                    then
                        file_to_edit=${audit_file}
                        rule_to_edit=${rule}
                        rule_syscalls_to_edit=${rule_syscalls}
                    fi
                done
            done
        else
            # If there is any candidate rule, it is compliant; skip rest of macro
            if [ "${#candidate_rules[@]}" -gt 0 ]
            then
                skip=0
            fi
        fi

        if [ "$skip" -eq 0 ]; then
            break
        fi
    done

    if [ "$skip" -ne 0 ]; then
        # We checked all rules that matched the expected resemblance pattern (action, arch &amp; auid)
        # At this point we know if we need to either append the $full_rule or group
        # the syscall together with an exsiting rule

        # Append the full_rule if it cannot be grouped to any other rule
        if [ -z ${rule_to_edit+x} ]
        then
            # Build full_rule while avoid adding double spaces when other_filters is empty
            if [ "${#syscall_a[@]}" -gt 0 ]
            then
                syscall_string=""
                for syscall in "${syscall_a[@]}"
                do
                    syscall_string+=" -S $syscall"
                done
            fi
            other_string=$([[ $OTHER_FILTERS ]] &amp;&amp; echo " $OTHER_FILTERS") || /bin/true
            auid_string=$([[ $AUID_FILTERS ]] &amp;&amp; echo " $AUID_FILTERS") || /bin/true
            full_rule="$ACTION_ARCH_FILTERS${syscall_string}${other_string}${auid_string} -F key=$KEY" || /bin/true
            echo "$full_rule" &gt;&gt; "$default_file"
            chmod 0600 ${default_file}
        else
            # Check if the syscalls are declared as a comma separated list or
            # as multiple -S parameters
            if grep -q -- "," &lt;&lt;&lt; "${rule_syscalls_to_edit}"
            then
                delimiter=","
            else
                delimiter=" -S "
            fi
            new_grouped_syscalls="${rule_syscalls_to_edit}"
            for syscall in "${syscall_a[@]}"
            do
                grep -q -- "\b${syscall}\b" &lt;&lt;&lt; "${rule_syscalls_to_edit}" || {
                   # A syscall was not found in the candidate rule
                   new_grouped_syscalls+="${delimiter}${syscall}"
                   }
            done

            # Group the syscall in the rule
            sed -i -e "\#${rule_to_edit}#s#${rule_syscalls_to_edit}#${new_grouped_syscalls}#" "$file_to_edit"
        fi
    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_time_stime" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_stime
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Perform remediation of Audit rules for stime syscall for x86 platform
  block:

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - stime
      syscall_grouping:
      - adjtimex
      - settimeofday
      - stime

  - name: Check existence of stime in /etc/audit/rules.d/
    ansible.builtin.find:
      paths: /etc/audit/rules.d
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* (-k\s+|-F\s+key=)\S+\s*$
      patterns: '*.rules'
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Reset syscalls found per file
    ansible.builtin.set_fact:
      syscalls_per_file: {}
      found_paths_dict: {}

  - name: Declare syscalls found per file
    ansible.builtin.set_fact: syscalls_per_file="{{ syscalls_per_file | combine( {item.files[0].path
      :[item.item] + syscalls_per_file.get(item.files[0].path, []) } ) }}"
    loop: '{{ find_command.results | selectattr(''matched'') | list }}'

  - name: Declare files where syscalls were found
    ansible.builtin.set_fact: found_paths="{{ find_command.results | map(attribute='files')
      | flatten | map(attribute='path') | list }}"

  - name: Count occurrences of syscalls in paths
    ansible.builtin.set_fact: found_paths_dict="{{ found_paths_dict | combine({ item:1+found_paths_dict.get(item,
      0) }) }}"
    loop: '{{ find_command.results | map(attribute=''files'') | flatten | map(attribute=''path'')
      | list }}'

  - name: Get path with most syscalls
    ansible.builtin.set_fact: audit_file="{{ (found_paths_dict | dict2items() | sort(attribute='value')
      | last).key }}"
    when: found_paths | length &gt;= 1

  - name: No file with syscall found, set path to /etc/audit/rules.d/audit_time_rules.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/rules.d/audit_time_rules.rules"
    when: found_paths | length == 0

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_per_file[audit_file]
        | join("|") }}))\b)((?:( -S |,)\w+)+)( (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F key=audit_time_rules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0

  - name: Declare list of syscalls
    ansible.builtin.set_fact:
      syscalls:
      - stime
      syscall_grouping:
      - adjtimex
      - settimeofday
      - stime

  - name: Check existence of stime in /etc/audit/audit.rules
    ansible.builtin.find:
      paths: /etc/audit
      contains: -a always,exit -F arch=b32(( -S |,)\w+)*(( -S |,){{ item }})+(( -S
        |,)\w+)* (-k\s+|-F\s+key=)\S+\s*$
      patterns: audit.rules
    register: find_command
    loop: '{{ (syscall_grouping + syscalls) | unique }}'

  - name: Set path to /etc/audit/audit.rules
    ansible.builtin.set_fact: audit_file="/etc/audit/audit.rules"

  - name: Declare found syscalls
    ansible.builtin.set_fact: syscalls_found="{{ find_command.results | selectattr('matched')
      | map(attribute='item') | list }}"

  - name: Declare missing syscalls
    ansible.builtin.set_fact: missing_syscalls="{{ syscalls | difference(syscalls_found)
      }}"

  - name: Replace the audit rule in {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      regexp: (-a always,exit -F arch=b32)(?=.*(?:(?:-S |,)(?:{{ syscalls_found |
        join("|") }}))\b)((?:( -S |,)\w+)+)( (?:-k |-F key=)\w+)
      line: \1\2\3{{ missing_syscalls | join("\3") }}\4
      backrefs: true
      state: present
      mode: g-rwx,o-rwx
    when: syscalls_found | length &gt; 0 and missing_syscalls | length &gt; 0

  - name: Add the audit rule to {{ audit_file }}
    ansible.builtin.lineinfile:
      path: '{{ audit_file }}'
      line: -a always,exit -F arch=b32 -S {{ syscalls | join(',') }} -F key=audit_time_rules
      create: true
      mode: g-rwx,o-rwx
      state: present
    when: syscalls_found | length == 0
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - ( not ( ansible_architecture == "aarch64" ) and not ( ansible_architecture ==
    "s390x" ) )
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_stime
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_time_stime" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ -a%20always%2Cexit%20-F%20arch%3Db64%20-S%20stime%20-k%20audit_time_rules%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20stime%20-k%20audit_time_rules%0A }}
        mode: 0600
        path: /etc/audit/rules.d/75-syscall-stime.rules
        overwrite: true
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_time_stime:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
            <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_time_watch_localtime" selected="false" severity="medium">
              <xccdf-1.2:title>Record Attempts to Alter the localtime File</xccdf-1.2:title>
              <xccdf-1.2:description>



If the <html:code>auditd</html:code> daemon is configured to use the <html:code>augenrules</html:code>
program to read audit rules during daemon startup (the default), add the
following lines to a file with suffix <html:code>.rules</html:code> in the
directory <html:code>/etc/audit/rules.d</html:code>:

<html:pre>-w /etc/localtime -p wa -k audit_time_rules</html:pre>

If the <html:code>auditd</html:code> daemon is configured to use the <html:code>auditctl</html:code>
utility to read audit rules during daemon startup, add the following lines to
<html:code>/etc/audit/audit.rules</html:code>:

<html:pre>-w /etc/localtime -p wa -k audit_time_rules</html:pre></xccdf-1.2:description>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.6.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 1.13</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 3.8</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 5.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.11.2.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.1.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.13.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.1.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.6.2.2</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(d)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(c)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AC-6(9)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.AC-3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.4.2.b</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R73</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6.3</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.6</xccdf-1.2:reference>
              <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.3.4</xccdf-1.2:reference>
              <xccdf-1.2:rationale>Arbitrary changes to the system time can be used to obfuscate
nefarious activities in log files, as well as to confuse network services that
are highly dependent upon an accurate system time (such as sshd). All changes
to the system time should be audited.</xccdf-1.2:rationale>
              <xccdf-1.2:fix id="audit_rules_time_watch_localtime" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

# Perform the remediation for both possible tools: 'auditctl' and 'augenrules'






# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()


# If the audit tool is 'auditctl', then add '/etc/audit/audit.rules'
# into the list of files to be inspected
files_to_inspect+=('/etc/audit/audit.rules')

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/localtime" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/localtime $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/localtime$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/localtime -p wa -k audit_time_rules" &gt;&gt; "$audit_rules_file"

    fi
done
# Create a list of audit *.rules files that should be inspected for presence and correctness
# of a particular audit rule. The scheme is as follows:
#
# -----------------------------------------------------------------------------------------
# Tool used to load audit rules	| Rule already defined	|  Audit rules file to inspect	  |
# -----------------------------------------------------------------------------------------
#	auditctl		|     Doesn't matter	|  /etc/audit/audit.rules	  |
# -----------------------------------------------------------------------------------------
# 	augenrules		|          Yes		|  /etc/audit/rules.d/*.rules	  |
# 	augenrules		|          No		|  /etc/audit/rules.d/$key.rules  |
# -----------------------------------------------------------------------------------------
files_to_inspect=()

# If the audit is 'augenrules', then check if rule is already defined
# If rule is defined, add '/etc/audit/rules.d/*.rules' to list of files for inspection.
# If rule isn't defined, add '/etc/audit/rules.d/audit_time_rules.rules' to list of files for inspection.

readarray -t matches &lt; &lt;(grep -HP "[\s]*-w[\s]+/etc/localtime" /etc/audit/rules.d/*.rules)


# For each of the matched entries
for match in "${matches[@]}"
do
    # Extract filepath from the match
    rulesd_audit_file=$(echo $match | cut -f1 -d ':')
    # Append that path into list of files for inspection
    files_to_inspect+=("$rulesd_audit_file")
done
# Case when particular audit rule isn't defined yet
if [ "${#files_to_inspect[@]}" -eq "0" ]
then
    # Append '/etc/audit/rules.d/audit_time_rules.rules' into list of files for inspection
    key_rule_file="/etc/audit/rules.d/audit_time_rules.rules"
    # If the audit_time_rules.rules file doesn't exist yet, create it with correct permissions
    if [ ! -e "$key_rule_file" ]
    then
        touch "$key_rule_file"
        chmod 0600 "$key_rule_file"
    fi
    files_to_inspect+=("$key_rule_file")
fi

# Finally perform the inspection and possible subsequent audit rule
# correction for each of the files previously identified for inspection
for audit_rules_file in "${files_to_inspect[@]}"
do
    # Check if audit watch file system object rule for given path already present

    if grep -q -P -- "^[\s]*-w[\s]+/etc/localtime" "$audit_rules_file"

    then
        # Rule is found =&gt; verify yet if existing rule definition contains
        # all of the required access type bits

        # Define BRE whitespace class shortcut
        sp="[[:space:]]"
        # Extract current permission access types (e.g. -p [r|w|x|a] values) from audit rule

        current_access_bits=$(sed -ne "s#$sp*-w$sp\+/etc/localtime $sp\+-p$sp\+\([rxwa]\{1,4\}\).*#\1#p" "$audit_rules_file")

        # Split required access bits string into characters array
        # (to check bit's presence for one bit at a time)
        for access_bit in $(echo "wa" | grep -o .)
        do
            # For each from the required access bits (e.g. 'w', 'a') check
            # if they are already present in current access bits for rule.
            # If not, append that bit at the end
            if ! grep -q "$access_bit" &lt;&lt;&lt; "$current_access_bits"
            then
                # Concatenate the existing mask with the missing bit
                current_access_bits="$current_access_bits$access_bit"
            fi
        done
        # Propagate the updated rule's access bits (original + the required
        # ones) back into the /etc/audit/audit.rules file for that rule

        sed -i "s#\($sp*-w$sp\+/etc/localtime$sp\+-p$sp\+\)\([rxwa]\{1,4\}\)\(.*\)#\1$current_access_bits\3#" "$audit_rules_file"

    else
        # Rule isn't present yet. Append it at the end of $audit_rules_file file
        # with proper key


        echo "-w /etc/localtime -p wa -k audit_time_rules" &gt;&gt; "$audit_rules_file"

    fi
done

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
              <xccdf-1.2:fix complexity="low" disruption="low" id="audit_rules_time_watch_localtime" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_watch_localtime
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter the localtime File - Check if watch rule for /etc/localtime
    already exists in /etc/audit/rules.d/
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^\s*-w\s+/etc/localtime\s+-p\s+wa(\s|$)+
    patterns: '*.rules'
  register: find_existing_watch_rules_d
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_watch_localtime
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter the localtime File - Search /etc/audit/rules.d for
    other rules with specified key audit_time_rules
  ansible.builtin.find:
    paths: /etc/audit/rules.d
    contains: ^.*(?:-F key=|-k\s+)audit_time_rules$
    patterns: '*.rules'
  register: find_watch_key
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_watch_localtime
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter the localtime File - Use /etc/audit/rules.d/audit_time_rules.rules
    as the recipient for the rule
  ansible.builtin.set_fact:
    all_files:
    - /etc/audit/rules.d/audit_time_rules.rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched == 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_watch_localtime
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter the localtime File - Use matched file as the recipient
    for the rule
  ansible.builtin.set_fact:
    all_files:
    - '{{ find_watch_key.files | map(attribute=''path'') | list | first }}'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_watch_key.matched is defined and find_watch_key.matched &gt; 0 and find_existing_watch_rules_d.matched
    is defined and find_existing_watch_rules_d.matched == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_watch_localtime
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter the localtime File - Add watch rule for /etc/localtime
    in /etc/audit/rules.d/
  ansible.builtin.lineinfile:
    path: '{{ all_files[0] }}'
    line: -w /etc/localtime -p wa -k audit_time_rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_rules_d.matched is defined and find_existing_watch_rules_d.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_watch_localtime
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter the localtime File - Check if watch rule for /etc/localtime
    already exists in /etc/audit/audit.rules
  ansible.builtin.find:
    paths: /etc/audit/
    contains: ^\s*-w\s+/etc/localtime\s+-p\s+wa(\s|$)+
    patterns: audit.rules
  register: find_existing_watch_audit_rules
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_watch_localtime
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Record Attempts to Alter the localtime File - Add watch rule for /etc/localtime
    in /etc/audit/audit.rules
  ansible.builtin.lineinfile:
    line: -w /etc/localtime -p wa -k audit_time_rules
    state: present
    dest: /etc/audit/audit.rules
    create: true
    mode: '0600'
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  - find_existing_watch_audit_rules.matched is defined and find_existing_watch_audit_rules.matched
    == 0
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.1.7
  - NIST-800-53-AC-6(9)
  - NIST-800-53-AU-12(c)
  - NIST-800-53-AU-2(d)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.4.2.b
  - PCI-DSSv4-10.6
  - PCI-DSSv4-10.6.3
  - audit_rules_time_watch_localtime
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
              <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_time_watch_localtime:def:1"/>
              </xccdf-1.2:check>
              <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
                <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1"/>
              </xccdf-1.2:check>
            </xccdf-1.2:Rule>
          </xccdf-1.2:Group>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_configure_auditd_data_retention">
          <xccdf-1.2:title>Configure auditd Data Retention</xccdf-1.2:title>
          <xccdf-1.2:description>The audit system writes data to <html:code>/var/log/audit/audit.log</html:code>. By default,
<html:code>auditd</html:code> rotates 5 logs by size (6MB), retaining a maximum of 30MB of
data in total, and refuses to write entries when the disk is too
full. This minimizes the risk of audit data filling its partition
and impacting other services. This also minimizes the risk of the audit
daemon temporarily disabling the system if it cannot write audit log (which
it can be configured to do).

For a busy
system or a system which is thoroughly auditing system activity, the default settings
for data retention may be
 insufficient. The log file size needed will depend heavily on what types
of events are being audited. First configure auditing to log all the events of
interest. Then monitor the log size manually for awhile to determine what file
size will allow you to keep the required data for the correct time period.
<html:br/><html:br/>
Using a dedicated partition for <html:code>/var/log/audit</html:code> prevents the
<html:code>auditd</html:code> logs from disrupting system functionality if they fill, and,
more importantly, prevents other activity in <html:code>/var</html:code> from filling the
partition and stopping the audit trail. (The audit logs are size-limited and
therefore unlikely to grow without bound unless configured to do so.) Some
machines may have requirements that no actions occur which cannot be audited.
If this is the case, then <html:code>auditd</html:code> can be configured to halt the machine
if it runs out of space. <html:b>Note:</html:b> Since older logs are rotated,
configuring <html:code>auditd</html:code> this way does not prevent older logs from being
rotated away before they can be viewed.

<html:i>If your system is configured to halt when logging cannot be performed, make
sure this can never happen under normal circumstances! Ensure that
<html:code>/var/log/audit</html:code> is on its own partition, and that this partition is
larger than the maximum amount of data <html:code>auditd</html:code> will retain
normally.</html:i></xccdf-1.2:description>
          <xccdf-1.2:platform idref="#package_audit"/>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_audispd_disk_full_action" type="string">
            <xccdf-1.2:title>Action for audispd to take when disk is full</xccdf-1.2:title>
            <xccdf-1.2:description>The setting for disk_full_action in /etc/audisp/audisp-remote.conf</xccdf-1.2:description>
            <xccdf-1.2:value>single</xccdf-1.2:value>
            <xccdf-1.2:value selector="exec">exec</xccdf-1.2:value>
            <xccdf-1.2:value selector="halt">halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="single">single</xccdf-1.2:value>
            <xccdf-1.2:value selector="suspend">suspend</xccdf-1.2:value>
            <xccdf-1.2:value selector="syslog">syslog</xccdf-1.2:value>
            <xccdf-1.2:value selector="warn_once">warn_once</xccdf-1.2:value>
            <xccdf-1.2:value selector="stop">stop</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_audispd_network_failure_action" type="string">
            <xccdf-1.2:title>Action for audispd to take when network fails</xccdf-1.2:title>
            <xccdf-1.2:description>The setting for network_failure_action in /etc/audisp/audisp-remote.conf</xccdf-1.2:description>
            <xccdf-1.2:value>single</xccdf-1.2:value>
            <xccdf-1.2:value selector="exec">exec</xccdf-1.2:value>
            <xccdf-1.2:value selector="halt">halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="single">single</xccdf-1.2:value>
            <xccdf-1.2:value selector="suspend">suspend</xccdf-1.2:value>
            <xccdf-1.2:value selector="syslog">syslog</xccdf-1.2:value>
            <xccdf-1.2:value selector="warn_once">warn_once</xccdf-1.2:value>
            <xccdf-1.2:value selector="stop">stop</xccdf-1.2:value>
            <xccdf-1.2:value selector="ignore">ignore</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_audispd_remote_server" interactive="true" type="string">
            <xccdf-1.2:title>Remote server for audispd to send audit records</xccdf-1.2:title>
            <xccdf-1.2:description>The configuration file could be "/etc/audit/audisp-remote.conf"
or "/etc/audisp/audisp-remote.conf" depending on the distro</xccdf-1.2:description>
            <xccdf-1.2:value>logcollector</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_auditd_action_mail_acct" type="string">
            <xccdf-1.2:title>Account for auditd to send email when actions occurs</xccdf-1.2:title>
            <xccdf-1.2:description>The setting for action_mail_acct in /etc/audit/auditd.conf</xccdf-1.2:description>
            <xccdf-1.2:value selector="admin">admin</xccdf-1.2:value>
            <xccdf-1.2:value>root</xccdf-1.2:value>
            <xccdf-1.2:value selector="root">root</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_auditd_admin_space_left_action" type="string">
            <xccdf-1.2:title>Action for auditd to take when disk space is low</xccdf-1.2:title>
            <xccdf-1.2:description>The setting for admin_space_left_action in /etc/audit/auditd.conf</xccdf-1.2:description>
            <xccdf-1.2:value>single</xccdf-1.2:value>
            <xccdf-1.2:value selector="email">email</xccdf-1.2:value>
            <xccdf-1.2:value selector="exec">exec</xccdf-1.2:value>
            <xccdf-1.2:value selector="halt">halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="single">single</xccdf-1.2:value>
            <xccdf-1.2:value selector="suspend">suspend</xccdf-1.2:value>
            <xccdf-1.2:value selector="syslog">syslog</xccdf-1.2:value>
            <xccdf-1.2:value selector="rotate">rotate</xccdf-1.2:value>
            <xccdf-1.2:value selector="ignore">ignore</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel8">single|halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel9">single|halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel10">single|halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_fedora">single|halt</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_auditd_admin_space_left_percentage" interactive="true" type="number">
            <xccdf-1.2:title>The percentage remaining in disk space before prompting admin_space_left_action</xccdf-1.2:title>
            <xccdf-1.2:description>The setting for admin_space_left as a percentage in /etc/audit/auditd.conf</xccdf-1.2:description>
            <xccdf-1.2:value selector="5pc">5</xccdf-1.2:value>
            <xccdf-1.2:value selector="25pc">25</xccdf-1.2:value>
            <xccdf-1.2:value selector="50pc">50</xccdf-1.2:value>
            <xccdf-1.2:value selector="75pc">75</xccdf-1.2:value>
            <xccdf-1.2:value>5</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_auditd_disk_error_action" type="string">
            <xccdf-1.2:title>Action for auditd to take when disk errors</xccdf-1.2:title>
            <xccdf-1.2:description>'The setting for disk_error_action in /etc/audit/auditd.conf, if multiple
values are allowed write them separated by pipes as in "syslog|single|halt",
for remediations the first value will be taken'</xccdf-1.2:description>
            <xccdf-1.2:value>single</xccdf-1.2:value>
            <xccdf-1.2:value selector="exec">exec</xccdf-1.2:value>
            <xccdf-1.2:value selector="halt">halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="single">single</xccdf-1.2:value>
            <xccdf-1.2:value selector="suspend">suspend</xccdf-1.2:value>
            <xccdf-1.2:value selector="syslog">syslog</xccdf-1.2:value>
            <xccdf-1.2:value selector="ignore">ignore</xccdf-1.2:value>
            <xccdf-1.2:value selector="ol8">syslog|single|halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="rhel8">syslog|single|halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel8">syslog|single|halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel9">syslog|single|halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel10">syslog|single|halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_fedora">syslog|single|halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_ubuntu2204">syslog|single|halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_ubuntu2404">syslog|single|halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_debian12">syslog|single|halt</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_auditd_disk_full_action" type="string">
            <xccdf-1.2:title>Action for auditd to take when disk is full</xccdf-1.2:title>
            <xccdf-1.2:description>'The setting for disk_full_action in /etc/audit/auditd.conf, if multiple
values are allowed write them separated by pipes as in "syslog|single|halt",
for remediations the first value will be taken'</xccdf-1.2:description>
            <xccdf-1.2:value>single</xccdf-1.2:value>
            <xccdf-1.2:value selector="exec">exec</xccdf-1.2:value>
            <xccdf-1.2:value selector="halt">halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="single">single</xccdf-1.2:value>
            <xccdf-1.2:value selector="suspend">suspend</xccdf-1.2:value>
            <xccdf-1.2:value selector="syslog">syslog</xccdf-1.2:value>
            <xccdf-1.2:value selector="ignore">ignore</xccdf-1.2:value>
            <xccdf-1.2:value selector="rotate">rotate</xccdf-1.2:value>
            <xccdf-1.2:value selector="ol8">syslog|single|halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="rhel8">syslog|single|halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel8">single|halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel9">halt|single</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel10">halt|single</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_fedora">halt|single</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_ubuntu2204">halt|single</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_ubuntu2404">halt|single</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_debian12">halt|single</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_auditd_flush" type="string">
            <xccdf-1.2:title>Auditd priority for flushing data to disk</xccdf-1.2:title>
            <xccdf-1.2:description>The setting for flush in /etc/audit/auditd.conf</xccdf-1.2:description>
            <xccdf-1.2:value selector="data">data</xccdf-1.2:value>
            <xccdf-1.2:value>data</xccdf-1.2:value>
            <xccdf-1.2:value selector="incremental">incremental</xccdf-1.2:value>
            <xccdf-1.2:value selector="incremental_async">incremental_async</xccdf-1.2:value>
            <xccdf-1.2:value selector="none">none</xccdf-1.2:value>
            <xccdf-1.2:value selector="sync">sync</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_auditd_freq" interactive="true" type="number">
            <xccdf-1.2:title>Number of Record to Retain Before Flushing to Disk</xccdf-1.2:title>
            <xccdf-1.2:description>The setting for freq in /etc/audit/auditd.conf</xccdf-1.2:description>
            <xccdf-1.2:value selector="50">50</xccdf-1.2:value>
            <xccdf-1.2:value selector="100">100</xccdf-1.2:value>
            <xccdf-1.2:value>50</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_auditd_max_log_file" type="number">
            <xccdf-1.2:title>Maximum audit log file size for auditd</xccdf-1.2:title>
            <xccdf-1.2:description>The setting for max_log_file in /etc/audit/auditd.conf</xccdf-1.2:description>
            <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
            <xccdf-1.2:value selector="10">10</xccdf-1.2:value>
            <xccdf-1.2:value selector="20">20</xccdf-1.2:value>
            <xccdf-1.2:value selector="5">5</xccdf-1.2:value>
            <xccdf-1.2:value selector="6">6</xccdf-1.2:value>
            <xccdf-1.2:value selector="8">8</xccdf-1.2:value>
            <xccdf-1.2:value>6</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_auditd_max_log_file_action" type="string">
            <xccdf-1.2:title>Action for auditd to take when log files reach their maximum size</xccdf-1.2:title>
            <xccdf-1.2:description>The setting for max_log_file_action in /etc/audit/auditd.conf. The following options are available:
<html:br/>ignore - audit daemon does nothing.
<html:br/>syslog - audit daemon will issue a warning to syslog.
<html:br/>suspend - audit daemon will stop writing records to the disk.
<html:br/>rotate - audit daemon will rotate logs in the same convention used by logrotate.
<html:br/>keep_logs - similar to rotate but prevents audit logs to be overwritten. May trigger space_left_action if volume is full.</xccdf-1.2:description>
            <xccdf-1.2:value>rotate</xccdf-1.2:value>
            <xccdf-1.2:value selector="keep_logs">keep_logs</xccdf-1.2:value>
            <xccdf-1.2:value selector="rotate">rotate</xccdf-1.2:value>
            <xccdf-1.2:value selector="suspend">suspend</xccdf-1.2:value>
            <xccdf-1.2:value selector="syslog">syslog</xccdf-1.2:value>
            <xccdf-1.2:value selector="ignore">ignore</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_auditd_name_format" type="string">
            <xccdf-1.2:title>Type of hostname to record the audit event</xccdf-1.2:title>
            <xccdf-1.2:description>Type of hostname to record the audit event</xccdf-1.2:description>
            <xccdf-1.2:value>hostname</xccdf-1.2:value>
            <xccdf-1.2:value selector="hostname">hostname</xccdf-1.2:value>
            <xccdf-1.2:value selector="fqd">fqd</xccdf-1.2:value>
            <xccdf-1.2:value selector="numeric">numeric</xccdf-1.2:value>
            <xccdf-1.2:value selector="user">user</xccdf-1.2:value>
            <xccdf-1.2:value selector="none">none</xccdf-1.2:value>
            <xccdf-1.2:value selector="stig">hostname|fqd|numeric</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_auditd_num_logs" type="number">
            <xccdf-1.2:title>Number of log files for auditd to retain</xccdf-1.2:title>
            <xccdf-1.2:description>The setting for num_logs in /etc/audit/auditd.conf</xccdf-1.2:description>
            <xccdf-1.2:value selector="0">0</xccdf-1.2:value>
            <xccdf-1.2:value selector="1">1</xccdf-1.2:value>
            <xccdf-1.2:value selector="2">2</xccdf-1.2:value>
            <xccdf-1.2:value selector="3">3</xccdf-1.2:value>
            <xccdf-1.2:value selector="4">4</xccdf-1.2:value>
            <xccdf-1.2:value selector="5">5</xccdf-1.2:value>
            <xccdf-1.2:value selector="10">10</xccdf-1.2:value>
            <xccdf-1.2:value selector="20">20</xccdf-1.2:value>
            <xccdf-1.2:value selector="50">50</xccdf-1.2:value>
            <xccdf-1.2:value selector="100">100</xccdf-1.2:value>
            <xccdf-1.2:value>5</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_auditd_space_left" type="number">
            <xccdf-1.2:title>Size remaining in disk space before prompting space_left_action</xccdf-1.2:title>
            <xccdf-1.2:description>The setting for space_left (MB) in /etc/audit/auditd.conf</xccdf-1.2:description>
            <xccdf-1.2:value selector="1000MB">1000</xccdf-1.2:value>
            <xccdf-1.2:value selector="100MB">100</xccdf-1.2:value>
            <xccdf-1.2:value selector="250MB">250</xccdf-1.2:value>
            <xccdf-1.2:value selector="500MB">500</xccdf-1.2:value>
            <xccdf-1.2:value selector="750MB">750</xccdf-1.2:value>
            <xccdf-1.2:value>100</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_auditd_space_left_action" type="string">
            <xccdf-1.2:title>Action for auditd to take when disk space just starts to run low</xccdf-1.2:title>
            <xccdf-1.2:description>The setting for space_left_action in /etc/audit/auditd.conf</xccdf-1.2:description>
            <xccdf-1.2:value>email</xccdf-1.2:value>
            <xccdf-1.2:value selector="email">email</xccdf-1.2:value>
            <xccdf-1.2:value selector="exec">exec</xccdf-1.2:value>
            <xccdf-1.2:value selector="halt">halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="single">single</xccdf-1.2:value>
            <xccdf-1.2:value selector="suspend">suspend</xccdf-1.2:value>
            <xccdf-1.2:value selector="syslog">syslog</xccdf-1.2:value>
            <xccdf-1.2:value selector="rotate">rotate</xccdf-1.2:value>
            <xccdf-1.2:value selector="ignore">ignore</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel8">email|exec|single|halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel9">email|exec|single|halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_rhel10">email|exec|single|halt</xccdf-1.2:value>
            <xccdf-1.2:value selector="cis_fedora">email|exec|single|halt</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Value id="xccdf_org.ssgproject.content_value_var_auditd_space_left_percentage" interactive="true" type="number">
            <xccdf-1.2:title>The percentage remaining in disk space before prompting space_left_action</xccdf-1.2:title>
            <xccdf-1.2:description>The setting for space_left as a percentage in /etc/audit/auditd.conf</xccdf-1.2:description>
            <xccdf-1.2:value selector="25pc">25</xccdf-1.2:value>
            <xccdf-1.2:value selector="50pc">50</xccdf-1.2:value>
            <xccdf-1.2:value selector="75pc">75</xccdf-1.2:value>
            <xccdf-1.2:value>25</xccdf-1.2:value>
          </xccdf-1.2:Value>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_audispd_configure_remote_server" selected="false" severity="medium">
            <xccdf-1.2:title>Configure audispd Plugin To Send Logs To Remote Server</xccdf-1.2:title>
            <xccdf-1.2:description>Configure the audispd plugin to off-load audit records onto a different
system or media from the system being audited.

Set the <html:code>remote_server</html:code> option in <html:pre>/etc/audit/audisp-remote.conf</html:pre>
with an IP address or hostname of the system that the audispd plugin should
send audit records to. For example
<html:pre>remote_server = <html:i><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audispd_remote_server" use="legacy"/></html:i></html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000342-GPOS-00133</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000479-GPOS-00224</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Information stored in one location is vulnerable to accidental or incidental
deletion or alteration.Off-loading is a common process in information systems
with limited audit storage capacity.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_audispd_configure_remote_server" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_audispd_remote_server='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audispd_remote_server" use="legacy"/>'


AUDITCONFIG=/etc/audit/audisp-remote.conf



if [ -e "$AUDITCONFIG" ] ; then
    
    LC_ALL=C sed -i "/^\s*remote_server\s*=\s*/Id" "$AUDITCONFIG"
else
    printf '%s\n' "Path '$AUDITCONFIG' wasn't found on this system. Refusing to continue." &gt;&amp;2
    return 1
fi
# make sure file has newline at the end
sed -i -e '$a\' "$AUDITCONFIG"

cp "$AUDITCONFIG" "$AUDITCONFIG.bak"
# Insert at the end of the file
printf '%s\n' "remote_server = $var_audispd_remote_server" &gt;&gt; "$AUDITCONFIG"
# Clean up after ourselves.
rm "$AUDITCONFIG.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_audispd_configure_remote_server" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - auditd_audispd_configure_remote_server
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
- name: XCCDF Value var_audispd_remote_server # promote to variable
  set_fact:
    var_audispd_remote_server: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audispd_remote_server" use="legacy"/>
  tags:
    - always

- name: Configure audispd Plugin To Send Logs To Remote Server - Make sure that a
    remote server is configured for Audispd
  ansible.builtin.lineinfile:
    path: /etc/audit/audisp-remote.conf
    line: remote_server = {{ var_audispd_remote_server }}
    regexp: ^\s*remote_server\s*=.*$
    create: true
    state: present
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - auditd_audispd_configure_remote_server
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_audispd_remote_server:var:1" value-id="xccdf_org.ssgproject.content_value_var_audispd_remote_server"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_audispd_configure_remote_server:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_audispd_configure_remote_server_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_audispd_configure_sufficiently_large_partition" selected="false" severity="medium">
            <xccdf-1.2:title>Configure a Sufficiently Large Partition for Audit Logs</xccdf-1.2:title>
            <xccdf-1.2:description>The AlmaLinux OS 8 operating system must allocate audit record storage
capacity to store at least one weeks worth of audit records when audit
records are not immediately sent to a central audit record storage
facility.

The partition size needed to capture a week's worth of audit records is
based on the activity level of the system and the total storage capacity
available.

In normal circumstances, 10.0 GB of storage space for audit
records will be sufficient.


Determine which partition the audit records are being written to with the
following command:

<html:pre>$ sudo grep log_file /etc/audit/auditd.conf
log_file = /var/log/audit/audit.log</html:pre>

Check the size of the partition that audit records are written to with the
following command:

<html:pre>$ sudo df -h /var/log/audit/
/dev/sda2 24G 10.4G 13.6G 43% /var/log/audit</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000341-GPOS-00132</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000342-GPOS-00133</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030660</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230476r958752_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Information stored in one location is vulnerable to accidental or incidental
deletion or alteration. Off-loading is a common process in information
systems with limited audit storage capacity.</xccdf-1.2:rationale>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_audispd_configure_sufficiently_large_partition_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_audispd_disk_full_action" selected="false" severity="medium">
            <xccdf-1.2:title>Configure audispd's Plugin disk_full_action When Disk Is Full</xccdf-1.2:title>
            <xccdf-1.2:description>Configure the action the operating system takes if the disk the audit records
are written to becomes full. Edit the file <html:code>/etc/audit/audisp-remote.conf</html:code>.
Add or modify the following line, substituting <html:i>ACTION</html:i> appropriately:
<html:pre>disk_full_action = <html:i>ACTION</html:i></html:pre>
Set this value to <html:code>single</html:code> to cause the system to switch to single user
mode for corrective action. Acceptable values also include <html:code>syslog</html:code> and
<html:code>halt</html:code>. For certain systems, the need for availability
outweighs the need to log all actions, and a different setting should be
determined.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000342-GPOS-00133</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000479-GPOS-00224</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Taking appropriate action in case of a filled audit storage volume will
minimize the possibility of losing audit records.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_audispd_disk_full_action" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_audispd_disk_full_action='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audispd_disk_full_action" use="legacy"/>'


AUDITCONFIG=/etc/audit/audisp-remote.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^disk_full_action")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_audispd_disk_full_action"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^disk_full_action\\&gt;" "$AUDITCONFIG"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^disk_full_action\\&gt;.*/$escaped_formatted_output/gi" "$AUDITCONFIG"
else
    if [[ -s "$AUDITCONFIG" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "$AUDITCONFIG" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "$AUDITCONFIG"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "$AUDITCONFIG"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_audispd_disk_full_action" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - auditd_audispd_disk_full_action
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
- name: XCCDF Value var_audispd_disk_full_action # promote to variable
  set_fact:
    var_audispd_disk_full_action: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audispd_disk_full_action" use="legacy"/>
  tags:
    - always

- name: Make sure that disk full action is configured for Audispd
  ansible.builtin.lineinfile:
    path: /etc/audit/audisp-remote.conf
    line: disk_full_action = {{ var_audispd_disk_full_action }}
    regexp: ^\s*disk_full_action\s*=.*$
    create: true
    state: present
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - auditd_audispd_disk_full_action
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_audispd_disk_full_action:var:1" value-id="xccdf_org.ssgproject.content_value_var_audispd_disk_full_action"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_audispd_disk_full_action:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_audispd_disk_full_action_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_audispd_encrypt_sent_records" selected="false" severity="medium">
            <xccdf-1.2:title>Encrypt Audit Records Sent With audispd Plugin</xccdf-1.2:title>
            <xccdf-1.2:description>Configure the operating system to encrypt the transfer of off-loaded audit
records onto a different system or media from the system being audited.

Set the <html:code>transport</html:code> option in <html:pre>/etc/audit/audisp-remote.conf</html:pre>
to <html:code>KRB5</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-9(3)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000342-GPOS-00133</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000479-GPOS-00224</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Information stored in one location is vulnerable to accidental or incidental deletion
or alteration. Off-loading is a common process in information systems with limited
audit storage capacity.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_audispd_encrypt_sent_records" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

AUDISP_REMOTE_CONFIG="/etc/audit/audisp-remote.conf"

option="^transport"
value="KRB5"


# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "$option")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$value"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "$option\\&gt;" "$AUDISP_REMOTE_CONFIG"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/$option\\&gt;.*/$escaped_formatted_output/gi" "$AUDISP_REMOTE_CONFIG"
else
    if [[ -s "$AUDISP_REMOTE_CONFIG" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "$AUDISP_REMOTE_CONFIG" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "$AUDISP_REMOTE_CONFIG"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "$AUDISP_REMOTE_CONFIG"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_audispd_encrypt_sent_records:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_audispd_encrypt_sent_records_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_audispd_network_failure_action" selected="false" severity="medium">
            <xccdf-1.2:title>Configure audispd's Plugin network_failure_action On Network Failure</xccdf-1.2:title>
            <xccdf-1.2:description>Configure the action the operating system takes if there is an error sending
audit records to a remote system. Edit the file <html:code>/etc/audit/audisp-remote.conf</html:code>.
Add or modify the following line, substituting <html:i>ACTION</html:i> appropriately:
<html:pre>network_failure_action = <html:i>ACTION</html:i></html:pre>
Set this value to <html:code>single</html:code> to cause the system to switch to single user
mode for corrective action. Acceptable values also include <html:code>syslog</html:code> and
<html:code>halt</html:code>. For certain systems, the need for availability
outweighs the need to log all actions, and a different setting should be
determined.
This profile configures the <html:i>action</html:i> to be <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audispd_network_failure_action" use="legacy"/></html:code>.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000342-GPOS-00133</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000479-GPOS-00224</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Taking appropriate action when there is an error sending audit records to a
remote system will minimize the possibility of losing audit records.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_audispd_network_failure_action" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_audispd_network_failure_action='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audispd_network_failure_action" use="legacy"/>'


AUDITCONFIG=/etc/audit/audisp-remote.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^network_failure_action")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_audispd_network_failure_action"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^network_failure_action\\&gt;" "$AUDITCONFIG"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^network_failure_action\\&gt;.*/$escaped_formatted_output/gi" "$AUDITCONFIG"
else
    if [[ -s "$AUDITCONFIG" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "$AUDITCONFIG" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "$AUDITCONFIG"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "$AUDITCONFIG"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_audispd_network_failure_action" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - auditd_audispd_network_failure_action
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
- name: XCCDF Value var_audispd_network_failure_action # promote to variable
  set_fact:
    var_audispd_network_failure_action: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_audispd_network_failure_action" use="legacy"/>
  tags:
    - always

- name: Make sure that network failure action is configured for Audispd
  ansible.builtin.lineinfile:
    path: /etc/audit/audisp-remote.conf
    line: network_failure_action = {{ var_audispd_network_failure_action }}
    regexp: ^\s*network_failure_action\s*=.*$
    create: true
    state: present
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - auditd_audispd_network_failure_action
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_audispd_network_failure_action:var:1" value-id="xccdf_org.ssgproject.content_value_var_audispd_network_failure_action"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_audispd_network_failure_action:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_audispd_network_failure_action_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_audispd_syslog_plugin_activated" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditd to use audispd's syslog plugin</xccdf-1.2:title>
            <xccdf-1.2:description>To configure the <html:code>auditd</html:code> service to use the
<html:code>syslog</html:code> plug-in of the <html:code>audispd</html:code> audit event multiplexor, set
the <html:code>active</html:code> line in <html:code>/etc/audit/plugins.d/syslog.conf</html:code> to <html:code>yes</html:code>.
Restart the <html:code>auditd</html:code> service:
<html:pre>$ sudo service auditd restart</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(B)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(6)(ii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(8)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.310(d)(2)(iii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.314(a)(2)(i)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.314(a)(2)(iii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-4(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000479-GPOS-00224</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000342-GPOS-00133</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.3</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The auditd service does not include the ability to send audit
records to a centralized server for management directly. It does, however,
include a plug-in for audit event multiplexor (audispd) to pass audit records
to the local syslog server.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_audispd_syslog_plugin_activated" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_syslog_active="yes"

AUDISP_SYSLOGCONFIG=/etc/audit/plugins.d/syslog.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^active")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_syslog_active"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^active\\&gt;" "$AUDISP_SYSLOGCONFIG"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^active\\&gt;.*/$escaped_formatted_output/gi" "$AUDISP_SYSLOGCONFIG"
else
    if [[ -s "$AUDISP_SYSLOGCONFIG" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "$AUDISP_SYSLOGCONFIG" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "$AUDISP_SYSLOGCONFIG"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "$AUDISP_SYSLOGCONFIG"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_audispd_syslog_plugin_activated" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.3.1
  - NIST-800-53-AU-4(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.3
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.3
  - auditd_audispd_syslog_plugin_activated
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Enable syslog plugin
  ansible.builtin.lineinfile:
    dest: /etc/audit/plugins.d/syslog.conf
    regexp: ^active
    line: active = yes
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.3.1
  - NIST-800-53-AU-4(1)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.5.3
  - PCI-DSSv4-10.3
  - PCI-DSSv4-10.3.3
  - auditd_audispd_syslog_plugin_activated
  - configure_strategy
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_audispd_syslog_plugin_activated:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_data_disk_error_action" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditd Disk Error Action on Disk Error</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>auditd</html:code> service can be configured to take an action
when there is a disk error.
Edit the file <html:code>/etc/audit/auditd.conf</html:code>. Add or modify the following line,
substituting <html:i>ACTION</html:i> appropriately:
<html:pre>disk_error_action = <html:i>ACTION</html:i></html:pre>
Set this value to <html:code>single</html:code> to cause the system to switch to single-user
mode for corrective action. Acceptable values also include

<html:code>syslog</html:code>, <html:code>exec</html:code>, <html:code>single</html:code>, and <html:code>halt</html:code>

For certain systems, the need for availability
outweighs the need to log all actions, and a different setting should be
determined. Details regarding all possible values for <html:i>ACTION</html:i> are described in the
<html:code>auditd.conf</html:code> man page.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000047-GPOS-00023</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000098-CTR-000185</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000099-CTR-000190</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000100-CTR-000195</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000100-CTR-000200</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000109-CTR-000215</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000290-CTR-000670</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000357-CTR-000800</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030040</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230390r1038966_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Taking appropriate action in case of disk errors will minimize the possibility of
losing audit records.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_data_disk_error_action" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_auditd_disk_error_action='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_disk_error_action" use="legacy"/>'


#
# If disk_error_action present in /etc/audit/auditd.conf, change value
# to var_auditd_disk_error_action, else
# add "disk_error_action = $var_auditd_disk_error_action" to /etc/audit/auditd.conf
#
var_auditd_disk_error_action="$(echo $var_auditd_disk_error_action | cut -d \| -f 1)"

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^disk_error_action")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_auditd_disk_error_action"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^disk_error_action\\&gt;" "/etc/audit/auditd.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^disk_error_action\\&gt;.*/$escaped_formatted_output/gi" "/etc/audit/auditd.conf"
else
    if [[ -s "/etc/audit/auditd.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/audit/auditd.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/audit/auditd.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/audit/auditd.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_disk_error_action" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030040
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - auditd_data_disk_error_action
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_auditd_disk_error_action # promote to variable
  set_fact:
    var_auditd_disk_error_action: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_disk_error_action" use="legacy"/>
  tags:
    - always

- name: Configure auditd Disk Error Action on Disk Error
  ansible.builtin.lineinfile:
    dest: /etc/audit/auditd.conf
    line: disk_error_action = {{ var_auditd_disk_error_action.split('|')[0] }}
    regexp: ^\s*disk_error_action\s*=\s*.*$
    state: present
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030040
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - auditd_data_disk_error_action
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_disk_error_action" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20audit%20daemon%0A%23%0A%0Alocal_events%20%3D%20yes%0Awrite_logs%20%3D%20yes%0Alog_file%20%3D%20/var/log/audit/audit.log%0Alog_group%20%3D%20root%0Alog_format%20%3D%20ENRICHED%0Aflush%20%3D%20%7B%7B.var_auditd_flush%7D%7D%0Afreq%20%3D%2050%0Amax_log_file%20%3D%20%7B%7B.var_auditd_max_log_file%7D%7D%0Anum_logs%20%3D%20%7B%7B.var_auditd_num_logs%7D%7D%0Apriority_boost%20%3D%204%0Aname_format%20%3D%20hostname%0A%23%23name%20%3D%20mydomain%0Amax_log_file_action%20%3D%20%7B%7B.var_auditd_max_log_file_action%7D%7D%0Aspace_left%20%3D%20%7B%7B.var_auditd_space_left%7D%7D%0Aspace_left_action%20%3D%20%7B%7B.var_auditd_space_left_action%7D%7D%0Averify_email%20%3D%20yes%0Aaction_mail_acct%20%3D%20%7B%7B.var_auditd_action_mail_acct%7D%7D%0Aadmin_space_left%20%3D%2050%0Aadmin_space_left_action%20%3D%20syslog%0Adisk_full_action%20%3D%20%7B%7B.var_auditd_disk_full_action%7D%7D%0Adisk_error_action%20%3D%20%7B%7B.var_auditd_disk_error_action%7D%7D%0Ause_libwrap%20%3D%20yes%0A%23%23tcp_listen_port%20%3D%2060%0Atcp_listen_queue%20%3D%205%0Atcp_max_per_addr%20%3D%201%0A%23%23tcp_client_ports%20%3D%201024-65535%0Atcp_client_max_idle%20%3D%200%0Atransport%20%3D%20TCP%0Akrb5_principal%20%3D%20auditd%0A%23%23krb5_key_file%20%3D%20/etc/audit/audit.key%0Adistribute_network%20%3D%20no%0Aq_depth%20%3D%20400%0Aoverflow_action%20%3D%20syslog%0Amax_restarts%20%3D%2010%0Aplugin_dir%20%3D%20/etc/audit/plugins.d }}
        mode: 0640
        path: /etc/audit/auditd.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_auditd_disk_error_action:var:1" value-id="xccdf_org.ssgproject.content_value_var_auditd_disk_error_action"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_data_disk_error_action:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_data_disk_error_action_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_data_disk_error_action_stig" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditd Disk Error Action on Disk Error</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>auditd</html:code> service can be configured to take an action
when there is a disk error.
Edit the file <html:code>/etc/audit/auditd.conf</html:code>. Add or modify the following line,
substituting <html:i>ACTION</html:i> appropriately:
<html:pre>disk_error_action = <html:i>ACTION</html:i></html:pre>
Set this value to <html:code>single</html:code> to cause the system to switch to single-user
mode for corrective action. Acceptable values also include <html:code>syslog</html:code>,
<html:code>exec</html:code>, <html:code>single</html:code>, and <html:code>halt</html:code>. For certain systems, the need for availability
outweighs the need to log all actions, and a different setting should be
determined. Details regarding all possible values for <html:i>ACTION</html:i> are described in the
<html:code>auditd.conf</html:code> man page.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000047-GPOS-00023</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Taking appropriate action in case of disk errors will minimize the possibility of
losing audit records.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_data_disk_error_action_stig" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_auditd_disk_error_action='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_disk_error_action" use="legacy"/>'


# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^disk_error_action")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_auditd_disk_error_action"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^disk_error_action\\&gt;" "/etc/audit/auditd.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^disk_error_action\\&gt;.*/$escaped_formatted_output/gi" "/etc/audit/auditd.conf"
else
    if [[ -s "/etc/audit/auditd.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/audit/auditd.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/audit/auditd.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/audit/auditd.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_disk_error_action_stig" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - auditd_data_disk_error_action_stig
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_auditd_disk_error_action # promote to variable
  set_fact:
    var_auditd_disk_error_action: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_disk_error_action" use="legacy"/>
  tags:
    - always

- name: Configure auditd Disk Error Action on Disk Error
  ansible.builtin.lineinfile:
    dest: /etc/audit/auditd.conf
    line: disk_error_action = {{ var_auditd_disk_error_action }}
    regexp: ^\s*disk_error_action\s*=\s*.*$
    state: present
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - auditd_data_disk_error_action_stig
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_disk_error_action_stig" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20audit%20daemon%0A%23%0A%0Alocal_events%20%3D%20yes%0Awrite_logs%20%3D%20yes%0Alog_file%20%3D%20/var/log/audit/audit.log%0Alog_group%20%3D%20root%0Alog_format%20%3D%20ENRICHED%0Aflush%20%3D%20%7B%7B.var_auditd_flush%7D%7D%0Afreq%20%3D%2050%0Amax_log_file%20%3D%20%7B%7B.var_auditd_max_log_file%7D%7D%0Anum_logs%20%3D%20%7B%7B.var_auditd_num_logs%7D%7D%0Apriority_boost%20%3D%204%0Aname_format%20%3D%20hostname%0A%23%23name%20%3D%20mydomain%0Amax_log_file_action%20%3D%20%7B%7B.var_auditd_max_log_file_action%7D%7D%0Aspace_left%20%3D%20%7B%7B.var_auditd_space_left%7D%7D%0Aspace_left_action%20%3D%20%7B%7B.var_auditd_space_left_action%7D%7D%0Averify_email%20%3D%20yes%0Aaction_mail_acct%20%3D%20%7B%7B.var_auditd_action_mail_acct%7D%7D%0Aadmin_space_left%20%3D%2050%0Aadmin_space_left_action%20%3D%20syslog%0Adisk_full_action%20%3D%20%7B%7B.var_auditd_disk_full_action%7D%7D%0Adisk_error_action%20%3D%20%7B%7B.var_auditd_disk_error_action%7D%7D%0Ause_libwrap%20%3D%20yes%0A%23%23tcp_listen_port%20%3D%2060%0Atcp_listen_queue%20%3D%205%0Atcp_max_per_addr%20%3D%201%0A%23%23tcp_client_ports%20%3D%201024-65535%0Atcp_client_max_idle%20%3D%200%0Atransport%20%3D%20TCP%0Akrb5_principal%20%3D%20auditd%0A%23%23krb5_key_file%20%3D%20/etc/audit/audit.key%0Adistribute_network%20%3D%20no%0Aq_depth%20%3D%20400%0Aoverflow_action%20%3D%20syslog%0Amax_restarts%20%3D%2010%0Aplugin_dir%20%3D%20/etc/audit/plugins.d }}
        mode: 0640
        path: /etc/audit/auditd.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_data_disk_error_action_stig:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_data_disk_error_action_stig_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_data_disk_full_action" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditd Disk Full Action when Disk Space Is Full</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>auditd</html:code> service can be configured to take an action
when disk space is running low but prior to running out of space completely.
Edit the file <html:code>/etc/audit/auditd.conf</html:code>. Add or modify the following line,
substituting <html:i>ACTION</html:i> appropriately:
<html:pre>disk_full_action = <html:i>ACTION</html:i></html:pre>
Set this value to <html:code>single</html:code> to cause the system to switch to single-user
mode for corrective action. Acceptable values also include

<html:code>syslog</html:code>, <html:code>exec</html:code>, <html:code>single</html:code>, and <html:code>halt</html:code>

For certain systems, the need for availability
outweighs the need to log all actions, and a different setting should be
determined. Details regarding all possible values for <html:i>ACTION</html:i> are described in the
<html:code>auditd.conf</html:code> man page.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000047-GPOS-00023</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030060</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230392r1038966_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Taking appropriate action in case of a filled audit storage volume will minimize
the possibility of losing audit records.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_data_disk_full_action" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_auditd_disk_full_action='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_disk_full_action" use="legacy"/>'


var_auditd_disk_full_action="$(echo $var_auditd_disk_full_action | cut -d \| -f 1)"

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^disk_full_action")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_auditd_disk_full_action"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^disk_full_action\\&gt;" "/etc/audit/auditd.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^disk_full_action\\&gt;.*/$escaped_formatted_output/gi" "/etc/audit/auditd.conf"
else
    if [[ -s "/etc/audit/auditd.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/audit/auditd.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/audit/auditd.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/audit/auditd.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_disk_full_action" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030060
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - auditd_data_disk_full_action
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_auditd_disk_full_action # promote to variable
  set_fact:
    var_auditd_disk_full_action: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_disk_full_action" use="legacy"/>
  tags:
    - always

- name: Configure auditd Disk Full Action when Disk Space Is Full
  ansible.builtin.lineinfile:
    dest: /etc/audit/auditd.conf
    line: disk_full_action = {{ var_auditd_disk_full_action.split('|')[0] }}
    regexp: ^\s*disk_full_action\s*=\s*.*$
    state: present
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030060
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - auditd_data_disk_full_action
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_disk_full_action" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20audit%20daemon%0A%23%0A%0Alocal_events%20%3D%20yes%0Awrite_logs%20%3D%20yes%0Alog_file%20%3D%20/var/log/audit/audit.log%0Alog_group%20%3D%20root%0Alog_format%20%3D%20ENRICHED%0Aflush%20%3D%20%7B%7B.var_auditd_flush%7D%7D%0Afreq%20%3D%2050%0Amax_log_file%20%3D%20%7B%7B.var_auditd_max_log_file%7D%7D%0Anum_logs%20%3D%20%7B%7B.var_auditd_num_logs%7D%7D%0Apriority_boost%20%3D%204%0Aname_format%20%3D%20hostname%0A%23%23name%20%3D%20mydomain%0Amax_log_file_action%20%3D%20%7B%7B.var_auditd_max_log_file_action%7D%7D%0Aspace_left%20%3D%20%7B%7B.var_auditd_space_left%7D%7D%0Aspace_left_action%20%3D%20%7B%7B.var_auditd_space_left_action%7D%7D%0Averify_email%20%3D%20yes%0Aaction_mail_acct%20%3D%20%7B%7B.var_auditd_action_mail_acct%7D%7D%0Aadmin_space_left%20%3D%2050%0Aadmin_space_left_action%20%3D%20syslog%0Adisk_full_action%20%3D%20%7B%7B.var_auditd_disk_full_action%7D%7D%0Adisk_error_action%20%3D%20%7B%7B.var_auditd_disk_error_action%7D%7D%0Ause_libwrap%20%3D%20yes%0A%23%23tcp_listen_port%20%3D%2060%0Atcp_listen_queue%20%3D%205%0Atcp_max_per_addr%20%3D%201%0A%23%23tcp_client_ports%20%3D%201024-65535%0Atcp_client_max_idle%20%3D%200%0Atransport%20%3D%20TCP%0Akrb5_principal%20%3D%20auditd%0A%23%23krb5_key_file%20%3D%20/etc/audit/audit.key%0Adistribute_network%20%3D%20no%0Aq_depth%20%3D%20400%0Aoverflow_action%20%3D%20syslog%0Amax_restarts%20%3D%2010%0Aplugin_dir%20%3D%20/etc/audit/plugins.d }}
        mode: 0640
        path: /etc/audit/auditd.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_auditd_disk_full_action:var:1" value-id="xccdf_org.ssgproject.content_value_var_auditd_disk_full_action"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_data_disk_full_action:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_data_disk_full_action_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_data_disk_full_action_stig" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditd Disk Full Action when Disk Space Is Full</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>auditd</html:code> service can be configured to take an action
when disk space is running low but prior to running out of space completely.
Edit the file <html:code>/etc/audit/auditd.conf</html:code>. Add or modify the following line,
substituting <html:i>ACTION</html:i> appropriately:
<html:pre>disk_full_action = <html:i>ACTION</html:i></html:pre>
Set this value to <html:code>single</html:code> to cause the system to switch to single-user
mode for corrective action. Acceptable values also include <html:code>syslog</html:code>,
<html:code>single</html:code>, and <html:code>halt</html:code>. For certain systems, the need for availability
outweighs the need to log all actions, and a different setting should be
determined. Details regarding all possible values for <html:i>ACTION</html:i> are described in the
<html:code>auditd.conf</html:code> man page.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000047-GPOS-00023</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Taking appropriate action in case of a filled audit storage volume will minimize
the possibility of losing audit records.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_data_disk_full_action_stig" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_auditd_disk_full_action='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_disk_full_action" use="legacy"/>'


# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^disk_full_action")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_auditd_disk_full_action"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^disk_full_action\\&gt;" "/etc/audit/auditd.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^disk_full_action\\&gt;.*/$escaped_formatted_output/gi" "/etc/audit/auditd.conf"
else
    if [[ -s "/etc/audit/auditd.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/audit/auditd.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/audit/auditd.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/audit/auditd.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_disk_full_action_stig" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - auditd_data_disk_full_action_stig
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_auditd_disk_full_action # promote to variable
  set_fact:
    var_auditd_disk_full_action: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_disk_full_action" use="legacy"/>
  tags:
    - always

- name: Configure auditd Disk Full Action when Disk Space Is Full
  ansible.builtin.lineinfile:
    dest: /etc/audit/auditd.conf
    line: disk_full_action = {{ var_auditd_disk_full_action }}
    regexp: ^\s*disk_full_action\s*=\s*.*$
    state: present
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - auditd_data_disk_full_action_stig
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_disk_full_action_stig" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20audit%20daemon%0A%23%0A%0Alocal_events%20%3D%20yes%0Awrite_logs%20%3D%20yes%0Alog_file%20%3D%20/var/log/audit/audit.log%0Alog_group%20%3D%20root%0Alog_format%20%3D%20ENRICHED%0Aflush%20%3D%20%7B%7B.var_auditd_flush%7D%7D%0Afreq%20%3D%2050%0Amax_log_file%20%3D%20%7B%7B.var_auditd_max_log_file%7D%7D%0Anum_logs%20%3D%20%7B%7B.var_auditd_num_logs%7D%7D%0Apriority_boost%20%3D%204%0Aname_format%20%3D%20hostname%0A%23%23name%20%3D%20mydomain%0Amax_log_file_action%20%3D%20%7B%7B.var_auditd_max_log_file_action%7D%7D%0Aspace_left%20%3D%20%7B%7B.var_auditd_space_left%7D%7D%0Aspace_left_action%20%3D%20%7B%7B.var_auditd_space_left_action%7D%7D%0Averify_email%20%3D%20yes%0Aaction_mail_acct%20%3D%20%7B%7B.var_auditd_action_mail_acct%7D%7D%0Aadmin_space_left%20%3D%2050%0Aadmin_space_left_action%20%3D%20syslog%0Adisk_full_action%20%3D%20%7B%7B.var_auditd_disk_full_action%7D%7D%0Adisk_error_action%20%3D%20%7B%7B.var_auditd_disk_error_action%7D%7D%0Ause_libwrap%20%3D%20yes%0A%23%23tcp_listen_port%20%3D%2060%0Atcp_listen_queue%20%3D%205%0Atcp_max_per_addr%20%3D%201%0A%23%23tcp_client_ports%20%3D%201024-65535%0Atcp_client_max_idle%20%3D%200%0Atransport%20%3D%20TCP%0Akrb5_principal%20%3D%20auditd%0A%23%23krb5_key_file%20%3D%20/etc/audit/audit.key%0Adistribute_network%20%3D%20no%0Aq_depth%20%3D%20400%0Aoverflow_action%20%3D%20syslog%0Amax_restarts%20%3D%2010%0Aplugin_dir%20%3D%20/etc/audit/plugins.d }}
        mode: 0640
        path: /etc/audit/auditd.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_data_disk_full_action_stig:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_data_disk_full_action_stig_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_data_retention_action_mail_acct" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditd mail_acct Action on Low Disk Space</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>auditd</html:code> service can be configured to send email to
a designated account in certain situations. Add or correct the following line
in <html:code>/etc/audit/auditd.conf</html:code> to ensure that administrators are notified
via email for those situations:
<html:pre>action_mail_acct = <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_action_mail_acct" use="legacy"/></html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(ii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-003-8 R5.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">IA-5(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.7.a</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000046-GPOS-00022</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000343-GPOS-00134</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030020</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230388r1017196_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Email sent to the root account is typically aliased to the
administrators of the system, who can take appropriate action.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_data_retention_action_mail_acct" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_auditd_action_mail_acct='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_action_mail_acct" use="legacy"/>'


AUDITCONFIG=/etc/audit/auditd.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^action_mail_acct")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_auditd_action_mail_acct"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^action_mail_acct\\&gt;" "$AUDITCONFIG"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^action_mail_acct\\&gt;.*/$escaped_formatted_output/gi" "$AUDITCONFIG"
else
    if [[ -s "$AUDITCONFIG" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "$AUDITCONFIG" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "$AUDITCONFIG"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "$AUDITCONFIG"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_action_mail_acct" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030020
  - NIST-800-171-3.3.1
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)
  - PCI-DSS-Req-10.7.a
  - auditd_data_retention_action_mail_acct
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_auditd_action_mail_acct # promote to variable
  set_fact:
    var_auditd_action_mail_acct: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_action_mail_acct" use="legacy"/>
  tags:
    - always

- name: Configure auditd mail_acct Action on Low Disk Space - Configure auditd mail_acct
    Action on Low Disk Space
  ansible.builtin.lineinfile:
    dest: /etc/audit/auditd.conf
    regexp: ^action_mail_acct
    line: action_mail_acct = {{ var_auditd_action_mail_acct }}
    state: present
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030020
  - NIST-800-171-3.3.1
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(a)
  - NIST-800-53-CM-6(a)
  - NIST-800-53-IA-5(1)
  - PCI-DSS-Req-10.7.a
  - auditd_data_retention_action_mail_acct
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_auditd_action_mail_acct:var:1" value-id="xccdf_org.ssgproject.content_value_var_auditd_action_mail_acct"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_data_retention_action_mail_acct:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_data_retention_admin_space_left_action" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditd admin_space_left Action on Low Disk Space</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>auditd</html:code> service can be configured to take an action
when disk space is running low but prior to running out of space completely.
Edit the file <html:code>/etc/audit/auditd.conf</html:code>. Add or modify the following line,
substituting <html:i>ACTION</html:i> appropriately:
<html:pre>admin_space_left_action = <html:i>ACTION</html:i></html:pre>
Set this value to <html:code>single</html:code> to cause the system to switch to single user
mode for corrective action. Acceptable values also include <html:code>suspend</html:code> and
<html:code>halt</html:code>. For certain systems, the need for availability
outweighs the need to log all actions, and a different setting should be
determined. Details regarding all possible values for <html:i>ACTION</html:i> are described in the
<html:code>auditd.conf</html:code> man page.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(ii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000343-GPOS-00134</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.2.4</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Administrators should be made aware of an inability to record
audit records. If a separate partition or logical volume of adequate size
is used, running low on space for audit records should never occur.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_data_retention_admin_space_left_action" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_auditd_admin_space_left_action='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_admin_space_left_action" use="legacy"/>'


var_auditd_admin_space_left_action="$(echo $var_auditd_admin_space_left_action | cut -d \| -f 1)"

AUDITCONFIG=/etc/audit/auditd.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^admin_space_left_action")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_auditd_admin_space_left_action"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^admin_space_left_action\\&gt;" "$AUDITCONFIG"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^admin_space_left_action\\&gt;.*/$escaped_formatted_output/gi" "$AUDITCONFIG"
else
    if [[ -s "$AUDITCONFIG" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "$AUDITCONFIG" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "$AUDITCONFIG"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "$AUDITCONFIG"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_admin_space_left_action" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.3.1
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - PCI-DSSv4-10.5
  - PCI-DSSv4-10.5.1
  - auditd_data_retention_admin_space_left_action
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_auditd_admin_space_left_action # promote to variable
  set_fact:
    var_auditd_admin_space_left_action: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_admin_space_left_action" use="legacy"/>
  tags:
    - always

- name: Configure auditd admin_space_left Action on Low Disk Space
  ansible.builtin.lineinfile:
    dest: /etc/audit/auditd.conf
    line: admin_space_left_action = {{ var_auditd_admin_space_left_action .split('|')[0]
      }}
    regexp: ^\s*admin_space_left_action\s*=\s*.*$
    state: present
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.3.1
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - PCI-DSSv4-10.5
  - PCI-DSSv4-10.5.1
  - auditd_data_retention_admin_space_left_action
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_admin_space_left_action" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20audit%20daemon%0A%23%0A%0Alocal_events%20%3D%20yes%0Awrite_logs%20%3D%20yes%0Alog_file%20%3D%20/var/log/audit/audit.log%0Alog_group%20%3D%20root%0Alog_format%20%3D%20ENRICHED%0Aflush%20%3D%20%7B%7B.var_auditd_flush%7D%7D%0Afreq%20%3D%2050%0Amax_log_file%20%3D%20%7B%7B.var_auditd_max_log_file%7D%7D%0Anum_logs%20%3D%20%7B%7B.var_auditd_num_logs%7D%7D%0Apriority_boost%20%3D%204%0Aname_format%20%3D%20hostname%0A%23%23name%20%3D%20mydomain%0Amax_log_file_action%20%3D%20%7B%7B.var_auditd_max_log_file_action%7D%7D%0Aspace_left%20%3D%20%7B%7B.var_auditd_space_left%7D%7D%0Aspace_left_action%20%3D%20%7B%7B.var_auditd_space_left_action%7D%7D%0Averify_email%20%3D%20yes%0Aaction_mail_acct%20%3D%20%7B%7B.var_auditd_action_mail_acct%7D%7D%0Aadmin_space_left%20%3D%2050%0Aadmin_space_left_action%20%3D%20syslog%0Adisk_full_action%20%3D%20%7B%7B.var_auditd_disk_full_action%7D%7D%0Adisk_error_action%20%3D%20%7B%7B.var_auditd_disk_error_action%7D%7D%0Ause_libwrap%20%3D%20yes%0A%23%23tcp_listen_port%20%3D%2060%0Atcp_listen_queue%20%3D%205%0Atcp_max_per_addr%20%3D%201%0A%23%23tcp_client_ports%20%3D%201024-65535%0Atcp_client_max_idle%20%3D%200%0Atransport%20%3D%20TCP%0Akrb5_principal%20%3D%20auditd%0A%23%23krb5_key_file%20%3D%20/etc/audit/audit.key%0Adistribute_network%20%3D%20no%0Aq_depth%20%3D%20400%0Aoverflow_action%20%3D%20syslog%0Amax_restarts%20%3D%2010%0Aplugin_dir%20%3D%20/etc/audit/plugins.d }}
        mode: 0640
        path: /etc/audit/auditd.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_auditd_admin_space_left_action:var:1" value-id="xccdf_org.ssgproject.content_value_var_auditd_admin_space_left_action"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_data_retention_admin_space_left_action:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_data_retention_admin_space_left_action_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_data_retention_admin_space_left_percentage" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditd admin_space_left on Low Disk Space</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>auditd</html:code> service can be configured to take an action
when disk space is running low but prior to running out of space completely.
Edit the file <html:code>/etc/audit/auditd.conf</html:code>. Add or modify the following line,
substituting <html:i>PERCENTAGE</html:i> appropriately:
<html:pre>admin_space_left = <html:i>PERCENTAGE</html:i>%</html:pre>
Set this value to <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_admin_space_left_percentage" use="legacy"/>
to cause the system to perform an action.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000343-GPOS-00134</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Notifying administrators of an impending disk space problem may allow them to
take corrective action prior to any disruption.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_data_retention_admin_space_left_percentage" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_auditd_admin_space_left_percentage='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_admin_space_left_percentage" use="legacy"/>'


grep -q "^admin_space_left[[:space:]]*=.*$" /etc/audit/auditd.conf &amp;&amp; \
  sed -i "s/^admin_space_left[[:space:]]*=.*$/admin_space_left = $var_auditd_admin_space_left_percentage%/g" /etc/audit/auditd.conf || \
  echo "admin_space_left = $var_auditd_admin_space_left_percentage%" &gt;&gt; /etc/audit/auditd.conf

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_admin_space_left_percentage" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - auditd_data_retention_admin_space_left_percentage
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_auditd_admin_space_left_percentage # promote to variable
  set_fact:
    var_auditd_admin_space_left_percentage: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_admin_space_left_percentage" use="legacy"/>
  tags:
    - always

- name: Configure auditd admin_space_left on Low Disk Space
  ansible.builtin.lineinfile:
    dest: /etc/audit/auditd.conf
    line: admin_space_left = {{ var_auditd_admin_space_left_percentage }}%
    regexp: ^\s*admin_space_left\s*=\s*.*$
    state: present
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - auditd_data_retention_admin_space_left_percentage
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_auditd_admin_space_left_percentage:var:1" value-id="xccdf_org.ssgproject.content_value_var_auditd_admin_space_left_percentage"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_data_retention_admin_space_left_percentage:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_data_retention_admin_space_left_percentage_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_data_retention_flush" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditd flush priority</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>auditd</html:code> service can be configured to
synchronously write audit event data to disk. Add or correct the following
line in <html:code>/etc/audit/auditd.conf</html:code> to ensure that audit event data is
fully synchronized with the log files on the disk:
<html:pre>flush = <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_flush" use="legacy"/></html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO10.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.03</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA01.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(1)(ii)(D)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(3)(ii)(A)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.308(a)(5)(ii)(C)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(i)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(d)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(e)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.2.6.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.14.2.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.15.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.CM-7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">ID.SC-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Audit data should be synchronously written to disk to ensure
log integrity. These parameters assure that all audit event data is fully
synchronized with the log files on the disk.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_data_retention_flush" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_auditd_flush='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_flush" use="legacy"/>'


AUDITCONFIG=/etc/audit/auditd.conf

# if flush is present, flush param edited to var_auditd_flush
# else flush param is defined by var_auditd_flush
#
# the freq param is only used for values 'incremental' and 'incremental_async' and will be
# commented out if flush != incremental or flush != incremental_async
#
# if flush == incremental or flush == incremental_async &amp;&amp; freq param is not defined, it 
# will be defined as the package-default value of 20

grep -q ^flush $AUDITCONFIG &amp;&amp; \
  sed -i 's/^flush.*/flush = '"$var_auditd_flush"'/g' $AUDITCONFIG
if ! [ $? -eq 0 ]; then
  echo "flush = $var_auditd_flush" &gt;&gt; $AUDITCONFIG
fi

if ! [ "$var_auditd_flush" == "incremental" ] &amp;&amp; ! [ "$var_auditd_flush" == "incremental_async" ]; then
  sed -i 's/^freq/##freq/g' $AUDITCONFIG
elif [ "$var_auditd_flush" == "incremental" ] || [ "$var_auditd_flush" == "incremental_async" ]; then
  grep -q freq $AUDITCONFIG &amp;&amp; \
    sed -i 's/^#\+freq/freq/g' $AUDITCONFIG
  if ! [ $? -eq 0 ]; then
    echo "freq = 20" &gt;&gt; $AUDITCONFIG
  fi
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_flush" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-171-3.3.1
  - NIST-800-53-AU-11
  - NIST-800-53-CM-6(a)
  - auditd_data_retention_flush
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_auditd_flush # promote to variable
  set_fact:
    var_auditd_flush: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_flush" use="legacy"/>
  tags:
    - always

- name: Configure auditd Flush Priority
  ansible.builtin.lineinfile:
    dest: /etc/audit/auditd.conf
    regexp: ^\s*flush\s*=\s*.*$
    line: flush = {{ var_auditd_flush }}
    state: present
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-171-3.3.1
  - NIST-800-53-AU-11
  - NIST-800-53-CM-6(a)
  - auditd_data_retention_flush
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_flush" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20audit%20daemon%0A%23%0A%0Alocal_events%20%3D%20yes%0Awrite_logs%20%3D%20yes%0Alog_file%20%3D%20/var/log/audit/audit.log%0Alog_group%20%3D%20root%0Alog_format%20%3D%20ENRICHED%0Aflush%20%3D%20%7B%7B.var_auditd_flush%7D%7D%0Afreq%20%3D%2050%0Amax_log_file%20%3D%20%7B%7B.var_auditd_max_log_file%7D%7D%0Anum_logs%20%3D%20%7B%7B.var_auditd_num_logs%7D%7D%0Apriority_boost%20%3D%204%0Aname_format%20%3D%20hostname%0A%23%23name%20%3D%20mydomain%0Amax_log_file_action%20%3D%20%7B%7B.var_auditd_max_log_file_action%7D%7D%0Aspace_left%20%3D%20%7B%7B.var_auditd_space_left%7D%7D%0Aspace_left_action%20%3D%20%7B%7B.var_auditd_space_left_action%7D%7D%0Averify_email%20%3D%20yes%0Aaction_mail_acct%20%3D%20%7B%7B.var_auditd_action_mail_acct%7D%7D%0Aadmin_space_left%20%3D%2050%0Aadmin_space_left_action%20%3D%20syslog%0Adisk_full_action%20%3D%20%7B%7B.var_auditd_disk_full_action%7D%7D%0Adisk_error_action%20%3D%20%7B%7B.var_auditd_disk_error_action%7D%7D%0Ause_libwrap%20%3D%20yes%0A%23%23tcp_listen_port%20%3D%2060%0Atcp_listen_queue%20%3D%205%0Atcp_max_per_addr%20%3D%201%0A%23%23tcp_client_ports%20%3D%201024-65535%0Atcp_client_max_idle%20%3D%200%0Atransport%20%3D%20TCP%0Akrb5_principal%20%3D%20auditd%0A%23%23krb5_key_file%20%3D%20/etc/audit/audit.key%0Adistribute_network%20%3D%20no%0Aq_depth%20%3D%20400%0Aoverflow_action%20%3D%20syslog%0Amax_restarts%20%3D%2010%0Aplugin_dir%20%3D%20/etc/audit/plugins.d }}
        mode: 0640
        path: /etc/audit/auditd.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_auditd_flush:var:1" value-id="xccdf_org.ssgproject.content_value_var_auditd_flush"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_data_retention_flush:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_data_retention_flush_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_data_retention_max_log_file" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditd Max Log File Size</xccdf-1.2:title>
            <xccdf-1.2:description>Determine the amount of audit data (in megabytes)
which should be retained in each log file. Edit the file
<html:code>/etc/audit/auditd.conf</html:code>. Add or modify the following line, substituting
the correct value of <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_max_log_file" use="legacy"/> for <html:i>STOREMB</html:i>:
<html:pre>max_log_file = <html:i>STOREMB</html:i></html:pre>
Set the value to <html:code>6</html:code> (MB) or higher for general-purpose systems.
Larger values, of course,
support retention of even more audit data.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.2.1</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The total storage for audit log files must be large enough to retain
log information over the period required. This is a function of the maximum
log file size and the number of logs retained.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_data_retention_max_log_file" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_auditd_max_log_file='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_max_log_file" use="legacy"/>'


AUDITCONFIG=/etc/audit/auditd.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^max_log_file")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_auditd_max_log_file"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^max_log_file\\&gt;" "$AUDITCONFIG"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^max_log_file\\&gt;.*/$escaped_formatted_output/gi" "$AUDITCONFIG"
else
    if [[ -s "$AUDITCONFIG" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "$AUDITCONFIG" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "$AUDITCONFIG"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "$AUDITCONFIG"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_max_log_file" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - NIST-800-53-AU-11
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - auditd_data_retention_max_log_file
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_auditd_max_log_file # promote to variable
  set_fact:
    var_auditd_max_log_file: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_max_log_file" use="legacy"/>
  tags:
    - always

- name: Configure auditd Max Log File Size
  ansible.builtin.lineinfile:
    dest: /etc/audit/auditd.conf
    regexp: ^\s*max_log_file\s*=\s*.*$
    line: max_log_file = {{ var_auditd_max_log_file }}
    state: present
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-53-AU-11
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - auditd_data_retention_max_log_file
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_max_log_file" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20audit%20daemon%0A%23%0A%0Alocal_events%20%3D%20yes%0Awrite_logs%20%3D%20yes%0Alog_file%20%3D%20/var/log/audit/audit.log%0Alog_group%20%3D%20root%0Alog_format%20%3D%20ENRICHED%0Aflush%20%3D%20%7B%7B.var_auditd_flush%7D%7D%0Afreq%20%3D%2050%0Amax_log_file%20%3D%20%7B%7B.var_auditd_max_log_file%7D%7D%0Anum_logs%20%3D%20%7B%7B.var_auditd_num_logs%7D%7D%0Apriority_boost%20%3D%204%0Aname_format%20%3D%20hostname%0A%23%23name%20%3D%20mydomain%0Amax_log_file_action%20%3D%20%7B%7B.var_auditd_max_log_file_action%7D%7D%0Aspace_left%20%3D%20%7B%7B.var_auditd_space_left%7D%7D%0Aspace_left_action%20%3D%20%7B%7B.var_auditd_space_left_action%7D%7D%0Averify_email%20%3D%20yes%0Aaction_mail_acct%20%3D%20%7B%7B.var_auditd_action_mail_acct%7D%7D%0Aadmin_space_left%20%3D%2050%0Aadmin_space_left_action%20%3D%20syslog%0Adisk_full_action%20%3D%20%7B%7B.var_auditd_disk_full_action%7D%7D%0Adisk_error_action%20%3D%20%7B%7B.var_auditd_disk_error_action%7D%7D%0Ause_libwrap%20%3D%20yes%0A%23%23tcp_listen_port%20%3D%2060%0Atcp_listen_queue%20%3D%205%0Atcp_max_per_addr%20%3D%201%0A%23%23tcp_client_ports%20%3D%201024-65535%0Atcp_client_max_idle%20%3D%200%0Atransport%20%3D%20TCP%0Akrb5_principal%20%3D%20auditd%0A%23%23krb5_key_file%20%3D%20/etc/audit/audit.key%0Adistribute_network%20%3D%20no%0Aq_depth%20%3D%20400%0Aoverflow_action%20%3D%20syslog%0Amax_restarts%20%3D%2010%0Aplugin_dir%20%3D%20/etc/audit/plugins.d }}
        mode: 0640
        path: /etc/audit/auditd.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_auditd_max_log_file:var:1" value-id="xccdf_org.ssgproject.content_value_var_auditd_max_log_file"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_data_retention_max_log_file:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_data_retention_max_log_file_action" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditd max_log_file_action Upon Reaching Maximum Log Size</xccdf-1.2:title>
            <xccdf-1.2:description>The default action to take when the logs reach their maximum size
is to rotate the log files, discarding the oldest one. To configure the action taken
by <html:code>auditd</html:code>, add or correct the line in <html:code>/etc/audit/auditd.conf</html:code>:
<html:pre>max_log_file_action = <html:i>ACTION</html:i></html:pre>
Possible values for <html:i>ACTION</html:i> are described in the <html:code>auditd.conf</html:code> man
page. These include:
<html:ul><html:li><html:code>ignore</html:code></html:li><html:li><html:code>syslog</html:code></html:li><html:li><html:code>suspend</html:code></html:li><html:li><html:code>rotate</html:code></html:li><html:li><html:code>keep_logs</html:code></html:li></html:ul>
Set the <html:code><html:i>ACTION</html:i></html:code> to <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_max_log_file_action" use="legacy"/></html:code>.
The setting is case-insensitive.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(ii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000047-GPOS-00023</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.2.2</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Automatically rotating logs (by setting this to <html:code>rotate</html:code>)
minimizes the chances of the system unexpectedly running out of disk space by
being overwhelmed with log data. However, for systems that must never discard
log data, or which use external processes to transfer it and reclaim space,
<html:code>keep_logs</html:code> can be employed.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_data_retention_max_log_file_action" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_auditd_max_log_file_action='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_max_log_file_action" use="legacy"/>'


AUDITCONFIG=/etc/audit/auditd.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^max_log_file_action")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_auditd_max_log_file_action"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^max_log_file_action\\&gt;" "$AUDITCONFIG"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^max_log_file_action\\&gt;.*/$escaped_formatted_output/gi" "$AUDITCONFIG"
else
    if [[ -s "$AUDITCONFIG" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "$AUDITCONFIG" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "$AUDITCONFIG"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "$AUDITCONFIG"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_max_log_file_action" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - auditd_data_retention_max_log_file_action
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_auditd_max_log_file_action # promote to variable
  set_fact:
    var_auditd_max_log_file_action: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_max_log_file_action" use="legacy"/>
  tags:
    - always

- name: Configure auditd max_log_file_action Upon Reaching Maximum Log Size
  ansible.builtin.lineinfile:
    dest: /etc/audit/auditd.conf
    line: max_log_file_action = {{ var_auditd_max_log_file_action }}
    regexp: ^\s*max_log_file_action\s*=\s*.*$
    state: present
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - auditd_data_retention_max_log_file_action
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_max_log_file_action" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20audit%20daemon%0A%23%0A%0Alocal_events%20%3D%20yes%0Awrite_logs%20%3D%20yes%0Alog_file%20%3D%20/var/log/audit/audit.log%0Alog_group%20%3D%20root%0Alog_format%20%3D%20ENRICHED%0Aflush%20%3D%20%7B%7B.var_auditd_flush%7D%7D%0Afreq%20%3D%2050%0Amax_log_file%20%3D%20%7B%7B.var_auditd_max_log_file%7D%7D%0Anum_logs%20%3D%20%7B%7B.var_auditd_num_logs%7D%7D%0Apriority_boost%20%3D%204%0Aname_format%20%3D%20hostname%0A%23%23name%20%3D%20mydomain%0Amax_log_file_action%20%3D%20%7B%7B.var_auditd_max_log_file_action%7D%7D%0Aspace_left%20%3D%20%7B%7B.var_auditd_space_left%7D%7D%0Aspace_left_action%20%3D%20%7B%7B.var_auditd_space_left_action%7D%7D%0Averify_email%20%3D%20yes%0Aaction_mail_acct%20%3D%20%7B%7B.var_auditd_action_mail_acct%7D%7D%0Aadmin_space_left%20%3D%2050%0Aadmin_space_left_action%20%3D%20syslog%0Adisk_full_action%20%3D%20%7B%7B.var_auditd_disk_full_action%7D%7D%0Adisk_error_action%20%3D%20%7B%7B.var_auditd_disk_error_action%7D%7D%0Ause_libwrap%20%3D%20yes%0A%23%23tcp_listen_port%20%3D%2060%0Atcp_listen_queue%20%3D%205%0Atcp_max_per_addr%20%3D%201%0A%23%23tcp_client_ports%20%3D%201024-65535%0Atcp_client_max_idle%20%3D%200%0Atransport%20%3D%20TCP%0Akrb5_principal%20%3D%20auditd%0A%23%23krb5_key_file%20%3D%20/etc/audit/audit.key%0Adistribute_network%20%3D%20no%0Aq_depth%20%3D%20400%0Aoverflow_action%20%3D%20syslog%0Amax_restarts%20%3D%2010%0Aplugin_dir%20%3D%20/etc/audit/plugins.d }}
        mode: 0640
        path: /etc/audit/auditd.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_auditd_max_log_file_action:var:1" value-id="xccdf_org.ssgproject.content_value_var_auditd_max_log_file_action"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_data_retention_max_log_file_action:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_data_retention_max_log_file_action_stig" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditd max_log_file_action Upon Reaching Maximum Log Size</xccdf-1.2:title>
            <xccdf-1.2:description>The default action to take when the logs reach their maximum size
is to rotate the log files, discarding the oldest one. To configure the action taken
by <html:code>auditd</html:code>, add or correct the line in <html:code>/etc/audit/auditd.conf</html:code>:
<html:pre>max_log_file_action = <html:i>ACTION</html:i></html:pre>
Possible values for <html:i>ACTION</html:i> are described in the <html:code>auditd.conf</html:code> man
page. These include:
<html:ul><html:li><html:code>ignore</html:code></html:li><html:li><html:code>syslog</html:code></html:li><html:li><html:code>suspend</html:code></html:li><html:li><html:code>rotate</html:code></html:li><html:li><html:code>keep_logs</html:code></html:li></html:ul>
Set the <html:code><html:i>ACTION</html:i></html:code> to <html:code>rotate</html:code> to ensure log rotation
occurs. This is the default. The setting is case-insensitive.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(ii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000047-GPOS-00023</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000098-CTR-000185</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000099-CTR-000190</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000100-CTR-000195</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000100-CTR-000200</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000109-CTR-000215</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000290-CTR-000670</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000357-CTR-000800</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Automatically rotating logs (by setting this to <html:code>rotate</html:code>)
minimizes the chances of the system unexpectedly running out of disk space by
being overwhelmed with log data. However, for systems that must never discard
log data, or which use external processes to transfer it and reclaim space,
<html:code>keep_logs</html:code> can be employed.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_data_retention_max_log_file_action_stig" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_auditd_max_log_file_action='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_max_log_file_action" use="legacy"/>'


# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^max_log_file_action")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_auditd_max_log_file_action"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^max_log_file_action\\&gt;" "/etc/audit/auditd.conf"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^max_log_file_action\\&gt;.*/$escaped_formatted_output/gi" "/etc/audit/auditd.conf"
else
    if [[ -s "/etc/audit/auditd.conf" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "/etc/audit/auditd.conf" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "/etc/audit/auditd.conf"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "/etc/audit/auditd.conf"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_max_log_file_action_stig" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - auditd_data_retention_max_log_file_action_stig
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_auditd_max_log_file_action # promote to variable
  set_fact:
    var_auditd_max_log_file_action: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_max_log_file_action" use="legacy"/>
  tags:
    - always

- name: Configure auditd max_log_file_action Upon Reaching Maximum Log Size
  ansible.builtin.lineinfile:
    dest: /etc/audit/auditd.conf
    line: max_log_file_action = {{ var_auditd_max_log_file_action }}
    regexp: ^\s*max_log_file_action\s*=\s*.*$
    state: present
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - auditd_data_retention_max_log_file_action_stig
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_max_log_file_action_stig" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20audit%20daemon%0A%23%0A%0Alocal_events%20%3D%20yes%0Awrite_logs%20%3D%20yes%0Alog_file%20%3D%20/var/log/audit/audit.log%0Alog_group%20%3D%20root%0Alog_format%20%3D%20ENRICHED%0Aflush%20%3D%20%7B%7B.var_auditd_flush%7D%7D%0Afreq%20%3D%2050%0Amax_log_file%20%3D%20%7B%7B.var_auditd_max_log_file%7D%7D%0Anum_logs%20%3D%20%7B%7B.var_auditd_num_logs%7D%7D%0Apriority_boost%20%3D%204%0Aname_format%20%3D%20hostname%0A%23%23name%20%3D%20mydomain%0Amax_log_file_action%20%3D%20%7B%7B.var_auditd_max_log_file_action%7D%7D%0Aspace_left%20%3D%20%7B%7B.var_auditd_space_left%7D%7D%0Aspace_left_action%20%3D%20%7B%7B.var_auditd_space_left_action%7D%7D%0Averify_email%20%3D%20yes%0Aaction_mail_acct%20%3D%20%7B%7B.var_auditd_action_mail_acct%7D%7D%0Aadmin_space_left%20%3D%2050%0Aadmin_space_left_action%20%3D%20syslog%0Adisk_full_action%20%3D%20%7B%7B.var_auditd_disk_full_action%7D%7D%0Adisk_error_action%20%3D%20%7B%7B.var_auditd_disk_error_action%7D%7D%0Ause_libwrap%20%3D%20yes%0A%23%23tcp_listen_port%20%3D%2060%0Atcp_listen_queue%20%3D%205%0Atcp_max_per_addr%20%3D%201%0A%23%23tcp_client_ports%20%3D%201024-65535%0Atcp_client_max_idle%20%3D%200%0Atransport%20%3D%20TCP%0Akrb5_principal%20%3D%20auditd%0A%23%23krb5_key_file%20%3D%20/etc/audit/audit.key%0Adistribute_network%20%3D%20no%0Aq_depth%20%3D%20400%0Aoverflow_action%20%3D%20syslog%0Amax_restarts%20%3D%2010%0Aplugin_dir%20%3D%20/etc/audit/plugins.d }}
        mode: 0640
        path: /etc/audit/auditd.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_data_retention_max_log_file_action_stig:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_data_retention_num_logs" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditd Number of Logs Retained</xccdf-1.2:title>
            <xccdf-1.2:description>Determine how many log files
<html:code>auditd</html:code> should retain when it rotates logs.
Edit the file <html:code>/etc/audit/auditd.conf</html:code>. Add or modify the following
line, substituting <html:i>NUMLOGS</html:i> with the correct value of <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_num_logs" use="legacy"/>:
<html:pre>num_logs = <html:i>NUMLOGS</html:i></html:pre>
Set the value to 5 for general-purpose systems.
Note that values less than 2 result in no log rotation.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R2.2.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-004-6 R3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R5.3.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.nerc.com/standards/reliability-standards/cip">CIP-007-3 R6.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.7</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The total storage for audit log files must be large enough to retain
log information over the period required. This is a function of the maximum log
file size and the number of logs retained.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_data_retention_num_logs" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_auditd_num_logs='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_num_logs" use="legacy"/>'


AUDITCONFIG=/etc/audit/auditd.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^num_logs")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_auditd_num_logs"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^num_logs\\&gt;" "$AUDITCONFIG"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^num_logs\\&gt;.*/$escaped_formatted_output/gi" "$AUDITCONFIG"
else
    if [[ -s "$AUDITCONFIG" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "$AUDITCONFIG" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "$AUDITCONFIG"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "$AUDITCONFIG"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_num_logs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.3.1
  - NIST-800-53-AU-11
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - auditd_data_retention_num_logs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_auditd_num_logs # promote to variable
  set_fact:
    var_auditd_num_logs: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_num_logs" use="legacy"/>
  tags:
    - always

- name: Configure auditd Number of Logs Retained
  ansible.builtin.lineinfile:
    dest: /etc/audit/auditd.conf
    line: num_logs = {{ var_auditd_num_logs }}
    regexp: ^\s*num_logs\s*=\s*.*$
    state: present
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - NIST-800-171-3.3.1
  - NIST-800-53-AU-11
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - auditd_data_retention_num_logs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_num_logs" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20audit%20daemon%0A%23%0A%0Alocal_events%20%3D%20yes%0Awrite_logs%20%3D%20yes%0Alog_file%20%3D%20/var/log/audit/audit.log%0Alog_group%20%3D%20root%0Alog_format%20%3D%20ENRICHED%0Aflush%20%3D%20%7B%7B.var_auditd_flush%7D%7D%0Afreq%20%3D%2050%0Amax_log_file%20%3D%20%7B%7B.var_auditd_max_log_file%7D%7D%0Anum_logs%20%3D%20%7B%7B.var_auditd_num_logs%7D%7D%0Apriority_boost%20%3D%204%0Aname_format%20%3D%20hostname%0A%23%23name%20%3D%20mydomain%0Amax_log_file_action%20%3D%20%7B%7B.var_auditd_max_log_file_action%7D%7D%0Aspace_left%20%3D%20%7B%7B.var_auditd_space_left%7D%7D%0Aspace_left_action%20%3D%20%7B%7B.var_auditd_space_left_action%7D%7D%0Averify_email%20%3D%20yes%0Aaction_mail_acct%20%3D%20%7B%7B.var_auditd_action_mail_acct%7D%7D%0Aadmin_space_left%20%3D%2050%0Aadmin_space_left_action%20%3D%20syslog%0Adisk_full_action%20%3D%20%7B%7B.var_auditd_disk_full_action%7D%7D%0Adisk_error_action%20%3D%20%7B%7B.var_auditd_disk_error_action%7D%7D%0Ause_libwrap%20%3D%20yes%0A%23%23tcp_listen_port%20%3D%2060%0Atcp_listen_queue%20%3D%205%0Atcp_max_per_addr%20%3D%201%0A%23%23tcp_client_ports%20%3D%201024-65535%0Atcp_client_max_idle%20%3D%200%0Atransport%20%3D%20TCP%0Akrb5_principal%20%3D%20auditd%0A%23%23krb5_key_file%20%3D%20/etc/audit/audit.key%0Adistribute_network%20%3D%20no%0Aq_depth%20%3D%20400%0Aoverflow_action%20%3D%20syslog%0Amax_restarts%20%3D%2010%0Aplugin_dir%20%3D%20/etc/audit/plugins.d }}
        mode: 0640
        path: /etc/audit/auditd.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_auditd_num_logs:var:1" value-id="xccdf_org.ssgproject.content_value_var_auditd_num_logs"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_data_retention_num_logs:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_data_retention_num_logs_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_data_retention_space_left" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditd space_left on Low Disk Space</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>auditd</html:code> service can be configured to take an action
when disk space is running low but prior to running out of space completely.
Edit the file <html:code>/etc/audit/auditd.conf</html:code>. Add or modify the following line,
substituting <html:i>SIZE_in_MB</html:i> appropriately:
<html:pre>space_left = <html:i>SIZE_in_MB</html:i></html:pre>
Set this value to the appropriate size in Megabytes cause the system to
notify the user of an issue.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000343-GPOS-00134</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.5</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Notifying administrators of an impending disk space problem may allow them to
take corrective action prior to any disruption.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_data_retention_space_left" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_auditd_space_left='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_space_left" use="legacy"/>'


grep -q "^space_left[[:space:]]*=.*$" /etc/audit/auditd.conf &amp;&amp; \
  sed -i "s/^space_left[[:space:]]*=.*$/space_left = $var_auditd_space_left/g" /etc/audit/auditd.conf || \
  echo "space_left = $var_auditd_space_left" &gt;&gt; /etc/audit/auditd.conf

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_space_left" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - PCI-DSSv4-10.5
  - PCI-DSSv4-10.5.1
  - auditd_data_retention_space_left
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_auditd_space_left # promote to variable
  set_fact:
    var_auditd_space_left: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_space_left" use="legacy"/>
  tags:
    - always

- name: Configure auditd space_left on Low Disk Space
  ansible.builtin.lineinfile:
    dest: /etc/audit/auditd.conf
    line: space_left = {{ var_auditd_space_left }}
    regexp: ^\s*space_left\s*=\s*.*$
    state: present
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - PCI-DSSv4-10.5
  - PCI-DSSv4-10.5.1
  - auditd_data_retention_space_left
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_space_left" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20audit%20daemon%0A%23%0A%0Alocal_events%20%3D%20yes%0Awrite_logs%20%3D%20yes%0Alog_file%20%3D%20/var/log/audit/audit.log%0Alog_group%20%3D%20root%0Alog_format%20%3D%20ENRICHED%0Aflush%20%3D%20%7B%7B.var_auditd_flush%7D%7D%0Afreq%20%3D%2050%0Amax_log_file%20%3D%20%7B%7B.var_auditd_max_log_file%7D%7D%0Anum_logs%20%3D%20%7B%7B.var_auditd_num_logs%7D%7D%0Apriority_boost%20%3D%204%0Aname_format%20%3D%20hostname%0A%23%23name%20%3D%20mydomain%0Amax_log_file_action%20%3D%20%7B%7B.var_auditd_max_log_file_action%7D%7D%0Aspace_left%20%3D%20%7B%7B.var_auditd_space_left%7D%7D%0Aspace_left_action%20%3D%20%7B%7B.var_auditd_space_left_action%7D%7D%0Averify_email%20%3D%20yes%0Aaction_mail_acct%20%3D%20%7B%7B.var_auditd_action_mail_acct%7D%7D%0Aadmin_space_left%20%3D%2050%0Aadmin_space_left_action%20%3D%20syslog%0Adisk_full_action%20%3D%20%7B%7B.var_auditd_disk_full_action%7D%7D%0Adisk_error_action%20%3D%20%7B%7B.var_auditd_disk_error_action%7D%7D%0Ause_libwrap%20%3D%20yes%0A%23%23tcp_listen_port%20%3D%2060%0Atcp_listen_queue%20%3D%205%0Atcp_max_per_addr%20%3D%201%0A%23%23tcp_client_ports%20%3D%201024-65535%0Atcp_client_max_idle%20%3D%200%0Atransport%20%3D%20TCP%0Akrb5_principal%20%3D%20auditd%0A%23%23krb5_key_file%20%3D%20/etc/audit/audit.key%0Adistribute_network%20%3D%20no%0Aq_depth%20%3D%20400%0Aoverflow_action%20%3D%20syslog%0Amax_restarts%20%3D%2010%0Aplugin_dir%20%3D%20/etc/audit/plugins.d }}
        mode: 0640
        path: /etc/audit/auditd.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_auditd_space_left:var:1" value-id="xccdf_org.ssgproject.content_value_var_auditd_space_left"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_data_retention_space_left:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_data_retention_space_left_action" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditd space_left Action on Low Disk Space</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>auditd</html:code> service can be configured to take an action
when disk space <html:i>starts</html:i> to run low.
Edit the file <html:code>/etc/audit/auditd.conf</html:code>. Modify the following line,
substituting <html:i>ACTION</html:i> appropriately:
<html:pre>space_left_action = <html:i>ACTION</html:i></html:pre>
Possible values for <html:i>ACTION</html:i> are described in the <html:code>auditd.conf</html:code> man page.
These include:
<html:ul><html:li><html:code>syslog</html:code></html:li><html:li><html:code>email</html:code></html:li><html:li><html:code>exec</html:code></html:li><html:li><html:code>suspend</html:code></html:li><html:li><html:code>single</html:code></html:li><html:li><html:code>halt</html:code></html:li></html:ul>
Set this to <html:code>email</html:code> (instead of the default,
which is <html:code>suspend</html:code>) as it is more likely to get prompt attention. Acceptable values
also include <html:code>suspend</html:code>, <html:code>single</html:code>, and <html:code>halt</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf">5.4.1.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf">3.3.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf">164.312(a)(2)(ii)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000343-GPOS-00134</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.5.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030731</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-244543r971542_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Notifying administrators of an impending disk space problem may
allow them to take corrective action prior to any disruption.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_data_retention_space_left_action" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_auditd_space_left_action='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_space_left_action" use="legacy"/>'


var_auditd_space_left_action="$(echo $var_auditd_space_left_action | cut -d \| -f 1)"
#
# If space_left_action present in /etc/audit/auditd.conf, change value
# to var_auditd_space_left_action, else
# add "space_left_action = $var_auditd_space_left_action" to /etc/audit/auditd.conf
#

AUDITCONFIG=/etc/audit/auditd.conf

# Strip any search characters in the key arg so that the key can be replaced without
# adding any search characters to the config file.
stripped_key=$(sed 's/[\^=\$,;+]*//g' &lt;&lt;&lt; "^space_left_action")

# shellcheck disable=SC2059
printf -v formatted_output "%s = %s" "$stripped_key" "$var_auditd_space_left_action"

# If the key exists, change it. Otherwise, add it to the config_file.
# We search for the key string followed by a word boundary (matched by \&gt;),
# so if we search for 'setting', 'setting2' won't match.
if LC_ALL=C grep -q -m 1 -i -e "^space_left_action\\&gt;" "$AUDITCONFIG"; then
    escaped_formatted_output=$(sed -e 's|/|\\/|g' &lt;&lt;&lt; "$formatted_output")
    LC_ALL=C sed -i --follow-symlinks "s/^space_left_action\\&gt;.*/$escaped_formatted_output/gi" "$AUDITCONFIG"
else
    if [[ -s "$AUDITCONFIG" ]] &amp;&amp; [[ -n "$(tail -c 1 -- "$AUDITCONFIG" || true)" ]]; then
        LC_ALL=C sed -i --follow-symlinks '$a'\\ "$AUDITCONFIG"
    fi
    printf '%s\n' "$formatted_output" &gt;&gt; "$AUDITCONFIG"
fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_space_left_action" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030731
  - NIST-800-171-3.3.1
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - PCI-DSSv4-10.5
  - PCI-DSSv4-10.5.1
  - auditd_data_retention_space_left_action
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_auditd_space_left_action # promote to variable
  set_fact:
    var_auditd_space_left_action: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_space_left_action" use="legacy"/>
  tags:
    - always

- name: Configure auditd space_left Action on Low Disk Space
  ansible.builtin.lineinfile:
    dest: /etc/audit/auditd.conf
    line: space_left_action = {{ var_auditd_space_left_action.split('|')[0] }}
    regexp: ^\s*space_left_action\s*=\s*.*$
    state: present
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - CJIS-5.4.1.1
  - DISA-STIG-RHEL-08-030731
  - NIST-800-171-3.3.1
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - PCI-DSSv4-10.5
  - PCI-DSSv4-10.5.1
  - auditd_data_retention_space_left_action
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_space_left_action" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20audit%20daemon%0A%23%0A%0Alocal_events%20%3D%20yes%0Awrite_logs%20%3D%20yes%0Alog_file%20%3D%20/var/log/audit/audit.log%0Alog_group%20%3D%20root%0Alog_format%20%3D%20ENRICHED%0Aflush%20%3D%20%7B%7B.var_auditd_flush%7D%7D%0Afreq%20%3D%2050%0Amax_log_file%20%3D%20%7B%7B.var_auditd_max_log_file%7D%7D%0Anum_logs%20%3D%20%7B%7B.var_auditd_num_logs%7D%7D%0Apriority_boost%20%3D%204%0Aname_format%20%3D%20hostname%0A%23%23name%20%3D%20mydomain%0Amax_log_file_action%20%3D%20%7B%7B.var_auditd_max_log_file_action%7D%7D%0Aspace_left%20%3D%20%7B%7B.var_auditd_space_left%7D%7D%0Aspace_left_action%20%3D%20%7B%7B.var_auditd_space_left_action%7D%7D%0Averify_email%20%3D%20yes%0Aaction_mail_acct%20%3D%20%7B%7B.var_auditd_action_mail_acct%7D%7D%0Aadmin_space_left%20%3D%2050%0Aadmin_space_left_action%20%3D%20syslog%0Adisk_full_action%20%3D%20%7B%7B.var_auditd_disk_full_action%7D%7D%0Adisk_error_action%20%3D%20%7B%7B.var_auditd_disk_error_action%7D%7D%0Ause_libwrap%20%3D%20yes%0A%23%23tcp_listen_port%20%3D%2060%0Atcp_listen_queue%20%3D%205%0Atcp_max_per_addr%20%3D%201%0A%23%23tcp_client_ports%20%3D%201024-65535%0Atcp_client_max_idle%20%3D%200%0Atransport%20%3D%20TCP%0Akrb5_principal%20%3D%20auditd%0A%23%23krb5_key_file%20%3D%20/etc/audit/audit.key%0Adistribute_network%20%3D%20no%0Aq_depth%20%3D%20400%0Aoverflow_action%20%3D%20syslog%0Amax_restarts%20%3D%2010%0Aplugin_dir%20%3D%20/etc/audit/plugins.d }}
        mode: 0640
        path: /etc/audit/auditd.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_auditd_space_left_action:var:1" value-id="xccdf_org.ssgproject.content_value_var_auditd_space_left_action"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_data_retention_space_left_action:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_data_retention_space_left_percentage" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditd space_left on Low Disk Space</xccdf-1.2:title>
            <xccdf-1.2:description>The <html:code>auditd</html:code> service can be configured to take an action
when disk space is running low but prior to running out of space completely.
Edit the file <html:code>/etc/audit/auditd.conf</html:code>. Add or modify the following line,
substituting <html:i>PERCENTAGE</html:i> appropriately:
<html:pre>space_left = <html:i>PERCENTAGE</html:i>%</html:pre>
Set this value to at least 25 to cause the system to
notify the user of an issue.</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">13</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">14</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">15</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">16</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">19</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/controls/">8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO11.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO12.06</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">APO13.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI03.05</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI04.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">BAI08.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.02</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS02.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS03.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.04</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">DSS05.07</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isaca.org/resources/cobit">MEA02.01</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.2.3.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.3.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.3.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.4.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.3.4.5.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat">4.4.2.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.10</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.11</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.12</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.8</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 2.9</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 6.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu">SR 7.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.1.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.4.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.12.7.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.16.1.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.iso.org/contents/data/standard/05/45/54534.html">A.17.2.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(2)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-5(4)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">DE.AE-5</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.DS-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.PT-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">RS.AN-4</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-10.7</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000343-GPOS-00134</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030730</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230483r971542_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Notifying administrators of an impending disk space problem may allow them to
take corrective action prior to any disruption.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="auditd_data_retention_space_left_percentage" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_auditd_space_left_percentage='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_space_left_percentage" use="legacy"/>'


grep -q "^space_left[[:space:]]*=.*$" /etc/audit/auditd.conf &amp;&amp; \
  sed -i "s/^space_left[[:space:]]*=.*$/space_left = $var_auditd_space_left_percentage%/g" /etc/audit/auditd.conf || \
  echo "space_left = $var_auditd_space_left_percentage%" &gt;&gt; /etc/audit/auditd.conf

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_data_retention_space_left_percentage" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030730
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - auditd_data_retention_space_left_percentage
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_auditd_space_left_percentage # promote to variable
  set_fact:
    var_auditd_space_left_percentage: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_space_left_percentage" use="legacy"/>
  tags:
    - always

- name: Configure auditd space_left on Low Disk Space
  ansible.builtin.lineinfile:
    dest: /etc/audit/auditd.conf
    line: space_left = {{ var_auditd_space_left_percentage }}%
    regexp: ^\s*space_left\s*=\s*.*$
    state: present
    create: true
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030730
  - NIST-800-53-AU-5(1)
  - NIST-800-53-AU-5(2)
  - NIST-800-53-AU-5(4)
  - NIST-800-53-AU-5(b)
  - NIST-800-53-CM-6(a)
  - PCI-DSS-Req-10.7
  - auditd_data_retention_space_left_percentage
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_auditd_space_left_percentage:var:1" value-id="xccdf_org.ssgproject.content_value_var_auditd_space_left_percentage"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_data_retention_space_left_percentage:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_data_retention_space_left_percentage_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_freq" selected="false" severity="medium">
            <xccdf-1.2:title>Set number of records to cause an explicit flush to audit logs</xccdf-1.2:title>
            <xccdf-1.2:description>To configure Audit daemon to issue an explicit flush to disk command
after writing <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_freq" use="legacy"/> records, set <html:code>freq</html:code> to <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_freq" use="legacy"/></html:code>
in <html:code>/etc/audit/auditd.conf</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000051-GPOS-00024</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If option <html:code>freq</html:code> isn't set to <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_freq" use="legacy"/></html:code>, the flush to disk
may happen after higher number of records, increasing the danger
of audit loss.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_freq" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_auditd_freq='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_freq" use="legacy"/>'



if [ -e "/etc/audit/auditd.conf" ] ; then
    
    LC_ALL=C sed -i "/^\s*freq\s*=\s*/Id" "/etc/audit/auditd.conf"
else
    touch "/etc/audit/auditd.conf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/audit/auditd.conf"

cp "/etc/audit/auditd.conf" "/etc/audit/auditd.conf.bak"
# Insert at the end of the file
printf '%s\n' "freq = $var_auditd_freq" &gt;&gt; "/etc/audit/auditd.conf"
# Clean up after ourselves.
rm "/etc/audit/auditd.conf.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_freq" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6
  - auditd_freq
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_auditd_freq # promote to variable
  set_fact:
    var_auditd_freq: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_freq" use="legacy"/>
  tags:
    - always

- name: Set number of records to cause an explicit flush to audit logs
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*freq\s*=\s*
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/audit/auditd.conf
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*freq\s*=\s*
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/audit/auditd.conf
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*freq\s*=\s*
      line: freq = {{ var_auditd_freq }}
      state: present
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6
  - auditd_freq
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_freq" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20audit%20daemon%0A%23%0A%0Alocal_events%20%3D%20yes%0Awrite_logs%20%3D%20yes%0Alog_file%20%3D%20/var/log/audit/audit.log%0Alog_group%20%3D%20root%0Alog_format%20%3D%20ENRICHED%0Aflush%20%3D%20%7B%7B.var_auditd_flush%7D%7D%0Afreq%20%3D%2050%0Amax_log_file%20%3D%20%7B%7B.var_auditd_max_log_file%7D%7D%0Anum_logs%20%3D%20%7B%7B.var_auditd_num_logs%7D%7D%0Apriority_boost%20%3D%204%0Aname_format%20%3D%20hostname%0A%23%23name%20%3D%20mydomain%0Amax_log_file_action%20%3D%20%7B%7B.var_auditd_max_log_file_action%7D%7D%0Aspace_left%20%3D%20%7B%7B.var_auditd_space_left%7D%7D%0Aspace_left_action%20%3D%20%7B%7B.var_auditd_space_left_action%7D%7D%0Averify_email%20%3D%20yes%0Aaction_mail_acct%20%3D%20%7B%7B.var_auditd_action_mail_acct%7D%7D%0Aadmin_space_left%20%3D%2050%0Aadmin_space_left_action%20%3D%20syslog%0Adisk_full_action%20%3D%20%7B%7B.var_auditd_disk_full_action%7D%7D%0Adisk_error_action%20%3D%20%7B%7B.var_auditd_disk_error_action%7D%7D%0Ause_libwrap%20%3D%20yes%0A%23%23tcp_listen_port%20%3D%2060%0Atcp_listen_queue%20%3D%205%0Atcp_max_per_addr%20%3D%201%0A%23%23tcp_client_ports%20%3D%201024-65535%0Atcp_client_max_idle%20%3D%200%0Atransport%20%3D%20TCP%0Akrb5_principal%20%3D%20auditd%0A%23%23krb5_key_file%20%3D%20/etc/audit/audit.key%0Adistribute_network%20%3D%20no%0Aq_depth%20%3D%20400%0Aoverflow_action%20%3D%20syslog%0Amax_restarts%20%3D%2010%0Aplugin_dir%20%3D%20/etc/audit/plugins.d }}
        mode: 0640
        path: /etc/audit/auditd.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_auditd_freq:var:1" value-id="xccdf_org.ssgproject.content_value_var_auditd_freq"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_freq:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_freq_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_local_events" selected="false" severity="medium">
            <xccdf-1.2:title>Include Local Events in Audit Logs</xccdf-1.2:title>
            <xccdf-1.2:description>To configure Audit daemon to include local events in Audit logs, set
<html:code>local_events</html:code> to <html:code>yes</html:code> in <html:code>/etc/audit/auditd.conf</html:code>.
This is the default setting.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000062-GPOS-00031</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030061</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230393r1017200_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If option <html:code>local_events</html:code> isn't set to <html:code>yes</html:code> only events from
network will be aggregated.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_local_events" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

if [ -e "/etc/audit/auditd.conf" ] ; then
    
    LC_ALL=C sed -i "/^\s*local_events\s*=\s*/Id" "/etc/audit/auditd.conf"
else
    touch "/etc/audit/auditd.conf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/audit/auditd.conf"

cp "/etc/audit/auditd.conf" "/etc/audit/auditd.conf.bak"
# Insert at the end of the file
printf '%s\n' "local_events = yes" &gt;&gt; "/etc/audit/auditd.conf"
# Clean up after ourselves.
rm "/etc/audit/auditd.conf.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_local_events" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030061
  - NIST-800-53-CM-6
  - auditd_local_events
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Include Local Events in Audit Logs
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*local_events\s*=\s*
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/audit/auditd.conf
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*local_events\s*=\s*
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/audit/auditd.conf
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*local_events\s*=\s*
      line: local_events = yes
      state: present
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030061
  - NIST-800-53-CM-6
  - auditd_local_events
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_local_events" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20audit%20daemon%0A%23%0A%0Alocal_events%20%3D%20yes%0Awrite_logs%20%3D%20yes%0Alog_file%20%3D%20/var/log/audit/audit.log%0Alog_group%20%3D%20root%0Alog_format%20%3D%20ENRICHED%0Aflush%20%3D%20%7B%7B.var_auditd_flush%7D%7D%0Afreq%20%3D%2050%0Amax_log_file%20%3D%20%7B%7B.var_auditd_max_log_file%7D%7D%0Anum_logs%20%3D%20%7B%7B.var_auditd_num_logs%7D%7D%0Apriority_boost%20%3D%204%0Aname_format%20%3D%20hostname%0A%23%23name%20%3D%20mydomain%0Amax_log_file_action%20%3D%20%7B%7B.var_auditd_max_log_file_action%7D%7D%0Aspace_left%20%3D%20%7B%7B.var_auditd_space_left%7D%7D%0Aspace_left_action%20%3D%20%7B%7B.var_auditd_space_left_action%7D%7D%0Averify_email%20%3D%20yes%0Aaction_mail_acct%20%3D%20%7B%7B.var_auditd_action_mail_acct%7D%7D%0Aadmin_space_left%20%3D%2050%0Aadmin_space_left_action%20%3D%20syslog%0Adisk_full_action%20%3D%20%7B%7B.var_auditd_disk_full_action%7D%7D%0Adisk_error_action%20%3D%20%7B%7B.var_auditd_disk_error_action%7D%7D%0Ause_libwrap%20%3D%20yes%0A%23%23tcp_listen_port%20%3D%2060%0Atcp_listen_queue%20%3D%205%0Atcp_max_per_addr%20%3D%201%0A%23%23tcp_client_ports%20%3D%201024-65535%0Atcp_client_max_idle%20%3D%200%0Atransport%20%3D%20TCP%0Akrb5_principal%20%3D%20auditd%0A%23%23krb5_key_file%20%3D%20/etc/audit/audit.key%0Adistribute_network%20%3D%20no%0Aq_depth%20%3D%20400%0Aoverflow_action%20%3D%20syslog%0Amax_restarts%20%3D%2010%0Aplugin_dir%20%3D%20/etc/audit/plugins.d }}
        mode: 0640
        path: /etc/audit/auditd.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_local_events:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_local_events_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_log_format" selected="false" severity="low">
            <xccdf-1.2:title>Resolve information before writing to audit logs</xccdf-1.2:title>
            <xccdf-1.2:description>To configure Audit daemon to resolve all uid, gid, syscall,
architecture, and socket address information before writing the
events to disk, set <html:code>log_format</html:code> to <html:code>ENRICHED</html:code>
in <html:code>/etc/audit/auditd.conf</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000255-GPOS-00096</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000096-CTR-000175</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000097-CTR-000180</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000098-CTR-000185</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000099-CTR-000190</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000100-CTR-000195</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000100-CTR-000200</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000109-CTR-000215</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000290-CTR-000670</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000357-CTR-000800</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030063</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230395r1017201_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If option <html:code>log_format</html:code> isn't set to <html:code>ENRICHED</html:code>, the
audit records will be stored in a format exactly as the kernel sends them.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_log_format" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

if [ -e "/etc/audit/auditd.conf" ] ; then
    
    LC_ALL=C sed -i "/^\s*log_format\s*=\s*/Id" "/etc/audit/auditd.conf"
else
    touch "/etc/audit/auditd.conf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/audit/auditd.conf"

cp "/etc/audit/auditd.conf" "/etc/audit/auditd.conf.bak"
# Insert at the end of the file
printf '%s\n' "log_format = ENRICHED" &gt;&gt; "/etc/audit/auditd.conf"
# Clean up after ourselves.
rm "/etc/audit/auditd.conf.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_log_format" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030063
  - NIST-800-53-AU-3
  - NIST-800-53-CM-6
  - auditd_log_format
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy

- name: Resolve information before writing to audit logs
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*log_format\s*=\s*
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/audit/auditd.conf
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*log_format\s*=\s*
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/audit/auditd.conf
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*log_format\s*=\s*
      line: log_format = ENRICHED
      state: present
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030063
  - NIST-800-53-AU-3
  - NIST-800-53-CM-6
  - auditd_log_format
  - low_complexity
  - low_disruption
  - low_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_log_format" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20audit%20daemon%0A%23%0A%0Alocal_events%20%3D%20yes%0Awrite_logs%20%3D%20yes%0Alog_file%20%3D%20/var/log/audit/audit.log%0Alog_group%20%3D%20root%0Alog_format%20%3D%20ENRICHED%0Aflush%20%3D%20%7B%7B.var_auditd_flush%7D%7D%0Afreq%20%3D%2050%0Amax_log_file%20%3D%20%7B%7B.var_auditd_max_log_file%7D%7D%0Anum_logs%20%3D%20%7B%7B.var_auditd_num_logs%7D%7D%0Apriority_boost%20%3D%204%0Aname_format%20%3D%20hostname%0A%23%23name%20%3D%20mydomain%0Amax_log_file_action%20%3D%20%7B%7B.var_auditd_max_log_file_action%7D%7D%0Aspace_left%20%3D%20%7B%7B.var_auditd_space_left%7D%7D%0Aspace_left_action%20%3D%20%7B%7B.var_auditd_space_left_action%7D%7D%0Averify_email%20%3D%20yes%0Aaction_mail_acct%20%3D%20%7B%7B.var_auditd_action_mail_acct%7D%7D%0Aadmin_space_left%20%3D%2050%0Aadmin_space_left_action%20%3D%20syslog%0Adisk_full_action%20%3D%20%7B%7B.var_auditd_disk_full_action%7D%7D%0Adisk_error_action%20%3D%20%7B%7B.var_auditd_disk_error_action%7D%7D%0Ause_libwrap%20%3D%20yes%0A%23%23tcp_listen_port%20%3D%2060%0Atcp_listen_queue%20%3D%205%0Atcp_max_per_addr%20%3D%201%0A%23%23tcp_client_ports%20%3D%201024-65535%0Atcp_client_max_idle%20%3D%200%0Atransport%20%3D%20TCP%0Akrb5_principal%20%3D%20auditd%0A%23%23krb5_key_file%20%3D%20/etc/audit/audit.key%0Adistribute_network%20%3D%20no%0Aq_depth%20%3D%20400%0Aoverflow_action%20%3D%20syslog%0Amax_restarts%20%3D%2010%0Aplugin_dir%20%3D%20/etc/audit/plugins.d }}
        mode: 0640
        path: /etc/audit/auditd.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_log_format:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_log_format_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_name_format" selected="false" severity="medium">
            <xccdf-1.2:title>Set type of computer node name logging in audit logs</xccdf-1.2:title>
            <xccdf-1.2:description>To configure Audit daemon to use a unique identifier
as computer node name in the audit events,
set <html:code>name_format</html:code> to <html:code><xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_name_format" use="legacy"/></html:code>
in <html:code>/etc/audit/auditd.conf</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:warning category="general">Whenever the variable <html:pre>var_auditd_name_format</html:pre> uses a multiple value option, for example
<html:pre>A|B|C</html:pre>, the first value will be used when remediating this rule.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-3</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000039-GPOS-00017</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000342-GPOS-00133</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000479-GPOS-00224</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">10.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030062</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230394r958754_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If option <html:code>name_format</html:code> is left at its default value of
<html:code>none</html:code>, audit events from different computers may be hard
to distinguish.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_name_format" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

var_auditd_name_format='<xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_name_format" use="legacy"/>'


var_auditd_name_format="$(echo $var_auditd_name_format | cut -d \| -f 1)"

if [ -e "/etc/audit/auditd.conf" ] ; then
    
    LC_ALL=C sed -i "/^\s*name_format\s*=\s*/Id" "/etc/audit/auditd.conf"
else
    touch "/etc/audit/auditd.conf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/audit/auditd.conf"

cp "/etc/audit/auditd.conf" "/etc/audit/auditd.conf.bak"
# Insert at the end of the file
printf '%s\n' "name_format = $var_auditd_name_format" &gt;&gt; "/etc/audit/auditd.conf"
# Clean up after ourselves.
rm "/etc/audit/auditd.conf.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_name_format" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030062
  - NIST-800-53-AU-3
  - NIST-800-53-CM-6
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.2
  - auditd_name_format
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
- name: XCCDF Value var_auditd_name_format # promote to variable
  set_fact:
    var_auditd_name_format: !!str <xccdf-1.2:sub idref="xccdf_org.ssgproject.content_value_var_auditd_name_format" use="legacy"/>
  tags:
    - always

- name: Set type of computer node name logging in audit logs - Define Value to Be
    Used in the Remediation
  ansible.builtin.set_fact: auditd_name_format_split="{{ var_auditd_name_format.split('|')[0]
    }}"
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030062
  - NIST-800-53-AU-3
  - NIST-800-53-CM-6
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.2
  - auditd_name_format
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Set type of computer node name logging in audit logs
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*name_format\s*=\s*
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/audit/auditd.conf
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*name_format\s*=\s*
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/audit/auditd.conf
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*name_format\s*=\s*
      line: name_format = {{ auditd_name_format_split }}
      state: present
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030062
  - NIST-800-53-AU-3
  - NIST-800-53-CM-6
  - PCI-DSSv4-10.2
  - PCI-DSSv4-10.2.2
  - auditd_name_format
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_name_format" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20audit%20daemon%0A%23%0A%0Alocal_events%20%3D%20yes%0Awrite_logs%20%3D%20yes%0Alog_file%20%3D%20/var/log/audit/audit.log%0Alog_group%20%3D%20root%0Alog_format%20%3D%20ENRICHED%0Aflush%20%3D%20%7B%7B.var_auditd_flush%7D%7D%0Afreq%20%3D%2050%0Amax_log_file%20%3D%20%7B%7B.var_auditd_max_log_file%7D%7D%0Anum_logs%20%3D%20%7B%7B.var_auditd_num_logs%7D%7D%0Apriority_boost%20%3D%204%0Aname_format%20%3D%20hostname%0A%23%23name%20%3D%20mydomain%0Amax_log_file_action%20%3D%20%7B%7B.var_auditd_max_log_file_action%7D%7D%0Aspace_left%20%3D%20%7B%7B.var_auditd_space_left%7D%7D%0Aspace_left_action%20%3D%20%7B%7B.var_auditd_space_left_action%7D%7D%0Averify_email%20%3D%20yes%0Aaction_mail_acct%20%3D%20%7B%7B.var_auditd_action_mail_acct%7D%7D%0Aadmin_space_left%20%3D%2050%0Aadmin_space_left_action%20%3D%20syslog%0Adisk_full_action%20%3D%20%7B%7B.var_auditd_disk_full_action%7D%7D%0Adisk_error_action%20%3D%20%7B%7B.var_auditd_disk_error_action%7D%7D%0Ause_libwrap%20%3D%20yes%0A%23%23tcp_listen_port%20%3D%2060%0Atcp_listen_queue%20%3D%205%0Atcp_max_per_addr%20%3D%201%0A%23%23tcp_client_ports%20%3D%201024-65535%0Atcp_client_max_idle%20%3D%200%0Atransport%20%3D%20TCP%0Akrb5_principal%20%3D%20auditd%0A%23%23krb5_key_file%20%3D%20/etc/audit/audit.key%0Adistribute_network%20%3D%20no%0Aq_depth%20%3D%20400%0Aoverflow_action%20%3D%20syslog%0Amax_restarts%20%3D%2010%0Aplugin_dir%20%3D%20/etc/audit/plugins.d }}
        mode: 0640
        path: /etc/audit/auditd.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-export export-name="oval:ssg-var_auditd_name_format:var:1" value-id="xccdf_org.ssgproject.content_value_var_auditd_name_format"/>
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_name_format:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_name_format_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_overflow_action" selected="false" severity="medium">
            <xccdf-1.2:title>Appropriate Action Must be Setup When the Internal Audit Event Queue is Full</xccdf-1.2:title>
            <xccdf-1.2:description>The audit system should have an action setup in the event the internal event queue becomes full.
To setup an overflow action edit <html:code>/etc/audit/auditd.conf</html:code>. Set <html:code>overflow_action</html:code>
to one of the following values: <html:code>syslog</html:code>, <html:code>single</html:code>, <html:code>halt</html:code>.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-4(1)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000342-GPOS-00133</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000479-GPOS-00224</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030700</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230480r958754_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The audit system should have an action setup in the event the internal event queue becomes full
so that no data is lost.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_overflow_action" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

if [ -e "/etc/audit/auditd.conf" ] ; then
    
    LC_ALL=C sed -i "/^\s*overflow_action\s*=\s*/Id" "/etc/audit/auditd.conf"
else
    touch "/etc/audit/auditd.conf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/audit/auditd.conf"

cp "/etc/audit/auditd.conf" "/etc/audit/auditd.conf.bak"
# Insert at the end of the file
printf '%s\n' "overflow_action = syslog" &gt;&gt; "/etc/audit/auditd.conf"
# Clean up after ourselves.
rm "/etc/audit/auditd.conf.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_overflow_action" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030700
  - NIST-800-53-AU-4(1)
  - auditd_overflow_action
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Appropriate Action Must be Setup When the Internal Audit Event Queue is Full
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*overflow_action\s*=\s*
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/audit/auditd.conf
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*overflow_action\s*=\s*
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/audit/auditd.conf
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*overflow_action\s*=\s*
      line: overflow_action = syslog
      state: present
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030700
  - NIST-800-53-AU-4(1)
  - auditd_overflow_action
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_overflow_action:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_auditd_write_logs" selected="false" severity="medium">
            <xccdf-1.2:title>Write Audit Logs to the Disk</xccdf-1.2:title>
            <xccdf-1.2:description>To configure Audit daemon to write Audit logs to the disk, set
<html:code>write_logs</html:code> to <html:code>yes</html:code> in <html:code>/etc/audit/auditd.conf</html:code>.
This is the default setting.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">CM-6</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000480-GPOS-00227</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If <html:code>write_logs</html:code> isn't set to <html:code>yes</html:code>, the Audit logs will
not be written to the disk.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_write_logs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q audit &amp;&amp; rpm --quiet -q kernel; then

if [ -e "/etc/audit/auditd.conf" ] ; then
    
    LC_ALL=C sed -i "/^\s*write_logs\s*=\s*/Id" "/etc/audit/auditd.conf"
else
    touch "/etc/audit/auditd.conf"
fi
# make sure file has newline at the end
sed -i -e '$a\' "/etc/audit/auditd.conf"

cp "/etc/audit/auditd.conf" "/etc/audit/auditd.conf.bak"
# Insert at the end of the file
printf '%s\n' "write_logs = yes" &gt;&gt; "/etc/audit/auditd.conf"
# Clean up after ourselves.
rm "/etc/audit/auditd.conf.bak"

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_write_logs" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-CM-6
  - auditd_write_logs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Write Audit Logs to the Disk
  block:

  - name: Check for duplicate values
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*write_logs\s*=\s*
      state: absent
    check_mode: true
    changed_when: false
    register: dupes

  - name: Deduplicate values from /etc/audit/auditd.conf
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*write_logs\s*=\s*
      state: absent
    when: dupes.found is defined and dupes.found &gt; 1

  - name: Insert correct line to /etc/audit/auditd.conf
    ansible.builtin.lineinfile:
      path: /etc/audit/auditd.conf
      create: true
      regexp: (?i)(?i)^\s*write_logs\s*=\s*
      line: write_logs = yes
      state: present
  when:
  - '"audit" in ansible_facts.packages'
  - '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-CM-6
  - auditd_write_logs
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="auditd_write_logs" reboot="true" strategy="restrict" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%0A%23%20This%20file%20controls%20the%20configuration%20of%20the%20audit%20daemon%0A%23%0A%0Alocal_events%20%3D%20yes%0Awrite_logs%20%3D%20yes%0Alog_file%20%3D%20/var/log/audit/audit.log%0Alog_group%20%3D%20root%0Alog_format%20%3D%20ENRICHED%0Aflush%20%3D%20%7B%7B.var_auditd_flush%7D%7D%0Afreq%20%3D%2050%0Amax_log_file%20%3D%20%7B%7B.var_auditd_max_log_file%7D%7D%0Anum_logs%20%3D%20%7B%7B.var_auditd_num_logs%7D%7D%0Apriority_boost%20%3D%204%0Aname_format%20%3D%20hostname%0A%23%23name%20%3D%20mydomain%0Amax_log_file_action%20%3D%20%7B%7B.var_auditd_max_log_file_action%7D%7D%0Aspace_left%20%3D%20%7B%7B.var_auditd_space_left%7D%7D%0Aspace_left_action%20%3D%20%7B%7B.var_auditd_space_left_action%7D%7D%0Averify_email%20%3D%20yes%0Aaction_mail_acct%20%3D%20%7B%7B.var_auditd_action_mail_acct%7D%7D%0Aadmin_space_left%20%3D%2050%0Aadmin_space_left_action%20%3D%20syslog%0Adisk_full_action%20%3D%20%7B%7B.var_auditd_disk_full_action%7D%7D%0Adisk_error_action%20%3D%20%7B%7B.var_auditd_disk_error_action%7D%7D%0Ause_libwrap%20%3D%20yes%0A%23%23tcp_listen_port%20%3D%2060%0Atcp_listen_queue%20%3D%205%0Atcp_max_per_addr%20%3D%201%0A%23%23tcp_client_ports%20%3D%201024-65535%0Atcp_client_max_idle%20%3D%200%0Atransport%20%3D%20TCP%0Akrb5_principal%20%3D%20auditd%0A%23%23krb5_key_file%20%3D%20/etc/audit/audit.key%0Adistribute_network%20%3D%20no%0Aq_depth%20%3D%20400%0Aoverflow_action%20%3D%20syslog%0Amax_restarts%20%3D%2010%0Aplugin_dir%20%3D%20/etc/audit/plugins.d }}
        mode: 0640
        path: /etc/audit/auditd.conf
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-auditd_write_logs:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-auditd_write_logs_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_file_permissions_auditd">
          <xccdf-1.2:title>System Accounting with auditd</xccdf-1.2:title>
          <xccdf-1.2:description>The audit service provides substantial capabilities
for recording system activities. This section
deals with permissions of auditd related files.</xccdf-1.2:description>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_groupownership_audit_binaries" selected="false" severity="medium">
            <xccdf-1.2:title>Verify that audit tools are owned by group root</xccdf-1.2:title>
            <xccdf-1.2:description>The AlmaLinux OS 8 operating system audit tools must have the proper
ownership configured to protected against unauthorized access.

Verify it by running the following command:
<html:pre>$ stat -c "%n %G" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd /sbin/augenrules

/sbin/auditctl root

/sbin/aureport root

/sbin/ausearch root

/sbin/autrace root

/sbin/auditd root

/sbin/audispd root

/sbin/augenrules root

</html:pre>

Audit tools needed to successfully view and manipulate audit information
system activity and records. Audit tools include custom queries and report
generators</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000256-GPOS-00097</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000257-GPOS-00098</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.4.10</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Protecting audit information also includes identifying and protecting the
tools used to view and manipulate log data. Therefore, protecting audit
tools is necessary to prevent unauthorized operation on audit information.

Operating systems providing tools to interface with audit information
will leverage user permissions and roles identifying the user accessing the
tools and the corresponding rights the user enjoys to make access decisions
regarding the access to audit tools.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupownership_audit_binaries" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newgroup=""
if getent group "0" &gt;/dev/null 2&gt;&amp;1; then
  newgroup="0"
fi

if [[ -z "${newgroup}" ]]; then
  &gt;&amp;2 echo "0 is not a defined group on the system"
else
if ! stat -c "%g %G" "/sbin/auditctl" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /sbin/auditctl
fi
if ! stat -c "%g %G" "/sbin/aureport" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /sbin/aureport
fi
if ! stat -c "%g %G" "/sbin/ausearch" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /sbin/ausearch
fi
if ! stat -c "%g %G" "/sbin/autrace" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /sbin/autrace
fi
if ! stat -c "%g %G" "/sbin/auditd" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /sbin/auditd
fi
if ! stat -c "%g %G" "/sbin/audispd" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /sbin/audispd
fi
if ! stat -c "%g %G" "/sbin/augenrules" | grep -E -w -q "0"; then
    chgrp --no-dereference "$newgroup" /sbin/augenrules
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_groupownership_audit_binaries" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_groupownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_groupownership_audit_binaries_newgroup variable if represented
    by gid
  ansible.builtin.set_fact:
    file_groupownership_audit_binaries_newgroup: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/auditctl
  ansible.builtin.stat:
    path: /sbin/auditctl
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /sbin/auditctl
  ansible.builtin.file:
    path: /sbin/auditctl
    follow: false
    group: '{{ file_groupownership_audit_binaries_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/aureport
  ansible.builtin.stat:
    path: /sbin/aureport
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /sbin/aureport
  ansible.builtin.file:
    path: /sbin/aureport
    follow: false
    group: '{{ file_groupownership_audit_binaries_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/ausearch
  ansible.builtin.stat:
    path: /sbin/ausearch
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /sbin/ausearch
  ansible.builtin.file:
    path: /sbin/ausearch
    follow: false
    group: '{{ file_groupownership_audit_binaries_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/autrace
  ansible.builtin.stat:
    path: /sbin/autrace
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /sbin/autrace
  ansible.builtin.file:
    path: /sbin/autrace
    follow: false
    group: '{{ file_groupownership_audit_binaries_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/auditd
  ansible.builtin.stat:
    path: /sbin/auditd
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /sbin/auditd
  ansible.builtin.file:
    path: /sbin/auditd
    follow: false
    group: '{{ file_groupownership_audit_binaries_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/audispd
  ansible.builtin.stat:
    path: /sbin/audispd
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /sbin/audispd
  ansible.builtin.file:
    path: /sbin/audispd
    follow: false
    group: '{{ file_groupownership_audit_binaries_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/augenrules
  ansible.builtin.stat:
    path: /sbin/augenrules
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_groupownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure group owner on /sbin/augenrules
  ansible.builtin.file:
    path: /sbin/augenrules
    follow: false
    group: '{{ file_groupownership_audit_binaries_newgroup }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_groupownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_groupownership_audit_binaries:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_groupownership_audit_binaries_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_ownership_audit_binaries" selected="false" severity="medium">
            <xccdf-1.2:title>Verify that audit tools are owned by root</xccdf-1.2:title>
            <xccdf-1.2:description>The AlmaLinux OS 8 operating system audit tools must have the proper
ownership configured to protected against unauthorized access.

Verify it by running the following command:
<html:pre>$ stat -c "%n %U" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd /sbin/augenrules

/sbin/auditctl root

/sbin/aureport root

/sbin/ausearch root

/sbin/autrace root

/sbin/auditd root

/sbin/audispd root

/sbin/augenrules root

</html:pre>

Audit tools needed to successfully view and manipulate audit information
system activity and records. Audit tools include custom queries and report
generators</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000256-GPOS-00097</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000257-GPOS-00098</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.4.9</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Protecting audit information also includes identifying and protecting the
tools used to view and manipulate log data. Therefore, protecting audit
tools is necessary to prevent unauthorized operation on audit information.

Operating systems providing tools to interface with audit information
will leverage user permissions and roles identifying the user accessing the
tools and the corresponding rights the user enjoys to make access decisions
regarding the access to audit tools.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_ownership_audit_binaries" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

newown=""
if id "0" &gt;/dev/null 2&gt;&amp;1; then
  newown="0"
fi

if [[ -z "$newown" ]]; then
  &gt;&amp;2 echo "0 is not a defined user on the system"
else
if ! stat -c "%u %U" "/sbin/auditctl" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /sbin/auditctl
fi
if ! stat -c "%u %U" "/sbin/aureport" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /sbin/aureport
fi
if ! stat -c "%u %U" "/sbin/ausearch" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /sbin/ausearch
fi
if ! stat -c "%u %U" "/sbin/autrace" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /sbin/autrace
fi
if ! stat -c "%u %U" "/sbin/auditd" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /sbin/auditd
fi
if ! stat -c "%u %U" "/sbin/audispd" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /sbin/audispd
fi
if ! stat -c "%u %U" "/sbin/augenrules" | grep -E -w -q "0"; then
    chown --no-dereference "$newown" /sbin/augenrules
fi

fi

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_ownership_audit_binaries" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_ownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set the file_ownership_audit_binaries_newown variable if represented by uid
  ansible.builtin.set_fact:
    file_ownership_audit_binaries_newown: '0'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/auditctl
  ansible.builtin.stat:
    path: /sbin/auditctl
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /sbin/auditctl
  ansible.builtin.file:
    path: /sbin/auditctl
    follow: false
    owner: '{{ file_ownership_audit_binaries_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_ownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/aureport
  ansible.builtin.stat:
    path: /sbin/aureport
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /sbin/aureport
  ansible.builtin.file:
    path: /sbin/aureport
    follow: false
    owner: '{{ file_ownership_audit_binaries_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_ownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/ausearch
  ansible.builtin.stat:
    path: /sbin/ausearch
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /sbin/ausearch
  ansible.builtin.file:
    path: /sbin/ausearch
    follow: false
    owner: '{{ file_ownership_audit_binaries_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_ownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/autrace
  ansible.builtin.stat:
    path: /sbin/autrace
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /sbin/autrace
  ansible.builtin.file:
    path: /sbin/autrace
    follow: false
    owner: '{{ file_ownership_audit_binaries_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_ownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/auditd
  ansible.builtin.stat:
    path: /sbin/auditd
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /sbin/auditd
  ansible.builtin.file:
    path: /sbin/auditd
    follow: false
    owner: '{{ file_ownership_audit_binaries_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_ownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/audispd
  ansible.builtin.stat:
    path: /sbin/audispd
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /sbin/audispd
  ansible.builtin.file:
    path: /sbin/audispd
    follow: false
    owner: '{{ file_ownership_audit_binaries_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_ownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/augenrules
  ansible.builtin.stat:
    path: /sbin/augenrules
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_ownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure owner on /sbin/augenrules
  ansible.builtin.file:
    path: /sbin/augenrules
    follow: false
    owner: '{{ file_ownership_audit_binaries_newown }}'
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_ownership_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_ownership_audit_binaries:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_ownership_audit_binaries_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_audit_binaries" selected="false" severity="medium">
            <xccdf-1.2:title>Verify that audit tools Have Mode 0755 or less</xccdf-1.2:title>
            <xccdf-1.2:description>The AlmaLinux OS 8 operating system audit tools must have the proper
permissions configured to protected against unauthorized access.

Verify it by running the following command:
<html:pre>$ stat -c "%n %a" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd /sbin/augenrules

/sbin/auditctl 755

/sbin/aureport 755

/sbin/ausearch 755

/sbin/autrace 755

/sbin/auditd 755

/sbin/audispd 755

/sbin/augenrules 755

</html:pre>

Audit tools needed to successfully view and manipulate audit information
system activity and records. Audit tools include custom queries and report
generators</xccdf-1.2:description>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000256-GPOS-00097</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000257-GPOS-00098</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cisecurity.org/benchmark/almalinuxos_linux/">6.3.4.8</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Protecting audit information also includes identifying and protecting the
tools used to view and manipulate log data. Therefore, protecting audit
tools is necessary to prevent unauthorized operation on audit information.

Operating systems providing tools to interface with audit information
will leverage user permissions and roles identifying the user accessing the
tools and the corresponding rights the user enjoys to make access decisions
regarding the access to audit tools.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_audit_binaries" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

chmod u-s,g-ws,o-wt /sbin/auditctl

chmod u-s,g-ws,o-wt /sbin/aureport

chmod u-s,g-ws,o-wt /sbin/ausearch

chmod u-s,g-ws,o-wt /sbin/autrace

chmod u-s,g-ws,o-wt /sbin/auditd

chmod u-s,g-ws,o-wt /sbin/audispd

chmod u-s,g-ws,o-wt /sbin/augenrules

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_audit_binaries" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - configure_strategy
  - file_permissions_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/auditctl
  ansible.builtin.stat:
    path: /sbin/auditctl
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_permissions_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-s,g-ws,o-wt on /sbin/auditctl
  ansible.builtin.file:
    path: /sbin/auditctl
    mode: u-s,g-ws,o-wt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/aureport
  ansible.builtin.stat:
    path: /sbin/aureport
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_permissions_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-s,g-ws,o-wt on /sbin/aureport
  ansible.builtin.file:
    path: /sbin/aureport
    mode: u-s,g-ws,o-wt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/ausearch
  ansible.builtin.stat:
    path: /sbin/ausearch
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_permissions_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-s,g-ws,o-wt on /sbin/ausearch
  ansible.builtin.file:
    path: /sbin/ausearch
    mode: u-s,g-ws,o-wt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/autrace
  ansible.builtin.stat:
    path: /sbin/autrace
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_permissions_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-s,g-ws,o-wt on /sbin/autrace
  ansible.builtin.file:
    path: /sbin/autrace
    mode: u-s,g-ws,o-wt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/auditd
  ansible.builtin.stat:
    path: /sbin/auditd
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_permissions_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-s,g-ws,o-wt on /sbin/auditd
  ansible.builtin.file:
    path: /sbin/auditd
    mode: u-s,g-ws,o-wt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/audispd
  ansible.builtin.stat:
    path: /sbin/audispd
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_permissions_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-s,g-ws,o-wt on /sbin/audispd
  ansible.builtin.file:
    path: /sbin/audispd
    mode: u-s,g-ws,o-wt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /sbin/augenrules
  ansible.builtin.stat:
    path: /sbin/augenrules
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - configure_strategy
  - file_permissions_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-s,g-ws,o-wt on /sbin/augenrules
  ansible.builtin.file:
    path: /sbin/augenrules
    mode: u-s,g-ws,o-wt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - configure_strategy
  - file_permissions_audit_binaries
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_audit_binaries:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_audit_auditd" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Permissions on /etc/audit/auditd.conf</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/audit/auditd.conf</html:code>, run the command:
<html:pre>$ sudo chmod 0640 /etc/audit/auditd.conf</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000063-GPOS-00032</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030610</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230471r1069296_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Without the capability to restrict the roles and individuals that can select which events
are audited, unauthorized personnel may be able to prevent the auditing of critical
events. Misconfigured audits may degrade the system's performance by overwhelming
the audit log. Misconfigured audits may also make it more difficult to establish,
correlate, and investigate the events relating to an incident or identify
those responsible for one.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_audit_auditd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

chmod u-xs,g-xws,o-xwrt /etc/audit/auditd.conf

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_audit_auditd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030610
  - NIST-800-53-AU-12(b)
  - configure_strategy
  - file_permissions_etc_audit_auditd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Test for existence /etc/audit/auditd.conf
  ansible.builtin.stat:
    path: /etc/audit/auditd.conf
  register: file_exists
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030610
  - NIST-800-53-AU-12(b)
  - configure_strategy
  - file_permissions_etc_audit_auditd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Ensure permission u-xs,g-xws,o-xwrt on /etc/audit/auditd.conf
  ansible.builtin.file:
    path: /etc/audit/auditd.conf
    mode: u-xs,g-xws,o-xwrt
  when:
  - '"kernel" in ansible_facts.packages'
  - file_exists.stat is defined and file_exists.stat.exists
  tags:
  - DISA-STIG-RHEL-08-030610
  - NIST-800-53-AU-12(b)
  - configure_strategy
  - file_permissions_etc_audit_auditd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_audit_auditd:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_audit_auditd_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_file_permissions_etc_audit_rulesd" selected="false" severity="medium">
            <xccdf-1.2:title>Verify Permissions on /etc/audit/rules.d/*.rules</xccdf-1.2:title>
            <xccdf-1.2:description>To properly set the permissions of <html:code>/etc/audit/rules.d/*.rules</html:code>, run the command:
<html:pre>$ sudo chmod 0600 /etc/audit/rules.d/*.rules</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-12(b)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000063-GPOS-00032</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">RHEL-08-030610</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/srg-stig-tools/">SV-230471r1069296_rule</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Without the capability to restrict the roles and individuals that can select which events
are audited, unauthorized personnel may be able to prevent the auditing of critical
events. Misconfigured audits may degrade the system's performance by overwhelming
the audit log. Misconfigured audits may also make it more difficult to establish,
correlate, and investigate the events relating to an incident or identify
those responsible for one.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_audit_rulesd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

find -P /etc/audit/rules.d/ -maxdepth 1 -perm /u+xs,g+xwrs,o+xwrt  -type f -regextype posix-extended -regex '^.*rules$' -exec chmod u-xs,g-xwrs,o-xwrt {} \;

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="file_permissions_etc_audit_rulesd" reboot="false" strategy="configure" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - DISA-STIG-RHEL-08-030610
  - NIST-800-53-AU-12(b)
  - configure_strategy
  - file_permissions_etc_audit_rulesd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Find /etc/audit/rules.d/ file(s)
  ansible.builtin.command: find -P /etc/audit/rules.d/ -maxdepth 1 -perm /u+xs,g+xwrs,o+xwrt  -type
    f -regextype posix-extended -regex "^.*rules$"
  register: files_found
  changed_when: false
  failed_when: false
  check_mode: false
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030610
  - NIST-800-53-AU-12(b)
  - configure_strategy
  - file_permissions_etc_audit_rulesd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed

- name: Set permissions for /etc/audit/rules.d/ file(s)
  ansible.builtin.file:
    path: '{{ item }}'
    mode: u-xs,g-xwrs,o-xwrt
    state: file
  with_items:
  - '{{ files_found.stdout_lines }}'
  when: '"kernel" in ansible_facts.packages'
  tags:
  - DISA-STIG-RHEL-08-030610
  - NIST-800-53-AU-12(b)
  - configure_strategy
  - file_permissions_etc_audit_rulesd
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-file_permissions_etc_audit_rulesd:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
        </xccdf-1.2:Group>
        <xccdf-1.2:Group id="xccdf_org.ssgproject.content_group_policy_rules">
          <xccdf-1.2:title>System Accounting with auditd</xccdf-1.2:title>
          <xccdf-1.2:description>The <html:code>auditd</html:code> program can perform comprehensive
monitoring of system activity. This section makes use of recommended
configuration settings for specific policies or use cases.
The rules in this section make use of rules defined in <html:code>/usr/share/doc/audit-VERSION/rules</html:code>.</xccdf-1.2:description>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_access_failed" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditing of unsuccessful file accesses</xccdf-1.2:title>
            <xccdf-1.2:description>Ensure that unsuccessful attempts to access a file are audited.

The following rules configure audit as described above:
<html:pre>## Unsuccessful file access (any other opens) This has to go last.
-a always,exit -F arch=b32 -S open,openat,openat2,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
-a always,exit -F arch=b64 -S open,openat,openat2,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
-a always,exit -F arch=b32 -S open,openat,openat2,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
-a always,exit -F arch=b64 -S open,openat,openat2,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access    </html:pre>

Load new Audit rules into kernel by running:
<html:pre>augenrules --load</html:pre>

Note: This rule uses a special set of Audit rules to comply with OSPP 4.2.1. You may reuse this rule in different profiles. If you decide to do so, it is recommended that you inspect contents of the file closely and make sure that they are aligned with your needs.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.1.c</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000091-CTR-000160</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000492-CTR-001220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000493-CTR-001225</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000494-CTR-001230</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000500-CTR-001260</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000507-CTR-001295</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0846</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Unsuccessful attempts to access a file might be signs of malicious activity happening within the system. Auditing of such activities helps in their monitoring and investigation.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_access_failed" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &lt;&lt; 'EOF' &gt; /etc/audit/rules.d/30-ospp-v42-3-access-failed.rules
## Unsuccessful file access (any other opens) This has to go last.
-a always,exit -F arch=b32 -S open,openat,openat2,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
-a always,exit -F arch=b64 -S open,openat,openat2,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
-a always,exit -F arch=b32 -S open,openat,openat2,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
-a always,exit -F arch=b64 -S open,openat,openat2,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
EOF

chmod o-rwx /etc/audit/rules.d/30-ospp-v42-3-access-failed.rules

augenrules --load

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_access_failed" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-2(a)
  - audit_access_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Put contents into /etc/audit/rules.d/30-ospp-v42-3-access-failed.rules according
    to policy
  ansible.builtin.copy:
    dest: /etc/audit/rules.d/30-ospp-v42-3-access-failed.rules
    content: |
      ## Unsuccessful file access (any other opens) This has to go last.
      -a always,exit -F arch=b32 -S open,openat,openat2,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
      -a always,exit -F arch=b64 -S open,openat,openat2,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
      -a always,exit -F arch=b32 -S open,openat,openat2,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
      -a always,exit -F arch=b64 -S open,openat,openat2,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
    force: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_access_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure auditing of unsuccessful file accesses - Remove any permissions
    from group and other
  ansible.builtin.file:
    path: /etc/audit/rules.d/30-ospp-v42-3-access-failed.rules
    mode: g-rwx,o-rwx
    state: touch
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_access_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_access_failed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_access_failed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_access_success" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditing of successful file accesses</xccdf-1.2:title>
            <xccdf-1.2:description>Ensure that successful attempts to access a file are audited.

The following rules configure audit as described above:
<html:pre>## Successful file access (any other opens) This has to go last.
## These next two are likely to result in a whole lot of events
-a always,exit -F arch=b32 -S open,openat,openat2,open_by_handle_at -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access
-a always,exit -F arch=b64 -S open,openat,openat2,open_by_handle_at -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access    </html:pre>

Load new Audit rules into kernel by running:
<html:pre>augenrules --load</html:pre>

Note: This rule uses a special set of Audit rules to comply with OSPP 4.2.1. You may reuse this rule in different profiles. If you decide to do so, it is recommended that you inspect contents of the file closely and make sure that they are aligned with your needs.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.1.c</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0582</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.gov.au/acsc/view-all-content/ism">0846</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Auditing of successful attempts to access a file helps in investigation of activities performed on the system.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_access_success" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &lt;&lt; 'EOF' &gt; /etc/audit/rules.d/30-ospp-v42-3-access-success.rules
## Successful file access (any other opens) This has to go last.
## These next two are likely to result in a whole lot of events
-a always,exit -F arch=b32 -S open,openat,openat2,open_by_handle_at -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access
-a always,exit -F arch=b64 -S open,openat,openat2,open_by_handle_at -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access
EOF

chmod o-rwx /etc/audit/rules.d/30-ospp-v42-3-access-success.rules

augenrules --load

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_access_success" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-2(a)
  - audit_access_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Put contents into /etc/audit/rules.d/30-ospp-v42-3-access-success.rules according
    to policy
  ansible.builtin.copy:
    dest: /etc/audit/rules.d/30-ospp-v42-3-access-success.rules
    content: |
      ## Successful file access (any other opens) This has to go last.
      ## These next two are likely to result in a whole lot of events
      -a always,exit -F arch=b32 -S open,openat,openat2,open_by_handle_at -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access
      -a always,exit -F arch=b64 -S open,openat,openat2,open_by_handle_at -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access
    force: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_access_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure auditing of successful file accesses - Remove any permissions from
    group and other
  ansible.builtin.file:
    path: /etc/audit/rules.d/30-ospp-v42-3-access-success.rules
    mode: g-rwx,o-rwx
    state: touch
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_access_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="audit_access_success" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,%23%23%20Successful%20file%20access%20%28any%20other%20opens%29%20This%20has%20to%20go%20last.%0A%23%23%20These%20next%20two%20are%20likely%20to%20result%20in%20a%20whole%20lot%20of%20events%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20open%2Copenat%2Copen_by_handle_at%20-F%20success%3D1%20-F%20auid%26gt%3B%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dsuccessful-access%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20open%2Copenat%2Copen_by_handle_at%20-F%20success%3D1%20-F%20auid%26gt%3B%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dsuccessful-access
        mode: 0600
        path: /etc/audit/rules.d/30-ospp-v42-3-access-success.rules
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_access_success:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_access_success_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_basic_configuration" selected="false" severity="medium">
            <xccdf-1.2:title>Configure basic parameters of Audit system</xccdf-1.2:title>
            <xccdf-1.2:description>Perform basic configuration of Audit system.
Make sure that any previously defined rules are cleared, the auditing system is configured to handle sudden bursts of events, and in cases of failure, messages are configured to be directed to system log.

The following rules configure audit as described above:
<html:pre>## First rule - delete all
-D

## Increase the buffers to survive stress events.
## Make this bigger for busy systems
-b 8192

## This determine how long to wait in burst of events
--backlog_wait_time 60000

## Set failure mode to syslog
-f 1    </html:pre>

Load new Audit rules into kernel by running:
<html:pre>augenrules --load</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="performance">It might happen that Audit buffer configured by this rule is not large enough for certain use cases. If that is the case, the buffer size can be overridden by placing <html:pre>-b larger_buffer_size</html:pre> into a file within <html:code>/etc/audit/rules.d</html:code> directory, replacing <html:code>larger_file_size</html:code> with the desired value. The file name should start with a number higher than 10 and lower than 99.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000365-GPOS-00152</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Without basic configurations, audit may not perform as expected. It may not be able to correctly handle events under stressful conditions, or log events in case of failure.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_basic_configuration" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &lt;&lt; 'EOF' &gt; /etc/audit/rules.d/10-base-config.rules
## First rule - delete all
-D

## Increase the buffers to survive stress events.
## Make this bigger for busy systems
-b 8192

## This determine how long to wait in burst of events
--backlog_wait_time 60000

## Set failure mode to syslog
-f 1

EOF

chmod o-rwx /etc/audit/rules.d/10-base-config.rules

augenrules --load

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_basic_configuration" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-2(a)
  - audit_basic_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Put contents into /etc/audit/rules.d/10-base-config.rules according to policy
  ansible.builtin.copy:
    dest: /etc/audit/rules.d/10-base-config.rules
    content: |+
      ## First rule - delete all
      -D

      ## Increase the buffers to survive stress events.
      ## Make this bigger for busy systems
      -b 8192

      ## This determine how long to wait in burst of events
      --backlog_wait_time 60000

      ## Set failure mode to syslog
      -f 1

    force: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_basic_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure basic parameters of Audit system - Remove any permissions from group
    and other
  ansible.builtin.file:
    path: /etc/audit/rules.d/10-base-config.rules
    mode: g-rwx,o-rwx
    state: touch
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_basic_configuration
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="audit_basic_configuration" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,%23%23%20First%20rule%20-%20delete%20all%0A-D%0A%0A%23%23%20Increase%20the%20buffers%20to%20survive%20stress%20events.%0A%23%23%20Make%20this%20bigger%20for%20busy%20systems%0A-b%208192%0A%0A%23%23%20This%20determine%20how%20long%20to%20wait%20in%20burst%20of%20events%0A--backlog_wait_time%2060000%0A%0A%23%23%20Set%20failure%20mode%20to%20syslog%0A-f%201%0A
        mode: 0600
        path: /etc/audit/rules.d/10-base-config.rules
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_basic_configuration:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_basic_configuration_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_create_failed" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditing of unsuccessful file creations</xccdf-1.2:title>
            <xccdf-1.2:description>Ensure that unsuccessful attempts to create a file are audited.

The following rules configure audit as described above:
<html:pre>## Unsuccessful file creation (open with O_CREAT)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create    </html:pre>

Load new Audit rules into kernel by running:
<html:pre>augenrules --load</html:pre>

Note: This rule uses a special set of Audit rules to comply with OSPP 4.2.1. You may reuse this rule in different profiles. If you decide to do so, it is recommended that you inspect contents of the file closely and make sure that they are aligned with your needs.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.1.c</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000091-CTR-000160</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000492-CTR-001220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000493-CTR-001225</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000494-CTR-001230</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000500-CTR-001260</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000507-CTR-001295</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Unsuccessful file creations might be a sign of a malicious action being performed on the system. Keeping log of such events helps in monitoring and investigation of such actions.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_create_failed" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &lt;&lt; 'EOF' &gt; /etc/audit/rules.d/30-ospp-v42-1-create-failed.rules
## Unsuccessful file creation (open with O_CREAT)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
EOF

chmod o-rwx /etc/audit/rules.d/30-ospp-v42-1-create-failed.rules

augenrules --load

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_create_failed" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-2(a)
  - audit_create_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Put contents into /etc/audit/rules.d/30-ospp-v42-1-create-failed.rules according
    to policy
  ansible.builtin.copy:
    dest: /etc/audit/rules.d/30-ospp-v42-1-create-failed.rules
    content: |
      ## Unsuccessful file creation (open with O_CREAT)
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
      -a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
      -a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
      -a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
      -a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
      -a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
      -a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
      -a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
      -a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
    force: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_create_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure auditing of unsuccessful file creations - Remove any permissions
    from group and other
  ansible.builtin.file:
    path: /etc/audit/rules.d/30-ospp-v42-1-create-failed.rules
    mode: g-rwx,o-rwx
    state: touch
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_create_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_create_failed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_create_failed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_create_success" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditing of successful file creations</xccdf-1.2:title>
            <xccdf-1.2:description>Ensure that successful attempts to create a file are audited.

The following rules configure audit as described above:
<html:pre>## Successful file creation (open with O_CREAT)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b32 -S creat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b64 -S creat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create    </html:pre>

Load new Audit rules into kernel by running:
<html:pre>augenrules --load</html:pre>

Note: This rule uses a special set of Audit rules to comply with OSPP 4.2.1. You may reuse this rule in different profiles. If you decide to do so, it is recommended that you inspect contents of the file closely and make sure that they are aligned with your needs.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.1.c</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Auditing of successful attempts to create a file helps in investigation of actions which happened on the system.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_create_success" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &lt;&lt; 'EOF' &gt; /etc/audit/rules.d/30-ospp-v42-1-create-success.rules
## Successful file creation (open with O_CREAT)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b32 -S creat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b64 -S creat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
EOF

chmod o-rwx /etc/audit/rules.d/30-ospp-v42-1-create-success.rules

augenrules --load

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_create_success" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-2(a)
  - audit_create_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Put contents into /etc/audit/rules.d/30-ospp-v42-1-create-success.rules according
    to policy
  ansible.builtin.copy:
    dest: /etc/audit/rules.d/30-ospp-v42-1-create-success.rules
    content: |
      ## Successful file creation (open with O_CREAT)
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
      -a always,exit -F arch=b32 -S open -F a1&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
      -a always,exit -F arch=b64 -S open -F a1&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
      -a always,exit -F arch=b32 -S creat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
      -a always,exit -F arch=b64 -S creat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
    force: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_create_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure auditing of successful file creations - Remove any permissions from
    group and other
  ansible.builtin.file:
    path: /etc/audit/rules.d/30-ospp-v42-1-create-success.rules
    mode: g-rwx,o-rwx
    state: touch
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_create_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_create_success:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_create_success_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_delete_failed" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditing of unsuccessful file deletions</xccdf-1.2:title>
            <xccdf-1.2:description>Ensure that unsuccessful attempts to delete a file are audited.

The following rules configure audit as described above:
<html:pre>## Unsuccessful file delete
-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete    </html:pre>

Load new Audit rules into kernel by running:
<html:pre>augenrules --load</html:pre>

Note: This rule uses a special set of Audit rules to comply with OSPP 4.2.1. You may reuse this rule in different profiles. If you decide to do so, it is recommended that you inspect contents of the file closely and make sure that they are aligned with your needs.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.1.c</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000501-CTR-001265</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000502-CTR-001270</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Unsuccessful attempts to delete a file might be signs of malicious activities. Auditing of such events help in monitoring and investigating of such activities.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_delete_failed" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &lt;&lt; 'EOF' &gt; /etc/audit/rules.d/30-ospp-v42-4-delete-failed.rules
## Unsuccessful file delete
-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
EOF

chmod o-rwx /etc/audit/rules.d/30-ospp-v42-4-delete-failed.rules

augenrules --load

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_delete_failed" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-2(a)
  - audit_delete_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Put contents into /etc/audit/rules.d/30-ospp-v42-4-delete-failed.rules according
    to policy
  ansible.builtin.copy:
    dest: /etc/audit/rules.d/30-ospp-v42-4-delete-failed.rules
    content: |
      ## Unsuccessful file delete
      -a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
      -a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
      -a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
      -a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
    force: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_delete_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure auditing of unsuccessful file deletions - Remove any permissions
    from group and other
  ansible.builtin.file:
    path: /etc/audit/rules.d/30-ospp-v42-4-delete-failed.rules
    mode: g-rwx,o-rwx
    state: touch
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_delete_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="audit_delete_failed" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,%23%23%20Unsuccessful%20file%20delete%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20unlink%2Cunlinkat%2Crename%2Crenameat%20-F%20exit%3D-EACCES%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-delete%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20unlink%2Cunlinkat%2Crename%2Crenameat%20-F%20exit%3D-EACCES%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-delete%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20unlink%2Cunlinkat%2Crename%2Crenameat%20-F%20exit%3D-EPERM%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-delete%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20unlink%2Cunlinkat%2Crename%2Crenameat%20-F%20exit%3D-EPERM%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-delete%0A
        mode: 0600
        path: /etc/audit/rules.d/30-ospp-v42-4-delete-failed.rules
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_delete_failed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_delete_failed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_delete_success" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditing of successful file deletions</xccdf-1.2:title>
            <xccdf-1.2:description>Ensure that successful attempts to delete a file are audited.

The following rules configure audit as described above:
<html:pre>## Successful file delete
-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete
-a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete    </html:pre>

Load new Audit rules into kernel by running:
<html:pre>augenrules --load</html:pre>

Note: This rule uses a special set of Audit rules to comply with OSPP 4.2.1. You may reuse this rule in different profiles. If you decide to do so, it is recommended that you inspect contents of the file closely and make sure that they are aligned with your needs.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.1.c</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Auditing of successful attempts to delete a file may help in monitoring and investigation of activities performed on the system.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_delete_success" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &lt;&lt; 'EOF' &gt; /etc/audit/rules.d/30-ospp-v42-4-delete-success.rules
## Successful file delete
-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete
-a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete
EOF

chmod o-rwx /etc/audit/rules.d/30-ospp-v42-4-delete-success.rules

augenrules --load

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_delete_success" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-2(a)
  - audit_delete_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Put contents into /etc/audit/rules.d/30-ospp-v42-4-delete-success.rules according
    to policy
  ansible.builtin.copy:
    dest: /etc/audit/rules.d/30-ospp-v42-4-delete-success.rules
    content: |
      ## Successful file delete
      -a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete
      -a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete
    force: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_delete_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure auditing of successful file deletions - Remove any permissions from
    group and other
  ansible.builtin.file:
    path: /etc/audit/rules.d/30-ospp-v42-4-delete-success.rules
    mode: g-rwx,o-rwx
    state: touch
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_delete_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="audit_delete_success" system="urn:xccdf:fix:script:kubernetes">---

apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,{{ %23%23%20Successful%20file%20delete%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20unlink%2Cunlinkat%2Crename%2Crenameat%20-F%20success%3D1%20-F%20auid%26gt%3B%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dsuccessful-delete%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20unlink%2Cunlinkat%2Crename%2Crenameat%20-F%20success%3D1%20-F%20auid%26gt%3B%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dsuccessful-delete }}
        mode: 0600
        path: /etc/audit/rules.d/30-ospp-v42-4-delete-success.rules
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_delete_success:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_delete_success_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_immutable_login_uids" selected="false" severity="medium">
            <xccdf-1.2:title>Configure immutable Audit login UIDs</xccdf-1.2:title>
            <xccdf-1.2:description>Configure kernel to prevent modification of login UIDs once they are set.
Changing login UIDs while this configuration is enforced requires special capabilities which
are not available to unprivileged users.

The following rules configure audit as described above:
<html:pre>## Make the loginuid immutable. This prevents tampering with the auid.
--loginuid-immutable    </html:pre>

Load new Audit rules into kernel by running:
<html:pre>augenrules --load</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.2</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000057-GPOS-00027</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000058-GPOS-00028</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000059-GPOS-00029</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000121-CTR-000255</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000495-CTR-001235</xccdf-1.2:reference>
            <xccdf-1.2:rationale>If modification of login UIDs is not prevented, they can be changed by unprivileged users and
make auditing complicated or impossible.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_immutable_login_uids" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &lt;&lt; 'EOF' &gt; /etc/audit/rules.d/11-loginuid.rules
## Make the loginuid immutable. This prevents tampering with the auid.
--loginuid-immutable

EOF

chmod o-rwx /etc/audit/rules.d/11-loginuid.rules

augenrules --load

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_immutable_login_uids" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-2(a)
  - audit_immutable_login_uids
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Put contents into /etc/audit/rules.d/11-loginuid.rules according to policy
  ansible.builtin.copy:
    dest: /etc/audit/rules.d/11-loginuid.rules
    content: |+
      ## Make the loginuid immutable. This prevents tampering with the auid.
      --loginuid-immutable

    force: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_immutable_login_uids
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure immutable Audit login UIDs - Remove any permissions from group and
    other
  ansible.builtin.file:
    path: /etc/audit/rules.d/11-loginuid.rules
    mode: g-rwx,o-rwx
    state: touch
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_immutable_login_uids
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="audit_immutable_login_uids" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,%23%23%20Make%20the%20loginuid%20immutable.%20This%20prevents%20tampering%20with%20the%20auid.%0A--loginuid-immutable%0A%0A
        mode: 0600
        path: /etc/audit/rules.d/11-loginuid.rules
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_immutable_login_uids:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_immutable_login_uids_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_modify_failed" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditing of unsuccessful file modifications</xccdf-1.2:title>
            <xccdf-1.2:description>Ensure that unsuccessful attempts to modify a file are audited.

The following rules configure audit as described above:
<html:pre>## Unsuccessful file modifications (open for write or truncate)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification    </html:pre>

Load new Audit rules into kernel by running:
<html:pre>augenrules --load</html:pre>

Note: This rule uses a special set of Audit rules to comply with OSPP 4.2.1. You may reuse this rule in different profiles. If you decide to do so, it is recommended that you inspect contents of the file closely and make sure that they are aligned with your needs.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.1.c</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000091-CTR-000160</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000492-CTR-001220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000493-CTR-001225</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000494-CTR-001230</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000500-CTR-001260</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security">SRG-APP-000507-CTR-001295</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Unsuccessful file modifications might be a sign of a malicious action being performed on the system. Auditing of such events helps in detection and investigation of such actions.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_modify_failed" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &lt;&lt; 'EOF' &gt; /etc/audit/rules.d/30-ospp-v42-2-modify-failed.rules
## Unsuccessful file modifications (open for write or truncate)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
EOF

chmod o-rwx /etc/audit/rules.d/30-ospp-v42-2-modify-failed.rules

augenrules --load

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_modify_failed" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-2(a)
  - audit_modify_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Put contents into /etc/audit/rules.d/30-ospp-v42-2-modify-failed.rules according
    to policy
  ansible.builtin.copy:
    dest: /etc/audit/rules.d/30-ospp-v42-2-modify-failed.rules
    content: |
      ## Unsuccessful file modifications (open for write or truncate)
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
      -a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
      -a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
      -a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
      -a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
      -a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
      -a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
      -a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
      -a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
    force: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_modify_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure auditing of unsuccessful file modifications - Remove any permissions
    from group and other
  ansible.builtin.file:
    path: /etc/audit/rules.d/30-ospp-v42-2-modify-failed.rules
    mode: g-rwx,o-rwx
    state: touch
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_modify_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="audit_modify_failed" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,%23%23%20Unsuccessful%20file%20modifications%20%28open%20for%20write%20or%20truncate%29%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20openat%2Copen_by_handle_at%20-F%20a2%2601003%20-F%20exit%3D-EACCES%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-modification%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20openat%2Copen_by_handle_at%20-F%20a2%2601003%20-F%20exit%3D-EACCES%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-modification%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20open%20-F%20a1%2601003%20-F%20exit%3D-EACCES%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-modification%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20open%20-F%20a1%2601003%20-F%20exit%3D-EACCES%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-modification%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20truncate%2Cftruncate%20-F%20exit%3D-EACCES%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-modification%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20truncate%2Cftruncate%20-F%20exit%3D-EACCES%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-modification%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20openat%2Copen_by_handle_at%20-F%20a2%2601003%20-F%20exit%3D-EPERM%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-modification%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20openat%2Copen_by_handle_at%20-F%20a2%2601003%20-F%20exit%3D-EPERM%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-modification%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20open%20-F%20a1%2601003%20-F%20exit%3D-EPERM%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-modification%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20open%20-F%20a1%2601003%20-F%20exit%3D-EPERM%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-modification%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20truncate%2Cftruncate%20-F%20exit%3D-EPERM%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-modification%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20truncate%2Cftruncate%20-F%20exit%3D-EPERM%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-modification%0A
        mode: 0600
        path: /etc/audit/rules.d/30-ospp-v42-2-modify-failed.rules 
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_modify_failed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_modify_failed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_modify_success" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditing of successful file modifications</xccdf-1.2:title>
            <xccdf-1.2:description>Ensure that successful attempts to modify a file are audited.

The following rules configure audit as described above:
<html:pre>## Successful file modifications (open for write or truncate)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification    </html:pre>

Load new Audit rules into kernel by running:
<html:pre>augenrules --load</html:pre>

Note: This rule uses a special set of Audit rules to comply with OSPP 4.2.1. You may reuse this rule in different profiles. If you decide to do so, it is recommended that you inspect contents of the file closely and make sure that they are aligned with your needs.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.1.c</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Auditing of successful attempts to modify a file helps in investigation of actions which happened on the system.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_modify_success" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &lt;&lt; 'EOF' &gt; /etc/audit/rules.d/30-ospp-v42-2-modify-success.rules
## Successful file modifications (open for write or truncate)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
EOF

chmod o-rwx /etc/audit/rules.d/30-ospp-v42-2-modify-success.rules

augenrules --load

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_modify_success" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-2(a)
  - audit_modify_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Put contents into /etc/audit/rules.d/30-ospp-v42-2-modify-success.rules according
    to policy
  ansible.builtin.copy:
    dest: /etc/audit/rules.d/30-ospp-v42-2-modify-success.rules
    content: |
      ## Successful file modifications (open for write or truncate)
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
      -a always,exit -F arch=b32 -S open -F a1&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
      -a always,exit -F arch=b64 -S open -F a1&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
      -a always,exit -F arch=b32 -S truncate,ftruncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
      -a always,exit -F arch=b64 -S truncate,ftruncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
    force: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_modify_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure auditing of successful file modifications - Remove any permissions
    from group and other
  ansible.builtin.file:
    path: /etc/audit/rules.d/30-ospp-v42-2-modify-success.rules
    mode: g-rwx,o-rwx
    state: touch
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_modify_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="audit_modify_success" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,%23%23%20Successful%20file%20modifications%20%28open%20for%20write%20or%20truncate%29%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20openat%2Copen_by_handle_at%20-F%20a2%26amp%3B01003%20-F%20success%3D1%20-F%20auid%26gt%3B%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dsuccessful-modification%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20openat%2Copen_by_handle_at%20-F%20a2%26amp%3B01003%20-F%20success%3D1%20-F%20auid%26gt%3B%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dsuccessful-modification%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20open%20-F%20a1%26amp%3B01003%20-F%20success%3D1%20-F%20auid%26gt%3B%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dsuccessful-modification%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20open%20-F%20a1%26amp%3B01003%20-F%20success%3D1%20-F%20auid%26gt%3B%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dsuccessful-modification%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20truncate%2Cftruncate%20-F%20success%3D1%20-F%20auid%26gt%3B%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dsuccessful-modification%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20truncate%2Cftruncate%20-F%20success%3D1%20-F%20auid%26gt%3B%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dsuccessful-modification%0A
        mode: 0600
        path: /etc/audit/rules.d/30-ospp-v42-2-modify-success.rules
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_modify_success:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_modify_success_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_module_load" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditing of loading and unloading of kernel modules</xccdf-1.2:title>
            <xccdf-1.2:description>Ensure that loading and unloading of kernel modules is audited.

The following rules configure audit as described above:
<html:pre>## These rules watch for kernel module insertion. By monitoring
## the syscall, we do not need any watches on programs.
-a always,exit -F arch=b32 -S init_module,finit_module -F key=module-load
-a always,exit -F arch=b64 -S init_module,finit_module -F key=module-load
-a always,exit -F arch=b32 -S delete_module -F key=module-unload
-a always,exit -F arch=b64 -S delete_module -F key=module-unload    </html:pre>

Load new Audit rules into kernel by running:
<html:pre>augenrules --load</html:pre></xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.1.c</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00216</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000477-GPOS-00222</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Loading of a malicious kernel module introduces a risk to the system, as the module has access to sensitive data and perform actions at the operating system kernel level. Having such events audited helps in monitoring and investigating of malicious activities.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_module_load" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &lt;&lt; 'EOF' &gt; /etc/audit/rules.d/43-module-load.rules
## These rules watch for kernel module insertion. By monitoring
## the syscall, we do not need any watches on programs.
-a always,exit -F arch=b32 -S init_module,finit_module -F key=module-load
-a always,exit -F arch=b64 -S init_module,finit_module -F key=module-load
-a always,exit -F arch=b32 -S delete_module -F key=module-unload
-a always,exit -F arch=b64 -S delete_module -F key=module-unload
EOF

chmod o-rwx /etc/audit/rules.d/43-module-load.rules

augenrules --load

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_module_load" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-2(a)
  - audit_module_load
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Put contents into /etc/audit/rules.d/43-module-load.rules according to policy
  ansible.builtin.copy:
    dest: /etc/audit/rules.d/43-module-load.rules
    content: |
      ## These rules watch for kernel module insertion. By monitoring
      ## the syscall, we do not need any watches on programs.
      -a always,exit -F arch=b32 -S init_module,finit_module -F key=module-load
      -a always,exit -F arch=b64 -S init_module,finit_module -F key=module-load
      -a always,exit -F arch=b32 -S delete_module -F key=module-unload
      -a always,exit -F arch=b64 -S delete_module -F key=module-unload
    force: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_module_load
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure auditing of loading and unloading of kernel modules - Remove any
    permissions from group and other
  ansible.builtin.file:
    path: /etc/audit/rules.d/43-module-load.rules
    mode: g-rwx,o-rwx
    state: touch
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_module_load
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="audit_module_load" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,%23%23%20These%20rules%20watch%20for%20kernel%20module%20insertion.%20By%20monitoring%0A%23%23%20the%20syscall%2C%20we%20do%20not%20need%20any%20watches%20on%20programs.%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20init_module%2Cfinit_module%20-F%20key%3Dmodule-load%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20init_module%2Cfinit_module%20-F%20key%3Dmodule-load%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20delete_module%20-F%20key%3Dmodule-unload%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20delete_module%20-F%20key%3Dmodule-unload%0A
        mode: 0600
        path: /etc/audit/rules.d/43-module-load.rules
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_module_load:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_module_load_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_ospp_general" selected="false" severity="medium">
            <xccdf-1.2:title>Perform general configuration of Audit for OSPP</xccdf-1.2:title>
            <xccdf-1.2:description>Configure some basic <html:code>Audit</html:code> parameters specific for OSPP profile.
In particular, configure <html:code>Audit</html:code> to watch for direct modification of files storing system user and group information, and usage of applications with special rights which can change system configuration.
Further audited events include access to audit log it self, attempts to Alter Process and Session Initiation Information, and attempts to modify MAC controls.

The following rules configure audit as described above:
<html:pre>## The purpose of these rules is to meet the requirements for Operating
## System Protection Profile (OSPP)v4.2. These rules depends on having
## the following rule files copied to /etc/audit/rules.d:
##
## 10-base-config.rules, 11-loginuid.rules,
## 30-ospp-v42-1-create-failed.rules, 30-ospp-v42-1-create-success.rules,
## 30-ospp-v42-2-modify-failed.rules, 30-ospp-v42-2-modify-success.rules,
## 30-ospp-v42-3-access-failed.rules, 30-ospp-v42-3-access-success.rules,
## 30-ospp-v42-4-delete-failed.rules, 30-ospp-v42-4-delete-success.rules,
## 30-ospp-v42-5-perm-change-failed.rules,
## 30-ospp-v42-5-perm-change-success.rules,
## 30-ospp-v42-6-owner-change-failed.rules,
## 30-ospp-v42-6-owner-change-success.rules
##
## original copies may be found in /usr/share/audit/sample-rules/


## User add delete modify. This is covered by pam. However, someone could
## open a file and directly create or modify a user, so we'll watch passwd and
## shadow for writes
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -S open -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -S open -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify

## User enable and disable. This is entirely handled by pam.

## Group add delete modify. This is covered by pam. However, someone could
## open a file and directly create or modify a user, so we'll watch group and
## gshadow for writes
-a always,exit -F arch=b32 -F path=/etc/passwd -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -F path=/etc/passwd -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -F path=/etc/shadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -F path=/etc/shadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -F path=/etc/group -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify
-a always,exit -F arch=b64 -F path=/etc/group -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify
-a always,exit -F arch=b32 -F path=/etc/gshadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify
-a always,exit -F arch=b64 -F path=/etc/gshadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify


## Use of special rights for config changes. This would be use of setuid
## programs that relate to user accts. This is not all setuid apps because
## requirements are only for ones that affect system configuration.
-a always,exit -F arch=b32 -F path=/usr/sbin/unix_chkpwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/unix_chkpwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/sbin/usernetctl -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/usernetctl -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/sbin/userhelper -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/userhelper -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/sbin/seunshare -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/seunshare -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/mount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/mount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/newgrp -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/newgrp -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/newuidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/newuidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/gpasswd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/gpasswd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/newgidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/newgidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/umount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/umount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/passwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/passwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/crontab -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/crontab -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/at -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/at -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/sbin/grub2-set-bootflag -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/grub2-set-bootflag -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes

## Privilege escalation via su or sudo. This is entirely handled by pam.
## Special case for systemd-run. It is not audit aware, specifically watch it
-a always,exit -F arch=b32 -F path=/usr/bin/systemd-run -F perm=x -F auid!=unset -F key=maybe-escalation
-a always,exit -F arch=b64 -F path=/usr/bin/systemd-run -F perm=x -F auid!=unset -F key=maybe-escalation
## Special case for pkexec. It is not audit aware, specifically watch it
-a always,exit -F arch=b32 -F path=/usr/bin/pkexec -F perm=x -F key=maybe-escalation
-a always,exit -F arch=b64 -F path=/usr/bin/pkexec -F perm=x -F key=maybe-escalation


## Watch for configuration changes to privilege escalation.
-a always,exit -F arch=b32 -F path=/etc/sudoers -F perm=wa -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/etc/sudoers -F perm=wa -F key=special-config-changes
-a always,exit -F arch=b32 -F dir=/etc/sudoers.d/ -F perm=wa -F key=special-config-changes
-a always,exit -F arch=b64 -F dir=/etc/sudoers.d/ -F perm=wa -F key=special-config-changes

## Audit log access
-a always,exit -F arch=b32 -F dir=/var/log/audit/ -F perm=r -F auid&gt;=1000 -F auid!=unset -F key=access-audit-trail
-a always,exit -F arch=b64 -F dir=/var/log/audit/ -F perm=r -F auid&gt;=1000 -F auid!=unset -F key=access-audit-trail
## Attempts to Alter Process and Session Initiation Information
-a always,exit -F arch=b32 -F path=/var/run/utmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b64 -F path=/var/run/utmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b32 -F path=/var/log/btmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b64 -F path=/var/log/btmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b32 -F path=/var/log/wtmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b64 -F path=/var/log/wtmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session

## Attempts to modify MAC controls
-a always,exit -F arch=b32 -F dir=/etc/selinux/ -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=MAC-policy
-a always,exit -F arch=b64 -F dir=/etc/selinux/ -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=MAC-policy

## Software updates. This is entirely handled by rpm.

## System start and shutdown. This is entirely handled by systemd

## Kernel Module loading. This is handled in 43-module-load.rules

## Application invocation. The requirements list an optional requirement
## FPT_SRP_EXT.1 Software Restriction Policies. This event is intended to
## state results from that policy. This would be handled entirely by
## that daemon.    </html:pre>

Load new Audit rules into kernel by running:
<html:pre>augenrules --load</html:pre>

Note: This rule uses a special set of Audit rules to comply with OSPP 4.2.1. You may reuse this rule in different profiles. If you decide to do so, it is recommended that you inspect contents of the file closely and make sure that they are aligned with your needs.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.1.c</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000004-GPOS-00004</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000241-GPOS-00091</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000476-GPOS-00221</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000327-GPOS-00127</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000239-GPOS-00089</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000274-GPOS-00104</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000275-GPOS-00105</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000303-GPOS-00120</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000304-GPOS-00121</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Auditing of events listed in the description provides data for monitoring and investigation of potentially malicious events e.g. tampering with <html:code>Audit</html:code> logs, malicious access to files storing information about system users and groups etc.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_ospp_general" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &lt;&lt; 'EOF' &gt; /etc/audit/rules.d/30-ospp-v42.rules
## The purpose of these rules is to meet the requirements for Operating
## System Protection Profile (OSPP)v4.2. These rules depends on having
## the following rule files copied to /etc/audit/rules.d:
##
## 10-base-config.rules, 11-loginuid.rules,
## 30-ospp-v42-1-create-failed.rules, 30-ospp-v42-1-create-success.rules,
## 30-ospp-v42-2-modify-failed.rules, 30-ospp-v42-2-modify-success.rules,
## 30-ospp-v42-3-access-failed.rules, 30-ospp-v42-3-access-success.rules,
## 30-ospp-v42-4-delete-failed.rules, 30-ospp-v42-4-delete-success.rules,
## 30-ospp-v42-5-perm-change-failed.rules,
## 30-ospp-v42-5-perm-change-success.rules,
## 30-ospp-v42-6-owner-change-failed.rules,
## 30-ospp-v42-6-owner-change-success.rules
##
## original copies may be found in /usr/share/audit/sample-rules/


## User add delete modify. This is covered by pam. However, someone could
## open a file and directly create or modify a user, so we'll watch passwd and
## shadow for writes
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -S open -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -S open -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify

## User enable and disable. This is entirely handled by pam.

## Group add delete modify. This is covered by pam. However, someone could
## open a file and directly create or modify a user, so we'll watch group and
## gshadow for writes
-a always,exit -F arch=b32 -F path=/etc/passwd -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -F path=/etc/passwd -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -F path=/etc/shadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -F path=/etc/shadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -F path=/etc/group -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify
-a always,exit -F arch=b64 -F path=/etc/group -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify
-a always,exit -F arch=b32 -F path=/etc/gshadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify
-a always,exit -F arch=b64 -F path=/etc/gshadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify


## Use of special rights for config changes. This would be use of setuid
## programs that relate to user accts. This is not all setuid apps because
## requirements are only for ones that affect system configuration.
-a always,exit -F arch=b32 -F path=/usr/sbin/unix_chkpwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/unix_chkpwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/sbin/usernetctl -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/usernetctl -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/sbin/userhelper -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/userhelper -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/sbin/seunshare -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/seunshare -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/mount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/mount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/newgrp -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/newgrp -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/newuidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/newuidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/gpasswd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/gpasswd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/newgidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/newgidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/umount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/umount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/passwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/passwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/crontab -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/crontab -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/at -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/at -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/sbin/grub2-set-bootflag -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/grub2-set-bootflag -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes

## Privilege escalation via su or sudo. This is entirely handled by pam.
## Special case for systemd-run. It is not audit aware, specifically watch it
-a always,exit -F arch=b32 -F path=/usr/bin/systemd-run -F perm=x -F auid!=unset -F key=maybe-escalation
-a always,exit -F arch=b64 -F path=/usr/bin/systemd-run -F perm=x -F auid!=unset -F key=maybe-escalation
## Special case for pkexec. It is not audit aware, specifically watch it
-a always,exit -F arch=b32 -F path=/usr/bin/pkexec -F perm=x -F key=maybe-escalation
-a always,exit -F arch=b64 -F path=/usr/bin/pkexec -F perm=x -F key=maybe-escalation


## Watch for configuration changes to privilege escalation.
-a always,exit -F arch=b32 -F path=/etc/sudoers -F perm=wa -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/etc/sudoers -F perm=wa -F key=special-config-changes
-a always,exit -F arch=b32 -F dir=/etc/sudoers.d/ -F perm=wa -F key=special-config-changes
-a always,exit -F arch=b64 -F dir=/etc/sudoers.d/ -F perm=wa -F key=special-config-changes

## Audit log access
-a always,exit -F arch=b32 -F dir=/var/log/audit/ -F perm=r -F auid&gt;=1000 -F auid!=unset -F key=access-audit-trail
-a always,exit -F arch=b64 -F dir=/var/log/audit/ -F perm=r -F auid&gt;=1000 -F auid!=unset -F key=access-audit-trail
## Attempts to Alter Process and Session Initiation Information
-a always,exit -F arch=b32 -F path=/var/run/utmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b64 -F path=/var/run/utmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b32 -F path=/var/log/btmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b64 -F path=/var/log/btmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b32 -F path=/var/log/wtmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b64 -F path=/var/log/wtmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session

## Attempts to modify MAC controls
-a always,exit -F arch=b32 -F dir=/etc/selinux/ -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=MAC-policy
-a always,exit -F arch=b64 -F dir=/etc/selinux/ -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=MAC-policy

## Software updates. This is entirely handled by rpm.

## System start and shutdown. This is entirely handled by systemd

## Kernel Module loading. This is handled in 43-module-load.rules

## Application invocation. The requirements list an optional requirement
## FPT_SRP_EXT.1 Software Restriction Policies. This event is intended to
## state results from that policy. This would be handled entirely by
## that daemon.

EOF

chmod o-rwx /etc/audit/rules.d/30-ospp-v42.rules

augenrules --load

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_ospp_general" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-2(a)
  - audit_ospp_general
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Put contents into /etc/audit/rules.d/30-ospp-v42.rules according to policy
  ansible.builtin.copy:
    dest: /etc/audit/rules.d/30-ospp-v42.rules
    content: |+
      ## The purpose of these rules is to meet the requirements for Operating
      ## System Protection Profile (OSPP)v4.2. These rules depends on having
      ## the following rule files copied to /etc/audit/rules.d:
      ##
      ## 10-base-config.rules, 11-loginuid.rules,
      ## 30-ospp-v42-1-create-failed.rules, 30-ospp-v42-1-create-success.rules,
      ## 30-ospp-v42-2-modify-failed.rules, 30-ospp-v42-2-modify-success.rules,
      ## 30-ospp-v42-3-access-failed.rules, 30-ospp-v42-3-access-success.rules,
      ## 30-ospp-v42-4-delete-failed.rules, 30-ospp-v42-4-delete-success.rules,
      ## 30-ospp-v42-5-perm-change-failed.rules,
      ## 30-ospp-v42-5-perm-change-success.rules,
      ## 30-ospp-v42-6-owner-change-failed.rules,
      ## 30-ospp-v42-6-owner-change-success.rules
      ##
      ## original copies may be found in /usr/share/audit/sample-rules/


      ## User add delete modify. This is covered by pam. However, someone could
      ## open a file and directly create or modify a user, so we'll watch passwd and
      ## shadow for writes
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
      -a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
      -a always,exit -F arch=b64 -S open -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
      -a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify
      -a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify
      -a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify
      -a always,exit -F arch=b64 -S open -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify

      ## User enable and disable. This is entirely handled by pam.

      ## Group add delete modify. This is covered by pam. However, someone could
      ## open a file and directly create or modify a user, so we'll watch group and
      ## gshadow for writes
      -a always,exit -F arch=b32 -F path=/etc/passwd -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
      -a always,exit -F arch=b64 -F path=/etc/passwd -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
      -a always,exit -F arch=b32 -F path=/etc/shadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
      -a always,exit -F arch=b64 -F path=/etc/shadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
      -a always,exit -F arch=b32 -F path=/etc/group -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify
      -a always,exit -F arch=b64 -F path=/etc/group -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify
      -a always,exit -F arch=b32 -F path=/etc/gshadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify
      -a always,exit -F arch=b64 -F path=/etc/gshadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify


      ## Use of special rights for config changes. This would be use of setuid
      ## programs that relate to user accts. This is not all setuid apps because
      ## requirements are only for ones that affect system configuration.
      -a always,exit -F arch=b32 -F path=/usr/sbin/unix_chkpwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b64 -F path=/usr/sbin/unix_chkpwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b32 -F path=/usr/sbin/usernetctl -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b64 -F path=/usr/sbin/usernetctl -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b32 -F path=/usr/sbin/userhelper -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b64 -F path=/usr/sbin/userhelper -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b32 -F path=/usr/sbin/seunshare -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b64 -F path=/usr/sbin/seunshare -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b32 -F path=/usr/bin/mount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b64 -F path=/usr/bin/mount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b32 -F path=/usr/bin/newgrp -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b64 -F path=/usr/bin/newgrp -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b32 -F path=/usr/bin/newuidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b64 -F path=/usr/bin/newuidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b32 -F path=/usr/bin/gpasswd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b64 -F path=/usr/bin/gpasswd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b32 -F path=/usr/bin/newgidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b64 -F path=/usr/bin/newgidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b32 -F path=/usr/bin/umount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b64 -F path=/usr/bin/umount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b32 -F path=/usr/bin/passwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b64 -F path=/usr/bin/passwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b32 -F path=/usr/bin/crontab -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b64 -F path=/usr/bin/crontab -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b32 -F path=/usr/bin/at -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b64 -F path=/usr/bin/at -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b32 -F path=/usr/sbin/grub2-set-bootflag -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
      -a always,exit -F arch=b64 -F path=/usr/sbin/grub2-set-bootflag -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes

      ## Privilege escalation via su or sudo. This is entirely handled by pam.
      ## Special case for systemd-run. It is not audit aware, specifically watch it
      -a always,exit -F arch=b32 -F path=/usr/bin/systemd-run -F perm=x -F auid!=unset -F key=maybe-escalation
      -a always,exit -F arch=b64 -F path=/usr/bin/systemd-run -F perm=x -F auid!=unset -F key=maybe-escalation
      ## Special case for pkexec. It is not audit aware, specifically watch it
      -a always,exit -F arch=b32 -F path=/usr/bin/pkexec -F perm=x -F key=maybe-escalation
      -a always,exit -F arch=b64 -F path=/usr/bin/pkexec -F perm=x -F key=maybe-escalation


      ## Watch for configuration changes to privilege escalation.
      -a always,exit -F arch=b32 -F path=/etc/sudoers -F perm=wa -F key=special-config-changes
      -a always,exit -F arch=b64 -F path=/etc/sudoers -F perm=wa -F key=special-config-changes
      -a always,exit -F arch=b32 -F dir=/etc/sudoers.d/ -F perm=wa -F key=special-config-changes
      -a always,exit -F arch=b64 -F dir=/etc/sudoers.d/ -F perm=wa -F key=special-config-changes

      ## Audit log access
      -a always,exit -F arch=b32 -F dir=/var/log/audit/ -F perm=r -F auid&gt;=1000 -F auid!=unset -F key=access-audit-trail
      -a always,exit -F arch=b64 -F dir=/var/log/audit/ -F perm=r -F auid&gt;=1000 -F auid!=unset -F key=access-audit-trail
      ## Attempts to Alter Process and Session Initiation Information
      -a always,exit -F arch=b32 -F path=/var/run/utmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
      -a always,exit -F arch=b64 -F path=/var/run/utmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
      -a always,exit -F arch=b32 -F path=/var/log/btmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
      -a always,exit -F arch=b64 -F path=/var/log/btmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
      -a always,exit -F arch=b32 -F path=/var/log/wtmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
      -a always,exit -F arch=b64 -F path=/var/log/wtmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session

      ## Attempts to modify MAC controls
      -a always,exit -F arch=b32 -F dir=/etc/selinux/ -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=MAC-policy
      -a always,exit -F arch=b64 -F dir=/etc/selinux/ -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=MAC-policy

      ## Software updates. This is entirely handled by rpm.

      ## System start and shutdown. This is entirely handled by systemd

      ## Kernel Module loading. This is handled in 43-module-load.rules

      ## Application invocation. The requirements list an optional requirement
      ## FPT_SRP_EXT.1 Software Restriction Policies. This event is intended to
      ## state results from that policy. This would be handled entirely by
      ## that daemon.

    force: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_ospp_general
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Perform general configuration of Audit for OSPP - Remove any permissions from
    group and other
  ansible.builtin.file:
    path: /etc/audit/rules.d/30-ospp-v42.rules
    mode: g-rwx,o-rwx
    state: touch
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_ospp_general
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:fix id="audit_ospp_general" system="urn:xccdf:fix:script:kubernetes">---
apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
spec:
  config:
    ignition:
      version: 3.1.0
    storage:
      files:
      - contents:
          source: data:,%23%23%20The%20purpose%20of%20these%20rules%20is%20to%20meet%20the%20requirements%20for%20Operating%0A%23%23%20System%20Protection%20Profile%20%28OSPP%29v4.2.%20These%20rules%20depends%20on%20having%0A%23%23%20the%20following%20rule%20files%20copied%20to%20%2Fetc%2Faudit%2Frules.d%3A%0A%23%23%0A%23%23%2010-base-config.rules%2C%2011-loginuid.rules%2C%0A%23%23%2030-ospp-v42-1-create-failed.rules%2C%2030-ospp-v42-1-create-success.rules%2C%0A%23%23%2030-ospp-v42-2-modify-failed.rules%2C%2030-ospp-v42-2-modify-success.rules%2C%0A%23%23%2030-ospp-v42-3-access-failed.rules%2C%2030-ospp-v42-3-access-success.rules%2C%0A%23%23%2030-ospp-v42-4-delete-failed.rules%2C%2030-ospp-v42-4-delete-success.rules%2C%0A%23%23%2030-ospp-v42-5-perm-change-failed.rules%2C%0A%23%23%2030-ospp-v42-5-perm-change-success.rules%2C%0A%23%23%2030-ospp-v42-6-owner-change-failed.rules%2C%0A%23%23%2030-ospp-v42-6-owner-change-success.rules%0A%0A%23%23%20User%20add%20delete%20modify.%20This%20is%20covered%20by%20pam.%20However%2C%20someone%20could%0A%23%23%20open%20a%20file%20and%20directly%20create%20or%20modify%20a%20user%2C%20so%20we%27ll%20watch%20passwd%20and%0A%23%23%20shadow%20for%20writes%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20openat%2Copen_by_handle_at%20-F%20a2%2603%20-F%20path%3D%2Fetc%2Fpasswd%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Duser-modify%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20openat%2Copen_by_handle_at%20-F%20a2%2603%20-F%20path%3D%2Fetc%2Fpasswd%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Duser-modify%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20open%20-F%20a1%2603%20-F%20path%3D%2Fetc%2Fpasswd%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Duser-modify%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20open%20-F%20a1%2603%20-F%20path%3D%2Fetc%2Fpasswd%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Duser-modify%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20openat%2Copen_by_handle_at%20-F%20a2%2603%20-F%20path%3D%2Fetc%2Fshadow%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Duser-modify%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20openat%2Copen_by_handle_at%20-F%20a2%2603%20-F%20path%3D%2Fetc%2Fshadow%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Duser-modify%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20open%20-F%20a1%2603%20-F%20path%3D%2Fetc%2Fshadow%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Duser-modify%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20open%20-F%20a1%2603%20-F%20path%3D%2Fetc%2Fshadow%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Duser-modify%0A%0A%23%23%20User%20enable%20and%20disable.%20This%20is%20entirely%20handled%20by%20pam.%0A%0A%23%23%20Group%20add%20delete%20modify.%20This%20is%20covered%20by%20pam.%20However%2C%20someone%20could%0A%23%23%20open%20a%20file%20and%20directly%20create%20or%20modify%20a%20user%2C%20so%20we%27ll%20watch%20group%20and%0A%23%23%20gshadow%20for%20writes%0A-a%20always%2Cexit%20-F%20path%3D%2Fetc%2Fpasswd%20-F%20perm%3Dwa%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Duser-modify%0A-a%20always%2Cexit%20-F%20path%3D%2Fetc%2Fshadow%20-F%20perm%3Dwa%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Duser-modify%0A-a%20always%2Cexit%20-F%20path%3D%2Fetc%2Fgroup%20-F%20perm%3Dwa%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dgroup-modify%0A-a%20always%2Cexit%20-F%20path%3D%2Fetc%2Fgshadow%20-F%20perm%3Dwa%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dgroup-modify%0A%0A%0A%23%23%20Use%20of%20special%20rights%20for%20config%20changes.%20This%20would%20be%20use%20of%20setuid%0A%23%23%20programs%20that%20relate%20to%20user%20accts.%20This%20is%20not%20all%20setuid%20apps%20because%0A%23%23%20requirements%20are%20only%20for%20ones%20that%20affect%20system%20configuration.%0A-a%20always%2Cexit%20-F%20path%3D%2Fusr%2Fsbin%2Funix_chkpwd%20-F%20perm%3Dx%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dspecial-config-changes%0A-a%20always%2Cexit%20-F%20path%3D%2Fusr%2Fsbin%2Fusernetctl%20-F%20perm%3Dx%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dspecial-config-changes%0A-a%20always%2Cexit%20-F%20path%3D%2Fusr%2Fsbin%2Fuserhelper%20-F%20perm%3Dx%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dspecial-config-changes%0A-a%20always%2Cexit%20-F%20path%3D%2Fusr%2Fsbin%2Fseunshare%20-F%20perm%3Dx%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dspecial-config-changes%0A-a%20always%2Cexit%20-F%20path%3D%2Fusr%2Fbin%2Fmount%20-F%20perm%3Dx%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dspecial-config-changes%0A-a%20always%2Cexit%20-F%20path%3D%2Fusr%2Fbin%2Fnewgrp%20-F%20perm%3Dx%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dspecial-config-changes%0A-a%20always%2Cexit%20-F%20path%3D%2Fusr%2Fbin%2Fnewuidmap%20-F%20perm%3Dx%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dspecial-config-changes%0A-a%20always%2Cexit%20-F%20path%3D%2Fusr%2Fbin%2Fgpasswd%20-F%20perm%3Dx%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dspecial-config-changes%0A-a%20always%2Cexit%20-F%20path%3D%2Fusr%2Fbin%2Fnewgidmap%20-F%20perm%3Dx%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dspecial-config-changes%0A-a%20always%2Cexit%20-F%20path%3D%2Fusr%2Fbin%2Fumount%20-F%20perm%3Dx%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dspecial-config-changes%0A-a%20always%2Cexit%20-F%20path%3D%2Fusr%2Fbin%2Fpasswd%20-F%20perm%3Dx%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dspecial-config-changes%0A-a%20always%2Cexit%20-F%20path%3D%2Fusr%2Fbin%2Fcrontab%20-F%20perm%3Dx%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dspecial-config-changes%0A-a%20always%2Cexit%20-F%20path%3D%2Fusr%2Fbin%2Fat%20-F%20perm%3Dx%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dspecial-config-changes%0A%0A%23%23%20Privilege%20escalation%20via%20su%20or%20sudo.%20This%20is%20entirely%20handled%20by%20pam.%0A%0A%23%23%20Watch%20for%20configuration%20changes%20to%20privilege%20escalation.%0A-a%20always%2Cexit%20-F%20path%3D%2Fetc%2Fsudoers%20-F%20perm%3Dwa%20-F%20key%3Dspecial-config-changes%0A-a%20always%2Cexit%20-F%20dir%3D%2Fetc%2Fsudoers.d%2F%20-F%20perm%3Dwa%20-F%20key%3Dspecial-config-changes%0A%0A%23%23%20Audit%20log%20access%0A-a%20always%2Cexit%20-F%20dir%3D%2Fvar%2Flog%2Faudit%2F%20-F%20perm%3Dr%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Daccess-audit-trail%0A%23%23%20Attempts%20to%20Alter%20Process%20and%20Session%20Initiation%20Information%0A-a%20always%2Cexit%20-F%20path%3D%2Fvar%2Frun%2Futmp%20-F%20perm%3Dwa%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dsession%0A-a%20always%2Cexit%20-F%20path%3D%2Fvar%2Flog%2Fbtmp%20-F%20perm%3Dwa%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dsession%0A-a%20always%2Cexit%20-F%20path%3D%2Fvar%2Flog%2Fwtmp%20-F%20perm%3Dwa%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dsession%0A%0A%23%23%20Attempts%20to%20modify%20MAC%20controls%0A-a%20always%2Cexit%20-F%20dir%3D%2Fetc%2Fselinux%2F%20-F%20perm%3Dwa%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3DMAC-policy%0A%0A%23%23%20Software%20updates.%20This%20is%20entirely%20handled%20by%20rpm.%0A%0A%23%23%20System%20start%20and%20shutdown.%20This%20is%20entirely%20handled%20by%20systemd%0A%0A%23%23%20Kernel%20Module%20loading.%20This%20is%20handled%20in%2043-module-load.rules%0A%0A%23%23%20Application%20invocation.%20The%20requirements%20list%20an%20optional%20requirement%0A%23%23%20FPT_SRP_EXT.1%20Software%20Restriction%20Policies.%20This%20event%20is%20intended%20to%0A%23%23%20state%20results%20from%20that%20policy.%20This%20would%20be%20handled%20entirely%20by%0A%23%23%20that%20daemon.%0A%0A
        mode: 0600
        path: /etc/audit/rules.d/30-ospp-v42.rules
        overwrite: true
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_ospp_general:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_ospp_general_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_owner_change_failed" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditing of unsuccessful ownership changes</xccdf-1.2:title>
            <xccdf-1.2:description>Ensure that unsuccessful attempts to change an ownership of files or directories are audited.

The following rules configure audit as described above:
<html:pre>## Unsuccessful ownership change
-a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
-a always,exit -F arch=b64 -S lchown,fchown,chown,fchownat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
-a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
-a always,exit -F arch=b64 -S lchown,fchown,chown,fchownat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change    </html:pre>

Load new Audit rules into kernel by running:
<html:pre>augenrules --load</html:pre>

Note: This rule uses a special set of Audit rules to comply with OSPP 4.2.1. You may reuse this rule in different profiles. If you decide to do so, it is recommended that you inspect contents of the file closely and make sure that they are aligned with your needs.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.1.c</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Unsuccessful attempts to change an ownership of files or directories might be signs of a malicious activity. Having such events audited helps in monitoring and investigation of such activities.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_owner_change_failed" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &lt;&lt; 'EOF' &gt; /etc/audit/rules.d/30-ospp-v42-6-owner-change-failed.rules
## Unsuccessful ownership change
-a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
-a always,exit -F arch=b64 -S lchown,fchown,chown,fchownat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
-a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
-a always,exit -F arch=b64 -S lchown,fchown,chown,fchownat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
EOF

chmod o-rwx /etc/audit/rules.d/30-ospp-v42-6-owner-change-failed.rules

augenrules --load

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_owner_change_failed" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-2(a)
  - audit_owner_change_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Put contents into /etc/audit/rules.d/30-ospp-v42-6-owner-change-failed.rules
    according to policy
  ansible.builtin.copy:
    dest: /etc/audit/rules.d/30-ospp-v42-6-owner-change-failed.rules
    content: |
      ## Unsuccessful ownership change
      -a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
      -a always,exit -F arch=b64 -S lchown,fchown,chown,fchownat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
      -a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
      -a always,exit -F arch=b64 -S lchown,fchown,chown,fchownat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
    force: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_owner_change_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure auditing of unsuccessful ownership changes - Remove any permissions
    from group and other
  ansible.builtin.file:
    path: /etc/audit/rules.d/30-ospp-v42-6-owner-change-failed.rules
    mode: g-rwx,o-rwx
    state: touch
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_owner_change_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_owner_change_failed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_owner_change_failed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_owner_change_success" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditing of successful ownership changes</xccdf-1.2:title>
            <xccdf-1.2:description>Ensure that successful attempts to change an ownership of files or directories are audited.

The following rules configure audit as described above:
<html:pre>## Successful ownership change
-a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-owner-change
-a always,exit -F arch=b64 -S lchown,fchown,chown,fchownat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-owner-change    </html:pre>

Load new Audit rules into kernel by running:
<html:pre>augenrules --load</html:pre>

Note: This rule uses a special set of Audit rules to comply with OSPP 4.2.1. You may reuse this rule in different profiles. If you decide to do so, it is recommended that you inspect contents of the file closely and make sure that they are aligned with your needs.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.1.c</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Auditing of successful ownership changes of files or directories helps in monitoring or investigating of activities performed on the system.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_owner_change_success" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &lt;&lt; 'EOF' &gt; /etc/audit/rules.d/30-ospp-v42-6-owner-change-success.rules
## Successful ownership change
-a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-owner-change
-a always,exit -F arch=b64 -S lchown,fchown,chown,fchownat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-owner-change
EOF

chmod o-rwx /etc/audit/rules.d/30-ospp-v42-6-owner-change-success.rules

augenrules --load

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_owner_change_success" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-2(a)
  - audit_owner_change_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Put contents into /etc/audit/rules.d/30-ospp-v42-6-owner-change-success.rules
    according to policy
  ansible.builtin.copy:
    dest: /etc/audit/rules.d/30-ospp-v42-6-owner-change-success.rules
    content: |
      ## Successful ownership change
      -a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-owner-change
      -a always,exit -F arch=b64 -S lchown,fchown,chown,fchownat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-owner-change
    force: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_owner_change_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure auditing of successful ownership changes - Remove any permissions
    from group and other
  ansible.builtin.file:
    path: /etc/audit/rules.d/30-ospp-v42-6-owner-change-success.rules
    mode: g-rwx,o-rwx
    state: touch
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_owner_change_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_owner_change_success:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_owner_change_success_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_perm_change_failed" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditing of unsuccessful permission changes</xccdf-1.2:title>
            <xccdf-1.2:description>Ensure that unsuccessful attempts to change file or directory permissions are audited.

The following rules configure audit as described above:
<html:pre>## Unsuccessful permission change
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change    </html:pre>

Load new Audit rules into kernel by running:
<html:pre>augenrules --load</html:pre>

Note: This rule uses a special set of Audit rules to comply with OSPP 4.2.1. You may reuse this rule in different profiles. If you decide to do so, it is recommended that you inspect contents of the file closely and make sure that they are aligned with your needs.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.1.c</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Unsuccessful attempts to change permissions of files or directories might be signs of malicious activity. Having such events audited helps in monitoring and investigation of such activities.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_perm_change_failed" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &lt;&lt; 'EOF' &gt; /etc/audit/rules.d/30-ospp-v42-5-perm-change-failed.rules
## Unsuccessful permission change
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
EOF

chmod o-rwx /etc/audit/rules.d/30-ospp-v42-5-perm-change-failed.rules

augenrules --load

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_perm_change_failed" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-2(a)
  - audit_perm_change_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Put contents into /etc/audit/rules.d/30-ospp-v42-5-perm-change-failed.rules
    according to policy
  ansible.builtin.copy:
    dest: /etc/audit/rules.d/30-ospp-v42-5-perm-change-failed.rules
    content: |
      ## Unsuccessful permission change
      -a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
      -a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
      -a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
      -a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
    force: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_perm_change_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure auditing of unsuccessful permission changes - Remove any permissions
    from group and other
  ansible.builtin.file:
    path: /etc/audit/rules.d/30-ospp-v42-5-perm-change-failed.rules
    mode: g-rwx,o-rwx
    state: touch
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_perm_change_failed
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_perm_change_failed:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_perm_change_failed_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_perm_change_success" selected="false" severity="medium">
            <xccdf-1.2:title>Configure auditing of successful permission changes</xccdf-1.2:title>
            <xccdf-1.2:description>Ensure that successful attempts to modify permissions of files or directories are audited.

The following rules configure audit as described above:
<html:pre>## Successful permission change
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change    </html:pre>

Load new Audit rules into kernel by running:
<html:pre>augenrules --load</html:pre>

Note: This rule uses a special set of Audit rules to comply with OSPP 4.2.1. You may reuse this rule in different profiles. If you decide to do so, it is recommended that you inspect contents of the file closely and make sure that they are aligned with your needs.</xccdf-1.2:description>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">AU-2(a)</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.niap-ccevs.org/Profile/PP.cfm">FAU_GEN.1.1.c</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
            <xccdf-1.2:rationale>Auditing successful file or directory permission changes helps in monitoring and investigating of activities performed on the system.</xccdf-1.2:rationale>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_perm_change_success" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cat &lt;&lt; 'EOF' &gt; /etc/audit/rules.d/30-ospp-v42-5-perm-change-success.rules
## Successful permission change
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change
EOF

chmod o-rwx /etc/audit/rules.d/30-ospp-v42-5-perm-change-success.rules

augenrules --load

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:fix complexity="low" disruption="low" id="audit_perm_change_success" reboot="false" strategy="restrict" system="urn:xccdf:fix:script:ansible">- name: Gather the package facts
  package_facts:
    manager: auto
  tags:
  - NIST-800-53-AU-2(a)
  - audit_perm_change_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Put contents into /etc/audit/rules.d/30-ospp-v42-5-perm-change-success.rules
    according to policy
  ansible.builtin.copy:
    dest: /etc/audit/rules.d/30-ospp-v42-5-perm-change-success.rules
    content: |
      ## Successful permission change
      -a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change
      -a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change
    force: true
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_perm_change_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy

- name: Configure auditing of successful permission changes - Remove any permissions
    from group and other
  ansible.builtin.file:
    path: /etc/audit/rules.d/30-ospp-v42-5-perm-change-success.rules
    mode: g-rwx,o-rwx
    state: touch
  when: '"kernel" in ansible_facts.packages'
  tags:
  - NIST-800-53-AU-2(a)
  - audit_perm_change_success
  - low_complexity
  - low_disruption
  - medium_severity
  - no_reboot_needed
  - restrict_strategy
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_perm_change_success:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_perm_change_success_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
          <xccdf-1.2:Rule id="xccdf_org.ssgproject.content_rule_audit_rules_for_ospp" selected="false" severity="medium">
            <xccdf-1.2:title>Configure audit according to OSPP requirements</xccdf-1.2:title>
            <xccdf-1.2:description>Configure audit to meet requirements for Operating System Protection Profile (OSPP) v4.2.1.

Audit defines groups of rules in <html:code>/usr/share/doc/audit/rules</html:code> to satisfy specific policies.

To fulfill requirements for compliance with OSPP v4.2.1, the following files are necessary:
<html:ul><html:li>/usr/share/doc/audit/rules/10-base-config.rules</html:li><html:li>/usr/share/doc/audit/rules/11-loginuid.rules</html:li><html:li>/usr/share/doc/audit/rules/30-ospp-v42.rules</html:li><html:li>/usr/share/doc/audit/rules/43-module-load.rules</html:li></html:ul>

Copy the files from <html:code>/usr/share/doc/audit/rules</html:code> to <html:code>/etc/audit/rules.d</html:code>:
<html:pre>
cp /usr/share/doc/audit*/rules/{10-base-config,11-loginuid,30-ospp-v42,43-module-load}.rules /etc/audit/rules.d/
</html:pre></xccdf-1.2:description>
            <xccdf-1.2:warning category="performance">It might happen that Audit buffer configured by this rule is not large enough for certain use cases. If that is the case, the buffer size can be overridden by placing <html:pre>-b larger_buffer_size</html:pre> into a file within <html:code>/etc/audit/rules.d</html:code> directory, replacing <html:code>larger_file_size</html:code> with the desired value. The file name should start with a number higher than 10 and lower than 99.</xccdf-1.2:warning>
            <xccdf-1.2:reference href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">NONE</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000004-GPOS-00004</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000240-GPOS-00090</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000241-GPOS-00091</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000303-GPOS-00120</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000476-GPOS-00221</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000327-GPOS-00127</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000064-GPOS-00033</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000365-GPOS-00152</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000458-GPOS-00203</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000461-GPOS-00205</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000462-GPOS-00206</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000463-GPOS-00207</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000465-GPOS-00209</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000466-GPOS-00210</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000468-GPOS-00212</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000470-GPOS-00214</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00215</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000471-GPOS-00216</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000472-GPOS-00217</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000474-GPOS-00219</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000475-GPOS-00220</xccdf-1.2:reference>
            <xccdf-1.2:reference href="https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000477-GPOS-00222</xccdf-1.2:reference>
            <xccdf-1.2:rationale>The audit rules defined in <html:code>/usr/share/doc/audit/rules</html:code> are the recommended way to meet compliance with OSPP v4.2.1.</xccdf-1.2:rationale>
            <xccdf-1.2:fix id="audit_rules_for_ospp" system="urn:xccdf:fix:script:sh"># Remediation is applicable only in certain platforms
if rpm --quiet -q kernel; then

cp /usr/share/doc/audit*/rules/10-base-config.rules /etc/audit/rules.d
cp /usr/share/doc/audit*/rules/11-loginuid.rules /etc/audit/rules.d
cp /usr/share/doc/audit*/rules/30-ospp-v42.rules /etc/audit/rules.d
cp /usr/share/doc/audit*/rules/43-module-load.rules /etc/audit/rules.d

augenrules --load

else
    &gt;&amp;2 echo 'Remediation is not applicable, nothing was done'
fi
</xccdf-1.2:fix>
            <xccdf-1.2:check system="http://oval.mitre.org/XMLSchema/oval-definitions-5">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-oval.xml" name="oval:ssg-audit_rules_for_ospp:def:1"/>
            </xccdf-1.2:check>
            <xccdf-1.2:check system="http://scap.nist.gov/schema/ocil/2">
              <xccdf-1.2:check-content-ref href="ssg-almalinux8-ocil.xml" name="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1"/>
            </xccdf-1.2:check>
          </xccdf-1.2:Rule>
        </xccdf-1.2:Group>
      </xccdf-1.2:Group>
    </xccdf-1.2:Benchmark>
  </ds:component>
  <ds:component id="scap_org.open-scap_comp_ssg-almalinux8-oval.xml" timestamp="2026-06-15T09:09:30">
    <oval-def:oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
      <oval-def:generator>
        <oval:product_name>OVALFileLinker from SCAP Security Guide</oval:product_name>
        <oval:product_version>ssg: [0, 1, 81], python: 3.6.8</oval:product_version>
        <oval:schema_version>5.11</oval:schema_version>
        <oval:timestamp>2026-06-15T09:09:10</oval:timestamp>
      </oval-def:generator>
      <oval-def:definitions>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_continue_loading:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure the Audit Configuration is Loaded Regardless of Errors</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_continue_loading" source="ssg"/>
            <oval-def:description>Ensure the Audit Configuration is Loaded Regardless of Errors</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules configuration locked" test_ref="oval:ssg-test_audit_rules_continue_loading_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl configuration locked" test_ref="oval:ssg-test_audit_rules_continue_loading_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_immutable:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Make the auditd Configuration Immutable</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_immutable" source="ssg"/>
            <oval-def:description>Force a reboot to change audit rules is enabled</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules configuration locked" test_ref="oval:ssg-test_ari_locked_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl configuration locked" test_ref="oval:ssg-test_ari_locked_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_immutable_login_uids:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure immutable Audit login UIDs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_immutable_login_uids" source="ssg"/>
            <oval-def:description>Check if system is configured to make login UIDs immutable</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="check that --loginuid-immutable is set in /etc/audit/rules.d/*.rules" test_ref="oval:ssg-test_augen_immutable_login_uids:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="test that --loginuid-immutable is set in /etc/audit/audit.rules" test_ref="oval:ssg-test_auditctl_immutable_login_uids:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_mac_modification:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Mandatory Access Controls</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_mac_modification" source="ssg"/>
            <oval-def:description>Audit rules that detect changes to the system's mandatory access controls (SELinux) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit selinux changes augenrules" test_ref="oval:ssg-test_armm_selinux_watch_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit selinux changes auditctl" test_ref="oval:ssg-test_armm_selinux_watch_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_networkconfig_modification:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Network Environment</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_networkconfig_modification" source="ssg"/>
            <oval-def:description>The network environment should not be modified by anything other than
      administrator action. Any change to network parameters should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit /etc/issue augenrules" test_ref="oval:ssg-test_arnm_common_etc_issue_augenrules:tst:1"/>
              <oval-def:criterion comment="audit /etc/issue.net augenrules" test_ref="oval:ssg-test_arnm_common_etc_issue_net_augenrules:tst:1"/>
              <oval-def:criterion comment="audit /etc/hosts augenrules" test_ref="oval:ssg-test_arnm_common_etc_hosts_augenrules:tst:1"/>
              <oval-def:criterion comment="audit /etc/sysconfig/network augenrules" test_ref="oval:ssg-test_arnm_common_etc_sysconfig_network_augenrules:tst:1"/>
              <oval-def:extend_definition comment="audit augenrules sethostname" definition_ref="oval:ssg-audit_rules_networkconfig_modification_hostname:def:1"/>
              <oval-def:extend_definition comment="audit augenrules setdomainname" definition_ref="oval:ssg-audit_rules_networkconfig_modification_domainname:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit /etc/issue auditctl" test_ref="oval:ssg-test_arnm_common_etc_issue_auditctl:tst:1"/>
              <oval-def:criterion comment="audit /etc/issue.net auditctl" test_ref="oval:ssg-test_arnm_common_etc_issue_net_auditctl:tst:1"/>
              <oval-def:criterion comment="audit /etc/hosts auditctl" test_ref="oval:ssg-test_arnm_common_etc_hosts_auditctl:tst:1"/>
              <oval-def:criterion comment="audit /etc/sysconfig/network auditctl" test_ref="oval:ssg-test_arnm_common_etc_sysconfig_network_auditctl:tst:1"/>
              <oval-def:extend_definition comment="audit augenrules sethostname" definition_ref="oval:ssg-audit_rules_networkconfig_modification_hostname:def:1"/>
              <oval-def:extend_definition comment="audit augenrules setdomainname" definition_ref="oval:ssg-audit_rules_networkconfig_modification_domainname:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_session_events:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Attempts to Alter Process and Session Initiation Information</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_session_events" source="ssg"/>
            <oval-def:description>Audit rules should capture information about session initiation.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules utmp" test_ref="oval:ssg-test_arse_utmp_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules btmp" test_ref="oval:ssg-test_arse_btmp_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules wtmp" test_ref="oval:ssg-test_arse_wtmp_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl utmp" test_ref="oval:ssg-test_arse_utmp_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl btmp" test_ref="oval:ssg-test_arse_btmp_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl wtmp" test_ref="oval:ssg-test_arse_wtmp_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_suid_auid_privilege_function:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events When Executables Are Run As Another User</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_suid_auid_privilege_function" source="ssg"/>
            <oval-def:description>Ensure audit rule for all uses of privileged functions is enabled</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit uid privileged function " test_ref="oval:ssg-test_32bit_uid_auid_privileged_function_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 64-bit uid privileged function" test_ref="oval:ssg-test_64bit_uid_auid_privileged_function_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit uid privileged function" test_ref="oval:ssg-test_32bit_uid_auid_privileged_function_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 64-bit uid privileged function" test_ref="oval:ssg-test_64bit_uid_auid_privileged_function_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_suid_privilege_function:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events When Privileged Executables Are Run</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_suid_privilege_function" source="ssg"/>
            <oval-def:description>Ensure audit rule for all uses of privileged functions is enabled</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit uid privileged function " test_ref="oval:ssg-test_32bit_uid_privileged_function_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 64-bit uid privileged function" test_ref="oval:ssg-test_64bit_uid_privileged_function_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit gid privileged function " test_ref="oval:ssg-test_32bit_gid_privileged_function_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 64-bit gid privileged function" test_ref="oval:ssg-test_64bit_gid_privileged_function_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit uid privileged function" test_ref="oval:ssg-test_32bit_uid_privileged_function_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 64-bit uid privileged function" test_ref="oval:ssg-test_64bit_uid_privileged_function_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit gid privileged function" test_ref="oval:ssg-test_32bit_gid_privileged_function_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 64-bit gid privileged function" test_ref="oval:ssg-test_64bit_gid_privileged_function_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_sysadmin_actions:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects System Administrator Actions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_sysadmin_actions" source="ssg"/>
            <oval-def:description>Audit actions taken by system administrators on the system.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_sudoers:def:1"/>
            <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_sudoers_d:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_system_shutdown:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Shutdown System When Auditing Failures Occur</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_system_shutdown" source="ssg"/>
            <oval-def:description>The system will shutdown when auditing fails.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules configuration shutdown" test_ref="oval:ssg-test_ars_shutdown_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl configuration shutdown" test_ref="oval:ssg-test_ars_shutdown_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_usergroup_modification:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_usergroup_modification" source="ssg"/>
            <oval-def:description>Audit rules should detect modification to system files that hold information about users and groups.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit /etc/group" test_ref="oval:ssg-test_audit_rules_usergroup_modification_etc_group_augen:tst:1"/>
              <oval-def:criterion comment="audit /etc/passwd" test_ref="oval:ssg-test_audit_rules_usergroup_modification_etc_passwd_augen:tst:1"/>
              <oval-def:criterion comment="audit /etc/gshadow" test_ref="oval:ssg-test_audit_rules_usergroup_modification_etc_gshadow_augen:tst:1"/>
              <oval-def:criterion comment="audit /etc/shadow" test_ref="oval:ssg-test_audit_rules_usergroup_modification_etc_shadow_augen:tst:1"/>
              <oval-def:criterion comment="audit /etc/security/opasswd" test_ref="oval:ssg-test_audit_rules_usergroup_modification_etc_security_opasswd_augen:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit /etc/group" test_ref="oval:ssg-test_audit_rules_usergroup_modification_etc_group_auditctl:tst:1"/>
              <oval-def:criterion comment="audit /etc/passwd" test_ref="oval:ssg-test_audit_rules_usergroup_modification_etc_passwd_auditctl:tst:1"/>
              <oval-def:criterion comment="audit /etc/gshadow" test_ref="oval:ssg-test_audit_rules_usergroup_modification_etc_gshadow_auditctl:tst:1"/>
              <oval-def:criterion comment="audit /etc/shadow" test_ref="oval:ssg-test_audit_rules_usergroup_modification_etc_shadow_auditctl:tst:1"/>
              <oval-def:criterion comment="audit /etc/security/opasswd" test_ref="oval:ssg-test_audit_rules_usergroup_modification_etc_security_opasswd_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_access_var_log_audit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Access Events to Audit Log Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_access_var_log_audit" source="ssg"/>
            <oval-def:description>Audit rules about the read events to /var/log/audit</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit rule to record read access events to /var/log/audit" test_ref="oval:ssg-test_directory_access_var_log_audit_augenrules_32bit:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit rule to record read access events to /var/log/audit" test_ref="oval:ssg-test_directory_access_var_log_audit_augenrules_64bit:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit rule to record read access events to /var/log/audit" test_ref="oval:ssg-test_directory_access_var_log_audit_auditctl_32bit:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit rule to record read access events to /var/log/audit" test_ref="oval:ssg-test_directory_access_var_log_audit_auditctl_64bit:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_group_ownership_var_log_audit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>System Audit Directories Must Be Group Owned By Root</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_group_ownership_var_log_audit" source="ssg"/>
            <oval-def:description>Checks that all /var/log/audit directories are group owned by the root user.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria comment="log_file set" operator="AND">
              <oval-def:extend_definition comment="log_file set in auditd.conf" definition_ref="oval:ssg-auditd_conf_log_file_not_set:def:1" negate="true"/>
              <oval-def:criterion comment="log directory is owned by root" test_ref="oval:ssg-test_group_ownership_var_log_audit_directories:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="log_file not set" operator="AND">
              <oval-def:extend_definition comment="log_file set in auditd.conf" definition_ref="oval:ssg-auditd_conf_log_file_not_set:def:1"/>
              <oval-def:criterion comment="default log directory is owned by root" test_ref="oval:ssg-test_group_ownership_default_var_log_audit_directories:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="log_group in auditd.conf is not root" operator="AND">
              <oval-def:extend_definition comment="log_group in auditd.conf is not root" definition_ref="oval:ssg-auditd_conf_log_group_not_root:def:1"/>
              <oval-def:criterion test_ref="oval:ssg-test_group_ownership_var_log_audit_directories-non_root:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_ownership_var_log_audit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>System Audit Directories Must Be Owned By Root</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_ownership_var_log_audit" source="ssg"/>
            <oval-def:description>Checks that all /var/log/audit directories are owned by the root user.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="directories are root owned" operator="OR">
            <oval-def:criteria comment="log_file set" operator="AND">
              <oval-def:extend_definition comment="log_file set in auditd.conf" definition_ref="oval:ssg-auditd_conf_log_file_not_set:def:1" negate="true"/>
              <oval-def:criterion test_ref="oval:ssg-test_user_ownership_var_log_audit_path:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="log_file not set" operator="AND">
              <oval-def:extend_definition comment="log_file not set in auditd.conf" definition_ref="oval:ssg-auditd_conf_log_file_not_set:def:1"/>
              <oval-def:criterion test_ref="oval:ssg-test_user_ownership_var_log_audit_directories:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_permissions_var_log_audit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>System Audit Logs Must Have Mode 0750 or Less Permissive</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_permissions_var_log_audit" source="ssg"/>
            <oval-def:description>Checks for correct permissions for audit logs.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria comment="log_file set" operator="AND">
              <oval-def:extend_definition comment="log file set in auditd.conf" definition_ref="oval:ssg-auditd_conf_log_file_not_set:def:1" negate="true"/>
              <oval-def:criteria operator="OR">
                <oval-def:criteria comment="log_file set and log_group set to not root" operator="AND">
                  <oval-def:extend_definition comment="log_group in auditd.conf is not set to root" definition_ref="oval:ssg-auditd_conf_log_group_not_root:def:1"/>
                  <oval-def:criterion comment="non-default log_file and log_group set to non-root" test_ref="oval:ssg-test_permissions_audit_log_directory_not_root:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria comment="log_file set and log_group root or not set" operator="AND">
                  <oval-def:extend_definition comment="log_group in auditd.conf is set to root or not set" definition_ref="oval:ssg-auditd_conf_log_group_not_root:def:1" negate="true"/>
                  <oval-def:criterion comment="non-default log_file and log_group root or not set" test_ref="oval:ssg-test_permissions_audit_log_directory_root:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria comment="log_file not set" operator="AND">
              <oval-def:extend_definition comment="log file not set in auditd.conf" definition_ref="oval:ssg-auditd_conf_log_file_not_set:def:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:criteria comment="default log_file and log_group set to not root" operator="AND">
                  <oval-def:extend_definition comment="log_group in auditd.conf is not set to root" definition_ref="oval:ssg-auditd_conf_log_group_not_root:def:1"/>
                  <oval-def:criterion comment="default log_file and log_group set to non-root" test_ref="oval:ssg-test_permissions_default_audit_log_directory_not_root:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria comment="default log_file and log_group root or not set" operator="AND">
                  <oval-def:extend_definition comment="log_group in auditd.conf is set to root or not set" definition_ref="oval:ssg-auditd_conf_log_group_not_root:def:1" negate="true"/>
                  <oval-def:criterion comment="default log_file and log_group root or not set" test_ref="oval:ssg-test_permissions_default_audit_log_directory_root:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_group_ownership_var_log_audit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>System Audit Logs Must Be Group Owned By Root</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_group_ownership_var_log_audit" source="ssg"/>
            <oval-def:description>Checks that all audit log files are group owned by the root user.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria comment="log_file set" operator="AND">
              <oval-def:extend_definition comment="log file set in auditd.conf" definition_ref="oval:ssg-auditd_conf_log_file_not_set:def:1" negate="true"/>
              <oval-def:criteria operator="XOR">
                <oval-def:criterion comment="audit log files are root group owned" test_ref="oval:ssg-test_group_ownership_audit_log_files:tst:1"/>
                <oval-def:extend_definition comment="log_group in auditd.conf is not root" definition_ref="oval:ssg-auditd_conf_log_group_not_root:def:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria comment="log_file not set" operator="AND">
              <oval-def:extend_definition comment="log file not set in auditd.conf" definition_ref="oval:ssg-auditd_conf_log_file_not_set:def:1"/>
              <oval-def:criteria operator="XOR">
                <oval-def:criterion comment="default audit log files are root group owned" test_ref="oval:ssg-test_group_ownership_default_audit_log_files:tst:1"/>
                <oval-def:extend_definition comment="log_group in auditd.conf is not root" definition_ref="oval:ssg-auditd_conf_log_group_not_root:def:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_ownership_var_log_audit:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>System Audit Logs Must Be Owned By Root</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_ownership_var_log_audit" source="ssg"/>
            <oval-def:description>Checks that all /var/log/audit files and directories are owned by the root user and group.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria comment="directories are root owned" operator="AND">
              <oval-def:criterion test_ref="oval:ssg-test_ownership_var_log_audit_files:tst:1"/>
              <oval-def:criterion test_ref="oval:ssg-test_ownership_var_log_audit_directories:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="log_group in auditd.conf is not root" operator="AND">
              <oval-def:extend_definition comment="log_group in auditd.conf is not root" definition_ref="oval:ssg-auditd_conf_log_group_not_root:def:1"/>
              <oval-def:criterion test_ref="oval:ssg-test_ownership_var_log_audit_files-non_root:tst:1"/>
              <oval-def:criterion test_ref="oval:ssg-test_ownership_var_log_audit_directories-non_root:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_ownership_var_log_audit_stig:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>System Audit Logs Must Be Owned By Root</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_ownership_var_log_audit_stig" source="ssg"/>
            <oval-def:description>Checks that all audit log files are owned by the root user.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria comment="log_file set" operator="AND">
              <oval-def:extend_definition comment="log_file not set in auditd.conf" definition_ref="oval:ssg-auditd_conf_log_file_not_set:def:1" negate="true"/>
              <oval-def:criterion comment="audit log files are root owned" test_ref="oval:ssg-test_user_ownership_audit_log_files:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="/var/log/audit root owned" test_ref="oval:ssg-test_user_ownership_var_log_audit_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_var_log_audit:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>System Audit Logs Must Have Mode 0640 or Less Permissive</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_var_log_audit" source="ssg"/>
            <oval-def:description>Checks for correct permissions for all audit log files.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria comment="log_file set" operator="AND">
              <oval-def:extend_definition comment="log file set in auditd.conf" definition_ref="oval:ssg-auditd_conf_log_file_not_set:def:1" negate="true"/>
              <oval-def:criteria operator="OR">
                <oval-def:criteria comment="log_file set and log_group set to not root" operator="AND">
                  <oval-def:extend_definition comment="log_group in auditd.conf is not set to root" definition_ref="oval:ssg-auditd_conf_log_group_not_root:def:1"/>
                  <oval-def:criterion comment="non-default log_file and log_group set to non-root" negate="true" test_ref="oval:ssg-test_file_permissions_audit_log-non_root:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria comment="log_file set and log_group root or not set" operator="AND">
                  <oval-def:extend_definition comment="log_group in auditd.conf is set to root or not set" definition_ref="oval:ssg-auditd_conf_log_group_not_root:def:1" negate="true"/>
                  <oval-def:criterion comment="non-default log_file and log_group root or not set" negate="true" test_ref="oval:ssg-test_file_permissions_audit_log:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria comment="log_file not set" operator="AND">
              <oval-def:extend_definition comment="log file not set in auditd.conf" definition_ref="oval:ssg-auditd_conf_log_file_not_set:def:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:criteria comment="default log_file and log_group set to not root" operator="AND">
                  <oval-def:extend_definition comment="log_group in auditd.conf is not set to root" definition_ref="oval:ssg-auditd_conf_log_group_not_root:def:1"/>
                  <oval-def:criterion comment="default log_file and log_group set to non-root" negate="true" test_ref="oval:ssg-test_file_permissions_var_log_audit-non_root:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria comment="default log_file and log_group root or not set" operator="AND">
                  <oval-def:extend_definition comment="log_group in auditd.conf is set to root or not set" definition_ref="oval:ssg-auditd_conf_log_group_not_root:def:1" negate="true"/>
                  <oval-def:criterion comment="default log_file and log_group root or not set" negate="true" test_ref="oval:ssg-test_file_permissions_var_log_audit:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_dac_modification_umount:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Discretionary Access Controls - umount</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_dac_modification_umount" source="ssg"/>
            <oval-def:description>The changing of file permissions and attributes should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit umount" test_ref="oval:ssg-test_32bit_ardm_umount_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit umount" test_ref="oval:ssg-test_32bit_ardm_umount_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_file_deletion_events:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects File Deletion Events by User</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_file_deletion_events" source="ssg"/>
            <oval-def:description>Audit files deletion events.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="audit rmdir" definition_ref="oval:ssg-audit_rules_file_deletion_events_rmdir:def:1"/>
            <oval-def:extend_definition comment="audit unlink" definition_ref="oval:ssg-audit_rules_file_deletion_events_unlink:def:1"/>
            <oval-def:extend_definition comment="audit unlinkat" definition_ref="oval:ssg-audit_rules_file_deletion_events_unlinkat:def:1"/>
            <oval-def:extend_definition comment="audit rename" definition_ref="oval:ssg-audit_rules_file_deletion_events_rename:def:1"/>
            <oval-def:extend_definition comment="audit renameat" definition_ref="oval:ssg-audit_rules_file_deletion_events_renameat:def:1"/>
            <oval-def:extend_definition comment="audit renameat2" definition_ref="oval:ssg-audit_rules_file_deletion_events_renameat2:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Unauthorized Access Attempts to Files (unsuccessful)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="audit creat" definition_ref="oval:ssg-audit_rules_unsuccessful_file_modification_creat:def:1"/>
            <oval-def:extend_definition comment="audit ftruncate" definition_ref="oval:ssg-audit_rules_unsuccessful_file_modification_ftruncate:def:1"/>
            <oval-def:extend_definition comment="audit openat" definition_ref="oval:ssg-audit_rules_unsuccessful_file_modification_openat:def:1"/>
            <oval-def:extend_definition comment="audit open_by_handle_at" definition_ref="oval:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at:def:1"/>
            <oval-def:extend_definition comment="audit open" definition_ref="oval:ssg-audit_rules_unsuccessful_file_modification_open:def:1"/>
            <oval-def:extend_definition comment="audit truncate" definition_ref="oval:ssg-audit_rules_unsuccessful_file_modification_truncate:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_kernel_module_loading:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on Kernel Module Loading and Unloading</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_kernel_module_loading" source="ssg"/>
            <oval-def:description>The audit rules should be configured to log information about kernel module loading and unloading.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="audit init_module" definition_ref="oval:ssg-audit_rules_kernel_module_loading_init:def:1"/>
            <oval-def:extend_definition comment="audit delete_module" definition_ref="oval:ssg-audit_rules_kernel_module_loading_delete:def:1"/>
            <oval-def:extend_definition comment="audit finit_module" definition_ref="oval:ssg-audit_rules_kernel_module_loading_finit:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_login_events:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Record Attempts to Alter Logon and Logout Events</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_login_events" source="ssg"/>
            <oval-def:description>Audit rules should be configured to log successful and unsuccessful login and logout events.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="audit tallylog" definition_ref="oval:ssg-audit_rules_login_events_tallylog:def:1"/>
            <oval-def:extend_definition comment="audit faillock" definition_ref="oval:ssg-audit_rules_login_events_faillock:def:1"/>
            <oval-def:extend_definition comment="audit lastlog" definition_ref="oval:ssg-audit_rules_login_events_lastlog:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of privileged commands are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules format is used" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:criteria comment="Audit rules are configured for Image Mode" operator="AND">
                  <oval-def:extend_definition comment="The system is RHEL Image Mode" definition_ref="oval:ssg-bootc:def:1"/>
                  <oval-def:criterion comment="augenrules cover all privileged commands on the system" test_ref="oval:ssg-test_augenrules_all_priv_cmds_covered_bootc:tst:1"/>
                  <oval-def:criterion comment="count of augenrules for priv cmds matches count of priv cmds in the system" test_ref="oval:ssg-test_augenrules_count_matches_system_priv_cmds_bootc:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria comment="Audit rules are configured for Package Mode" operator="AND">
                  <oval-def:extend_definition comment="The system is RHEL Image Mode" definition_ref="oval:ssg-bootc:def:1" negate="true"/>
                  <oval-def:criterion comment="augenrules cover all privileged commands on the system" test_ref="oval:ssg-test_augenrules_all_priv_cmds_covered:tst:1"/>
                  <oval-def:criterion comment="count of augenrules for priv cmds matches count of priv cmds in the system" test_ref="oval:ssg-test_augenrules_count_matches_system_priv_cmds:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl format is used" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:criteria comment="Audit rules are configured for Image Mode" operator="AND">
                  <oval-def:extend_definition comment="The system is RHEL Image Mode" definition_ref="oval:ssg-bootc:def:1"/>
                  <oval-def:criterion comment="auditctl cover all privileged commands on the system" test_ref="oval:ssg-test_auditctl_all_priv_cmds_covered_bootc:tst:1"/>
                  <oval-def:criterion comment="count of auditctl for priv cmds matches count of priv cmds in the system" test_ref="oval:ssg-test_auditctl_count_matches_system_priv_cmds_bootc:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria comment="Audit rules are configured for Package Mode" operator="AND">
                  <oval-def:extend_definition comment="The system is RHEL Image Mode" definition_ref="oval:ssg-bootc:def:1" negate="true"/>
                  <oval-def:criterion comment="auditctl cover all privileged commands on the system" test_ref="oval:ssg-test_auditctl_all_priv_cmds_covered:tst:1"/>
                  <oval-def:criterion comment="count of auditctl for priv cmds matches count of priv cmds in the system" test_ref="oval:ssg-test_auditctl_count_matches_system_priv_cmds:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_time_adjtimex:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record attempts to alter time through adjtimex</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_time_adjtimex" source="ssg"/>
            <oval-def:description>Record attempts to alter time through adjtimex.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit adjtimex" test_ref="oval:ssg-test_32bit_art_adjtimex_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit adjtimex" test_ref="oval:ssg-test_64bit_art_adjtimex_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit adjtimex" test_ref="oval:ssg-test_32bit_art_adjtimex_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit adjtimex" test_ref="oval:ssg-test_64bit_art_adjtimex_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_time_clock_settime:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Record Attempts to Alter Time Through clock_settime</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_time_clock_settime" source="ssg"/>
            <oval-def:description>Record attempts to alter time through clock_settime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit clock_settime" test_ref="oval:ssg-test_32bit_art_clock_settime_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit clock_settime" test_ref="oval:ssg-test_64bit_art_clock_settime_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit clock_settime" test_ref="oval:ssg-test_32bit_art_clock_settime_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit clock_settime" test_ref="oval:ssg-test_64bit_art_clock_settime_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_time_settimeofday:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record attempts to alter time through settimeofday</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_time_settimeofday" source="ssg"/>
            <oval-def:description>Record attempts to alter time through settimeofday.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit settimeofday" test_ref="oval:ssg-test_32bit_art_settimeofday_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit settimeofday" test_ref="oval:ssg-test_64bit_art_settimeofday_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit settimeofday" test_ref="oval:ssg-test_32bit_art_settimeofday_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit settimeofday" test_ref="oval:ssg-test_64bit_art_settimeofday_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_time_stime:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Attempts to Alter Time Through stime</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_time_stime" source="ssg"/>
            <oval-def:description>Record attempts to alter time through stime. Note that on
      64-bit architectures the stime system call is not defined in the audit
      system calls lookup table.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria comment="32-bit or 64-bit system" operator="OR">
              <oval-def:extend_definition comment="32-bit system" definition_ref="oval:ssg-system_info_architecture_x86:def:1"/>
              <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="audit augenrules or audit auditctl" operator="OR">
              <oval-def:criteria comment="audit augenrules stime" operator="AND">
                <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
                <oval-def:criterion comment="audit augenrules 32-bit stime" test_ref="oval:ssg-test_32bit_art_stime_augenrules:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="audit auditctl stime" operator="AND">
                <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
                <oval-def:criterion comment="audit auditctl 32-bit stime" test_ref="oval:ssg-test_32bit_art_stime_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_audispd_configure_remote_server:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure audispd Plugin To Send Logs To Remote Server</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_audispd_configure_remote_server" source="ssg"/>
            <oval-def:description>remote_server setting in /etc/audit/audisp-remote.conf is set to a certain IP address or hostname</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="remote_server setting in audisp-remote.conf" test_ref="oval:ssg-test_auditd_audispd_configure_remote_server:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_audispd_disk_full_action:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure audispd's Plugin disk_full_action When Disk Is Full</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_audispd_disk_full_action" source="ssg"/>
            <oval-def:description>remote_server setting in /etc/audit/audisp-remote.conf is set to a certain IP address or hostname</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="remote_server setting in audisp-remote.conf" test_ref="oval:ssg-test_auditd_audispd_disk_full_action:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_audispd_encrypt_sent_records:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Encrypt Audit Records Sent With audispd Plugin</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_audispd_encrypt_sent_records" source="ssg"/>
            <oval-def:description>transport setting in /etc/audit/audisp-remote.conf is set to 'KRB5'</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="setting in audisp-remote.conf" test_ref="oval:ssg-test_auditd_audispd_encrypt_sent_records:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_audispd_network_failure_action:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure audispd's Plugin network_failure_action On Network Failure</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_audispd_network_failure_action" source="ssg"/>
            <oval-def:description>remote_server setting in /etc/audit/audisp-remote.conf is set to a certain IP address or hostname</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="remote_server setting in audisp-remote.conf" test_ref="oval:ssg-test_auditd_audispd_network_failure_action:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_audispd_syslog_plugin_activated:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditd to use audispd's syslog plugin</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_audispd_syslog_plugin_activated" source="ssg"/>
            <oval-def:description>active setting in /etc/audit/plugins.d/syslog.conf is set to 'yes'</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="active setting in syslog.conf" test_ref="oval:ssg-test_auditd_audispd_syslog_plugin_activated:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_data_disk_error_action:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditd Disk Error Action on Disk Error</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_data_disk_error_action" source="ssg"/>
            <oval-def:description>disk_error_action setting in /etc/audit/auditd.conf is set to a certain action</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="disk_error_action setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_disk_error_action:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_data_disk_error_action_stig:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditd Disk Error Action on Disk Error</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_data_disk_error_action_stig" source="ssg"/>
            <oval-def:description>disk_error_action setting in /etc/audit/auditd.conf is set to SYSLOG, SINGLE or HALT</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="disk_error_action setting in auditd.conf is set to SYSLOG" test_ref="oval:ssg-test_auditd_data_disk_error_action_stig_syslog:tst:1"/>
            <oval-def:criterion comment="disk_error_action setting in auditd.conf is set to SINGLE" test_ref="oval:ssg-test_auditd_data_disk_error_action_stig_single:tst:1"/>
            <oval-def:criterion comment="disk_error_action setting in auditd.conf is set to HALT" test_ref="oval:ssg-test_auditd_data_disk_error_action_stig_halt:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_data_disk_full_action:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditd Disk Full Action when Disk Space Is Full</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_data_disk_full_action" source="ssg"/>
            <oval-def:description>disk_full_action setting in /etc/audit/auditd.conf is set to a certain action</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="disk_full_action setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_disk_full_action:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_data_disk_full_action_stig:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditd Disk Full Action when Disk Space Is Full</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_data_disk_full_action_stig" source="ssg"/>
            <oval-def:description>disk_full_action setting in /etc/audit/auditd.conf is set to SYSLOG, SINGLE or HALT</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="disk_full_action setting in auditd.conf is set to SYSLOG" test_ref="oval:ssg-test_auditd_data_disk_full_action_stig_syslog:tst:1"/>
            <oval-def:criterion comment="disk_full_action setting in auditd.conf is set to SINGLE" test_ref="oval:ssg-test_auditd_data_disk_full_action_stig_single:tst:1"/>
            <oval-def:criterion comment="disk_full_action setting in auditd.conf is set to HALT" test_ref="oval:ssg-test_auditd_data_disk_full_action_stig_halt:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_data_retention_action_mail_acct:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Configure auditd mail_acct Action on Low Disk Space</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_data_retention_action_mail_acct" source="ssg"/>
            <oval-def:description>action_mail_acct setting in /etc/audit/auditd.conf is set to a certain account</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="action_mail_acct setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_retention_action_mail_acct:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_data_retention_admin_space_left_action:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Configure auditd admin_space_left Action on Low Disk Space</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_data_retention_admin_space_left_action" source="ssg"/>
            <oval-def:description>admin_space_left_action setting in /etc/audit/auditd.conf is set to a certain action</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="admin_space_left_action setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_retention_admin_space_left_action:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_data_retention_admin_space_left_percentage:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Configure auditd admin_space_left on Low Disk Space</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_data_retention_admin_space_left_percentage" source="ssg"/>
            <oval-def:description>admin_space_left setting in /etc/audit/auditd.conf is set to at least a certain value</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="admin_space_left setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_retention_admin_space_left_percentage:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_data_retention_flush:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditd flush priority</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_data_retention_flush" source="ssg"/>
            <oval-def:description>The setting for flush in /etc/audit/auditd.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="flush setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_retention_flush:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_data_retention_max_log_file:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Configure auditd Max Log File Size</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_data_retention_max_log_file" source="ssg"/>
            <oval-def:description>max_log_file setting in /etc/audit/auditd.conf is set to at least a certain value</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="max_log_file setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_retention_max_log_file:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_data_retention_max_log_file_action:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Configure auditd max_log_file_action Upon Reaching Maximum Log Size</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_data_retention_max_log_file_action" source="ssg"/>
            <oval-def:description>max_log_file_action setting in /etc/audit/auditd.conf is set to a certain action</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="max_log_file_action setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_retention_max_log_file_action:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_data_retention_max_log_file_action_stig:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditd max_log_file_action Upon Reaching Maximum Log Size</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_data_retention_max_log_file_action_stig" source="ssg"/>
            <oval-def:description>max_log_file_action setting in /etc/audit/auditd.conf is set to a certain action</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="max_log_file_action setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_retention_max_log_file_action_stig_rotate:tst:1"/>
            <oval-def:criterion comment="max_log_file_action setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_retention_max_log_file_action_stig_single:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_data_retention_num_logs:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Configure auditd Number of Logs Retained</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_data_retention_num_logs" source="ssg"/>
            <oval-def:description>num_logs setting in /etc/audit/auditd.conf is set to at least a certain value</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="num_logs setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_retention_num_logs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_data_retention_space_left:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Configure auditd space_left on Low Disk Space</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_data_retention_space_left" source="ssg"/>
            <oval-def:description>space_left setting in /etc/audit/auditd.conf is set to at least a certain value</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="space_left setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_retention_space_left:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_data_retention_space_left_action:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure auditd space_left Action on Low Disk Space</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_data_retention_space_left_action" source="ssg"/>
            <oval-def:description>space_left_action setting in /etc/audit/auditd.conf is set to a certain action</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="space_left_action setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_retention_space_left_action:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_data_retention_space_left_percentage:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Configure auditd space_left on Low Disk Space</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_data_retention_space_left_percentage" source="ssg"/>
            <oval-def:description>space_left setting in /etc/audit/auditd.conf is set to at least a certain value</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="space_left setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_retention_space_left_percentage:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_name_format:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set type of computer node name logging in audit logs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_name_format" source="ssg"/>
            <oval-def:description>Ensure 'name_format' is configured with value 'hostname|fdq|numeric' in /etc/audit/auditd.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="The respective application or service is configured correctly" operator="OR">
            <oval-def:criterion comment="Check the name_format in /etc/audit/auditd.conf" test_ref="oval:ssg-test_auditd_name_format:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_overflow_action:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Appropriate Action Must be Setup When the Internal Audit Event Queue is Full</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_overflow_action" source="ssg"/>
            <oval-def:description>Ensure 'overflow_action' is configured with value '(syslog|single|halt)' in /etc/audit/auditd.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="The respective application or service is configured correctly" operator="OR">
            <oval-def:criterion comment="Check the overflow_action in /etc/audit/auditd.conf" test_ref="oval:ssg-test_auditd_overflow_action:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_for_ospp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure audit according to OSPP requirements</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_for_ospp" source="ssg"/>
            <oval-def:description>Compare configure audit rules against the recommended pre-configured files.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="check 10-base-config.rules file" test_ref="oval:ssg-test_compare_10-base-config_old:tst:1"/>
            <oval-def:criterion comment="check 11-loginuid.rules file" test_ref="oval:ssg-test_compare_11-loginuid_old:tst:1"/>
            <oval-def:criterion comment="check 30-ospp-v42.rules file" test_ref="oval:ssg-test_compare_30-ospp-v42_old:tst:1"/>
            <oval-def:criterion comment="check 43-module-load.rules file" test_ref="oval:ssg-test_compare_43-module-load_old:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysconfig_networking_bootproto_ifcfg:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Disable DHCP Client in ifcfg</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysconfig_networking_bootproto_ifcfg" source="ssg"/>
            <oval-def:description>DHCP configuration should be static for all
      interfaces.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test for BOOTPROTO=(static|none) across all interfaces" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_sysconfig_networking_bootproto_ifcfg:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-fapolicy_default_deny:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure Fapolicy Module to Employ a Deny-all, Permit-by-exception Policy to Allow the Execution of Authorized Software Programs.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="fapolicy_default_deny" source="ssg"/>
            <oval-def:description>Configure Fapolicy Module to Employ a Deny-all, Permit-by-exception Policy</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="fapolicyd employs a deny-all policy in compiled.rules file" test_ref="oval:ssg-test_fapolicy_default_deny_policy_with_rulesd:tst:1"/>
              <oval-def:criterion comment="fapolicyd employs a deny-all policy fapolicyd.rules file" test_ref="oval:ssg-test_fapolicy_default_deny_policy_without_rulesd:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="fapolicyd is in enforcement mode" test_ref="oval:ssg-test_fapolicy_default_deny_enforcement:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ftp_log_transactions:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable Logging of All FTP Transactions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ftp_log_transactions" source="ssg"/>
            <oval-def:description>To trace malicious activity facilitated by the FTP 
      service, it must be configured to ensure that all commands sent to 
      the FTP server are logged using the verbose vsftpd log format.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="FTP is not being used or the conditions are met" operator="OR">
            <oval-def:extend_definition comment="vsftp package is not installed" definition_ref="oval:ssg-package_vsftpd_installed:def:1" negate="true"/>
            <oval-def:criteria comment="FTP configuration conditions are not set or are met" operator="AND">
              <oval-def:criterion comment="log ftp transactions enable" test_ref="oval:ssg-test_ftp_log_transactions_enable:tst:1"/>
              <oval-def:criterion comment="log ftp transactions format" test_ref="oval:ssg-test_ftp_log_transactions_format:tst:1"/>
              <oval-def:criterion comment="log ftp transactions protocol" test_ref="oval:ssg-test_ftp_log_transactions_protocol:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ftp_present_banner:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Create Warning Banners for All FTP Users</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ftp_present_banner" source="ssg"/>
            <oval-def:description>This setting will cause the system greeting banner to be 
      used for FTP connections as well.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="vsftpd package is not installed" definition_ref="oval:ssg-package_vsftpd_removed:def:1"/>
            <oval-def:criterion comment="Banner for FTP Users" test_ref="oval:ssg-test_ftp_present_banner:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dir_perms_etc_httpd_conf:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Set Permissions on the /etc/httpd/conf/ Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dir_perms_etc_httpd_conf" source="ssg"/>
            <oval-def:description>Directory permissions for /etc/httpd/conf/ should be set to 0750 (or stronger).</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="httpd not present or in use" definition_ref="oval:ssg-package_httpd_removed:def:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_dir_perms_etc_httpd_conf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dir_perms_var_log_httpd:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Set Permissions on the /var/log/httpd/ Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dir_perms_var_log_httpd" source="ssg"/>
            <oval-def:description>Directory permissions for /var/log/httpd should be set to 0700 (or stronger).</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="httpd not present or in use" definition_ref="oval:ssg-package_httpd_removed:def:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_dir_perms_var_log_httpd:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_httpd_server_conf_d_files:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Set Permissions on All Configuration Files Inside /etc/httpd/conf.d/</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_httpd_server_conf_d_files" source="ssg"/>
            <oval-def:description>The /etc/httpd/conf.d/* files should have the appropriate permissions (0640 or stronger).</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="httpd not present or in use" definition_ref="oval:ssg-package_httpd_removed:def:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_file_permissions_httpd_server_conf_d_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_httpd_server_conf_files:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Set Permissions on All Configuration Files Inside /etc/httpd/conf/</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_httpd_server_conf_files" source="ssg"/>
            <oval-def:description>The /etc/httpd/conf/* files should have the appropriate permissions (0640 or stronger).</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="httpd not present or in use" definition_ref="oval:ssg-package_httpd_removed:def:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_file_permissions_httpd_server_conf_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_httpd_server_modules_files:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Set Permissions on All Configuration Files Inside /etc/httpd/conf.modules.d/</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_httpd_server_modules_files" source="ssg"/>
            <oval-def:description>The /etc/httpd/conf.modules.d/* files should have the appropriate permissions (0640 or stronger).</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="httpd not present or in use" definition_ref="oval:ssg-package_httpd_removed:def:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_file_permissions_httpd_server_modules_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dovecot_disable_plaintext_auth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Plaintext Authentication</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dovecot_disable_plaintext_auth" source="ssg"/>
            <oval-def:description>Plaintext authentication of mail clients should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Disable Plaintext Authentication in Dovecot" operator="OR">
            <oval-def:extend_definition comment="dovecot service is disabled" definition_ref="oval:ssg-service_dovecot_disabled:def:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_dovecot_disable_plaintext_auth:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dovecot_enable_ssl:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the SSL flag in /etc/dovecot.conf</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dovecot_enable_ssl" source="ssg"/>
            <oval-def:description>SSL capabilities should be enabled for the mail server.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Enable SSL in Dovecot" operator="OR">
            <oval-def:extend_definition comment="dovecot service is disabled" definition_ref="oval:ssg-service_dovecot_disabled:def:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_dovecot_enable_ssl:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kerberos_disable_no_keytab:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Kerberos by removing host keytab</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kerberos_disable_no_keytab" source="ssg"/>
            <oval-def:description>Check that there is no Kerberos keytab file present in /etc</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Restrict Kerberos operation by removing keytab files" test_ref="oval:ssg-test_kerberos_disable_no_keytab:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-enable_ldap_client:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the LDAP Client For Use in Authconfig</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="enable_ldap_client" source="ssg"/>
            <oval-def:description>Enable LDAP in authconfig.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="LDAP client is enabled" test_ref="oval:ssg-test_enable_ldap_client:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ldap_client_start_tls:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure LDAP Client to Use TLS For All Transactions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ldap_client_start_tls" source="ssg"/>
            <oval-def:description>Require the use of TLS for LDAP clients.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="LDAP is in use" definition_ref="oval:ssg-enable_ldap_client:def:1"/>
            <oval-def:criterion comment="look for ssl start_tls in /etc/nslcd.conf" test_ref="oval:ssg-test_ldap_client_start_tls_ssl:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ldap_client_tls_cacertpath:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure Certificate Directives for LDAP Use of TLS</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ldap_client_tls_cacertpath" source="ssg"/>
            <oval-def:description>Require the use of TLS for LDAP clients.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="LDAP is in use" definition_ref="oval:ssg-enable_ldap_client:def:1"/>
            <oval-def:criterion comment="look for tls_cacertdir in /etc/nslcd.conf" test_ref="oval:ssg-test_ldap_client_tls_cacertdir:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-has_nonlocal_mta:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Mail Transfer Agent is not Listening on any non-loopback Address</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="has_nonlocal_mta" source="ssg"/>
            <oval-def:description>Verify MTA is not listening on any non-loopback address</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mta is not listening on any non-loopbackaddress for port 25" test_ref="oval:ssg-tst_nothing_listening_external_mta_port_25:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-postfix_client_configure_mail_alias:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure System to Forward All Mail For The Root Account</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="postfix_client_configure_mail_alias" source="ssg"/>
            <oval-def:description>Check if root has the correct mail alias.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check if root has the correct mail alias." operator="AND">
            <oval-def:criterion comment="Check if root has the correct mail alias." test_ref="oval:ssg-test_postfix_client_configure_mail_alias:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-postfix_client_configure_mail_alias_postmaster:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure System to Forward All Mail From Postmaster to The Root Account</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="postfix_client_configure_mail_alias_postmaster" source="ssg"/>
            <oval-def:description>Check if postmaster has the correct mail alias.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check if postmaster has the correct mail alias." operator="AND">
            <oval-def:criterion comment="Check if postmaster has the correct mail alias." test_ref="oval:ssg-test_postfix_client_configure_mail_alias_postmaster:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-postfix_network_listening_disabled:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Disable Postfix Network Listening</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="postfix_network_listening_disabled" source="ssg"/>
            <oval-def:description>Postfix network listening should be disabled</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="Postfix installed and configured to start" definition_ref="oval:ssg-service_postfix_enabled:def:1" negate="true"/>
            <oval-def:criterion comment="Check inet_interfaces in /etc/postfix/main.cf" test_ref="oval:ssg-test_postfix_network_listening_disabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-postfix_server_banner:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure SMTP Greeting Banner</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="postfix_server_banner" source="ssg"/>
            <oval-def:description>Protect against unnecessary release of information.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Limit release of information" test_ref="oval:ssg-test_postfix_server_banner:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-postfix_prevent_unrestricted_relay:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Prevent Unrestricted Mail Relaying</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="postfix_prevent_unrestricted_relay" source="ssg"/>
            <oval-def:description>Ensure 'smtpd_client_restrictions' is configured with value 'permit_mynetworks[ \t]*[, \t][ \t]*reject' in /etc/postfix/main.cf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="mail is configured correctly and configuration file exists" operator="AND">
            <oval-def:criteria comment="mail is configured correctly" operator="OR">
              <oval-def:criterion comment="Check the smtpd_client_restrictions in /etc/postfix/main.cf" test_ref="oval:ssg-test_postfix_prevent_unrestricted_relay:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="test if configuration file /etc/postfix/main.cf exists for postfix_prevent_unrestricted_relay" test_ref="oval:ssg-test_postfix_prevent_unrestricted_relay_config_file_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_insecure_locks_exports:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Insecure File Locking is Not Allowed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_insecure_locks_exports" source="ssg"/>
            <oval-def:description>Allowing insecure file locking could allow for sensitive 
      data to be viewed or edited by an unauthorized user.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check for insecure NFS locks in /etc/exports" test_ref="oval:ssg-test_no_insecure_locks_exports:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-use_kerberos_security_all_exports:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Use Kerberos Security on All Exports</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="use_kerberos_security_all_exports" source="ssg"/>
            <oval-def:description>Using Kerberos Security allows to cryptography authenticate a
      valid user to an NFS share.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="Check for Kerberos settings in /etc/exports" test_ref="oval:ssg-test_use_kerberos_security_all_exports:tst:1"/>
            <oval-def:criterion comment="Check for a share in /etc/exports" negate="true" test_ref="oval:ssg-test_non_empty_exports_file:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-chronyd_client_only:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable chrony daemon from acting as server</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="chronyd_client_only" source="ssg"/>
            <oval-def:description>Configure the port setting in /etc/chrony.conf to disable
      server operation.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="check if port is 0 in /etc/chrony.conf" test_ref="oval:ssg-test_chronyd_client_only:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-chronyd_configure_local_socket:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure chrony-wait.service to use Unix socket</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="chronyd_configure_local_socket" source="ssg"/>
            <oval-def:description>Ensure chrony-wait.service is configured to use Unix socket
      instead of network addresses.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="chrony-wait.service is not installed" test_ref="oval:ssg-test_chrony_wait_service_not_installed:tst:1"/>
            <oval-def:criterion comment="check if chrony-wait.service has been fixed (KCS 7064388)" test_ref="oval:ssg-test_chrony_wait_service_fixed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-chronyd_no_chronyc_network:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable network management of chrony daemon</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="chronyd_no_chronyc_network" source="ssg"/>
            <oval-def:description>Configure the cmdport setting in /etc/chrony.conf to disable
      chronyc management connections over network.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="check if cmdport is 0 in /etc/chrony.conf" test_ref="oval:ssg-test_chronyd_no_chronyc_network:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-chronyd_or_ntpd_set_maxpoll:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure Time Service Maxpoll Interval</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="chronyd_or_ntpd_set_maxpoll" source="ssg"/>
            <oval-def:description>Configure the maxpoll setting in /etc/ntp.conf or chrony.conf
      to continuously poll the time source servers.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="check if maxpoll is set in /etc/ntp.conf" test_ref="oval:ssg-test_ntp_set_maxpoll:tst:1"/>
              <oval-def:criterion comment="check if all server entries have maxpoll set in /etc/ntp.conf" test_ref="oval:ssg-test_ntp_all_server_has_maxpoll:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="check if maxpoll is set in /etc/chrony.conf or /etc/chrony.d/" test_ref="oval:ssg-test_chrony_set_maxpoll:tst:1"/>
              <oval-def:criterion comment="check if all server entries have maxpoll set in /etc/chrony.conf or /etc/chrony.d/" test_ref="oval:ssg-test_chrony_all_server_has_maxpoll:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-chronyd_or_ntpd_specify_multiple_servers:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Specify Additional Remote NTP Servers</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="chronyd_or_ntpd_specify_multiple_servers" source="ssg"/>
            <oval-def:description>Multiple remote chronyd or ntpd NTP Servers for time synchronization should be specified (and dependencies are met)</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="multiple chronyd remote servers specified" definition_ref="oval:ssg-chronyd_specify_multiple_servers:def:1"/>
            <oval-def:extend_definition comment="multiple ntpd remote servers specified" definition_ref="oval:ssg-ntpd_specify_multiple_servers:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-chronyd_or_ntpd_specify_remote_server:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Specify a Remote NTP Server</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="chronyd_or_ntpd_specify_remote_server" source="ssg"/>
            <oval-def:description>A remote chronyd or ntpd NTP Server for time synchronization should be specified (and dependencies are met)</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="chronyd remote server specified" definition_ref="oval:ssg-chronyd_specify_remote_server:def:1"/>
            <oval-def:extend_definition comment="ntpd remote server specified" definition_ref="oval:ssg-ntpd_specify_remote_server:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-chronyd_run_as_chrony_user:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure that chronyd is running under chrony user account</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="chronyd_run_as_chrony_user" source="ssg"/>
            <oval-def:description>Ensure 'OPTIONS' is configured with value '["]?.*-u[\s]*chrony.*["]?' in /etc/sysconfig/chronyd</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="The respective application or service is configured correctly and configuration file exists" operator="AND">
            <oval-def:criteria comment="The respective application or service is configured correctly" operator="OR">
              <oval-def:criterion comment="Check the OPTIONS in /etc/sysconfig/chronyd" test_ref="oval:ssg-test_chronyd_run_as_chrony_user:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="test if configuration file /etc/sysconfig/chronyd exists for chronyd_run_as_chrony_user" test_ref="oval:ssg-test_chronyd_run_as_chrony_user_config_file_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-chronyd_server_directive:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Chrony is only configured with the server directive</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="chronyd_server_directive" source="ssg"/>
            <oval-def:description>Ensure Chrony has time sources configured with server directive</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="chrony.conf only has server directive" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_chronyd_server_directive_with_server:tst:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_chronyd_server_directive_no_pool:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-chronyd_specify_remote_server:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>A remote time server for Chrony is configured</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="chronyd_specify_remote_server" source="ssg"/>
            <oval-def:description>A remote NTP Server for time synchronization should be
      specified (and dependencies are met)</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="chrony.conf conditions are met" operator="OR">
            <oval-def:criterion comment="server/pool in main chrony.conf" test_ref="oval:ssg-test_chronyd_server_in_main_conf:tst:1"/>
            <oval-def:criterion comment="server/pool in sourcedir .sources files" test_ref="oval:ssg-test_chronyd_server_in_sourcedir_files:tst:1"/>
            <oval-def:criterion comment="server/pool in confdir .conf files" test_ref="oval:ssg-test_chronyd_server_in_confdir_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_etc_chrony_keys:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/chrony.keys File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_etc_chrony_keys" source="ssg"/>
            <oval-def:description>/etc/chrony.keys should be owned by chrony group</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria negate="true" operator="AND">
                <oval-def:criterion comment="The /etc/nsswitch.conf uses nss-altfiles" test_ref="oval:ssg-test_file_groupowner_etc_chrony_keys_nsswitch_uses_altfiles:tst:1"/>
                <oval-def:criterion comment="Check if nss-altfiles package is installed" test_ref="oval:ssg-test_file_groupowner_etc_chrony_keys_package_nss-altfiles_installed:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="Check group ownership of /etc/chrony.keys" test_ref="oval:ssg-test_file_groupowner_etc_chrony_keys:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="AND">
                <oval-def:criterion comment="The /etc/nsswitch.conf uses nss-altfiles" test_ref="oval:ssg-test_file_groupowner_etc_chrony_keys_nsswitch_uses_altfiles:tst:1"/>
                <oval-def:criterion comment="Check if nss-altfiles package is installed" test_ref="oval:ssg-test_file_groupowner_etc_chrony_keys_package_nss-altfiles_installed:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="Check group ownership of /etc/chrony.keys" test_ref="oval:ssg-test_file_groupowner_etc_chrony_keys_with_usrlib:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ntpd_specify_multiple_servers:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Specify Additional Remote NTP Servers</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ntpd_specify_multiple_servers" source="ssg"/>
            <oval-def:description>Multiple ntpd NTP Servers for time synchronization should be specified.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="ntp.conf conditions are met" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_ntpd_multiple_servers:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ntpd_specify_remote_server:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Specify a Remote NTP Server</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ntpd_specify_remote_server" source="ssg"/>
            <oval-def:description>A remote ntpd NTP Server for time synchronization should be
      specified (and dependencies are met)</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="ntp.conf conditions are met" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_ntp_remote_server:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_chronyd_or_ntpd_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the NTP Daemon</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_chronyd_or_ntpd_enabled" source="ssg"/>
            <oval-def:description>At least one of the chronyd or ntpd services should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="chronyd or ntpd service enabled" operator="OR">
            <oval-def:extend_definition comment="service chronyd enabled" definition_ref="oval:ssg-service_chronyd_enabled:def:1"/>
            <oval-def:extend_definition comment="service ntpd enabled" definition_ref="oval:ssg-service_ntpd_enabled:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_nis_in_nsswitch:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Name Service Switch does not use NIS</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_nis_in_nsswitch" source="ssg"/>
            <oval-def:description>nis is not configured as a database in /etc/nsswitch.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="nis is not configured as a database in /etc/nsswitch.conf" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_no_nis_in_nsswitch:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_host_based_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Remove Host-Based Authentication Files</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_host_based_files" source="ssg"/>
            <oval-def:description>There should not be any shosts.equiv files on the system.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_no_shosts_equiv:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_rsh_trust_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Remove Rsh Trust Files</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_rsh_trust_files" source="ssg"/>
            <oval-def:description>There should not be any .rhosts or hosts.equiv files on the system.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion negate="true" test_ref="oval:ssg-test_no_rsh_trust_files_root:tst:1"/>
            <oval-def:criterion negate="true" test_ref="oval:ssg-test_no_rsh_trust_files_home:tst:1"/>
            <oval-def:criterion negate="true" test_ref="oval:ssg-test_no_rsh_trust_files_etc:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_user_host_based_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Remove User Host-Based Authentication Files</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_user_host_based_files" source="ssg"/>
            <oval-def:description>There should not be any .shosts files on the system.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_no_shosts:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-tftp_uses_secure_mode_systemd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure tftp systemd Service Uses Secure Mode</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="tftp_uses_secure_mode_systemd" source="ssg"/>
            <oval-def:description>The TFTP daemon should use secure mode.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package tftp-server removed or tftp.service configured correctly" operator="OR">
            <oval-def:extend_definition comment="rpm package tftp-server removed" definition_ref="oval:ssg-package_tftp-server_removed:def:1"/>
            <oval-def:criteria comment="Validate drop-ins if they exist, else validate original file" operator="OR">
              <oval-def:criterion comment="Drop-in secure mode" test_ref="oval:ssg-file_tftp_service_dropin_exists:tst:1"/>
              <oval-def:criteria comment="No drop-ins, validate original file" operator="AND">
                <oval-def:criterion comment="No drop-in files exist" test_ref="oval:ssg-file_tftp_service_dropin_notexists:tst:1"/>
                <oval-def:criterion comment="Original secure mode" test_ref="oval:ssg-test_tftp_uses_secure_mode_systemd_original:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-tftpd_uses_secure_mode:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure tftp Daemon Uses Secure Mode</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="tftpd_uses_secure_mode" source="ssg"/>
            <oval-def:description>The TFTP daemon should use secure mode.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package tftp-server removed or /etc/xinetd.d/tftp configured correctly" operator="OR">
            <oval-def:extend_definition comment="rpm package tftp-server removed" definition_ref="oval:ssg-package_tftp-server_removed:def:1"/>
            <oval-def:criterion comment="tftpd secure mode" test_ref="oval:ssg-test_tftpd_uses_secure_mode:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-cups_disable_browsing:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Printer Browsing Entirely if Possible</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cups_disable_browsing" source="ssg"/>
            <oval-def:description>The CUPS print service can be configured to broadcast a list
      of available printers to the network. Other machines on the network, also
      running the CUPS print service, can be configured to listen to these
      broadcasts and add and configure these printers for immediate use. By
      disabling this browsing capability, the machine will no longer generate
      or receive such broadcasts.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Ensure remote printer browsing is off" test_ref="oval:ssg-test_cups_disable_browsing_browsing_off:tst:1"/>
            <oval-def:criterion comment="Ensure no incoming printer information packets are allowed" test_ref="oval:ssg-test_cups_disable_browsing_browseallow:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-cups_disable_printserver:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Print Server Capabilities</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cups_disable_printserver" source="ssg"/>
            <oval-def:description>By default, locally configured printers will not be shared
      over the network, but if this functionality has somehow been enabled,
      these recommendations will disable it again. Be sure to disable outgoing
      printer list broadcasts, or remote users will still be able to see the
      locally configured printers, even if they cannot actually print to them.
      To limit print serving to a particular set of users, use the Policy
      directive.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Don't use port directive" test_ref="oval:ssg-test_cups_disable_printserver_disable_port:tst:1"/>
            <oval-def:criterion comment="Do use the listen directive" test_ref="oval:ssg-test_cups_disable_printserver_use_listen:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_smb_client_signing:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Require Client SMB Packet Signing, if using mount.cifs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_smb_client_signing" source="ssg"/>
            <oval-def:description>Require packet signing of clients who mount
      Samba shares using the mount.cifs program (e.g., those who
      specify shares in /etc/fstab). To do so, ensure that signing
      options (either sec=krb5i or sec=ntlmv2i) are
      used.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="samba-common installed" definition_ref="oval:ssg-package_samba-common_installed:def:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:criterion comment="check for no cifs in /etc/fstab" test_ref="oval:ssg-test_20340111:tst:1"/>
                <oval-def:criterion comment="check for sec=krb5i or sec=ntlmv2i in /etc/fstab" test_ref="oval:ssg-test_20340112:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria operator="OR">
                <oval-def:criterion comment="check for no cifs in /etc/mtab" test_ref="oval:ssg-test_20340113:tst:1"/>
                <oval-def:criterion comment="check for sec=krb5i or sec=ntlmv2i in /etc/mtab" test_ref="oval:ssg-test_20340114:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-require_smb_client_signing:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Require Client SMB Packet Signing, if using smbclient</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="require_smb_client_signing" source="ssg"/>
            <oval-def:description>Require samba clients which use smb.conf, such as smbclient,
      to use packet signing. A Samba client should only communicate with
      servers who can support SMB packet signing.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="package samba-common is not installed" definition_ref="oval:ssg-package_samba-common_removed:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="samba-common installed" definition_ref="oval:ssg-package_samba-common_installed:def:1"/>
              <oval-def:criterion comment="check for client signing = mandatory in /etc/samba/smb.conf" test_ref="oval:ssg-test_require_smb_client_signing:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-snmpd_not_default_password:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure Default SNMP Password Is Not Used</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="snmpd_not_default_password" source="ssg"/>
            <oval-def:description>SNMP default communities must be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="SNMP communities" test_ref="oval:ssg-test_snmp_default_communities:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-snmpd_use_newer_protocol:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Configure SNMP Service to Use Only SNMPv3 or Newer</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="snmpd_use_newer_protocol" source="ssg"/>
            <oval-def:description>SNMP version 1 and 2c must not be enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="SNMP installed" definition_ref="oval:ssg-package_net-snmp_removed:def:1"/>
            <oval-def:criterion comment="SNMP protocols" test_ref="oval:ssg-test_snmp_versions:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_sshd_private_key:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on SSH Server Private *_key Key Files</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_sshd_private_key" source="ssg"/>
            <oval-def:description>The system sshd key is owned by root:root and has the 0600 permission, or by a root:ssh_keys with the 0640 permission</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="No keys that have unsafe ownership/permissions combination exist" test_ref="oval:ssg-test_no_offending_keys:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firewalld_sshd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Remove SSH Server firewalld Firewall exception (Unusual)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="firewalld_sshd_disabled" source="ssg"/>
            <oval-def:description>If inbound SSH access is not needed, the firewall should disallow or reject access to
      the SSH port (22).</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="ssh service is not enabled in services" test_ref="oval:ssg-test_firewalld_service_sshd:tst:1"/>
            <oval-def:criterion comment="ssh port is not enabled in services" test_ref="oval:ssg-test_firewalld_service_sshd_port:tst:1"/>
            <oval-def:criterion comment="ssh service is not enabled in zones" test_ref="oval:ssg-test_firewalld_zone_sshd:tst:1"/>
            <oval-def:criterion comment="ssh port is not enabled in zones" test_ref="oval:ssg-test_firewalld_zone_sshd_port:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ssh_client_rekey_limit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure session renegotiation for SSH client</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ssh_client_rekey_limit" source="ssg"/>
            <oval-def:description>Ensure 'RekeyLimit' is configured with the correct value in /etc/ssh/ssh_config and /etc/ssh/ssh_config.d/*.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="RekeyLimit is correctly configured for ssh client" operator="AND">
            <oval-def:criterion comment="check that RekeyLimit is not configured in /etc/ssh/ssh_config" negate="true" test_ref="oval:ssg-test_ssh_client_rekey_limit_main_config:tst:1"/>
            <oval-def:criterion comment="check correct RekeyLimit configuration in /etc/ssh/ssh_config.d/*.conf" test_ref="oval:ssg-test_ssh_client_rekey_limit_include_configs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ssh_client_use_strong_rng_csh:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>SSH client uses strong entropy to seed (for CSH like shells)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ssh_client_use_strong_rng_csh" source="ssg"/>
            <oval-def:description>Ensure the SSH_USE_STRONG_RNG environment variable is exported in /etc/profile.d/cc-ssh-strong-rng.csh and is not overridden in /etc/profile</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="ssh client is configured to use strong entropy" operator="AND">
            <oval-def:criterion comment="check configuration in /etc/profile.d/cc-ssh-strong-rng.csh" test_ref="oval:ssg-test_ssh_client_strong_rng_csh:tst:1"/>
            <oval-def:criterion comment="check that the configuration is not overridden in /etc/profile" test_ref="oval:ssg-test_ssh_client_strong_rng_csh_not_overridden:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ssh_client_use_strong_rng_sh:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>SSH client uses strong entropy to seed (Bash-like shells)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ssh_client_use_strong_rng_sh" source="ssg"/>
            <oval-def:description>Ensure the SSH_USE_STRONG_RNG environment variable is exported in /etc/profile.d/cc-ssh-strong-rng.sh and is not overridden in /etc/profile</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="ssh client is configured to use strong entropy" operator="AND">
            <oval-def:criterion comment="check configuration in /etc/profile.d/cc-ssh-strong-rng.sh" test_ref="oval:ssg-test_ssh_client_strong_rng_sh:tst:1"/>
            <oval-def:criterion comment="check that the configuration is not overridden in /etc/profile" test_ref="oval:ssg-test_ssh_client_strong_rng_sh_not_overridden:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firewalld_sshd_port_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable SSH Server firewalld Firewall Exception</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="firewalld_sshd_port_enabled" source="ssg"/>
            <oval-def:description>If inbound SSH access is needed, the firewall should allow access to
        the SSH service.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criteria operator="AND">
                <oval-def:criterion comment="Ensure default file zones have SSH service defined" test_ref="oval:ssg-test_firewalld_sshd_port_enabled_zone_ssh_enabled_usr:tst:1"/>
                <oval-def:criterion comment="Ensure default files from active zones were not overridden" test_ref="oval:ssg-test_firewalld_sshd_port_enabled_usr_zones_not_overridden:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="Ensure custom files from active zones have SSH service defined" test_ref="oval:ssg-test_firewalld_sshd_port_enabled_zone_ssh_enabled_etc:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Ensure default file for SSH service is correct" test_ref="oval:ssg-test_firewalld_sshd_port_enabled_ssh_service_usr:tst:1"/>
              <oval-def:criterion comment="Ensure the modified firewalld SSH port is correct" test_ref="oval:ssg-test_firewalld_sshd_port_enabled_ssh_service_etc:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_limit_user_access:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Limit Users' SSH Access</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_limit_user_access" source="ssg"/>
            <oval-def:description>One of the following parameters of the sshd configuration file is set:  AllowUsers, DenyUsers, AllowGroups, DenyGroups.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion test_ref="oval:ssg-test_allow_user_is_configured:tst:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_allow_group_is_configured:tst:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_deny_user_is_configured:tst:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_deny_group_is_configured:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_rekey_limit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Force frequent session key renegotiation</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_rekey_limit" source="ssg"/>
            <oval-def:description>Ensure RekeyLimit is configured with the appropriate value in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="OR">
                <oval-def:criterion comment="Check the RekeyLimit in /etc/ssh/sshd_config" test_ref="oval:ssg-test_sshd_rekey_limit:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_set_idle_timeout:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set SSH Client Alive Interval</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_set_idle_timeout" source="ssg"/>
            <oval-def:description>The SSH idle timeout interval should be set to an
      appropriate value.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="SSH is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="ClientAliveInterval is configured correctly" operator="AND">
                <oval-def:criterion comment="Check ClientAliveInterval in /etc/ssh/sshd_config" test_ref="oval:ssg-test_sshd_idle_timeout:tst:1"/>
                <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_clientaliveinterval_present:tst:1"/>
              </oval-def:criteria>
              <oval-def:extend_definition comment="The SSH ClientAliveCountMax is set to zero" definition_ref="oval:ssg-sshd_set_keepalive:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_set_login_grace_time:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure SSH LoginGraceTime is configured</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_set_login_grace_time" source="ssg"/>
            <oval-def:description>The SSH number seconds for login grace time should be set to an
      appropriate value.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="SSH is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criterion comment="Check LoginGraceTime in /etc/ssh/sshd_config" test_ref="oval:ssg-test_sshd_login_grace_time:tst:1"/>
              <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_LoginGraceTime_present_sshd_set_login_grace_time:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_set_max_auth_tries:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set SSH authentication attempt limit</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_set_max_auth_tries" source="ssg"/>
            <oval-def:description>The SSH MaxAuthTries should be set to an
      appropriate value.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="SSH is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criterion comment="Check MaxAuthTries in /etc/ssh/sshd_config" test_ref="oval:ssg-test_sshd_max_auth_tries:tst:1"/>
              <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_MaxAuthTries_present_sshd_set_max_auth_tries:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_set_max_sessions:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set SSH MaxSessions limit</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_set_max_sessions" source="ssg"/>
            <oval-def:description>The SSH number of max sessions should be set to an
      appropriate value.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="SSH is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criterion comment="Check MaxSessions in /etc/ssh/sshd_config" test_ref="oval:ssg-test_sshd_max_sessions:tst:1"/>
              <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_MaxSessions_present_sshd_set_max_sessions:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_set_maxstartups:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure SSH MaxStartups is configured</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_set_maxstartups" source="ssg"/>
            <oval-def:description>Ensure 'MaxStartups' is properly configured in SSH configuration files.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd MaxStartups parameter is properly configured if sshd is installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server is removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="SSH MaxStartups start parameter is less than or equal to 10" test_ref="oval:ssg-tst_maxstartups_start_parameter:tst:1"/>
              <oval-def:criterion comment="SSH MaxStartups rate parameter is greater than or equal to 30" test_ref="oval:ssg-tst_maxstartups_rate_parameter:tst:1"/>
              <oval-def:criterion comment="SSH MaxStartups full parameter is less than or equal to 100" test_ref="oval:ssg-tst_maxstartups_full_parameter:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_use_approved_ciphers:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Use Only FIPS 140-2 Validated Ciphers</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_use_approved_ciphers" source="ssg"/>
            <oval-def:description>Limit the ciphers to those which are FIPS-approved.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="SSH is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criterion comment="Check the Ciphers list in /etc/ssh/sshd_config" test_ref="oval:ssg-test_sshd_use_approved_ciphers:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_use_approved_kex_ordered_stig:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Use Only FIPS 140-2 Validated Key Exchange Algorithms</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_use_approved_kex_ordered_stig" source="ssg"/>
            <oval-def:description>Limit the Key Exchange (Kex) algorithms to those which are FIPS-approved.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="SSH is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criterion comment="Check Kex in " test_ref="oval:ssg-test_sshd_use_approved_kex_ordered_stig:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_use_approved_macs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Use Only FIPS 140-2 Validated MACs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_use_approved_macs" source="ssg"/>
            <oval-def:description>Limit the Message Authentication Codes (MACs) to those which are FIPS-approved.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="SSH is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criterion comment="Check MACs in /etc/ssh/sshd_config" test_ref="oval:ssg-test_sshd_use_approved_macs:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_use_strong_kex:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Use Only Strong Key Exchange algorithms</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_use_strong_kex" source="ssg"/>
            <oval-def:description>Limit the Key Exchange Algorithms to those which are FIPS-approved.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="SSH is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criterion comment="Check KexAlgorithms in /etc/ssh/sshd_config" test_ref="oval:ssg-test_sshd_use_strong_kex:tst:1"/>
              <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_sshd_kexalgorithms_exists:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_use_strong_macs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Use Only Strong MACs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_use_strong_macs" source="ssg"/>
            <oval-def:description>Ensure only strong MAC algorithms are used</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria comment="SSH is configured correctly or is not installed" operator="OR">
              <oval-def:criteria comment="sshd is not installed" operator="AND">
                <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
                <oval-def:extend_definition comment="package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="sshd is installed and configured" operator="AND">
                <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
                <oval-def:extend_definition comment="package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
                <oval-def:criterion comment="Check MACs in /etc/ssh/sshd_config" test_ref="oval:ssg-test_sshd_use_strong_macs:tst:1"/>
                <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_sshd_macs_exists:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sssd_certificate_verification:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Certificate status checking in SSSD</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sssd_certificate_verification" source="ssg"/>
            <oval-def:description>SSSD should be configured with the correct ocsp_dgst
            digest function</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="check value of certificate_verification in sssd configuration" test_ref="oval:ssg-test_sssd_certificate_verification:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sssd_enable_pam_services:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure PAM in SSSD Services</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sssd_enable_pam_services" source="ssg"/>
            <oval-def:description>SSSD should be configured to run SSSD PAM services.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="check if pam is configured in the services setting of the sssd section" test_ref="oval:ssg-test_sssd_enable_pam_services:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sssd_enable_smartcards:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable Smartcards in SSSD</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sssd_enable_smartcards" source="ssg"/>
            <oval-def:description>SSSD should be configured to authenticate access to the system
    using smart cards.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check pam_cert_auth in /etc/sssd/sssd.conf" test_ref="oval:ssg-test_sssd_enable_smartcards:tst:1"/>
            <oval-def:criterion comment="Check try_cert_auth or require_cert_auth in /etc/pam.d/system-auth" test_ref="oval:ssg-test_sssd_enable_smartcards_cert_auth_system_auth:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sssd_memcache_timeout:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure SSSD's Memory Cache to Expire</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sssd_memcache_timeout" source="ssg"/>
            <oval-def:description>SSSD's memory cache should be configured to set to expire records after 1 day.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="Check memcache_timeout in /etc/sssd/sssd.conf" test_ref="oval:ssg-test_sssd_memcache_timeout:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sssd_offline_cred_expiration:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure SSSD to Expire Offline Credentials</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sssd_offline_cred_expiration" source="ssg"/>
            <oval-def:description>SSSD should be configured to expire offline credentials after 1 day.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="Check offline_credentials_expiration in /etc/sssd/sssd.conf" test_ref="oval:ssg-test_sssd_offline_cred_expiration:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sssd_run_as_sssd_user:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure SSSD to run as user sssd</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sssd_run_as_sssd_user" source="ssg"/>
            <oval-def:description>SSSD processes should be configured to run as user sssd, not root.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check user setting in SSSD configuration" test_ref="oval:ssg-test_sssd_run_as_sssd_user:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sssd_ssh_known_hosts_timeout:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure SSSD to Expire SSH Known Hosts</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sssd_ssh_known_hosts_timeout" source="ssg"/>
            <oval-def:description>SSSD should be configured to expire keys from known SSH hosts after 1 day.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="Check ssh_known_hosts_timeout in /etc/sssd/sssd.conf" test_ref="oval:ssg-test_sssd_ssh_known_hosts_timeout:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sssd_ldap_configure_tls_ca_dir:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure SSSD LDAP Backend Client CA Certificate Location</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sssd_ldap_configure_tls_ca_dir" source="ssg"/>
            <oval-def:description>Configure SSSD to implement cryptography to protect the integrity of LDAP remote access sessions.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_sssd_ldap_tls_ca_dir:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sssd_ldap_configure_tls_reqcert:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure SSSD LDAP Backend Client to Demand a Valid Certificate from the Server</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sssd_ldap_configure_tls_reqcert" source="ssg"/>
            <oval-def:description>Configure SSSD to request a valid certificate from the server to protect LDAP remote access sessions.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_sssd_ldap_tls_reqcert:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sssd_ldap_start_tls:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure SSSD LDAP Backend to Use TLS For All Transactions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sssd_ldap_start_tls" source="ssg"/>
            <oval-def:description>LDAP should be used for authentication and use STARTTLS</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="LDAP uses STARTTLS set within /etc/sssd/sssd.conf" test_ref="oval:ssg-test_use_starttls:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-usbguard_allow_hid:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Authorize Human Interface Devices in USBGuard daemon</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="usbguard_allow_hid" source="ssg"/>
            <oval-def:description>Check that /etc/usbguard/rules.conf exists and that it contains at least one non white space character.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check that /etc/usbguard/rules.conf contains at least one non whitespace character." operator="AND">
            <oval-def:extend_definition comment="Check that /etc/usbguard/rules.conf contains at least one non whitespace character." definition_ref="oval:ssg-usbguard_rules_not_empty_not_missing:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-usbguard_allow_hid_and_hub:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Authorize Human Interface Devices and USB hubs in USBGuard daemon</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="usbguard_allow_hid_and_hub" source="ssg"/>
            <oval-def:description>Check that /etc/usbguard/rules.conf contains at least one non whitespace character and exists.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check that /etc/usbguard/rules.conf contains at least one non whitespace character." operator="AND">
            <oval-def:extend_definition comment="Check that /etc/usbguard/rules.conf contains at least one non whitespace character." definition_ref="oval:ssg-usbguard_rules_not_empty_not_missing:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-usbguard_allow_hub:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Authorize USB hubs in USBGuard daemon</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="usbguard_allow_hub" source="ssg"/>
            <oval-def:description>Check that /etc/usbguard/rules.conf contains at least one non whitespace character and exists.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check that /etc/usbguard/rules.conf contains at least one non whitespace character." operator="AND">
            <oval-def:extend_definition comment="Check that /etc/usbguard/rules.conf contains at least one non whitespace character." definition_ref="oval:ssg-usbguard_rules_not_empty_not_missing:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-usbguard_generate_policy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Generate USBGuard Policy</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="usbguard_generate_policy" source="ssg"/>
            <oval-def:description>Check that /etc/usbguard/rules.conf contains at least one non whitespace character and exists.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check that /etc/usbguard/rules.conf contains at least one non whitespace character." operator="AND">
            <oval-def:extend_definition comment="Check that /etc/usbguard/rules.conf contains at least one non whitespace character." definition_ref="oval:ssg-usbguard_rules_not_empty_not_missing:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-xwindows_remove_packages:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable graphical user interface</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="xwindows_remove_packages" source="ssg"/>
            <oval-def:description>Ensure that the default runlevel target is set to multi-user.target.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Make sure all xwindows packages are removed" operator="AND">
            <oval-def:criterion comment="package xorg-x11-server-Xorg is removed" test_ref="oval:ssg-test_package_xorg-x11-server-Xorg_removed:tst:1"/>
            <oval-def:criterion comment="package xorg-x11-server-common is removed" test_ref="oval:ssg-test_package_xorg-x11-server-common_removed:tst:1"/>
            <oval-def:criterion comment="package xorg-x11-server-utils is removed" test_ref="oval:ssg-test_package_xorg-x11-server-utils_removed:tst:1"/>
            <oval-def:criterion comment="package xorg-x11-server-Xwayland is removed" test_ref="oval:ssg-test_package_xorg-x11-server-Xwayland_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-xwindows_runlevel_target:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Graphical Environment Startup By Setting Default Target</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="xwindows_runlevel_target" source="ssg"/>
            <oval-def:description>Ensure that the default runlevel target is set to multi-user.target.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="default.target systemd softlink exists" test_ref="oval:ssg-test_disable_xwindows_runlevel_target:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-enable_authselect:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable authselect</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="enable_authselect" source="ssg"/>
            <oval-def:description>Check that authselect is enabled</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check that authselect symlinks are set up properly." operator="AND">
            <oval-def:criterion comment="The 'fingerprint-auth' PAM config is a symlink to its authselect counterpart" test_ref="oval:ssg-test_pam_fingerprint_symlinked_to_authselect:tst:1"/>
            <oval-def:criterion comment="The 'password-auth' PAM config is a symlink to its authselect counterpart" test_ref="oval:ssg-test_pam_password_symlinked_to_authselect:tst:1"/>
            <oval-def:criterion comment="The 'postlogin' PAM config is a symlink to its authselect counterpart" test_ref="oval:ssg-test_pam_postlogin_symlinked_to_authselect:tst:1"/>
            <oval-def:criterion comment="The 'smartcard-auth' PAM config is a symlink to its authselect counterpart" test_ref="oval:ssg-test_pam_smartcard_symlinked_to_authselect:tst:1"/>
            <oval-def:criterion comment="The 'system-auth' PAM config is a symlink to its authselect counterpart" test_ref="oval:ssg-test_pam_system_symlinked_to_authselect:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-banner_etc_issue:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Modify the System Login Banner</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="banner_etc_issue" source="ssg"/>
            <oval-def:description>The system login banner text should be set correctly.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="/etc/issue is set appropriately" test_ref="oval:ssg-test_banner_etc_issue:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-banner_etc_issue_net:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Modify the System Login Banner for Remote Connections</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="banner_etc_issue_net" source="ssg"/>
            <oval-def:description>The system login banner text should be set correctly.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="/etc/issue.net is set appropriately" test_ref="oval:ssg-test_banner_etc_issue_net:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-banner_etc_motd:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Modify the System Message of the Day Banner</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="banner_etc_motd" source="ssg"/>
            <oval-def:description>The system motd banner text should be set correctly.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="/etc/motd is absent" negate="true" test_ref="oval:ssg-test_banner_etc_motd_exists:tst:1"/>
            <oval-def:criterion comment="/etc/motd is set appropriately" test_ref="oval:ssg-test_banner_etc_motd:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_banner_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable GNOME3 Login Warning Banner</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_banner_enabled" source="ssg"/>
            <oval-def:description>Enable the GNOME3 Login warning banner.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="Enable GUI banner and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="Enable GUI banner" test_ref="oval:ssg-test_banner_gui_enabled:tst:1"/>
              <oval-def:criterion comment="Prevent user from disabling banner" test_ref="oval:ssg-test_prevent_user_banner_gui_enabled_change:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_login_banner_text:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set the GNOME3 Login Warning Banner Text</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_login_banner_text" source="ssg"/>
            <oval-def:description>Enable the GUI warning banner.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="Enable GUI banner and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="Prevent user from changing banner" test_ref="oval:ssg-test_prevent_user_banner_change:tst:1"/>
              <oval-def:criterion comment="Login banner is correctly set" test_ref="oval:ssg-test_gdm_login_banner_text_setting:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_modules_in_authselect_profile:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Active Authselect Profile Includes PAM Modules</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_modules_in_authselect_profile" source="ssg"/>
            <oval-def:description>Ensure active authselect profile includes pam modules</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check that authselect is enabled and profile includes required modules" operator="AND">
            <oval-def:extend_definition comment="authselect must be enabled" definition_ref="oval:ssg-enable_authselect:def:1"/>
            <oval-def:criteria comment="All required PAM modules must be present in system-auth" operator="AND">
              <oval-def:criterion comment="pam_pwquality.so exists in system-auth" test_ref="oval:ssg-test_accounts_password_pam_modules_in_authselect_profile_pam_pwquality_system_auth:tst:1"/>
              <oval-def:criterion comment="pam_pwhistory.so exists in system-auth" test_ref="oval:ssg-test_accounts_password_pam_modules_in_authselect_profile_pam_pwhistory_system_auth:tst:1"/>
              <oval-def:criterion comment="pam_faillock.so exists in system-auth" test_ref="oval:ssg-test_accounts_password_pam_modules_in_authselect_profile_pam_faillock_system_auth:tst:1"/>
              <oval-def:criterion comment="pam_unix.so exists in system-auth" test_ref="oval:ssg-test_accounts_password_pam_modules_in_authselect_profile_pam_unix_system_auth:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="All required PAM modules must be present in password-auth" operator="AND">
              <oval-def:criterion comment="pam_pwquality.so exists in password-auth" test_ref="oval:ssg-test_accounts_password_pam_modules_in_authselect_profile_pam_pwquality_password_auth:tst:1"/>
              <oval-def:criterion comment="pam_pwhistory.so exists in password-auth" test_ref="oval:ssg-test_accounts_password_pam_modules_in_authselect_profile_pam_pwhistory_password_auth:tst:1"/>
              <oval-def:criterion comment="pam_faillock.so exists in password-auth" test_ref="oval:ssg-test_accounts_password_pam_modules_in_authselect_profile_pam_faillock_password_auth:tst:1"/>
              <oval-def:criterion comment="pam_unix.so exists in password-auth" test_ref="oval:ssg-test_accounts_password_pam_modules_in_authselect_profile_pam_unix_password_auth:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_unix_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify pam_unix module is activated</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_unix_enabled" source="ssg"/>
            <oval-def:description>Ensure pam_unix.so is properly configured in PAM configuration files</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check if pam_unix.so is properly defined in all PAM files" operator="AND">
            <oval-def:criterion comment="pam_unix is configured in auth section in password-auth" test_ref="oval:ssg-test_pam_unix_password-auth_auth:tst:1"/>
            <oval-def:criterion comment="pam_unix is configured in account section in password-auth" test_ref="oval:ssg-test_pam_unix_password-auth_account:tst:1"/>
            <oval-def:criterion comment="pam_unix is configured in password section in password-auth" test_ref="oval:ssg-test_pam_unix_password-auth_password:tst:1"/>
            <oval-def:criterion comment="pam_unix is configured in session section in password-auth" test_ref="oval:ssg-test_pam_unix_password-auth_session:tst:1"/>
            <oval-def:criterion comment="pam_unix is configured in auth section in system-auth" test_ref="oval:ssg-test_pam_unix_system-auth_auth:tst:1"/>
            <oval-def:criterion comment="pam_unix is configured in account section in system-auth" test_ref="oval:ssg-test_pam_unix_system-auth_account:tst:1"/>
            <oval-def:criterion comment="pam_unix is configured in password section in system-auth" test_ref="oval:ssg-test_pam_unix_system-auth_password:tst:1"/>
            <oval-def:criterion comment="pam_unix is configured in session section in system-auth" test_ref="oval:ssg-test_pam_unix_system-auth_session:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-disallow_bypass_password_sudo:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disallow Configuration to Bypass Password Requirements for Privilege Escalation</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="disallow_bypass_password_sudo" source="ssg"/>
            <oval-def:description>Disallow Configuration to Bypass Password Requirements for Privilege Escalation.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check absence of conf pam_succeed_if in /etc/pam.d/sudo" test_ref="oval:ssg-test_disallow_bypass_password_sudo:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-display_login_attempts:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure PAM Displays Last Logon/Access Notification</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="display_login_attempts" source="ssg"/>
            <oval-def:description>Configure the system to notify users of last login/access using pam_lastlog.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="conditions for pam_lastlog are satisfied" test_ref="oval:ssg-test_display_login_attempts:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-enable_pam_namespace:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set Up a Private Namespace in PAM Configuration</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="enable_pam_namespace" source="ssg"/>
            <oval-def:description>Check presence of pam_namespace.so module in the /etc/pam.d/login file</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check that /etc/pam.d/login contains a line with certain text" operator="AND">
            <oval-def:criterion comment="Check that /etc/pam.d/login contains a line with certain text" test_ref="oval:ssg-test_enable_pam_namespace:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-account_password_pam_faillock_password_auth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="account_password_pam_faillock_password_auth" source="ssg"/>
            <oval-def:description>Configure the use of the pam_faillock.so module in the /etc/pam.d/password-auth file.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="pam_unix.so appears only once in auth section of password-auth" test_ref="oval:ssg-test_pam_faillock_password_auth_pam_unix_auth:tst:1"/>
            <oval-def:criterion comment="pam_faillock.so is defined in auth section of password-auth" test_ref="oval:ssg-test_pam_faillock_password_auth_pam_faillock_auth:tst:1"/>
            <oval-def:criterion comment="pam_faillock.so is defined in account section of password-auth" test_ref="oval:ssg-test_pam_faillock_password_auth_pam_faillock_account:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-account_password_pam_faillock_system_auth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="account_password_pam_faillock_system_auth" source="ssg"/>
            <oval-def:description>Configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="pam_unix.so appears only once in auth section of system-auth" test_ref="oval:ssg-test_pam_faillock_system_auth_pam_unix_auth:tst:1"/>
            <oval-def:criterion comment="pam_faillock.so is defined in auth section of system-auth" test_ref="oval:ssg-test_pam_faillock_system_auth_pam_faillock_auth:tst:1"/>
            <oval-def:criterion comment="pam_faillock.so is defined in account section of system-auth" test_ref="oval:ssg-test_pam_faillock_system_auth_pam_faillock_account:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-account_password_selinux_faillock_dir:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>An SELinux Context must be configured for the pam_faillock.so records directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="account_password_selinux_faillock_dir" source="ssg"/>
            <oval-def:description>An SELinux Context must be configured for the Faillock directory.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="The faillock directories should have faillog_t as context" test_ref="oval:ssg-test_account_password_selinux_faillock_dir:tst:1"/>
            <oval-def:criterion comment="There is no faillock directory set in pam_faillock.so settings" test_ref="oval:ssg-test_account_password_selinux_faillock_dir_not_set:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-account_passwords_pam_faillock_audit:def:1" version="5">
          <oval-def:metadata>
            <oval-def:title>Account Lockouts Must Be Logged</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="account_passwords_pam_faillock_audit" source="ssg"/>
            <oval-def:description>Account Lockouts Must Be Logged</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check expected value for pam_faillock.so audit parameter" operator="OR">
            <oval-def:criteria comment="Check expected pam_faillock.so audit parameter in pam files" operator="AND">
              <oval-def:criterion comment="Check the audit parameter in auth section of system-auth file" test_ref="oval:ssg-test_account_pam_faillock_audit_parameter_system_auth:tst:1"/>
              <oval-def:criterion comment="Check the audit parameter in auth section of password-auth file" test_ref="oval:ssg-test_account_pam_faillock_audit_parameter_password_auth:tst:1"/>
              <oval-def:criterion comment="Ensure /etc/security/faillock.conf is not used together with pam files" test_ref="oval:ssg-test_account_pam_faillock_audit_parameter_no_faillock_conf:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="Check expected pam_faillock.so audit parameter in faillock.conf" operator="AND">
              <oval-def:criterion comment="Check the audit parameter is not present system-auth file" test_ref="oval:ssg-test_account_pam_faillock_audit_parameter_no_pamd_system:tst:1"/>
              <oval-def:criterion comment="Check the audit parameter is not present password-auth file" test_ref="oval:ssg-test_account_pam_faillock_audit_parameter_no_pamd_password:tst:1"/>
              <oval-def:criterion comment="Ensure the audit parameter is present in /etc/security/faillock.conf" test_ref="oval:ssg-test_account_pam_faillock_audit_parameter_faillock_conf:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_pwhistory_remember_password_auth:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Limit Password Reuse: password-auth</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_pwhistory_remember_password_auth" source="ssg"/>
            <oval-def:description>The passwords to remember should be set correctly.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check if pam_pwhistory.so is properly configured" operator="AND">
            <oval-def:criterion comment="pam_pwhistory.so is properly defined in password section of password-auth" test_ref="oval:ssg-test_accounts_password_pam_pwhistory_remember_password_auth:tst:1"/>
            <oval-def:criteria comment="Check the expected value for pam_pwhistory.so remember parameter" operator="OR">
              <oval-def:criteria comment="Check the pam_pwhistory.so remember parameter is only in password-auth file" operator="AND">
                <oval-def:criterion comment="Check the remember parameter in password section of password-auth file" test_ref="oval:ssg-test_accounts_password_pam_pwhistory_remember_password_auth_pamd:tst:1"/>
                <oval-def:criterion comment="Check the pam_pwhistory.so remember parameter is absent in pwhistory.conf" test_ref="oval:ssg-test_accounts_password_pam_pwhistory_remember_password_auth_no_pwhistory_conf:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="Check the pam_pwhistory.so remember parameter is only in pwhistory.conf file" operator="AND">
                <oval-def:criterion comment="Check the pam_pwhistory.so remember parameter is absent in password-auth file" test_ref="oval:ssg-test_accounts_password_pam_pwhistory_remember_password_auth_no_pamd:tst:1"/>
                <oval-def:criterion comment="Check the remember parameter in /etc/security/pwhistory.conf" test_ref="oval:ssg-test_accounts_password_pam_pwhistory_remember_password_auth_pwhistory_conf:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_pwhistory_remember_system_auth:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Limit Password Reuse: system-auth</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_pwhistory_remember_system_auth" source="ssg"/>
            <oval-def:description>The passwords to remember should be set correctly.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check if pam_pwhistory.so is properly configured" operator="AND">
            <oval-def:criterion comment="pam_pwhistory.so is properly defined in password section of system-auth" test_ref="oval:ssg-test_accounts_password_pam_pwhistory_remember_system_auth:tst:1"/>
            <oval-def:criteria comment="Check the expected value for pam_pwhistory.so remember parameter" operator="OR">
              <oval-def:criteria comment="Check the pam_pwhistory.so remember parameter is only in system-auth file" operator="AND">
                <oval-def:criterion comment="Check the remember parameter in password section of system-auth file" test_ref="oval:ssg-test_accounts_password_pam_pwhistory_remember_system_auth_pamd:tst:1"/>
                <oval-def:criterion comment="Check the pam_pwhistory.so remember parameter is absent in /etc/security/pwhistory.conf" test_ref="oval:ssg-test_accounts_password_pam_pwhistory_remember_system_auth_no_pwhistory_conf:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="Check the pam_pwhistory.so remember parameter is only in /etc/security/pwhistory.conf file" operator="AND">
                <oval-def:criterion comment="Check the pam_pwhistory.so remember parameter is absent in system-auth file" test_ref="oval:ssg-test_accounts_password_pam_pwhistory_remember_system_auth_no_pamd:tst:1"/>
                <oval-def:criterion comment="Check the remember parameter in /etc/security/pwhistory.conf" test_ref="oval:ssg-test_accounts_password_pam_pwhistory_remember_system_auth_pwhistory_conf:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_pwhistory_use_authtok:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enforce Password History with use_authtok</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_pwhistory_use_authtok" source="ssg"/>
            <oval-def:description>Configure the system to include use_authtok for pam_pwhistory common_password configuration file</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria comment="Check if pam_pwhistory.so is properly configured in /etc/pam.d/system-auth file" operator="AND">
              <oval-def:criterion comment="At least one pwhistory line exists" test_ref="oval:ssg-accounts_password_pam_pwhistory_use_authtok_test_pwhistory_exists_system-auth:tst:1"/>
              <oval-def:criterion comment="use_authtok is configured in pam pwhistory in /etc/pam.d/system-auth file" test_ref="oval:ssg-accounts_password_pam_pwhistory_use_authtok_test_password_pam_pwhistory_use_authtok_system-auth:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_unix_authtok:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Require use_authtok for pam_unix.so</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_unix_authtok" source="ssg"/>
            <oval-def:description>Configure the system to include use_authtok in pam common_password configuration file</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="at least one pam_unix line exists in /etc/pam.d/common-password file" test_ref="oval:ssg-test_accounts_password_pam_unix_authtok_pam_unix_exists_common-password:tst:1"/>
              <oval-def:criterion comment="use_authtok is configured in pam unix in  /etc/pam.d/common-password , ignoring first line on stack" test_ref="oval:ssg-test_accounts_password_pam_unix_authtok_prm_exists_not_initial_common-password:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_unix_remember:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Limit Password Reuse</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_unix_remember" source="ssg"/>
            <oval-def:description>The passwords to remember should be set correctly.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check if pam_pwhistory.so or pam_unix.so are configured" operator="OR">
            <oval-def:criteria comment="Check if pam_pwhistory.so is properly configured" operator="AND">
              <oval-def:criterion comment="pam_pwhistory.so is properly defined in password section of PAM file" test_ref="oval:ssg-test_accounts_password_pam_unix_remember:tst:1"/>
              <oval-def:criteria comment="Check the expected value for pam_pwhistory.so remember parameter" operator="OR">
                <oval-def:criteria comment="Check the pam_pwhistory.so remember parameter is only in PAM file" operator="AND">
                  <oval-def:criterion comment="Check the remember parameter in password section of PAM file" test_ref="oval:ssg-test_accounts_password_pam_unix_remember_pamd:tst:1"/>
                  <oval-def:criterion comment="Check the pam_pwhistory.so remember parameter is absent in /etc/security/pwhistory.conf" test_ref="oval:ssg-test_accounts_password_pam_unix_remember_no_pwhistory_conf:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria comment="Check the pam_pwhistory.so remember parameter is only in /etc/security/pwhistory.conf file" operator="AND">
                  <oval-def:criterion comment="Check the pam_pwhistory.so remember parameter is absent in PAM file" test_ref="oval:ssg-test_accounts_password_pam_unix_remember_no_pamd:tst:1"/>
                  <oval-def:criterion comment="Check the remember parameter in /etc/security/pwhistory.conf" test_ref="oval:ssg-test_accounts_password_pam_unix_remember_pwhistory_conf:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criterion comment="Remember parameter of pam_unix.so is properly configured" test_ref="oval:ssg-test_accounts_password_pam_unix_remember_legacy:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_passwords_pam_faillock_audit:def:1" version="5">
          <oval-def:metadata>
            <oval-def:title>Account Lockouts Must Be Logged</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_passwords_pam_faillock_audit" source="ssg"/>
            <oval-def:description>Account Lockouts Must Be Logged</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check expected value for pam_faillock.so audit parameter" operator="OR">
            <oval-def:criteria comment="Check expected pam_faillock.so audit parameter in pam files" operator="AND">
              <oval-def:criterion comment="Check the audit parameter in auth section of system-auth file" test_ref="oval:ssg-test_pam_faillock_audit_parameter_system_auth:tst:1"/>
              <oval-def:criterion comment="Check the audit parameter in auth section of password-auth file" test_ref="oval:ssg-test_pam_faillock_audit_parameter_password_auth:tst:1"/>
              <oval-def:criterion comment="Ensure /etc/security/faillock.conf is not used together with pam files" test_ref="oval:ssg-test_pam_faillock_audit_parameter_no_faillock_conf:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="Check expected pam_faillock.so audit parameter in faillock.conf" operator="AND">
              <oval-def:criterion comment="Check the audit parameter is not present system-auth file" test_ref="oval:ssg-test_pam_faillock_audit_parameter_no_pamd_system:tst:1"/>
              <oval-def:criterion comment="Check the audit parameter is not present password-auth file" test_ref="oval:ssg-test_pam_faillock_audit_parameter_no_pamd_password:tst:1"/>
              <oval-def:criterion comment="Ensure the audit parameter is present in /etc/security/faillock.conf" test_ref="oval:ssg-test_pam_faillock_audit_parameter_faillock_conf:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_passwords_pam_faillock_deny_root:def:1" version="5">
          <oval-def:metadata>
            <oval-def:title>Configure the root Account for Failed Password Attempts</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_passwords_pam_faillock_deny_root" source="ssg"/>
            <oval-def:description>The root account should be configured to deny access after the number of
      defined failed attempts has been reached.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check the proper configuration of pam_faillock.so" operator="AND">
            <oval-def:criteria comment="Check if pam_faillock.so is properly enabled" operator="AND">
              <oval-def:criteria comment="Count occurrences of pam_unix.so in system-auth and password-auth" operator="AND">
                <oval-def:criterion comment="pam_unix.so appears only once in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_system_pam_unix_auth:tst:1"/>
                <oval-def:criterion comment="pam_unix.so appears only once in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_password_pam_unix_auth:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="Check common definition of pam_faillock.so" operator="AND">
                <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_system_pam_faillock_auth:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in account section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_system_pam_faillock_account:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_password_pam_faillock_auth:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in account section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_password_pam_faillock_account:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria comment="Check expected value for pam_faillock.so even_deny_root parameter" operator="OR">
              <oval-def:criteria comment="Check expected pam_faillock.so even_deny_root parameter in pam files" operator="AND">
                <oval-def:criterion comment="Check the even_deny_root parameter in auth section of system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_parameter_pamd_system:tst:1"/>
                <oval-def:criterion comment="Check the even_deny_root parameter in auth section of password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_parameter_pamd_password:tst:1"/>
                <oval-def:criterion comment="Ensure /etc/security/faillock.conf is not used together with pam files" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_parameter_no_faillock_conf:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="Check expected pam_faillock.so even_deny_root parameter in /etc/security/faillock.conf" operator="AND">
                <oval-def:criterion comment="Check the even_deny_root parameter is not present system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_parameter_no_pamd_system:tst:1"/>
                <oval-def:criterion comment="Check the even_deny_root parameter is not present password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_parameter_no_pamd_password:tst:1"/>
                <oval-def:criterion comment="Ensure the even_deny_root parameter is present in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_parameter_faillock_conf:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_passwords_pam_faillock_dir:def:1" version="5">
          <oval-def:metadata>
            <oval-def:title>Lock Accounts Must Persist</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_passwords_pam_faillock_dir" source="ssg"/>
            <oval-def:description> Persist lockout account after reboot</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check expected value for pam_faillock.so dir parameter" operator="OR">
            <oval-def:criteria comment="Check expected pam_faillock.so dir parameter in pam files" operator="AND">
              <oval-def:criterion comment="Check the dir parameter in auth section of system-auth file" test_ref="oval:ssg-test_pam_faillock_dir_parameter_system_auth:tst:1"/>
              <oval-def:criterion comment="Check the dir parameter in auth section of password-auth file" test_ref="oval:ssg-test_pam_faillock_dir_parameter_password_auth:tst:1"/>
              <oval-def:criterion comment="Ensure /etc/security/faillock.conf is not used together with pam files" test_ref="oval:ssg-test_pam_faillock_dir_parameter_no_faillock_conf:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="Check expected pam_faillock.so dir parameter in faillock.conf" operator="AND">
              <oval-def:criterion comment="Check the dir parameter is not present system-auth file" test_ref="oval:ssg-test_pam_faillock_dir_parameter_no_pamd_system:tst:1"/>
              <oval-def:criterion comment="Check the dir parameter is not present password-auth file" test_ref="oval:ssg-test_pam_faillock_dir_parameter_no_pamd_password:tst:1"/>
              <oval-def:criterion comment="Ensure the dir parameter is present in /etc/security/faillock.conf" test_ref="oval:ssg-test_pam_faillock_dir_parameter_faillock_conf:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_passwords_pam_faillock_enforce_local:def:1" version="5">
          <oval-def:metadata>
            <oval-def:title>Enforce pam_faillock for Local Accounts Only</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_passwords_pam_faillock_enforce_local" source="ssg"/>
            <oval-def:description>Enforce pam_faillock for Local Accounts Only</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check the proper configuration of pam_faillock.so" operator="AND">
            <oval-def:criteria comment="Check if pam_faillock.so is properly enabled" operator="AND">
              <oval-def:criteria comment="Count occurrences of pam_unix.so in system-auth and password-auth" operator="AND">
                <oval-def:criterion comment="pam_unix.so appears only once in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_enforce_local_system_pam_unix_auth:tst:1"/>
                <oval-def:criterion comment="pam_unix.so appears only once in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_enforce_local_password_pam_unix_auth:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="Check common definition of pam_faillock.so" operator="AND">
                <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_enforce_local_system_pam_faillock_auth:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in account section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_enforce_local_system_pam_faillock_account:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_enforce_local_password_pam_faillock_auth:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in account section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_enforce_local_password_pam_faillock_account:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criterion comment="Ensure the local_users_only parameter is present in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_enforce_local_parameter_faillock_conf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Root Account Lockout on Failed Password Attempts</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time" source="ssg"/>
            <oval-def:description>The root account should be included in the account lockout policy.
      Either the even_deny_root option should be set or root_unlock_time should be set to
      the required minimum value or greater.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check the proper configuration of pam_faillock.so" operator="AND">
            <oval-def:criteria comment="Check if pam_faillock.so is properly enabled" operator="AND">
              <oval-def:criteria comment="Count occurrences of pam_unix.so in system-auth and password-auth" operator="AND">
                <oval-def:criterion comment="pam_unix.so appears only once in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_system_pam_unix_auth:tst:1"/>
                <oval-def:criterion comment="pam_unix.so appears only once in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_password_pam_unix_auth:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="Check common definition of pam_faillock.so" operator="AND">
                <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_system_pam_faillock_auth:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in account section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_system_pam_faillock_account:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_password_pam_faillock_auth:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in account section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_password_pam_faillock_account:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria comment="Check even_deny_root is set or root_unlock_time &gt;= var_accounts_passwords_pam_faillock_root_unlock_time" operator="OR">
              <oval-def:criteria comment="Check expected value for pam_faillock.so even_deny_root parameter" operator="OR">
                <oval-def:criteria comment="Check expected pam_faillock.so even_deny_root parameter in pam files" operator="AND">
                  <oval-def:criterion comment="Check the even_deny_root parameter in auth section of system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_pamd_system:tst:1"/>
                  <oval-def:criterion comment="Check the even_deny_root parameter in auth section of password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_pamd_password:tst:1"/>
                  <oval-def:criterion comment="Ensure /etc/security/faillock.conf is not used together with pam files" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_no_faillock_conf:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria comment="Check expected pam_faillock.so even_deny_root parameter in /etc/security/faillock.conf" operator="AND">
                  <oval-def:criterion comment="Check the even_deny_root parameter is not present system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_no_pamd_system:tst:1"/>
                  <oval-def:criterion comment="Check the even_deny_root parameter is not present password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_no_pamd_password:tst:1"/>
                  <oval-def:criterion comment="Ensure the even_deny_root parameter is present in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_faillock_conf:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
              <oval-def:criteria comment="Check expected value for pam_faillock.so root_unlock_time parameter" operator="OR">
                <oval-def:criteria comment="Check pam_faillock.so root_unlock_time parameter in pam files" operator="AND">
                  <oval-def:criterion comment="Check root_unlock_time &gt;= var_accounts_passwords_pam_faillock_root_unlock_time in auth section of system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_pamd_system:tst:1"/>
                  <oval-def:criterion comment="Check root_unlock_time &gt;= var_accounts_passwords_pam_faillock_root_unlock_time in auth section of password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_pamd_password:tst:1"/>
                  <oval-def:criterion comment="Ensure root_unlock_time is not in /etc/security/faillock.conf together with pam files" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_no_faillock_conf:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria comment="Check pam_faillock.so root_unlock_time parameter in /etc/security/faillock.conf" operator="AND">
                  <oval-def:criterion comment="Check root_unlock_time is not present in system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_no_pamd_system:tst:1"/>
                  <oval-def:criterion comment="Check root_unlock_time is not present in password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_no_pamd_password:tst:1"/>
                  <oval-def:criterion comment="Ensure root_unlock_time &gt;= var_accounts_passwords_pam_faillock_root_unlock_time in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_faillock_conf:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_passwords_pam_faillock_silent:def:1" version="5">
          <oval-def:metadata>
            <oval-def:title>Do Not Show System Messages When Unsuccessful Logon Attempts Occur</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_passwords_pam_faillock_silent" source="ssg"/>
            <oval-def:description>Prevent System Messages When Three Unsuccessful Logon Attempts Occur</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check expected value for pam_faillock.so silent parameter" operator="OR">
            <oval-def:criteria comment="Check expected pam_faillock.so silent parameter in pam files" operator="AND">
              <oval-def:criterion comment="Check the silent parameter in auth section of system-auth file" test_ref="oval:ssg-test_pam_faillock_silent_parameter_system_auth:tst:1"/>
              <oval-def:criterion comment="Check the silent parameter in auth section of password-auth file" test_ref="oval:ssg-test_pam_faillock_silent_parameter_password_auth:tst:1"/>
              <oval-def:criterion comment="Ensure /etc/security/faillock.conf is not used together with pam files" test_ref="oval:ssg-test_pam_faillock_silent_parameter_no_faillock_conf:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="Check expected pam_faillock.so silent parameter in faillock.conf" operator="AND">
              <oval-def:criterion comment="Check the silent parameter is not present system-auth file" test_ref="oval:ssg-test_pam_faillock_silent_parameter_no_pamd_system:tst:1"/>
              <oval-def:criterion comment="Check the silent parameter is not present password-auth file" test_ref="oval:ssg-test_pam_faillock_silent_parameter_no_pamd_password:tst:1"/>
              <oval-def:criterion comment="Ensure the silent parameter is present in /etc/security/faillock.conf" test_ref="oval:ssg-test_pam_faillock_silent_parameter_faillock_conf:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_passwords_pam_faillock_unlock_time_with_zero:def:1" version="6">
          <oval-def:metadata>
            <oval-def:title>Set Lockout Time for Failed Password Attempts</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_passwords_pam_faillock_unlock_time_with_zero" source="ssg"/>
            <oval-def:description/>
          </oval-def:metadata>
          <oval-def:criteria comment="Check the proper configuration of pam_faillock.so" operator="AND">
            <oval-def:criteria comment="Check if pam_faillock.so is properly enabled" operator="AND">
              <oval-def:criteria comment="Count occurrences of pam_unix.so in system-auth and password-auth" operator="AND">
                <oval-def:criterion comment="pam_unix.so appears only once in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_system_pam_unix_auth:tst:1"/>
                <oval-def:criterion comment="pam_unix.so appears only once in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_password_pam_unix_auth:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="Check common definition of pam_faillock.so" operator="AND">
                <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_system_pam_faillock_auth:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in account section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_system_pam_faillock_account:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_password_pam_faillock_auth:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in account section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_password_pam_faillock_account:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria comment="Check expected value for pam_faillock.so unlock_time parameter" operator="OR">
              <oval-def:criteria comment="Check expected pam_faillock.so unlock_time parameter in pam files" operator="AND">
                <oval-def:criterion comment="Check the unlock_time parameter in auth section of system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_pamd_system:tst:1"/>
                <oval-def:criterion comment="Check the unlock_time parameter in auth section of password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_pamd_password:tst:1"/>
                <oval-def:criterion comment="Ensure the unlock_time parameter is not present in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_no_faillock_conf:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="Check expected pam_faillock.so unlock_time parameter in /etc/security/faillock.conf" operator="AND">
                <oval-def:criterion comment="Check the unlock_time parameter is not present system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_no_pamd_system:tst:1"/>
                <oval-def:criterion comment="Check the unlock_time parameter is not present password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_no_pamd_password:tst:1"/>
                <oval-def:criterion comment="Ensure the unlock_time parameter is present in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_faillock_conf:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_enforce_root:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Ensure PAM Enforces Password Requirements - Enforce for root User</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_enforce_root" source="ssg"/>
            <oval-def:description>The password policy should also be enforced for root.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="conditions for enforce_for_root are satisfied" operator="AND">
            <oval-def:extend_definition comment="pwquality.so exists in system-auth" definition_ref="oval:ssg-accounts_password_pam_pwquality:def:1"/>
            <oval-def:criterion comment="pwquality.conf" test_ref="oval:ssg-test_password_pam_pwquality_enforce_for_root:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_pwquality_password_auth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure PAM password complexity module is enabled in password-auth</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_pwquality_password_auth" source="ssg"/>
            <oval-def:description>The PAM module pam_pwquality is used in password-auth</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Condition for pam_pwquality in password-auth is satisfied" operator="AND">
            <oval-def:criterion comment="pam_pwquality password-auth" test_ref="oval:ssg-test_accounts_password_pam_pwquality_password_auth:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_pwquality_system_auth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure PAM password complexity module is enabled in system-auth</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_pwquality_system_auth" source="ssg"/>
            <oval-def:description>The PAM module pam_pwquality is used in system-auth</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Condition for pam_pwquality in system-auth is satisfied" operator="AND">
            <oval-def:criterion comment="pam_pwquality system-auth" test_ref="oval:ssg-test_accounts_password_pam_pwquality_system_auth:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_retry:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted Per-Session</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_retry" source="ssg"/>
            <oval-def:description>The password retry should meet minimum requirements</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="The password retry should meet minimum requirements" operator="AND">
            <oval-def:extend_definition definition_ref="oval:ssg-enable_authselect:def:1"/>
            <oval-def:criteria comment="Conditions for retry are satisfied" operator="OR">
              <oval-def:criteria comment="Conditions for retry in PAM files are satisfied" operator="AND">
                <oval-def:criterion comment="pam_pwquality has correctly set the retry argument in  system-auth" test_ref="oval:ssg-test_password_pam_pwquality_retry_system_auth:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="Conditions for retry in /etc/security/pwquality.conf file are satisfied" operator="AND">
                <oval-def:criterion comment="retry value not set in PAM files" test_ref="oval:ssg-test_password_pam_pwquality_retry_system_auth_not_set:tst:1"/>
                <oval-def:criterion comment="check retry parameter in /etc/security/pwquality.conf" test_ref="oval:ssg-test_password_pam_pwquality_retry_pwquality_conf:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-set_password_hashing_algorithm_libuserconf:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set Password Hashing Algorithm in /etc/libuser.conf</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="set_password_hashing_algorithm_libuserconf" source="ssg"/>
            <oval-def:description>The password hashing algorithm should be set correctly in /etc/libuser.conf.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_set_password_hashing_algorithm_libuserconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-set_password_hashing_algorithm_logindefs:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Set Password Hashing Algorithm in /etc/login.defs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="set_password_hashing_algorithm_logindefs" source="ssg"/>
            <oval-def:description>The password hashing algorithm should be set correctly in /etc/login.defs.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_password_hashing_algorithm_logindefs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-set_password_hashing_algorithm_passwordauth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set PAM Password Hashing Algorithm - password-auth</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="set_password_hashing_algorithm_passwordauth" source="ssg"/>
            <oval-def:description>The password hashing algorithm should be set correctly in /etc/pam.d/password-auth.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_set_password_hashing_algorithm_passwordauth:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-set_password_hashing_algorithm_systemauth:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Set PAM Password Hashing Algorithm - system-auth</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="set_password_hashing_algorithm_systemauth" source="ssg"/>
            <oval-def:description>The password hashing algorithm should be set correctly in {{{ pam_file }}}.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_pam_unix_hashing_algorithm_systemauth:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-set_password_hashing_min_rounds_logindefs:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Set Password Hashing Minimum Rounds in /etc/login.defs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="set_password_hashing_min_rounds_logindefs" source="ssg"/>
            <oval-def:description>The password hashing minimum rounds should be set correctly in /etc/login.defs.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criteria operator="AND">
                <oval-def:criterion test_ref="oval:ssg-test_etc_login_defs_sha_crypt_min_rounds_default:tst:1"/>
                <oval-def:criterion test_ref="oval:ssg-test_var_password_hashing_min_rounds_login_defs_le_5000:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion test_ref="oval:ssg-test_etc_login_defs_sha_crypt_min_rounds_present:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criteria operator="AND">
                <oval-def:criterion test_ref="oval:ssg-test_var_password_hashing_min_rounds_login_defs_le_5000:tst:1"/>
                <oval-def:criterion test_ref="oval:ssg-test_etc_login_defs_sha_crypt_max_rounds_default:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion negate="true" test_ref="oval:ssg-test_etc_login_defs_sha_crypt_min_rounds_default:tst:1"/>
              <oval-def:criterion test_ref="oval:ssg-test_etc_login_defs_sha_crypt_max_rounds_present:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-disable_ctrlaltdel_burstaction:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Ctrl-Alt-Del Burst Action</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="disable_ctrlaltdel_burstaction" source="ssg"/>
            <oval-def:description>Configure the CtrlAltDelBurstAction setting in /etc/systemd/system.conf
      or /etc/systemd/system.conf.d/* to none to prevent a reboot if Ctrl-Alt-Delete is
      pressed more than 7 times in 2 seconds.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="check CtrlAltDelBurstAction is set to none" test_ref="oval:ssg-test_disable_ctrlaltdel_burstaction:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-disable_ctrlaltdel_reboot:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Ctrl-Alt-Del Reboot Activation</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="disable_ctrlaltdel_reboot" source="ssg"/>
            <oval-def:description>By default, the system will reboot when the
      Ctrl-Alt-Del key sequence is pressed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Disable Ctrl-Alt-Del systemd softlink exists" test_ref="oval:ssg-test_disable_ctrlaltdel_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_disable_interactive_boot:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Verify that Interactive Boot is Disabled</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_disable_interactive_boot" source="ssg"/>
            <oval-def:description>The ability for users to perform interactive startups should
      be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check systemd.confirm_spawn=(1|yes|true|on) not in GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_disable_interactive_boot_grub_cmdline_linux:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check systemd.confirm_spawn=(1|yes|true|on) not in GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_disable_interactive_boot_grub_cmdline_linux_default:tst:1"/>
              <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-logind_session_timeout:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure Logind to terminate idle sessions after certain time of inactivity</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="logind_session_timeout" source="ssg"/>
            <oval-def:description>Ensure 'StopIdleSessionSec' is configured with desired value in section 'Login' in /etc/systemd/logind.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="logind is configured correctly and configuration file exists" operator="AND">
            <oval-def:criterion comment="Check the StopIdleSessionSec in /etc/systemd/logind.conf" test_ref="oval:ssg-test_logind_session_timeout:tst:1"/>
            <oval-def:criterion comment="test if configuration file /etc/systemd/logind.conf exists for logind_session_timeout" test_ref="oval:ssg-test_logind_session_timeout_config_file_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-require_emergency_target_auth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Require Authentication for Emergency Systemd Target</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="require_emergency_target_auth" source="ssg"/>
            <oval-def:description>The requirement for a password to boot into emergency mode
      should be configured correctly.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Conditions are satisfied" test_ref="oval:ssg-test_require_emergency_service:tst:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_require_emergency_service_emergency_target:tst:1"/>
            <oval-def:criterion negate="true" test_ref="oval:ssg-test_no_custom_emergency_target:tst:1"/>
            <oval-def:criterion negate="true" test_ref="oval:ssg-test_no_custom_emergency_service:tst:1"/>
            <oval-def:criterion negate="true" test_ref="oval:ssg-test_require_emergency_target_auth_drop_in_config_exist:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-require_singleuser_auth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Require Authentication for Single User Mode</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="require_singleuser_auth" source="ssg"/>
            <oval-def:description>The requirement for a password to boot into single-user mode
      should be configured correctly.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criteria operator="AND">
                <oval-def:criterion comment="authentication for single user mode is configured in the file provided by distro" test_ref="oval:ssg-test_require_rescue_service_distro:tst:1"/>
                <oval-def:criterion comment="Execstart directive of rescue.service is not overridden" test_ref="oval:ssg-test_rescue_service_not_overridden:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="authentication for single user mode is configured in the override file" test_ref="oval:ssg-test_require_rescue_service_override:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion test_ref="oval:ssg-test_require_rescue_service_runlevel1:tst:1"/>
            <oval-def:criterion negate="true" test_ref="oval:ssg-test_no_custom_runlevel1_target:tst:1"/>
            <oval-def:criterion negate="true" test_ref="oval:ssg-test_no_custom_rescue_service:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-configure_bashrc_exec_tmux:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Support session locking with tmux</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="configure_bashrc_exec_tmux" source="ssg"/>
            <oval-def:description>Check if tmux is configured to exec at the end of bashrc.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check exec tmux configured at the end of bashrc" operator="AND">
            <oval-def:criterion comment="check tmux is configured to exec on the last line of /etc/bashrc" test_ref="oval:ssg-test_configure_bashrc_exec_tmux:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-configure_bashrc_tmux:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Support session locking with tmux (not enforcing)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="configure_bashrc_tmux" source="ssg"/>
            <oval-def:description>Check if tmux is configured to be launched at the end of bashrc.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check tmux is configured to be launched at the end of bashrc" operator="AND">
            <oval-def:criterion comment="check tmux is configured to be launched on the last line of /etc/bashrc" test_ref="oval:ssg-test_configure_bashrc_tmux:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-configure_tmux_lock_after_time:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure tmux to lock session after inactivity</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="configure_tmux_lock_after_time" source="ssg"/>
            <oval-def:description>Check if tmux is configured to lock sessions after period of inactivity.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Configure tmux to lock session after inactivity" operator="AND">
            <oval-def:criterion comment="check lock-after-time is set to 900 in /etc/tmux.conf" test_ref="oval:ssg-test_configure_tmux_lock_after_time:tst:1"/>
            <oval-def:extend_definition comment="Check /etc/tmux.conf is readable by others" definition_ref="oval:ssg-tmux_conf_readable_by_others:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-configure_tmux_lock_command:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure the tmux Lock Command</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="configure_tmux_lock_command" source="ssg"/>
            <oval-def:description>Check if the vlock command is configured to be used as a locking mechanism in tmux.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Configure the tmux Lock Command" operator="AND">
            <oval-def:criterion comment="check lock-command is set to vlock in /etc/tmux.conf" test_ref="oval:ssg-test_configure_tmux_lock_command:tst:1"/>
            <oval-def:extend_definition comment="Check /etc/tmux.conf is readable by others" definition_ref="oval:ssg-tmux_conf_readable_by_others:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-configure_tmux_lock_keybinding:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure the tmux lock session key binding</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="configure_tmux_lock_keybinding" source="ssg"/>
            <oval-def:description>Check if the lock-session command is bound to a key.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Configure binding for the tmux Lock Session command" operator="AND">
            <oval-def:criterion comment="check lock-session is bound to a key" test_ref="oval:ssg-test_configure_tmux_lock_keybinding:tst:1"/>
            <oval-def:extend_definition comment="Check /etc/tmux.conf is readable by others" definition_ref="oval:ssg-tmux_conf_readable_by_others:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_tmux_in_shells:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Prevent user from disabling the screen lock</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_tmux_in_shells" source="ssg"/>
            <oval-def:description>Check that tmux is not listed in /etc/shells</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check that tmux is not listed in /etc/shells" operator="AND">
            <oval-def:criterion comment="check that tmux is not listed in /etc/shells" test_ref="oval:ssg-test_no_tmux_in_shells:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-configure_opensc_card_drivers:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure opensc Smart Card Drivers</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="configure_opensc_card_drivers" source="ssg"/>
            <oval-def:description>Configure the organization's smart card driver so that only
      the smart card in use by the organization will be recognized by the system.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check that card_drivers is configured for opensc" test_ref="oval:ssg-test_configure_opensc_card_drivers:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-force_opensc_card_drivers:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Force opensc To Use Defined Smart Card Driver</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="force_opensc_card_drivers" source="ssg"/>
            <oval-def:description>Force opensc to use the organization's smart card driver so that only
      the smart card in use by the organization will be recognized by the system.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check that force_card_driver is configured for opensc" test_ref="oval:ssg-test_force_opensc_card_drivers:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-account_unique_id:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure All Accounts on the System Have Unique User IDs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="account_unique_id" source="ssg"/>
            <oval-def:description>All accounts on the system should have unique IDs for proper accountability.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="There should not exist duplicate user IDs entries in /etc/passwd" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_etc_passwd_no_duplicate_user_ids:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_authorized_local_users:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Only Authorized Local User Accounts Exist on Operating System</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_authorized_local_users" source="ssg"/>
            <oval-def:description>Besides the default operating system user, there should be no other users
      except the users that are authorized to exist locally on the operating system.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="only root user and explicitly authorized users are allowed in /etc/passwd" test_ref="oval:ssg-test_accounts_authorized_local_users:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-group_unique_id:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure All Groups on the System Have Unique Group ID</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="group_unique_id" source="ssg"/>
            <oval-def:description>All groups on the system should have unique names for proper accountability.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="There should not exist duplicate group ids entries in /etc/passwd" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_etc_group_no_duplicate_group_ids:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-group_unique_name:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure All Groups on the System Have Unique Group Names</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="group_unique_name" source="ssg"/>
            <oval-def:description>All groups on the system should have unique names for proper accountability.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="There should not exist duplicate group names entries in /etc/passwd" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_etc_group_no_duplicate_group_names:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_nologin_in_shells:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure nologin Shell is Not Listed in /etc/shells</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_nologin_in_shells" source="ssg"/>
            <oval-def:description>The nologin shell should not be listed in /etc/shells.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="nologin not in /etc/shells" test_ref="oval:ssg-test_no_nologin_in_shells:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-account_disable_post_pw_expiration:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Set Account Expiration Following Inactivity</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="account_disable_post_pw_expiration" source="ssg"/>
            <oval-def:description>The accounts should be configured to expire automatically following password expiration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="the value INACTIVE parameter should be set appropriately in /etc/default/useradd" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_etc_default_useradd_inactive:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-account_unique_name:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure All Accounts on the System Have Unique Names</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="account_unique_name" source="ssg"/>
            <oval-def:description>All accounts on the system should have unique names for proper accountability.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="There should not exist duplicate user name entries in /etc/passwd" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_etc_passwd_no_duplicate_user_names:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_maximum_age_login_defs:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Set Password Maximum Age</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_maximum_age_login_defs" source="ssg"/>
            <oval-def:description>The maximum password age policy should meet minimum requirements.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="The value PASS_MAX_DAYS should be set appropriately in /etc/login.defs" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_pass_max_days:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_minimum_age_login_defs:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Set Password Minimum Age</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_minimum_age_login_defs" source="ssg"/>
            <oval-def:description>The minimum password age policy should be set appropriately.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="The value of PASS_MIN_DAYS should be set appropriately in /etc/login.defs" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_pass_min_days:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_minlen_login_defs:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Set Password Minimum Length in login.defs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_minlen_login_defs" source="ssg"/>
            <oval-def:description>The password minimum length should be set appropriately.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_pass_min_len:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_set_max_life_existing:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Set Existing Passwords Maximum Age</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_set_max_life_existing" source="ssg"/>
            <oval-def:description>Set Existing Passwords Maximum Age</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Passwords must be restricted to the appropriate maximum age for existing accounts." test_ref="oval:ssg-test_accounts_password_set_max_life_existing_password_max_life_existing:tst:1"/>
            <oval-def:criterion comment="Passwords must have a maximum lifetime greater than or equal minimum password age." test_ref="oval:ssg-test_accounts_password_set_max_life_existing_password_max_life_existing_minimum:tst:1"/>
            <oval-def:criterion comment="Passwords must have the maximum password age set non-empty in /etc/shadow." test_ref="oval:ssg-test_accounts_password_set_max_life_existing_password_max_life_not_empty:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_set_max_life_root:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set Root Account Password Maximum Age</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_set_max_life_root" source="ssg"/>
            <oval-def:description>A maximum password age should be set for the root account</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="root max age" test_ref="oval:ssg-test_accounts_password_set_max_life_root:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_set_min_life_existing:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Set Existing Passwords Minimum Age</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_set_min_life_existing" source="ssg"/>
            <oval-def:description>Set Existing Passwords Maximum Age</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Passwords must be restricted to the appropriate maximum age for existing accounts." test_ref="oval:ssg-test_accounts_password_set_min_life_existing_password_max_life_existing:tst:1"/>
            <oval-def:criterion comment="Passwords must have a maximum lifetime greater than or equal minimum password age." test_ref="oval:ssg-test_accounts_password_set_min_life_existing_password_max_life_existing_minimum:tst:1"/>
            <oval-def:criterion comment="Passwords must have the maximum password age set non-empty in /etc/shadow." test_ref="oval:ssg-test_accounts_password_set_min_life_existing_password_max_life_not_empty:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_set_warn_age_existing:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set Existing Passwords Warning Age</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_set_warn_age_existing" source="ssg"/>
            <oval-def:description>Set Existing Passwords Warning Age</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="Passwords must be configured to the appropriate value" test_ref="oval:ssg-test_accounts_password_set_warn_age_existing:tst:1"/>
            <oval-def:criterion comment="There is no password defined in /etc/shadow" test_ref="oval:ssg-test_accounts_password_set_warn_age_existing_no_pass:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_warn_age_login_defs:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Set Password Warning Age</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_warn_age_login_defs" source="ssg"/>
            <oval-def:description>The password expiration warning age should be set appropriately.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_pass_warn_age:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_set_post_pw_existing:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set existing passwords a period of inactivity before they been locked</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_set_post_pw_existing" source="ssg"/>
            <oval-def:description>Set existing passwords a period of inactivity before they been locked</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="Passwords must be configured to the appropriate value" test_ref="oval:ssg-test_accounts_set_post_pw_existing:tst:1"/>
            <oval-def:criterion comment="There is no password defined in /etc/shadow" test_ref="oval:ssg-test_accounts_set_post_pw_existing_no_pass:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_all_shadowed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify All Account Password Hashes are Shadowed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_all_shadowed" source="ssg"/>
            <oval-def:description>All password hashes should be shadowed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="password hashes are shadowed" test_ref="oval:ssg-test_accounts_password_all_shadowed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_all_shadowed_sha512:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify All Account Password Hashes are Shadowed with SHA512</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_all_shadowed_sha512" source="ssg"/>
            <oval-def:description>All password hashes should be shadowed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="password hashes are shadowed using sha512" negate="true" test_ref="oval:ssg-test_accounts_password_all_shadowed_sha512:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_last_change_is_in_past:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure all users last password change date is in the past</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_last_change_is_in_past" source="ssg"/>
            <oval-def:description>All passwords last change date is in the past.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="All passwords last change date is in the past" test_ref="oval:ssg-test_accounts_password_last_change_is_in_past:tst:1"/>
            <oval-def:criterion comment="There is no password defined in /etc/shadow" test_ref="oval:ssg-test_accounts_password_last_change_is_in_past_no_pass:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_unix_no_remember:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Avoid using remember in pam_unix module</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_unix_no_remember" source="ssg"/>
            <oval-def:description>The pam_unix module should not include remember option</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="make sure the remember option is not used in pam_unix.so module" test_ref="oval:ssg-test_pam_unix_no_remember:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_unix_rounds_password_auth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set number of Password Hashing Rounds - password-auth</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_unix_rounds_password_auth" source="ssg"/>
            <oval-def:description>The number of rounds for password hashing should be set correctly.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check if rounds option of pam_unix is as expected" operator="OR">
            <oval-def:criterion comment="The value of rounds is set correctly in pam_unix.so" test_ref="oval:ssg-test_password_auth_pam_unix_rounds_is_set:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_unix_rounds_system_auth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set number of Password Hashing Rounds - system-auth</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_unix_rounds_system_auth" source="ssg"/>
            <oval-def:description>The number of rounds for password hashing should be set correctly.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check if rounds option of pam_unix is as expected" operator="OR">
            <oval-def:criterion comment="The value of rounds is set correctly in pam_unix.so" test_ref="oval:ssg-test_system_auth_pam_unix_rounds_is_set:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-gid_passwd_group_same:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>All GIDs referenced in /etc/passwd must be defined in /etc/group</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="gid_passwd_group_same" source="ssg"/>
            <oval-def:description>All GIDs referenced in /etc/passwd must be defined in /etc/group.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_gid_passwd_group_same:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_empty_passwords:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Prevent Login to Accounts With Empty Password</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_empty_passwords" source="ssg"/>
            <oval-def:description>The file /etc/pam.d/system-auth should not contain the nullok option</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="make sure the nullok option is not used in /etc/pam.d/system-auth" test_ref="oval:ssg-test_no_empty_passwords:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_empty_passwords_etc_shadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure There Are No Accounts With Blank or Null Passwords</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_empty_passwords_etc_shadow" source="ssg"/>
            <oval-def:description>The file /etc/shadow shows that there aren't empty passwords</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="make sure there aren't blank or null passwords in /etc/shadow" test_ref="oval:ssg-test_no_empty_passwords_etc_shadow:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_forward_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify No .forward Files Exist</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_forward_files" source="ssg"/>
            <oval-def:description>The .forward file specifies an email address to forward the user's mail to. Any .forward files should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion negate="true" test_ref="oval:ssg-test_accounts_users_home_forward_file_existance:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_legacy_plus_entries_etc_group:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure there are no legacy + NIS entries in /etc/group</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_legacy_plus_entries_etc_group" source="ssg"/>
            <oval-def:description>No lines starting with + are in /etc/group</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="no lines starting with + are in /etc/group" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_no_legacy_plus_entries_etc_group:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_legacy_plus_entries_etc_passwd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure there are no legacy + NIS entries in /etc/passwd</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_legacy_plus_entries_etc_passwd" source="ssg"/>
            <oval-def:description>No lines starting with + are in /etc/passwd</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="no lines starting with + are in /etc/passwd" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_no_legacy_plus_entries_etc_passwd:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_legacy_plus_entries_etc_shadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure there are no legacy + NIS entries in /etc/shadow</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_legacy_plus_entries_etc_shadow" source="ssg"/>
            <oval-def:description>No lines starting with + are in /etc/shadow</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="no lines starting with + are in /etc/shadow" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_no_legacy_plus_entries_etc_shadow:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_netrc_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify No netrc Files Exist</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_netrc_files" source="ssg"/>
            <oval-def:description>The .netrc files contain login information used to auto-login into FTP servers and reside in the user's home directory. Any .netrc files should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion negate="true" test_ref="oval:ssg-test_no_netrc_files_home:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_rhost_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify No .rhost Files Exist</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_rhost_files" source="ssg"/>
            <oval-def:description>Local system users should not have a .rhost file in their home directory.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion negate="true" test_ref="oval:ssg-test_no_rhost_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_no_uid_except_zero:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Only Root Has UID 0</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_no_uid_except_zero" source="ssg"/>
            <oval-def:description>Only the root account should be assigned a user id of 0, or the account must be locked.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="tests that there are no accounts with UID 0 except root in the /etc/passwd file" test_ref="oval:ssg-test_accounts_no_uid_except_root:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_root_gid_zero:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Root Has A Primary GID 0</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_root_gid_zero" source="ssg"/>
            <oval-def:description>The root account should have primary group of 0</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="tests that the root account's gid is equal to 0" test_ref="oval:ssg-test_accounts_root_gid_zero:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ensure_pam_wheel_group_empty:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ensure_pam_wheel_group_empty" source="ssg"/>
            <oval-def:description>Group referred by var_pam_wheel_group_for_su variable exists and has no members.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_ensure_pam_wheel_group_empty_group_exists:tst:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_ensure_pam_wheel_group_empty_has_no_members:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ensure_root_password_configured:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Authentication Required for Single User Mode</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ensure_root_password_configured" source="ssg"/>
            <oval-def:description>Ensure root password is configured</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="verify root password is set" test_ref="oval:ssg-test_root_password_etc_shadow:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-groups_no_zero_gid_except_root:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Only Group Root Has GID 0</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="groups_no_zero_gid_except_root" source="ssg"/>
            <oval-def:description>Only the root group should be assigned a GID of 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="no groups with GID 0 except root in the /etc/group file" test_ref="oval:ssg-test_groups_no_zero_gid_except_root:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_direct_root_logins:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Direct root Logins Not Allowed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_direct_root_logins" source="ssg"/>
            <oval-def:description>Preventing direct root logins help ensure accountability for actions
      taken on the system using the root account.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="serial ports /etc/securetty" test_ref="oval:ssg-test_no_direct_root_logins:tst:1"/>
            <oval-def:criterion comment="serial ports /etc/securetty" test_ref="oval:ssg-test_etc_securetty_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_invalid_shell_accounts_unlocked:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Non-Interactive Accounts Are Locked</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_invalid_shell_accounts_unlocked" source="ssg"/>
            <oval-def:description>Ensure Accounts Without Valid Login Shell Are Locked</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check that the accounts do not have valid shells" negate="true" test_ref="oval:ssg-test_no_invalid_shell_accounts_unlocked_no_invalid_shell_accounts:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_password_auth_for_systemaccounts:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure that System Accounts Are Locked</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_password_auth_for_systemaccounts" source="ssg"/>
            <oval-def:description>Ensure that System Accounts Are Locked</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="system accounts must not have a password defined" test_ref="oval:ssg-test_no_password_auth_for_systemaccounts:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_shelllogin_for_systemaccounts:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure that System Accounts Do Not Run a Shell Upon Login</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_shelllogin_for_systemaccounts" source="ssg"/>
            <oval-def:description>The root account is the only system account that should have
      a login shell.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Test SYS_UID_MIN not defined in /etc/login.defs" test_ref="oval:ssg-test_sys_uid_min_not_defined:tst:1"/>
              <oval-def:criterion comment="Test SYS_UID_MAX not defined in /etc/login.defs" test_ref="oval:ssg-test_sys_uid_max_not_defined:tst:1"/>
              <oval-def:criterion comment="Test shell defined for UID from &lt;0, UID_MIN -1&gt;" test_ref="oval:ssg-test_shell_defined_default_uid_range:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Test SYS_UID_MIN defined in /etc/login.defs" negate="true" test_ref="oval:ssg-test_sys_uid_min_not_defined:tst:1"/>
              <oval-def:criterion comment="Test SYS_UID_MAX defined in /etc/login.defs" negate="true" test_ref="oval:ssg-test_sys_uid_max_not_defined:tst:1"/>
              <oval-def:criterion comment="Test shell defined for reserved system UIDs" test_ref="oval:ssg-test_shell_defined_reserved_uid_range:tst:1"/>
              <oval-def:criterion comment="Test shell defined for dynamically allocated system UIDs" test_ref="oval:ssg-test_shell_defined_dynalloc_uid_range:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-restrict_serial_port_logins:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Restrict Serial Port Root Logins</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="restrict_serial_port_logins" source="ssg"/>
            <oval-def:description>Preventing direct root login to serial port interfaces helps
      ensure accountability for actions taken on the system using the root
      account.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="serial ports /etc/securetty" negate="true" test_ref="oval:ssg-test_serial_ports_etc_securetty:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-securetty_root_login_console_only:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Restrict Virtual Console Root Logins</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="securetty_root_login_console_only" source="ssg"/>
            <oval-def:description>Preventing direct root login to virtual console devices
      helps ensure accountability for actions taken on the system using the
      root account.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virtual consoles /etc/securetty" test_ref="oval:ssg-test_virtual_consoles_etc_securetty:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_have_homedir_login_defs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Home Directories are Created for New Users</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_have_homedir_login_defs" source="ssg"/>
            <oval-def:description>CREATE_HOME should be enabled</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check CREATE_HOME in /etc/login.defs" test_ref="oval:ssg-test_accounts_have_homedir_login_defs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_logon_fail_delay:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure the Logon Failure Delay is Set Correctly in login.defs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_logon_fail_delay" source="ssg"/>
            <oval-def:description>The delay between failed authentication attempts should be
      set for all users specified in /etc/login.defs</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_accounts_logon_fail_delay:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_max_concurrent_login_sessions:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Limit the Number of Concurrent Login Sessions Allowed Per User</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_max_concurrent_login_sessions" source="ssg"/>
            <oval-def:description>The maximum number of concurrent login sessions per user should meet
      minimum requirements.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="the value maxlogins should be set appropriately in /etc/security/limits.d/*.conf" test_ref="oval:ssg-test_limitsd_maxlogins:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="the value maxlogins should not be set at all in /etc/security/limits.d/*.conf" negate="true" test_ref="oval:ssg-test_limitsd_maxlogins_exists:tst:1"/>
              <oval-def:criterion comment="the value maxlogins should be set appropriately in /etc/security/limits.conf" test_ref="oval:ssg-test_maxlogins:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_polyinstantiated_tmp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure Polyinstantiation of /tmp Directories</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_polyinstantiated_tmp" source="ssg"/>
            <oval-def:description/>
          </oval-def:metadata>
          <oval-def:criteria comment="Check Polyinstantiation of /tmp Directories" operator="AND">
            <oval-def:criterion comment="Check that if /tmp/tmp-inst exists and has mode 000" test_ref="oval:ssg-test_tmp_inst:tst:1"/>
            <oval-def:criterion comment="Check configuration of /tmp in /etc/security/namespace.conf file" test_ref="oval:ssg-test_tmp_in_namespace_conf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_polyinstantiated_var_tmp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure Polyinstantiation of /var/tmp Directories</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_polyinstantiated_var_tmp" source="ssg"/>
            <oval-def:description/>
          </oval-def:metadata>
          <oval-def:criteria comment="Check Polyinstantiation of /tmp Directories" operator="AND">
            <oval-def:criterion comment="Check that /var/tmp/tmp-inst doesn't exist or it exists and has mode 000" test_ref="oval:ssg-test_var_tmp_tmp_inst:tst:1"/>
            <oval-def:criterion comment="Check configuration of /var/tmp in /etc/security/namespace.conf file" test_ref="oval:ssg-test_var_tmp_in_namespace_conf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_tmout:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Set Interactive Session Timeout</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_tmout" source="ssg"/>
            <oval-def:description>Checks interactive shell timeout</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="TMOUT value in /etc/profile &lt;= var_accounts_tmout" test_ref="oval:ssg-test_etc_profile_tmout:tst:1"/>
            <oval-def:criterion comment="TMOUT value in /etc/profile.d/*.sh &lt;= var_accounts_tmout" test_ref="oval:ssg-test_etc_profiled_tmout:tst:1"/>
            <oval-def:criterion comment="At least one config file has TMOUT defined" test_ref="oval:ssg-test_accounts_tmout_defined:tst:1"/>
            <oval-def:criterion comment="All configured TMOUT values must be &gt;= 1" test_ref="oval:ssg-test_accounts_tmout_lower_bound:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_user_dot_group_ownership:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>User Initialization Files Must Be Group-Owned By The Primary Group</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_user_dot_group_ownership" source="ssg"/>
            <oval-def:description>User Initialization Files Must Be Group-Owned By The Primary Group</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="User Initialization Files Must Be Group-Owned By The Primary Group" test_ref="oval:ssg-test_accounts_user_dot_group_ownership:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_user_dot_no_world_writable_programs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>User Initialization Files Must Not Run World-Writable Programs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_user_dot_no_world_writable_programs" source="ssg"/>
            <oval-def:description>User Initialization Files Must Not Execute World-Writable Programs</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="User Initialization Files Must Not Execute World-Writable Programs" test_ref="oval:ssg-test_accounts_user_dot_no_world_writable_programs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_user_dot_user_ownership:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>User Initialization Files Must Be Owned By the Primary User</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_user_dot_user_ownership" source="ssg"/>
            <oval-def:description>User Initialization Files Must Be Owned By the Primary User</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="User Initialization Files Must Be Owned By the Primary User" test_ref="oval:ssg-test_accounts_user_dot_user_ownership:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_user_interactive_home_directory_defined:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>All Interactive Users Must Have A Home Directory Defined</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_user_interactive_home_directory_defined" source="ssg"/>
            <oval-def:description>All Interactive Users Must Have A Home Directory Defined</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="All Interactive Users Must Have A Home Directory Defined" test_ref="oval:ssg-test_accounts_user_interactive_home_directory_defined:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_user_interactive_home_directory_exists:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>All Interactive Users Home Directories Must Exist</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_user_interactive_home_directory_exists" source="ssg"/>
            <oval-def:description>All Interactive Users Home Directories Must Exist</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="All Interactive Users Home Directories Must Exist" test_ref="oval:ssg-test_accounts_user_interactive_home_directory_exists:tst:1"/>
            <oval-def:criterion comment="Interactive users don't exist on the system" test_ref="oval:ssg-test_accounts_user_interactive_home_directory_exists_users:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_user_interactive_home_directory_on_separate_partition:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>All Interactive User Home Directories Must Reside On a Separate Partition</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_user_interactive_home_directory_on_separate_partition" source="ssg"/>
            <oval-def:description>All interactive user home directories must reside on a separate partition from root.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="All interactive user home directories are on a separate partition" test_ref="oval:ssg-test_accounts_user_interactive_home_directory_on_separate_partition:tst:1"/>
            <oval-def:criterion comment="No interactive users exist on the system" test_ref="oval:ssg-test_accounts_user_interactive_home_directory_on_separate_partition_no_interactive_users:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_users_home_files_groupownership:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>All User Files and Directories In The Home Directory Must Be Group-Owned By The Primary Group</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_users_home_files_groupownership" source="ssg"/>
            <oval-def:description>All User Files and Directories In The Home Directory Must Be Group-Owned By The Primary Group</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="All User Files and Directories In The Home Directory Must Be Group-Owned By The Primary Group" test_ref="oval:ssg-test_accounts_users_home_files_groupownership:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_users_home_files_ownership:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>All User Files and Directories In The Home Directory Must Have a Valid Owner</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_users_home_files_ownership" source="ssg"/>
            <oval-def:description>All User Files and Directories In The Home Directory Must Have a Valid Owner</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="All User Files and Directories In The Home Directory Must Have a Valid Owner" test_ref="oval:ssg-test_accounts_users_home_files_ownership:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_users_home_files_permissions:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>All User Files and Directories In The Home Directory Must Have Mode 0750 Or Less Permissive</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_users_home_files_permissions" source="ssg"/>
            <oval-def:description>All User Files and Directories In The Home Directory Must Have Mode 0750 Or Less Permissive</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="All files under interactive user's Home Directories must have proper permissions" test_ref="oval:ssg-test_accounts_users_home_files_permissions_files:tst:1"/>
            <oval-def:criterion comment="All directories under home directories must have proper permissions" test_ref="oval:ssg-test_accounts_users_home_files_permissions_dirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_users_netrc_file_permissions:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure users' .netrc Files are not group or world accessible</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_users_netrc_file_permissions" source="ssg"/>
            <oval-def:description>Netrc User File In The Home Directory Must Not be group or world
    accessible</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Netrc User File In The Home Directory Must Not be group or world                           accessible" test_ref="oval:ssg-test_accounts_users_home_netrc_file_permissions:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupownership_home_directories:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>All Interactive User Home Directories Must Be Group-Owned By The Primary Group</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupownership_home_directories" source="ssg"/>
            <oval-def:description>All interactive user's Home Directories must be group-owned by its user</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="All interactive user's Home Directories must be group-owned by its user" test_ref="oval:ssg-test_file_groupownership_home_directories:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_ownership_home_directories:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>All Interactive User Home Directories Must Be Owned By The Primary User</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_ownership_home_directories" source="ssg"/>
            <oval-def:description>All interactive user's Home Directories must be owned by its user</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="All interactive user's Home Directories must be owned by its user" test_ref="oval:ssg-test_file_ownership_home_directories:tst:1"/>
            <oval-def:criterion comment="Interactive users should own only one Home Directory" test_ref="oval:ssg-test_file_ownership_home_directories_duplicated:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permission_user_bash_history:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure User Bash History File Has Correct Permissions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permission_user_bash_history" source="ssg"/>
            <oval-def:description>User Bash History File Has Correct Permissions</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="User Bash History File Has Correct Permissions" test_ref="oval:ssg-test_file_permission_user_bash_history:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permission_user_init_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure All User Initialization Files Have Mode 0740 Or Less Permissive</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permission_user_init_files" source="ssg"/>
            <oval-def:description>User initialization files have mode 0740 or less permissive</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Initialization files have mode 0740 or less permissive" test_ref="oval:ssg-test_file_permission_user_init_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permission_user_init_files_root:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure All User Initialization Files Have Mode 0740 Or Less Permissive</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permission_user_init_files_root" source="ssg"/>
            <oval-def:description>User initialization files have mode 0740 or less permissive</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Initialization files have mode 0740 or less permissive" test_ref="oval:ssg-test_file_permission_user_init_files_root:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_home_directories:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>All Interactive User Home Directories Must Have mode 0750 Or Less Permissive</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_home_directories" source="ssg"/>
            <oval-def:description>All Interactive User Home Directories Must Have mode 0750 Or Less Permissive</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="All interactive user's Home Directories must have proper permissions" test_ref="oval:ssg-test_file_permissions_home_directories:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_home_dirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure that User Home Directories are not Group-Writable or World-Readable</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_home_dirs" source="ssg"/>
            <oval-def:description>Ensure that User Home Directories are not Group-Writable or World-Readable</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="home directories" test_ref="oval:ssg-test_file_permissions_home_dirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_root_path_dirs_no_write:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure that Root's Path Does Not Include World or Group-Writable Directories</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_root_path_dirs_no_write" source="ssg"/>
            <oval-def:description>Check each directory in root's path and make use it does
      not grant write permission to group and other</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check that write permission to group and other in root's path is denied" operator="AND">
            <oval-def:criterion comment="Check for write permission to group and other in root's path" test_ref="oval:ssg-test_accounts_root_path_dirs_no_group_other_write:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-root_path_no_dot:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure that Root's Path Does Not Include Relative Paths or Null Directories</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="root_path_no_dot" source="ssg"/>
            <oval-def:description>The environment variable PATH should be set correctly for
      the root user.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="environment variable PATH contains dangerous path" operator="AND">
            <oval-def:criterion comment="environment variable PATH starts with : or ." test_ref="oval:ssg-test_env_var_begins:tst:1"/>
            <oval-def:criterion comment="environment variable PATH contains : twice in a row" test_ref="oval:ssg-test_env_var_contains_doublecolon:tst:1"/>
            <oval-def:criterion comment="environment variable PATH contains . twice in a row" test_ref="oval:ssg-test_env_var_contains_doubleperiod:tst:1"/>
            <oval-def:criterion comment="environment variable PATH ends with : or ." test_ref="oval:ssg-test_env_var_ends:tst:1"/>
            <oval-def:criterion comment="environment variable PATH doesn't begin with a /" test_ref="oval:ssg-test_env_var_begins_slash:tst:1"/>
            <oval-def:criterion comment="environment variable PATH doesn't contain relative paths" test_ref="oval:ssg-test_env_var_contains_relative_path:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_umask_etc_bashrc:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure the Default Bash Umask is Set Correctly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_umask_etc_bashrc" source="ssg"/>
            <oval-def:description>The default umask for users of the bash shell</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Get value of var_accounts_user_umask variable as octal number" definition_ref="oval:ssg-var_accounts_user_umask_as_number:def:1"/>
            <oval-def:criterion test_ref="oval:ssg-tst_accounts_umask_etc_bashrc:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_umask_etc_csh_cshrc:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure the Default C Shell Umask is Set Correctly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_umask_etc_csh_cshrc" source="ssg"/>
            <oval-def:description>The default umask for users of the csh shell</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Get value of var_accounts_user_umask variable as octal number" definition_ref="oval:ssg-var_accounts_user_umask_as_number:def:1"/>
            <oval-def:criterion test_ref="oval:ssg-tst_accounts_umask_etc_csh_cshrc:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_umask_etc_login_defs:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure the Default Umask is Set Correctly in login.defs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_umask_etc_login_defs" source="ssg"/>
            <oval-def:description>The default umask for all users specified in {{{ login_defs_path }}}</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Get value of var_accounts_user_umask variable as octal number" definition_ref="oval:ssg-var_accounts_user_umask_as_number:def:1"/>
            <oval-def:criterion test_ref="oval:ssg-tst_accounts_umask_etc_login_defs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_umask_etc_profile:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure the Default Umask is Set Correctly in /etc/profile</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_umask_etc_profile" source="ssg"/>
            <oval-def:description>The default umask for all users should be set correctly</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="get value of var_accounts_user_umask variable as octal number" definition_ref="oval:ssg-var_accounts_user_umask_as_number:def:1"/>
            <oval-def:criterion test_ref="oval:ssg-tst_accounts_umask_etc_profile:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_umask_interactive_users:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure the Default Umask is Set Correctly For Interactive Users</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_umask_interactive_users" source="ssg"/>
            <oval-def:description>Ensure the Default Umask is Set Correctly For Interactive Users</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Ensure the Default Umask is Set Correctly For Interactive Users" test_ref="oval:ssg-test_accounts_umask_interactive_users:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_umask_root:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure the Root Bash Umask is Set Correctly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_umask_root" source="ssg"/>
            <oval-def:description>The umask for root user of the bash shell</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-tst_accounts_umask_root:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_disable_recovery:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Recovery Booting</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_disable_recovery" source="ssg"/>
            <oval-def:description>Recovery mode should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_kernel_trust_cpu_rng:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure kernel to trust the CPU random number generator</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_kernel_trust_cpu_rng" source="ssg"/>
            <oval-def:description>Ensure the kernel is configured to trust the CPU hardware random number generator.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="check if the option is compiled in" test_ref="oval:ssg-test_trust_cpu_rng_compiled_in:tst:1"/>
              <oval-def:criterion comment="check if the option is not overridden through a boot parameter" negate="true" test_ref="oval:ssg-test_trust_cpu_rng_boot_param_off:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="check if the option is configured as a boot parameter" test_ref="oval:ssg-test_trust_cpu_rng_boot_param_on:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_admin_username:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set the Boot Loader Admin Username to a Non-Default Value</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_admin_username" source="ssg"/>
            <oval-def:description>The grub2 boot loader superuser should have a username that is hard to guess.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="Superuser is defined in /boot/grub2/grub.cfg and it isn't             root, admin, administrator nor equal to any system username" test_ref="oval:ssg-test_bootloader_superuser_differ_from_other_users:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_no_removeable_media:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Boot Loader Is Not Installed On Removable Media</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_no_removeable_media" source="ssg"/>
            <oval-def:description>Ensure the system is not configured to use a boot loader on removable media.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Do not allow removable media to be used as the boot loader" operator="OR">
            <oval-def:criteria comment="All menuentry entries have a set root setting" operator="AND">
              <oval-def:criterion comment="Check the set root in /boot/grub2/grub.cfg" test_ref="oval:ssg-test_grub2_no_removeable_media:tst:1"/>
              <oval-def:criterion comment="Check the set root in /boot/grub2/grub.cfg for every menuentry" test_ref="oval:ssg-test_grub2_no_removeable_media_count:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Pass if there are no files matching pattern '/boot/grub2/grub.cfg' exist in the system" test_ref="oval:ssg-test_grub2_no_removeable_media_file_boot_grub2_grub_cfg_absent:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_password:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set Boot Loader Password in grub2</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_password" source="ssg"/>
            <oval-def:description>The grub2 boot loader should have password protection enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="make sure a password is defined in /boot/grub2/user.cfg" test_ref="oval:ssg-test_grub2_password_usercfg:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_uefi_admin_username:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set the UEFI Boot Loader Admin Username to a Non-Default Value</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_uefi_admin_username" source="ssg"/>
            <oval-def:description>The grub2 boot loader superuser should have a username that is hard to guess.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="Superuser is defined in /boot/efi/EFI/almalinux/grub.cfg and it             isn't root, admin, administrator nor equal to any system username" test_ref="oval:ssg-test_bootloader_uefi_superuser_differ_from_other_users:tst:1"/>
            <oval-def:criteria comment="check if /boot/efi/EFI/almalinux/grub.cfg is a stub pointing to /boot/grub2/grub.cfg" operator="AND">
              <oval-def:criterion comment="check if /boot/efi/EFI/almalinux/grub.cfg contains a configfile directive" test_ref="oval:ssg-test_grub2_uefi_admin_username_stub:tst:1"/>
              <oval-def:criterion comment="Superuser is defined in /boot/grub2/grub.cfg and it               isn't root, admin, administrator nor equal to any system username" test_ref="oval:ssg-test_bootloader_uefi_boot_superuser_differ_from_other_users:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_uefi_password:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set the UEFI Boot Loader Password</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_uefi_password" source="ssg"/>
            <oval-def:description>The UEFI grub2 boot loader should have password protection enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="make sure a password is defined in /boot/efi/EFI/almalinux/user.cfg" test_ref="oval:ssg-test_grub2_uefi_password_usercfg:tst:1"/>
            <oval-def:criteria comment="check if /boot/efi/EFI/almalinux/grub.cfg is a stub pointing to /boot/grub2/grub.cfg" operator="AND">
              <oval-def:criterion comment="check if /boot/efi/EFI/almalinux/grub.cfg contains a configfile directive" test_ref="oval:ssg-test_grub2_uefi_password_stub:tst:1"/>
              <oval-def:criterion comment="make sure a password is defined in /boot/grub2/user.cfg" test_ref="oval:ssg-test_grub2_uefi_password_boot_usercfg:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-uefi_no_removeable_media:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>UEFI Boot Loader Is Not Installed On Removable Media</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="uefi_no_removeable_media" source="ssg"/>
            <oval-def:description>Ensure the system is not configured to use a boot loader on removable media.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="The respective application or service is configured correctly or system boot mode is not UEFI" operator="OR">
            <oval-def:criteria comment="All menuentry entries have a set root setting" operator="AND">
              <oval-def:criterion comment="Check the set root in /boot/efi/EFI/almalinux/grub.cfg" test_ref="oval:ssg-test_uefi_no_removeable_media:tst:1"/>
              <oval-def:criterion comment="Check the set root in /boot/efi/EFI/almalinux/grub.cfg for every menuentry" test_ref="oval:ssg-test_uefi_no_removeable_media_count:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Pass if there are no files matching pattern '/boot/efi/EFI/almalinux/grub.cfg' exist in the system" test_ref="oval:ssg-test_uefi_no_removeable_media_file_boot_efi_EFI_almalinux_grub_cfg_absent:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-zipl_bls_entries_only:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure all zIPL boot entries are BLS compliant</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="zipl_bls_entries_only" source="ssg"/>
            <oval-def:description>Check if /etc/zipl.conf configures any boot entry</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Test presence of image configuration in /etc/zipl.conf" test_ref="oval:ssg-test_zipl_bls_entries_only:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-zipl_bootmap_is_up_to_date:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure zIPL bootmap is up to date</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="zipl_bootmap_is_up_to_date" source="ssg"/>
            <oval-def:description>Check if /boot/bootmap is up to date</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Compare mtime of /boot/bootmap against /etc/zipl.conf and /boot/loader/entries/*.conf" test_ref="oval:ssg-test_zipl_bootmap_is_up_to_date:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-zipl_systemd_debug-shell_argument_absent:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure debug-shell service is not enabled in zIPL</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="zipl_systemd_debug-shell_argument_absent" source="ssg"/>
            <oval-def:description>Ensure systemd.debug-shell option is not configured in the 'options' line in /boot/loader/entries/*.conf. Make sure that newly installed kernels won't have this option, it should not be configured in /etc/kernel/cmdline.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check if argument systemd.debug-shell for Linux kernel is not present in /boot/loader/entries/.*.conf" negate="true" test_ref="oval:ssg-test_zipl_systemd_debug-shell_argument_in_boot_loader_entries_conf:tst:1"/>
            <oval-def:criterion comment="Check if argument systemd.debug-shell for Linux kernel is not present in /etc/kernel/cmdline" negate="true" test_ref="oval:ssg-test_zipl_systemd_debug-shell_argument_in_etc_kernel_cmdline:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_default_mmap_min_addr:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure Low Address Space To Protect From User Allocation</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_default_mmap_min_addr" source="ssg"/>
            <oval-def:description>The kernel config CONFIG_DEFAULT_MMAP_MIN_ADDR should have value 65536 on x86_64 and 32768 on aarch64</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criteria operator="AND">
                <oval-def:criterion comment="Check architecture is x86_64" test_ref="oval:ssg-test_proc_sys_kernel_osrelease_arch_x86_64:tst:1"/>
                <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_default_mmap_min_addr_x86_64:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria operator="AND">
                <oval-def:criterion comment="Check architecture is aarch64" test_ref="oval:ssg-test_proc_sys_kernel_osrelease_arch_aarch64:tst:1"/>
                <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_default_mmap_min_addr_aarch64:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_kernel_config_default_mmap_min_addr_all_kernels:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rsyslog_filecreatemode:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure rsyslog Default File Permissions Configured</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rsyslog_filecreatemode" source="ssg"/>
            <oval-def:description>FileCreateMode setting controls permissions applied to newly created files.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="FileCreateMode declared once in either /etc/rsyslog.conf or /etc/rsyslog.d/*" test_ref="oval:ssg-tst_filecreatemode_declared:tst:1"/>
            <oval-def:criterion comment="FileCreateMode value is valid" test_ref="oval:ssg-tst_filecreatemode_valid:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-logwatch_configured_hostlimit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure Logwatch HostLimit Line</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="logwatch_configured_hostlimit" source="ssg"/>
            <oval-def:description>Test if HostLimit line in logwatch.conf is set appropriately.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Test value of HostLimit" test_ref="oval:ssg-test_logwatch_configured_hostlimit:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-logwatch_configured_splithosts:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure Logwatch SplitHosts Line</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="logwatch_configured_splithosts" source="ssg"/>
            <oval-def:description>Check if SplitHosts line in logwatch.conf is set appropriately.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Test value of SplitHosts" test_ref="oval:ssg-test_logwatch_configured_splithosts:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rsyslog_cron_logging:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure cron Is Logging To Rsyslog</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rsyslog_cron_logging" source="ssg"/>
            <oval-def:description>Rsyslog should be configured to capture cron messages.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="cron is configured in /etc/rsyslog.conf" test_ref="oval:ssg-test_cron_logging_rsyslog:tst:1"/>
            <oval-def:criterion comment="cron is configured in /etc/rsyslog.conf using RainerScript" test_ref="oval:ssg-test_cron_logging_rsyslog_rainer:tst:1"/>
            <oval-def:criterion comment="cron is configured in /etc/rsyslog.d" test_ref="oval:ssg-test_cron_logging_rsyslog_dir:tst:1"/>
            <oval-def:criterion comment="cron is configured in /etc/rsyslog.d using RainerScript" test_ref="oval:ssg-test_cron_logging_rsyslog_dir_rainer:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Rsyslog Authenticates Off-Loaded Audit Records</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rsyslog_encrypt_offload_actionsendstreamdriverauthmode" source="ssg"/>
            <oval-def:description>Rsyslogd must authenticate remote system its sending logs to.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="Check if $ActionSendStreamDriverAuthMode x509/name is set in /etc/rsyslog.conf" test_ref="oval:ssg-test_rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action_send_stream_driver_auth_mode:tst:1"/>
              <oval-def:criterion comment="Check if StreamDriverAuthMode is set to x509/name in /etc/rsyslog.conf using RainerScript" test_ref="oval:ssg-test_rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action_send_stream_driver_auth_mode_rainer:tst:1"/>
              <oval-def:criterion comment="Check if $ActionSendStreamDriverAuthMode x509/name is set in files in /etc/rsyslog.d" test_ref="oval:ssg-test_rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action_send_stream_driver_auth_mode_dir:tst:1"/>
              <oval-def:criterion comment="Check if StreamDriverAuthMode is set to x509/name in files in /etc/rsyslog.d using RainerScript" test_ref="oval:ssg-test_rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action_send_stream_driver_auth_mode_dir_rainer:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Rsyslog Encrypts Off-Loaded Audit Records</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rsyslog_encrypt_offload_actionsendstreamdrivermode" source="ssg"/>
            <oval-def:description>Rsyslogd must encrypt the off-loading of logs off of the system.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="Check if $ActionSendStreamDriverMode 1 is set in /etc/rsyslog.conf" test_ref="oval:ssg-test_rsyslog_encrypt_offload_actionsendstreamdrivermode_action_send_stream_driver_mode_rsyslog:tst:1"/>
              <oval-def:criterion comment="Check if StreamDriverMode is set to 1 in /etc/rsyslog.conf using RainerScript" test_ref="oval:ssg-test_rsyslog_encrypt_offload_actionsendstreamdrivermode_action_send_stream_driver_mode_rsyslog_rainer:tst:1"/>
              <oval-def:criterion comment="Check if $ActionSendStreamDriverMode 1 is set in files in /etc/rsyslog.d" test_ref="oval:ssg-test_rsyslog_encrypt_offload_actionsendstreamdrivermode_action_send_stream_driver_mode_rsyslog_dir:tst:1"/>
              <oval-def:criterion comment="Check if StreamDriverMode is set to 1 in files in /etc/rsyslog.d using RainerScript" test_ref="oval:ssg-test_rsyslog_encrypt_offload_actionsendstreamdrivermode_action_send_stream_driver_mode_rsyslog_dir_rainer:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Rsyslog Encrypts Off-Loaded Audit Records</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rsyslog_encrypt_offload_defaultnetstreamdriver" source="ssg"/>
            <oval-def:description>Rsyslogd must encrypt the off-loading of logs off of the system.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="Check if $DefaultNetstreamDriver gtls is set in /etc/rsyslog.conf" test_ref="oval:ssg-test_rsyslog_encrypt_offload_defaultnetstreamdriver_default_netstream_rsyslog:tst:1"/>
              <oval-def:criterion comment="Check if DefaultNetstreamDriver is set to gtls in /etc/rsyslog.conf using RainerScript" test_ref="oval:ssg-test_rsyslog_encrypt_offload_defaultnetstreamdriver_default_netstream_rsyslog_rainer:tst:1"/>
              <oval-def:criterion comment="Check if $DefaultNetstreamDriver gtls is set in files in /etc/rsyslog.d" test_ref="oval:ssg-test_rsyslog_encrypt_offload_defaultnetstreamdriver_default_netstream_rsyslog_dir:tst:1"/>
              <oval-def:criterion comment="Check if DefaultNetstreamDriver is set to gtls in files in /etc/rsyslog.d using RainerScript" test_ref="oval:ssg-test_rsyslog_encrypt_offload_defaultnetstreamdriver_default_netstream_rsyslog_dir_rainer:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rsyslog_logging_configured:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure logging is configured</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rsyslog_logging_configured" source="ssg"/>
            <oval-def:description>Syslog logs should be configured</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="Logging configured within /etc/rsyslog.conf" test_ref="oval:ssg-test_logging_configured_rsyslog_conf:tst:1"/>
              <oval-def:criterion comment="Remote logging set within /etc/rsyslog.d" test_ref="oval:ssg-test_logging_configured_rsyslog_d:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rsyslog_remote_access_monitoring:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure remote access methods are monitored in Rsyslog</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rsyslog_remote_access_monitoring" source="ssg"/>
            <oval-def:description>Rsyslog should be configured to monitor remote access methods.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="remote access methods are configured in rsyslog" operator="AND">
            <oval-def:criterion comment="ensure 'auth.*' remote method is configured in rsyslog" test_ref="oval:ssg-test_remote_method_monitoring_auth:tst:1"/>
            <oval-def:criterion comment="ensure 'authpriv.*' remote method is configured in rsyslog" test_ref="oval:ssg-test_remote_method_monitoring_authpriv:tst:1"/>
            <oval-def:criterion comment="ensure 'daemon.*' remote method is configured in rsyslog" test_ref="oval:ssg-test_remote_method_monitoring_daemon:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ensure_logrotate_activated:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Logrotate Runs Periodically</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ensure_logrotate_activated" source="ssg"/>
            <oval-def:description>
      The frequency of automatic log files rotation performed by the logrotate utility should be configured to run daily
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="/etc/logrotate.conf contains daily setting and /etc/cron.daily/logrotate file exists" operator="AND">
            <oval-def:extend_definition comment="package logrotate installed" definition_ref="oval:ssg-package_logrotate_installed:def:1"/>
            <oval-def:criterion comment="Check if daily is set in /etc/logrotate.conf" test_ref="oval:ssg-test_logrotate_conf_daily_setting:tst:1"/>
            <oval-def:criterion comment="check that there is no weekly/monthly/yearly keyword in logrotate.conf" test_ref="oval:ssg-test_logrotate_conf_no_other_keyword:tst:1"/>
            <oval-def:criteria comment="Check if either logrotate timer or cron job is enabled" operator="OR">
              <oval-def:criterion comment="Check if /etc/cron.daily/logrotate file exists (and calls logrotate)" test_ref="oval:ssg-test_cron_daily_logrotate_existence:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rsyslog_nolisten:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Ensure rsyslog Does Not Accept Remote Messages Unless Acting As Log Server</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rsyslog_nolisten" source="ssg"/>
            <oval-def:description>rsyslogd should reject remote messages</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="rsyslog legacy syntax is not configured to accept remote messages" test_ref="oval:ssg-test_rsyslog_nolisten_legacy:tst:1"/>
            <oval-def:criterion comment="rsyslog RainerScript is not configured to accept remote messages" test_ref="oval:ssg-test_rsyslog_nolisten_rainerscript:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rsyslog_remote_loghost:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Logs Sent To Remote Host</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rsyslog_remote_loghost" source="ssg"/>
            <oval-def:description>Syslog logs should be sent to a remote loghost</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="Remote logging set within /etc/rsyslog.conf" test_ref="oval:ssg-test_remote_rsyslog_conf:tst:1"/>
            <oval-def:criterion comment="Remote logging set within /etc/rsyslog.d" test_ref="oval:ssg-test_remote_rsyslog_d:tst:1"/>
            <oval-def:criterion comment="Remote logging set within /etc/rsyslog.conf in RainerScript" test_ref="oval:ssg-test_remote_rsyslog_conf_rainer:tst:1"/>
            <oval-def:criterion comment="Remote logging set within /etc/rsyslog.d through RainerScript" test_ref="oval:ssg-test_remote_rsyslog_d_rainer:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rsyslog_remote_tls:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure TLS for rsyslog remote logging</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rsyslog_remote_tls" source="ssg"/>
            <oval-def:description>Check that all needed TLS-related options are present</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check that rsyslog is configured to use TLS for remote logging" operator="AND">
            <oval-def:criterion comment="Check that all needed TLS-related options are present" test_ref="oval:ssg-test_rsyslog_remote_tls:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rsyslog_remote_tls_cacert:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure CA certificate for rsyslog remote logging</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rsyslog_remote_tls_cacert" source="ssg"/>
            <oval-def:description>Check that the CA certificate path is set</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check that CA certificate is configured for rsyslog remote logging" operator="AND">
            <oval-def:criterion comment="Check that the CA certificate path is set" test_ref="oval:ssg-test_rsyslog_remote_tls_cacert:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-network_configure_name_resolution:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure Multiple DNS Servers in /etc/resolv.conf</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="network_configure_name_resolution" source="ssg"/>
            <oval-def:description>Multiple Domain Name System (DNS) Servers should be configured
      in /etc/resolv.conf.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="check if more than one nameserver in /etc/resolv.conf" test_ref="oval:ssg-test_network_configure_name_resolution:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-network_disable_ddns_interfaces:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Client Dynamic DNS Updates</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="network_disable_ddns_interfaces" source="ssg"/>
            <oval-def:description>Clients should not automatically update their own
      DNS record.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_network_disable_ddns_interfaces_ifcfg:tst:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_network_disable_ddns_interfaces_dhclient:tst:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_network_disable_ddns_interfaces_dhcp:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-network_disable_zeroconf:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Zeroconf Networking</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="network_disable_zeroconf" source="ssg"/>
            <oval-def:description>Disable Zeroconf automatic route assignment in the
      169.254.0.0 subnet.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Look for NOZEROCONF=yes in /etc/sysconfig/network" test_ref="oval:ssg-test_sysconfig_nozeroconf_yes:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-network_nmcli_permissions:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Prevent non-Privileged Users from Modifying Network Interfaces using nmcli</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="network_nmcli_permissions" source="ssg"/>
            <oval-def:description>polkit is properly configured to prevent non-privileged users from changing networking settings</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="check for properly configured .pkla file" test_ref="oval:ssg-test_network_nmcli_permissions:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-network_sniffer_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure System is Not Acting as a Network Sniffer</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="network_sniffer_disabled" source="ssg"/>
            <oval-def:description>Disable the network sniffer</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="promisc interfaces" negate="true" test_ref="oval:ssg-test_promisc_interfaces:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firewalld_loopback_traffic_restricted:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure Firewalld to Restrict Loopback Traffic</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="firewalld_loopback_traffic_restricted" source="ssg"/>
            <oval-def:description>Configure Firewalld to Restrict Loopback Traffic</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Ensure default trusted zone file was not overridden" test_ref="oval:ssg-test_firewalld_trusted_zone_not_overridden:tst:1"/>
              <oval-def:criterion comment="Ensure default trusted restrict loopback source" test_ref="oval:ssg-test_firewalld_loopback_restricted_source_usr:tst:1"/>
              <oval-def:criterion comment="Ensure default trusted zone restrict loopback destination" test_ref="oval:ssg-test_firewalld_loopback_restricted_destination_usr:tst:1"/>
              <oval-def:criterion comment="Ensure default trusted zone restrict loopback traffic" test_ref="oval:ssg-test_firewalld_loopback_restricted_policy_usr:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Ensure custom trusted zone restrict loopback source" test_ref="oval:ssg-test_firewalld_loopback_restricted_source_etc:tst:1"/>
              <oval-def:criterion comment="Ensure custom trusted zone zone restrict loopback destination" test_ref="oval:ssg-test_firewalld_loopback_restricted_destination_etc:tst:1"/>
              <oval-def:criterion comment="Ensure custom trusted zone zone restrict loopback traffic" test_ref="oval:ssg-test_firewalld_loopback_restricted_policy_etc:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firewalld_loopback_traffic_trusted:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure Firewalld to Trust Loopback Traffic</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="firewalld_loopback_traffic_trusted" source="ssg"/>
            <oval-def:description>Configure Firewalld to Trust Loopback Traffic</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Ensure default trusted zone file has lo interface defined" test_ref="oval:ssg-test_firewalld_lo_interface_trusted_usr:tst:1"/>
              <oval-def:criterion comment="Ensure default trusted zone file was not overridden" test_ref="oval:ssg-test_firewalld_trusted_zone_not_overridden:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Ensure custom trusted zone file has lo interface defined" test_ref="oval:ssg-test_firewalld_lo_interface_trusted_etc:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-network_ipv6_default_gateway:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Manually Assign IPv6 Router Address</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="network_ipv6_default_gateway" source="ssg"/>
            <oval-def:description>Define default gateways for IPv6 traffic</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="IPv6 disabled or..." definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criterion comment="Define default gateways" test_ref="oval:ssg-test_network_ipv6_default_gateway:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-network_ipv6_privacy_extensions:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Use Privacy Extensions for Address</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="network_ipv6_privacy_extensions" source="ssg"/>
            <oval-def:description>Enable privacy extensions for IPv6</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="IPv6 disabled or..." definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criterion comment="Enable privacy extensions per interface" test_ref="oval:ssg-test_network_ipv6_privacy_extensions:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-network_ipv6_static_address:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Manually Assign Global IPv6 Address</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="network_ipv6_static_address" source="ssg"/>
            <oval-def:description>Manually configure addresses for IPv6</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="IPv6 disabled or..." definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criterion comment="Set static IPv6 address on each interface" test_ref="oval:ssg-test_network_ipv6_static_address:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_ipv6_option_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable IPv6 Networking Support Automatic Loading</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_ipv6_option_disabled" source="ssg"/>
            <oval-def:description>The disable option will allow the IPv6 module to be inserted, but prevent address assignment and activation of the network stack.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="ipv6 disabled any modprobe conf file" test_ref="oval:ssg-test_kernel_module_ipv6_option_disabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-network_ipv6_disable_rpc:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Support for RPC IPv6</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="network_ipv6_disable_rpc" source="ssg"/>
            <oval-def:description>Disable ipv6 based rpc services</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Disable udp6" test_ref="oval:ssg-test_network_ipv6_disable_rpc_udp6:tst:1"/>
            <oval-def:criterion comment="Disable tcp6" test_ref="oval:ssg-test_network_ipv6_disable_rpc_tcp6:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-wireless_disable_interfaces:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Deactivate Wireless Network Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="wireless_disable_interfaces" source="ssg"/>
            <oval-def:description>All wireless interfaces should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="check if wifi interfaces are disabled" negate="true" test_ref="oval:ssg-test_wireless_disable_interfaces:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dir_perms_world_writable_root_owned:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure All World-Writable Directories Are Owned by root User</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dir_perms_world_writable_root_owned" source="ssg"/>
            <oval-def:description>All world writable directories should be owned by root.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria negate="true" operator="AND">
            <oval-def:criterion comment="check for local directories that are world writable and owner is not root" test_ref="oval:ssg-test_dir_world_writable_uid_gt_zero:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dir_perms_world_writable_sticky_bits:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Verify that All World-Writable Directories Have Sticky Bits Set</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dir_perms_world_writable_sticky_bits" source="ssg"/>
            <oval-def:description>The sticky bit should be set for all world-writable directories.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="All local world-writable directories have sticky bit set" test_ref="oval:ssg-test_dir_perms_world_writable_sticky_bits:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dir_perms_world_writable_system_owned:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure All World-Writable Directories Are Owned by a System Account</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dir_perms_world_writable_system_owned" source="ssg"/>
            <oval-def:description>All world writable directories should be owned by a system account.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check world-writable directories with uid greater than or equal to 1000" test_ref="oval:ssg-test_dir_perms_world_writable_system_owned:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dir_perms_world_writable_system_owned_group:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure All World-Writable Directories Are Group Owned by a System Account</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dir_perms_world_writable_system_owned_group" source="ssg"/>
            <oval-def:description>All world writable directories should be group owned by a system user.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="check for local directories that are world writable and have gid greater than or equal to 1000" negate="true" operator="AND">
            <oval-def:criterion comment="check for local directories that are world writable and have gid greater than or equal to 1000" test_ref="oval:ssg-test_dir_world_writable_gid_gt_value:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dir_system_commands_group_root_owned:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify that system commands directories have root as a group owner</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dir_system_commands_group_root_owned" source="ssg"/>
            <oval-def:description>
        Checks that directories /bin /sbin /usr/bin /usr/sbin /usr/local/bin /usr/local/sbin
        have root as a group owner
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_group_ownership_system_commands_dirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dir_system_commands_root_owned:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify that system commands directories have root ownership</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dir_system_commands_root_owned" source="ssg"/>
            <oval-def:description>
        Checks that directories /bin /sbin /usr/bin /usr/sbin /usr/local/bin /usr/local/sbin
        are owned by root.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="system commands directories are root owned" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_ownership_system_commands_directory_bin:tst:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_ownership_system_commands_directory_sbin:tst:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_ownership_system_commands_directory_usr_bin:tst:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_ownership_system_commands_directory_usr_sbin:tst:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_ownership_system_commands_directory_usr_local_bin:tst:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_ownership_system_commands_directory_usr_local_sbin:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_unauthorized_sgid:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure All SGID Executables Are Authorized</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_unauthorized_sgid" source="ssg"/>
            <oval-def:description>Evaluates to true if all files with SGID set are owned by RPM packages.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check if all sgid files present in the system are authorized" test_ref="oval:ssg-test_file_permissions_unauthorized_sgid:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_unauthorized_suid:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure All SUID Executables Are Authorized</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_unauthorized_suid" source="ssg"/>
            <oval-def:description>Evaluates to true if all files with SUID set are owned by RPM packages.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check if all suid files present in the system are authorized" test_ref="oval:ssg-test_file_permissions_unauthorized_suid:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_unauthorized_world_writable:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure No World-Writable Files Exist</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_unauthorized_world_writable" source="ssg"/>
            <oval-def:description>The world-write permission should be disabled for all files.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_file_permissions_unauthorized_world_write:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_ungroupowned:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure All Files Are Owned by a Group</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_ungroupowned" source="ssg"/>
            <oval-def:description>All files should be owned by a group</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria negate="true" operator="AND">
                <oval-def:criterion comment="The /etc/nsswitch.conf uses nss-altfiles" test_ref="oval:ssg-test_file_permissions_ungroupowned_nsswitch_uses_altfiles:tst:1"/>
                <oval-def:criterion comment="Check if nss-altfiles package is installed" test_ref="oval:ssg-test_file_permissions_ungroupowned_package_nss-altfiles_installed:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="Check all local files and make sure they are owned by a group" test_ref="oval:ssg-test_file_permissions_ungroupowned:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="AND">
                <oval-def:criterion comment="The /etc/nsswitch.conf uses nss-altfiles" test_ref="oval:ssg-test_file_permissions_ungroupowned_nsswitch_uses_altfiles:tst:1"/>
                <oval-def:criterion comment="Check if nss-altfiles package is installed" test_ref="oval:ssg-test_file_permissions_ungroupowned_package_nss-altfiles_installed:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="Check all local files and make sure they are owned by a group" test_ref="oval:ssg-test_file_permissions_ungroupowned_with_usrlib:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_files_or_dirs_ungroupowned:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure All Files And Directories Are Owned by a Group</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_files_or_dirs_ungroupowned" source="ssg"/>
            <oval-def:description>All files should be owned by a group</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria negate="true" operator="AND">
                <oval-def:criterion comment="The /etc/nsswitch.conf uses nss-altfiles" test_ref="oval:ssg-test_no_files_or_dirs_ungroupowned_nsswitch_uses_altfiles:tst:1"/>
                <oval-def:criterion comment="Check if nss-altfiles package is installed" test_ref="oval:ssg-test_no_files_or_dirs_ungroupowned_package_nss-altfiles_installed:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="Check all local files and make sure they are owned by a group" test_ref="oval:ssg-test_no_files_or_dirs_ungroupowned:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="AND">
                <oval-def:criterion comment="The /etc/nsswitch.conf uses nss-altfiles" test_ref="oval:ssg-test_no_files_or_dirs_ungroupowned_nsswitch_uses_altfiles:tst:1"/>
                <oval-def:criterion comment="Check if nss-altfiles package is installed" test_ref="oval:ssg-test_no_files_or_dirs_ungroupowned_package_nss-altfiles_installed:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="Check all local files and make sure they are owned by a group" test_ref="oval:ssg-test_no_files_or_dirs_ungroupowned_with_usrlib:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_files_or_dirs_unowned_by_user:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure All Files And Directories Are Owned by a User</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_files_or_dirs_unowned_by_user" source="ssg"/>
            <oval-def:description>All files should be owned by a user</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check all files and make sure they are owned by a user" test_ref="oval:ssg-test_no_files_or_dirs_unowned_by_user:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_files_unowned_by_user:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure All Files Are Owned by a User</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_files_unowned_by_user" source="ssg"/>
            <oval-def:description>All files should be owned by a user</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check all files and make sure they are owned by a user" test_ref="oval:ssg-test_no_files_unowned_by_user:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_etc_security_opasswd:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions and Ownership of Old Passwords File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_etc_security_opasswd" source="ssg"/>
            <oval-def:description>Verify Permissions and Ownership of Old Passwords File</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="root should own /etc/security/opasswd" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_file_etc_security_opasswd:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupownership_system_commands_dirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify that system commands files are group owned by root or a system account</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupownership_system_commands_dirs" source="ssg"/>
            <oval-def:description>
        Checks that system commands in /bin /sbin /usr/bin /usr/sbin /usr/local/bin /usr/local/sbin 
        are owned by root group or a system account.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_groupownership_system_commands_dirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_ownership_binary_dirs:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Verify that System Executables Have Root Ownership</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_ownership_binary_dirs" source="ssg"/>
            <oval-def:description>
        Checks that /bin, /sbin, /usr/bin, /usr/sbin, /usr/local/bin,
        /usr/local/sbin, /usr/libexec, and objects therein, are owned by root.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_ownership_binary_directories:tst:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_ownership_binary_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_binary_dirs:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Verify that System Executables Have Restrictive Permissions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_binary_dirs" source="ssg"/>
            <oval-def:description>
        Checks that binary files under /bin, /sbin, /usr/bin, /usr/sbin,
        /usr/local/bin, /usr/local/sbin, and /usr/libexec are not group-writable or world-writable.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_perms_binary_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rootfiles_configured:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure rootfiles tmpfile.d is Configured Correctly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rootfiles_configured" source="ssg"/>
            <oval-def:description>Ensure that tmpfiles for rootfiles is configured correctly.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Ensure that tmpfiles for rootfiles is configured correctly." operator="AND">
            <oval-def:criterion comment="Check that /root/.bash_logout is configured correctly" test_ref="oval:ssg-test_rootfiles_configured_bash_logout:tst:1"/>
            <oval-def:criterion comment="Check that /root/.bash_profile is configured correctly" test_ref="oval:ssg-test_rootfiles_configured_bash_profile:tst:1"/>
            <oval-def:criterion comment="Check that /root/.bashrc is configured correctly" test_ref="oval:ssg-test_rootfiles_configured_bashrc:tst:1"/>
            <oval-def:criterion comment="Check that /root/.cshrc is configured correctly" test_ref="oval:ssg-test_rootfiles_configured_cshrc:tst:1"/>
            <oval-def:criterion comment="Check that /root/.tcshrc is configured correctly" test_ref="oval:ssg-test_rootfiles_configured_tcshrc:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_nodev_nonroot_local_partitions:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Add nodev Option to Non-Root Local Partitions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_nodev_nonroot_local_partitions" source="ssg"/>
            <oval-def:description>The nodev mount option prevents files from being interpreted
      as character or block devices. Legitimate character and block devices
      should exist in the /dev directory on the root partition or within chroot
      jails built for system services. All other locations should not allow
      character and block devices.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="nodev on local filesystems" negate="true" test_ref="oval:ssg-test_nodev_nonroot_local_partitions:tst:1"/>
            <oval-def:criterion comment="nodev on local filesystems in /etc/fstab" test_ref="oval:ssg-test_nodev_nonroot_local_partitions_in_fstab:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_var_tmp_bind:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Bind Mount /var/tmp To /tmp</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_var_tmp_bind" source="ssg"/>
            <oval-def:description>The /var/tmp directory should be bind mounted to /tmp in
      order to consolidate temporary storage into one location protected by the
      same techniques as /tmp.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Ensure /var/tmp is configured to bind mount to /tmp" test_ref="oval:ssg-test_configure_mount_option_var_tmp_bind_tmp:tst:1"/>
            <oval-def:criterion comment="Ensure /var/tmp is mounted" test_ref="oval:ssg-test_mount_option_var_tmp:tst:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="Ensure /var/tmp is mounted and binded" test_ref="oval:ssg-test_mount_option_var_tmp_bind:tst:1"/>
              <oval-def:criterion comment="Ensure /var/tmp and /tmp have the same source device" test_ref="oval:ssg-test_mount_option_var_tmp_bind_compare_source:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-disable_users_coredumps:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Core Dumps for All Users</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="disable_users_coredumps" source="ssg"/>
            <oval-def:description>Core dumps for all users should be disabled</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="Are core dumps disabled in /etc/security/limits.d/*" test_ref="oval:ssg-test_core_dumps_limits_d:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Are core dumps configured in /etc/security/limits.d/*" negate="true" test_ref="oval:ssg-test_core_dumps_limits_d_exists:tst:1"/>
              <oval-def:criterion comment="Are core dumps disabled in /etc/security/limits.conf" test_ref="oval:ssg-test_core_dumps_limitsconf:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-umask_for_daemons:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Set Daemon Umask</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="umask_for_daemons" source="ssg"/>
            <oval-def:description>The daemon umask should be set as appropriate</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Get value of var_accounts_user_umask variable as octal number" definition_ref="oval:ssg-var_umask_for_daemons_as_number:def:1"/>
            <oval-def:criterion test_ref="oval:ssg-tst_umask_for_daemons:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_exec_shield:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Enable ExecShield via sysctl</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_exec_shield" source="ssg"/>
            <oval-def:description>The kernel runtime parameter 'kernel.exec-shield' should not be disabled and set to 1 on 32-bit systems.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="32-bit system" definition_ref="oval:ssg-system_info_architecture_x86:def:1"/>
              <oval-def:criterion comment="kernel runtime parameter kernel.exec-shield set to 1" test_ref="oval:ssg-test_runtime_sysctl_kernel_exec_shield:tst:1"/>
              <oval-def:criterion comment="kernel /etc/sysctl.conf parameter kernel.exec-shield set to 1" test_ref="oval:ssg-test_static_sysctl_kernel_exec_shield:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1"/>
              <oval-def:criterion comment="NX is supported and is not disabled" test_ref="oval:ssg-test_nx_disabled_grub:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-bios_enable_execution_restrictions:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Enable NX or XD Support in the BIOS</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="bios_enable_execution_restrictions" source="ssg"/>
            <oval-def:description>The NX (no-execution) bit flag should be set on the system.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="NX bit is set" test_ref="oval:ssg-test_NX_cpu_support:tst:1"/>
            <oval-def:criterion comment="NX is not disabled in the kernel command line" test_ref="oval:ssg-test_noexec_cmd_line:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-install_PAE_kernel_on_x86-32:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Install PAE Kernel on Supported 32-bit x86 Systems</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="install_PAE_kernel_on_x86-32" source="ssg"/>
            <oval-def:description>The RPM package kernel-PAE should be installed on 32-bit
      systems.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="Not a 32-bit system" definition_ref="oval:ssg-system_info_architecture_x86:def:1" negate="true"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="Check if PAE or NX is supported by the CPUs" negate="true" test_ref="oval:ssg-test_PAE_NX_cpu_support:tst:1"/>
              <oval-def:criteria operator="AND">
                <oval-def:extend_definition comment="A 32-bit system" definition_ref="oval:ssg-system_info_architecture_x86:def:1"/>
                <oval-def:criterion comment="Package kernel-PAE is installed" test_ref="oval:ssg-test_package_kernel-PAE_installed:tst:1"/>
                <oval-def:criterion comment="check for DEFAULTKERNEL set to kernel-PAE in /etc/sysconfig/kernel" test_ref="oval:ssg-test_defaultkernel_sysconfig_kernel:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_enable_selinux:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure SELinux Not Disabled in /etc/default/grub</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_enable_selinux" source="ssg"/>
            <oval-def:description>
        Check if selinux=0 OR enforcing=0 within the GRUB2 configuration files, fail if found.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="check value selinux|enforcing=0 in /etc/default/grub, fail if found" test_ref="oval:ssg-test_selinux_default_grub:tst:1"/>
            <oval-def:criterion comment="check value selinux|enforcing=0 in /etc/grub2.cfg, fail if found" test_ref="oval:ssg-test_selinux_grub2_cfg:tst:1"/>
            <oval-def:criterion comment="check value selinux|enforcing=0 in /etc/grub.d, fail if found" test_ref="oval:ssg-test_selinux_grub_dir:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-selinux_all_devicefiles_labeled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure No Device Files are Unlabeled by SELinux</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="selinux_all_devicefiles_labeled" source="ssg"/>
            <oval-def:description>All device files in /dev should be assigned an SELinux security context other than 'device_t' and 'unlabeled_t'.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="device_t in /dev" test_ref="oval:ssg-test_selinux_dev_device_t:tst:1"/>
            <oval-def:criterion comment="unlabeled_t in /dev" test_ref="oval:ssg-test_selinux_dev_unlabeled_t:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-selinux_confinement_of_daemons:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure No Daemons are Unconfined by SELinux</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="selinux_confinement_of_daemons" source="ssg"/>
            <oval-def:description>All pids in /proc should be assigned an SELinux security context other than 'unconfined_service_t'.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="no unconfined_service_t in /proc" test_ref="oval:ssg-test_selinux_confinement_of_daemons:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-selinux_context_elevation_for_sudo:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Elevate The SELinux Context When An Administrator Calls The Sudo Command</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="selinux_context_elevation_for_sudo" source="ssg"/>
            <oval-def:description>Elevate The SELinux Context When An Administrator Calls The Sudo Command</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Sudo elevate the SELinux type and role to sysadm_t and sysadm_r" operator="AND">
            <oval-def:criterion comment="check configuration in /etc/sudoers and /etc/sudoers.d/*" test_ref="oval:ssg-test_sudo_selinux_elevation_type:tst:1"/>
            <oval-def:criterion comment="check configuration in /etc/sudoers and /etc/sudoers.d/*" test_ref="oval:ssg-test_sudo_selinux_elevation_role:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-selinux_not_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure SELinux is Not Disabled</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="selinux_not_disabled" source="ssg"/>
            <oval-def:description>SELinux is not Disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="SELinux is not disabled" test_ref="oval:ssg-test_selinux_not_disabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-selinux_state:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure SELinux State is Enforcing</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="selinux_state" source="ssg"/>
            <oval-def:description>The SELinux state should be enforcing the local policy.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="enforce is disabled" test_ref="oval:ssg-test_etc_selinux_config:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-prefer_64bit_os:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Prefer to use a 64-bit Operating System when supported</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="prefer_64bit_os" source="ssg"/>
            <oval-def:description>Check if the system supports a 64-bit Operating System</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Either the OS is 64-bit, or the CPU doesn't support 64-bit (it is 32 or 16 bit)" operator="OR">
            <oval-def:criteria comment="Either check osrelease in procfs, or kernel package arch parameter" operator="OR">
              <oval-def:criterion comment="Check if OS is 64-bit" test_ref="oval:ssg-test_proc_sys_kernel_osrelease_64_bit:tst:1"/>
              <oval-def:criterion comment="Check kernel rpm is x86_64" test_ref="oval:ssg-test_package_kernel_x64:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check if CPU is not 64-bit" negate="true" test_ref="oval:ssg-test_proc_cpuinfo_64_bit:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_db_up_to_date:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Make sure that the dconf databases are up-to-date with regards to respective keyfiles</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_db_up_to_date" source="ssg"/>
            <oval-def:description>Make sure that the dconf databases are up-to-date with regards to respective keyfiles.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="check that all DBs in question are up-to-date" operator="AND">
              <oval-def:criteria comment="check that all DBs in question are up-to-date" operator="OR">
                <oval-def:criterion comment="gdm database is up-to-date wrt keyfiles" test_ref="oval:ssg-test_dconf_gdm_up_to_date:tst:1"/>
                <oval-def:criterion comment="no keyfiles applicable to the gdm database" test_ref="oval:ssg-test_dconf_gdm_no_keyfiles:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="check that all DBs in question are up-to-date" operator="OR">
                <oval-def:criterion comment="local database is up-to-date wrt keyfiles" test_ref="oval:ssg-test_dconf_local_up_to_date:tst:1"/>
                <oval-def:criterion comment="no keyfiles applicable to the local database" test_ref="oval:ssg-test_dconf_local_no_keyfiles:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-enable_dconf_user_profile:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure GNOME3 DConf User Profile</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="enable_dconf_user_profile" source="ssg"/>
            <oval-def:description>The DConf User profile should have the local DB configured.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criterion comment="dconf user profile exists" test_ref="oval:ssg-test_dconf_user_profile:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-xwayland_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable XWayland</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="xwayland_disabled" source="ssg"/>
            <oval-def:description>Ensure 'WaylandEnable' is configured with value 'false in section 'daemon' in /etc/gdm/custom.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="gdm is configured correctly and configuration file exists" operator="AND">
            <oval-def:criteria comment="gdm is configured correctly" operator="OR">
              <oval-def:criterion comment="Check the WaylandEnable in /etc/gdm/custom.conf" test_ref="oval:ssg-test_xwayland_disabled:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="test if configuration file /etc/gdm/custom.conf exists for xwayland_disabled" test_ref="oval:ssg-test_xwayland_disabled_config_file_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_disable_restart_shutdown:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the GNOME3 Login Restart and Shutdown Buttons</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_disable_restart_shutdown" source="ssg"/>
            <oval-def:description>Disable the GNOME3 Login GUI Restart and Shutdown buttons to all users on the login screen.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="Disable GUI shutdown and restart buttons and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="Disable restart and shutdown buttons" test_ref="oval:ssg-test_disable_restart_buttons:tst:1"/>
              <oval-def:criterion comment="Prevent user from changing" test_ref="oval:ssg-test_prevent_user_enable_restart_buttons:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_disable_user_list:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the GNOME3 Login User List</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_disable_user_list" source="ssg"/>
            <oval-def:description>Disable the GNOME3 GUI listing of all known users on the login screen.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="Disable GUI listing of known users and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="Disable user list" test_ref="oval:ssg-test_disable_user_list:tst:1"/>
              <oval-def:criterion comment="Prevent user from disabling banner" test_ref="oval:ssg-test_prevent_user_disable_user_list:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_enable_smartcard_auth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the GNOME3 Login Smartcard Authentication</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_enable_smartcard_auth" source="ssg"/>
            <oval-def:description>Enable smartcard authentication in the GNOME3 Login GUI.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="Enable smartcard authentication and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="Enable smartcard authentication" test_ref="oval:ssg-test_enable_gnome_smartcard:tst:1"/>
              <oval-def:criterion comment="Prevent user from changing" test_ref="oval:ssg-test_prevent_user_disable_smartcard:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_login_retries:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set the GNOME3 Login Number of Failures</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_login_retries" source="ssg"/>
            <oval-def:description>Set the GNOME3 number of login failure attempts.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="Set number of login attempts and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="Set number of login tries" test_ref="oval:ssg-test_configure_allowed_failures:tst:1"/>
              <oval-def:criterion comment="Prevent user from changing" test_ref="oval:ssg-test_prevent_user_allowed-failures_change:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-gnome_gdm_disable_automatic_login:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Disable GDM Automatic Login</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="gnome_gdm_disable_automatic_login" source="ssg"/>
            <oval-def:description>Disable the GNOME Display Manager (GDM) ability to allow users to
      automatically login.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="gdm installed" definition_ref="oval:ssg-package_gdm_installed:def:1" negate="true"/>
            <oval-def:criterion comment="Disable GDM Automatic Login" test_ref="oval:ssg-test_disable_automatic_login:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-gnome_gdm_disable_guest_login:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Disable GDM Guest Login</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="gnome_gdm_disable_guest_login" source="ssg"/>
            <oval-def:description>Disable the GNOME Display Manager (GDM) ability to allow guest users
      to login.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="gdm installed" definition_ref="oval:ssg-package_gdm_installed:def:1" negate="true"/>
            <oval-def:criterion comment="Disable GDM Guest Login" test_ref="oval:ssg-test_disable_guest_login:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-gnome_gdm_disable_xdmcp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable XDMCP in GDM</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="gnome_gdm_disable_xdmcp" source="ssg"/>
            <oval-def:description>Ensure 'Enable' is configured with value 'false in section 'xdmcp' in /etc/gdm/custom.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="gdm is configured correctly and configuration file exists" operator="AND">
            <oval-def:criteria comment="gdm is configured correctly" operator="OR">
              <oval-def:criterion comment="Check the Enable in /etc/gdm/custom.conf" test_ref="oval:ssg-test_gnome_gdm_disable_xdmcp:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="test if configuration file /etc/gdm/custom.conf exists for gnome_gdm_disable_xdmcp" test_ref="oval:ssg-test_gnome_gdm_disable_xdmcp_config_file_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_disable_automount:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Disable GNOME3 automount</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_disable_automount" source="ssg"/>
            <oval-def:description>The system's default desktop environment, GNOME3, will mount
      devices and removable media (such as DVDs, CDs and USB flash drives)
      whenever they are inserted into the system. Disable automount within GNOME3.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="Disable GNOME3 automount and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="Disable automount in GNOME3" test_ref="oval:ssg-test_dconf_gnome_disable_automount:tst:1"/>
              <oval-def:criterion comment="Prevent user from changing automount setting" test_ref="oval:ssg-test_prevent_user_gnome_automount:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_disable_automount_open:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable GNOME3 automount-open</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_disable_automount_open" source="ssg"/>
            <oval-def:description>The system's default desktop environment, GNOME3, will mount
    devices and removable media (such as DVDs, CDs and USB flash drives)
    whenever they are inserted into the system. Disable automount-open within GNOME3.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="Disable GNOME3 automount/autorun and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="Disable automount-open in GNOME3" test_ref="oval:ssg-test_dconf_gnome_disable_automount_open:tst:1"/>
              <oval-def:criterion comment="Prevent user from changing automount-open setting" test_ref="oval:ssg-test_prevent_user_gnome_automount_open:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_disable_autorun:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable GNOME3 autorun</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_disable_autorun" source="ssg"/>
            <oval-def:description>The system's default desktop environment, GNOME3, will mount
    devices and removable media (such as DVDs, CDs and USB flash drives)
    whenever they are inserted into the system. Disable autorun within GNOME3.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="Disable GNOME3 autorun and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="Disable autorun in GNOME3" test_ref="oval:ssg-test_dconf_gnome_disable_autorun:tst:1"/>
              <oval-def:criterion comment="Prevent user from changing autorun setting" test_ref="oval:ssg-test_prevent_user_gnome_autorun:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_disable_thumbnailers:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable All GNOME3 Thumbnailers</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_disable_thumbnailers" source="ssg"/>
            <oval-def:description>The system's default desktop environment, GNOME3, uses a
      number of different thumbnailer programs to generate thumbnails for any
      new or modified content in an opened folder. Disable the execution of
      these thumbnail applications within GNOME3.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="Disable Gnome3 Thumbnailers and prevent user from enabling" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="Disable thumbnailers in GNOME3" test_ref="oval:ssg-test_gnome_disable_thumbnailers:tst:1"/>
              <oval-def:criterion comment="prevent user from changing idle delay" test_ref="oval:ssg-test_prevent_user_change_gnome_thumbnailers:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_disable_wifi_create:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable WIFI Network Connection Creation in GNOME3</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_disable_wifi_create" source="ssg"/>
            <oval-def:description>Disable the GNOME3 wireless network creation settings.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="Disable wifi creation" test_ref="oval:ssg-test_disable_wifi_creation:tst:1"/>
              <oval-def:criterion comment="Prevent user from changing" test_ref="oval:ssg-test_prevent_user_enable_wifi_creation:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_disable_wifi_notification:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable WIFI Network Notification in GNOME3</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_disable_wifi_notification" source="ssg"/>
            <oval-def:description>Disable the GNOME3 wireless network notification.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="Disable wifi notification" test_ref="oval:ssg-test_disable_wifi_notification:tst:1"/>
              <oval-def:criterion comment="Prevent user from changing" test_ref="oval:ssg-test_prevent_user_enable_wifi_notification:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_remote_access_credential_prompt:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Require Credential Prompting for Remote Access in GNOME3</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_remote_access_credential_prompt" source="ssg"/>
            <oval-def:description>Configure GNOME3 to require credential prompting for remote access.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="configure remote access credentials" test_ref="oval:ssg-test_configure_remote_access_creds:tst:1"/>
              <oval-def:criterion comment="Prevent user from changing" test_ref="oval:ssg-test_prevent_user_remote_access_creds:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_remote_access_encryption:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Require Encryption for Remote Access in GNOME3</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_remote_access_encryption" source="ssg"/>
            <oval-def:description>Configure GNOME3 to require encryption for remote access connections.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="configure remote access encryption" test_ref="oval:ssg-test_configure_remote_access_encryption:tst:1"/>
              <oval-def:criterion comment="Prevent user from changing" test_ref="oval:ssg-test_prevent_user_remote_access_encryption:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_screensaver_idle_activation_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable GNOME3 Screensaver Idle Activation</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_screensaver_idle_activation_enabled" source="ssg"/>
            <oval-def:description>Idle activation of the screen saver should be enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="check screensaver idle activation and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="idle activation has been configured" test_ref="oval:ssg-test_screensaver_idle_activation_enabled:tst:1"/>
              <oval-def:criterion comment="prevent user from changing idle delay" test_ref="oval:ssg-test_prevent_user_change_idle_activation_enabled:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_screensaver_idle_activation_locked:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Users Cannot Change GNOME3 Screensaver Idle Activation</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_screensaver_idle_activation_locked" source="ssg"/>
            <oval-def:description>Idle activation of the screen saver should not be changed by users.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="check screensaver idle activation and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="prevent user from changing idle delay" test_ref="oval:ssg-test_prevent_user_change_idle_activation_locked:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_screensaver_idle_delay:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Set GNOME3 Screensaver Inactivity Timeout</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_screensaver_idle_delay" source="ssg"/>
            <oval-def:description>The allowed period of inactivity before the screensaver is activated.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="check screensaver idle delay and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="idle delay has been configured" test_ref="oval:ssg-test_screensaver_idle_delay:tst:1"/>
              <oval-def:criterion comment="idle delay is set correctly" test_ref="oval:ssg-test_screensaver_idle_delay_setting:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_screensaver_lock_delay:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Set GNOME3 Screensaver Lock Delay After Activation Period</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_screensaver_lock_delay" source="ssg"/>
            <oval-def:description>Idle activation of the screen lock should be enabled immediately or
      after a delay.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="Enable screensaver lock and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="screensaver lock delay is configured" test_ref="oval:ssg-test_screensaver_lock_delay:tst:1"/>
              <oval-def:criterion comment="lock delay is set correctly" test_ref="oval:ssg-test_screensaver_lock_delay_setting:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_screensaver_lock_enabled:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Enable GNOME3 Screensaver Lock After Idle Period</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_screensaver_lock_enabled" source="ssg"/>
            <oval-def:description>Idle activation of the screen lock should be enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="Enable screensaver lock and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="screensaver lock is enabled" test_ref="oval:ssg-test_screensaver_lock_enabled:tst:1"/>
              <oval-def:criterion comment="screensaver lock prevent user from changing" test_ref="oval:ssg-test_prevent_user_screensaver_lock:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_screensaver_lock_locked:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Users Cannot Change GNOME3 Screensaver Lock After Idle Period</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_screensaver_lock_locked" source="ssg"/>
            <oval-def:description>Idle activation of the screen lock should not be changed by users.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="Enable screensaver lock and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="screensaver lock prevent user from changing" test_ref="oval:ssg-test_prevent_user_screensaver_lock_locked:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_screensaver_mode_blank:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Implement Blank Screensaver</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_screensaver_mode_blank" source="ssg"/>
            <oval-def:description>The GNOME3 screensaver should be blank.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="Enable blank screensaver and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="screensaver is blank" test_ref="oval:ssg-test_screensaver_mode_blank:tst:1"/>
              <oval-def:criterion comment="screensaver prevent user from changing mode" test_ref="oval:ssg-test_prevent_user_screensaver_mode_change:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_screensaver_user_info:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Full User Name on Splash Shield</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_screensaver_user_info" source="ssg"/>
            <oval-def:description>GNOME3 screen splash shield should not display full name of logged in user.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="Disable screensaver user info and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="screensaver user info is disabled" test_ref="oval:ssg-test_screensaver_disable_user_info:tst:1"/>
              <oval-def:criterion comment="screensaver prevent user from changing" test_ref="oval:ssg-test_prevent_user_info_change:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_screensaver_user_locks:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Users Cannot Change GNOME3 Screensaver Settings</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_screensaver_user_locks" source="ssg"/>
            <oval-def:description>Ensure that users cannot change GNOME3 screensaver idle and lock settings.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="check screensaver idle delay and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="prevent user from changing screensaver lock delay" test_ref="oval:ssg-test_user_change_lock_delay_lock:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_session_idle_user_locks:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Users Cannot Change GNOME3 Session Idle Settings</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_session_idle_user_locks" source="ssg"/>
            <oval-def:description>Ensure that users cannot change GNOME3 session idle settings.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria comment="check screensaver idle delay and prevent user from changing it" operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="prevent user from changing idle delay" test_ref="oval:ssg-test_user_change_idle_delay_lock:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_disable_ctrlaltdel_reboot:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Ctrl-Alt-Del Reboot Key Sequence in GNOME3</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_disable_ctrlaltdel_reboot" source="ssg"/>
            <oval-def:description>Disable the GNOME3 ctrl-alt-del reboot key sequence in GNOME3.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="Disable Ctrl-Alt-Del" test_ref="oval:ssg-test_disable_gnome_ctrlaltdel:tst:1"/>
              <oval-def:criterion comment="Prevent user from changing" test_ref="oval:ssg-test_prevent_user_enable_ctrlaltdel:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_disable_geolocation:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Geolocation in GNOME3</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_disable_geolocation" source="ssg"/>
            <oval-def:description>Disable GNOME3 Geolocation for the clock and system.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="Disable system geolocation" test_ref="oval:ssg-test_disable_sys_geolocation:tst:1"/>
              <oval-def:criterion comment="Prevent user from changing" test_ref="oval:ssg-test_prevent_user_sys_geolocation:tst:1"/>
              <oval-def:criterion comment="Disable clock geolocation" test_ref="oval:ssg-test_disable_clock_geolocation:tst:1"/>
              <oval-def:criterion comment="Prevent user from changing" test_ref="oval:ssg-test_prevent_user_clock_geolocation:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_disable_power_settings:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Power Settings in GNOME3</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_disable_power_settings" source="ssg"/>
            <oval-def:description>Disable GNOME3 power settings.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="dconf installed" definition_ref="oval:ssg-package_dconf_installed:def:1" negate="true"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="dconf user profile exists" definition_ref="oval:ssg-enable_dconf_user_profile:def:1"/>
              <oval-def:criterion comment="Disable power settings" test_ref="oval:ssg-test_disable_gnome_power_setting:tst:1"/>
              <oval-def:criterion comment="Prevent user from changing" test_ref="oval:ssg-test_prevent_user_power_setting_change:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-installed_OS_is_FIPS_certified:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>The Installed Operating System Is FIPS 140-2 Certified</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="installed_OS_is_FIPS_certified" source="ssg"/>
            <oval-def:description>
          The operating system installed on the system is a certified operating system that meets FIPS 140-2 requirements.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Installed operating system is a certified operating system" operator="OR">
            <oval-def:extend_definition comment="Installed OS is RHEL8" definition_ref="oval:ssg-installed_OS_is_rhel8:def:1"/>
            <oval-def:extend_definition comment="Installed OS is RHCOS4" definition_ref="oval:ssg-installed_OS_is_rhcos4:def:1"/>
            <oval-def:extend_definition comment="Installed OS is OL7" definition_ref="oval:ssg-installed_OS_is_ol7:def:1"/>
            <oval-def:extend_definition comment="Installed OS is OL8" definition_ref="oval:ssg-installed_OS_is_ol8:def:1"/>
            <oval-def:extend_definition comment="Installed OS is OL9" definition_ref="oval:ssg-installed_OS_is_ol9:def:1"/>
            <oval-def:extend_definition comment="Installed OS is SLE12" definition_ref="oval:ssg-installed_OS_is_sle12:def:1"/>
            <oval-def:extend_definition comment="Installed OS is SLE15" definition_ref="oval:ssg-installed_OS_is_sle15:def:1"/>
            <oval-def:extend_definition comment="Installed OS is SLE Micro 5" definition_ref="oval:ssg-installed_OS_is_slmicro5:def:1"/>
            <oval-def:extend_definition comment="Installed OS is SLE Micro 6" definition_ref="oval:ssg-installed_OS_is_slmicro6:def:1"/>
            <oval-def:extend_definition comment="Installed OS is Ubuntu 22.04" definition_ref="oval:ssg-installed_OS_is_ubuntu2204:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-installed_OS_is_vendor_supported:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>The Installed Operating System Is Vendor Supported</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="installed_OS_is_vendor_supported" source="ssg"/>
            <oval-def:description>
        The operating system installed on the system is supported by a vendor that provides security patches.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Installed operating system is supported by a vendor" operator="OR">
            <oval-def:extend_definition comment="Installed OS is ALMALINUX8" definition_ref="oval:ssg-installed_OS_is_almalinux8:def:1"/>
            <oval-def:extend_definition comment="Installed OS is RHEL8" definition_ref="oval:ssg-installed_OS_is_rhel8:def:1"/>
            <oval-def:extend_definition comment="Installed OS is RHEL9" definition_ref="oval:ssg-installed_OS_is_rhel9:def:1"/>
            <oval-def:extend_definition comment="Installed OS is RHEL10" definition_ref="oval:ssg-installed_OS_is_rhel10:def:1"/>
            <oval-def:extend_definition comment="Installed OS is Hummingbird" definition_ref="oval:ssg-installed_OS_is_hummingbird:def:1"/>
            <oval-def:extend_definition comment="Installed OS is OL7" definition_ref="oval:ssg-installed_OS_is_ol7:def:1"/>
            <oval-def:extend_definition comment="Installed OS is OL8" definition_ref="oval:ssg-installed_OS_is_ol8:def:1"/>
            <oval-def:extend_definition comment="Installed OS is OL9" definition_ref="oval:ssg-installed_OS_is_ol9:def:1"/>
            <oval-def:extend_definition comment="Installed OS is SLE12" definition_ref="oval:ssg-installed_OS_is_sle12:def:1"/>
            <oval-def:extend_definition comment="Installed OS is SLE15" definition_ref="oval:ssg-installed_OS_is_sle15:def:1"/>
            <oval-def:extend_definition comment="Installed OS is SLE16" definition_ref="oval:ssg-installed_OS_is_sle16:def:1"/>
            <oval-def:extend_definition comment="Installed OS is SLE Micro 5" definition_ref="oval:ssg-installed_OS_is_slmicro5:def:1"/>
            <oval-def:extend_definition comment="Installed OS is SLE Micro 6" definition_ref="oval:ssg-installed_OS_is_slmicro6:def:1"/>
            <oval-def:extend_definition comment="Installed OS is Ubuntu 22.04" definition_ref="oval:ssg-installed_OS_is_ubuntu2204:def:1"/>
            <oval-def:extend_definition comment="Installed OS is Ubuntu 24.04" definition_ref="oval:ssg-installed_OS_is_ubuntu2404:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-configure_bind_crypto_policy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure BIND to use System Crypto Policy</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="configure_bind_crypto_policy" source="ssg"/>
            <oval-def:description>BIND should be configured to use the system-wide crypto policy setting.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="Check if package bind is not installed" definition_ref="oval:ssg-package_bind_removed:def:1"/>
            <oval-def:criterion comment="Check that the configuration includes the policy config file." test_ref="oval:ssg-test_configure_bind_crypto_policy:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-configure_crypto_policy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure System Cryptography Policy</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="configure_crypto_policy" source="ssg"/>
            <oval-def:description>Ensure crypto policy is correctly configured in /etc/crypto-policies/config, and the policy is current.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="check for crypto policy correctly configured in /etc/crypto-policy/config" test_ref="oval:ssg-test_configure_crypto_policy:tst:1"/>
            <oval-def:criterion comment="check for crypto policy correctly configured in /etc/crypto-policy/state/current" test_ref="oval:ssg-test_configure_crypto_policy_current:tst:1"/>
            <oval-def:criterion comment="Check if update-crypto-policies has been run after config update" test_ref="oval:ssg-test_crypto_policies_updated:tst:1"/>
            <oval-def:criterion comment="Check if /etc/crypto-policies/back-ends/nss.config exists" test_ref="oval:ssg-test_crypto_policy_nss_config:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-configure_gnutls_tls_crypto_policy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure GnuTLS library to use DoD-approved TLS Encryption</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="configure_gnutls_tls_crypto_policy" source="ssg"/>
            <oval-def:description>Check presence of +VERS-ALL:-VERS-DTLS0.9:-VERS-TLS1.1:-VERS-TLS1.0:-VERS-SSL3.0:-VERS-DTLS1.0 in /etc/crypto-policies/back-ends/gnutls.config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check that /etc/crypto-policies/back-ends/gnutls.config contains a line with certain text" test_ref="oval:ssg-test_configure_gnutls_tls_crypto_policy:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-configure_kerberos_crypto_policy:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Configure Kerberos to use System Crypto Policy</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="configure_kerberos_crypto_policy" source="ssg"/>
            <oval-def:description>Kerberos should be configured to use the system-wide crypto policy setting.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="The config file is always a symlink to the backend, but the backend itself may be either a file, or a symlink. For this reason, we need two tests, if one passes, the other one is expected to either fail, or error." operator="OR">
            <oval-def:criterion comment="kerberos crypto-policy configuration links to same file as kerberos crypto-policy backend" test_ref="oval:ssg-test_configure_kerberos_crypto_policy_symlink:tst:1"/>
            <oval-def:criterion comment="kerberos crypto-policy configuration links to the crypto-policy backend file" test_ref="oval:ssg-test_configure_kerberos_crypto_policy_nosymlink:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-configure_libreswan_crypto_policy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure Libreswan to use System Crypto Policy</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="configure_libreswan_crypto_policy" source="ssg"/>
            <oval-def:description>Libreswan should be configured to use the system-wide crypto policy setting.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="Check if package libreswan is not installed" definition_ref="oval:ssg-package_libreswan_installed:def:1" negate="true"/>
            <oval-def:criterion comment="Check that the libreswan configuration includes the crypto policy config file" test_ref="oval:ssg-test_configure_libreswan_crypto_policy:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-configure_openssl_crypto_policy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure OpenSSL library to use System Crypto Policy</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="configure_openssl_crypto_policy" source="ssg"/>
            <oval-def:description>OpenSSL should be configured to use the system-wide crypto policy setting.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check that the configuration mandates usage of system-wide crypto policies." test_ref="oval:ssg-test_configure_openssl_crypto_policy:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-configure_openssl_tls_crypto_policy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure OpenSSL library to use TLS Encryption</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="configure_openssl_tls_crypto_policy" source="ssg"/>
            <oval-def:description>Configure OpenSSL library to use TLS Encryption</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="OpenSSL library is configured to use only TLS v1.2 or newer encryption" test_ref="oval:ssg-test_configure_openssl_tls_crypto_policy:tst:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="Installed version of  crypto-policies is older than 20210617-1" test_ref="oval:ssg-test_installed_version_of_crypto_policies:tst:1"/>
              <oval-def:criterion comment="OpenSSL library is configured to use only DTLS v1.2 or newer encryption" test_ref="oval:ssg-test_configure_openssl_dtls_crypto_policy:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-configure_ssh_crypto_policy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure SSH to use System Crypto Policy</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="configure_ssh_crypto_policy" source="ssg"/>
            <oval-def:description>SSH should be configured to use the system-wide crypto policy setting.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check that the SSH configuration mandates usage of system-wide crypto policies." test_ref="oval:ssg-test_configure_ssh_crypto_policy:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-harden_openssl_crypto_policy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Harden OpenSSL Crypto Policy</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="harden_openssl_crypto_policy" source="ssg"/>
            <oval-def:description>Ensure 'Ciphersuites' is configured with value 'TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256' in /etc/crypto-policies/back-ends/opensslcnf.config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="The respective application or service is configured correctly" operator="OR">
            <oval-def:criterion comment="Check the Ciphersuites in /etc/crypto-policies/back-ends/opensslcnf.config" test_ref="oval:ssg-test_harden_openssl_crypto_policy:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-harden_ssh_client_crypto_policy:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Harden SSH client Crypto Policy</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="harden_ssh_client_crypto_policy" source="ssg"/>
            <oval-def:description>Ensure the ssh client ciphers are configured correctly in /etc/ssh/ssh_config.d/02-ospp.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="SSH client is configured correctly" operator="AND">
            <oval-def:criterion comment="Check the Match in /etc/ssh/ssh_config.d/02-ospp.conf" test_ref="oval:ssg-test_harden_ssh_client_crypto_policy_Match:tst:1"/>
            <oval-def:criterion comment="Check the RekeyLimit in /etc/ssh/ssh_config.d/02-ospp.conf" test_ref="oval:ssg-test_harden_ssh_client_crypto_policy_RekeyLimit:tst:1"/>
            <oval-def:criterion comment="Check the GSSAPIAuthentication in /etc/ssh/ssh_config.d/02-ospp.conf" test_ref="oval:ssg-test_harden_ssh_client_crypto_policy_GSSAPIAuthentication:tst:1"/>
            <oval-def:criterion comment="Check the Ciphers in /etc/ssh/ssh_config.d/02-ospp.conf" test_ref="oval:ssg-test_harden_ssh_client_crypto_policy_Ciphers:tst:1"/>
            <oval-def:criterion comment="Check the PubkeyAcceptedKeyTypes in /etc/ssh/ssh_config.d/02-ospp.conf" test_ref="oval:ssg-test_harden_ssh_client_crypto_policy_PubkeyAcceptedKeyTypes:tst:1"/>
            <oval-def:criterion comment="Check the MACs in /etc/ssh/ssh_config.d/02-ospp.conf" test_ref="oval:ssg-test_harden_ssh_client_crypto_policy_MACs:tst:1"/>
            <oval-def:criterion comment="Check the KexAlgorithms in /etc/ssh/ssh_config.d/02-ospp.conf" test_ref="oval:ssg-test_harden_ssh_client_crypto_policy_KexAlgorithms:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-harden_sshd_ciphers_openssh_conf_crypto_policy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure SSH Client to Use FIPS 140 Validated Ciphers: openssh.config</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="harden_sshd_ciphers_openssh_conf_crypto_policy" source="ssg"/>
            <oval-def:description>Limit the Ciphers to those which are FIPS-approved.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - presence of the file plus." operator="AND">
            <oval-def:criterion comment="Check that /etc/crypto-policies/back-ends/openssh.config contains FIPS-approved SSHD Ciphers" test_ref="oval:ssg-test_harden_sshd_ciphers_openssh_conf_crypto_policy:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-harden_sshd_ciphers_opensshserver_conf_crypto_policy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure SSH Server to Use FIPS 140-2 Validated Ciphers: opensshserver.config</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="harden_sshd_ciphers_opensshserver_conf_crypto_policy" source="ssg"/>
            <oval-def:description>Limit the Ciphers to those which are FIPS-approved.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - presence of the file plus." operator="AND">
            <oval-def:criterion comment="Check that /etc/crypto-policies/back-ends/opensshserver.config contains FIPS-approved SSHD Ciphers" test_ref="oval:ssg-test_harden_sshd_ciphers_opensshserver_conf_crypto_policy:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-harden_sshd_crypto_policy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Harden SSHD Crypto Policy</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="harden_sshd_crypto_policy" source="ssg"/>
            <oval-def:description>Ensure 'CRYPTO_POLICY' is configured with value ''-oCiphers=aes256-ctr,aes128-ctr,aes256-cbc,aes128-cbc -oMACs=hmac-sha2-512,hmac-sha2-256 -oGSSAPIKeyExchange=no -oKexAlgorithms=ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group14-sha1 -oHostKeyAlgorithms=ssh-rsa,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256 -oPubkeyAcceptedKeyTypes=rsa-sha2-512,rsa-sha2-256,ssh-rsa,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256'' in /etc/crypto-policies/back-ends/opensshserver.config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly" operator="OR">
            <oval-def:criterion comment="Check the CRYPTO_POLICY in /etc/crypto-policies/back-ends/opensshserver.config" test_ref="oval:ssg-test_harden_sshd_crypto_policy:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-harden_sshd_macs_openssh_conf_crypto_policy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure SSH Client to Use FIPS 140-2 Validated MACs: openssh.config</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="harden_sshd_macs_openssh_conf_crypto_policy" source="ssg"/>
            <oval-def:description>Limit the Message Authentication Codes (MACs) to those which are FIPS-approved.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - presence of the file plus." operator="AND">
            <oval-def:criterion comment="Check that /etc/crypto-policies/back-ends/openssh.config contains FIPS-approved SSHD MACs" test_ref="oval:ssg-test_harden_sshd_macs_openssh_conf_crypto_policy:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-harden_sshd_macs_opensshserver_conf_crypto_policy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure SSH Server to Use FIPS 140-2 Validated MACs: opensshserver.config</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="harden_sshd_macs_opensshserver_conf_crypto_policy" source="ssg"/>
            <oval-def:description>Limit the Message Authentication Codes (MACs) to those which are FIPS-approved.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - presence of the file plus." operator="AND">
            <oval-def:criterion comment="Check that /etc/crypto-policies/back-ends/opensshserver.config contains FIPS-approved SSHD MACs" test_ref="oval:ssg-test_harden_sshd_macs_opensshserver_conf_crypto_policy:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-openssl_use_strong_entropy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>OpenSSL uses strong entropy source</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="openssl_use_strong_entropy" source="ssg"/>
            <oval-def:description>OpenSSL should be configured to generate random data with strong entropy.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check that the OpenSSL is configured to generate random data with strong entropy." test_ref="oval:ssg-test_openssl_strong_entropy:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-install_antivirus:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install Virus Scanning Software</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="install_antivirus" source="ssg"/>
            <oval-def:description>Antivirus software should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Antivirus is not being used or conditions are met" operator="AND">
            <oval-def:extend_definition comment="McAfee A/V Installed" definition_ref="oval:ssg-install_mcafee_antivirus:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-install_mcafee_hbss:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install Intrusion Detection Software</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="install_mcafee_hbss" source="ssg"/>
            <oval-def:description>Install McAfee Host-Based Intrusion Detection Software (HBSS)</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="McAfee HBSS" definition_ref="oval:ssg-install_mcafee_cma_rt:def:1"/>
            <oval-def:extend_definition comment="McAfee HBSS" definition_ref="oval:ssg-install_mcafee_hbss_accm:def:1"/>
            <oval-def:extend_definition comment="McAfee HBSS" definition_ref="oval:ssg-package_MFEhiplsm_installed:def:1"/>
            <oval-def:extend_definition comment="McAfee HBSS" definition_ref="oval:ssg-install_mcafee_hbss_pa:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-install_hids:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install Intrusion Detection Software</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="install_hids" source="ssg"/>
            <oval-def:description>Intrusion detection software or SELinux should be installed and enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="McAfee HBSS" definition_ref="oval:ssg-install_mcafee_hbss:def:1"/>
            <oval-def:criterion comment="SELinux enabled" test_ref="oval:ssg-test_selinux_enforcing:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-install_mcafee_antivirus:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install McAfee Virus Scanning Software</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="install_mcafee_antivirus" source="ssg"/>
            <oval-def:description>McAfee Antivirus software should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Antivirus is not being used or conditions are met" operator="AND">
            <oval-def:extend_definition comment="McAfee Runtime Libraries and Agent" definition_ref="oval:ssg-install_mcafee_cma_rt:def:1"/>
            <oval-def:criterion comment="Linuxshield AntiVirus package is installed" test_ref="oval:ssg-test_linuxshield_install_antivirus:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-install_mcafee_cma_rt:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install the McAfee Runtime Libraries and Linux Agent</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="install_mcafee_cma_rt" source="ssg"/>
            <oval-def:description>Install the McAfee Runtime Libraries (MFErt) and Linux Agent (MFEcma).</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="McAfee runtime library package installed" test_ref="oval:ssg-test_mcafee_runtime_installed:tst:1"/>
            <oval-def:criterion comment="McAfee management agent package installed" test_ref="oval:ssg-test_mcafee_management_agent:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mcafee_antivirus_definitions_updated:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Virus Scanning Software Definitions Are Updated</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mcafee_antivirus_definitions_updated" source="ssg"/>
            <oval-def:description>Verify that McAfee AntiVirus definitions have been updated.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check if McAfee AntiVirus definitions have been updated" test_ref="oval:ssg-test_mcafee_antivirus_definitions_updated:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-agent_mfetpd_running:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure McAfee Endpoint Security for Linux (ENSL) is running</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="agent_mfetpd_running" source="ssg"/>
            <oval-def:description>Ensure that McAfee Endpoint Security for Linux (ENSL) is running.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="McAfee ENSL is running" test_ref="oval:ssg-test_agent_mfetpd_running:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-install_mcafee_hbss_accm:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install the Asset Configuration Compliance Module (ACCM)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="install_mcafee_hbss_accm" source="ssg"/>
            <oval-def:description>Install the Asset Configuration Compliance Module (ACCM).</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="McAfee ACCM is installed" test_ref="oval:ssg-test_mcafee_accm_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-install_mcafee_hbss_pa:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install the Policy Auditor (PA) Module</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="install_mcafee_hbss_pa" source="ssg"/>
            <oval-def:description>Install the Policy Auditor (PA) Module.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="McAfee Policy Auditor is installed" test_ref="oval:ssg-test_mcafee_auditengine_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-enable_dracut_fips_module:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable Dracut FIPS Module</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="enable_dracut_fips_module" source="ssg"/>
            <oval-def:description>fips module should be enabled in Dracut configuration</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="dracut fips module is enabled" test_ref="oval:ssg-test_enable_dracut_fips_module:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-enable_fips_mode:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable FIPS Mode</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="enable_fips_mode" source="ssg"/>
            <oval-def:description>Check if FIPS mode is enabled on the system</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="check contents of /proc/sys/crypto/fips_enabled" test_ref="oval:ssg-test_proc_sys_crypto_fips_enabled:tst:1"/>
            <oval-def:extend_definition comment="check option crypto.fips_enabled = 1 in sysctl" definition_ref="oval:ssg-sysctl_crypto_fips_enabled:def:1"/>
            <oval-def:extend_definition comment="dracut FIPS module is enabled" definition_ref="oval:ssg-enable_dracut_fips_module:def:1"/>
            <oval-def:extend_definition comment="system cryptography policy is configured" definition_ref="oval:ssg-configure_crypto_policy:def:1"/>
            <oval-def:criterion comment="check if var_system_crypto_policy variable selection is set to FIPS" test_ref="oval:ssg-test_system_crypto_policy_value:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-etc_system_fips_exists:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure '/etc/system-fips' exists</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="etc_system_fips_exists" source="ssg"/>
            <oval-def:description>Check /etc/system-fips exists</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="/etc/system-fips exists" test_ref="oval:ssg-test_etc_system_fips:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-fips_crypto_subpolicy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>FIPS Must Use a Supported Subpolicy</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="fips_crypto_subpolicy" source="ssg"/>
            <oval-def:description>No or the correct crypto sub-policy must be configured.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Correct sub policy enabled" test_ref="oval:ssg-test_fips_crypto_subpolicy:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-fips_custom_stig_sub_policy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Implement STIG Sub Crypto Policy</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="fips_custom_stig_sub_policy" source="ssg"/>
            <oval-def:description>Ensure that the custom STIG</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Ensure that all of the correct lines are in the file." operator="AND">
            <oval-def:criterion comment="Check that cipher@SSH item is configured" test_ref="oval:ssg-test_fips_custom_stig_sub_policy_cipher_ssh:tst:1"/>
            <oval-def:criterion comment="Check that mac@SSH item is configured" test_ref="oval:ssg-test_fips_custom_stig_sub_policy_mac_ssh:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_crypto_fips_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set kernel parameter 'crypto.fips_enabled' to 1</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_crypto_fips_enabled" source="ssg"/>
            <oval-def:description>The kernel 'crypto.fips_enabled' parameter should be set to '1' in system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter crypto.fips_enabled set to 1" test_ref="oval:ssg-test_sysctl_crypto_fips_enabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-aide_build_database:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Build and Test AIDE Database</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="aide_build_database" source="ssg"/>
            <oval-def:description>The aide database must be initialized.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Aide is installed" definition_ref="oval:ssg-package_aide_installed:def:1"/>
            <oval-def:criterion test_ref="oval:ssg-test_aide_operational_database_absolute_path:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-aide_check_audit_tools:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure AIDE to Verify the Audit Tools</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="aide_check_audit_tools" source="ssg"/>
            <oval-def:description>The AlmaLinux OS 8 operating system file integrity tool must be configured to protect the integrity of the audit tools.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Aide is installed" definition_ref="oval:ssg-package_aide_installed:def:1"/>
            <oval-def:criterion comment="auditctl is checked in /etc/aide.conf" test_ref="oval:ssg-test_aide_verify_auditctl:tst:1"/>
            <oval-def:criterion comment="auditd is checked in /etc/aide.conf" test_ref="oval:ssg-test_aide_verify_auditd:tst:1"/>
            <oval-def:criterion comment="ausearch is checked in /etc/aide.conf" test_ref="oval:ssg-test_aide_verify_ausearch:tst:1"/>
            <oval-def:criterion comment="aureport is checked in /etc/aide.conf" test_ref="oval:ssg-test_aide_verify_aureport:tst:1"/>
            <oval-def:criterion comment="autrace is checked in /etc/aide.conf" test_ref="oval:ssg-test_aide_verify_autrace:tst:1"/>
            <oval-def:criterion comment="rsyslogd is checked in /etc/aide.conf" test_ref="oval:ssg-test_aide_verify_rsyslogd:tst:1"/>
            <oval-def:criterion comment="augenrules is checked in /etc/aide.conf" test_ref="oval:ssg-test_aide_verify_augenrules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-aide_periodic_cron_checking:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Periodic Execution of AIDE</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="aide_periodic_cron_checking" source="ssg"/>
            <oval-def:description>By default, AIDE does not install itself for periodic
      execution. Periodically running AIDE is necessary to reveal
      unexpected changes in installed files.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Aide is installed" definition_ref="oval:ssg-package_aide_installed:def:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="run aide with cron" test_ref="oval:ssg-test_aide_periodic_cron_checking:tst:1"/>
              <oval-def:criterion comment="run aide with cron" test_ref="oval:ssg-test_aide_crond_checking:tst:1"/>
              <oval-def:criterion comment="run aide with cron" test_ref="oval:ssg-test_aide_var_cron_checking:tst:1"/>
              <oval-def:criterion comment="run aide with cron.(daily|weekly)" test_ref="oval:ssg-test_aide_crontabs_checking:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-aide_scan_notification:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure Notification of Post-AIDE Scan Details</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="aide_scan_notification" source="ssg"/>
            <oval-def:description>AIDE should notify appropriate personnel of the details
      of a scan after the scan has been run.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Aide is installed" definition_ref="oval:ssg-package_aide_installed:def:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="notify personnel when aide completes" test_ref="oval:ssg-test_aide_scan_notification:tst:1"/>
              <oval-def:criterion comment="notify personnel when aide completes" test_ref="oval:ssg-test_aide_var_cron_notification:tst:1"/>
              <oval-def:criterion comment="notify personnel when aide completes in cron.(d|daily|weekly|monthly)" test_ref="oval:ssg-test_aide_crontabs_notification:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-aide_use_fips_hashes:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure AIDE to Use FIPS 140-2 for Validating Hashes</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="aide_use_fips_hashes" source="ssg"/>
            <oval-def:description>AIDE should be configured to use the FIPS 140-2 
      cryptographic hashes.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Aide is installed" definition_ref="oval:ssg-package_aide_installed:def:1"/>
            <oval-def:criterion comment="non-FIPS hashes are not configured" test_ref="oval:ssg-test_aide_non_fips_hashes:tst:1"/>
            <oval-def:criterion comment="FIPS hashes are configured" test_ref="oval:ssg-test_aide_use_fips_hashes:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-aide_verify_acls:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure AIDE to Verify Access Control Lists (ACLs)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="aide_verify_acls" source="ssg"/>
            <oval-def:description>AIDE should be configured to verify Access Control Lists (ACLs).</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Aide is installed" definition_ref="oval:ssg-package_aide_installed:def:1"/>
            <oval-def:criterion comment="acl is set in /etc/aide.conf" test_ref="oval:ssg-test_aide_verify_acls:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-aide_verify_ext_attributes:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure AIDE to Verify Extended Attributes</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="aide_verify_ext_attributes" source="ssg"/>
            <oval-def:description>AIDE should be configured to verify extended file attributes.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Aide is installed" definition_ref="oval:ssg-package_aide_installed:def:1"/>
            <oval-def:criterion comment="xattrs is set in /etc/aide.conf" test_ref="oval:ssg-test_aide_verify_ext_attributes:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rpm_verify_hashes:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Verify File Hashes with RPM</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rpm_verify_hashes" source="ssg"/>
            <oval-def:description>Verify the RPM digests of system binaries using the RPM database.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="verify file md5 hashes" test_ref="oval:ssg-test_rpm_verify_hashes:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rpm_verify_ownership:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Verify and Correct Ownership with RPM</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rpm_verify_ownership" source="ssg"/>
            <oval-def:description>Verify ownership of installed packages by comparing the installed files
      with information about the files taken from the package metadata stored in the RPM
      database.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="user ownership of all files matches local rpm database" test_ref="oval:ssg-test_rpm_verify_ownership_verify_all_rpms_ownership:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rpm_verify_permissions:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Verify and Correct File Permissions with RPM</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rpm_verify_permissions" source="ssg"/>
            <oval-def:description>Verify the permissions of installed packages by comparing the installed
        files with information about the files taken from the package metadata stored in the RPM
        database.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mode of all files matches local rpm database" test_ref="oval:ssg-test_rpm_verify_permissions:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudo_dedicated_group:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure a dedicated group owns sudo</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudo_dedicated_group" source="ssg"/>
            <oval-def:description>This test makes sure that /usr/bin/sudo is owned by the group set in var_sudo_dedicated_group</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check if dedicated group exists" test_ref="oval:ssg-test_dedicated_group_exists:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /usr/bin/sudo" test_ref="oval:ssg-test_sudo_owned_by_dedicated_group:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudo_remove_no_authenticate:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Users Re-Authenticate for Privilege Escalation - sudo !authenticate</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudo_remove_no_authenticate" source="ssg"/>
            <oval-def:description>Checks sudo usage without authentication</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="!authenticate does not exist in /etc/sudoers" test_ref="oval:ssg-test_no_authenticate_etc_sudoers:tst:1"/>
            <oval-def:criterion comment="!authenticate does not exist in /etc/sudoers.d" test_ref="oval:ssg-test_no_authenticate_etc_sudoers_d:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudo_remove_nopasswd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Users Re-Authenticate for Privilege Escalation - sudo NOPASSWD</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudo_remove_nopasswd" source="ssg"/>
            <oval-def:description>Checks sudo usage without password</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="NOPASSWD is not configured in /etc/sudoers" test_ref="oval:ssg-test_nopasswd_etc_sudoers:tst:1"/>
            <oval-def:criterion comment="NOPASSWD is not configured in /etc/sudoers.d" test_ref="oval:ssg-test_nopasswd_etc_sudoers_d:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudo_require_authentication:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Users Re-Authenticate for Privilege Escalation - sudo</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudo_require_authentication" source="ssg"/>
            <oval-def:description>Checks sudo usage without password</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition definition_ref="oval:ssg-sudo_remove_no_authenticate:def:1"/>
            <oval-def:extend_definition definition_ref="oval:ssg-sudo_remove_nopasswd:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudo_require_reauthentication:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Require Re-Authentication When Using the sudo Command</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudo_require_reauthentication" source="ssg"/>
            <oval-def:description>'Ensure sudo timestamp_timeout is appropriate - sudo timestamp_timeout</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="The timestamp_timeout should be configured" operator="AND">
            <oval-def:criterion comment="check configuration in /etc/sudoers" test_ref="oval:ssg-test_sudo_timestamp_timeout:tst:1"/>
            <oval-def:criterion comment="check for - sign in configuration" test_ref="oval:ssg-test_sudo_timestamp_timeout_no_signs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudo_restrict_privilege_elevation_to_authorized:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>The operating system must restrict privilege elevation to authorized personnel</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudo_restrict_privilege_elevation_to_authorized" source="ssg"/>
            <oval-def:description>Check that sudoers doesn't allow all users to run commands via sudo</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Make sure that sudoers has restrictions on which users can run sudo for any target user" test_ref="oval:ssg-test_not_all_users_can_sudo_to_users:tst:1"/>
            <oval-def:criterion comment="Make sure that sudoers has restrictions on which users can run sudo for any target group" test_ref="oval:ssg-test_not_all_users_can_sudo_to_group:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudo_vdsm_nopasswd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Only the VDSM User Can Use sudo NOPASSWD</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudo_vdsm_nopasswd" source="ssg"/>
            <oval-def:description>Checks sudo usage for the vdsm user without a password</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="NOPASSWD only exists for vdsm user in /etc/sudoers" test_ref="oval:ssg-test_vdsm_nopasswd_etc_sudoers:tst:1"/>
            <oval-def:criterion comment="NOPASSWD only exists for vdsm user in /etc/sudoers.d" test_ref="oval:ssg-test_vdsm_nopasswd_etc_sudoers_d:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudoers_default_includedir:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure sudo only includes the default configuration directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudoers_default_includedir" source="ssg"/>
            <oval-def:description>Check if sudo includes only the default includedir</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check /etc/sudoers doesn't have any #include or @include" test_ref="oval:ssg-test_sudoers_without_include:tst:1"/>
              <oval-def:criterion comment="Check /etc/sudoers doesn't have any #includedir" test_ref="oval:ssg-test_sudoers_without_includedir:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check /etc/sudoers for #includedir" test_ref="oval:ssg-test_sudoers_default_includedir:tst:1"/>
              <oval-def:criterion comment="Check /etc/sudoers doesn't have any #include" test_ref="oval:ssg-test_sudoers_without_include:tst:1"/>
              <oval-def:criterion comment="Check /etc/sudoers doesn't have any @includedir" test_ref="oval:ssg-test_sudoers_without_includedir_new:tst:1"/>
              <oval-def:criterion comment="Check /etc/sudoers.d doesn't have any #include or #includedir" test_ref="oval:ssg-test_sudoersd_without_includes:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudoers_explicit_command_args:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Explicit arguments in sudo specifications</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudoers_explicit_command_args" source="ssg"/>
            <oval-def:description>Check that sudoers doesn't contain commands without arguments specified</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Make sure that no commands are without arguments" test_ref="oval:ssg-test_sudoers_explicit_command_args:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudoers_no_command_negation:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Don't define allowed commands in sudoers by means of exclusion</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudoers_no_command_negation" source="ssg"/>
            <oval-def:description>Check that sudoers doesn't contain command negations</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Make sure that no command in user spec contains negation" test_ref="oval:ssg-test_sudoers_no_command_negation:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudoers_no_root_target:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Don't target root user in the sudoers file</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudoers_no_root_target" source="ssg"/>
            <oval-def:description>Check that sudoers doesn't allow users to run commands as root</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Make sure that no user spec in sudoers has a runas spec that includes root or ALL" test_ref="oval:ssg-test_no_root_or_ALL_in_runas_spec:tst:1"/>
            <oval-def:criterion comment="Make sure that all user specs in sudoers feature a runas spec" test_ref="oval:ssg-test_no_user_spec_rules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudoers_validate_passwd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure invoking users password for privilege escalation when using sudo</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudoers_validate_passwd" source="ssg"/>
            <oval-def:description>Ensure invoking user's password for privilege escalation when using sudo</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check Defaults !targetpw exists in /etc/sudoers file" test_ref="oval:ssg-test_sudoers_targetpw_config:tst:1"/>
            <oval-def:criterion comment="Check Defaults !rootpw exists in /etc/sudoers file" test_ref="oval:ssg-test_sudoers_rootpw_config:tst:1"/>
            <oval-def:criterion comment="Check Defaults !runaspw exists in /etc/sudoers file" test_ref="oval:ssg-test_sudoers_runaspw_config:tst:1"/>
            <oval-def:criterion comment="Check Defaults targetpw is not defined in /etc/sudoers file" test_ref="oval:ssg-test_sudoers_targetpw_not_defined:tst:1"/>
            <oval-def:criterion comment="Check Defaults rootpw is not defined in /etc/sudoers file" test_ref="oval:ssg-test_sudoers_rootpw_not_defined:tst:1"/>
            <oval-def:criterion comment="Check Defaults runaspw is not defined in /etc/sudoers file" test_ref="oval:ssg-test_sudoers_runaspw_not_defined:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-clean_components_post_updating:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure yum Removes Previous Package Versions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="clean_components_post_updating" source="ssg"/>
            <oval-def:description>The clean_requirements_on_remove option should be used to ensure that old
      versions of software components are removed after updating.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="check value of clean_requirements_on_remove in /etc/yum.conf" test_ref="oval:ssg-test_yum_clean_components_post_updating:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-disable_weak_deps:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Installation of Weak Dependencies in DNF</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="disable_weak_deps" source="ssg"/>
            <oval-def:description>Ensure 'install_weak_deps' is configured with value '0' in section 'main' in /etc/dnf/dnf.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="dnf is configured correctly and configuration file exists" operator="AND">
            <oval-def:criterion comment="Check the install_weak_deps in /etc/dnf/dnf.conf" test_ref="oval:ssg-disable_weak_deps_test_disable_weak_deps:tst:1"/>
            <oval-def:criterion comment="test if configuration file /etc/dnf/dnf.conf exists for disable_weak_deps" test_ref="oval:ssg-disable_weak_deps_test_disable_weak_deps_config_file_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dnf-automatic_apply_updates:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure dnf-automatic to Install Available Updates Automatically</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dnf-automatic_apply_updates" source="ssg"/>
            <oval-def:description>Ensure 'apply_updates' is configured with value 'yes in section 'commands' in /etc/dnf/automatic.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="dnf-automatic is configured correctly and configuration file exists" operator="AND">
            <oval-def:criteria comment="dnf-automatic is configured correctly" operator="OR">
              <oval-def:criterion comment="Check the apply_updates in /etc/dnf/automatic.conf" test_ref="oval:ssg-test_dnf-automatic_apply_updates:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="test if configuration file /etc/dnf/automatic.conf exists for dnf-automatic_apply_updates" test_ref="oval:ssg-test_dnf-automatic_apply_updates_config_file_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dnf-automatic_security_updates_only:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure dnf-automatic to Install Only Security Updates</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dnf-automatic_security_updates_only" source="ssg"/>
            <oval-def:description>Ensure 'upgrade_type' is configured with value 'security in section 'commands' in /etc/dnf/automatic.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="dnf-automatic is configured correctly and configuration file exists" operator="AND">
            <oval-def:criteria comment="dnf-automatic is configured correctly" operator="OR">
              <oval-def:criterion comment="Check the upgrade_type in /etc/dnf/automatic.conf" test_ref="oval:ssg-test_dnf-automatic_security_updates_only:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="test if configuration file /etc/dnf/automatic.conf exists for dnf-automatic_security_updates_only" test_ref="oval:ssg-test_dnf-automatic_security_updates_only_config_file_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-enable_gpgcheck_for_all_repositories:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure gpgcheck Is Enabled for All Package Repositories</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="enable_gpgcheck_for_all_repositories" source="ssg"/>
            <oval-def:description>Ensure gpgcheck Is Enabled for All Package Repositories</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Ensure gpgcheck Is Enabled for All Package Repositories" operator="AND">
            <oval-def:criterion comment="verify all repos in /etc/yum.repos.d have gpgcheck enabled" test_ref="oval:ssg-test_enable_gpgcheck_for_all_repositories_all_enabled:tst:1"/>
            <oval-def:criterion comment="verify no repo in /etc/yum.repos.d has gpgcheck disabled" test_ref="oval:ssg-test_enable_gpgcheck_for_all_repositories_no_disabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ensure_almalinux_gpgkey_installed:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure AlmaLinux GPG Key Installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ensure_almalinux_gpgkey_installed" source="ssg"/>
            <oval-def:description>The AlmaLinux release and auxiliary key packages are required to be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Vendor GPG keys" operator="OR">
            <oval-def:criteria comment="AlmaLinux Vendor Keys" operator="AND">
              <oval-def:criteria comment="AlmaLinux Installed" operator="OR">
                <oval-def:extend_definition comment="almalinux8 installed" definition_ref="oval:ssg-installed_OS_is_almalinux8:def:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="package gpg-pubkey-3abb34f8-5ffd890e is installed" test_ref="oval:ssg-test_almalinux_package_gpgkey-3abb34f8-5ffd890e_installed:tst:1"/>
              <oval-def:criteria comment="Auxiliary AlmaLinux Key Installed" operator="OR">
                <oval-def:criterion comment="package gpg-pubkey-ced7258b-6525146f is installed" test_ref="oval:ssg-test_almalinux_package_gpgkey-ced7258b-6525146f_installed:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ensure_epel_repos_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure EPEL Repository is Disabled</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ensure_epel_repos_disabled" source="ssg"/>
            <oval-def:description>The EPEL repository should be disabled or not present on the system.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="Check if EPEL repository sections don't exist" test_ref="oval:ssg-test_no_epel_sections:tst:1"/>
            <oval-def:criterion comment="Check if EPEL repositories are disabled" test_ref="oval:ssg-test_epel_repos_disabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ensure_gpgcheck_globally_activated:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure gpgcheck Enabled In Main yum Configuration</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ensure_gpgcheck_globally_activated" source="ssg"/>
            <oval-def:description>The gpgcheck option should be used to ensure that checking
      of an RPM package's signature always occurs prior to its
      installation.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="check value of gpgcheck in /etc/yum.conf" test_ref="oval:ssg-test_ensure_gpgcheck_globally_activated:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ensure_gpgcheck_local_packages:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure gpgcheck Enabled for Local Packages</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ensure_gpgcheck_local_packages" source="ssg"/>
            <oval-def:description>The localpkg_gpgcheck option should be used to ensure that checking 
      of an RPM package's signature always occurs prior to its
      installation.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="check value of localpkg_gpgcheck in /etc/yum.conf" test_ref="oval:ssg-test_yum_ensure_gpgcheck_local_packages:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ensure_gpgcheck_never_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure gpgcheck Enabled for All yum Package Repositories</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ensure_gpgcheck_never_disabled" source="ssg"/>
            <oval-def:description>Ensure all yum or dnf repositories utilize signature checking.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="ensure all yum or dnf repositories utilize signiature checking" operator="AND">
            <oval-def:criterion comment="verify no gpgpcheck=0 present in /etc/yum.repos.d files" test_ref="oval:ssg-test_ensure_gpgcheck_never_disabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-ensure_gpgcheck_repo_metadata:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure gpgcheck Enabled for Repository Metadata</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="ensure_gpgcheck_repo_metadata" source="ssg"/>
            <oval-def:description>The repo_gpgcheck option should be used to ensure that checking
      of repository metadata always occurs.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="check value of repo_gpgcheck in /etc/yum.conf" test_ref="oval:ssg-test_yum_ensure_gpgcheck_repo_metadata:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_dcredit:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Ensure PAM Enforces Password Requirements - Minimum Digit Characters</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_dcredit" source="ssg"/>
            <oval-def:description>The password dcredit should meet minimum requirements</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="conditions for dcredit are satisfied" operator="AND">
            <oval-def:extend_definition comment="pwquality.so exists in system-auth" definition_ref="oval:ssg-accounts_password_pam_pwquality:def:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="pwquality.conf" test_ref="oval:ssg-test_password_pam_pwquality_dcredit:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_dictcheck:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_dictcheck" source="ssg"/>
            <oval-def:description>The password dictcheck should meet minimum requirements</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="conditions for dictcheck are satisfied" operator="AND">
            <oval-def:extend_definition comment="pwquality.so exists in system-auth" definition_ref="oval:ssg-accounts_password_pam_pwquality:def:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="pwquality.conf" test_ref="oval:ssg-test_password_pam_pwquality_dictcheck:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_difok:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Ensure PAM Enforces Password Requirements - Minimum Different Characters</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_difok" source="ssg"/>
            <oval-def:description>The password difok should meet minimum requirements</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="conditions for difok are satisfied" operator="AND">
            <oval-def:extend_definition comment="pwquality.so exists in system-auth" definition_ref="oval:ssg-accounts_password_pam_pwquality:def:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="pwquality.conf" test_ref="oval:ssg-test_password_pam_pwquality_difok:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_enforce_local:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure PAM Enforces Password Requirements - Enforce for Local Accounts Only</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_enforce_local" source="ssg"/>
            <oval-def:description>Check presence of local_users_only in /etc/security/pwquality.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - presence of the file plus 1 extra definitions." operator="AND">
            <oval-def:extend_definition comment="extend_definition added explicitly" definition_ref="oval:ssg-accounts_password_pam_pwquality:def:1"/>
            <oval-def:criterion comment="Check that /etc/security/pwquality.conf contains a line with certain text" test_ref="oval:ssg-test_accounts_password_pam_enforce_local:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_lcredit:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Ensure PAM Enforces Password Requirements - Minimum Lowercase Characters</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_lcredit" source="ssg"/>
            <oval-def:description>The password lcredit should meet minimum requirements</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="conditions for lcredit are satisfied" operator="AND">
            <oval-def:extend_definition comment="pwquality.so exists in system-auth" definition_ref="oval:ssg-accounts_password_pam_pwquality:def:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="pwquality.conf" test_ref="oval:ssg-test_password_pam_pwquality_lcredit:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_maxclassrepeat:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Ensure PAM Enforces Password Requirements - Maximum Consecutive Repeating Characters from Same Character Class</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_maxclassrepeat" source="ssg"/>
            <oval-def:description>The password maxclassrepeat should meet minimum requirements</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="conditions for maxclassrepeat are satisfied" operator="AND">
            <oval-def:extend_definition comment="pwquality.so exists in system-auth" definition_ref="oval:ssg-accounts_password_pam_pwquality:def:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="pwquality.conf" test_ref="oval:ssg-test_password_pam_pwquality_maxclassrepeat:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_maxrepeat:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Set Password Maximum Consecutive Repeating Characters</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_maxrepeat" source="ssg"/>
            <oval-def:description>The password maxrepeat should meet minimum requirements</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="conditions for maxrepeat are satisfied" operator="AND">
            <oval-def:extend_definition comment="pwquality.so exists in system-auth" definition_ref="oval:ssg-accounts_password_pam_pwquality:def:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="pwquality.conf" test_ref="oval:ssg-test_password_pam_pwquality_maxrepeat:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_maxsequence:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Limit the maximum number of sequential characters in passwords</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_maxsequence" source="ssg"/>
            <oval-def:description>The password maxsequence should meet minimum requirements</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="conditions for maxsequence are satisfied" operator="AND">
            <oval-def:extend_definition comment="pwquality.so exists in system-auth" definition_ref="oval:ssg-accounts_password_pam_pwquality:def:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="pwquality.conf" test_ref="oval:ssg-test_password_pam_pwquality_maxsequence:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_minclass:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Ensure PAM Enforces Password Requirements - Minimum Different Categories</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_minclass" source="ssg"/>
            <oval-def:description>The password minclass should meet minimum requirements</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="conditions for minclass are satisfied" operator="AND">
            <oval-def:extend_definition comment="pwquality.so exists in system-auth" definition_ref="oval:ssg-accounts_password_pam_pwquality:def:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="pwquality.conf" test_ref="oval:ssg-test_password_pam_pwquality_minclass:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_minlen:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Ensure PAM Enforces Password Requirements - Minimum Length</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_minlen" source="ssg"/>
            <oval-def:description>The password minlen should meet minimum requirements</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="conditions for minlen are satisfied" operator="AND">
            <oval-def:extend_definition comment="pwquality.so exists in system-auth" definition_ref="oval:ssg-accounts_password_pam_pwquality:def:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="pwquality.conf" test_ref="oval:ssg-test_password_pam_pwquality_minlen:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_ocredit:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Ensure PAM Enforces Password Requirements - Minimum Special Characters</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_ocredit" source="ssg"/>
            <oval-def:description>The password ocredit should meet minimum requirements</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="conditions for ocredit are satisfied" operator="AND">
            <oval-def:extend_definition comment="pwquality.so exists in system-auth" definition_ref="oval:ssg-accounts_password_pam_pwquality:def:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="pwquality.conf" test_ref="oval:ssg-test_password_pam_pwquality_ocredit:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_pwhistory_enforce_for_root:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Password History Is Enforced for the Root User</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_pwhistory_enforce_for_root" source="ssg"/>
            <oval-def:description>Check presence of enforce_for_root in /etc/security/pwhistory.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - presence of the file plus 0 extra definitions." operator="AND">
            <oval-def:criterion comment="Check that /etc/security/pwhistory.conf contains a line with certain text" test_ref="oval:ssg-test_accounts_password_pam_pwhistory_enforce_for_root:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_ucredit:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Ensure PAM Enforces Password Requirements - Minimum Uppercase Characters</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_ucredit" source="ssg"/>
            <oval-def:description>The password ucredit should meet minimum requirements</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="conditions for ucredit are satisfied" operator="AND">
            <oval-def:extend_definition comment="pwquality.so exists in system-auth" definition_ref="oval:ssg-accounts_password_pam_pwquality:def:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="pwquality.conf" test_ref="oval:ssg-test_password_pam_pwquality_ucredit:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_passwords_pam_faillock_deny:def:1" version="6">
          <oval-def:metadata>
            <oval-def:title>Lock Accounts After Failed Password Attempts</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_passwords_pam_faillock_deny" source="ssg"/>
            <oval-def:description>Lockout account after failed login attempts.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check the proper configuration of pam_faillock.so" operator="AND">
            <oval-def:criteria comment="Check if pam_faillock.so is properly enabled" operator="AND">
              <oval-def:criteria comment="Count occurrences of pam_unix.so in system-auth and password-auth" operator="AND">
                <oval-def:criterion comment="pam_unix.so appears only once in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_system_pam_unix_auth:tst:1"/>
                <oval-def:criterion comment="pam_unix.so appears only once in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_password_pam_unix_auth:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="Check common definition of pam_faillock.so" operator="AND">
                <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_system_pam_faillock_auth:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in account section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_system_pam_faillock_account:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_password_pam_faillock_auth:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in account section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_password_pam_faillock_account:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria comment="Check expected value for pam_faillock.so deny parameter" operator="OR">
              <oval-def:criteria comment="Check expected pam_faillock.so deny parameter in pam files" operator="AND">
                <oval-def:criterion comment="Check the deny parameter in auth section of system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_pamd_system:tst:1"/>
                <oval-def:criterion comment="Check the deny parameter in auth section of password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_pamd_password:tst:1"/>
                <oval-def:criterion comment="Ensure the deny parameter is not present in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_no_faillock_conf:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="Check expected pam_faillock.so deny parameter in /etc/security/faillock.conf" operator="AND">
                <oval-def:criterion comment="Check the deny parameter is not present system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_no_pamd_system:tst:1"/>
                <oval-def:criterion comment="Check the deny parameter is not present password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_no_pamd_password:tst:1"/>
                <oval-def:criterion comment="Ensure the deny parameter is present in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_faillock_conf:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_passwords_pam_faillock_interval:def:1" version="6">
          <oval-def:metadata>
            <oval-def:title>Set Interval For Counting Failed Password Attempts</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_passwords_pam_faillock_interval" source="ssg"/>
            <oval-def:description>The number of allowed failed logins should be set correctly.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check the proper configuration of pam_faillock.so" operator="AND">
            <oval-def:criteria comment="Check if pam_faillock.so is properly enabled" operator="AND">
              <oval-def:criteria comment="Count occurrences of pam_unix.so in system-auth and password-auth" operator="AND">
                <oval-def:criterion comment="pam_unix.so appears only once in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_system_pam_unix_auth:tst:1"/>
                <oval-def:criterion comment="pam_unix.so appears only once in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_password_pam_unix_auth:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="Check common definition of pam_faillock.so" operator="AND">
                <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_system_pam_faillock_auth:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in account section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_system_pam_faillock_account:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_password_pam_faillock_auth:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in account section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_password_pam_faillock_account:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria comment="Check expected value for pam_faillock.so fail_interval parameter" operator="OR">
              <oval-def:criteria comment="Check expected pam_faillock.so fail_interval parameter in pam files" operator="AND">
                <oval-def:criterion comment="Check the fail_interval parameter in auth section of system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_system:tst:1"/>
                <oval-def:criterion comment="Check the fail_interval parameter in auth section of password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_password:tst:1"/>
                <oval-def:criterion comment="Ensure the fail_interval parameter is not present in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_no_faillock_conf:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="Check expected pam_faillock.so fail_interval parameter in /etc/security/faillock.conf" operator="AND">
                <oval-def:criterion comment="Check the fail_interval parameter is not present system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_no_pamd_system:tst:1"/>
                <oval-def:criterion comment="Check the fail_interval parameter is not present password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_no_pamd_password:tst:1"/>
                <oval-def:criterion comment="Ensure the fail_interval parameter is present in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_faillock_conf:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_passwords_pam_faillock_unlock_time:def:1" version="6">
          <oval-def:metadata>
            <oval-def:title>Set Lockout Time for Failed Password Attempts</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_passwords_pam_faillock_unlock_time" source="ssg"/>
            <oval-def:description>The unlock time after number of failed logins should be set correctly.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check the proper configuration of pam_faillock.so" operator="AND">
            <oval-def:criteria comment="Check if pam_faillock.so is properly enabled" operator="AND">
              <oval-def:criteria comment="Count occurrences of pam_unix.so in system-auth and password-auth" operator="AND">
                <oval-def:criterion comment="pam_unix.so appears only once in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_system_pam_unix_auth:tst:1"/>
                <oval-def:criterion comment="pam_unix.so appears only once in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_password_pam_unix_auth:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="Check common definition of pam_faillock.so" operator="AND">
                <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_system_pam_faillock_auth:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in account section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_system_pam_faillock_account:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_password_pam_faillock_auth:tst:1"/>
                <oval-def:criterion comment="pam_faillock.so is properly defined in account section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_password_pam_faillock_account:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria comment="Check expected value for pam_faillock.so unlock_time parameter" operator="OR">
              <oval-def:criteria comment="Check expected pam_faillock.so unlock_time parameter in pam files" operator="AND">
                <oval-def:criterion comment="Check the unlock_time parameter in auth section of system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_system:tst:1"/>
                <oval-def:criterion comment="Check the unlock_time parameter in auth section of password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_password:tst:1"/>
                <oval-def:criterion comment="Ensure the unlock_time parameter is not present in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_no_faillock_conf:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria comment="Check expected pam_faillock.so unlock_time parameter in /etc/security/faillock.conf" operator="AND">
                <oval-def:criterion comment="Check the unlock_time parameter is not present system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_no_pamd_system:tst:1"/>
                <oval-def:criterion comment="Check the unlock_time parameter is not present password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_no_pamd_password:tst:1"/>
                <oval-def:criterion comment="Ensure the unlock_time parameter is present in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_faillock_conf:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_access_failed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditing of unsuccessful file accesses</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_access_failed" source="ssg"/>
            <oval-def:description>Inspect the contents of /etc/audit/rules.d/30-ospp-v42-3-access-failed.rules</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check contents of file" test_ref="oval:ssg-audit_access_failed_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_3_access_failed_rules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_access_success:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditing of successful file accesses</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_access_success" source="ssg"/>
            <oval-def:description>Inspect the contents of /etc/audit/rules.d/30-ospp-v42-3-access-success.rules</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check contents of file" test_ref="oval:ssg-audit_access_success_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_3_access_success_rules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_basic_configuration:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure basic parameters of Audit system</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_basic_configuration" source="ssg"/>
            <oval-def:description>Inspect the contents of /etc/audit/rules.d/10-base-config.rules</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check contents of file" test_ref="oval:ssg-audit_basic_configuration_test_whole_file_contents_tc_audit_rules_d_10_base_config_rules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_create_failed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditing of unsuccessful file creations</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_create_failed" source="ssg"/>
            <oval-def:description>Inspect the contents of /etc/audit/rules.d/30-ospp-v42-1-create-failed.rules</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check contents of file" test_ref="oval:ssg-audit_create_failed_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_1_create_failed_rules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_create_success:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditing of successful file creations</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_create_success" source="ssg"/>
            <oval-def:description>Inspect the contents of /etc/audit/rules.d/30-ospp-v42-1-create-success.rules</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check contents of file" test_ref="oval:ssg-audit_create_success_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_1_create_success_rules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_delete_failed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditing of unsuccessful file deletions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_delete_failed" source="ssg"/>
            <oval-def:description>Inspect the contents of /etc/audit/rules.d/30-ospp-v42-4-delete-failed.rules</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check contents of file" test_ref="oval:ssg-audit_delete_failed_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_failed_rules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_delete_success:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditing of successful file deletions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_delete_success" source="ssg"/>
            <oval-def:description>Inspect the contents of /etc/audit/rules.d/30-ospp-v42-4-delete-success.rules</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check contents of file" test_ref="oval:ssg-audit_delete_success_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_success_rules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_immutable_login_uids:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure immutable Audit login UIDs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_immutable_login_uids" source="ssg"/>
            <oval-def:description>Inspect the contents of /etc/audit/rules.d/11-loginuid.rules</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check contents of file" test_ref="oval:ssg-audit_immutable_login_uids_test_whole_file_contents_tc_audit_rules_d_11_loginuid_rules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_modify_failed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditing of unsuccessful file modifications</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_modify_failed" source="ssg"/>
            <oval-def:description>Inspect the contents of /etc/audit/rules.d/30-ospp-v42-2-modify-failed.rules</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check contents of file" test_ref="oval:ssg-audit_modify_failed_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_2_modify_failed_rules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_modify_success:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditing of successful file modifications</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_modify_success" source="ssg"/>
            <oval-def:description>Inspect the contents of /etc/audit/rules.d/30-ospp-v42-2-modify-success.rules</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check contents of file" test_ref="oval:ssg-audit_modify_success_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_2_modify_success_rules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_module_load:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditing of loading and unloading of kernel modules</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_module_load" source="ssg"/>
            <oval-def:description>Inspect the contents of /etc/audit/rules.d/43-module-load.rules</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check contents of file" test_ref="oval:ssg-audit_module_load_test_whole_file_contents_tc_audit_rules_d_43_module_load_rules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_ospp_general:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Perform general configuration of Audit for OSPP</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_ospp_general" source="ssg"/>
            <oval-def:description>Inspect the contents of /etc/audit/rules.d/30-ospp-v42.rules</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check contents of file" test_ref="oval:ssg-audit_ospp_general_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_rules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_owner_change_failed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditing of unsuccessful ownership changes</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_owner_change_failed" source="ssg"/>
            <oval-def:description>Inspect the contents of /etc/audit/rules.d/30-ospp-v42-6-owner-change-failed.rules</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check contents of file" test_ref="oval:ssg-audit_owner_change_failed_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_6_owner_change_failed_rules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_owner_change_success:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditing of successful ownership changes</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_owner_change_success" source="ssg"/>
            <oval-def:description>Inspect the contents of /etc/audit/rules.d/30-ospp-v42-6-owner-change-success.rules</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check contents of file" test_ref="oval:ssg-audit_owner_change_success_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_6_owner_change_success_rules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_perm_change_failed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditing of unsuccessful permission changes</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_perm_change_failed" source="ssg"/>
            <oval-def:description>Inspect the contents of /etc/audit/rules.d/30-ospp-v42-5-perm-change-failed.rules</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check contents of file" test_ref="oval:ssg-audit_perm_change_failed_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_5_perm_change_failed_rules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_perm_change_success:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure auditing of successful permission changes</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_perm_change_success" source="ssg"/>
            <oval-def:description>Inspect the contents of /etc/audit/rules.d/30-ospp-v42-5-perm-change-success.rules</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check contents of file" test_ref="oval:ssg-audit_perm_change_success_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_5_perm_change_success_rules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_privileged_commands_init:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - init</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_privileged_commands_init" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of init is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules init" test_ref="oval:ssg-test_audit_privileged_commands_init_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl init" test_ref="oval:ssg-test_audit_privileged_commands_init_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_privileged_commands_poweroff:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - poweroff</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_privileged_commands_poweroff" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of poweroff is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules poweroff" test_ref="oval:ssg-test_audit_privileged_commands_poweroff_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl poweroff" test_ref="oval:ssg-test_audit_privileged_commands_poweroff_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_privileged_commands_reboot:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - reboot</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_privileged_commands_reboot" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of reboot is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules reboot" test_ref="oval:ssg-test_audit_privileged_commands_reboot_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl reboot" test_ref="oval:ssg-test_audit_privileged_commands_reboot_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_privileged_commands_shutdown:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - shutdown</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_privileged_commands_shutdown" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of shutdown is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules shutdown" test_ref="oval:ssg-test_audit_privileged_commands_shutdown_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl shutdown" test_ref="oval:ssg-test_audit_privileged_commands_shutdown_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_dac_modification_chmod:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Discretionary Access Controls - chmod</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_dac_modification_chmod" source="ssg"/>
            <oval-def:description>The changing of file permissions and attributes should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit chmod" test_ref="oval:ssg-test_32bit_ardm_chmod_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit chmod" test_ref="oval:ssg-test_64bit_ardm_chmod_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit chmod" test_ref="oval:ssg-test_32bit_ardm_chmod_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit chmod" test_ref="oval:ssg-test_64bit_ardm_chmod_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_dac_modification_chown:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Discretionary Access Controls - chown</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_dac_modification_chown" source="ssg"/>
            <oval-def:description>The changing of file permissions and attributes should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit chown" test_ref="oval:ssg-test_32bit_ardm_chown_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit chown" test_ref="oval:ssg-test_64bit_ardm_chown_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit chown" test_ref="oval:ssg-test_32bit_ardm_chown_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit chown" test_ref="oval:ssg-test_64bit_ardm_chown_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_dac_modification_fchmod:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Discretionary Access Controls - fchmod</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_dac_modification_fchmod" source="ssg"/>
            <oval-def:description>The changing of file permissions and attributes should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit fchmod" test_ref="oval:ssg-test_32bit_ardm_fchmod_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit fchmod" test_ref="oval:ssg-test_64bit_ardm_fchmod_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit fchmod" test_ref="oval:ssg-test_32bit_ardm_fchmod_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit fchmod" test_ref="oval:ssg-test_64bit_ardm_fchmod_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_dac_modification_fchmodat:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Discretionary Access Controls - fchmodat</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_dac_modification_fchmodat" source="ssg"/>
            <oval-def:description>The changing of file permissions and attributes should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit fchmodat" test_ref="oval:ssg-test_32bit_ardm_fchmodat_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit fchmodat" test_ref="oval:ssg-test_64bit_ardm_fchmodat_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit fchmodat" test_ref="oval:ssg-test_32bit_ardm_fchmodat_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit fchmodat" test_ref="oval:ssg-test_64bit_ardm_fchmodat_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_dac_modification_fchown:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Discretionary Access Controls - fchown</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_dac_modification_fchown" source="ssg"/>
            <oval-def:description>The changing of file permissions and attributes should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit fchown" test_ref="oval:ssg-test_32bit_ardm_fchown_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit fchown" test_ref="oval:ssg-test_64bit_ardm_fchown_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit fchown" test_ref="oval:ssg-test_32bit_ardm_fchown_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit fchown" test_ref="oval:ssg-test_64bit_ardm_fchown_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_dac_modification_fchownat:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Discretionary Access Controls - fchownat</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_dac_modification_fchownat" source="ssg"/>
            <oval-def:description>The changing of file permissions and attributes should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit fchownat" test_ref="oval:ssg-test_32bit_ardm_fchownat_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit fchownat" test_ref="oval:ssg-test_64bit_ardm_fchownat_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit fchownat" test_ref="oval:ssg-test_32bit_ardm_fchownat_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit fchownat" test_ref="oval:ssg-test_64bit_ardm_fchownat_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_dac_modification_fremovexattr:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Discretionary Access Controls - fremovexattr</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_dac_modification_fremovexattr" source="ssg"/>
            <oval-def:description>The changing of file permissions and attributes should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit fremovexattr" test_ref="oval:ssg-test_32bit_ardm_fremovexattr_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit fremovexattr" test_ref="oval:ssg-test_64bit_ardm_fremovexattr_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit fremovexattr" test_ref="oval:ssg-test_32bit_ardm_fremovexattr_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit fremovexattr" test_ref="oval:ssg-test_64bit_ardm_fremovexattr_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_dac_modification_fsetxattr:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Discretionary Access Controls - fsetxattr</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_dac_modification_fsetxattr" source="ssg"/>
            <oval-def:description>The changing of file permissions and attributes should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit fsetxattr" test_ref="oval:ssg-test_32bit_ardm_fsetxattr_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit fsetxattr" test_ref="oval:ssg-test_64bit_ardm_fsetxattr_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit fsetxattr" test_ref="oval:ssg-test_32bit_ardm_fsetxattr_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit fsetxattr" test_ref="oval:ssg-test_64bit_ardm_fsetxattr_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_dac_modification_lchown:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Discretionary Access Controls - lchown</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_dac_modification_lchown" source="ssg"/>
            <oval-def:description>The changing of file permissions and attributes should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit lchown" test_ref="oval:ssg-test_32bit_ardm_lchown_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit lchown" test_ref="oval:ssg-test_64bit_ardm_lchown_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit lchown" test_ref="oval:ssg-test_32bit_ardm_lchown_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit lchown" test_ref="oval:ssg-test_64bit_ardm_lchown_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_dac_modification_lremovexattr:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Discretionary Access Controls - lremovexattr</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_dac_modification_lremovexattr" source="ssg"/>
            <oval-def:description>The changing of file permissions and attributes should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit lremovexattr" test_ref="oval:ssg-test_32bit_ardm_lremovexattr_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit lremovexattr" test_ref="oval:ssg-test_64bit_ardm_lremovexattr_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit lremovexattr" test_ref="oval:ssg-test_32bit_ardm_lremovexattr_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit lremovexattr" test_ref="oval:ssg-test_64bit_ardm_lremovexattr_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_dac_modification_lsetxattr:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Discretionary Access Controls - lsetxattr</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_dac_modification_lsetxattr" source="ssg"/>
            <oval-def:description>The changing of file permissions and attributes should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit lsetxattr" test_ref="oval:ssg-test_32bit_ardm_lsetxattr_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit lsetxattr" test_ref="oval:ssg-test_64bit_ardm_lsetxattr_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit lsetxattr" test_ref="oval:ssg-test_32bit_ardm_lsetxattr_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit lsetxattr" test_ref="oval:ssg-test_64bit_ardm_lsetxattr_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_dac_modification_removexattr:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Discretionary Access Controls - removexattr</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_dac_modification_removexattr" source="ssg"/>
            <oval-def:description>The changing of file permissions and attributes should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit removexattr" test_ref="oval:ssg-test_32bit_ardm_removexattr_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit removexattr" test_ref="oval:ssg-test_64bit_ardm_removexattr_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit removexattr" test_ref="oval:ssg-test_32bit_ardm_removexattr_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit removexattr" test_ref="oval:ssg-test_64bit_ardm_removexattr_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_dac_modification_setxattr:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Discretionary Access Controls - setxattr</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_dac_modification_setxattr" source="ssg"/>
            <oval-def:description>The changing of file permissions and attributes should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit setxattr" test_ref="oval:ssg-test_32bit_ardm_setxattr_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit setxattr" test_ref="oval:ssg-test_64bit_ardm_setxattr_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit setxattr" test_ref="oval:ssg-test_32bit_ardm_setxattr_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit setxattr" test_ref="oval:ssg-test_64bit_ardm_setxattr_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_dac_modification_umount2:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Discretionary Access Controls - umount2</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_dac_modification_umount2" source="ssg"/>
            <oval-def:description>The changing of file permissions and attributes should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit umount2" test_ref="oval:ssg-test_32bit_ardm_umount2_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit umount2" test_ref="oval:ssg-test_64bit_ardm_umount2_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit umount2" test_ref="oval:ssg-test_32bit_ardm_umount2_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit umount2" test_ref="oval:ssg-test_64bit_ardm_umount2_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_etc_cron_d:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Changes to Cron Jobs - /etc/cron.d/</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_etc_cron_d" source="ssg"/>
            <oval-def:description>Check if actions on '/etc/cron.d/' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules cron_d" test_ref="oval:ssg-test_audit_rules_etc_cron_d_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl cron_d" test_ref="oval:ssg-test_audit_rules_etc_cron_d_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_etc_group_open:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information via open syscall - /etc/group</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_etc_group_open" source="ssg"/>
            <oval-def:description>Audit rules about the write events to /etc/group</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/group" test_ref="oval:ssg-test_audit_rules_tc_group_open_32bit_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/group" test_ref="oval:ssg-test_audit_rules_tc_group_open_64bit_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/group" test_ref="oval:ssg-test_audit_rules_tc_group_open_32bit_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/group" test_ref="oval:ssg-test_audit_rules_tc_group_open_64bit_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_etc_group_open_by_handle_at:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/group</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_etc_group_open_by_handle_at" source="ssg"/>
            <oval-def:description>Audit rules about the write events to /etc/group</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/group" test_ref="oval:ssg-test_audit_rules_tc_group_open_by_handle_at_32bit_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/group" test_ref="oval:ssg-test_audit_rules_tc_group_open_by_handle_at_64bit_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/group" test_ref="oval:ssg-test_audit_rules_tc_group_open_by_handle_at_32bit_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/group" test_ref="oval:ssg-test_audit_rules_tc_group_open_by_handle_at_64bit_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_etc_group_openat:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information via openat syscall - /etc/group</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_etc_group_openat" source="ssg"/>
            <oval-def:description>Audit rules about the write events to /etc/group</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/group" test_ref="oval:ssg-test_audit_rules_tc_group_openat_32bit_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/group" test_ref="oval:ssg-test_audit_rules_tc_group_openat_64bit_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/group" test_ref="oval:ssg-test_audit_rules_tc_group_openat_32bit_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/group" test_ref="oval:ssg-test_audit_rules_tc_group_openat_64bit_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_etc_gshadow_open:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information via open syscall - /etc/gshadow</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_etc_gshadow_open" source="ssg"/>
            <oval-def:description>Audit rules about the write events to /etc/gshadow</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/gshadow" test_ref="oval:ssg-test_audit_rules_tc_gshadow_open_32bit_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/gshadow" test_ref="oval:ssg-test_audit_rules_tc_gshadow_open_64bit_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/gshadow" test_ref="oval:ssg-test_audit_rules_tc_gshadow_open_32bit_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/gshadow" test_ref="oval:ssg-test_audit_rules_tc_gshadow_open_64bit_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_etc_gshadow_open_by_handle_at:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/gshadow</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_etc_gshadow_open_by_handle_at" source="ssg"/>
            <oval-def:description>Audit rules about the write events to /etc/gshadow</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/gshadow" test_ref="oval:ssg-test_audit_rules_tc_gshadow_open_by_handle_at_32bit_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/gshadow" test_ref="oval:ssg-test_audit_rules_tc_gshadow_open_by_handle_at_64bit_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/gshadow" test_ref="oval:ssg-test_audit_rules_tc_gshadow_open_by_handle_at_32bit_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/gshadow" test_ref="oval:ssg-test_audit_rules_tc_gshadow_open_by_handle_at_64bit_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_etc_gshadow_openat:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information via openat syscall - /etc/gshadow</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_etc_gshadow_openat" source="ssg"/>
            <oval-def:description>Audit rules about the write events to /etc/gshadow</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/gshadow" test_ref="oval:ssg-test_audit_rules_tc_gshadow_openat_32bit_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/gshadow" test_ref="oval:ssg-test_audit_rules_tc_gshadow_openat_64bit_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/gshadow" test_ref="oval:ssg-test_audit_rules_tc_gshadow_openat_32bit_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/gshadow" test_ref="oval:ssg-test_audit_rules_tc_gshadow_openat_64bit_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_etc_passwd_open:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information via open syscall - /etc/passwd</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_etc_passwd_open" source="ssg"/>
            <oval-def:description>Audit rules about the write events to /etc/passwd</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/passwd" test_ref="oval:ssg-test_audit_rules_tc_passwd_open_32bit_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/passwd" test_ref="oval:ssg-test_audit_rules_tc_passwd_open_64bit_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/passwd" test_ref="oval:ssg-test_audit_rules_tc_passwd_open_32bit_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/passwd" test_ref="oval:ssg-test_audit_rules_tc_passwd_open_64bit_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_etc_passwd_open_by_handle_at:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/passwd</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_etc_passwd_open_by_handle_at" source="ssg"/>
            <oval-def:description>Audit rules about the write events to /etc/passwd</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/passwd" test_ref="oval:ssg-test_audit_rules_tc_passwd_open_by_handle_at_32bit_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/passwd" test_ref="oval:ssg-test_audit_rules_tc_passwd_open_by_handle_at_64bit_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/passwd" test_ref="oval:ssg-test_audit_rules_tc_passwd_open_by_handle_at_32bit_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/passwd" test_ref="oval:ssg-test_audit_rules_tc_passwd_open_by_handle_at_64bit_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_etc_passwd_openat:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information via openat syscall - /etc/passwd</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_etc_passwd_openat" source="ssg"/>
            <oval-def:description>Audit rules about the write events to /etc/passwd</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/passwd" test_ref="oval:ssg-test_audit_rules_tc_passwd_openat_32bit_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/passwd" test_ref="oval:ssg-test_audit_rules_tc_passwd_openat_64bit_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/passwd" test_ref="oval:ssg-test_audit_rules_tc_passwd_openat_32bit_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/passwd" test_ref="oval:ssg-test_audit_rules_tc_passwd_openat_64bit_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_etc_shadow_open:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information via open syscall - /etc/shadow</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_etc_shadow_open" source="ssg"/>
            <oval-def:description>Audit rules about the write events to /etc/shadow</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/shadow" test_ref="oval:ssg-test_audit_rules_tc_shadow_open_32bit_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/shadow" test_ref="oval:ssg-test_audit_rules_tc_shadow_open_64bit_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/shadow" test_ref="oval:ssg-test_audit_rules_tc_shadow_open_32bit_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/shadow" test_ref="oval:ssg-test_audit_rules_tc_shadow_open_64bit_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_etc_shadow_open_by_handle_at:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/shadow</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_etc_shadow_open_by_handle_at" source="ssg"/>
            <oval-def:description>Audit rules about the write events to /etc/shadow</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/shadow" test_ref="oval:ssg-test_audit_rules_tc_shadow_open_by_handle_at_32bit_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/shadow" test_ref="oval:ssg-test_audit_rules_tc_shadow_open_by_handle_at_64bit_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/shadow" test_ref="oval:ssg-test_audit_rules_tc_shadow_open_by_handle_at_32bit_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/shadow" test_ref="oval:ssg-test_audit_rules_tc_shadow_open_by_handle_at_64bit_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_etc_shadow_openat:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information via openat syscall - /etc/shadow</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_etc_shadow_openat" source="ssg"/>
            <oval-def:description>Audit rules about the write events to /etc/shadow</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/shadow" test_ref="oval:ssg-test_audit_rules_tc_shadow_openat_32bit_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/shadow" test_ref="oval:ssg-test_audit_rules_tc_shadow_openat_64bit_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit rule to record write events to /etc/shadow" test_ref="oval:ssg-test_audit_rules_tc_shadow_openat_32bit_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit rule to record write events to /etc/shadow" test_ref="oval:ssg-test_audit_rules_tc_shadow_openat_64bit_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_execution_chacl:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Any Attempts to Run chacl</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_execution_chacl" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of chacl is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules chacl" test_ref="oval:ssg-test_audit_rules_execution_chacl_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl chacl" test_ref="oval:ssg-test_audit_rules_execution_chacl_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_execution_chcon:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Any Attempts to Run chcon</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_execution_chcon" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of chcon is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules chcon" test_ref="oval:ssg-test_audit_rules_execution_chcon_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl chcon" test_ref="oval:ssg-test_audit_rules_execution_chcon_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_execution_restorecon:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Any Attempts to Run restorecon</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_execution_restorecon" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of restorecon is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules restorecon" test_ref="oval:ssg-test_audit_rules_execution_restorecon_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl restorecon" test_ref="oval:ssg-test_audit_rules_execution_restorecon_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_execution_semanage:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Any Attempts to Run semanage</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_execution_semanage" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of semanage is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules semanage" test_ref="oval:ssg-test_audit_rules_execution_semanage_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl semanage" test_ref="oval:ssg-test_audit_rules_execution_semanage_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_execution_setfacl:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Any Attempts to Run setfacl</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_execution_setfacl" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of setfacl is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules setfacl" test_ref="oval:ssg-test_audit_rules_execution_setfacl_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl setfacl" test_ref="oval:ssg-test_audit_rules_execution_setfacl_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_execution_setfiles:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Any Attempts to Run setfiles</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_execution_setfiles" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of setfiles is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules setfiles" test_ref="oval:ssg-test_audit_rules_execution_setfiles_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl setfiles" test_ref="oval:ssg-test_audit_rules_execution_setfiles_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_execution_setsebool:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Any Attempts to Run setsebool</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_execution_setsebool" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of setsebool is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules setsebool" test_ref="oval:ssg-test_audit_rules_execution_setsebool_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl setsebool" test_ref="oval:ssg-test_audit_rules_execution_setsebool_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_execution_seunshare:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Any Attempts to Run seunshare</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_execution_seunshare" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of seunshare is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules seunshare" test_ref="oval:ssg-test_audit_rules_execution_seunshare_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl seunshare" test_ref="oval:ssg-test_audit_rules_execution_seunshare_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_file_deletion_events_rename:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects File Deletion Events by User - rename</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_file_deletion_events_rename" source="ssg"/>
            <oval-def:description>The deletion of files should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit rename" test_ref="oval:ssg-test_32bit_ardm_rename_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit rename" test_ref="oval:ssg-test_64bit_ardm_rename_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit rename" test_ref="oval:ssg-test_32bit_ardm_rename_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit rename" test_ref="oval:ssg-test_64bit_ardm_rename_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_file_deletion_events_renameat:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects File Deletion Events by User - renameat</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_file_deletion_events_renameat" source="ssg"/>
            <oval-def:description>The deletion of files should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit renameat" test_ref="oval:ssg-test_32bit_ardm_renameat_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit renameat" test_ref="oval:ssg-test_64bit_ardm_renameat_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit renameat" test_ref="oval:ssg-test_32bit_ardm_renameat_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit renameat" test_ref="oval:ssg-test_64bit_ardm_renameat_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_file_deletion_events_renameat2:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects File Deletion Events by User - renameat2</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_file_deletion_events_renameat2" source="ssg"/>
            <oval-def:description>The deletion of files should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit renameat2" test_ref="oval:ssg-test_32bit_ardm_renameat2_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit renameat2" test_ref="oval:ssg-test_64bit_ardm_renameat2_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit renameat2" test_ref="oval:ssg-test_32bit_ardm_renameat2_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit renameat2" test_ref="oval:ssg-test_64bit_ardm_renameat2_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_file_deletion_events_rmdir:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects File Deletion Events by User - rmdir</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_file_deletion_events_rmdir" source="ssg"/>
            <oval-def:description>The deletion of files should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit rmdir" test_ref="oval:ssg-test_32bit_ardm_rmdir_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit rmdir" test_ref="oval:ssg-test_64bit_ardm_rmdir_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit rmdir" test_ref="oval:ssg-test_32bit_ardm_rmdir_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit rmdir" test_ref="oval:ssg-test_64bit_ardm_rmdir_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_file_deletion_events_unlink:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects File Deletion Events by User - unlink</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_file_deletion_events_unlink" source="ssg"/>
            <oval-def:description>The deletion of files should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit unlink" test_ref="oval:ssg-test_32bit_ardm_unlink_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit unlink" test_ref="oval:ssg-test_64bit_ardm_unlink_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit unlink" test_ref="oval:ssg-test_32bit_ardm_unlink_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit unlink" test_ref="oval:ssg-test_64bit_ardm_unlink_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_file_deletion_events_unlinkat:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects File Deletion Events by User - unlinkat</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_file_deletion_events_unlinkat" source="ssg"/>
            <oval-def:description>The deletion of files should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit unlinkat" test_ref="oval:ssg-test_32bit_ardm_unlinkat_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit unlinkat" test_ref="oval:ssg-test_64bit_ardm_unlinkat_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit unlinkat" test_ref="oval:ssg-test_32bit_ardm_unlinkat_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit unlinkat" test_ref="oval:ssg-test_64bit_ardm_unlinkat_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_kernel_module_loading_create:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on Kernel Module Unloading - create_module</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_kernel_module_loading_create" source="ssg"/>
            <oval-def:description>The audit rules should be configured to log information about kernel module loading and unloading.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit create_module" test_ref="oval:ssg-test_32bit_arkml_create_module_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit create_module" test_ref="oval:ssg-test_64bit_arkml_create_module_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit create_module" test_ref="oval:ssg-test_32bit_arkml_create_module_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit create_module" test_ref="oval:ssg-test_64bit_arkml_create_module_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_kernel_module_loading_delete:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on Kernel Module Unloading - delete_module</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_kernel_module_loading_delete" source="ssg"/>
            <oval-def:description>The audit rules should be configured to log information about kernel module loading and unloading.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit delete_module" test_ref="oval:ssg-test_32bit_arkml_delete_module_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit delete_module" test_ref="oval:ssg-test_64bit_arkml_delete_module_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit delete_module" test_ref="oval:ssg-test_32bit_arkml_delete_module_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit delete_module" test_ref="oval:ssg-test_64bit_arkml_delete_module_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_kernel_module_loading_finit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on Kernel Module Loading and Unloading - finit_module</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_kernel_module_loading_finit" source="ssg"/>
            <oval-def:description>The audit rules should be configured to log information about kernel module loading and unloading.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit finit_module" test_ref="oval:ssg-test_32bit_arkml_finit_module_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit finit_module" test_ref="oval:ssg-test_64bit_arkml_finit_module_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit finit_module" test_ref="oval:ssg-test_32bit_arkml_finit_module_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit finit_module" test_ref="oval:ssg-test_64bit_arkml_finit_module_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_kernel_module_loading_init:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on Kernel Module Loading - init_module</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_kernel_module_loading_init" source="ssg"/>
            <oval-def:description>The audit rules should be configured to log information about kernel module loading and unloading.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit init_module" test_ref="oval:ssg-test_32bit_arkml_init_module_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit init_module" test_ref="oval:ssg-test_64bit_arkml_init_module_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit init_module" test_ref="oval:ssg-test_32bit_arkml_init_module_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit init_module" test_ref="oval:ssg-test_64bit_arkml_init_module_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_kernel_module_loading_query:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on Kernel Module Loading and Unloading - query_module</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_kernel_module_loading_query" source="ssg"/>
            <oval-def:description>The audit rules should be configured to log information about kernel module loading and unloading.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit query_module" test_ref="oval:ssg-test_32bit_arkml_query_module_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit query_module" test_ref="oval:ssg-test_64bit_arkml_query_module_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit query_module" test_ref="oval:ssg-test_32bit_arkml_query_module_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit query_module" test_ref="oval:ssg-test_64bit_arkml_query_module_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_login_events_faillock:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Attempts to Alter Logon and Logout Events - faillock</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_login_events_faillock" source="ssg"/>
            <oval-def:description>Check if actions on path specified in the 'var_accounts_passwords_pam_faillock_dir' variable are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules var_accounts_passwords_pam_faillock_dir" test_ref="oval:ssg-test_audit_rules_login_events_faillock_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl var_accounts_passwords_pam_faillock_dir" test_ref="oval:ssg-test_audit_rules_login_events_faillock_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_login_events_lastlog:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Attempts to Alter Logon and Logout Events - lastlog</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_login_events_lastlog" source="ssg"/>
            <oval-def:description>Check if actions on '/var/log/lastlog' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules lastlog" test_ref="oval:ssg-test_audit_rules_login_events_lastlog_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl lastlog" test_ref="oval:ssg-test_audit_rules_login_events_lastlog_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_login_events_tallylog:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Attempts to Alter Logon and Logout Events - tallylog</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_login_events_tallylog" source="ssg"/>
            <oval-def:description>Check if actions on '/var/log/tallylog' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules tallylog" test_ref="oval:ssg-test_audit_rules_login_events_tallylog_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl tallylog" test_ref="oval:ssg-test_audit_rules_login_events_tallylog_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_mac_modification_usr_share:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Mandatory Access Controls in usr/share</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_mac_modification_usr_share" source="ssg"/>
            <oval-def:description>Check if actions on '/usr/share/selinux/' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules selinux" test_ref="oval:ssg-test_audit_rules_mac_modification_usr_share_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl selinux" test_ref="oval:ssg-test_audit_rules_mac_modification_usr_share_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_media_export:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on Exporting to Media (successful)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_media_export" source="ssg"/>
            <oval-def:description>The changing of file permissions and attributes should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit mount" test_ref="oval:ssg-test_32bit_ardm_mount_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit mount" test_ref="oval:ssg-test_64bit_ardm_mount_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit mount" test_ref="oval:ssg-test_32bit_ardm_mount_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit mount" test_ref="oval:ssg-test_64bit_ardm_mount_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_networkconfig_modification_network_scripts:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Network Environment - /etc/sysconfig/network-scripts</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_networkconfig_modification_network_scripts" source="ssg"/>
            <oval-def:description>Check if actions on '/etc/sysconfig/network-scripts' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules network_scripts" test_ref="oval:ssg-test_audit_rules_networkconfig_modification_network_scripts_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl network_scripts" test_ref="oval:ssg-test_audit_rules_networkconfig_modification_network_scripts_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_at:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - at</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_at" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of at is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules at" test_ref="oval:ssg-test_audit_rules_privileged_commands_at_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl at" test_ref="oval:ssg-test_audit_rules_privileged_commands_at_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_chage:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - chage</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_chage" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of chage is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules chage" test_ref="oval:ssg-test_audit_rules_privileged_commands_chage_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl chage" test_ref="oval:ssg-test_audit_rules_privileged_commands_chage_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_chsh:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - chsh</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_chsh" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of chsh is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules chsh" test_ref="oval:ssg-test_audit_rules_privileged_commands_chsh_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl chsh" test_ref="oval:ssg-test_audit_rules_privileged_commands_chsh_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_crontab:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - crontab</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_crontab" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of crontab is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules crontab" test_ref="oval:ssg-test_audit_rules_privileged_commands_crontab_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl crontab" test_ref="oval:ssg-test_audit_rules_privileged_commands_crontab_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_gpasswd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - gpasswd</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_gpasswd" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of gpasswd is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules gpasswd" test_ref="oval:ssg-test_audit_rules_privileged_commands_gpasswd_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl gpasswd" test_ref="oval:ssg-test_audit_rules_privileged_commands_gpasswd_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_kmod:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - kmod</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_kmod" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of kmod is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules kmod" test_ref="oval:ssg-test_audit_rules_privileged_commands_kmod_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl kmod" test_ref="oval:ssg-test_audit_rules_privileged_commands_kmod_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_mount:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - mount</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_mount" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of mount is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules mount" test_ref="oval:ssg-test_audit_rules_privileged_commands_mount_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl mount" test_ref="oval:ssg-test_audit_rules_privileged_commands_mount_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_newgidmap:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - newgidmap</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_newgidmap" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of newgidmap is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules newgidmap" test_ref="oval:ssg-test_audit_rules_privileged_commands_newgidmap_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl newgidmap" test_ref="oval:ssg-test_audit_rules_privileged_commands_newgidmap_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_newgrp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - newgrp</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_newgrp" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of newgrp is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules newgrp" test_ref="oval:ssg-test_audit_rules_privileged_commands_newgrp_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl newgrp" test_ref="oval:ssg-test_audit_rules_privileged_commands_newgrp_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_newuidmap:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - newuidmap</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_newuidmap" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of newuidmap is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules newuidmap" test_ref="oval:ssg-test_audit_rules_privileged_commands_newuidmap_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl newuidmap" test_ref="oval:ssg-test_audit_rules_privileged_commands_newuidmap_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_pam_timestamp_check:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - pam_timestamp_check</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_pam_timestamp_check" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of pam_timestamp_check is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules pam_timestamp_check" test_ref="oval:ssg-test_audit_rules_privileged_commands_pam_timestamp_check_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl pam_timestamp_check" test_ref="oval:ssg-test_audit_rules_privileged_commands_pam_timestamp_check_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_passwd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - passwd</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_passwd" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of passwd is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules passwd" test_ref="oval:ssg-test_audit_rules_privileged_commands_passwd_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl passwd" test_ref="oval:ssg-test_audit_rules_privileged_commands_passwd_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_postdrop:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - postdrop</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_postdrop" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of postdrop is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules postdrop" test_ref="oval:ssg-test_audit_rules_privileged_commands_postdrop_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl postdrop" test_ref="oval:ssg-test_audit_rules_privileged_commands_postdrop_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_postqueue:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - postqueue</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_postqueue" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of postqueue is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules postqueue" test_ref="oval:ssg-test_audit_rules_privileged_commands_postqueue_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl postqueue" test_ref="oval:ssg-test_audit_rules_privileged_commands_postqueue_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_pt_chown:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - pt_chown</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_pt_chown" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of pt_chown is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules pt_chown" test_ref="oval:ssg-test_audit_rules_privileged_commands_pt_chown_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl pt_chown" test_ref="oval:ssg-test_audit_rules_privileged_commands_pt_chown_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_ssh_agent:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Any Attempts to Run ssh-agent</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_ssh_agent" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of ssh_agent is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules ssh_agent" test_ref="oval:ssg-test_audit_rules_privileged_commands_ssh_agent_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl ssh_agent" test_ref="oval:ssg-test_audit_rules_privileged_commands_ssh_agent_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_ssh_keysign:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - ssh-keysign</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_ssh_keysign" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of ssh_keysign is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules ssh_keysign" test_ref="oval:ssg-test_audit_rules_privileged_commands_ssh_keysign_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl ssh_keysign" test_ref="oval:ssg-test_audit_rules_privileged_commands_ssh_keysign_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_su:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - su</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_su" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of su is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules su" test_ref="oval:ssg-test_audit_rules_privileged_commands_su_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl su" test_ref="oval:ssg-test_audit_rules_privileged_commands_su_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_sudo:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - sudo</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_sudo" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of sudo is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules sudo" test_ref="oval:ssg-test_audit_rules_privileged_commands_sudo_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl sudo" test_ref="oval:ssg-test_audit_rules_privileged_commands_sudo_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_sudoedit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - sudoedit</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_sudoedit" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of sudoedit is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules sudoedit" test_ref="oval:ssg-test_audit_rules_privileged_commands_sudoedit_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl sudoedit" test_ref="oval:ssg-test_audit_rules_privileged_commands_sudoedit_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_umount:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - umount</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_umount" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of umount is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules umount" test_ref="oval:ssg-test_audit_rules_privileged_commands_umount_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl umount" test_ref="oval:ssg-test_audit_rules_privileged_commands_umount_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_unix_chkpwd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - unix_chkpwd</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_unix_chkpwd" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of unix_chkpwd is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules unix_chkpwd" test_ref="oval:ssg-test_audit_rules_privileged_commands_unix_chkpwd_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl unix_chkpwd" test_ref="oval:ssg-test_audit_rules_privileged_commands_unix_chkpwd_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_unix_update:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - unix_update</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_unix_update" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of unix_update is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules unix_update" test_ref="oval:ssg-test_audit_rules_privileged_commands_unix_update_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl unix_update" test_ref="oval:ssg-test_audit_rules_privileged_commands_unix_update_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_userhelper:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - userhelper</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_userhelper" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of userhelper is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules userhelper" test_ref="oval:ssg-test_audit_rules_privileged_commands_userhelper_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl userhelper" test_ref="oval:ssg-test_audit_rules_privileged_commands_userhelper_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_usermod:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - usermod</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_usermod" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of usermod is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules usermod" test_ref="oval:ssg-test_audit_rules_privileged_commands_usermod_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl usermod" test_ref="oval:ssg-test_audit_rules_privileged_commands_usermod_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_privileged_commands_usernetctl:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Information on the Use of Privileged Commands - usernetctl</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_privileged_commands_usernetctl" source="ssg"/>
            <oval-def:description>Audit rules about the information on the use of usernetctl is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules usernetctl" test_ref="oval:ssg-test_audit_rules_privileged_commands_usernetctl_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl usernetctl" test_ref="oval:ssg-test_audit_rules_privileged_commands_usernetctl_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_session_events_btmp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Attempts to Alter Process and Session Initiation Information btmp</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_session_events_btmp" source="ssg"/>
            <oval-def:description>Check if actions on '/var/log/btmp' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules btmp" test_ref="oval:ssg-test_audit_rules_session_events_btmp_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl btmp" test_ref="oval:ssg-test_audit_rules_session_events_btmp_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_session_events_utmp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Attempts to Alter Process and Session Initiation Information utmp</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_session_events_utmp" source="ssg"/>
            <oval-def:description>Check if actions on '/var/run/utmp' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules utmp" test_ref="oval:ssg-test_audit_rules_session_events_utmp_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl utmp" test_ref="oval:ssg-test_audit_rules_session_events_utmp_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_session_events_wtmp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Attempts to Alter Process and Session Initiation Information wtmp</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_session_events_wtmp" source="ssg"/>
            <oval-def:description>Check if actions on '/var/log/wtmp' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules wtmp" test_ref="oval:ssg-test_audit_rules_session_events_wtmp_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl wtmp" test_ref="oval:ssg-test_audit_rules_session_events_wtmp_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_sudoers:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects System Administrator Actions - /etc/sudoers</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_sudoers" source="ssg"/>
            <oval-def:description>Check if actions on '/etc/sudoers' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules sudoers" test_ref="oval:ssg-test_audit_rules_sudoers_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl sudoers" test_ref="oval:ssg-test_audit_rules_sudoers_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_sudoers_d:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects System Administrator Actions - /etc/sudoers.d/</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_sudoers_d" source="ssg"/>
            <oval-def:description>Check if actions on '/etc/sudoers.d/' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules sudoers_d" test_ref="oval:ssg-test_audit_rules_sudoers_d_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl sudoers_d" test_ref="oval:ssg-test_audit_rules_sudoers_d_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_time_watch_localtime:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Attempts to Alter the localtime File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_time_watch_localtime" source="ssg"/>
            <oval-def:description>Check if actions on '/etc/localtime' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules localtime" test_ref="oval:ssg-test_audit_rules_time_watch_localtime_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl localtime" test_ref="oval:ssg-test_audit_rules_time_watch_localtime_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_chmod:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Permission Changes to Files - chmod</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_chmod" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_chmod_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_chmod_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_chmod_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_chmod_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_chmod_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_chmod_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_chmod_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_chmod_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_chown:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Ownership Changes to Files - chown</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_chown" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_chown_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_chown_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_chown_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_chown_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_chown_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_chown_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_chown_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_chown_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_creat:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Access Attempts to Files - creat</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_creat" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_creat_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_creat_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_creat_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_creat_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_creat_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_creat_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_creat_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_creat_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_fchmod:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Permission Changes to Files - fchmod</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_fchmod" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_fchmod_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_fchmod_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_fchmod_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_fchmod_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_fchmod_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_fchmod_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_fchmod_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_fchmod_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_fchmodat:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Permission Changes to Files - fchmodat</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_fchmodat" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_fchmodat_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_fchmodat_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_fchmodat_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_fchmodat_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_fchmodat_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_fchmodat_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_fchmodat_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_fchmodat_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_fchown:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Ownership Changes to Files - fchown</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_fchown" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_fchown_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_fchown_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_fchown_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_fchown_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_fchown_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_fchown_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_fchown_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_fchown_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_fchownat:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Ownership Changes to Files - fchownat</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_fchownat" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_fchownat_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_fchownat_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_fchownat_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_fchownat_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_fchownat_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_fchownat_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_fchownat_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_fchownat_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_fremovexattr:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Permission Changes to Files - fremovexattr</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_fremovexattr" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_fremovexattr_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_fremovexattr_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_fremovexattr_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_fremovexattr_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_fremovexattr_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_fremovexattr_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_fremovexattr_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_fremovexattr_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_fsetxattr:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Permission Changes to Files - fsetxattr</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_fsetxattr" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_fsetxattr_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_fsetxattr_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_fsetxattr_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_fsetxattr_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_fsetxattr_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_fsetxattr_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_fsetxattr_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_fsetxattr_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_ftruncate:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Access Attempts to Files - ftruncate</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_ftruncate" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_ftruncate_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_ftruncate_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_ftruncate_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_ftruncate_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_ftruncate_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_ftruncate_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_ftruncate_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_ftruncate_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_lchown:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Ownership Changes to Files - lchown</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_lchown" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_lchown_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_lchown_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_lchown_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_lchown_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_lchown_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_lchown_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_lchown_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_lchown_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_lremovexattr:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Permission Changes to Files - lremovexattr</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_lremovexattr" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_lremovexattr_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_lremovexattr_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_lremovexattr_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_lremovexattr_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_lremovexattr_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_lremovexattr_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_lremovexattr_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_lremovexattr_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_lsetxattr:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Permission Changes to Files - lsetxattr</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_lsetxattr" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_lsetxattr_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_lsetxattr_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_lsetxattr_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_lsetxattr_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_lsetxattr_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_lsetxattr_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_lsetxattr_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_lsetxattr_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_open:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Access Attempts to Files - open</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_open" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_open_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_open_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_open_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_open_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_open_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_open_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_open_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_open_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Access Attempts to Files - open_by_handle_at</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_open_by_handle_at" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_open_by_handle_at_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_open_by_handle_at_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_open_by_handle_at_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_open_by_handle_at_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_open_by_handle_at_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_open_by_handle_at_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_open_by_handle_at_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_open_by_handle_at_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Creation Attempts to Files - open_by_handle_at O_CREAT</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat" source="ssg"/>
            <oval-def:description>Audit rules about the information on the unsuccessful use of open_by_handle_at O_CREAT is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="Verify audit rule open_by_handle_at 32bit a2&amp;0100 eacces augenrules exists" test_ref="oval:ssg-test_arufm_open_by_handle_at_o_creat_32bit_a20100_eacces_augenrules:tst:1"/>
              <oval-def:criterion comment="Verify audit rule open_by_handle_at 32bit a2&amp;0100 eperm augenrules exists" test_ref="oval:ssg-test_arufm_open_by_handle_at_o_creat_32bit_a20100_eperm_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="Verify audit rule open_by_handle_at 64bit a2&amp;0100 eacces augenrules exists" test_ref="oval:ssg-test_arufm_open_by_handle_at_o_creat_64bit_a20100_eacces_augenrules:tst:1"/>
                  <oval-def:criterion comment="Verify audit rule open_by_handle_at 64bit a2&amp;0100 eperm augenrules exists" test_ref="oval:ssg-test_arufm_open_by_handle_at_o_creat_64bit_a20100_eperm_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="Verify audit rule open_by_handle_at 32bit a2&amp;0100 eacces auditctl exists" test_ref="oval:ssg-test_arufm_open_by_handle_at_o_creat_32bit_a20100_eacces_auditctl:tst:1"/>
              <oval-def:criterion comment="Verify audit rule open_by_handle_at 32bit a2&amp;0100 eperm auditctl exists" test_ref="oval:ssg-test_arufm_open_by_handle_at_o_creat_32bit_a20100_eperm_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="Verify audit rule open_by_handle_at 64bit a2&amp;0100 eacces auditctl exists" test_ref="oval:ssg-test_arufm_open_by_handle_at_o_creat_64bit_a20100_eacces_auditctl:tst:1"/>
                  <oval-def:criterion comment="Verify audit rule open_by_handle_at 64bit a2&amp;0100 eperm auditctl exists" test_ref="oval:ssg-test_arufm_open_by_handle_at_o_creat_64bit_a20100_eperm_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_trunc_write:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Modification Attempts to Files - open_by_handle_at O_TRUNC_WRITE</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_open_by_handle_at_o_trunc_write" source="ssg"/>
            <oval-def:description>Audit rules about the information on the unsuccessful use of open_by_handle_at O_TRUNC is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="Verify audit rule open_by_handle_at 32bit a2&amp;01003 eacces augenrules exists" test_ref="oval:ssg-test_arufm_open_by_handle_at_o_trunc_32bit_a201003_eacces_augenrules:tst:1"/>
              <oval-def:criterion comment="Verify audit rule open_by_handle_at 32bit a2&amp;01003 eperm augenrules exists" test_ref="oval:ssg-test_arufm_open_by_handle_at_o_trunc_32bit_a201003_eperm_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="Verify audit rule open_by_handle_at 64bit a2&amp;01003 eacces augenrules exists" test_ref="oval:ssg-test_arufm_open_by_handle_at_o_trunc_64bit_a201003_eacces_augenrules:tst:1"/>
                  <oval-def:criterion comment="Verify audit rule open_by_handle_at 64bit a2&amp;01003 eperm augenrules exists" test_ref="oval:ssg-test_arufm_open_by_handle_at_o_trunc_64bit_a201003_eperm_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="Verify audit rule open_by_handle_at 32bit a2&amp;01003 eacces auditctl exists" test_ref="oval:ssg-test_arufm_open_by_handle_at_o_trunc_32bit_a201003_eacces_auditctl:tst:1"/>
              <oval-def:criterion comment="Verify audit rule open_by_handle_at 32bit a2&amp;01003 eperm auditctl exists" test_ref="oval:ssg-test_arufm_open_by_handle_at_o_trunc_32bit_a201003_eperm_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="Verify audit rule open_by_handle_at 64bit a2&amp;01003 eacces auditctl exists" test_ref="oval:ssg-test_arufm_open_by_handle_at_o_trunc_64bit_a201003_eacces_auditctl:tst:1"/>
                  <oval-def:criterion comment="Verify audit rule open_by_handle_at 64bit a2&amp;01003 eperm auditctl exists" test_ref="oval:ssg-test_arufm_open_by_handle_at_o_trunc_64bit_a201003_eperm_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Unauthorized Access Attempts To open_by_handle_at Are Ordered Correctly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order" source="ssg"/>
            <oval-def:description>Audit rules about the information on the unsuccessful use of open_by_handle_at is configured in the proper rule order.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_open_by_handle_at_order_32bit_eacces_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_open_by_handle_at_order_32bit_eperm_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit" test_ref="oval:ssg-test_arufm_open_by_handle_at_order_64bit_eacces_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit" test_ref="oval:ssg-test_arufm_open_by_handle_at_order_64bit_eperm_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_open_by_handle_at_order_32bit_eacces_auditctl:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_open_by_handle_at_order_32bit_eperm_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_open_by_handle_at_order_64bit_eacces_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_open_by_handle_at_order_64bit_eperm_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_open_o_creat:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Creation Attempts to Files - open O_CREAT</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_open_o_creat" source="ssg"/>
            <oval-def:description>Audit rules about the information on the unsuccessful use of open O_CREAT is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="Verify audit rule open 32bit a1&amp;0100 eacces augenrules exists" test_ref="oval:ssg-test_arufm_open_o_creat_32bit_a20100_eacces_augenrules:tst:1"/>
              <oval-def:criterion comment="Verify audit rule open 32bit a1&amp;0100 eperm augenrules exists" test_ref="oval:ssg-test_arufm_open_o_creat_32bit_a20100_eperm_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="Verify audit rule open 64bit a1&amp;0100 eacces augenrules exists" test_ref="oval:ssg-test_arufm_open_o_creat_64bit_a20100_eacces_augenrules:tst:1"/>
                  <oval-def:criterion comment="Verify audit rule open 64bit a1&amp;0100 eperm augenrules exists" test_ref="oval:ssg-test_arufm_open_o_creat_64bit_a20100_eperm_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="Verify audit rule open 32bit a1&amp;0100 eacces auditctl exists" test_ref="oval:ssg-test_arufm_open_o_creat_32bit_a20100_eacces_auditctl:tst:1"/>
              <oval-def:criterion comment="Verify audit rule open 32bit a1&amp;0100 eperm auditctl exists" test_ref="oval:ssg-test_arufm_open_o_creat_32bit_a20100_eperm_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="Verify audit rule open 64bit a1&amp;0100 eacces auditctl exists" test_ref="oval:ssg-test_arufm_open_o_creat_64bit_a20100_eacces_auditctl:tst:1"/>
                  <oval-def:criterion comment="Verify audit rule open 64bit a1&amp;0100 eperm auditctl exists" test_ref="oval:ssg-test_arufm_open_o_creat_64bit_a20100_eperm_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_open_o_trunc_write:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Modification Attempts to Files - open O_TRUNC_WRITE</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_open_o_trunc_write" source="ssg"/>
            <oval-def:description>Audit rules about the information on the unsuccessful use of open O_TRUNC is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="Verify audit rule open 32bit a1&amp;01003 eacces augenrules exists" test_ref="oval:ssg-test_arufm_open_o_trunc_32bit_a201003_eacces_augenrules:tst:1"/>
              <oval-def:criterion comment="Verify audit rule open 32bit a1&amp;01003 eperm augenrules exists" test_ref="oval:ssg-test_arufm_open_o_trunc_32bit_a201003_eperm_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="Verify audit rule open 64bit a1&amp;01003 eacces augenrules exists" test_ref="oval:ssg-test_arufm_open_o_trunc_64bit_a201003_eacces_augenrules:tst:1"/>
                  <oval-def:criterion comment="Verify audit rule open 64bit a1&amp;01003 eperm augenrules exists" test_ref="oval:ssg-test_arufm_open_o_trunc_64bit_a201003_eperm_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="Verify audit rule open 32bit a1&amp;01003 eacces auditctl exists" test_ref="oval:ssg-test_arufm_open_o_trunc_32bit_a201003_eacces_auditctl:tst:1"/>
              <oval-def:criterion comment="Verify audit rule open 32bit a1&amp;01003 eperm auditctl exists" test_ref="oval:ssg-test_arufm_open_o_trunc_32bit_a201003_eperm_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="Verify audit rule open 64bit a1&amp;01003 eacces auditctl exists" test_ref="oval:ssg-test_arufm_open_o_trunc_64bit_a201003_eacces_auditctl:tst:1"/>
                  <oval-def:criterion comment="Verify audit rule open 64bit a1&amp;01003 eperm auditctl exists" test_ref="oval:ssg-test_arufm_open_o_trunc_64bit_a201003_eperm_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_open_rule_order:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Rules For Unauthorized Attempts To open Are Ordered Correctly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_open_rule_order" source="ssg"/>
            <oval-def:description>Audit rules about the information on the unsuccessful use of open is configured in the proper rule order.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_open_order_32bit_eacces_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_open_order_32bit_eperm_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit" test_ref="oval:ssg-test_arufm_open_order_64bit_eacces_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit" test_ref="oval:ssg-test_arufm_open_order_64bit_eperm_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_open_order_32bit_eacces_auditctl:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_open_order_32bit_eperm_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_open_order_64bit_eacces_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_open_order_64bit_eperm_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_openat:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Access Attempts to Files - openat</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_openat" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_openat_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_openat_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_openat_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_openat_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_openat_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_openat_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_openat_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_openat_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_openat_o_creat:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Creation Attempts to Files - openat O_CREAT</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_openat_o_creat" source="ssg"/>
            <oval-def:description>Audit rules about the information on the unsuccessful use of openat O_CREAT is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="Verify audit rule openat 32bit a2&amp;0100 eacces augenrules exists" test_ref="oval:ssg-test_arufm_openat_o_creat_32bit_a20100_eacces_augenrules:tst:1"/>
              <oval-def:criterion comment="Verify audit rule openat 32bit a2&amp;0100 eperm augenrules exists" test_ref="oval:ssg-test_arufm_openat_o_creat_32bit_a20100_eperm_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="Verify audit rule openat 64bit a2&amp;0100 eacces augenrules exists" test_ref="oval:ssg-test_arufm_openat_o_creat_64bit_a20100_eacces_augenrules:tst:1"/>
                  <oval-def:criterion comment="Verify audit rule openat 64bit a2&amp;0100 eperm augenrules exists" test_ref="oval:ssg-test_arufm_openat_o_creat_64bit_a20100_eperm_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="Verify audit rule openat 32bit a2&amp;0100 eacces auditctl exists" test_ref="oval:ssg-test_arufm_openat_o_creat_32bit_a20100_eacces_auditctl:tst:1"/>
              <oval-def:criterion comment="Verify audit rule openat 32bit a2&amp;0100 eperm auditctl exists" test_ref="oval:ssg-test_arufm_openat_o_creat_32bit_a20100_eperm_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="Verify audit rule openat 64bit a2&amp;0100 eacces auditctl exists" test_ref="oval:ssg-test_arufm_openat_o_creat_64bit_a20100_eacces_auditctl:tst:1"/>
                  <oval-def:criterion comment="Verify audit rule openat 64bit a2&amp;0100 eperm auditctl exists" test_ref="oval:ssg-test_arufm_openat_o_creat_64bit_a20100_eperm_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_openat_o_trunc_write:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Modification Attempts to Files - openat O_TRUNC_WRITE</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_openat_o_trunc_write" source="ssg"/>
            <oval-def:description>Audit rules about the information on the unsuccessful use of openat O_TRUNC is enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="Verify audit rule openat 32bit a2&amp;01003 eacces augenrules exists" test_ref="oval:ssg-test_arufm_openat_o_trunc_32bit_a201003_eacces_augenrules:tst:1"/>
              <oval-def:criterion comment="Verify audit rule openat 32bit a2&amp;01003 eperm augenrules exists" test_ref="oval:ssg-test_arufm_openat_o_trunc_32bit_a201003_eperm_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="Verify audit rule openat 64bit a2&amp;01003 eacces augenrules exists" test_ref="oval:ssg-test_arufm_openat_o_trunc_64bit_a201003_eacces_augenrules:tst:1"/>
                  <oval-def:criterion comment="Verify audit rule openat 64bit a2&amp;01003 eperm augenrules exists" test_ref="oval:ssg-test_arufm_openat_o_trunc_64bit_a201003_eperm_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="Verify audit rule openat 32bit a2&amp;01003 eacces auditctl exists" test_ref="oval:ssg-test_arufm_openat_o_trunc_32bit_a201003_eacces_auditctl:tst:1"/>
              <oval-def:criterion comment="Verify audit rule openat 32bit a2&amp;01003 eperm auditctl exists" test_ref="oval:ssg-test_arufm_openat_o_trunc_32bit_a201003_eperm_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="Verify audit rule openat 64bit a2&amp;01003 eacces auditctl exists" test_ref="oval:ssg-test_arufm_openat_o_trunc_64bit_a201003_eacces_auditctl:tst:1"/>
                  <oval-def:criterion comment="Verify audit rule openat 64bit a2&amp;01003 eperm auditctl exists" test_ref="oval:ssg-test_arufm_openat_o_trunc_64bit_a201003_eperm_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_openat_rule_order:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Rules For Unauthorized Attempts To openat Are Ordered Correctly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_openat_rule_order" source="ssg"/>
            <oval-def:description>Audit rules about the information on the unsuccessful use of openat is configured in the proper rule order.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_openat_order_32bit_eacces_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_openat_order_32bit_eperm_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit" test_ref="oval:ssg-test_arufm_openat_order_64bit_eacces_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit" test_ref="oval:ssg-test_arufm_openat_order_64bit_eperm_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_openat_order_32bit_eacces_auditctl:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_openat_order_32bit_eperm_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_openat_order_64bit_eacces_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 32-bit" test_ref="oval:ssg-test_arufm_openat_order_64bit_eperm_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_removexattr:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Permission Changes to Files - removexattr</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_removexattr" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_removexattr_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_removexattr_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_removexattr_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_removexattr_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_removexattr_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_removexattr_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_removexattr_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_removexattr_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_rename:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Delete Attempts to Files - rename</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_rename" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_rename_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_rename_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_rename_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_rename_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_rename_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_rename_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_rename_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_rename_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_renameat:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Delete Attempts to Files - renameat</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_renameat" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_renameat_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_renameat_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_renameat_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_renameat_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_renameat_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_renameat_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_renameat_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_renameat_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_setxattr:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Permission Changes to Files - setxattr</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_setxattr" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_setxattr_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_setxattr_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_setxattr_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_setxattr_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_setxattr_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_setxattr_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_setxattr_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_setxattr_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_truncate:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Access Attempts to Files - truncate</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_truncate" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_truncate_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_truncate_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_truncate_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_truncate_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_truncate_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_truncate_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_truncate_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_truncate_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_unlink:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Delete Attempts to Files - unlink</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_unlink" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_unlink_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_unlink_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_unlink_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_unlink_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_unlink_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_unlink_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_unlink_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_unlink_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_unsuccessful_file_modification_unlinkat:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Unsuccessful Delete Attempts to Files - unlinkat</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_unsuccessful_file_modification_unlinkat" source="ssg"/>
            <oval-def:description>Audit rules about the unauthorized access attempts to files (unsuccessful) are enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_unlinkat_augenrules:tst:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_unlinkat_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit augenrules 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_unlinkat_augenrules:tst:1"/>
                  <oval-def:criterion comment="audit augenrules 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_unlinkat_augenrules:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eacces" test_ref="oval:ssg-test_32bit_arufm_eacces_unlinkat_auditctl:tst:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit file eperm" test_ref="oval:ssg-test_32bit_arufm_eperm_unlinkat_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit_system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="audit auditctl 64-bit file eacces" test_ref="oval:ssg-test_64bit_arufm_eacces_unlinkat_auditctl:tst:1"/>
                  <oval-def:criterion comment="audit auditctl 64-bit file eperm" test_ref="oval:ssg-test_64bit_arufm_eperm_unlinkat_auditctl:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_usergroup_modification_group:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information - /etc/group</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_usergroup_modification_group" source="ssg"/>
            <oval-def:description>Check if actions on '/etc/group' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules group" test_ref="oval:ssg-test_audit_rules_usergroup_modification_group_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl group" test_ref="oval:ssg-test_audit_rules_usergroup_modification_group_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_usergroup_modification_gshadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information - /etc/gshadow</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_usergroup_modification_gshadow" source="ssg"/>
            <oval-def:description>Check if actions on '/etc/gshadow' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules gshadow" test_ref="oval:ssg-test_audit_rules_usergroup_modification_gshadow_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl gshadow" test_ref="oval:ssg-test_audit_rules_usergroup_modification_gshadow_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_usergroup_modification_nsswitch_conf:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information - /etc/nsswitch.conf</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_usergroup_modification_nsswitch_conf" source="ssg"/>
            <oval-def:description>Check if actions on '/etc/nsswitch.conf' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules nsswitch_conf" test_ref="oval:ssg-test_audit_rules_usergroup_modification_nsswitch_conf_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl nsswitch_conf" test_ref="oval:ssg-test_audit_rules_usergroup_modification_nsswitch_conf_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_usergroup_modification_opasswd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information - /etc/security/opasswd</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_usergroup_modification_opasswd" source="ssg"/>
            <oval-def:description>Check if actions on '/etc/security/opasswd' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules opasswd" test_ref="oval:ssg-test_audit_rules_usergroup_modification_opasswd_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl opasswd" test_ref="oval:ssg-test_audit_rules_usergroup_modification_opasswd_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_usergroup_modification_pam_conf:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information - /etc/pam.conf</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_usergroup_modification_pam_conf" source="ssg"/>
            <oval-def:description>Check if actions on '/etc/pam.conf' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules pam_conf" test_ref="oval:ssg-test_audit_rules_usergroup_modification_pam_conf_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl pam_conf" test_ref="oval:ssg-test_audit_rules_usergroup_modification_pam_conf_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_usergroup_modification_pamd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information - /etc/pam.d/</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_usergroup_modification_pamd" source="ssg"/>
            <oval-def:description>Check if actions on '/etc/pam.d/' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules pam_d" test_ref="oval:ssg-test_audit_rules_usergroup_modification_pamd_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl pam_d" test_ref="oval:ssg-test_audit_rules_usergroup_modification_pamd_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_usergroup_modification_passwd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information - /etc/passwd</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_usergroup_modification_passwd" source="ssg"/>
            <oval-def:description>Check if actions on '/etc/passwd' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules passwd" test_ref="oval:ssg-test_audit_rules_usergroup_modification_passwd_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl passwd" test_ref="oval:ssg-test_audit_rules_usergroup_modification_passwd_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_usergroup_modification_shadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify User/Group Information - /etc/shadow</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_usergroup_modification_shadow" source="ssg"/>
            <oval-def:description>Check if actions on '/etc/shadow' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules shadow" test_ref="oval:ssg-test_audit_rules_usergroup_modification_shadow_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl shadow" test_ref="oval:ssg-test_audit_rules_usergroup_modification_shadow_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_var_spool_cron:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure auditd Collects Changes to Cron Jobs - /var/spool/cron</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_var_spool_cron" source="ssg"/>
            <oval-def:description>Check if actions on '/var/spool/cron' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules cron" test_ref="oval:ssg-test_audit_rules_var_spool_cron_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl cron" test_ref="oval:ssg-test_audit_rules_var_spool_cron_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_sudo_log_events:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Attempts to perform maintenance activities</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_sudo_log_events" source="ssg"/>
            <oval-def:description>Check if actions on '/var/log/sudo.log' are configured to be audited</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules sudo_log" test_ref="oval:ssg-test_audit_sudo_log_events_augenrules:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl sudo_log" test_ref="oval:ssg-test_audit_sudo_log_events_auditctl:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_freq:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set number of records to cause an explicit flush to audit logs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_freq" source="ssg"/>
            <oval-def:description>Ensure 'freq' is configured with value configured through XCCDF variable var_auditd_freq' in /etc/audit/auditd.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="auditd is configured correctly" operator="OR">
            <oval-def:criterion comment="Check the freq in /etc/audit/auditd.conf" test_ref="oval:ssg-test_auditd_freq:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_local_events:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Include Local Events in Audit Logs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_local_events" source="ssg"/>
            <oval-def:description>Ensure 'local_events' is configured with value 'yes' in /etc/audit/auditd.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="auditd is configured correctly" operator="OR">
            <oval-def:criterion comment="Check the local_events in /etc/audit/auditd.conf" test_ref="oval:ssg-test_auditd_local_events:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_log_format:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Resolve information before writing to audit logs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_log_format" source="ssg"/>
            <oval-def:description>Ensure 'log_format' is configured with value 'ENRICHED' in /etc/audit/auditd.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="auditd is configured correctly" operator="OR">
            <oval-def:criterion comment="Check the log_format in /etc/audit/auditd.conf" test_ref="oval:ssg-test_auditd_log_format:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_write_logs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Write Audit Logs to the Disk</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_write_logs" source="ssg"/>
            <oval-def:description>Ensure 'write_logs' is configured with value 'yes' in /etc/audit/auditd.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="auditd is configured correctly" operator="OR">
            <oval-def:criterion comment="Check the write_logs in /etc/audit/auditd.conf" test_ref="oval:ssg-test_auditd_write_logs:tst:1"/>
            <oval-def:criterion comment="Check the absence of write_logs in /etc/audit/auditd.conf" test_ref="oval:ssg-test_auditd_write_logs_default_not_overriden:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-banner_etc_issue_cis:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Local Login Warning Banner Is Configured Properly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="banner_etc_issue_cis" source="ssg"/>
            <oval-def:description>Check that /etc/issue does not contain OS and version information</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="check" operator="AND">
            <oval-def:criterion comment="Check /etc/issue contains a banner" test_ref="oval:ssg-test_banner_etc_issue_cis_file_nonempty:tst:1"/>
            <oval-def:criterion comment="Check /etc/issue does not contain OS and version information" test_ref="oval:ssg-test_banner_etc_issue_cis:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-banner_etc_issue_net_cis:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Remote Login Warning Banner Is Configured Properly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="banner_etc_issue_net_cis" source="ssg"/>
            <oval-def:description>Check that /etc/issue.net does not contain OS and version information</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="check" operator="AND">
            <oval-def:criterion comment="Check /etc/issue.net contains a banner" test_ref="oval:ssg-test_banner_etc_issue_net_cis_file_nonempty:tst:1"/>
            <oval-def:criterion comment="Check /etc/issue.net does not contain OS and version information" test_ref="oval:ssg-test_banner_etc_issue_net_cis:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-banner_etc_motd_cis:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Message Of The Day Is Configured Properly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="banner_etc_motd_cis" source="ssg"/>
            <oval-def:description>Check that /etc/motd does not contain OS and version information</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="check" operator="AND">
            <oval-def:criterion comment="Check /etc/motd does not contain OS and version information" test_ref="oval:ssg-test_banner_etc_motd_cis:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-configure_custom_crypto_policy_cis:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Implement Custom Crypto Policy Modules for CIS Benchmark</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="configure_custom_crypto_policy_cis" source="ssg"/>
            <oval-def:description>Ensure that the custom crypto policy module is configured</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Ensure that all of the correct lines are in the file." operator="AND">
            <oval-def:criterion comment="Check that cipher@SSH is configured in NO-SSHCBC.pmod" test_ref="oval:ssg-test_configure_custom_crypto_policy_cis_NO-SSHCBC:tst:1"/>
            <oval-def:criterion comment="Check that cipher@SSH is configured in NO-SSHWEAKCIPHERS.pmod" test_ref="oval:ssg-test_configure_custom_crypto_policy_cis_NO-SSHWEAKCIPHERS:tst:1"/>
            <oval-def:criterion comment="Check that mac@SSH is configured in NO-SSHWEAKMACS.pmod" test_ref="oval:ssg-test_configure_custom_crypto_policy_cis_NO-SSHWEAKMACS:tst:1"/>
            <oval-def:criterion comment="Check that mac is configured in NO-WEAKMAC.pmod" test_ref="oval:ssg-test_configure_custom_crypto_policy_cis_NO-WEAKMAC:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-configure_usbguard_auditbackend:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Log USBGuard daemon audit events using Linux Audit</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="configure_usbguard_auditbackend" source="ssg"/>
            <oval-def:description>Ensure 'AuditBackend' is configured with value 'LinuxAudit' in /etc/usbguard/usbguard-daemon.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="usbguard is configured correctly and configuration file exists" operator="AND">
            <oval-def:criteria comment="usbguard is configured correctly" operator="OR">
              <oval-def:criterion comment="Check the AuditBackend in /etc/usbguard/usbguard-daemon.conf" test_ref="oval:ssg-test_configure_usbguard_auditbackend:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="test if configuration file /etc/usbguard/usbguard-daemon.conf exists for configure_usbguard_auditbackend" test_ref="oval:ssg-test_configure_usbguard_auditbackend_config_file_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-coredump_disable_backtraces:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable core dump backtraces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="coredump_disable_backtraces" source="ssg"/>
            <oval-def:description>Ensure 'ProcessSizeMax' is configured with value '0' in section 'Coredump' in /etc/systemd/coredump.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="systemd-coredump is configured correctly" operator="OR">
            <oval-def:criterion comment="Check the ProcessSizeMax in /etc/systemd/coredump.conf" test_ref="oval:ssg-test_coredump_disable_backtraces:tst:1"/>
            <oval-def:criterion comment="Check the ProcessSizeMax in /etc/systemd/coredump.conf.d" test_ref="oval:ssg-test_coredump_disable_backtraces_config_dir:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-coredump_disable_storage:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable storing core dump</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="coredump_disable_storage" source="ssg"/>
            <oval-def:description>Ensure 'Storage' is configured with value 'none' in section 'Coredump' in /etc/systemd/coredump.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="systemd-coredump is configured correctly" operator="OR">
            <oval-def:criterion comment="Check the Storage in /etc/systemd/coredump.conf" test_ref="oval:ssg-test_coredump_disable_storage:tst:1"/>
            <oval-def:criterion comment="Check the Storage in /etc/systemd/coredump.conf.d" test_ref="oval:ssg-test_coredump_disable_storage_config_dir:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-coreos_enable_selinux_kernel_argument:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure SELinux Not Disabled in the kernel arguments</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="coreos_enable_selinux_kernel_argument" source="ssg"/>
            <oval-def:description>Ensure selinux=0 argument is not present in the 'options' line of /boot/loader/entries/ostree-2-*.conf (or ostree-1-*.conf if there is no ostree-2-*.conf as ostree has only two enries at the most, with *-2-*.conf entry always being the most recent). Also, ensure that kernel is currently running with this argument by checking /proc/cmdline.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criteria operator="AND">
                <oval-def:criterion comment="Pass if there are no files matching pattern '/boot/loader/entries/ostree-2.*.conf' exist in the system" test_ref="oval:ssg-test_coreos_enable_selinux_kernel_argument_file_boot_loader_entries_ostree_2_conf_absent:tst:1"/>
                <oval-def:criterion comment="Check if argument selinux=0 for Linux kernel is not present in /boot/loader/entries/ostree-1.*.conf" negate="true" test_ref="oval:ssg-test_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_boot_loader_entries_ostree_1_conf:tst:1"/>
              </oval-def:criteria>
              <oval-def:criteria operator="AND">
                <oval-def:criterion comment="Check if argument selinux=0 for Linux kernel is not present in /boot/loader/entries/ostree-2.*.conf" negate="true" test_ref="oval:ssg-test_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_boot_loader_entries_ostree_2_conf:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check if argument selinux=0 for Linux kernel is not present in /proc/cmdline" negate="true" test_ref="oval:ssg-test_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_proc_cmdline:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_disable_user_admin:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable User Administration in GNOME3</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_disable_user_admin" source="ssg"/>
            <oval-def:description>Ensure 'user-administration-disabled' is configured with value 'true in section 'org/gnome/desktop/lockdown' in /etc/dconf/db/local.d/</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="dconf is configured correctly" operator="AND">
            <oval-def:criterion comment="Check the user-administration-disabled in /etc/dconf/db/local.d/" test_ref="oval:ssg-test_dconf_gnome_disable_user_admin:tst:1"/>
            <oval-def:criterion comment="Prevent user from modifying user-administration-disabled" test_ref="oval:ssg-test_prevent_user_user-administration-disabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dconf_gnome_lock_screen_on_smartcard_removal:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the GNOME3 Screen Locking On Smartcard Removal</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dconf_gnome_lock_screen_on_smartcard_removal" source="ssg"/>
            <oval-def:description>Ensure 'removal-action' is configured with value ''lock-screen' in section 'org/gnome/settings-daemon/peripherals/smartcard' in /etc/dconf/db/local.d/</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="dconf is configured correctly" operator="AND">
            <oval-def:criterion comment="Check the removal-action in /etc/dconf/db/local.d/" test_ref="oval:ssg-test_dconf_gnome_lock_screen_on_smartcard_removal:tst:1"/>
            <oval-def:criterion comment="Prevent user from modifying removal-action" test_ref="oval:ssg-test_prevent_user_removal-action:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dir_group_ownership_library_dirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify that Shared Library Directories Have Root Group Ownership</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dir_group_ownership_library_dirs" source="ssg"/>
            <oval-def:description>This test makes sure that /lib/, /lib64/, /usr/lib/, /usr/lib64/ is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /lib/" test_ref="oval:ssg-test_file_groupownerdir_group_ownership_library_dirs_0:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /lib64/" test_ref="oval:ssg-test_file_groupownerdir_group_ownership_library_dirs_1:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /usr/lib/" test_ref="oval:ssg-test_file_groupownerdir_group_ownership_library_dirs_2:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /usr/lib64/" test_ref="oval:ssg-test_file_groupownerdir_group_ownership_library_dirs_3:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dir_ownership_binary_dirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify that System Executable Have Root Ownership</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dir_ownership_binary_dirs" source="ssg"/>
            <oval-def:description>This test makes sure that /bin/, /sbin/, /usr/bin/, /usr/sbin/, /usr/local/bin/, /usr/local/sbin/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /bin/" test_ref="oval:ssg-test_file_ownerdir_ownership_binary_dirs_0:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /sbin/" test_ref="oval:ssg-test_file_ownerdir_ownership_binary_dirs_1:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /usr/bin/" test_ref="oval:ssg-test_file_ownerdir_ownership_binary_dirs_2:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /usr/sbin/" test_ref="oval:ssg-test_file_ownerdir_ownership_binary_dirs_3:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /usr/local/bin/" test_ref="oval:ssg-test_file_ownerdir_ownership_binary_dirs_4:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /usr/local/sbin/" test_ref="oval:ssg-test_file_ownerdir_ownership_binary_dirs_5:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dir_ownership_library_dirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify that Shared Library Directories Have Root Ownership</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dir_ownership_library_dirs" source="ssg"/>
            <oval-def:description>This test makes sure that /lib/, /lib64/, /usr/lib/, /usr/lib64/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /lib/" test_ref="oval:ssg-test_file_ownerdir_ownership_library_dirs_0:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /lib64/" test_ref="oval:ssg-test_file_ownerdir_ownership_library_dirs_1:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /usr/lib/" test_ref="oval:ssg-test_file_ownerdir_ownership_library_dirs_2:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /usr/lib64/" test_ref="oval:ssg-test_file_ownerdir_ownership_library_dirs_3:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dir_permissions_binary_dirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify that System Executable Directories Have Restrictive Permissions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dir_permissions_binary_dirs" source="ssg"/>
            <oval-def:description>This test makes sure that /bin/, /sbin/, /usr/bin/, /usr/sbin/, /usr/local/bin/, /usr/local/sbin/ has mode 0755.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /bin/" test_ref="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_0:tst:1"/>
            <oval-def:criterion comment="Check file mode of /sbin/" test_ref="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_1:tst:1"/>
            <oval-def:criterion comment="Check file mode of /usr/bin/" test_ref="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_2:tst:1"/>
            <oval-def:criterion comment="Check file mode of /usr/sbin/" test_ref="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_3:tst:1"/>
            <oval-def:criterion comment="Check file mode of /usr/local/bin/" test_ref="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_4:tst:1"/>
            <oval-def:criterion comment="Check file mode of /usr/local/sbin/" test_ref="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_5:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-dir_permissions_library_dirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify that Shared Library Directories Have Restrictive Permissions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="dir_permissions_library_dirs" source="ssg"/>
            <oval-def:description>This test makes sure that /lib/, /lib64/, /usr/lib/, /usr/lib64/ has mode 7755.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /lib/" test_ref="oval:ssg-test_file_permissionsdir_permissions_library_dirs_0:tst:1"/>
            <oval-def:criterion comment="Check file mode of /lib64/" test_ref="oval:ssg-test_file_permissionsdir_permissions_library_dirs_1:tst:1"/>
            <oval-def:criterion comment="Check file mode of /usr/lib/" test_ref="oval:ssg-test_file_permissionsdir_permissions_library_dirs_2:tst:1"/>
            <oval-def:criterion comment="Check file mode of /usr/lib64/" test_ref="oval:ssg-test_file_permissionsdir_permissions_library_dirs_3:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_groupowner_etc_ipsecd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/ipsec.d Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_groupowner_etc_ipsecd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/ipsec.d/ is group owned by root.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/ipsec.d/" test_ref="oval:ssg-test_file_groupownerdirectory_groupowner_etc_ipsecd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_groupowner_etc_iptables:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/iptables Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_groupowner_etc_iptables" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/iptables/ is group owned by root.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/iptables/" test_ref="oval:ssg-test_file_groupownerdirectory_groupowner_etc_iptables_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_groupowner_etc_nftables:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/nftables Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_groupowner_etc_nftables" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/nftables/ is group owned by root.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/nftables/" test_ref="oval:ssg-test_file_groupownerdirectory_groupowner_etc_nftables_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_groupowner_etc_selinux:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/selinux Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_groupowner_etc_selinux" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/selinux/ is group owned by root.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/selinux/" test_ref="oval:ssg-test_file_groupownerdirectory_groupowner_etc_selinux_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_groupowner_etc_sudoersd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/sudoers.d Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_groupowner_etc_sudoersd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/sudoers.d/ is group owned by root.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/sudoers.d/" test_ref="oval:ssg-test_file_groupownerdirectory_groupowner_etc_sudoersd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_groupowner_etc_sysctld:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/sysctl.d Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_groupowner_etc_sysctld" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/sysctl.d/ is group owned by root.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/sysctl.d/" test_ref="oval:ssg-test_file_groupownerdirectory_groupowner_etc_sysctld_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_owner_etc_ipsecd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /etc/ipsec.d Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_owner_etc_ipsecd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/ipsec.d/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/ipsec.d/" test_ref="oval:ssg-test_file_ownerdirectory_owner_etc_ipsecd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_owner_etc_iptables:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /etc/iptables Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_owner_etc_iptables" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/iptables/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/iptables/" test_ref="oval:ssg-test_file_ownerdirectory_owner_etc_iptables_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_owner_etc_nftables:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /etc/nftables Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_owner_etc_nftables" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/nftables/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/nftables/" test_ref="oval:ssg-test_file_ownerdirectory_owner_etc_nftables_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_owner_etc_selinux:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /etc/selinux Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_owner_etc_selinux" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/selinux/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/selinux/" test_ref="oval:ssg-test_file_ownerdirectory_owner_etc_selinux_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_owner_etc_sudoersd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /etc/sudoers.d Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_owner_etc_sudoersd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/sudoers.d/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/sudoers.d/" test_ref="oval:ssg-test_file_ownerdirectory_owner_etc_sudoersd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_owner_etc_sysctld:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /etc/sysctl.d Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_owner_etc_sysctld" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/sysctl.d/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/sysctl.d/" test_ref="oval:ssg-test_file_ownerdirectory_owner_etc_sysctld_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_permissions_etc_ipsecd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions On /etc/ipsec.d Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_permissions_etc_ipsecd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/ipsec.d/ has mode 0700.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/ipsec.d/" test_ref="oval:ssg-test_file_permissionsdirectory_permissions_etc_ipsecd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_permissions_etc_iptables:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions On /etc/iptables Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_permissions_etc_iptables" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/iptables/ has mode 0700.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/iptables/" test_ref="oval:ssg-test_file_permissionsdirectory_permissions_etc_iptables_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_permissions_etc_nftables:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions On /etc/nftables Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_permissions_etc_nftables" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/nftables/ has mode 0700.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/nftables/" test_ref="oval:ssg-test_file_permissionsdirectory_permissions_etc_nftables_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_permissions_etc_selinux:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions On /etc/selinux Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_permissions_etc_selinux" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/selinux/ has mode 0755.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/selinux/" test_ref="oval:ssg-test_file_permissionsdirectory_permissions_etc_selinux_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_permissions_etc_sudoersd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions On /etc/sudoers.d Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_permissions_etc_sudoersd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/sudoers.d/ has mode 0750.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/sudoers.d/" test_ref="oval:ssg-test_file_permissionsdirectory_permissions_etc_sudoersd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-directory_permissions_etc_sysctld:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions On /etc/sysctl.d Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="directory_permissions_etc_sysctld" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/sysctl.d/ has mode 0755.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/sysctl.d/" test_ref="oval:ssg-test_file_permissionsdirectory_permissions_etc_sysctld_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-disable_host_auth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Host-Based Authentication</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="disable_host_auth" source="ssg"/>
            <oval-def:description>Ensure 'HostbasedAuthentication' is configured with value 'no' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the HostbasedAuthentication in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_disable_host_auth:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_HostbasedAuthentication_present_disable_host_auth:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_at_allow_exists:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure that /etc/at.allow exists</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_at_allow_exists" source="ssg"/>
            <oval-def:description>This test makes sure that/etc/at.allow does exist.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Ensure that /etc/at.allow does exist." test_ref="oval:ssg-test_file_at_allow_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_at_deny_not_exist:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure that /etc/at.deny does not exist</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_at_deny_not_exist" source="ssg"/>
            <oval-def:description>This test makes sure that/etc/at.deny does not exist.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Ensure that /etc/at.deny does not exist." test_ref="oval:ssg-test_file_at_deny_not_exist:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_audit_tools_group_ownership:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Audit Tools Must Be Group-owned by Root</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_audit_tools_group_ownership" source="ssg"/>
            <oval-def:description>This test makes sure that /sbin/auditctl, /sbin/aureport, /sbin/ausearch, /sbin/autrace, /sbin/auditd, /sbin/rsyslogd, /sbin/augenrules is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /sbin/auditctl" test_ref="oval:ssg-test_file_groupownerfile_audit_tools_group_ownership_0:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /sbin/aureport" test_ref="oval:ssg-test_file_groupownerfile_audit_tools_group_ownership_1:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /sbin/ausearch" test_ref="oval:ssg-test_file_groupownerfile_audit_tools_group_ownership_2:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /sbin/autrace" test_ref="oval:ssg-test_file_groupownerfile_audit_tools_group_ownership_3:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /sbin/auditd" test_ref="oval:ssg-test_file_groupownerfile_audit_tools_group_ownership_4:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /sbin/rsyslogd" test_ref="oval:ssg-test_file_groupownerfile_audit_tools_group_ownership_5:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /sbin/augenrules" test_ref="oval:ssg-test_file_groupownerfile_audit_tools_group_ownership_6:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_audit_tools_ownership:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Audit Tools Must Be Owned by Root</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_audit_tools_ownership" source="ssg"/>
            <oval-def:description>This test makes sure that /sbin/auditctl, /sbin/aureport, /sbin/ausearch, /sbin/autrace, /sbin/auditd, /sbin/rsyslogd, /sbin/augenrules is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /sbin/auditctl" test_ref="oval:ssg-test_file_ownerfile_audit_tools_ownership_0:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /sbin/aureport" test_ref="oval:ssg-test_file_ownerfile_audit_tools_ownership_1:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /sbin/ausearch" test_ref="oval:ssg-test_file_ownerfile_audit_tools_ownership_2:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /sbin/autrace" test_ref="oval:ssg-test_file_ownerfile_audit_tools_ownership_3:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /sbin/auditd" test_ref="oval:ssg-test_file_ownerfile_audit_tools_ownership_4:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /sbin/rsyslogd" test_ref="oval:ssg-test_file_ownerfile_audit_tools_ownership_5:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /sbin/augenrules" test_ref="oval:ssg-test_file_ownerfile_audit_tools_ownership_6:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_audit_tools_permissions:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Audit Tools Must Have a Mode of 0755 or Less Permissive</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_audit_tools_permissions" source="ssg"/>
            <oval-def:description>This test makes sure that /sbin/auditctl, /sbin/aureport, /sbin/ausearch, /sbin/autrace, /sbin/auditd, /sbin/rsyslogd, /sbin/augenrules has mode 0755.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /sbin/auditctl" test_ref="oval:ssg-test_file_permissionsfile_audit_tools_permissions_0:tst:1"/>
            <oval-def:criterion comment="Check file mode of /sbin/aureport" test_ref="oval:ssg-test_file_permissionsfile_audit_tools_permissions_1:tst:1"/>
            <oval-def:criterion comment="Check file mode of /sbin/ausearch" test_ref="oval:ssg-test_file_permissionsfile_audit_tools_permissions_2:tst:1"/>
            <oval-def:criterion comment="Check file mode of /sbin/autrace" test_ref="oval:ssg-test_file_permissionsfile_audit_tools_permissions_3:tst:1"/>
            <oval-def:criterion comment="Check file mode of /sbin/auditd" test_ref="oval:ssg-test_file_permissionsfile_audit_tools_permissions_4:tst:1"/>
            <oval-def:criterion comment="Check file mode of /sbin/rsyslogd" test_ref="oval:ssg-test_file_permissionsfile_audit_tools_permissions_5:tst:1"/>
            <oval-def:criterion comment="Check file mode of /sbin/augenrules" test_ref="oval:ssg-test_file_permissionsfile_audit_tools_permissions_6:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_cron_allow_exists:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure that /etc/cron.allow exists</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_cron_allow_exists" source="ssg"/>
            <oval-def:description>This test makes sure that/etc/cron.allow does exist.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Ensure that /etc/cron.allow does exist." test_ref="oval:ssg-test_file_cron_allow_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_cron_deny_not_exist:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure that /etc/cron.deny does not exist</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_cron_deny_not_exist" source="ssg"/>
            <oval-def:description>This test makes sure that/etc/cron.deny does not exist.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Ensure that /etc/cron.deny does not exist." test_ref="oval:ssg-test_file_cron_deny_not_exist:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_at_allow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/at.allow file</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_at_allow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/at.allow is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/at.allow" test_ref="oval:ssg-test_file_groupowner_at_allow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_backup_etc_group:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns Backup group File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_backup_etc_group" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/group- is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/group-" test_ref="oval:ssg-test_file_groupowner_backup_etc_group_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_backup_etc_gshadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns Backup gshadow File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_backup_etc_gshadow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/gshadow- is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/gshadow-" test_ref="oval:ssg-test_file_groupowner_backup_etc_gshadow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_backup_etc_passwd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns Backup passwd File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_backup_etc_passwd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/passwd- is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/passwd-" test_ref="oval:ssg-test_file_groupowner_backup_etc_passwd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_backup_etc_shadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns Backup shadow File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_backup_etc_shadow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/shadow- is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/shadow-" test_ref="oval:ssg-test_file_groupowner_backup_etc_shadow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_cron_allow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/cron.allow file</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_cron_allow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.allow is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/cron.allow" test_ref="oval:ssg-test_file_groupowner_cron_allow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_cron_d:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns cron.d</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_cron_d" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.d/ is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/cron.d/" test_ref="oval:ssg-test_file_groupowner_cron_d_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_cron_daily:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns cron.daily</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_cron_daily" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.daily/ is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/cron.daily/" test_ref="oval:ssg-test_file_groupowner_cron_daily_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_cron_hourly:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns cron.hourly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_cron_hourly" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.hourly/ is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/cron.hourly/" test_ref="oval:ssg-test_file_groupowner_cron_hourly_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_cron_monthly:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns cron.monthly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_cron_monthly" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.monthly/ is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/cron.monthly/" test_ref="oval:ssg-test_file_groupowner_cron_monthly_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_cron_weekly:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns cron.weekly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_cron_weekly" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.weekly/ is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/cron.weekly/" test_ref="oval:ssg-test_file_groupowner_cron_weekly_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_cron_yearly:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns cron.yearly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_cron_yearly" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.yearly/ is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/cron.yearly/" test_ref="oval:ssg-test_file_groupowner_cron_yearly_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_crontab:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns Crontab</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_crontab" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/crontab is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/crontab" test_ref="oval:ssg-test_file_groupowner_crontab_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_efi_grub2_cfg:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify the UEFI Boot Loader grub.cfg Group Ownership</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_efi_grub2_cfg" source="ssg"/>
            <oval-def:description>This test makes sure that /boot/efi/EFI/almalinux/grub.cfg is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /boot/efi/EFI/almalinux/grub.cfg" test_ref="oval:ssg-test_file_groupowner_efi_grub2_cfg_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_efi_user_cfg:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify /boot/efi/EFI/almalinux/user.cfg Group Ownership</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_efi_user_cfg" source="ssg"/>
            <oval-def:description>This test makes sure that /boot/efi/EFI/almalinux/user.cfg is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /boot/efi/EFI/almalinux/user.cfg" test_ref="oval:ssg-test_file_groupowner_efi_user_cfg_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_etc_crypttab:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/crypttab File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_etc_crypttab" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/crypttab is group owned by root.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/crypttab" test_ref="oval:ssg-test_file_groupowner_etc_crypttab_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_etc_group:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns group File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_etc_group" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/group is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/group" test_ref="oval:ssg-test_file_groupowner_etc_group_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_etc_gshadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns gshadow File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_etc_gshadow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/gshadow is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/gshadow" test_ref="oval:ssg-test_file_groupowner_etc_gshadow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_etc_ipsec_conf:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/ipsec.conf File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_etc_ipsec_conf" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/ipsec.conf is group owned by root.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/ipsec.conf" test_ref="oval:ssg-test_file_groupowner_etc_ipsec_conf_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_etc_ipsec_secrets:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/ipsec.secrets File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_etc_ipsec_secrets" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/ipsec.secrets is group owned by root.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/ipsec.secrets" test_ref="oval:ssg-test_file_groupowner_etc_ipsec_secrets_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_etc_issue:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Ownership of System Login Banner</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_etc_issue" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/issue is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/issue" test_ref="oval:ssg-test_file_groupowner_etc_issue_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_etc_issue_net:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Ownership of System Login Banner for Remote Connections</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_etc_issue_net" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/issue.net is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/issue.net" test_ref="oval:ssg-test_file_groupowner_etc_issue_net_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_etc_motd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Ownership of Message of the Day Banner</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_etc_motd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/motd is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/motd" test_ref="oval:ssg-test_file_groupowner_etc_motd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_etc_passwd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns passwd File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_etc_passwd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/passwd is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/passwd" test_ref="oval:ssg-test_file_groupowner_etc_passwd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_etc_security_opasswd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/security/opasswd File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_etc_security_opasswd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/security/opasswd is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/security/opasswd" test_ref="oval:ssg-test_file_groupowner_etc_security_opasswd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_etc_security_opasswd_old:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/security/opasswd.old File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_etc_security_opasswd_old" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/security/opasswd.old is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/security/opasswd.old" test_ref="oval:ssg-test_file_groupowner_etc_security_opasswd_old_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_etc_sestatus_conf:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/sestatus.conf File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_etc_sestatus_conf" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/sestatus.conf is group owned by root.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/sestatus.conf" test_ref="oval:ssg-test_file_groupowner_etc_sestatus_conf_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_etc_shadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns shadow File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_etc_shadow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/shadow is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/shadow" test_ref="oval:ssg-test_file_groupowner_etc_shadow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_etc_shells:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/shells File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_etc_shells" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/shells is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/shells" test_ref="oval:ssg-test_file_groupowner_etc_shells_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_etc_sudoers:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/sudoers File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_etc_sudoers" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/sudoers is group owned by root.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/sudoers" test_ref="oval:ssg-test_file_groupowner_etc_sudoers_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_etc_sysconfig_sshd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /etc/sysconfig/sshd File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_etc_sysconfig_sshd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/sysconfig/sshd is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/sysconfig/sshd" test_ref="oval:ssg-test_file_groupowner_etc_sysconfig_sshd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_grub2_cfg:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify /boot/grub2/grub.cfg Group Ownership</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_grub2_cfg" source="ssg"/>
            <oval-def:description>This test makes sure that /boot/grub2/grub.cfg is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /boot/grub2/grub.cfg" test_ref="oval:ssg-test_file_groupowner_grub2_cfg_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_sshd_config:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns SSH Server config file</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_sshd_config" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/ssh/sshd_config is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/ssh/sshd_config" test_ref="oval:ssg-test_file_groupowner_sshd_config_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_systemmap:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns System.map Files</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_systemmap" source="ssg"/>
            <oval-def:description>This test makes sure that /boot/ is group owned by root.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /boot/" test_ref="oval:ssg-test_file_groupowner_systemmap_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_user_cfg:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify /boot/grub2/user.cfg Group Ownership</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_user_cfg" source="ssg"/>
            <oval-def:description>This test makes sure that /boot/grub2/user.cfg is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /boot/grub2/user.cfg" test_ref="oval:ssg-test_file_groupowner_user_cfg_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_var_log:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /var/log Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_var_log" source="ssg"/>
            <oval-def:description>This test makes sure that /var/log/ is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /var/log/" test_ref="oval:ssg-test_file_groupowner_var_log_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_var_log_messages:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /var/log/messages File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_var_log_messages" source="ssg"/>
            <oval-def:description>This test makes sure that /var/log/messages is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /var/log/messages" test_ref="oval:ssg-test_file_groupowner_var_log_messages_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupowner_var_log_syslog:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns /var/log/syslog File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupowner_var_log_syslog" source="ssg"/>
            <oval-def:description>This test makes sure that /var/log/syslog is group owned by 4.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /var/log/syslog" test_ref="oval:ssg-test_file_groupowner_var_log_syslog_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupownership_audit_binaries:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify that audit tools are owned by group root</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupownership_audit_binaries" source="ssg"/>
            <oval-def:description>This test makes sure that /sbin/auditctl, /sbin/aureport, /sbin/ausearch, /sbin/autrace, /sbin/auditd, /sbin/audispd, /sbin/augenrules is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /sbin/auditctl" test_ref="oval:ssg-test_file_groupownership_audit_binaries_0:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /sbin/aureport" test_ref="oval:ssg-test_file_groupownership_audit_binaries_1:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /sbin/ausearch" test_ref="oval:ssg-test_file_groupownership_audit_binaries_2:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /sbin/autrace" test_ref="oval:ssg-test_file_groupownership_audit_binaries_3:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /sbin/auditd" test_ref="oval:ssg-test_file_groupownership_audit_binaries_4:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /sbin/audispd" test_ref="oval:ssg-test_file_groupownership_audit_binaries_5:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /sbin/augenrules" test_ref="oval:ssg-test_file_groupownership_audit_binaries_6:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupownership_audit_configuration:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Audit Configuration Files Must Be Owned By Group root</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupownership_audit_configuration" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/audit/, /etc/audit/rules.d/ is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/audit/" test_ref="oval:ssg-test_file_groupownership_audit_configuration_0:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /etc/audit/rules.d/" test_ref="oval:ssg-test_file_groupownership_audit_configuration_1:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupownership_sshd_private_key:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Ownership on SSH Server Private *_key Key Files</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupownership_sshd_private_key" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/ssh/ is group owned by ssh_keys.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/ssh/" test_ref="oval:ssg-test_file_groupownership_sshd_private_key_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_groupownership_sshd_pub_key:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Ownership on SSH Server Public *.pub Key Files</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_groupownership_sshd_pub_key" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/ssh/ is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /etc/ssh/" test_ref="oval:ssg-test_file_groupownership_sshd_pub_key_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_at_allow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /etc/at.allow file</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_at_allow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/at.allow is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/at.allow" test_ref="oval:ssg-test_file_owner_at_allow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_backup_etc_group:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns Backup group File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_backup_etc_group" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/group- is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/group-" test_ref="oval:ssg-test_file_owner_backup_etc_group_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_backup_etc_gshadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns Backup gshadow File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_backup_etc_gshadow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/gshadow- is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/gshadow-" test_ref="oval:ssg-test_file_owner_backup_etc_gshadow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_backup_etc_passwd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns Backup passwd File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_backup_etc_passwd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/passwd- is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/passwd-" test_ref="oval:ssg-test_file_owner_backup_etc_passwd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_backup_etc_shadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Group Who Owns Backup shadow File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_backup_etc_shadow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/shadow- is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/shadow-" test_ref="oval:ssg-test_file_owner_backup_etc_shadow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_cron_allow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /etc/cron.allow file</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_cron_allow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.allow is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/cron.allow" test_ref="oval:ssg-test_file_owner_cron_allow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_cron_d:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Owner on cron.d</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_cron_d" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.d/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/cron.d/" test_ref="oval:ssg-test_file_owner_cron_d_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_cron_daily:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Owner on cron.daily</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_cron_daily" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.daily/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/cron.daily/" test_ref="oval:ssg-test_file_owner_cron_daily_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_cron_hourly:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Owner on cron.hourly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_cron_hourly" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.hourly/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/cron.hourly/" test_ref="oval:ssg-test_file_owner_cron_hourly_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_cron_monthly:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Owner on cron.monthly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_cron_monthly" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.monthly/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/cron.monthly/" test_ref="oval:ssg-test_file_owner_cron_monthly_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_cron_weekly:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Owner on cron.weekly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_cron_weekly" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.weekly/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/cron.weekly/" test_ref="oval:ssg-test_file_owner_cron_weekly_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_cron_yearly:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Owner on cron.yearly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_cron_yearly" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.yearly/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/cron.yearly/" test_ref="oval:ssg-test_file_owner_cron_yearly_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_crontab:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Owner on crontab</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_crontab" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/crontab is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/crontab" test_ref="oval:ssg-test_file_owner_crontab_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_efi_grub2_cfg:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify the UEFI Boot Loader grub.cfg User Ownership</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_efi_grub2_cfg" source="ssg"/>
            <oval-def:description>This test makes sure that /boot/efi/EFI/almalinux/grub.cfg is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /boot/efi/EFI/almalinux/grub.cfg" test_ref="oval:ssg-test_file_owner_efi_grub2_cfg_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_efi_user_cfg:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify /boot/efi/EFI/almalinux/user.cfg User Ownership</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_efi_user_cfg" source="ssg"/>
            <oval-def:description>This test makes sure that /boot/efi/EFI/almalinux/user.cfg is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /boot/efi/EFI/almalinux/user.cfg" test_ref="oval:ssg-test_file_owner_efi_user_cfg_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_etc_chrony_keys:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /etc/chrony.keys File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_etc_chrony_keys" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/chrony.keys is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/chrony.keys" test_ref="oval:ssg-test_file_owner_etc_chrony_keys_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_etc_crypttab:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /etc/crypttab File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_etc_crypttab" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/crypttab is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/crypttab" test_ref="oval:ssg-test_file_owner_etc_crypttab_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_etc_group:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns group File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_etc_group" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/group is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/group" test_ref="oval:ssg-test_file_owner_etc_group_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_etc_gshadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns gshadow File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_etc_gshadow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/gshadow is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/gshadow" test_ref="oval:ssg-test_file_owner_etc_gshadow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_etc_ipsec_conf:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /etc/ipsec.conf File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_etc_ipsec_conf" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/ipsec.conf is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/ipsec.conf" test_ref="oval:ssg-test_file_owner_etc_ipsec_conf_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_etc_ipsec_secrets:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /etc/ipsec.secrets File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_etc_ipsec_secrets" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/ipsec.secrets is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/ipsec.secrets" test_ref="oval:ssg-test_file_owner_etc_ipsec_secrets_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_etc_issue:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify ownership of System Login Banner</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_etc_issue" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/issue is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/issue" test_ref="oval:ssg-test_file_owner_etc_issue_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_etc_issue_net:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify ownership of System Login Banner for Remote Connections</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_etc_issue_net" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/issue.net is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/issue.net" test_ref="oval:ssg-test_file_owner_etc_issue_net_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_etc_motd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify ownership of Message of the Day Banner</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_etc_motd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/motd is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/motd" test_ref="oval:ssg-test_file_owner_etc_motd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_etc_passwd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns passwd File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_etc_passwd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/passwd is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/passwd" test_ref="oval:ssg-test_file_owner_etc_passwd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_etc_security_opasswd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /etc/security/opasswd File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_etc_security_opasswd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/security/opasswd is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/security/opasswd" test_ref="oval:ssg-test_file_owner_etc_security_opasswd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_etc_security_opasswd_old:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /etc/security/opasswd.old File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_etc_security_opasswd_old" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/security/opasswd.old is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/security/opasswd.old" test_ref="oval:ssg-test_file_owner_etc_security_opasswd_old_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_etc_sestatus_conf:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /etc/sestatus.conf File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_etc_sestatus_conf" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/sestatus.conf is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/sestatus.conf" test_ref="oval:ssg-test_file_owner_etc_sestatus_conf_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_etc_shadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns shadow File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_etc_shadow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/shadow is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/shadow" test_ref="oval:ssg-test_file_owner_etc_shadow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_etc_shells:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Who Owns /etc/shells File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_etc_shells" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/shells is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/shells" test_ref="oval:ssg-test_file_owner_etc_shells_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_etc_sudoers:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /etc/sudoers File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_etc_sudoers" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/sudoers is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/sudoers" test_ref="oval:ssg-test_file_owner_etc_sudoers_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_etc_sysconfig_sshd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /etc/sysconfig/sshd File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_etc_sysconfig_sshd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/sysconfig/sshd is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/sysconfig/sshd" test_ref="oval:ssg-test_file_owner_etc_sysconfig_sshd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_grub2_cfg:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify /boot/grub2/grub.cfg User Ownership</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_grub2_cfg" source="ssg"/>
            <oval-def:description>This test makes sure that /boot/grub2/grub.cfg is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /boot/grub2/grub.cfg" test_ref="oval:ssg-test_file_owner_grub2_cfg_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_sshd_config:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Owner on SSH Server config file</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_sshd_config" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/ssh/sshd_config is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/ssh/sshd_config" test_ref="oval:ssg-test_file_owner_sshd_config_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_systemmap:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns System.map Files</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_systemmap" source="ssg"/>
            <oval-def:description>This test makes sure that /boot/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /boot/" test_ref="oval:ssg-test_file_owner_systemmap_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_user_cfg:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify /boot/grub2/user.cfg User Ownership</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_user_cfg" source="ssg"/>
            <oval-def:description>This test makes sure that /boot/grub2/user.cfg is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /boot/grub2/user.cfg" test_ref="oval:ssg-test_file_owner_user_cfg_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_var_log:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /var/log Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_var_log" source="ssg"/>
            <oval-def:description>This test makes sure that /var/log/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /var/log/" test_ref="oval:ssg-test_file_owner_var_log_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_var_log_messages:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /var/log/messages File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_var_log_messages" source="ssg"/>
            <oval-def:description>This test makes sure that /var/log/messages is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /var/log/messages" test_ref="oval:ssg-test_file_owner_var_log_messages_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_owner_var_log_syslog:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify User Who Owns /var/log/syslog File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_owner_var_log_syslog" source="ssg"/>
            <oval-def:description>This test makes sure that /var/log/syslog is owned by syslog.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /var/log/syslog" test_ref="oval:ssg-test_file_owner_var_log_syslog_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_ownership_audit_binaries:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify that audit tools are owned by root</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_ownership_audit_binaries" source="ssg"/>
            <oval-def:description>This test makes sure that /sbin/auditctl, /sbin/aureport, /sbin/ausearch, /sbin/autrace, /sbin/auditd, /sbin/audispd, /sbin/augenrules is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /sbin/auditctl" test_ref="oval:ssg-test_file_ownership_audit_binaries_0:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /sbin/aureport" test_ref="oval:ssg-test_file_ownership_audit_binaries_1:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /sbin/ausearch" test_ref="oval:ssg-test_file_ownership_audit_binaries_2:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /sbin/autrace" test_ref="oval:ssg-test_file_ownership_audit_binaries_3:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /sbin/auditd" test_ref="oval:ssg-test_file_ownership_audit_binaries_4:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /sbin/audispd" test_ref="oval:ssg-test_file_ownership_audit_binaries_5:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /sbin/augenrules" test_ref="oval:ssg-test_file_ownership_audit_binaries_6:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_ownership_audit_configuration:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Audit Configuration Files Must Be Owned By Root</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_ownership_audit_configuration" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/audit/, /etc/audit/rules.d/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/audit/" test_ref="oval:ssg-test_file_ownership_audit_configuration_0:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /etc/audit/rules.d/" test_ref="oval:ssg-test_file_ownership_audit_configuration_1:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_ownership_library_dirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify that Shared Library Files Have Root Ownership</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_ownership_library_dirs" source="ssg"/>
            <oval-def:description>This test makes sure that /lib/, /lib64/, /usr/lib/, /usr/lib64/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /lib/" test_ref="oval:ssg-test_file_ownership_library_dirs_0:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /lib64/" test_ref="oval:ssg-test_file_ownership_library_dirs_1:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /usr/lib/" test_ref="oval:ssg-test_file_ownership_library_dirs_2:tst:1"/>
            <oval-def:criterion comment="Check file ownership of /usr/lib64/" test_ref="oval:ssg-test_file_ownership_library_dirs_3:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_ownership_sshd_private_key:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Ownership on SSH Server Private *_key Key Files</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_ownership_sshd_private_key" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/ssh/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/ssh/" test_ref="oval:ssg-test_file_ownership_sshd_private_key_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_ownership_sshd_pub_key:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Ownership on SSH Server Public *.pub Key Files</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_ownership_sshd_pub_key" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/ssh/ is owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file ownership of /etc/ssh/" test_ref="oval:ssg-test_file_ownership_sshd_pub_key_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_at_allow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on /etc/at.allow file</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_at_allow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/at.allow has mode 0640.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/at.allow" test_ref="oval:ssg-test_file_permissions_at_allow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_audit_binaries:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify that audit tools Have Mode 0755 or less</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_audit_binaries" source="ssg"/>
            <oval-def:description>This test makes sure that /sbin/auditctl, /sbin/aureport, /sbin/ausearch, /sbin/autrace, /sbin/auditd, /sbin/audispd, /sbin/augenrules has mode 0755.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /sbin/auditctl" test_ref="oval:ssg-test_file_permissions_audit_binaries_0:tst:1"/>
            <oval-def:criterion comment="Check file mode of /sbin/aureport" test_ref="oval:ssg-test_file_permissions_audit_binaries_1:tst:1"/>
            <oval-def:criterion comment="Check file mode of /sbin/ausearch" test_ref="oval:ssg-test_file_permissions_audit_binaries_2:tst:1"/>
            <oval-def:criterion comment="Check file mode of /sbin/autrace" test_ref="oval:ssg-test_file_permissions_audit_binaries_3:tst:1"/>
            <oval-def:criterion comment="Check file mode of /sbin/auditd" test_ref="oval:ssg-test_file_permissions_audit_binaries_4:tst:1"/>
            <oval-def:criterion comment="Check file mode of /sbin/audispd" test_ref="oval:ssg-test_file_permissions_audit_binaries_5:tst:1"/>
            <oval-def:criterion comment="Check file mode of /sbin/augenrules" test_ref="oval:ssg-test_file_permissions_audit_binaries_6:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_audit_configuration:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Audit Configuration Files Permissions are 640 or More Restrictive</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_audit_configuration" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/audit/, /etc/audit/rules.d/ has mode 0640.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/audit/" test_ref="oval:ssg-test_file_permissions_audit_configuration_0:tst:1"/>
            <oval-def:criterion comment="Check file mode of /etc/audit/rules.d/" test_ref="oval:ssg-test_file_permissions_audit_configuration_1:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_backup_etc_group:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on Backup group File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_backup_etc_group" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/group- has mode 0644.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/group-" test_ref="oval:ssg-test_file_permissions_backup_etc_group_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_backup_etc_gshadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on Backup gshadow File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_backup_etc_gshadow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/gshadow- has mode 0000.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/gshadow-" test_ref="oval:ssg-test_file_permissions_backup_etc_gshadow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_backup_etc_passwd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on Backup passwd File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_backup_etc_passwd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/passwd- has mode 0644.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/passwd-" test_ref="oval:ssg-test_file_permissions_backup_etc_passwd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_backup_etc_shadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on Backup shadow File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_backup_etc_shadow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/shadow- has mode 0000.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/shadow-" test_ref="oval:ssg-test_file_permissions_backup_etc_shadow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_cron_allow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on /etc/cron.allow file</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_cron_allow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.allow has mode 0640.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/cron.allow" test_ref="oval:ssg-test_file_permissions_cron_allow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_cron_d:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on cron.d</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_cron_d" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.d/ has mode 0700.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/cron.d/" test_ref="oval:ssg-test_file_permissions_cron_d_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_cron_daily:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on cron.daily</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_cron_daily" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.daily/ has mode 0700.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/cron.daily/" test_ref="oval:ssg-test_file_permissions_cron_daily_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_cron_hourly:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on cron.hourly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_cron_hourly" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.hourly/ has mode 0700.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/cron.hourly/" test_ref="oval:ssg-test_file_permissions_cron_hourly_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_cron_monthly:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on cron.monthly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_cron_monthly" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.monthly/ has mode 0700.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/cron.monthly/" test_ref="oval:ssg-test_file_permissions_cron_monthly_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_cron_weekly:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on cron.weekly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_cron_weekly" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.weekly/ has mode 0700.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/cron.weekly/" test_ref="oval:ssg-test_file_permissions_cron_weekly_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_cron_yearly:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on cron.yearly</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_cron_yearly" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/cron.yearly/ has mode 0700.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/cron.yearly/" test_ref="oval:ssg-test_file_permissions_cron_yearly_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_crontab:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on crontab</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_crontab" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/crontab has mode 0600.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/crontab" test_ref="oval:ssg-test_file_permissions_crontab_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_efi_grub2_cfg:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify the UEFI Boot Loader grub.cfg Permissions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_efi_grub2_cfg" source="ssg"/>
            <oval-def:description>This test makes sure that /boot/efi/EFI/almalinux/grub.cfg has mode 0700.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /boot/efi/EFI/almalinux/grub.cfg" test_ref="oval:ssg-test_file_permissions_efi_grub2_cfg_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_efi_user_cfg:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify /boot/efi/EFI/almalinux/user.cfg Permissions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_efi_user_cfg" source="ssg"/>
            <oval-def:description>This test makes sure that /boot/efi/EFI/almalinux/user.cfg has mode 0700.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /boot/efi/EFI/almalinux/user.cfg" test_ref="oval:ssg-test_file_permissions_efi_user_cfg_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_audit_auditd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on /etc/audit/auditd.conf</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_audit_auditd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/audit/auditd.conf has mode 0640.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/audit/auditd.conf" test_ref="oval:ssg-test_file_permissions_etc_audit_auditd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_audit_rulesd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on /etc/audit/rules.d/*.rules</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_audit_rulesd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/audit/rules.d/ has mode 0600.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/audit/rules.d/" test_ref="oval:ssg-test_file_permissions_etc_audit_rulesd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_chrony_keys:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions On /etc/chrony.keys File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_chrony_keys" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/chrony.keys has mode 0640.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/chrony.keys" test_ref="oval:ssg-test_file_permissions_etc_chrony_keys_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_crypttab:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions On /etc/crypttab File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_crypttab" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/crypttab has mode 0600.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/crypttab" test_ref="oval:ssg-test_file_permissions_etc_crypttab_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_group:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on group File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_group" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/group has mode 0644.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/group" test_ref="oval:ssg-test_file_permissions_etc_group_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_gshadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on gshadow File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_gshadow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/gshadow has mode 0000.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/gshadow" test_ref="oval:ssg-test_file_permissions_etc_gshadow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_ipsec_conf:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions On /etc/ipsec.conf File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_ipsec_conf" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/ipsec.conf has mode 0644.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/ipsec.conf" test_ref="oval:ssg-test_file_permissions_etc_ipsec_conf_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_ipsec_secrets:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions On /etc/ipsec.secrets File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_ipsec_secrets" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/ipsec.secrets has mode 0644.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/ipsec.secrets" test_ref="oval:ssg-test_file_permissions_etc_ipsec_secrets_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_issue:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify permissions on System Login Banner</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_issue" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/issue has mode 0644.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/issue" test_ref="oval:ssg-test_file_permissions_etc_issue_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_issue_net:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify permissions on System Login Banner for Remote Connections</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_issue_net" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/issue.net has mode 0644.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/issue.net" test_ref="oval:ssg-test_file_permissions_etc_issue_net_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_motd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify permissions on Message of the Day Banner</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_motd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/motd has mode 0644.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/motd" test_ref="oval:ssg-test_file_permissions_etc_motd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_passwd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on passwd File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_passwd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/passwd has mode 0644.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/passwd" test_ref="oval:ssg-test_file_permissions_etc_passwd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_security_opasswd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on /etc/security/opasswd File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_security_opasswd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/security/opasswd has mode 0600.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/security/opasswd" test_ref="oval:ssg-test_file_permissions_etc_security_opasswd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_security_opasswd_old:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on /etc/security/opasswd.old File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_security_opasswd_old" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/security/opasswd.old has mode 0600.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/security/opasswd.old" test_ref="oval:ssg-test_file_permissions_etc_security_opasswd_old_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_sestatus_conf:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions On /etc/sestatus.conf File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_sestatus_conf" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/sestatus.conf has mode 0644.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/sestatus.conf" test_ref="oval:ssg-test_file_permissions_etc_sestatus_conf_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_shadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on shadow File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_shadow" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/shadow has mode 0000.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/shadow" test_ref="oval:ssg-test_file_permissions_etc_shadow_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_shells:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on /etc/shells File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_shells" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/shells has mode 0644.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/shells" test_ref="oval:ssg-test_file_permissions_etc_shells_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_sudoers:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions On /etc/sudoers File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_sudoers" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/sudoers has mode 0440.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/sudoers" test_ref="oval:ssg-test_file_permissions_etc_sudoers_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_etc_sysconfig_sshd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on /etc/sysconfig/sshd File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_etc_sysconfig_sshd" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/sysconfig/sshd has mode 0640.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/sysconfig/sshd" test_ref="oval:ssg-test_file_permissions_etc_sysconfig_sshd_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_grub2_cfg:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify /boot/grub2/grub.cfg Permissions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_grub2_cfg" source="ssg"/>
            <oval-def:description>This test makes sure that /boot/grub2/grub.cfg has mode 0600.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /boot/grub2/grub.cfg" test_ref="oval:ssg-test_file_permissions_grub2_cfg_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_library_dirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify that Shared Library Files Have Restrictive Permissions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_library_dirs" source="ssg"/>
            <oval-def:description>This test makes sure that /lib/, /lib64/, /usr/lib/, /usr/lib64/ has mode 7755.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /lib/" test_ref="oval:ssg-test_file_permissions_library_dirs_0:tst:1"/>
            <oval-def:criterion comment="Check file mode of /lib64/" test_ref="oval:ssg-test_file_permissions_library_dirs_1:tst:1"/>
            <oval-def:criterion comment="Check file mode of /usr/lib/" test_ref="oval:ssg-test_file_permissions_library_dirs_2:tst:1"/>
            <oval-def:criterion comment="Check file mode of /usr/lib64/" test_ref="oval:ssg-test_file_permissions_library_dirs_3:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_sshd_config:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on SSH Server config file</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_sshd_config" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/ssh/sshd_config has mode 0600.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/ssh/sshd_config" test_ref="oval:ssg-test_file_permissions_sshd_config_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_sshd_pub_key:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on SSH Server Public *.pub Key Files</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_sshd_pub_key" source="ssg"/>
            <oval-def:description>This test makes sure that /etc/ssh/ has mode 0644.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /etc/ssh/" test_ref="oval:ssg-test_file_permissions_sshd_pub_key_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_sudo:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure That the sudo Binary Has the Correct Permissions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_sudo" source="ssg"/>
            <oval-def:description>This test makes sure that /usr/bin/sudo has mode 4110.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /usr/bin/sudo" test_ref="oval:ssg-test_file_permissions_sudo_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_systemmap:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on System.map Files</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_systemmap" source="ssg"/>
            <oval-def:description>This test makes sure that /boot/ has mode 0600.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /boot/" test_ref="oval:ssg-test_file_permissions_systemmap_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_user_cfg:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify /boot/grub2/user.cfg Permissions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_user_cfg" source="ssg"/>
            <oval-def:description>This test makes sure that /boot/grub2/user.cfg has mode 0600.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /boot/grub2/user.cfg" test_ref="oval:ssg-test_file_permissions_user_cfg_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_var_log:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on /var/log Directory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_var_log" source="ssg"/>
            <oval-def:description>This test makes sure that /var/log/ has mode 0755.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /var/log/" test_ref="oval:ssg-test_file_permissions_var_log_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_var_log_messages:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on /var/log/messages File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_var_log_messages" source="ssg"/>
            <oval-def:description>This test makes sure that /var/log/messages has mode 0600.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /var/log/messages" test_ref="oval:ssg-test_file_permissions_var_log_messages_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-file_permissions_var_log_syslog:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify Permissions on /var/log/syslog File</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="file_permissions_var_log_syslog" source="ssg"/>
            <oval-def:description>This test makes sure that /var/log/syslog has mode 0640.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /var/log/syslog" test_ref="oval:ssg-test_file_permissions_var_log_syslog_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-firewalld-backend:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure Firewalld to Use the Nftables Backend</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="firewalld-backend" source="ssg"/>
            <oval-def:description>Ensure 'FirewallBackend' is configured with value 'nftables' in /etc/firewalld/firewalld.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="The respective application or service is configured correctly" operator="OR">
            <oval-def:criterion comment="Check the FirewallBackend in /etc/firewalld/firewalld.conf" test_ref="oval:ssg-test_firewalld-backend:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_audit_argument:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Enable Auditing for Processes Which Start Prior to the Audit Daemon</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_audit_argument" source="ssg"/>
            <oval-def:description>Ensure audit=1 is configured in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criteria operator="OR">
                  <oval-def:criterion comment="check for audit=1 in /etc/default/grub via GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_audit_argument:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria operator="AND">
                  <oval-def:criteria operator="OR">
                    <oval-def:criterion comment="check for audit=1 in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_audit_argument_default:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_audit_backlog_limit_argument:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Extend Audit Backlog Limit for the Audit Daemon</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_audit_backlog_limit_argument" source="ssg"/>
            <oval-def:description>Ensure audit_backlog_limit is configured in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criteria operator="OR">
                  <oval-def:criterion comment="check for audit_backlog_limit in /etc/default/grub via GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_audit_backlog_limit_argument:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria operator="AND">
                  <oval-def:criteria operator="OR">
                    <oval-def:criterion comment="check for audit_backlog_limit in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_audit_backlog_limit_argument_default:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_enable_iommu_force:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>IOMMU configuration directive</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_enable_iommu_force" source="ssg"/>
            <oval-def:description>Ensure iommu=force is configured in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criteria operator="OR">
                  <oval-def:criterion comment="check for iommu=force in /etc/default/grub via GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_iommu_argument:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria operator="AND">
                  <oval-def:criteria operator="OR">
                    <oval-def:criterion comment="check for iommu=force in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_iommu_argument_default:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_init_on_free:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>The system must booted with init_on_free=1</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_init_on_free" source="ssg"/>
            <oval-def:description>Ensure init_on_free=1 is configured in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criteria operator="OR">
                  <oval-def:criterion comment="check for init_on_free=1 in /etc/default/grub via GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_init_on_free_argument:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria operator="AND">
                  <oval-def:criteria operator="OR">
                    <oval-def:criterion comment="check for init_on_free=1 in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_init_on_free_argument_default:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_ipv6_disable_argument:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure IPv6 is disabled through kernel boot parameter</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_ipv6_disable_argument" source="ssg"/>
            <oval-def:description>Ensure ipv6.disable=1 is configured in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criteria operator="OR">
                  <oval-def:criterion comment="check for ipv6.disable=1 in /etc/default/grub via GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_ipv6_disable_argument:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria operator="AND">
                  <oval-def:criteria operator="OR">
                    <oval-def:criterion comment="check for ipv6.disable=1 in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_ipv6_disable_argument_default:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_l1tf_argument:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Configure L1 Terminal Fault mitigations</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_l1tf_argument" source="ssg"/>
            <oval-def:description>Ensure l1tf is configured in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criteria operator="OR">
                  <oval-def:criterion comment="check for l1tf in /etc/default/grub via GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_l1tf_argument:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria operator="AND">
                  <oval-def:criteria operator="OR">
                    <oval-def:criterion comment="check for l1tf in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_l1tf_argument_default:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_mce_argument:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Force kernel panic on uncorrected MCEs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_mce_argument" source="ssg"/>
            <oval-def:description>Ensure mce=0 is configured in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criteria operator="OR">
                  <oval-def:criterion comment="check for mce=0 in /etc/default/grub via GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_mce_argument:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria operator="AND">
                  <oval-def:criteria operator="OR">
                    <oval-def:criterion comment="check for mce=0 in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_mce_argument_default:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_nosmap_argument_absent:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure SMAP is not disabled during boot</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_nosmap_argument_absent" source="ssg"/>
            <oval-def:description>Ensure nosmap is not set in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criterion comment="check for absence of nosmap in /etc/default/grub on GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_nosmap_argument_absent:tst:1"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="check for absence ofnosmap in /etc/default/grub on GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_nosmap_argument_absent_default:tst:1"/>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_nosmep_argument_absent:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure SMEP is not disabled during boot</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_nosmep_argument_absent" source="ssg"/>
            <oval-def:description>Ensure nosmep is not set in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criterion comment="check for absence of nosmep in /etc/default/grub on GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_nosmep_argument_absent:tst:1"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="check for absence ofnosmep in /etc/default/grub on GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_nosmep_argument_absent_default:tst:1"/>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_nousb_argument:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Support for USB via Bootloader Configuration</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_nousb_argument" source="ssg"/>
            <oval-def:description>Ensure nousb is configured in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criteria operator="OR">
                  <oval-def:criterion comment="check for nousb in /etc/default/grub via GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_nousb_argument:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria operator="AND">
                  <oval-def:criteria operator="OR">
                    <oval-def:criterion comment="check for nousb in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_nousb_argument_default:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_page_poison_argument:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Enable page allocator poisoning</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_page_poison_argument" source="ssg"/>
            <oval-def:description>Ensure page_poison=1 is configured in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criteria operator="OR">
                  <oval-def:criterion comment="check for page_poison=1 in /etc/default/grub via GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_page_poison_argument:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria operator="AND">
                  <oval-def:criteria operator="OR">
                    <oval-def:criterion comment="check for page_poison=1 in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_page_poison_argument_default:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_pti_argument:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Page-Table Isolation (KPTI)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_pti_argument" source="ssg"/>
            <oval-def:description>Ensure pti=on is configured in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criteria operator="OR">
                  <oval-def:criterion comment="check for pti=on in /etc/default/grub via GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_pti_argument:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria operator="AND">
                  <oval-def:criteria operator="OR">
                    <oval-def:criterion comment="check for pti=on in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_pti_argument_default:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_rng_core_default_quality_argument:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Configure the confidence in TPM for entropy</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_rng_core_default_quality_argument" source="ssg"/>
            <oval-def:description>Ensure rng_core.default_quality is configured in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criteria operator="OR">
                  <oval-def:criterion comment="check for rng_core.default_quality in /etc/default/grub via GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_rng_core_default_quality_argument:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria operator="AND">
                  <oval-def:criteria operator="OR">
                    <oval-def:criterion comment="check for rng_core.default_quality in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_rng_core_default_quality_argument_default:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_slab_nomerge_argument:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Disable merging of slabs with similar size</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_slab_nomerge_argument" source="ssg"/>
            <oval-def:description>Ensure slab_nomerge=yes is configured in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criteria operator="OR">
                  <oval-def:criterion comment="check for slab_nomerge=yes in /etc/default/grub via GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_slab_nomerge_argument:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria operator="AND">
                  <oval-def:criteria operator="OR">
                    <oval-def:criterion comment="check for slab_nomerge=yes in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_slab_nomerge_argument_default:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_slub_debug_argument:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Enable SLUB/SLAB allocator poisoning</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_slub_debug_argument" source="ssg"/>
            <oval-def:description>Ensure slub_debug is configured in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criteria operator="OR">
                  <oval-def:criterion comment="check for slub_debug in /etc/default/grub via GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_slub_debug_argument:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria operator="AND">
                  <oval-def:criteria operator="OR">
                    <oval-def:criterion comment="check for slub_debug in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_slub_debug_argument_default:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_spec_store_bypass_disable_argument:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Configure Speculative Store Bypass Mitigation</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_spec_store_bypass_disable_argument" source="ssg"/>
            <oval-def:description>Ensure spec_store_bypass_disable is configured in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criteria operator="OR">
                  <oval-def:criterion comment="check for spec_store_bypass_disable in /etc/default/grub via GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_spec_store_bypass_disable_argument:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria operator="AND">
                  <oval-def:criteria operator="OR">
                    <oval-def:criterion comment="check for spec_store_bypass_disable in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_spec_store_bypass_disable_argument_default:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_spectre_v2_argument:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Enforce Spectre v2 mitigation</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_spectre_v2_argument" source="ssg"/>
            <oval-def:description>Ensure spectre_v2=on is configured in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criteria operator="OR">
                  <oval-def:criterion comment="check for spectre_v2=on in /etc/default/grub via GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_spectre_v2_argument:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria operator="AND">
                  <oval-def:criteria operator="OR">
                    <oval-def:criterion comment="check for spectre_v2=on in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_spectre_v2_argument_default:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_systemd_debug-shell_argument_absent:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Ensure debug-shell service is not enabled during boot</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_systemd_debug-shell_argument_absent" source="ssg"/>
            <oval-def:description>Ensure systemd.debug-shell is not set in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criterion comment="check for absence of systemd.debug-shell in /etc/default/grub on GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_systemd_debug_shell_argument_absent:tst:1"/>
                <oval-def:criteria operator="AND">
                  <oval-def:criterion comment="check for absence ofsystemd.debug-shell in /etc/default/grub on GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_systemd_debug_shell_argument_absent_default:tst:1"/>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-grub2_vsyscall_argument:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Disable vsyscalls</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="grub2_vsyscall_argument" source="ssg"/>
            <oval-def:description>Ensure vsyscall=none is configured in the kernel line in /etc/default/grub.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criteria operator="OR">
                <oval-def:criteria operator="OR">
                  <oval-def:criterion comment="check for vsyscall=none in /etc/default/grub via GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_vsyscall_argument:tst:1"/>
                </oval-def:criteria>
                <oval-def:criteria operator="AND">
                  <oval-def:criteria operator="OR">
                    <oval-def:criterion comment="check for vsyscall=none in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" test_ref="oval:ssg-test_grub2_vsyscall_argument_default:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:extend_definition comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" definition_ref="oval:ssg-bootloader_disable_recovery_set_to_true:def:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-install_smartcard_packages:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install Smart Card Packages For Multifactor Authentication</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="install_smartcard_packages" source="ssg"/>
            <oval-def:description>The RPM package openssl-pkcs11 should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package openssl-pkcs11 is installed" test_ref="oval:ssg-test_package_openssl-pkcs11_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-journald_compress:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure journald is configured to compress large log files</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="journald_compress" source="ssg"/>
            <oval-def:description>Ensure 'Compress' is configured with value 'yes' in /etc/systemd/journald.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="The respective application or service is configured correctly" operator="OR">
            <oval-def:criterion comment="Check the Compress in /etc/systemd/journald.conf" test_ref="oval:ssg-test_journald_compress:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-journald_disable_forward_to_syslog:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure journald ForwardToSyslog is disabled</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="journald_disable_forward_to_syslog" source="ssg"/>
            <oval-def:description>Ensure 'ForwardToSyslog' is configured with value 'no' in /etc/systemd/journald.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="The respective application or service is configured correctly" operator="OR">
            <oval-def:criterion comment="Check the ForwardToSyslog in /etc/systemd/journald.conf" test_ref="oval:ssg-test_journald_disable_forward_to_syslog:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-journald_forward_to_syslog:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure journald is configured to send logs to rsyslog</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="journald_forward_to_syslog" source="ssg"/>
            <oval-def:description>Ensure 'ForwardToSyslog' is configured with value 'yes' in /etc/systemd/journald.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="The respective application or service is configured correctly" operator="OR">
            <oval-def:criterion comment="Check the ForwardToSyslog in /etc/systemd/journald.conf" test_ref="oval:ssg-test_journald_forward_to_syslog:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-journald_storage:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure journald is configured to write log files to persistent disk</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="journald_storage" source="ssg"/>
            <oval-def:description>Ensure 'Storage' is configured with value 'persistent' in /etc/systemd/journald.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="The respective application or service is configured correctly" operator="OR">
            <oval-def:criterion comment="Check the Storage in /etc/systemd/journald.conf" test_ref="oval:ssg-test_journald_storage:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_acpi_custom_method:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Do not allow ACPI methods to be inserted/replaced at run time</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_acpi_custom_method" source="ssg"/>
            <oval-def:description>The kernel CONFIG_ACPI_CUSTOM_METHOD should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_acpi_custom_method:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_acpi_custom_method_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_acpi_custom_method_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_arm64_sw_ttbr0_pan:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Emulate Privileged Access Never (PAN)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_arm64_sw_ttbr0_pan" source="ssg"/>
            <oval-def:description>The kernel CONFIG_ARM64_SW_TTBR0_PAN should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_arm64_sw_ttbr0_pan:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_arm64_sw_ttbr0_pan_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_binfmt_misc:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable kernel support for MISC binaries</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_binfmt_misc" source="ssg"/>
            <oval-def:description>The kernel CONFIG_BINFMT_MISC should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_binfmt_misc:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_binfmt_misc_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_binfmt_misc_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_bug:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable support for BUG()</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_bug" source="ssg"/>
            <oval-def:description>The kernel CONFIG_BUG should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_bug:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_bug_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_bug_on_data_corruption:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Trigger a kernel BUG when data corruption is detected</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_bug_on_data_corruption" source="ssg"/>
            <oval-def:description>The kernel CONFIG_BUG_ON_DATA_CORRUPTION should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_bug_on_data_corruption:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_bug_on_data_corruption_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_compat_brk:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable compatibility with brk()</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_compat_brk" source="ssg"/>
            <oval-def:description>The kernel CONFIG_COMPAT_BRK should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_compat_brk:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_compat_brk_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_compat_brk_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_compat_vdso:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the 32-bit vDSO</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_compat_vdso" source="ssg"/>
            <oval-def:description>The kernel CONFIG_COMPAT_VDSO should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_compat_vdso:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_compat_vdso_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_compat_vdso_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_debug_credentials:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable checks on credential management</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_debug_credentials" source="ssg"/>
            <oval-def:description>The kernel CONFIG_DEBUG_CREDENTIALS should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_debug_credentials:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_debug_credentials_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_debug_fs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable kernel debugfs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_debug_fs" source="ssg"/>
            <oval-def:description>The kernel CONFIG_DEBUG_FS should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_debug_fs:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_debug_fs_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_debug_fs_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_debug_list:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable checks on linked list manipulation</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_debug_list" source="ssg"/>
            <oval-def:description>The kernel CONFIG_DEBUG_LIST should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_debug_list:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_debug_list_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_debug_notifiers:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable checks on notifier call chains</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_debug_notifiers" source="ssg"/>
            <oval-def:description>The kernel CONFIG_DEBUG_NOTIFIERS should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_debug_notifiers:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_debug_notifiers_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_debug_sg:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable checks on scatter-gather (SG) table operations</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_debug_sg" source="ssg"/>
            <oval-def:description>The kernel CONFIG_DEBUG_SG should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_debug_sg:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_debug_sg_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_debug_wx:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Warn on W+X mappings found at boot</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_debug_wx" source="ssg"/>
            <oval-def:description>The kernel CONFIG_DEBUG_WX should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_debug_wx:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_debug_wx_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_devkmem:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable /dev/kmem virtual device support</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_devkmem" source="ssg"/>
            <oval-def:description>The kernel CONFIG_DEVKMEM should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_devkmem:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_devkmem_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_devkmem_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_fortify_source:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Harden common str/mem functions against buffer overflows</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_fortify_source" source="ssg"/>
            <oval-def:description>The kernel CONFIG_FORTIFY_SOURCE should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_fortify_source:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_fortify_source_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_gcc_plugin_latent_entropy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Generate some entropy during boot and runtime</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_gcc_plugin_latent_entropy" source="ssg"/>
            <oval-def:description>The kernel CONFIG_GCC_PLUGIN_LATENT_ENTROPY should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_gcc_plugin_latent_entropy:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_gcc_plugin_latent_entropy_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_gcc_plugin_structleak:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Force initialization of variables containing userspace addresses</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_gcc_plugin_structleak" source="ssg"/>
            <oval-def:description>The kernel CONFIG_GCC_PLUGIN_STRUCTLEAK should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_gcc_plugin_structleak:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_gcc_plugin_structleak_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_hardened_usercopy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Harden memory copies between kernel and userspace</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_hardened_usercopy" source="ssg"/>
            <oval-def:description>The kernel CONFIG_HARDENED_USERCOPY should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_hardened_usercopy:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_hardened_usercopy_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_hardened_usercopy_fallback:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Do not allow usercopy whitelist violations to fallback to object size</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_hardened_usercopy_fallback" source="ssg"/>
            <oval-def:description>The kernel CONFIG_HARDENED_USERCOPY_FALLBACK should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_hardened_usercopy_fallback:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_hardened_usercopy_fallback_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_hardened_usercopy_fallback_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_hibernation:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable hibernation</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_hibernation" source="ssg"/>
            <oval-def:description>The kernel CONFIG_HIBERNATION should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_hibernation:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_hibernation_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_hibernation_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_ia32_emulation:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable IA32 emulation</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_ia32_emulation" source="ssg"/>
            <oval-def:description>The kernel CONFIG_IA32_EMULATION should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_ia32_emulation:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_ia32_emulation_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_ia32_emulation_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_ipv6:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the IPv6 protocol</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_ipv6" source="ssg"/>
            <oval-def:description>The kernel CONFIG_IPV6 should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_ipv6:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_ipv6_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_ipv6_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_kexec:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable kexec system call</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_kexec" source="ssg"/>
            <oval-def:description>The kernel CONFIG_KEXEC should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_kexec:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_kexec_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_kexec_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_legacy_ptys:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable legacy (BSD) PTY support</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_legacy_ptys" source="ssg"/>
            <oval-def:description>The kernel CONFIG_LEGACY_PTYS should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_legacy_ptys:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_legacy_ptys_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_legacy_ptys_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_legacy_vsyscall_emulate:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable vsyscall emulation</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_legacy_vsyscall_emulate" source="ssg"/>
            <oval-def:description>The kernel CONFIG_LEGACY_VSYSCALL_EMULATE should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_legacy_vsyscall_emulate:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_legacy_vsyscall_emulate_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_legacy_vsyscall_emulate_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_legacy_vsyscall_none:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable vsyscall mapping</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_legacy_vsyscall_none" source="ssg"/>
            <oval-def:description>The kernel CONFIG_LEGACY_VSYSCALL_NONE should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_legacy_vsyscall_none:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_legacy_vsyscall_none_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_modify_ldt_syscall:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the LDT (local descriptor table)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_modify_ldt_syscall" source="ssg"/>
            <oval-def:description>The kernel CONFIG_MODIFY_LDT_SYSCALL should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_modify_ldt_syscall:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_modify_ldt_syscall_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_modify_ldt_syscall_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_module_sig:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable module signature verification</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_module_sig" source="ssg"/>
            <oval-def:description>The kernel CONFIG_MODULE_SIG should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_module_sig:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_module_sig_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_module_sig_all:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable automatic signing of all modules</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_module_sig_all" source="ssg"/>
            <oval-def:description>The kernel CONFIG_MODULE_SIG_ALL should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_module_sig_all:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_module_sig_all_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_module_sig_force:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Require modules to be validly signed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_module_sig_force" source="ssg"/>
            <oval-def:description>The kernel CONFIG_MODULE_SIG_FORCE should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_module_sig_force:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_module_sig_force_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_module_sig_hash:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Specify the hash to use when signing modules</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_module_sig_hash" source="ssg"/>
            <oval-def:description>The kernel CONFIG_MODULE_SIG_HASH should have value according to var_kernel_config_module_sig_hash</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_module_sig_hash:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_module_sig_hash_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_module_sig_key:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Specify module signing key to use</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_module_sig_key" source="ssg"/>
            <oval-def:description>The kernel CONFIG_MODULE_SIG_KEY should have value according to var_kernel_config_module_sig_key</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_module_sig_key:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_module_sig_key_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_module_sig_sha512:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Sign kernel modules with SHA-512</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_module_sig_sha512" source="ssg"/>
            <oval-def:description>The kernel CONFIG_MODULE_SIG_SHA512 should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_module_sig_sha512:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_module_sig_sha512_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_page_poisoning:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable poison of pages after freeing</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_page_poisoning" source="ssg"/>
            <oval-def:description>The kernel CONFIG_PAGE_POISONING should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_page_poisoning:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_page_poisoning_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_page_poisoning_no_sanity:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable poison without sanity check</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_page_poisoning_no_sanity" source="ssg"/>
            <oval-def:description>The kernel CONFIG_PAGE_POISONING_NO_SANITY should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_page_poisoning_no_sanity:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_page_poisoning_no_sanity_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_page_poisoning_zero:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Use zero for poisoning instead of debugging value</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_page_poisoning_zero" source="ssg"/>
            <oval-def:description>The kernel CONFIG_PAGE_POISONING_ZERO should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_page_poisoning_zero:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_page_poisoning_zero_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_page_table_isolation:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Remove the kernel mapping in user mode</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_page_table_isolation" source="ssg"/>
            <oval-def:description>The kernel CONFIG_PAGE_TABLE_ISOLATION should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_page_table_isolation:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_page_table_isolation_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_panic_on_oops:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Kernel panic oops</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_panic_on_oops" source="ssg"/>
            <oval-def:description>The kernel CONFIG_PANIC_ON_OOPS should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_panic_on_oops:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_panic_on_oops_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_panic_timeout:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Kernel panic timeout</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_panic_timeout" source="ssg"/>
            <oval-def:description>The kernel CONFIG_PANIC_TIMEOUT should have value according to var_kernel_config_panic_timeout</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_panic_timeout:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_panic_timeout_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_proc_kcore:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable support for /proc/kkcore</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_proc_kcore" source="ssg"/>
            <oval-def:description>The kernel CONFIG_PROC_KCORE should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_proc_kcore:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_proc_kcore_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_proc_kcore_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_randomize_base:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Randomize the address of the kernel image (KASLR)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_randomize_base" source="ssg"/>
            <oval-def:description>The kernel CONFIG_RANDOMIZE_BASE should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_randomize_base:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_randomize_base_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_randomize_memory:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Randomize the kernel memory sections</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_randomize_memory" source="ssg"/>
            <oval-def:description>The kernel CONFIG_RANDOMIZE_MEMORY should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_randomize_memory:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_randomize_memory_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_refcount_full:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Perform full reference count validation</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_refcount_full" source="ssg"/>
            <oval-def:description>The kernel CONFIG_REFCOUNT_FULL should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_refcount_full:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_refcount_full_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_retpoline:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Avoid speculative indirect branches in kernel</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_retpoline" source="ssg"/>
            <oval-def:description>The kernel CONFIG_RETPOLINE should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_retpoline:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_retpoline_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_sched_stack_end_check:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Detect stack corruption on calls to schedule()</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_sched_stack_end_check" source="ssg"/>
            <oval-def:description>The kernel CONFIG_SCHED_STACK_END_CHECK should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_sched_stack_end_check:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_sched_stack_end_check_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_seccomp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable seccomp to safely compute untrusted bytecode</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_seccomp" source="ssg"/>
            <oval-def:description>The kernel CONFIG_SECCOMP should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_seccomp:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_seccomp_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_seccomp_filter:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable use of Berkeley Packet Filter with seccomp</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_seccomp_filter" source="ssg"/>
            <oval-def:description>The kernel CONFIG_SECCOMP_FILTER should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_seccomp_filter:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_seccomp_filter_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_security:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable different security models</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_security" source="ssg"/>
            <oval-def:description>The kernel CONFIG_SECURITY should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_security:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_security_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_security_dmesg_restrict:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Restrict unprivileged access to the kernel syslog</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_security_dmesg_restrict" source="ssg"/>
            <oval-def:description>The kernel CONFIG_SECURITY_DMESG_RESTRICT should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_security_dmesg_restrict:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_security_dmesg_restrict_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_security_writable_hooks:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable mutable hooks</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_security_writable_hooks" source="ssg"/>
            <oval-def:description>The kernel CONFIG_SECURITY_WRITABLE_HOOKS should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_security_writable_hooks:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_security_writable_hooks_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_security_writable_hooks_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_security_yama:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable Yama support</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_security_yama" source="ssg"/>
            <oval-def:description>The kernel CONFIG_SECURITY_YAMA should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_security_yama:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_security_yama_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_slab_freelist_hardened:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Harden slab freelist metadata</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_slab_freelist_hardened" source="ssg"/>
            <oval-def:description>The kernel CONFIG_SLAB_FREELIST_HARDENED should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_slab_freelist_hardened:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_slab_freelist_hardened_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_slab_freelist_random:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Randomize slab freelist</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_slab_freelist_random" source="ssg"/>
            <oval-def:description>The kernel CONFIG_SLAB_FREELIST_RANDOM should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_slab_freelist_random:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_slab_freelist_random_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_slab_merge_default:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disallow merge of slab caches</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_slab_merge_default" source="ssg"/>
            <oval-def:description>The kernel CONFIG_SLAB_MERGE_DEFAULT should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_slab_merge_default:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_slab_merge_default_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_slab_merge_default_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_slub_debug:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable SLUB debugging support</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_slub_debug" source="ssg"/>
            <oval-def:description>The kernel CONFIG_SLUB_DEBUG should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_slub_debug:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_slub_debug_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_stackprotector:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Stack Protector buffer overflow detection</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_stackprotector" source="ssg"/>
            <oval-def:description>The kernel CONFIG_STACKPROTECTOR should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_stackprotector:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_stackprotector_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_stackprotector_strong:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Strong Stack Protector</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_stackprotector_strong" source="ssg"/>
            <oval-def:description>The kernel CONFIG_STACKPROTECTOR_STRONG should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_stackprotector_strong:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_stackprotector_strong_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_strict_kernel_rwx:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Make the kernel text and rodata read-only</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_strict_kernel_rwx" source="ssg"/>
            <oval-def:description>The kernel CONFIG_STRICT_KERNEL_RWX should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_strict_kernel_rwx:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_strict_kernel_rwx_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_strict_module_rwx:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Make the module text and rodata read-only</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_strict_module_rwx" source="ssg"/>
            <oval-def:description>The kernel CONFIG_STRICT_MODULE_RWX should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_strict_module_rwx:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_strict_module_rwx_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_syn_cookies:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable TCP/IP syncookie support</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_syn_cookies" source="ssg"/>
            <oval-def:description>The kernel CONFIG_SYN_COOKIES should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_syn_cookies:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_syn_cookies_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_unmap_kernel_at_el0:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Unmap kernel when running in userspace (aka KAISER)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_unmap_kernel_at_el0" source="ssg"/>
            <oval-def:description>The kernel CONFIG_UNMAP_KERNEL_AT_EL0 should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_unmap_kernel_at_el0:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_unmap_kernel_at_el0_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_vmap_stack:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>User a virtually-mapped stack</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_vmap_stack" source="ssg"/>
            <oval-def:description>The kernel CONFIG_VMAP_STACK should have value y</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_vmap_stack:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_vmap_stack_compliant:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_config_x86_vsyscall_emulation:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable x86 vsyscall emulation</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_config_x86_vsyscall_emulation" source="ssg"/>
            <oval-def:description>The kernel CONFIG_X86_VSYSCALL_EMULATION should have value n</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="Check presence of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_x86_vsyscall_emulation:tst:1"/>
              <oval-def:criterion comment="Ensure all kernels have the config" test_ref="oval:ssg-test_all_kernels_config_x86_vsyscall_emulation_compliant:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="Check absense of build configuration of installed kernels" test_ref="oval:ssg-test_kernel_config_x86_vsyscall_emulation_absence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_atm_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable ATM Support</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_atm_disabled" source="ssg"/>
            <oval-def:description>The kernel module atm should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module atm disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_atm_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module atm disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_atm_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_bluetooth_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Bluetooth Kernel Module</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_bluetooth_disabled" source="ssg"/>
            <oval-def:description>The kernel module bluetooth should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module bluetooth disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_bluetooth_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module bluetooth disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_bluetooth_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_can_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable CAN Support</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_can_disabled" source="ssg"/>
            <oval-def:description>The kernel module can should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module can disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_can_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module can disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_can_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_cfg80211_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel cfg80211 Module</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_cfg80211_disabled" source="ssg"/>
            <oval-def:description>The kernel module cfg80211 should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module cfg80211 disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_cfg80211_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module cfg80211 disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_cfg80211_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_cramfs_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Mounting of cramfs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_cramfs_disabled" source="ssg"/>
            <oval-def:description>The kernel module cramfs should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module cramfs disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_cramfs_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module cramfs disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_cramfs_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_dccp_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable DCCP Support</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_dccp_disabled" source="ssg"/>
            <oval-def:description>The kernel module dccp should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module dccp disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_dccp_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module dccp disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_dccp_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_firewire-core_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable IEEE 1394 (FireWire) Support</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_firewire-core_disabled" source="ssg"/>
            <oval-def:description>The kernel module firewire-core should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module firewire-core disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_firewire-core_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module firewire-core disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_firewire-core_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_freevxfs_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Mounting of freevxfs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_freevxfs_disabled" source="ssg"/>
            <oval-def:description>The kernel module freevxfs should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module freevxfs disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_freevxfs_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module freevxfs disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_freevxfs_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_hfs_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Mounting of hfs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_hfs_disabled" source="ssg"/>
            <oval-def:description>The kernel module hfs should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module hfs disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_hfs_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module hfs disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_hfs_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_hfsplus_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Mounting of hfsplus</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_hfsplus_disabled" source="ssg"/>
            <oval-def:description>The kernel module hfsplus should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module hfsplus disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_hfsplus_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module hfsplus disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_hfsplus_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_iwlmvm_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel iwlmvm Module</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_iwlmvm_disabled" source="ssg"/>
            <oval-def:description>The kernel module iwlmvm should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module iwlmvm disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_iwlmvm_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module iwlmvm disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_iwlmvm_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_iwlwifi_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel iwlwifi Module</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_iwlwifi_disabled" source="ssg"/>
            <oval-def:description>The kernel module iwlwifi should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module iwlwifi disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_iwlwifi_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module iwlwifi disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_iwlwifi_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_jffs2_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Mounting of jffs2</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_jffs2_disabled" source="ssg"/>
            <oval-def:description>The kernel module jffs2 should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module jffs2 disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_jffs2_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module jffs2 disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_jffs2_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_mac80211_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel mac80211 Module</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_mac80211_disabled" source="ssg"/>
            <oval-def:description>The kernel module mac80211 should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module mac80211 disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_mac80211_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module mac80211 disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_mac80211_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_overlayfs_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure overlayfs kernel module is not available</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_overlayfs_disabled" source="ssg"/>
            <oval-def:description>The kernel module overlayfs should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module overlayfs disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_overlayfs_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module overlayfs disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_overlayfs_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_rds_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable RDS Support</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_rds_disabled" source="ssg"/>
            <oval-def:description>The kernel module rds should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module rds disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_rds_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module rds disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_rds_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_sctp_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable SCTP Support</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_sctp_disabled" source="ssg"/>
            <oval-def:description>The kernel module sctp should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module sctp disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_sctp_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module sctp disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_sctp_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_squashfs_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Mounting of squashfs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_squashfs_disabled" source="ssg"/>
            <oval-def:description>The kernel module squashfs should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module squashfs disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_squashfs_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module squashfs disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_squashfs_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_tipc_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable TIPC Support</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_tipc_disabled" source="ssg"/>
            <oval-def:description>The kernel module tipc should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module tipc disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_tipc_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module tipc disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_tipc_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_udf_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Mounting of udf</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_udf_disabled" source="ssg"/>
            <oval-def:description>The kernel module udf should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module udf disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_udf_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module udf disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_udf_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_usb-storage_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Modprobe Loading of USB Storage Driver</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_usb-storage_disabled" source="ssg"/>
            <oval-def:description>The kernel module usb-storage should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module usb-storage disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_usb-storage_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module usb-storage disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_usb-storage_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_uvcvideo_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the uvcvideo module</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_uvcvideo_disabled" source="ssg"/>
            <oval-def:description>The kernel module uvcvideo should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module uvcvideo disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_uvcvideo_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module uvcvideo disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_uvcvideo_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-kernel_module_vfat_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Mounting of vFAT filesystems</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="kernel_module_vfat_disabled" source="ssg"/>
            <oval-def:description>The kernel module vfat should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel module vfat disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_vfat_disabled:tst:1"/>
            <oval-def:criterion comment="kernel module vfat disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_vfat_modprobeconf:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_boot_efi_nosuid:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nosuid Option to /boot/efi</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_boot_efi_nosuid" source="ssg"/>
            <oval-def:description>/boot/efi should be mounted with mount option nosuid.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /boot/efi" test_ref="oval:ssg-test_boot_efi_partition_nosuid_optional:tst:1"/>
              <oval-def:criterion comment="/boot/efi does not exist" negate="true" test_ref="oval:ssg-test_boot_efi_partition_nosuid_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /boot/efi in /etc/fstab" test_ref="oval:ssg-test_boot_efi_partition_nosuid_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/boot/efi does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_boot_efi_partition_nosuid_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_boot_noauto:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add noauto Option to /boot</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_boot_noauto" source="ssg"/>
            <oval-def:description>/boot should be mounted with mount option noauto.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noauto on /boot" test_ref="oval:ssg-test_boot_partition_noauto_optional:tst:1"/>
              <oval-def:criterion comment="/boot does not exist" negate="true" test_ref="oval:ssg-test_boot_partition_noauto_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noauto on /boot in /etc/fstab" test_ref="oval:ssg-test_boot_partition_noauto_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/boot does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_boot_partition_noauto_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_boot_nodev:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nodev Option to /boot</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_boot_nodev" source="ssg"/>
            <oval-def:description>/boot should be mounted with mount option nodev.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nodev on /boot" test_ref="oval:ssg-test_boot_partition_nodev_optional:tst:1"/>
              <oval-def:criterion comment="/boot does not exist" negate="true" test_ref="oval:ssg-test_boot_partition_nodev_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nodev on /boot in /etc/fstab" test_ref="oval:ssg-test_boot_partition_nodev_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/boot does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_boot_partition_nodev_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_boot_noexec:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add noexec Option to /boot</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_boot_noexec" source="ssg"/>
            <oval-def:description>/boot should be mounted with mount option noexec.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noexec on /boot" test_ref="oval:ssg-test_boot_partition_noexec_optional:tst:1"/>
              <oval-def:criterion comment="/boot does not exist" negate="true" test_ref="oval:ssg-test_boot_partition_noexec_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noexec on /boot in /etc/fstab" test_ref="oval:ssg-test_boot_partition_noexec_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/boot does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_boot_partition_noexec_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_boot_nosuid:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nosuid Option to /boot</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_boot_nosuid" source="ssg"/>
            <oval-def:description>/boot should be mounted with mount option nosuid.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /boot" test_ref="oval:ssg-test_boot_partition_nosuid_optional:tst:1"/>
              <oval-def:criterion comment="/boot does not exist" negate="true" test_ref="oval:ssg-test_boot_partition_nosuid_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /boot in /etc/fstab" test_ref="oval:ssg-test_boot_partition_nosuid_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/boot does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_boot_partition_nosuid_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_dev_shm_nodev:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nodev Option to /dev/shm</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_dev_shm_nodev" source="ssg"/>
            <oval-def:description>/dev/shm should be mounted with mount option nodev.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nodev on /dev/shm" test_ref="oval:ssg-test_dev_shm_partition_nodev_expected:tst:1"/>
              <oval-def:criterion comment="/dev/shm does not exist" negate="true" test_ref="oval:ssg-test_dev_shm_partition_nodev_expected_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nodev on /dev/shm in /etc/fstab" test_ref="oval:ssg-test_dev_shm_partition_nodev_expected_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_dev_shm_noexec:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add noexec Option to /dev/shm</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_dev_shm_noexec" source="ssg"/>
            <oval-def:description>/dev/shm should be mounted with mount option noexec.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noexec on /dev/shm" test_ref="oval:ssg-test_dev_shm_partition_noexec_expected:tst:1"/>
              <oval-def:criterion comment="/dev/shm does not exist" negate="true" test_ref="oval:ssg-test_dev_shm_partition_noexec_expected_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noexec on /dev/shm in /etc/fstab" test_ref="oval:ssg-test_dev_shm_partition_noexec_expected_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_dev_shm_nosuid:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nosuid Option to /dev/shm</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_dev_shm_nosuid" source="ssg"/>
            <oval-def:description>/dev/shm should be mounted with mount option nosuid.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /dev/shm" test_ref="oval:ssg-test_dev_shm_partition_nosuid_expected:tst:1"/>
              <oval-def:criterion comment="/dev/shm does not exist" negate="true" test_ref="oval:ssg-test_dev_shm_partition_nosuid_expected_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /dev/shm in /etc/fstab" test_ref="oval:ssg-test_dev_shm_partition_nosuid_expected_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_home_grpquota:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add grpquota Option to /home</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_home_grpquota" source="ssg"/>
            <oval-def:description>/home should be mounted with mount option grpquota.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="grpquota on /home" test_ref="oval:ssg-test_home_partition_grpquota_optional:tst:1"/>
              <oval-def:criterion comment="/home does not exist" negate="true" test_ref="oval:ssg-test_home_partition_grpquota_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="grpquota on /home in /etc/fstab" test_ref="oval:ssg-test_home_partition_grpquota_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/home does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_home_partition_grpquota_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_home_nodev:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nodev Option to /home</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_home_nodev" source="ssg"/>
            <oval-def:description>/home should be mounted with mount option nodev.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nodev on /home" test_ref="oval:ssg-test_home_partition_nodev_optional:tst:1"/>
              <oval-def:criterion comment="/home does not exist" negate="true" test_ref="oval:ssg-test_home_partition_nodev_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nodev on /home in /etc/fstab" test_ref="oval:ssg-test_home_partition_nodev_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/home does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_home_partition_nodev_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_home_noexec:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add noexec Option to /home</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_home_noexec" source="ssg"/>
            <oval-def:description>/home should be mounted with mount option noexec.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noexec on /home" test_ref="oval:ssg-test_home_partition_noexec_optional:tst:1"/>
              <oval-def:criterion comment="/home does not exist" negate="true" test_ref="oval:ssg-test_home_partition_noexec_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noexec on /home in /etc/fstab" test_ref="oval:ssg-test_home_partition_noexec_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/home does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_home_partition_noexec_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_home_nosuid:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nosuid Option to /home</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_home_nosuid" source="ssg"/>
            <oval-def:description>/home should be mounted with mount option nosuid.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /home" test_ref="oval:ssg-test_home_partition_nosuid_optional:tst:1"/>
              <oval-def:criterion comment="/home does not exist" negate="true" test_ref="oval:ssg-test_home_partition_nosuid_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /home in /etc/fstab" test_ref="oval:ssg-test_home_partition_nosuid_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/home does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_home_partition_nosuid_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_home_usrquota:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add usrquota Option to /home</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_home_usrquota" source="ssg"/>
            <oval-def:description>/home should be mounted with mount option usrquota.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="usrquota on /home" test_ref="oval:ssg-test_home_partition_usrquota_optional:tst:1"/>
              <oval-def:criterion comment="/home does not exist" negate="true" test_ref="oval:ssg-test_home_partition_usrquota_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="usrquota on /home in /etc/fstab" test_ref="oval:ssg-test_home_partition_usrquota_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/home does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_home_partition_usrquota_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_krb_sec_remote_filesystems:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Mount Remote Filesystems with Kerberos Security</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_krb_sec_remote_filesystems" source="ssg"/>
            <oval-def:description>The sec_krb5_krb5i_krb5p option should be enabled for all NFS mounts in /etc/fstab.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="remote nfs filesystems" test_ref="oval:ssg-test_nfs_sec_krb5_krb5i_krb5p_etc_fstab:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_nodev_remote_filesystems:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Mount Remote Filesystems with nodev</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_nodev_remote_filesystems" source="ssg"/>
            <oval-def:description>The nodev option should be enabled for all NFS mounts in /etc/fstab.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="remote nfs filesystems" test_ref="oval:ssg-test_nfs_nodev_etc_fstab:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_nodev_removable_partitions:def:1" version="5">
          <oval-def:metadata>
            <oval-def:title>Add nodev Option to Removable Media Partitions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_nodev_removable_partitions" source="ssg"/>
            <oval-def:description>The nodev option should be enabled for all removable devices mounts in /etc/fstab.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="Check if removable partition really exists on the system" definition_ref="oval:ssg-removable_partition_doesnt_exist:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="Check if removable partition value represents CD/DVD drive" definition_ref="oval:ssg-var_removable_partition_is_cd_dvd_drive:def:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:criterion comment="Check if at least one from CD/DVD drive alternative names is using 'nodev' mount option in /etc/fstab" test_ref="oval:ssg-test_nodev_etc_fstab_cd_dvd_drive:tst:1"/>
                <oval-def:extend_definition comment="Check if CD/DVD drive is not configured to automount in /etc/fstab" definition_ref="oval:ssg-no_cd_dvd_drive_in_etc_fstab:def:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criterion comment="Check if removable partition is using 'nodev' mount option in /etc/fstab" test_ref="oval:ssg-test_nodev_etc_fstab_not_cd_dvd_drive:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_noexec_remote_filesystems:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Mount Remote Filesystems with noexec</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_noexec_remote_filesystems" source="ssg"/>
            <oval-def:description>The noexec option should be enabled for all NFS mounts in /etc/fstab.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="remote nfs filesystems" test_ref="oval:ssg-test_nfs_noexec_etc_fstab:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_noexec_removable_partitions:def:1" version="5">
          <oval-def:metadata>
            <oval-def:title>Add noexec Option to Removable Media Partitions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_noexec_removable_partitions" source="ssg"/>
            <oval-def:description>The noexec option should be enabled for all removable devices mounts in /etc/fstab.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="Check if removable partition really exists on the system" definition_ref="oval:ssg-removable_partition_doesnt_exist:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="Check if removable partition value represents CD/DVD drive" definition_ref="oval:ssg-var_removable_partition_is_cd_dvd_drive:def:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:criterion comment="Check if at least one from CD/DVD drive alternative names is using 'noexec' mount option in /etc/fstab" test_ref="oval:ssg-test_noexec_etc_fstab_cd_dvd_drive:tst:1"/>
                <oval-def:extend_definition comment="Check if CD/DVD drive is not configured to automount in /etc/fstab" definition_ref="oval:ssg-no_cd_dvd_drive_in_etc_fstab:def:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criterion comment="Check if removable partition is using 'noexec' mount option in /etc/fstab" test_ref="oval:ssg-test_noexec_etc_fstab_not_cd_dvd_drive:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_nosuid_remote_filesystems:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Mount Remote Filesystems with nosuid</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_nosuid_remote_filesystems" source="ssg"/>
            <oval-def:description>The nosuid option should be enabled for all NFS mounts in /etc/fstab.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="remote nfs filesystems" test_ref="oval:ssg-test_nfs_nosuid_etc_fstab:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_nosuid_removable_partitions:def:1" version="5">
          <oval-def:metadata>
            <oval-def:title>Add nosuid Option to Removable Media Partitions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_nosuid_removable_partitions" source="ssg"/>
            <oval-def:description>The nosuid option should be enabled for all removable devices mounts in /etc/fstab.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="Check if removable partition really exists on the system" definition_ref="oval:ssg-removable_partition_doesnt_exist:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="Check if removable partition value represents CD/DVD drive" definition_ref="oval:ssg-var_removable_partition_is_cd_dvd_drive:def:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:criterion comment="Check if at least one from CD/DVD drive alternative names is using 'nosuid' mount option in /etc/fstab" test_ref="oval:ssg-test_nosuid_etc_fstab_cd_dvd_drive:tst:1"/>
                <oval-def:extend_definition comment="Check if CD/DVD drive is not configured to automount in /etc/fstab" definition_ref="oval:ssg-no_cd_dvd_drive_in_etc_fstab:def:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criterion comment="Check if removable partition is using 'nosuid' mount option in /etc/fstab" test_ref="oval:ssg-test_nosuid_etc_fstab_not_cd_dvd_drive:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_opt_nosuid:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nosuid Option to /opt</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_opt_nosuid" source="ssg"/>
            <oval-def:description>/opt should be mounted with mount option nosuid.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /opt" test_ref="oval:ssg-test_opt_partition_nosuid_optional:tst:1"/>
              <oval-def:criterion comment="/opt does not exist" negate="true" test_ref="oval:ssg-test_opt_partition_nosuid_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /opt in /etc/fstab" test_ref="oval:ssg-test_opt_partition_nosuid_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/opt does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_opt_partition_nosuid_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_proc_hidepid:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add hidepid Option to /proc</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_proc_hidepid" source="ssg"/>
            <oval-def:description>/proc should be mounted with mount option hidepid.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="hidepid on /proc" test_ref="oval:ssg-test_proc_partition_hidepid_expected:tst:1"/>
              <oval-def:criterion comment="/proc does not exist" negate="true" test_ref="oval:ssg-test_proc_partition_hidepid_expected_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="hidepid on /proc in /etc/fstab" test_ref="oval:ssg-test_proc_partition_hidepid_expected_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_srv_nosuid:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nosuid Option to /srv</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_srv_nosuid" source="ssg"/>
            <oval-def:description>/srv should be mounted with mount option nosuid.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /srv" test_ref="oval:ssg-test_srv_partition_nosuid_optional:tst:1"/>
              <oval-def:criterion comment="/srv does not exist" negate="true" test_ref="oval:ssg-test_srv_partition_nosuid_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /srv in /etc/fstab" test_ref="oval:ssg-test_srv_partition_nosuid_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/srv does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_srv_partition_nosuid_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_tmp_nodev:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nodev Option to /tmp</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_tmp_nodev" source="ssg"/>
            <oval-def:description>/tmp should be mounted with mount option nodev.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nodev on /tmp" test_ref="oval:ssg-test_tmp_partition_nodev_optional:tst:1"/>
              <oval-def:criterion comment="/tmp does not exist" negate="true" test_ref="oval:ssg-test_tmp_partition_nodev_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nodev on /tmp in /etc/fstab" test_ref="oval:ssg-test_tmp_partition_nodev_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/tmp does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_tmp_partition_nodev_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_tmp_noexec:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add noexec Option to /tmp</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_tmp_noexec" source="ssg"/>
            <oval-def:description>/tmp should be mounted with mount option noexec.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noexec on /tmp" test_ref="oval:ssg-test_tmp_partition_noexec_optional:tst:1"/>
              <oval-def:criterion comment="/tmp does not exist" negate="true" test_ref="oval:ssg-test_tmp_partition_noexec_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noexec on /tmp in /etc/fstab" test_ref="oval:ssg-test_tmp_partition_noexec_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/tmp does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_tmp_partition_noexec_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_tmp_nosuid:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nosuid Option to /tmp</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_tmp_nosuid" source="ssg"/>
            <oval-def:description>/tmp should be mounted with mount option nosuid.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /tmp" test_ref="oval:ssg-test_tmp_partition_nosuid_optional:tst:1"/>
              <oval-def:criterion comment="/tmp does not exist" negate="true" test_ref="oval:ssg-test_tmp_partition_nosuid_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /tmp in /etc/fstab" test_ref="oval:ssg-test_tmp_partition_nosuid_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/tmp does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_tmp_partition_nosuid_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_var_log_audit_nodev:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nodev Option to /var/log/audit</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_var_log_audit_nodev" source="ssg"/>
            <oval-def:description>/var/log/audit should be mounted with mount option nodev.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nodev on /var/log/audit" test_ref="oval:ssg-test_var_log_audit_partition_nodev_optional:tst:1"/>
              <oval-def:criterion comment="/var/log/audit does not exist" negate="true" test_ref="oval:ssg-test_var_log_audit_partition_nodev_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nodev on /var/log/audit in /etc/fstab" test_ref="oval:ssg-test_var_log_audit_partition_nodev_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/var/log/audit does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_var_log_audit_partition_nodev_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_var_log_audit_noexec:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add noexec Option to /var/log/audit</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_var_log_audit_noexec" source="ssg"/>
            <oval-def:description>/var/log/audit should be mounted with mount option noexec.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noexec on /var/log/audit" test_ref="oval:ssg-test_var_log_audit_partition_noexec_optional:tst:1"/>
              <oval-def:criterion comment="/var/log/audit does not exist" negate="true" test_ref="oval:ssg-test_var_log_audit_partition_noexec_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noexec on /var/log/audit in /etc/fstab" test_ref="oval:ssg-test_var_log_audit_partition_noexec_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/var/log/audit does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_var_log_audit_partition_noexec_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_var_log_audit_nosuid:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nosuid Option to /var/log/audit</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_var_log_audit_nosuid" source="ssg"/>
            <oval-def:description>/var/log/audit should be mounted with mount option nosuid.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /var/log/audit" test_ref="oval:ssg-test_var_log_audit_partition_nosuid_optional:tst:1"/>
              <oval-def:criterion comment="/var/log/audit does not exist" negate="true" test_ref="oval:ssg-test_var_log_audit_partition_nosuid_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /var/log/audit in /etc/fstab" test_ref="oval:ssg-test_var_log_audit_partition_nosuid_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/var/log/audit does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_var_log_audit_partition_nosuid_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_var_log_nodev:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nodev Option to /var/log</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_var_log_nodev" source="ssg"/>
            <oval-def:description>/var/log should be mounted with mount option nodev.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nodev on /var/log" test_ref="oval:ssg-test_var_log_partition_nodev_optional:tst:1"/>
              <oval-def:criterion comment="/var/log does not exist" negate="true" test_ref="oval:ssg-test_var_log_partition_nodev_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nodev on /var/log in /etc/fstab" test_ref="oval:ssg-test_var_log_partition_nodev_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/var/log does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_var_log_partition_nodev_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_var_log_noexec:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add noexec Option to /var/log</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_var_log_noexec" source="ssg"/>
            <oval-def:description>/var/log should be mounted with mount option noexec.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noexec on /var/log" test_ref="oval:ssg-test_var_log_partition_noexec_optional:tst:1"/>
              <oval-def:criterion comment="/var/log does not exist" negate="true" test_ref="oval:ssg-test_var_log_partition_noexec_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noexec on /var/log in /etc/fstab" test_ref="oval:ssg-test_var_log_partition_noexec_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/var/log does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_var_log_partition_noexec_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_var_log_nosuid:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nosuid Option to /var/log</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_var_log_nosuid" source="ssg"/>
            <oval-def:description>/var/log should be mounted with mount option nosuid.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /var/log" test_ref="oval:ssg-test_var_log_partition_nosuid_optional:tst:1"/>
              <oval-def:criterion comment="/var/log does not exist" negate="true" test_ref="oval:ssg-test_var_log_partition_nosuid_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /var/log in /etc/fstab" test_ref="oval:ssg-test_var_log_partition_nosuid_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/var/log does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_var_log_partition_nosuid_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_var_nodev:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nodev Option to /var</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_var_nodev" source="ssg"/>
            <oval-def:description>/var should be mounted with mount option nodev.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nodev on /var" test_ref="oval:ssg-test_var_partition_nodev_optional:tst:1"/>
              <oval-def:criterion comment="/var does not exist" negate="true" test_ref="oval:ssg-test_var_partition_nodev_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nodev on /var in /etc/fstab" test_ref="oval:ssg-test_var_partition_nodev_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/var does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_var_partition_nodev_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_var_noexec:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add noexec Option to /var</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_var_noexec" source="ssg"/>
            <oval-def:description>/var should be mounted with mount option noexec.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noexec on /var" test_ref="oval:ssg-test_var_partition_noexec_optional:tst:1"/>
              <oval-def:criterion comment="/var does not exist" negate="true" test_ref="oval:ssg-test_var_partition_noexec_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noexec on /var in /etc/fstab" test_ref="oval:ssg-test_var_partition_noexec_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/var does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_var_partition_noexec_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_var_nosuid:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nosuid Option to /var</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_var_nosuid" source="ssg"/>
            <oval-def:description>/var should be mounted with mount option nosuid.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /var" test_ref="oval:ssg-test_var_partition_nosuid_optional:tst:1"/>
              <oval-def:criterion comment="/var does not exist" negate="true" test_ref="oval:ssg-test_var_partition_nosuid_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /var in /etc/fstab" test_ref="oval:ssg-test_var_partition_nosuid_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/var does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_var_partition_nosuid_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_var_tmp_nodev:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nodev Option to /var/tmp</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_var_tmp_nodev" source="ssg"/>
            <oval-def:description>/var/tmp should be mounted with mount option nodev.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nodev on /var/tmp" test_ref="oval:ssg-test_var_tmp_partition_nodev_optional:tst:1"/>
              <oval-def:criterion comment="/var/tmp does not exist" negate="true" test_ref="oval:ssg-test_var_tmp_partition_nodev_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nodev on /var/tmp in /etc/fstab" test_ref="oval:ssg-test_var_tmp_partition_nodev_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/var/tmp does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_var_tmp_partition_nodev_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_var_tmp_noexec:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add noexec Option to /var/tmp</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_var_tmp_noexec" source="ssg"/>
            <oval-def:description>/var/tmp should be mounted with mount option noexec.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noexec on /var/tmp" test_ref="oval:ssg-test_var_tmp_partition_noexec_optional:tst:1"/>
              <oval-def:criterion comment="/var/tmp does not exist" negate="true" test_ref="oval:ssg-test_var_tmp_partition_noexec_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="noexec on /var/tmp in /etc/fstab" test_ref="oval:ssg-test_var_tmp_partition_noexec_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/var/tmp does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_var_tmp_partition_noexec_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-mount_option_var_tmp_nosuid:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Add nosuid Option to /var/tmp</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="mount_option_var_tmp_nosuid" source="ssg"/>
            <oval-def:description>/var/tmp should be mounted with mount option nosuid.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /var/tmp" test_ref="oval:ssg-test_var_tmp_partition_nosuid_optional:tst:1"/>
              <oval-def:criterion comment="/var/tmp does not exist" negate="true" test_ref="oval:ssg-test_var_tmp_partition_nosuid_optional_exist:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="nosuid on /var/tmp in /etc/fstab" test_ref="oval:ssg-test_var_tmp_partition_nosuid_optional_in_fstab:tst:1"/>
              <oval-def:criterion comment="/var/tmp does not exist in /etc/fstab" negate="true" test_ref="oval:ssg-test_var_tmp_partition_nosuid_optional_exist_in_fstab:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_389-ds-base_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall 389-ds-base Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_389-ds-base_removed" source="ssg"/>
            <oval-def:description>The RPM package 389-ds-base should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package 389-ds-base is removed" test_ref="oval:ssg-test_package_389-ds-base_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_MFEhiplsm_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install the Host Intrusion Prevention System (HIPS) Module</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_MFEhiplsm_installed" source="ssg"/>
            <oval-def:description>The RPM package MFEhiplsm should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package MFEhiplsm is installed" test_ref="oval:ssg-test_package_MFEhiplsm_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_abrt-addon-ccpp_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall abrt-addon-ccpp Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_abrt-addon-ccpp_removed" source="ssg"/>
            <oval-def:description>The RPM package abrt-addon-ccpp should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package abrt-addon-ccpp is removed" test_ref="oval:ssg-test_package_abrt-addon-ccpp_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_abrt-addon-kerneloops_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall abrt-addon-kerneloops Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_abrt-addon-kerneloops_removed" source="ssg"/>
            <oval-def:description>The RPM package abrt-addon-kerneloops should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package abrt-addon-kerneloops is removed" test_ref="oval:ssg-test_package_abrt-addon-kerneloops_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_abrt-cli_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall abrt-cli Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_abrt-cli_removed" source="ssg"/>
            <oval-def:description>The RPM package abrt-cli should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package abrt-cli is removed" test_ref="oval:ssg-test_package_abrt-cli_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_abrt-plugin-logger_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall abrt-plugin-logger Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_abrt-plugin-logger_removed" source="ssg"/>
            <oval-def:description>The RPM package abrt-plugin-logger should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package abrt-plugin-logger is removed" test_ref="oval:ssg-test_package_abrt-plugin-logger_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_abrt-plugin-rhtsupport_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall abrt-plugin-rhtsupport Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_abrt-plugin-rhtsupport_removed" source="ssg"/>
            <oval-def:description>The RPM package abrt-plugin-rhtsupport should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package abrt-plugin-rhtsupport is removed" test_ref="oval:ssg-test_package_abrt-plugin-rhtsupport_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_abrt-plugin-sosreport_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall abrt-plugin-sosreport Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_abrt-plugin-sosreport_removed" source="ssg"/>
            <oval-def:description>The RPM package abrt-plugin-sosreport should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package abrt-plugin-sosreport is removed" test_ref="oval:ssg-test_package_abrt-plugin-sosreport_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_abrt_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall Automatic Bug Reporting Tool (abrt)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_abrt_removed" source="ssg"/>
            <oval-def:description>The RPM package abrt should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package abrt is removed" test_ref="oval:ssg-test_package_abrt_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_aide_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install AIDE</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_aide_installed" source="ssg"/>
            <oval-def:description>The RPM package aide should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package aide is installed" test_ref="oval:ssg-test_package_aide_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_audispd-plugins_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install audispd-plugins Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_audispd-plugins_installed" source="ssg"/>
            <oval-def:description>The RPM package audispd-plugins should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package audispd-plugins is installed" test_ref="oval:ssg-test_package_audispd-plugins_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_audit-audispd-plugins_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure the default plugins for the audit dispatcher are Installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_audit-audispd-plugins_installed" source="ssg"/>
            <oval-def:description>The RPM package audit-audispd-plugins should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package audit-audispd-plugins is installed" test_ref="oval:ssg-test_package_audit-audispd-plugins_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_audit-libs_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure the audit-libs package as a part of audit Subsystem is Installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_audit-libs_installed" source="ssg"/>
            <oval-def:description>The RPM package audit-libs should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package audit-libs is installed" test_ref="oval:ssg-test_package_audit-libs_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_audit_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure the audit Subsystem is Installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_audit_installed" source="ssg"/>
            <oval-def:description>The RPM package audit should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package audit is installed" test_ref="oval:ssg-test_package_audit_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_authselect_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install authselect Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_authselect_installed" source="ssg"/>
            <oval-def:description>The RPM package authselect should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package authselect is installed" test_ref="oval:ssg-test_package_authselect_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_avahi-autoipd_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall avahi-autoipd Server Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_avahi-autoipd_removed" source="ssg"/>
            <oval-def:description>The RPM package avahi-autoipd should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package avahi-autoipd is removed" test_ref="oval:ssg-test_package_avahi-autoipd_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_avahi_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall avahi Server Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_avahi_removed" source="ssg"/>
            <oval-def:description>The RPM package avahi should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package avahi is removed" test_ref="oval:ssg-test_package_avahi_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_bind_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall bind Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_bind_removed" source="ssg"/>
            <oval-def:description>The RPM package bind should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package bind is removed" test_ref="oval:ssg-test_package_bind_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_binutils_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install binutils Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_binutils_installed" source="ssg"/>
            <oval-def:description>The RPM package binutils should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package binutils is installed" test_ref="oval:ssg-test_package_binutils_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_chrony_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>The Chrony package is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_chrony_installed" source="ssg"/>
            <oval-def:description>The RPM package chrony should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package chrony is installed" test_ref="oval:ssg-test_package_chrony_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_cron_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install the cron service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_cron_installed" source="ssg"/>
            <oval-def:description>The RPM package cron should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package cron is installed" test_ref="oval:ssg-test_package_cron_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_crypto-policies_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install crypto-policies package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_crypto-policies_installed" source="ssg"/>
            <oval-def:description>The RPM package crypto-policies should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package crypto-policies is installed" test_ref="oval:ssg-test_package_crypto-policies_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_cups_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall CUPS Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_cups_removed" source="ssg"/>
            <oval-def:description>The RPM package cups should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package cups is removed" test_ref="oval:ssg-test_package_cups_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_cyrus-imapd_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall cyrus-imapd Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_cyrus-imapd_removed" source="ssg"/>
            <oval-def:description>The RPM package cyrus-imapd should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package cyrus-imapd is removed" test_ref="oval:ssg-test_package_cyrus-imapd_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_dconf_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>package_dconf_installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_dconf_installed" source="ssg"/>
            <oval-def:description>The RPM package dconf should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package dconf is installed" test_ref="oval:ssg-test_package_dconf_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_dhcp_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall DHCP Server Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_dhcp_removed" source="ssg"/>
            <oval-def:description>The RPM package dhcp should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package dhcp is removed" test_ref="oval:ssg-test_package_dhcp_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_dnf-automatic_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install dnf-automatic Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_dnf-automatic_installed" source="ssg"/>
            <oval-def:description>The RPM package dnf-automatic should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package dnf-automatic is installed" test_ref="oval:ssg-test_package_dnf-automatic_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_dnf-plugin-subscription-manager_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install dnf-plugin-subscription-manager Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_dnf-plugin-subscription-manager_installed" source="ssg"/>
            <oval-def:description>The RPM package dnf-plugin-subscription-manager should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package dnf-plugin-subscription-manager is installed" test_ref="oval:ssg-test_package_dnf-plugin-subscription-manager_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_dnsmasq_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall dnsmasq Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_dnsmasq_removed" source="ssg"/>
            <oval-def:description>The RPM package dnsmasq should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package dnsmasq is removed" test_ref="oval:ssg-test_package_dnsmasq_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_dovecot_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall dovecot Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_dovecot_removed" source="ssg"/>
            <oval-def:description>The RPM package dovecot should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package dovecot is removed" test_ref="oval:ssg-test_package_dovecot_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_fapolicyd_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install fapolicyd Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_fapolicyd_installed" source="ssg"/>
            <oval-def:description>The RPM package fapolicyd should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package fapolicyd is installed" test_ref="oval:ssg-test_package_fapolicyd_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_firewalld_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install firewalld Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_firewalld_installed" source="ssg"/>
            <oval-def:description>The RPM package firewalld should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package firewalld is installed" test_ref="oval:ssg-test_package_firewalld_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_freeradius_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Remove the FreeRadius Server Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_freeradius_removed" source="ssg"/>
            <oval-def:description>The RPM package freeradius should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package freeradius is removed" test_ref="oval:ssg-test_package_freeradius_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_ftp_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Remove ftp Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_ftp_removed" source="ssg"/>
            <oval-def:description>The RPM package ftp should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package ftp is removed" test_ref="oval:ssg-test_package_ftp_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_gdm_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>package_gdm_installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_gdm_installed" source="ssg"/>
            <oval-def:description>The RPM package gdm should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package gdm is installed" test_ref="oval:ssg-test_package_gdm_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_gdm_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Remove the GDM Package Group</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_gdm_removed" source="ssg"/>
            <oval-def:description>The RPM package gdm should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package gdm is removed" test_ref="oval:ssg-test_package_gdm_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_geolite2-city_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall geolite2-city Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_geolite2-city_removed" source="ssg"/>
            <oval-def:description>The RPM package geolite2-city should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package geolite2-city is removed" test_ref="oval:ssg-test_package_geolite2-city_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_geolite2-country_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall geolite2-country Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_geolite2-country_removed" source="ssg"/>
            <oval-def:description>The RPM package geolite2-country should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package geolite2-country is removed" test_ref="oval:ssg-test_package_geolite2-country_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_gnutls-utils_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure gnutls-utils is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_gnutls-utils_installed" source="ssg"/>
            <oval-def:description>The RPM package gnutls-utils should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package gnutls-utils is installed" test_ref="oval:ssg-test_package_gnutls-utils_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_gssproxy_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall gssproxy Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_gssproxy_removed" source="ssg"/>
            <oval-def:description>The RPM package gssproxy should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package gssproxy is removed" test_ref="oval:ssg-test_package_gssproxy_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_httpd_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall httpd Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_httpd_removed" source="ssg"/>
            <oval-def:description>The RPM package httpd should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package httpd is removed" test_ref="oval:ssg-test_package_httpd_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_inetutils-telnetd_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall the inet-based telnet server</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_inetutils-telnetd_removed" source="ssg"/>
            <oval-def:description>The RPM package inetutils-telnetd should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package inetutils-telnetd is removed" test_ref="oval:ssg-test_package_inetutils-telnetd_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_iprutils_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall iprutils Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_iprutils_removed" source="ssg"/>
            <oval-def:description>The RPM package iprutils should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package iprutils is removed" test_ref="oval:ssg-test_package_iprutils_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_iptables-services_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install iptables-services Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_iptables-services_installed" source="ssg"/>
            <oval-def:description>The RPM package iptables-services should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package iptables-services is installed" test_ref="oval:ssg-test_package_iptables-services_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_iptables-services_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Remove iptables-services Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_iptables-services_removed" source="ssg"/>
            <oval-def:description>The RPM package iptables-services should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package iptables-services is removed" test_ref="oval:ssg-test_package_iptables-services_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_iptables_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install iptables Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_iptables_installed" source="ssg"/>
            <oval-def:description>The RPM package iptables should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package iptables is installed" test_ref="oval:ssg-test_package_iptables_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_krb5-server_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Remove the Kerberos Server Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_krb5-server_removed" source="ssg"/>
            <oval-def:description>The RPM package krb5-server should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package krb5-server is removed" test_ref="oval:ssg-test_package_krb5-server_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_krb5-workstation_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall krb5-workstation Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_krb5-workstation_removed" source="ssg"/>
            <oval-def:description>The RPM package krb5-workstation should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package krb5-workstation is removed" test_ref="oval:ssg-test_package_krb5-workstation_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_libcap-ng-utils_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install libcap-ng-utils Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_libcap-ng-utils_installed" source="ssg"/>
            <oval-def:description>The RPM package libcap-ng-utils should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package libcap-ng-utils is installed" test_ref="oval:ssg-test_package_libcap-ng-utils_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_libreport-plugin-logger_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall libreport-plugin-logger Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_libreport-plugin-logger_removed" source="ssg"/>
            <oval-def:description>The RPM package libreport-plugin-logger should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package libreport-plugin-logger is removed" test_ref="oval:ssg-test_package_libreport-plugin-logger_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_libreport-plugin-rhtsupport_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall libreport-plugin-rhtsupport Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_libreport-plugin-rhtsupport_removed" source="ssg"/>
            <oval-def:description>The RPM package libreport-plugin-rhtsupport should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package libreport-plugin-rhtsupport is removed" test_ref="oval:ssg-test_package_libreport-plugin-rhtsupport_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_libreswan_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install libreswan Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_libreswan_installed" source="ssg"/>
            <oval-def:description>The RPM package libreswan should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package libreswan is installed" test_ref="oval:ssg-test_package_libreswan_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_libselinux_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install libselinux Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_libselinux_installed" source="ssg"/>
            <oval-def:description>The RPM package libselinux should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package libselinux is installed" test_ref="oval:ssg-test_package_libselinux_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_logrotate_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure logrotate is Installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_logrotate_installed" source="ssg"/>
            <oval-def:description>The RPM package logrotate should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package logrotate is installed" test_ref="oval:ssg-test_package_logrotate_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_mailx_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>The mailx Package Is Installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_mailx_installed" source="ssg"/>
            <oval-def:description>The RPM package mailx should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package mailx is installed" test_ref="oval:ssg-test_package_mailx_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_mcafeetp_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install McAfee Endpoint Security for Linux (ENSL)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_mcafeetp_installed" source="ssg"/>
            <oval-def:description>The RPM package McAfeeTP should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package McAfeeTP is installed" test_ref="oval:ssg-test_package_McAfeeTP_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_mcstrans_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall mcstrans Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_mcstrans_removed" source="ssg"/>
            <oval-def:description>The RPM package mcstrans should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package mcstrans is removed" test_ref="oval:ssg-test_package_mcstrans_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_net-snmp_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall net-snmp Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_net-snmp_removed" source="ssg"/>
            <oval-def:description>The RPM package net-snmp should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package net-snmp is removed" test_ref="oval:ssg-test_package_net-snmp_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_nfs-utils_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall nfs-utils Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_nfs-utils_removed" source="ssg"/>
            <oval-def:description>The RPM package nfs-utils should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package nfs-utils is removed" test_ref="oval:ssg-test_package_nfs-utils_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_nftables_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install nftables Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_nftables_installed" source="ssg"/>
            <oval-def:description>The RPM package nftables should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package nftables is installed" test_ref="oval:ssg-test_package_nftables_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_nginx_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall nginx Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_nginx_removed" source="ssg"/>
            <oval-def:description>The RPM package nginx should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package nginx is removed" test_ref="oval:ssg-test_package_nginx_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_nis_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall the nis package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_nis_removed" source="ssg"/>
            <oval-def:description>The RPM package nis should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package nis is removed" test_ref="oval:ssg-test_package_nis_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_nss-tools_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure nss-tools is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_nss-tools_installed" source="ssg"/>
            <oval-def:description>The RPM package nss-tools should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package nss-tools is installed" test_ref="oval:ssg-test_package_nss-tools_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_ntp_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install the ntp service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_ntp_installed" source="ssg"/>
            <oval-def:description>The RPM package ntp should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package ntp is installed" test_ref="oval:ssg-test_package_ntp_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_ntpdate_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall the ntpdate package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_ntpdate_removed" source="ssg"/>
            <oval-def:description>The RPM package ntpdate should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package ntpdate is removed" test_ref="oval:ssg-test_package_ntpdate_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_openldap-clients_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure LDAP client is not installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_openldap-clients_removed" source="ssg"/>
            <oval-def:description>The RPM package openldap-clients should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package openldap-clients is removed" test_ref="oval:ssg-test_package_openldap-clients_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_openldap-servers_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall openldap-servers Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_openldap-servers_removed" source="ssg"/>
            <oval-def:description>The RPM package openldap-servers should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package openldap-servers is removed" test_ref="oval:ssg-test_package_openldap-servers_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_opensc_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install the opensc Package For Multifactor Authentication</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_opensc_installed" source="ssg"/>
            <oval-def:description>The RPM package opensc should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package opensc is installed" test_ref="oval:ssg-test_package_opensc_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_openscap-scanner_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install openscap-scanner Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_openscap-scanner_installed" source="ssg"/>
            <oval-def:description>The RPM package openscap-scanner should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package openscap-scanner is installed" test_ref="oval:ssg-test_package_openscap-scanner_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_openssh-clients_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install OpenSSH client software</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_openssh-clients_installed" source="ssg"/>
            <oval-def:description>The RPM package openssh-clients should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package openssh-clients is installed" test_ref="oval:ssg-test_package_openssh-clients_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_openssh-server_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install the OpenSSH Server Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_openssh-server_installed" source="ssg"/>
            <oval-def:description>The RPM package openssh-server should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package openssh-server is installed" test_ref="oval:ssg-test_package_openssh-server_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_openssh-server_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Remove the OpenSSH Server Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_openssh-server_removed" source="ssg"/>
            <oval-def:description>The RPM package openssh-server should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package openssh-server is removed" test_ref="oval:ssg-test_package_openssh-server_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_pam_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install pam Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_pam_installed" source="ssg"/>
            <oval-def:description>The RPM package pam should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package pam is installed" test_ref="oval:ssg-test_package_pam_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_pam_pwquality_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install pam_pwquality Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_pam_pwquality_installed" source="ssg"/>
            <oval-def:description>The RPM package libpwquality should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package libpwquality is installed" test_ref="oval:ssg-test_package_libpwquality_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_pcsc-lite_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install the pcsc-lite package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_pcsc-lite_installed" source="ssg"/>
            <oval-def:description>The RPM package pcsc-lite should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package pcsc-lite is installed" test_ref="oval:ssg-test_package_pcsc-lite_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_pigz_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall pigz Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_pigz_removed" source="ssg"/>
            <oval-def:description>The RPM package pigz should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package pigz is removed" test_ref="oval:ssg-test_package_pigz_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_policycoreutils-python-utils_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install policycoreutils-python-utils package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_policycoreutils-python-utils_installed" source="ssg"/>
            <oval-def:description>The RPM package policycoreutils-python-utils should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package policycoreutils-python-utils is installed" test_ref="oval:ssg-test_package_policycoreutils-python-utils_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_policycoreutils_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install policycoreutils Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_policycoreutils_installed" source="ssg"/>
            <oval-def:description>The RPM package policycoreutils should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package policycoreutils is installed" test_ref="oval:ssg-test_package_policycoreutils_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_postfix_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>The Postfix package is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_postfix_installed" source="ssg"/>
            <oval-def:description>The RPM package postfix should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package postfix is installed" test_ref="oval:ssg-test_package_postfix_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_psacct_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install the psacct package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_psacct_installed" source="ssg"/>
            <oval-def:description>The RPM package psacct should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package psacct is installed" test_ref="oval:ssg-test_package_psacct_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_python3-abrt-addon_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall python3-abrt-addon Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_python3-abrt-addon_removed" source="ssg"/>
            <oval-def:description>The RPM package python3-abrt-addon should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package python3-abrt-addon is removed" test_ref="oval:ssg-test_package_python3-abrt-addon_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_quagga_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall quagga Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_quagga_removed" source="ssg"/>
            <oval-def:description>The RPM package quagga should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package quagga is removed" test_ref="oval:ssg-test_package_quagga_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_rear_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install rear Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_rear_installed" source="ssg"/>
            <oval-def:description>The RPM package rear should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package rear is installed" test_ref="oval:ssg-test_package_rear_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_rng-tools_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install rng-tools Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_rng-tools_installed" source="ssg"/>
            <oval-def:description>The RPM package rng-tools should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package rng-tools is installed" test_ref="oval:ssg-test_package_rng-tools_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_rpcbind_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall rpcbind Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_rpcbind_removed" source="ssg"/>
            <oval-def:description>The RPM package rpcbind should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package rpcbind is removed" test_ref="oval:ssg-test_package_rpcbind_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_rsh-server_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall rsh-server Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_rsh-server_removed" source="ssg"/>
            <oval-def:description>The RPM package rsh-server should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package rsh-server is removed" test_ref="oval:ssg-test_package_rsh-server_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_rsh_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall rsh Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_rsh_removed" source="ssg"/>
            <oval-def:description>The RPM package rsh should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package rsh is removed" test_ref="oval:ssg-test_package_rsh_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_rsync_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall rsync Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_rsync_removed" source="ssg"/>
            <oval-def:description>The RPM package rsync should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package rsync is removed" test_ref="oval:ssg-test_package_rsync_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_rsyslog-gnutls_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure rsyslog-gnutls is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_rsyslog-gnutls_installed" source="ssg"/>
            <oval-def:description>The RPM package rsyslog-gnutls should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package rsyslog-gnutls is installed" test_ref="oval:ssg-test_package_rsyslog-gnutls_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_rsyslog_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure rsyslog is Installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_rsyslog_installed" source="ssg"/>
            <oval-def:description>The RPM package rsyslog should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package rsyslog is installed" test_ref="oval:ssg-test_package_rsyslog_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_samba-common_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install the Samba Common Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_samba-common_installed" source="ssg"/>
            <oval-def:description>The RPM package samba-common should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package samba-common is installed" test_ref="oval:ssg-test_package_samba-common_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_samba-common_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>package_samba-common_removed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_samba-common_removed" source="ssg"/>
            <oval-def:description>The RPM package samba-common should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package samba-common is removed" test_ref="oval:ssg-test_package_samba-common_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_samba_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall Samba Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_samba_removed" source="ssg"/>
            <oval-def:description>The RPM package samba should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package samba is removed" test_ref="oval:ssg-test_package_samba_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_scap-security-guide_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install scap-security-guide Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_scap-security-guide_installed" source="ssg"/>
            <oval-def:description>The RPM package scap-security-guide should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package scap-security-guide is installed" test_ref="oval:ssg-test_package_scap-security-guide_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_sendmail_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall Sendmail Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_sendmail_removed" source="ssg"/>
            <oval-def:description>The RPM package sendmail should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package sendmail is removed" test_ref="oval:ssg-test_package_sendmail_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_setroubleshoot-plugins_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall setroubleshoot-plugins Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_setroubleshoot-plugins_removed" source="ssg"/>
            <oval-def:description>The RPM package setroubleshoot-plugins should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package setroubleshoot-plugins is removed" test_ref="oval:ssg-test_package_setroubleshoot-plugins_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_setroubleshoot-server_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall setroubleshoot-server Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_setroubleshoot-server_removed" source="ssg"/>
            <oval-def:description>The RPM package setroubleshoot-server should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package setroubleshoot-server is removed" test_ref="oval:ssg-test_package_setroubleshoot-server_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_setroubleshoot_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall setroubleshoot Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_setroubleshoot_removed" source="ssg"/>
            <oval-def:description>The RPM package setroubleshoot should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package setroubleshoot is removed" test_ref="oval:ssg-test_package_setroubleshoot_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_squid_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall squid Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_squid_removed" source="ssg"/>
            <oval-def:description>The RPM package squid should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package squid is removed" test_ref="oval:ssg-test_package_squid_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_sssd-ipa_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install sssd-ipa Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_sssd-ipa_installed" source="ssg"/>
            <oval-def:description>The RPM package sssd-ipa should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package sssd-ipa is installed" test_ref="oval:ssg-test_package_sssd-ipa_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_sssd_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install the SSSD Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_sssd_installed" source="ssg"/>
            <oval-def:description>The RPM package sssd should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package sssd is installed" test_ref="oval:ssg-test_package_sssd_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_subscription-manager_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install subscription-manager Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_subscription-manager_installed" source="ssg"/>
            <oval-def:description>The RPM package subscription-manager should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package subscription-manager is installed" test_ref="oval:ssg-test_package_subscription-manager_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_sudo_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install sudo Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_sudo_installed" source="ssg"/>
            <oval-def:description>The RPM package sudo should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package sudo is installed" test_ref="oval:ssg-test_package_sudo_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_syslogng_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure syslog-ng is Installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_syslogng_installed" source="ssg"/>
            <oval-def:description>The RPM package syslog-ng should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package syslog-ng is installed" test_ref="oval:ssg-test_package_syslog-ng_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_systemd-journal-remote_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install systemd-journal-remote Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_systemd-journal-remote_installed" source="ssg"/>
            <oval-def:description>The RPM package systemd-journal-remote should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package systemd-journal-remote is installed" test_ref="oval:ssg-test_package_systemd-journal-remote_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_talk-server_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall talk-server Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_talk-server_removed" source="ssg"/>
            <oval-def:description>The RPM package talk-server should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package talk-server is removed" test_ref="oval:ssg-test_package_talk-server_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_talk_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall talk Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_talk_removed" source="ssg"/>
            <oval-def:description>The RPM package talk should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package talk is removed" test_ref="oval:ssg-test_package_talk_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_tar_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install tar Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_tar_installed" source="ssg"/>
            <oval-def:description>The RPM package tar should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package tar is installed" test_ref="oval:ssg-test_package_tar_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_telnet-server_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall telnet-server Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_telnet-server_removed" source="ssg"/>
            <oval-def:description>The RPM package telnet-server should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package telnet-server is removed" test_ref="oval:ssg-test_package_telnet-server_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_telnet_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Remove telnet Clients</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_telnet_removed" source="ssg"/>
            <oval-def:description>The RPM package telnet should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package telnet is removed" test_ref="oval:ssg-test_package_telnet_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_telnetd-ssl_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall the ssl compliant telnet server</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_telnetd-ssl_removed" source="ssg"/>
            <oval-def:description>The RPM package telnetd-ssl should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package telnetd-ssl is removed" test_ref="oval:ssg-test_package_telnetd-ssl_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_telnetd_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall the telnet server</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_telnetd_removed" source="ssg"/>
            <oval-def:description>The RPM package telnetd should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package telnetd is removed" test_ref="oval:ssg-test_package_telnetd_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_tftp-server_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall tftp-server Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_tftp-server_removed" source="ssg"/>
            <oval-def:description>The RPM package tftp-server should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package tftp-server is removed" test_ref="oval:ssg-test_package_tftp-server_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_tftp_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Remove tftp Daemon</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_tftp_removed" source="ssg"/>
            <oval-def:description>The RPM package tftp should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package tftp is removed" test_ref="oval:ssg-test_package_tftp_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_tmux_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install the tmux Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_tmux_installed" source="ssg"/>
            <oval-def:description>The RPM package tmux should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package tmux is installed" test_ref="oval:ssg-test_package_tmux_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_tuned_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall tuned Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_tuned_removed" source="ssg"/>
            <oval-def:description>The RPM package tuned should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package tuned is removed" test_ref="oval:ssg-test_package_tuned_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_usbguard_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install usbguard Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_usbguard_installed" source="ssg"/>
            <oval-def:description>The RPM package usbguard should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package usbguard is installed" test_ref="oval:ssg-test_package_usbguard_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_vim_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install vim Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_vim_installed" source="ssg"/>
            <oval-def:description>The RPM package vim-enhanced should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package vim-enhanced is installed" test_ref="oval:ssg-test_package_vim-enhanced_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_vsftpd_installed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Install vsftpd Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_vsftpd_installed" source="ssg"/>
            <oval-def:description>The RPM package vsftpd should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package vsftpd is installed" test_ref="oval:ssg-test_package_vsftpd_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_vsftpd_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall vsftpd Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_vsftpd_removed" source="ssg"/>
            <oval-def:description>The RPM package vsftpd should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package vsftpd is removed" test_ref="oval:ssg-test_package_vsftpd_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_xinetd_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall xinetd package if not used by network services</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_xinetd_removed" source="ssg"/>
            <oval-def:description>The RPM package xinetd should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package xinetd is removed" test_ref="oval:ssg-test_package_xinetd_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_xorg-x11-server-Xwayland_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Remove the X Windows Xwayland Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_xorg-x11-server-Xwayland_removed" source="ssg"/>
            <oval-def:description>The RPM package xorg-x11-server-Xwayland should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package xorg-x11-server-Xwayland is removed" test_ref="oval:ssg-test_package_xorg-x11-server-Xwayland_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_xorg-x11-server-common_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Remove the X Windows Package Group</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_xorg-x11-server-common_removed" source="ssg"/>
            <oval-def:description>The RPM package xorg-x11-server-common should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package xorg-x11-server-common is removed" test_ref="oval:ssg-test_package_xorg-x11-server-common_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_ypbind_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Remove NIS Client</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_ypbind_removed" source="ssg"/>
            <oval-def:description>The RPM package ypbind should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package ypbind is removed" test_ref="oval:ssg-test_package_ypbind_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-package_ypserv_removed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Uninstall ypserv Package</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="package_ypserv_removed" source="ssg"/>
            <oval-def:description>The RPM package ypserv should be removed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="package ypserv is removed" test_ref="oval:ssg-test_package_ypserv_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-partition_for_boot:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure /boot Located On Separate Partition</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="partition_for_boot" source="ssg"/>
            <oval-def:description>If stored locally, create a separate partition for
      /boot. If /boot will be mounted from another
      system such as an NFS server, then creating a separate partition is not
      necessary at this time, and the mountpoint can instead be configured
      later.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="/boot on own partition" test_ref="oval:ssg-testboot_partition:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-partition_for_dev_shm:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure /dev/shm is configured</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="partition_for_dev_shm" source="ssg"/>
            <oval-def:description>If stored locally, create a separate partition for
      /dev/shm. If /dev/shm will be mounted from another
      system such as an NFS server, then creating a separate partition is not
      necessary at this time, and the mountpoint can instead be configured
      later.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="/dev/shm on own partition" test_ref="oval:ssg-testdev_shm_partition:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-partition_for_home:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure /home Located On Separate Partition</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="partition_for_home" source="ssg"/>
            <oval-def:description>If stored locally, create a separate partition for
      /home. If /home will be mounted from another
      system such as an NFS server, then creating a separate partition is not
      necessary at this time, and the mountpoint can instead be configured
      later.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="/home on own partition" test_ref="oval:ssg-testhome_partition:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-partition_for_opt:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure /opt Located On Separate Partition</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="partition_for_opt" source="ssg"/>
            <oval-def:description>If stored locally, create a separate partition for
      /opt. If /opt will be mounted from another
      system such as an NFS server, then creating a separate partition is not
      necessary at this time, and the mountpoint can instead be configured
      later.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="/opt on own partition" test_ref="oval:ssg-testopt_partition:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-partition_for_srv:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure /srv Located On Separate Partition</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="partition_for_srv" source="ssg"/>
            <oval-def:description>If stored locally, create a separate partition for
      /srv. If /srv will be mounted from another
      system such as an NFS server, then creating a separate partition is not
      necessary at this time, and the mountpoint can instead be configured
      later.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="/srv on own partition" test_ref="oval:ssg-testsrv_partition:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-partition_for_tmp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure /tmp Located On Separate Partition</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="partition_for_tmp" source="ssg"/>
            <oval-def:description>If stored locally, create a separate partition for
      /tmp. If /tmp will be mounted from another
      system such as an NFS server, then creating a separate partition is not
      necessary at this time, and the mountpoint can instead be configured
      later.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="/tmp on own partition" test_ref="oval:ssg-testtmp_partition:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-partition_for_usr:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure /usr Located On Separate Partition</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="partition_for_usr" source="ssg"/>
            <oval-def:description>If stored locally, create a separate partition for
      /usr. If /usr will be mounted from another
      system such as an NFS server, then creating a separate partition is not
      necessary at this time, and the mountpoint can instead be configured
      later.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="/usr on own partition" test_ref="oval:ssg-testusr_partition:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-partition_for_var:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure /var Located On Separate Partition</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="partition_for_var" source="ssg"/>
            <oval-def:description>If stored locally, create a separate partition for
      /var. If /var will be mounted from another
      system such as an NFS server, then creating a separate partition is not
      necessary at this time, and the mountpoint can instead be configured
      later.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="/var on own partition" test_ref="oval:ssg-testvar_partition:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-partition_for_var_log:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure /var/log Located On Separate Partition</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="partition_for_var_log" source="ssg"/>
            <oval-def:description>If stored locally, create a separate partition for
      /var/log. If /var/log will be mounted from another
      system such as an NFS server, then creating a separate partition is not
      necessary at this time, and the mountpoint can instead be configured
      later.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="/var/log on own partition" test_ref="oval:ssg-testvar_log_partition:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-partition_for_var_log_audit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure /var/log/audit Located On Separate Partition</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="partition_for_var_log_audit" source="ssg"/>
            <oval-def:description>If stored locally, create a separate partition for
      /var/log/audit. If /var/log/audit will be mounted from another
      system such as an NFS server, then creating a separate partition is not
      necessary at this time, and the mountpoint can instead be configured
      later.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="/var/log/audit on own partition" test_ref="oval:ssg-testvar_log_audit_partition:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-partition_for_var_tmp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure /var/tmp Located On Separate Partition</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="partition_for_var_tmp" source="ssg"/>
            <oval-def:description>If stored locally, create a separate partition for
      /var/tmp. If /var/tmp will be mounted from another
      system such as an NFS server, then creating a separate partition is not
      necessary at this time, and the mountpoint can instead be configured
      later.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="/var/tmp on own partition" test_ref="oval:ssg-testvar_tmp_partition:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-root_permissions_syslibrary_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify the system-wide library files in directories
"/lib", "/lib64", "/usr/lib/" and "/usr/lib64" are group-owned by root.</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="root_permissions_syslibrary_files" source="ssg"/>
            <oval-def:description>This test makes sure that /lib/, /lib64/, /usr/lib/, /usr/lib64/ is group owned by 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file group ownership of /lib/" test_ref="oval:ssg-test_file_groupownerroot_permissions_syslibrary_files_0:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /lib64/" test_ref="oval:ssg-test_file_groupownerroot_permissions_syslibrary_files_1:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /usr/lib/" test_ref="oval:ssg-test_file_groupownerroot_permissions_syslibrary_files_2:tst:1"/>
            <oval-def:criterion comment="Check file group ownership of /usr/lib64/" test_ref="oval:ssg-test_file_groupownerroot_permissions_syslibrary_files_3:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rsyslog_files_groupownership:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Log Files Are Owned By Appropriate Group</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rsyslog_files_groupownership" source="ssg"/>
            <oval-def:description>All syslog log files should have appropriate ownership.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check if all system log files have appropriate groupowner set" test_ref="oval:ssg-test_rsyslog_files_groupownership:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rsyslog_files_ownership:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Log Files Are Owned By Appropriate User</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rsyslog_files_ownership" source="ssg"/>
            <oval-def:description>All syslog log files should have appropriate ownership.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check if all system log files have appropriate owner set" test_ref="oval:ssg-test_rsyslog_files_ownership:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-rsyslog_files_permissions:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure System Log Files Have Correct Permissions</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="rsyslog_files_permissions" source="ssg"/>
            <oval-def:description>All syslog log files should have appropriate ownership.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check if all system log files have appropriate permissions set" test_ref="oval:ssg-test_rsyslog_files_permissions:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_abrt_anon_write:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the abrt_anon_write SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_abrt_anon_write" source="ssg"/>
            <oval-def:description>The SELinux 'abrt_anon_write' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="abrt_anon_write is configured correctly" test_ref="oval:ssg-test_sebool_abrt_anon_write:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_abrt_handle_event:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the abrt_handle_event SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_abrt_handle_event" source="ssg"/>
            <oval-def:description>The SELinux 'abrt_handle_event' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="abrt_handle_event is configured correctly" test_ref="oval:ssg-test_sebool_abrt_handle_event:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_abrt_upload_watch_anon_write:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the abrt_upload_watch_anon_write SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_abrt_upload_watch_anon_write" source="ssg"/>
            <oval-def:description>The SELinux 'abrt_upload_watch_anon_write' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="abrt_upload_watch_anon_write is configured correctly" test_ref="oval:ssg-test_sebool_abrt_upload_watch_anon_write:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_antivirus_can_scan_system:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the antivirus_can_scan_system SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_antivirus_can_scan_system" source="ssg"/>
            <oval-def:description>The SELinux 'antivirus_can_scan_system' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="antivirus_can_scan_system is configured correctly" test_ref="oval:ssg-test_sebool_antivirus_can_scan_system:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_antivirus_use_jit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the antivirus_use_jit SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_antivirus_use_jit" source="ssg"/>
            <oval-def:description>The SELinux 'antivirus_use_jit' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="antivirus_use_jit is configured correctly" test_ref="oval:ssg-test_sebool_antivirus_use_jit:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_auditadm_exec_content:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the auditadm_exec_content SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_auditadm_exec_content" source="ssg"/>
            <oval-def:description>The SELinux 'auditadm_exec_content' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="auditadm_exec_content is configured correctly" test_ref="oval:ssg-test_sebool_auditadm_exec_content:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_authlogin_nsswitch_use_ldap:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the authlogin_nsswitch_use_ldap SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_authlogin_nsswitch_use_ldap" source="ssg"/>
            <oval-def:description>The SELinux 'authlogin_nsswitch_use_ldap' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="authlogin_nsswitch_use_ldap is configured correctly" test_ref="oval:ssg-test_sebool_authlogin_nsswitch_use_ldap:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_authlogin_radius:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the authlogin_radius SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_authlogin_radius" source="ssg"/>
            <oval-def:description>The SELinux 'authlogin_radius' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="authlogin_radius is configured correctly" test_ref="oval:ssg-test_sebool_authlogin_radius:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_authlogin_yubikey:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the authlogin_yubikey SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_authlogin_yubikey" source="ssg"/>
            <oval-def:description>The SELinux 'authlogin_yubikey' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="authlogin_yubikey is configured correctly" test_ref="oval:ssg-test_sebool_authlogin_yubikey:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_awstats_purge_apache_log_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the awstats_purge_apache_log_files SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_awstats_purge_apache_log_files" source="ssg"/>
            <oval-def:description>The SELinux 'awstats_purge_apache_log_files' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="awstats_purge_apache_log_files is configured correctly" test_ref="oval:ssg-test_sebool_awstats_purge_apache_log_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_boinc_execmem:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the boinc_execmem SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_boinc_execmem" source="ssg"/>
            <oval-def:description>The SELinux 'boinc_execmem' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="boinc_execmem is configured correctly" test_ref="oval:ssg-test_sebool_boinc_execmem:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_cdrecord_read_content:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the cdrecord_read_content SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_cdrecord_read_content" source="ssg"/>
            <oval-def:description>The SELinux 'cdrecord_read_content' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="cdrecord_read_content is configured correctly" test_ref="oval:ssg-test_sebool_cdrecord_read_content:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_cluster_can_network_connect:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the cluster_can_network_connect SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_cluster_can_network_connect" source="ssg"/>
            <oval-def:description>The SELinux 'cluster_can_network_connect' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="cluster_can_network_connect is configured correctly" test_ref="oval:ssg-test_sebool_cluster_can_network_connect:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_cluster_manage_all_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the cluster_manage_all_files SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_cluster_manage_all_files" source="ssg"/>
            <oval-def:description>The SELinux 'cluster_manage_all_files' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="cluster_manage_all_files is configured correctly" test_ref="oval:ssg-test_sebool_cluster_manage_all_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_cluster_use_execmem:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the cluster_use_execmem SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_cluster_use_execmem" source="ssg"/>
            <oval-def:description>The SELinux 'cluster_use_execmem' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="cluster_use_execmem is configured correctly" test_ref="oval:ssg-test_sebool_cluster_use_execmem:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_cobbler_anon_write:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the cobbler_anon_write SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_cobbler_anon_write" source="ssg"/>
            <oval-def:description>The SELinux 'cobbler_anon_write' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="cobbler_anon_write is configured correctly" test_ref="oval:ssg-test_sebool_cobbler_anon_write:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_cobbler_can_network_connect:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the cobbler_can_network_connect SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_cobbler_can_network_connect" source="ssg"/>
            <oval-def:description>The SELinux 'cobbler_can_network_connect' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="cobbler_can_network_connect is configured correctly" test_ref="oval:ssg-test_sebool_cobbler_can_network_connect:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_cobbler_use_cifs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the cobbler_use_cifs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_cobbler_use_cifs" source="ssg"/>
            <oval-def:description>The SELinux 'cobbler_use_cifs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="cobbler_use_cifs is configured correctly" test_ref="oval:ssg-test_sebool_cobbler_use_cifs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_cobbler_use_nfs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the cobbler_use_nfs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_cobbler_use_nfs" source="ssg"/>
            <oval-def:description>The SELinux 'cobbler_use_nfs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="cobbler_use_nfs is configured correctly" test_ref="oval:ssg-test_sebool_cobbler_use_nfs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_collectd_tcp_network_connect:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the collectd_tcp_network_connect SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_collectd_tcp_network_connect" source="ssg"/>
            <oval-def:description>The SELinux 'collectd_tcp_network_connect' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="collectd_tcp_network_connect is configured correctly" test_ref="oval:ssg-test_sebool_collectd_tcp_network_connect:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_condor_tcp_network_connect:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the condor_tcp_network_connect SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_condor_tcp_network_connect" source="ssg"/>
            <oval-def:description>The SELinux 'condor_tcp_network_connect' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="condor_tcp_network_connect is configured correctly" test_ref="oval:ssg-test_sebool_condor_tcp_network_connect:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_conman_can_network:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the conman_can_network SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_conman_can_network" source="ssg"/>
            <oval-def:description>The SELinux 'conman_can_network' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="conman_can_network is configured correctly" test_ref="oval:ssg-test_sebool_conman_can_network:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_container_connect_any:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the container_connect_any SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_container_connect_any" source="ssg"/>
            <oval-def:description>The SELinux 'container_connect_any' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="container_connect_any is configured correctly" test_ref="oval:ssg-test_sebool_container_connect_any:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_cron_can_relabel:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the cron_can_relabel SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_cron_can_relabel" source="ssg"/>
            <oval-def:description>The SELinux 'cron_can_relabel' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="cron_can_relabel is configured correctly" test_ref="oval:ssg-test_sebool_cron_can_relabel:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_cron_system_cronjob_use_shares:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the cron_system_cronjob_use_shares SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_cron_system_cronjob_use_shares" source="ssg"/>
            <oval-def:description>The SELinux 'cron_system_cronjob_use_shares' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="cron_system_cronjob_use_shares is configured correctly" test_ref="oval:ssg-test_sebool_cron_system_cronjob_use_shares:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_cron_userdomain_transition:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the cron_userdomain_transition SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_cron_userdomain_transition" source="ssg"/>
            <oval-def:description>The SELinux 'cron_userdomain_transition' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="cron_userdomain_transition is configured correctly" test_ref="oval:ssg-test_sebool_cron_userdomain_transition:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_cups_execmem:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the cups_execmem SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_cups_execmem" source="ssg"/>
            <oval-def:description>The SELinux 'cups_execmem' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="cups_execmem is configured correctly" test_ref="oval:ssg-test_sebool_cups_execmem:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_cvs_read_shadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the cvs_read_shadow SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_cvs_read_shadow" source="ssg"/>
            <oval-def:description>The SELinux 'cvs_read_shadow' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="cvs_read_shadow is configured correctly" test_ref="oval:ssg-test_sebool_cvs_read_shadow:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_daemons_dump_core:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the daemons_dump_core SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_daemons_dump_core" source="ssg"/>
            <oval-def:description>The SELinux 'daemons_dump_core' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="daemons_dump_core is configured correctly" test_ref="oval:ssg-test_sebool_daemons_dump_core:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_daemons_enable_cluster_mode:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the daemons_enable_cluster_mode SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_daemons_enable_cluster_mode" source="ssg"/>
            <oval-def:description>The SELinux 'daemons_enable_cluster_mode' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="daemons_enable_cluster_mode is configured correctly" test_ref="oval:ssg-test_sebool_daemons_enable_cluster_mode:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_daemons_use_tcp_wrapper:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the daemons_use_tcp_wrapper SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_daemons_use_tcp_wrapper" source="ssg"/>
            <oval-def:description>The SELinux 'daemons_use_tcp_wrapper' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="daemons_use_tcp_wrapper is configured correctly" test_ref="oval:ssg-test_sebool_daemons_use_tcp_wrapper:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_daemons_use_tty:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the daemons_use_tty SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_daemons_use_tty" source="ssg"/>
            <oval-def:description>The SELinux 'daemons_use_tty' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="daemons_use_tty is configured correctly" test_ref="oval:ssg-test_sebool_daemons_use_tty:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_dbadm_exec_content:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the dbadm_exec_content SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_dbadm_exec_content" source="ssg"/>
            <oval-def:description>The SELinux 'dbadm_exec_content' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="dbadm_exec_content is configured correctly" test_ref="oval:ssg-test_sebool_dbadm_exec_content:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_dbadm_manage_user_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the dbadm_manage_user_files SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_dbadm_manage_user_files" source="ssg"/>
            <oval-def:description>The SELinux 'dbadm_manage_user_files' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="dbadm_manage_user_files is configured correctly" test_ref="oval:ssg-test_sebool_dbadm_manage_user_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_dbadm_read_user_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the dbadm_read_user_files SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_dbadm_read_user_files" source="ssg"/>
            <oval-def:description>The SELinux 'dbadm_read_user_files' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="dbadm_read_user_files is configured correctly" test_ref="oval:ssg-test_sebool_dbadm_read_user_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_deny_execmem:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure the deny_execmem SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_deny_execmem" source="ssg"/>
            <oval-def:description>The SELinux 'deny_execmem' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="deny_execmem is configured correctly" test_ref="oval:ssg-test_sebool_deny_execmem:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_deny_ptrace:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the deny_ptrace SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_deny_ptrace" source="ssg"/>
            <oval-def:description>The SELinux 'deny_ptrace' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="deny_ptrace is configured correctly" test_ref="oval:ssg-test_sebool_deny_ptrace:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_dhcpc_exec_iptables:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the dhcpc_exec_iptables SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_dhcpc_exec_iptables" source="ssg"/>
            <oval-def:description>The SELinux 'dhcpc_exec_iptables' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="dhcpc_exec_iptables is configured correctly" test_ref="oval:ssg-test_sebool_dhcpc_exec_iptables:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_dhcpd_use_ldap:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the dhcpd_use_ldap SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_dhcpd_use_ldap" source="ssg"/>
            <oval-def:description>The SELinux 'dhcpd_use_ldap' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="dhcpd_use_ldap is configured correctly" test_ref="oval:ssg-test_sebool_dhcpd_use_ldap:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_domain_fd_use:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the domain_fd_use SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_domain_fd_use" source="ssg"/>
            <oval-def:description>The SELinux 'domain_fd_use' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="domain_fd_use is configured correctly" test_ref="oval:ssg-test_sebool_domain_fd_use:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_domain_kernel_load_modules:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the domain_kernel_load_modules SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_domain_kernel_load_modules" source="ssg"/>
            <oval-def:description>The SELinux 'domain_kernel_load_modules' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="domain_kernel_load_modules is configured correctly" test_ref="oval:ssg-test_sebool_domain_kernel_load_modules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_entropyd_use_audio:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the entropyd_use_audio SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_entropyd_use_audio" source="ssg"/>
            <oval-def:description>The SELinux 'entropyd_use_audio' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="entropyd_use_audio is configured correctly" test_ref="oval:ssg-test_sebool_entropyd_use_audio:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_exim_can_connect_db:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the exim_can_connect_db SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_exim_can_connect_db" source="ssg"/>
            <oval-def:description>The SELinux 'exim_can_connect_db' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="exim_can_connect_db is configured correctly" test_ref="oval:ssg-test_sebool_exim_can_connect_db:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_exim_manage_user_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the exim_manage_user_files SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_exim_manage_user_files" source="ssg"/>
            <oval-def:description>The SELinux 'exim_manage_user_files' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="exim_manage_user_files is configured correctly" test_ref="oval:ssg-test_sebool_exim_manage_user_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_exim_read_user_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the exim_read_user_files SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_exim_read_user_files" source="ssg"/>
            <oval-def:description>The SELinux 'exim_read_user_files' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="exim_read_user_files is configured correctly" test_ref="oval:ssg-test_sebool_exim_read_user_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_fcron_crond:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the fcron_crond SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_fcron_crond" source="ssg"/>
            <oval-def:description>The SELinux 'fcron_crond' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="fcron_crond is configured correctly" test_ref="oval:ssg-test_sebool_fcron_crond:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_fenced_can_network_connect:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the fenced_can_network_connect SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_fenced_can_network_connect" source="ssg"/>
            <oval-def:description>The SELinux 'fenced_can_network_connect' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="fenced_can_network_connect is configured correctly" test_ref="oval:ssg-test_sebool_fenced_can_network_connect:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_fenced_can_ssh:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the fenced_can_ssh SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_fenced_can_ssh" source="ssg"/>
            <oval-def:description>The SELinux 'fenced_can_ssh' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="fenced_can_ssh is configured correctly" test_ref="oval:ssg-test_sebool_fenced_can_ssh:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_fips_mode:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the fips_mode SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_fips_mode" source="ssg"/>
            <oval-def:description>The SELinux 'fips_mode' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="fips_mode is configured correctly" test_ref="oval:ssg-test_sebool_fips_mode:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_ftpd_anon_write:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the ftpd_anon_write SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_ftpd_anon_write" source="ssg"/>
            <oval-def:description>The SELinux 'ftpd_anon_write' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="ftpd_anon_write is configured correctly" test_ref="oval:ssg-test_sebool_ftpd_anon_write:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_ftpd_connect_all_unreserved:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the ftpd_connect_all_unreserved SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_ftpd_connect_all_unreserved" source="ssg"/>
            <oval-def:description>The SELinux 'ftpd_connect_all_unreserved' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="ftpd_connect_all_unreserved is configured correctly" test_ref="oval:ssg-test_sebool_ftpd_connect_all_unreserved:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_ftpd_connect_db:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the ftpd_connect_db SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_ftpd_connect_db" source="ssg"/>
            <oval-def:description>The SELinux 'ftpd_connect_db' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="ftpd_connect_db is configured correctly" test_ref="oval:ssg-test_sebool_ftpd_connect_db:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_ftpd_full_access:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the ftpd_full_access SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_ftpd_full_access" source="ssg"/>
            <oval-def:description>The SELinux 'ftpd_full_access' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="ftpd_full_access is configured correctly" test_ref="oval:ssg-test_sebool_ftpd_full_access:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_ftpd_use_cifs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the ftpd_use_cifs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_ftpd_use_cifs" source="ssg"/>
            <oval-def:description>The SELinux 'ftpd_use_cifs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="ftpd_use_cifs is configured correctly" test_ref="oval:ssg-test_sebool_ftpd_use_cifs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_ftpd_use_fusefs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the ftpd_use_fusefs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_ftpd_use_fusefs" source="ssg"/>
            <oval-def:description>The SELinux 'ftpd_use_fusefs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="ftpd_use_fusefs is configured correctly" test_ref="oval:ssg-test_sebool_ftpd_use_fusefs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_ftpd_use_nfs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the ftpd_use_nfs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_ftpd_use_nfs" source="ssg"/>
            <oval-def:description>The SELinux 'ftpd_use_nfs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="ftpd_use_nfs is configured correctly" test_ref="oval:ssg-test_sebool_ftpd_use_nfs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_ftpd_use_passive_mode:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the ftpd_use_passive_mode SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_ftpd_use_passive_mode" source="ssg"/>
            <oval-def:description>The SELinux 'ftpd_use_passive_mode' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="ftpd_use_passive_mode is configured correctly" test_ref="oval:ssg-test_sebool_ftpd_use_passive_mode:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_git_cgi_enable_homedirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the git_cgi_enable_homedirs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_git_cgi_enable_homedirs" source="ssg"/>
            <oval-def:description>The SELinux 'git_cgi_enable_homedirs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="git_cgi_enable_homedirs is configured correctly" test_ref="oval:ssg-test_sebool_git_cgi_enable_homedirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_git_cgi_use_cifs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the git_cgi_use_cifs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_git_cgi_use_cifs" source="ssg"/>
            <oval-def:description>The SELinux 'git_cgi_use_cifs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="git_cgi_use_cifs is configured correctly" test_ref="oval:ssg-test_sebool_git_cgi_use_cifs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_git_cgi_use_nfs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the git_cgi_use_nfs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_git_cgi_use_nfs" source="ssg"/>
            <oval-def:description>The SELinux 'git_cgi_use_nfs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="git_cgi_use_nfs is configured correctly" test_ref="oval:ssg-test_sebool_git_cgi_use_nfs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_git_session_bind_all_unreserved_ports:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the git_session_bind_all_unreserved_ports SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_git_session_bind_all_unreserved_ports" source="ssg"/>
            <oval-def:description>The SELinux 'git_session_bind_all_unreserved_ports' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="git_session_bind_all_unreserved_ports is configured correctly" test_ref="oval:ssg-test_sebool_git_session_bind_all_unreserved_ports:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_git_session_users:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the git_session_users SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_git_session_users" source="ssg"/>
            <oval-def:description>The SELinux 'git_session_users' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="git_session_users is configured correctly" test_ref="oval:ssg-test_sebool_git_session_users:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_git_system_enable_homedirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the git_system_enable_homedirs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_git_system_enable_homedirs" source="ssg"/>
            <oval-def:description>The SELinux 'git_system_enable_homedirs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="git_system_enable_homedirs is configured correctly" test_ref="oval:ssg-test_sebool_git_system_enable_homedirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_git_system_use_cifs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the git_system_use_cifs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_git_system_use_cifs" source="ssg"/>
            <oval-def:description>The SELinux 'git_system_use_cifs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="git_system_use_cifs is configured correctly" test_ref="oval:ssg-test_sebool_git_system_use_cifs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_git_system_use_nfs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the git_system_use_nfs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_git_system_use_nfs" source="ssg"/>
            <oval-def:description>The SELinux 'git_system_use_nfs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="git_system_use_nfs is configured correctly" test_ref="oval:ssg-test_sebool_git_system_use_nfs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_gitosis_can_sendmail:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the gitosis_can_sendmail SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_gitosis_can_sendmail" source="ssg"/>
            <oval-def:description>The SELinux 'gitosis_can_sendmail' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="gitosis_can_sendmail is configured correctly" test_ref="oval:ssg-test_sebool_gitosis_can_sendmail:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_glance_api_can_network:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the glance_api_can_network SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_glance_api_can_network" source="ssg"/>
            <oval-def:description>The SELinux 'glance_api_can_network' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="glance_api_can_network is configured correctly" test_ref="oval:ssg-test_sebool_glance_api_can_network:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_glance_use_execmem:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the glance_use_execmem SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_glance_use_execmem" source="ssg"/>
            <oval-def:description>The SELinux 'glance_use_execmem' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="glance_use_execmem is configured correctly" test_ref="oval:ssg-test_sebool_glance_use_execmem:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_glance_use_fusefs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the glance_use_fusefs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_glance_use_fusefs" source="ssg"/>
            <oval-def:description>The SELinux 'glance_use_fusefs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="glance_use_fusefs is configured correctly" test_ref="oval:ssg-test_sebool_glance_use_fusefs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_global_ssp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the global_ssp SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_global_ssp" source="ssg"/>
            <oval-def:description>The SELinux 'global_ssp' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="global_ssp is configured correctly" test_ref="oval:ssg-test_sebool_global_ssp:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_gluster_anon_write:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the gluster_anon_write SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_gluster_anon_write" source="ssg"/>
            <oval-def:description>The SELinux 'gluster_anon_write' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="gluster_anon_write is configured correctly" test_ref="oval:ssg-test_sebool_gluster_anon_write:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_gluster_export_all_ro:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the gluster_export_all_ro SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_gluster_export_all_ro" source="ssg"/>
            <oval-def:description>The SELinux 'gluster_export_all_ro' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="gluster_export_all_ro is configured correctly" test_ref="oval:ssg-test_sebool_gluster_export_all_ro:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_gluster_export_all_rw:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure the gluster_export_all_rw SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_gluster_export_all_rw" source="ssg"/>
            <oval-def:description>The SELinux 'gluster_export_all_rw' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="gluster_export_all_rw is configured correctly" test_ref="oval:ssg-test_sebool_gluster_export_all_rw:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_gpg_web_anon_write:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the gpg_web_anon_write SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_gpg_web_anon_write" source="ssg"/>
            <oval-def:description>The SELinux 'gpg_web_anon_write' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="gpg_web_anon_write is configured correctly" test_ref="oval:ssg-test_sebool_gpg_web_anon_write:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_gssd_read_tmp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the gssd_read_tmp SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_gssd_read_tmp" source="ssg"/>
            <oval-def:description>The SELinux 'gssd_read_tmp' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="gssd_read_tmp is configured correctly" test_ref="oval:ssg-test_sebool_gssd_read_tmp:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_guest_exec_content:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the guest_exec_content SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_guest_exec_content" source="ssg"/>
            <oval-def:description>The SELinux 'guest_exec_content' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="guest_exec_content is configured correctly" test_ref="oval:ssg-test_sebool_guest_exec_content:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_haproxy_connect_any:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the haproxy_connect_any SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_haproxy_connect_any" source="ssg"/>
            <oval-def:description>The SELinux 'haproxy_connect_any' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="haproxy_connect_any is configured correctly" test_ref="oval:ssg-test_sebool_haproxy_connect_any:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_anon_write:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_anon_write SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_anon_write" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_anon_write' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_anon_write is configured correctly" test_ref="oval:ssg-test_sebool_httpd_anon_write:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_builtin_scripting:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure the httpd_builtin_scripting SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_builtin_scripting" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_builtin_scripting' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_builtin_scripting is configured correctly" test_ref="oval:ssg-test_sebool_httpd_builtin_scripting:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_can_check_spam:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_can_check_spam SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_can_check_spam" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_can_check_spam' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_can_check_spam is configured correctly" test_ref="oval:ssg-test_sebool_httpd_can_check_spam:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_can_connect_ftp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_can_connect_ftp SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_can_connect_ftp" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_can_connect_ftp' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_can_connect_ftp is configured correctly" test_ref="oval:ssg-test_sebool_httpd_can_connect_ftp:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_can_connect_ldap:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_can_connect_ldap SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_can_connect_ldap" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_can_connect_ldap' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_can_connect_ldap is configured correctly" test_ref="oval:ssg-test_sebool_httpd_can_connect_ldap:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_can_connect_mythtv:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_can_connect_mythtv SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_can_connect_mythtv" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_can_connect_mythtv' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_can_connect_mythtv is configured correctly" test_ref="oval:ssg-test_sebool_httpd_can_connect_mythtv:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_can_connect_zabbix:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_can_connect_zabbix SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_can_connect_zabbix" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_can_connect_zabbix' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_can_connect_zabbix is configured correctly" test_ref="oval:ssg-test_sebool_httpd_can_connect_zabbix:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_can_network_connect:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_can_network_connect SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_can_network_connect" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_can_network_connect' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_can_network_connect is configured correctly" test_ref="oval:ssg-test_sebool_httpd_can_network_connect:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_can_network_connect_cobbler:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_can_network_connect_cobbler SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_can_network_connect_cobbler" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_can_network_connect_cobbler' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_can_network_connect_cobbler is configured correctly" test_ref="oval:ssg-test_sebool_httpd_can_network_connect_cobbler:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_can_network_connect_db:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_can_network_connect_db SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_can_network_connect_db" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_can_network_connect_db' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_can_network_connect_db is configured correctly" test_ref="oval:ssg-test_sebool_httpd_can_network_connect_db:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_can_network_memcache:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_can_network_memcache SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_can_network_memcache" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_can_network_memcache' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_can_network_memcache is configured correctly" test_ref="oval:ssg-test_sebool_httpd_can_network_memcache:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_can_network_relay:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_can_network_relay SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_can_network_relay" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_can_network_relay' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_can_network_relay is configured correctly" test_ref="oval:ssg-test_sebool_httpd_can_network_relay:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_can_sendmail:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_can_sendmail SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_can_sendmail" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_can_sendmail' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_can_sendmail is configured correctly" test_ref="oval:ssg-test_sebool_httpd_can_sendmail:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_dbus_avahi:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_dbus_avahi SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_dbus_avahi" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_dbus_avahi' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_dbus_avahi is configured correctly" test_ref="oval:ssg-test_sebool_httpd_dbus_avahi:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_dbus_sssd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_dbus_sssd SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_dbus_sssd" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_dbus_sssd' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_dbus_sssd is configured correctly" test_ref="oval:ssg-test_sebool_httpd_dbus_sssd:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_dontaudit_search_dirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_dontaudit_search_dirs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_dontaudit_search_dirs" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_dontaudit_search_dirs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_dontaudit_search_dirs is configured correctly" test_ref="oval:ssg-test_sebool_httpd_dontaudit_search_dirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_enable_cgi:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure the httpd_enable_cgi SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_enable_cgi" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_enable_cgi' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_enable_cgi is configured correctly" test_ref="oval:ssg-test_sebool_httpd_enable_cgi:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_enable_ftp_server:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_enable_ftp_server SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_enable_ftp_server" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_enable_ftp_server' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_enable_ftp_server is configured correctly" test_ref="oval:ssg-test_sebool_httpd_enable_ftp_server:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_enable_homedirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_enable_homedirs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_enable_homedirs" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_enable_homedirs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_enable_homedirs is configured correctly" test_ref="oval:ssg-test_sebool_httpd_enable_homedirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_execmem:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_execmem SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_execmem" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_execmem' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_execmem is configured correctly" test_ref="oval:ssg-test_sebool_httpd_execmem:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_graceful_shutdown:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the httpd_graceful_shutdown SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_graceful_shutdown" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_graceful_shutdown' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_graceful_shutdown is configured correctly" test_ref="oval:ssg-test_sebool_httpd_graceful_shutdown:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_manage_ipa:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_manage_ipa SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_manage_ipa" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_manage_ipa' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_manage_ipa is configured correctly" test_ref="oval:ssg-test_sebool_httpd_manage_ipa:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_mod_auth_ntlm_winbind:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_mod_auth_ntlm_winbind SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_mod_auth_ntlm_winbind" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_mod_auth_ntlm_winbind' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_mod_auth_ntlm_winbind is configured correctly" test_ref="oval:ssg-test_sebool_httpd_mod_auth_ntlm_winbind:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_mod_auth_pam:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_mod_auth_pam SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_mod_auth_pam" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_mod_auth_pam' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_mod_auth_pam is configured correctly" test_ref="oval:ssg-test_sebool_httpd_mod_auth_pam:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_read_user_content:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_read_user_content SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_read_user_content" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_read_user_content' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_read_user_content is configured correctly" test_ref="oval:ssg-test_sebool_httpd_read_user_content:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_run_ipa:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_run_ipa SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_run_ipa" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_run_ipa' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_run_ipa is configured correctly" test_ref="oval:ssg-test_sebool_httpd_run_ipa:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_run_preupgrade:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_run_preupgrade SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_run_preupgrade" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_run_preupgrade' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_run_preupgrade is configured correctly" test_ref="oval:ssg-test_sebool_httpd_run_preupgrade:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_run_stickshift:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_run_stickshift SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_run_stickshift" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_run_stickshift' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_run_stickshift is configured correctly" test_ref="oval:ssg-test_sebool_httpd_run_stickshift:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_serve_cobbler_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_serve_cobbler_files SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_serve_cobbler_files" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_serve_cobbler_files' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_serve_cobbler_files is configured correctly" test_ref="oval:ssg-test_sebool_httpd_serve_cobbler_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_setrlimit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_setrlimit SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_setrlimit" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_setrlimit' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_setrlimit is configured correctly" test_ref="oval:ssg-test_sebool_httpd_setrlimit:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_ssi_exec:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_ssi_exec SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_ssi_exec" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_ssi_exec' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_ssi_exec is configured correctly" test_ref="oval:ssg-test_sebool_httpd_ssi_exec:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_sys_script_anon_write:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_sys_script_anon_write SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_sys_script_anon_write" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_sys_script_anon_write' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_sys_script_anon_write is configured correctly" test_ref="oval:ssg-test_sebool_httpd_sys_script_anon_write:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_tmp_exec:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_tmp_exec SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_tmp_exec" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_tmp_exec' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_tmp_exec is configured correctly" test_ref="oval:ssg-test_sebool_httpd_tmp_exec:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_tty_comm:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_tty_comm SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_tty_comm" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_tty_comm' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_tty_comm is configured correctly" test_ref="oval:ssg-test_sebool_httpd_tty_comm:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_unified:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_unified SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_unified" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_unified' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_unified is configured correctly" test_ref="oval:ssg-test_sebool_httpd_unified:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_use_cifs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_use_cifs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_use_cifs" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_use_cifs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_use_cifs is configured correctly" test_ref="oval:ssg-test_sebool_httpd_use_cifs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_use_fusefs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_use_fusefs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_use_fusefs" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_use_fusefs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_use_fusefs is configured correctly" test_ref="oval:ssg-test_sebool_httpd_use_fusefs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_use_gpg:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_use_gpg SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_use_gpg" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_use_gpg' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_use_gpg is configured correctly" test_ref="oval:ssg-test_sebool_httpd_use_gpg:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_use_nfs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_use_nfs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_use_nfs" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_use_nfs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_use_nfs is configured correctly" test_ref="oval:ssg-test_sebool_httpd_use_nfs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_use_openstack:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_use_openstack SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_use_openstack" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_use_openstack' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_use_openstack is configured correctly" test_ref="oval:ssg-test_sebool_httpd_use_openstack:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_use_sasl:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_use_sasl SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_use_sasl" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_use_sasl' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_use_sasl is configured correctly" test_ref="oval:ssg-test_sebool_httpd_use_sasl:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_httpd_verify_dns:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the httpd_verify_dns SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_httpd_verify_dns" source="ssg"/>
            <oval-def:description>The SELinux 'httpd_verify_dns' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="httpd_verify_dns is configured correctly" test_ref="oval:ssg-test_sebool_httpd_verify_dns:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_icecast_use_any_tcp_ports:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the icecast_use_any_tcp_ports SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_icecast_use_any_tcp_ports" source="ssg"/>
            <oval-def:description>The SELinux 'icecast_use_any_tcp_ports' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="icecast_use_any_tcp_ports is configured correctly" test_ref="oval:ssg-test_sebool_icecast_use_any_tcp_ports:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_irc_use_any_tcp_ports:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the irc_use_any_tcp_ports SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_irc_use_any_tcp_ports" source="ssg"/>
            <oval-def:description>The SELinux 'irc_use_any_tcp_ports' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="irc_use_any_tcp_ports is configured correctly" test_ref="oval:ssg-test_sebool_irc_use_any_tcp_ports:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_irssi_use_full_network:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the irssi_use_full_network SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_irssi_use_full_network" source="ssg"/>
            <oval-def:description>The SELinux 'irssi_use_full_network' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="irssi_use_full_network is configured correctly" test_ref="oval:ssg-test_sebool_irssi_use_full_network:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_kdumpgui_run_bootloader:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the kdumpgui_run_bootloader SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_kdumpgui_run_bootloader" source="ssg"/>
            <oval-def:description>The SELinux 'kdumpgui_run_bootloader' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kdumpgui_run_bootloader is configured correctly" test_ref="oval:ssg-test_sebool_kdumpgui_run_bootloader:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_kerberos_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the kerberos_enabled SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_kerberos_enabled" source="ssg"/>
            <oval-def:description>The SELinux 'kerberos_enabled' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kerberos_enabled is configured correctly" test_ref="oval:ssg-test_sebool_kerberos_enabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_ksmtuned_use_cifs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the ksmtuned_use_cifs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_ksmtuned_use_cifs" source="ssg"/>
            <oval-def:description>The SELinux 'ksmtuned_use_cifs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="ksmtuned_use_cifs is configured correctly" test_ref="oval:ssg-test_sebool_ksmtuned_use_cifs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_ksmtuned_use_nfs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the ksmtuned_use_nfs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_ksmtuned_use_nfs" source="ssg"/>
            <oval-def:description>The SELinux 'ksmtuned_use_nfs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="ksmtuned_use_nfs is configured correctly" test_ref="oval:ssg-test_sebool_ksmtuned_use_nfs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_logadm_exec_content:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the logadm_exec_content SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_logadm_exec_content" source="ssg"/>
            <oval-def:description>The SELinux 'logadm_exec_content' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="logadm_exec_content is configured correctly" test_ref="oval:ssg-test_sebool_logadm_exec_content:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_logging_syslogd_can_sendmail:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the logging_syslogd_can_sendmail SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_logging_syslogd_can_sendmail" source="ssg"/>
            <oval-def:description>The SELinux 'logging_syslogd_can_sendmail' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="logging_syslogd_can_sendmail is configured correctly" test_ref="oval:ssg-test_sebool_logging_syslogd_can_sendmail:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_logging_syslogd_run_nagios_plugins:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the logging_syslogd_run_nagios_plugins SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_logging_syslogd_run_nagios_plugins" source="ssg"/>
            <oval-def:description>The SELinux 'logging_syslogd_run_nagios_plugins' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="logging_syslogd_run_nagios_plugins is configured correctly" test_ref="oval:ssg-test_sebool_logging_syslogd_run_nagios_plugins:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_logging_syslogd_use_tty:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the logging_syslogd_use_tty SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_logging_syslogd_use_tty" source="ssg"/>
            <oval-def:description>The SELinux 'logging_syslogd_use_tty' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="logging_syslogd_use_tty is configured correctly" test_ref="oval:ssg-test_sebool_logging_syslogd_use_tty:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_login_console_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the login_console_enabled SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_login_console_enabled" source="ssg"/>
            <oval-def:description>The SELinux 'login_console_enabled' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="login_console_enabled is configured correctly" test_ref="oval:ssg-test_sebool_login_console_enabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_logrotate_use_nfs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the logrotate_use_nfs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_logrotate_use_nfs" source="ssg"/>
            <oval-def:description>The SELinux 'logrotate_use_nfs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="logrotate_use_nfs is configured correctly" test_ref="oval:ssg-test_sebool_logrotate_use_nfs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_logwatch_can_network_connect_mail:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the logwatch_can_network_connect_mail SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_logwatch_can_network_connect_mail" source="ssg"/>
            <oval-def:description>The SELinux 'logwatch_can_network_connect_mail' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="logwatch_can_network_connect_mail is configured correctly" test_ref="oval:ssg-test_sebool_logwatch_can_network_connect_mail:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_lsmd_plugin_connect_any:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the lsmd_plugin_connect_any SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_lsmd_plugin_connect_any" source="ssg"/>
            <oval-def:description>The SELinux 'lsmd_plugin_connect_any' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="lsmd_plugin_connect_any is configured correctly" test_ref="oval:ssg-test_sebool_lsmd_plugin_connect_any:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mailman_use_fusefs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the mailman_use_fusefs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mailman_use_fusefs" source="ssg"/>
            <oval-def:description>The SELinux 'mailman_use_fusefs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mailman_use_fusefs is configured correctly" test_ref="oval:ssg-test_sebool_mailman_use_fusefs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mcelog_client:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the mcelog_client SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mcelog_client" source="ssg"/>
            <oval-def:description>The SELinux 'mcelog_client' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mcelog_client is configured correctly" test_ref="oval:ssg-test_sebool_mcelog_client:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mcelog_exec_scripts:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the mcelog_exec_scripts SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mcelog_exec_scripts" source="ssg"/>
            <oval-def:description>The SELinux 'mcelog_exec_scripts' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mcelog_exec_scripts is configured correctly" test_ref="oval:ssg-test_sebool_mcelog_exec_scripts:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mcelog_foreground:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the mcelog_foreground SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mcelog_foreground" source="ssg"/>
            <oval-def:description>The SELinux 'mcelog_foreground' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mcelog_foreground is configured correctly" test_ref="oval:ssg-test_sebool_mcelog_foreground:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mcelog_server:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the mcelog_server SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mcelog_server" source="ssg"/>
            <oval-def:description>The SELinux 'mcelog_server' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mcelog_server is configured correctly" test_ref="oval:ssg-test_sebool_mcelog_server:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_minidlna_read_generic_user_content:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the minidlna_read_generic_user_content SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_minidlna_read_generic_user_content" source="ssg"/>
            <oval-def:description>The SELinux 'minidlna_read_generic_user_content' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="minidlna_read_generic_user_content is configured correctly" test_ref="oval:ssg-test_sebool_minidlna_read_generic_user_content:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mmap_low_allowed:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the mmap_low_allowed SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mmap_low_allowed" source="ssg"/>
            <oval-def:description>The SELinux 'mmap_low_allowed' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mmap_low_allowed is configured correctly" test_ref="oval:ssg-test_sebool_mmap_low_allowed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mock_enable_homedirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the mock_enable_homedirs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mock_enable_homedirs" source="ssg"/>
            <oval-def:description>The SELinux 'mock_enable_homedirs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mock_enable_homedirs is configured correctly" test_ref="oval:ssg-test_sebool_mock_enable_homedirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mount_anyfile:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the mount_anyfile SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mount_anyfile" source="ssg"/>
            <oval-def:description>The SELinux 'mount_anyfile' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mount_anyfile is configured correctly" test_ref="oval:ssg-test_sebool_mount_anyfile:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mozilla_plugin_bind_unreserved_ports:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the mozilla_plugin_bind_unreserved_ports SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mozilla_plugin_bind_unreserved_ports" source="ssg"/>
            <oval-def:description>The SELinux 'mozilla_plugin_bind_unreserved_ports' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mozilla_plugin_bind_unreserved_ports is configured correctly" test_ref="oval:ssg-test_sebool_mozilla_plugin_bind_unreserved_ports:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mozilla_plugin_can_network_connect:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the mozilla_plugin_can_network_connect SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mozilla_plugin_can_network_connect" source="ssg"/>
            <oval-def:description>The SELinux 'mozilla_plugin_can_network_connect' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mozilla_plugin_can_network_connect is configured correctly" test_ref="oval:ssg-test_sebool_mozilla_plugin_can_network_connect:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mozilla_plugin_use_bluejeans:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the mozilla_plugin_use_bluejeans SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mozilla_plugin_use_bluejeans" source="ssg"/>
            <oval-def:description>The SELinux 'mozilla_plugin_use_bluejeans' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mozilla_plugin_use_bluejeans is configured correctly" test_ref="oval:ssg-test_sebool_mozilla_plugin_use_bluejeans:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mozilla_plugin_use_gps:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the mozilla_plugin_use_gps SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mozilla_plugin_use_gps" source="ssg"/>
            <oval-def:description>The SELinux 'mozilla_plugin_use_gps' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mozilla_plugin_use_gps is configured correctly" test_ref="oval:ssg-test_sebool_mozilla_plugin_use_gps:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mozilla_plugin_use_spice:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the mozilla_plugin_use_spice SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mozilla_plugin_use_spice" source="ssg"/>
            <oval-def:description>The SELinux 'mozilla_plugin_use_spice' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mozilla_plugin_use_spice is configured correctly" test_ref="oval:ssg-test_sebool_mozilla_plugin_use_spice:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mozilla_read_content:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the mozilla_read_content SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mozilla_read_content" source="ssg"/>
            <oval-def:description>The SELinux 'mozilla_read_content' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mozilla_read_content is configured correctly" test_ref="oval:ssg-test_sebool_mozilla_read_content:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mpd_enable_homedirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the mpd_enable_homedirs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mpd_enable_homedirs" source="ssg"/>
            <oval-def:description>The SELinux 'mpd_enable_homedirs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mpd_enable_homedirs is configured correctly" test_ref="oval:ssg-test_sebool_mpd_enable_homedirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mpd_use_cifs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the mpd_use_cifs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mpd_use_cifs" source="ssg"/>
            <oval-def:description>The SELinux 'mpd_use_cifs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mpd_use_cifs is configured correctly" test_ref="oval:ssg-test_sebool_mpd_use_cifs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mpd_use_nfs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the mpd_use_nfs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mpd_use_nfs" source="ssg"/>
            <oval-def:description>The SELinux 'mpd_use_nfs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mpd_use_nfs is configured correctly" test_ref="oval:ssg-test_sebool_mpd_use_nfs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mplayer_execstack:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the mplayer_execstack SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mplayer_execstack" source="ssg"/>
            <oval-def:description>The SELinux 'mplayer_execstack' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mplayer_execstack is configured correctly" test_ref="oval:ssg-test_sebool_mplayer_execstack:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_mysql_connect_any:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the mysql_connect_any SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_mysql_connect_any" source="ssg"/>
            <oval-def:description>The SELinux 'mysql_connect_any' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="mysql_connect_any is configured correctly" test_ref="oval:ssg-test_sebool_mysql_connect_any:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_nagios_run_pnp4nagios:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the nagios_run_pnp4nagios SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_nagios_run_pnp4nagios" source="ssg"/>
            <oval-def:description>The SELinux 'nagios_run_pnp4nagios' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="nagios_run_pnp4nagios is configured correctly" test_ref="oval:ssg-test_sebool_nagios_run_pnp4nagios:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_nagios_run_sudo:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the nagios_run_sudo SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_nagios_run_sudo" source="ssg"/>
            <oval-def:description>The SELinux 'nagios_run_sudo' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="nagios_run_sudo is configured correctly" test_ref="oval:ssg-test_sebool_nagios_run_sudo:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_named_tcp_bind_http_port:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the named_tcp_bind_http_port SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_named_tcp_bind_http_port" source="ssg"/>
            <oval-def:description>The SELinux 'named_tcp_bind_http_port' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="named_tcp_bind_http_port is configured correctly" test_ref="oval:ssg-test_sebool_named_tcp_bind_http_port:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_named_write_master_zones:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the named_write_master_zones SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_named_write_master_zones" source="ssg"/>
            <oval-def:description>The SELinux 'named_write_master_zones' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="named_write_master_zones is configured correctly" test_ref="oval:ssg-test_sebool_named_write_master_zones:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_neutron_can_network:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the neutron_can_network SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_neutron_can_network" source="ssg"/>
            <oval-def:description>The SELinux 'neutron_can_network' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="neutron_can_network is configured correctly" test_ref="oval:ssg-test_sebool_neutron_can_network:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_nfs_export_all_ro:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the nfs_export_all_ro SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_nfs_export_all_ro" source="ssg"/>
            <oval-def:description>The SELinux 'nfs_export_all_ro' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="nfs_export_all_ro is configured correctly" test_ref="oval:ssg-test_sebool_nfs_export_all_ro:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_nfs_export_all_rw:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the nfs_export_all_rw SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_nfs_export_all_rw" source="ssg"/>
            <oval-def:description>The SELinux 'nfs_export_all_rw' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="nfs_export_all_rw is configured correctly" test_ref="oval:ssg-test_sebool_nfs_export_all_rw:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_nfsd_anon_write:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the nfsd_anon_write SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_nfsd_anon_write" source="ssg"/>
            <oval-def:description>The SELinux 'nfsd_anon_write' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="nfsd_anon_write is configured correctly" test_ref="oval:ssg-test_sebool_nfsd_anon_write:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_nis_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the nis_enabled SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_nis_enabled" source="ssg"/>
            <oval-def:description>The SELinux 'nis_enabled' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="nis_enabled is configured correctly" test_ref="oval:ssg-test_sebool_nis_enabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_nscd_use_shm:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the nscd_use_shm SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_nscd_use_shm" source="ssg"/>
            <oval-def:description>The SELinux 'nscd_use_shm' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="nscd_use_shm is configured correctly" test_ref="oval:ssg-test_sebool_nscd_use_shm:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_openshift_use_nfs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the openshift_use_nfs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_openshift_use_nfs" source="ssg"/>
            <oval-def:description>The SELinux 'openshift_use_nfs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="openshift_use_nfs is configured correctly" test_ref="oval:ssg-test_sebool_openshift_use_nfs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_openvpn_can_network_connect:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the openvpn_can_network_connect SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_openvpn_can_network_connect" source="ssg"/>
            <oval-def:description>The SELinux 'openvpn_can_network_connect' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="openvpn_can_network_connect is configured correctly" test_ref="oval:ssg-test_sebool_openvpn_can_network_connect:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_openvpn_enable_homedirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the openvpn_enable_homedirs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_openvpn_enable_homedirs" source="ssg"/>
            <oval-def:description>The SELinux 'openvpn_enable_homedirs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="openvpn_enable_homedirs is configured correctly" test_ref="oval:ssg-test_sebool_openvpn_enable_homedirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_openvpn_run_unconfined:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the openvpn_run_unconfined SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_openvpn_run_unconfined" source="ssg"/>
            <oval-def:description>The SELinux 'openvpn_run_unconfined' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="openvpn_run_unconfined is configured correctly" test_ref="oval:ssg-test_sebool_openvpn_run_unconfined:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_pcp_bind_all_unreserved_ports:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the pcp_bind_all_unreserved_ports SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_pcp_bind_all_unreserved_ports" source="ssg"/>
            <oval-def:description>The SELinux 'pcp_bind_all_unreserved_ports' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="pcp_bind_all_unreserved_ports is configured correctly" test_ref="oval:ssg-test_sebool_pcp_bind_all_unreserved_ports:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_pcp_read_generic_logs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the pcp_read_generic_logs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_pcp_read_generic_logs" source="ssg"/>
            <oval-def:description>The SELinux 'pcp_read_generic_logs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="pcp_read_generic_logs is configured correctly" test_ref="oval:ssg-test_sebool_pcp_read_generic_logs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_piranha_lvs_can_network_connect:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the piranha_lvs_can_network_connect SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_piranha_lvs_can_network_connect" source="ssg"/>
            <oval-def:description>The SELinux 'piranha_lvs_can_network_connect' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="piranha_lvs_can_network_connect is configured correctly" test_ref="oval:ssg-test_sebool_piranha_lvs_can_network_connect:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_polipo_connect_all_unreserved:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the polipo_connect_all_unreserved SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_polipo_connect_all_unreserved" source="ssg"/>
            <oval-def:description>The SELinux 'polipo_connect_all_unreserved' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="polipo_connect_all_unreserved is configured correctly" test_ref="oval:ssg-test_sebool_polipo_connect_all_unreserved:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_polipo_session_bind_all_unreserved_ports:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the polipo_session_bind_all_unreserved_ports SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_polipo_session_bind_all_unreserved_ports" source="ssg"/>
            <oval-def:description>The SELinux 'polipo_session_bind_all_unreserved_ports' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="polipo_session_bind_all_unreserved_ports is configured correctly" test_ref="oval:ssg-test_sebool_polipo_session_bind_all_unreserved_ports:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_polipo_session_users:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the polipo_session_users SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_polipo_session_users" source="ssg"/>
            <oval-def:description>The SELinux 'polipo_session_users' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="polipo_session_users is configured correctly" test_ref="oval:ssg-test_sebool_polipo_session_users:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_polipo_use_cifs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the polipo_use_cifs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_polipo_use_cifs" source="ssg"/>
            <oval-def:description>The SELinux 'polipo_use_cifs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="polipo_use_cifs is configured correctly" test_ref="oval:ssg-test_sebool_polipo_use_cifs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_polipo_use_nfs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the polipo_use_nfs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_polipo_use_nfs" source="ssg"/>
            <oval-def:description>The SELinux 'polipo_use_nfs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="polipo_use_nfs is configured correctly" test_ref="oval:ssg-test_sebool_polipo_use_nfs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_polyinstantiation_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure the polyinstantiation_enabled SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_polyinstantiation_enabled" source="ssg"/>
            <oval-def:description>The SELinux 'polyinstantiation_enabled' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="polyinstantiation_enabled is configured correctly" test_ref="oval:ssg-test_sebool_polyinstantiation_enabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_postfix_local_write_mail_spool:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the postfix_local_write_mail_spool SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_postfix_local_write_mail_spool" source="ssg"/>
            <oval-def:description>The SELinux 'postfix_local_write_mail_spool' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="postfix_local_write_mail_spool is configured correctly" test_ref="oval:ssg-test_sebool_postfix_local_write_mail_spool:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_postgresql_can_rsync:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the postgresql_can_rsync SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_postgresql_can_rsync" source="ssg"/>
            <oval-def:description>The SELinux 'postgresql_can_rsync' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="postgresql_can_rsync is configured correctly" test_ref="oval:ssg-test_sebool_postgresql_can_rsync:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_postgresql_selinux_transmit_client_label:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the postgresql_selinux_transmit_client_label SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_postgresql_selinux_transmit_client_label" source="ssg"/>
            <oval-def:description>The SELinux 'postgresql_selinux_transmit_client_label' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="postgresql_selinux_transmit_client_label is configured correctly" test_ref="oval:ssg-test_sebool_postgresql_selinux_transmit_client_label:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_postgresql_selinux_unconfined_dbadm:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the postgresql_selinux_unconfined_dbadm SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_postgresql_selinux_unconfined_dbadm" source="ssg"/>
            <oval-def:description>The SELinux 'postgresql_selinux_unconfined_dbadm' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="postgresql_selinux_unconfined_dbadm is configured correctly" test_ref="oval:ssg-test_sebool_postgresql_selinux_unconfined_dbadm:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_postgresql_selinux_users_ddl:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the postgresql_selinux_users_ddl SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_postgresql_selinux_users_ddl" source="ssg"/>
            <oval-def:description>The SELinux 'postgresql_selinux_users_ddl' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="postgresql_selinux_users_ddl is configured correctly" test_ref="oval:ssg-test_sebool_postgresql_selinux_users_ddl:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_pppd_can_insmod:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the pppd_can_insmod SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_pppd_can_insmod" source="ssg"/>
            <oval-def:description>The SELinux 'pppd_can_insmod' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="pppd_can_insmod is configured correctly" test_ref="oval:ssg-test_sebool_pppd_can_insmod:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_pppd_for_user:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the pppd_for_user SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_pppd_for_user" source="ssg"/>
            <oval-def:description>The SELinux 'pppd_for_user' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="pppd_for_user is configured correctly" test_ref="oval:ssg-test_sebool_pppd_for_user:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_privoxy_connect_any:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the privoxy_connect_any SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_privoxy_connect_any" source="ssg"/>
            <oval-def:description>The SELinux 'privoxy_connect_any' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="privoxy_connect_any is configured correctly" test_ref="oval:ssg-test_sebool_privoxy_connect_any:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_prosody_bind_http_port:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the prosody_bind_http_port SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_prosody_bind_http_port" source="ssg"/>
            <oval-def:description>The SELinux 'prosody_bind_http_port' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="prosody_bind_http_port is configured correctly" test_ref="oval:ssg-test_sebool_prosody_bind_http_port:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_puppetagent_manage_all_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the puppetagent_manage_all_files SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_puppetagent_manage_all_files" source="ssg"/>
            <oval-def:description>The SELinux 'puppetagent_manage_all_files' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="puppetagent_manage_all_files is configured correctly" test_ref="oval:ssg-test_sebool_puppetagent_manage_all_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_puppetmaster_use_db:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the puppetmaster_use_db SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_puppetmaster_use_db" source="ssg"/>
            <oval-def:description>The SELinux 'puppetmaster_use_db' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="puppetmaster_use_db is configured correctly" test_ref="oval:ssg-test_sebool_puppetmaster_use_db:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_racoon_read_shadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the racoon_read_shadow SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_racoon_read_shadow" source="ssg"/>
            <oval-def:description>The SELinux 'racoon_read_shadow' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="racoon_read_shadow is configured correctly" test_ref="oval:ssg-test_sebool_racoon_read_shadow:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_rsync_anon_write:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the rsync_anon_write SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_rsync_anon_write" source="ssg"/>
            <oval-def:description>The SELinux 'rsync_anon_write' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="rsync_anon_write is configured correctly" test_ref="oval:ssg-test_sebool_rsync_anon_write:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_rsync_client:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the rsync_client SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_rsync_client" source="ssg"/>
            <oval-def:description>The SELinux 'rsync_client' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="rsync_client is configured correctly" test_ref="oval:ssg-test_sebool_rsync_client:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_rsync_export_all_ro:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the rsync_export_all_ro SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_rsync_export_all_ro" source="ssg"/>
            <oval-def:description>The SELinux 'rsync_export_all_ro' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="rsync_export_all_ro is configured correctly" test_ref="oval:ssg-test_sebool_rsync_export_all_ro:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_rsync_full_access:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the rsync_full_access SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_rsync_full_access" source="ssg"/>
            <oval-def:description>The SELinux 'rsync_full_access' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="rsync_full_access is configured correctly" test_ref="oval:ssg-test_sebool_rsync_full_access:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_samba_create_home_dirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the samba_create_home_dirs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_samba_create_home_dirs" source="ssg"/>
            <oval-def:description>The SELinux 'samba_create_home_dirs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="samba_create_home_dirs is configured correctly" test_ref="oval:ssg-test_sebool_samba_create_home_dirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_samba_domain_controller:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the samba_domain_controller SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_samba_domain_controller" source="ssg"/>
            <oval-def:description>The SELinux 'samba_domain_controller' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="samba_domain_controller is configured correctly" test_ref="oval:ssg-test_sebool_samba_domain_controller:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_samba_enable_home_dirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the samba_enable_home_dirs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_samba_enable_home_dirs" source="ssg"/>
            <oval-def:description>The SELinux 'samba_enable_home_dirs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="samba_enable_home_dirs is configured correctly" test_ref="oval:ssg-test_sebool_samba_enable_home_dirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_samba_export_all_ro:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the samba_export_all_ro SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_samba_export_all_ro" source="ssg"/>
            <oval-def:description>The SELinux 'samba_export_all_ro' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="samba_export_all_ro is configured correctly" test_ref="oval:ssg-test_sebool_samba_export_all_ro:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_samba_export_all_rw:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the samba_export_all_rw SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_samba_export_all_rw" source="ssg"/>
            <oval-def:description>The SELinux 'samba_export_all_rw' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="samba_export_all_rw is configured correctly" test_ref="oval:ssg-test_sebool_samba_export_all_rw:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_samba_load_libgfapi:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the samba_load_libgfapi SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_samba_load_libgfapi" source="ssg"/>
            <oval-def:description>The SELinux 'samba_load_libgfapi' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="samba_load_libgfapi is configured correctly" test_ref="oval:ssg-test_sebool_samba_load_libgfapi:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_samba_portmapper:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the samba_portmapper SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_samba_portmapper" source="ssg"/>
            <oval-def:description>The SELinux 'samba_portmapper' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="samba_portmapper is configured correctly" test_ref="oval:ssg-test_sebool_samba_portmapper:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_samba_run_unconfined:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the samba_run_unconfined SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_samba_run_unconfined" source="ssg"/>
            <oval-def:description>The SELinux 'samba_run_unconfined' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="samba_run_unconfined is configured correctly" test_ref="oval:ssg-test_sebool_samba_run_unconfined:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_samba_share_fusefs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the samba_share_fusefs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_samba_share_fusefs" source="ssg"/>
            <oval-def:description>The SELinux 'samba_share_fusefs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="samba_share_fusefs is configured correctly" test_ref="oval:ssg-test_sebool_samba_share_fusefs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_samba_share_nfs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the samba_share_nfs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_samba_share_nfs" source="ssg"/>
            <oval-def:description>The SELinux 'samba_share_nfs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="samba_share_nfs is configured correctly" test_ref="oval:ssg-test_sebool_samba_share_nfs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_sanlock_use_fusefs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the sanlock_use_fusefs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_sanlock_use_fusefs" source="ssg"/>
            <oval-def:description>The SELinux 'sanlock_use_fusefs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="sanlock_use_fusefs is configured correctly" test_ref="oval:ssg-test_sebool_sanlock_use_fusefs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_sanlock_use_nfs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the sanlock_use_nfs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_sanlock_use_nfs" source="ssg"/>
            <oval-def:description>The SELinux 'sanlock_use_nfs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="sanlock_use_nfs is configured correctly" test_ref="oval:ssg-test_sebool_sanlock_use_nfs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_sanlock_use_samba:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the sanlock_use_samba SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_sanlock_use_samba" source="ssg"/>
            <oval-def:description>The SELinux 'sanlock_use_samba' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="sanlock_use_samba is configured correctly" test_ref="oval:ssg-test_sebool_sanlock_use_samba:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_saslauthd_read_shadow:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the saslauthd_read_shadow SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_saslauthd_read_shadow" source="ssg"/>
            <oval-def:description>The SELinux 'saslauthd_read_shadow' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="saslauthd_read_shadow is configured correctly" test_ref="oval:ssg-test_sebool_saslauthd_read_shadow:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_secadm_exec_content:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the secadm_exec_content SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_secadm_exec_content" source="ssg"/>
            <oval-def:description>The SELinux 'secadm_exec_content' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="secadm_exec_content is configured correctly" test_ref="oval:ssg-test_sebool_secadm_exec_content:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_secure_mode:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the secure_mode SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_secure_mode" source="ssg"/>
            <oval-def:description>The SELinux 'secure_mode' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="secure_mode is configured correctly" test_ref="oval:ssg-test_sebool_secure_mode:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_secure_mode_insmod:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure the secure_mode_insmod SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_secure_mode_insmod" source="ssg"/>
            <oval-def:description>The SELinux 'secure_mode_insmod' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="secure_mode_insmod is configured correctly" test_ref="oval:ssg-test_sebool_secure_mode_insmod:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_secure_mode_policyload:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the secure_mode_policyload SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_secure_mode_policyload" source="ssg"/>
            <oval-def:description>The SELinux 'secure_mode_policyload' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="secure_mode_policyload is configured correctly" test_ref="oval:ssg-test_sebool_secure_mode_policyload:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_selinuxuser_direct_dri_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure the selinuxuser_direct_dri_enabled SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_selinuxuser_direct_dri_enabled" source="ssg"/>
            <oval-def:description>The SELinux 'selinuxuser_direct_dri_enabled' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="selinuxuser_direct_dri_enabled is configured correctly" test_ref="oval:ssg-test_sebool_selinuxuser_direct_dri_enabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_selinuxuser_execheap:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the selinuxuser_execheap SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_selinuxuser_execheap" source="ssg"/>
            <oval-def:description>The SELinux 'selinuxuser_execheap' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="selinuxuser_execheap is configured correctly" test_ref="oval:ssg-test_sebool_selinuxuser_execheap:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_selinuxuser_execmod:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the selinuxuser_execmod SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_selinuxuser_execmod" source="ssg"/>
            <oval-def:description>The SELinux 'selinuxuser_execmod' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="selinuxuser_execmod is configured correctly" test_ref="oval:ssg-test_sebool_selinuxuser_execmod:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_selinuxuser_execstack:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the selinuxuser_execstack SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_selinuxuser_execstack" source="ssg"/>
            <oval-def:description>The SELinux 'selinuxuser_execstack' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="selinuxuser_execstack is configured correctly" test_ref="oval:ssg-test_sebool_selinuxuser_execstack:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_selinuxuser_mysql_connect_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the selinuxuser_mysql_connect_enabled SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_selinuxuser_mysql_connect_enabled" source="ssg"/>
            <oval-def:description>The SELinux 'selinuxuser_mysql_connect_enabled' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="selinuxuser_mysql_connect_enabled is configured correctly" test_ref="oval:ssg-test_sebool_selinuxuser_mysql_connect_enabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_selinuxuser_ping:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the selinuxuser_ping SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_selinuxuser_ping" source="ssg"/>
            <oval-def:description>The SELinux 'selinuxuser_ping' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="selinuxuser_ping is configured correctly" test_ref="oval:ssg-test_sebool_selinuxuser_ping:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_selinuxuser_postgresql_connect_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the selinuxuser_postgresql_connect_enabled SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_selinuxuser_postgresql_connect_enabled" source="ssg"/>
            <oval-def:description>The SELinux 'selinuxuser_postgresql_connect_enabled' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="selinuxuser_postgresql_connect_enabled is configured correctly" test_ref="oval:ssg-test_sebool_selinuxuser_postgresql_connect_enabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_selinuxuser_rw_noexattrfile:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the selinuxuser_rw_noexattrfile SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_selinuxuser_rw_noexattrfile" source="ssg"/>
            <oval-def:description>The SELinux 'selinuxuser_rw_noexattrfile' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="selinuxuser_rw_noexattrfile is configured correctly" test_ref="oval:ssg-test_sebool_selinuxuser_rw_noexattrfile:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_selinuxuser_share_music:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the selinuxuser_share_music SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_selinuxuser_share_music" source="ssg"/>
            <oval-def:description>The SELinux 'selinuxuser_share_music' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="selinuxuser_share_music is configured correctly" test_ref="oval:ssg-test_sebool_selinuxuser_share_music:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_selinuxuser_tcp_server:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the selinuxuser_tcp_server SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_selinuxuser_tcp_server" source="ssg"/>
            <oval-def:description>The SELinux 'selinuxuser_tcp_server' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="selinuxuser_tcp_server is configured correctly" test_ref="oval:ssg-test_sebool_selinuxuser_tcp_server:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_selinuxuser_udp_server:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the selinuxuser_udp_server SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_selinuxuser_udp_server" source="ssg"/>
            <oval-def:description>The SELinux 'selinuxuser_udp_server' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="selinuxuser_udp_server is configured correctly" test_ref="oval:ssg-test_sebool_selinuxuser_udp_server:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_selinuxuser_use_ssh_chroot:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the selinuxuser_use_ssh_chroot SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_selinuxuser_use_ssh_chroot" source="ssg"/>
            <oval-def:description>The SELinux 'selinuxuser_use_ssh_chroot' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="selinuxuser_use_ssh_chroot is configured correctly" test_ref="oval:ssg-test_sebool_selinuxuser_use_ssh_chroot:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_sge_domain_can_network_connect:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the sge_domain_can_network_connect SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_sge_domain_can_network_connect" source="ssg"/>
            <oval-def:description>The SELinux 'sge_domain_can_network_connect' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="sge_domain_can_network_connect is configured correctly" test_ref="oval:ssg-test_sebool_sge_domain_can_network_connect:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_sge_use_nfs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the sge_use_nfs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_sge_use_nfs" source="ssg"/>
            <oval-def:description>The SELinux 'sge_use_nfs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="sge_use_nfs is configured correctly" test_ref="oval:ssg-test_sebool_sge_use_nfs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_smartmon_3ware:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the smartmon_3ware SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_smartmon_3ware" source="ssg"/>
            <oval-def:description>The SELinux 'smartmon_3ware' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="smartmon_3ware is configured correctly" test_ref="oval:ssg-test_sebool_smartmon_3ware:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_smbd_anon_write:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the smbd_anon_write SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_smbd_anon_write" source="ssg"/>
            <oval-def:description>The SELinux 'smbd_anon_write' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="smbd_anon_write is configured correctly" test_ref="oval:ssg-test_sebool_smbd_anon_write:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_spamassassin_can_network:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the spamassassin_can_network SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_spamassassin_can_network" source="ssg"/>
            <oval-def:description>The SELinux 'spamassassin_can_network' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="spamassassin_can_network is configured correctly" test_ref="oval:ssg-test_sebool_spamassassin_can_network:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_spamd_enable_home_dirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the spamd_enable_home_dirs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_spamd_enable_home_dirs" source="ssg"/>
            <oval-def:description>The SELinux 'spamd_enable_home_dirs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="spamd_enable_home_dirs is configured correctly" test_ref="oval:ssg-test_sebool_spamd_enable_home_dirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_squid_connect_any:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the squid_connect_any SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_squid_connect_any" source="ssg"/>
            <oval-def:description>The SELinux 'squid_connect_any' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="squid_connect_any is configured correctly" test_ref="oval:ssg-test_sebool_squid_connect_any:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_squid_use_tproxy:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the squid_use_tproxy SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_squid_use_tproxy" source="ssg"/>
            <oval-def:description>The SELinux 'squid_use_tproxy' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="squid_use_tproxy is configured correctly" test_ref="oval:ssg-test_sebool_squid_use_tproxy:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_ssh_chroot_rw_homedirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the ssh_chroot_rw_homedirs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_ssh_chroot_rw_homedirs" source="ssg"/>
            <oval-def:description>The SELinux 'ssh_chroot_rw_homedirs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="ssh_chroot_rw_homedirs is configured correctly" test_ref="oval:ssg-test_sebool_ssh_chroot_rw_homedirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_ssh_keysign:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the ssh_keysign SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_ssh_keysign" source="ssg"/>
            <oval-def:description>The SELinux 'ssh_keysign' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="ssh_keysign is configured correctly" test_ref="oval:ssg-test_sebool_ssh_keysign:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_ssh_sysadm_login:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the ssh_sysadm_login SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_ssh_sysadm_login" source="ssg"/>
            <oval-def:description>The SELinux 'ssh_sysadm_login' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="ssh_sysadm_login is configured correctly" test_ref="oval:ssg-test_sebool_ssh_sysadm_login:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_staff_exec_content:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the staff_exec_content SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_staff_exec_content" source="ssg"/>
            <oval-def:description>The SELinux 'staff_exec_content' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="staff_exec_content is configured correctly" test_ref="oval:ssg-test_sebool_staff_exec_content:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_staff_use_svirt:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the staff_use_svirt SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_staff_use_svirt" source="ssg"/>
            <oval-def:description>The SELinux 'staff_use_svirt' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="staff_use_svirt is configured correctly" test_ref="oval:ssg-test_sebool_staff_use_svirt:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_swift_can_network:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the swift_can_network SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_swift_can_network" source="ssg"/>
            <oval-def:description>The SELinux 'swift_can_network' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="swift_can_network is configured correctly" test_ref="oval:ssg-test_sebool_swift_can_network:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_sysadm_exec_content:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the sysadm_exec_content SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_sysadm_exec_content" source="ssg"/>
            <oval-def:description>The SELinux 'sysadm_exec_content' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="sysadm_exec_content is configured correctly" test_ref="oval:ssg-test_sebool_sysadm_exec_content:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_telepathy_connect_all_ports:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the telepathy_connect_all_ports SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_telepathy_connect_all_ports" source="ssg"/>
            <oval-def:description>The SELinux 'telepathy_connect_all_ports' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="telepathy_connect_all_ports is configured correctly" test_ref="oval:ssg-test_sebool_telepathy_connect_all_ports:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_telepathy_tcp_connect_generic_network_ports:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the telepathy_tcp_connect_generic_network_ports SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_telepathy_tcp_connect_generic_network_ports" source="ssg"/>
            <oval-def:description>The SELinux 'telepathy_tcp_connect_generic_network_ports' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="telepathy_tcp_connect_generic_network_ports is configured correctly" test_ref="oval:ssg-test_sebool_telepathy_tcp_connect_generic_network_ports:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_tftp_anon_write:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the tftp_anon_write SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_tftp_anon_write" source="ssg"/>
            <oval-def:description>The SELinux 'tftp_anon_write' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="tftp_anon_write is configured correctly" test_ref="oval:ssg-test_sebool_tftp_anon_write:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_tftp_home_dir:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the tftp_home_dir SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_tftp_home_dir" source="ssg"/>
            <oval-def:description>The SELinux 'tftp_home_dir' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="tftp_home_dir is configured correctly" test_ref="oval:ssg-test_sebool_tftp_home_dir:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_tmpreaper_use_nfs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the tmpreaper_use_nfs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_tmpreaper_use_nfs" source="ssg"/>
            <oval-def:description>The SELinux 'tmpreaper_use_nfs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="tmpreaper_use_nfs is configured correctly" test_ref="oval:ssg-test_sebool_tmpreaper_use_nfs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_tmpreaper_use_samba:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the tmpreaper_use_samba SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_tmpreaper_use_samba" source="ssg"/>
            <oval-def:description>The SELinux 'tmpreaper_use_samba' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="tmpreaper_use_samba is configured correctly" test_ref="oval:ssg-test_sebool_tmpreaper_use_samba:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_tor_bind_all_unreserved_ports:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the tor_bind_all_unreserved_ports SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_tor_bind_all_unreserved_ports" source="ssg"/>
            <oval-def:description>The SELinux 'tor_bind_all_unreserved_ports' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="tor_bind_all_unreserved_ports is configured correctly" test_ref="oval:ssg-test_sebool_tor_bind_all_unreserved_ports:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_tor_can_network_relay:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the tor_can_network_relay SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_tor_can_network_relay" source="ssg"/>
            <oval-def:description>The SELinux 'tor_can_network_relay' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="tor_can_network_relay is configured correctly" test_ref="oval:ssg-test_sebool_tor_can_network_relay:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_unconfined_chrome_sandbox_transition:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the unconfined_chrome_sandbox_transition SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_unconfined_chrome_sandbox_transition" source="ssg"/>
            <oval-def:description>The SELinux 'unconfined_chrome_sandbox_transition' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="unconfined_chrome_sandbox_transition is configured correctly" test_ref="oval:ssg-test_sebool_unconfined_chrome_sandbox_transition:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_unconfined_login:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the unconfined_login SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_unconfined_login" source="ssg"/>
            <oval-def:description>The SELinux 'unconfined_login' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="unconfined_login is configured correctly" test_ref="oval:ssg-test_sebool_unconfined_login:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_unconfined_mozilla_plugin_transition:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the unconfined_mozilla_plugin_transition SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_unconfined_mozilla_plugin_transition" source="ssg"/>
            <oval-def:description>The SELinux 'unconfined_mozilla_plugin_transition' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="unconfined_mozilla_plugin_transition is configured correctly" test_ref="oval:ssg-test_sebool_unconfined_mozilla_plugin_transition:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_unprivuser_use_svirt:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the unprivuser_use_svirt SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_unprivuser_use_svirt" source="ssg"/>
            <oval-def:description>The SELinux 'unprivuser_use_svirt' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="unprivuser_use_svirt is configured correctly" test_ref="oval:ssg-test_sebool_unprivuser_use_svirt:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_use_ecryptfs_home_dirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the use_ecryptfs_home_dirs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_use_ecryptfs_home_dirs" source="ssg"/>
            <oval-def:description>The SELinux 'use_ecryptfs_home_dirs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="use_ecryptfs_home_dirs is configured correctly" test_ref="oval:ssg-test_sebool_use_ecryptfs_home_dirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_use_fusefs_home_dirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the use_fusefs_home_dirs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_use_fusefs_home_dirs" source="ssg"/>
            <oval-def:description>The SELinux 'use_fusefs_home_dirs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="use_fusefs_home_dirs is configured correctly" test_ref="oval:ssg-test_sebool_use_fusefs_home_dirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_use_lpd_server:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the use_lpd_server SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_use_lpd_server" source="ssg"/>
            <oval-def:description>The SELinux 'use_lpd_server' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="use_lpd_server is configured correctly" test_ref="oval:ssg-test_sebool_use_lpd_server:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_use_nfs_home_dirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the use_nfs_home_dirs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_use_nfs_home_dirs" source="ssg"/>
            <oval-def:description>The SELinux 'use_nfs_home_dirs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="use_nfs_home_dirs is configured correctly" test_ref="oval:ssg-test_sebool_use_nfs_home_dirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_use_samba_home_dirs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the use_samba_home_dirs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_use_samba_home_dirs" source="ssg"/>
            <oval-def:description>The SELinux 'use_samba_home_dirs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="use_samba_home_dirs is configured correctly" test_ref="oval:ssg-test_sebool_use_samba_home_dirs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_user_exec_content:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the user_exec_content SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_user_exec_content" source="ssg"/>
            <oval-def:description>The SELinux 'user_exec_content' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="user_exec_content is configured correctly" test_ref="oval:ssg-test_sebool_user_exec_content:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_varnishd_connect_any:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the varnishd_connect_any SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_varnishd_connect_any" source="ssg"/>
            <oval-def:description>The SELinux 'varnishd_connect_any' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="varnishd_connect_any is configured correctly" test_ref="oval:ssg-test_sebool_varnishd_connect_any:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_virt_read_qemu_ga_data:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the virt_read_qemu_ga_data SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_virt_read_qemu_ga_data" source="ssg"/>
            <oval-def:description>The SELinux 'virt_read_qemu_ga_data' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virt_read_qemu_ga_data is configured correctly" test_ref="oval:ssg-test_sebool_virt_read_qemu_ga_data:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_virt_rw_qemu_ga_data:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the virt_rw_qemu_ga_data SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_virt_rw_qemu_ga_data" source="ssg"/>
            <oval-def:description>The SELinux 'virt_rw_qemu_ga_data' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virt_rw_qemu_ga_data is configured correctly" test_ref="oval:ssg-test_sebool_virt_rw_qemu_ga_data:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_virt_sandbox_use_all_caps:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the virt_sandbox_use_all_caps SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_virt_sandbox_use_all_caps" source="ssg"/>
            <oval-def:description>The SELinux 'virt_sandbox_use_all_caps' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virt_sandbox_use_all_caps is configured correctly" test_ref="oval:ssg-test_sebool_virt_sandbox_use_all_caps:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_virt_sandbox_use_audit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the virt_sandbox_use_audit SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_virt_sandbox_use_audit" source="ssg"/>
            <oval-def:description>The SELinux 'virt_sandbox_use_audit' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virt_sandbox_use_audit is configured correctly" test_ref="oval:ssg-test_sebool_virt_sandbox_use_audit:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_virt_sandbox_use_mknod:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the virt_sandbox_use_mknod SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_virt_sandbox_use_mknod" source="ssg"/>
            <oval-def:description>The SELinux 'virt_sandbox_use_mknod' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virt_sandbox_use_mknod is configured correctly" test_ref="oval:ssg-test_sebool_virt_sandbox_use_mknod:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_virt_sandbox_use_netlink:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the virt_sandbox_use_netlink SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_virt_sandbox_use_netlink" source="ssg"/>
            <oval-def:description>The SELinux 'virt_sandbox_use_netlink' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virt_sandbox_use_netlink is configured correctly" test_ref="oval:ssg-test_sebool_virt_sandbox_use_netlink:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_virt_sandbox_use_sys_admin:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the virt_sandbox_use_sys_admin SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_virt_sandbox_use_sys_admin" source="ssg"/>
            <oval-def:description>The SELinux 'virt_sandbox_use_sys_admin' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virt_sandbox_use_sys_admin is configured correctly" test_ref="oval:ssg-test_sebool_virt_sandbox_use_sys_admin:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_virt_transition_userdomain:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the virt_transition_userdomain SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_virt_transition_userdomain" source="ssg"/>
            <oval-def:description>The SELinux 'virt_transition_userdomain' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virt_transition_userdomain is configured correctly" test_ref="oval:ssg-test_sebool_virt_transition_userdomain:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_virt_use_comm:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the virt_use_comm SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_virt_use_comm" source="ssg"/>
            <oval-def:description>The SELinux 'virt_use_comm' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virt_use_comm is configured correctly" test_ref="oval:ssg-test_sebool_virt_use_comm:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_virt_use_execmem:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the virt_use_execmem SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_virt_use_execmem" source="ssg"/>
            <oval-def:description>The SELinux 'virt_use_execmem' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virt_use_execmem is configured correctly" test_ref="oval:ssg-test_sebool_virt_use_execmem:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_virt_use_fusefs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the virt_use_fusefs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_virt_use_fusefs" source="ssg"/>
            <oval-def:description>The SELinux 'virt_use_fusefs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virt_use_fusefs is configured correctly" test_ref="oval:ssg-test_sebool_virt_use_fusefs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_virt_use_nfs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the virt_use_nfs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_virt_use_nfs" source="ssg"/>
            <oval-def:description>The SELinux 'virt_use_nfs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virt_use_nfs is configured correctly" test_ref="oval:ssg-test_sebool_virt_use_nfs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_virt_use_rawip:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the virt_use_rawip SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_virt_use_rawip" source="ssg"/>
            <oval-def:description>The SELinux 'virt_use_rawip' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virt_use_rawip is configured correctly" test_ref="oval:ssg-test_sebool_virt_use_rawip:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_virt_use_samba:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the virt_use_samba SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_virt_use_samba" source="ssg"/>
            <oval-def:description>The SELinux 'virt_use_samba' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virt_use_samba is configured correctly" test_ref="oval:ssg-test_sebool_virt_use_samba:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_virt_use_sanlock:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the virt_use_sanlock SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_virt_use_sanlock" source="ssg"/>
            <oval-def:description>The SELinux 'virt_use_sanlock' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virt_use_sanlock is configured correctly" test_ref="oval:ssg-test_sebool_virt_use_sanlock:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_virt_use_usb:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the virt_use_usb SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_virt_use_usb" source="ssg"/>
            <oval-def:description>The SELinux 'virt_use_usb' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virt_use_usb is configured correctly" test_ref="oval:ssg-test_sebool_virt_use_usb:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_virt_use_xserver:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the virt_use_xserver SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_virt_use_xserver" source="ssg"/>
            <oval-def:description>The SELinux 'virt_use_xserver' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="virt_use_xserver is configured correctly" test_ref="oval:ssg-test_sebool_virt_use_xserver:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_webadm_manage_user_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the webadm_manage_user_files SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_webadm_manage_user_files" source="ssg"/>
            <oval-def:description>The SELinux 'webadm_manage_user_files' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="webadm_manage_user_files is configured correctly" test_ref="oval:ssg-test_sebool_webadm_manage_user_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_webadm_read_user_files:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the webadm_read_user_files SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_webadm_read_user_files" source="ssg"/>
            <oval-def:description>The SELinux 'webadm_read_user_files' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="webadm_read_user_files is configured correctly" test_ref="oval:ssg-test_sebool_webadm_read_user_files:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_wine_mmap_zero_ignore:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the wine_mmap_zero_ignore SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_wine_mmap_zero_ignore" source="ssg"/>
            <oval-def:description>The SELinux 'wine_mmap_zero_ignore' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="wine_mmap_zero_ignore is configured correctly" test_ref="oval:ssg-test_sebool_wine_mmap_zero_ignore:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_xdm_bind_vnc_tcp_port:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the xdm_bind_vnc_tcp_port SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_xdm_bind_vnc_tcp_port" source="ssg"/>
            <oval-def:description>The SELinux 'xdm_bind_vnc_tcp_port' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="xdm_bind_vnc_tcp_port is configured correctly" test_ref="oval:ssg-test_sebool_xdm_bind_vnc_tcp_port:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_xdm_exec_bootloader:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the xdm_exec_bootloader SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_xdm_exec_bootloader" source="ssg"/>
            <oval-def:description>The SELinux 'xdm_exec_bootloader' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="xdm_exec_bootloader is configured correctly" test_ref="oval:ssg-test_sebool_xdm_exec_bootloader:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_xdm_sysadm_login:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the xdm_sysadm_login SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_xdm_sysadm_login" source="ssg"/>
            <oval-def:description>The SELinux 'xdm_sysadm_login' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="xdm_sysadm_login is configured correctly" test_ref="oval:ssg-test_sebool_xdm_sysadm_login:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_xdm_write_home:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the xdm_write_home SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_xdm_write_home" source="ssg"/>
            <oval-def:description>The SELinux 'xdm_write_home' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="xdm_write_home is configured correctly" test_ref="oval:ssg-test_sebool_xdm_write_home:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_xen_use_nfs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the xen_use_nfs SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_xen_use_nfs" source="ssg"/>
            <oval-def:description>The SELinux 'xen_use_nfs' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="xen_use_nfs is configured correctly" test_ref="oval:ssg-test_sebool_xen_use_nfs:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_xend_run_blktap:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the xend_run_blktap SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_xend_run_blktap" source="ssg"/>
            <oval-def:description>The SELinux 'xend_run_blktap' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="xend_run_blktap is configured correctly" test_ref="oval:ssg-test_sebool_xend_run_blktap:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_xend_run_qemu:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the xend_run_qemu SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_xend_run_qemu" source="ssg"/>
            <oval-def:description>The SELinux 'xend_run_qemu' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="xend_run_qemu is configured correctly" test_ref="oval:ssg-test_sebool_xend_run_qemu:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_xguest_connect_network:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the xguest_connect_network SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_xguest_connect_network" source="ssg"/>
            <oval-def:description>The SELinux 'xguest_connect_network' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="xguest_connect_network is configured correctly" test_ref="oval:ssg-test_sebool_xguest_connect_network:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_xguest_exec_content:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the xguest_exec_content SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_xguest_exec_content" source="ssg"/>
            <oval-def:description>The SELinux 'xguest_exec_content' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="xguest_exec_content is configured correctly" test_ref="oval:ssg-test_sebool_xguest_exec_content:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_xguest_mount_media:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the xguest_mount_media SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_xguest_mount_media" source="ssg"/>
            <oval-def:description>The SELinux 'xguest_mount_media' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="xguest_mount_media is configured correctly" test_ref="oval:ssg-test_sebool_xguest_mount_media:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_xguest_use_bluetooth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the xguest_use_bluetooth SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_xguest_use_bluetooth" source="ssg"/>
            <oval-def:description>The SELinux 'xguest_use_bluetooth' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="xguest_use_bluetooth is configured correctly" test_ref="oval:ssg-test_sebool_xguest_use_bluetooth:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_xserver_clients_write_xshm:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the xserver_clients_write_xshm SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_xserver_clients_write_xshm" source="ssg"/>
            <oval-def:description>The SELinux 'xserver_clients_write_xshm' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="xserver_clients_write_xshm is configured correctly" test_ref="oval:ssg-test_sebool_xserver_clients_write_xshm:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_xserver_execmem:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the xserver_execmem SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_xserver_execmem" source="ssg"/>
            <oval-def:description>The SELinux 'xserver_execmem' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="xserver_execmem is configured correctly" test_ref="oval:ssg-test_sebool_xserver_execmem:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_xserver_object_manager:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the xserver_object_manager SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_xserver_object_manager" source="ssg"/>
            <oval-def:description>The SELinux 'xserver_object_manager' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="xserver_object_manager is configured correctly" test_ref="oval:ssg-test_sebool_xserver_object_manager:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_zabbix_can_network:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the zabbix_can_network SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_zabbix_can_network" source="ssg"/>
            <oval-def:description>The SELinux 'zabbix_can_network' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="zabbix_can_network is configured correctly" test_ref="oval:ssg-test_sebool_zabbix_can_network:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_zarafa_setrlimit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the zarafa_setrlimit SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_zarafa_setrlimit" source="ssg"/>
            <oval-def:description>The SELinux 'zarafa_setrlimit' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="zarafa_setrlimit is configured correctly" test_ref="oval:ssg-test_sebool_zarafa_setrlimit:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_zebra_write_config:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the zebra_write_config SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_zebra_write_config" source="ssg"/>
            <oval-def:description>The SELinux 'zebra_write_config' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="zebra_write_config is configured correctly" test_ref="oval:ssg-test_sebool_zebra_write_config:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_zoneminder_anon_write:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the zoneminder_anon_write SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_zoneminder_anon_write" source="ssg"/>
            <oval-def:description>The SELinux 'zoneminder_anon_write' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="zoneminder_anon_write is configured correctly" test_ref="oval:ssg-test_sebool_zoneminder_anon_write:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sebool_zoneminder_run_sudo:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the zoneminder_run_sudo SELinux Boolean</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sebool_zoneminder_run_sudo" source="ssg"/>
            <oval-def:description>The SELinux 'zoneminder_run_sudo' boolean should be set in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="zoneminder_run_sudo is configured correctly" test_ref="oval:ssg-test_sebool_zoneminder_run_sudo:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-selinux_policytype:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Configure SELinux Policy</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="selinux_policytype" source="ssg"/>
            <oval-def:description>Ensure 'SELINUXTYPE' is configured with value configured through XCCDF variable var_selinux_policy_name' in /etc/selinux/config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="selinux is configured correctly and configuration file exists" operator="AND">
            <oval-def:criteria comment="selinux is configured correctly" operator="OR">
              <oval-def:criterion comment="Check the SELINUXTYPE in /etc/selinux/config" test_ref="oval:ssg-test_selinux_policytype:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="test if configuration file /etc/selinux/config exists for selinux_policytype" test_ref="oval:ssg-test_selinux_policytype_config_file_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_abrtd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Automatic Bug Reporting Tool (abrtd)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_abrtd_disabled" source="ssg"/>
            <oval-def:description>The abrtd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package abrt removed or service abrtd is not configured to start" operator="OR">
            <oval-def:criterion comment="abrt removed" test_ref="oval:ssg-service_abrtd_disabled_test_service_abrtd_package_abrt_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service abrtd is not configured to start" operator="AND">
                <oval-def:criterion comment="abrtd is not running" test_ref="oval:ssg-test_service_not_running_service_abrtd_disabled_abrtd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service abrtd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_abrtd_disabled_abrtd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="abrtd is not found" test_ref="oval:ssg-test_service_not_found_service_abrtd_disabled_abrtd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_acpid_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Advanced Configuration and Power Interface (acpid)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_acpid_disabled" source="ssg"/>
            <oval-def:description>The acpid service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package acpid removed or service acpid is not configured to start" operator="OR">
            <oval-def:criterion comment="acpid removed" test_ref="oval:ssg-service_acpid_disabled_test_service_acpid_package_acpid_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service acpid is not configured to start" operator="AND">
                <oval-def:criterion comment="acpid is not running" test_ref="oval:ssg-test_service_not_running_service_acpid_disabled_acpid:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service acpid is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_acpid_disabled_acpid:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="acpid is not found" test_ref="oval:ssg-test_service_not_found_service_acpid_disabled_acpid:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_atd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable At Service (atd)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_atd_disabled" source="ssg"/>
            <oval-def:description>The atd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package at removed or service atd is not configured to start" operator="OR">
            <oval-def:criterion comment="at removed" test_ref="oval:ssg-service_atd_disabled_test_service_atd_package_at_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service atd is not configured to start" operator="AND">
                <oval-def:criterion comment="atd is not running" test_ref="oval:ssg-test_service_not_running_service_atd_disabled_atd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service atd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_atd_disabled_atd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="atd is not found" test_ref="oval:ssg-test_service_not_found_service_atd_disabled_atd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_auditd_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable auditd Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_auditd_enabled" source="ssg"/>
            <oval-def:description>The auditd service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package audit installed and service auditd is configured to start" operator="AND">
            <oval-def:criterion comment="audit installed" test_ref="oval:ssg-test_service_auditd_package_audit_installed:tst:1"/>
            <oval-def:criteria comment="service auditd is configured to start and is running" operator="AND">
              <oval-def:criterion comment="auditd is running" test_ref="oval:ssg-test_service_running_auditd:tst:1"/>
              <oval-def:criteria comment="service auditd is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants auditd" test_ref="oval:ssg-test_multi_user_wants_auditd:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants auditd socket" test_ref="oval:ssg-test_multi_user_wants_auditd_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_autofs_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the Automounter</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_autofs_disabled" source="ssg"/>
            <oval-def:description>The autofs service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package autofs removed or service autofs is not configured to start" operator="OR">
            <oval-def:criterion comment="autofs removed" test_ref="oval:ssg-service_autofs_disabled_test_service_autofs_package_autofs_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service autofs is not configured to start" operator="AND">
                <oval-def:criterion comment="autofs is not running" test_ref="oval:ssg-test_service_not_running_service_autofs_disabled_autofs:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service autofs is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_autofs_disabled_autofs:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="autofs is not found" test_ref="oval:ssg-test_service_not_found_service_autofs_disabled_autofs:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_avahi-daemon_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Avahi Server Software</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_avahi-daemon_disabled" source="ssg"/>
            <oval-def:description>The avahi-daemon service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package avahi removed or service avahi-daemon is not configured to start" operator="OR">
            <oval-def:criterion comment="avahi removed" test_ref="oval:ssg-service_avahi-daemon_disabled_test_service_avahi-daemon_package_avahi_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service avahi-daemon is not configured to start" operator="AND">
                <oval-def:criterion comment="avahi-daemon is not running" test_ref="oval:ssg-test_service_not_running_service_avahi-daemon_disabled_avahi-daemon:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service avahi-daemon is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_avahi-daemon_disabled_avahi-daemon:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="avahi-daemon is not found" test_ref="oval:ssg-test_service_not_found_service_avahi-daemon_disabled_avahi-daemon:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_bluetooth_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Bluetooth Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_bluetooth_disabled" source="ssg"/>
            <oval-def:description>The bluetooth service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package bluez removed or service bluetooth is not configured to start" operator="OR">
            <oval-def:criterion comment="bluez removed" test_ref="oval:ssg-service_bluetooth_disabled_test_service_bluetooth_package_bluez_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service bluetooth is not configured to start" operator="AND">
                <oval-def:criterion comment="bluetooth is not running" test_ref="oval:ssg-test_service_not_running_service_bluetooth_disabled_bluetooth:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service bluetooth is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_bluetooth_disabled_bluetooth:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="bluetooth is not found" test_ref="oval:ssg-test_service_not_found_service_bluetooth_disabled_bluetooth:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_certmonger_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Certmonger Service (certmonger)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_certmonger_disabled" source="ssg"/>
            <oval-def:description>The certmonger service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package certmonger removed or service certmonger is not configured to start" operator="OR">
            <oval-def:criterion comment="certmonger removed" test_ref="oval:ssg-service_certmonger_disabled_test_service_certmonger_package_certmonger_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service certmonger is not configured to start" operator="AND">
                <oval-def:criterion comment="certmonger is not running" test_ref="oval:ssg-test_service_not_running_service_certmonger_disabled_certmonger:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service certmonger is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_certmonger_disabled_certmonger:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="certmonger is not found" test_ref="oval:ssg-test_service_not_found_service_certmonger_disabled_certmonger:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_chronyd_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>The Chronyd service is enabled</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_chronyd_enabled" source="ssg"/>
            <oval-def:description>The chronyd service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package chrony installed and service chronyd is configured to start" operator="AND">
            <oval-def:criterion comment="chrony installed" test_ref="oval:ssg-test_service_chronyd_package_chrony_installed:tst:1"/>
            <oval-def:criteria comment="service chronyd is configured to start and is running" operator="AND">
              <oval-def:criterion comment="chronyd is running" test_ref="oval:ssg-test_service_running_chronyd:tst:1"/>
              <oval-def:criteria comment="service chronyd is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants chronyd" test_ref="oval:ssg-test_multi_user_wants_chronyd:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants chronyd socket" test_ref="oval:ssg-test_multi_user_wants_chronyd_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_cockpit_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Cockpit Management Server</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_cockpit_disabled" source="ssg"/>
            <oval-def:description>The cockpit service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package cockpit removed or service cockpit is not configured to start" operator="OR">
            <oval-def:criterion comment="cockpit removed" test_ref="oval:ssg-service_cockpit_disabled_test_service_cockpit_package_cockpit_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service cockpit is not configured to start" operator="AND">
                <oval-def:criterion comment="cockpit is not running" test_ref="oval:ssg-test_service_not_running_service_cockpit_disabled_cockpit:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service cockpit is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_cockpit_disabled_cockpit:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="cockpit is not found" test_ref="oval:ssg-test_service_not_found_service_cockpit_disabled_cockpit:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_cpupower_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable CPU Speed (cpupower)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_cpupower_disabled" source="ssg"/>
            <oval-def:description>The cpupower service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package kernel-tools removed or service cpupower is not configured to start" operator="OR">
            <oval-def:criterion comment="kernel-tools removed" test_ref="oval:ssg-service_cpupower_disabled_test_service_cpupower_package_kernel-tools_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service cpupower is not configured to start" operator="AND">
                <oval-def:criterion comment="cpupower is not running" test_ref="oval:ssg-test_service_not_running_service_cpupower_disabled_cpupower:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service cpupower is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_cpupower_disabled_cpupower:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="cpupower is not found" test_ref="oval:ssg-test_service_not_found_service_cpupower_disabled_cpupower:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_cron_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable cron Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_cron_enabled" source="ssg"/>
            <oval-def:description>The cron service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package cron installed and service cron is configured to start" operator="AND">
            <oval-def:criterion comment="cron installed" test_ref="oval:ssg-test_service_cron_package_cron_installed:tst:1"/>
            <oval-def:criteria comment="service cron is configured to start and is running" operator="AND">
              <oval-def:criterion comment="cron is running" test_ref="oval:ssg-test_service_running_cron:tst:1"/>
              <oval-def:criteria comment="service cron is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants cron" test_ref="oval:ssg-test_multi_user_wants_cron:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants cron socket" test_ref="oval:ssg-test_multi_user_wants_cron_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_crond_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable cron Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_crond_enabled" source="ssg"/>
            <oval-def:description>The crond service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package cronie installed and service crond is configured to start" operator="AND">
            <oval-def:criterion comment="cronie installed" test_ref="oval:ssg-test_service_crond_package_cronie_installed:tst:1"/>
            <oval-def:criteria comment="service crond is configured to start and is running" operator="AND">
              <oval-def:criterion comment="crond is running" test_ref="oval:ssg-test_service_running_crond:tst:1"/>
              <oval-def:criteria comment="service crond is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants crond" test_ref="oval:ssg-test_multi_user_wants_crond:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants crond socket" test_ref="oval:ssg-test_multi_user_wants_crond_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_cups_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable the CUPS Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_cups_disabled" source="ssg"/>
            <oval-def:description>The cups service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package cups removed or service cups is not configured to start" operator="OR">
            <oval-def:criterion comment="cups removed" test_ref="oval:ssg-service_cups_disabled_test_service_cups_package_cups_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service cups is not configured to start" operator="AND">
                <oval-def:criterion comment="cups is not running" test_ref="oval:ssg-test_service_not_running_service_cups_disabled_cups:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service cups is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_cups_disabled_cups:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="cups is not found" test_ref="oval:ssg-test_service_not_found_service_cups_disabled_cups:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_debug-shell_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable debug-shell SystemD Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_debug-shell_disabled" source="ssg"/>
            <oval-def:description>The debug-shell service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package systemd removed or service debug-shell is not configured to start" operator="OR">
            <oval-def:criterion comment="systemd removed" test_ref="oval:ssg-service_debug-shell_disabled_test_service_debug-shell_package_systemd_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service debug-shell is not configured to start" operator="AND">
                <oval-def:criterion comment="debug-shell is not running" test_ref="oval:ssg-test_service_not_running_service_debug-shell_disabled_debug-shell:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service debug-shell is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_debug-shell_disabled_debug-shell:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="debug-shell is not found" test_ref="oval:ssg-test_service_not_found_service_debug-shell_disabled_debug-shell:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_dhcpd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable DHCP Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_dhcpd_disabled" source="ssg"/>
            <oval-def:description>The dhcpd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package dhcp removed or service dhcpd is not configured to start" operator="OR">
            <oval-def:criterion comment="dhcp removed" test_ref="oval:ssg-service_dhcpd_disabled_test_service_dhcpd_package_dhcp_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service dhcpd is not configured to start" operator="AND">
                <oval-def:criterion comment="dhcpd is not running" test_ref="oval:ssg-test_service_not_running_service_dhcpd_disabled_dhcpd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service dhcpd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_dhcpd_disabled_dhcpd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="dhcpd is not found" test_ref="oval:ssg-test_service_not_found_service_dhcpd_disabled_dhcpd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_dnsmasq_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable dnsmasq Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_dnsmasq_disabled" source="ssg"/>
            <oval-def:description>The dnsmasq service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package dnsmasq removed or service dnsmasq is not configured to start" operator="OR">
            <oval-def:criterion comment="dnsmasq removed" test_ref="oval:ssg-service_dnsmasq_disabled_test_service_dnsmasq_package_dnsmasq_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service dnsmasq is not configured to start" operator="AND">
                <oval-def:criterion comment="dnsmasq is not running" test_ref="oval:ssg-test_service_not_running_service_dnsmasq_disabled_dnsmasq:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service dnsmasq is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_dnsmasq_disabled_dnsmasq:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="dnsmasq is not found" test_ref="oval:ssg-test_service_not_found_service_dnsmasq_disabled_dnsmasq:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_dovecot_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Dovecot Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_dovecot_disabled" source="ssg"/>
            <oval-def:description>The dovecot service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package dovecot removed or service dovecot is not configured to start" operator="OR">
            <oval-def:criterion comment="dovecot removed" test_ref="oval:ssg-service_dovecot_disabled_test_service_dovecot_package_dovecot_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service dovecot is not configured to start" operator="AND">
                <oval-def:criterion comment="dovecot is not running" test_ref="oval:ssg-test_service_not_running_service_dovecot_disabled_dovecot:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service dovecot is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_dovecot_disabled_dovecot:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="dovecot is not found" test_ref="oval:ssg-test_service_not_found_service_dovecot_disabled_dovecot:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_fapolicyd_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the File Access Policy Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_fapolicyd_enabled" source="ssg"/>
            <oval-def:description>The fapolicyd service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package fapolicyd installed and service fapolicyd is configured to start" operator="AND">
            <oval-def:criterion comment="fapolicyd installed" test_ref="oval:ssg-test_service_fapolicyd_package_fapolicyd_installed:tst:1"/>
            <oval-def:criteria comment="service fapolicyd is configured to start and is running" operator="AND">
              <oval-def:criterion comment="fapolicyd is running" test_ref="oval:ssg-test_service_running_fapolicyd:tst:1"/>
              <oval-def:criteria comment="service fapolicyd is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants fapolicyd" test_ref="oval:ssg-test_multi_user_wants_fapolicyd:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants fapolicyd socket" test_ref="oval:ssg-test_multi_user_wants_fapolicyd_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_firewalld_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify firewalld Enabled</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_firewalld_enabled" source="ssg"/>
            <oval-def:description>The firewalld service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package firewalld installed and service firewalld is configured to start" operator="AND">
            <oval-def:criterion comment="firewalld installed" test_ref="oval:ssg-test_service_firewalld_package_firewalld_installed:tst:1"/>
            <oval-def:criteria comment="service firewalld is configured to start and is running" operator="AND">
              <oval-def:criterion comment="firewalld is running" test_ref="oval:ssg-test_service_running_firewalld:tst:1"/>
              <oval-def:criteria comment="service firewalld is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants firewalld" test_ref="oval:ssg-test_multi_user_wants_firewalld:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants firewalld socket" test_ref="oval:ssg-test_multi_user_wants_firewalld_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_httpd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable httpd Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_httpd_disabled" source="ssg"/>
            <oval-def:description>The httpd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package httpd removed or service httpd is not configured to start" operator="OR">
            <oval-def:criterion comment="httpd removed" test_ref="oval:ssg-service_httpd_disabled_test_service_httpd_package_httpd_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service httpd is not configured to start" operator="AND">
                <oval-def:criterion comment="httpd is not running" test_ref="oval:ssg-test_service_not_running_service_httpd_disabled_httpd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service httpd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_httpd_disabled_httpd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="httpd is not found" test_ref="oval:ssg-test_service_not_found_service_httpd_disabled_httpd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_ip6tables_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify ip6tables Enabled if Using IPv6</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_ip6tables_enabled" source="ssg"/>
            <oval-def:description>The ip6tables service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package iptables-ipv6 installed and service ip6tables is configured to start" operator="AND">
            <oval-def:criterion comment="iptables-ipv6 installed" test_ref="oval:ssg-test_service_ip6tables_package_iptables-ipv6_installed:tst:1"/>
            <oval-def:criteria comment="service ip6tables is configured to start and is running" operator="AND">
              <oval-def:criterion comment="ip6tables is running" test_ref="oval:ssg-test_service_running_ip6tables:tst:1"/>
              <oval-def:criteria comment="service ip6tables is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants ip6tables" test_ref="oval:ssg-test_multi_user_wants_ip6tables:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants ip6tables socket" test_ref="oval:ssg-test_multi_user_wants_ip6tables_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_iptables_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify iptables Enabled</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_iptables_enabled" source="ssg"/>
            <oval-def:description>The iptables service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package iptables installed and service iptables is configured to start" operator="AND">
            <oval-def:criterion comment="iptables installed" test_ref="oval:ssg-test_service_iptables_package_iptables_installed:tst:1"/>
            <oval-def:criteria comment="service iptables is configured to start and is running" operator="AND">
              <oval-def:criterion comment="iptables is running" test_ref="oval:ssg-test_service_running_iptables:tst:1"/>
              <oval-def:criteria comment="service iptables is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants iptables" test_ref="oval:ssg-test_multi_user_wants_iptables:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants iptables socket" test_ref="oval:ssg-test_multi_user_wants_iptables_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_kdump_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable KDump Kernel Crash Analyzer (kdump)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_kdump_disabled" source="ssg"/>
            <oval-def:description>The kdump service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package kexec-tools removed or service kdump is not configured to start" operator="OR">
            <oval-def:criterion comment="kexec-tools removed" test_ref="oval:ssg-service_kdump_disabled_test_service_kdump_package_kexec-tools_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service kdump is not configured to start" operator="AND">
                <oval-def:criterion comment="kdump is not running" test_ref="oval:ssg-test_service_not_running_service_kdump_disabled_kdump:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service kdump is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_kdump_disabled_kdump:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="kdump is not found" test_ref="oval:ssg-test_service_not_found_service_kdump_disabled_kdump:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_mdmonitor_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Software RAID Monitor (mdmonitor)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_mdmonitor_disabled" source="ssg"/>
            <oval-def:description>The mdmonitor service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package mdadm removed or service mdmonitor is not configured to start" operator="OR">
            <oval-def:criterion comment="mdadm removed" test_ref="oval:ssg-service_mdmonitor_disabled_test_service_mdmonitor_package_mdadm_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service mdmonitor is not configured to start" operator="AND">
                <oval-def:criterion comment="mdmonitor is not running" test_ref="oval:ssg-test_service_not_running_service_mdmonitor_disabled_mdmonitor:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service mdmonitor is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_mdmonitor_disabled_mdmonitor:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="mdmonitor is not found" test_ref="oval:ssg-test_service_not_found_service_mdmonitor_disabled_mdmonitor:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_nails_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable nails Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_nails_enabled" source="ssg"/>
            <oval-def:description>The nails service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package nails installed and service nails is configured to start" operator="AND">
            <oval-def:criterion comment="nails installed" test_ref="oval:ssg-test_service_nails_package_nails_installed:tst:1"/>
            <oval-def:criteria comment="service nails is configured to start and is running" operator="AND">
              <oval-def:criterion comment="nails is running" test_ref="oval:ssg-test_service_running_nails:tst:1"/>
              <oval-def:criteria comment="service nails is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants nails" test_ref="oval:ssg-test_multi_user_wants_nails:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants nails socket" test_ref="oval:ssg-test_multi_user_wants_nails_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_named_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable named Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_named_disabled" source="ssg"/>
            <oval-def:description>The named service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package bind removed or service named is not configured to start" operator="OR">
            <oval-def:criterion comment="bind removed" test_ref="oval:ssg-service_named_disabled_test_service_named_package_bind_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service named is not configured to start" operator="AND">
                <oval-def:criterion comment="named is not running" test_ref="oval:ssg-test_service_not_running_service_named_disabled_named:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service named is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_named_disabled_named:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="named is not found" test_ref="oval:ssg-test_service_not_found_service_named_disabled_named:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_netconsole_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Network Console (netconsole)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_netconsole_disabled" source="ssg"/>
            <oval-def:description>The netconsole service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package netconsole removed or service netconsole is not configured to start" operator="OR">
            <oval-def:criterion comment="netconsole removed" test_ref="oval:ssg-service_netconsole_disabled_test_service_netconsole_package_netconsole_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service netconsole is not configured to start" operator="AND">
                <oval-def:criterion comment="netconsole is not running" test_ref="oval:ssg-test_service_not_running_service_netconsole_disabled_netconsole:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service netconsole is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_netconsole_disabled_netconsole:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="netconsole is not found" test_ref="oval:ssg-test_service_not_found_service_netconsole_disabled_netconsole:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_netfs_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Network File Systems (netfs)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_netfs_disabled" source="ssg"/>
            <oval-def:description>The netfs service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package netfs removed or service netfs is not configured to start" operator="OR">
            <oval-def:criterion comment="netfs removed" test_ref="oval:ssg-service_netfs_disabled_test_service_netfs_package_netfs_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service netfs is not configured to start" operator="AND">
                <oval-def:criterion comment="netfs is not running" test_ref="oval:ssg-test_service_not_running_service_netfs_disabled_netfs:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service netfs is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_netfs_disabled_netfs:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="netfs is not found" test_ref="oval:ssg-test_service_not_found_service_netfs_disabled_netfs:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_nfs_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Network File System (nfs)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_nfs_disabled" source="ssg"/>
            <oval-def:description>The nfs-server service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package nfs-utils removed or service nfs-server is not configured to start" operator="OR">
            <oval-def:criterion comment="nfs-utils removed" test_ref="oval:ssg-service_nfs_disabled_test_service_nfs-server_package_nfs-utils_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service nfs-server is not configured to start" operator="AND">
                <oval-def:criterion comment="nfs-server is not running" test_ref="oval:ssg-test_service_not_running_service_nfs_disabled_nfs-server:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service nfs-server is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_nfs_disabled_nfs-server:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="nfs-server is not found" test_ref="oval:ssg-test_service_not_found_service_nfs_disabled_nfs-server:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_nfslock_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Network File System Lock Service (nfslock)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_nfslock_disabled" source="ssg"/>
            <oval-def:description>The nfslock service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package nfs-utils removed or service nfslock is not configured to start" operator="OR">
            <oval-def:criterion comment="nfs-utils removed" test_ref="oval:ssg-service_nfslock_disabled_test_service_nfslock_package_nfs-utils_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service nfslock is not configured to start" operator="AND">
                <oval-def:criterion comment="nfslock is not running" test_ref="oval:ssg-test_service_not_running_service_nfslock_disabled_nfslock:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service nfslock is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_nfslock_disabled_nfslock:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="nfslock is not found" test_ref="oval:ssg-test_service_not_found_service_nfslock_disabled_nfslock:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_nftables_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify nftables Service is Disabled</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_nftables_disabled" source="ssg"/>
            <oval-def:description>The nftables service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package nftables removed or service nftables is not configured to start" operator="OR">
            <oval-def:criterion comment="nftables removed" test_ref="oval:ssg-service_nftables_disabled_test_service_nftables_package_nftables_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service nftables is not configured to start" operator="AND">
                <oval-def:criterion comment="nftables is not running" test_ref="oval:ssg-test_service_not_running_service_nftables_disabled_nftables:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service nftables is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_nftables_disabled_nftables:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="nftables is not found" test_ref="oval:ssg-test_service_not_found_service_nftables_disabled_nftables:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_nftables_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify nftables Service is Enabled</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_nftables_enabled" source="ssg"/>
            <oval-def:description>The nftables service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package nftables installed and service nftables is configured to start" operator="AND">
            <oval-def:criterion comment="nftables installed" test_ref="oval:ssg-test_service_nftables_package_nftables_installed:tst:1"/>
            <oval-def:criteria comment="service nftables is configured to start and is running" operator="AND">
              <oval-def:criterion comment="nftables is running" test_ref="oval:ssg-test_service_running_nftables:tst:1"/>
              <oval-def:criteria comment="service nftables is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants nftables" test_ref="oval:ssg-test_multi_user_wants_nftables:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants nftables socket" test_ref="oval:ssg-test_multi_user_wants_nftables_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_ntp_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the NTP Daemon</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_ntp_enabled" source="ssg"/>
            <oval-def:description>The ntp service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package ntp installed and service ntp is configured to start" operator="AND">
            <oval-def:criterion comment="ntp installed" test_ref="oval:ssg-test_service_ntp_package_ntp_installed:tst:1"/>
            <oval-def:criteria comment="service ntp is configured to start and is running" operator="AND">
              <oval-def:criterion comment="ntp is running" test_ref="oval:ssg-test_service_running_ntp:tst:1"/>
              <oval-def:criteria comment="service ntp is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants ntp" test_ref="oval:ssg-test_multi_user_wants_ntp:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants ntp socket" test_ref="oval:ssg-test_multi_user_wants_ntp_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_ntpd_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the NTP Daemon</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_ntpd_enabled" source="ssg"/>
            <oval-def:description>The ntpd service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package ntp installed and service ntpd is configured to start" operator="AND">
            <oval-def:criterion comment="ntp installed" test_ref="oval:ssg-test_service_ntpd_package_ntp_installed:tst:1"/>
            <oval-def:criteria comment="service ntpd is configured to start and is running" operator="AND">
              <oval-def:criterion comment="ntpd is running" test_ref="oval:ssg-test_service_running_ntpd:tst:1"/>
              <oval-def:criteria comment="service ntpd is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants ntpd" test_ref="oval:ssg-test_multi_user_wants_ntpd:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants ntpd socket" test_ref="oval:ssg-test_multi_user_wants_ntpd_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_ntpdate_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable ntpdate Service (ntpdate)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_ntpdate_disabled" source="ssg"/>
            <oval-def:description>The ntpdate service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package ntpdate removed or service ntpdate is not configured to start" operator="OR">
            <oval-def:criterion comment="ntpdate removed" test_ref="oval:ssg-service_ntpdate_disabled_test_service_ntpdate_package_ntpdate_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service ntpdate is not configured to start" operator="AND">
                <oval-def:criterion comment="ntpdate is not running" test_ref="oval:ssg-test_service_not_running_service_ntpdate_disabled_ntpdate:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service ntpdate is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_ntpdate_disabled_ntpdate:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="ntpdate is not found" test_ref="oval:ssg-test_service_not_found_service_ntpdate_disabled_ntpdate:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_oddjobd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Odd Job Daemon (oddjobd)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_oddjobd_disabled" source="ssg"/>
            <oval-def:description>The oddjobd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package oddjob removed or service oddjobd is not configured to start" operator="OR">
            <oval-def:criterion comment="oddjob removed" test_ref="oval:ssg-service_oddjobd_disabled_test_service_oddjobd_package_oddjob_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service oddjobd is not configured to start" operator="AND">
                <oval-def:criterion comment="oddjobd is not running" test_ref="oval:ssg-test_service_not_running_service_oddjobd_disabled_oddjobd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service oddjobd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_oddjobd_disabled_oddjobd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="oddjobd is not found" test_ref="oval:ssg-test_service_not_found_service_oddjobd_disabled_oddjobd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_pcscd_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the pcscd Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_pcscd_enabled" source="ssg"/>
            <oval-def:description>The pcscd service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package pcsc-lite installed and service pcscd is configured to start" operator="AND">
            <oval-def:criterion comment="pcsc-lite installed" test_ref="oval:ssg-test_service_pcscd_package_pcsc-lite_installed:tst:1"/>
            <oval-def:criteria comment="service pcscd is configured to start and is running" operator="AND">
              <oval-def:criterion comment="pcscd is running" test_ref="oval:ssg-test_service_running_pcscd:tst:1"/>
              <oval-def:criteria comment="service pcscd is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants pcscd" test_ref="oval:ssg-test_multi_user_wants_pcscd:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants pcscd socket" test_ref="oval:ssg-test_multi_user_wants_pcscd_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_portreserve_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Portreserve (portreserve)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_portreserve_disabled" source="ssg"/>
            <oval-def:description>The portreserve service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package portreserve removed or service portreserve is not configured to start" operator="OR">
            <oval-def:criterion comment="portreserve removed" test_ref="oval:ssg-service_portreserve_disabled_test_service_portreserve_package_portreserve_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service portreserve is not configured to start" operator="AND">
                <oval-def:criterion comment="portreserve is not running" test_ref="oval:ssg-test_service_not_running_service_portreserve_disabled_portreserve:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service portreserve is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_portreserve_disabled_portreserve:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="portreserve is not found" test_ref="oval:ssg-test_service_not_found_service_portreserve_disabled_portreserve:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_postfix_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable Postfix Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_postfix_enabled" source="ssg"/>
            <oval-def:description>The postfix service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package postfix installed and service postfix is configured to start" operator="AND">
            <oval-def:criterion comment="postfix installed" test_ref="oval:ssg-test_service_postfix_package_postfix_installed:tst:1"/>
            <oval-def:criteria comment="service postfix is configured to start and is running" operator="AND">
              <oval-def:criterion comment="postfix is running" test_ref="oval:ssg-test_service_running_postfix:tst:1"/>
              <oval-def:criteria comment="service postfix is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants postfix" test_ref="oval:ssg-test_multi_user_wants_postfix:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants postfix socket" test_ref="oval:ssg-test_multi_user_wants_postfix_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_psacct_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable Process Accounting (psacct)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_psacct_enabled" source="ssg"/>
            <oval-def:description>The psacct service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package psacct installed and service psacct is configured to start" operator="AND">
            <oval-def:criterion comment="psacct installed" test_ref="oval:ssg-test_service_psacct_package_psacct_installed:tst:1"/>
            <oval-def:criteria comment="service psacct is configured to start and is running" operator="AND">
              <oval-def:criterion comment="psacct is running" test_ref="oval:ssg-test_service_running_psacct:tst:1"/>
              <oval-def:criteria comment="service psacct is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants psacct" test_ref="oval:ssg-test_multi_user_wants_psacct:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants psacct socket" test_ref="oval:ssg-test_multi_user_wants_psacct_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_qpidd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Apache Qpid (qpidd)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_qpidd_disabled" source="ssg"/>
            <oval-def:description>The qpidd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package qpid-cpp-server removed or service qpidd is not configured to start" operator="OR">
            <oval-def:criterion comment="qpid-cpp-server removed" test_ref="oval:ssg-service_qpidd_disabled_test_service_qpidd_package_qpid-cpp-server_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service qpidd is not configured to start" operator="AND">
                <oval-def:criterion comment="qpidd is not running" test_ref="oval:ssg-test_service_not_running_service_qpidd_disabled_qpidd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service qpidd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_qpidd_disabled_qpidd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="qpidd is not found" test_ref="oval:ssg-test_service_not_found_service_qpidd_disabled_qpidd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_quota_nld_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Quota Netlink (quota_nld)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_quota_nld_disabled" source="ssg"/>
            <oval-def:description>The quota_nld service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package quota-nld removed or service quota_nld is not configured to start" operator="OR">
            <oval-def:criterion comment="quota-nld removed" test_ref="oval:ssg-service_quota_nld_disabled_test_service_quota_nld_package_quota-nld_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service quota_nld is not configured to start" operator="AND">
                <oval-def:criterion comment="quota_nld is not running" test_ref="oval:ssg-test_service_not_running_service_quota_nld_disabled_quota_nld:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service quota_nld is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_quota_nld_disabled_quota_nld:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="quota_nld is not found" test_ref="oval:ssg-test_service_not_found_service_quota_nld_disabled_quota_nld:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_rdisc_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Network Router Discovery Daemon (rdisc)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_rdisc_disabled" source="ssg"/>
            <oval-def:description>The rdisc service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package iputils removed or service rdisc is not configured to start" operator="OR">
            <oval-def:criterion comment="iputils removed" test_ref="oval:ssg-service_rdisc_disabled_test_service_rdisc_package_iputils_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service rdisc is not configured to start" operator="AND">
                <oval-def:criterion comment="rdisc is not running" test_ref="oval:ssg-test_service_not_running_service_rdisc_disabled_rdisc:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service rdisc is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_rdisc_disabled_rdisc:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="rdisc is not found" test_ref="oval:ssg-test_service_not_found_service_rdisc_disabled_rdisc:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_rexec_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable rexec Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_rexec_disabled" source="ssg"/>
            <oval-def:description>The rexec service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package rsh-server removed or service rexec is not configured to start" operator="OR">
            <oval-def:criterion comment="rsh-server removed" test_ref="oval:ssg-service_rexec_disabled_test_service_rexec_package_rsh-server_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service rexec is not configured to start" operator="AND">
                <oval-def:criterion comment="rexec is not running" test_ref="oval:ssg-test_service_not_running_service_rexec_disabled_rexec:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service rexec is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_rexec_disabled_rexec:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="rexec is not found" test_ref="oval:ssg-test_service_not_found_service_rexec_disabled_rexec:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_rhnsd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Red Hat Network Service (rhnsd)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_rhnsd_disabled" source="ssg"/>
            <oval-def:description>The rhnsd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package rhnsd removed or service rhnsd is not configured to start" operator="OR">
            <oval-def:criterion comment="rhnsd removed" test_ref="oval:ssg-service_rhnsd_disabled_test_service_rhnsd_package_rhnsd_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service rhnsd is not configured to start" operator="AND">
                <oval-def:criterion comment="rhnsd is not running" test_ref="oval:ssg-test_service_not_running_service_rhnsd_disabled_rhnsd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service rhnsd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_rhnsd_disabled_rhnsd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="rhnsd is not found" test_ref="oval:ssg-test_service_not_found_service_rhnsd_disabled_rhnsd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_rhsmcertd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Red Hat Subscription Manager Daemon (rhsmcertd)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_rhsmcertd_disabled" source="ssg"/>
            <oval-def:description>The rhsmcertd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package subscription-manager removed or service rhsmcertd is not configured to start" operator="OR">
            <oval-def:criterion comment="subscription-manager removed" test_ref="oval:ssg-service_rhsmcertd_disabled_test_service_rhsmcertd_package_subscription-manager_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service rhsmcertd is not configured to start" operator="AND">
                <oval-def:criterion comment="rhsmcertd is not running" test_ref="oval:ssg-test_service_not_running_service_rhsmcertd_disabled_rhsmcertd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service rhsmcertd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_rhsmcertd_disabled_rhsmcertd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="rhsmcertd is not found" test_ref="oval:ssg-test_service_not_found_service_rhsmcertd_disabled_rhsmcertd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_rlogin_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable rlogin Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_rlogin_disabled" source="ssg"/>
            <oval-def:description>The rlogin service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package rsh-server removed or service rlogin is not configured to start" operator="OR">
            <oval-def:criterion comment="rsh-server removed" test_ref="oval:ssg-service_rlogin_disabled_test_service_rlogin_package_rsh-server_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service rlogin is not configured to start" operator="AND">
                <oval-def:criterion comment="rlogin is not running" test_ref="oval:ssg-test_service_not_running_service_rlogin_disabled_rlogin:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service rlogin is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_rlogin_disabled_rlogin:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="rlogin is not found" test_ref="oval:ssg-test_service_not_found_service_rlogin_disabled_rlogin:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_rngd_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the Hardware RNG Entropy Gatherer Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_rngd_enabled" source="ssg"/>
            <oval-def:description>The rngd service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package rng-tools installed and service rngd is configured to start" operator="AND">
            <oval-def:criterion comment="rng-tools installed" test_ref="oval:ssg-test_service_rngd_package_rng-tools_installed:tst:1"/>
            <oval-def:criteria comment="service rngd is configured to start and is running" operator="AND">
              <oval-def:criterion comment="rngd is running" test_ref="oval:ssg-test_service_running_rngd:tst:1"/>
              <oval-def:criteria comment="service rngd is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants rngd" test_ref="oval:ssg-test_multi_user_wants_rngd:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants rngd socket" test_ref="oval:ssg-test_multi_user_wants_rngd_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_rpcbind_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable rpcbind Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_rpcbind_disabled" source="ssg"/>
            <oval-def:description>The rpcbind service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package rpcbind removed or service rpcbind is not configured to start" operator="OR">
            <oval-def:criterion comment="rpcbind removed" test_ref="oval:ssg-service_rpcbind_disabled_test_service_rpcbind_package_rpcbind_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service rpcbind is not configured to start" operator="AND">
                <oval-def:criterion comment="rpcbind is not running" test_ref="oval:ssg-test_service_not_running_service_rpcbind_disabled_rpcbind:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service rpcbind is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_rpcbind_disabled_rpcbind:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="rpcbind is not found" test_ref="oval:ssg-test_service_not_found_service_rpcbind_disabled_rpcbind:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_rpcgssd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Secure RPC Client Service (rpcgssd)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_rpcgssd_disabled" source="ssg"/>
            <oval-def:description>The rpcgssd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package nfs-utils removed or service rpcgssd is not configured to start" operator="OR">
            <oval-def:criterion comment="nfs-utils removed" test_ref="oval:ssg-service_rpcgssd_disabled_test_service_rpcgssd_package_nfs-utils_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service rpcgssd is not configured to start" operator="AND">
                <oval-def:criterion comment="rpcgssd is not running" test_ref="oval:ssg-test_service_not_running_service_rpcgssd_disabled_rpcgssd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service rpcgssd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_rpcgssd_disabled_rpcgssd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="rpcgssd is not found" test_ref="oval:ssg-test_service_not_found_service_rpcgssd_disabled_rpcgssd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_rpcidmapd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable RPC ID Mapping Service (rpcidmapd)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_rpcidmapd_disabled" source="ssg"/>
            <oval-def:description>The rpcidmapd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package nfs-utils removed or service rpcidmapd is not configured to start" operator="OR">
            <oval-def:criterion comment="nfs-utils removed" test_ref="oval:ssg-service_rpcidmapd_disabled_test_service_rpcidmapd_package_nfs-utils_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service rpcidmapd is not configured to start" operator="AND">
                <oval-def:criterion comment="rpcidmapd is not running" test_ref="oval:ssg-test_service_not_running_service_rpcidmapd_disabled_rpcidmapd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service rpcidmapd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_rpcidmapd_disabled_rpcidmapd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="rpcidmapd is not found" test_ref="oval:ssg-test_service_not_found_service_rpcidmapd_disabled_rpcidmapd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_rpcsvcgssd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Secure RPC Server Service (rpcsvcgssd)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_rpcsvcgssd_disabled" source="ssg"/>
            <oval-def:description>The rpcsvcgssd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package nfs-utils removed or service rpcsvcgssd is not configured to start" operator="OR">
            <oval-def:criterion comment="nfs-utils removed" test_ref="oval:ssg-service_rpcsvcgssd_disabled_test_service_rpcsvcgssd_package_nfs-utils_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service rpcsvcgssd is not configured to start" operator="AND">
                <oval-def:criterion comment="rpcsvcgssd is not running" test_ref="oval:ssg-test_service_not_running_service_rpcsvcgssd_disabled_rpcsvcgssd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service rpcsvcgssd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_rpcsvcgssd_disabled_rpcsvcgssd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="rpcsvcgssd is not found" test_ref="oval:ssg-test_service_not_found_service_rpcsvcgssd_disabled_rpcsvcgssd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_rsh_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable rsh Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_rsh_disabled" source="ssg"/>
            <oval-def:description>The rsh service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package rsh removed or service rsh is not configured to start" operator="OR">
            <oval-def:criterion comment="rsh removed" test_ref="oval:ssg-service_rsh_disabled_test_service_rsh_package_rsh_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service rsh is not configured to start" operator="AND">
                <oval-def:criterion comment="rsh is not running" test_ref="oval:ssg-test_service_not_running_service_rsh_disabled_rsh:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service rsh is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_rsh_disabled_rsh:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="rsh is not found" test_ref="oval:ssg-test_service_not_found_service_rsh_disabled_rsh:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_rsyncd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure rsyncd service is disabled</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_rsyncd_disabled" source="ssg"/>
            <oval-def:description>The rsyncd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package rsync-daemon removed or service rsyncd is not configured to start" operator="OR">
            <oval-def:criterion comment="rsync-daemon removed" test_ref="oval:ssg-service_rsyncd_disabled_test_service_rsyncd_package_rsync-daemon_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service rsyncd is not configured to start" operator="AND">
                <oval-def:criterion comment="rsyncd is not running" test_ref="oval:ssg-test_service_not_running_service_rsyncd_disabled_rsyncd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service rsyncd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_rsyncd_disabled_rsyncd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="rsyncd is not found" test_ref="oval:ssg-test_service_not_found_service_rsyncd_disabled_rsyncd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_rsyslog_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable rsyslog Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_rsyslog_enabled" source="ssg"/>
            <oval-def:description>The rsyslog service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package rsyslog installed and service rsyslog is configured to start" operator="AND">
            <oval-def:criterion comment="rsyslog installed" test_ref="oval:ssg-test_service_rsyslog_package_rsyslog_installed:tst:1"/>
            <oval-def:criteria comment="service rsyslog is configured to start and is running" operator="AND">
              <oval-def:criterion comment="rsyslog is running" test_ref="oval:ssg-test_service_running_rsyslog:tst:1"/>
              <oval-def:criteria comment="service rsyslog is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants rsyslog" test_ref="oval:ssg-test_multi_user_wants_rsyslog:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants rsyslog socket" test_ref="oval:ssg-test_multi_user_wants_rsyslog_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_saslauthd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Cyrus SASL Authentication Daemon (saslauthd)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_saslauthd_disabled" source="ssg"/>
            <oval-def:description>The saslauthd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package cyrus-sasl removed or service saslauthd is not configured to start" operator="OR">
            <oval-def:criterion comment="cyrus-sasl removed" test_ref="oval:ssg-service_saslauthd_disabled_test_service_saslauthd_package_cyrus-sasl_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service saslauthd is not configured to start" operator="AND">
                <oval-def:criterion comment="saslauthd is not running" test_ref="oval:ssg-test_service_not_running_service_saslauthd_disabled_saslauthd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service saslauthd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_saslauthd_disabled_saslauthd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="saslauthd is not found" test_ref="oval:ssg-test_service_not_found_service_saslauthd_disabled_saslauthd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_slapd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable LDAP Server (slapd)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_slapd_disabled" source="ssg"/>
            <oval-def:description>The slapd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package openldap-servers removed or service slapd is not configured to start" operator="OR">
            <oval-def:criterion comment="openldap-servers removed" test_ref="oval:ssg-service_slapd_disabled_test_service_slapd_package_openldap-servers_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service slapd is not configured to start" operator="AND">
                <oval-def:criterion comment="slapd is not running" test_ref="oval:ssg-test_service_not_running_service_slapd_disabled_slapd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service slapd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_slapd_disabled_slapd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="slapd is not found" test_ref="oval:ssg-test_service_not_found_service_slapd_disabled_slapd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_smb_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Samba</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_smb_disabled" source="ssg"/>
            <oval-def:description>The smb service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package samba removed or service smb is not configured to start" operator="OR">
            <oval-def:criterion comment="samba removed" test_ref="oval:ssg-service_smb_disabled_test_service_smb_package_samba_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service smb is not configured to start" operator="AND">
                <oval-def:criterion comment="smb is not running" test_ref="oval:ssg-test_service_not_running_service_smb_disabled_smb:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service smb is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_smb_disabled_smb:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="smb is not found" test_ref="oval:ssg-test_service_not_found_service_smb_disabled_smb:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_snmpd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable snmpd Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_snmpd_disabled" source="ssg"/>
            <oval-def:description>The snmpd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package net-snmp removed or service snmpd is not configured to start" operator="OR">
            <oval-def:criterion comment="net-snmp removed" test_ref="oval:ssg-service_snmpd_disabled_test_service_snmpd_package_net-snmp_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service snmpd is not configured to start" operator="AND">
                <oval-def:criterion comment="snmpd is not running" test_ref="oval:ssg-test_service_not_running_service_snmpd_disabled_snmpd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service snmpd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_snmpd_disabled_snmpd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="snmpd is not found" test_ref="oval:ssg-test_service_not_found_service_snmpd_disabled_snmpd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_squid_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Squid</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_squid_disabled" source="ssg"/>
            <oval-def:description>The squid service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package squid removed or service squid is not configured to start" operator="OR">
            <oval-def:criterion comment="squid removed" test_ref="oval:ssg-service_squid_disabled_test_service_squid_package_squid_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service squid is not configured to start" operator="AND">
                <oval-def:criterion comment="squid is not running" test_ref="oval:ssg-test_service_not_running_service_squid_disabled_squid:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service squid is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_squid_disabled_squid:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="squid is not found" test_ref="oval:ssg-test_service_not_found_service_squid_disabled_squid:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_sshd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable SSH Server If Possible</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_sshd_disabled" source="ssg"/>
            <oval-def:description>The sshd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package openssh-server removed or service sshd is not configured to start" operator="OR">
            <oval-def:criterion comment="openssh-server removed" test_ref="oval:ssg-service_sshd_disabled_test_service_sshd_package_openssh-server_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service sshd is not configured to start" operator="AND">
                <oval-def:criterion comment="sshd is not running" test_ref="oval:ssg-test_service_not_running_service_sshd_disabled_sshd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service sshd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_sshd_disabled_sshd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="sshd is not found" test_ref="oval:ssg-test_service_not_found_service_sshd_disabled_sshd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_sshd_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the OpenSSH Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_sshd_enabled" source="ssg"/>
            <oval-def:description>The sshd service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package openssh-server installed and service sshd is configured to start" operator="AND">
            <oval-def:criterion comment="openssh-server installed" test_ref="oval:ssg-test_service_sshd_package_openssh-server_installed:tst:1"/>
            <oval-def:criteria comment="service sshd is configured to start and is running" operator="AND">
              <oval-def:criterion comment="sshd is running" test_ref="oval:ssg-test_service_running_sshd:tst:1"/>
              <oval-def:criteria comment="service sshd is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants sshd" test_ref="oval:ssg-test_multi_user_wants_sshd:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants sshd socket" test_ref="oval:ssg-test_multi_user_wants_sshd_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_sssd_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the SSSD Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_sssd_enabled" source="ssg"/>
            <oval-def:description>The sssd service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package sssd-common installed and service sssd is configured to start" operator="AND">
            <oval-def:criterion comment="sssd-common installed" test_ref="oval:ssg-test_service_sssd_package_sssd-common_installed:tst:1"/>
            <oval-def:criteria comment="service sssd is configured to start and is running" operator="AND">
              <oval-def:criterion comment="sssd is running" test_ref="oval:ssg-test_service_running_sssd:tst:1"/>
              <oval-def:criteria comment="service sssd is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants sssd" test_ref="oval:ssg-test_multi_user_wants_sssd:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants sssd socket" test_ref="oval:ssg-test_multi_user_wants_sssd_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_syslogng_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable syslog-ng Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_syslogng_enabled" source="ssg"/>
            <oval-def:description>The syslog-ng service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package syslog-ng installed and service syslog-ng is configured to start" operator="AND">
            <oval-def:criterion comment="syslog-ng installed" test_ref="oval:ssg-test_service_syslog-ng_package_syslog-ng_installed:tst:1"/>
            <oval-def:criteria comment="service syslog-ng is configured to start and is running" operator="AND">
              <oval-def:criterion comment="syslog-ng is running" test_ref="oval:ssg-test_service_running_syslog-ng:tst:1"/>
              <oval-def:criteria comment="service syslog-ng is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants syslog-ng" test_ref="oval:ssg-test_multi_user_wants_syslog-ng:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants syslog-ng socket" test_ref="oval:ssg-test_multi_user_wants_syslog-ng_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_sysstat_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable System Statistics Reset Service (sysstat)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_sysstat_disabled" source="ssg"/>
            <oval-def:description>The sysstat service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package sysstat removed or service sysstat is not configured to start" operator="OR">
            <oval-def:criterion comment="sysstat removed" test_ref="oval:ssg-service_sysstat_disabled_test_service_sysstat_package_sysstat_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service sysstat is not configured to start" operator="AND">
                <oval-def:criterion comment="sysstat is not running" test_ref="oval:ssg-test_service_not_running_service_sysstat_disabled_sysstat:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service sysstat is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_sysstat_disabled_sysstat:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="sysstat is not found" test_ref="oval:ssg-test_service_not_found_service_sysstat_disabled_sysstat:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_systemd-coredump_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable acquiring, saving, and processing core dumps</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_systemd-coredump_disabled" source="ssg"/>
            <oval-def:description>Disable systemd-coredump.socket</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Property LoadState of systemd-coredump.socket is masked" test_ref="oval:ssg-test_socket_loadstate_is_masked_systemd-coredump:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_systemd-journal-upload_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable systemd-journal-upload Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_systemd-journal-upload_enabled" source="ssg"/>
            <oval-def:description>The systemd-journal-upload service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package systemd-journal-remote installed and service systemd-journal-upload is configured to start" operator="AND">
            <oval-def:criterion comment="systemd-journal-remote installed" test_ref="oval:ssg-test_service_systemd-journal-upload_package_systemd-journal-remote_installed:tst:1"/>
            <oval-def:criteria comment="service systemd-journal-upload is configured to start and is running" operator="AND">
              <oval-def:criterion comment="systemd-journal-upload is running" test_ref="oval:ssg-test_service_running_systemd-journal-upload:tst:1"/>
              <oval-def:criteria comment="service systemd-journal-upload is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants systemd-journal-upload" test_ref="oval:ssg-test_multi_user_wants_systemd-journal-upload:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants systemd-journal-upload socket" test_ref="oval:ssg-test_multi_user_wants_systemd-journal-upload_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_systemd-journald_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable systemd-journald Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_systemd-journald_enabled" source="ssg"/>
            <oval-def:description>The systemd-journald service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package systemd installed and service systemd-journald is configured to start" operator="AND">
            <oval-def:criterion comment="systemd installed" test_ref="oval:ssg-test_service_systemd-journald_package_systemd_installed:tst:1"/>
            <oval-def:criteria comment="service systemd-journald is configured to start and is running" operator="AND">
              <oval-def:criterion comment="systemd-journald is running" test_ref="oval:ssg-test_service_running_systemd-journald:tst:1"/>
              <oval-def:criteria comment="service systemd-journald is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants systemd-journald" test_ref="oval:ssg-test_multi_user_wants_systemd-journald:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants systemd-journald socket" test_ref="oval:ssg-test_multi_user_wants_systemd-journald_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_telnet_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable telnet Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_telnet_disabled" source="ssg"/>
            <oval-def:description>The telnet service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package telnet-server removed or service telnet is not configured to start" operator="OR">
            <oval-def:criterion comment="telnet-server removed" test_ref="oval:ssg-service_telnet_disabled_test_service_telnet_package_telnet-server_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service telnet is not configured to start" operator="AND">
                <oval-def:criterion comment="telnet is not running" test_ref="oval:ssg-test_service_not_running_service_telnet_disabled_telnet:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service telnet is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_telnet_disabled_telnet:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="telnet is not found" test_ref="oval:ssg-test_service_not_found_service_telnet_disabled_telnet:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_tftp_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable tftp Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_tftp_disabled" source="ssg"/>
            <oval-def:description>The tftp service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package tftp-server removed or service tftp is not configured to start" operator="OR">
            <oval-def:criterion comment="tftp-server removed" test_ref="oval:ssg-service_tftp_disabled_test_service_tftp_package_tftp-server_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service tftp is not configured to start" operator="AND">
                <oval-def:criterion comment="tftp is not running" test_ref="oval:ssg-test_service_not_running_service_tftp_disabled_tftp:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service tftp is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_tftp_disabled_tftp:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="tftp is not found" test_ref="oval:ssg-test_service_not_found_service_tftp_disabled_tftp:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_ufw_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify ufw Enabled</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_ufw_enabled" source="ssg"/>
            <oval-def:description>The ufw service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package ufw installed and service ufw is configured to start" operator="AND">
            <oval-def:criterion comment="ufw installed" test_ref="oval:ssg-test_service_ufw_package_ufw_installed:tst:1"/>
            <oval-def:criteria comment="service ufw is configured to start and is running" operator="AND">
              <oval-def:criterion comment="ufw is running" test_ref="oval:ssg-test_service_running_ufw:tst:1"/>
              <oval-def:criteria comment="service ufw is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants ufw" test_ref="oval:ssg-test_multi_user_wants_ufw:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants ufw socket" test_ref="oval:ssg-test_multi_user_wants_ufw_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_usbguard_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable the USBGuard Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_usbguard_enabled" source="ssg"/>
            <oval-def:description>The usbguard service should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package usbguard installed and service usbguard is configured to start" operator="AND">
            <oval-def:criterion comment="usbguard installed" test_ref="oval:ssg-test_service_usbguard_package_usbguard_installed:tst:1"/>
            <oval-def:criteria comment="service usbguard is configured to start and is running" operator="AND">
              <oval-def:criterion comment="usbguard is running" test_ref="oval:ssg-test_service_running_usbguard:tst:1"/>
              <oval-def:criteria comment="service usbguard is configured to start" operator="OR">
                <oval-def:criterion comment="multi-user.target wants usbguard" test_ref="oval:ssg-test_multi_user_wants_usbguard:tst:1"/>
                <oval-def:criterion comment="multi-user.target wants usbguard socket" test_ref="oval:ssg-test_multi_user_wants_usbguard_socket:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_vsftpd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable vsftpd Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_vsftpd_disabled" source="ssg"/>
            <oval-def:description>The vsftpd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package vsftpd removed or service vsftpd is not configured to start" operator="OR">
            <oval-def:criterion comment="vsftpd removed" test_ref="oval:ssg-service_vsftpd_disabled_test_service_vsftpd_package_vsftpd_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service vsftpd is not configured to start" operator="AND">
                <oval-def:criterion comment="vsftpd is not running" test_ref="oval:ssg-test_service_not_running_service_vsftpd_disabled_vsftpd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service vsftpd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_vsftpd_disabled_vsftpd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="vsftpd is not found" test_ref="oval:ssg-test_service_not_found_service_vsftpd_disabled_vsftpd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_xinetd_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable xinetd Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_xinetd_disabled" source="ssg"/>
            <oval-def:description>The xinetd service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package xinetd removed or service xinetd is not configured to start" operator="OR">
            <oval-def:criterion comment="xinetd removed" test_ref="oval:ssg-service_xinetd_disabled_test_service_xinetd_package_xinetd_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service xinetd is not configured to start" operator="AND">
                <oval-def:criterion comment="xinetd is not running" test_ref="oval:ssg-test_service_not_running_service_xinetd_disabled_xinetd:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service xinetd is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_xinetd_disabled_xinetd:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="xinetd is not found" test_ref="oval:ssg-test_service_not_found_service_xinetd_disabled_xinetd:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_ypbind_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable ypbind Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_ypbind_disabled" source="ssg"/>
            <oval-def:description>The ypbind service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package ypbind removed or service ypbind is not configured to start" operator="OR">
            <oval-def:criterion comment="ypbind removed" test_ref="oval:ssg-service_ypbind_disabled_test_service_ypbind_package_ypbind_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service ypbind is not configured to start" operator="AND">
                <oval-def:criterion comment="ypbind is not running" test_ref="oval:ssg-test_service_not_running_service_ypbind_disabled_ypbind:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service ypbind is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_ypbind_disabled_ypbind:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="ypbind is not found" test_ref="oval:ssg-test_service_not_found_service_ypbind_disabled_ypbind:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_ypserv_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable ypserv Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_ypserv_disabled" source="ssg"/>
            <oval-def:description>The ypserv service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package ypserv removed or service ypserv is not configured to start" operator="OR">
            <oval-def:criterion comment="ypserv removed" test_ref="oval:ssg-service_ypserv_disabled_test_service_ypserv_package_ypserv_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service ypserv is not configured to start" operator="AND">
                <oval-def:criterion comment="ypserv is not running" test_ref="oval:ssg-test_service_not_running_service_ypserv_disabled_ypserv:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service ypserv is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_ypserv_disabled_ypserv:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="ypserv is not found" test_ref="oval:ssg-test_service_not_found_service_ypserv_disabled_ypserv:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-service_zebra_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Quagga Service</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="service_zebra_disabled" source="ssg"/>
            <oval-def:description>The zebra service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package quagga removed or service zebra is not configured to start" operator="OR">
            <oval-def:criterion comment="quagga removed" test_ref="oval:ssg-service_zebra_disabled_test_service_zebra_package_quagga_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service zebra is not configured to start" operator="AND">
                <oval-def:criterion comment="zebra is not running" test_ref="oval:ssg-test_service_not_running_service_zebra_disabled_zebra:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service zebra is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_zebra_disabled_zebra:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="zebra is not found" test_ref="oval:ssg-test_service_not_found_service_zebra_disabled_zebra:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-set_firewalld_default_zone:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set Default firewalld Zone for Incoming Packets</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="set_firewalld_default_zone" source="ssg"/>
            <oval-def:description>Check presence of DefaultZone=drop in /etc/firewalld/firewalld.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - presence of the file plus 0 extra definitions." operator="AND">
            <oval-def:criterion comment="Check that /etc/firewalld/firewalld.conf contains a line with certain text" test_ref="oval:ssg-test_set_firewalld_default_zone:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-socket_systemd-journal-remote_disabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable systemd-journal-remote Socket</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="socket_systemd-journal-remote_disabled" source="ssg"/>
            <oval-def:description>Disable systemd-journal-remote.socket</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Property LoadState of systemd-journal-remote.socket is masked" test_ref="oval:ssg-test_socket_loadstate_is_masked_systemd-journal-remote:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_allow_only_protocol2:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Allow Only SSH Protocol 2</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_allow_only_protocol2" source="ssg"/>
            <oval-def:description>Ensure 'Protocol' is configured with value '2' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the Protocol in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_allow_only_protocol2:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_Protocol_present_sshd_allow_only_protocol2:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_disable_compression:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Compression Or Set Compression to delayed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_disable_compression" source="ssg"/>
            <oval-def:description>Ensure 'Compression' is configured with value configured in var_sshd_disable_compression variable in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the Compression in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_disable_compression:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_Compression_present_sshd_disable_compression:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_disable_empty_passwords:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable SSH Access via Empty Passwords</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_disable_empty_passwords" source="ssg"/>
            <oval-def:description>Ensure 'PermitEmptyPasswords' is configured with value 'no' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the PermitEmptyPasswords in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_disable_empty_passwords:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_PermitEmptyPasswords_present_sshd_disable_empty_passwords:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_disable_forwarding:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable SSH Forwarding</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_disable_forwarding" source="ssg"/>
            <oval-def:description>Ensure 'DisableForwarding' is configured with value 'yes' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the DisableForwarding in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_disable_forwarding:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_DisableForwarding_present_sshd_disable_forwarding:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_disable_gssapi_auth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable GSSAPI Authentication</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_disable_gssapi_auth" source="ssg"/>
            <oval-def:description>Ensure 'GSSAPIAuthentication' is configured with value 'no' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the GSSAPIAuthentication in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_disable_gssapi_auth:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_GSSAPIAuthentication_present_sshd_disable_gssapi_auth:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_disable_kerb_auth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable Kerberos Authentication</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_disable_kerb_auth" source="ssg"/>
            <oval-def:description>Ensure 'KerberosAuthentication' is configured with value 'no' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the KerberosAuthentication in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_disable_kerb_auth:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_KerberosAuthentication_present_sshd_disable_kerb_auth:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_disable_pubkey_auth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable PubkeyAuthentication Authentication</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_disable_pubkey_auth" source="ssg"/>
            <oval-def:description>Ensure 'PubkeyAuthentication' is configured with value 'no' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the PubkeyAuthentication in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_disable_pubkey_auth:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_PubkeyAuthentication_present_sshd_disable_pubkey_auth:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_disable_rhosts:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable SSH Support for .rhosts Files</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_disable_rhosts" source="ssg"/>
            <oval-def:description>Ensure 'IgnoreRhosts' is configured with value 'yes' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the IgnoreRhosts in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_disable_rhosts:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_IgnoreRhosts_present_sshd_disable_rhosts:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_disable_rhosts_rsa:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable SSH Support for Rhosts RSA Authentication</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_disable_rhosts_rsa" source="ssg"/>
            <oval-def:description>Ensure 'RhostsRSAAuthentication' is configured with value 'no' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the RhostsRSAAuthentication in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_disable_rhosts_rsa:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_RhostsRSAAuthentication_present_sshd_disable_rhosts_rsa:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_disable_root_login:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable SSH Root Login</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_disable_root_login" source="ssg"/>
            <oval-def:description>Ensure 'PermitRootLogin' is configured with value 'no' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the PermitRootLogin in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_disable_root_login:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_PermitRootLogin_present_sshd_disable_root_login:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_disable_root_password_login:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable SSH root Login with a Password (Insecure)</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_disable_root_password_login" source="ssg"/>
            <oval-def:description>Ensure 'PermitRootLogin' is configured with value 'prohibit-password' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the PermitRootLogin in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_disable_root_password_login:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_PermitRootLogin_present_sshd_disable_root_password_login:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_disable_tcp_forwarding:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable SSH TCP Forwarding</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_disable_tcp_forwarding" source="ssg"/>
            <oval-def:description>Ensure 'AllowTcpForwarding' is configured with value 'no' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the AllowTcpForwarding in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_disable_tcp_forwarding:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_AllowTcpForwarding_present_sshd_disable_tcp_forwarding:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_disable_user_known_hosts:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable SSH Support for User Known Hosts</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_disable_user_known_hosts" source="ssg"/>
            <oval-def:description>Ensure 'IgnoreUserKnownHosts' is configured with value 'yes' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the IgnoreUserKnownHosts in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_disable_user_known_hosts:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_IgnoreUserKnownHosts_present_sshd_disable_user_known_hosts:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_disable_x11_forwarding:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable X11 Forwarding</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_disable_x11_forwarding" source="ssg"/>
            <oval-def:description>Ensure 'X11Forwarding' is configured with value 'no' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the X11Forwarding in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_disable_x11_forwarding:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_X11Forwarding_present_sshd_disable_x11_forwarding:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_do_not_permit_user_env:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Do Not Allow SSH Environment Options</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_do_not_permit_user_env" source="ssg"/>
            <oval-def:description>Ensure 'PermitUserEnvironment' is configured with value 'no' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the PermitUserEnvironment in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_do_not_permit_user_env:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_PermitUserEnvironment_present_sshd_do_not_permit_user_env:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_enable_gssapi_auth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable GSSAPI Authentication</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_enable_gssapi_auth" source="ssg"/>
            <oval-def:description>Ensure 'GSSAPIAuthentication' is configured with value 'yes' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the GSSAPIAuthentication in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_enable_gssapi_auth:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_GSSAPIAuthentication_present_sshd_enable_gssapi_auth:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_enable_pam:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable PAM</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_enable_pam" source="ssg"/>
            <oval-def:description>Ensure 'UsePAM' is configured with value 'yes' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the UsePAM in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_enable_pam:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_UsePAM_present_sshd_enable_pam:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_enable_pubkey_auth:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable Public Key Authentication</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_enable_pubkey_auth" source="ssg"/>
            <oval-def:description>Ensure 'PubkeyAuthentication' is configured with value 'yes' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the PubkeyAuthentication in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_enable_pubkey_auth:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_PubkeyAuthentication_present_sshd_enable_pubkey_auth:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_enable_strictmodes:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable Use of Strict Mode Checking</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_enable_strictmodes" source="ssg"/>
            <oval-def:description>Ensure 'StrictModes' is configured with value 'yes' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the StrictModes in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_enable_strictmodes:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_StrictModes_present_sshd_enable_strictmodes:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_enable_warning_banner:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable SSH Warning Banner</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_enable_warning_banner" source="ssg"/>
            <oval-def:description>Ensure 'Banner' is configured with value '/etc/issue' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the Banner in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_enable_warning_banner:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_Banner_present_sshd_enable_warning_banner:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_enable_warning_banner_net:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable SSH Warning Banner</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_enable_warning_banner_net" source="ssg"/>
            <oval-def:description>Ensure 'Banner' is configured with value '/etc/issue.net' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the Banner in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_enable_warning_banner_net:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_Banner_present_sshd_enable_warning_banner_net:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_enable_x11_forwarding:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable Encrypted X11 Forwarding</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_enable_x11_forwarding" source="ssg"/>
            <oval-def:description>Ensure 'X11Forwarding' is configured with value 'yes' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the X11Forwarding in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_enable_x11_forwarding:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_X11Forwarding_present_sshd_enable_x11_forwarding:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_print_last_log:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable SSH Print Last Log</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_print_last_log" source="ssg"/>
            <oval-def:description>Ensure 'PrintLastLog' is configured with value 'yes' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the PrintLastLog in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_print_last_log:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_PrintLastLog_present_sshd_print_last_log:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_set_keepalive:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set SSH Client Alive Count Max</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_set_keepalive" source="ssg"/>
            <oval-def:description>Ensure 'ClientAliveCountMax' is configured with value configured in var_sshd_set_keepalive variable in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the ClientAliveCountMax in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_set_keepalive:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_ClientAliveCountMax_present_sshd_set_keepalive:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_set_keepalive_0:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set SSH Client Alive Count Max to zero</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_set_keepalive_0" source="ssg"/>
            <oval-def:description>Ensure 'ClientAliveCountMax' is configured with value '0' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the ClientAliveCountMax in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_set_keepalive_0:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_ClientAliveCountMax_present_sshd_set_keepalive_0:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_set_loglevel_info:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set LogLevel to INFO</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_set_loglevel_info" source="ssg"/>
            <oval-def:description>Ensure 'LogLevel' is configured with value 'INFO' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the LogLevel in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_set_loglevel_info:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_LogLevel_present_sshd_set_loglevel_info:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_set_loglevel_verbose:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Set SSH Daemon LogLevel to VERBOSE</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_set_loglevel_verbose" source="ssg"/>
            <oval-def:description>Ensure 'LogLevel' is configured with value 'VERBOSE' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the LogLevel in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_set_loglevel_verbose:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_LogLevel_present_sshd_set_loglevel_verbose:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_use_priv_separation:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable Use of Privilege Separation</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_use_priv_separation" source="ssg"/>
            <oval-def:description>Ensure 'UsePrivilegeSeparation' is configured with value configured in var_sshd_priv_separation variable in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the UsePrivilegeSeparation in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_use_priv_separation:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_UsePrivilegeSeparation_present_sshd_use_priv_separation:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_use_strong_rng:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>SSH server uses strong entropy to seed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_use_strong_rng" source="ssg"/>
            <oval-def:description>Ensure 'SSH_USE_STRONG_RNG' is configured with value '32' in /etc/sysconfig/sshd</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="The respective application or service is configured correctly" operator="OR">
            <oval-def:criterion comment="Check the SSH_USE_STRONG_RNG in /etc/sysconfig/sshd" test_ref="oval:ssg-test_sshd_use_strong_rng:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_x11_use_localhost:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Prevent remote hosts from connecting to the proxy display</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_x11_use_localhost" source="ssg"/>
            <oval-def:description>Ensure 'X11UseLocalhost' is configured with value 'yes' in /etc/ssh/sshd_config</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="sshd is configured correctly or is not installed" operator="OR">
            <oval-def:criteria comment="sshd is not installed" operator="AND">
              <oval-def:extend_definition comment="sshd is not required or requirement is unset" definition_ref="oval:ssg-sshd_not_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server removed" definition_ref="oval:ssg-package_openssh-server_removed:def:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="sshd is installed and configured" operator="AND">
              <oval-def:extend_definition comment="sshd is required or requirement is unset" definition_ref="oval:ssg-sshd_required_or_unset:def:1"/>
              <oval-def:extend_definition comment="rpm package openssh-server installed" definition_ref="oval:ssg-package_openssh-server_installed:def:1"/>
              <oval-def:criteria comment="sshd is configured correctly" operator="AND">
                <oval-def:criteria comment="static configuration is correct" operator="AND">
                  <oval-def:criteria comment="the configuration is correct if it exists" operator="AND">
                    <oval-def:criterion comment="Check the X11UseLocalhost in /etc/ssh/sshd_config if any" test_ref="oval:ssg-test_sshd_x11_use_localhost:tst:1"/>
                  </oval-def:criteria>
                  <oval-def:criterion comment="the configuration exists" test_ref="oval:ssg-test_X11UseLocalhost_present_sshd_x11_use_localhost:tst:1"/>
                </oval-def:criteria>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sssd_enable_certmap:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable Certmap in SSSD</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sssd_enable_certmap" source="ssg"/>
            <oval-def:description>Check presence of \[certmap\/.+\/.+\] in /etc/sssd/sssd.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Test conditions - presence of the file plus 0 extra definitions." operator="AND">
            <oval-def:criterion comment="Check that /etc/sssd/sssd.conf contains a line with certain text" test_ref="oval:ssg-test_sssd_enable_certmap:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudo_add_env_reset:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure sudo Runs In A Minimal Environment - sudo env_reset</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudo_add_env_reset" source="ssg"/>
            <oval-def:description>Checks sudoers Defaults env_reset configuration</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="env_reset is configured in /etc/sudoers or /etc/sudoers.d/" test_ref="oval:ssg-test_env_reset_sudoers:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudo_add_ignore_dot:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure sudo Ignores Commands In Current Dir - sudo ignore_dot</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudo_add_ignore_dot" source="ssg"/>
            <oval-def:description>Checks sudoers Defaults ignore_dot configuration</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="ignore_dot is configured in /etc/sudoers or /etc/sudoers.d/" test_ref="oval:ssg-test_ignore_dot_sudoers:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudo_add_noexec:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Privileged Escalated Commands Cannot Execute Other Commands - sudo NOEXEC</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudo_add_noexec" source="ssg"/>
            <oval-def:description>Checks sudoers Defaults noexec configuration</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="noexec is configured in /etc/sudoers or /etc/sudoers.d/" test_ref="oval:ssg-test_noexec_sudoers:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudo_add_passwd_timeout:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure sudo passwd_timeout is appropriate - sudo passwd_timeout</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudo_add_passwd_timeout" source="ssg"/>
            <oval-def:description>Checks sudoers Defaults passwd_timeout configuration</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="passwd_timeout is configured in /etc/sudoers or /etc/sudoers.d/" test_ref="oval:ssg-test_passwd_timeout_sudoers:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudo_add_requiretty:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo requiretty</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudo_add_requiretty" source="ssg"/>
            <oval-def:description>Checks sudoers Defaults requiretty configuration</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="requiretty is configured in /etc/sudoers or /etc/sudoers.d/" test_ref="oval:ssg-test_requiretty_sudoers:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudo_add_umask:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure sudo umask is appropriate - sudo umask</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudo_add_umask" source="ssg"/>
            <oval-def:description>Checks sudoers Defaults umask configuration</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="umask is configured in /etc/sudoers or /etc/sudoers.d/" test_ref="oval:ssg-test_umask_sudoers:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudo_add_use_pty:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudo_add_use_pty" source="ssg"/>
            <oval-def:description>Checks sudoers Defaults use_pty configuration</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="use_pty is configured in /etc/sudoers or /etc/sudoers.d/" test_ref="oval:ssg-test_use_pty_sudoers:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudo_custom_logfile:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure Sudo Logfile Exists - sudo logfile</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudo_custom_logfile" source="ssg"/>
            <oval-def:description>Checks sudoers Defaults logfile configuration</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="logfile is configured in /etc/sudoers or /etc/sudoers.d/" test_ref="oval:ssg-test_logfile_sudoers:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sudo_restrict_others_executable_permission:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure only owner and members of group owner of /usr/bin/sudo can execute it</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sudo_restrict_others_executable_permission" source="ssg"/>
            <oval-def:description>This test makes sure that /usr/bin/sudo has mode 4110.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check file mode of /usr/bin/sudo" test_ref="oval:ssg-test_file_permissionssudo_restrict_others_executable_permission_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_fs_protected_hardlinks:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Enforce DAC on Hardlinks</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_fs_protected_hardlinks" source="ssg"/>
            <oval-def:description>The 'fs.protected_hardlinks' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="fs.protected_hardlinks configuration setting check" definition_ref="oval:ssg-sysctl_fs_protected_hardlinks_static:def:1"/>
            <oval-def:extend_definition comment="fs.protected_hardlinks runtime setting check" definition_ref="oval:ssg-sysctl_fs_protected_hardlinks_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_fs_protected_hardlinks_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Enforce DAC on Hardlinks</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_fs_protected_hardlinks_runtime" source="ssg"/>
            <oval-def:description>The kernel 'fs.protected_hardlinks' parameter should be set to 1 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter fs.protected_hardlinks set to 1" test_ref="oval:ssg-test_sysctl_fs_protected_hardlinks_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_fs_protected_hardlinks_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Enforce DAC on Hardlinks</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_fs_protected_hardlinks_static" source="ssg"/>
            <oval-def:description>The kernel 'fs.protected_hardlinks' parameter should be set to 1 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter fs.protected_hardlinks set to 1 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_fs_protected_hardlinks_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter fs.protected_hardlinks missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_fs_protected_hardlinks_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter fs.protected_hardlinks set to 1 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_fs_protected_hardlinks_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_fs_protected_symlinks:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Enforce DAC on Symlinks</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_fs_protected_symlinks" source="ssg"/>
            <oval-def:description>The 'fs.protected_symlinks' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="fs.protected_symlinks configuration setting check" definition_ref="oval:ssg-sysctl_fs_protected_symlinks_static:def:1"/>
            <oval-def:extend_definition comment="fs.protected_symlinks runtime setting check" definition_ref="oval:ssg-sysctl_fs_protected_symlinks_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_fs_protected_symlinks_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Enforce DAC on Symlinks</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_fs_protected_symlinks_runtime" source="ssg"/>
            <oval-def:description>The kernel 'fs.protected_symlinks' parameter should be set to 1 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter fs.protected_symlinks set to 1" test_ref="oval:ssg-test_sysctl_fs_protected_symlinks_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_fs_protected_symlinks_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Enforce DAC on Symlinks</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_fs_protected_symlinks_static" source="ssg"/>
            <oval-def:description>The kernel 'fs.protected_symlinks' parameter should be set to 1 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter fs.protected_symlinks set to 1 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_fs_protected_symlinks_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter fs.protected_symlinks missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_fs_protected_symlinks_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter fs.protected_symlinks set to 1 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_fs_protected_symlinks_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_fs_suid_dumpable:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Core Dumps for SUID programs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_fs_suid_dumpable" source="ssg"/>
            <oval-def:description>The 'fs.suid_dumpable' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="fs.suid_dumpable configuration setting check" definition_ref="oval:ssg-sysctl_fs_suid_dumpable_static:def:1"/>
            <oval-def:extend_definition comment="fs.suid_dumpable runtime setting check" definition_ref="oval:ssg-sysctl_fs_suid_dumpable_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_fs_suid_dumpable_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Core Dumps for SUID programs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_fs_suid_dumpable_runtime" source="ssg"/>
            <oval-def:description>The kernel 'fs.suid_dumpable' parameter should be set to 0 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter fs.suid_dumpable set to 0" test_ref="oval:ssg-test_sysctl_fs_suid_dumpable_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_fs_suid_dumpable_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Core Dumps for SUID programs</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_fs_suid_dumpable_static" source="ssg"/>
            <oval-def:description>The kernel 'fs.suid_dumpable' parameter should be set to 0 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter fs.suid_dumpable set to 0 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_fs_suid_dumpable_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter fs.suid_dumpable missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_fs_suid_dumpable_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter fs.suid_dumpable set to 0 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_fs_suid_dumpable_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_core_pattern:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable storing core dumps</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_core_pattern" source="ssg"/>
            <oval-def:description>The 'kernel.core_pattern' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="kernel.core_pattern configuration setting check" definition_ref="oval:ssg-sysctl_kernel_core_pattern_static:def:1"/>
            <oval-def:extend_definition comment="kernel.core_pattern runtime setting check" definition_ref="oval:ssg-sysctl_kernel_core_pattern_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_core_pattern_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable storing core dumps</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_core_pattern_runtime" source="ssg"/>
            <oval-def:description>The kernel 'kernel.core_pattern' parameter should be set to |/bin/false in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter kernel.core_pattern set to |/bin/false" test_ref="oval:ssg-test_sysctl_kernel_core_pattern_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_core_pattern_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable storing core dumps</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_core_pattern_static" source="ssg"/>
            <oval-def:description>The kernel 'kernel.core_pattern' parameter should be set to |/bin/false in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter kernel.core_pattern set to |/bin/false in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_core_pattern_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter kernel.core_pattern missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_core_pattern_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter kernel.core_pattern set to |/bin/false in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_kernel_core_pattern_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_core_uses_pid:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure file name of core dumps</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_core_uses_pid" source="ssg"/>
            <oval-def:description>The 'kernel.core_uses_pid' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="kernel.core_uses_pid configuration setting check" definition_ref="oval:ssg-sysctl_kernel_core_uses_pid_static:def:1"/>
            <oval-def:extend_definition comment="kernel.core_uses_pid runtime setting check" definition_ref="oval:ssg-sysctl_kernel_core_uses_pid_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_core_uses_pid_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure file name of core dumps</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_core_uses_pid_runtime" source="ssg"/>
            <oval-def:description>The kernel 'kernel.core_uses_pid' parameter should be set to 0 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter kernel.core_uses_pid set to 0" test_ref="oval:ssg-test_sysctl_kernel_core_uses_pid_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_core_uses_pid_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure file name of core dumps</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_core_uses_pid_static" source="ssg"/>
            <oval-def:description>The kernel 'kernel.core_uses_pid' parameter should be set to 0 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter kernel.core_uses_pid set to 0 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_core_uses_pid_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter kernel.core_uses_pid missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_core_uses_pid_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter kernel.core_uses_pid set to 0 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_kernel_core_uses_pid_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_dmesg_restrict:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Restrict Access to Kernel Message Buffer</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_dmesg_restrict" source="ssg"/>
            <oval-def:description>The 'kernel.dmesg_restrict' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="kernel.dmesg_restrict configuration setting check" definition_ref="oval:ssg-sysctl_kernel_dmesg_restrict_static:def:1"/>
            <oval-def:extend_definition comment="kernel.dmesg_restrict runtime setting check" definition_ref="oval:ssg-sysctl_kernel_dmesg_restrict_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_dmesg_restrict_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Restrict Access to Kernel Message Buffer</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_dmesg_restrict_runtime" source="ssg"/>
            <oval-def:description>The kernel 'kernel.dmesg_restrict' parameter should be set to 1 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter kernel.dmesg_restrict set to 1" test_ref="oval:ssg-test_sysctl_kernel_dmesg_restrict_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_dmesg_restrict_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Restrict Access to Kernel Message Buffer</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_dmesg_restrict_static" source="ssg"/>
            <oval-def:description>The kernel 'kernel.dmesg_restrict' parameter should be set to 1 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter kernel.dmesg_restrict set to 1 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_dmesg_restrict_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter kernel.dmesg_restrict missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_dmesg_restrict_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter kernel.dmesg_restrict set to 1 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_kernel_dmesg_restrict_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_kexec_load_disabled:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Image Loading</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_kexec_load_disabled" source="ssg"/>
            <oval-def:description>The 'kernel.kexec_load_disabled' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="kernel.kexec_load_disabled configuration setting check" definition_ref="oval:ssg-sysctl_kernel_kexec_load_disabled_static:def:1"/>
            <oval-def:extend_definition comment="kernel.kexec_load_disabled runtime setting check" definition_ref="oval:ssg-sysctl_kernel_kexec_load_disabled_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_kexec_load_disabled_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Image Loading</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_kexec_load_disabled_runtime" source="ssg"/>
            <oval-def:description>The kernel 'kernel.kexec_load_disabled' parameter should be set to 1 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter kernel.kexec_load_disabled set to 1" test_ref="oval:ssg-test_sysctl_kernel_kexec_load_disabled_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_kexec_load_disabled_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Image Loading</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_kexec_load_disabled_static" source="ssg"/>
            <oval-def:description>The kernel 'kernel.kexec_load_disabled' parameter should be set to 1 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter kernel.kexec_load_disabled set to 1 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_kexec_load_disabled_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter kernel.kexec_load_disabled missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_kexec_load_disabled_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter kernel.kexec_load_disabled set to 1 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_kernel_kexec_load_disabled_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_kptr_restrict:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Restrict Exposed Kernel Pointer Addresses Access</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_kptr_restrict" source="ssg"/>
            <oval-def:description>The 'kernel.kptr_restrict' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="kernel.kptr_restrict configuration setting check" definition_ref="oval:ssg-sysctl_kernel_kptr_restrict_static:def:1"/>
            <oval-def:extend_definition comment="kernel.kptr_restrict runtime setting check" definition_ref="oval:ssg-sysctl_kernel_kptr_restrict_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_kptr_restrict_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Restrict Exposed Kernel Pointer Addresses Access</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_kptr_restrict_runtime" source="ssg"/>
            <oval-def:description>The kernel 'kernel.kptr_restrict' parameter should be set to 1 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter kernel.kptr_restrict set to 1" test_ref="oval:ssg-test_sysctl_kernel_kptr_restrict_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_kptr_restrict_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Restrict Exposed Kernel Pointer Addresses Access</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_kptr_restrict_static" source="ssg"/>
            <oval-def:description>The kernel 'kernel.kptr_restrict' parameter should be set to 1 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter kernel.kptr_restrict set to 1 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_kptr_restrict_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter kernel.kptr_restrict missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_kptr_restrict_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter kernel.kptr_restrict set to 1 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_kernel_kptr_restrict_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_modules_disabled:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable loading and unloading of kernel modules</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_modules_disabled" source="ssg"/>
            <oval-def:description>The 'kernel.modules_disabled' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="kernel.modules_disabled configuration setting check" definition_ref="oval:ssg-sysctl_kernel_modules_disabled_static:def:1"/>
            <oval-def:extend_definition comment="kernel.modules_disabled runtime setting check" definition_ref="oval:ssg-sysctl_kernel_modules_disabled_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_modules_disabled_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable loading and unloading of kernel modules</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_modules_disabled_runtime" source="ssg"/>
            <oval-def:description>The kernel 'kernel.modules_disabled' parameter should be set to 1 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter kernel.modules_disabled set to 1" test_ref="oval:ssg-test_sysctl_kernel_modules_disabled_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_modules_disabled_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable loading and unloading of kernel modules</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_modules_disabled_static" source="ssg"/>
            <oval-def:description>The kernel 'kernel.modules_disabled' parameter should be set to 1 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter kernel.modules_disabled set to 1 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_modules_disabled_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter kernel.modules_disabled missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_modules_disabled_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter kernel.modules_disabled set to 1 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_kernel_modules_disabled_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_panic_on_oops:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Kernel panic on oops</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_panic_on_oops" source="ssg"/>
            <oval-def:description>The 'kernel.panic_on_oops' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="kernel.panic_on_oops configuration setting check" definition_ref="oval:ssg-sysctl_kernel_panic_on_oops_static:def:1"/>
            <oval-def:extend_definition comment="kernel.panic_on_oops runtime setting check" definition_ref="oval:ssg-sysctl_kernel_panic_on_oops_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_panic_on_oops_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Kernel panic on oops</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_panic_on_oops_runtime" source="ssg"/>
            <oval-def:description>The kernel 'kernel.panic_on_oops' parameter should be set to 1 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter kernel.panic_on_oops set to 1" test_ref="oval:ssg-test_sysctl_kernel_panic_on_oops_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_panic_on_oops_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Kernel panic on oops</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_panic_on_oops_static" source="ssg"/>
            <oval-def:description>The kernel 'kernel.panic_on_oops' parameter should be set to 1 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter kernel.panic_on_oops set to 1 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_panic_on_oops_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter kernel.panic_on_oops missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_panic_on_oops_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter kernel.panic_on_oops set to 1 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_kernel_panic_on_oops_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_perf_cpu_time_max_percent:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Limit CPU consumption of the Perf system</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_perf_cpu_time_max_percent" source="ssg"/>
            <oval-def:description>The 'kernel.perf_cpu_time_max_percent' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="kernel.perf_cpu_time_max_percent configuration setting check" definition_ref="oval:ssg-sysctl_kernel_perf_cpu_time_max_percent_static:def:1"/>
            <oval-def:extend_definition comment="kernel.perf_cpu_time_max_percent runtime setting check" definition_ref="oval:ssg-sysctl_kernel_perf_cpu_time_max_percent_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_perf_cpu_time_max_percent_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Limit CPU consumption of the Perf system</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_perf_cpu_time_max_percent_runtime" source="ssg"/>
            <oval-def:description>The kernel 'kernel.perf_cpu_time_max_percent' parameter should be set to 1 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter kernel.perf_cpu_time_max_percent set to 1" test_ref="oval:ssg-test_sysctl_kernel_perf_cpu_time_max_percent_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_perf_cpu_time_max_percent_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Limit CPU consumption of the Perf system</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_perf_cpu_time_max_percent_static" source="ssg"/>
            <oval-def:description>The kernel 'kernel.perf_cpu_time_max_percent' parameter should be set to 1 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter kernel.perf_cpu_time_max_percent set to 1 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_perf_cpu_time_max_percent_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter kernel.perf_cpu_time_max_percent missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_perf_cpu_time_max_percent_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter kernel.perf_cpu_time_max_percent set to 1 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_kernel_perf_cpu_time_max_percent_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_perf_event_max_sample_rate:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Limit sampling frequency of the Perf system</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_perf_event_max_sample_rate" source="ssg"/>
            <oval-def:description>The 'kernel.perf_event_max_sample_rate' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="kernel.perf_event_max_sample_rate configuration setting check" definition_ref="oval:ssg-sysctl_kernel_perf_event_max_sample_rate_static:def:1"/>
            <oval-def:extend_definition comment="kernel.perf_event_max_sample_rate runtime setting check" definition_ref="oval:ssg-sysctl_kernel_perf_event_max_sample_rate_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_perf_event_max_sample_rate_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Limit sampling frequency of the Perf system</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_perf_event_max_sample_rate_runtime" source="ssg"/>
            <oval-def:description>The kernel 'kernel.perf_event_max_sample_rate' parameter should be set to 1 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter kernel.perf_event_max_sample_rate set to 1" test_ref="oval:ssg-test_sysctl_kernel_perf_event_max_sample_rate_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_perf_event_max_sample_rate_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Limit sampling frequency of the Perf system</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_perf_event_max_sample_rate_static" source="ssg"/>
            <oval-def:description>The kernel 'kernel.perf_event_max_sample_rate' parameter should be set to 1 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter kernel.perf_event_max_sample_rate set to 1 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_perf_event_max_sample_rate_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter kernel.perf_event_max_sample_rate missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_perf_event_max_sample_rate_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter kernel.perf_event_max_sample_rate set to 1 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_kernel_perf_event_max_sample_rate_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_perf_event_paranoid:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disallow kernel profiling by unprivileged users</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_perf_event_paranoid" source="ssg"/>
            <oval-def:description>The 'kernel.perf_event_paranoid' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="kernel.perf_event_paranoid configuration setting check" definition_ref="oval:ssg-sysctl_kernel_perf_event_paranoid_static:def:1"/>
            <oval-def:extend_definition comment="kernel.perf_event_paranoid runtime setting check" definition_ref="oval:ssg-sysctl_kernel_perf_event_paranoid_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_perf_event_paranoid_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disallow kernel profiling by unprivileged users</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_perf_event_paranoid_runtime" source="ssg"/>
            <oval-def:description>The kernel 'kernel.perf_event_paranoid' parameter should be set to 2 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter kernel.perf_event_paranoid set to 2" test_ref="oval:ssg-test_sysctl_kernel_perf_event_paranoid_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_perf_event_paranoid_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disallow kernel profiling by unprivileged users</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_perf_event_paranoid_static" source="ssg"/>
            <oval-def:description>The kernel 'kernel.perf_event_paranoid' parameter should be set to 2 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter kernel.perf_event_paranoid set to 2 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_perf_event_paranoid_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter kernel.perf_event_paranoid missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_perf_event_paranoid_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter kernel.perf_event_paranoid set to 2 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_kernel_perf_event_paranoid_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_pid_max:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure maximum number of process identifiers</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_pid_max" source="ssg"/>
            <oval-def:description>The 'kernel.pid_max' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="kernel.pid_max configuration setting check" definition_ref="oval:ssg-sysctl_kernel_pid_max_static:def:1"/>
            <oval-def:extend_definition comment="kernel.pid_max runtime setting check" definition_ref="oval:ssg-sysctl_kernel_pid_max_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_pid_max_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure maximum number of process identifiers</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_pid_max_runtime" source="ssg"/>
            <oval-def:description>The kernel 'kernel.pid_max' parameter should be set to 65536 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter kernel.pid_max set to 65536" test_ref="oval:ssg-test_sysctl_kernel_pid_max_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_pid_max_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure maximum number of process identifiers</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_pid_max_static" source="ssg"/>
            <oval-def:description>The kernel 'kernel.pid_max' parameter should be set to 65536 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter kernel.pid_max set to 65536 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_pid_max_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter kernel.pid_max missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_pid_max_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter kernel.pid_max set to 65536 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_kernel_pid_max_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_randomize_va_space:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Randomized Layout of Virtual Address Space</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_randomize_va_space" source="ssg"/>
            <oval-def:description>The 'kernel.randomize_va_space' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="kernel.randomize_va_space configuration setting check" definition_ref="oval:ssg-sysctl_kernel_randomize_va_space_static:def:1"/>
            <oval-def:extend_definition comment="kernel.randomize_va_space runtime setting check" definition_ref="oval:ssg-sysctl_kernel_randomize_va_space_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_randomize_va_space_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Randomized Layout of Virtual Address Space</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_randomize_va_space_runtime" source="ssg"/>
            <oval-def:description>The kernel 'kernel.randomize_va_space' parameter should be set to 2 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter kernel.randomize_va_space set to 2" test_ref="oval:ssg-test_sysctl_kernel_randomize_va_space_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_randomize_va_space_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Randomized Layout of Virtual Address Space</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_randomize_va_space_static" source="ssg"/>
            <oval-def:description>The kernel 'kernel.randomize_va_space' parameter should be set to 2 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter kernel.randomize_va_space set to 2 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_randomize_va_space_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter kernel.randomize_va_space missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_randomize_va_space_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter kernel.randomize_va_space set to 2 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_kernel_randomize_va_space_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_sysrq:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disallow magic SysRq key</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_sysrq" source="ssg"/>
            <oval-def:description>The 'kernel.sysrq' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="kernel.sysrq configuration setting check" definition_ref="oval:ssg-sysctl_kernel_sysrq_static:def:1"/>
            <oval-def:extend_definition comment="kernel.sysrq runtime setting check" definition_ref="oval:ssg-sysctl_kernel_sysrq_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_sysrq_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disallow magic SysRq key</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_sysrq_runtime" source="ssg"/>
            <oval-def:description>The kernel 'kernel.sysrq' parameter should be set to 0 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter kernel.sysrq set to 0" test_ref="oval:ssg-test_sysctl_kernel_sysrq_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_sysrq_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disallow magic SysRq key</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_sysrq_static" source="ssg"/>
            <oval-def:description>The kernel 'kernel.sysrq' parameter should be set to 0 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter kernel.sysrq set to 0 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_sysrq_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter kernel.sysrq missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_sysrq_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter kernel.sysrq set to 0 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_kernel_sysrq_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_unprivileged_bpf_disabled:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Access to Network bpf() Syscall From Unprivileged Processes</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_unprivileged_bpf_disabled" source="ssg"/>
            <oval-def:description>The 'kernel.unprivileged_bpf_disabled' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="kernel.unprivileged_bpf_disabled configuration setting check" definition_ref="oval:ssg-sysctl_kernel_unprivileged_bpf_disabled_static:def:1"/>
            <oval-def:extend_definition comment="kernel.unprivileged_bpf_disabled runtime setting check" definition_ref="oval:ssg-sysctl_kernel_unprivileged_bpf_disabled_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_unprivileged_bpf_disabled_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Access to Network bpf() Syscall From Unprivileged Processes</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_unprivileged_bpf_disabled_runtime" source="ssg"/>
            <oval-def:description>The kernel 'kernel.unprivileged_bpf_disabled' parameter should be set to 1 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter kernel.unprivileged_bpf_disabled set to 1" test_ref="oval:ssg-test_sysctl_kernel_unprivileged_bpf_disabled_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_unprivileged_bpf_disabled_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Access to Network bpf() Syscall From Unprivileged Processes</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_unprivileged_bpf_disabled_static" source="ssg"/>
            <oval-def:description>The kernel 'kernel.unprivileged_bpf_disabled' parameter should be set to 1 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter kernel.unprivileged_bpf_disabled set to 1 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_unprivileged_bpf_disabled_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter kernel.unprivileged_bpf_disabled missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_unprivileged_bpf_disabled_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter kernel.unprivileged_bpf_disabled set to 1 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_kernel_unprivileged_bpf_disabled_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_yama_ptrace_scope:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Restrict usage of ptrace to descendant processes</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_yama_ptrace_scope" source="ssg"/>
            <oval-def:description>The 'kernel.yama.ptrace_scope' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="kernel.yama.ptrace_scope configuration setting check" definition_ref="oval:ssg-sysctl_kernel_yama_ptrace_scope_static:def:1"/>
            <oval-def:extend_definition comment="kernel.yama.ptrace_scope runtime setting check" definition_ref="oval:ssg-sysctl_kernel_yama_ptrace_scope_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_yama_ptrace_scope_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Restrict usage of ptrace to descendant processes</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_yama_ptrace_scope_runtime" source="ssg"/>
            <oval-def:description>The kernel 'kernel.yama.ptrace_scope' parameter should be set to 1 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter kernel.yama.ptrace_scope set to 1" test_ref="oval:ssg-test_sysctl_kernel_yama_ptrace_scope_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_yama_ptrace_scope_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Restrict usage of ptrace to descendant processes</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_yama_ptrace_scope_static" source="ssg"/>
            <oval-def:description>The kernel 'kernel.yama.ptrace_scope' parameter should be set to 1 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter kernel.yama.ptrace_scope set to 1 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_yama_ptrace_scope_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter kernel.yama.ptrace_scope missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_yama_ptrace_scope_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter kernel.yama.ptrace_scope set to 1 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_kernel_yama_ptrace_scope_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_core_bpf_jit_harden:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Harden the operation of the BPF just-in-time compiler</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_core_bpf_jit_harden" source="ssg"/>
            <oval-def:description>The 'net.core.bpf_jit_harden' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.core.bpf_jit_harden configuration setting check" definition_ref="oval:ssg-sysctl_net_core_bpf_jit_harden_static:def:1"/>
            <oval-def:extend_definition comment="net.core.bpf_jit_harden runtime setting check" definition_ref="oval:ssg-sysctl_net_core_bpf_jit_harden_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_core_bpf_jit_harden_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Harden the operation of the BPF just-in-time compiler</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_core_bpf_jit_harden_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.core.bpf_jit_harden' parameter should be set to 2 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.core.bpf_jit_harden set to 2" test_ref="oval:ssg-test_sysctl_net_core_bpf_jit_harden_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_core_bpf_jit_harden_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Harden the operation of the BPF just-in-time compiler</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_core_bpf_jit_harden_static" source="ssg"/>
            <oval-def:description>The kernel 'net.core.bpf_jit_harden' parameter should be set to 2 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.core.bpf_jit_harden set to 2 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_core_bpf_jit_harden_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.core.bpf_jit_harden missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_core_bpf_jit_harden_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.core.bpf_jit_harden set to 2 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_core_bpf_jit_harden_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_accept_local:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Accepting Packets Routed Between Local Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_accept_local" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.all.accept_local' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.all.accept_local configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_accept_local_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.all.accept_local runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_accept_local_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_accept_local_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Accepting Packets Routed Between Local Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_accept_local_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.accept_local' parameter should be set to 0 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.all.accept_local set to 0" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_local_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_accept_local_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Accepting Packets Routed Between Local Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_accept_local_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.accept_local' parameter should be set to 0 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.accept_local set to 0 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_local_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.accept_local missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_local_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.accept_local set to 0 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_local_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_accept_redirects:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Accepting ICMP Redirects for All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_accept_redirects" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.all.accept_redirects' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.all.accept_redirects configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_accept_redirects_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.all.accept_redirects runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_accept_redirects_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_accept_redirects_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Accepting ICMP Redirects for All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_accept_redirects_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.accept_redirects' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.all.accept_redirects set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_redirects_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_accept_redirects_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Accepting ICMP Redirects for All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_accept_redirects_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.accept_redirects' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.accept_redirects set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_redirects_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.accept_redirects missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_redirects_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.accept_redirects set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_redirects_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_accept_source_route:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_accept_source_route" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.all.accept_source_route' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.all.accept_source_route configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_accept_source_route_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.all.accept_source_route runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_accept_source_route_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_accept_source_route_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_accept_source_route_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.accept_source_route' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.all.accept_source_route set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_source_route_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_accept_source_route_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_accept_source_route_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.accept_source_route' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.accept_source_route set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_source_route_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.accept_source_route missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_source_route_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.accept_source_route set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_source_route_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_arp_filter:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure ARP filtering for All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_arp_filter" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.all.arp_filter' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.all.arp_filter configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_arp_filter_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.all.arp_filter runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_arp_filter_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_arp_filter_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure ARP filtering for All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_arp_filter_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.arp_filter' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.all.arp_filter set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_arp_filter_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_arp_filter_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure ARP filtering for All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_arp_filter_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.arp_filter' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.arp_filter set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_arp_filter_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.arp_filter missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_arp_filter_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.arp_filter set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_arp_filter_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_arp_ignore:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Response Mode of ARP Requests for All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_arp_ignore" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.all.arp_ignore' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.all.arp_ignore configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_arp_ignore_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.all.arp_ignore runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_arp_ignore_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_arp_ignore_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Response Mode of ARP Requests for All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_arp_ignore_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.arp_ignore' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.all.arp_ignore set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_arp_ignore_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_arp_ignore_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Response Mode of ARP Requests for All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_arp_ignore_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.arp_ignore' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.arp_ignore set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_arp_ignore_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.arp_ignore missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_arp_ignore_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.arp_ignore set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_arp_ignore_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_drop_gratuitous_arp:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Drop Gratuitous ARP frames on All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_drop_gratuitous_arp" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.all.drop_gratuitous_arp' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.all.drop_gratuitous_arp configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_drop_gratuitous_arp_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.all.drop_gratuitous_arp runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_drop_gratuitous_arp_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_drop_gratuitous_arp_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Drop Gratuitous ARP frames on All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_drop_gratuitous_arp_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.drop_gratuitous_arp' parameter should be set to 1 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.all.drop_gratuitous_arp set to 1" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_drop_gratuitous_arp_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_drop_gratuitous_arp_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Drop Gratuitous ARP frames on All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_drop_gratuitous_arp_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.drop_gratuitous_arp' parameter should be set to 1 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.drop_gratuitous_arp set to 1 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_drop_gratuitous_arp_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.drop_gratuitous_arp missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_drop_gratuitous_arp_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.drop_gratuitous_arp set to 1 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_drop_gratuitous_arp_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_forwarding:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_forwarding" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.all.forwarding' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.all.forwarding configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_forwarding_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.all.forwarding runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_forwarding_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_forwarding_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_forwarding_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.forwarding' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.all.forwarding set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_forwarding_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_forwarding_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_forwarding_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.forwarding' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.forwarding set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_forwarding_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.forwarding missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_forwarding_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.forwarding set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_forwarding_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_log_martians:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_log_martians" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.all.log_martians' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.all.log_martians configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_log_martians_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.all.log_martians runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_log_martians_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_log_martians_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_log_martians_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.log_martians' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.all.log_martians set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_log_martians_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_log_martians_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_log_martians_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.log_martians' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.log_martians set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_log_martians_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.log_martians missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_log_martians_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.log_martians set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_log_martians_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_route_localnet:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Prevent Routing External Traffic to Local Loopback on All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_route_localnet" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.all.route_localnet' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.all.route_localnet configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_route_localnet_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.all.route_localnet runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_route_localnet_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_route_localnet_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Prevent Routing External Traffic to Local Loopback on All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_route_localnet_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.route_localnet' parameter should be set to 0 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.all.route_localnet set to 0" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_route_localnet_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_route_localnet_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Prevent Routing External Traffic to Local Loopback on All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_route_localnet_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.route_localnet' parameter should be set to 0 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.route_localnet set to 0 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_route_localnet_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.route_localnet missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_route_localnet_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.route_localnet set to 0 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_route_localnet_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_rp_filter:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_rp_filter" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.all.rp_filter' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.all.rp_filter configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_rp_filter_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.all.rp_filter runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_rp_filter_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_rp_filter_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_rp_filter_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.rp_filter' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.all.rp_filter set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_rp_filter_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_rp_filter_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_rp_filter_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.rp_filter' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.rp_filter set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_rp_filter_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.rp_filter missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_rp_filter_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.rp_filter set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_rp_filter_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_secure_redirects:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_secure_redirects" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.all.secure_redirects' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.all.secure_redirects configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_secure_redirects_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.all.secure_redirects runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_secure_redirects_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_secure_redirects_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_secure_redirects_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.secure_redirects' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.all.secure_redirects set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_secure_redirects_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_secure_redirects_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_secure_redirects_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.secure_redirects' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.secure_redirects set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_secure_redirects_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.secure_redirects missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_secure_redirects_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.secure_redirects set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_secure_redirects_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_send_redirects:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_send_redirects" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.all.send_redirects' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.all.send_redirects configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_send_redirects_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.all.send_redirects runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_send_redirects_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_send_redirects_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_send_redirects_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.send_redirects' parameter should be set to 0 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.all.send_redirects set to 0" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_send_redirects_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_send_redirects_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_send_redirects_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.send_redirects' parameter should be set to 0 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.send_redirects set to 0 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_send_redirects_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.send_redirects missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_send_redirects_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.send_redirects set to 0 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_send_redirects_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_shared_media:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Sending and Accepting Shared Media Redirects for All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_shared_media" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.all.shared_media' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.all.shared_media configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_shared_media_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.all.shared_media runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_all_shared_media_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_shared_media_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Sending and Accepting Shared Media Redirects for All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_shared_media_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.shared_media' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.all.shared_media set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_shared_media_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_all_shared_media_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Sending and Accepting Shared Media Redirects for All IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_all_shared_media_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.all.shared_media' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.shared_media set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_shared_media_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.shared_media missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_shared_media_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.all.shared_media set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_all_shared_media_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_accept_redirects:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_accept_redirects" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.default.accept_redirects' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.default.accept_redirects configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_default_accept_redirects_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.default.accept_redirects runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_default_accept_redirects_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_accept_redirects_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_accept_redirects_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.default.accept_redirects' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.default.accept_redirects set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_accept_redirects_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_accept_redirects_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_accept_redirects_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.default.accept_redirects' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.accept_redirects set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_accept_redirects_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.accept_redirects missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_accept_redirects_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.accept_redirects set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_accept_redirects_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_accept_source_route:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_accept_source_route" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.default.accept_source_route' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.default.accept_source_route configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_default_accept_source_route_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.default.accept_source_route runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_default_accept_source_route_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_accept_source_route_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_accept_source_route_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.default.accept_source_route' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.default.accept_source_route set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_accept_source_route_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_accept_source_route_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_accept_source_route_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.default.accept_source_route' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.accept_source_route set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_accept_source_route_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.accept_source_route missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_accept_source_route_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.accept_source_route set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_accept_source_route_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_forwarding:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for IPv4 Forwarding By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_forwarding" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.default.forwarding' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.default.forwarding configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_default_forwarding_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.default.forwarding runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_default_forwarding_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_forwarding_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for IPv4 Forwarding By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_forwarding_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.default.forwarding' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.default.forwarding set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_forwarding_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_forwarding_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for IPv4 Forwarding By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_forwarding_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.default.forwarding' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.forwarding set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_forwarding_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.forwarding missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_forwarding_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.forwarding set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_forwarding_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_log_martians:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_log_martians" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.default.log_martians' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.default.log_martians configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_default_log_martians_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.default.log_martians runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_default_log_martians_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_log_martians_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_log_martians_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.default.log_martians' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.default.log_martians set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_log_martians_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_log_martians_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_log_martians_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.default.log_martians' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.log_martians set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_log_martians_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.log_martians missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_log_martians_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.log_martians set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_log_martians_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_rp_filter:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_rp_filter" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.default.rp_filter' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.default.rp_filter configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_default_rp_filter_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.default.rp_filter runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_default_rp_filter_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_rp_filter_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_rp_filter_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.default.rp_filter' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.default.rp_filter set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_rp_filter_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_rp_filter_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_rp_filter_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.default.rp_filter' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.rp_filter set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_rp_filter_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.rp_filter missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_rp_filter_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.rp_filter set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_rp_filter_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_secure_redirects:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Kernel Parameter for Accepting Secure Redirects By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_secure_redirects" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.default.secure_redirects' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.default.secure_redirects configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_default_secure_redirects_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.default.secure_redirects runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_default_secure_redirects_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_secure_redirects_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Kernel Parameter for Accepting Secure Redirects By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_secure_redirects_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.default.secure_redirects' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.default.secure_redirects set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_secure_redirects_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_secure_redirects_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Kernel Parameter for Accepting Secure Redirects By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_secure_redirects_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.default.secure_redirects' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.secure_redirects set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_secure_redirects_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.secure_redirects missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_secure_redirects_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.secure_redirects set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_secure_redirects_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_send_redirects:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_send_redirects" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.default.send_redirects' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.default.send_redirects configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_default_send_redirects_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.default.send_redirects runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_default_send_redirects_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_send_redirects_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_send_redirects_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.default.send_redirects' parameter should be set to 0 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.default.send_redirects set to 0" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_send_redirects_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_send_redirects_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_send_redirects_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.default.send_redirects' parameter should be set to 0 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.send_redirects set to 0 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_send_redirects_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.send_redirects missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_send_redirects_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.send_redirects set to 0 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_send_redirects_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_shared_media:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Sending and Accepting Shared Media Redirects by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_shared_media" source="ssg"/>
            <oval-def:description>The 'net.ipv4.conf.default.shared_media' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.conf.default.shared_media configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_default_shared_media_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.conf.default.shared_media runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_conf_default_shared_media_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_shared_media_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Sending and Accepting Shared Media Redirects by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_shared_media_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.default.shared_media' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.conf.default.shared_media set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_shared_media_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_conf_default_shared_media_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Sending and Accepting Shared Media Redirects by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_conf_default_shared_media_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.conf.default.shared_media' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.shared_media set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_shared_media_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.shared_media missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_shared_media_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.conf.default.shared_media set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_conf_default_shared_media_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_icmp_echo_ignore_broadcasts" source="ssg"/>
            <oval-def:description>The 'net.ipv4.icmp_echo_ignore_broadcasts' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.icmp_echo_ignore_broadcasts configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.icmp_echo_ignore_broadcasts runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_icmp_echo_ignore_broadcasts_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.icmp_echo_ignore_broadcasts' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.icmp_echo_ignore_broadcasts set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_icmp_echo_ignore_broadcasts_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.icmp_echo_ignore_broadcasts' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.icmp_echo_ignore_broadcasts set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.icmp_echo_ignore_broadcasts missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.icmp_echo_ignore_broadcasts set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_icmp_ignore_bogus_error_responses" source="ssg"/>
            <oval-def:description>The 'net.ipv4.icmp_ignore_bogus_error_responses' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.icmp_ignore_bogus_error_responses configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.icmp_ignore_bogus_error_responses runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_icmp_ignore_bogus_error_responses_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.icmp_ignore_bogus_error_responses' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.icmp_ignore_bogus_error_responses set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_icmp_ignore_bogus_error_responses_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.icmp_ignore_bogus_error_responses' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.icmp_ignore_bogus_error_responses set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.icmp_ignore_bogus_error_responses missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.icmp_ignore_bogus_error_responses set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_ip_forward:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_ip_forward" source="ssg"/>
            <oval-def:description>The 'net.ipv4.ip_forward' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.ip_forward configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_ip_forward_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.ip_forward runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_ip_forward_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_ip_forward_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_ip_forward_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.ip_forward' parameter should be set to 0 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.ip_forward set to 0" test_ref="oval:ssg-test_sysctl_net_ipv4_ip_forward_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_ip_forward_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_ip_forward_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.ip_forward' parameter should be set to 0 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.ip_forward set to 0 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_ip_forward_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.ip_forward missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_ip_forward_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.ip_forward set to 0 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_ip_forward_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_ip_local_port_range:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Set Kernel Parameter to Increase Local Port Range</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_ip_local_port_range" source="ssg"/>
            <oval-def:description>The 'net.ipv4.ip_local_port_range' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.ip_local_port_range configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_ip_local_port_range_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.ip_local_port_range runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_ip_local_port_range_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_ip_local_port_range_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Set Kernel Parameter to Increase Local Port Range</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_ip_local_port_range_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.ip_local_port_range' parameter should be set to 32768 65535 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.ip_local_port_range set to 32768 65535" test_ref="oval:ssg-test_sysctl_net_ipv4_ip_local_port_range_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_ip_local_port_range_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Set Kernel Parameter to Increase Local Port Range</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_ip_local_port_range_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.ip_local_port_range' parameter should be set to 32768 65535 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.ip_local_port_range set to 32768 65535 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_ip_local_port_range_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.ip_local_port_range missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_ip_local_port_range_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.ip_local_port_range set to 32768 65535 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_ip_local_port_range_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_tcp_invalid_ratelimit:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Kernel to Rate Limit Sending of Duplicate TCP Acknowledgments</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_tcp_invalid_ratelimit" source="ssg"/>
            <oval-def:description>The 'net.ipv4.tcp_invalid_ratelimit' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.tcp_invalid_ratelimit configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_tcp_invalid_ratelimit_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.tcp_invalid_ratelimit runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_tcp_invalid_ratelimit_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_tcp_invalid_ratelimit_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Kernel to Rate Limit Sending of Duplicate TCP Acknowledgments</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_tcp_invalid_ratelimit_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.tcp_invalid_ratelimit' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.tcp_invalid_ratelimit set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_tcp_invalid_ratelimit_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_tcp_invalid_ratelimit_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Kernel to Rate Limit Sending of Duplicate TCP Acknowledgments</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_tcp_invalid_ratelimit_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.tcp_invalid_ratelimit' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.tcp_invalid_ratelimit set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_tcp_invalid_ratelimit_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.tcp_invalid_ratelimit missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_tcp_invalid_ratelimit_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.tcp_invalid_ratelimit set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_tcp_invalid_ratelimit_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_tcp_rfc1337:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Use TCP RFC 1337 on IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_tcp_rfc1337" source="ssg"/>
            <oval-def:description>The 'net.ipv4.tcp_rfc1337' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.tcp_rfc1337 configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_tcp_rfc1337_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.tcp_rfc1337 runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_tcp_rfc1337_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_tcp_rfc1337_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Use TCP RFC 1337 on IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_tcp_rfc1337_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.tcp_rfc1337' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.tcp_rfc1337 set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_tcp_rfc1337_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_tcp_rfc1337_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Use TCP RFC 1337 on IPv4 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_tcp_rfc1337_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.tcp_rfc1337' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.tcp_rfc1337 set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_tcp_rfc1337_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.tcp_rfc1337 missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_tcp_rfc1337_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.tcp_rfc1337 set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_tcp_rfc1337_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_tcp_syncookies:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_tcp_syncookies" source="ssg"/>
            <oval-def:description>The 'net.ipv4.tcp_syncookies' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="net.ipv4.tcp_syncookies configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_tcp_syncookies_static:def:1"/>
            <oval-def:extend_definition comment="net.ipv4.tcp_syncookies runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_tcp_syncookies_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_tcp_syncookies_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_tcp_syncookies_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.tcp_syncookies' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv4.tcp_syncookies set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_tcp_syncookies_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv4_tcp_syncookies_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv4_tcp_syncookies_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv4.tcp_syncookies' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv4.tcp_syncookies set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_tcp_syncookies_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv4.tcp_syncookies missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_tcp_syncookies_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv4.tcp_syncookies set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_tcp_syncookies_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Router Advertisements on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_ra" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_ra' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.all.accept_ra set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.all.accept_ra configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.all.accept_ra runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Router Advertisements on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_ra_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_ra' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.all.accept_ra set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Router Advertisements on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_ra_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_ra' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_ra set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_ra missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_ra set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_ra_defrtr" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_ra_defrtr' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.all.accept_ra_defrtr set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.all.accept_ra_defrtr configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.all.accept_ra_defrtr runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_ra_defrtr_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_ra_defrtr' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.all.accept_ra_defrtr set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_defrtr_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_ra_defrtr_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_ra_defrtr' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_ra_defrtr set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_defrtr_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_ra_defrtr missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_defrtr_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_ra_defrtr set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_defrtr_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Prefix Information in Router Advertisements on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_ra_pinfo" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_ra_pinfo' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.all.accept_ra_pinfo set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.all.accept_ra_pinfo configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.all.accept_ra_pinfo runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Prefix Information in Router Advertisements on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_ra_pinfo_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_ra_pinfo' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.all.accept_ra_pinfo set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_pinfo_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Prefix Information in Router Advertisements on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_ra_pinfo_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_ra_pinfo' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_ra_pinfo set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_pinfo_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_ra_pinfo missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_pinfo_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_ra_pinfo set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_pinfo_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Router Preference in Router Advertisements on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_ra_rtr_pref" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_ra_rtr_pref' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.all.accept_ra_rtr_pref set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.all.accept_ra_rtr_pref configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.all.accept_ra_rtr_pref runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Router Preference in Router Advertisements on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_ra_rtr_pref' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.all.accept_ra_rtr_pref set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Router Preference in Router Advertisements on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_ra_rtr_pref' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_ra_rtr_pref set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_ra_rtr_pref missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_ra_rtr_pref set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_redirects:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Disable Accepting ICMP Redirects for All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_redirects" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_redirects' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.all.accept_redirects set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.all.accept_redirects configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_redirects_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.all.accept_redirects runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_redirects_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_redirects_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Accepting ICMP Redirects for All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_redirects_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_redirects' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.all.accept_redirects set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_redirects_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_redirects_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Accepting ICMP Redirects for All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_redirects_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_redirects' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_redirects set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_redirects_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_redirects missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_redirects_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_redirects set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_redirects_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_source_route:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_source_route" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_source_route' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.all.accept_source_route set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.all.accept_source_route configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_source_route_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.all.accept_source_route runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_source_route_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_source_route_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_source_route_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_source_route' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.all.accept_source_route set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_source_route_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_source_route_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_accept_source_route_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.accept_source_route' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_source_route set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_source_route_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_source_route missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_source_route_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.accept_source_route set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_source_route_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_autoconf:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Configure Auto Configuration on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_autoconf" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.autoconf' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.all.autoconf set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.all.autoconf configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_autoconf_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.all.autoconf runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_autoconf_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_autoconf_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Auto Configuration on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_autoconf_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.autoconf' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.all.autoconf set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_autoconf_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_autoconf_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Auto Configuration on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_autoconf_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.autoconf' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.autoconf set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_autoconf_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.autoconf missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_autoconf_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.autoconf set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_autoconf_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_disable_ipv6:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Disable IPv6 Addressing on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_disable_ipv6" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.disable_ipv6' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.all.disable_ipv6 set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.all.disable_ipv6 configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.all.disable_ipv6 runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable IPv6 Addressing on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_disable_ipv6_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.disable_ipv6' parameter should be set to 1 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.all.disable_ipv6 set to 1" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_disable_ipv6_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable IPv6 Addressing on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_disable_ipv6_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.disable_ipv6' parameter should be set to 1 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.disable_ipv6 set to 1 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_disable_ipv6_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.disable_ipv6 missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_disable_ipv6_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.disable_ipv6 set to 1 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_disable_ipv6_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_forwarding:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for IPv6 Forwarding</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_forwarding" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.forwarding' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.all.forwarding set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.all.forwarding configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_forwarding_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.all.forwarding runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_forwarding_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_forwarding_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for IPv6 Forwarding</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_forwarding_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.forwarding' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.all.forwarding set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_forwarding_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_forwarding_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for IPv6 Forwarding</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_forwarding_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.forwarding' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.forwarding set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_forwarding_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.forwarding missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_forwarding_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.forwarding set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_forwarding_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_max_addresses:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_max_addresses" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.max_addresses' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.all.max_addresses set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.all.max_addresses configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_max_addresses_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.all.max_addresses runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_max_addresses_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_max_addresses_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_max_addresses_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.max_addresses' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.all.max_addresses set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_max_addresses_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_max_addresses_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_max_addresses_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.max_addresses' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.max_addresses set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_max_addresses_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.max_addresses missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_max_addresses_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.max_addresses set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_max_addresses_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_router_solicitations:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Configure Denying Router Solicitations on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_router_solicitations" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.router_solicitations' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.all.router_solicitations set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.all.router_solicitations configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_router_solicitations_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.all.router_solicitations runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_router_solicitations_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_router_solicitations_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Denying Router Solicitations on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_router_solicitations_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.router_solicitations' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.all.router_solicitations set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_router_solicitations_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_all_router_solicitations_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Denying Router Solicitations on All IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_all_router_solicitations_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.all.router_solicitations' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.router_solicitations set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_router_solicitations_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.router_solicitations missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_router_solicitations_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.all.router_solicitations set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_all_router_solicitations_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Disable Accepting Router Advertisements on all IPv6 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_ra" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_ra' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.default.accept_ra set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.default.accept_ra configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.default.accept_ra runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Accepting Router Advertisements on all IPv6 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_ra_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_ra' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.default.accept_ra set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Accepting Router Advertisements on all IPv6 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_ra_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_ra' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_ra set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_ra missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_ra set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_ra_defrtr" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_ra_defrtr' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.default.accept_ra_defrtr set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.default.accept_ra_defrtr configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.default.accept_ra_defrtr runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_ra_defrtr_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_ra_defrtr' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.default.accept_ra_defrtr set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_defrtr_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_ra_defrtr_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_ra_defrtr' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_ra_defrtr set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_defrtr_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_ra_defrtr missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_defrtr_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_ra_defrtr set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_defrtr_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Prefix Information in Router Advertisements on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_ra_pinfo" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_ra_pinfo' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.default.accept_ra_pinfo set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.default.accept_ra_pinfo configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.default.accept_ra_pinfo runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Prefix Information in Router Advertisements on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_ra_pinfo_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_ra_pinfo' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.default.accept_ra_pinfo set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_pinfo_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Prefix Information in Router Advertisements on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_ra_pinfo_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_ra_pinfo' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_ra_pinfo set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_pinfo_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_ra_pinfo missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_pinfo_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_ra_pinfo set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_pinfo_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Router Preference in Router Advertisements on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_ra_rtr_pref" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_ra_rtr_pref' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.default.accept_ra_rtr_pref set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.default.accept_ra_rtr_pref configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.default.accept_ra_rtr_pref runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Router Preference in Router Advertisements on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_ra_rtr_pref' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.default.accept_ra_rtr_pref set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Accepting Router Preference in Router Advertisements on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_ra_rtr_pref' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_ra_rtr_pref set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_ra_rtr_pref missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_ra_rtr_pref set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_redirects:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_redirects" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_redirects' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.default.accept_redirects set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.default.accept_redirects configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_redirects_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.default.accept_redirects runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_redirects_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_redirects_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_redirects_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_redirects' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.default.accept_redirects set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_redirects_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_redirects_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_redirects_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_redirects' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_redirects set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_redirects_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_redirects missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_redirects_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_redirects set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_redirects_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_source_route:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_source_route" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_source_route' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.default.accept_source_route set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.default.accept_source_route configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_source_route_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.default.accept_source_route runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_source_route_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_source_route_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_source_route_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_source_route' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.default.accept_source_route set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_source_route_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_source_route_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_accept_source_route_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.accept_source_route' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_source_route set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_source_route_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_source_route missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_source_route_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.accept_source_route set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_source_route_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_autoconf:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Configure Auto Configuration on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_autoconf" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.autoconf' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.default.autoconf set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.default.autoconf configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_autoconf_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.default.autoconf runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_autoconf_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_autoconf_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Auto Configuration on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_autoconf_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.autoconf' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.default.autoconf set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_autoconf_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_autoconf_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Auto Configuration on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_autoconf_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.autoconf' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.autoconf set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_autoconf_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.autoconf missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_autoconf_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.autoconf set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_autoconf_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_disable_ipv6:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Disable IPv6 Addressing on IPv6 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_disable_ipv6" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.disable_ipv6' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.default.disable_ipv6 set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.default.disable_ipv6 configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.default.disable_ipv6 runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable IPv6 Addressing on IPv6 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_disable_ipv6_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.disable_ipv6' parameter should be set to 1 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.default.disable_ipv6 set to 1" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_disable_ipv6_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable IPv6 Addressing on IPv6 Interfaces by Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_disable_ipv6_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.disable_ipv6' parameter should be set to 1 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.disable_ipv6 set to 1 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_disable_ipv6_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.disable_ipv6 missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_disable_ipv6_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.disable_ipv6 set to 1 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_disable_ipv6_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_forwarding:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for IPv6 Forwarding by default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_forwarding" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.forwarding' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.default.forwarding set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.default.forwarding configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_forwarding_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.default.forwarding runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_forwarding_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_forwarding_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for IPv6 Forwarding by default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_forwarding_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.forwarding' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.default.forwarding set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_forwarding_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_forwarding_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable Kernel Parameter for IPv6 Forwarding by default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_forwarding_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.forwarding' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.forwarding set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_forwarding_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.forwarding missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_forwarding_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.forwarding set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_forwarding_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_max_addresses:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_max_addresses" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.max_addresses' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.default.max_addresses set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.default.max_addresses configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_max_addresses_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.default.max_addresses runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_max_addresses_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_max_addresses_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_max_addresses_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.max_addresses' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.default.max_addresses set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_max_addresses_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_max_addresses_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_max_addresses_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.max_addresses' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.max_addresses set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_max_addresses_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.max_addresses missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_max_addresses_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.max_addresses set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_max_addresses_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_router_solicitations:def:1" version="4">
          <oval-def:metadata>
            <oval-def:title>Configure Denying Router Solicitations on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_router_solicitations" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.router_solicitations' parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.default.router_solicitations set correctly" operator="OR">
            <oval-def:extend_definition comment="is IPv6 enabled?" definition_ref="oval:ssg-sysctl_kernel_ipv6_disable:def:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.default.router_solicitations configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_router_solicitations_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.default.router_solicitations runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_default_router_solicitations_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_router_solicitations_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Denying Router Solicitations on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_router_solicitations_runtime" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.router_solicitations' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter net.ipv6.conf.default.router_solicitations set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_router_solicitations_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_net_ipv6_conf_default_router_solicitations_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Configure Denying Router Solicitations on All IPv6 Interfaces By Default</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_net_ipv6_conf_default_router_solicitations_static" source="ssg"/>
            <oval-def:description>The kernel 'net.ipv6.conf.default.router_solicitations' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.router_solicitations set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_router_solicitations_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.router_solicitations missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_router_solicitations_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter net.ipv6.conf.default.router_solicitations set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv6_conf_default_router_solicitations_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_user_max_user_namespaces:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable the use of user namespaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_user_max_user_namespaces" source="ssg"/>
            <oval-def:description>The 'user.max_user_namespaces' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="user.max_user_namespaces configuration setting check" definition_ref="oval:ssg-sysctl_user_max_user_namespaces_static:def:1"/>
            <oval-def:extend_definition comment="user.max_user_namespaces runtime setting check" definition_ref="oval:ssg-sysctl_user_max_user_namespaces_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_user_max_user_namespaces_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable the use of user namespaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_user_max_user_namespaces_runtime" source="ssg"/>
            <oval-def:description>The kernel 'user.max_user_namespaces' parameter should be set to 0 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter user.max_user_namespaces set to 0" test_ref="oval:ssg-test_sysctl_user_max_user_namespaces_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_user_max_user_namespaces_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable the use of user namespaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_user_max_user_namespaces_static" source="ssg"/>
            <oval-def:description>The kernel 'user.max_user_namespaces' parameter should be set to 0 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter user.max_user_namespaces set to 0 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_user_max_user_namespaces_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter user.max_user_namespaces missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_user_max_user_namespaces_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter user.max_user_namespaces set to 0 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_user_max_user_namespaces_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_user_max_user_namespaces_no_remediation:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable the use of user namespaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_user_max_user_namespaces_no_remediation" source="ssg"/>
            <oval-def:description>The 'user.max_user_namespaces' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="user.max_user_namespaces configuration setting check" definition_ref="oval:ssg-sysctl_user_max_user_namespaces_no_remediation_static:def:1"/>
            <oval-def:extend_definition comment="user.max_user_namespaces runtime setting check" definition_ref="oval:ssg-sysctl_user_max_user_namespaces_no_remediation_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_user_max_user_namespaces_no_remediation_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable the use of user namespaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_user_max_user_namespaces_no_remediation_runtime" source="ssg"/>
            <oval-def:description>The kernel 'user.max_user_namespaces' parameter should be set to 0 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter user.max_user_namespaces set to 0" test_ref="oval:ssg-test_sysctl_user_max_user_namespaces_no_remediation_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_user_max_user_namespaces_no_remediation_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Disable the use of user namespaces</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_user_max_user_namespaces_no_remediation_static" source="ssg"/>
            <oval-def:description>The kernel 'user.max_user_namespaces' parameter should be set to 0 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter user.max_user_namespaces set to 0 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_user_max_user_namespaces_no_remediation_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter user.max_user_namespaces missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_user_max_user_namespaces_no_remediation_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter user.max_user_namespaces set to 0 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_user_max_user_namespaces_no_remediation_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_vm_mmap_min_addr:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Prevent applications from mapping low portion of virtual memory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_vm_mmap_min_addr" source="ssg"/>
            <oval-def:description>The 'vm.mmap_min_addr' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="vm.mmap_min_addr configuration setting check" definition_ref="oval:ssg-sysctl_vm_mmap_min_addr_static:def:1"/>
            <oval-def:extend_definition comment="vm.mmap_min_addr runtime setting check" definition_ref="oval:ssg-sysctl_vm_mmap_min_addr_runtime:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_vm_mmap_min_addr_runtime:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Prevent applications from mapping low portion of virtual memory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_vm_mmap_min_addr_runtime" source="ssg"/>
            <oval-def:description>The kernel 'vm.mmap_min_addr' parameter should be set to 65536 in the system runtime.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel runtime parameter vm.mmap_min_addr set to 65536" test_ref="oval:ssg-test_sysctl_vm_mmap_min_addr_runtime:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_vm_mmap_min_addr_static:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Prevent applications from mapping low portion of virtual memory</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_vm_mmap_min_addr_static" source="ssg"/>
            <oval-def:description>The kernel 'vm.mmap_min_addr' parameter should be set to 65536 in the system configuration.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel static parameter vm.mmap_min_addr set to 65536 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_vm_mmap_min_addr_static_user:tst:1"/>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="kernel static parameter vm.mmap_min_addr missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_vm_mmap_min_addr_static_user_missing:tst:1"/>
              <oval-def:criterion comment="kernel static parameter vm.mmap_min_addr set to 65536 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_vm_mmap_min_addr_static_pkg_correct:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-systemd_tmp_mount_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ensure tmp.mount Unit Is Enabled</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="systemd_tmp_mount_enabled" source="ssg"/>
            <oval-def:description>The tmp mount should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="mount tmp is configured to start and is running" operator="AND">
            <oval-def:criterion comment="tmp is running" test_ref="oval:ssg-test_mount_running_tmp:tst:1"/>
            <oval-def:criterion comment="multi-user.target wants tmp" test_ref="oval:ssg-test_multi_user_wants_tmp:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-timer_dnf-automatic_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable dnf-automatic Timer</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="timer_dnf-automatic_enabled" source="ssg"/>
            <oval-def:description>The dnf-automatic timer should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package dnf-automatic installed and timer dnf-automatic is configured to start" operator="AND">
            <oval-def:extend_definition comment="dnf-automatic installed" definition_ref="oval:ssg-package_dnf-automatic_installed:def:1"/>
            <oval-def:criteria comment="timer dnf-automatic is configured to start and is running" operator="AND">
              <oval-def:criterion comment="dnf-automatic is running" test_ref="oval:ssg-test_timer_running_dnf-automatic:tst:1"/>
              <oval-def:criterion comment="multi-user.target wants dnf-automatic" test_ref="oval:ssg-test_multi_user_wants_dnf-automatic:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-timer_logrotate_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable logrotate Timer</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="timer_logrotate_enabled" source="ssg"/>
            <oval-def:description>The logrotate timer should be enabled if possible.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package logrotate installed and timer logrotate is configured to start" operator="AND">
            <oval-def:extend_definition comment="logrotate installed" definition_ref="oval:ssg-package_logrotate_installed:def:1"/>
            <oval-def:criteria comment="timer logrotate is configured to start and is running" operator="AND">
              <oval-def:criterion comment="logrotate is running" test_ref="oval:ssg-test_timer_running_logrotate:tst:1"/>
              <oval-def:criterion comment="multi-user.target wants logrotate" test_ref="oval:ssg-test_multi_user_wants_logrotate:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-use_pam_wheel_for_su:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enforce usage of pam_wheel for su authentication</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="use_pam_wheel_for_su" source="ssg"/>
            <oval-def:description>Configure PAM module</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Make sure arguments are properly configured in /etc/pam.d/su" operator="AND">
            <oval-def:criterion comment="Verify use_uid is set to the desired state" test_ref="oval:ssg-test_pam_auth_pam_wheel_use_uid:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-use_pam_wheel_group_for_su:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Enforce Usage of pam_wheel with Group Parameter for su Authentication</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="use_pam_wheel_group_for_su" source="ssg"/>
            <oval-def:description>Configure PAM module</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Make sure arguments are properly configured in /etc/pam.d/su" operator="AND">
            <oval-def:criterion comment="Verify group is set to the desired state" test_ref="oval:ssg-test_pam_auth_pam_wheel_group:tst:1"/>
            <oval-def:criterion comment="Verify use_uid is set to the desired state" test_ref="oval:ssg-test_pam_auth_pam_wheel_use_uid:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-zipl_audit_argument:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable Auditing to Start Prior to the Audit Daemon in zIPL</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="zipl_audit_argument" source="ssg"/>
            <oval-def:description>Ensure audit=1 option is configured in the 'options' line in /boot/loader/entries/*.conf. Make sure that newly installed kernels will retain this option, it should be configured in /etc/kernel/cmdline as well.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check if argument audit=1 for Linux kernel is present in /boot/loader/entries/.*.conf" test_ref="oval:ssg-test_zipl_audit_argument_audit_1_argument_in_boot_loader_entries_conf:tst:1"/>
            <oval-def:criterion comment="Check if argument audit=1 for Linux kernel is present in /etc/kernel/cmdline" test_ref="oval:ssg-test_zipl_audit_argument_audit_1_argument_in_etc_kernel_cmdline:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-zipl_audit_backlog_limit_argument:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Extend Audit Backlog Limit for the Audit Daemon in zIPL</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="zipl_audit_backlog_limit_argument" source="ssg"/>
            <oval-def:description>Ensure audit_backlog_limit=8192 option is configured in the 'options' line in /boot/loader/entries/*.conf. Make sure that newly installed kernels will retain this option, it should be configured in /etc/kernel/cmdline as well.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check if argument audit_backlog_limit=8192 for Linux kernel is present in /boot/loader/entries/.*.conf" test_ref="oval:ssg-test_zipl_audit_backlog_limit_argument_audit_backlog_limit_8192_argument_in_boot_loader_entries_conf:tst:1"/>
            <oval-def:criterion comment="Check if argument audit_backlog_limit=8192 for Linux kernel is present in /etc/kernel/cmdline" test_ref="oval:ssg-test_zipl_audit_backlog_limit_argument_audit_backlog_limit_8192_argument_in_etc_kernel_cmdline:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-zipl_page_poison_argument:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable page allocator poisoning in zIPL</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="zipl_page_poison_argument" source="ssg"/>
            <oval-def:description>Ensure page_poison=1 option is configured in the 'options' line in /boot/loader/entries/*.conf. Make sure that newly installed kernels will retain this option, it should be configured in /etc/kernel/cmdline as well.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check if argument page_poison=1 for Linux kernel is present in /boot/loader/entries/.*.conf" test_ref="oval:ssg-test_zipl_page_poison_argument_page_poison_1_argument_in_boot_loader_entries_conf:tst:1"/>
            <oval-def:criterion comment="Check if argument page_poison=1 for Linux kernel is present in /etc/kernel/cmdline" test_ref="oval:ssg-test_zipl_page_poison_argument_page_poison_1_argument_in_etc_kernel_cmdline:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-zipl_slub_debug_argument:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Enable SLUB/SLAB allocator poisoning in zIPL</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="zipl_slub_debug_argument" source="ssg"/>
            <oval-def:description>Ensure slub_debug=P option is configured in the 'options' line in /boot/loader/entries/*.conf. Make sure that newly installed kernels will retain this option, it should be configured in /etc/kernel/cmdline as well.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check if argument slub_debug=P for Linux kernel is present in /boot/loader/entries/.*.conf" test_ref="oval:ssg-test_zipl_slub_debug_argument_slub_debug_P_argument_in_boot_loader_entries_conf:tst:1"/>
            <oval-def:criterion comment="Check if argument slub_debug=P for Linux kernel is present in /etc/kernel/cmdline" test_ref="oval:ssg-test_zipl_slub_debug_argument_slub_debug_P_argument_in_etc_kernel_cmdline:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-zipl_vsyscall_argument:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Disable vsyscalls in zIPL</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="zipl_vsyscall_argument" source="ssg"/>
            <oval-def:description>Ensure vsyscall=none option is configured in the 'options' line in /boot/loader/entries/*.conf. Make sure that newly installed kernels will retain this option, it should be configured in /etc/kernel/cmdline as well.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check if argument vsyscall=none for Linux kernel is present in /boot/loader/entries/.*.conf" test_ref="oval:ssg-test_zipl_vsyscall_argument_vsyscall_none_argument_in_boot_loader_entries_conf:tst:1"/>
            <oval-def:criterion comment="Check if argument vsyscall=none for Linux kernel is present in /etc/kernel/cmdline" test_ref="oval:ssg-test_zipl_vsyscall_argument_vsyscall_none_argument_in_etc_kernel_cmdline:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-accounts_password_pam_pwquality:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Check pam_pwquality Existence in system-auth</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="accounts_password_pam_pwquality" source="ssg"/>
            <oval-def:description>Check that pam_pwquality.so exists in system-auth</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Conditions for pam_pwquality are satisfied" test_ref="oval:ssg-test_password_pam_pwquality:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_auditctl:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Test if auditctl is in use for audit rules</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_auditctl" source="ssg"/>
            <oval-def:description>Test if auditctl is in use for audit rules.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="audit auditctl" test_ref="oval:ssg-test_audit_rules_auditctl:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_augenrules:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Test if augenrules is enabled for audit rules</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_augenrules" source="ssg"/>
            <oval-def:description>Test if augenrules is enabled for audit rules.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="audit augenrules" test_ref="oval:ssg-test_audit_rules_augenrules:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_networkconfig_modification_domainname:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Network Environment</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_networkconfig_modification_domainname" source="ssg"/>
            <oval-def:description>The network environment should not be modified by anything other than
      administrator action. Any change to network parameters should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit setdomainname" test_ref="oval:ssg-test_32bit_setdomainname_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit setdomainname" test_ref="oval:ssg-test_64bit_setdomainname_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit setdomainname" test_ref="oval:ssg-test_32bit_setdomainname_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit setdomainname" test_ref="oval:ssg-test_64bit_setdomainname_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-audit_rules_networkconfig_modification_hostname:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Record Events that Modify the System's Network Environment</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="audit_rules_networkconfig_modification_hostname" source="ssg"/>
            <oval-def:description>The network environment should not be modified by anything other than
      administrator action. Any change to network parameters should be audited.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit augenrules" definition_ref="oval:ssg-audit_rules_augenrules:def:1"/>
              <oval-def:criterion comment="audit augenrules 32-bit sethostname" test_ref="oval:ssg-test_32bit_sethostname_augenrules:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit augenrules 64-bit sethostname" test_ref="oval:ssg-test_64bit_sethostname_augenrules:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="audit auditctl" definition_ref="oval:ssg-audit_rules_auditctl:def:1"/>
              <oval-def:criterion comment="audit auditctl 32-bit sethostname" test_ref="oval:ssg-test_32bit_sethostname_auditctl:tst:1"/>
              <oval-def:criteria operator="OR">
                <oval-def:extend_definition comment="64-bit system" definition_ref="oval:ssg-system_info_architecture_64bit:def:1" negate="true"/>
                <oval-def:criterion comment="audit auditctl 64-bit sethostname" test_ref="oval:ssg-test_64bit_sethostname_auditctl:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_conf_log_file_not_set:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>'log_file' Not Set In /etc/audit/auditd.conf</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_conf_log_file_not_set" source="ssg"/>
            <oval-def:description>Verify 'log_file' is not set in /etc/audit/auditd.conf.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Verify 'log_file' not set in /etc/audit/auditd.conf" test_ref="oval:ssg-test_auditd_conf_log_file_not_set:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-auditd_conf_log_group_not_root:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>'log_group' Not Set To 'root' In /etc/audit/auditd.conf</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="auditd_conf_log_group_not_root" source="ssg"/>
            <oval-def:description>Verify 'log_group' is not set to 'root' in
      /etc/audit/auditd.conf.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Verify 'log_group' not set to 'root' in /etc/audit/auditd.conf" test_ref="oval:ssg-test_auditd_conf_log_group_not_root:tst:1"/>
            <oval-def:criterion comment="Verify 'log_group' is set in /etc/audit/auditd.conf" test_ref="oval:ssg-test_auditd_conf_log_group_is_set:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-bootc:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title/>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="bootc" source="ssg"/>
            <oval-def:description>Bootable container or bootc system</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel is installed" test_ref="oval:ssg-bootc_platform_test_kernel_installed:tst:1"/>
            <oval-def:criterion comment="rpm-ostree is installed" test_ref="oval:ssg-bootc_platform_test_rpm_ostree_installed:tst:1"/>
            <oval-def:criterion comment="bootc is installed" test_ref="oval:ssg-bootc_platform_test_bootc_installed:tst:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="/run/ostree-booted exists, suggesting that we are in a running bootc environment" test_ref="oval:ssg-bootc_platform_test_run_ostree_booted_exists:tst:1"/>
              <oval-def:criterion comment="/ostree symlink exists, suggesting that we are in a bootc environment being built and hardened" test_ref="oval:ssg-bootc_platform_test_ostree_symlink_exists:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="openshift-kubelet is not installed" test_ref="oval:ssg-bootc_platform_test_openshift_kubelet_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-bootloader_disable_recovery_set_to_true:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Verify GRUB_DISABLE_RECOVERY Set to true</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="bootloader_disable_recovery_set_to_true" source="ssg"/>
            <oval-def:description>GRUB_DISABLE_RECOVERY set to 'true' in
      /etc/default/grub</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" test_ref="oval:ssg-test_bootloader_disable_recovery_set_to_true:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-chronyd_specify_multiple_servers:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Specify Multiple Remote chronyd NTP Servers for Time Data</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="chronyd_specify_multiple_servers" source="ssg"/>
            <oval-def:description>Multiple chronyd NTP Servers for time synchronization should be specified.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="chrony.conf conditions are met" operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_chronyd_multiple_servers:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_almalinux8:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>AlmaLinux OS 8</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/o:almalinux:almalinux:8" source="CPE"/>
            <oval-def:reference ref_id="installed_OS_is_almalinux8" source="ssg"/>
            <oval-def:description>The operating system installed on the system is AlmaLinux OS 8</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="current OS is 8" operator="AND">
            <oval-def:extend_definition comment="Installed OS is part of the Unix family" definition_ref="oval:ssg-installed_OS_is_part_of_Unix_family:def:1"/>
            <oval-def:criterion comment="AlmaLinux OS is installed" test_ref="oval:ssg-test_almalinux:tst:1"/>
            <oval-def:criterion comment="AlmaLinux OS 8 is installed" test_ref="oval:ssg-test_almalinux8:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_hummingbird:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>Installed operating system is hummingbird</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/a:redhat:hummingbird" source="CPE"/>
            <oval-def:reference ref_id="installed_OS_is_hummingbird" source="ssg"/>
            <oval-def:description>The operating system installed on the system is hummingbird</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Installed OS is part of the Unix family" definition_ref="oval:ssg-installed_OS_is_part_of_Unix_family:def:1"/>
            <oval-def:criterion comment="hummingbird-release RPM packages are installed" test_ref="oval:ssg-test_hummingbird_release_rpm:tst:1"/>
            <oval-def:criterion comment="CPE vendor is 'redhat' and product is 'hummingbird'" test_ref="oval:ssg-test_hummingbird_vendor_product:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_ol7:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Oracle Linux 7</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/o:oracle:linux:7" source="CPE"/>
            <oval-def:reference ref_id="installed_OS_is_ol7" source="ssg"/>
            <oval-def:description>The operating system installed on the system is
      Oracle Linux 7</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Installed OS is part of the Unix family" definition_ref="oval:ssg-installed_OS_is_part_of_Unix_family:def:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="Oracle Linux 7 System is installed" test_ref="oval:ssg-test_ol7_system:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_ol8:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Oracle Linux 8</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/o:oracle:linux:8" source="CPE"/>
            <oval-def:reference ref_id="installed_OS_is_ol8" source="ssg"/>
            <oval-def:description>The operating system installed on the system is
      Oracle Linux 8</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Installed OS is part of the Unix family" definition_ref="oval:ssg-installed_OS_is_part_of_Unix_family:def:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="Oracle Linux 8 System is installed" test_ref="oval:ssg-test_ol8_system:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_ol9:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Oracle Linux 9</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/o:oracle:linux:9" source="CPE"/>
            <oval-def:reference ref_id="installed_OS_is_ol9" source="ssg"/>
            <oval-def:description>The operating system installed on the system is
      Oracle Linux 9</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Installed OS is part of the Unix family" definition_ref="oval:ssg-installed_OS_is_part_of_Unix_family:def:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="Oracle Linux 9 System is installed" test_ref="oval:ssg-test_ol9_system:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_part_of_Unix_family:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Installed operating system is part of the Unix family</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="installed_OS_is_part_of_Unix_family" source="ssg"/>
            <oval-def:description>The operating system installed on the system is part of the Unix OS family</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Installed operating system is part of the unix family" test_ref="oval:ssg-test_unix_family:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_rhcos4:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Red Hat Enterprise Linux CoreOS</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/o:redhat:enterprise_linux_coreos:4" source="CPE"/>
            <oval-def:reference ref_id="installed_OS_is_rhcos4" source="ssg"/>
            <oval-def:description>The operating system installed on the system is
      Red Hat Enterprise Linux CoreOS release 4</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="CoreOS variant" test_ref="oval:ssg-test_rhel_coreos_variant:tst:1"/>
              <oval-def:criterion comment="RHCOS version 4 is installed" test_ref="oval:ssg-test_rhcos4:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="RHCOS is installed (ID='rhcos')" test_ref="oval:ssg-test_rhcos:tst:1"/>
              <oval-def:criterion comment="RHEL_VERSION is 8" test_ref="oval:ssg-test_rhcos4_rhel8_rhel_version:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="RHCOS is installed (ID='rhcos')" test_ref="oval:ssg-test_rhcos:tst:1"/>
              <oval-def:criterion comment="RHEL_VERSION is 9" test_ref="oval:ssg-test_rhcos4_rhel9_rhel_version:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="ID is rhel" test_ref="oval:ssg-test_rhel_id:tst:1"/>
              <oval-def:criterion comment="Major version is 9" test_ref="oval:ssg-test_rhel_coreos_version9:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="ID is rhel" test_ref="oval:ssg-test_rhel_id:tst:1"/>
              <oval-def:criterion comment="Major version is 10" test_ref="oval:ssg-test_rhel_coreos_version10:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_rhel10:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Red Hat Enterprise Linux 10</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/o:redhat:enterprise_linux:10" source="CPE"/>
            <oval-def:reference ref_id="installed_OS_is_rhel10" source="ssg"/>
            <oval-def:description>The operating system installed on the system is
      Red Hat Enterprise Linux 10</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Installed operating system is part of the unix family" test_ref="oval:ssg-test_rhel10_unix_family:tst:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="RHEL 10 is installed" test_ref="oval:ssg-test_rhel10:tst:1"/>
              <oval-def:criteria comment="Red Hat Enterprise Virtualization Host is installed" operator="AND">
                <oval-def:criterion comment="Red Hat Virtualization Host (RHVH)" test_ref="oval:ssg-test_rhvh4_version:tst:1"/>
                <oval-def:criterion comment="Red Hat Enterprise Virtualization Host is based on RHEL 10" test_ref="oval:ssg-test_rhevh_rhel10_version:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_rhel8:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Red Hat Enterprise Linux 8</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/o:redhat:enterprise_linux:8" source="CPE"/>
            <oval-def:reference ref_id="installed_OS_is_rhel8" source="ssg"/>
            <oval-def:description>The operating system installed on the system is
      Red Hat Enterprise Linux 8</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Installed operating system is part of the unix family" test_ref="oval:ssg-test_rhel8_unix_family:tst:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criteria comment="RHEL 8 is installed" operator="AND">
                <oval-def:criterion comment="RHEL 8 is installed" test_ref="oval:ssg-test_rhel8:tst:1"/>
                <oval-def:extend_definition comment="Installed OS is not OL8" definition_ref="oval:ssg-installed_OS_is_ol8:def:1" negate="true"/>
              </oval-def:criteria>
              <oval-def:criteria comment="Red Hat Enterprise Virtualization Host is installed" operator="AND">
                <oval-def:criterion comment="Red Hat Virtualization Host (RHVH)" test_ref="oval:ssg-test_rhvh4_version:tst:1"/>
                <oval-def:criterion comment="Red Hat Enterprise Virtualization Host is based on RHEL 8" test_ref="oval:ssg-test_rhevh_rhel8_version:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_rhel9:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Red Hat Enterprise Linux 9</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/o:redhat:enterprise_linux:9" source="CPE"/>
            <oval-def:reference ref_id="installed_OS_is_rhel9" source="ssg"/>
            <oval-def:description>The operating system installed on the system is
      Red Hat Enterprise Linux 9</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Installed operating system is part of the unix family" test_ref="oval:ssg-test_rhel9_unix_family:tst:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criteria comment="RHEL 9 is installed" operator="AND">
                <oval-def:criterion comment="RHEL 9 is installed" test_ref="oval:ssg-test_rhel9:tst:1"/>
                <oval-def:extend_definition comment="Installed OS is not OL9" definition_ref="oval:ssg-installed_OS_is_ol9:def:1" negate="true"/>
              </oval-def:criteria>
              <oval-def:criteria comment="Red Hat Enterprise Virtualization Host is installed" operator="AND">
                <oval-def:criterion comment="Red Hat Virtualization Host (RHVH)" test_ref="oval:ssg-test_rhvh4_version:tst:1"/>
                <oval-def:criterion comment="Red Hat Enterprise Virtualization Host is based on RHEL 9" test_ref="oval:ssg-test_rhevh_rhel9_version:tst:1"/>
              </oval-def:criteria>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_sle12:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>SUSE Linux Enterprise 12</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/o:suse:linux_enterprise_server:12" source="CPE"/>
            <oval-def:reference ref_id="cpe:/o:suse:linux_enterprise_desktop:12" source="CPE"/>
            <oval-def:reference ref_id="installed_OS_is_sle12" source="ssg"/>
            <oval-def:description>The operating system installed on the system is
      SUSE Linux Enterprise 12.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Installed operating system is part of the unix family" test_ref="oval:ssg-test_sle12_unix_family:tst:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="SLE 12 Desktop is installed" test_ref="oval:ssg-test_sle12_desktop:tst:1"/>
              <oval-def:criterion comment="SLE 12 Server is installed" test_ref="oval:ssg-test_sle12_server:tst:1"/>
              <oval-def:criterion comment="SLES 12 for SAP Applications is installed" test_ref="oval:ssg-test_sles_12_for_sap:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_sle15:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>SUSE Linux Enterprise 15</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/o:suse:linux_enterprise_server:15" source="CPE"/>
            <oval-def:reference ref_id="cpe:/o:suse:linux_enterprise_desktop:15" source="CPE"/>
            <oval-def:reference ref_id="installed_OS_is_sle15" source="ssg"/>
            <oval-def:description>The operating system installed on the system is
      SUSE Linux Enterprise 15.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Installed operating system is part of the unix family" test_ref="oval:ssg-test_sle15_unix_family:tst:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="SLE 15 Desktop is installed" test_ref="oval:ssg-test_sle15_desktop:tst:1"/>
              <oval-def:criterion comment="SLE 15 Server is installed" test_ref="oval:ssg-test_sle15_server:tst:1"/>
              <oval-def:criterion comment="SLES 15 for SAP Applications is installed" test_ref="oval:ssg-test_sles_15_for_sap:tst:1"/>
              <oval-def:criterion comment="SUSE Manager 4 is installed" test_ref="oval:ssg-test_suma_4:tst:1"/>
              <oval-def:criterion comment="SLE HPC is installed" test_ref="oval:ssg-test_sle_hpc:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_sle16:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>SUSE Linux Enterprise 16</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/o:suse:linux_enterprise_server:16" source="CPE"/>
            <oval-def:reference ref_id="installed_OS_is_sle16" source="ssg"/>
            <oval-def:description>The operating system installed on the system is SUSE Linux Enterprise Server 16.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Installed operating system is part of the unix family" test_ref="oval:ssg-test_sle16_unix_family:tst:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="SLE 16 Server is installed" test_ref="oval:ssg-test_sle16_server:tst:1"/>
              <oval-def:criterion comment="SLES 16 for SAP Applications is installed" test_ref="oval:ssg-test_sles_16_for_sap:tst:1"/>
              <oval-def:criterion comment="SLES 16 for High Availability Extension is installed" test_ref="oval:ssg-test_sles_16_for_ha:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_slmicro5:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>SUSE Linux Enterprise Micro</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/o:suse:suse-microos:5.2" source="CPE"/>
            <oval-def:reference ref_id="cpe:/o:suse:sle-micro:5.3" source="CPE"/>
            <oval-def:reference ref_id="cpe:/o:suse:sle-micro:5.4" source="CPE"/>
            <oval-def:reference ref_id="cpe:/o:suse:sle-micro:5.5" source="CPE"/>
            <oval-def:reference ref_id="installed_OS_is_slmicro5" source="ssg"/>
            <oval-def:description>The operating system installed on the system is
                SUSE Linux Enterprise Micro.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Installed operating system is part of the unix family" test_ref="oval:ssg-test_slmicro5_unix_family:tst:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="SUSE MicroOS 5.* is installed" test_ref="oval:ssg-test_slmicroos5:tst:1"/>
              <oval-def:criterion comment="SLE Micro 5.* is installed" test_ref="oval:ssg-test_slmicro5:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_slmicro6:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>SUSE Linux Enterprise Micro</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/o:suse:sl-micro:6.0" source="CPE"/>
            <oval-def:reference ref_id="cpe:/o:suse:sl-micro:6.1" source="CPE"/>
            <oval-def:reference ref_id="installed_OS_is_slmicro6" source="ssg"/>
            <oval-def:description>The operating system installed on the system is
                SUSE Linux Micro.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Installed operating system is part of the unix family" test_ref="oval:ssg-test_slmicro6_unix_family:tst:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="SLE Micro 6.* is installed" test_ref="oval:ssg-test_slmicro6:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_ubuntu:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ubuntu</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="installed_OS_is_ubuntu" source="ssg"/>
            <oval-def:description>The operating system installed is an Ubuntu System</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="System is Ubuntu" operator="AND">
            <oval-def:extend_definition comment="Installed OS is part of the Unix family" definition_ref="oval:ssg-installed_OS_is_part_of_Unix_family:def:1"/>
            <oval-def:criterion comment="lsb-based distrib" test_ref="oval:ssg-test_lsb:tst:1"/>
            <oval-def:criterion comment="Ubuntu is installed" test_ref="oval:ssg-test_ubuntu:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_ubuntu2204:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ubuntu 22.04 LTS</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/o:canonical:ubuntu_linux:22.04" source="CPE"/>
            <oval-def:reference ref_id="installed_OS_is_ubuntu2204" source="ssg"/>
            <oval-def:description>The operating system installed on the system is Ubuntu 22.04 LTS</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="current Ubuntu version is Jammy" operator="AND">
            <oval-def:extend_definition comment="Ubuntu is installed" definition_ref="oval:ssg-installed_OS_is_ubuntu:def:1"/>
            <oval-def:criterion comment="Jammy is installed" test_ref="oval:ssg-test_ubuntu_jammy:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_ubuntu2404:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Ubuntu 24.04 LTS</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/o:canonical:ubuntu_linux:24.04" source="CPE"/>
            <oval-def:reference ref_id="installed_OS_is_ubuntu2404" source="ssg"/>
            <oval-def:description>The operating system installed on the system is Ubuntu 24.04 LTS</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="current Ubuntu version is Noble" operator="AND">
            <oval-def:extend_definition comment="Ubuntu is installed" definition_ref="oval:ssg-installed_OS_is_ubuntu:def:1"/>
            <oval-def:criterion comment="Noble is installed" test_ref="oval:ssg-test_ubuntu_noble:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-no_cd_dvd_drive_in_etc_fstab:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>No CD/DVD drive is configured to automount in /etc/fstab</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="no_cd_dvd_drive_in_etc_fstab" source="ssg"/>
            <oval-def:description>Check the /etc/fstab and check if a CD/DVD drive
      is not configured for automount.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check if CD/DVD drive is not configured to automout in /etc/fstab" test_ref="oval:ssg-test_no_cd_dvd_drive_in_etc_fstab:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-removable_partition_doesnt_exist:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Device Files for Removable Media Partitions Does Not Exist on the System</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="removable_partition_doesnt_exist" source="ssg"/>
            <oval-def:description>Verify if device file representing removable partitions
      exist on the system</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check if removable partition really exists on the system" test_ref="oval:ssg-test_removable_partition_doesnt_exist:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_not_required_or_unset:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>SSHD is not required to be installed or requirement not set</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_not_required_or_unset" source="ssg"/>
            <oval-def:description>If SSHD is not required, we check it is not installed. If SSH requirement is unset, we are good.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="SSH not required or not set" operator="OR">
            <oval-def:criterion test_ref="oval:ssg-test_sshd_not_required:tst:1"/>
            <oval-def:extend_definition comment="SSH requirement is unset" definition_ref="oval:ssg-sshd_requirement_unset:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_required_or_unset:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>SSHD is required to be installed or requirement not set</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_required_or_unset" source="ssg"/>
            <oval-def:description>If SSHD is required, we check it is installed. If SSH requirement is unset, we are good.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="SSH required or not set" operator="OR">
            <oval-def:criterion test_ref="oval:ssg-test_sshd_required:tst:1"/>
            <oval-def:extend_definition comment="SSH requirement is unset" definition_ref="oval:ssg-sshd_requirement_unset:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sshd_requirement_unset:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>It doesn't matter if sshd is installed or not</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sshd_requirement_unset" source="ssg"/>
            <oval-def:description>Test if value sshd_required is 0.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_sshd_requirement_unset:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-sysctl_kernel_ipv6_disable:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Kernel Runtime Parameter IPv6 Check</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="sysctl_kernel_ipv6_disable" source="ssg"/>
            <oval-def:description>Disables IPv6 for all network interfaces.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="IPv6 disabled or net.ipv6.conf.all.disable_ipv6 set correctly" operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:extend_definition comment="net.ipv6.conf.all.disable_ipv6 configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_static:def:1"/>
              <oval-def:extend_definition comment="net.ipv6.conf.all.disable_ipv6 runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_runtime:def:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-system_info_architecture_64bit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Test for 64-bit Architecture</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="system_info_architecture_64bit" source="ssg"/>
            <oval-def:description>Generic test for 64-bit architectures to be used by other tests</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:extend_definition comment="Generic test for x86_64 architecture" definition_ref="oval:ssg-system_info_architecture_x86_64:def:1"/>
            <oval-def:extend_definition comment="Generic test for ppc64 architecture" definition_ref="oval:ssg-system_info_architecture_ppc_64:def:1"/>
            <oval-def:extend_definition comment="Generic test for aarch64 architecture" definition_ref="oval:ssg-system_info_architecture_aarch_64:def:1"/>
            <oval-def:extend_definition comment="Generic test for s390x architecture" definition_ref="oval:ssg-system_info_architecture_s390_64:def:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-system_info_architecture_aarch_64:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Test for aarch_64 Architecture</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="system_info_architecture_aarch_64" source="ssg"/>
            <oval-def:description>Generic test for aarch_64 architecture to be used by other tests</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Generic test for aarch_64 architecture" test_ref="oval:ssg-test_system_info_architecture_aarch_64:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-system_info_architecture_ppc_64:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Test for PPC and PPCLE Architecture</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="system_info_architecture_ppc_64" source="ssg"/>
            <oval-def:description>Generic test for PPC PPC64LE architecture to be used by other tests</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="Generic test for ppc64 architecture" test_ref="oval:ssg-test_system_info_architecture_ppc_64:tst:1"/>
            <oval-def:criterion comment="Generic test for ppcle64 architecture" test_ref="oval:ssg-test_system_info_architecture_ppcle_64:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-system_info_architecture_s390_64:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Test for s390_64 Architecture</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="system_info_architecture_s390_64" source="ssg"/>
            <oval-def:description>Generic test for s390_64 architecture to be used by other tests</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Generic test for s390_64 architecture" test_ref="oval:ssg-test_system_info_architecture_s390_64:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-system_info_architecture_x86:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Test for x86 Architecture</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="system_info_architecture_x86" source="ssg"/>
            <oval-def:description>Generic test for x86 architecture to be used by other tests</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Generic test for x86 architecture" test_ref="oval:ssg-test_system_info_architecture_x86:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-system_info_architecture_x86_64:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Test for x86_64 Architecture</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="system_info_architecture_x86_64" source="ssg"/>
            <oval-def:description>Generic test for x86_64 architecture to be used by other tests</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Generic test for x86_64 architecture" test_ref="oval:ssg-test_system_info_architecture_x86_64:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-tmux_conf_readable_by_others:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title/>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="tmux_conf_readable_by_others" source="ssg"/>
            <oval-def:description>Check /etc/tmux.conf is readable by others</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check /etc/tmux.conf is readable by others" test_ref="oval:ssg-test_tmux_conf_readable_by_others:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-usbguard_rules_not_empty_not_missing:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Check that file storing USBGuard rules exists and is not empty</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="usbguard_rules_not_empty_not_missing" source="ssg"/>
            <oval-def:description>Check that file storing USBGuard rules at /etc/usbguard/rules.conf exists and is not empty</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Check that file storing USBGuard rules exists and is not empty" operator="AND">
            <oval-def:criterion comment="Check that the usbguard rules in either /etc/usbguard/rules.conf or /etc/usbguard/rules.d/ contain at least one non white space character." test_ref="oval:ssg-test_usbguard_rules_nonempty:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-var_accounts_user_umask_as_number:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Value of 'var_accounts_user_umask' variable represented as octal number</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="var_accounts_user_umask_as_number" source="ssg"/>
            <oval-def:description>Value of 'var_accounts_user_umask' variable represented as octal number</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_existence_of_var_accounts_user_umask_as_number_variable:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-var_removable_partition_is_cd_dvd_drive:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Value of 'var_removable_partition' variable is set to '/dev/cdrom'</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="var_removable_partition_is_cd_dvd_drive" source="ssg"/>
            <oval-def:description>Verify if value of 'var_removable_partition' variable is set
      to '/dev/cdrom'</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check if removable partition value represents CD/DVD drive" test_ref="oval:ssg-test_var_removable_partition_is_cd_dvd_drive:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="compliance" id="oval:ssg-var_umask_for_daemons_as_number:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Value of 'var_umask_for_daemons' variable represented as octal number</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="var_umask_for_daemons_as_number" source="ssg"/>
            <oval-def:description>Value of 'var_umask_for_daemons' variable represented as octal number</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion test_ref="oval:ssg-test_existence_of_var_umask_for_daemons_as_number_variable:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
      </oval-def:definitions>
      <oval-def:tests>
        <ind:textfilecontent54_test check="all" comment="audit augenrules configuration locked" id="oval:ssg-test_audit_rules_continue_loading_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_continue_loading_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl configuration locked" id="oval:ssg-test_audit_rules_continue_loading_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_continue_loading_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules configuration locked" id="oval:ssg-test_ari_locked_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_ari_locked_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl configuration locked" id="oval:ssg-test_ari_locked_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_ari_locked_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="test presence of --loginuid-immutable in some file in /etc/audit/rules.d/*.rules" id="oval:ssg-test_augen_immutable_login_uids:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_augen_immutable_login_uids:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="test presence of --loginuid-immutable in some file in /etc/audit/audit.rules" id="oval:ssg-test_auditctl_immutable_login_uids:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_auditctl_immutable_login_uids:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit selinux changes augenrules" id="oval:ssg-test_armm_selinux_watch_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_armm_selinux_watch_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit selinux changes auditctl" id="oval:ssg-test_armm_selinux_watch_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_armm_selinux_watch_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit /etc/issue augenrules" id="oval:ssg-test_arnm_common_etc_issue_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_arnm_common_etc_issue_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit /etc/issue auditctl" id="oval:ssg-test_arnm_common_etc_issue_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_arnm_common_etc_issue_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit /etc/issue.net augenrules" id="oval:ssg-test_arnm_common_etc_issue_net_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_arnm_common_etc_issue_net_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit /etc/issue.net auditctl" id="oval:ssg-test_arnm_common_etc_issue_net_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_arnm_common_etc_issue_net_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit /etc/hosts augenrules" id="oval:ssg-test_arnm_common_etc_hosts_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_arnm_common_etc_hosts_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit /etc/hosts auditctl" id="oval:ssg-test_arnm_common_etc_hosts_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_arnm_common_etc_hosts_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit /etc/sysconfig/network augenrules" id="oval:ssg-test_arnm_common_etc_sysconfig_network_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_arnm_common_etc_sysconfig_network_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit /etc/sysconfig/network auditctl" id="oval:ssg-test_arnm_common_etc_sysconfig_network_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_arnm_common_etc_sysconfig_network_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules utmp" id="oval:ssg-test_arse_utmp_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arse_utmp_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules btmp" id="oval:ssg-test_arse_btmp_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arse_btmp_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules wtmp" id="oval:ssg-test_arse_wtmp_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arse_wtmp_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl utmp" id="oval:ssg-test_arse_utmp_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arse_utmp_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl btmp" id="oval:ssg-test_arse_btmp_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arse_btmp_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl wtmp" id="oval:ssg-test_arse_wtmp_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arse_wtmp_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit uid privileged function" id="oval:ssg-test_32bit_uid_auid_privileged_function_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_uid_auid_privileged_function_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit uid privileged function" id="oval:ssg-test_64bit_uid_auid_privileged_function_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_uid_auid_privileged_function_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit uid privileged function" id="oval:ssg-test_32bit_uid_auid_privileged_function_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_uid_auid_privileged_function_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit uid privileged_function" id="oval:ssg-test_64bit_uid_auid_privileged_function_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_uid_auid_privileged_function_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit uid privileged function" id="oval:ssg-test_32bit_uid_privileged_function_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_uid_privileged_function_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit uid privileged function" id="oval:ssg-test_64bit_uid_privileged_function_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_uid_privileged_function_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit uid privileged function" id="oval:ssg-test_32bit_uid_privileged_function_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_uid_privileged_function_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit uid privileged_function" id="oval:ssg-test_64bit_uid_privileged_function_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_uid_privileged_function_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit gid privileged function" id="oval:ssg-test_32bit_gid_privileged_function_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_gid_privileged_function_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit gid privileged function" id="oval:ssg-test_64bit_gid_privileged_function_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_gid_privileged_function_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit gid privileged function" id="oval:ssg-test_32bit_gid_privileged_function_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_gid_privileged_function_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit gid privileged_function" id="oval:ssg-test_64bit_gid_privileged_function_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_gid_privileged_function_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="at least one" comment="audit augenrules configuration shutdown" id="oval:ssg-test_ars_shutdown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_ars_shutdown_augenrules:obj:1"/>
          <ind:state state_ref="oval:ssg-state_ars_shutdown:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl configuration shutdown" id="oval:ssg-test_ars_shutdown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_ars_shutdown_auditctl:obj:1"/>
          <ind:state state_ref="oval:ssg-state_ars_shutdown:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules /etc/group" id="oval:ssg-test_audit_rules_usergroup_modification_etc_group_augen:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_etc_group_augen:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules /etc/passwd" id="oval:ssg-test_audit_rules_usergroup_modification_etc_passwd_augen:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_etc_passwd_augen:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules /etc/gshadow" id="oval:ssg-test_audit_rules_usergroup_modification_etc_gshadow_augen:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_etc_gshadow_augen:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules /etc/shadow" id="oval:ssg-test_audit_rules_usergroup_modification_etc_shadow_augen:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_etc_shadow_augen:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules /etc/security/opasswd" id="oval:ssg-test_audit_rules_usergroup_modification_etc_security_opasswd_augen:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_etc_security_opasswd_augen:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit /etc/group" id="oval:ssg-test_audit_rules_usergroup_modification_etc_group_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_etc_group_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit /etc/passwd" id="oval:ssg-test_audit_rules_usergroup_modification_etc_passwd_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_etc_passwd_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit /etc/gshadow" id="oval:ssg-test_audit_rules_usergroup_modification_etc_gshadow_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_etc_gshadow_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit /etc/shadow" id="oval:ssg-test_audit_rules_usergroup_modification_etc_shadow_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_etc_shadow_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit /etc/security/opasswd" id="oval:ssg-test_audit_rules_usergroup_modification_etc_security_opasswd_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_etc_security_opasswd_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules " id="oval:ssg-test_directory_access_var_log_audit_augenrules_32bit:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_directory_access_var_log_audit_augenrules_32bit:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules " id="oval:ssg-test_directory_access_var_log_audit_augenrules_64bit:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_directory_access_var_log_audit_augenrules_64bit:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl " id="oval:ssg-test_directory_access_var_log_audit_auditctl_32bit:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_directory_access_var_log_audit_auditctl_32bit:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl " id="oval:ssg-test_directory_access_var_log_audit_auditctl_64bit:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_directory_access_var_log_audit_auditctl_64bit:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="none_exist" comment="/var/log/audit directories uid root gid root" id="oval:ssg-test_group_ownership_default_var_log_audit_directories:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_group_ownership_default_var_log_audit_directories:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="/var/log/audit directories uid root gid root" id="oval:ssg-test_group_ownership_var_log_audit_directories-non_root:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_group_ownership_var_log_audit_directories-non_root:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="/var/log/audit directories uid root gid root" id="oval:ssg-test_group_ownership_var_log_audit_directories:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_group_ownership_var_log_audit_directories:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="log_file's directory uid root gid root" id="oval:ssg-test_user_ownership_var_log_audit_path:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_user_ownership_var_log_audit_path:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="/var/log/audit directories uid root gid root" id="oval:ssg-test_user_ownership_var_log_audit_directories:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_user_ownership_var_log_audit_directories:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="non default audit log dir mode 0700" id="oval:ssg-test_permissions_audit_log_directory_root:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_var_log_audit_directory_non_default_root:obj:1"/>
          <unix:state state_ref="oval:ssg-state_mode_0700:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="non default audit log dir mode 0750" id="oval:ssg-test_permissions_audit_log_directory_not_root:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_var_log_audit_directory_non_default_not_root:obj:1"/>
          <unix:state state_ref="oval:ssg-state_mode_0750:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="/var/log/audit mode 0700" id="oval:ssg-test_permissions_default_audit_log_directory_root:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_var_log_audit_directory_root:obj:1"/>
          <unix:state state_ref="oval:ssg-state_mode_0700:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="/var/log/audit mode 0750" id="oval:ssg-test_permissions_default_audit_log_directory_not_root:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_var_log_audit_directory_non_root:obj:1"/>
          <unix:state state_ref="oval:ssg-state_mode_0750:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="audit log files gid root" id="oval:ssg-test_group_ownership_audit_log_files:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_group_ownership_audit_log_files:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="audit log files gid root" id="oval:ssg-test_group_ownership_default_audit_log_files:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_group_ownership_default_audit_log_files:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="/var/log/audit directories uid root gid root" id="oval:ssg-test_ownership_var_log_audit_directories:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_ownership_var_log_audit_directories:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="/var/log/audit files uid root gid root" id="oval:ssg-test_ownership_var_log_audit_files:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_ownership_var_log_audit_files:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="/var/log/audit directories uid root gid root" id="oval:ssg-test_ownership_var_log_audit_directories-non_root:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_ownership_var_log_audit_directories-non_root:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="/var/log/audit files uid root gid root" id="oval:ssg-test_ownership_var_log_audit_files-non_root:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_ownership_var_log_audit_files-non_root:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="audit log files uid root" id="oval:ssg-test_user_ownership_audit_log_files:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_user_ownership_audit_log_files:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="/var/log/audit files uid root" id="oval:ssg-test_user_ownership_var_log_audit_files:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_user_ownership_var_log_audit_files:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" comment="audit log files mode 0600" id="oval:ssg-test_file_permissions_audit_log:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_audit_log_files:obj:1"/>
          <unix:state state_ref="oval:ssg-state_not_mode_0600:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" comment="/var/log/audit files mode 0600" id="oval:ssg-test_file_permissions_var_log_audit:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_var_log_audit_files:obj:1"/>
          <unix:state state_ref="oval:ssg-state_not_mode_0600:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" comment="audit log files mode 0640" id="oval:ssg-test_file_permissions_audit_log-non_root:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_audit_log_files-non_root:obj:1"/>
          <unix:state state_ref="oval:ssg-state_not_mode_0640:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" comment="/var/log/audit files mode 0640" id="oval:ssg-test_file_permissions_var_log_audit-non_root:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_var_log_audit_files-non_root:obj:1"/>
          <unix:state state_ref="oval:ssg-state_not_mode_0640:ste:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit umount" id="oval:ssg-test_32bit_ardm_umount_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_umount_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit umount" id="oval:ssg-test_32bit_ardm_umount_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_umount_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="There is one augenrules rule for each privileged command on the system." id="oval:ssg-test_augenrules_all_priv_cmds_covered:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_priv_cmds_from_augenrules:obj:1"/>
          <ind:state state_ref="oval:ssg-state_priv_cmds_from_system:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Count of augenrules for priv cmds matches the count of priv cmds in the system" id="oval:ssg-test_augenrules_count_matches_system_priv_cmds:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_priv_cmds_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_priv_cmds_from_augenrules_count:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="There is one auditctl rule for each privileged command on the system." id="oval:ssg-test_auditctl_all_priv_cmds_covered:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_priv_cmds_from_auditctl:obj:1"/>
          <ind:state state_ref="oval:ssg-state_priv_cmds_from_system:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Count of auditctl for priv cmds matches the count of priv cmds in the system" id="oval:ssg-test_auditctl_count_matches_system_priv_cmds:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_priv_cmds_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_priv_cmds_from_auditctl_count:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="There is one augenrules rule for each privileged command on the system." id="oval:ssg-test_augenrules_all_priv_cmds_covered_bootc:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_priv_cmds_from_augenrules_bootc:obj:1"/>
          <ind:state state_ref="oval:ssg-state_priv_cmds_from_system_bootc:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Count of augenrules for priv cmds matches the count of priv cmds in the system" id="oval:ssg-test_augenrules_count_matches_system_priv_cmds_bootc:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_priv_cmds_count_bootc:obj:1"/>
          <ind:state state_ref="oval:ssg-state_priv_cmds_from_augenrules_count_bootc:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="There is one auditctl rule for each privileged command on the system." id="oval:ssg-test_auditctl_all_priv_cmds_covered_bootc:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_priv_cmds_from_auditctl_bootc:obj:1"/>
          <ind:state state_ref="oval:ssg-state_priv_cmds_from_system_bootc:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Count of auditctl for priv cmds matches the count of priv cmds in the system" id="oval:ssg-test_auditctl_count_matches_system_priv_cmds_bootc:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_priv_cmds_count_bootc:obj:1"/>
          <ind:state state_ref="oval:ssg-state_priv_cmds_from_auditctl_count_bootc:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit adjtimex" id="oval:ssg-test_32bit_art_adjtimex_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_art_adjtimex_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit adjtimex" id="oval:ssg-test_64bit_art_adjtimex_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_art_adjtimex_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit adjtimex" id="oval:ssg-test_32bit_art_adjtimex_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_art_adjtimex_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit adjtimex" id="oval:ssg-test_64bit_art_adjtimex_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_art_adjtimex_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit clock_settime" id="oval:ssg-test_32bit_art_clock_settime_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_art_clock_settime_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit clock_settime" id="oval:ssg-test_64bit_art_clock_settime_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_art_clock_settime_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit clock_settime" id="oval:ssg-test_32bit_art_clock_settime_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_art_clock_settime_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit clock_settime" id="oval:ssg-test_64bit_art_clock_settime_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_art_clock_settime_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit settimeofday" id="oval:ssg-test_32bit_art_settimeofday_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_art_settimeofday_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit settimeofday" id="oval:ssg-test_64bit_art_settimeofday_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_art_settimeofday_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit settimeofday" id="oval:ssg-test_32bit_art_settimeofday_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_art_settimeofday_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit settimeofday" id="oval:ssg-test_64bit_art_settimeofday_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_art_settimeofday_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit stime" id="oval:ssg-test_32bit_art_stime_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_art_stime_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit stime" id="oval:ssg-test_32bit_art_stime_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_art_stime_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="remote server to send audit records" id="oval:ssg-test_auditd_audispd_configure_remote_server:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_audispd_configure_remote_server:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_audispd_configure_remote_server:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="the action the operating system takes if there is an error sending audit records to a remote system" id="oval:ssg-test_auditd_audispd_disk_full_action:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_audispd_disk_full_action:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_audispd_disk_full_action:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="setting in audisp-remote.conf" id="oval:ssg-test_auditd_audispd_encrypt_sent_records:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_audispd_encrypt_sent_records:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="the action the operating system takes if there is an error sending audit records to a remote system" id="oval:ssg-test_auditd_audispd_network_failure_action:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_audispd_network_failure_action:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_audispd_network_failure_action:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audispd syslog plugin activated" id="oval:ssg-test_auditd_audispd_syslog_plugin_activated:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_audispd_syslog_plugin_activated:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="disk full action" id="oval:ssg-test_auditd_data_disk_error_action:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_disk_error_action:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_disk_error_action:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="disk full action" id="oval:ssg-test_auditd_data_disk_error_action_stig_syslog:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_disk_error_action_stig:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_disk_error_action_stig_syslog:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="disk full action" id="oval:ssg-test_auditd_data_disk_error_action_stig_single:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_disk_error_action_stig:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_disk_error_action_stig_single:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="disk full action" id="oval:ssg-test_auditd_data_disk_error_action_stig_halt:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_disk_error_action_stig:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_disk_error_action_stig_halt:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="disk error action" id="oval:ssg-test_auditd_data_disk_full_action:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_disk_full_action:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_disk_full_action:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="disk full action" id="oval:ssg-test_auditd_data_disk_full_action_stig_syslog:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_disk_full_action_stig:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_disk_full_action_stig_syslog:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="disk full action" id="oval:ssg-test_auditd_data_disk_full_action_stig_single:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_disk_full_action_stig:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_disk_full_action_stig_single:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="disk full action" id="oval:ssg-test_auditd_data_disk_full_action_stig_halt:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_disk_full_action_stig:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_disk_full_action_stig_halt:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="email account for actions" id="oval:ssg-test_auditd_data_retention_action_mail_acct:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_retention_action_mail_acct:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_retention_action_mail_acct:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="space left action" id="oval:ssg-test_auditd_data_retention_admin_space_left_action:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_retention_admin_space_left_action:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_retention_admin_space_left_action:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="admin space left action " id="oval:ssg-test_auditd_data_retention_admin_space_left_percentage:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_retention_admin_space_left_percentage:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_retention_admin_space_left_percentage:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="test the value of flush parameter in /etc/audit/auditd.conf" id="oval:ssg-test_auditd_data_retention_flush:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_retention_flush:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_retention_flush:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="max log file size" id="oval:ssg-test_auditd_data_retention_max_log_file:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_retention_max_log_file:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_retention_max_log_file:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="admin space left action " id="oval:ssg-test_auditd_data_retention_max_log_file_action:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_retention_max_log_file_action:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_retention_max_log_file_action:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="admin space left action " id="oval:ssg-test_auditd_data_retention_max_log_file_action_stig_rotate:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_retention_max_log_file_action_stig:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_retention_max_log_file_action_stig_rotate:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="admin space left action " id="oval:ssg-test_auditd_data_retention_max_log_file_action_stig_single:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_retention_max_log_file_action_stig:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_retention_max_log_file_action_stig_single:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="admin space left action " id="oval:ssg-test_auditd_data_retention_num_logs:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_retention_num_logs:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_retention_num_logs:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="admin space left action " id="oval:ssg-test_auditd_data_retention_space_left:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_retention_space_left:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_retention_space_left:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="space left action" id="oval:ssg-test_auditd_data_retention_space_left_action:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_auditd_data_retention_space_left_action:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_retention_space_left_action:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="admin space left action " id="oval:ssg-test_auditd_data_retention_space_left_percentage:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_data_retention_space_left_percentage:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_data_retention_space_left_percentage:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of name_format setting in the /etc/audit/auditd.conf file" id="oval:ssg-test_auditd_name_format:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_auditd_name_format:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_name_format:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of overflow_action setting in the /etc/audit/auditd.conf file" id="oval:ssg-test_auditd_overflow_action:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_auditd_overflow_action:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_overflow_action:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Compare 10-base-config.rules file in /etc/audit/rules.d against file in /usr/share/doc/audit/" id="oval:ssg-test_compare_10-base-config_old:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_etc_10-base-config_old:obj:1"/>
          <ind:state state_ref="oval:ssg-state_doc_10-base-config:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Compare 11-loginuid.rules file in /etc/audit/rules.d against file in /usr/share/doc/audit/" id="oval:ssg-test_compare_11-loginuid_old:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_etc_11-loginuid_old:obj:1"/>
          <ind:state state_ref="oval:ssg-state_doc_11-loginuid:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Compare 30-ospp-v42.rules file in /etc/audit/rules.d against file in /usr/share/doc/audit/" id="oval:ssg-test_compare_30-ospp-v42_old:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_etc_30-ospp-v42_old:obj:1"/>
          <ind:state state_ref="oval:ssg-state_doc_30-ospp-v42:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Compare 43-module-load.rules file in /etc/audit/rules.d against file in /usr/share/doc/audit/" id="oval:ssg-test_compare_43-module-load_old:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_etc_43-module-load_old:obj:1"/>
          <ind:state state_ref="oval:ssg-state_doc_43-module-load:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests the value of the ^[\s]*BOOTPROTO[\s]*=[\s]*([^#]*) expression in the /etc/sysconfig/network-scripts/ifcfg-.* file" id="oval:ssg-test_sysconfig_networking_bootproto_ifcfg:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sysconfig_networking_bootproto_ifcfg:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sysconfig_networking_bootproto_ifcfg:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="fapolicyd employs a deny-all policy in compiled.rules file" id="oval:ssg-test_fapolicy_default_deny_policy_with_rulesd:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_fapolicy_default_deny_policy_compiled_rules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="fapolicyd employs a deny-all policy in fapolicyd.rules file" id="oval:ssg-test_fapolicy_default_deny_policy_without_rulesd:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_fapolicy_default_deny_policy_fapolicyd_rules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="permissive mode is disabled in fapolicyd settings" id="oval:ssg-test_fapolicy_default_deny_enforcement:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_fapolicy_default_deny_permissive_mode:obj:1"/>
          <ind:state state_ref="oval:ssg-state_fapolicy_default_deny_permissive_mode_off:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="log ftp transactions" id="oval:ssg-test_ftp_log_transactions_enable:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_ftp_log_transactions_enable:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="log ftp transactions" id="oval:ssg-test_ftp_log_transactions_format:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_ftp_log_transactions_format:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="log ftp transactions" id="oval:ssg-test_ftp_log_transactions_protocol:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_ftp_log_transactions_protocol:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Banner for FTP Users" id="oval:ssg-test_ftp_present_banner:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_ftp_present_banner:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="Testing directory permissions" id="oval:ssg-test_dir_perms_etc_httpd_conf:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_dir_perms_etc_httpd_conf:obj:1"/>
          <unix:state state_ref="oval:ssg-state_dir_perms_etc_httpd_conf:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="Testing directory permissions" id="oval:ssg-test_dir_perms_var_log_httpd:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_dir_perms_var_log_httpd:obj:1"/>
          <unix:state state_ref="oval:ssg-state_dir_perms_var_log_httpd:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="/etc/httpd/conf.d/* permissions" id="oval:ssg-test_file_permissions_httpd_server_conf_d_files:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_permissions_httpd_server_conf_d_files:obj:1"/>
          <unix:state state_ref="oval:ssg-state_wrong_file_permissions_httpd_server_conf_d_files:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="/etc/httpd/conf/* permissions" id="oval:ssg-test_file_permissions_httpd_server_conf_files:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_permissions_httpd_server_conf_files:obj:1"/>
          <unix:state state_ref="oval:ssg-state_wrong_file_permissions_httpd_server_conf_files:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="/etc/httpd/conf.modules.d/* permissions" id="oval:ssg-test_file_permissions_httpd_server_modules_files:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_permissions_httpd_server_modules_files:obj:1"/>
          <unix:state state_ref="oval:ssg-state_wrong_file_permissions_httpd_server_modules_files:ste:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests the value of the disable_plaintext_auth[\s]*(&lt;:nocomment:&gt;*) setting in the /etc/dovecot.conf file" id="oval:ssg-test_dovecot_disable_plaintext_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_dovecot_disable_plaintext_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests the value of the ssl[\s]*(&lt;:nocomment:&gt;*) setting in the /etc/dovecot.conf file" id="oval:ssg-test_dovecot_enable_ssl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_dovecot_enable_ssl:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Ensure keytab file does not exist" id="oval:ssg-test_kerberos_disable_no_keytab:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_kerberos_disable_no_keytab:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="LDAP client is enabled" id="oval:ssg-test_enable_ldap_client:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_enable_ldap_client:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Tests the value of the ssl start_tls setting in the configuration file" id="oval:ssg-test_ldap_client_start_tls_ssl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_ldap_client_start_tls_ssl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Tests the value of the tls_cacertdir setting in the configuration file" id="oval:ssg-test_ldap_client_tls_cacertdir:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_ldap_client_tls_cacertdir:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:inetlisteningservers_test check="all" check_existence="none_exist" comment="mta is not listening on any non-loopback address 25" id="oval:ssg-tst_nothing_listening_external_mta_port_25:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_listening_port_25:obj:1"/>
        </linux:inetlisteningservers_test>
        <ind:textfilecontent54_test check="all" comment="Check if root has the correct mail alias." id="oval:ssg-test_postfix_client_configure_mail_alias:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_root_mail_alias:obj:1"/>
          <ind:state state_ref="oval:ssg-state_root_mail_alias:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check if postmaster has the correct mail alias" id="oval:ssg-test_postfix_client_configure_mail_alias_postmaster:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_postmaster_mail_alias:obj:1"/>
          <ind:state state_ref="oval:ssg-state_postmaster_mail_alias:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="inet_interfaces in /etc/postfix/main.cf should be set correctly" id="oval:ssg-test_postfix_network_listening_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_postfix_network_listening_disabled:obj:1"/>
          <ind:state state_ref="oval:ssg-state_postfix_network_listening_disabled:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Set banner" id="oval:ssg-test_postfix_server_banner:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_postfix_server_banner:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of smtpd_client_restrictions setting in the /etc/postfix/main.cf file" id="oval:ssg-test_postfix_prevent_unrestricted_relay:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_postfix_prevent_unrestricted_relay:obj:1"/>
          <ind:state state_ref="oval:ssg-state_postfix_prevent_unrestricted_relay:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="The configuration file /etc/postfix/main.cf exists for postfix_prevent_unrestricted_relay" id="oval:ssg-test_postfix_prevent_unrestricted_relay_config_file_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_postfix_prevent_unrestricted_relay_config_file:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Tests the value of the insecure locks in /etc/exports" id="oval:ssg-test_no_insecure_locks_exports:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_no_insecure_locks_exports:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests the value of the Kerberos Settings in /etc/exports" id="oval:ssg-test_use_kerberos_security_all_exports:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-obj_use_kerberos_security_all_exports:obj:1"/>
          <ind:state state_ref="oval:ssg-state_use_kerberos_security_all_exports:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests if a share is configured in /etc/exports" id="oval:ssg-test_non_empty_exports_file:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_non_empty_exports_file:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check if port is 0 in /etc/chrony.conf" id="oval:ssg-test_chronyd_client_only:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_chronyd_port_value:obj:1"/>
          <ind:state state_ref="oval:ssg-state_chronyd_port_value_0:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="none_exist" comment="check if /usr/lib/systemd/system/chrony-wait.service does not exist" id="oval:ssg-test_chrony_wait_service_not_installed:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_chrony_wait_service_package:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" comment="check if chrony-wait.service ExecStart does not use -h flag for network addresses" id="oval:ssg-test_chrony_wait_service_fixed:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_chrony_wait_service_execstart:obj:1"/>
          <ind:state state_ref="oval:ssg-state_chrony_wait_execstart_no_h_flag:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check if cmdport is 0 in /etc/chrony.conf" id="oval:ssg-test_chronyd_no_chronyc_network:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_chronyd_cmdport_value:obj:1"/>
          <ind:state state_ref="oval:ssg-state_chronyd_cmdport_value_0:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check if maxpoll is set in /etc/ntp.conf" id="oval:ssg-test_ntp_set_maxpoll:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_ntp_set_maxpoll:obj:1"/>
          <ind:state state_ref="oval:ssg-state_time_service_set_maxpoll:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check if maxpoll is set in /etc/chrony.conf or /etc/chrony.d/" id="oval:ssg-test_chrony_set_maxpoll:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_chrony_set_maxpoll:obj:1"/>
          <ind:state state_ref="oval:ssg-state_time_service_set_maxpoll:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check if all server entries have maxpoll set in /etc/ntp.conf" id="oval:ssg-test_ntp_all_server_has_maxpoll:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_ntp_all_server_has_maxpoll:obj:1"/>
          <ind:state state_ref="oval:ssg-state_server_has_maxpoll:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check if all server entries have maxpoll set in /etc/chrony.conf or /etc/chrony.d/" id="oval:ssg-test_chrony_all_server_has_maxpoll:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_chrony_all_server_has_maxpoll:obj:1"/>
          <ind:state state_ref="oval:ssg-state_server_has_maxpoll:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of OPTIONS setting in the /etc/sysconfig/chronyd file" id="oval:ssg-test_chronyd_run_as_chrony_user:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_chronyd_run_as_chrony_user:obj:1"/>
          <ind:state state_ref="oval:ssg-state_chronyd_run_as_chrony_user:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="The configuration file /etc/sysconfig/chronyd exists for chronyd_run_as_chrony_user" id="oval:ssg-test_chronyd_run_as_chrony_user_config_file_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_chronyd_run_as_chrony_user_config_file:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" comment="Ensure at least one time source is set with server directive" id="oval:ssg-test_chronyd_server_directive_with_server:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_chronyd_server_directive:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Ensure no time source is set with pool directive" id="oval:ssg-test_chronyd_server_directive_no_pool:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_chronyd_no_pool_directive:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check for server/pool in main chrony.conf" id="oval:ssg-test_chronyd_server_in_main_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_chronyd_server_in_main_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check for server/pool in sourcedir .sources files" id="oval:ssg-test_chronyd_server_in_sourcedir_files:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_chronyd_server_in_sourcedir_files:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check for server/pool in confdir .conf files" id="oval:ssg-test_chronyd_server_in_confdir_files:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_chronyd_server_in_confdir_files:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Test if /etc/nssswitch.conf contains 'altfiles' in 'group' key" id="oval:ssg-test_file_groupowner_etc_chrony_keys_nsswitch_uses_altfiles:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_file_groupowner_etc_chrony_keys_nsswitch_uses_altfiles:obj:1"/>
          <ind:state state_ref="oval:ssg-state_file_groupowner_etc_chrony_keys_nsswitch_uses_altfiles:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package nss-altfiles is installed" id="oval:ssg-test_file_groupowner_etc_chrony_keys_package_nss-altfiles_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_file_groupowner_etc_chrony_keys_package_nss-altfiles_installed:obj:1"/>
        </linux:rpminfo_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/chrony.keys" id="oval:ssg-test_file_groupowner_etc_chrony_keys:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_chrony_keys:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/chrony.keys" id="oval:ssg-test_file_groupowner_etc_chrony_keys_with_usrlib:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_chrony_keys_with_usrlib:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Ensure more than one ntpd NTP server is set" id="oval:ssg-test_ntpd_multiple_servers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_ntpd_multiple_servers:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Ensure at least one ntpd NTP server is set" id="oval:ssg-test_ntp_remote_server:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_ntp_remote_server:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="check for nsswitch.conf lines which have nis configured as a database" id="oval:ssg-test_no_nis_in_nsswitch:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_no_nis_in_nsswitch:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="none_exist" comment="look for shosts.equiv in /" id="oval:ssg-test_no_shosts_equiv:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_no_shosts_equiv_files_root:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" comment="look for .rhosts in /root" id="oval:ssg-test_no_rsh_trust_files_root:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_no_rsh_trust_files_root:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" comment="look for .rhosts in /home" id="oval:ssg-test_no_rsh_trust_files_home:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_no_rsh_trust_files_home:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" comment="look for /etc/hosts.equiv" id="oval:ssg-test_no_rsh_trust_files_etc:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_no_rsh_trust_files_etc:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="look for .shosts in /" id="oval:ssg-test_no_shosts:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_no_shosts_files_root:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="No drop-in configuration files exist" id="oval:ssg-file_tftp_service_dropin_notexists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_tftp_service_dropin:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="drop-in configuration files exist" id="oval:ssg-file_tftp_service_dropin_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_tftp_service_dropin:obj:1"/>
          <ind:state state_ref="oval:ssg-state_tftp_service_dropin_exists:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Ensure original unit ExecStart uses secure mode" id="oval:ssg-test_tftp_uses_secure_mode_systemd_original:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_tftp_uses_secure_mode_systemd_original:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="tftpd secure mode" id="oval:ssg-test_tftpd_uses_secure_mode:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_tftpd_uses_secure_mode:obj:1"/>
          <ind:state state_ref="oval:ssg-state_tftpd_uses_secure_mode:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Disable Browsing" id="oval:ssg-test_cups_disable_browsing_browsing_off:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-obj_cups_disable_browsing_browsing_off:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Do not allow incoming printer information packets" id="oval:ssg-test_cups_disable_browsing_browseallow:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-obj_cups_disable_browsing_browseallow:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Disable the more general port directive" id="oval:ssg-test_cups_disable_printserver_disable_port:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_cups_disable_printserver_disable_port:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Listen only at the localhost level" id="oval:ssg-test_cups_disable_printserver_use_listen:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_cups_disable_printserver_use_listen:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="check for no cifs in /etc/fstab" id="oval:ssg-test_20340111:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_20340111:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check for sec=krb5i or sec=ntlmv2i in /etc/fstab" id="oval:ssg-test_20340112:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_20340111:obj:1"/>
          <ind:state state_ref="oval:ssg-state_20340112:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="check for no cifs in /etc/mtab" id="oval:ssg-test_20340113:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_20340112:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check for sec=krb5i or sec=ntlmv2i in /etc/mtab" id="oval:ssg-test_20340114:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_20340112:obj:1"/>
          <ind:state state_ref="oval:ssg-state_20340112:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check for client signing = mandatory in /etc/samba/smb.conf" id="oval:ssg-test_require_smb_client_signing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_require_smb_client_signing:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check snmpd configuration" id="oval:ssg-test_snmp_default_communities:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_snmp_default_communities:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check snmpd configuration" id="oval:ssg-test_snmp_versions:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_snmp_versions:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="none_exist" comment="No keys that have unsafe ownership/permissions combination exist" id="oval:ssg-test_no_offending_keys:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_offending_keys:obj:1"/>
        </unix:file_test>
        <ind:xmlfilecontent_test check="all" check_existence="none_exist" comment="ssh service is not enabled in services" id="oval:ssg-test_firewalld_service_sshd:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_firewalld_service_sshd:obj:1"/>
        </ind:xmlfilecontent_test>
        <ind:xmlfilecontent_test check="all" check_existence="none_exist" comment="ssh port is not enabled in services" id="oval:ssg-test_firewalld_service_sshd_port:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_firewalld_service_sshd_port:obj:1"/>
        </ind:xmlfilecontent_test>
        <ind:xmlfilecontent_test check="all" check_existence="none_exist" comment="ssh service is not enabled in zones" id="oval:ssg-test_firewalld_zone_sshd:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_firewalld_zone_sshd:obj:1"/>
        </ind:xmlfilecontent_test>
        <ind:xmlfilecontent_test check="all" check_existence="none_exist" comment="ssh port is not enabled in zones" id="oval:ssg-test_firewalld_zone_sshd_port:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_firewalld_zone_sshd_port:obj:1"/>
        </ind:xmlfilecontent_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of RekeyLimit setting in /etc/ssh/ssh_config" id="oval:ssg-test_ssh_client_rekey_limit_main_config:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_ssh_client_rekey_limit_main_config:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of RekeyLimit setting in /etc/ssh/ssh_config.d/*.conf" id="oval:ssg-test_ssh_client_rekey_limit_include_configs:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_ssh_client_rekey_limit_include_configs:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check correct entropy configuration in /etc/profile.d/cc-ssh-strong-rng.csh" id="oval:ssg-test_ssh_client_strong_rng_csh:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_ssh_client_strong_rng_csh:obj:1"/>
          <ind:state state_ref="oval:ssg-state_ssh_client_strong_rng_csh:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="check that the configuration is not overridden in /etc/profile" id="oval:ssg-test_ssh_client_strong_rng_csh_not_overridden:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_ssh_client_strong_rng_csh_not_overridden:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check correct entropy configuration in /etc/profile.d/cc-ssh-strong-rng.sh" id="oval:ssg-test_ssh_client_strong_rng_sh:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_ssh_client_strong_rng_sh:obj:1"/>
          <ind:state state_ref="oval:ssg-state_ssh_client_strong_rng_sh:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="check that the configuration is not overridden in /etc/profile" id="oval:ssg-test_ssh_client_strong_rng_sh_not_overridden:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_ssh_client_strong_rng_sh_not_overridden:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:xmlfilecontent_test check="all" comment="SSH service is defined in all zones delivered in the firewalld package" id="oval:ssg-test_firewalld_sshd_port_enabled_zone_ssh_enabled_usr:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_firewalld_sshd_port_enabled_zone_files_usr:obj:1"/>
        </ind:xmlfilecontent_test>
        <unix:file_test check="all" check_existence="none_exist" comment="there is no equivalent zone file defined by the administrator in /etc dir" id="oval:ssg-test_firewalld_sshd_port_enabled_usr_zones_not_overridden:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_firewalld_sshd_port_enabled_customized_zone_files:obj:1"/>
        </unix:file_test>
        <ind:variable_test check="all" comment="SSH service is defined in all zones created or modified by the administrator" id="oval:ssg-test_firewalld_sshd_port_enabled_zone_ssh_enabled_etc:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_firewalld_sshd_port_enabled_custom_zone_files_with_ssh_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firewalld_sshd_port_enabled_custom_zone_files_count:ste:1"/>
        </ind:variable_test>
        <ind:xmlfilecontent_test check="all" check_existence="all_exist" comment="SSH service is integer in the /usr/lib/firewalld/services dir" id="oval:ssg-test_firewalld_sshd_port_enabled_ssh_service_usr:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_firewalld_sshd_port_enabled_ssh_service_file_usr:obj:1"/>
        </ind:xmlfilecontent_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="SSH service is properly configured in /etc/firewalld/services dir" id="oval:ssg-test_firewalld_sshd_port_enabled_ssh_service_etc:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_firewalld_sshd_port_enabled_ssh_service_file_etc:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firewalld_sshd_port_enabled_ssh_service_file_etc:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="Check if there is an AllowUsers entry" id="oval:ssg-test_allow_user_is_configured:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_allow_user:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="Check if there is an AllowGroups entry" id="oval:ssg-test_allow_group_is_configured:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_allow_group:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="Check if there is a DenyUsers entry" id="oval:ssg-test_deny_user_is_configured:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_deny_user:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="Check if there is a DenyGroups entry" id="oval:ssg-test_deny_group_is_configured:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_deny_group:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of RekeyLimit setting in the file" id="oval:ssg-test_sshd_rekey_limit:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_rekey_limit:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_rekey_limit:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="timeout is configured" id="oval:ssg-test_sshd_idle_timeout:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sshd_idle_timeout:obj:1"/>
          <ind:state state_ref="oval:ssg-state_timeout_value_upper_bound:ste:1"/>
          <ind:state state_ref="oval:ssg-state_timeout_value_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of ClientAliveInterval is present" id="oval:ssg-test_clientaliveinterval_present:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_set_idle_timeout:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="LoginGraceTime is configured" id="oval:ssg-test_sshd_login_grace_time:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sshd_login_grace_time:obj:1"/>
          <ind:state state_ref="oval:ssg-state_logingracetime_value_upper_bound:ste:1"/>
          <ind:state state_ref="oval:ssg-state_logingracetime_value_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of LoginGraceTime is present" id="oval:ssg-test_LoginGraceTime_present_sshd_set_login_grace_time:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_set_login_grace_time:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="MaxAuthTries is configured" id="oval:ssg-test_sshd_max_auth_tries:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sshd_max_auth_tries:obj:1"/>
          <ind:state state_ref="oval:ssg-state_maxauthtries_value_upper_bound:ste:1"/>
          <ind:state state_ref="oval:ssg-state_maxauthtries_value_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of MaxAuthTries is present" id="oval:ssg-test_MaxAuthTries_present_sshd_set_max_auth_tries:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_set_max_auth_tries:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="MaxSessions is configured" id="oval:ssg-test_sshd_max_sessions:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sshd_max_sessions:obj:1"/>
          <ind:state state_ref="oval:ssg-state_maxsessions_value_upper_bound:ste:1"/>
          <ind:state state_ref="oval:ssg-state_maxsessions_value_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of MaxSessions is present" id="oval:ssg-test_MaxSessions_present_sshd_set_max_sessions:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_set_max_sessions:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="SSH MaxStartups start parameter is less than or equal to the expected value" id="oval:ssg-tst_maxstartups_start_parameter:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-obj_sshd_config_maxstartups_first_parameter:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_sshd_config_start_parameter_valid:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="SSH MaxStartups rate parameter is greater than or equal to the expected value" id="oval:ssg-tst_maxstartups_rate_parameter:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-obj_sshd_config_maxstartups_second_parameter:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_sshd_config_rate_parameter_valid:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="SSH MaxStartups full parameter is less than or equal to the expected value" id="oval:ssg-tst_maxstartups_full_parameter:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-obj_sshd_config_maxstartups_third_parameter:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_sshd_config_full_parameter_valid:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="tests the value of Ciphers setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_use_approved_ciphers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_use_approved_ciphers:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_sshd_use_approved_ciphers:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of Kex algorithms setting in the  file" id="oval:ssg-test_sshd_use_approved_kex_ordered_stig:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_use_approved_kex_ordered_stig:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_use_approved_kex_ordered_stig:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="at least one" comment="tests the value of MACs setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_use_approved_macs:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_use_approved_macs:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_sshd_use_approved_macs:ste:1"/>
        </ind:variable_test>
        <ind:variable_test check="all" check_existence="any_exist" comment="tests the value of KexAlgorithms setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_use_strong_kex:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_use_strong_kex:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_sshd_use_strong_kex:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of KexAlgorithms is present" id="oval:ssg-test_sshd_kexalgorithms_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_kex_all_configs:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="any_exist" comment="tests the value of MACs setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_use_strong_macs:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_use_strong_macs:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_sshd_use_strong_macs:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of MACs is present" id="oval:ssg-test_sshd_macs_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_macs_all_configs:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="test the value of         certificate_verification in sssd configuration" id="oval:ssg-test_sssd_certificate_verification:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sssd_certificate_verification:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sssd_certificate_verification:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check if pam is configured in the services setting of the sssd section" id="oval:ssg-test_sssd_enable_pam_services:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sssd_enable_pam_services:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sssd_enable_pam_services:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of pam_cert_auth setting in the /etc/sssd/sssd.conf file" id="oval:ssg-test_sssd_enable_smartcards:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sssd_enable_smartcards:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sssd_enable_smartcards:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the presence of try_cert_auth or require_cert_auth in /etc/pam.d/system-auth" id="oval:ssg-test_sssd_enable_smartcards_cert_auth_system_auth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-obj_sssd_enable_smartcards_system_auth_options:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sssd_enable_smartcards_cert_auth:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of memcache_timeout setting in the /etc/sssd/sssd.conf file" id="oval:ssg-test_sssd_memcache_timeout:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sssd_memcache_timeout:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sssd_memcache_timeout:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of offline_credentials_expiration setting in the /etc/sssd/sssd.conf file" id="oval:ssg-test_sssd_offline_cred_expiration:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sssd_offline_cred_expiration:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sssd_offline_cred_expiration:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="tests the value of user setting in SSSD config files" id="oval:ssg-test_sssd_run_as_sssd_user:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sssd_user_value:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sssd_user_value:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of ssh_known_hosts_timeout setting in the /etc/sssd/sssd.conf file" id="oval:ssg-test_sssd_ssh_known_hosts_timeout:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sssd_ssh_known_hosts_timeout:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sssd_ssh_known_hosts_timeout:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Ensures that LDAP TLS CA certificate directory is set" id="oval:ssg-test_sssd_ldap_tls_ca_dir:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sssd_ldap_tls_ca_dir:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sssd_ldap_tls_ca_dir:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Ensures that LDAP TLS requires certificate is set" id="oval:ssg-test_sssd_ldap_tls_reqcert:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sssd_ldap_tls_reqcert:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sssd_ldap_tls_reqcert:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Ensures that LDAP uses STARTTLS" id="oval:ssg-test_use_starttls:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_use_starttls_sssd_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_use_starttls_sssd_conf:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package xorg-x11-server-Xorg is removed" id="oval:ssg-test_package_xorg-x11-server-Xorg_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_xorg-x11-server-Xorg_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package xorg-x11-server-common is removed" id="oval:ssg-test_package_xorg-x11-server-common_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_xorg-x11-server-common_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package xorg-x11-server-utils is removed" id="oval:ssg-test_package_xorg-x11-server-utils_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_xorg-x11-server-utils_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package xorg-x11-server-Xwayland is removed" id="oval:ssg-test_package_xorg-x11-server-Xwayland_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_xorg-x11-server-Xwayland_removed:obj:1"/>
        </linux:rpminfo_test>
        <unix:symlink_test check="all" check_existence="all_exist" comment="default.target systemd softlink exists" id="oval:ssg-test_disable_xwindows_runlevel_target:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_disable_xwindows_runlevel_target:obj:1"/>
          <unix:state state_ref="oval:ssg-state_disable_xwindows_runlevel_target:ste:1"/>
        </unix:symlink_test>
        <unix:symlink_test check="all" check_existence="all_exist" comment="The 'fingerprint-auth' PAM config is a symlink to its authselect counterpart" id="oval:ssg-test_pam_fingerprint_symlinked_to_authselect:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_pam_fingerprint_symlinked_to_authselect:obj:1"/>
          <unix:state state_ref="oval:ssg-state_pam_fingerprint_symlinked_to_authselect:ste:1"/>
        </unix:symlink_test>
        <unix:symlink_test check="all" check_existence="all_exist" comment="The 'password-auth' PAM config is a symlink to its authselect counterpart" id="oval:ssg-test_pam_password_symlinked_to_authselect:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_pam_password_symlinked_to_authselect:obj:1"/>
          <unix:state state_ref="oval:ssg-state_pam_password_symlinked_to_authselect:ste:1"/>
        </unix:symlink_test>
        <unix:symlink_test check="all" check_existence="all_exist" comment="The 'postlogin' PAM config is a symlink to its authselect counterpart" id="oval:ssg-test_pam_postlogin_symlinked_to_authselect:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_pam_postlogin_symlinked_to_authselect:obj:1"/>
          <unix:state state_ref="oval:ssg-state_pam_postlogin_symlinked_to_authselect:ste:1"/>
        </unix:symlink_test>
        <unix:symlink_test check="all" check_existence="all_exist" comment="The 'smartcard-auth' PAM config is a symlink to its authselect counterpart" id="oval:ssg-test_pam_smartcard_symlinked_to_authselect:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_pam_smartcard_symlinked_to_authselect:obj:1"/>
          <unix:state state_ref="oval:ssg-state_pam_smartcard_symlinked_to_authselect:ste:1"/>
        </unix:symlink_test>
        <unix:symlink_test check="all" check_existence="all_exist" comment="The 'system-auth' PAM config is a symlink to its authselect counterpart" id="oval:ssg-test_pam_system_symlinked_to_authselect:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_pam_system_symlinked_to_authselect:obj:1"/>
          <unix:state state_ref="oval:ssg-state_pam_system_symlinked_to_authselect:ste:1"/>
        </unix:symlink_test>
        <ind:textfilecontent54_test check="at least one" comment="correct banner in /etc/issue" id="oval:ssg-test_banner_etc_issue:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_banner_etc_issue:obj:1"/>
          <ind:state state_ref="oval:ssg-state_banner_etc_issue:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="at least one" comment="correct banner in /etc/issue.net" id="oval:ssg-test_banner_etc_issue_net:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_banner_etc_issue_net:obj:1"/>
          <ind:state state_ref="oval:ssg-state_banner_etc_issue_net:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="/etc/motd exists" id="oval:ssg-test_banner_etc_motd_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_banner_etc_motd_exists:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="at least one" comment="correct banner in /etc/motd" id="oval:ssg-test_banner_etc_motd:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_banner_etc_motd:obj:1"/>
          <ind:state state_ref="oval:ssg-state_banner_etc_motd:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="GUI banner is enabled" id="oval:ssg-test_banner_gui_enabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_banner_gui_enabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="GUI banner cannot be changed by user" id="oval:ssg-test_prevent_user_banner_gui_enabled_change:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_banner_gui_enabled_change:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="GUI banner cannot be changed by user" id="oval:ssg-test_prevent_user_banner_change:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_banner_change:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="login banner text is correctly set" id="oval:ssg-test_gdm_login_banner_text_setting:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_gdm_login_banner_text_setting:obj:1"/>
          <ind:state state_ref="oval:ssg-state_gdm_login_banner_text_setting:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check that pam_pwquality.so exists in system-auth" id="oval:ssg-test_accounts_password_pam_modules_in_authselect_profile_pam_pwquality_system_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_pam_pwquality_system_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check that pam_pwhistory.so exists in system-auth" id="oval:ssg-test_accounts_password_pam_modules_in_authselect_profile_pam_pwhistory_system_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_pam_pwhistory_system_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check that pam_faillock.so exists in system-auth" id="oval:ssg-test_accounts_password_pam_modules_in_authselect_profile_pam_faillock_system_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_pam_faillock_system_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check that pam_unix.so exists in system-auth" id="oval:ssg-test_accounts_password_pam_modules_in_authselect_profile_pam_unix_system_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_pam_unix_system_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check that pam_pwquality.so exists in password-auth" id="oval:ssg-test_accounts_password_pam_modules_in_authselect_profile_pam_pwquality_password_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_pam_pwquality_password_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check that pam_pwhistory.so exists in password-auth" id="oval:ssg-test_accounts_password_pam_modules_in_authselect_profile_pam_pwhistory_password_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_pam_pwhistory_password_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check that pam_faillock.so exists in password-auth" id="oval:ssg-test_accounts_password_pam_modules_in_authselect_profile_pam_faillock_password_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_pam_faillock_password_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check that pam_unix.so exists in password-auth" id="oval:ssg-test_accounts_password_pam_modules_in_authselect_profile_pam_unix_password_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_pam_unix_password_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="No more than one pam_unix.so is expected in auth section of /etc/pam.d/password-auth" id="oval:ssg-test_pam_unix_password-auth_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_pam_unix_password-auth_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="No more than one pam_unix.so is expected in account section of /etc/pam.d/password-auth" id="oval:ssg-test_pam_unix_password-auth_account:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_pam_unix_password-auth_account:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="No more than one pam_unix.so is expected in password section of /etc/pam.d/password-auth" id="oval:ssg-test_pam_unix_password-auth_password:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_pam_unix_password-auth_password:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="No more than one pam_unix.so is expected in session section of /etc/pam.d/password-auth" id="oval:ssg-test_pam_unix_password-auth_session:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_pam_unix_password-auth_session:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="No more than one pam_unix.so is expected in auth section of /etc/pam.d/system-auth" id="oval:ssg-test_pam_unix_system-auth_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_pam_unix_system-auth_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="No more than one pam_unix.so is expected in account section of /etc/pam.d/system-auth" id="oval:ssg-test_pam_unix_system-auth_account:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_pam_unix_system-auth_account:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="No more than one pam_unix.so is expected in password section of /etc/pam.d/system-auth" id="oval:ssg-test_pam_unix_system-auth_password:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_pam_unix_system-auth_password:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="No more than one pam_unix.so is expected in session section of /etc/pam.d/system-auth" id="oval:ssg-test_pam_unix_system-auth_session:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_pam_unix_system-auth_session:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check absence of conf pam_succeed_if in /etc/pam.d/sudo" id="oval:ssg-test_disallow_bypass_password_sudo:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_disallow_bypass_password_sudo:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check the pam_lastlog is configured to show last login information" id="oval:ssg-test_display_login_attempts:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-obj_display_login_attempts:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="tests the presence of pam_namespace.so module in the /etc/pam.d/login file" id="oval:ssg-test_enable_pam_namespace:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_enable_pam_namespace:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="No more than one pam_unix.so is expected in auth section of password-auth" id="oval:ssg-test_pam_faillock_password_auth_pam_unix_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_pam_faillock_password_auth_pam_unix_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in auth section of password-auth" id="oval:ssg-test_pam_faillock_password_auth_pam_faillock_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_pam_faillock_password_auth_pam_faillock_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in auth section of password-auth" id="oval:ssg-test_pam_faillock_password_auth_pam_faillock_account:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_pam_faillock_password_auth_pam_faillock_account:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="No more than one pam_unix.so is expected in auth section of system-auth" id="oval:ssg-test_pam_faillock_system_auth_pam_unix_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_pam_faillock_system_auth_pam_unix_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in auth section of system-auth" id="oval:ssg-test_pam_faillock_system_auth_pam_faillock_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_pam_faillock_system_auth_pam_faillock_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in auth section of system-auth" id="oval:ssg-test_pam_faillock_system_auth_pam_faillock_account:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_pam_faillock_system_auth_pam_faillock_account:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:selinuxsecuritycontext_test check="all" check_existence="all_exist" comment="faillog_t context is set in pam_faillock.so tally directories" id="oval:ssg-test_account_password_selinux_faillock_dir:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_account_password_selinux_faillock_dir:obj:1"/>
          <linux:state state_ref="oval:ssg-state_account_password_selinux_faillock_dir:ste:1"/>
        </linux:selinuxsecuritycontext_test>
        <ind:variable_test check="all" check_existence="none_exist" comment="Check the existence of faillock tally dirs" id="oval:ssg-test_account_password_selinux_faillock_dir_not_set:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_account_password_selinux_faillock_dir_not_set:obj:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check the presence of audit parameter in system-auth" id="oval:ssg-test_account_pam_faillock_audit_parameter_system_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_all_account_pam_faillock_audit_parameter_system_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of audit parameter in system-auth" id="oval:ssg-test_account_pam_faillock_audit_parameter_no_pamd_system:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_all_account_pam_faillock_audit_parameter_system_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check the presence of audit parameter in password-auth" id="oval:ssg-test_account_pam_faillock_audit_parameter_password_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_all_account_pam_faillock_audit_parameter_password_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of audit parameter in password-auth" id="oval:ssg-test_account_pam_faillock_audit_parameter_no_pamd_password:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_all_account_pam_faillock_audit_parameter_password_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected audit value in in /etc/security/faillock.conf" id="oval:ssg-test_account_pam_faillock_audit_parameter_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_account_pam_faillock_audit_parameter_faillock_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of audit parameter in /etc/security/faillock.conf" id="oval:ssg-test_account_pam_faillock_audit_parameter_no_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_account_pam_faillock_audit_parameter_faillock_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check pam_pwhistory.so presence in /etc/pam.d/password-auth" id="oval:ssg-test_accounts_password_pam_pwhistory_remember_password_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_pwhistory_remember_password_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check remember parameter is present and correct in /etc/pam.d/password-auth" id="oval:ssg-test_accounts_password_pam_pwhistory_remember_password_auth_pamd:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_pwhistory_remember_password_auth_pamd:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_password_pam_pwhistory_remember_password_auth:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of remember parameter in /etc/security/pwhistory.conf" id="oval:ssg-test_accounts_password_pam_pwhistory_remember_password_auth_no_pwhistory_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_pwhistory_remember_password_auth_param_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check remember parameter is absent in /etc/pam.d/password-auth" id="oval:ssg-test_accounts_password_pam_pwhistory_remember_password_auth_no_pamd:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_pwhistory_remember_password_auth_pamd:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check remember parameter is present and correct in /etc/security/pwhistory.conf" id="oval:ssg-test_accounts_password_pam_pwhistory_remember_password_auth_pwhistory_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_pwhistory_remember_password_auth_param_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_password_pam_pwhistory_remember_password_auth:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check pam_pwhistory.so presence in /etc/pam.d/system-auth" id="oval:ssg-test_accounts_password_pam_pwhistory_remember_system_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_pwhistory_remember_system_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check remember parameter is present and correct in /etc/pam.d/system-auth" id="oval:ssg-test_accounts_password_pam_pwhistory_remember_system_auth_pamd:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_pwhistory_remember_system_auth_pamd:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_password_pam_pwhistory_remember_system_auth:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of remember parameter in /etc/security/pwhistory.conf" id="oval:ssg-test_accounts_password_pam_pwhistory_remember_system_auth_no_pwhistory_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_pwhistory_remember_system_auth_param_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check remember parameter is absent in /etc/pam.d/system-auth" id="oval:ssg-test_accounts_password_pam_pwhistory_remember_system_auth_no_pamd:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_pwhistory_remember_system_auth_pamd:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check remember parameter is present and correct in /etc/security/pwhistory.conf" id="oval:ssg-test_accounts_password_pam_pwhistory_remember_system_auth_pwhistory_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_pwhistory_remember_system_auth_param_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_password_pam_pwhistory_remember_system_auth:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="At least one pwhistory line exists" id="oval:ssg-accounts_password_pam_pwhistory_use_authtok_test_pwhistory_exists_system-auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-accounts_password_pam_pwhistory_use_authtok_obj_pwhistory_exists_system-auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="use_authtok is configured in pam pwhistory in common_password file" id="oval:ssg-accounts_password_pam_pwhistory_use_authtok_test_password_pam_pwhistory_use_authtok_system-auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-accounts_password_pam_pwhistory_use_authtok_obj_use_authtok_system-auth:obj:1"/>
          <ind:state state_ref="oval:ssg-accounts_password_pam_pwhistory_use_authtok_ste_use_authtok:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="At least one pam_unix line exists" id="oval:ssg-test_accounts_password_pam_unix_authtok_pam_unix_exists_common-password:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_password_pam_unix_authtok_pam_unix_exists_common-password:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="use_authtok is configured in pam unix in  /etc/pam.d/common-password file, ignoring first line on stack" id="oval:ssg-test_accounts_password_pam_unix_authtok_prm_exists_not_initial_common-password:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_password_pam_unix_authtok_pam_unix_lines_not_initial_common-password:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_accounts_password_pam_unix_authtok_prm_exists:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check pam_pwhistory.so presence in PAM file" id="oval:ssg-test_accounts_password_pam_unix_remember:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_unix_remember:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check remember parameter is present and correct in PAM file" id="oval:ssg-test_accounts_password_pam_unix_remember_pamd:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_unix_remember_pamd:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_password_pam_unix_remember:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of remember parameter in /etc/security/pwhistory.conf" id="oval:ssg-test_accounts_password_pam_unix_remember_no_pwhistory_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_unix_remember_param_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check remember parameter is absent in PAM file" id="oval:ssg-test_accounts_password_pam_unix_remember_no_pamd:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_unix_remember_pamd:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check remember parameter is present and correct in /etc/security/pwhistory.conf" id="oval:ssg-test_accounts_password_pam_unix_remember_pwhistory_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_unix_remember_param_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_password_pam_unix_remember:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Test if remember attribute of pam_unix.so is set correctly in /etc/pam.d/system-auth" id="oval:ssg-test_accounts_password_pam_unix_remember_legacy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_unix_remember_legacy:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_password_pam_unix_remember:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check the presence of audit parameter in system-auth" id="oval:ssg-test_pam_faillock_audit_parameter_system_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_all_pam_faillock_audit_parameter_system_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of audit parameter in system-auth" id="oval:ssg-test_pam_faillock_audit_parameter_no_pamd_system:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_all_pam_faillock_audit_parameter_system_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check the presence of audit parameter in password-auth" id="oval:ssg-test_pam_faillock_audit_parameter_password_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_all_pam_faillock_audit_parameter_password_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of audit parameter in password-auth" id="oval:ssg-test_pam_faillock_audit_parameter_no_pamd_password:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_all_pam_faillock_audit_parameter_password_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected audit value in in /etc/security/faillock.conf" id="oval:ssg-test_pam_faillock_audit_parameter_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_pam_faillock_audit_parameter_faillock_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of audit parameter in /etc/security/faillock.conf" id="oval:ssg-test_pam_faillock_audit_parameter_no_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_pam_faillock_audit_parameter_faillock_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="No more than one pam_unix.so is expected in auth section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_system_pam_unix_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_system_pam_unix_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="No more than one pam_unix.so is expected in auth section of password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_password_pam_unix_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_password_pam_unix_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one pattern occurrence is expected in auth section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_system_pam_faillock_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_system_pam_faillock_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one pattern occurrence is expected in account section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_system_pam_faillock_account:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_system_pam_faillock_account:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one pattern occurrence is expected in auth section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_password_pam_faillock_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_password_pam_faillock_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one pattern occurrence is expected in account section of password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_password_pam_faillock_account:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_password_pam_faillock_account:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected even_deny_root parameter in system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_parameter_pamd_system:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_parameter_pamd_system:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of even_deny_root parameter in system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_parameter_no_pamd_system:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_parameter_pamd_system:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected even_deny_root parameter in password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_parameter_pamd_password:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_parameter_pamd_password:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of even_deny_root parameter in password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_parameter_no_pamd_password:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_parameter_pamd_password:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected even_deny_root parameter in /etc/security/faillock.conf" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_parameter_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_parameter_faillock_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of even_deny_root parameter in /etc/security/faillock.conf" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_root_parameter_no_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_parameter_faillock_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check that the expected dir value in system-auth is present both with preauth and       authfail" id="oval:ssg-test_pam_faillock_dir_parameter_system_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_pam_faillock_dir_parameter_system_auth:obj:1"/>
          <ind:state state_ref="oval:ssg-state_pam_faillock_dir_parameter_system_auth:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of dir parameter in system-auth" id="oval:ssg-test_pam_faillock_dir_parameter_no_pamd_system:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_all_pam_faillock_dir_parameter_system_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check that the expected dir value in password-auth is present both with preauth and       authfail" id="oval:ssg-test_pam_faillock_dir_parameter_password_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_pam_faillock_dir_parameter_password_auth:obj:1"/>
          <ind:state state_ref="oval:ssg-state_pam_faillock_dir_parameter_password_auth:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of dir parameter in password-auth" id="oval:ssg-test_pam_faillock_dir_parameter_no_pamd_password:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_all_pam_faillock_dir_parameter_password_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected dir value in in /etc/security/faillock.conf" id="oval:ssg-test_pam_faillock_dir_parameter_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_pam_faillock_dir_parameter_faillock_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_pam_faillock_dir_parameter_not_default_value:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of dir parameter in /etc/security/faillock.conf" id="oval:ssg-test_pam_faillock_dir_parameter_no_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_pam_faillock_dir_parameter_faillock_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="No more than one pam_unix.so is expected in auth section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_enforce_local_system_pam_unix_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_enforce_local_system_pam_unix_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="No more than one pam_unix.so is expected in auth section of password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_enforce_local_password_pam_unix_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_enforce_local_password_pam_unix_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="One and only one pattern occurrence is expected in auth section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_enforce_local_system_pam_faillock_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_enforce_local_system_pam_faillock_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="One and only one pattern occurrence is expected in account section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_enforce_local_system_pam_faillock_account:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_enforce_local_system_pam_faillock_account:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="One and only one pattern occurrence is expected in auth section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_enforce_local_password_pam_faillock_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_enforce_local_password_pam_faillock_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="One and only one pattern occurrence is expected in account section of password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_enforce_local_password_pam_faillock_account:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_enforce_local_password_pam_faillock_account:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected local_users_only parameter in /etc/security/faillock.conf" id="oval:ssg-test_accounts_passwords_pam_faillock_enforce_local_parameter_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_enforce_local_parameter_faillock_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="No more than one pam_unix.so is expected in auth section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_system_pam_unix_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_system_pam_unix_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="No more than one pam_unix.so is expected in auth section of password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_password_pam_unix_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_password_pam_unix_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one pattern occurrence is expected in auth section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_system_pam_faillock_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_system_pam_faillock_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one pattern occurrence is expected in account section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_system_pam_faillock_account:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_system_pam_faillock_account:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one pattern occurrence is expected in auth section of password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_password_pam_faillock_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_password_pam_faillock_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one pattern occurrence is expected in account section of password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_password_pam_faillock_account:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_password_pam_faillock_account:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected even_deny_root parameter in system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_pamd_system:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_pamd_system:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of even_deny_root parameter in system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_no_pamd_system:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_pamd_system:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected even_deny_root parameter in password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_pamd_password:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_pamd_password:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of even_deny_root parameter in password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_no_pamd_password:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_pamd_password:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected even_deny_root parameter in /etc/security/faillock.conf" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_faillock_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of even_deny_root parameter in /etc/security/faillock.conf" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_no_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_faillock_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check root_unlock_time &gt;= var_accounts_passwords_pam_faillock_root_unlock_time in auth section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_pamd_system:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_pamd_system:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of root_unlock_time parameter in system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_no_pamd_system:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_pamd_system:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check root_unlock_time &gt;= var_accounts_passwords_pam_faillock_root_unlock_time in auth section of password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_pamd_password:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_pamd_password:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of root_unlock_time parameter in password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_no_pamd_password:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_pamd_password:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check root_unlock_time &gt;= 60 in /etc/security/faillock.conf" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_faillock_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of root_unlock_time parameter in /etc/security/faillock.conf" id="oval:ssg-test_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_no_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_faillock_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check the presence of silent parameter in system-auth" id="oval:ssg-test_pam_faillock_silent_parameter_system_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_all_pam_faillock_silent_parameter_system_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of silent parameter in system-auth" id="oval:ssg-test_pam_faillock_silent_parameter_no_pamd_system:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_all_pam_faillock_silent_parameter_system_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check the presence of silent parameter in password-auth" id="oval:ssg-test_pam_faillock_silent_parameter_password_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_all_pam_faillock_silent_parameter_password_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of silent parameter in password-auth" id="oval:ssg-test_pam_faillock_silent_parameter_no_pamd_password:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_all_pam_faillock_silent_parameter_password_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected silent value in in /etc/security/faillock.conf" id="oval:ssg-test_pam_faillock_silent_parameter_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_pam_faillock_silent_parameter_faillock_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of silent parameter in /etc/security/faillock.conf" id="oval:ssg-test_pam_faillock_silent_parameter_no_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_pam_faillock_silent_parameter_faillock_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="no more that one pam_unix.so is expected in auth section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_system_pam_unix_auth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_system_pam_unix_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in auth section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_system_pam_faillock_auth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_system_pam_faillock_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="no more that one pam_unix.so is expected in auth section of password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_password_pam_unix_auth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_password_pam_unix_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in auth section of password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_password_pam_faillock_auth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_password_pam_faillock_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_system_pam_faillock_account:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_system_pam_faillock_account:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_password_pam_faillock_account:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_password_pam_faillock_account:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of unlock_time parameter in system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_no_pamd_system:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_pamd_system:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected unlock_time value in system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_pamd_system:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_pamd_system:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_lower_bound:ste:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_special_allowed_value:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of unlock_time parameter in password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_no_pamd_password:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_pamd_password:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected unlock_time value in password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_pamd_password:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_pamd_password:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_lower_bound:ste:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_special_allowed_value:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected unlock_time value in /etc/security/faillock.conf" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_faillock_conf:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_faillock_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_lower_bound:ste:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_special_allowed_value:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of unlock_time parameter in /etc/security/faillock.conf" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_no_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_faillock_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check the configuration of /etc/security/pwquality.conf" id="oval:ssg-test_password_pam_pwquality_enforce_for_root:tst:1" state_operator="AND" version="3">
          <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_enforce_for_root:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="check the configuration of /etc/pam.d/password-auth" id="oval:ssg-test_accounts_password_pam_pwquality_password_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_pwquality_password_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="check the configuration of /etc/pam.d/system-auth" id="oval:ssg-test_accounts_password_pam_pwquality_system_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_pam_pwquality_system_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check the configuration of /etc/pam.d/system-auth" id="oval:ssg-test_password_pam_pwquality_retry_system_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_retry_system_auth:obj:1"/>
          <ind:state state_ref="oval:ssg-state_password_pam_retry_upper_bound:ste:1"/>
          <ind:state state_ref="oval:ssg-state_password_pam_retry_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="check the configuration of /etc/pam.d/system-auth" id="oval:ssg-test_password_pam_pwquality_retry_system_auth_not_set:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_retry_system_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check the configuration of /etc/security/pwquality.conf" id="oval:ssg-test_password_pam_pwquality_retry_pwquality_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_retry_pwquality_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_password_pam_retry_upper_bound:ste:1"/>
          <ind:state state_ref="oval:ssg-state_password_pam_retry_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check if /etc/libuser.conf hashing algorithm option is correct" id="oval:ssg-test_set_password_hashing_algorithm_libuserconf:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_set_password_hashing_algorithm_libuserconf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_set_password_hashing_algorithm_libuserconf:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" comment="The value of ENCRYPT_METHOD should be set appropriately in /etc/login.defs" id="oval:ssg-test_password_hashing_algorithm_logindefs:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-variable_object_test_password_hashing_algorithm_logindefs:obj:1"/>
          <ind:state state_ref="oval:ssg-state_test_password_hashing_algorithm_logindefs:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="check if pam_unix.so hashing algorithm option is correct and specified only once in /etc/pam.d/password-auth" id="oval:ssg-test_set_password_hashing_algorithm_passwordauth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_set_password_hashing_algorithm_passwordauth:obj:1"/>
          <ind:state state_ref="oval:ssg-state_set_password_hashing_algorithm_passwordauth:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check if pam_unix.so hashing algorithm option is correct and specified only once in /etc/pam.d/system-auth" id="oval:ssg-test_pam_unix_hashing_algorithm_systemauth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_pam_unix_hashing_algorithm_systemauth:obj:1"/>
          <ind:state state_ref="oval:ssg-state_pam_unix_hashing_algorithm_systemauth:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="SHA_CRYPT_MIN_ROUNDS is not explicitly configured in /etc/login.defs and therefore takes on the default value" id="oval:ssg-test_etc_login_defs_sha_crypt_min_rounds_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_etc_login_defs_sha_crypt_min_rounds_default:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="SHA_CRYPT_MIN_ROUNDS is explicitly configured in /etc/login.defs and its value most be greater or equal to 5000" id="oval:ssg-test_etc_login_defs_sha_crypt_min_rounds_present:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_etc_login_defs_sha_crypt_min_rounds_present:obj:1"/>
          <ind:state state_ref="oval:ssg-state_etc_login_defs_sha_crypt_rounds:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="SHA_CRYPT_MAX_ROUNDS is not explicitly configured in /etc/login.defs and therefore takes on the default value" id="oval:ssg-test_etc_login_defs_sha_crypt_max_rounds_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_etc_login_defs_sha_crypt_max_rounds_default:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="SHA_CRYPT_MAX_ROUNDS is explicitly configured in /etc/login.defs and its value most be greater or equal to 5000" id="oval:ssg-test_etc_login_defs_sha_crypt_max_rounds_present:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_etc_login_defs_sha_crypt_max_rounds_present:obj:1"/>
          <ind:state state_ref="oval:ssg-state_etc_login_defs_sha_crypt_rounds:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if the variable is set to 5000 or lower" id="oval:ssg-test_var_password_hashing_min_rounds_login_defs_le_5000:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_password_hashing_min_rounds_login_defs_le_5000:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_password_hashing_min_rounds_login_defs_le_5000:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check if CtrlAltDelBurstAction is set to none" id="oval:ssg-test_disable_ctrlaltdel_burstaction:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_disable_ctrlaltdel_burstaction:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:symlink_test check="all" check_existence="all_exist" comment="Disable Ctrl-Alt-Del key sequence override exists" id="oval:ssg-test_disable_ctrlaltdel_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_disable_ctrlaltdel_exists:obj:1"/>
          <unix:state state_ref="oval:ssg-state_disable_ctrlaltdel_exists:ste:1"/>
        </unix:symlink_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check systemd.confirm_spawn=(1|true|yes|on) not in GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_disable_interactive_boot_grub_cmdline_linux:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_disable_interactive_boot_grub_cmdline_linux:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check systemd.confirm_spawn=(1|true|yes|on) not in GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_disable_interactive_boot_grub_cmdline_linux_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_disable_interactive_boot_grub_cmdline_linux_default:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of StopIdleSessionSec setting in the /etc/systemd/logind.conf file" id="oval:ssg-test_logind_session_timeout:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_logind_session_timeout:obj:1"/>
          <ind:state state_ref="oval:ssg-state_logind_session_timeout:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="The configuration file /etc/systemd/logind.conf exists for logind_session_timeout" id="oval:ssg-test_logind_session_timeout_config_file_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_logind_session_timeout_config_file:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests that     /sbin/sulogin     was not removed from the default systemd emergency.service to ensure that a     password must be entered to access single user mode" id="oval:ssg-test_require_emergency_service:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_require_emergency_service:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests that the systemd emergency.service is in the emergency.target" id="oval:ssg-test_require_emergency_service_emergency_target:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_require_emergency_service_emergency:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" comment="look for emergency.service in /etc/systemd/system" id="oval:ssg-test_no_custom_emergency_service:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_no_custom_emergency_service:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" comment="look for emergency.target in /etc/systemd/system" id="oval:ssg-test_no_custom_emergency_target:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_no_custom_emergency_target:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" comment="Look for drop in config files for emergency.service" id="oval:ssg-test_require_emergency_target_auth_drop_in_config_exist:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_require_emergency_target_auth_drop_in_config_exist:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests that     /sbin/sulogin     was not removed from the default systemd rescue.service to ensure that a   password must be entered to access single user mode" id="oval:ssg-test_require_rescue_service_distro:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_require_rescue_service_distro:obj:1"/>
          <ind:state state_ref="oval:ssg-state_require_rescue_service:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests that/sbin/sulogin     is defined in /etc/systemd/system/rescue.service.d/*.conf" id="oval:ssg-test_require_rescue_service_override:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_require_rescue_service_override:obj:1"/>
          <ind:state state_ref="oval:ssg-state_require_rescue_service:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check that there is no override file for rescue.service with Execstart - directive" id="oval:ssg-test_rescue_service_not_overridden:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_require_rescue_service_override:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests that the systemd rescue.service is in the runlevel1.target" id="oval:ssg-test_require_rescue_service_runlevel1:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_require_rescue_service_runlevel1:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" comment="look for rescue.service in /etc/systemd/system" id="oval:ssg-test_no_custom_rescue_service:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_no_custom_rescue_service:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" comment="look for runlevel1.target in /etc/systemd/system" id="oval:ssg-test_no_custom_runlevel1_target:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_no_custom_runlevel1_target:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check tmux is configured to exec on the last line of /etc/bashrc" id="oval:ssg-test_configure_bashrc_exec_tmux:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_configure_bashrc_exec_tmux:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check tmux is configured to be launched on the last line of /etc/bashrc" id="oval:ssg-test_configure_bashrc_tmux:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_configure_bashrc_tmux:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check lock-after-time is set to 900 in /etc/tmux.conf" id="oval:ssg-test_configure_tmux_lock_after_time:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_configure_tmux_lock_after_time:obj:1"/>
          <ind:state state_ref="oval:ssg-state_configure_tmux_lock_after_time_lower_boundary:ste:1"/>
          <ind:state state_ref="oval:ssg-state_configure_tmux_lock_after_time_upper_boundary:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check lock-command is set to vlock in /etc/tmux.conf" id="oval:ssg-test_configure_tmux_lock_command:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_configure_tmux_lock_command:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check lock-sessin is bound to a key in /etc/tmux.conf" id="oval:ssg-test_configure_tmux_lock_keybinding:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_configure_tmux_lock_keybinding:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="check that tmux is not listed in /etc/shells" id="oval:ssg-test_no_tmux_in_shells:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_no_tmux_in_shells:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check that card_drivers is configured for opensc" id="oval:ssg-test_configure_opensc_card_drivers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_configure_opensc_card_drivers:obj:1"/>
          <ind:state state_ref="oval:ssg-state_configure_opensc_card_drivers:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check that force_card_driver is configured for opensc" id="oval:ssg-test_force_opensc_card_drivers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_force_opensc_card_drivers:obj:1"/>
          <ind:state state_ref="oval:ssg-state_force_opensc_card_drivers:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="There should not exist duplicate user ids in /etc/passwd" id="oval:ssg-test_etc_passwd_no_duplicate_user_ids:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_count_of_all_uids:obj:1"/>
          <ind:state state_ref="oval:ssg-state_no_duplicate_uids:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="query /etc/passwd" id="oval:ssg-test_accounts_authorized_local_users:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_authorized_local_users:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_authorized_local_users:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="There should not exist duplicate group ids in /etc/passwd" id="oval:ssg-test_etc_group_no_duplicate_group_ids:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_count_of_all_group_ids:obj:1"/>
          <ind:state state_ref="oval:ssg-state_no_duplicate_group_ids:ste:1"/>
        </ind:variable_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="There should not exist duplicate group names in /etc/passwd" id="oval:ssg-test_etc_group_no_duplicate_group_names:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_count_of_all_group_names:obj:1"/>
          <ind:state state_ref="oval:ssg-state_no_duplicate_group_names:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check for nologin in /etc/shells" id="oval:ssg-test_no_nologin_in_shells:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_no_nologin_in_shells:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="the value INACTIVE parameter should be set appropriately in /etc/default/useradd" id="oval:ssg-test_etc_default_useradd_inactive:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_etc_default_useradd_inactive:obj:1"/>
          <ind:state state_ref="oval:ssg-state_etc_default_useradd_inactive:ste:1"/>
          <ind:state state_ref="oval:ssg-state_etc_default_useradd_inactive_nonnegative:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="There should not exist duplicate user name entries in /etc/passwd" id="oval:ssg-test_etc_passwd_no_duplicate_user_names:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_count_of_all_usernames_from_etc_passwd:obj:1"/>
          <ind:state state_ref="oval:ssg-state_etc_passwd_no_duplicate_user_names:ste:1"/>
        </ind:variable_test>
        <ind:variable_test check="all" comment="The value of PASS_MAX_DAYS should be set appropriately in /etc/login.defs" id="oval:ssg-test_pass_max_days:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_last_pass_max_days_instance_value:obj:1"/>
          <ind:state state_ref="oval:ssg-state_last_pass_max_days_instance_value:ste:1"/>
        </ind:variable_test>
        <ind:variable_test check="all" comment="The value of PASS_MIN_DAYS should be set appropriately in /etc/login.defs" id="oval:ssg-test_pass_min_days:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_last_pass_min_days_instance_value:obj:1"/>
          <ind:state state_ref="oval:ssg-state_last_pass_min_days_instance_value:ste:1"/>
        </ind:variable_test>
        <ind:variable_test check="all" comment="The value of PASS_MIN_LEN should be set appropriately in /etc/login.defs" id="oval:ssg-test_pass_min_len:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_last_pass_min_len_instance_value:obj:1"/>
          <ind:state state_ref="oval:ssg-state_last_pass_min_len_instance_value:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="Compares a specific field in /etc/shadow with a specific variable value" id="oval:ssg-test_accounts_password_set_max_life_existing_password_max_life_existing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_accounts_password_set_max_life_existing_password_max_life_existing:obj:1"/>
          <ind:state state_ref="oval:ssg-state_test_accounts_password_set_max_life_existing_password_max_life_existing:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="Compares a specific field in /etc/shadow with a specific variable value" id="oval:ssg-test_accounts_password_set_max_life_existing_password_max_life_existing_minimum:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_accounts_password_set_max_life_existing_password_max_life_existing_minimum:obj:1"/>
          <ind:state state_ref="oval:ssg-state_test_accounts_password_set_max_life_existing_password_max_life_existing_minimum:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Passwords must have the maximum password age set non-empty in /etc/shadow." id="oval:ssg-test_accounts_password_set_max_life_existing_password_max_life_not_empty:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_set_max_life_existing_shadow_password_users_max_life_not_existing:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:shadow_test check="all" comment="root max age" id="oval:ssg-test_accounts_password_set_max_life_root:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_accounts_password_set_max_life_root:obj:1"/>
          <unix:state state_ref="oval:ssg-state_accounts_password_set_max_life_root:ste:1"/>
        </unix:shadow_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="Compares a specific field in /etc/shadow with a specific variable value" id="oval:ssg-test_accounts_password_set_min_life_existing_password_max_life_existing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_accounts_password_set_min_life_existing_password_max_life_existing:obj:1"/>
          <ind:state state_ref="oval:ssg-state_test_accounts_password_set_min_life_existing_password_max_life_existing:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="Compares a specific field in /etc/shadow with a specific variable value" id="oval:ssg-test_accounts_password_set_min_life_existing_password_max_life_existing_minimum:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_accounts_password_set_min_life_existing_password_max_life_existing_minimum:obj:1"/>
          <ind:state state_ref="oval:ssg-state_test_accounts_password_set_min_life_existing_password_max_life_existing_minimum:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Passwords must have the maximum password age set non-empty in /etc/shadow." id="oval:ssg-test_accounts_password_set_min_life_existing_password_max_life_not_empty:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_set_min_life_existing_shadow_password_users_max_life_not_existing:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="Compares a specific field in /etc/shadow with a specific variable value" id="oval:ssg-test_accounts_password_set_warn_age_existing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_accounts_password_set_warn_age_existing:obj:1"/>
          <ind:state state_ref="oval:ssg-state_test_accounts_password_set_warn_age_existing:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the inexistence of users with a password defined" id="oval:ssg-test_accounts_password_set_warn_age_existing_no_pass:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_set_warn_age_existing_no_pass:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" comment="The value of PASS_WARN_AGE should be set appropriately in /etc/login.defs" id="oval:ssg-test_pass_warn_age:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-variable_object_test_pass_warn_age:obj:1"/>
          <ind:state state_ref="oval:ssg-state_test_pass_warn_age:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="Compares a specific field in /etc/shadow with a specific variable value" id="oval:ssg-test_accounts_set_post_pw_existing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_accounts_set_post_pw_existing:obj:1"/>
          <ind:state state_ref="oval:ssg-state_test_accounts_set_post_pw_existing:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the inexistence of users with a password defined" id="oval:ssg-test_accounts_set_post_pw_existing_no_pass:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_set_post_pw_existing_no_pass:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:password_test check="all" comment="password hashes are shadowed" id="oval:ssg-test_accounts_password_all_shadowed:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_accounts_password_all_shadowed:obj:1"/>
          <unix:state state_ref="oval:ssg-state_accounts_password_all_shadowed:ste:1"/>
        </unix:password_test>
        <unix:shadow_test check="all" comment="password hashes are shadowed using sha512" id="oval:ssg-test_accounts_password_all_shadowed_sha512:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_accounts_password_all_shadowed_sha512:obj:1"/>
          <unix:state state_ref="oval:ssg-state_accounts_password_all_shadowed_sha512_hidepass:ste:1"/>
        </unix:shadow_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if the password last chage time is less than or equal today." id="oval:ssg-test_accounts_password_last_change_is_in_past:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_password_last_change_is_in_past_time_diff:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_password_last_change_is_in_past_time_diff:ste:1"/>
        </ind:variable_test>
        <unix:shadow_test check="all" check_existence="none_exist" comment="Check the inexistence of users with a password defined" id="oval:ssg-test_accounts_password_last_change_is_in_past_no_pass:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_accounts_password_last_change_is_in_past:obj:1"/>
        </unix:shadow_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="make sure remember is not used in /etc/pam.d/common-auth" id="oval:ssg-test_pam_unix_no_remember:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_pam_unix_no_remember:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Test if rounds attribute of pam_unix.so is set correctly in /etc/pam.d/password-auth " id="oval:ssg-test_password_auth_pam_unix_rounds_is_set:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_password_auth_pam_unix_rounds:obj:1"/>
          <ind:state state_ref="oval:ssg-state_password_auth_pam_unix_rounds:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Test if rounds attribute of pam_unix.so is set correctly in /etc/pam.d/system-auth" id="oval:ssg-test_system_auth_pam_unix_rounds_is_set:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_system_auth_pam_unix_rounds:obj:1"/>
          <ind:state state_ref="oval:ssg-state_system_auth_pam_unix_rounds:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Verify all GIDs referenced in /etc/passwd are defined in /etc/group" id="oval:ssg-test_gid_passwd_group_same:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_gid_passwd_group_same:obj:1"/>
          <ind:state state_ref="oval:ssg-state_gid_passwd_group_same:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="make sure nullok is not used in /etc/pam.d/system-auth" id="oval:ssg-test_no_empty_passwords:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_no_empty_passwords:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="make sure there aren't blank or null passwords in /etc/shadow" id="oval:ssg-test_no_empty_passwords_etc_shadow:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_no_empty_passwords_etc_shadow:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" comment=".forward files are not group or world accessible" id="oval:ssg-test_accounts_users_home_forward_file_existance:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_accounts_users_home_forward_file_existance:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="check for existence of lines starting with +" id="oval:ssg-test_no_legacy_plus_entries_etc_group:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_no_legacy_plus_entries_etc_group:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="check for existence of lines starting with +" id="oval:ssg-test_no_legacy_plus_entries_etc_passwd:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_no_legacy_plus_entries_etc_passwd:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="check for existence of lines starting with +" id="oval:ssg-test_no_legacy_plus_entries_etc_shadow:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_no_legacy_plus_entries_etc_shadow:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" comment="look for .netrc in /home" id="oval:ssg-test_no_netrc_files_home:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_no_netrc_files_home:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" comment="look for .rhost in /home" id="oval:ssg-test_no_rhost_files:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_no_rhost_files:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="test that there are no accounts with UID 0 except root in the /etc/passwd file" id="oval:ssg-test_accounts_no_uid_except_root:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_no_uid_except_root:obj:1"/>
          <ind:state state_ref="oval:ssg-state_is_locked_in_shadow:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="test that the root user has GID 0 in the /etc/passwd file" id="oval:ssg-test_accounts_root_gid_zero:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_root_gid_zero:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_root_gid_zero:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="at least one" check_existence="all_exist" comment="check if group in var_pam_wheel_group_for_su variable used by pam_wheel.so exists" id="oval:ssg-test_ensure_pam_wheel_group_empty_group_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_ensure_pam_wheel_group_exists:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="at least one" check_existence="all_exist" comment="check if group defined by pam_wheel.so group option has no members" id="oval:ssg-test_ensure_pam_wheel_group_empty_has_no_members:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_ensure_pam_wheel_group_exists:obj:1"/>
          <ind:state state_ref="oval:ssg-state_ensure_pam_wheel_group_has_no_members:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="make sure root password is set in /etc/shadow" id="oval:ssg-test_root_password_etc_shadow:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_root_password_etc_shadow:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="no groups with GID 0 except root in the /etc/group file" id="oval:ssg-test_groups_no_zero_gid_except_root:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_groups_no_zero_gid_except_root:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/etc/securetty file exists" id="oval:ssg-test_etc_securetty_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_etc_securetty_exists:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="no entries in /etc/securetty" id="oval:ssg-test_no_direct_root_logins:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_no_direct_root_logins:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify there is no account with invalid shell which is not locked exists" id="oval:ssg-test_no_invalid_shell_accounts_unlocked_no_invalid_shell_accounts:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_no_invalid_shell_accounts_unlocked_shells:obj:1"/>
          <ind:state state_ref="oval:ssg-state_no_invalid_shell_accounts_unlocked_valid_shells:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:shadow_test check="all" check_existence="none_exist" comment="system accounts with a password defined" id="oval:ssg-test_no_password_auth_for_systemaccounts:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_no_password_auth_for_systemaccounts:obj:1"/>
        </unix:shadow_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="&lt;0, UID_MIN - 1&gt; system UIDs having shell set" id="oval:ssg-test_shell_defined_default_uid_range:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_etc_passwd_entries:obj:1"/>
          <ind:state state_ref="oval:ssg-state_uid_less_than_zero:ste:1"/>
          <ind:state state_ref="oval:ssg-state_uid_greater_than_or_equal_uid_min:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="SYS_UID_MIN not defined in /etc/login.defs" id="oval:ssg-test_sys_uid_min_not_defined:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_last_sys_uid_min_from_etc_login_defs:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="SYS_UID_MAX not defined in /etc/login.defs" id="oval:ssg-test_sys_uid_max_not_defined:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_last_sys_uid_max_from_etc_login_defs:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="&lt;0, SYS_UID_MIN&gt; system UIDs having shell set" id="oval:ssg-test_shell_defined_reserved_uid_range:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_etc_passwd_entries:obj:1"/>
          <ind:state state_ref="oval:ssg-state_uid_less_than_zero:ste:1"/>
          <ind:state state_ref="oval:ssg-state_uid_greater_than_or_equal_sys_uid_min:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="&lt;SYS_UID_MIN, SYS_UID_MAX&gt; system UIDS having shell set" id="oval:ssg-test_shell_defined_dynalloc_uid_range:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_etc_passwd_entries:obj:1"/>
          <ind:state state_ref="oval:ssg-state_uid_less_than_sys_uid_min:ste:1"/>
          <ind:state state_ref="oval:ssg-state_uid_greater_than_or_equal_sys_uid_max:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="serial ports /etc/securetty" id="oval:ssg-test_serial_ports_etc_securetty:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_serial_ports_etc_securetty:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="virtual consoles /etc/securetty" id="oval:ssg-test_virtual_consoles_etc_securetty:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_virtual_consoles_etc_securetty:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check value of CREATE_HOME in /etc/login.defs" id="oval:ssg-test_accounts_have_homedir_login_defs:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_have_homedir_login_defs:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check FAIL_DELAY in /etc/login.defs" id="oval:ssg-test_accounts_logon_fail_delay:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_logon_fail_delay:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_logon_fail_delay:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="the value maxlogins should be set appropriately in /etc/security/limits.conf" id="oval:ssg-test_maxlogins:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_etc_security_limits_conf_maxlogins:obj:1"/>
          <ind:state state_ref="oval:ssg-state_maxlogins:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="the value maxlogins should be set appropriately in /etc/security/limits.d/*.conf" id="oval:ssg-test_limitsd_maxlogins:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_etc_security_limitsd_conf_maxlogins:obj:1"/>
          <ind:state state_ref="oval:ssg-state_maxlogins:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="the value maxlogins should be set appropriately in /etc/security/limits.d/*.conf" id="oval:ssg-test_limitsd_maxlogins_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_etc_security_limitsd_conf_maxlogins_exists:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="any_exist" comment="Check that /tmp/tmp-inst doesn't exist or it exists and has mode 000" id="oval:ssg-test_tmp_inst:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_tmp_inst:obj:1"/>
          <unix:state state_ref="oval:ssg-state_tmp_inst:ste:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" comment="Check configuration of /tmp in /etc/security/namespace.conf file" id="oval:ssg-test_tmp_in_namespace_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_tmp_in_namespace_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="any_exist" comment="Check that /var/tmp/tmp-inst doesn't exist or it exists and has mode 000" id="oval:ssg-test_var_tmp_tmp_inst:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_var_tmp_tmp_inst:obj:1"/>
          <unix:state state_ref="oval:ssg-state_var_tmp_tmp_inst:ste:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" comment="Check configuration of /tmp in /etc/security/namespace.conf file" id="oval:ssg-test_var_tmp_in_namespace_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_var_tmp_in_namespace_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="TMOUT in /etc/profile" id="oval:ssg-test_etc_profile_tmout:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_etc_profile_tmout:obj:1"/>
          <ind:state state_ref="oval:ssg-state_etc_profile_tmout:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="TMOUT in /etc/profile.d/*.sh" id="oval:ssg-test_etc_profiled_tmout:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_etc_profiled_tmout:obj:1"/>
          <ind:state state_ref="oval:ssg-state_etc_profile_tmout:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check that at least one TMOUT is defined" id="oval:ssg-test_accounts_tmout_defined:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_tmout_defined:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_tmout_defined:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="All TMOUT values must be greater than or equal to 1" id="oval:ssg-test_accounts_tmout_lower_bound:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_tmout_all_tmout_instances:obj:1"/>
          <ind:state state_ref="oval:ssg-state_etc_profile_tmout_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="any_exist" comment="All user initialization files are group-owned by a local interactive user" id="oval:ssg-test_accounts_user_dot_group_ownership:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_accounts_user_dot_group_ownership_init_files:obj:1"/>
          <unix:state state_ref="oval:ssg-state_accounts_user_dot_group_ownership_gids:ste:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Init files do not execute world-writable programs" id="oval:ssg-test_accounts_user_dot_no_world_writable_programs:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_user_dot_no_world_writable_programs_init_files:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="any_exist" comment="All user initialization files are owned by a local interactive user" id="oval:ssg-test_accounts_user_dot_user_ownership:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_accounts_user_dot_user_ownership_init_files:obj:1"/>
          <unix:state state_ref="oval:ssg-state_accounts_user_dot_user_ownership_uids:ste:1"/>
        </unix:file_test>
        <unix:password_test check="all" check_existence="any_exist" comment="All Interactive Users Have A Home Directory Defined" id="oval:ssg-test_accounts_user_interactive_home_directory_defined:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_accounts_user_interactive_home_directory_defined_objects:obj:1"/>
          <unix:state state_ref="oval:ssg-state_accounts_user_interactive_home_directory_defined:ste:1"/>
        </unix:password_test>
        <ind:variable_test check="all" comment="Check the existence of interactive users." id="oval:ssg-test_accounts_user_interactive_home_directory_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_user_interactive_home_directory_exists_dirs_count_fs:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_user_interactive_home_directory_exists_dirs_count_pw:ste:1"/>
        </ind:variable_test>
        <ind:variable_test check="all" check_existence="none_exist" comment="Check the existence of interactive users." id="oval:ssg-test_accounts_user_interactive_home_directory_exists_users:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_user_interactive_home_directory_exists_dirs_count_pw:obj:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="All interactive user home dirs are on separate partitions" id="oval:ssg-test_accounts_user_interactive_home_directory_on_separate_partition:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_user_interactive_home_directory_on_separate_partition_interactive_users:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_user_interactive_home_directory_on_separate_partition_on_separate_partition:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="No interactive users exist on the system" id="oval:ssg-test_accounts_user_interactive_home_directory_on_separate_partition_no_interactive_users:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_user_interactive_home_directory_on_separate_partition_interactive_users:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="any_exist" comment="All home directories files are group-owned by a local interactive user" id="oval:ssg-test_accounts_users_home_files_groupownership:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_accounts_users_home_files_groupownership_dirs:obj:1"/>
          <unix:state state_ref="oval:ssg-state_accounts_users_home_files_groupownership_gids:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="any_exist" comment="All home directories files are owned by a local interactive user" id="oval:ssg-test_accounts_users_home_files_ownership:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_accounts_users_home_files_ownership_dirs:obj:1"/>
          <unix:state state_ref="oval:ssg-state_accounts_users_home_files_ownership_uids:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="any_exist" comment="All files into home directories have proper permissions" id="oval:ssg-test_accounts_users_home_files_permissions_files:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_accounts_users_home_files_permissions_files:obj:1"/>
          <unix:state state_ref="oval:ssg-state_accounts_users_home_files_permissions_dirs:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="any_exist" comment="All directories into home directories have proper permissions" id="oval:ssg-test_accounts_users_home_files_permissions_dirs:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_accounts_users_home_files_permissions_dirs:obj:1"/>
          <unix:state state_ref="oval:ssg-state_accounts_users_home_files_permissions_dirs:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="any_exist" comment=".netrc files are not group or world accessible" id="oval:ssg-test_accounts_users_home_netrc_file_permissions:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_accounts_users_home_netrc_file_permissions:obj:1"/>
          <unix:state state_ref="oval:ssg-state_accounts_users_home_netrc_file_permissions_gread:ste:1"/>
          <unix:state state_ref="oval:ssg-state_accounts_users_home_netrc_file_permissions_gwrite:ste:1"/>
          <unix:state state_ref="oval:ssg-state_accounts_users_home_netrc_file_permissions_gexec:ste:1"/>
          <unix:state state_ref="oval:ssg-state_accounts_users_home_netrc_file_permissions_oread:ste:1"/>
          <unix:state state_ref="oval:ssg-state_accounts_users_home_netrc_file_permissions_owrite:ste:1"/>
          <unix:state state_ref="oval:ssg-state_accounts_users_home_netrc_file_permissions_oexec:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="any_exist" comment="All home directories are group-owned by a local interactive group" id="oval:ssg-test_file_groupownership_home_directories:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownership_home_directories_dirs:obj:1"/>
          <unix:state state_ref="oval:ssg-state_file_groupownership_home_directories_gids:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="any_exist" comment="All home directories are owned by a local interactive user" id="oval:ssg-test_file_ownership_home_directories:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_home_directories_dirs:obj:1"/>
          <unix:state state_ref="oval:ssg-state_file_ownership_home_directories_uids:ste:1"/>
        </unix:file_test>
        <ind:variable_test check="all" check_existence="any_exist" comment="It should not exist duplicated owners of home dirs" id="oval:ssg-test_file_ownership_home_directories_duplicated:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_file_ownership_home_directories_uids_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_file_ownership_home_directories_uids_count_uniq:ste:1"/>
        </ind:variable_test>
        <unix:file_test check="all" check_existence="any_exist" comment="User Bash History File Has Correct Permissions" id="oval:ssg-test_file_permission_user_bash_history:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_permission_user_bash_history:obj:1"/>
          <unix:state state_ref="oval:ssg-state_file_permission_user_bash_history:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="any_exist" comment="Init files have mode 0740 or less permissive" id="oval:ssg-test_file_permission_user_init_files:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_permission_user_init_files:obj:1"/>
          <unix:state state_ref="oval:ssg-state_file_permission_user_init_files:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="any_exist" comment="Init files have mode 0740 or less permissive" id="oval:ssg-test_file_permission_user_init_files_root:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_permission_user_init_files_root:obj:1"/>
          <unix:state state_ref="oval:ssg-state_file_permission_user_init_files_root:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="any_exist" comment="All home directories have proper permissions" id="oval:ssg-test_file_permissions_home_directories:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_permissions_home_directories_dirs:obj:1"/>
          <unix:state state_ref="oval:ssg-state_file_permissions_home_directories_dirs:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="any_exist" comment="All home directories have proper permissions" id="oval:ssg-test_file_permissions_home_dirs:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_permissions_home_dirs_dirs:obj:1"/>
          <unix:state state_ref="oval:ssg-state_file_permissions_home_dirs_dirs:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Check if there aren't directories in root's path having write permission set for group or other" id="oval:ssg-test_accounts_root_path_dirs_no_group_other_write:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_accounts_root_path_dirs_no_group_other_write:obj:1"/>
        </unix:file_test>
        <ind:environmentvariable58_test check="none satisfy" comment="environment variable PATH starts with : or ." id="oval:ssg-test_env_var_begins:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_root_path_no_dot:obj:1"/>
          <ind:state state_ref="oval:ssg-state_begins_colon_period:ste:1"/>
        </ind:environmentvariable58_test>
        <ind:environmentvariable58_test check="none satisfy" comment="environment variable PATH doesn't contain : twice in a row" id="oval:ssg-test_env_var_contains_doublecolon:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_root_path_no_dot:obj:1"/>
          <ind:state state_ref="oval:ssg-state_contains_double_colon:ste:1"/>
        </ind:environmentvariable58_test>
        <ind:environmentvariable58_test check="none satisfy" comment="environment variable PATH doesn't contain . twice in a row" id="oval:ssg-test_env_var_contains_doubleperiod:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_root_path_no_dot:obj:1"/>
          <ind:state state_ref="oval:ssg-state_contains_double_period:ste:1"/>
        </ind:environmentvariable58_test>
        <ind:environmentvariable58_test check="none satisfy" comment="environment variable PATH ends with : or ." id="oval:ssg-test_env_var_ends:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_root_path_no_dot:obj:1"/>
          <ind:state state_ref="oval:ssg-state_ends_colon_period:ste:1"/>
        </ind:environmentvariable58_test>
        <ind:environmentvariable58_test check="none satisfy" comment="environment variable PATH starts with an absolute path /" id="oval:ssg-test_env_var_begins_slash:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_root_path_no_dot:obj:1"/>
          <ind:state state_ref="oval:ssg-state_begins_slash:ste:1"/>
        </ind:environmentvariable58_test>
        <ind:environmentvariable58_test check="none satisfy" comment="environment variable PATH contains relative paths" id="oval:ssg-test_env_var_contains_relative_path:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_root_path_no_dot:obj:1"/>
          <ind:state state_ref="oval:ssg-state_contains_relative_path:ste:1"/>
        </ind:environmentvariable58_test>
        <ind:variable_test check="all" comment="Test the retrieved /etc/bashrc umask value(s) match the var_accounts_user_umask requirement" id="oval:ssg-tst_accounts_umask_etc_bashrc:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_umask_etc_bashrc:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_accounts_umask_etc_bashrc:ste:1"/>
        </ind:variable_test>
        <ind:variable_test check="all" comment="Test the retrieved /etc/csh.cshrc umask value(s) match the var_accounts_user_umask requirement" id="oval:ssg-tst_accounts_umask_etc_csh_cshrc:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_umask_etc_csh_cshrc:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_accounts_umask_etc_csh_cshrc:ste:1"/>
        </ind:variable_test>
        <ind:variable_test check="all" comment="Test the retrieved /etc/login.defs umask value(s) match the var_accounts_user_umask requirement" id="oval:ssg-tst_accounts_umask_etc_login_defs:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_umask_etc_login_defs:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_accounts_umask_etc_login_defs:ste:1"/>
        </ind:variable_test>
        <ind:variable_test check="all" comment="umask value(s) from profile configuration files match the requirement" id="oval:ssg-tst_accounts_umask_etc_profile:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_umask_etc_profile:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_accounts_umask_etc_profile:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Umask must not be defined in user initialization files" id="oval:ssg-test_accounts_umask_interactive_users:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_umask_interactive_users:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Test that no umask with lenient permissions exists" id="oval:ssg-tst_accounts_umask_root:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_umask_root:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check if the parameter was set at the compile time for current kernel" id="oval:ssg-test_trust_cpu_rng_compiled_in:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_trust_cpu_rng_compiled_in:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for kernel command line parameters random.trust_cpu=off in /boot/grub2/grubenv for all kernels" id="oval:ssg-test_trust_cpu_rng_boot_param_off:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_trust_cpu_rng_boot_param:obj:1"/>
          <ind:state state_ref="oval:ssg-state_trust_cpu_rng_boot_param_off:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check forkernel command line parameters random.trust_cpu=on in /boot/grub2/grubenv for all kernels" id="oval:ssg-test_trust_cpu_rng_boot_param_on:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_trust_cpu_rng_boot_param:obj:1"/>
          <ind:state state_ref="oval:ssg-state_trust_cpu_rng_boot_param_on:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="superuser           is defined in /boot/grub2/grub.cfg. Superuser is not           equal to other system account nor root, admin, administrator" id="oval:ssg-test_bootloader_superuser_differ_from_other_users:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_bootloader_unique_superuser:obj:1"/>
          <ind:state state_ref="oval:ssg-state_bootloader_superuser_differ_from_other_users:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of set root setting in the /boot/grub2/grub.cfg file" id="oval:ssg-test_grub2_no_removeable_media:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_grub2_no_removeable_media:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_no_removeable_media:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="The number of menuentry entries matches the number of set root settings" id="oval:ssg-test_grub2_no_removeable_media_count:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_grub2_menuentry_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_set_root_count:ste:1"/>
        </ind:variable_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Check if /boot/grub2/grub.cfg does not exist" id="oval:ssg-test_grub2_no_removeable_media_file_boot_grub2_grub_cfg_absent:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_grub2_no_removeable_media_file_boot_grub2_grub_cfg_absent:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="make sure a password is defined in /boot/grub2/user.cfg" id="oval:ssg-test_grub2_password_usercfg:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_password_usercfg:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="superuser           is defined in /boot/efi/EFI/almalinux/grub.cfg. Superuser is not           equal to other system account nor root, admin, administrator" id="oval:ssg-test_bootloader_uefi_superuser_differ_from_other_users:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_bootloader_uefi_unique_superuser:obj:1"/>
          <ind:state state_ref="oval:ssg-state_bootloader_uefi_superuser_differ_from_other_users:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check if /boot/efi/EFI/almalinux/grub.cfg contains a configfile directive" id="oval:ssg-test_grub2_uefi_admin_username_stub:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_uefi_admin_username_stub:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="superuser           is defined in /boot/grub2/grub.cfg. Superuser is not           equal to other system account nor root, admin, administrator" id="oval:ssg-test_bootloader_uefi_boot_superuser_differ_from_other_users:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_bootloader_uefi_boot_unique_superuser:obj:1"/>
          <ind:state state_ref="oval:ssg-state_bootloader_uefi_superuser_differ_from_other_users:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="make sure a password is defined in /boot/efi/EFI/almalinux/user.cfg" id="oval:ssg-test_grub2_uefi_password_usercfg:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_uefi_password_usercfg:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check if /boot/efi/EFI/almalinux/grub.cfg contains a configfile directive" id="oval:ssg-test_grub2_uefi_password_stub:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_uefi_password_stub:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="make sure a password is defined in /boot/grub2/user.cfg" id="oval:ssg-test_grub2_uefi_password_boot_usercfg:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_uefi_password_boot_usercfg:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of set root setting in the /boot/efi/EFI/almalinux/grub.cfg file" id="oval:ssg-test_uefi_no_removeable_media:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_uefi_no_removeable_media:obj:1"/>
          <ind:state state_ref="oval:ssg-state_uefi_no_removeable_media:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="The number of menuentry entries matches the number of set root settings" id="oval:ssg-test_uefi_no_removeable_media_count:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_uefi_menuentry_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_uefi_set_root_count:ste:1"/>
        </ind:variable_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Check if /boot/efi/EFI/almalinux/grub.cfg does not exist" id="oval:ssg-test_uefi_no_removeable_media_file_boot_efi_EFI_almalinux_grub_cfg_absent:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_uefi_no_removeable_media_file_boot_efi_EFI_almalinux_grub_cfg_absent:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Test presence of image configuration in /etc/zipl.conf" id="oval:ssg-test_zipl_bls_entries_only:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_zipl_bls_entries_only:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="Check /boot/bootmap timestamps" id="oval:ssg-test_zipl_bootmap_is_up_to_date:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_zipl_boot_bootmap_file:obj:1"/>
          <unix:state state_ref="oval:ssg-state_zipl_bootmap_is_newer_than_zipl_conf:ste:1"/>
          <unix:state state_ref="oval:ssg-state_zipl_bootmap_is_newer_than_boot_entries:ste:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="at least one" check_existence="all_exist" comment="Check if argument systemd.debug-shell is present in the line starting with 'options ' in /boot/loader/entries/.*.conf" id="oval:ssg-test_zipl_systemd_debug-shell_argument_in_boot_loader_entries_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_zipl_systemd_debug-shell_argument_in_boot_loader_entries_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_zipl_systemd_debug-shell_argument_in_boot_loader_entries_conf:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if argument systemd.debug-shell is present in /etc/kernel/cmdline" id="oval:ssg-test_zipl_systemd_debug-shell_argument_in_etc_kernel_cmdline:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_zipl_systemd_debug-shell_argument_in_etc_kernel_cmdline:obj:1"/>
          <ind:state state_ref="oval:ssg-state_zipl_systemd_debug-shell_argument_in_etc_kernel_cmdline:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_DEFAULT_MMAP_MIN_ADDR=65536" id="oval:ssg-test_kernel_config_default_mmap_min_addr_x86_64:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_default_mmap_min_addr:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_default_mmap_min_addr_x86_64:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_DEFAULT_MMAP_MIN_ADDR=32768" id="oval:ssg-test_kernel_config_default_mmap_min_addr_aarch64:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_default_mmap_min_addr:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_default_mmap_min_addr_aarch64:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_kernel_config_default_mmap_min_addr_all_kernels:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_default_mmap_min_addr_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_default_mmap_min_addr:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="proc_sys_kernel is for aarch64 architecture" id="oval:ssg-test_proc_sys_kernel_osrelease_arch_aarch64:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_proc_sys_kernel_osrelease_arch_aarch64:obj:1"/>
          <ind:state state_ref="oval:ssg-state_proc_sys_kernel_osrelease_arch_aarch64:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="proc_sys_kernel is for x86_64 architecture" id="oval:ssg-test_proc_sys_kernel_osrelease_arch_x86_64:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_proc_sys_kernel_osrelease_arch_x86_64:obj:1"/>
          <ind:state state_ref="oval:ssg-state_proc_sys_kernel_osrelease_arch_x86_64:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="rsyslog FileCreateMode is configured in only one place" id="oval:ssg-tst_filecreatemode_declared:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_filecreatemode:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" comment="Test if FileCreateMode value is valid" id="oval:ssg-tst_filecreatemode_valid:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_filecreatemode_dec:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_filecreatemode_is_0640_or_stricter:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Test HostLimit" id="oval:ssg-test_logwatch_configured_hostlimit:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_logwatch_configured_hostlimit:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Test SplitHosts" id="oval:ssg-test_logwatch_configured_splithosts:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_logwatch_configured_splithosts:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="cron is configured in /etc/rsyslog.conf" id="oval:ssg-test_cron_logging_rsyslog:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_cron_logging_rsyslog:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="cron is configured in /etc/rsyslog.conf using RainerScript" id="oval:ssg-test_cron_logging_rsyslog_rainer:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_cron_logging_rsyslog_rainer:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="cron is configured in /etc/rsyslog.d" id="oval:ssg-test_cron_logging_rsyslog_dir:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_cron_logging_rsyslog_dir:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="cron is configured in /etc/rsyslog.d using RainerScript" id="oval:ssg-test_cron_logging_rsyslog_dir_rainer:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_cron_logging_rsyslog_dir_rainer:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if $ActionSendStreamDriverAuthMode x509/name is set in /etc/rsyslog.conf" id="oval:ssg-test_rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action_send_stream_driver_auth_mode:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action_send_stream_driver_auth_mode:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if StreamDriverAuthMode is set to x509/name in /etc/rsyslog.conf using RainerScript" id="oval:ssg-test_rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action_send_stream_driver_auth_mode_rainer:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action_send_stream_driver_auth_mode_rainer:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if $ActionSendStreamDriverAuthMode x509/name is set in /etc/rsyslog.conf" id="oval:ssg-test_rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action_send_stream_driver_auth_mode_dir:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action_send_stream_driver_auth_mode_dir:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if StreamDriverAuthMode is set to x509/name in files in /etc/rsyslog.d using RainerScript" id="oval:ssg-test_rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action_send_stream_driver_auth_mode_dir_rainer:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action_send_stream_driver_auth_mode_dir_rainer:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if $ActionSendStreamDriverMode 1 is set in /etc/rsyslog.conf" id="oval:ssg-test_rsyslog_encrypt_offload_actionsendstreamdrivermode_action_send_stream_driver_mode_rsyslog:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rsyslog_encrypt_offload_actionsendstreamdrivermode_action_send_stream_driver_mode_rsyslog:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if StreamDriverMode is set to 1 in /etc/rsyslog.conf using RainerScript" id="oval:ssg-test_rsyslog_encrypt_offload_actionsendstreamdrivermode_action_send_stream_driver_mode_rsyslog_rainer:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rsyslog_encrypt_offload_actionsendstreamdrivermode_action_send_stream_driver_mode_rsyslog_rainer:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if $ActionSendStreamDriverMode 1 is set in /etc/rsyslog.conf" id="oval:ssg-test_rsyslog_encrypt_offload_actionsendstreamdrivermode_action_send_stream_driver_mode_rsyslog_dir:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rsyslog_encrypt_offload_actionsendstreamdrivermode_action_send_stream_driver_mode_rsyslog_dir:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if StreamDriverMode is set to 1 in files in /etc/rsyslog.d using RainerScript" id="oval:ssg-test_rsyslog_encrypt_offload_actionsendstreamdrivermode_action_send_stream_driver_mode_rsyslog_dir_rainer:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rsyslog_encrypt_offload_actionsendstreamdrivermode_action_send_stream_driver_mode_rsyslog_dir_rainer:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if $DefaultNetstreamDriver gtls is set in /etc/rsyslog.conf" id="oval:ssg-test_rsyslog_encrypt_offload_defaultnetstreamdriver_default_netstream_rsyslog:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rsyslog_encrypt_offload_defaultnetstreamdriver_default_netstream_rsyslog:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if DefaultNetstreamDriver is set to gtls in /etc/rsyslog.conf using RainerScript" id="oval:ssg-test_rsyslog_encrypt_offload_defaultnetstreamdriver_default_netstream_rsyslog_rainer:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rsyslog_encrypt_offload_defaultnetstreamdriver_default_netstream_rsyslog_rainer:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if $DefaultNetstreamDriver gtls is set in /etc/rsyslog.conf" id="oval:ssg-test_rsyslog_encrypt_offload_defaultnetstreamdriver_default_netstream_rsyslog_dir:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rsyslog_encrypt_offload_defaultnetstreamdriver_default_netstream_rsyslog_dir:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if DefaultNetstreamDriver is set to gtls in files in /etc/rsyslog.d using RainerScript" id="oval:ssg-test_rsyslog_encrypt_offload_defaultnetstreamdriver_default_netstream_rsyslog_dir_rainer:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rsyslog_encrypt_offload_defaultnetstreamdriver_default_netstream_rsyslog_dir_rainer:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Ensures system logging configured in main conf file" id="oval:ssg-test_logging_configured_rsyslog_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_logging_configured_rsyslog_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Ensures system logging_configured in .d files" id="oval:ssg-test_logging_configured_rsyslog_d:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_logging_configured_rsyslog_d:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="remote method auth monitoring configured in rsyslog'" id="oval:ssg-test_remote_method_monitoring_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_remote_method_monitoring_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="remote method authpriv monitoring configured in rsyslog'" id="oval:ssg-test_remote_method_monitoring_authpriv:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_remote_method_monitoring_authpriv:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="remote method daemon monitoring configured in rsyslog'" id="oval:ssg-test_remote_method_monitoring_daemon:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_remote_method_monitoring_daemon:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests the presence of daily setting in /etc/logrotate.conf file" id="oval:ssg-test_logrotate_conf_daily_setting:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_logrotate_conf_daily_setting:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Test if there is no weekly/monthly/yearly keyword" id="oval:ssg-test_logrotate_conf_no_other_keyword:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_logrotate_conf_no_other_keyword:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests the existence of /etc/cron.daily/logrotate file (and verify it actually calls logrotate utility)" id="oval:ssg-test_cron_daily_logrotate_existence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_cron_daily_logrotate_existence:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="rsyslog configuration files don't contain legacy syntax for remote message reception" id="oval:ssg-test_rsyslog_nolisten_legacy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_rsyslog_nolisten_legacy:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="rsyslog configuration files don't use imtcp, imudp, or imrelp modules" id="oval:ssg-test_rsyslog_nolisten_rainerscript:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_rsyslog_nolisten_rainerscript:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Ensures system configured to export logs to remote host" id="oval:ssg-test_remote_rsyslog_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_remote_loghost_rsyslog_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Ensures system configured to export logs to remote host" id="oval:ssg-test_remote_rsyslog_d:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_remote_loghost_rsyslog_d:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Ensures system configured to export logs to remote host using Rainer syntax" id="oval:ssg-test_remote_rsyslog_conf_rainer:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_remote_loghost_rsyslog_conf_rainer:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Ensures system configured to export logs to remote host using Rainer" id="oval:ssg-test_remote_rsyslog_d_rainer:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_remote_loghost_rsyslog_d_rainer:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="tests the omfwd action configuration" id="oval:ssg-test_rsyslog_remote_tls:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rsyslog_remote_tls:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rsyslog_remote_tls:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="tests the DefaultNetstreamDriverCAFile configuration" id="oval:ssg-test_rsyslog_remote_tls_cacert:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rsyslog_remote_tls_cacert:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check if more than one nameserver in /etc/resolv.conf" id="oval:ssg-test_network_configure_name_resolution:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_network_configure_name_resolution:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Tests for the existence of DHCP_HOSTNAME in the /etc/sysconfig/network-scripts/ifcfg-.* file" id="oval:ssg-test_network_disable_ddns_interfaces_ifcfg:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_network_disable_ddns_interfaces_ifcfg:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Tests for the existence of 'send host-name' in /etc/dhclient.conf file" id="oval:ssg-test_network_disable_ddns_interfaces_dhclient:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_network_disable_ddns_interfaces_dhclient:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Tests for the existence of 'send host-name' in the /etc/dhcp folder" id="oval:ssg-test_network_disable_ddns_interfaces_dhcp:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_network_disable_ddns_interfaces_dhcp:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check NOZEROCONF=yes in /etc/sysconfig/network" id="oval:ssg-test_sysconfig_nozeroconf_yes:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sysconfig_nozeroconf_yes:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="polkit is properly configured to prevent non-privileged users from changing networking settings" id="oval:ssg-test_network_nmcli_permissions:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_network_nmcli_permissions:obj:1"/>
          <ind:state state_ref="oval:ssg-state_network_nmcli_permissions:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:interface_test check="all" comment="check all network interfaces for PROMISC flag" id="oval:ssg-test_promisc_interfaces:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_promisc_interfaces:obj:1"/>
          <unix:state state_ref="oval:ssg-state_promisc:ste:1"/>
        </unix:interface_test>
        <ind:xmlfilecontent_test check="all" check_existence="all_exist" comment="default trusted zone has rich-rule to restrict loopback source" id="oval:ssg-test_firewalld_loopback_restricted_source_usr:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_firewalld_loopback_restricted_source_usr:obj:1"/>
        </ind:xmlfilecontent_test>
        <ind:xmlfilecontent_test check="all" check_existence="all_exist" comment="default trusted zone has rich-rule to restrict loopback destination" id="oval:ssg-test_firewalld_loopback_restricted_destination_usr:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_firewalld_loopback_restricted_destination_usr:obj:1"/>
        </ind:xmlfilecontent_test>
        <ind:xmlfilecontent_test check="all" check_existence="all_exist" comment="default trusted zone has rich-rule to restrict loopback traffic" id="oval:ssg-test_firewalld_loopback_restricted_policy_usr:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_firewalld_loopback_restricted_policy_usr:obj:1"/>
        </ind:xmlfilecontent_test>
        <ind:xmlfilecontent_test check="all" check_existence="all_exist" comment="custom trusted zone has rich-rule to restrict loopback source" id="oval:ssg-test_firewalld_loopback_restricted_source_etc:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_firewalld_loopback_restricted_source_etc:obj:1"/>
        </ind:xmlfilecontent_test>
        <ind:xmlfilecontent_test check="all" check_existence="all_exist" comment="custom trusted zone has rich-rule to restrict loopback destination" id="oval:ssg-test_firewalld_loopback_restricted_destination_etc:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_firewalld_loopback_restricted_destination_etc:obj:1"/>
        </ind:xmlfilecontent_test>
        <ind:xmlfilecontent_test check="all" check_existence="all_exist" comment="custom trusted zone has rich-rule to restrict loopback traffic" id="oval:ssg-test_firewalld_loopback_restricted_policy_etc:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_firewalld_loopback_restricted_policy_etc:obj:1"/>
        </ind:xmlfilecontent_test>
        <ind:xmlfilecontent_test check="all" check_existence="all_exist" comment="lo interface is assigned to the trusted zone by default" id="oval:ssg-test_firewalld_lo_interface_trusted_usr:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_firewalld_lo_interface_trusted_usr:obj:1"/>
        </ind:xmlfilecontent_test>
        <ind:xmlfilecontent_test check="all" check_existence="all_exist" comment="lo interface is assigned to the custom trusted zone in /etc/firewalld/zones" id="oval:ssg-test_firewalld_lo_interface_trusted_etc:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_firewalld_lo_interface_trusted_etc:obj:1"/>
        </ind:xmlfilecontent_test>
        <unix:file_test check="all" check_existence="none_exist" comment="there is no equivalent file for trusted zone defined by the administrator" id="oval:ssg-test_firewalld_trusted_zone_not_overridden:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_firewalld_customized_trusted_zone_file:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Define default gateways" id="oval:ssg-test_network_ipv6_default_gateway:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_network_ipv6_default_gateway:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Enable privacy extensions on each interface" id="oval:ssg-test_network_ipv6_privacy_extensions:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_network_ipv6_privacy_extensions:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Set static IPv6 address on each interface" id="oval:ssg-test_network_ipv6_static_address:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_network_ipv6_static_address:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="ipv6 disabled any modprobe conf file" id="oval:ssg-test_kernel_module_ipv6_option_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_module_ipv6_option_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Test for udp6 based rpc services" id="oval:ssg-test_network_ipv6_disable_rpc_udp6:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_network_ipv6_disable_rpc_udp6:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Test for tcp6 based rpc services" id="oval:ssg-test_network_ipv6_disable_rpc_tcp6:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_network_ipv6_disable_rpc_tcp6:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:interface_test check="all" comment="check if UP flag is present on wifi interfaces" id="oval:ssg-test_wireless_disable_interfaces:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_active_wifi_interfaces:obj:1"/>
          <unix:state state_ref="oval:ssg-state_wifi_up:ste:1"/>
        </unix:interface_test>
        <unix:file_test check="all" comment="check for local directories that are world writable and have uid greater than 0" id="oval:ssg-test_dir_world_writable_uid_gt_zero:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-all_local_directories_uid_zero:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Check the existence of world-writable directories without sticky bits" id="oval:ssg-test_dir_perms_world_writable_sticky_bits:tst:1" state_operator="AND" version="2">
          <unix:object object_ref="oval:ssg-object_dir_perms_world_writable_sticky_bits:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Check the existence of world-writable directories not owned by system accounts." id="oval:ssg-test_dir_perms_world_writable_system_owned:tst:1" state_operator="AND" version="2">
          <unix:object object_ref="oval:ssg-object_dir_perms_world_writable_system_owned:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" comment="check for local directories that are world writable and have gid greater than or equal to 1000" id="oval:ssg-test_dir_world_writable_gid_gt_value:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-all_local_directories_gid:obj:1"/>
          <unix:state state_ref="oval:ssg-state_gid_is_user_and_world_writable:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="system commands directories uid root" id="oval:ssg-test_group_ownership_system_commands_dirs:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_system_commands_dirs_group_ownership:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="system commands directories uid root" id="oval:ssg-test_ownership_system_commands_directory_bin:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_ownership_system_commands_directory_bin_ownership:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="system commands directories uid root" id="oval:ssg-test_ownership_system_commands_directory_sbin:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_ownership_system_commands_directory_sbin_ownership:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="system commands directories uid root" id="oval:ssg-test_ownership_system_commands_directory_usr_bin:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_ownership_system_commands_directory_usr_bin_ownership:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="system commands directories uid root" id="oval:ssg-test_ownership_system_commands_directory_usr_sbin:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_ownership_system_commands_directory_usr_sbin_ownership:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="system commands directories uid root" id="oval:ssg-test_ownership_system_commands_directory_usr_local_bin:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_ownership_system_commands_directory_usr_local_bin_ownership:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="system commands directories uid root" id="oval:ssg-test_ownership_system_commands_directory_usr_local_sbin:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_ownership_system_commands_directory_usr_local_sbin_ownership:obj:1"/>
        </unix:file_test>
        <ind:variable_test check="all" check_existence="none_exist" comment="Check the existence of sgid files not included in rpm packages." id="oval:ssg-test_file_permissions_unauthorized_sgid:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_file_permissions_unauthorized_sgid_no_rpm_files:obj:1"/>
        </ind:variable_test>
        <ind:variable_test check="all" check_existence="none_exist" comment="Check the existence of suid files not included in rpm packages." id="oval:ssg-test_file_permissions_unauthorized_suid:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_file_permissions_unauthorized_suid_no_rpm_files:obj:1"/>
        </ind:variable_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Check the existence of world-writable files" id="oval:ssg-test_file_permissions_unauthorized_world_write:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_permissions_unauthorized_world_write:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" comment="Test if /etc/nssswitch.conf contains 'altfiles' in 'group' key" id="oval:ssg-test_file_permissions_ungroupowned_nsswitch_uses_altfiles:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_file_permissions_ungroupowned_nsswitch_uses_altfiles:obj:1"/>
          <ind:state state_ref="oval:ssg-state_file_permissions_ungroupowned_nsswitch_uses_altfiles:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package nss-altfiles is installed" id="oval:ssg-test_file_permissions_ungroupowned_package_nss-altfiles_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_file_permissions_ungroupowned_package_nss-altfiles_installed:obj:1"/>
        </linux:rpminfo_test>
        <unix:file_test check="all" check_existence="none_exist" comment="there are no files with group owner different than local groups" id="oval:ssg-test_file_permissions_ungroupowned:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_permissions_ungroupowned:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="there are no files with group owner different than local groups" id="oval:ssg-test_file_permissions_ungroupowned_with_usrlib:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_permissions_ungroupowned_with_usrlib:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" comment="Test if /etc/nssswitch.conf contains 'altfiles' in 'group' key" id="oval:ssg-test_no_files_or_dirs_ungroupowned_nsswitch_uses_altfiles:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_no_files_or_dirs_ungroupowned_nsswitch_uses_altfiles:obj:1"/>
          <ind:state state_ref="oval:ssg-state_no_files_or_dirs_ungroupowned_nsswitch_uses_altfiles:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package nss-altfiles is installed" id="oval:ssg-test_no_files_or_dirs_ungroupowned_package_nss-altfiles_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_no_files_or_dirs_ungroupowned_package_nss-altfiles_installed:obj:1"/>
        </linux:rpminfo_test>
        <unix:file_test check="all" check_existence="none_exist" comment="there are no files with group owner different than local groups" id="oval:ssg-test_no_files_or_dirs_ungroupowned:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_no_files_or_dirs_ungroupowned_all:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="there are no files with group owner different than local groups" id="oval:ssg-test_no_files_or_dirs_ungroupowned_with_usrlib:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_no_files_or_dirs_ungroupowned_all_with_usrlib:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="there are no files without a known owner" id="oval:ssg-test_no_files_or_dirs_unowned_by_user:tst:1" state_operator="AND" version="2">
          <unix:object object_ref="oval:ssg-object_no_files_or_dirs_unowned_by_user_all:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="there are no files without a known owner" id="oval:ssg-test_no_files_unowned_by_user:tst:1" state_operator="AND" version="2">
          <unix:object object_ref="oval:ssg-object_no_files_unowned_by_user:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="/etc/security/opasswd is owned by root:root / 0600" id="oval:ssg-test_file_etc_security_opasswd:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_etc_security_opasswd:obj:1"/>
          <unix:state state_ref="oval:ssg-state_file_etc_security_opasswd:ste:1"/>
          <unix:state state_ref="oval:ssg-state_file_group_etc_security_opasswd:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="system commands are owned by root or a system account" id="oval:ssg-test_groupownership_system_commands_dirs:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_groupownership_system_commands_dirs:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="binary directories uid root" id="oval:ssg-test_ownership_binary_directories:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_binary_directories:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="binary files uid root" id="oval:ssg-test_ownership_binary_files:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_binary_files:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="binary files go-w" id="oval:ssg-test_perms_binary_files:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_permissions_binary_files:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" comment="Tests that .bash_logout is configured correctly." id="oval:ssg-test_rootfiles_configured_bash_logout:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rootfiles_configured_bash_logout:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rootfiles_configured_bash_logout:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Tests that .bash_profile is configured correctly." id="oval:ssg-test_rootfiles_configured_bash_profile:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rootfiles_configured_bash_profile:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rootfiles_configured_bash_profile:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Tests that .bashrc is configured correctly." id="oval:ssg-test_rootfiles_configured_bashrc:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rootfiles_configured_bashrc:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rootfiles_configured_bashrc:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Tests that .cshrc is configured correctly." id="oval:ssg-test_rootfiles_configured_cshrc:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rootfiles_configured_cshrc:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rootfiles_configured_cshrc:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Tests that .tcshrc is configured correctly." id="oval:ssg-test_rootfiles_configured_tcshrc:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rootfiles_configured_tcshrc:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rootfiles_configured_tcshrc:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nodev on local filesystems" id="oval:ssg-test_nodev_nonroot_local_partitions:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_non_root_partitions:obj:1"/>
          <linux:state state_ref="oval:ssg-state_local_nodev:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="nodev on local filesystems in /etc/fstab" id="oval:ssg-test_nodev_nonroot_local_partitions_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_non_root_partitions_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_non_root_partitions_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Ensure /var/tmp is configured to bind mount to /tmp" id="oval:ssg-test_configure_mount_option_var_tmp_bind_tmp:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_configure_mount_option_var_tmp_bind_tmp:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" comment="Ensure /var/tmp is mounted" id="oval:ssg-test_mount_option_var_tmp:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mount_option_var_tmp:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" comment="Ensure bind mount option is on /var/tmp" id="oval:ssg-test_mount_option_var_tmp_bind:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_mount_option_var_tmp_bind:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" comment="Ensure /var/tmp and /tmp have the same source device" id="oval:ssg-test_mount_option_var_tmp_bind_compare_source:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mount_option_var_tmp_bind_compare_source:obj:1"/>
          <linux:state state_ref="oval:ssg-state_mount_option_var_tmp_bind_compare_source:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" comment="Tests the value of the ^[\s]*\*[\s]+(hard|-)[\s]+core[\s]+([\d]+) setting in the /etc/security/limits.conf file" id="oval:ssg-test_core_dumps_limitsconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_core_dumps_limitsconf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_core_dumps_limitsconf:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Tests the value of the ^[\s]*\*[\s]+(hard|-)[\s]+core[\s]+([\d]+) setting in the /etc/security/limits.d directory" id="oval:ssg-test_core_dumps_limits_d:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_core_dumps_limits_d:obj:1"/>
          <ind:state state_ref="oval:ssg-state_core_dumps_limits_d:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Tests for existence of the ^[\s]*\*[\s]+(hard|-)[\s]+core setting in the /etc/security/limits.d directory" id="oval:ssg-test_core_dumps_limits_d_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_core_dumps_limits_d_exists:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" comment="Test the retrieved /etc/init.d/functions umask value(s) match the var_umask_for_daemons requirement" id="oval:ssg-tst_umask_for_daemons:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_umask_for_daemons:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_umask_for_daemons:ste:1"/>
        </ind:variable_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter kernel.exec-shield set to 1" id="oval:ssg-test_runtime_sysctl_kernel_exec_shield:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_kernel_exec_shield:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_kernel_exec_shield:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.exec-shield static configuration" id="oval:ssg-test_static_sysctl_kernel_exec_shield:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_sysctl_kernel_exec_shield:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="NX is disabled" id="oval:ssg-test_nx_disabled_grub:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_nx_disabled_grub:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="CPUs support for NX bit" id="oval:ssg-test_NX_cpu_support:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_NX_cpu_support:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="NX is not disabled in the kernel command line" id="oval:ssg-test_noexec_cmd_line:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_noexec_cmd_line:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="Package kernel-PAE is installed" id="oval:ssg-test_package_kernel-PAE_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_package_kernel-PAE_installed:obj:1"/>
        </linux:rpminfo_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="CPUs support PAE kernel or NX bit" id="oval:ssg-test_PAE_NX_cpu_support:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_PAE_NX_cpu_support:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for DEFAULTKERNEL set to kernel-PAE in /etc/sysconfig/kernel" id="oval:ssg-test_defaultkernel_sysconfig_kernel:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_defaultkernel_sysconfig_kernel:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="check value selinux|enforcing=0 in /etc/default/grub, fail if found" id="oval:ssg-test_selinux_default_grub:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_selinux_default_grub:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="check value selinux|enforcing=0 in /etc/grub2.cfg, fail if found" id="oval:ssg-test_selinux_grub2_cfg:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_selinux_grub2_cfg:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="check value selinux|enforcing=0 in /etc/grub.d fail if found" id="oval:ssg-test_selinux_grub_dir:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_selinux_grub_dir:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:selinuxsecuritycontext_test check="none satisfy" check_existence="any_exist" comment="device_t in /dev" id="oval:ssg-test_selinux_dev_device_t:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_selinux_dev_device_t:obj:1"/>
          <linux:state state_ref="oval:ssg-state_selinux_dev_device_t:ste:1"/>
        </linux:selinuxsecuritycontext_test>
        <linux:selinuxsecuritycontext_test check="none satisfy" check_existence="any_exist" comment="unlabeled_t in /dev" id="oval:ssg-test_selinux_dev_unlabeled_t:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_selinux_dev_unlabeled_t:obj:1"/>
          <linux:state state_ref="oval:ssg-state_selinux_dev_unlabeled_t:ste:1"/>
        </linux:selinuxsecuritycontext_test>
        <linux:selinuxsecuritycontext_test check="none satisfy" check_existence="any_exist" comment="none satisfy unconfined_service_t in /proc" id="oval:ssg-test_selinux_confinement_of_daemons:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_selinux_confinement_of_daemons:obj:1"/>
          <linux:state state_ref="oval:ssg-state_selinux_confinement_of_daemons:ste:1"/>
        </linux:selinuxsecuritycontext_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check correct configuration in /etc/sudoers and /etc/sudoers.d/*" id="oval:ssg-test_sudo_selinux_elevation_type:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sudo_selinux_elevation_type:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sudo_selinux_elevation_type:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check correct configuration in /etc/sudoers and /etc/sudoers.d/*" id="oval:ssg-test_sudo_selinux_elevation_role:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sudo_selinux_elevation_role:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sudo_selinux_elevation_role:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="SELinux is not disabled in /etc/selinux/config" id="oval:ssg-test_selinux_not_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_selinux_not_disabled:obj:1"/>
          <ind:state state_ref="oval:ssg-state_selinux_not_disabled:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/selinux/enforce is 1" id="oval:ssg-test_etc_selinux_config:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_etc_selinux_config:obj:1"/>
          <ind:state state_ref="oval:ssg-state_etc_selinux_config:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="Package kernel arch is x64" id="oval:ssg-test_package_kernel_x64:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_package_kernel:obj:1"/>
          <linux:state state_ref="oval:ssg-state_installed_arch_of_kernel_package:ste:1"/>
        </linux:rpminfo_test>
        <ind:textfilecontent54_test check="all" comment="Check for CPU flag lm" id="oval:ssg-test_proc_cpuinfo_64_bit:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_proc_cpuinfo_64_bit:obj:1"/>
          <ind:state state_ref="oval:ssg-state_proc_cpuinfo_64_bit:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="Check if kernel nvr arch is 64-bit" id="oval:ssg-test_proc_sys_kernel_osrelease_64_bit:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_proc_sys_kernel_osrelease_64_bit:obj:1"/>
          <ind:state state_ref="oval:ssg-state_proc_sys_kernel_osrelease_64_bit:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if the gdm dconf DB is up-to-date with keyfiles in the gdm tree." id="oval:ssg-test_dconf_gdm_up_to_date:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_gdm_db_modified_time:obj:1"/>
          <ind:state state_ref="oval:ssg-state_gdm_db_is_up_to_date:ste:1"/>
        </ind:variable_test>
        <unix:file_test check="all" check_existence="none_exist" comment="no keyfiles applicable to the gdm database" id="oval:ssg-test_dconf_gdm_no_keyfiles:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_dconf_gdm_config:obj:1"/>
        </unix:file_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if the local dconf DB is up-to-date with keyfiles in the local tree." id="oval:ssg-test_dconf_local_up_to_date:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_local_db_modified_time:obj:1"/>
          <ind:state state_ref="oval:ssg-state_local_db_is_up_to_date:ste:1"/>
        </ind:variable_test>
        <unix:file_test check="all" check_existence="none_exist" comment="no keyfiles applicable to the local database" id="oval:ssg-test_dconf_local_no_keyfiles:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_dconf_local_config:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="dconf user profile exists" id="oval:ssg-test_dconf_user_profile:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_dconf_user_profile:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of WaylandEnable setting in the /etc/gdm/custom.conf file" id="oval:ssg-test_xwayland_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_xwayland_disabled:obj:1"/>
          <ind:state state_ref="oval:ssg-state_xwayland_disabled:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="The configuration file /etc/gdm/custom.conf exists for xwayland_disabled" id="oval:ssg-test_xwayland_disabled_config_file_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_xwayland_disabled_config_file:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="GUI restart and shutdown buttons are disabled" id="oval:ssg-test_disable_restart_buttons:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_disable_restart_buttons:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="GUI restart and shutdown buttons cannot be enabled" id="oval:ssg-test_prevent_user_enable_restart_buttons:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_enable_restart_buttons:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="GUI user list is disabled" id="oval:ssg-test_disable_user_list:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_disable_user_list:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="GUI user list cannot be enabled" id="oval:ssg-test_prevent_user_disable_user_list:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_disable_user_list:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Enable GUI Login Smartcard authentication" id="oval:ssg-test_enable_gnome_smartcard:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_enable_gnome_smartcard:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="GUI smartcard authentication cannot be disabled" id="oval:ssg-test_prevent_user_disable_smartcard:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_disable_smartcard:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Set number of login tries" id="oval:ssg-test_configure_allowed_failures:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_configure_allowed_failures:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="number of login attempts cannot be changed" id="oval:ssg-test_prevent_user_allowed-failures_change:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_allowed-failures_change:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Disable GDM Automatic Login" id="oval:ssg-test_disable_automatic_login:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_disable_automatic_login:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Disable GDM Guest Login" id="oval:ssg-test_disable_guest_login:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_disable_guest_login:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of Enable setting in the /etc/gdm/custom.conf file" id="oval:ssg-test_gnome_gdm_disable_xdmcp:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_gnome_gdm_disable_xdmcp:obj:1"/>
          <ind:state state_ref="oval:ssg-state_gnome_gdm_disable_xdmcp:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="The configuration file /etc/gdm/custom.conf exists for gnome_gdm_disable_xdmcp" id="oval:ssg-test_gnome_gdm_disable_xdmcp_config_file_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_gnome_gdm_disable_xdmcp_config_file:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Disable automount in GNOME3" id="oval:ssg-test_dconf_gnome_disable_automount:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_dconf_gnome_disable_automount:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Prevent user from changing automount setting" id="oval:ssg-test_prevent_user_gnome_automount:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_gnome_automount:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Disable automount-open in GNOME" id="oval:ssg-test_dconf_gnome_disable_automount_open:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_dconf_gnome_disable_automount_open:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Prevent user from changing automount-open setting" id="oval:ssg-test_prevent_user_gnome_automount_open:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_gnome_automount_open:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Disable autorun in GNOME" id="oval:ssg-test_dconf_gnome_disable_autorun:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_dconf_gnome_disable_autorun:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Prevent user from changing autorun setting" id="oval:ssg-test_prevent_user_gnome_autorun:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_gnome_autorun:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Disable thumbnailers in GNOME3" id="oval:ssg-test_gnome_disable_thumbnailers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_gnome_disable_thumbnailers:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="user cannot enable thumbnailers " id="oval:ssg-test_prevent_user_change_gnome_thumbnailers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_change_gnome_thumbnailers:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Disable wifi creation" id="oval:ssg-test_disable_wifi_creation:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_disable_wifi_creation:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Prevent enabling of wifi creation capability" id="oval:ssg-test_prevent_user_enable_wifi_creation:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_enable_wifi_creation:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Disable wifi notification" id="oval:ssg-test_disable_wifi_notification:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_disable_wifi_notification:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Prevent enabling of wifi notification capability" id="oval:ssg-test_prevent_user_enable_wifi_notification:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_enable_wifi_notification:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="configure remote access credentials" id="oval:ssg-test_configure_remote_access_creds:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_configure_remote_access_creds:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="prevent user from disabling remote access credential requirements" id="oval:ssg-test_prevent_user_remote_access_creds:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_remote_access_creds:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="configure remote access encryption" id="oval:ssg-test_configure_remote_access_encryption:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_configure_remote_access_encryption:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="prevent user from disabling remote access encryption" id="oval:ssg-test_prevent_user_remote_access_encryption:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_remote_access_encryption:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="idle delay is configured" id="oval:ssg-test_screensaver_idle_activation_enabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_screensaver_idle_activation_enabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="user cannot change idle_activation_enabled" id="oval:ssg-test_prevent_user_change_idle_activation_enabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_change_idle_activation_enabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="user cannot change idle_activation_locked" id="oval:ssg-test_prevent_user_change_idle_activation_locked:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_change_idle_activation_locked:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="screensaver idle delay is configured" id="oval:ssg-test_screensaver_idle_delay:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_screensaver_idle_delay:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="screensaver idle delay setting is correct" id="oval:ssg-test_screensaver_idle_delay_setting:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_screensaver_idle_delay_setting:obj:1"/>
          <ind:state state_ref="oval:ssg-state_screensaver_idle_delay_setting:ste:1"/>
          <ind:state state_ref="oval:ssg-state_screensaver_idle_delay_setting_not_zero:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="screensaver lock is set correctly" id="oval:ssg-test_screensaver_lock_delay:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_screensaver_lock_delay:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="screensaver lock delay setting is correct" id="oval:ssg-test_screensaver_lock_delay_setting:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_screensaver_lock_delay_setting:obj:1"/>
          <ind:state state_ref="oval:ssg-state_screensaver_lock_delay_setting:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="screensaver lock is enabled" id="oval:ssg-test_screensaver_lock_enabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_screensaver_lock_enabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="screensaver lock cannot be changed by user" id="oval:ssg-test_prevent_user_screensaver_lock:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_screensaver_lock:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="screensaver lock cannot be changed by user" id="oval:ssg-test_prevent_user_screensaver_lock_locked:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_screensaver_lock_locked:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="screensaver mode is blank" id="oval:ssg-test_screensaver_mode_blank:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_screensaver_mode_blank:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="blank screensaver cannot be changed by user" id="oval:ssg-test_prevent_user_screensaver_mode_change:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_screensaver_mode_change:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="screensaver user info is disabled" id="oval:ssg-test_screensaver_disable_user_info:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_screensaver_disable_user_info:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="screensaver prevent user from changing" id="oval:ssg-test_prevent_user_info_change:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_info_change:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="screensaver lock delay cannot be changed by user" id="oval:ssg-test_user_change_lock_delay_lock:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_user_change_lock_delay_lock:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="user cannot change screensaver idle delay" id="oval:ssg-test_user_change_idle_delay_lock:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_user_change_idle_delay_lock:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Disable Ctrl-Alt-Del" id="oval:ssg-test_disable_gnome_ctrlaltdel:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_disable_gnome_ctrlaltdel:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Prevent enabling of ctrl-alt-del keys" id="oval:ssg-test_prevent_user_enable_ctrlaltdel:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_enable_ctrlaltdel:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Disable system geolocation" id="oval:ssg-test_disable_sys_geolocation:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_disable_sys_geolocation:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Prevent enabling of system geolocation" id="oval:ssg-test_prevent_user_sys_geolocation:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_sys_geolocation:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Disable clock geolocation" id="oval:ssg-test_disable_clock_geolocation:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_disable_clock_geolocation:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Prevent enabling of clock geolocation" id="oval:ssg-test_prevent_user_clock_geolocation:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_clock_geolocation:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Disable power settings" id="oval:ssg-test_disable_gnome_power_setting:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_disable_gnome_power_setting:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Prevent enabling of power settings" id="oval:ssg-test_prevent_user_power_setting_change:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_power_setting_change:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check that the configuration includes the policy config file." id="oval:ssg-test_configure_bind_crypto_policy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_configure_bind_crypto_policy:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if update-crypto-policies has been run" id="oval:ssg-test_crypto_policies_updated:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_crypto_policies_config_file_modified_time:obj:1"/>
          <ind:state state_ref="oval:ssg-state_crypto_current_file_newer_than_config_file:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="check for crypto policy correctly configured in /etc/crypto-policies/config" id="oval:ssg-test_configure_crypto_policy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_configure_crypto_policy:obj:1"/>
          <ind:state state_ref="oval:ssg-state_configure_crypto_policy:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="check for crypto policy correctly configured in /etc/crypto-policies/state/current" id="oval:ssg-test_configure_crypto_policy_current:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_configure_crypto_policy_current:obj:1"/>
          <ind:state state_ref="oval:ssg-state_configure_crypto_policy_current:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="Check if /etc/crypto-policies/back-ends/nss.config exists" id="oval:ssg-test_crypto_policy_nss_config:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_crypto_policy_nss_config:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" comment="tests the presence of '+VERS-ALL:-VERS-DTLS0.9:-VERS-TLS1.1:-VERS-TLS1.0:-VERS-SSL3.0:-VERS-DTLS1.0' setting in the /etc/crypto-policies/back-ends/gnutls.config file" id="oval:ssg-test_configure_gnutls_tls_crypto_policy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_configure_gnutls_tls_crypto_policy:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if kerberos configuration symlink and crypto policy kerberos backend symlink point to same file" id="oval:ssg-test_configure_kerberos_crypto_policy_symlink:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_symlink_kerberos_crypto_policy_configuration:obj:1"/>
          <ind:state state_ref="oval:ssg-state_symlink_kerberos_crypto_policy_backend:ste:1"/>
        </ind:variable_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if kerberos configuration symlink links to the crypto-policy backend file" id="oval:ssg-test_configure_kerberos_crypto_policy_nosymlink:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_symlink_kerberos_crypto_policy_configuration:obj:1"/>
          <ind:state state_ref="oval:ssg-state_location_of_kerberos_crypto_policy_backend:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check that the libreswan configuration includes the crypto policy config file" id="oval:ssg-test_configure_libreswan_crypto_policy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_configure_libreswan_crypto_policy:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check that the configuration mandates usage of system-wide crypto policies." id="oval:ssg-test_configure_openssl_crypto_policy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_configure_openssl_crypto_policy:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="only one" comment="Check that the SSH configuration mandates usage of system-wide crypto policies." id="oval:ssg-test_configure_openssl_tls_crypto_policy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_configure_openssl_tls_crypto_policy:obj:1"/>
          <ind:state state_ref="oval:ssg-state_configure_openssl_tls_crypto_policy:ste:1"/>
          <ind:state state_ref="oval:ssg-state_configure_openssl_tls_crypto_policy_last_instance:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="only one" comment="Check that the SSH configuration mandates usage of system-wide crypto policies." id="oval:ssg-test_configure_openssl_dtls_crypto_policy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_configure_openssl_dtls_crypto_policy:obj:1"/>
          <ind:state state_ref="oval:ssg-state_configure_openssl_tls_crypto_policy:ste:1"/>
          <ind:state state_ref="oval:ssg-state_configure_openssl_dtls_crypto_policy_last_instance:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:rpminfo_test check="all" check_existence="any_exist" comment="Installed version of  crypto-policies is older than 20210617-1" id="oval:ssg-test_installed_version_of_crypto_policies:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_installed_version_of_crypto_policies:obj:1"/>
          <linux:state state_ref="oval:ssg-state_installed_version_of_crypto_policies:ste:1"/>
        </linux:rpminfo_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check that the SSH configuration mandates usage of system-wide crypto policies." id="oval:ssg-test_configure_ssh_crypto_policy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_configure_ssh_crypto_policy:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of Ciphersuites setting in the /etc/crypto-policies/back-ends/opensslcnf.config file" id="oval:ssg-test_harden_openssl_crypto_policy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_harden_openssl_crypto_policy:obj:1"/>
          <ind:state state_ref="oval:ssg-state_harden_openssl_crypto_policy:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the absence of Match setting in the /etc/ssh/ssh_config.d/02-ospp.conf file" id="oval:ssg-test_harden_ssh_client_crypto_policy_Match:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_harden_ssh_client_crypto_policy_Match:obj:1"/>
          <ind:state state_ref="oval:ssg-state_harden_ssh_client_crypto_policy_Match:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the absence of RekeyLimit setting in the /etc/ssh/ssh_config.d/02-ospp.conf file" id="oval:ssg-test_harden_ssh_client_crypto_policy_RekeyLimit:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_harden_ssh_client_crypto_policy_RekeyLimit:obj:1"/>
          <ind:state state_ref="oval:ssg-state_harden_ssh_client_crypto_policy_RekeyLimit:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the absence of GSSAPIAuthentication setting in the /etc/ssh/ssh_config.d/02-ospp.conf file" id="oval:ssg-test_harden_ssh_client_crypto_policy_GSSAPIAuthentication:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_harden_ssh_client_crypto_policy_GSSAPIAuthentication:obj:1"/>
          <ind:state state_ref="oval:ssg-state_harden_ssh_client_crypto_policy_GSSAPIAuthentication:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the absence of Ciphers setting in the /etc/ssh/ssh_config.d/02-ospp.conf file" id="oval:ssg-test_harden_ssh_client_crypto_policy_Ciphers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_harden_ssh_client_crypto_policy_Ciphers:obj:1"/>
          <ind:state state_ref="oval:ssg-state_harden_ssh_client_crypto_policy_Ciphers:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the absence of PubkeyAcceptedKeyTypes setting in the /etc/ssh/ssh_config.d/02-ospp.conf file" id="oval:ssg-test_harden_ssh_client_crypto_policy_PubkeyAcceptedKeyTypes:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_harden_ssh_client_crypto_policy_PubkeyAcceptedKeyTypes:obj:1"/>
          <ind:state state_ref="oval:ssg-state_harden_ssh_client_crypto_policy_PubkeyAcceptedKeyTypes:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the absence of MACs setting in the /etc/ssh/ssh_config.d/02-ospp.conf file" id="oval:ssg-test_harden_ssh_client_crypto_policy_MACs:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_harden_ssh_client_crypto_policy_MACs:obj:1"/>
          <ind:state state_ref="oval:ssg-state_harden_ssh_client_crypto_policy_MACs:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the absence of KexAlgorithms setting in the /etc/ssh/ssh_config.d/02-ospp.conf file" id="oval:ssg-test_harden_ssh_client_crypto_policy_KexAlgorithms:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_harden_ssh_client_crypto_policy_KexAlgorithms:obj:1"/>
          <ind:state state_ref="oval:ssg-state_harden_ssh_client_crypto_policy_KexAlgorithms:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="test the value of Ciphers setting in the /etc/crypto-policies/back-ends/openssh.config file" id="oval:ssg-test_harden_sshd_ciphers_openssh_conf_crypto_policy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_harden_sshd_ciphers_openssh_conf_crypto_policy:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_harden_sshd_ciphers_openssh_conf_crypto_policy:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="test the value of Ciphers setting in the /etc/crypto-policies/back-ends/opensshserver.config file" id="oval:ssg-test_harden_sshd_ciphers_opensshserver_conf_crypto_policy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_harden_sshd_ciphers_opensshserver_conf_crypto_policy:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_harden_sshd_ciphers_opensshserver_conf_crypto_policy:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of CRYPTO_POLICY setting in the /etc/crypto-policies/back-ends/opensshserver.config file" id="oval:ssg-test_harden_sshd_crypto_policy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_harden_sshd_crypto_policy:obj:1"/>
          <ind:state state_ref="oval:ssg-state_harden_sshd_crypto_policy:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="test the value of MACs setting in the /etc/crypto-policies/back-ends/openssh.config file" id="oval:ssg-test_harden_sshd_macs_openssh_conf_crypto_policy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_harden_sshd_macs_openssh_conf_crypto_policy:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_harden_sshd_macs_openssh_conf_crypto_policy:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="test the value of MACs setting in the /etc/crypto-policies/back-ends/opensshserver.config file" id="oval:ssg-test_harden_sshd_macs_opensshserver_conf_crypto_policy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_harden_sshd_macs_opensshserver_conf_crypto_policy:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_harden_sshd_macs_opensshserver_conf_crypto_policy:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:filehash58_test check="all" check_existence="all_exist" comment="Test if openssl is configured to generate random data with strong entropy" id="oval:ssg-test_openssl_strong_entropy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_openssl_strong_entropy:obj:1"/>
          <ind:state state_ref="oval:ssg-state_openssl_strong_entropy:ste:1"/>
        </ind:filehash58_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/selinux/enforce is 1" id="oval:ssg-test_selinux_enforcing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_selinux_enforcing:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="AntiVirus package is installed" id="oval:ssg-test_linuxshield_install_antivirus:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_linuxshield_install_antivirus:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="Runtime Libraries package is installed" id="oval:ssg-test_mcafee_runtime_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_mcafee_runtime_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="Agent package is installed" id="oval:ssg-test_mcafee_management_agent:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_mcafee_management_agent:obj:1"/>
        </linux:rpminfo_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="McAfee AntiVirus definitions have been updated" id="oval:ssg-test_mcafee_antivirus_definitions_updated:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_mcafee_definitions_modified_time:obj:1"/>
          <ind:state state_ref="oval:ssg-state_mcafee_definitions_max_age:ste:1"/>
        </ind:variable_test>
        <unix:process58_test check="all" comment="is mfetpd running" id="oval:ssg-test_agent_mfetpd_running:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_agent_mfetpd_running:obj:1"/>
        </unix:process58_test>
        <unix:file_test check="all" check_existence="all_exist" comment="McAfee ACCM installed" id="oval:ssg-test_mcafee_accm_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_mcafee_accm_exists:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="McAfee Policy Auditor installed" id="oval:ssg-test_mcafee_auditengine_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_mcafee_auditengine_exists:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="add_dracutmodules contains fips" id="oval:ssg-test_enable_dracut_fips_module:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_enable_dracut_fips_module:obj:1"/>
          <ind:state state_ref="oval:ssg-state_enable_dracut_fips_module:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="at least one" comment="test if var_system_crypto_policy selection is set to FIPS" id="oval:ssg-test_system_crypto_policy_value:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_system_crypto_policy_value:obj:1"/>
          <ind:state state_ref="oval:ssg-ste_system_crypto_policy_value:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel runtime parameter crypto.fips_enabled set to 1" id="oval:ssg-test_proc_sys_crypto_fips_enabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_proc_sys_crypto_fips_enabled:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="/etc/system-fips exists" id="oval:ssg-test_etc_system_fips:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_etc_system_fips:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Correct sub policy enabled" id="oval:ssg-test_fips_crypto_subpolicy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_fips_crypto_subpolicy:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Tests that cipher_ssh is configured correctly." id="oval:ssg-test_fips_custom_stig_sub_policy_cipher_ssh:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_fips_custom_stig_sub_policy_cipher_ssh:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Tests that mac_ssh is configured correctly." id="oval:ssg-test_fips_custom_stig_sub_policy_mac_ssh:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_fips_custom_stig_sub_policy_mac_ssh:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter crypto.fips_enabled set to 1" id="oval:ssg-test_sysctl_crypto_fips_enabled:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_crypto_fips_enabled:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_crypto_fips_enabled:ste:1"/>
        </unix:sysctl_test>
        <unix:file_test check="all" check_existence="all_exist" comment="Testing existence of operational aide database file" id="oval:ssg-test_aide_operational_database_absolute_path:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_aide_operational_database_absolute_path:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="auditctl is checked in /etc/aide.conf" id="oval:ssg-test_aide_verify_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_aide_verify_auditctl:obj:1"/>
          <ind:state state_ref="oval:ssg-state_aide_check_attributes:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="auditd is checked in /etc/aide.conf" id="oval:ssg-test_aide_verify_auditd:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_aide_verify_auditd:obj:1"/>
          <ind:state state_ref="oval:ssg-state_aide_check_attributes:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="ausearch is checked in /etc/aide.conf" id="oval:ssg-test_aide_verify_ausearch:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_aide_verify_ausearch:obj:1"/>
          <ind:state state_ref="oval:ssg-state_aide_check_attributes:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="aureport is checked in /etc/aide.conf" id="oval:ssg-test_aide_verify_aureport:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_aide_verify_aureport:obj:1"/>
          <ind:state state_ref="oval:ssg-state_aide_check_attributes:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="autrace is checked in /etc/aide.conf" id="oval:ssg-test_aide_verify_autrace:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_aide_verify_autrace:obj:1"/>
          <ind:state state_ref="oval:ssg-state_aide_check_attributes:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="rsyslogd is checked in /etc/aide.conf" id="oval:ssg-test_aide_verify_rsyslogd:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_aide_verify_rsyslogd:obj:1"/>
          <ind:state state_ref="oval:ssg-state_aide_check_attributes:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="augenrules is checked in /etc/aide.conf" id="oval:ssg-test_aide_verify_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_aide_verify_augenrules:obj:1"/>
          <ind:state state_ref="oval:ssg-state_aide_check_attributes:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="run aide with cron" id="oval:ssg-test_aide_periodic_cron_checking:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_aide_periodic_cron_checking:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="run aide with cron" id="oval:ssg-test_aide_crond_checking:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_aide_crond_checking:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="run aide with cron" id="oval:ssg-test_aide_var_cron_checking:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_aide_var_cron_checking:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="run aide with cron.(daily|weekly)" id="oval:ssg-test_aide_crontabs_checking:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_aide_crontabs_checking:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="notify personnel when aide completes" id="oval:ssg-test_aide_scan_notification:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_aide_scan_notification:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="notify personnel when aide completes" id="oval:ssg-test_aide_var_cron_notification:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_aide_var_cron_notification:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="notify personnel when aide completes in cron.(daily|weekly|monthly)" id="oval:ssg-test_aide_crontabs_notification:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_aide_crontabs_notification:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Verify non-FIPS hashes are not configured in /etc/aide.conf" id="oval:ssg-test_aide_non_fips_hashes:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_aide_non_fips_hashes:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Verify FIPS hashes are configured in /etc/aide.conf" id="oval:ssg-test_aide_use_fips_hashes:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_aide_use_fips_hashes:obj:1"/>
          <ind:state state_ref="oval:ssg-state_aide_use_fips_hashes:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="acl is set in /etc/aide.conf" id="oval:ssg-test_aide_verify_acls:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_aide_verify_acls:obj:1"/>
          <ind:state state_ref="oval:ssg-state_aide_verify_acls:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="xattrs is set in /etc/aide.conf" id="oval:ssg-test_aide_verify_ext_attributes:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_aide_verify_ext_attributes:obj:1"/>
          <ind:state state_ref="oval:ssg-state_aide_verify_ext_attributes:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:rpmverifyfile_test check="all" check_existence="none_exist" comment="verify file md5 hashes" id="oval:ssg-test_rpm_verify_hashes:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_rpm_verify_hashes_fail_md5_hash:obj:1"/>
        </linux:rpmverifyfile_test>
        <linux:rpmverifyfile_test check="all" check_existence="none_exist" comment="Ownership of all files matches local rpm database" id="oval:ssg-test_rpm_verify_ownership_verify_all_rpms_ownership:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_rpm_verify_ownership_files_fail_ownership:obj:1"/>
        </linux:rpmverifyfile_test>
        <linux:rpmverifyfile_test check="all" check_existence="none_exist" comment="mode of all files matches local rpm database" id="oval:ssg-test_rpm_verify_permissions:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_rpm_verify_permissions_files_fail_mode:obj:1"/>
        </linux:rpmverifyfile_test>
        <unix:file_test check="all" check_existence="all_exist" comment="Check /usr/bin/sudo is owned by group defined in var_sudo_dedicated_group " id="oval:ssg-test_sudo_owned_by_dedicated_group:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_sudo_file:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sudo_file_gid_is_dedicated_group_gid:ste:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="Check if dedicated group is listed in /etc/group" id="oval:ssg-test_dedicated_group_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-sudo_dedicated_group_gid:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="!authenticate does not exist in /etc/sudoers" id="oval:ssg-test_no_authenticate_etc_sudoers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_no_authenticate_etc_sudoers:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="!authenticate does not exist in /etc/sudoers.d" id="oval:ssg-test_no_authenticate_etc_sudoers_d:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_no_authenticate_etc_sudoers_d:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="NOPASSWD does not exist /etc/sudoers" id="oval:ssg-test_nopasswd_etc_sudoers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_nopasswd_etc_sudoers:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="NOPASSWD does not exist in /etc/sudoers.d" id="oval:ssg-test_nopasswd_etc_sudoers_d:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_nopasswd_etc_sudoers_d:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="check correct configuration in /etc/sudoers" id="oval:ssg-test_sudo_timestamp_timeout:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sudo_timestamp_timeout:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="check correct configuration in /etc/sudoers" id="oval:ssg-test_sudo_timestamp_timeout_no_signs:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sudo_timestamp_timeout_no_signs:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Make sure that sudoers has restrictions on which users can run sudo" id="oval:ssg-test_not_all_users_can_sudo_to_users:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sudoers_cfg_spec_all_users:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Make sure that sudoers has restrictions on which users can run sudo" id="oval:ssg-test_not_all_users_can_sudo_to_group:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sudoers_cfg_spec_all_group:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="NOPASSWD only exists for vdsm user in /etc/sudoers" id="oval:ssg-test_vdsm_nopasswd_etc_sudoers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_vdsm_nopasswd_etc_sudoers:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="NOPASSWD only exists for vdsm user in /etc/sudoers.d" id="oval:ssg-test_vdsm_nopasswd_etc_sudoers_d:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_vdsm_nopasswd_etc_sudoers_d:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="test only one sudoers #includedir" id="oval:ssg-test_sudoers_default_includedir:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sudoers_default_includedir:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sudoers_default_includedir:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="test none sudoers #include or @include" id="oval:ssg-test_sudoers_without_include:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sudoers_without_include:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="test none sudoers @includedir" id="oval:ssg-test_sudoers_without_includedir_new:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sudoers_without_include_new:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="test none sudoers #includedir or @includdir" id="oval:ssg-test_sudoers_without_includedir:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sudoers_without_includedir:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="test none sudoers.d #include, @include, #includedir or @includedir" id="oval:ssg-test_sudoersd_without_includes:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sudoersd_without_includes:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Make sure that no command in user spec is without any argument" id="oval:ssg-test_sudoers_explicit_command_args:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sudoers_explicit_command_args:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Make sure that no command in user spec contains negation" id="oval:ssg-test_sudoers_no_command_negation:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sudoers_no_command_negation:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Make sure that no user spec in sudoers has a runas spec that includes root or ALL" id="oval:ssg-test_no_root_or_ALL_in_runas_spec:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-root_or_ALL_in_runas_spec:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="make sure that all user specs in sudoers feature a runas spec" id="oval:ssg-test_no_user_spec_rules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_no_runas_spec:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Ensure invoking user's password for privilege escalation when using sudo" id="oval:ssg-test_sudoers_targetpw_config:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_sudoers_targetpw_config:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Ensure invoking user's password for privilege escalation when using sudo" id="oval:ssg-test_sudoers_rootpw_config:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_sudoers_rootpw_config:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Ensure invoking user's password for privilege escalation when using sudo" id="oval:ssg-test_sudoers_runaspw_config:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_sudoers_runaspw_config:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Ensure invoking user's password for privilege escalation when using sudo" id="oval:ssg-test_sudoers_targetpw_not_defined:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_sudoers_targetpw_not_defined:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Ensure invoking user's password for privilege escalation when using sudo" id="oval:ssg-test_sudoers_rootpw_not_defined:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_sudoers_rootpw_not_defined:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Ensure invoking user's password for privilege escalation when using sudo" id="oval:ssg-test_sudoers_runaspw_not_defined:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_test_sudoers_runaspw_not_defined:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check value of clean_requirements_on_remove in /etc/yum.conf" id="oval:ssg-test_yum_clean_components_post_updating:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_yum_clean_components_post_updating:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of install_weak_deps setting in the /etc/dnf/dnf.conf file" id="oval:ssg-disable_weak_deps_test_disable_weak_deps:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-disable_weak_deps_obj_disable_weak_deps:obj:1"/>
          <ind:state state_ref="oval:ssg-disable_weak_deps_state_disable_weak_deps:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="The configuration file /etc/dnf/dnf.conf exists for disable_weak_deps" id="oval:ssg-disable_weak_deps_test_disable_weak_deps_config_file_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-disable_weak_deps_obj_disable_weak_deps_config_file:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of apply_updates setting in the /etc/dnf/automatic.conf file" id="oval:ssg-test_dnf-automatic_apply_updates:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_dnf-automatic_apply_updates:obj:1"/>
          <ind:state state_ref="oval:ssg-state_dnf-automatic_apply_updates:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="The configuration file /etc/dnf/automatic.conf exists for dnf-automatic_apply_updates" id="oval:ssg-test_dnf-automatic_apply_updates_config_file_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_dnf-automatic_apply_updates_config_file:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of upgrade_type setting in the /etc/dnf/automatic.conf file" id="oval:ssg-test_dnf-automatic_security_updates_only:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_dnf-automatic_security_updates_only:obj:1"/>
          <ind:state state_ref="oval:ssg-state_dnf-automatic_security_updates_only:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="The configuration file /etc/dnf/automatic.conf exists for dnf-automatic_security_updates_only" id="oval:ssg-test_dnf-automatic_security_updates_only_config_file_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_dnf-automatic_security_updates_only_config_file:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="verify all repos in /etc/yum.repos.d have gpgcheck enabled" id="oval:ssg-test_enable_gpgcheck_for_all_repositories_all_enabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_enable_gpgcheck_for_all_repositories:obj:1"/>
          <ind:state state_ref="oval:ssg-state_enable_gpgcheck_for_all_repositories_all_enabled:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="none satisfy" check_existence="all_exist" comment="verify no repo in /etc/yum.repos.d has gpgcheck disabled" id="oval:ssg-test_enable_gpgcheck_for_all_repositories_no_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_enable_gpgcheck_for_all_repositories:obj:1"/>
          <ind:state state_ref="oval:ssg-state_enable_gpgcheck_for_all_repositories_no_disabled:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:rpminfo_test check="only one" comment="AlmaLinux release key package is installed" id="oval:ssg-test_almalinux_package_gpgkey-3abb34f8-5ffd890e_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_almalinux_package_gpg-pubkey:obj:1"/>
          <linux:state state_ref="oval:ssg-state_almalinux_package_gpg-pubkey-3abb34f8-5ffd890e:ste:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="only one" comment="AlmaLinux auxiliary key package is installed" id="oval:ssg-test_almalinux_package_gpgkey-ced7258b-6525146f_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_almalinux_package_gpg-pubkey:obj:1"/>
          <linux:state state_ref="oval:ssg-state_almalinux_package_gpg-pubkey-ced7258b-6525146f:ste:1"/>
        </linux:rpminfo_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Ensure no EPEL repository sections exist" id="oval:ssg-test_no_epel_sections:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_epel_section_headers:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Ensure all EPEL repositories have enabled=0" id="oval:ssg-test_epel_repos_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_epel_repos_check_disabled:obj:1"/>
          <ind:state state_ref="oval:ssg-state_epel_disabled:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check value of gpgcheck in /etc/yum.conf" id="oval:ssg-test_ensure_gpgcheck_globally_activated:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_ensure_gpgcheck_globally_activated:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check value of localpkg_gpgcheck in /etc/yum.conf" id="oval:ssg-test_yum_ensure_gpgcheck_local_packages:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_yum_ensure_gpgcheck_local_packages:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="check for existence of gpgcheck=0 in /etc/yum.repos.d/ files" id="oval:ssg-test_ensure_gpgcheck_never_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_ensure_gpgcheck_never_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check value of repo_gpgcheck in /etc/yum.conf" id="oval:ssg-test_yum_ensure_gpgcheck_repo_metadata:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_yum_ensure_gpgcheck_repo_metadata:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check the configuration of ^/etc/security/pwquality.conf$" id="oval:ssg-test_password_pam_pwquality_dcredit:tst:1" state_operator="AND" version="3">
          <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_dcredit:obj:1"/>
          <ind:state state_ref="oval:ssg-state_password_pam_dcredit:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check the configuration of ^/etc/security/pwquality.conf$" id="oval:ssg-test_password_pam_pwquality_dictcheck:tst:1" state_operator="AND" version="3">
          <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_dictcheck:obj:1"/>
          <ind:state state_ref="oval:ssg-state_password_pam_dictcheck:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check the configuration of ^/etc/security/pwquality.conf$" id="oval:ssg-test_password_pam_pwquality_difok:tst:1" state_operator="AND" version="3">
          <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_difok:obj:1"/>
          <ind:state state_ref="oval:ssg-state_password_pam_difok:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="tests the presence of 'local_users_only' setting in the /etc/security/pwquality.conf file" id="oval:ssg-test_accounts_password_pam_enforce_local:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_password_pam_enforce_local:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check the configuration of ^/etc/security/pwquality.conf$" id="oval:ssg-test_password_pam_pwquality_lcredit:tst:1" state_operator="AND" version="3">
          <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_lcredit:obj:1"/>
          <ind:state state_ref="oval:ssg-state_password_pam_lcredit:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check the configuration of ^/etc/security/pwquality.conf$" id="oval:ssg-test_password_pam_pwquality_maxclassrepeat:tst:1" state_operator="AND" version="3">
          <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_maxclassrepeat:obj:1"/>
          <ind:state state_ref="oval:ssg-state_password_pam_maxclassrepeat:ste:1"/>
          <ind:state state_ref="oval:ssg-state_password_pam_maxclassrepeat_zero_comparison:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check the configuration of ^/etc/security/pwquality.conf$" id="oval:ssg-test_password_pam_pwquality_maxrepeat:tst:1" state_operator="AND" version="3">
          <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_maxrepeat:obj:1"/>
          <ind:state state_ref="oval:ssg-state_password_pam_maxrepeat:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check the configuration of ^/etc/security/pwquality.conf$" id="oval:ssg-test_password_pam_pwquality_maxsequence:tst:1" state_operator="AND" version="3">
          <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_maxsequence:obj:1"/>
          <ind:state state_ref="oval:ssg-state_password_pam_maxsequence:ste:1"/>
          <ind:state state_ref="oval:ssg-state_password_pam_maxsequence_zero_comparison:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check the configuration of ^/etc/security/pwquality.conf$" id="oval:ssg-test_password_pam_pwquality_minclass:tst:1" state_operator="AND" version="3">
          <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_minclass:obj:1"/>
          <ind:state state_ref="oval:ssg-state_password_pam_minclass:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check the configuration of ^/etc/security/pwquality.conf$" id="oval:ssg-test_password_pam_pwquality_minlen:tst:1" state_operator="AND" version="3">
          <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_minlen:obj:1"/>
          <ind:state state_ref="oval:ssg-state_password_pam_minlen:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check the configuration of ^/etc/security/pwquality.conf$" id="oval:ssg-test_password_pam_pwquality_ocredit:tst:1" state_operator="AND" version="3">
          <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_ocredit:obj:1"/>
          <ind:state state_ref="oval:ssg-state_password_pam_ocredit:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="tests the presence of 'enforce_for_root' setting in the /etc/security/pwhistory.conf file" id="oval:ssg-test_accounts_password_pam_pwhistory_enforce_for_root:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_accounts_password_pam_pwhistory_enforce_for_root:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check the configuration of ^/etc/security/pwquality.conf$" id="oval:ssg-test_password_pam_pwquality_ucredit:tst:1" state_operator="AND" version="3">
          <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_ucredit:obj:1"/>
          <ind:state state_ref="oval:ssg-state_password_pam_ucredit:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="no more that one pam_unix.so is expected in auth section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_system_pam_unix_auth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_system_pam_unix_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in auth section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_system_pam_faillock_auth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_system_pam_faillock_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="no more that one pam_unix.so is expected in auth section of password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_password_pam_unix_auth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_password_pam_unix_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in auth section of password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_password_pam_faillock_auth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_password_pam_faillock_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_system_pam_faillock_account:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_system_pam_faillock_account:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_password_pam_faillock_account:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_password_pam_faillock_account:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of deny parameter in system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_no_pamd_system:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_pamd_system:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected deny value in system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_pamd_system:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_pamd_system:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_deny_parameter_upper_bound:ste:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_deny_parameter_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of deny parameter in password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_no_pamd_password:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_pamd_password:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected deny value in password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_pamd_password:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_pamd_password:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_deny_parameter_upper_bound:ste:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_deny_parameter_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected deny value in /etc/security/faillock.conf" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_faillock_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_deny_parameter_upper_bound:ste:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_deny_parameter_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of deny parameter in /etc/security/faillock.conf" id="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_no_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_faillock_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="no more that one pam_unix.so is expected in auth section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_system_pam_unix_auth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_system_pam_unix_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in auth section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_system_pam_faillock_auth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_system_pam_faillock_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="no more that one pam_unix.so is expected in auth section of password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_password_pam_unix_auth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_password_pam_unix_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in auth section of password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_password_pam_faillock_auth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_password_pam_faillock_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_system_pam_faillock_account:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_system_pam_faillock_account:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_password_pam_faillock_account:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_password_pam_faillock_account:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of fail_interval parameter in system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_no_pamd_system:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_system:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected fail_interval value in system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_system:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_system:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_fail_interval_parameter_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of fail_interval parameter in password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_no_pamd_password:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_password:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected fail_interval value in password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_password:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_password:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_fail_interval_parameter_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected fail_interval value in /etc/security/faillock.conf" id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_faillock_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_fail_interval_parameter_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of fail_interval parameter in /etc/security/faillock.conf" id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_no_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_faillock_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="no more that one pam_unix.so is expected in auth section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_system_pam_unix_auth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_system_pam_unix_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in auth section of system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_system_pam_faillock_auth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_system_pam_faillock_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="no more that one pam_unix.so is expected in auth section of password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_password_pam_unix_auth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_password_pam_unix_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in auth section of password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_password_pam_faillock_auth:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_password_pam_faillock_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_system_pam_faillock_account:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_system_pam_faillock_account:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="One and only one occurrence is expected in password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_password_pam_faillock_account:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_password_pam_faillock_account:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of unlock_time parameter in system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_no_pamd_system:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_system:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected unlock_time value in system-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_system:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_system:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_unlock_time_parameter_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of unlock_time parameter in password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_no_pamd_password:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_password:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected unlock_time value in password-auth" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_password:tst:1" state_operator="AND" version="2">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_password:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_unlock_time_parameter_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check the expected unlock_time value in /etc/security/faillock.conf" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_faillock_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_unlock_time_parameter_lower_bound:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check the absence of unlock_time parameter in /etc/security/faillock.conf" id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_no_faillock_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_faillock_conf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests if contents of /etc/audit/rules.d/30-ospp-v42-3-access-failed.rules is exactly what is defined in rule description" id="oval:ssg-audit_access_failed_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_3_access_failed_rules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-audit_access_failed_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_3_access_failed_rules:obj:1"/>
          <ind:state state_ref="oval:ssg-audit_access_failed_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_3_access_failed_rules:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests if contents of /etc/audit/rules.d/30-ospp-v42-3-access-success.rules is exactly what is defined in rule description" id="oval:ssg-audit_access_success_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_3_access_success_rules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-audit_access_success_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_3_access_success_rules:obj:1"/>
          <ind:state state_ref="oval:ssg-audit_access_success_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_3_access_success_rules:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests if contents of /etc/audit/rules.d/10-base-config.rules is exactly what is defined in rule description" id="oval:ssg-audit_basic_configuration_test_whole_file_contents_tc_audit_rules_d_10_base_config_rules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-audit_basic_configuration_object_whole_file_contents_tc_audit_rules_d_10_base_config_rules:obj:1"/>
          <ind:state state_ref="oval:ssg-audit_basic_configuration_state_whole_file_contents_tc_audit_rules_d_10_base_config_rules:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests if contents of /etc/audit/rules.d/30-ospp-v42-1-create-failed.rules is exactly what is defined in rule description" id="oval:ssg-audit_create_failed_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_1_create_failed_rules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-audit_create_failed_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_1_create_failed_rules:obj:1"/>
          <ind:state state_ref="oval:ssg-audit_create_failed_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_1_create_failed_rules:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests if contents of /etc/audit/rules.d/30-ospp-v42-1-create-success.rules is exactly what is defined in rule description" id="oval:ssg-audit_create_success_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_1_create_success_rules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-audit_create_success_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_1_create_success_rules:obj:1"/>
          <ind:state state_ref="oval:ssg-audit_create_success_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_1_create_success_rules:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests if contents of /etc/audit/rules.d/30-ospp-v42-4-delete-failed.rules is exactly what is defined in rule description" id="oval:ssg-audit_delete_failed_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_failed_rules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-audit_delete_failed_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_failed_rules:obj:1"/>
          <ind:state state_ref="oval:ssg-audit_delete_failed_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_failed_rules:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests if contents of /etc/audit/rules.d/30-ospp-v42-4-delete-success.rules is exactly what is defined in rule description" id="oval:ssg-audit_delete_success_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_success_rules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-audit_delete_success_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_success_rules:obj:1"/>
          <ind:state state_ref="oval:ssg-audit_delete_success_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_success_rules:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests if contents of /etc/audit/rules.d/11-loginuid.rules is exactly what is defined in rule description" id="oval:ssg-audit_immutable_login_uids_test_whole_file_contents_tc_audit_rules_d_11_loginuid_rules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-audit_immutable_login_uids_object_whole_file_contents_tc_audit_rules_d_11_loginuid_rules:obj:1"/>
          <ind:state state_ref="oval:ssg-audit_immutable_login_uids_state_whole_file_contents_tc_audit_rules_d_11_loginuid_rules:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests if contents of /etc/audit/rules.d/30-ospp-v42-2-modify-failed.rules is exactly what is defined in rule description" id="oval:ssg-audit_modify_failed_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_2_modify_failed_rules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-audit_modify_failed_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_2_modify_failed_rules:obj:1"/>
          <ind:state state_ref="oval:ssg-audit_modify_failed_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_2_modify_failed_rules:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests if contents of /etc/audit/rules.d/30-ospp-v42-2-modify-success.rules is exactly what is defined in rule description" id="oval:ssg-audit_modify_success_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_2_modify_success_rules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-audit_modify_success_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_2_modify_success_rules:obj:1"/>
          <ind:state state_ref="oval:ssg-audit_modify_success_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_2_modify_success_rules:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests if contents of /etc/audit/rules.d/43-module-load.rules is exactly what is defined in rule description" id="oval:ssg-audit_module_load_test_whole_file_contents_tc_audit_rules_d_43_module_load_rules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-audit_module_load_object_whole_file_contents_tc_audit_rules_d_43_module_load_rules:obj:1"/>
          <ind:state state_ref="oval:ssg-audit_module_load_state_whole_file_contents_tc_audit_rules_d_43_module_load_rules:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests if contents of /etc/audit/rules.d/30-ospp-v42.rules is exactly what is defined in rule description" id="oval:ssg-audit_ospp_general_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_rules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-audit_ospp_general_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_rules:obj:1"/>
          <ind:state state_ref="oval:ssg-audit_ospp_general_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_rules:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests if contents of /etc/audit/rules.d/30-ospp-v42-6-owner-change-failed.rules is exactly what is defined in rule description" id="oval:ssg-audit_owner_change_failed_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_6_owner_change_failed_rules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-audit_owner_change_failed_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_6_owner_change_failed_rules:obj:1"/>
          <ind:state state_ref="oval:ssg-audit_owner_change_failed_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_6_owner_change_failed_rules:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests if contents of /etc/audit/rules.d/30-ospp-v42-6-owner-change-success.rules is exactly what is defined in rule description" id="oval:ssg-audit_owner_change_success_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_6_owner_change_success_rules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-audit_owner_change_success_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_6_owner_change_success_rules:obj:1"/>
          <ind:state state_ref="oval:ssg-audit_owner_change_success_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_6_owner_change_success_rules:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests if contents of /etc/audit/rules.d/30-ospp-v42-5-perm-change-failed.rules is exactly what is defined in rule description" id="oval:ssg-audit_perm_change_failed_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_5_perm_change_failed_rules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-audit_perm_change_failed_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_5_perm_change_failed_rules:obj:1"/>
          <ind:state state_ref="oval:ssg-audit_perm_change_failed_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_5_perm_change_failed_rules:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Tests if contents of /etc/audit/rules.d/30-ospp-v42-5-perm-change-success.rules is exactly what is defined in rule description" id="oval:ssg-audit_perm_change_success_test_whole_file_contents_tc_audit_rules_d_30_ospp_v42_5_perm_change_success_rules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-audit_perm_change_success_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_5_perm_change_success_rules:obj:1"/>
          <ind:state state_ref="oval:ssg-audit_perm_change_success_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_5_perm_change_success_rules:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules init" id="oval:ssg-test_audit_privileged_commands_init_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_privileged_commands_init_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl init" id="oval:ssg-test_audit_privileged_commands_init_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_privileged_commands_init_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules poweroff" id="oval:ssg-test_audit_privileged_commands_poweroff_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_privileged_commands_poweroff_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl poweroff" id="oval:ssg-test_audit_privileged_commands_poweroff_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_privileged_commands_poweroff_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules reboot" id="oval:ssg-test_audit_privileged_commands_reboot_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_privileged_commands_reboot_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl reboot" id="oval:ssg-test_audit_privileged_commands_reboot_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_privileged_commands_reboot_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules shutdown" id="oval:ssg-test_audit_privileged_commands_shutdown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_privileged_commands_shutdown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl shutdown" id="oval:ssg-test_audit_privileged_commands_shutdown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_privileged_commands_shutdown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit chmod" id="oval:ssg-test_32bit_ardm_chmod_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_chmod_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit chmod" id="oval:ssg-test_64bit_ardm_chmod_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_chmod_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit chmod" id="oval:ssg-test_32bit_ardm_chmod_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_chmod_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit chmod" id="oval:ssg-test_64bit_ardm_chmod_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_chmod_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit chown" id="oval:ssg-test_32bit_ardm_chown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_chown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit chown" id="oval:ssg-test_64bit_ardm_chown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_chown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit chown" id="oval:ssg-test_32bit_ardm_chown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_chown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit chown" id="oval:ssg-test_64bit_ardm_chown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_chown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit fchmod" id="oval:ssg-test_32bit_ardm_fchmod_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_fchmod_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit fchmod" id="oval:ssg-test_64bit_ardm_fchmod_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_fchmod_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit fchmod" id="oval:ssg-test_32bit_ardm_fchmod_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_fchmod_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit fchmod" id="oval:ssg-test_64bit_ardm_fchmod_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_fchmod_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit fchmodat" id="oval:ssg-test_32bit_ardm_fchmodat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_fchmodat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit fchmodat" id="oval:ssg-test_64bit_ardm_fchmodat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_fchmodat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit fchmodat" id="oval:ssg-test_32bit_ardm_fchmodat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_fchmodat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit fchmodat" id="oval:ssg-test_64bit_ardm_fchmodat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_fchmodat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit fchown" id="oval:ssg-test_32bit_ardm_fchown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_fchown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit fchown" id="oval:ssg-test_64bit_ardm_fchown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_fchown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit fchown" id="oval:ssg-test_32bit_ardm_fchown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_fchown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit fchown" id="oval:ssg-test_64bit_ardm_fchown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_fchown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit fchownat" id="oval:ssg-test_32bit_ardm_fchownat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_fchownat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit fchownat" id="oval:ssg-test_64bit_ardm_fchownat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_fchownat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit fchownat" id="oval:ssg-test_32bit_ardm_fchownat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_fchownat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit fchownat" id="oval:ssg-test_64bit_ardm_fchownat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_fchownat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit fremovexattr" id="oval:ssg-test_32bit_ardm_fremovexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_fremovexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit fremovexattr" id="oval:ssg-test_64bit_ardm_fremovexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_fremovexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit fremovexattr" id="oval:ssg-test_32bit_ardm_fremovexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_fremovexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit fremovexattr" id="oval:ssg-test_64bit_ardm_fremovexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_fremovexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit fsetxattr" id="oval:ssg-test_32bit_ardm_fsetxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_fsetxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit fsetxattr" id="oval:ssg-test_64bit_ardm_fsetxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_fsetxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit fsetxattr" id="oval:ssg-test_32bit_ardm_fsetxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_fsetxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit fsetxattr" id="oval:ssg-test_64bit_ardm_fsetxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_fsetxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit lchown" id="oval:ssg-test_32bit_ardm_lchown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_lchown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit lchown" id="oval:ssg-test_64bit_ardm_lchown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_lchown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit lchown" id="oval:ssg-test_32bit_ardm_lchown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_lchown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit lchown" id="oval:ssg-test_64bit_ardm_lchown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_lchown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit lremovexattr" id="oval:ssg-test_32bit_ardm_lremovexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_lremovexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit lremovexattr" id="oval:ssg-test_64bit_ardm_lremovexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_lremovexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit lremovexattr" id="oval:ssg-test_32bit_ardm_lremovexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_lremovexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit lremovexattr" id="oval:ssg-test_64bit_ardm_lremovexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_lremovexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit lsetxattr" id="oval:ssg-test_32bit_ardm_lsetxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_lsetxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit lsetxattr" id="oval:ssg-test_64bit_ardm_lsetxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_lsetxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit lsetxattr" id="oval:ssg-test_32bit_ardm_lsetxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_lsetxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit lsetxattr" id="oval:ssg-test_64bit_ardm_lsetxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_lsetxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit removexattr" id="oval:ssg-test_32bit_ardm_removexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_removexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit removexattr" id="oval:ssg-test_64bit_ardm_removexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_removexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit removexattr" id="oval:ssg-test_32bit_ardm_removexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_removexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit removexattr" id="oval:ssg-test_64bit_ardm_removexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_removexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit setxattr" id="oval:ssg-test_32bit_ardm_setxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_setxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit setxattr" id="oval:ssg-test_64bit_ardm_setxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_setxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit setxattr" id="oval:ssg-test_32bit_ardm_setxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_setxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit setxattr" id="oval:ssg-test_64bit_ardm_setxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_setxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit umount2" id="oval:ssg-test_32bit_ardm_umount2_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_umount2_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit umount2" id="oval:ssg-test_64bit_ardm_umount2_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_umount2_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit umount2" id="oval:ssg-test_32bit_ardm_umount2_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_umount2_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit umount2" id="oval:ssg-test_64bit_ardm_umount2_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_umount2_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules cron_d" id="oval:ssg-test_audit_rules_etc_cron_d_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_etc_cron_d_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl cron_d" id="oval:ssg-test_audit_rules_etc_cron_d_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_etc_cron_d_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_group_open_32bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_group_open_32bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_group_open_64bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_group_open_64bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_group_open_32bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_group_open_32bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_group_open_64bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_group_open_64bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_group_open_by_handle_at_32bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_group_open_by_handle_at_32bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_group_open_by_handle_at_64bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_group_open_by_handle_at_64bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_group_open_by_handle_at_32bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_group_open_by_handle_at_32bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_group_open_by_handle_at_64bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_group_open_by_handle_at_64bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_group_openat_32bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_group_openat_32bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_group_openat_64bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_group_openat_64bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_group_openat_32bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_group_openat_32bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_group_openat_64bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_group_openat_64bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_gshadow_open_32bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_gshadow_open_32bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_gshadow_open_64bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_gshadow_open_64bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_gshadow_open_32bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_gshadow_open_32bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_gshadow_open_64bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_gshadow_open_64bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_gshadow_open_by_handle_at_32bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_gshadow_open_by_handle_at_32bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_gshadow_open_by_handle_at_64bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_gshadow_open_by_handle_at_64bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_gshadow_open_by_handle_at_32bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_gshadow_open_by_handle_at_32bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_gshadow_open_by_handle_at_64bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_gshadow_open_by_handle_at_64bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_gshadow_openat_32bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_gshadow_openat_32bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_gshadow_openat_64bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_gshadow_openat_64bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_gshadow_openat_32bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_gshadow_openat_32bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_gshadow_openat_64bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_gshadow_openat_64bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_passwd_open_32bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_passwd_open_32bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_passwd_open_64bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_passwd_open_64bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_passwd_open_32bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_passwd_open_32bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_passwd_open_64bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_passwd_open_64bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_passwd_open_by_handle_at_32bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_passwd_open_by_handle_at_32bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_passwd_open_by_handle_at_64bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_passwd_open_by_handle_at_64bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_passwd_open_by_handle_at_32bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_passwd_open_by_handle_at_32bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_passwd_open_by_handle_at_64bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_passwd_open_by_handle_at_64bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_passwd_openat_32bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_passwd_openat_32bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_passwd_openat_64bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_passwd_openat_64bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_passwd_openat_32bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_passwd_openat_32bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_passwd_openat_64bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_passwd_openat_64bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_shadow_open_32bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_shadow_open_32bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_shadow_open_64bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_shadow_open_64bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_shadow_open_32bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_shadow_open_32bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_shadow_open_64bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_shadow_open_64bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_shadow_open_by_handle_at_32bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_shadow_open_by_handle_at_32bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_shadow_open_by_handle_at_64bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_shadow_open_by_handle_at_64bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_shadow_open_by_handle_at_32bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_shadow_open_by_handle_at_32bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_shadow_open_by_handle_at_64bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_shadow_open_by_handle_at_64bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_shadow_openat_32bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_shadow_openat_32bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_shadow_openat_64bit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_shadow_openat_64bit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_shadow_openat_32bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_shadow_openat_32bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_audit_rules_tc_shadow_openat_64bit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_tc_shadow_openat_64bit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules chacl" id="oval:ssg-test_audit_rules_execution_chacl_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_execution_chacl_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl chacl" id="oval:ssg-test_audit_rules_execution_chacl_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_execution_chacl_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules chcon" id="oval:ssg-test_audit_rules_execution_chcon_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_execution_chcon_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl chcon" id="oval:ssg-test_audit_rules_execution_chcon_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_execution_chcon_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules restorecon" id="oval:ssg-test_audit_rules_execution_restorecon_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_execution_restorecon_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl restorecon" id="oval:ssg-test_audit_rules_execution_restorecon_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_execution_restorecon_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules semanage" id="oval:ssg-test_audit_rules_execution_semanage_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_execution_semanage_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl semanage" id="oval:ssg-test_audit_rules_execution_semanage_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_execution_semanage_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules setfacl" id="oval:ssg-test_audit_rules_execution_setfacl_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_execution_setfacl_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl setfacl" id="oval:ssg-test_audit_rules_execution_setfacl_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_execution_setfacl_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules setfiles" id="oval:ssg-test_audit_rules_execution_setfiles_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_execution_setfiles_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl setfiles" id="oval:ssg-test_audit_rules_execution_setfiles_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_execution_setfiles_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules setsebool" id="oval:ssg-test_audit_rules_execution_setsebool_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_execution_setsebool_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl setsebool" id="oval:ssg-test_audit_rules_execution_setsebool_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_execution_setsebool_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules seunshare" id="oval:ssg-test_audit_rules_execution_seunshare_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_execution_seunshare_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl seunshare" id="oval:ssg-test_audit_rules_execution_seunshare_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_execution_seunshare_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit rename" id="oval:ssg-test_32bit_ardm_rename_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_rename_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit rename" id="oval:ssg-test_64bit_ardm_rename_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_rename_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit rename" id="oval:ssg-test_32bit_ardm_rename_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_rename_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit rename" id="oval:ssg-test_64bit_ardm_rename_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_rename_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit renameat" id="oval:ssg-test_32bit_ardm_renameat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_renameat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit renameat" id="oval:ssg-test_64bit_ardm_renameat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_renameat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit renameat" id="oval:ssg-test_32bit_ardm_renameat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_renameat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit renameat" id="oval:ssg-test_64bit_ardm_renameat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_renameat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit renameat2" id="oval:ssg-test_32bit_ardm_renameat2_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_renameat2_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit renameat2" id="oval:ssg-test_64bit_ardm_renameat2_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_renameat2_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit renameat2" id="oval:ssg-test_32bit_ardm_renameat2_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_renameat2_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit renameat2" id="oval:ssg-test_64bit_ardm_renameat2_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_renameat2_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit rmdir" id="oval:ssg-test_32bit_ardm_rmdir_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_rmdir_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit rmdir" id="oval:ssg-test_64bit_ardm_rmdir_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_rmdir_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit rmdir" id="oval:ssg-test_32bit_ardm_rmdir_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_rmdir_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit rmdir" id="oval:ssg-test_64bit_ardm_rmdir_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_rmdir_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit unlink" id="oval:ssg-test_32bit_ardm_unlink_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_unlink_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit unlink" id="oval:ssg-test_64bit_ardm_unlink_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_unlink_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit unlink" id="oval:ssg-test_32bit_ardm_unlink_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_unlink_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit unlink" id="oval:ssg-test_64bit_ardm_unlink_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_unlink_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit unlinkat" id="oval:ssg-test_32bit_ardm_unlinkat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_unlinkat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit unlinkat" id="oval:ssg-test_64bit_ardm_unlinkat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_unlinkat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit unlinkat" id="oval:ssg-test_32bit_ardm_unlinkat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_unlinkat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit unlinkat" id="oval:ssg-test_64bit_ardm_unlinkat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_unlinkat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit create_module" id="oval:ssg-test_32bit_arkml_create_module_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arkml_create_module_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit create_module" id="oval:ssg-test_64bit_arkml_create_module_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arkml_create_module_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit create_module" id="oval:ssg-test_32bit_arkml_create_module_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arkml_create_module_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit create_module" id="oval:ssg-test_64bit_arkml_create_module_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arkml_create_module_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit delete_module" id="oval:ssg-test_32bit_arkml_delete_module_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arkml_delete_module_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit delete_module" id="oval:ssg-test_64bit_arkml_delete_module_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arkml_delete_module_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit delete_module" id="oval:ssg-test_32bit_arkml_delete_module_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arkml_delete_module_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit delete_module" id="oval:ssg-test_64bit_arkml_delete_module_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arkml_delete_module_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit finit_module" id="oval:ssg-test_32bit_arkml_finit_module_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arkml_finit_module_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit finit_module" id="oval:ssg-test_64bit_arkml_finit_module_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arkml_finit_module_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit finit_module" id="oval:ssg-test_32bit_arkml_finit_module_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arkml_finit_module_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit finit_module" id="oval:ssg-test_64bit_arkml_finit_module_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arkml_finit_module_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit init_module" id="oval:ssg-test_32bit_arkml_init_module_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arkml_init_module_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit init_module" id="oval:ssg-test_64bit_arkml_init_module_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arkml_init_module_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit init_module" id="oval:ssg-test_32bit_arkml_init_module_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arkml_init_module_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit init_module" id="oval:ssg-test_64bit_arkml_init_module_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arkml_init_module_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit query_module" id="oval:ssg-test_32bit_arkml_query_module_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arkml_query_module_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit query_module" id="oval:ssg-test_64bit_arkml_query_module_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arkml_query_module_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit query_module" id="oval:ssg-test_32bit_arkml_query_module_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arkml_query_module_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit query_module" id="oval:ssg-test_64bit_arkml_query_module_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arkml_query_module_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules var_accounts_passwords_pam_faillock_dir" id="oval:ssg-test_audit_rules_login_events_faillock_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_login_events_faillock_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl var_accounts_passwords_pam_faillock_dir" id="oval:ssg-test_audit_rules_login_events_faillock_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_login_events_faillock_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules lastlog" id="oval:ssg-test_audit_rules_login_events_lastlog_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_login_events_lastlog_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl lastlog" id="oval:ssg-test_audit_rules_login_events_lastlog_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_login_events_lastlog_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules tallylog" id="oval:ssg-test_audit_rules_login_events_tallylog_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_login_events_tallylog_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl tallylog" id="oval:ssg-test_audit_rules_login_events_tallylog_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_login_events_tallylog_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules selinux" id="oval:ssg-test_audit_rules_mac_modification_usr_share_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_mac_modification_usr_share_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl selinux" id="oval:ssg-test_audit_rules_mac_modification_usr_share_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_mac_modification_usr_share_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit mount" id="oval:ssg-test_32bit_ardm_mount_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_mount_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit mount" id="oval:ssg-test_64bit_ardm_mount_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_mount_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit mount" id="oval:ssg-test_32bit_ardm_mount_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_ardm_mount_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit mount" id="oval:ssg-test_64bit_ardm_mount_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_ardm_mount_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules network_scripts" id="oval:ssg-test_audit_rules_networkconfig_modification_network_scripts_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_networkconfig_modification_network_scripts_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl network_scripts" id="oval:ssg-test_audit_rules_networkconfig_modification_network_scripts_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_networkconfig_modification_network_scripts_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules at" id="oval:ssg-test_audit_rules_privileged_commands_at_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_at_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl at" id="oval:ssg-test_audit_rules_privileged_commands_at_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_at_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules chage" id="oval:ssg-test_audit_rules_privileged_commands_chage_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_chage_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl chage" id="oval:ssg-test_audit_rules_privileged_commands_chage_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_chage_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules chsh" id="oval:ssg-test_audit_rules_privileged_commands_chsh_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_chsh_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl chsh" id="oval:ssg-test_audit_rules_privileged_commands_chsh_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_chsh_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules crontab" id="oval:ssg-test_audit_rules_privileged_commands_crontab_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_crontab_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl crontab" id="oval:ssg-test_audit_rules_privileged_commands_crontab_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_crontab_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules gpasswd" id="oval:ssg-test_audit_rules_privileged_commands_gpasswd_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_gpasswd_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl gpasswd" id="oval:ssg-test_audit_rules_privileged_commands_gpasswd_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_gpasswd_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules kmod" id="oval:ssg-test_audit_rules_privileged_commands_kmod_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_kmod_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl kmod" id="oval:ssg-test_audit_rules_privileged_commands_kmod_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_kmod_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules mount" id="oval:ssg-test_audit_rules_privileged_commands_mount_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_mount_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl mount" id="oval:ssg-test_audit_rules_privileged_commands_mount_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_mount_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules newgidmap" id="oval:ssg-test_audit_rules_privileged_commands_newgidmap_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_newgidmap_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl newgidmap" id="oval:ssg-test_audit_rules_privileged_commands_newgidmap_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_newgidmap_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules newgrp" id="oval:ssg-test_audit_rules_privileged_commands_newgrp_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_newgrp_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl newgrp" id="oval:ssg-test_audit_rules_privileged_commands_newgrp_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_newgrp_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules newuidmap" id="oval:ssg-test_audit_rules_privileged_commands_newuidmap_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_newuidmap_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl newuidmap" id="oval:ssg-test_audit_rules_privileged_commands_newuidmap_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_newuidmap_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules pam_timestamp_check" id="oval:ssg-test_audit_rules_privileged_commands_pam_timestamp_check_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_pam_timestamp_check_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl pam_timestamp_check" id="oval:ssg-test_audit_rules_privileged_commands_pam_timestamp_check_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_pam_timestamp_check_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules passwd" id="oval:ssg-test_audit_rules_privileged_commands_passwd_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_passwd_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl passwd" id="oval:ssg-test_audit_rules_privileged_commands_passwd_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_passwd_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules postdrop" id="oval:ssg-test_audit_rules_privileged_commands_postdrop_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_postdrop_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl postdrop" id="oval:ssg-test_audit_rules_privileged_commands_postdrop_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_postdrop_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules postqueue" id="oval:ssg-test_audit_rules_privileged_commands_postqueue_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_postqueue_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl postqueue" id="oval:ssg-test_audit_rules_privileged_commands_postqueue_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_postqueue_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules pt_chown" id="oval:ssg-test_audit_rules_privileged_commands_pt_chown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_pt_chown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl pt_chown" id="oval:ssg-test_audit_rules_privileged_commands_pt_chown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_pt_chown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules ssh_agent" id="oval:ssg-test_audit_rules_privileged_commands_ssh_agent_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_ssh_agent_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl ssh_agent" id="oval:ssg-test_audit_rules_privileged_commands_ssh_agent_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_ssh_agent_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules ssh_keysign" id="oval:ssg-test_audit_rules_privileged_commands_ssh_keysign_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_ssh_keysign_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl ssh_keysign" id="oval:ssg-test_audit_rules_privileged_commands_ssh_keysign_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_ssh_keysign_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules su" id="oval:ssg-test_audit_rules_privileged_commands_su_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_su_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl su" id="oval:ssg-test_audit_rules_privileged_commands_su_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_su_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules sudo" id="oval:ssg-test_audit_rules_privileged_commands_sudo_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_sudo_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl sudo" id="oval:ssg-test_audit_rules_privileged_commands_sudo_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_sudo_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules sudoedit" id="oval:ssg-test_audit_rules_privileged_commands_sudoedit_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_sudoedit_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl sudoedit" id="oval:ssg-test_audit_rules_privileged_commands_sudoedit_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_sudoedit_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules umount" id="oval:ssg-test_audit_rules_privileged_commands_umount_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_umount_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl umount" id="oval:ssg-test_audit_rules_privileged_commands_umount_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_umount_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules unix_chkpwd" id="oval:ssg-test_audit_rules_privileged_commands_unix_chkpwd_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_unix_chkpwd_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl unix_chkpwd" id="oval:ssg-test_audit_rules_privileged_commands_unix_chkpwd_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_unix_chkpwd_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules unix_update" id="oval:ssg-test_audit_rules_privileged_commands_unix_update_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_unix_update_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl unix_update" id="oval:ssg-test_audit_rules_privileged_commands_unix_update_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_unix_update_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules userhelper" id="oval:ssg-test_audit_rules_privileged_commands_userhelper_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_userhelper_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl userhelper" id="oval:ssg-test_audit_rules_privileged_commands_userhelper_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_userhelper_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules usermod" id="oval:ssg-test_audit_rules_privileged_commands_usermod_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_usermod_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl usermod" id="oval:ssg-test_audit_rules_privileged_commands_usermod_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_usermod_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit augenrules usernetctl" id="oval:ssg-test_audit_rules_privileged_commands_usernetctl_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_usernetctl_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="audit auditctl usernetctl" id="oval:ssg-test_audit_rules_privileged_commands_usernetctl_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_privileged_commands_usernetctl_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules btmp" id="oval:ssg-test_audit_rules_session_events_btmp_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_session_events_btmp_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl btmp" id="oval:ssg-test_audit_rules_session_events_btmp_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_session_events_btmp_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules utmp" id="oval:ssg-test_audit_rules_session_events_utmp_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_session_events_utmp_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl utmp" id="oval:ssg-test_audit_rules_session_events_utmp_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_session_events_utmp_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules wtmp" id="oval:ssg-test_audit_rules_session_events_wtmp_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_session_events_wtmp_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl wtmp" id="oval:ssg-test_audit_rules_session_events_wtmp_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_session_events_wtmp_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules sudoers" id="oval:ssg-test_audit_rules_sudoers_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_sudoers_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl sudoers" id="oval:ssg-test_audit_rules_sudoers_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_sudoers_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules sudoers_d" id="oval:ssg-test_audit_rules_sudoers_d_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_sudoers_d_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl sudoers_d" id="oval:ssg-test_audit_rules_sudoers_d_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_sudoers_d_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules localtime" id="oval:ssg-test_audit_rules_time_watch_localtime_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_time_watch_localtime_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl localtime" id="oval:ssg-test_audit_rules_time_watch_localtime_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_time_watch_localtime_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_chmod_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_chmod_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_chmod_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_chmod_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_chmod_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_chmod_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_chmod_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_chmod_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_chmod_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_chmod_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_chmod_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_chmod_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_chmod_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_chmod_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_chmod_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_chmod_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_chown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_chown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_chown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_chown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_chown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_chown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_chown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_chown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_chown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_chown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_chown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_chown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_chown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_chown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_chown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_chown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_creat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_creat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_creat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_creat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_creat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_creat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_creat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_creat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_creat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_creat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_creat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_creat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_creat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_creat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_creat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_creat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_fchmod_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_fchmod_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_fchmod_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_fchmod_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_fchmod_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_fchmod_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_fchmod_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_fchmod_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_fchmod_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_fchmod_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_fchmod_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_fchmod_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_fchmod_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_fchmod_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_fchmod_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_fchmod_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_fchmodat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_fchmodat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_fchmodat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_fchmodat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_fchmodat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_fchmodat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_fchmodat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_fchmodat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_fchmodat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_fchmodat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_fchmodat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_fchmodat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_fchmodat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_fchmodat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_fchmodat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_fchmodat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_fchown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_fchown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_fchown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_fchown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_fchown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_fchown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_fchown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_fchown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_fchown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_fchown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_fchown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_fchown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_fchown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_fchown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_fchown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_fchown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_fchownat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_fchownat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_fchownat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_fchownat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_fchownat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_fchownat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_fchownat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_fchownat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_fchownat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_fchownat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_fchownat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_fchownat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_fchownat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_fchownat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_fchownat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_fchownat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_fremovexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_fremovexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_fremovexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_fremovexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_fremovexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_fremovexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_fremovexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_fremovexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_fremovexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_fremovexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_fremovexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_fremovexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_fremovexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_fremovexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_fremovexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_fremovexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_fsetxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_fsetxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_fsetxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_fsetxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_fsetxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_fsetxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_fsetxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_fsetxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_fsetxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_fsetxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_fsetxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_fsetxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_fsetxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_fsetxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_fsetxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_fsetxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_ftruncate_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_ftruncate_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_ftruncate_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_ftruncate_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_ftruncate_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_ftruncate_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_ftruncate_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_ftruncate_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_ftruncate_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_ftruncate_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_ftruncate_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_ftruncate_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_ftruncate_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_ftruncate_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_ftruncate_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_ftruncate_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_lchown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_lchown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_lchown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_lchown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_lchown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_lchown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_lchown_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_lchown_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_lchown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_lchown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_lchown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_lchown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_lchown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_lchown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_lchown_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_lchown_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_lremovexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_lremovexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_lremovexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_lremovexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_lremovexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_lremovexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_lremovexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_lremovexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_lremovexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_lremovexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_lremovexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_lremovexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_lremovexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_lremovexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_lremovexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_lremovexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_lsetxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_lsetxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_lsetxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_lsetxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_lsetxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_lsetxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_lsetxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_lsetxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_lsetxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_lsetxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_lsetxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_lsetxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_lsetxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_lsetxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_lsetxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_lsetxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_open_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_open_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_open_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_open_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_open_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_open_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_open_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_open_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_open_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_open_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_open_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_open_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_open_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_open_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_open_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_open_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_open_by_handle_at_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_open_by_handle_at_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_open_by_handle_at_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_open_by_handle_at_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_open_by_handle_at_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_open_by_handle_at_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_open_by_handle_at_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_open_by_handle_at_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_open_by_handle_at_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_open_by_handle_at_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_open_by_handle_at_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_open_by_handle_at_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_open_by_handle_at_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_open_by_handle_at_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_open_by_handle_at_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_open_by_handle_at_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_o_creat_32bit_a20100_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_o_creat_32bit_a20100_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_o_creat_32bit_a20100_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_o_creat_32bit_a20100_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_o_creat_64bit_a20100_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_o_creat_64bit_a20100_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_o_creat_64bit_a20100_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_o_creat_64bit_a20100_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_o_creat_32bit_a20100_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_o_creat_32bit_a20100_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_o_creat_32bit_a20100_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_o_creat_32bit_a20100_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_o_creat_64bit_a20100_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_o_creat_64bit_a20100_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_o_creat_64bit_a20100_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_o_creat_64bit_a20100_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_o_trunc_32bit_a201003_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_o_trunc_32bit_a201003_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_o_trunc_32bit_a201003_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_o_trunc_32bit_a201003_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_o_trunc_64bit_a201003_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_o_trunc_64bit_a201003_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_o_trunc_64bit_a201003_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_o_trunc_64bit_a201003_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_o_trunc_32bit_a201003_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_o_trunc_32bit_a201003_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_o_trunc_32bit_a201003_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_o_trunc_32bit_a201003_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_o_trunc_64bit_a201003_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_o_trunc_64bit_a201003_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_o_trunc_64bit_a201003_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_o_trunc_64bit_a201003_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_order_32bit_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_order_32bit_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_order_64bit_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_order_64bit_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_order_32bit_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="Test order of audit 32bit auditctl eperm rules order" id="oval:ssg-test_arufm_open_by_handle_at_order_32bit_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_order_64bit_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_by_handle_at_order_64bit_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_o_creat_32bit_a20100_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_o_creat_32bit_a20100_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_o_creat_32bit_a20100_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_o_creat_32bit_a20100_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_o_creat_64bit_a20100_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_o_creat_64bit_a20100_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_o_creat_64bit_a20100_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_o_creat_64bit_a20100_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_o_creat_32bit_a20100_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_o_creat_32bit_a20100_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_o_creat_32bit_a20100_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_o_creat_32bit_a20100_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_o_creat_64bit_a20100_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_o_creat_64bit_a20100_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_o_creat_64bit_a20100_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_o_creat_64bit_a20100_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_o_trunc_32bit_a201003_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_o_trunc_32bit_a201003_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_o_trunc_32bit_a201003_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_o_trunc_32bit_a201003_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_o_trunc_64bit_a201003_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_o_trunc_64bit_a201003_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_o_trunc_64bit_a201003_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_o_trunc_64bit_a201003_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_o_trunc_32bit_a201003_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_o_trunc_32bit_a201003_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_o_trunc_32bit_a201003_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_o_trunc_32bit_a201003_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_o_trunc_64bit_a201003_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_o_trunc_64bit_a201003_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_o_trunc_64bit_a201003_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_o_trunc_64bit_a201003_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_order_32bit_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_order_32bit_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_order_32bit_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_order_32bit_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_order_64bit_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_order_64bit_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_order_64bit_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_order_64bit_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_order_32bit_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_order_32bit_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="Test order of audit 32bit auditctl eperm rules order" id="oval:ssg-test_arufm_open_order_32bit_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_order_32bit_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_order_64bit_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_order_64bit_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_open_order_64bit_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_open_order_64bit_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_openat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_openat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_openat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_openat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_openat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_openat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_openat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_openat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_openat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_openat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_openat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_openat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_openat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_openat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_openat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_openat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_o_creat_32bit_a20100_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_o_creat_32bit_a20100_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_o_creat_32bit_a20100_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_o_creat_32bit_a20100_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_o_creat_64bit_a20100_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_o_creat_64bit_a20100_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_o_creat_64bit_a20100_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_o_creat_64bit_a20100_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_o_creat_32bit_a20100_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_o_creat_32bit_a20100_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_o_creat_32bit_a20100_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_o_creat_32bit_a20100_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_o_creat_64bit_a20100_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_o_creat_64bit_a20100_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_o_creat_64bit_a20100_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_o_creat_64bit_a20100_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_o_trunc_32bit_a201003_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_o_trunc_32bit_a201003_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_o_trunc_32bit_a201003_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_o_trunc_32bit_a201003_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_o_trunc_64bit_a201003_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_o_trunc_64bit_a201003_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_o_trunc_64bit_a201003_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_o_trunc_64bit_a201003_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_o_trunc_32bit_a201003_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_o_trunc_32bit_a201003_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_o_trunc_32bit_a201003_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_o_trunc_32bit_a201003_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_o_trunc_64bit_a201003_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_o_trunc_64bit_a201003_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_o_trunc_64bit_a201003_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_o_trunc_64bit_a201003_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_order_32bit_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_order_32bit_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_order_32bit_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_order_32bit_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_order_64bit_eacces_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_order_64bit_eacces_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_order_64bit_eperm_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_order_64bit_eperm_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_order_32bit_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_order_32bit_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="Test order of audit 32bit auditctl eperm rules order" id="oval:ssg-test_arufm_openat_order_32bit_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_order_32bit_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_order_64bit_eacces_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_order_64bit_eacces_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="only_one_exists" comment="defined audit rule must exist" id="oval:ssg-test_arufm_openat_order_64bit_eperm_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_arufm_openat_order_64bit_eperm_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_removexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_removexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_removexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_removexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_removexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_removexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_removexattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_removexattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_removexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_removexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_removexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_removexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_removexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_removexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_removexattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_removexattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_rename_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_rename_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_rename_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_rename_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_rename_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_rename_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_rename_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_rename_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_rename_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_rename_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_rename_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_rename_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_rename_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_rename_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_rename_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_rename_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_renameat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_renameat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_renameat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_renameat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_renameat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_renameat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_renameat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_renameat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_renameat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_renameat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_renameat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_renameat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_renameat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_renameat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_renameat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_renameat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_setxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_setxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_setxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_setxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_setxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_setxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_setxattr_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_setxattr_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_setxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_setxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_setxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_setxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_setxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_setxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_setxattr_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_setxattr_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_truncate_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_truncate_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_truncate_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_truncate_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_truncate_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_truncate_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_truncate_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_truncate_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_truncate_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_truncate_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_truncate_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_truncate_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_truncate_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_truncate_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_truncate_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_truncate_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_unlink_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_unlink_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_unlink_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_unlink_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_unlink_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_unlink_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_unlink_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_unlink_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_unlink_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_unlink_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_unlink_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_unlink_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_unlink_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_unlink_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_unlink_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_unlink_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_unlinkat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_unlinkat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_unlinkat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_unlinkat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_unlinkat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_unlinkat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_unlinkat_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_unlinkat_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eacces" id="oval:ssg-test_32bit_arufm_eacces_unlinkat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eacces_unlinkat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit file eperm" id="oval:ssg-test_32bit_arufm_eperm_unlinkat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_arufm_eperm_unlinkat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eacces" id="oval:ssg-test_64bit_arufm_eacces_unlinkat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eacces_unlinkat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit file eperm" id="oval:ssg-test_64bit_arufm_eperm_unlinkat_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_arufm_eperm_unlinkat_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules group" id="oval:ssg-test_audit_rules_usergroup_modification_group_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_group_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl group" id="oval:ssg-test_audit_rules_usergroup_modification_group_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_group_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules gshadow" id="oval:ssg-test_audit_rules_usergroup_modification_gshadow_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_gshadow_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl gshadow" id="oval:ssg-test_audit_rules_usergroup_modification_gshadow_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_gshadow_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules nsswitch_conf" id="oval:ssg-test_audit_rules_usergroup_modification_nsswitch_conf_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_nsswitch_conf_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl nsswitch_conf" id="oval:ssg-test_audit_rules_usergroup_modification_nsswitch_conf_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_nsswitch_conf_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules opasswd" id="oval:ssg-test_audit_rules_usergroup_modification_opasswd_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_opasswd_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl opasswd" id="oval:ssg-test_audit_rules_usergroup_modification_opasswd_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_opasswd_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules pam_conf" id="oval:ssg-test_audit_rules_usergroup_modification_pam_conf_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_pam_conf_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl pam_conf" id="oval:ssg-test_audit_rules_usergroup_modification_pam_conf_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_pam_conf_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules pam_d" id="oval:ssg-test_audit_rules_usergroup_modification_pamd_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_pamd_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl pam_d" id="oval:ssg-test_audit_rules_usergroup_modification_pamd_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_pamd_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules passwd" id="oval:ssg-test_audit_rules_usergroup_modification_passwd_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_passwd_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl passwd" id="oval:ssg-test_audit_rules_usergroup_modification_passwd_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_passwd_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules shadow" id="oval:ssg-test_audit_rules_usergroup_modification_shadow_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_shadow_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl shadow" id="oval:ssg-test_audit_rules_usergroup_modification_shadow_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_usergroup_modification_shadow_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules cron" id="oval:ssg-test_audit_rules_var_spool_cron_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_var_spool_cron_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl cron" id="oval:ssg-test_audit_rules_var_spool_cron_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_var_spool_cron_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules sudo_log" id="oval:ssg-test_audit_sudo_log_events_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_sudo_log_events_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl sudo_log" id="oval:ssg-test_audit_sudo_log_events_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_sudo_log_events_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of freq setting in the /etc/audit/auditd.conf file" id="oval:ssg-test_auditd_freq:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_auditd_freq:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_freq:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of local_events setting in the /etc/audit/auditd.conf file" id="oval:ssg-test_auditd_local_events:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_auditd_local_events:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_local_events:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of log_format setting in the /etc/audit/auditd.conf file" id="oval:ssg-test_auditd_log_format:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_auditd_log_format:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_log_format:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of write_logs setting in the /etc/audit/auditd.conf file" id="oval:ssg-test_auditd_write_logs:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_auditd_write_logs:obj:1"/>
          <ind:state state_ref="oval:ssg-state_auditd_write_logs:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="tests the absence of write_logs setting in the /etc/audit/auditd.conf file" id="oval:ssg-test_auditd_write_logs_default_not_overriden:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_auditd_write_logs_default_not_overriden:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check that the given object does not exist" id="oval:ssg-test_banner_etc_issue_cis_file_nonempty:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_banner_etc_issue_cis_file_nonempty:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check that the given object does not exist" id="oval:ssg-test_banner_etc_issue_cis:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_banner_etc_issue_cis:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check that the given object does not exist" id="oval:ssg-test_banner_etc_issue_net_cis_file_nonempty:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_banner_etc_issue_net_cis_file_nonempty:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check that the given object does not exist" id="oval:ssg-test_banner_etc_issue_net_cis:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_banner_etc_issue_net_cis:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check that the given object does not exist" id="oval:ssg-test_banner_etc_motd_cis:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_banner_etc_motd_cis:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Tests that cipher@SSH is configured correctly." id="oval:ssg-test_configure_custom_crypto_policy_cis_NO-SSHCBC:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_configure_custom_crypto_policy_cis_NO-SSHCBC:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Tests that cipher@SSH is configured correctly." id="oval:ssg-test_configure_custom_crypto_policy_cis_NO-SSHWEAKCIPHERS:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_configure_custom_crypto_policy_cis_NO-SSHWEAKCIPHERS:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Tests that mac@SSH is configured correctly." id="oval:ssg-test_configure_custom_crypto_policy_cis_NO-SSHWEAKMACS:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_configure_custom_crypto_policy_cis_NO-SSHWEAKMACS:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Tests that mac is configured correctly." id="oval:ssg-test_configure_custom_crypto_policy_cis_NO-WEAKMAC:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_configure_custom_crypto_policy_cis_NO-WEAKMAC:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of AuditBackend setting in the /etc/usbguard/usbguard-daemon.conf file" id="oval:ssg-test_configure_usbguard_auditbackend:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_configure_usbguard_auditbackend:obj:1"/>
          <ind:state state_ref="oval:ssg-state_configure_usbguard_auditbackend:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="The configuration file /etc/usbguard/usbguard-daemon.conf exists for configure_usbguard_auditbackend" id="oval:ssg-test_configure_usbguard_auditbackend_config_file_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_configure_usbguard_auditbackend_config_file:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of ProcessSizeMax setting in the /etc/systemd/coredump.conf file" id="oval:ssg-test_coredump_disable_backtraces:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_coredump_disable_backtraces:obj:1"/>
          <ind:state state_ref="oval:ssg-state_coredump_disable_backtraces:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of ProcessSizeMax setting in the /etc/systemd/coredump.conf.d file" id="oval:ssg-test_coredump_disable_backtraces_config_dir:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_coredump_disable_backtraces_config_dir:obj:1"/>
          <ind:state state_ref="oval:ssg-state_coredump_disable_backtraces_config_dir:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of Storage setting in the /etc/systemd/coredump.conf file" id="oval:ssg-test_coredump_disable_storage:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_coredump_disable_storage:obj:1"/>
          <ind:state state_ref="oval:ssg-state_coredump_disable_storage:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of Storage setting in the /etc/systemd/coredump.conf.d file" id="oval:ssg-test_coredump_disable_storage_config_dir:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_coredump_disable_storage_config_dir:obj:1"/>
          <ind:state state_ref="oval:ssg-state_coredump_disable_storage_config_dir:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Check if /boot/loader/entries/ostree-2.*.conf does not exist" id="oval:ssg-test_coreos_enable_selinux_kernel_argument_file_boot_loader_entries_ostree_2_conf_absent:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_coreos_enable_selinux_kernel_argument_file_boot_loader_entries_ostree_2_conf_absent:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if argument selinux=0 is present in the line starting with 'options ' in /boot/loader/entries/ostree-1.*.conf" id="oval:ssg-test_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_boot_loader_entries_ostree_1_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_boot_loader_entries_ostree_1_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_boot_loader_entries_ostree_1_conf:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if argument selinux=0 is present in the line starting with 'options ' in /boot/loader/entries/ostree-2.*.conf" id="oval:ssg-test_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_boot_loader_entries_ostree_2_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_boot_loader_entries_ostree_2_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_boot_loader_entries_ostree_2_conf:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if argument selinux=0 is present in the line starting with 'BOOT_IMAGE' in /proc/cmdline" id="oval:ssg-test_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_proc_cmdline:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_proc_cmdline:obj:1"/>
          <ind:state state_ref="oval:ssg-state_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_proc_cmdline:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of user-administration-disabled setting in the /etc/dconf/db/local.d/ file" id="oval:ssg-test_dconf_gnome_disable_user_admin:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_dconf_gnome_disable_user_admin:obj:1"/>
          <ind:state state_ref="oval:ssg-state_dconf_gnome_disable_user_admin:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Prevent user from modifying user-administration-disabled" id="oval:ssg-test_prevent_user_user-administration-disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_user-administration-disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of removal-action setting in the /etc/dconf/db/local.d/ file" id="oval:ssg-test_dconf_gnome_lock_screen_on_smartcard_removal:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_dconf_gnome_lock_screen_on_smartcard_removal:obj:1"/>
          <ind:state state_ref="oval:ssg-state_dconf_gnome_lock_screen_on_smartcard_removal:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Prevent user from modifying removal-action" id="oval:ssg-test_prevent_user_removal-action:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_prevent_user_removal-action:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /lib/" id="oval:ssg-test_file_groupownerdir_group_ownership_library_dirs_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerdir_group_ownership_library_dirs_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /lib64/" id="oval:ssg-test_file_groupownerdir_group_ownership_library_dirs_1:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerdir_group_ownership_library_dirs_1:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /usr/lib/" id="oval:ssg-test_file_groupownerdir_group_ownership_library_dirs_2:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerdir_group_ownership_library_dirs_2:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /usr/lib64/" id="oval:ssg-test_file_groupownerdir_group_ownership_library_dirs_3:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerdir_group_ownership_library_dirs_3:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /bin/" id="oval:ssg-test_file_ownerdir_ownership_binary_dirs_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_binary_dirs_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /sbin/" id="oval:ssg-test_file_ownerdir_ownership_binary_dirs_1:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_binary_dirs_1:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /usr/bin/" id="oval:ssg-test_file_ownerdir_ownership_binary_dirs_2:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_binary_dirs_2:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /usr/sbin/" id="oval:ssg-test_file_ownerdir_ownership_binary_dirs_3:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_binary_dirs_3:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /usr/local/bin/" id="oval:ssg-test_file_ownerdir_ownership_binary_dirs_4:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_binary_dirs_4:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /usr/local/sbin/" id="oval:ssg-test_file_ownerdir_ownership_binary_dirs_5:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_binary_dirs_5:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /lib/" id="oval:ssg-test_file_ownerdir_ownership_library_dirs_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_library_dirs_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /lib64/" id="oval:ssg-test_file_ownerdir_ownership_library_dirs_1:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_library_dirs_1:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /usr/lib/" id="oval:ssg-test_file_ownerdir_ownership_library_dirs_2:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_library_dirs_2:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /usr/lib64/" id="oval:ssg-test_file_ownerdir_ownership_library_dirs_3:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_library_dirs_3:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /bin/" id="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /sbin/" id="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_1:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_1:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /usr/bin/" id="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_2:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_2:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /usr/sbin/" id="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_3:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_3:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /usr/local/bin/" id="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_4:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_4:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /usr/local/sbin/" id="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_5:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_5:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /lib/" id="oval:ssg-test_file_permissionsdir_permissions_library_dirs_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_library_dirs_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /lib64/" id="oval:ssg-test_file_permissionsdir_permissions_library_dirs_1:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_library_dirs_1:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /usr/lib/" id="oval:ssg-test_file_permissionsdir_permissions_library_dirs_2:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_library_dirs_2:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /usr/lib64/" id="oval:ssg-test_file_permissionsdir_permissions_library_dirs_3:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_library_dirs_3:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/ipsec.d/" id="oval:ssg-test_file_groupownerdirectory_groupowner_etc_ipsecd_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerdirectory_groupowner_etc_ipsecd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/iptables/" id="oval:ssg-test_file_groupownerdirectory_groupowner_etc_iptables_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerdirectory_groupowner_etc_iptables_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/nftables/" id="oval:ssg-test_file_groupownerdirectory_groupowner_etc_nftables_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerdirectory_groupowner_etc_nftables_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/selinux/" id="oval:ssg-test_file_groupownerdirectory_groupowner_etc_selinux_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerdirectory_groupowner_etc_selinux_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/sudoers.d/" id="oval:ssg-test_file_groupownerdirectory_groupowner_etc_sudoersd_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerdirectory_groupowner_etc_sudoersd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/sysctl.d/" id="oval:ssg-test_file_groupownerdirectory_groupowner_etc_sysctld_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerdirectory_groupowner_etc_sysctld_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/ipsec.d/" id="oval:ssg-test_file_ownerdirectory_owner_etc_ipsecd_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerdirectory_owner_etc_ipsecd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/iptables/" id="oval:ssg-test_file_ownerdirectory_owner_etc_iptables_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerdirectory_owner_etc_iptables_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/nftables/" id="oval:ssg-test_file_ownerdirectory_owner_etc_nftables_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerdirectory_owner_etc_nftables_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/selinux/" id="oval:ssg-test_file_ownerdirectory_owner_etc_selinux_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerdirectory_owner_etc_selinux_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/sudoers.d/" id="oval:ssg-test_file_ownerdirectory_owner_etc_sudoersd_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerdirectory_owner_etc_sudoersd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/sysctl.d/" id="oval:ssg-test_file_ownerdirectory_owner_etc_sysctld_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerdirectory_owner_etc_sysctld_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/ipsec.d/" id="oval:ssg-test_file_permissionsdirectory_permissions_etc_ipsecd_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsdirectory_permissions_etc_ipsecd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/iptables/" id="oval:ssg-test_file_permissionsdirectory_permissions_etc_iptables_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsdirectory_permissions_etc_iptables_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/nftables/" id="oval:ssg-test_file_permissionsdirectory_permissions_etc_nftables_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsdirectory_permissions_etc_nftables_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/selinux/" id="oval:ssg-test_file_permissionsdirectory_permissions_etc_selinux_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsdirectory_permissions_etc_selinux_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/sudoers.d/" id="oval:ssg-test_file_permissionsdirectory_permissions_etc_sudoersd_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsdirectory_permissions_etc_sudoersd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/sysctl.d/" id="oval:ssg-test_file_permissionsdirectory_permissions_etc_sysctld_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsdirectory_permissions_etc_sysctld_0:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of HostbasedAuthentication setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_disable_host_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_disable_host_auth:obj:1"/>
          <ind:state state_ref="oval:ssg-state_disable_host_auth:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of HostbasedAuthentication is present" id="oval:ssg-test_HostbasedAuthentication_present_disable_host_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_disable_host_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="Test that that /etc/at.allow does exist" id="oval:ssg-test_file_at_allow_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_at_allow_exists:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Test that that /etc/at.deny does not exist" id="oval:ssg-test_file_at_deny_not_exist:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_at_deny_not_exist:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /sbin/auditctl" id="oval:ssg-test_file_groupownerfile_audit_tools_group_ownership_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerfile_audit_tools_group_ownership_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /sbin/aureport" id="oval:ssg-test_file_groupownerfile_audit_tools_group_ownership_1:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerfile_audit_tools_group_ownership_1:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /sbin/ausearch" id="oval:ssg-test_file_groupownerfile_audit_tools_group_ownership_2:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerfile_audit_tools_group_ownership_2:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /sbin/autrace" id="oval:ssg-test_file_groupownerfile_audit_tools_group_ownership_3:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerfile_audit_tools_group_ownership_3:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /sbin/auditd" id="oval:ssg-test_file_groupownerfile_audit_tools_group_ownership_4:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerfile_audit_tools_group_ownership_4:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /sbin/rsyslogd" id="oval:ssg-test_file_groupownerfile_audit_tools_group_ownership_5:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerfile_audit_tools_group_ownership_5:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /sbin/augenrules" id="oval:ssg-test_file_groupownerfile_audit_tools_group_ownership_6:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerfile_audit_tools_group_ownership_6:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /sbin/auditctl" id="oval:ssg-test_file_ownerfile_audit_tools_ownership_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerfile_audit_tools_ownership_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /sbin/aureport" id="oval:ssg-test_file_ownerfile_audit_tools_ownership_1:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerfile_audit_tools_ownership_1:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /sbin/ausearch" id="oval:ssg-test_file_ownerfile_audit_tools_ownership_2:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerfile_audit_tools_ownership_2:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /sbin/autrace" id="oval:ssg-test_file_ownerfile_audit_tools_ownership_3:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerfile_audit_tools_ownership_3:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /sbin/auditd" id="oval:ssg-test_file_ownerfile_audit_tools_ownership_4:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerfile_audit_tools_ownership_4:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /sbin/rsyslogd" id="oval:ssg-test_file_ownerfile_audit_tools_ownership_5:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerfile_audit_tools_ownership_5:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /sbin/augenrules" id="oval:ssg-test_file_ownerfile_audit_tools_ownership_6:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownerfile_audit_tools_ownership_6:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /sbin/auditctl" id="oval:ssg-test_file_permissionsfile_audit_tools_permissions_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsfile_audit_tools_permissions_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /sbin/aureport" id="oval:ssg-test_file_permissionsfile_audit_tools_permissions_1:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsfile_audit_tools_permissions_1:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /sbin/ausearch" id="oval:ssg-test_file_permissionsfile_audit_tools_permissions_2:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsfile_audit_tools_permissions_2:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /sbin/autrace" id="oval:ssg-test_file_permissionsfile_audit_tools_permissions_3:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsfile_audit_tools_permissions_3:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /sbin/auditd" id="oval:ssg-test_file_permissionsfile_audit_tools_permissions_4:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsfile_audit_tools_permissions_4:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /sbin/rsyslogd" id="oval:ssg-test_file_permissionsfile_audit_tools_permissions_5:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsfile_audit_tools_permissions_5:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /sbin/augenrules" id="oval:ssg-test_file_permissionsfile_audit_tools_permissions_6:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionsfile_audit_tools_permissions_6:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="Test that that /etc/cron.allow does exist" id="oval:ssg-test_file_cron_allow_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_cron_allow_exists:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Test that that /etc/cron.deny does not exist" id="oval:ssg-test_file_cron_deny_not_exist:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_cron_deny_not_exist:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/at.allow" id="oval:ssg-test_file_groupowner_at_allow_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_at_allow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/group-" id="oval:ssg-test_file_groupowner_backup_etc_group_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_backup_etc_group_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/gshadow-" id="oval:ssg-test_file_groupowner_backup_etc_gshadow_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_backup_etc_gshadow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/passwd-" id="oval:ssg-test_file_groupowner_backup_etc_passwd_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_backup_etc_passwd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/shadow-" id="oval:ssg-test_file_groupowner_backup_etc_shadow_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_backup_etc_shadow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/cron.allow" id="oval:ssg-test_file_groupowner_cron_allow_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_cron_allow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/cron.d/" id="oval:ssg-test_file_groupowner_cron_d_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_cron_d_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/cron.daily/" id="oval:ssg-test_file_groupowner_cron_daily_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_cron_daily_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/cron.hourly/" id="oval:ssg-test_file_groupowner_cron_hourly_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_cron_hourly_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/cron.monthly/" id="oval:ssg-test_file_groupowner_cron_monthly_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_cron_monthly_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/cron.weekly/" id="oval:ssg-test_file_groupowner_cron_weekly_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_cron_weekly_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/cron.yearly/" id="oval:ssg-test_file_groupowner_cron_yearly_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_cron_yearly_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/crontab" id="oval:ssg-test_file_groupowner_crontab_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_crontab_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /boot/efi/EFI/almalinux/grub.cfg" id="oval:ssg-test_file_groupowner_efi_grub2_cfg_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_efi_grub2_cfg_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /boot/efi/EFI/almalinux/user.cfg" id="oval:ssg-test_file_groupowner_efi_user_cfg_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_efi_user_cfg_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/crypttab" id="oval:ssg-test_file_groupowner_etc_crypttab_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_crypttab_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/group" id="oval:ssg-test_file_groupowner_etc_group_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_group_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/gshadow" id="oval:ssg-test_file_groupowner_etc_gshadow_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_gshadow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/ipsec.conf" id="oval:ssg-test_file_groupowner_etc_ipsec_conf_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_ipsec_conf_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/ipsec.secrets" id="oval:ssg-test_file_groupowner_etc_ipsec_secrets_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_ipsec_secrets_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/issue" id="oval:ssg-test_file_groupowner_etc_issue_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_issue_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/issue.net" id="oval:ssg-test_file_groupowner_etc_issue_net_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_issue_net_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/motd" id="oval:ssg-test_file_groupowner_etc_motd_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_motd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/passwd" id="oval:ssg-test_file_groupowner_etc_passwd_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_passwd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/security/opasswd" id="oval:ssg-test_file_groupowner_etc_security_opasswd_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_security_opasswd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/security/opasswd.old" id="oval:ssg-test_file_groupowner_etc_security_opasswd_old_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_security_opasswd_old_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/sestatus.conf" id="oval:ssg-test_file_groupowner_etc_sestatus_conf_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_sestatus_conf_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/shadow" id="oval:ssg-test_file_groupowner_etc_shadow_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_shadow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/shells" id="oval:ssg-test_file_groupowner_etc_shells_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_shells_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/sudoers" id="oval:ssg-test_file_groupowner_etc_sudoers_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_sudoers_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/sysconfig/sshd" id="oval:ssg-test_file_groupowner_etc_sysconfig_sshd_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_etc_sysconfig_sshd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /boot/grub2/grub.cfg" id="oval:ssg-test_file_groupowner_grub2_cfg_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_grub2_cfg_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/ssh/sshd_config" id="oval:ssg-test_file_groupowner_sshd_config_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_sshd_config_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /boot/" id="oval:ssg-test_file_groupowner_systemmap_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_systemmap_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /boot/grub2/user.cfg" id="oval:ssg-test_file_groupowner_user_cfg_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_user_cfg_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /var/log/" id="oval:ssg-test_file_groupowner_var_log_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_var_log_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /var/log/messages" id="oval:ssg-test_file_groupowner_var_log_messages_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_var_log_messages_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /var/log/syslog" id="oval:ssg-test_file_groupowner_var_log_syslog_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupowner_var_log_syslog_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /sbin/auditctl" id="oval:ssg-test_file_groupownership_audit_binaries_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownership_audit_binaries_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /sbin/aureport" id="oval:ssg-test_file_groupownership_audit_binaries_1:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownership_audit_binaries_1:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /sbin/ausearch" id="oval:ssg-test_file_groupownership_audit_binaries_2:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownership_audit_binaries_2:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /sbin/autrace" id="oval:ssg-test_file_groupownership_audit_binaries_3:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownership_audit_binaries_3:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /sbin/auditd" id="oval:ssg-test_file_groupownership_audit_binaries_4:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownership_audit_binaries_4:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /sbin/audispd" id="oval:ssg-test_file_groupownership_audit_binaries_5:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownership_audit_binaries_5:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /sbin/augenrules" id="oval:ssg-test_file_groupownership_audit_binaries_6:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownership_audit_binaries_6:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/audit/" id="oval:ssg-test_file_groupownership_audit_configuration_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownership_audit_configuration_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/audit/rules.d/" id="oval:ssg-test_file_groupownership_audit_configuration_1:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownership_audit_configuration_1:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/ssh/" id="oval:ssg-test_file_groupownership_sshd_private_key_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownership_sshd_private_key_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /etc/ssh/" id="oval:ssg-test_file_groupownership_sshd_pub_key_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownership_sshd_pub_key_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/at.allow" id="oval:ssg-test_file_owner_at_allow_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_at_allow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/group-" id="oval:ssg-test_file_owner_backup_etc_group_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_backup_etc_group_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/gshadow-" id="oval:ssg-test_file_owner_backup_etc_gshadow_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_backup_etc_gshadow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/passwd-" id="oval:ssg-test_file_owner_backup_etc_passwd_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_backup_etc_passwd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/shadow-" id="oval:ssg-test_file_owner_backup_etc_shadow_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_backup_etc_shadow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/cron.allow" id="oval:ssg-test_file_owner_cron_allow_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_cron_allow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/cron.d/" id="oval:ssg-test_file_owner_cron_d_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_cron_d_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/cron.daily/" id="oval:ssg-test_file_owner_cron_daily_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_cron_daily_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/cron.hourly/" id="oval:ssg-test_file_owner_cron_hourly_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_cron_hourly_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/cron.monthly/" id="oval:ssg-test_file_owner_cron_monthly_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_cron_monthly_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/cron.weekly/" id="oval:ssg-test_file_owner_cron_weekly_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_cron_weekly_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/cron.yearly/" id="oval:ssg-test_file_owner_cron_yearly_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_cron_yearly_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/crontab" id="oval:ssg-test_file_owner_crontab_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_crontab_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /boot/efi/EFI/almalinux/grub.cfg" id="oval:ssg-test_file_owner_efi_grub2_cfg_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_efi_grub2_cfg_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /boot/efi/EFI/almalinux/user.cfg" id="oval:ssg-test_file_owner_efi_user_cfg_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_efi_user_cfg_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/chrony.keys" id="oval:ssg-test_file_owner_etc_chrony_keys_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_etc_chrony_keys_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/crypttab" id="oval:ssg-test_file_owner_etc_crypttab_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_etc_crypttab_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/group" id="oval:ssg-test_file_owner_etc_group_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_etc_group_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/gshadow" id="oval:ssg-test_file_owner_etc_gshadow_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_etc_gshadow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/ipsec.conf" id="oval:ssg-test_file_owner_etc_ipsec_conf_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_etc_ipsec_conf_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/ipsec.secrets" id="oval:ssg-test_file_owner_etc_ipsec_secrets_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_etc_ipsec_secrets_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/issue" id="oval:ssg-test_file_owner_etc_issue_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_etc_issue_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/issue.net" id="oval:ssg-test_file_owner_etc_issue_net_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_etc_issue_net_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/motd" id="oval:ssg-test_file_owner_etc_motd_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_etc_motd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/passwd" id="oval:ssg-test_file_owner_etc_passwd_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_etc_passwd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/security/opasswd" id="oval:ssg-test_file_owner_etc_security_opasswd_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_etc_security_opasswd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/security/opasswd.old" id="oval:ssg-test_file_owner_etc_security_opasswd_old_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_etc_security_opasswd_old_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/sestatus.conf" id="oval:ssg-test_file_owner_etc_sestatus_conf_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_etc_sestatus_conf_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/shadow" id="oval:ssg-test_file_owner_etc_shadow_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_etc_shadow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/shells" id="oval:ssg-test_file_owner_etc_shells_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_etc_shells_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/sudoers" id="oval:ssg-test_file_owner_etc_sudoers_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_etc_sudoers_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/sysconfig/sshd" id="oval:ssg-test_file_owner_etc_sysconfig_sshd_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_etc_sysconfig_sshd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /boot/grub2/grub.cfg" id="oval:ssg-test_file_owner_grub2_cfg_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_grub2_cfg_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/ssh/sshd_config" id="oval:ssg-test_file_owner_sshd_config_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_sshd_config_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /boot/" id="oval:ssg-test_file_owner_systemmap_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_systemmap_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /boot/grub2/user.cfg" id="oval:ssg-test_file_owner_user_cfg_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_user_cfg_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /var/log/" id="oval:ssg-test_file_owner_var_log_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_var_log_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /var/log/messages" id="oval:ssg-test_file_owner_var_log_messages_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_var_log_messages_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /var/log/syslog" id="oval:ssg-test_file_owner_var_log_syslog_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_owner_var_log_syslog_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /sbin/auditctl" id="oval:ssg-test_file_ownership_audit_binaries_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_audit_binaries_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /sbin/aureport" id="oval:ssg-test_file_ownership_audit_binaries_1:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_audit_binaries_1:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /sbin/ausearch" id="oval:ssg-test_file_ownership_audit_binaries_2:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_audit_binaries_2:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /sbin/autrace" id="oval:ssg-test_file_ownership_audit_binaries_3:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_audit_binaries_3:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /sbin/auditd" id="oval:ssg-test_file_ownership_audit_binaries_4:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_audit_binaries_4:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /sbin/audispd" id="oval:ssg-test_file_ownership_audit_binaries_5:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_audit_binaries_5:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /sbin/augenrules" id="oval:ssg-test_file_ownership_audit_binaries_6:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_audit_binaries_6:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/audit/" id="oval:ssg-test_file_ownership_audit_configuration_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_audit_configuration_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/audit/rules.d/" id="oval:ssg-test_file_ownership_audit_configuration_1:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_audit_configuration_1:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /lib/" id="oval:ssg-test_file_ownership_library_dirs_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_library_dirs_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /lib64/" id="oval:ssg-test_file_ownership_library_dirs_1:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_library_dirs_1:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /usr/lib/" id="oval:ssg-test_file_ownership_library_dirs_2:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_library_dirs_2:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /usr/lib64/" id="oval:ssg-test_file_ownership_library_dirs_3:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_library_dirs_3:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/ssh/" id="oval:ssg-test_file_ownership_sshd_private_key_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_sshd_private_key_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing user ownership of /etc/ssh/" id="oval:ssg-test_file_ownership_sshd_pub_key_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_ownership_sshd_pub_key_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/at.allow" id="oval:ssg-test_file_permissions_at_allow_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_at_allow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /sbin/auditctl" id="oval:ssg-test_file_permissions_audit_binaries_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_audit_binaries_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /sbin/aureport" id="oval:ssg-test_file_permissions_audit_binaries_1:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_audit_binaries_1:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /sbin/ausearch" id="oval:ssg-test_file_permissions_audit_binaries_2:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_audit_binaries_2:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /sbin/autrace" id="oval:ssg-test_file_permissions_audit_binaries_3:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_audit_binaries_3:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /sbin/auditd" id="oval:ssg-test_file_permissions_audit_binaries_4:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_audit_binaries_4:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /sbin/audispd" id="oval:ssg-test_file_permissions_audit_binaries_5:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_audit_binaries_5:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /sbin/augenrules" id="oval:ssg-test_file_permissions_audit_binaries_6:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_audit_binaries_6:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/audit/" id="oval:ssg-test_file_permissions_audit_configuration_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_audit_configuration_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/audit/rules.d/" id="oval:ssg-test_file_permissions_audit_configuration_1:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_audit_configuration_1:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/group-" id="oval:ssg-test_file_permissions_backup_etc_group_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_backup_etc_group_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/gshadow-" id="oval:ssg-test_file_permissions_backup_etc_gshadow_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_backup_etc_gshadow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/passwd-" id="oval:ssg-test_file_permissions_backup_etc_passwd_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_backup_etc_passwd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/shadow-" id="oval:ssg-test_file_permissions_backup_etc_shadow_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_backup_etc_shadow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/cron.allow" id="oval:ssg-test_file_permissions_cron_allow_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_cron_allow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/cron.d/" id="oval:ssg-test_file_permissions_cron_d_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_cron_d_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/cron.daily/" id="oval:ssg-test_file_permissions_cron_daily_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_cron_daily_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/cron.hourly/" id="oval:ssg-test_file_permissions_cron_hourly_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_cron_hourly_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/cron.monthly/" id="oval:ssg-test_file_permissions_cron_monthly_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_cron_monthly_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/cron.weekly/" id="oval:ssg-test_file_permissions_cron_weekly_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_cron_weekly_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/cron.yearly/" id="oval:ssg-test_file_permissions_cron_yearly_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_cron_yearly_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/crontab" id="oval:ssg-test_file_permissions_crontab_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_crontab_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /boot/efi/EFI/almalinux/grub.cfg" id="oval:ssg-test_file_permissions_efi_grub2_cfg_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_efi_grub2_cfg_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /boot/efi/EFI/almalinux/user.cfg" id="oval:ssg-test_file_permissions_efi_user_cfg_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_efi_user_cfg_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/audit/auditd.conf" id="oval:ssg-test_file_permissions_etc_audit_auditd_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_audit_auditd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/audit/rules.d/" id="oval:ssg-test_file_permissions_etc_audit_rulesd_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_audit_rulesd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/chrony.keys" id="oval:ssg-test_file_permissions_etc_chrony_keys_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_chrony_keys_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/crypttab" id="oval:ssg-test_file_permissions_etc_crypttab_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_crypttab_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/group" id="oval:ssg-test_file_permissions_etc_group_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_group_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/gshadow" id="oval:ssg-test_file_permissions_etc_gshadow_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_gshadow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/ipsec.conf" id="oval:ssg-test_file_permissions_etc_ipsec_conf_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_ipsec_conf_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/ipsec.secrets" id="oval:ssg-test_file_permissions_etc_ipsec_secrets_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_ipsec_secrets_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/issue" id="oval:ssg-test_file_permissions_etc_issue_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_issue_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/issue.net" id="oval:ssg-test_file_permissions_etc_issue_net_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_issue_net_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/motd" id="oval:ssg-test_file_permissions_etc_motd_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_motd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/passwd" id="oval:ssg-test_file_permissions_etc_passwd_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_passwd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/security/opasswd" id="oval:ssg-test_file_permissions_etc_security_opasswd_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_security_opasswd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/security/opasswd.old" id="oval:ssg-test_file_permissions_etc_security_opasswd_old_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_security_opasswd_old_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/sestatus.conf" id="oval:ssg-test_file_permissions_etc_sestatus_conf_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_sestatus_conf_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/shadow" id="oval:ssg-test_file_permissions_etc_shadow_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_shadow_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/shells" id="oval:ssg-test_file_permissions_etc_shells_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_shells_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/sudoers" id="oval:ssg-test_file_permissions_etc_sudoers_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_sudoers_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/sysconfig/sshd" id="oval:ssg-test_file_permissions_etc_sysconfig_sshd_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_etc_sysconfig_sshd_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /boot/grub2/grub.cfg" id="oval:ssg-test_file_permissions_grub2_cfg_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_grub2_cfg_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /lib/" id="oval:ssg-test_file_permissions_library_dirs_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_library_dirs_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /lib64/" id="oval:ssg-test_file_permissions_library_dirs_1:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_library_dirs_1:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /usr/lib/" id="oval:ssg-test_file_permissions_library_dirs_2:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_library_dirs_2:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /usr/lib64/" id="oval:ssg-test_file_permissions_library_dirs_3:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_library_dirs_3:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/ssh/sshd_config" id="oval:ssg-test_file_permissions_sshd_config_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_sshd_config_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /etc/ssh/" id="oval:ssg-test_file_permissions_sshd_pub_key_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_sshd_pub_key_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /usr/bin/sudo" id="oval:ssg-test_file_permissions_sudo_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_sudo_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /boot/" id="oval:ssg-test_file_permissions_systemmap_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_systemmap_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /boot/grub2/user.cfg" id="oval:ssg-test_file_permissions_user_cfg_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_user_cfg_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /var/log/" id="oval:ssg-test_file_permissions_var_log_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_var_log_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /var/log/messages" id="oval:ssg-test_file_permissions_var_log_messages_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_var_log_messages_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /var/log/syslog" id="oval:ssg-test_file_permissions_var_log_syslog_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissions_var_log_syslog_0:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of FirewallBackend setting in the /etc/firewalld/firewalld.conf file" id="oval:ssg-test_firewalld-backend:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_firewalld-backend:obj:1"/>
          <ind:state state_ref="oval:ssg-state_firewalld-backend:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for audit=1 in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_audit_argument:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_audit_argument:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_audit_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for audit=1 in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_audit_argument_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_audit_argument_default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_audit_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for audit_backlog_limit in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_audit_backlog_limit_argument:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_audit_backlog_limit_argument:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_audit_backlog_limit_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for audit_backlog_limit in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_audit_backlog_limit_argument_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_audit_backlog_limit_argument_default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_audit_backlog_limit_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for iommu=force in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_iommu_argument:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_iommu_argument:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_iommu_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for iommu=force in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_iommu_argument_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_iommu_argument_default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_iommu_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for init_on_free=1 in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_init_on_free_argument:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_init_on_free_argument:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_init_on_free_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for init_on_free=1 in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_init_on_free_argument_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_init_on_free_argument_default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_init_on_free_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for ipv6.disable=1 in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_ipv6_disable_argument:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_ipv6_disable_argument:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_ipv6_disable_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for ipv6.disable=1 in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_ipv6_disable_argument_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_ipv6_disable_argument_default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_ipv6_disable_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for l1tf in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_l1tf_argument:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_l1tf_argument:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_l1tf_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for l1tf in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_l1tf_argument_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_l1tf_argument_default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_l1tf_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for mce=0 in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_mce_argument:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_mce_argument:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_mce_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for mce=0 in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_mce_argument_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_mce_argument_default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_mce_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for absence nosmap in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_nosmap_argument_absent:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_nosmap_argument_absent:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for absence nosmap in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_nosmap_argument_absent_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_nosmap_argument_absent_default:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for absence nosmep in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_nosmep_argument_absent:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_nosmep_argument_absent:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for absence nosmep in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_nosmep_argument_absent_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_nosmep_argument_absent_default:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for nousb in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_nousb_argument:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_nousb_argument:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_nousb_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for nousb in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_nousb_argument_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_nousb_argument_default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_nousb_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for page_poison=1 in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_page_poison_argument:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_page_poison_argument:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_page_poison_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for page_poison=1 in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_page_poison_argument_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_page_poison_argument_default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_page_poison_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for pti=on in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_pti_argument:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_pti_argument:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_pti_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for pti=on in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_pti_argument_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_pti_argument_default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_pti_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for rng_core.default_quality in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_rng_core_default_quality_argument:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_rng_core_default_quality_argument:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_rng_core_default_quality_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for rng_core.default_quality in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_rng_core_default_quality_argument_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_rng_core_default_quality_argument_default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_rng_core_default_quality_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for slab_nomerge=yes in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_slab_nomerge_argument:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_slab_nomerge_argument:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_slab_nomerge_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for slab_nomerge=yes in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_slab_nomerge_argument_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_slab_nomerge_argument_default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_slab_nomerge_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for slub_debug in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_slub_debug_argument:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_slub_debug_argument:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_slub_debug_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for slub_debug in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_slub_debug_argument_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_slub_debug_argument_default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_slub_debug_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for spec_store_bypass_disable in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_spec_store_bypass_disable_argument:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_spec_store_bypass_disable_argument:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_spec_store_bypass_disable_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for spec_store_bypass_disable in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_spec_store_bypass_disable_argument_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_spec_store_bypass_disable_argument_default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_spec_store_bypass_disable_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for spectre_v2=on in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_spectre_v2_argument:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_spectre_v2_argument:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_spectre_v2_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for spectre_v2=on in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_spectre_v2_argument_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_spectre_v2_argument_default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_spectre_v2_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for absence systemd.debug-shell in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_systemd_debug_shell_argument_absent:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_systemd_debug_shell_argument_absent:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for absence systemd.debug-shell in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_systemd_debug_shell_argument_absent_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_systemd_debug_shell_argument_absent_default:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for vsyscall=none in /etc/default/grub via GRUB_CMDLINE_LINUX" id="oval:ssg-test_grub2_vsyscall_argument:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_vsyscall_argument:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_vsyscall_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check for vsyscall=none in /etc/default/grub via GRUB_CMDLINE_LINUX_DEFAULT" id="oval:ssg-test_grub2_vsyscall_argument_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_vsyscall_argument_default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_vsyscall_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package openssl-pkcs11 is installed" id="oval:ssg-test_package_openssl-pkcs11_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_openssl-pkcs11_installed:obj:1"/>
        </linux:rpminfo_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of Compress setting in the /etc/systemd/journald.conf file" id="oval:ssg-test_journald_compress:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_journald_compress:obj:1"/>
          <ind:state state_ref="oval:ssg-state_journald_compress:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of ForwardToSyslog setting in the /etc/systemd/journald.conf file" id="oval:ssg-test_journald_disable_forward_to_syslog:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_journald_disable_forward_to_syslog:obj:1"/>
          <ind:state state_ref="oval:ssg-state_journald_disable_forward_to_syslog:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of ForwardToSyslog setting in the /etc/systemd/journald.conf file" id="oval:ssg-test_journald_forward_to_syslog:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_journald_forward_to_syslog:obj:1"/>
          <ind:state state_ref="oval:ssg-state_journald_forward_to_syslog:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of Storage setting in the /etc/systemd/journald.conf file" id="oval:ssg-test_journald_storage:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_journald_storage:obj:1"/>
          <ind:state state_ref="oval:ssg-state_journald_storage:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_ACPI_CUSTOM_METHOD=n" id="oval:ssg-test_kernel_config_acpi_custom_method:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_acpi_custom_method:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_acpi_custom_method:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_ACPI_CUSTOM_METHOD" id="oval:ssg-test_kernel_config_acpi_custom_method_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_acpi_custom_method:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_acpi_custom_method_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_acpi_custom_method_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_acpi_custom_method:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_ARM64_SW_TTBR0_PAN=y" id="oval:ssg-test_kernel_config_arm64_sw_ttbr0_pan:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_arm64_sw_ttbr0_pan:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_arm64_sw_ttbr0_pan:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_arm64_sw_ttbr0_pan_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_arm64_sw_ttbr0_pan_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_arm64_sw_ttbr0_pan:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_BINFMT_MISC=n" id="oval:ssg-test_kernel_config_binfmt_misc:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_binfmt_misc:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_binfmt_misc:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_BINFMT_MISC" id="oval:ssg-test_kernel_config_binfmt_misc_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_binfmt_misc:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_binfmt_misc_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_binfmt_misc_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_binfmt_misc:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_BUG=y" id="oval:ssg-test_kernel_config_bug:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_bug:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_bug:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_bug_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_bug_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_bug:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_BUG_ON_DATA_CORRUPTION=y" id="oval:ssg-test_kernel_config_bug_on_data_corruption:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_bug_on_data_corruption:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_bug_on_data_corruption:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_bug_on_data_corruption_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_bug_on_data_corruption_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_bug_on_data_corruption:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_COMPAT_BRK=n" id="oval:ssg-test_kernel_config_compat_brk:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_compat_brk:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_compat_brk:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_COMPAT_BRK" id="oval:ssg-test_kernel_config_compat_brk_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_compat_brk:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_compat_brk_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_compat_brk_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_compat_brk:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_COMPAT_VDSO=n" id="oval:ssg-test_kernel_config_compat_vdso:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_compat_vdso:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_compat_vdso:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_COMPAT_VDSO" id="oval:ssg-test_kernel_config_compat_vdso_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_compat_vdso:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_compat_vdso_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_compat_vdso_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_compat_vdso:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_DEBUG_CREDENTIALS=y" id="oval:ssg-test_kernel_config_debug_credentials:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_debug_credentials:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_debug_credentials:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_debug_credentials_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_debug_credentials_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_debug_credentials:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_DEBUG_FS=n" id="oval:ssg-test_kernel_config_debug_fs:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_debug_fs:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_debug_fs:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_DEBUG_FS" id="oval:ssg-test_kernel_config_debug_fs_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_debug_fs:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_debug_fs_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_debug_fs_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_debug_fs:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_DEBUG_LIST=y" id="oval:ssg-test_kernel_config_debug_list:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_debug_list:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_debug_list:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_debug_list_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_debug_list_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_debug_list:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_DEBUG_NOTIFIERS=y" id="oval:ssg-test_kernel_config_debug_notifiers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_debug_notifiers:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_debug_notifiers:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_debug_notifiers_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_debug_notifiers_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_debug_notifiers:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_DEBUG_SG=y" id="oval:ssg-test_kernel_config_debug_sg:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_debug_sg:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_debug_sg:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_debug_sg_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_debug_sg_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_debug_sg:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_DEBUG_WX=y" id="oval:ssg-test_kernel_config_debug_wx:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_debug_wx:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_debug_wx:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_debug_wx_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_debug_wx_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_debug_wx:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_DEVKMEM=n" id="oval:ssg-test_kernel_config_devkmem:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_devkmem:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_devkmem:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_DEVKMEM" id="oval:ssg-test_kernel_config_devkmem_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_devkmem:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_devkmem_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_devkmem_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_devkmem:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_FORTIFY_SOURCE=y" id="oval:ssg-test_kernel_config_fortify_source:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_fortify_source:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_fortify_source:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_fortify_source_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_fortify_source_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_fortify_source:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_GCC_PLUGIN_LATENT_ENTROPY=y" id="oval:ssg-test_kernel_config_gcc_plugin_latent_entropy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_gcc_plugin_latent_entropy:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_gcc_plugin_latent_entropy:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_gcc_plugin_latent_entropy_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_gcc_plugin_latent_entropy_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_gcc_plugin_latent_entropy:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_GCC_PLUGIN_STRUCTLEAK=y" id="oval:ssg-test_kernel_config_gcc_plugin_structleak:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_gcc_plugin_structleak:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_gcc_plugin_structleak:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_gcc_plugin_structleak_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_gcc_plugin_structleak_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_gcc_plugin_structleak:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_HARDENED_USERCOPY=y" id="oval:ssg-test_kernel_config_hardened_usercopy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_hardened_usercopy:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_hardened_usercopy:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_hardened_usercopy_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_hardened_usercopy_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_hardened_usercopy:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_HARDENED_USERCOPY_FALLBACK=n" id="oval:ssg-test_kernel_config_hardened_usercopy_fallback:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_hardened_usercopy_fallback:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_hardened_usercopy_fallback:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_HARDENED_USERCOPY_FALLBACK" id="oval:ssg-test_kernel_config_hardened_usercopy_fallback_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_hardened_usercopy_fallback:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_hardened_usercopy_fallback_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_hardened_usercopy_fallback_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_hardened_usercopy_fallback:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_HIBERNATION=n" id="oval:ssg-test_kernel_config_hibernation:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_hibernation:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_hibernation:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_HIBERNATION" id="oval:ssg-test_kernel_config_hibernation_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_hibernation:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_hibernation_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_hibernation_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_hibernation:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_IA32_EMULATION=n" id="oval:ssg-test_kernel_config_ia32_emulation:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_ia32_emulation:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_ia32_emulation:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_IA32_EMULATION" id="oval:ssg-test_kernel_config_ia32_emulation_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_ia32_emulation:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_ia32_emulation_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_ia32_emulation_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_ia32_emulation:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_IPV6=n" id="oval:ssg-test_kernel_config_ipv6:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_ipv6:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_ipv6:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_IPV6" id="oval:ssg-test_kernel_config_ipv6_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_ipv6:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_ipv6_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_ipv6_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_ipv6:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_KEXEC=n" id="oval:ssg-test_kernel_config_kexec:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_kexec:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_kexec:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_KEXEC" id="oval:ssg-test_kernel_config_kexec_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_kexec:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_kexec_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_kexec_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_kexec:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_LEGACY_PTYS=n" id="oval:ssg-test_kernel_config_legacy_ptys:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_legacy_ptys:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_legacy_ptys:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_LEGACY_PTYS" id="oval:ssg-test_kernel_config_legacy_ptys_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_legacy_ptys:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_legacy_ptys_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_legacy_ptys_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_legacy_ptys:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_LEGACY_VSYSCALL_EMULATE=n" id="oval:ssg-test_kernel_config_legacy_vsyscall_emulate:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_legacy_vsyscall_emulate:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_legacy_vsyscall_emulate:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_LEGACY_VSYSCALL_EMULATE" id="oval:ssg-test_kernel_config_legacy_vsyscall_emulate_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_legacy_vsyscall_emulate:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_legacy_vsyscall_emulate_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_legacy_vsyscall_emulate_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_legacy_vsyscall_emulate:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_LEGACY_VSYSCALL_NONE=y" id="oval:ssg-test_kernel_config_legacy_vsyscall_none:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_legacy_vsyscall_none:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_legacy_vsyscall_none:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_legacy_vsyscall_none_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_legacy_vsyscall_none_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_legacy_vsyscall_none:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_MODIFY_LDT_SYSCALL=n" id="oval:ssg-test_kernel_config_modify_ldt_syscall:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_modify_ldt_syscall:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_modify_ldt_syscall:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_MODIFY_LDT_SYSCALL" id="oval:ssg-test_kernel_config_modify_ldt_syscall_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_modify_ldt_syscall:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_modify_ldt_syscall_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_modify_ldt_syscall_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_modify_ldt_syscall:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_MODULE_SIG=y" id="oval:ssg-test_kernel_config_module_sig:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_module_sig:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_module_sig:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_module_sig_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_module_sig_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_module_sig:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_MODULE_SIG_ALL=y" id="oval:ssg-test_kernel_config_module_sig_all:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_module_sig_all:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_module_sig_all:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_module_sig_all_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_module_sig_all_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_module_sig_all:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_MODULE_SIG_FORCE=y" id="oval:ssg-test_kernel_config_module_sig_force:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_module_sig_force:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_module_sig_force:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_module_sig_force_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_module_sig_force_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_module_sig_force:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_MODULE_SIG_HASH according to var_kernel_config_module_sig_hash" id="oval:ssg-test_kernel_config_module_sig_hash:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_module_sig_hash:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_module_sig_hash:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_module_sig_hash_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_module_sig_hash_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_module_sig_hash:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_MODULE_SIG_KEY according to var_kernel_config_module_sig_key" id="oval:ssg-test_kernel_config_module_sig_key:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_module_sig_key:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_module_sig_key:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_module_sig_key_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_module_sig_key_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_module_sig_key:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_MODULE_SIG_SHA512=y" id="oval:ssg-test_kernel_config_module_sig_sha512:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_module_sig_sha512:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_module_sig_sha512:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_module_sig_sha512_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_module_sig_sha512_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_module_sig_sha512:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_PAGE_POISONING=y" id="oval:ssg-test_kernel_config_page_poisoning:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_page_poisoning:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_page_poisoning:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_page_poisoning_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_page_poisoning_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_page_poisoning:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_PAGE_POISONING_NO_SANITY=y" id="oval:ssg-test_kernel_config_page_poisoning_no_sanity:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_page_poisoning_no_sanity:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_page_poisoning_no_sanity:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_page_poisoning_no_sanity_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_page_poisoning_no_sanity_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_page_poisoning_no_sanity:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_PAGE_POISONING_ZERO=y" id="oval:ssg-test_kernel_config_page_poisoning_zero:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_page_poisoning_zero:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_page_poisoning_zero:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_page_poisoning_zero_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_page_poisoning_zero_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_page_poisoning_zero:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_PAGE_TABLE_ISOLATION=y" id="oval:ssg-test_kernel_config_page_table_isolation:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_page_table_isolation:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_page_table_isolation:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_page_table_isolation_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_page_table_isolation_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_page_table_isolation:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_PANIC_ON_OOPS=y" id="oval:ssg-test_kernel_config_panic_on_oops:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_panic_on_oops:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_panic_on_oops:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_panic_on_oops_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_panic_on_oops_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_panic_on_oops:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_PANIC_TIMEOUT according to var_kernel_config_panic_timeout" id="oval:ssg-test_kernel_config_panic_timeout:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_panic_timeout:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_panic_timeout:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_panic_timeout_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_panic_timeout_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_panic_timeout:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_PROC_KCORE=n" id="oval:ssg-test_kernel_config_proc_kcore:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_proc_kcore:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_proc_kcore:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_PROC_KCORE" id="oval:ssg-test_kernel_config_proc_kcore_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_proc_kcore:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_proc_kcore_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_proc_kcore_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_proc_kcore:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_RANDOMIZE_BASE=y" id="oval:ssg-test_kernel_config_randomize_base:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_randomize_base:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_randomize_base:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_randomize_base_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_randomize_base_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_randomize_base:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_RANDOMIZE_MEMORY=y" id="oval:ssg-test_kernel_config_randomize_memory:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_randomize_memory:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_randomize_memory:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_randomize_memory_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_randomize_memory_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_randomize_memory:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_REFCOUNT_FULL=y" id="oval:ssg-test_kernel_config_refcount_full:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_refcount_full:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_refcount_full:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_refcount_full_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_refcount_full_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_refcount_full:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_RETPOLINE=y" id="oval:ssg-test_kernel_config_retpoline:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_retpoline:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_retpoline:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_retpoline_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_retpoline_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_retpoline:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_SCHED_STACK_END_CHECK=y" id="oval:ssg-test_kernel_config_sched_stack_end_check:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_sched_stack_end_check:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_sched_stack_end_check:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_sched_stack_end_check_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_sched_stack_end_check_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_sched_stack_end_check:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_SECCOMP=y" id="oval:ssg-test_kernel_config_seccomp:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_seccomp:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_seccomp:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_seccomp_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_seccomp_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_seccomp:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_SECCOMP_FILTER=y" id="oval:ssg-test_kernel_config_seccomp_filter:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_seccomp_filter:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_seccomp_filter:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_seccomp_filter_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_seccomp_filter_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_seccomp_filter:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_SECURITY=y" id="oval:ssg-test_kernel_config_security:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_security:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_security:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_security_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_security_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_security:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_SECURITY_DMESG_RESTRICT=y" id="oval:ssg-test_kernel_config_security_dmesg_restrict:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_security_dmesg_restrict:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_security_dmesg_restrict:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_security_dmesg_restrict_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_security_dmesg_restrict_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_security_dmesg_restrict:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_SECURITY_WRITABLE_HOOKS=n" id="oval:ssg-test_kernel_config_security_writable_hooks:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_security_writable_hooks:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_security_writable_hooks:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_SECURITY_WRITABLE_HOOKS" id="oval:ssg-test_kernel_config_security_writable_hooks_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_security_writable_hooks:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_security_writable_hooks_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_security_writable_hooks_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_security_writable_hooks:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_SECURITY_YAMA=y" id="oval:ssg-test_kernel_config_security_yama:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_security_yama:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_security_yama:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_security_yama_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_security_yama_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_security_yama:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_SLAB_FREELIST_HARDENED=y" id="oval:ssg-test_kernel_config_slab_freelist_hardened:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_slab_freelist_hardened:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_slab_freelist_hardened:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_slab_freelist_hardened_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_slab_freelist_hardened_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_slab_freelist_hardened:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_SLAB_FREELIST_RANDOM=y" id="oval:ssg-test_kernel_config_slab_freelist_random:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_slab_freelist_random:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_slab_freelist_random:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_slab_freelist_random_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_slab_freelist_random_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_slab_freelist_random:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_SLAB_MERGE_DEFAULT=n" id="oval:ssg-test_kernel_config_slab_merge_default:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_slab_merge_default:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_slab_merge_default:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_SLAB_MERGE_DEFAULT" id="oval:ssg-test_kernel_config_slab_merge_default_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_slab_merge_default:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_slab_merge_default_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_slab_merge_default_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_slab_merge_default:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_SLUB_DEBUG=y" id="oval:ssg-test_kernel_config_slub_debug:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_slub_debug:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_slub_debug:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_slub_debug_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_slub_debug_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_slub_debug:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_STACKPROTECTOR=y" id="oval:ssg-test_kernel_config_stackprotector:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_stackprotector:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_stackprotector:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_stackprotector_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_stackprotector_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_stackprotector:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_STACKPROTECTOR_STRONG=y" id="oval:ssg-test_kernel_config_stackprotector_strong:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_stackprotector_strong:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_stackprotector_strong:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_stackprotector_strong_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_stackprotector_strong_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_stackprotector_strong:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_STRICT_KERNEL_RWX=y" id="oval:ssg-test_kernel_config_strict_kernel_rwx:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_strict_kernel_rwx:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_strict_kernel_rwx:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_strict_kernel_rwx_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_strict_kernel_rwx_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_strict_kernel_rwx:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_STRICT_MODULE_RWX=y" id="oval:ssg-test_kernel_config_strict_module_rwx:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_strict_module_rwx:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_strict_module_rwx:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_strict_module_rwx_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_strict_module_rwx_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_strict_module_rwx:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_SYN_COOKIES=y" id="oval:ssg-test_kernel_config_syn_cookies:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_syn_cookies:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_syn_cookies:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_syn_cookies_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_syn_cookies_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_syn_cookies:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_UNMAP_KERNEL_AT_EL0=y" id="oval:ssg-test_kernel_config_unmap_kernel_at_el0:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_unmap_kernel_at_el0:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_unmap_kernel_at_el0:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_unmap_kernel_at_el0_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_unmap_kernel_at_el0_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_unmap_kernel_at_el0:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_VMAP_STACK=y" id="oval:ssg-test_kernel_config_vmap_stack:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_vmap_stack:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_vmap_stack:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_vmap_stack_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_vmap_stack_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_vmap_stack:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="Check /boot/config-.* files for CONFIG_X86_VSYSCALL_EMULATION=n" id="oval:ssg-test_kernel_config_x86_vsyscall_emulation:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_x86_vsyscall_emulation:obj:1"/>
          <ind:state state_ref="oval:ssg-state_kernel_config_x86_vsyscall_emulation:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="Check /boot/config-.* files for absence of CONFIG_X86_VSYSCALL_EMULATION" id="oval:ssg-test_kernel_config_x86_vsyscall_emulation_absence:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_kernel_config_x86_vsyscall_emulation:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" check_existence="all_exist" comment="Check if all installed kernels are compliant" id="oval:ssg-test_all_kernels_config_x86_vsyscall_emulation_compliant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_kernel_config_x86_vsyscall_emulation_count:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_kernel_config_x86_vsyscall_emulation:ste:1"/>
        </ind:variable_test>
        <ind:textfilecontent54_test check="all" comment="kernel module atm disabled" id="oval:ssg-test_kernmod_atm_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_atm_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module atm disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_atm_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_atm_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module bluetooth disabled" id="oval:ssg-test_kernmod_bluetooth_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_bluetooth_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module bluetooth disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_bluetooth_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_bluetooth_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module can disabled" id="oval:ssg-test_kernmod_can_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_can_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module can disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_can_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_can_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module cfg80211 disabled" id="oval:ssg-test_kernmod_cfg80211_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_cfg80211_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module cfg80211 disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_cfg80211_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_cfg80211_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module cramfs disabled" id="oval:ssg-test_kernmod_cramfs_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_cramfs_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module cramfs disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_cramfs_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_cramfs_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module dccp disabled" id="oval:ssg-test_kernmod_dccp_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_dccp_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module dccp disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_dccp_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_dccp_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module firewire-core disabled" id="oval:ssg-test_kernmod_firewire-core_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_firewire-core_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module firewire-core disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_firewire-core_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_firewire-core_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module freevxfs disabled" id="oval:ssg-test_kernmod_freevxfs_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_freevxfs_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module freevxfs disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_freevxfs_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_freevxfs_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module hfs disabled" id="oval:ssg-test_kernmod_hfs_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_hfs_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module hfs disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_hfs_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_hfs_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module hfsplus disabled" id="oval:ssg-test_kernmod_hfsplus_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_hfsplus_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module hfsplus disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_hfsplus_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_hfsplus_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module iwlmvm disabled" id="oval:ssg-test_kernmod_iwlmvm_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_iwlmvm_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module iwlmvm disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_iwlmvm_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_iwlmvm_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module iwlwifi disabled" id="oval:ssg-test_kernmod_iwlwifi_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_iwlwifi_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module iwlwifi disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_iwlwifi_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_iwlwifi_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module jffs2 disabled" id="oval:ssg-test_kernmod_jffs2_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_jffs2_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module jffs2 disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_jffs2_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_jffs2_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module mac80211 disabled" id="oval:ssg-test_kernmod_mac80211_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_mac80211_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module mac80211 disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_mac80211_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_mac80211_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module overlayfs disabled" id="oval:ssg-test_kernmod_overlayfs_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_overlayfs_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module overlayfs disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_overlayfs_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_overlayfs_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module rds disabled" id="oval:ssg-test_kernmod_rds_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_rds_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module rds disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_rds_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_rds_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module sctp disabled" id="oval:ssg-test_kernmod_sctp_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_sctp_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module sctp disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_sctp_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_sctp_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module squashfs disabled" id="oval:ssg-test_kernmod_squashfs_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_squashfs_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module squashfs disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_squashfs_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_squashfs_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module tipc disabled" id="oval:ssg-test_kernmod_tipc_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_tipc_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module tipc disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_tipc_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_tipc_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module udf disabled" id="oval:ssg-test_kernmod_udf_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_udf_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module udf disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_udf_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_udf_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module usb-storage disabled" id="oval:ssg-test_kernmod_usb-storage_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_usb-storage_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module usb-storage disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_usb-storage_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_usb-storage_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module uvcvideo disabled" id="oval:ssg-test_kernmod_uvcvideo_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_uvcvideo_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module uvcvideo disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_uvcvideo_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_uvcvideo_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module vfat disabled" id="oval:ssg-test_kernmod_vfat_disabled:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_vfat_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="kernel module vfat disabled in /etc/modprobe.conf" id="oval:ssg-test_kernmod_vfat_modprobeconf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_kernmod_vfat_modprobeconf:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nosuid on /boot/efi " id="oval:ssg-test_boot_efi_partition_nosuid_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_boot_efi_partition_nosuid_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_boot_efi_partition_nosuid_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nosuid on /boot/efi  in /etc/fstab" id="oval:ssg-test_boot_efi_partition_nosuid_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_boot_efi_partition_nosuid_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_boot_efi_partition_nosuid_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/boot/efi exists" id="oval:ssg-test_boot_efi_partition_nosuid_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_boot_efi_partition_nosuid_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/boot/efi exists in /etc/fstab" id="oval:ssg-test_boot_efi_partition_nosuid_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_boot_efi_partition_nosuid_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="noauto on /boot " id="oval:ssg-test_boot_partition_noauto_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_boot_partition_noauto_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_boot_partition_noauto_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="noauto on /boot  in /etc/fstab" id="oval:ssg-test_boot_partition_noauto_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_boot_partition_noauto_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_boot_partition_noauto_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/boot exists" id="oval:ssg-test_boot_partition_noauto_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_boot_partition_noauto_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/boot exists in /etc/fstab" id="oval:ssg-test_boot_partition_noauto_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_boot_partition_noauto_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nodev on /boot " id="oval:ssg-test_boot_partition_nodev_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_boot_partition_nodev_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_boot_partition_nodev_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nodev on /boot  in /etc/fstab" id="oval:ssg-test_boot_partition_nodev_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_boot_partition_nodev_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_boot_partition_nodev_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/boot exists" id="oval:ssg-test_boot_partition_nodev_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_boot_partition_nodev_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/boot exists in /etc/fstab" id="oval:ssg-test_boot_partition_nodev_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_boot_partition_nodev_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="noexec on /boot " id="oval:ssg-test_boot_partition_noexec_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_boot_partition_noexec_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_boot_partition_noexec_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="noexec on /boot  in /etc/fstab" id="oval:ssg-test_boot_partition_noexec_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_boot_partition_noexec_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_boot_partition_noexec_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/boot exists" id="oval:ssg-test_boot_partition_noexec_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_boot_partition_noexec_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/boot exists in /etc/fstab" id="oval:ssg-test_boot_partition_noexec_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_boot_partition_noexec_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nosuid on /boot " id="oval:ssg-test_boot_partition_nosuid_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_boot_partition_nosuid_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_boot_partition_nosuid_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nosuid on /boot  in /etc/fstab" id="oval:ssg-test_boot_partition_nosuid_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_boot_partition_nosuid_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_boot_partition_nosuid_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/boot exists" id="oval:ssg-test_boot_partition_nosuid_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_boot_partition_nosuid_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/boot exists in /etc/fstab" id="oval:ssg-test_boot_partition_nosuid_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_boot_partition_nosuid_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nodev on /dev/shm " id="oval:ssg-test_dev_shm_partition_nodev_expected:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_dev_shm_partition_nodev_expected:obj:1"/>
          <linux:state state_ref="oval:ssg-state_dev_shm_partition_nodev_expected:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nodev on /dev/shm  in /etc/fstab" id="oval:ssg-test_dev_shm_partition_nodev_expected_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_dev_shm_partition_nodev_expected_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_dev_shm_partition_nodev_expected_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/dev/shm exists" id="oval:ssg-test_dev_shm_partition_nodev_expected_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_dev_shm_partition_nodev_expected:obj:1"/>
        </linux:partition_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="noexec on /dev/shm " id="oval:ssg-test_dev_shm_partition_noexec_expected:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_dev_shm_partition_noexec_expected:obj:1"/>
          <linux:state state_ref="oval:ssg-state_dev_shm_partition_noexec_expected:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="noexec on /dev/shm  in /etc/fstab" id="oval:ssg-test_dev_shm_partition_noexec_expected_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_dev_shm_partition_noexec_expected_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_dev_shm_partition_noexec_expected_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/dev/shm exists" id="oval:ssg-test_dev_shm_partition_noexec_expected_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_dev_shm_partition_noexec_expected:obj:1"/>
        </linux:partition_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nosuid on /dev/shm " id="oval:ssg-test_dev_shm_partition_nosuid_expected:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_dev_shm_partition_nosuid_expected:obj:1"/>
          <linux:state state_ref="oval:ssg-state_dev_shm_partition_nosuid_expected:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nosuid on /dev/shm  in /etc/fstab" id="oval:ssg-test_dev_shm_partition_nosuid_expected_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_dev_shm_partition_nosuid_expected_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_dev_shm_partition_nosuid_expected_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/dev/shm exists" id="oval:ssg-test_dev_shm_partition_nosuid_expected_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_dev_shm_partition_nosuid_expected:obj:1"/>
        </linux:partition_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="grpquota on /home " id="oval:ssg-test_home_partition_grpquota_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_home_partition_grpquota_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_home_partition_grpquota_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="grpquota on /home  in /etc/fstab" id="oval:ssg-test_home_partition_grpquota_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_home_partition_grpquota_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_home_partition_grpquota_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/home exists" id="oval:ssg-test_home_partition_grpquota_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_home_partition_grpquota_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/home exists in /etc/fstab" id="oval:ssg-test_home_partition_grpquota_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_home_partition_grpquota_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nodev on /home " id="oval:ssg-test_home_partition_nodev_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_home_partition_nodev_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_home_partition_nodev_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nodev on /home  in /etc/fstab" id="oval:ssg-test_home_partition_nodev_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_home_partition_nodev_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_home_partition_nodev_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/home exists" id="oval:ssg-test_home_partition_nodev_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_home_partition_nodev_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/home exists in /etc/fstab" id="oval:ssg-test_home_partition_nodev_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_home_partition_nodev_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="noexec on /home " id="oval:ssg-test_home_partition_noexec_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_home_partition_noexec_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_home_partition_noexec_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="noexec on /home  in /etc/fstab" id="oval:ssg-test_home_partition_noexec_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_home_partition_noexec_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_home_partition_noexec_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/home exists" id="oval:ssg-test_home_partition_noexec_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_home_partition_noexec_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/home exists in /etc/fstab" id="oval:ssg-test_home_partition_noexec_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_home_partition_noexec_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nosuid on /home " id="oval:ssg-test_home_partition_nosuid_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_home_partition_nosuid_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_home_partition_nosuid_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nosuid on /home  in /etc/fstab" id="oval:ssg-test_home_partition_nosuid_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_home_partition_nosuid_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_home_partition_nosuid_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/home exists" id="oval:ssg-test_home_partition_nosuid_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_home_partition_nosuid_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/home exists in /etc/fstab" id="oval:ssg-test_home_partition_nosuid_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_home_partition_nosuid_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="usrquota on /home " id="oval:ssg-test_home_partition_usrquota_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_home_partition_usrquota_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_home_partition_usrquota_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="usrquota on /home  in /etc/fstab" id="oval:ssg-test_home_partition_usrquota_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_home_partition_usrquota_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_home_partition_usrquota_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/home exists" id="oval:ssg-test_home_partition_usrquota_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_home_partition_usrquota_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/home exists in /etc/fstab" id="oval:ssg-test_home_partition_usrquota_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_home_partition_usrquota_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="all nfs has sec_krb5_krb5i_krb5p" id="oval:ssg-test_nfs_sec_krb5_krb5i_krb5p_etc_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_nfs_sec_krb5_krb5i_krb5p_etc_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_remote_filesystem_sec_krb5_krb5i_krb5p:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="all nfs has nodev" id="oval:ssg-test_nfs_nodev_etc_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_nfs_nodev_etc_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_remote_filesystem_nodev:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="'nodev' mount option used for at least one CD / DVD drive alternative names in /etc/fstab" id="oval:ssg-test_nodev_etc_fstab_cd_dvd_drive:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_nodev_etc_fstab_cd_dvd_drive:obj:1"/>
          <ind:state state_ref="oval:ssg-state_nodev_etc_fstab_cd_dvd_drive:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="at least one" check_existence="all_exist" comment="Check if removable partition is configured with 'nodev' mount option in /etc/fstab" id="oval:ssg-test_nodev_etc_fstab_not_cd_dvd_drive:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_nodev_etc_fstab_not_cd_dvd_drive:obj:1"/>
          <ind:state state_ref="oval:ssg-state_nodev_etc_fstab_not_cd_dvd_drive:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="all nfs has noexec" id="oval:ssg-test_nfs_noexec_etc_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_nfs_noexec_etc_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_remote_filesystem_noexec:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="'noexec' mount option used for at least one CD / DVD drive alternative names in /etc/fstab" id="oval:ssg-test_noexec_etc_fstab_cd_dvd_drive:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_noexec_etc_fstab_cd_dvd_drive:obj:1"/>
          <ind:state state_ref="oval:ssg-state_noexec_etc_fstab_cd_dvd_drive:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="at least one" check_existence="all_exist" comment="Check if removable partition is configured with 'noexec' mount option in /etc/fstab" id="oval:ssg-test_noexec_etc_fstab_not_cd_dvd_drive:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_noexec_etc_fstab_not_cd_dvd_drive:obj:1"/>
          <ind:state state_ref="oval:ssg-state_noexec_etc_fstab_not_cd_dvd_drive:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="all nfs has nosuid" id="oval:ssg-test_nfs_nosuid_etc_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_nfs_nosuid_etc_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_remote_filesystem_nosuid:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="'nosuid' mount option used for at least one CD / DVD drive alternative names in /etc/fstab" id="oval:ssg-test_nosuid_etc_fstab_cd_dvd_drive:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_nosuid_etc_fstab_cd_dvd_drive:obj:1"/>
          <ind:state state_ref="oval:ssg-state_nosuid_etc_fstab_cd_dvd_drive:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="at least one" check_existence="all_exist" comment="Check if removable partition is configured with 'nosuid' mount option in /etc/fstab" id="oval:ssg-test_nosuid_etc_fstab_not_cd_dvd_drive:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_nosuid_etc_fstab_not_cd_dvd_drive:obj:1"/>
          <ind:state state_ref="oval:ssg-state_nosuid_etc_fstab_not_cd_dvd_drive:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nosuid on /opt " id="oval:ssg-test_opt_partition_nosuid_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_opt_partition_nosuid_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_opt_partition_nosuid_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nosuid on /opt  in /etc/fstab" id="oval:ssg-test_opt_partition_nosuid_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_opt_partition_nosuid_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_opt_partition_nosuid_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/opt exists" id="oval:ssg-test_opt_partition_nosuid_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_opt_partition_nosuid_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/opt exists in /etc/fstab" id="oval:ssg-test_opt_partition_nosuid_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_opt_partition_nosuid_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="hidepid on /proc " id="oval:ssg-test_proc_partition_hidepid_expected:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_proc_partition_hidepid_expected:obj:1"/>
          <linux:state state_ref="oval:ssg-state_proc_partition_hidepid_expected:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="hidepid on /proc  in /etc/fstab" id="oval:ssg-test_proc_partition_hidepid_expected_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_proc_partition_hidepid_expected_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_proc_partition_hidepid_expected_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/proc exists" id="oval:ssg-test_proc_partition_hidepid_expected_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_proc_partition_hidepid_expected:obj:1"/>
        </linux:partition_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nosuid on /srv " id="oval:ssg-test_srv_partition_nosuid_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_srv_partition_nosuid_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_srv_partition_nosuid_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nosuid on /srv  in /etc/fstab" id="oval:ssg-test_srv_partition_nosuid_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_srv_partition_nosuid_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_srv_partition_nosuid_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/srv exists" id="oval:ssg-test_srv_partition_nosuid_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_srv_partition_nosuid_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/srv exists in /etc/fstab" id="oval:ssg-test_srv_partition_nosuid_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_srv_partition_nosuid_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nodev on /tmp " id="oval:ssg-test_tmp_partition_nodev_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_tmp_partition_nodev_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_tmp_partition_nodev_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nodev on /tmp  in /etc/fstab" id="oval:ssg-test_tmp_partition_nodev_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_tmp_partition_nodev_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_tmp_partition_nodev_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/tmp exists" id="oval:ssg-test_tmp_partition_nodev_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_tmp_partition_nodev_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/tmp exists in /etc/fstab" id="oval:ssg-test_tmp_partition_nodev_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_tmp_partition_nodev_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="noexec on /tmp " id="oval:ssg-test_tmp_partition_noexec_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_tmp_partition_noexec_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_tmp_partition_noexec_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="noexec on /tmp  in /etc/fstab" id="oval:ssg-test_tmp_partition_noexec_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_tmp_partition_noexec_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_tmp_partition_noexec_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/tmp exists" id="oval:ssg-test_tmp_partition_noexec_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_tmp_partition_noexec_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/tmp exists in /etc/fstab" id="oval:ssg-test_tmp_partition_noexec_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_tmp_partition_noexec_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nosuid on /tmp " id="oval:ssg-test_tmp_partition_nosuid_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_tmp_partition_nosuid_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_tmp_partition_nosuid_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nosuid on /tmp  in /etc/fstab" id="oval:ssg-test_tmp_partition_nosuid_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_tmp_partition_nosuid_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_tmp_partition_nosuid_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/tmp exists" id="oval:ssg-test_tmp_partition_nosuid_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_tmp_partition_nosuid_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/tmp exists in /etc/fstab" id="oval:ssg-test_tmp_partition_nosuid_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_tmp_partition_nosuid_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nodev on /var/log/audit " id="oval:ssg-test_var_log_audit_partition_nodev_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_var_log_audit_partition_nodev_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_var_log_audit_partition_nodev_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nodev on /var/log/audit  in /etc/fstab" id="oval:ssg-test_var_log_audit_partition_nodev_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_log_audit_partition_nodev_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_log_audit_partition_nodev_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/var/log/audit exists" id="oval:ssg-test_var_log_audit_partition_nodev_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_var_log_audit_partition_nodev_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/var/log/audit exists in /etc/fstab" id="oval:ssg-test_var_log_audit_partition_nodev_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_log_audit_partition_nodev_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="noexec on /var/log/audit " id="oval:ssg-test_var_log_audit_partition_noexec_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_var_log_audit_partition_noexec_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_var_log_audit_partition_noexec_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="noexec on /var/log/audit  in /etc/fstab" id="oval:ssg-test_var_log_audit_partition_noexec_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_log_audit_partition_noexec_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_log_audit_partition_noexec_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/var/log/audit exists" id="oval:ssg-test_var_log_audit_partition_noexec_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_var_log_audit_partition_noexec_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/var/log/audit exists in /etc/fstab" id="oval:ssg-test_var_log_audit_partition_noexec_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_log_audit_partition_noexec_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nosuid on /var/log/audit " id="oval:ssg-test_var_log_audit_partition_nosuid_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_var_log_audit_partition_nosuid_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_var_log_audit_partition_nosuid_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nosuid on /var/log/audit  in /etc/fstab" id="oval:ssg-test_var_log_audit_partition_nosuid_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_log_audit_partition_nosuid_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_log_audit_partition_nosuid_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/var/log/audit exists" id="oval:ssg-test_var_log_audit_partition_nosuid_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_var_log_audit_partition_nosuid_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/var/log/audit exists in /etc/fstab" id="oval:ssg-test_var_log_audit_partition_nosuid_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_log_audit_partition_nosuid_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nodev on /var/log " id="oval:ssg-test_var_log_partition_nodev_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_var_log_partition_nodev_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_var_log_partition_nodev_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nodev on /var/log  in /etc/fstab" id="oval:ssg-test_var_log_partition_nodev_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_log_partition_nodev_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_log_partition_nodev_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/var/log exists" id="oval:ssg-test_var_log_partition_nodev_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_var_log_partition_nodev_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/var/log exists in /etc/fstab" id="oval:ssg-test_var_log_partition_nodev_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_log_partition_nodev_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="noexec on /var/log " id="oval:ssg-test_var_log_partition_noexec_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_var_log_partition_noexec_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_var_log_partition_noexec_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="noexec on /var/log  in /etc/fstab" id="oval:ssg-test_var_log_partition_noexec_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_log_partition_noexec_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_log_partition_noexec_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/var/log exists" id="oval:ssg-test_var_log_partition_noexec_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_var_log_partition_noexec_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/var/log exists in /etc/fstab" id="oval:ssg-test_var_log_partition_noexec_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_log_partition_noexec_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nosuid on /var/log " id="oval:ssg-test_var_log_partition_nosuid_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_var_log_partition_nosuid_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_var_log_partition_nosuid_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nosuid on /var/log  in /etc/fstab" id="oval:ssg-test_var_log_partition_nosuid_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_log_partition_nosuid_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_log_partition_nosuid_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/var/log exists" id="oval:ssg-test_var_log_partition_nosuid_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_var_log_partition_nosuid_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/var/log exists in /etc/fstab" id="oval:ssg-test_var_log_partition_nosuid_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_log_partition_nosuid_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nodev on /var " id="oval:ssg-test_var_partition_nodev_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_var_partition_nodev_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_var_partition_nodev_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nodev on /var  in /etc/fstab" id="oval:ssg-test_var_partition_nodev_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_partition_nodev_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_partition_nodev_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/var exists" id="oval:ssg-test_var_partition_nodev_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_var_partition_nodev_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/var exists in /etc/fstab" id="oval:ssg-test_var_partition_nodev_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_partition_nodev_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="noexec on /var " id="oval:ssg-test_var_partition_noexec_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_var_partition_noexec_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_var_partition_noexec_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="noexec on /var  in /etc/fstab" id="oval:ssg-test_var_partition_noexec_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_partition_noexec_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_partition_noexec_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/var exists" id="oval:ssg-test_var_partition_noexec_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_var_partition_noexec_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/var exists in /etc/fstab" id="oval:ssg-test_var_partition_noexec_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_partition_noexec_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nosuid on /var " id="oval:ssg-test_var_partition_nosuid_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_var_partition_nosuid_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_var_partition_nosuid_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nosuid on /var  in /etc/fstab" id="oval:ssg-test_var_partition_nosuid_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_partition_nosuid_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_partition_nosuid_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/var exists" id="oval:ssg-test_var_partition_nosuid_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_var_partition_nosuid_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/var exists in /etc/fstab" id="oval:ssg-test_var_partition_nosuid_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_partition_nosuid_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nodev on /var/tmp " id="oval:ssg-test_var_tmp_partition_nodev_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_var_tmp_partition_nodev_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_var_tmp_partition_nodev_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nodev on /var/tmp  in /etc/fstab" id="oval:ssg-test_var_tmp_partition_nodev_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_tmp_partition_nodev_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_tmp_partition_nodev_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/var/tmp exists" id="oval:ssg-test_var_tmp_partition_nodev_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_var_tmp_partition_nodev_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/var/tmp exists in /etc/fstab" id="oval:ssg-test_var_tmp_partition_nodev_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_tmp_partition_nodev_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="noexec on /var/tmp " id="oval:ssg-test_var_tmp_partition_noexec_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_var_tmp_partition_noexec_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_var_tmp_partition_noexec_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="noexec on /var/tmp  in /etc/fstab" id="oval:ssg-test_var_tmp_partition_noexec_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_tmp_partition_noexec_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_tmp_partition_noexec_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/var/tmp exists" id="oval:ssg-test_var_tmp_partition_noexec_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_var_tmp_partition_noexec_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/var/tmp exists in /etc/fstab" id="oval:ssg-test_var_tmp_partition_noexec_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_tmp_partition_noexec_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="nosuid on /var/tmp " id="oval:ssg-test_var_tmp_partition_nosuid_optional:tst:1" state_operator="AND" version="2">
          <linux:object object_ref="oval:ssg-object_var_tmp_partition_nosuid_optional:obj:1"/>
          <linux:state state_ref="oval:ssg-state_var_tmp_partition_nosuid_optional:ste:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="nosuid on /var/tmp  in /etc/fstab" id="oval:ssg-test_var_tmp_partition_nosuid_optional_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_tmp_partition_nosuid_optional_in_fstab:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_tmp_partition_nosuid_optional_in_fstab:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/var/tmp exists" id="oval:ssg-test_var_tmp_partition_nosuid_optional_exist:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_var_tmp_partition_nosuid_optional:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/var/tmp exists in /etc/fstab" id="oval:ssg-test_var_tmp_partition_nosuid_optional_exist_in_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_tmp_partition_nosuid_optional_in_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package 389-ds-base is removed" id="oval:ssg-test_package_389-ds-base_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_389-ds-base_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package MFEhiplsm is installed" id="oval:ssg-test_package_MFEhiplsm_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_MFEhiplsm_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package abrt-addon-ccpp is removed" id="oval:ssg-test_package_abrt-addon-ccpp_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_abrt-addon-ccpp_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package abrt-addon-kerneloops is removed" id="oval:ssg-test_package_abrt-addon-kerneloops_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_abrt-addon-kerneloops_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package abrt-cli is removed" id="oval:ssg-test_package_abrt-cli_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_abrt-cli_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package abrt-plugin-logger is removed" id="oval:ssg-test_package_abrt-plugin-logger_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_abrt-plugin-logger_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package abrt-plugin-rhtsupport is removed" id="oval:ssg-test_package_abrt-plugin-rhtsupport_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_abrt-plugin-rhtsupport_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package abrt-plugin-sosreport is removed" id="oval:ssg-test_package_abrt-plugin-sosreport_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_abrt-plugin-sosreport_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package abrt is removed" id="oval:ssg-test_package_abrt_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_abrt_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package aide is installed" id="oval:ssg-test_package_aide_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_aide_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package audispd-plugins is installed" id="oval:ssg-test_package_audispd-plugins_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_audispd-plugins_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package audit-audispd-plugins is installed" id="oval:ssg-test_package_audit-audispd-plugins_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_audit-audispd-plugins_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package audit-libs is installed" id="oval:ssg-test_package_audit-libs_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_audit-libs_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package audit is installed" id="oval:ssg-test_package_audit_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_audit_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package authselect is installed" id="oval:ssg-test_package_authselect_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_authselect_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package avahi-autoipd is removed" id="oval:ssg-test_package_avahi-autoipd_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_avahi-autoipd_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package avahi is removed" id="oval:ssg-test_package_avahi_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_avahi_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package bind is removed" id="oval:ssg-test_package_bind_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_bind_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package binutils is installed" id="oval:ssg-test_package_binutils_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_binutils_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package chrony is installed" id="oval:ssg-test_package_chrony_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_chrony_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package cron is installed" id="oval:ssg-test_package_cron_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_cron_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package crypto-policies is installed" id="oval:ssg-test_package_crypto-policies_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_crypto-policies_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package cups is removed" id="oval:ssg-test_package_cups_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_cups_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package cyrus-imapd is removed" id="oval:ssg-test_package_cyrus-imapd_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_cyrus-imapd_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package dconf is installed" id="oval:ssg-test_package_dconf_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_dconf_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package dhcp is removed" id="oval:ssg-test_package_dhcp_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_dhcp_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package dnf-automatic is installed" id="oval:ssg-test_package_dnf-automatic_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_dnf-automatic_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package dnf-plugin-subscription-manager is installed" id="oval:ssg-test_package_dnf-plugin-subscription-manager_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_dnf-plugin-subscription-manager_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package dnsmasq is removed" id="oval:ssg-test_package_dnsmasq_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_dnsmasq_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package dovecot is removed" id="oval:ssg-test_package_dovecot_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_dovecot_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package fapolicyd is installed" id="oval:ssg-test_package_fapolicyd_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_fapolicyd_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package firewalld is installed" id="oval:ssg-test_package_firewalld_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_firewalld_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package freeradius is removed" id="oval:ssg-test_package_freeradius_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_freeradius_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package ftp is removed" id="oval:ssg-test_package_ftp_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_ftp_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package gdm is installed" id="oval:ssg-test_package_gdm_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_gdm_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package gdm is removed" id="oval:ssg-test_package_gdm_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_gdm_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package geolite2-city is removed" id="oval:ssg-test_package_geolite2-city_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_geolite2-city_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package geolite2-country is removed" id="oval:ssg-test_package_geolite2-country_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_geolite2-country_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package gnutls-utils is installed" id="oval:ssg-test_package_gnutls-utils_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_gnutls-utils_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package gssproxy is removed" id="oval:ssg-test_package_gssproxy_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_gssproxy_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package httpd is removed" id="oval:ssg-test_package_httpd_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_httpd_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package inetutils-telnetd is removed" id="oval:ssg-test_package_inetutils-telnetd_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_inetutils-telnetd_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package iprutils is removed" id="oval:ssg-test_package_iprutils_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_iprutils_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package iptables-services is installed" id="oval:ssg-test_package_iptables-services_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_iptables-services_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package iptables-services is removed" id="oval:ssg-test_package_iptables-services_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_iptables-services_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package iptables is installed" id="oval:ssg-test_package_iptables_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_iptables_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package krb5-server is removed" id="oval:ssg-test_package_krb5-server_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_krb5-server_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package krb5-workstation is removed" id="oval:ssg-test_package_krb5-workstation_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_krb5-workstation_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package libcap-ng-utils is installed" id="oval:ssg-test_package_libcap-ng-utils_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_libcap-ng-utils_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package libreport-plugin-logger is removed" id="oval:ssg-test_package_libreport-plugin-logger_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_libreport-plugin-logger_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package libreport-plugin-rhtsupport is removed" id="oval:ssg-test_package_libreport-plugin-rhtsupport_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_libreport-plugin-rhtsupport_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package libreswan is installed" id="oval:ssg-test_package_libreswan_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_libreswan_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package libselinux is installed" id="oval:ssg-test_package_libselinux_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_libselinux_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package logrotate is installed" id="oval:ssg-test_package_logrotate_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_logrotate_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package mailx is installed" id="oval:ssg-test_package_mailx_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_mailx_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package McAfeeTP is installed" id="oval:ssg-test_package_McAfeeTP_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_McAfeeTP_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package mcstrans is removed" id="oval:ssg-test_package_mcstrans_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_mcstrans_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package net-snmp is removed" id="oval:ssg-test_package_net-snmp_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_net-snmp_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package nfs-utils is removed" id="oval:ssg-test_package_nfs-utils_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_nfs-utils_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package nftables is installed" id="oval:ssg-test_package_nftables_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_nftables_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package nginx is removed" id="oval:ssg-test_package_nginx_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_nginx_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package nis is removed" id="oval:ssg-test_package_nis_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_nis_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package nss-tools is installed" id="oval:ssg-test_package_nss-tools_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_nss-tools_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package ntp is installed" id="oval:ssg-test_package_ntp_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_ntp_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package ntpdate is removed" id="oval:ssg-test_package_ntpdate_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_ntpdate_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package openldap-clients is removed" id="oval:ssg-test_package_openldap-clients_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_openldap-clients_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package openldap-servers is removed" id="oval:ssg-test_package_openldap-servers_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_openldap-servers_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package opensc is installed" id="oval:ssg-test_package_opensc_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_opensc_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package openscap-scanner is installed" id="oval:ssg-test_package_openscap-scanner_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_openscap-scanner_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package openssh-clients is installed" id="oval:ssg-test_package_openssh-clients_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_openssh-clients_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package openssh-server is installed" id="oval:ssg-test_package_openssh-server_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_openssh-server_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package openssh-server is removed" id="oval:ssg-test_package_openssh-server_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_openssh-server_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package pam is installed" id="oval:ssg-test_package_pam_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_pam_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package libpwquality is installed" id="oval:ssg-test_package_libpwquality_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_libpwquality_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package pcsc-lite is installed" id="oval:ssg-test_package_pcsc-lite_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_pcsc-lite_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package pigz is removed" id="oval:ssg-test_package_pigz_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_pigz_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package policycoreutils-python-utils is installed" id="oval:ssg-test_package_policycoreutils-python-utils_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_policycoreutils-python-utils_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package policycoreutils is installed" id="oval:ssg-test_package_policycoreutils_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_policycoreutils_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package postfix is installed" id="oval:ssg-test_package_postfix_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_postfix_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package psacct is installed" id="oval:ssg-test_package_psacct_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_psacct_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package python3-abrt-addon is removed" id="oval:ssg-test_package_python3-abrt-addon_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_python3-abrt-addon_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package quagga is removed" id="oval:ssg-test_package_quagga_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_quagga_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package rear is installed" id="oval:ssg-test_package_rear_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_rear_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package rng-tools is installed" id="oval:ssg-test_package_rng-tools_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_rng-tools_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package rpcbind is removed" id="oval:ssg-test_package_rpcbind_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_rpcbind_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package rsh-server is removed" id="oval:ssg-test_package_rsh-server_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_rsh-server_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package rsh is removed" id="oval:ssg-test_package_rsh_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_rsh_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package rsync is removed" id="oval:ssg-test_package_rsync_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_rsync_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package rsyslog-gnutls is installed" id="oval:ssg-test_package_rsyslog-gnutls_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_rsyslog-gnutls_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package rsyslog is installed" id="oval:ssg-test_package_rsyslog_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_rsyslog_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package samba-common is installed" id="oval:ssg-test_package_samba-common_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_samba-common_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package samba-common is removed" id="oval:ssg-test_package_samba-common_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_samba-common_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package samba is removed" id="oval:ssg-test_package_samba_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_samba_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package scap-security-guide is installed" id="oval:ssg-test_package_scap-security-guide_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_scap-security-guide_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package sendmail is removed" id="oval:ssg-test_package_sendmail_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_sendmail_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package setroubleshoot-plugins is removed" id="oval:ssg-test_package_setroubleshoot-plugins_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_setroubleshoot-plugins_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package setroubleshoot-server is removed" id="oval:ssg-test_package_setroubleshoot-server_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_setroubleshoot-server_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package setroubleshoot is removed" id="oval:ssg-test_package_setroubleshoot_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_setroubleshoot_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package squid is removed" id="oval:ssg-test_package_squid_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_squid_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package sssd-ipa is installed" id="oval:ssg-test_package_sssd-ipa_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_sssd-ipa_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package sssd is installed" id="oval:ssg-test_package_sssd_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_sssd_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package subscription-manager is installed" id="oval:ssg-test_package_subscription-manager_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_subscription-manager_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package sudo is installed" id="oval:ssg-test_package_sudo_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_sudo_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package syslog-ng is installed" id="oval:ssg-test_package_syslog-ng_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_syslog-ng_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package systemd-journal-remote is installed" id="oval:ssg-test_package_systemd-journal-remote_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_systemd-journal-remote_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package talk-server is removed" id="oval:ssg-test_package_talk-server_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_talk-server_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package talk is removed" id="oval:ssg-test_package_talk_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_talk_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package tar is installed" id="oval:ssg-test_package_tar_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_tar_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package telnet-server is removed" id="oval:ssg-test_package_telnet-server_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_telnet-server_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package telnet is removed" id="oval:ssg-test_package_telnet_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_telnet_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package telnetd-ssl is removed" id="oval:ssg-test_package_telnetd-ssl_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_telnetd-ssl_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package telnetd is removed" id="oval:ssg-test_package_telnetd_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_telnetd_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package tftp-server is removed" id="oval:ssg-test_package_tftp-server_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_tftp-server_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package tftp is removed" id="oval:ssg-test_package_tftp_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_tftp_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package tmux is installed" id="oval:ssg-test_package_tmux_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_tmux_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package tuned is removed" id="oval:ssg-test_package_tuned_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_tuned_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package usbguard is installed" id="oval:ssg-test_package_usbguard_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_usbguard_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package vim-enhanced is installed" id="oval:ssg-test_package_vim-enhanced_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_vim-enhanced_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package vsftpd is installed" id="oval:ssg-test_package_vsftpd_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_vsftpd_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package vsftpd is removed" id="oval:ssg-test_package_vsftpd_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_vsftpd_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package xinetd is removed" id="oval:ssg-test_package_xinetd_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_xinetd_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package ypbind is removed" id="oval:ssg-test_package_ypbind_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_ypbind_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package ypserv is removed" id="oval:ssg-test_package_ypserv_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_package_ypserv_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/boot on own partition" id="oval:ssg-testboot_partition:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mountboot_own_partition:obj:1"/>
        </linux:partition_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/dev/shm on own partition" id="oval:ssg-testdev_shm_partition:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mountdev_shm_own_partition:obj:1"/>
        </linux:partition_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/home on own partition" id="oval:ssg-testhome_partition:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mounthome_own_partition:obj:1"/>
        </linux:partition_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/opt on own partition" id="oval:ssg-testopt_partition:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mountopt_own_partition:obj:1"/>
        </linux:partition_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/srv on own partition" id="oval:ssg-testsrv_partition:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mountsrv_own_partition:obj:1"/>
        </linux:partition_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/tmp on own partition" id="oval:ssg-testtmp_partition:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mounttmp_own_partition:obj:1"/>
        </linux:partition_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/usr on own partition" id="oval:ssg-testusr_partition:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mountusr_own_partition:obj:1"/>
        </linux:partition_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/var on own partition" id="oval:ssg-testvar_partition:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mountvar_own_partition:obj:1"/>
        </linux:partition_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/var/log on own partition" id="oval:ssg-testvar_log_partition:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mountvar_log_own_partition:obj:1"/>
        </linux:partition_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/var/log/audit on own partition" id="oval:ssg-testvar_log_audit_partition:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mountvar_log_audit_own_partition:obj:1"/>
        </linux:partition_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="/var/tmp on own partition" id="oval:ssg-testvar_tmp_partition:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mountvar_tmp_own_partition:obj:1"/>
        </linux:partition_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /lib/" id="oval:ssg-test_file_groupownerroot_permissions_syslibrary_files_0:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerroot_permissions_syslibrary_files_0:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /lib64/" id="oval:ssg-test_file_groupownerroot_permissions_syslibrary_files_1:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerroot_permissions_syslibrary_files_1:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /usr/lib/" id="oval:ssg-test_file_groupownerroot_permissions_syslibrary_files_2:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerroot_permissions_syslibrary_files_2:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing group ownership of /usr/lib64/" id="oval:ssg-test_file_groupownerroot_permissions_syslibrary_files_3:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_groupownerroot_permissions_syslibrary_files_3:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="System log files have appropriate groupowner set" id="oval:ssg-test_rsyslog_files_groupownership:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_rsyslog_files_groupownership_groupowner:obj:1"/>
          <unix:state state_ref="oval:ssg-state_rsyslog_files_groupownership:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="System log files have appropriate owner set" id="oval:ssg-test_rsyslog_files_ownership:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_rsyslog_files_ownership_owner:obj:1"/>
          <unix:state state_ref="oval:ssg-state_rsyslog_files_ownership:ste:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="System log files have appropriate permissions set" id="oval:ssg-test_rsyslog_files_permissions:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_rsyslog_files_permissions_permissions:obj:1"/>
          <unix:state state_ref="oval:ssg-state_rsyslog_files_permissions:ste:1"/>
        </unix:file_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="abrt_anon_write is configured correctly" id="oval:ssg-test_sebool_abrt_anon_write:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_abrt_anon_write:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_abrt_anon_write:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="abrt_handle_event is configured correctly" id="oval:ssg-test_sebool_abrt_handle_event:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_abrt_handle_event:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_abrt_handle_event:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="abrt_upload_watch_anon_write is configured correctly" id="oval:ssg-test_sebool_abrt_upload_watch_anon_write:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_abrt_upload_watch_anon_write:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_abrt_upload_watch_anon_write:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="antivirus_can_scan_system is configured correctly" id="oval:ssg-test_sebool_antivirus_can_scan_system:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_antivirus_can_scan_system:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_antivirus_can_scan_system:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="antivirus_use_jit is configured correctly" id="oval:ssg-test_sebool_antivirus_use_jit:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_antivirus_use_jit:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_antivirus_use_jit:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="auditadm_exec_content is configured correctly" id="oval:ssg-test_sebool_auditadm_exec_content:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_auditadm_exec_content:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_auditadm_exec_content:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="authlogin_nsswitch_use_ldap is configured correctly" id="oval:ssg-test_sebool_authlogin_nsswitch_use_ldap:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_authlogin_nsswitch_use_ldap:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_authlogin_nsswitch_use_ldap:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="authlogin_radius is configured correctly" id="oval:ssg-test_sebool_authlogin_radius:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_authlogin_radius:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_authlogin_radius:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="authlogin_yubikey is configured correctly" id="oval:ssg-test_sebool_authlogin_yubikey:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_authlogin_yubikey:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_authlogin_yubikey:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="awstats_purge_apache_log_files is configured correctly" id="oval:ssg-test_sebool_awstats_purge_apache_log_files:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_awstats_purge_apache_log_files:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_awstats_purge_apache_log_files:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="boinc_execmem is configured correctly" id="oval:ssg-test_sebool_boinc_execmem:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_boinc_execmem:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_boinc_execmem:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="cdrecord_read_content is configured correctly" id="oval:ssg-test_sebool_cdrecord_read_content:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_cdrecord_read_content:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_cdrecord_read_content:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="cluster_can_network_connect is configured correctly" id="oval:ssg-test_sebool_cluster_can_network_connect:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_cluster_can_network_connect:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_cluster_can_network_connect:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="cluster_manage_all_files is configured correctly" id="oval:ssg-test_sebool_cluster_manage_all_files:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_cluster_manage_all_files:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_cluster_manage_all_files:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="cluster_use_execmem is configured correctly" id="oval:ssg-test_sebool_cluster_use_execmem:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_cluster_use_execmem:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_cluster_use_execmem:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="cobbler_anon_write is configured correctly" id="oval:ssg-test_sebool_cobbler_anon_write:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_cobbler_anon_write:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_cobbler_anon_write:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="cobbler_can_network_connect is configured correctly" id="oval:ssg-test_sebool_cobbler_can_network_connect:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_cobbler_can_network_connect:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_cobbler_can_network_connect:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="cobbler_use_cifs is configured correctly" id="oval:ssg-test_sebool_cobbler_use_cifs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_cobbler_use_cifs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_cobbler_use_cifs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="cobbler_use_nfs is configured correctly" id="oval:ssg-test_sebool_cobbler_use_nfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_cobbler_use_nfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_cobbler_use_nfs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="collectd_tcp_network_connect is configured correctly" id="oval:ssg-test_sebool_collectd_tcp_network_connect:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_collectd_tcp_network_connect:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_collectd_tcp_network_connect:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="condor_tcp_network_connect is configured correctly" id="oval:ssg-test_sebool_condor_tcp_network_connect:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_condor_tcp_network_connect:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_condor_tcp_network_connect:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="conman_can_network is configured correctly" id="oval:ssg-test_sebool_conman_can_network:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_conman_can_network:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_conman_can_network:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="container_connect_any is configured correctly" id="oval:ssg-test_sebool_container_connect_any:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_container_connect_any:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_container_connect_any:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="cron_can_relabel is configured correctly" id="oval:ssg-test_sebool_cron_can_relabel:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_cron_can_relabel:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_cron_can_relabel:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="cron_system_cronjob_use_shares is configured correctly" id="oval:ssg-test_sebool_cron_system_cronjob_use_shares:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_cron_system_cronjob_use_shares:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_cron_system_cronjob_use_shares:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="cron_userdomain_transition is configured correctly" id="oval:ssg-test_sebool_cron_userdomain_transition:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_cron_userdomain_transition:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_cron_userdomain_transition:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="cups_execmem is configured correctly" id="oval:ssg-test_sebool_cups_execmem:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_cups_execmem:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_cups_execmem:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="cvs_read_shadow is configured correctly" id="oval:ssg-test_sebool_cvs_read_shadow:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_cvs_read_shadow:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_cvs_read_shadow:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="daemons_dump_core is configured correctly" id="oval:ssg-test_sebool_daemons_dump_core:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_daemons_dump_core:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_daemons_dump_core:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="daemons_enable_cluster_mode is configured correctly" id="oval:ssg-test_sebool_daemons_enable_cluster_mode:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_daemons_enable_cluster_mode:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_daemons_enable_cluster_mode:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="daemons_use_tcp_wrapper is configured correctly" id="oval:ssg-test_sebool_daemons_use_tcp_wrapper:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_daemons_use_tcp_wrapper:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_daemons_use_tcp_wrapper:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="daemons_use_tty is configured correctly" id="oval:ssg-test_sebool_daemons_use_tty:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_daemons_use_tty:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_daemons_use_tty:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="dbadm_exec_content is configured correctly" id="oval:ssg-test_sebool_dbadm_exec_content:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_dbadm_exec_content:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_dbadm_exec_content:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="dbadm_manage_user_files is configured correctly" id="oval:ssg-test_sebool_dbadm_manage_user_files:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_dbadm_manage_user_files:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_dbadm_manage_user_files:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="dbadm_read_user_files is configured correctly" id="oval:ssg-test_sebool_dbadm_read_user_files:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_dbadm_read_user_files:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_dbadm_read_user_files:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="deny_execmem is configured correctly" id="oval:ssg-test_sebool_deny_execmem:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_deny_execmem:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_deny_execmem:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="deny_ptrace is configured correctly" id="oval:ssg-test_sebool_deny_ptrace:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_deny_ptrace:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_deny_ptrace:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="dhcpc_exec_iptables is configured correctly" id="oval:ssg-test_sebool_dhcpc_exec_iptables:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_dhcpc_exec_iptables:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_dhcpc_exec_iptables:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="dhcpd_use_ldap is configured correctly" id="oval:ssg-test_sebool_dhcpd_use_ldap:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_dhcpd_use_ldap:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_dhcpd_use_ldap:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="domain_fd_use is configured correctly" id="oval:ssg-test_sebool_domain_fd_use:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_domain_fd_use:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_domain_fd_use:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="domain_kernel_load_modules is configured correctly" id="oval:ssg-test_sebool_domain_kernel_load_modules:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_domain_kernel_load_modules:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_domain_kernel_load_modules:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="entropyd_use_audio is configured correctly" id="oval:ssg-test_sebool_entropyd_use_audio:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_entropyd_use_audio:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_entropyd_use_audio:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="exim_can_connect_db is configured correctly" id="oval:ssg-test_sebool_exim_can_connect_db:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_exim_can_connect_db:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_exim_can_connect_db:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="exim_manage_user_files is configured correctly" id="oval:ssg-test_sebool_exim_manage_user_files:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_exim_manage_user_files:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_exim_manage_user_files:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="exim_read_user_files is configured correctly" id="oval:ssg-test_sebool_exim_read_user_files:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_exim_read_user_files:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_exim_read_user_files:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="fcron_crond is configured correctly" id="oval:ssg-test_sebool_fcron_crond:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_fcron_crond:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_fcron_crond:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="fenced_can_network_connect is configured correctly" id="oval:ssg-test_sebool_fenced_can_network_connect:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_fenced_can_network_connect:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_fenced_can_network_connect:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="fenced_can_ssh is configured correctly" id="oval:ssg-test_sebool_fenced_can_ssh:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_fenced_can_ssh:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_fenced_can_ssh:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="fips_mode is configured correctly" id="oval:ssg-test_sebool_fips_mode:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_fips_mode:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_fips_mode:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="ftpd_anon_write is configured correctly" id="oval:ssg-test_sebool_ftpd_anon_write:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_ftpd_anon_write:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_ftpd_anon_write:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="ftpd_connect_all_unreserved is configured correctly" id="oval:ssg-test_sebool_ftpd_connect_all_unreserved:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_ftpd_connect_all_unreserved:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_ftpd_connect_all_unreserved:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="ftpd_connect_db is configured correctly" id="oval:ssg-test_sebool_ftpd_connect_db:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_ftpd_connect_db:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_ftpd_connect_db:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="ftpd_full_access is configured correctly" id="oval:ssg-test_sebool_ftpd_full_access:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_ftpd_full_access:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_ftpd_full_access:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="ftpd_use_cifs is configured correctly" id="oval:ssg-test_sebool_ftpd_use_cifs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_ftpd_use_cifs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_ftpd_use_cifs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="ftpd_use_fusefs is configured correctly" id="oval:ssg-test_sebool_ftpd_use_fusefs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_ftpd_use_fusefs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_ftpd_use_fusefs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="ftpd_use_nfs is configured correctly" id="oval:ssg-test_sebool_ftpd_use_nfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_ftpd_use_nfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_ftpd_use_nfs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="ftpd_use_passive_mode is configured correctly" id="oval:ssg-test_sebool_ftpd_use_passive_mode:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_ftpd_use_passive_mode:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_ftpd_use_passive_mode:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="git_cgi_enable_homedirs is configured correctly" id="oval:ssg-test_sebool_git_cgi_enable_homedirs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_git_cgi_enable_homedirs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_git_cgi_enable_homedirs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="git_cgi_use_cifs is configured correctly" id="oval:ssg-test_sebool_git_cgi_use_cifs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_git_cgi_use_cifs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_git_cgi_use_cifs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="git_cgi_use_nfs is configured correctly" id="oval:ssg-test_sebool_git_cgi_use_nfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_git_cgi_use_nfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_git_cgi_use_nfs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="git_session_bind_all_unreserved_ports is configured correctly" id="oval:ssg-test_sebool_git_session_bind_all_unreserved_ports:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_git_session_bind_all_unreserved_ports:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_git_session_bind_all_unreserved_ports:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="git_session_users is configured correctly" id="oval:ssg-test_sebool_git_session_users:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_git_session_users:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_git_session_users:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="git_system_enable_homedirs is configured correctly" id="oval:ssg-test_sebool_git_system_enable_homedirs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_git_system_enable_homedirs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_git_system_enable_homedirs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="git_system_use_cifs is configured correctly" id="oval:ssg-test_sebool_git_system_use_cifs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_git_system_use_cifs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_git_system_use_cifs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="git_system_use_nfs is configured correctly" id="oval:ssg-test_sebool_git_system_use_nfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_git_system_use_nfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_git_system_use_nfs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="gitosis_can_sendmail is configured correctly" id="oval:ssg-test_sebool_gitosis_can_sendmail:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_gitosis_can_sendmail:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_gitosis_can_sendmail:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="glance_api_can_network is configured correctly" id="oval:ssg-test_sebool_glance_api_can_network:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_glance_api_can_network:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_glance_api_can_network:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="glance_use_execmem is configured correctly" id="oval:ssg-test_sebool_glance_use_execmem:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_glance_use_execmem:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_glance_use_execmem:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="glance_use_fusefs is configured correctly" id="oval:ssg-test_sebool_glance_use_fusefs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_glance_use_fusefs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_glance_use_fusefs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="global_ssp is configured correctly" id="oval:ssg-test_sebool_global_ssp:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_global_ssp:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_global_ssp:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="gluster_anon_write is configured correctly" id="oval:ssg-test_sebool_gluster_anon_write:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_gluster_anon_write:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_gluster_anon_write:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="gluster_export_all_ro is configured correctly" id="oval:ssg-test_sebool_gluster_export_all_ro:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_gluster_export_all_ro:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_gluster_export_all_ro:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="gluster_export_all_rw is configured correctly" id="oval:ssg-test_sebool_gluster_export_all_rw:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_gluster_export_all_rw:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_gluster_export_all_rw:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="gpg_web_anon_write is configured correctly" id="oval:ssg-test_sebool_gpg_web_anon_write:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_gpg_web_anon_write:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_gpg_web_anon_write:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="gssd_read_tmp is configured correctly" id="oval:ssg-test_sebool_gssd_read_tmp:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_gssd_read_tmp:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_gssd_read_tmp:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="guest_exec_content is configured correctly" id="oval:ssg-test_sebool_guest_exec_content:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_guest_exec_content:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_guest_exec_content:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="haproxy_connect_any is configured correctly" id="oval:ssg-test_sebool_haproxy_connect_any:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_haproxy_connect_any:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_haproxy_connect_any:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_anon_write is configured correctly" id="oval:ssg-test_sebool_httpd_anon_write:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_anon_write:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_anon_write:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_builtin_scripting is configured correctly" id="oval:ssg-test_sebool_httpd_builtin_scripting:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_builtin_scripting:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_builtin_scripting:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_can_check_spam is configured correctly" id="oval:ssg-test_sebool_httpd_can_check_spam:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_can_check_spam:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_can_check_spam:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_can_connect_ftp is configured correctly" id="oval:ssg-test_sebool_httpd_can_connect_ftp:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_can_connect_ftp:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_can_connect_ftp:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_can_connect_ldap is configured correctly" id="oval:ssg-test_sebool_httpd_can_connect_ldap:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_can_connect_ldap:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_can_connect_ldap:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_can_connect_mythtv is configured correctly" id="oval:ssg-test_sebool_httpd_can_connect_mythtv:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_can_connect_mythtv:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_can_connect_mythtv:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_can_connect_zabbix is configured correctly" id="oval:ssg-test_sebool_httpd_can_connect_zabbix:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_can_connect_zabbix:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_can_connect_zabbix:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_can_network_connect is configured correctly" id="oval:ssg-test_sebool_httpd_can_network_connect:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_can_network_connect:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_can_network_connect:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_can_network_connect_cobbler is configured correctly" id="oval:ssg-test_sebool_httpd_can_network_connect_cobbler:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_can_network_connect_cobbler:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_can_network_connect_cobbler:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_can_network_connect_db is configured correctly" id="oval:ssg-test_sebool_httpd_can_network_connect_db:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_can_network_connect_db:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_can_network_connect_db:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_can_network_memcache is configured correctly" id="oval:ssg-test_sebool_httpd_can_network_memcache:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_can_network_memcache:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_can_network_memcache:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_can_network_relay is configured correctly" id="oval:ssg-test_sebool_httpd_can_network_relay:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_can_network_relay:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_can_network_relay:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_can_sendmail is configured correctly" id="oval:ssg-test_sebool_httpd_can_sendmail:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_can_sendmail:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_can_sendmail:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_dbus_avahi is configured correctly" id="oval:ssg-test_sebool_httpd_dbus_avahi:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_dbus_avahi:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_dbus_avahi:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_dbus_sssd is configured correctly" id="oval:ssg-test_sebool_httpd_dbus_sssd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_dbus_sssd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_dbus_sssd:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_dontaudit_search_dirs is configured correctly" id="oval:ssg-test_sebool_httpd_dontaudit_search_dirs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_dontaudit_search_dirs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_dontaudit_search_dirs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_enable_cgi is configured correctly" id="oval:ssg-test_sebool_httpd_enable_cgi:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_enable_cgi:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_enable_cgi:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_enable_ftp_server is configured correctly" id="oval:ssg-test_sebool_httpd_enable_ftp_server:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_enable_ftp_server:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_enable_ftp_server:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_enable_homedirs is configured correctly" id="oval:ssg-test_sebool_httpd_enable_homedirs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_enable_homedirs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_enable_homedirs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_execmem is configured correctly" id="oval:ssg-test_sebool_httpd_execmem:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_execmem:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_execmem:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_graceful_shutdown is configured correctly" id="oval:ssg-test_sebool_httpd_graceful_shutdown:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_graceful_shutdown:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_graceful_shutdown:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_manage_ipa is configured correctly" id="oval:ssg-test_sebool_httpd_manage_ipa:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_manage_ipa:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_manage_ipa:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_mod_auth_ntlm_winbind is configured correctly" id="oval:ssg-test_sebool_httpd_mod_auth_ntlm_winbind:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_mod_auth_ntlm_winbind:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_mod_auth_ntlm_winbind:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_mod_auth_pam is configured correctly" id="oval:ssg-test_sebool_httpd_mod_auth_pam:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_mod_auth_pam:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_mod_auth_pam:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_read_user_content is configured correctly" id="oval:ssg-test_sebool_httpd_read_user_content:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_read_user_content:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_read_user_content:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_run_ipa is configured correctly" id="oval:ssg-test_sebool_httpd_run_ipa:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_run_ipa:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_run_ipa:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_run_preupgrade is configured correctly" id="oval:ssg-test_sebool_httpd_run_preupgrade:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_run_preupgrade:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_run_preupgrade:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_run_stickshift is configured correctly" id="oval:ssg-test_sebool_httpd_run_stickshift:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_run_stickshift:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_run_stickshift:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_serve_cobbler_files is configured correctly" id="oval:ssg-test_sebool_httpd_serve_cobbler_files:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_serve_cobbler_files:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_serve_cobbler_files:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_setrlimit is configured correctly" id="oval:ssg-test_sebool_httpd_setrlimit:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_setrlimit:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_setrlimit:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_ssi_exec is configured correctly" id="oval:ssg-test_sebool_httpd_ssi_exec:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_ssi_exec:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_ssi_exec:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_sys_script_anon_write is configured correctly" id="oval:ssg-test_sebool_httpd_sys_script_anon_write:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_sys_script_anon_write:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_sys_script_anon_write:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_tmp_exec is configured correctly" id="oval:ssg-test_sebool_httpd_tmp_exec:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_tmp_exec:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_tmp_exec:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_tty_comm is configured correctly" id="oval:ssg-test_sebool_httpd_tty_comm:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_tty_comm:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_tty_comm:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_unified is configured correctly" id="oval:ssg-test_sebool_httpd_unified:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_unified:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_unified:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_use_cifs is configured correctly" id="oval:ssg-test_sebool_httpd_use_cifs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_use_cifs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_use_cifs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_use_fusefs is configured correctly" id="oval:ssg-test_sebool_httpd_use_fusefs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_use_fusefs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_use_fusefs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_use_gpg is configured correctly" id="oval:ssg-test_sebool_httpd_use_gpg:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_use_gpg:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_use_gpg:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_use_nfs is configured correctly" id="oval:ssg-test_sebool_httpd_use_nfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_use_nfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_use_nfs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_use_openstack is configured correctly" id="oval:ssg-test_sebool_httpd_use_openstack:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_use_openstack:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_use_openstack:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_use_sasl is configured correctly" id="oval:ssg-test_sebool_httpd_use_sasl:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_use_sasl:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_use_sasl:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="httpd_verify_dns is configured correctly" id="oval:ssg-test_sebool_httpd_verify_dns:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_httpd_verify_dns:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_httpd_verify_dns:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="icecast_use_any_tcp_ports is configured correctly" id="oval:ssg-test_sebool_icecast_use_any_tcp_ports:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_icecast_use_any_tcp_ports:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_icecast_use_any_tcp_ports:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="irc_use_any_tcp_ports is configured correctly" id="oval:ssg-test_sebool_irc_use_any_tcp_ports:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_irc_use_any_tcp_ports:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_irc_use_any_tcp_ports:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="irssi_use_full_network is configured correctly" id="oval:ssg-test_sebool_irssi_use_full_network:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_irssi_use_full_network:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_irssi_use_full_network:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="kdumpgui_run_bootloader is configured correctly" id="oval:ssg-test_sebool_kdumpgui_run_bootloader:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_kdumpgui_run_bootloader:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_kdumpgui_run_bootloader:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="kerberos_enabled is configured correctly" id="oval:ssg-test_sebool_kerberos_enabled:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_kerberos_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_kerberos_enabled:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="ksmtuned_use_cifs is configured correctly" id="oval:ssg-test_sebool_ksmtuned_use_cifs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_ksmtuned_use_cifs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_ksmtuned_use_cifs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="ksmtuned_use_nfs is configured correctly" id="oval:ssg-test_sebool_ksmtuned_use_nfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_ksmtuned_use_nfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_ksmtuned_use_nfs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="logadm_exec_content is configured correctly" id="oval:ssg-test_sebool_logadm_exec_content:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_logadm_exec_content:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_logadm_exec_content:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="logging_syslogd_can_sendmail is configured correctly" id="oval:ssg-test_sebool_logging_syslogd_can_sendmail:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_logging_syslogd_can_sendmail:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_logging_syslogd_can_sendmail:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="logging_syslogd_run_nagios_plugins is configured correctly" id="oval:ssg-test_sebool_logging_syslogd_run_nagios_plugins:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_logging_syslogd_run_nagios_plugins:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_logging_syslogd_run_nagios_plugins:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="logging_syslogd_use_tty is configured correctly" id="oval:ssg-test_sebool_logging_syslogd_use_tty:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_logging_syslogd_use_tty:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_logging_syslogd_use_tty:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="login_console_enabled is configured correctly" id="oval:ssg-test_sebool_login_console_enabled:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_login_console_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_login_console_enabled:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="logrotate_use_nfs is configured correctly" id="oval:ssg-test_sebool_logrotate_use_nfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_logrotate_use_nfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_logrotate_use_nfs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="logwatch_can_network_connect_mail is configured correctly" id="oval:ssg-test_sebool_logwatch_can_network_connect_mail:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_logwatch_can_network_connect_mail:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_logwatch_can_network_connect_mail:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="lsmd_plugin_connect_any is configured correctly" id="oval:ssg-test_sebool_lsmd_plugin_connect_any:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_lsmd_plugin_connect_any:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_lsmd_plugin_connect_any:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mailman_use_fusefs is configured correctly" id="oval:ssg-test_sebool_mailman_use_fusefs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mailman_use_fusefs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mailman_use_fusefs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mcelog_client is configured correctly" id="oval:ssg-test_sebool_mcelog_client:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mcelog_client:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mcelog_client:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mcelog_exec_scripts is configured correctly" id="oval:ssg-test_sebool_mcelog_exec_scripts:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mcelog_exec_scripts:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mcelog_exec_scripts:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mcelog_foreground is configured correctly" id="oval:ssg-test_sebool_mcelog_foreground:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mcelog_foreground:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mcelog_foreground:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mcelog_server is configured correctly" id="oval:ssg-test_sebool_mcelog_server:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mcelog_server:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mcelog_server:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="minidlna_read_generic_user_content is configured correctly" id="oval:ssg-test_sebool_minidlna_read_generic_user_content:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_minidlna_read_generic_user_content:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_minidlna_read_generic_user_content:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mmap_low_allowed is configured correctly" id="oval:ssg-test_sebool_mmap_low_allowed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mmap_low_allowed:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mmap_low_allowed:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mock_enable_homedirs is configured correctly" id="oval:ssg-test_sebool_mock_enable_homedirs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mock_enable_homedirs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mock_enable_homedirs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mount_anyfile is configured correctly" id="oval:ssg-test_sebool_mount_anyfile:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mount_anyfile:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mount_anyfile:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mozilla_plugin_bind_unreserved_ports is configured correctly" id="oval:ssg-test_sebool_mozilla_plugin_bind_unreserved_ports:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mozilla_plugin_bind_unreserved_ports:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mozilla_plugin_bind_unreserved_ports:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mozilla_plugin_can_network_connect is configured correctly" id="oval:ssg-test_sebool_mozilla_plugin_can_network_connect:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mozilla_plugin_can_network_connect:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mozilla_plugin_can_network_connect:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mozilla_plugin_use_bluejeans is configured correctly" id="oval:ssg-test_sebool_mozilla_plugin_use_bluejeans:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mozilla_plugin_use_bluejeans:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mozilla_plugin_use_bluejeans:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mozilla_plugin_use_gps is configured correctly" id="oval:ssg-test_sebool_mozilla_plugin_use_gps:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mozilla_plugin_use_gps:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mozilla_plugin_use_gps:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mozilla_plugin_use_spice is configured correctly" id="oval:ssg-test_sebool_mozilla_plugin_use_spice:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mozilla_plugin_use_spice:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mozilla_plugin_use_spice:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mozilla_read_content is configured correctly" id="oval:ssg-test_sebool_mozilla_read_content:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mozilla_read_content:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mozilla_read_content:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mpd_enable_homedirs is configured correctly" id="oval:ssg-test_sebool_mpd_enable_homedirs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mpd_enable_homedirs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mpd_enable_homedirs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mpd_use_cifs is configured correctly" id="oval:ssg-test_sebool_mpd_use_cifs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mpd_use_cifs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mpd_use_cifs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mpd_use_nfs is configured correctly" id="oval:ssg-test_sebool_mpd_use_nfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mpd_use_nfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mpd_use_nfs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mplayer_execstack is configured correctly" id="oval:ssg-test_sebool_mplayer_execstack:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mplayer_execstack:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mplayer_execstack:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="mysql_connect_any is configured correctly" id="oval:ssg-test_sebool_mysql_connect_any:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_mysql_connect_any:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_mysql_connect_any:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="nagios_run_pnp4nagios is configured correctly" id="oval:ssg-test_sebool_nagios_run_pnp4nagios:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_nagios_run_pnp4nagios:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_nagios_run_pnp4nagios:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="nagios_run_sudo is configured correctly" id="oval:ssg-test_sebool_nagios_run_sudo:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_nagios_run_sudo:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_nagios_run_sudo:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="named_tcp_bind_http_port is configured correctly" id="oval:ssg-test_sebool_named_tcp_bind_http_port:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_named_tcp_bind_http_port:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_named_tcp_bind_http_port:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="named_write_master_zones is configured correctly" id="oval:ssg-test_sebool_named_write_master_zones:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_named_write_master_zones:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_named_write_master_zones:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="neutron_can_network is configured correctly" id="oval:ssg-test_sebool_neutron_can_network:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_neutron_can_network:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_neutron_can_network:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="nfs_export_all_ro is configured correctly" id="oval:ssg-test_sebool_nfs_export_all_ro:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_nfs_export_all_ro:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_nfs_export_all_ro:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="nfs_export_all_rw is configured correctly" id="oval:ssg-test_sebool_nfs_export_all_rw:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_nfs_export_all_rw:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_nfs_export_all_rw:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="nfsd_anon_write is configured correctly" id="oval:ssg-test_sebool_nfsd_anon_write:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_nfsd_anon_write:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_nfsd_anon_write:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="nis_enabled is configured correctly" id="oval:ssg-test_sebool_nis_enabled:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_nis_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_nis_enabled:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="nscd_use_shm is configured correctly" id="oval:ssg-test_sebool_nscd_use_shm:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_nscd_use_shm:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_nscd_use_shm:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="openshift_use_nfs is configured correctly" id="oval:ssg-test_sebool_openshift_use_nfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_openshift_use_nfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_openshift_use_nfs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="openvpn_can_network_connect is configured correctly" id="oval:ssg-test_sebool_openvpn_can_network_connect:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_openvpn_can_network_connect:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_openvpn_can_network_connect:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="openvpn_enable_homedirs is configured correctly" id="oval:ssg-test_sebool_openvpn_enable_homedirs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_openvpn_enable_homedirs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_openvpn_enable_homedirs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="openvpn_run_unconfined is configured correctly" id="oval:ssg-test_sebool_openvpn_run_unconfined:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_openvpn_run_unconfined:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_openvpn_run_unconfined:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="pcp_bind_all_unreserved_ports is configured correctly" id="oval:ssg-test_sebool_pcp_bind_all_unreserved_ports:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_pcp_bind_all_unreserved_ports:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_pcp_bind_all_unreserved_ports:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="pcp_read_generic_logs is configured correctly" id="oval:ssg-test_sebool_pcp_read_generic_logs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_pcp_read_generic_logs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_pcp_read_generic_logs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="piranha_lvs_can_network_connect is configured correctly" id="oval:ssg-test_sebool_piranha_lvs_can_network_connect:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_piranha_lvs_can_network_connect:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_piranha_lvs_can_network_connect:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="polipo_connect_all_unreserved is configured correctly" id="oval:ssg-test_sebool_polipo_connect_all_unreserved:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_polipo_connect_all_unreserved:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_polipo_connect_all_unreserved:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="polipo_session_bind_all_unreserved_ports is configured correctly" id="oval:ssg-test_sebool_polipo_session_bind_all_unreserved_ports:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_polipo_session_bind_all_unreserved_ports:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_polipo_session_bind_all_unreserved_ports:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="polipo_session_users is configured correctly" id="oval:ssg-test_sebool_polipo_session_users:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_polipo_session_users:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_polipo_session_users:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="polipo_use_cifs is configured correctly" id="oval:ssg-test_sebool_polipo_use_cifs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_polipo_use_cifs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_polipo_use_cifs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="polipo_use_nfs is configured correctly" id="oval:ssg-test_sebool_polipo_use_nfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_polipo_use_nfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_polipo_use_nfs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="polyinstantiation_enabled is configured correctly" id="oval:ssg-test_sebool_polyinstantiation_enabled:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_polyinstantiation_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_polyinstantiation_enabled:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="postfix_local_write_mail_spool is configured correctly" id="oval:ssg-test_sebool_postfix_local_write_mail_spool:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_postfix_local_write_mail_spool:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_postfix_local_write_mail_spool:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="postgresql_can_rsync is configured correctly" id="oval:ssg-test_sebool_postgresql_can_rsync:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_postgresql_can_rsync:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_postgresql_can_rsync:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="postgresql_selinux_transmit_client_label is configured correctly" id="oval:ssg-test_sebool_postgresql_selinux_transmit_client_label:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_postgresql_selinux_transmit_client_label:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_postgresql_selinux_transmit_client_label:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="postgresql_selinux_unconfined_dbadm is configured correctly" id="oval:ssg-test_sebool_postgresql_selinux_unconfined_dbadm:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_postgresql_selinux_unconfined_dbadm:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_postgresql_selinux_unconfined_dbadm:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="postgresql_selinux_users_ddl is configured correctly" id="oval:ssg-test_sebool_postgresql_selinux_users_ddl:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_postgresql_selinux_users_ddl:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_postgresql_selinux_users_ddl:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="pppd_can_insmod is configured correctly" id="oval:ssg-test_sebool_pppd_can_insmod:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_pppd_can_insmod:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_pppd_can_insmod:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="pppd_for_user is configured correctly" id="oval:ssg-test_sebool_pppd_for_user:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_pppd_for_user:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_pppd_for_user:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="privoxy_connect_any is configured correctly" id="oval:ssg-test_sebool_privoxy_connect_any:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_privoxy_connect_any:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_privoxy_connect_any:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="prosody_bind_http_port is configured correctly" id="oval:ssg-test_sebool_prosody_bind_http_port:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_prosody_bind_http_port:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_prosody_bind_http_port:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="puppetagent_manage_all_files is configured correctly" id="oval:ssg-test_sebool_puppetagent_manage_all_files:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_puppetagent_manage_all_files:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_puppetagent_manage_all_files:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="puppetmaster_use_db is configured correctly" id="oval:ssg-test_sebool_puppetmaster_use_db:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_puppetmaster_use_db:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_puppetmaster_use_db:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="racoon_read_shadow is configured correctly" id="oval:ssg-test_sebool_racoon_read_shadow:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_racoon_read_shadow:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_racoon_read_shadow:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="rsync_anon_write is configured correctly" id="oval:ssg-test_sebool_rsync_anon_write:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_rsync_anon_write:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_rsync_anon_write:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="rsync_client is configured correctly" id="oval:ssg-test_sebool_rsync_client:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_rsync_client:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_rsync_client:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="rsync_export_all_ro is configured correctly" id="oval:ssg-test_sebool_rsync_export_all_ro:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_rsync_export_all_ro:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_rsync_export_all_ro:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="rsync_full_access is configured correctly" id="oval:ssg-test_sebool_rsync_full_access:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_rsync_full_access:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_rsync_full_access:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="samba_create_home_dirs is configured correctly" id="oval:ssg-test_sebool_samba_create_home_dirs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_samba_create_home_dirs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_samba_create_home_dirs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="samba_domain_controller is configured correctly" id="oval:ssg-test_sebool_samba_domain_controller:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_samba_domain_controller:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_samba_domain_controller:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="samba_enable_home_dirs is configured correctly" id="oval:ssg-test_sebool_samba_enable_home_dirs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_samba_enable_home_dirs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_samba_enable_home_dirs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="samba_export_all_ro is configured correctly" id="oval:ssg-test_sebool_samba_export_all_ro:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_samba_export_all_ro:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_samba_export_all_ro:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="samba_export_all_rw is configured correctly" id="oval:ssg-test_sebool_samba_export_all_rw:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_samba_export_all_rw:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_samba_export_all_rw:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="samba_load_libgfapi is configured correctly" id="oval:ssg-test_sebool_samba_load_libgfapi:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_samba_load_libgfapi:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_samba_load_libgfapi:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="samba_portmapper is configured correctly" id="oval:ssg-test_sebool_samba_portmapper:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_samba_portmapper:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_samba_portmapper:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="samba_run_unconfined is configured correctly" id="oval:ssg-test_sebool_samba_run_unconfined:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_samba_run_unconfined:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_samba_run_unconfined:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="samba_share_fusefs is configured correctly" id="oval:ssg-test_sebool_samba_share_fusefs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_samba_share_fusefs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_samba_share_fusefs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="samba_share_nfs is configured correctly" id="oval:ssg-test_sebool_samba_share_nfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_samba_share_nfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_samba_share_nfs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="sanlock_use_fusefs is configured correctly" id="oval:ssg-test_sebool_sanlock_use_fusefs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_sanlock_use_fusefs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_sanlock_use_fusefs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="sanlock_use_nfs is configured correctly" id="oval:ssg-test_sebool_sanlock_use_nfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_sanlock_use_nfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_sanlock_use_nfs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="sanlock_use_samba is configured correctly" id="oval:ssg-test_sebool_sanlock_use_samba:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_sanlock_use_samba:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_sanlock_use_samba:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="saslauthd_read_shadow is configured correctly" id="oval:ssg-test_sebool_saslauthd_read_shadow:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_saslauthd_read_shadow:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_saslauthd_read_shadow:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="secadm_exec_content is configured correctly" id="oval:ssg-test_sebool_secadm_exec_content:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_secadm_exec_content:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_secadm_exec_content:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="secure_mode is configured correctly" id="oval:ssg-test_sebool_secure_mode:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_secure_mode:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_secure_mode:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="secure_mode_insmod is configured correctly" id="oval:ssg-test_sebool_secure_mode_insmod:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_secure_mode_insmod:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_secure_mode_insmod:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="secure_mode_policyload is configured correctly" id="oval:ssg-test_sebool_secure_mode_policyload:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_secure_mode_policyload:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_secure_mode_policyload:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="selinuxuser_direct_dri_enabled is configured correctly" id="oval:ssg-test_sebool_selinuxuser_direct_dri_enabled:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_selinuxuser_direct_dri_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_selinuxuser_direct_dri_enabled:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="selinuxuser_execheap is configured correctly" id="oval:ssg-test_sebool_selinuxuser_execheap:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_selinuxuser_execheap:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_selinuxuser_execheap:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="selinuxuser_execmod is configured correctly" id="oval:ssg-test_sebool_selinuxuser_execmod:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_selinuxuser_execmod:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_selinuxuser_execmod:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="selinuxuser_execstack is configured correctly" id="oval:ssg-test_sebool_selinuxuser_execstack:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_selinuxuser_execstack:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_selinuxuser_execstack:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="selinuxuser_mysql_connect_enabled is configured correctly" id="oval:ssg-test_sebool_selinuxuser_mysql_connect_enabled:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_selinuxuser_mysql_connect_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_selinuxuser_mysql_connect_enabled:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="selinuxuser_ping is configured correctly" id="oval:ssg-test_sebool_selinuxuser_ping:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_selinuxuser_ping:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_selinuxuser_ping:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="selinuxuser_postgresql_connect_enabled is configured correctly" id="oval:ssg-test_sebool_selinuxuser_postgresql_connect_enabled:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_selinuxuser_postgresql_connect_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_selinuxuser_postgresql_connect_enabled:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="selinuxuser_rw_noexattrfile is configured correctly" id="oval:ssg-test_sebool_selinuxuser_rw_noexattrfile:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_selinuxuser_rw_noexattrfile:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_selinuxuser_rw_noexattrfile:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="selinuxuser_share_music is configured correctly" id="oval:ssg-test_sebool_selinuxuser_share_music:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_selinuxuser_share_music:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_selinuxuser_share_music:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="selinuxuser_tcp_server is configured correctly" id="oval:ssg-test_sebool_selinuxuser_tcp_server:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_selinuxuser_tcp_server:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_selinuxuser_tcp_server:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="selinuxuser_udp_server is configured correctly" id="oval:ssg-test_sebool_selinuxuser_udp_server:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_selinuxuser_udp_server:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_selinuxuser_udp_server:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="selinuxuser_use_ssh_chroot is configured correctly" id="oval:ssg-test_sebool_selinuxuser_use_ssh_chroot:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_selinuxuser_use_ssh_chroot:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_selinuxuser_use_ssh_chroot:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="sge_domain_can_network_connect is configured correctly" id="oval:ssg-test_sebool_sge_domain_can_network_connect:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_sge_domain_can_network_connect:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_sge_domain_can_network_connect:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="sge_use_nfs is configured correctly" id="oval:ssg-test_sebool_sge_use_nfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_sge_use_nfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_sge_use_nfs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="smartmon_3ware is configured correctly" id="oval:ssg-test_sebool_smartmon_3ware:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_smartmon_3ware:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_smartmon_3ware:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="smbd_anon_write is configured correctly" id="oval:ssg-test_sebool_smbd_anon_write:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_smbd_anon_write:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_smbd_anon_write:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="spamassassin_can_network is configured correctly" id="oval:ssg-test_sebool_spamassassin_can_network:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_spamassassin_can_network:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_spamassassin_can_network:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="spamd_enable_home_dirs is configured correctly" id="oval:ssg-test_sebool_spamd_enable_home_dirs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_spamd_enable_home_dirs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_spamd_enable_home_dirs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="squid_connect_any is configured correctly" id="oval:ssg-test_sebool_squid_connect_any:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_squid_connect_any:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_squid_connect_any:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="squid_use_tproxy is configured correctly" id="oval:ssg-test_sebool_squid_use_tproxy:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_squid_use_tproxy:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_squid_use_tproxy:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="ssh_chroot_rw_homedirs is configured correctly" id="oval:ssg-test_sebool_ssh_chroot_rw_homedirs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_ssh_chroot_rw_homedirs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_ssh_chroot_rw_homedirs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="ssh_keysign is configured correctly" id="oval:ssg-test_sebool_ssh_keysign:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_ssh_keysign:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_ssh_keysign:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="ssh_sysadm_login is configured correctly" id="oval:ssg-test_sebool_ssh_sysadm_login:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_ssh_sysadm_login:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_ssh_sysadm_login:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="staff_exec_content is configured correctly" id="oval:ssg-test_sebool_staff_exec_content:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_staff_exec_content:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_staff_exec_content:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="staff_use_svirt is configured correctly" id="oval:ssg-test_sebool_staff_use_svirt:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_staff_use_svirt:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_staff_use_svirt:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="swift_can_network is configured correctly" id="oval:ssg-test_sebool_swift_can_network:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_swift_can_network:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_swift_can_network:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="sysadm_exec_content is configured correctly" id="oval:ssg-test_sebool_sysadm_exec_content:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_sysadm_exec_content:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_sysadm_exec_content:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="telepathy_connect_all_ports is configured correctly" id="oval:ssg-test_sebool_telepathy_connect_all_ports:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_telepathy_connect_all_ports:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_telepathy_connect_all_ports:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="telepathy_tcp_connect_generic_network_ports is configured correctly" id="oval:ssg-test_sebool_telepathy_tcp_connect_generic_network_ports:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_telepathy_tcp_connect_generic_network_ports:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_telepathy_tcp_connect_generic_network_ports:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="tftp_anon_write is configured correctly" id="oval:ssg-test_sebool_tftp_anon_write:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_tftp_anon_write:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_tftp_anon_write:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="tftp_home_dir is configured correctly" id="oval:ssg-test_sebool_tftp_home_dir:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_tftp_home_dir:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_tftp_home_dir:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="tmpreaper_use_nfs is configured correctly" id="oval:ssg-test_sebool_tmpreaper_use_nfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_tmpreaper_use_nfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_tmpreaper_use_nfs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="tmpreaper_use_samba is configured correctly" id="oval:ssg-test_sebool_tmpreaper_use_samba:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_tmpreaper_use_samba:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_tmpreaper_use_samba:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="tor_bind_all_unreserved_ports is configured correctly" id="oval:ssg-test_sebool_tor_bind_all_unreserved_ports:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_tor_bind_all_unreserved_ports:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_tor_bind_all_unreserved_ports:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="tor_can_network_relay is configured correctly" id="oval:ssg-test_sebool_tor_can_network_relay:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_tor_can_network_relay:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_tor_can_network_relay:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="unconfined_chrome_sandbox_transition is configured correctly" id="oval:ssg-test_sebool_unconfined_chrome_sandbox_transition:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_unconfined_chrome_sandbox_transition:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_unconfined_chrome_sandbox_transition:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="unconfined_login is configured correctly" id="oval:ssg-test_sebool_unconfined_login:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_unconfined_login:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_unconfined_login:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="unconfined_mozilla_plugin_transition is configured correctly" id="oval:ssg-test_sebool_unconfined_mozilla_plugin_transition:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_unconfined_mozilla_plugin_transition:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_unconfined_mozilla_plugin_transition:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="unprivuser_use_svirt is configured correctly" id="oval:ssg-test_sebool_unprivuser_use_svirt:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_unprivuser_use_svirt:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_unprivuser_use_svirt:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="use_ecryptfs_home_dirs is configured correctly" id="oval:ssg-test_sebool_use_ecryptfs_home_dirs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_use_ecryptfs_home_dirs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_use_ecryptfs_home_dirs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="use_fusefs_home_dirs is configured correctly" id="oval:ssg-test_sebool_use_fusefs_home_dirs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_use_fusefs_home_dirs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_use_fusefs_home_dirs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="use_lpd_server is configured correctly" id="oval:ssg-test_sebool_use_lpd_server:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_use_lpd_server:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_use_lpd_server:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="use_nfs_home_dirs is configured correctly" id="oval:ssg-test_sebool_use_nfs_home_dirs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_use_nfs_home_dirs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_use_nfs_home_dirs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="use_samba_home_dirs is configured correctly" id="oval:ssg-test_sebool_use_samba_home_dirs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_use_samba_home_dirs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_use_samba_home_dirs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="user_exec_content is configured correctly" id="oval:ssg-test_sebool_user_exec_content:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_user_exec_content:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_user_exec_content:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="varnishd_connect_any is configured correctly" id="oval:ssg-test_sebool_varnishd_connect_any:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_varnishd_connect_any:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_varnishd_connect_any:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="virt_read_qemu_ga_data is configured correctly" id="oval:ssg-test_sebool_virt_read_qemu_ga_data:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_virt_read_qemu_ga_data:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_virt_read_qemu_ga_data:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="virt_rw_qemu_ga_data is configured correctly" id="oval:ssg-test_sebool_virt_rw_qemu_ga_data:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_virt_rw_qemu_ga_data:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_virt_rw_qemu_ga_data:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="virt_sandbox_use_all_caps is configured correctly" id="oval:ssg-test_sebool_virt_sandbox_use_all_caps:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_virt_sandbox_use_all_caps:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_virt_sandbox_use_all_caps:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="virt_sandbox_use_audit is configured correctly" id="oval:ssg-test_sebool_virt_sandbox_use_audit:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_virt_sandbox_use_audit:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_virt_sandbox_use_audit:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="virt_sandbox_use_mknod is configured correctly" id="oval:ssg-test_sebool_virt_sandbox_use_mknod:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_virt_sandbox_use_mknod:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_virt_sandbox_use_mknod:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="virt_sandbox_use_netlink is configured correctly" id="oval:ssg-test_sebool_virt_sandbox_use_netlink:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_virt_sandbox_use_netlink:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_virt_sandbox_use_netlink:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="virt_sandbox_use_sys_admin is configured correctly" id="oval:ssg-test_sebool_virt_sandbox_use_sys_admin:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_virt_sandbox_use_sys_admin:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_virt_sandbox_use_sys_admin:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="virt_transition_userdomain is configured correctly" id="oval:ssg-test_sebool_virt_transition_userdomain:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_virt_transition_userdomain:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_virt_transition_userdomain:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="virt_use_comm is configured correctly" id="oval:ssg-test_sebool_virt_use_comm:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_virt_use_comm:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_virt_use_comm:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="virt_use_execmem is configured correctly" id="oval:ssg-test_sebool_virt_use_execmem:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_virt_use_execmem:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_virt_use_execmem:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="virt_use_fusefs is configured correctly" id="oval:ssg-test_sebool_virt_use_fusefs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_virt_use_fusefs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_virt_use_fusefs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="virt_use_nfs is configured correctly" id="oval:ssg-test_sebool_virt_use_nfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_virt_use_nfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_virt_use_nfs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="virt_use_rawip is configured correctly" id="oval:ssg-test_sebool_virt_use_rawip:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_virt_use_rawip:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_virt_use_rawip:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="virt_use_samba is configured correctly" id="oval:ssg-test_sebool_virt_use_samba:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_virt_use_samba:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_virt_use_samba:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="virt_use_sanlock is configured correctly" id="oval:ssg-test_sebool_virt_use_sanlock:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_virt_use_sanlock:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_virt_use_sanlock:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="virt_use_usb is configured correctly" id="oval:ssg-test_sebool_virt_use_usb:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_virt_use_usb:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_virt_use_usb:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="virt_use_xserver is configured correctly" id="oval:ssg-test_sebool_virt_use_xserver:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_virt_use_xserver:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_virt_use_xserver:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="webadm_manage_user_files is configured correctly" id="oval:ssg-test_sebool_webadm_manage_user_files:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_webadm_manage_user_files:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_webadm_manage_user_files:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="webadm_read_user_files is configured correctly" id="oval:ssg-test_sebool_webadm_read_user_files:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_webadm_read_user_files:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_webadm_read_user_files:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="wine_mmap_zero_ignore is configured correctly" id="oval:ssg-test_sebool_wine_mmap_zero_ignore:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_wine_mmap_zero_ignore:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_wine_mmap_zero_ignore:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="xdm_bind_vnc_tcp_port is configured correctly" id="oval:ssg-test_sebool_xdm_bind_vnc_tcp_port:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_xdm_bind_vnc_tcp_port:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_xdm_bind_vnc_tcp_port:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="xdm_exec_bootloader is configured correctly" id="oval:ssg-test_sebool_xdm_exec_bootloader:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_xdm_exec_bootloader:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_xdm_exec_bootloader:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="xdm_sysadm_login is configured correctly" id="oval:ssg-test_sebool_xdm_sysadm_login:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_xdm_sysadm_login:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_xdm_sysadm_login:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="xdm_write_home is configured correctly" id="oval:ssg-test_sebool_xdm_write_home:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_xdm_write_home:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_xdm_write_home:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="xen_use_nfs is configured correctly" id="oval:ssg-test_sebool_xen_use_nfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_xen_use_nfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_xen_use_nfs:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="xend_run_blktap is configured correctly" id="oval:ssg-test_sebool_xend_run_blktap:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_xend_run_blktap:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_xend_run_blktap:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="xend_run_qemu is configured correctly" id="oval:ssg-test_sebool_xend_run_qemu:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_xend_run_qemu:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_xend_run_qemu:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="xguest_connect_network is configured correctly" id="oval:ssg-test_sebool_xguest_connect_network:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_xguest_connect_network:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_xguest_connect_network:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="xguest_exec_content is configured correctly" id="oval:ssg-test_sebool_xguest_exec_content:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_xguest_exec_content:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_xguest_exec_content:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="xguest_mount_media is configured correctly" id="oval:ssg-test_sebool_xguest_mount_media:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_xguest_mount_media:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_xguest_mount_media:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="xguest_use_bluetooth is configured correctly" id="oval:ssg-test_sebool_xguest_use_bluetooth:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_xguest_use_bluetooth:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_xguest_use_bluetooth:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="xserver_clients_write_xshm is configured correctly" id="oval:ssg-test_sebool_xserver_clients_write_xshm:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_xserver_clients_write_xshm:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_xserver_clients_write_xshm:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="xserver_execmem is configured correctly" id="oval:ssg-test_sebool_xserver_execmem:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_xserver_execmem:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_xserver_execmem:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="xserver_object_manager is configured correctly" id="oval:ssg-test_sebool_xserver_object_manager:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_xserver_object_manager:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_xserver_object_manager:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="zabbix_can_network is configured correctly" id="oval:ssg-test_sebool_zabbix_can_network:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_zabbix_can_network:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_zabbix_can_network:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="zarafa_setrlimit is configured correctly" id="oval:ssg-test_sebool_zarafa_setrlimit:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_zarafa_setrlimit:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_zarafa_setrlimit:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="zebra_write_config is configured correctly" id="oval:ssg-test_sebool_zebra_write_config:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_zebra_write_config:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_zebra_write_config:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="zoneminder_anon_write is configured correctly" id="oval:ssg-test_sebool_zoneminder_anon_write:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_zoneminder_anon_write:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_zoneminder_anon_write:ste:1"/>
        </linux:selinuxboolean_test>
        <linux:selinuxboolean_test check="all" check_existence="all_exist" comment="zoneminder_run_sudo is configured correctly" id="oval:ssg-test_sebool_zoneminder_run_sudo:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_sebool_zoneminder_run_sudo:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sebool_zoneminder_run_sudo:ste:1"/>
        </linux:selinuxboolean_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of SELINUXTYPE setting in the /etc/selinux/config file" id="oval:ssg-test_selinux_policytype:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_selinux_policytype:obj:1"/>
          <ind:state state_ref="oval:ssg-state_selinux_policytype:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="The configuration file /etc/selinux/config exists for selinux_policytype" id="oval:ssg-test_selinux_policytype_config_file_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_selinux_policytype_config_file:obj:1"/>
        </unix:file_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the abrtd service is not running" id="oval:ssg-test_service_not_running_service_abrtd_disabled_abrtd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_abrtd_disabled_abrtd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_abrtd_disabled_abrtd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service abrtd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_abrtd_disabled_abrtd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_abrtd_disabled_abrtd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_abrtd_disabled_abrtd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service abrtd is not found" id="oval:ssg-test_service_not_found_service_abrtd_disabled_abrtd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_abrtd_disabled_abrtd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_abrtd_disabled_abrtd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package abrt is removed" id="oval:ssg-service_abrtd_disabled_test_service_abrtd_package_abrt_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_abrtd_disabled_test_service_abrtd_package_abrt_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the acpid service is not running" id="oval:ssg-test_service_not_running_service_acpid_disabled_acpid:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_acpid_disabled_acpid:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_acpid_disabled_acpid:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service acpid is masked" id="oval:ssg-test_service_loadstate_is_masked_service_acpid_disabled_acpid:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_acpid_disabled_acpid:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_acpid_disabled_acpid:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service acpid is not found" id="oval:ssg-test_service_not_found_service_acpid_disabled_acpid:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_acpid_disabled_acpid:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_acpid_disabled_acpid:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package acpid is removed" id="oval:ssg-service_acpid_disabled_test_service_acpid_package_acpid_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_acpid_disabled_test_service_acpid_package_acpid_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the atd service is not running" id="oval:ssg-test_service_not_running_service_atd_disabled_atd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_atd_disabled_atd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_atd_disabled_atd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service atd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_atd_disabled_atd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_atd_disabled_atd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_atd_disabled_atd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service atd is not found" id="oval:ssg-test_service_not_found_service_atd_disabled_atd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_atd_disabled_atd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_atd_disabled_atd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package at is removed" id="oval:ssg-service_atd_disabled_test_service_atd_package_at_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_atd_disabled_test_service_atd_package_at_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_auditd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_auditd_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_auditd_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_auditd_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_auditd_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_auditd_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the auditd service is running" id="oval:ssg-test_service_running_auditd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_auditd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_auditd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package audit is installed" id="oval:ssg-test_service_auditd_package_audit_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_auditd_package_audit_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the autofs service is not running" id="oval:ssg-test_service_not_running_service_autofs_disabled_autofs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_autofs_disabled_autofs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_autofs_disabled_autofs:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service autofs is masked" id="oval:ssg-test_service_loadstate_is_masked_service_autofs_disabled_autofs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_autofs_disabled_autofs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_autofs_disabled_autofs:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service autofs is not found" id="oval:ssg-test_service_not_found_service_autofs_disabled_autofs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_autofs_disabled_autofs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_autofs_disabled_autofs:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package autofs is removed" id="oval:ssg-service_autofs_disabled_test_service_autofs_package_autofs_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_autofs_disabled_test_service_autofs_package_autofs_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the avahi-daemon service is not running" id="oval:ssg-test_service_not_running_service_avahi-daemon_disabled_avahi-daemon:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_avahi-daemon_disabled_avahi-daemon:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_avahi-daemon_disabled_avahi-daemon:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service avahi-daemon is masked" id="oval:ssg-test_service_loadstate_is_masked_service_avahi-daemon_disabled_avahi-daemon:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_avahi-daemon_disabled_avahi-daemon:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_avahi-daemon_disabled_avahi-daemon:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service avahi-daemon is not found" id="oval:ssg-test_service_not_found_service_avahi-daemon_disabled_avahi-daemon:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_avahi-daemon_disabled_avahi-daemon:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_avahi-daemon_disabled_avahi-daemon:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package avahi is removed" id="oval:ssg-service_avahi-daemon_disabled_test_service_avahi-daemon_package_avahi_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_avahi-daemon_disabled_test_service_avahi-daemon_package_avahi_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the bluetooth service is not running" id="oval:ssg-test_service_not_running_service_bluetooth_disabled_bluetooth:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_bluetooth_disabled_bluetooth:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_bluetooth_disabled_bluetooth:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service bluetooth is masked" id="oval:ssg-test_service_loadstate_is_masked_service_bluetooth_disabled_bluetooth:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_bluetooth_disabled_bluetooth:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_bluetooth_disabled_bluetooth:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service bluetooth is not found" id="oval:ssg-test_service_not_found_service_bluetooth_disabled_bluetooth:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_bluetooth_disabled_bluetooth:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_bluetooth_disabled_bluetooth:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package bluez is removed" id="oval:ssg-service_bluetooth_disabled_test_service_bluetooth_package_bluez_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_bluetooth_disabled_test_service_bluetooth_package_bluez_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the certmonger service is not running" id="oval:ssg-test_service_not_running_service_certmonger_disabled_certmonger:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_certmonger_disabled_certmonger:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_certmonger_disabled_certmonger:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service certmonger is masked" id="oval:ssg-test_service_loadstate_is_masked_service_certmonger_disabled_certmonger:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_certmonger_disabled_certmonger:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_certmonger_disabled_certmonger:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service certmonger is not found" id="oval:ssg-test_service_not_found_service_certmonger_disabled_certmonger:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_certmonger_disabled_certmonger:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_certmonger_disabled_certmonger:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package certmonger is removed" id="oval:ssg-service_certmonger_disabled_test_service_certmonger_package_certmonger_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_certmonger_disabled_test_service_certmonger_package_certmonger_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_chronyd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_chronyd_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_chronyd_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_chronyd_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_chronyd_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_chronyd_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the chronyd service is running" id="oval:ssg-test_service_running_chronyd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_chronyd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_chronyd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package chrony is installed" id="oval:ssg-test_service_chronyd_package_chrony_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_chronyd_package_chrony_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the cockpit service is not running" id="oval:ssg-test_service_not_running_service_cockpit_disabled_cockpit:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_cockpit_disabled_cockpit:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_cockpit_disabled_cockpit:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service cockpit is masked" id="oval:ssg-test_service_loadstate_is_masked_service_cockpit_disabled_cockpit:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_cockpit_disabled_cockpit:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_cockpit_disabled_cockpit:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service cockpit is not found" id="oval:ssg-test_service_not_found_service_cockpit_disabled_cockpit:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_cockpit_disabled_cockpit:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_cockpit_disabled_cockpit:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package cockpit is removed" id="oval:ssg-service_cockpit_disabled_test_service_cockpit_package_cockpit_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_cockpit_disabled_test_service_cockpit_package_cockpit_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the cpupower service is not running" id="oval:ssg-test_service_not_running_service_cpupower_disabled_cpupower:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_cpupower_disabled_cpupower:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_cpupower_disabled_cpupower:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service cpupower is masked" id="oval:ssg-test_service_loadstate_is_masked_service_cpupower_disabled_cpupower:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_cpupower_disabled_cpupower:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_cpupower_disabled_cpupower:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service cpupower is not found" id="oval:ssg-test_service_not_found_service_cpupower_disabled_cpupower:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_cpupower_disabled_cpupower:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_cpupower_disabled_cpupower:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package kernel-tools is removed" id="oval:ssg-service_cpupower_disabled_test_service_cpupower_package_kernel-tools_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_cpupower_disabled_test_service_cpupower_package_kernel-tools_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_cron:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_cron_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_cron_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_cron_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_cron_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_cron_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the cron service is running" id="oval:ssg-test_service_running_cron:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_cron:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_cron:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package cron is installed" id="oval:ssg-test_service_cron_package_cron_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_cron_package_cron_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_crond:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_crond_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_crond_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_crond_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_crond_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_crond_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the crond service is running" id="oval:ssg-test_service_running_crond:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_crond:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_crond:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package cronie is installed" id="oval:ssg-test_service_crond_package_cronie_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_crond_package_cronie_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the cups service is not running" id="oval:ssg-test_service_not_running_service_cups_disabled_cups:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_cups_disabled_cups:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_cups_disabled_cups:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service cups is masked" id="oval:ssg-test_service_loadstate_is_masked_service_cups_disabled_cups:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_cups_disabled_cups:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_cups_disabled_cups:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service cups is not found" id="oval:ssg-test_service_not_found_service_cups_disabled_cups:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_cups_disabled_cups:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_cups_disabled_cups:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package cups is removed" id="oval:ssg-service_cups_disabled_test_service_cups_package_cups_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_cups_disabled_test_service_cups_package_cups_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the debug-shell service is not running" id="oval:ssg-test_service_not_running_service_debug-shell_disabled_debug-shell:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_debug-shell_disabled_debug-shell:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_debug-shell_disabled_debug-shell:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service debug-shell is masked" id="oval:ssg-test_service_loadstate_is_masked_service_debug-shell_disabled_debug-shell:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_debug-shell_disabled_debug-shell:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_debug-shell_disabled_debug-shell:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service debug-shell is not found" id="oval:ssg-test_service_not_found_service_debug-shell_disabled_debug-shell:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_debug-shell_disabled_debug-shell:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_debug-shell_disabled_debug-shell:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package systemd is removed" id="oval:ssg-service_debug-shell_disabled_test_service_debug-shell_package_systemd_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_debug-shell_disabled_test_service_debug-shell_package_systemd_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the dhcpd service is not running" id="oval:ssg-test_service_not_running_service_dhcpd_disabled_dhcpd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_dhcpd_disabled_dhcpd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_dhcpd_disabled_dhcpd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service dhcpd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_dhcpd_disabled_dhcpd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_dhcpd_disabled_dhcpd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_dhcpd_disabled_dhcpd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service dhcpd is not found" id="oval:ssg-test_service_not_found_service_dhcpd_disabled_dhcpd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_dhcpd_disabled_dhcpd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_dhcpd_disabled_dhcpd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package dhcp is removed" id="oval:ssg-service_dhcpd_disabled_test_service_dhcpd_package_dhcp_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_dhcpd_disabled_test_service_dhcpd_package_dhcp_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the dnsmasq service is not running" id="oval:ssg-test_service_not_running_service_dnsmasq_disabled_dnsmasq:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_dnsmasq_disabled_dnsmasq:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_dnsmasq_disabled_dnsmasq:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service dnsmasq is masked" id="oval:ssg-test_service_loadstate_is_masked_service_dnsmasq_disabled_dnsmasq:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_dnsmasq_disabled_dnsmasq:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_dnsmasq_disabled_dnsmasq:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service dnsmasq is not found" id="oval:ssg-test_service_not_found_service_dnsmasq_disabled_dnsmasq:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_dnsmasq_disabled_dnsmasq:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_dnsmasq_disabled_dnsmasq:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package dnsmasq is removed" id="oval:ssg-service_dnsmasq_disabled_test_service_dnsmasq_package_dnsmasq_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_dnsmasq_disabled_test_service_dnsmasq_package_dnsmasq_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the dovecot service is not running" id="oval:ssg-test_service_not_running_service_dovecot_disabled_dovecot:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_dovecot_disabled_dovecot:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_dovecot_disabled_dovecot:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service dovecot is masked" id="oval:ssg-test_service_loadstate_is_masked_service_dovecot_disabled_dovecot:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_dovecot_disabled_dovecot:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_dovecot_disabled_dovecot:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service dovecot is not found" id="oval:ssg-test_service_not_found_service_dovecot_disabled_dovecot:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_dovecot_disabled_dovecot:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_dovecot_disabled_dovecot:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package dovecot is removed" id="oval:ssg-service_dovecot_disabled_test_service_dovecot_package_dovecot_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_dovecot_disabled_test_service_dovecot_package_dovecot_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_fapolicyd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_fapolicyd_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_fapolicyd_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_fapolicyd_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_fapolicyd_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_fapolicyd_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the fapolicyd service is running" id="oval:ssg-test_service_running_fapolicyd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_fapolicyd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_fapolicyd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package fapolicyd is installed" id="oval:ssg-test_service_fapolicyd_package_fapolicyd_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_fapolicyd_package_fapolicyd_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_firewalld:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_firewalld_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_firewalld_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_firewalld_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_firewalld_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_firewalld_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the firewalld service is running" id="oval:ssg-test_service_running_firewalld:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_firewalld:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_firewalld:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package firewalld is installed" id="oval:ssg-test_service_firewalld_package_firewalld_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_firewalld_package_firewalld_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the httpd service is not running" id="oval:ssg-test_service_not_running_service_httpd_disabled_httpd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_httpd_disabled_httpd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_httpd_disabled_httpd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service httpd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_httpd_disabled_httpd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_httpd_disabled_httpd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_httpd_disabled_httpd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service httpd is not found" id="oval:ssg-test_service_not_found_service_httpd_disabled_httpd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_httpd_disabled_httpd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_httpd_disabled_httpd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package httpd is removed" id="oval:ssg-service_httpd_disabled_test_service_httpd_package_httpd_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_httpd_disabled_test_service_httpd_package_httpd_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_ip6tables:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_ip6tables_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_ip6tables_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_ip6tables_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_ip6tables_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_ip6tables_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the ip6tables service is running" id="oval:ssg-test_service_running_ip6tables:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_ip6tables:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_ip6tables:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package iptables-ipv6 is installed" id="oval:ssg-test_service_ip6tables_package_iptables-ipv6_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_ip6tables_package_iptables-ipv6_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_iptables:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_iptables_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_iptables_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_iptables_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_iptables_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_iptables_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the iptables service is running" id="oval:ssg-test_service_running_iptables:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_iptables:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_iptables:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package iptables is installed" id="oval:ssg-test_service_iptables_package_iptables_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_iptables_package_iptables_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the kdump service is not running" id="oval:ssg-test_service_not_running_service_kdump_disabled_kdump:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_kdump_disabled_kdump:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_kdump_disabled_kdump:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service kdump is masked" id="oval:ssg-test_service_loadstate_is_masked_service_kdump_disabled_kdump:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_kdump_disabled_kdump:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_kdump_disabled_kdump:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service kdump is not found" id="oval:ssg-test_service_not_found_service_kdump_disabled_kdump:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_kdump_disabled_kdump:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_kdump_disabled_kdump:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package kexec-tools is removed" id="oval:ssg-service_kdump_disabled_test_service_kdump_package_kexec-tools_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_kdump_disabled_test_service_kdump_package_kexec-tools_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the mdmonitor service is not running" id="oval:ssg-test_service_not_running_service_mdmonitor_disabled_mdmonitor:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_mdmonitor_disabled_mdmonitor:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_mdmonitor_disabled_mdmonitor:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service mdmonitor is masked" id="oval:ssg-test_service_loadstate_is_masked_service_mdmonitor_disabled_mdmonitor:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_mdmonitor_disabled_mdmonitor:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_mdmonitor_disabled_mdmonitor:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service mdmonitor is not found" id="oval:ssg-test_service_not_found_service_mdmonitor_disabled_mdmonitor:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_mdmonitor_disabled_mdmonitor:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_mdmonitor_disabled_mdmonitor:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package mdadm is removed" id="oval:ssg-service_mdmonitor_disabled_test_service_mdmonitor_package_mdadm_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_mdmonitor_disabled_test_service_mdmonitor_package_mdadm_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_nails:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_nails_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_nails_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_nails_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_nails_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_nails_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the nails service is running" id="oval:ssg-test_service_running_nails:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_nails:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_nails:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package nails is installed" id="oval:ssg-test_service_nails_package_nails_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_nails_package_nails_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the named service is not running" id="oval:ssg-test_service_not_running_service_named_disabled_named:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_named_disabled_named:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_named_disabled_named:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service named is masked" id="oval:ssg-test_service_loadstate_is_masked_service_named_disabled_named:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_named_disabled_named:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_named_disabled_named:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service named is not found" id="oval:ssg-test_service_not_found_service_named_disabled_named:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_named_disabled_named:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_named_disabled_named:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package bind is removed" id="oval:ssg-service_named_disabled_test_service_named_package_bind_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_named_disabled_test_service_named_package_bind_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the netconsole service is not running" id="oval:ssg-test_service_not_running_service_netconsole_disabled_netconsole:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_netconsole_disabled_netconsole:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_netconsole_disabled_netconsole:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service netconsole is masked" id="oval:ssg-test_service_loadstate_is_masked_service_netconsole_disabled_netconsole:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_netconsole_disabled_netconsole:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_netconsole_disabled_netconsole:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service netconsole is not found" id="oval:ssg-test_service_not_found_service_netconsole_disabled_netconsole:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_netconsole_disabled_netconsole:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_netconsole_disabled_netconsole:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package netconsole is removed" id="oval:ssg-service_netconsole_disabled_test_service_netconsole_package_netconsole_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_netconsole_disabled_test_service_netconsole_package_netconsole_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the netfs service is not running" id="oval:ssg-test_service_not_running_service_netfs_disabled_netfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_netfs_disabled_netfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_netfs_disabled_netfs:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service netfs is masked" id="oval:ssg-test_service_loadstate_is_masked_service_netfs_disabled_netfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_netfs_disabled_netfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_netfs_disabled_netfs:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service netfs is not found" id="oval:ssg-test_service_not_found_service_netfs_disabled_netfs:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_netfs_disabled_netfs:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_netfs_disabled_netfs:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package netfs is removed" id="oval:ssg-service_netfs_disabled_test_service_netfs_package_netfs_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_netfs_disabled_test_service_netfs_package_netfs_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the nfs-server service is not running" id="oval:ssg-test_service_not_running_service_nfs_disabled_nfs-server:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_nfs_disabled_nfs-server:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_nfs_disabled_nfs-server:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service nfs-server is masked" id="oval:ssg-test_service_loadstate_is_masked_service_nfs_disabled_nfs-server:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_nfs_disabled_nfs-server:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_nfs_disabled_nfs-server:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service nfs-server is not found" id="oval:ssg-test_service_not_found_service_nfs_disabled_nfs-server:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_nfs_disabled_nfs-server:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_nfs_disabled_nfs-server:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package nfs-utils is removed" id="oval:ssg-service_nfs_disabled_test_service_nfs-server_package_nfs-utils_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_nfs_disabled_test_service_nfs-server_package_nfs-utils_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the nfslock service is not running" id="oval:ssg-test_service_not_running_service_nfslock_disabled_nfslock:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_nfslock_disabled_nfslock:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_nfslock_disabled_nfslock:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service nfslock is masked" id="oval:ssg-test_service_loadstate_is_masked_service_nfslock_disabled_nfslock:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_nfslock_disabled_nfslock:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_nfslock_disabled_nfslock:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service nfslock is not found" id="oval:ssg-test_service_not_found_service_nfslock_disabled_nfslock:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_nfslock_disabled_nfslock:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_nfslock_disabled_nfslock:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package nfs-utils is removed" id="oval:ssg-service_nfslock_disabled_test_service_nfslock_package_nfs-utils_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_nfslock_disabled_test_service_nfslock_package_nfs-utils_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the nftables service is not running" id="oval:ssg-test_service_not_running_service_nftables_disabled_nftables:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_nftables_disabled_nftables:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_nftables_disabled_nftables:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service nftables is masked" id="oval:ssg-test_service_loadstate_is_masked_service_nftables_disabled_nftables:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_nftables_disabled_nftables:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_nftables_disabled_nftables:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service nftables is not found" id="oval:ssg-test_service_not_found_service_nftables_disabled_nftables:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_nftables_disabled_nftables:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_nftables_disabled_nftables:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package nftables is removed" id="oval:ssg-service_nftables_disabled_test_service_nftables_package_nftables_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_nftables_disabled_test_service_nftables_package_nftables_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_nftables:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_nftables_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_nftables_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_nftables_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_nftables_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_nftables_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the nftables service is running" id="oval:ssg-test_service_running_nftables:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_nftables:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_nftables:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package nftables is installed" id="oval:ssg-test_service_nftables_package_nftables_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_nftables_package_nftables_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_ntp:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_ntp_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_ntp_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_ntp_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_ntp_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_ntp_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the ntp service is running" id="oval:ssg-test_service_running_ntp:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_ntp:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_ntp:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package ntp is installed" id="oval:ssg-test_service_ntp_package_ntp_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_ntp_package_ntp_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_ntpd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_ntpd_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_ntpd_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_ntpd_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_ntpd_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_ntpd_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the ntpd service is running" id="oval:ssg-test_service_running_ntpd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_ntpd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_ntpd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package ntp is installed" id="oval:ssg-test_service_ntpd_package_ntp_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_ntpd_package_ntp_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the ntpdate service is not running" id="oval:ssg-test_service_not_running_service_ntpdate_disabled_ntpdate:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_ntpdate_disabled_ntpdate:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_ntpdate_disabled_ntpdate:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service ntpdate is masked" id="oval:ssg-test_service_loadstate_is_masked_service_ntpdate_disabled_ntpdate:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_ntpdate_disabled_ntpdate:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_ntpdate_disabled_ntpdate:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service ntpdate is not found" id="oval:ssg-test_service_not_found_service_ntpdate_disabled_ntpdate:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_ntpdate_disabled_ntpdate:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_ntpdate_disabled_ntpdate:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package ntpdate is removed" id="oval:ssg-service_ntpdate_disabled_test_service_ntpdate_package_ntpdate_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_ntpdate_disabled_test_service_ntpdate_package_ntpdate_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the oddjobd service is not running" id="oval:ssg-test_service_not_running_service_oddjobd_disabled_oddjobd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_oddjobd_disabled_oddjobd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_oddjobd_disabled_oddjobd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service oddjobd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_oddjobd_disabled_oddjobd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_oddjobd_disabled_oddjobd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_oddjobd_disabled_oddjobd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service oddjobd is not found" id="oval:ssg-test_service_not_found_service_oddjobd_disabled_oddjobd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_oddjobd_disabled_oddjobd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_oddjobd_disabled_oddjobd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package oddjob is removed" id="oval:ssg-service_oddjobd_disabled_test_service_oddjobd_package_oddjob_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_oddjobd_disabled_test_service_oddjobd_package_oddjob_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_pcscd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_pcscd_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_pcscd_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_pcscd_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_pcscd_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_pcscd_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the pcscd service is running" id="oval:ssg-test_service_running_pcscd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_pcscd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_pcscd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package pcsc-lite is installed" id="oval:ssg-test_service_pcscd_package_pcsc-lite_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_pcscd_package_pcsc-lite_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the portreserve service is not running" id="oval:ssg-test_service_not_running_service_portreserve_disabled_portreserve:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_portreserve_disabled_portreserve:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_portreserve_disabled_portreserve:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service portreserve is masked" id="oval:ssg-test_service_loadstate_is_masked_service_portreserve_disabled_portreserve:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_portreserve_disabled_portreserve:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_portreserve_disabled_portreserve:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service portreserve is not found" id="oval:ssg-test_service_not_found_service_portreserve_disabled_portreserve:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_portreserve_disabled_portreserve:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_portreserve_disabled_portreserve:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package portreserve is removed" id="oval:ssg-service_portreserve_disabled_test_service_portreserve_package_portreserve_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_portreserve_disabled_test_service_portreserve_package_portreserve_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_postfix:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_postfix_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_postfix_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_postfix_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_postfix_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_postfix_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the postfix service is running" id="oval:ssg-test_service_running_postfix:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_postfix:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_postfix:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package postfix is installed" id="oval:ssg-test_service_postfix_package_postfix_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_postfix_package_postfix_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_psacct:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_psacct_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_psacct_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_psacct_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_psacct_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_psacct_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the psacct service is running" id="oval:ssg-test_service_running_psacct:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_psacct:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_psacct:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package psacct is installed" id="oval:ssg-test_service_psacct_package_psacct_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_psacct_package_psacct_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the qpidd service is not running" id="oval:ssg-test_service_not_running_service_qpidd_disabled_qpidd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_qpidd_disabled_qpidd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_qpidd_disabled_qpidd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service qpidd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_qpidd_disabled_qpidd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_qpidd_disabled_qpidd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_qpidd_disabled_qpidd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service qpidd is not found" id="oval:ssg-test_service_not_found_service_qpidd_disabled_qpidd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_qpidd_disabled_qpidd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_qpidd_disabled_qpidd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package qpid-cpp-server is removed" id="oval:ssg-service_qpidd_disabled_test_service_qpidd_package_qpid-cpp-server_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_qpidd_disabled_test_service_qpidd_package_qpid-cpp-server_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the quota_nld service is not running" id="oval:ssg-test_service_not_running_service_quota_nld_disabled_quota_nld:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_quota_nld_disabled_quota_nld:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_quota_nld_disabled_quota_nld:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service quota_nld is masked" id="oval:ssg-test_service_loadstate_is_masked_service_quota_nld_disabled_quota_nld:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_quota_nld_disabled_quota_nld:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_quota_nld_disabled_quota_nld:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service quota_nld is not found" id="oval:ssg-test_service_not_found_service_quota_nld_disabled_quota_nld:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_quota_nld_disabled_quota_nld:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_quota_nld_disabled_quota_nld:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package quota-nld is removed" id="oval:ssg-service_quota_nld_disabled_test_service_quota_nld_package_quota-nld_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_quota_nld_disabled_test_service_quota_nld_package_quota-nld_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the rdisc service is not running" id="oval:ssg-test_service_not_running_service_rdisc_disabled_rdisc:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_rdisc_disabled_rdisc:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_rdisc_disabled_rdisc:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service rdisc is masked" id="oval:ssg-test_service_loadstate_is_masked_service_rdisc_disabled_rdisc:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rdisc_disabled_rdisc:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_rdisc_disabled_rdisc:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service rdisc is not found" id="oval:ssg-test_service_not_found_service_rdisc_disabled_rdisc:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rdisc_disabled_rdisc:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_rdisc_disabled_rdisc:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package iputils is removed" id="oval:ssg-service_rdisc_disabled_test_service_rdisc_package_iputils_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_rdisc_disabled_test_service_rdisc_package_iputils_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the rexec service is not running" id="oval:ssg-test_service_not_running_service_rexec_disabled_rexec:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_rexec_disabled_rexec:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_rexec_disabled_rexec:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service rexec is masked" id="oval:ssg-test_service_loadstate_is_masked_service_rexec_disabled_rexec:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rexec_disabled_rexec:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_rexec_disabled_rexec:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service rexec is not found" id="oval:ssg-test_service_not_found_service_rexec_disabled_rexec:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rexec_disabled_rexec:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_rexec_disabled_rexec:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package rsh-server is removed" id="oval:ssg-service_rexec_disabled_test_service_rexec_package_rsh-server_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_rexec_disabled_test_service_rexec_package_rsh-server_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the rhnsd service is not running" id="oval:ssg-test_service_not_running_service_rhnsd_disabled_rhnsd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_rhnsd_disabled_rhnsd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_rhnsd_disabled_rhnsd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service rhnsd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_rhnsd_disabled_rhnsd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rhnsd_disabled_rhnsd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_rhnsd_disabled_rhnsd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service rhnsd is not found" id="oval:ssg-test_service_not_found_service_rhnsd_disabled_rhnsd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rhnsd_disabled_rhnsd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_rhnsd_disabled_rhnsd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package rhnsd is removed" id="oval:ssg-service_rhnsd_disabled_test_service_rhnsd_package_rhnsd_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_rhnsd_disabled_test_service_rhnsd_package_rhnsd_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the rhsmcertd service is not running" id="oval:ssg-test_service_not_running_service_rhsmcertd_disabled_rhsmcertd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_rhsmcertd_disabled_rhsmcertd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_rhsmcertd_disabled_rhsmcertd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service rhsmcertd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_rhsmcertd_disabled_rhsmcertd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rhsmcertd_disabled_rhsmcertd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_rhsmcertd_disabled_rhsmcertd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service rhsmcertd is not found" id="oval:ssg-test_service_not_found_service_rhsmcertd_disabled_rhsmcertd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rhsmcertd_disabled_rhsmcertd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_rhsmcertd_disabled_rhsmcertd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package subscription-manager is removed" id="oval:ssg-service_rhsmcertd_disabled_test_service_rhsmcertd_package_subscription-manager_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_rhsmcertd_disabled_test_service_rhsmcertd_package_subscription-manager_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the rlogin service is not running" id="oval:ssg-test_service_not_running_service_rlogin_disabled_rlogin:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_rlogin_disabled_rlogin:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_rlogin_disabled_rlogin:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service rlogin is masked" id="oval:ssg-test_service_loadstate_is_masked_service_rlogin_disabled_rlogin:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rlogin_disabled_rlogin:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_rlogin_disabled_rlogin:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service rlogin is not found" id="oval:ssg-test_service_not_found_service_rlogin_disabled_rlogin:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rlogin_disabled_rlogin:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_rlogin_disabled_rlogin:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package rsh-server is removed" id="oval:ssg-service_rlogin_disabled_test_service_rlogin_package_rsh-server_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_rlogin_disabled_test_service_rlogin_package_rsh-server_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_rngd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_rngd_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_rngd_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_rngd_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_rngd_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_rngd_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the rngd service is running" id="oval:ssg-test_service_running_rngd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_rngd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_rngd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package rng-tools is installed" id="oval:ssg-test_service_rngd_package_rng-tools_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_rngd_package_rng-tools_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the rpcbind service is not running" id="oval:ssg-test_service_not_running_service_rpcbind_disabled_rpcbind:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_rpcbind_disabled_rpcbind:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_rpcbind_disabled_rpcbind:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service rpcbind is masked" id="oval:ssg-test_service_loadstate_is_masked_service_rpcbind_disabled_rpcbind:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rpcbind_disabled_rpcbind:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_rpcbind_disabled_rpcbind:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service rpcbind is not found" id="oval:ssg-test_service_not_found_service_rpcbind_disabled_rpcbind:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rpcbind_disabled_rpcbind:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_rpcbind_disabled_rpcbind:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package rpcbind is removed" id="oval:ssg-service_rpcbind_disabled_test_service_rpcbind_package_rpcbind_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_rpcbind_disabled_test_service_rpcbind_package_rpcbind_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the rpcgssd service is not running" id="oval:ssg-test_service_not_running_service_rpcgssd_disabled_rpcgssd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_rpcgssd_disabled_rpcgssd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_rpcgssd_disabled_rpcgssd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service rpcgssd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_rpcgssd_disabled_rpcgssd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rpcgssd_disabled_rpcgssd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_rpcgssd_disabled_rpcgssd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service rpcgssd is not found" id="oval:ssg-test_service_not_found_service_rpcgssd_disabled_rpcgssd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rpcgssd_disabled_rpcgssd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_rpcgssd_disabled_rpcgssd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package nfs-utils is removed" id="oval:ssg-service_rpcgssd_disabled_test_service_rpcgssd_package_nfs-utils_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_rpcgssd_disabled_test_service_rpcgssd_package_nfs-utils_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the rpcidmapd service is not running" id="oval:ssg-test_service_not_running_service_rpcidmapd_disabled_rpcidmapd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_rpcidmapd_disabled_rpcidmapd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_rpcidmapd_disabled_rpcidmapd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service rpcidmapd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_rpcidmapd_disabled_rpcidmapd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rpcidmapd_disabled_rpcidmapd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_rpcidmapd_disabled_rpcidmapd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service rpcidmapd is not found" id="oval:ssg-test_service_not_found_service_rpcidmapd_disabled_rpcidmapd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rpcidmapd_disabled_rpcidmapd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_rpcidmapd_disabled_rpcidmapd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package nfs-utils is removed" id="oval:ssg-service_rpcidmapd_disabled_test_service_rpcidmapd_package_nfs-utils_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_rpcidmapd_disabled_test_service_rpcidmapd_package_nfs-utils_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the rpcsvcgssd service is not running" id="oval:ssg-test_service_not_running_service_rpcsvcgssd_disabled_rpcsvcgssd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_rpcsvcgssd_disabled_rpcsvcgssd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_rpcsvcgssd_disabled_rpcsvcgssd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service rpcsvcgssd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_rpcsvcgssd_disabled_rpcsvcgssd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rpcsvcgssd_disabled_rpcsvcgssd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_rpcsvcgssd_disabled_rpcsvcgssd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service rpcsvcgssd is not found" id="oval:ssg-test_service_not_found_service_rpcsvcgssd_disabled_rpcsvcgssd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rpcsvcgssd_disabled_rpcsvcgssd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_rpcsvcgssd_disabled_rpcsvcgssd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package nfs-utils is removed" id="oval:ssg-service_rpcsvcgssd_disabled_test_service_rpcsvcgssd_package_nfs-utils_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_rpcsvcgssd_disabled_test_service_rpcsvcgssd_package_nfs-utils_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the rsh service is not running" id="oval:ssg-test_service_not_running_service_rsh_disabled_rsh:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_rsh_disabled_rsh:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_rsh_disabled_rsh:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service rsh is masked" id="oval:ssg-test_service_loadstate_is_masked_service_rsh_disabled_rsh:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rsh_disabled_rsh:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_rsh_disabled_rsh:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service rsh is not found" id="oval:ssg-test_service_not_found_service_rsh_disabled_rsh:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rsh_disabled_rsh:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_rsh_disabled_rsh:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package rsh is removed" id="oval:ssg-service_rsh_disabled_test_service_rsh_package_rsh_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_rsh_disabled_test_service_rsh_package_rsh_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the rsyncd service is not running" id="oval:ssg-test_service_not_running_service_rsyncd_disabled_rsyncd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_rsyncd_disabled_rsyncd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_rsyncd_disabled_rsyncd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service rsyncd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_rsyncd_disabled_rsyncd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rsyncd_disabled_rsyncd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_rsyncd_disabled_rsyncd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service rsyncd is not found" id="oval:ssg-test_service_not_found_service_rsyncd_disabled_rsyncd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_rsyncd_disabled_rsyncd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_rsyncd_disabled_rsyncd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package rsync-daemon is removed" id="oval:ssg-service_rsyncd_disabled_test_service_rsyncd_package_rsync-daemon_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_rsyncd_disabled_test_service_rsyncd_package_rsync-daemon_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_rsyslog:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_rsyslog_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_rsyslog_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_rsyslog_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_rsyslog_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_rsyslog_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the rsyslog service is running" id="oval:ssg-test_service_running_rsyslog:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_rsyslog:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_rsyslog:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package rsyslog is installed" id="oval:ssg-test_service_rsyslog_package_rsyslog_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_rsyslog_package_rsyslog_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the saslauthd service is not running" id="oval:ssg-test_service_not_running_service_saslauthd_disabled_saslauthd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_saslauthd_disabled_saslauthd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_saslauthd_disabled_saslauthd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service saslauthd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_saslauthd_disabled_saslauthd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_saslauthd_disabled_saslauthd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_saslauthd_disabled_saslauthd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service saslauthd is not found" id="oval:ssg-test_service_not_found_service_saslauthd_disabled_saslauthd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_saslauthd_disabled_saslauthd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_saslauthd_disabled_saslauthd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package cyrus-sasl is removed" id="oval:ssg-service_saslauthd_disabled_test_service_saslauthd_package_cyrus-sasl_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_saslauthd_disabled_test_service_saslauthd_package_cyrus-sasl_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the slapd service is not running" id="oval:ssg-test_service_not_running_service_slapd_disabled_slapd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_slapd_disabled_slapd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_slapd_disabled_slapd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service slapd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_slapd_disabled_slapd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_slapd_disabled_slapd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_slapd_disabled_slapd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service slapd is not found" id="oval:ssg-test_service_not_found_service_slapd_disabled_slapd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_slapd_disabled_slapd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_slapd_disabled_slapd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package openldap-servers is removed" id="oval:ssg-service_slapd_disabled_test_service_slapd_package_openldap-servers_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_slapd_disabled_test_service_slapd_package_openldap-servers_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the smb service is not running" id="oval:ssg-test_service_not_running_service_smb_disabled_smb:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_smb_disabled_smb:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_smb_disabled_smb:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service smb is masked" id="oval:ssg-test_service_loadstate_is_masked_service_smb_disabled_smb:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_smb_disabled_smb:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_smb_disabled_smb:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service smb is not found" id="oval:ssg-test_service_not_found_service_smb_disabled_smb:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_smb_disabled_smb:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_smb_disabled_smb:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package samba is removed" id="oval:ssg-service_smb_disabled_test_service_smb_package_samba_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_smb_disabled_test_service_smb_package_samba_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the snmpd service is not running" id="oval:ssg-test_service_not_running_service_snmpd_disabled_snmpd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_snmpd_disabled_snmpd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_snmpd_disabled_snmpd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service snmpd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_snmpd_disabled_snmpd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_snmpd_disabled_snmpd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_snmpd_disabled_snmpd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service snmpd is not found" id="oval:ssg-test_service_not_found_service_snmpd_disabled_snmpd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_snmpd_disabled_snmpd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_snmpd_disabled_snmpd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package net-snmp is removed" id="oval:ssg-service_snmpd_disabled_test_service_snmpd_package_net-snmp_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_snmpd_disabled_test_service_snmpd_package_net-snmp_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the squid service is not running" id="oval:ssg-test_service_not_running_service_squid_disabled_squid:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_squid_disabled_squid:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_squid_disabled_squid:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service squid is masked" id="oval:ssg-test_service_loadstate_is_masked_service_squid_disabled_squid:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_squid_disabled_squid:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_squid_disabled_squid:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service squid is not found" id="oval:ssg-test_service_not_found_service_squid_disabled_squid:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_squid_disabled_squid:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_squid_disabled_squid:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package squid is removed" id="oval:ssg-service_squid_disabled_test_service_squid_package_squid_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_squid_disabled_test_service_squid_package_squid_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the sshd service is not running" id="oval:ssg-test_service_not_running_service_sshd_disabled_sshd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_sshd_disabled_sshd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_sshd_disabled_sshd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service sshd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_sshd_disabled_sshd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_sshd_disabled_sshd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_sshd_disabled_sshd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service sshd is not found" id="oval:ssg-test_service_not_found_service_sshd_disabled_sshd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_sshd_disabled_sshd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_sshd_disabled_sshd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package openssh-server is removed" id="oval:ssg-service_sshd_disabled_test_service_sshd_package_openssh-server_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_sshd_disabled_test_service_sshd_package_openssh-server_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_sshd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_sshd_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_sshd_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_sshd_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_sshd_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_sshd_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the sshd service is running" id="oval:ssg-test_service_running_sshd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_sshd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_sshd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package openssh-server is installed" id="oval:ssg-test_service_sshd_package_openssh-server_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_sshd_package_openssh-server_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_sssd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_sssd_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_sssd_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_sssd_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_sssd_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_sssd_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the sssd service is running" id="oval:ssg-test_service_running_sssd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_sssd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_sssd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package sssd-common is installed" id="oval:ssg-test_service_sssd_package_sssd-common_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_sssd_package_sssd-common_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_syslog-ng:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_syslog-ng_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_syslog-ng_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_syslog-ng_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_syslog-ng_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_syslog-ng_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the syslog-ng service is running" id="oval:ssg-test_service_running_syslog-ng:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_syslog-ng:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_syslog-ng:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package syslog-ng is installed" id="oval:ssg-test_service_syslog-ng_package_syslog-ng_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_syslog-ng_package_syslog-ng_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the sysstat service is not running" id="oval:ssg-test_service_not_running_service_sysstat_disabled_sysstat:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_sysstat_disabled_sysstat:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_sysstat_disabled_sysstat:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service sysstat is masked" id="oval:ssg-test_service_loadstate_is_masked_service_sysstat_disabled_sysstat:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_sysstat_disabled_sysstat:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_sysstat_disabled_sysstat:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service sysstat is not found" id="oval:ssg-test_service_not_found_service_sysstat_disabled_sysstat:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_sysstat_disabled_sysstat:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_sysstat_disabled_sysstat:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package sysstat is removed" id="oval:ssg-service_sysstat_disabled_test_service_sysstat_package_sysstat_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_sysstat_disabled_test_service_sysstat_package_sysstat_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the systemd-coredump.socket is masked" id="oval:ssg-test_socket_loadstate_is_masked_systemd-coredump:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_socket_loadstate_is_masked_systemd-coredump:obj:1"/>
          <linux:state state_ref="oval:ssg-state_socket_loadstate_is_masked_systemd-coredump:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_systemd-journal-upload:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_systemd-journal-upload_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_systemd-journal-upload_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_systemd-journal-upload_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_systemd-journal-upload_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_systemd-journal-upload_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the systemd-journal-upload service is running" id="oval:ssg-test_service_running_systemd-journal-upload:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_systemd-journal-upload:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_systemd-journal-upload:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package systemd-journal-remote is installed" id="oval:ssg-test_service_systemd-journal-upload_package_systemd-journal-remote_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_systemd-journal-upload_package_systemd-journal-remote_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_systemd-journald:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_systemd-journald_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_systemd-journald_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_systemd-journald_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_systemd-journald_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_systemd-journald_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the systemd-journald service is running" id="oval:ssg-test_service_running_systemd-journald:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_systemd-journald:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_systemd-journald:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package systemd is installed" id="oval:ssg-test_service_systemd-journald_package_systemd_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_systemd-journald_package_systemd_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the telnet service is not running" id="oval:ssg-test_service_not_running_service_telnet_disabled_telnet:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_telnet_disabled_telnet:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_telnet_disabled_telnet:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service telnet is masked" id="oval:ssg-test_service_loadstate_is_masked_service_telnet_disabled_telnet:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_telnet_disabled_telnet:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_telnet_disabled_telnet:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service telnet is not found" id="oval:ssg-test_service_not_found_service_telnet_disabled_telnet:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_telnet_disabled_telnet:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_telnet_disabled_telnet:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package telnet-server is removed" id="oval:ssg-service_telnet_disabled_test_service_telnet_package_telnet-server_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_telnet_disabled_test_service_telnet_package_telnet-server_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the tftp service is not running" id="oval:ssg-test_service_not_running_service_tftp_disabled_tftp:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_tftp_disabled_tftp:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_tftp_disabled_tftp:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service tftp is masked" id="oval:ssg-test_service_loadstate_is_masked_service_tftp_disabled_tftp:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_tftp_disabled_tftp:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_tftp_disabled_tftp:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service tftp is not found" id="oval:ssg-test_service_not_found_service_tftp_disabled_tftp:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_tftp_disabled_tftp:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_tftp_disabled_tftp:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package tftp-server is removed" id="oval:ssg-service_tftp_disabled_test_service_tftp_package_tftp-server_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_tftp_disabled_test_service_tftp_package_tftp-server_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_ufw:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_ufw_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_ufw_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_ufw_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_ufw_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_ufw_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the ufw service is running" id="oval:ssg-test_service_running_ufw:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_ufw:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_ufw:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package ufw is installed" id="oval:ssg-test_service_ufw_package_ufw_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_ufw_package_ufw_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_usbguard:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_usbguard_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_usbguard_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_usbguard_socket:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_usbguard_socket_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_usbguard_socket_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the usbguard service is running" id="oval:ssg-test_service_running_usbguard:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_running_usbguard:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_running_usbguard:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package usbguard is installed" id="oval:ssg-test_service_usbguard_package_usbguard_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_test_service_usbguard_package_usbguard_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the vsftpd service is not running" id="oval:ssg-test_service_not_running_service_vsftpd_disabled_vsftpd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_vsftpd_disabled_vsftpd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_vsftpd_disabled_vsftpd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service vsftpd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_vsftpd_disabled_vsftpd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_vsftpd_disabled_vsftpd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_vsftpd_disabled_vsftpd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service vsftpd is not found" id="oval:ssg-test_service_not_found_service_vsftpd_disabled_vsftpd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_vsftpd_disabled_vsftpd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_vsftpd_disabled_vsftpd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package vsftpd is removed" id="oval:ssg-service_vsftpd_disabled_test_service_vsftpd_package_vsftpd_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_vsftpd_disabled_test_service_vsftpd_package_vsftpd_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the xinetd service is not running" id="oval:ssg-test_service_not_running_service_xinetd_disabled_xinetd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_xinetd_disabled_xinetd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_xinetd_disabled_xinetd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service xinetd is masked" id="oval:ssg-test_service_loadstate_is_masked_service_xinetd_disabled_xinetd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_xinetd_disabled_xinetd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_xinetd_disabled_xinetd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service xinetd is not found" id="oval:ssg-test_service_not_found_service_xinetd_disabled_xinetd:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_xinetd_disabled_xinetd:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_xinetd_disabled_xinetd:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package xinetd is removed" id="oval:ssg-service_xinetd_disabled_test_service_xinetd_package_xinetd_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_xinetd_disabled_test_service_xinetd_package_xinetd_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the ypbind service is not running" id="oval:ssg-test_service_not_running_service_ypbind_disabled_ypbind:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_ypbind_disabled_ypbind:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_ypbind_disabled_ypbind:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service ypbind is masked" id="oval:ssg-test_service_loadstate_is_masked_service_ypbind_disabled_ypbind:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_ypbind_disabled_ypbind:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_ypbind_disabled_ypbind:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service ypbind is not found" id="oval:ssg-test_service_not_found_service_ypbind_disabled_ypbind:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_ypbind_disabled_ypbind:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_ypbind_disabled_ypbind:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package ypbind is removed" id="oval:ssg-service_ypbind_disabled_test_service_ypbind_package_ypbind_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_ypbind_disabled_test_service_ypbind_package_ypbind_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the ypserv service is not running" id="oval:ssg-test_service_not_running_service_ypserv_disabled_ypserv:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_ypserv_disabled_ypserv:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_ypserv_disabled_ypserv:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service ypserv is masked" id="oval:ssg-test_service_loadstate_is_masked_service_ypserv_disabled_ypserv:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_ypserv_disabled_ypserv:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_ypserv_disabled_ypserv:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service ypserv is not found" id="oval:ssg-test_service_not_found_service_ypserv_disabled_ypserv:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_ypserv_disabled_ypserv:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_ypserv_disabled_ypserv:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package ypserv is removed" id="oval:ssg-service_ypserv_disabled_test_service_ypserv_package_ypserv_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_ypserv_disabled_test_service_ypserv_package_ypserv_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the zebra service is not running" id="oval:ssg-test_service_not_running_service_zebra_disabled_zebra:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_zebra_disabled_zebra:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_zebra_disabled_zebra:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service zebra is masked" id="oval:ssg-test_service_loadstate_is_masked_service_zebra_disabled_zebra:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_zebra_disabled_zebra:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_zebra_disabled_zebra:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service zebra is not found" id="oval:ssg-test_service_not_found_service_zebra_disabled_zebra:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_zebra_disabled_zebra:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_zebra_disabled_zebra:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package quagga is removed" id="oval:ssg-service_zebra_disabled_test_service_zebra_package_quagga_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_zebra_disabled_test_service_zebra_package_quagga_removed:obj:1"/>
        </linux:rpminfo_test>
        <ind:textfilecontent54_test check="all" comment="tests the presence of 'DefaultZone=drop' setting in the /etc/firewalld/firewalld.conf file" id="oval:ssg-test_set_firewalld_default_zone:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_set_firewalld_default_zone:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the systemd-journal-remote.socket is masked" id="oval:ssg-test_socket_loadstate_is_masked_systemd-journal-remote:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_socket_loadstate_is_masked_systemd-journal-remote:obj:1"/>
          <linux:state state_ref="oval:ssg-state_socket_loadstate_is_masked_systemd-journal-remote:ste:1"/>
        </linux:systemdunitproperty_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of Protocol setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_allow_only_protocol2:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_allow_only_protocol2:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_allow_only_protocol2:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of Protocol is present" id="oval:ssg-test_Protocol_present_sshd_allow_only_protocol2:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_allow_only_protocol2:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of Compression setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_disable_compression:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_disable_compression:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_disable_compression:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of Compression is present" id="oval:ssg-test_Compression_present_sshd_disable_compression:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_disable_compression:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of PermitEmptyPasswords setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_disable_empty_passwords:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_disable_empty_passwords:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_disable_empty_passwords:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of PermitEmptyPasswords is present" id="oval:ssg-test_PermitEmptyPasswords_present_sshd_disable_empty_passwords:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_disable_empty_passwords:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of DisableForwarding setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_disable_forwarding:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_disable_forwarding:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_disable_forwarding:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of DisableForwarding is present" id="oval:ssg-test_DisableForwarding_present_sshd_disable_forwarding:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_disable_forwarding:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of GSSAPIAuthentication setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_disable_gssapi_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_disable_gssapi_auth:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_disable_gssapi_auth:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of GSSAPIAuthentication is present" id="oval:ssg-test_GSSAPIAuthentication_present_sshd_disable_gssapi_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_disable_gssapi_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of KerberosAuthentication setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_disable_kerb_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_disable_kerb_auth:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_disable_kerb_auth:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of KerberosAuthentication is present" id="oval:ssg-test_KerberosAuthentication_present_sshd_disable_kerb_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_disable_kerb_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of PubkeyAuthentication setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_disable_pubkey_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_disable_pubkey_auth:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_disable_pubkey_auth:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of PubkeyAuthentication is present" id="oval:ssg-test_PubkeyAuthentication_present_sshd_disable_pubkey_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_disable_pubkey_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of IgnoreRhosts setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_disable_rhosts:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_disable_rhosts:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_disable_rhosts:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of IgnoreRhosts is present" id="oval:ssg-test_IgnoreRhosts_present_sshd_disable_rhosts:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_disable_rhosts:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of RhostsRSAAuthentication setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_disable_rhosts_rsa:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_disable_rhosts_rsa:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_disable_rhosts_rsa:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of RhostsRSAAuthentication is present" id="oval:ssg-test_RhostsRSAAuthentication_present_sshd_disable_rhosts_rsa:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_disable_rhosts_rsa:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of PermitRootLogin setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_disable_root_login:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_disable_root_login:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_disable_root_login:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of PermitRootLogin is present" id="oval:ssg-test_PermitRootLogin_present_sshd_disable_root_login:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_disable_root_login:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of PermitRootLogin setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_disable_root_password_login:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_disable_root_password_login:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_disable_root_password_login:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of PermitRootLogin is present" id="oval:ssg-test_PermitRootLogin_present_sshd_disable_root_password_login:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_disable_root_password_login:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of AllowTcpForwarding setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_disable_tcp_forwarding:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_disable_tcp_forwarding:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_disable_tcp_forwarding:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of AllowTcpForwarding is present" id="oval:ssg-test_AllowTcpForwarding_present_sshd_disable_tcp_forwarding:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_disable_tcp_forwarding:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of IgnoreUserKnownHosts setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_disable_user_known_hosts:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_disable_user_known_hosts:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_disable_user_known_hosts:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of IgnoreUserKnownHosts is present" id="oval:ssg-test_IgnoreUserKnownHosts_present_sshd_disable_user_known_hosts:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_disable_user_known_hosts:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of X11Forwarding setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_disable_x11_forwarding:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_disable_x11_forwarding:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_disable_x11_forwarding:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of X11Forwarding is present" id="oval:ssg-test_X11Forwarding_present_sshd_disable_x11_forwarding:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_disable_x11_forwarding:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of PermitUserEnvironment setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_do_not_permit_user_env:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_do_not_permit_user_env:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_do_not_permit_user_env:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of PermitUserEnvironment is present" id="oval:ssg-test_PermitUserEnvironment_present_sshd_do_not_permit_user_env:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_do_not_permit_user_env:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of GSSAPIAuthentication setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_enable_gssapi_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_enable_gssapi_auth:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_enable_gssapi_auth:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of GSSAPIAuthentication is present" id="oval:ssg-test_GSSAPIAuthentication_present_sshd_enable_gssapi_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_enable_gssapi_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of UsePAM setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_enable_pam:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_enable_pam:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_enable_pam:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of UsePAM is present" id="oval:ssg-test_UsePAM_present_sshd_enable_pam:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_enable_pam:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of PubkeyAuthentication setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_enable_pubkey_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_enable_pubkey_auth:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_enable_pubkey_auth:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of PubkeyAuthentication is present" id="oval:ssg-test_PubkeyAuthentication_present_sshd_enable_pubkey_auth:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_enable_pubkey_auth:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of StrictModes setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_enable_strictmodes:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_enable_strictmodes:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_enable_strictmodes:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of StrictModes is present" id="oval:ssg-test_StrictModes_present_sshd_enable_strictmodes:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_enable_strictmodes:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of Banner setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_enable_warning_banner:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_enable_warning_banner:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_enable_warning_banner:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of Banner is present" id="oval:ssg-test_Banner_present_sshd_enable_warning_banner:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_enable_warning_banner:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of Banner setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_enable_warning_banner_net:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_enable_warning_banner_net:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_enable_warning_banner_net:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of Banner is present" id="oval:ssg-test_Banner_present_sshd_enable_warning_banner_net:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_enable_warning_banner_net:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of X11Forwarding setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_enable_x11_forwarding:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_enable_x11_forwarding:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_enable_x11_forwarding:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of X11Forwarding is present" id="oval:ssg-test_X11Forwarding_present_sshd_enable_x11_forwarding:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_enable_x11_forwarding:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of PrintLastLog setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_print_last_log:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_print_last_log:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_print_last_log:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of PrintLastLog is present" id="oval:ssg-test_PrintLastLog_present_sshd_print_last_log:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_print_last_log:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of ClientAliveCountMax setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_set_keepalive:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_set_keepalive:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_set_keepalive:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of ClientAliveCountMax is present" id="oval:ssg-test_ClientAliveCountMax_present_sshd_set_keepalive:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_set_keepalive:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of ClientAliveCountMax setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_set_keepalive_0:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_set_keepalive_0:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_set_keepalive_0:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of ClientAliveCountMax is present" id="oval:ssg-test_ClientAliveCountMax_present_sshd_set_keepalive_0:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_set_keepalive_0:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of LogLevel setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_set_loglevel_info:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_set_loglevel_info:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_set_loglevel_info:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of LogLevel is present" id="oval:ssg-test_LogLevel_present_sshd_set_loglevel_info:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_set_loglevel_info:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of LogLevel setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_set_loglevel_verbose:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_set_loglevel_verbose:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_set_loglevel_verbose:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of LogLevel is present" id="oval:ssg-test_LogLevel_present_sshd_set_loglevel_verbose:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_set_loglevel_verbose:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of UsePrivilegeSeparation setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_use_priv_separation:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_use_priv_separation:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_use_priv_separation:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of UsePrivilegeSeparation is present" id="oval:ssg-test_UsePrivilegeSeparation_present_sshd_use_priv_separation:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_use_priv_separation:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="tests the value of SSH_USE_STRONG_RNG setting in the /etc/sysconfig/sshd file" id="oval:ssg-test_sshd_use_strong_rng:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_use_strong_rng:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_use_strong_rng:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="any_exist" comment="tests the value of X11UseLocalhost setting in the /etc/ssh/sshd_config file" id="oval:ssg-test_sshd_x11_use_localhost:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sshd_x11_use_localhost:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_x11_use_localhost:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify that the value of X11UseLocalhost is present" id="oval:ssg-test_X11UseLocalhost_present_sshd_x11_use_localhost:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_collection_obj_sshd_x11_use_localhost:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="tests the presence of '\[certmap\/.+\/.+\]' setting in the /etc/sssd/sssd.conf file" id="oval:ssg-test_sssd_enable_certmap:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sssd_enable_certmap:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="env_reset exists in /etc/sudoers or /etc/sudoers.d/" id="oval:ssg-test_env_reset_sudoers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_env_reset_sudoers:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="ignore_dot exists in /etc/sudoers or /etc/sudoers.d/" id="oval:ssg-test_ignore_dot_sudoers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_ignore_dot_sudoers:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="noexec exists in /etc/sudoers or /etc/sudoers.d/" id="oval:ssg-test_noexec_sudoers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_noexec_sudoers:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="passwd_timeout exists in /etc/sudoers or /etc/sudoers.d/" id="oval:ssg-test_passwd_timeout_sudoers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_passwd_timeout_sudoers:obj:1"/>
          <ind:state state_ref="oval:ssg-state_passwd_timeout_sudoers:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="requiretty exists in /etc/sudoers or /etc/sudoers.d/" id="oval:ssg-test_requiretty_sudoers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_requiretty_sudoers:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="umask exists in /etc/sudoers or /etc/sudoers.d/" id="oval:ssg-test_umask_sudoers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_umask_sudoers:obj:1"/>
          <ind:state state_ref="oval:ssg-state_umask_sudoers:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="use_pty exists in /etc/sudoers or /etc/sudoers.d/" id="oval:ssg-test_use_pty_sudoers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_use_pty_sudoers:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="logfile exists in /etc/sudoers or /etc/sudoers.d/" id="oval:ssg-test_logfile_sudoers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_logfile_sudoers:obj:1"/>
          <ind:state state_ref="oval:ssg-state_logfile_sudoers:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Testing mode of /usr/bin/sudo" id="oval:ssg-test_file_permissionssudo_restrict_others_executable_permission_0:tst:1" state_operator="AND" version="3">
          <unix:object object_ref="oval:ssg-object_file_permissionssudo_restrict_others_executable_permission_0:obj:1"/>
        </unix:file_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter fs.protected_hardlinks set to 1" id="oval:ssg-test_sysctl_fs_protected_hardlinks_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_fs_protected_hardlinks_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_fs_protected_hardlinks_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="fs.protected_hardlinks static configuration" id="oval:ssg-test_sysctl_fs_protected_hardlinks_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_fs_protected_hardlinks:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="fs.protected_hardlinks static configuration" id="oval:ssg-test_sysctl_fs_protected_hardlinks_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_fs_protected_hardlinks:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_fs_protected_hardlinks:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="fs.protected_hardlinks static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_fs_protected_hardlinks_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_fs_protected_hardlinks:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_fs_protected_hardlinks:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter fs.protected_symlinks set to 1" id="oval:ssg-test_sysctl_fs_protected_symlinks_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_fs_protected_symlinks_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_fs_protected_symlinks_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="fs.protected_symlinks static configuration" id="oval:ssg-test_sysctl_fs_protected_symlinks_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_fs_protected_symlinks:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="fs.protected_symlinks static configuration" id="oval:ssg-test_sysctl_fs_protected_symlinks_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_fs_protected_symlinks:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_fs_protected_symlinks:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="fs.protected_symlinks static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_fs_protected_symlinks_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_fs_protected_symlinks:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_fs_protected_symlinks:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter fs.suid_dumpable set to 0" id="oval:ssg-test_sysctl_fs_suid_dumpable_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_fs_suid_dumpable_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_fs_suid_dumpable_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="fs.suid_dumpable static configuration" id="oval:ssg-test_sysctl_fs_suid_dumpable_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_fs_suid_dumpable:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="fs.suid_dumpable static configuration" id="oval:ssg-test_sysctl_fs_suid_dumpable_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_fs_suid_dumpable:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_fs_suid_dumpable:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="fs.suid_dumpable static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_fs_suid_dumpable_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_fs_suid_dumpable:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_fs_suid_dumpable:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter kernel.core_pattern set to |/bin/false" id="oval:ssg-test_sysctl_kernel_core_pattern_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_kernel_core_pattern_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_kernel_core_pattern_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="kernel.core_pattern static configuration" id="oval:ssg-test_sysctl_kernel_core_pattern_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_core_pattern:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.core_pattern static configuration" id="oval:ssg-test_sysctl_kernel_core_pattern_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_core_pattern:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_core_pattern:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.core_pattern static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_kernel_core_pattern_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_core_pattern:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_core_pattern:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter kernel.core_uses_pid set to 0" id="oval:ssg-test_sysctl_kernel_core_uses_pid_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_kernel_core_uses_pid_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_kernel_core_uses_pid_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="kernel.core_uses_pid static configuration" id="oval:ssg-test_sysctl_kernel_core_uses_pid_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_core_uses_pid:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.core_uses_pid static configuration" id="oval:ssg-test_sysctl_kernel_core_uses_pid_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_core_uses_pid:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_core_uses_pid:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.core_uses_pid static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_kernel_core_uses_pid_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_core_uses_pid:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_core_uses_pid:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter kernel.dmesg_restrict set to 1" id="oval:ssg-test_sysctl_kernel_dmesg_restrict_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_kernel_dmesg_restrict_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_kernel_dmesg_restrict_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="kernel.dmesg_restrict static configuration" id="oval:ssg-test_sysctl_kernel_dmesg_restrict_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_dmesg_restrict:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.dmesg_restrict static configuration" id="oval:ssg-test_sysctl_kernel_dmesg_restrict_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_dmesg_restrict:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_dmesg_restrict:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.dmesg_restrict static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_kernel_dmesg_restrict_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_dmesg_restrict:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_dmesg_restrict:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter kernel.kexec_load_disabled set to 1" id="oval:ssg-test_sysctl_kernel_kexec_load_disabled_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_kernel_kexec_load_disabled_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_kernel_kexec_load_disabled_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="kernel.kexec_load_disabled static configuration" id="oval:ssg-test_sysctl_kernel_kexec_load_disabled_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_kexec_load_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.kexec_load_disabled static configuration" id="oval:ssg-test_sysctl_kernel_kexec_load_disabled_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_kexec_load_disabled:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_kexec_load_disabled:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.kexec_load_disabled static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_kernel_kexec_load_disabled_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_kexec_load_disabled:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_kexec_load_disabled:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter kernel.kptr_restrict set to 1" id="oval:ssg-test_sysctl_kernel_kptr_restrict_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_kernel_kptr_restrict_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_kernel_kptr_restrict_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="kernel.kptr_restrict static configuration" id="oval:ssg-test_sysctl_kernel_kptr_restrict_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_kptr_restrict:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.kptr_restrict static configuration" id="oval:ssg-test_sysctl_kernel_kptr_restrict_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_kptr_restrict:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_kptr_restrict:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.kptr_restrict static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_kernel_kptr_restrict_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_kptr_restrict:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_kptr_restrict:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter kernel.modules_disabled set to 1" id="oval:ssg-test_sysctl_kernel_modules_disabled_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_kernel_modules_disabled_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_kernel_modules_disabled_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="kernel.modules_disabled static configuration" id="oval:ssg-test_sysctl_kernel_modules_disabled_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_modules_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.modules_disabled static configuration" id="oval:ssg-test_sysctl_kernel_modules_disabled_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_modules_disabled:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_modules_disabled:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.modules_disabled static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_kernel_modules_disabled_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_modules_disabled:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_modules_disabled:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter kernel.panic_on_oops set to 1" id="oval:ssg-test_sysctl_kernel_panic_on_oops_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_kernel_panic_on_oops_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_kernel_panic_on_oops_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="kernel.panic_on_oops static configuration" id="oval:ssg-test_sysctl_kernel_panic_on_oops_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_panic_on_oops:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.panic_on_oops static configuration" id="oval:ssg-test_sysctl_kernel_panic_on_oops_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_panic_on_oops:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_panic_on_oops:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.panic_on_oops static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_kernel_panic_on_oops_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_panic_on_oops:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_panic_on_oops:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter kernel.perf_cpu_time_max_percent set to 1" id="oval:ssg-test_sysctl_kernel_perf_cpu_time_max_percent_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_kernel_perf_cpu_time_max_percent_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_kernel_perf_cpu_time_max_percent_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="kernel.perf_cpu_time_max_percent static configuration" id="oval:ssg-test_sysctl_kernel_perf_cpu_time_max_percent_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_perf_cpu_time_max_percent:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.perf_cpu_time_max_percent static configuration" id="oval:ssg-test_sysctl_kernel_perf_cpu_time_max_percent_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_perf_cpu_time_max_percent:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_perf_cpu_time_max_percent:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.perf_cpu_time_max_percent static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_kernel_perf_cpu_time_max_percent_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_perf_cpu_time_max_percent:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_perf_cpu_time_max_percent:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter kernel.perf_event_max_sample_rate set to 1" id="oval:ssg-test_sysctl_kernel_perf_event_max_sample_rate_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_kernel_perf_event_max_sample_rate_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_kernel_perf_event_max_sample_rate_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="kernel.perf_event_max_sample_rate static configuration" id="oval:ssg-test_sysctl_kernel_perf_event_max_sample_rate_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_perf_event_max_sample_rate:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.perf_event_max_sample_rate static configuration" id="oval:ssg-test_sysctl_kernel_perf_event_max_sample_rate_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_perf_event_max_sample_rate:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_perf_event_max_sample_rate:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.perf_event_max_sample_rate static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_kernel_perf_event_max_sample_rate_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_perf_event_max_sample_rate:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_perf_event_max_sample_rate:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter kernel.perf_event_paranoid set to 2" id="oval:ssg-test_sysctl_kernel_perf_event_paranoid_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_kernel_perf_event_paranoid_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_kernel_perf_event_paranoid_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="kernel.perf_event_paranoid static configuration" id="oval:ssg-test_sysctl_kernel_perf_event_paranoid_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_perf_event_paranoid:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.perf_event_paranoid static configuration" id="oval:ssg-test_sysctl_kernel_perf_event_paranoid_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_perf_event_paranoid:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_perf_event_paranoid:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.perf_event_paranoid static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_kernel_perf_event_paranoid_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_perf_event_paranoid:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_perf_event_paranoid:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter kernel.pid_max set to 65536" id="oval:ssg-test_sysctl_kernel_pid_max_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_kernel_pid_max_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_kernel_pid_max_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="kernel.pid_max static configuration" id="oval:ssg-test_sysctl_kernel_pid_max_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_pid_max:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.pid_max static configuration" id="oval:ssg-test_sysctl_kernel_pid_max_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_pid_max:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_pid_max:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.pid_max static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_kernel_pid_max_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_pid_max:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_pid_max:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter kernel.randomize_va_space set to 2" id="oval:ssg-test_sysctl_kernel_randomize_va_space_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_kernel_randomize_va_space_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_kernel_randomize_va_space_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="kernel.randomize_va_space static configuration" id="oval:ssg-test_sysctl_kernel_randomize_va_space_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_randomize_va_space:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.randomize_va_space static configuration" id="oval:ssg-test_sysctl_kernel_randomize_va_space_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_randomize_va_space:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_randomize_va_space:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.randomize_va_space static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_kernel_randomize_va_space_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_randomize_va_space:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_randomize_va_space:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter kernel.sysrq set to 0" id="oval:ssg-test_sysctl_kernel_sysrq_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_kernel_sysrq_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_kernel_sysrq_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="kernel.sysrq static configuration" id="oval:ssg-test_sysctl_kernel_sysrq_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_sysrq:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.sysrq static configuration" id="oval:ssg-test_sysctl_kernel_sysrq_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_sysrq:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_sysrq:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.sysrq static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_kernel_sysrq_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_sysrq:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_sysrq:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter kernel.unprivileged_bpf_disabled set to 1" id="oval:ssg-test_sysctl_kernel_unprivileged_bpf_disabled_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_kernel_unprivileged_bpf_disabled_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_kernel_unprivileged_bpf_disabled_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="kernel.unprivileged_bpf_disabled static configuration" id="oval:ssg-test_sysctl_kernel_unprivileged_bpf_disabled_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_unprivileged_bpf_disabled:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.unprivileged_bpf_disabled static configuration" id="oval:ssg-test_sysctl_kernel_unprivileged_bpf_disabled_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_unprivileged_bpf_disabled:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_unprivileged_bpf_disabled:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.unprivileged_bpf_disabled static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_kernel_unprivileged_bpf_disabled_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_unprivileged_bpf_disabled:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_unprivileged_bpf_disabled:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter kernel.yama.ptrace_scope set to 1" id="oval:ssg-test_sysctl_kernel_yama_ptrace_scope_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_kernel_yama_ptrace_scope_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_kernel_yama_ptrace_scope_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="kernel.yama.ptrace_scope static configuration" id="oval:ssg-test_sysctl_kernel_yama_ptrace_scope_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_yama_ptrace_scope:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.yama.ptrace_scope static configuration" id="oval:ssg-test_sysctl_kernel_yama_ptrace_scope_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_yama_ptrace_scope:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_yama_ptrace_scope:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="kernel.yama.ptrace_scope static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_kernel_yama_ptrace_scope_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_yama_ptrace_scope:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_yama_ptrace_scope:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.core.bpf_jit_harden set to 2" id="oval:ssg-test_sysctl_net_core_bpf_jit_harden_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_core_bpf_jit_harden_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_core_bpf_jit_harden_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.core.bpf_jit_harden static configuration" id="oval:ssg-test_sysctl_net_core_bpf_jit_harden_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_core_bpf_jit_harden:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.core.bpf_jit_harden static configuration" id="oval:ssg-test_sysctl_net_core_bpf_jit_harden_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_core_bpf_jit_harden:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_core_bpf_jit_harden:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.core.bpf_jit_harden static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_core_bpf_jit_harden_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_core_bpf_jit_harden:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_core_bpf_jit_harden:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.all.accept_local set to 0" id="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_local_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_all_accept_local_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_all_accept_local_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.all.accept_local static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_local_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_accept_local:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.accept_local static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_local_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_accept_local:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_accept_local:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.accept_local static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_local_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_accept_local:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_accept_local:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.all.accept_redirects set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_redirects_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_all_accept_redirects_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_all_accept_redirects_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.all.accept_redirects static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_redirects_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_accept_redirects:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.accept_redirects static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_redirects_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_accept_redirects:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_accept_redirects:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.accept_redirects static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_redirects_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_accept_redirects:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_accept_redirects:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.all.accept_source_route set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_source_route_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_all_accept_source_route_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_all_accept_source_route_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.all.accept_source_route static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_source_route_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_accept_source_route:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.accept_source_route static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_source_route_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_accept_source_route:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_accept_source_route:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.accept_source_route static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_all_accept_source_route_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_accept_source_route:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_accept_source_route:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.all.arp_filter set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_conf_all_arp_filter_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_all_arp_filter_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_all_arp_filter_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.all.arp_filter static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_arp_filter_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_arp_filter:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.arp_filter static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_arp_filter_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_arp_filter:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_arp_filter:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.arp_filter static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_all_arp_filter_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_arp_filter:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_arp_filter:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.all.arp_ignore set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_conf_all_arp_ignore_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_all_arp_ignore_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_all_arp_ignore_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.all.arp_ignore static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_arp_ignore_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_arp_ignore:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.arp_ignore static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_arp_ignore_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_arp_ignore:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_arp_ignore:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.arp_ignore static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_all_arp_ignore_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_arp_ignore:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_arp_ignore:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.all.drop_gratuitous_arp set to 1" id="oval:ssg-test_sysctl_net_ipv4_conf_all_drop_gratuitous_arp_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_all_drop_gratuitous_arp_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_all_drop_gratuitous_arp_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.all.drop_gratuitous_arp static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_drop_gratuitous_arp_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.drop_gratuitous_arp static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_drop_gratuitous_arp_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.drop_gratuitous_arp static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_all_drop_gratuitous_arp_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.all.forwarding set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_conf_all_forwarding_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_all_forwarding_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_all_forwarding_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.all.forwarding static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_forwarding_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_forwarding:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.forwarding static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_forwarding_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_forwarding:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_forwarding:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.forwarding static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_all_forwarding_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_forwarding:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_forwarding:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.all.log_martians set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_conf_all_log_martians_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_all_log_martians_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_all_log_martians_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.all.log_martians static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_log_martians_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_log_martians:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.log_martians static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_log_martians_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_log_martians:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_log_martians:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.log_martians static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_all_log_martians_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_log_martians:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_log_martians:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.all.route_localnet set to 0" id="oval:ssg-test_sysctl_net_ipv4_conf_all_route_localnet_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_all_route_localnet_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_all_route_localnet_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.all.route_localnet static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_route_localnet_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_route_localnet:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.route_localnet static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_route_localnet_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_route_localnet:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_route_localnet:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.route_localnet static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_all_route_localnet_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_route_localnet:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_route_localnet:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.all.rp_filter set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_conf_all_rp_filter_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_all_rp_filter_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_all_rp_filter_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.all.rp_filter static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_rp_filter_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_rp_filter:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.rp_filter static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_rp_filter_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_rp_filter:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_rp_filter:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.rp_filter static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_all_rp_filter_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_rp_filter:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_rp_filter:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.all.secure_redirects set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_conf_all_secure_redirects_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_all_secure_redirects_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_all_secure_redirects_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.all.secure_redirects static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_secure_redirects_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_secure_redirects:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.secure_redirects static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_secure_redirects_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_secure_redirects:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_secure_redirects:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.secure_redirects static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_all_secure_redirects_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_secure_redirects:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_secure_redirects:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.all.send_redirects set to 0" id="oval:ssg-test_sysctl_net_ipv4_conf_all_send_redirects_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_all_send_redirects_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_all_send_redirects_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.all.send_redirects static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_send_redirects_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_send_redirects:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.send_redirects static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_send_redirects_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_send_redirects:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_send_redirects:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.send_redirects static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_all_send_redirects_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_send_redirects:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_send_redirects:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.all.shared_media set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_conf_all_shared_media_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_all_shared_media_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_all_shared_media_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.all.shared_media static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_shared_media_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_shared_media:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.shared_media static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_all_shared_media_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_shared_media:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_shared_media:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.all.shared_media static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_all_shared_media_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_shared_media:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_shared_media:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.default.accept_redirects set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_conf_default_accept_redirects_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_default_accept_redirects_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_default_accept_redirects_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.default.accept_redirects static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_default_accept_redirects_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_accept_redirects:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.default.accept_redirects static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_default_accept_redirects_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_accept_redirects:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_accept_redirects:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.default.accept_redirects static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_default_accept_redirects_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_default_accept_redirects:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_accept_redirects:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.default.accept_source_route set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_conf_default_accept_source_route_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_default_accept_source_route_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_default_accept_source_route_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.default.accept_source_route static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_default_accept_source_route_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_accept_source_route:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.default.accept_source_route static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_default_accept_source_route_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_accept_source_route:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_accept_source_route:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.default.accept_source_route static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_default_accept_source_route_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_default_accept_source_route:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_accept_source_route:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.default.forwarding set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_conf_default_forwarding_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_default_forwarding_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_default_forwarding_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.default.forwarding static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_default_forwarding_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_forwarding:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.default.forwarding static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_default_forwarding_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_forwarding:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_forwarding:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.default.forwarding static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_default_forwarding_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_default_forwarding:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_forwarding:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.default.log_martians set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_conf_default_log_martians_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_default_log_martians_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_default_log_martians_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.default.log_martians static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_default_log_martians_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_log_martians:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.default.log_martians static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_default_log_martians_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_log_martians:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_log_martians:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.default.log_martians static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_default_log_martians_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_default_log_martians:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_log_martians:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.default.rp_filter set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_conf_default_rp_filter_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_default_rp_filter_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_default_rp_filter_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.default.rp_filter static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_default_rp_filter_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_rp_filter:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.default.rp_filter static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_default_rp_filter_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_rp_filter:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_rp_filter:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.default.rp_filter static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_default_rp_filter_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_default_rp_filter:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_rp_filter:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.default.secure_redirects set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_conf_default_secure_redirects_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_default_secure_redirects_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_default_secure_redirects_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.default.secure_redirects static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_default_secure_redirects_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_secure_redirects:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.default.secure_redirects static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_default_secure_redirects_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_secure_redirects:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_secure_redirects:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.default.secure_redirects static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_default_secure_redirects_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_default_secure_redirects:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_secure_redirects:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.default.send_redirects set to 0" id="oval:ssg-test_sysctl_net_ipv4_conf_default_send_redirects_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_default_send_redirects_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_default_send_redirects_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.default.send_redirects static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_default_send_redirects_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_send_redirects:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.default.send_redirects static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_default_send_redirects_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_send_redirects:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_send_redirects:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.default.send_redirects static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_default_send_redirects_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_default_send_redirects:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_send_redirects:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.conf.default.shared_media set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_conf_default_shared_media_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_conf_default_shared_media_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_conf_default_shared_media_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.conf.default.shared_media static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_default_shared_media_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_shared_media:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.default.shared_media static configuration" id="oval:ssg-test_sysctl_net_ipv4_conf_default_shared_media_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_shared_media:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_shared_media:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.conf.default.shared_media static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_conf_default_shared_media_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_default_shared_media:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_shared_media:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.icmp_echo_ignore_broadcasts set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.icmp_echo_ignore_broadcasts static configuration" id="oval:ssg-test_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.icmp_echo_ignore_broadcasts static configuration" id="oval:ssg-test_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.icmp_echo_ignore_broadcasts static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.icmp_ignore_bogus_error_responses set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.icmp_ignore_bogus_error_responses static configuration" id="oval:ssg-test_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.icmp_ignore_bogus_error_responses static configuration" id="oval:ssg-test_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.icmp_ignore_bogus_error_responses static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.ip_forward set to 0" id="oval:ssg-test_sysctl_net_ipv4_ip_forward_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_ip_forward_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_ip_forward_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.ip_forward static configuration" id="oval:ssg-test_sysctl_net_ipv4_ip_forward_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_ip_forward:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.ip_forward static configuration" id="oval:ssg-test_sysctl_net_ipv4_ip_forward_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_ip_forward:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_ip_forward:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.ip_forward static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_ip_forward_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_ip_forward:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_ip_forward:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.ip_local_port_range set to 32768 65535" id="oval:ssg-test_sysctl_net_ipv4_ip_local_port_range_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_ip_local_port_range_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_ip_local_port_range_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.ip_local_port_range static configuration" id="oval:ssg-test_sysctl_net_ipv4_ip_local_port_range_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_ip_local_port_range:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.ip_local_port_range static configuration" id="oval:ssg-test_sysctl_net_ipv4_ip_local_port_range_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_ip_local_port_range:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_ip_local_port_range:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.ip_local_port_range static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_ip_local_port_range_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_ip_local_port_range:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_ip_local_port_range:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.tcp_invalid_ratelimit set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_tcp_invalid_ratelimit_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_tcp_invalid_ratelimit_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_tcp_invalid_ratelimit_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.tcp_invalid_ratelimit static configuration" id="oval:ssg-test_sysctl_net_ipv4_tcp_invalid_ratelimit_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.tcp_invalid_ratelimit static configuration" id="oval:ssg-test_sysctl_net_ipv4_tcp_invalid_ratelimit_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_tcp_invalid_ratelimit:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.tcp_invalid_ratelimit static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_tcp_invalid_ratelimit_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_tcp_invalid_ratelimit:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.tcp_rfc1337 set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_tcp_rfc1337_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_tcp_rfc1337_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_tcp_rfc1337_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.tcp_rfc1337 static configuration" id="oval:ssg-test_sysctl_net_ipv4_tcp_rfc1337_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_tcp_rfc1337:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.tcp_rfc1337 static configuration" id="oval:ssg-test_sysctl_net_ipv4_tcp_rfc1337_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_tcp_rfc1337:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_tcp_rfc1337:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.tcp_rfc1337 static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_tcp_rfc1337_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_tcp_rfc1337:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_tcp_rfc1337:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv4.tcp_syncookies set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv4_tcp_syncookies_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_tcp_syncookies_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_tcp_syncookies_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv4.tcp_syncookies static configuration" id="oval:ssg-test_sysctl_net_ipv4_tcp_syncookies_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_tcp_syncookies:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.tcp_syncookies static configuration" id="oval:ssg-test_sysctl_net_ipv4_tcp_syncookies_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_tcp_syncookies:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_tcp_syncookies:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv4.tcp_syncookies static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv4_tcp_syncookies_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_tcp_syncookies:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.all.accept_ra set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_all_accept_ra_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_all_accept_ra_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.all.accept_ra static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_ra:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.accept_ra static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_ra:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_ra:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.accept_ra static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_ra:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.all.accept_ra_defrtr set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_defrtr_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_all_accept_ra_defrtr_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_all_accept_ra_defrtr_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.all.accept_ra_defrtr static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_defrtr_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.accept_ra_defrtr static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_defrtr_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_ra_defrtr:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.accept_ra_defrtr static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_defrtr_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_ra_defrtr:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.all.accept_ra_pinfo set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_pinfo_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_all_accept_ra_pinfo_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_all_accept_ra_pinfo_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.all.accept_ra_pinfo static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_pinfo_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.accept_ra_pinfo static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_pinfo_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_ra_pinfo:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.accept_ra_pinfo static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_pinfo_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_ra_pinfo:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.all.accept_ra_rtr_pref set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.all.accept_ra_rtr_pref static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.accept_ra_rtr_pref static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.accept_ra_rtr_pref static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.all.accept_redirects set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_redirects_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_all_accept_redirects_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_all_accept_redirects_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.all.accept_redirects static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_redirects_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_redirects:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.accept_redirects static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_redirects_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_redirects:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_redirects:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.accept_redirects static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_redirects_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_accept_redirects:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_redirects:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.all.accept_source_route set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_source_route_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_all_accept_source_route_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_all_accept_source_route_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.all.accept_source_route static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_source_route_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_source_route:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.accept_source_route static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_source_route_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_source_route:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_source_route:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.accept_source_route static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_all_accept_source_route_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_accept_source_route:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_source_route:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.all.autoconf set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_all_autoconf_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_all_autoconf_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_all_autoconf_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.all.autoconf static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_autoconf_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_autoconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.autoconf static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_autoconf_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_autoconf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_autoconf:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.autoconf static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_all_autoconf_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_autoconf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_autoconf:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.all.disable_ipv6 set to 1" id="oval:ssg-test_sysctl_net_ipv6_conf_all_disable_ipv6_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_all_disable_ipv6_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_all_disable_ipv6_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.all.disable_ipv6 static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_disable_ipv6_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.disable_ipv6 static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_disable_ipv6_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_disable_ipv6:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.disable_ipv6 static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_all_disable_ipv6_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_disable_ipv6:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.all.forwarding set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_all_forwarding_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_all_forwarding_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_all_forwarding_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.all.forwarding static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_forwarding_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_forwarding:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.forwarding static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_forwarding_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_forwarding:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_forwarding:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.forwarding static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_all_forwarding_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_forwarding:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_forwarding:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.all.max_addresses set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_all_max_addresses_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_all_max_addresses_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_all_max_addresses_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.all.max_addresses static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_max_addresses_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_max_addresses:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.max_addresses static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_max_addresses_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_max_addresses:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_max_addresses:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.max_addresses static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_all_max_addresses_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_max_addresses:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_max_addresses:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.all.router_solicitations set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_all_router_solicitations_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_all_router_solicitations_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_all_router_solicitations_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.all.router_solicitations static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_router_solicitations_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_router_solicitations:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.router_solicitations static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_all_router_solicitations_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_router_solicitations:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_router_solicitations:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.all.router_solicitations static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_all_router_solicitations_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_router_solicitations:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_router_solicitations:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.default.accept_ra set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_default_accept_ra_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_default_accept_ra_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.default.accept_ra static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_ra:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.accept_ra static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_ra:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_ra:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.accept_ra static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_ra:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.default.accept_ra_defrtr set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_defrtr_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_default_accept_ra_defrtr_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_default_accept_ra_defrtr_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.default.accept_ra_defrtr static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_defrtr_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.accept_ra_defrtr static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_defrtr_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_ra_defrtr:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.accept_ra_defrtr static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_defrtr_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_ra_defrtr:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.default.accept_ra_pinfo set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_pinfo_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_default_accept_ra_pinfo_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_default_accept_ra_pinfo_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.default.accept_ra_pinfo static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_pinfo_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.accept_ra_pinfo static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_pinfo_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_ra_pinfo:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.accept_ra_pinfo static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_pinfo_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_ra_pinfo:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.default.accept_ra_rtr_pref set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.default.accept_ra_rtr_pref static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.accept_ra_rtr_pref static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.accept_ra_rtr_pref static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.default.accept_redirects set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_redirects_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_default_accept_redirects_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_default_accept_redirects_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.default.accept_redirects static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_redirects_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_redirects:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.accept_redirects static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_redirects_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_redirects:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_redirects:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.accept_redirects static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_redirects_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_accept_redirects:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_redirects:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.default.accept_source_route set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_source_route_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_default_accept_source_route_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_default_accept_source_route_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.default.accept_source_route static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_source_route_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_source_route:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.accept_source_route static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_source_route_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_source_route:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_source_route:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.accept_source_route static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_default_accept_source_route_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_accept_source_route:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_source_route:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.default.autoconf set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_default_autoconf_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_default_autoconf_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_default_autoconf_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.default.autoconf static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_autoconf_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_autoconf:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.autoconf static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_autoconf_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_autoconf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_autoconf:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.autoconf static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_default_autoconf_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_autoconf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_autoconf:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.default.disable_ipv6 set to 1" id="oval:ssg-test_sysctl_net_ipv6_conf_default_disable_ipv6_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_default_disable_ipv6_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_default_disable_ipv6_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.default.disable_ipv6 static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_disable_ipv6_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.disable_ipv6 static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_disable_ipv6_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_disable_ipv6:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.disable_ipv6 static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_default_disable_ipv6_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_disable_ipv6:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.default.forwarding set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_default_forwarding_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_default_forwarding_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_default_forwarding_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.default.forwarding static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_forwarding_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_forwarding:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.forwarding static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_forwarding_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_forwarding:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_forwarding:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.forwarding static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_default_forwarding_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_forwarding:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_forwarding:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.default.max_addresses set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_default_max_addresses_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_default_max_addresses_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_default_max_addresses_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.default.max_addresses static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_max_addresses_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_max_addresses:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.max_addresses static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_max_addresses_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_max_addresses:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_max_addresses:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.max_addresses static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_default_max_addresses_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_max_addresses:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_max_addresses:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter net.ipv6.conf.default.router_solicitations set to the appropriate value" id="oval:ssg-test_sysctl_net_ipv6_conf_default_router_solicitations_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_net_ipv6_conf_default_router_solicitations_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_net_ipv6_conf_default_router_solicitations_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="net.ipv6.conf.default.router_solicitations static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_router_solicitations_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_router_solicitations:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.router_solicitations static configuration" id="oval:ssg-test_sysctl_net_ipv6_conf_default_router_solicitations_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_router_solicitations:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_router_solicitations:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="net.ipv6.conf.default.router_solicitations static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_net_ipv6_conf_default_router_solicitations_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_router_solicitations:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_router_solicitations:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter user.max_user_namespaces set to 0" id="oval:ssg-test_sysctl_user_max_user_namespaces_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_user_max_user_namespaces_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_user_max_user_namespaces_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="user.max_user_namespaces static configuration" id="oval:ssg-test_sysctl_user_max_user_namespaces_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_user_max_user_namespaces:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="user.max_user_namespaces static configuration" id="oval:ssg-test_sysctl_user_max_user_namespaces_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_user_max_user_namespaces:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_user_max_user_namespaces:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="user.max_user_namespaces static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_user_max_user_namespaces_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_user_max_user_namespaces:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_user_max_user_namespaces:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter user.max_user_namespaces set to 0" id="oval:ssg-test_sysctl_user_max_user_namespaces_no_remediation_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_user_max_user_namespaces_no_remediation_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_user_max_user_namespaces_no_remediation_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="user.max_user_namespaces static configuration" id="oval:ssg-test_sysctl_user_max_user_namespaces_no_remediation_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_user_max_user_namespaces_no_remediation:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="user.max_user_namespaces static configuration" id="oval:ssg-test_sysctl_user_max_user_namespaces_no_remediation_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_user_max_user_namespaces_no_remediation:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_user_max_user_namespaces_no_remediation:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="user.max_user_namespaces static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_user_max_user_namespaces_no_remediation_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_user_max_user_namespaces_no_remediation:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_user_max_user_namespaces_no_remediation:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter vm.mmap_min_addr set to 65536" id="oval:ssg-test_sysctl_vm_mmap_min_addr_runtime:tst:1" state_operator="OR" version="1">
          <unix:object object_ref="oval:ssg-object_sysctl_vm_mmap_min_addr_runtime:obj:1"/>
          <unix:state state_ref="oval:ssg-state_sysctl_vm_mmap_min_addr_runtime:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="vm.mmap_min_addr static configuration" id="oval:ssg-test_sysctl_vm_mmap_min_addr_static_user_missing:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_vm_mmap_min_addr:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="vm.mmap_min_addr static configuration" id="oval:ssg-test_sysctl_vm_mmap_min_addr_static_user:tst:1" state_operator="OR" version="1">
          <ind:object object_ref="oval:ssg-object_static_user_sysctl_vm_mmap_min_addr:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_vm_mmap_min_addr:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="vm.mmap_min_addr static configuration in /usr/lib/sysctl.d/*.conf" id="oval:ssg-test_sysctl_vm_mmap_min_addr_static_pkg_correct:tst:1" state_operator="OR" version="2">
          <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_vm_mmap_min_addr:obj:1"/>
          <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_vm_mmap_min_addr:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_tmp:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_tmp_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_tmp_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the tmp mount is running" id="oval:ssg-test_mount_running_tmp:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_mount_running_tmp:obj:1"/>
          <linux:state state_ref="oval:ssg-state_mount_running_tmp:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_dnf-automatic:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_dnf-automatic_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_dnf-automatic_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the dnf-automatic timer is running" id="oval:ssg-test_timer_running_dnf-automatic:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_timer_running_dnf-automatic:obj:1"/>
          <linux:state state_ref="oval:ssg-state_timer_running_dnf-automatic:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitdependency_test check="all" check_existence="any_exist" comment="systemd test" id="oval:ssg-test_multi_user_wants_logrotate:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_multi_user_target_for_logrotate_enabled:obj:1"/>
          <linux:state state_ref="oval:ssg-state_systemd_logrotate_on:ste:1"/>
        </linux:systemdunitdependency_test>
        <linux:systemdunitproperty_test check="at least one" comment="Test that the logrotate timer is running" id="oval:ssg-test_timer_running_logrotate:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_timer_running_logrotate:obj:1"/>
          <linux:state state_ref="oval:ssg-state_timer_running_logrotate:ste:1"/>
        </linux:systemdunitproperty_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Verify use_uid configuation of pam_wheel.so" id="oval:ssg-test_pam_auth_pam_wheel_use_uid:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_pam_auth_pam_wheel_use_uid:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Verify group configuation of pam_wheel.so" id="oval:ssg-test_pam_auth_pam_wheel_group:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_pam_auth_pam_wheel_group:obj:1"/>
          <ind:state state_ref="oval:ssg-state_pam_auth_pam_wheel_group:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if argument audit=1 is present in the line starting with 'options ' in /boot/loader/entries/.*.conf" id="oval:ssg-test_zipl_audit_argument_audit_1_argument_in_boot_loader_entries_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_zipl_audit_argument_audit_1_argument_in_boot_loader_entries_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_zipl_audit_argument_audit_1_argument_in_boot_loader_entries_conf:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if argument audit=1 is present in /etc/kernel/cmdline" id="oval:ssg-test_zipl_audit_argument_audit_1_argument_in_etc_kernel_cmdline:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_zipl_audit_argument_audit_1_argument_in_etc_kernel_cmdline:obj:1"/>
          <ind:state state_ref="oval:ssg-state_zipl_audit_argument_audit_1_argument_in_etc_kernel_cmdline:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if argument audit_backlog_limit=8192 is present in the line starting with 'options ' in /boot/loader/entries/.*.conf" id="oval:ssg-test_zipl_audit_backlog_limit_argument_audit_backlog_limit_8192_argument_in_boot_loader_entries_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_zipl_audit_backlog_limit_argument_audit_backlog_limit_8192_argument_in_boot_loader_entries_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_zipl_audit_backlog_limit_argument_audit_backlog_limit_8192_argument_in_boot_loader_entries_conf:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if argument audit_backlog_limit=8192 is present in /etc/kernel/cmdline" id="oval:ssg-test_zipl_audit_backlog_limit_argument_audit_backlog_limit_8192_argument_in_etc_kernel_cmdline:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_zipl_audit_backlog_limit_argument_audit_backlog_limit_8192_argument_in_etc_kernel_cmdline:obj:1"/>
          <ind:state state_ref="oval:ssg-state_zipl_audit_backlog_limit_argument_audit_backlog_limit_8192_argument_in_etc_kernel_cmdline:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if argument page_poison=1 is present in the line starting with 'options ' in /boot/loader/entries/.*.conf" id="oval:ssg-test_zipl_page_poison_argument_page_poison_1_argument_in_boot_loader_entries_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_zipl_page_poison_argument_page_poison_1_argument_in_boot_loader_entries_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_zipl_page_poison_argument_page_poison_1_argument_in_boot_loader_entries_conf:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if argument page_poison=1 is present in /etc/kernel/cmdline" id="oval:ssg-test_zipl_page_poison_argument_page_poison_1_argument_in_etc_kernel_cmdline:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_zipl_page_poison_argument_page_poison_1_argument_in_etc_kernel_cmdline:obj:1"/>
          <ind:state state_ref="oval:ssg-state_zipl_page_poison_argument_page_poison_1_argument_in_etc_kernel_cmdline:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if argument slub_debug=P is present in the line starting with 'options ' in /boot/loader/entries/.*.conf" id="oval:ssg-test_zipl_slub_debug_argument_slub_debug_P_argument_in_boot_loader_entries_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_zipl_slub_debug_argument_slub_debug_P_argument_in_boot_loader_entries_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_zipl_slub_debug_argument_slub_debug_P_argument_in_boot_loader_entries_conf:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if argument slub_debug=P is present in /etc/kernel/cmdline" id="oval:ssg-test_zipl_slub_debug_argument_slub_debug_P_argument_in_etc_kernel_cmdline:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_zipl_slub_debug_argument_slub_debug_P_argument_in_etc_kernel_cmdline:obj:1"/>
          <ind:state state_ref="oval:ssg-state_zipl_slub_debug_argument_slub_debug_P_argument_in_etc_kernel_cmdline:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if argument vsyscall=none is present in the line starting with 'options ' in /boot/loader/entries/.*.conf" id="oval:ssg-test_zipl_vsyscall_argument_vsyscall_none_argument_in_boot_loader_entries_conf:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_zipl_vsyscall_argument_vsyscall_none_argument_in_boot_loader_entries_conf:obj:1"/>
          <ind:state state_ref="oval:ssg-state_zipl_vsyscall_argument_vsyscall_none_argument_in_boot_loader_entries_conf:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check if argument vsyscall=none is present in /etc/kernel/cmdline" id="oval:ssg-test_zipl_vsyscall_argument_vsyscall_none_argument_in_etc_kernel_cmdline:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_zipl_vsyscall_argument_vsyscall_none_argument_in_etc_kernel_cmdline:obj:1"/>
          <ind:state state_ref="oval:ssg-state_zipl_vsyscall_argument_vsyscall_none_argument_in_etc_kernel_cmdline:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="check the configuration of /etc/pam.d/system-auth" id="oval:ssg-test_password_pam_pwquality:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_password_pam_pwquality:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl" id="oval:ssg-test_audit_rules_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules" id="oval:ssg-test_audit_rules_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_audit_rules_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit setdomainname" id="oval:ssg-test_32bit_setdomainname_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_setdomainname_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit setdomainname" id="oval:ssg-test_64bit_setdomainname_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_setdomainname_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit setdomainname" id="oval:ssg-test_32bit_setdomainname_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_setdomainname_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit setdomainname" id="oval:ssg-test_64bit_setdomainname_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_setdomainname_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 32-bit sethostname" id="oval:ssg-test_32bit_sethostname_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_sethostname_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit augenrules 64-bit sethostname" id="oval:ssg-test_64bit_sethostname_augenrules:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_sethostname_augenrules:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 32-bit sethostname" id="oval:ssg-test_32bit_sethostname_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_32bit_sethostname_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="audit auditctl 64-bit sethostname" id="oval:ssg-test_64bit_sethostname_auditctl:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_64bit_sethostname_auditctl:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="log_file not set" id="oval:ssg-test_auditd_conf_log_file_not_set:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="log_group = root" id="oval:ssg-test_auditd_conf_log_group_not_root:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_conf_log_group_root:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="log_group is set" id="oval:ssg-test_auditd_conf_log_group_is_set:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_auditd_conf_log_group_is_set:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package kernel is installed" id="oval:ssg-bootc_platform_test_kernel_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_bootc_platform_test_kernel_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package rpm-ostree is installed" id="oval:ssg-bootc_platform_test_rpm_ostree_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_bootc_platform_test_rpm_ostree_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package bootc is installed" id="oval:ssg-bootc_platform_test_bootc_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_bootc_platform_test_bootc_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package openshift-kubelet is removed" id="oval:ssg-bootc_platform_test_openshift_kubelet_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_bootc_platform_test_openshift_kubelet_removed:obj:1"/>
        </linux:rpminfo_test>
        <unix:file_test check="all" check_existence="all_exist" comment="The file /run/ostree-booted exists" id="oval:ssg-bootc_platform_test_run_ostree_booted_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-bootc_platform_obj_run_ostree_booted_exists:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="The file /ostree is a symlink" id="oval:ssg-bootc_platform_test_ostree_symlink_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-bootc_platform_obj_ostree_symlink_exists:obj:1"/>
          <unix:state state_ref="oval:ssg-bootc_platform_ste_ostree_symlink_exists:ste:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Check for GRUB_DISABLE_RECOVERY=true in /etc/default/grub" id="oval:ssg-test_bootloader_disable_recovery_set_to_true:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_bootloader_disable_recovery_argument:obj:1"/>
          <ind:state state_ref="oval:ssg-state_bootloader_disable_recovery_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Ensure more than one chronyd NTP server is set" id="oval:ssg-test_chronyd_multiple_servers:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_chronyd_multiple_servers:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="/etc/almalinux-release exists" id="oval:ssg-test_almalinux:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_almalinux:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" comment="Check Custom OS version" id="oval:ssg-test_almalinux8:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_almalinux8:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:rpminfo_test check="all" comment="hummingbird-release RPM packages are installed" id="oval:ssg-test_hummingbird_release_rpm:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_hummingbird_release_rpm:obj:1"/>
        </linux:rpminfo_test>
        <ind:textfilecontent54_test check="all" comment="CPE vendor is 'redhat' and 'product' is hummingbird" id="oval:ssg-test_hummingbird_vendor_product:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_hummingbird_vendor_product:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:rpminfo_test check="all" comment="oraclelinux-release is version 7" id="oval:ssg-test_ol7_system:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_ol7_system:obj:1"/>
          <linux:state state_ref="oval:ssg-state_ol7_system:ste:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" comment="oraclelinux-release is version 8" id="oval:ssg-test_ol8_system:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_ol8_system:obj:1"/>
          <linux:state state_ref="oval:ssg-state_ol8_system:ste:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" comment="oraclelinux-release is version 9" id="oval:ssg-test_ol9_system:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_ol9_system:obj:1"/>
          <linux:state state_ref="oval:ssg-state_ol9_system:ste:1"/>
        </linux:rpminfo_test>
        <ind:family_test check="all" comment="Test installed OS is part of the unix family" id="oval:ssg-test_unix_family:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_unix_family:obj:1"/>
          <ind:state state_ref="oval:ssg-state_unix_family:ste:1"/>
        </ind:family_test>
        <ind:textfilecontent54_test check="all" comment="os-release is rhcos" id="oval:ssg-test_rhcos:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhcos:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhcos:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check for variant=CoreOS" id="oval:ssg-test_rhel_coreos_variant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhel_coreos_variant:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhel_coreos_variant:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check if VERSION_ID=9.x" id="oval:ssg-test_rhel_coreos_version9:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhel_coreos_version9:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhel_coreos_version9:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check if VERSION_ID=10.x" id="oval:ssg-test_rhel_coreos_version10:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhel_coreos_version10:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhel_coreos_version10:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="rhcoreos is version 4" id="oval:ssg-test_rhcos4:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhcos4:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhcos4:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="rhcoreos RHEL_VERSION is 8 (old format)" id="oval:ssg-test_rhcos4_rhel8_rhel_version:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhcos4_rhel8_rhel_version:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhcos4_rhel8_rhel_version:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="ID is rhel" id="oval:ssg-test_rhel_id:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhel_id:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhel_id:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="rhcoreos RHEL_VERSION is 9 (old format)" id="oval:ssg-test_rhcos4_rhel9_rhel_version:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhcos4_rhel9_rhel_version:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhcos4_rhel9_rhel_version:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:family_test check="all" comment="installed OS part of unix family" id="oval:ssg-test_rhel10_unix_family:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhel10_unix_family:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhel10_unix_family:ste:1"/>
        </ind:family_test>
        <linux:rpminfo_test check="all" comment="redhat-release is version 10" id="oval:ssg-test_rhel10:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_rhel10:obj:1"/>
          <linux:state state_ref="oval:ssg-state_rhel10:ste:1"/>
        </linux:rpminfo_test>
        <ind:textfilecontent54_test check="all" comment="RHEVH base RHEL is version 10" id="oval:ssg-test_rhevh_rhel10_version:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhevh_rhel10_version:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhevh_rhel10_version:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:family_test check="all" comment="installed OS part of unix family" id="oval:ssg-test_rhel8_unix_family:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhel8_unix_family:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhel8_unix_family:ste:1"/>
        </ind:family_test>
        <linux:rpminfo_test check="all" comment="redhat-release is version 8" id="oval:ssg-test_rhel8:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_rhel8:obj:1"/>
          <linux:state state_ref="oval:ssg-state_rhel8:ste:1"/>
        </linux:rpminfo_test>
        <ind:textfilecontent54_test check="all" comment="RHEVH base RHEL is version 8" id="oval:ssg-test_rhevh_rhel8_version:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhevh_rhel8_version:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhevh_rhel8_version:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:family_test check="all" comment="installed OS part of unix family" id="oval:ssg-test_rhel9_unix_family:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhel9_unix_family:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhel9_unix_family:ste:1"/>
        </ind:family_test>
        <linux:rpminfo_test check="all" comment="redhat-release is version 9" id="oval:ssg-test_rhel9:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_rhel9:obj:1"/>
          <linux:state state_ref="oval:ssg-state_rhel9:ste:1"/>
        </linux:rpminfo_test>
        <ind:textfilecontent54_test check="all" comment="RHEVH base RHEL is version 9" id="oval:ssg-test_rhevh_rhel9_version:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhevh_rhel9_version:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhevh_rhel9_version:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:rpminfo_test check="all" check_existence="only_one_exists" comment="redhat-release-virtualization-host RPM package is installed" id="oval:ssg-test_rhvh4_version:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_rhvh4_version:obj:1"/>
          <linux:state state_ref="oval:ssg-state_rhvh4_version:ste:1"/>
        </linux:rpminfo_test>
        <ind:family_test check="all" comment="installed OS part of unix family" id="oval:ssg-test_sle12_unix_family:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sle12_unix_family:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sle12_unix_family:ste:1"/>
        </ind:family_test>
        <linux:rpminfo_test check="all" comment="sled-release is version 6" id="oval:ssg-test_sle12_desktop:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_sle12_desktop:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sle12_desktop:ste:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" comment="sles-release is version 6" id="oval:ssg-test_sle12_server:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_sle12_server:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sle12_server:ste:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" comment="SLES_SAP-release is version 12" id="oval:ssg-test_sles_12_for_sap:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_sles_12_for_sap:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sles_12_for_sap:ste:1"/>
        </linux:rpminfo_test>
        <ind:family_test check="all" comment="installed OS part of unix family" id="oval:ssg-test_sle15_unix_family:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sle15_unix_family:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sle15_unix_family:ste:1"/>
        </ind:family_test>
        <linux:rpminfo_test check="all" comment="sled-release is version 15" id="oval:ssg-test_sle15_desktop:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_sle15_desktop:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sle15_desktop:ste:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" comment="sles-release is version 15" id="oval:ssg-test_sle15_server:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_sle15_server:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sle15_server:ste:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" comment="SLES_SAP-release is version 15" id="oval:ssg-test_sles_15_for_sap:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_sles_15_for_sap:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sles_15_for_sap:ste:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" comment="SUMA is version 4" id="oval:ssg-test_suma_4:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_suma_4:obj:1"/>
          <linux:state state_ref="oval:ssg-state_suma_4:ste:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" comment="SLE HPC release is version 15" id="oval:ssg-test_sle_hpc:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_sle_hpc:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sle_hpc:ste:1"/>
        </linux:rpminfo_test>
        <ind:family_test check="all" comment="installed OS part of unix family" id="oval:ssg-test_sle16_unix_family:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_sle16_unix_family:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sle16_unix_family:ste:1"/>
        </ind:family_test>
        <linux:rpminfo_test check="all" comment="SLES-release is version 16" id="oval:ssg-test_sle16_server:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_sle16_server:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sle16_server:ste:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" comment="SLES_SAP-release is version 16" id="oval:ssg-test_sles_16_for_sap:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_sles_16_for_sap:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sles_16_for_sap:ste:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" comment="sle-ha-release is version 16" id="oval:ssg-test_sles_16_for_ha:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_sles_16_for_ha:obj:1"/>
          <linux:state state_ref="oval:ssg-state_sles_16_for_ha:ste:1"/>
        </linux:rpminfo_test>
        <ind:family_test check="all" comment="installed OS part of unix family" id="oval:ssg-test_slmicro5_unix_family:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_slmicro5_unix_family:obj:1"/>
          <ind:state state_ref="oval:ssg-state_slmicro5_unix_family:ste:1"/>
        </ind:family_test>
        <linux:rpminfo_test check="all" comment="sle-micro-release is version 5" id="oval:ssg-test_slmicroos5:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_slmicroos5:obj:1"/>
          <linux:state state_ref="oval:ssg-state_slmicroos5:ste:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" comment="sle-micro-release is version 5" id="oval:ssg-test_slmicro5:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_slmicro5:obj:1"/>
          <linux:state state_ref="oval:ssg-state_slmicro5:ste:1"/>
        </linux:rpminfo_test>
        <ind:family_test check="all" comment="installed OS part of unix family" id="oval:ssg-test_slmicro6_unix_family:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_slmicro6_unix_family:obj:1"/>
          <ind:state state_ref="oval:ssg-state_slmicro6_unix_family:ste:1"/>
        </ind:family_test>
        <linux:rpminfo_test check="all" comment="sle-micro-release is version 6" id="oval:ssg-test_slmicro6:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_slmicro6:obj:1"/>
          <linux:state state_ref="oval:ssg-state_slmicro6:ste:1"/>
        </linux:rpminfo_test>
        <unix:file_test check="all" check_existence="all_exist" comment="/etc/lsb-release exists" id="oval:ssg-test_lsb:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_lsb:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" comment="Check Ubuntu" id="oval:ssg-test_ubuntu:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_ubuntu:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check Ubuntu version" id="oval:ssg-test_ubuntu_jammy:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_ubuntu_jammy:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check Ubuntu version" id="oval:ssg-test_ubuntu_noble:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_ubuntu_noble:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="'CD/DVD drive is not listed in /etc/fstab" id="oval:ssg-test_no_cd_dvd_drive_in_etc_fstab:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_no_cd_dvd_drive_in_etc_fstab:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="none_exist" comment="Check if expected removable partitions truly exist on the system" id="oval:ssg-test_removable_partition_doesnt_exist:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_removable_partition_doesnt_exist:obj:1"/>
        </unix:file_test>
        <ind:variable_test check="all" comment="Verify if Profile set Value sshd_required as not required" id="oval:ssg-test_sshd_not_required:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sshd_not_required:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_not_required:ste:1"/>
        </ind:variable_test>
        <ind:variable_test check="all" comment="Verify if Profile set Value sshd_required as required" id="oval:ssg-test_sshd_required:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sshd_required:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_required:ste:1"/>
        </ind:variable_test>
        <ind:variable_test check="all" comment="Verify if Value of sshd_required is the default" id="oval:ssg-test_sshd_requirement_unset:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_sshd_requirement_unknown:obj:1"/>
          <ind:state state_ref="oval:ssg-state_sshd_requirement_unset:ste:1"/>
        </ind:variable_test>
        <unix:uname_test check="all" comment="64 bit architecture" id="oval:ssg-test_system_info_architecture_aarch_64:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_system_info_architecture_aarch_64:obj:1"/>
          <unix:state state_ref="oval:ssg-state_system_info_architecture_aarch_64:ste:1"/>
        </unix:uname_test>
        <unix:uname_test check="all" comment="64 bit architecture" id="oval:ssg-test_system_info_architecture_ppc_64:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_system_info_architecture_ppc_64:obj:1"/>
          <unix:state state_ref="oval:ssg-state_system_info_architecture_ppc_64:ste:1"/>
        </unix:uname_test>
        <unix:uname_test check="all" comment="64 bit architecture" id="oval:ssg-test_system_info_architecture_ppcle_64:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_system_info_architecture_ppcle_64:obj:1"/>
          <unix:state state_ref="oval:ssg-state_system_info_architecture_ppcle_64:ste:1"/>
        </unix:uname_test>
        <unix:uname_test check="all" comment="64 bit architecture" id="oval:ssg-test_system_info_architecture_s390_64:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_system_info_architecture_s390_64:obj:1"/>
          <unix:state state_ref="oval:ssg-state_system_info_architecture_s390_64:ste:1"/>
        </unix:uname_test>
        <unix:uname_test check="all" comment="32 bit architecture" id="oval:ssg-test_system_info_architecture_x86:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_system_info_architecture_x86:obj:1"/>
          <unix:state state_ref="oval:ssg-state_system_info_architecture_x86:ste:1"/>
        </unix:uname_test>
        <unix:uname_test check="all" comment="64 bit architecture" id="oval:ssg-test_system_info_architecture_x86_64:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_system_info_architecture_x86_64:obj:1"/>
          <unix:state state_ref="oval:ssg-state_system_info_architecture_x86_64:ste:1"/>
        </unix:uname_test>
        <unix:file_test check="all" comment="Check /etc/tmux.conf is readable by others" id="oval:ssg-test_tmux_conf_readable_by_others:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_tmux_conf_readable_by_others:obj:1"/>
          <unix:state state_ref="oval:ssg-state_tmux_conf_readable_by_others:ste:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" comment="Check the usbguard rules in either /etc/usbguard/rules.conf or /etc/usbguard/rules.d/ contain at least one non whitespace character and exists" id="oval:ssg-test_usbguard_rules_nonempty:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_usbguard_rules_nonempty:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:variable_test check="all" comment="Verify the existence of var_accounts_user_umask_as_number variable" id="oval:ssg-test_existence_of_var_accounts_user_umask_as_number_variable:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_accounts_user_umask_umask_as_number:obj:1"/>
        </ind:variable_test>
        <ind:variable_test check="all" comment="Check if removable partition variable value represents CD/DVD drive" id="oval:ssg-test_var_removable_partition_is_cd_dvd_drive:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_removable_partition_is_cd_dvd_drive:obj:1"/>
          <ind:state state_ref="oval:ssg-state_var_removable_partition_is_cd_dvd_drive:ste:1"/>
        </ind:variable_test>
        <ind:variable_test check="all" comment="Verify the existence of var_umask_for_daemons_as_number variable" id="oval:ssg-test_existence_of_var_umask_for_daemons_as_number_variable:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_var_umask_for_daemons_umask_as_number:obj:1"/>
        </ind:variable_test>
      </oval-def:tests>
      <oval-def:objects>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_continue_loading_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^\-c\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_continue_loading_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\-c\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_ari_locked_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^\-e\s+2\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_ari_locked_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\-e\s+2\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_augen_immutable_login_uids:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*--loginuid-immutable\s*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_auditctl_immutable_login_uids:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\s*--loginuid-immutable\s*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_armm_selinux_watch_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/selinux/[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_armm_selinux_watch_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/selinux/[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_arnm_common_etc_issue_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/issue[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_arnm_common_etc_issue_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/issue[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_arnm_common_etc_issue_net_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/issue\.net[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_arnm_common_etc_issue_net_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/issue\.net[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_arnm_common_etc_hosts_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/hosts[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_arnm_common_etc_hosts_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/hosts[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_arnm_common_etc_sysconfig_network_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/sysconfig/network[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_arnm_common_etc_sysconfig_network_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/sysconfig/network[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arse_utmp_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^\-w\s+/var/run/utmp\s+\-p\s+wa\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arse_btmp_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^\-w\s+/var/log/btmp\s+\-p\s+wa\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arse_wtmp_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^\-w\s+/var/log/wtmp\s+\-p\s+wa\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arse_utmp_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\-w\s+/var/run/utmp\s+\-p\s+wa\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arse_btmp_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\-w\s+/var/log/btmp\s+\-p\s+wa\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arse_wtmp_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\-w\s+/var/log/wtmp\s+\-p\s+wa\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_uid_auid_privileged_function_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32[\s]+-S[\s]+execve[\s]+-C[\s]+euid!=uid[\s]+-F[\s]+auid!=unset[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_uid_auid_privileged_function_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b64[\s]+-S[\s]+execve[\s]+-C[\s]+euid!=uid[\s]+-F[\s]+auid!=unset[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_uid_auid_privileged_function_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32[\s]+-S[\s]+execve[\s]+-C[\s]+euid!=uid[\s]+-F[\s]+auid!=unset[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_uid_auid_privileged_function_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b64[\s]+-S[\s]+execve[\s]+-C[\s]+euid!=uid[\s]+-F[\s]+auid!=unset[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_uid_privileged_function_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32[\s]+-S[\s]+execve[\s]+-C[\s]+uid!=euid[\s]+-F[\s]+euid=0[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_uid_privileged_function_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b64[\s]+-S[\s]+execve[\s]+-C[\s]+uid!=euid[\s]+-F[\s]+euid=0[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_uid_privileged_function_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32[\s]+-S[\s]+execve[\s]+-C[\s]+uid!=euid[\s]+-F[\s]+euid=0[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_uid_privileged_function_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b64[\s]+-S[\s]+execve[\s]+-C[\s]+uid!=euid[\s]+-F[\s]+euid=0[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_gid_privileged_function_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32[\s]+-S[\s]+execve[\s]+-C[\s]+gid!=egid[\s]+-F[\s]+egid=0[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_gid_privileged_function_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b64[\s]+-S[\s]+execve[\s]+-C[\s]+gid!=egid[\s]+-F[\s]+egid=0[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_gid_privileged_function_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32[\s]+-S[\s]+execve[\s]+-C[\s]+gid!=egid[\s]+-F[\s]+egid=0[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_gid_privileged_function_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b64[\s]+-S[\s]+execve[\s]+-C[\s]+gid!=egid[\s]+-F[\s]+egid=0[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_ars_shutdown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^\-f\s+(\d)\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_ars_shutdown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\-f\s+(\d)\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_etc_group_augen:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/group[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_etc_passwd_augen:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/passwd[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_etc_gshadow_augen:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/gshadow[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_etc_shadow_augen:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/shadow[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_etc_security_opasswd_augen:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/security/opasswd[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_etc_group_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/group[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_etc_passwd_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/passwd[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_etc_gshadow_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/gshadow[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_etc_shadow_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/shadow[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_etc_security_opasswd_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\-w[\s]+/etc/security/opasswd[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_directory_access_var_log_audit_augenrules_32bit:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32[\s]+(?:-F[\s]+dir=/var/log/audit/)[\s]+(?:-F[\s]+perm=r)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_directory_access_var_log_audit_augenrules_64bit:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b64[\s]+(?:-F[\s]+dir=/var/log/audit/)[\s]+(?:-F[\s]+perm=r)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_directory_access_var_log_audit_auditctl_32bit:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32[\s]+(?:-F[\s]+dir=/var/log/audit/)[\s]+(?:-F[\s]+perm=r)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_directory_access_var_log_audit_auditctl_64bit:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b64[\s]+(?:-F[\s]+dir=/var/log/audit/)[\s]+(?:-F[\s]+perm=r)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/var/log/audit directories" id="oval:ssg-object_group_ownership_default_var_log_audit_directories:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/var/log/audit</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_group_owner_not_root_var_log_audit_directories:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/audit directories" id="oval:ssg-object_group_ownership_var_log_audit_directories-non_root:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/var/log/audit</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_group_owner_not_root_var_log_audit_directories-non_root:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="log directories" id="oval:ssg-object_group_ownership_var_log_audit_directories:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals" var_ref="oval:ssg-audit_log_dir_group_ownership:var:1"/>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_group_owner_not_root_var_log_audit_directories:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="audit log files" id="oval:ssg-object_directory_ownership_var_log_audit_file:obj:1" version="1">
          <unix:filepath operation="pattern match" var_ref="oval:ssg-audit_log_file_path:var:1"/>
        </unix:file_object>
        <unix:file_object comment="log_file's directory" id="oval:ssg-object_user_ownership_var_log_audit_path:obj:1" version="1">
          <unix:path operation="equals" var_ref="oval:ssg-var_directory_ownership_var_log_audit_path:var:1"/>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_owner_not_root_var_log_audit_directories:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/audit directories" id="oval:ssg-object_user_ownership_var_log_audit_directories:obj:1" version="1">
          <unix:path operation="equals">/var/log/audit</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_owner_not_root_var_log_audit_directories:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="non default audit log dir" id="oval:ssg-object_var_log_audit_directory_non_default_root:obj:1" version="1">
          <unix:path operation="equals" var_ref="oval:ssg-audit_log_dir:var:1"/>
          <unix:filename xsi:nil="true"/>
        </unix:file_object>
        <unix:file_object comment="non default audit log dir" id="oval:ssg-object_var_log_audit_directory_non_default_not_root:obj:1" version="1">
          <unix:path operation="equals" var_ref="oval:ssg-audit_log_dir:var:1"/>
          <unix:filename xsi:nil="true"/>
        </unix:file_object>
        <unix:file_object comment="/var/log/audit dir" id="oval:ssg-object_var_log_audit_directory_root:obj:1" version="1">
          <unix:path>/var/log/audit</unix:path>
          <unix:filename xsi:nil="true"/>
        </unix:file_object>
        <unix:file_object comment="/var/log/audit dir" id="oval:ssg-object_var_log_audit_directory_non_root:obj:1" version="1">
          <unix:path>/var/log/audit</unix:path>
          <unix:filename xsi:nil="true"/>
        </unix:file_object>
        <unix:file_object comment="audit log files" id="oval:ssg-object_group_ownership_audit_log_files:obj:1" version="1">
          <unix:filepath operation="equals" var_ref="oval:ssg-audit_log_file_path:var:1"/>
          <oval-def:filter action="include">oval:ssg-state_group_owner_not_root_var_log_audit:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/audit files" id="oval:ssg-object_group_ownership_default_audit_log_files:obj:1" version="1">
          <unix:filepath operation="equals">/var/log/audit/audit.log</unix:filepath>
          <oval-def:filter action="include">oval:ssg-state_group_owner_not_root_var_log_audit:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/audit directories" id="oval:ssg-object_ownership_var_log_audit_directories:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/var/log/audit</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_owner_not_root_root_var_log_audit:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/audit files" id="oval:ssg-object_ownership_var_log_audit_files:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/var/log/audit</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="include">oval:ssg-state_owner_not_root_root_var_log_audit:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/audit directories" id="oval:ssg-object_ownership_var_log_audit_directories-non_root:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/var/log/audit</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_owner_not_root_var_log_audit-non_root:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/audit files" id="oval:ssg-object_ownership_var_log_audit_files-non_root:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/var/log/audit</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="include">oval:ssg-state_owner_not_root_var_log_audit-non_root:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="audit log files" id="oval:ssg-object_user_ownership_audit_log_files:obj:1" version="1">
          <unix:filepath operation="pattern match" var_ref="oval:ssg-audit_log_file_path:var:1"/>
          <oval-def:filter action="include">oval:ssg-state_owner_not_root_var_log_audit:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="audit log files" id="oval:ssg-object_user_ownership_var_log_audit_files:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/var/log/audit</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="include">oval:ssg-state_owner_not_root_var_log_audit:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/audit files" id="oval:ssg-object_audit_log_files:obj:1" version="1">
          <unix:filepath operation="pattern match" var_ref="oval:ssg-audit_log_file_path:var:1"/>
          <oval-def:filter action="include">oval:ssg-state_not_mode_0600:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/audit files" id="oval:ssg-object_var_log_audit_files:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path operation="equals">/var/log/audit</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="include">oval:ssg-state_not_mode_0600:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="audit log files" id="oval:ssg-object_audit_log_files-non_root:obj:1" version="1">
          <unix:filepath operation="pattern match" var_ref="oval:ssg-audit_log_file_path:var:1"/>
          <oval-def:filter action="include">oval:ssg-state_not_mode_0640:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/audit files" id="oval:ssg-object_var_log_audit_files-non_root:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path operation="equals">/var/log/audit</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="include">oval:ssg-state_not_mode_0640:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_umount_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+umount[\s]+|([\s]+|[,])umount([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_umount_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+umount[\s]+|([\s]+|[,])umount([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_audit_rules_privileged_commands_exec_partitions:obj:1" version="1">
          <linux:mount_point operation="pattern match">^(?!/proc(/.*|$)).*$</linux:mount_point>
          <oval-def:filter action="include">oval:ssg-state_audit_rules_privileged_commands_dev_partitons:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_audit_rules_privileged_commands_nosuid_partitons:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_audit_rules_privileged_commands_noexec_partitons:ste:1</oval-def:filter>
        </linux:partition_object>
        <unix:file_object comment="Files with setuid or setgid permission in file systems that allow their execution" id="oval:ssg-object_audit_rules_privileged_commands:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="defined"/>
          <unix:path operation="equals" var_check="at least one" var_ref="oval:ssg-var_audit_rules_privileged_commands_exec_mountpoints:var:1"/>
          <unix:filename operation="not equal">/</unix:filename>
          <oval-def:filter action="include">oval:ssg-state_setuid_or_setgid_set:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_dracut_tmp_files:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="Files with setuid or setgid permission in file systems that allow their execution" id="oval:ssg-object_audit_rules_privileged_commands_bootc:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="defined"/>
          <unix:path operation="equals">/</unix:path>
          <unix:filename operation="not equal">/</unix:filename>
          <oval-def:filter action="include">oval:ssg-state_setuid_or_setgid_set:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_dracut_tmp_files:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_audit_rules_privileged_commands_sysroot:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:variable_object comment="Number of all privileged commands in the system, regardless of audit rules." id="oval:ssg-object_audit_rules_privileged_commands_priv_cmds_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_audit_rules_privileged_commands_priv_cmds_count:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-object_priv_cmds_from_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rules_privileged_commands_rule_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_unprivileged_commands:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_priv_cmds_from_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rules_privileged_commands_rule_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_unprivileged_commands:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <ind:variable_object comment="Number of all privileged commands in the system, regardless of audit rules." id="oval:ssg-object_audit_rules_privileged_commands_priv_cmds_count_bootc:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_audit_rules_privileged_commands_priv_cmds_count_bootc:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-object_priv_cmds_from_augenrules_bootc:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rules_privileged_commands_rule_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_unprivileged_commands_bootc:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_priv_cmds_from_auditctl_bootc:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rules_privileged_commands_rule_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_unprivileged_commands_bootc:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_art_adjtimex_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32.*(-S[\s]+adjtimex[\s]+|([\s]+|[,])adjtimex([\s]+|[,])).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_art_adjtimex_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b64.*(-S[\s]+adjtimex[\s]+|([\s]+|[,])adjtimex([\s]+|[,])).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_art_adjtimex_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32.*(-S[\s]+adjtimex[\s]+|([\s]+|[,])adjtimex([\s]+|[,])).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_art_adjtimex_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b64.*(-S[\s]+adjtimex[\s]+|([\s]+|[,])adjtimex([\s]+|[,])).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_art_clock_settime_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32[\s]+(-S[\s]+clock_settime[\s]+|([\s]+|[,])clock_settime([\s]+|[,]))-F[\s]+a0=(?:0x)?0[\s]+(?:-F[\s]+key=|-k[\s]+)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_art_clock_settime_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b64[\s]+(-S[\s]+clock_settime[\s]+|([\s]+|[,])clock_settime([\s]+|[,]))-F[\s]+a0=(?:0x)?0[\s]+(?:-F[\s]+key=|-k[\s]+)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_art_clock_settime_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32[\s]+(-S[\s]+clock_settime[\s]+|([\s]+|[,])clock_settime([\s]+|[,]))-F[\s]+a0=(?:0x)?0[\s]+(?:-F[\s]+key=|-k[\s]+)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_art_clock_settime_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b64[\s]+(-S[\s]+clock_settime[\s]+|([\s]+|[,])clock_settime([\s]+|[,]))-F[\s]+a0=(?:0x)?0[\s]+(?:-F[\s]+key=|-k[\s]+)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_art_settimeofday_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32.*(-S[\s]+settimeofday[\s]+|([\s]+|[,])settimeofday([\s]+|[,])).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_art_settimeofday_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b64.*(-S[\s]+settimeofday[\s]+|([\s]+|[,])settimeofday([\s]+|[,])).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_art_settimeofday_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32.*(-S[\s]+settimeofday[\s]+|([\s]+|[,])settimeofday([\s]+|[,])).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_art_settimeofday_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b64.*(-S[\s]+settimeofday[\s]+|([\s]+|[,])settimeofday([\s]+|[,])).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_art_stime_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32.*(-S[\s]+stime[\s]+|([\s]+|[,])stime([\s]+|[,])).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_art_stime_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+arch=b32.*(-S[\s]+stime[\s]+|([\s]+|[,])stime([\s]+|[,])).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_audispd_configure_remote_server:obj:1" version="1">
          <ind:filepath>/etc/audit/audisp-remote.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*(?i)remote_server(?-i)[ ]+=[ ]+(\S+)[ ]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_audispd_disk_full_action:obj:1" version="1">
          <ind:filepath>/etc/audit/audisp-remote.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*disk_full_action[ ]+=[ ]+(\S+)[ ]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_audispd_encrypt_sent_records:obj:1" version="1">
          <ind:filepath>/etc/audit/audisp-remote.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*transport[ ]+=[ ]+KRB5[ ]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_audispd_network_failure_action:obj:1" version="1">
          <ind:filepath>/etc/audit/audisp-remote.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*network_failure_action[ ]+=[ ]+(\S+)[ ]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_audispd_syslog_plugin_activated:obj:1" version="1">
          <ind:filepath>/etc/audit/plugins.d/syslog.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*active[ ]+=[ ]+yes[ ]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_disk_error_action:obj:1" version="3">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*disk_error_action[ ]+=[ ]+(\S+)[ ]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_disk_error_action_stig:obj:1" version="2">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*disk_error_action[ ]+=[ ]+(\S+)[ ]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_disk_full_action:obj:1" version="3">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*disk_full_action[ ]+=[ ]+(\S+)[ ]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_disk_full_action_stig:obj:1" version="2">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*disk_full_action[ ]+=[ ]+(\S+)[ ]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_retention_action_mail_acct:obj:1" version="2">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*action_mail_acct[ ]+=[ ]+(\S+)[ ]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_retention_admin_space_left_action:obj:1" version="2">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*admin_space_left_action[ ]+=[ ]+(\S+)[ ]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_retention_admin_space_left_percentage:obj:1" version="2">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*admin_space_left[\s]+=[\s]+(\d+)%[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_retention_flush:obj:1" version="1">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*flush[ ]+=[ ]+(\S+)[ ]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_retention_max_log_file:obj:1" version="2">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*max_log_file[ ]+=[ ]+(\d+)[ ]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_retention_max_log_file_action:obj:1" version="2">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*max_log_file_action[ ]+=[ ]+(\S+)[ ]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_retention_max_log_file_action_stig:obj:1" version="2">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*max_log_file_action[ ]+=[ ]+(\S+)[ ]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_retention_num_logs:obj:1" version="2">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*num_logs[ ]+=[ ]+(\d+)[ ]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_retention_space_left:obj:1" version="2">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*space_left[\s]+=[\s]+(\d+)[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_retention_space_left_action:obj:1" version="2">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*space_left_action[ ]+=[ ]+(\S+)[ ]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_retention_space_left_percentage:obj:1" version="2">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*space_left[\s]+=[\s]+(\d+)%[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_auditd_name_format:obj:1" version="1">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)name_format(?-i)[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_auditd_overflow_action:obj:1" version="1">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)overflow_action(?-i)[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_10-base-config_old:obj:1" version="1">
          <ind:filepath>/etc/audit/rules.d/10-base-config.rules</ind:filepath>
          <ind:pattern operation="pattern match">(?:.*\n)*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_doc_10-base-config:obj:1" version="1">
          <ind:filepath operation="pattern match">^/usr/share/doc/audit(?:-\d.\d.\d)?/rules/10-base-config.rules</ind:filepath>
          <ind:pattern operation="pattern match">(?:.*\n)*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_11-loginuid_old:obj:1" version="1">
          <ind:filepath>/etc/audit/rules.d/11-loginuid.rules</ind:filepath>
          <ind:pattern operation="pattern match">(?:.*\n)*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_doc_11-loginuid:obj:1" version="1">
          <ind:filepath operation="pattern match">^/usr/share/doc/audit(?:-\d.\d.\d)?/rules/11-loginuid.rules</ind:filepath>
          <ind:pattern operation="pattern match">(?:.*\n)*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_30-ospp-v42_old:obj:1" version="1">
          <ind:filepath>/etc/audit/rules.d/30-ospp-v42.rules</ind:filepath>
          <ind:pattern operation="pattern match">(?:.*\n)*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_doc_30-ospp-v42:obj:1" version="1">
          <ind:filepath operation="pattern match">^/usr/share/doc/audit(?:-\d.\d.\d)?/rules/30-ospp-v42.rules</ind:filepath>
          <ind:pattern operation="pattern match">(?:.*\n)*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_43-module-load_old:obj:1" version="1">
          <ind:filepath>/etc/audit/rules.d/43-module-load.rules</ind:filepath>
          <ind:pattern operation="pattern match">(?:.*\n)*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_doc_43-module-load:obj:1" version="1">
          <ind:filepath operation="pattern match">^/usr/share/doc/audit(?:-\d.\d.\d)?/rules/43-module-load.rules</ind:filepath>
          <ind:pattern operation="pattern match">(?:.*\n)*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sysconfig_networking_bootproto_ifcfg:obj:1" version="1">
          <ind:path>/etc/sysconfig/network-scripts</ind:path>
          <ind:filename operation="pattern match">ifcfg-.*</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*BOOTPROTO[\s]*=[\s"]*([^#"\s]*)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_fapolicy_default_deny_policy_compiled_rules:obj:1" version="1">
          <ind:filepath>/etc/fapolicyd/compiled.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\s*deny(_log|_audit)?\s*perm=any\s*all\s*:\s*all\s*\z</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_fapolicy_default_deny_policy_fapolicyd_rules:obj:1" version="2">
          <ind:filepath>/etc/fapolicyd/fapolicyd.rules</ind:filepath>
          <ind:pattern operation="pattern match">^\s*deny(_log|_audit)?\s*perm=any\s*all\s*:\s*all\s*\z</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_fapolicy_default_deny_permissive_mode:obj:1" version="2">
          <ind:filepath>/etc/fapolicyd/fapolicyd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*permissive\s*=\s*(\d+)</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="log ftp transactions" id="oval:ssg-object_test_ftp_log_transactions_enable:obj:1" version="1">
          <ind:filepath>/etc/vsftpd/vsftpd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*xferlog_enable[\s]*=[\s]*YES$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="log ftp transactions" id="oval:ssg-object_test_ftp_log_transactions_format:obj:1" version="1">
          <ind:filepath>/etc/vsftpd/vsftpd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*xferlog_std_format[\s]*=[\s]*NO$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="log ftp transactions" id="oval:ssg-object_test_ftp_log_transactions_protocol:obj:1" version="1">
          <ind:filepath>/etc/vsftpd/vsftpd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*log_ftp_protocol[\s]*=[\s]*YES$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Banner for FTP Users" id="oval:ssg-object_test_ftp_present_banner:obj:1" version="1">
          <ind:filepath>/etc/vsftpd/vsftpd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*banner_file=/etc/issue[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/etc/httpd/conf/" id="oval:ssg-object_dir_perms_etc_httpd_conf:obj:1" version="1">
          <unix:path>/etc/httpd/conf</unix:path>
          <unix:filename xsi:nil="true"/>
        </unix:file_object>
        <unix:file_object comment="/var/log/httpd/" id="oval:ssg-object_dir_perms_var_log_httpd:obj:1" version="1">
          <unix:path>/var/log/httpd</unix:path>
          <unix:filename xsi:nil="true"/>
        </unix:file_object>
        <unix:file_object comment="/etc/httpd/conf.d/* permissions" id="oval:ssg-object_file_permissions_httpd_server_conf_d_files:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path operation="equals">/etc/httpd/conf.d/</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
        </unix:file_object>
        <unix:file_object comment="/etc/httpd/conf/* permissions" id="oval:ssg-object_file_permissions_httpd_server_conf_files:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path operation="equals">/etc/httpd/conf</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
        </unix:file_object>
        <unix:file_object comment="/etc/httpd/conf.modules.d/* permissions" id="oval:ssg-object_file_permissions_httpd_server_modules_files:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path operation="equals">/etc/httpd/conf.modules.d/</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_dovecot_disable_plaintext_auth:obj:1" version="1">
          <ind:filepath>/etc/dovecot/conf.d/10-auth.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*disable_plaintext_auth[\s]*=[\s]*yes[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_dovecot_enable_ssl:obj:1" version="1">
          <ind:filepath>/etc/dovecot/conf.d/10-ssl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*ssl[\s]*=[\s]*(yes|required)[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="Default Kerberos keytab file" id="oval:ssg-obj_kerberos_disable_no_keytab:obj:1" version="1">
          <unix:filepath operation="pattern match">^/etc/.+\.keytab$</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_enable_ldap_client:obj:1" version="1">
          <ind:filepath>/etc/sysconfig/authconfig</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*USELDAPAUTH=yes[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_ldap_client_start_tls_ssl:obj:1" version="1">
          <ind:filepath>/etc/nslcd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*ssl[\s]+start_tls[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_ldap_client_tls_cacertdir:obj:1" version="1">
          <ind:filepath>/etc/nslcd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*tls_cacertdir[\s]+/etc/pki/tls/CA$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:inetlisteningservers_object id="oval:ssg-obj_listening_port_25:obj:1" version="1">
          <linux:protocol>tcp</linux:protocol>
          <linux:local_address operation="not equal">127.0.0.1</linux:local_address>
          <linux:local_port datatype="int">25</linux:local_port>
          <oval-def:filter action="exclude">oval:ssg-ste_not_port_25:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-ste_not_on_localhost:ste:1</oval-def:filter>
        </linux:inetlisteningservers_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_root_mail_alias:obj:1" version="1">
          <ind:filepath operation="equals">/etc/aliases</ind:filepath>
          <ind:pattern operation="pattern match">^(?:[rR][oO][oO][tT]|"[rR][oO][oO][tT]")\s*:\s*(.+)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_postmaster_mail_alias:obj:1" version="1">
          <ind:filepath operation="equals">/etc/aliases</ind:filepath>
          <ind:pattern operation="pattern match">^(?i)postmaster\s*:\s*(.+)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="inet_interfaces in /etc/postfix/main.cf should be set correctly" id="oval:ssg-obj_postfix_network_listening_disabled:obj:1" version="1">
          <ind:filepath>/etc/postfix/main.cf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*inet_interfaces[\s]*=[\s]*(.*)[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_postfix_server_banner:obj:1" version="1">
          <ind:filepath>/etc/postfix/main.cf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*smtpd_banner[\s]*=[\s]*\$myhostname[\s]+ESMTP[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_postfix_prevent_unrestricted_relay:obj:1" version="1">
          <ind:filepath>/etc/postfix/main.cf</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*smtpd_client_restrictions = (.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="The configuration file /etc/postfix/main.cf for postfix_prevent_unrestricted_relay" id="oval:ssg-obj_postfix_prevent_unrestricted_relay_config_file:obj:1" version="1">
          <unix:filepath operation="pattern match">^/etc/postfix/main.cf</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_no_insecure_locks_exports:obj:1" version="2">
          <ind:filepath>/etc/exports</ind:filepath>
          <ind:pattern operation="pattern match">^(.*?(\binsecure_locks\b)[^$]*)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_use_kerberos_security_all_exports:obj:1" version="2">
          <ind:filepath>/etc/exports</ind:filepath>
          <ind:pattern operation="pattern match">^\/.*\((\S+)\)$</ind:pattern>
          <ind:instance datatype="int" operation="not equal">0</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_non_empty_exports_file:obj:1" version="1">
          <ind:filepath>/etc/exports</ind:filepath>
          <ind:pattern operation="pattern match">^\/.*$</ind:pattern>
          <ind:instance datatype="int" operation="not equal">0</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_chronyd_port_value:obj:1" version="1">
          <ind:filepath>/etc/chrony.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*port[\s]+(\S+)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-obj_chrony_wait_service_package:obj:1" version="1">
          <unix:filepath>/usr/lib/systemd/system/chrony-wait.service</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_chrony_wait_service_execstart:obj:1" version="1">
          <ind:filepath>/etc/systemd/system/chrony-wait.service</ind:filepath>
          <ind:pattern operation="pattern match">^ExecStart=(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_chronyd_cmdport_value:obj:1" version="1">
          <ind:filepath>/etc/chrony.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*cmdport[\s]+(\S+)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_ntp_set_maxpoll:obj:1" version="1">
          <ind:filepath>/etc/ntp.conf</ind:filepath>
          <ind:pattern operation="pattern match">^server[\s]+[\S]+.*maxpoll[\s]+(\d+)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_chrony_set_maxpoll:obj:1" version="1">
          <ind:filepath operation="pattern match">^(/etc/chrony\.conf|/etc/chrony\.d/.+\.conf)$</ind:filepath>
          <ind:pattern operation="pattern match">^(?:server|pool|peer)[\s]+[\S]+.*maxpoll[\s]+(\d+)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_ntp_all_server_has_maxpoll:obj:1" version="1">
          <ind:filepath>/etc/ntp.conf</ind:filepath>
          <ind:pattern operation="pattern match">^server[\s]+[\S]+[\s]+(.*)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_chrony_all_server_has_maxpoll:obj:1" version="1">
          <ind:filepath operation="pattern match">^(/etc/chrony\.conf|/etc/chrony\.d/.+\.conf)$</ind:filepath>
          <ind:pattern operation="pattern match">^(?:server|pool|peer)[\s]+[\S]+[\s]+(.*)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_chronyd_run_as_chrony_user:obj:1" version="1">
          <ind:filepath>/etc/sysconfig/chronyd</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*OPTIONS=(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="The configuration file /etc/sysconfig/chronyd for chronyd_run_as_chrony_user" id="oval:ssg-obj_chronyd_run_as_chrony_user_config_file:obj:1" version="1">
          <unix:filepath operation="pattern match">^/etc/sysconfig/chronyd</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object comment="Matches server entries in Chrony conf files" id="oval:ssg-object_chronyd_server_directive:obj:1" version="1">
          <ind:filepath operation="pattern match">^(/etc/chrony\.conf|/etc/chrony\.d/.+\.conf)$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*server.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Matches pool entries in Chrony conf files" id="oval:ssg-object_chronyd_no_pool_directive:obj:1" version="1">
          <ind:filepath operation="pattern match">^(/etc/chrony\.conf|/etc/chrony\.d/.+\.conf)$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]+pool.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check main chrony.conf for server/pool directives" id="oval:ssg-obj_chronyd_server_in_main_conf:obj:1" version="1">
          <ind:filepath>/etc/chrony.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?:server|pool)[\s]+.+$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Extract sourcedir paths from chrony.conf" id="oval:ssg-obj_extract_sourcedir_paths:obj:1" version="1">
          <ind:filepath>/etc/chrony.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*sourcedir[\s]+(\S+)[\s]*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check .sources files in sourcedir for server/pool directives" id="oval:ssg-obj_chronyd_server_in_sourcedir_files:obj:1" version="1">
          <ind:filepath operation="pattern match" var_check="at least one" var_ref="oval:ssg-var_sourcedir_file_paths_regex:var:1"/>
          <ind:pattern operation="pattern match">^[\s]*(?:server|pool)[\s]+.+$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Extract confdir paths from chrony.conf" id="oval:ssg-obj_extract_confdir_paths:obj:1" version="1">
          <ind:filepath>/etc/chrony.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*confdir[\s]+(\S+)[\s]*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check .conf files in confdir for server/pool directives" id="oval:ssg-obj_chronyd_server_in_confdir_files:obj:1" version="1">
          <ind:filepath operation="pattern match" var_check="at least one" var_ref="oval:ssg-var_confdir_file_paths_regex:var:1"/>
          <ind:pattern operation="pattern match">^[\s]*(?:server|pool)[\s]+.+$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_file_groupowner_etc_chrony_keys_nsswitch_uses_altfiles:obj:1" version="1">
          <ind:filepath>/etc/nsswitch.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*group:\s+(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_file_groupowner_etc_chrony_keys_package_nss-altfiles_installed:obj:1" version="1">
          <linux:name>nss-altfiles</linux:name>
        </linux:rpminfo_object>
        <unix:file_object comment="/etc/chrony.keys" id="oval:ssg-object_file_groupowner_etc_chrony_keys:obj:1" version="1">
          <unix:filepath>/etc/chrony.keys</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_chrony_keys_uid_chrony:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_chrony_keys_gid_chrony:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object comment="gid of the dedicated chrony group" id="oval:ssg-object_file_groupowner_etc_chrony_keys_etc_group:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^chrony:[\w!]+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/etc/chrony.keys" id="oval:ssg-object_file_groupowner_etc_chrony_keys_with_usrlib:obj:1" version="1">
          <unix:filepath>/etc/chrony.keys</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_chrony_keys_uid_chrony:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_chrony_keys_gid_chrony_with_usrlib:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object comment="gid of the dedicated chrony group" id="oval:ssg-object_file_groupowner_etc_chrony_keys_etc_group_with_usrlib:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_groupowner_etc_chrony_keys_etc_group:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_file_groupowner_etc_chrony_keys_usr_lib_group:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_file_groupowner_etc_chrony_keys_usr_lib_group:obj:1" version="1">
          <ind:filepath>/usr/lib/group</ind:filepath>
          <ind:pattern operation="pattern match">^chrony:[\w!]+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Ensure more than one ntpd NTP server is set" id="oval:ssg-obj_ntpd_multiple_servers:obj:1" version="1">
          <ind:filepath>/etc/ntp.conf</ind:filepath>
          <ind:pattern operation="pattern match">^([\s]*server[\s]+.+$){2,}$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Ensure at least one ntpd NTP server is set" id="oval:ssg-obj_ntp_remote_server:obj:1" version="1">
          <ind:filepath>/etc/ntp.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*server[\s]+.+$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="nsswitch.conf lines which have nis defined as a database" id="oval:ssg-object_no_nis_in_nsswitch:obj:1" version="1">
          <ind:filepath>/etc/nsswitch.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\w+\s+(\w+\s+)*nis($|\s+.*$)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="look for any shosts.equiv file on the system" id="oval:ssg-object_no_shosts_equiv_files_root:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path operation="equals">/</unix:path>
          <unix:filename operation="equals">shosts.equiv</unix:filename>
        </unix:file_object>
        <unix:file_object comment="look for .rhosts in /root" id="oval:ssg-object_no_rsh_trust_files_root:obj:1" version="1">
          <unix:path operation="equals">/root</unix:path>
          <unix:filename operation="pattern match">^\.rhosts$</unix:filename>
        </unix:file_object>
        <unix:file_object comment="look for .rhosts in /home" id="oval:ssg-object_no_rsh_trust_files_home:obj:1" version="1">
          <unix:behaviors max_depth="1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/home</unix:path>
          <unix:filename operation="pattern match">^\.rhosts$</unix:filename>
        </unix:file_object>
        <unix:file_object comment="look for /etc/hosts.equiv" id="oval:ssg-object_no_rsh_trust_files_etc:obj:1" version="1">
          <unix:path operation="equals">/etc</unix:path>
          <unix:filename operation="pattern match">^hosts\.equiv$</unix:filename>
        </unix:file_object>
        <unix:file_object comment="look for any .shosts file on the system" id="oval:ssg-object_no_shosts_files_root:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path operation="equals">/</unix:path>
          <unix:filename operation="equals">.shosts</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_tftp_service_dropin:obj:1" version="1">
          <ind:path>/etc/systemd/system/tftp.service.d</ind:path>
          <ind:filename operation="pattern match">.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*ExecStart=\s*(?:.*\n)*?(\s*ExecStart=.+)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_tftp_uses_secure_mode_systemd_original:obj:1" version="1">
          <ind:filepath>/usr/lib/systemd/system/tftp.service</ind:filepath>
          <ind:pattern operation="pattern match">^\s*ExecStart\s*=\s*/\S+\s+-s\s+(/\S+).*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_tftpd_uses_secure_mode:obj:1" version="1">
          <ind:filepath>/etc/xinetd.d/tftp</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*server_args[\s]+=[\s]+.*?-s[\s]+([/\.\w]+).*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_cups_disable_browsing_browsing_off:obj:1" version="2">
          <ind:filepath>/etc/cups/cupsd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*Browsing[\s]+(?:Off|No)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_cups_disable_browsing_browseallow:obj:1" version="2">
          <ind:filepath>/etc/cups/cupsd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*BrowseAllow[\s]+(?:none)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_cups_disable_printserver_disable_port:obj:1" version="2">
          <ind:filepath>/etc/cups/cupsd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*Port[\s]+(\d)+</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_cups_disable_printserver_use_listen:obj:1" version="2">
          <ind:filepath>/etc/cups/cupsd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*Listen[\s]+(?:localhost|127\.0\.0\.1|::1):(\d)+</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_20340111:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*[\S]+[\s]+[\S]+[\s]+cifs[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_20340112:obj:1" version="1">
          <ind:filepath>/etc/mtab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*[\S]+[\s]+[\S]+[\s]+cifs[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_require_smb_client_signing:obj:1" version="1">
          <ind:filepath>/etc/samba/smb.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*client[\s]+signing[\s]*=[\s]*mandatory</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_snmp_default_communities:obj:1" version="1">
          <ind:filepath>/etc/snmp/snmpd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^((?!#).)*(public|private).*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_snmp_versions:obj:1" version="1">
          <ind:filepath>/etc/snmp/snmpd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(com2se|rocommunity|rwcommunity)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="All keys in /etc/ssh with unsafe ownership/permission combination" id="oval:ssg-object_offending_keys:obj:1" version="1">
          <unix:path>/etc/ssh</unix:path>
          <unix:filename operation="pattern match">.*_key$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__sshd_private_key:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-filter_ssh_key_owner_root:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-filter_ssh_key_owner_ssh_keys:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object comment="gid of the dedicated ssh key group" id="oval:ssg-obj_dedicated_group_gid:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^ssh_keys:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:xmlfilecontent_object id="oval:ssg-object_firewalld_service_sshd:obj:1" version="1">
          <ind:path>/etc/firewalld/services</ind:path>
          <ind:filename operation="pattern match">^.*\.xml$</ind:filename>
          <ind:xpath>/service/service[@name='ssh']</ind:xpath>
        </ind:xmlfilecontent_object>
        <ind:xmlfilecontent_object id="oval:ssg-object_firewalld_service_sshd_port:obj:1" version="1">
          <ind:path>/etc/firewalld/services</ind:path>
          <ind:filename operation="pattern match">^.*\.xml$</ind:filename>
          <ind:xpath>/service/port[@port='22']</ind:xpath>
        </ind:xmlfilecontent_object>
        <ind:xmlfilecontent_object id="oval:ssg-object_firewalld_zone_sshd:obj:1" version="1">
          <ind:path>/etc/firewalld/zones</ind:path>
          <ind:filename operation="pattern match">^.*\.xml$</ind:filename>
          <ind:xpath>/zone/service[@name='ssh']</ind:xpath>
        </ind:xmlfilecontent_object>
        <ind:xmlfilecontent_object id="oval:ssg-object_firewalld_zone_sshd_port:obj:1" version="1">
          <ind:path>/etc/firewalld/zones</ind:path>
          <ind:filename operation="pattern match">^.*\.xml$</ind:filename>
          <ind:xpath>/zone/port[@port='22']</ind:xpath>
        </ind:xmlfilecontent_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_ssh_client_rekey_limit_main_config:obj:1" version="1">
          <ind:filepath>/etc/ssh/ssh_config</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*RekeyLimit.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_ssh_client_rekey_limit_include_configs:obj:1" version="1">
          <ind:path>/etc/ssh/ssh_config.d</ind:path>
          <ind:filename operation="pattern match">.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-ssh_client_line_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_ssh_client_strong_rng_csh:obj:1" version="1">
          <ind:filepath>/etc/profile.d/cc-ssh-strong-rng.csh</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*setenv[\s]+SSH_USE_STRONG_RNG[\s]+([\d]+)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_ssh_client_strong_rng_csh_not_overridden:obj:1" version="1">
          <ind:filepath>/etc/profile</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*setenv[\s]+SSH_USE_STRONG_RNG.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_ssh_client_strong_rng_sh:obj:1" version="1">
          <ind:filepath>/etc/profile.d/cc-ssh-strong-rng.sh</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*export[\s]+SSH_USE_STRONG_RNG=([\d]+)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_ssh_client_strong_rng_sh_not_overridden:obj:1" version="1">
          <ind:filepath>/etc/profile</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*export[\s]+SSH_USE_STRONG_RNG=.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:xmlfilecontent_object id="oval:ssg-object_firewalld_sshd_port_enabled_zone_files_usr:obj:1" version="1">
          <ind:path>/usr/lib/firewalld/zones</ind:path>
          <ind:filename operation="pattern match" var_check="all" var_ref="oval:ssg-var_firewalld_sshd_port_enabled_default_zones:var:1"/>
          <ind:xpath>/zone/service[@name='ssh']</ind:xpath>
        </ind:xmlfilecontent_object>
        <unix:file_object id="oval:ssg-object_firewalld_sshd_port_enabled_customized_zone_files:obj:1" version="1">
          <unix:behaviors max_depth="1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path>/etc/firewalld/zones</unix:path>
          <unix:filename operation="pattern match" var_check="at least one" var_ref="oval:ssg-var_firewalld_sshd_port_enabled_default_zones:var:1"/>
        </unix:file_object>
        <ind:variable_object id="oval:ssg-object_firewalld_sshd_port_enabled_custom_zone_files_with_ssh_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_firewalld_sshd_port_enabled_custom_zone_files_with_ssh_count:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:xmlfilecontent_object id="oval:ssg-object_firewalld_sshd_port_enabled_zone_files_etc:obj:1" version="1">
          <ind:path>/etc/firewalld/zones</ind:path>
          <ind:filename operation="pattern match">^.*\.xml$</ind:filename>
          <ind:xpath>/zone/service[@name='ssh']</ind:xpath>
        </ind:xmlfilecontent_object>
        <unix:file_object id="oval:ssg-object_firewalld_sshd_port_enabled_custom_zone_files:obj:1" version="1">
          <unix:behaviors max_depth="1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/etc/firewalld/zones</unix:path>
          <unix:filename operation="pattern match">^.*\.xml$</unix:filename>
        </unix:file_object>
        <ind:xmlfilecontent_object id="oval:ssg-object_firewalld_sshd_port_enabled_ssh_service_file_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/firewalld/services/ssh.xml</ind:filepath>
          <ind:xpath>/service/port[@port='22']</ind:xpath>
        </ind:xmlfilecontent_object>
        <ind:textfilecontent54_object id="oval:ssg-object_firewalld_sshd_port_enabled_ssh_service_file_etc:obj:1" version="1">
          <ind:filepath>/etc/firewalld/services/ssh.xml</ind:filepath>
          <ind:pattern operation="pattern match">&lt;port.*port="(\d+)"</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_allow_user:obj:1" version="1">
          <ind:filepath operation="pattern match">^(/etc/ssh/sshd_config|/etc/ssh/sshd_config\.d/.*\.conf)$</ind:filepath>
          <ind:pattern datatype="string" operation="pattern match">(?i)^[ ]*AllowUsers[ ]+((?:[^ \n]+[ ]*)+)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_allow_group:obj:1" version="1">
          <ind:filepath operation="pattern match">^(/etc/ssh/sshd_config|/etc/ssh/sshd_config\.d/.*\.conf)$</ind:filepath>
          <ind:pattern datatype="string" operation="pattern match">(?i)^[ ]*AllowGroups[ ]+((?:[^ \n]+[ ]*)+)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_deny_user:obj:1" version="1">
          <ind:filepath operation="pattern match">^(/etc/ssh/sshd_config|/etc/ssh/sshd_config\.d/.*\.conf)$</ind:filepath>
          <ind:pattern datatype="string" operation="pattern match">(?i)^[ ]*DenyUsers[ ]+((?:[^ \n]+[ ]*)+)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_deny_group:obj:1" version="1">
          <ind:filepath operation="pattern match">^(/etc/ssh/sshd_config|/etc/ssh/sshd_config\.d/.*\.conf)$</ind:filepath>
          <ind:pattern datatype="string" operation="pattern match">(?i)^[ ]*DenyGroups[ ]+((?:[^ \n]+[ ]*)+)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_rekey_limit:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*RekeyLimit[\s]+(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_sshd_idle_timeout:obj:1" version="2">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?i)ClientAliveInterval[\s]+(\d+)[\s]*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_set_idle_timeout:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_sshd_idle_timeout:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_sshd_login_grace_time:obj:1" version="2">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?i)LoginGraceTime[\s]+(\d+)[\s]*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_set_login_grace_time:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_sshd_login_grace_time:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_sshd_max_auth_tries:obj:1" version="2">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?i)MaxAuthTries[\s]+(\d+)[\s]*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_set_max_auth_tries:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_sshd_max_auth_tries:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_sshd_max_sessions:obj:1" version="2">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?i)MaxSessions[\s]+(\d+)[\s]*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_set_max_sessions:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_sshd_max_sessions:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_config_maxstartups_first_parameter:obj:1" version="2">
          <ind:path operation="pattern match">/etc/(ssh|ssh/sshd_config.d)</ind:path>
          <ind:filename operation="pattern match">(sshd_config|.*\.conf)$</ind:filename>
          <ind:pattern datatype="string" operation="pattern match">(?i)^\s*MaxStartups\s+(\d+):\d+:\d+\s*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_config_maxstartups_second_parameter:obj:1" version="2">
          <ind:path operation="pattern match">/etc/(ssh|ssh/sshd_config.d)</ind:path>
          <ind:filename operation="pattern match">(sshd_config|.*\.conf)$</ind:filename>
          <ind:pattern datatype="string" operation="pattern match">(?i)^\s*MaxStartups\s+\d+:(\d+):\d+\s*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_config_maxstartups_third_parameter:obj:1" version="2">
          <ind:path operation="pattern match">/etc/(ssh|ssh/sshd_config.d)</ind:path>
          <ind:filename operation="pattern match">(sshd_config|.*\.conf)$</ind:filename>
          <ind:pattern datatype="string" operation="pattern match">(?i)^\s*MaxStartups\s+\d+:\d+:(\d+)\s*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-obj_sshd_use_approved_ciphers:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_sshd_config_ciphers:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_config_ciphers:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?i)Ciphers(?-i)[\s]+([\w,-@]+)+[\s]*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_use_approved_kex_ordered_stig:obj:1" version="1">
          <ind:filepath/>
          <ind:pattern operation="pattern match">.*</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-obj_sshd_use_approved_macs:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_sshd_config_macs:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_config_macs:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?i)MACs(?-i)[\s]+([\w,-@]+)+[\s]*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-obj_sshd_use_strong_kex:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_sshd_config_kex:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_config_kex:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?i)KexAlgorithms(?-i)[\s]+([\w,-@]+)+[\s]*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_sshd_kex_all_configs:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_config_kex:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-obj_sshd_use_strong_macs:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_sshd_config_strong_macs:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_config_strong_macs:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?i)MACs(?-i)[\s]+([\w,-@]+)+[\s]*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_sshd_macs_all_configs:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_config_strong_macs:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sssd_certificate_verification:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sssd/(sssd|conf\.d/.*)\.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*\[sssd](?:[^\n\[]*\n+)+?[\s]*certificate_verification\s*=\s*ocsp_dgst=(\w+)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sssd_enable_pam_services:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sssd/(sssd|conf\.d/.*)\.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\[sssd\].*(?:\n\s*[^[\s].*)*\n\s*services[ \t]*=[ \t]*(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sssd_enable_smartcards:obj:1" version="2">
          <ind:filepath operation="pattern match">/etc/sssd/(sssd\.conf|conf.d/[^/]+\.conf)</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*\[pam](?:[^\n\[]*\n+)+?[\s]*pam_cert_auth[\s]*=[\s]*(\w+)\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sssd_enable_smartcards_system_auth_options:obj:1" version="2">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match">^\s*auth.*?pam_sss\.so(.*)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sssd_memcache_timeout:obj:1" version="1">
          <ind:filepath>/etc/sssd/sssd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*\[nss](?:[^\n\[]*\n+)+?[\s]*memcache_timeout[\s]*=[\s]*(\d+)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sssd_offline_cred_expiration:obj:1" version="1">
          <ind:filepath>/etc/sssd/sssd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*\[pam](?:[^\n\[]*\n+)+?[\s]*offline_credentials_expiration[\s]*=[\s]*(\d+)\s*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="get last user value from each [sssd] section" id="oval:ssg-obj_sssd_user_value:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sssd/(sssd|conf\.d/.*)\.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\[sssd\].*(?:\n\s*[^[\s].*)*\n\s*user[ \t]*=[ \t]*(\S*)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sssd_ssh_known_hosts_timeout:obj:1" version="1">
          <ind:filepath>/etc/sssd/sssd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*\[ssh](?:[^\n\[]*\n+)+?[\s]*ssh_known_hosts_timeout[\s]*=[\s]*(\d+)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_sssd_ldap_tls_ca_dir:obj:1" version="2">
          <ind:filepath operation="pattern match">/etc/sssd/(sssd\.conf|conf.d/[^/]+\.conf)</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*\[domain\/[^]]*](?:[^\n[\]]*\n+)+?[\s]*ldap_tls_cacertdir[\s]+=[\s]+([^\s]+)[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_sssd_ldap_tls_reqcert:obj:1" version="2">
          <ind:filepath operation="pattern match">^\/etc\/sssd\/(sssd.conf|conf\.d\/.+\.conf)$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*\[domain\/[^]]*](?:[^\n\[\]]*\n+)+?[\s]*ldap_tls_reqcert[ \t]*=[ \t]*(\w+)[ \t]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_use_starttls_sssd_conf:obj:1" version="2">
          <ind:filepath operation="pattern match">^\/etc\/sssd\/(sssd.conf|conf\.d\/.+\.conf)$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*\[domain\/[^]]*](?:[^\n\[\]]*\n+)+?[\s]*ldap_id_use_start_tls[ \t]*=[ \t]*((?i)\w+)[ \t]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_xorg-x11-server-Xorg_removed:obj:1" version="1">
          <linux:name>xorg-x11-server-Xorg</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_xorg-x11-server-common_removed:obj:1" version="1">
          <linux:name>xorg-x11-server-common</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_xorg-x11-server-utils_removed:obj:1" version="1">
          <linux:name>xorg-x11-server-utils</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_xorg-x11-server-Xwayland_removed:obj:1" version="1">
          <linux:name>xorg-x11-server-Xwayland</linux:name>
        </linux:rpminfo_object>
        <unix:symlink_object comment="default.target systemd softlink exists" id="oval:ssg-object_disable_xwindows_runlevel_target:obj:1" version="1">
          <unix:filepath>/etc/systemd/system/default.target</unix:filepath>
        </unix:symlink_object>
        <unix:symlink_object comment="see the test comment" id="oval:ssg-object_pam_fingerprint_symlinked_to_authselect:obj:1" version="1">
          <unix:filepath>/etc/pam.d/fingerprint-auth</unix:filepath>
        </unix:symlink_object>
        <unix:symlink_object comment="see the test comment" id="oval:ssg-object_pam_password_symlinked_to_authselect:obj:1" version="1">
          <unix:filepath>/etc/pam.d/password-auth</unix:filepath>
        </unix:symlink_object>
        <unix:symlink_object comment="see the test comment" id="oval:ssg-object_pam_postlogin_symlinked_to_authselect:obj:1" version="1">
          <unix:filepath>/etc/pam.d/postlogin</unix:filepath>
        </unix:symlink_object>
        <unix:symlink_object comment="see the test comment" id="oval:ssg-object_pam_smartcard_symlinked_to_authselect:obj:1" version="1">
          <unix:filepath>/etc/pam.d/smartcard-auth</unix:filepath>
        </unix:symlink_object>
        <unix:symlink_object comment="see the test comment" id="oval:ssg-object_pam_system_symlinked_to_authselect:obj:1" version="1">
          <unix:filepath>/etc/pam.d/system-auth</unix:filepath>
        </unix:symlink_object>
        <ind:textfilecontent54_object id="oval:ssg-object_banner_etc_issue:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath operation="pattern match">^/etc/issue(\.d/.*)?$</ind:filepath>
          <ind:pattern operation="pattern match">^(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_banner_etc_issue_net:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath operation="pattern match">^/etc/issue\.net$</ind:filepath>
          <ind:pattern operation="pattern match">^(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-object_banner_etc_motd_exists:obj:1" version="1">
          <unix:filepath>/etc/motd</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_banner_etc_motd:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath>/etc/motd</ind:filepath>
          <ind:pattern operation="pattern match">^(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_banner_gui_enabled:obj:1" version="1">
          <ind:path>/etc/dconf/db/gdm.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/login-screen\]([^\n]*\n+)+?banner-message-enable=true$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_banner_gui_enabled_change:obj:1" version="1">
          <ind:path>/etc/dconf/db/gdm.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/login-screen/banner-message-enable$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_banner_change:obj:1" version="1">
          <ind:path>/etc/dconf/db/gdm.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/login-screen/banner-message-text$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_gdm_login_banner_text_setting:obj:1" version="1">
          <ind:path>/etc/dconf/db/gdm.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^banner-message-text=[\s]*'*(.*?)'$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_authselect_profile:obj:1" version="1">
          <ind:filepath>/etc/authselect/authselect.conf</ind:filepath>
          <ind:pattern operation="pattern match">^(.+)$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_pam_pwquality_system_auth:obj:1" version="1">
          <ind:filepath var_ref="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_pam_pwquality_system_auth_path:var:1"/>
          <ind:pattern operation="pattern match">^\s*\S+\s+\S+\s+pam_pwquality\.so</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_pam_pwhistory_system_auth:obj:1" version="1">
          <ind:filepath var_ref="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_pam_pwhistory_system_auth_path:var:1"/>
          <ind:pattern operation="pattern match">^\s*\S+\s+\S+\s+pam_pwhistory\.so</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_pam_faillock_system_auth:obj:1" version="1">
          <ind:filepath var_ref="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_pam_faillock_system_auth_path:var:1"/>
          <ind:pattern operation="pattern match">^\s*\S+\s+\S+\s+pam_faillock\.so</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_pam_unix_system_auth:obj:1" version="1">
          <ind:filepath var_ref="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_pam_unix_system_auth_path:var:1"/>
          <ind:pattern operation="pattern match">^\s*\S+\s+\S+\s+pam_unix\.so</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_pam_pwquality_password_auth:obj:1" version="1">
          <ind:filepath var_ref="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_pam_pwquality_password_auth_path:var:1"/>
          <ind:pattern operation="pattern match">^\s*\S+\s+\S+\s+pam_pwquality\.so</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_pam_pwhistory_password_auth:obj:1" version="1">
          <ind:filepath var_ref="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_pam_pwhistory_password_auth_path:var:1"/>
          <ind:pattern operation="pattern match">^\s*\S+\s+\S+\s+pam_pwhistory\.so</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_pam_faillock_password_auth:obj:1" version="1">
          <ind:filepath var_ref="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_pam_faillock_password_auth_path:var:1"/>
          <ind:pattern operation="pattern match">^\s*\S+\s+\S+\s+pam_faillock\.so</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_pam_unix_password_auth:obj:1" version="1">
          <ind:filepath var_ref="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_pam_unix_password_auth_path:var:1"/>
          <ind:pattern operation="pattern match">^\s*\S+\s+\S+\s+pam_unix\.so</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the occurrences of pam_unix.so in auth section of /etc/pam.d/password-auth" id="oval:ssg-obj_pam_unix_password-auth_auth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*auth[\s]+(required|sufficient)[\s]+pam_unix\.so.*$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the occurrences of pam_unix.so in account section of /etc/pam.d/password-auth" id="oval:ssg-obj_pam_unix_password-auth_account:obj:1" version="1">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*account[\s]+(required|sufficient)[\s]+pam_unix\.so.*$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the occurrences of pam_unix.so in password section of /etc/pam.d/password-auth" id="oval:ssg-obj_pam_unix_password-auth_password:obj:1" version="1">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*password[\s]+(required|sufficient)[\s]+pam_unix\.so.*$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the occurrences of pam_unix.so in session section of /etc/pam.d/password-auth" id="oval:ssg-obj_pam_unix_password-auth_session:obj:1" version="1">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*session[\s]+(required|sufficient)[\s]+pam_unix\.so.*$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the occurrences of pam_unix.so in auth section of /etc/pam.d/system-auth" id="oval:ssg-obj_pam_unix_system-auth_auth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*auth[\s]+(required|sufficient)[\s]+pam_unix\.so.*$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the occurrences of pam_unix.so in account section of /etc/pam.d/system-auth" id="oval:ssg-obj_pam_unix_system-auth_account:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*account[\s]+(required|sufficient)[\s]+pam_unix\.so.*$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the occurrences of pam_unix.so in password section of /etc/pam.d/system-auth" id="oval:ssg-obj_pam_unix_system-auth_password:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*password[\s]+(required|sufficient)[\s]+pam_unix\.so.*$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the occurrences of pam_unix.so in session section of /etc/pam.d/system-auth" id="oval:ssg-obj_pam_unix_system-auth_session:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*session[\s]+(required|sufficient)[\s]+pam_unix\.so.*$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_disallow_bypass_password_sudo:obj:1" version="1">
          <ind:filepath>/etc/pam.d/sudo</ind:filepath>
          <ind:pattern operation="pattern match">^.*pam_succeed_if.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_display_login_attempts:obj:1" version="2">
          <ind:filepath>/etc/pam.d/postlogin</ind:filepath>
          <ind:pattern operation="pattern match">^\s*session\s+.*\s+pam_lastlog.so\b(?!.*\ssilent\s).*\sshowfailed\s.*$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_enable_pam_namespace:obj:1" version="1">
          <ind:filepath>/etc/pam.d/login</ind:filepath>
          <ind:pattern operation="pattern match">^\s*session\s+required\s+pam_namespace\.so\s*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get all occurrences of pam_unix.so in auth section of password-auth" id="oval:ssg-obj_pam_faillock_password_auth_pam_unix_auth:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/password-auth$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*auth\N+pam_unix\.so</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in auth section of password-auth" id="oval:ssg-obj_pam_faillock_password_auth_pam_faillock_auth:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/password-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_pam_faillock_password_auth_pam_faillock_auth_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in account section of password-auth" id="oval:ssg-obj_pam_faillock_password_auth_pam_faillock_account:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/password-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_pam_faillock_password_auth_pam_faillock_account_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get all occurrences of pam_unix.so in auth section of system-auth" id="oval:ssg-obj_pam_faillock_system_auth_pam_unix_auth:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/system-auth$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*auth\N+pam_unix\.so</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in auth section of system-auth" id="oval:ssg-obj_pam_faillock_system_auth_pam_faillock_auth:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/system-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_pam_faillock_system_auth_pam_faillock_auth_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in account section of system-auth" id="oval:ssg-obj_pam_faillock_system_auth_pam_faillock_account:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/system-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_pam_faillock_system_auth_pam_faillock_account_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_account_password_selinux_faillock_dir_collector:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/pam.d/password-auth|/etc/pam.d/system-auth|/etc/security/faillock.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*(?:auth.*pam_faillock\.so.*)?dir\s*=\s*(\S+)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:selinuxsecuritycontext_object comment="SELinux context information from pam_faillock.so tally directories" id="oval:ssg-object_account_password_selinux_faillock_dir:obj:1" version="1">
          <linux:path operation="equals" var_check="at least one" var_ref="oval:ssg-var_account_password_selinux_faillock_dir_collector:var:1"/>
          <linux:filename xsi:nil="true"/>
        </linux:selinuxsecuritycontext_object>
        <ind:variable_object id="oval:ssg-object_account_password_selinux_faillock_dir_not_set:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_account_password_selinux_faillock_dir_collector:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so preauth audit parameter from system-auth file" id="oval:ssg-obj_all_account_pam_faillock_audit_parameter_system_auth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_account_pam_faillock_audit_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so preauth audit parameter from system-auth file" id="oval:ssg-obj_all_account_pam_faillock_audit_parameter_password_auth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_account_pam_faillock_audit_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check the expected pam_faillock.so audit parameter in /etc/security/faillock.conf" id="oval:ssg-object_account_pam_faillock_audit_parameter_faillock_conf:obj:1" version="1">
          <ind:filepath>/etc/security/faillock.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*audit</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_password_pam_pwhistory_remember_password_auth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-var_accounts_password_pam_pwhistory_remember_password_auth_module_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_password_pam_pwhistory_remember_password_auth_pamd:obj:1" version="1">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-var_accounts_password_pam_pwhistory_remember_password_auth_pam_param_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Collect the pam_pwhistory.so remember parameter from /etc/security/pwhistory.conf" id="oval:ssg-object_accounts_password_pam_pwhistory_remember_password_auth_param_conf:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/security/pwhistory.conf$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_password_pam_pwhistory_remember_password_auth_conf_param_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_password_pam_pwhistory_remember_system_auth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-var_accounts_password_pam_pwhistory_remember_system_auth_module_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_password_pam_pwhistory_remember_system_auth_pamd:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-var_accounts_password_pam_pwhistory_remember_system_auth_pam_param_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Collect the pam_pwhistory.so remember parameter from /etc/security/pwhistory.conf" id="oval:ssg-object_accounts_password_pam_pwhistory_remember_system_auth_param_conf:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/security/pwhistory.conf$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_password_pam_pwhistory_remember_system_auth_conf_param_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-accounts_password_pam_pwhistory_use_authtok_obj_pwhistory_exists_system-auth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match">^[^#\n\r]*password[ \t]+.*pam_pwhistory\.so.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-accounts_password_pam_pwhistory_use_authtok_obj_use_authtok_system-auth:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-accounts_password_pam_pwhistory_use_authtok_obj_use_authtok_password_lines_except_first_system-auth:obj:1</oval-def:object_reference>
            <oval-def:filter action="include">oval:ssg-accounts_password_pam_pwhistory_use_authtok_ste_use_authtok_pam_pwhistory_lines:ste:1</oval-def:filter>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-accounts_password_pam_pwhistory_use_authtok_obj_use_authtok_password_lines_except_first_system-auth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*password[ \t]+(.+)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">2</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_accounts_password_pam_unix_authtok_pam_unix_exists_common-password:obj:1" version="1">
          <ind:filepath>/etc/pam.d/common-password</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*password[ \t]+[^#\n\r]+[ \t]+pam_unix\.so.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_accounts_password_pam_unix_authtok_pam_unix_lines_not_initial_common-password:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_accounts_password_pam_unix_authtok_password_lines_not_initial_common-password:obj:1</oval-def:object_reference>
            <oval-def:filter action="include">oval:ssg-ste_accounts_password_pam_unix_authtok_pam_unix_lines:ste:1</oval-def:filter>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_accounts_password_pam_unix_authtok_password_lines_not_initial_common-password:obj:1" version="1">
          <ind:filepath>/etc/pam.d/common-password</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*password[ \t]+(.+)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">2</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_password_pam_unix_remember:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-var_accounts_password_pam_unix_remember_module_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_password_pam_unix_remember_pamd:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-var_accounts_password_pam_unix_remember_pam_param_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Collect the pam_pwhistory.so remember parameter from /etc/security/pwhistory.conf" id="oval:ssg-object_accounts_password_pam_unix_remember_param_conf:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/security/pwhistory.conf$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_password_pam_unix_remember_conf_param_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_password_pam_unix_remember_legacy:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match">^\s*password\s+(?:(?:sufficient)|(?:required)|(?:\[.*\]))\s+pam_unix\.so.*remember=([0-9]*).*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so preauth audit parameter from system-auth file" id="oval:ssg-obj_all_pam_faillock_audit_parameter_system_auth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_pam_faillock_audit_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so preauth audit parameter from system-auth file" id="oval:ssg-obj_all_pam_faillock_audit_parameter_password_auth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_pam_faillock_audit_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check the expected pam_faillock.so audit parameter in /etc/security/faillock.conf" id="oval:ssg-object_pam_faillock_audit_parameter_faillock_conf:obj:1" version="1">
          <ind:filepath>/etc/security/faillock.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*audit</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the second and subsequent occurrences of pam_unix.so in auth section of system-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_system_pam_unix_auth:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/system-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_root_pam_unix_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the second and subsequent occurrences of pam_unix.so in auth section of password-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_password_pam_unix_auth:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/password-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_root_pam_unix_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in auth section of system-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_system_pam_faillock_auth:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/system-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_root_pam_faillock_auth_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in account section of system-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_system_pam_faillock_account:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/system-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_root_pam_faillock_account_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in auth section of password-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_password_pam_faillock_auth:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/password-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_root_pam_faillock_auth_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in account section of password-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_password_pam_faillock_account:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/password-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_root_pam_faillock_account_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so even_deny_root parameter from system-auth file" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_parameter_pamd_system:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/system-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_root_pam_faillock_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so even_deny_root parameter from password-auth file" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_parameter_pamd_password:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/password-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_root_pam_faillock_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Try to get the even_deny_root parameter from /etc/security/faillock.conf" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_root_parameter_faillock_conf:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/security/faillock.conf$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_root_faillock_conf_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so preauth dir parameter from system-auth file" id="oval:ssg-obj_all_pam_faillock_dir_parameter_system_auth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_pam_faillock_dir_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="include">oval:ssg-state_pam_faillock_dir_parameter_not_default_value:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so preauth dir parameter from system-auth file" id="oval:ssg-obj_all_pam_faillock_dir_parameter_password_auth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_pam_faillock_dir_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="include">oval:ssg-state_pam_faillock_dir_parameter_not_default_value:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-obj_pam_faillock_dir_parameter_system_auth:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_faillock_dir_set_both_preauth_authfail_system_auth:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:variable_object id="oval:ssg-obj_pam_faillock_dir_parameter_password_auth:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_faillock_dir_set_both_preauth_authfail_password_auth:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object comment="Check the expected pam_faillock.so dir parameter in /etc/security/faillock.conf" id="oval:ssg-object_pam_faillock_dir_parameter_faillock_conf:obj:1" version="1">
          <ind:filepath>/etc/security/faillock.conf</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_faillock_conf_dir_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the second and subsequent occurrences of pam_unix.so in auth section of system-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_enforce_local_system_pam_unix_auth:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/system-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_enforce_local_pam_unix_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the second and subsequent occurrences of pam_unix.so in auth section of password-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_enforce_local_password_pam_unix_auth:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/password-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_enforce_local_pam_unix_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in auth section of system-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_enforce_local_system_pam_faillock_auth:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/system-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_enforce_local_pam_faillock_auth_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in account section of system-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_enforce_local_system_pam_faillock_account:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/system-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_enforce_local_pam_faillock_account_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in auth section of password-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_enforce_local_password_pam_faillock_auth:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/password-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_enforce_local_pam_faillock_auth_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in account section of password-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_enforce_local_password_pam_faillock_account:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/password-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_enforce_local_pam_faillock_account_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Try to get the local_users_only parameter from /etc/security/faillock.conf" id="oval:ssg-object_accounts_passwords_pam_faillock_enforce_local_parameter_faillock_conf:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/security/faillock.conf$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_enforce_local_faillock_conf_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the second and subsequent occurrences of pam_unix.so in auth section of system-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_system_pam_unix_auth:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/system-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_pam_unix_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the second and subsequent occurrences of pam_unix.so in auth section of password-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_password_pam_unix_auth:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/password-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_pam_unix_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in auth section of system-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_system_pam_faillock_auth:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/system-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_pam_faillock_auth_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in account section of system-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_system_pam_faillock_account:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/system-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_pam_faillock_account_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in auth section of password-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_password_pam_faillock_auth:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/password-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_pam_faillock_auth_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in account section of password-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_password_pam_faillock_account:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/password-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_pam_faillock_account_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so even_deny_root parameter from system-auth file" id="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_pamd_system:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/system-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so even_deny_root parameter from password-auth file" id="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_pamd_password:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/password-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Try to get the even_deny_root parameter from /etc/security/faillock.conf" id="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_faillock_conf:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/security/faillock.conf$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_faillock_conf_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so root_unlock_time parameter from system-auth file" id="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_pamd_system:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/system-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so root_unlock_time parameter from password-auth file" id="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_pamd_password:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/password-auth$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the root_unlock_time parameter from /etc/security/faillock.conf" id="oval:ssg-object_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_faillock_conf:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/security/faillock.conf$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_faillock_conf_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so preauth silent parameter from system-auth file" id="oval:ssg-obj_all_pam_faillock_silent_parameter_system_auth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_pam_faillock_silent_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so preauth silent parameter from system-auth file" id="oval:ssg-obj_all_pam_faillock_silent_parameter_password_auth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_pam_faillock_silent_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check the expected pam_faillock.so silent parameter in /etc/security/faillock.conf" id="oval:ssg-object_pam_faillock_silent_parameter_faillock_conf:obj:1" version="1">
          <ind:filepath>/etc/security/faillock.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*silent</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the second and subsequent occurrences of pam_unix.so in auth section of system-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_system_pam_unix_auth:obj:1" version="2">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_with_zero_pam_unix_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in auth section of common-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_system_pam_faillock_auth:obj:1" version="2">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_with_zero_pam_faillock_auth_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the second and subsequent occurrences of pam_unix.so in auth section of password-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_password_pam_unix_auth:obj:1" version="2">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_with_zero_pam_unix_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in auth section of common-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_password_pam_faillock_auth:obj:1" version="2">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_with_zero_pam_faillock_auth_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in account section of system-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_system_pam_faillock_account:obj:1" version="2">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_with_zero_pam_faillock_account_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in account section of password-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_password_pam_faillock_account:obj:1" version="2">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_with_zero_pam_faillock_account_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so unlock_time parameter from system-auth file" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_pamd_system:obj:1" version="2">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_with_zero_pam_faillock_unlock_time_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so unlock_time parameter from password-auth file" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_pamd_password:obj:1" version="2">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_with_zero_pam_faillock_unlock_time_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check the expected pam_faillock.so unlock_time parameter in /etc/security/faillock.conf" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_faillock_conf:obj:1" version="1">
          <ind:filepath>/etc/security/faillock.conf</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_with_zero_faillock_conf_unlock_time_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_password_pam_pwquality_enforce_for_root:obj:1" version="3">
          <ind:filepath operation="pattern match">^/etc/security/pwquality.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^enforce_for_root$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_password_pam_pwquality_password_auth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match">^password[\s]*requisite[\s]*pam_pwquality\.so</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_password_pam_pwquality_system_auth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match">^password[\s]*requisite[\s]*pam_pwquality\.so</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_password_pam_pwquality_retry_system_auth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match">^\s*password\s+(?:(?:required)|(?:requisite))\s+pam_pwquality\.so.*retry=([0-9]*).*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_password_pam_pwquality_retry_pwquality_conf:obj:1" version="1">
          <ind:filepath>/etc/security/pwquality.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*retry[\s]*=[\s]*(\d+)(?:[\s]|$)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="only one hashing algorithm option for pam_unix.so is found in /etc/libuser.conf" id="oval:ssg-object_set_password_hashing_algorithm_libuserconf:obj:1" version="2">
          <ind:filepath>/etc/libuser.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*crypt_style[\s]*=[\s]*(\w*)[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_test_password_hashing_algorithm_logindefs:obj:1" version="1">
          <ind:filepath>/etc/login.defs</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?i)(ENCRYPT_METHOD[\s]+\w+)[\s]*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-variable_object_test_password_hashing_algorithm_logindefs:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_variable_test_password_hashing_algorithm_logindefs:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object comment="only one hashing algorithm option for pam_unix.so is found in /etc/pam.d/password-auth" id="oval:ssg-object_set_password_hashing_algorithm_passwordauth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*password[\s]+(?:(?:required)|(?:sufficient))[\s]+pam_unix\.so[\s]+(?!.*(sha512|yescrypt|gost_yescrypt|blowfish|sha256|md5|bigcrypt).*(sha512|yescrypt|gost_yescrypt|blowfish|sha256|md5|bigcrypt)).*(sha512|yescrypt|gost_yescrypt|blowfish|sha256|md5|bigcrypt).*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="only one hashing algorithm option for pam_unix.so is found in /etc/pam.d/system-auth" id="oval:ssg-object_pam_unix_hashing_algorithm_systemauth:obj:1" version="1">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*password[\s]+(?:(?:required)|(?:sufficient))[\s]+pam_unix\.so[\s]+(?!.*\b(sha512|yescrypt|gost_yescrypt|blowfish|sha256|md5|bigcrypt)\b[^#]*\b(sha512|yescrypt|gost_yescrypt|blowfish|sha256|md5|bigcrypt)\b)[^#]*\b(sha512|yescrypt|gost_yescrypt|blowfish|sha256|md5|bigcrypt)\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_login_defs_sha_crypt_min_rounds_default:obj:1" version="1">
          <ind:filepath>/etc/login.defs</ind:filepath>
          <ind:pattern operation="pattern match">^\s*SHA_CRYPT_MIN_ROUNDS\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_login_defs_sha_crypt_min_rounds_present:obj:1" version="1">
          <ind:filepath>/etc/login.defs</ind:filepath>
          <ind:pattern operation="pattern match">^\s*SHA_CRYPT_MIN_ROUNDS\s+(\d+)\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_login_defs_sha_crypt_max_rounds_default:obj:1" version="1">
          <ind:filepath>/etc/login.defs</ind:filepath>
          <ind:pattern operation="pattern match">^\s*SHA_CRYPT_MAX_ROUNDS\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_login_defs_sha_crypt_max_rounds_present:obj:1" version="1">
          <ind:filepath>/etc/login.defs</ind:filepath>
          <ind:pattern operation="pattern match">^\s*SHA_CRYPT_MAX_ROUNDS\s+(\d+)\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_password_hashing_min_rounds_login_defs_le_5000:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_password_hashing_min_rounds_login_defs:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_disable_ctrlaltdel_burstaction:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/systemd/system.conf(\.d/.*\.conf)?$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*CtrlAltDelBurstAction[\s]*=[\s]*none$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:symlink_object comment="Disable Ctrl-Alt-Del key sequence override exists" id="oval:ssg-object_disable_ctrlaltdel_exists:obj:1" version="1">
          <unix:filepath>/etc/systemd/system/ctrl-alt-del.target</unix:filepath>
        </unix:symlink_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_disable_interactive_boot_grub_cmdline_linux:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(?:.*\s)?systemd\.confirm_spawn(?:=(?:1|yes|true|on))?(?:\s.*)?"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_disable_interactive_boot_grub_cmdline_linux_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT=".*systemd\.confirm_spawn=(?:1|yes|true|on).*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_logind_session_timeout:obj:1" version="1">
          <ind:filepath>/etc/systemd/logind.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\[Login\].*(?:\n\s*[^[\s].*)*\n^\s*StopIdleSessionSec[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="The configuration file /etc/systemd/logind.conf for logind_session_timeout" id="oval:ssg-obj_logind_session_timeout_config_file:obj:1" version="1">
          <unix:filepath operation="pattern match">^/etc/systemd/logind.conf</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_require_emergency_service:obj:1" version="1">
          <ind:filepath>/usr/lib/systemd/system/emergency.service</ind:filepath>
          <ind:pattern operation="pattern match">^ExecStart=\-/bin/sh[\s]+-c[\s]+\"(/usr)?/sbin/sulogin;[\s]+/usr/bin/systemctl[\s]+--fail[\s]+--no-block[\s]+default\"</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_require_emergency_service_emergency:obj:1" version="1">
          <ind:filepath>/usr/lib/systemd/system/emergency.target</ind:filepath>
          <ind:pattern operation="pattern match">^Requires=.*emergency\.service</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="look for emergency.service in /etc/systemd/system" id="oval:ssg-object_no_custom_emergency_service:obj:1" version="1">
          <unix:behaviors recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/etc/systemd/system</unix:path>
          <unix:filename operation="pattern match">^emergency.service$</unix:filename>
        </unix:file_object>
        <unix:file_object comment="look for emergency.target in /etc/systemd/system" id="oval:ssg-object_no_custom_emergency_target:obj:1" version="1">
          <unix:behaviors recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/etc/systemd/system</unix:path>
          <unix:filename operation="pattern match">^emergency.target$</unix:filename>
        </unix:file_object>
        <unix:file_object comment="Look for drop in config files for emergency.service" id="oval:ssg-object_require_emergency_target_auth_drop_in_config_exist:obj:1" version="1">
          <unix:path operation="equals">/etc/systemd/system/emergency.service.d</unix:path>
          <unix:filename operation="pattern match">^.*\.conf$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_require_rescue_service_distro:obj:1" version="1">
          <ind:filepath>/usr/lib/systemd/system/rescue.service</ind:filepath>
          <ind:pattern operation="pattern match">^ExecStart\s?=\s?\-?(.*)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_require_rescue_service_override:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:path>/etc/systemd/system/rescue.service.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^.*ExecStart\s?=\s+.*ExecStart\s?=\s?\-?(.*)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_require_rescue_service_runlevel1:obj:1" version="1">
          <ind:filepath>/usr/lib/systemd/system/runlevel1.target</ind:filepath>
          <ind:pattern operation="pattern match">^Requires=.*rescue\.service</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="look for rescue.service in /etc/systemd/system" id="oval:ssg-object_no_custom_rescue_service:obj:1" version="1">
          <unix:behaviors recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/etc/systemd/system</unix:path>
          <unix:filename operation="pattern match">^rescue.service$</unix:filename>
        </unix:file_object>
        <unix:file_object comment="look for runlevel1.target or rescue.target in /etc/systemd/system" id="oval:ssg-object_no_custom_runlevel1_target:obj:1" version="1">
          <unix:behaviors recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/etc/systemd/system</unix:path>
          <unix:filename operation="pattern match">^runlevel1.target$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_configure_bashrc_exec_tmux:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath operation="pattern match">^/etc/bashrc$|^/etc/profile\.d/.*$</ind:filepath>
          <ind:pattern operation="pattern match">if \[ "\$PS1" \]; then\n\s+parent=\$\(ps -o ppid= -p \$\$\)\n\s+name=\$\(ps -o comm= -p \$parent\)\n\s+case "\$name" in \(?sshd\|login\) exec tmux ;; esac\nfi</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_configure_bashrc_tmux:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath operation="pattern match">^/etc/bashrc$|^/etc/profile\.d/.*$</ind:filepath>
          <ind:pattern operation="pattern match">if \[ "\$PS1" \]; then\n\s+parent=\$\(ps -o ppid= -p \$\$\)\n\s+name=\$\(ps -o comm= -p \$parent\)\n\s+case "\$name" in \(?sshd\|login\) tmux ;; esac\nfi</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_configure_tmux_lock_after_time:obj:1" version="2">
          <ind:filepath>/etc/tmux.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*set\s+-g\s+lock-after-time\s+(\d+)\s*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_configure_tmux_lock_command:obj:1" version="1">
          <ind:filepath>/etc/tmux.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*set\s+-g\s+lock-command\s+vlock\s*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_configure_tmux_lock_keybinding:obj:1" version="1">
          <ind:filepath>/etc/tmux.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*bind\s+[a-zA-Z]\s+lock-session(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_no_tmux_in_shells:obj:1" version="1">
          <ind:filepath>/etc/shells</ind:filepath>
          <ind:pattern operation="pattern match">tmux\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_configure_opensc_card_drivers:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/opensc.*\.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]+card_drivers[\s]+=[\s]+(\S+);$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_force_opensc_card_drivers:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/opensc.*\.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]+force_card_driver[\s]+=[\s]+(\S+);$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:password_object id="oval:ssg-obj_all_uids:obj:1" version="1">
          <unix:username operation="pattern match">.*</unix:username>
        </unix:password_object>
        <ind:variable_object id="oval:ssg-obj_count_of_all_uids:obj:1" version="1">
          <ind:var_ref>oval:ssg-variable_count_of_all_uids:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_authorized_local_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([a-zA-Z0-9_.-]+?):</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_default_os_user:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get all group ids" id="oval:ssg-obj_all_group_ids:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^.+:.+:(\d+):.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-obj_count_of_all_group_ids:obj:1" version="1">
          <ind:var_ref>oval:ssg-variable_count_of_all_group_ids:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object comment="Get all group names" id="oval:ssg-obj_all_group_names:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^(.+):.+</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-obj_count_of_all_group_names:obj:1" version="1">
          <ind:var_ref>oval:ssg-variable_count_of_all_group_names:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_no_nologin_in_shells:obj:1" version="1">
          <ind:filepath>/etc/shells</ind:filepath>
          <ind:pattern operation="pattern match">^[^#]*/nologin\b.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_default_useradd_inactive:obj:1" version="1">
          <ind:filepath>/etc/default/useradd</ind:filepath>
          <ind:pattern operation="pattern match">^\s*INACTIVE\s*=\s*(\d+)\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_passwd_content:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]+):.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_count_of_all_usernames_from_etc_passwd:obj:1" version="1">
          <ind:var_ref>oval:ssg-variable_count_of_all_usernames_from_etc_passwd:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-object_last_pass_max_days_from_etc_login_defs:obj:1" version="1">
          <ind:filepath>/etc/login.defs</ind:filepath>
          <ind:pattern operation="pattern match">^(?:.*\n)*\s*[^#]*(PASS_MAX_DAYS\s+\d+)\s*\n</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_last_pass_max_days_instance_value:obj:1" version="1">
          <ind:var_ref>oval:ssg-variable_last_pass_max_days_instance_value:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-object_last_pass_min_days_from_etc_login_defs:obj:1" version="1">
          <ind:behaviors singleline="true"/>
          <ind:filepath>/etc/login.defs</ind:filepath>
          <ind:pattern operation="pattern match">.*\n[^#]*(PASS_MIN_DAYS\s+\d+)\s*\n</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_last_pass_min_days_instance_value:obj:1" version="1">
          <ind:var_ref>oval:ssg-variable_last_pass_min_days_instance_value:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-object_last_pass_min_len_from_etc_login_defs:obj:1" version="1">
          <ind:behaviors singleline="true"/>
          <ind:filepath>/etc/login.defs</ind:filepath>
          <ind:pattern operation="pattern match">.*\n[^#]*(PASS_MIN_LEN\s+\d+)\s*\n</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_last_pass_min_len_instance_value:obj:1" version="1">
          <ind:var_ref>oval:ssg-variable_last_pass_min_len_instance_value:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-object_test_accounts_password_set_max_life_existing_password_max_life_existing:obj:1" version="1">
          <ind:filepath>/etc/shadow</ind:filepath>
          <ind:pattern operation="pattern match">^(?:[^:]*:)(?:[^\!\*:]*:)(?:[^:]*:){2}(\d+):(?:[^:]*:){3}(?:[^:]*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_test_accounts_password_set_max_life_existing_password_max_life_existing_minimum:obj:1" version="1">
          <ind:filepath>/etc/shadow</ind:filepath>
          <ind:pattern operation="pattern match">^(?:[^:]*:)(?:[^\!\*:]*:)(?:[^:]*:){2}(\d+):(?:[^:]*:){3}(?:[^:]*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_password_set_max_life_existing_shadow_password_users_max_life_not_existing:obj:1" version="1">
          <ind:filepath>/etc/shadow</ind:filepath>
          <ind:pattern operation="pattern match">^(?:[^:]*:)(?:[^\!\*:]+:)(?:[^:]*:){2}():(?:[^:]*:){3}(?:[^:]*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:shadow_object id="oval:ssg-object_accounts_password_set_max_life_root:obj:1" version="1">
          <unix:username operation="equals">root</unix:username>
        </unix:shadow_object>
        <ind:textfilecontent54_object id="oval:ssg-object_test_accounts_password_set_min_life_existing_password_max_life_existing:obj:1" version="1">
          <ind:filepath>/etc/shadow</ind:filepath>
          <ind:pattern operation="pattern match">^(?:[^:]*:)(?:[^\!\*:]*:)(?:[^:]*:)(\d+):(?:[^:]*:){4}(?:[^:]*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_test_accounts_password_set_min_life_existing_password_max_life_existing_minimum:obj:1" version="1">
          <ind:filepath>/etc/shadow</ind:filepath>
          <ind:pattern operation="pattern match">^(?:[^:]*:)(?:[^\!\*:]*:)(?:[^:]*:)(\d+):(?:[^:]*:){4}(?:[^:]*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_password_set_min_life_existing_shadow_password_users_max_life_not_existing:obj:1" version="1">
          <ind:filepath>/etc/shadow</ind:filepath>
          <ind:pattern operation="pattern match">^(?:[^:]*:)(?:[^\!\*:]+:)(?:[^:]*:)():(?:[^:]*:){4}(?:[^:]*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_test_accounts_password_set_warn_age_existing:obj:1" version="1">
          <ind:filepath>/etc/shadow</ind:filepath>
          <ind:pattern operation="pattern match">^(?:[^:]*:)(?:[^\!\*:]*:)(?:[^:]*:){3}(\d+):(?:[^:]*:){2}(?:[^:]*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_password_set_warn_age_existing_no_pass:obj:1" version="1">
          <ind:filepath>/etc/shadow</ind:filepath>
          <ind:pattern operation="pattern match">^(?:[^:]*:)(?:[^\!\*:]*:)(?:[^:]*:){3}(\d+):(?:[^:]*:){2}(?:[^:]*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_test_pass_warn_age:obj:1" version="1">
          <ind:filepath>/etc/login.defs</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?i)(PASS_WARN_AGE[\s]+\d+)[\s]*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-variable_object_test_pass_warn_age:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_variable_test_pass_warn_age:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-object_test_accounts_set_post_pw_existing:obj:1" version="1">
          <ind:filepath>/etc/shadow</ind:filepath>
          <ind:pattern operation="pattern match">^(?:[^:]*:)(?:[^\!\*:]*:)(?:[^:]*:){4}(\d+):(?:[^:]*:)(?:[^:]*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_set_post_pw_existing_no_pass:obj:1" version="1">
          <ind:filepath>/etc/shadow</ind:filepath>
          <ind:pattern operation="pattern match">^(?:[^:]*:)(?:[^\!\*:]*:)(?:[^:]*:){4}(\d+):(?:[^:]*:)(?:[^:]*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:password_object id="oval:ssg-object_accounts_password_all_shadowed:obj:1" version="1">
          <unix:username operation="pattern match">.*</unix:username>
        </unix:password_object>
        <unix:shadow_object id="oval:ssg-object_accounts_password_all_shadowed_sha512:obj:1" version="1">
          <unix:username operation="pattern match">.*</unix:username>
          <oval-def:filter action="exclude">oval:ssg-state_accounts_password_all_shadowed_has_no_password:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_accounts_password_all_shadowed_has_locked_password:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_accounts_password_all_shadowed_sha512:ste:1</oval-def:filter>
        </unix:shadow_object>
        <unix:shadow_object id="oval:ssg-object_accounts_password_last_change_is_in_past:obj:1" version="1">
          <unix:username operation="pattern match">.*</unix:username>
          <oval-def:filter action="exclude">oval:ssg-state_accounts_password_all_chage_past_has_no_password:ste:1</oval-def:filter>
        </unix:shadow_object>
        <ind:variable_object id="oval:ssg-object_accounts_password_last_change_is_in_past_time_diff:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_accounts_password_last_change_is_in_past_time_diff:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-object_pam_unix_no_remember:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/(system|password)-auth$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*password\s+(?:(?:sufficient)|(?:required)|(?:\[.*\]))\s+pam_unix\.so[^#]+\bremember=\d+\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_password_auth_pam_unix_rounds:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/password-auth$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*password\s+(?:(?:sufficient)|(?:required))\s+pam_unix\.so[^#]*rounds=([0-9]*).*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_system_auth_pam_unix_rounds:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/system-auth$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*password\s+(?:(?:sufficient)|(?:required))\s+pam_unix\.so.*rounds=([0-9]*).*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_gid_passwd_group_same_var:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^[^:]+:[^:]+:([0-9]+):</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_gid_passwd_group_same:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^[^:]+:[^:]+:[0-9]+:([0-9]+):</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_no_empty_passwords:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/pam.d/(system|password)-auth$</ind:filepath>
          <ind:pattern operation="pattern match">^[^#]*\bnullok\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_no_empty_passwords_etc_shadow:obj:1" version="1">
          <ind:filepath>/etc/shadow</ind:filepath>
          <ind:pattern operation="pattern match">^[^:]+::.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:password_object id="oval:ssg-object_no_forward_files_objects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_no_forward_files_objects_others:obj:1</oval-def:object_reference>
          </oval-def:set>
        </unix:password_object>
        <unix:password_object id="oval:ssg-object_no_forward_files_objects_others:obj:1" version="1">
          <unix:username datatype="string" operation="pattern match">.*</unix:username>
          <oval-def:filter action="include">oval:ssg-state_no_forward_files_users_uids:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_no_forward_files_users_ignored:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_no_forward_files_users_nologin_shell:ste:1</oval-def:filter>
        </unix:password_object>
        <unix:file_object id="oval:ssg-object_accounts_users_home_forward_file_existance:obj:1" version="1">
          <unix:path var_check="at least one" var_ref="oval:ssg-var_accounts_users_home_forward_file_existance_dirs:var:1"/>
          <unix:filename operation="pattern match">\.forward$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object comment="lines starting with +" id="oval:ssg-object_no_legacy_plus_entries_etc_group:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^\+.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="lines starting with +" id="oval:ssg-object_no_legacy_plus_entries_etc_passwd:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^\+.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="lines starting with +" id="oval:ssg-object_no_legacy_plus_entries_etc_shadow:obj:1" version="1">
          <ind:filepath>/etc/shadow</ind:filepath>
          <ind:pattern operation="pattern match">^\+.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="look for .netrc in /home" id="oval:ssg-object_no_netrc_files_home:obj:1" version="1">
          <unix:behaviors max_depth="1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/home</unix:path>
          <unix:filename operation="pattern match">^\.netrc$</unix:filename>
        </unix:file_object>
        <unix:file_object comment="look for .rhost in /home" id="oval:ssg-object_no_rhost_files:obj:1" version="1">
          <unix:behaviors max_depth="1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/home</unix:path>
          <unix:filename operation="pattern match">^\.rhost$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_no_uid_except_root:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^(?!root:)([^:]+):[^:]+:0:.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_shadow_locked_users:obj:1" version="1">
          <ind:filepath>/etc/shadow</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]+):[!*][^:]*:.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_root_gid_zero:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^root:.+:\d+:(\d+).+</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="locate the line referring the group used in pam_wheel.so module" id="oval:ssg-object_ensure_pam_wheel_group_exists:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_ensure_pam_wheel_group_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_root_password_etc_shadow:obj:1" version="1">
          <ind:filepath>/etc/shadow</ind:filepath>
          <ind:pattern operation="pattern match">^root:\$(y|[0-9].+)\$.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_groups_no_zero_gid_except_root:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^(?!root:)[^:]*:[^:]*:0</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="/etc/securetty file exists" id="oval:ssg-object_etc_securetty_exists:obj:1" version="1">
          <ind:filepath>/etc/securetty</ind:filepath>
          <ind:pattern operation="pattern match">^.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="no entries /etc/securetty" id="oval:ssg-object_no_direct_root_logins:obj:1" version="1">
          <ind:filepath>/etc/securetty</ind:filepath>
          <ind:pattern operation="pattern match">^$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_no_invalid_shell_accounts_unlocked_valid_shells:obj:1" version="1">
          <ind:filepath>/etc/shells</ind:filepath>
          <ind:pattern operation="pattern match">^\/[^\n\r]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-filter_no_invalid_shell_accounts_unlocked_not_valid_shell:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_no_invalid_shell_accounts_unlocked_shells:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_no_invalid_shell_accounts_unlocked_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_no_invalid_shell_accounts_unlocked_local_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):[^:]*:\d+:(?:[^:]*:){3}(?!(\/usr)?(\/sbin\/nologin|\/bin\/false))[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_no_invalid_shell_accounts_unlocked_users_ignored:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_no_invalid_shell_accounts_unlocked_locked_accounts:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_no_invalid_shell_accounts_unlocked_locked_accounts:obj:1" version="1">
          <ind:filepath>/etc/shadow</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):(?:[ \t\n\r\:\;\*\!\\]*):(?:[^:]*:){6}$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:password_object id="oval:ssg-object_no_password_auth_for_systemaccounts_objects:obj:1" version="1">
          <unix:username datatype="string" operation="pattern match">.*</unix:username>
          <oval-def:filter action="include">oval:ssg-state_no_password_auth_for_systemaccounts_users_uids:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_no_password_auth_for_systemaccounts_users_ignored:ste:1</oval-def:filter>
        </unix:password_object>
        <unix:shadow_object id="oval:ssg-object_no_password_auth_for_systemaccounts:obj:1" version="1">
          <unix:username var_check="at least one" var_ref="oval:ssg-var_no_password_auth_for_systemaccounts_usernames:var:1"/>
          <oval-def:filter action="exclude">oval:ssg-filter_no_password_auth_for_systemaccounts_no_passwords_or_locked_accounts:ste:1</oval-def:filter>
        </unix:shadow_object>
        <ind:textfilecontent54_object id="oval:ssg-object_last_uid_min_from_etc_login_defs:obj:1" version="1">
          <ind:behaviors singleline="true"/>
          <ind:filepath>/etc/login.defs</ind:filepath>
          <ind:pattern operation="pattern match">.*(?:^|\n)\s*(UID_MIN[\s]+[\d]+)\s*(?:$|\n)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_last_sys_uid_min_from_etc_login_defs:obj:1" version="1">
          <ind:behaviors singleline="true"/>
          <ind:filepath>/etc/login.defs</ind:filepath>
          <ind:pattern operation="pattern match">.*(?:^|\n)\s*(SYS_UID_MIN[\s]+[\d]+)\s*(?:$|\n)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_last_sys_uid_max_from_etc_login_defs:obj:1" version="1">
          <ind:behaviors singleline="true"/>
          <ind:filepath>/etc/login.defs</ind:filepath>
          <ind:pattern operation="pattern match">.*(?:^|\n)\s*(SYS_UID_MAX[\s]+[\d]+)\s*(?:$|\n)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_passwd_entries:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^(?!root).*:x:([\d]+):[\d]+:[^:]*:[^:]*:(?!\/usr\/sbin\/nologin|\/sbin\/nologin|\/bin\/sync|\/sbin\/shutdown|\/sbin\/halt).*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="serial ports /etc/securetty" id="oval:ssg-object_serial_ports_etc_securetty:obj:1" version="1">
          <ind:filepath>/etc/securetty</ind:filepath>
          <ind:pattern operation="pattern match">^ttyS[0-9]+$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="virtual consoles /etc/securetty" id="oval:ssg-object_virtual_consoles_etc_securetty:obj:1" version="1">
          <ind:filepath>/etc/securetty</ind:filepath>
          <ind:pattern operation="pattern match">^vc/[0-9]+$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_accounts_have_homedir_login_defs:obj:1" version="2">
          <ind:filepath>/etc/login.defs</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?i)CREATE_HOME(?-i)[\s]+yes[\s]*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="FAIL_DELAY value from /etc/login.defs" id="oval:ssg-object_accounts_logon_fail_delay:obj:1" version="1">
          <ind:filepath>/etc/login.defs</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?i)FAIL_DELAY(?-i)[\s]+([^#\s]*)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_security_limits_conf_maxlogins:obj:1" version="1">
          <ind:filepath>/etc/security/limits.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*\*[\s]+(?:(?:hard)|(?:-))[\s]+maxlogins[\s]+(\d+)\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_security_limitsd_conf_maxlogins:obj:1" version="1">
          <ind:path>/etc/security/limits.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*\*[\s]+(?:(?:hard)|(?:-))[\s]+maxlogins[\s]+(\d+)\s*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_security_limitsd_conf_maxlogins_exists:obj:1" version="1">
          <ind:path>/etc/security/limits.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*\*[\s]+(?:(?:hard)|(?:-))[\s]+maxlogins</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-obj_tmp_inst:obj:1" version="1">
          <unix:path>/tmp/tmp-inst</unix:path>
          <unix:filename xsi:nil="true"/>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_tmp_in_namespace_conf:obj:1" version="1">
          <ind:filepath>/etc/security/namespace.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*/tmp\s+/tmp/tmp-inst/\s+level\s+root,adm$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-obj_var_tmp_tmp_inst:obj:1" version="1">
          <unix:path>/var/tmp/tmp-inst</unix:path>
          <unix:filename xsi:nil="true"/>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_var_tmp_in_namespace_conf:obj:1" version="1">
          <ind:filepath>/etc/security/namespace.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*/var/tmp\s+/var/tmp/tmp-inst/\s+level\s+root,adm$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_profile_tmout:obj:1" version="3">
          <ind:filepath>/etc/profile</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?:typeset|declare)[\s]+-xr[\s]+TMOUT=([\w$]+).*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_profiled_tmout:obj:1" version="3">
          <ind:path>/etc/profile.d</ind:path>
          <ind:filename operation="pattern match">^.*\.sh$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*(?:typeset|declare)[\s]+-xr[\s]+TMOUT=([\w$]+).*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_tmout_all_tmout_instances:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_etc_profile_tmout:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_etc_profiled_tmout:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_accounts_tmout_defined:obj:1" version="1">
          <ind:var_ref>oval:ssg-variable_count_of_tmout_instances:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_user_dot_group_ownership_home_dirs:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_object_accounts_user_dot_group_ownership_home_dirs_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_user_dot_group_ownership_home_dirs_local_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):[^:]*:\d{4,}:(?:[^:]*:){3}(?!(\/usr)?(\/sbin\/nologin|\/bin\/false))[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_object_accounts_user_dot_group_ownership_home_dirs_users_ignored:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_user_dot_group_ownership_gids:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_object_accounts_user_dot_group_ownership_gids_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_user_dot_group_ownership_gids_local_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):[^:]*:\d{4,}:(?:[^:]*:){3}(?!(\/usr)?(\/sbin\/nologin|\/bin\/false))[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_object_accounts_user_dot_group_ownership_gids_users_ignored:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-object_accounts_user_dot_group_ownership_init_files:obj:1" version="1">
          <unix:behaviors max_depth="1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path var_check="at least one" var_ref="oval:ssg-var_accounts_user_dot_group_ownership_dirs:var:1"/>
          <unix:filename operation="pattern match">^\..*</unix:filename>
        </unix:file_object>
        <unix:password_object id="oval:ssg-object_accounts_user_dot_no_world_writable_programs_objects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_accounts_user_dot_no_world_writable_programs_objects_others:obj:1</oval-def:object_reference>
          </oval-def:set>
        </unix:password_object>
        <unix:password_object id="oval:ssg-object_accounts_user_dot_no_world_writable_programs_objects_others:obj:1" version="1">
          <unix:username datatype="string" operation="pattern match">.*</unix:username>
          <oval-def:filter action="include">oval:ssg-state_accounts_user_dot_no_world_writable_programs_users_uids:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_accounts_user_dot_no_world_writable_programs_users_ignored:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_accounts_user_dot_no_world_writable_programs_users_nologin_shell:ste:1</oval-def:filter>
        </unix:password_object>
        <unix:file_object id="oval:ssg-object_world_writable_programs:obj:1" version="2">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="defined"/>
          <unix:path>/</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="include">oval:ssg-state_world_writable_programs:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_user_dot_no_world_writable_programs_init_files:obj:1" version="3">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_accounts_user_dot_no_world_writable_programs_dirs:var:1"/>
          <ind:filename operation="pattern match" var_ref="oval:ssg-var_user_initialization_files_regex:var:1"/>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-var_world_writable_programs_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_user_dot_user_ownership_home_dirs:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_object_accounts_user_dot_user_ownership_home_dirs_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_user_dot_user_ownership_home_dirs_local_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):[^:]*:\d{4,}:(?:[^:]*:){3}(?!(\/usr)?(\/sbin\/nologin|\/bin\/false))[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_object_accounts_user_dot_user_ownership_home_dirs_users_ignored:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_user_dot_user_ownership_uids:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_object_accounts_user_dot_user_ownership_uids_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_user_dot_user_ownership_uids_local_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):[^:]*:\d{4,}:(?:[^:]*:){3}(?!(\/usr)?(\/sbin\/nologin|\/bin\/false))[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_object_accounts_user_dot_user_ownership_uids_users_ignored:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-object_accounts_user_dot_user_ownership_init_files:obj:1" version="1">
          <unix:behaviors max_depth="1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path var_check="at least one" var_ref="oval:ssg-var_accounts_user_dot_user_ownership_dirs:var:1"/>
          <unix:filename operation="pattern match">^\..*</unix:filename>
        </unix:file_object>
        <unix:password_object id="oval:ssg-object_accounts_user_interactive_home_directory_defined_objects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_accounts_user_interactive_home_directory_defined_objects_others:obj:1</oval-def:object_reference>
          </oval-def:set>
        </unix:password_object>
        <unix:password_object id="oval:ssg-object_accounts_user_interactive_home_directory_defined_objects_others:obj:1" version="1">
          <unix:username datatype="string" operation="pattern match">.*</unix:username>
          <oval-def:filter action="include">oval:ssg-state_accounts_user_interactive_home_directory_defined_users_uids:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_accounts_user_interactive_home_directory_defined_users_ignored:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_accounts_user_interactive_home_directory_defined_users_nologin_shell:ste:1</oval-def:filter>
        </unix:password_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_user_interactive_home_directory_exists_objects:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_object_accounts_user_interactive_home_directory_exists_objects_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_user_interactive_home_directory_exists_objects_local_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):[^:]*:\d{4,}:(?:[^:]*:){3}(?!(\/usr)?(\/sbin\/nologin|\/bin\/false))[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_object_accounts_user_interactive_home_directory_exists_objects_users_ignored:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-object_accounts_user_interactive_home_directory_exists_dirs_fs:obj:1" version="1">
          <unix:path var_check="at least one" var_ref="oval:ssg-var_accounts_user_interactive_home_directory_exists_dirs_list:var:1"/>
          <unix:filename xsi:nil="true"/>
        </unix:file_object>
        <ind:variable_object id="oval:ssg-object_accounts_user_interactive_home_directory_exists_dirs_count_fs:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_accounts_user_interactive_home_directory_exists_dirs_count_fs:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:variable_object id="oval:ssg-object_accounts_user_interactive_home_directory_exists_dirs_count_pw:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_accounts_user_interactive_home_directory_exists_dirs_count:var:1</ind:var_ref>
        </ind:variable_object>
        <linux:partition_object id="oval:ssg-object_accounts_user_interactive_home_directory_on_separate_partition_non_root_partitions:obj:1" version="1">
          <linux:mount_point operation="not equal">/</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_user_interactive_home_directory_on_separate_partition_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^(?:(?!nobody|nfsnobody)[^:]*):(?:[^:]*:)[1-9]\d{3,}:(?:[^:]*:){2}([^:]+):(?!(?:/usr)?/sbin/nologin$)[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_users_home_files_groupownership_home_dirs:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_object_accounts_users_home_files_groupownership_home_dirs_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_users_home_files_groupownership_home_dirs_local_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):[^:]*:\d{4,}:(?:[^:]*:){3}(?!(\/usr)?(\/sbin\/nologin|\/bin\/false))[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_object_accounts_users_home_files_groupownership_home_dirs_users_ignored:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_users_home_files_groupownership_gids:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_object_accounts_users_home_files_groupownership_gids_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_users_home_files_groupownership_gids_local_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):[^:]*:\d{4,}:(?:[^:]*:){3}(?!(\/usr)?(\/sbin\/nologin|\/bin\/false))[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_object_accounts_users_home_files_groupownership_gids_users_ignored:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-object_accounts_users_home_files_groupownership_dirs:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path var_check="at least one" var_ref="oval:ssg-var_accounts_users_home_files_groupownership_dirs:var:1"/>
          <unix:filename operation="not equal">/</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_users_home_files_ownership_home_dirs:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_object_accounts_users_home_files_ownership_home_dirs_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_users_home_files_ownership_home_dirs_local_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):[^:]*:\d{4,}:(?:[^:]*:){3}(?!(\/usr)?(\/sbin\/nologin|\/bin\/false))[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_object_accounts_users_home_files_ownership_home_dirs_users_ignored:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_users_home_files_ownership_uids:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_object_accounts_users_home_files_ownership_uids_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_users_home_files_ownership_uids_local_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):[^:]*:\d{4,}:(?:[^:]*:){3}(?!(\/usr)?(\/sbin\/nologin|\/bin\/false))[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_object_accounts_users_home_files_ownership_uids_users_ignored:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-object_accounts_users_home_files_ownership_dirs:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path var_check="at least one" var_ref="oval:ssg-var_accounts_users_home_files_ownership_dirs:var:1"/>
          <unix:filename operation="not equal">/</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_users_home_files_permissions_home_dirs:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_object_accounts_users_home_files_permissions_home_dirs_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_users_home_files_permissions_home_dirs_local_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):[^:]*:\d{4,}:(?:[^:]*:){3}(?!(\/usr)?(\/sbin\/nologin|\/bin\/false))[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_object_accounts_users_home_files_permissions_home_dirs_users_ignored:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-object_accounts_users_home_files_permissions_dirs:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path var_check="at least one" var_ref="oval:ssg-var_accounts_users_home_files_permissions_dirs:var:1"/>
          <unix:filename xsi:nil="true"/>
        </unix:file_object>
        <unix:file_object id="oval:ssg-object_accounts_users_home_files_permissions_files:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path var_check="at least one" var_ref="oval:ssg-var_accounts_users_home_files_permissions_dirs:var:1"/>
          <unix:filename operation="pattern match">^[^\.].*</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-state_accounts_users_home_files_permissions_is_symlink:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:password_object id="oval:ssg-object_accounts_users_netrc_file_permissions_objects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_accounts_users_netrc_file_permissions_objects_others:obj:1</oval-def:object_reference>
          </oval-def:set>
        </unix:password_object>
        <unix:password_object id="oval:ssg-object_accounts_users_netrc_file_permissions_objects_others:obj:1" version="1">
          <unix:username datatype="string" operation="pattern match">.*</unix:username>
          <oval-def:filter action="include">oval:ssg-state_accounts_users_netrc_file_permissions_users_uids:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_accounts_users_netrc_file_permissions_users_ignored:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_accounts_users_netrc_file_permissions_users_nologin_shell:ste:1</oval-def:filter>
        </unix:password_object>
        <unix:file_object id="oval:ssg-object_accounts_users_home_netrc_file_permissions:obj:1" version="1">
          <unix:path var_check="at least one" var_ref="oval:ssg-var_accounts_users_home_netrc_file_permissions_dirs:var:1"/>
          <unix:filename operation="pattern match">\.netrc</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_file_groupownership_home_directories_home_dirs:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_object_file_groupownership_home_directories_home_dirs_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_file_groupownership_home_directories_home_dirs_local_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):[^:]*:\d{4,}:(?:[^:]*:){3}(?!(\/usr)?(\/sbin\/nologin|\/bin\/false))[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_object_file_groupownership_home_directories_home_dirs_users_ignored:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_file_groupownership_home_directories_gids:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_object_file_groupownership_home_directories_gids_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_file_groupownership_home_directories_gids_local_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):[^:]*:\d{4,}:(?:[^:]*:){3}(?!(\/usr)?(\/sbin\/nologin|\/bin\/false))[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_object_file_groupownership_home_directories_gids_users_ignored:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-object_file_groupownership_home_directories_dirs:obj:1" version="1">
          <unix:path var_check="at least one" var_ref="oval:ssg-var_file_groupownership_home_directories_dirs:var:1"/>
          <unix:filename xsi:nil="true"/>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_file_ownership_home_directories_home_dirs:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_object_file_ownership_home_directories_home_dirs_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_file_ownership_home_directories_home_dirs_local_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):[^:]*:\d{4,}:(?:[^:]*:){3}(?!(\/usr)?(\/sbin\/nologin|\/bin\/false))[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_object_file_ownership_home_directories_home_dirs_users_ignored:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_file_ownership_home_directories_uids:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_object_file_ownership_home_directories_uids_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_file_ownership_home_directories_uids_local_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):[^:]*:\d{4,}:(?:[^:]*:){3}(?!(\/usr)?(\/sbin\/nologin|\/bin\/false))[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_object_file_ownership_home_directories_uids_users_ignored:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-object_file_ownership_home_directories_dirs:obj:1" version="1">
          <unix:path var_check="at least one" var_ref="oval:ssg-var_file_ownership_home_directories_dirs:var:1"/>
          <unix:filename xsi:nil="true"/>
        </unix:file_object>
        <ind:variable_object id="oval:ssg-object_file_ownership_home_directories_uids_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_file_ownership_home_directories_uids_count:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object id="oval:ssg-object_file_permission_user_bash_history:obj:1" version="1">
          <unix:path var_check="at least one" var_ref="oval:ssg-var_file_permission_user_bash_history_home_dirs:var:1"/>
          <unix:filename operation="equals">.bash_history</unix:filename>
        </unix:file_object>
        <unix:password_object id="oval:ssg-object_file_permission_user_bash_history_objects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_permission_user_bash_history_objects_others:obj:1</oval-def:object_reference>
          </oval-def:set>
        </unix:password_object>
        <unix:password_object id="oval:ssg-object_file_permission_user_bash_history_objects_others:obj:1" version="1">
          <unix:username datatype="string" operation="pattern match">.*</unix:username>
          <oval-def:filter action="include">oval:ssg-state_file_permission_user_bash_history_users_uids:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permission_user_bash_history_users_ignored:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permission_user_bash_history_users_nologin_shell:ste:1</oval-def:filter>
        </unix:password_object>
        <unix:file_object id="oval:ssg-object_file_permission_user_init_files:obj:1" version="1">
          <unix:path var_check="at least one" var_ref="oval:ssg-var_file_permission_user_init_files_home_dirs:var:1"/>
          <unix:filename operation="pattern match" var_ref="oval:ssg-var_user_initialization_files_regex:var:1"/>
        </unix:file_object>
        <unix:password_object id="oval:ssg-object_file_permission_user_init_files_objects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_permission_user_init_files_objects_others:obj:1</oval-def:object_reference>
          </oval-def:set>
        </unix:password_object>
        <unix:password_object id="oval:ssg-object_file_permission_user_init_files_objects_others:obj:1" version="1">
          <unix:username datatype="string" operation="pattern match">.*</unix:username>
          <oval-def:filter action="include">oval:ssg-state_file_permission_user_init_files_users_uids:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permission_user_init_files_users_ignored:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permission_user_init_files_users_nologin_shell:ste:1</oval-def:filter>
        </unix:password_object>
        <unix:file_object id="oval:ssg-object_file_permission_user_init_files_root:obj:1" version="1">
          <unix:path var_check="at least one" var_ref="oval:ssg-var_file_permission_user_init_files_root_home_dirs:var:1"/>
          <unix:filename operation="pattern match" var_ref="oval:ssg-var_user_initialization_files_regex:var:1"/>
        </unix:file_object>
        <unix:password_object id="oval:ssg-object_file_permission_user_init_files_root_objects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_permission_user_init_files_root_objects_root:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_file_permission_user_init_files_root_objects_others:obj:1</oval-def:object_reference>
          </oval-def:set>
        </unix:password_object>
        <unix:password_object id="oval:ssg-object_file_permission_user_init_files_root_objects_root:obj:1" version="1">
          <unix:username datatype="string" operation="equals">root</unix:username>
        </unix:password_object>
        <unix:password_object id="oval:ssg-object_file_permission_user_init_files_root_objects_others:obj:1" version="1">
          <unix:username datatype="string" operation="pattern match">.*</unix:username>
          <oval-def:filter action="include">oval:ssg-state_file_permission_user_init_files_root_users_uids:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permission_user_init_files_root_users_ignored:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permission_user_init_files_root_users_nologin_shell:ste:1</oval-def:filter>
        </unix:password_object>
        <ind:textfilecontent54_object id="oval:ssg-object_file_permissions_home_directories_objects:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_object_file_permissions_home_directories_objects_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_file_permissions_home_directories_objects_local_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):[^:]*:\d{4,}:(?:[^:]*:){3}(?!(\/usr)?(\/sbin\/nologin|\/bin\/false))[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_object_file_permissions_home_directories_objects_users_ignored:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-object_file_permissions_home_directories_dirs:obj:1" version="1">
          <unix:path var_check="at least one" var_ref="oval:ssg-var_file_permissions_home_directories_dirs:var:1"/>
          <unix:filename xsi:nil="true"/>
        </unix:file_object>
        <unix:password_object id="oval:ssg-object_file_permissions_home_dirs_objects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_permissions_home_dirs_objects_others:obj:1</oval-def:object_reference>
          </oval-def:set>
        </unix:password_object>
        <unix:password_object id="oval:ssg-object_file_permissions_home_dirs_objects_others:obj:1" version="1">
          <unix:username datatype="string" operation="pattern match">.*</unix:username>
          <oval-def:filter action="include">oval:ssg-state_file_permissions_home_dirs_users_uids:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_home_dirs_users_ignored:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_home_dirs_users_nologin_shell:ste:1</oval-def:filter>
        </unix:password_object>
        <unix:file_object id="oval:ssg-object_file_permissions_home_dirs_dirs:obj:1" version="1">
          <unix:path var_check="at least one" var_ref="oval:ssg-var_file_permissions_home_dirs_dirs:var:1"/>
          <unix:filename xsi:nil="true"/>
        </unix:file_object>
        <ind:environmentvariable58_object id="oval:ssg-object_accounts_root_path_dirs_no_write_pathenv:obj:1" version="1">
          <ind:pid datatype="int" xsi:nil="true"/>
          <ind:name>PATH</ind:name>
        </ind:environmentvariable58_object>
        <unix:file_object comment="root's path directories with wrong group / other write permissions" id="oval:ssg-object_accounts_root_path_dirs_no_group_other_write:obj:1" version="1">
          <unix:path var_check="at least one" var_ref="oval:ssg-var_accounts_root_path_dirs_no_write:var:1"/>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_accounts_root_path_dirs_wrong_perms:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_accounts_root_path_dirs_symlink:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:environmentvariable58_object id="oval:ssg-object_root_path_no_dot:obj:1" version="1">
          <ind:pid datatype="int" xsi:nil="true"/>
          <ind:name>PATH</ind:name>
        </ind:environmentvariable58_object>
        <ind:textfilecontent54_object comment="Umask value from /etc/bashrc" id="oval:ssg-obj_umask_from_etc_bashrc:obj:1" version="1">
          <ind:filepath>/etc/bashrc</ind:filepath>
          <ind:pattern operation="pattern match">^[^#]*\bumask\s+(\d{3})\s*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-obj_accounts_umask_etc_bashrc:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_etc_bashrc_umask_as_number:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object comment="Umask value from /etc/csh.cshrc" id="oval:ssg-obj_umask_from_etc_csh_cshrc:obj:1" version="1">
          <ind:filepath>/etc/csh.cshrc</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?i)UMASK(?-i)[\s]+([^#\s]*)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-obj_accounts_umask_etc_csh_cshrc:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_etc_csh_cshrc_umask_as_number:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object comment="Umask value from /etc/login.defs" id="oval:ssg-obj_umask_from_etc_login_defs:obj:1" version="1">
          <ind:filepath>/etc/login.defs</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*UMASK[\s]+([^#\s]*)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-obj_accounts_umask_etc_login_defs:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_etc_login_defs_umask_as_number:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object comment="umask value retrieved from profile configuration files" id="oval:ssg-obj_umask_from_etc_profile:obj:1" version="1">
          <ind:filepath operation="pattern match">^\/etc\/profile(?:\.d\/.*\.sh|\.d\/sh\.local)?$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*umask[\s]+([^#\s]*)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-obj_accounts_umask_etc_profile:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_etc_profile_umask_as_number:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_umask_interactive_users_objects:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_object_accounts_umask_interactive_users_objects_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_accounts_umask_interactive_users_objects_local_interactive_users:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^([^:]*):[^:]*:\d{4,}:(?:[^:]*:){3}(?!(\/usr)?(\/sbin\/nologin|\/bin\/false))[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_object_accounts_umask_interactive_users_objects_users_ignored:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Umask value from initialization files" id="oval:ssg-object_accounts_umask_interactive_users:obj:1" version="1">
          <ind:behaviors max_depth="0" recurse_direction="down"/>
          <ind:path var_check="at least one" var_ref="oval:ssg-var_accounts_umask_interactive_users_dirs:var:1"/>
          <ind:filename operation="pattern match">^\..*</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*umask\s*</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_accounts_umask_interactive_users_bash_history:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Umask value from /root/.bashrc and /root/.profile" id="oval:ssg-obj_accounts_umask_root:obj:1" version="1">
          <ind:filepath operation="pattern match">^(/root/.bashrc|/root/.profile)$</ind:filepath>
          <ind:pattern operation="pattern match">^[^#]*\bumask\s+[0-7]?[0-7]([0-1][0-7]|[0-7][0-6])\s*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:uname_object comment="determine version and build of currently running kernel" id="oval:ssg-trust_cpu_rng_uname:obj:1" version="1"/>
        <ind:textfilecontent54_object id="oval:ssg-object_trust_cpu_rng_compiled_in:obj:1" version="1">
          <ind:filepath operation="equals" var_ref="oval:ssg-var_kernel_config_file:var:1"/>
          <ind:pattern operation="pattern match">^CONFIG_RANDOM_TRUST_CPU=(y|Y)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_trust_cpu_rng_boot_param:obj:1" version="1">
          <ind:filepath>/boot/grub2/grubenv</ind:filepath>
          <ind:pattern operation="pattern match">^kernelopts=(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:password_object id="oval:ssg-object_user_accounts:obj:1" version="1">
          <unix:username datatype="string" operation="pattern match">.*</unix:username>
        </unix:password_object>
        <ind:textfilecontent54_object id="oval:ssg-object_bootloader_unique_superuser:obj:1" version="1">
          <ind:filepath>/boot/grub2/grub.cfg</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*set[\s]+superusers="(?i)\b(?!(?:root|admin|administrator)\b)(\w+)".*\n[\s]*export[\s]+superusers[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_grub2_no_removeable_media:obj:1" version="1">
          <ind:filepath>/boot/grub2/grub.cfg</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*set root=(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_grub2_menuentry:obj:1" version="1">
          <ind:filepath>/boot/grub2/grub.cfg</ind:filepath>
          <ind:pattern operation="pattern match">^menuentry</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-obj_grub2_menuentry_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_grub2_menuentry_count:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object id="oval:ssg-object_grub2_no_removeable_media_file_boot_grub2_grub_cfg_absent:obj:1" version="1">
          <unix:filepath operation="pattern match">^/boot/grub2/grub.cfg</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_password_usercfg:obj:1" version="1">
          <ind:filepath>/boot/grub2/user.cfg</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*GRUB2_PASSWORD=grub\.pbkdf2\.sha512.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:password_object id="oval:ssg-object_uefi_user_accounts:obj:1" version="1">
          <unix:username datatype="string" operation="pattern match">.*</unix:username>
        </unix:password_object>
        <ind:textfilecontent54_object id="oval:ssg-object_bootloader_uefi_unique_superuser:obj:1" version="1">
          <ind:filepath>/boot/efi/EFI/almalinux/grub.cfg</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*set[\s]+superusers="(?i)\b(?!(?:root|admin|administrator)\b)(\w+)".*\n[\s]*export[\s]+superusers[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_uefi_admin_username_stub:obj:1" version="1">
          <ind:filepath>/boot/efi/EFI/almalinux/grub.cfg</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*configfile\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_bootloader_uefi_boot_unique_superuser:obj:1" version="1">
          <ind:filepath>/boot/grub2/grub.cfg</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*set[\s]+superusers="(?i)\b(?!(?:root|admin|administrator)\b)(\w+)".*\n[\s]*export[\s]+superusers[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_uefi_password_usercfg:obj:1" version="1">
          <ind:filepath>/boot/efi/EFI/almalinux/user.cfg</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*GRUB2_PASSWORD=grub\.pbkdf2\.sha512.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_uefi_password_stub:obj:1" version="1">
          <ind:filepath>/boot/efi/EFI/almalinux/grub.cfg</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*configfile\b.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_uefi_password_boot_usercfg:obj:1" version="1">
          <ind:filepath>/boot/grub2/user.cfg</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*GRUB2_PASSWORD=grub\.pbkdf2\.sha512.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_uefi_no_removeable_media:obj:1" version="1">
          <ind:filepath>/boot/efi/EFI/almalinux/grub.cfg</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*set root=(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_uefi_menuentry:obj:1" version="1">
          <ind:filepath>/boot/efi/EFI/almalinux/grub.cfg</ind:filepath>
          <ind:pattern operation="pattern match">^menuentry</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-obj_uefi_menuentry_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_uefi_menuentry_count:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object id="oval:ssg-object_uefi_no_removeable_media_file_boot_efi_EFI_almalinux_grub_cfg_absent:obj:1" version="1">
          <unix:filepath operation="pattern match">^/boot/efi/EFI/almalinux/grub.cfg</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_zipl_bls_entries_only:obj:1" version="1">
          <ind:filepath operation="equals">/etc/zipl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*image\s*=.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="current bootmap state" id="oval:ssg-object_zipl_boot_bootmap_file:obj:1" version="1">
          <unix:filepath>/boot/bootmap</unix:filepath>
        </unix:file_object>
        <unix:file_object comment="/etc/zipl.conf state" id="oval:ssg-zipl_conf_file:obj:1" version="1">
          <unix:filepath datatype="string">/etc/zipl.conf</unix:filepath>
        </unix:file_object>
        <unix:file_object comment="/boot/loader/entries/*.conf states" id="oval:ssg-boot_entry_files:obj:1" version="1">
          <unix:filepath datatype="string" operation="pattern match">^/boot/loader/entries/.*\.conf$</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_zipl_systemd_debug-shell_argument_in_boot_loader_entries_conf:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/loader/entries/.*\.conf</ind:filepath>
          <ind:pattern operation="pattern match">^options (.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_zipl_systemd_debug-shell_argument_in_etc_kernel_cmdline:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/kernel/cmdline</ind:filepath>
          <ind:pattern operation="pattern match">^(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_default_mmap_min_addr:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_DEFAULT_MMAP_MIN_ADDR="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_default_mmap_min_addr_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_kernel_config_default_mmap_min_addr_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_default_mmap_min_addr_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_proc_sys_kernel_osrelease_arch_aarch64:obj:1" version="1">
          <ind:filepath>/proc/sys/kernel/osrelease</ind:filepath>
          <ind:pattern operation="pattern match">^.*\.(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_proc_sys_kernel_osrelease_arch_x86_64:obj:1" version="1">
          <ind:filepath>/proc/sys/kernel/osrelease</ind:filepath>
          <ind:pattern operation="pattern match">^.*\.(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_filecreatemode:obj:1" version="1">
          <ind:filepath operation="pattern match">^\/etc\/rsyslog(\.conf|\.d\/.*\.conf)$</ind:filepath>
          <ind:pattern operation="pattern match">^\$FileCreateMode\s+(\d+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-obj_filecreatemode_dec:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_filecreatemode_dec:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-object_logwatch_configured_hostlimit:obj:1" version="1">
          <ind:filepath>/etc/logwatch/conf/logwatch.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]HostLimit[\s]*=[\s]*no[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_logwatch_configured_splithosts:obj:1" version="1">
          <ind:filepath>/etc/logwatch/conf/logwatch.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]SplitHosts[\s]*=[\s]*yes[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_cron_logging_rsyslog:obj:1" version="1">
          <ind:filepath>/etc/rsyslog.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*cron\.\*[\s]+/var/log/cron\s*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_cron_logging_rsyslog_rainer:obj:1" version="1">
          <ind:filepath>/etc/rsyslog.conf</ind:filepath>
          <ind:pattern operation="pattern match">(?ms)^\s*cron\.\*\s+action\(\s*.*(?i)\btype\b(?-i)="omfile"\s*.*(?i)\bfile\b(?-i)="/var/log/cron"\s*.*\)\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_cron_logging_rsyslog_dir:obj:1" version="1">
          <ind:path>/etc/rsyslog.d</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*cron\.\*[\s]+/var/log/cron\s*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_cron_logging_rsyslog_dir_rainer:obj:1" version="1">
          <ind:path>/etc/rsyslog.d</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">(?ms)^\s*cron\.\*\s+action\(\s*.*(?i)\btype\b(?-i)="omfile"\s*.*(?i)\bfile\b(?-i)="/var/log/cron"\s*.*\)\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check if  $ActionSendStreamDriverAuthMode x509/name is set in /etc/rsyslog.conf" id="oval:ssg-obj_rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action_send_stream_driver_auth_mode:obj:1" version="1">
          <ind:filepath>/etc/rsyslog.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\$ActionSendStreamDriverAuthMode\s+x509/name\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check if StreamDriverAuthMode is set to x509/name in /etc/rsyslog.conf using RainerScript" id="oval:ssg-obj_rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action_send_stream_driver_auth_mode_rainer:obj:1" version="1">
          <ind:filepath>/etc/rsyslog.conf</ind:filepath>
          <ind:pattern operation="pattern match">(?ms)^\s*action\(.*(?i)\btype\b(?-i)="omfwd".*(?i)\bStreamDriverAuthMode\b(?-i)="x509/name".*\)\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check if $ActionSendStreamDriverAuthMode x509/name is set in /etc/rsyslog.d" id="oval:ssg-obj_rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action_send_stream_driver_auth_mode_dir:obj:1" version="1">
          <ind:path>/etc/rsyslog.d</ind:path>
          <ind:filename operation="pattern match">^.*conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*\$ActionSendStreamDriverAuthMode\s+x509/name\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check if StreamDriverAuthMode is set to x509/name in files in /etc/rsyslog.d using RainerScript" id="oval:ssg-obj_rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action_send_stream_driver_auth_mode_dir_rainer:obj:1" version="1">
          <ind:path>/etc/rsyslog.d</ind:path>
          <ind:filename operation="pattern match">^.*conf$</ind:filename>
          <ind:pattern operation="pattern match">(?ms)^\s*action\(.*(?i)\btype\b(?-i)="omfwd".*(?i)\bStreamDriverAuthMode\b(?-i)="x509/name".*\)\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check if  $ActionSendStreamDriverMode 1 is set in /etc/rsyslog.conf" id="oval:ssg-obj_rsyslog_encrypt_offload_actionsendstreamdrivermode_action_send_stream_driver_mode_rsyslog:obj:1" version="1">
          <ind:filepath>/etc/rsyslog.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\$ActionSendStreamDriverMode\s+1\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check if StreamDriverMode is set to 1 in /etc/rsyslog.conf using RainerScript" id="oval:ssg-obj_rsyslog_encrypt_offload_actionsendstreamdrivermode_action_send_stream_driver_mode_rsyslog_rainer:obj:1" version="1">
          <ind:filepath>/etc/rsyslog.conf</ind:filepath>
          <ind:pattern operation="pattern match">(?ms)^\s*action\(.*(?i)\btype\b(?-i)="omfwd".*(?i)\bStreamDriverMode\b(?-i)="1".*\)\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check if $ActionSendStreamDriverMode 1 is set in /etc/rsyslog.d" id="oval:ssg-obj_rsyslog_encrypt_offload_actionsendstreamdrivermode_action_send_stream_driver_mode_rsyslog_dir:obj:1" version="1">
          <ind:path>/etc/rsyslog.d</ind:path>
          <ind:filename operation="pattern match">^.*conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*\$ActionSendStreamDriverMode\s+1\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check if StreamDriverMode is set to 1 in files in /etc/rsyslog.d using RainerScript" id="oval:ssg-obj_rsyslog_encrypt_offload_actionsendstreamdrivermode_action_send_stream_driver_mode_rsyslog_dir_rainer:obj:1" version="1">
          <ind:path>/etc/rsyslog.d</ind:path>
          <ind:filename operation="pattern match">^.*conf$</ind:filename>
          <ind:pattern operation="pattern match">(?ms)^\s*action\(.*(?i)\btype\b(?-i)="omfwd".*(?i)\bStreamDriverMode\b(?-i)="1".*\)\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check if  $DefaultNetstreamDriver gtls is set in /etc/rsyslog.conf" id="oval:ssg-obj_rsyslog_encrypt_offload_defaultnetstreamdriver_default_netstream_rsyslog:obj:1" version="1">
          <ind:filepath>/etc/rsyslog.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\$DefaultNetstreamDriver\s+gtls\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check if DefaultNetstreamDriver is set to gtls in /etc/rsyslog.conf using RainerScript" id="oval:ssg-obj_rsyslog_encrypt_offload_defaultnetstreamdriver_default_netstream_rsyslog_rainer:obj:1" version="1">
          <ind:filepath>/etc/rsyslog.conf</ind:filepath>
          <ind:pattern operation="pattern match">(?ms)^\s*global\(.*(?i)\bDefaultNetStreamDriver\b(?-i)="gtls".*\)\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check if $DefaultNetstreamDriver gtls is set in /etc/rsyslog.d" id="oval:ssg-obj_rsyslog_encrypt_offload_defaultnetstreamdriver_default_netstream_rsyslog_dir:obj:1" version="1">
          <ind:path>/etc/rsyslog.d</ind:path>
          <ind:filename operation="pattern match">^.*conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*\$DefaultNetstreamDriver\s+gtls\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check if DefaultNetstreamDriver is set to gtls in files in /etc/rsyslog.d using RainerScript" id="oval:ssg-obj_rsyslog_encrypt_offload_defaultnetstreamdriver_default_netstream_rsyslog_dir_rainer:obj:1" version="1">
          <ind:path>/etc/rsyslog.d</ind:path>
          <ind:filename operation="pattern match">^.*conf$</ind:filename>
          <ind:pattern operation="pattern match">(?ms)^\s*global\(.*(?i)\bDefaultNetStreamDriver\b(?-i)="gtls".*\)\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_logging_configured_rsyslog_conf:obj:1" version="1">
          <ind:filepath>/etc/rsyslog.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[^(\s|#|\$)]+[\s]+.*[\s]+(\:\w+\:\S*|-?(\/+[^:;\s]+);*\.*)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_logging_configured_rsyslog_d:obj:1" version="1">
          <ind:path>/etc/rsyslog.d</ind:path>
          <ind:filename operation="pattern match">^.+\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[^(\s|#|\$)]+[\s]+.*[\s]+(\:\w+\:\S*|-?(\/+[^:;\s]+);*\.*)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_remote_method_monitoring_auth:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/rsyslog\.(conf|d/.+\.conf)$</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?:(?:\w+,)*auth(?:,\w+)*\.\*|\S+;auth\.\*|auth\.\*;\S+|\S+;auth\.\*;\S+)[ \t]+(?:(?!(?i)action(?-i)\()\S+|(?i)action(?-i)\([^)]*(?i)file(?-i)\s*=\s*["'][^"']+["'][^)]*\))\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_remote_method_monitoring_authpriv:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/rsyslog\.(conf|d/.+\.conf)$</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?:(?:\w+,)*authpriv(?:,\w+)*\.\*|\S+;authpriv\.\*|authpriv\.\*;\S+|\S+;authpriv\.\*;\S+)[ \t]+(?:(?!(?i)action(?-i)\()\S+|(?i)action(?-i)\([^)]*(?i)file(?-i)\s*=\s*["'][^"']+["'][^)]*\))\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_remote_method_monitoring_daemon:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/rsyslog\.(conf|d/.+\.conf)$</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?:(?:\w+,)*daemon(?:,\w+)*\.\*|\S+;daemon\.\*|daemon\.\*;\S+|\S+;daemon\.\*;\S+)[ \t]+(?:(?!(?i)action(?-i)\()\S+|(?i)action(?-i)\([^)]*(?i)file(?-i)\s*=\s*["'][^"']+["'][^)]*\))\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_logrotate_conf_daily_setting:obj:1" version="2">
          <ind:filepath>/etc/logrotate.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*daily[\s#]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_logrotate_conf_no_other_keyword:obj:1" version="2">
          <ind:filepath>/etc/logrotate.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*(weekly|monthly|yearly)[\s#]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_cron_daily_logrotate_existence:obj:1" version="1">
          <ind:filepath>/etc/cron.daily/logrotate</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*/usr/sbin/logrotate[\s\S]*/etc/logrotate.conf$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_rsyslog_nolisten_legacy:obj:1" version="2">
          <ind:filepath operation="pattern match">^\/etc\/rsyslog(\.conf|\.d\/.*\.conf)$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*\$((?:Input(?:TCP|RELP)|UDP)ServerRun|ModLoad[\s]+(imtcp|imudp|imrelp))</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_rsyslog_nolisten_rainerscript:obj:1" version="3">
          <ind:filepath operation="pattern match">^\/etc\/rsyslog(\.conf|\.d\/.*\.conf)$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*(?:module|input)\((?:load|type)="(imtcp|imudp|imrelp)".*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_remote_loghost_rsyslog_conf:obj:1" version="1">
          <ind:filepath>/etc/rsyslog.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\*\.\*[\s]+(?:@|\:omrelp\:)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_remote_loghost_rsyslog_d:obj:1" version="1">
          <ind:path>/etc/rsyslog.d</ind:path>
          <ind:filename operation="pattern match">^.+\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\*\.\*[\s]+(?:@|\:omrelp\:)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_remote_loghost_rsyslog_conf_rainer:obj:1" version="1">
          <ind:filepath>/etc/rsyslog.conf</ind:filepath>
          <ind:pattern operation="pattern match">(?ms)^\s*\*\.\*\s+action\(\s*.*(?i)\btype\b(?-i)="omfwd"\s*.*(?i)\btarget\b(?-i)="\S+"\s*.*\)\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_remote_loghost_rsyslog_d_rainer:obj:1" version="1">
          <ind:path>/etc/rsyslog.d</ind:path>
          <ind:filename operation="pattern match">^.+\.conf$</ind:filename>
          <ind:pattern operation="pattern match">(?ms)^\s*\*\.\*\s+action\(\s*.*(?i)\btype\b(?-i)="omfwd"\s*.*(?i)\btarget\b(?-i)="\S+"\s*.*\)\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rsyslog_remote_tls:obj:1" version="1">
          <ind:behaviors singleline="true"/>
          <ind:filepath operation="pattern match">^/etc/rsyslog\.(conf|d/.+\.conf)$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*action\((?i)type(?-i)="omfwd"(.+?)\)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">0</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rsyslog_remote_tls_cacert:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/rsyslog\.(conf|d/.+\.conf)$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*global\(DefaultNetstreamDriverCAFile="(.+?)"\)\s*\n</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">0</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_network_configure_name_resolution:obj:1" version="1">
          <ind:filepath>/etc/resolv.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*nameserver[\s]+([0-9\.]+)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_network_disable_ddns_interfaces_ifcfg:obj:1" version="1">
          <ind:path>/etc/sysconfig/network-scripts</ind:path>
          <ind:filename operation="pattern match">ifcfg-.*</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*DHCP_HOSTNAME[\s]*=.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_network_disable_ddns_interfaces_dhclient:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/dhclient.*\.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*send[\s]+host-name.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_network_disable_ddns_interfaces_dhcp:obj:1" version="1">
          <ind:path>/etc/dhcp</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*send[\s]+host-name.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sysconfig_nozeroconf_yes:obj:1" version="1">
          <ind:filepath>/etc/sysconfig/network</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*NOZEROCONF[\s]*=[\s]*yes</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_network_nmcli_permissions:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/polkit-1/localauthority/20-org.d/.*$</ind:filepath>
          <ind:pattern operation="pattern match">^\[.*\]\n\s*Identity=default\n\s*Action=org\.freedesktop\.NetworkManager\.\*\n\s*ResultAny=no\n\s*ResultInactive=no\n\s*(ResultActive=auth_admin)\n*\s*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:interface_object id="oval:ssg-object_promisc_interfaces:obj:1" version="1">
          <unix:name operation="pattern match">^.*$</unix:name>
          <oval-def:filter action="include">oval:ssg-state_promisc:ste:1</oval-def:filter>
        </unix:interface_object>
        <ind:xmlfilecontent_object id="oval:ssg-object_firewalld_loopback_restricted_source_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/firewalld/zones/trusted.xml</ind:filepath>
          <ind:xpath>/zone/rule/source[@address='127.0.0.1' or @address='::1']</ind:xpath>
        </ind:xmlfilecontent_object>
        <ind:xmlfilecontent_object id="oval:ssg-object_firewalld_loopback_restricted_destination_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/firewalld/zones/trusted.xml</ind:filepath>
          <ind:xpath>/zone/rule/destination[@address='127.0.0.1' or @address='::1' and @invert='True']</ind:xpath>
        </ind:xmlfilecontent_object>
        <ind:xmlfilecontent_object id="oval:ssg-object_firewalld_loopback_restricted_policy_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/firewalld/zones/trusted.xml</ind:filepath>
          <ind:xpath>/zone/rule/drop</ind:xpath>
        </ind:xmlfilecontent_object>
        <ind:xmlfilecontent_object id="oval:ssg-object_firewalld_loopback_restricted_source_etc:obj:1" version="1">
          <ind:filepath>/etc/firewalld/zones/trusted.xml</ind:filepath>
          <ind:xpath>/zone/rule/source[@address='127.0.0.1' or @address='::1']</ind:xpath>
        </ind:xmlfilecontent_object>
        <ind:xmlfilecontent_object id="oval:ssg-object_firewalld_loopback_restricted_destination_etc:obj:1" version="1">
          <ind:filepath>/etc/firewalld/zones/trusted.xml</ind:filepath>
          <ind:xpath>/zone/rule/destination[@address='127.0.0.1' or @address='::1' and @invert='True']</ind:xpath>
        </ind:xmlfilecontent_object>
        <ind:xmlfilecontent_object id="oval:ssg-object_firewalld_loopback_restricted_policy_etc:obj:1" version="1">
          <ind:filepath>/etc/firewalld/zones/trusted.xml</ind:filepath>
          <ind:xpath>/zone/rule/drop</ind:xpath>
        </ind:xmlfilecontent_object>
        <ind:xmlfilecontent_object id="oval:ssg-object_firewalld_lo_interface_trusted_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/firewalld/zones/trusted.xml</ind:filepath>
          <ind:xpath>/zone/interface[@name='lo']</ind:xpath>
        </ind:xmlfilecontent_object>
        <ind:xmlfilecontent_object id="oval:ssg-object_firewalld_lo_interface_trusted_etc:obj:1" version="1">
          <ind:filepath>/etc/firewalld/zones/trusted.xml</ind:filepath>
          <ind:xpath>/zone/interface[@name='lo']</ind:xpath>
        </ind:xmlfilecontent_object>
        <unix:file_object id="oval:ssg-object_firewalld_customized_trusted_zone_file:obj:1" version="1">
          <unix:filepath>/etc/firewalld/zones/trusted.xml</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object comment="Define default gateways" id="oval:ssg-obj_network_ipv6_default_gateway:obj:1" version="1">
          <ind:path>/etc/sysconfig/network-scripts</ind:path>
          <ind:filename operation="pattern match">ifcfg-.*</ind:filename>
          <ind:pattern operation="pattern match">^IPV6_DEFAULTGW=.+$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Enable privacy extensions on each interface" id="oval:ssg-obj_network_ipv6_privacy_extensions:obj:1" version="1">
          <ind:path>/etc/sysconfig/network-scripts</ind:path>
          <ind:filename operation="pattern match">ifcfg-.*</ind:filename>
          <ind:pattern operation="pattern match">^IPV6_PRIVACY=rfc3041$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Set static IPv6 address on each interface" id="oval:ssg-obj_network_ipv6_static_address:obj:1" version="1">
          <ind:path>/etc/sysconfig/network-scripts</ind:path>
          <ind:filename operation="pattern match">ifcfg-.*</ind:filename>
          <ind:pattern operation="pattern match">^IPV6ADDR=.+$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="ipv6 disabled any modprobe conf file" id="oval:ssg-object_kernel_module_ipv6_option_disabled:obj:1" version="1">
          <ind:path>/etc/modprobe.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*options\s+ipv6\s+.*disable=1.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Test for udp6 based rpc services" id="oval:ssg-obj_network_ipv6_disable_rpc_udp6:obj:1" version="1">
          <ind:filepath>/etc/netconfig</ind:filepath>
          <ind:pattern operation="pattern match">^udp6\s+tpi_clts\s+v\s+inet6\s+udp\s+-\s+-$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Test for tcp6 based rpc services" id="oval:ssg-obj_network_ipv6_disable_rpc_tcp6:obj:1" version="1">
          <ind:filepath>/etc/netconfig</ind:filepath>
          <ind:pattern operation="pattern match">^tcp6\s+tpi_cots_ord\s+v\s+inet6\s+tcp\s+-\s+-$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:interface_object id="oval:ssg-object_active_wifi_interfaces:obj:1" version="1">
          <unix:name operation="pattern match">^wl.*$</unix:name>
        </unix:interface_object>
        <unix:file_object comment="collect all local directories and filter them by uid and others write permission" id="oval:ssg-all_local_directories_uid_zero:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path operation="equals">/</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_uid_is_not_root_and_world_writable:ste:1</oval-def:filter>
        </unix:file_object>
        <linux:partition_object id="oval:ssg-object_dir_perms_world_writable_sticky_bits_local_partitions:obj:1" version="1">
          <linux:mount_point operation="pattern match">.*</linux:mount_point>
          <oval-def:filter action="include">oval:ssg-state_dir_perms_world_writable_sticky_bits_dev_partitons:ste:1</oval-def:filter>
        </linux:partition_object>
        <unix:file_object comment="All world-writable directories without sticky bits" id="oval:ssg-object_dir_perms_world_writable_sticky_bits:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="defined"/>
          <unix:path operation="equals" var_check="at least one" var_ref="oval:ssg-var_dir_perms_world_writable_sticky_bits_local_mountpoints:var:1"/>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_dir_perms_world_writable_sticky_bits:ste:1</oval-def:filter>
        </unix:file_object>
        <linux:partition_object id="oval:ssg-object_dir_perms_world_writable_system_owned_local_partitions:obj:1" version="1">
          <linux:mount_point operation="pattern match">.*</linux:mount_point>
          <oval-def:filter action="include">oval:ssg-state_dir_perms_world_writable_system_owned_dev_partitons:ste:1</oval-def:filter>
        </linux:partition_object>
        <unix:file_object comment="All world-writable directories." id="oval:ssg-object_dir_perms_world_writable_system_owned:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="defined"/>
          <unix:path operation="equals" var_check="at least one" var_ref="oval:ssg-var_dir_perms_world_writable_system_owned_local_mountpoints:var:1"/>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_dir_perms_world_writable_system_owned:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="all local directories" id="oval:ssg-all_local_directories_gid:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path operation="equals">/</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_gid_is_user_and_world_writable:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="system commands directories" id="oval:ssg-object_system_commands_dirs_group_ownership:obj:1" version="1">
          <unix:path operation="pattern match">^\/s?bin|^\/usr\/s?bin|^\/usr\/local\/s?bin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_system_commands_dirs_group_owner_not_root:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="system commands directories have root ownership" id="oval:ssg-object_ownership_system_commands_directory_bin_ownership:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/bin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_system_commands_directory_bin_owner_not_root:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="system commands directories have root ownership" id="oval:ssg-object_ownership_system_commands_directory_sbin_ownership:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/sbin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_system_commands_directory_sbin_owner_not_root:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="system commands directories have root ownership" id="oval:ssg-object_ownership_system_commands_directory_usr_bin_ownership:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/usr/bin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_system_commands_directory_usr_bin_owner_not_root:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="system commands directories have root ownership" id="oval:ssg-object_ownership_system_commands_directory_usr_sbin_ownership:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/usr/sbin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_system_commands_directory_usr_sbin_owner_not_root:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="system commands directories have root ownership" id="oval:ssg-object_ownership_system_commands_directory_usr_local_bin_ownership:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/usr/local/bin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_system_commands_directory_usr_local_bin_owner_not_root:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="system commands directories have root ownership" id="oval:ssg-object_ownership_system_commands_directory_usr_local_sbin_ownership:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="all"/>
          <unix:path operation="equals">/usr/local/sbin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_system_commands_directory_usr_local_sbin_owner_not_root:ste:1</oval-def:filter>
        </unix:file_object>
        <linux:partition_object id="oval:ssg-object_file_permissions_unauthorized_sgid_local_partitions:obj:1" version="1">
          <linux:mount_point operation="pattern match">.*</linux:mount_point>
          <oval-def:filter action="include">oval:ssg-state_file_permissions_unauthorized_sgid_dev_partitons:ste:1</oval-def:filter>
        </linux:partition_object>
        <unix:file_object comment="all files with sgid set" id="oval:ssg-object_file_permissions_unauthorized_sgid_all_sgid_files:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="defined"/>
          <unix:path operation="equals" var_check="at least one" var_ref="oval:ssg-var_file_permissions_unauthorized_sgid_local_mountpoints:var:1"/>
          <unix:filename operation="not equal">/</unix:filename>
          <oval-def:filter action="include">oval:ssg-state_file_permissions_unauthorized_sgid_set:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_unauthorized_sgid_sysroot:ste:1</oval-def:filter>
        </unix:file_object>
        <linux:rpmverifyfile_object comment="all files with sgid set that come from a RPM package" id="oval:ssg-object_file_permissions_unauthorized_sgid_rpms:obj:1" version="1">
          <linux:behaviors nogroup="true" nolinkto="true" nomd5="true" nomode="true" nomtime="true" nordev="true" nosize="true" nouser="true"/>
          <linux:name operation="pattern match">.*</linux:name>
          <linux:epoch operation="pattern match">.*</linux:epoch>
          <linux:version operation="pattern match">.*</linux:version>
          <linux:release operation="pattern match">.*</linux:release>
          <linux:arch operation="pattern match">.*</linux:arch>
          <linux:filepath operation="equals" var_check="all" var_ref="oval:ssg-var_file_permissions_unauthorized_sgid_all_sgid_files:var:1"/>
        </linux:rpmverifyfile_object>
        <ind:variable_object id="oval:ssg-object_file_permissions_unauthorized_sgid_no_rpm_files:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_file_permissions_unauthorized_sgid_all_sgid_files:var:1</ind:var_ref>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_unauthorized_sgid_rpm_filepaths:ste:1</oval-def:filter>
        </ind:variable_object>
        <linux:partition_object id="oval:ssg-object_file_permissions_unauthorized_suid_local_partitions:obj:1" version="1">
          <linux:mount_point operation="pattern match">.*</linux:mount_point>
          <oval-def:filter action="include">oval:ssg-state_file_permissions_unauthorized_suid_dev_partitons:ste:1</oval-def:filter>
        </linux:partition_object>
        <unix:file_object comment="all files with suid set" id="oval:ssg-object_file_permissions_unauthorized_suid_all_suid_files:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="defined"/>
          <unix:path operation="equals" var_check="at least one" var_ref="oval:ssg-var_file_permissions_unauthorized_suid_local_mountpoints:var:1"/>
          <unix:filename operation="not equal">/</unix:filename>
          <oval-def:filter action="include">oval:ssg-state_file_permissions_unauthorized_suid_set:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_unauthorized_suid_sysroot:ste:1</oval-def:filter>
        </unix:file_object>
        <linux:rpmverifyfile_object comment="all files with suid set that come from a RPM package" id="oval:ssg-object_file_permissions_unauthorized_suid_rpms:obj:1" version="1">
          <linux:behaviors nogroup="true" nolinkto="true" nomd5="true" nomode="true" nomtime="true" nordev="true" nosize="true" nouser="true"/>
          <linux:name operation="pattern match">.*</linux:name>
          <linux:epoch operation="pattern match">.*</linux:epoch>
          <linux:version operation="pattern match">.*</linux:version>
          <linux:release operation="pattern match">.*</linux:release>
          <linux:arch operation="pattern match">.*</linux:arch>
          <linux:filepath operation="equals" var_check="all" var_ref="oval:ssg-var_file_permissions_unauthorized_suid_all_suid_files:var:1"/>
        </linux:rpmverifyfile_object>
        <ind:variable_object id="oval:ssg-object_file_permissions_unauthorized_suid_no_rpm_files:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_file_permissions_unauthorized_suid_all_suid_files:var:1</ind:var_ref>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_unauthorized_suid_rpm_filepaths:ste:1</oval-def:filter>
        </ind:variable_object>
        <linux:partition_object id="oval:ssg-object_file_permissions_unauthorized_world_writable_local_partitions:obj:1" version="1">
          <linux:mount_point operation="pattern match">.*</linux:mount_point>
          <oval-def:filter action="include">oval:ssg-state_file_permissions_unauthorized_world_writable_dev_partitons:ste:1</oval-def:filter>
        </linux:partition_object>
        <unix:file_object comment="All files with world-write permission." id="oval:ssg-object_file_permissions_unauthorized_world_write:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="defined"/>
          <unix:path operation="equals" var_check="at least one" var_ref="oval:ssg-var_file_permissions_unauthorized_world_writable_local_mountpoints:var:1"/>
          <unix:filename operation="not equal">/</unix:filename>
          <oval-def:filter action="include">oval:ssg-state_file_permissions_unauthorized_world_write:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_unauthorized_world_write_special_selinux_files:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_unauthorized_world_write_sysroot:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_group:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^[^:]+:[^:]*:([\d]+):[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_usr_lib_group:obj:1" version="1">
          <ind:filepath>/usr/lib/group</ind:filepath>
          <ind:pattern operation="pattern match">^[^:]+:[^:]*:([\d]+):[^:]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_all_gids_with_usrlib:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_etc_group:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_usr_lib_group:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_file_permissions_ungroupowned_local_partitions:obj:1" version="1">
          <linux:mount_point operation="pattern match">.*</linux:mount_point>
          <oval-def:filter action="include">oval:ssg-state_file_permissions_ungroupowned_dev_partitons:ste:1</oval-def:filter>
        </linux:partition_object>
        <unix:file_object comment="all local files without a known group owner" id="oval:ssg-object_file_permissions_ungroupowned:obj:1" version="2">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="defined"/>
          <unix:path operation="equals" var_check="at least one" var_ref="oval:ssg-var_file_permissions_ungroupowned_local_mountpoints:var:1"/>
          <unix:filename operation="not equal">/</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_ungroupowned_local_group_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_ungroupowned_sysroot:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="all local files without a known group owner" id="oval:ssg-object_file_permissions_ungroupowned_with_usrlib:obj:1" version="2">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="defined"/>
          <unix:path operation="equals" var_check="at least one" var_ref="oval:ssg-var_file_permissions_ungroupowned_local_mountpoints:var:1"/>
          <unix:filename operation="not equal">/</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_ungroupowned_local_group_owner_with_usrlib:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_ungroupowned_sysroot:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_file_permissions_ungroupowned_nsswitch_uses_altfiles:obj:1" version="1">
          <ind:filepath>/etc/nsswitch.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*group:\s+(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_file_permissions_ungroupowned_package_nss-altfiles_installed:obj:1" version="1">
          <linux:name>nss-altfiles</linux:name>
        </linux:rpminfo_object>
        <linux:partition_object id="oval:ssg-object_no_files_or_dirs_ungroupowned_local_partitions:obj:1" version="1">
          <linux:mount_point operation="pattern match">.*</linux:mount_point>
          <oval-def:filter action="include">oval:ssg-state_no_files_or_dirs_ungroupowned_dev_partitons:ste:1</oval-def:filter>
        </linux:partition_object>
        <unix:file_object comment="all local files and directories without a known group owner" id="oval:ssg-object_no_files_or_dirs_ungroupowned_all:obj:1" version="2">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_no_files_or_dirs_ungroupowned_files:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_no_files_or_dirs_ungroupowned_directories:obj:1</oval-def:object_reference>
          </oval-def:set>
        </unix:file_object>
        <unix:file_object comment="all local files without a known group owner" id="oval:ssg-object_no_files_or_dirs_ungroupowned_files:obj:1" version="2">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="defined"/>
          <unix:path operation="equals" var_check="at least one" var_ref="oval:ssg-var_no_files_or_dirs_ungroupowned_local_mountpoints:var:1"/>
          <unix:filename operation="not equal">/</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-state_no_files_or_dirs_ungroupowned_local_group_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_no_files_or_dirs_ungroupowned_sysroot:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="all local directories without a known group owner" id="oval:ssg-object_no_files_or_dirs_ungroupowned_directories:obj:1" version="2">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="defined"/>
          <unix:path operation="equals" var_check="at least one" var_ref="oval:ssg-var_no_files_or_dirs_ungroupowned_local_mountpoints:var:1"/>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-state_no_files_or_dirs_ungroupowned_local_group_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_no_files_or_dirs_ungroupowned_sysroot:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="all local files and directories without a known group owner" id="oval:ssg-object_no_files_or_dirs_ungroupowned_all_with_usrlib:obj:1" version="2">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_no_files_or_dirs_ungroupowned_files_with_usrlib:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_no_files_or_dirs_ungroupowned_directories_with_usrlib:obj:1</oval-def:object_reference>
          </oval-def:set>
        </unix:file_object>
        <unix:file_object comment="all local files without a known group owner" id="oval:ssg-object_no_files_or_dirs_ungroupowned_files_with_usrlib:obj:1" version="2">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="defined"/>
          <unix:path operation="equals" var_check="at least one" var_ref="oval:ssg-var_no_files_or_dirs_ungroupowned_local_mountpoints:var:1"/>
          <unix:filename operation="pattern match">.*</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-state_no_files_or_dirs_ungroupowned_local_group_owner_with_usrlib:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_no_files_or_dirs_ungroupowned_sysroot:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="all local directories without a known group owner" id="oval:ssg-object_no_files_or_dirs_ungroupowned_directories_with_usrlib:obj:1" version="2">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="defined"/>
          <unix:path operation="equals" var_check="at least one" var_ref="oval:ssg-var_no_files_or_dirs_ungroupowned_local_mountpoints:var:1"/>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-state_no_files_or_dirs_ungroupowned_local_group_owner_with_usrlib:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_no_files_or_dirs_ungroupowned_sysroot:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_no_files_or_dirs_ungroupowned_nsswitch_uses_altfiles:obj:1" version="1">
          <ind:filepath>/etc/nsswitch.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*group:\s+(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_no_files_or_dirs_ungroupowned_package_nss-altfiles_installed:obj:1" version="1">
          <linux:name>nss-altfiles</linux:name>
        </linux:rpminfo_object>
        <unix:password_object id="oval:ssg-object_no_files_or_dirs_unowned_by_user_all_users:obj:1" version="2">
          <unix:username datatype="string" operation="pattern match">.*</unix:username>
        </unix:password_object>
        <linux:partition_object id="oval:ssg-object_no_files_or_dirs_unowned_by_user_local_partitions:obj:1" version="1">
          <linux:mount_point operation="pattern match">.*</linux:mount_point>
          <oval-def:filter action="include">oval:ssg-state_no_files_or_dirs_unowned_by_user_dev_partitons:ste:1</oval-def:filter>
        </linux:partition_object>
        <unix:file_object comment="all local files and directories without a known owner" id="oval:ssg-object_no_files_or_dirs_unowned_by_user_all:obj:1" version="2">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_no_files_or_dirs_unowned_by_user_files:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_no_files_or_dirs_unowned_by_user_directories:obj:1</oval-def:object_reference>
          </oval-def:set>
        </unix:file_object>
        <unix:file_object comment="all local files without a known owner" id="oval:ssg-object_no_files_or_dirs_unowned_by_user_files:obj:1" version="2">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="defined"/>
          <unix:path operation="equals" var_check="at least one" var_ref="oval:ssg-var_no_files_or_dirs_unowned_by_user_local_mountpoints:var:1"/>
          <unix:filename operation="not equal">/</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-state_no_files_or_dirs_unowned_by_user_uids_list:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="all local directories without a known owner" id="oval:ssg-object_no_files_or_dirs_unowned_by_user_directories:obj:1" version="2">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="defined"/>
          <unix:path operation="equals" var_check="at least one" var_ref="oval:ssg-var_no_files_or_dirs_unowned_by_user_local_mountpoints:var:1"/>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-state_no_files_or_dirs_unowned_by_user_uids_list:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:password_object id="oval:ssg-object_no_files_unowned_by_user_all_users:obj:1" version="2">
          <unix:username datatype="string" operation="pattern match">.*</unix:username>
        </unix:password_object>
        <linux:partition_object id="oval:ssg-object_no_files_unowned_by_user_local_partitions:obj:1" version="1">
          <linux:mount_point operation="pattern match">.*</linux:mount_point>
          <oval-def:filter action="include">oval:ssg-state_no_files_unowned_by_user_dev_partitons:ste:1</oval-def:filter>
        </linux:partition_object>
        <unix:file_object comment="all local files without a known owner" id="oval:ssg-object_no_files_unowned_by_user:obj:1" version="2">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="defined"/>
          <unix:path operation="equals" var_check="at least one" var_ref="oval:ssg-var_no_files_unowned_by_user_local_mountpoints:var:1"/>
          <unix:filename operation="not equal">/</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-state_no_files_unowned_by_user_uids_list:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object id="oval:ssg-object_file_etc_security_opasswd:obj:1" version="1">
          <unix:filepath>/etc/security/opasswd</unix:filepath>
        </unix:file_object>
        <unix:file_object comment="system commands files" id="oval:ssg-object_groupownership_system_commands_dirs:obj:1" version="1">
          <unix:path operation="pattern match">^\/s?bin|^\/usr\/s?bin|^\/usr\/local\/s?bin</unix:path>
          <unix:filename operation="not equal">/</unix:filename>
          <oval-def:filter action="include">oval:ssg-state_groupowner_system_commands_dirs_not_root_or_system_account:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_groupowner_system_commands_dirs_symlink:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="binary directories" id="oval:ssg-object_file_ownership_binary_directories:obj:1" version="1">
          <unix:path operation="pattern match">^\/(|s)bin|^\/usr\/(|local\/)(|s)bin|^\/usr\/libexec</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="include">oval:ssg-state_owner_binaries_not_root:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="binary files" id="oval:ssg-object_file_ownership_binary_files:obj:1" version="1">
          <unix:path operation="pattern match">^\/(|s)bin|^\/usr\/(|local\/)(|s)bin|^\/usr\/libexec</unix:path>
          <unix:filename operation="not equal">/</unix:filename>
          <oval-def:filter action="include">oval:ssg-state_owner_binaries_not_root:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="binary files" id="oval:ssg-object_file_permissions_binary_files:obj:1" version="1">
          <unix:path operation="pattern match">^\/(|s)bin|^\/usr\/(|local\/)(|s)bin|^\/usr\/libexec</unix:path>
          <unix:filename operation="not equal">/</unix:filename>
          <oval-def:filter action="include">oval:ssg-state_perms_binary_files_nogroupwrite_noworldwrite:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_perms_binary_files_symlink:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rootfiles_configured_bash_logout:obj:1" version="1">
          <ind:path>/etc/tmpfiles.d/</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^C[[:blank:]]+\/root\/.bash_logout[[:blank:]]+(\d{3})[[:blank:]]+root[[:blank:]]+root[[:blank:]]+-[[:blank:]]+\/usr\/share\/rootfiles/.bash_logout$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rootfiles_configured_bash_profile:obj:1" version="1">
          <ind:path>/etc/tmpfiles.d/</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^C[[:blank:]]+\/root\/.bash_profile[[:blank:]]+(\d{3})[[:blank:]]+root[[:blank:]]+root[[:blank:]]+-[[:blank:]]+\/usr\/share\/rootfiles/.bash_profile$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rootfiles_configured_bashrc:obj:1" version="1">
          <ind:path>/etc/tmpfiles.d/</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^C[[:blank:]]+\/root\/.bashrc[[:blank:]]+(\d{3})[[:blank:]]+root[[:blank:]]+root[[:blank:]]+-[[:blank:]]+\/usr\/share\/rootfiles/.bashrc$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rootfiles_configured_cshrc:obj:1" version="1">
          <ind:path>/etc/tmpfiles.d/</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^C[[:blank:]]+\/root\/.cshrc[[:blank:]]+(\d{3})[[:blank:]]+root[[:blank:]]+root[[:blank:]]+-[[:blank:]]+\/usr\/share\/rootfiles/.cshrc$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rootfiles_configured_tcshrc:obj:1" version="1">
          <ind:path>/etc/tmpfiles.d/</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^C[[:blank:]]+\/root\/.tcshrc[[:blank:]]+(\d{3})[[:blank:]]+root[[:blank:]]+root[[:blank:]]+-[[:blank:]]+\/usr\/share\/rootfiles/.tcshrc$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_non_root_partitions:obj:1" version="1">
          <linux:mount_point operation="pattern match">^/(?!boot|efi)\w.*$</linux:mount_point>
          <oval-def:filter action="include">oval:ssg-state_local_nodev:ste:1</oval-def:filter>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_non_root_partitions_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^\s*(?!#)(?:/dev/\S+|UUID=\S+)\s+/(?!boot|efi)\w\S*\s+\S+\s+(\S+)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="look for the partition mount point in /etc/mtab" id="oval:ssg-object_configure_mount_option_var_tmp_bind_tmp:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*/tmp[\s]+/var/tmp[\s]+.*bind.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_mount_option_var_tmp:obj:1" version="1">
          <linux:mount_point operation="pattern match">^/var/tmp$</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object comment="look for the partition mount point in /etc/mtab" id="oval:ssg-object_mount_option_var_tmp_bind:obj:1" version="1">
          <ind:filepath>/etc/mtab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*/tmp[\s]+/var/tmp[\s]+.*bind.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_mount_option_var_tmp_bind_compare_source:obj:1" version="1">
          <linux:mount_point operation="pattern match">^/tmp$</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_core_dumps_limitsconf:obj:1" version="1">
          <ind:filepath>/etc/security/limits.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*\*[\s]+(?:hard|-)[\s]+core[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_core_dumps_limits_d:obj:1" version="1">
          <ind:path>/etc/security/limits.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*\*[\s]+(?:hard|-)[\s]+core[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_core_dumps_limits_d_exists:obj:1" version="1">
          <ind:path>/etc/security/limits.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*\*[\s]+(?:hard|-)[\s]+core</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Umask value from /etc/init.d/functions" id="oval:ssg-obj_umask_from_etc_init_d_functions:obj:1" version="1">
          <ind:filepath>/etc/init.d/functions</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?i)UMASK(?-i)[\s]+([^#\s]*)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-obj_umask_for_daemons:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_etc_init_d_functions_umask_as_number:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_kernel_exec_shield:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*kernel.exec-shield[\s]*=[\s]*1[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_exec_shield:obj:1" version="1">
          <unix:name>kernel.exec-shield</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_nx_disabled_grub:obj:1" version="1">
          <ind:filepath>/boot/grub2/grub.cfg</ind:filepath>
          <ind:pattern operation="pattern match">[\s]*noexec[\s]*=[\s]*off</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_NX_cpu_support:obj:1" version="1">
          <ind:filepath>/proc/cpuinfo</ind:filepath>
          <ind:pattern operation="pattern match">^flags[\s]+:.*[\s]+nx[\s]+.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_noexec_cmd_line:obj:1" version="1">
          <ind:filepath>/proc/cmdline</ind:filepath>
          <ind:pattern operation="pattern match">.+noexec[0-9]*=off.+</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:rpminfo_object id="oval:ssg-obj_package_kernel-PAE_installed:obj:1" version="1">
          <linux:name>kernel-PAE</linux:name>
        </linux:rpminfo_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_PAE_NX_cpu_support:obj:1" version="1">
          <ind:filepath>/proc/cpuinfo</ind:filepath>
          <ind:pattern operation="pattern match">^flags[\s]+:.*[\s]+pae[\s]+.*[\s]+nx[\s]+.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_defaultkernel_sysconfig_kernel:obj:1" version="1">
          <ind:filepath>/etc/sysconfig/kernel</ind:filepath>
          <ind:pattern operation="pattern match">^\s*DEFAULTKERNEL[\s]*=[\s]*kernel-PAE$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="check value selinux|enforcing=0 in /etc/default/grub, fail if found" id="oval:ssg-object_selinux_default_grub:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*GRUB_CMDLINE_LINUX.*(selinux|enforcing)=0.*$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="check value selinux|enforcing=0 in /etc/grub2.cfg, fail if found" id="oval:ssg-object_selinux_grub2_cfg:obj:1" version="1">
          <ind:filepath>/etc/grub2.cfg</ind:filepath>
          <ind:pattern operation="pattern match">^.*(selinux|enforcing)=0.*$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="check value selinux|enforcing=0 in /etc/grub.d, fail if found" id="oval:ssg-object_selinux_grub_dir:obj:1" version="1">
          <ind:path>/etc/grub.d</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^.*(selinux|enforcing)=0.*$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="device files within /dev directory" id="oval:ssg-object_dev_device_files:obj:1" version="1">
          <unix:behaviors recurse_direction="down"/>
          <unix:path operation="equals">/dev</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="include">oval:ssg-state_block_or_char_device_file:ste:1</oval-def:filter>
        </unix:file_object>
        <linux:selinuxsecuritycontext_object comment="device_t in /dev" id="oval:ssg-object_selinux_dev_device_t:obj:1" version="1">
          <linux:filepath operation="equals" var_check="at least one" var_ref="oval:ssg-variable_dev_device_files:var:1"/>
          <oval-def:filter action="include">oval:ssg-state_selinux_dev_device_t:ste:1</oval-def:filter>
        </linux:selinuxsecuritycontext_object>
        <linux:selinuxsecuritycontext_object comment="unlabeled_t in /dev" id="oval:ssg-object_selinux_dev_unlabeled_t:obj:1" version="1">
          <linux:filepath operation="equals" var_check="at least one" var_ref="oval:ssg-variable_dev_device_files:var:1"/>
          <oval-def:filter action="include">oval:ssg-state_selinux_dev_unlabeled_t:ste:1</oval-def:filter>
        </linux:selinuxsecuritycontext_object>
        <linux:selinuxsecuritycontext_object comment="find unconfined_service_t in /proc" id="oval:ssg-object_selinux_confinement_of_daemons:obj:1" version="1">
          <linux:behaviors max_depth="1" recurse_direction="down"/>
          <linux:path>/proc</linux:path>
          <linux:filename operation="pattern match">^.*$</linux:filename>
          <oval-def:filter action="include">oval:ssg-state_selinux_confinement_of_daemons:ste:1</oval-def:filter>
        </linux:selinuxsecuritycontext_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sudo_selinux_elevation_type:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(\.d/.*)?$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*%\w+.*TYPE=(\w+).*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sudo_selinux_elevation_role:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(\.d/.*)?$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*%\w+.*ROLE=(\w+).*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_selinux_not_disabled:obj:1" version="1">
          <ind:filepath>/etc/selinux/config</ind:filepath>
          <ind:pattern operation="pattern match">^SELINUX=(.*)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_selinux_config:obj:1" version="1">
          <ind:filepath>/etc/selinux/config</ind:filepath>
          <ind:pattern operation="pattern match">^SELINUX=(.*)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:rpminfo_object id="oval:ssg-obj_package_kernel:obj:1" version="1">
          <linux:name>kernel</linux:name>
        </linux:rpminfo_object>
        <ind:textfilecontent54_object id="oval:ssg-object_proc_cpuinfo_64_bit:obj:1" version="1">
          <ind:filepath>/proc/cpuinfo</ind:filepath>
          <ind:pattern operation="pattern match">^flags\s+:\s+(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_proc_sys_kernel_osrelease_64_bit:obj:1" version="1">
          <ind:filepath>/proc/sys/kernel/osrelease</ind:filepath>
          <ind:pattern operation="pattern match">^.*\.(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="The binary system-wide dconf database with 'gdm' settings" id="oval:ssg-obj_dconf_gdm_db:obj:1" version="1">
          <unix:filepath>/etc/dconf/db/gdm</unix:filepath>
        </unix:file_object>
        <unix:file_object comment="The dconf keyfile with 'gdm' settings" id="oval:ssg-obj_dconf_gdm_config:obj:1" version="1">
          <unix:filepath operation="pattern match">^/etc/dconf/db/gdm.d/.*</unix:filepath>
        </unix:file_object>
        <ind:variable_object comment="All modified times of all keyfiles" id="oval:ssg-object_gdm_db_modified_time:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_dconf_gdm_db_modified_time:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="The binary system-wide dconf database with 'local' settings" id="oval:ssg-obj_dconf_local_db:obj:1" version="1">
          <unix:filepath>/etc/dconf/db/local</unix:filepath>
        </unix:file_object>
        <unix:file_object comment="The dconf keyfile with 'local' settings" id="oval:ssg-obj_dconf_local_config:obj:1" version="1">
          <unix:filepath operation="pattern match">^/etc/dconf/db/local.d/.*</unix:filepath>
        </unix:file_object>
        <ind:variable_object comment="All modified times of all keyfiles" id="oval:ssg-object_local_db_modified_time:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_dconf_local_db_modified_time:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_dconf_user_profile:obj:1" version="2">
          <ind:filepath>/etc/dconf/profile/user</ind:filepath>
          <ind:pattern operation="pattern match">^user-db:user\nsystem-db:local$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_xwayland_disabled:obj:1" version="1">
          <ind:filepath>/etc/gdm/custom.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\[daemon\].*(?:\n\s*[^[\s].*)*\n^\s*WaylandEnable[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="The configuration file /etc/gdm/custom.conf for xwayland_disabled" id="oval:ssg-obj_xwayland_disabled_config_file:obj:1" version="1">
          <unix:filepath operation="pattern match">^/etc/gdm/custom.conf</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_disable_restart_buttons:obj:1" version="1">
          <ind:path>/etc/dconf/db/gdm.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/login-screen\]([^\n]*\n+)+?disable-restart-buttons=true$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_enable_restart_buttons:obj:1" version="1">
          <ind:path>/etc/dconf/db/gdm.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/login-screen/disable-restart-buttons$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_disable_user_list:obj:1" version="1">
          <ind:path>/etc/dconf/db/gdm.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/login-screen\]([^\n]*\n+)+?disable-user-list=true$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_disable_user_list:obj:1" version="1">
          <ind:path>/etc/dconf/db/gdm.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/login-screen/disable-user-list$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_enable_gnome_smartcard:obj:1" version="1">
          <ind:path>/etc/dconf/db/gdm.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/login-screen\]([^\n]*\n+)+?enable-smartcard-authentication=true$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_disable_smartcard:obj:1" version="1">
          <ind:path>/etc/dconf/db/gdm.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/login-screen/enable-smartcard-authentication$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_configure_allowed_failures:obj:1" version="1">
          <ind:path>/etc/dconf/db/gdm.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/login-screen\]([^\n]*\n+)+?allowed-failures=3$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_allowed-failures_change:obj:1" version="1">
          <ind:path>/etc/dconf/db/gdm.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/login-screen/allowed-failures$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_disable_automatic_login:obj:1" version="1">
          <ind:filepath>/etc/gdm/custom.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\[daemon]([^\n]*\n+)+?AutomaticLoginEnable=[Ff]alse$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_disable_guest_login:obj:1" version="1">
          <ind:filepath>/etc/gdm/custom.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\[daemon]([^\n]*\n+)+?TimedLoginEnable=[Ff]alse$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_gnome_gdm_disable_xdmcp:obj:1" version="1">
          <ind:filepath>/etc/gdm/custom.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\[xdmcp\].*(?:\n\s*[^[\s].*)*\n^\s*Enable[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="The configuration file /etc/gdm/custom.conf for gnome_gdm_disable_xdmcp" id="oval:ssg-obj_gnome_gdm_disable_xdmcp_config_file:obj:1" version="1">
          <unix:filepath operation="pattern match">^/etc/gdm/custom.conf</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_dconf_gnome_disable_automount:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/desktop/media-handling\]([^\n]*\n+)+?automount=false$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_gnome_automount:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/desktop/media-handling/automount$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_dconf_gnome_disable_automount_open:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/desktop/media-handling\]([^\n]*\n+)+?automount-open=false$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_gnome_automount_open:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/desktop/media-handling/automount-open$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_dconf_gnome_disable_autorun:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/desktop/media-handling\]([^\n]*\n+)+?autorun-never=true$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_gnome_autorun:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/desktop/media-handling/autorun-never$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_gnome_disable_thumbnailers:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/desktop/thumbnailers\]([^\n]*\n+)+?disable-all=true$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_change_gnome_thumbnailers:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/desktop/thumbnailers/disable-all$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_disable_wifi_creation:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/nm-applet\]([^\n]*\n+)+?disable-wifi-create=true$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_enable_wifi_creation:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/nm-applet/disable-wifi-create$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_disable_wifi_notification:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/nm-applet\]([^\n]*\n+)+?suppress-wireless-networks-available=true$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_enable_wifi_notification:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/nm-applet/suppress-wireless-networks-available$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_configure_remote_access_creds:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/Vino\]([^\n]*\n+)+?authentication-methods=\['vnc'\]$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_remote_access_creds:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/Vino/authentication-methods$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_configure_remote_access_encryption:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/Vino\]([^\n]*\n+)+?require-encryption=true$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_remote_access_encryption:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/Vino/require-encryption$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_screensaver_idle_activation_enabled:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/desktop/screensaver\]([^\n]*\n+)+?idle-activation-enabled=true$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_change_idle_activation_enabled:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/desktop/screensaver/idle-activation-enabled$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_change_idle_activation_locked:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/desktop/screensaver/idle-activation-enabled$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_screensaver_idle_delay:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/desktop/session\]([^\n]*\n+)+?idle-delay=uint32[\s][0-9]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_screensaver_idle_delay_setting:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^idle-delay[\s=]*uint32[\s]([^=\s]*)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_screensaver_lock_delay:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/desktop/screensaver\]([^\n]*\n+)+?lock-delay=uint32[\s][0-9]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_screensaver_lock_delay_setting:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^lock-delay[\s=]*uint32[\s]([^=\s]*)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_screensaver_lock_enabled:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/desktop/screensaver\]([^\n]*\n+)+?lock-enabled=true$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_screensaver_lock:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/desktop/screensaver/lock-enabled$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_screensaver_lock_locked:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/desktop/screensaver/lock-enabled$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_screensaver_mode_blank:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/desktop/screensaver\]([^\n]*\n+)+?picture-uri=string \'\'$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_screensaver_mode_change:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/desktop/screensaver/picture-uri$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_screensaver_disable_user_info:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/desktop/screensaver\]([^\n]*\n+)+?show-full-name-in-top-bar=false$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_info_change:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/desktop/screensaver/show-full-name-in-top-bar$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_user_change_lock_delay_lock:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/desktop/screensaver/lock-delay$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_user_change_idle_delay_lock:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/desktop/session/idle-delay$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_disable_gnome_ctrlaltdel:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/settings-daemon/plugins/media-keys\]([^\n]*\n+)+?logout[\s]*=[\s]*\[''\]$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_enable_ctrlaltdel:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/settings-daemon/plugins/media-keys/logout$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_disable_sys_geolocation:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/system/location\]([^\n]*\n+)+?enabled=false$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_sys_geolocation:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/system/location/enabled$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_disable_clock_geolocation:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/clocks\]([^\n]*\n+)+?geolocation=false$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_clock_geolocation:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/clocks/geolocation$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_disable_gnome_power_setting:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\[org/gnome/settings-daemon/plugins/power\]([^\n]*\n+)+?active=false$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_power_setting_change:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/settings-daemon/plugins/power/active$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_configure_bind_crypto_policy:obj:1" version="1">
          <ind:filepath>/etc/named.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*include\s+"/etc/crypto-policies/back-ends/bind.config"\s*;\s*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="crypto-policies current state" id="oval:ssg-crypto_policies_current_file:obj:1" version="1">
          <unix:filepath>/etc/crypto-policies/state/current</unix:filepath>
        </unix:file_object>
        <unix:file_object comment="crypto-policies config state" id="oval:ssg-crypto_policies_config_file:obj:1" version="1">
          <unix:filepath datatype="string">/etc/crypto-policies/config</unix:filepath>
        </unix:file_object>
        <ind:variable_object comment="Crypto policy current file timestamp" id="oval:ssg-object_crypto_policies_config_file_modified_time:obj:1" version="1">
          <ind:var_ref>oval:ssg-variable_crypto_policies_config_file_timestamp:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-object_configure_crypto_policy:obj:1" version="1">
          <ind:filepath>/etc/crypto-policies/config</ind:filepath>
          <ind:pattern operation="pattern match">^(?!#)(\S+)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_configure_crypto_policy_current:obj:1" version="1">
          <ind:filepath>/etc/crypto-policies/state/current</ind:filepath>
          <ind:pattern operation="pattern match">^(?!#)(\S+)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-object_crypto_policy_nss_config:obj:1" version="1">
          <unix:filepath>/etc/crypto-policies/back-ends/nss.config</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_configure_gnutls_tls_crypto_policy:obj:1" version="1">
          <ind:filepath>/etc/crypto-policies/back-ends/gnutls.config</ind:filepath>
          <ind:pattern operation="pattern match">\+VERS-ALL:-VERS-DTLS0\.9:-VERS-TLS1\.1:-VERS-TLS1\.0:-VERS-SSL3\.0:-VERS-DTLS1\.0</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_symlink_kerberos_crypto_policy_configuration:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_symlink_kerberos_crypto_policy_configuration:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:symlink_object comment="kerberos crypto-policy configuration softlink" id="oval:ssg-object_kerberos_crypto_policy_configuration:obj:1" version="1">
          <unix:filepath>/etc/krb5.conf.d/crypto-policies</unix:filepath>
        </unix:symlink_object>
        <unix:symlink_object comment="kerberos crypto-policy backend softlink" id="oval:ssg-object_kerberos_crypto_policy_backend:obj:1" version="1">
          <unix:filepath>/etc/crypto-policies/back-ends/krb5.config</unix:filepath>
        </unix:symlink_object>
        <ind:textfilecontent54_object id="oval:ssg-object_configure_libreswan_crypto_policy:obj:1" version="1">
          <ind:filepath>/etc/ipsec.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*include\s+/etc/crypto-policies/back-ends/libreswan.config\s*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_configure_openssl_crypto_policy:obj:1" version="1">
          <ind:filepath>/etc/pki/tls/openssl.cnf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\[\s*crypto_policy\s*\]\s*\n*\s*\.include\s*(?:=\s*)?/etc/crypto-policies/back-ends/opensslcnf.config\s*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_configure_openssl_tls_crypto_policy:obj:1" version="1">
          <ind:filepath>/etc/crypto-policies/back-ends/opensslcnf.config</ind:filepath>
          <ind:pattern operation="pattern match">^\s*(?:TLS\.)?(?i)MinProtocol\s*=\s*TLSv(\S*)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_configure_openssl_dtls_crypto_policy:obj:1" version="1">
          <ind:filepath>/etc/crypto-policies/back-ends/opensslcnf.config</ind:filepath>
          <ind:pattern operation="pattern match">^\s*(?:DTLS\.)?(?i)MinProtocol\s*=\s*DTLSv(\S*)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:rpminfo_object id="oval:ssg-obj_installed_version_of_crypto_policies:obj:1" version="1">
          <linux:name>crypto-policies</linux:name>
        </linux:rpminfo_object>
        <ind:textfilecontent54_object id="oval:ssg-object_configure_ssh_crypto_policy:obj:1" version="1">
          <ind:filepath>/etc/sysconfig/sshd</ind:filepath>
          <ind:pattern operation="pattern match">^\s*(?i)CRYPTO_POLICY\s*=.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_harden_openssl_crypto_policy:obj:1" version="1">
          <ind:filepath>/etc/crypto-policies/back-ends/opensslcnf.config</ind:filepath>
          <ind:pattern operation="pattern match">^(?:.*\n)*\s*Ciphersuites\s*=\s*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_harden_ssh_client_crypto_policy_Match:obj:1" version="1">
          <ind:filepath>/etc/ssh/ssh_config.d/02-ospp.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*Match[\s]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_harden_ssh_client_crypto_policy_RekeyLimit:obj:1" version="1">
          <ind:filepath>/etc/ssh/ssh_config.d/02-ospp.conf</ind:filepath>
          <ind:pattern operation="pattern match">^Match final all(?:.*
)*?\s*RekeyLimit[\s]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_harden_ssh_client_crypto_policy_GSSAPIAuthentication:obj:1" version="1">
          <ind:filepath>/etc/ssh/ssh_config.d/02-ospp.conf</ind:filepath>
          <ind:pattern operation="pattern match">^Match final all(?:.*
)*?\s*GSSAPIAuthentication[\s]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_harden_ssh_client_crypto_policy_Ciphers:obj:1" version="1">
          <ind:filepath>/etc/ssh/ssh_config.d/02-ospp.conf</ind:filepath>
          <ind:pattern operation="pattern match">^Match final all(?:.*
)*?\s*Ciphers[\s]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_harden_ssh_client_crypto_policy_PubkeyAcceptedKeyTypes:obj:1" version="1">
          <ind:filepath>/etc/ssh/ssh_config.d/02-ospp.conf</ind:filepath>
          <ind:pattern operation="pattern match">^Match final all(?:.*
)*?\s*PubkeyAcceptedKeyTypes[\s]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_harden_ssh_client_crypto_policy_MACs:obj:1" version="1">
          <ind:filepath>/etc/ssh/ssh_config.d/02-ospp.conf</ind:filepath>
          <ind:pattern operation="pattern match">^Match final all(?:.*
)*?\s*MACs[\s]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_harden_ssh_client_crypto_policy_KexAlgorithms:obj:1" version="1">
          <ind:filepath>/etc/ssh/ssh_config.d/02-ospp.conf</ind:filepath>
          <ind:pattern operation="pattern match">^Match final all(?:.*
)*?\s*KexAlgorithms[\s]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_harden_sshd_ciphers_openssh_conf_crypto_policy:obj:1" version="1">
          <ind:filepath>/etc/crypto-policies/back-ends/openssh.config</ind:filepath>
          <ind:pattern operation="pattern match">^Ciphers.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_harden_sshd_ciphers_opensshserver_conf_crypto_policy:obj:1" version="1">
          <ind:filepath>/etc/crypto-policies/back-ends/opensshserver.config</ind:filepath>
          <ind:pattern operation="pattern match">^(?!#).*-oCiphers=([^\s']+).*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">-1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_harden_sshd_crypto_policy:obj:1" version="1">
          <ind:filepath>/etc/crypto-policies/back-ends/opensshserver.config</ind:filepath>
          <ind:pattern operation="pattern match">^(?:.*\n)*\s*CRYPTO_POLICY=(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_harden_sshd_macs_openssh_conf_crypto_policy:obj:1" version="1">
          <ind:filepath>/etc/crypto-policies/back-ends/openssh.config</ind:filepath>
          <ind:pattern operation="pattern match">^MACs.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_harden_sshd_macs_opensshserver_conf_crypto_policy:obj:1" version="1">
          <ind:filepath>/etc/crypto-policies/back-ends/opensshserver.config</ind:filepath>
          <ind:pattern operation="pattern match">^(?!#).*-oMACs=([^\s']+).*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">-1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:filehash58_object id="oval:ssg-object_openssl_strong_entropy:obj:1" version="1">
          <ind:filepath>/etc/profile.d/openssl-rand.sh</ind:filepath>
          <ind:hash_type>SHA-256</ind:hash_type>
        </ind:filehash58_object>
        <ind:textfilecontent54_object id="oval:ssg-object_selinux_enforcing:obj:1" version="1">
          <ind:filepath>/etc/selinux/config</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*SELINUX[\s]*=[\s]*enforcing[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:rpminfo_object id="oval:ssg-obj_linuxshield_install_antivirus:obj:1" version="1">
          <linux:name>McAfeeVSEForLinux</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_mcafee_runtime_installed:obj:1" version="1">
          <linux:name>MFErt</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_mcafee_management_agent:obj:1" version="1">
          <linux:name>MFEcma</linux:name>
        </linux:rpminfo_object>
        <unix:file_object comment="McAfee definition files" id="oval:ssg-mcafee_dat_files_mtime:obj:1" version="1">
          <unix:path datatype="string">/opt/NAI/LinuxShield/engine/dat</unix:path>
          <unix:filename datatype="string" operation="pattern match">^.*\.dat$</unix:filename>
        </unix:file_object>
        <ind:variable_object comment="McAfee AntiVirus definitions age" id="oval:ssg-object_mcafee_definitions_modified_time:obj:1" version="1">
          <ind:var_ref>oval:ssg-variable_mcafee_dat_files_mtime:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:process58_object id="oval:ssg-obj_agent_mfetpd_running:obj:1" version="1">
          <unix:command_line operation="pattern match">^mfetpd.*$</unix:command_line>
          <unix:pid datatype="int" operation="greater than">0</unix:pid>
        </unix:process58_object>
        <unix:file_object id="oval:ssg-object_mcafee_accm_exists:obj:1" version="1">
          <unix:path>/opt/McAfee/accm/bin</unix:path>
          <unix:filename>accm</unix:filename>
        </unix:file_object>
        <unix:file_object id="oval:ssg-object_mcafee_auditengine_exists:obj:1" version="1">
          <unix:path>/opt/McAfee/auditengine/bin</unix:path>
          <unix:filename>auditmanager</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_enable_dracut_fips_module:obj:1" version="1">
          <ind:filepath>/etc/dracut.conf.d/40-fips.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*add_dracutmodules\+="\s*(\w*)\s*"\s*(?:#.*)?$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-obj_system_crypto_policy_value:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_system_crypto_policy:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_proc_sys_crypto_fips_enabled:obj:1" version="1">
          <ind:filepath>/proc/sys/crypto/fips_enabled</ind:filepath>
          <ind:pattern operation="pattern match">^1$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-object_etc_system_fips:obj:1" version="1">
          <unix:filepath>/etc/system-fips</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_fips_crypto_subpolicy:obj:1" version="1">
          <ind:filepath>/etc/crypto-policies/config</ind:filepath>
          <ind:pattern operation="pattern match">^FIPS$|^FIPS:(OSPP|NO-SHA1|NO-CAMELLIA|ECDHE-ONLY|STIG)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_fips_custom_stig_sub_policy_cipher_ssh:obj:1" version="1">
          <ind:path>/etc/crypto-policies/policies/modules/</ind:path>
          <ind:filename>STIG.pmod</ind:filename>
          <ind:pattern operation="pattern match">^cipher@SSH=AES-256-GCM AES-256-CTR AES-128-GCM AES-128-CTR$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_fips_custom_stig_sub_policy_mac_ssh:obj:1" version="1">
          <ind:path>/etc/crypto-policies/policies/modules/</ind:path>
          <ind:filename>STIG.pmod</ind:filename>
          <ind:pattern operation="pattern match">^mac@SSH=HMAC-SHA2-512 HMAC-SHA2-256$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_crypto_fips_enabled:obj:1" version="1">
          <unix:name>crypto.fips_enabled</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_aide_operational_database_filename:obj:1" version="1">
          <ind:filepath>/etc/aide.conf</ind:filepath>
          <ind:pattern operation="pattern match">^database=file:(?:@@{DBDIR})?/(?:[a-z.]+/)*([a-z.]+)$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_aide_build_database_dirpath:obj:1" version="1">
          <ind:filepath>/etc/aide.conf</ind:filepath>
          <ind:pattern operation="pattern match">^@@define[\s]DBDIR[\s]+(/.*)$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-object_aide_operational_database_absolute_path:obj:1" version="1">
          <unix:filepath var_check="at least one" var_ref="oval:ssg-variable_aide_operational_database_absolute_path:var:1"/>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_aide_verify_auditctl:obj:1" version="1">
          <ind:filepath>/etc/aide.conf</ind:filepath>
          <ind:pattern operation="pattern match">^(?:/usr)?/sbin/auditctl\s+([^\n]+)$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_aide_verify_auditd:obj:1" version="1">
          <ind:filepath>/etc/aide.conf</ind:filepath>
          <ind:pattern operation="pattern match">^(?:/usr)?/sbin/auditd\s+([^\n]+)$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_aide_verify_ausearch:obj:1" version="1">
          <ind:filepath>/etc/aide.conf</ind:filepath>
          <ind:pattern operation="pattern match">^(?:/usr)?/sbin/ausearch\s+([^\n]+)$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_aide_verify_aureport:obj:1" version="1">
          <ind:filepath>/etc/aide.conf</ind:filepath>
          <ind:pattern operation="pattern match">^(?:/usr)?/sbin/aureport\s+([^\n]+)$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_aide_verify_autrace:obj:1" version="1">
          <ind:filepath>/etc/aide.conf</ind:filepath>
          <ind:pattern operation="pattern match">^(?:/usr)?/sbin/autrace\s+([^\n]+)$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_aide_verify_rsyslogd:obj:1" version="1">
          <ind:filepath>/etc/aide.conf</ind:filepath>
          <ind:pattern operation="pattern match">^(?:/usr)?/sbin/rsyslogd\s+([^\n]+)$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_aide_verify_augenrules:obj:1" version="1">
          <ind:filepath>/etc/aide.conf</ind:filepath>
          <ind:pattern operation="pattern match">^(?:/usr)?/sbin/augenrules\s+([^\n]+)$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="run aide with cron" id="oval:ssg-object_test_aide_periodic_cron_checking:obj:1" version="1">
          <ind:filepath>/etc/crontab</ind:filepath>
          <ind:pattern operation="pattern match">^(([0-9]*[\s]*[0-9]*[\s]*\*[\s]*\*[\s]*(\*|([0-7]|mon|tue|wed|thu|fri|sat|sun)|[0-7]-[0-7]))|@(hourly|daily|weekly))[\s]*root[\s]*\/usr\/sbin\/aide[\s]*\-\-check.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="run aide with cron" id="oval:ssg-object_test_aide_crond_checking:obj:1" version="1">
          <ind:path>/etc/cron.d</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^(([0-9]*[\s]*[0-9]*[\s]*\*[\s]*\*[\s]*(\*|([0-7]|mon|tue|wed|thu|fri|sat|sun)|[0-7]-[0-7]))|@(hourly|daily|weekly))[\s]*root[\s]*\/usr\/sbin\/aide[\s]*\-\-check.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="run aide with cron" id="oval:ssg-object_aide_var_cron_checking:obj:1" version="1">
          <ind:filepath>/var/spool/cron/root</ind:filepath>
          <ind:pattern operation="pattern match">^(([0-9]*[\s]*[0-9]*[\s]*\*[\s]*\*[\s]*(\*|([0-7]|mon|tue|wed|thu|fri|sat|sun)|[0-7]-[0-7]))|@(hourly|daily|weekly))[\s]*(root)?[\s]*\/usr\/sbin\/aide[\s]*\-\-check.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="run aide with cron.(daily|weekly)" id="oval:ssg-object_aide_crontabs_checking:obj:1" version="1">
          <ind:path operation="pattern match">^/etc/cron.(daily|weekly)$</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^[^#]*\/usr\/sbin\/aide\s+\-\-check\s*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="notify personnel when aide completes" id="oval:ssg-object_test_aide_scan_notification:obj:1" version="1">
          <ind:filepath>/etc/crontab</ind:filepath>
          <ind:pattern operation="pattern match">^.*/usr/sbin/aide[\s]*\-\-check.*\|.*/bin/mail[\s]*-s[\s]*".*"[\s]*.+@.+$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="notify personnel when aide completes" id="oval:ssg-object_aide_var_cron_notification:obj:1" version="1">
          <ind:filepath>/var/spool/cron/root</ind:filepath>
          <ind:pattern operation="pattern match">^.*/usr/sbin/aide[\s]*\-\-check.*\|.*/bin/mail[\s]*-s[\s]*".*"[\s]*.+@.+$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="notify personnel when aide completes in cron.(d|daily|weekly|monthly)" id="oval:ssg-object_aide_crontabs_notification:obj:1" version="1">
          <ind:path operation="pattern match">^/etc/cron.(d|daily|weekly|monthly)$</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^.*/usr/sbin/aide[\s]*\-\-check.*\|.*/bin/mail[\s]*-s[\s]*".*"[\s]*.+@.+$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_aide_non_fips_hashes:obj:1" version="1">
          <ind:filepath>/etc/aide.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[A-Z][a-zA-Z_]*[\s]*=[\s]*.*(sha1|rmd160|sha256|whirlpool|tiger|haval|gost|crc32).*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">0</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_aide_use_fips_hashes:obj:1" version="1">
          <ind:filepath>/etc/aide.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[A-Z][A-Za-z_]*[\s]*=[\s]*([a-zA-Z0-9\+]*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_aide_verify_acls:obj:1" version="2">
          <ind:filepath>/etc/aide.conf</ind:filepath>
          <ind:pattern operation="pattern match">^(?!ALLXTRAHASHES)[A-Z][a-zA-Z_]*[\s]*=[\s]*([a-zA-Z0-9\+]*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_aide_verify_ext_attributes:obj:1" version="2">
          <ind:filepath>/etc/aide.conf</ind:filepath>
          <ind:pattern operation="pattern match">^(?!ALLXTRAHASHES)[A-Z][a-zA-Z_]*[\s]*=[\s]*([a-zA-Z0-9\+]*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:rpmverifyfile_object comment="rpm verify of all files" id="oval:ssg-object_rpm_verify_hashes_fail_md5_hash:obj:1" version="1">
          <linux:behaviors nomd5="false"/>
          <linux:name operation="pattern match">.*</linux:name>
          <linux:epoch operation="pattern match">.*</linux:epoch>
          <linux:version operation="pattern match">.*</linux:version>
          <linux:release operation="pattern match">.*</linux:release>
          <linux:arch operation="pattern match">.*</linux:arch>
          <linux:filepath operation="pattern match">^/(bin|sbin|lib|lib64|usr)/.+$</linux:filepath>
          <oval-def:filter action="include">oval:ssg-state_rpm_verify_hashes_fail_md5_hash:ste:1</oval-def:filter>
        </linux:rpmverifyfile_object>
        <linux:rpmverifyfile_object comment="rpm verify ownership of all files" id="oval:ssg-object_rpm_verify_ownership_files_fail_ownership:obj:1" version="2">
          <linux:behaviors noghostfiles="true" nomd5="true"/>
          <linux:name operation="pattern match">.*</linux:name>
          <linux:epoch operation="pattern match">.*</linux:epoch>
          <linux:version operation="pattern match">.*</linux:version>
          <linux:release operation="pattern match">.*</linux:release>
          <linux:arch operation="pattern match">.*</linux:arch>
          <linux:filepath operation="pattern match">.*</linux:filepath>
          <oval-def:filter action="include">oval:ssg-state_rpm_verify_ownership_files_fail_ownership:ste:1</oval-def:filter>
        </linux:rpmverifyfile_object>
        <linux:rpmverifyfile_object comment="rpm verify permissions of all files" id="oval:ssg-object_rpm_verify_permissions_files_fail_mode:obj:1" version="1">
          <linux:behaviors noghostfiles="true" nomd5="true"/>
          <linux:name operation="pattern match">.*</linux:name>
          <linux:epoch operation="pattern match">.*</linux:epoch>
          <linux:version operation="pattern match">.*</linux:version>
          <linux:release operation="pattern match">.*</linux:release>
          <linux:arch operation="pattern match">.*</linux:arch>
          <linux:filepath operation="pattern match">.*</linux:filepath>
          <oval-def:filter action="include">oval:ssg-state_rpm_verify_permissions_files_fail_mode:ste:1</oval-def:filter>
        </linux:rpmverifyfile_object>
        <unix:file_object comment="Fetch /usr/bin/sudo" id="oval:ssg-object_sudo_file:obj:1" version="1">
          <unix:filepath>/usr/bin/sudo</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object comment="Grab GID of group set in var_sudo_dedicated_group" id="oval:ssg-sudo_dedicated_group_gid:obj:1" version="1">
          <ind:filepath operation="equals">/etc/group</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-sudo_dedicated_group_regex_for_gid:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_no_authenticate_etc_sudoers:obj:1" version="1">
          <ind:filepath>/etc/sudoers</ind:filepath>
          <ind:pattern operation="pattern match">^(?!#).*[\s]+\!authenticate.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_no_authenticate_etc_sudoers_d:obj:1" version="1">
          <ind:path>/etc/sudoers.d</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^(?!#).*[\s]+\!authenticate.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_nopasswd_etc_sudoers:obj:1" version="1">
          <ind:filepath>/etc/sudoers</ind:filepath>
          <ind:pattern operation="pattern match">^(?!#).*[\s]+NOPASSWD[\s]*\:.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_nopasswd_etc_sudoers_d:obj:1" version="1">
          <ind:path>/etc/sudoers.d</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^(?!#).*[\s]+NOPASSWD[\s]*\:.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sudo_timestamp_timeout:obj:1" version="1">
          <ind:filepath operation="pattern match">^\/etc\/(sudoers|sudoers\.d\/.*)$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*Defaults[\s]+timestamp_timeout[\s]*=\s*[+]?(\d*\.\d+|\d+\.\d*|\d+)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sudo_timestamp_timeout_no_signs:obj:1" version="1">
          <ind:filepath operation="pattern match">^\/etc\/(sudoers|sudoers\.d\/.*)$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*Defaults[\s]+timestamp_timeout[\s]*=\s*[\-](\d*\.\d+|\d+\.\d*|\d+)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_sudoers_cfg_spec_all_users:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(\.d/.*)?$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*ALL\s+ALL\=\(ALL\)\s+ALL\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_sudoers_cfg_spec_all_group:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(\.d/.*)?$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*ALL\s+ALL\=\(ALL\:ALL\)\s+ALL\s*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_vdsm_nopasswd_etc_sudoers:obj:1" version="1">
          <ind:filepath>/etc/sudoers</ind:filepath>
          <ind:pattern operation="pattern match">^(?!(#|vdsm.*)).*[\s]+NOPASSWD[\s]*\:.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_vdsm_nopasswd_etc_sudoers_d:obj:1" version="1">
          <ind:path>/etc/sudoers.d</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^(?!(#|vdsm.*)).*[\s]+NOPASSWD[\s]*\:.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_sudoers_default_includedir:obj:1" version="1">
          <ind:filepath>/etc/sudoers</ind:filepath>
          <ind:pattern operation="pattern match">^#includedir[\s]+(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_sudoers_without_include:obj:1" version="1">
          <ind:filepath>/etc/sudoers</ind:filepath>
          <ind:pattern operation="pattern match">^[#@]include[\s]+.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_sudoers_without_include_new:obj:1" version="1">
          <ind:filepath>/etc/sudoers</ind:filepath>
          <ind:pattern operation="pattern match">^@includedir[\s]+.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_sudoers_without_includedir:obj:1" version="1">
          <ind:filepath>/etc/sudoers</ind:filepath>
          <ind:pattern operation="pattern match">^[#@]includedir[\s]+.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_sudoersd_without_includes:obj:1" version="1">
          <ind:path>/etc/sudoers.d/</ind:path>
          <ind:filename operation="pattern match">.*</ind:filename>
          <ind:pattern operation="pattern match">^[#@]include(?:dir)?[\s]+.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_sudoers_explicit_command_args:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(\.d/.*)?$</ind:filepath>
          <ind:pattern operation="pattern match">^(?!\s*Defaults)(?:\s*[^#=]+)=(?:\s*(?:\([^\)]+\))?\s*(?!\s*\()[^,\s]+(?:[ \t]+[^,\s]+)+[ \t]*,)*(\s*(?:\([^\)]+\))?\s*(?!\s*\()[^,\s]+[ \t]*(?:,|$))</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_sudoers_no_command_negation:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(\.d/.*)?$</ind:filepath>
          <ind:pattern operation="pattern match">^(?:\s*[^#=]+)=(?:\s*(?:\([^\)]+\))?\s*(?!\s*\()[^,!\n][^,\n]+,)*\s*(?:\([^\)]+\))?\s*(?!\s*\()(!\S+).*</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-root_or_ALL_in_runas_spec:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(\.d/.*)?$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*((?!(root|Defaults)\b)[\w]+)\s*(\w+)\s*=\s*(.*,)?\s*\([\w\s]*\b(root|ALL)\b[\w\s]*\)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_no_runas_spec:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(\.d/.*)?$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*((?!(root|Defaults)\b)[\w]+)\s*(\w+)\s*=\s*(.*,)?\s*[^\(\s]</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_test_sudoers_targetpw_config:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(\.d/.*)?$</ind:filepath>
          <ind:pattern operation="pattern match">^Defaults !targetpw$\r?\n</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_test_sudoers_rootpw_config:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(\.d/.*)?$</ind:filepath>
          <ind:pattern operation="pattern match">^Defaults !rootpw$\r?\n</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_test_sudoers_runaspw_config:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(\.d/.*)?$</ind:filepath>
          <ind:pattern operation="pattern match">^Defaults !runaspw$\r?\n</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_test_sudoers_targetpw_not_defined:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(\.d/.*)?$</ind:filepath>
          <ind:pattern operation="pattern match">^Defaults targetpw$\r?\n</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_test_sudoers_rootpw_not_defined:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(\.d/.*)?$</ind:filepath>
          <ind:pattern operation="pattern match">^Defaults rootpw$\r?\n</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_test_sudoers_runaspw_not_defined:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(\.d/.*)?$</ind:filepath>
          <ind:pattern operation="pattern match">^Defaults runaspw$\r?\n</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="clean_requirements_on_remove set in /etc/yum.conf" id="oval:ssg-object_yum_clean_components_post_updating:obj:1" version="1">
          <ind:filepath>/etc/yum.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*clean_requirements_on_remove\s*=\s*(1|True|yes)\s*$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-disable_weak_deps_obj_disable_weak_deps:obj:1" version="1">
          <ind:filepath>/etc/dnf/dnf.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\[main\].*(?:\n\s*[^[\s].*)*\n^\s*install_weak_deps[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="The configuration file /etc/dnf/dnf.conf for disable_weak_deps" id="oval:ssg-disable_weak_deps_obj_disable_weak_deps_config_file:obj:1" version="1">
          <unix:filepath operation="pattern match">^/etc/dnf/dnf.conf</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_dnf-automatic_apply_updates:obj:1" version="1">
          <ind:filepath>/etc/dnf/automatic.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\[commands\].*(?:\n\s*[^[\s].*)*\n^\s*apply_updates[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="The configuration file /etc/dnf/automatic.conf for dnf-automatic_apply_updates" id="oval:ssg-obj_dnf-automatic_apply_updates_config_file:obj:1" version="1">
          <unix:filepath operation="pattern match">^/etc/dnf/automatic.conf</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_dnf-automatic_security_updates_only:obj:1" version="1">
          <ind:filepath>/etc/dnf/automatic.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\[commands\].*(?:\n\s*[^[\s].*)*\n^\s*upgrade_type[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="The configuration file /etc/dnf/automatic.conf for dnf-automatic_security_updates_only" id="oval:ssg-obj_dnf-automatic_security_updates_only_config_file:obj:1" version="1">
          <unix:filepath operation="pattern match">^/etc/dnf/automatic.conf</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_enable_gpgcheck_for_all_repositories:obj:1" version="1">
          <ind:path>/etc/yum.repos.d</ind:path>
          <ind:filename operation="pattern match">^.*\.repo$</ind:filename>
          <ind:pattern operation="pattern match">^\s*\[[^]]+\]\s*\n(?:[^[]*\n)*</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:rpminfo_object id="oval:ssg-object_almalinux_package_gpg-pubkey:obj:1" version="1">
          <linux:name>gpg-pubkey</linux:name>
        </linux:rpminfo_object>
        <ind:textfilecontent54_object id="oval:ssg-object_epel_section_headers:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/yum\.repos\.d/.*\.repo$</ind:filepath>
          <ind:pattern operation="pattern match">(?i)^\s*\[[^\]]*epel[^\]]*\]</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_epel_repos_check_disabled:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/yum\.repos\.d/.*\.repo$</ind:filepath>
          <ind:pattern operation="pattern match">(?i)(?:^\s*\[[^\]]*epel[^\]]*\][\s\S]*?)^\s*enabled\s*=\s*(\S+)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gpgcheck set in /etc/yum.conf" id="oval:ssg-object_ensure_gpgcheck_globally_activated:obj:1" version="1">
          <ind:filepath>/etc/yum.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*gpgcheck\s*=\s*(1|True|yes)\s*$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="localpkg_gpgcheck set in /etc/yum.conf" id="oval:ssg-object_yum_ensure_gpgcheck_local_packages:obj:1" version="1">
          <ind:filepath>/etc/yum.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*localpkg_gpgcheck\s*=\s*(1|True|yes)\s*$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_ensure_gpgcheck_never_disabled:obj:1" version="1">
          <ind:path>/etc/yum.repos.d</ind:path>
          <ind:filename operation="pattern match">.*</ind:filename>
          <ind:pattern operation="pattern match">^\s*gpgcheck\s*=\s*0\s*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="repo_gpgcheck set in /etc/yum.conf" id="oval:ssg-object_yum_ensure_gpgcheck_repo_metadata:obj:1" version="1">
          <ind:filepath>/etc/yum.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*repo_gpgcheck\s*=\s*(1|True|yes)\s*$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_password_pam_pwquality_dcredit:obj:1" version="3">
          <ind:filepath operation="pattern match">^/etc/security/pwquality.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*dcredit[\s]*=[\s]*(-?\d+)(?:[\s]|$)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_password_pam_pwquality_dictcheck:obj:1" version="3">
          <ind:filepath operation="pattern match">^/etc/security/pwquality.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*dictcheck[\s]*=[\s]*(-?\d+)(?:[\s]|$)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_password_pam_pwquality_difok:obj:1" version="3">
          <ind:filepath operation="pattern match">^/etc/security/pwquality.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*difok[\s]*=[\s]*(-?\d+)(?:[\s]|$)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_accounts_password_pam_enforce_local:obj:1" version="1">
          <ind:filepath>/etc/security/pwquality.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*local_users_only[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_password_pam_pwquality_lcredit:obj:1" version="3">
          <ind:filepath operation="pattern match">^/etc/security/pwquality.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*lcredit[\s]*=[\s]*(-?\d+)(?:[\s]|$)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_password_pam_pwquality_maxclassrepeat:obj:1" version="3">
          <ind:filepath operation="pattern match">^/etc/security/pwquality.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*maxclassrepeat[\s]*=[\s]*(-?\d+)(?:[\s]|$)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_password_pam_pwquality_maxrepeat:obj:1" version="3">
          <ind:filepath operation="pattern match">^/etc/security/pwquality.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*maxrepeat[\s]*=[\s]*(-?\d+)(?:[\s]|$)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_password_pam_pwquality_maxsequence:obj:1" version="3">
          <ind:filepath operation="pattern match">^/etc/security/pwquality.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*maxsequence[\s]*=[\s]*(-?\d+)(?:[\s]|$)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_password_pam_pwquality_minclass:obj:1" version="3">
          <ind:filepath operation="pattern match">^/etc/security/pwquality.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*minclass[\s]*=[\s]*(-?\d+)(?:[\s]|$)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_password_pam_pwquality_minlen:obj:1" version="3">
          <ind:filepath operation="pattern match">^/etc/security/pwquality.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*minlen[\s]*=[\s]*(-?\d+)(?:[\s]|$)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_password_pam_pwquality_ocredit:obj:1" version="3">
          <ind:filepath operation="pattern match">^/etc/security/pwquality.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*ocredit[\s]*=[\s]*(-?\d+)(?:[\s]|$)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_accounts_password_pam_pwhistory_enforce_for_root:obj:1" version="1">
          <ind:filepath>/etc/security/pwhistory.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*enforce_for_root[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_password_pam_pwquality_ucredit:obj:1" version="3">
          <ind:filepath operation="pattern match">^/etc/security/pwquality.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^\s*ucredit[\s]*=[\s]*(-?\d+)(?:[\s]|$)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the second and subsequent occurrences of pam_unix.so in auth section of system-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_system_pam_unix_auth:obj:1" version="2">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_unix_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in auth section of common-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_system_pam_faillock_auth:obj:1" version="2">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_auth_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the second and subsequent occurrences of pam_unix.so in auth section of password-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_password_pam_unix_auth:obj:1" version="2">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_unix_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in auth section of common-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_password_pam_faillock_auth:obj:1" version="2">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_auth_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in account section of system-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_system_pam_faillock_account:obj:1" version="2">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_account_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in account section of password-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_password_pam_faillock_account:obj:1" version="2">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_account_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so deny parameter from system-auth file" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_pamd_system:obj:1" version="2">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_deny_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so deny parameter from password-auth file" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_pamd_password:obj:1" version="2">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_deny_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check the expected pam_faillock.so deny parameter in /etc/security/faillock.conf" id="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_faillock_conf:obj:1" version="1">
          <ind:filepath>/etc/security/faillock.conf</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_faillock_conf_deny_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the second and subsequent occurrences of pam_unix.so in auth section of system-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_system_pam_unix_auth:obj:1" version="2">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_unix_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in auth section of common-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_system_pam_faillock_auth:obj:1" version="2">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_auth_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the second and subsequent occurrences of pam_unix.so in auth section of password-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_password_pam_unix_auth:obj:1" version="2">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_unix_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in auth section of common-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_password_pam_faillock_auth:obj:1" version="2">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_auth_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in account section of system-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_system_pam_faillock_account:obj:1" version="2">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_account_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in account section of password-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_password_pam_faillock_account:obj:1" version="2">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_account_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so fail_interval parameter from system-auth file" id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_system:obj:1" version="2">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_fail_interval_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so fail_interval parameter from password-auth file" id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_password:obj:1" version="2">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_fail_interval_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check the expected pam_faillock.so fail_interval parameter in /etc/security/faillock.conf" id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_faillock_conf:obj:1" version="1">
          <ind:filepath>/etc/security/faillock.conf</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_faillock_conf_fail_interval_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the second and subsequent occurrences of pam_unix.so in auth section of system-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_system_pam_unix_auth:obj:1" version="2">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_unix_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in auth section of common-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_system_pam_faillock_auth:obj:1" version="2">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_auth_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the second and subsequent occurrences of pam_unix.so in auth section of password-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_password_pam_unix_auth:obj:1" version="2">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_unix_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in auth section of common-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_password_pam_faillock_auth:obj:1" version="2">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_auth_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in account section of system-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_system_pam_faillock_account:obj:1" version="2">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_account_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check common definition of pam_faillock.so in account section of password-auth" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_password_pam_faillock_account:obj:1" version="2">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_account_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so unlock_time parameter from system-auth file" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_system:obj:1" version="2">
          <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_unlock_time_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Get the pam_faillock.so unlock_time parameter from password-auth file" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_password:obj:1" version="2">
          <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_unlock_time_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check the expected pam_faillock.so unlock_time parameter in /etc/security/faillock.conf" id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_faillock_conf:obj:1" version="1">
          <ind:filepath>/etc/security/faillock.conf</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_faillock_conf_unlock_time_parameter_regex:var:1"/>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-audit_access_failed_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_3_access_failed_rules:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath>/etc/audit/rules.d/30-ospp-v42-3-access-failed.rules</ind:filepath>
          <ind:pattern operation="pattern match">^.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-audit_access_success_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_3_access_success_rules:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath>/etc/audit/rules.d/30-ospp-v42-3-access-success.rules</ind:filepath>
          <ind:pattern operation="pattern match">^.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-audit_basic_configuration_object_whole_file_contents_tc_audit_rules_d_10_base_config_rules:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath>/etc/audit/rules.d/10-base-config.rules</ind:filepath>
          <ind:pattern operation="pattern match">^.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-audit_create_failed_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_1_create_failed_rules:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath>/etc/audit/rules.d/30-ospp-v42-1-create-failed.rules</ind:filepath>
          <ind:pattern operation="pattern match">^.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-audit_create_success_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_1_create_success_rules:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath>/etc/audit/rules.d/30-ospp-v42-1-create-success.rules</ind:filepath>
          <ind:pattern operation="pattern match">^.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-audit_delete_failed_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_failed_rules:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath>/etc/audit/rules.d/30-ospp-v42-4-delete-failed.rules</ind:filepath>
          <ind:pattern operation="pattern match">^.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-audit_delete_success_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_success_rules:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath>/etc/audit/rules.d/30-ospp-v42-4-delete-success.rules</ind:filepath>
          <ind:pattern operation="pattern match">^.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-audit_immutable_login_uids_object_whole_file_contents_tc_audit_rules_d_11_loginuid_rules:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath>/etc/audit/rules.d/11-loginuid.rules</ind:filepath>
          <ind:pattern operation="pattern match">^.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-audit_modify_failed_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_2_modify_failed_rules:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath>/etc/audit/rules.d/30-ospp-v42-2-modify-failed.rules</ind:filepath>
          <ind:pattern operation="pattern match">^.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-audit_modify_success_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_2_modify_success_rules:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath>/etc/audit/rules.d/30-ospp-v42-2-modify-success.rules</ind:filepath>
          <ind:pattern operation="pattern match">^.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-audit_module_load_object_whole_file_contents_tc_audit_rules_d_43_module_load_rules:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath>/etc/audit/rules.d/43-module-load.rules</ind:filepath>
          <ind:pattern operation="pattern match">^.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-audit_ospp_general_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_rules:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath>/etc/audit/rules.d/30-ospp-v42.rules</ind:filepath>
          <ind:pattern operation="pattern match">^.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-audit_owner_change_failed_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_6_owner_change_failed_rules:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath>/etc/audit/rules.d/30-ospp-v42-6-owner-change-failed.rules</ind:filepath>
          <ind:pattern operation="pattern match">^.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-audit_owner_change_success_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_6_owner_change_success_rules:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath>/etc/audit/rules.d/30-ospp-v42-6-owner-change-success.rules</ind:filepath>
          <ind:pattern operation="pattern match">^.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-audit_perm_change_failed_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_5_perm_change_failed_rules:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath>/etc/audit/rules.d/30-ospp-v42-5-perm-change-failed.rules</ind:filepath>
          <ind:pattern operation="pattern match">^.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-audit_perm_change_success_object_whole_file_contents_tc_audit_rules_d_30_ospp_v42_5_perm_change_success_rules:obj:1" version="1">
          <ind:behaviors multiline="false" singleline="true"/>
          <ind:filepath>/etc/audit/rules.d/30-ospp-v42-5-perm-change-success.rules</ind:filepath>
          <ind:pattern operation="pattern match">^.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_privileged_commands_init_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/init[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_privileged_commands_init_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/init[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_privileged_commands_poweroff_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/poweroff[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_privileged_commands_poweroff_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/poweroff[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_privileged_commands_reboot_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/reboot[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_privileged_commands_reboot_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/reboot[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_privileged_commands_shutdown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/shutdown[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_privileged_commands_shutdown_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/shutdown[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_chmod_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+chmod[\s]+|([\s]+|[,])chmod([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_chmod_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+chmod[\s]+|([\s]+|[,])chmod([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_chmod_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+chmod[\s]+|([\s]+|[,])chmod([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_chmod_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+chmod[\s]+|([\s]+|[,])chmod([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_chown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+chown[\s]+|([\s]+|[,])chown([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_chown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+chown[\s]+|([\s]+|[,])chown([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_chown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+chown[\s]+|([\s]+|[,])chown([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_chown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+chown[\s]+|([\s]+|[,])chown([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_fchmod_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fchmod[\s]+|([\s]+|[,])fchmod([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_fchmod_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fchmod[\s]+|([\s]+|[,])fchmod([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_fchmod_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fchmod[\s]+|([\s]+|[,])fchmod([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_fchmod_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fchmod[\s]+|([\s]+|[,])fchmod([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_fchmodat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fchmodat[\s]+|([\s]+|[,])fchmodat([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_fchmodat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fchmodat[\s]+|([\s]+|[,])fchmodat([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_fchmodat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fchmodat[\s]+|([\s]+|[,])fchmodat([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_fchmodat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fchmodat[\s]+|([\s]+|[,])fchmodat([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_fchown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fchown[\s]+|([\s]+|[,])fchown([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_fchown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fchown[\s]+|([\s]+|[,])fchown([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_fchown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fchown[\s]+|([\s]+|[,])fchown([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_fchown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fchown[\s]+|([\s]+|[,])fchown([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_fchownat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fchownat[\s]+|([\s]+|[,])fchownat([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_fchownat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fchownat[\s]+|([\s]+|[,])fchownat([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_fchownat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fchownat[\s]+|([\s]+|[,])fchownat([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_fchownat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fchownat[\s]+|([\s]+|[,])fchownat([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_fremovexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fremovexattr[\s]+|([\s]+|[,])fremovexattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_fremovexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fremovexattr[\s]+|([\s]+|[,])fremovexattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_fremovexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fremovexattr[\s]+|([\s]+|[,])fremovexattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_fremovexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fremovexattr[\s]+|([\s]+|[,])fremovexattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_fsetxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fsetxattr[\s]+|([\s]+|[,])fsetxattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_fsetxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fsetxattr[\s]+|([\s]+|[,])fsetxattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_fsetxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fsetxattr[\s]+|([\s]+|[,])fsetxattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_fsetxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fsetxattr[\s]+|([\s]+|[,])fsetxattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_lchown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+lchown[\s]+|([\s]+|[,])lchown([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_lchown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+lchown[\s]+|([\s]+|[,])lchown([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_lchown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+lchown[\s]+|([\s]+|[,])lchown([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_lchown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+lchown[\s]+|([\s]+|[,])lchown([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_lremovexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+lremovexattr[\s]+|([\s]+|[,])lremovexattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_lremovexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+lremovexattr[\s]+|([\s]+|[,])lremovexattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_lremovexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+lremovexattr[\s]+|([\s]+|[,])lremovexattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_lremovexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+lremovexattr[\s]+|([\s]+|[,])lremovexattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_lsetxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+lsetxattr[\s]+|([\s]+|[,])lsetxattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_lsetxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+lsetxattr[\s]+|([\s]+|[,])lsetxattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_lsetxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+lsetxattr[\s]+|([\s]+|[,])lsetxattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_lsetxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+lsetxattr[\s]+|([\s]+|[,])lsetxattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_removexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+removexattr[\s]+|([\s]+|[,])removexattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_removexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+removexattr[\s]+|([\s]+|[,])removexattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_removexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+removexattr[\s]+|([\s]+|[,])removexattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_removexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+removexattr[\s]+|([\s]+|[,])removexattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_setxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+setxattr[\s]+|([\s]+|[,])setxattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_setxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+setxattr[\s]+|([\s]+|[,])setxattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_setxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+setxattr[\s]+|([\s]+|[,])setxattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_setxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+setxattr[\s]+|([\s]+|[,])setxattr([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_umount2_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+umount2[\s]+|([\s]+|[,])umount2([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_umount2_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+umount2[\s]+|([\s]+|[,])umount2([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_umount2_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+umount2[\s]+|([\s]+|[,])umount2([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_umount2_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+umount2[\s]+|([\s]+|[,])umount2([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_etc_cron_d_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_etc_cron_d_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_etc_cron_d_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_etc_cron_d_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_group_open_32bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_open_write_tc_group_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_group_open_64bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_open_write_tc_group_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_group_open_32bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_open_write_tc_group_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_group_open_64bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_open_write_tc_group_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_group_open_by_handle_at_32bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_open_by_handle_at_write_tc_group_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_group_open_by_handle_at_64bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_open_by_handle_at_write_tc_group_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_group_open_by_handle_at_32bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_open_by_handle_at_write_tc_group_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_group_open_by_handle_at_64bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_open_by_handle_at_write_tc_group_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_group_openat_32bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_openat_write_tc_group_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_group_openat_64bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_openat_write_tc_group_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_group_openat_32bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_openat_write_tc_group_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_group_openat_64bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_openat_write_tc_group_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_gshadow_open_32bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_open_write_tc_gshadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_gshadow_open_64bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_open_write_tc_gshadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_gshadow_open_32bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_open_write_tc_gshadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_gshadow_open_64bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_open_write_tc_gshadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_gshadow_open_by_handle_at_32bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_open_by_handle_at_write_tc_gshadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_gshadow_open_by_handle_at_64bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_open_by_handle_at_write_tc_gshadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_gshadow_open_by_handle_at_32bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_open_by_handle_at_write_tc_gshadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_gshadow_open_by_handle_at_64bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_open_by_handle_at_write_tc_gshadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_gshadow_openat_32bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_openat_write_tc_gshadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_gshadow_openat_64bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_openat_write_tc_gshadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_gshadow_openat_32bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_openat_write_tc_gshadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_gshadow_openat_64bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_openat_write_tc_gshadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_passwd_open_32bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_open_write_tc_passwd_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_passwd_open_64bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_open_write_tc_passwd_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_passwd_open_32bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_open_write_tc_passwd_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_passwd_open_64bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_open_write_tc_passwd_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_passwd_open_by_handle_at_32bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_open_by_handle_at_write_tc_passwd_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_passwd_open_by_handle_at_64bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_open_by_handle_at_write_tc_passwd_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_passwd_open_by_handle_at_32bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_open_by_handle_at_write_tc_passwd_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_passwd_open_by_handle_at_64bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_open_by_handle_at_write_tc_passwd_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_passwd_openat_32bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_openat_write_tc_passwd_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_passwd_openat_64bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_openat_write_tc_passwd_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_passwd_openat_32bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_openat_write_tc_passwd_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_passwd_openat_64bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_openat_write_tc_passwd_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_shadow_open_32bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_open_write_tc_shadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_shadow_open_64bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_open_write_tc_shadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_shadow_open_32bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_open_write_tc_shadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_shadow_open_64bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_open_write_tc_shadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_shadow_open_by_handle_at_32bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_open_by_handle_at_write_tc_shadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_shadow_open_by_handle_at_64bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_open_by_handle_at_write_tc_shadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_shadow_open_by_handle_at_32bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_open_by_handle_at_write_tc_shadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_shadow_open_by_handle_at_64bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_open_by_handle_at_write_tc_shadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_shadow_openat_32bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_openat_write_tc_shadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_shadow_openat_64bit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_openat_write_tc_shadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_shadow_openat_32bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_32bit_openat_write_tc_shadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_tc_shadow_openat_64bit_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_64bit_openat_write_tc_shadow_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_execution_chacl_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/chacl[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_execution_chacl_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/chacl[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_execution_chcon_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/chcon[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_execution_chcon_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/chcon[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_execution_restorecon_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/restorecon[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_execution_restorecon_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/restorecon[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_execution_semanage_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/semanage[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_execution_semanage_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/semanage[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_execution_setfacl_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/setfacl[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_execution_setfacl_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/setfacl[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_execution_setfiles_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/setfiles[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_execution_setfiles_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/setfiles[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_execution_setsebool_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/setsebool[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_execution_setsebool_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/setsebool[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_execution_seunshare_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/seunshare[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_execution_seunshare_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/seunshare[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_rename_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+rename[\s]+|([\s]+|[,])rename([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_rename_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+rename[\s]+|([\s]+|[,])rename([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_rename_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+rename[\s]+|([\s]+|[,])rename([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_rename_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+rename[\s]+|([\s]+|[,])rename([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_renameat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+renameat[\s]+|([\s]+|[,])renameat([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_renameat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+renameat[\s]+|([\s]+|[,])renameat([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_renameat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+renameat[\s]+|([\s]+|[,])renameat([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_renameat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+renameat[\s]+|([\s]+|[,])renameat([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_renameat2_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+renameat2[\s]+|([\s]+|[,])renameat2([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_renameat2_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+renameat2[\s]+|([\s]+|[,])renameat2([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_renameat2_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+renameat2[\s]+|([\s]+|[,])renameat2([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_renameat2_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+renameat2[\s]+|([\s]+|[,])renameat2([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_rmdir_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+rmdir[\s]+|([\s]+|[,])rmdir([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_rmdir_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+rmdir[\s]+|([\s]+|[,])rmdir([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_rmdir_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+rmdir[\s]+|([\s]+|[,])rmdir([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_rmdir_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+rmdir[\s]+|([\s]+|[,])rmdir([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_unlink_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+unlink[\s]+|([\s]+|[,])unlink([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_unlink_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+unlink[\s]+|([\s]+|[,])unlink([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_unlink_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+unlink[\s]+|([\s]+|[,])unlink([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_unlink_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+unlink[\s]+|([\s]+|[,])unlink([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_unlinkat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+unlinkat[\s]+|([\s]+|[,])unlinkat([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_unlinkat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+unlinkat[\s]+|([\s]+|[,])unlinkat([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_unlinkat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+unlinkat[\s]+|([\s]+|[,])unlinkat([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_unlinkat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+unlinkat[\s]+|([\s]+|[,])unlinkat([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arkml_create_module_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+create_module[\s]+|([\s]+|[,])create_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arkml_create_module_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+create_module[\s]+|([\s]+|[,])create_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arkml_create_module_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+create_module[\s]+|([\s]+|[,])create_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arkml_create_module_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+create_module[\s]+|([\s]+|[,])create_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arkml_delete_module_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+delete_module[\s]+|([\s]+|[,])delete_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arkml_delete_module_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+delete_module[\s]+|([\s]+|[,])delete_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arkml_delete_module_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+delete_module[\s]+|([\s]+|[,])delete_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arkml_delete_module_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+delete_module[\s]+|([\s]+|[,])delete_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arkml_finit_module_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+finit_module[\s]+|([\s]+|[,])finit_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arkml_finit_module_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+finit_module[\s]+|([\s]+|[,])finit_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arkml_finit_module_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+finit_module[\s]+|([\s]+|[,])finit_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arkml_finit_module_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+finit_module[\s]+|([\s]+|[,])finit_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arkml_init_module_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+init_module[\s]+|([\s]+|[,])init_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arkml_init_module_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+init_module[\s]+|([\s]+|[,])init_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arkml_init_module_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+init_module[\s]+|([\s]+|[,])init_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arkml_init_module_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+init_module[\s]+|([\s]+|[,])init_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arkml_query_module_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+query_module[\s]+|([\s]+|[,])query_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arkml_query_module_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+query_module[\s]+|([\s]+|[,])query_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arkml_query_module_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+query_module[\s]+|([\s]+|[,])query_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arkml_query_module_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+query_module[\s]+|([\s]+|[,])query_module([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_login_events_faillock_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_login_events_faillock_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_login_events_faillock_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_login_events_faillock_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_login_events_lastlog_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_login_events_lastlog_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_login_events_lastlog_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_login_events_lastlog_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_login_events_tallylog_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_login_events_tallylog_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_login_events_tallylog_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_login_events_tallylog_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_mac_modification_usr_share_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_mac_modification_usr_share_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_mac_modification_usr_share_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_mac_modification_usr_share_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_mount_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+mount[\s]+|([\s]+|[,])mount([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_mount_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+mount[\s]+|([\s]+|[,])mount([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_ardm_mount_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+mount[\s]+|([\s]+|[,])mount([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_ardm_mount_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+mount[\s]+|([\s]+|[,])mount([\s]+|[,])))(?:.*-F\s+auid&gt;=1000[\s]+)(?:.*-F\s+auid!=(?:4294967295|unset)[\s]+).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_networkconfig_modification_network_scripts_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_networkconfig_modification_network_scripts_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_networkconfig_modification_network_scripts_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_networkconfig_modification_network_scripts_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_at_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/at[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_at_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/at[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_chage_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/chage[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_chage_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/chage[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_chsh_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/chsh[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_chsh_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/chsh[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_crontab_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/crontab[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_crontab_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/crontab[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_gpasswd_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/gpasswd[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_gpasswd_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/gpasswd[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_kmod_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/kmod[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_kmod_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/kmod[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_mount_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/mount[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_mount_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/mount[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_newgidmap_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/newgidmap[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_newgidmap_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/newgidmap[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_newgrp_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/newgrp[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_newgrp_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/newgrp[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_newuidmap_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/newuidmap[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_newuidmap_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/newuidmap[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_pam_timestamp_check_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/pam_timestamp_check[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_pam_timestamp_check_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/pam_timestamp_check[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_passwd_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/passwd[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_passwd_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/passwd[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_postdrop_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/postdrop[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_postdrop_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/postdrop[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_postqueue_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/postqueue[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_postqueue_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/postqueue[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_pt_chown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/libexec\/pt_chown[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_pt_chown_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/libexec\/pt_chown[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_ssh_agent_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/ssh-agent[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_ssh_agent_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/ssh-agent[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_ssh_keysign_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/libexec\/openssh\/ssh-keysign[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_ssh_keysign_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/libexec\/openssh\/ssh-keysign[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_su_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/su[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_su_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/su[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_sudo_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/sudo[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_sudo_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/sudo[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_sudoedit_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/sudoedit[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_sudoedit_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/sudoedit[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_umount_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/umount[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_umount_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/bin\/umount[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_unix_chkpwd_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/unix_chkpwd[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_unix_chkpwd_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/unix_chkpwd[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_unix_update_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/unix_update[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_unix_update_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/unix_update[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_userhelper_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/userhelper[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_userhelper_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/userhelper[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_usermod_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/usermod[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_usermod_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/usermod[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_usernetctl_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/usernetctl[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_privileged_commands_usernetctl_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+-F[\s]+path=\/usr\/sbin\/usernetctl[\s]+-F[\s]+auid&gt;=1000[\s]+-F[\s]+auid!=(?:4294967295|unset|-1)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_session_events_btmp_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_session_events_btmp_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_session_events_btmp_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_session_events_btmp_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_session_events_utmp_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_session_events_utmp_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_session_events_utmp_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_session_events_utmp_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_session_events_wtmp_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_session_events_wtmp_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_session_events_wtmp_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_session_events_wtmp_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_sudoers_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_sudoers_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_sudoers_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_sudoers_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_sudoers_d_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_sudoers_d_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_sudoers_d_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_sudoers_d_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_time_watch_localtime_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_time_watch_localtime_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_time_watch_localtime_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_time_watch_localtime_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_chmod_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_chmod_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_chmod_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_chmod_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_chmod_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_chmod_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_chmod_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_chmod_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_chmod_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_chmod_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_chmod_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_chmod_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_chmod_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_chmod_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_chmod_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_chmod_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_chown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_chown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_chown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_chown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_chown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_chown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_chown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_chown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_chown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_chown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_chown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_chown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_chown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_chown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_chown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_chown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_creat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_creat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_creat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_creat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_creat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_creat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_creat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_creat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_creat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_creat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_creat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_creat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_creat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_creat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_creat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_creat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_fchmod_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_fchmod_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_fchmod_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_fchmod_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_fchmod_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_fchmod_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_fchmod_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_fchmod_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_fchmod_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_fchmod_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_fchmod_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_fchmod_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_fchmod_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_fchmod_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_fchmod_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_fchmod_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_fchmodat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_fchmodat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_fchmodat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_fchmodat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_fchmodat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_fchmodat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_fchmodat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_fchmodat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_fchmodat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_fchmodat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_fchmodat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_fchmodat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_fchmodat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_fchmodat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_fchmodat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_fchmodat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_fchown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_fchown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_fchown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_fchown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_fchown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_fchown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_fchown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_fchown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_fchown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_fchown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_fchown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_fchown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_fchown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_fchown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_fchown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_fchown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_fchownat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_fchownat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_fchownat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_fchownat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_fchownat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_fchownat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_fchownat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_fchownat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_fchownat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_fchownat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_fchownat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_fchownat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_fchownat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_fchownat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_fchownat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_fchownat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_fremovexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_fremovexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_fremovexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_fremovexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_fremovexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_fremovexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_fremovexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_fremovexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_fremovexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_fremovexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_fremovexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_fremovexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_fremovexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_fremovexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_fremovexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_fremovexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_fsetxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_fsetxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_fsetxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_fsetxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_fsetxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_fsetxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_fsetxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_fsetxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_fsetxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_fsetxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_fsetxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_fsetxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_fsetxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_fsetxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_fsetxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_fsetxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_ftruncate_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_ftruncate_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_ftruncate_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_ftruncate_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_ftruncate_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_ftruncate_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_ftruncate_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_ftruncate_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_ftruncate_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_ftruncate_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_ftruncate_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_ftruncate_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_ftruncate_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_ftruncate_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_ftruncate_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_ftruncate_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_lchown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_lchown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_lchown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_lchown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_lchown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_lchown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_lchown_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_lchown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_lchown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_lchown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_lchown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_lchown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_lchown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_lchown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_lchown_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_lchown_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_lremovexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_lremovexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_lremovexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_lremovexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_lremovexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_lremovexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_lremovexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_lremovexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_lremovexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_lremovexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_lremovexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_lremovexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_lremovexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_lremovexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_lremovexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_lremovexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_lsetxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_lsetxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_lsetxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_lsetxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_lsetxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_lsetxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_lsetxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_lsetxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_lsetxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_lsetxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_lsetxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_lsetxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_lsetxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_lsetxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_lsetxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_lsetxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_open_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_open_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_open_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_open_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_open_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_open_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_open_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_open_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_open_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_open_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_open_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_open_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_open_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_open_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_open_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_open_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_open_by_handle_at_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_open_by_handle_at_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_open_by_handle_at_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_open_by_handle_at_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_open_by_handle_at_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_open_by_handle_at_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_open_by_handle_at_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_open_by_handle_at_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_open_by_handle_at_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_open_by_handle_at_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_open_by_handle_at_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_open_by_handle_at_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_open_by_handle_at_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_open_by_handle_at_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_open_by_handle_at_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_open_by_handle_at_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_o_creat_32bit_a20100_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_32bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_o_creat_32bit_a20100_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_32bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_o_creat_64bit_a20100_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_64bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_o_creat_64bit_a20100_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_64bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_o_creat_32bit_a20100_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_32bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_o_creat_32bit_a20100_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_32bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_o_creat_64bit_a20100_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_64bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_o_creat_64bit_a20100_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_64bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_o_trunc_32bit_a201003_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_32bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_o_trunc_32bit_a201003_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_32bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_o_trunc_64bit_a201003_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_64bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_o_trunc_64bit_a201003_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_64bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_o_trunc_32bit_a201003_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_32bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_o_trunc_32bit_a201003_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_32bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_o_trunc_64bit_a201003_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_64bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_o_trunc_64bit_a201003_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_64bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a20100_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a201003_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_32bit_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_32bit_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_32bit_open_by_handle_at_eacces_augenrules_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a20100_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a201003_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_32bit_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_32bit_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_32bit_open_by_handle_at_eperm_augenrules_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a20100_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a201003_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_64bit_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_64bit_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_64bit_open_by_handle_at_eacces_augenrules_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a20100_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a201003_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_64bit_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_64bit_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_64bit_open_by_handle_at_eperm_augenrules_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a20100_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a201003_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_32bit_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_32bit_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_32bit_open_by_handle_at_auditctl_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a20100_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a201003_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_32bit_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_32bit_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_32bit_open_by_handle_at_auditctl_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a20100_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a201003_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_64bit_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_64bit_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_open_by_handle_at_order_64bit_auditctl_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a20100_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a201003_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_64bit_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_by_handle_at_order_64bit_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_64bit_open_by_handle_at_auditctl_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_o_creat_32bit_a20100_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_o_creat_32bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_o_creat_32bit_a20100_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_o_creat_32bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_o_creat_64bit_a20100_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_o_creat_64bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_o_creat_64bit_a20100_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_o_creat_64bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_o_creat_32bit_a20100_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_o_creat_32bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_o_creat_32bit_a20100_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_o_creat_32bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_o_creat_64bit_a20100_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_o_creat_64bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_o_creat_64bit_a20100_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_o_creat_64bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_o_trunc_32bit_a201003_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_o_trunc_32bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_o_trunc_32bit_a201003_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_o_trunc_32bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_o_trunc_64bit_a201003_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_o_trunc_64bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_o_trunc_64bit_a201003_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_o_trunc_64bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_o_trunc_32bit_a201003_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_o_trunc_32bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_o_trunc_32bit_a201003_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_o_trunc_32bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_o_trunc_64bit_a201003_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_o_trunc_64bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_o_trunc_64bit_a201003_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_o_trunc_64bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_32bit_a20100_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_32bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_32bit_a201003_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_32bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_nofilter_32bit_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_32bit_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_32bit_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_32bit_open_eacces_augenrules_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_32bit_a20100_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_32bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_32bit_a201003_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_32bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_nofilter_32bit_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_32bit_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_32bit_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_32bit_open_eperm_augenrules_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_64bit_a20100_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_64bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_64bit_a201003_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_64bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_nofilter_64bit_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_64bit_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_64bit_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_64bit_open_eacces_augenrules_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_64bit_a20100_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_64bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_64bit_a201003_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_64bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_nofilter_64bit_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_64bit_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_64bit_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_64bit_open_eperm_augenrules_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_32bit_a20100_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_32bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_32bit_a201003_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_32bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_nofilter_32bit_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_32bit_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_32bit_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_32bit_open_auditctl_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_32bit_a20100_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_32bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_32bit_a201003_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_32bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_nofilter_32bit_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_32bit_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_32bit_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_32bit_open_auditctl_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_64bit_a20100_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_64bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_64bit_a201003_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_64bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_nofilter_64bit_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_64bit_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_64bit_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_open_order_64bit_auditctl_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_64bit_a20100_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_64bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_64bit_a201003_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_64bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_nofilter_64bit_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_open_order_64bit_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_open_order_64bit_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_64bit_open_auditctl_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_openat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_openat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_openat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_openat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_openat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_openat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_openat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_openat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_openat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_openat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_openat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_openat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_openat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_openat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_openat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_openat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_o_creat_32bit_a20100_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_o_creat_32bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_o_creat_32bit_a20100_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_o_creat_32bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_o_creat_64bit_a20100_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_o_creat_64bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_o_creat_64bit_a20100_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_o_creat_64bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_o_creat_32bit_a20100_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_o_creat_32bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_o_creat_32bit_a20100_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_o_creat_32bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_o_creat_64bit_a20100_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_o_creat_64bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_o_creat_64bit_a20100_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_o_creat_64bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_o_trunc_32bit_a201003_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_o_trunc_32bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_o_trunc_32bit_a201003_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_o_trunc_32bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_o_trunc_64bit_a201003_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_o_trunc_64bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_o_trunc_64bit_a201003_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_o_trunc_64bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_o_trunc_32bit_a201003_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_o_trunc_32bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_o_trunc_32bit_a201003_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_o_trunc_32bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_o_trunc_64bit_a201003_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_o_trunc_64bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_o_trunc_64bit_a201003_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_o_trunc_64bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_32bit_a20100_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_32bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_32bit_a201003_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_32bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_nofilter_32bit_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_32bit_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_32bit_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_32bit_openat_eacces_augenrules_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_32bit_a20100_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_32bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_32bit_a201003_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_32bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_nofilter_32bit_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_32bit_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_32bit_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_32bit_openat_eperm_augenrules_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_64bit_a20100_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_64bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_64bit_a201003_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_64bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_nofilter_64bit_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_64bit_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_64bit_eacces_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_64bit_openat_eacces_augenrules_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_64bit_a20100_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_64bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_64bit_a201003_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_64bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_nofilter_64bit_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_64bit_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_64bit_eperm_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_64bit_openat_eperm_augenrules_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_32bit_a20100_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_32bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_32bit_a201003_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_32bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_nofilter_32bit_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_32bit_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_32bit_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_32bit_openat_auditctl_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_32bit_a20100_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_32bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_32bit_a201003_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_32bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_nofilter_32bit_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_32bit_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_32bit_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_32bit_openat_auditctl_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_64bit_a20100_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_64bit_a20100_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_64bit_a201003_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_64bit_a201003_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_nofilter_64bit_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_64bit_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_64bit_eacces_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_openat_order_64bit_auditctl_eacces_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_64bit_a20100_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_64bit_a20100_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_64bit_a201003_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_64bit_a201003_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_nofilter_64bit_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_audit_rule_openat_order_64bit_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_arufm_openat_order_64bit_eperm_auditctl:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_arufm_rule_order_64bit_openat_auditctl_eperm_regex:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_removexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_removexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_removexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_removexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_removexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_removexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_removexattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_removexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_removexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_removexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_removexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_removexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_removexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_removexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_removexattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_removexattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_rename_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_rename_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_rename_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_rename_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_rename_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_rename_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_rename_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_rename_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_rename_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_rename_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_rename_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_rename_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_rename_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_rename_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_rename_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_rename_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_renameat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_renameat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_renameat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_renameat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_renameat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_renameat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_renameat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_renameat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_renameat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_renameat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_renameat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_renameat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_renameat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_renameat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_renameat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_renameat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_setxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_setxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_setxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_setxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_setxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_setxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_setxattr_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_setxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_setxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_setxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_setxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_setxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_setxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_setxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_setxattr_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_setxattr_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_truncate_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_truncate_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_truncate_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_truncate_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_truncate_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_truncate_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_truncate_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_truncate_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_truncate_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_truncate_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_truncate_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_truncate_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_truncate_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_truncate_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_truncate_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_truncate_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_unlink_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_unlink_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_unlink_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_unlink_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_unlink_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_unlink_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_unlink_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_unlink_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_unlink_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_unlink_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_unlink_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_unlink_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_unlink_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_unlink_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_unlink_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_unlink_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_unlinkat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_unlinkat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_unlinkat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_unlinkat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_unlinkat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_unlinkat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_unlinkat_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_unlinkat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eacces_unlinkat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eacces_unlinkat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_arufm_eperm_unlinkat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_32bit_arufm_eperm_unlinkat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eacces_unlinkat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eacces_unlinkat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_arufm_eperm_unlinkat_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-var_64bit_arufm_eperm_unlinkat_regex:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_group_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_usergroup_modification_group_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_group_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_usergroup_modification_group_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_gshadow_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_usergroup_modification_gshadow_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_gshadow_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_usergroup_modification_gshadow_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_nsswitch_conf_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_usergroup_modification_nsswitch_conf_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_nsswitch_conf_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_usergroup_modification_nsswitch_conf_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_opasswd_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_usergroup_modification_opasswd_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_opasswd_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_usergroup_modification_opasswd_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_pam_conf_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_usergroup_modification_pam_conf_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_pam_conf_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_usergroup_modification_pam_conf_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_pamd_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_usergroup_modification_pamd_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_pamd_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_usergroup_modification_pamd_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_passwd_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_usergroup_modification_passwd_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_passwd_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_usergroup_modification_passwd_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_shadow_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_usergroup_modification_shadow_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_usergroup_modification_shadow_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_usergroup_modification_shadow_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_var_spool_cron_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_var_spool_cron_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_var_spool_cron_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_rules_var_spool_cron_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_sudo_log_events_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_sudo_log_events_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_sudo_log_events_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match" var_ref="oval:ssg-audit_sudo_log_events_path_pattern:var:1"/>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_auditd_freq:obj:1" version="1">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)freq(?-i)[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_auditd_local_events:obj:1" version="1">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)local_events(?-i)[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_auditd_log_format:obj:1" version="1">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)log_format(?-i)[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_auditd_write_logs:obj:1" version="1">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)write_logs(?-i)[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_auditd_write_logs_default_not_overriden:obj:1" version="1">
          <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)write_logs(?-i)[ \t]*=[ \t]*</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_banner_etc_issue_cis_file_nonempty:obj:1" version="1">
          <ind:filepath>/etc/issue</ind:filepath>
          <ind:pattern operation="pattern match">^.+$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_banner_etc_issue_cis:obj:1" version="1">
          <ind:filepath>/etc/issue</ind:filepath>
          <ind:pattern operation="pattern match">(\\v|\\r|\\m|\\s|almalinux8)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_banner_etc_issue_net_cis_file_nonempty:obj:1" version="1">
          <ind:filepath>/etc/issue.net</ind:filepath>
          <ind:pattern operation="pattern match">^.+$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_banner_etc_issue_net_cis:obj:1" version="1">
          <ind:filepath>/etc/issue.net</ind:filepath>
          <ind:pattern operation="pattern match">(\\v|\\r|\\m|\\s|almalinux8)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_banner_etc_motd_cis:obj:1" version="1">
          <ind:filepath>/etc/motd</ind:filepath>
          <ind:pattern operation="pattern match">(\\v|\\r|\\m|\\s|almalinux8)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_configure_custom_crypto_policy_cis_NO-SSHCBC:obj:1" version="1">
          <ind:path>/etc/crypto-policies/policies/modules/</ind:path>
          <ind:filename>NO-SSHCBC.pmod</ind:filename>
          <ind:pattern operation="pattern match">^cipher@SSH = \-\*\-CBC$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_configure_custom_crypto_policy_cis_NO-SSHWEAKCIPHERS:obj:1" version="1">
          <ind:path>/etc/crypto-policies/policies/modules/</ind:path>
          <ind:filename>NO-SSHWEAKCIPHERS.pmod</ind:filename>
          <ind:pattern operation="pattern match">^cipher@SSH = \-3DES\-CBC \-AES\-128\-CBC \-AES\-192\-CBC \-AES\-256\-CBC \-CHACHA20\-POLY1305$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_configure_custom_crypto_policy_cis_NO-SSHWEAKMACS:obj:1" version="1">
          <ind:path>/etc/crypto-policies/policies/modules/</ind:path>
          <ind:filename>NO-SSHWEAKMACS.pmod</ind:filename>
          <ind:pattern operation="pattern match">^mac@SSH = \-HMAC\-MD5\* \-UMAC\-64\* \-UMAC\-128\*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_configure_custom_crypto_policy_cis_NO-WEAKMAC:obj:1" version="1">
          <ind:path>/etc/crypto-policies/policies/modules/</ind:path>
          <ind:filename>NO-WEAKMAC.pmod</ind:filename>
          <ind:pattern operation="pattern match">^mac = \-\*\-128\*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_configure_usbguard_auditbackend:obj:1" version="1">
          <ind:filepath>/etc/usbguard/usbguard-daemon.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ \\t]*AuditBackend=(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="The configuration file /etc/usbguard/usbguard-daemon.conf for configure_usbguard_auditbackend" id="oval:ssg-obj_configure_usbguard_auditbackend_config_file:obj:1" version="1">
          <unix:filepath operation="pattern match">^/etc/usbguard/usbguard-daemon.conf</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_coredump_disable_backtraces:obj:1" version="1">
          <ind:filepath>/etc/systemd/coredump.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\[Coredump\].*(?:\n\s*[^[\s].*)*\n^[ \t]*ProcessSizeMax\h*=\h*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_coredump_disable_backtraces_config_dir:obj:1" version="1">
          <ind:path>/etc/systemd/coredump.conf.d</ind:path>
          <ind:filename operation="pattern match">.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*\[Coredump\].*(?:\n\s*[^[\s].*)*\n^[ \t]*ProcessSizeMax\h*=\h*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_coredump_disable_storage:obj:1" version="1">
          <ind:filepath>/etc/systemd/coredump.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\[Coredump\].*(?:\n\s*[^[\s].*)*\n^[ \t]*Storage\h*=\h*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_coredump_disable_storage_config_dir:obj:1" version="1">
          <ind:path>/etc/systemd/coredump.conf.d</ind:path>
          <ind:filename operation="pattern match">.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*\[Coredump\].*(?:\n\s*[^[\s].*)*\n^[ \t]*Storage\h*=\h*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-object_coreos_enable_selinux_kernel_argument_file_boot_loader_entries_ostree_2_conf_absent:obj:1" version="1">
          <unix:filepath operation="pattern match">^/boot/loader/entries/ostree-2.*.conf</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_boot_loader_entries_ostree_1_conf:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/loader/entries/ostree-1.*.conf</ind:filepath>
          <ind:pattern operation="pattern match">^options (.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_boot_loader_entries_ostree_2_conf:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/loader/entries/ostree-2.*.conf</ind:filepath>
          <ind:pattern operation="pattern match">^options (.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_proc_cmdline:obj:1" version="1">
          <ind:filepath operation="pattern match">^/proc/cmdline</ind:filepath>
          <ind:pattern operation="pattern match">^BOOT_IMAGE(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_dconf_gnome_disable_user_admin:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\s*\[org/gnome/desktop/lockdown\].*(?:\n\s*[^[\s].*)*\n^\s*user-administration-disabled[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_user-administration-disabled:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/desktop/lockdown/user-administration-disabled$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_dconf_gnome_lock_screen_on_smartcard_removal:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^\s*\[org/gnome/settings-daemon/peripherals/smartcard\].*(?:\n\s*[^[\s].*)*\n^\s*removal-action[ \t]*=[ \t]*(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_prevent_user_removal-action:obj:1" version="1">
          <ind:path>/etc/dconf/db/local.d/locks</ind:path>
          <ind:filename operation="pattern match">^.*$</ind:filename>
          <ind:pattern operation="pattern match">^/org/gnome/settings-daemon/peripherals/smartcard/removal-action$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/lib/" id="oval:ssg-object_file_groupownerdir_group_ownership_library_dirs_0:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/lib</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdir_group_ownership_library_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/lib64/" id="oval:ssg-object_file_groupownerdir_group_ownership_library_dirs_1:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/lib64</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdir_group_ownership_library_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/lib/" id="oval:ssg-object_file_groupownerdir_group_ownership_library_dirs_2:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/lib</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdir_group_ownership_library_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/lib64/" id="oval:ssg-object_file_groupownerdir_group_ownership_library_dirs_3:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/lib64</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdir_group_ownership_library_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/bin/" id="oval:ssg-object_file_ownerdir_ownership_binary_dirs_0:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/bin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_binary_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/" id="oval:ssg-object_file_ownerdir_ownership_binary_dirs_1:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/sbin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_binary_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/bin/" id="oval:ssg-object_file_ownerdir_ownership_binary_dirs_2:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/bin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_binary_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/sbin/" id="oval:ssg-object_file_ownerdir_ownership_binary_dirs_3:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/sbin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_binary_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/local/bin/" id="oval:ssg-object_file_ownerdir_ownership_binary_dirs_4:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/local/bin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_binary_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/local/sbin/" id="oval:ssg-object_file_ownerdir_ownership_binary_dirs_5:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/local/sbin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_binary_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/lib/" id="oval:ssg-object_file_ownerdir_ownership_library_dirs_0:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/lib</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_library_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/lib64/" id="oval:ssg-object_file_ownerdir_ownership_library_dirs_1:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/lib64</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_library_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/lib/" id="oval:ssg-object_file_ownerdir_ownership_library_dirs_2:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/lib</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_library_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/lib64/" id="oval:ssg-object_file_ownerdir_ownership_library_dirs_3:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/lib64</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_library_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/bin/" id="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_0:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/bin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_binary_dirs:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_binary_dirs_0_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/" id="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_1:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/sbin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_binary_dirs:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_binary_dirs_1_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/bin/" id="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_2:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/bin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_binary_dirs:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_binary_dirs_2_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/sbin/" id="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_3:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/sbin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_binary_dirs:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_binary_dirs_3_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/local/bin/" id="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_4:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/local/bin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_binary_dirs:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_binary_dirs_4_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/local/sbin/" id="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_5:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/local/sbin</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_binary_dirs:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_binary_dirs_5_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/lib/" id="oval:ssg-object_file_permissionsdir_permissions_library_dirs_0:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/lib</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_library_dirs:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_library_dirs_0_mode_7755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/lib64/" id="oval:ssg-object_file_permissionsdir_permissions_library_dirs_1:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/lib64</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_library_dirs:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_library_dirs_1_mode_7755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/lib/" id="oval:ssg-object_file_permissionsdir_permissions_library_dirs_2:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/lib</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_library_dirs:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_library_dirs_2_mode_7755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/lib64/" id="oval:ssg-object_file_permissionsdir_permissions_library_dirs_3:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/lib64</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_library_dirs:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_library_dirs_3_mode_7755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_ipsecd_root_gid_etc:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /usr/lib/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_ipsecd_root_gid_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group or /usr/lib/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_ipsecd_root_gid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_groupownerdirectory_groupowner_etc_ipsecd_root_gid_etc:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_file_groupownerdirectory_groupowner_etc_ipsecd_root_gid_usr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/etc/ipsec.d/" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_ipsecd_0:obj:1" version="1">
          <unix:path>/etc/ipsec.d</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdirectory_groupowner_etc_ipsecd_0_root:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_iptables_root_gid_etc:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /usr/lib/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_iptables_root_gid_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group or /usr/lib/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_iptables_root_gid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_groupownerdirectory_groupowner_etc_iptables_root_gid_etc:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_file_groupownerdirectory_groupowner_etc_iptables_root_gid_usr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/etc/iptables/" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_iptables_0:obj:1" version="1">
          <unix:path>/etc/iptables</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdirectory_groupowner_etc_iptables_0_root:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_nftables_root_gid_etc:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /usr/lib/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_nftables_root_gid_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group or /usr/lib/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_nftables_root_gid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_groupownerdirectory_groupowner_etc_nftables_root_gid_etc:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_file_groupownerdirectory_groupowner_etc_nftables_root_gid_usr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/etc/nftables/" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_nftables_0:obj:1" version="1">
          <unix:path>/etc/nftables</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdirectory_groupowner_etc_nftables_0_root:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_selinux_root_gid_etc:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /usr/lib/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_selinux_root_gid_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group or /usr/lib/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_selinux_root_gid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_groupownerdirectory_groupowner_etc_selinux_root_gid_etc:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_file_groupownerdirectory_groupowner_etc_selinux_root_gid_usr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/etc/selinux/" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_selinux_0:obj:1" version="1">
          <unix:path>/etc/selinux</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdirectory_groupowner_etc_selinux_0_root:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_sudoersd_root_gid_etc:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /usr/lib/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_sudoersd_root_gid_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group or /usr/lib/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_sudoersd_root_gid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_groupownerdirectory_groupowner_etc_sudoersd_root_gid_etc:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_file_groupownerdirectory_groupowner_etc_sudoersd_root_gid_usr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/etc/sudoers.d/" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_sudoersd_0:obj:1" version="1">
          <unix:path>/etc/sudoers.d</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdirectory_groupowner_etc_sudoersd_0_root:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_sysctld_root_gid_etc:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /usr/lib/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_sysctld_root_gid_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group or /usr/lib/group)" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_sysctld_root_gid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_groupownerdirectory_groupowner_etc_sysctld_root_gid_etc:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_file_groupownerdirectory_groupowner_etc_sysctld_root_gid_usr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/etc/sysctl.d/" id="oval:ssg-object_file_groupownerdirectory_groupowner_etc_sysctld_0:obj:1" version="1">
          <unix:path>/etc/sysctl.d</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdirectory_groupowner_etc_sysctld_0_root:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/ipsec.d/" id="oval:ssg-object_file_ownerdirectory_owner_etc_ipsecd_0:obj:1" version="1">
          <unix:path>/etc/ipsec.d</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerdirectory_owner_etc_ipsecd_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/iptables/" id="oval:ssg-object_file_ownerdirectory_owner_etc_iptables_0:obj:1" version="1">
          <unix:path>/etc/iptables</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerdirectory_owner_etc_iptables_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/nftables/" id="oval:ssg-object_file_ownerdirectory_owner_etc_nftables_0:obj:1" version="1">
          <unix:path>/etc/nftables</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerdirectory_owner_etc_nftables_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/selinux/" id="oval:ssg-object_file_ownerdirectory_owner_etc_selinux_0:obj:1" version="1">
          <unix:path>/etc/selinux</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerdirectory_owner_etc_selinux_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/sudoers.d/" id="oval:ssg-object_file_ownerdirectory_owner_etc_sudoersd_0:obj:1" version="1">
          <unix:path>/etc/sudoers.d</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerdirectory_owner_etc_sudoersd_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/sysctl.d/" id="oval:ssg-object_file_ownerdirectory_owner_etc_sysctld_0:obj:1" version="1">
          <unix:path>/etc/sysctl.d</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerdirectory_owner_etc_sysctld_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/ipsec.d/" id="oval:ssg-object_file_permissionsdirectory_permissions_etc_ipsecd_0:obj:1" version="1">
          <unix:path>/etc/ipsec.d</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_directory_permissions_etc_ipsecd:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdirectory_permissions_etc_ipsecd_0_mode_0700or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/iptables/" id="oval:ssg-object_file_permissionsdirectory_permissions_etc_iptables_0:obj:1" version="1">
          <unix:path>/etc/iptables</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_directory_permissions_etc_iptables:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdirectory_permissions_etc_iptables_0_mode_0700or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/nftables/" id="oval:ssg-object_file_permissionsdirectory_permissions_etc_nftables_0:obj:1" version="1">
          <unix:path>/etc/nftables</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_directory_permissions_etc_nftables:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdirectory_permissions_etc_nftables_0_mode_0700or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/selinux/" id="oval:ssg-object_file_permissionsdirectory_permissions_etc_selinux_0:obj:1" version="1">
          <unix:path>/etc/selinux</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_directory_permissions_etc_selinux:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdirectory_permissions_etc_selinux_0_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/sudoers.d/" id="oval:ssg-object_file_permissionsdirectory_permissions_etc_sudoersd_0:obj:1" version="1">
          <unix:path>/etc/sudoers.d</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_directory_permissions_etc_sudoersd:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdirectory_permissions_etc_sudoersd_0_mode_0750or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/sysctl.d/" id="oval:ssg-object_file_permissionsdirectory_permissions_etc_sysctld_0:obj:1" version="1">
          <unix:path>/etc/sysctl.d</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_directory_permissions_etc_sysctld:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdirectory_permissions_etc_sysctld_0_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_disable_host_auth:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)HostbasedAuthentication(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_disable_host_auth:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_disable_host_auth:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/etc/at.allow" id="oval:ssg-object_file_at_allow_exists:obj:1" version="1">
          <unix:filepath>/etc/at.allow</unix:filepath>
        </unix:file_object>
        <unix:file_object comment="/etc/at.deny" id="oval:ssg-object_file_at_deny_not_exist:obj:1" version="1">
          <unix:filepath>/etc/at.deny</unix:filepath>
        </unix:file_object>
        <unix:file_object comment="/sbin/auditctl" id="oval:ssg-object_file_groupownerfile_audit_tools_group_ownership_0:obj:1" version="1">
          <unix:filepath>/sbin/auditctl</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerfile_audit_tools_group_ownership_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/aureport" id="oval:ssg-object_file_groupownerfile_audit_tools_group_ownership_1:obj:1" version="1">
          <unix:filepath>/sbin/aureport</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerfile_audit_tools_group_ownership_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/ausearch" id="oval:ssg-object_file_groupownerfile_audit_tools_group_ownership_2:obj:1" version="1">
          <unix:filepath>/sbin/ausearch</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerfile_audit_tools_group_ownership_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/autrace" id="oval:ssg-object_file_groupownerfile_audit_tools_group_ownership_3:obj:1" version="1">
          <unix:filepath>/sbin/autrace</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerfile_audit_tools_group_ownership_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/auditd" id="oval:ssg-object_file_groupownerfile_audit_tools_group_ownership_4:obj:1" version="1">
          <unix:filepath>/sbin/auditd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerfile_audit_tools_group_ownership_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/rsyslogd" id="oval:ssg-object_file_groupownerfile_audit_tools_group_ownership_5:obj:1" version="1">
          <unix:filepath>/sbin/rsyslogd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerfile_audit_tools_group_ownership_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/augenrules" id="oval:ssg-object_file_groupownerfile_audit_tools_group_ownership_6:obj:1" version="1">
          <unix:filepath>/sbin/augenrules</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerfile_audit_tools_group_ownership_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/auditctl" id="oval:ssg-object_file_ownerfile_audit_tools_ownership_0:obj:1" version="1">
          <unix:filepath>/sbin/auditctl</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerfile_audit_tools_ownership_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/aureport" id="oval:ssg-object_file_ownerfile_audit_tools_ownership_1:obj:1" version="1">
          <unix:filepath>/sbin/aureport</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerfile_audit_tools_ownership_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/ausearch" id="oval:ssg-object_file_ownerfile_audit_tools_ownership_2:obj:1" version="1">
          <unix:filepath>/sbin/ausearch</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerfile_audit_tools_ownership_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/autrace" id="oval:ssg-object_file_ownerfile_audit_tools_ownership_3:obj:1" version="1">
          <unix:filepath>/sbin/autrace</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerfile_audit_tools_ownership_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/auditd" id="oval:ssg-object_file_ownerfile_audit_tools_ownership_4:obj:1" version="1">
          <unix:filepath>/sbin/auditd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerfile_audit_tools_ownership_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/rsyslogd" id="oval:ssg-object_file_ownerfile_audit_tools_ownership_5:obj:1" version="1">
          <unix:filepath>/sbin/rsyslogd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerfile_audit_tools_ownership_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/augenrules" id="oval:ssg-object_file_ownerfile_audit_tools_ownership_6:obj:1" version="1">
          <unix:filepath>/sbin/augenrules</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownerfile_audit_tools_ownership_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/auditctl" id="oval:ssg-object_file_permissionsfile_audit_tools_permissions_0:obj:1" version="1">
          <unix:filepath>/sbin/auditctl</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_file_audit_tools_permissions:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsfile_audit_tools_permissions_0_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/aureport" id="oval:ssg-object_file_permissionsfile_audit_tools_permissions_1:obj:1" version="1">
          <unix:filepath>/sbin/aureport</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_file_audit_tools_permissions:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsfile_audit_tools_permissions_1_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/ausearch" id="oval:ssg-object_file_permissionsfile_audit_tools_permissions_2:obj:1" version="1">
          <unix:filepath>/sbin/ausearch</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_file_audit_tools_permissions:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsfile_audit_tools_permissions_2_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/autrace" id="oval:ssg-object_file_permissionsfile_audit_tools_permissions_3:obj:1" version="1">
          <unix:filepath>/sbin/autrace</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_file_audit_tools_permissions:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsfile_audit_tools_permissions_3_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/auditd" id="oval:ssg-object_file_permissionsfile_audit_tools_permissions_4:obj:1" version="1">
          <unix:filepath>/sbin/auditd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_file_audit_tools_permissions:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsfile_audit_tools_permissions_4_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/rsyslogd" id="oval:ssg-object_file_permissionsfile_audit_tools_permissions_5:obj:1" version="1">
          <unix:filepath>/sbin/rsyslogd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_file_audit_tools_permissions:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsfile_audit_tools_permissions_5_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/augenrules" id="oval:ssg-object_file_permissionsfile_audit_tools_permissions_6:obj:1" version="1">
          <unix:filepath>/sbin/augenrules</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_file_audit_tools_permissions:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionsfile_audit_tools_permissions_6_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.allow" id="oval:ssg-object_file_cron_allow_exists:obj:1" version="1">
          <unix:filepath>/etc/cron.allow</unix:filepath>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.deny" id="oval:ssg-object_file_cron_deny_not_exist:obj:1" version="1">
          <unix:filepath>/etc/cron.deny</unix:filepath>
        </unix:file_object>
        <unix:file_object comment="/etc/at.allow" id="oval:ssg-object_file_groupowner_at_allow_0:obj:1" version="1">
          <unix:filepath>/etc/at.allow</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_at_allow_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/group-" id="oval:ssg-object_file_groupowner_backup_etc_group_0:obj:1" version="1">
          <unix:filepath>/etc/group-</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_backup_etc_group_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/gshadow-" id="oval:ssg-object_file_groupowner_backup_etc_gshadow_0:obj:1" version="1">
          <unix:filepath>/etc/gshadow-</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_backup_etc_gshadow_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/passwd-" id="oval:ssg-object_file_groupowner_backup_etc_passwd_0:obj:1" version="1">
          <unix:filepath>/etc/passwd-</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_backup_etc_passwd_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/shadow-" id="oval:ssg-object_file_groupowner_backup_etc_shadow_0:obj:1" version="1">
          <unix:filepath>/etc/shadow-</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_backup_etc_shadow_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.allow" id="oval:ssg-object_file_groupowner_cron_allow_0:obj:1" version="1">
          <unix:filepath>/etc/cron.allow</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_cron_allow_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.d/" id="oval:ssg-object_file_groupowner_cron_d_0:obj:1" version="1">
          <unix:path>/etc/cron.d</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_cron_d_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.daily/" id="oval:ssg-object_file_groupowner_cron_daily_0:obj:1" version="1">
          <unix:path>/etc/cron.daily</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_cron_daily_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.hourly/" id="oval:ssg-object_file_groupowner_cron_hourly_0:obj:1" version="1">
          <unix:path>/etc/cron.hourly</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_cron_hourly_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.monthly/" id="oval:ssg-object_file_groupowner_cron_monthly_0:obj:1" version="1">
          <unix:path>/etc/cron.monthly</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_cron_monthly_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.weekly/" id="oval:ssg-object_file_groupowner_cron_weekly_0:obj:1" version="1">
          <unix:path>/etc/cron.weekly</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_cron_weekly_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.yearly/" id="oval:ssg-object_file_groupowner_cron_yearly_0:obj:1" version="1">
          <unix:path>/etc/cron.yearly</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_cron_yearly_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/crontab" id="oval:ssg-object_file_groupowner_crontab_0:obj:1" version="1">
          <unix:filepath>/etc/crontab</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_crontab_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/boot/efi/EFI/almalinux/grub.cfg" id="oval:ssg-object_file_groupowner_efi_grub2_cfg_0:obj:1" version="1">
          <unix:filepath>/boot/efi/EFI/almalinux/grub.cfg</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_efi_grub2_cfg_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/boot/efi/EFI/almalinux/user.cfg" id="oval:ssg-object_file_groupowner_efi_user_cfg_0:obj:1" version="1">
          <unix:filepath>/boot/efi/EFI/almalinux/user.cfg</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_efi_user_cfg_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group)" id="oval:ssg-object_file_groupowner_etc_crypttab_root_gid_etc:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /usr/lib/group)" id="oval:ssg-object_file_groupowner_etc_crypttab_root_gid_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group or /usr/lib/group)" id="oval:ssg-object_file_groupowner_etc_crypttab_root_gid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_groupowner_etc_crypttab_root_gid_etc:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_file_groupowner_etc_crypttab_root_gid_usr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/etc/crypttab" id="oval:ssg-object_file_groupowner_etc_crypttab_0:obj:1" version="1">
          <unix:filepath>/etc/crypttab</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_crypttab_0_root:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/group" id="oval:ssg-object_file_groupowner_etc_group_0:obj:1" version="1">
          <unix:filepath>/etc/group</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_group_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/gshadow" id="oval:ssg-object_file_groupowner_etc_gshadow_0:obj:1" version="1">
          <unix:filepath>/etc/gshadow</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_gshadow_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group)" id="oval:ssg-object_file_groupowner_etc_ipsec_conf_root_gid_etc:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /usr/lib/group)" id="oval:ssg-object_file_groupowner_etc_ipsec_conf_root_gid_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group or /usr/lib/group)" id="oval:ssg-object_file_groupowner_etc_ipsec_conf_root_gid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_groupowner_etc_ipsec_conf_root_gid_etc:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_file_groupowner_etc_ipsec_conf_root_gid_usr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/etc/ipsec.conf" id="oval:ssg-object_file_groupowner_etc_ipsec_conf_0:obj:1" version="1">
          <unix:filepath>/etc/ipsec.conf</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_ipsec_conf_0_root:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group)" id="oval:ssg-object_file_groupowner_etc_ipsec_secrets_root_gid_etc:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /usr/lib/group)" id="oval:ssg-object_file_groupowner_etc_ipsec_secrets_root_gid_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group or /usr/lib/group)" id="oval:ssg-object_file_groupowner_etc_ipsec_secrets_root_gid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_groupowner_etc_ipsec_secrets_root_gid_etc:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_file_groupowner_etc_ipsec_secrets_root_gid_usr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/etc/ipsec.secrets" id="oval:ssg-object_file_groupowner_etc_ipsec_secrets_0:obj:1" version="1">
          <unix:filepath>/etc/ipsec.secrets</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_ipsec_secrets_0_root:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/issue" id="oval:ssg-object_file_groupowner_etc_issue_0:obj:1" version="1">
          <unix:filepath>/etc/issue</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_issue_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/issue.net" id="oval:ssg-object_file_groupowner_etc_issue_net_0:obj:1" version="1">
          <unix:filepath>/etc/issue.net</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_issue_net_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/motd" id="oval:ssg-object_file_groupowner_etc_motd_0:obj:1" version="1">
          <unix:filepath>/etc/motd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_motd_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/passwd" id="oval:ssg-object_file_groupowner_etc_passwd_0:obj:1" version="1">
          <unix:filepath>/etc/passwd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_passwd_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/security/opasswd" id="oval:ssg-object_file_groupowner_etc_security_opasswd_0:obj:1" version="1">
          <unix:filepath>/etc/security/opasswd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_security_opasswd_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/security/opasswd.old" id="oval:ssg-object_file_groupowner_etc_security_opasswd_old_0:obj:1" version="1">
          <unix:filepath>/etc/security/opasswd.old</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_security_opasswd_old_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group)" id="oval:ssg-object_file_groupowner_etc_sestatus_conf_root_gid_etc:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /usr/lib/group)" id="oval:ssg-object_file_groupowner_etc_sestatus_conf_root_gid_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group or /usr/lib/group)" id="oval:ssg-object_file_groupowner_etc_sestatus_conf_root_gid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_groupowner_etc_sestatus_conf_root_gid_etc:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_file_groupowner_etc_sestatus_conf_root_gid_usr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/etc/sestatus.conf" id="oval:ssg-object_file_groupowner_etc_sestatus_conf_0:obj:1" version="1">
          <unix:filepath>/etc/sestatus.conf</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_sestatus_conf_0_root:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/shadow" id="oval:ssg-object_file_groupowner_etc_shadow_0:obj:1" version="1">
          <unix:filepath>/etc/shadow</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_shadow_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/shells" id="oval:ssg-object_file_groupowner_etc_shells_0:obj:1" version="1">
          <unix:filepath>/etc/shells</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_shells_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group)" id="oval:ssg-object_file_groupowner_etc_sudoers_root_gid_etc:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /usr/lib/group)" id="oval:ssg-object_file_groupowner_etc_sudoers_root_gid_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group or /usr/lib/group)" id="oval:ssg-object_file_groupowner_etc_sudoers_root_gid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_groupowner_etc_sudoers_root_gid_etc:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_file_groupowner_etc_sudoers_root_gid_usr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/etc/sudoers" id="oval:ssg-object_file_groupowner_etc_sudoers_0:obj:1" version="1">
          <unix:filepath>/etc/sudoers</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_sudoers_0_root:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/sysconfig/sshd" id="oval:ssg-object_file_groupowner_etc_sysconfig_sshd_0:obj:1" version="1">
          <unix:filepath>/etc/sysconfig/sshd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_etc_sysconfig_sshd_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/boot/grub2/grub.cfg" id="oval:ssg-object_file_groupowner_grub2_cfg_0:obj:1" version="1">
          <unix:filepath>/boot/grub2/grub.cfg</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_grub2_cfg_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/ssh/sshd_config" id="oval:ssg-object_file_groupowner_sshd_config_0:obj:1" version="1">
          <unix:filepath>/etc/ssh/sshd_config</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_sshd_config_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group)" id="oval:ssg-object_file_groupowner_systemmap_root_gid_etc:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /usr/lib/group)" id="oval:ssg-object_file_groupowner_systemmap_root_gid_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the root group (from /etc/group or /usr/lib/group)" id="oval:ssg-object_file_groupowner_systemmap_root_gid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_groupowner_systemmap_root_gid_etc:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_file_groupowner_systemmap_root_gid_usr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/boot/" id="oval:ssg-object_file_groupowner_systemmap_0:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^.*System\.map.*$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_systemmap_0_root:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/boot/grub2/user.cfg" id="oval:ssg-object_file_groupowner_user_cfg_0:obj:1" version="1">
          <unix:filepath>/boot/grub2/user.cfg</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_user_cfg_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/" id="oval:ssg-object_file_groupowner_var_log_0:obj:1" version="1">
          <unix:path>/var/log</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_var_log_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/messages" id="oval:ssg-object_file_groupowner_var_log_messages_0:obj:1" version="1">
          <unix:filepath>/var/log/messages</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_var_log_messages_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/syslog" id="oval:ssg-object_file_groupowner_var_log_syslog_0:obj:1" version="1">
          <unix:filepath>/var/log/syslog</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_var_log_syslog_0_4:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/auditctl" id="oval:ssg-object_file_groupownership_audit_binaries_0:obj:1" version="1">
          <unix:filepath>/sbin/auditctl</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownership_audit_binaries_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/aureport" id="oval:ssg-object_file_groupownership_audit_binaries_1:obj:1" version="1">
          <unix:filepath>/sbin/aureport</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownership_audit_binaries_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/ausearch" id="oval:ssg-object_file_groupownership_audit_binaries_2:obj:1" version="1">
          <unix:filepath>/sbin/ausearch</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownership_audit_binaries_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/autrace" id="oval:ssg-object_file_groupownership_audit_binaries_3:obj:1" version="1">
          <unix:filepath>/sbin/autrace</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownership_audit_binaries_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/auditd" id="oval:ssg-object_file_groupownership_audit_binaries_4:obj:1" version="1">
          <unix:filepath>/sbin/auditd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownership_audit_binaries_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/audispd" id="oval:ssg-object_file_groupownership_audit_binaries_5:obj:1" version="1">
          <unix:filepath>/sbin/audispd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownership_audit_binaries_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/augenrules" id="oval:ssg-object_file_groupownership_audit_binaries_6:obj:1" version="1">
          <unix:filepath>/sbin/augenrules</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownership_audit_binaries_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/audit/" id="oval:ssg-object_file_groupownership_audit_configuration_0:obj:1" version="1">
          <unix:path>/etc/audit</unix:path>
          <unix:filename operation="pattern match">^.*audit(\.rules|d\.conf)$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownership_audit_configuration_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/audit/rules.d/" id="oval:ssg-object_file_groupownership_audit_configuration_1:obj:1" version="1">
          <unix:path>/etc/audit/rules.d</unix:path>
          <unix:filename operation="pattern match">^.*\.rules$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownership_audit_configuration_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object comment="gid of the ssh_keys group (from /etc/group)" id="oval:ssg-object_file_groupownership_sshd_private_key_ssh_keys_gid_etc:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^ssh_keys:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the ssh_keys group (from /usr/lib/group)" id="oval:ssg-object_file_groupownership_sshd_private_key_ssh_keys_gid_usr:obj:1" version="1">
          <ind:filepath>/usr/lib/group</ind:filepath>
          <ind:pattern operation="pattern match">^ssh_keys:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="gid of the ssh_keys group (from /etc/group or /usr/lib/group)" id="oval:ssg-object_file_groupownership_sshd_private_key_ssh_keys_gid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_file_groupownership_sshd_private_key_ssh_keys_gid_etc:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_file_groupownership_sshd_private_key_ssh_keys_gid_usr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/etc/ssh/" id="oval:ssg-object_file_groupownership_sshd_private_key_0:obj:1" version="1">
          <unix:path>/etc/ssh</unix:path>
          <unix:filename operation="pattern match">^.*_key$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownership_sshd_private_key_0_ssh_keys:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/ssh/" id="oval:ssg-object_file_groupownership_sshd_pub_key_0:obj:1" version="1">
          <unix:path>/etc/ssh</unix:path>
          <unix:filename operation="pattern match">^.*\.pub$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownership_sshd_pub_key_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/at.allow" id="oval:ssg-object_file_owner_at_allow_0:obj:1" version="1">
          <unix:filepath>/etc/at.allow</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_at_allow_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/group-" id="oval:ssg-object_file_owner_backup_etc_group_0:obj:1" version="1">
          <unix:filepath>/etc/group-</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_backup_etc_group_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/gshadow-" id="oval:ssg-object_file_owner_backup_etc_gshadow_0:obj:1" version="1">
          <unix:filepath>/etc/gshadow-</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_backup_etc_gshadow_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/passwd-" id="oval:ssg-object_file_owner_backup_etc_passwd_0:obj:1" version="1">
          <unix:filepath>/etc/passwd-</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_backup_etc_passwd_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/shadow-" id="oval:ssg-object_file_owner_backup_etc_shadow_0:obj:1" version="1">
          <unix:filepath>/etc/shadow-</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_backup_etc_shadow_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.allow" id="oval:ssg-object_file_owner_cron_allow_0:obj:1" version="1">
          <unix:filepath>/etc/cron.allow</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_cron_allow_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.d/" id="oval:ssg-object_file_owner_cron_d_0:obj:1" version="1">
          <unix:path>/etc/cron.d</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_cron_d_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.daily/" id="oval:ssg-object_file_owner_cron_daily_0:obj:1" version="1">
          <unix:path>/etc/cron.daily</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_cron_daily_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.hourly/" id="oval:ssg-object_file_owner_cron_hourly_0:obj:1" version="1">
          <unix:path>/etc/cron.hourly</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_cron_hourly_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.monthly/" id="oval:ssg-object_file_owner_cron_monthly_0:obj:1" version="1">
          <unix:path>/etc/cron.monthly</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_cron_monthly_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.weekly/" id="oval:ssg-object_file_owner_cron_weekly_0:obj:1" version="1">
          <unix:path>/etc/cron.weekly</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_cron_weekly_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.yearly/" id="oval:ssg-object_file_owner_cron_yearly_0:obj:1" version="1">
          <unix:path>/etc/cron.yearly</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_cron_yearly_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/crontab" id="oval:ssg-object_file_owner_crontab_0:obj:1" version="1">
          <unix:filepath>/etc/crontab</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_crontab_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/boot/efi/EFI/almalinux/grub.cfg" id="oval:ssg-object_file_owner_efi_grub2_cfg_0:obj:1" version="1">
          <unix:filepath>/boot/efi/EFI/almalinux/grub.cfg</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_efi_grub2_cfg_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/boot/efi/EFI/almalinux/user.cfg" id="oval:ssg-object_file_owner_efi_user_cfg_0:obj:1" version="1">
          <unix:filepath>/boot/efi/EFI/almalinux/user.cfg</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_efi_user_cfg_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/chrony.keys" id="oval:ssg-object_file_owner_etc_chrony_keys_0:obj:1" version="1">
          <unix:filepath>/etc/chrony.keys</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_etc_chrony_keys_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/crypttab" id="oval:ssg-object_file_owner_etc_crypttab_0:obj:1" version="1">
          <unix:filepath>/etc/crypttab</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_etc_crypttab_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/group" id="oval:ssg-object_file_owner_etc_group_0:obj:1" version="1">
          <unix:filepath>/etc/group</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_etc_group_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/gshadow" id="oval:ssg-object_file_owner_etc_gshadow_0:obj:1" version="1">
          <unix:filepath>/etc/gshadow</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_etc_gshadow_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/ipsec.conf" id="oval:ssg-object_file_owner_etc_ipsec_conf_0:obj:1" version="1">
          <unix:filepath>/etc/ipsec.conf</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_etc_ipsec_conf_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/ipsec.secrets" id="oval:ssg-object_file_owner_etc_ipsec_secrets_0:obj:1" version="1">
          <unix:filepath>/etc/ipsec.secrets</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_etc_ipsec_secrets_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/issue" id="oval:ssg-object_file_owner_etc_issue_0:obj:1" version="1">
          <unix:filepath>/etc/issue</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_etc_issue_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/issue.net" id="oval:ssg-object_file_owner_etc_issue_net_0:obj:1" version="1">
          <unix:filepath>/etc/issue.net</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_etc_issue_net_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/motd" id="oval:ssg-object_file_owner_etc_motd_0:obj:1" version="1">
          <unix:filepath>/etc/motd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_etc_motd_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/passwd" id="oval:ssg-object_file_owner_etc_passwd_0:obj:1" version="1">
          <unix:filepath>/etc/passwd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_etc_passwd_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/security/opasswd" id="oval:ssg-object_file_owner_etc_security_opasswd_0:obj:1" version="1">
          <unix:filepath>/etc/security/opasswd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_etc_security_opasswd_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/security/opasswd.old" id="oval:ssg-object_file_owner_etc_security_opasswd_old_0:obj:1" version="1">
          <unix:filepath>/etc/security/opasswd.old</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_etc_security_opasswd_old_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/sestatus.conf" id="oval:ssg-object_file_owner_etc_sestatus_conf_0:obj:1" version="1">
          <unix:filepath>/etc/sestatus.conf</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_etc_sestatus_conf_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/shadow" id="oval:ssg-object_file_owner_etc_shadow_0:obj:1" version="1">
          <unix:filepath>/etc/shadow</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_etc_shadow_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/shells" id="oval:ssg-object_file_owner_etc_shells_0:obj:1" version="1">
          <unix:filepath>/etc/shells</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_etc_shells_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/sudoers" id="oval:ssg-object_file_owner_etc_sudoers_0:obj:1" version="1">
          <unix:filepath>/etc/sudoers</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_etc_sudoers_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/sysconfig/sshd" id="oval:ssg-object_file_owner_etc_sysconfig_sshd_0:obj:1" version="1">
          <unix:filepath>/etc/sysconfig/sshd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_etc_sysconfig_sshd_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/boot/grub2/grub.cfg" id="oval:ssg-object_file_owner_grub2_cfg_0:obj:1" version="1">
          <unix:filepath>/boot/grub2/grub.cfg</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_grub2_cfg_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/ssh/sshd_config" id="oval:ssg-object_file_owner_sshd_config_0:obj:1" version="1">
          <unix:filepath>/etc/ssh/sshd_config</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_sshd_config_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/boot/" id="oval:ssg-object_file_owner_systemmap_0:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^.*System\.map.*$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_systemmap_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/boot/grub2/user.cfg" id="oval:ssg-object_file_owner_user_cfg_0:obj:1" version="1">
          <unix:filepath>/boot/grub2/user.cfg</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_user_cfg_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/" id="oval:ssg-object_file_owner_var_log_0:obj:1" version="1">
          <unix:path>/var/log</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_var_log_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/messages" id="oval:ssg-object_file_owner_var_log_messages_0:obj:1" version="1">
          <unix:filepath>/var/log/messages</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_var_log_messages_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:password_object id="oval:ssg-object_file_owner_var_log_syslog_syslog_uid:obj:1" version="1">
          <unix:username operation="equals">syslog</unix:username>
        </unix:password_object>
        <unix:file_object comment="/var/log/syslog" id="oval:ssg-object_file_owner_var_log_syslog_0:obj:1" version="1">
          <unix:filepath>/var/log/syslog</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_owner_var_log_syslog_0_syslog:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/auditctl" id="oval:ssg-object_file_ownership_audit_binaries_0:obj:1" version="1">
          <unix:filepath>/sbin/auditctl</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_binaries_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/aureport" id="oval:ssg-object_file_ownership_audit_binaries_1:obj:1" version="1">
          <unix:filepath>/sbin/aureport</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_binaries_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/ausearch" id="oval:ssg-object_file_ownership_audit_binaries_2:obj:1" version="1">
          <unix:filepath>/sbin/ausearch</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_binaries_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/autrace" id="oval:ssg-object_file_ownership_audit_binaries_3:obj:1" version="1">
          <unix:filepath>/sbin/autrace</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_binaries_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/auditd" id="oval:ssg-object_file_ownership_audit_binaries_4:obj:1" version="1">
          <unix:filepath>/sbin/auditd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_binaries_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/audispd" id="oval:ssg-object_file_ownership_audit_binaries_5:obj:1" version="1">
          <unix:filepath>/sbin/audispd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_binaries_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/augenrules" id="oval:ssg-object_file_ownership_audit_binaries_6:obj:1" version="1">
          <unix:filepath>/sbin/augenrules</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_binaries_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/audit/" id="oval:ssg-object_file_ownership_audit_configuration_0:obj:1" version="1">
          <unix:path>/etc/audit</unix:path>
          <unix:filename operation="pattern match">^.*audit(\.rules|d\.conf)$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_configuration_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/audit/rules.d/" id="oval:ssg-object_file_ownership_audit_configuration_1:obj:1" version="1">
          <unix:path>/etc/audit/rules.d</unix:path>
          <unix:filename operation="pattern match">^.*\.rules$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_configuration_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/lib/" id="oval:ssg-object_file_ownership_library_dirs_0:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/lib</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownership_library_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/lib64/" id="oval:ssg-object_file_ownership_library_dirs_1:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/lib64</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownership_library_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/lib/" id="oval:ssg-object_file_ownership_library_dirs_2:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/lib</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownership_library_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/lib64/" id="oval:ssg-object_file_ownership_library_dirs_3:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/lib64</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownership_library_dirs_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/ssh/" id="oval:ssg-object_file_ownership_sshd_private_key_0:obj:1" version="1">
          <unix:path>/etc/ssh</unix:path>
          <unix:filename operation="pattern match">^.*_key$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownership_sshd_private_key_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/ssh/" id="oval:ssg-object_file_ownership_sshd_pub_key_0:obj:1" version="1">
          <unix:path>/etc/ssh</unix:path>
          <unix:filename operation="pattern match">^.*\.pub$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_ownership_sshd_pub_key_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/at.allow" id="oval:ssg-object_file_permissions_at_allow_0:obj:1" version="1">
          <unix:filepath>/etc/at.allow</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__at_allow:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_at_allow_0_mode_0640or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/auditctl" id="oval:ssg-object_file_permissions_audit_binaries_0:obj:1" version="1">
          <unix:filepath>/sbin/auditctl</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__audit_binaries:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_audit_binaries_0_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/aureport" id="oval:ssg-object_file_permissions_audit_binaries_1:obj:1" version="1">
          <unix:filepath>/sbin/aureport</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__audit_binaries:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_audit_binaries_1_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/ausearch" id="oval:ssg-object_file_permissions_audit_binaries_2:obj:1" version="1">
          <unix:filepath>/sbin/ausearch</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__audit_binaries:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_audit_binaries_2_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/autrace" id="oval:ssg-object_file_permissions_audit_binaries_3:obj:1" version="1">
          <unix:filepath>/sbin/autrace</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__audit_binaries:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_audit_binaries_3_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/auditd" id="oval:ssg-object_file_permissions_audit_binaries_4:obj:1" version="1">
          <unix:filepath>/sbin/auditd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__audit_binaries:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_audit_binaries_4_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/audispd" id="oval:ssg-object_file_permissions_audit_binaries_5:obj:1" version="1">
          <unix:filepath>/sbin/audispd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__audit_binaries:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_audit_binaries_5_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/sbin/augenrules" id="oval:ssg-object_file_permissions_audit_binaries_6:obj:1" version="1">
          <unix:filepath>/sbin/augenrules</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__audit_binaries:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_audit_binaries_6_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/audit/" id="oval:ssg-object_file_permissions_audit_configuration_0:obj:1" version="1">
          <unix:path>/etc/audit</unix:path>
          <unix:filename operation="pattern match">^.*audit(\.rules|d\.conf)$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__audit_configuration:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_audit_configuration_0_mode_0640or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/audit/rules.d/" id="oval:ssg-object_file_permissions_audit_configuration_1:obj:1" version="1">
          <unix:path>/etc/audit/rules.d</unix:path>
          <unix:filename operation="pattern match">^.*\.rules$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__audit_configuration:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_audit_configuration_1_mode_0640or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/group-" id="oval:ssg-object_file_permissions_backup_etc_group_0:obj:1" version="1">
          <unix:filepath>/etc/group-</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__backup_etc_group:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_backup_etc_group_0_mode_0644or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/gshadow-" id="oval:ssg-object_file_permissions_backup_etc_gshadow_0:obj:1" version="1">
          <unix:filepath>/etc/gshadow-</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__backup_etc_gshadow:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_backup_etc_gshadow_0_mode_0000or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/passwd-" id="oval:ssg-object_file_permissions_backup_etc_passwd_0:obj:1" version="1">
          <unix:filepath>/etc/passwd-</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__backup_etc_passwd:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_backup_etc_passwd_0_mode_0644or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/shadow-" id="oval:ssg-object_file_permissions_backup_etc_shadow_0:obj:1" version="1">
          <unix:filepath>/etc/shadow-</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__backup_etc_shadow:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_backup_etc_shadow_0_mode_0000or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.allow" id="oval:ssg-object_file_permissions_cron_allow_0:obj:1" version="1">
          <unix:filepath>/etc/cron.allow</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__cron_allow:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_cron_allow_0_mode_0640or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.d/" id="oval:ssg-object_file_permissions_cron_d_0:obj:1" version="1">
          <unix:path>/etc/cron.d</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__cron_d:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_cron_d_0_mode_0700or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.daily/" id="oval:ssg-object_file_permissions_cron_daily_0:obj:1" version="1">
          <unix:path>/etc/cron.daily</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__cron_daily:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_cron_daily_0_mode_0700or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.hourly/" id="oval:ssg-object_file_permissions_cron_hourly_0:obj:1" version="1">
          <unix:path>/etc/cron.hourly</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__cron_hourly:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_cron_hourly_0_mode_0700or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.monthly/" id="oval:ssg-object_file_permissions_cron_monthly_0:obj:1" version="1">
          <unix:path>/etc/cron.monthly</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__cron_monthly:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_cron_monthly_0_mode_0700or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.weekly/" id="oval:ssg-object_file_permissions_cron_weekly_0:obj:1" version="1">
          <unix:path>/etc/cron.weekly</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__cron_weekly:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_cron_weekly_0_mode_0700or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/cron.yearly/" id="oval:ssg-object_file_permissions_cron_yearly_0:obj:1" version="1">
          <unix:path>/etc/cron.yearly</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__cron_yearly:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_cron_yearly_0_mode_0700or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/crontab" id="oval:ssg-object_file_permissions_crontab_0:obj:1" version="1">
          <unix:filepath>/etc/crontab</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__crontab:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_crontab_0_mode_0600or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/boot/efi/EFI/almalinux/grub.cfg" id="oval:ssg-object_file_permissions_efi_grub2_cfg_0:obj:1" version="1">
          <unix:filepath>/boot/efi/EFI/almalinux/grub.cfg</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__efi_grub2_cfg:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_efi_grub2_cfg_0_mode_0700or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/boot/efi/EFI/almalinux/user.cfg" id="oval:ssg-object_file_permissions_efi_user_cfg_0:obj:1" version="1">
          <unix:filepath>/boot/efi/EFI/almalinux/user.cfg</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__efi_user_cfg:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_efi_user_cfg_0_mode_0700or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/audit/auditd.conf" id="oval:ssg-object_file_permissions_etc_audit_auditd_0:obj:1" version="1">
          <unix:filepath>/etc/audit/auditd.conf</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_audit_auditd:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_audit_auditd_0_mode_0640or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/audit/rules.d/" id="oval:ssg-object_file_permissions_etc_audit_rulesd_0:obj:1" version="1">
          <unix:path>/etc/audit/rules.d</unix:path>
          <unix:filename operation="pattern match">^.*rules$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_audit_rulesd:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_audit_rulesd_0_mode_0600or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/chrony.keys" id="oval:ssg-object_file_permissions_etc_chrony_keys_0:obj:1" version="1">
          <unix:filepath>/etc/chrony.keys</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_chrony_keys:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_chrony_keys_0_mode_0640or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/crypttab" id="oval:ssg-object_file_permissions_etc_crypttab_0:obj:1" version="1">
          <unix:filepath>/etc/crypttab</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_crypttab:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_crypttab_0_mode_0600or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/group" id="oval:ssg-object_file_permissions_etc_group_0:obj:1" version="1">
          <unix:filepath>/etc/group</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_group:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_group_0_mode_0644or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/gshadow" id="oval:ssg-object_file_permissions_etc_gshadow_0:obj:1" version="1">
          <unix:filepath>/etc/gshadow</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_gshadow:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_gshadow_0_mode_0000or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/ipsec.conf" id="oval:ssg-object_file_permissions_etc_ipsec_conf_0:obj:1" version="1">
          <unix:filepath>/etc/ipsec.conf</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_ipsec_conf:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_ipsec_conf_0_mode_0644or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/ipsec.secrets" id="oval:ssg-object_file_permissions_etc_ipsec_secrets_0:obj:1" version="1">
          <unix:filepath>/etc/ipsec.secrets</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_ipsec_secrets:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_ipsec_secrets_0_mode_0644or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/issue" id="oval:ssg-object_file_permissions_etc_issue_0:obj:1" version="1">
          <unix:filepath>/etc/issue</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_issue:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_issue_0_mode_0644or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/issue.net" id="oval:ssg-object_file_permissions_etc_issue_net_0:obj:1" version="1">
          <unix:filepath>/etc/issue.net</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_issue_net:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_issue_net_0_mode_0644or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/motd" id="oval:ssg-object_file_permissions_etc_motd_0:obj:1" version="1">
          <unix:filepath>/etc/motd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_motd:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_motd_0_mode_0644or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/passwd" id="oval:ssg-object_file_permissions_etc_passwd_0:obj:1" version="1">
          <unix:filepath>/etc/passwd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_passwd:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_passwd_0_mode_0644or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/security/opasswd" id="oval:ssg-object_file_permissions_etc_security_opasswd_0:obj:1" version="1">
          <unix:filepath>/etc/security/opasswd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_security_opasswd:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_security_opasswd_0_mode_0600or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/security/opasswd.old" id="oval:ssg-object_file_permissions_etc_security_opasswd_old_0:obj:1" version="1">
          <unix:filepath>/etc/security/opasswd.old</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_security_opasswd_old:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_security_opasswd_old_0_mode_0600or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/sestatus.conf" id="oval:ssg-object_file_permissions_etc_sestatus_conf_0:obj:1" version="1">
          <unix:filepath>/etc/sestatus.conf</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_sestatus_conf:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_sestatus_conf_0_mode_0644or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/shadow" id="oval:ssg-object_file_permissions_etc_shadow_0:obj:1" version="1">
          <unix:filepath>/etc/shadow</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_shadow:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_shadow_0_mode_0000or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/shells" id="oval:ssg-object_file_permissions_etc_shells_0:obj:1" version="1">
          <unix:filepath>/etc/shells</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_shells:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_shells_0_mode_0644or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/sudoers" id="oval:ssg-object_file_permissions_etc_sudoers_0:obj:1" version="1">
          <unix:filepath>/etc/sudoers</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_sudoers:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_sudoers_0_mode_0440or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/sysconfig/sshd" id="oval:ssg-object_file_permissions_etc_sysconfig_sshd_0:obj:1" version="1">
          <unix:filepath>/etc/sysconfig/sshd</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_sysconfig_sshd:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_sysconfig_sshd_0_mode_0640or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/boot/grub2/grub.cfg" id="oval:ssg-object_file_permissions_grub2_cfg_0:obj:1" version="1">
          <unix:filepath>/boot/grub2/grub.cfg</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__grub2_cfg:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_grub2_cfg_0_mode_0600or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/lib/" id="oval:ssg-object_file_permissions_library_dirs_0:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/lib</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__library_dirs:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_library_dirs_0_mode_7755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/lib64/" id="oval:ssg-object_file_permissions_library_dirs_1:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/lib64</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__library_dirs:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_library_dirs_1_mode_7755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/lib/" id="oval:ssg-object_file_permissions_library_dirs_2:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/lib</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__library_dirs:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_library_dirs_2_mode_7755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/lib64/" id="oval:ssg-object_file_permissions_library_dirs_3:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/lib64</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__library_dirs:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_library_dirs_3_mode_7755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/ssh/sshd_config" id="oval:ssg-object_file_permissions_sshd_config_0:obj:1" version="1">
          <unix:filepath>/etc/ssh/sshd_config</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__sshd_config:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_sshd_config_0_mode_0600or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/etc/ssh/" id="oval:ssg-object_file_permissions_sshd_pub_key_0:obj:1" version="1">
          <unix:path>/etc/ssh</unix:path>
          <unix:filename operation="pattern match">^.*\.pub$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__sshd_pub_key:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_sshd_pub_key_0_mode_0644or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/bin/sudo" id="oval:ssg-object_file_permissions_sudo_0:obj:1" version="1">
          <unix:filepath>/usr/bin/sudo</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__sudo:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_sudo_0_mode_4110:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/boot/" id="oval:ssg-object_file_permissions_systemmap_0:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^.*System\.map.*$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__systemmap:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_systemmap_0_mode_0600or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/boot/grub2/user.cfg" id="oval:ssg-object_file_permissions_user_cfg_0:obj:1" version="1">
          <unix:filepath>/boot/grub2/user.cfg</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__user_cfg:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_user_cfg_0_mode_0600or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/" id="oval:ssg-object_file_permissions_var_log_0:obj:1" version="1">
          <unix:path>/var/log</unix:path>
          <unix:filename xsi:nil="true"/>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__var_log:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_var_log_0_mode_0755or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/messages" id="oval:ssg-object_file_permissions_var_log_messages_0:obj:1" version="1">
          <unix:filepath>/var/log/messages</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__var_log_messages:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_var_log_messages_0_mode_0600or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/var/log/syslog" id="oval:ssg-object_file_permissions_var_log_syslog_0:obj:1" version="1">
          <unix:filepath>/var/log/syslog</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__var_log_syslog:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissions_var_log_syslog_0_mode_0640or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_firewalld-backend:obj:1" version="1">
          <ind:filepath>/etc/firewalld/firewalld.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*FirewallBackend=(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_audit_argument:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_audit_argument_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_audit_backlog_limit_argument:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_audit_backlog_limit_argument_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_iommu_argument:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_iommu_argument_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_init_on_free_argument:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_init_on_free_argument_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_ipv6_disable_argument:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_ipv6_disable_argument_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_l1tf_argument:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_l1tf_argument_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_mce_argument:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_mce_argument_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_nosmap_argument_absent:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(?!.*\bnosmap\b.*).*"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_nosmap_argument_absent_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(?!.*\bnosmap\b).*"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_nosmep_argument_absent:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(?!.*\bnosmep\b.*).*"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_nosmep_argument_absent_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(?!.*\bnosmep\b).*"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_nousb_argument:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_nousb_argument_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_page_poison_argument:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_page_poison_argument_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_pti_argument:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_pti_argument_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_rng_core_default_quality_argument:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_rng_core_default_quality_argument_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_slab_nomerge_argument:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_slab_nomerge_argument_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_slub_debug_argument:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_slub_debug_argument_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_spec_store_bypass_disable_argument:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_spec_store_bypass_disable_argument_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_spectre_v2_argument:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_spectre_v2_argument_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_systemd_debug_shell_argument_absent:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(?!.*\bsystemd.debug-shell\b.*).*"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_systemd_debug_shell_argument_absent_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(?!.*\bsystemd.debug-shell\b).*"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_vsyscall_argument:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_vsyscall_argument_default:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT="(.*)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_openssl-pkcs11_installed:obj:1" version="1">
          <linux:name>openssl-pkcs11</linux:name>
        </linux:rpminfo_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_journald_compress:obj:1" version="1">
          <ind:filepath>/etc/systemd/journald.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*Compress=(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_journald_disable_forward_to_syslog:obj:1" version="1">
          <ind:filepath>/etc/systemd/journald.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*ForwardToSyslog=(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_journald_forward_to_syslog:obj:1" version="1">
          <ind:filepath>/etc/systemd/journald.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*ForwardToSyslog=(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_journald_storage:obj:1" version="1">
          <ind:filepath>/etc/systemd/journald.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*Storage=(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_acpi_custom_method:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_ACPI_CUSTOM_METHOD="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_acpi_custom_method_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_acpi_custom_method_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_acpi_custom_method_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_arm64_sw_ttbr0_pan:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_ARM64_SW_TTBR0_PAN="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_arm64_sw_ttbr0_pan_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_arm64_sw_ttbr0_pan_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_arm64_sw_ttbr0_pan_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_binfmt_misc:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_BINFMT_MISC="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_binfmt_misc_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_binfmt_misc_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_binfmt_misc_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_bug:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_BUG="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_bug_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_bug_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_bug_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_bug_on_data_corruption:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_BUG_ON_DATA_CORRUPTION="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_bug_on_data_corruption_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_bug_on_data_corruption_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_bug_on_data_corruption_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_compat_brk:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_COMPAT_BRK="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_compat_brk_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_compat_brk_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_compat_brk_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_compat_vdso:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_COMPAT_VDSO="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_compat_vdso_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_compat_vdso_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_compat_vdso_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_debug_credentials:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_DEBUG_CREDENTIALS="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_debug_credentials_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_debug_credentials_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_debug_credentials_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_debug_fs:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_DEBUG_FS="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_debug_fs_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_debug_fs_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_debug_fs_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_debug_list:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_DEBUG_LIST="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_debug_list_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_debug_list_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_debug_list_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_debug_notifiers:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_DEBUG_NOTIFIERS="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_debug_notifiers_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_debug_notifiers_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_debug_notifiers_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_debug_sg:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_DEBUG_SG="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_debug_sg_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_debug_sg_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_debug_sg_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_debug_wx:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_DEBUG_WX="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_debug_wx_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_debug_wx_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_debug_wx_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_devkmem:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_DEVKMEM="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_devkmem_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_devkmem_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_devkmem_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_fortify_source:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_FORTIFY_SOURCE="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_fortify_source_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_fortify_source_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_fortify_source_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_gcc_plugin_latent_entropy:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_GCC_PLUGIN_LATENT_ENTROPY="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_gcc_plugin_latent_entropy_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_gcc_plugin_latent_entropy_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_gcc_plugin_latent_entropy_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_gcc_plugin_structleak:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_GCC_PLUGIN_STRUCTLEAK="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_gcc_plugin_structleak_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_gcc_plugin_structleak_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_gcc_plugin_structleak_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_hardened_usercopy:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_HARDENED_USERCOPY="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_hardened_usercopy_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_hardened_usercopy_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_hardened_usercopy_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_hardened_usercopy_fallback:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_HARDENED_USERCOPY_FALLBACK="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_hardened_usercopy_fallback_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_hardened_usercopy_fallback_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_hardened_usercopy_fallback_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_hibernation:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_HIBERNATION="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_hibernation_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_hibernation_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_hibernation_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_ia32_emulation:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_IA32_EMULATION="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_ia32_emulation_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_ia32_emulation_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_ia32_emulation_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_ipv6:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_IPV6="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_ipv6_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_ipv6_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_ipv6_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_kexec:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_KEXEC="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_kexec_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_kexec_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_kexec_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_legacy_ptys:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_LEGACY_PTYS="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_legacy_ptys_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_legacy_ptys_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_legacy_ptys_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_legacy_vsyscall_emulate:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_LEGACY_VSYSCALL_EMULATE="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_legacy_vsyscall_emulate_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_legacy_vsyscall_emulate_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_legacy_vsyscall_emulate_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_legacy_vsyscall_none:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_LEGACY_VSYSCALL_NONE="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_legacy_vsyscall_none_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_legacy_vsyscall_none_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_legacy_vsyscall_none_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_modify_ldt_syscall:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_MODIFY_LDT_SYSCALL="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_modify_ldt_syscall_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_modify_ldt_syscall_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_modify_ldt_syscall_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_module_sig:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_MODULE_SIG="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_module_sig_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_module_sig_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_module_sig_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_module_sig_all:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_MODULE_SIG_ALL="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_module_sig_all_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_module_sig_all_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_module_sig_all_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_module_sig_force:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_MODULE_SIG_FORCE="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_module_sig_force_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_module_sig_force_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_module_sig_force_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_module_sig_hash:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_MODULE_SIG_HASH="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_module_sig_hash_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_module_sig_hash_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_module_sig_hash_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_module_sig_key:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_MODULE_SIG_KEY="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_module_sig_key_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_module_sig_key_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_module_sig_key_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_module_sig_sha512:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_MODULE_SIG_SHA512="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_module_sig_sha512_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_module_sig_sha512_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_module_sig_sha512_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_page_poisoning:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_PAGE_POISONING="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_page_poisoning_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_page_poisoning_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_page_poisoning_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_page_poisoning_no_sanity:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_PAGE_POISONING_NO_SANITY="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_page_poisoning_no_sanity_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_page_poisoning_no_sanity_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_page_poisoning_no_sanity_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_page_poisoning_zero:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_PAGE_POISONING_ZERO="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_page_poisoning_zero_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_page_poisoning_zero_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_page_poisoning_zero_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_page_table_isolation:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_PAGE_TABLE_ISOLATION="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_page_table_isolation_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_page_table_isolation_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_page_table_isolation_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_panic_on_oops:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_PANIC_ON_OOPS="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_panic_on_oops_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_panic_on_oops_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_panic_on_oops_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_panic_timeout:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_PANIC_TIMEOUT="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_panic_timeout_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_panic_timeout_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_panic_timeout_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_proc_kcore:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_PROC_KCORE="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_proc_kcore_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_proc_kcore_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_proc_kcore_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_randomize_base:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_RANDOMIZE_BASE="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_randomize_base_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_randomize_base_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_randomize_base_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_randomize_memory:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_RANDOMIZE_MEMORY="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_randomize_memory_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_randomize_memory_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_randomize_memory_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_refcount_full:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_REFCOUNT_FULL="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_refcount_full_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_refcount_full_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_refcount_full_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_retpoline:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_RETPOLINE="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_retpoline_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_retpoline_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_retpoline_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_sched_stack_end_check:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_SCHED_STACK_END_CHECK="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_sched_stack_end_check_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_sched_stack_end_check_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_sched_stack_end_check_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_seccomp:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_SECCOMP="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_seccomp_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_seccomp_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_seccomp_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_seccomp_filter:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_SECCOMP_FILTER="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_seccomp_filter_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_seccomp_filter_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_seccomp_filter_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_security:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_SECURITY="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_security_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_security_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_security_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_security_dmesg_restrict:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_SECURITY_DMESG_RESTRICT="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_security_dmesg_restrict_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_security_dmesg_restrict_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_security_dmesg_restrict_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_security_writable_hooks:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_SECURITY_WRITABLE_HOOKS="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_security_writable_hooks_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_security_writable_hooks_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_security_writable_hooks_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_security_yama:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_SECURITY_YAMA="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_security_yama_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_security_yama_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_security_yama_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_slab_freelist_hardened:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_SLAB_FREELIST_HARDENED="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_slab_freelist_hardened_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_slab_freelist_hardened_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_slab_freelist_hardened_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_slab_freelist_random:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_SLAB_FREELIST_RANDOM="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_slab_freelist_random_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_slab_freelist_random_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_slab_freelist_random_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_slab_merge_default:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_SLAB_MERGE_DEFAULT="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_slab_merge_default_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_slab_merge_default_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_slab_merge_default_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_slub_debug:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_SLUB_DEBUG="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_slub_debug_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_slub_debug_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_slub_debug_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_stackprotector:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_STACKPROTECTOR="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_stackprotector_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_stackprotector_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_stackprotector_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_stackprotector_strong:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_STACKPROTECTOR_STRONG="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_stackprotector_strong_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_stackprotector_strong_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_stackprotector_strong_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_strict_kernel_rwx:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_STRICT_KERNEL_RWX="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_strict_kernel_rwx_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_strict_kernel_rwx_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_strict_kernel_rwx_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_strict_module_rwx:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_STRICT_MODULE_RWX="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_strict_module_rwx_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_strict_module_rwx_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_strict_module_rwx_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_syn_cookies:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_SYN_COOKIES="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_syn_cookies_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_syn_cookies_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_syn_cookies_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_unmap_kernel_at_el0:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_UNMAP_KERNEL_AT_EL0="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_unmap_kernel_at_el0_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_unmap_kernel_at_el0_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_unmap_kernel_at_el0_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_vmap_stack:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_VMAP_STACK="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_vmap_stack_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_vmap_stack_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_vmap_stack_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_kernel_config_x86_vsyscall_emulation:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/config-.*$</ind:filepath>
          <ind:pattern operation="pattern match">^CONFIG_X86_VSYSCALL_EMULATION="?(.*?)"?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_kernel_config_x86_vsyscall_emulation_count:obj:1" version="1">
          <ind:var_ref>oval:ssg-local_var_config_x86_vsyscall_emulation_count_kernels_installed:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:file_object comment="Collect the kernel config files" id="oval:ssg-object_kernel_config_x86_vsyscall_emulation_files:obj:1" version="1">
          <unix:path>/boot</unix:path>
          <unix:filename operation="pattern match">^config-.*$</unix:filename>
        </unix:file_object>
        <ind:textfilecontent54_object comment="kernel module atm disabled" id="oval:ssg-obj_kernmod_atm_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_atm_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+atm\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of atm" id="oval:ssg-obj_kernmod_atm_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+atm\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module bluetooth disabled" id="oval:ssg-obj_kernmod_bluetooth_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_bluetooth_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+bluetooth\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of bluetooth" id="oval:ssg-obj_kernmod_bluetooth_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+bluetooth\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module can disabled" id="oval:ssg-obj_kernmod_can_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_can_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+can\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of can" id="oval:ssg-obj_kernmod_can_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+can\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module cfg80211 disabled" id="oval:ssg-obj_kernmod_cfg80211_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_cfg80211_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+cfg80211\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of cfg80211" id="oval:ssg-obj_kernmod_cfg80211_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+cfg80211\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module cramfs disabled" id="oval:ssg-obj_kernmod_cramfs_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_cramfs_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+cramfs\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of cramfs" id="oval:ssg-obj_kernmod_cramfs_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+cramfs\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module dccp disabled" id="oval:ssg-obj_kernmod_dccp_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_dccp_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+dccp\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of dccp" id="oval:ssg-obj_kernmod_dccp_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+dccp\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module firewire-core disabled" id="oval:ssg-obj_kernmod_firewire-core_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_firewire-core_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+firewire-core\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of firewire-core" id="oval:ssg-obj_kernmod_firewire-core_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+firewire-core\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module freevxfs disabled" id="oval:ssg-obj_kernmod_freevxfs_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_freevxfs_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+freevxfs\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of freevxfs" id="oval:ssg-obj_kernmod_freevxfs_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+freevxfs\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module hfs disabled" id="oval:ssg-obj_kernmod_hfs_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_hfs_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+hfs\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of hfs" id="oval:ssg-obj_kernmod_hfs_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+hfs\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module hfsplus disabled" id="oval:ssg-obj_kernmod_hfsplus_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_hfsplus_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+hfsplus\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of hfsplus" id="oval:ssg-obj_kernmod_hfsplus_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+hfsplus\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module iwlmvm disabled" id="oval:ssg-obj_kernmod_iwlmvm_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_iwlmvm_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+iwlmvm\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of iwlmvm" id="oval:ssg-obj_kernmod_iwlmvm_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+iwlmvm\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module iwlwifi disabled" id="oval:ssg-obj_kernmod_iwlwifi_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_iwlwifi_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+iwlwifi\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of iwlwifi" id="oval:ssg-obj_kernmod_iwlwifi_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+iwlwifi\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module jffs2 disabled" id="oval:ssg-obj_kernmod_jffs2_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_jffs2_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+jffs2\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of jffs2" id="oval:ssg-obj_kernmod_jffs2_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+jffs2\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module mac80211 disabled" id="oval:ssg-obj_kernmod_mac80211_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_mac80211_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+mac80211\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of mac80211" id="oval:ssg-obj_kernmod_mac80211_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+mac80211\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module overlayfs disabled" id="oval:ssg-obj_kernmod_overlayfs_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_overlayfs_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+overlayfs\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of overlayfs" id="oval:ssg-obj_kernmod_overlayfs_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+overlayfs\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module rds disabled" id="oval:ssg-obj_kernmod_rds_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_rds_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+rds\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of rds" id="oval:ssg-obj_kernmod_rds_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+rds\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module sctp disabled" id="oval:ssg-obj_kernmod_sctp_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_sctp_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+sctp\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of sctp" id="oval:ssg-obj_kernmod_sctp_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+sctp\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module squashfs disabled" id="oval:ssg-obj_kernmod_squashfs_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_squashfs_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+squashfs\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of squashfs" id="oval:ssg-obj_kernmod_squashfs_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+squashfs\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module tipc disabled" id="oval:ssg-obj_kernmod_tipc_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_tipc_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+tipc\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of tipc" id="oval:ssg-obj_kernmod_tipc_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+tipc\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module udf disabled" id="oval:ssg-obj_kernmod_udf_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_udf_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+udf\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of udf" id="oval:ssg-obj_kernmod_udf_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+udf\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module usb-storage disabled" id="oval:ssg-obj_kernmod_usb-storage_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_usb-storage_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+usb-storage\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of usb-storage" id="oval:ssg-obj_kernmod_usb-storage_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+usb-storage\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module uvcvideo disabled" id="oval:ssg-obj_kernmod_uvcvideo_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_uvcvideo_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+uvcvideo\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of uvcvideo" id="oval:ssg-obj_kernmod_uvcvideo_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+uvcvideo\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="kernel module vfat disabled" id="oval:ssg-obj_kernmod_vfat_disabled:obj:1" version="1">
          <ind:path var_check="at least one" var_ref="oval:ssg-var_kernel_module_vfat_paths:var:1"/>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^\s*install\s+vfat\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check deprecated /etc/modprobe.conf for disablement of vfat" id="oval:ssg-obj_kernmod_vfat_modprobeconf:obj:1" version="1">
          <ind:filepath>/etc/modprobe.conf</ind:filepath>
          <ind:pattern operation="pattern match">^\s*install\s+vfat\s+(/bin/false|/bin/true)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_boot_efi_partition_nosuid_optional:obj:1" version="1">
          <linux:mount_point>/boot/efi</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_boot_efi_partition_nosuid_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/boot/efi[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_boot_partition_noauto_optional:obj:1" version="1">
          <linux:mount_point>/boot</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_boot_partition_noauto_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/boot[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_boot_partition_nodev_optional:obj:1" version="1">
          <linux:mount_point>/boot</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_boot_partition_nodev_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/boot[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_boot_partition_noexec_optional:obj:1" version="1">
          <linux:mount_point>/boot</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_boot_partition_noexec_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/boot[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_boot_partition_nosuid_optional:obj:1" version="1">
          <linux:mount_point>/boot</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_boot_partition_nosuid_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/boot[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_dev_shm_partition_nodev_expected:obj:1" version="1">
          <linux:mount_point>/dev/shm</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_dev_shm_partition_nodev_expected_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/dev/shm[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_dev_shm_partition_noexec_expected:obj:1" version="1">
          <linux:mount_point>/dev/shm</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_dev_shm_partition_noexec_expected_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/dev/shm[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_dev_shm_partition_nosuid_expected:obj:1" version="1">
          <linux:mount_point>/dev/shm</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_dev_shm_partition_nosuid_expected_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/dev/shm[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_home_partition_grpquota_optional:obj:1" version="1">
          <linux:mount_point>/home</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_home_partition_grpquota_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/home[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_home_partition_nodev_optional:obj:1" version="1">
          <linux:mount_point>/home</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_home_partition_nodev_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/home[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_home_partition_noexec_optional:obj:1" version="1">
          <linux:mount_point>/home</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_home_partition_noexec_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/home[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_home_partition_nosuid_optional:obj:1" version="1">
          <linux:mount_point>/home</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_home_partition_nosuid_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/home[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_home_partition_usrquota_optional:obj:1" version="1">
          <linux:mount_point>/home</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_home_partition_usrquota_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/home[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_nfs_sec_krb5_krb5i_krb5p_etc_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\[?[\.\w:-]+\]?[:=][/\w-]+\s+[/\w\\-]+\s+nfs[4]?\s+(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="not equal">0</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_nfs_nodev_etc_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\[?[\.\w:-]+\]?[:=][/\w-]+\s+[/\w\\-]+\s+nfs[4]?\s+(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="not equal">0</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_nodev_etc_fstab_cd_dvd_drive:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern datatype="string" operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_cd_dvd_drive_regex_pattern_nodev:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_nodev_etc_fstab_not_cd_dvd_drive:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern datatype="string" operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_not_cd_dvd_drive_regex_pattern_nodev:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_nfs_noexec_etc_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\[?[\.\w:-]+\]?[:=][/\w-]+\s+[/\w\\-]+\s+nfs[4]?\s+(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="not equal">0</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_noexec_etc_fstab_cd_dvd_drive:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern datatype="string" operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_cd_dvd_drive_regex_pattern_noexec:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_noexec_etc_fstab_not_cd_dvd_drive:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern datatype="string" operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_not_cd_dvd_drive_regex_pattern_noexec:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_nfs_nosuid_etc_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\[?[\.\w:-]+\]?[:=][/\w-]+\s+[/\w\\-]+\s+nfs[4]?\s+(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="not equal">0</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_nosuid_etc_fstab_cd_dvd_drive:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern datatype="string" operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_cd_dvd_drive_regex_pattern_nosuid:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_nosuid_etc_fstab_not_cd_dvd_drive:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern datatype="string" operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_not_cd_dvd_drive_regex_pattern_nosuid:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_opt_partition_nosuid_optional:obj:1" version="1">
          <linux:mount_point>/opt</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_opt_partition_nosuid_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/opt[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_proc_partition_hidepid_expected:obj:1" version="1">
          <linux:mount_point>/proc</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_proc_partition_hidepid_expected_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/proc[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_srv_partition_nosuid_optional:obj:1" version="1">
          <linux:mount_point>/srv</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_srv_partition_nosuid_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/srv[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_tmp_partition_nodev_optional:obj:1" version="1">
          <linux:mount_point>/tmp</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_tmp_partition_nodev_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/tmp[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_tmp_partition_noexec_optional:obj:1" version="1">
          <linux:mount_point>/tmp</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_tmp_partition_noexec_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/tmp[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_tmp_partition_nosuid_optional:obj:1" version="1">
          <linux:mount_point>/tmp</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_tmp_partition_nosuid_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/tmp[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_var_log_audit_partition_nodev_optional:obj:1" version="1">
          <linux:mount_point>/var/log/audit</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_var_log_audit_partition_nodev_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/var/log/audit[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_var_log_audit_partition_noexec_optional:obj:1" version="1">
          <linux:mount_point>/var/log/audit</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_var_log_audit_partition_noexec_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/var/log/audit[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_var_log_audit_partition_nosuid_optional:obj:1" version="1">
          <linux:mount_point>/var/log/audit</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_var_log_audit_partition_nosuid_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/var/log/audit[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_var_log_partition_nodev_optional:obj:1" version="1">
          <linux:mount_point>/var/log</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_var_log_partition_nodev_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/var/log[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_var_log_partition_noexec_optional:obj:1" version="1">
          <linux:mount_point>/var/log</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_var_log_partition_noexec_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/var/log[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_var_log_partition_nosuid_optional:obj:1" version="1">
          <linux:mount_point>/var/log</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_var_log_partition_nosuid_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/var/log[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_var_partition_nodev_optional:obj:1" version="1">
          <linux:mount_point>/var</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_var_partition_nodev_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/var[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_var_partition_noexec_optional:obj:1" version="1">
          <linux:mount_point>/var</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_var_partition_noexec_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/var[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_var_partition_nosuid_optional:obj:1" version="1">
          <linux:mount_point>/var</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_var_partition_nosuid_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/var[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_var_tmp_partition_nodev_optional:obj:1" version="1">
          <linux:mount_point>/var/tmp</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_var_tmp_partition_nodev_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/var/tmp[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_var_tmp_partition_noexec_optional:obj:1" version="1">
          <linux:mount_point>/var/tmp</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_var_tmp_partition_noexec_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/var/tmp[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_var_tmp_partition_nosuid_optional:obj:1" version="1">
          <linux:mount_point>/var/tmp</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_var_tmp_partition_nosuid_optional_in_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*(?!#)[\S]+[\s]+/var/tmp[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_389-ds-base_removed:obj:1" version="1">
          <linux:name>389-ds-base</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_MFEhiplsm_installed:obj:1" version="1">
          <linux:name>MFEhiplsm</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_abrt-addon-ccpp_removed:obj:1" version="1">
          <linux:name>abrt-addon-ccpp</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_abrt-addon-kerneloops_removed:obj:1" version="1">
          <linux:name>abrt-addon-kerneloops</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_abrt-cli_removed:obj:1" version="1">
          <linux:name>abrt-cli</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_abrt-plugin-logger_removed:obj:1" version="1">
          <linux:name>abrt-plugin-logger</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_abrt-plugin-rhtsupport_removed:obj:1" version="1">
          <linux:name>abrt-plugin-rhtsupport</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_abrt-plugin-sosreport_removed:obj:1" version="1">
          <linux:name>abrt-plugin-sosreport</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_abrt_removed:obj:1" version="1">
          <linux:name>abrt</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_aide_installed:obj:1" version="1">
          <linux:name>aide</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_audispd-plugins_installed:obj:1" version="1">
          <linux:name>audispd-plugins</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_audit-audispd-plugins_installed:obj:1" version="1">
          <linux:name>audit-audispd-plugins</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_audit-libs_installed:obj:1" version="1">
          <linux:name>audit-libs</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_audit_installed:obj:1" version="1">
          <linux:name>audit</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_authselect_installed:obj:1" version="1">
          <linux:name>authselect</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_avahi-autoipd_removed:obj:1" version="1">
          <linux:name>avahi-autoipd</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_avahi_removed:obj:1" version="1">
          <linux:name>avahi</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_bind_removed:obj:1" version="1">
          <linux:name>bind</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_binutils_installed:obj:1" version="1">
          <linux:name>binutils</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_chrony_installed:obj:1" version="1">
          <linux:name>chrony</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_cron_installed:obj:1" version="1">
          <linux:name>cron</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_crypto-policies_installed:obj:1" version="1">
          <linux:name>crypto-policies</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_cups_removed:obj:1" version="1">
          <linux:name>cups</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_cyrus-imapd_removed:obj:1" version="1">
          <linux:name>cyrus-imapd</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_dconf_installed:obj:1" version="1">
          <linux:name>dconf</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_dhcp_removed:obj:1" version="1">
          <linux:name>dhcp</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_dnf-automatic_installed:obj:1" version="1">
          <linux:name>dnf-automatic</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_dnf-plugin-subscription-manager_installed:obj:1" version="1">
          <linux:name>dnf-plugin-subscription-manager</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_dnsmasq_removed:obj:1" version="1">
          <linux:name>dnsmasq</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_dovecot_removed:obj:1" version="1">
          <linux:name>dovecot</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_fapolicyd_installed:obj:1" version="1">
          <linux:name>fapolicyd</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_firewalld_installed:obj:1" version="1">
          <linux:name>firewalld</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_freeradius_removed:obj:1" version="1">
          <linux:name>freeradius</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_ftp_removed:obj:1" version="1">
          <linux:name>ftp</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_gdm_installed:obj:1" version="1">
          <linux:name>gdm</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_gdm_removed:obj:1" version="1">
          <linux:name>gdm</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_geolite2-city_removed:obj:1" version="1">
          <linux:name>geolite2-city</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_geolite2-country_removed:obj:1" version="1">
          <linux:name>geolite2-country</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_gnutls-utils_installed:obj:1" version="1">
          <linux:name>gnutls-utils</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_gssproxy_removed:obj:1" version="1">
          <linux:name>gssproxy</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_httpd_removed:obj:1" version="1">
          <linux:name>httpd</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_inetutils-telnetd_removed:obj:1" version="1">
          <linux:name>inetutils-telnetd</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_iprutils_removed:obj:1" version="1">
          <linux:name>iprutils</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_iptables-services_installed:obj:1" version="1">
          <linux:name>iptables-services</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_iptables-services_removed:obj:1" version="1">
          <linux:name>iptables-services</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_iptables_installed:obj:1" version="1">
          <linux:name>iptables</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_krb5-server_removed:obj:1" version="1">
          <linux:name>krb5-server</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_krb5-workstation_removed:obj:1" version="1">
          <linux:name>krb5-workstation</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_libcap-ng-utils_installed:obj:1" version="1">
          <linux:name>libcap-ng-utils</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_libreport-plugin-logger_removed:obj:1" version="1">
          <linux:name>libreport-plugin-logger</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_libreport-plugin-rhtsupport_removed:obj:1" version="1">
          <linux:name>libreport-plugin-rhtsupport</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_libreswan_installed:obj:1" version="1">
          <linux:name>libreswan</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_libselinux_installed:obj:1" version="1">
          <linux:name>libselinux</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_logrotate_installed:obj:1" version="1">
          <linux:name>logrotate</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_mailx_installed:obj:1" version="1">
          <linux:name>mailx</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_McAfeeTP_installed:obj:1" version="1">
          <linux:name>McAfeeTP</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_mcstrans_removed:obj:1" version="1">
          <linux:name>mcstrans</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_net-snmp_removed:obj:1" version="1">
          <linux:name>net-snmp</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_nfs-utils_removed:obj:1" version="1">
          <linux:name>nfs-utils</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_nftables_installed:obj:1" version="1">
          <linux:name>nftables</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_nginx_removed:obj:1" version="1">
          <linux:name>nginx</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_nis_removed:obj:1" version="1">
          <linux:name>nis</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_nss-tools_installed:obj:1" version="1">
          <linux:name>nss-tools</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_ntp_installed:obj:1" version="1">
          <linux:name>ntp</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_ntpdate_removed:obj:1" version="1">
          <linux:name>ntpdate</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_openldap-clients_removed:obj:1" version="1">
          <linux:name>openldap-clients</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_openldap-servers_removed:obj:1" version="1">
          <linux:name>openldap-servers</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_opensc_installed:obj:1" version="1">
          <linux:name>opensc</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_openscap-scanner_installed:obj:1" version="1">
          <linux:name>openscap-scanner</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_openssh-clients_installed:obj:1" version="1">
          <linux:name>openssh-clients</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_openssh-server_installed:obj:1" version="1">
          <linux:name>openssh-server</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_openssh-server_removed:obj:1" version="1">
          <linux:name>openssh-server</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_pam_installed:obj:1" version="1">
          <linux:name>pam</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_libpwquality_installed:obj:1" version="1">
          <linux:name>libpwquality</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_pcsc-lite_installed:obj:1" version="1">
          <linux:name>pcsc-lite</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_pigz_removed:obj:1" version="1">
          <linux:name>pigz</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_policycoreutils-python-utils_installed:obj:1" version="1">
          <linux:name>policycoreutils-python-utils</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_policycoreutils_installed:obj:1" version="1">
          <linux:name>policycoreutils</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_postfix_installed:obj:1" version="1">
          <linux:name>postfix</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_psacct_installed:obj:1" version="1">
          <linux:name>psacct</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_python3-abrt-addon_removed:obj:1" version="1">
          <linux:name>python3-abrt-addon</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_quagga_removed:obj:1" version="1">
          <linux:name>quagga</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_rear_installed:obj:1" version="1">
          <linux:name>rear</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_rng-tools_installed:obj:1" version="1">
          <linux:name>rng-tools</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_rpcbind_removed:obj:1" version="1">
          <linux:name>rpcbind</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_rsh-server_removed:obj:1" version="1">
          <linux:name>rsh-server</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_rsh_removed:obj:1" version="1">
          <linux:name>rsh</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_rsync_removed:obj:1" version="1">
          <linux:name>rsync</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_rsyslog-gnutls_installed:obj:1" version="1">
          <linux:name>rsyslog-gnutls</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_rsyslog_installed:obj:1" version="1">
          <linux:name>rsyslog</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_samba-common_installed:obj:1" version="1">
          <linux:name>samba-common</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_samba-common_removed:obj:1" version="1">
          <linux:name>samba-common</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_samba_removed:obj:1" version="1">
          <linux:name>samba</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_scap-security-guide_installed:obj:1" version="1">
          <linux:name>scap-security-guide</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_sendmail_removed:obj:1" version="1">
          <linux:name>sendmail</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_setroubleshoot-plugins_removed:obj:1" version="1">
          <linux:name>setroubleshoot-plugins</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_setroubleshoot-server_removed:obj:1" version="1">
          <linux:name>setroubleshoot-server</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_setroubleshoot_removed:obj:1" version="1">
          <linux:name>setroubleshoot</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_squid_removed:obj:1" version="1">
          <linux:name>squid</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_sssd-ipa_installed:obj:1" version="1">
          <linux:name>sssd-ipa</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_sssd_installed:obj:1" version="1">
          <linux:name>sssd</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_subscription-manager_installed:obj:1" version="1">
          <linux:name>subscription-manager</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_sudo_installed:obj:1" version="1">
          <linux:name>sudo</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_syslog-ng_installed:obj:1" version="1">
          <linux:name>syslog-ng</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_systemd-journal-remote_installed:obj:1" version="1">
          <linux:name>systemd-journal-remote</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_talk-server_removed:obj:1" version="1">
          <linux:name>talk-server</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_talk_removed:obj:1" version="1">
          <linux:name>talk</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_tar_installed:obj:1" version="1">
          <linux:name>tar</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_telnet-server_removed:obj:1" version="1">
          <linux:name>telnet-server</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_telnet_removed:obj:1" version="1">
          <linux:name>telnet</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_telnetd-ssl_removed:obj:1" version="1">
          <linux:name>telnetd-ssl</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_telnetd_removed:obj:1" version="1">
          <linux:name>telnetd</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_tftp-server_removed:obj:1" version="1">
          <linux:name>tftp-server</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_tftp_removed:obj:1" version="1">
          <linux:name>tftp</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_tmux_installed:obj:1" version="1">
          <linux:name>tmux</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_tuned_removed:obj:1" version="1">
          <linux:name>tuned</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_usbguard_installed:obj:1" version="1">
          <linux:name>usbguard</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_vim-enhanced_installed:obj:1" version="1">
          <linux:name>vim-enhanced</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_vsftpd_installed:obj:1" version="1">
          <linux:name>vsftpd</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_vsftpd_removed:obj:1" version="1">
          <linux:name>vsftpd</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_xinetd_removed:obj:1" version="1">
          <linux:name>xinetd</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_ypbind_removed:obj:1" version="1">
          <linux:name>ypbind</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_package_ypserv_removed:obj:1" version="1">
          <linux:name>ypserv</linux:name>
        </linux:rpminfo_object>
        <linux:partition_object id="oval:ssg-object_mountboot_own_partition:obj:1" version="1">
          <linux:mount_point>/boot</linux:mount_point>
        </linux:partition_object>
        <linux:partition_object id="oval:ssg-object_mountdev_shm_own_partition:obj:1" version="1">
          <linux:mount_point>/dev/shm</linux:mount_point>
        </linux:partition_object>
        <linux:partition_object id="oval:ssg-object_mounthome_own_partition:obj:1" version="1">
          <linux:mount_point>/home</linux:mount_point>
        </linux:partition_object>
        <linux:partition_object id="oval:ssg-object_mountopt_own_partition:obj:1" version="1">
          <linux:mount_point>/opt</linux:mount_point>
        </linux:partition_object>
        <linux:partition_object id="oval:ssg-object_mountsrv_own_partition:obj:1" version="1">
          <linux:mount_point>/srv</linux:mount_point>
        </linux:partition_object>
        <linux:partition_object id="oval:ssg-object_mounttmp_own_partition:obj:1" version="1">
          <linux:mount_point>/tmp</linux:mount_point>
        </linux:partition_object>
        <linux:partition_object id="oval:ssg-object_mountusr_own_partition:obj:1" version="1">
          <linux:mount_point>/usr</linux:mount_point>
        </linux:partition_object>
        <linux:partition_object id="oval:ssg-object_mountvar_own_partition:obj:1" version="1">
          <linux:mount_point>/var</linux:mount_point>
        </linux:partition_object>
        <linux:partition_object id="oval:ssg-object_mountvar_log_own_partition:obj:1" version="1">
          <linux:mount_point>/var/log</linux:mount_point>
        </linux:partition_object>
        <linux:partition_object id="oval:ssg-object_mountvar_log_audit_own_partition:obj:1" version="1">
          <linux:mount_point>/var/log/audit</linux:mount_point>
        </linux:partition_object>
        <linux:partition_object id="oval:ssg-object_mountvar_tmp_own_partition:obj:1" version="1">
          <linux:mount_point>/var/tmp</linux:mount_point>
        </linux:partition_object>
        <unix:file_object comment="/lib/" id="oval:ssg-object_file_groupownerroot_permissions_syslibrary_files_0:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/lib</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerroot_permissions_syslibrary_files_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/lib64/" id="oval:ssg-object_file_groupownerroot_permissions_syslibrary_files_1:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/lib64</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerroot_permissions_syslibrary_files_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/lib/" id="oval:ssg-object_file_groupownerroot_permissions_syslibrary_files_2:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/lib</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerroot_permissions_syslibrary_files_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:file_object comment="/usr/lib64/" id="oval:ssg-object_file_groupownerroot_permissions_syslibrary_files_3:obj:1" version="1">
          <unix:behaviors max_depth="-1" recurse="directories" recurse_direction="down" recurse_file_system="local"/>
          <unix:path>/usr/lib64</unix:path>
          <unix:filename operation="pattern match">^.*$</unix:filename>
          <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_groupownerroot_permissions_syslibrary_files_0_0:ste:1</oval-def:filter>
        </unix:file_object>
        <ind:textfilecontent54_object comment="rsyslog's $IncludeConfig and include() statements values." id="oval:ssg-object_rsyslog_files_groupownership_include_config_value:obj:1" version="1">
          <ind:filepath>/etc/rsyslog.conf</ind:filepath>
          <ind:pattern operation="pattern match">^(?:include\([\n\s]*file="([^\s;]+)".*|\$IncludeConfig[\s]+([^\s;]+))$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object comment="Make variable object from regex variable." id="oval:ssg-object_var_rsyslog_files_groupownership_include_config_regex:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_rsyslog_files_groupownership_include_config_regex:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:variable_object comment="Make variable object from local variable." id="oval:ssg-object_var_rsyslog_files_groupownership_syslog_config:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_rsyslog_files_groupownership_syslog_config:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:variable_object comment="Variable containing all rsyslog configuration files." id="oval:ssg-object_var_rsyslog_files_groupownership_all_conf_files:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_var_rsyslog_files_groupownership_include_config_regex:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_var_rsyslog_files_groupownership_syslog_config:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:variable_object>
        <ind:textfilecontent54_object comment="All rsyslog log files collected from rsyslog configuration files." id="oval:ssg-object_rsyslog_files_groupownership_log_files_paths:obj:1" version="1">
          <ind:filepath operation="pattern match" var_check="at least one" var_ref="oval:ssg-var_rsyslog_files_groupownership_all_conf_files:var:1"/>
          <ind:pattern operation="pattern match">^\s*[^#$].*?(?:\b[Ff]ile="([^"\s]+)"|[\s]+-?(\/[^:;\s]+)).*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_rsyslog_files_groupownership_ignore_include_paths:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <unix:file_object comment="All system log files collected from rsyslog configuration files" id="oval:ssg-object_rsyslog_files_groupownership_groupowner:obj:1" version="1">
          <unix:filepath datatype="string" var_check="at least one" var_ref="oval:ssg-var_rsyslog_files_groupownership_log_files_paths:var:1"/>
        </unix:file_object>
        <ind:textfilecontent54_object comment="GID of group root" id="oval:ssg-obj_rsyslog_files_groupownership_groupowner_gid:obj:1" version="1">
          <ind:filepath>/etc/group</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="rsyslog's $IncludeConfig and include() statements values." id="oval:ssg-object_rsyslog_files_ownership_include_config_value:obj:1" version="1">
          <ind:filepath>/etc/rsyslog.conf</ind:filepath>
          <ind:pattern operation="pattern match">^(?:include\([\n\s]*file="([^\s;]+)".*|\$IncludeConfig[\s]+([^\s;]+))$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object comment="Make variable object from regex variable." id="oval:ssg-object_var_rsyslog_files_ownership_include_config_regex:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_rsyslog_files_ownership_include_config_regex:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:variable_object comment="Make variable object from local variable." id="oval:ssg-object_var_rsyslog_files_ownership_syslog_config:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_rsyslog_files_ownership_syslog_config:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:variable_object comment="Variable containing all rsyslog configuration files." id="oval:ssg-object_var_rsyslog_files_ownership_all_conf_files:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_var_rsyslog_files_ownership_include_config_regex:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_var_rsyslog_files_ownership_syslog_config:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:variable_object>
        <ind:textfilecontent54_object comment="All rsyslog log files collected from rsyslog configuration files." id="oval:ssg-object_rsyslog_files_ownership_log_files_paths:obj:1" version="1">
          <ind:filepath operation="pattern match" var_check="at least one" var_ref="oval:ssg-var_rsyslog_files_ownership_all_conf_files:var:1"/>
          <ind:pattern operation="pattern match">^\s*[^#$].*?(?:\b[Ff]ile="([^"\s]+)"|[\s]+-?(\/[^:;\s]+)).*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_rsyslog_files_ownership_ignore_include_paths:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <unix:file_object comment="All system log files collected from rsyslog configuration files" id="oval:ssg-object_rsyslog_files_ownership_owner:obj:1" version="1">
          <unix:filepath datatype="string" var_check="at least one" var_ref="oval:ssg-var_rsyslog_files_ownership_log_files_paths:var:1"/>
        </unix:file_object>
        <ind:textfilecontent54_object comment="UID of user root" id="oval:ssg-obj_rsyslog_files_ownership_owner_uid:obj:1" version="1">
          <ind:filepath>/etc/passwd</ind:filepath>
          <ind:pattern operation="pattern match">^root:\w+:(\w+):.*</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="rsyslog's $IncludeConfig and include() statements values." id="oval:ssg-object_rsyslog_files_permissions_include_config_value:obj:1" version="1">
          <ind:filepath>/etc/rsyslog.conf</ind:filepath>
          <ind:pattern operation="pattern match">^(?:include\([\n\s]*file="([^\s;]+)".*|\$IncludeConfig[\s]+([^\s;]+))$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object comment="Make variable object from regex variable." id="oval:ssg-object_var_rsyslog_files_permissions_include_config_regex:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_rsyslog_files_permissions_include_config_regex:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:variable_object comment="Make variable object from local variable." id="oval:ssg-object_var_rsyslog_files_permissions_syslog_config:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_rsyslog_files_permissions_syslog_config:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:variable_object comment="Variable containing all rsyslog configuration files." id="oval:ssg-object_var_rsyslog_files_permissions_all_conf_files:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_var_rsyslog_files_permissions_include_config_regex:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_var_rsyslog_files_permissions_syslog_config:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:variable_object>
        <ind:textfilecontent54_object comment="All rsyslog log files collected from rsyslog configuration files." id="oval:ssg-object_rsyslog_files_permissions_log_files_paths:obj:1" version="1">
          <ind:filepath operation="pattern match" var_check="at least one" var_ref="oval:ssg-var_rsyslog_files_permissions_all_conf_files:var:1"/>
          <ind:pattern operation="pattern match">^\s*[^#$].*?(?:\b[Ff]ile="([^"\s]+)"|[\s]+-?(\/[^:;\s]+)).*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <oval-def:filter action="exclude">oval:ssg-state_rsyslog_files_permissions_ignore_include_paths:ste:1</oval-def:filter>
        </ind:textfilecontent54_object>
        <unix:file_object comment="All system log files collected from rsyslog configuration files" id="oval:ssg-object_rsyslog_files_permissions_permissions:obj:1" version="1">
          <unix:filepath datatype="string" var_check="at least one" var_ref="oval:ssg-var_rsyslog_files_permissions_log_files_paths:var:1"/>
        </unix:file_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_abrt_anon_write:obj:1" version="1">
          <linux:name>abrt_anon_write</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_abrt_handle_event:obj:1" version="1">
          <linux:name>abrt_handle_event</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_abrt_upload_watch_anon_write:obj:1" version="1">
          <linux:name>abrt_upload_watch_anon_write</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_antivirus_can_scan_system:obj:1" version="1">
          <linux:name>antivirus_can_scan_system</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_antivirus_use_jit:obj:1" version="1">
          <linux:name>antivirus_use_jit</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_auditadm_exec_content:obj:1" version="1">
          <linux:name>auditadm_exec_content</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_authlogin_nsswitch_use_ldap:obj:1" version="1">
          <linux:name>authlogin_nsswitch_use_ldap</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_authlogin_radius:obj:1" version="1">
          <linux:name>authlogin_radius</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_authlogin_yubikey:obj:1" version="1">
          <linux:name>authlogin_yubikey</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_awstats_purge_apache_log_files:obj:1" version="1">
          <linux:name>awstats_purge_apache_log_files</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_boinc_execmem:obj:1" version="1">
          <linux:name>boinc_execmem</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_cdrecord_read_content:obj:1" version="1">
          <linux:name>cdrecord_read_content</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_cluster_can_network_connect:obj:1" version="1">
          <linux:name>cluster_can_network_connect</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_cluster_manage_all_files:obj:1" version="1">
          <linux:name>cluster_manage_all_files</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_cluster_use_execmem:obj:1" version="1">
          <linux:name>cluster_use_execmem</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_cobbler_anon_write:obj:1" version="1">
          <linux:name>cobbler_anon_write</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_cobbler_can_network_connect:obj:1" version="1">
          <linux:name>cobbler_can_network_connect</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_cobbler_use_cifs:obj:1" version="1">
          <linux:name>cobbler_use_cifs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_cobbler_use_nfs:obj:1" version="1">
          <linux:name>cobbler_use_nfs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_collectd_tcp_network_connect:obj:1" version="1">
          <linux:name>collectd_tcp_network_connect</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_condor_tcp_network_connect:obj:1" version="1">
          <linux:name>condor_tcp_network_connect</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_conman_can_network:obj:1" version="1">
          <linux:name>conman_can_network</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_container_connect_any:obj:1" version="1">
          <linux:name>container_connect_any</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_cron_can_relabel:obj:1" version="1">
          <linux:name>cron_can_relabel</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_cron_system_cronjob_use_shares:obj:1" version="1">
          <linux:name>cron_system_cronjob_use_shares</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_cron_userdomain_transition:obj:1" version="1">
          <linux:name>cron_userdomain_transition</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_cups_execmem:obj:1" version="1">
          <linux:name>cups_execmem</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_cvs_read_shadow:obj:1" version="1">
          <linux:name>cvs_read_shadow</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_daemons_dump_core:obj:1" version="1">
          <linux:name>daemons_dump_core</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_daemons_enable_cluster_mode:obj:1" version="1">
          <linux:name>daemons_enable_cluster_mode</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_daemons_use_tcp_wrapper:obj:1" version="1">
          <linux:name>daemons_use_tcp_wrapper</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_daemons_use_tty:obj:1" version="1">
          <linux:name>daemons_use_tty</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_dbadm_exec_content:obj:1" version="1">
          <linux:name>dbadm_exec_content</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_dbadm_manage_user_files:obj:1" version="1">
          <linux:name>dbadm_manage_user_files</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_dbadm_read_user_files:obj:1" version="1">
          <linux:name>dbadm_read_user_files</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_deny_execmem:obj:1" version="1">
          <linux:name>deny_execmem</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_deny_ptrace:obj:1" version="1">
          <linux:name>deny_ptrace</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_dhcpc_exec_iptables:obj:1" version="1">
          <linux:name>dhcpc_exec_iptables</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_dhcpd_use_ldap:obj:1" version="1">
          <linux:name>dhcpd_use_ldap</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_domain_fd_use:obj:1" version="1">
          <linux:name>domain_fd_use</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_domain_kernel_load_modules:obj:1" version="1">
          <linux:name>domain_kernel_load_modules</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_entropyd_use_audio:obj:1" version="1">
          <linux:name>entropyd_use_audio</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_exim_can_connect_db:obj:1" version="1">
          <linux:name>exim_can_connect_db</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_exim_manage_user_files:obj:1" version="1">
          <linux:name>exim_manage_user_files</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_exim_read_user_files:obj:1" version="1">
          <linux:name>exim_read_user_files</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_fcron_crond:obj:1" version="1">
          <linux:name>fcron_crond</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_fenced_can_network_connect:obj:1" version="1">
          <linux:name>fenced_can_network_connect</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_fenced_can_ssh:obj:1" version="1">
          <linux:name>fenced_can_ssh</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_fips_mode:obj:1" version="1">
          <linux:name>fips_mode</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_ftpd_anon_write:obj:1" version="1">
          <linux:name>ftpd_anon_write</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_ftpd_connect_all_unreserved:obj:1" version="1">
          <linux:name>ftpd_connect_all_unreserved</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_ftpd_connect_db:obj:1" version="1">
          <linux:name>ftpd_connect_db</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_ftpd_full_access:obj:1" version="1">
          <linux:name>ftpd_full_access</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_ftpd_use_cifs:obj:1" version="1">
          <linux:name>ftpd_use_cifs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_ftpd_use_fusefs:obj:1" version="1">
          <linux:name>ftpd_use_fusefs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_ftpd_use_nfs:obj:1" version="1">
          <linux:name>ftpd_use_nfs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_ftpd_use_passive_mode:obj:1" version="1">
          <linux:name>ftpd_use_passive_mode</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_git_cgi_enable_homedirs:obj:1" version="1">
          <linux:name>git_cgi_enable_homedirs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_git_cgi_use_cifs:obj:1" version="1">
          <linux:name>git_cgi_use_cifs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_git_cgi_use_nfs:obj:1" version="1">
          <linux:name>git_cgi_use_nfs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_git_session_bind_all_unreserved_ports:obj:1" version="1">
          <linux:name>git_session_bind_all_unreserved_ports</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_git_session_users:obj:1" version="1">
          <linux:name>git_session_users</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_git_system_enable_homedirs:obj:1" version="1">
          <linux:name>git_system_enable_homedirs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_git_system_use_cifs:obj:1" version="1">
          <linux:name>git_system_use_cifs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_git_system_use_nfs:obj:1" version="1">
          <linux:name>git_system_use_nfs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_gitosis_can_sendmail:obj:1" version="1">
          <linux:name>gitosis_can_sendmail</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_glance_api_can_network:obj:1" version="1">
          <linux:name>glance_api_can_network</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_glance_use_execmem:obj:1" version="1">
          <linux:name>glance_use_execmem</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_glance_use_fusefs:obj:1" version="1">
          <linux:name>glance_use_fusefs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_global_ssp:obj:1" version="1">
          <linux:name>global_ssp</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_gluster_anon_write:obj:1" version="1">
          <linux:name>gluster_anon_write</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_gluster_export_all_ro:obj:1" version="1">
          <linux:name>gluster_export_all_ro</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_gluster_export_all_rw:obj:1" version="1">
          <linux:name>gluster_export_all_rw</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_gpg_web_anon_write:obj:1" version="1">
          <linux:name>gpg_web_anon_write</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_gssd_read_tmp:obj:1" version="1">
          <linux:name>gssd_read_tmp</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_guest_exec_content:obj:1" version="1">
          <linux:name>guest_exec_content</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_haproxy_connect_any:obj:1" version="1">
          <linux:name>haproxy_connect_any</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_anon_write:obj:1" version="1">
          <linux:name>httpd_anon_write</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_builtin_scripting:obj:1" version="1">
          <linux:name>httpd_builtin_scripting</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_can_check_spam:obj:1" version="1">
          <linux:name>httpd_can_check_spam</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_can_connect_ftp:obj:1" version="1">
          <linux:name>httpd_can_connect_ftp</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_can_connect_ldap:obj:1" version="1">
          <linux:name>httpd_can_connect_ldap</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_can_connect_mythtv:obj:1" version="1">
          <linux:name>httpd_can_connect_mythtv</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_can_connect_zabbix:obj:1" version="1">
          <linux:name>httpd_can_connect_zabbix</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_can_network_connect:obj:1" version="1">
          <linux:name>httpd_can_network_connect</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_can_network_connect_cobbler:obj:1" version="1">
          <linux:name>httpd_can_network_connect_cobbler</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_can_network_connect_db:obj:1" version="1">
          <linux:name>httpd_can_network_connect_db</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_can_network_memcache:obj:1" version="1">
          <linux:name>httpd_can_network_memcache</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_can_network_relay:obj:1" version="1">
          <linux:name>httpd_can_network_relay</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_can_sendmail:obj:1" version="1">
          <linux:name>httpd_can_sendmail</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_dbus_avahi:obj:1" version="1">
          <linux:name>httpd_dbus_avahi</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_dbus_sssd:obj:1" version="1">
          <linux:name>httpd_dbus_sssd</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_dontaudit_search_dirs:obj:1" version="1">
          <linux:name>httpd_dontaudit_search_dirs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_enable_cgi:obj:1" version="1">
          <linux:name>httpd_enable_cgi</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_enable_ftp_server:obj:1" version="1">
          <linux:name>httpd_enable_ftp_server</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_enable_homedirs:obj:1" version="1">
          <linux:name>httpd_enable_homedirs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_execmem:obj:1" version="1">
          <linux:name>httpd_execmem</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_graceful_shutdown:obj:1" version="1">
          <linux:name>httpd_graceful_shutdown</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_manage_ipa:obj:1" version="1">
          <linux:name>httpd_manage_ipa</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_mod_auth_ntlm_winbind:obj:1" version="1">
          <linux:name>httpd_mod_auth_ntlm_winbind</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_mod_auth_pam:obj:1" version="1">
          <linux:name>httpd_mod_auth_pam</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_read_user_content:obj:1" version="1">
          <linux:name>httpd_read_user_content</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_run_ipa:obj:1" version="1">
          <linux:name>httpd_run_ipa</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_run_preupgrade:obj:1" version="1">
          <linux:name>httpd_run_preupgrade</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_run_stickshift:obj:1" version="1">
          <linux:name>httpd_run_stickshift</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_serve_cobbler_files:obj:1" version="1">
          <linux:name>httpd_serve_cobbler_files</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_setrlimit:obj:1" version="1">
          <linux:name>httpd_setrlimit</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_ssi_exec:obj:1" version="1">
          <linux:name>httpd_ssi_exec</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_sys_script_anon_write:obj:1" version="1">
          <linux:name>httpd_sys_script_anon_write</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_tmp_exec:obj:1" version="1">
          <linux:name>httpd_tmp_exec</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_tty_comm:obj:1" version="1">
          <linux:name>httpd_tty_comm</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_unified:obj:1" version="1">
          <linux:name>httpd_unified</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_use_cifs:obj:1" version="1">
          <linux:name>httpd_use_cifs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_use_fusefs:obj:1" version="1">
          <linux:name>httpd_use_fusefs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_use_gpg:obj:1" version="1">
          <linux:name>httpd_use_gpg</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_use_nfs:obj:1" version="1">
          <linux:name>httpd_use_nfs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_use_openstack:obj:1" version="1">
          <linux:name>httpd_use_openstack</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_use_sasl:obj:1" version="1">
          <linux:name>httpd_use_sasl</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_httpd_verify_dns:obj:1" version="1">
          <linux:name>httpd_verify_dns</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_icecast_use_any_tcp_ports:obj:1" version="1">
          <linux:name>icecast_use_any_tcp_ports</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_irc_use_any_tcp_ports:obj:1" version="1">
          <linux:name>irc_use_any_tcp_ports</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_irssi_use_full_network:obj:1" version="1">
          <linux:name>irssi_use_full_network</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_kdumpgui_run_bootloader:obj:1" version="1">
          <linux:name>kdumpgui_run_bootloader</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_kerberos_enabled:obj:1" version="1">
          <linux:name>kerberos_enabled</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_ksmtuned_use_cifs:obj:1" version="1">
          <linux:name>ksmtuned_use_cifs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_ksmtuned_use_nfs:obj:1" version="1">
          <linux:name>ksmtuned_use_nfs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_logadm_exec_content:obj:1" version="1">
          <linux:name>logadm_exec_content</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_logging_syslogd_can_sendmail:obj:1" version="1">
          <linux:name>logging_syslogd_can_sendmail</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_logging_syslogd_run_nagios_plugins:obj:1" version="1">
          <linux:name>logging_syslogd_run_nagios_plugins</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_logging_syslogd_use_tty:obj:1" version="1">
          <linux:name>logging_syslogd_use_tty</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_login_console_enabled:obj:1" version="1">
          <linux:name>login_console_enabled</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_logrotate_use_nfs:obj:1" version="1">
          <linux:name>logrotate_use_nfs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_logwatch_can_network_connect_mail:obj:1" version="1">
          <linux:name>logwatch_can_network_connect_mail</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_lsmd_plugin_connect_any:obj:1" version="1">
          <linux:name>lsmd_plugin_connect_any</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mailman_use_fusefs:obj:1" version="1">
          <linux:name>mailman_use_fusefs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mcelog_client:obj:1" version="1">
          <linux:name>mcelog_client</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mcelog_exec_scripts:obj:1" version="1">
          <linux:name>mcelog_exec_scripts</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mcelog_foreground:obj:1" version="1">
          <linux:name>mcelog_foreground</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mcelog_server:obj:1" version="1">
          <linux:name>mcelog_server</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_minidlna_read_generic_user_content:obj:1" version="1">
          <linux:name>minidlna_read_generic_user_content</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mmap_low_allowed:obj:1" version="1">
          <linux:name>mmap_low_allowed</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mock_enable_homedirs:obj:1" version="1">
          <linux:name>mock_enable_homedirs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mount_anyfile:obj:1" version="1">
          <linux:name>mount_anyfile</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mozilla_plugin_bind_unreserved_ports:obj:1" version="1">
          <linux:name>mozilla_plugin_bind_unreserved_ports</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mozilla_plugin_can_network_connect:obj:1" version="1">
          <linux:name>mozilla_plugin_can_network_connect</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mozilla_plugin_use_bluejeans:obj:1" version="1">
          <linux:name>mozilla_plugin_use_bluejeans</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mozilla_plugin_use_gps:obj:1" version="1">
          <linux:name>mozilla_plugin_use_gps</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mozilla_plugin_use_spice:obj:1" version="1">
          <linux:name>mozilla_plugin_use_spice</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mozilla_read_content:obj:1" version="1">
          <linux:name>mozilla_read_content</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mpd_enable_homedirs:obj:1" version="1">
          <linux:name>mpd_enable_homedirs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mpd_use_cifs:obj:1" version="1">
          <linux:name>mpd_use_cifs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mpd_use_nfs:obj:1" version="1">
          <linux:name>mpd_use_nfs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mplayer_execstack:obj:1" version="1">
          <linux:name>mplayer_execstack</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_mysql_connect_any:obj:1" version="1">
          <linux:name>mysql_connect_any</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_nagios_run_pnp4nagios:obj:1" version="1">
          <linux:name>nagios_run_pnp4nagios</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_nagios_run_sudo:obj:1" version="1">
          <linux:name>nagios_run_sudo</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_named_tcp_bind_http_port:obj:1" version="1">
          <linux:name>named_tcp_bind_http_port</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_named_write_master_zones:obj:1" version="1">
          <linux:name>named_write_master_zones</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_neutron_can_network:obj:1" version="1">
          <linux:name>neutron_can_network</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_nfs_export_all_ro:obj:1" version="1">
          <linux:name>nfs_export_all_ro</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_nfs_export_all_rw:obj:1" version="1">
          <linux:name>nfs_export_all_rw</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_nfsd_anon_write:obj:1" version="1">
          <linux:name>nfsd_anon_write</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_nis_enabled:obj:1" version="1">
          <linux:name>nis_enabled</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_nscd_use_shm:obj:1" version="1">
          <linux:name>nscd_use_shm</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_openshift_use_nfs:obj:1" version="1">
          <linux:name>openshift_use_nfs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_openvpn_can_network_connect:obj:1" version="1">
          <linux:name>openvpn_can_network_connect</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_openvpn_enable_homedirs:obj:1" version="1">
          <linux:name>openvpn_enable_homedirs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_openvpn_run_unconfined:obj:1" version="1">
          <linux:name>openvpn_run_unconfined</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_pcp_bind_all_unreserved_ports:obj:1" version="1">
          <linux:name>pcp_bind_all_unreserved_ports</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_pcp_read_generic_logs:obj:1" version="1">
          <linux:name>pcp_read_generic_logs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_piranha_lvs_can_network_connect:obj:1" version="1">
          <linux:name>piranha_lvs_can_network_connect</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_polipo_connect_all_unreserved:obj:1" version="1">
          <linux:name>polipo_connect_all_unreserved</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_polipo_session_bind_all_unreserved_ports:obj:1" version="1">
          <linux:name>polipo_session_bind_all_unreserved_ports</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_polipo_session_users:obj:1" version="1">
          <linux:name>polipo_session_users</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_polipo_use_cifs:obj:1" version="1">
          <linux:name>polipo_use_cifs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_polipo_use_nfs:obj:1" version="1">
          <linux:name>polipo_use_nfs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_polyinstantiation_enabled:obj:1" version="1">
          <linux:name>polyinstantiation_enabled</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_postfix_local_write_mail_spool:obj:1" version="1">
          <linux:name>postfix_local_write_mail_spool</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_postgresql_can_rsync:obj:1" version="1">
          <linux:name>postgresql_can_rsync</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_postgresql_selinux_transmit_client_label:obj:1" version="1">
          <linux:name>postgresql_selinux_transmit_client_label</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_postgresql_selinux_unconfined_dbadm:obj:1" version="1">
          <linux:name>postgresql_selinux_unconfined_dbadm</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_postgresql_selinux_users_ddl:obj:1" version="1">
          <linux:name>postgresql_selinux_users_ddl</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_pppd_can_insmod:obj:1" version="1">
          <linux:name>pppd_can_insmod</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_pppd_for_user:obj:1" version="1">
          <linux:name>pppd_for_user</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_privoxy_connect_any:obj:1" version="1">
          <linux:name>privoxy_connect_any</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_prosody_bind_http_port:obj:1" version="1">
          <linux:name>prosody_bind_http_port</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_puppetagent_manage_all_files:obj:1" version="1">
          <linux:name>puppetagent_manage_all_files</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_puppetmaster_use_db:obj:1" version="1">
          <linux:name>puppetmaster_use_db</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_racoon_read_shadow:obj:1" version="1">
          <linux:name>racoon_read_shadow</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_rsync_anon_write:obj:1" version="1">
          <linux:name>rsync_anon_write</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_rsync_client:obj:1" version="1">
          <linux:name>rsync_client</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_rsync_export_all_ro:obj:1" version="1">
          <linux:name>rsync_export_all_ro</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_rsync_full_access:obj:1" version="1">
          <linux:name>rsync_full_access</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_samba_create_home_dirs:obj:1" version="1">
          <linux:name>samba_create_home_dirs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_samba_domain_controller:obj:1" version="1">
          <linux:name>samba_domain_controller</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_samba_enable_home_dirs:obj:1" version="1">
          <linux:name>samba_enable_home_dirs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_samba_export_all_ro:obj:1" version="1">
          <linux:name>samba_export_all_ro</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_samba_export_all_rw:obj:1" version="1">
          <linux:name>samba_export_all_rw</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_samba_load_libgfapi:obj:1" version="1">
          <linux:name>samba_load_libgfapi</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_samba_portmapper:obj:1" version="1">
          <linux:name>samba_portmapper</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_samba_run_unconfined:obj:1" version="1">
          <linux:name>samba_run_unconfined</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_samba_share_fusefs:obj:1" version="1">
          <linux:name>samba_share_fusefs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_samba_share_nfs:obj:1" version="1">
          <linux:name>samba_share_nfs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_sanlock_use_fusefs:obj:1" version="1">
          <linux:name>sanlock_use_fusefs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_sanlock_use_nfs:obj:1" version="1">
          <linux:name>sanlock_use_nfs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_sanlock_use_samba:obj:1" version="1">
          <linux:name>sanlock_use_samba</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_saslauthd_read_shadow:obj:1" version="1">
          <linux:name>saslauthd_read_shadow</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_secadm_exec_content:obj:1" version="1">
          <linux:name>secadm_exec_content</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_secure_mode:obj:1" version="1">
          <linux:name>secure_mode</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_secure_mode_insmod:obj:1" version="1">
          <linux:name>secure_mode_insmod</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_secure_mode_policyload:obj:1" version="1">
          <linux:name>secure_mode_policyload</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_selinuxuser_direct_dri_enabled:obj:1" version="1">
          <linux:name>selinuxuser_direct_dri_enabled</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_selinuxuser_execheap:obj:1" version="1">
          <linux:name>selinuxuser_execheap</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_selinuxuser_execmod:obj:1" version="1">
          <linux:name>selinuxuser_execmod</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_selinuxuser_execstack:obj:1" version="1">
          <linux:name>selinuxuser_execstack</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_selinuxuser_mysql_connect_enabled:obj:1" version="1">
          <linux:name>selinuxuser_mysql_connect_enabled</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_selinuxuser_ping:obj:1" version="1">
          <linux:name>selinuxuser_ping</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_selinuxuser_postgresql_connect_enabled:obj:1" version="1">
          <linux:name>selinuxuser_postgresql_connect_enabled</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_selinuxuser_rw_noexattrfile:obj:1" version="1">
          <linux:name>selinuxuser_rw_noexattrfile</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_selinuxuser_share_music:obj:1" version="1">
          <linux:name>selinuxuser_share_music</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_selinuxuser_tcp_server:obj:1" version="1">
          <linux:name>selinuxuser_tcp_server</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_selinuxuser_udp_server:obj:1" version="1">
          <linux:name>selinuxuser_udp_server</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_selinuxuser_use_ssh_chroot:obj:1" version="1">
          <linux:name>selinuxuser_use_ssh_chroot</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_sge_domain_can_network_connect:obj:1" version="1">
          <linux:name>sge_domain_can_network_connect</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_sge_use_nfs:obj:1" version="1">
          <linux:name>sge_use_nfs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_smartmon_3ware:obj:1" version="1">
          <linux:name>smartmon_3ware</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_smbd_anon_write:obj:1" version="1">
          <linux:name>smbd_anon_write</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_spamassassin_can_network:obj:1" version="1">
          <linux:name>spamassassin_can_network</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_spamd_enable_home_dirs:obj:1" version="1">
          <linux:name>spamd_enable_home_dirs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_squid_connect_any:obj:1" version="1">
          <linux:name>squid_connect_any</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_squid_use_tproxy:obj:1" version="1">
          <linux:name>squid_use_tproxy</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_ssh_chroot_rw_homedirs:obj:1" version="1">
          <linux:name>ssh_chroot_rw_homedirs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_ssh_keysign:obj:1" version="1">
          <linux:name>ssh_keysign</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_ssh_sysadm_login:obj:1" version="1">
          <linux:name>ssh_sysadm_login</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_staff_exec_content:obj:1" version="1">
          <linux:name>staff_exec_content</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_staff_use_svirt:obj:1" version="1">
          <linux:name>staff_use_svirt</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_swift_can_network:obj:1" version="1">
          <linux:name>swift_can_network</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_sysadm_exec_content:obj:1" version="1">
          <linux:name>sysadm_exec_content</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_telepathy_connect_all_ports:obj:1" version="1">
          <linux:name>telepathy_connect_all_ports</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_telepathy_tcp_connect_generic_network_ports:obj:1" version="1">
          <linux:name>telepathy_tcp_connect_generic_network_ports</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_tftp_anon_write:obj:1" version="1">
          <linux:name>tftp_anon_write</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_tftp_home_dir:obj:1" version="1">
          <linux:name>tftp_home_dir</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_tmpreaper_use_nfs:obj:1" version="1">
          <linux:name>tmpreaper_use_nfs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_tmpreaper_use_samba:obj:1" version="1">
          <linux:name>tmpreaper_use_samba</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_tor_bind_all_unreserved_ports:obj:1" version="1">
          <linux:name>tor_bind_all_unreserved_ports</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_tor_can_network_relay:obj:1" version="1">
          <linux:name>tor_can_network_relay</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_unconfined_chrome_sandbox_transition:obj:1" version="1">
          <linux:name>unconfined_chrome_sandbox_transition</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_unconfined_login:obj:1" version="1">
          <linux:name>unconfined_login</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_unconfined_mozilla_plugin_transition:obj:1" version="1">
          <linux:name>unconfined_mozilla_plugin_transition</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_unprivuser_use_svirt:obj:1" version="1">
          <linux:name>unprivuser_use_svirt</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_use_ecryptfs_home_dirs:obj:1" version="1">
          <linux:name>use_ecryptfs_home_dirs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_use_fusefs_home_dirs:obj:1" version="1">
          <linux:name>use_fusefs_home_dirs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_use_lpd_server:obj:1" version="1">
          <linux:name>use_lpd_server</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_use_nfs_home_dirs:obj:1" version="1">
          <linux:name>use_nfs_home_dirs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_use_samba_home_dirs:obj:1" version="1">
          <linux:name>use_samba_home_dirs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_user_exec_content:obj:1" version="1">
          <linux:name>user_exec_content</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_varnishd_connect_any:obj:1" version="1">
          <linux:name>varnishd_connect_any</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_virt_read_qemu_ga_data:obj:1" version="1">
          <linux:name>virt_read_qemu_ga_data</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_virt_rw_qemu_ga_data:obj:1" version="1">
          <linux:name>virt_rw_qemu_ga_data</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_virt_sandbox_use_all_caps:obj:1" version="1">
          <linux:name>virt_sandbox_use_all_caps</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_virt_sandbox_use_audit:obj:1" version="1">
          <linux:name>virt_sandbox_use_audit</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_virt_sandbox_use_mknod:obj:1" version="1">
          <linux:name>virt_sandbox_use_mknod</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_virt_sandbox_use_netlink:obj:1" version="1">
          <linux:name>virt_sandbox_use_netlink</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_virt_sandbox_use_sys_admin:obj:1" version="1">
          <linux:name>virt_sandbox_use_sys_admin</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_virt_transition_userdomain:obj:1" version="1">
          <linux:name>virt_transition_userdomain</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_virt_use_comm:obj:1" version="1">
          <linux:name>virt_use_comm</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_virt_use_execmem:obj:1" version="1">
          <linux:name>virt_use_execmem</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_virt_use_fusefs:obj:1" version="1">
          <linux:name>virt_use_fusefs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_virt_use_nfs:obj:1" version="1">
          <linux:name>virt_use_nfs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_virt_use_rawip:obj:1" version="1">
          <linux:name>virt_use_rawip</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_virt_use_samba:obj:1" version="1">
          <linux:name>virt_use_samba</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_virt_use_sanlock:obj:1" version="1">
          <linux:name>virt_use_sanlock</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_virt_use_usb:obj:1" version="1">
          <linux:name>virt_use_usb</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_virt_use_xserver:obj:1" version="1">
          <linux:name>virt_use_xserver</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_webadm_manage_user_files:obj:1" version="1">
          <linux:name>webadm_manage_user_files</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_webadm_read_user_files:obj:1" version="1">
          <linux:name>webadm_read_user_files</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_wine_mmap_zero_ignore:obj:1" version="1">
          <linux:name>wine_mmap_zero_ignore</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_xdm_bind_vnc_tcp_port:obj:1" version="1">
          <linux:name>xdm_bind_vnc_tcp_port</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_xdm_exec_bootloader:obj:1" version="1">
          <linux:name>xdm_exec_bootloader</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_xdm_sysadm_login:obj:1" version="1">
          <linux:name>xdm_sysadm_login</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_xdm_write_home:obj:1" version="1">
          <linux:name>xdm_write_home</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_xen_use_nfs:obj:1" version="1">
          <linux:name>xen_use_nfs</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_xend_run_blktap:obj:1" version="1">
          <linux:name>xend_run_blktap</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_xend_run_qemu:obj:1" version="1">
          <linux:name>xend_run_qemu</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_xguest_connect_network:obj:1" version="1">
          <linux:name>xguest_connect_network</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_xguest_exec_content:obj:1" version="1">
          <linux:name>xguest_exec_content</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_xguest_mount_media:obj:1" version="1">
          <linux:name>xguest_mount_media</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_xguest_use_bluetooth:obj:1" version="1">
          <linux:name>xguest_use_bluetooth</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_xserver_clients_write_xshm:obj:1" version="1">
          <linux:name>xserver_clients_write_xshm</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_xserver_execmem:obj:1" version="1">
          <linux:name>xserver_execmem</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_xserver_object_manager:obj:1" version="1">
          <linux:name>xserver_object_manager</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_zabbix_can_network:obj:1" version="1">
          <linux:name>zabbix_can_network</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_zarafa_setrlimit:obj:1" version="1">
          <linux:name>zarafa_setrlimit</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_zebra_write_config:obj:1" version="1">
          <linux:name>zebra_write_config</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_zoneminder_anon_write:obj:1" version="1">
          <linux:name>zoneminder_anon_write</linux:name>
        </linux:selinuxboolean_object>
        <linux:selinuxboolean_object id="oval:ssg-object_sebool_zoneminder_run_sudo:obj:1" version="1">
          <linux:name>zoneminder_run_sudo</linux:name>
        </linux:selinuxboolean_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_selinux_policytype:obj:1" version="1">
          <ind:filepath>/etc/selinux/config</ind:filepath>
          <ind:pattern operation="pattern match">^SELINUXTYPE=(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="The configuration file /etc/selinux/config for selinux_policytype" id="oval:ssg-obj_selinux_policytype_config_file:obj:1" version="1">
          <unix:filepath operation="pattern match">^/etc/selinux/config</unix:filepath>
        </unix:file_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of abrtd" id="oval:ssg-obj_service_not_running_service_abrtd_disabled_abrtd:obj:1" version="1">
          <linux:unit operation="pattern match">^abrtd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of abrtd" id="oval:ssg-obj_service_loadstate_is_masked_service_abrtd_disabled_abrtd:obj:1" version="1">
          <linux:unit operation="pattern match">^abrtd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_abrtd_disabled_test_service_abrtd_package_abrt_removed:obj:1" version="1">
          <linux:name>abrt</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of acpid" id="oval:ssg-obj_service_not_running_service_acpid_disabled_acpid:obj:1" version="1">
          <linux:unit operation="pattern match">^acpid\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of acpid" id="oval:ssg-obj_service_loadstate_is_masked_service_acpid_disabled_acpid:obj:1" version="1">
          <linux:unit operation="pattern match">^acpid\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_acpid_disabled_test_service_acpid_package_acpid_removed:obj:1" version="1">
          <linux:name>acpid</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of atd" id="oval:ssg-obj_service_not_running_service_atd_disabled_atd:obj:1" version="1">
          <linux:unit operation="pattern match">^atd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of atd" id="oval:ssg-obj_service_loadstate_is_masked_service_atd_disabled_atd:obj:1" version="1">
          <linux:unit operation="pattern match">^atd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_atd_disabled_test_service_atd_package_at_removed:obj:1" version="1">
          <linux:name>at</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_auditd_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_auditd_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of auditd" id="oval:ssg-obj_service_running_auditd:obj:1" version="1">
          <linux:unit operation="pattern match">^auditd\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_auditd_package_audit_installed:obj:1" version="1">
          <linux:name>audit</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of autofs" id="oval:ssg-obj_service_not_running_service_autofs_disabled_autofs:obj:1" version="1">
          <linux:unit operation="pattern match">^autofs\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of autofs" id="oval:ssg-obj_service_loadstate_is_masked_service_autofs_disabled_autofs:obj:1" version="1">
          <linux:unit operation="pattern match">^autofs\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_autofs_disabled_test_service_autofs_package_autofs_removed:obj:1" version="1">
          <linux:name>autofs</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of avahi-daemon" id="oval:ssg-obj_service_not_running_service_avahi-daemon_disabled_avahi-daemon:obj:1" version="1">
          <linux:unit operation="pattern match">^avahi-daemon\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of avahi-daemon" id="oval:ssg-obj_service_loadstate_is_masked_service_avahi-daemon_disabled_avahi-daemon:obj:1" version="1">
          <linux:unit operation="pattern match">^avahi-daemon\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_avahi-daemon_disabled_test_service_avahi-daemon_package_avahi_removed:obj:1" version="1">
          <linux:name>avahi</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of bluetooth" id="oval:ssg-obj_service_not_running_service_bluetooth_disabled_bluetooth:obj:1" version="1">
          <linux:unit operation="pattern match">^bluetooth\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of bluetooth" id="oval:ssg-obj_service_loadstate_is_masked_service_bluetooth_disabled_bluetooth:obj:1" version="1">
          <linux:unit operation="pattern match">^bluetooth\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_bluetooth_disabled_test_service_bluetooth_package_bluez_removed:obj:1" version="1">
          <linux:name>bluez</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of certmonger" id="oval:ssg-obj_service_not_running_service_certmonger_disabled_certmonger:obj:1" version="1">
          <linux:unit operation="pattern match">^certmonger\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of certmonger" id="oval:ssg-obj_service_loadstate_is_masked_service_certmonger_disabled_certmonger:obj:1" version="1">
          <linux:unit operation="pattern match">^certmonger\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_certmonger_disabled_test_service_certmonger_package_certmonger_removed:obj:1" version="1">
          <linux:name>certmonger</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_chronyd_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_chronyd_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of chronyd" id="oval:ssg-obj_service_running_chronyd:obj:1" version="1">
          <linux:unit operation="pattern match">^chronyd\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_chronyd_package_chrony_installed:obj:1" version="1">
          <linux:name>chrony</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of cockpit" id="oval:ssg-obj_service_not_running_service_cockpit_disabled_cockpit:obj:1" version="1">
          <linux:unit operation="pattern match">^cockpit\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of cockpit" id="oval:ssg-obj_service_loadstate_is_masked_service_cockpit_disabled_cockpit:obj:1" version="1">
          <linux:unit operation="pattern match">^cockpit\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_cockpit_disabled_test_service_cockpit_package_cockpit_removed:obj:1" version="1">
          <linux:name>cockpit</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of cpupower" id="oval:ssg-obj_service_not_running_service_cpupower_disabled_cpupower:obj:1" version="1">
          <linux:unit operation="pattern match">^cpupower\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of cpupower" id="oval:ssg-obj_service_loadstate_is_masked_service_cpupower_disabled_cpupower:obj:1" version="1">
          <linux:unit operation="pattern match">^cpupower\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_cpupower_disabled_test_service_cpupower_package_kernel-tools_removed:obj:1" version="1">
          <linux:name>kernel-tools</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_cron_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_cron_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of cron" id="oval:ssg-obj_service_running_cron:obj:1" version="1">
          <linux:unit operation="pattern match">^cron\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_cron_package_cron_installed:obj:1" version="1">
          <linux:name>cron</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_crond_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_crond_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of crond" id="oval:ssg-obj_service_running_crond:obj:1" version="1">
          <linux:unit operation="pattern match">^crond\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_crond_package_cronie_installed:obj:1" version="1">
          <linux:name>cronie</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of cups" id="oval:ssg-obj_service_not_running_service_cups_disabled_cups:obj:1" version="1">
          <linux:unit operation="pattern match">^cups\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of cups" id="oval:ssg-obj_service_loadstate_is_masked_service_cups_disabled_cups:obj:1" version="1">
          <linux:unit operation="pattern match">^cups\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_cups_disabled_test_service_cups_package_cups_removed:obj:1" version="1">
          <linux:name>cups</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of debug-shell" id="oval:ssg-obj_service_not_running_service_debug-shell_disabled_debug-shell:obj:1" version="1">
          <linux:unit operation="pattern match">^debug-shell\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of debug-shell" id="oval:ssg-obj_service_loadstate_is_masked_service_debug-shell_disabled_debug-shell:obj:1" version="1">
          <linux:unit operation="pattern match">^debug-shell\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_debug-shell_disabled_test_service_debug-shell_package_systemd_removed:obj:1" version="1">
          <linux:name>systemd</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of dhcpd" id="oval:ssg-obj_service_not_running_service_dhcpd_disabled_dhcpd:obj:1" version="1">
          <linux:unit operation="pattern match">^dhcpd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of dhcpd" id="oval:ssg-obj_service_loadstate_is_masked_service_dhcpd_disabled_dhcpd:obj:1" version="1">
          <linux:unit operation="pattern match">^dhcpd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_dhcpd_disabled_test_service_dhcpd_package_dhcp_removed:obj:1" version="1">
          <linux:name>dhcp</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of dnsmasq" id="oval:ssg-obj_service_not_running_service_dnsmasq_disabled_dnsmasq:obj:1" version="1">
          <linux:unit operation="pattern match">^dnsmasq\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of dnsmasq" id="oval:ssg-obj_service_loadstate_is_masked_service_dnsmasq_disabled_dnsmasq:obj:1" version="1">
          <linux:unit operation="pattern match">^dnsmasq\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_dnsmasq_disabled_test_service_dnsmasq_package_dnsmasq_removed:obj:1" version="1">
          <linux:name>dnsmasq</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of dovecot" id="oval:ssg-obj_service_not_running_service_dovecot_disabled_dovecot:obj:1" version="1">
          <linux:unit operation="pattern match">^dovecot\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of dovecot" id="oval:ssg-obj_service_loadstate_is_masked_service_dovecot_disabled_dovecot:obj:1" version="1">
          <linux:unit operation="pattern match">^dovecot\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_dovecot_disabled_test_service_dovecot_package_dovecot_removed:obj:1" version="1">
          <linux:name>dovecot</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_fapolicyd_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_fapolicyd_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of fapolicyd" id="oval:ssg-obj_service_running_fapolicyd:obj:1" version="1">
          <linux:unit operation="pattern match">^fapolicyd\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_fapolicyd_package_fapolicyd_installed:obj:1" version="1">
          <linux:name>fapolicyd</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_firewalld_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_firewalld_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of firewalld" id="oval:ssg-obj_service_running_firewalld:obj:1" version="1">
          <linux:unit operation="pattern match">^firewalld\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_firewalld_package_firewalld_installed:obj:1" version="1">
          <linux:name>firewalld</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of httpd" id="oval:ssg-obj_service_not_running_service_httpd_disabled_httpd:obj:1" version="1">
          <linux:unit operation="pattern match">^httpd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of httpd" id="oval:ssg-obj_service_loadstate_is_masked_service_httpd_disabled_httpd:obj:1" version="1">
          <linux:unit operation="pattern match">^httpd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_httpd_disabled_test_service_httpd_package_httpd_removed:obj:1" version="1">
          <linux:name>httpd</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_ip6tables_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_ip6tables_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of ip6tables" id="oval:ssg-obj_service_running_ip6tables:obj:1" version="1">
          <linux:unit operation="pattern match">^ip6tables\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_ip6tables_package_iptables-ipv6_installed:obj:1" version="1">
          <linux:name>iptables-ipv6</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_iptables_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_iptables_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of iptables" id="oval:ssg-obj_service_running_iptables:obj:1" version="1">
          <linux:unit operation="pattern match">^iptables\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_iptables_package_iptables_installed:obj:1" version="1">
          <linux:name>iptables</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of kdump" id="oval:ssg-obj_service_not_running_service_kdump_disabled_kdump:obj:1" version="1">
          <linux:unit operation="pattern match">^kdump\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of kdump" id="oval:ssg-obj_service_loadstate_is_masked_service_kdump_disabled_kdump:obj:1" version="1">
          <linux:unit operation="pattern match">^kdump\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_kdump_disabled_test_service_kdump_package_kexec-tools_removed:obj:1" version="1">
          <linux:name>kexec-tools</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of mdmonitor" id="oval:ssg-obj_service_not_running_service_mdmonitor_disabled_mdmonitor:obj:1" version="1">
          <linux:unit operation="pattern match">^mdmonitor\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of mdmonitor" id="oval:ssg-obj_service_loadstate_is_masked_service_mdmonitor_disabled_mdmonitor:obj:1" version="1">
          <linux:unit operation="pattern match">^mdmonitor\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_mdmonitor_disabled_test_service_mdmonitor_package_mdadm_removed:obj:1" version="1">
          <linux:name>mdadm</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_nails_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_nails_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of nails" id="oval:ssg-obj_service_running_nails:obj:1" version="1">
          <linux:unit operation="pattern match">^nails\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_nails_package_nails_installed:obj:1" version="1">
          <linux:name>nails</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of named" id="oval:ssg-obj_service_not_running_service_named_disabled_named:obj:1" version="1">
          <linux:unit operation="pattern match">^named\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of named" id="oval:ssg-obj_service_loadstate_is_masked_service_named_disabled_named:obj:1" version="1">
          <linux:unit operation="pattern match">^named\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_named_disabled_test_service_named_package_bind_removed:obj:1" version="1">
          <linux:name>bind</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of netconsole" id="oval:ssg-obj_service_not_running_service_netconsole_disabled_netconsole:obj:1" version="1">
          <linux:unit operation="pattern match">^netconsole\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of netconsole" id="oval:ssg-obj_service_loadstate_is_masked_service_netconsole_disabled_netconsole:obj:1" version="1">
          <linux:unit operation="pattern match">^netconsole\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_netconsole_disabled_test_service_netconsole_package_netconsole_removed:obj:1" version="1">
          <linux:name>netconsole</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of netfs" id="oval:ssg-obj_service_not_running_service_netfs_disabled_netfs:obj:1" version="1">
          <linux:unit operation="pattern match">^netfs\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of netfs" id="oval:ssg-obj_service_loadstate_is_masked_service_netfs_disabled_netfs:obj:1" version="1">
          <linux:unit operation="pattern match">^netfs\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_netfs_disabled_test_service_netfs_package_netfs_removed:obj:1" version="1">
          <linux:name>netfs</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of nfs-server" id="oval:ssg-obj_service_not_running_service_nfs_disabled_nfs-server:obj:1" version="1">
          <linux:unit operation="pattern match">^nfs-server\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of nfs-server" id="oval:ssg-obj_service_loadstate_is_masked_service_nfs_disabled_nfs-server:obj:1" version="1">
          <linux:unit operation="pattern match">^nfs-server\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_nfs_disabled_test_service_nfs-server_package_nfs-utils_removed:obj:1" version="1">
          <linux:name>nfs-utils</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of nfslock" id="oval:ssg-obj_service_not_running_service_nfslock_disabled_nfslock:obj:1" version="1">
          <linux:unit operation="pattern match">^nfslock\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of nfslock" id="oval:ssg-obj_service_loadstate_is_masked_service_nfslock_disabled_nfslock:obj:1" version="1">
          <linux:unit operation="pattern match">^nfslock\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_nfslock_disabled_test_service_nfslock_package_nfs-utils_removed:obj:1" version="1">
          <linux:name>nfs-utils</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of nftables" id="oval:ssg-obj_service_not_running_service_nftables_disabled_nftables:obj:1" version="1">
          <linux:unit operation="pattern match">^nftables\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of nftables" id="oval:ssg-obj_service_loadstate_is_masked_service_nftables_disabled_nftables:obj:1" version="1">
          <linux:unit operation="pattern match">^nftables\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_nftables_disabled_test_service_nftables_package_nftables_removed:obj:1" version="1">
          <linux:name>nftables</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_nftables_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_nftables_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of nftables" id="oval:ssg-obj_service_running_nftables:obj:1" version="1">
          <linux:unit operation="pattern match">^nftables\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_nftables_package_nftables_installed:obj:1" version="1">
          <linux:name>nftables</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_ntp_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_ntp_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of ntp" id="oval:ssg-obj_service_running_ntp:obj:1" version="1">
          <linux:unit operation="pattern match">^ntp\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_ntp_package_ntp_installed:obj:1" version="1">
          <linux:name>ntp</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_ntpd_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_ntpd_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of ntpd" id="oval:ssg-obj_service_running_ntpd:obj:1" version="1">
          <linux:unit operation="pattern match">^ntpd\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_ntpd_package_ntp_installed:obj:1" version="1">
          <linux:name>ntp</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of ntpdate" id="oval:ssg-obj_service_not_running_service_ntpdate_disabled_ntpdate:obj:1" version="1">
          <linux:unit operation="pattern match">^ntpdate\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of ntpdate" id="oval:ssg-obj_service_loadstate_is_masked_service_ntpdate_disabled_ntpdate:obj:1" version="1">
          <linux:unit operation="pattern match">^ntpdate\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_ntpdate_disabled_test_service_ntpdate_package_ntpdate_removed:obj:1" version="1">
          <linux:name>ntpdate</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of oddjobd" id="oval:ssg-obj_service_not_running_service_oddjobd_disabled_oddjobd:obj:1" version="1">
          <linux:unit operation="pattern match">^oddjobd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of oddjobd" id="oval:ssg-obj_service_loadstate_is_masked_service_oddjobd_disabled_oddjobd:obj:1" version="1">
          <linux:unit operation="pattern match">^oddjobd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_oddjobd_disabled_test_service_oddjobd_package_oddjob_removed:obj:1" version="1">
          <linux:name>oddjob</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_pcscd_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_pcscd_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of pcscd" id="oval:ssg-obj_service_running_pcscd:obj:1" version="1">
          <linux:unit operation="pattern match">^pcscd\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_pcscd_package_pcsc-lite_installed:obj:1" version="1">
          <linux:name>pcsc-lite</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of portreserve" id="oval:ssg-obj_service_not_running_service_portreserve_disabled_portreserve:obj:1" version="1">
          <linux:unit operation="pattern match">^portreserve\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of portreserve" id="oval:ssg-obj_service_loadstate_is_masked_service_portreserve_disabled_portreserve:obj:1" version="1">
          <linux:unit operation="pattern match">^portreserve\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_portreserve_disabled_test_service_portreserve_package_portreserve_removed:obj:1" version="1">
          <linux:name>portreserve</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_postfix_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_postfix_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of postfix" id="oval:ssg-obj_service_running_postfix:obj:1" version="1">
          <linux:unit operation="pattern match">^postfix\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_postfix_package_postfix_installed:obj:1" version="1">
          <linux:name>postfix</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_psacct_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_psacct_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of psacct" id="oval:ssg-obj_service_running_psacct:obj:1" version="1">
          <linux:unit operation="pattern match">^psacct\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_psacct_package_psacct_installed:obj:1" version="1">
          <linux:name>psacct</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of qpidd" id="oval:ssg-obj_service_not_running_service_qpidd_disabled_qpidd:obj:1" version="1">
          <linux:unit operation="pattern match">^qpidd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of qpidd" id="oval:ssg-obj_service_loadstate_is_masked_service_qpidd_disabled_qpidd:obj:1" version="1">
          <linux:unit operation="pattern match">^qpidd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_qpidd_disabled_test_service_qpidd_package_qpid-cpp-server_removed:obj:1" version="1">
          <linux:name>qpid-cpp-server</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of quota_nld" id="oval:ssg-obj_service_not_running_service_quota_nld_disabled_quota_nld:obj:1" version="1">
          <linux:unit operation="pattern match">^quota_nld\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of quota_nld" id="oval:ssg-obj_service_loadstate_is_masked_service_quota_nld_disabled_quota_nld:obj:1" version="1">
          <linux:unit operation="pattern match">^quota_nld\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_quota_nld_disabled_test_service_quota_nld_package_quota-nld_removed:obj:1" version="1">
          <linux:name>quota-nld</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of rdisc" id="oval:ssg-obj_service_not_running_service_rdisc_disabled_rdisc:obj:1" version="1">
          <linux:unit operation="pattern match">^rdisc\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of rdisc" id="oval:ssg-obj_service_loadstate_is_masked_service_rdisc_disabled_rdisc:obj:1" version="1">
          <linux:unit operation="pattern match">^rdisc\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_rdisc_disabled_test_service_rdisc_package_iputils_removed:obj:1" version="1">
          <linux:name>iputils</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of rexec" id="oval:ssg-obj_service_not_running_service_rexec_disabled_rexec:obj:1" version="1">
          <linux:unit operation="pattern match">^rexec\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of rexec" id="oval:ssg-obj_service_loadstate_is_masked_service_rexec_disabled_rexec:obj:1" version="1">
          <linux:unit operation="pattern match">^rexec\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_rexec_disabled_test_service_rexec_package_rsh-server_removed:obj:1" version="1">
          <linux:name>rsh-server</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of rhnsd" id="oval:ssg-obj_service_not_running_service_rhnsd_disabled_rhnsd:obj:1" version="1">
          <linux:unit operation="pattern match">^rhnsd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of rhnsd" id="oval:ssg-obj_service_loadstate_is_masked_service_rhnsd_disabled_rhnsd:obj:1" version="1">
          <linux:unit operation="pattern match">^rhnsd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_rhnsd_disabled_test_service_rhnsd_package_rhnsd_removed:obj:1" version="1">
          <linux:name>rhnsd</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of rhsmcertd" id="oval:ssg-obj_service_not_running_service_rhsmcertd_disabled_rhsmcertd:obj:1" version="1">
          <linux:unit operation="pattern match">^rhsmcertd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of rhsmcertd" id="oval:ssg-obj_service_loadstate_is_masked_service_rhsmcertd_disabled_rhsmcertd:obj:1" version="1">
          <linux:unit operation="pattern match">^rhsmcertd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_rhsmcertd_disabled_test_service_rhsmcertd_package_subscription-manager_removed:obj:1" version="1">
          <linux:name>subscription-manager</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of rlogin" id="oval:ssg-obj_service_not_running_service_rlogin_disabled_rlogin:obj:1" version="1">
          <linux:unit operation="pattern match">^rlogin\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of rlogin" id="oval:ssg-obj_service_loadstate_is_masked_service_rlogin_disabled_rlogin:obj:1" version="1">
          <linux:unit operation="pattern match">^rlogin\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_rlogin_disabled_test_service_rlogin_package_rsh-server_removed:obj:1" version="1">
          <linux:name>rsh-server</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_rngd_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_rngd_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of rngd" id="oval:ssg-obj_service_running_rngd:obj:1" version="1">
          <linux:unit operation="pattern match">^rngd\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_rngd_package_rng-tools_installed:obj:1" version="1">
          <linux:name>rng-tools</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of rpcbind" id="oval:ssg-obj_service_not_running_service_rpcbind_disabled_rpcbind:obj:1" version="1">
          <linux:unit operation="pattern match">^rpcbind\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of rpcbind" id="oval:ssg-obj_service_loadstate_is_masked_service_rpcbind_disabled_rpcbind:obj:1" version="1">
          <linux:unit operation="pattern match">^rpcbind\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_rpcbind_disabled_test_service_rpcbind_package_rpcbind_removed:obj:1" version="1">
          <linux:name>rpcbind</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of rpcgssd" id="oval:ssg-obj_service_not_running_service_rpcgssd_disabled_rpcgssd:obj:1" version="1">
          <linux:unit operation="pattern match">^rpcgssd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of rpcgssd" id="oval:ssg-obj_service_loadstate_is_masked_service_rpcgssd_disabled_rpcgssd:obj:1" version="1">
          <linux:unit operation="pattern match">^rpcgssd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_rpcgssd_disabled_test_service_rpcgssd_package_nfs-utils_removed:obj:1" version="1">
          <linux:name>nfs-utils</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of rpcidmapd" id="oval:ssg-obj_service_not_running_service_rpcidmapd_disabled_rpcidmapd:obj:1" version="1">
          <linux:unit operation="pattern match">^rpcidmapd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of rpcidmapd" id="oval:ssg-obj_service_loadstate_is_masked_service_rpcidmapd_disabled_rpcidmapd:obj:1" version="1">
          <linux:unit operation="pattern match">^rpcidmapd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_rpcidmapd_disabled_test_service_rpcidmapd_package_nfs-utils_removed:obj:1" version="1">
          <linux:name>nfs-utils</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of rpcsvcgssd" id="oval:ssg-obj_service_not_running_service_rpcsvcgssd_disabled_rpcsvcgssd:obj:1" version="1">
          <linux:unit operation="pattern match">^rpcsvcgssd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of rpcsvcgssd" id="oval:ssg-obj_service_loadstate_is_masked_service_rpcsvcgssd_disabled_rpcsvcgssd:obj:1" version="1">
          <linux:unit operation="pattern match">^rpcsvcgssd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_rpcsvcgssd_disabled_test_service_rpcsvcgssd_package_nfs-utils_removed:obj:1" version="1">
          <linux:name>nfs-utils</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of rsh" id="oval:ssg-obj_service_not_running_service_rsh_disabled_rsh:obj:1" version="1">
          <linux:unit operation="pattern match">^rsh\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of rsh" id="oval:ssg-obj_service_loadstate_is_masked_service_rsh_disabled_rsh:obj:1" version="1">
          <linux:unit operation="pattern match">^rsh\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_rsh_disabled_test_service_rsh_package_rsh_removed:obj:1" version="1">
          <linux:name>rsh</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of rsyncd" id="oval:ssg-obj_service_not_running_service_rsyncd_disabled_rsyncd:obj:1" version="1">
          <linux:unit operation="pattern match">^rsyncd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of rsyncd" id="oval:ssg-obj_service_loadstate_is_masked_service_rsyncd_disabled_rsyncd:obj:1" version="1">
          <linux:unit operation="pattern match">^rsyncd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_rsyncd_disabled_test_service_rsyncd_package_rsync-daemon_removed:obj:1" version="1">
          <linux:name>rsync-daemon</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_rsyslog_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_rsyslog_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of rsyslog" id="oval:ssg-obj_service_running_rsyslog:obj:1" version="1">
          <linux:unit operation="pattern match">^rsyslog\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_rsyslog_package_rsyslog_installed:obj:1" version="1">
          <linux:name>rsyslog</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of saslauthd" id="oval:ssg-obj_service_not_running_service_saslauthd_disabled_saslauthd:obj:1" version="1">
          <linux:unit operation="pattern match">^saslauthd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of saslauthd" id="oval:ssg-obj_service_loadstate_is_masked_service_saslauthd_disabled_saslauthd:obj:1" version="1">
          <linux:unit operation="pattern match">^saslauthd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_saslauthd_disabled_test_service_saslauthd_package_cyrus-sasl_removed:obj:1" version="1">
          <linux:name>cyrus-sasl</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of slapd" id="oval:ssg-obj_service_not_running_service_slapd_disabled_slapd:obj:1" version="1">
          <linux:unit operation="pattern match">^slapd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of slapd" id="oval:ssg-obj_service_loadstate_is_masked_service_slapd_disabled_slapd:obj:1" version="1">
          <linux:unit operation="pattern match">^slapd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_slapd_disabled_test_service_slapd_package_openldap-servers_removed:obj:1" version="1">
          <linux:name>openldap-servers</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of smb" id="oval:ssg-obj_service_not_running_service_smb_disabled_smb:obj:1" version="1">
          <linux:unit operation="pattern match">^smb\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of smb" id="oval:ssg-obj_service_loadstate_is_masked_service_smb_disabled_smb:obj:1" version="1">
          <linux:unit operation="pattern match">^smb\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_smb_disabled_test_service_smb_package_samba_removed:obj:1" version="1">
          <linux:name>samba</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of snmpd" id="oval:ssg-obj_service_not_running_service_snmpd_disabled_snmpd:obj:1" version="1">
          <linux:unit operation="pattern match">^snmpd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of snmpd" id="oval:ssg-obj_service_loadstate_is_masked_service_snmpd_disabled_snmpd:obj:1" version="1">
          <linux:unit operation="pattern match">^snmpd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_snmpd_disabled_test_service_snmpd_package_net-snmp_removed:obj:1" version="1">
          <linux:name>net-snmp</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of squid" id="oval:ssg-obj_service_not_running_service_squid_disabled_squid:obj:1" version="1">
          <linux:unit operation="pattern match">^squid\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of squid" id="oval:ssg-obj_service_loadstate_is_masked_service_squid_disabled_squid:obj:1" version="1">
          <linux:unit operation="pattern match">^squid\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_squid_disabled_test_service_squid_package_squid_removed:obj:1" version="1">
          <linux:name>squid</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of sshd" id="oval:ssg-obj_service_not_running_service_sshd_disabled_sshd:obj:1" version="1">
          <linux:unit operation="pattern match">^sshd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of sshd" id="oval:ssg-obj_service_loadstate_is_masked_service_sshd_disabled_sshd:obj:1" version="1">
          <linux:unit operation="pattern match">^sshd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_sshd_disabled_test_service_sshd_package_openssh-server_removed:obj:1" version="1">
          <linux:name>openssh-server</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_sshd_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_sshd_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of sshd" id="oval:ssg-obj_service_running_sshd:obj:1" version="1">
          <linux:unit operation="pattern match">^sshd\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_sshd_package_openssh-server_installed:obj:1" version="1">
          <linux:name>openssh-server</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_sssd_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_sssd_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of sssd" id="oval:ssg-obj_service_running_sssd:obj:1" version="1">
          <linux:unit operation="pattern match">^sssd\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_sssd_package_sssd-common_installed:obj:1" version="1">
          <linux:name>sssd-common</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_syslog-ng_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_syslog-ng_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of syslog-ng" id="oval:ssg-obj_service_running_syslog-ng:obj:1" version="1">
          <linux:unit operation="pattern match">^syslog-ng\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_syslog-ng_package_syslog-ng_installed:obj:1" version="1">
          <linux:name>syslog-ng</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of sysstat" id="oval:ssg-obj_service_not_running_service_sysstat_disabled_sysstat:obj:1" version="1">
          <linux:unit operation="pattern match">^sysstat\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of sysstat" id="oval:ssg-obj_service_loadstate_is_masked_service_sysstat_disabled_sysstat:obj:1" version="1">
          <linux:unit operation="pattern match">^sysstat\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_sysstat_disabled_test_service_sysstat_package_sysstat_removed:obj:1" version="1">
          <linux:name>sysstat</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of systemd-coredump.socket" id="oval:ssg-obj_socket_loadstate_is_masked_systemd-coredump:obj:1" version="1">
          <linux:unit operation="pattern match">^systemd-coredump.socket$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_systemd-journal-upload_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_systemd-journal-upload_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of systemd-journal-upload" id="oval:ssg-obj_service_running_systemd-journal-upload:obj:1" version="1">
          <linux:unit operation="pattern match">^systemd-journal-upload\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_systemd-journal-upload_package_systemd-journal-remote_installed:obj:1" version="1">
          <linux:name>systemd-journal-remote</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_systemd-journald_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_systemd-journald_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of systemd-journald" id="oval:ssg-obj_service_running_systemd-journald:obj:1" version="1">
          <linux:unit operation="pattern match">^systemd-journald\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_systemd-journald_package_systemd_installed:obj:1" version="1">
          <linux:name>systemd</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of telnet" id="oval:ssg-obj_service_not_running_service_telnet_disabled_telnet:obj:1" version="1">
          <linux:unit operation="pattern match">^telnet\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of telnet" id="oval:ssg-obj_service_loadstate_is_masked_service_telnet_disabled_telnet:obj:1" version="1">
          <linux:unit operation="pattern match">^telnet\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_telnet_disabled_test_service_telnet_package_telnet-server_removed:obj:1" version="1">
          <linux:name>telnet-server</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of tftp" id="oval:ssg-obj_service_not_running_service_tftp_disabled_tftp:obj:1" version="1">
          <linux:unit operation="pattern match">^tftp\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of tftp" id="oval:ssg-obj_service_loadstate_is_masked_service_tftp_disabled_tftp:obj:1" version="1">
          <linux:unit operation="pattern match">^tftp\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_tftp_disabled_test_service_tftp_package_tftp-server_removed:obj:1" version="1">
          <linux:name>tftp-server</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_ufw_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_ufw_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of ufw" id="oval:ssg-obj_service_running_ufw:obj:1" version="1">
          <linux:unit operation="pattern match">^ufw\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_ufw_package_ufw_installed:obj:1" version="1">
          <linux:name>ufw</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_usbguard_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_usbguard_socket_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of usbguard" id="oval:ssg-obj_service_running_usbguard:obj:1" version="1">
          <linux:unit operation="pattern match">^usbguard\.(socket|service)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_test_service_usbguard_package_usbguard_installed:obj:1" version="1">
          <linux:name>usbguard</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of vsftpd" id="oval:ssg-obj_service_not_running_service_vsftpd_disabled_vsftpd:obj:1" version="1">
          <linux:unit operation="pattern match">^vsftpd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of vsftpd" id="oval:ssg-obj_service_loadstate_is_masked_service_vsftpd_disabled_vsftpd:obj:1" version="1">
          <linux:unit operation="pattern match">^vsftpd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_vsftpd_disabled_test_service_vsftpd_package_vsftpd_removed:obj:1" version="1">
          <linux:name>vsftpd</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of xinetd" id="oval:ssg-obj_service_not_running_service_xinetd_disabled_xinetd:obj:1" version="1">
          <linux:unit operation="pattern match">^xinetd\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of xinetd" id="oval:ssg-obj_service_loadstate_is_masked_service_xinetd_disabled_xinetd:obj:1" version="1">
          <linux:unit operation="pattern match">^xinetd\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_xinetd_disabled_test_service_xinetd_package_xinetd_removed:obj:1" version="1">
          <linux:name>xinetd</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of ypbind" id="oval:ssg-obj_service_not_running_service_ypbind_disabled_ypbind:obj:1" version="1">
          <linux:unit operation="pattern match">^ypbind\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of ypbind" id="oval:ssg-obj_service_loadstate_is_masked_service_ypbind_disabled_ypbind:obj:1" version="1">
          <linux:unit operation="pattern match">^ypbind\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_ypbind_disabled_test_service_ypbind_package_ypbind_removed:obj:1" version="1">
          <linux:name>ypbind</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of ypserv" id="oval:ssg-obj_service_not_running_service_ypserv_disabled_ypserv:obj:1" version="1">
          <linux:unit operation="pattern match">^ypserv\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of ypserv" id="oval:ssg-obj_service_loadstate_is_masked_service_ypserv_disabled_ypserv:obj:1" version="1">
          <linux:unit operation="pattern match">^ypserv\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_ypserv_disabled_test_service_ypserv_package_ypserv_removed:obj:1" version="1">
          <linux:name>ypserv</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of zebra" id="oval:ssg-obj_service_not_running_service_zebra_disabled_zebra:obj:1" version="1">
          <linux:unit operation="pattern match">^zebra\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of zebra" id="oval:ssg-obj_service_loadstate_is_masked_service_zebra_disabled_zebra:obj:1" version="1">
          <linux:unit operation="pattern match">^zebra\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_zebra_disabled_test_service_zebra_package_quagga_removed:obj:1" version="1">
          <linux:name>quagga</linux:name>
        </linux:rpminfo_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_set_firewalld_default_zone:obj:1" version="1">
          <ind:filepath>/etc/firewalld/firewalld.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*DefaultZone=drop[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of systemd-journal-remote.socket" id="oval:ssg-obj_socket_loadstate_is_masked_systemd-journal-remote:obj:1" version="1">
          <linux:unit operation="pattern match">^systemd-journal-remote.socket$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_allow_only_protocol2:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)Protocol(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_allow_only_protocol2:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_allow_only_protocol2:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_disable_compression:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)Compression(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_disable_compression:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_disable_compression:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_disable_empty_passwords:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)PermitEmptyPasswords(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_disable_empty_passwords:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_disable_empty_passwords:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_disable_forwarding:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)DisableForwarding(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_disable_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_disable_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_disable_gssapi_auth:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)GSSAPIAuthentication(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_disable_gssapi_auth:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_disable_gssapi_auth:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_disable_kerb_auth:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)KerberosAuthentication(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_disable_kerb_auth:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_disable_kerb_auth:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_disable_pubkey_auth:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)PubkeyAuthentication(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_disable_pubkey_auth:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_disable_pubkey_auth:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_disable_rhosts:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)IgnoreRhosts(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_disable_rhosts:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_disable_rhosts:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_disable_rhosts_rsa:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)RhostsRSAAuthentication(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_disable_rhosts_rsa:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_disable_rhosts_rsa:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_disable_root_login:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)PermitRootLogin(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_disable_root_login:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_disable_root_login:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_disable_root_password_login:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)PermitRootLogin(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_disable_root_password_login:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_disable_root_password_login:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_disable_tcp_forwarding:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)AllowTcpForwarding(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_disable_tcp_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_disable_tcp_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_disable_user_known_hosts:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)IgnoreUserKnownHosts(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_disable_user_known_hosts:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_disable_user_known_hosts:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_disable_x11_forwarding:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)X11Forwarding(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_disable_x11_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_disable_x11_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_do_not_permit_user_env:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)PermitUserEnvironment(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_do_not_permit_user_env:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_do_not_permit_user_env:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_enable_gssapi_auth:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)GSSAPIAuthentication(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_enable_gssapi_auth:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_enable_gssapi_auth:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_enable_pam:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)UsePAM(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_enable_pam:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_enable_pam:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_enable_pubkey_auth:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)PubkeyAuthentication(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_enable_pubkey_auth:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_enable_pubkey_auth:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_enable_strictmodes:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)StrictModes(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_enable_strictmodes:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_enable_strictmodes:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_enable_warning_banner:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)Banner(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_enable_warning_banner:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_enable_warning_banner:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_enable_warning_banner_net:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)Banner(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_enable_warning_banner_net:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_enable_warning_banner_net:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_enable_x11_forwarding:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)X11Forwarding(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_enable_x11_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_enable_x11_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_print_last_log:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)PrintLastLog(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_print_last_log:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_print_last_log:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_set_keepalive:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)ClientAliveCountMax(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_set_keepalive:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_set_keepalive:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_set_keepalive_0:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)ClientAliveCountMax(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_set_keepalive_0:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_set_keepalive_0:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_set_loglevel_info:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)LogLevel(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_set_loglevel_info:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_set_loglevel_info:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_set_loglevel_verbose:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)LogLevel(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_set_loglevel_verbose:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_set_loglevel_verbose:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_use_priv_separation:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)UsePrivilegeSeparation(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_use_priv_separation:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_use_priv_separation:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_use_strong_rng:obj:1" version="1">
          <ind:filepath>/etc/sysconfig/sshd</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*SSH_USE_STRONG_RNG=(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sshd_x11_use_localhost:obj:1" version="1">
          <ind:filepath>/etc/ssh/sshd_config</ind:filepath>
          <ind:pattern operation="pattern match">^[ \t]*(?i)X11UseLocalhost(?-i)[ \t]+(.+?)[ \t]*(?:$|#)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="All confs collection" id="oval:ssg-obj_collection_obj_sshd_x11_use_localhost:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-obj_sshd_x11_use_localhost:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_sssd_enable_certmap:obj:1" version="1">
          <ind:filepath>/etc/sssd/sssd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*\[certmap\/.+\/.+\][\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_env_reset_sudoers:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(|\.d/.*)$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*Defaults\b[^!\n]*\benv_reset.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_ignore_dot_sudoers:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(|\.d/.*)$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*Defaults\b[^!\n]*\bignore_dot.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_noexec_sudoers:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(|\.d/.*)$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*Defaults\b[^!\n]*\bnoexec.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_passwd_timeout_sudoers:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(|\.d/.*)$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*Defaults\b[^!\n]*\bpasswd_timeout=(\w+)\b.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_requiretty_sudoers:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(|\.d/.*)$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*Defaults\b[^!\n]*\brequiretty.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_umask_sudoers:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(|\.d/.*)$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*Defaults\b[^!\n]*\bumask=(\w+)\b.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_use_pty_sudoers:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(|\.d/.*)$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*Defaults\b[^!\n]*\buse_pty.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_logfile_sudoers:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/sudoers(|\.d/.*)$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*Defaults\b[^!\n]*\blogfile\s*=\s*(?:"?([^",\s]+)"?).*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/usr/bin/sudo" id="oval:ssg-object_file_permissionssudo_restrict_others_executable_permission_0:obj:1" version="1">
          <unix:filepath>/usr/bin/sudo</unix:filepath>
          <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_sudo_restrict_others_executable_permission:ste:1</oval-def:filter>
          <oval-def:filter action="exclude">oval:ssg-state_file_permissionssudo_restrict_others_executable_permission_0_mode_4110or_stricter_:ste:1</oval-def:filter>
        </unix:file_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_fs_protected_hardlinks_runtime:obj:1" version="1">
          <unix:name>fs.protected_hardlinks</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_fs_protected_hardlinks:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_fs_protected_hardlinks:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_fs_protected_hardlinks:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_fs_protected_hardlinks:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_fs_protected_hardlinks:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_fs_protected_hardlinks:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_fs_protected_hardlinks:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_fs_protected_hardlinks:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_fs_protected_hardlinks:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_fs_protected_hardlinks:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_fs_protected_hardlinks:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_fs_protected_hardlinks:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_fs_protected_hardlinks:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*fs.protected_hardlinks[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_fs_protected_hardlinks:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*fs.protected_hardlinks[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_fs_protected_hardlinks:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*fs.protected_hardlinks[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_fs_protected_hardlinks:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*fs.protected_hardlinks[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_fs_protected_hardlinks:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*fs.protected_hardlinks[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_fs_protected_hardlinks:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*fs.protected_hardlinks[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_fs_protected_symlinks_runtime:obj:1" version="1">
          <unix:name>fs.protected_symlinks</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_fs_protected_symlinks:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_fs_protected_symlinks:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_fs_protected_symlinks:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_fs_protected_symlinks:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_fs_protected_symlinks:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_fs_protected_symlinks:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_fs_protected_symlinks:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_fs_protected_symlinks:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_fs_protected_symlinks:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_fs_protected_symlinks:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_fs_protected_symlinks:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_fs_protected_symlinks:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_fs_protected_symlinks:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*fs.protected_symlinks[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_fs_protected_symlinks:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*fs.protected_symlinks[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_fs_protected_symlinks:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*fs.protected_symlinks[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_fs_protected_symlinks:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*fs.protected_symlinks[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_fs_protected_symlinks:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*fs.protected_symlinks[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_fs_protected_symlinks:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*fs.protected_symlinks[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_fs_suid_dumpable_runtime:obj:1" version="1">
          <unix:name>fs.suid_dumpable</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_fs_suid_dumpable:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_fs_suid_dumpable:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_fs_suid_dumpable:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_fs_suid_dumpable:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_fs_suid_dumpable:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_fs_suid_dumpable:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_fs_suid_dumpable:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_fs_suid_dumpable:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_fs_suid_dumpable:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_fs_suid_dumpable:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_fs_suid_dumpable:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_fs_suid_dumpable:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_fs_suid_dumpable:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*fs.suid_dumpable[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_fs_suid_dumpable:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*fs.suid_dumpable[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_fs_suid_dumpable:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*fs.suid_dumpable[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_fs_suid_dumpable:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*fs.suid_dumpable[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_fs_suid_dumpable:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*fs.suid_dumpable[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_fs_suid_dumpable:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*fs.suid_dumpable[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_core_pattern_runtime:obj:1" version="1">
          <unix:name>kernel.core_pattern</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_kernel_core_pattern:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_core_pattern:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_core_pattern:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_core_pattern:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_kernel_core_pattern:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_kernel_core_pattern:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_kernel_core_pattern:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_kernel_core_pattern:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_kernel_core_pattern:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_core_pattern:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_core_pattern:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_kernel_core_pattern:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_kernel_core_pattern:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*kernel.core_pattern[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_kernel_core_pattern:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.core_pattern[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_kernel_core_pattern:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.core_pattern[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_core_pattern:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.core_pattern[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_core_pattern:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.core_pattern[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_kernel_core_pattern:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.core_pattern[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_core_uses_pid_runtime:obj:1" version="1">
          <unix:name>kernel.core_uses_pid</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_kernel_core_uses_pid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_core_uses_pid:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_core_uses_pid:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_core_uses_pid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_kernel_core_uses_pid:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_kernel_core_uses_pid:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_kernel_core_uses_pid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_kernel_core_uses_pid:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_kernel_core_uses_pid:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_core_uses_pid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_core_uses_pid:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_kernel_core_uses_pid:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_kernel_core_uses_pid:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*kernel.core_uses_pid[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_kernel_core_uses_pid:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.core_uses_pid[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_kernel_core_uses_pid:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.core_uses_pid[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_core_uses_pid:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.core_uses_pid[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_core_uses_pid:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.core_uses_pid[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_kernel_core_uses_pid:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.core_uses_pid[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_dmesg_restrict_runtime:obj:1" version="1">
          <unix:name>kernel.dmesg_restrict</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_kernel_dmesg_restrict:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_dmesg_restrict:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_dmesg_restrict:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_dmesg_restrict:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_kernel_dmesg_restrict:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_kernel_dmesg_restrict:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_kernel_dmesg_restrict:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_kernel_dmesg_restrict:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_kernel_dmesg_restrict:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_dmesg_restrict:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_dmesg_restrict:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_kernel_dmesg_restrict:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_kernel_dmesg_restrict:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*kernel.dmesg_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_kernel_dmesg_restrict:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.dmesg_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_kernel_dmesg_restrict:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.dmesg_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_dmesg_restrict:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.dmesg_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_dmesg_restrict:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.dmesg_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_kernel_dmesg_restrict:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.dmesg_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_kexec_load_disabled_runtime:obj:1" version="1">
          <unix:name>kernel.kexec_load_disabled</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_kernel_kexec_load_disabled:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_kexec_load_disabled:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_kexec_load_disabled:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_kexec_load_disabled:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_kernel_kexec_load_disabled:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_kernel_kexec_load_disabled:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_kernel_kexec_load_disabled:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_kernel_kexec_load_disabled:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_kernel_kexec_load_disabled:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_kexec_load_disabled:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_kexec_load_disabled:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_kernel_kexec_load_disabled:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_kernel_kexec_load_disabled:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*kernel.kexec_load_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_kernel_kexec_load_disabled:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.kexec_load_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_kernel_kexec_load_disabled:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.kexec_load_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_kexec_load_disabled:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.kexec_load_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_kexec_load_disabled:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.kexec_load_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_kernel_kexec_load_disabled:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.kexec_load_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_kptr_restrict_runtime:obj:1" version="1">
          <unix:name>kernel.kptr_restrict</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_kernel_kptr_restrict:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_kptr_restrict:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_kptr_restrict:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_kptr_restrict:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_kernel_kptr_restrict:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_kernel_kptr_restrict:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_kernel_kptr_restrict:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_kernel_kptr_restrict:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_kernel_kptr_restrict:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_kptr_restrict:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_kptr_restrict:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_kernel_kptr_restrict:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_kernel_kptr_restrict:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*kernel.kptr_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_kernel_kptr_restrict:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.kptr_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_kernel_kptr_restrict:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.kptr_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_kptr_restrict:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.kptr_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_kptr_restrict:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.kptr_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_kernel_kptr_restrict:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.kptr_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_modules_disabled_runtime:obj:1" version="1">
          <unix:name>kernel.modules_disabled</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_kernel_modules_disabled:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_modules_disabled:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_modules_disabled:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_modules_disabled:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_kernel_modules_disabled:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_kernel_modules_disabled:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_kernel_modules_disabled:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_kernel_modules_disabled:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_kernel_modules_disabled:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_modules_disabled:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_modules_disabled:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_kernel_modules_disabled:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_kernel_modules_disabled:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*kernel.modules_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_kernel_modules_disabled:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.modules_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_kernel_modules_disabled:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.modules_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_modules_disabled:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.modules_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_modules_disabled:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.modules_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_kernel_modules_disabled:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.modules_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_panic_on_oops_runtime:obj:1" version="1">
          <unix:name>kernel.panic_on_oops</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_kernel_panic_on_oops:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_panic_on_oops:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_panic_on_oops:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_panic_on_oops:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_kernel_panic_on_oops:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_kernel_panic_on_oops:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_kernel_panic_on_oops:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_kernel_panic_on_oops:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_kernel_panic_on_oops:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_panic_on_oops:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_panic_on_oops:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_kernel_panic_on_oops:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_kernel_panic_on_oops:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*kernel.panic_on_oops[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_kernel_panic_on_oops:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.panic_on_oops[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_kernel_panic_on_oops:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.panic_on_oops[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_panic_on_oops:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.panic_on_oops[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_panic_on_oops:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.panic_on_oops[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_kernel_panic_on_oops:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.panic_on_oops[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_perf_cpu_time_max_percent_runtime:obj:1" version="1">
          <unix:name>kernel.perf_cpu_time_max_percent</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_kernel_perf_cpu_time_max_percent:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_perf_cpu_time_max_percent:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_perf_cpu_time_max_percent:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_perf_cpu_time_max_percent:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_kernel_perf_cpu_time_max_percent:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_kernel_perf_cpu_time_max_percent:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_kernel_perf_cpu_time_max_percent:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_kernel_perf_cpu_time_max_percent:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_kernel_perf_cpu_time_max_percent:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_perf_cpu_time_max_percent:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_perf_cpu_time_max_percent:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_kernel_perf_cpu_time_max_percent:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_kernel_perf_cpu_time_max_percent:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_cpu_time_max_percent[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_kernel_perf_cpu_time_max_percent:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_cpu_time_max_percent[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_kernel_perf_cpu_time_max_percent:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_cpu_time_max_percent[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_perf_cpu_time_max_percent:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_cpu_time_max_percent[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_perf_cpu_time_max_percent:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_cpu_time_max_percent[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_kernel_perf_cpu_time_max_percent:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_cpu_time_max_percent[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_perf_event_max_sample_rate_runtime:obj:1" version="1">
          <unix:name>kernel.perf_event_max_sample_rate</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_kernel_perf_event_max_sample_rate:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_perf_event_max_sample_rate:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_perf_event_max_sample_rate:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_perf_event_max_sample_rate:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_kernel_perf_event_max_sample_rate:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_kernel_perf_event_max_sample_rate:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_kernel_perf_event_max_sample_rate:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_kernel_perf_event_max_sample_rate:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_kernel_perf_event_max_sample_rate:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_perf_event_max_sample_rate:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_perf_event_max_sample_rate:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_kernel_perf_event_max_sample_rate:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_kernel_perf_event_max_sample_rate:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_event_max_sample_rate[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_kernel_perf_event_max_sample_rate:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_event_max_sample_rate[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_kernel_perf_event_max_sample_rate:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_event_max_sample_rate[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_perf_event_max_sample_rate:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_event_max_sample_rate[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_perf_event_max_sample_rate:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_event_max_sample_rate[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_kernel_perf_event_max_sample_rate:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_event_max_sample_rate[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_perf_event_paranoid_runtime:obj:1" version="1">
          <unix:name>kernel.perf_event_paranoid</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_kernel_perf_event_paranoid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_perf_event_paranoid:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_perf_event_paranoid:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_perf_event_paranoid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_kernel_perf_event_paranoid:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_kernel_perf_event_paranoid:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_kernel_perf_event_paranoid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_kernel_perf_event_paranoid:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_kernel_perf_event_paranoid:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_perf_event_paranoid:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_perf_event_paranoid:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_kernel_perf_event_paranoid:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_kernel_perf_event_paranoid:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_event_paranoid[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_kernel_perf_event_paranoid:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_event_paranoid[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_kernel_perf_event_paranoid:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_event_paranoid[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_perf_event_paranoid:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_event_paranoid[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_perf_event_paranoid:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_event_paranoid[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_kernel_perf_event_paranoid:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.perf_event_paranoid[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_pid_max_runtime:obj:1" version="1">
          <unix:name>kernel.pid_max</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_kernel_pid_max:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_pid_max:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_pid_max:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_pid_max:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_kernel_pid_max:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_kernel_pid_max:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_kernel_pid_max:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_kernel_pid_max:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_kernel_pid_max:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_pid_max:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_pid_max:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_kernel_pid_max:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_kernel_pid_max:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*kernel.pid_max[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_kernel_pid_max:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.pid_max[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_kernel_pid_max:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.pid_max[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_pid_max:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.pid_max[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_pid_max:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.pid_max[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_kernel_pid_max:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.pid_max[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_randomize_va_space_runtime:obj:1" version="1">
          <unix:name>kernel.randomize_va_space</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_kernel_randomize_va_space:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_randomize_va_space:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_randomize_va_space:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_randomize_va_space:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_kernel_randomize_va_space:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_kernel_randomize_va_space:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_kernel_randomize_va_space:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_kernel_randomize_va_space:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_kernel_randomize_va_space:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_randomize_va_space:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_randomize_va_space:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_kernel_randomize_va_space:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_kernel_randomize_va_space:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*kernel.randomize_va_space[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_kernel_randomize_va_space:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.randomize_va_space[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_kernel_randomize_va_space:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.randomize_va_space[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_randomize_va_space:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.randomize_va_space[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_randomize_va_space:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.randomize_va_space[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_kernel_randomize_va_space:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.randomize_va_space[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_sysrq_runtime:obj:1" version="1">
          <unix:name>kernel.sysrq</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_kernel_sysrq:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_sysrq:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_sysrq:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_sysrq:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_kernel_sysrq:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_kernel_sysrq:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_kernel_sysrq:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_kernel_sysrq:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_kernel_sysrq:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_sysrq:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_sysrq:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_kernel_sysrq:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_kernel_sysrq:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*kernel.sysrq[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_kernel_sysrq:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.sysrq[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_kernel_sysrq:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.sysrq[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_sysrq:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.sysrq[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_sysrq:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.sysrq[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_kernel_sysrq:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.sysrq[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_unprivileged_bpf_disabled_runtime:obj:1" version="1">
          <unix:name>kernel.unprivileged_bpf_disabled</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_kernel_unprivileged_bpf_disabled:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_unprivileged_bpf_disabled:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_unprivileged_bpf_disabled:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_unprivileged_bpf_disabled:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_kernel_unprivileged_bpf_disabled:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_kernel_unprivileged_bpf_disabled:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_kernel_unprivileged_bpf_disabled:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_kernel_unprivileged_bpf_disabled:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_kernel_unprivileged_bpf_disabled:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_unprivileged_bpf_disabled:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_unprivileged_bpf_disabled:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_kernel_unprivileged_bpf_disabled:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_kernel_unprivileged_bpf_disabled:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*kernel.unprivileged_bpf_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_kernel_unprivileged_bpf_disabled:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.unprivileged_bpf_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_kernel_unprivileged_bpf_disabled:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.unprivileged_bpf_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_unprivileged_bpf_disabled:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.unprivileged_bpf_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_unprivileged_bpf_disabled:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.unprivileged_bpf_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_kernel_unprivileged_bpf_disabled:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.unprivileged_bpf_disabled[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_yama_ptrace_scope_runtime:obj:1" version="1">
          <unix:name>kernel.yama.ptrace_scope</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_kernel_yama_ptrace_scope:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_yama_ptrace_scope:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_yama_ptrace_scope:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_yama_ptrace_scope:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_kernel_yama_ptrace_scope:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_kernel_yama_ptrace_scope:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_kernel_yama_ptrace_scope:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_kernel_yama_ptrace_scope:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_kernel_yama_ptrace_scope:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_yama_ptrace_scope:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_yama_ptrace_scope:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_kernel_yama_ptrace_scope:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_kernel_yama_ptrace_scope:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*kernel.yama.ptrace_scope[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_kernel_yama_ptrace_scope:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.yama.ptrace_scope[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_kernel_yama_ptrace_scope:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.yama.ptrace_scope[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_yama_ptrace_scope:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.yama.ptrace_scope[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_yama_ptrace_scope:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.yama.ptrace_scope[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_kernel_yama_ptrace_scope:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*kernel.yama.ptrace_scope[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_core_bpf_jit_harden_runtime:obj:1" version="1">
          <unix:name>net.core.bpf_jit_harden</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_core_bpf_jit_harden:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_core_bpf_jit_harden:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_core_bpf_jit_harden:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_core_bpf_jit_harden:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_core_bpf_jit_harden:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_core_bpf_jit_harden:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_core_bpf_jit_harden:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_core_bpf_jit_harden:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_core_bpf_jit_harden:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_core_bpf_jit_harden:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_core_bpf_jit_harden:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_core_bpf_jit_harden:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_core_bpf_jit_harden:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.core.bpf_jit_harden[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_core_bpf_jit_harden:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.core.bpf_jit_harden[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_core_bpf_jit_harden:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.core.bpf_jit_harden[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_core_bpf_jit_harden:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.core.bpf_jit_harden[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_core_bpf_jit_harden:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.core.bpf_jit_harden[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_core_bpf_jit_harden:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.core.bpf_jit_harden[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_all_accept_local_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.all.accept_local</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_accept_local:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_accept_local:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_accept_local:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_accept_local:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_accept_local:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_accept_local:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_accept_local:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_accept_local:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_accept_local:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_accept_local:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_accept_local:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_accept_local:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_accept_local:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_local[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_accept_local:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_local[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_accept_local:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_local[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_accept_local:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_local[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_accept_local:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_local[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_accept_local:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_local[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_all_accept_redirects_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.all.accept_redirects</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_accept_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_accept_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_accept_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_accept_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_accept_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_accept_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_accept_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_accept_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_accept_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_accept_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_accept_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_accept_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_accept_redirects:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_accept_redirects:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_accept_redirects:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_accept_redirects:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_accept_redirects:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_accept_redirects:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_all_accept_source_route_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.all.accept_source_route</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_accept_source_route:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_accept_source_route:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_accept_source_route:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_accept_source_route:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_accept_source_route:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_accept_source_route:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_accept_source_route:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_accept_source_route:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_accept_source_route:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_accept_source_route:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_accept_source_route:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_accept_source_route:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_accept_source_route:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_accept_source_route:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_accept_source_route:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_accept_source_route:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_accept_source_route:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_accept_source_route:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_all_arp_filter_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.all.arp_filter</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_arp_filter:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_arp_filter:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_arp_filter:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_arp_filter:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_arp_filter:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_arp_filter:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_arp_filter:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_arp_filter:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_arp_filter:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_arp_filter:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_arp_filter:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_arp_filter:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_arp_filter:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.arp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_arp_filter:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.arp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_arp_filter:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.arp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_arp_filter:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.arp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_arp_filter:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.arp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_arp_filter:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.arp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_all_arp_ignore_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.all.arp_ignore</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_arp_ignore:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_arp_ignore:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_arp_ignore:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_arp_ignore:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_arp_ignore:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_arp_ignore:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_arp_ignore:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_arp_ignore:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_arp_ignore:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_arp_ignore:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_arp_ignore:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_arp_ignore:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_arp_ignore:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.arp_ignore[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_arp_ignore:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.arp_ignore[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_arp_ignore:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.arp_ignore[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_arp_ignore:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.arp_ignore[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_arp_ignore:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.arp_ignore[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_arp_ignore:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.arp_ignore[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_all_drop_gratuitous_arp_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.all.drop_gratuitous_arp</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.drop_gratuitous_arp[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.drop_gratuitous_arp[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.drop_gratuitous_arp[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.drop_gratuitous_arp[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.drop_gratuitous_arp[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.drop_gratuitous_arp[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_all_forwarding_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.all.forwarding</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_forwarding:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_forwarding:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_forwarding:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_forwarding:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_forwarding:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_forwarding:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_forwarding:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_forwarding:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_forwarding:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_forwarding:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_all_log_martians_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.all.log_martians</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_log_martians:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_log_martians:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_log_martians:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_log_martians:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_log_martians:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_log_martians:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_log_martians:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_log_martians:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_log_martians:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_log_martians:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_log_martians:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_log_martians:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_log_martians:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.log_martians[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_log_martians:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.log_martians[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_log_martians:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.log_martians[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_log_martians:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.log_martians[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_log_martians:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.log_martians[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_log_martians:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.log_martians[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_all_route_localnet_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.all.route_localnet</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_route_localnet:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_route_localnet:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_route_localnet:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_route_localnet:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_route_localnet:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_route_localnet:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_route_localnet:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_route_localnet:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_route_localnet:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_route_localnet:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_route_localnet:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_route_localnet:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_route_localnet:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.route_localnet[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_route_localnet:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.route_localnet[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_route_localnet:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.route_localnet[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_route_localnet:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.route_localnet[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_route_localnet:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.route_localnet[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_route_localnet:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.route_localnet[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_all_rp_filter_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.all.rp_filter</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_rp_filter:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_rp_filter:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_rp_filter:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_rp_filter:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_rp_filter:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_rp_filter:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_rp_filter:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_rp_filter:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_rp_filter:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_rp_filter:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_rp_filter:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_rp_filter:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_rp_filter:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.rp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_rp_filter:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.rp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_rp_filter:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.rp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_rp_filter:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.rp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_rp_filter:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.rp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_rp_filter:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.rp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_all_secure_redirects_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.all.secure_redirects</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_secure_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_secure_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_secure_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_secure_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_secure_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_secure_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_secure_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_secure_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_secure_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_secure_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_secure_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_secure_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_secure_redirects:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.secure_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_secure_redirects:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.secure_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_secure_redirects:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.secure_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_secure_redirects:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.secure_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_secure_redirects:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.secure_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_secure_redirects:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.secure_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_all_send_redirects_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.all.send_redirects</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_send_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_send_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_send_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_send_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_send_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_send_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_send_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_send_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_send_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_send_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_send_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_send_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_send_redirects:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.send_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_send_redirects:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.send_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_send_redirects:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.send_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_send_redirects:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.send_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_send_redirects:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.send_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_send_redirects:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.send_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_all_shared_media_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.all.shared_media</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_all_shared_media:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_shared_media:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_shared_media:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_all_shared_media:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_shared_media:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_shared_media:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_all_shared_media:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_shared_media:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_shared_media:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_all_shared_media:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_shared_media:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_shared_media:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_all_shared_media:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.shared_media[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_all_shared_media:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.shared_media[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_all_shared_media:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.shared_media[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_all_shared_media:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.shared_media[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_all_shared_media:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.shared_media[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_all_shared_media:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.all.shared_media[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_default_accept_redirects_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.default.accept_redirects</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_accept_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_default_accept_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_default_accept_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_default_accept_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_default_accept_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_default_accept_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_default_accept_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_default_accept_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_default_accept_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_default_accept_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_default_accept_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_default_accept_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_default_accept_redirects:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_default_accept_redirects:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_default_accept_redirects:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_default_accept_redirects:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_default_accept_redirects:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_default_accept_redirects:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_default_accept_source_route_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.default.accept_source_route</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_accept_source_route:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_default_accept_source_route:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_default_accept_source_route:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_default_accept_source_route:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_default_accept_source_route:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_default_accept_source_route:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_default_accept_source_route:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_default_accept_source_route:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_default_accept_source_route:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_default_accept_source_route:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_default_accept_source_route:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_default_accept_source_route:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_default_accept_source_route:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_default_accept_source_route:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_default_accept_source_route:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_default_accept_source_route:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_default_accept_source_route:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_default_accept_source_route:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_default_forwarding_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.default.forwarding</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_default_forwarding:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_default_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_default_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_default_forwarding:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_default_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_default_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_default_forwarding:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_default_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_default_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_default_forwarding:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_default_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_default_forwarding:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_default_forwarding:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_default_forwarding:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_default_forwarding:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_default_forwarding:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_default_forwarding:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_default_log_martians_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.default.log_martians</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_log_martians:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_default_log_martians:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_default_log_martians:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_default_log_martians:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_default_log_martians:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_default_log_martians:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_default_log_martians:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_default_log_martians:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_default_log_martians:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_default_log_martians:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_default_log_martians:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_default_log_martians:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_default_log_martians:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.log_martians[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_default_log_martians:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.log_martians[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_default_log_martians:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.log_martians[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_default_log_martians:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.log_martians[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_default_log_martians:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.log_martians[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_default_log_martians:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.log_martians[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_default_rp_filter_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.default.rp_filter</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_rp_filter:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_default_rp_filter:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_default_rp_filter:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_default_rp_filter:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_default_rp_filter:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_default_rp_filter:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_default_rp_filter:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_default_rp_filter:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_default_rp_filter:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_default_rp_filter:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_default_rp_filter:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_default_rp_filter:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_default_rp_filter:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.rp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_default_rp_filter:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.rp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_default_rp_filter:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.rp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_default_rp_filter:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.rp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_default_rp_filter:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.rp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_default_rp_filter:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.rp_filter[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_default_secure_redirects_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.default.secure_redirects</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_secure_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_default_secure_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_default_secure_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_default_secure_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_default_secure_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_default_secure_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_default_secure_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_default_secure_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_default_secure_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_default_secure_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_default_secure_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_default_secure_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_default_secure_redirects:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.secure_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_default_secure_redirects:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.secure_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_default_secure_redirects:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.secure_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_default_secure_redirects:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.secure_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_default_secure_redirects:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.secure_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_default_secure_redirects:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.secure_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_default_send_redirects_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.default.send_redirects</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_send_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_default_send_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_default_send_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_default_send_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_default_send_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_default_send_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_default_send_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_default_send_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_default_send_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_default_send_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_default_send_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_default_send_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_default_send_redirects:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.send_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_default_send_redirects:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.send_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_default_send_redirects:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.send_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_default_send_redirects:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.send_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_default_send_redirects:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.send_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_default_send_redirects:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.send_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_conf_default_shared_media_runtime:obj:1" version="1">
          <unix:name>net.ipv4.conf.default.shared_media</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_conf_default_shared_media:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_default_shared_media:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_default_shared_media:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_conf_default_shared_media:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_default_shared_media:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_default_shared_media:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_conf_default_shared_media:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_default_shared_media:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_default_shared_media:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_conf_default_shared_media:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_default_shared_media:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_default_shared_media:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_conf_default_shared_media:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.shared_media[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_conf_default_shared_media:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.shared_media[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_conf_default_shared_media:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.shared_media[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_conf_default_shared_media:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.shared_media[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_conf_default_shared_media:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.shared_media[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_conf_default_shared_media:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.conf.default.shared_media[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_runtime:obj:1" version="1">
          <unix:name>net.ipv4.icmp_echo_ignore_broadcasts</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.icmp_echo_ignore_broadcasts[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.icmp_echo_ignore_broadcasts[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.icmp_echo_ignore_broadcasts[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.icmp_echo_ignore_broadcasts[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.icmp_echo_ignore_broadcasts[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.icmp_echo_ignore_broadcasts[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_runtime:obj:1" version="1">
          <unix:name>net.ipv4.icmp_ignore_bogus_error_responses</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.icmp_ignore_bogus_error_responses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.icmp_ignore_bogus_error_responses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.icmp_ignore_bogus_error_responses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.icmp_ignore_bogus_error_responses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.icmp_ignore_bogus_error_responses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.icmp_ignore_bogus_error_responses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_ip_forward_runtime:obj:1" version="1">
          <unix:name>net.ipv4.ip_forward</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_ip_forward:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_ip_forward:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_ip_forward:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_ip_forward:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_ip_forward:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_ip_forward:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_ip_forward:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_ip_forward:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_ip_forward:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_ip_forward:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_ip_forward:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_ip_forward:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_ip_forward:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.ip_forward[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_ip_forward:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.ip_forward[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_ip_forward:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.ip_forward[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_ip_forward:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.ip_forward[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_ip_forward:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.ip_forward[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_ip_forward:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.ip_forward[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_ip_local_port_range_runtime:obj:1" version="1">
          <unix:name>net.ipv4.ip_local_port_range</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_ip_local_port_range:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_ip_local_port_range:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_ip_local_port_range:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_ip_local_port_range:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_ip_local_port_range:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_ip_local_port_range:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_ip_local_port_range:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_ip_local_port_range:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_ip_local_port_range:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_ip_local_port_range:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_ip_local_port_range:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_ip_local_port_range:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_ip_local_port_range:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.ip_local_port_range[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_ip_local_port_range:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.ip_local_port_range[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_ip_local_port_range:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.ip_local_port_range[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_ip_local_port_range:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.ip_local_port_range[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_ip_local_port_range:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.ip_local_port_range[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_ip_local_port_range:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.ip_local_port_range[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_tcp_invalid_ratelimit_runtime:obj:1" version="1">
          <unix:name>net.ipv4.tcp_invalid_ratelimit</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_invalid_ratelimit[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_invalid_ratelimit[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_invalid_ratelimit[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_invalid_ratelimit[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_invalid_ratelimit[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_tcp_invalid_ratelimit:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_invalid_ratelimit[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_tcp_rfc1337_runtime:obj:1" version="1">
          <unix:name>net.ipv4.tcp_rfc1337</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_tcp_rfc1337:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_tcp_rfc1337:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_tcp_rfc1337:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_tcp_rfc1337:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_tcp_rfc1337:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_tcp_rfc1337:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_tcp_rfc1337:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_tcp_rfc1337:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_tcp_rfc1337:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_tcp_rfc1337:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_tcp_rfc1337:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_tcp_rfc1337:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_tcp_rfc1337:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_rfc1337[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_tcp_rfc1337:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_rfc1337[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_tcp_rfc1337:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_rfc1337[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_tcp_rfc1337:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_rfc1337[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_tcp_rfc1337:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_rfc1337[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_tcp_rfc1337:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_rfc1337[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_tcp_syncookies_runtime:obj:1" version="1">
          <unix:name>net.ipv4.tcp_syncookies</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_tcp_syncookies:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_tcp_syncookies:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_tcp_syncookies:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_tcp_syncookies:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_syncookies[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_syncookies[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_syncookies[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_syncookies[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_syncookies[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_syncookies[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_all_accept_ra_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.all.accept_ra</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_ra:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_accept_ra:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_accept_ra:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_accept_ra:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_accept_ra:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_accept_ra:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_accept_ra:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_accept_ra:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_accept_ra:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_accept_ra:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_accept_ra:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_accept_ra:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_accept_ra:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_all_accept_ra_defrtr_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.all.accept_ra_defrtr</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_defrtr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_defrtr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_defrtr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_defrtr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_defrtr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_defrtr:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_defrtr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_all_accept_ra_pinfo_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.all.accept_ra_pinfo</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_pinfo[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_pinfo[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_pinfo[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_pinfo[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_pinfo[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_pinfo:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_pinfo[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.all.accept_ra_rtr_pref</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_rtr_pref[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_rtr_pref[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_rtr_pref[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_rtr_pref[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_rtr_pref[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_ra_rtr_pref[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_all_accept_redirects_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.all.accept_redirects</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_accept_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_accept_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_accept_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_accept_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_accept_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_accept_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_accept_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_accept_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_accept_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_accept_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_accept_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_accept_redirects:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_accept_redirects:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_accept_redirects:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_accept_redirects:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_accept_redirects:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_accept_redirects:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_all_accept_source_route_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.all.accept_source_route</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_accept_source_route:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_accept_source_route:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_accept_source_route:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_accept_source_route:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_accept_source_route:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_accept_source_route:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_accept_source_route:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_accept_source_route:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_accept_source_route:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_accept_source_route:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_accept_source_route:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_accept_source_route:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_accept_source_route:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_accept_source_route:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_accept_source_route:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_accept_source_route:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_accept_source_route:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_accept_source_route:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_all_autoconf_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.all.autoconf</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_autoconf:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_autoconf:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_autoconf:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_autoconf:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_autoconf:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_autoconf:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_autoconf:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_autoconf:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_autoconf:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_autoconf:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_autoconf:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_autoconf:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_autoconf:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.autoconf[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_autoconf:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.autoconf[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_autoconf:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.autoconf[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_autoconf:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.autoconf[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_autoconf:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.autoconf[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_autoconf:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.autoconf[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_all_disable_ipv6_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.all.disable_ipv6</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_disable_ipv6:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.disable_ipv6[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_all_forwarding_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.all.forwarding</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_forwarding:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_forwarding:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_forwarding:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_forwarding:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_forwarding:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_forwarding:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_forwarding:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_forwarding:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_forwarding:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_forwarding:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_all_max_addresses_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.all.max_addresses</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_max_addresses:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_max_addresses:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_max_addresses:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_max_addresses:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_max_addresses:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_max_addresses:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_max_addresses:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_max_addresses:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_max_addresses:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_max_addresses:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_max_addresses:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_max_addresses:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_max_addresses:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.max_addresses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_max_addresses:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.max_addresses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_max_addresses:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.max_addresses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_max_addresses:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.max_addresses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_max_addresses:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.max_addresses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_max_addresses:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.max_addresses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_all_router_solicitations_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.all.router_solicitations</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_all_router_solicitations:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_router_solicitations:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_router_solicitations:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_all_router_solicitations:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_router_solicitations:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_router_solicitations:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_all_router_solicitations:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_router_solicitations:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_router_solicitations:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_all_router_solicitations:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_router_solicitations:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_router_solicitations:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_all_router_solicitations:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.router_solicitations[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_all_router_solicitations:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.router_solicitations[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_all_router_solicitations:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.router_solicitations[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_all_router_solicitations:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.router_solicitations[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_all_router_solicitations:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.router_solicitations[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_all_router_solicitations:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.all.router_solicitations[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_default_accept_ra_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.default.accept_ra</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_ra:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_accept_ra:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_accept_ra:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_accept_ra:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_accept_ra:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_accept_ra:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_accept_ra:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_accept_ra:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_accept_ra:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_accept_ra:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_accept_ra:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_accept_ra:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_accept_ra:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_default_accept_ra_defrtr_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.default.accept_ra_defrtr</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_defrtr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_defrtr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_defrtr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_defrtr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_defrtr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_defrtr:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_defrtr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_default_accept_ra_pinfo_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.default.accept_ra_pinfo</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_pinfo[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_pinfo[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_pinfo[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_pinfo[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_pinfo[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_pinfo:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_pinfo[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.default.accept_ra_rtr_pref</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_rtr_pref[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_rtr_pref[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_rtr_pref[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_rtr_pref[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_rtr_pref[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_ra_rtr_pref[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_default_accept_redirects_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.default.accept_redirects</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_accept_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_accept_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_accept_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_accept_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_accept_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_accept_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_accept_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_accept_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_accept_redirects:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_accept_redirects:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_accept_redirects:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_accept_redirects:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_accept_redirects:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_accept_redirects:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_accept_redirects:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_accept_redirects:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_accept_redirects:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_redirects[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_default_accept_source_route_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.default.accept_source_route</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_accept_source_route:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_accept_source_route:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_accept_source_route:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_accept_source_route:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_accept_source_route:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_accept_source_route:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_accept_source_route:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_accept_source_route:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_accept_source_route:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_accept_source_route:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_accept_source_route:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_accept_source_route:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_accept_source_route:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_accept_source_route:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_accept_source_route:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_accept_source_route:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_accept_source_route:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_accept_source_route:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.accept_source_route[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_default_autoconf_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.default.autoconf</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_autoconf:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_autoconf:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_autoconf:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_autoconf:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_autoconf:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_autoconf:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_autoconf:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_autoconf:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_autoconf:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_autoconf:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_autoconf:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_autoconf:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_autoconf:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.autoconf[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_autoconf:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.autoconf[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_autoconf:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.autoconf[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_autoconf:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.autoconf[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_autoconf:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.autoconf[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_autoconf:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.autoconf[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_default_disable_ipv6_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.default.disable_ipv6</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.disable_ipv6[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.disable_ipv6[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.disable_ipv6[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.disable_ipv6[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.disable_ipv6[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_disable_ipv6:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.disable_ipv6[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_default_forwarding_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.default.forwarding</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_forwarding:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_forwarding:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_forwarding:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_forwarding:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_forwarding:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_forwarding:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_forwarding:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_forwarding:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_forwarding:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_forwarding:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_forwarding:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_forwarding:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.forwarding[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_default_max_addresses_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.default.max_addresses</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_max_addresses:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_max_addresses:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_max_addresses:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_max_addresses:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_max_addresses:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_max_addresses:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_max_addresses:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_max_addresses:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_max_addresses:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_max_addresses:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_max_addresses:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_max_addresses:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_max_addresses:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.max_addresses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_max_addresses:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.max_addresses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_max_addresses:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.max_addresses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_max_addresses:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.max_addresses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_max_addresses:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.max_addresses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_max_addresses:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.max_addresses[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv6_conf_default_router_solicitations_runtime:obj:1" version="1">
          <unix:name>net.ipv6.conf.default.router_solicitations</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv6_conf_default_router_solicitations:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_router_solicitations:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_router_solicitations:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv6_conf_default_router_solicitations:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_router_solicitations:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_router_solicitations:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv6_conf_default_router_solicitations:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_router_solicitations:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_router_solicitations:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv6_conf_default_router_solicitations:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_router_solicitations:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_router_solicitations:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv6_conf_default_router_solicitations:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.router_solicitations[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv6_conf_default_router_solicitations:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.router_solicitations[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv6_conf_default_router_solicitations:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.router_solicitations[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv6_conf_default_router_solicitations:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.router_solicitations[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv6_conf_default_router_solicitations:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.router_solicitations[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv6_conf_default_router_solicitations:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*net.ipv6.conf.default.router_solicitations[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_user_max_user_namespaces_runtime:obj:1" version="1">
          <unix:name>user.max_user_namespaces</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_user_max_user_namespaces:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_user_max_user_namespaces:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_user_max_user_namespaces:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_user_max_user_namespaces:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_user_max_user_namespaces:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_user_max_user_namespaces:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_user_max_user_namespaces:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_user_max_user_namespaces:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_user_max_user_namespaces:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_user_max_user_namespaces:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_user_max_user_namespaces:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_user_max_user_namespaces:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_user_max_user_namespaces:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*user.max_user_namespaces[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_user_max_user_namespaces:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*user.max_user_namespaces[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_user_max_user_namespaces:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*user.max_user_namespaces[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_user_max_user_namespaces:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*user.max_user_namespaces[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_user_max_user_namespaces:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*user.max_user_namespaces[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_user_max_user_namespaces:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*user.max_user_namespaces[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_user_max_user_namespaces_no_remediation_runtime:obj:1" version="1">
          <unix:name>user.max_user_namespaces</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_user_max_user_namespaces_no_remediation:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_user_max_user_namespaces_no_remediation:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_user_max_user_namespaces_no_remediation:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_user_max_user_namespaces_no_remediation:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_user_max_user_namespaces_no_remediation:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_user_max_user_namespaces_no_remediation:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_user_max_user_namespaces_no_remediation:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_user_max_user_namespaces_no_remediation:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_user_max_user_namespaces_no_remediation:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_user_max_user_namespaces_no_remediation:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_user_max_user_namespaces_no_remediation:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_user_max_user_namespaces_no_remediation:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_user_max_user_namespaces_no_remediation:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*user.max_user_namespaces[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_user_max_user_namespaces_no_remediation:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*user.max_user_namespaces[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_user_max_user_namespaces_no_remediation:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*user.max_user_namespaces[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_user_max_user_namespaces_no_remediation:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*user.max_user_namespaces[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_user_max_user_namespaces_no_remediation:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*user.max_user_namespaces[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_user_max_user_namespaces_no_remediation:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*user.max_user_namespaces[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-object_sysctl_vm_mmap_min_addr_runtime:obj:1" version="1">
          <unix:name>vm.mmap_min_addr</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_vm_mmap_min_addr:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_vm_mmap_min_addr:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_vm_mmap_min_addr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_vm_mmap_min_addr:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_vm_mmap_min_addr:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_vm_mmap_min_addr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_vm_mmap_min_addr:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_vm_mmap_min_addr:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_vm_mmap_min_addr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_vm_mmap_min_addr:obj:1" version="1">
          <oval-def:set>
            <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_vm_mmap_min_addr:obj:1</oval-def:object_reference>
            <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_vm_mmap_min_addr:obj:1</oval-def:object_reference>
          </oval-def:set>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_vm_mmap_min_addr:obj:1" version="1">
          <ind:filepath>/etc/sysctl.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*vm.mmap_min_addr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_vm_mmap_min_addr:obj:1" version="1">
          <ind:path>/etc/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*vm.mmap_min_addr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_vm_mmap_min_addr:obj:1" version="1">
          <ind:path>/run/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*vm.mmap_min_addr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_vm_mmap_min_addr:obj:1" version="1">
          <ind:path>/usr/local/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*vm.mmap_min_addr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_vm_mmap_min_addr:obj:1" version="1">
          <ind:path>/usr/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*vm.mmap_min_addr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_vm_mmap_min_addr:obj:1" version="1">
          <ind:path>/lib/sysctl.d</ind:path>
          <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
          <ind:pattern operation="pattern match">^[\s]*vm.mmap_min_addr[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_tmp_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of tmp" id="oval:ssg-obj_mount_running_tmp:obj:1" version="1">
          <linux:unit operation="equals">tmp.mount</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_dnf-automatic_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of dnf-automatic" id="oval:ssg-obj_timer_running_dnf-automatic:obj:1" version="1">
          <linux:unit operation="pattern match">dnf-automatic\.timer</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitdependency_object comment="list of dependencies of multi-user.target" id="oval:ssg-object_multi_user_target_for_logrotate_enabled:obj:1" version="1">
          <linux:unit>multi-user.target</linux:unit>
        </linux:systemdunitdependency_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of logrotate" id="oval:ssg-obj_timer_running_logrotate:obj:1" version="1">
          <linux:unit operation="pattern match">logrotate\.timer</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <ind:textfilecontent54_object comment="Check use_uid configuration of PAM pam_wheel.so module" id="oval:ssg-object_pam_auth_pam_wheel_use_uid:obj:1" version="1">
          <ind:filepath>/etc/pam.d/su</ind:filepath>
          <ind:pattern operation="pattern match">^\s*auth(?:(?!\n)\s)+required(?:(?!\n)\s)+pam_wheel.so((?!\n)\s[^\n]+)?(?!\n)\s+use_uid((\s+\S+)*\s*\\*\s*)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check group configuration of PAM pam_wheel.so module" id="oval:ssg-object_pam_auth_pam_wheel_group:obj:1" version="1">
          <ind:filepath>/etc/pam.d/su</ind:filepath>
          <ind:pattern operation="pattern match">^\s*auth\s+required\s+pam_wheel.so.*\sgroup=(-?[a-zA-Z0-9]+)(?:\s+.*)?</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_zipl_audit_argument_audit_1_argument_in_boot_loader_entries_conf:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/loader/entries/.*.conf</ind:filepath>
          <ind:pattern operation="pattern match">^options (.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_zipl_audit_argument_audit_1_argument_in_etc_kernel_cmdline:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/kernel/cmdline</ind:filepath>
          <ind:pattern operation="pattern match">^(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_zipl_audit_backlog_limit_argument_audit_backlog_limit_8192_argument_in_boot_loader_entries_conf:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/loader/entries/.*.conf</ind:filepath>
          <ind:pattern operation="pattern match">^options (.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_zipl_audit_backlog_limit_argument_audit_backlog_limit_8192_argument_in_etc_kernel_cmdline:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/kernel/cmdline</ind:filepath>
          <ind:pattern operation="pattern match">^(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_zipl_page_poison_argument_page_poison_1_argument_in_boot_loader_entries_conf:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/loader/entries/.*.conf</ind:filepath>
          <ind:pattern operation="pattern match">^options (.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_zipl_page_poison_argument_page_poison_1_argument_in_etc_kernel_cmdline:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/kernel/cmdline</ind:filepath>
          <ind:pattern operation="pattern match">^(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_zipl_slub_debug_argument_slub_debug_P_argument_in_boot_loader_entries_conf:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/loader/entries/.*.conf</ind:filepath>
          <ind:pattern operation="pattern match">^options (.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_zipl_slub_debug_argument_slub_debug_P_argument_in_etc_kernel_cmdline:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/kernel/cmdline</ind:filepath>
          <ind:pattern operation="pattern match">^(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_zipl_vsyscall_argument_vsyscall_none_argument_in_boot_loader_entries_conf:obj:1" version="1">
          <ind:filepath operation="pattern match">^/boot/loader/entries/.*.conf</ind:filepath>
          <ind:pattern operation="pattern match">^options (.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_zipl_vsyscall_argument_vsyscall_none_argument_in_etc_kernel_cmdline:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/kernel/cmdline</ind:filepath>
          <ind:pattern operation="pattern match">^(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_password_pam_pwquality:obj:1" version="1">
          <ind:filepath var_check="at least one" var_ref="oval:ssg-var_pam_pwquality_config_path:var:1"/>
          <ind:pattern operation="pattern match">^\s*password\s+(?:(?:required)|(?:requisite))\s+pam_pwquality\.so.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_auditctl:obj:1" version="1">
          <ind:filepath>/usr/lib/systemd/system/auditd.service</ind:filepath>
          <ind:pattern operation="pattern match">^ExecStartPost=\-\/sbin\/auditctl.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_audit_rules_augenrules:obj:1" version="1">
          <ind:filepath>/usr/lib/systemd/system/auditd.service</ind:filepath>
          <ind:pattern operation="pattern match">^(ExecStartPost=\-\/sbin\/augenrules.*$|Requires=augenrules.service)</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_setdomainname_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+setdomainname[\s]+|([\s]+|[,])setdomainname([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_setdomainname_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+setdomainname[\s]+|([\s]+|[,])setdomainname([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_setdomainname_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+setdomainname[\s]+|([\s]+|[,])setdomainname([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_setdomainname_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+setdomainname[\s]+|([\s]+|[,])setdomainname([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_sethostname_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+sethostname[\s]+|([\s]+|[,])sethostname([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_sethostname_augenrules:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+sethostname[\s]+|([\s]+|[,])sethostname([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_32bit_sethostname_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+sethostname[\s]+|([\s]+|[,])sethostname([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_64bit_sethostname_auditctl:obj:1" version="1">
          <ind:filepath>/etc/audit/audit.rules</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+sethostname[\s]+|([\s]+|[,])sethostname([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_auditd_conf_log_file:obj:1" version="1">
          <ind:filepath operation="equals">/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^(log_file\s*=\s*.*)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="log_group = root" id="oval:ssg-object_auditd_conf_log_group_root:obj:1" version="1">
          <ind:filepath operation="equals">/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*log_group[ ]+=[ ]+root[ ]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="log_group is set" id="oval:ssg-object_auditd_conf_log_group_is_set:obj:1" version="1">
          <ind:filepath operation="equals">/etc/audit/auditd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[ ]*log_group[ ]+=.*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:rpminfo_object id="oval:ssg-obj_bootc_platform_test_kernel_installed:obj:1" version="1">
          <linux:name>kernel</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_bootc_platform_test_rpm_ostree_installed:obj:1" version="1">
          <linux:name>rpm-ostree</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_bootc_platform_test_bootc_installed:obj:1" version="1">
          <linux:name>bootc</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_bootc_platform_test_openshift_kubelet_removed:obj:1" version="1">
          <linux:name>openshift-kubelet</linux:name>
        </linux:rpminfo_object>
        <unix:file_object comment="The file /run/ostree-booted exists" id="oval:ssg-bootc_platform_obj_run_ostree_booted_exists:obj:1" version="1">
          <unix:filepath operation="equals">/run/ostree-booted</unix:filepath>
        </unix:file_object>
        <unix:file_object comment="The file /ostree exists" id="oval:ssg-bootc_platform_obj_ostree_symlink_exists:obj:1" version="1">
          <unix:filepath operation="equals">/ostree</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_bootloader_disable_recovery_argument:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_DISABLE_RECOVERY=(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Ensure more than one chronyd NTP server is set" id="oval:ssg-object_chronyd_multiple_servers:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/chrony\.(conf|d/.+\.conf)$</ind:filepath>
          <ind:pattern operation="pattern match">^([\s]*server[\s]+.+$){2,}$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="check /etc/almalinux file" id="oval:ssg-obj_almalinux:obj:1" version="1">
          <unix:filepath>/etc/almalinux-release</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object comment="Check AlmaLinux OS version" id="oval:ssg-obj_almalinux8:obj:1" version="1">
          <ind:filepath>/etc/almalinux-release</ind:filepath>
          <ind:pattern operation="pattern match">^AlmaLinux release 8.[0-9]+ .*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:rpminfo_object id="oval:ssg-object_hummingbird_release_rpm:obj:1" version="1">
          <linux:name operation="pattern match">hummingbird-release.*</linux:name>
        </linux:rpminfo_object>
        <ind:textfilecontent54_object id="oval:ssg-object_hummingbird_vendor_product:obj:1" version="1">
          <ind:filepath>/etc/system-release-cpe</ind:filepath>
          <ind:pattern operation="pattern match">^cpe:\/a:redhat:hummingbird:[\d]+$</ind:pattern>
          <ind:instance datatype="int" operation="equals">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:rpminfo_object id="oval:ssg-obj_ol7_system:obj:1" version="1">
          <linux:name>oraclelinux-release</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_ol8_system:obj:1" version="1">
          <linux:name>oraclelinux-release</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_ol9_system:obj:1" version="1">
          <linux:name>oraclelinux-release</linux:name>
        </linux:rpminfo_object>
        <ind:family_object id="oval:ssg-object_unix_family:obj:1" version="1"/>
        <ind:textfilecontent54_object id="oval:ssg-obj_rhcos:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^ID="(\w+)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rhel_coreos_variant:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^VARIANT_ID=(\S+)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rhel_coreos_version9:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^VERSION_ID="(\d+\.\d+)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rhel_coreos_version10:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^VERSION_ID="(\d+\.\d+)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rhcos4:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^OPENSHIFT_VERSION="(\d)\.\d+"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rhcos4_rhel8_rhel_version:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^RHEL_VERSION="?(\d+\.?\d*)"?$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rhel_id:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^ID="(\w+)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rhcos4_rhel9_rhel_version:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^RHEL_VERSION="?(\d+\.?\d*)"?$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:family_object id="oval:ssg-obj_rhel10_unix_family:obj:1" version="1"/>
        <linux:rpminfo_object id="oval:ssg-obj_rhel10:obj:1" version="1">
          <linux:name>redhat-release</linux:name>
        </linux:rpminfo_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rhevh_rhel10_version:obj:1" version="1">
          <ind:filepath>/etc/redhat-release</ind:filepath>
          <ind:pattern operation="pattern match">^Red Hat Enterprise Linux release (\d)\.\d+$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:family_object id="oval:ssg-obj_rhel8_unix_family:obj:1" version="1"/>
        <linux:rpminfo_object id="oval:ssg-obj_rhel8:obj:1" version="1">
          <linux:name>redhat-release</linux:name>
        </linux:rpminfo_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rhevh_rhel8_version:obj:1" version="1">
          <ind:filepath>/etc/redhat-release</ind:filepath>
          <ind:pattern operation="pattern match">^Red Hat Enterprise Linux release (\d)\.\d+$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:family_object id="oval:ssg-obj_rhel9_unix_family:obj:1" version="1"/>
        <linux:rpminfo_object id="oval:ssg-obj_rhel9:obj:1" version="1">
          <linux:name>redhat-release</linux:name>
        </linux:rpminfo_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rhevh_rhel9_version:obj:1" version="1">
          <ind:filepath>/etc/redhat-release</ind:filepath>
          <ind:pattern operation="pattern match">^Red Hat Enterprise Linux release (\d)\.\d+$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:rpminfo_object id="oval:ssg-obj_rhvh4_version:obj:1" version="1">
          <linux:name>redhat-release-virtualization-host</linux:name>
        </linux:rpminfo_object>
        <ind:family_object id="oval:ssg-obj_sle12_unix_family:obj:1" version="1"/>
        <linux:rpminfo_object id="oval:ssg-obj_sle12_desktop:obj:1" version="1">
          <linux:name>sled-release</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_sle12_server:obj:1" version="1">
          <linux:name>sles-release</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_sles_12_for_sap:obj:1" version="1">
          <linux:name>SLES_SAP-release</linux:name>
        </linux:rpminfo_object>
        <ind:family_object id="oval:ssg-obj_sle15_unix_family:obj:1" version="1"/>
        <linux:rpminfo_object id="oval:ssg-obj_sle15_desktop:obj:1" version="1">
          <linux:name>sled-release</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_sle15_server:obj:1" version="1">
          <linux:name>sles-release</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_sles_15_for_sap:obj:1" version="1">
          <linux:name>SLES_SAP-release</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_suma_4:obj:1" version="1">
          <linux:name>SUSE-Manager-Server-release</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_sle_hpc:obj:1" version="1">
          <linux:name>SLE_HPC-release</linux:name>
        </linux:rpminfo_object>
        <ind:family_object id="oval:ssg-obj_sle16_unix_family:obj:1" version="1"/>
        <linux:rpminfo_object id="oval:ssg-obj_sle16_server:obj:1" version="1">
          <linux:name>SLES-release</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_sles_16_for_sap:obj:1" version="1">
          <linux:name>SLES_SAP-release</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_sles_16_for_ha:obj:1" version="1">
          <linux:name>sle-ha-release</linux:name>
        </linux:rpminfo_object>
        <ind:family_object id="oval:ssg-obj_slmicro5_unix_family:obj:1" version="1"/>
        <linux:rpminfo_object id="oval:ssg-obj_slmicroos5:obj:1" version="1">
          <linux:name>SUSE-MicroOS-release</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_slmicro5:obj:1" version="1">
          <linux:name>SLE-Micro-release</linux:name>
        </linux:rpminfo_object>
        <ind:family_object id="oval:ssg-obj_slmicro6_unix_family:obj:1" version="1"/>
        <linux:rpminfo_object id="oval:ssg-obj_slmicro6:obj:1" version="1">
          <linux:name>SL-Micro-release</linux:name>
        </linux:rpminfo_object>
        <unix:file_object comment="check /etc/lsb-release file" id="oval:ssg-obj_lsb:obj:1" version="1">
          <unix:filepath>/etc/lsb-release</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object comment="Check Ubuntu" id="oval:ssg-obj_ubuntu:obj:1" version="1">
          <ind:filepath>/etc/lsb-release</ind:filepath>
          <ind:pattern operation="pattern match">^DISTRIB_ID=Ubuntu$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check Ubuntu version" id="oval:ssg-obj_ubuntu_jammy:obj:1" version="1">
          <ind:filepath>/etc/lsb-release</ind:filepath>
          <ind:pattern operation="pattern match">^DISTRIB_CODENAME=jammy$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object comment="Check Ubuntu version" id="oval:ssg-obj_ubuntu_noble:obj:1" version="1">
          <ind:filepath>/etc/lsb-release</ind:filepath>
          <ind:pattern operation="pattern match">^DISTRIB_CODENAME=noble$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_no_cd_dvd_drive_in_etc_fstab:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern datatype="string" operation="pattern match" var_check="at least one" var_ref="oval:ssg-variable_cd_dvd_drive_alternative_names:var:1"/>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object id="oval:ssg-object_removable_partition_doesnt_exist:obj:1" version="1">
          <unix:filepath var_check="at least one" var_ref="oval:ssg-var_removable_partition:var:1"/>
        </unix:file_object>
        <ind:variable_object id="oval:ssg-object_sshd_not_required:obj:1" version="1">
          <ind:var_ref>oval:ssg-sshd_required:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:variable_object id="oval:ssg-object_sshd_required:obj:1" version="1">
          <ind:var_ref>oval:ssg-sshd_required:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:variable_object id="oval:ssg-object_sshd_requirement_unknown:obj:1" version="1">
          <ind:var_ref>oval:ssg-sshd_required:var:1</ind:var_ref>
        </ind:variable_object>
        <unix:uname_object comment="64 bit architecture" id="oval:ssg-object_system_info_architecture_aarch_64:obj:1" version="1"/>
        <unix:uname_object comment="64 bit architecture" id="oval:ssg-object_system_info_architecture_ppc_64:obj:1" version="1"/>
        <unix:uname_object comment="64 bit architecture" id="oval:ssg-object_system_info_architecture_ppcle_64:obj:1" version="1"/>
        <unix:uname_object comment="64 bit architecture" id="oval:ssg-object_system_info_architecture_s390_64:obj:1" version="1"/>
        <unix:uname_object comment="32 bit architecture" id="oval:ssg-object_system_info_architecture_x86:obj:1" version="1"/>
        <unix:uname_object comment="64 bit architecture" id="oval:ssg-object_system_info_architecture_x86_64:obj:1" version="1"/>
        <unix:file_object comment="/etc/tmux.conf" id="oval:ssg-object_tmux_conf_readable_by_others:obj:1" version="1">
          <unix:filepath operation="equals">/etc/tmux.conf</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_usbguard_rules_nonempty:obj:1" version="1">
          <ind:filepath operation="pattern match">^/etc/usbguard/(rules|rules\.d/.*)\.conf$</ind:filepath>
          <ind:pattern operation="pattern match">^.*\S+.*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:variable_object id="oval:ssg-object_var_accounts_user_umask_umask_as_number:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_accounts_user_umask_umask_as_number:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:variable_object id="oval:ssg-object_var_removable_partition_is_cd_dvd_drive:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_removable_partition:var:1</ind:var_ref>
        </ind:variable_object>
        <ind:variable_object id="oval:ssg-object_var_umask_for_daemons_umask_as_number:obj:1" version="1">
          <ind:var_ref>oval:ssg-var_umask_for_daemons_umask_as_number:var:1</ind:var_ref>
        </ind:variable_object>
      </oval-def:objects>
      <oval-def:states>
        <ind:textfilecontent54_state id="oval:ssg-state_ars_shutdown:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_check="all" var_ref="oval:ssg-var_audit_failure_mode:var:1"/>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_group_owner_not_root_var_log_audit_directories:ste:1" operator="OR" version="1">
          <unix:group_id datatype="int" operation="not equal">0</unix:group_id>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_group_owner_not_root_var_log_audit_directories-non_root:ste:1" operator="OR" version="1">
          <unix:group_id datatype="int" operation="not equal">0</unix:group_id>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_owner_not_root_var_log_audit_directories:ste:1" operator="OR" version="1">
          <unix:user_id datatype="int" operation="not equal">0</unix:user_id>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_mode_0700:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uread datatype="boolean">true</unix:uread>
          <unix:uwrite datatype="boolean">true</unix:uwrite>
          <unix:uexec datatype="boolean">true</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_mode_0750:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uread datatype="boolean">true</unix:uread>
          <unix:uwrite datatype="boolean">true</unix:uwrite>
          <unix:uexec datatype="boolean">true</unix:uexec>
          <unix:gread datatype="boolean">true</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">true</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_group_owner_not_root_var_log_audit:ste:1" operator="OR" version="1">
          <unix:group_id datatype="int" operation="not equal">0</unix:group_id>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_owner_not_root_root_var_log_audit:ste:1" operator="OR" version="1">
          <unix:group_id datatype="int" operation="not equal">0</unix:group_id>
          <unix:user_id datatype="int" operation="not equal">0</unix:user_id>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_owner_not_root_var_log_audit-non_root:ste:1" operator="OR" version="1">
          <unix:group_id datatype="int" operation="not equal">0</unix:group_id>
          <unix:user_id datatype="int" operation="equals">0</unix:user_id>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_owner_not_root_var_log_audit:ste:1" operator="OR" version="1">
          <unix:user_id datatype="int" operation="not equal">0</unix:user_id>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_not_mode_0640:ste:1" operator="OR" version="1">
          <unix:suid datatype="boolean">true</unix:suid>
          <unix:sgid datatype="boolean">true</unix:sgid>
          <unix:sticky datatype="boolean">true</unix:sticky>
          <unix:uexec datatype="boolean">true</unix:uexec>
          <unix:gwrite datatype="boolean">true</unix:gwrite>
          <unix:gexec datatype="boolean">true</unix:gexec>
          <unix:oread datatype="boolean">true</unix:oread>
          <unix:owrite datatype="boolean">true</unix:owrite>
          <unix:oexec datatype="boolean">true</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_not_mode_0600:ste:1" operator="OR" version="1">
          <unix:suid datatype="boolean">true</unix:suid>
          <unix:sgid datatype="boolean">true</unix:sgid>
          <unix:sticky datatype="boolean">true</unix:sticky>
          <unix:uexec datatype="boolean">true</unix:uexec>
          <unix:gread datatype="boolean">true</unix:gread>
          <unix:gwrite datatype="boolean">true</unix:gwrite>
          <unix:gexec datatype="boolean">true</unix:gexec>
          <unix:oread datatype="boolean">true</unix:oread>
          <unix:owrite datatype="boolean">true</unix:owrite>
          <unix:oexec datatype="boolean">true</unix:oexec>
        </unix:file_state>
        <linux:partition_state id="oval:ssg-state_audit_rules_privileged_commands_dev_partitons:ste:1" operator="AND" version="1">
          <linux:device operation="pattern match">^(/dev/.*|composefs)$</linux:device>
        </linux:partition_state>
        <linux:partition_state id="oval:ssg-state_audit_rules_privileged_commands_nosuid_partitons:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nosuid</linux:mount_options>
        </linux:partition_state>
        <linux:partition_state id="oval:ssg-state_audit_rules_privileged_commands_noexec_partitons:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">noexec</linux:mount_options>
        </linux:partition_state>
        <unix:file_state id="oval:ssg-state_setuid_or_setgid_set:ste:1" operator="OR" version="1">
          <unix:suid datatype="boolean">true</unix:suid>
          <unix:sgid datatype="boolean">true</unix:sgid>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_dracut_tmp_files:ste:1" operator="AND" version="1">
          <unix:filepath operation="pattern match">^/var/tmp/dracut.*</unix:filepath>
        </unix:file_state>
        <unix:file_state comment="Used to filter out all files in the /sysroot directory" id="oval:ssg-state_audit_rules_privileged_commands_sysroot:ste:1" operator="AND" version="1">
          <unix:filepath operation="pattern match">^/sysroot/.*$</unix:filepath>
        </unix:file_state>
        <ind:textfilecontent54_state id="oval:ssg-state_unprivileged_commands:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="not equal" var_check="all" var_ref="oval:ssg-var_audit_rules_privileged_commands_priv_cmds:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_priv_cmds_from_system:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match" var_check="at least one" var_ref="oval:ssg-var_audit_rules_privileged_commands_priv_cmds:var:1"/>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_priv_cmds_from_augenrules_count:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_check="at least one" var_ref="oval:ssg-var_priv_cmds_from_augenrules_count:var:1"/>
        </ind:variable_state>
        <ind:variable_state id="oval:ssg-state_priv_cmds_from_auditctl_count:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_check="at least one" var_ref="oval:ssg-var_priv_cmds_from_auditctl_count:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_unprivileged_commands_bootc:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="not equal" var_check="all" var_ref="oval:ssg-var_audit_rules_privileged_commands_priv_cmds_bootc:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_priv_cmds_from_system_bootc:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match" var_check="at least one" var_ref="oval:ssg-var_audit_rules_privileged_commands_priv_cmds_bootc:var:1"/>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_priv_cmds_from_augenrules_count_bootc:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_check="at least one" var_ref="oval:ssg-var_priv_cmds_from_augenrules_count_bootc:var:1"/>
        </ind:variable_state>
        <ind:variable_state id="oval:ssg-state_priv_cmds_from_auditctl_count_bootc:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_check="at least one" var_ref="oval:ssg-var_priv_cmds_from_auditctl_count_bootc:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_audispd_configure_remote_server:ste:1" operator="AND" version="1">
          <ind:subexpression operation="equals" var_ref="oval:ssg-var_audispd_remote_server:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_audispd_disk_full_action:ste:1" operator="AND" version="1">
          <ind:subexpression operation="equals" var_ref="oval:ssg-var_audispd_disk_full_action:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_audispd_network_failure_action:ste:1" operator="AND" version="1">
          <ind:subexpression operation="equals" var_ref="oval:ssg-var_audispd_network_failure_action:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_disk_error_action:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match" var_ref="oval:ssg-var_auditd_disk_error_action_regex:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_disk_error_action_stig_syslog:ste:1" operator="AND" version="1">
          <ind:subexpression operation="case insensitive equals">SYSLOG</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_disk_error_action_stig_single:ste:1" operator="AND" version="1">
          <ind:subexpression operation="case insensitive equals">SINGLE</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_disk_error_action_stig_halt:ste:1" operator="AND" version="1">
          <ind:subexpression operation="case insensitive equals">HALT</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_disk_full_action:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match" var_ref="oval:ssg-var_auditd_disk_full_action_regex:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_disk_full_action_stig_syslog:ste:1" operator="AND" version="1">
          <ind:subexpression operation="case insensitive equals">SYSLOG</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_disk_full_action_stig_single:ste:1" operator="AND" version="1">
          <ind:subexpression operation="case insensitive equals">SINGLE</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_disk_full_action_stig_halt:ste:1" operator="AND" version="1">
          <ind:subexpression operation="case insensitive equals">HALT</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_retention_action_mail_acct:ste:1" operator="AND" version="1">
          <ind:subexpression operation="equals" var_ref="oval:ssg-var_auditd_action_mail_acct:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_retention_admin_space_left_action:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match" var_ref="oval:ssg-var_auditd_admin_space_left_action_regex:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_retention_admin_space_left_percentage:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_auditd_admin_space_left_percentage:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_retention_flush:ste:1" operator="AND" version="1">
          <ind:subexpression operation="case insensitive equals" var_ref="oval:ssg-var_auditd_flush:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_retention_max_log_file:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_auditd_max_log_file:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_retention_max_log_file_action:ste:1" operator="AND" version="1">
          <ind:subexpression operation="case insensitive equals" var_ref="oval:ssg-var_auditd_max_log_file_action:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_retention_max_log_file_action_stig_rotate:ste:1" operator="AND" version="1">
          <ind:subexpression operation="case insensitive equals">rotate</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_retention_max_log_file_action_stig_single:ste:1" operator="AND" version="1">
          <ind:subexpression operation="case insensitive equals">single</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_retention_num_logs:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_auditd_num_logs:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_retention_space_left:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_auditd_space_left:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_retention_space_left_action:ste:1" operator="AND" version="2">
          <ind:subexpression operation="pattern match" var_ref="oval:ssg-var_auditd_space_left_action_regex:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_retention_space_left_percentage:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_auditd_space_left_percentage:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_name_format:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match" var_ref="oval:ssg-var_auditd_name_format_regex:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_overflow_action:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?i)(syslog|single|halt)(?-i)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_doc_10-base-config:ste:1" operator="AND" version="1">
          <ind:text operation="equals" var_check="all" var_ref="oval:ssg-var_doc_10-base-config:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_doc_11-loginuid:ste:1" operator="AND" version="1">
          <ind:text operation="equals" var_check="all" var_ref="oval:ssg-var_doc_11-loginuid:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_doc_30-ospp-v42:ste:1" operator="AND" version="1">
          <ind:text operation="equals" var_check="all" var_ref="oval:ssg-var_doc_30-ospp-v42:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_doc_43-module-load:ste:1" operator="AND" version="1">
          <ind:text operation="equals" var_check="all" var_ref="oval:ssg-var_doc_43-module-load:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sysconfig_networking_bootproto_ifcfg:ste:1" operator="AND" version="2">
          <ind:subexpression operation="pattern match">^(static|none)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="permissive mode value is set to 0 (off) in fapolicyd settings file" id="oval:ssg-state_fapolicy_default_deny_permissive_mode_off:ste:1" operator="AND" version="2">
          <ind:subexpression datatype="int" operation="equals">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_dir_perms_etc_httpd_conf:ste:1" operator="AND" version="2">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_dir_perms_var_log_httpd:ste:1" operator="AND" version="2">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_wrong_file_permissions_httpd_server_conf_d_files:ste:1" operator="AND" version="2">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_wrong_file_permissions_httpd_server_conf_files:ste:1" operator="AND" version="2">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_wrong_file_permissions_httpd_server_modules_files:ste:1" operator="AND" version="2">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <linux:inetlisteningservers_state id="oval:ssg-ste_not_on_localhost:ste:1" operator="AND" version="1">
          <linux:local_address operation="equals">::1</linux:local_address>
        </linux:inetlisteningservers_state>
        <linux:inetlisteningservers_state id="oval:ssg-ste_not_port_25:ste:1" operator="AND" version="1">
          <linux:local_port datatype="int" operation="not equal">25</linux:local_port>
        </linux:inetlisteningservers_state>
        <ind:textfilecontent54_state comment="root email alias" id="oval:ssg-state_root_mail_alias:ste:1" operator="AND" version="1">
          <ind:subexpression operation="equals" var_check="all" var_ref="oval:ssg-var_postfix_root_mail_alias:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="postmaster email alias" id="oval:ssg-state_postmaster_mail_alias:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">(?i)root</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_postfix_network_listening_disabled:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_ref="oval:ssg-var_postfix_inet_interfaces:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_postfix_prevent_unrestricted_relay:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^permit_mynetworks[ \t]*[, \t][ \t]*reject$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_use_kerberos_security_all_exports:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^.*,sec=krb5\:krb5i\:krb5p.*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_chronyd_port_value_0:ste:1" operator="AND" version="1">
          <ind:subexpression>0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_chrony_wait_execstart_no_h_flag:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^/usr/bin/chronyc\s+waitsync\s+\d+\s+[\d.]+\s+[\d.]+\s+\d+\s*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_chronyd_cmdport_value_0:ste:1" operator="AND" version="1">
          <ind:subexpression>0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_time_service_set_maxpoll:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than or equal" var_ref="oval:ssg-var_time_service_set_maxpoll:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_server_has_maxpoll:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">maxpoll \d+</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_chronyd_run_as_chrony_user:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^["]?.*-u[\s]*chrony.*["]?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_file_groupowner_etc_chrony_keys_nsswitch_uses_altfiles:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">altfiles</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_chrony_keys_gid_chrony:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" var_ref="oval:ssg-var_dedicated_groupowner_etc_chrony_keys_uid_chrony:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_chrony_keys_uid_chrony:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_chrony_keys_gid_chrony_with_usrlib:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" var_ref="oval:ssg-var_dedicated_groupowner_etc_chrony_keys_uid_chrony_with_usrlib:var:1"/>
        </unix:file_state>
        <ind:textfilecontent54_state id="oval:ssg-state_tftp_service_dropin_exists:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">\s*ExecStart\s*=\s*\S+\s+-s\s+\S+.*</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_tftpd_uses_secure_mode:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_check="all" var_ref="oval:ssg-var_tftpd_secure_directory:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_20340112:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">2</ind:instance>
          <ind:subexpression operation="pattern match">sec=(krb5i|ntlmv2i)</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__sshd_private_key:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state comment="All keys in /etc/ssh groupowned by root have the right permissions" id="oval:ssg-filter_ssh_key_owner_root:ste:1" operator="AND" version="1">
          <unix:path>/etc/ssh</unix:path>
          <unix:filename operation="pattern match">.*_key$</unix:filename>
          <unix:group_id datatype="int">0</unix:group_id>
          <unix:user_id datatype="int">0</unix:user_id>
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state comment="All keys in /etc/ssh groupowned by ssh_keys have the right permissions" id="oval:ssg-filter_ssh_key_owner_ssh_keys:ste:1" operator="AND" version="1">
          <unix:path>/etc/ssh</unix:path>
          <unix:filename operation="pattern match">.*_key$</unix:filename>
          <unix:group_id datatype="int" var_ref="oval:ssg-group_gid:var:1"/>
          <unix:user_id datatype="int">0</unix:user_id>
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <ind:textfilecontent54_state id="oval:ssg-state_ssh_client_strong_rng_csh:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal">32</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_ssh_client_strong_rng_sh:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal">32</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_firewalld_sshd_port_enabled_custom_zone_files_count:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_check="at least one" var_ref="oval:ssg-var_firewalld_sshd_port_enabled_custom_zone_files_count:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state comment="expected SSH port as defined by external variable" id="oval:ssg-state_firewalld_sshd_port_enabled_ssh_service_file_etc:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sshd_listening_port:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_rekey_limit:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match" var_ref="oval:ssg-sshd_line_regex:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="upper bound of ClientAliveInterval in seconds" id="oval:ssg-state_timeout_value_upper_bound:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-sshd_idle_timeout_value:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="lower bound of ClientAliveInterval in seconds" id="oval:ssg-state_timeout_value_lower_bound:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="upper bound of LoginGraceTime in number of sessions" id="oval:ssg-state_logingracetime_value_upper_bound:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-var_sshd_set_login_grace_time:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="lower bound of LoginGraceTime in number of sessions" id="oval:ssg-state_logingracetime_value_lower_bound:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="upper bound of MaxAuthTries in number of sessions" id="oval:ssg-state_maxauthtries_value_upper_bound:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-sshd_max_auth_tries_value:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="lower bound of MaxAuthTries in number of sessions" id="oval:ssg-state_maxauthtries_value_lower_bound:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="upper bound of MaxSessions in number of sessions" id="oval:ssg-state_maxsessions_value_upper_bound:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-var_sshd_max_sessions:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="lower bound of MaxSessions in number of sessions" id="oval:ssg-state_maxsessions_value_lower_bound:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-ste_sshd_config_start_parameter_valid:ste:1" operator="AND" version="2">
          <ind:subexpression datatype="int" operation="less than or equal" var_ref="oval:ssg-var_sshd_set_maxstartups_first:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-ste_sshd_config_rate_parameter_valid:ste:1" operator="AND" version="2">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_sshd_set_maxstartups_second:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-ste_sshd_config_full_parameter_valid:ste:1" operator="AND" version="2">
          <ind:subexpression datatype="int" operation="less than or equal" var_ref="oval:ssg-var_sshd_set_maxstartups_third:var:1"/>
        </ind:textfilecontent54_state>
        <ind:variable_state comment="approved ciphers" id="oval:ssg-ste_sshd_use_approved_ciphers:ste:1" operator="AND" version="1">
          <ind:value datatype="string" operation="equals" var_check="at least one" var_ref="oval:ssg-var_sshd_approved_ciphers:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_use_approved_kex_ordered_stig:ste:1" operator="AND" version="1">
          <ind:text operation="pattern match">(?=[\w-])(\b)?[\s]*(?:#.*)?$</ind:text>
        </ind:textfilecontent54_state>
        <ind:variable_state comment="approved macs" id="oval:ssg-ste_sshd_use_approved_macs:ste:1" operator="AND" version="1">
          <ind:value datatype="string" operation="equals" var_check="at least one" var_ref="oval:ssg-var_sshd_approved_macs:var:1"/>
        </ind:variable_state>
        <ind:variable_state comment="approved strong kex" id="oval:ssg-ste_sshd_use_strong_kex:ste:1" operator="AND" version="1">
          <ind:value datatype="string" operation="equals" var_check="at least one" var_ref="oval:ssg-var_sshd_strong_kex:var:1"/>
        </ind:variable_state>
        <ind:variable_state comment="strong macs" id="oval:ssg-ste_sshd_use_strong_macs:ste:1" operator="AND" version="1">
          <ind:value datatype="string" operation="equals" var_check="at least one" var_ref="oval:ssg-var_sshd_strong_macs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state comment="value of certificate_verification" id="oval:ssg-state_sssd_certificate_verification:ste:1" operator="AND" version="1">
          <ind:subexpression operation="equals" var_check="all" var_ref="oval:ssg-var_sssd_certificate_verification_digest_function:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sssd_enable_pam_services:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^.*pam.*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sssd_enable_smartcards:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">(?i)true</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sssd_enable_smartcards_cert_auth:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^.*(try_cert_auth|require_cert_auth).*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="value of memcache_timeout setting" id="oval:ssg-state_sssd_memcache_timeout:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-var_sssd_memcache_timeout:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sssd_offline_cred_expiration:ste:1" operator="AND" version="1">
          <ind:subexpression>1</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="value of user setting" id="oval:ssg-state_sssd_user_value:ste:1" operator="AND" version="1">
          <ind:subexpression>sssd</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="value of ssh_known_hosts_timeout setting" id="oval:ssg-state_sssd_ssh_known_hosts_timeout:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-var_sssd_ssh_known_hosts_timeout:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sssd_ldap_tls_ca_dir:ste:1" operator="AND" version="1">
          <ind:subexpression operation="equals" var_check="all" var_ref="oval:ssg-var_sssd_ldap_tls_ca_dir:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sssd_ldap_tls_reqcert:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">(?i)demand</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_use_starttls_sssd_conf:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">(?i)true</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:symlink_state comment="default.target is linked to multi-user.target" id="oval:ssg-state_disable_xwindows_runlevel_target:ste:1" operator="AND" version="1">
          <unix:filepath>/etc/systemd/system/default.target</unix:filepath>
          <unix:canonical_path operation="pattern match">^(/usr)?/lib/systemd/system/multi-user.target$</unix:canonical_path>
        </unix:symlink_state>
        <unix:symlink_state comment="see the test comment" id="oval:ssg-state_pam_fingerprint_symlinked_to_authselect:ste:1" operator="AND" version="1">
          <unix:filepath>/etc/pam.d/fingerprint-auth</unix:filepath>
          <unix:canonical_path>/etc/authselect/fingerprint-auth</unix:canonical_path>
        </unix:symlink_state>
        <unix:symlink_state comment="see the test comment" id="oval:ssg-state_pam_password_symlinked_to_authselect:ste:1" operator="AND" version="1">
          <unix:filepath>/etc/pam.d/password-auth</unix:filepath>
          <unix:canonical_path>/etc/authselect/password-auth</unix:canonical_path>
        </unix:symlink_state>
        <unix:symlink_state comment="see the test comment" id="oval:ssg-state_pam_postlogin_symlinked_to_authselect:ste:1" operator="AND" version="1">
          <unix:filepath>/etc/pam.d/postlogin</unix:filepath>
          <unix:canonical_path>/etc/authselect/postlogin</unix:canonical_path>
        </unix:symlink_state>
        <unix:symlink_state comment="see the test comment" id="oval:ssg-state_pam_smartcard_symlinked_to_authselect:ste:1" operator="AND" version="1">
          <unix:filepath>/etc/pam.d/smartcard-auth</unix:filepath>
          <unix:canonical_path>/etc/authselect/smartcard-auth</unix:canonical_path>
        </unix:symlink_state>
        <unix:symlink_state comment="see the test comment" id="oval:ssg-state_pam_system_symlinked_to_authselect:ste:1" operator="AND" version="1">
          <unix:filepath>/etc/pam.d/system-auth</unix:filepath>
          <unix:canonical_path>/etc/authselect/system-auth</unix:canonical_path>
        </unix:symlink_state>
        <ind:textfilecontent54_state id="oval:ssg-state_banner_etc_issue:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match" var_ref="oval:ssg-login_banner_text:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_banner_etc_issue_net:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match" var_ref="oval:ssg-remote_login_banner_text:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_banner_etc_motd:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match" var_ref="oval:ssg-motd_banner_text:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_gdm_login_banner_text_setting:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match" var_ref="oval:ssg-dconf_login_banner_text:var:1"/>
        </ind:textfilecontent54_state>
        <linux:selinuxsecuritycontext_state comment="faillog_t context is set" id="oval:ssg-state_account_password_selinux_faillock_dir:ste:1" operator="AND" version="1">
          <linux:type datatype="string" operation="equals">faillog_t</linux:type>
        </linux:selinuxsecuritycontext_state>
        <ind:textfilecontent54_state id="oval:ssg-state_accounts_password_pam_pwhistory_remember_password_auth:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_password_pam_remember:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_accounts_password_pam_pwhistory_remember_system_auth:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_password_pam_remember:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-accounts_password_pam_pwhistory_use_authtok_ste_use_authtok:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^[^#\n\r]*pam_pwhistory\.so[ \t]+[^#\n\r]*use_authtok.*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-accounts_password_pam_pwhistory_use_authtok_ste_use_authtok_pam_pwhistory_lines:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^[^#\n\r]*pam_pwhistory\.so.*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-ste_accounts_password_pam_unix_authtok_prm_exists:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^[^#\n\r]+[ \t]+pam_unix\.so[ \t]+[^#\n\r]+use_authtok.*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-ste_accounts_password_pam_unix_authtok_pam_unix_lines:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^[^#\n\r]+[ \t]+pam_unix\.so.*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_accounts_password_pam_unix_remember:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_password_pam_unix_remember:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_pam_faillock_dir_parameter_not_default_value:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="not equal">/var/run/faillock</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_pam_faillock_dir_parameter_system_auth:ste:1" operator="AND" version="1">
          <ind:value>2</ind:value>
        </ind:variable_state>
        <ind:variable_state id="oval:ssg-state_pam_faillock_dir_parameter_password_auth:ste:1" operator="AND" version="1">
          <ind:value>2</ind:value>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_lower_bound:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_root_unlock_time:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_lower_bound:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_accounts_passwords_pam_faillock_unlock_time_with_zero_parameter_special_allowed_value:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="upper bound of password_pam_retry" id="oval:ssg-state_password_pam_retry_upper_bound:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than or equal" var_ref="oval:ssg-var_password_pam_retry:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="lower bound of password_pam_retry" id="oval:ssg-state_password_pam_retry_lower_bound:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_set_password_hashing_algorithm_libuserconf:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_ref="oval:ssg-var_password_hashing_algorithm_pam:var:1"/>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_test_password_hashing_algorithm_logindefs:ste:1" operator="AND" version="1">
          <ind:value datatype="string" operation="pattern match" var_check="at least one" var_ref="oval:ssg-var_password_hashing_algorithm:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_set_password_hashing_algorithm_passwordauth:ste:1" operator="AND" version="2">
          <ind:subexpression datatype="string" operation="pattern match" var_ref="oval:ssg-var_password_hashing_algorithm_pam_regex:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_pam_unix_hashing_algorithm_systemauth:ste:1" operator="AND" version="2">
          <ind:subexpression datatype="string" operation="pattern match" var_ref="oval:ssg-var_password_hashing_algorithm_pam_regex:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="Rounds should be set to more than 5000" id="oval:ssg-state_etc_login_defs_sha_crypt_rounds:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-local_var_password_hashing_min_rounds_login_defs:var:1"/>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_password_hashing_min_rounds_login_defs_le_5000:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="less than or equal">5000</ind:value>
        </ind:variable_state>
        <unix:symlink_state comment="Disable Ctrl-Alt-Del key sequence override exists" id="oval:ssg-state_disable_ctrlaltdel_exists:ste:1" operator="AND" version="1">
          <unix:filepath>/etc/systemd/system/ctrl-alt-del.target</unix:filepath>
          <unix:canonical_path>/dev/null</unix:canonical_path>
        </unix:symlink_state>
        <ind:textfilecontent54_state id="oval:ssg-state_logind_session_timeout:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-var_logind_session_timeout:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_require_rescue_service:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">/bin/sh[\s]+-c[\s]+\"(/usr)?/sbin/sulogin;[\s]+/usr/bin/systemctl[\s]+--fail[\s]+--no-block[\s]+default\"</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="the value is greater than zero" id="oval:ssg-state_configure_tmux_lock_after_time_lower_boundary:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="the value is less than or equal to 900" id="oval:ssg-state_configure_tmux_lock_after_time_upper_boundary:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than or equal">900</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_configure_opensc_card_drivers:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_check="all" var_ref="oval:ssg-var_smartcard_drivers:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_force_opensc_card_drivers:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_check="all" var_ref="oval:ssg-var_smartcard_drivers:var:1"/>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_no_duplicate_uids:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_check="at least one" var_ref="oval:ssg-variable_count_of_unique_uids:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state comment="The user root is always allowed as default opering system user" id="oval:ssg-state_default_os_user:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^root$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="authorized usernames required by the installed software groups and applications" id="oval:ssg-state_accounts_authorized_local_users:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match" var_ref="oval:ssg-var_accounts_authorized_local_users_regex:var:1"/>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_no_duplicate_group_ids:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_check="at least one" var_ref="oval:ssg-variable_count_of_unique_group_ids:var:1"/>
        </ind:variable_state>
        <ind:variable_state id="oval:ssg-state_no_duplicate_group_names:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_check="at least one" var_ref="oval:ssg-variable_count_of_unique_group_names:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_etc_default_useradd_inactive:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than or equal" var_ref="oval:ssg-var_account_disable_post_pw_expiration:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_etc_default_useradd_inactive_nonnegative:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than">-1</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_etc_passwd_no_duplicate_user_names:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_check="at least one" var_ref="oval:ssg-variable_count_of_unique_usernames_from_etc_passwd:var:1"/>
        </ind:variable_state>
        <ind:variable_state id="oval:ssg-state_last_pass_max_days_instance_value:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="less than or equal" var_check="at least one" var_ref="oval:ssg-var_accounts_maximum_age_login_defs:var:1"/>
        </ind:variable_state>
        <ind:variable_state id="oval:ssg-state_last_pass_min_days_instance_value:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="greater than or equal" var_check="at least one" var_ref="oval:ssg-var_accounts_minimum_age_login_defs:var:1"/>
        </ind:variable_state>
        <ind:variable_state id="oval:ssg-state_last_pass_min_len_instance_value:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="greater than or equal" var_check="at least one" var_ref="oval:ssg-var_accounts_password_minlen_login_defs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_test_accounts_password_set_max_life_existing_password_max_life_existing:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-var_accounts_maximum_age_login_defs:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_test_accounts_password_set_max_life_existing_password_max_life_existing_minimum:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_check="all" var_ref="oval:ssg-var_accounts_minimum_age_login_defs:var:1"/>
        </ind:textfilecontent54_state>
        <unix:shadow_state id="oval:ssg-state_accounts_password_set_max_life_root:ste:1" operator="AND" version="1">
          <unix:chg_req datatype="int" operation="equals" var_ref="oval:ssg-var_accounts_maximum_age_root:var:1"/>
        </unix:shadow_state>
        <ind:textfilecontent54_state id="oval:ssg-state_test_accounts_password_set_min_life_existing_password_max_life_existing:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-var_accounts_maximum_age_login_defs:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_test_accounts_password_set_min_life_existing_password_max_life_existing_minimum:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_check="all" var_ref="oval:ssg-var_accounts_minimum_age_login_defs:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_test_accounts_password_set_warn_age_existing:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_check="all" var_ref="oval:ssg-var_accounts_password_warn_age_login_defs:var:1"/>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_test_pass_warn_age:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="greater than or equal" var_check="at least one" var_ref="oval:ssg-var_accounts_password_warn_age_login_defs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_test_accounts_set_post_pw_existing:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-var_account_disable_post_pw_expiration:var:1"/>
        </ind:textfilecontent54_state>
        <unix:password_state id="oval:ssg-state_accounts_password_all_shadowed:ste:1" operator="AND" version="1">
          <unix:password mask="true" operation="pattern match">^[x*]$</unix:password>
        </unix:password_state>
        <unix:shadow_state id="oval:ssg-state_accounts_password_all_shadowed_has_no_password:ste:1" operator="AND" version="1">
          <unix:password operation="pattern match">^(!|!!|!\*|\*|!locked)$</unix:password>
        </unix:shadow_state>
        <unix:shadow_state id="oval:ssg-state_accounts_password_all_shadowed_has_locked_password:ste:1" operator="AND" version="1">
          <unix:password operation="pattern match">^(!\$6\$|!!\$6\$).*$</unix:password>
        </unix:shadow_state>
        <unix:shadow_state id="oval:ssg-state_accounts_password_all_shadowed_sha512:ste:1" operator="AND" version="1">
          <unix:encrypt_method operation="equals">SHA-512</unix:encrypt_method>
        </unix:shadow_state>
        <unix:shadow_state id="oval:ssg-state_accounts_password_all_shadowed_sha512_hidepass:ste:1" operator="AND" version="1">
          <unix:password mask="true" operation="pattern match">.*</unix:password>
        </unix:shadow_state>
        <unix:shadow_state id="oval:ssg-state_accounts_password_all_chage_past_has_no_password:ste:1" operator="AND" version="1">
          <unix:password operation="pattern match">^(!|!!|!\*|\*|!locked)$</unix:password>
        </unix:shadow_state>
        <ind:variable_state id="oval:ssg-state_accounts_password_last_change_is_in_past_time_diff:ste:1" operator="AND" version="2">
          <ind:value datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-var_accounts_password_last_change_is_in_past_current_epoch:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_password_auth_pam_unix_rounds:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_password_pam_unix_rounds:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_system_auth_pam_unix_rounds:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_password_pam_unix_rounds:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_gid_passwd_group_same:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_check="at least one" var_ref="oval:ssg-var_gid_passwd_group_same:var:1"/>
        </ind:textfilecontent54_state>
        <unix:password_state id="oval:ssg-state_no_forward_files_users_uids:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="greater than or equal">1000</unix:user_id>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_no_forward_files_users_ignored:ste:1" operator="AND" version="1">
          <unix:username datatype="string" operation="pattern match">^(nobody|nfsnobody)$</unix:username>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_no_forward_files_users_nologin_shell:ste:1" operator="AND" version="1">
          <unix:login_shell datatype="string" operation="pattern match">^(?:/usr)?/sbin/nologin$</unix:login_shell>
        </unix:password_state>
        <ind:textfilecontent54_state id="oval:ssg-state_is_locked_in_shadow:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_check="at least one" var_ref="oval:ssg-var_locked_users:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="root account's gid is equal to 0" id="oval:ssg-state_accounts_root_gid_zero:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="check if the group line does not contain members" id="oval:ssg-state_ensure_pam_wheel_group_has_no_members:ste:1" operator="AND" version="1">
          <ind:text operation="pattern match">^[^:]+:[^:]+:[0-9]+:\s*$</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_no_invalid_shell_accounts_unlocked_valid_shells:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="not equal" var_check="all" var_ref="oval:ssg-var_no_invalid_shell_accounts_unlocked_valid_shells:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state comment="The nologin shell can be safely ignored" id="oval:ssg-filter_no_invalid_shell_accounts_unlocked_not_valid_shell:ste:1" operator="AND" version="1">
          <ind:pattern operation="pattern match">^.*\bnologin\b.*$</ind:pattern>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_no_invalid_shell_accounts_unlocked_users_ignored:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^(nobody|nfsnobody|root)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_no_invalid_shell_accounts_unlocked_locked_accounts:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_check="at least one" var_ref="oval:ssg-var_no_invalid_shell_accounts_unlocked_locked_accounts:var:1"/>
        </ind:textfilecontent54_state>
        <unix:password_state id="oval:ssg-state_no_password_auth_for_systemaccounts_users_uids:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="less than">1000</unix:user_id>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_no_password_auth_for_systemaccounts_users_ignored:ste:1" operator="AND" version="1">
          <unix:username datatype="string" operation="pattern match">^(root|halt|sync|shutdown|nfsnobody)$</unix:username>
        </unix:password_state>
        <unix:shadow_state id="oval:ssg-filter_no_password_auth_for_systemaccounts_no_passwords_or_locked_accounts:ste:1" operator="AND" version="1">
          <unix:password operation="pattern match">^(!|!!|!\*|\*|!locked).*$</unix:password>
        </unix:shadow_state>
        <ind:textfilecontent54_state id="oval:ssg-state_uid_less_than_zero:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_uid_greater_than_or_equal_uid_min:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-variable_uid_min_value:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_uid_greater_than_or_equal_sys_uid_min:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-variable_sys_uid_min_value:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_uid_less_than_sys_uid_min:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than" var_ref="oval:ssg-variable_sys_uid_min_value:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_uid_greater_than_or_equal_sys_uid_max:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-variable_sys_uid_max_value:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_accounts_logon_fail_delay:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_accounts_fail_delay:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_maxlogins:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than or equal" var_ref="oval:ssg-var_accounts_max_concurrent_login_sessions:var:1"/>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_tmp_inst:ste:1" operator="AND" version="1">
          <unix:type>directory</unix:type>
          <unix:uread datatype="boolean">false</unix:uread>
          <unix:uwrite datatype="boolean">false</unix:uwrite>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_var_tmp_tmp_inst:ste:1" operator="AND" version="1">
          <unix:type>directory</unix:type>
          <unix:uread datatype="boolean">false</unix:uread>
          <unix:uwrite datatype="boolean">false</unix:uwrite>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <ind:variable_state id="oval:ssg-state_accounts_tmout_defined:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="greater than or equal">1</ind:value>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_etc_profile_tmout:ste:1" operator="AND" version="2">
          <ind:subexpression datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-var_accounts_tmout:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_etc_profile_tmout_lower_bound:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal">1</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_object_accounts_user_dot_group_ownership_home_dirs_users_ignored:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^(nobody|nfsnobody)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_object_accounts_user_dot_group_ownership_gids_users_ignored:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^(nobody|nfsnobody)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_accounts_user_dot_group_ownership_gids:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" var_check="only one" var_ref="oval:ssg-var_accounts_user_dot_group_ownership_gids:var:1"/>
        </unix:file_state>
        <unix:password_state id="oval:ssg-state_accounts_user_dot_no_world_writable_programs_users_uids:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="greater than or equal">1000</unix:user_id>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_accounts_user_dot_no_world_writable_programs_users_ignored:ste:1" operator="AND" version="1">
          <unix:username datatype="string" operation="pattern match">^(nobody|nfsnobody)$</unix:username>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_accounts_user_dot_no_world_writable_programs_users_nologin_shell:ste:1" operator="AND" version="1">
          <unix:login_shell datatype="string" operation="pattern match">^(?:/usr)?/sbin/nologin$</unix:login_shell>
        </unix:password_state>
        <unix:file_state id="oval:ssg-state_world_writable_programs:ste:1" operator="AND" version="1">
          <unix:type>regular</unix:type>
          <unix:owrite datatype="boolean">true</unix:owrite>
        </unix:file_state>
        <ind:textfilecontent54_state id="oval:ssg-state_object_accounts_user_dot_user_ownership_home_dirs_users_ignored:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^(nobody|nfsnobody)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_object_accounts_user_dot_user_ownership_uids_users_ignored:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^(nobody|nfsnobody)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_accounts_user_dot_user_ownership_uids:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" var_check="only one" var_ref="oval:ssg-var_accounts_user_dot_user_ownership_uids:var:1"/>
        </unix:file_state>
        <unix:password_state id="oval:ssg-state_accounts_user_interactive_home_directory_defined_users_uids:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="greater than or equal">1000</unix:user_id>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_accounts_user_interactive_home_directory_defined_users_ignored:ste:1" operator="AND" version="1">
          <unix:username datatype="string" operation="pattern match">^(nobody|nfsnobody)$</unix:username>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_accounts_user_interactive_home_directory_defined_users_nologin_shell:ste:1" operator="AND" version="1">
          <unix:login_shell datatype="string" operation="pattern match">^(?:/usr)?/sbin/nologin$</unix:login_shell>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_accounts_user_interactive_home_directory_defined:ste:1" operator="AND" version="1">
          <unix:home_dir operation="pattern match">^\/[^\/\n]*\/[^\/\n]{1,}.*$</unix:home_dir>
        </unix:password_state>
        <ind:textfilecontent54_state id="oval:ssg-state_object_accounts_user_interactive_home_directory_exists_objects_users_ignored:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^(nobody|nfsnobody)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_accounts_user_interactive_home_directory_exists_dirs_count_pw:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_check="at least one" var_ref="oval:ssg-var_accounts_user_interactive_home_directory_exists_dirs_count:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_accounts_user_interactive_home_directory_on_separate_partition_on_separate_partition:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match" var_check="at least one" var_ref="oval:ssg-var_accounts_user_interactive_home_directory_on_separate_partition_mount_regex:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_object_accounts_users_home_files_groupownership_home_dirs_users_ignored:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^(nobody|nfsnobody)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_object_accounts_users_home_files_groupownership_gids_users_ignored:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^(nobody|nfsnobody)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_accounts_users_home_files_groupownership_gids:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" var_check="only one" var_ref="oval:ssg-var_accounts_users_home_files_groupownership_gids:var:1"/>
        </unix:file_state>
        <ind:textfilecontent54_state id="oval:ssg-state_object_accounts_users_home_files_ownership_home_dirs_users_ignored:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^(nobody|nfsnobody)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_object_accounts_users_home_files_ownership_uids_users_ignored:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^(nobody|nfsnobody)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_accounts_users_home_files_ownership_uids:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" var_check="only one" var_ref="oval:ssg-var_accounts_users_home_files_ownership_uids:var:1"/>
        </unix:file_state>
        <ind:textfilecontent54_state id="oval:ssg-state_object_accounts_users_home_files_permissions_home_dirs_users_ignored:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^(nobody|nfsnobody)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_accounts_users_home_files_permissions_is_symlink:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_accounts_users_home_files_permissions_dirs:ste:1" operator="AND" version="1">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:password_state id="oval:ssg-state_accounts_users_netrc_file_permissions_users_uids:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="greater than or equal">1000</unix:user_id>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_accounts_users_netrc_file_permissions_users_ignored:ste:1" operator="AND" version="1">
          <unix:username datatype="string" operation="pattern match">^(nobody|nfsnobody)$</unix:username>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_accounts_users_netrc_file_permissions_users_nologin_shell:ste:1" operator="AND" version="1">
          <unix:login_shell datatype="string" operation="pattern match">^(?:/usr)?/sbin/nologin$</unix:login_shell>
        </unix:password_state>
        <unix:file_state id="oval:ssg-state_accounts_users_home_netrc_file_permissions_gread:ste:1" operator="AND" version="1">
          <unix:gread datatype="boolean">false</unix:gread>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_accounts_users_home_netrc_file_permissions_gwrite:ste:1" operator="AND" version="1">
          <unix:gwrite datatype="boolean">false</unix:gwrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_accounts_users_home_netrc_file_permissions_gexec:ste:1" operator="AND" version="1">
          <unix:gexec datatype="boolean">false</unix:gexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_accounts_users_home_netrc_file_permissions_oread:ste:1" operator="AND" version="1">
          <unix:oread datatype="boolean">false</unix:oread>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_accounts_users_home_netrc_file_permissions_owrite:ste:1" operator="AND" version="1">
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_accounts_users_home_netrc_file_permissions_oexec:ste:1" operator="AND" version="1">
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <ind:textfilecontent54_state id="oval:ssg-state_object_file_groupownership_home_directories_home_dirs_users_ignored:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^(nobody|nfsnobody)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_object_file_groupownership_home_directories_gids_users_ignored:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^(nobody|nfsnobody)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_file_groupownership_home_directories_gids:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" var_check="only one" var_ref="oval:ssg-var_file_groupownership_home_directories_gids:var:1"/>
        </unix:file_state>
        <ind:textfilecontent54_state id="oval:ssg-state_object_file_ownership_home_directories_home_dirs_users_ignored:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^(nobody|nfsnobody)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_object_file_ownership_home_directories_uids_users_ignored:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^(nobody|nfsnobody)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_file_ownership_home_directories_uids:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" var_check="only one" var_ref="oval:ssg-var_file_ownership_home_directories_uids:var:1"/>
        </unix:file_state>
        <ind:variable_state id="oval:ssg-state_file_ownership_home_directories_uids_count_uniq:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_check="at least one" var_ref="oval:ssg-var_file_ownership_home_directories_uids_count_uniq:var:1"/>
        </ind:variable_state>
        <unix:file_state id="oval:ssg-state_file_permission_user_bash_history:ste:1" operator="AND" version="1">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:password_state id="oval:ssg-state_file_permission_user_bash_history_users_uids:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="greater than or equal">1000</unix:user_id>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_file_permission_user_bash_history_users_ignored:ste:1" operator="AND" version="1">
          <unix:username datatype="string" operation="pattern match">^(nobody|nfsnobody)$</unix:username>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_file_permission_user_bash_history_users_nologin_shell:ste:1" operator="AND" version="1">
          <unix:login_shell datatype="string" operation="pattern match">^(?:/usr)?/sbin/nologin$</unix:login_shell>
        </unix:password_state>
        <unix:file_state id="oval:ssg-state_file_permission_user_init_files:ste:1" operator="AND" version="1">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:password_state id="oval:ssg-state_file_permission_user_init_files_users_uids:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="greater than or equal">1000</unix:user_id>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_file_permission_user_init_files_users_ignored:ste:1" operator="AND" version="1">
          <unix:username datatype="string" operation="pattern match">^(nobody|nfsnobody)$</unix:username>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_file_permission_user_init_files_users_nologin_shell:ste:1" operator="AND" version="1">
          <unix:login_shell datatype="string" operation="pattern match">^(?:/usr)?/sbin/nologin$</unix:login_shell>
        </unix:password_state>
        <unix:file_state id="oval:ssg-state_file_permission_user_init_files_root:ste:1" operator="AND" version="1">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:password_state id="oval:ssg-state_file_permission_user_init_files_root_users_uids:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="greater than or equal">1000</unix:user_id>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_file_permission_user_init_files_root_users_ignored:ste:1" operator="AND" version="1">
          <unix:username datatype="string" operation="pattern match">^(nobody|nfsnobody)$</unix:username>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_file_permission_user_init_files_root_users_nologin_shell:ste:1" operator="AND" version="1">
          <unix:login_shell datatype="string" operation="pattern match">^(?:/usr)?/sbin/nologin$</unix:login_shell>
        </unix:password_state>
        <ind:textfilecontent54_state id="oval:ssg-state_object_file_permissions_home_directories_objects_users_ignored:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^(nobody|nfsnobody)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_file_permissions_home_directories_dirs:ste:1" operator="AND" version="1">
          <unix:type operation="equals">directory</unix:type>
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:password_state id="oval:ssg-state_file_permissions_home_dirs_users_uids:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="greater than or equal">1000</unix:user_id>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_file_permissions_home_dirs_users_ignored:ste:1" operator="AND" version="1">
          <unix:username datatype="string" operation="pattern match">^(nobody|nfsnobody)$</unix:username>
        </unix:password_state>
        <unix:password_state id="oval:ssg-state_file_permissions_home_dirs_users_nologin_shell:ste:1" operator="AND" version="1">
          <unix:login_shell datatype="string" operation="pattern match">^(?:/usr)?/sbin/nologin$</unix:login_shell>
        </unix:password_state>
        <unix:file_state id="oval:ssg-state_file_permissions_home_dirs_dirs:ste:1" operator="AND" version="1">
          <unix:type operation="equals">directory</unix:type>
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state comment="group or other has write privilege" id="oval:ssg-state_accounts_root_path_dirs_wrong_perms:ste:1" operator="OR" version="1">
          <unix:gwrite datatype="boolean">true</unix:gwrite>
          <unix:owrite datatype="boolean">true</unix:owrite>
        </unix:file_state>
        <unix:file_state comment="symbolic link" id="oval:ssg-state_accounts_root_path_dirs_symlink:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <ind:environmentvariable58_state comment="starts with colon or period" id="oval:ssg-state_begins_colon_period:ste:1" operator="AND" version="1">
          <ind:value operation="pattern match">^[:\.]</ind:value>
        </ind:environmentvariable58_state>
        <ind:environmentvariable58_state comment="colon twice in a row" id="oval:ssg-state_contains_double_colon:ste:1" operator="AND" version="1">
          <ind:value operation="pattern match">::</ind:value>
        </ind:environmentvariable58_state>
        <ind:environmentvariable58_state comment="period twice in a row" id="oval:ssg-state_contains_double_period:ste:1" operator="AND" version="1">
          <ind:value operation="pattern match">\.\.</ind:value>
        </ind:environmentvariable58_state>
        <ind:environmentvariable58_state comment="ends with colon or period" id="oval:ssg-state_ends_colon_period:ste:1" operator="AND" version="1">
          <ind:value operation="pattern match">[:\.]$</ind:value>
        </ind:environmentvariable58_state>
        <ind:environmentvariable58_state comment="begins with a slash" id="oval:ssg-state_begins_slash:ste:1" operator="AND" version="1">
          <ind:value operation="pattern match">^[^/]</ind:value>
        </ind:environmentvariable58_state>
        <ind:environmentvariable58_state comment="elements begin with a slash" id="oval:ssg-state_contains_relative_path:ste:1" operator="AND" version="1">
          <ind:value operation="pattern match">[^\\]:[^/]</ind:value>
        </ind:environmentvariable58_state>
        <ind:variable_state id="oval:ssg-ste_accounts_umask_etc_bashrc:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="bitwise and" var_ref="oval:ssg-var_accounts_user_umask_umask_as_number:var:1"/>
        </ind:variable_state>
        <ind:variable_state id="oval:ssg-ste_accounts_umask_etc_csh_cshrc:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="bitwise and" var_ref="oval:ssg-var_accounts_user_umask_umask_as_number:var:1"/>
        </ind:variable_state>
        <ind:variable_state id="oval:ssg-ste_accounts_umask_etc_login_defs:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="bitwise and" var_ref="oval:ssg-var_accounts_user_umask_umask_as_number:var:1"/>
        </ind:variable_state>
        <ind:variable_state id="oval:ssg-ste_accounts_umask_etc_profile:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="bitwise and" var_ref="oval:ssg-var_accounts_user_umask_umask_as_number:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_object_accounts_umask_interactive_users_objects_users_ignored:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^(nobody|nfsnobody)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_accounts_umask_interactive_users_bash_history:ste:1" operator="AND" version="1">
          <ind:filename operation="pattern match">^\.bash_history</ind:filename>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_trust_cpu_rng_boot_param_on:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?random\.trust_cpu=on(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_trust_cpu_rng_boot_param_off:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?random\.trust_cpu=off(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_bootloader_superuser_differ_from_other_users:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="not equal" var_check="all" var_ref="oval:ssg-var_user_accounts:var:1"/>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_grub2_set_root_count:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_check="all" var_ref="oval:ssg-var_grub2_set_root_count:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_no_removeable_media:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^['|\(](?!fd)(?!cd)(?!usb).*['|\)]$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_bootloader_uefi_superuser_differ_from_other_users:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="not equal" var_check="all" var_ref="oval:ssg-var_uefi_user_accounts:var:1"/>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_uefi_set_root_count:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_check="all" var_ref="oval:ssg-var_uefi_set_root_count:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_uefi_no_removeable_media:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^['|\(](?!fd)(?!cd)(?!usb).*['|\)]$</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_zipl_bootmap_is_newer_than_zipl_conf:ste:1" operator="AND" version="1">
          <unix:m_time datatype="int" operation="greater than or equal" var_check="all" var_ref="oval:ssg-variable_zipl_conf_file_age:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_zipl_bootmap_is_newer_than_boot_entries:ste:1" operator="AND" version="1">
          <unix:m_time datatype="int" operation="greater than or equal" var_check="all" var_ref="oval:ssg-variable_boot_entry_files_age:var:1"/>
        </unix:file_state>
        <ind:textfilecontent54_state id="oval:ssg-state_zipl_systemd_debug-shell_argument_in_boot_loader_entries_conf:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">\bsystemd.debug-shell\b</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_zipl_systemd_debug-shell_argument_in_etc_kernel_cmdline:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">\bsystemd.debug-shell\b</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_default_mmap_min_addr_x86_64:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">65536</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_default_mmap_min_addr_aarch64:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">32768</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_default_mmap_min_addr:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_kernel_config_default_mmap_min_addr_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_proc_sys_kernel_osrelease_arch_aarch64:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^aarch64$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_proc_sys_kernel_osrelease_arch_x86_64:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^x86_64$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-ste_filecreatemode_is_0640_or_stricter:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="bitwise or">416</ind:value>
        </ind:variable_state>
        <ind:textfilecontent54_state comment="value of omfwd action" id="oval:ssg-state_rsyslog_remote_tls:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">(?=[\S\s]*\s(?i)protocol(?-i)="tcp")(?=[\S\s]*\s(?i)Target(?-i)="[^"]+?")(?=[\S\s]*\s(?i)port(?-i)="6514")(?=[\S\s]*\s(?i)StreamDriver(?-i)="gtls")(?=[\S\s]*\s(?i)StreamDriverMode(?-i)="1")(?=[\S\s]*\s(?i)StreamDriverAuthMode(?-i)="x509/name")(?=[\S\s]*\s(?i)StreamDriver\.CheckExtendedKeyPurpose(?-i)="on")</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_network_nmcli_permissions:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string">ResultActive=auth_admin</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:interface_state id="oval:ssg-state_promisc:ste:1" operator="AND" version="1">
          <unix:flag datatype="string" entity_check="at least one" operation="equals">PROMISC</unix:flag>
        </unix:interface_state>
        <unix:interface_state id="oval:ssg-state_wifi_up:ste:1" operator="AND" version="1">
          <unix:flag datatype="string" entity_check="at least one" operation="equals">UP</unix:flag>
        </unix:interface_state>
        <unix:file_state comment="uid greater than 0 and world writable" id="oval:ssg-state_uid_is_not_root_and_world_writable:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="greater than">0</unix:user_id>
          <unix:owrite datatype="boolean">true</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_dir_perms_world_writable_sticky_bits:ste:1" operator="AND" version="1">
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:owrite datatype="boolean">true</unix:owrite>
        </unix:file_state>
        <linux:partition_state id="oval:ssg-state_dir_perms_world_writable_sticky_bits_dev_partitons:ste:1" operator="AND" version="1">
          <linux:device operation="pattern match">^/dev/.*$</linux:device>
        </linux:partition_state>
        <unix:file_state comment="uid greater than or equal to 1000 and world writable" id="oval:ssg-state_dir_perms_world_writable_system_owned:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="greater than or equal">1000</unix:user_id>
          <unix:owrite datatype="boolean">true</unix:owrite>
        </unix:file_state>
        <linux:partition_state id="oval:ssg-state_dir_perms_world_writable_system_owned_dev_partitons:ste:1" operator="AND" version="1">
          <linux:device operation="pattern match">^/dev/.*$</linux:device>
        </linux:partition_state>
        <unix:file_state comment="gid greater than or equal to 1000 and world writable" id="oval:ssg-state_gid_is_user_and_world_writable:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="greater than or equal">1000</unix:group_id>
          <unix:owrite datatype="boolean">true</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_system_commands_dirs_group_owner_not_root:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="not equal">0</unix:group_id>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_system_commands_directory_bin_owner_not_root:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="not equal">0</unix:user_id>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_system_commands_directory_sbin_owner_not_root:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="not equal">0</unix:user_id>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_system_commands_directory_usr_bin_owner_not_root:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="not equal">0</unix:user_id>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_system_commands_directory_usr_sbin_owner_not_root:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="not equal">0</unix:user_id>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_system_commands_directory_usr_local_bin_owner_not_root:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="not equal">0</unix:user_id>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_system_commands_directory_usr_local_sbin_owner_not_root:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="not equal">0</unix:user_id>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_unauthorized_sgid_set:ste:1" operator="AND" version="1">
          <unix:sgid datatype="boolean">true</unix:sgid>
        </unix:file_state>
        <unix:file_state comment="Used to filter out all files in the /sysroot directory" id="oval:ssg-state_file_permissions_unauthorized_sgid_sysroot:ste:1" operator="AND" version="1">
          <unix:filepath operation="pattern match">^/sysroot/.*$</unix:filepath>
        </unix:file_state>
        <linux:partition_state id="oval:ssg-state_file_permissions_unauthorized_sgid_dev_partitons:ste:1" operator="AND" version="1">
          <linux:device operation="pattern match">^/dev/.*$</linux:device>
        </linux:partition_state>
        <ind:variable_state id="oval:ssg-state_file_permissions_unauthorized_sgid_rpm_filepaths:ste:1" operator="AND" version="1">
          <ind:value datatype="string" operation="equals" var_check="at least one" var_ref="oval:ssg-var_file_permissions_unauthorized_sgid_rpms:var:1"/>
        </ind:variable_state>
        <unix:file_state id="oval:ssg-state_file_permissions_unauthorized_suid_set:ste:1" operator="AND" version="1">
          <unix:suid datatype="boolean">true</unix:suid>
        </unix:file_state>
        <unix:file_state comment="Used to filter out all files in the /sysroot directory" id="oval:ssg-state_file_permissions_unauthorized_suid_sysroot:ste:1" operator="AND" version="1">
          <unix:filepath operation="pattern match">^/sysroot/.*$</unix:filepath>
        </unix:file_state>
        <linux:partition_state id="oval:ssg-state_file_permissions_unauthorized_suid_dev_partitons:ste:1" operator="AND" version="1">
          <linux:device operation="pattern match">^/dev/.*$</linux:device>
        </linux:partition_state>
        <ind:variable_state id="oval:ssg-state_file_permissions_unauthorized_suid_rpm_filepaths:ste:1" operator="AND" version="1">
          <ind:value datatype="string" operation="equals" var_check="at least one" var_ref="oval:ssg-var_file_permissions_unauthorized_suid_rpms:var:1"/>
        </ind:variable_state>
        <unix:file_state id="oval:ssg-state_file_permissions_unauthorized_world_write:ste:1" operator="AND" version="1">
          <unix:type operation="equals">regular</unix:type>
          <unix:owrite datatype="boolean">true</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_unauthorized_world_write_special_selinux_files:ste:1" operator="AND" version="1">
          <unix:filepath operation="pattern match">^/selinux/(?:(?:member)|(?:user)|(?:relabel)|(?:create)|(?:access)|(?:context))$</unix:filepath>
        </unix:file_state>
        <unix:file_state comment="Used to filter out all files in the /sysroot directory" id="oval:ssg-state_file_permissions_unauthorized_world_write_sysroot:ste:1" operator="AND" version="1">
          <unix:filepath operation="pattern match">^/sysroot/.*$</unix:filepath>
        </unix:file_state>
        <linux:partition_state id="oval:ssg-state_file_permissions_unauthorized_world_writable_dev_partitons:ste:1" operator="AND" version="1">
          <linux:device operation="pattern match">^/dev/.*$</linux:device>
        </linux:partition_state>
        <unix:file_state comment="Used to filter out all files group-owned by a group defined in /etc/group" id="oval:ssg-state_file_permissions_ungroupowned_local_group_owner:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" var_check="at least one" var_ref="oval:ssg-var_all_local_gids:var:1"/>
        </unix:file_state>
        <unix:file_state comment="Used to filter out all files group-owned by a group defined in /etc/group" id="oval:ssg-state_file_permissions_ungroupowned_local_group_owner_with_usrlib:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" var_check="at least one" var_ref="oval:ssg-var_all_local_gids_with_usrlib:var:1"/>
        </unix:file_state>
        <unix:file_state comment="Used to filter out all files in the /sysroot directory" id="oval:ssg-state_file_permissions_ungroupowned_sysroot:ste:1" operator="AND" version="1">
          <unix:filepath operation="pattern match">^/sysroot/.*$</unix:filepath>
        </unix:file_state>
        <linux:partition_state id="oval:ssg-state_file_permissions_ungroupowned_dev_partitons:ste:1" operator="AND" version="1">
          <linux:device operation="pattern match">^/dev/.*$</linux:device>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_file_permissions_ungroupowned_nsswitch_uses_altfiles:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">altfiles</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state comment="Used to filter out all files group-owned by a group defined in /etc/group" id="oval:ssg-state_no_files_or_dirs_ungroupowned_local_group_owner:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" var_check="at least one" var_ref="oval:ssg-var_all_local_gids:var:1"/>
        </unix:file_state>
        <unix:file_state comment="Used to filter out all files group-owned by a group defined in /etc/group" id="oval:ssg-state_no_files_or_dirs_ungroupowned_local_group_owner_with_usrlib:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" var_check="at least one" var_ref="oval:ssg-var_all_local_gids_with_usrlib:var:1"/>
        </unix:file_state>
        <unix:file_state comment="Used to filter out all files in the /sysroot directory" id="oval:ssg-state_no_files_or_dirs_ungroupowned_sysroot:ste:1" operator="AND" version="1">
          <unix:filepath operation="pattern match">^/sysroot/.*$</unix:filepath>
        </unix:file_state>
        <linux:partition_state id="oval:ssg-state_no_files_or_dirs_ungroupowned_dev_partitons:ste:1" operator="AND" version="1">
          <linux:device operation="pattern match">^/dev/.*$</linux:device>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_no_files_or_dirs_ungroupowned_nsswitch_uses_altfiles:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">altfiles</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_no_files_or_dirs_unowned_by_user_uids_list:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" var_check="at least one" var_ref="oval:ssg-var_no_files_or_dirs_unowned_by_user_uids_list:var:1"/>
        </unix:file_state>
        <linux:partition_state id="oval:ssg-state_no_files_or_dirs_unowned_by_user_dev_partitons:ste:1" operator="AND" version="1">
          <linux:device operation="pattern match">^/dev/.*$</linux:device>
        </linux:partition_state>
        <unix:file_state id="oval:ssg-state_no_files_unowned_by_user_uids_list:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" var_check="at least one" var_ref="oval:ssg-var_no_files_unowned_by_user_uids_list:var:1"/>
        </unix:file_state>
        <linux:partition_state id="oval:ssg-state_no_files_unowned_by_user_dev_partitons:ste:1" operator="AND" version="1">
          <linux:device operation="pattern match">^/dev/.*$</linux:device>
        </linux:partition_state>
        <unix:file_state id="oval:ssg-state_file_etc_security_opasswd:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals">0</unix:user_id>
          <unix:suid datatype="boolean" operation="equals">0</unix:suid>
          <unix:sticky datatype="boolean" operation="equals">0</unix:sticky>
          <unix:uread datatype="boolean" operation="equals">1</unix:uread>
          <unix:uwrite datatype="boolean" operation="equals">1</unix:uwrite>
          <unix:uexec datatype="boolean" operation="equals">0</unix:uexec>
          <unix:oread datatype="boolean" operation="equals">0</unix:oread>
          <unix:owrite datatype="boolean" operation="equals">0</unix:owrite>
          <unix:oexec datatype="boolean" operation="equals">0</unix:oexec>
          <unix:has_extended_acl datatype="boolean" operation="equals">0</unix:has_extended_acl>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_group_etc_security_opasswd:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals">0</unix:group_id>
          <unix:sgid datatype="boolean" operation="equals">0</unix:sgid>
          <unix:gread datatype="boolean" operation="equals">0</unix:gread>
          <unix:gwrite datatype="boolean" operation="equals">0</unix:gwrite>
          <unix:gexec datatype="boolean" operation="equals">0</unix:gexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_groupowner_system_commands_dirs_not_root_or_system_account:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="greater than or equal">1000</unix:group_id>
        </unix:file_state>
        <unix:file_state comment="symbolic link" id="oval:ssg-state_groupowner_system_commands_dirs_symlink:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_owner_binaries_not_root:ste:1" operator="OR" version="1">
          <unix:user_id datatype="int" operation="not equal">0</unix:user_id>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_perms_binary_files_nogroupwrite_noworldwrite:ste:1" operator="OR" version="1">
          <unix:gwrite datatype="boolean">true</unix:gwrite>
          <unix:owrite datatype="boolean">true</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_perms_binary_files_symlink:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rootfiles_configured_bash_logout:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">600</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rootfiles_configured_bash_profile:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">600</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rootfiles_configured_bashrc:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">600</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rootfiles_configured_cshrc:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">600</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rootfiles_configured_tcshrc:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">600</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_local_nodev:ste:1" operator="AND" version="1">
          <linux:device operation="pattern match">^/dev/.*$</linux:device>
          <linux:fs_type operation="pattern match">^(?!afs$|autofs$|ceph$|cifs$|smb3$|smbfs$|sshfs$|ncpfs$|ncp$|nfs$|nfs4$|gfs$|gfs2$|glusterfs$|gpfs$|pvfs2$|ocfs2$|lustre$|davfs$|fuse\.sshfs$).+</linux:fs_type>
          <linux:mount_options datatype="string" entity_check="all" operation="not equal">nodev</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_non_root_partitions_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
          <ind:subexpression operation="pattern match">nodev</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_mount_option_var_tmp_bind_compare_source:ste:1" operator="AND" version="1">
          <linux:device datatype="string" entity_check="at least one" operation="equals" var_ref="oval:ssg-var_mount_option_var_tmp_bind_var_tmp_source_device:var:1"/>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_core_dumps_limitsconf:ste:1" operator="AND" version="1">
          <ind:subexpression operation="equals">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_core_dumps_limits_d:ste:1" operator="AND" version="1">
          <ind:subexpression operation="equals">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-ste_umask_for_daemons:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="bitwise and" var_ref="oval:ssg-var_umask_for_daemons_umask_as_number:var:1"/>
        </ind:variable_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_exec_shield:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">1</unix:value>
        </unix:sysctl_state>
        <unix:file_state comment="device files" id="oval:ssg-state_block_or_char_device_file:ste:1" operator="AND" version="1">
          <unix:type operation="pattern match">^(block|character) special$</unix:type>
        </unix:file_state>
        <linux:selinuxsecuritycontext_state comment="device_t label" id="oval:ssg-state_selinux_dev_device_t:ste:1" operator="AND" version="1">
          <linux:type datatype="string" operation="equals">device_t</linux:type>
        </linux:selinuxsecuritycontext_state>
        <linux:selinuxsecuritycontext_state comment="unlabeled_t label" id="oval:ssg-state_selinux_dev_unlabeled_t:ste:1" operator="AND" version="1">
          <linux:type datatype="string" operation="equals">unlabeled_t</linux:type>
        </linux:selinuxsecuritycontext_state>
        <linux:selinuxsecuritycontext_state comment="state unconfined_service_t" id="oval:ssg-state_selinux_confinement_of_daemons:ste:1" operator="AND" version="1">
          <linux:type datatype="string" operation="equals">unconfined_service_t</linux:type>
        </linux:selinuxsecuritycontext_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sudo_selinux_elevation_type:ste:1" operator="AND" version="1">
          <ind:subexpression operation="equals">sysadm_t</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sudo_selinux_elevation_role:ste:1" operator="AND" version="1">
          <ind:subexpression operation="equals">sysadm_r</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_selinux_not_disabled:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(enforcing|permissive)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_etc_selinux_config:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_check="all" var_ref="oval:ssg-var_selinux_state:var:1"/>
        </ind:textfilecontent54_state>
        <linux:rpminfo_state id="oval:ssg-state_installed_arch_of_kernel_package:ste:1" operator="AND" version="1">
          <linux:arch>x86_64</linux:arch>
        </linux:rpminfo_state>
        <ind:textfilecontent54_state id="oval:ssg-state_proc_cpuinfo_64_bit:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">\blm\b</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_proc_sys_kernel_osrelease_64_bit:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(x86_64|aarch64|ppc64le|s390x|.*-amd64)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_gdm_db_is_up_to_date:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-var_dconf_gdm_keyfiles_modified_time:var:1"/>
        </ind:variable_state>
        <ind:variable_state id="oval:ssg-state_local_db_is_up_to_date:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-var_dconf_local_keyfiles_modified_time:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_xwayland_disabled:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^false$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_gnome_gdm_disable_xdmcp:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^false$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_screensaver_idle_delay_setting:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-inactivity_timeout_value:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_screensaver_idle_delay_setting_not_zero:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="not equal">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_screensaver_lock_delay_setting:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-var_screensaver_lock_delay:var:1"/>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_crypto_current_file_newer_than_config_file:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-variable_crypto_policies_current_file_timestamp:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_configure_crypto_policy:ste:1" operator="AND" version="1">
          <ind:subexpression operation="equals" var_check="all" var_ref="oval:ssg-var_system_crypto_policy:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_configure_crypto_policy_current:ste:1" operator="AND" version="1">
          <ind:subexpression operation="equals" var_check="all" var_ref="oval:ssg-var_system_crypto_policy:var:1"/>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_symlink_kerberos_crypto_policy_backend:ste:1" operator="AND" version="1">
          <ind:value datatype="string" operation="equals" var_ref="oval:ssg-var_symlink_kerberos_crypto_policy_backend:var:1"/>
        </ind:variable_state>
        <ind:variable_state id="oval:ssg-state_location_of_kerberos_crypto_policy_backend:ste:1" operator="AND" version="1">
          <ind:value datatype="string" operation="equals">/etc/crypto-policies/back-ends/krb5.config</ind:value>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_configure_openssl_tls_crypto_policy:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="version" operation="greater than or equal">1.2</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_configure_openssl_tls_crypto_policy_last_instance:ste:1" operator="AND" version="1">
          <ind:instance datatype="int" operation="equals" var_ref="oval:ssg-var_count_configure_openssl_tls_crypto_policy:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_configure_openssl_dtls_crypto_policy_last_instance:ste:1" operator="AND" version="1">
          <ind:instance datatype="int" operation="equals" var_ref="oval:ssg-var_count_configure_openssl_dtls_crypto_policy:var:1"/>
        </ind:textfilecontent54_state>
        <linux:rpminfo_state id="oval:ssg-state_installed_version_of_crypto_policies:ste:1" operator="AND" version="1">
          <linux:evr datatype="evr_string" operation="less than">0:20210617-1</linux:evr>
        </linux:rpminfo_state>
        <ind:textfilecontent54_state id="oval:ssg-state_harden_openssl_crypto_policy:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_harden_ssh_client_crypto_policy_Match:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^final all$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_harden_ssh_client_crypto_policy_RekeyLimit:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^512M 1h$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_harden_ssh_client_crypto_policy_GSSAPIAuthentication:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^no$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_harden_ssh_client_crypto_policy_Ciphers:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^aes256-ctr,aes256-cbc,aes128-ctr,aes128-cbc$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_harden_ssh_client_crypto_policy_PubkeyAcceptedKeyTypes:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^ssh-rsa,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_harden_ssh_client_crypto_policy_MACs:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^hmac-sha2-512,hmac-sha2-256$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_harden_ssh_client_crypto_policy_KexAlgorithms:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group14-sha1$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-ste_harden_sshd_ciphers_openssh_conf_crypto_policy:ste:1" operator="AND" version="1">
          <ind:text operation="equals" var_ref="oval:ssg-sshd_ciphers_crypto:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-ste_harden_sshd_ciphers_opensshserver_conf_crypto_policy:ste:1" operator="AND" version="1">
          <ind:subexpression operation="equals" var_ref="oval:ssg-sshd_approved_ciphers:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_harden_sshd_crypto_policy:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^'-oCiphers=aes256-ctr,aes128-ctr,aes256-cbc,aes128-cbc -oMACs=hmac-sha2-512,hmac-sha2-256 -oGSSAPIKeyExchange=no -oKexAlgorithms=ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group14-sha1 -oHostKeyAlgorithms=ssh-rsa,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256 -oPubkeyAcceptedKeyTypes=rsa-sha2-512,rsa-sha2-256,ssh-rsa,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256'$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-ste_harden_sshd_macs_openssh_conf_crypto_policy:ste:1" operator="AND" version="1">
          <ind:text operation="equals" var_ref="oval:ssg-sshd_macs_crypto:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-ste_harden_sshd_macs_opensshserver_conf_crypto_policy:ste:1" operator="AND" version="1">
          <ind:subexpression operation="equals" var_ref="oval:ssg-sshd_approved_macs:var:1"/>
        </ind:textfilecontent54_state>
        <ind:filehash58_state id="oval:ssg-state_openssl_strong_entropy:ste:1" operator="AND" version="1">
          <ind:filepath>/etc/profile.d/openssl-rand.sh</ind:filepath>
          <ind:hash_type>SHA-256</ind:hash_type>
          <ind:hash>6488c757642cd493da09dd78ee27f039711a1ad79039900970553772fd2106af</ind:hash>
        </ind:filehash58_state>
        <ind:variable_state id="oval:ssg-state_mcafee_definitions_max_age:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-var_mcafee_antivirus_definition_expire:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_enable_dracut_fips_module:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">fips</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state comment="variable value is set to 'FIPS' or 'FIPS:modifier', where the modifier corresponds to a crypto policy module that further restricts the modified crypto policy." id="oval:ssg-ste_system_crypto_policy_value:ste:1" operator="AND" version="2">
          <ind:value datatype="string" operation="pattern match">^FIPS(:(OSPP|NO-SHA1|NO-CAMELLIA|STIG))?$</ind:value>
        </ind:variable_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_crypto_fips_enabled:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">1</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_aide_check_attributes:ste:1" operator="AND" version="1">
          <ind:subexpression operation="equals">p+i+n+u+g+s+b+acl+selinux+xattrs+sha512</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_aide_use_fips_hashes:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^.*sha512.*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_aide_verify_acls:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^.*acl.*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_aide_verify_ext_attributes:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^.*xattrs.*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:rpmverifyfile_state id="oval:ssg-state_rpm_verify_hashes_fail_md5_hash:ste:1" operator="AND" version="1">
          <linux:md5_differs>fail</linux:md5_differs>
          <linux:configuration_file datatype="boolean">false</linux:configuration_file>
          <linux:ghost_file datatype="boolean">false</linux:ghost_file>
        </linux:rpmverifyfile_state>
        <linux:rpmverifyfile_state id="oval:ssg-state_rpm_verify_ownership_files_fail_ownership:ste:1" operator="OR" version="2">
          <linux:ownership_differs>fail</linux:ownership_differs>
          <linux:group_differs>fail</linux:group_differs>
        </linux:rpmverifyfile_state>
        <linux:rpmverifyfile_state id="oval:ssg-state_rpm_verify_permissions_files_fail_mode:ste:1" operator="AND" version="1">
          <linux:mode_differs>fail</linux:mode_differs>
        </linux:rpmverifyfile_state>
        <unix:file_state id="oval:ssg-state_sudo_file_gid_is_dedicated_group_gid:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="not equal">0</unix:group_id>
        </unix:file_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sudoers_default_includedir:ste:1" operator="AND" version="1">
          <ind:subexpression operation="equals">/etc/sudoers.d</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-disable_weak_deps_state_disable_weak_deps:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(0|false|no)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_dnf-automatic_apply_updates:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^yes$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_dnf-automatic_security_updates_only:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^security$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_enable_gpgcheck_for_all_repositories_all_enabled:ste:1" operator="AND" version="1">
          <ind:text datatype="string" operation="pattern match">\n\s*gpgcheck\s*=\s*(True|1|yes)\s*(\n|$)</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_enable_gpgcheck_for_all_repositories_no_disabled:ste:1" operator="AND" version="1">
          <ind:text datatype="string" operation="pattern match">\n\s*gpgcheck\s*=\s*(False|0|no)\s*(\n|$)</ind:text>
        </ind:textfilecontent54_state>
        <linux:rpminfo_state id="oval:ssg-state_almalinux_package_gpg-pubkey-3abb34f8-5ffd890e:ste:1" operator="AND" version="1">
          <linux:release>5ffd890e</linux:release>
          <linux:version>3abb34f8</linux:version>
        </linux:rpminfo_state>
        <linux:rpminfo_state id="oval:ssg-state_almalinux_package_gpg-pubkey-ced7258b-6525146f:ste:1" operator="AND" version="1">
          <linux:release>6525146f</linux:release>
          <linux:version>ced7258b</linux:version>
        </linux:rpminfo_state>
        <ind:textfilecontent54_state id="oval:ssg-state_epel_disabled:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(0|[Ff]alse|[Nn]o)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_password_pam_dcredit:ste:1" operator="AND" version="3">
          <ind:subexpression datatype="int" operation="less than or equal" var_ref="oval:ssg-var_password_pam_dcredit:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_password_pam_dictcheck:ste:1" operator="AND" version="3">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-var_password_pam_dictcheck:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_password_pam_difok:ste:1" operator="AND" version="3">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_password_pam_difok:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_password_pam_lcredit:ste:1" operator="AND" version="3">
          <ind:subexpression datatype="int" operation="less than or equal" var_ref="oval:ssg-var_password_pam_lcredit:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_password_pam_maxclassrepeat:ste:1" operator="AND" version="3">
          <ind:subexpression datatype="int" operation="less than or equal" var_ref="oval:ssg-var_password_pam_maxclassrepeat:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_password_pam_maxclassrepeat_zero_comparison:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_password_pam_maxrepeat:ste:1" operator="AND" version="3">
          <ind:subexpression datatype="int" operation="less than or equal" var_ref="oval:ssg-var_password_pam_maxrepeat:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_password_pam_maxsequence:ste:1" operator="AND" version="3">
          <ind:subexpression datatype="int" operation="less than or equal" var_ref="oval:ssg-var_password_pam_maxsequence:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_password_pam_maxsequence_zero_comparison:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_password_pam_minclass:ste:1" operator="AND" version="3">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_password_pam_minclass:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_password_pam_minlen:ste:1" operator="AND" version="3">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_password_pam_minlen:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_password_pam_ocredit:ste:1" operator="AND" version="3">
          <ind:subexpression datatype="int" operation="less than or equal" var_ref="oval:ssg-var_password_pam_ocredit:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_password_pam_ucredit:ste:1" operator="AND" version="3">
          <ind:subexpression datatype="int" operation="less than or equal" var_ref="oval:ssg-var_password_pam_ucredit:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_accounts_passwords_pam_faillock_deny_parameter_upper_bound:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="less than or equal" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_accounts_passwords_pam_faillock_deny_parameter_lower_bound:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal">1</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_accounts_passwords_pam_faillock_fail_interval_parameter_lower_bound:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_accounts_passwords_pam_faillock_unlock_time_parameter_lower_bound:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-audit_access_failed_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_3_access_failed_rules:ste:1" operator="AND" version="1">
          <ind:text operation="equals">## Unsuccessful file access (any other opens) This has to go last.
-a always,exit -F arch=b32 -S open,openat,openat2,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
-a always,exit -F arch=b64 -S open,openat,openat2,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
-a always,exit -F arch=b32 -S open,openat,openat2,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
-a always,exit -F arch=b64 -S open,openat,openat2,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-audit_access_success_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_3_access_success_rules:ste:1" operator="AND" version="1">
          <ind:text operation="equals">## Successful file access (any other opens) This has to go last.
## These next two are likely to result in a whole lot of events
-a always,exit -F arch=b32 -S open,openat,openat2,open_by_handle_at -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access
-a always,exit -F arch=b64 -S open,openat,openat2,open_by_handle_at -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access
</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-audit_basic_configuration_state_whole_file_contents_tc_audit_rules_d_10_base_config_rules:ste:1" operator="AND" version="1">
          <ind:text operation="equals">## First rule - delete all
-D

## Increase the buffers to survive stress events.
## Make this bigger for busy systems
-b 8192

## This determine how long to wait in burst of events
--backlog_wait_time 60000

## Set failure mode to syslog
-f 1

</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-audit_create_failed_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_1_create_failed_rules:ste:1" operator="AND" version="1">
          <ind:text operation="equals">## Unsuccessful file creation (open with O_CREAT)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-audit_create_success_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_1_create_success_rules:ste:1" operator="AND" version="1">
          <ind:text operation="equals">## Successful file creation (open with O_CREAT)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b32 -S creat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b64 -S creat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-audit_delete_failed_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_failed_rules:ste:1" operator="AND" version="1">
          <ind:text operation="equals">## Unsuccessful file delete
-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-audit_delete_success_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_4_delete_success_rules:ste:1" operator="AND" version="1">
          <ind:text operation="equals">## Successful file delete
-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete
-a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete
</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-audit_immutable_login_uids_state_whole_file_contents_tc_audit_rules_d_11_loginuid_rules:ste:1" operator="AND" version="1">
          <ind:text operation="equals">## Make the loginuid immutable. This prevents tampering with the auid.
--loginuid-immutable

</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-audit_modify_failed_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_2_modify_failed_rules:ste:1" operator="AND" version="1">
          <ind:text operation="equals">## Unsuccessful file modifications (open for write or truncate)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-audit_modify_success_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_2_modify_success_rules:ste:1" operator="AND" version="1">
          <ind:text operation="equals">## Successful file modifications (open for write or truncate)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-audit_module_load_state_whole_file_contents_tc_audit_rules_d_43_module_load_rules:ste:1" operator="AND" version="1">
          <ind:text operation="equals">## These rules watch for kernel module insertion. By monitoring
## the syscall, we do not need any watches on programs.
-a always,exit -F arch=b32 -S init_module,finit_module -F key=module-load
-a always,exit -F arch=b64 -S init_module,finit_module -F key=module-load
-a always,exit -F arch=b32 -S delete_module -F key=module-unload
-a always,exit -F arch=b64 -S delete_module -F key=module-unload
</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-audit_ospp_general_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_rules:ste:1" operator="AND" version="1">
          <ind:text operation="equals">## The purpose of these rules is to meet the requirements for Operating
## System Protection Profile (OSPP)v4.2. These rules depends on having
## the following rule files copied to /etc/audit/rules.d:
##
## 10-base-config.rules, 11-loginuid.rules,
## 30-ospp-v42-1-create-failed.rules, 30-ospp-v42-1-create-success.rules,
## 30-ospp-v42-2-modify-failed.rules, 30-ospp-v42-2-modify-success.rules,
## 30-ospp-v42-3-access-failed.rules, 30-ospp-v42-3-access-success.rules,
## 30-ospp-v42-4-delete-failed.rules, 30-ospp-v42-4-delete-success.rules,
## 30-ospp-v42-5-perm-change-failed.rules,
## 30-ospp-v42-5-perm-change-success.rules,
## 30-ospp-v42-6-owner-change-failed.rules,
## 30-ospp-v42-6-owner-change-success.rules
##
## original copies may be found in /usr/share/audit/sample-rules/


## User add delete modify. This is covered by pam. However, someone could
## open a file and directly create or modify a user, so we'll watch passwd and
## shadow for writes
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -S open -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -S open -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify

## User enable and disable. This is entirely handled by pam.

## Group add delete modify. This is covered by pam. However, someone could
## open a file and directly create or modify a user, so we'll watch group and
## gshadow for writes
-a always,exit -F arch=b32 -F path=/etc/passwd -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -F path=/etc/passwd -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -F path=/etc/shadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -F path=/etc/shadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -F path=/etc/group -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify
-a always,exit -F arch=b64 -F path=/etc/group -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify
-a always,exit -F arch=b32 -F path=/etc/gshadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify
-a always,exit -F arch=b64 -F path=/etc/gshadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify


## Use of special rights for config changes. This would be use of setuid
## programs that relate to user accts. This is not all setuid apps because
## requirements are only for ones that affect system configuration.
-a always,exit -F arch=b32 -F path=/usr/sbin/unix_chkpwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/unix_chkpwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/sbin/usernetctl -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/usernetctl -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/sbin/userhelper -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/userhelper -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/sbin/seunshare -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/seunshare -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/mount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/mount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/newgrp -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/newgrp -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/newuidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/newuidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/gpasswd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/gpasswd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/newgidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/newgidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/umount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/umount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/passwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/passwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/crontab -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/crontab -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/at -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/at -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/sbin/grub2-set-bootflag -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/grub2-set-bootflag -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes

## Privilege escalation via su or sudo. This is entirely handled by pam.
## Special case for systemd-run. It is not audit aware, specifically watch it
-a always,exit -F arch=b32 -F path=/usr/bin/systemd-run -F perm=x -F auid!=unset -F key=maybe-escalation
-a always,exit -F arch=b64 -F path=/usr/bin/systemd-run -F perm=x -F auid!=unset -F key=maybe-escalation
## Special case for pkexec. It is not audit aware, specifically watch it
-a always,exit -F arch=b32 -F path=/usr/bin/pkexec -F perm=x -F key=maybe-escalation
-a always,exit -F arch=b64 -F path=/usr/bin/pkexec -F perm=x -F key=maybe-escalation


## Watch for configuration changes to privilege escalation.
-a always,exit -F arch=b32 -F path=/etc/sudoers -F perm=wa -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/etc/sudoers -F perm=wa -F key=special-config-changes
-a always,exit -F arch=b32 -F dir=/etc/sudoers.d/ -F perm=wa -F key=special-config-changes
-a always,exit -F arch=b64 -F dir=/etc/sudoers.d/ -F perm=wa -F key=special-config-changes

## Audit log access
-a always,exit -F arch=b32 -F dir=/var/log/audit/ -F perm=r -F auid&gt;=1000 -F auid!=unset -F key=access-audit-trail
-a always,exit -F arch=b64 -F dir=/var/log/audit/ -F perm=r -F auid&gt;=1000 -F auid!=unset -F key=access-audit-trail
## Attempts to Alter Process and Session Initiation Information
-a always,exit -F arch=b32 -F path=/var/run/utmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b64 -F path=/var/run/utmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b32 -F path=/var/log/btmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b64 -F path=/var/log/btmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b32 -F path=/var/log/wtmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b64 -F path=/var/log/wtmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session

## Attempts to modify MAC controls
-a always,exit -F arch=b32 -F dir=/etc/selinux/ -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=MAC-policy
-a always,exit -F arch=b64 -F dir=/etc/selinux/ -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=MAC-policy

## Software updates. This is entirely handled by rpm.

## System start and shutdown. This is entirely handled by systemd

## Kernel Module loading. This is handled in 43-module-load.rules

## Application invocation. The requirements list an optional requirement
## FPT_SRP_EXT.1 Software Restriction Policies. This event is intended to
## state results from that policy. This would be handled entirely by
## that daemon.

</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-audit_owner_change_failed_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_6_owner_change_failed_rules:ste:1" operator="AND" version="1">
          <ind:text operation="equals">## Unsuccessful ownership change
-a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
-a always,exit -F arch=b64 -S lchown,fchown,chown,fchownat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
-a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
-a always,exit -F arch=b64 -S lchown,fchown,chown,fchownat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-audit_owner_change_success_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_6_owner_change_success_rules:ste:1" operator="AND" version="1">
          <ind:text operation="equals">## Successful ownership change
-a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-owner-change
-a always,exit -F arch=b64 -S lchown,fchown,chown,fchownat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-owner-change
</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-audit_perm_change_failed_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_5_perm_change_failed_rules:ste:1" operator="AND" version="1">
          <ind:text operation="equals">## Unsuccessful permission change
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-audit_perm_change_success_state_whole_file_contents_tc_audit_rules_d_30_ospp_v42_5_perm_change_success_rules:ste:1" operator="AND" version="1">
          <ind:text operation="equals">## Successful permission change
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change
</ind:text>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_freq:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-var_auditd_freq:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_local_events:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?i)yes(?-i)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_log_format:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?i)ENRICHED(?-i)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_auditd_write_logs:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?i)yes(?-i)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_configure_usbguard_auditbackend:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^LinuxAudit$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_coredump_disable_backtraces:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^0$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_coredump_disable_backtraces_config_dir:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^0$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_coredump_disable_storage:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^none$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_coredump_disable_storage_config_dir:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^none$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_boot_loader_entries_ostree_1_conf:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?selinux=0(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_boot_loader_entries_ostree_2_conf:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?selinux=0(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_coreos_enable_selinux_kernel_argument_selinux_0_argument_in_proc_cmdline:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?selinux=0(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_dconf_gnome_disable_user_admin:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^true$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_dconf_gnome_lock_screen_on_smartcard_removal:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^'lock-screen'$</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_file_groupownerdir_group_ownership_library_dirs_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownerdir_group_ownership_library_dirs_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-symlink_file_groupowner:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-symlink_file_owner:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_ownerdir_ownership_binary_dirs_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownerdir_ownership_binary_dirs_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_ownerdir_ownership_library_dirs_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownerdir_ownership_library_dirs_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_binary_dirs_0_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_binary_dirs_1_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_binary_dirs_2_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_binary_dirs_3_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_binary_dirs_4_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_binary_dirs_5_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks_dir_permissions_binary_dirs:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_library_dirs_0_mode_7755or_stricter_:ste:1" operator="AND" version="3">
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_library_dirs_1_mode_7755or_stricter_:ste:1" operator="AND" version="3">
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_library_dirs_2_mode_7755or_stricter_:ste:1" operator="AND" version="3">
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_library_dirs_3_mode_7755or_stricter_:ste:1" operator="AND" version="3">
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks_dir_permissions_library_dirs:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupownerdirectory_groupowner_etc_ipsecd_0_root:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownerdirectory_groupowner_etc_ipsecd_root_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupownerdirectory_groupowner_etc_iptables_0_root:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownerdirectory_groupowner_etc_iptables_root_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupownerdirectory_groupowner_etc_nftables_0_root:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownerdirectory_groupowner_etc_nftables_root_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupownerdirectory_groupowner_etc_selinux_0_root:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownerdirectory_groupowner_etc_selinux_root_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupownerdirectory_groupowner_etc_sudoersd_0_root:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownerdirectory_groupowner_etc_sudoersd_root_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupownerdirectory_groupowner_etc_sysctld_0_root:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownerdirectory_groupowner_etc_sysctld_root_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_ownerdirectory_owner_etc_ipsecd_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownerdirectory_owner_etc_ipsecd_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_ownerdirectory_owner_etc_iptables_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownerdirectory_owner_etc_iptables_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_ownerdirectory_owner_etc_nftables_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownerdirectory_owner_etc_nftables_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_ownerdirectory_owner_etc_selinux_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownerdirectory_owner_etc_selinux_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_ownerdirectory_owner_etc_sudoersd_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownerdirectory_owner_etc_sudoersd_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_ownerdirectory_owner_etc_sysctld_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownerdirectory_owner_etc_sysctld_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsdirectory_permissions_etc_ipsecd_0_mode_0700or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks_directory_permissions_etc_ipsecd:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsdirectory_permissions_etc_iptables_0_mode_0700or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks_directory_permissions_etc_iptables:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsdirectory_permissions_etc_nftables_0_mode_0700or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks_directory_permissions_etc_nftables:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsdirectory_permissions_etc_selinux_0_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks_directory_permissions_etc_selinux:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsdirectory_permissions_etc_sudoersd_0_mode_0750or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks_directory_permissions_etc_sudoersd:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsdirectory_permissions_etc_sysctld_0_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks_directory_permissions_etc_sysctld:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <ind:textfilecontent54_state id="oval:ssg-state_disable_host_auth:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^no$</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_file_groupownerfile_audit_tools_group_ownership_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownerfile_audit_tools_group_ownership_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_ownerfile_audit_tools_ownership_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownerfile_audit_tools_ownership_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsfile_audit_tools_permissions_0_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsfile_audit_tools_permissions_1_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsfile_audit_tools_permissions_2_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsfile_audit_tools_permissions_3_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsfile_audit_tools_permissions_4_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsfile_audit_tools_permissions_5_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissionsfile_audit_tools_permissions_6_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks_file_audit_tools_permissions:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_at_allow_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_at_allow_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_backup_etc_group_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_backup_etc_group_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_backup_etc_gshadow_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_backup_etc_gshadow_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_backup_etc_passwd_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_backup_etc_passwd_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_backup_etc_shadow_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_backup_etc_shadow_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_cron_allow_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_cron_allow_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_cron_d_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_cron_d_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_cron_daily_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_cron_daily_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_cron_hourly_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_cron_hourly_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_cron_monthly_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_cron_monthly_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_cron_weekly_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_cron_weekly_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_cron_yearly_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_cron_yearly_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_crontab_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_crontab_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_efi_grub2_cfg_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_efi_grub2_cfg_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_efi_user_cfg_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_efi_user_cfg_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_crypttab_0_root:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_etc_crypttab_root_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_group_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_etc_group_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_gshadow_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_etc_gshadow_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_ipsec_conf_0_root:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_etc_ipsec_conf_root_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_ipsec_secrets_0_root:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_etc_ipsec_secrets_root_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_issue_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_etc_issue_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_issue_net_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_etc_issue_net_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_motd_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_etc_motd_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_passwd_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_etc_passwd_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_security_opasswd_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_etc_security_opasswd_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_security_opasswd_old_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_etc_security_opasswd_old_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_sestatus_conf_0_root:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_etc_sestatus_conf_root_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_shadow_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_etc_shadow_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_shells_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_etc_shells_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_sudoers_0_root:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_etc_sudoers_root_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_etc_sysconfig_sshd_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_etc_sysconfig_sshd_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_grub2_cfg_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_grub2_cfg_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_sshd_config_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_sshd_config_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_systemmap_0_root:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_systemmap_root_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_user_cfg_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_user_cfg_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_var_log_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_var_log_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_var_log_messages_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_var_log_messages_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupowner_var_log_syslog_0_4:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_var_log_syslog_4_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupownership_audit_binaries_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownership_audit_binaries_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupownership_audit_configuration_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownership_audit_configuration_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupownership_sshd_private_key_0_ssh_keys:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownership_sshd_private_key_ssh_keys_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_groupownership_sshd_pub_key_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownership_sshd_pub_key_0_gid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_at_allow_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_at_allow_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_backup_etc_group_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_backup_etc_group_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_backup_etc_gshadow_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_backup_etc_gshadow_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_backup_etc_passwd_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_backup_etc_passwd_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_backup_etc_shadow_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_backup_etc_shadow_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_cron_allow_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_cron_allow_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_cron_d_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_cron_d_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_cron_daily_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_cron_daily_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_cron_hourly_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_cron_hourly_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_cron_monthly_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_cron_monthly_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_cron_weekly_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_cron_weekly_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_cron_yearly_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_cron_yearly_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_crontab_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_crontab_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_efi_grub2_cfg_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_efi_grub2_cfg_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_efi_user_cfg_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_efi_user_cfg_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_etc_chrony_keys_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_etc_chrony_keys_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_etc_crypttab_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_etc_crypttab_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_etc_group_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_etc_group_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_etc_gshadow_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_etc_gshadow_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_etc_ipsec_conf_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_etc_ipsec_conf_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_etc_ipsec_secrets_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_etc_ipsec_secrets_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_etc_issue_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_etc_issue_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_etc_issue_net_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_etc_issue_net_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_etc_motd_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_etc_motd_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_etc_passwd_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_etc_passwd_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_etc_security_opasswd_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_etc_security_opasswd_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_etc_security_opasswd_old_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_etc_security_opasswd_old_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_etc_sestatus_conf_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_etc_sestatus_conf_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_etc_shadow_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_etc_shadow_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_etc_shells_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_etc_shells_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_etc_sudoers_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_etc_sudoers_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_etc_sysconfig_sshd_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_etc_sysconfig_sshd_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_grub2_cfg_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_grub2_cfg_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_sshd_config_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_sshd_config_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_systemmap_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_systemmap_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_user_cfg_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_user_cfg_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_var_log_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_var_log_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_var_log_messages_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_var_log_messages_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_owner_var_log_syslog_0_syslog:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_var_log_syslog_syslog_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_ownership_audit_binaries_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownership_audit_binaries_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_ownership_audit_configuration_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownership_audit_configuration_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_ownership_library_dirs_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownership_library_dirs_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_ownership_sshd_private_key_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownership_sshd_private_key_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_ownership_sshd_pub_key_0_0:ste:1" operator="AND" version="1">
          <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownership_sshd_pub_key_0_uid:var:1"/>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_at_allow_0_mode_0640or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__at_allow:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_audit_binaries_0_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_audit_binaries_1_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_audit_binaries_2_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_audit_binaries_3_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_audit_binaries_4_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_audit_binaries_5_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_audit_binaries_6_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__audit_binaries:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_audit_configuration_0_mode_0640or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_audit_configuration_1_mode_0640or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__audit_configuration:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_backup_etc_group_0_mode_0644or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__backup_etc_group:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_backup_etc_gshadow_0_mode_0000or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uread datatype="boolean">false</unix:uread>
          <unix:uwrite datatype="boolean">false</unix:uwrite>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__backup_etc_gshadow:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_backup_etc_passwd_0_mode_0644or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__backup_etc_passwd:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_backup_etc_shadow_0_mode_0000or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uread datatype="boolean">false</unix:uread>
          <unix:uwrite datatype="boolean">false</unix:uwrite>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__backup_etc_shadow:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_cron_allow_0_mode_0640or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__cron_allow:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_cron_d_0_mode_0700or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__cron_d:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_cron_daily_0_mode_0700or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__cron_daily:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_cron_hourly_0_mode_0700or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__cron_hourly:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_cron_monthly_0_mode_0700or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__cron_monthly:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_cron_weekly_0_mode_0700or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__cron_weekly:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_cron_yearly_0_mode_0700or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__cron_yearly:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_crontab_0_mode_0600or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__crontab:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_efi_grub2_cfg_0_mode_0700or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__efi_grub2_cfg:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_efi_user_cfg_0_mode_0700or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__efi_user_cfg:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_audit_auditd_0_mode_0640or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_audit_auditd:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_audit_rulesd_0_mode_0600or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_audit_rulesd:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_chrony_keys_0_mode_0640or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_chrony_keys:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_crypttab_0_mode_0600or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_crypttab:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_group_0_mode_0644or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_group:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_gshadow_0_mode_0000or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uread datatype="boolean">false</unix:uread>
          <unix:uwrite datatype="boolean">false</unix:uwrite>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_gshadow:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_ipsec_conf_0_mode_0644or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_ipsec_conf:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_ipsec_secrets_0_mode_0644or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_ipsec_secrets:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_issue_0_mode_0644or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_issue:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_issue_net_0_mode_0644or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_issue_net:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_motd_0_mode_0644or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_motd:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_passwd_0_mode_0644or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_passwd:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_security_opasswd_0_mode_0600or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_security_opasswd:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_security_opasswd_old_0_mode_0600or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_security_opasswd_old:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_sestatus_conf_0_mode_0644or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_sestatus_conf:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_shadow_0_mode_0000or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uread datatype="boolean">false</unix:uread>
          <unix:uwrite datatype="boolean">false</unix:uwrite>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_shadow:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_shells_0_mode_0644or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_shells:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_sudoers_0_mode_0440or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uwrite datatype="boolean">false</unix:uwrite>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_sudoers:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_etc_sysconfig_sshd_0_mode_0640or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__etc_sysconfig_sshd:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_grub2_cfg_0_mode_0600or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__grub2_cfg:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_library_dirs_0_mode_7755or_stricter_:ste:1" operator="AND" version="3">
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_library_dirs_1_mode_7755or_stricter_:ste:1" operator="AND" version="3">
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_library_dirs_2_mode_7755or_stricter_:ste:1" operator="AND" version="3">
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_library_dirs_3_mode_7755or_stricter_:ste:1" operator="AND" version="3">
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__library_dirs:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_sshd_config_0_mode_0600or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__sshd_config:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_sshd_pub_key_0_mode_0644or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__sshd_pub_key:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_sudo_0_mode_4110:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">true</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uread datatype="boolean">false</unix:uread>
          <unix:uwrite datatype="boolean">false</unix:uwrite>
          <unix:uexec datatype="boolean">true</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">true</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__sudo:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_systemmap_0_mode_0600or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__systemmap:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_user_cfg_0_mode_0600or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__user_cfg:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_var_log_0_mode_0755or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:owrite datatype="boolean">false</unix:owrite>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__var_log:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_var_log_messages_0_mode_0600or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__var_log_messages:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:file_state id="oval:ssg-state_file_permissions_var_log_syslog_0_mode_0640or_stricter_:ste:1" operator="AND" version="3">
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks__var_log_syslog:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <ind:textfilecontent54_state id="oval:ssg-state_firewalld-backend:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^nftables$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_audit_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?audit=1(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_audit_backlog_limit_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match" var_ref="oval:ssg-local_var_regex_audit_backlog_limit_var_audit_backlog_limit:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_iommu_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?iommu=force(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_init_on_free_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?init_on_free=1(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_ipv6_disable_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?ipv6\.disable=1(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_l1tf_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match" var_ref="oval:ssg-local_var_regex_l1tf_var_l1tf_options:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_mce_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?mce=0(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_nousb_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?nousb(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_page_poison_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?page_poison=1(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_pti_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?pti=on(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_rng_core_default_quality_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match" var_ref="oval:ssg-local_var_regex_rng_core_default_quality_var_rng_core_default_quality:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_slab_nomerge_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?slab_nomerge=yes(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_slub_debug_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match" var_ref="oval:ssg-local_var_regex_slub_debug_var_slub_debug_options:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_spec_store_bypass_disable_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match" var_ref="oval:ssg-local_var_regex_spec_store_bypass_disable_var_spec_store_bypass_disable_options:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_spectre_v2_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?spectre_v2=on(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_vsyscall_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?vsyscall=none(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_journald_compress:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^yes$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_journald_disable_forward_to_syslog:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^no$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_journald_forward_to_syslog:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^yes$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_journald_storage:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^persistent$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_acpi_custom_method:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_acpi_custom_method:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_acpi_custom_method_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_arm64_sw_ttbr0_pan:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_arm64_sw_ttbr0_pan:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_arm64_sw_ttbr0_pan_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_binfmt_misc:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_binfmt_misc:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_binfmt_misc_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_bug:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_bug:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_bug_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_bug_on_data_corruption:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_bug_on_data_corruption:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_bug_on_data_corruption_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_compat_brk:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_compat_brk:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_compat_brk_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_compat_vdso:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_compat_vdso:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_compat_vdso_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_debug_credentials:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_debug_credentials:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_debug_credentials_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_debug_fs:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_debug_fs:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_debug_fs_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_debug_list:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_debug_list:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_debug_list_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_debug_notifiers:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_debug_notifiers:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_debug_notifiers_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_debug_sg:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_debug_sg:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_debug_sg_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_debug_wx:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_debug_wx:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_debug_wx_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_devkmem:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_devkmem:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_devkmem_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_fortify_source:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_fortify_source:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_fortify_source_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_gcc_plugin_latent_entropy:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_gcc_plugin_latent_entropy:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_gcc_plugin_latent_entropy_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_gcc_plugin_structleak:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_gcc_plugin_structleak:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_gcc_plugin_structleak_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_hardened_usercopy:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_hardened_usercopy:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_hardened_usercopy_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_hardened_usercopy_fallback:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_hardened_usercopy_fallback:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_hardened_usercopy_fallback_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_hibernation:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_hibernation:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_hibernation_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_ia32_emulation:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_ia32_emulation:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_ia32_emulation_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_ipv6:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_ipv6:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_ipv6_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_kexec:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_kexec:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_kexec_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_legacy_ptys:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_legacy_ptys:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_legacy_ptys_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_legacy_vsyscall_emulate:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_legacy_vsyscall_emulate:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_legacy_vsyscall_emulate_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_legacy_vsyscall_none:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_legacy_vsyscall_none:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_legacy_vsyscall_none_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_modify_ldt_syscall:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_modify_ldt_syscall:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_modify_ldt_syscall_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_module_sig:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_module_sig:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_module_sig_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_module_sig_all:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_module_sig_all:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_module_sig_all_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_module_sig_force:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_module_sig_force:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_module_sig_force_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_module_sig_hash:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_ref="oval:ssg-var_kernel_config_module_sig_hash:var:1"/>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_module_sig_hash:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_module_sig_hash_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_module_sig_key:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_ref="oval:ssg-var_kernel_config_module_sig_key:var:1"/>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_module_sig_key:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_module_sig_key_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_module_sig_sha512:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_module_sig_sha512:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_module_sig_sha512_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_page_poisoning:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_page_poisoning:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_page_poisoning_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_page_poisoning_no_sanity:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_page_poisoning_no_sanity:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_page_poisoning_no_sanity_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_page_poisoning_zero:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_page_poisoning_zero:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_page_poisoning_zero_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_page_table_isolation:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_page_table_isolation:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_page_table_isolation_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_panic_on_oops:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_panic_on_oops:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_panic_on_oops_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_panic_timeout:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_ref="oval:ssg-var_kernel_config_panic_timeout:var:1"/>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_panic_timeout:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_panic_timeout_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_proc_kcore:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_proc_kcore:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_proc_kcore_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_randomize_base:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_randomize_base:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_randomize_base_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_randomize_memory:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_randomize_memory:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_randomize_memory_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_refcount_full:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_refcount_full:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_refcount_full_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_retpoline:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_retpoline:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_retpoline_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_sched_stack_end_check:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_sched_stack_end_check:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_sched_stack_end_check_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_seccomp:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_seccomp:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_seccomp_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_seccomp_filter:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_seccomp_filter:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_seccomp_filter_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_security:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_security:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_security_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_security_dmesg_restrict:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_security_dmesg_restrict:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_security_dmesg_restrict_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_security_writable_hooks:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_security_writable_hooks:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_security_writable_hooks_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_security_yama:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_security_yama:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_security_yama_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_slab_freelist_hardened:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_slab_freelist_hardened:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_slab_freelist_hardened_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_slab_freelist_random:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_slab_freelist_random:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_slab_freelist_random_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_slab_merge_default:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_slab_merge_default:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_slab_merge_default_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_slub_debug:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_slub_debug:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_slub_debug_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_stackprotector:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_stackprotector:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_stackprotector_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_stackprotector_strong:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_stackprotector_strong:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_stackprotector_strong_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_strict_kernel_rwx:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_strict_kernel_rwx:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_strict_kernel_rwx_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_strict_module_rwx:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_strict_module_rwx:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_strict_module_rwx_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_syn_cookies:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_syn_cookies:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_syn_cookies_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_unmap_kernel_at_el0:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_unmap_kernel_at_el0:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_unmap_kernel_at_el0_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_vmap_stack:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">y</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_vmap_stack:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_vmap_stack_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <ind:textfilecontent54_state id="oval:ssg-state_kernel_config_x86_vsyscall_emulation:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">n</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:variable_state id="oval:ssg-state_var_kernel_config_x86_vsyscall_emulation:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals" var_ref="oval:ssg-local_var_config_x86_vsyscall_emulation_count_compliant_configs:var:1"/>
        </ind:variable_state>
        <linux:partition_state id="oval:ssg-state_boot_efi_partition_nosuid_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nosuid</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_boot_efi_partition_nosuid_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nosuid</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_boot_partition_noauto_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">noauto</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_boot_partition_noauto_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">noauto</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_boot_partition_nodev_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nodev</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_boot_partition_nodev_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nodev</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_boot_partition_noexec_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">noexec</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_boot_partition_noexec_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">noexec</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_boot_partition_nosuid_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nosuid</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_boot_partition_nosuid_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nosuid</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_dev_shm_partition_nodev_expected:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nodev</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_dev_shm_partition_nodev_expected_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nodev</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_dev_shm_partition_noexec_expected:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">noexec</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_dev_shm_partition_noexec_expected_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">noexec</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_dev_shm_partition_nosuid_expected:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nosuid</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_dev_shm_partition_nosuid_expected_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nosuid</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_home_partition_grpquota_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">grpquota</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_home_partition_grpquota_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">grpquota</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_home_partition_nodev_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nodev</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_home_partition_nodev_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nodev</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_home_partition_noexec_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">noexec</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_home_partition_noexec_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">noexec</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_home_partition_nosuid_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nosuid</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_home_partition_nosuid_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nosuid</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_home_partition_usrquota_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">usrquota</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_home_partition_usrquota_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">usrquota</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_remote_filesystem_sec_krb5_krb5i_krb5p:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^.*sec=krb5:krb5i:krb5p.*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_remote_filesystem_nodev:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^.*nodev.*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_nodev_etc_fstab_cd_dvd_drive:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^.*,?nodev,?.*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_nodev_etc_fstab_not_cd_dvd_drive:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^.*,?nodev,?.*</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_remote_filesystem_noexec:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^.*noexec.*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_noexec_etc_fstab_cd_dvd_drive:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^.*,?noexec,?.*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_noexec_etc_fstab_not_cd_dvd_drive:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^.*,?noexec,?.*</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_remote_filesystem_nosuid:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^.*nosuid.*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_nosuid_etc_fstab_cd_dvd_drive:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^.*,?nosuid,?.*$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_nosuid_etc_fstab_not_cd_dvd_drive:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^.*,?nosuid,?.*</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_opt_partition_nosuid_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nosuid</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_opt_partition_nosuid_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nosuid</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_proc_partition_hidepid_expected:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals" var_ref="oval:ssg-local_var_mountoption_hidepid_with_value:var:1"/>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_proc_partition_hidepid_expected_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match" var_ref="oval:ssg-local_var_mountoption_hidepid_with_value:var:1"/>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_srv_partition_nosuid_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nosuid</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_srv_partition_nosuid_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nosuid</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_tmp_partition_nodev_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nodev</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_tmp_partition_nodev_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nodev</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_tmp_partition_noexec_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">noexec</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_tmp_partition_noexec_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">noexec</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_tmp_partition_nosuid_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nosuid</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_tmp_partition_nosuid_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nosuid</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_var_log_audit_partition_nodev_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nodev</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_var_log_audit_partition_nodev_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nodev</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_var_log_audit_partition_noexec_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">noexec</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_var_log_audit_partition_noexec_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">noexec</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_var_log_audit_partition_nosuid_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nosuid</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_var_log_audit_partition_nosuid_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nosuid</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_var_log_partition_nodev_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nodev</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_var_log_partition_nodev_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nodev</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_var_log_partition_noexec_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">noexec</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_var_log_partition_noexec_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">noexec</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_var_log_partition_nosuid_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nosuid</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_var_log_partition_nosuid_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nosuid</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_var_partition_nodev_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nodev</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_var_partition_nodev_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nodev</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_var_partition_noexec_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">noexec</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_var_partition_noexec_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">noexec</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_var_partition_nosuid_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nosuid</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_var_partition_nosuid_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nosuid</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_var_tmp_partition_nodev_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nodev</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_var_tmp_partition_nodev_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nodev</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_var_tmp_partition_noexec_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">noexec</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_var_tmp_partition_noexec_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">noexec</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:partition_state id="oval:ssg-state_var_tmp_partition_nosuid_optional:ste:1" operator="AND" version="1">
          <linux:mount_options datatype="string" entity_check="at least one" operation="equals">nosuid</linux:mount_options>
        </linux:partition_state>
        <ind:textfilecontent54_state id="oval:ssg-state_var_tmp_partition_nosuid_optional_in_fstab:ste:1" operator="AND" version="1">
          <ind:instance datatype="int">1</ind:instance>
          <ind:subexpression entity_check="at least one" operation="pattern match">nosuid</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_file_groupownerroot_permissions_syslibrary_files_0_0:ste:1" operator="AND" version="1">
          <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownerroot_permissions_syslibrary_files_0_gid:var:1"/>
        </unix:file_state>
        <ind:textfilecontent54_state comment="ignore" id="oval:ssg-state_rsyslog_files_groupownership_ignore_include_paths:ste:1" operator="AND" version="1">
          <ind:text operation="pattern match">(?:include\([\n\s]*\b[Ff]ile="[^\s;]+"|\$IncludeConfig[\s]+[^\s;]+|^\s+\b[Ff]ile="|\/dev\/.*)</ind:text>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_rsyslog_files_groupownership:ste:1" operator="AND" version="1">
          <unix:type operation="equals">regular</unix:type>
          <unix:group_id datatype="int" var_ref="oval:ssg-var_rsyslog_files_groupownership_groupowner_gid:var:1"/>
        </unix:file_state>
        <ind:textfilecontent54_state comment="ignore" id="oval:ssg-state_rsyslog_files_ownership_ignore_include_paths:ste:1" operator="AND" version="1">
          <ind:text operation="pattern match">(?:include\([\n\s]*\b[Ff]ile="[^\s;]+"|\$IncludeConfig[\s]+[^\s;]+|^\s+\b[Ff]ile="|\/dev\/.*)</ind:text>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_rsyslog_files_ownership:ste:1" operator="AND" version="1">
          <unix:type operation="equals">regular</unix:type>
          <unix:user_id datatype="int" var_ref="oval:ssg-var_rsyslog_files_ownership_owner_uid:var:1"/>
        </unix:file_state>
        <ind:textfilecontent54_state comment="ignore" id="oval:ssg-state_rsyslog_files_permissions_ignore_include_paths:ste:1" operator="AND" version="1">
          <ind:text operation="pattern match">(?:include\([\n\s]*\b[Ff]ile="[^\s;]+"|\$IncludeConfig[\s]+[^\s;]+|^\s+\b[Ff]ile="|\/dev\/.*)</ind:text>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_rsyslog_files_permissions:ste:1" operator="AND" version="1">
          <unix:type operation="equals">regular</unix:type>
          <unix:suid datatype="boolean">false</unix:suid>
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uexec datatype="boolean">false</unix:uexec>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:gexec datatype="boolean">false</unix:gexec>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_abrt_anon_write:ste:1" operator="AND" version="1">
          <linux:name>abrt_anon_write</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_abrt_anon_write:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_abrt_anon_write:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_abrt_handle_event:ste:1" operator="AND" version="1">
          <linux:name>abrt_handle_event</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_abrt_handle_event:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_abrt_handle_event:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_abrt_upload_watch_anon_write:ste:1" operator="AND" version="1">
          <linux:name>abrt_upload_watch_anon_write</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_abrt_upload_watch_anon_write:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_abrt_upload_watch_anon_write:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_antivirus_can_scan_system:ste:1" operator="AND" version="1">
          <linux:name>antivirus_can_scan_system</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_antivirus_can_scan_system:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_antivirus_can_scan_system:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_antivirus_use_jit:ste:1" operator="AND" version="1">
          <linux:name>antivirus_use_jit</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_antivirus_use_jit:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_antivirus_use_jit:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_auditadm_exec_content:ste:1" operator="AND" version="1">
          <linux:name>auditadm_exec_content</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_auditadm_exec_content:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_auditadm_exec_content:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_authlogin_nsswitch_use_ldap:ste:1" operator="AND" version="1">
          <linux:name>authlogin_nsswitch_use_ldap</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_authlogin_nsswitch_use_ldap:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_authlogin_nsswitch_use_ldap:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_authlogin_radius:ste:1" operator="AND" version="1">
          <linux:name>authlogin_radius</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_authlogin_radius:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_authlogin_radius:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_authlogin_yubikey:ste:1" operator="AND" version="1">
          <linux:name>authlogin_yubikey</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_authlogin_yubikey:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_authlogin_yubikey:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_awstats_purge_apache_log_files:ste:1" operator="AND" version="1">
          <linux:name>awstats_purge_apache_log_files</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_awstats_purge_apache_log_files:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_awstats_purge_apache_log_files:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_boinc_execmem:ste:1" operator="AND" version="1">
          <linux:name>boinc_execmem</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_boinc_execmem:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_boinc_execmem:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_cdrecord_read_content:ste:1" operator="AND" version="1">
          <linux:name>cdrecord_read_content</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_cdrecord_read_content:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_cdrecord_read_content:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_cluster_can_network_connect:ste:1" operator="AND" version="1">
          <linux:name>cluster_can_network_connect</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_cluster_can_network_connect:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_cluster_can_network_connect:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_cluster_manage_all_files:ste:1" operator="AND" version="1">
          <linux:name>cluster_manage_all_files</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_cluster_manage_all_files:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_cluster_manage_all_files:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_cluster_use_execmem:ste:1" operator="AND" version="1">
          <linux:name>cluster_use_execmem</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_cluster_use_execmem:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_cluster_use_execmem:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_cobbler_anon_write:ste:1" operator="AND" version="1">
          <linux:name>cobbler_anon_write</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_cobbler_anon_write:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_cobbler_anon_write:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_cobbler_can_network_connect:ste:1" operator="AND" version="1">
          <linux:name>cobbler_can_network_connect</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_cobbler_can_network_connect:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_cobbler_can_network_connect:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_cobbler_use_cifs:ste:1" operator="AND" version="1">
          <linux:name>cobbler_use_cifs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_cobbler_use_cifs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_cobbler_use_cifs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_cobbler_use_nfs:ste:1" operator="AND" version="1">
          <linux:name>cobbler_use_nfs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_cobbler_use_nfs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_cobbler_use_nfs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_collectd_tcp_network_connect:ste:1" operator="AND" version="1">
          <linux:name>collectd_tcp_network_connect</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_collectd_tcp_network_connect:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_collectd_tcp_network_connect:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_condor_tcp_network_connect:ste:1" operator="AND" version="1">
          <linux:name>condor_tcp_network_connect</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_condor_tcp_network_connect:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_condor_tcp_network_connect:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_conman_can_network:ste:1" operator="AND" version="1">
          <linux:name>conman_can_network</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_conman_can_network:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_conman_can_network:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_container_connect_any:ste:1" operator="AND" version="1">
          <linux:name>container_connect_any</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_container_connect_any:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_container_connect_any:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_cron_can_relabel:ste:1" operator="AND" version="1">
          <linux:name>cron_can_relabel</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_cron_can_relabel:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_cron_can_relabel:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_cron_system_cronjob_use_shares:ste:1" operator="AND" version="1">
          <linux:name>cron_system_cronjob_use_shares</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_cron_system_cronjob_use_shares:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_cron_system_cronjob_use_shares:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_cron_userdomain_transition:ste:1" operator="AND" version="1">
          <linux:name>cron_userdomain_transition</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_cron_userdomain_transition:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_cron_userdomain_transition:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_cups_execmem:ste:1" operator="AND" version="1">
          <linux:name>cups_execmem</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_cups_execmem:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_cups_execmem:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_cvs_read_shadow:ste:1" operator="AND" version="1">
          <linux:name>cvs_read_shadow</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_cvs_read_shadow:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_cvs_read_shadow:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_daemons_dump_core:ste:1" operator="AND" version="1">
          <linux:name>daemons_dump_core</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_daemons_dump_core:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_daemons_dump_core:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_daemons_enable_cluster_mode:ste:1" operator="AND" version="1">
          <linux:name>daemons_enable_cluster_mode</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_daemons_enable_cluster_mode:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_daemons_enable_cluster_mode:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_daemons_use_tcp_wrapper:ste:1" operator="AND" version="1">
          <linux:name>daemons_use_tcp_wrapper</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_daemons_use_tcp_wrapper:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_daemons_use_tcp_wrapper:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_daemons_use_tty:ste:1" operator="AND" version="1">
          <linux:name>daemons_use_tty</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_daemons_use_tty:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_daemons_use_tty:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_dbadm_exec_content:ste:1" operator="AND" version="1">
          <linux:name>dbadm_exec_content</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_dbadm_exec_content:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_dbadm_exec_content:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_dbadm_manage_user_files:ste:1" operator="AND" version="1">
          <linux:name>dbadm_manage_user_files</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_dbadm_manage_user_files:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_dbadm_manage_user_files:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_dbadm_read_user_files:ste:1" operator="AND" version="1">
          <linux:name>dbadm_read_user_files</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_dbadm_read_user_files:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_dbadm_read_user_files:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_deny_execmem:ste:1" operator="AND" version="1">
          <linux:name>deny_execmem</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_deny_execmem:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_deny_execmem:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_deny_ptrace:ste:1" operator="AND" version="1">
          <linux:name>deny_ptrace</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_deny_ptrace:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_deny_ptrace:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_dhcpc_exec_iptables:ste:1" operator="AND" version="1">
          <linux:name>dhcpc_exec_iptables</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_dhcpc_exec_iptables:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_dhcpc_exec_iptables:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_dhcpd_use_ldap:ste:1" operator="AND" version="1">
          <linux:name>dhcpd_use_ldap</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_dhcpd_use_ldap:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_dhcpd_use_ldap:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_domain_fd_use:ste:1" operator="AND" version="1">
          <linux:name>domain_fd_use</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_domain_fd_use:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_domain_fd_use:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_domain_kernel_load_modules:ste:1" operator="AND" version="1">
          <linux:name>domain_kernel_load_modules</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_domain_kernel_load_modules:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_domain_kernel_load_modules:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_entropyd_use_audio:ste:1" operator="AND" version="1">
          <linux:name>entropyd_use_audio</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_entropyd_use_audio:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_entropyd_use_audio:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_exim_can_connect_db:ste:1" operator="AND" version="1">
          <linux:name>exim_can_connect_db</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_exim_can_connect_db:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_exim_can_connect_db:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_exim_manage_user_files:ste:1" operator="AND" version="1">
          <linux:name>exim_manage_user_files</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_exim_manage_user_files:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_exim_manage_user_files:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_exim_read_user_files:ste:1" operator="AND" version="1">
          <linux:name>exim_read_user_files</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_exim_read_user_files:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_exim_read_user_files:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_fcron_crond:ste:1" operator="AND" version="1">
          <linux:name>fcron_crond</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_fcron_crond:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_fcron_crond:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_fenced_can_network_connect:ste:1" operator="AND" version="1">
          <linux:name>fenced_can_network_connect</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_fenced_can_network_connect:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_fenced_can_network_connect:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_fenced_can_ssh:ste:1" operator="AND" version="1">
          <linux:name>fenced_can_ssh</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_fenced_can_ssh:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_fenced_can_ssh:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_fips_mode:ste:1" operator="AND" version="1">
          <linux:name>fips_mode</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_fips_mode:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_fips_mode:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_ftpd_anon_write:ste:1" operator="AND" version="1">
          <linux:name>ftpd_anon_write</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_ftpd_anon_write:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_ftpd_anon_write:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_ftpd_connect_all_unreserved:ste:1" operator="AND" version="1">
          <linux:name>ftpd_connect_all_unreserved</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_ftpd_connect_all_unreserved:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_ftpd_connect_all_unreserved:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_ftpd_connect_db:ste:1" operator="AND" version="1">
          <linux:name>ftpd_connect_db</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_ftpd_connect_db:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_ftpd_connect_db:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_ftpd_full_access:ste:1" operator="AND" version="1">
          <linux:name>ftpd_full_access</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_ftpd_full_access:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_ftpd_full_access:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_ftpd_use_cifs:ste:1" operator="AND" version="1">
          <linux:name>ftpd_use_cifs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_ftpd_use_cifs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_ftpd_use_cifs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_ftpd_use_fusefs:ste:1" operator="AND" version="1">
          <linux:name>ftpd_use_fusefs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_ftpd_use_fusefs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_ftpd_use_fusefs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_ftpd_use_nfs:ste:1" operator="AND" version="1">
          <linux:name>ftpd_use_nfs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_ftpd_use_nfs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_ftpd_use_nfs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_ftpd_use_passive_mode:ste:1" operator="AND" version="1">
          <linux:name>ftpd_use_passive_mode</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_ftpd_use_passive_mode:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_ftpd_use_passive_mode:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_git_cgi_enable_homedirs:ste:1" operator="AND" version="1">
          <linux:name>git_cgi_enable_homedirs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_git_cgi_enable_homedirs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_git_cgi_enable_homedirs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_git_cgi_use_cifs:ste:1" operator="AND" version="1">
          <linux:name>git_cgi_use_cifs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_git_cgi_use_cifs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_git_cgi_use_cifs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_git_cgi_use_nfs:ste:1" operator="AND" version="1">
          <linux:name>git_cgi_use_nfs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_git_cgi_use_nfs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_git_cgi_use_nfs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_git_session_bind_all_unreserved_ports:ste:1" operator="AND" version="1">
          <linux:name>git_session_bind_all_unreserved_ports</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_git_session_bind_all_unreserved_ports:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_git_session_bind_all_unreserved_ports:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_git_session_users:ste:1" operator="AND" version="1">
          <linux:name>git_session_users</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_git_session_users:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_git_session_users:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_git_system_enable_homedirs:ste:1" operator="AND" version="1">
          <linux:name>git_system_enable_homedirs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_git_system_enable_homedirs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_git_system_enable_homedirs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_git_system_use_cifs:ste:1" operator="AND" version="1">
          <linux:name>git_system_use_cifs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_git_system_use_cifs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_git_system_use_cifs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_git_system_use_nfs:ste:1" operator="AND" version="1">
          <linux:name>git_system_use_nfs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_git_system_use_nfs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_git_system_use_nfs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_gitosis_can_sendmail:ste:1" operator="AND" version="1">
          <linux:name>gitosis_can_sendmail</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_gitosis_can_sendmail:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_gitosis_can_sendmail:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_glance_api_can_network:ste:1" operator="AND" version="1">
          <linux:name>glance_api_can_network</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_glance_api_can_network:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_glance_api_can_network:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_glance_use_execmem:ste:1" operator="AND" version="1">
          <linux:name>glance_use_execmem</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_glance_use_execmem:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_glance_use_execmem:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_glance_use_fusefs:ste:1" operator="AND" version="1">
          <linux:name>glance_use_fusefs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_glance_use_fusefs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_glance_use_fusefs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_global_ssp:ste:1" operator="AND" version="1">
          <linux:name>global_ssp</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_global_ssp:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_global_ssp:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_gluster_anon_write:ste:1" operator="AND" version="1">
          <linux:name>gluster_anon_write</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_gluster_anon_write:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_gluster_anon_write:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_gluster_export_all_ro:ste:1" operator="AND" version="1">
          <linux:name>gluster_export_all_ro</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_gluster_export_all_ro:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_gluster_export_all_ro:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_gluster_export_all_rw:ste:1" operator="AND" version="1">
          <linux:name>gluster_export_all_rw</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_gluster_export_all_rw:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_gluster_export_all_rw:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_gpg_web_anon_write:ste:1" operator="AND" version="1">
          <linux:name>gpg_web_anon_write</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_gpg_web_anon_write:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_gpg_web_anon_write:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_gssd_read_tmp:ste:1" operator="AND" version="1">
          <linux:name>gssd_read_tmp</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_gssd_read_tmp:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_gssd_read_tmp:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_guest_exec_content:ste:1" operator="AND" version="1">
          <linux:name>guest_exec_content</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_guest_exec_content:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_guest_exec_content:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_haproxy_connect_any:ste:1" operator="AND" version="1">
          <linux:name>haproxy_connect_any</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_haproxy_connect_any:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_haproxy_connect_any:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_anon_write:ste:1" operator="AND" version="1">
          <linux:name>httpd_anon_write</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_anon_write:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_anon_write:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_builtin_scripting:ste:1" operator="AND" version="1">
          <linux:name>httpd_builtin_scripting</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_builtin_scripting:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_builtin_scripting:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_can_check_spam:ste:1" operator="AND" version="1">
          <linux:name>httpd_can_check_spam</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_check_spam:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_check_spam:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_can_connect_ftp:ste:1" operator="AND" version="1">
          <linux:name>httpd_can_connect_ftp</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_connect_ftp:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_connect_ftp:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_can_connect_ldap:ste:1" operator="AND" version="1">
          <linux:name>httpd_can_connect_ldap</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_connect_ldap:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_connect_ldap:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_can_connect_mythtv:ste:1" operator="AND" version="1">
          <linux:name>httpd_can_connect_mythtv</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_connect_mythtv:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_connect_mythtv:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_can_connect_zabbix:ste:1" operator="AND" version="1">
          <linux:name>httpd_can_connect_zabbix</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_connect_zabbix:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_connect_zabbix:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_can_network_connect:ste:1" operator="AND" version="1">
          <linux:name>httpd_can_network_connect</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_network_connect:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_network_connect:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_can_network_connect_cobbler:ste:1" operator="AND" version="1">
          <linux:name>httpd_can_network_connect_cobbler</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_network_connect_cobbler:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_network_connect_cobbler:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_can_network_connect_db:ste:1" operator="AND" version="1">
          <linux:name>httpd_can_network_connect_db</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_network_connect_db:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_network_connect_db:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_can_network_memcache:ste:1" operator="AND" version="1">
          <linux:name>httpd_can_network_memcache</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_network_memcache:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_network_memcache:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_can_network_relay:ste:1" operator="AND" version="1">
          <linux:name>httpd_can_network_relay</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_network_relay:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_network_relay:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_can_sendmail:ste:1" operator="AND" version="1">
          <linux:name>httpd_can_sendmail</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_sendmail:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_can_sendmail:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_dbus_avahi:ste:1" operator="AND" version="1">
          <linux:name>httpd_dbus_avahi</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_dbus_avahi:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_dbus_avahi:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_dbus_sssd:ste:1" operator="AND" version="1">
          <linux:name>httpd_dbus_sssd</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_dbus_sssd:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_dbus_sssd:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_dontaudit_search_dirs:ste:1" operator="AND" version="1">
          <linux:name>httpd_dontaudit_search_dirs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_dontaudit_search_dirs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_dontaudit_search_dirs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_enable_cgi:ste:1" operator="AND" version="1">
          <linux:name>httpd_enable_cgi</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_enable_cgi:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_enable_cgi:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_enable_ftp_server:ste:1" operator="AND" version="1">
          <linux:name>httpd_enable_ftp_server</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_enable_ftp_server:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_enable_ftp_server:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_enable_homedirs:ste:1" operator="AND" version="1">
          <linux:name>httpd_enable_homedirs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_enable_homedirs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_enable_homedirs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_execmem:ste:1" operator="AND" version="1">
          <linux:name>httpd_execmem</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_execmem:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_execmem:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_graceful_shutdown:ste:1" operator="AND" version="1">
          <linux:name>httpd_graceful_shutdown</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_graceful_shutdown:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_graceful_shutdown:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_manage_ipa:ste:1" operator="AND" version="1">
          <linux:name>httpd_manage_ipa</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_manage_ipa:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_manage_ipa:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_mod_auth_ntlm_winbind:ste:1" operator="AND" version="1">
          <linux:name>httpd_mod_auth_ntlm_winbind</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_mod_auth_ntlm_winbind:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_mod_auth_ntlm_winbind:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_mod_auth_pam:ste:1" operator="AND" version="1">
          <linux:name>httpd_mod_auth_pam</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_mod_auth_pam:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_mod_auth_pam:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_read_user_content:ste:1" operator="AND" version="1">
          <linux:name>httpd_read_user_content</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_read_user_content:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_read_user_content:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_run_ipa:ste:1" operator="AND" version="1">
          <linux:name>httpd_run_ipa</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_run_ipa:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_run_ipa:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_run_preupgrade:ste:1" operator="AND" version="1">
          <linux:name>httpd_run_preupgrade</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_run_preupgrade:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_run_preupgrade:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_run_stickshift:ste:1" operator="AND" version="1">
          <linux:name>httpd_run_stickshift</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_run_stickshift:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_run_stickshift:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_serve_cobbler_files:ste:1" operator="AND" version="1">
          <linux:name>httpd_serve_cobbler_files</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_serve_cobbler_files:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_serve_cobbler_files:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_setrlimit:ste:1" operator="AND" version="1">
          <linux:name>httpd_setrlimit</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_setrlimit:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_setrlimit:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_ssi_exec:ste:1" operator="AND" version="1">
          <linux:name>httpd_ssi_exec</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_ssi_exec:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_ssi_exec:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_sys_script_anon_write:ste:1" operator="AND" version="1">
          <linux:name>httpd_sys_script_anon_write</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_sys_script_anon_write:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_sys_script_anon_write:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_tmp_exec:ste:1" operator="AND" version="1">
          <linux:name>httpd_tmp_exec</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_tmp_exec:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_tmp_exec:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_tty_comm:ste:1" operator="AND" version="1">
          <linux:name>httpd_tty_comm</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_tty_comm:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_tty_comm:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_unified:ste:1" operator="AND" version="1">
          <linux:name>httpd_unified</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_unified:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_unified:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_use_cifs:ste:1" operator="AND" version="1">
          <linux:name>httpd_use_cifs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_use_cifs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_use_cifs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_use_fusefs:ste:1" operator="AND" version="1">
          <linux:name>httpd_use_fusefs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_use_fusefs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_use_fusefs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_use_gpg:ste:1" operator="AND" version="1">
          <linux:name>httpd_use_gpg</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_use_gpg:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_use_gpg:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_use_nfs:ste:1" operator="AND" version="1">
          <linux:name>httpd_use_nfs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_use_nfs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_use_nfs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_use_openstack:ste:1" operator="AND" version="1">
          <linux:name>httpd_use_openstack</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_use_openstack:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_use_openstack:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_use_sasl:ste:1" operator="AND" version="1">
          <linux:name>httpd_use_sasl</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_use_sasl:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_use_sasl:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_httpd_verify_dns:ste:1" operator="AND" version="1">
          <linux:name>httpd_verify_dns</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_httpd_verify_dns:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_httpd_verify_dns:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_icecast_use_any_tcp_ports:ste:1" operator="AND" version="1">
          <linux:name>icecast_use_any_tcp_ports</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_icecast_use_any_tcp_ports:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_icecast_use_any_tcp_ports:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_irc_use_any_tcp_ports:ste:1" operator="AND" version="1">
          <linux:name>irc_use_any_tcp_ports</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_irc_use_any_tcp_ports:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_irc_use_any_tcp_ports:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_irssi_use_full_network:ste:1" operator="AND" version="1">
          <linux:name>irssi_use_full_network</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_irssi_use_full_network:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_irssi_use_full_network:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_kdumpgui_run_bootloader:ste:1" operator="AND" version="1">
          <linux:name>kdumpgui_run_bootloader</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_kdumpgui_run_bootloader:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_kdumpgui_run_bootloader:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_kerberos_enabled:ste:1" operator="AND" version="1">
          <linux:name>kerberos_enabled</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_kerberos_enabled:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_kerberos_enabled:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_ksmtuned_use_cifs:ste:1" operator="AND" version="1">
          <linux:name>ksmtuned_use_cifs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_ksmtuned_use_cifs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_ksmtuned_use_cifs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_ksmtuned_use_nfs:ste:1" operator="AND" version="1">
          <linux:name>ksmtuned_use_nfs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_ksmtuned_use_nfs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_ksmtuned_use_nfs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_logadm_exec_content:ste:1" operator="AND" version="1">
          <linux:name>logadm_exec_content</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_logadm_exec_content:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_logadm_exec_content:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_logging_syslogd_can_sendmail:ste:1" operator="AND" version="1">
          <linux:name>logging_syslogd_can_sendmail</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_logging_syslogd_can_sendmail:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_logging_syslogd_can_sendmail:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_logging_syslogd_run_nagios_plugins:ste:1" operator="AND" version="1">
          <linux:name>logging_syslogd_run_nagios_plugins</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_logging_syslogd_run_nagios_plugins:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_logging_syslogd_run_nagios_plugins:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_logging_syslogd_use_tty:ste:1" operator="AND" version="1">
          <linux:name>logging_syslogd_use_tty</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_logging_syslogd_use_tty:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_logging_syslogd_use_tty:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_login_console_enabled:ste:1" operator="AND" version="1">
          <linux:name>login_console_enabled</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_login_console_enabled:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_login_console_enabled:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_logrotate_use_nfs:ste:1" operator="AND" version="1">
          <linux:name>logrotate_use_nfs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_logrotate_use_nfs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_logrotate_use_nfs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_logwatch_can_network_connect_mail:ste:1" operator="AND" version="1">
          <linux:name>logwatch_can_network_connect_mail</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_logwatch_can_network_connect_mail:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_logwatch_can_network_connect_mail:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_lsmd_plugin_connect_any:ste:1" operator="AND" version="1">
          <linux:name>lsmd_plugin_connect_any</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_lsmd_plugin_connect_any:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_lsmd_plugin_connect_any:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mailman_use_fusefs:ste:1" operator="AND" version="1">
          <linux:name>mailman_use_fusefs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mailman_use_fusefs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mailman_use_fusefs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mcelog_client:ste:1" operator="AND" version="1">
          <linux:name>mcelog_client</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mcelog_client:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mcelog_client:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mcelog_exec_scripts:ste:1" operator="AND" version="1">
          <linux:name>mcelog_exec_scripts</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mcelog_exec_scripts:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mcelog_exec_scripts:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mcelog_foreground:ste:1" operator="AND" version="1">
          <linux:name>mcelog_foreground</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mcelog_foreground:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mcelog_foreground:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mcelog_server:ste:1" operator="AND" version="1">
          <linux:name>mcelog_server</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mcelog_server:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mcelog_server:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_minidlna_read_generic_user_content:ste:1" operator="AND" version="1">
          <linux:name>minidlna_read_generic_user_content</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_minidlna_read_generic_user_content:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_minidlna_read_generic_user_content:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mmap_low_allowed:ste:1" operator="AND" version="1">
          <linux:name>mmap_low_allowed</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mmap_low_allowed:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mmap_low_allowed:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mock_enable_homedirs:ste:1" operator="AND" version="1">
          <linux:name>mock_enable_homedirs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mock_enable_homedirs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mock_enable_homedirs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mount_anyfile:ste:1" operator="AND" version="1">
          <linux:name>mount_anyfile</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mount_anyfile:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mount_anyfile:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mozilla_plugin_bind_unreserved_ports:ste:1" operator="AND" version="1">
          <linux:name>mozilla_plugin_bind_unreserved_ports</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mozilla_plugin_bind_unreserved_ports:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mozilla_plugin_bind_unreserved_ports:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mozilla_plugin_can_network_connect:ste:1" operator="AND" version="1">
          <linux:name>mozilla_plugin_can_network_connect</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mozilla_plugin_can_network_connect:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mozilla_plugin_can_network_connect:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mozilla_plugin_use_bluejeans:ste:1" operator="AND" version="1">
          <linux:name>mozilla_plugin_use_bluejeans</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mozilla_plugin_use_bluejeans:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mozilla_plugin_use_bluejeans:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mozilla_plugin_use_gps:ste:1" operator="AND" version="1">
          <linux:name>mozilla_plugin_use_gps</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mozilla_plugin_use_gps:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mozilla_plugin_use_gps:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mozilla_plugin_use_spice:ste:1" operator="AND" version="1">
          <linux:name>mozilla_plugin_use_spice</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mozilla_plugin_use_spice:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mozilla_plugin_use_spice:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mozilla_read_content:ste:1" operator="AND" version="1">
          <linux:name>mozilla_read_content</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mozilla_read_content:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mozilla_read_content:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mpd_enable_homedirs:ste:1" operator="AND" version="1">
          <linux:name>mpd_enable_homedirs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mpd_enable_homedirs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mpd_enable_homedirs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mpd_use_cifs:ste:1" operator="AND" version="1">
          <linux:name>mpd_use_cifs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mpd_use_cifs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mpd_use_cifs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mpd_use_nfs:ste:1" operator="AND" version="1">
          <linux:name>mpd_use_nfs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mpd_use_nfs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mpd_use_nfs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mplayer_execstack:ste:1" operator="AND" version="1">
          <linux:name>mplayer_execstack</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mplayer_execstack:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mplayer_execstack:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_mysql_connect_any:ste:1" operator="AND" version="1">
          <linux:name>mysql_connect_any</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_mysql_connect_any:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_mysql_connect_any:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_nagios_run_pnp4nagios:ste:1" operator="AND" version="1">
          <linux:name>nagios_run_pnp4nagios</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_nagios_run_pnp4nagios:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_nagios_run_pnp4nagios:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_nagios_run_sudo:ste:1" operator="AND" version="1">
          <linux:name>nagios_run_sudo</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_nagios_run_sudo:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_nagios_run_sudo:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_named_tcp_bind_http_port:ste:1" operator="AND" version="1">
          <linux:name>named_tcp_bind_http_port</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_named_tcp_bind_http_port:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_named_tcp_bind_http_port:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_named_write_master_zones:ste:1" operator="AND" version="1">
          <linux:name>named_write_master_zones</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_named_write_master_zones:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_named_write_master_zones:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_neutron_can_network:ste:1" operator="AND" version="1">
          <linux:name>neutron_can_network</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_neutron_can_network:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_neutron_can_network:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_nfs_export_all_ro:ste:1" operator="AND" version="1">
          <linux:name>nfs_export_all_ro</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_nfs_export_all_ro:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_nfs_export_all_ro:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_nfs_export_all_rw:ste:1" operator="AND" version="1">
          <linux:name>nfs_export_all_rw</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_nfs_export_all_rw:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_nfs_export_all_rw:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_nfsd_anon_write:ste:1" operator="AND" version="1">
          <linux:name>nfsd_anon_write</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_nfsd_anon_write:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_nfsd_anon_write:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_nis_enabled:ste:1" operator="AND" version="1">
          <linux:name>nis_enabled</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_nis_enabled:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_nis_enabled:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_nscd_use_shm:ste:1" operator="AND" version="1">
          <linux:name>nscd_use_shm</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_nscd_use_shm:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_nscd_use_shm:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_openshift_use_nfs:ste:1" operator="AND" version="1">
          <linux:name>openshift_use_nfs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_openshift_use_nfs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_openshift_use_nfs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_openvpn_can_network_connect:ste:1" operator="AND" version="1">
          <linux:name>openvpn_can_network_connect</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_openvpn_can_network_connect:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_openvpn_can_network_connect:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_openvpn_enable_homedirs:ste:1" operator="AND" version="1">
          <linux:name>openvpn_enable_homedirs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_openvpn_enable_homedirs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_openvpn_enable_homedirs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_openvpn_run_unconfined:ste:1" operator="AND" version="1">
          <linux:name>openvpn_run_unconfined</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_openvpn_run_unconfined:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_openvpn_run_unconfined:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_pcp_bind_all_unreserved_ports:ste:1" operator="AND" version="1">
          <linux:name>pcp_bind_all_unreserved_ports</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_pcp_bind_all_unreserved_ports:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_pcp_bind_all_unreserved_ports:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_pcp_read_generic_logs:ste:1" operator="AND" version="1">
          <linux:name>pcp_read_generic_logs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_pcp_read_generic_logs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_pcp_read_generic_logs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_piranha_lvs_can_network_connect:ste:1" operator="AND" version="1">
          <linux:name>piranha_lvs_can_network_connect</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_piranha_lvs_can_network_connect:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_piranha_lvs_can_network_connect:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_polipo_connect_all_unreserved:ste:1" operator="AND" version="1">
          <linux:name>polipo_connect_all_unreserved</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_polipo_connect_all_unreserved:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_polipo_connect_all_unreserved:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_polipo_session_bind_all_unreserved_ports:ste:1" operator="AND" version="1">
          <linux:name>polipo_session_bind_all_unreserved_ports</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_polipo_session_bind_all_unreserved_ports:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_polipo_session_bind_all_unreserved_ports:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_polipo_session_users:ste:1" operator="AND" version="1">
          <linux:name>polipo_session_users</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_polipo_session_users:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_polipo_session_users:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_polipo_use_cifs:ste:1" operator="AND" version="1">
          <linux:name>polipo_use_cifs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_polipo_use_cifs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_polipo_use_cifs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_polipo_use_nfs:ste:1" operator="AND" version="1">
          <linux:name>polipo_use_nfs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_polipo_use_nfs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_polipo_use_nfs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_polyinstantiation_enabled:ste:1" operator="AND" version="1">
          <linux:name>polyinstantiation_enabled</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_polyinstantiation_enabled:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_polyinstantiation_enabled:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_postfix_local_write_mail_spool:ste:1" operator="AND" version="1">
          <linux:name>postfix_local_write_mail_spool</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_postfix_local_write_mail_spool:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_postfix_local_write_mail_spool:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_postgresql_can_rsync:ste:1" operator="AND" version="1">
          <linux:name>postgresql_can_rsync</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_postgresql_can_rsync:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_postgresql_can_rsync:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_postgresql_selinux_transmit_client_label:ste:1" operator="AND" version="1">
          <linux:name>postgresql_selinux_transmit_client_label</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_postgresql_selinux_transmit_client_label:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_postgresql_selinux_transmit_client_label:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_postgresql_selinux_unconfined_dbadm:ste:1" operator="AND" version="1">
          <linux:name>postgresql_selinux_unconfined_dbadm</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_postgresql_selinux_unconfined_dbadm:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_postgresql_selinux_unconfined_dbadm:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_postgresql_selinux_users_ddl:ste:1" operator="AND" version="1">
          <linux:name>postgresql_selinux_users_ddl</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_postgresql_selinux_users_ddl:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_postgresql_selinux_users_ddl:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_pppd_can_insmod:ste:1" operator="AND" version="1">
          <linux:name>pppd_can_insmod</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_pppd_can_insmod:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_pppd_can_insmod:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_pppd_for_user:ste:1" operator="AND" version="1">
          <linux:name>pppd_for_user</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_pppd_for_user:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_pppd_for_user:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_privoxy_connect_any:ste:1" operator="AND" version="1">
          <linux:name>privoxy_connect_any</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_privoxy_connect_any:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_privoxy_connect_any:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_prosody_bind_http_port:ste:1" operator="AND" version="1">
          <linux:name>prosody_bind_http_port</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_prosody_bind_http_port:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_prosody_bind_http_port:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_puppetagent_manage_all_files:ste:1" operator="AND" version="1">
          <linux:name>puppetagent_manage_all_files</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_puppetagent_manage_all_files:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_puppetagent_manage_all_files:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_puppetmaster_use_db:ste:1" operator="AND" version="1">
          <linux:name>puppetmaster_use_db</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_puppetmaster_use_db:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_puppetmaster_use_db:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_racoon_read_shadow:ste:1" operator="AND" version="1">
          <linux:name>racoon_read_shadow</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_racoon_read_shadow:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_racoon_read_shadow:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_rsync_anon_write:ste:1" operator="AND" version="1">
          <linux:name>rsync_anon_write</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_rsync_anon_write:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_rsync_anon_write:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_rsync_client:ste:1" operator="AND" version="1">
          <linux:name>rsync_client</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_rsync_client:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_rsync_client:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_rsync_export_all_ro:ste:1" operator="AND" version="1">
          <linux:name>rsync_export_all_ro</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_rsync_export_all_ro:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_rsync_export_all_ro:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_rsync_full_access:ste:1" operator="AND" version="1">
          <linux:name>rsync_full_access</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_rsync_full_access:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_rsync_full_access:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_samba_create_home_dirs:ste:1" operator="AND" version="1">
          <linux:name>samba_create_home_dirs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_samba_create_home_dirs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_samba_create_home_dirs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_samba_domain_controller:ste:1" operator="AND" version="1">
          <linux:name>samba_domain_controller</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_samba_domain_controller:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_samba_domain_controller:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_samba_enable_home_dirs:ste:1" operator="AND" version="1">
          <linux:name>samba_enable_home_dirs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_samba_enable_home_dirs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_samba_enable_home_dirs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_samba_export_all_ro:ste:1" operator="AND" version="1">
          <linux:name>samba_export_all_ro</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_samba_export_all_ro:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_samba_export_all_ro:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_samba_export_all_rw:ste:1" operator="AND" version="1">
          <linux:name>samba_export_all_rw</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_samba_export_all_rw:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_samba_export_all_rw:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_samba_load_libgfapi:ste:1" operator="AND" version="1">
          <linux:name>samba_load_libgfapi</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_samba_load_libgfapi:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_samba_load_libgfapi:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_samba_portmapper:ste:1" operator="AND" version="1">
          <linux:name>samba_portmapper</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_samba_portmapper:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_samba_portmapper:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_samba_run_unconfined:ste:1" operator="AND" version="1">
          <linux:name>samba_run_unconfined</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_samba_run_unconfined:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_samba_run_unconfined:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_samba_share_fusefs:ste:1" operator="AND" version="1">
          <linux:name>samba_share_fusefs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_samba_share_fusefs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_samba_share_fusefs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_samba_share_nfs:ste:1" operator="AND" version="1">
          <linux:name>samba_share_nfs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_samba_share_nfs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_samba_share_nfs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_sanlock_use_fusefs:ste:1" operator="AND" version="1">
          <linux:name>sanlock_use_fusefs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_sanlock_use_fusefs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_sanlock_use_fusefs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_sanlock_use_nfs:ste:1" operator="AND" version="1">
          <linux:name>sanlock_use_nfs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_sanlock_use_nfs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_sanlock_use_nfs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_sanlock_use_samba:ste:1" operator="AND" version="1">
          <linux:name>sanlock_use_samba</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_sanlock_use_samba:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_sanlock_use_samba:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_saslauthd_read_shadow:ste:1" operator="AND" version="1">
          <linux:name>saslauthd_read_shadow</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_saslauthd_read_shadow:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_saslauthd_read_shadow:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_secadm_exec_content:ste:1" operator="AND" version="1">
          <linux:name>secadm_exec_content</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_secadm_exec_content:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_secadm_exec_content:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_secure_mode:ste:1" operator="AND" version="1">
          <linux:name>secure_mode</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_secure_mode:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_secure_mode:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_secure_mode_insmod:ste:1" operator="AND" version="1">
          <linux:name>secure_mode_insmod</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_secure_mode_insmod:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_secure_mode_insmod:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_secure_mode_policyload:ste:1" operator="AND" version="1">
          <linux:name>secure_mode_policyload</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_secure_mode_policyload:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_secure_mode_policyload:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_selinuxuser_direct_dri_enabled:ste:1" operator="AND" version="1">
          <linux:name>selinuxuser_direct_dri_enabled</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_direct_dri_enabled:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_direct_dri_enabled:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_selinuxuser_execheap:ste:1" operator="AND" version="1">
          <linux:name>selinuxuser_execheap</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_execheap:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_execheap:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_selinuxuser_execmod:ste:1" operator="AND" version="1">
          <linux:name>selinuxuser_execmod</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_execmod:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_execmod:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_selinuxuser_execstack:ste:1" operator="AND" version="1">
          <linux:name>selinuxuser_execstack</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_execstack:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_execstack:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_selinuxuser_mysql_connect_enabled:ste:1" operator="AND" version="1">
          <linux:name>selinuxuser_mysql_connect_enabled</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_mysql_connect_enabled:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_mysql_connect_enabled:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_selinuxuser_ping:ste:1" operator="AND" version="1">
          <linux:name>selinuxuser_ping</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_ping:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_ping:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_selinuxuser_postgresql_connect_enabled:ste:1" operator="AND" version="1">
          <linux:name>selinuxuser_postgresql_connect_enabled</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_postgresql_connect_enabled:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_postgresql_connect_enabled:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_selinuxuser_rw_noexattrfile:ste:1" operator="AND" version="1">
          <linux:name>selinuxuser_rw_noexattrfile</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_rw_noexattrfile:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_rw_noexattrfile:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_selinuxuser_share_music:ste:1" operator="AND" version="1">
          <linux:name>selinuxuser_share_music</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_share_music:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_share_music:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_selinuxuser_tcp_server:ste:1" operator="AND" version="1">
          <linux:name>selinuxuser_tcp_server</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_tcp_server:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_tcp_server:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_selinuxuser_udp_server:ste:1" operator="AND" version="1">
          <linux:name>selinuxuser_udp_server</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_udp_server:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_udp_server:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_selinuxuser_use_ssh_chroot:ste:1" operator="AND" version="1">
          <linux:name>selinuxuser_use_ssh_chroot</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_use_ssh_chroot:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_selinuxuser_use_ssh_chroot:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_sge_domain_can_network_connect:ste:1" operator="AND" version="1">
          <linux:name>sge_domain_can_network_connect</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_sge_domain_can_network_connect:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_sge_domain_can_network_connect:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_sge_use_nfs:ste:1" operator="AND" version="1">
          <linux:name>sge_use_nfs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_sge_use_nfs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_sge_use_nfs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_smartmon_3ware:ste:1" operator="AND" version="1">
          <linux:name>smartmon_3ware</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_smartmon_3ware:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_smartmon_3ware:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_smbd_anon_write:ste:1" operator="AND" version="1">
          <linux:name>smbd_anon_write</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_smbd_anon_write:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_smbd_anon_write:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_spamassassin_can_network:ste:1" operator="AND" version="1">
          <linux:name>spamassassin_can_network</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_spamassassin_can_network:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_spamassassin_can_network:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_spamd_enable_home_dirs:ste:1" operator="AND" version="1">
          <linux:name>spamd_enable_home_dirs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_spamd_enable_home_dirs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_spamd_enable_home_dirs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_squid_connect_any:ste:1" operator="AND" version="1">
          <linux:name>squid_connect_any</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_squid_connect_any:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_squid_connect_any:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_squid_use_tproxy:ste:1" operator="AND" version="1">
          <linux:name>squid_use_tproxy</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_squid_use_tproxy:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_squid_use_tproxy:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_ssh_chroot_rw_homedirs:ste:1" operator="AND" version="1">
          <linux:name>ssh_chroot_rw_homedirs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_ssh_chroot_rw_homedirs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_ssh_chroot_rw_homedirs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_ssh_keysign:ste:1" operator="AND" version="1">
          <linux:name>ssh_keysign</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_ssh_keysign:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_ssh_keysign:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_ssh_sysadm_login:ste:1" operator="AND" version="1">
          <linux:name>ssh_sysadm_login</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_ssh_sysadm_login:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_ssh_sysadm_login:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_staff_exec_content:ste:1" operator="AND" version="1">
          <linux:name>staff_exec_content</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_staff_exec_content:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_staff_exec_content:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_staff_use_svirt:ste:1" operator="AND" version="1">
          <linux:name>staff_use_svirt</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_staff_use_svirt:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_staff_use_svirt:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_swift_can_network:ste:1" operator="AND" version="1">
          <linux:name>swift_can_network</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_swift_can_network:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_swift_can_network:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_sysadm_exec_content:ste:1" operator="AND" version="1">
          <linux:name>sysadm_exec_content</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_sysadm_exec_content:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_sysadm_exec_content:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_telepathy_connect_all_ports:ste:1" operator="AND" version="1">
          <linux:name>telepathy_connect_all_ports</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_telepathy_connect_all_ports:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_telepathy_connect_all_ports:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_telepathy_tcp_connect_generic_network_ports:ste:1" operator="AND" version="1">
          <linux:name>telepathy_tcp_connect_generic_network_ports</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_telepathy_tcp_connect_generic_network_ports:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_telepathy_tcp_connect_generic_network_ports:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_tftp_anon_write:ste:1" operator="AND" version="1">
          <linux:name>tftp_anon_write</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_tftp_anon_write:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_tftp_anon_write:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_tftp_home_dir:ste:1" operator="AND" version="1">
          <linux:name>tftp_home_dir</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_tftp_home_dir:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_tftp_home_dir:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_tmpreaper_use_nfs:ste:1" operator="AND" version="1">
          <linux:name>tmpreaper_use_nfs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_tmpreaper_use_nfs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_tmpreaper_use_nfs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_tmpreaper_use_samba:ste:1" operator="AND" version="1">
          <linux:name>tmpreaper_use_samba</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_tmpreaper_use_samba:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_tmpreaper_use_samba:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_tor_bind_all_unreserved_ports:ste:1" operator="AND" version="1">
          <linux:name>tor_bind_all_unreserved_ports</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_tor_bind_all_unreserved_ports:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_tor_bind_all_unreserved_ports:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_tor_can_network_relay:ste:1" operator="AND" version="1">
          <linux:name>tor_can_network_relay</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_tor_can_network_relay:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_tor_can_network_relay:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_unconfined_chrome_sandbox_transition:ste:1" operator="AND" version="1">
          <linux:name>unconfined_chrome_sandbox_transition</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_unconfined_chrome_sandbox_transition:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_unconfined_chrome_sandbox_transition:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_unconfined_login:ste:1" operator="AND" version="1">
          <linux:name>unconfined_login</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_unconfined_login:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_unconfined_login:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_unconfined_mozilla_plugin_transition:ste:1" operator="AND" version="1">
          <linux:name>unconfined_mozilla_plugin_transition</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_unconfined_mozilla_plugin_transition:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_unconfined_mozilla_plugin_transition:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_unprivuser_use_svirt:ste:1" operator="AND" version="1">
          <linux:name>unprivuser_use_svirt</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_unprivuser_use_svirt:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_unprivuser_use_svirt:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_use_ecryptfs_home_dirs:ste:1" operator="AND" version="1">
          <linux:name>use_ecryptfs_home_dirs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_use_ecryptfs_home_dirs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_use_ecryptfs_home_dirs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_use_fusefs_home_dirs:ste:1" operator="AND" version="1">
          <linux:name>use_fusefs_home_dirs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_use_fusefs_home_dirs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_use_fusefs_home_dirs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_use_lpd_server:ste:1" operator="AND" version="1">
          <linux:name>use_lpd_server</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_use_lpd_server:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_use_lpd_server:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_use_nfs_home_dirs:ste:1" operator="AND" version="1">
          <linux:name>use_nfs_home_dirs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_use_nfs_home_dirs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_use_nfs_home_dirs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_use_samba_home_dirs:ste:1" operator="AND" version="1">
          <linux:name>use_samba_home_dirs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_use_samba_home_dirs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_use_samba_home_dirs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_user_exec_content:ste:1" operator="AND" version="1">
          <linux:name>user_exec_content</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_user_exec_content:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_user_exec_content:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_varnishd_connect_any:ste:1" operator="AND" version="1">
          <linux:name>varnishd_connect_any</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_varnishd_connect_any:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_varnishd_connect_any:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_virt_read_qemu_ga_data:ste:1" operator="AND" version="1">
          <linux:name>virt_read_qemu_ga_data</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_virt_read_qemu_ga_data:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_virt_read_qemu_ga_data:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_virt_rw_qemu_ga_data:ste:1" operator="AND" version="1">
          <linux:name>virt_rw_qemu_ga_data</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_virt_rw_qemu_ga_data:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_virt_rw_qemu_ga_data:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_virt_sandbox_use_all_caps:ste:1" operator="AND" version="1">
          <linux:name>virt_sandbox_use_all_caps</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_virt_sandbox_use_all_caps:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_virt_sandbox_use_all_caps:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_virt_sandbox_use_audit:ste:1" operator="AND" version="1">
          <linux:name>virt_sandbox_use_audit</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_virt_sandbox_use_audit:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_virt_sandbox_use_audit:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_virt_sandbox_use_mknod:ste:1" operator="AND" version="1">
          <linux:name>virt_sandbox_use_mknod</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_virt_sandbox_use_mknod:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_virt_sandbox_use_mknod:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_virt_sandbox_use_netlink:ste:1" operator="AND" version="1">
          <linux:name>virt_sandbox_use_netlink</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_virt_sandbox_use_netlink:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_virt_sandbox_use_netlink:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_virt_sandbox_use_sys_admin:ste:1" operator="AND" version="1">
          <linux:name>virt_sandbox_use_sys_admin</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_virt_sandbox_use_sys_admin:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_virt_sandbox_use_sys_admin:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_virt_transition_userdomain:ste:1" operator="AND" version="1">
          <linux:name>virt_transition_userdomain</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_virt_transition_userdomain:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_virt_transition_userdomain:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_virt_use_comm:ste:1" operator="AND" version="1">
          <linux:name>virt_use_comm</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_virt_use_comm:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_virt_use_comm:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_virt_use_execmem:ste:1" operator="AND" version="1">
          <linux:name>virt_use_execmem</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_virt_use_execmem:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_virt_use_execmem:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_virt_use_fusefs:ste:1" operator="AND" version="1">
          <linux:name>virt_use_fusefs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_virt_use_fusefs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_virt_use_fusefs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_virt_use_nfs:ste:1" operator="AND" version="1">
          <linux:name>virt_use_nfs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_virt_use_nfs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_virt_use_nfs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_virt_use_rawip:ste:1" operator="AND" version="1">
          <linux:name>virt_use_rawip</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_virt_use_rawip:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_virt_use_rawip:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_virt_use_samba:ste:1" operator="AND" version="1">
          <linux:name>virt_use_samba</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_virt_use_samba:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_virt_use_samba:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_virt_use_sanlock:ste:1" operator="AND" version="1">
          <linux:name>virt_use_sanlock</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_virt_use_sanlock:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_virt_use_sanlock:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_virt_use_usb:ste:1" operator="AND" version="1">
          <linux:name>virt_use_usb</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_virt_use_usb:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_virt_use_usb:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_virt_use_xserver:ste:1" operator="AND" version="1">
          <linux:name>virt_use_xserver</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_virt_use_xserver:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_virt_use_xserver:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_webadm_manage_user_files:ste:1" operator="AND" version="1">
          <linux:name>webadm_manage_user_files</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_webadm_manage_user_files:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_webadm_manage_user_files:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_webadm_read_user_files:ste:1" operator="AND" version="1">
          <linux:name>webadm_read_user_files</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_webadm_read_user_files:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_webadm_read_user_files:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_wine_mmap_zero_ignore:ste:1" operator="AND" version="1">
          <linux:name>wine_mmap_zero_ignore</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_wine_mmap_zero_ignore:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_wine_mmap_zero_ignore:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_xdm_bind_vnc_tcp_port:ste:1" operator="AND" version="1">
          <linux:name>xdm_bind_vnc_tcp_port</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_xdm_bind_vnc_tcp_port:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_xdm_bind_vnc_tcp_port:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_xdm_exec_bootloader:ste:1" operator="AND" version="1">
          <linux:name>xdm_exec_bootloader</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_xdm_exec_bootloader:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_xdm_exec_bootloader:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_xdm_sysadm_login:ste:1" operator="AND" version="1">
          <linux:name>xdm_sysadm_login</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_xdm_sysadm_login:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_xdm_sysadm_login:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_xdm_write_home:ste:1" operator="AND" version="1">
          <linux:name>xdm_write_home</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_xdm_write_home:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_xdm_write_home:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_xen_use_nfs:ste:1" operator="AND" version="1">
          <linux:name>xen_use_nfs</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_xen_use_nfs:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_xen_use_nfs:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_xend_run_blktap:ste:1" operator="AND" version="1">
          <linux:name>xend_run_blktap</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_xend_run_blktap:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_xend_run_blktap:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_xend_run_qemu:ste:1" operator="AND" version="1">
          <linux:name>xend_run_qemu</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_xend_run_qemu:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_xend_run_qemu:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_xguest_connect_network:ste:1" operator="AND" version="1">
          <linux:name>xguest_connect_network</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_xguest_connect_network:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_xguest_connect_network:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_xguest_exec_content:ste:1" operator="AND" version="1">
          <linux:name>xguest_exec_content</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_xguest_exec_content:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_xguest_exec_content:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_xguest_mount_media:ste:1" operator="AND" version="1">
          <linux:name>xguest_mount_media</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_xguest_mount_media:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_xguest_mount_media:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_xguest_use_bluetooth:ste:1" operator="AND" version="1">
          <linux:name>xguest_use_bluetooth</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_xguest_use_bluetooth:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_xguest_use_bluetooth:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_xserver_clients_write_xshm:ste:1" operator="AND" version="1">
          <linux:name>xserver_clients_write_xshm</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_xserver_clients_write_xshm:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_xserver_clients_write_xshm:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_xserver_execmem:ste:1" operator="AND" version="1">
          <linux:name>xserver_execmem</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_xserver_execmem:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_xserver_execmem:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_xserver_object_manager:ste:1" operator="AND" version="1">
          <linux:name>xserver_object_manager</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_xserver_object_manager:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_xserver_object_manager:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_zabbix_can_network:ste:1" operator="AND" version="1">
          <linux:name>zabbix_can_network</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_zabbix_can_network:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_zabbix_can_network:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_zarafa_setrlimit:ste:1" operator="AND" version="1">
          <linux:name>zarafa_setrlimit</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_zarafa_setrlimit:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_zarafa_setrlimit:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_zebra_write_config:ste:1" operator="AND" version="1">
          <linux:name>zebra_write_config</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_zebra_write_config:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_zebra_write_config:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_zoneminder_anon_write:ste:1" operator="AND" version="1">
          <linux:name>zoneminder_anon_write</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_zoneminder_anon_write:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_zoneminder_anon_write:var:1"/>
        </linux:selinuxboolean_state>
        <linux:selinuxboolean_state id="oval:ssg-state_sebool_zoneminder_run_sudo:ste:1" operator="AND" version="1">
          <linux:name>zoneminder_run_sudo</linux:name>
          <linux:current_status datatype="boolean" var_ref="oval:ssg-var_zoneminder_run_sudo:var:1"/>
          <linux:pending_status datatype="boolean" var_ref="oval:ssg-var_zoneminder_run_sudo:var:1"/>
        </linux:selinuxboolean_state>
        <ind:textfilecontent54_state id="oval:ssg-state_selinux_policytype:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_ref="oval:ssg-var_selinux_policy_name:var:1"/>
        </ind:textfilecontent54_state>
        <linux:systemdunitproperty_state comment="abrtd is not running" id="oval:ssg-state_service_not_running_service_abrtd_disabled_abrtd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_abrtd_disabled_abrtd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_abrtd_disabled_abrtd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="acpid is not running" id="oval:ssg-state_service_not_running_service_acpid_disabled_acpid:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_acpid_disabled_acpid:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_acpid_disabled_acpid:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="atd is not running" id="oval:ssg-state_service_not_running_service_atd_disabled_atd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_atd_disabled_atd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_atd_disabled_atd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="auditd listed at least once in the dependencies" id="oval:ssg-state_systemd_auditd_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">auditd.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="auditd listed at least once in the dependencies" id="oval:ssg-state_systemd_auditd_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">auditd.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="auditd is running" id="oval:ssg-state_service_running_auditd:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="autofs is not running" id="oval:ssg-state_service_not_running_service_autofs_disabled_autofs:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_autofs_disabled_autofs:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_autofs_disabled_autofs:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="avahi-daemon is not running" id="oval:ssg-state_service_not_running_service_avahi-daemon_disabled_avahi-daemon:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_avahi-daemon_disabled_avahi-daemon:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_avahi-daemon_disabled_avahi-daemon:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="bluetooth is not running" id="oval:ssg-state_service_not_running_service_bluetooth_disabled_bluetooth:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_bluetooth_disabled_bluetooth:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_bluetooth_disabled_bluetooth:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="certmonger is not running" id="oval:ssg-state_service_not_running_service_certmonger_disabled_certmonger:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_certmonger_disabled_certmonger:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_certmonger_disabled_certmonger:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="chronyd listed at least once in the dependencies" id="oval:ssg-state_systemd_chronyd_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">chronyd.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="chronyd listed at least once in the dependencies" id="oval:ssg-state_systemd_chronyd_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">chronyd.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="chronyd is running" id="oval:ssg-state_service_running_chronyd:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="cockpit is not running" id="oval:ssg-state_service_not_running_service_cockpit_disabled_cockpit:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_cockpit_disabled_cockpit:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_cockpit_disabled_cockpit:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="cpupower is not running" id="oval:ssg-state_service_not_running_service_cpupower_disabled_cpupower:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_cpupower_disabled_cpupower:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_cpupower_disabled_cpupower:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="cron listed at least once in the dependencies" id="oval:ssg-state_systemd_cron_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">cron.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="cron listed at least once in the dependencies" id="oval:ssg-state_systemd_cron_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">cron.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="cron is running" id="oval:ssg-state_service_running_cron:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="crond listed at least once in the dependencies" id="oval:ssg-state_systemd_crond_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">crond.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="crond listed at least once in the dependencies" id="oval:ssg-state_systemd_crond_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">crond.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="crond is running" id="oval:ssg-state_service_running_crond:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="cups is not running" id="oval:ssg-state_service_not_running_service_cups_disabled_cups:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_cups_disabled_cups:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_cups_disabled_cups:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="debug-shell is not running" id="oval:ssg-state_service_not_running_service_debug-shell_disabled_debug-shell:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_debug-shell_disabled_debug-shell:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_debug-shell_disabled_debug-shell:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="dhcpd is not running" id="oval:ssg-state_service_not_running_service_dhcpd_disabled_dhcpd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_dhcpd_disabled_dhcpd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_dhcpd_disabled_dhcpd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="dnsmasq is not running" id="oval:ssg-state_service_not_running_service_dnsmasq_disabled_dnsmasq:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_dnsmasq_disabled_dnsmasq:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_dnsmasq_disabled_dnsmasq:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="dovecot is not running" id="oval:ssg-state_service_not_running_service_dovecot_disabled_dovecot:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_dovecot_disabled_dovecot:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_dovecot_disabled_dovecot:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="fapolicyd listed at least once in the dependencies" id="oval:ssg-state_systemd_fapolicyd_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">fapolicyd.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="fapolicyd listed at least once in the dependencies" id="oval:ssg-state_systemd_fapolicyd_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">fapolicyd.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="fapolicyd is running" id="oval:ssg-state_service_running_fapolicyd:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="firewalld listed at least once in the dependencies" id="oval:ssg-state_systemd_firewalld_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">firewalld.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="firewalld listed at least once in the dependencies" id="oval:ssg-state_systemd_firewalld_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">firewalld.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="firewalld is running" id="oval:ssg-state_service_running_firewalld:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="httpd is not running" id="oval:ssg-state_service_not_running_service_httpd_disabled_httpd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_httpd_disabled_httpd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_httpd_disabled_httpd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="ip6tables listed at least once in the dependencies" id="oval:ssg-state_systemd_ip6tables_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">ip6tables.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="ip6tables listed at least once in the dependencies" id="oval:ssg-state_systemd_ip6tables_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">ip6tables.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="ip6tables is running" id="oval:ssg-state_service_running_ip6tables:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="iptables listed at least once in the dependencies" id="oval:ssg-state_systemd_iptables_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">iptables.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="iptables listed at least once in the dependencies" id="oval:ssg-state_systemd_iptables_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">iptables.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="iptables is running" id="oval:ssg-state_service_running_iptables:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="kdump is not running" id="oval:ssg-state_service_not_running_service_kdump_disabled_kdump:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_kdump_disabled_kdump:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_kdump_disabled_kdump:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="mdmonitor is not running" id="oval:ssg-state_service_not_running_service_mdmonitor_disabled_mdmonitor:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_mdmonitor_disabled_mdmonitor:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_mdmonitor_disabled_mdmonitor:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="nails listed at least once in the dependencies" id="oval:ssg-state_systemd_nails_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">nails.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="nails listed at least once in the dependencies" id="oval:ssg-state_systemd_nails_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">nails.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="nails is running" id="oval:ssg-state_service_running_nails:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="named is not running" id="oval:ssg-state_service_not_running_service_named_disabled_named:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_named_disabled_named:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_named_disabled_named:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="netconsole is not running" id="oval:ssg-state_service_not_running_service_netconsole_disabled_netconsole:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_netconsole_disabled_netconsole:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_netconsole_disabled_netconsole:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="netfs is not running" id="oval:ssg-state_service_not_running_service_netfs_disabled_netfs:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_netfs_disabled_netfs:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_netfs_disabled_netfs:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="nfs-server is not running" id="oval:ssg-state_service_not_running_service_nfs_disabled_nfs-server:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_nfs_disabled_nfs-server:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_nfs_disabled_nfs-server:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="nfslock is not running" id="oval:ssg-state_service_not_running_service_nfslock_disabled_nfslock:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_nfslock_disabled_nfslock:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_nfslock_disabled_nfslock:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="nftables is not running" id="oval:ssg-state_service_not_running_service_nftables_disabled_nftables:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_nftables_disabled_nftables:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_nftables_disabled_nftables:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="nftables listed at least once in the dependencies" id="oval:ssg-state_systemd_nftables_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">nftables.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="nftables listed at least once in the dependencies" id="oval:ssg-state_systemd_nftables_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">nftables.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="nftables is running" id="oval:ssg-state_service_running_nftables:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="ntp listed at least once in the dependencies" id="oval:ssg-state_systemd_ntp_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">ntp.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="ntp listed at least once in the dependencies" id="oval:ssg-state_systemd_ntp_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">ntp.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="ntp is running" id="oval:ssg-state_service_running_ntp:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="ntpd listed at least once in the dependencies" id="oval:ssg-state_systemd_ntpd_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">ntpd.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="ntpd listed at least once in the dependencies" id="oval:ssg-state_systemd_ntpd_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">ntpd.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="ntpd is running" id="oval:ssg-state_service_running_ntpd:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="ntpdate is not running" id="oval:ssg-state_service_not_running_service_ntpdate_disabled_ntpdate:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_ntpdate_disabled_ntpdate:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_ntpdate_disabled_ntpdate:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="oddjobd is not running" id="oval:ssg-state_service_not_running_service_oddjobd_disabled_oddjobd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_oddjobd_disabled_oddjobd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_oddjobd_disabled_oddjobd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="pcscd listed at least once in the dependencies" id="oval:ssg-state_systemd_pcscd_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">pcscd.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="pcscd listed at least once in the dependencies" id="oval:ssg-state_systemd_pcscd_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">pcscd.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="pcscd is running" id="oval:ssg-state_service_running_pcscd:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="portreserve is not running" id="oval:ssg-state_service_not_running_service_portreserve_disabled_portreserve:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_portreserve_disabled_portreserve:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_portreserve_disabled_portreserve:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="postfix listed at least once in the dependencies" id="oval:ssg-state_systemd_postfix_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">postfix.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="postfix listed at least once in the dependencies" id="oval:ssg-state_systemd_postfix_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">postfix.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="postfix is running" id="oval:ssg-state_service_running_postfix:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="psacct listed at least once in the dependencies" id="oval:ssg-state_systemd_psacct_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">psacct.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="psacct listed at least once in the dependencies" id="oval:ssg-state_systemd_psacct_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">psacct.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="psacct is running" id="oval:ssg-state_service_running_psacct:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="qpidd is not running" id="oval:ssg-state_service_not_running_service_qpidd_disabled_qpidd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_qpidd_disabled_qpidd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_qpidd_disabled_qpidd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="quota_nld is not running" id="oval:ssg-state_service_not_running_service_quota_nld_disabled_quota_nld:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_quota_nld_disabled_quota_nld:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_quota_nld_disabled_quota_nld:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="rdisc is not running" id="oval:ssg-state_service_not_running_service_rdisc_disabled_rdisc:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_rdisc_disabled_rdisc:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_rdisc_disabled_rdisc:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="rexec is not running" id="oval:ssg-state_service_not_running_service_rexec_disabled_rexec:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_rexec_disabled_rexec:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_rexec_disabled_rexec:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="rhnsd is not running" id="oval:ssg-state_service_not_running_service_rhnsd_disabled_rhnsd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_rhnsd_disabled_rhnsd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_rhnsd_disabled_rhnsd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="rhsmcertd is not running" id="oval:ssg-state_service_not_running_service_rhsmcertd_disabled_rhsmcertd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_rhsmcertd_disabled_rhsmcertd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_rhsmcertd_disabled_rhsmcertd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="rlogin is not running" id="oval:ssg-state_service_not_running_service_rlogin_disabled_rlogin:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_rlogin_disabled_rlogin:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_rlogin_disabled_rlogin:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="rngd listed at least once in the dependencies" id="oval:ssg-state_systemd_rngd_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">rngd.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="rngd listed at least once in the dependencies" id="oval:ssg-state_systemd_rngd_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">rngd.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="rngd is running" id="oval:ssg-state_service_running_rngd:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="rpcbind is not running" id="oval:ssg-state_service_not_running_service_rpcbind_disabled_rpcbind:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_rpcbind_disabled_rpcbind:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_rpcbind_disabled_rpcbind:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="rpcgssd is not running" id="oval:ssg-state_service_not_running_service_rpcgssd_disabled_rpcgssd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_rpcgssd_disabled_rpcgssd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_rpcgssd_disabled_rpcgssd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="rpcidmapd is not running" id="oval:ssg-state_service_not_running_service_rpcidmapd_disabled_rpcidmapd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_rpcidmapd_disabled_rpcidmapd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_rpcidmapd_disabled_rpcidmapd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="rpcsvcgssd is not running" id="oval:ssg-state_service_not_running_service_rpcsvcgssd_disabled_rpcsvcgssd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_rpcsvcgssd_disabled_rpcsvcgssd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_rpcsvcgssd_disabled_rpcsvcgssd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="rsh is not running" id="oval:ssg-state_service_not_running_service_rsh_disabled_rsh:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_rsh_disabled_rsh:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_rsh_disabled_rsh:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="rsyncd is not running" id="oval:ssg-state_service_not_running_service_rsyncd_disabled_rsyncd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_rsyncd_disabled_rsyncd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_rsyncd_disabled_rsyncd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="rsyslog listed at least once in the dependencies" id="oval:ssg-state_systemd_rsyslog_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">rsyslog.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="rsyslog listed at least once in the dependencies" id="oval:ssg-state_systemd_rsyslog_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">rsyslog.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="rsyslog is running" id="oval:ssg-state_service_running_rsyslog:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="saslauthd is not running" id="oval:ssg-state_service_not_running_service_saslauthd_disabled_saslauthd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_saslauthd_disabled_saslauthd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_saslauthd_disabled_saslauthd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="slapd is not running" id="oval:ssg-state_service_not_running_service_slapd_disabled_slapd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_slapd_disabled_slapd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_slapd_disabled_slapd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="smb is not running" id="oval:ssg-state_service_not_running_service_smb_disabled_smb:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_smb_disabled_smb:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_smb_disabled_smb:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="snmpd is not running" id="oval:ssg-state_service_not_running_service_snmpd_disabled_snmpd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_snmpd_disabled_snmpd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_snmpd_disabled_snmpd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="squid is not running" id="oval:ssg-state_service_not_running_service_squid_disabled_squid:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_squid_disabled_squid:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_squid_disabled_squid:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="sshd is not running" id="oval:ssg-state_service_not_running_service_sshd_disabled_sshd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_sshd_disabled_sshd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_sshd_disabled_sshd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="sshd listed at least once in the dependencies" id="oval:ssg-state_systemd_sshd_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">sshd.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="sshd listed at least once in the dependencies" id="oval:ssg-state_systemd_sshd_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">sshd.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="sshd is running" id="oval:ssg-state_service_running_sshd:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="sssd listed at least once in the dependencies" id="oval:ssg-state_systemd_sssd_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">sssd.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="sssd listed at least once in the dependencies" id="oval:ssg-state_systemd_sssd_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">sssd.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="sssd is running" id="oval:ssg-state_service_running_sssd:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="syslog-ng listed at least once in the dependencies" id="oval:ssg-state_systemd_syslog-ng_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">syslog-ng.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="syslog-ng listed at least once in the dependencies" id="oval:ssg-state_systemd_syslog-ng_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">syslog-ng.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="syslog-ng is running" id="oval:ssg-state_service_running_syslog-ng:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="sysstat is not running" id="oval:ssg-state_service_not_running_service_sysstat_disabled_sysstat:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_sysstat_disabled_sysstat:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_sysstat_disabled_sysstat:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_socket_loadstate_is_masked_systemd-coredump:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="systemd-journal-upload listed at least once in the dependencies" id="oval:ssg-state_systemd_systemd-journal-upload_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">systemd-journal-upload.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="systemd-journal-upload listed at least once in the dependencies" id="oval:ssg-state_systemd_systemd-journal-upload_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">systemd-journal-upload.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="systemd-journal-upload is running" id="oval:ssg-state_service_running_systemd-journal-upload:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="systemd-journald listed at least once in the dependencies" id="oval:ssg-state_systemd_systemd-journald_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">systemd-journald.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="systemd-journald listed at least once in the dependencies" id="oval:ssg-state_systemd_systemd-journald_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">systemd-journald.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="systemd-journald is running" id="oval:ssg-state_service_running_systemd-journald:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="telnet is not running" id="oval:ssg-state_service_not_running_service_telnet_disabled_telnet:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_telnet_disabled_telnet:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_telnet_disabled_telnet:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="tftp is not running" id="oval:ssg-state_service_not_running_service_tftp_disabled_tftp:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_tftp_disabled_tftp:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_tftp_disabled_tftp:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="ufw listed at least once in the dependencies" id="oval:ssg-state_systemd_ufw_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">ufw.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="ufw listed at least once in the dependencies" id="oval:ssg-state_systemd_ufw_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">ufw.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="ufw is running" id="oval:ssg-state_service_running_ufw:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="usbguard listed at least once in the dependencies" id="oval:ssg-state_systemd_usbguard_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">usbguard.service</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitdependency_state comment="usbguard listed at least once in the dependencies" id="oval:ssg-state_systemd_usbguard_socket_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">usbguard.socket</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="usbguard is running" id="oval:ssg-state_service_running_usbguard:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="vsftpd is not running" id="oval:ssg-state_service_not_running_service_vsftpd_disabled_vsftpd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_vsftpd_disabled_vsftpd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_vsftpd_disabled_vsftpd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="xinetd is not running" id="oval:ssg-state_service_not_running_service_xinetd_disabled_xinetd:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_xinetd_disabled_xinetd:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_xinetd_disabled_xinetd:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="ypbind is not running" id="oval:ssg-state_service_not_running_service_ypbind_disabled_ypbind:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_ypbind_disabled_ypbind:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_ypbind_disabled_ypbind:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="ypserv is not running" id="oval:ssg-state_service_not_running_service_ypserv_disabled_ypserv:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_ypserv_disabled_ypserv:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_ypserv_disabled_ypserv:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="zebra is not running" id="oval:ssg-state_service_not_running_service_zebra_disabled_zebra:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_zebra_disabled_zebra:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_zebra_disabled_zebra:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_socket_loadstate_is_masked_systemd-journal-remote:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_allow_only_protocol2:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^2$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_disable_compression:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_ref="oval:ssg-var_sshd_disable_compression:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_disable_empty_passwords:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^no$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_disable_forwarding:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^yes$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_disable_gssapi_auth:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^no$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_disable_kerb_auth:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^no$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_disable_pubkey_auth:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^no$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_disable_rhosts:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^yes$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_disable_rhosts_rsa:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^no$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_disable_root_login:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^no$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_disable_root_password_login:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^prohibit-password$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_disable_tcp_forwarding:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^no$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_disable_user_known_hosts:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^yes$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_disable_x11_forwarding:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^no$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_do_not_permit_user_env:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^no$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_enable_gssapi_auth:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^yes$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_enable_pam:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^yes$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_enable_pubkey_auth:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^yes$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_enable_strictmodes:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^yes$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_enable_warning_banner:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^/etc/issue$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_enable_warning_banner_net:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^/etc/issue.net$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_enable_x11_forwarding:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^yes$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_print_last_log:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^yes$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_set_keepalive:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-var_sshd_set_keepalive:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_set_keepalive_0:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^0$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_set_loglevel_info:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^INFO$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_set_loglevel_verbose:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^VERBOSE$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_use_priv_separation:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_ref="oval:ssg-var_sshd_priv_separation:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_use_strong_rng:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^32$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_sshd_x11_use_localhost:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^yes$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_passwd_timeout_sudoers:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_ref="oval:ssg-var_sudo_passwd_timeout:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_umask_sudoers:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_ref="oval:ssg-var_sudo_umask:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_logfile_sudoers:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals" var_ref="oval:ssg-var_sudo_logfile:var:1"/>
        </ind:textfilecontent54_state>
        <unix:file_state id="oval:ssg-state_file_permissionssudo_restrict_others_executable_permission_0_mode_4110or_stricter_:ste:1" operator="AND" version="3">
          <unix:sgid datatype="boolean">false</unix:sgid>
          <unix:sticky datatype="boolean">false</unix:sticky>
          <unix:uread datatype="boolean">false</unix:uread>
          <unix:uwrite datatype="boolean">false</unix:uwrite>
          <unix:gread datatype="boolean">false</unix:gread>
          <unix:gwrite datatype="boolean">false</unix:gwrite>
          <unix:oread datatype="boolean">false</unix:oread>
          <unix:owrite datatype="boolean">false</unix:owrite>
          <unix:oexec datatype="boolean">false</unix:oexec>
        </unix:file_state>
        <unix:file_state id="oval:ssg-exclude_symlinks_sudo_restrict_others_executable_permission:ste:1" operator="AND" version="1">
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_fs_protected_hardlinks_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">1</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_fs_protected_hardlinks:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">1</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_fs_protected_symlinks_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">1</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_fs_protected_symlinks:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">1</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_fs_suid_dumpable_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">0</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_fs_suid_dumpable:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_core_pattern_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="string" operation="equals">|/bin/false</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_kernel_core_pattern:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="equals">|/bin/false</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_core_uses_pid_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">0</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_kernel_core_uses_pid:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_dmesg_restrict_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">1</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_kernel_dmesg_restrict:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">1</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_kexec_load_disabled_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">1</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_kernel_kexec_load_disabled:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">1</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_kptr_restrict_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">1</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_kernel_kptr_restrict:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">1</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_modules_disabled_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">1</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_kernel_modules_disabled:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">1</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_panic_on_oops_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">1</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_kernel_panic_on_oops:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">1</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_perf_cpu_time_max_percent_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">1</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_kernel_perf_cpu_time_max_percent:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">1</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_perf_event_max_sample_rate_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">1</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_kernel_perf_event_max_sample_rate:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">1</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_perf_event_paranoid_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">2</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_kernel_perf_event_paranoid:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">2</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_pid_max_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">65536</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_kernel_pid_max:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">65536</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_randomize_va_space_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">2</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_kernel_randomize_va_space:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">2</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_sysrq_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">0</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_kernel_sysrq:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_unprivileged_bpf_disabled_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">1</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_kernel_unprivileged_bpf_disabled:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">1</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_yama_ptrace_scope_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">1</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_kernel_yama_ptrace_scope:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">1</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_core_bpf_jit_harden_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">2</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_core_bpf_jit_harden:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">2</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_all_accept_local_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">0</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_accept_local:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_all_accept_redirects_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_accept_redirects_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_accept_redirects:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_accept_redirects_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_all_accept_source_route_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_accept_source_route_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_accept_source_route:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_accept_source_route_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_all_arp_filter_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_arp_filter_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_arp_filter:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_arp_filter_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_all_arp_ignore_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_arp_ignore_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_arp_ignore:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_arp_ignore_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_all_drop_gratuitous_arp_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">1</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_drop_gratuitous_arp:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">1</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_all_forwarding_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_forwarding_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_forwarding:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_forwarding_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_all_log_martians_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_log_martians_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_log_martians:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_log_martians_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_all_route_localnet_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">0</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_route_localnet:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_all_rp_filter_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_rp_filter_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_rp_filter:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_rp_filter_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_all_secure_redirects_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_secure_redirects_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_secure_redirects:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_secure_redirects_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_all_send_redirects_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">0</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_send_redirects:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_all_shared_media_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_shared_media_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_all_shared_media:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_all_shared_media_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_default_accept_redirects_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_default_accept_redirects_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_accept_redirects:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_default_accept_redirects_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_default_accept_source_route_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_default_accept_source_route_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_accept_source_route:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_default_accept_source_route_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_default_forwarding_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_default_forwarding_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_forwarding:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_default_forwarding_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_default_log_martians_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_default_log_martians_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_log_martians:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_default_log_martians_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_default_rp_filter_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_default_rp_filter_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_rp_filter:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_default_rp_filter_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_default_secure_redirects_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_default_secure_redirects_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_secure_redirects:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_default_secure_redirects_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_default_send_redirects_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">0</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_send_redirects:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_conf_default_shared_media_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_default_shared_media_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_conf_default_shared_media:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_conf_default_shared_media_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_icmp_echo_ignore_broadcasts_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_icmp_echo_ignore_broadcasts:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_icmp_ignore_bogus_error_responses_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_icmp_ignore_bogus_error_responses:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_ip_forward_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">0</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_ip_forward:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_ip_local_port_range_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="string" operation="pattern match">32768\s*65535</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_ip_local_port_range:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">32768\s*65535</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_tcp_invalid_ratelimit_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_tcp_invalid_ratelimit_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_tcp_invalid_ratelimit:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_tcp_invalid_ratelimit_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_tcp_rfc1337_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_tcp_rfc1337_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_tcp_rfc1337:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_tcp_rfc1337_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_tcp_syncookies_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_tcp_syncookies_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_tcp_syncookies:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_tcp_syncookies_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_all_accept_ra_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_ra:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_all_accept_ra_defrtr_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_ra_defrtr:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_all_accept_ra_pinfo_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_ra_pinfo:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_ra_rtr_pref:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_all_accept_redirects_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_redirects_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_redirects:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_redirects_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_all_accept_source_route_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_source_route_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_accept_source_route:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_accept_source_route_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_all_autoconf_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_autoconf_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_autoconf:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_autoconf_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_all_disable_ipv6_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">1</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_disable_ipv6:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">1</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_all_forwarding_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_forwarding_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_forwarding:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_forwarding_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_all_max_addresses_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_max_addresses_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_max_addresses:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_max_addresses_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_all_router_solicitations_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_router_solicitations_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_all_router_solicitations:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_all_router_solicitations_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_default_accept_ra_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_ra:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_default_accept_ra_defrtr_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_ra_defrtr:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_default_accept_ra_pinfo_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_ra_pinfo:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_ra_rtr_pref:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_default_accept_redirects_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_redirects_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_redirects:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_redirects_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_default_accept_source_route_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_source_route_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_accept_source_route:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_accept_source_route_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_default_autoconf_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_autoconf_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_autoconf:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_autoconf_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_default_disable_ipv6_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">1</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_disable_ipv6:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">1</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_default_forwarding_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_forwarding_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_forwarding:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_forwarding_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_default_max_addresses_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_max_addresses_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_max_addresses:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_max_addresses_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv6_conf_default_router_solicitations_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_router_solicitations_value:var:1"/>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv6_conf_default_router_solicitations:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv6_conf_default_router_solicitations_value:var:1"/>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_user_max_user_namespaces_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">0</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_user_max_user_namespaces:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_user_max_user_namespaces_no_remediation_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">0</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_user_max_user_namespaces_no_remediation:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:sysctl_state id="oval:ssg-state_sysctl_vm_mmap_min_addr_runtime:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">65536</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_vm_mmap_min_addr:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">65536</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:systemdunitdependency_state comment="tmp mount is listed at least once in the dependencies" id="oval:ssg-state_systemd_tmp_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">tmp.mount</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="tmp mount is active" id="oval:ssg-state_mount_running_tmp:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="dnf-automatic listed at least once in the dependencies" id="oval:ssg-state_systemd_dnf-automatic_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">dnf-automatic.timer</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="dnf-automatic is running" id="oval:ssg-state_timer_running_dnf-automatic:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitdependency_state comment="logrotate listed at least once in the dependencies" id="oval:ssg-state_systemd_logrotate_on:ste:1" operator="AND" version="1">
          <linux:dependency entity_check="at least one">logrotate.timer</linux:dependency>
        </linux:systemdunitdependency_state>
        <linux:systemdunitproperty_state comment="logrotate is running" id="oval:ssg-state_timer_running_logrotate:ste:1" operator="AND" version="1">
          <linux:value>active</linux:value>
        </linux:systemdunitproperty_state>
        <ind:textfilecontent54_state id="oval:ssg-state_pam_auth_pam_wheel_group:ste:1" operator="AND" version="3">
          <ind:subexpression datatype="string" operation="equals" var_ref="oval:ssg-var_pam_wheel_group_for_su:var:1"/>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_zipl_audit_argument_audit_1_argument_in_boot_loader_entries_conf:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?audit=1(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_zipl_audit_argument_audit_1_argument_in_etc_kernel_cmdline:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?audit=1(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_zipl_audit_backlog_limit_argument_audit_backlog_limit_8192_argument_in_boot_loader_entries_conf:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?audit_backlog_limit=8192(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_zipl_audit_backlog_limit_argument_audit_backlog_limit_8192_argument_in_etc_kernel_cmdline:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?audit_backlog_limit=8192(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_zipl_page_poison_argument_page_poison_1_argument_in_boot_loader_entries_conf:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?page_poison=1(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_zipl_page_poison_argument_page_poison_1_argument_in_etc_kernel_cmdline:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?page_poison=1(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_zipl_slub_debug_argument_slub_debug_P_argument_in_boot_loader_entries_conf:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?slub_debug=P(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_zipl_slub_debug_argument_slub_debug_P_argument_in_etc_kernel_cmdline:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?slub_debug=P(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_zipl_vsyscall_argument_vsyscall_none_argument_in_boot_loader_entries_conf:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?vsyscall=none(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_zipl_vsyscall_argument_vsyscall_none_argument_in_etc_kernel_cmdline:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(?:.*\s)?vsyscall=none(?:\s.*)?$</ind:subexpression>
        </ind:textfilecontent54_state>
        <unix:file_state comment="The file /ostree is a symlink" id="oval:ssg-bootc_platform_ste_ostree_symlink_exists:ste:1" operator="AND" version="1">
          <unix:filepath operation="equals">/ostree</unix:filepath>
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <ind:textfilecontent54_state id="oval:ssg-state_bootloader_disable_recovery_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(true|"true")$</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:rpminfo_state id="oval:ssg-state_ol7_system:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^7.*$</linux:version>
        </linux:rpminfo_state>
        <linux:rpminfo_state id="oval:ssg-state_ol8_system:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^8.*$</linux:version>
        </linux:rpminfo_state>
        <linux:rpminfo_state id="oval:ssg-state_ol9_system:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^9.*$</linux:version>
        </linux:rpminfo_state>
        <ind:family_state id="oval:ssg-state_unix_family:ste:1" operator="AND" version="1">
          <ind:family>unix</ind:family>
        </ind:family_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rhcos:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">rhcos</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rhel_coreos_variant:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">coreos</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rhel_coreos_version9:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^9\.</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rhel_coreos_version10:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^10\.</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rhcos4:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">4</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rhcos4_rhel8_rhel_version:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^8\.</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rhel_id:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">rhel</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rhcos4_rhel9_rhel_version:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^9\.</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:family_state id="oval:ssg-state_rhel10_unix_family:ste:1" operator="AND" version="1">
          <ind:family>unix</ind:family>
        </ind:family_state>
        <linux:rpminfo_state id="oval:ssg-state_rhel10:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^10.*$</linux:version>
        </linux:rpminfo_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rhevh_rhel10_version:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">10</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:family_state id="oval:ssg-state_rhel8_unix_family:ste:1" operator="AND" version="1">
          <ind:family>unix</ind:family>
        </ind:family_state>
        <linux:rpminfo_state id="oval:ssg-state_rhel8:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^8\.\d{1,2}$</linux:version>
        </linux:rpminfo_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rhevh_rhel8_version:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">8</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:family_state id="oval:ssg-state_rhel9_unix_family:ste:1" operator="AND" version="1">
          <ind:family>unix</ind:family>
        </ind:family_state>
        <linux:rpminfo_state id="oval:ssg-state_rhel9:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^9.*$</linux:version>
        </linux:rpminfo_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rhevh_rhel9_version:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">9</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:rpminfo_state id="oval:ssg-state_rhvh4_version:ste:1" operator="AND" version="1">
          <linux:evr datatype="evr_string" operation="greater than or equal">0:4.4</linux:evr>
        </linux:rpminfo_state>
        <ind:family_state id="oval:ssg-state_sle12_unix_family:ste:1" operator="AND" version="1">
          <ind:family>unix</ind:family>
        </ind:family_state>
        <linux:rpminfo_state id="oval:ssg-state_sle12_desktop:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^12.*$</linux:version>
        </linux:rpminfo_state>
        <linux:rpminfo_state id="oval:ssg-state_sle12_server:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^12.*$</linux:version>
        </linux:rpminfo_state>
        <linux:rpminfo_state id="oval:ssg-state_sles_12_for_sap:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^12.*$</linux:version>
        </linux:rpminfo_state>
        <ind:family_state id="oval:ssg-state_sle15_unix_family:ste:1" operator="AND" version="1">
          <ind:family>unix</ind:family>
        </ind:family_state>
        <linux:rpminfo_state id="oval:ssg-state_sle15_desktop:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^15.*$</linux:version>
        </linux:rpminfo_state>
        <linux:rpminfo_state id="oval:ssg-state_sle15_server:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^15.*$</linux:version>
        </linux:rpminfo_state>
        <linux:rpminfo_state id="oval:ssg-state_sles_15_for_sap:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^15.*$</linux:version>
        </linux:rpminfo_state>
        <linux:rpminfo_state id="oval:ssg-state_suma_4:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^4.*$</linux:version>
        </linux:rpminfo_state>
        <linux:rpminfo_state id="oval:ssg-state_sle_hpc:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^15.*$</linux:version>
        </linux:rpminfo_state>
        <ind:family_state id="oval:ssg-state_sle16_unix_family:ste:1" operator="AND" version="1">
          <ind:family>unix</ind:family>
        </ind:family_state>
        <linux:rpminfo_state id="oval:ssg-state_sle16_server:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^16.*$</linux:version>
        </linux:rpminfo_state>
        <linux:rpminfo_state id="oval:ssg-state_sles_16_for_sap:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^16.*$</linux:version>
        </linux:rpminfo_state>
        <linux:rpminfo_state id="oval:ssg-state_sles_16_for_ha:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^16.*$</linux:version>
        </linux:rpminfo_state>
        <ind:family_state id="oval:ssg-state_slmicro5_unix_family:ste:1" operator="AND" version="1">
          <ind:family>unix</ind:family>
        </ind:family_state>
        <linux:rpminfo_state id="oval:ssg-state_slmicroos5:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^5.*$</linux:version>
        </linux:rpminfo_state>
        <linux:rpminfo_state id="oval:ssg-state_slmicro5:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^5.*$</linux:version>
        </linux:rpminfo_state>
        <ind:family_state id="oval:ssg-state_slmicro6_unix_family:ste:1" operator="AND" version="1">
          <ind:family>unix</ind:family>
        </ind:family_state>
        <linux:rpminfo_state id="oval:ssg-state_slmicro6:ste:1" operator="AND" version="1">
          <linux:version operation="pattern match">^6.*$</linux:version>
        </linux:rpminfo_state>
        <ind:variable_state id="oval:ssg-state_sshd_not_required:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals">1</ind:value>
        </ind:variable_state>
        <ind:variable_state id="oval:ssg-state_sshd_required:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals">2</ind:value>
        </ind:variable_state>
        <ind:variable_state id="oval:ssg-state_sshd_requirement_unset:ste:1" operator="AND" version="1">
          <ind:value datatype="int" operation="equals">0</ind:value>
        </ind:variable_state>
        <unix:uname_state comment="64 bit architecture" id="oval:ssg-state_system_info_architecture_aarch_64:ste:1" operator="AND" version="1">
          <unix:processor_type operation="equals">aarch64</unix:processor_type>
        </unix:uname_state>
        <unix:uname_state comment="64 bit architecture" id="oval:ssg-state_system_info_architecture_ppc_64:ste:1" operator="AND" version="1">
          <unix:processor_type operation="equals">ppc64</unix:processor_type>
        </unix:uname_state>
        <unix:uname_state comment="64 bit architecture" id="oval:ssg-state_system_info_architecture_ppcle_64:ste:1" operator="AND" version="1">
          <unix:processor_type operation="equals">ppc64le</unix:processor_type>
        </unix:uname_state>
        <unix:uname_state comment="64 bit architecture" id="oval:ssg-state_system_info_architecture_s390_64:ste:1" operator="AND" version="1">
          <unix:processor_type operation="equals">s390x</unix:processor_type>
        </unix:uname_state>
        <unix:uname_state comment="32 bit architecture" id="oval:ssg-state_system_info_architecture_x86:ste:1" operator="AND" version="1">
          <unix:processor_type operation="equals">i686</unix:processor_type>
        </unix:uname_state>
        <unix:uname_state comment="64 bit architecture" id="oval:ssg-state_system_info_architecture_x86_64:ste:1" operator="AND" version="1">
          <unix:processor_type operation="equals">x86_64</unix:processor_type>
        </unix:uname_state>
        <unix:file_state id="oval:ssg-state_tmux_conf_readable_by_others:ste:1" operator="AND" version="1">
          <unix:oread datatype="boolean">true</unix:oread>
        </unix:file_state>
        <ind:variable_state id="oval:ssg-state_var_removable_partition_is_cd_dvd_drive:ste:1" operator="AND" version="1">
          <ind:value operation="equals">/dev/cdrom</ind:value>
        </ind:variable_state>
      </oval-def:states>
      <oval-def:variables>
        <oval-def:external_variable comment="external variable for audit failure mode" datatype="string" id="oval:ssg-var_audit_failure_mode:var:1" version="1"/>
        <oval-def:local_variable comment="path to audit log directory" datatype="string" id="oval:ssg-audit_log_dir_group_ownership:var:1" version="1">
          <oval-def:regex_capture pattern="^(.*)\/([^\/]+$)">
            <oval-def:variable_component var_ref="oval:ssg-audit_log_file_path:var:1"/>
          </oval-def:regex_capture>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Path to log_file" datatype="string" id="oval:ssg-var_directory_ownership_var_log_audit_path:var:1" version="1">
          <oval-def:object_component item_field="path" object_ref="oval:ssg-object_directory_ownership_var_log_audit_file:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="path to audit log directory" datatype="string" id="oval:ssg-audit_log_dir:var:1" version="1">
          <oval-def:regex_capture pattern="^(.*)\/([^\/]+$)">
            <oval-def:variable_component var_ref="oval:ssg-audit_log_file_path:var:1"/>
          </oval-def:regex_capture>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Mount points where suid or sgid files can be executed" datatype="string" id="oval:ssg-var_audit_rules_privileged_commands_exec_mountpoints:var:1" version="1">
          <oval-def:object_component item_field="mount_point" object_ref="oval:ssg-object_audit_rules_privileged_commands_exec_partitions:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Regex for auditd rule" datatype="string" id="oval:ssg-var_audit_rules_privileged_commands_rule_regex:var:1" version="1">
          <oval-def:literal_component>^[\s]*-a always,exit (?:-F path=([\S]+))+(?: -F perm=x)? -F auid&gt;=1000 -F auid!=(?:4294967295|unset)[\s]+(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Filepath of all privileged commands found in the system" datatype="string" id="oval:ssg-var_audit_rules_privileged_commands_priv_cmds:var:1" version="1">
          <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_audit_rules_privileged_commands:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count all privileged commands present in the system" datatype="int" id="oval:ssg-var_audit_rules_privileged_commands_priv_cmds_count:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_audit_rules_privileged_commands:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count privileged commands found in audit rules in augenrules format" datatype="int" id="oval:ssg-var_priv_cmds_from_augenrules_count:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_priv_cmds_from_augenrules:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count privileged commands found in audit rules in auditctl format" datatype="int" id="oval:ssg-var_priv_cmds_from_auditctl_count:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_priv_cmds_from_auditctl:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Filepath of all privileged commands found in the system" datatype="string" id="oval:ssg-var_audit_rules_privileged_commands_priv_cmds_bootc:var:1" version="1">
          <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_audit_rules_privileged_commands_bootc:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count all privileged commands present in the system" datatype="int" id="oval:ssg-var_audit_rules_privileged_commands_priv_cmds_count_bootc:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_audit_rules_privileged_commands_bootc:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count privileged commands found in audit rules in augenrules format" datatype="int" id="oval:ssg-var_priv_cmds_from_augenrules_count_bootc:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_priv_cmds_from_augenrules_bootc:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count privileged commands found in audit rules in auditctl format" datatype="int" id="oval:ssg-var_priv_cmds_from_auditctl_count_bootc:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_priv_cmds_from_auditctl_bootc:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:external_variable comment="audispd remote_server setting" datatype="string" id="oval:ssg-var_audispd_remote_server:var:1" version="1"/>
        <oval-def:external_variable comment="audispd network failure action" datatype="string" id="oval:ssg-var_audispd_disk_full_action:var:1" version="1"/>
        <oval-def:external_variable comment="audispd network failure action" datatype="string" id="oval:ssg-var_audispd_network_failure_action:var:1" version="1"/>
        <oval-def:local_variable comment="Build regex to be case insensitive" datatype="string" id="oval:ssg-var_auditd_disk_error_action_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>(?i)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_auditd_disk_error_action:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="audit disk_error_action setting" datatype="string" id="oval:ssg-var_auditd_disk_error_action:var:1" version="1"/>
        <oval-def:local_variable comment="Build regex to be case insensitive" datatype="string" id="oval:ssg-var_auditd_disk_full_action_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>(?i)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_auditd_disk_full_action:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="audit disk_full_action setting" datatype="string" id="oval:ssg-var_auditd_disk_full_action:var:1" version="1"/>
        <oval-def:external_variable comment="audit action_mail_acct setting" datatype="string" id="oval:ssg-var_auditd_action_mail_acct:var:1" version="1"/>
        <oval-def:local_variable comment="Build regex to be case insensitive" datatype="string" id="oval:ssg-var_auditd_admin_space_left_action_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>(?i)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_auditd_admin_space_left_action:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="audit admin_space_left_action setting" datatype="string" id="oval:ssg-var_auditd_admin_space_left_action:var:1" version="1"/>
        <oval-def:external_variable comment="audit admin_space_left setting" datatype="int" id="oval:ssg-var_auditd_admin_space_left_percentage:var:1" version="1"/>
        <oval-def:external_variable comment="audit flush setting" datatype="string" id="oval:ssg-var_auditd_flush:var:1" version="1"/>
        <oval-def:external_variable comment="audit max_log_file setting" datatype="int" id="oval:ssg-var_auditd_max_log_file:var:1" version="1"/>
        <oval-def:external_variable comment="audit max_log_file_action setting" datatype="string" id="oval:ssg-var_auditd_max_log_file_action:var:1" version="1"/>
        <oval-def:external_variable comment="audit num_logs setting" datatype="int" id="oval:ssg-var_auditd_num_logs:var:1" version="1"/>
        <oval-def:external_variable comment="audit space_left setting" datatype="int" id="oval:ssg-var_auditd_space_left:var:1" version="1"/>
        <oval-def:local_variable comment="Build regex to be case insensitive" datatype="string" id="oval:ssg-var_auditd_space_left_action_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>(?i)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_auditd_space_left_action:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="audit space_left_action setting" datatype="string" id="oval:ssg-var_auditd_space_left_action:var:1" version="2"/>
        <oval-def:external_variable comment="audit space_left setting" datatype="int" id="oval:ssg-var_auditd_space_left_percentage:var:1" version="1"/>
        <oval-def:local_variable comment="Build regex to be case insensitive" datatype="string" id="oval:ssg-var_auditd_name_format_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>(?i)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_auditd_name_format:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="audit name_format setting" datatype="string" id="oval:ssg-var_auditd_name_format:var:1" version="1"/>
        <oval-def:local_variable comment="Contents of reference file in /usr/share/doc/10-base-config.rules" datatype="string" id="oval:ssg-var_doc_10-base-config:var:1" version="1">
          <oval-def:object_component item_field="text" object_ref="oval:ssg-object_doc_10-base-config:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Contents of reference file in /usr/share/doc/11-loginuid.rules" datatype="string" id="oval:ssg-var_doc_11-loginuid:var:1" version="1">
          <oval-def:object_component item_field="text" object_ref="oval:ssg-object_doc_11-loginuid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Contents of reference file in /usr/share/doc/30-ospp-v42.rules" datatype="string" id="oval:ssg-var_doc_30-ospp-v42:var:1" version="1">
          <oval-def:object_component item_field="text" object_ref="oval:ssg-object_doc_30-ospp-v42:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Contents of reference file in /usr/share/doc/43-module-load.rules" datatype="string" id="oval:ssg-var_doc_43-module-load:var:1" version="1">
          <oval-def:object_component item_field="text" object_ref="oval:ssg-object_doc_43-module-load:obj:1"/>
        </oval-def:local_variable>
        <oval-def:external_variable comment="expected email alias" datatype="string" id="oval:ssg-var_postfix_root_mail_alias:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for postfix inet_interfaces" datatype="string" id="oval:ssg-var_postfix_inet_interfaces:var:1" version="1"/>
        <oval-def:external_variable comment="maxpoll value" datatype="int" id="oval:ssg-var_time_service_set_maxpoll:var:1" version="1"/>
        <oval-def:local_variable comment="Construct glob patterns for .sources files" datatype="string" id="oval:ssg-var_sourcedir_file_paths:var:1" version="1">
          <oval-def:concat>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_extract_sourcedir_paths:obj:1"/>
            <oval-def:literal_component>/*.sources</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Convert to regex for filepath matching" datatype="string" id="oval:ssg-var_sourcedir_file_paths_regex:var:1" version="1">
          <oval-def:glob_to_regex>
            <oval-def:variable_component var_ref="oval:ssg-var_sourcedir_file_paths:var:1"/>
          </oval-def:glob_to_regex>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Construct glob patterns for .conf files" datatype="string" id="oval:ssg-var_confdir_file_paths:var:1" version="1">
          <oval-def:concat>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_extract_confdir_paths:obj:1"/>
            <oval-def:literal_component>/*.conf</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Convert to regex for filepath matching" datatype="string" id="oval:ssg-var_confdir_file_paths_regex:var:1" version="1">
          <oval-def:glob_to_regex>
            <oval-def:variable_component var_ref="oval:ssg-var_confdir_file_paths:var:1"/>
          </oval-def:glob_to_regex>
        </oval-def:local_variable>
        <oval-def:local_variable comment="gid of the dedicated chrony group" datatype="int" id="oval:ssg-var_dedicated_groupowner_etc_chrony_keys_uid_chrony:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupowner_etc_chrony_keys_etc_group:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="gid of the dedicated chrony group" datatype="int" id="oval:ssg-var_dedicated_groupowner_etc_chrony_keys_uid_chrony_with_usrlib:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupowner_etc_chrony_keys_etc_group_with_usrlib:obj:1"/>
        </oval-def:local_variable>
        <oval-def:external_variable comment="TFTP server secure directory" datatype="string" id="oval:ssg-var_tftpd_secure_directory:var:1" version="1"/>
        <oval-def:local_variable comment="Count of all group names (including duplicates if any)" datatype="int" id="oval:ssg-group_gid:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_dedicated_group_gid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The regex of the directive" datatype="string" id="oval:ssg-ssh_client_line_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^[\s]*RekeyLimit[\s]+</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_ssh_client_rekey_limit_size:var:1"/>
            <oval-def:literal_component>[\s]+</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_ssh_client_rekey_limit_time:var:1"/>
            <oval-def:literal_component>[\s]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Size component of the rekey limit" datatype="string" id="oval:ssg-var_ssh_client_rekey_limit_size:var:1" version="1"/>
        <oval-def:external_variable comment="Time component of the rekey limit" datatype="string" id="oval:ssg-var_ssh_client_rekey_limit_time:var:1" version="1"/>
        <oval-def:local_variable comment="Regex containing the list of zones files delivered in the firewalld package" datatype="string" id="oval:ssg-var_firewalld_sshd_port_enabled_default_zones:var:1" version="1">
          <oval-def:literal_component>^(dmz|external|home|internal|public|trusted|work)\.xml$</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including number of custom zone files allowing ssh" datatype="int" id="oval:ssg-var_firewalld_sshd_port_enabled_custom_zone_files_with_ssh_count:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_firewalld_sshd_port_enabled_zone_files_etc:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including number of custom zone files present in /etc/firewalld/zones" datatype="int" id="oval:ssg-var_firewalld_sshd_port_enabled_custom_zone_files_count:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_firewalld_sshd_port_enabled_custom_zone_files:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:external_variable comment="external variable containing the expected SSH port" datatype="int" id="oval:ssg-sshd_listening_port:var:1" version="1"/>
        <oval-def:local_variable comment="The regex of the directive" datatype="string" id="oval:ssg-sshd_line_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_rekey_limit_size:var:1"/>
            <oval-def:literal_component>[\s]+</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_rekey_limit_time:var:1"/>
            <oval-def:literal_component>[\s]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Size component of the rekey limit" datatype="string" id="oval:ssg-var_rekey_limit_size:var:1" version="1"/>
        <oval-def:external_variable comment="Time component of the rekey limit" datatype="string" id="oval:ssg-var_rekey_limit_time:var:1" version="1"/>
        <oval-def:external_variable comment="timeout value" datatype="int" id="oval:ssg-sshd_idle_timeout_value:var:1" version="1"/>
        <oval-def:external_variable comment="logingracetime value" datatype="int" id="oval:ssg-var_sshd_set_login_grace_time:var:1" version="1"/>
        <oval-def:external_variable comment="MaxAuthTries value" datatype="int" id="oval:ssg-sshd_max_auth_tries_value:var:1" version="1"/>
        <oval-def:external_variable comment="maxsessions value" datatype="int" id="oval:ssg-var_sshd_max_sessions:var:1" version="1"/>
        <oval-def:external_variable comment="Expected value for MaxStartups parameter" datatype="string" id="oval:ssg-var_sshd_set_maxstartups:var:1" version="1"/>
        <oval-def:local_variable comment="First number from MaxStartup parameter value." datatype="int" id="oval:ssg-var_sshd_set_maxstartups_first:var:1" version="1">
          <oval-def:regex_capture pattern="(\d+):\d+:\d+">
            <oval-def:variable_component var_ref="oval:ssg-var_sshd_set_maxstartups:var:1"/>
          </oval-def:regex_capture>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Second number from MaxStartup parameter value." datatype="int" id="oval:ssg-var_sshd_set_maxstartups_second:var:1" version="1">
          <oval-def:regex_capture pattern="\d+:(\d+):\d+">
            <oval-def:variable_component var_ref="oval:ssg-var_sshd_set_maxstartups:var:1"/>
          </oval-def:regex_capture>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Third number from MaxStartup parameter value." datatype="int" id="oval:ssg-var_sshd_set_maxstartups_third:var:1" version="1">
          <oval-def:regex_capture pattern="\d+:\d+:(\d+)">
            <oval-def:variable_component var_ref="oval:ssg-var_sshd_set_maxstartups:var:1"/>
          </oval-def:regex_capture>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Ciphers values split on comma" datatype="string" id="oval:ssg-var_sshd_config_ciphers:var:1" version="1">
          <oval-def:split delimiter=",">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_sshd_config_ciphers:obj:1"/>
          </oval-def:split>
        </oval-def:local_variable>
        <oval-def:local_variable comment="approved ciphers values split on comma" datatype="string" id="oval:ssg-var_sshd_approved_ciphers:var:1" version="1">
          <oval-def:split delimiter=",">
            <oval-def:variable_component var_ref="oval:ssg-sshd_approved_ciphers:var:1"/>
          </oval-def:split>
        </oval-def:local_variable>
        <oval-def:external_variable comment="SSH Approved Ciphers by FIPS" datatype="string" id="oval:ssg-sshd_approved_ciphers:var:1" version="1"/>
        <oval-def:local_variable comment="MACs values split on comma" datatype="string" id="oval:ssg-var_sshd_config_macs:var:1" version="1">
          <oval-def:split delimiter=",">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_sshd_config_macs:obj:1"/>
          </oval-def:split>
        </oval-def:local_variable>
        <oval-def:local_variable comment="approved MACs values split on comma" datatype="string" id="oval:ssg-var_sshd_approved_macs:var:1" version="1">
          <oval-def:split delimiter=",">
            <oval-def:variable_component var_ref="oval:ssg-sshd_approved_macs:var:1"/>
          </oval-def:split>
        </oval-def:local_variable>
        <oval-def:external_variable comment="SSH Approved MACs by FIPS" datatype="string" id="oval:ssg-sshd_approved_macs:var:1" version="1"/>
        <oval-def:local_variable comment="KEXs values split on comma" datatype="string" id="oval:ssg-var_sshd_config_kex:var:1" version="1">
          <oval-def:split delimiter=",">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_sshd_config_kex:obj:1"/>
          </oval-def:split>
        </oval-def:local_variable>
        <oval-def:local_variable comment="approved strong KEX values split on comma" datatype="string" id="oval:ssg-var_sshd_strong_kex:var:1" version="1">
          <oval-def:split delimiter=",">
            <oval-def:variable_component var_ref="oval:ssg-sshd_strong_kex:var:1"/>
          </oval-def:split>
        </oval-def:local_variable>
        <oval-def:external_variable comment="SSH Approved KEX by FIPS" datatype="string" id="oval:ssg-sshd_strong_kex:var:1" version="1"/>
        <oval-def:local_variable comment="MACs values split on comma" datatype="string" id="oval:ssg-var_sshd_config_strong_macs:var:1" version="1">
          <oval-def:split delimiter=",">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_sshd_config_strong_macs:obj:1"/>
          </oval-def:split>
        </oval-def:local_variable>
        <oval-def:local_variable comment="strong MACs values split on comma" datatype="string" id="oval:ssg-var_sshd_strong_macs:var:1" version="1">
          <oval-def:split delimiter=",">
            <oval-def:variable_component var_ref="oval:ssg-sshd_strong_macs:var:1"/>
          </oval-def:split>
        </oval-def:local_variable>
        <oval-def:external_variable comment="SSH MAC algorithms considered strong" datatype="string" id="oval:ssg-sshd_strong_macs:var:1" version="1"/>
        <oval-def:external_variable comment="certificate_verification value" datatype="string" id="oval:ssg-var_sssd_certificate_verification_digest_function:var:1" version="1"/>
        <oval-def:external_variable comment="memcache_timeout value" datatype="int" id="oval:ssg-var_sssd_memcache_timeout:var:1" version="1"/>
        <oval-def:external_variable comment="var_sssd_ssh_known_hosts_timeout value" datatype="int" id="oval:ssg-var_sssd_ssh_known_hosts_timeout:var:1" version="1"/>
        <oval-def:external_variable comment="External variable: path of the X.509 certificates in /etc/sssd/sssd.conf" datatype="string" id="oval:ssg-var_sssd_ldap_tls_ca_dir:var:1" version="1"/>
        <oval-def:external_variable comment="warning banner text variable" datatype="string" id="oval:ssg-login_banner_text:var:1" version="1"/>
        <oval-def:external_variable comment="warning banner text variable" datatype="string" id="oval:ssg-remote_login_banner_text:var:1" version="1"/>
        <oval-def:external_variable comment="warning banner text variable" datatype="string" id="oval:ssg-motd_banner_text:var:1" version="1"/>
        <oval-def:external_variable comment="warning banner text variable" datatype="string" id="oval:ssg-dconf_login_banner_text:var:1" version="1"/>
        <oval-def:local_variable comment="Current authselect profile name" datatype="string" id="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_authselect_profile:var:1" version="1">
          <oval-def:regex_capture pattern="^(.+)$">
            <oval-def:object_component item_field="text" object_ref="oval:ssg-obj_accounts_password_pam_modules_in_authselect_profile_authselect_profile:obj:1"/>
          </oval-def:regex_capture>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Full path to system-auth in current profile" datatype="string" id="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_pam_pwquality_system_auth_path:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>/etc/authselect/</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_authselect_profile:var:1"/>
            <oval-def:literal_component>/system-auth</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Full path to system-auth in current profile" datatype="string" id="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_pam_pwhistory_system_auth_path:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>/etc/authselect/</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_authselect_profile:var:1"/>
            <oval-def:literal_component>/system-auth</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Full path to system-auth in current profile" datatype="string" id="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_pam_faillock_system_auth_path:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>/etc/authselect/</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_authselect_profile:var:1"/>
            <oval-def:literal_component>/system-auth</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Full path to system-auth in current profile" datatype="string" id="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_pam_unix_system_auth_path:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>/etc/authselect/</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_authselect_profile:var:1"/>
            <oval-def:literal_component>/system-auth</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Full path to password-auth in current profile" datatype="string" id="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_pam_pwquality_password_auth_path:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>/etc/authselect/</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_authselect_profile:var:1"/>
            <oval-def:literal_component>/password-auth</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Full path to password-auth in current profile" datatype="string" id="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_pam_pwhistory_password_auth_path:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>/etc/authselect/</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_authselect_profile:var:1"/>
            <oval-def:literal_component>/password-auth</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Full path to password-auth in current profile" datatype="string" id="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_pam_faillock_password_auth_path:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>/etc/authselect/</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_authselect_profile:var:1"/>
            <oval-def:literal_component>/password-auth</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Full path to password-auth in current profile" datatype="string" id="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_pam_unix_password_auth_path:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>/etc/authselect/</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_accounts_password_pam_modules_in_authselect_profile_authselect_profile:var:1"/>
            <oval-def:literal_component>/password-auth</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entries in auth section of pam files" datatype="string" id="oval:ssg-var_pam_faillock_password_auth_pam_faillock_auth_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+preauth[\s\S]*^[\s]*auth[\s]+(sufficient|\[(?=.*\bsuccess=done\b)(?=.*?\bnew_authtok_reqd=done\b)(?=.*?\bdefault=ignore\b).*\])[\s]+pam_unix\.so[\s\S]*^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+authfail</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entry in account section of pam files" datatype="string" id="oval:ssg-var_pam_faillock_password_auth_pam_faillock_account_regex:var:1" version="1">
          <oval-def:value>^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\S]*^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_unix\.so</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entries in auth section of pam files" datatype="string" id="oval:ssg-var_pam_faillock_system_auth_pam_faillock_auth_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+preauth[\s\S]*^[\s]*auth[\s]+(sufficient|\[(?=.*\bsuccess=done\b)(?=.*?\bnew_authtok_reqd=done\b)(?=.*?\bdefault=ignore\b).*\])[\s]+pam_unix\.so[\s\S]*^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+authfail</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entry in account section of pam files" datatype="string" id="oval:ssg-var_pam_faillock_system_auth_pam_faillock_account_regex:var:1" version="1">
          <oval-def:value>^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\S]*^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_unix\.so</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="List of directories defined in pam_faillock.so dir parameters" datatype="string" id="oval:ssg-var_account_password_selinux_faillock_dir_collector:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_account_password_selinux_faillock_dir_collector:obj:1"/>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="regex to identify audit parameter in pam files" datatype="string" id="oval:ssg-var_account_pam_faillock_audit_parameter_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth[\s]+(?:required|requisite)[\s]+pam_faillock.so[^\n#]preauth[^\n#]*audit</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:external_variable comment="number of passwords that should be remembered" datatype="int" id="oval:ssg-var_password_pam_remember:var:1" version="1"/>
        <oval-def:local_variable comment="The regex is to confirm the pam_pwhistory.so module is enabled" datatype="string" id="oval:ssg-var_accounts_password_pam_pwhistory_remember_password_auth_module_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\s*password\s+(?:</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_possible_control_flags_password_auth:var:1"/>
            <oval-def:literal_component>)\s+pam_pwhistory\.so.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="All accepted control flags" datatype="string" id="oval:ssg-var_possible_control_flags_password_auth:var:1" version="1">
          <oval-def:split delimiter=",">
            <oval-def:variable_component var_ref="oval:ssg-var_password_pam_remember_control_flag:var:1"/>
          </oval-def:split>
        </oval-def:local_variable>
        <oval-def:external_variable comment="control flag for pwhistory module" datatype="string" id="oval:ssg-var_password_pam_remember_control_flag:var:1" version="1"/>
        <oval-def:local_variable comment="The regex is to collect the pam_pwhistory.so remember parameter from PAM files" datatype="string" id="oval:ssg-var_accounts_password_pam_pwhistory_remember_password_auth_pam_param_regex:var:1" version="1">
          <oval-def:literal_component>^\s*password\b.*\bpam_pwhistory\.so\b.*\bremember=([0-9]*).*$</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The regex is to collect the pam_pwhistory.so remember parameter in pwhistory.conf" datatype="string" id="oval:ssg-var_accounts_password_pam_pwhistory_remember_password_auth_conf_param_regex:var:1" version="1">
          <oval-def:literal_component>^\s*remember\s*=\s*([0-9]+)</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The regex is to confirm the pam_pwhistory.so module is enabled" datatype="string" id="oval:ssg-var_accounts_password_pam_pwhistory_remember_system_auth_module_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\s*password\s+(?:</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_possible_control_flags_system_auth:var:1"/>
            <oval-def:literal_component>)\s+pam_pwhistory\.so.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="All accepted control flags" datatype="string" id="oval:ssg-var_possible_control_flags_system_auth:var:1" version="1">
          <oval-def:split delimiter=",">
            <oval-def:variable_component var_ref="oval:ssg-var_password_pam_remember_control_flag:var:1"/>
          </oval-def:split>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The regex is to collect the pam_pwhistory.so remember parameter from PAM files" datatype="string" id="oval:ssg-var_accounts_password_pam_pwhistory_remember_system_auth_pam_param_regex:var:1" version="1">
          <oval-def:literal_component>^\s*password\b.*\bpam_pwhistory\.so\b.*\bremember=([0-9]*).*$</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The regex is to collect the pam_pwhistory.so remember parameter in pwhistory.conf" datatype="string" id="oval:ssg-var_accounts_password_pam_pwhistory_remember_system_auth_conf_param_regex:var:1" version="1">
          <oval-def:literal_component>^\s*remember\s*=\s*([0-9]+)</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:external_variable comment="number of passwords that should be remembered" datatype="int" id="oval:ssg-var_password_pam_unix_remember:var:1" version="1"/>
        <oval-def:local_variable comment="The regex is to confirm the pam_pwhistory.so module is enabled" datatype="string" id="oval:ssg-var_accounts_password_pam_unix_remember_module_regex:var:1" version="1">
          <oval-def:literal_component>^\s*password\s+(?:(?:requisite)|(?:required))\s+pam_pwhistory\.so.*$</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The regex is to collect the pam_pwhistory.so remember parameter from PAM files" datatype="string" id="oval:ssg-var_accounts_password_pam_unix_remember_pam_param_regex:var:1" version="1">
          <oval-def:literal_component>^\s*password\b.*\bpam_pwhistory\.so\b.*\bremember=([0-9]*).*$</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The regex is to collect the pam_pwhistory.so remember parameter in /etc/security/pwhistory.conf" datatype="string" id="oval:ssg-var_accounts_password_pam_unix_remember_conf_param_regex:var:1" version="1">
          <oval-def:literal_component>^\s*remember\s*=\s*([0-9]+)</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="regex to identify audit parameter in pam files" datatype="string" id="oval:ssg-var_pam_faillock_audit_parameter_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth[\s]+(?:required|requisite)[\s]+pam_faillock.so[^\n#]preauth[^\n#]*audit</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_unix.so in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_deny_root_pam_unix_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth\N+pam_unix\.so</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entries in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_deny_root_pam_faillock_auth_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+preauth[\s\S]*^[\s]*auth[\s]+(sufficient|\[(?=.*\bsuccess=done\b)(?=.*?\bnew_authtok_reqd=done\b)(?=.*?\bdefault=ignore\b).*\])[\s]+pam_unix\.so[\s\S]*^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+authfail</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entry in account section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_deny_root_pam_faillock_account_regex:var:1" version="1">
          <oval-def:value>^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\S]*^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_unix\.so</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so deny entry in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_deny_root_pam_faillock_parameter_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth[\s]+.+[\s]+pam_faillock.so[\s]+[^\n]*even_deny_root</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify deny entry in /etc/security/faillock.conf" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_deny_root_faillock_conf_parameter_regex:var:1" version="1">
          <oval-def:value>^[\s]*even_deny_root</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="common regex to identify dir entry" datatype="string" id="oval:ssg-var_faillock_dir_parameter_regex:var:1" version="1">
          <oval-def:value>dir\s*=\s*(\S+|"[^"]+)</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="regex to identify dir parameter in pam files" datatype="string" id="oval:ssg-var_pam_faillock_dir_parameter_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^[\s]*auth[\s]+(?:required|requisite)</oval-def:literal_component>
            <oval-def:literal_component>[\s]+pam_faillock.so[^\n#]*</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_faillock_dir_parameter_regex:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="regex to identify dir parameter in faillock.conf file" datatype="string" id="oval:ssg-var_faillock_conf_dir_parameter_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^[\s]*</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_faillock_dir_parameter_regex:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Counts the unique occurrences of preauth and authfail so if it is two, it       demonstrates both are present, this takes the results from system-auth file" datatype="int" id="oval:ssg-var_faillock_dir_set_both_preauth_authfail_system_auth:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:regex_capture pattern="(authfail|preauth)">
                <oval-def:object_component item_field="text" object_ref="oval:ssg-obj_all_pam_faillock_dir_parameter_system_auth:obj:1"/>
              </oval-def:regex_capture>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Counts the unique occurrences of preauth and authfail so if it is two, it       demonstrates both are present, this takes the results from password-auth file" datatype="int" id="oval:ssg-var_faillock_dir_set_both_preauth_authfail_password_auth:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:regex_capture pattern="(authfail|preauth)">
                <oval-def:object_component item_field="text" object_ref="oval:ssg-obj_all_pam_faillock_dir_parameter_password_auth:obj:1"/>
              </oval-def:regex_capture>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="regex to identify pam_unix.so in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_enforce_local_pam_unix_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth\N+pam_unix\.so</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entries in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_enforce_local_pam_faillock_auth_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+preauth[\s\S]*^[\s]*auth[\s]+(sufficient|\[(?=.*\bsuccess=done\b)(?=.*?\bnew_authtok_reqd=done\b)(?=.*?\bdefault=ignore\b).*\])[\s]+pam_unix\.so[\s\S]*^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+authfail</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entry in account section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_enforce_local_pam_faillock_account_regex:var:1" version="1">
          <oval-def:value>^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\S]*^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_unix\.so</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify deny entry in /etc/security/faillock.conf" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_enforce_local_faillock_conf_parameter_regex:var:1" version="1">
          <oval-def:value>^[\s]*local_users_only</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_unix.so in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_pam_unix_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth\N+pam_unix\.so</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entries in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_pam_faillock_auth_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+preauth[\s\S]*^[\s]*auth[\s]+(sufficient|\[(?=.*\bsuccess=done\b)(?=.*?\bnew_authtok_reqd=done\b)(?=.*?\bdefault=ignore\b).*\])[\s]+pam_unix\.so[\s\S]*^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+authfail</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entry in account section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_pam_faillock_account_regex:var:1" version="1">
          <oval-def:value>^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\S]*^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_unix\.so</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify even_deny_root in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_parameter_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth[\s]+.+[\s]+pam_faillock.so[\s]+[^\n]*even_deny_root</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify even_deny_root in /etc/security/faillock.conf" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_even_deny_root_faillock_conf_regex:var:1" version="1">
          <oval-def:value>^[\s]*even_deny_root</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify root_unlock_time in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_parameter_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth[\s]+.+[\s]+pam_faillock.so[\s]+[^\n]*root_unlock_time=([0-9]+)</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify root_unlock_time in /etc/security/faillock.conf" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_root_unlock_time_faillock_conf_regex:var:1" version="1">
          <oval-def:value>^[\s]*root_unlock_time[\s]*=[\s]*([0-9]+)</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:external_variable comment="root_unlock_time minimum value" datatype="int" id="oval:ssg-var_accounts_passwords_pam_faillock_root_unlock_time:var:1" version="1"/>
        <oval-def:constant_variable comment="regex to identify silent parameter in pam files" datatype="string" id="oval:ssg-var_pam_faillock_silent_parameter_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth[\s]+(?:required|requisite)[\s]+pam_faillock.so[^\n#]+preauth[^\n#]+silent</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_unix.so in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_with_zero_pam_unix_regex:var:1" version="2">
          <oval-def:value>^\s*auth\N+pam_unix\.so</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entries in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_with_zero_pam_faillock_auth_regex:var:1" version="2">
          <oval-def:value>^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+preauth[\s\S]*^[\s]*auth[\s]+(sufficient|\[(?=.*\bsuccess=done\b)(?=.*?\bnew_authtok_reqd=done\b)(?=.*?\bdefault=ignore\b).*\])[\s]+pam_unix\.so[\s\S]*^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+authfail</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entry in account section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_with_zero_pam_faillock_account_regex:var:1" version="2">
          <oval-def:value>^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\S]*^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_unix\.so</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so unlock_time entry in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_with_zero_pam_faillock_unlock_time_parameter_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth[\s]+.+[\s]+pam_faillock.so[\s]+[^\n]*unlock_time=([0-9]+)</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify unlock_time entry in /etc/security/faillock.conf" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_with_zero_faillock_conf_unlock_time_parameter_regex:var:1" version="1">
          <oval-def:value>^[\s]*unlock_time[\s]*=[\s]*([0-9]+)</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:external_variable comment="external variable to use" datatype="int" id="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for pam_pwquality retry" datatype="int" id="oval:ssg-var_password_pam_retry:var:1" version="1"/>
        <oval-def:external_variable comment="hashing algorithm for pam_unix.so" datatype="string" id="oval:ssg-var_password_hashing_algorithm_pam:var:1" version="1"/>
        <oval-def:local_variable comment="The value of ENCRYPT_METHOD in /etc/login.defs" datatype="string" id="oval:ssg-local_variable_test_password_hashing_algorithm_logindefs:var:1" version="1">
          <oval-def:regex_capture pattern="ENCRYPT_METHOD\s+(\w+)">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_test_password_hashing_algorithm_logindefs:obj:1"/>
          </oval-def:regex_capture>
        </oval-def:local_variable>
        <oval-def:external_variable comment="External variable var_password_hashing_algorithm" datatype="string" id="oval:ssg-var_password_hashing_algorithm:var:1" version="1"/>
        <oval-def:local_variable comment="Limit regex" datatype="string" id="oval:ssg-var_password_hashing_algorithm_pam_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_password_hashing_algorithm_pam:var:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="variable storing number of password hashing rounds" datatype="int" id="oval:ssg-local_var_password_hashing_min_rounds_login_defs:var:1" version="1">
          <oval-def:variable_component var_ref="oval:ssg-var_password_hashing_min_rounds_login_defs:var:1"/>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Variable defining the value the argument should have" datatype="int" id="oval:ssg-var_password_hashing_min_rounds_login_defs:var:1" version="1"/>
        <oval-def:external_variable comment="idle session timeout in seconds" datatype="int" id="oval:ssg-var_logind_session_timeout:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for opensc smartcard drivers" datatype="string" id="oval:ssg-var_smartcard_drivers:var:1" version="1"/>
        <oval-def:local_variable comment="Count of all uids (including duplicates if any)" datatype="int" id="oval:ssg-variable_count_of_all_uids:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="user_id" object_ref="oval:ssg-obj_all_uids:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count of unique uids" datatype="int" id="oval:ssg-variable_count_of_unique_uids:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="user_id" object_ref="oval:ssg-obj_all_uids:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:external_variable comment="accounts authorized local users on operating system" datatype="string" id="oval:ssg-var_accounts_authorized_local_users_regex:var:1" version="1"/>
        <oval-def:local_variable comment="Count of all group ids (including duplicates if any)" datatype="int" id="oval:ssg-variable_count_of_all_group_ids:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_all_group_ids:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count of unique group ids" datatype="int" id="oval:ssg-variable_count_of_unique_group_ids:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_all_group_ids:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count of all group names (including duplicates if any)" datatype="int" id="oval:ssg-variable_count_of_all_group_names:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_all_group_names:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count of unique group names" datatype="int" id="oval:ssg-variable_count_of_unique_group_names:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_all_group_names:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:external_variable comment="inactive days expiration" datatype="int" id="oval:ssg-var_account_disable_post_pw_expiration:var:1" version="1"/>
        <oval-def:local_variable comment="Count of all username rows retrieved from /etc/passwd (including duplicates if any)" datatype="int" id="oval:ssg-variable_count_of_all_usernames_from_etc_passwd:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_etc_passwd_content:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count of unique username rows retrieved from /etc/passwd" datatype="int" id="oval:ssg-variable_count_of_unique_usernames_from_etc_passwd:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_etc_passwd_content:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The value of last PASS_MAX_DAYS directive in /etc/login.defs" datatype="int" id="oval:ssg-variable_last_pass_max_days_instance_value:var:1" version="1">
          <oval-def:regex_capture pattern="PASS_MAX_DAYS\s+(\d+)">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_last_pass_max_days_from_etc_login_defs:obj:1"/>
          </oval-def:regex_capture>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Maximum password age" datatype="int" id="oval:ssg-var_accounts_maximum_age_login_defs:var:1" version="1"/>
        <oval-def:local_variable comment="The value of last PASS_MIN_DAYS directive in /etc/login.defs" datatype="int" id="oval:ssg-variable_last_pass_min_days_instance_value:var:1" version="1">
          <oval-def:regex_capture pattern="PASS_MIN_DAYS\s+(\d+)">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_last_pass_min_days_from_etc_login_defs:obj:1"/>
          </oval-def:regex_capture>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Minimum password age in days" datatype="int" id="oval:ssg-var_accounts_minimum_age_login_defs:var:1" version="1"/>
        <oval-def:local_variable comment="The value of last PASS_MIN_LEN directive in /etc/login.defs" datatype="int" id="oval:ssg-variable_last_pass_min_len_instance_value:var:1" version="1">
          <oval-def:regex_capture pattern="PASS_MIN_LEN\s+(\d+)">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_last_pass_min_len_from_etc_login_defs:obj:1"/>
          </oval-def:regex_capture>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Password minimum length" datatype="int" id="oval:ssg-var_accounts_password_minlen_login_defs:var:1" version="1"/>
        <oval-def:external_variable comment="maximum password age in days" datatype="int" id="oval:ssg-var_accounts_maximum_age_root:var:1" version="1"/>
        <oval-def:external_variable comment="External variable" datatype="int" id="oval:ssg-var_accounts_password_warn_age_login_defs:var:1" version="1"/>
        <oval-def:local_variable comment="The value of PASS_WARN_AGE in /etc/login.defs" datatype="int" id="oval:ssg-local_variable_test_pass_warn_age:var:1" version="1">
          <oval-def:regex_capture pattern="PASS_WARN_AGE\s+(\d+)">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_test_pass_warn_age:obj:1"/>
          </oval-def:regex_capture>
        </oval-def:local_variable>
        <oval-def:local_variable comment="last change field of shadow entry in seconds" datatype="int" id="oval:ssg-var_accounts_password_last_change_is_in_past_time_in_secs:var:1" version="1">
          <oval-def:arithmetic arithmetic_operation="multiply">
            <oval-def:object_component item_field="chg_lst" object_ref="oval:ssg-object_accounts_password_last_change_is_in_past:obj:1"/>
            <oval-def:literal_component datatype="int">86400</oval-def:literal_component>
          </oval-def:arithmetic>
        </oval-def:local_variable>
        <oval-def:local_variable comment="time difference between the last change field of shadow entry and the current time" datatype="int" id="oval:ssg-var_accounts_password_last_change_is_in_past_time_diff:var:1" version="1">
          <oval-def:time_difference format_2="seconds_since_epoch">
            <oval-def:variable_component var_ref="oval:ssg-var_accounts_password_last_change_is_in_past_time_in_secs:var:1"/>
          </oval-def:time_difference>
        </oval-def:local_variable>
        <oval-def:local_variable comment="the current time in seconds since epoch" datatype="int" id="oval:ssg-var_accounts_password_last_change_is_in_past_current_epoch:var:1" version="1">
          <oval-def:time_difference format_2="seconds_since_epoch">
            <oval-def:literal_component datatype="int">0</oval-def:literal_component>
          </oval-def:time_difference>
        </oval-def:local_variable>
        <oval-def:external_variable comment="number of passwords hashing rounds" datatype="int" id="oval:ssg-var_password_pam_unix_rounds:var:1" version="1"/>
        <oval-def:local_variable comment="GIDs from /etc/group" datatype="string" id="oval:ssg-var_gid_passwd_group_same:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_gid_passwd_group_same_var:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all home dirs from interactive users" datatype="string" id="oval:ssg-var_accounts_users_home_forward_file_existance_dirs:var:1" version="1">
          <oval-def:object_component item_field="home_dir" object_ref="oval:ssg-object_no_forward_files_objects:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable containing all locked users" datatype="string" id="oval:ssg-var_locked_users:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_shadow_locked_users:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Regex to match the whole group line in /etc/group" datatype="string" id="oval:ssg-var_ensure_pam_wheel_group_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:escape_regex>
              <oval-def:variable_component var_ref="oval:ssg-var_pam_wheel_group_for_su:var:1"/>
            </oval-def:escape_regex>
            <oval-def:literal_component>:[^:]+:[0-9]+:.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="name of the group used by pam_wheel.so group option" datatype="string" id="oval:ssg-var_pam_wheel_group_for_su:var:1" version="1"/>
        <oval-def:local_variable comment="Local variable which includes all valid shells" datatype="string" id="oval:ssg-var_no_invalid_shell_accounts_unlocked_valid_shells:var:1" version="1">
          <oval-def:object_component item_field="text" object_ref="oval:ssg-obj_no_invalid_shell_accounts_unlocked_valid_shells:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="shell rows retrieved from /etc/passwd" datatype="string" id="oval:ssg-variable_no_invalid_shell_accounts_unlocked_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_no_invalid_shell_accounts_unlocked_local_interactive_users:obj:1"/>
            <oval-def:literal_component>):(?:[^:]*:){5}([^:]+)$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Account name of locked accounts" datatype="string" id="oval:ssg-var_no_invalid_shell_accounts_unlocked_locked_accounts:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_no_invalid_shell_accounts_unlocked_locked_accounts:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including usernames of system accounts" datatype="string" id="oval:ssg-var_no_password_auth_for_systemaccounts_usernames:var:1" version="1">
          <oval-def:object_component item_field="username" object_ref="oval:ssg-object_no_password_auth_for_systemaccounts_objects:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Value of last UID_MIN from /etc/login.defs" datatype="int" id="oval:ssg-variable_uid_min_value:var:1" version="1">
          <oval-def:regex_capture pattern="UID_MIN[\s]+(\d+)">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_last_uid_min_from_etc_login_defs:obj:1"/>
          </oval-def:regex_capture>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Value of last SYS_UID_MIN from /etc/login.defs" datatype="int" id="oval:ssg-variable_sys_uid_min_value:var:1" version="1">
          <oval-def:regex_capture pattern="SYS_UID_MIN[\s]+(\d+)">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_last_sys_uid_min_from_etc_login_defs:obj:1"/>
          </oval-def:regex_capture>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Value of last SYS_UID_MAX from /etc/login.defs" datatype="int" id="oval:ssg-variable_sys_uid_max_value:var:1" version="1">
          <oval-def:regex_capture pattern="SYS_UID_MAX[\s]+(\d+)">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_last_sys_uid_max_from_etc_login_defs:obj:1"/>
          </oval-def:regex_capture>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Expected fail_delay" datatype="int" id="oval:ssg-var_accounts_fail_delay:var:1" version="1"/>
        <oval-def:external_variable comment="maximum number of concurrent logins per user" datatype="int" id="oval:ssg-var_accounts_max_concurrent_login_sessions:var:1" version="1"/>
        <oval-def:local_variable comment="Count of TMOUT instances" datatype="int" id="oval:ssg-variable_count_of_tmout_instances:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_accounts_tmout_all_tmout_instances:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:external_variable comment="external variable for TMOUT" datatype="int" id="oval:ssg-var_accounts_tmout:var:1" version="1"/>
        <oval-def:local_variable comment="usernames rows retrieved from /etc/passwd" datatype="string" id="oval:ssg-variable_object_accounts_user_dot_group_ownership_home_dirs_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_user_dot_group_ownership_home_dirs_local_interactive_users:obj:1"/>
            <oval-def:literal_component>):(?:[^:]*:){4}([^:]+):[^:]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="usernames rows retrieved from /etc/passwd" datatype="string" id="oval:ssg-variable_object_accounts_user_dot_group_ownership_gids_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_user_dot_group_ownership_gids_local_interactive_users:obj:1"/>
            <oval-def:literal_component>:)(?:[^:]*:){2}([^:]+):(?:[^:]*:){2}[^:]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all home dirs from interactive users" datatype="string" id="oval:ssg-var_accounts_user_dot_group_ownership_dirs:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_user_dot_group_ownership_home_dirs:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="List of interactive users gids" datatype="int" id="oval:ssg-var_accounts_user_dot_group_ownership_gids:var:1" version="1">
          <oval-def:unique>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_user_dot_group_ownership_gids:obj:1"/>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all home dirs from interactive users" datatype="string" id="oval:ssg-var_accounts_user_dot_no_world_writable_programs_dirs:var:1" version="1">
          <oval-def:object_component item_field="home_dir" object_ref="oval:ssg-object_accounts_user_dot_no_world_writable_programs_objects:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all world writable programs" datatype="string" id="oval:ssg-var_world_writable_programs:var:1" version="1">
          <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_world_writable_programs:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Regex including all world writable programs" datatype="string" id="oval:ssg-var_world_writable_programs_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^[^#]*</oval-def:literal_component>
            <oval-def:escape_regex>
              <oval-def:variable_component var_ref="oval:ssg-var_world_writable_programs:var:1"/>
            </oval-def:escape_regex>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="User initialization files" datatype="string" id="oval:ssg-var_user_initialization_files_regex:var:1" version="1"/>
        <oval-def:local_variable comment="usernames rows retrieved from /etc/passwd" datatype="string" id="oval:ssg-variable_object_accounts_user_dot_user_ownership_home_dirs_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_user_dot_user_ownership_home_dirs_local_interactive_users:obj:1"/>
            <oval-def:literal_component>):(?:[^:]*:){4}([^:]+):[^:]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="usernames rows retrieved from /etc/passwd" datatype="string" id="oval:ssg-variable_object_accounts_user_dot_user_ownership_uids_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_user_dot_user_ownership_uids_local_interactive_users:obj:1"/>
            <oval-def:literal_component>:)(?:[^:]*:)([^:]+):(?:[^:]*:){3}[^:]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all home dirs from interactive users" datatype="string" id="oval:ssg-var_accounts_user_dot_user_ownership_dirs:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_user_dot_user_ownership_home_dirs:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="List of interactive users uids" datatype="int" id="oval:ssg-var_accounts_user_dot_user_ownership_uids:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_user_dot_user_ownership_uids:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="usernames rows retrieved from /etc/passwd" datatype="string" id="oval:ssg-variable_object_accounts_user_interactive_home_directory_exists_objects_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_user_interactive_home_directory_exists_objects_local_interactive_users:obj:1"/>
            <oval-def:literal_component>):(?:[^:]*:){4}([^:]+):[^:]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all home dirs from interactive users" datatype="string" id="oval:ssg-var_accounts_user_interactive_home_directory_exists_dirs_list:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_user_interactive_home_directory_exists_objects:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including expected count of home dirs present on the system" datatype="int" id="oval:ssg-var_accounts_user_interactive_home_directory_exists_dirs_count:var:1" version="1">
          <oval-def:count>
            <oval-def:variable_component var_ref="oval:ssg-var_accounts_user_interactive_home_directory_exists_dirs_list:var:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including number of home dirs present on file system" datatype="int" id="oval:ssg-var_accounts_user_interactive_home_directory_exists_dirs_count_fs:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="path" object_ref="oval:ssg-object_accounts_user_interactive_home_directory_exists_dirs_fs:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Regex patterns to match home dirs on non-root partitions" datatype="string" id="oval:ssg-var_accounts_user_interactive_home_directory_on_separate_partition_mount_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="mount_point" object_ref="oval:ssg-object_accounts_user_interactive_home_directory_on_separate_partition_non_root_partitions:obj:1"/>
            <oval-def:literal_component>(/|$)</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="usernames rows retrieved from /etc/passwd" datatype="string" id="oval:ssg-variable_object_accounts_users_home_files_groupownership_home_dirs_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_users_home_files_groupownership_home_dirs_local_interactive_users:obj:1"/>
            <oval-def:literal_component>):(?:[^:]*:){4}([^:]+):[^:]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="usernames rows retrieved from /etc/passwd" datatype="string" id="oval:ssg-variable_object_accounts_users_home_files_groupownership_gids_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_users_home_files_groupownership_gids_local_interactive_users:obj:1"/>
            <oval-def:literal_component>:)(?:[^:]*:){2}([^:]+):(?:[^:]*:){2}[^:]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all home dirs from interactive users" datatype="string" id="oval:ssg-var_accounts_users_home_files_groupownership_dirs:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_users_home_files_groupownership_home_dirs:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="List of interactive users gids" datatype="int" id="oval:ssg-var_accounts_users_home_files_groupownership_gids:var:1" version="1">
          <oval-def:unique>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_users_home_files_groupownership_gids:obj:1"/>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="usernames rows retrieved from /etc/passwd" datatype="string" id="oval:ssg-variable_object_accounts_users_home_files_ownership_home_dirs_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_users_home_files_ownership_home_dirs_local_interactive_users:obj:1"/>
            <oval-def:literal_component>):(?:[^:]*:){4}([^:]+):[^:]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="usernames rows retrieved from /etc/passwd" datatype="string" id="oval:ssg-variable_object_accounts_users_home_files_ownership_uids_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_users_home_files_ownership_uids_local_interactive_users:obj:1"/>
            <oval-def:literal_component>:)(?:[^:]*:)([^:]+):(?:[^:]*:){3}[^:]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all home dirs from interactive users" datatype="string" id="oval:ssg-var_accounts_users_home_files_ownership_dirs:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_users_home_files_ownership_home_dirs:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="List of interactive users uids" datatype="int" id="oval:ssg-var_accounts_users_home_files_ownership_uids:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_users_home_files_ownership_uids:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="usernames rows retrieved from /etc/passwd" datatype="string" id="oval:ssg-variable_object_accounts_users_home_files_permissions_home_dirs_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_users_home_files_permissions_home_dirs_local_interactive_users:obj:1"/>
            <oval-def:literal_component>):(?:[^:]*:){4}([^:]+):[^:]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all home dirs from interactive users" datatype="string" id="oval:ssg-var_accounts_users_home_files_permissions_dirs:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_users_home_files_permissions_home_dirs:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all home dirs from interactive users" datatype="string" id="oval:ssg-var_accounts_users_home_netrc_file_permissions_dirs:var:1" version="1">
          <oval-def:object_component item_field="home_dir" object_ref="oval:ssg-object_accounts_users_netrc_file_permissions_objects:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="usernames rows retrieved from /etc/passwd" datatype="string" id="oval:ssg-variable_object_file_groupownership_home_directories_home_dirs_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupownership_home_directories_home_dirs_local_interactive_users:obj:1"/>
            <oval-def:literal_component>):(?:[^:]*:){4}([^:]+):[^:]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="usernames rows retrieved from /etc/passwd" datatype="string" id="oval:ssg-variable_object_file_groupownership_home_directories_gids_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupownership_home_directories_gids_local_interactive_users:obj:1"/>
            <oval-def:literal_component>:)(?:[^:]*:){2}([^:]+):(?:[^:]*:){2}[^:]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all home dirs from primary interactive groups" datatype="string" id="oval:ssg-var_file_groupownership_home_directories_dirs:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupownership_home_directories_home_dirs:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all gids from primary interactive group" datatype="int" id="oval:ssg-var_file_groupownership_home_directories_gids:var:1" version="1">
          <oval-def:unique>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupownership_home_directories_gids:obj:1"/>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="usernames rows retrieved from /etc/passwd" datatype="string" id="oval:ssg-variable_object_file_ownership_home_directories_home_dirs_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_ownership_home_directories_home_dirs_local_interactive_users:obj:1"/>
            <oval-def:literal_component>):(?:[^:]*:){4}([^:]+):[^:]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="usernames rows retrieved from /etc/passwd" datatype="string" id="oval:ssg-variable_object_file_ownership_home_directories_uids_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_ownership_home_directories_uids_local_interactive_users:obj:1"/>
            <oval-def:literal_component>:)(?:[^:]*:)([^:]+):(?:[^:]*:){3}[^:]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all home dirs from interactive users" datatype="string" id="oval:ssg-var_file_ownership_home_directories_dirs:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_ownership_home_directories_home_dirs:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="List of interactive users uids" datatype="int" id="oval:ssg-var_file_ownership_home_directories_uids:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_ownership_home_directories_uids:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count home dirs related to interactive users" datatype="int" id="oval:ssg-var_file_ownership_home_directories_uids_count:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="user_id" object_ref="oval:ssg-object_file_ownership_home_directories_dirs:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count current owners of relevant home dirs" datatype="int" id="oval:ssg-var_file_ownership_home_directories_uids_count_uniq:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="user_id" object_ref="oval:ssg-object_file_ownership_home_directories_dirs:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all home dirs from interactive users" datatype="string" id="oval:ssg-var_file_permission_user_bash_history_home_dirs:var:1" version="1">
          <oval-def:object_component item_field="home_dir" object_ref="oval:ssg-object_file_permission_user_bash_history_objects:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all home dirs from interactive users" datatype="string" id="oval:ssg-var_file_permission_user_init_files_home_dirs:var:1" version="1">
          <oval-def:object_component item_field="home_dir" object_ref="oval:ssg-object_file_permission_user_init_files_objects:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all home dirs from interactive users" datatype="string" id="oval:ssg-var_file_permission_user_init_files_root_home_dirs:var:1" version="1">
          <oval-def:object_component item_field="home_dir" object_ref="oval:ssg-object_file_permission_user_init_files_root_objects:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="usernames rows retrieved from /etc/passwd" datatype="string" id="oval:ssg-variable_object_file_permissions_home_directories_objects_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_permissions_home_directories_objects_local_interactive_users:obj:1"/>
            <oval-def:literal_component>):(?:[^:]*:){4}([^:]+):[^:]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all home dirs from interactive users" datatype="string" id="oval:ssg-var_file_permissions_home_directories_dirs:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_permissions_home_directories_objects:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all home dirs from interactive users" datatype="string" id="oval:ssg-var_file_permissions_home_dirs_dirs:var:1" version="1">
          <oval-def:object_component item_field="home_dir" object_ref="oval:ssg-object_file_permissions_home_dirs_objects:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Split the PATH on the : delimiter" datatype="string" id="oval:ssg-var_accounts_root_path_dirs_no_write:var:1" version="1">
          <oval-def:split delimiter=":">
            <oval-def:object_component item_field="value" object_ref="oval:ssg-object_accounts_root_path_dirs_no_write_pathenv:obj:1"/>
          </oval-def:split>
        </oval-def:local_variable>
        <oval-def:local_variable comment="First octal digit of umask from /etc/bashrc" datatype="int" id="oval:ssg-var_first_digit_of_umask_from_etc_bashrc:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="1">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_umask_from_etc_bashrc:obj:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Second octal digit of umask from /etc/bashrc" datatype="int" id="oval:ssg-var_second_digit_of_umask_from_etc_bashrc:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="2">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_umask_from_etc_bashrc:obj:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Third octal digit of umask from /etc/bashrc" datatype="int" id="oval:ssg-var_third_digit_of_umask_from_etc_bashrc:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="3">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_umask_from_etc_bashrc:obj:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="/etc/bashrc umask converted from string to a number" datatype="int" id="oval:ssg-var_etc_bashrc_umask_as_number:var:1" version="1">
          <oval-def:arithmetic arithmetic_operation="add">
            <oval-def:arithmetic arithmetic_operation="multiply">
              <oval-def:literal_component datatype="int">64</oval-def:literal_component>
              <oval-def:variable_component var_ref="oval:ssg-var_first_digit_of_umask_from_etc_bashrc:var:1"/>
            </oval-def:arithmetic>
            <oval-def:arithmetic arithmetic_operation="multiply">
              <oval-def:literal_component datatype="int">8</oval-def:literal_component>
              <oval-def:variable_component var_ref="oval:ssg-var_second_digit_of_umask_from_etc_bashrc:var:1"/>
            </oval-def:arithmetic>
            <oval-def:variable_component var_ref="oval:ssg-var_third_digit_of_umask_from_etc_bashrc:var:1"/>
          </oval-def:arithmetic>
        </oval-def:local_variable>
        <oval-def:local_variable comment="First octal digit of umask from /etc/csh.cshrc" datatype="int" id="oval:ssg-var_first_digit_of_umask_from_etc_csh_cshrc:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="1">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_umask_from_etc_csh_cshrc:obj:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Second octal digit of umask from /etc/csh.cshrc" datatype="int" id="oval:ssg-var_second_digit_of_umask_from_etc_csh_cshrc:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="2">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_umask_from_etc_csh_cshrc:obj:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Third octal digit of umask from /etc/csh.cshrc" datatype="int" id="oval:ssg-var_third_digit_of_umask_from_etc_csh_cshrc:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="3">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_umask_from_etc_csh_cshrc:obj:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="/etc/csh.cshrc umask converted from string to a number" datatype="int" id="oval:ssg-var_etc_csh_cshrc_umask_as_number:var:1" version="1">
          <oval-def:arithmetic arithmetic_operation="add">
            <oval-def:arithmetic arithmetic_operation="multiply">
              <oval-def:literal_component datatype="int">64</oval-def:literal_component>
              <oval-def:variable_component var_ref="oval:ssg-var_first_digit_of_umask_from_etc_csh_cshrc:var:1"/>
            </oval-def:arithmetic>
            <oval-def:arithmetic arithmetic_operation="multiply">
              <oval-def:literal_component datatype="int">8</oval-def:literal_component>
              <oval-def:variable_component var_ref="oval:ssg-var_second_digit_of_umask_from_etc_csh_cshrc:var:1"/>
            </oval-def:arithmetic>
            <oval-def:variable_component var_ref="oval:ssg-var_third_digit_of_umask_from_etc_csh_cshrc:var:1"/>
          </oval-def:arithmetic>
        </oval-def:local_variable>
        <oval-def:local_variable comment="First octal digit of umask from /etc/login.defs" datatype="int" id="oval:ssg-var_first_digit_of_umask_from_etc_login_defs:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="1">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_umask_from_etc_login_defs:obj:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Second octal digit of umask from /etc/login.defs" datatype="int" id="oval:ssg-var_second_digit_of_umask_from_etc_login_defs:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="2">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_umask_from_etc_login_defs:obj:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Third octal digit of umask from /etc/login.defs" datatype="int" id="oval:ssg-var_third_digit_of_umask_from_etc_login_defs:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="3">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_umask_from_etc_login_defs:obj:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="/etc/login.defs umask converted from string to a number" datatype="int" id="oval:ssg-var_etc_login_defs_umask_as_number:var:1" version="1">
          <oval-def:arithmetic arithmetic_operation="add">
            <oval-def:arithmetic arithmetic_operation="multiply">
              <oval-def:literal_component datatype="int">64</oval-def:literal_component>
              <oval-def:variable_component var_ref="oval:ssg-var_first_digit_of_umask_from_etc_login_defs:var:1"/>
            </oval-def:arithmetic>
            <oval-def:arithmetic arithmetic_operation="multiply">
              <oval-def:literal_component datatype="int">8</oval-def:literal_component>
              <oval-def:variable_component var_ref="oval:ssg-var_second_digit_of_umask_from_etc_login_defs:var:1"/>
            </oval-def:arithmetic>
            <oval-def:variable_component var_ref="oval:ssg-var_third_digit_of_umask_from_etc_login_defs:var:1"/>
          </oval-def:arithmetic>
        </oval-def:local_variable>
        <oval-def:local_variable comment="first octal digit of umask value(s)" datatype="int" id="oval:ssg-var_first_digit_of_umask_from_etc_profile:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="1">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_umask_from_etc_profile:obj:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="second octal digit of umask value(s)" datatype="int" id="oval:ssg-var_second_digit_of_umask_from_etc_profile:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="2">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_umask_from_etc_profile:obj:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="third octal digit of umask value(s)" datatype="int" id="oval:ssg-var_third_digit_of_umask_from_etc_profile:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="3">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_umask_from_etc_profile:obj:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="umask value converted from string to a number" datatype="int" id="oval:ssg-var_etc_profile_umask_as_number:var:1" version="1">
          <oval-def:arithmetic arithmetic_operation="add">
            <oval-def:arithmetic arithmetic_operation="multiply">
              <oval-def:literal_component datatype="int">64</oval-def:literal_component>
              <oval-def:variable_component var_ref="oval:ssg-var_first_digit_of_umask_from_etc_profile:var:1"/>
            </oval-def:arithmetic>
            <oval-def:arithmetic arithmetic_operation="multiply">
              <oval-def:literal_component datatype="int">8</oval-def:literal_component>
              <oval-def:variable_component var_ref="oval:ssg-var_second_digit_of_umask_from_etc_profile:var:1"/>
            </oval-def:arithmetic>
            <oval-def:variable_component var_ref="oval:ssg-var_third_digit_of_umask_from_etc_profile:var:1"/>
          </oval-def:arithmetic>
        </oval-def:local_variable>
        <oval-def:local_variable comment="usernames rows retrieved from /etc/passwd" datatype="string" id="oval:ssg-variable_object_accounts_umask_interactive_users_objects_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_umask_interactive_users_objects_local_interactive_users:obj:1"/>
            <oval-def:literal_component>):(?:[^:]*:){4}([^:]+):[^:]*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable including all home dirs from interactive users" datatype="string" id="oval:ssg-var_accounts_umask_interactive_users_dirs:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_accounts_umask_interactive_users_objects:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="the config file for currently running kernel" datatype="string" id="oval:ssg-var_kernel_config_file:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>/boot/config-</oval-def:literal_component>
            <oval-def:object_component item_field="os_release" object_ref="oval:ssg-trust_cpu_rng_uname:obj:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable           including all system usernames" datatype="string" id="oval:ssg-var_user_accounts:var:1" version="1">
          <oval-def:object_component item_field="username" object_ref="oval:ssg-object_user_accounts:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable to hold the number of set root settings in /boot/grub2/grub.cfg" datatype="int" id="oval:ssg-var_grub2_set_root_count:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="filepath" object_ref="oval:ssg-obj_grub2_no_removeable_media:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable to hold the number of menu entries in /boot/grub2/grub.cfg" datatype="int" id="oval:ssg-var_grub2_menuentry_count:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="filepath" object_ref="oval:ssg-obj_grub2_menuentry:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable           including all system usernames" datatype="string" id="oval:ssg-var_uefi_user_accounts:var:1" version="1">
          <oval-def:object_component item_field="username" object_ref="oval:ssg-object_uefi_user_accounts:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable to hold the number of set root settings in /boot/efi/EFI/almalinux/grub.cfg" datatype="int" id="oval:ssg-var_uefi_set_root_count:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="filepath" object_ref="oval:ssg-obj_uefi_no_removeable_media:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Variable to hold the number of menu entries in /boot/efi/EFI/almalinux/grub.cfg" datatype="int" id="oval:ssg-var_uefi_menuentry_count:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="filepath" object_ref="oval:ssg-obj_uefi_menuentry:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Age of /etc/zipl.conf" datatype="int" id="oval:ssg-variable_zipl_conf_file_age:var:1" version="1">
          <oval-def:object_component item_field="m_time" object_ref="oval:ssg-zipl_conf_file:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Age of /boot/loader/entries/*.conf files" datatype="int" id="oval:ssg-variable_boot_entry_files_age:var:1" version="1">
          <oval-def:object_component item_field="m_time" object_ref="oval:ssg-boot_entry_files:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_kernel_config_default_mmap_min_addr_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_default_mmap_min_addr_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_kernel_config_default_mmap_min_addr_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_default_mmap_min_addr:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="decimal conversion of octal value from FileCreateMode parameter" datatype="int" id="oval:ssg-var_filecreatemode_dec:var:1" version="1">
          <oval-def:arithmetic arithmetic_operation="add">
            <oval-def:arithmetic arithmetic_operation="multiply">
              <oval-def:literal_component datatype="int">64</oval-def:literal_component>
              <oval-def:regex_capture pattern="\d(\d)\d\d">
                <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_filecreatemode:obj:1"/>
              </oval-def:regex_capture>
            </oval-def:arithmetic>
            <oval-def:arithmetic arithmetic_operation="multiply">
              <oval-def:literal_component datatype="int">8</oval-def:literal_component>
              <oval-def:regex_capture pattern="\d\d(\d)\d">
                <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_filecreatemode:obj:1"/>
              </oval-def:regex_capture>
            </oval-def:arithmetic>
            <oval-def:regex_capture pattern="\d\d\d(\d)">
              <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_filecreatemode:obj:1"/>
            </oval-def:regex_capture>
          </oval-def:arithmetic>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Mount points for local devices" datatype="string" id="oval:ssg-var_dir_perms_world_writable_sticky_bits_local_mountpoints:var:1" version="1">
          <oval-def:object_component item_field="mount_point" object_ref="oval:ssg-object_dir_perms_world_writable_sticky_bits_local_partitions:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Mount points for local devices" datatype="string" id="oval:ssg-var_dir_perms_world_writable_system_owned_local_mountpoints:var:1" version="1">
          <oval-def:object_component item_field="mount_point" object_ref="oval:ssg-object_dir_perms_world_writable_system_owned_local_partitions:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Mount points for local devices" datatype="string" id="oval:ssg-var_file_permissions_unauthorized_sgid_local_mountpoints:var:1" version="1">
          <oval-def:object_component item_field="mount_point" object_ref="oval:ssg-object_file_permissions_unauthorized_sgid_local_partitions:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="all files with sgid set" datatype="string" id="oval:ssg-var_file_permissions_unauthorized_sgid_all_sgid_files:var:1" version="1">
          <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_file_permissions_unauthorized_sgid_all_sgid_files:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="all files with sgid set that are managed by a RPM package" datatype="string" id="oval:ssg-var_file_permissions_unauthorized_sgid_rpms:var:1" version="1">
          <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_file_permissions_unauthorized_sgid_rpms:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Mount points for local devices" datatype="string" id="oval:ssg-var_file_permissions_unauthorized_suid_local_mountpoints:var:1" version="1">
          <oval-def:object_component item_field="mount_point" object_ref="oval:ssg-object_file_permissions_unauthorized_suid_local_partitions:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="all files with suid set" datatype="string" id="oval:ssg-var_file_permissions_unauthorized_suid_all_suid_files:var:1" version="1">
          <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_file_permissions_unauthorized_suid_all_suid_files:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="all files with suid set that are managed by a RPM package" datatype="string" id="oval:ssg-var_file_permissions_unauthorized_suid_rpms:var:1" version="1">
          <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_file_permissions_unauthorized_suid_rpms:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Mount points for local devices" datatype="string" id="oval:ssg-var_file_permissions_unauthorized_world_writable_local_mountpoints:var:1" version="1">
          <oval-def:object_component item_field="mount_point" object_ref="oval:ssg-object_file_permissions_unauthorized_world_writable_local_partitions:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="all GIDs extracted from /etc/group on the target system" datatype="int" id="oval:ssg-var_all_local_gids:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_etc_group:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="all GIDs extracted from /etc/group on the target system" datatype="int" id="oval:ssg-var_all_local_gids_with_usrlib:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_all_gids_with_usrlib:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Mount points for local devices" datatype="string" id="oval:ssg-var_file_permissions_ungroupowned_local_mountpoints:var:1" version="1">
          <oval-def:object_component item_field="mount_point" object_ref="oval:ssg-object_file_permissions_ungroupowned_local_partitions:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Mount points for local devices" datatype="string" id="oval:ssg-var_no_files_or_dirs_ungroupowned_local_mountpoints:var:1" version="1">
          <oval-def:object_component item_field="mount_point" object_ref="oval:ssg-object_no_files_or_dirs_ungroupowned_local_partitions:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="List of valid user ids" datatype="int" id="oval:ssg-var_no_files_or_dirs_unowned_by_user_uids_list:var:1" version="1">
          <oval-def:object_component item_field="user_id" object_ref="oval:ssg-object_no_files_or_dirs_unowned_by_user_all_users:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Mount points for local devices" datatype="string" id="oval:ssg-var_no_files_or_dirs_unowned_by_user_local_mountpoints:var:1" version="1">
          <oval-def:object_component item_field="mount_point" object_ref="oval:ssg-object_no_files_or_dirs_unowned_by_user_local_partitions:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="List of valid user ids" datatype="int" id="oval:ssg-var_no_files_unowned_by_user_uids_list:var:1" version="1">
          <oval-def:object_component item_field="user_id" object_ref="oval:ssg-object_no_files_unowned_by_user_all_users:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Mount points for local devices" datatype="string" id="oval:ssg-var_no_files_unowned_by_user_local_mountpoints:var:1" version="1">
          <oval-def:object_component item_field="mount_point" object_ref="oval:ssg-object_no_files_unowned_by_user_local_partitions:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Source device of /var/tmp" datatype="string" id="oval:ssg-var_mount_option_var_tmp_bind_var_tmp_source_device:var:1" version="1">
          <oval-def:object_component item_field="device" object_ref="oval:ssg-object_mount_option_var_tmp:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="First octal digit of umask from /etc/init.d/functions" datatype="int" id="oval:ssg-var_first_digit_of_umask_from_etc_init_d_functions:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="1">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_umask_from_etc_init_d_functions:obj:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Second octal digit of umask from /etc/init.d/functions" datatype="int" id="oval:ssg-var_second_digit_of_umask_from_etc_init_d_functions:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="2">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_umask_from_etc_init_d_functions:obj:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Third octal digit of umask from /etc/init.d/functions" datatype="int" id="oval:ssg-var_third_digit_of_umask_from_etc_init_d_functions:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="3">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_umask_from_etc_init_d_functions:obj:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="/etc/init.d/functions umask converted from string to a number" datatype="int" id="oval:ssg-var_etc_init_d_functions_umask_as_number:var:1" version="1">
          <oval-def:arithmetic arithmetic_operation="add">
            <oval-def:arithmetic arithmetic_operation="multiply">
              <oval-def:literal_component datatype="int">64</oval-def:literal_component>
              <oval-def:variable_component var_ref="oval:ssg-var_first_digit_of_umask_from_etc_init_d_functions:var:1"/>
            </oval-def:arithmetic>
            <oval-def:arithmetic arithmetic_operation="multiply">
              <oval-def:literal_component datatype="int">8</oval-def:literal_component>
              <oval-def:variable_component var_ref="oval:ssg-var_second_digit_of_umask_from_etc_init_d_functions:var:1"/>
            </oval-def:arithmetic>
            <oval-def:variable_component var_ref="oval:ssg-var_third_digit_of_umask_from_etc_init_d_functions:var:1"/>
          </oval-def:arithmetic>
        </oval-def:local_variable>
        <oval-def:local_variable comment="all device files within /dev directory" datatype="string" id="oval:ssg-variable_dev_device_files:var:1" version="1">
          <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_dev_device_files:obj:1"/>
        </oval-def:local_variable>
        <oval-def:external_variable comment="external variable for selinux state" datatype="string" id="oval:ssg-var_selinux_state:var:1" version="1"/>
        <oval-def:local_variable comment="When the 'gdm' dconf DB has been modified" datatype="string" id="oval:ssg-var_dconf_gdm_db_modified_time:var:1" version="1">
          <oval-def:time_difference format_2="seconds_since_epoch">
            <oval-def:object_component item_field="m_time" object_ref="oval:ssg-obj_dconf_gdm_db:obj:1"/>
          </oval-def:time_difference>
        </oval-def:local_variable>
        <oval-def:local_variable comment="When dconf keyfiles in the 'gdm' tree have been modified" datatype="int" id="oval:ssg-var_dconf_gdm_keyfiles_modified_time:var:1" version="1">
          <oval-def:time_difference format_2="seconds_since_epoch">
            <oval-def:object_component item_field="m_time" object_ref="oval:ssg-obj_dconf_gdm_config:obj:1"/>
          </oval-def:time_difference>
        </oval-def:local_variable>
        <oval-def:local_variable comment="When the 'local' dconf DB has been modified" datatype="string" id="oval:ssg-var_dconf_local_db_modified_time:var:1" version="1">
          <oval-def:time_difference format_2="seconds_since_epoch">
            <oval-def:object_component item_field="m_time" object_ref="oval:ssg-obj_dconf_local_db:obj:1"/>
          </oval-def:time_difference>
        </oval-def:local_variable>
        <oval-def:local_variable comment="When dconf keyfiles in the 'local' tree have been modified" datatype="int" id="oval:ssg-var_dconf_local_keyfiles_modified_time:var:1" version="1">
          <oval-def:time_difference format_2="seconds_since_epoch">
            <oval-def:object_component item_field="m_time" object_ref="oval:ssg-obj_dconf_local_config:obj:1"/>
          </oval-def:time_difference>
        </oval-def:local_variable>
        <oval-def:external_variable comment="inactivity timeout variable" datatype="int" id="oval:ssg-inactivity_timeout_value:var:1" version="1"/>
        <oval-def:external_variable comment="screensaver lock delay variable" datatype="int" id="oval:ssg-var_screensaver_lock_delay:var:1" version="1"/>
        <oval-def:local_variable comment="Age of /etc/crypto-policies/state/current" datatype="int" id="oval:ssg-variable_crypto_policies_current_file_timestamp:var:1" version="1">
          <oval-def:object_component item_field="m_time" object_ref="oval:ssg-crypto_policies_current_file:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Age of /etc/crypto-policies/config" datatype="int" id="oval:ssg-variable_crypto_policies_config_file_timestamp:var:1" version="1">
          <oval-def:object_component item_field="m_time" object_ref="oval:ssg-crypto_policies_config_file:obj:1"/>
        </oval-def:local_variable>
        <oval-def:external_variable comment="defined crypto policy" datatype="string" id="oval:ssg-var_system_crypto_policy:var:1" version="1"/>
        <oval-def:local_variable comment="regex variable for canonical path to targeted kerberos policy" datatype="string" id="oval:ssg-var_symlink_kerberos_crypto_policy_configuration:var:1" version="1">
          <oval-def:object_component item_field="canonical_path" object_ref="oval:ssg-object_kerberos_crypto_policy_configuration:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="regex variable for canonical path to targeted kerberos policy" datatype="string" id="oval:ssg-var_symlink_kerberos_crypto_policy_backend:var:1" version="1">
          <oval-def:object_component item_field="canonical_path" object_ref="oval:ssg-object_kerberos_crypto_policy_backend:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Number of matches of TLS versions" datatype="int" id="oval:ssg-var_count_configure_openssl_tls_crypto_policy:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="instance" object_ref="oval:ssg-obj_configure_openssl_tls_crypto_policy:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Number of matches of DTLS versions" datatype="int" id="oval:ssg-var_count_configure_openssl_dtls_crypto_policy:var:1" version="1">
          <oval-def:count>
            <oval-def:object_component item_field="instance" object_ref="oval:ssg-obj_configure_openssl_dtls_crypto_policy:obj:1"/>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The regex of the directive" datatype="string" id="oval:ssg-sshd_ciphers_crypto:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>Ciphers </oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-sshd_approved_ciphers:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The regex of the directive" datatype="string" id="oval:ssg-sshd_macs_crypto:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>MACs </oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-sshd_approved_macs:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Age of file for each McAfee definition file." datatype="int" id="oval:ssg-variable_mcafee_dat_files_mtime:var:1" version="1">
          <oval-def:time_difference format_2="seconds_since_epoch">
            <oval-def:object_component item_field="m_time" object_ref="oval:ssg-mcafee_dat_files_mtime:obj:1"/>
          </oval-def:time_difference>
        </oval-def:local_variable>
        <oval-def:external_variable comment="definitions age" datatype="int" id="oval:ssg-var_mcafee_antivirus_definition_expire:var:1" version="1"/>
        <oval-def:local_variable comment="Absolute path of Aide build database file" datatype="string" id="oval:ssg-variable_aide_operational_database_absolute_path:var:1" version="1">
          <oval-def:concat>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_aide_build_database_dirpath:obj:1"/>
            <oval-def:literal_component>/</oval-def:literal_component>
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_aide_operational_database_filename:obj:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Build the regex for the group ID based on the variable" datatype="string" id="oval:ssg-sudo_dedicated_group_regex_for_gid:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_sudo_dedicated_group:var:1"/>
            <oval-def:literal_component>:x:(\d+):.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Name of sudo dedicated group" datatype="string" id="oval:ssg-var_sudo_dedicated_group:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for pam_dcredit" datatype="int" id="oval:ssg-var_password_pam_dcredit:var:1" version="3"/>
        <oval-def:external_variable comment="External variable for pam_dictcheck" datatype="int" id="oval:ssg-var_password_pam_dictcheck:var:1" version="3"/>
        <oval-def:external_variable comment="External variable for pam_difok" datatype="int" id="oval:ssg-var_password_pam_difok:var:1" version="3"/>
        <oval-def:external_variable comment="External variable for pam_lcredit" datatype="int" id="oval:ssg-var_password_pam_lcredit:var:1" version="3"/>
        <oval-def:external_variable comment="External variable for pam_maxclassrepeat" datatype="int" id="oval:ssg-var_password_pam_maxclassrepeat:var:1" version="3"/>
        <oval-def:external_variable comment="External variable for pam_maxrepeat" datatype="int" id="oval:ssg-var_password_pam_maxrepeat:var:1" version="3"/>
        <oval-def:external_variable comment="External variable for pam_maxsequence" datatype="int" id="oval:ssg-var_password_pam_maxsequence:var:1" version="3"/>
        <oval-def:external_variable comment="External variable for pam_minclass" datatype="int" id="oval:ssg-var_password_pam_minclass:var:1" version="3"/>
        <oval-def:external_variable comment="External variable for pam_minlen" datatype="int" id="oval:ssg-var_password_pam_minlen:var:1" version="3"/>
        <oval-def:external_variable comment="External variable for pam_ocredit" datatype="int" id="oval:ssg-var_password_pam_ocredit:var:1" version="3"/>
        <oval-def:external_variable comment="External variable for pam_ucredit" datatype="int" id="oval:ssg-var_password_pam_ucredit:var:1" version="3"/>
        <oval-def:constant_variable comment="regex to identify pam_unix.so in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_unix_regex:var:1" version="2">
          <oval-def:value>^\s*auth\N+pam_unix\.so</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entries in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_auth_regex:var:1" version="2">
          <oval-def:value>^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+preauth[\s\S]*^[\s]*auth[\s]+(sufficient|\[(?=.*\bsuccess=done\b)(?=.*?\bnew_authtok_reqd=done\b)(?=.*?\bdefault=ignore\b).*\])[\s]+pam_unix\.so[\s\S]*^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+authfail</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entry in account section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_account_regex:var:1" version="2">
          <oval-def:value>^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\S]*^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_unix\.so</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so deny entry in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_deny_parameter_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth[\s]+.+[\s]+pam_faillock.so[\s]+[^\n]*deny=([0-9]+)</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify deny entry in /etc/security/faillock.conf" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_deny_faillock_conf_deny_parameter_regex:var:1" version="1">
          <oval-def:value>^[\s]*deny[\s]*=[\s]*([0-9]+)</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:external_variable comment="external variable to use" datatype="int" id="oval:ssg-var_accounts_passwords_pam_faillock_deny:var:1" version="1"/>
        <oval-def:constant_variable comment="regex to identify pam_unix.so in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_unix_regex:var:1" version="2">
          <oval-def:value>^\s*auth\N+pam_unix\.so</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entries in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_auth_regex:var:1" version="2">
          <oval-def:value>^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+preauth[\s\S]*^[\s]*auth[\s]+(sufficient|\[(?=.*\bsuccess=done\b)(?=.*?\bnew_authtok_reqd=done\b)(?=.*?\bdefault=ignore\b).*\])[\s]+pam_unix\.so[\s\S]*^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+authfail</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entry in account section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_account_regex:var:1" version="2">
          <oval-def:value>^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\S]*^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_unix\.so</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so fail_interval entry in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_fail_interval_parameter_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth[\s]+.+[\s]+pam_faillock.so[\s]+[^\n]*fail_interval=([0-9]+)</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify fail_interval entry in /etc/security/faillock.conf" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_faillock_conf_fail_interval_parameter_regex:var:1" version="1">
          <oval-def:value>^[\s]*fail_interval[\s]*=[\s]*([0-9]+)</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:external_variable comment="external variable to use" datatype="int" id="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval:var:1" version="1"/>
        <oval-def:constant_variable comment="regex to identify pam_unix.so in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_unix_regex:var:1" version="2">
          <oval-def:value>^\s*auth\N+pam_unix\.so</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entries in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_auth_regex:var:1" version="2">
          <oval-def:value>^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+preauth[\s\S]*^[\s]*auth[\s]+(sufficient|\[(?=.*\bsuccess=done\b)(?=.*?\bnew_authtok_reqd=done\b)(?=.*?\bdefault=ignore\b).*\])[\s]+pam_unix\.so[\s\S]*^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+authfail</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so entry in account section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_account_regex:var:1" version="2">
          <oval-def:value>^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\S]*^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_unix\.so</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify pam_faillock.so unlock_time entry in auth section of pam files" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_unlock_time_parameter_regex:var:1" version="1">
          <oval-def:value>^[\s]*auth[\s]+.+[\s]+pam_faillock.so[\s]+[^\n]*unlock_time=([0-9]+)</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="regex to identify unlock_time entry in /etc/security/faillock.conf" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_faillock_conf_unlock_time_parameter_regex:var:1" version="1">
          <oval-def:value>^[\s]*unlock_time[\s]*=[\s]*([0-9]+)</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_etc_cron_d_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/etc\/cron.d\/</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_32bit_open_write_tc_group_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(open)(?:,[\S]+)*)[\s]+(?:-F[\s]+a1&amp;03)[\s]+(?:-F[\s]+path=/etc/group)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_64bit_open_write_tc_group_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(open)(?:,[\S]+)*)[\s]+(?:-F[\s]+a1&amp;03)[\s]+(?:-F[\s]+path=/etc/group)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_32bit_open_by_handle_at_write_tc_group_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(open_by_handle_at)(?:,[\S]+)*)[\s]+(?:-F[\s]+a2&amp;03)[\s]+(?:-F[\s]+path=/etc/group)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_64bit_open_by_handle_at_write_tc_group_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(open_by_handle_at)(?:,[\S]+)*)[\s]+(?:-F[\s]+a2&amp;03)[\s]+(?:-F[\s]+path=/etc/group)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_32bit_openat_write_tc_group_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(openat)(?:,[\S]+)*)[\s]+(?:-F[\s]+a2&amp;03)[\s]+(?:-F[\s]+path=/etc/group)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_64bit_openat_write_tc_group_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(openat)(?:,[\S]+)*)[\s]+(?:-F[\s]+a2&amp;03)[\s]+(?:-F[\s]+path=/etc/group)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_32bit_open_write_tc_gshadow_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(open)(?:,[\S]+)*)[\s]+(?:-F[\s]+a1&amp;03)[\s]+(?:-F[\s]+path=/etc/gshadow)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_64bit_open_write_tc_gshadow_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(open)(?:,[\S]+)*)[\s]+(?:-F[\s]+a1&amp;03)[\s]+(?:-F[\s]+path=/etc/gshadow)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_32bit_open_by_handle_at_write_tc_gshadow_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(open_by_handle_at)(?:,[\S]+)*)[\s]+(?:-F[\s]+a2&amp;03)[\s]+(?:-F[\s]+path=/etc/gshadow)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_64bit_open_by_handle_at_write_tc_gshadow_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(open_by_handle_at)(?:,[\S]+)*)[\s]+(?:-F[\s]+a2&amp;03)[\s]+(?:-F[\s]+path=/etc/gshadow)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_32bit_openat_write_tc_gshadow_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(openat)(?:,[\S]+)*)[\s]+(?:-F[\s]+a2&amp;03)[\s]+(?:-F[\s]+path=/etc/gshadow)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_64bit_openat_write_tc_gshadow_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(openat)(?:,[\S]+)*)[\s]+(?:-F[\s]+a2&amp;03)[\s]+(?:-F[\s]+path=/etc/gshadow)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_32bit_open_write_tc_passwd_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(open)(?:,[\S]+)*)[\s]+(?:-F[\s]+a1&amp;03)[\s]+(?:-F[\s]+path=/etc/passwd)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_64bit_open_write_tc_passwd_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(open)(?:,[\S]+)*)[\s]+(?:-F[\s]+a1&amp;03)[\s]+(?:-F[\s]+path=/etc/passwd)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_32bit_open_by_handle_at_write_tc_passwd_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(open_by_handle_at)(?:,[\S]+)*)[\s]+(?:-F[\s]+a2&amp;03)[\s]+(?:-F[\s]+path=/etc/passwd)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_64bit_open_by_handle_at_write_tc_passwd_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(open_by_handle_at)(?:,[\S]+)*)[\s]+(?:-F[\s]+a2&amp;03)[\s]+(?:-F[\s]+path=/etc/passwd)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_32bit_openat_write_tc_passwd_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(openat)(?:,[\S]+)*)[\s]+(?:-F[\s]+a2&amp;03)[\s]+(?:-F[\s]+path=/etc/passwd)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_64bit_openat_write_tc_passwd_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(openat)(?:,[\S]+)*)[\s]+(?:-F[\s]+a2&amp;03)[\s]+(?:-F[\s]+path=/etc/passwd)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_32bit_open_write_tc_shadow_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(open)(?:,[\S]+)*)[\s]+(?:-F[\s]+a1&amp;03)[\s]+(?:-F[\s]+path=/etc/shadow)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_64bit_open_write_tc_shadow_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(open)(?:,[\S]+)*)[\s]+(?:-F[\s]+a1&amp;03)[\s]+(?:-F[\s]+path=/etc/shadow)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_32bit_open_by_handle_at_write_tc_shadow_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(open_by_handle_at)(?:,[\S]+)*)[\s]+(?:-F[\s]+a2&amp;03)[\s]+(?:-F[\s]+path=/etc/shadow)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_64bit_open_by_handle_at_write_tc_shadow_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(open_by_handle_at)(?:,[\S]+)*)[\s]+(?:-F[\s]+a2&amp;03)[\s]+(?:-F[\s]+path=/etc/shadow)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_32bit_openat_write_tc_shadow_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(openat)(?:,[\S]+)*)[\s]+(?:-F[\s]+a2&amp;03)[\s]+(?:-F[\s]+path=/etc/shadow)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_64bit_openat_write_tc_shadow_regex:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(openat)(?:,[\S]+)*)[\s]+(?:-F[\s]+a2&amp;03)[\s]+(?:-F[\s]+path=/etc/shadow)[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_login_events_faillock_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_accounts_passwords_pam_faillock_dir:var:1"/>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="variable specifying the path that should be watched by the audit watch" datatype="string" id="oval:ssg-var_accounts_passwords_pam_faillock_dir:var:1" version="1"/>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_login_events_lastlog_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/var\/log\/lastlog</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_login_events_tallylog_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/var\/log\/tallylog</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_mac_modification_usr_share_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/usr\/share\/selinux\/</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_networkconfig_modification_network_scripts_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/etc\/sysconfig\/network-scripts</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_session_events_btmp_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/var\/log\/btmp</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_session_events_utmp_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/var\/run\/utmp</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_session_events_wtmp_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/var\/log\/wtmp</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_sudoers_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/etc\/sudoers</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_sudoers_d_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/etc\/sudoers.d\/</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_time_watch_localtime_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/etc\/localtime</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_chmod_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+chmod[\s]+|([\s]+|[,])chmod([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_chmod_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+chmod[\s]+|([\s]+|[,])chmod([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_chmod_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit chmod EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_chmod_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_chmod_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_chmod_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit chmod EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_chmod_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_chmod_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_chmod_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit chmod EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_chmod_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_chmod_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_chmod_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit chmod EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_chmod_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_chmod_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_chmod_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_chown_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+chown[\s]+|([\s]+|[,])chown([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_chown_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+chown[\s]+|([\s]+|[,])chown([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_chown_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit chown EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_chown_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_chown_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_chown_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit chown EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_chown_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_chown_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_chown_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit chown EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_chown_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_chown_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_chown_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit chown EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_chown_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_chown_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_chown_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_creat_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+creat[\s]+|([\s]+|[,])creat([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_creat_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+creat[\s]+|([\s]+|[,])creat([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_creat_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit creat EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_creat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_creat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_creat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit creat EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_creat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_creat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_creat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit creat EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_creat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_creat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_creat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit creat EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_creat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_creat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_creat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_fchmod_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fchmod[\s]+|([\s]+|[,])fchmod([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_fchmod_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fchmod[\s]+|([\s]+|[,])fchmod([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_fchmod_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit fchmod EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_fchmod_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_fchmod_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fchmod_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit fchmod EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_fchmod_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_fchmod_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fchmod_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit fchmod EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_fchmod_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_fchmod_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fchmod_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit fchmod EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_fchmod_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_fchmod_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fchmod_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_fchmodat_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fchmodat[\s]+|([\s]+|[,])fchmodat([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_fchmodat_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fchmodat[\s]+|([\s]+|[,])fchmodat([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_fchmodat_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit fchmodat EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_fchmodat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_fchmodat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fchmodat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit fchmodat EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_fchmodat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_fchmodat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fchmodat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit fchmodat EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_fchmodat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_fchmodat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fchmodat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit fchmodat EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_fchmodat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_fchmodat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fchmodat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_fchown_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fchown[\s]+|([\s]+|[,])fchown([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_fchown_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fchown[\s]+|([\s]+|[,])fchown([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_fchown_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit fchown EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_fchown_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_fchown_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fchown_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit fchown EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_fchown_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_fchown_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fchown_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit fchown EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_fchown_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_fchown_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fchown_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit fchown EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_fchown_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_fchown_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fchown_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_fchownat_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fchownat[\s]+|([\s]+|[,])fchownat([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_fchownat_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fchownat[\s]+|([\s]+|[,])fchownat([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_fchownat_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit fchownat EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_fchownat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_fchownat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fchownat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit fchownat EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_fchownat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_fchownat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fchownat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit fchownat EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_fchownat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_fchownat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fchownat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit fchownat EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_fchownat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_fchownat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fchownat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_fremovexattr_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fremovexattr[\s]+|([\s]+|[,])fremovexattr([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_fremovexattr_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fremovexattr[\s]+|([\s]+|[,])fremovexattr([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_fremovexattr_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit fremovexattr EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_fremovexattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_fremovexattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fremovexattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit fremovexattr EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_fremovexattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_fremovexattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fremovexattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit fremovexattr EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_fremovexattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_fremovexattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fremovexattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit fremovexattr EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_fremovexattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_fremovexattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fremovexattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_fsetxattr_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+fsetxattr[\s]+|([\s]+|[,])fsetxattr([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_fsetxattr_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+fsetxattr[\s]+|([\s]+|[,])fsetxattr([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_fsetxattr_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit fsetxattr EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_fsetxattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_fsetxattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fsetxattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit fsetxattr EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_fsetxattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_fsetxattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fsetxattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit fsetxattr EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_fsetxattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_fsetxattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fsetxattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit fsetxattr EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_fsetxattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_fsetxattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_fsetxattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_ftruncate_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+ftruncate[\s]+|([\s]+|[,])ftruncate([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_ftruncate_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+ftruncate[\s]+|([\s]+|[,])ftruncate([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_ftruncate_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit ftruncate EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_ftruncate_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_ftruncate_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_ftruncate_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit ftruncate EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_ftruncate_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_ftruncate_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_ftruncate_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit ftruncate EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_ftruncate_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_ftruncate_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_ftruncate_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit ftruncate EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_ftruncate_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_ftruncate_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_ftruncate_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_lchown_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+lchown[\s]+|([\s]+|[,])lchown([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_lchown_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+lchown[\s]+|([\s]+|[,])lchown([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_lchown_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit lchown EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_lchown_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_lchown_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_lchown_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit lchown EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_lchown_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_lchown_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_lchown_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit lchown EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_lchown_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_lchown_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_lchown_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit lchown EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_lchown_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_lchown_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_lchown_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_lremovexattr_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+lremovexattr[\s]+|([\s]+|[,])lremovexattr([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_lremovexattr_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+lremovexattr[\s]+|([\s]+|[,])lremovexattr([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_lremovexattr_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit lremovexattr EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_lremovexattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_lremovexattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_lremovexattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit lremovexattr EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_lremovexattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_lremovexattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_lremovexattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit lremovexattr EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_lremovexattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_lremovexattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_lremovexattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit lremovexattr EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_lremovexattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_lremovexattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_lremovexattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_lsetxattr_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+lsetxattr[\s]+|([\s]+|[,])lsetxattr([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_lsetxattr_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+lsetxattr[\s]+|([\s]+|[,])lsetxattr([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_lsetxattr_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit lsetxattr EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_lsetxattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_lsetxattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_lsetxattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit lsetxattr EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_lsetxattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_lsetxattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_lsetxattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit lsetxattr EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_lsetxattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_lsetxattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_lsetxattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit lsetxattr EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_lsetxattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_lsetxattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_lsetxattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_open_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+open[\s]+|([\s]+|[,])open([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_open_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+open[\s]+|([\s]+|[,])open([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_open_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit open EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_open_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_open_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_open_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit open EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_open_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_open_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_open_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit open EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_open_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_open_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_open_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit open EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_open_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_open_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_open_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_open_by_handle_at_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+open_by_handle_at[\s]+|([\s]+|[,])open_by_handle_at([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_open_by_handle_at_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+open_by_handle_at[\s]+|([\s]+|[,])open_by_handle_at([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_open_by_handle_at_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit open_by_handle_at EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_open_by_handle_at_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_open_by_handle_at_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_open_by_handle_at_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit open_by_handle_at EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_open_by_handle_at_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_open_by_handle_at_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_open_by_handle_at_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit open_by_handle_at EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_open_by_handle_at_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_open_by_handle_at_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_open_by_handle_at_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit open_by_handle_at EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_open_by_handle_at_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_open_by_handle_at_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_open_by_handle_at_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_32bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(open_by_handle_at)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_64bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(open_by_handle_at)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit open_by_handle_at O_CREAT EACCES syscall" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_32bit_a20100_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;0100)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit open_by_handle_at O_CREAT EPERM syscall" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_32bit_a20100_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;0100)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit open_by_handle_at O_CREAT EACCES syscall" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_64bit_a20100_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;0100)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit open_by_handle_at O_CREAT EPERM syscall" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_64bit_a20100_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;0100)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_creat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_32bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(open_by_handle_at)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_64bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(open_by_handle_at)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit open_by_handle_at O_TRUNC EACCES syscall" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_32bit_a201003_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;01003)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit open_by_handle_at O_TRUNC EPERM EACCES syscall" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_32bit_a201003_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;01003)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit open_by_handle_at O_TRUNC EACCES syscall" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_64bit_a201003_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;01003)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit open_by_handle_at O_TRUNC EPERM syscall" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_64bit_a201003_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;01003)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_o_trunc_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(open_by_handle_at)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(open_by_handle_at)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_order_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(?:unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_a20100_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;0100)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_a201003_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;01003)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_a20100_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;0100)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_a201003_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;01003)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_a20100_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;0100)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_a201003_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;01003)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_a20100_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;0100)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_a201003_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;01003)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_by_handle_at_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_32bit_open_by_handle_at_eacces_augenrules_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_32bit_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a201003_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a201003_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_32bit_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_32bit_open_by_handle_at_eperm_augenrules_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_32bit_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a201003_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a201003_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_32bit_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_64bit_open_by_handle_at_eacces_augenrules_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_64bit_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a201003_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a201003_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_64bit_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_64bit_open_by_handle_at_eperm_augenrules_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_64bit_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a201003_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a201003_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_64bit_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_32bit_open_by_handle_at_auditctl_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_32bit_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a201003_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a201003_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_32bit_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_32bit_open_by_handle_at_auditctl_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_32bit_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a201003_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a201003_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_32bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_32bit_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_open_by_handle_at_order_64bit_auditctl_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_64bit_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a201003_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a201003_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_64bit_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_64bit_open_by_handle_at_auditctl_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_64bit_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a201003_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a201003_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_64bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_by_handle_at_order_nofilter_64bit_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_open_o_creat_32bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(open)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_open_o_creat_64bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(open)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_audit_rule_open_o_creat_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit open O_CREAT EACCES syscall" datatype="string" id="oval:ssg-var_audit_rule_open_o_creat_32bit_a20100_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_o_creat_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a1&amp;0100)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_o_creat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit open O_CREAT EPERM syscall" datatype="string" id="oval:ssg-var_audit_rule_open_o_creat_32bit_a20100_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_o_creat_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a1&amp;0100)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_o_creat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit open O_CREAT EACCES syscall" datatype="string" id="oval:ssg-var_audit_rule_open_o_creat_64bit_a20100_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_o_creat_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a1&amp;0100)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_o_creat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit open O_CREAT EPERM syscall" datatype="string" id="oval:ssg-var_audit_rule_open_o_creat_64bit_a20100_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_o_creat_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a1&amp;0100)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_o_creat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_open_o_trunc_32bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(open)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_open_o_trunc_64bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(open)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_audit_rule_open_o_trunc_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit open O_TRUNC EACCES syscall" datatype="string" id="oval:ssg-var_audit_rule_open_o_trunc_32bit_a201003_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_o_trunc_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a1&amp;01003)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_o_trunc_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit open O_TRUNC EPERM EACCES syscall" datatype="string" id="oval:ssg-var_audit_rule_open_o_trunc_32bit_a201003_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_o_trunc_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a1&amp;01003)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_o_trunc_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit open O_TRUNC EACCES syscall" datatype="string" id="oval:ssg-var_audit_rule_open_o_trunc_64bit_a201003_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_o_trunc_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a1&amp;01003)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_o_trunc_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit open O_TRUNC EPERM syscall" datatype="string" id="oval:ssg-var_audit_rule_open_o_trunc_64bit_a201003_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_o_trunc_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a1&amp;01003)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_o_trunc_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_open_order_32bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(open)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_open_order_64bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(open)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_audit_rule_open_order_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(?:unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_order_32bit_a20100_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a1&amp;0100)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_order_32bit_a201003_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a1&amp;01003)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_order_32bit_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_order_32bit_a20100_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a1&amp;0100)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_order_32bit_a201003_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a1&amp;01003)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_order_32bit_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_order_64bit_a20100_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a1&amp;0100)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_order_64bit_a201003_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a1&amp;01003)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_order_64bit_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_order_64bit_a20100_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a1&amp;0100)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_order_64bit_a201003_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a1&amp;01003)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_open_order_64bit_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_open_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_32bit_open_eacces_augenrules_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_nofilter_32bit_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a201003_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a201003_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_nofilter_32bit_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_32bit_open_eperm_augenrules_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_nofilter_32bit_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a201003_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a201003_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_nofilter_32bit_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_64bit_open_eacces_augenrules_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_nofilter_64bit_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a201003_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a201003_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_nofilter_64bit_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_64bit_open_eperm_augenrules_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_nofilter_64bit_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a201003_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a201003_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_nofilter_64bit_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_32bit_open_auditctl_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_nofilter_32bit_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a201003_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a201003_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_nofilter_32bit_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_32bit_open_auditctl_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_nofilter_32bit_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a201003_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a201003_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_32bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_nofilter_32bit_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_open_order_64bit_auditctl_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_nofilter_64bit_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a201003_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a201003_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_nofilter_64bit_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_64bit_open_auditctl_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_nofilter_64bit_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a201003_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a201003_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_64bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_open_order_nofilter_64bit_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_openat_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+openat[\s]+|([\s]+|[,])openat([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_openat_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+openat[\s]+|([\s]+|[,])openat([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_openat_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit openat EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_openat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_openat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_openat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit openat EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_openat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_openat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_openat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit openat EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_openat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_openat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_openat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit openat EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_openat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_openat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_openat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_openat_o_creat_32bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(openat)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_openat_o_creat_64bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(openat)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_audit_rule_openat_o_creat_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit openat O_CREAT EACCES syscall" datatype="string" id="oval:ssg-var_audit_rule_openat_o_creat_32bit_a20100_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_o_creat_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;0100)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_o_creat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit openat O_CREAT EPERM syscall" datatype="string" id="oval:ssg-var_audit_rule_openat_o_creat_32bit_a20100_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_o_creat_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;0100)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_o_creat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit openat O_CREAT EACCES syscall" datatype="string" id="oval:ssg-var_audit_rule_openat_o_creat_64bit_a20100_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_o_creat_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;0100)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_o_creat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit openat O_CREAT EPERM syscall" datatype="string" id="oval:ssg-var_audit_rule_openat_o_creat_64bit_a20100_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_o_creat_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;0100)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_o_creat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_openat_o_trunc_32bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(openat)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_openat_o_trunc_64bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(openat)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_audit_rule_openat_o_trunc_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit openat O_TRUNC EACCES syscall" datatype="string" id="oval:ssg-var_audit_rule_openat_o_trunc_32bit_a201003_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_o_trunc_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;01003)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_o_trunc_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit openat O_TRUNC EPERM EACCES syscall" datatype="string" id="oval:ssg-var_audit_rule_openat_o_trunc_32bit_a201003_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_o_trunc_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;01003)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_o_trunc_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit openat O_TRUNC EACCES syscall" datatype="string" id="oval:ssg-var_audit_rule_openat_o_trunc_64bit_a201003_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_o_trunc_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;01003)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_o_trunc_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit openat O_TRUNC EPERM syscall" datatype="string" id="oval:ssg-var_audit_rule_openat_o_trunc_64bit_a201003_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_o_trunc_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;01003)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_o_trunc_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_openat_order_32bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:-S[\s]+(?:[\S]+,)*(openat)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_audit_rule_openat_order_64bit_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:-S[\s]+(?:[\S]+,)*(openat)(?:,[\S]+)*)[\s]+</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_audit_rule_openat_order_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(?:unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_openat_order_32bit_a20100_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;0100)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_openat_order_32bit_a201003_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;01003)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_openat_order_32bit_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_openat_order_32bit_a20100_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;0100)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_openat_order_32bit_a201003_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;01003)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_openat_order_32bit_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_32bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_openat_order_64bit_a20100_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;0100)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_openat_order_64bit_a201003_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;01003)[\s]+(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_openat_order_64bit_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_openat_order_64bit_a20100_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;0100)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_openat_order_64bit_a201003_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+a2&amp;01003)[\s]+(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_audit_rule_openat_order_64bit_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_64bit_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_rule_openat_order_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_32bit_openat_eacces_augenrules_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_nofilter_32bit_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a201003_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a201003_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_nofilter_32bit_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_32bit_openat_eperm_augenrules_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_nofilter_32bit_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a201003_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a201003_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_nofilter_32bit_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_64bit_openat_eacces_augenrules_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_nofilter_64bit_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a201003_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a201003_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a20100_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_nofilter_64bit_eacces_augenrules:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_64bit_openat_eperm_augenrules_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_nofilter_64bit_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a201003_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a201003_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a20100_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_nofilter_64bit_eperm_augenrules:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_32bit_openat_auditctl_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_nofilter_32bit_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a201003_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a201003_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_nofilter_32bit_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_32bit_openat_auditctl_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_nofilter_32bit_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a201003_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a201003_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_32bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_nofilter_32bit_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_openat_order_64bit_auditctl_eacces_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_nofilter_64bit_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a201003_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a201003_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a20100_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_nofilter_64bit_eacces_auditctl:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="arches to audit" datatype="string" id="oval:ssg-var_arufm_rule_order_64bit_openat_auditctl_eperm_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_nofilter_64bit_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a201003_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$\n(^(?!</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a201003_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>|</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_64bit_a20100_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>).*$\n)*^</oval-def:literal_component>
            <oval-def:object_component item_field="text" object_ref="oval:ssg-object_arufm_openat_order_nofilter_64bit_eperm_auditctl:obj:1"/>
            <oval-def:literal_component>$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_removexattr_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+removexattr[\s]+|([\s]+|[,])removexattr([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_removexattr_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+removexattr[\s]+|([\s]+|[,])removexattr([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_removexattr_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit removexattr EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_removexattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_removexattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_removexattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit removexattr EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_removexattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_removexattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_removexattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit removexattr EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_removexattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_removexattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_removexattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit removexattr EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_removexattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_removexattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_removexattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_rename_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+rename[\s]+|([\s]+|[,])rename([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_rename_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+rename[\s]+|([\s]+|[,])rename([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_rename_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit rename EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_rename_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_rename_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_rename_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit rename EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_rename_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_rename_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_rename_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit rename EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_rename_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_rename_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_rename_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit rename EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_rename_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_rename_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_rename_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_renameat_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+renameat[\s]+|([\s]+|[,])renameat([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_renameat_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+renameat[\s]+|([\s]+|[,])renameat([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_renameat_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit renameat EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_renameat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_renameat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_renameat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit renameat EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_renameat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_renameat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_renameat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit renameat EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_renameat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_renameat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_renameat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit renameat EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_renameat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_renameat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_renameat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_setxattr_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+setxattr[\s]+|([\s]+|[,])setxattr([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_setxattr_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+setxattr[\s]+|([\s]+|[,])setxattr([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_setxattr_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit setxattr EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_setxattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_setxattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_setxattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit setxattr EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_setxattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_setxattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_setxattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit setxattr EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_setxattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_setxattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_setxattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit setxattr EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_setxattr_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_setxattr_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_setxattr_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_truncate_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+truncate[\s]+|([\s]+|[,])truncate([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_truncate_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+truncate[\s]+|([\s]+|[,])truncate([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_truncate_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit truncate EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_truncate_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_truncate_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_truncate_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit truncate EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_truncate_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_truncate_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_truncate_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit truncate EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_truncate_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_truncate_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_truncate_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit truncate EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_truncate_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_truncate_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_truncate_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_unlink_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+unlink[\s]+|([\s]+|[,])unlink([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_unlink_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+unlink[\s]+|([\s]+|[,])unlink([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_unlink_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit unlink EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_unlink_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_unlink_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_unlink_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit unlink EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_unlink_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_unlink_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_unlink_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit unlink EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_unlink_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_unlink_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_unlink_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit unlink EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_unlink_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_unlink_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_unlink_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_32bit_arufm_unlinkat_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+unlinkat[\s]+|([\s]+|[,])unlinkat([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule arch and syscal" datatype="string" id="oval:ssg-var_64bit_arufm_unlinkat_head:var:1" version="1">
          <oval-def:value>^[\s]*-a[\s]+always,exit[\s]+(?:-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+unlinkat[\s]+|([\s]+|[,])unlinkat([\s]+|[,])))(?:(?!-F[\s]+a\d&amp;).)*</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="audit rule auid and key" datatype="string" id="oval:ssg-var_arufm_unlinkat_tail:var:1" version="1">
          <oval-def:value>[\s]+(?:-F\s+auid&gt;=1000[\s]+)(?:-F\s+auid!=(unset|4294967295)[\s]+)(?:-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Expression to match 32bit unlinkat EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eacces_unlinkat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_unlinkat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_unlinkat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 32bit unlinkat EPERM EACCES syscall" datatype="string" id="oval:ssg-var_32bit_arufm_eperm_unlinkat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_32bit_arufm_unlinkat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_unlinkat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit unlinkat EACCES syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eacces_unlinkat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_unlinkat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EACCES)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_unlinkat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Expression to match 64bit unlinkat EPERM syscall" datatype="string" id="oval:ssg-var_64bit_arufm_eperm_unlinkat_regex:var:1" version="1">
          <oval-def:concat>
            <oval-def:variable_component var_ref="oval:ssg-var_64bit_arufm_unlinkat_head:var:1"/>
            <oval-def:literal_component>(?:-F\s+exit=-EPERM)</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_arufm_unlinkat_tail:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_usergroup_modification_group_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/etc\/group</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_usergroup_modification_gshadow_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/etc\/gshadow</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_usergroup_modification_nsswitch_conf_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/etc\/nsswitch.conf</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_usergroup_modification_opasswd_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/etc\/security\/opasswd</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_usergroup_modification_pam_conf_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/etc\/pam.conf</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_usergroup_modification_pamd_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/etc\/pam.d\/</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_usergroup_modification_passwd_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/etc\/passwd</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_usergroup_modification_shadow_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/etc\/shadow</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_rules_var_spool_cron_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/var\/spool\/cron</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="The composite pattern used to detect if audit as been configured" datatype="string" id="oval:ssg-audit_sudo_log_events_path_pattern:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^\-w[\s]+</oval-def:literal_component>
            <oval-def:literal_component>\/var\/log\/sudo.log</oval-def:literal_component>
            <oval-def:literal_component>[\s]+\-p[\s]+\b([rx]*w[rx]*a[rx]*|[rx]*a[rx]*w[rx]*)\b.*$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Variable defining the value the argument should have" datatype="int" id="oval:ssg-var_auditd_freq:var:1" version="1"/>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupownerdir_group_ownership_library_dirs_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_ownerdir_ownership_binary_dirs_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_ownerdir_ownership_library_dirs_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Retrieve the gid of root from either /etc/group or /usr/lib/group" datatype="int" id="oval:ssg-var_file_groupownerdirectory_groupowner_etc_ipsecd_root_gid:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupownerdirectory_groupowner_etc_ipsecd_root_gid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Retrieve the gid of root from either /etc/group or /usr/lib/group" datatype="int" id="oval:ssg-var_file_groupownerdirectory_groupowner_etc_iptables_root_gid:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupownerdirectory_groupowner_etc_iptables_root_gid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Retrieve the gid of root from either /etc/group or /usr/lib/group" datatype="int" id="oval:ssg-var_file_groupownerdirectory_groupowner_etc_nftables_root_gid:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupownerdirectory_groupowner_etc_nftables_root_gid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Retrieve the gid of root from either /etc/group or /usr/lib/group" datatype="int" id="oval:ssg-var_file_groupownerdirectory_groupowner_etc_selinux_root_gid:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupownerdirectory_groupowner_etc_selinux_root_gid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Retrieve the gid of root from either /etc/group or /usr/lib/group" datatype="int" id="oval:ssg-var_file_groupownerdirectory_groupowner_etc_sudoersd_root_gid:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupownerdirectory_groupowner_etc_sudoersd_root_gid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Retrieve the gid of root from either /etc/group or /usr/lib/group" datatype="int" id="oval:ssg-var_file_groupownerdirectory_groupowner_etc_sysctld_root_gid:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupownerdirectory_groupowner_etc_sysctld_root_gid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_ownerdirectory_owner_etc_ipsecd_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_ownerdirectory_owner_etc_iptables_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_ownerdirectory_owner_etc_nftables_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_ownerdirectory_owner_etc_selinux_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_ownerdirectory_owner_etc_sudoersd_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_ownerdirectory_owner_etc_sysctld_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupownerfile_audit_tools_group_ownership_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_ownerfile_audit_tools_ownership_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_at_allow_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_backup_etc_group_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_backup_etc_gshadow_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_backup_etc_passwd_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_backup_etc_shadow_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_cron_allow_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_cron_d_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_cron_daily_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_cron_hourly_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_cron_monthly_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_cron_weekly_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_cron_yearly_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_crontab_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_efi_grub2_cfg_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_efi_user_cfg_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Retrieve the gid of root from either /etc/group or /usr/lib/group" datatype="int" id="oval:ssg-var_file_groupowner_etc_crypttab_root_gid:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupowner_etc_crypttab_root_gid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_etc_group_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_etc_gshadow_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Retrieve the gid of root from either /etc/group or /usr/lib/group" datatype="int" id="oval:ssg-var_file_groupowner_etc_ipsec_conf_root_gid:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupowner_etc_ipsec_conf_root_gid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Retrieve the gid of root from either /etc/group or /usr/lib/group" datatype="int" id="oval:ssg-var_file_groupowner_etc_ipsec_secrets_root_gid:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupowner_etc_ipsec_secrets_root_gid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_etc_issue_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_etc_issue_net_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_etc_motd_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_etc_passwd_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_etc_security_opasswd_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_etc_security_opasswd_old_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Retrieve the gid of root from either /etc/group or /usr/lib/group" datatype="int" id="oval:ssg-var_file_groupowner_etc_sestatus_conf_root_gid:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupowner_etc_sestatus_conf_root_gid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_etc_shadow_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_etc_shells_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Retrieve the gid of root from either /etc/group or /usr/lib/group" datatype="int" id="oval:ssg-var_file_groupowner_etc_sudoers_root_gid:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupowner_etc_sudoers_root_gid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_etc_sysconfig_sshd_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_grub2_cfg_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_sshd_config_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Retrieve the gid of root from either /etc/group or /usr/lib/group" datatype="int" id="oval:ssg-var_file_groupowner_systemmap_root_gid:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupowner_systemmap_root_gid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_user_cfg_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_var_log_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupowner_var_log_messages_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 4" datatype="int" id="oval:ssg-var_file_groupowner_var_log_syslog_4_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">4</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupownership_audit_binaries_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupownership_audit_configuration_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Retrieve the gid of ssh_keys from either /etc/group or /usr/lib/group" datatype="int" id="oval:ssg-var_file_groupownership_sshd_private_key_ssh_keys_gid:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupownership_sshd_private_key_ssh_keys_gid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupownership_sshd_pub_key_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_at_allow_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_backup_etc_group_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_backup_etc_gshadow_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_backup_etc_passwd_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_backup_etc_shadow_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_cron_allow_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_cron_d_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_cron_daily_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_cron_hourly_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_cron_monthly_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_cron_weekly_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_cron_yearly_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_crontab_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_efi_grub2_cfg_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_efi_user_cfg_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_etc_chrony_keys_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_etc_crypttab_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_etc_group_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_etc_gshadow_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_etc_ipsec_conf_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_etc_ipsec_secrets_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_etc_issue_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_etc_issue_net_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_etc_motd_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_etc_passwd_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_etc_security_opasswd_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_etc_security_opasswd_old_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_etc_sestatus_conf_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_etc_shadow_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_etc_shells_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_etc_sudoers_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_etc_sysconfig_sshd_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_grub2_cfg_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_sshd_config_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_systemmap_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_user_cfg_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_var_log_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_owner_var_log_messages_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Retrieve the uid of syslog" datatype="int" id="oval:ssg-var_file_owner_var_log_syslog_syslog_uid:var:1" version="1">
          <oval-def:object_component item_field="user_id" object_ref="oval:ssg-object_file_owner_var_log_syslog_syslog_uid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_ownership_audit_binaries_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_ownership_audit_configuration_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_ownership_library_dirs_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_ownership_sshd_private_key_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the uid to 0" datatype="int" id="oval:ssg-var_file_ownership_sshd_pub_key_0_uid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Regex that matches audit_backlog_limit with value var_audit_backlog_limit" datatype="string" id="oval:ssg-local_var_regex_audit_backlog_limit_var_audit_backlog_limit:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:.*\s)?audit_backlog_limit=</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_audit_backlog_limit:var:1"/>
            <oval-def:literal_component>(?:\s.*)?$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Variable defining the value the argument should have" datatype="string" id="oval:ssg-var_audit_backlog_limit:var:1" version="1"/>
        <oval-def:local_variable comment="Regex that matches l1tf with value var_l1tf_options" datatype="string" id="oval:ssg-local_var_regex_l1tf_var_l1tf_options:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:.*\s)?l1tf=</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_l1tf_options:var:1"/>
            <oval-def:literal_component>(?:\s.*)?$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Variable defining the value the argument should have" datatype="string" id="oval:ssg-var_l1tf_options:var:1" version="1"/>
        <oval-def:local_variable comment="Regex that matches rng_core.default_quality with value var_rng_core_default_quality" datatype="string" id="oval:ssg-local_var_regex_rng_core_default_quality_var_rng_core_default_quality:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:.*\s)?rng_core.default_quality=</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_rng_core_default_quality:var:1"/>
            <oval-def:literal_component>(?:\s.*)?$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Variable defining the value the argument should have" datatype="string" id="oval:ssg-var_rng_core_default_quality:var:1" version="1"/>
        <oval-def:local_variable comment="Regex that matches slub_debug with value var_slub_debug_options" datatype="string" id="oval:ssg-local_var_regex_slub_debug_var_slub_debug_options:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:.*\s)?slub_debug=</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_slub_debug_options:var:1"/>
            <oval-def:literal_component>(?:\s.*)?$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Variable defining the value the argument should have" datatype="string" id="oval:ssg-var_slub_debug_options:var:1" version="1"/>
        <oval-def:local_variable comment="Regex that matches spec_store_bypass_disable with value var_spec_store_bypass_disable_options" datatype="string" id="oval:ssg-local_var_regex_spec_store_bypass_disable_var_spec_store_bypass_disable_options:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^(?:.*\s)?spec_store_bypass_disable=</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_spec_store_bypass_disable_options:var:1"/>
            <oval-def:literal_component>(?:\s.*)?$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Variable defining the value the argument should have" datatype="string" id="oval:ssg-var_spec_store_bypass_disable_options:var:1" version="1"/>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_acpi_custom_method_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_acpi_custom_method_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_acpi_custom_method_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_acpi_custom_method:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_arm64_sw_ttbr0_pan_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_arm64_sw_ttbr0_pan_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_arm64_sw_ttbr0_pan_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_arm64_sw_ttbr0_pan:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_binfmt_misc_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_binfmt_misc_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_binfmt_misc_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_binfmt_misc:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_bug_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_bug_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_bug_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_bug:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_bug_on_data_corruption_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_bug_on_data_corruption_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_bug_on_data_corruption_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_bug_on_data_corruption:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_compat_brk_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_compat_brk_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_compat_brk_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_compat_brk:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_compat_vdso_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_compat_vdso_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_compat_vdso_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_compat_vdso:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_debug_credentials_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_debug_credentials_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_debug_credentials_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_debug_credentials:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_debug_fs_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_debug_fs_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_debug_fs_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_debug_fs:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_debug_list_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_debug_list_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_debug_list_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_debug_list:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_debug_notifiers_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_debug_notifiers_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_debug_notifiers_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_debug_notifiers:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_debug_sg_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_debug_sg_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_debug_sg_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_debug_sg:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_debug_wx_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_debug_wx_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_debug_wx_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_debug_wx:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_devkmem_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_devkmem_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_devkmem_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_devkmem:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_fortify_source_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_fortify_source_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_fortify_source_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_fortify_source:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_gcc_plugin_latent_entropy_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_gcc_plugin_latent_entropy_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_gcc_plugin_latent_entropy_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_gcc_plugin_latent_entropy:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_gcc_plugin_structleak_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_gcc_plugin_structleak_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_gcc_plugin_structleak_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_gcc_plugin_structleak:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_hardened_usercopy_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_hardened_usercopy_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_hardened_usercopy_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_hardened_usercopy:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_hardened_usercopy_fallback_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_hardened_usercopy_fallback_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_hardened_usercopy_fallback_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_hardened_usercopy_fallback:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_hibernation_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_hibernation_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_hibernation_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_hibernation:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_ia32_emulation_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_ia32_emulation_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_ia32_emulation_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_ia32_emulation:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_ipv6_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_ipv6_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_ipv6_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_ipv6:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_kexec_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_kexec_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_kexec_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_kexec:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_legacy_ptys_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_legacy_ptys_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_legacy_ptys_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_legacy_ptys:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_legacy_vsyscall_emulate_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_legacy_vsyscall_emulate_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_legacy_vsyscall_emulate_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_legacy_vsyscall_emulate:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_legacy_vsyscall_none_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_legacy_vsyscall_none_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_legacy_vsyscall_none_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_legacy_vsyscall_none:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_modify_ldt_syscall_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_modify_ldt_syscall_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_modify_ldt_syscall_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_modify_ldt_syscall:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_module_sig_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_module_sig_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_module_sig_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_module_sig:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_module_sig_all_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_module_sig_all_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_module_sig_all_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_module_sig_all:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_module_sig_force_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_module_sig_force_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_module_sig_force_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_module_sig_force:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_module_sig_hash_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_module_sig_hash_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_module_sig_hash_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_module_sig_hash:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Value for kernel CONFIG_MODULE_SIG_HASH setting" datatype="string" id="oval:ssg-var_kernel_config_module_sig_hash:var:1" version="1"/>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_module_sig_key_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_module_sig_key_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_module_sig_key_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_module_sig_key:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Value for kernel CONFIG_MODULE_SIG_KEY setting" datatype="string" id="oval:ssg-var_kernel_config_module_sig_key:var:1" version="1"/>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_module_sig_sha512_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_module_sig_sha512_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_module_sig_sha512_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_module_sig_sha512:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_page_poisoning_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_page_poisoning_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_page_poisoning_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_page_poisoning:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_page_poisoning_no_sanity_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_page_poisoning_no_sanity_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_page_poisoning_no_sanity_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_page_poisoning_no_sanity:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_page_poisoning_zero_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_page_poisoning_zero_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_page_poisoning_zero_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_page_poisoning_zero:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_page_table_isolation_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_page_table_isolation_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_page_table_isolation_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_page_table_isolation:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_panic_on_oops_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_panic_on_oops_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_panic_on_oops_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_panic_on_oops:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_panic_timeout_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_panic_timeout_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_panic_timeout_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_panic_timeout:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Value for kernel CONFIG_PANIC_TIMEOUT setting" datatype="string" id="oval:ssg-var_kernel_config_panic_timeout:var:1" version="1"/>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_proc_kcore_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_proc_kcore_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_proc_kcore_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_proc_kcore:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_randomize_base_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_randomize_base_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_randomize_base_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_randomize_base:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_randomize_memory_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_randomize_memory_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_randomize_memory_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_randomize_memory:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_refcount_full_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_refcount_full_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_refcount_full_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_refcount_full:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_retpoline_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_retpoline_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_retpoline_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_retpoline:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_sched_stack_end_check_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_sched_stack_end_check_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_sched_stack_end_check_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_sched_stack_end_check:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_seccomp_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_seccomp_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_seccomp_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_seccomp:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_seccomp_filter_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_seccomp_filter_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_seccomp_filter_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_seccomp_filter:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_security_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_security_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_security_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_security:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_security_dmesg_restrict_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_security_dmesg_restrict_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_security_dmesg_restrict_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_security_dmesg_restrict:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_security_writable_hooks_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_security_writable_hooks_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_security_writable_hooks_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_security_writable_hooks:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_security_yama_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_security_yama_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_security_yama_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_security_yama:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_slab_freelist_hardened_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_slab_freelist_hardened_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_slab_freelist_hardened_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_slab_freelist_hardened:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_slab_freelist_random_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_slab_freelist_random_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_slab_freelist_random_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_slab_freelist_random:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_slab_merge_default_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_slab_merge_default_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_slab_merge_default_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_slab_merge_default:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_slub_debug_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_slub_debug_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_slub_debug_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_slub_debug:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_stackprotector_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_stackprotector_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_stackprotector_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_stackprotector:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_stackprotector_strong_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_stackprotector_strong_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_stackprotector_strong_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_stackprotector_strong:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_strict_kernel_rwx_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_strict_kernel_rwx_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_strict_kernel_rwx_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_strict_kernel_rwx:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_strict_module_rwx_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_strict_module_rwx_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_strict_module_rwx_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_strict_module_rwx:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_syn_cookies_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_syn_cookies_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_syn_cookies_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_syn_cookies:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_unmap_kernel_at_el0_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_unmap_kernel_at_el0_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_unmap_kernel_at_el0_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_unmap_kernel_at_el0:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_vmap_stack_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_vmap_stack_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_vmap_stack_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_vmap_stack:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of kernels installed" datatype="int" id="oval:ssg-local_var_config_x86_vsyscall_emulation_count_kernels_installed:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_x86_vsyscall_emulation_files:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Count number of configs found" datatype="int" id="oval:ssg-local_var_config_x86_vsyscall_emulation_count_compliant_configs:var:1" version="1">
          <oval-def:count>
            <oval-def:unique>
              <oval-def:object_component item_field="filepath" object_ref="oval:ssg-object_kernel_config_x86_vsyscall_emulation:obj:1"/>
            </oval-def:unique>
          </oval-def:count>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_atm_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_bluetooth_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_can_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_cfg80211_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_cramfs_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_dccp_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_firewire-core_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_freevxfs_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_hfs_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_hfsplus_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_iwlmvm_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_iwlwifi_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_jffs2_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_mac80211_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_overlayfs_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_rds_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_sctp_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_squashfs_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_tipc_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_udf_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_usb-storage_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_uvcvideo_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="Other paths where kernel modules can be configured" datatype="string" id="oval:ssg-var_kernel_module_vfat_paths:var:1" version="1">
          <oval-def:value>/etc/modprobe.d</oval-def:value>
          <oval-def:value>/etc/modules-load.d</oval-def:value>
          <oval-def:value>/run/modprobe.d</oval-def:value>
          <oval-def:value>/run/modules-load.d</oval-def:value>
          <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
          <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:constant_variable comment="CD/DVD drive allowed alternative names" datatype="string" id="oval:ssg-variable_cd_dvd_drive_alternative_names_nodev:var:1" version="1">
          <oval-def:value>/dev/cdrom</oval-def:value>
          <oval-def:value>/dev/dvd</oval-def:value>
          <oval-def:value>/dev/scd0</oval-def:value>
          <oval-def:value>/dev/sr0</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Regular expression pattern for CD / DVD drive alternative names" datatype="string" id="oval:ssg-variable_cd_dvd_drive_regex_pattern_nodev:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^[\s]*</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-variable_cd_dvd_drive_alternative_names_nodev:var:1"/>
            <oval-def:literal_component>[\s]+[/\w]+[\s]+[\w]+[\s]+([^\s]+)(?:[\s]+[\d]+){2}$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Regular expression pattern for removable block special device other than CD / DVD drive" datatype="string" id="oval:ssg-variable_not_cd_dvd_drive_regex_pattern_nodev:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^[\s]*</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_removable_partition:var:1"/>
            <oval-def:literal_component>[\s]+[/\w]+[\s]+[\w]+[\s]+([^\s]+)(?:[\s]+[\d]+){2}$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="removable partition" datatype="string" id="oval:ssg-var_removable_partition:var:1" version="1"/>
        <oval-def:constant_variable comment="CD/DVD drive allowed alternative names" datatype="string" id="oval:ssg-variable_cd_dvd_drive_alternative_names_noexec:var:1" version="1">
          <oval-def:value>/dev/cdrom</oval-def:value>
          <oval-def:value>/dev/dvd</oval-def:value>
          <oval-def:value>/dev/scd0</oval-def:value>
          <oval-def:value>/dev/sr0</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Regular expression pattern for CD / DVD drive alternative names" datatype="string" id="oval:ssg-variable_cd_dvd_drive_regex_pattern_noexec:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^[\s]*</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-variable_cd_dvd_drive_alternative_names_noexec:var:1"/>
            <oval-def:literal_component>[\s]+[/\w]+[\s]+[\w]+[\s]+([^\s]+)(?:[\s]+[\d]+){2}$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Regular expression pattern for removable block special device other than CD / DVD drive" datatype="string" id="oval:ssg-variable_not_cd_dvd_drive_regex_pattern_noexec:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^[\s]*</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_removable_partition:var:1"/>
            <oval-def:literal_component>[\s]+[/\w]+[\s]+[\w]+[\s]+([^\s]+)(?:[\s]+[\d]+){2}$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="CD/DVD drive allowed alternative names" datatype="string" id="oval:ssg-variable_cd_dvd_drive_alternative_names_nosuid:var:1" version="1">
          <oval-def:value>/dev/cdrom</oval-def:value>
          <oval-def:value>/dev/dvd</oval-def:value>
          <oval-def:value>/dev/scd0</oval-def:value>
          <oval-def:value>/dev/sr0</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="Regular expression pattern for CD / DVD drive alternative names" datatype="string" id="oval:ssg-variable_cd_dvd_drive_regex_pattern_nosuid:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^[\s]*</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-variable_cd_dvd_drive_alternative_names_nosuid:var:1"/>
            <oval-def:literal_component>[\s]+[/\w]+[\s]+[\w]+[\s]+([^\s]+)(?:[\s]+[\d]+){2}$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Regular expression pattern for removable block special device other than CD / DVD drive" datatype="string" id="oval:ssg-variable_not_cd_dvd_drive_regex_pattern_nosuid:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>^[\s]*</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_removable_partition:var:1"/>
            <oval-def:literal_component>[\s]+[/\w]+[\s]+[\w]+[\s]+([^\s]+)(?:[\s]+[\d]+){2}$</oval-def:literal_component>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Variable defining the value the argument should have" datatype="string" id="oval:ssg-var_mount_option_proc_hidepid:var:1" version="1"/>
        <oval-def:local_variable comment="Value used in hidepid option as defined in var_mount_option_proc_hidepid variable" datatype="string" id="oval:ssg-local_var_mountoption_hidepid_with_value:var:1" version="1">
          <oval-def:concat>
            <oval-def:literal_component>hidepid=</oval-def:literal_component>
            <oval-def:variable_component var_ref="oval:ssg-var_mount_option_proc_hidepid:var:1"/>
          </oval-def:concat>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Set the gid to 0" datatype="int" id="oval:ssg-var_file_groupownerroot_permissions_syslibrary_files_0_gid:var:1" version="1">
          <oval-def:literal_component datatype="int">0</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="rsyslog's include config values converted to regex." datatype="string" id="oval:ssg-var_rsyslog_files_groupownership_include_config_regex:var:1" version="1">
          <oval-def:unique>
            <oval-def:glob_to_regex>
              <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_rsyslog_files_groupownership_include_config_value:obj:1"/>
            </oval-def:glob_to_regex>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Main rsyslog configuration file." datatype="string" id="oval:ssg-var_rsyslog_files_groupownership_syslog_config:var:1" version="1">
          <oval-def:literal_component datatype="string">^/etc/rsyslog.conf$</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Locations of all rsyslog configuration files as collection." datatype="string" id="oval:ssg-var_rsyslog_files_groupownership_all_conf_files:var:1" version="1">
          <oval-def:object_component item_field="value" object_ref="oval:ssg-object_var_rsyslog_files_groupownership_all_conf_files:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="File paths of all rsyslog log files" datatype="string" id="oval:ssg-var_rsyslog_files_groupownership_log_files_paths:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_rsyslog_files_groupownership_log_files_paths:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="GID of group root" datatype="int" id="oval:ssg-var_rsyslog_files_groupownership_groupowner_gid:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_rsyslog_files_groupownership_groupowner_gid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="rsyslog's include config values converted to regex." datatype="string" id="oval:ssg-var_rsyslog_files_ownership_include_config_regex:var:1" version="1">
          <oval-def:unique>
            <oval-def:glob_to_regex>
              <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_rsyslog_files_ownership_include_config_value:obj:1"/>
            </oval-def:glob_to_regex>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Main rsyslog configuration file." datatype="string" id="oval:ssg-var_rsyslog_files_ownership_syslog_config:var:1" version="1">
          <oval-def:literal_component datatype="string">^/etc/rsyslog.conf$</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Locations of all rsyslog configuration files as collection." datatype="string" id="oval:ssg-var_rsyslog_files_ownership_all_conf_files:var:1" version="1">
          <oval-def:object_component item_field="value" object_ref="oval:ssg-object_var_rsyslog_files_ownership_all_conf_files:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="File paths of all rsyslog log files" datatype="string" id="oval:ssg-var_rsyslog_files_ownership_log_files_paths:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_rsyslog_files_ownership_log_files_paths:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="UID of user root" datatype="int" id="oval:ssg-var_rsyslog_files_ownership_owner_uid:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-obj_rsyslog_files_ownership_owner_uid:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="rsyslog's include config values converted to regex." datatype="string" id="oval:ssg-var_rsyslog_files_permissions_include_config_regex:var:1" version="1">
          <oval-def:unique>
            <oval-def:glob_to_regex>
              <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_rsyslog_files_permissions_include_config_value:obj:1"/>
            </oval-def:glob_to_regex>
          </oval-def:unique>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Main rsyslog configuration file." datatype="string" id="oval:ssg-var_rsyslog_files_permissions_syslog_config:var:1" version="1">
          <oval-def:literal_component datatype="string">^/etc/rsyslog.conf$</oval-def:literal_component>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Locations of all rsyslog configuration files as collection." datatype="string" id="oval:ssg-var_rsyslog_files_permissions_all_conf_files:var:1" version="1">
          <oval-def:object_component item_field="value" object_ref="oval:ssg-object_var_rsyslog_files_permissions_all_conf_files:obj:1"/>
        </oval-def:local_variable>
        <oval-def:local_variable comment="File paths of all rsyslog log files" datatype="string" id="oval:ssg-var_rsyslog_files_permissions_log_files_paths:var:1" version="1">
          <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_rsyslog_files_permissions_log_files_paths:obj:1"/>
        </oval-def:local_variable>
        <oval-def:external_variable comment="external variable for abrt_anon_write" datatype="boolean" id="oval:ssg-var_abrt_anon_write:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for abrt_handle_event" datatype="boolean" id="oval:ssg-var_abrt_handle_event:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for abrt_upload_watch_anon_write" datatype="boolean" id="oval:ssg-var_abrt_upload_watch_anon_write:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for antivirus_can_scan_system" datatype="boolean" id="oval:ssg-var_antivirus_can_scan_system:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for antivirus_use_jit" datatype="boolean" id="oval:ssg-var_antivirus_use_jit:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for auditadm_exec_content" datatype="boolean" id="oval:ssg-var_auditadm_exec_content:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for authlogin_nsswitch_use_ldap" datatype="boolean" id="oval:ssg-var_authlogin_nsswitch_use_ldap:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for authlogin_radius" datatype="boolean" id="oval:ssg-var_authlogin_radius:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for authlogin_yubikey" datatype="boolean" id="oval:ssg-var_authlogin_yubikey:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for awstats_purge_apache_log_files" datatype="boolean" id="oval:ssg-var_awstats_purge_apache_log_files:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for boinc_execmem" datatype="boolean" id="oval:ssg-var_boinc_execmem:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for cdrecord_read_content" datatype="boolean" id="oval:ssg-var_cdrecord_read_content:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for cluster_can_network_connect" datatype="boolean" id="oval:ssg-var_cluster_can_network_connect:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for cluster_manage_all_files" datatype="boolean" id="oval:ssg-var_cluster_manage_all_files:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for cluster_use_execmem" datatype="boolean" id="oval:ssg-var_cluster_use_execmem:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for cobbler_anon_write" datatype="boolean" id="oval:ssg-var_cobbler_anon_write:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for cobbler_can_network_connect" datatype="boolean" id="oval:ssg-var_cobbler_can_network_connect:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for cobbler_use_cifs" datatype="boolean" id="oval:ssg-var_cobbler_use_cifs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for cobbler_use_nfs" datatype="boolean" id="oval:ssg-var_cobbler_use_nfs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for collectd_tcp_network_connect" datatype="boolean" id="oval:ssg-var_collectd_tcp_network_connect:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for condor_tcp_network_connect" datatype="boolean" id="oval:ssg-var_condor_tcp_network_connect:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for conman_can_network" datatype="boolean" id="oval:ssg-var_conman_can_network:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for container_connect_any" datatype="boolean" id="oval:ssg-var_container_connect_any:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for cron_can_relabel" datatype="boolean" id="oval:ssg-var_cron_can_relabel:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for cron_system_cronjob_use_shares" datatype="boolean" id="oval:ssg-var_cron_system_cronjob_use_shares:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for cron_userdomain_transition" datatype="boolean" id="oval:ssg-var_cron_userdomain_transition:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for cups_execmem" datatype="boolean" id="oval:ssg-var_cups_execmem:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for cvs_read_shadow" datatype="boolean" id="oval:ssg-var_cvs_read_shadow:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for daemons_dump_core" datatype="boolean" id="oval:ssg-var_daemons_dump_core:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for daemons_enable_cluster_mode" datatype="boolean" id="oval:ssg-var_daemons_enable_cluster_mode:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for daemons_use_tcp_wrapper" datatype="boolean" id="oval:ssg-var_daemons_use_tcp_wrapper:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for daemons_use_tty" datatype="boolean" id="oval:ssg-var_daemons_use_tty:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for dbadm_exec_content" datatype="boolean" id="oval:ssg-var_dbadm_exec_content:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for dbadm_manage_user_files" datatype="boolean" id="oval:ssg-var_dbadm_manage_user_files:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for dbadm_read_user_files" datatype="boolean" id="oval:ssg-var_dbadm_read_user_files:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for deny_execmem" datatype="boolean" id="oval:ssg-var_deny_execmem:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for deny_ptrace" datatype="boolean" id="oval:ssg-var_deny_ptrace:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for dhcpc_exec_iptables" datatype="boolean" id="oval:ssg-var_dhcpc_exec_iptables:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for dhcpd_use_ldap" datatype="boolean" id="oval:ssg-var_dhcpd_use_ldap:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for domain_fd_use" datatype="boolean" id="oval:ssg-var_domain_fd_use:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for domain_kernel_load_modules" datatype="boolean" id="oval:ssg-var_domain_kernel_load_modules:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for entropyd_use_audio" datatype="boolean" id="oval:ssg-var_entropyd_use_audio:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for exim_can_connect_db" datatype="boolean" id="oval:ssg-var_exim_can_connect_db:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for exim_manage_user_files" datatype="boolean" id="oval:ssg-var_exim_manage_user_files:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for exim_read_user_files" datatype="boolean" id="oval:ssg-var_exim_read_user_files:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for fcron_crond" datatype="boolean" id="oval:ssg-var_fcron_crond:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for fenced_can_network_connect" datatype="boolean" id="oval:ssg-var_fenced_can_network_connect:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for fenced_can_ssh" datatype="boolean" id="oval:ssg-var_fenced_can_ssh:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for fips_mode" datatype="boolean" id="oval:ssg-var_fips_mode:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for ftpd_anon_write" datatype="boolean" id="oval:ssg-var_ftpd_anon_write:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for ftpd_connect_all_unreserved" datatype="boolean" id="oval:ssg-var_ftpd_connect_all_unreserved:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for ftpd_connect_db" datatype="boolean" id="oval:ssg-var_ftpd_connect_db:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for ftpd_full_access" datatype="boolean" id="oval:ssg-var_ftpd_full_access:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for ftpd_use_cifs" datatype="boolean" id="oval:ssg-var_ftpd_use_cifs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for ftpd_use_fusefs" datatype="boolean" id="oval:ssg-var_ftpd_use_fusefs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for ftpd_use_nfs" datatype="boolean" id="oval:ssg-var_ftpd_use_nfs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for ftpd_use_passive_mode" datatype="boolean" id="oval:ssg-var_ftpd_use_passive_mode:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for git_cgi_enable_homedirs" datatype="boolean" id="oval:ssg-var_git_cgi_enable_homedirs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for git_cgi_use_cifs" datatype="boolean" id="oval:ssg-var_git_cgi_use_cifs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for git_cgi_use_nfs" datatype="boolean" id="oval:ssg-var_git_cgi_use_nfs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for git_session_bind_all_unreserved_ports" datatype="boolean" id="oval:ssg-var_git_session_bind_all_unreserved_ports:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for git_session_users" datatype="boolean" id="oval:ssg-var_git_session_users:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for git_system_enable_homedirs" datatype="boolean" id="oval:ssg-var_git_system_enable_homedirs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for git_system_use_cifs" datatype="boolean" id="oval:ssg-var_git_system_use_cifs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for git_system_use_nfs" datatype="boolean" id="oval:ssg-var_git_system_use_nfs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for gitosis_can_sendmail" datatype="boolean" id="oval:ssg-var_gitosis_can_sendmail:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for glance_api_can_network" datatype="boolean" id="oval:ssg-var_glance_api_can_network:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for glance_use_execmem" datatype="boolean" id="oval:ssg-var_glance_use_execmem:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for glance_use_fusefs" datatype="boolean" id="oval:ssg-var_glance_use_fusefs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for global_ssp" datatype="boolean" id="oval:ssg-var_global_ssp:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for gluster_anon_write" datatype="boolean" id="oval:ssg-var_gluster_anon_write:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for gluster_export_all_ro" datatype="boolean" id="oval:ssg-var_gluster_export_all_ro:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for gluster_export_all_rw" datatype="boolean" id="oval:ssg-var_gluster_export_all_rw:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for gpg_web_anon_write" datatype="boolean" id="oval:ssg-var_gpg_web_anon_write:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for gssd_read_tmp" datatype="boolean" id="oval:ssg-var_gssd_read_tmp:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for guest_exec_content" datatype="boolean" id="oval:ssg-var_guest_exec_content:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for haproxy_connect_any" datatype="boolean" id="oval:ssg-var_haproxy_connect_any:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_anon_write" datatype="boolean" id="oval:ssg-var_httpd_anon_write:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_builtin_scripting" datatype="boolean" id="oval:ssg-var_httpd_builtin_scripting:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_can_check_spam" datatype="boolean" id="oval:ssg-var_httpd_can_check_spam:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_can_connect_ftp" datatype="boolean" id="oval:ssg-var_httpd_can_connect_ftp:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_can_connect_ldap" datatype="boolean" id="oval:ssg-var_httpd_can_connect_ldap:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_can_connect_mythtv" datatype="boolean" id="oval:ssg-var_httpd_can_connect_mythtv:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_can_connect_zabbix" datatype="boolean" id="oval:ssg-var_httpd_can_connect_zabbix:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_can_network_connect" datatype="boolean" id="oval:ssg-var_httpd_can_network_connect:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_can_network_connect_cobbler" datatype="boolean" id="oval:ssg-var_httpd_can_network_connect_cobbler:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_can_network_connect_db" datatype="boolean" id="oval:ssg-var_httpd_can_network_connect_db:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_can_network_memcache" datatype="boolean" id="oval:ssg-var_httpd_can_network_memcache:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_can_network_relay" datatype="boolean" id="oval:ssg-var_httpd_can_network_relay:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_can_sendmail" datatype="boolean" id="oval:ssg-var_httpd_can_sendmail:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_dbus_avahi" datatype="boolean" id="oval:ssg-var_httpd_dbus_avahi:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_dbus_sssd" datatype="boolean" id="oval:ssg-var_httpd_dbus_sssd:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_dontaudit_search_dirs" datatype="boolean" id="oval:ssg-var_httpd_dontaudit_search_dirs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_enable_cgi" datatype="boolean" id="oval:ssg-var_httpd_enable_cgi:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_enable_ftp_server" datatype="boolean" id="oval:ssg-var_httpd_enable_ftp_server:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_enable_homedirs" datatype="boolean" id="oval:ssg-var_httpd_enable_homedirs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_execmem" datatype="boolean" id="oval:ssg-var_httpd_execmem:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_graceful_shutdown" datatype="boolean" id="oval:ssg-var_httpd_graceful_shutdown:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_manage_ipa" datatype="boolean" id="oval:ssg-var_httpd_manage_ipa:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_mod_auth_ntlm_winbind" datatype="boolean" id="oval:ssg-var_httpd_mod_auth_ntlm_winbind:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_mod_auth_pam" datatype="boolean" id="oval:ssg-var_httpd_mod_auth_pam:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_read_user_content" datatype="boolean" id="oval:ssg-var_httpd_read_user_content:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_run_ipa" datatype="boolean" id="oval:ssg-var_httpd_run_ipa:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_run_preupgrade" datatype="boolean" id="oval:ssg-var_httpd_run_preupgrade:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_run_stickshift" datatype="boolean" id="oval:ssg-var_httpd_run_stickshift:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_serve_cobbler_files" datatype="boolean" id="oval:ssg-var_httpd_serve_cobbler_files:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_setrlimit" datatype="boolean" id="oval:ssg-var_httpd_setrlimit:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_ssi_exec" datatype="boolean" id="oval:ssg-var_httpd_ssi_exec:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_sys_script_anon_write" datatype="boolean" id="oval:ssg-var_httpd_sys_script_anon_write:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_tmp_exec" datatype="boolean" id="oval:ssg-var_httpd_tmp_exec:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_tty_comm" datatype="boolean" id="oval:ssg-var_httpd_tty_comm:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_unified" datatype="boolean" id="oval:ssg-var_httpd_unified:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_use_cifs" datatype="boolean" id="oval:ssg-var_httpd_use_cifs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_use_fusefs" datatype="boolean" id="oval:ssg-var_httpd_use_fusefs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_use_gpg" datatype="boolean" id="oval:ssg-var_httpd_use_gpg:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_use_nfs" datatype="boolean" id="oval:ssg-var_httpd_use_nfs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_use_openstack" datatype="boolean" id="oval:ssg-var_httpd_use_openstack:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_use_sasl" datatype="boolean" id="oval:ssg-var_httpd_use_sasl:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for httpd_verify_dns" datatype="boolean" id="oval:ssg-var_httpd_verify_dns:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for icecast_use_any_tcp_ports" datatype="boolean" id="oval:ssg-var_icecast_use_any_tcp_ports:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for irc_use_any_tcp_ports" datatype="boolean" id="oval:ssg-var_irc_use_any_tcp_ports:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for irssi_use_full_network" datatype="boolean" id="oval:ssg-var_irssi_use_full_network:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for kdumpgui_run_bootloader" datatype="boolean" id="oval:ssg-var_kdumpgui_run_bootloader:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for kerberos_enabled" datatype="boolean" id="oval:ssg-var_kerberos_enabled:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for ksmtuned_use_cifs" datatype="boolean" id="oval:ssg-var_ksmtuned_use_cifs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for ksmtuned_use_nfs" datatype="boolean" id="oval:ssg-var_ksmtuned_use_nfs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for logadm_exec_content" datatype="boolean" id="oval:ssg-var_logadm_exec_content:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for logging_syslogd_can_sendmail" datatype="boolean" id="oval:ssg-var_logging_syslogd_can_sendmail:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for logging_syslogd_run_nagios_plugins" datatype="boolean" id="oval:ssg-var_logging_syslogd_run_nagios_plugins:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for logging_syslogd_use_tty" datatype="boolean" id="oval:ssg-var_logging_syslogd_use_tty:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for login_console_enabled" datatype="boolean" id="oval:ssg-var_login_console_enabled:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for logrotate_use_nfs" datatype="boolean" id="oval:ssg-var_logrotate_use_nfs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for logwatch_can_network_connect_mail" datatype="boolean" id="oval:ssg-var_logwatch_can_network_connect_mail:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for lsmd_plugin_connect_any" datatype="boolean" id="oval:ssg-var_lsmd_plugin_connect_any:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mailman_use_fusefs" datatype="boolean" id="oval:ssg-var_mailman_use_fusefs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mcelog_client" datatype="boolean" id="oval:ssg-var_mcelog_client:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mcelog_exec_scripts" datatype="boolean" id="oval:ssg-var_mcelog_exec_scripts:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mcelog_foreground" datatype="boolean" id="oval:ssg-var_mcelog_foreground:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mcelog_server" datatype="boolean" id="oval:ssg-var_mcelog_server:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for minidlna_read_generic_user_content" datatype="boolean" id="oval:ssg-var_minidlna_read_generic_user_content:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mmap_low_allowed" datatype="boolean" id="oval:ssg-var_mmap_low_allowed:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mock_enable_homedirs" datatype="boolean" id="oval:ssg-var_mock_enable_homedirs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mount_anyfile" datatype="boolean" id="oval:ssg-var_mount_anyfile:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mozilla_plugin_bind_unreserved_ports" datatype="boolean" id="oval:ssg-var_mozilla_plugin_bind_unreserved_ports:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mozilla_plugin_can_network_connect" datatype="boolean" id="oval:ssg-var_mozilla_plugin_can_network_connect:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mozilla_plugin_use_bluejeans" datatype="boolean" id="oval:ssg-var_mozilla_plugin_use_bluejeans:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mozilla_plugin_use_gps" datatype="boolean" id="oval:ssg-var_mozilla_plugin_use_gps:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mozilla_plugin_use_spice" datatype="boolean" id="oval:ssg-var_mozilla_plugin_use_spice:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mozilla_read_content" datatype="boolean" id="oval:ssg-var_mozilla_read_content:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mpd_enable_homedirs" datatype="boolean" id="oval:ssg-var_mpd_enable_homedirs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mpd_use_cifs" datatype="boolean" id="oval:ssg-var_mpd_use_cifs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mpd_use_nfs" datatype="boolean" id="oval:ssg-var_mpd_use_nfs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mplayer_execstack" datatype="boolean" id="oval:ssg-var_mplayer_execstack:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for mysql_connect_any" datatype="boolean" id="oval:ssg-var_mysql_connect_any:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for nagios_run_pnp4nagios" datatype="boolean" id="oval:ssg-var_nagios_run_pnp4nagios:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for nagios_run_sudo" datatype="boolean" id="oval:ssg-var_nagios_run_sudo:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for named_tcp_bind_http_port" datatype="boolean" id="oval:ssg-var_named_tcp_bind_http_port:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for named_write_master_zones" datatype="boolean" id="oval:ssg-var_named_write_master_zones:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for neutron_can_network" datatype="boolean" id="oval:ssg-var_neutron_can_network:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for nfs_export_all_ro" datatype="boolean" id="oval:ssg-var_nfs_export_all_ro:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for nfs_export_all_rw" datatype="boolean" id="oval:ssg-var_nfs_export_all_rw:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for nfsd_anon_write" datatype="boolean" id="oval:ssg-var_nfsd_anon_write:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for nis_enabled" datatype="boolean" id="oval:ssg-var_nis_enabled:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for nscd_use_shm" datatype="boolean" id="oval:ssg-var_nscd_use_shm:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for openshift_use_nfs" datatype="boolean" id="oval:ssg-var_openshift_use_nfs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for openvpn_can_network_connect" datatype="boolean" id="oval:ssg-var_openvpn_can_network_connect:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for openvpn_enable_homedirs" datatype="boolean" id="oval:ssg-var_openvpn_enable_homedirs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for openvpn_run_unconfined" datatype="boolean" id="oval:ssg-var_openvpn_run_unconfined:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for pcp_bind_all_unreserved_ports" datatype="boolean" id="oval:ssg-var_pcp_bind_all_unreserved_ports:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for pcp_read_generic_logs" datatype="boolean" id="oval:ssg-var_pcp_read_generic_logs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for piranha_lvs_can_network_connect" datatype="boolean" id="oval:ssg-var_piranha_lvs_can_network_connect:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for polipo_connect_all_unreserved" datatype="boolean" id="oval:ssg-var_polipo_connect_all_unreserved:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for polipo_session_bind_all_unreserved_ports" datatype="boolean" id="oval:ssg-var_polipo_session_bind_all_unreserved_ports:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for polipo_session_users" datatype="boolean" id="oval:ssg-var_polipo_session_users:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for polipo_use_cifs" datatype="boolean" id="oval:ssg-var_polipo_use_cifs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for polipo_use_nfs" datatype="boolean" id="oval:ssg-var_polipo_use_nfs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for polyinstantiation_enabled" datatype="boolean" id="oval:ssg-var_polyinstantiation_enabled:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for postfix_local_write_mail_spool" datatype="boolean" id="oval:ssg-var_postfix_local_write_mail_spool:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for postgresql_can_rsync" datatype="boolean" id="oval:ssg-var_postgresql_can_rsync:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for postgresql_selinux_transmit_client_label" datatype="boolean" id="oval:ssg-var_postgresql_selinux_transmit_client_label:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for postgresql_selinux_unconfined_dbadm" datatype="boolean" id="oval:ssg-var_postgresql_selinux_unconfined_dbadm:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for postgresql_selinux_users_ddl" datatype="boolean" id="oval:ssg-var_postgresql_selinux_users_ddl:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for pppd_can_insmod" datatype="boolean" id="oval:ssg-var_pppd_can_insmod:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for pppd_for_user" datatype="boolean" id="oval:ssg-var_pppd_for_user:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for privoxy_connect_any" datatype="boolean" id="oval:ssg-var_privoxy_connect_any:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for prosody_bind_http_port" datatype="boolean" id="oval:ssg-var_prosody_bind_http_port:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for puppetagent_manage_all_files" datatype="boolean" id="oval:ssg-var_puppetagent_manage_all_files:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for puppetmaster_use_db" datatype="boolean" id="oval:ssg-var_puppetmaster_use_db:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for racoon_read_shadow" datatype="boolean" id="oval:ssg-var_racoon_read_shadow:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for rsync_anon_write" datatype="boolean" id="oval:ssg-var_rsync_anon_write:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for rsync_client" datatype="boolean" id="oval:ssg-var_rsync_client:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for rsync_export_all_ro" datatype="boolean" id="oval:ssg-var_rsync_export_all_ro:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for rsync_full_access" datatype="boolean" id="oval:ssg-var_rsync_full_access:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for samba_create_home_dirs" datatype="boolean" id="oval:ssg-var_samba_create_home_dirs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for samba_domain_controller" datatype="boolean" id="oval:ssg-var_samba_domain_controller:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for samba_enable_home_dirs" datatype="boolean" id="oval:ssg-var_samba_enable_home_dirs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for samba_export_all_ro" datatype="boolean" id="oval:ssg-var_samba_export_all_ro:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for samba_export_all_rw" datatype="boolean" id="oval:ssg-var_samba_export_all_rw:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for samba_load_libgfapi" datatype="boolean" id="oval:ssg-var_samba_load_libgfapi:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for samba_portmapper" datatype="boolean" id="oval:ssg-var_samba_portmapper:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for samba_run_unconfined" datatype="boolean" id="oval:ssg-var_samba_run_unconfined:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for samba_share_fusefs" datatype="boolean" id="oval:ssg-var_samba_share_fusefs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for samba_share_nfs" datatype="boolean" id="oval:ssg-var_samba_share_nfs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for sanlock_use_fusefs" datatype="boolean" id="oval:ssg-var_sanlock_use_fusefs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for sanlock_use_nfs" datatype="boolean" id="oval:ssg-var_sanlock_use_nfs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for sanlock_use_samba" datatype="boolean" id="oval:ssg-var_sanlock_use_samba:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for saslauthd_read_shadow" datatype="boolean" id="oval:ssg-var_saslauthd_read_shadow:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for secadm_exec_content" datatype="boolean" id="oval:ssg-var_secadm_exec_content:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for secure_mode" datatype="boolean" id="oval:ssg-var_secure_mode:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for secure_mode_insmod" datatype="boolean" id="oval:ssg-var_secure_mode_insmod:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for secure_mode_policyload" datatype="boolean" id="oval:ssg-var_secure_mode_policyload:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for selinuxuser_direct_dri_enabled" datatype="boolean" id="oval:ssg-var_selinuxuser_direct_dri_enabled:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for selinuxuser_execheap" datatype="boolean" id="oval:ssg-var_selinuxuser_execheap:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for selinuxuser_execmod" datatype="boolean" id="oval:ssg-var_selinuxuser_execmod:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for selinuxuser_execstack" datatype="boolean" id="oval:ssg-var_selinuxuser_execstack:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for selinuxuser_mysql_connect_enabled" datatype="boolean" id="oval:ssg-var_selinuxuser_mysql_connect_enabled:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for selinuxuser_ping" datatype="boolean" id="oval:ssg-var_selinuxuser_ping:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for selinuxuser_postgresql_connect_enabled" datatype="boolean" id="oval:ssg-var_selinuxuser_postgresql_connect_enabled:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for selinuxuser_rw_noexattrfile" datatype="boolean" id="oval:ssg-var_selinuxuser_rw_noexattrfile:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for selinuxuser_share_music" datatype="boolean" id="oval:ssg-var_selinuxuser_share_music:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for selinuxuser_tcp_server" datatype="boolean" id="oval:ssg-var_selinuxuser_tcp_server:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for selinuxuser_udp_server" datatype="boolean" id="oval:ssg-var_selinuxuser_udp_server:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for selinuxuser_use_ssh_chroot" datatype="boolean" id="oval:ssg-var_selinuxuser_use_ssh_chroot:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for sge_domain_can_network_connect" datatype="boolean" id="oval:ssg-var_sge_domain_can_network_connect:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for sge_use_nfs" datatype="boolean" id="oval:ssg-var_sge_use_nfs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for smartmon_3ware" datatype="boolean" id="oval:ssg-var_smartmon_3ware:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for smbd_anon_write" datatype="boolean" id="oval:ssg-var_smbd_anon_write:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for spamassassin_can_network" datatype="boolean" id="oval:ssg-var_spamassassin_can_network:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for spamd_enable_home_dirs" datatype="boolean" id="oval:ssg-var_spamd_enable_home_dirs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for squid_connect_any" datatype="boolean" id="oval:ssg-var_squid_connect_any:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for squid_use_tproxy" datatype="boolean" id="oval:ssg-var_squid_use_tproxy:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for ssh_chroot_rw_homedirs" datatype="boolean" id="oval:ssg-var_ssh_chroot_rw_homedirs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for ssh_keysign" datatype="boolean" id="oval:ssg-var_ssh_keysign:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for ssh_sysadm_login" datatype="boolean" id="oval:ssg-var_ssh_sysadm_login:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for staff_exec_content" datatype="boolean" id="oval:ssg-var_staff_exec_content:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for staff_use_svirt" datatype="boolean" id="oval:ssg-var_staff_use_svirt:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for swift_can_network" datatype="boolean" id="oval:ssg-var_swift_can_network:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for sysadm_exec_content" datatype="boolean" id="oval:ssg-var_sysadm_exec_content:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for telepathy_connect_all_ports" datatype="boolean" id="oval:ssg-var_telepathy_connect_all_ports:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for telepathy_tcp_connect_generic_network_ports" datatype="boolean" id="oval:ssg-var_telepathy_tcp_connect_generic_network_ports:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for tftp_anon_write" datatype="boolean" id="oval:ssg-var_tftp_anon_write:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for tftp_home_dir" datatype="boolean" id="oval:ssg-var_tftp_home_dir:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for tmpreaper_use_nfs" datatype="boolean" id="oval:ssg-var_tmpreaper_use_nfs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for tmpreaper_use_samba" datatype="boolean" id="oval:ssg-var_tmpreaper_use_samba:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for tor_bind_all_unreserved_ports" datatype="boolean" id="oval:ssg-var_tor_bind_all_unreserved_ports:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for tor_can_network_relay" datatype="boolean" id="oval:ssg-var_tor_can_network_relay:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for unconfined_chrome_sandbox_transition" datatype="boolean" id="oval:ssg-var_unconfined_chrome_sandbox_transition:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for unconfined_login" datatype="boolean" id="oval:ssg-var_unconfined_login:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for unconfined_mozilla_plugin_transition" datatype="boolean" id="oval:ssg-var_unconfined_mozilla_plugin_transition:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for unprivuser_use_svirt" datatype="boolean" id="oval:ssg-var_unprivuser_use_svirt:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for use_ecryptfs_home_dirs" datatype="boolean" id="oval:ssg-var_use_ecryptfs_home_dirs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for use_fusefs_home_dirs" datatype="boolean" id="oval:ssg-var_use_fusefs_home_dirs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for use_lpd_server" datatype="boolean" id="oval:ssg-var_use_lpd_server:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for use_nfs_home_dirs" datatype="boolean" id="oval:ssg-var_use_nfs_home_dirs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for use_samba_home_dirs" datatype="boolean" id="oval:ssg-var_use_samba_home_dirs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for user_exec_content" datatype="boolean" id="oval:ssg-var_user_exec_content:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for varnishd_connect_any" datatype="boolean" id="oval:ssg-var_varnishd_connect_any:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for virt_read_qemu_ga_data" datatype="boolean" id="oval:ssg-var_virt_read_qemu_ga_data:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for virt_rw_qemu_ga_data" datatype="boolean" id="oval:ssg-var_virt_rw_qemu_ga_data:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for virt_sandbox_use_all_caps" datatype="boolean" id="oval:ssg-var_virt_sandbox_use_all_caps:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for virt_sandbox_use_audit" datatype="boolean" id="oval:ssg-var_virt_sandbox_use_audit:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for virt_sandbox_use_mknod" datatype="boolean" id="oval:ssg-var_virt_sandbox_use_mknod:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for virt_sandbox_use_netlink" datatype="boolean" id="oval:ssg-var_virt_sandbox_use_netlink:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for virt_sandbox_use_sys_admin" datatype="boolean" id="oval:ssg-var_virt_sandbox_use_sys_admin:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for virt_transition_userdomain" datatype="boolean" id="oval:ssg-var_virt_transition_userdomain:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for virt_use_comm" datatype="boolean" id="oval:ssg-var_virt_use_comm:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for virt_use_execmem" datatype="boolean" id="oval:ssg-var_virt_use_execmem:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for virt_use_fusefs" datatype="boolean" id="oval:ssg-var_virt_use_fusefs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for virt_use_nfs" datatype="boolean" id="oval:ssg-var_virt_use_nfs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for virt_use_rawip" datatype="boolean" id="oval:ssg-var_virt_use_rawip:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for virt_use_samba" datatype="boolean" id="oval:ssg-var_virt_use_samba:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for virt_use_sanlock" datatype="boolean" id="oval:ssg-var_virt_use_sanlock:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for virt_use_usb" datatype="boolean" id="oval:ssg-var_virt_use_usb:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for virt_use_xserver" datatype="boolean" id="oval:ssg-var_virt_use_xserver:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for webadm_manage_user_files" datatype="boolean" id="oval:ssg-var_webadm_manage_user_files:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for webadm_read_user_files" datatype="boolean" id="oval:ssg-var_webadm_read_user_files:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for wine_mmap_zero_ignore" datatype="boolean" id="oval:ssg-var_wine_mmap_zero_ignore:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for xdm_bind_vnc_tcp_port" datatype="boolean" id="oval:ssg-var_xdm_bind_vnc_tcp_port:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for xdm_exec_bootloader" datatype="boolean" id="oval:ssg-var_xdm_exec_bootloader:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for xdm_sysadm_login" datatype="boolean" id="oval:ssg-var_xdm_sysadm_login:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for xdm_write_home" datatype="boolean" id="oval:ssg-var_xdm_write_home:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for xen_use_nfs" datatype="boolean" id="oval:ssg-var_xen_use_nfs:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for xend_run_blktap" datatype="boolean" id="oval:ssg-var_xend_run_blktap:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for xend_run_qemu" datatype="boolean" id="oval:ssg-var_xend_run_qemu:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for xguest_connect_network" datatype="boolean" id="oval:ssg-var_xguest_connect_network:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for xguest_exec_content" datatype="boolean" id="oval:ssg-var_xguest_exec_content:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for xguest_mount_media" datatype="boolean" id="oval:ssg-var_xguest_mount_media:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for xguest_use_bluetooth" datatype="boolean" id="oval:ssg-var_xguest_use_bluetooth:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for xserver_clients_write_xshm" datatype="boolean" id="oval:ssg-var_xserver_clients_write_xshm:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for xserver_execmem" datatype="boolean" id="oval:ssg-var_xserver_execmem:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for xserver_object_manager" datatype="boolean" id="oval:ssg-var_xserver_object_manager:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for zabbix_can_network" datatype="boolean" id="oval:ssg-var_zabbix_can_network:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for zarafa_setrlimit" datatype="boolean" id="oval:ssg-var_zarafa_setrlimit:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for zebra_write_config" datatype="boolean" id="oval:ssg-var_zebra_write_config:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for zoneminder_anon_write" datatype="boolean" id="oval:ssg-var_zoneminder_anon_write:var:1" version="1"/>
        <oval-def:external_variable comment="external variable for zoneminder_run_sudo" datatype="boolean" id="oval:ssg-var_zoneminder_run_sudo:var:1" version="1"/>
        <oval-def:external_variable comment="Variable defining the value the argument should have" datatype="string" id="oval:ssg-var_selinux_policy_name:var:1" version="1"/>
        <oval-def:external_variable comment="Variable defining the value the argument should have" datatype="string" id="oval:ssg-var_sshd_disable_compression:var:1" version="1"/>
        <oval-def:external_variable comment="Variable defining the value the argument should have" datatype="int" id="oval:ssg-var_sshd_set_keepalive:var:1" version="1"/>
        <oval-def:external_variable comment="Variable defining the value the argument should have" datatype="string" id="oval:ssg-var_sshd_priv_separation:var:1" version="1"/>
        <oval-def:external_variable comment="Variable value for sudo passwd_timeout " datatype="string" id="oval:ssg-var_sudo_passwd_timeout:var:1" version="1"/>
        <oval-def:external_variable comment="Variable value for sudo umask " datatype="string" id="oval:ssg-var_sudo_umask:var:1" version="1"/>
        <oval-def:external_variable comment="Variable value for sudo logfile " datatype="string" id="oval:ssg-var_sudo_logfile:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.conf.all.accept_redirects" datatype="int" id="oval:ssg-sysctl_net_ipv4_conf_all_accept_redirects_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.conf.all.accept_source_route" datatype="int" id="oval:ssg-sysctl_net_ipv4_conf_all_accept_source_route_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.conf.all.arp_filter" datatype="int" id="oval:ssg-sysctl_net_ipv4_conf_all_arp_filter_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.conf.all.arp_ignore" datatype="int" id="oval:ssg-sysctl_net_ipv4_conf_all_arp_ignore_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.conf.all.forwarding" datatype="int" id="oval:ssg-sysctl_net_ipv4_conf_all_forwarding_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.conf.all.log_martians" datatype="int" id="oval:ssg-sysctl_net_ipv4_conf_all_log_martians_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.conf.all.rp_filter" datatype="int" id="oval:ssg-sysctl_net_ipv4_conf_all_rp_filter_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.conf.all.secure_redirects" datatype="int" id="oval:ssg-sysctl_net_ipv4_conf_all_secure_redirects_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.conf.all.shared_media" datatype="int" id="oval:ssg-sysctl_net_ipv4_conf_all_shared_media_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.conf.default.accept_redirects" datatype="int" id="oval:ssg-sysctl_net_ipv4_conf_default_accept_redirects_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.conf.default.accept_source_route" datatype="int" id="oval:ssg-sysctl_net_ipv4_conf_default_accept_source_route_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.conf.default.forwarding" datatype="int" id="oval:ssg-sysctl_net_ipv4_conf_default_forwarding_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.conf.default.log_martians" datatype="int" id="oval:ssg-sysctl_net_ipv4_conf_default_log_martians_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.conf.default.rp_filter" datatype="int" id="oval:ssg-sysctl_net_ipv4_conf_default_rp_filter_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.conf.default.secure_redirects" datatype="int" id="oval:ssg-sysctl_net_ipv4_conf_default_secure_redirects_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.conf.default.shared_media" datatype="int" id="oval:ssg-sysctl_net_ipv4_conf_default_shared_media_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.icmp_echo_ignore_broadcasts" datatype="int" id="oval:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.icmp_ignore_bogus_error_responses" datatype="int" id="oval:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.tcp_invalid_ratelimit" datatype="int" id="oval:ssg-sysctl_net_ipv4_tcp_invalid_ratelimit_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.tcp_rfc1337" datatype="int" id="oval:ssg-sysctl_net_ipv4_tcp_rfc1337_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv4.tcp_syncookies" datatype="int" id="oval:ssg-sysctl_net_ipv4_tcp_syncookies_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.all.accept_ra" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.all.accept_ra_defrtr" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.all.accept_ra_pinfo" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.all.accept_ra_rtr_pref" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.all.accept_redirects" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_redirects_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.all.accept_source_route" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_all_accept_source_route_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.all.autoconf" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_all_autoconf_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.all.forwarding" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_all_forwarding_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.all.max_addresses" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_all_max_addresses_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.all.router_solicitations" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_all_router_solicitations_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.default.accept_ra" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.default.accept_ra_defrtr" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.default.accept_ra_pinfo" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.default.accept_ra_rtr_pref" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.default.accept_redirects" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_redirects_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.default.accept_source_route" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_default_accept_source_route_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.default.autoconf" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_default_autoconf_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.default.forwarding" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_default_forwarding_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.default.max_addresses" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_default_max_addresses_value:var:1" version="1"/>
        <oval-def:external_variable comment="External variable for net.ipv6.conf.default.router_solicitations" datatype="int" id="oval:ssg-sysctl_net_ipv6_conf_default_router_solicitations_value:var:1" version="1"/>
        <oval-def:constant_variable comment="correct path for pam_pwquality.so check" datatype="string" id="oval:ssg-var_pam_pwquality_config_path:var:1" version="1">
          <oval-def:value>/etc/pam.d/system-auth</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:local_variable comment="path to audit log files" datatype="string" id="oval:ssg-audit_log_file_path:var:1" version="1">
          <oval-def:regex_capture pattern="^log_file\s*=\s*(.*)">
            <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_auditd_conf_log_file:obj:1"/>
          </oval-def:regex_capture>
        </oval-def:local_variable>
        <oval-def:constant_variable comment="CD/DVD drive allowed alternative names" datatype="string" id="oval:ssg-variable_cd_dvd_drive_alternative_names:var:1" version="1">
          <oval-def:value>/dev/cdrom</oval-def:value>
          <oval-def:value>/dev/dvd</oval-def:value>
          <oval-def:value>/dev/scd0</oval-def:value>
          <oval-def:value>/dev/sr0</oval-def:value>
        </oval-def:constant_variable>
        <oval-def:external_variable comment="May be defined by Profiles to explicitly say if sshd is required or not" datatype="int" id="oval:ssg-sshd_required:var:1" version="1"/>
        <oval-def:external_variable comment="Value of var_accounts_user_umask (the required umask) as string" datatype="string" id="oval:ssg-var_accounts_user_umask:var:1" version="1"/>
        <oval-def:local_variable comment="First octal digit of umask from var_accounts_user_umask" datatype="int" id="oval:ssg-var_first_digit_of_umask_from_var_accounts_user_umask:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="1">
            <oval-def:variable_component var_ref="oval:ssg-var_accounts_user_umask:var:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Second octal digit of umask from var_accounts_user_umask" datatype="int" id="oval:ssg-var_second_digit_of_umask_from_var_accounts_user_umask:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="2">
            <oval-def:variable_component var_ref="oval:ssg-var_accounts_user_umask:var:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Third octal digit of umask from var_accounts_user_umask" datatype="int" id="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="3">
            <oval-def:variable_component var_ref="oval:ssg-var_accounts_user_umask:var:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="var_accounts_user_umask umask converted from string to a number" datatype="int" id="oval:ssg-var_accounts_user_umask_umask_as_number:var:1" version="1">
          <oval-def:arithmetic arithmetic_operation="add">
            <oval-def:arithmetic arithmetic_operation="multiply">
              <oval-def:literal_component datatype="int">64</oval-def:literal_component>
              <oval-def:variable_component var_ref="oval:ssg-var_first_digit_of_umask_from_var_accounts_user_umask:var:1"/>
            </oval-def:arithmetic>
            <oval-def:arithmetic arithmetic_operation="multiply">
              <oval-def:literal_component datatype="int">8</oval-def:literal_component>
              <oval-def:variable_component var_ref="oval:ssg-var_second_digit_of_umask_from_var_accounts_user_umask:var:1"/>
            </oval-def:arithmetic>
            <oval-def:variable_component var_ref="oval:ssg-var_third_digit_of_umask_from_var_accounts_user_umask:var:1"/>
          </oval-def:arithmetic>
        </oval-def:local_variable>
        <oval-def:external_variable comment="Value of var_umask_for_daemons (the required umask) as string" datatype="string" id="oval:ssg-var_umask_for_daemons:var:1" version="1"/>
        <oval-def:local_variable comment="First octal digit of umask from var_umask_for_daemons" datatype="int" id="oval:ssg-var_first_digit_of_umask_from_var_umask_for_daemons:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="1">
            <oval-def:variable_component var_ref="oval:ssg-var_umask_for_daemons:var:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Second octal digit of umask from var_umask_for_daemons" datatype="int" id="oval:ssg-var_second_digit_of_umask_from_var_umask_for_daemons:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="2">
            <oval-def:variable_component var_ref="oval:ssg-var_umask_for_daemons:var:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="Third octal digit of umask from var_umask_for_daemons" datatype="int" id="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1" version="1">
          <oval-def:substring substring_length="1" substring_start="3">
            <oval-def:variable_component var_ref="oval:ssg-var_umask_for_daemons:var:1"/>
          </oval-def:substring>
        </oval-def:local_variable>
        <oval-def:local_variable comment="var_umask_for_daemons umask converted from string to a number" datatype="int" id="oval:ssg-var_umask_for_daemons_umask_as_number:var:1" version="1">
          <oval-def:arithmetic arithmetic_operation="add">
            <oval-def:arithmetic arithmetic_operation="multiply">
              <oval-def:literal_component datatype="int">64</oval-def:literal_component>
              <oval-def:variable_component var_ref="oval:ssg-var_first_digit_of_umask_from_var_umask_for_daemons:var:1"/>
            </oval-def:arithmetic>
            <oval-def:arithmetic arithmetic_operation="multiply">
              <oval-def:literal_component datatype="int">8</oval-def:literal_component>
              <oval-def:variable_component var_ref="oval:ssg-var_second_digit_of_umask_from_var_umask_for_daemons:var:1"/>
            </oval-def:arithmetic>
            <oval-def:variable_component var_ref="oval:ssg-var_third_digit_of_umask_from_var_umask_for_daemons:var:1"/>
          </oval-def:arithmetic>
        </oval-def:local_variable>
      </oval-def:variables>
    </oval-def:oval_definitions>
  </ds:component>
  <ds:component id="scap_org.open-scap_comp_ssg-almalinux8-ocil.xml" timestamp="2026-06-15T09:09:30">
    <ocil:ocil>
      <ocil:generator>
        <ocil:product_name>build_shorthand.py from SCAP Security Guide</ocil:product_name>
        <ocil:product_version>ssg: 0.1.81</ocil:product_version>
        <ocil:schema_version>2.0</ocil:schema_version>
        <ocil:timestamp>2026-06-15T09:09:10</ocil:timestamp>
      </ocil:generator>
      <ocil:questionnaires>
        <ocil:questionnaire id="ocil:ssg-account_disable_post_pw_expiration_ocil:questionnaire:1">
          <ocil:title>Set Account Expiration Following Inactivity</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-account_disable_post_pw_expiration_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-account_emergency_expire_date_ocil:questionnaire:1">
          <ocil:title>Assign Expiration Date to Emergency Accounts</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-account_emergency_expire_date_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-account_password_pam_faillock_password_auth_ocil:questionnaire:1">
          <ocil:title>Configure the Use of the pam_faillock.so Module in the /etc/pam.d/password-auth File.</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-account_password_pam_faillock_password_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-account_password_pam_faillock_system_auth_ocil:questionnaire:1">
          <ocil:title>Configure the Use of the pam_faillock.so Module in the /etc/pam.d/system-auth File.</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-account_password_pam_faillock_system_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-account_password_selinux_faillock_dir_ocil:questionnaire:1">
          <ocil:title>An SELinux Context must be configured for the pam_faillock.so records directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-account_password_selinux_faillock_dir_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-account_passwords_pam_faillock_audit_ocil:questionnaire:1">
          <ocil:title>Account Lockouts Must Be Logged</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-account_passwords_pam_faillock_dir_ocil:questionnaire:1">
          <ocil:title>Account Lockouts Must Persist</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-account_passwords_pam_faillock_dir_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-account_temp_expire_date_ocil:questionnaire:1">
          <ocil:title>Assign Expiration Date to Temporary Accounts</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-account_temp_expire_date_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-account_unique_id_ocil:questionnaire:1">
          <ocil:title>Ensure All Accounts on the System Have Unique User IDs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-account_unique_id_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-account_unique_name_ocil:questionnaire:1">
          <ocil:title>Ensure All Accounts on the System Have Unique Names</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-account_unique_name_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-account_use_centralized_automated_auth_ocil:questionnaire:1">
          <ocil:title>Use Centralized and Automated Authentication</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-account_use_centralized_automated_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_authorized_local_users_ocil:questionnaire:1">
          <ocil:title>Only Authorized Local User Accounts Exist on Operating System</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_authorized_local_users_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_have_homedir_login_defs_ocil:questionnaire:1">
          <ocil:title>Ensure Home Directories are Created for New Users</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_have_homedir_login_defs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_logon_fail_delay_ocil:questionnaire:1">
          <ocil:title>Ensure the Logon Failure Delay is Set Correctly in login.defs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_logon_fail_delay_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_max_concurrent_login_sessions_ocil:questionnaire:1">
          <ocil:title>Limit the Number of Concurrent Login Sessions Allowed Per User</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_max_concurrent_login_sessions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_maximum_age_login_defs_ocil:questionnaire:1">
          <ocil:title>Set Password Maximum Age</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_maximum_age_login_defs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1">
          <ocil:title>Set Password Minimum Age</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_no_uid_except_zero_ocil:questionnaire:1">
          <ocil:title>Verify Only Root Has UID 0</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_no_uid_except_zero_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_all_shadowed_ocil:questionnaire:1">
          <ocil:title>Verify All Account Password Hashes are Shadowed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_all_shadowed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_all_shadowed_sha512_ocil:questionnaire:1">
          <ocil:title>Verify All Account Password Hashes are Shadowed with SHA512</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_all_shadowed_sha512_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_last_change_is_in_past_ocil:questionnaire:1">
          <ocil:title>Ensure all users last password change date is in the past</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_last_change_is_in_past_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_minlen_login_defs_ocil:questionnaire:1">
          <ocil:title>Set Password Minimum Length in login.defs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_minlen_login_defs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_dcredit_ocil:questionnaire:1">
          <ocil:title>Ensure PAM Enforces Password Requirements - Minimum Digit Characters</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_dcredit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_dictcheck_ocil:questionnaire:1">
          <ocil:title>Ensure PAM Enforces Password Requirements - Prevent the Use of Dictionary Words</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_dictcheck_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_difok_ocil:questionnaire:1">
          <ocil:title>Ensure PAM Enforces Password Requirements - Minimum Different Characters</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_difok_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_enforce_local_ocil:questionnaire:1">
          <ocil:title>Ensure PAM Enforces Password Requirements - Enforce for Local Accounts Only</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_enforce_local_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_enforce_root_ocil:questionnaire:1">
          <ocil:title>Ensure PAM Enforces Password Requirements - Enforce for root User</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_enforce_root_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_lcredit_ocil:questionnaire:1">
          <ocil:title>Ensure PAM Enforces Password Requirements - Minimum Lowercase Characters</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_lcredit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_maxclassrepeat_ocil:questionnaire:1">
          <ocil:title>Ensure PAM Enforces Password Requirements - Maximum Consecutive Repeating Characters from Same Character Class</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_maxclassrepeat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_maxrepeat_ocil:questionnaire:1">
          <ocil:title>Set Password Maximum Consecutive Repeating Characters</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_maxrepeat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_minclass_ocil:questionnaire:1">
          <ocil:title>Ensure PAM Enforces Password Requirements - Minimum Different Categories</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_minclass_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_minlen_ocil:questionnaire:1">
          <ocil:title>Ensure PAM Enforces Password Requirements - Minimum Length</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_minlen_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_modules_in_authselect_profile_ocil:questionnaire:1">
          <ocil:title>Ensure Active Authselect Profile Includes PAM Modules</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_modules_in_authselect_profile_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_ocredit_ocil:questionnaire:1">
          <ocil:title>Ensure PAM Enforces Password Requirements - Minimum Special Characters</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_ocredit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_ocil:questionnaire:1">
          <ocil:title>Limit Password Reuse: password-auth</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_pwhistory_remember_system_auth_ocil:questionnaire:1">
          <ocil:title>Limit Password Reuse: system-auth</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwhistory_remember_system_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_pwquality_password_auth_ocil:questionnaire:1">
          <ocil:title>Ensure PAM password complexity module is enabled in password-auth</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwquality_password_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_pwquality_system_auth_ocil:questionnaire:1">
          <ocil:title>Ensure PAM password complexity module is enabled in system-auth</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_pwquality_system_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_retry_ocil:questionnaire:1">
          <ocil:title>Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted Per-Session</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_retry_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_ucredit_ocil:questionnaire:1">
          <ocil:title>Ensure PAM Enforces Password Requirements - Minimum Uppercase Characters</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_ucredit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_unix_authtok_ocil:questionnaire:1">
          <ocil:title>Require use_authtok for pam_unix.so</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_authtok_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_unix_no_remember_ocil:questionnaire:1">
          <ocil:title>Avoid using remember in pam_unix module</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_no_remember_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_unix_remember_ocil:questionnaire:1">
          <ocil:title>Limit Password Reuse</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_remember_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_unix_rounds_password_auth_ocil:questionnaire:1">
          <ocil:title>Set number of Password Hashing Rounds - password-auth</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_rounds_password_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_pam_unix_rounds_system_auth_ocil:questionnaire:1">
          <ocil:title>Set number of Password Hashing Rounds - system-auth</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_rounds_system_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_set_max_life_existing_ocil:questionnaire:1">
          <ocil:title>Set Existing Passwords Maximum Age</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_set_max_life_existing_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_set_max_life_root_ocil:questionnaire:1">
          <ocil:title>Set Root Account Password Maximum Age</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_set_max_life_root_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_set_min_life_existing_ocil:questionnaire:1">
          <ocil:title>Set Existing Passwords Minimum Age</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_set_min_life_existing_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_set_warn_age_existing_ocil:questionnaire:1">
          <ocil:title>Set Existing Passwords Warning Age</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_set_warn_age_existing_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_password_warn_age_login_defs_ocil:questionnaire:1">
          <ocil:title>Set Password Warning Age</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_password_warn_age_login_defs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_passwords_pam_faillock_audit_ocil:questionnaire:1">
          <ocil:title>Account Lockouts Must Be Logged</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_audit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_passwords_pam_faillock_deny_ocil:questionnaire:1">
          <ocil:title>Lock Accounts After Failed Password Attempts</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_deny_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_passwords_pam_faillock_deny_root_ocil:questionnaire:1">
          <ocil:title>Configure the root Account for Failed Password Attempts</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_deny_root_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_passwords_pam_faillock_dir_ocil:questionnaire:1">
          <ocil:title>Lock Accounts Must Persist</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_dir_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_passwords_pam_faillock_enforce_local_ocil:questionnaire:1">
          <ocil:title>Enforce pam_faillock for Local Accounts Only</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_enforce_local_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_ocil:questionnaire:1">
          <ocil:title>Ensure Root Account Lockout on Failed Password Attempts</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_passwords_pam_faillock_interval_ocil:questionnaire:1">
          <ocil:title>Set Interval For Counting Failed Password Attempts</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_interval_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_passwords_pam_faillock_silent_ocil:questionnaire:1">
          <ocil:title>Do Not Show System Messages When Unsuccessful Logon Attempts Occur</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_silent_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_ocil:questionnaire:1">
          <ocil:title>Set Lockout Time for Failed Password Attempts</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_unlock_time_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_with_zero_ocil:questionnaire:1">
          <ocil:title>Set Lockout Time for Failed Password Attempts</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_passwords_pam_faillock_unlock_time_with_zero_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_polyinstantiated_tmp_ocil:questionnaire:1">
          <ocil:title>Configure Polyinstantiation of /tmp Directories</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_polyinstantiated_var_tmp_ocil:questionnaire:1">
          <ocil:title>Configure Polyinstantiation of /var/tmp Directories</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_polyinstantiated_var_tmp_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_root_gid_zero_ocil:questionnaire:1">
          <ocil:title>Verify Root Has A Primary GID 0</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_root_gid_zero_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_root_path_dirs_no_write_ocil:questionnaire:1">
          <ocil:title>Ensure that Root's Path Does Not Include World or Group-Writable Directories</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_root_path_dirs_no_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_set_post_pw_existing_ocil:questionnaire:1">
          <ocil:title>Set existing passwords a period of inactivity before they been locked</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_set_post_pw_existing_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_tmout_ocil:questionnaire:1">
          <ocil:title>Set Interactive Session Timeout</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_tmout_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">
          <ocil:title>Ensure the Default Bash Umask is Set Correctly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_umask_etc_csh_cshrc_ocil:questionnaire:1">
          <ocil:title>Ensure the Default C Shell Umask is Set Correctly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_umask_etc_csh_cshrc_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_umask_etc_login_defs_ocil:questionnaire:1">
          <ocil:title>Ensure the Default Umask is Set Correctly in login.defs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_umask_etc_profile_ocil:questionnaire:1">
          <ocil:title>Ensure the Default Umask is Set Correctly in /etc/profile</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_umask_etc_profile_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_umask_interactive_users_ocil:questionnaire:1">
          <ocil:title>Ensure the Default Umask is Set Correctly For Interactive Users</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_umask_interactive_users_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_user_dot_group_ownership_ocil:questionnaire:1">
          <ocil:title>User Initialization Files Must Be Group-Owned By The Primary Group</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_user_dot_group_ownership_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_user_dot_no_world_writable_programs_ocil:questionnaire:1">
          <ocil:title>User Initialization Files Must Not Run World-Writable Programs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_user_dot_no_world_writable_programs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_user_dot_user_ownership_ocil:questionnaire:1">
          <ocil:title>User Initialization Files Must Be Owned By the Primary User</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_user_dot_user_ownership_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_user_home_paths_only_ocil:questionnaire:1">
          <ocil:title>Ensure that Users Path Contains Only Local Directories</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_user_home_paths_only_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_user_interactive_home_directory_defined_ocil:questionnaire:1">
          <ocil:title>All Interactive Users Must Have A Home Directory Defined</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_user_interactive_home_directory_defined_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_user_interactive_home_directory_exists_ocil:questionnaire:1">
          <ocil:title>All Interactive Users Home Directories Must Exist</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_user_interactive_home_directory_exists_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_user_interactive_home_directory_on_separate_partition_ocil:questionnaire:1">
          <ocil:title>All Interactive User Home Directories Must Reside On a Separate Partition</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_user_interactive_home_directory_on_separate_partition_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_users_home_files_groupownership_ocil:questionnaire:1">
          <ocil:title>All User Files and Directories In The Home Directory Must Be Group-Owned By The Primary Group</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_users_home_files_groupownership_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_users_home_files_ownership_ocil:questionnaire:1">
          <ocil:title>All User Files and Directories In The Home Directory Must Have a Valid Owner</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_users_home_files_ownership_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_users_home_files_permissions_ocil:questionnaire:1">
          <ocil:title>All User Files and Directories In The Home Directory Must Have Mode 0750 Or Less Permissive</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_users_home_files_permissions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-accounts_users_netrc_file_permissions_ocil:questionnaire:1">
          <ocil:title>Ensure users' .netrc Files are not group or world accessible</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-accounts_users_netrc_file_permissions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-agent_mfetpd_running_ocil:questionnaire:1">
          <ocil:title>Ensure McAfee Endpoint Security for Linux (ENSL) is running</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-agent_mfetpd_running_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-aide_build_database_ocil:questionnaire:1">
          <ocil:title>Build and Test AIDE Database</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-aide_build_database_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-aide_check_audit_tools_ocil:questionnaire:1">
          <ocil:title>Configure AIDE to Verify the Audit Tools</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-aide_check_audit_tools_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-aide_periodic_cron_checking_ocil:questionnaire:1">
          <ocil:title>Configure Periodic Execution of AIDE</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-aide_periodic_cron_checking_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-aide_scan_notification_ocil:questionnaire:1">
          <ocil:title>Configure Notification of Post-AIDE Scan Details</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-aide_scan_notification_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-aide_use_fips_hashes_ocil:questionnaire:1">
          <ocil:title>Configure AIDE to Use FIPS 140-2 for Validating Hashes</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-aide_use_fips_hashes_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-aide_verify_acls_ocil:questionnaire:1">
          <ocil:title>Configure AIDE to Verify Access Control Lists (ACLs)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-aide_verify_acls_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-aide_verify_ext_attributes_ocil:questionnaire:1">
          <ocil:title>Configure AIDE to Verify Extended Attributes</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-aide_verify_ext_attributes_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_access_failed_ocil:questionnaire:1">
          <ocil:title>Configure auditing of unsuccessful file accesses</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_access_failed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_access_success_ocil:questionnaire:1">
          <ocil:title>Configure auditing of successful file accesses</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_access_success_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_basic_configuration_ocil:questionnaire:1">
          <ocil:title>Configure basic parameters of Audit system</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_basic_configuration_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_create_failed_ocil:questionnaire:1">
          <ocil:title>Configure auditing of unsuccessful file creations</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_create_failed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_create_success_ocil:questionnaire:1">
          <ocil:title>Configure auditing of successful file creations</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_create_success_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_delete_failed_ocil:questionnaire:1">
          <ocil:title>Configure auditing of unsuccessful file deletions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_delete_failed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_delete_success_ocil:questionnaire:1">
          <ocil:title>Configure auditing of successful file deletions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_delete_success_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_immutable_login_uids_ocil:questionnaire:1">
          <ocil:title>Configure immutable Audit login UIDs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_immutable_login_uids_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_modify_failed_ocil:questionnaire:1">
          <ocil:title>Configure auditing of unsuccessful file modifications</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_modify_failed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_modify_success_ocil:questionnaire:1">
          <ocil:title>Configure auditing of successful file modifications</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_modify_success_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_module_load_ocil:questionnaire:1">
          <ocil:title>Configure auditing of loading and unloading of kernel modules</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_module_load_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_ospp_general_ocil:questionnaire:1">
          <ocil:title>Perform general configuration of Audit for OSPP</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_ospp_general_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_owner_change_failed_ocil:questionnaire:1">
          <ocil:title>Configure auditing of unsuccessful ownership changes</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_owner_change_failed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_owner_change_success_ocil:questionnaire:1">
          <ocil:title>Configure auditing of successful ownership changes</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_owner_change_success_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_perm_change_failed_ocil:questionnaire:1">
          <ocil:title>Configure auditing of unsuccessful permission changes</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_perm_change_failed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_perm_change_success_ocil:questionnaire:1">
          <ocil:title>Configure auditing of successful permission changes</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_perm_change_success_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_privileged_commands_init_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - init</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_privileged_commands_init_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_privileged_commands_poweroff_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - poweroff</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_privileged_commands_poweroff_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_privileged_commands_reboot_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - reboot</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_privileged_commands_reboot_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_privileged_commands_shutdown_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - shutdown</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_privileged_commands_shutdown_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_continue_loading_ocil:questionnaire:1">
          <ocil:title>Ensure the Audit Configuration is Loaded Regardless of Errors</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_continue_loading_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_dac_modification_chmod_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Discretionary Access Controls - chmod</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chmod_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_dac_modification_chown_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Discretionary Access Controls - chown</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_dac_modification_fchmod_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Discretionary Access Controls - fchmod</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmod_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_dac_modification_fchmodat_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Discretionary Access Controls - fchmodat</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchmodat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_dac_modification_fchown_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Discretionary Access Controls - fchown</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchown_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_dac_modification_fchownat_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Discretionary Access Controls - fchownat</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_dac_modification_fremovexattr_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Discretionary Access Controls - fremovexattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_dac_modification_fsetxattr_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Discretionary Access Controls - fsetxattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_fsetxattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_dac_modification_lchown_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Discretionary Access Controls - lchown</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lchown_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_dac_modification_lremovexattr_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Discretionary Access Controls - lremovexattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_dac_modification_lsetxattr_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Discretionary Access Controls - lsetxattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_dac_modification_removexattr_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Discretionary Access Controls - removexattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_dac_modification_setxattr_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Discretionary Access Controls - setxattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_dac_modification_umount_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Discretionary Access Controls - umount</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_dac_modification_umount2_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Discretionary Access Controls - umount2</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_dac_modification_umount2_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_etc_cron_d_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Changes to Cron Jobs - /etc/cron.d/</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_etc_cron_d_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_etc_group_open_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information via open syscall - /etc/group</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_etc_group_open_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_etc_group_open_by_handle_at_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/group</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_etc_group_open_by_handle_at_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_etc_group_openat_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information via openat syscall - /etc/group</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_etc_group_openat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_etc_gshadow_open_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information via open syscall - /etc/gshadow</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_etc_gshadow_open_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_etc_gshadow_open_by_handle_at_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/gshadow</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_etc_gshadow_open_by_handle_at_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_etc_gshadow_openat_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information via openat syscall - /etc/gshadow</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_etc_gshadow_openat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_etc_passwd_open_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information via open syscall - /etc/passwd</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_etc_passwd_open_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_etc_passwd_open_by_handle_at_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/passwd</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_etc_passwd_open_by_handle_at_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_etc_passwd_openat_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information via openat syscall - /etc/passwd</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_etc_passwd_openat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_etc_shadow_open_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information via open syscall - /etc/shadow</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_etc_shadow_open_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_etc_shadow_open_by_handle_at_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information via open_by_handle_at syscall - /etc/shadow</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_etc_shadow_open_by_handle_at_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_etc_shadow_openat_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information via openat syscall - /etc/shadow</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_etc_shadow_openat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_execution_chacl_ocil:questionnaire:1">
          <ocil:title>Record Any Attempts to Run chacl</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_execution_chacl_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_execution_chcon_ocil:questionnaire:1">
          <ocil:title>Record Any Attempts to Run chcon</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_execution_chcon_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_execution_restorecon_ocil:questionnaire:1">
          <ocil:title>Record Any Attempts to Run restorecon</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_execution_restorecon_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_execution_semanage_ocil:questionnaire:1">
          <ocil:title>Record Any Attempts to Run semanage</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_execution_semanage_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_execution_setfacl_ocil:questionnaire:1">
          <ocil:title>Record Any Attempts to Run setfacl</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_execution_setfacl_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_execution_setfiles_ocil:questionnaire:1">
          <ocil:title>Record Any Attempts to Run setfiles</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_execution_setfiles_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_execution_setsebool_ocil:questionnaire:1">
          <ocil:title>Record Any Attempts to Run setsebool</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_execution_setsebool_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_execution_seunshare_ocil:questionnaire:1">
          <ocil:title>Record Any Attempts to Run seunshare</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_execution_seunshare_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_file_deletion_events_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects File Deletion Events by User</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_file_deletion_events_rename_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects File Deletion Events by User - rename</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rename_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_file_deletion_events_renameat_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects File Deletion Events by User - renameat</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_renameat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_file_deletion_events_rmdir_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects File Deletion Events by User - rmdir</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_rmdir_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_file_deletion_events_unlink_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects File Deletion Events by User - unlink</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_file_deletion_events_unlinkat_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects File Deletion Events by User - unlinkat</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_file_deletion_events_unlinkat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_for_ospp_ocil:questionnaire:1">
          <ocil:title>Configure audit according to OSPP requirements</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_for_ospp_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_immutable_ocil:questionnaire:1">
          <ocil:title>Make the auditd Configuration Immutable</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_immutable_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_immutable_login_uids_ocil:questionnaire:1">
          <ocil:title>Configure immutable Audit login UIDs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_immutable_login_uids_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_kernel_module_loading_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on Kernel Module Loading and Unloading</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_kernel_module_loading_create_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on Kernel Module Unloading - create_module</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_create_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_kernel_module_loading_delete_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on Kernel Module Unloading - delete_module</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_delete_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_kernel_module_loading_finit_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on Kernel Module Loading and Unloading - finit_module</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_finit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_kernel_module_loading_init_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on Kernel Module Loading - init_module</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_kernel_module_loading_query_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on Kernel Module Loading and Unloading - query_module</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_kernel_module_loading_query_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_login_events_faillock_ocil:questionnaire:1">
          <ocil:title>Record Attempts to Alter Logon and Logout Events - faillock</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_login_events_faillock_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_login_events_lastlog_ocil:questionnaire:1">
          <ocil:title>Record Attempts to Alter Logon and Logout Events - lastlog</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_login_events_lastlog_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_login_events_tallylog_ocil:questionnaire:1">
          <ocil:title>Record Attempts to Alter Logon and Logout Events - tallylog</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_login_events_tallylog_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_mac_modification_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Mandatory Access Controls</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_mac_modification_usr_share_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Mandatory Access Controls in usr/share</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_mac_modification_usr_share_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_media_export_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on Exporting to Media (successful)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_media_export_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_networkconfig_modification_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Network Environment</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_networkconfig_modification_network_scripts_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify the System's Network Environment - /etc/sysconfig/network-scripts</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_networkconfig_modification_network_scripts_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_at_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - at</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_at_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_chage_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - chage</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_chage_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_chsh_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - chsh</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_chsh_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_crontab_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - crontab</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_crontab_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_gpasswd_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - gpasswd</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_gpasswd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_kmod_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - kmod</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_kmod_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_mount_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - mount</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_mount_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_newgidmap_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - newgidmap</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_newgidmap_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_newgrp_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - newgrp</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_newgrp_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_newuidmap_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - newuidmap</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_newuidmap_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_pam_timestamp_check_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - pam_timestamp_check</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_pam_timestamp_check_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_passwd_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - passwd</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_passwd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_postdrop_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - postdrop</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_postdrop_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_postqueue_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - postqueue</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_postqueue_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_pt_chown_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - pt_chown</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_pt_chown_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_ssh_agent_ocil:questionnaire:1">
          <ocil:title>Record Any Attempts to Run ssh-agent</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_ssh_agent_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_ssh_keysign_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - ssh-keysign</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_ssh_keysign_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_su_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - su</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_su_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_sudo_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - sudo</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_sudo_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_sudoedit_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - sudoedit</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_sudoedit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_umount_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - umount</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_umount_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - unix_chkpwd</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_unix_update_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - unix_update</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_unix_update_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_userhelper_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - userhelper</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_userhelper_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_usermod_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - usermod</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_usermod_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_privileged_commands_usernetctl_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Information on the Use of Privileged Commands - usernetctl</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_privileged_commands_usernetctl_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_session_events_btmp_ocil:questionnaire:1">
          <ocil:title>Record Attempts to Alter Process and Session Initiation Information btmp</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_session_events_btmp_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_session_events_utmp_ocil:questionnaire:1">
          <ocil:title>Record Attempts to Alter Process and Session Initiation Information utmp</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_session_events_utmp_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_session_events_wtmp_ocil:questionnaire:1">
          <ocil:title>Record Attempts to Alter Process and Session Initiation Information wtmp</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_session_events_wtmp_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_chmod_ocil:questionnaire:1">
          <ocil:title>Record Successful Permission Changes to Files - chmod</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_chmod_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_chown_ocil:questionnaire:1">
          <ocil:title>Record Successful Ownership Changes to Files - chown</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_chown_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_creat_ocil:questionnaire:1">
          <ocil:title>Record Successful Access Attempts to Files - creat</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_creat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_fchmod_ocil:questionnaire:1">
          <ocil:title>Record Successful Permission Changes to Files - fchmod</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fchmod_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_fchmodat_ocil:questionnaire:1">
          <ocil:title>Record Successful Permission Changes to Files - fchmodat</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fchmodat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_fchown_ocil:questionnaire:1">
          <ocil:title>Record Successful Ownership Changes to Files - fchown</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fchown_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_fchownat_ocil:questionnaire:1">
          <ocil:title>Record Successful Ownership Changes to Files - fchownat</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fchownat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_fremovexattr_ocil:questionnaire:1">
          <ocil:title>Record Successful Permission Changes to Files - fremovexattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_fsetxattr_ocil:questionnaire:1">
          <ocil:title>Record Successful Permission Changes to Files - fsetxattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_fsetxattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_ftruncate_ocil:questionnaire:1">
          <ocil:title>Record Successful Access Attempts to Files - ftruncate</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_lchown_ocil:questionnaire:1">
          <ocil:title>Record Successful Ownership Changes to Files - lchown</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_lchown_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_lremovexattr_ocil:questionnaire:1">
          <ocil:title>Record Successful Permission Changes to Files - lremovexattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_lsetxattr_ocil:questionnaire:1">
          <ocil:title>Record Successful Permission Changes to Files - lsetxattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_open_ocil:questionnaire:1">
          <ocil:title>Record Successful Access Attempts to Files - open</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_open_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_ocil:questionnaire:1">
          <ocil:title>Record Successful Access Attempts to Files - open_by_handle_at</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_o_creat_ocil:questionnaire:1">
          <ocil:title>Record Successful Creation Attempts to Files - open_by_handle_at O_CREAT</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_o_creat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_o_trunc_write_ocil:questionnaire:1">
          <ocil:title>Record Successful Creation Attempts to Files - open_by_handle_at O_TRUNC_WRITE</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_o_trunc_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_open_o_creat_ocil:questionnaire:1">
          <ocil:title>Record Successful Creation Attempts to Files - open O_CREAT</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_open_o_creat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_open_o_trunc_write_ocil:questionnaire:1">
          <ocil:title>Record Successful Creation Attempts to Files - open O_TRUNC_WRITE</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_open_o_trunc_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_openat_ocil:questionnaire:1">
          <ocil:title>Record Successful Access Attempts to Files - openat</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_openat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_openat_o_creat_ocil:questionnaire:1">
          <ocil:title>Record Successful Creation Attempts to Files - openat O_CREAT</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_openat_o_creat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_openat_o_trunc_write_ocil:questionnaire:1">
          <ocil:title>Record Successful Creation Attempts to Files - openat O_TRUNC_WRITE</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_openat_o_trunc_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_removexattr_ocil:questionnaire:1">
          <ocil:title>Record Successful Permission Changes to Files - removexattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_removexattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_rename_ocil:questionnaire:1">
          <ocil:title>Record Successful Delete Attempts to Files - rename</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_rename_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_renameat_ocil:questionnaire:1">
          <ocil:title>Record Successful Delete Attempts to Files - renameat</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_renameat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_setxattr_ocil:questionnaire:1">
          <ocil:title>Record Successful Permission Changes to Files - setxattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_setxattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_truncate_ocil:questionnaire:1">
          <ocil:title>Record Successful Access Attempts to Files - truncate</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_truncate_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_unlink_ocil:questionnaire:1">
          <ocil:title>Record Successful Delete Attempts to Files - unlink</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_unlink_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_successful_file_modification_unlinkat_ocil:questionnaire:1">
          <ocil:title>Record Successful Delete Attempts to Files - unlinkat</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_successful_file_modification_unlinkat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_sudoers_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects System Administrator Actions - /etc/sudoers</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_sudoers_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_sudoers_d_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects System Administrator Actions - /etc/sudoers.d/</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_sudoers_d_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_suid_auid_privilege_function_ocil:questionnaire:1">
          <ocil:title>Record Events When Executables Are Run As Another User</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_suid_auid_privilege_function_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_suid_privilege_function_ocil:questionnaire:1">
          <ocil:title>Record Events When Privileged Executables Are Run</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_suid_privilege_function_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_sysadmin_actions_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects System Administrator Actions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_sysadmin_actions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_system_shutdown_ocil:questionnaire:1">
          <ocil:title>Shutdown System When Auditing Failures Occur</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_system_shutdown_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_time_adjtimex_ocil:questionnaire:1">
          <ocil:title>Record attempts to alter time through adjtimex</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_time_adjtimex_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_time_clock_settime_ocil:questionnaire:1">
          <ocil:title>Record Attempts to Alter Time Through clock_settime</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_time_clock_settime_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_time_settimeofday_ocil:questionnaire:1">
          <ocil:title>Record attempts to alter time through settimeofday</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_time_settimeofday_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_time_stime_ocil:questionnaire:1">
          <ocil:title>Record Attempts to Alter Time Through stime</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_time_stime_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_time_watch_localtime_ocil:questionnaire:1">
          <ocil:title>Record Attempts to Alter the localtime File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Unauthorized Access Attempts to Files (unsuccessful)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_chmod_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Permission Changes to Files - chmod</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_chmod_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_chown_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Ownership Changes to Files - chown</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_chown_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Access Attempts to Files - creat</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_creat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_fchmod_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Permission Changes to Files - fchmod</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_fchmod_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_fchmodat_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Permission Changes to Files - fchmodat</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_fchmodat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_fchown_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Ownership Changes to Files - fchown</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_fchown_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_fchownat_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Ownership Changes to Files - fchownat</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_fchownat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_fremovexattr_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Permission Changes to Files - fremovexattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_fremovexattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_fsetxattr_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Permission Changes to Files - fsetxattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_fsetxattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Access Attempts to Files - ftruncate</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_lchown_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Ownership Changes to Files - lchown</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_lchown_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_lremovexattr_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Permission Changes to Files - lremovexattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_lremovexattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_lsetxattr_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Permission Changes to Files - lsetxattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_lsetxattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Access Attempts to Files - open</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Access Attempts to Files - open_by_handle_at</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Creation Attempts to Files - open_by_handle_at O_CREAT</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_trunc_write_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Modification Attempts to Files - open_by_handle_at O_TRUNC_WRITE</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_trunc_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Unauthorized Access Attempts To open_by_handle_at Are Ordered Correctly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_creat_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Creation Attempts to Files - open O_CREAT</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_creat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_trunc_write_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Modification Attempts to Files - open O_TRUNC_WRITE</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_trunc_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_rule_order_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Rules For Unauthorized Attempts To open Are Ordered Correctly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_open_rule_order_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Access Attempts to Files - openat</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_creat_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Creation Attempts to Files - openat O_CREAT</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_creat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_trunc_write_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Modification Attempts to Files - openat O_TRUNC_WRITE</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_trunc_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_rule_order_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Rules For Unauthorized Attempts To openat Are Ordered Correctly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_openat_rule_order_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_removexattr_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Permission Changes to Files - removexattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_removexattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_rename_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Delete Attempts to Files - rename</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_rename_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_renameat_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Delete Attempts to Files - renameat</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_renameat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_setxattr_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Permission Changes to Files - setxattr</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_setxattr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Access Attempts to Files - truncate</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Delete Attempts to Files - unlink</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_unsuccessful_file_modification_unlinkat_ocil:questionnaire:1">
          <ocil:title>Record Unsuccessful Delete Attempts to Files - unlinkat</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_unsuccessful_file_modification_unlinkat_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_usergroup_modification_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_usergroup_modification_group_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information - /etc/group</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_group_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_usergroup_modification_gshadow_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information - /etc/gshadow</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_gshadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_usergroup_modification_nsswitch_conf_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information - /etc/nsswitch.conf</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_nsswitch_conf_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_usergroup_modification_opasswd_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information - /etc/security/opasswd</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_opasswd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_usergroup_modification_pam_conf_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information - /etc/pam.conf</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_pam_conf_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_usergroup_modification_pamd_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information - /etc/pam.d/</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_pamd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_usergroup_modification_passwd_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information - /etc/passwd</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_passwd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_usergroup_modification_shadow_ocil:questionnaire:1">
          <ocil:title>Record Events that Modify User/Group Information - /etc/shadow</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_usergroup_modification_shadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_rules_var_spool_cron_ocil:questionnaire:1">
          <ocil:title>Ensure auditd Collects Changes to Cron Jobs - /var/spool/cron</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_rules_var_spool_cron_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-audit_sudo_log_events_ocil:questionnaire:1">
          <ocil:title>Record Attempts to perform maintenance activities</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-audit_sudo_log_events_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_audispd_configure_remote_server_ocil:questionnaire:1">
          <ocil:title>Configure audispd Plugin To Send Logs To Remote Server</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_audispd_configure_remote_server_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_audispd_configure_sufficiently_large_partition_ocil:questionnaire:1">
          <ocil:title>Configure a Sufficiently Large Partition for Audit Logs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_audispd_configure_sufficiently_large_partition_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_audispd_disk_full_action_ocil:questionnaire:1">
          <ocil:title>Configure audispd's Plugin disk_full_action When Disk Is Full</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_audispd_disk_full_action_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_audispd_encrypt_sent_records_ocil:questionnaire:1">
          <ocil:title>Encrypt Audit Records Sent With audispd Plugin</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_audispd_encrypt_sent_records_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_audispd_network_failure_action_ocil:questionnaire:1">
          <ocil:title>Configure audispd's Plugin network_failure_action On Network Failure</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_audispd_network_failure_action_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_audispd_syslog_plugin_activated_ocil:questionnaire:1">
          <ocil:title>Configure auditd to use audispd's syslog plugin</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_data_disk_error_action_ocil:questionnaire:1">
          <ocil:title>Configure auditd Disk Error Action on Disk Error</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_data_disk_error_action_stig_ocil:questionnaire:1">
          <ocil:title>Configure auditd Disk Error Action on Disk Error</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_data_disk_error_action_stig_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_data_disk_full_action_ocil:questionnaire:1">
          <ocil:title>Configure auditd Disk Full Action when Disk Space Is Full</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_data_disk_full_action_stig_ocil:questionnaire:1">
          <ocil:title>Configure auditd Disk Full Action when Disk Space Is Full</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_data_disk_full_action_stig_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_data_retention_action_mail_acct_ocil:questionnaire:1">
          <ocil:title>Configure auditd mail_acct Action on Low Disk Space</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_data_retention_admin_space_left_action_ocil:questionnaire:1">
          <ocil:title>Configure auditd admin_space_left Action on Low Disk Space</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_data_retention_admin_space_left_action_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_data_retention_admin_space_left_percentage_ocil:questionnaire:1">
          <ocil:title>Configure auditd admin_space_left on Low Disk Space</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_data_retention_admin_space_left_percentage_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_data_retention_flush_ocil:questionnaire:1">
          <ocil:title>Configure auditd flush priority</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_data_retention_flush_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_data_retention_max_log_file_ocil:questionnaire:1">
          <ocil:title>Configure auditd Max Log File Size</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_data_retention_max_log_file_action_ocil:questionnaire:1">
          <ocil:title>Configure auditd max_log_file_action Upon Reaching Maximum Log Size</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_ocil:questionnaire:1">
          <ocil:title>Configure auditd max_log_file_action Upon Reaching Maximum Log Size</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_data_retention_max_log_file_action_stig_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_data_retention_num_logs_ocil:questionnaire:1">
          <ocil:title>Configure auditd Number of Logs Retained</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_data_retention_num_logs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_data_retention_space_left_ocil:questionnaire:1">
          <ocil:title>Configure auditd space_left on Low Disk Space</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_data_retention_space_left_action_ocil:questionnaire:1">
          <ocil:title>Configure auditd space_left Action on Low Disk Space</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_data_retention_space_left_percentage_ocil:questionnaire:1">
          <ocil:title>Configure auditd space_left on Low Disk Space</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_data_retention_space_left_percentage_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_freq_ocil:questionnaire:1">
          <ocil:title>Set number of records to cause an explicit flush to audit logs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_freq_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_local_events_ocil:questionnaire:1">
          <ocil:title>Include Local Events in Audit Logs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_local_events_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_log_format_ocil:questionnaire:1">
          <ocil:title>Resolve information before writing to audit logs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_log_format_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_name_format_ocil:questionnaire:1">
          <ocil:title>Set type of computer node name logging in audit logs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_name_format_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_overflow_action_ocil:questionnaire:1">
          <ocil:title>Appropriate Action Must be Setup When the Internal Audit Event Queue is Full</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_overflow_action_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-auditd_write_logs_ocil:questionnaire:1">
          <ocil:title>Write Audit Logs to the Disk</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-auditd_write_logs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-banner_etc_issue_ocil:questionnaire:1">
          <ocil:title>Modify the System Login Banner</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-banner_etc_issue_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-banner_etc_issue_cis_ocil:questionnaire:1">
          <ocil:title>Ensure Local Login Warning Banner Is Configured Properly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-banner_etc_issue_cis_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-banner_etc_issue_net_ocil:questionnaire:1">
          <ocil:title>Modify the System Login Banner for Remote Connections</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-banner_etc_issue_net_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-banner_etc_issue_net_cis_ocil:questionnaire:1">
          <ocil:title>Ensure Remote Login Warning Banner Is Configured Properly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-banner_etc_issue_net_cis_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-banner_etc_motd_ocil:questionnaire:1">
          <ocil:title>Modify the System Message of the Day Banner</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-banner_etc_motd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-banner_etc_motd_cis_ocil:questionnaire:1">
          <ocil:title>Ensure Message Of The Day Is Configured Properly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-banner_etc_motd_cis_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-bios_disable_usb_boot_ocil:questionnaire:1">
          <ocil:title>Disable Booting from USB Devices in Boot Firmware</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-bios_disable_usb_boot_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-bios_enable_execution_restrictions_ocil:questionnaire:1">
          <ocil:title>Enable NX or XD Support in the BIOS</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-bios_enable_execution_restrictions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-chronyd_client_only_ocil:questionnaire:1">
          <ocil:title>Disable chrony daemon from acting as server</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-chronyd_client_only_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-chronyd_configure_local_socket_ocil:questionnaire:1">
          <ocil:title>Configure chrony-wait.service to use Unix socket</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-chronyd_configure_local_socket_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-chronyd_no_chronyc_network_ocil:questionnaire:1">
          <ocil:title>Disable network management of chrony daemon</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-chronyd_no_chronyc_network_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-chronyd_or_ntpd_set_maxpoll_ocil:questionnaire:1">
          <ocil:title>Configure Time Service Maxpoll Interval</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-chronyd_or_ntpd_set_maxpoll_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-chronyd_or_ntpd_specify_remote_server_ocil:questionnaire:1">
          <ocil:title>Specify a Remote NTP Server</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-chronyd_or_ntpd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-chronyd_run_as_chrony_user_ocil:questionnaire:1">
          <ocil:title>Ensure that chronyd is running under chrony user account</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-chronyd_run_as_chrony_user_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-chronyd_server_directive_ocil:questionnaire:1">
          <ocil:title>Ensure Chrony is only configured with the server directive</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-chronyd_server_directive_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-chronyd_specify_remote_server_ocil:questionnaire:1">
          <ocil:title>A remote time server for Chrony is configured</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-chronyd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-clean_components_post_updating_ocil:questionnaire:1">
          <ocil:title>Ensure yum Removes Previous Package Versions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-clean_components_post_updating_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_bashrc_exec_tmux_ocil:questionnaire:1">
          <ocil:title>Support session locking with tmux</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_bashrc_exec_tmux_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_bashrc_tmux_ocil:questionnaire:1">
          <ocil:title>Support session locking with tmux (not enforcing)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_bashrc_tmux_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_bind_crypto_policy_ocil:questionnaire:1">
          <ocil:title>Configure BIND to use System Crypto Policy</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_bind_crypto_policy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_crypto_policy_ocil:questionnaire:1">
          <ocil:title>Configure System Cryptography Policy</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_crypto_policy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_custom_crypto_policy_cis_ocil:questionnaire:1">
          <ocil:title>Implement Custom Crypto Policy Modules for CIS Benchmark</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_custom_crypto_policy_cis_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_firewalld_ports_ocil:questionnaire:1">
          <ocil:title>Configure the Firewalld Ports</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_firewalld_ports_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_gnutls_tls_crypto_policy_ocil:questionnaire:1">
          <ocil:title>Configure GnuTLS library to use DoD-approved TLS Encryption</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_gnutls_tls_crypto_policy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_kerberos_crypto_policy_ocil:questionnaire:1">
          <ocil:title>Configure Kerberos to use System Crypto Policy</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_kerberos_crypto_policy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_libreswan_crypto_policy_ocil:questionnaire:1">
          <ocil:title>Configure Libreswan to use System Crypto Policy</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_libreswan_crypto_policy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_opensc_card_drivers_ocil:questionnaire:1">
          <ocil:title>Configure opensc Smart Card Drivers</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_opensc_card_drivers_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_openssl_crypto_policy_ocil:questionnaire:1">
          <ocil:title>Configure OpenSSL library to use System Crypto Policy</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_openssl_crypto_policy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_openssl_tls_crypto_policy_ocil:questionnaire:1">
          <ocil:title>Configure OpenSSL library to use TLS Encryption</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_openssl_tls_crypto_policy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_ssh_crypto_policy_ocil:questionnaire:1">
          <ocil:title>Configure SSH to use System Crypto Policy</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_ssh_crypto_policy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_tmux_lock_after_time_ocil:questionnaire:1">
          <ocil:title>Configure tmux to lock session after inactivity</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_tmux_lock_after_time_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_tmux_lock_command_ocil:questionnaire:1">
          <ocil:title>Configure the tmux Lock Command</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_tmux_lock_command_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_tmux_lock_keybinding_ocil:questionnaire:1">
          <ocil:title>Configure the tmux lock session key binding</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_tmux_lock_keybinding_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_usbguard_auditbackend_ocil:questionnaire:1">
          <ocil:title>Log USBGuard daemon audit events using Linux Audit</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_usbguard_auditbackend_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configure_user_data_backups_ocil:questionnaire:1">
          <ocil:title>Configure Backups of User Data</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configure_user_data_backups_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-configured_firewalld_default_deny_ocil:questionnaire:1">
          <ocil:title>Firewalld Must Employ a Deny-all, Allow-by-exception Policy for Allowing Connections to Other Systems</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-configured_firewalld_default_deny_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-coredump_disable_backtraces_ocil:questionnaire:1">
          <ocil:title>Disable core dump backtraces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-coredump_disable_backtraces_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-coredump_disable_storage_ocil:questionnaire:1">
          <ocil:title>Disable storing core dump</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-coredump_disable_storage_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-coreos_enable_selinux_kernel_argument_ocil:questionnaire:1">
          <ocil:title>Ensure SELinux Not Disabled in the kernel arguments</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-coreos_enable_selinux_kernel_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-cups_disable_browsing_ocil:questionnaire:1">
          <ocil:title>Disable Printer Browsing Entirely if Possible</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-cups_disable_browsing_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_db_up_to_date_ocil:questionnaire:1">
          <ocil:title>Make sure that the dconf databases are up-to-date with regards to respective keyfiles</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_db_up_to_date_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_banner_enabled_ocil:questionnaire:1">
          <ocil:title>Enable GNOME3 Login Warning Banner</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_banner_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_disable_automount_ocil:questionnaire:1">
          <ocil:title>Disable GNOME3 Automounting</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_automount_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_disable_automount_open_ocil:questionnaire:1">
          <ocil:title>Disable GNOME3 Automount Opening</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_automount_open_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_disable_autorun_ocil:questionnaire:1">
          <ocil:title>Disable GNOME3 Automount running</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_autorun_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_disable_ctrlaltdel_reboot_ocil:questionnaire:1">
          <ocil:title>Disable Ctrl-Alt-Del Reboot Key Sequence in GNOME3</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_ctrlaltdel_reboot_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_disable_geolocation_ocil:questionnaire:1">
          <ocil:title>Disable Geolocation in GNOME3</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_geolocation_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_disable_power_settings_ocil:questionnaire:1">
          <ocil:title>Disable Power Settings in GNOME3</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_power_settings_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_disable_restart_shutdown_ocil:questionnaire:1">
          <ocil:title>Disable the GNOME3 Login Restart and Shutdown Buttons</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_restart_shutdown_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_disable_thumbnailers_ocil:questionnaire:1">
          <ocil:title>Disable All GNOME3 Thumbnailers</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_thumbnailers_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_disable_user_admin_ocil:questionnaire:1">
          <ocil:title>Disable User Administration in GNOME3</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_user_admin_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_disable_user_list_ocil:questionnaire:1">
          <ocil:title>Disable the GNOME3 Login User List</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_user_list_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_disable_wifi_create_ocil:questionnaire:1">
          <ocil:title>Disable WIFI Network Connection Creation in GNOME3</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_wifi_create_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_disable_wifi_notification_ocil:questionnaire:1">
          <ocil:title>Disable WIFI Network Notification in GNOME3</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_disable_wifi_notification_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_enable_smartcard_auth_ocil:questionnaire:1">
          <ocil:title>Enable the GNOME3 Login Smartcard Authentication</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_enable_smartcard_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_lock_screen_on_smartcard_removal_ocil:questionnaire:1">
          <ocil:title>Enable the GNOME3 Screen Locking On Smartcard Removal</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_lock_screen_on_smartcard_removal_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_login_banner_text_ocil:questionnaire:1">
          <ocil:title>Set the GNOME3 Login Warning Banner Text</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_login_banner_text_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_login_retries_ocil:questionnaire:1">
          <ocil:title>Set the GNOME3 Login Number of Failures</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_login_retries_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_remote_access_credential_prompt_ocil:questionnaire:1">
          <ocil:title>Require Credential Prompting for Remote Access in GNOME3</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_remote_access_credential_prompt_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_remote_access_encryption_ocil:questionnaire:1">
          <ocil:title>Require Encryption for Remote Access in GNOME3</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_remote_access_encryption_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_screensaver_idle_activation_enabled_ocil:questionnaire:1">
          <ocil:title>Enable GNOME3 Screensaver Idle Activation</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_idle_activation_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_screensaver_idle_activation_locked_ocil:questionnaire:1">
          <ocil:title>Ensure Users Cannot Change GNOME3 Screensaver Idle Activation</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_idle_activation_locked_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_screensaver_idle_delay_ocil:questionnaire:1">
          <ocil:title>Set GNOME3 Screensaver Inactivity Timeout</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_idle_delay_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_screensaver_lock_delay_ocil:questionnaire:1">
          <ocil:title>Set GNOME3 Screensaver Lock Delay After Activation Period</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_lock_delay_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_screensaver_lock_enabled_ocil:questionnaire:1">
          <ocil:title>Enable GNOME3 Screensaver Lock After Idle Period</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_lock_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_screensaver_lock_locked_ocil:questionnaire:1">
          <ocil:title>Ensure Users Cannot Change GNOME3 Screensaver Lock After Idle Period</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_lock_locked_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_screensaver_mode_blank_ocil:questionnaire:1">
          <ocil:title>Implement Blank Screensaver</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_mode_blank_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_screensaver_user_info_ocil:questionnaire:1">
          <ocil:title>Disable Full User Name on Splash Shield</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_user_info_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_screensaver_user_locks_ocil:questionnaire:1">
          <ocil:title>Ensure Users Cannot Change GNOME3 Screensaver Settings</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_user_locks_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dconf_gnome_session_idle_user_locks_ocil:questionnaire:1">
          <ocil:title>Ensure Users Cannot Change GNOME3 Session Idle Settings</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dconf_gnome_session_idle_user_locks_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dir_group_ownership_library_dirs_ocil:questionnaire:1">
          <ocil:title>Verify that Shared Library Directories Have Root Group Ownership</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dir_group_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dir_ownership_binary_dirs_ocil:questionnaire:1">
          <ocil:title>Verify that System Executable Have Root Ownership</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dir_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dir_ownership_library_dirs_ocil:questionnaire:1">
          <ocil:title>Verify that Shared Library Directories Have Root Ownership</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dir_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dir_permissions_binary_dirs_ocil:questionnaire:1">
          <ocil:title>Verify that System Executable Directories Have Restrictive Permissions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dir_permissions_binary_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dir_permissions_library_dirs_ocil:questionnaire:1">
          <ocil:title>Verify that Shared Library Directories Have Restrictive Permissions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dir_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dir_perms_etc_httpd_conf_ocil:questionnaire:1">
          <ocil:title>Set Permissions on the /etc/httpd/conf/ Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dir_perms_etc_httpd_conf_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dir_perms_var_log_httpd_ocil:questionnaire:1">
          <ocil:title>Set Permissions on the /var/log/httpd/ Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dir_perms_var_log_httpd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dir_perms_world_writable_root_owned_ocil:questionnaire:1">
          <ocil:title>Ensure All World-Writable Directories Are Owned by root User</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dir_perms_world_writable_root_owned_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dir_perms_world_writable_sticky_bits_ocil:questionnaire:1">
          <ocil:title>Verify that All World-Writable Directories Have Sticky Bits Set</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dir_perms_world_writable_sticky_bits_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dir_perms_world_writable_system_owned_ocil:questionnaire:1">
          <ocil:title>Ensure All World-Writable Directories Are Owned by a System Account</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dir_perms_world_writable_system_owned_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dir_perms_world_writable_system_owned_group_ocil:questionnaire:1">
          <ocil:title>Ensure All World-Writable Directories Are Group Owned by a System Account</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dir_perms_world_writable_system_owned_group_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dir_system_commands_group_root_owned_ocil:questionnaire:1">
          <ocil:title>Verify that system commands directories have root as a group owner</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dir_system_commands_group_root_owned_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dir_system_commands_root_owned_ocil:questionnaire:1">
          <ocil:title>Verify that system commands directories have root ownership</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dir_system_commands_root_owned_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_access_var_log_audit_ocil:questionnaire:1">
          <ocil:title>Record Access Events to Audit Log Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_access_var_log_audit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_group_ownership_var_log_audit_ocil:questionnaire:1">
          <ocil:title>System Audit Directories Must Be Group Owned By Root</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_group_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_groupowner_etc_ipsecd_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/ipsec.d Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_groupowner_etc_ipsecd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_groupowner_etc_iptables_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/iptables Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_groupowner_etc_iptables_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_groupowner_etc_nftables_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/nftables Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_groupowner_etc_nftables_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_groupowner_etc_selinux_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/selinux Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_groupowner_etc_selinux_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_groupowner_etc_sudoersd_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/sudoers.d Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_groupowner_etc_sudoersd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_groupowner_etc_sysctld_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/sysctl.d Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_groupowner_etc_sysctld_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_owner_etc_ipsecd_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /etc/ipsec.d Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_owner_etc_ipsecd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_owner_etc_iptables_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /etc/iptables Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_owner_etc_iptables_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_owner_etc_nftables_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /etc/nftables Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_owner_etc_nftables_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_owner_etc_selinux_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /etc/selinux Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_owner_etc_selinux_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_owner_etc_sudoersd_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /etc/sudoers.d Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_owner_etc_sudoersd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_owner_etc_sysctld_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /etc/sysctl.d Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_owner_etc_sysctld_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_ownership_var_log_audit_ocil:questionnaire:1">
          <ocil:title>System Audit Directories Must Be Owned By Root</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_permissions_etc_ipsecd_ocil:questionnaire:1">
          <ocil:title>Verify Permissions On /etc/ipsec.d Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_permissions_etc_ipsecd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_permissions_etc_iptables_ocil:questionnaire:1">
          <ocil:title>Verify Permissions On /etc/iptables Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_permissions_etc_iptables_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_permissions_etc_nftables_ocil:questionnaire:1">
          <ocil:title>Verify Permissions On /etc/nftables Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_permissions_etc_nftables_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_permissions_etc_selinux_ocil:questionnaire:1">
          <ocil:title>Verify Permissions On /etc/selinux Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_permissions_etc_selinux_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_permissions_etc_sudoersd_ocil:questionnaire:1">
          <ocil:title>Verify Permissions On /etc/sudoers.d Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_permissions_etc_sudoersd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_permissions_etc_sysctld_ocil:questionnaire:1">
          <ocil:title>Verify Permissions On /etc/sysctl.d Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_permissions_etc_sysctld_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-directory_permissions_var_log_audit_ocil:questionnaire:1">
          <ocil:title>System Audit Logs Must Have Mode 0750 or Less Permissive</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-directory_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-disable_anacron_ocil:questionnaire:1">
          <ocil:title>Disable anacron Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-disable_anacron_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-disable_ctrlaltdel_burstaction_ocil:questionnaire:1">
          <ocil:title>Disable Ctrl-Alt-Del Burst Action</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-disable_ctrlaltdel_burstaction_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-disable_ctrlaltdel_reboot_ocil:questionnaire:1">
          <ocil:title>Disable Ctrl-Alt-Del Reboot Activation</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-disable_ctrlaltdel_reboot_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
          <ocil:title>Disable Host-Based Authentication</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-disable_users_coredumps_ocil:questionnaire:1">
          <ocil:title>Disable Core Dumps for All Users</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-disable_users_coredumps_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-disable_weak_deps_ocil:questionnaire:1">
          <ocil:title>Disable Installation of Weak Dependencies in DNF</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-disable_weak_deps_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-disallow_bypass_password_sudo_ocil:questionnaire:1">
          <ocil:title>Disallow Configuration to Bypass Password Requirements for Privilege Escalation</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-disallow_bypass_password_sudo_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-display_login_attempts_ocil:questionnaire:1">
          <ocil:title>Ensure PAM Displays Last Logon/Access Notification</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-display_login_attempts_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dnf-automatic_apply_updates_ocil:questionnaire:1">
          <ocil:title>Configure dnf-automatic to Install Available Updates Automatically</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dnf-automatic_apply_updates_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-dnf-automatic_security_updates_only_ocil:questionnaire:1">
          <ocil:title>Configure dnf-automatic to Install Only Security Updates</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-dnf-automatic_security_updates_only_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-enable_authselect_ocil:questionnaire:1">
          <ocil:title>Enable authselect</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-enable_authselect_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-enable_dconf_user_profile_ocil:questionnaire:1">
          <ocil:title>Configure GNOME3 DConf User Profile</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-enable_dconf_user_profile_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-enable_dracut_fips_module_ocil:questionnaire:1">
          <ocil:title>Enable Dracut FIPS Module</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-enable_dracut_fips_module_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-enable_fips_mode_ocil:questionnaire:1">
          <ocil:title>Enable FIPS Mode</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-enable_fips_mode_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-enable_gpgcheck_for_all_repositories_ocil:questionnaire:1">
          <ocil:title>Ensure gpgcheck Is Enabled for All Package Repositories</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-enable_gpgcheck_for_all_repositories_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-enable_ldap_client_ocil:questionnaire:1">
          <ocil:title>Enable the LDAP Client For Use in Authconfig</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-enable_ldap_client_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-enable_pam_namespace_ocil:questionnaire:1">
          <ocil:title>Set Up a Private Namespace in PAM Configuration</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-enable_pam_namespace_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-encrypt_partitions_ocil:questionnaire:1">
          <ocil:title>Encrypt Partitions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-encrypt_partitions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ensure_almalinux_gpgkey_installed_ocil:questionnaire:1">
          <ocil:title>Ensure AlmaLinux GPG Key Installed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ensure_almalinux_gpgkey_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ensure_epel_repos_disabled_ocil:questionnaire:1">
          <ocil:title>Ensure EPEL Repository is Disabled</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ensure_epel_repos_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1">
          <ocil:title>Ensure gpgcheck Enabled In Main yum Configuration</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ensure_gpgcheck_local_packages_ocil:questionnaire:1">
          <ocil:title>Ensure gpgcheck Enabled for Local Packages</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_local_packages_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ensure_gpgcheck_never_disabled_ocil:questionnaire:1">
          <ocil:title>Ensure gpgcheck Enabled for All yum Package Repositories</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_never_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ensure_gpgcheck_repo_metadata_ocil:questionnaire:1">
          <ocil:title>Ensure gpgcheck Enabled for Repository Metadata</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_repo_metadata_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ensure_logrotate_activated_ocil:questionnaire:1">
          <ocil:title>Ensure Logrotate Runs Periodically</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ensure_logrotate_activated_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ensure_pam_wheel_group_empty_ocil:questionnaire:1">
          <ocil:title>Ensure the Group Used by pam_wheel.so Module Exists on System and is Empty</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ensure_pam_wheel_group_empty_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ensure_root_password_configured_ocil:questionnaire:1">
          <ocil:title>Ensure Authentication Required for Single User Mode</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ensure_root_password_configured_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-etc_system_fips_exists_ocil:questionnaire:1">
          <ocil:title>Ensure '/etc/system-fips' exists</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-etc_system_fips_exists_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-fapolicy_default_deny_ocil:questionnaire:1">
          <ocil:title>Configure Fapolicy Module to Employ a Deny-all, Permit-by-exception Policy to Allow the Execution of Authorized Software Programs.</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-fapolicy_default_deny_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_at_allow_exists_ocil:questionnaire:1">
          <ocil:title>Ensure that /etc/at.allow exists</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_at_allow_exists_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_at_deny_not_exist_ocil:questionnaire:1">
          <ocil:title>Ensure that /etc/at.deny does not exist</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_at_deny_not_exist_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_audit_tools_group_ownership_ocil:questionnaire:1">
          <ocil:title>Audit Tools Must Be Group-owned by Root</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_audit_tools_group_ownership_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_audit_tools_ownership_ocil:questionnaire:1">
          <ocil:title>Audit Tools Must Be Owned by Root</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_audit_tools_ownership_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_audit_tools_permissions_ocil:questionnaire:1">
          <ocil:title>Audit Tools Must Have a Mode of 0755 or Less Permissive</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_audit_tools_permissions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_cron_allow_exists_ocil:questionnaire:1">
          <ocil:title>Ensure that /etc/cron.allow exists</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_cron_allow_exists_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_cron_deny_not_exist_ocil:questionnaire:1">
          <ocil:title>Ensure that /etc/cron.deny does not exist</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_cron_deny_not_exist_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_etc_security_opasswd_ocil:questionnaire:1">
          <ocil:title>Verify Permissions and Ownership of Old Passwords File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_etc_security_opasswd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_group_ownership_var_log_audit_ocil:questionnaire:1">
          <ocil:title>System Audit Logs Must Be Group Owned By Root</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_group_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_at_allow_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/at.allow file</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_at_allow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_backup_etc_group_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns Backup group File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_backup_etc_gshadow_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns Backup gshadow File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_backup_etc_passwd_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns Backup passwd File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_backup_etc_shadow_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns Backup shadow File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_cron_allow_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/cron.allow file</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_cron_allow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_cron_d_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns cron.d</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_cron_d_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_cron_daily_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns cron.daily</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_cron_daily_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_cron_hourly_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns cron.hourly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_cron_hourly_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_cron_monthly_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns cron.monthly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_cron_monthly_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_cron_weekly_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns cron.weekly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_cron_weekly_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_cron_yearly_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns cron.yearly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_cron_yearly_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_crontab_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns Crontab</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_crontab_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_efi_grub2_cfg_ocil:questionnaire:1">
          <ocil:title>Verify the UEFI Boot Loader grub.cfg Group Ownership</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_efi_grub2_cfg_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_efi_user_cfg_ocil:questionnaire:1">
          <ocil:title>Verify /boot/efi/EFI/almalinux/user.cfg Group Ownership</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_efi_user_cfg_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_etc_chrony_keys_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/chrony.keys File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_etc_chrony_keys_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_etc_crypttab_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/crypttab File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_etc_crypttab_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_etc_group_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns group File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_etc_group_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_etc_gshadow_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns gshadow File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_etc_gshadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_etc_ipsec_conf_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/ipsec.conf File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_etc_ipsec_conf_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_etc_ipsec_secrets_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/ipsec.secrets File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_etc_ipsec_secrets_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_etc_issue_ocil:questionnaire:1">
          <ocil:title>Verify Group Ownership of System Login Banner</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_etc_issue_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_etc_issue_net_ocil:questionnaire:1">
          <ocil:title>Verify Group Ownership of System Login Banner for Remote Connections</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_etc_issue_net_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_etc_motd_ocil:questionnaire:1">
          <ocil:title>Verify Group Ownership of Message of the Day Banner</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_etc_motd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_etc_passwd_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns passwd File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_etc_passwd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_etc_security_opasswd_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/security/opasswd File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_etc_security_opasswd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_etc_security_opasswd_old_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/security/opasswd.old File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_etc_security_opasswd_old_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_etc_sestatus_conf_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/sestatus.conf File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sestatus_conf_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_etc_shadow_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns shadow File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_etc_shadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_etc_shells_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/shells File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_etc_shells_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_etc_sudoers_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/sudoers File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sudoers_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_etc_sysconfig_sshd_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /etc/sysconfig/sshd File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_etc_sysconfig_sshd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_grub2_cfg_ocil:questionnaire:1">
          <ocil:title>Verify /boot/grub2/grub.cfg Group Ownership</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_grub2_cfg_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_sshd_config_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns SSH Server config file</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_sshd_config_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_systemmap_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns System.map Files</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_systemmap_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_user_cfg_ocil:questionnaire:1">
          <ocil:title>Verify /boot/grub2/user.cfg Group Ownership</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_user_cfg_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_var_log_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /var/log Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_var_log_messages_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /var/log/messages File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_messages_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupowner_var_log_syslog_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns /var/log/syslog File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupowner_var_log_syslog_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupownership_audit_binaries_ocil:questionnaire:1">
          <ocil:title>Verify that audit tools are owned by group root</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupownership_audit_binaries_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupownership_audit_configuration_ocil:questionnaire:1">
          <ocil:title>Audit Configuration Files Must Be Owned By Group root</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupownership_audit_configuration_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupownership_home_directories_ocil:questionnaire:1">
          <ocil:title>All Interactive User Home Directories Must Be Group-Owned By The Primary Group</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupownership_home_directories_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupownership_sshd_private_key_ocil:questionnaire:1">
          <ocil:title>Verify Group Ownership on SSH Server Private *_key Key Files</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupownership_sshd_pub_key_ocil:questionnaire:1">
          <ocil:title>Verify Group Ownership on SSH Server Public *.pub Key Files</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_groupownership_system_commands_dirs_ocil:questionnaire:1">
          <ocil:title>Verify that system commands files are group owned by root or a system account</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_groupownership_system_commands_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_at_allow_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /etc/at.allow file</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_at_allow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_backup_etc_group_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns Backup group File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_group_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_backup_etc_gshadow_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns Backup gshadow File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_backup_etc_passwd_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns Backup passwd File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_backup_etc_shadow_ocil:questionnaire:1">
          <ocil:title>Verify Group Who Owns Backup shadow File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_cron_allow_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /etc/cron.allow file</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_cron_allow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_cron_d_ocil:questionnaire:1">
          <ocil:title>Verify Owner on cron.d</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_cron_d_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_cron_daily_ocil:questionnaire:1">
          <ocil:title>Verify Owner on cron.daily</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_cron_daily_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_cron_hourly_ocil:questionnaire:1">
          <ocil:title>Verify Owner on cron.hourly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_cron_hourly_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_cron_monthly_ocil:questionnaire:1">
          <ocil:title>Verify Owner on cron.monthly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_cron_monthly_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_cron_weekly_ocil:questionnaire:1">
          <ocil:title>Verify Owner on cron.weekly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_cron_weekly_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_cron_yearly_ocil:questionnaire:1">
          <ocil:title>Verify Owner on cron.yearly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_cron_yearly_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_crontab_ocil:questionnaire:1">
          <ocil:title>Verify Owner on crontab</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_crontab_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_efi_grub2_cfg_ocil:questionnaire:1">
          <ocil:title>Verify the UEFI Boot Loader grub.cfg User Ownership</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_efi_grub2_cfg_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_efi_user_cfg_ocil:questionnaire:1">
          <ocil:title>Verify /boot/efi/EFI/almalinux/user.cfg User Ownership</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_efi_user_cfg_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_etc_chrony_keys_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /etc/chrony.keys File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_etc_chrony_keys_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_etc_crypttab_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /etc/crypttab File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_etc_crypttab_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_etc_group_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns group File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_etc_group_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_etc_gshadow_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns gshadow File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_etc_gshadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_etc_ipsec_conf_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /etc/ipsec.conf File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_etc_ipsec_conf_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_etc_ipsec_secrets_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /etc/ipsec.secrets File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_etc_ipsec_secrets_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_etc_issue_ocil:questionnaire:1">
          <ocil:title>Verify ownership of System Login Banner</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_etc_issue_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_etc_issue_net_ocil:questionnaire:1">
          <ocil:title>Verify ownership of System Login Banner for Remote Connections</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_etc_issue_net_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_etc_motd_ocil:questionnaire:1">
          <ocil:title>Verify ownership of Message of the Day Banner</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_etc_motd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns passwd File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_etc_security_opasswd_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /etc/security/opasswd File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_etc_security_opasswd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_etc_security_opasswd_old_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /etc/security/opasswd.old File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_etc_security_opasswd_old_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_etc_sestatus_conf_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /etc/sestatus.conf File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_etc_sestatus_conf_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_etc_shadow_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns shadow File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_etc_shadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_etc_shells_ocil:questionnaire:1">
          <ocil:title>Verify Who Owns /etc/shells File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_etc_shells_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_etc_sudoers_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /etc/sudoers File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_etc_sudoers_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_etc_sysconfig_sshd_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /etc/sysconfig/sshd File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_etc_sysconfig_sshd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_grub2_cfg_ocil:questionnaire:1">
          <ocil:title>Verify /boot/grub2/grub.cfg User Ownership</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_grub2_cfg_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_sshd_config_ocil:questionnaire:1">
          <ocil:title>Verify Owner on SSH Server config file</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_sshd_config_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_systemmap_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns System.map Files</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_systemmap_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_user_cfg_ocil:questionnaire:1">
          <ocil:title>Verify /boot/grub2/user.cfg User Ownership</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_user_cfg_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_var_log_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /var/log Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_var_log_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_var_log_messages_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /var/log/messages File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_var_log_messages_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_owner_var_log_syslog_ocil:questionnaire:1">
          <ocil:title>Verify User Who Owns /var/log/syslog File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_owner_var_log_syslog_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_ownership_audit_binaries_ocil:questionnaire:1">
          <ocil:title>Verify that audit tools are owned by root</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_ownership_audit_binaries_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_ownership_audit_configuration_ocil:questionnaire:1">
          <ocil:title>Audit Configuration Files Must Be Owned By Root</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_ownership_audit_configuration_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_ownership_binary_dirs_ocil:questionnaire:1">
          <ocil:title>Verify that System Executables Have Root Ownership</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_ownership_binary_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_ownership_home_directories_ocil:questionnaire:1">
          <ocil:title>All Interactive User Home Directories Must Be Owned By The Primary User</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_ownership_home_directories_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_ownership_library_dirs_ocil:questionnaire:1">
          <ocil:title>Verify that Shared Library Files Have Root Ownership</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_ownership_library_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_ownership_sshd_private_key_ocil:questionnaire:1">
          <ocil:title>Verify Ownership on SSH Server Private *_key Key Files</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_ownership_sshd_private_key_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_ownership_sshd_pub_key_ocil:questionnaire:1">
          <ocil:title>Verify Ownership on SSH Server Public *.pub Key Files</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_ownership_var_log_audit_ocil:questionnaire:1">
          <ocil:title>System Audit Logs Must Be Owned By Root</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_ownership_var_log_audit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_ownership_var_log_audit_stig_ocil:questionnaire:1">
          <ocil:title>System Audit Logs Must Be Owned By Root</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_ownership_var_log_audit_stig_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permission_user_bash_history_ocil:questionnaire:1">
          <ocil:title>Ensure User Bash History File Has Correct Permissions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permission_user_bash_history_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permission_user_init_files_ocil:questionnaire:1">
          <ocil:title>Ensure All User Initialization Files Have Mode 0740 Or Less Permissive</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permission_user_init_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permission_user_init_files_root_ocil:questionnaire:1">
          <ocil:title>Ensure All User Initialization Files Have Mode 0740 Or Less Permissive</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permission_user_init_files_root_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_at_allow_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on /etc/at.allow file</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_at_allow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_audit_binaries_ocil:questionnaire:1">
          <ocil:title>Verify that audit tools Have Mode 0755 or less</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_audit_binaries_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_audit_configuration_ocil:questionnaire:1">
          <ocil:title>Audit Configuration Files Permissions are 640 or More Restrictive</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_audit_configuration_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_backup_etc_group_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on Backup group File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_group_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_backup_etc_gshadow_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on Backup gshadow File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_backup_etc_passwd_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on Backup passwd File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_backup_etc_shadow_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on Backup shadow File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_binary_dirs_ocil:questionnaire:1">
          <ocil:title>Verify that System Executables Have Restrictive Permissions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_binary_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_cron_allow_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on /etc/cron.allow file</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_cron_allow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_cron_d_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on cron.d</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_cron_d_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_cron_daily_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on cron.daily</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_cron_daily_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_cron_hourly_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on cron.hourly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_cron_hourly_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_cron_monthly_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on cron.monthly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_cron_monthly_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_cron_weekly_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on cron.weekly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_cron_weekly_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_cron_yearly_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on cron.yearly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_cron_yearly_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_crontab_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on crontab</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_crontab_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_efi_grub2_cfg_ocil:questionnaire:1">
          <ocil:title>Verify the UEFI Boot Loader grub.cfg Permissions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_efi_grub2_cfg_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_efi_user_cfg_ocil:questionnaire:1">
          <ocil:title>Verify /boot/efi/EFI/almalinux/user.cfg Permissions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_efi_user_cfg_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_audit_auditd_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on /etc/audit/auditd.conf</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_audit_auditd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_audit_rulesd_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on /etc/audit/rules.d/*.rules</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_audit_rulesd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_chrony_keys_ocil:questionnaire:1">
          <ocil:title>Verify Permissions On /etc/chrony.keys File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_chrony_keys_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_crypttab_ocil:questionnaire:1">
          <ocil:title>Verify Permissions On /etc/crypttab File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_crypttab_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_group_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on group File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_group_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_gshadow_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on gshadow File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_gshadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_ipsec_conf_ocil:questionnaire:1">
          <ocil:title>Verify Permissions On /etc/ipsec.conf File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_ipsec_conf_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_ipsec_secrets_ocil:questionnaire:1">
          <ocil:title>Verify Permissions On /etc/ipsec.secrets File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_ipsec_secrets_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_issue_ocil:questionnaire:1">
          <ocil:title>Verify permissions on System Login Banner</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_issue_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_issue_net_ocil:questionnaire:1">
          <ocil:title>Verify permissions on System Login Banner for Remote Connections</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_issue_net_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_motd_ocil:questionnaire:1">
          <ocil:title>Verify permissions on Message of the Day Banner</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_motd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_passwd_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on passwd File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_passwd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_security_opasswd_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on /etc/security/opasswd File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_security_opasswd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_security_opasswd_old_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on /etc/security/opasswd.old File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_security_opasswd_old_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_sestatus_conf_ocil:questionnaire:1">
          <ocil:title>Verify Permissions On /etc/sestatus.conf File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_sestatus_conf_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_shadow_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on shadow File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_shadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_shells_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on /etc/shells File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_shells_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_sudoers_ocil:questionnaire:1">
          <ocil:title>Verify Permissions On /etc/sudoers File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_sudoers_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_etc_sysconfig_sshd_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on /etc/sysconfig/sshd File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_etc_sysconfig_sshd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_grub2_cfg_ocil:questionnaire:1">
          <ocil:title>Verify /boot/grub2/grub.cfg Permissions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_grub2_cfg_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_home_directories_ocil:questionnaire:1">
          <ocil:title>All Interactive User Home Directories Must Have mode 0750 Or Less Permissive</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_home_directories_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_home_dirs_ocil:questionnaire:1">
          <ocil:title>Ensure that User Home Directories are not Group-Writable or World-Readable</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_home_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_httpd_server_conf_d_files_ocil:questionnaire:1">
          <ocil:title>Set Permissions on All Configuration Files Inside /etc/httpd/conf.d/</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_httpd_server_conf_d_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_httpd_server_conf_files_ocil:questionnaire:1">
          <ocil:title>Set Permissions on All Configuration Files Inside /etc/httpd/conf/</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_httpd_server_conf_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_httpd_server_modules_files_ocil:questionnaire:1">
          <ocil:title>Set Permissions on All Configuration Files Inside /etc/httpd/conf.modules.d/</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_httpd_server_modules_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_library_dirs_ocil:questionnaire:1">
          <ocil:title>Verify that Shared Library Files Have Restrictive Permissions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_library_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_sshd_config_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on SSH Server config file</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_sshd_config_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_sshd_private_key_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on SSH Server Private *_key Key Files</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_sshd_private_key_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_sshd_pub_key_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on SSH Server Public *.pub Key Files</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_systemmap_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on System.map Files</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_systemmap_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_unauthorized_sgid_ocil:questionnaire:1">
          <ocil:title>Ensure All SGID Executables Are Authorized</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_sgid_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_unauthorized_suid_ocil:questionnaire:1">
          <ocil:title>Ensure All SUID Executables Are Authorized</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_suid_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_unauthorized_world_writable_ocil:questionnaire:1">
          <ocil:title>Ensure No World-Writable Files Exist</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_unauthorized_world_writable_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_ungroupowned_ocil:questionnaire:1">
          <ocil:title>Ensure All Files Are Owned by a Group</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_ungroupowned_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_user_cfg_ocil:questionnaire:1">
          <ocil:title>Verify /boot/grub2/user.cfg Permissions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_user_cfg_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_var_log_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on /var/log Directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_var_log_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_var_log_audit_ocil:questionnaire:1">
          <ocil:title>System Audit Logs Must Have Mode 0640 or Less Permissive</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_var_log_audit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_var_log_messages_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on /var/log/messages File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_var_log_messages_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-file_permissions_var_log_syslog_ocil:questionnaire:1">
          <ocil:title>Verify Permissions on /var/log/syslog File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-file_permissions_var_log_syslog_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-fips_crypto_subpolicy_ocil:questionnaire:1">
          <ocil:title>FIPS Must Use a Supported Subpolicy</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-fips_crypto_subpolicy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-fips_custom_stig_sub_policy_ocil:questionnaire:1">
          <ocil:title>Implement STIG Sub Crypto Policy</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-fips_custom_stig_sub_policy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firewalld-backend_ocil:questionnaire:1">
          <ocil:title>Configure Firewalld to Use the Nftables Backend</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firewalld-backend_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firewalld_loopback_traffic_restricted_ocil:questionnaire:1">
          <ocil:title>Configure Firewalld to Restrict Loopback Traffic</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firewalld_loopback_traffic_restricted_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firewalld_loopback_traffic_trusted_ocil:questionnaire:1">
          <ocil:title>Configure Firewalld to Trust Loopback Traffic</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firewalld_loopback_traffic_trusted_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-firewalld_sshd_port_enabled_ocil:questionnaire:1">
          <ocil:title>Enable SSH Server firewalld Firewall Exception</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-firewalld_sshd_port_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-force_opensc_card_drivers_ocil:questionnaire:1">
          <ocil:title>Force opensc To Use Defined Smart Card Driver</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-force_opensc_card_drivers_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ftp_log_transactions_ocil:questionnaire:1">
          <ocil:title>Enable Logging of All FTP Transactions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ftp_log_transactions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ftp_present_banner_ocil:questionnaire:1">
          <ocil:title>Create Warning Banners for All FTP Users</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ftp_present_banner_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-gid_passwd_group_same_ocil:questionnaire:1">
          <ocil:title>All GIDs referenced in /etc/passwd must be defined in /etc/group</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-gid_passwd_group_same_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-gnome_gdm_disable_automatic_login_ocil:questionnaire:1">
          <ocil:title>Disable GDM Automatic Login</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_automatic_login_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-gnome_gdm_disable_guest_login_ocil:questionnaire:1">
          <ocil:title>Disable GDM Guest Login</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_guest_login_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-gnome_gdm_disable_xdmcp_ocil:questionnaire:1">
          <ocil:title>Disable XDMCP in GDM</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-group_unique_id_ocil:questionnaire:1">
          <ocil:title>Ensure All Groups on the System Have Unique Group ID</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-group_unique_id_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-group_unique_name_ocil:questionnaire:1">
          <ocil:title>Ensure All Groups on the System Have Unique Group Names</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-group_unique_name_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-groups_no_zero_gid_except_root_ocil:questionnaire:1">
          <ocil:title>Verify Only Group Root Has GID 0</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-groups_no_zero_gid_except_root_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_admin_username_ocil:questionnaire:1">
          <ocil:title>Set the Boot Loader Admin Username to a Non-Default Value</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_admin_username_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_audit_argument_ocil:questionnaire:1">
          <ocil:title>Enable Auditing for Processes Which Start Prior to the Audit Daemon</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_audit_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_audit_backlog_limit_argument_ocil:questionnaire:1">
          <ocil:title>Extend Audit Backlog Limit for the Audit Daemon</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_audit_backlog_limit_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_disable_interactive_boot_ocil:questionnaire:1">
          <ocil:title>Verify that Interactive Boot is Disabled</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_disable_interactive_boot_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_disable_recovery_ocil:questionnaire:1">
          <ocil:title>Disable Recovery Booting</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_disable_recovery_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_enable_iommu_force_ocil:questionnaire:1">
          <ocil:title>IOMMU configuration directive</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_enable_iommu_force_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_enable_selinux_ocil:questionnaire:1">
          <ocil:title>Ensure SELinux Not Disabled in /etc/default/grub</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_enable_selinux_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_ipv6_disable_argument_ocil:questionnaire:1">
          <ocil:title>Ensure IPv6 is disabled through kernel boot parameter</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_ipv6_disable_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_kernel_trust_cpu_rng_ocil:questionnaire:1">
          <ocil:title>Configure kernel to trust the CPU random number generator</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_kernel_trust_cpu_rng_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_l1tf_argument_ocil:questionnaire:1">
          <ocil:title>Configure L1 Terminal Fault mitigations</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_l1tf_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_mce_argument_ocil:questionnaire:1">
          <ocil:title>Force kernel panic on uncorrected MCEs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_mce_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_no_removeable_media_ocil:questionnaire:1">
          <ocil:title>Boot Loader Is Not Installed On Removable Media</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_no_removeable_media_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_nosmap_argument_absent_ocil:questionnaire:1">
          <ocil:title>Ensure SMAP is not disabled during boot</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_nosmap_argument_absent_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_nosmep_argument_absent_ocil:questionnaire:1">
          <ocil:title>Ensure SMEP is not disabled during boot</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_nosmep_argument_absent_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_nousb_argument_ocil:questionnaire:1">
          <ocil:title>Disable Kernel Support for USB via Bootloader Configuration</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_nousb_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_page_poison_argument_ocil:questionnaire:1">
          <ocil:title>Enable page allocator poisoning</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_page_poison_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_password_ocil:questionnaire:1">
          <ocil:title>Set Boot Loader Password in grub2</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_password_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_pti_argument_ocil:questionnaire:1">
          <ocil:title>Enable Kernel Page-Table Isolation (KPTI)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_pti_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_rng_core_default_quality_argument_ocil:questionnaire:1">
          <ocil:title>Configure the confidence in TPM for entropy</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_rng_core_default_quality_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_slab_nomerge_argument_ocil:questionnaire:1">
          <ocil:title>Disable merging of slabs with similar size</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_slub_debug_argument_ocil:questionnaire:1">
          <ocil:title>Enable SLUB/SLAB allocator poisoning</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_slub_debug_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_spec_store_bypass_disable_argument_ocil:questionnaire:1">
          <ocil:title>Configure Speculative Store Bypass Mitigation</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_spectre_v2_argument_ocil:questionnaire:1">
          <ocil:title>Enforce Spectre v2 mitigation</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_spectre_v2_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_systemd_debug-shell_argument_absent_ocil:questionnaire:1">
          <ocil:title>Ensure debug-shell service is not enabled during boot</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_systemd_debug-shell_argument_absent_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_uefi_admin_username_ocil:questionnaire:1">
          <ocil:title>Set the UEFI Boot Loader Admin Username to a Non-Default Value</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_uefi_admin_username_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_uefi_password_ocil:questionnaire:1">
          <ocil:title>Set the UEFI Boot Loader Password</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_uefi_password_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-grub2_vsyscall_argument_ocil:questionnaire:1">
          <ocil:title>Disable vsyscalls</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-grub2_vsyscall_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-harden_openssl_crypto_policy_ocil:questionnaire:1">
          <ocil:title>Harden OpenSSL Crypto Policy</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-harden_openssl_crypto_policy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-harden_ssh_client_crypto_policy_ocil:questionnaire:1">
          <ocil:title>Harden SSH client Crypto Policy</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-harden_ssh_client_crypto_policy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-harden_sshd_ciphers_openssh_conf_crypto_policy_ocil:questionnaire:1">
          <ocil:title>Configure SSH Client to Use FIPS 140 Validated Ciphers: openssh.config</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-harden_sshd_ciphers_openssh_conf_crypto_policy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-harden_sshd_ciphers_opensshserver_conf_crypto_policy_ocil:questionnaire:1">
          <ocil:title>Configure SSH Server to Use FIPS 140-2 Validated Ciphers: opensshserver.config</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-harden_sshd_ciphers_opensshserver_conf_crypto_policy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-harden_sshd_crypto_policy_ocil:questionnaire:1">
          <ocil:title>Harden SSHD Crypto Policy</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-harden_sshd_crypto_policy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-harden_sshd_macs_openssh_conf_crypto_policy_ocil:questionnaire:1">
          <ocil:title>Configure SSH Client to Use FIPS 140-2 Validated MACs: openssh.config</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-harden_sshd_macs_openssh_conf_crypto_policy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-harden_sshd_macs_opensshserver_conf_crypto_policy_ocil:questionnaire:1">
          <ocil:title>Configure SSH Server to Use FIPS 140-2 Validated MACs: opensshserver.config</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-harden_sshd_macs_opensshserver_conf_crypto_policy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-has_nonlocal_mta_ocil:questionnaire:1">
          <ocil:title>Ensure Mail Transfer Agent is not Listening on any non-loopback Address</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-has_nonlocal_mta_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-http_configure_log_file_ownership_ocil:questionnaire:1">
          <ocil:title>HTTPD Log Files Must Be Owned By Root</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-http_configure_log_file_ownership_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_anonymous_content_sharing_ocil:questionnaire:1">
          <ocil:title>Web Content Directories Must Not Be Shared Anonymously</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_anonymous_content_sharing_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_antivirus_scan_uploads_ocil:questionnaire:1">
          <ocil:title>Scan All Uploaded Content for Malicious Software</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_antivirus_scan_uploads_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_configure_banner_page_ocil:questionnaire:1">
          <ocil:title>Configure A Banner Page For Each Website</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_configure_banner_page_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_configure_documentroot_ocil:questionnaire:1">
          <ocil:title>Each Web Content Directory Must Contain An index.html File</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_configure_documentroot_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_configure_firewall_ocil:questionnaire:1">
          <ocil:title>Configure firewall to Allow Access to the Web Server</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_configure_firewall_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_configure_log_format_ocil:questionnaire:1">
          <ocil:title>Configure Error Log Format</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_configure_log_format_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_configure_max_keepalive_requests_ocil:questionnaire:1">
          <ocil:title>Configure The Number of Allowed Simultaneous Requests</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_configure_max_keepalive_requests_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_configure_perl_taint_ocil:questionnaire:1">
          <ocil:title>Configure HTTP PERL Scripts To Use TAINT Option</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_configure_perl_taint_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_configure_remote_session_encryption_ocil:questionnaire:1">
          <ocil:title>Ensure Remote Administrative Access Is Encrypted</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_configure_remote_session_encryption_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_configure_script_permissions_ocil:questionnaire:1">
          <ocil:title>Remove Write Permissions From Filesystem Paths And Server Scripts</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_configure_script_permissions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_configure_tls_ocil:questionnaire:1">
          <ocil:title>Enable Transport Layer Security (TLS) Encryption</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_configure_tls_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_configure_valid_server_cert_ocil:questionnaire:1">
          <ocil:title>Configure A Valid Server Certificate</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_configure_valid_server_cert_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_disable_anonymous_ftp_access_ocil:questionnaire:1">
          <ocil:title>Disable Anonymous FTP Access</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_disable_anonymous_ftp_access_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_disable_content_symlinks_ocil:questionnaire:1">
          <ocil:title>Disable Web Content Symbolic Links</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_disable_content_symlinks_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_disable_mime_types_ocil:questionnaire:1">
          <ocil:title>MIME types for csh or sh shell programs must be disabled</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_disable_mime_types_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_enable_error_logging_ocil:questionnaire:1">
          <ocil:title>Enable HTTPD Error Logging</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_enable_error_logging_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_enable_log_config_ocil:questionnaire:1">
          <ocil:title>Enable log_config_module For HTTPD Logging</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_enable_log_config_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_enable_loglevel_ocil:questionnaire:1">
          <ocil:title>Enable HTTPD LogLevel</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_enable_loglevel_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_enable_system_logging_ocil:questionnaire:1">
          <ocil:title>Enable HTTPD System Logging</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_enable_system_logging_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_encrypt_file_uploads_ocil:questionnaire:1">
          <ocil:title>Encrypt All File Uploads</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_encrypt_file_uploads_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_entrust_passwords_ocil:questionnaire:1">
          <ocil:title>The web server password(s) must be entrusted to the SA or Web Manager</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_entrust_passwords_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_ignore_htaccess_files_ocil:questionnaire:1">
          <ocil:title>Ignore HTTPD .htaccess Files</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_ignore_htaccess_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_limit_java_files_ocil:questionnaire:1">
          <ocil:title>Remove .java And .jpp Files</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_limit_java_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_nipr_accredited_dmz_ocil:questionnaire:1">
          <ocil:title>A public web server, if hosted on the NIPRNet, must be isolated in an accredited DoD DMZ extension</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_nipr_accredited_dmz_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_no_compilers_in_prod_ocil:questionnaire:1">
          <ocil:title>Installation of a compiler on production web server is prohibited</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_no_compilers_in_prod_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_private_server_on_separate_subnet_ocil:questionnaire:1">
          <ocil:title>A private web server must be located on a separate controlled access subnet</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_private_server_on_separate_subnet_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_public_resources_not_shared_ocil:questionnaire:1">
          <ocil:title>Public web server resources must not be shared with private assets</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_public_resources_not_shared_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_remove_backups_ocil:questionnaire:1">
          <ocil:title>Backup interactive scripts on the production web server are prohibited</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_remove_backups_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_remove_robots_file_ocil:questionnaire:1">
          <ocil:title>The robots.txt Files Must Not Exist</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_remove_robots_file_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-httpd_require_client_certs_ocil:questionnaire:1">
          <ocil:title>Require Client Certificates</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-httpd_require_client_certs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-install_antivirus_ocil:questionnaire:1">
          <ocil:title>Install Virus Scanning Software</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-install_antivirus_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-install_hids_ocil:questionnaire:1">
          <ocil:title>Install Intrusion Detection Software</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-install_hids_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-install_mcafee_antivirus_ocil:questionnaire:1">
          <ocil:title>Install McAfee Virus Scanning Software</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-install_mcafee_antivirus_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-install_mcafee_cma_rt_ocil:questionnaire:1">
          <ocil:title>Install the McAfee Runtime Libraries and Linux Agent</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-install_mcafee_cma_rt_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-install_mcafee_hbss_accm_ocil:questionnaire:1">
          <ocil:title>Install the Asset Configuration Compliance Module (ACCM)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-install_mcafee_hbss_accm_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-install_mcafee_hbss_pa_ocil:questionnaire:1">
          <ocil:title>Install the Policy Auditor (PA) Module</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-install_mcafee_hbss_pa_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-install_smartcard_packages_ocil:questionnaire:1">
          <ocil:title>Install Smart Card Packages For Multifactor Authentication</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-install_smartcard_packages_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-installed_OS_is_FIPS_certified_ocil:questionnaire:1">
          <ocil:title>The Installed Operating System Is FIPS 140-2 Certified</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-installed_OS_is_vendor_supported_ocil:questionnaire:1">
          <ocil:title>The Installed Operating System Is Vendor Supported</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-installed_OS_is_vendor_supported_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ip6tables_rules_for_open_ports_ocil:questionnaire:1">
          <ocil:title>Ensure ip6tables Firewall Rules Exist for All Open Ports</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ip6tables_rules_for_open_ports_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-iptables_rules_for_open_ports_ocil:questionnaire:1">
          <ocil:title>Ensure iptables Firewall Rules Exist for All Open Ports</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-iptables_rules_for_open_ports_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-journald_compress_ocil:questionnaire:1">
          <ocil:title>Ensure journald is configured to compress large log files</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-journald_compress_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-journald_disable_forward_to_syslog_ocil:questionnaire:1">
          <ocil:title>Ensure journald ForwardToSyslog is disabled</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-journald_disable_forward_to_syslog_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-journald_forward_to_syslog_ocil:questionnaire:1">
          <ocil:title>Ensure journald is configured to send logs to rsyslog</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-journald_forward_to_syslog_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-journald_storage_ocil:questionnaire:1">
          <ocil:title>Ensure journald is configured to write log files to persistent disk</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-journald_storage_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kerberos_disable_no_keytab_ocil:questionnaire:1">
          <ocil:title>Disable Kerberos by removing host keytab</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kerberos_disable_no_keytab_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_acpi_custom_method_ocil:questionnaire:1">
          <ocil:title>Do not allow ACPI methods to be inserted/replaced at run time</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_acpi_custom_method_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_ocil:questionnaire:1">
          <ocil:title>Emulate Privileged Access Never (PAN)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_binfmt_misc_ocil:questionnaire:1">
          <ocil:title>Disable kernel support for MISC binaries</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_binfmt_misc_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_bug_ocil:questionnaire:1">
          <ocil:title>Enable support for BUG()</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_bug_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_bug_on_data_corruption_ocil:questionnaire:1">
          <ocil:title>Trigger a kernel BUG when data corruption is detected</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_bug_on_data_corruption_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_compat_brk_ocil:questionnaire:1">
          <ocil:title>Disable compatibility with brk()</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_compat_brk_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_compat_vdso_ocil:questionnaire:1">
          <ocil:title>Disable the 32-bit vDSO</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_compat_vdso_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_debug_credentials_ocil:questionnaire:1">
          <ocil:title>Enable checks on credential management</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_debug_credentials_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_debug_fs_ocil:questionnaire:1">
          <ocil:title>Disable kernel debugfs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_debug_fs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_debug_list_ocil:questionnaire:1">
          <ocil:title>Enable checks on linked list manipulation</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_debug_list_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_debug_notifiers_ocil:questionnaire:1">
          <ocil:title>Enable checks on notifier call chains</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_debug_notifiers_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_debug_sg_ocil:questionnaire:1">
          <ocil:title>Enable checks on scatter-gather (SG) table operations</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_debug_sg_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_debug_wx_ocil:questionnaire:1">
          <ocil:title>Warn on W+X mappings found at boot</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_debug_wx_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_default_mmap_min_addr_ocil:questionnaire:1">
          <ocil:title>Configure Low Address Space To Protect From User Allocation</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_default_mmap_min_addr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_devkmem_ocil:questionnaire:1">
          <ocil:title>Disable /dev/kmem virtual device support</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_devkmem_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_fortify_source_ocil:questionnaire:1">
          <ocil:title>Harden common str/mem functions against buffer overflows</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_fortify_source_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_gcc_plugin_latent_entropy_ocil:questionnaire:1">
          <ocil:title>Generate some entropy during boot and runtime</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_gcc_plugin_latent_entropy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_gcc_plugin_structleak_ocil:questionnaire:1">
          <ocil:title>Force initialization of variables containing userspace addresses</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_gcc_plugin_structleak_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_hardened_usercopy_ocil:questionnaire:1">
          <ocil:title>Harden memory copies between kernel and userspace</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_hardened_usercopy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_hardened_usercopy_fallback_ocil:questionnaire:1">
          <ocil:title>Do not allow usercopy whitelist violations to fallback to object size</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_hardened_usercopy_fallback_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_hibernation_ocil:questionnaire:1">
          <ocil:title>Disable hibernation</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_hibernation_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_ia32_emulation_ocil:questionnaire:1">
          <ocil:title>Disable IA32 emulation</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_ia32_emulation_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_ipv6_ocil:questionnaire:1">
          <ocil:title>Disable the IPv6 protocol</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_ipv6_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_kexec_ocil:questionnaire:1">
          <ocil:title>Disable kexec system call</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_kexec_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_legacy_ptys_ocil:questionnaire:1">
          <ocil:title>Disable legacy (BSD) PTY support</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_legacy_ptys_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_legacy_vsyscall_emulate_ocil:questionnaire:1">
          <ocil:title>Disable vsyscall emulation</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_legacy_vsyscall_emulate_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_legacy_vsyscall_none_ocil:questionnaire:1">
          <ocil:title>Disable vsyscall mapping</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_legacy_vsyscall_none_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_modify_ldt_syscall_ocil:questionnaire:1">
          <ocil:title>Disable the LDT (local descriptor table)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_modify_ldt_syscall_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_module_sig_ocil:questionnaire:1">
          <ocil:title>Enable module signature verification</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_module_sig_all_ocil:questionnaire:1">
          <ocil:title>Enable automatic signing of all modules</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_all_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_module_sig_force_ocil:questionnaire:1">
          <ocil:title>Require modules to be validly signed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_force_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_module_sig_hash_ocil:questionnaire:1">
          <ocil:title>Specify the hash to use when signing modules</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_hash_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_module_sig_key_ocil:questionnaire:1">
          <ocil:title>Specify module signing key to use</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_key_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_module_sig_sha512_ocil:questionnaire:1">
          <ocil:title>Sign kernel modules with SHA-512</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_module_sig_sha512_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_page_poisoning_ocil:questionnaire:1">
          <ocil:title>Enable poison of pages after freeing</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_page_poisoning_no_sanity_ocil:questionnaire:1">
          <ocil:title>Enable poison without sanity check</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_no_sanity_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_page_poisoning_zero_ocil:questionnaire:1">
          <ocil:title>Use zero for poisoning instead of debugging value</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_page_table_isolation_ocil:questionnaire:1">
          <ocil:title>Remove the kernel mapping in user mode</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_page_table_isolation_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_panic_on_oops_ocil:questionnaire:1">
          <ocil:title>Kernel panic oops</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_panic_on_oops_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_panic_timeout_ocil:questionnaire:1">
          <ocil:title>Kernel panic timeout</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_panic_timeout_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_proc_kcore_ocil:questionnaire:1">
          <ocil:title>Disable support for /proc/kkcore</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_proc_kcore_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_randomize_base_ocil:questionnaire:1">
          <ocil:title>Randomize the address of the kernel image (KASLR)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_randomize_base_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_randomize_memory_ocil:questionnaire:1">
          <ocil:title>Randomize the kernel memory sections</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_randomize_memory_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_refcount_full_ocil:questionnaire:1">
          <ocil:title>Perform full reference count validation</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_refcount_full_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_retpoline_ocil:questionnaire:1">
          <ocil:title>Avoid speculative indirect branches in kernel</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_retpoline_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_sched_stack_end_check_ocil:questionnaire:1">
          <ocil:title>Detect stack corruption on calls to schedule()</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_sched_stack_end_check_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_seccomp_ocil:questionnaire:1">
          <ocil:title>Enable seccomp to safely compute untrusted bytecode</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_seccomp_filter_ocil:questionnaire:1">
          <ocil:title>Enable use of Berkeley Packet Filter with seccomp</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_seccomp_filter_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_security_ocil:questionnaire:1">
          <ocil:title>Enable different security models</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_security_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_security_dmesg_restrict_ocil:questionnaire:1">
          <ocil:title>Restrict unprivileged access to the kernel syslog</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_security_dmesg_restrict_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_security_writable_hooks_ocil:questionnaire:1">
          <ocil:title>Disable mutable hooks</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_security_writable_hooks_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_security_yama_ocil:questionnaire:1">
          <ocil:title>Enable Yama support</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_security_yama_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_slab_freelist_hardened_ocil:questionnaire:1">
          <ocil:title>Harden slab freelist metadata</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_slab_freelist_hardened_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_slab_freelist_random_ocil:questionnaire:1">
          <ocil:title>Randomize slab freelist</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_slab_freelist_random_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_slab_merge_default_ocil:questionnaire:1">
          <ocil:title>Disallow merge of slab caches</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_slab_merge_default_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_slub_debug_ocil:questionnaire:1">
          <ocil:title>Enable SLUB debugging support</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_slub_debug_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_stackprotector_ocil:questionnaire:1">
          <ocil:title>Stack Protector buffer overflow detection</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_stackprotector_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_stackprotector_strong_ocil:questionnaire:1">
          <ocil:title>Strong Stack Protector</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_stackprotector_strong_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_strict_kernel_rwx_ocil:questionnaire:1">
          <ocil:title>Make the kernel text and rodata read-only</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_strict_kernel_rwx_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_strict_module_rwx_ocil:questionnaire:1">
          <ocil:title>Make the module text and rodata read-only</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_strict_module_rwx_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_syn_cookies_ocil:questionnaire:1">
          <ocil:title>Enable TCP/IP syncookie support</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_syn_cookies_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_unmap_kernel_at_el0_ocil:questionnaire:1">
          <ocil:title>Unmap kernel when running in userspace (aka KAISER)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_unmap_kernel_at_el0_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_vmap_stack_ocil:questionnaire:1">
          <ocil:title>User a virtually-mapped stack</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_vmap_stack_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_config_x86_vsyscall_emulation_ocil:questionnaire:1">
          <ocil:title>Disable x86 vsyscall emulation</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_config_x86_vsyscall_emulation_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_module_atm_disabled_ocil:questionnaire:1">
          <ocil:title>Disable ATM Support</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_module_atm_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_module_bluetooth_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Bluetooth Kernel Module</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_module_bluetooth_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_module_can_disabled_ocil:questionnaire:1">
          <ocil:title>Disable CAN Support</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_module_can_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_module_cfg80211_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Kernel cfg80211 Module</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_module_cfg80211_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_module_cramfs_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Mounting of cramfs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_module_cramfs_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_module_dccp_disabled_ocil:questionnaire:1">
          <ocil:title>Disable DCCP Support</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_module_dccp_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_module_firewire-core_disabled_ocil:questionnaire:1">
          <ocil:title>Disable IEEE 1394 (FireWire) Support</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_module_firewire-core_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_module_ipv6_option_disabled_ocil:questionnaire:1">
          <ocil:title>Disable IPv6 Networking Support Automatic Loading</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_module_ipv6_option_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_module_iwlmvm_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Kernel iwlmvm Module</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_module_iwlmvm_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_module_iwlwifi_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Kernel iwlwifi Module</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_module_iwlwifi_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_module_mac80211_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Kernel mac80211 Module</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_module_mac80211_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_module_rds_disabled_ocil:questionnaire:1">
          <ocil:title>Disable RDS Support</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_module_rds_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_module_sctp_disabled_ocil:questionnaire:1">
          <ocil:title>Disable SCTP Support</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_module_sctp_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_module_tipc_disabled_ocil:questionnaire:1">
          <ocil:title>Disable TIPC Support</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_module_tipc_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_module_usb-storage_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Modprobe Loading of USB Storage Driver</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-kernel_module_uvcvideo_disabled_ocil:questionnaire:1">
          <ocil:title>Disable the uvcvideo module</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-kernel_module_uvcvideo_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ldap_client_start_tls_ocil:questionnaire:1">
          <ocil:title>Configure LDAP Client to Use TLS For All Transactions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ldap_client_start_tls_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ldap_client_tls_cacertpath_ocil:questionnaire:1">
          <ocil:title>Configure Certificate Directives for LDAP Use of TLS</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ldap_client_tls_cacertpath_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-libreswan_approved_tunnels_ocil:questionnaire:1">
          <ocil:title>Verify Any Configured IPSec Tunnel Connections</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-libreswan_approved_tunnels_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-logind_session_timeout_ocil:questionnaire:1">
          <ocil:title>Configure Logind to terminate idle sessions after certain time of inactivity</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-logind_session_timeout_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mcafee_antivirus_definitions_updated_ocil:questionnaire:1">
          <ocil:title>Virus Scanning Software Definitions Are Updated</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mcafee_antivirus_definitions_updated_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_boot_efi_nosuid_ocil:questionnaire:1">
          <ocil:title>Add nosuid Option to /boot/efi</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_boot_efi_nosuid_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_boot_noauto_ocil:questionnaire:1">
          <ocil:title>Add noauto Option to /boot</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_boot_noauto_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_boot_nodev_ocil:questionnaire:1">
          <ocil:title>Add nodev Option to /boot</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_boot_nodev_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_boot_noexec_ocil:questionnaire:1">
          <ocil:title>Add noexec Option to /boot</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_boot_noexec_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_boot_nosuid_ocil:questionnaire:1">
          <ocil:title>Add nosuid Option to /boot</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_boot_nosuid_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_dev_shm_nodev_ocil:questionnaire:1">
          <ocil:title>Add nodev Option to /dev/shm</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nodev_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_dev_shm_noexec_ocil:questionnaire:1">
          <ocil:title>Add noexec Option to /dev/shm</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_noexec_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_dev_shm_nosuid_ocil:questionnaire:1">
          <ocil:title>Add nosuid Option to /dev/shm</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_dev_shm_nosuid_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_home_grpquota_ocil:questionnaire:1">
          <ocil:title>Add grpquota Option to /home</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_home_grpquota_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_home_nodev_ocil:questionnaire:1">
          <ocil:title>Add nodev Option to /home</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_home_nodev_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_home_noexec_ocil:questionnaire:1">
          <ocil:title>Add noexec Option to /home</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_home_noexec_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_home_nosuid_ocil:questionnaire:1">
          <ocil:title>Add nosuid Option to /home</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_home_nosuid_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_home_usrquota_ocil:questionnaire:1">
          <ocil:title>Add usrquota Option to /home</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_home_usrquota_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_krb_sec_remote_filesystems_ocil:questionnaire:1">
          <ocil:title>Mount Remote Filesystems with Kerberos Security</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_krb_sec_remote_filesystems_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_nodev_nonroot_local_partitions_ocil:questionnaire:1">
          <ocil:title>Add nodev Option to Non-Root Local Partitions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_nodev_nonroot_local_partitions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_nodev_remote_filesystems_ocil:questionnaire:1">
          <ocil:title>Mount Remote Filesystems with nodev</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_nodev_remote_filesystems_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_nodev_removable_partitions_ocil:questionnaire:1">
          <ocil:title>Add nodev Option to Removable Media Partitions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_nodev_removable_partitions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_noexec_remote_filesystems_ocil:questionnaire:1">
          <ocil:title>Mount Remote Filesystems with noexec</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_noexec_remote_filesystems_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_noexec_removable_partitions_ocil:questionnaire:1">
          <ocil:title>Add noexec Option to Removable Media Partitions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_noexec_removable_partitions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_nosuid_remote_filesystems_ocil:questionnaire:1">
          <ocil:title>Mount Remote Filesystems with nosuid</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_nosuid_remote_filesystems_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_nosuid_removable_partitions_ocil:questionnaire:1">
          <ocil:title>Add nosuid Option to Removable Media Partitions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_nosuid_removable_partitions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_opt_nosuid_ocil:questionnaire:1">
          <ocil:title>Add nosuid Option to /opt</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_opt_nosuid_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_proc_hidepid_ocil:questionnaire:1">
          <ocil:title>Add hidepid Option to /proc</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_proc_hidepid_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_smb_client_signing_ocil:questionnaire:1">
          <ocil:title>Require Client SMB Packet Signing, if using mount.cifs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_smb_client_signing_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_srv_nosuid_ocil:questionnaire:1">
          <ocil:title>Add nosuid Option to /srv</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_srv_nosuid_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_tmp_nodev_ocil:questionnaire:1">
          <ocil:title>Add nodev Option to /tmp</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_tmp_nodev_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_tmp_noexec_ocil:questionnaire:1">
          <ocil:title>Add noexec Option to /tmp</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_tmp_noexec_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_tmp_nosuid_ocil:questionnaire:1">
          <ocil:title>Add nosuid Option to /tmp</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_tmp_nosuid_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_var_log_audit_nodev_ocil:questionnaire:1">
          <ocil:title>Add nodev Option to /var/log/audit</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_nodev_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_var_log_audit_noexec_ocil:questionnaire:1">
          <ocil:title>Add noexec Option to /var/log/audit</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_noexec_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_var_log_audit_nosuid_ocil:questionnaire:1">
          <ocil:title>Add nosuid Option to /var/log/audit</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_var_log_audit_nosuid_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_var_log_nodev_ocil:questionnaire:1">
          <ocil:title>Add nodev Option to /var/log</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_var_log_nodev_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_var_log_noexec_ocil:questionnaire:1">
          <ocil:title>Add noexec Option to /var/log</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_var_log_noexec_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_var_log_nosuid_ocil:questionnaire:1">
          <ocil:title>Add nosuid Option to /var/log</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_var_log_nosuid_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_var_nodev_ocil:questionnaire:1">
          <ocil:title>Add nodev Option to /var</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_var_nodev_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_var_noexec_ocil:questionnaire:1">
          <ocil:title>Add noexec Option to /var</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_var_noexec_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_var_nosuid_ocil:questionnaire:1">
          <ocil:title>Add nosuid Option to /var</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_var_nosuid_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_var_tmp_nodev_ocil:questionnaire:1">
          <ocil:title>Add nodev Option to /var/tmp</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_nodev_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_var_tmp_noexec_ocil:questionnaire:1">
          <ocil:title>Add noexec Option to /var/tmp</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_noexec_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-mount_option_var_tmp_nosuid_ocil:questionnaire:1">
          <ocil:title>Add nosuid Option to /var/tmp</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-mount_option_var_tmp_nosuid_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-network_configure_name_resolution_ocil:questionnaire:1">
          <ocil:title>Configure Multiple DNS Servers in /etc/resolv.conf</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-network_configure_name_resolution_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-network_disable_ddns_interfaces_ocil:questionnaire:1">
          <ocil:title>Disable Client Dynamic DNS Updates</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-network_disable_ddns_interfaces_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-network_nmcli_permissions_ocil:questionnaire:1">
          <ocil:title>Prevent non-Privileged Users from Modifying Network Interfaces using nmcli</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-network_nmcli_permissions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-network_sniffer_disabled_ocil:questionnaire:1">
          <ocil:title>Ensure System is Not Acting as a Network Sniffer</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-network_sniffer_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-nfs_no_anonymous_ocil:questionnaire:1">
          <ocil:title>Specify UID and GID for Anonymous NFS Connections</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-nfs_no_anonymous_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_all_squash_exports_ocil:questionnaire:1">
          <ocil:title>Ensure All-Squashing Disabled On All Exports</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_all_squash_exports_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_direct_root_logins_ocil:questionnaire:1">
          <ocil:title>Direct root Logins Not Allowed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_direct_root_logins_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_empty_passwords_ocil:questionnaire:1">
          <ocil:title>Prevent Login to Accounts With Empty Password</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_empty_passwords_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_empty_passwords_etc_shadow_ocil:questionnaire:1">
          <ocil:title>Ensure There Are No Accounts With Blank or Null Passwords</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_empty_passwords_etc_shadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_files_or_dirs_ungroupowned_ocil:questionnaire:1">
          <ocil:title>Ensure All Files And Directories Are Owned by a Group</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_files_or_dirs_ungroupowned_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_files_or_dirs_unowned_by_user_ocil:questionnaire:1">
          <ocil:title>Ensure All Files And Directories Are Owned by a User</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_files_or_dirs_unowned_by_user_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_files_unowned_by_user_ocil:questionnaire:1">
          <ocil:title>Ensure All Files Are Owned by a User</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_files_unowned_by_user_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_forward_files_ocil:questionnaire:1">
          <ocil:title>Verify No .forward Files Exist</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_forward_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_host_based_files_ocil:questionnaire:1">
          <ocil:title>Remove Host-Based Authentication Files</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_host_based_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_insecure_locks_exports_ocil:questionnaire:1">
          <ocil:title>Ensure Insecure File Locking is Not Allowed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_insecure_locks_exports_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_legacy_plus_entries_etc_group_ocil:questionnaire:1">
          <ocil:title>Ensure there are no legacy + NIS entries in /etc/group</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_legacy_plus_entries_etc_group_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_legacy_plus_entries_etc_passwd_ocil:questionnaire:1">
          <ocil:title>Ensure there are no legacy + NIS entries in /etc/passwd</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_legacy_plus_entries_etc_passwd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_legacy_plus_entries_etc_shadow_ocil:questionnaire:1">
          <ocil:title>Ensure there are no legacy + NIS entries in /etc/shadow</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_legacy_plus_entries_etc_shadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_netrc_files_ocil:questionnaire:1">
          <ocil:title>Verify No netrc Files Exist</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_netrc_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_nis_in_nsswitch_ocil:questionnaire:1">
          <ocil:title>Name Service Switch does not use NIS</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_nis_in_nsswitch_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_nologin_in_shells_ocil:questionnaire:1">
          <ocil:title>Ensure nologin Shell is Not Listed in /etc/shells</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_nologin_in_shells_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_password_auth_for_systemaccounts_ocil:questionnaire:1">
          <ocil:title>Ensure that System Accounts Are Locked</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_password_auth_for_systemaccounts_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_rhost_files_ocil:questionnaire:1">
          <ocil:title>Verify No .rhost Files Exist</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_rhost_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_root_webbrowsing_ocil:questionnaire:1">
          <ocil:title>Restrict Web Browser Use for Administrative Accounts</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_root_webbrowsing_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_rsh_trust_files_ocil:questionnaire:1">
          <ocil:title>Remove Rsh Trust Files</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_rsh_trust_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_shelllogin_for_systemaccounts_ocil:questionnaire:1">
          <ocil:title>Ensure that System Accounts Do Not Run a Shell Upon Login</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_shelllogin_for_systemaccounts_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_tmux_in_shells_ocil:questionnaire:1">
          <ocil:title>Prevent user from disabling the screen lock</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_tmux_in_shells_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-no_user_host_based_files_ocil:questionnaire:1">
          <ocil:title>Remove User Host-Based Authentication Files</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-no_user_host_based_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ntpd_specify_remote_server_ocil:questionnaire:1">
          <ocil:title>Specify a Remote NTP Server</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ntpd_specify_remote_server_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-openssl_use_strong_entropy_ocil:questionnaire:1">
          <ocil:title>OpenSSL uses strong entropy source</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-openssl_use_strong_entropy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_389-ds-base_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall 389-ds-base Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_389-ds-base_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_MFEhiplsm_installed_ocil:questionnaire:1">
          <ocil:title>Install the Host Intrusion Prevention System (HIPS) Module</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_MFEhiplsm_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_abrt-addon-ccpp_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall abrt-addon-ccpp Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_abrt-addon-ccpp_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_abrt-addon-kerneloops_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall abrt-addon-kerneloops Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_abrt-addon-kerneloops_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_abrt-cli_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall abrt-cli Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_abrt-cli_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_abrt-plugin-logger_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall abrt-plugin-logger Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_abrt-plugin-logger_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_abrt-plugin-rhtsupport_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall abrt-plugin-rhtsupport Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_abrt-plugin-rhtsupport_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_abrt-plugin-sosreport_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall abrt-plugin-sosreport Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_abrt-plugin-sosreport_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_abrt_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall Automatic Bug Reporting Tool (abrt)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_abrt_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_aide_installed_ocil:questionnaire:1">
          <ocil:title>Install AIDE</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_aide_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_audispd-plugins_installed_ocil:questionnaire:1">
          <ocil:title>Install audispd-plugins Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_audispd-plugins_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_audit-audispd-plugins_installed_ocil:questionnaire:1">
          <ocil:title>Ensure the default plugins for the audit dispatcher are Installed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_audit-audispd-plugins_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_audit-libs_installed_ocil:questionnaire:1">
          <ocil:title>Ensure the audit-libs package as a part of audit Subsystem is Installed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_audit-libs_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_audit_installed_ocil:questionnaire:1">
          <ocil:title>Ensure the audit Subsystem is Installed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_audit_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_authselect_installed_ocil:questionnaire:1">
          <ocil:title>Install authselect Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_authselect_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_avahi-autoipd_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall avahi-autoipd Server Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_avahi-autoipd_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_avahi_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall avahi Server Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_avahi_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_bind_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall bind Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_bind_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_binutils_installed_ocil:questionnaire:1">
          <ocil:title>Install binutils Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_binutils_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1">
          <ocil:title>The Chrony package is installed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_cron_installed_ocil:questionnaire:1">
          <ocil:title>Install the cron service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_cron_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_crypto-policies_installed_ocil:questionnaire:1">
          <ocil:title>Install crypto-policies package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_crypto-policies_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_cups_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall CUPS Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_cups_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_cyrus-imapd_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall cyrus-imapd Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_cyrus-imapd_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_dhcp_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall DHCP Server Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_dhcp_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_dnf-automatic_installed_ocil:questionnaire:1">
          <ocil:title>Install dnf-automatic Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_dnf-automatic_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_dnf-plugin-subscription-manager_installed_ocil:questionnaire:1">
          <ocil:title>Install dnf-plugin-subscription-manager Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_dnf-plugin-subscription-manager_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_dnsmasq_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall dnsmasq Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_dnsmasq_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_dovecot_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall dovecot Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_dovecot_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_fapolicyd_installed_ocil:questionnaire:1">
          <ocil:title>Install fapolicyd Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_fapolicyd_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_firewalld_installed_ocil:questionnaire:1">
          <ocil:title>Install firewalld Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_firewalld_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_freeradius_removed_ocil:questionnaire:1">
          <ocil:title>Remove the FreeRadius Server Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_freeradius_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_ftp_removed_ocil:questionnaire:1">
          <ocil:title>Remove ftp Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_ftp_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_gdm_removed_ocil:questionnaire:1">
          <ocil:title>Remove the GDM Package Group</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_gdm_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_geolite2-city_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall geolite2-city Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_geolite2-city_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_geolite2-country_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall geolite2-country Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_geolite2-country_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_gnutls-utils_installed_ocil:questionnaire:1">
          <ocil:title>Ensure gnutls-utils is installed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_gnutls-utils_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_gssproxy_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall gssproxy Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_gssproxy_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_httpd_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall httpd Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_httpd_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_iprutils_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall iprutils Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_iprutils_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_iptables-services_installed_ocil:questionnaire:1">
          <ocil:title>Install iptables-services Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_iptables-services_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_iptables-services_removed_ocil:questionnaire:1">
          <ocil:title>Remove iptables-services Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_iptables-services_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_iptables_installed_ocil:questionnaire:1">
          <ocil:title>Install iptables Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_iptables_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_krb5-server_removed_ocil:questionnaire:1">
          <ocil:title>Remove the Kerberos Server Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_krb5-server_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_krb5-workstation_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall krb5-workstation Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_krb5-workstation_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_libcap-ng-utils_installed_ocil:questionnaire:1">
          <ocil:title>Install libcap-ng-utils Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_libcap-ng-utils_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_libreport-plugin-logger_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall libreport-plugin-logger Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_libreport-plugin-logger_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_libreport-plugin-rhtsupport_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall libreport-plugin-rhtsupport Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_libreport-plugin-rhtsupport_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_libreswan_installed_ocil:questionnaire:1">
          <ocil:title>Install libreswan Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_libreswan_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_libselinux_installed_ocil:questionnaire:1">
          <ocil:title>Install libselinux Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_libselinux_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_logrotate_installed_ocil:questionnaire:1">
          <ocil:title>Ensure logrotate is Installed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_logrotate_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_mailx_installed_ocil:questionnaire:1">
          <ocil:title>The mailx Package Is Installed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_mailx_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_mcafeetp_installed_ocil:questionnaire:1">
          <ocil:title>Install McAfee Endpoint Security for Linux (ENSL)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_mcafeetp_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_net-snmp_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall net-snmp Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_net-snmp_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_nfs-utils_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall nfs-utils Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_nfs-utils_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_nftables_installed_ocil:questionnaire:1">
          <ocil:title>Install nftables Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_nftables_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_nginx_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall nginx Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_nginx_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_nss-tools_installed_ocil:questionnaire:1">
          <ocil:title>Ensure nss-tools is installed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_nss-tools_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_ntp_installed_ocil:questionnaire:1">
          <ocil:title>Install the ntp service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_ntp_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_openldap-clients_removed_ocil:questionnaire:1">
          <ocil:title>Ensure LDAP client is not installed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_openldap-clients_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_openldap-servers_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall openldap-servers Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_openldap-servers_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_opensc_installed_ocil:questionnaire:1">
          <ocil:title>Install the opensc Package For Multifactor Authentication</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_opensc_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_openscap-scanner_installed_ocil:questionnaire:1">
          <ocil:title>Install openscap-scanner Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_openscap-scanner_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_openssh-clients_installed_ocil:questionnaire:1">
          <ocil:title>Install OpenSSH client software</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_openssh-clients_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_openssh-server_installed_ocil:questionnaire:1">
          <ocil:title>Install the OpenSSH Server Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_openssh-server_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_openssh-server_removed_ocil:questionnaire:1">
          <ocil:title>Remove the OpenSSH Server Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_openssh-server_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_pam_installed_ocil:questionnaire:1">
          <ocil:title>Install pam Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_pam_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_pam_pwquality_installed_ocil:questionnaire:1">
          <ocil:title>Install pam_pwquality Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_pam_pwquality_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_pcsc-lite_installed_ocil:questionnaire:1">
          <ocil:title>Install the pcsc-lite package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_pcsc-lite_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_pigz_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall pigz Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_pigz_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_policycoreutils-python-utils_installed_ocil:questionnaire:1">
          <ocil:title>Install policycoreutils-python-utils package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_policycoreutils-python-utils_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_policycoreutils_installed_ocil:questionnaire:1">
          <ocil:title>Install policycoreutils Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_policycoreutils_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_postfix_installed_ocil:questionnaire:1">
          <ocil:title>The Postfix package is installed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_postfix_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_psacct_installed_ocil:questionnaire:1">
          <ocil:title>Install the psacct package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_psacct_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_python3-abrt-addon_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall python3-abrt-addon Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_python3-abrt-addon_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_quagga_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall quagga Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_quagga_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_rear_installed_ocil:questionnaire:1">
          <ocil:title>Install rear Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_rear_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_rng-tools_installed_ocil:questionnaire:1">
          <ocil:title>Install rng-tools Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_rng-tools_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_rpcbind_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall rpcbind Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_rpcbind_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_rsh-server_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall rsh-server Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_rsh-server_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_rsh_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall rsh Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_rsh_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_rsync_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall rsync Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_rsync_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_rsyslog-gnutls_installed_ocil:questionnaire:1">
          <ocil:title>Ensure rsyslog-gnutls is installed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_rsyslog-gnutls_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_rsyslog_installed_ocil:questionnaire:1">
          <ocil:title>Ensure rsyslog is Installed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_rsyslog_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_samba-common_installed_ocil:questionnaire:1">
          <ocil:title>Install the Samba Common Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_samba-common_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_samba_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall Samba Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_samba_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_scap-security-guide_installed_ocil:questionnaire:1">
          <ocil:title>Install scap-security-guide Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_scap-security-guide_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_sendmail_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall Sendmail Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_sendmail_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_setroubleshoot-plugins_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall setroubleshoot-plugins Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_setroubleshoot-plugins_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_setroubleshoot-server_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall setroubleshoot-server Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_setroubleshoot-server_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_squid_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall squid Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_squid_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_sssd-ipa_installed_ocil:questionnaire:1">
          <ocil:title>Install sssd-ipa Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_sssd-ipa_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_sssd_installed_ocil:questionnaire:1">
          <ocil:title>Install the SSSD Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_sssd_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_subscription-manager_installed_ocil:questionnaire:1">
          <ocil:title>Install subscription-manager Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_subscription-manager_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_sudo_installed_ocil:questionnaire:1">
          <ocil:title>Install sudo Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_sudo_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_syslogng_installed_ocil:questionnaire:1">
          <ocil:title>Ensure syslog-ng is Installed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_syslogng_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_systemd-journal-remote_installed_ocil:questionnaire:1">
          <ocil:title>Install systemd-journal-remote Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_systemd-journal-remote_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_talk-server_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall talk-server Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_talk-server_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_talk_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall talk Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_talk_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_tar_installed_ocil:questionnaire:1">
          <ocil:title>Install tar Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_tar_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_telnet-server_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall telnet-server Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_telnet-server_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_telnet_removed_ocil:questionnaire:1">
          <ocil:title>Remove telnet Clients</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_telnet_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_tftp-server_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall tftp-server Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_tftp-server_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_tftp_removed_ocil:questionnaire:1">
          <ocil:title>Remove tftp Daemon</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_tftp_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_tmux_installed_ocil:questionnaire:1">
          <ocil:title>Install the tmux Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_tmux_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_tuned_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall tuned Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_tuned_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_usbguard_installed_ocil:questionnaire:1">
          <ocil:title>Install usbguard Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_usbguard_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_vim_installed_ocil:questionnaire:1">
          <ocil:title>Install vim Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_vim_installed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_vsftpd_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall vsftpd Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_vsftpd_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_xinetd_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall xinetd package if not used by network services</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_xinetd_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_xorg-x11-server-Xwayland_removed_ocil:questionnaire:1">
          <ocil:title>Remove the X Windows Xwayland Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_xorg-x11-server-Xwayland_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_xorg-x11-server-common_removed_ocil:questionnaire:1">
          <ocil:title>Remove the X Windows Package Group</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_xorg-x11-server-common_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1">
          <ocil:title>Remove NIS Client</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_ypbind_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-package_ypserv_removed_ocil:questionnaire:1">
          <ocil:title>Uninstall ypserv Package</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-package_ypserv_removed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-partition_for_boot_ocil:questionnaire:1">
          <ocil:title>Ensure /boot Located On Separate Partition</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-partition_for_boot_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-partition_for_dev_shm_ocil:questionnaire:1">
          <ocil:title>Ensure /dev/shm is configured</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-partition_for_dev_shm_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-partition_for_home_ocil:questionnaire:1">
          <ocil:title>Ensure /home Located On Separate Partition</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-partition_for_home_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-partition_for_opt_ocil:questionnaire:1">
          <ocil:title>Ensure /opt Located On Separate Partition</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-partition_for_opt_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-partition_for_srv_ocil:questionnaire:1">
          <ocil:title>Ensure /srv Located On Separate Partition</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-partition_for_srv_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-partition_for_tmp_ocil:questionnaire:1">
          <ocil:title>Ensure /tmp Located On Separate Partition</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-partition_for_tmp_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-partition_for_usr_ocil:questionnaire:1">
          <ocil:title>Ensure /usr Located On Separate Partition</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-partition_for_usr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-partition_for_var_ocil:questionnaire:1">
          <ocil:title>Ensure /var Located On Separate Partition</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-partition_for_var_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-partition_for_var_log_ocil:questionnaire:1">
          <ocil:title>Ensure /var/log Located On Separate Partition</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-partition_for_var_log_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-partition_for_var_log_audit_ocil:questionnaire:1">
          <ocil:title>Ensure /var/log/audit Located On Separate Partition</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-partition_for_var_log_audit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-partition_for_var_tmp_ocil:questionnaire:1">
          <ocil:title>Ensure /var/tmp Located On Separate Partition</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-partition_for_var_tmp_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-partition_for_web_content_ocil:questionnaire:1">
          <ocil:title>Ensure Web Content Located on Separate partition</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-partition_for_web_content_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1">
          <ocil:title>Configure System to Forward All Mail For The Root Account</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-postfix_client_configure_mail_alias_postmaster_ocil:questionnaire:1">
          <ocil:title>Configure System to Forward All Mail From Postmaster to The Root Account</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_postmaster_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-postfix_client_configure_relayhost_ocil:questionnaire:1">
          <ocil:title>Configure System to Forward All Mail through a specific host</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-postfix_client_configure_relayhost_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-postfix_network_listening_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Postfix Network Listening</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-postfix_network_listening_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-postfix_prevent_unrestricted_relay_ocil:questionnaire:1">
          <ocil:title>Prevent Unrestricted Mail Relaying</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-postfix_prevent_unrestricted_relay_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-prefer_64bit_os_ocil:questionnaire:1">
          <ocil:title>Prefer to use a 64-bit Operating System when supported</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-prefer_64bit_os_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-require_emergency_target_auth_ocil:questionnaire:1">
          <ocil:title>Require Authentication for Emergency Systemd Target</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-require_emergency_target_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-require_singleuser_auth_ocil:questionnaire:1">
          <ocil:title>Require Authentication for Single User Mode</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-require_singleuser_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-require_smb_client_signing_ocil:questionnaire:1">
          <ocil:title>Require Client SMB Packet Signing, if using smbclient</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-require_smb_client_signing_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-restrict_serial_port_logins_ocil:questionnaire:1">
          <ocil:title>Restrict Serial Port Root Logins</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-restrict_serial_port_logins_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-root_path_default_ocil:questionnaire:1">
          <ocil:title>Root Path Must Be Vendor Default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-root_path_default_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-root_permissions_syslibrary_files_ocil:questionnaire:1">
          <ocil:title>Verify the system-wide library files in directories
"/lib", "/lib64", "/usr/lib/" and "/usr/lib64" are group-owned by root.</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-root_permissions_syslibrary_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rootfiles_configured_ocil:questionnaire:1">
          <ocil:title>Ensure rootfiles tmpfile.d is Configured Correctly</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rootfiles_configured_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rpm_verify_hashes_ocil:questionnaire:1">
          <ocil:title>Verify File Hashes with RPM</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rpm_verify_hashes_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rpm_verify_ownership_ocil:questionnaire:1">
          <ocil:title>Verify and Correct Ownership with RPM</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rpm_verify_ownership_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rpm_verify_permissions_ocil:questionnaire:1">
          <ocil:title>Verify and Correct File Permissions with RPM</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rpm_verify_permissions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rsyslog_cron_logging_ocil:questionnaire:1">
          <ocil:title>Ensure cron Is Logging To Rsyslog</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rsyslog_cron_logging_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_ocil:questionnaire:1">
          <ocil:title>Ensure Rsyslog Authenticates Off-Loaded Audit Records</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_ocil:questionnaire:1">
          <ocil:title>Ensure Rsyslog Encrypts Off-Loaded Audit Records</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_ocil:questionnaire:1">
          <ocil:title>Ensure Rsyslog Encrypts Off-Loaded Audit Records</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rsyslog_filecreatemode_ocil:questionnaire:1">
          <ocil:title>Ensure rsyslog Default File Permissions Configured</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rsyslog_filecreatemode_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rsyslog_files_groupownership_ocil:questionnaire:1">
          <ocil:title>Ensure Log Files Are Owned By Appropriate Group</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rsyslog_files_groupownership_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rsyslog_files_ownership_ocil:questionnaire:1">
          <ocil:title>Ensure Log Files Are Owned By Appropriate User</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rsyslog_files_ownership_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rsyslog_files_permissions_ocil:questionnaire:1">
          <ocil:title>Ensure System Log Files Have Correct Permissions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rsyslog_files_permissions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rsyslog_logging_configured_ocil:questionnaire:1">
          <ocil:title>Ensure logging is configured</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rsyslog_logging_configured_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rsyslog_nolisten_ocil:questionnaire:1">
          <ocil:title>Ensure rsyslog Does Not Accept Remote Messages Unless Acting As Log Server</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rsyslog_nolisten_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rsyslog_remote_access_monitoring_ocil:questionnaire:1">
          <ocil:title>Ensure remote access methods are monitored in Rsyslog</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rsyslog_remote_access_monitoring_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rsyslog_remote_loghost_ocil:questionnaire:1">
          <ocil:title>Ensure Logs Sent To Remote Host</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rsyslog_remote_loghost_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rsyslog_remote_tls_ocil:questionnaire:1">
          <ocil:title>Configure TLS for rsyslog remote logging</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rsyslog_remote_tls_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-rsyslog_remote_tls_cacert_ocil:questionnaire:1">
          <ocil:title>Configure CA certificate for rsyslog remote logging</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-rsyslog_remote_tls_cacert_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_abrt_anon_write_ocil:questionnaire:1">
          <ocil:title>Disable the abrt_anon_write SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_abrt_anon_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_abrt_handle_event_ocil:questionnaire:1">
          <ocil:title>Disable the abrt_handle_event SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_abrt_handle_event_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_abrt_upload_watch_anon_write_ocil:questionnaire:1">
          <ocil:title>Disable the abrt_upload_watch_anon_write SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_abrt_upload_watch_anon_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_antivirus_can_scan_system_ocil:questionnaire:1">
          <ocil:title>Enable the antivirus_can_scan_system SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_antivirus_can_scan_system_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_antivirus_use_jit_ocil:questionnaire:1">
          <ocil:title>Disable the antivirus_use_jit SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_antivirus_use_jit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_auditadm_exec_content_ocil:questionnaire:1">
          <ocil:title>Enable the auditadm_exec_content SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_auditadm_exec_content_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_authlogin_nsswitch_use_ldap_ocil:questionnaire:1">
          <ocil:title>Disable the authlogin_nsswitch_use_ldap SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_authlogin_nsswitch_use_ldap_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_authlogin_radius_ocil:questionnaire:1">
          <ocil:title>Disable the authlogin_radius SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_authlogin_radius_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_authlogin_yubikey_ocil:questionnaire:1">
          <ocil:title>Disable the authlogin_yubikey SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_authlogin_yubikey_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_awstats_purge_apache_log_files_ocil:questionnaire:1">
          <ocil:title>Disable the awstats_purge_apache_log_files SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_awstats_purge_apache_log_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_boinc_execmem_ocil:questionnaire:1">
          <ocil:title>Disable the boinc_execmem SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_boinc_execmem_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_cdrecord_read_content_ocil:questionnaire:1">
          <ocil:title>Disable the cdrecord_read_content SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_cdrecord_read_content_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_cluster_can_network_connect_ocil:questionnaire:1">
          <ocil:title>Disable the cluster_can_network_connect SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_cluster_can_network_connect_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_cluster_manage_all_files_ocil:questionnaire:1">
          <ocil:title>Disable the cluster_manage_all_files SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_cluster_manage_all_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_cluster_use_execmem_ocil:questionnaire:1">
          <ocil:title>Disable the cluster_use_execmem SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_cluster_use_execmem_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_cobbler_anon_write_ocil:questionnaire:1">
          <ocil:title>Disable the cobbler_anon_write SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_cobbler_anon_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_cobbler_can_network_connect_ocil:questionnaire:1">
          <ocil:title>Disable the cobbler_can_network_connect SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_cobbler_can_network_connect_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_cobbler_use_cifs_ocil:questionnaire:1">
          <ocil:title>Disable the cobbler_use_cifs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_cobbler_use_cifs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_cobbler_use_nfs_ocil:questionnaire:1">
          <ocil:title>Disable the cobbler_use_nfs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_cobbler_use_nfs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_collectd_tcp_network_connect_ocil:questionnaire:1">
          <ocil:title>Disable the collectd_tcp_network_connect SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_collectd_tcp_network_connect_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_condor_tcp_network_connect_ocil:questionnaire:1">
          <ocil:title>Disable the condor_tcp_network_connect SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_condor_tcp_network_connect_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_conman_can_network_ocil:questionnaire:1">
          <ocil:title>Disable the conman_can_network SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_conman_can_network_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_container_connect_any_ocil:questionnaire:1">
          <ocil:title>Disable the container_connect_any SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_container_connect_any_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_cron_can_relabel_ocil:questionnaire:1">
          <ocil:title>Disable the cron_can_relabel SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_cron_can_relabel_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_cron_system_cronjob_use_shares_ocil:questionnaire:1">
          <ocil:title>Disable the cron_system_cronjob_use_shares SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_cron_system_cronjob_use_shares_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_cron_userdomain_transition_ocil:questionnaire:1">
          <ocil:title>Enable the cron_userdomain_transition SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_cron_userdomain_transition_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_cups_execmem_ocil:questionnaire:1">
          <ocil:title>Disable the cups_execmem SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_cups_execmem_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_cvs_read_shadow_ocil:questionnaire:1">
          <ocil:title>Disable the cvs_read_shadow SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_cvs_read_shadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_daemons_dump_core_ocil:questionnaire:1">
          <ocil:title>Disable the daemons_dump_core SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_daemons_dump_core_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_daemons_enable_cluster_mode_ocil:questionnaire:1">
          <ocil:title>Disable the daemons_enable_cluster_mode SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_daemons_enable_cluster_mode_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_daemons_use_tcp_wrapper_ocil:questionnaire:1">
          <ocil:title>Disable the daemons_use_tcp_wrapper SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_daemons_use_tcp_wrapper_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_daemons_use_tty_ocil:questionnaire:1">
          <ocil:title>Disable the daemons_use_tty SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_daemons_use_tty_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_dbadm_exec_content_ocil:questionnaire:1">
          <ocil:title>Enable the dbadm_exec_content SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_dbadm_exec_content_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_dbadm_manage_user_files_ocil:questionnaire:1">
          <ocil:title>Disable the dbadm_manage_user_files SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_dbadm_manage_user_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_dbadm_read_user_files_ocil:questionnaire:1">
          <ocil:title>Disable the dbadm_read_user_files SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_dbadm_read_user_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_deny_execmem_ocil:questionnaire:1">
          <ocil:title>Configure the deny_execmem SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_deny_execmem_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_deny_ptrace_ocil:questionnaire:1">
          <ocil:title>Disable the deny_ptrace SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_deny_ptrace_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_dhcpc_exec_iptables_ocil:questionnaire:1">
          <ocil:title>Disable the dhcpc_exec_iptables SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_dhcpc_exec_iptables_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_dhcpd_use_ldap_ocil:questionnaire:1">
          <ocil:title>Disable the dhcpd_use_ldap SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_dhcpd_use_ldap_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_domain_fd_use_ocil:questionnaire:1">
          <ocil:title>Enable the domain_fd_use SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_domain_fd_use_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_domain_kernel_load_modules_ocil:questionnaire:1">
          <ocil:title>Disable the domain_kernel_load_modules SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_domain_kernel_load_modules_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_entropyd_use_audio_ocil:questionnaire:1">
          <ocil:title>Disable the entropyd_use_audio SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_entropyd_use_audio_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_exim_can_connect_db_ocil:questionnaire:1">
          <ocil:title>Disable the exim_can_connect_db SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_exim_can_connect_db_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_exim_manage_user_files_ocil:questionnaire:1">
          <ocil:title>Disable the exim_manage_user_files SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_exim_manage_user_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_exim_read_user_files_ocil:questionnaire:1">
          <ocil:title>Disable the exim_read_user_files SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_exim_read_user_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_fcron_crond_ocil:questionnaire:1">
          <ocil:title>Disable the fcron_crond SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_fcron_crond_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_fenced_can_network_connect_ocil:questionnaire:1">
          <ocil:title>Disable the fenced_can_network_connect SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_fenced_can_network_connect_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_fenced_can_ssh_ocil:questionnaire:1">
          <ocil:title>Disable the fenced_can_ssh SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_fenced_can_ssh_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_fips_mode_ocil:questionnaire:1">
          <ocil:title>Enable the fips_mode SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_fips_mode_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_ftpd_anon_write_ocil:questionnaire:1">
          <ocil:title>Disable the ftpd_anon_write SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_ftpd_anon_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_ftpd_connect_all_unreserved_ocil:questionnaire:1">
          <ocil:title>Disable the ftpd_connect_all_unreserved SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_ftpd_connect_all_unreserved_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_ftpd_connect_db_ocil:questionnaire:1">
          <ocil:title>Disable the ftpd_connect_db SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_ftpd_connect_db_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_ftpd_full_access_ocil:questionnaire:1">
          <ocil:title>Disable the ftpd_full_access SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_ftpd_full_access_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_ftpd_use_cifs_ocil:questionnaire:1">
          <ocil:title>Disable the ftpd_use_cifs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_ftpd_use_cifs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_ftpd_use_fusefs_ocil:questionnaire:1">
          <ocil:title>Disable the ftpd_use_fusefs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_ftpd_use_fusefs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_ftpd_use_nfs_ocil:questionnaire:1">
          <ocil:title>Disable the ftpd_use_nfs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_ftpd_use_nfs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_ftpd_use_passive_mode_ocil:questionnaire:1">
          <ocil:title>Disable the ftpd_use_passive_mode SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_ftpd_use_passive_mode_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_git_cgi_enable_homedirs_ocil:questionnaire:1">
          <ocil:title>Disable the git_cgi_enable_homedirs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_git_cgi_enable_homedirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_git_cgi_use_cifs_ocil:questionnaire:1">
          <ocil:title>Disable the git_cgi_use_cifs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_git_cgi_use_cifs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_git_cgi_use_nfs_ocil:questionnaire:1">
          <ocil:title>Disable the git_cgi_use_nfs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_git_cgi_use_nfs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_git_session_bind_all_unreserved_ports_ocil:questionnaire:1">
          <ocil:title>Disable the git_session_bind_all_unreserved_ports SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_git_session_bind_all_unreserved_ports_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_git_session_users_ocil:questionnaire:1">
          <ocil:title>Disable the git_session_users SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_git_session_users_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_git_system_enable_homedirs_ocil:questionnaire:1">
          <ocil:title>Disable the git_system_enable_homedirs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_git_system_enable_homedirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_git_system_use_cifs_ocil:questionnaire:1">
          <ocil:title>Disable the git_system_use_cifs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_git_system_use_cifs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_git_system_use_nfs_ocil:questionnaire:1">
          <ocil:title>Disable the git_system_use_nfs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_git_system_use_nfs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_gitosis_can_sendmail_ocil:questionnaire:1">
          <ocil:title>Disable the gitosis_can_sendmail SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_gitosis_can_sendmail_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_glance_api_can_network_ocil:questionnaire:1">
          <ocil:title>Disable the glance_api_can_network SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_glance_api_can_network_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_glance_use_execmem_ocil:questionnaire:1">
          <ocil:title>Disable the glance_use_execmem SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_glance_use_execmem_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_glance_use_fusefs_ocil:questionnaire:1">
          <ocil:title>Disable the glance_use_fusefs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_glance_use_fusefs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_global_ssp_ocil:questionnaire:1">
          <ocil:title>Disable the global_ssp SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_global_ssp_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_gluster_anon_write_ocil:questionnaire:1">
          <ocil:title>Disable the gluster_anon_write SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_gluster_anon_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_gluster_export_all_ro_ocil:questionnaire:1">
          <ocil:title>Disable the gluster_export_all_ro SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_gluster_export_all_ro_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_gluster_export_all_rw_ocil:questionnaire:1">
          <ocil:title>Configure the gluster_export_all_rw SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_gluster_export_all_rw_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_gpg_web_anon_write_ocil:questionnaire:1">
          <ocil:title>Disable the gpg_web_anon_write SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_gpg_web_anon_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_gssd_read_tmp_ocil:questionnaire:1">
          <ocil:title>Enable the gssd_read_tmp SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_gssd_read_tmp_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_guest_exec_content_ocil:questionnaire:1">
          <ocil:title>Disable the guest_exec_content SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_guest_exec_content_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_haproxy_connect_any_ocil:questionnaire:1">
          <ocil:title>Disable the haproxy_connect_any SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_haproxy_connect_any_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_anon_write_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_anon_write SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_anon_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_builtin_scripting_ocil:questionnaire:1">
          <ocil:title>Configure the httpd_builtin_scripting SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_builtin_scripting_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_can_check_spam_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_can_check_spam SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_can_check_spam_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_can_connect_ftp_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_can_connect_ftp SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_can_connect_ftp_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_can_connect_ldap_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_can_connect_ldap SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_can_connect_ldap_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_can_connect_mythtv_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_can_connect_mythtv SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_can_connect_mythtv_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_can_connect_zabbix_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_can_connect_zabbix SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_can_connect_zabbix_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_can_network_connect_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_can_network_connect SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_can_network_connect_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_can_network_connect_cobbler_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_can_network_connect_cobbler SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_can_network_connect_cobbler_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_can_network_connect_db_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_can_network_connect_db SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_can_network_connect_db_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_can_network_memcache_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_can_network_memcache SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_can_network_memcache_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_can_network_relay_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_can_network_relay SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_can_network_relay_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_can_sendmail_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_can_sendmail SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_can_sendmail_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_dbus_avahi_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_dbus_avahi SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_dbus_avahi_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_dbus_sssd_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_dbus_sssd SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_dbus_sssd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_dontaudit_search_dirs_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_dontaudit_search_dirs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_dontaudit_search_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_enable_cgi_ocil:questionnaire:1">
          <ocil:title>Configure the httpd_enable_cgi SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_enable_cgi_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_enable_ftp_server_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_enable_ftp_server SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_enable_ftp_server_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_enable_homedirs_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_enable_homedirs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_enable_homedirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_execmem_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_execmem SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_execmem_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_graceful_shutdown_ocil:questionnaire:1">
          <ocil:title>Enable the httpd_graceful_shutdown SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_graceful_shutdown_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_manage_ipa_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_manage_ipa SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_manage_ipa_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_mod_auth_ntlm_winbind_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_mod_auth_ntlm_winbind SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_mod_auth_ntlm_winbind_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_mod_auth_pam_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_mod_auth_pam SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_mod_auth_pam_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_read_user_content_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_read_user_content SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_read_user_content_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_run_ipa_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_run_ipa SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_run_ipa_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_run_preupgrade_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_run_preupgrade SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_run_preupgrade_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_run_stickshift_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_run_stickshift SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_run_stickshift_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_serve_cobbler_files_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_serve_cobbler_files SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_serve_cobbler_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_setrlimit_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_setrlimit SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_setrlimit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_ssi_exec_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_ssi_exec SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_ssi_exec_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_sys_script_anon_write_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_sys_script_anon_write SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_sys_script_anon_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_tmp_exec_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_tmp_exec SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_tmp_exec_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_tty_comm_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_tty_comm SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_tty_comm_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_unified_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_unified SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_unified_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_use_cifs_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_use_cifs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_use_cifs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_use_fusefs_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_use_fusefs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_use_fusefs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_use_gpg_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_use_gpg SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_use_gpg_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_use_nfs_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_use_nfs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_use_nfs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_use_openstack_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_use_openstack SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_use_openstack_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_use_sasl_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_use_sasl SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_use_sasl_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_httpd_verify_dns_ocil:questionnaire:1">
          <ocil:title>Disable the httpd_verify_dns SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_httpd_verify_dns_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_icecast_use_any_tcp_ports_ocil:questionnaire:1">
          <ocil:title>Disable the icecast_use_any_tcp_ports SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_icecast_use_any_tcp_ports_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_irc_use_any_tcp_ports_ocil:questionnaire:1">
          <ocil:title>Disable the irc_use_any_tcp_ports SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_irc_use_any_tcp_ports_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_irssi_use_full_network_ocil:questionnaire:1">
          <ocil:title>Disable the irssi_use_full_network SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_irssi_use_full_network_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_kdumpgui_run_bootloader_ocil:questionnaire:1">
          <ocil:title>Disable the kdumpgui_run_bootloader SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_kdumpgui_run_bootloader_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_kerberos_enabled_ocil:questionnaire:1">
          <ocil:title>Enable the kerberos_enabled SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_kerberos_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_ksmtuned_use_cifs_ocil:questionnaire:1">
          <ocil:title>Disable the ksmtuned_use_cifs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_ksmtuned_use_cifs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_ksmtuned_use_nfs_ocil:questionnaire:1">
          <ocil:title>Disable the ksmtuned_use_nfs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_ksmtuned_use_nfs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_logadm_exec_content_ocil:questionnaire:1">
          <ocil:title>Enable the logadm_exec_content SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_logadm_exec_content_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_logging_syslogd_can_sendmail_ocil:questionnaire:1">
          <ocil:title>Disable the logging_syslogd_can_sendmail SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_logging_syslogd_can_sendmail_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_logging_syslogd_run_nagios_plugins_ocil:questionnaire:1">
          <ocil:title>Disable the logging_syslogd_run_nagios_plugins SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_logging_syslogd_run_nagios_plugins_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_logging_syslogd_use_tty_ocil:questionnaire:1">
          <ocil:title>Enable the logging_syslogd_use_tty SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_logging_syslogd_use_tty_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_login_console_enabled_ocil:questionnaire:1">
          <ocil:title>Enable the login_console_enabled SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_login_console_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_logrotate_use_nfs_ocil:questionnaire:1">
          <ocil:title>Disable the logrotate_use_nfs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_logrotate_use_nfs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_logwatch_can_network_connect_mail_ocil:questionnaire:1">
          <ocil:title>Disable the logwatch_can_network_connect_mail SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_logwatch_can_network_connect_mail_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_lsmd_plugin_connect_any_ocil:questionnaire:1">
          <ocil:title>Disable the lsmd_plugin_connect_any SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_lsmd_plugin_connect_any_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mailman_use_fusefs_ocil:questionnaire:1">
          <ocil:title>Disable the mailman_use_fusefs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mailman_use_fusefs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mcelog_client_ocil:questionnaire:1">
          <ocil:title>Disable the mcelog_client SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mcelog_client_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mcelog_exec_scripts_ocil:questionnaire:1">
          <ocil:title>Enable the mcelog_exec_scripts SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mcelog_exec_scripts_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mcelog_foreground_ocil:questionnaire:1">
          <ocil:title>Disable the mcelog_foreground SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mcelog_foreground_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mcelog_server_ocil:questionnaire:1">
          <ocil:title>Disable the mcelog_server SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mcelog_server_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_minidlna_read_generic_user_content_ocil:questionnaire:1">
          <ocil:title>Disable the minidlna_read_generic_user_content SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_minidlna_read_generic_user_content_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mmap_low_allowed_ocil:questionnaire:1">
          <ocil:title>Disable the mmap_low_allowed SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mmap_low_allowed_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mock_enable_homedirs_ocil:questionnaire:1">
          <ocil:title>Disable the mock_enable_homedirs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mock_enable_homedirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mount_anyfile_ocil:questionnaire:1">
          <ocil:title>Enable the mount_anyfile SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mount_anyfile_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mozilla_plugin_bind_unreserved_ports_ocil:questionnaire:1">
          <ocil:title>Disable the mozilla_plugin_bind_unreserved_ports SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mozilla_plugin_bind_unreserved_ports_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mozilla_plugin_can_network_connect_ocil:questionnaire:1">
          <ocil:title>Disable the mozilla_plugin_can_network_connect SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mozilla_plugin_can_network_connect_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mozilla_plugin_use_bluejeans_ocil:questionnaire:1">
          <ocil:title>Disable the mozilla_plugin_use_bluejeans SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mozilla_plugin_use_bluejeans_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mozilla_plugin_use_gps_ocil:questionnaire:1">
          <ocil:title>Disable the mozilla_plugin_use_gps SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mozilla_plugin_use_gps_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mozilla_plugin_use_spice_ocil:questionnaire:1">
          <ocil:title>Disable the mozilla_plugin_use_spice SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mozilla_plugin_use_spice_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mozilla_read_content_ocil:questionnaire:1">
          <ocil:title>Disable the mozilla_read_content SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mozilla_read_content_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mpd_enable_homedirs_ocil:questionnaire:1">
          <ocil:title>Disable the mpd_enable_homedirs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mpd_enable_homedirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mpd_use_cifs_ocil:questionnaire:1">
          <ocil:title>Disable the mpd_use_cifs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mpd_use_cifs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mpd_use_nfs_ocil:questionnaire:1">
          <ocil:title>Disable the mpd_use_nfs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mpd_use_nfs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mplayer_execstack_ocil:questionnaire:1">
          <ocil:title>Disable the mplayer_execstack SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mplayer_execstack_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_mysql_connect_any_ocil:questionnaire:1">
          <ocil:title>Disable the mysql_connect_any SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_mysql_connect_any_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_nagios_run_pnp4nagios_ocil:questionnaire:1">
          <ocil:title>Disable the nagios_run_pnp4nagios SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_nagios_run_pnp4nagios_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_nagios_run_sudo_ocil:questionnaire:1">
          <ocil:title>Disable the nagios_run_sudo SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_nagios_run_sudo_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_named_tcp_bind_http_port_ocil:questionnaire:1">
          <ocil:title>Disable the named_tcp_bind_http_port SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_named_tcp_bind_http_port_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_named_write_master_zones_ocil:questionnaire:1">
          <ocil:title>Disable the named_write_master_zones SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_named_write_master_zones_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_neutron_can_network_ocil:questionnaire:1">
          <ocil:title>Disable the neutron_can_network SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_neutron_can_network_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_nfs_export_all_ro_ocil:questionnaire:1">
          <ocil:title>Enable the nfs_export_all_ro SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_nfs_export_all_ro_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_nfs_export_all_rw_ocil:questionnaire:1">
          <ocil:title>Enable the nfs_export_all_rw SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_nfs_export_all_rw_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_nfsd_anon_write_ocil:questionnaire:1">
          <ocil:title>Disable the nfsd_anon_write SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_nfsd_anon_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_nis_enabled_ocil:questionnaire:1">
          <ocil:title>Disable the nis_enabled SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_nis_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_nscd_use_shm_ocil:questionnaire:1">
          <ocil:title>Enable the nscd_use_shm SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_nscd_use_shm_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_openshift_use_nfs_ocil:questionnaire:1">
          <ocil:title>Disable the openshift_use_nfs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_openshift_use_nfs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_openvpn_can_network_connect_ocil:questionnaire:1">
          <ocil:title>Disable the openvpn_can_network_connect SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_openvpn_can_network_connect_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_openvpn_enable_homedirs_ocil:questionnaire:1">
          <ocil:title>Disable the openvpn_enable_homedirs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_openvpn_enable_homedirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_openvpn_run_unconfined_ocil:questionnaire:1">
          <ocil:title>Disable the openvpn_run_unconfined SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_openvpn_run_unconfined_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_pcp_bind_all_unreserved_ports_ocil:questionnaire:1">
          <ocil:title>Disable the pcp_bind_all_unreserved_ports SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_pcp_bind_all_unreserved_ports_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_pcp_read_generic_logs_ocil:questionnaire:1">
          <ocil:title>Disable the pcp_read_generic_logs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_pcp_read_generic_logs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_piranha_lvs_can_network_connect_ocil:questionnaire:1">
          <ocil:title>Disable the piranha_lvs_can_network_connect SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_piranha_lvs_can_network_connect_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_polipo_connect_all_unreserved_ocil:questionnaire:1">
          <ocil:title>Disable the polipo_connect_all_unreserved SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_polipo_connect_all_unreserved_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_polipo_session_bind_all_unreserved_ports_ocil:questionnaire:1">
          <ocil:title>Disable the polipo_session_bind_all_unreserved_ports SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_polipo_session_bind_all_unreserved_ports_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_polipo_session_users_ocil:questionnaire:1">
          <ocil:title>Disable the polipo_session_users SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_polipo_session_users_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_polipo_use_cifs_ocil:questionnaire:1">
          <ocil:title>Disable the polipo_use_cifs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_polipo_use_cifs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_polipo_use_nfs_ocil:questionnaire:1">
          <ocil:title>Disable the polipo_use_nfs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_polipo_use_nfs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_polyinstantiation_enabled_ocil:questionnaire:1">
          <ocil:title>Configure the polyinstantiation_enabled SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_polyinstantiation_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_postfix_local_write_mail_spool_ocil:questionnaire:1">
          <ocil:title>Enable the postfix_local_write_mail_spool SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_postfix_local_write_mail_spool_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_postgresql_can_rsync_ocil:questionnaire:1">
          <ocil:title>Disable the postgresql_can_rsync SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_postgresql_can_rsync_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_postgresql_selinux_transmit_client_label_ocil:questionnaire:1">
          <ocil:title>Disable the postgresql_selinux_transmit_client_label SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_postgresql_selinux_transmit_client_label_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_postgresql_selinux_unconfined_dbadm_ocil:questionnaire:1">
          <ocil:title>Enable the postgresql_selinux_unconfined_dbadm SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_postgresql_selinux_unconfined_dbadm_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_postgresql_selinux_users_ddl_ocil:questionnaire:1">
          <ocil:title>Enable the postgresql_selinux_users_ddl SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_postgresql_selinux_users_ddl_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_pppd_can_insmod_ocil:questionnaire:1">
          <ocil:title>Disable the pppd_can_insmod SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_pppd_can_insmod_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_pppd_for_user_ocil:questionnaire:1">
          <ocil:title>Disable the pppd_for_user SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_pppd_for_user_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_privoxy_connect_any_ocil:questionnaire:1">
          <ocil:title>Disable the privoxy_connect_any SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_privoxy_connect_any_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_prosody_bind_http_port_ocil:questionnaire:1">
          <ocil:title>Disable the prosody_bind_http_port SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_prosody_bind_http_port_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_puppetagent_manage_all_files_ocil:questionnaire:1">
          <ocil:title>Disable the puppetagent_manage_all_files SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_puppetagent_manage_all_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_puppetmaster_use_db_ocil:questionnaire:1">
          <ocil:title>Disable the puppetmaster_use_db SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_puppetmaster_use_db_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_racoon_read_shadow_ocil:questionnaire:1">
          <ocil:title>Disable the racoon_read_shadow SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_racoon_read_shadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_rsync_anon_write_ocil:questionnaire:1">
          <ocil:title>Disable the rsync_anon_write SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_rsync_anon_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_rsync_client_ocil:questionnaire:1">
          <ocil:title>Disable the rsync_client SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_rsync_client_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_rsync_export_all_ro_ocil:questionnaire:1">
          <ocil:title>Disable the rsync_export_all_ro SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_rsync_export_all_ro_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_rsync_full_access_ocil:questionnaire:1">
          <ocil:title>Disable the rsync_full_access SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_rsync_full_access_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_samba_create_home_dirs_ocil:questionnaire:1">
          <ocil:title>Disable the samba_create_home_dirs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_samba_create_home_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_samba_domain_controller_ocil:questionnaire:1">
          <ocil:title>Disable the samba_domain_controller SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_samba_domain_controller_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_samba_enable_home_dirs_ocil:questionnaire:1">
          <ocil:title>Disable the samba_enable_home_dirs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_samba_enable_home_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_samba_export_all_ro_ocil:questionnaire:1">
          <ocil:title>Disable the samba_export_all_ro SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_samba_export_all_ro_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_samba_export_all_rw_ocil:questionnaire:1">
          <ocil:title>Disable the samba_export_all_rw SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_samba_export_all_rw_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_samba_load_libgfapi_ocil:questionnaire:1">
          <ocil:title>Disable the samba_load_libgfapi SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_samba_load_libgfapi_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_samba_portmapper_ocil:questionnaire:1">
          <ocil:title>Disable the samba_portmapper SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_samba_portmapper_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_samba_run_unconfined_ocil:questionnaire:1">
          <ocil:title>Disable the samba_run_unconfined SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_samba_run_unconfined_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_samba_share_fusefs_ocil:questionnaire:1">
          <ocil:title>Disable the samba_share_fusefs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_samba_share_fusefs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_samba_share_nfs_ocil:questionnaire:1">
          <ocil:title>Disable the samba_share_nfs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_samba_share_nfs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_sanlock_use_fusefs_ocil:questionnaire:1">
          <ocil:title>Disable the sanlock_use_fusefs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_sanlock_use_fusefs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_sanlock_use_nfs_ocil:questionnaire:1">
          <ocil:title>Disable the sanlock_use_nfs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_sanlock_use_nfs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_sanlock_use_samba_ocil:questionnaire:1">
          <ocil:title>Disable the sanlock_use_samba SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_sanlock_use_samba_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_saslauthd_read_shadow_ocil:questionnaire:1">
          <ocil:title>Disable the saslauthd_read_shadow SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_saslauthd_read_shadow_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_secadm_exec_content_ocil:questionnaire:1">
          <ocil:title>Enable the secadm_exec_content SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_secadm_exec_content_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_secure_mode_ocil:questionnaire:1">
          <ocil:title>Disable the secure_mode SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_secure_mode_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_secure_mode_insmod_ocil:questionnaire:1">
          <ocil:title>Configure the secure_mode_insmod SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_secure_mode_insmod_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_secure_mode_policyload_ocil:questionnaire:1">
          <ocil:title>Disable the secure_mode_policyload SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_secure_mode_policyload_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_selinuxuser_direct_dri_enabled_ocil:questionnaire:1">
          <ocil:title>Configure the selinuxuser_direct_dri_enabled SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_direct_dri_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_selinuxuser_execheap_ocil:questionnaire:1">
          <ocil:title>Disable the selinuxuser_execheap SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_execheap_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_selinuxuser_execmod_ocil:questionnaire:1">
          <ocil:title>Enable the selinuxuser_execmod SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_execmod_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_selinuxuser_execstack_ocil:questionnaire:1">
          <ocil:title>Disable the selinuxuser_execstack SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_execstack_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_selinuxuser_mysql_connect_enabled_ocil:questionnaire:1">
          <ocil:title>Disable the selinuxuser_mysql_connect_enabled SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_mysql_connect_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_selinuxuser_ping_ocil:questionnaire:1">
          <ocil:title>Enable the selinuxuser_ping SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_ping_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_selinuxuser_postgresql_connect_enabled_ocil:questionnaire:1">
          <ocil:title>Disable the selinuxuser_postgresql_connect_enabled SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_postgresql_connect_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_selinuxuser_rw_noexattrfile_ocil:questionnaire:1">
          <ocil:title>Disable the selinuxuser_rw_noexattrfile SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_rw_noexattrfile_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_selinuxuser_share_music_ocil:questionnaire:1">
          <ocil:title>Disable the selinuxuser_share_music SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_share_music_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_selinuxuser_tcp_server_ocil:questionnaire:1">
          <ocil:title>Disable the selinuxuser_tcp_server SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_tcp_server_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_selinuxuser_udp_server_ocil:questionnaire:1">
          <ocil:title>Disable the selinuxuser_udp_server SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_udp_server_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_selinuxuser_use_ssh_chroot_ocil:questionnaire:1">
          <ocil:title>Disable the selinuxuser_use_ssh_chroot SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_selinuxuser_use_ssh_chroot_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_sge_domain_can_network_connect_ocil:questionnaire:1">
          <ocil:title>Disable the sge_domain_can_network_connect SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_sge_domain_can_network_connect_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_sge_use_nfs_ocil:questionnaire:1">
          <ocil:title>Disable the sge_use_nfs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_sge_use_nfs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_smartmon_3ware_ocil:questionnaire:1">
          <ocil:title>Disable the smartmon_3ware SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_smartmon_3ware_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_smbd_anon_write_ocil:questionnaire:1">
          <ocil:title>Disable the smbd_anon_write SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_smbd_anon_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_spamassassin_can_network_ocil:questionnaire:1">
          <ocil:title>Disable the spamassassin_can_network SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_spamassassin_can_network_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_spamd_enable_home_dirs_ocil:questionnaire:1">
          <ocil:title>Enable the spamd_enable_home_dirs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_spamd_enable_home_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_squid_connect_any_ocil:questionnaire:1">
          <ocil:title>Disable the squid_connect_any SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_squid_connect_any_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_squid_use_tproxy_ocil:questionnaire:1">
          <ocil:title>Disable the squid_use_tproxy SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_squid_use_tproxy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_ssh_chroot_rw_homedirs_ocil:questionnaire:1">
          <ocil:title>Disable the ssh_chroot_rw_homedirs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_ssh_chroot_rw_homedirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_ssh_keysign_ocil:questionnaire:1">
          <ocil:title>Disable the ssh_keysign SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_ssh_keysign_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_ssh_sysadm_login_ocil:questionnaire:1">
          <ocil:title>Disable the ssh_sysadm_login SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_ssh_sysadm_login_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_staff_exec_content_ocil:questionnaire:1">
          <ocil:title>Enable the staff_exec_content SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_staff_exec_content_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_staff_use_svirt_ocil:questionnaire:1">
          <ocil:title>Disable the staff_use_svirt SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_staff_use_svirt_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_swift_can_network_ocil:questionnaire:1">
          <ocil:title>Disable the swift_can_network SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_swift_can_network_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_sysadm_exec_content_ocil:questionnaire:1">
          <ocil:title>Enable the sysadm_exec_content SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_sysadm_exec_content_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_telepathy_connect_all_ports_ocil:questionnaire:1">
          <ocil:title>Disable the telepathy_connect_all_ports SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_telepathy_connect_all_ports_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_telepathy_tcp_connect_generic_network_ports_ocil:questionnaire:1">
          <ocil:title>Disable the telepathy_tcp_connect_generic_network_ports SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_telepathy_tcp_connect_generic_network_ports_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_tftp_anon_write_ocil:questionnaire:1">
          <ocil:title>Disable the tftp_anon_write SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_tftp_anon_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_tftp_home_dir_ocil:questionnaire:1">
          <ocil:title>Disable the tftp_home_dir SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_tftp_home_dir_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_tmpreaper_use_nfs_ocil:questionnaire:1">
          <ocil:title>Disable the tmpreaper_use_nfs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_tmpreaper_use_nfs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_tmpreaper_use_samba_ocil:questionnaire:1">
          <ocil:title>Disable the tmpreaper_use_samba SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_tmpreaper_use_samba_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_tor_bind_all_unreserved_ports_ocil:questionnaire:1">
          <ocil:title>Disable the tor_bind_all_unreserved_ports SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_tor_bind_all_unreserved_ports_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_tor_can_network_relay_ocil:questionnaire:1">
          <ocil:title>Disable the tor_can_network_relay SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_tor_can_network_relay_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_unconfined_chrome_sandbox_transition_ocil:questionnaire:1">
          <ocil:title>Enable the unconfined_chrome_sandbox_transition SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_unconfined_chrome_sandbox_transition_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_unconfined_login_ocil:questionnaire:1">
          <ocil:title>Enable the unconfined_login SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_unconfined_login_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_unconfined_mozilla_plugin_transition_ocil:questionnaire:1">
          <ocil:title>Enable the unconfined_mozilla_plugin_transition SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_unconfined_mozilla_plugin_transition_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_unprivuser_use_svirt_ocil:questionnaire:1">
          <ocil:title>Disable the unprivuser_use_svirt SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_unprivuser_use_svirt_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_use_ecryptfs_home_dirs_ocil:questionnaire:1">
          <ocil:title>Disable the use_ecryptfs_home_dirs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_use_ecryptfs_home_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_use_fusefs_home_dirs_ocil:questionnaire:1">
          <ocil:title>Disable the use_fusefs_home_dirs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_use_fusefs_home_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_use_lpd_server_ocil:questionnaire:1">
          <ocil:title>Disable the use_lpd_server SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_use_lpd_server_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_use_nfs_home_dirs_ocil:questionnaire:1">
          <ocil:title>Disable the use_nfs_home_dirs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_use_nfs_home_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_use_samba_home_dirs_ocil:questionnaire:1">
          <ocil:title>Disable the use_samba_home_dirs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_use_samba_home_dirs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_user_exec_content_ocil:questionnaire:1">
          <ocil:title>Enable the user_exec_content SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_user_exec_content_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_varnishd_connect_any_ocil:questionnaire:1">
          <ocil:title>Disable the varnishd_connect_any SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_varnishd_connect_any_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_virt_read_qemu_ga_data_ocil:questionnaire:1">
          <ocil:title>Disable the virt_read_qemu_ga_data SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_virt_read_qemu_ga_data_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_virt_rw_qemu_ga_data_ocil:questionnaire:1">
          <ocil:title>Disable the virt_rw_qemu_ga_data SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_virt_rw_qemu_ga_data_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_virt_sandbox_use_all_caps_ocil:questionnaire:1">
          <ocil:title>Disable the virt_sandbox_use_all_caps SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_virt_sandbox_use_all_caps_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_virt_sandbox_use_audit_ocil:questionnaire:1">
          <ocil:title>Enable the virt_sandbox_use_audit SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_virt_sandbox_use_audit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_virt_sandbox_use_mknod_ocil:questionnaire:1">
          <ocil:title>Disable the virt_sandbox_use_mknod SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_virt_sandbox_use_mknod_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_virt_sandbox_use_netlink_ocil:questionnaire:1">
          <ocil:title>Disable the virt_sandbox_use_netlink SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_virt_sandbox_use_netlink_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_virt_sandbox_use_sys_admin_ocil:questionnaire:1">
          <ocil:title>Disable the virt_sandbox_use_sys_admin SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_virt_sandbox_use_sys_admin_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_virt_transition_userdomain_ocil:questionnaire:1">
          <ocil:title>Disable the virt_transition_userdomain SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_virt_transition_userdomain_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_virt_use_comm_ocil:questionnaire:1">
          <ocil:title>Disable the virt_use_comm SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_virt_use_comm_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_virt_use_execmem_ocil:questionnaire:1">
          <ocil:title>Disable the virt_use_execmem SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_virt_use_execmem_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_virt_use_fusefs_ocil:questionnaire:1">
          <ocil:title>Disable the virt_use_fusefs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_virt_use_fusefs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_virt_use_nfs_ocil:questionnaire:1">
          <ocil:title>Disable the virt_use_nfs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_virt_use_nfs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_virt_use_rawip_ocil:questionnaire:1">
          <ocil:title>Disable the virt_use_rawip SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_virt_use_rawip_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_virt_use_samba_ocil:questionnaire:1">
          <ocil:title>Disable the virt_use_samba SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_virt_use_samba_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_virt_use_sanlock_ocil:questionnaire:1">
          <ocil:title>Disable the virt_use_sanlock SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_virt_use_sanlock_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_virt_use_usb_ocil:questionnaire:1">
          <ocil:title>Disable the virt_use_usb SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_virt_use_usb_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_virt_use_xserver_ocil:questionnaire:1">
          <ocil:title>Disable the virt_use_xserver SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_virt_use_xserver_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_webadm_manage_user_files_ocil:questionnaire:1">
          <ocil:title>Disable the webadm_manage_user_files SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_webadm_manage_user_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_webadm_read_user_files_ocil:questionnaire:1">
          <ocil:title>Disable the webadm_read_user_files SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_webadm_read_user_files_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_wine_mmap_zero_ignore_ocil:questionnaire:1">
          <ocil:title>Disable the wine_mmap_zero_ignore SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_wine_mmap_zero_ignore_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_xdm_bind_vnc_tcp_port_ocil:questionnaire:1">
          <ocil:title>Disable the xdm_bind_vnc_tcp_port SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_xdm_bind_vnc_tcp_port_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_xdm_exec_bootloader_ocil:questionnaire:1">
          <ocil:title>Disable the xdm_exec_bootloader SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_xdm_exec_bootloader_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_xdm_sysadm_login_ocil:questionnaire:1">
          <ocil:title>Disable the xdm_sysadm_login SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_xdm_sysadm_login_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_xdm_write_home_ocil:questionnaire:1">
          <ocil:title>Disable the xdm_write_home SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_xdm_write_home_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_xen_use_nfs_ocil:questionnaire:1">
          <ocil:title>Disable the xen_use_nfs SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_xen_use_nfs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_xend_run_blktap_ocil:questionnaire:1">
          <ocil:title>Enable the xend_run_blktap SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_xend_run_blktap_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_xend_run_qemu_ocil:questionnaire:1">
          <ocil:title>Enable the xend_run_qemu SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_xend_run_qemu_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_xguest_connect_network_ocil:questionnaire:1">
          <ocil:title>Disable the xguest_connect_network SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_xguest_connect_network_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_xguest_exec_content_ocil:questionnaire:1">
          <ocil:title>Disable the xguest_exec_content SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_xguest_exec_content_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_xguest_mount_media_ocil:questionnaire:1">
          <ocil:title>Disable the xguest_mount_media SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_xguest_mount_media_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_xguest_use_bluetooth_ocil:questionnaire:1">
          <ocil:title>Disable the xguest_use_bluetooth SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_xguest_use_bluetooth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_xserver_clients_write_xshm_ocil:questionnaire:1">
          <ocil:title>Disable the xserver_clients_write_xshm SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_xserver_clients_write_xshm_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_xserver_execmem_ocil:questionnaire:1">
          <ocil:title>Disable the xserver_execmem SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_xserver_execmem_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_xserver_object_manager_ocil:questionnaire:1">
          <ocil:title>Disable the xserver_object_manager SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_xserver_object_manager_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_zabbix_can_network_ocil:questionnaire:1">
          <ocil:title>Disable the zabbix_can_network SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_zabbix_can_network_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_zarafa_setrlimit_ocil:questionnaire:1">
          <ocil:title>Disable the zarafa_setrlimit SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_zarafa_setrlimit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_zebra_write_config_ocil:questionnaire:1">
          <ocil:title>Disable the zebra_write_config SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_zebra_write_config_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_zoneminder_anon_write_ocil:questionnaire:1">
          <ocil:title>Disable the zoneminder_anon_write SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_zoneminder_anon_write_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sebool_zoneminder_run_sudo_ocil:questionnaire:1">
          <ocil:title>Disable the zoneminder_run_sudo SELinux Boolean</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sebool_zoneminder_run_sudo_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-securetty_root_login_console_only_ocil:questionnaire:1">
          <ocil:title>Restrict Virtual Console Root Logins</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-securetty_root_login_console_only_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-security_patches_up_to_date_ocil:questionnaire:1">
          <ocil:title>Ensure Software Patches Installed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-security_patches_up_to_date_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-selinux_all_devicefiles_labeled_ocil:questionnaire:1">
          <ocil:title>Ensure No Device Files are Unlabeled by SELinux</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-selinux_all_devicefiles_labeled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-selinux_confinement_of_daemons_ocil:questionnaire:1">
          <ocil:title>Ensure No Daemons are Unconfined by SELinux</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-selinux_confinement_of_daemons_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-selinux_context_elevation_for_sudo_ocil:questionnaire:1">
          <ocil:title>Elevate The SELinux Context When An Administrator Calls The Sudo Command</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-selinux_context_elevation_for_sudo_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-selinux_not_disabled_ocil:questionnaire:1">
          <ocil:title>Ensure SELinux is Not Disabled</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-selinux_not_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-selinux_policytype_ocil:questionnaire:1">
          <ocil:title>Configure SELinux Policy</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-selinux_policytype_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-selinux_state_ocil:questionnaire:1">
          <ocil:title>Ensure SELinux State is Enforcing</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-selinux_state_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-selinux_user_login_roles_ocil:questionnaire:1">
          <ocil:title>Map System Users To The Appropriate SELinux Role</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-selinux_user_login_roles_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_abrtd_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Automatic Bug Reporting Tool (abrtd)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_abrtd_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_acpid_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Advanced Configuration and Power Interface (acpid)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_acpid_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_atd_disabled_ocil:questionnaire:1">
          <ocil:title>Disable At Service (atd)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_atd_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1">
          <ocil:title>Enable auditd Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_autofs_disabled_ocil:questionnaire:1">
          <ocil:title>Disable the Automounter</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_autofs_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_avahi-daemon_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Avahi Server Software</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_avahi-daemon_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_bluetooth_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Bluetooth Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_bluetooth_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_certmonger_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Certmonger Service (certmonger)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_certmonger_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_chronyd_enabled_ocil:questionnaire:1">
          <ocil:title>The Chronyd service is enabled</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_chronyd_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_chronyd_or_ntpd_enabled_ocil:questionnaire:1">
          <ocil:title>Enable the NTP Daemon</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_chronyd_or_ntpd_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_cockpit_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Cockpit Management Server</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_cockpit_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_cpupower_disabled_ocil:questionnaire:1">
          <ocil:title>Disable CPU Speed (cpupower)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_cpupower_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_cron_enabled_ocil:questionnaire:1">
          <ocil:title>Enable cron Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_cron_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_crond_enabled_ocil:questionnaire:1">
          <ocil:title>Enable cron Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_crond_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_cups_disabled_ocil:questionnaire:1">
          <ocil:title>Disable the CUPS Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_cups_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_debug-shell_disabled_ocil:questionnaire:1">
          <ocil:title>Disable debug-shell SystemD Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_debug-shell_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_dhcpd_disabled_ocil:questionnaire:1">
          <ocil:title>Disable DHCP Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_dhcpd_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_dovecot_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Dovecot Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_dovecot_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_fapolicyd_enabled_ocil:questionnaire:1">
          <ocil:title>Enable the File Access Policy Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_fapolicyd_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_firewalld_enabled_ocil:questionnaire:1">
          <ocil:title>Verify firewalld Enabled</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_firewalld_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_httpd_disabled_ocil:questionnaire:1">
          <ocil:title>Disable httpd Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_httpd_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_ip6tables_enabled_ocil:questionnaire:1">
          <ocil:title>Verify ip6tables Enabled if Using IPv6</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_ip6tables_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_iptables_enabled_ocil:questionnaire:1">
          <ocil:title>Verify iptables Enabled</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_iptables_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_kdump_disabled_ocil:questionnaire:1">
          <ocil:title>Disable KDump Kernel Crash Analyzer (kdump)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_kdump_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_mdmonitor_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Software RAID Monitor (mdmonitor)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_mdmonitor_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_nails_enabled_ocil:questionnaire:1">
          <ocil:title>Enable nails Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_nails_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_named_disabled_ocil:questionnaire:1">
          <ocil:title>Disable named Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_named_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_netconsole_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Network Console (netconsole)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_netconsole_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_nfs_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Network File System (nfs)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_nfs_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_nftables_disabled_ocil:questionnaire:1">
          <ocil:title>Verify nftables Service is Disabled</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_nftables_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_nftables_enabled_ocil:questionnaire:1">
          <ocil:title>Verify nftables Service is Enabled</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_nftables_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_ntp_enabled_ocil:questionnaire:1">
          <ocil:title>Enable the NTP Daemon</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_ntp_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_ntpd_enabled_ocil:questionnaire:1">
          <ocil:title>Enable the NTP Daemon</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_ntpd_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_ntpdate_disabled_ocil:questionnaire:1">
          <ocil:title>Disable ntpdate Service (ntpdate)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_ntpdate_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_oddjobd_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Odd Job Daemon (oddjobd)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_oddjobd_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_pcscd_enabled_ocil:questionnaire:1">
          <ocil:title>Enable the pcscd Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_pcscd_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_portreserve_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Portreserve (portreserve)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_portreserve_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_postfix_enabled_ocil:questionnaire:1">
          <ocil:title>Enable Postfix Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_postfix_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_psacct_enabled_ocil:questionnaire:1">
          <ocil:title>Enable Process Accounting (psacct)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_psacct_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_qpidd_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Apache Qpid (qpidd)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_qpidd_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_quota_nld_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Quota Netlink (quota_nld)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_quota_nld_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_rdisc_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Network Router Discovery Daemon (rdisc)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_rdisc_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_rexec_disabled_ocil:questionnaire:1">
          <ocil:title>Disable rexec Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_rexec_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_rhnsd_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Red Hat Network Service (rhnsd)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_rhnsd_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_rhsmcertd_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Red Hat Subscription Manager Daemon (rhsmcertd)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_rhsmcertd_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_rlogin_disabled_ocil:questionnaire:1">
          <ocil:title>Disable rlogin Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_rlogin_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_rngd_enabled_ocil:questionnaire:1">
          <ocil:title>Enable the Hardware RNG Entropy Gatherer Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_rngd_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_rpcsvcgssd_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Secure RPC Server Service (rpcsvcgssd)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_rpcsvcgssd_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_rsh_disabled_ocil:questionnaire:1">
          <ocil:title>Disable rsh Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_rsh_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_rsyncd_disabled_ocil:questionnaire:1">
          <ocil:title>Ensure rsyncd service is disabled</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_rsyncd_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_rsyslog_enabled_ocil:questionnaire:1">
          <ocil:title>Enable rsyslog Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_rsyslog_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_saslauthd_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Cyrus SASL Authentication Daemon (saslauthd)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_saslauthd_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_slapd_disabled_ocil:questionnaire:1">
          <ocil:title>Disable LDAP Server (slapd)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_slapd_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_smb_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Samba</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_smb_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_snmpd_disabled_ocil:questionnaire:1">
          <ocil:title>Disable snmpd Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_snmpd_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_squid_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Squid</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_squid_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_sshd_disabled_ocil:questionnaire:1">
          <ocil:title>Disable SSH Server If Possible</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_sshd_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_sshd_enabled_ocil:questionnaire:1">
          <ocil:title>Enable the OpenSSH Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_sshd_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_sssd_enabled_ocil:questionnaire:1">
          <ocil:title>Enable the SSSD Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_sssd_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_syslogng_enabled_ocil:questionnaire:1">
          <ocil:title>Enable syslog-ng Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_syslogng_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_sysstat_disabled_ocil:questionnaire:1">
          <ocil:title>Disable System Statistics Reset Service (sysstat)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_sysstat_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_systemd-coredump_disabled_ocil:questionnaire:1">
          <ocil:title>Disable acquiring, saving, and processing core dumps</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_systemd-coredump_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_systemd-journal-upload_enabled_ocil:questionnaire:1">
          <ocil:title>Enable systemd-journal-upload Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_systemd-journal-upload_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_systemd-journald_enabled_ocil:questionnaire:1">
          <ocil:title>Enable systemd-journald Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_systemd-journald_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_telnet_disabled_ocil:questionnaire:1">
          <ocil:title>Disable telnet Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_telnet_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_tftp_disabled_ocil:questionnaire:1">
          <ocil:title>Disable tftp Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_tftp_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_ufw_enabled_ocil:questionnaire:1">
          <ocil:title>Verify ufw Enabled</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_ufw_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_usbguard_enabled_ocil:questionnaire:1">
          <ocil:title>Enable the USBGuard Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_usbguard_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_vsftpd_disabled_ocil:questionnaire:1">
          <ocil:title>Disable vsftpd Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_vsftpd_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_xinetd_disabled_ocil:questionnaire:1">
          <ocil:title>Disable xinetd Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_xinetd_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_ypbind_disabled_ocil:questionnaire:1">
          <ocil:title>Disable ypbind Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_ypbind_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_ypserv_disabled_ocil:questionnaire:1">
          <ocil:title>Disable ypserv Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_ypserv_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-service_zebra_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Quagga Service</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-service_zebra_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-set_firewalld_appropriate_zone_ocil:questionnaire:1">
          <ocil:title>Ensure network interfaces are assigned to appropriate zone</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-set_firewalld_appropriate_zone_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-set_firewalld_default_zone_ocil:questionnaire:1">
          <ocil:title>Set Default firewalld Zone for Incoming Packets</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-set_firewalld_default_zone_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-set_ip6tables_default_rule_ocil:questionnaire:1">
          <ocil:title>Set Default ip6tables Policy for Incoming Packets</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-set_ip6tables_default_rule_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-set_iptables_default_rule_ocil:questionnaire:1">
          <ocil:title>Set Default iptables Policy for Incoming Packets</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-set_iptables_default_rule_forward_ocil:questionnaire:1">
          <ocil:title>Set Default iptables Policy for Forwarded Packets</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-set_iptables_default_rule_forward_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-set_ipv6_loopback_traffic_ocil:questionnaire:1">
          <ocil:title>Set configuration for IPv6 loopback traffic</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-set_ipv6_loopback_traffic_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-set_loopback_traffic_ocil:questionnaire:1">
          <ocil:title>Set configuration for loopback traffic</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-set_loopback_traffic_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-set_nftables_table_ocil:questionnaire:1">
          <ocil:title>Ensure a Table Exists for Nftables</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-set_nftables_table_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-set_password_hashing_algorithm_libuserconf_ocil:questionnaire:1">
          <ocil:title>Set Password Hashing Algorithm in /etc/libuser.conf</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_libuserconf_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-set_password_hashing_algorithm_logindefs_ocil:questionnaire:1">
          <ocil:title>Set Password Hashing Algorithm in /etc/login.defs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_logindefs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-set_password_hashing_algorithm_passwordauth_ocil:questionnaire:1">
          <ocil:title>Set PAM Password Hashing Algorithm - password-auth</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_passwordauth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-set_password_hashing_algorithm_systemauth_ocil:questionnaire:1">
          <ocil:title>Set PAM Password Hashing Algorithm - system-auth</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-set_password_hashing_algorithm_systemauth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-set_password_hashing_min_rounds_logindefs_ocil:questionnaire:1">
          <ocil:title>Set Password Hashing Rounds in /etc/login.defs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-set_password_hashing_min_rounds_logindefs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-snmpd_no_rwusers_ocil:questionnaire:1">
          <ocil:title>Ensure SNMP Read Write is disabled</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-snmpd_no_rwusers_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-snmpd_not_default_password_ocil:questionnaire:1">
          <ocil:title>Ensure Default SNMP Password Is Not Used</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-snmpd_not_default_password_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-snmpd_use_newer_protocol_ocil:questionnaire:1">
          <ocil:title>Configure SNMP Service to Use Only SNMPv3 or Newer</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-snmpd_use_newer_protocol_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-socket_systemd-journal-remote_disabled_ocil:questionnaire:1">
          <ocil:title>Disable systemd-journal-remote Socket</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-socket_systemd-journal-remote_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ssh_client_rekey_limit_ocil:questionnaire:1">
          <ocil:title>Configure session renegotiation for SSH client</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ssh_client_rekey_limit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ssh_client_use_strong_rng_csh_ocil:questionnaire:1">
          <ocil:title>SSH client uses strong entropy to seed (for CSH like shells)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ssh_client_use_strong_rng_csh_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ssh_client_use_strong_rng_sh_ocil:questionnaire:1">
          <ocil:title>SSH client uses strong entropy to seed (Bash-like shells)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ssh_client_use_strong_rng_sh_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-ssh_keys_passphrase_protected_ocil:questionnaire:1">
          <ocil:title>Verify the SSH Private Key Files Have a Passcode</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-ssh_keys_passphrase_protected_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_allow_only_protocol2_ocil:questionnaire:1">
          <ocil:title>Allow Only SSH Protocol 2</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_allow_only_protocol2_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_disable_compression_ocil:questionnaire:1">
          <ocil:title>Disable Compression Or Set Compression to delayed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_disable_compression_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">
          <ocil:title>Disable SSH Access via Empty Passwords</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_disable_forwarding_ocil:questionnaire:1">
          <ocil:title>Disable SSH Forwarding</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_disable_forwarding_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_disable_gssapi_auth_ocil:questionnaire:1">
          <ocil:title>Disable GSSAPI Authentication</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_disable_gssapi_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_disable_kerb_auth_ocil:questionnaire:1">
          <ocil:title>Disable Kerberos Authentication</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_disable_kerb_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_disable_pubkey_auth_ocil:questionnaire:1">
          <ocil:title>Disable PubkeyAuthentication Authentication</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_disable_rhosts_ocil:questionnaire:1">
          <ocil:title>Disable SSH Support for .rhosts Files</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_disable_rhosts_rsa_ocil:questionnaire:1">
          <ocil:title>Disable SSH Support for Rhosts RSA Authentication</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">
          <ocil:title>Disable SSH Root Login</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_disable_root_password_login_ocil:questionnaire:1">
          <ocil:title>Disable SSH root Login with a Password (Insecure)</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_disable_root_password_login_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_disable_tcp_forwarding_ocil:questionnaire:1">
          <ocil:title>Disable SSH TCP Forwarding</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_disable_user_known_hosts_ocil:questionnaire:1">
          <ocil:title>Disable SSH Support for User Known Hosts</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_disable_x11_forwarding_ocil:questionnaire:1">
          <ocil:title>Disable X11 Forwarding</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_do_not_permit_user_env_ocil:questionnaire:1">
          <ocil:title>Do Not Allow SSH Environment Options</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_do_not_permit_user_env_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_enable_gssapi_auth_ocil:questionnaire:1">
          <ocil:title>Enable GSSAPI Authentication</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_enable_gssapi_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_enable_pam_ocil:questionnaire:1">
          <ocil:title>Enable PAM</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_enable_pam_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_enable_pubkey_auth_ocil:questionnaire:1">
          <ocil:title>Enable Public Key Authentication</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_enable_pubkey_auth_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_enable_strictmodes_ocil:questionnaire:1">
          <ocil:title>Enable Use of Strict Mode Checking</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_enable_strictmodes_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_enable_warning_banner_ocil:questionnaire:1">
          <ocil:title>Enable SSH Warning Banner</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_enable_warning_banner_net_ocil:questionnaire:1">
          <ocil:title>Enable SSH Warning Banner</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_enable_warning_banner_net_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_enable_x11_forwarding_ocil:questionnaire:1">
          <ocil:title>Enable Encrypted X11 Forwarding</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_enable_x11_forwarding_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_limit_user_access_ocil:questionnaire:1">
          <ocil:title>Limit Users' SSH Access</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_limit_user_access_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_print_last_log_ocil:questionnaire:1">
          <ocil:title>Enable SSH Print Last Log</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_print_last_log_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_rekey_limit_ocil:questionnaire:1">
          <ocil:title>Force frequent session key renegotiation</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_rekey_limit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_set_idle_timeout_ocil:questionnaire:1">
          <ocil:title>Set SSH Client Alive Interval</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_set_idle_timeout_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_set_keepalive_ocil:questionnaire:1">
          <ocil:title>Set SSH Client Alive Count Max</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_set_keepalive_0_ocil:questionnaire:1">
          <ocil:title>Set SSH Client Alive Count Max to zero</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_set_keepalive_0_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_set_login_grace_time_ocil:questionnaire:1">
          <ocil:title>Ensure SSH LoginGraceTime is configured</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_set_login_grace_time_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_set_loglevel_info_ocil:questionnaire:1">
          <ocil:title>Set LogLevel to INFO</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_info_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_set_loglevel_verbose_ocil:questionnaire:1">
          <ocil:title>Set SSH Daemon LogLevel to VERBOSE</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_set_max_auth_tries_ocil:questionnaire:1">
          <ocil:title>Set SSH authentication attempt limit</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_set_max_auth_tries_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_set_max_sessions_ocil:questionnaire:1">
          <ocil:title>Set SSH MaxSessions limit</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_set_max_sessions_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_set_maxstartups_ocil:questionnaire:1">
          <ocil:title>Ensure SSH MaxStartups is configured</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_set_maxstartups_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_use_approved_ciphers_ocil:questionnaire:1">
          <ocil:title>Use Only FIPS 140-2 Validated Ciphers</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_use_approved_ciphers_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_use_approved_kex_ordered_stig_ocil:questionnaire:1">
          <ocil:title>Use Only FIPS 140-2 Validated Key Exchange Algorithms</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_use_approved_kex_ordered_stig_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_use_approved_macs_ocil:questionnaire:1">
          <ocil:title>Use Only FIPS 140-2 Validated MACs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_use_approved_macs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_use_priv_separation_ocil:questionnaire:1">
          <ocil:title>Enable Use of Privilege Separation</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_use_priv_separation_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_use_strong_kex_ocil:questionnaire:1">
          <ocil:title>Use Only Strong Key Exchange algorithms</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_use_strong_kex_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_use_strong_macs_ocil:questionnaire:1">
          <ocil:title>Use Only Strong MACs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_use_strong_macs_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_use_strong_rng_ocil:questionnaire:1">
          <ocil:title>SSH server uses strong entropy to seed</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_use_strong_rng_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sshd_x11_use_localhost_ocil:questionnaire:1">
          <ocil:title>Prevent remote hosts from connecting to the proxy display</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sshd_x11_use_localhost_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sssd_certificate_verification_ocil:questionnaire:1">
          <ocil:title>Certificate status checking in SSSD</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sssd_certificate_verification_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sssd_enable_certmap_ocil:questionnaire:1">
          <ocil:title>Enable Certmap in SSSD</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sssd_enable_certmap_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sssd_enable_pam_services_ocil:questionnaire:1">
          <ocil:title>Configure PAM in SSSD Services</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sssd_enable_pam_services_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sssd_enable_smartcards_ocil:questionnaire:1">
          <ocil:title>Enable Smartcards in SSSD</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sssd_enable_smartcards_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sssd_has_trust_anchor_ocil:questionnaire:1">
          <ocil:title>SSSD Has a Correct Trust Anchor</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sssd_has_trust_anchor_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sssd_ldap_configure_tls_ca_ocil:questionnaire:1">
          <ocil:title>Configure SSSD LDAP Backend Client CA Certificate</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sssd_ldap_configure_tls_ca_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sssd_ldap_configure_tls_ca_dir_ocil:questionnaire:1">
          <ocil:title>Configure SSSD LDAP Backend Client CA Certificate Location</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sssd_ldap_configure_tls_ca_dir_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sssd_ldap_configure_tls_reqcert_ocil:questionnaire:1">
          <ocil:title>Configure SSSD LDAP Backend Client to Demand a Valid Certificate from the Server</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sssd_ldap_configure_tls_reqcert_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sssd_ldap_start_tls_ocil:questionnaire:1">
          <ocil:title>Configure SSSD LDAP Backend to Use TLS For All Transactions</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sssd_ldap_start_tls_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sssd_memcache_timeout_ocil:questionnaire:1">
          <ocil:title>Configure SSSD's Memory Cache to Expire</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sssd_memcache_timeout_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sssd_offline_cred_expiration_ocil:questionnaire:1">
          <ocil:title>Configure SSSD to Expire Offline Credentials</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sssd_offline_cred_expiration_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sssd_run_as_sssd_user_ocil:questionnaire:1">
          <ocil:title>Configure SSSD to run as user sssd</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sssd_run_as_sssd_user_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sssd_ssh_known_hosts_timeout_ocil:questionnaire:1">
          <ocil:title>Configure SSSD to Expire SSH Known Hosts</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sssd_ssh_known_hosts_timeout_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudo_add_env_reset_ocil:questionnaire:1">
          <ocil:title>Ensure sudo Runs In A Minimal Environment - sudo env_reset</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudo_add_env_reset_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudo_add_ignore_dot_ocil:questionnaire:1">
          <ocil:title>Ensure sudo Ignores Commands In Current Dir - sudo ignore_dot</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudo_add_ignore_dot_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudo_add_noexec_ocil:questionnaire:1">
          <ocil:title>Ensure Privileged Escalated Commands Cannot Execute Other Commands - sudo NOEXEC</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudo_add_noexec_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudo_add_passwd_timeout_ocil:questionnaire:1">
          <ocil:title>Ensure sudo passwd_timeout is appropriate - sudo passwd_timeout</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudo_add_passwd_timeout_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudo_add_requiretty_ocil:questionnaire:1">
          <ocil:title>Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo requiretty</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudo_add_requiretty_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudo_add_umask_ocil:questionnaire:1">
          <ocil:title>Ensure sudo umask is appropriate - sudo umask</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudo_add_umask_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudo_add_use_pty_ocil:questionnaire:1">
          <ocil:title>Ensure Only Users Logged In To Real tty Can Execute Sudo - sudo use_pty</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudo_add_use_pty_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudo_custom_logfile_ocil:questionnaire:1">
          <ocil:title>Ensure Sudo Logfile Exists - sudo logfile</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudo_custom_logfile_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudo_dedicated_group_ocil:questionnaire:1">
          <ocil:title>Ensure a dedicated group owns sudo</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudo_dedicated_group_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudo_remove_no_authenticate_ocil:questionnaire:1">
          <ocil:title>Ensure Users Re-Authenticate for Privilege Escalation - sudo !authenticate</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudo_remove_no_authenticate_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudo_remove_nopasswd_ocil:questionnaire:1">
          <ocil:title>Ensure Users Re-Authenticate for Privilege Escalation - sudo NOPASSWD</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudo_remove_nopasswd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudo_require_authentication_ocil:questionnaire:1">
          <ocil:title>Ensure Users Re-Authenticate for Privilege Escalation - sudo</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudo_require_authentication_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudo_require_reauthentication_ocil:questionnaire:1">
          <ocil:title>Require Re-Authentication When Using the sudo Command</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudo_require_reauthentication_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudo_restrict_others_executable_permission_ocil:questionnaire:1">
          <ocil:title>Ensure only owner and members of group owner of /usr/bin/sudo can execute it</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudo_restrict_others_executable_permission_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_ocil:questionnaire:1">
          <ocil:title>The operating system must restrict privilege elevation to authorized personnel</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudo_vdsm_nopasswd_ocil:questionnaire:1">
          <ocil:title>Only the VDSM User Can Use sudo NOPASSWD</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudo_vdsm_nopasswd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudoers_default_includedir_ocil:questionnaire:1">
          <ocil:title>Ensure sudo only includes the default configuration directory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudoers_default_includedir_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudoers_explicit_command_args_ocil:questionnaire:1">
          <ocil:title>Explicit arguments in sudo specifications</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudoers_explicit_command_args_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudoers_no_command_negation_ocil:questionnaire:1">
          <ocil:title>Don't define allowed commands in sudoers by means of exclusion</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudoers_no_command_negation_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudoers_no_root_target_ocil:questionnaire:1">
          <ocil:title>Don't target root user in the sudoers file</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudoers_no_root_target_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sudoers_validate_passwd_ocil:questionnaire:1">
          <ocil:title>Ensure invoking users password for privilege escalation when using sudo</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sudoers_validate_passwd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysconfig_networking_bootproto_ifcfg_ocil:questionnaire:1">
          <ocil:title>Disable DHCP Client in ifcfg</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysconfig_networking_bootproto_ifcfg_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_crypto_fips_enabled_ocil:questionnaire:1">
          <ocil:title>Set kernel parameter 'crypto.fips_enabled' to 1</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_crypto_fips_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_fs_protected_hardlinks_ocil:questionnaire:1">
          <ocil:title>Enable Kernel Parameter to Enforce DAC on Hardlinks</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_fs_protected_symlinks_ocil:questionnaire:1">
          <ocil:title>Enable Kernel Parameter to Enforce DAC on Symlinks</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_fs_protected_symlinks_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_fs_suid_dumpable_ocil:questionnaire:1">
          <ocil:title>Disable Core Dumps for SUID programs</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_kernel_core_pattern_ocil:questionnaire:1">
          <ocil:title>Disable storing core dumps</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_kernel_core_pattern_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_kernel_core_uses_pid_ocil:questionnaire:1">
          <ocil:title>Configure file name of core dumps</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_kernel_core_uses_pid_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_kernel_dmesg_restrict_ocil:questionnaire:1">
          <ocil:title>Restrict Access to Kernel Message Buffer</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_kernel_dmesg_restrict_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_kernel_exec_shield_ocil:questionnaire:1">
          <ocil:title>Enable ExecShield via sysctl</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_kernel_exec_shield_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_kernel_kexec_load_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Kernel Image Loading</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_kernel_kexec_load_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_kernel_kptr_restrict_ocil:questionnaire:1">
          <ocil:title>Restrict Exposed Kernel Pointer Addresses Access</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_kernel_kptr_restrict_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_kernel_modules_disabled_ocil:questionnaire:1">
          <ocil:title>Disable loading and unloading of kernel modules</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_kernel_modules_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_kernel_panic_on_oops_ocil:questionnaire:1">
          <ocil:title>Kernel panic on oops</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_kernel_panic_on_oops_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_kernel_perf_cpu_time_max_percent_ocil:questionnaire:1">
          <ocil:title>Limit CPU consumption of the Perf system</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_kernel_perf_cpu_time_max_percent_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_kernel_perf_event_max_sample_rate_ocil:questionnaire:1">
          <ocil:title>Limit sampling frequency of the Perf system</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_kernel_perf_event_max_sample_rate_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_kernel_perf_event_paranoid_ocil:questionnaire:1">
          <ocil:title>Disallow kernel profiling by unprivileged users</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_kernel_perf_event_paranoid_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_kernel_pid_max_ocil:questionnaire:1">
          <ocil:title>Configure maximum number of process identifiers</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_kernel_pid_max_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_kernel_randomize_va_space_ocil:questionnaire:1">
          <ocil:title>Enable Randomized Layout of Virtual Address Space</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_kernel_sysrq_ocil:questionnaire:1">
          <ocil:title>Disallow magic SysRq key</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_kernel_sysrq_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_kernel_unprivileged_bpf_disabled_ocil:questionnaire:1">
          <ocil:title>Disable Access to Network bpf() Syscall From Unprivileged Processes</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_kernel_unprivileged_bpf_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_kernel_yama_ptrace_scope_ocil:questionnaire:1">
          <ocil:title>Restrict usage of ptrace to descendant processes</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_kernel_yama_ptrace_scope_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_core_bpf_jit_harden_ocil:questionnaire:1">
          <ocil:title>Harden the operation of the BPF just-in-time compiler</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_core_bpf_jit_harden_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_ocil:questionnaire:1">
          <ocil:title>Disable Accepting Packets Routed Between Local Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_ocil:questionnaire:1">
          <ocil:title>Disable Accepting ICMP Redirects for All IPv4 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1">
          <ocil:title>Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv4 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_ocil:questionnaire:1">
          <ocil:title>Configure ARP filtering for All IPv4 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_ocil:questionnaire:1">
          <ocil:title>Configure Response Mode of ARP Requests for All IPv4 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_all_drop_gratuitous_arp_ocil:questionnaire:1">
          <ocil:title>Drop Gratuitous ARP frames on All IPv4 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_drop_gratuitous_arp_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_all_forwarding_ocil:questionnaire:1">
          <ocil:title>Disable Kernel Parameter for IPv4 Forwarding on all IPv4 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_forwarding_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_ocil:questionnaire:1">
          <ocil:title>Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_ocil:questionnaire:1">
          <ocil:title>Prevent Routing External Traffic to Local Loopback on All IPv4 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_ocil:questionnaire:1">
          <ocil:title>Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_ocil:questionnaire:1">
          <ocil:title>Disable Kernel Parameter for Accepting Secure ICMP Redirects on all IPv4 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_ocil:questionnaire:1">
          <ocil:title>Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_ocil:questionnaire:1">
          <ocil:title>Configure Sending and Accepting Shared Media Redirects for All IPv4 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_ocil:questionnaire:1">
          <ocil:title>Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv4 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1">
          <ocil:title>Disable Kernel Parameter for Accepting Source-Routed Packets on IPv4 Interfaces by Default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_default_forwarding_ocil:questionnaire:1">
          <ocil:title>Disable Kernel Parameter for IPv4 Forwarding By Default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_forwarding_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_ocil:questionnaire:1">
          <ocil:title>Enable Kernel Parameter to Log Martian Packets on all IPv4 Interfaces by Default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1">
          <ocil:title>Enable Kernel Parameter to Use Reverse Path Filtering on all IPv4 Interfaces by Default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1">
          <ocil:title>Configure Kernel Parameter for Accepting Secure Redirects By Default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_ocil:questionnaire:1">
          <ocil:title>Disable Kernel Parameter for Sending ICMP Redirects on all IPv4 Interfaces by Default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_ocil:questionnaire:1">
          <ocil:title>Configure Sending and Accepting Shared Media Redirects by Default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_ocil:questionnaire:1">
          <ocil:title>Enable Kernel Parameter to Ignore ICMP Broadcast Echo Requests on IPv4 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_ocil:questionnaire:1">
          <ocil:title>Enable Kernel Parameter to Ignore Bogus ICMP Error Responses on IPv4 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_ip_forward_ocil:questionnaire:1">
          <ocil:title>Disable Kernel Parameter for IP Forwarding on IPv4 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_ip_forward_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_ip_local_port_range_ocil:questionnaire:1">
          <ocil:title>Set Kernel Parameter to Increase Local Port Range</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_ip_local_port_range_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_tcp_invalid_ratelimit_ocil:questionnaire:1">
          <ocil:title>Configure Kernel to Rate Limit Sending of Duplicate TCP Acknowledgments</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_tcp_invalid_ratelimit_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_tcp_rfc1337_ocil:questionnaire:1">
          <ocil:title>Enable Kernel Parameter to Use TCP RFC 1337 on IPv4 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_tcp_rfc1337_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv4_tcp_syncookies_ocil:questionnaire:1">
          <ocil:title>Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_tcp_syncookies_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_ocil:questionnaire:1">
          <ocil:title>Configure Accepting Router Advertisements on All IPv6 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_ocil:questionnaire:1">
          <ocil:title>Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo_ocil:questionnaire:1">
          <ocil:title>Configure Accepting Prefix Information in Router Advertisements on All IPv6 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_ocil:questionnaire:1">
          <ocil:title>Configure Accepting Router Preference in Router Advertisements on All IPv6 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_ocil:questionnaire:1">
          <ocil:title>Disable Accepting ICMP Redirects for All IPv6 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_ocil:questionnaire:1">
          <ocil:title>Disable Kernel Parameter for Accepting Source-Routed Packets on all IPv6 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_ocil:questionnaire:1">
          <ocil:title>Configure Auto Configuration on All IPv6 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_ocil:questionnaire:1">
          <ocil:title>Disable IPv6 Addressing on All IPv6 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_ocil:questionnaire:1">
          <ocil:title>Disable Kernel Parameter for IPv6 Forwarding</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_all_max_addresses_ocil:questionnaire:1">
          <ocil:title>Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_max_addresses_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_all_router_solicitations_ocil:questionnaire:1">
          <ocil:title>Configure Denying Router Solicitations on All IPv6 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_all_router_solicitations_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_ocil:questionnaire:1">
          <ocil:title>Disable Accepting Router Advertisements on all IPv6 Interfaces by Default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_ocil:questionnaire:1">
          <ocil:title>Configure Accepting Default Router in Router Advertisements on All IPv6 Interfaces By Default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_ocil:questionnaire:1">
          <ocil:title>Configure Accepting Prefix Information in Router Advertisements on All IPv6 Interfaces By Default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_ocil:questionnaire:1">
          <ocil:title>Configure Accepting Router Preference in Router Advertisements on All IPv6 Interfaces By Default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_ocil:questionnaire:1">
          <ocil:title>Disable Kernel Parameter for Accepting ICMP Redirects by Default on IPv6 Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_ocil:questionnaire:1">
          <ocil:title>Disable Kernel Parameter for Accepting Source-Routed Packets on IPv6 Interfaces by Default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_default_autoconf_ocil:questionnaire:1">
          <ocil:title>Configure Auto Configuration on All IPv6 Interfaces By Default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_autoconf_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_ocil:questionnaire:1">
          <ocil:title>Disable IPv6 Addressing on IPv6 Interfaces by Default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_default_forwarding_ocil:questionnaire:1">
          <ocil:title>Disable Kernel Parameter for IPv6 Forwarding by default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_forwarding_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_default_max_addresses_ocil:questionnaire:1">
          <ocil:title>Configure Maximum Number of Autoconfigured Addresses on All IPv6 Interfaces By Default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_max_addresses_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_net_ipv6_conf_default_router_solicitations_ocil:questionnaire:1">
          <ocil:title>Configure Denying Router Solicitations on All IPv6 Interfaces By Default</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_net_ipv6_conf_default_router_solicitations_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_user_max_user_namespaces_ocil:questionnaire:1">
          <ocil:title>Disable the use of user namespaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_user_max_user_namespaces_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_user_max_user_namespaces_no_remediation_ocil:questionnaire:1">
          <ocil:title>Disable the use of user namespaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_user_max_user_namespaces_no_remediation_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-sysctl_vm_mmap_min_addr_ocil:questionnaire:1">
          <ocil:title>Prevent applications from mapping low portion of virtual memory</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-sysctl_vm_mmap_min_addr_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-systemd_tmp_mount_enabled_ocil:questionnaire:1">
          <ocil:title>Ensure tmp.mount Unit Is Enabled</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-systemd_tmp_mount_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-tftp_uses_secure_mode_systemd_ocil:questionnaire:1">
          <ocil:title>Ensure tftp systemd Service Uses Secure Mode</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-tftp_uses_secure_mode_systemd_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-tftpd_uses_secure_mode_ocil:questionnaire:1">
          <ocil:title>Ensure tftp Daemon Uses Secure Mode</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-tftpd_uses_secure_mode_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-timer_dnf-automatic_enabled_ocil:questionnaire:1">
          <ocil:title>Enable dnf-automatic Timer</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-timer_dnf-automatic_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-timer_logrotate_enabled_ocil:questionnaire:1">
          <ocil:title>Enable logrotate Timer</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-timer_logrotate_enabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-uefi_no_removeable_media_ocil:questionnaire:1">
          <ocil:title>UEFI Boot Loader Is Not Installed On Removable Media</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-uefi_no_removeable_media_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-umask_for_daemons_ocil:questionnaire:1">
          <ocil:title>Set Daemon Umask</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-umask_for_daemons_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-usbguard_allow_hid_ocil:questionnaire:1">
          <ocil:title>Authorize Human Interface Devices in USBGuard daemon</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-usbguard_allow_hid_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-usbguard_allow_hid_and_hub_ocil:questionnaire:1">
          <ocil:title>Authorize Human Interface Devices and USB hubs in USBGuard daemon</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-usbguard_allow_hid_and_hub_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-usbguard_allow_hub_ocil:questionnaire:1">
          <ocil:title>Authorize USB hubs in USBGuard daemon</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-usbguard_allow_hub_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-usbguard_generate_policy_ocil:questionnaire:1">
          <ocil:title>Generate USBGuard Policy</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-usbguard_generate_policy_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-use_kerberos_security_all_exports_ocil:questionnaire:1">
          <ocil:title>Use Kerberos Security on All Exports</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-use_kerberos_security_all_exports_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-use_pam_wheel_for_su_ocil:questionnaire:1">
          <ocil:title>Enforce usage of pam_wheel for su authentication</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-use_pam_wheel_for_su_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-use_pam_wheel_group_for_su_ocil:questionnaire:1">
          <ocil:title>Enforce Usage of pam_wheel with Group Parameter for su Authentication</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-use_pam_wheel_group_for_su_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-wireless_disable_in_bios_ocil:questionnaire:1">
          <ocil:title>Disable WiFi or Bluetooth in BIOS</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-wireless_disable_in_bios_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-wireless_disable_interfaces_ocil:questionnaire:1">
          <ocil:title>Deactivate Wireless Network Interfaces</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-wireless_disable_interfaces_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-xwayland_disabled_ocil:questionnaire:1">
          <ocil:title>Disable XWayland</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-xwayland_disabled_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-xwindows_remove_packages_ocil:questionnaire:1">
          <ocil:title>Disable graphical user interface</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-xwindows_remove_packages_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-xwindows_runlevel_target_ocil:questionnaire:1">
          <ocil:title>Disable Graphical Environment Startup By Setting Default Target</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-xwindows_runlevel_target_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-zipl_audit_argument_ocil:questionnaire:1">
          <ocil:title>Enable Auditing to Start Prior to the Audit Daemon in zIPL</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-zipl_audit_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-zipl_audit_backlog_limit_argument_ocil:questionnaire:1">
          <ocil:title>Extend Audit Backlog Limit for the Audit Daemon in zIPL</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-zipl_audit_backlog_limit_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-zipl_bls_entries_only_ocil:questionnaire:1">
          <ocil:title>Ensure all zIPL boot entries are BLS compliant</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-zipl_bls_entries_only_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-zipl_bootmap_is_up_to_date_ocil:questionnaire:1">
          <ocil:title>Ensure zIPL bootmap is up to date</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-zipl_bootmap_is_up_to_date_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-zipl_enable_selinux_ocil:questionnaire:1">
          <ocil:title>Ensure SELinux Not Disabled in zIPL</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-zipl_enable_selinux_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-zipl_page_poison_argument_ocil:questionnaire:1">
          <ocil:title>Enable page allocator poisoning in zIPL</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-zipl_page_poison_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-zipl_slub_debug_argument_ocil:questionnaire:1">
          <ocil:title>Enable SLUB/SLAB allocator poisoning in zIPL</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-zipl_slub_debug_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-zipl_systemd_debug-shell_argument_absent_ocil:questionnaire:1">
          <ocil:title>Ensure debug-shell service is not enabled in zIPL</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-zipl_systemd_debug-shell_argument_absent_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
        <ocil:questionnaire id="ocil:ssg-zipl_vsyscall_argument_ocil:questionnaire:1">
          <ocil:title>Disable vsyscalls in zIPL</ocil:title>
          <ocil:actions>
            <ocil:test_action_ref>ocil:ssg-zipl_vsyscall_argument_action:testaction:1</ocil:test_action_ref>
          </ocil:actions>
        </ocil:questionnaire>
      </ocil:questionnaires>
      <ocil:test_actions>
        <ocil:boolean_question_test_action id="ocil:ssg-account_disable_post_pw_expiration_action:testaction:1" question_ref="ocil:ssg-account_disable_post_pw_expiration_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-account_emergency_expire_date_action:testaction:1" question_ref="ocil:ssg-account_emergency_expire_date_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-account_password_pam_faillock_password_auth_action:testaction:1" question_ref="ocil:ssg-account_password_pam_faillock_password_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-account_password_pam_faillock_system_auth_action:testaction:1" question_ref="ocil:ssg-account_password_pam_faillock_system_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-account_password_selinux_faillock_dir_action:testaction:1" question_ref="ocil:ssg-account_password_selinux_faillock_dir_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-account_passwords_pam_faillock_audit_action:testaction:1" question_ref="ocil:ssg-account_passwords_pam_faillock_audit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-account_passwords_pam_faillock_dir_action:testaction:1" question_ref="ocil:ssg-account_passwords_pam_faillock_dir_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-account_temp_expire_date_action:testaction:1" question_ref="ocil:ssg-account_temp_expire_date_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-account_unique_id_action:testaction:1" question_ref="ocil:ssg-account_unique_id_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-account_unique_name_action:testaction:1" question_ref="ocil:ssg-account_unique_name_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-account_use_centralized_automated_auth_action:testaction:1" question_ref="ocil:ssg-account_use_centralized_automated_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_authorized_local_users_action:testaction:1" question_ref="ocil:ssg-accounts_authorized_local_users_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_have_homedir_login_defs_action:testaction:1" question_ref="ocil:ssg-accounts_have_homedir_login_defs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_logon_fail_delay_action:testaction:1" question_ref="ocil:ssg-accounts_logon_fail_delay_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_max_concurrent_login_sessions_action:testaction:1" question_ref="ocil:ssg-accounts_max_concurrent_login_sessions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_maximum_age_login_defs_action:testaction:1" question_ref="ocil:ssg-accounts_maximum_age_login_defs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1" question_ref="ocil:ssg-accounts_minimum_age_login_defs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_no_uid_except_zero_action:testaction:1" question_ref="ocil:ssg-accounts_no_uid_except_zero_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_all_shadowed_action:testaction:1" question_ref="ocil:ssg-accounts_password_all_shadowed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_all_shadowed_sha512_action:testaction:1" question_ref="ocil:ssg-accounts_password_all_shadowed_sha512_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_last_change_is_in_past_action:testaction:1" question_ref="ocil:ssg-accounts_password_last_change_is_in_past_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_minlen_login_defs_action:testaction:1" question_ref="ocil:ssg-accounts_password_minlen_login_defs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_dcredit_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_dcredit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_dictcheck_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_dictcheck_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_difok_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_difok_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_enforce_local_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_enforce_local_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_enforce_root_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_enforce_root_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_lcredit_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_lcredit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_maxclassrepeat_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_maxclassrepeat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_maxrepeat_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_maxrepeat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_minclass_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_minclass_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_minlen_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_minlen_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_modules_in_authselect_profile_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_modules_in_authselect_profile_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_ocredit_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_ocredit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_pwhistory_remember_system_auth_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_pwhistory_remember_system_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_pwquality_password_auth_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_pwquality_password_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_pwquality_system_auth_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_pwquality_system_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_retry_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_retry_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_ucredit_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_ucredit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_unix_authtok_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_unix_authtok_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_unix_no_remember_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_unix_no_remember_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_unix_remember_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_unix_remember_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_unix_rounds_password_auth_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_unix_rounds_password_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_pam_unix_rounds_system_auth_action:testaction:1" question_ref="ocil:ssg-accounts_password_pam_unix_rounds_system_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_set_max_life_existing_action:testaction:1" question_ref="ocil:ssg-accounts_password_set_max_life_existing_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_set_max_life_root_action:testaction:1" question_ref="ocil:ssg-accounts_password_set_max_life_root_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_set_min_life_existing_action:testaction:1" question_ref="ocil:ssg-accounts_password_set_min_life_existing_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_set_warn_age_existing_action:testaction:1" question_ref="ocil:ssg-accounts_password_set_warn_age_existing_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_password_warn_age_login_defs_action:testaction:1" question_ref="ocil:ssg-accounts_password_warn_age_login_defs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_passwords_pam_faillock_audit_action:testaction:1" question_ref="ocil:ssg-accounts_passwords_pam_faillock_audit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_passwords_pam_faillock_deny_action:testaction:1" question_ref="ocil:ssg-accounts_passwords_pam_faillock_deny_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_passwords_pam_faillock_deny_root_action:testaction:1" question_ref="ocil:ssg-accounts_passwords_pam_faillock_deny_root_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_passwords_pam_faillock_dir_action:testaction:1" question_ref="ocil:ssg-accounts_passwords_pam_faillock_dir_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_passwords_pam_faillock_enforce_local_action:testaction:1" question_ref="ocil:ssg-accounts_passwords_pam_faillock_enforce_local_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_action:testaction:1" question_ref="ocil:ssg-accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_passwords_pam_faillock_interval_action:testaction:1" question_ref="ocil:ssg-accounts_passwords_pam_faillock_interval_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_passwords_pam_faillock_silent_action:testaction:1" question_ref="ocil:ssg-accounts_passwords_pam_faillock_silent_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_action:testaction:1" question_ref="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_with_zero_action:testaction:1" question_ref="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_with_zero_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_polyinstantiated_tmp_action:testaction:1" question_ref="ocil:ssg-accounts_polyinstantiated_tmp_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_polyinstantiated_var_tmp_action:testaction:1" question_ref="ocil:ssg-accounts_polyinstantiated_var_tmp_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_root_gid_zero_action:testaction:1" question_ref="ocil:ssg-accounts_root_gid_zero_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_root_path_dirs_no_write_action:testaction:1" question_ref="ocil:ssg-accounts_root_path_dirs_no_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_set_post_pw_existing_action:testaction:1" question_ref="ocil:ssg-accounts_set_post_pw_existing_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_tmout_action:testaction:1" question_ref="ocil:ssg-accounts_tmout_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1" question_ref="ocil:ssg-accounts_umask_etc_bashrc_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_umask_etc_csh_cshrc_action:testaction:1" question_ref="ocil:ssg-accounts_umask_etc_csh_cshrc_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_umask_etc_login_defs_action:testaction:1" question_ref="ocil:ssg-accounts_umask_etc_login_defs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_umask_etc_profile_action:testaction:1" question_ref="ocil:ssg-accounts_umask_etc_profile_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_umask_interactive_users_action:testaction:1" question_ref="ocil:ssg-accounts_umask_interactive_users_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_user_dot_group_ownership_action:testaction:1" question_ref="ocil:ssg-accounts_user_dot_group_ownership_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_user_dot_no_world_writable_programs_action:testaction:1" question_ref="ocil:ssg-accounts_user_dot_no_world_writable_programs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_user_dot_user_ownership_action:testaction:1" question_ref="ocil:ssg-accounts_user_dot_user_ownership_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_user_home_paths_only_action:testaction:1" question_ref="ocil:ssg-accounts_user_home_paths_only_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_user_interactive_home_directory_defined_action:testaction:1" question_ref="ocil:ssg-accounts_user_interactive_home_directory_defined_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_user_interactive_home_directory_exists_action:testaction:1" question_ref="ocil:ssg-accounts_user_interactive_home_directory_exists_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_user_interactive_home_directory_on_separate_partition_action:testaction:1" question_ref="ocil:ssg-accounts_user_interactive_home_directory_on_separate_partition_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_users_home_files_groupownership_action:testaction:1" question_ref="ocil:ssg-accounts_users_home_files_groupownership_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_users_home_files_ownership_action:testaction:1" question_ref="ocil:ssg-accounts_users_home_files_ownership_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_users_home_files_permissions_action:testaction:1" question_ref="ocil:ssg-accounts_users_home_files_permissions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-accounts_users_netrc_file_permissions_action:testaction:1" question_ref="ocil:ssg-accounts_users_netrc_file_permissions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-agent_mfetpd_running_action:testaction:1" question_ref="ocil:ssg-agent_mfetpd_running_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-aide_build_database_action:testaction:1" question_ref="ocil:ssg-aide_build_database_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-aide_check_audit_tools_action:testaction:1" question_ref="ocil:ssg-aide_check_audit_tools_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-aide_periodic_cron_checking_action:testaction:1" question_ref="ocil:ssg-aide_periodic_cron_checking_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-aide_scan_notification_action:testaction:1" question_ref="ocil:ssg-aide_scan_notification_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-aide_use_fips_hashes_action:testaction:1" question_ref="ocil:ssg-aide_use_fips_hashes_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-aide_verify_acls_action:testaction:1" question_ref="ocil:ssg-aide_verify_acls_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-aide_verify_ext_attributes_action:testaction:1" question_ref="ocil:ssg-aide_verify_ext_attributes_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_access_failed_action:testaction:1" question_ref="ocil:ssg-audit_access_failed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_access_success_action:testaction:1" question_ref="ocil:ssg-audit_access_success_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_basic_configuration_action:testaction:1" question_ref="ocil:ssg-audit_basic_configuration_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_create_failed_action:testaction:1" question_ref="ocil:ssg-audit_create_failed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_create_success_action:testaction:1" question_ref="ocil:ssg-audit_create_success_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_delete_failed_action:testaction:1" question_ref="ocil:ssg-audit_delete_failed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_delete_success_action:testaction:1" question_ref="ocil:ssg-audit_delete_success_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_immutable_login_uids_action:testaction:1" question_ref="ocil:ssg-audit_immutable_login_uids_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_modify_failed_action:testaction:1" question_ref="ocil:ssg-audit_modify_failed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_modify_success_action:testaction:1" question_ref="ocil:ssg-audit_modify_success_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_module_load_action:testaction:1" question_ref="ocil:ssg-audit_module_load_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_ospp_general_action:testaction:1" question_ref="ocil:ssg-audit_ospp_general_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_owner_change_failed_action:testaction:1" question_ref="ocil:ssg-audit_owner_change_failed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_owner_change_success_action:testaction:1" question_ref="ocil:ssg-audit_owner_change_success_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_perm_change_failed_action:testaction:1" question_ref="ocil:ssg-audit_perm_change_failed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_perm_change_success_action:testaction:1" question_ref="ocil:ssg-audit_perm_change_success_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_privileged_commands_init_action:testaction:1" question_ref="ocil:ssg-audit_privileged_commands_init_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_privileged_commands_poweroff_action:testaction:1" question_ref="ocil:ssg-audit_privileged_commands_poweroff_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_privileged_commands_reboot_action:testaction:1" question_ref="ocil:ssg-audit_privileged_commands_reboot_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_privileged_commands_shutdown_action:testaction:1" question_ref="ocil:ssg-audit_privileged_commands_shutdown_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_continue_loading_action:testaction:1" question_ref="ocil:ssg-audit_rules_continue_loading_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_dac_modification_chmod_action:testaction:1" question_ref="ocil:ssg-audit_rules_dac_modification_chmod_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_dac_modification_chown_action:testaction:1" question_ref="ocil:ssg-audit_rules_dac_modification_chown_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_dac_modification_fchmod_action:testaction:1" question_ref="ocil:ssg-audit_rules_dac_modification_fchmod_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_dac_modification_fchmodat_action:testaction:1" question_ref="ocil:ssg-audit_rules_dac_modification_fchmodat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_dac_modification_fchown_action:testaction:1" question_ref="ocil:ssg-audit_rules_dac_modification_fchown_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_dac_modification_fchownat_action:testaction:1" question_ref="ocil:ssg-audit_rules_dac_modification_fchownat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_dac_modification_fremovexattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_dac_modification_fremovexattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_dac_modification_fsetxattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_dac_modification_fsetxattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_dac_modification_lchown_action:testaction:1" question_ref="ocil:ssg-audit_rules_dac_modification_lchown_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_dac_modification_lremovexattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_dac_modification_lremovexattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_dac_modification_lsetxattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_dac_modification_lsetxattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_dac_modification_removexattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_dac_modification_removexattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_dac_modification_setxattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_dac_modification_setxattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_dac_modification_umount_action:testaction:1" question_ref="ocil:ssg-audit_rules_dac_modification_umount_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_dac_modification_umount2_action:testaction:1" question_ref="ocil:ssg-audit_rules_dac_modification_umount2_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_etc_cron_d_action:testaction:1" question_ref="ocil:ssg-audit_rules_etc_cron_d_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_etc_group_open_action:testaction:1" question_ref="ocil:ssg-audit_rules_etc_group_open_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_etc_group_open_by_handle_at_action:testaction:1" question_ref="ocil:ssg-audit_rules_etc_group_open_by_handle_at_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_etc_group_openat_action:testaction:1" question_ref="ocil:ssg-audit_rules_etc_group_openat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_etc_gshadow_open_action:testaction:1" question_ref="ocil:ssg-audit_rules_etc_gshadow_open_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_etc_gshadow_open_by_handle_at_action:testaction:1" question_ref="ocil:ssg-audit_rules_etc_gshadow_open_by_handle_at_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_etc_gshadow_openat_action:testaction:1" question_ref="ocil:ssg-audit_rules_etc_gshadow_openat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_etc_passwd_open_action:testaction:1" question_ref="ocil:ssg-audit_rules_etc_passwd_open_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_etc_passwd_open_by_handle_at_action:testaction:1" question_ref="ocil:ssg-audit_rules_etc_passwd_open_by_handle_at_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_etc_passwd_openat_action:testaction:1" question_ref="ocil:ssg-audit_rules_etc_passwd_openat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_etc_shadow_open_action:testaction:1" question_ref="ocil:ssg-audit_rules_etc_shadow_open_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_etc_shadow_open_by_handle_at_action:testaction:1" question_ref="ocil:ssg-audit_rules_etc_shadow_open_by_handle_at_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_etc_shadow_openat_action:testaction:1" question_ref="ocil:ssg-audit_rules_etc_shadow_openat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_execution_chacl_action:testaction:1" question_ref="ocil:ssg-audit_rules_execution_chacl_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_execution_chcon_action:testaction:1" question_ref="ocil:ssg-audit_rules_execution_chcon_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_execution_restorecon_action:testaction:1" question_ref="ocil:ssg-audit_rules_execution_restorecon_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_execution_semanage_action:testaction:1" question_ref="ocil:ssg-audit_rules_execution_semanage_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_execution_setfacl_action:testaction:1" question_ref="ocil:ssg-audit_rules_execution_setfacl_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_execution_setfiles_action:testaction:1" question_ref="ocil:ssg-audit_rules_execution_setfiles_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_execution_setsebool_action:testaction:1" question_ref="ocil:ssg-audit_rules_execution_setsebool_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_execution_seunshare_action:testaction:1" question_ref="ocil:ssg-audit_rules_execution_seunshare_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_file_deletion_events_action:testaction:1" question_ref="ocil:ssg-audit_rules_file_deletion_events_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_file_deletion_events_rename_action:testaction:1" question_ref="ocil:ssg-audit_rules_file_deletion_events_rename_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_file_deletion_events_renameat_action:testaction:1" question_ref="ocil:ssg-audit_rules_file_deletion_events_renameat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_file_deletion_events_rmdir_action:testaction:1" question_ref="ocil:ssg-audit_rules_file_deletion_events_rmdir_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_file_deletion_events_unlink_action:testaction:1" question_ref="ocil:ssg-audit_rules_file_deletion_events_unlink_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_file_deletion_events_unlinkat_action:testaction:1" question_ref="ocil:ssg-audit_rules_file_deletion_events_unlinkat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_for_ospp_action:testaction:1" question_ref="ocil:ssg-audit_rules_for_ospp_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_immutable_action:testaction:1" question_ref="ocil:ssg-audit_rules_immutable_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_immutable_login_uids_action:testaction:1" question_ref="ocil:ssg-audit_rules_immutable_login_uids_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_kernel_module_loading_action:testaction:1" question_ref="ocil:ssg-audit_rules_kernel_module_loading_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_kernel_module_loading_create_action:testaction:1" question_ref="ocil:ssg-audit_rules_kernel_module_loading_create_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_kernel_module_loading_delete_action:testaction:1" question_ref="ocil:ssg-audit_rules_kernel_module_loading_delete_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_kernel_module_loading_finit_action:testaction:1" question_ref="ocil:ssg-audit_rules_kernel_module_loading_finit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_kernel_module_loading_init_action:testaction:1" question_ref="ocil:ssg-audit_rules_kernel_module_loading_init_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_kernel_module_loading_query_action:testaction:1" question_ref="ocil:ssg-audit_rules_kernel_module_loading_query_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_login_events_faillock_action:testaction:1" question_ref="ocil:ssg-audit_rules_login_events_faillock_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_login_events_lastlog_action:testaction:1" question_ref="ocil:ssg-audit_rules_login_events_lastlog_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_login_events_tallylog_action:testaction:1" question_ref="ocil:ssg-audit_rules_login_events_tallylog_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_mac_modification_action:testaction:1" question_ref="ocil:ssg-audit_rules_mac_modification_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_mac_modification_usr_share_action:testaction:1" question_ref="ocil:ssg-audit_rules_mac_modification_usr_share_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_media_export_action:testaction:1" question_ref="ocil:ssg-audit_rules_media_export_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_networkconfig_modification_action:testaction:1" question_ref="ocil:ssg-audit_rules_networkconfig_modification_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_networkconfig_modification_network_scripts_action:testaction:1" question_ref="ocil:ssg-audit_rules_networkconfig_modification_network_scripts_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_at_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_at_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_chage_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_chage_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_chsh_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_chsh_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_crontab_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_crontab_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_gpasswd_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_gpasswd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_kmod_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_kmod_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_mount_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_mount_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_newgidmap_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_newgidmap_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_newgrp_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_newgrp_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_newuidmap_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_newuidmap_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_pam_timestamp_check_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_pam_timestamp_check_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_passwd_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_passwd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_postdrop_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_postdrop_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_postqueue_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_postqueue_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_pt_chown_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_pt_chown_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_ssh_agent_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_ssh_agent_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_ssh_keysign_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_ssh_keysign_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_su_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_su_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_sudo_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_sudo_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_sudoedit_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_sudoedit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_umount_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_umount_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_unix_update_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_unix_update_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_userhelper_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_userhelper_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_usermod_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_usermod_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_privileged_commands_usernetctl_action:testaction:1" question_ref="ocil:ssg-audit_rules_privileged_commands_usernetctl_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_session_events_btmp_action:testaction:1" question_ref="ocil:ssg-audit_rules_session_events_btmp_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_session_events_utmp_action:testaction:1" question_ref="ocil:ssg-audit_rules_session_events_utmp_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_session_events_wtmp_action:testaction:1" question_ref="ocil:ssg-audit_rules_session_events_wtmp_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_chmod_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_chmod_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_chown_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_chown_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_creat_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_creat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_fchmod_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_fchmod_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_fchmodat_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_fchmodat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_fchown_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_fchown_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_fchownat_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_fchownat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_fremovexattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_fremovexattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_fsetxattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_fsetxattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_ftruncate_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_ftruncate_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_lchown_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_lchown_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_lremovexattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_lremovexattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_lsetxattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_lsetxattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_open_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_open_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_o_creat_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_o_creat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_o_trunc_write_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_o_trunc_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_open_o_creat_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_open_o_creat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_open_o_trunc_write_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_open_o_trunc_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_openat_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_openat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_openat_o_creat_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_openat_o_creat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_openat_o_trunc_write_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_openat_o_trunc_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_removexattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_removexattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_rename_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_rename_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_renameat_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_renameat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_setxattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_setxattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_truncate_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_truncate_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_unlink_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_unlink_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_successful_file_modification_unlinkat_action:testaction:1" question_ref="ocil:ssg-audit_rules_successful_file_modification_unlinkat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_sudoers_action:testaction:1" question_ref="ocil:ssg-audit_rules_sudoers_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_sudoers_d_action:testaction:1" question_ref="ocil:ssg-audit_rules_sudoers_d_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_suid_auid_privilege_function_action:testaction:1" question_ref="ocil:ssg-audit_rules_suid_auid_privilege_function_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_suid_privilege_function_action:testaction:1" question_ref="ocil:ssg-audit_rules_suid_privilege_function_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_sysadmin_actions_action:testaction:1" question_ref="ocil:ssg-audit_rules_sysadmin_actions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_system_shutdown_action:testaction:1" question_ref="ocil:ssg-audit_rules_system_shutdown_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_time_adjtimex_action:testaction:1" question_ref="ocil:ssg-audit_rules_time_adjtimex_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_time_clock_settime_action:testaction:1" question_ref="ocil:ssg-audit_rules_time_clock_settime_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_time_settimeofday_action:testaction:1" question_ref="ocil:ssg-audit_rules_time_settimeofday_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_time_stime_action:testaction:1" question_ref="ocil:ssg-audit_rules_time_stime_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_time_watch_localtime_action:testaction:1" question_ref="ocil:ssg-audit_rules_time_watch_localtime_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_chmod_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_chmod_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_chown_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_chown_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_fchmod_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_fchmod_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_fchmodat_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_fchmodat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_fchown_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_fchown_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_fchownat_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_fchownat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_fremovexattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_fremovexattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_fsetxattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_fsetxattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_lchown_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_lchown_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_lremovexattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_lremovexattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_lsetxattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_lsetxattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_open_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_trunc_write_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_trunc_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_creat_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_creat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_trunc_write_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_trunc_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_rule_order_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_open_rule_order_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_creat_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_creat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_trunc_write_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_trunc_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_rule_order_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_rule_order_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_removexattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_removexattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_rename_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_rename_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_renameat_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_renameat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_setxattr_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_setxattr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_unsuccessful_file_modification_unlinkat_action:testaction:1" question_ref="ocil:ssg-audit_rules_unsuccessful_file_modification_unlinkat_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_usergroup_modification_action:testaction:1" question_ref="ocil:ssg-audit_rules_usergroup_modification_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_usergroup_modification_group_action:testaction:1" question_ref="ocil:ssg-audit_rules_usergroup_modification_group_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_usergroup_modification_gshadow_action:testaction:1" question_ref="ocil:ssg-audit_rules_usergroup_modification_gshadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_usergroup_modification_nsswitch_conf_action:testaction:1" question_ref="ocil:ssg-audit_rules_usergroup_modification_nsswitch_conf_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_usergroup_modification_opasswd_action:testaction:1" question_ref="ocil:ssg-audit_rules_usergroup_modification_opasswd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_usergroup_modification_pam_conf_action:testaction:1" question_ref="ocil:ssg-audit_rules_usergroup_modification_pam_conf_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_usergroup_modification_pamd_action:testaction:1" question_ref="ocil:ssg-audit_rules_usergroup_modification_pamd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_usergroup_modification_passwd_action:testaction:1" question_ref="ocil:ssg-audit_rules_usergroup_modification_passwd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_usergroup_modification_shadow_action:testaction:1" question_ref="ocil:ssg-audit_rules_usergroup_modification_shadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_rules_var_spool_cron_action:testaction:1" question_ref="ocil:ssg-audit_rules_var_spool_cron_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-audit_sudo_log_events_action:testaction:1" question_ref="ocil:ssg-audit_sudo_log_events_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_audispd_configure_remote_server_action:testaction:1" question_ref="ocil:ssg-auditd_audispd_configure_remote_server_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_audispd_configure_sufficiently_large_partition_action:testaction:1" question_ref="ocil:ssg-auditd_audispd_configure_sufficiently_large_partition_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_audispd_disk_full_action_action:testaction:1" question_ref="ocil:ssg-auditd_audispd_disk_full_action_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_audispd_encrypt_sent_records_action:testaction:1" question_ref="ocil:ssg-auditd_audispd_encrypt_sent_records_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_audispd_network_failure_action_action:testaction:1" question_ref="ocil:ssg-auditd_audispd_network_failure_action_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_audispd_syslog_plugin_activated_action:testaction:1" question_ref="ocil:ssg-auditd_audispd_syslog_plugin_activated_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_data_disk_error_action_action:testaction:1" question_ref="ocil:ssg-auditd_data_disk_error_action_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_data_disk_error_action_stig_action:testaction:1" question_ref="ocil:ssg-auditd_data_disk_error_action_stig_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_data_disk_full_action_action:testaction:1" question_ref="ocil:ssg-auditd_data_disk_full_action_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_data_disk_full_action_stig_action:testaction:1" question_ref="ocil:ssg-auditd_data_disk_full_action_stig_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_data_retention_action_mail_acct_action:testaction:1" question_ref="ocil:ssg-auditd_data_retention_action_mail_acct_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_data_retention_admin_space_left_action_action:testaction:1" question_ref="ocil:ssg-auditd_data_retention_admin_space_left_action_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_data_retention_admin_space_left_percentage_action:testaction:1" question_ref="ocil:ssg-auditd_data_retention_admin_space_left_percentage_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_data_retention_flush_action:testaction:1" question_ref="ocil:ssg-auditd_data_retention_flush_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_data_retention_max_log_file_action:testaction:1" question_ref="ocil:ssg-auditd_data_retention_max_log_file_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_data_retention_max_log_file_action_action:testaction:1" question_ref="ocil:ssg-auditd_data_retention_max_log_file_action_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_action:testaction:1" question_ref="ocil:ssg-auditd_data_retention_max_log_file_action_stig_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_data_retention_num_logs_action:testaction:1" question_ref="ocil:ssg-auditd_data_retention_num_logs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_data_retention_space_left_action:testaction:1" question_ref="ocil:ssg-auditd_data_retention_space_left_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_data_retention_space_left_action_action:testaction:1" question_ref="ocil:ssg-auditd_data_retention_space_left_action_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_data_retention_space_left_percentage_action:testaction:1" question_ref="ocil:ssg-auditd_data_retention_space_left_percentage_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_freq_action:testaction:1" question_ref="ocil:ssg-auditd_freq_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_local_events_action:testaction:1" question_ref="ocil:ssg-auditd_local_events_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_log_format_action:testaction:1" question_ref="ocil:ssg-auditd_log_format_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_name_format_action:testaction:1" question_ref="ocil:ssg-auditd_name_format_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_overflow_action_action:testaction:1" question_ref="ocil:ssg-auditd_overflow_action_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-auditd_write_logs_action:testaction:1" question_ref="ocil:ssg-auditd_write_logs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-banner_etc_issue_action:testaction:1" question_ref="ocil:ssg-banner_etc_issue_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-banner_etc_issue_cis_action:testaction:1" question_ref="ocil:ssg-banner_etc_issue_cis_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-banner_etc_issue_net_action:testaction:1" question_ref="ocil:ssg-banner_etc_issue_net_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-banner_etc_issue_net_cis_action:testaction:1" question_ref="ocil:ssg-banner_etc_issue_net_cis_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-banner_etc_motd_action:testaction:1" question_ref="ocil:ssg-banner_etc_motd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-banner_etc_motd_cis_action:testaction:1" question_ref="ocil:ssg-banner_etc_motd_cis_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-bios_disable_usb_boot_action:testaction:1" question_ref="ocil:ssg-bios_disable_usb_boot_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-bios_enable_execution_restrictions_action:testaction:1" question_ref="ocil:ssg-bios_enable_execution_restrictions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-chronyd_client_only_action:testaction:1" question_ref="ocil:ssg-chronyd_client_only_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-chronyd_configure_local_socket_action:testaction:1" question_ref="ocil:ssg-chronyd_configure_local_socket_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-chronyd_no_chronyc_network_action:testaction:1" question_ref="ocil:ssg-chronyd_no_chronyc_network_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-chronyd_or_ntpd_set_maxpoll_action:testaction:1" question_ref="ocil:ssg-chronyd_or_ntpd_set_maxpoll_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-chronyd_or_ntpd_specify_remote_server_action:testaction:1" question_ref="ocil:ssg-chronyd_or_ntpd_specify_remote_server_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-chronyd_run_as_chrony_user_action:testaction:1" question_ref="ocil:ssg-chronyd_run_as_chrony_user_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-chronyd_server_directive_action:testaction:1" question_ref="ocil:ssg-chronyd_server_directive_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-chronyd_specify_remote_server_action:testaction:1" question_ref="ocil:ssg-chronyd_specify_remote_server_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-clean_components_post_updating_action:testaction:1" question_ref="ocil:ssg-clean_components_post_updating_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_bashrc_exec_tmux_action:testaction:1" question_ref="ocil:ssg-configure_bashrc_exec_tmux_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_bashrc_tmux_action:testaction:1" question_ref="ocil:ssg-configure_bashrc_tmux_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_bind_crypto_policy_action:testaction:1" question_ref="ocil:ssg-configure_bind_crypto_policy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_crypto_policy_action:testaction:1" question_ref="ocil:ssg-configure_crypto_policy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_custom_crypto_policy_cis_action:testaction:1" question_ref="ocil:ssg-configure_custom_crypto_policy_cis_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_firewalld_ports_action:testaction:1" question_ref="ocil:ssg-configure_firewalld_ports_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_gnutls_tls_crypto_policy_action:testaction:1" question_ref="ocil:ssg-configure_gnutls_tls_crypto_policy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_kerberos_crypto_policy_action:testaction:1" question_ref="ocil:ssg-configure_kerberos_crypto_policy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_libreswan_crypto_policy_action:testaction:1" question_ref="ocil:ssg-configure_libreswan_crypto_policy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_opensc_card_drivers_action:testaction:1" question_ref="ocil:ssg-configure_opensc_card_drivers_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_openssl_crypto_policy_action:testaction:1" question_ref="ocil:ssg-configure_openssl_crypto_policy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_openssl_tls_crypto_policy_action:testaction:1" question_ref="ocil:ssg-configure_openssl_tls_crypto_policy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_ssh_crypto_policy_action:testaction:1" question_ref="ocil:ssg-configure_ssh_crypto_policy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_tmux_lock_after_time_action:testaction:1" question_ref="ocil:ssg-configure_tmux_lock_after_time_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_tmux_lock_command_action:testaction:1" question_ref="ocil:ssg-configure_tmux_lock_command_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_tmux_lock_keybinding_action:testaction:1" question_ref="ocil:ssg-configure_tmux_lock_keybinding_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_usbguard_auditbackend_action:testaction:1" question_ref="ocil:ssg-configure_usbguard_auditbackend_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configure_user_data_backups_action:testaction:1" question_ref="ocil:ssg-configure_user_data_backups_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-configured_firewalld_default_deny_action:testaction:1" question_ref="ocil:ssg-configured_firewalld_default_deny_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-coredump_disable_backtraces_action:testaction:1" question_ref="ocil:ssg-coredump_disable_backtraces_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-coredump_disable_storage_action:testaction:1" question_ref="ocil:ssg-coredump_disable_storage_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-coreos_enable_selinux_kernel_argument_action:testaction:1" question_ref="ocil:ssg-coreos_enable_selinux_kernel_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-cups_disable_browsing_action:testaction:1" question_ref="ocil:ssg-cups_disable_browsing_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_db_up_to_date_action:testaction:1" question_ref="ocil:ssg-dconf_db_up_to_date_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_banner_enabled_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_banner_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_disable_automount_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_disable_automount_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_disable_automount_open_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_disable_automount_open_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_disable_autorun_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_disable_autorun_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_disable_ctrlaltdel_reboot_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_disable_ctrlaltdel_reboot_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_disable_geolocation_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_disable_geolocation_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_disable_power_settings_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_disable_power_settings_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_disable_restart_shutdown_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_disable_restart_shutdown_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_disable_thumbnailers_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_disable_thumbnailers_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_disable_user_admin_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_disable_user_admin_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_disable_user_list_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_disable_user_list_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_disable_wifi_create_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_disable_wifi_create_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_disable_wifi_notification_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_disable_wifi_notification_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_enable_smartcard_auth_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_enable_smartcard_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_lock_screen_on_smartcard_removal_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_lock_screen_on_smartcard_removal_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_login_banner_text_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_login_banner_text_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_login_retries_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_login_retries_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_remote_access_credential_prompt_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_remote_access_credential_prompt_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_remote_access_encryption_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_remote_access_encryption_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_screensaver_idle_activation_enabled_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_screensaver_idle_activation_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_screensaver_idle_activation_locked_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_screensaver_idle_activation_locked_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_screensaver_idle_delay_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_screensaver_idle_delay_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_screensaver_lock_delay_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_screensaver_lock_delay_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_screensaver_lock_enabled_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_screensaver_lock_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_screensaver_lock_locked_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_screensaver_lock_locked_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_screensaver_mode_blank_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_screensaver_mode_blank_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_screensaver_user_info_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_screensaver_user_info_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_screensaver_user_locks_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_screensaver_user_locks_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dconf_gnome_session_idle_user_locks_action:testaction:1" question_ref="ocil:ssg-dconf_gnome_session_idle_user_locks_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dir_group_ownership_library_dirs_action:testaction:1" question_ref="ocil:ssg-dir_group_ownership_library_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dir_ownership_binary_dirs_action:testaction:1" question_ref="ocil:ssg-dir_ownership_binary_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dir_ownership_library_dirs_action:testaction:1" question_ref="ocil:ssg-dir_ownership_library_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dir_permissions_binary_dirs_action:testaction:1" question_ref="ocil:ssg-dir_permissions_binary_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dir_permissions_library_dirs_action:testaction:1" question_ref="ocil:ssg-dir_permissions_library_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dir_perms_etc_httpd_conf_action:testaction:1" question_ref="ocil:ssg-dir_perms_etc_httpd_conf_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dir_perms_var_log_httpd_action:testaction:1" question_ref="ocil:ssg-dir_perms_var_log_httpd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dir_perms_world_writable_root_owned_action:testaction:1" question_ref="ocil:ssg-dir_perms_world_writable_root_owned_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dir_perms_world_writable_sticky_bits_action:testaction:1" question_ref="ocil:ssg-dir_perms_world_writable_sticky_bits_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dir_perms_world_writable_system_owned_action:testaction:1" question_ref="ocil:ssg-dir_perms_world_writable_system_owned_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dir_perms_world_writable_system_owned_group_action:testaction:1" question_ref="ocil:ssg-dir_perms_world_writable_system_owned_group_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dir_system_commands_group_root_owned_action:testaction:1" question_ref="ocil:ssg-dir_system_commands_group_root_owned_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dir_system_commands_root_owned_action:testaction:1" question_ref="ocil:ssg-dir_system_commands_root_owned_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_access_var_log_audit_action:testaction:1" question_ref="ocil:ssg-directory_access_var_log_audit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_group_ownership_var_log_audit_action:testaction:1" question_ref="ocil:ssg-directory_group_ownership_var_log_audit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_groupowner_etc_ipsecd_action:testaction:1" question_ref="ocil:ssg-directory_groupowner_etc_ipsecd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_groupowner_etc_iptables_action:testaction:1" question_ref="ocil:ssg-directory_groupowner_etc_iptables_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_groupowner_etc_nftables_action:testaction:1" question_ref="ocil:ssg-directory_groupowner_etc_nftables_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_groupowner_etc_selinux_action:testaction:1" question_ref="ocil:ssg-directory_groupowner_etc_selinux_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_groupowner_etc_sudoersd_action:testaction:1" question_ref="ocil:ssg-directory_groupowner_etc_sudoersd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_groupowner_etc_sysctld_action:testaction:1" question_ref="ocil:ssg-directory_groupowner_etc_sysctld_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_owner_etc_ipsecd_action:testaction:1" question_ref="ocil:ssg-directory_owner_etc_ipsecd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_owner_etc_iptables_action:testaction:1" question_ref="ocil:ssg-directory_owner_etc_iptables_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_owner_etc_nftables_action:testaction:1" question_ref="ocil:ssg-directory_owner_etc_nftables_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_owner_etc_selinux_action:testaction:1" question_ref="ocil:ssg-directory_owner_etc_selinux_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_owner_etc_sudoersd_action:testaction:1" question_ref="ocil:ssg-directory_owner_etc_sudoersd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_owner_etc_sysctld_action:testaction:1" question_ref="ocil:ssg-directory_owner_etc_sysctld_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_ownership_var_log_audit_action:testaction:1" question_ref="ocil:ssg-directory_ownership_var_log_audit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_permissions_etc_ipsecd_action:testaction:1" question_ref="ocil:ssg-directory_permissions_etc_ipsecd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_permissions_etc_iptables_action:testaction:1" question_ref="ocil:ssg-directory_permissions_etc_iptables_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_permissions_etc_nftables_action:testaction:1" question_ref="ocil:ssg-directory_permissions_etc_nftables_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_permissions_etc_selinux_action:testaction:1" question_ref="ocil:ssg-directory_permissions_etc_selinux_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_permissions_etc_sudoersd_action:testaction:1" question_ref="ocil:ssg-directory_permissions_etc_sudoersd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_permissions_etc_sysctld_action:testaction:1" question_ref="ocil:ssg-directory_permissions_etc_sysctld_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-directory_permissions_var_log_audit_action:testaction:1" question_ref="ocil:ssg-directory_permissions_var_log_audit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-disable_anacron_action:testaction:1" question_ref="ocil:ssg-disable_anacron_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-disable_ctrlaltdel_burstaction_action:testaction:1" question_ref="ocil:ssg-disable_ctrlaltdel_burstaction_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-disable_ctrlaltdel_reboot_action:testaction:1" question_ref="ocil:ssg-disable_ctrlaltdel_reboot_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-disable_host_auth_action:testaction:1" question_ref="ocil:ssg-disable_host_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-disable_users_coredumps_action:testaction:1" question_ref="ocil:ssg-disable_users_coredumps_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-disable_weak_deps_action:testaction:1" question_ref="ocil:ssg-disable_weak_deps_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-disallow_bypass_password_sudo_action:testaction:1" question_ref="ocil:ssg-disallow_bypass_password_sudo_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-display_login_attempts_action:testaction:1" question_ref="ocil:ssg-display_login_attempts_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dnf-automatic_apply_updates_action:testaction:1" question_ref="ocil:ssg-dnf-automatic_apply_updates_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-dnf-automatic_security_updates_only_action:testaction:1" question_ref="ocil:ssg-dnf-automatic_security_updates_only_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-enable_authselect_action:testaction:1" question_ref="ocil:ssg-enable_authselect_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-enable_dconf_user_profile_action:testaction:1" question_ref="ocil:ssg-enable_dconf_user_profile_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-enable_dracut_fips_module_action:testaction:1" question_ref="ocil:ssg-enable_dracut_fips_module_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-enable_fips_mode_action:testaction:1" question_ref="ocil:ssg-enable_fips_mode_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-enable_gpgcheck_for_all_repositories_action:testaction:1" question_ref="ocil:ssg-enable_gpgcheck_for_all_repositories_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-enable_ldap_client_action:testaction:1" question_ref="ocil:ssg-enable_ldap_client_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-enable_pam_namespace_action:testaction:1" question_ref="ocil:ssg-enable_pam_namespace_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-encrypt_partitions_action:testaction:1" question_ref="ocil:ssg-encrypt_partitions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ensure_almalinux_gpgkey_installed_action:testaction:1" question_ref="ocil:ssg-ensure_almalinux_gpgkey_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ensure_epel_repos_disabled_action:testaction:1" question_ref="ocil:ssg-ensure_epel_repos_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1" question_ref="ocil:ssg-ensure_gpgcheck_globally_activated_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ensure_gpgcheck_local_packages_action:testaction:1" question_ref="ocil:ssg-ensure_gpgcheck_local_packages_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ensure_gpgcheck_never_disabled_action:testaction:1" question_ref="ocil:ssg-ensure_gpgcheck_never_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ensure_gpgcheck_repo_metadata_action:testaction:1" question_ref="ocil:ssg-ensure_gpgcheck_repo_metadata_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ensure_logrotate_activated_action:testaction:1" question_ref="ocil:ssg-ensure_logrotate_activated_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ensure_pam_wheel_group_empty_action:testaction:1" question_ref="ocil:ssg-ensure_pam_wheel_group_empty_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ensure_root_password_configured_action:testaction:1" question_ref="ocil:ssg-ensure_root_password_configured_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-etc_system_fips_exists_action:testaction:1" question_ref="ocil:ssg-etc_system_fips_exists_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-fapolicy_default_deny_action:testaction:1" question_ref="ocil:ssg-fapolicy_default_deny_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_at_allow_exists_action:testaction:1" question_ref="ocil:ssg-file_at_allow_exists_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_at_deny_not_exist_action:testaction:1" question_ref="ocil:ssg-file_at_deny_not_exist_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_audit_tools_group_ownership_action:testaction:1" question_ref="ocil:ssg-file_audit_tools_group_ownership_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_audit_tools_ownership_action:testaction:1" question_ref="ocil:ssg-file_audit_tools_ownership_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_audit_tools_permissions_action:testaction:1" question_ref="ocil:ssg-file_audit_tools_permissions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_cron_allow_exists_action:testaction:1" question_ref="ocil:ssg-file_cron_allow_exists_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_cron_deny_not_exist_action:testaction:1" question_ref="ocil:ssg-file_cron_deny_not_exist_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_etc_security_opasswd_action:testaction:1" question_ref="ocil:ssg-file_etc_security_opasswd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_group_ownership_var_log_audit_action:testaction:1" question_ref="ocil:ssg-file_group_ownership_var_log_audit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_at_allow_action:testaction:1" question_ref="ocil:ssg-file_groupowner_at_allow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_backup_etc_group_action:testaction:1" question_ref="ocil:ssg-file_groupowner_backup_etc_group_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_backup_etc_gshadow_action:testaction:1" question_ref="ocil:ssg-file_groupowner_backup_etc_gshadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_backup_etc_passwd_action:testaction:1" question_ref="ocil:ssg-file_groupowner_backup_etc_passwd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_backup_etc_shadow_action:testaction:1" question_ref="ocil:ssg-file_groupowner_backup_etc_shadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_cron_allow_action:testaction:1" question_ref="ocil:ssg-file_groupowner_cron_allow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_cron_d_action:testaction:1" question_ref="ocil:ssg-file_groupowner_cron_d_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_cron_daily_action:testaction:1" question_ref="ocil:ssg-file_groupowner_cron_daily_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_cron_hourly_action:testaction:1" question_ref="ocil:ssg-file_groupowner_cron_hourly_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_cron_monthly_action:testaction:1" question_ref="ocil:ssg-file_groupowner_cron_monthly_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_cron_weekly_action:testaction:1" question_ref="ocil:ssg-file_groupowner_cron_weekly_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_cron_yearly_action:testaction:1" question_ref="ocil:ssg-file_groupowner_cron_yearly_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_crontab_action:testaction:1" question_ref="ocil:ssg-file_groupowner_crontab_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_efi_grub2_cfg_action:testaction:1" question_ref="ocil:ssg-file_groupowner_efi_grub2_cfg_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_efi_user_cfg_action:testaction:1" question_ref="ocil:ssg-file_groupowner_efi_user_cfg_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_etc_chrony_keys_action:testaction:1" question_ref="ocil:ssg-file_groupowner_etc_chrony_keys_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_etc_crypttab_action:testaction:1" question_ref="ocil:ssg-file_groupowner_etc_crypttab_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_etc_group_action:testaction:1" question_ref="ocil:ssg-file_groupowner_etc_group_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_etc_gshadow_action:testaction:1" question_ref="ocil:ssg-file_groupowner_etc_gshadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_etc_ipsec_conf_action:testaction:1" question_ref="ocil:ssg-file_groupowner_etc_ipsec_conf_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_etc_ipsec_secrets_action:testaction:1" question_ref="ocil:ssg-file_groupowner_etc_ipsec_secrets_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_etc_issue_action:testaction:1" question_ref="ocil:ssg-file_groupowner_etc_issue_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_etc_issue_net_action:testaction:1" question_ref="ocil:ssg-file_groupowner_etc_issue_net_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_etc_motd_action:testaction:1" question_ref="ocil:ssg-file_groupowner_etc_motd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_etc_passwd_action:testaction:1" question_ref="ocil:ssg-file_groupowner_etc_passwd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_etc_security_opasswd_action:testaction:1" question_ref="ocil:ssg-file_groupowner_etc_security_opasswd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_etc_security_opasswd_old_action:testaction:1" question_ref="ocil:ssg-file_groupowner_etc_security_opasswd_old_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_etc_sestatus_conf_action:testaction:1" question_ref="ocil:ssg-file_groupowner_etc_sestatus_conf_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_etc_shadow_action:testaction:1" question_ref="ocil:ssg-file_groupowner_etc_shadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_etc_shells_action:testaction:1" question_ref="ocil:ssg-file_groupowner_etc_shells_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_etc_sudoers_action:testaction:1" question_ref="ocil:ssg-file_groupowner_etc_sudoers_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_etc_sysconfig_sshd_action:testaction:1" question_ref="ocil:ssg-file_groupowner_etc_sysconfig_sshd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_grub2_cfg_action:testaction:1" question_ref="ocil:ssg-file_groupowner_grub2_cfg_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_sshd_config_action:testaction:1" question_ref="ocil:ssg-file_groupowner_sshd_config_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_systemmap_action:testaction:1" question_ref="ocil:ssg-file_groupowner_systemmap_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_user_cfg_action:testaction:1" question_ref="ocil:ssg-file_groupowner_user_cfg_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_var_log_action:testaction:1" question_ref="ocil:ssg-file_groupowner_var_log_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_var_log_messages_action:testaction:1" question_ref="ocil:ssg-file_groupowner_var_log_messages_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupowner_var_log_syslog_action:testaction:1" question_ref="ocil:ssg-file_groupowner_var_log_syslog_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupownership_audit_binaries_action:testaction:1" question_ref="ocil:ssg-file_groupownership_audit_binaries_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupownership_audit_configuration_action:testaction:1" question_ref="ocil:ssg-file_groupownership_audit_configuration_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupownership_home_directories_action:testaction:1" question_ref="ocil:ssg-file_groupownership_home_directories_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupownership_sshd_private_key_action:testaction:1" question_ref="ocil:ssg-file_groupownership_sshd_private_key_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupownership_sshd_pub_key_action:testaction:1" question_ref="ocil:ssg-file_groupownership_sshd_pub_key_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_groupownership_system_commands_dirs_action:testaction:1" question_ref="ocil:ssg-file_groupownership_system_commands_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_at_allow_action:testaction:1" question_ref="ocil:ssg-file_owner_at_allow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_backup_etc_group_action:testaction:1" question_ref="ocil:ssg-file_owner_backup_etc_group_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_backup_etc_gshadow_action:testaction:1" question_ref="ocil:ssg-file_owner_backup_etc_gshadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_backup_etc_passwd_action:testaction:1" question_ref="ocil:ssg-file_owner_backup_etc_passwd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_backup_etc_shadow_action:testaction:1" question_ref="ocil:ssg-file_owner_backup_etc_shadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_cron_allow_action:testaction:1" question_ref="ocil:ssg-file_owner_cron_allow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_cron_d_action:testaction:1" question_ref="ocil:ssg-file_owner_cron_d_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_cron_daily_action:testaction:1" question_ref="ocil:ssg-file_owner_cron_daily_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_cron_hourly_action:testaction:1" question_ref="ocil:ssg-file_owner_cron_hourly_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_cron_monthly_action:testaction:1" question_ref="ocil:ssg-file_owner_cron_monthly_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_cron_weekly_action:testaction:1" question_ref="ocil:ssg-file_owner_cron_weekly_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_cron_yearly_action:testaction:1" question_ref="ocil:ssg-file_owner_cron_yearly_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_crontab_action:testaction:1" question_ref="ocil:ssg-file_owner_crontab_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_efi_grub2_cfg_action:testaction:1" question_ref="ocil:ssg-file_owner_efi_grub2_cfg_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_efi_user_cfg_action:testaction:1" question_ref="ocil:ssg-file_owner_efi_user_cfg_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_etc_chrony_keys_action:testaction:1" question_ref="ocil:ssg-file_owner_etc_chrony_keys_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_etc_crypttab_action:testaction:1" question_ref="ocil:ssg-file_owner_etc_crypttab_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_etc_group_action:testaction:1" question_ref="ocil:ssg-file_owner_etc_group_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_etc_gshadow_action:testaction:1" question_ref="ocil:ssg-file_owner_etc_gshadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_etc_ipsec_conf_action:testaction:1" question_ref="ocil:ssg-file_owner_etc_ipsec_conf_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_etc_ipsec_secrets_action:testaction:1" question_ref="ocil:ssg-file_owner_etc_ipsec_secrets_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_etc_issue_action:testaction:1" question_ref="ocil:ssg-file_owner_etc_issue_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_etc_issue_net_action:testaction:1" question_ref="ocil:ssg-file_owner_etc_issue_net_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_etc_motd_action:testaction:1" question_ref="ocil:ssg-file_owner_etc_motd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_etc_passwd_action:testaction:1" question_ref="ocil:ssg-file_owner_etc_passwd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_etc_security_opasswd_action:testaction:1" question_ref="ocil:ssg-file_owner_etc_security_opasswd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_etc_security_opasswd_old_action:testaction:1" question_ref="ocil:ssg-file_owner_etc_security_opasswd_old_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_etc_sestatus_conf_action:testaction:1" question_ref="ocil:ssg-file_owner_etc_sestatus_conf_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_etc_shadow_action:testaction:1" question_ref="ocil:ssg-file_owner_etc_shadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_etc_shells_action:testaction:1" question_ref="ocil:ssg-file_owner_etc_shells_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_etc_sudoers_action:testaction:1" question_ref="ocil:ssg-file_owner_etc_sudoers_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_etc_sysconfig_sshd_action:testaction:1" question_ref="ocil:ssg-file_owner_etc_sysconfig_sshd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_grub2_cfg_action:testaction:1" question_ref="ocil:ssg-file_owner_grub2_cfg_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_sshd_config_action:testaction:1" question_ref="ocil:ssg-file_owner_sshd_config_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_systemmap_action:testaction:1" question_ref="ocil:ssg-file_owner_systemmap_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_user_cfg_action:testaction:1" question_ref="ocil:ssg-file_owner_user_cfg_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_var_log_action:testaction:1" question_ref="ocil:ssg-file_owner_var_log_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_var_log_messages_action:testaction:1" question_ref="ocil:ssg-file_owner_var_log_messages_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_owner_var_log_syslog_action:testaction:1" question_ref="ocil:ssg-file_owner_var_log_syslog_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_ownership_audit_binaries_action:testaction:1" question_ref="ocil:ssg-file_ownership_audit_binaries_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_ownership_audit_configuration_action:testaction:1" question_ref="ocil:ssg-file_ownership_audit_configuration_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_ownership_binary_dirs_action:testaction:1" question_ref="ocil:ssg-file_ownership_binary_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_ownership_home_directories_action:testaction:1" question_ref="ocil:ssg-file_ownership_home_directories_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_ownership_library_dirs_action:testaction:1" question_ref="ocil:ssg-file_ownership_library_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_ownership_sshd_private_key_action:testaction:1" question_ref="ocil:ssg-file_ownership_sshd_private_key_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_ownership_sshd_pub_key_action:testaction:1" question_ref="ocil:ssg-file_ownership_sshd_pub_key_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_ownership_var_log_audit_action:testaction:1" question_ref="ocil:ssg-file_ownership_var_log_audit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_ownership_var_log_audit_stig_action:testaction:1" question_ref="ocil:ssg-file_ownership_var_log_audit_stig_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permission_user_bash_history_action:testaction:1" question_ref="ocil:ssg-file_permission_user_bash_history_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permission_user_init_files_action:testaction:1" question_ref="ocil:ssg-file_permission_user_init_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permission_user_init_files_root_action:testaction:1" question_ref="ocil:ssg-file_permission_user_init_files_root_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_at_allow_action:testaction:1" question_ref="ocil:ssg-file_permissions_at_allow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_audit_binaries_action:testaction:1" question_ref="ocil:ssg-file_permissions_audit_binaries_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_audit_configuration_action:testaction:1" question_ref="ocil:ssg-file_permissions_audit_configuration_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_backup_etc_group_action:testaction:1" question_ref="ocil:ssg-file_permissions_backup_etc_group_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_backup_etc_gshadow_action:testaction:1" question_ref="ocil:ssg-file_permissions_backup_etc_gshadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_backup_etc_passwd_action:testaction:1" question_ref="ocil:ssg-file_permissions_backup_etc_passwd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_backup_etc_shadow_action:testaction:1" question_ref="ocil:ssg-file_permissions_backup_etc_shadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_binary_dirs_action:testaction:1" question_ref="ocil:ssg-file_permissions_binary_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_cron_allow_action:testaction:1" question_ref="ocil:ssg-file_permissions_cron_allow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_cron_d_action:testaction:1" question_ref="ocil:ssg-file_permissions_cron_d_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_cron_daily_action:testaction:1" question_ref="ocil:ssg-file_permissions_cron_daily_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_cron_hourly_action:testaction:1" question_ref="ocil:ssg-file_permissions_cron_hourly_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_cron_monthly_action:testaction:1" question_ref="ocil:ssg-file_permissions_cron_monthly_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_cron_weekly_action:testaction:1" question_ref="ocil:ssg-file_permissions_cron_weekly_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_cron_yearly_action:testaction:1" question_ref="ocil:ssg-file_permissions_cron_yearly_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_crontab_action:testaction:1" question_ref="ocil:ssg-file_permissions_crontab_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_efi_grub2_cfg_action:testaction:1" question_ref="ocil:ssg-file_permissions_efi_grub2_cfg_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_efi_user_cfg_action:testaction:1" question_ref="ocil:ssg-file_permissions_efi_user_cfg_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_audit_auditd_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_audit_auditd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_audit_rulesd_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_audit_rulesd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_chrony_keys_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_chrony_keys_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_crypttab_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_crypttab_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_group_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_group_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_gshadow_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_gshadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_ipsec_conf_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_ipsec_conf_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_ipsec_secrets_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_ipsec_secrets_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_issue_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_issue_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_issue_net_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_issue_net_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_motd_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_motd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_passwd_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_passwd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_security_opasswd_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_security_opasswd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_security_opasswd_old_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_security_opasswd_old_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_sestatus_conf_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_sestatus_conf_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_shadow_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_shadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_shells_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_shells_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_sudoers_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_sudoers_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_etc_sysconfig_sshd_action:testaction:1" question_ref="ocil:ssg-file_permissions_etc_sysconfig_sshd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_grub2_cfg_action:testaction:1" question_ref="ocil:ssg-file_permissions_grub2_cfg_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_home_directories_action:testaction:1" question_ref="ocil:ssg-file_permissions_home_directories_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_home_dirs_action:testaction:1" question_ref="ocil:ssg-file_permissions_home_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_httpd_server_conf_d_files_action:testaction:1" question_ref="ocil:ssg-file_permissions_httpd_server_conf_d_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_httpd_server_conf_files_action:testaction:1" question_ref="ocil:ssg-file_permissions_httpd_server_conf_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_httpd_server_modules_files_action:testaction:1" question_ref="ocil:ssg-file_permissions_httpd_server_modules_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_library_dirs_action:testaction:1" question_ref="ocil:ssg-file_permissions_library_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_sshd_config_action:testaction:1" question_ref="ocil:ssg-file_permissions_sshd_config_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_sshd_private_key_action:testaction:1" question_ref="ocil:ssg-file_permissions_sshd_private_key_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_sshd_pub_key_action:testaction:1" question_ref="ocil:ssg-file_permissions_sshd_pub_key_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_systemmap_action:testaction:1" question_ref="ocil:ssg-file_permissions_systemmap_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_unauthorized_sgid_action:testaction:1" question_ref="ocil:ssg-file_permissions_unauthorized_sgid_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_unauthorized_suid_action:testaction:1" question_ref="ocil:ssg-file_permissions_unauthorized_suid_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_unauthorized_world_writable_action:testaction:1" question_ref="ocil:ssg-file_permissions_unauthorized_world_writable_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_ungroupowned_action:testaction:1" question_ref="ocil:ssg-file_permissions_ungroupowned_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_user_cfg_action:testaction:1" question_ref="ocil:ssg-file_permissions_user_cfg_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_var_log_action:testaction:1" question_ref="ocil:ssg-file_permissions_var_log_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_var_log_audit_action:testaction:1" question_ref="ocil:ssg-file_permissions_var_log_audit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_var_log_messages_action:testaction:1" question_ref="ocil:ssg-file_permissions_var_log_messages_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-file_permissions_var_log_syslog_action:testaction:1" question_ref="ocil:ssg-file_permissions_var_log_syslog_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-fips_crypto_subpolicy_action:testaction:1" question_ref="ocil:ssg-fips_crypto_subpolicy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-fips_custom_stig_sub_policy_action:testaction:1" question_ref="ocil:ssg-fips_custom_stig_sub_policy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firewalld-backend_action:testaction:1" question_ref="ocil:ssg-firewalld-backend_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firewalld_loopback_traffic_restricted_action:testaction:1" question_ref="ocil:ssg-firewalld_loopback_traffic_restricted_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firewalld_loopback_traffic_trusted_action:testaction:1" question_ref="ocil:ssg-firewalld_loopback_traffic_trusted_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-firewalld_sshd_port_enabled_action:testaction:1" question_ref="ocil:ssg-firewalld_sshd_port_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-force_opensc_card_drivers_action:testaction:1" question_ref="ocil:ssg-force_opensc_card_drivers_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ftp_log_transactions_action:testaction:1" question_ref="ocil:ssg-ftp_log_transactions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ftp_present_banner_action:testaction:1" question_ref="ocil:ssg-ftp_present_banner_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-gid_passwd_group_same_action:testaction:1" question_ref="ocil:ssg-gid_passwd_group_same_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-gnome_gdm_disable_automatic_login_action:testaction:1" question_ref="ocil:ssg-gnome_gdm_disable_automatic_login_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-gnome_gdm_disable_guest_login_action:testaction:1" question_ref="ocil:ssg-gnome_gdm_disable_guest_login_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-gnome_gdm_disable_xdmcp_action:testaction:1" question_ref="ocil:ssg-gnome_gdm_disable_xdmcp_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-group_unique_id_action:testaction:1" question_ref="ocil:ssg-group_unique_id_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-group_unique_name_action:testaction:1" question_ref="ocil:ssg-group_unique_name_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-groups_no_zero_gid_except_root_action:testaction:1" question_ref="ocil:ssg-groups_no_zero_gid_except_root_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_admin_username_action:testaction:1" question_ref="ocil:ssg-grub2_admin_username_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_audit_argument_action:testaction:1" question_ref="ocil:ssg-grub2_audit_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_audit_backlog_limit_argument_action:testaction:1" question_ref="ocil:ssg-grub2_audit_backlog_limit_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_disable_interactive_boot_action:testaction:1" question_ref="ocil:ssg-grub2_disable_interactive_boot_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_disable_recovery_action:testaction:1" question_ref="ocil:ssg-grub2_disable_recovery_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_enable_iommu_force_action:testaction:1" question_ref="ocil:ssg-grub2_enable_iommu_force_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_enable_selinux_action:testaction:1" question_ref="ocil:ssg-grub2_enable_selinux_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_ipv6_disable_argument_action:testaction:1" question_ref="ocil:ssg-grub2_ipv6_disable_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_kernel_trust_cpu_rng_action:testaction:1" question_ref="ocil:ssg-grub2_kernel_trust_cpu_rng_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_l1tf_argument_action:testaction:1" question_ref="ocil:ssg-grub2_l1tf_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_mce_argument_action:testaction:1" question_ref="ocil:ssg-grub2_mce_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_no_removeable_media_action:testaction:1" question_ref="ocil:ssg-grub2_no_removeable_media_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_nosmap_argument_absent_action:testaction:1" question_ref="ocil:ssg-grub2_nosmap_argument_absent_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_nosmep_argument_absent_action:testaction:1" question_ref="ocil:ssg-grub2_nosmep_argument_absent_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_nousb_argument_action:testaction:1" question_ref="ocil:ssg-grub2_nousb_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_page_poison_argument_action:testaction:1" question_ref="ocil:ssg-grub2_page_poison_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_password_action:testaction:1" question_ref="ocil:ssg-grub2_password_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_pti_argument_action:testaction:1" question_ref="ocil:ssg-grub2_pti_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_rng_core_default_quality_argument_action:testaction:1" question_ref="ocil:ssg-grub2_rng_core_default_quality_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_slab_nomerge_argument_action:testaction:1" question_ref="ocil:ssg-grub2_slab_nomerge_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_slub_debug_argument_action:testaction:1" question_ref="ocil:ssg-grub2_slub_debug_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_spec_store_bypass_disable_argument_action:testaction:1" question_ref="ocil:ssg-grub2_spec_store_bypass_disable_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_spectre_v2_argument_action:testaction:1" question_ref="ocil:ssg-grub2_spectre_v2_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_systemd_debug-shell_argument_absent_action:testaction:1" question_ref="ocil:ssg-grub2_systemd_debug-shell_argument_absent_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_uefi_admin_username_action:testaction:1" question_ref="ocil:ssg-grub2_uefi_admin_username_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_uefi_password_action:testaction:1" question_ref="ocil:ssg-grub2_uefi_password_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-grub2_vsyscall_argument_action:testaction:1" question_ref="ocil:ssg-grub2_vsyscall_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-harden_openssl_crypto_policy_action:testaction:1" question_ref="ocil:ssg-harden_openssl_crypto_policy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-harden_ssh_client_crypto_policy_action:testaction:1" question_ref="ocil:ssg-harden_ssh_client_crypto_policy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-harden_sshd_ciphers_openssh_conf_crypto_policy_action:testaction:1" question_ref="ocil:ssg-harden_sshd_ciphers_openssh_conf_crypto_policy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-harden_sshd_ciphers_opensshserver_conf_crypto_policy_action:testaction:1" question_ref="ocil:ssg-harden_sshd_ciphers_opensshserver_conf_crypto_policy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-harden_sshd_crypto_policy_action:testaction:1" question_ref="ocil:ssg-harden_sshd_crypto_policy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-harden_sshd_macs_openssh_conf_crypto_policy_action:testaction:1" question_ref="ocil:ssg-harden_sshd_macs_openssh_conf_crypto_policy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-harden_sshd_macs_opensshserver_conf_crypto_policy_action:testaction:1" question_ref="ocil:ssg-harden_sshd_macs_opensshserver_conf_crypto_policy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-has_nonlocal_mta_action:testaction:1" question_ref="ocil:ssg-has_nonlocal_mta_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-http_configure_log_file_ownership_action:testaction:1" question_ref="ocil:ssg-http_configure_log_file_ownership_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_anonymous_content_sharing_action:testaction:1" question_ref="ocil:ssg-httpd_anonymous_content_sharing_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_antivirus_scan_uploads_action:testaction:1" question_ref="ocil:ssg-httpd_antivirus_scan_uploads_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_configure_banner_page_action:testaction:1" question_ref="ocil:ssg-httpd_configure_banner_page_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_configure_documentroot_action:testaction:1" question_ref="ocil:ssg-httpd_configure_documentroot_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_configure_firewall_action:testaction:1" question_ref="ocil:ssg-httpd_configure_firewall_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_configure_log_format_action:testaction:1" question_ref="ocil:ssg-httpd_configure_log_format_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_configure_max_keepalive_requests_action:testaction:1" question_ref="ocil:ssg-httpd_configure_max_keepalive_requests_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_configure_perl_taint_action:testaction:1" question_ref="ocil:ssg-httpd_configure_perl_taint_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_configure_remote_session_encryption_action:testaction:1" question_ref="ocil:ssg-httpd_configure_remote_session_encryption_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_configure_script_permissions_action:testaction:1" question_ref="ocil:ssg-httpd_configure_script_permissions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_configure_tls_action:testaction:1" question_ref="ocil:ssg-httpd_configure_tls_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_configure_valid_server_cert_action:testaction:1" question_ref="ocil:ssg-httpd_configure_valid_server_cert_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_disable_anonymous_ftp_access_action:testaction:1" question_ref="ocil:ssg-httpd_disable_anonymous_ftp_access_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_disable_content_symlinks_action:testaction:1" question_ref="ocil:ssg-httpd_disable_content_symlinks_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_disable_mime_types_action:testaction:1" question_ref="ocil:ssg-httpd_disable_mime_types_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_enable_error_logging_action:testaction:1" question_ref="ocil:ssg-httpd_enable_error_logging_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_enable_log_config_action:testaction:1" question_ref="ocil:ssg-httpd_enable_log_config_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_enable_loglevel_action:testaction:1" question_ref="ocil:ssg-httpd_enable_loglevel_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_enable_system_logging_action:testaction:1" question_ref="ocil:ssg-httpd_enable_system_logging_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_encrypt_file_uploads_action:testaction:1" question_ref="ocil:ssg-httpd_encrypt_file_uploads_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_entrust_passwords_action:testaction:1" question_ref="ocil:ssg-httpd_entrust_passwords_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_ignore_htaccess_files_action:testaction:1" question_ref="ocil:ssg-httpd_ignore_htaccess_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_limit_java_files_action:testaction:1" question_ref="ocil:ssg-httpd_limit_java_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_nipr_accredited_dmz_action:testaction:1" question_ref="ocil:ssg-httpd_nipr_accredited_dmz_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_no_compilers_in_prod_action:testaction:1" question_ref="ocil:ssg-httpd_no_compilers_in_prod_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_private_server_on_separate_subnet_action:testaction:1" question_ref="ocil:ssg-httpd_private_server_on_separate_subnet_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_public_resources_not_shared_action:testaction:1" question_ref="ocil:ssg-httpd_public_resources_not_shared_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_remove_backups_action:testaction:1" question_ref="ocil:ssg-httpd_remove_backups_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_remove_robots_file_action:testaction:1" question_ref="ocil:ssg-httpd_remove_robots_file_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-httpd_require_client_certs_action:testaction:1" question_ref="ocil:ssg-httpd_require_client_certs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-install_antivirus_action:testaction:1" question_ref="ocil:ssg-install_antivirus_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-install_hids_action:testaction:1" question_ref="ocil:ssg-install_hids_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-install_mcafee_antivirus_action:testaction:1" question_ref="ocil:ssg-install_mcafee_antivirus_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-install_mcafee_cma_rt_action:testaction:1" question_ref="ocil:ssg-install_mcafee_cma_rt_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-install_mcafee_hbss_accm_action:testaction:1" question_ref="ocil:ssg-install_mcafee_hbss_accm_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-install_mcafee_hbss_pa_action:testaction:1" question_ref="ocil:ssg-install_mcafee_hbss_pa_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-install_smartcard_packages_action:testaction:1" question_ref="ocil:ssg-install_smartcard_packages_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-installed_OS_is_FIPS_certified_action:testaction:1" question_ref="ocil:ssg-installed_OS_is_FIPS_certified_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-installed_OS_is_vendor_supported_action:testaction:1" question_ref="ocil:ssg-installed_OS_is_vendor_supported_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ip6tables_rules_for_open_ports_action:testaction:1" question_ref="ocil:ssg-ip6tables_rules_for_open_ports_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-iptables_rules_for_open_ports_action:testaction:1" question_ref="ocil:ssg-iptables_rules_for_open_ports_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-journald_compress_action:testaction:1" question_ref="ocil:ssg-journald_compress_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-journald_disable_forward_to_syslog_action:testaction:1" question_ref="ocil:ssg-journald_disable_forward_to_syslog_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-journald_forward_to_syslog_action:testaction:1" question_ref="ocil:ssg-journald_forward_to_syslog_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-journald_storage_action:testaction:1" question_ref="ocil:ssg-journald_storage_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kerberos_disable_no_keytab_action:testaction:1" question_ref="ocil:ssg-kerberos_disable_no_keytab_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_acpi_custom_method_action:testaction:1" question_ref="ocil:ssg-kernel_config_acpi_custom_method_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_action:testaction:1" question_ref="ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_binfmt_misc_action:testaction:1" question_ref="ocil:ssg-kernel_config_binfmt_misc_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_bug_action:testaction:1" question_ref="ocil:ssg-kernel_config_bug_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_bug_on_data_corruption_action:testaction:1" question_ref="ocil:ssg-kernel_config_bug_on_data_corruption_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_compat_brk_action:testaction:1" question_ref="ocil:ssg-kernel_config_compat_brk_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_compat_vdso_action:testaction:1" question_ref="ocil:ssg-kernel_config_compat_vdso_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_debug_credentials_action:testaction:1" question_ref="ocil:ssg-kernel_config_debug_credentials_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_debug_fs_action:testaction:1" question_ref="ocil:ssg-kernel_config_debug_fs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_debug_list_action:testaction:1" question_ref="ocil:ssg-kernel_config_debug_list_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_debug_notifiers_action:testaction:1" question_ref="ocil:ssg-kernel_config_debug_notifiers_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_debug_sg_action:testaction:1" question_ref="ocil:ssg-kernel_config_debug_sg_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_debug_wx_action:testaction:1" question_ref="ocil:ssg-kernel_config_debug_wx_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_default_mmap_min_addr_action:testaction:1" question_ref="ocil:ssg-kernel_config_default_mmap_min_addr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_devkmem_action:testaction:1" question_ref="ocil:ssg-kernel_config_devkmem_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_fortify_source_action:testaction:1" question_ref="ocil:ssg-kernel_config_fortify_source_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_gcc_plugin_latent_entropy_action:testaction:1" question_ref="ocil:ssg-kernel_config_gcc_plugin_latent_entropy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_gcc_plugin_structleak_action:testaction:1" question_ref="ocil:ssg-kernel_config_gcc_plugin_structleak_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_hardened_usercopy_action:testaction:1" question_ref="ocil:ssg-kernel_config_hardened_usercopy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_hardened_usercopy_fallback_action:testaction:1" question_ref="ocil:ssg-kernel_config_hardened_usercopy_fallback_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_hibernation_action:testaction:1" question_ref="ocil:ssg-kernel_config_hibernation_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_ia32_emulation_action:testaction:1" question_ref="ocil:ssg-kernel_config_ia32_emulation_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_ipv6_action:testaction:1" question_ref="ocil:ssg-kernel_config_ipv6_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_kexec_action:testaction:1" question_ref="ocil:ssg-kernel_config_kexec_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_legacy_ptys_action:testaction:1" question_ref="ocil:ssg-kernel_config_legacy_ptys_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_legacy_vsyscall_emulate_action:testaction:1" question_ref="ocil:ssg-kernel_config_legacy_vsyscall_emulate_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_legacy_vsyscall_none_action:testaction:1" question_ref="ocil:ssg-kernel_config_legacy_vsyscall_none_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_modify_ldt_syscall_action:testaction:1" question_ref="ocil:ssg-kernel_config_modify_ldt_syscall_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_module_sig_action:testaction:1" question_ref="ocil:ssg-kernel_config_module_sig_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_module_sig_all_action:testaction:1" question_ref="ocil:ssg-kernel_config_module_sig_all_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_module_sig_force_action:testaction:1" question_ref="ocil:ssg-kernel_config_module_sig_force_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_module_sig_hash_action:testaction:1" question_ref="ocil:ssg-kernel_config_module_sig_hash_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_module_sig_key_action:testaction:1" question_ref="ocil:ssg-kernel_config_module_sig_key_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_module_sig_sha512_action:testaction:1" question_ref="ocil:ssg-kernel_config_module_sig_sha512_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_page_poisoning_action:testaction:1" question_ref="ocil:ssg-kernel_config_page_poisoning_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_page_poisoning_no_sanity_action:testaction:1" question_ref="ocil:ssg-kernel_config_page_poisoning_no_sanity_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_page_poisoning_zero_action:testaction:1" question_ref="ocil:ssg-kernel_config_page_poisoning_zero_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_page_table_isolation_action:testaction:1" question_ref="ocil:ssg-kernel_config_page_table_isolation_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_panic_on_oops_action:testaction:1" question_ref="ocil:ssg-kernel_config_panic_on_oops_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_panic_timeout_action:testaction:1" question_ref="ocil:ssg-kernel_config_panic_timeout_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_proc_kcore_action:testaction:1" question_ref="ocil:ssg-kernel_config_proc_kcore_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_randomize_base_action:testaction:1" question_ref="ocil:ssg-kernel_config_randomize_base_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_randomize_memory_action:testaction:1" question_ref="ocil:ssg-kernel_config_randomize_memory_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_refcount_full_action:testaction:1" question_ref="ocil:ssg-kernel_config_refcount_full_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_retpoline_action:testaction:1" question_ref="ocil:ssg-kernel_config_retpoline_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_sched_stack_end_check_action:testaction:1" question_ref="ocil:ssg-kernel_config_sched_stack_end_check_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_seccomp_action:testaction:1" question_ref="ocil:ssg-kernel_config_seccomp_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_seccomp_filter_action:testaction:1" question_ref="ocil:ssg-kernel_config_seccomp_filter_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_security_action:testaction:1" question_ref="ocil:ssg-kernel_config_security_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_security_dmesg_restrict_action:testaction:1" question_ref="ocil:ssg-kernel_config_security_dmesg_restrict_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_security_writable_hooks_action:testaction:1" question_ref="ocil:ssg-kernel_config_security_writable_hooks_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_security_yama_action:testaction:1" question_ref="ocil:ssg-kernel_config_security_yama_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_slab_freelist_hardened_action:testaction:1" question_ref="ocil:ssg-kernel_config_slab_freelist_hardened_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_slab_freelist_random_action:testaction:1" question_ref="ocil:ssg-kernel_config_slab_freelist_random_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_slab_merge_default_action:testaction:1" question_ref="ocil:ssg-kernel_config_slab_merge_default_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_slub_debug_action:testaction:1" question_ref="ocil:ssg-kernel_config_slub_debug_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_stackprotector_action:testaction:1" question_ref="ocil:ssg-kernel_config_stackprotector_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_stackprotector_strong_action:testaction:1" question_ref="ocil:ssg-kernel_config_stackprotector_strong_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_strict_kernel_rwx_action:testaction:1" question_ref="ocil:ssg-kernel_config_strict_kernel_rwx_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_strict_module_rwx_action:testaction:1" question_ref="ocil:ssg-kernel_config_strict_module_rwx_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_syn_cookies_action:testaction:1" question_ref="ocil:ssg-kernel_config_syn_cookies_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_unmap_kernel_at_el0_action:testaction:1" question_ref="ocil:ssg-kernel_config_unmap_kernel_at_el0_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_vmap_stack_action:testaction:1" question_ref="ocil:ssg-kernel_config_vmap_stack_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_config_x86_vsyscall_emulation_action:testaction:1" question_ref="ocil:ssg-kernel_config_x86_vsyscall_emulation_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_module_atm_disabled_action:testaction:1" question_ref="ocil:ssg-kernel_module_atm_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_module_bluetooth_disabled_action:testaction:1" question_ref="ocil:ssg-kernel_module_bluetooth_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_module_can_disabled_action:testaction:1" question_ref="ocil:ssg-kernel_module_can_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_module_cfg80211_disabled_action:testaction:1" question_ref="ocil:ssg-kernel_module_cfg80211_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_module_cramfs_disabled_action:testaction:1" question_ref="ocil:ssg-kernel_module_cramfs_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_module_dccp_disabled_action:testaction:1" question_ref="ocil:ssg-kernel_module_dccp_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_module_firewire-core_disabled_action:testaction:1" question_ref="ocil:ssg-kernel_module_firewire-core_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_module_ipv6_option_disabled_action:testaction:1" question_ref="ocil:ssg-kernel_module_ipv6_option_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_module_iwlmvm_disabled_action:testaction:1" question_ref="ocil:ssg-kernel_module_iwlmvm_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_module_iwlwifi_disabled_action:testaction:1" question_ref="ocil:ssg-kernel_module_iwlwifi_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_module_mac80211_disabled_action:testaction:1" question_ref="ocil:ssg-kernel_module_mac80211_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_module_rds_disabled_action:testaction:1" question_ref="ocil:ssg-kernel_module_rds_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_module_sctp_disabled_action:testaction:1" question_ref="ocil:ssg-kernel_module_sctp_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_module_tipc_disabled_action:testaction:1" question_ref="ocil:ssg-kernel_module_tipc_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_module_usb-storage_disabled_action:testaction:1" question_ref="ocil:ssg-kernel_module_usb-storage_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-kernel_module_uvcvideo_disabled_action:testaction:1" question_ref="ocil:ssg-kernel_module_uvcvideo_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ldap_client_start_tls_action:testaction:1" question_ref="ocil:ssg-ldap_client_start_tls_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ldap_client_tls_cacertpath_action:testaction:1" question_ref="ocil:ssg-ldap_client_tls_cacertpath_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-libreswan_approved_tunnels_action:testaction:1" question_ref="ocil:ssg-libreswan_approved_tunnels_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-logind_session_timeout_action:testaction:1" question_ref="ocil:ssg-logind_session_timeout_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mcafee_antivirus_definitions_updated_action:testaction:1" question_ref="ocil:ssg-mcafee_antivirus_definitions_updated_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_boot_efi_nosuid_action:testaction:1" question_ref="ocil:ssg-mount_option_boot_efi_nosuid_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_boot_noauto_action:testaction:1" question_ref="ocil:ssg-mount_option_boot_noauto_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_boot_nodev_action:testaction:1" question_ref="ocil:ssg-mount_option_boot_nodev_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_boot_noexec_action:testaction:1" question_ref="ocil:ssg-mount_option_boot_noexec_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_boot_nosuid_action:testaction:1" question_ref="ocil:ssg-mount_option_boot_nosuid_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_dev_shm_nodev_action:testaction:1" question_ref="ocil:ssg-mount_option_dev_shm_nodev_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_dev_shm_noexec_action:testaction:1" question_ref="ocil:ssg-mount_option_dev_shm_noexec_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_dev_shm_nosuid_action:testaction:1" question_ref="ocil:ssg-mount_option_dev_shm_nosuid_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_home_grpquota_action:testaction:1" question_ref="ocil:ssg-mount_option_home_grpquota_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_home_nodev_action:testaction:1" question_ref="ocil:ssg-mount_option_home_nodev_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_home_noexec_action:testaction:1" question_ref="ocil:ssg-mount_option_home_noexec_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_home_nosuid_action:testaction:1" question_ref="ocil:ssg-mount_option_home_nosuid_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_home_usrquota_action:testaction:1" question_ref="ocil:ssg-mount_option_home_usrquota_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_krb_sec_remote_filesystems_action:testaction:1" question_ref="ocil:ssg-mount_option_krb_sec_remote_filesystems_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_nodev_nonroot_local_partitions_action:testaction:1" question_ref="ocil:ssg-mount_option_nodev_nonroot_local_partitions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_nodev_remote_filesystems_action:testaction:1" question_ref="ocil:ssg-mount_option_nodev_remote_filesystems_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_nodev_removable_partitions_action:testaction:1" question_ref="ocil:ssg-mount_option_nodev_removable_partitions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_noexec_remote_filesystems_action:testaction:1" question_ref="ocil:ssg-mount_option_noexec_remote_filesystems_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_noexec_removable_partitions_action:testaction:1" question_ref="ocil:ssg-mount_option_noexec_removable_partitions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_nosuid_remote_filesystems_action:testaction:1" question_ref="ocil:ssg-mount_option_nosuid_remote_filesystems_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_nosuid_removable_partitions_action:testaction:1" question_ref="ocil:ssg-mount_option_nosuid_removable_partitions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_opt_nosuid_action:testaction:1" question_ref="ocil:ssg-mount_option_opt_nosuid_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_proc_hidepid_action:testaction:1" question_ref="ocil:ssg-mount_option_proc_hidepid_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_smb_client_signing_action:testaction:1" question_ref="ocil:ssg-mount_option_smb_client_signing_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_srv_nosuid_action:testaction:1" question_ref="ocil:ssg-mount_option_srv_nosuid_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_tmp_nodev_action:testaction:1" question_ref="ocil:ssg-mount_option_tmp_nodev_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_tmp_noexec_action:testaction:1" question_ref="ocil:ssg-mount_option_tmp_noexec_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_tmp_nosuid_action:testaction:1" question_ref="ocil:ssg-mount_option_tmp_nosuid_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_var_log_audit_nodev_action:testaction:1" question_ref="ocil:ssg-mount_option_var_log_audit_nodev_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_var_log_audit_noexec_action:testaction:1" question_ref="ocil:ssg-mount_option_var_log_audit_noexec_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_var_log_audit_nosuid_action:testaction:1" question_ref="ocil:ssg-mount_option_var_log_audit_nosuid_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_var_log_nodev_action:testaction:1" question_ref="ocil:ssg-mount_option_var_log_nodev_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_var_log_noexec_action:testaction:1" question_ref="ocil:ssg-mount_option_var_log_noexec_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_var_log_nosuid_action:testaction:1" question_ref="ocil:ssg-mount_option_var_log_nosuid_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_var_nodev_action:testaction:1" question_ref="ocil:ssg-mount_option_var_nodev_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_var_noexec_action:testaction:1" question_ref="ocil:ssg-mount_option_var_noexec_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_var_nosuid_action:testaction:1" question_ref="ocil:ssg-mount_option_var_nosuid_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_var_tmp_nodev_action:testaction:1" question_ref="ocil:ssg-mount_option_var_tmp_nodev_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_var_tmp_noexec_action:testaction:1" question_ref="ocil:ssg-mount_option_var_tmp_noexec_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-mount_option_var_tmp_nosuid_action:testaction:1" question_ref="ocil:ssg-mount_option_var_tmp_nosuid_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-network_configure_name_resolution_action:testaction:1" question_ref="ocil:ssg-network_configure_name_resolution_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-network_disable_ddns_interfaces_action:testaction:1" question_ref="ocil:ssg-network_disable_ddns_interfaces_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-network_nmcli_permissions_action:testaction:1" question_ref="ocil:ssg-network_nmcli_permissions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-network_sniffer_disabled_action:testaction:1" question_ref="ocil:ssg-network_sniffer_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-nfs_no_anonymous_action:testaction:1" question_ref="ocil:ssg-nfs_no_anonymous_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_all_squash_exports_action:testaction:1" question_ref="ocil:ssg-no_all_squash_exports_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_direct_root_logins_action:testaction:1" question_ref="ocil:ssg-no_direct_root_logins_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_empty_passwords_action:testaction:1" question_ref="ocil:ssg-no_empty_passwords_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_empty_passwords_etc_shadow_action:testaction:1" question_ref="ocil:ssg-no_empty_passwords_etc_shadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_files_or_dirs_ungroupowned_action:testaction:1" question_ref="ocil:ssg-no_files_or_dirs_ungroupowned_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_files_or_dirs_unowned_by_user_action:testaction:1" question_ref="ocil:ssg-no_files_or_dirs_unowned_by_user_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_files_unowned_by_user_action:testaction:1" question_ref="ocil:ssg-no_files_unowned_by_user_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_forward_files_action:testaction:1" question_ref="ocil:ssg-no_forward_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_host_based_files_action:testaction:1" question_ref="ocil:ssg-no_host_based_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_insecure_locks_exports_action:testaction:1" question_ref="ocil:ssg-no_insecure_locks_exports_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_legacy_plus_entries_etc_group_action:testaction:1" question_ref="ocil:ssg-no_legacy_plus_entries_etc_group_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_legacy_plus_entries_etc_passwd_action:testaction:1" question_ref="ocil:ssg-no_legacy_plus_entries_etc_passwd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_legacy_plus_entries_etc_shadow_action:testaction:1" question_ref="ocil:ssg-no_legacy_plus_entries_etc_shadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_netrc_files_action:testaction:1" question_ref="ocil:ssg-no_netrc_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_nis_in_nsswitch_action:testaction:1" question_ref="ocil:ssg-no_nis_in_nsswitch_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_nologin_in_shells_action:testaction:1" question_ref="ocil:ssg-no_nologin_in_shells_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_password_auth_for_systemaccounts_action:testaction:1" question_ref="ocil:ssg-no_password_auth_for_systemaccounts_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_rhost_files_action:testaction:1" question_ref="ocil:ssg-no_rhost_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_root_webbrowsing_action:testaction:1" question_ref="ocil:ssg-no_root_webbrowsing_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_rsh_trust_files_action:testaction:1" question_ref="ocil:ssg-no_rsh_trust_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_shelllogin_for_systemaccounts_action:testaction:1" question_ref="ocil:ssg-no_shelllogin_for_systemaccounts_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_tmux_in_shells_action:testaction:1" question_ref="ocil:ssg-no_tmux_in_shells_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-no_user_host_based_files_action:testaction:1" question_ref="ocil:ssg-no_user_host_based_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ntpd_specify_remote_server_action:testaction:1" question_ref="ocil:ssg-ntpd_specify_remote_server_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-openssl_use_strong_entropy_action:testaction:1" question_ref="ocil:ssg-openssl_use_strong_entropy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_389-ds-base_removed_action:testaction:1" question_ref="ocil:ssg-package_389-ds-base_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_MFEhiplsm_installed_action:testaction:1" question_ref="ocil:ssg-package_MFEhiplsm_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_abrt-addon-ccpp_removed_action:testaction:1" question_ref="ocil:ssg-package_abrt-addon-ccpp_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_abrt-addon-kerneloops_removed_action:testaction:1" question_ref="ocil:ssg-package_abrt-addon-kerneloops_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_abrt-cli_removed_action:testaction:1" question_ref="ocil:ssg-package_abrt-cli_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_abrt-plugin-logger_removed_action:testaction:1" question_ref="ocil:ssg-package_abrt-plugin-logger_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_abrt-plugin-rhtsupport_removed_action:testaction:1" question_ref="ocil:ssg-package_abrt-plugin-rhtsupport_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_abrt-plugin-sosreport_removed_action:testaction:1" question_ref="ocil:ssg-package_abrt-plugin-sosreport_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_abrt_removed_action:testaction:1" question_ref="ocil:ssg-package_abrt_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_aide_installed_action:testaction:1" question_ref="ocil:ssg-package_aide_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_audispd-plugins_installed_action:testaction:1" question_ref="ocil:ssg-package_audispd-plugins_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_audit-audispd-plugins_installed_action:testaction:1" question_ref="ocil:ssg-package_audit-audispd-plugins_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_audit-libs_installed_action:testaction:1" question_ref="ocil:ssg-package_audit-libs_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_audit_installed_action:testaction:1" question_ref="ocil:ssg-package_audit_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_authselect_installed_action:testaction:1" question_ref="ocil:ssg-package_authselect_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_avahi-autoipd_removed_action:testaction:1" question_ref="ocil:ssg-package_avahi-autoipd_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_avahi_removed_action:testaction:1" question_ref="ocil:ssg-package_avahi_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_bind_removed_action:testaction:1" question_ref="ocil:ssg-package_bind_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_binutils_installed_action:testaction:1" question_ref="ocil:ssg-package_binutils_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_chrony_installed_action:testaction:1" question_ref="ocil:ssg-package_chrony_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_cron_installed_action:testaction:1" question_ref="ocil:ssg-package_cron_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_crypto-policies_installed_action:testaction:1" question_ref="ocil:ssg-package_crypto-policies_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_cups_removed_action:testaction:1" question_ref="ocil:ssg-package_cups_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_cyrus-imapd_removed_action:testaction:1" question_ref="ocil:ssg-package_cyrus-imapd_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_dhcp_removed_action:testaction:1" question_ref="ocil:ssg-package_dhcp_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_dnf-automatic_installed_action:testaction:1" question_ref="ocil:ssg-package_dnf-automatic_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_dnf-plugin-subscription-manager_installed_action:testaction:1" question_ref="ocil:ssg-package_dnf-plugin-subscription-manager_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_dnsmasq_removed_action:testaction:1" question_ref="ocil:ssg-package_dnsmasq_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_dovecot_removed_action:testaction:1" question_ref="ocil:ssg-package_dovecot_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_fapolicyd_installed_action:testaction:1" question_ref="ocil:ssg-package_fapolicyd_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_firewalld_installed_action:testaction:1" question_ref="ocil:ssg-package_firewalld_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_freeradius_removed_action:testaction:1" question_ref="ocil:ssg-package_freeradius_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_ftp_removed_action:testaction:1" question_ref="ocil:ssg-package_ftp_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_gdm_removed_action:testaction:1" question_ref="ocil:ssg-package_gdm_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_geolite2-city_removed_action:testaction:1" question_ref="ocil:ssg-package_geolite2-city_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_geolite2-country_removed_action:testaction:1" question_ref="ocil:ssg-package_geolite2-country_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_gnutls-utils_installed_action:testaction:1" question_ref="ocil:ssg-package_gnutls-utils_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_gssproxy_removed_action:testaction:1" question_ref="ocil:ssg-package_gssproxy_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_httpd_removed_action:testaction:1" question_ref="ocil:ssg-package_httpd_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_iprutils_removed_action:testaction:1" question_ref="ocil:ssg-package_iprutils_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_iptables-services_installed_action:testaction:1" question_ref="ocil:ssg-package_iptables-services_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_iptables-services_removed_action:testaction:1" question_ref="ocil:ssg-package_iptables-services_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_iptables_installed_action:testaction:1" question_ref="ocil:ssg-package_iptables_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_krb5-server_removed_action:testaction:1" question_ref="ocil:ssg-package_krb5-server_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_krb5-workstation_removed_action:testaction:1" question_ref="ocil:ssg-package_krb5-workstation_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_libcap-ng-utils_installed_action:testaction:1" question_ref="ocil:ssg-package_libcap-ng-utils_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_libreport-plugin-logger_removed_action:testaction:1" question_ref="ocil:ssg-package_libreport-plugin-logger_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_libreport-plugin-rhtsupport_removed_action:testaction:1" question_ref="ocil:ssg-package_libreport-plugin-rhtsupport_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_libreswan_installed_action:testaction:1" question_ref="ocil:ssg-package_libreswan_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_libselinux_installed_action:testaction:1" question_ref="ocil:ssg-package_libselinux_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_logrotate_installed_action:testaction:1" question_ref="ocil:ssg-package_logrotate_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_mailx_installed_action:testaction:1" question_ref="ocil:ssg-package_mailx_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_mcafeetp_installed_action:testaction:1" question_ref="ocil:ssg-package_mcafeetp_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_net-snmp_removed_action:testaction:1" question_ref="ocil:ssg-package_net-snmp_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_nfs-utils_removed_action:testaction:1" question_ref="ocil:ssg-package_nfs-utils_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_nftables_installed_action:testaction:1" question_ref="ocil:ssg-package_nftables_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_nginx_removed_action:testaction:1" question_ref="ocil:ssg-package_nginx_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_nss-tools_installed_action:testaction:1" question_ref="ocil:ssg-package_nss-tools_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_ntp_installed_action:testaction:1" question_ref="ocil:ssg-package_ntp_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_openldap-clients_removed_action:testaction:1" question_ref="ocil:ssg-package_openldap-clients_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_openldap-servers_removed_action:testaction:1" question_ref="ocil:ssg-package_openldap-servers_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_opensc_installed_action:testaction:1" question_ref="ocil:ssg-package_opensc_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_openscap-scanner_installed_action:testaction:1" question_ref="ocil:ssg-package_openscap-scanner_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_openssh-clients_installed_action:testaction:1" question_ref="ocil:ssg-package_openssh-clients_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_openssh-server_installed_action:testaction:1" question_ref="ocil:ssg-package_openssh-server_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_openssh-server_removed_action:testaction:1" question_ref="ocil:ssg-package_openssh-server_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_pam_installed_action:testaction:1" question_ref="ocil:ssg-package_pam_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_pam_pwquality_installed_action:testaction:1" question_ref="ocil:ssg-package_pam_pwquality_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_pcsc-lite_installed_action:testaction:1" question_ref="ocil:ssg-package_pcsc-lite_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_pigz_removed_action:testaction:1" question_ref="ocil:ssg-package_pigz_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_policycoreutils-python-utils_installed_action:testaction:1" question_ref="ocil:ssg-package_policycoreutils-python-utils_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_policycoreutils_installed_action:testaction:1" question_ref="ocil:ssg-package_policycoreutils_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_postfix_installed_action:testaction:1" question_ref="ocil:ssg-package_postfix_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_psacct_installed_action:testaction:1" question_ref="ocil:ssg-package_psacct_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_python3-abrt-addon_removed_action:testaction:1" question_ref="ocil:ssg-package_python3-abrt-addon_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_quagga_removed_action:testaction:1" question_ref="ocil:ssg-package_quagga_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_rear_installed_action:testaction:1" question_ref="ocil:ssg-package_rear_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_rng-tools_installed_action:testaction:1" question_ref="ocil:ssg-package_rng-tools_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_rpcbind_removed_action:testaction:1" question_ref="ocil:ssg-package_rpcbind_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_rsh-server_removed_action:testaction:1" question_ref="ocil:ssg-package_rsh-server_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_rsh_removed_action:testaction:1" question_ref="ocil:ssg-package_rsh_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_rsync_removed_action:testaction:1" question_ref="ocil:ssg-package_rsync_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_rsyslog-gnutls_installed_action:testaction:1" question_ref="ocil:ssg-package_rsyslog-gnutls_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_rsyslog_installed_action:testaction:1" question_ref="ocil:ssg-package_rsyslog_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_samba-common_installed_action:testaction:1" question_ref="ocil:ssg-package_samba-common_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_samba_removed_action:testaction:1" question_ref="ocil:ssg-package_samba_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_scap-security-guide_installed_action:testaction:1" question_ref="ocil:ssg-package_scap-security-guide_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_sendmail_removed_action:testaction:1" question_ref="ocil:ssg-package_sendmail_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_setroubleshoot-plugins_removed_action:testaction:1" question_ref="ocil:ssg-package_setroubleshoot-plugins_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_setroubleshoot-server_removed_action:testaction:1" question_ref="ocil:ssg-package_setroubleshoot-server_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_squid_removed_action:testaction:1" question_ref="ocil:ssg-package_squid_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_sssd-ipa_installed_action:testaction:1" question_ref="ocil:ssg-package_sssd-ipa_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_sssd_installed_action:testaction:1" question_ref="ocil:ssg-package_sssd_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_subscription-manager_installed_action:testaction:1" question_ref="ocil:ssg-package_subscription-manager_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_sudo_installed_action:testaction:1" question_ref="ocil:ssg-package_sudo_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_syslogng_installed_action:testaction:1" question_ref="ocil:ssg-package_syslogng_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_systemd-journal-remote_installed_action:testaction:1" question_ref="ocil:ssg-package_systemd-journal-remote_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_talk-server_removed_action:testaction:1" question_ref="ocil:ssg-package_talk-server_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_talk_removed_action:testaction:1" question_ref="ocil:ssg-package_talk_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_tar_installed_action:testaction:1" question_ref="ocil:ssg-package_tar_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_telnet-server_removed_action:testaction:1" question_ref="ocil:ssg-package_telnet-server_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_telnet_removed_action:testaction:1" question_ref="ocil:ssg-package_telnet_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_tftp-server_removed_action:testaction:1" question_ref="ocil:ssg-package_tftp-server_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_tftp_removed_action:testaction:1" question_ref="ocil:ssg-package_tftp_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_tmux_installed_action:testaction:1" question_ref="ocil:ssg-package_tmux_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_tuned_removed_action:testaction:1" question_ref="ocil:ssg-package_tuned_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_usbguard_installed_action:testaction:1" question_ref="ocil:ssg-package_usbguard_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_vim_installed_action:testaction:1" question_ref="ocil:ssg-package_vim_installed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_vsftpd_removed_action:testaction:1" question_ref="ocil:ssg-package_vsftpd_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_xinetd_removed_action:testaction:1" question_ref="ocil:ssg-package_xinetd_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_xorg-x11-server-Xwayland_removed_action:testaction:1" question_ref="ocil:ssg-package_xorg-x11-server-Xwayland_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_xorg-x11-server-common_removed_action:testaction:1" question_ref="ocil:ssg-package_xorg-x11-server-common_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_ypbind_removed_action:testaction:1" question_ref="ocil:ssg-package_ypbind_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-package_ypserv_removed_action:testaction:1" question_ref="ocil:ssg-package_ypserv_removed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-partition_for_boot_action:testaction:1" question_ref="ocil:ssg-partition_for_boot_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-partition_for_dev_shm_action:testaction:1" question_ref="ocil:ssg-partition_for_dev_shm_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-partition_for_home_action:testaction:1" question_ref="ocil:ssg-partition_for_home_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-partition_for_opt_action:testaction:1" question_ref="ocil:ssg-partition_for_opt_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-partition_for_srv_action:testaction:1" question_ref="ocil:ssg-partition_for_srv_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-partition_for_tmp_action:testaction:1" question_ref="ocil:ssg-partition_for_tmp_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-partition_for_usr_action:testaction:1" question_ref="ocil:ssg-partition_for_usr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-partition_for_var_action:testaction:1" question_ref="ocil:ssg-partition_for_var_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-partition_for_var_log_action:testaction:1" question_ref="ocil:ssg-partition_for_var_log_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-partition_for_var_log_audit_action:testaction:1" question_ref="ocil:ssg-partition_for_var_log_audit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-partition_for_var_tmp_action:testaction:1" question_ref="ocil:ssg-partition_for_var_tmp_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-partition_for_web_content_action:testaction:1" question_ref="ocil:ssg-partition_for_web_content_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1" question_ref="ocil:ssg-postfix_client_configure_mail_alias_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-postfix_client_configure_mail_alias_postmaster_action:testaction:1" question_ref="ocil:ssg-postfix_client_configure_mail_alias_postmaster_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-postfix_client_configure_relayhost_action:testaction:1" question_ref="ocil:ssg-postfix_client_configure_relayhost_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-postfix_network_listening_disabled_action:testaction:1" question_ref="ocil:ssg-postfix_network_listening_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-postfix_prevent_unrestricted_relay_action:testaction:1" question_ref="ocil:ssg-postfix_prevent_unrestricted_relay_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-prefer_64bit_os_action:testaction:1" question_ref="ocil:ssg-prefer_64bit_os_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-require_emergency_target_auth_action:testaction:1" question_ref="ocil:ssg-require_emergency_target_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-require_singleuser_auth_action:testaction:1" question_ref="ocil:ssg-require_singleuser_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-require_smb_client_signing_action:testaction:1" question_ref="ocil:ssg-require_smb_client_signing_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-restrict_serial_port_logins_action:testaction:1" question_ref="ocil:ssg-restrict_serial_port_logins_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-root_path_default_action:testaction:1" question_ref="ocil:ssg-root_path_default_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-root_permissions_syslibrary_files_action:testaction:1" question_ref="ocil:ssg-root_permissions_syslibrary_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rootfiles_configured_action:testaction:1" question_ref="ocil:ssg-rootfiles_configured_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rpm_verify_hashes_action:testaction:1" question_ref="ocil:ssg-rpm_verify_hashes_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rpm_verify_ownership_action:testaction:1" question_ref="ocil:ssg-rpm_verify_ownership_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rpm_verify_permissions_action:testaction:1" question_ref="ocil:ssg-rpm_verify_permissions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rsyslog_cron_logging_action:testaction:1" question_ref="ocil:ssg-rsyslog_cron_logging_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_action:testaction:1" question_ref="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_action:testaction:1" question_ref="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_action:testaction:1" question_ref="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rsyslog_filecreatemode_action:testaction:1" question_ref="ocil:ssg-rsyslog_filecreatemode_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rsyslog_files_groupownership_action:testaction:1" question_ref="ocil:ssg-rsyslog_files_groupownership_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rsyslog_files_ownership_action:testaction:1" question_ref="ocil:ssg-rsyslog_files_ownership_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rsyslog_files_permissions_action:testaction:1" question_ref="ocil:ssg-rsyslog_files_permissions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rsyslog_logging_configured_action:testaction:1" question_ref="ocil:ssg-rsyslog_logging_configured_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rsyslog_nolisten_action:testaction:1" question_ref="ocil:ssg-rsyslog_nolisten_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rsyslog_remote_access_monitoring_action:testaction:1" question_ref="ocil:ssg-rsyslog_remote_access_monitoring_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rsyslog_remote_loghost_action:testaction:1" question_ref="ocil:ssg-rsyslog_remote_loghost_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rsyslog_remote_tls_action:testaction:1" question_ref="ocil:ssg-rsyslog_remote_tls_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-rsyslog_remote_tls_cacert_action:testaction:1" question_ref="ocil:ssg-rsyslog_remote_tls_cacert_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_abrt_anon_write_action:testaction:1" question_ref="ocil:ssg-sebool_abrt_anon_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_abrt_handle_event_action:testaction:1" question_ref="ocil:ssg-sebool_abrt_handle_event_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_abrt_upload_watch_anon_write_action:testaction:1" question_ref="ocil:ssg-sebool_abrt_upload_watch_anon_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_antivirus_can_scan_system_action:testaction:1" question_ref="ocil:ssg-sebool_antivirus_can_scan_system_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_antivirus_use_jit_action:testaction:1" question_ref="ocil:ssg-sebool_antivirus_use_jit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_auditadm_exec_content_action:testaction:1" question_ref="ocil:ssg-sebool_auditadm_exec_content_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_authlogin_nsswitch_use_ldap_action:testaction:1" question_ref="ocil:ssg-sebool_authlogin_nsswitch_use_ldap_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_authlogin_radius_action:testaction:1" question_ref="ocil:ssg-sebool_authlogin_radius_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_authlogin_yubikey_action:testaction:1" question_ref="ocil:ssg-sebool_authlogin_yubikey_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_awstats_purge_apache_log_files_action:testaction:1" question_ref="ocil:ssg-sebool_awstats_purge_apache_log_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_boinc_execmem_action:testaction:1" question_ref="ocil:ssg-sebool_boinc_execmem_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_cdrecord_read_content_action:testaction:1" question_ref="ocil:ssg-sebool_cdrecord_read_content_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_cluster_can_network_connect_action:testaction:1" question_ref="ocil:ssg-sebool_cluster_can_network_connect_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_cluster_manage_all_files_action:testaction:1" question_ref="ocil:ssg-sebool_cluster_manage_all_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_cluster_use_execmem_action:testaction:1" question_ref="ocil:ssg-sebool_cluster_use_execmem_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_cobbler_anon_write_action:testaction:1" question_ref="ocil:ssg-sebool_cobbler_anon_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_cobbler_can_network_connect_action:testaction:1" question_ref="ocil:ssg-sebool_cobbler_can_network_connect_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_cobbler_use_cifs_action:testaction:1" question_ref="ocil:ssg-sebool_cobbler_use_cifs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_cobbler_use_nfs_action:testaction:1" question_ref="ocil:ssg-sebool_cobbler_use_nfs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_collectd_tcp_network_connect_action:testaction:1" question_ref="ocil:ssg-sebool_collectd_tcp_network_connect_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_condor_tcp_network_connect_action:testaction:1" question_ref="ocil:ssg-sebool_condor_tcp_network_connect_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_conman_can_network_action:testaction:1" question_ref="ocil:ssg-sebool_conman_can_network_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_container_connect_any_action:testaction:1" question_ref="ocil:ssg-sebool_container_connect_any_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_cron_can_relabel_action:testaction:1" question_ref="ocil:ssg-sebool_cron_can_relabel_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_cron_system_cronjob_use_shares_action:testaction:1" question_ref="ocil:ssg-sebool_cron_system_cronjob_use_shares_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_cron_userdomain_transition_action:testaction:1" question_ref="ocil:ssg-sebool_cron_userdomain_transition_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_cups_execmem_action:testaction:1" question_ref="ocil:ssg-sebool_cups_execmem_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_cvs_read_shadow_action:testaction:1" question_ref="ocil:ssg-sebool_cvs_read_shadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_daemons_dump_core_action:testaction:1" question_ref="ocil:ssg-sebool_daemons_dump_core_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_daemons_enable_cluster_mode_action:testaction:1" question_ref="ocil:ssg-sebool_daemons_enable_cluster_mode_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_daemons_use_tcp_wrapper_action:testaction:1" question_ref="ocil:ssg-sebool_daemons_use_tcp_wrapper_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_daemons_use_tty_action:testaction:1" question_ref="ocil:ssg-sebool_daemons_use_tty_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_dbadm_exec_content_action:testaction:1" question_ref="ocil:ssg-sebool_dbadm_exec_content_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_dbadm_manage_user_files_action:testaction:1" question_ref="ocil:ssg-sebool_dbadm_manage_user_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_dbadm_read_user_files_action:testaction:1" question_ref="ocil:ssg-sebool_dbadm_read_user_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_deny_execmem_action:testaction:1" question_ref="ocil:ssg-sebool_deny_execmem_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_deny_ptrace_action:testaction:1" question_ref="ocil:ssg-sebool_deny_ptrace_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_dhcpc_exec_iptables_action:testaction:1" question_ref="ocil:ssg-sebool_dhcpc_exec_iptables_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_dhcpd_use_ldap_action:testaction:1" question_ref="ocil:ssg-sebool_dhcpd_use_ldap_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_domain_fd_use_action:testaction:1" question_ref="ocil:ssg-sebool_domain_fd_use_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_domain_kernel_load_modules_action:testaction:1" question_ref="ocil:ssg-sebool_domain_kernel_load_modules_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_entropyd_use_audio_action:testaction:1" question_ref="ocil:ssg-sebool_entropyd_use_audio_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_exim_can_connect_db_action:testaction:1" question_ref="ocil:ssg-sebool_exim_can_connect_db_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_exim_manage_user_files_action:testaction:1" question_ref="ocil:ssg-sebool_exim_manage_user_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_exim_read_user_files_action:testaction:1" question_ref="ocil:ssg-sebool_exim_read_user_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_fcron_crond_action:testaction:1" question_ref="ocil:ssg-sebool_fcron_crond_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_fenced_can_network_connect_action:testaction:1" question_ref="ocil:ssg-sebool_fenced_can_network_connect_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_fenced_can_ssh_action:testaction:1" question_ref="ocil:ssg-sebool_fenced_can_ssh_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_fips_mode_action:testaction:1" question_ref="ocil:ssg-sebool_fips_mode_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_ftpd_anon_write_action:testaction:1" question_ref="ocil:ssg-sebool_ftpd_anon_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_ftpd_connect_all_unreserved_action:testaction:1" question_ref="ocil:ssg-sebool_ftpd_connect_all_unreserved_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_ftpd_connect_db_action:testaction:1" question_ref="ocil:ssg-sebool_ftpd_connect_db_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_ftpd_full_access_action:testaction:1" question_ref="ocil:ssg-sebool_ftpd_full_access_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_ftpd_use_cifs_action:testaction:1" question_ref="ocil:ssg-sebool_ftpd_use_cifs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_ftpd_use_fusefs_action:testaction:1" question_ref="ocil:ssg-sebool_ftpd_use_fusefs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_ftpd_use_nfs_action:testaction:1" question_ref="ocil:ssg-sebool_ftpd_use_nfs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_ftpd_use_passive_mode_action:testaction:1" question_ref="ocil:ssg-sebool_ftpd_use_passive_mode_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_git_cgi_enable_homedirs_action:testaction:1" question_ref="ocil:ssg-sebool_git_cgi_enable_homedirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_git_cgi_use_cifs_action:testaction:1" question_ref="ocil:ssg-sebool_git_cgi_use_cifs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_git_cgi_use_nfs_action:testaction:1" question_ref="ocil:ssg-sebool_git_cgi_use_nfs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_git_session_bind_all_unreserved_ports_action:testaction:1" question_ref="ocil:ssg-sebool_git_session_bind_all_unreserved_ports_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_git_session_users_action:testaction:1" question_ref="ocil:ssg-sebool_git_session_users_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_git_system_enable_homedirs_action:testaction:1" question_ref="ocil:ssg-sebool_git_system_enable_homedirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_git_system_use_cifs_action:testaction:1" question_ref="ocil:ssg-sebool_git_system_use_cifs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_git_system_use_nfs_action:testaction:1" question_ref="ocil:ssg-sebool_git_system_use_nfs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_gitosis_can_sendmail_action:testaction:1" question_ref="ocil:ssg-sebool_gitosis_can_sendmail_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_glance_api_can_network_action:testaction:1" question_ref="ocil:ssg-sebool_glance_api_can_network_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_glance_use_execmem_action:testaction:1" question_ref="ocil:ssg-sebool_glance_use_execmem_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_glance_use_fusefs_action:testaction:1" question_ref="ocil:ssg-sebool_glance_use_fusefs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_global_ssp_action:testaction:1" question_ref="ocil:ssg-sebool_global_ssp_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_gluster_anon_write_action:testaction:1" question_ref="ocil:ssg-sebool_gluster_anon_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_gluster_export_all_ro_action:testaction:1" question_ref="ocil:ssg-sebool_gluster_export_all_ro_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_gluster_export_all_rw_action:testaction:1" question_ref="ocil:ssg-sebool_gluster_export_all_rw_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_gpg_web_anon_write_action:testaction:1" question_ref="ocil:ssg-sebool_gpg_web_anon_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_gssd_read_tmp_action:testaction:1" question_ref="ocil:ssg-sebool_gssd_read_tmp_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_guest_exec_content_action:testaction:1" question_ref="ocil:ssg-sebool_guest_exec_content_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_haproxy_connect_any_action:testaction:1" question_ref="ocil:ssg-sebool_haproxy_connect_any_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_anon_write_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_anon_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_builtin_scripting_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_builtin_scripting_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_can_check_spam_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_can_check_spam_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_can_connect_ftp_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_can_connect_ftp_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_can_connect_ldap_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_can_connect_ldap_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_can_connect_mythtv_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_can_connect_mythtv_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_can_connect_zabbix_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_can_connect_zabbix_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_can_network_connect_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_can_network_connect_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_can_network_connect_cobbler_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_can_network_connect_cobbler_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_can_network_connect_db_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_can_network_connect_db_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_can_network_memcache_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_can_network_memcache_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_can_network_relay_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_can_network_relay_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_can_sendmail_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_can_sendmail_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_dbus_avahi_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_dbus_avahi_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_dbus_sssd_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_dbus_sssd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_dontaudit_search_dirs_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_dontaudit_search_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_enable_cgi_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_enable_cgi_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_enable_ftp_server_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_enable_ftp_server_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_enable_homedirs_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_enable_homedirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_execmem_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_execmem_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_graceful_shutdown_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_graceful_shutdown_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_manage_ipa_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_manage_ipa_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_mod_auth_ntlm_winbind_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_mod_auth_ntlm_winbind_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_mod_auth_pam_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_mod_auth_pam_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_read_user_content_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_read_user_content_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_run_ipa_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_run_ipa_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_run_preupgrade_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_run_preupgrade_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_run_stickshift_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_run_stickshift_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_serve_cobbler_files_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_serve_cobbler_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_setrlimit_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_setrlimit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_ssi_exec_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_ssi_exec_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_sys_script_anon_write_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_sys_script_anon_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_tmp_exec_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_tmp_exec_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_tty_comm_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_tty_comm_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_unified_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_unified_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_use_cifs_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_use_cifs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_use_fusefs_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_use_fusefs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_use_gpg_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_use_gpg_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_use_nfs_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_use_nfs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_use_openstack_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_use_openstack_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_use_sasl_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_use_sasl_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_httpd_verify_dns_action:testaction:1" question_ref="ocil:ssg-sebool_httpd_verify_dns_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_icecast_use_any_tcp_ports_action:testaction:1" question_ref="ocil:ssg-sebool_icecast_use_any_tcp_ports_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_irc_use_any_tcp_ports_action:testaction:1" question_ref="ocil:ssg-sebool_irc_use_any_tcp_ports_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_irssi_use_full_network_action:testaction:1" question_ref="ocil:ssg-sebool_irssi_use_full_network_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_kdumpgui_run_bootloader_action:testaction:1" question_ref="ocil:ssg-sebool_kdumpgui_run_bootloader_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_kerberos_enabled_action:testaction:1" question_ref="ocil:ssg-sebool_kerberos_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_ksmtuned_use_cifs_action:testaction:1" question_ref="ocil:ssg-sebool_ksmtuned_use_cifs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_ksmtuned_use_nfs_action:testaction:1" question_ref="ocil:ssg-sebool_ksmtuned_use_nfs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_logadm_exec_content_action:testaction:1" question_ref="ocil:ssg-sebool_logadm_exec_content_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_logging_syslogd_can_sendmail_action:testaction:1" question_ref="ocil:ssg-sebool_logging_syslogd_can_sendmail_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_logging_syslogd_run_nagios_plugins_action:testaction:1" question_ref="ocil:ssg-sebool_logging_syslogd_run_nagios_plugins_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_logging_syslogd_use_tty_action:testaction:1" question_ref="ocil:ssg-sebool_logging_syslogd_use_tty_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_login_console_enabled_action:testaction:1" question_ref="ocil:ssg-sebool_login_console_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_logrotate_use_nfs_action:testaction:1" question_ref="ocil:ssg-sebool_logrotate_use_nfs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_logwatch_can_network_connect_mail_action:testaction:1" question_ref="ocil:ssg-sebool_logwatch_can_network_connect_mail_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_lsmd_plugin_connect_any_action:testaction:1" question_ref="ocil:ssg-sebool_lsmd_plugin_connect_any_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mailman_use_fusefs_action:testaction:1" question_ref="ocil:ssg-sebool_mailman_use_fusefs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mcelog_client_action:testaction:1" question_ref="ocil:ssg-sebool_mcelog_client_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mcelog_exec_scripts_action:testaction:1" question_ref="ocil:ssg-sebool_mcelog_exec_scripts_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mcelog_foreground_action:testaction:1" question_ref="ocil:ssg-sebool_mcelog_foreground_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mcelog_server_action:testaction:1" question_ref="ocil:ssg-sebool_mcelog_server_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_minidlna_read_generic_user_content_action:testaction:1" question_ref="ocil:ssg-sebool_minidlna_read_generic_user_content_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mmap_low_allowed_action:testaction:1" question_ref="ocil:ssg-sebool_mmap_low_allowed_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mock_enable_homedirs_action:testaction:1" question_ref="ocil:ssg-sebool_mock_enable_homedirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mount_anyfile_action:testaction:1" question_ref="ocil:ssg-sebool_mount_anyfile_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mozilla_plugin_bind_unreserved_ports_action:testaction:1" question_ref="ocil:ssg-sebool_mozilla_plugin_bind_unreserved_ports_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mozilla_plugin_can_network_connect_action:testaction:1" question_ref="ocil:ssg-sebool_mozilla_plugin_can_network_connect_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mozilla_plugin_use_bluejeans_action:testaction:1" question_ref="ocil:ssg-sebool_mozilla_plugin_use_bluejeans_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mozilla_plugin_use_gps_action:testaction:1" question_ref="ocil:ssg-sebool_mozilla_plugin_use_gps_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mozilla_plugin_use_spice_action:testaction:1" question_ref="ocil:ssg-sebool_mozilla_plugin_use_spice_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mozilla_read_content_action:testaction:1" question_ref="ocil:ssg-sebool_mozilla_read_content_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mpd_enable_homedirs_action:testaction:1" question_ref="ocil:ssg-sebool_mpd_enable_homedirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mpd_use_cifs_action:testaction:1" question_ref="ocil:ssg-sebool_mpd_use_cifs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mpd_use_nfs_action:testaction:1" question_ref="ocil:ssg-sebool_mpd_use_nfs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mplayer_execstack_action:testaction:1" question_ref="ocil:ssg-sebool_mplayer_execstack_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_mysql_connect_any_action:testaction:1" question_ref="ocil:ssg-sebool_mysql_connect_any_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_nagios_run_pnp4nagios_action:testaction:1" question_ref="ocil:ssg-sebool_nagios_run_pnp4nagios_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_nagios_run_sudo_action:testaction:1" question_ref="ocil:ssg-sebool_nagios_run_sudo_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_named_tcp_bind_http_port_action:testaction:1" question_ref="ocil:ssg-sebool_named_tcp_bind_http_port_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_named_write_master_zones_action:testaction:1" question_ref="ocil:ssg-sebool_named_write_master_zones_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_neutron_can_network_action:testaction:1" question_ref="ocil:ssg-sebool_neutron_can_network_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_nfs_export_all_ro_action:testaction:1" question_ref="ocil:ssg-sebool_nfs_export_all_ro_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_nfs_export_all_rw_action:testaction:1" question_ref="ocil:ssg-sebool_nfs_export_all_rw_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_nfsd_anon_write_action:testaction:1" question_ref="ocil:ssg-sebool_nfsd_anon_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_nis_enabled_action:testaction:1" question_ref="ocil:ssg-sebool_nis_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_nscd_use_shm_action:testaction:1" question_ref="ocil:ssg-sebool_nscd_use_shm_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_openshift_use_nfs_action:testaction:1" question_ref="ocil:ssg-sebool_openshift_use_nfs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_openvpn_can_network_connect_action:testaction:1" question_ref="ocil:ssg-sebool_openvpn_can_network_connect_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_openvpn_enable_homedirs_action:testaction:1" question_ref="ocil:ssg-sebool_openvpn_enable_homedirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_openvpn_run_unconfined_action:testaction:1" question_ref="ocil:ssg-sebool_openvpn_run_unconfined_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_pcp_bind_all_unreserved_ports_action:testaction:1" question_ref="ocil:ssg-sebool_pcp_bind_all_unreserved_ports_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_pcp_read_generic_logs_action:testaction:1" question_ref="ocil:ssg-sebool_pcp_read_generic_logs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_piranha_lvs_can_network_connect_action:testaction:1" question_ref="ocil:ssg-sebool_piranha_lvs_can_network_connect_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_polipo_connect_all_unreserved_action:testaction:1" question_ref="ocil:ssg-sebool_polipo_connect_all_unreserved_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_polipo_session_bind_all_unreserved_ports_action:testaction:1" question_ref="ocil:ssg-sebool_polipo_session_bind_all_unreserved_ports_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_polipo_session_users_action:testaction:1" question_ref="ocil:ssg-sebool_polipo_session_users_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_polipo_use_cifs_action:testaction:1" question_ref="ocil:ssg-sebool_polipo_use_cifs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_polipo_use_nfs_action:testaction:1" question_ref="ocil:ssg-sebool_polipo_use_nfs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_polyinstantiation_enabled_action:testaction:1" question_ref="ocil:ssg-sebool_polyinstantiation_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_postfix_local_write_mail_spool_action:testaction:1" question_ref="ocil:ssg-sebool_postfix_local_write_mail_spool_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_postgresql_can_rsync_action:testaction:1" question_ref="ocil:ssg-sebool_postgresql_can_rsync_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_postgresql_selinux_transmit_client_label_action:testaction:1" question_ref="ocil:ssg-sebool_postgresql_selinux_transmit_client_label_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_postgresql_selinux_unconfined_dbadm_action:testaction:1" question_ref="ocil:ssg-sebool_postgresql_selinux_unconfined_dbadm_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_postgresql_selinux_users_ddl_action:testaction:1" question_ref="ocil:ssg-sebool_postgresql_selinux_users_ddl_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_pppd_can_insmod_action:testaction:1" question_ref="ocil:ssg-sebool_pppd_can_insmod_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_pppd_for_user_action:testaction:1" question_ref="ocil:ssg-sebool_pppd_for_user_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_privoxy_connect_any_action:testaction:1" question_ref="ocil:ssg-sebool_privoxy_connect_any_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_prosody_bind_http_port_action:testaction:1" question_ref="ocil:ssg-sebool_prosody_bind_http_port_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_puppetagent_manage_all_files_action:testaction:1" question_ref="ocil:ssg-sebool_puppetagent_manage_all_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_puppetmaster_use_db_action:testaction:1" question_ref="ocil:ssg-sebool_puppetmaster_use_db_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_racoon_read_shadow_action:testaction:1" question_ref="ocil:ssg-sebool_racoon_read_shadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_rsync_anon_write_action:testaction:1" question_ref="ocil:ssg-sebool_rsync_anon_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_rsync_client_action:testaction:1" question_ref="ocil:ssg-sebool_rsync_client_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_rsync_export_all_ro_action:testaction:1" question_ref="ocil:ssg-sebool_rsync_export_all_ro_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_rsync_full_access_action:testaction:1" question_ref="ocil:ssg-sebool_rsync_full_access_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_samba_create_home_dirs_action:testaction:1" question_ref="ocil:ssg-sebool_samba_create_home_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_samba_domain_controller_action:testaction:1" question_ref="ocil:ssg-sebool_samba_domain_controller_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_samba_enable_home_dirs_action:testaction:1" question_ref="ocil:ssg-sebool_samba_enable_home_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_samba_export_all_ro_action:testaction:1" question_ref="ocil:ssg-sebool_samba_export_all_ro_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_samba_export_all_rw_action:testaction:1" question_ref="ocil:ssg-sebool_samba_export_all_rw_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_samba_load_libgfapi_action:testaction:1" question_ref="ocil:ssg-sebool_samba_load_libgfapi_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_samba_portmapper_action:testaction:1" question_ref="ocil:ssg-sebool_samba_portmapper_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_samba_run_unconfined_action:testaction:1" question_ref="ocil:ssg-sebool_samba_run_unconfined_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_samba_share_fusefs_action:testaction:1" question_ref="ocil:ssg-sebool_samba_share_fusefs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_samba_share_nfs_action:testaction:1" question_ref="ocil:ssg-sebool_samba_share_nfs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_sanlock_use_fusefs_action:testaction:1" question_ref="ocil:ssg-sebool_sanlock_use_fusefs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_sanlock_use_nfs_action:testaction:1" question_ref="ocil:ssg-sebool_sanlock_use_nfs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_sanlock_use_samba_action:testaction:1" question_ref="ocil:ssg-sebool_sanlock_use_samba_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_saslauthd_read_shadow_action:testaction:1" question_ref="ocil:ssg-sebool_saslauthd_read_shadow_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_secadm_exec_content_action:testaction:1" question_ref="ocil:ssg-sebool_secadm_exec_content_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_secure_mode_action:testaction:1" question_ref="ocil:ssg-sebool_secure_mode_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_secure_mode_insmod_action:testaction:1" question_ref="ocil:ssg-sebool_secure_mode_insmod_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_secure_mode_policyload_action:testaction:1" question_ref="ocil:ssg-sebool_secure_mode_policyload_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_selinuxuser_direct_dri_enabled_action:testaction:1" question_ref="ocil:ssg-sebool_selinuxuser_direct_dri_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_selinuxuser_execheap_action:testaction:1" question_ref="ocil:ssg-sebool_selinuxuser_execheap_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_selinuxuser_execmod_action:testaction:1" question_ref="ocil:ssg-sebool_selinuxuser_execmod_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_selinuxuser_execstack_action:testaction:1" question_ref="ocil:ssg-sebool_selinuxuser_execstack_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_selinuxuser_mysql_connect_enabled_action:testaction:1" question_ref="ocil:ssg-sebool_selinuxuser_mysql_connect_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_selinuxuser_ping_action:testaction:1" question_ref="ocil:ssg-sebool_selinuxuser_ping_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_selinuxuser_postgresql_connect_enabled_action:testaction:1" question_ref="ocil:ssg-sebool_selinuxuser_postgresql_connect_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_selinuxuser_rw_noexattrfile_action:testaction:1" question_ref="ocil:ssg-sebool_selinuxuser_rw_noexattrfile_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_selinuxuser_share_music_action:testaction:1" question_ref="ocil:ssg-sebool_selinuxuser_share_music_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_selinuxuser_tcp_server_action:testaction:1" question_ref="ocil:ssg-sebool_selinuxuser_tcp_server_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_selinuxuser_udp_server_action:testaction:1" question_ref="ocil:ssg-sebool_selinuxuser_udp_server_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_selinuxuser_use_ssh_chroot_action:testaction:1" question_ref="ocil:ssg-sebool_selinuxuser_use_ssh_chroot_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_sge_domain_can_network_connect_action:testaction:1" question_ref="ocil:ssg-sebool_sge_domain_can_network_connect_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_sge_use_nfs_action:testaction:1" question_ref="ocil:ssg-sebool_sge_use_nfs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_smartmon_3ware_action:testaction:1" question_ref="ocil:ssg-sebool_smartmon_3ware_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_smbd_anon_write_action:testaction:1" question_ref="ocil:ssg-sebool_smbd_anon_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_spamassassin_can_network_action:testaction:1" question_ref="ocil:ssg-sebool_spamassassin_can_network_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_spamd_enable_home_dirs_action:testaction:1" question_ref="ocil:ssg-sebool_spamd_enable_home_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_squid_connect_any_action:testaction:1" question_ref="ocil:ssg-sebool_squid_connect_any_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_squid_use_tproxy_action:testaction:1" question_ref="ocil:ssg-sebool_squid_use_tproxy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_ssh_chroot_rw_homedirs_action:testaction:1" question_ref="ocil:ssg-sebool_ssh_chroot_rw_homedirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_ssh_keysign_action:testaction:1" question_ref="ocil:ssg-sebool_ssh_keysign_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_ssh_sysadm_login_action:testaction:1" question_ref="ocil:ssg-sebool_ssh_sysadm_login_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_staff_exec_content_action:testaction:1" question_ref="ocil:ssg-sebool_staff_exec_content_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_staff_use_svirt_action:testaction:1" question_ref="ocil:ssg-sebool_staff_use_svirt_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_swift_can_network_action:testaction:1" question_ref="ocil:ssg-sebool_swift_can_network_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_sysadm_exec_content_action:testaction:1" question_ref="ocil:ssg-sebool_sysadm_exec_content_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_telepathy_connect_all_ports_action:testaction:1" question_ref="ocil:ssg-sebool_telepathy_connect_all_ports_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_telepathy_tcp_connect_generic_network_ports_action:testaction:1" question_ref="ocil:ssg-sebool_telepathy_tcp_connect_generic_network_ports_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_tftp_anon_write_action:testaction:1" question_ref="ocil:ssg-sebool_tftp_anon_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_tftp_home_dir_action:testaction:1" question_ref="ocil:ssg-sebool_tftp_home_dir_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_tmpreaper_use_nfs_action:testaction:1" question_ref="ocil:ssg-sebool_tmpreaper_use_nfs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_tmpreaper_use_samba_action:testaction:1" question_ref="ocil:ssg-sebool_tmpreaper_use_samba_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_tor_bind_all_unreserved_ports_action:testaction:1" question_ref="ocil:ssg-sebool_tor_bind_all_unreserved_ports_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_tor_can_network_relay_action:testaction:1" question_ref="ocil:ssg-sebool_tor_can_network_relay_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_unconfined_chrome_sandbox_transition_action:testaction:1" question_ref="ocil:ssg-sebool_unconfined_chrome_sandbox_transition_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_unconfined_login_action:testaction:1" question_ref="ocil:ssg-sebool_unconfined_login_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_unconfined_mozilla_plugin_transition_action:testaction:1" question_ref="ocil:ssg-sebool_unconfined_mozilla_plugin_transition_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_unprivuser_use_svirt_action:testaction:1" question_ref="ocil:ssg-sebool_unprivuser_use_svirt_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_use_ecryptfs_home_dirs_action:testaction:1" question_ref="ocil:ssg-sebool_use_ecryptfs_home_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_use_fusefs_home_dirs_action:testaction:1" question_ref="ocil:ssg-sebool_use_fusefs_home_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_use_lpd_server_action:testaction:1" question_ref="ocil:ssg-sebool_use_lpd_server_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_use_nfs_home_dirs_action:testaction:1" question_ref="ocil:ssg-sebool_use_nfs_home_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_use_samba_home_dirs_action:testaction:1" question_ref="ocil:ssg-sebool_use_samba_home_dirs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_user_exec_content_action:testaction:1" question_ref="ocil:ssg-sebool_user_exec_content_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_varnishd_connect_any_action:testaction:1" question_ref="ocil:ssg-sebool_varnishd_connect_any_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_virt_read_qemu_ga_data_action:testaction:1" question_ref="ocil:ssg-sebool_virt_read_qemu_ga_data_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_virt_rw_qemu_ga_data_action:testaction:1" question_ref="ocil:ssg-sebool_virt_rw_qemu_ga_data_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_virt_sandbox_use_all_caps_action:testaction:1" question_ref="ocil:ssg-sebool_virt_sandbox_use_all_caps_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_virt_sandbox_use_audit_action:testaction:1" question_ref="ocil:ssg-sebool_virt_sandbox_use_audit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_virt_sandbox_use_mknod_action:testaction:1" question_ref="ocil:ssg-sebool_virt_sandbox_use_mknod_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_virt_sandbox_use_netlink_action:testaction:1" question_ref="ocil:ssg-sebool_virt_sandbox_use_netlink_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_virt_sandbox_use_sys_admin_action:testaction:1" question_ref="ocil:ssg-sebool_virt_sandbox_use_sys_admin_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_virt_transition_userdomain_action:testaction:1" question_ref="ocil:ssg-sebool_virt_transition_userdomain_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_virt_use_comm_action:testaction:1" question_ref="ocil:ssg-sebool_virt_use_comm_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_virt_use_execmem_action:testaction:1" question_ref="ocil:ssg-sebool_virt_use_execmem_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_virt_use_fusefs_action:testaction:1" question_ref="ocil:ssg-sebool_virt_use_fusefs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_virt_use_nfs_action:testaction:1" question_ref="ocil:ssg-sebool_virt_use_nfs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_virt_use_rawip_action:testaction:1" question_ref="ocil:ssg-sebool_virt_use_rawip_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_virt_use_samba_action:testaction:1" question_ref="ocil:ssg-sebool_virt_use_samba_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_virt_use_sanlock_action:testaction:1" question_ref="ocil:ssg-sebool_virt_use_sanlock_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_virt_use_usb_action:testaction:1" question_ref="ocil:ssg-sebool_virt_use_usb_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_virt_use_xserver_action:testaction:1" question_ref="ocil:ssg-sebool_virt_use_xserver_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_webadm_manage_user_files_action:testaction:1" question_ref="ocil:ssg-sebool_webadm_manage_user_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_webadm_read_user_files_action:testaction:1" question_ref="ocil:ssg-sebool_webadm_read_user_files_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_wine_mmap_zero_ignore_action:testaction:1" question_ref="ocil:ssg-sebool_wine_mmap_zero_ignore_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_xdm_bind_vnc_tcp_port_action:testaction:1" question_ref="ocil:ssg-sebool_xdm_bind_vnc_tcp_port_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_xdm_exec_bootloader_action:testaction:1" question_ref="ocil:ssg-sebool_xdm_exec_bootloader_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_xdm_sysadm_login_action:testaction:1" question_ref="ocil:ssg-sebool_xdm_sysadm_login_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_xdm_write_home_action:testaction:1" question_ref="ocil:ssg-sebool_xdm_write_home_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_xen_use_nfs_action:testaction:1" question_ref="ocil:ssg-sebool_xen_use_nfs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_xend_run_blktap_action:testaction:1" question_ref="ocil:ssg-sebool_xend_run_blktap_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_xend_run_qemu_action:testaction:1" question_ref="ocil:ssg-sebool_xend_run_qemu_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_xguest_connect_network_action:testaction:1" question_ref="ocil:ssg-sebool_xguest_connect_network_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_xguest_exec_content_action:testaction:1" question_ref="ocil:ssg-sebool_xguest_exec_content_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_xguest_mount_media_action:testaction:1" question_ref="ocil:ssg-sebool_xguest_mount_media_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_xguest_use_bluetooth_action:testaction:1" question_ref="ocil:ssg-sebool_xguest_use_bluetooth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_xserver_clients_write_xshm_action:testaction:1" question_ref="ocil:ssg-sebool_xserver_clients_write_xshm_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_xserver_execmem_action:testaction:1" question_ref="ocil:ssg-sebool_xserver_execmem_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_xserver_object_manager_action:testaction:1" question_ref="ocil:ssg-sebool_xserver_object_manager_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_zabbix_can_network_action:testaction:1" question_ref="ocil:ssg-sebool_zabbix_can_network_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_zarafa_setrlimit_action:testaction:1" question_ref="ocil:ssg-sebool_zarafa_setrlimit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_zebra_write_config_action:testaction:1" question_ref="ocil:ssg-sebool_zebra_write_config_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_zoneminder_anon_write_action:testaction:1" question_ref="ocil:ssg-sebool_zoneminder_anon_write_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sebool_zoneminder_run_sudo_action:testaction:1" question_ref="ocil:ssg-sebool_zoneminder_run_sudo_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-securetty_root_login_console_only_action:testaction:1" question_ref="ocil:ssg-securetty_root_login_console_only_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-security_patches_up_to_date_action:testaction:1" question_ref="ocil:ssg-security_patches_up_to_date_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-selinux_all_devicefiles_labeled_action:testaction:1" question_ref="ocil:ssg-selinux_all_devicefiles_labeled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-selinux_confinement_of_daemons_action:testaction:1" question_ref="ocil:ssg-selinux_confinement_of_daemons_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-selinux_context_elevation_for_sudo_action:testaction:1" question_ref="ocil:ssg-selinux_context_elevation_for_sudo_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-selinux_not_disabled_action:testaction:1" question_ref="ocil:ssg-selinux_not_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-selinux_policytype_action:testaction:1" question_ref="ocil:ssg-selinux_policytype_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-selinux_state_action:testaction:1" question_ref="ocil:ssg-selinux_state_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-selinux_user_login_roles_action:testaction:1" question_ref="ocil:ssg-selinux_user_login_roles_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_abrtd_disabled_action:testaction:1" question_ref="ocil:ssg-service_abrtd_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_acpid_disabled_action:testaction:1" question_ref="ocil:ssg-service_acpid_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_atd_disabled_action:testaction:1" question_ref="ocil:ssg-service_atd_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_auditd_enabled_action:testaction:1" question_ref="ocil:ssg-service_auditd_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_autofs_disabled_action:testaction:1" question_ref="ocil:ssg-service_autofs_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_avahi-daemon_disabled_action:testaction:1" question_ref="ocil:ssg-service_avahi-daemon_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_bluetooth_disabled_action:testaction:1" question_ref="ocil:ssg-service_bluetooth_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_certmonger_disabled_action:testaction:1" question_ref="ocil:ssg-service_certmonger_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_chronyd_enabled_action:testaction:1" question_ref="ocil:ssg-service_chronyd_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_chronyd_or_ntpd_enabled_action:testaction:1" question_ref="ocil:ssg-service_chronyd_or_ntpd_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_cockpit_disabled_action:testaction:1" question_ref="ocil:ssg-service_cockpit_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_cpupower_disabled_action:testaction:1" question_ref="ocil:ssg-service_cpupower_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_cron_enabled_action:testaction:1" question_ref="ocil:ssg-service_cron_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_crond_enabled_action:testaction:1" question_ref="ocil:ssg-service_crond_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_cups_disabled_action:testaction:1" question_ref="ocil:ssg-service_cups_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_debug-shell_disabled_action:testaction:1" question_ref="ocil:ssg-service_debug-shell_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_dhcpd_disabled_action:testaction:1" question_ref="ocil:ssg-service_dhcpd_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_dovecot_disabled_action:testaction:1" question_ref="ocil:ssg-service_dovecot_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_fapolicyd_enabled_action:testaction:1" question_ref="ocil:ssg-service_fapolicyd_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_firewalld_enabled_action:testaction:1" question_ref="ocil:ssg-service_firewalld_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_httpd_disabled_action:testaction:1" question_ref="ocil:ssg-service_httpd_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_ip6tables_enabled_action:testaction:1" question_ref="ocil:ssg-service_ip6tables_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_iptables_enabled_action:testaction:1" question_ref="ocil:ssg-service_iptables_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_kdump_disabled_action:testaction:1" question_ref="ocil:ssg-service_kdump_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_mdmonitor_disabled_action:testaction:1" question_ref="ocil:ssg-service_mdmonitor_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_nails_enabled_action:testaction:1" question_ref="ocil:ssg-service_nails_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_named_disabled_action:testaction:1" question_ref="ocil:ssg-service_named_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_netconsole_disabled_action:testaction:1" question_ref="ocil:ssg-service_netconsole_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_nfs_disabled_action:testaction:1" question_ref="ocil:ssg-service_nfs_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_nftables_disabled_action:testaction:1" question_ref="ocil:ssg-service_nftables_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_nftables_enabled_action:testaction:1" question_ref="ocil:ssg-service_nftables_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_ntp_enabled_action:testaction:1" question_ref="ocil:ssg-service_ntp_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_ntpd_enabled_action:testaction:1" question_ref="ocil:ssg-service_ntpd_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_ntpdate_disabled_action:testaction:1" question_ref="ocil:ssg-service_ntpdate_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_oddjobd_disabled_action:testaction:1" question_ref="ocil:ssg-service_oddjobd_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_pcscd_enabled_action:testaction:1" question_ref="ocil:ssg-service_pcscd_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_portreserve_disabled_action:testaction:1" question_ref="ocil:ssg-service_portreserve_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_postfix_enabled_action:testaction:1" question_ref="ocil:ssg-service_postfix_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_psacct_enabled_action:testaction:1" question_ref="ocil:ssg-service_psacct_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_qpidd_disabled_action:testaction:1" question_ref="ocil:ssg-service_qpidd_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_quota_nld_disabled_action:testaction:1" question_ref="ocil:ssg-service_quota_nld_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_rdisc_disabled_action:testaction:1" question_ref="ocil:ssg-service_rdisc_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_rexec_disabled_action:testaction:1" question_ref="ocil:ssg-service_rexec_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_rhnsd_disabled_action:testaction:1" question_ref="ocil:ssg-service_rhnsd_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_rhsmcertd_disabled_action:testaction:1" question_ref="ocil:ssg-service_rhsmcertd_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_rlogin_disabled_action:testaction:1" question_ref="ocil:ssg-service_rlogin_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_rngd_enabled_action:testaction:1" question_ref="ocil:ssg-service_rngd_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_rpcsvcgssd_disabled_action:testaction:1" question_ref="ocil:ssg-service_rpcsvcgssd_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_rsh_disabled_action:testaction:1" question_ref="ocil:ssg-service_rsh_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_rsyncd_disabled_action:testaction:1" question_ref="ocil:ssg-service_rsyncd_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_rsyslog_enabled_action:testaction:1" question_ref="ocil:ssg-service_rsyslog_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_saslauthd_disabled_action:testaction:1" question_ref="ocil:ssg-service_saslauthd_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_slapd_disabled_action:testaction:1" question_ref="ocil:ssg-service_slapd_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_smb_disabled_action:testaction:1" question_ref="ocil:ssg-service_smb_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_snmpd_disabled_action:testaction:1" question_ref="ocil:ssg-service_snmpd_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_squid_disabled_action:testaction:1" question_ref="ocil:ssg-service_squid_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_sshd_disabled_action:testaction:1" question_ref="ocil:ssg-service_sshd_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_sshd_enabled_action:testaction:1" question_ref="ocil:ssg-service_sshd_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_sssd_enabled_action:testaction:1" question_ref="ocil:ssg-service_sssd_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_syslogng_enabled_action:testaction:1" question_ref="ocil:ssg-service_syslogng_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_sysstat_disabled_action:testaction:1" question_ref="ocil:ssg-service_sysstat_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_systemd-coredump_disabled_action:testaction:1" question_ref="ocil:ssg-service_systemd-coredump_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_systemd-journal-upload_enabled_action:testaction:1" question_ref="ocil:ssg-service_systemd-journal-upload_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_systemd-journald_enabled_action:testaction:1" question_ref="ocil:ssg-service_systemd-journald_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_telnet_disabled_action:testaction:1" question_ref="ocil:ssg-service_telnet_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_tftp_disabled_action:testaction:1" question_ref="ocil:ssg-service_tftp_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_ufw_enabled_action:testaction:1" question_ref="ocil:ssg-service_ufw_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_usbguard_enabled_action:testaction:1" question_ref="ocil:ssg-service_usbguard_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_vsftpd_disabled_action:testaction:1" question_ref="ocil:ssg-service_vsftpd_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_xinetd_disabled_action:testaction:1" question_ref="ocil:ssg-service_xinetd_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_ypbind_disabled_action:testaction:1" question_ref="ocil:ssg-service_ypbind_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_ypserv_disabled_action:testaction:1" question_ref="ocil:ssg-service_ypserv_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-service_zebra_disabled_action:testaction:1" question_ref="ocil:ssg-service_zebra_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-set_firewalld_appropriate_zone_action:testaction:1" question_ref="ocil:ssg-set_firewalld_appropriate_zone_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-set_firewalld_default_zone_action:testaction:1" question_ref="ocil:ssg-set_firewalld_default_zone_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-set_ip6tables_default_rule_action:testaction:1" question_ref="ocil:ssg-set_ip6tables_default_rule_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-set_iptables_default_rule_action:testaction:1" question_ref="ocil:ssg-set_iptables_default_rule_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-set_iptables_default_rule_forward_action:testaction:1" question_ref="ocil:ssg-set_iptables_default_rule_forward_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-set_ipv6_loopback_traffic_action:testaction:1" question_ref="ocil:ssg-set_ipv6_loopback_traffic_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-set_loopback_traffic_action:testaction:1" question_ref="ocil:ssg-set_loopback_traffic_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-set_nftables_table_action:testaction:1" question_ref="ocil:ssg-set_nftables_table_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-set_password_hashing_algorithm_libuserconf_action:testaction:1" question_ref="ocil:ssg-set_password_hashing_algorithm_libuserconf_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-set_password_hashing_algorithm_logindefs_action:testaction:1" question_ref="ocil:ssg-set_password_hashing_algorithm_logindefs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-set_password_hashing_algorithm_passwordauth_action:testaction:1" question_ref="ocil:ssg-set_password_hashing_algorithm_passwordauth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-set_password_hashing_algorithm_systemauth_action:testaction:1" question_ref="ocil:ssg-set_password_hashing_algorithm_systemauth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-set_password_hashing_min_rounds_logindefs_action:testaction:1" question_ref="ocil:ssg-set_password_hashing_min_rounds_logindefs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-snmpd_no_rwusers_action:testaction:1" question_ref="ocil:ssg-snmpd_no_rwusers_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-snmpd_not_default_password_action:testaction:1" question_ref="ocil:ssg-snmpd_not_default_password_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-snmpd_use_newer_protocol_action:testaction:1" question_ref="ocil:ssg-snmpd_use_newer_protocol_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-socket_systemd-journal-remote_disabled_action:testaction:1" question_ref="ocil:ssg-socket_systemd-journal-remote_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ssh_client_rekey_limit_action:testaction:1" question_ref="ocil:ssg-ssh_client_rekey_limit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ssh_client_use_strong_rng_csh_action:testaction:1" question_ref="ocil:ssg-ssh_client_use_strong_rng_csh_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ssh_client_use_strong_rng_sh_action:testaction:1" question_ref="ocil:ssg-ssh_client_use_strong_rng_sh_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-ssh_keys_passphrase_protected_action:testaction:1" question_ref="ocil:ssg-ssh_keys_passphrase_protected_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_allow_only_protocol2_action:testaction:1" question_ref="ocil:ssg-sshd_allow_only_protocol2_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_disable_compression_action:testaction:1" question_ref="ocil:ssg-sshd_disable_compression_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_disable_empty_passwords_action:testaction:1" question_ref="ocil:ssg-sshd_disable_empty_passwords_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_disable_forwarding_action:testaction:1" question_ref="ocil:ssg-sshd_disable_forwarding_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_disable_gssapi_auth_action:testaction:1" question_ref="ocil:ssg-sshd_disable_gssapi_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_disable_kerb_auth_action:testaction:1" question_ref="ocil:ssg-sshd_disable_kerb_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_disable_pubkey_auth_action:testaction:1" question_ref="ocil:ssg-sshd_disable_pubkey_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_disable_rhosts_action:testaction:1" question_ref="ocil:ssg-sshd_disable_rhosts_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_disable_rhosts_rsa_action:testaction:1" question_ref="ocil:ssg-sshd_disable_rhosts_rsa_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_disable_root_login_action:testaction:1" question_ref="ocil:ssg-sshd_disable_root_login_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_disable_root_password_login_action:testaction:1" question_ref="ocil:ssg-sshd_disable_root_password_login_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_disable_tcp_forwarding_action:testaction:1" question_ref="ocil:ssg-sshd_disable_tcp_forwarding_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_disable_user_known_hosts_action:testaction:1" question_ref="ocil:ssg-sshd_disable_user_known_hosts_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_disable_x11_forwarding_action:testaction:1" question_ref="ocil:ssg-sshd_disable_x11_forwarding_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_do_not_permit_user_env_action:testaction:1" question_ref="ocil:ssg-sshd_do_not_permit_user_env_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_enable_gssapi_auth_action:testaction:1" question_ref="ocil:ssg-sshd_enable_gssapi_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_enable_pam_action:testaction:1" question_ref="ocil:ssg-sshd_enable_pam_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_enable_pubkey_auth_action:testaction:1" question_ref="ocil:ssg-sshd_enable_pubkey_auth_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_enable_strictmodes_action:testaction:1" question_ref="ocil:ssg-sshd_enable_strictmodes_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_enable_warning_banner_action:testaction:1" question_ref="ocil:ssg-sshd_enable_warning_banner_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_enable_warning_banner_net_action:testaction:1" question_ref="ocil:ssg-sshd_enable_warning_banner_net_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_enable_x11_forwarding_action:testaction:1" question_ref="ocil:ssg-sshd_enable_x11_forwarding_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_limit_user_access_action:testaction:1" question_ref="ocil:ssg-sshd_limit_user_access_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_print_last_log_action:testaction:1" question_ref="ocil:ssg-sshd_print_last_log_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_rekey_limit_action:testaction:1" question_ref="ocil:ssg-sshd_rekey_limit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_set_idle_timeout_action:testaction:1" question_ref="ocil:ssg-sshd_set_idle_timeout_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_set_keepalive_action:testaction:1" question_ref="ocil:ssg-sshd_set_keepalive_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_set_keepalive_0_action:testaction:1" question_ref="ocil:ssg-sshd_set_keepalive_0_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_set_login_grace_time_action:testaction:1" question_ref="ocil:ssg-sshd_set_login_grace_time_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_set_loglevel_info_action:testaction:1" question_ref="ocil:ssg-sshd_set_loglevel_info_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_set_loglevel_verbose_action:testaction:1" question_ref="ocil:ssg-sshd_set_loglevel_verbose_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_set_max_auth_tries_action:testaction:1" question_ref="ocil:ssg-sshd_set_max_auth_tries_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_set_max_sessions_action:testaction:1" question_ref="ocil:ssg-sshd_set_max_sessions_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_set_maxstartups_action:testaction:1" question_ref="ocil:ssg-sshd_set_maxstartups_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_use_approved_ciphers_action:testaction:1" question_ref="ocil:ssg-sshd_use_approved_ciphers_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_use_approved_kex_ordered_stig_action:testaction:1" question_ref="ocil:ssg-sshd_use_approved_kex_ordered_stig_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_use_approved_macs_action:testaction:1" question_ref="ocil:ssg-sshd_use_approved_macs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_use_priv_separation_action:testaction:1" question_ref="ocil:ssg-sshd_use_priv_separation_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_use_strong_kex_action:testaction:1" question_ref="ocil:ssg-sshd_use_strong_kex_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_use_strong_macs_action:testaction:1" question_ref="ocil:ssg-sshd_use_strong_macs_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_use_strong_rng_action:testaction:1" question_ref="ocil:ssg-sshd_use_strong_rng_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sshd_x11_use_localhost_action:testaction:1" question_ref="ocil:ssg-sshd_x11_use_localhost_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sssd_certificate_verification_action:testaction:1" question_ref="ocil:ssg-sssd_certificate_verification_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sssd_enable_certmap_action:testaction:1" question_ref="ocil:ssg-sssd_enable_certmap_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sssd_enable_pam_services_action:testaction:1" question_ref="ocil:ssg-sssd_enable_pam_services_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sssd_enable_smartcards_action:testaction:1" question_ref="ocil:ssg-sssd_enable_smartcards_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sssd_has_trust_anchor_action:testaction:1" question_ref="ocil:ssg-sssd_has_trust_anchor_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sssd_ldap_configure_tls_ca_action:testaction:1" question_ref="ocil:ssg-sssd_ldap_configure_tls_ca_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sssd_ldap_configure_tls_ca_dir_action:testaction:1" question_ref="ocil:ssg-sssd_ldap_configure_tls_ca_dir_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sssd_ldap_configure_tls_reqcert_action:testaction:1" question_ref="ocil:ssg-sssd_ldap_configure_tls_reqcert_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sssd_ldap_start_tls_action:testaction:1" question_ref="ocil:ssg-sssd_ldap_start_tls_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sssd_memcache_timeout_action:testaction:1" question_ref="ocil:ssg-sssd_memcache_timeout_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sssd_offline_cred_expiration_action:testaction:1" question_ref="ocil:ssg-sssd_offline_cred_expiration_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sssd_run_as_sssd_user_action:testaction:1" question_ref="ocil:ssg-sssd_run_as_sssd_user_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sssd_ssh_known_hosts_timeout_action:testaction:1" question_ref="ocil:ssg-sssd_ssh_known_hosts_timeout_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudo_add_env_reset_action:testaction:1" question_ref="ocil:ssg-sudo_add_env_reset_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudo_add_ignore_dot_action:testaction:1" question_ref="ocil:ssg-sudo_add_ignore_dot_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudo_add_noexec_action:testaction:1" question_ref="ocil:ssg-sudo_add_noexec_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudo_add_passwd_timeout_action:testaction:1" question_ref="ocil:ssg-sudo_add_passwd_timeout_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudo_add_requiretty_action:testaction:1" question_ref="ocil:ssg-sudo_add_requiretty_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudo_add_umask_action:testaction:1" question_ref="ocil:ssg-sudo_add_umask_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudo_add_use_pty_action:testaction:1" question_ref="ocil:ssg-sudo_add_use_pty_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudo_custom_logfile_action:testaction:1" question_ref="ocil:ssg-sudo_custom_logfile_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudo_dedicated_group_action:testaction:1" question_ref="ocil:ssg-sudo_dedicated_group_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudo_remove_no_authenticate_action:testaction:1" question_ref="ocil:ssg-sudo_remove_no_authenticate_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudo_remove_nopasswd_action:testaction:1" question_ref="ocil:ssg-sudo_remove_nopasswd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudo_require_authentication_action:testaction:1" question_ref="ocil:ssg-sudo_require_authentication_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudo_require_reauthentication_action:testaction:1" question_ref="ocil:ssg-sudo_require_reauthentication_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudo_restrict_others_executable_permission_action:testaction:1" question_ref="ocil:ssg-sudo_restrict_others_executable_permission_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_action:testaction:1" question_ref="ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudo_vdsm_nopasswd_action:testaction:1" question_ref="ocil:ssg-sudo_vdsm_nopasswd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudoers_default_includedir_action:testaction:1" question_ref="ocil:ssg-sudoers_default_includedir_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudoers_explicit_command_args_action:testaction:1" question_ref="ocil:ssg-sudoers_explicit_command_args_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudoers_no_command_negation_action:testaction:1" question_ref="ocil:ssg-sudoers_no_command_negation_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudoers_no_root_target_action:testaction:1" question_ref="ocil:ssg-sudoers_no_root_target_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sudoers_validate_passwd_action:testaction:1" question_ref="ocil:ssg-sudoers_validate_passwd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysconfig_networking_bootproto_ifcfg_action:testaction:1" question_ref="ocil:ssg-sysconfig_networking_bootproto_ifcfg_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_crypto_fips_enabled_action:testaction:1" question_ref="ocil:ssg-sysctl_crypto_fips_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_fs_protected_hardlinks_action:testaction:1" question_ref="ocil:ssg-sysctl_fs_protected_hardlinks_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_fs_protected_symlinks_action:testaction:1" question_ref="ocil:ssg-sysctl_fs_protected_symlinks_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_fs_suid_dumpable_action:testaction:1" question_ref="ocil:ssg-sysctl_fs_suid_dumpable_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_kernel_core_pattern_action:testaction:1" question_ref="ocil:ssg-sysctl_kernel_core_pattern_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_kernel_core_uses_pid_action:testaction:1" question_ref="ocil:ssg-sysctl_kernel_core_uses_pid_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_kernel_dmesg_restrict_action:testaction:1" question_ref="ocil:ssg-sysctl_kernel_dmesg_restrict_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_kernel_exec_shield_action:testaction:1" question_ref="ocil:ssg-sysctl_kernel_exec_shield_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_kernel_kexec_load_disabled_action:testaction:1" question_ref="ocil:ssg-sysctl_kernel_kexec_load_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_kernel_kptr_restrict_action:testaction:1" question_ref="ocil:ssg-sysctl_kernel_kptr_restrict_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_kernel_modules_disabled_action:testaction:1" question_ref="ocil:ssg-sysctl_kernel_modules_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_kernel_panic_on_oops_action:testaction:1" question_ref="ocil:ssg-sysctl_kernel_panic_on_oops_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_kernel_perf_cpu_time_max_percent_action:testaction:1" question_ref="ocil:ssg-sysctl_kernel_perf_cpu_time_max_percent_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_kernel_perf_event_max_sample_rate_action:testaction:1" question_ref="ocil:ssg-sysctl_kernel_perf_event_max_sample_rate_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_kernel_perf_event_paranoid_action:testaction:1" question_ref="ocil:ssg-sysctl_kernel_perf_event_paranoid_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_kernel_pid_max_action:testaction:1" question_ref="ocil:ssg-sysctl_kernel_pid_max_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_kernel_randomize_va_space_action:testaction:1" question_ref="ocil:ssg-sysctl_kernel_randomize_va_space_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_kernel_sysrq_action:testaction:1" question_ref="ocil:ssg-sysctl_kernel_sysrq_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_kernel_unprivileged_bpf_disabled_action:testaction:1" question_ref="ocil:ssg-sysctl_kernel_unprivileged_bpf_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_kernel_yama_ptrace_scope_action:testaction:1" question_ref="ocil:ssg-sysctl_kernel_yama_ptrace_scope_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_core_bpf_jit_harden_action:testaction:1" question_ref="ocil:ssg-sysctl_net_core_bpf_jit_harden_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_all_drop_gratuitous_arp_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_all_drop_gratuitous_arp_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_all_forwarding_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_all_forwarding_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_default_forwarding_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_default_forwarding_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_ip_forward_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_ip_forward_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_ip_local_port_range_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_ip_local_port_range_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_tcp_invalid_ratelimit_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_tcp_invalid_ratelimit_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_tcp_rfc1337_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_tcp_rfc1337_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv4_tcp_syncookies_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv4_tcp_syncookies_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_all_max_addresses_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_all_max_addresses_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_all_router_solicitations_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_all_router_solicitations_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_default_autoconf_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_default_autoconf_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_default_forwarding_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_default_forwarding_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_default_max_addresses_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_default_max_addresses_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_net_ipv6_conf_default_router_solicitations_action:testaction:1" question_ref="ocil:ssg-sysctl_net_ipv6_conf_default_router_solicitations_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_user_max_user_namespaces_action:testaction:1" question_ref="ocil:ssg-sysctl_user_max_user_namespaces_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_user_max_user_namespaces_no_remediation_action:testaction:1" question_ref="ocil:ssg-sysctl_user_max_user_namespaces_no_remediation_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-sysctl_vm_mmap_min_addr_action:testaction:1" question_ref="ocil:ssg-sysctl_vm_mmap_min_addr_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-systemd_tmp_mount_enabled_action:testaction:1" question_ref="ocil:ssg-systemd_tmp_mount_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-tftp_uses_secure_mode_systemd_action:testaction:1" question_ref="ocil:ssg-tftp_uses_secure_mode_systemd_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-tftpd_uses_secure_mode_action:testaction:1" question_ref="ocil:ssg-tftpd_uses_secure_mode_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-timer_dnf-automatic_enabled_action:testaction:1" question_ref="ocil:ssg-timer_dnf-automatic_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-timer_logrotate_enabled_action:testaction:1" question_ref="ocil:ssg-timer_logrotate_enabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-uefi_no_removeable_media_action:testaction:1" question_ref="ocil:ssg-uefi_no_removeable_media_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-umask_for_daemons_action:testaction:1" question_ref="ocil:ssg-umask_for_daemons_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-usbguard_allow_hid_action:testaction:1" question_ref="ocil:ssg-usbguard_allow_hid_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-usbguard_allow_hid_and_hub_action:testaction:1" question_ref="ocil:ssg-usbguard_allow_hid_and_hub_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-usbguard_allow_hub_action:testaction:1" question_ref="ocil:ssg-usbguard_allow_hub_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-usbguard_generate_policy_action:testaction:1" question_ref="ocil:ssg-usbguard_generate_policy_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-use_kerberos_security_all_exports_action:testaction:1" question_ref="ocil:ssg-use_kerberos_security_all_exports_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-use_pam_wheel_for_su_action:testaction:1" question_ref="ocil:ssg-use_pam_wheel_for_su_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-use_pam_wheel_group_for_su_action:testaction:1" question_ref="ocil:ssg-use_pam_wheel_group_for_su_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-wireless_disable_in_bios_action:testaction:1" question_ref="ocil:ssg-wireless_disable_in_bios_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-wireless_disable_interfaces_action:testaction:1" question_ref="ocil:ssg-wireless_disable_interfaces_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-xwayland_disabled_action:testaction:1" question_ref="ocil:ssg-xwayland_disabled_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-xwindows_remove_packages_action:testaction:1" question_ref="ocil:ssg-xwindows_remove_packages_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-xwindows_runlevel_target_action:testaction:1" question_ref="ocil:ssg-xwindows_runlevel_target_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-zipl_audit_argument_action:testaction:1" question_ref="ocil:ssg-zipl_audit_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-zipl_audit_backlog_limit_argument_action:testaction:1" question_ref="ocil:ssg-zipl_audit_backlog_limit_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-zipl_bls_entries_only_action:testaction:1" question_ref="ocil:ssg-zipl_bls_entries_only_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-zipl_bootmap_is_up_to_date_action:testaction:1" question_ref="ocil:ssg-zipl_bootmap_is_up_to_date_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-zipl_enable_selinux_action:testaction:1" question_ref="ocil:ssg-zipl_enable_selinux_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-zipl_page_poison_argument_action:testaction:1" question_ref="ocil:ssg-zipl_page_poison_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-zipl_slub_debug_argument_action:testaction:1" question_ref="ocil:ssg-zipl_slub_debug_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-zipl_systemd_debug-shell_argument_absent_action:testaction:1" question_ref="ocil:ssg-zipl_systemd_debug-shell_argument_absent_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
        <ocil:boolean_question_test_action id="ocil:ssg-zipl_vsyscall_argument_action:testaction:1" question_ref="ocil:ssg-zipl_vsyscall_argument_question:question:1">
          <ocil:when_true>
            <ocil:result>PASS</ocil:result>
          </ocil:when_true>
          <ocil:when_false>
            <ocil:result>FAIL</ocil:result>
          </ocil:when_false>
        </ocil:boolean_question_test_action>
      </ocil:test_actions>
      <ocil:questions>
        <ocil:boolean_question id="ocil:ssg-account_disable_post_pw_expiration_question:question:1">
          <ocil:question_text>To verify the INACTIVE setting, run the following command:
$ grep "INACTIVE" /etc/default/useradd
The output should indicate the INACTIVE configuration option is set
to an appropriate integer as shown in the example below:
$ grep "INACTIVE" /etc/default/useradd
INACTIVE=
      Is it the case that the value of INACTIVE is greater than the expected value or is -1?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-account_emergency_expire_date_question:question:1">
          <ocil:question_text>Verify emergency accounts have been provisioned with an expiration date of 72 hours.

For every emergency account, run the following command to obtain its account aging and expiration information:

$ sudo chage -l emergency_account_name

Verify each of these accounts has an expiration date set within 72 hours or as documented.
      Is it the case that any emergency accounts have no expiration date set or do not expire within 72 hours?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-account_password_pam_faillock_password_auth_question:question:1">
          <ocil:question_text>Verify the pam_faillock.so module is present in the "/etc/pam.d/password-auth" file:

$ sudo grep pam_faillock.so /etc/pam.d/password-auth

auth required pam_faillock.so preauth
auth required pam_faillock.so authfail
account required pam_faillock.so
      Is it the case that the pam_faillock.so module is not present in the "/etc/pam.d/password-auth" file with the "preauth" line listed before pam_unix.so?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-account_password_pam_faillock_system_auth_question:question:1">
          <ocil:question_text>Verify the pam_faillock.so module is present in the "/etc/pam.d/system-auth" file:

$ sudo grep pam_faillock.so /etc/pam.d/system-auth

auth required pam_faillock.so preauth
auth required pam_faillock.so authfail
account required pam_faillock.so
      Is it the case that the pam_faillock.so module is not present in the "/etc/pam.d/system-auth" file with the "preauth" line listed before pam_unix.so?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-account_password_selinux_faillock_dir_question:question:1">
          <ocil:question_text>If the system does not have SELinux enabled and enforcing a targeted policy, or if the
pam_faillock.so module is not configured for use, this requirement is not applicable.

Verify the location of the non-default tally directory for the pam_faillock.so module with
the following command:

$ sudo grep -w dir /etc/security/faillock.conf

dir = /var/log/faillock

Check the security context type of the non-default tally directory with the following command:

$ sudo ls -Zd /var/log/faillock

unconfined_u:object_r:faillog_t:s0 /var/log/faillock
      Is it the case that the security context type of the non-default tally directory is not "faillog_t"?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-account_passwords_pam_faillock_audit_question:question:1">
          <ocil:question_text>Verify the "/etc/security/faillock.conf" file is configured to log user name information when unsuccessful logon attempts occur:

$ sudo grep audit /etc/security/faillock.conf

audit
      Is it the case that the "audit" option is not set, is missing or commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-account_passwords_pam_faillock_dir_question:question:1">
          <ocil:question_text>Verify the "/etc/security/faillock.conf" file is configured use a non-default faillock directory to ensure contents persist after reboot:

$ sudo grep 'dir =' /etc/security/faillock.conf

dir = /var/log/faillock
      Is it the case that the "dir" option is not set to a non-default documented tally log directory, is missing or commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-account_temp_expire_date_question:question:1">
          <ocil:question_text>Verify that temporary accounts have been provisioned with an expiration date
of 72 hours. For every temporary account, run the following command to
obtain its account aging and expiration information:
$ sudo chage -l temporary_account_name
Verify each of these accounts has an expiration date set within 72 hours or
as documented.
      Is it the case that any temporary accounts have no expiration date set or do not expire within 72 hours?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-account_unique_id_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 contains no duplicate User IDs (UIDs) for interactive users.

Check that the operating system contains no duplicate UIDs for interactive users with the following command:

$ sudo awk -F ":" 'list[$3]++{print $1, $3}' /etc/passwd
      Is it the case that output is produced and the accounts listed are interactive user accounts?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-account_unique_name_question:question:1">
          <ocil:question_text>To verify all accounts have unique names, run the following command:
$ sudo getent passwd | awk -F: '{ print $1}' | uniq -d
No output should be returned.
      Is it the case that a line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-account_use_centralized_automated_auth_question:question:1">
          <ocil:question_text>Verify that the system is integrated with a centralized authentication mechanism
such as as Active Directory, Kerberos, Directory Server, etc. that has
automated account mechanisms in place.
      Is it the case that the system is not using a centralized authentication mechanism, or it is not automated?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_authorized_local_users_question:question:1">
          <ocil:question_text>To verify that there are no unauthorized local user accounts, run the following command:
$ less /etc/passwd 
Inspect the results, and if unauthorized local user accounts exist, remove them by running
the following command:
$ sudo userdel unauthorized_user
      Is it the case that there are unauthorized local user accounts on the system?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_have_homedir_login_defs_question:question:1">
          <ocil:question_text>Verify all local interactive users on AlmaLinux OS 8 are assigned a home
directory upon creation with the following command:
$ grep -i create_home /etc/login.defs
CREATE_HOME yes
      Is it the case that the value for "CREATE_HOME" parameter is not set to "yes", the line is missing, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_logon_fail_delay_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 enforces a delay of at least  seconds between console logon prompts following a failed logon attempt with the following command:

$ sudo grep -i "FAIL_DELAY" /etc/login.defs
FAIL_DELAY 
      Is it the case that the value of "FAIL_DELAY" is not set to "&lt;sub idref="var_accounts_fail_delay" /&gt;" or greater, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_max_concurrent_login_sessions_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 limits the number of concurrent sessions to
"" for all
accounts and/or account types with the following command:
$ grep -r -s maxlogins /etc/security/limits.conf /etc/security/limits.d/*.conf
/etc/security/limits.conf:* hard maxlogins 10
This can be set as a global domain (with the * wildcard) but may be set differently for multiple domains.
      Is it the case that the "maxlogins" item is missing, commented out, or the value is set greater
than "&lt;sub idref="var_accounts_max_concurrent_login_sessions" /&gt;" and
is not documented with the Information System Security Officer (ISSO) as an
operational requirement for all domains that have the "maxlogins" item
assigned'?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_maximum_age_login_defs_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 enforces a -day maximum password lifetime for new user accounts by running the following command:

$ grep -i pass_max_days /etc/login.defs

PASS_MAX_DAYS 
      Is it the case that the "PASS_MAX_DAYS" parameter value is greater than "&lt;sub idref="var_accounts_maximum_age_login_defs" /&gt;", or commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_minimum_age_login_defs_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 enforces 24 hours/one day as the minimum password lifetime for new user accounts.

Check for the value of "PASS_MIN_DAYS" in "/etc/login.defs" with the following command:

$ grep -i pass_min_days /etc/login.defs

PASS_MIN_DAYS 
      Is it the case that the "PASS_MIN_DAYS" parameter value is not "&lt;sub idref="var_accounts_minimum_age_login_defs" /&gt;" or greater, or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_no_uid_except_zero_question:question:1">
          <ocil:question_text>Verify that only the "root" account has a UID "0" assignment with the
following command:
$ awk -F: '$3 == 0 {print $1}' /etc/passwd
root
Also make sure that if non-root account with UID "0" exist, it is locked:
$ grep -E '^[^:]+:[!*][^:]*:.*$' /etc/shadow
      Is it the case that any accounts other than "root" have a UID of "0"?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_all_shadowed_question:question:1">
          <ocil:question_text>To check that no password hashes are stored in
/etc/passwd, run the following command:
awk '!/\S:x|\*/ {print}' /etc/passwd
If it produces any output, then a password hash is
stored in /etc/passwd.
      Is it the case that any stored hashes are found in /etc/passwd?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_all_shadowed_sha512_question:question:1">
          <ocil:question_text>Verify that the interactive user account passwords are using a strong
password hash with the following command:

$ sudo cut -d: -f2 /etc/shadow

$6$kcOnRq/5$NUEYPuyL.wghQwWssXRcLRFiiru7f5JPV6GaJhNC2aK5F3PZpE/BCCtwrxRc/AInKMNX3CdMw11m9STiql12f/

Password hashes ! or * indicate inactive accounts not
available for logon and are not evaluated.
      Is it the case that any interactive user password hash does not begin with "$6"?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_last_change_is_in_past_question:question:1">
          <ocil:question_text>Verify that the interactive user account passwords last change time is not in the future
The following command should return no output
$ sudo expiration=$(cat /etc/shadow|awk -F ':' '{print $3}');
for edate in ${expiration[@]}; do if [[ $edate &gt; $(( $(date +%s)/86400 )) ]];
then echo "Expiry date in future";
fi; done 
      Is it the case that any interactive user password that has last change time in the future?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_minlen_login_defs_question:question:1">
          <ocil:question_text>To check the minimum password length, run the command:
$ grep PASS_MIN_LEN /etc/login.defs
The profile requirement is
.
      Is it the case that it is not set to the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_dcredit_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 enforces password complexity by requiring that at least one numeric character be used.

Check the value for "dcredit" with the following command:

$ sudo grep dcredit /etc/security/pwquality.conf /etc/security/pwquality.conf.d/*.conf

/etc/security/pwquality.conf:dcredit = 
      Is it the case that the value of "dcredit" is a positive number or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_dictcheck_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 prevents the use of dictionary words for passwords with the following command:

$ sudo grep dictcheck /etc/security/pwquality.conf /etc/pwquality.conf.d/*.conf

/etc/security/pwquality.conf:dictcheck=1
      Is it the case that "dictcheck" does not have a value other than "0", or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_difok_question:question:1">
          <ocil:question_text>Verify the value of the "difok" option in "/etc/security/pwquality.conf" with the following command:

$ sudo grep difok /etc/security/pwquality.conf

difok = 
      Is it the case that the value of "difok" is set to less than "&lt;sub idref="var_password_pam_difok" /&gt;", or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_enforce_local_question:question:1">
          <ocil:question_text>To verify if password complexities are only enforce on local users, run the following command:
$ grep local_users_only /etc/security/pwquality.conf
The output should return local_users_only uncommented.
      Is it the case that local_users_only is not uncommented or configured correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_enforce_root_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 enforces password complexity rules for the root account.

Check if root user is required to use complex passwords with the following command:

$ grep enforce_for_root /etc/security/pwquality.conf /etc/security/pwquality.conf.d/*.conf

/etc/security/pwquality.conf:enforce_for_root
      Is it the case that "enforce_for_root" is commented or missing?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_lcredit_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 enforces password complexity by requiring that at least one lower-case character.

Check the value for "lcredit" with the following command:

$ sudo grep lcredit /etc/security/pwquality.conf /etc/security/pwquality.conf.d/*.conf

/etc/security/pwquality.conf:lcredit = -1
      Is it the case that the value of "lcredit" is a positive number or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_maxclassrepeat_question:question:1">
          <ocil:question_text>Verify the value of the "maxclassrepeat" option in "/etc/security/pwquality.conf" with the following command:

$ grep maxclassrepeat /etc/security/pwquality.conf

maxclassrepeat = 
      Is it the case that the value of "maxclassrepeat" is set to "0", more than "&lt;sub idref="var_password_pam_maxclassrepeat" /&gt;" or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_maxrepeat_question:question:1">
          <ocil:question_text>Verify the value of the "maxrepeat" option in "/etc/security/pwquality.conf" with the following command:

$ grep maxrepeat /etc/security/pwquality.conf

maxrepeat = 
      Is it the case that the value of "maxrepeat" is set to more than "&lt;sub idref="var_password_pam_maxrepeat" /&gt;" or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_minclass_question:question:1">
          <ocil:question_text>Verify the value of the "minclass" option in "/etc/security/pwquality.conf" with the following command:

$ grep minclass /etc/security/pwquality.conf

minclass = 
      Is it the case that the value of "minclass" is set to less than "&lt;sub idref="var_password_pam_minclass" /&gt;" or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_minlen_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 enforces a minimum -character password length with the following command:

$ grep minlen /etc/security/pwquality.conf

minlen = 
      Is it the case that the command does not return a "minlen" value of "&lt;sub idref="var_password_pam_minlen" /&gt;" or greater, does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_modules_in_authselect_profile_question:question:1">
          <ocil:question_text>Run the following command to verify the active authselect profile includes lines for the
pwquality, pwhistory, faillock, and unix modules:

# grep -P '\b(pam_pwquality\.so|pam_pwhistory\.so|pam_faillock\.so|pam_unix\.so)\b' /etc/authselect/"$(head -1 /etc/authselect/authselect.conf)"/{system,password}-auth

The output should show entries for all four modules in both system-auth and password-auth files.
      Is it the case that the active authselect profile does not include all required PAM modules?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_ocredit_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 enforces password complexity by requiring that at least one special character with the following command:

$ sudo grep ocredit /etc/security/pwquality.conf /etc/security/pwquality.conf.d/*.conf

ocredit = 
      Is it the case that value of "ocredit" is a positive number or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_pwhistory_remember_password_auth_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 use the "pam_pwhistory.so" module in the /etc/pam.d/password-auth file
and is configured to prohibit password reuse for a minimum of 
generations.

Verify the "/etc/pam.d/password-auth" file with the following command:

$ grep pam_pwhistory.so /etc/pam.d/password-auth
password  pam_pwhistory.so use_authtok remember=


Verify the "/etc/security/pwhistory.conf" file using the following command:

$ grep remember /etc/security/pwhistory.conf
remember = 

The pam_pwhistory.so "remember" option must be configured only in one file.
      Is it the case that the pam_pwhistory.so module is not used, the "remember" module option is not set in
/etc/pam.d/password-auth or in /etc/security/pwhistory.conf, or is set in both files, or is set
with a value less than "&lt;sub idref="var_password_pam_remember" /&gt;"?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_pwhistory_remember_system_auth_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 use the "pam_pwhistory.so" module in the /etc/pam.d/system-auth file
and is configured to prohibit password reuse for a minimum of 
generations.

Verify the "/etc/pam.d/system-auth" file with the following command:

$ grep pam_pwhistory.so /etc/pam.d/system-auth
password  pam_pwhistory.so use_authtok remember=


Verify the "/etc/security/pwhistory.conf" file using the following command:

$ grep remember /etc/security/pwhistory.conf
remember = 

The pam_pwhistory.so "remember" option must be configured only in one file.
      Is it the case that the pam_pwhistory.so module is not used, the "remember" module option is not set in
/etc/pam.d/system-auth or in /etc/security/pwhistory.conf, or is set in both files, or is set
with a value less than "&lt;sub idref="var_password_pam_remember" /&gt;"?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_pwquality_password_auth_question:question:1">
          <ocil:question_text>To check if pam_pwquality.so is enabled in password-auth, run the following command:
$ grep pam_pwquality /etc/pam.d/password-auth
The output should be similar to the following:
password requisite pam_pwquality.so
      Is it the case that pam_pwquality.so is not enabled in password-auth?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_pwquality_system_auth_question:question:1">
          <ocil:question_text>To check if pam_pwquality.so is enabled in system-auth, run the following command:
$ grep pam_pwquality /etc/pam.d/system-auth
The output should be similar to the following:
password requisite pam_pwquality.so
      Is it the case that pam_pwquality.so is not enabled in system-auth?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_retry_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 is configured to limit the "pwquality" retry option to .


Check for the use of the "pwquality" retry option in the PAM files with the following command:

$ grep pam_pwquality /etc/pam.d/system-auth


password requisite pam_pwquality.so retry=
      Is it the case that the value of "retry" is set to "0" or greater than "&lt;sub idref="var_password_pam_retry" /&gt;", or is missing?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_ucredit_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 enforces password complexity by requiring that at least one upper-case character.

Check the value for "ucredit" with the following command:

$ sudo grep ucredit /etc/security/pwquality.conf /etc/security/pwquality.conf.d/*.conf

ucredit = -1
      Is it the case that the value of "ucredit" is a positive number or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_unix_authtok_question:question:1">
          <ocil:question_text>To verify the password reuse setting is compliant, run the following command:
$ grep use_authtok /etc/pam.d/common-password
The output should show use_authtok on the line.
      Is it the case that Usage of use_authtok for pam_unix.so is required?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_unix_no_remember_question:question:1">
          <ocil:question_text>To verify that the remember option is not present in pam_unix.so configuration,
run the following command:

$ grep -E "^\s*password\s+.*pam_unix\.so.*\bremember=" /etc/pam.d/system-auth /etc/pam.d/password-auth

The command should not return any output. If any lines are returned, it means the remember
option is configured in pam_unix.so, which is not compliant with this requirement.
      Is it the case that the remember option is found in pam_unix.so configuration?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_unix_remember_question:question:1">
          <ocil:question_text>To verify the password reuse setting is compliant, run the following command:
$ grep remember /etc/pam.d/system-auth
The output should show the following at the end of the line:
remember=


In newer systems, the pam_pwhistory PAM module options can also be set in
"/etc/security/pwhistory.conf" file. Use the following command to verify:
$ grep remember /etc/security/pwhistory.conf
remember = 

The pam_pwhistory remember option must be configured only in one file.
      Is it the case that the value of remember is not equal to or greater than the expected value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_unix_rounds_password_auth_question:question:1">
          <ocil:question_text>To verify the number of rounds for the password hashing algorithm is configured, run the following command:
$ sudo grep rounds /etc/pam.d/password-auth
The output should show the following match:

password sufficient pam_unix.so sha512 rounds=
      Is it the case that rounds is not set to &lt;sub idref="var_password_pam_unix_rounds" /&gt; or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_pam_unix_rounds_system_auth_question:question:1">
          <ocil:question_text>To verify the number of rounds for the password hashing algorithm is configured, run the following command:
$ sudo grep rounds /etc/pam.d/system-auth
The output should show the following match:
password sufficient pam_unix.so sha512 rounds=
      Is it the case that rounds is not set to &lt;sub idref="var_password_pam_unix_rounds" /&gt; or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_set_max_life_existing_question:question:1">
          <ocil:question_text>Check whether the maximum time period for existing passwords is restricted to  days with the following commands:

$ sudo awk -F: '$5 &gt; 60 {print $1 " " $5}' /etc/shadow

$ sudo awk -F: '$5 &lt;= 0 {print $1 " " $5}' /etc/shadow
      Is it the case that any results are returned that are not associated with a system account?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_set_max_life_root_question:question:1">
          <ocil:question_text>Check whether the maximum time period for root account password is restricted to  days with the following commands:

$ sudo awk -F: '$1 == "root" {print $1 " " $5}' /etc/shadow
      Is it the case that any results are returned that are not associated with a system account?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_set_min_life_existing_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 has configured the minimum time period between password changes for each user account is one day or greater with the following command:

$ sudo awk -F: '$4 &lt; 1 {print $1 " " $4}' /etc/shadow
      Is it the case that any results are returned that are not associated with a system account?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_set_warn_age_existing_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 set the days of warning before a password expires to
 or more for users with a
password:

$ sudo awk -F: '$6  || $6 == "" {print $1}' /etc/shadow
      Is it the case that any results are returned that are not associated with a system account?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_password_warn_age_login_defs_question:question:1">
          <ocil:question_text>To check the password warning age, run the command:
$ grep PASS_WARN_AGE /etc/login.defs
The profile requirement is .
      Is it the case that it is not set to the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_passwords_pam_faillock_audit_question:question:1">
          <ocil:question_text>Verify the "/etc/security/faillock.conf" file is configured to log user name information when unsuccessful logon attempts occur:

$ sudo grep audit /etc/security/faillock.conf

audit
      Is it the case that the "audit" option is not set, is missing or commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_passwords_pam_faillock_deny_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 is configured to lock an account after 
unsuccessful logon attempts with the command:

$ grep 'deny =' /etc/security/faillock.conf
deny = .
      Is it the case that the "deny" option is not set to "&lt;sub idref="var_accounts_passwords_pam_faillock_deny" /&gt;"
or less (but not "0"), is missing or commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_passwords_pam_faillock_deny_root_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 is configured to lock the root account after 
unsuccessful logon attempts with the command:

$ grep even_deny_root /etc/security/faillock.conf
even_deny_root
      Is it the case that the "even_deny_root" option is not set, is missing or commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_passwords_pam_faillock_dir_question:question:1">
          <ocil:question_text>To ensure the tally directory is configured correctly, run the following command:
$ sudo grep 'dir =' /etc/security/faillock.conf
The output should show that dir is set to something other than "/var/run/faillock"
      Is it the case that the "dir" option is not set to a non-default documented tally log directory, is missing or commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_passwords_pam_faillock_enforce_local_question:question:1">
          <ocil:question_text>To check if only local user are impacted by pam_faillock, run the following command:
$ grep local_users_only /etc/security/faillock.conf
The output should return local_users_only not commented.
      Is it the case that local_users_only is not uncommented or configured correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_passwords_pam_faillock_even_deny_root_or_root_unlock_time_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 is configured to include the root account in the account lockout policy with the command:
$ grep -E 'even_deny_root|root_unlock_time' /etc/security/faillock.conf
The output should show either: even_deny_root or: root_unlock_time = &lt;value&gt; where &lt;value&gt; is  or greater.
      Is it the case that neither "even_deny_root" is set nor "root_unlock_time" is set to &lt;sub idref="var_accounts_passwords_pam_faillock_root_unlock_time" /&gt; or greater?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_passwords_pam_faillock_interval_question:question:1">
          <ocil:question_text>To ensure the failed password attempt policy is configured correctly, run the following command:

$ grep fail_interval /etc/security/faillock.conf
The output should show fail_interval = &lt;interval-in-seconds&gt; where interval-in-seconds is  or greater.
      Is it the case that the "fail_interval" option is not set to "&lt;sub idref="var_accounts_passwords_pam_faillock_fail_interval" /&gt;"
or less (but not "0"), the line is commented out, or the line is missing?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_passwords_pam_faillock_silent_question:question:1">
          <ocil:question_text>To ensure that the system prevents messages from being shown when three unsuccessful logon
attempts occur, run the following command:
$ grep silent /etc/security/faillock.conf
The output should show silent.
      Is it the case that the system shows messages when three unsuccessful logon attempts occur?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 is configured to lock an account until released by an administrator
after  unsuccessful logon
attempts with the command:

$ grep 'unlock_time =' /etc/security/faillock.conf
unlock_time = 
      Is it the case that the "unlock_time" option is not set to "&lt;sub idref="var_accounts_passwords_pam_faillock_unlock_time" /&gt;",
the line is missing, or commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_passwords_pam_faillock_unlock_time_with_zero_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 is configured to lock an account until released by an administrator
after  unsuccessful logon
attempts with the command:

$ grep 'unlock_time =' /etc/security/faillock.conf
unlock_time = 
      Is it the case that the "unlock_time" option is not set to "0" or is not set to "&lt;sub idref="var_accounts_passwords_pam_faillock_unlock_time" /&gt;",
the line is missing, or commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_polyinstantiated_tmp_question:question:1">
          <ocil:question_text>Run the following command to ensure that /tmp is configured as a
polyinstantiated directory:
$ sudo grep /tmp /etc/security/namespace.conf
The output should return the following:
/tmp     /tmp/tmp-inst/            level      root,adm
      Is it the case that is not configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_polyinstantiated_var_tmp_question:question:1">
          <ocil:question_text>Run the following command to ensure that /var/tmp is configured as a
polyinstantiated directory:
$ sudo grep /var/tmp /etc/security/namespace.conf
The output should return the following:
/var/tmp /var/tmp/tmp-inst/    level      root,adm
      Is it the case that is not configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_root_gid_zero_question:question:1">
          <ocil:question_text>To verify that root's primary group is zero run the following command:

    awk -F: '($1 !~ /^(sync|shutdown|halt|operator)/ &amp;&amp; $4=="0") {print $1":"$4}' /etc/passwd

The command should return:

    root:0

      Is it the case that root has a primary gid not equal to zero or other non-system accounts has a primary gid equal to zero?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_root_path_dirs_no_write_question:question:1">
          <ocil:question_text>To ensure write permissions are disabled for group and other
 for each element in root's path, run the following command:
# ls -ld DIR
      Is it the case that group or other write permissions exist?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_set_post_pw_existing_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 's INACTIVE conforms to site policy (no more than 30 days) with the following command:

$ sudo awk -F: '$7 &gt; 30 {print $1 " " $7}' /etc/shadow
      Is it the case that the value of INACTIVE is greater than the expected value or is -1?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_tmout_question:question:1">
          <ocil:question_text>Run the following command to ensure the TMOUT value is configured for all users
on the system:

$ sudo grep TMOUT /etc/profile /etc/profile.d/*.sh

The output should return the following:
TMOUT=
      Is it the case that the TMOUT value is not configured, is set to 0, or is not less than or equal to the expected setting?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_umask_etc_bashrc_question:question:1">
          <ocil:question_text>Verify the umask setting is configured correctly in the /etc/bashrc file with the following command:

$ sudo grep "umask" /etc/bashrc

umask 
      Is it the case that the value for the "umask" parameter is not "&lt;sub idref="var_accounts_user_umask" /&gt;", or the "umask" parameter is missing or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_umask_etc_csh_cshrc_question:question:1">
          <ocil:question_text>Verify the "umask" setting is configured correctly in the "/etc/csh.cshrc" file with the following command:

$ grep umask /etc/csh.cshrc

umask 077
umask 077
      Is it the case that the value for the "umask" parameter is not "&lt;sub idref="var_accounts_user_umask" /&gt;", or the "umask" parameter is missing or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_umask_etc_login_defs_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 defines default permissions for all authenticated users in such a way that the user can only read and modify their own files with the following command:

# grep -i umask /etc/login.defs

UMASK 
      Is it the case that the value for the "UMASK" parameter is not "&lt;sub idref="var_accounts_user_umask" /&gt;", or the "UMASK" parameter is missing or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_umask_etc_profile_question:question:1">
          <ocil:question_text>Verify the umask setting is configured correctly in the /etc/profile file
or scripts within /etc/profile.d directory with the following command:
$ grep "umask" /etc/profile*
umask 
      Is it the case that the value for the "umask" parameter is not "&lt;sub idref="var_accounts_user_umask" /&gt;",
or the "umask" parameter is missing or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_umask_interactive_users_question:question:1">
          <ocil:question_text>Verify that the default umask for all local interactive users is "077".

Identify the locations of all local interactive user home directories by looking at the "/etc/passwd" file.

Check all local interactive user initialization files for interactive users with the following command:

Note: The example is for a system that is configured to create users home directories in the "/home" directory.

$ sudo find /home -maxdepth 2 -type f -name ".[^.]*" -exec grep -iH -d skip --exclude=.bash_history umask {} \;

/home/wadea/.bash_history:grep -i umask /etc/bashrc /etc/csh.cshrc /etc/profile
/home/wadea/.bash_history:grep -i umask /etc/login.defs
      Is it the case that any local interactive user initialization files are found to have a umask statement that sets a value less restrictive than "077"?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_user_dot_group_ownership_question:question:1">
          <ocil:question_text>To verify the local initialization files of all local interactive users are group-
owned by the appropriate user, inspect the primary group of the respective
users in /etc/passwd and verify all initialization files under the
respective users home directory. Check the group owner of all local interactive users
initialization files.
      Is it the case that they are not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_user_dot_no_world_writable_programs_question:question:1">
          <ocil:question_text>Verify that local initialization files do not execute world-writable programs with the following command:

Note: The example will be for a system that is configured to create user home directories in the "/home" directory.

$ sudo find /home -perm -002 -type f -name ".[^.]*" -exec ls -ld {} \;
      Is it the case that any local initialization files are found to reference world-writable files?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_user_dot_user_ownership_question:question:1">
          <ocil:question_text>To verify all local initialization files for interactive users are owned by the
primary user, run the following command:
$ sudo ls -al /home/USER/.*
The user initialization files should be owned by USER.
      Is it the case that they are not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_user_home_paths_only_question:question:1">
          <ocil:question_text>Verify that all local interactive user initialization file executable search path statements do not contain statements that will reference a working directory other than user home directories with the following commands:

$ sudo grep -i path= /home/*/.*

/home/[localinteractiveuser]/.bash_profile:PATH=$PATH:$HOME/.local/bin:$HOME/bin
      Is it the case that any local interactive user initialization files have executable search path statements that include directories outside of their home directory and is not documented with the ISSO as an operational requirement?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_user_interactive_home_directory_defined_question:question:1">
          <ocil:question_text>Verify that interactive users on the system have a home directory assigned with the following command:

$ sudo awk -F: '($3&gt;=1000)&amp;&amp;($7 !~ /nologin/){print $1, $3, $6}' /etc/passwd

Inspect the output and verify that all interactive users (normally users with a UID greater than 1000) have a home directory defined.
      Is it the case that users home directory is not defined?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_user_interactive_home_directory_exists_question:question:1">
          <ocil:question_text>Verify the assigned home directories of all interactive users on the system exist with the following command:

$ sudo pwck -r

user 'mailnull': directory 'var/spool/mqueue' does not exist

The output should not return any interactive users.
      Is it the case that users home directory does not exist?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_user_interactive_home_directory_on_separate_partition_question:question:1">
          <ocil:question_text>Verify that all interactive user home directories are on a separate
file system partition with the following commands:

List interactive users and their home directories:
$ awk -F: '($3&gt;=1000)&amp;&amp;($7 !~ /nologin/){print $1, $6}' /etc/passwd

For each home directory listed, verify it is on a separate partition:
$ df &lt;home_directory&gt; | tail -1 | awk '{print $6}'

If the command returns / for any interactive user home directory,
this is a finding.
      Is it the case that any interactive user home directory is on the root partition?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_users_home_files_groupownership_question:question:1">
          <ocil:question_text>To verify all files and directories in interactive user home directory are
group-owned by a group the user is a member of, run the
following command:
$ sudo ls -lLR /home/USER
      Is it the case that the group ownership is incorrect?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_users_home_files_ownership_question:question:1">
          <ocil:question_text>To verify all files and directories in a local interactive user's
home directory have a valid owner, run the following command:
$ sudo ls -lLR /home/USER
      Is it the case that the user ownership is incorrect?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_users_home_files_permissions_question:question:1">
          <ocil:question_text>To verify all files and directories contained in interactive user home
directory, excluding local initialization files, have a mode of 0750,
run the following command:
$ sudo ls -lLR /home/USER
      Is it the case that home directory files or folders have incorrect permissions?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-accounts_users_netrc_file_permissions_question:question:1">
          <ocil:question_text>To verify .netrc file in interactive user home directory is
not group or world accessible", run the following command:
$ sudo ls -lLR /home/USER/.netrc
      Is it the case that the group and world permissions are incorrect?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-agent_mfetpd_running_question:question:1">
          <ocil:question_text>To verify that McAfee Endpoint Security for Linux is
running, run the following command:
$ sudo ps -ef | grep -i mfetpd
      Is it the case that virus scanning software is not running?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-aide_build_database_question:question:1">
          <ocil:question_text>To find the location of the AIDE database file, run the following command:
$ sudo ls -l DBDIR/database_file_name
      Is it the case that there is no database file?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-aide_check_audit_tools_question:question:1">
          <ocil:question_text>Check that AIDE is properly configured to protect the integrity of the
audit tools by running the following command:

# sudo cat /etc/aide.conf | grep /usr/sbin/au

/usr/sbin/auditctl p+i+n+u+g+s+b+acl+selinux+xattrs+sha512
/usr/sbin/auditd p+i+n+u+g+s+b+acl+selinux+xattrs+sha512
/usr/sbin/ausearch p+i+n+u+g+s+b+acl+selinux+xattrs+sha512
/usr/sbin/aureport p+i+n+u+g+s+b+acl+selinux+xattrs+sha512
/usr/sbin/autrace p+i+n+u+g+s+b+acl+selinux+xattrs+sha512
/usr/sbin/audispd p+i+n+u+g+s+b+acl+selinux+xattrs+sha512

/usr/sbin/augenrules p+i+n+u+g+s+b+acl+selinux+xattrs+sha512


If AIDE is configured properly to protect the integrity of the audit tools,
all lines listed above will be returned from the command.

If one or more lines are missing, this is a finding.
      Is it the case that integrity checks of the audit tools are missing or incomplete?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-aide_periodic_cron_checking_question:question:1">
          <ocil:question_text>Verify the operating system routinely checks the baseline configuration for unauthorized changes.

To determine that periodic AIDE execution has been scheduled, run the following command:
$ grep aide /etc/crontab
The output should return something similar to the following:
05 4 * * * root /usr/sbin/aide --check

NOTE: The usage of special cron times, such as @daily or @weekly, is acceptable.
      Is it the case that AIDE is not configured to scan periodically?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-aide_scan_notification_question:question:1">
          <ocil:question_text>To determine that periodic AIDE execution has been scheduled, run the following command:

$ grep aide /etc/crontab
The output should return something similar to the following:
05 4 * * * root /usr/sbin/aide --check | /bin/mail -s "$(hostname) - AIDE Integrity Check" root@localhost
The email address that the notifications are sent to can be changed by overriding
.
      Is it the case that AIDE has not been configured or has not been configured to notify personnel of scan details?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-aide_use_fips_hashes_question:question:1">
          <ocil:question_text>To determine that AIDE is configured for FIPS 140-2 file hashing, run the following command:
$ grep sha512 /etc/aide.conf
Verify that the sha512 option is added to the correct ruleset.
      Is it the case that the sha512 option is missing or not added to the correct ruleset?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-aide_verify_acls_question:question:1">
          <ocil:question_text>To determine that AIDE is verifying ACLs, run the following command:
$ grep acl /etc/aide.conf
Verify that the acl option is added to the correct ruleset.
      Is it the case that the acl option is missing or not added to the correct ruleset?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-aide_verify_ext_attributes_question:question:1">
          <ocil:question_text>To determine that AIDE is verifying extended file attributes, run the following command:
$ grep xattrs /etc/aide.conf
Verify that the xattrs option is added to the correct ruleset.
      Is it the case that the xattrs option is missing or not added to the correct ruleset?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_access_failed_question:question:1">
          <ocil:question_text>To verify that the Audit is correctly configured according to recommended rules, check the content of the file with the following command:
cat /etc/audit/rules.d/30-ospp-v42-3-access-failed.rules
The output has to be exactly as follows:
## Unsuccessful file access (any other opens) This has to go last.
-a always,exit -F arch=b32 -S open,openat,openat2,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
-a always,exit -F arch=b64 -S open,openat,openat2,open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
-a always,exit -F arch=b32 -S open,openat,openat2,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access
-a always,exit -F arch=b64 -S open,openat,openat2,open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-access    
      Is it the case that the file does not exist or the content differs?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_access_success_question:question:1">
          <ocil:question_text>To verify that the Audit is correctly configured according to recommended rules, check the content of the file with the following command:
cat /etc/audit/rules.d/30-ospp-v42-3-access-success.rules
The output has to be exactly as follows:
## Successful file access (any other opens) This has to go last.
## These next two are likely to result in a whole lot of events
-a always,exit -F arch=b32 -S open,openat,openat2,open_by_handle_at -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access
-a always,exit -F arch=b64 -S open,openat,openat2,open_by_handle_at -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-access    
      Is it the case that the file does not exist or the content differs?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_basic_configuration_question:question:1">
          <ocil:question_text>To verify that the Audit is correctly configured according to recommended rules, check the content of the file with the following command:
cat /etc/audit/rules.d/10-base-config.rules
The output has to be exactly as follows:
## First rule - delete all
-D

## Increase the buffers to survive stress events.
## Make this bigger for busy systems
-b 8192

## This determine how long to wait in burst of events
--backlog_wait_time 60000

## Set failure mode to syslog
-f 1    
      Is it the case that the file does not exist or the content differs?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_create_failed_question:question:1">
          <ocil:question_text>To verify that the Audit is correctly configured according to recommended rules, check the content of the file with the following command:
cat /etc/audit/rules.d/30-ospp-v42-1-create-failed.rules
The output has to be exactly as follows:
## Unsuccessful file creation (open with O_CREAT)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create
-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-create    
      Is it the case that the file does not exist or the content differs?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_create_success_question:question:1">
          <ocil:question_text>To verify that the Audit is correctly configured according to recommended rules, check the content of the file with the following command:
cat /etc/audit/rules.d/30-ospp-v42-1-create-success.rules
The output has to be exactly as follows:
## Successful file creation (open with O_CREAT)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b32 -S creat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create
-a always,exit -F arch=b64 -S creat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-create    
      Is it the case that the file does not exist or the content differs?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_delete_failed_question:question:1">
          <ocil:question_text>To verify that the Audit is correctly configured according to recommended rules, check the content of the file with the following command:
cat /etc/audit/rules.d/30-ospp-v42-4-delete-failed.rules
The output has to be exactly as follows:
## Unsuccessful file delete
-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete
-a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-delete    
      Is it the case that the file does not exist or the content differs?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_delete_success_question:question:1">
          <ocil:question_text>To verify that the Audit is correctly configured according to recommended rules, check the content of the file with the following command:
cat /etc/audit/rules.d/30-ospp-v42-4-delete-success.rules
The output has to be exactly as follows:
## Successful file delete
-a always,exit -F arch=b32 -S unlink,unlinkat,rename,renameat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete
-a always,exit -F arch=b64 -S unlink,unlinkat,rename,renameat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-delete    
      Is it the case that the file does not exist or the content differs?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_immutable_login_uids_question:question:1">
          <ocil:question_text>To verify that the Audit is correctly configured according to recommended rules, check the content of the file with the following command:
$ sudo cat /etc/audit/rules.d/11-loginuid.rules
The output has to be exactly as follows:
## Make the loginuid immutable. This prevents tampering with the auid.
--loginuid-immutable    
      Is it the case that the file does not exist or the content differs?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_modify_failed_question:question:1">
          <ocil:question_text>To verify that the Audit is correctly configured according to recommended rules, check the content of the file with the following command:
cat /etc/audit/rules.d/30-ospp-v42-2-modify-failed.rules
The output has to be exactly as follows:
## Unsuccessful file modifications (open for write or truncate)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-modification    
      Is it the case that the file does not exist or the content differs?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_modify_success_question:question:1">
          <ocil:question_text>To verify that the Audit is correctly configured according to recommended rules, check the content of the file with the following command:
cat /etc/audit/rules.d/30-ospp-v42-2-modify-success.rules
The output has to be exactly as follows:
## Successful file modifications (open for write or truncate)
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b32 -S truncate,ftruncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification
-a always,exit -F arch=b64 -S truncate,ftruncate -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-modification    
      Is it the case that the file does not exist or the content differs?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_module_load_question:question:1">
          <ocil:question_text>To verify that the Audit is correctly configured according to recommended rules, check the content of the file with the following command:
cat /etc/audit/rules.d/43-module-load.rules
The output has to be exactly as follows:
## These rules watch for kernel module insertion. By monitoring
## the syscall, we do not need any watches on programs.
-a always,exit -F arch=b32 -S init_module,finit_module -F key=module-load
-a always,exit -F arch=b64 -S init_module,finit_module -F key=module-load
-a always,exit -F arch=b32 -S delete_module -F key=module-unload
-a always,exit -F arch=b64 -S delete_module -F key=module-unload    
      Is it the case that the file does not exist or the content differs?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_ospp_general_question:question:1">
          <ocil:question_text>To verify that the Audit is correctly configured according to recommended rules, check the content of the file with the following command:
cat /etc/audit/rules.d/30-ospp-v42.rules
The output has to be exactly as follows:
## The purpose of these rules is to meet the requirements for Operating
## System Protection Profile (OSPP)v4.2. These rules depends on having
## the following rule files copied to /etc/audit/rules.d:
##
## 10-base-config.rules, 11-loginuid.rules,
## 30-ospp-v42-1-create-failed.rules, 30-ospp-v42-1-create-success.rules,
## 30-ospp-v42-2-modify-failed.rules, 30-ospp-v42-2-modify-success.rules,
## 30-ospp-v42-3-access-failed.rules, 30-ospp-v42-3-access-success.rules,
## 30-ospp-v42-4-delete-failed.rules, 30-ospp-v42-4-delete-success.rules,
## 30-ospp-v42-5-perm-change-failed.rules,
## 30-ospp-v42-5-perm-change-success.rules,
## 30-ospp-v42-6-owner-change-failed.rules,
## 30-ospp-v42-6-owner-change-success.rules
##
## original copies may be found in /usr/share/audit/sample-rules/


## User add delete modify. This is covered by pam. However, someone could
## open a file and directly create or modify a user, so we'll watch passwd and
## shadow for writes
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -S open -F a1&amp;03 -F path=/etc/passwd -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -S openat,open_by_handle_at -F a2&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -S open -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -S open -F a1&amp;03 -F path=/etc/shadow -F auid&gt;=1000 -F auid!=unset -F key=user-modify

## User enable and disable. This is entirely handled by pam.

## Group add delete modify. This is covered by pam. However, someone could
## open a file and directly create or modify a user, so we'll watch group and
## gshadow for writes
-a always,exit -F arch=b32 -F path=/etc/passwd -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -F path=/etc/passwd -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -F path=/etc/shadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b64 -F path=/etc/shadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=user-modify
-a always,exit -F arch=b32 -F path=/etc/group -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify
-a always,exit -F arch=b64 -F path=/etc/group -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify
-a always,exit -F arch=b32 -F path=/etc/gshadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify
-a always,exit -F arch=b64 -F path=/etc/gshadow -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=group-modify


## Use of special rights for config changes. This would be use of setuid
## programs that relate to user accts. This is not all setuid apps because
## requirements are only for ones that affect system configuration.
-a always,exit -F arch=b32 -F path=/usr/sbin/unix_chkpwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/unix_chkpwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/sbin/usernetctl -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/usernetctl -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/sbin/userhelper -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/userhelper -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/sbin/seunshare -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/seunshare -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/mount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/mount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/newgrp -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/newgrp -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/newuidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/newuidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/gpasswd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/gpasswd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/newgidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/newgidmap -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/umount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/umount -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/passwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/passwd -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/crontab -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/crontab -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/bin/at -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/bin/at -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b32 -F path=/usr/sbin/grub2-set-bootflag -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/usr/sbin/grub2-set-bootflag -F perm=x -F auid&gt;=1000 -F auid!=unset -F key=special-config-changes

## Privilege escalation via su or sudo. This is entirely handled by pam.
## Special case for systemd-run. It is not audit aware, specifically watch it
-a always,exit -F arch=b32 -F path=/usr/bin/systemd-run -F perm=x -F auid!=unset -F key=maybe-escalation
-a always,exit -F arch=b64 -F path=/usr/bin/systemd-run -F perm=x -F auid!=unset -F key=maybe-escalation
## Special case for pkexec. It is not audit aware, specifically watch it
-a always,exit -F arch=b32 -F path=/usr/bin/pkexec -F perm=x -F key=maybe-escalation
-a always,exit -F arch=b64 -F path=/usr/bin/pkexec -F perm=x -F key=maybe-escalation


## Watch for configuration changes to privilege escalation.
-a always,exit -F arch=b32 -F path=/etc/sudoers -F perm=wa -F key=special-config-changes
-a always,exit -F arch=b64 -F path=/etc/sudoers -F perm=wa -F key=special-config-changes
-a always,exit -F arch=b32 -F dir=/etc/sudoers.d/ -F perm=wa -F key=special-config-changes
-a always,exit -F arch=b64 -F dir=/etc/sudoers.d/ -F perm=wa -F key=special-config-changes

## Audit log access
-a always,exit -F arch=b32 -F dir=/var/log/audit/ -F perm=r -F auid&gt;=1000 -F auid!=unset -F key=access-audit-trail
-a always,exit -F arch=b64 -F dir=/var/log/audit/ -F perm=r -F auid&gt;=1000 -F auid!=unset -F key=access-audit-trail
## Attempts to Alter Process and Session Initiation Information
-a always,exit -F arch=b32 -F path=/var/run/utmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b64 -F path=/var/run/utmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b32 -F path=/var/log/btmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b64 -F path=/var/log/btmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b32 -F path=/var/log/wtmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session
-a always,exit -F arch=b64 -F path=/var/log/wtmp -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=session

## Attempts to modify MAC controls
-a always,exit -F arch=b32 -F dir=/etc/selinux/ -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=MAC-policy
-a always,exit -F arch=b64 -F dir=/etc/selinux/ -F perm=wa -F auid&gt;=1000 -F auid!=unset -F key=MAC-policy

## Software updates. This is entirely handled by rpm.

## System start and shutdown. This is entirely handled by systemd

## Kernel Module loading. This is handled in 43-module-load.rules

## Application invocation. The requirements list an optional requirement
## FPT_SRP_EXT.1 Software Restriction Policies. This event is intended to
## state results from that policy. This would be handled entirely by
## that daemon.    
      Is it the case that the file does not exist or the content differs?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_owner_change_failed_question:question:1">
          <ocil:question_text>To verify that the Audit is correctly configured according to recommended rules, check the content of the file with the following command:
cat /etc/audit/rules.d/30-ospp-v42-6-owner-change-failed.rules
The output has to be exactly as follows:
## Unsuccessful ownership change
-a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
-a always,exit -F arch=b64 -S lchown,fchown,chown,fchownat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
-a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change
-a always,exit -F arch=b64 -S lchown,fchown,chown,fchownat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-owner-change    
      Is it the case that the file does not exist or the content differs?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_owner_change_success_question:question:1">
          <ocil:question_text>To verify that the Audit is correctly configured according to recommended rules, check the content of the file with the following command:
cat /etc/audit/rules.d/30-ospp-v42-6-owner-change-success.rules
The output has to be exactly as follows:
## Successful ownership change
-a always,exit -F arch=b32 -S lchown,fchown,chown,fchownat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-owner-change
-a always,exit -F arch=b64 -S lchown,fchown,chown,fchownat -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-owner-change    
      Is it the case that the file does not exist or the content differs?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_perm_change_failed_question:question:1">
          <ocil:question_text>To verify that the Audit is correctly configured according to recommended rules, check the content of the file with the following command:
cat /etc/audit/rules.d/30-ospp-v42-5-perm-change-failed.rules
The output has to be exactly as follows:
## Unsuccessful permission change
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccessful-perm-change    
      Is it the case that the file does not exist or the content differs?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_perm_change_success_question:question:1">
          <ocil:question_text>To verify that the Audit is correctly configured according to recommended rules, check the content of the file with the following command:
cat /etc/audit/rules.d/30-ospp-v42-5-perm-change-success.rules
The output has to be exactly as follows:
## Successful permission change
-a always,exit -F arch=b32 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change
-a always,exit -F arch=b64 -S chmod,fchmod,fchmodat,setxattr,lsetxattr,fsetxattr,removexattr,lremovexattr,fremovexattr -F success=1 -F auid&gt;=1000 -F auid!=unset -F key=successful-perm-change    
      Is it the case that the file does not exist or the content differs?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_privileged_commands_init_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "init" command with the following command:

$ sudo auditctl -l | grep init

-a always,exit -F path={{{ path }}}/init -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-init
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_privileged_commands_poweroff_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "poweroff" command with the following command:

$ sudo auditctl -l | grep poweroff

-a always,exit -F path={{{ path }}}/poweroff -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-poweroff
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_privileged_commands_reboot_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "reboot" command with the following command:

$ sudo auditctl -l | grep reboot

-a always,exit -F path={{{ path }}}/reboot -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-reboot
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_privileged_commands_shutdown_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "shutdown" command with the following command:

$ sudo auditctl -l | grep shutdown

-a always,exit -F path={{{ path }}}/shutdown -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-shutdown
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_continue_loading_question:question:1">
          <ocil:question_text>Verify that the '-c' option is set in the '/etc/audit/audit.rules' file with the following command:

$ sudo grep -Ph -- '^\h*-c\b' /etc/audit/rules.d/*.rules | tail -1

The output should be:

-c

      Is it the case that the option '-c' is not set in the '/etc/audit/audit.rules' file?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_dac_modification_chmod_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
chmod system call, run the following command:
$ sudo grep "chmod" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_dac_modification_chown_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
chown system call, run the following command:
$ sudo grep "chown" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_dac_modification_fchmod_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
fchmod system call, run the following command:
$ sudo grep "fchmod" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_dac_modification_fchmodat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
fchmodat system call, run the following command:
$ sudo grep "fchmodat" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_dac_modification_fchown_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
fchown system call, run the following command:
$ sudo grep "fchown" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_dac_modification_fchownat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
fchownat system call, run the following command:
$ sudo grep "fchownat" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_dac_modification_fremovexattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
fremovexattr system call, run the following command:
$ sudo grep "fremovexattr" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_dac_modification_fsetxattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
fsetxattr system call, run the following command:
$ sudo grep "fsetxattr" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_dac_modification_lchown_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
lchown system call, run the following command:
$ sudo grep "lchown" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_dac_modification_lremovexattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
lremovexattr system call, run the following command:
$ sudo grep "lremovexattr" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_dac_modification_lsetxattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
lsetxattr system call, run the following command:
$ sudo grep "lsetxattr" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_dac_modification_removexattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
removexattr system call, run the following command:
$ sudo grep "removexattr" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_dac_modification_setxattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
setxattr system call, run the following command:
$ sudo grep "setxattr" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_dac_modification_umount_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 generates an audit record for all uses of the "umount" and system call.
To determine if the system is configured to audit calls to the
"umount" system call, run the following command:
$ sudo grep "umount" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line like the following.
-a always,exit -F arch=b32 -S umount -F auid&gt;=1000 -F auid!=unset -k privileged-umount
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_dac_modification_umount2_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
umount2 system call, run the following command:
$ sudo grep "umount2" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_etc_cron_d_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/etc/cron.d/" with the following command:

$ sudo auditctl -l | grep /etc/cron.d/

-w /etc/cron.d/ -p wa -k cronjobs
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_etc_group_open_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
open system call, run the following command:
$ sudo grep "open" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_etc_group_open_by_handle_at_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
open_by_handle_at system call, run the following command:
$ sudo grep "open_by_handle_at" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_etc_group_openat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
openat system call, run the following command:
$ sudo grep "openat" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_etc_gshadow_open_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
open system call, run the following command:
$ sudo grep "open" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_etc_gshadow_open_by_handle_at_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
open_by_handle_at system call, run the following command:
$ sudo grep "open_by_handle_at" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_etc_gshadow_openat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
openat system call, run the following command:
$ sudo grep "openat" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_etc_passwd_open_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
open system call, run the following command:
$ sudo grep "open" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_etc_passwd_open_by_handle_at_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
open_by_handle_at system call, run the following command:
$ sudo grep "open_by_handle_at" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_etc_passwd_openat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
openat system call, run the following command:
$ sudo grep "openat" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_etc_shadow_open_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
open system call, run the following command:
$ sudo grep "open" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_etc_shadow_open_by_handle_at_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
open_by_handle_at system call, run the following command:
$ sudo grep "open_by_handle_at" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_etc_shadow_openat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
openat system call, run the following command:
$ sudo grep "openat" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_execution_chacl_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "chacl" command with the following command:

$ sudo auditctl -l | grep chacl

-a always,exit -F path=/usr/bin/chacl -F perm=x -F auid&gt;=1000 -F auid!=unset -k perm_mod
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_execution_chcon_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "chcon" command with the following command:

$ sudo auditctl -l | grep chcon

-a always,exit -F path=/usr/bin/chcon -F perm=x -F auid&gt;=1000 -F auid!=unset -k perm_mod
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_execution_restorecon_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "restorecon" command with the following command:

$ sudo auditctl -l | grep restorecon

-a always,exit -F path=/usr/sbin/restorecon -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-restorecon
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_execution_semanage_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "semanage" command with the following command:

$ sudo auditctl -l | grep semanage

-a always,exit -F path=/usr/sbin/semanage -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-unix-update
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_execution_setfacl_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "setfacl" command with the following command:

$ sudo auditctl -l | grep setfacl

-a always,exit -F path=/usr/bin/setfacl -F perm=x -F auid&gt;=1000 -F auid!=unset -k perm_mod
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_execution_setfiles_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "setfiles" command with the following command:

$ sudo auditctl -l | grep setfiles

-a always,exit -F path=/usr/sbin/setfiles -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-unix-update
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_execution_setsebool_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "setsebool" command with the following command:

$ sudo auditctl -l | grep setsebool

-a always,exit -F path=/usr/sbin/setsebool -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_execution_seunshare_question:question:1">
          <ocil:question_text>To verify that execution of the command is being audited, run the following command:
$ sudo grep "path=/usr/sbin/seunshare" /etc/audit/audit.rules /etc/audit/rules.d/*
The output should return something similar to:
-a always,exit -F path=/usr/sbin/seunshare -F auid&gt;=1000 -F auid!=unset -F key=privileged
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_file_deletion_events_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
rmdir system call, run the following command:
$ sudo grep "rmdir" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.
To determine if the system is configured to audit calls to the
unlink system call, run the following command:
$ sudo grep "unlink" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.
To determine if the system is configured to audit calls to the
unlinkat system call, run the following command:
$ sudo grep "unlinkat" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.
To determine if the system is configured to audit calls to the
rename system call, run the following command:
$ sudo grep "rename" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.
To determine if the system is configured to audit calls to the
renameat system call, run the following command:
$ sudo grep "renameat" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.
To determine if the system is configured to audit calls to the
renameat2 system call, run the following command:
$ sudo grep "renameat2" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_file_deletion_events_rename_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
rename system call, run the following command:
$ sudo grep "rename" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_file_deletion_events_renameat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
renameat system call, run the following command:
$ sudo grep "renameat" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_file_deletion_events_rmdir_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
rmdir system call, run the following command:
$ sudo grep "rmdir" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_file_deletion_events_unlink_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
unlink system call, run the following command:
$ sudo grep "unlink" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_file_deletion_events_unlinkat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
unlinkat system call, run the following command:
$ sudo grep "unlinkat" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_for_ospp_question:question:1">
          <ocil:question_text>To verify that audit is configured for OSPP v4.2.1, run the following commands:
for file in "10-base-config" "11-loginuid" "30-ospp-v42" "43-module-load";do diff /etc/audit/rules.d/$file.rules /usr/share/doc/audit*/rules/$file.rules; done

If the system is configured properly, no lines should be returned.
      Is it the case that the files are not there or differ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_immutable_question:question:1">
          <ocil:question_text>Verify the audit system prevents unauthorized changes with the following command:

$ sudo grep "^\s*[^#]" /etc/audit/audit.rules | tail -1
-e 2

      Is it the case that the audit system is not set to be immutable by adding the "-e 2" option to the end of "/etc/audit/audit.rules"?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_immutable_login_uids_question:question:1">
          <ocil:question_text>To determine if the system is configured to make login UIDs immutable, run
one of the following commands.
If the auditd daemon is configured to use the
augenrules program to read audit rules during daemon startup (the
default), run the following:
sudo grep immutable /etc/audit/rules.d/*.rules
If the auditd daemon is configured to use the auditctl
utility to read audit rules during daemon startup, run the following command:
sudo grep immutable /etc/audit/audit.rules
The following line should be returned:
--loginuid-immutable
      Is it the case that the system is not configured to make login UIDs immutable?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_kernel_module_loading_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
init_module system call, run the following command:
$ sudo grep "init_module" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.
To determine if the system is configured to audit calls to the
finit_module system call, run the following command:
$ sudo grep "finit_module" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.
To determine if the system is configured to audit calls to the
delete_module system call, run the following command:
$ sudo grep "delete_module" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_kernel_module_loading_create_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
create_module system call, run the following command:
$ sudo grep "create_module" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_kernel_module_loading_delete_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
delete_module system call, run the following command:
$ sudo grep "delete_module" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_kernel_module_loading_finit_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
finit_module system call, run the following command:
$ sudo grep "finit_module" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_kernel_module_loading_init_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
init_module system call, run the following command:
$ sudo grep "init_module" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_kernel_module_loading_query_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
query_module system call, run the following command:
$ sudo grep "query_module" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_login_events_faillock_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "" with the following command:

$ sudo auditctl -l | grep 

-w  -p wa -k logins
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_login_events_lastlog_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/var/log/lastlog" with the following command:

$ sudo auditctl -l | grep /var/log/lastlog

-w /var/log/lastlog -p wa -k logins
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_login_events_tallylog_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/var/log/tallylog" with the following command:

$ sudo auditctl -l | grep /var/log/tallylog

-w /var/log/tallylog -p wa -k logins
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_mac_modification_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit changes to its SELinux
configuration files, run the following command:
$ sudo auditctl -l | grep "dir=/etc/selinux"
If the system is configured to watch for changes to its SELinux
configuration, a line should be returned (including
perm=wa indicating permissions that are watched).
      Is it the case that the system is not configured to audit attempts to change the MAC policy?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_mac_modification_usr_share_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit changes to its SELinux
configuration files, run the following command:
$ sudo auditctl -l | grep "dir=/usr/share/selinux"
If the system is configured to watch for changes to its SELinux
configuration, a line should be returned (including
perm=wa indicating permissions that are watched).
      Is it the case that the system is not configured to audit attempts to change the MAC policy?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_media_export_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
mount system call, run the following command:
$ sudo grep "mount" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_networkconfig_modification_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit changes to its network configuration,
run the following command:
auditctl -l | grep -E '(/etc/issue|/etc/issue.net|/etc/hosts|/etc/sysconfig/network)'

If the system is configured to watch for network configuration changes, a line should be returned for
each file specified (and perm=wa should be indicated for each).
      Is it the case that the system is not configured to audit changes of the network configuration?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_networkconfig_modification_network_scripts_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit changes to its network configuration,
run the following command:
auditctl -l | grep -E '/etc/sysconfig/network-scripts'
If the system is configured to watch for network configuration changes, a line should
be returned and perm=wa should be indicated.
      Is it the case that the system is not configured to audit changes of the network configuration?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_question:question:1">
          <ocil:question_text>To verify that auditing of privileged command use is configured, run the following command
to search privileged commands in relevant partitions and check if they are covered by auditd
rules:

FILTER_NODEV=$(awk '/nodev/ { print $2 }' /proc/filesystems | paste -sd,)
PARTITIONS=$(findmnt -n -l -k -it $FILTER_NODEV | grep -Pv "noexec|nosuid" | awk '{ print $1 }')
for PARTITION in $PARTITIONS; do
  for PRIV_CMD in $(find "${PARTITION}" -xdev -perm /6000 -type f 2&gt;/dev/null); do
    grep -qr "${PRIV_CMD}" /etc/audit/rules.d /etc/audit/audit.rules &amp;&amp;
      printf "OK: ${PRIV_CMD}\n" || printf "WARNING - rule not found for: ${PRIV_CMD}\n"
  done
done

The output should not contain any WARNING.
      Is it the case that any setuid or setgid programs doesn't have a line in the audit rules?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_at_question:question:1">
          <ocil:question_text>To verify that auditing of privileged command use is configured, run the
following command:
$ sudo grep '\bat\b' /etc/audit/audit.rules /etc/audit/rules.d/*
It should return a relevant line in the audit rules.
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_chage_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "chage" command with the following command:

$ sudo auditctl -l | grep chage

-a always,exit -F path=/usr/bin/chage -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-chage
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_chsh_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "chsh" command with the following command:

$ sudo auditctl -l | grep chsh

-a always,exit -F path=/usr/bin/chsh -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-chsh
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_crontab_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "crontab" command with the following command:

$ sudo auditctl -l | grep crontab

-a always,exit -F path=/usr/bin/crontab -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-crontab
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_gpasswd_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "gpasswd" command with the following command:

$ sudo auditctl -l | grep gpasswd

-a always,exit -F path=/usr/bin/gpasswd -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-gpasswd
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_kmod_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "kmod" command with the following command:

$ sudo auditctl -l | grep kmod

-a always,exit -F path=/usr/bin/kmod -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-kmod
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_mount_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "mount" command with the following command:

$ sudo auditctl -l | grep mount

-a always,exit -F path=/usr/bin/mount -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-mount
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_newgidmap_question:question:1">
          <ocil:question_text>To verify that auditing of privileged command use is configured, run the
following command:
$ sudo grep newgidmap /etc/audit/audit.rules /etc/audit/rules.d/*
It should return a relevant line in the audit rules.
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_newgrp_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "newgrp" command with the following command:

$ sudo auditctl -l | grep newgrp

-a always,exit -F path=/usr/bin/newgrp -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-newgrp
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_newuidmap_question:question:1">
          <ocil:question_text>To verify that auditing of privileged command use is configured, run the
following command:
$ sudo grep newuidmap /etc/audit/audit.rules /etc/audit/rules.d/*
It should return a relevant line in the audit rules.
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_pam_timestamp_check_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "pam_timestamp_check" command with the following command:

$ sudo auditctl -l | grep pam_timestamp_check

-a always,exit -F path=/usr/sbin/pam_timestamp_check -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-pam_timestamp_check
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_passwd_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "passwd" command with the following command:

$ sudo auditctl -l | grep passwd

-a always,exit -F path=/usr/bin/passwd -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-passwd
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_postdrop_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "postdrop" command with the following command:

$ sudo auditctl -l | grep postdrop

-a always,exit -F path=/usr/bin/postdrop -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-postdrop
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_postqueue_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "postqueue" command with the following command:

$ sudo auditctl -l | grep postqueue

-a always,exit -F path=/usr/bin/postqueue -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-postqueue
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_pt_chown_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "pt_chown" command with the following command:

$ sudo auditctl -l | grep pt_chown

-a always,exit -F path=/usr/libexec/pt_chown -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-pt_chown
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_ssh_agent_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "ssh-agent" command with the following command:

$ sudo auditctl -l | grep ssh-agent

-a always,exit -F path=/usr/bin/ssh-agent -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-ssh-agent
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_ssh_keysign_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "ssh-keysign" command with the following command:

$ sudo auditctl -l | grep ssh-keysign

-a always,exit -F path=/usr/libexec/openssh/ssh-keysignssh-keysign -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-ssh-keysign
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_su_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "su" command with the following command:

$ sudo auditctl -l | grep su

-a always,exit -F path=/usr/bin/su -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-su
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_sudo_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "sudo" command with the following command:

$ sudo auditctl -l | grep sudo

-a always,exit -F path=/usr/bin/sudo -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-sudo
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_sudoedit_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "sudoedit" command with the following command:

$ sudo auditctl -l | grep sudoedit

-a always,exit -F path=/usr/bin/sudoedit -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-sudoedit
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_umount_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "umount" command with the following command:

$ sudo auditctl -l | grep umount

-a always,exit -F path=/usr/bin/umount -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-umount
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_unix_chkpwd_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "unix_chkpwd" command with the following command:

$ sudo auditctl -l | grep unix_chkpwd

-a always,exit -F path=/usr/bin/unix_chkpwd -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-unix_chkpwd
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_unix_update_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "unix_update" command with the following command:

$ sudo auditctl -l | grep unix_update

-a always,exit -F path=/usr/bin/unix_update -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-unix_update
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_userhelper_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "userhelper" command with the following command:

$ sudo auditctl -l | grep userhelper

-a always,exit -F path=/usr/bin/userhelper -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-userhelper
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_usermod_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to audit the execution of the "usermod" command with the following command:

$ sudo auditctl -l | grep usermod

-a always,exit -F path=/usr/bin/usermod -F perm=x -F auid&gt;=1000 -F auid!=unset -k privileged-usermod
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_privileged_commands_usernetctl_question:question:1">
          <ocil:question_text>To verify that auditing of privileged command use is configured, run the
following command:
$ sudo grep usernetctl /etc/audit/audit.rules /etc/audit/rules.d/*
It should return a relevant line in the audit rules.
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_session_events_btmp_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/var/log/btmp" with the following command:

$ sudo auditctl -l | grep /var/log/btmp

-w /var/log/btmp -p wa -k session
      Is it the case that Audit rule is not present?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_session_events_utmp_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/var/run/utmp" with the following command:

$ sudo auditctl -l | grep /var/run/utmp

-w /var/run/utmp -p wa -k session
      Is it the case that Audit rule is not present?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_session_events_wtmp_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/var/log/wtmp" with the following command:

$ sudo auditctl -l | grep /var/log/wtmp

-w /var/log/wtmp -p wa -k session
      Is it the case that Audit rule is not present?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_chmod_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the chmod system call, run the following command:
$ sudo grep "chmod" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_chown_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the chown system call, run the following command:
$ sudo grep "chown" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_creat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the creat system call, run the following command:
$ sudo grep "creat" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_fchmod_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the fchmod system call, run the following command:
$ sudo grep "fchmod" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_fchmodat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the fchmodat system call, run the following command:
$ sudo grep "fchmodat" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_fchown_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the fchown system call, run the following command:
$ sudo grep "fchown" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_fchownat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the fchownat system call, run the following command:
$ sudo grep "fchownat" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_fremovexattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the fremovexattr system call, run the following command:
$ sudo grep "fremovexattr" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_fsetxattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the fsetxattr system call, run the following command:
$ sudo grep "fsetxattr" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_ftruncate_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the ftruncate system call, run the following command:
$ sudo grep "ftruncate" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_lchown_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the lchown system call, run the following command:
$ sudo grep "lchown" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_lremovexattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the lremovexattr system call, run the following command:
$ sudo grep "lremovexattr" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_lsetxattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the lsetxattr system call, run the following command:
$ sudo grep "lsetxattr" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_open_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the open system call, run the following command:
$ sudo grep "open" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the open_by_handle_at system call, run the following command:
$ sudo grep "open_by_handle_at" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_o_creat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the open_by_handle_at system call, run the following command:
$ sudo grep "open_by_handle_at" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_open_by_handle_at_o_trunc_write_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the open_by_handle_at system call, run the following command:
$ sudo grep "open_by_handle_at" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_open_o_creat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the open system call, run the following command:
$ sudo grep "open" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_open_o_trunc_write_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the open system call, run the following command:
$ sudo grep "open" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_openat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the openat system call, run the following command:
$ sudo grep "openat" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_openat_o_creat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the openat system call, run the following command:
$ sudo grep "openat" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_openat_o_trunc_write_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the openat system call, run the following command:
$ sudo grep "openat" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_removexattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the removexattr system call, run the following command:
$ sudo grep "removexattr" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_rename_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the rename system call, run the following command:
$ sudo grep "rename" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_renameat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the renameat system call, run the following command:
$ sudo grep "renameat" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_setxattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the setxattr system call, run the following command:
$ sudo grep "setxattr" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_truncate_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the truncate system call, run the following command:
$ sudo grep "truncate" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_unlink_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the unlink system call, run the following command:
$ sudo grep "unlink" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_successful_file_modification_unlinkat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit successful calls
to the unlinkat system call, run the following command:
$ sudo grep "unlinkat" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_sudoers_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/etc/sudoers" with the following command:

$ sudo auditctl -l | grep /etc/sudoers

-w /etc/sudoers -p wa -k actions
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_sudoers_d_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/etc/sudoers.d/" with the following command:

$ sudo auditctl -l | grep /etc/sudoers.d/

-w /etc/sudoers.d/ -p wa -k actions
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_suid_auid_privilege_function_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 audits execution as another user.

Check if AlmaLinux OS 8 is configured to audit the execution of the "execve" system call using the following command:

$ sudo grep execve /etc/audit/audit.rules

The output should be the following:

-a always,exit -F arch=b32 -S execve -C euid!=uid -F auid!=unset -k user_emulation
-a always,exit -F arch=b64 -S execve  -C euid!=uid -F auid!=unset-k user_emulation
      Is it the case that the command does not return all lines, or the lines are commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_suid_privilege_function_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 audits the execution of privileged functions.

Check if AlmaLinux OS 8 is configured to audit the execution of the "execve" system call using the following command:

$ sudo grep execve /etc/audit/audit.rules

The output should be the following:


-a always,exit -F arch=b32 -S execve -C uid!=euid -F euid=0 -k setuid
-a always,exit -F arch=b64 -S execve -C uid!=euid -F euid=0 -k setuid
-a always,exit -F arch=b32 -S execve -C gid!=egid -F egid=0 -k setgid
-a always,exit -F arch=b64 -S execve -C gid!=egid -F egid=0 -k setgid
      Is it the case that the command does not return all lines, or the lines are commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_sysadmin_actions_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/etc/sudoers" with the following command:

$ sudo auditctl -l | grep /etc/sudoers

-w /etc/sudoers -p wa -k actions



Verify AlmaLinux OS 8 generates audit records for all events that affect "/etc/sudoers.d/" with the following command:

$ sudo auditctl -l | grep /etc/sudoers.d/

-w /etc/sudoers.d/ -p wa -k actions
      Is it the case that there is not output?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_system_shutdown_question:question:1">
          <ocil:question_text>To verify that the system will shutdown when auditd fails,
run the following command:
$ sudo grep "\-f " /etc/audit/audit.rules
The output should contain:
-f 
      Is it the case that the system is not configured to shutdown on auditd failures?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_time_adjtimex_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
adjtimex system call, run the following command:
$ sudo grep "adjtimex" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_time_clock_settime_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
clock_settime system call, run the following command:
$ sudo grep "clock_settime" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_time_settimeofday_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit calls to the
settimeofday system call, run the following command:
$ sudo grep "settimeofday" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_time_stime_question:question:1">
          <ocil:question_text>If the system is not configured to audit time changes, this is a finding.
If the system is 64-bit only, this is not applicable
ocil: |
To determine if the system is configured to audit calls to the
stime system call, run the following command:
$ sudo grep "stime" /etc/audit/audit.*
If the system is configured to audit this activity, it will return a line.
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_time_watch_localtime_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/etc/localtime" with the following command:

$ sudo auditctl -l | grep /etc/localtime

-w /etc/localtime -p wa -k audit_time_rules
      Is it the case that the system is not configured to audit time changes?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_question:question:1">
          <ocil:question_text>To verify that the audit system collects unauthorized file accesses, run the following commands:
$ sudo grep EACCES /etc/audit/audit.rules
$ sudo grep EPERM /etc/audit/audit.rules
      Is it the case that 32-bit and 64-bit system calls to creat, open, openat, open_by_handle_at, truncate, and ftruncate are not audited during EACCES and EPERM?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_chmod_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit unsuccessful calls
to the chmod system call, run the following command:
$ sudo grep "chmod" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_chown_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit unsuccessful calls
to the chown system call, run the following command:
$ sudo grep "chown" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_creat_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 generates an audit record for unsuccessful attempts to use the creat system call.

If the auditd daemon is configured to use the "augenrules" program to to read audit rules during daemon startup (the default), run the following command:

$ sudo grep -r creat /etc/audit/rules.d

If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, run the following command:

$ sudo grep creat /etc/audit/audit.rules

The output should be the following:

-a always,exit -F arch=b32 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b64 -S creat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b32 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b64 -S creat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k access
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_fchmod_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit unsuccessful calls
to the fchmod system call, run the following command:
$ sudo grep "fchmod" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_fchmodat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit unsuccessful calls
to the fchmodat system call, run the following command:
$ sudo grep "fchmodat" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_fchown_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit unsuccessful calls
to the fchown system call, run the following command:
$ sudo grep "fchown" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_fchownat_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit unsuccessful calls
to the fchownat system call, run the following command:
$ sudo grep "fchownat" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_fremovexattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit unsuccessful calls
to the fremovexattr system call, run the following command:
$ sudo grep "fremovexattr" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_fsetxattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit unsuccessful calls
to the fsetxattr system call, run the following command:
$ sudo grep "fsetxattr" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_ftruncate_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 generates an audit record for unsuccessful attempts to use the ftruncate system call.

If the auditd daemon is configured to use the "augenrules" program to to read audit rules during daemon startup (the default), run the following command:

$ sudo grep -r ftruncate /etc/audit/rules.d

If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, run the following command:

$ sudo grep ftruncate /etc/audit/audit.rules

The output should be the following:

-a always,exit -F arch=b32 -S ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b64 -S ftruncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b32 -S ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b64 -S ftruncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k access
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_lchown_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit unsuccessful calls
to the lchown system call, run the following command:
$ sudo grep "lchown" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_lremovexattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit unsuccessful calls
to the lremovexattr system call, run the following command:
$ sudo grep "lremovexattr" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_lsetxattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit unsuccessful calls
to the lsetxattr system call, run the following command:
$ sudo grep "lsetxattr" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 generates an audit record for unsuccessful attempts to use the open system call.

If the auditd daemon is configured to use the "augenrules" program to to read audit rules during daemon startup (the default), run the following command:

$ sudo grep -r open /etc/audit/rules.d

If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, run the following command:

$ sudo grep open /etc/audit/audit.rules

The output should be the following:

-a always,exit -F arch=b32 -S open -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b64 -S open -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b32 -S open -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b64 -S open -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k access
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 generates an audit record for unsuccessful attempts to use the open_by_handle_at system call.

If the auditd daemon is configured to use the "augenrules" program to to read audit rules during daemon startup (the default), run the following command:

$ sudo grep -r open_by_handle_at /etc/audit/rules.d

If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, run the following command:

$ sudo grep open_by_handle_at /etc/audit/audit.rules

The output should be the following:

-a always,exit -F arch=b32 -S open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b64 -S open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b32 -S open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b64 -S open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k access
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 generates an audit record for unsuccessful attempts to create files using the open_by_handle_at system call with O_CREAT flag.

If the auditd daemon is configured to use the "augenrules" program to read audit rules during daemon startup (the default), run the following command:

$ sudo grep -r open_by_handle_at /etc/audit/rules.d

If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, run the following command:

$ sudo grep open_by_handle_at /etc/audit/audit.rules

The output should be the following:

-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_o_trunc_write_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 generates an audit record for unsuccessful attempts to modify files using the open_by_handle_at system call with O_TRUNC_WRITE flag.

If the auditd daemon is configured to use the "augenrules" program to read audit rules during daemon startup (the default), run the following command:

$ sudo grep -r open_by_handle_at /etc/audit/rules.d

If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, run the following command:

$ sudo grep open_by_handle_at /etc/audit/audit.rules

The output should be the following:

-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order_question:question:1">
          <ocil:question_text>Verify that rules for unsuccessful calls of the open_by_handle_at syscall are in the order shown below.

    If the auditd daemon is configured to use the "augenrules" program to read audit rules during daemon startup (the default), check the order of rules below in a file with suffix ".rules" in the directory "/etc/audit/rules.d".
    If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, check the order of rules below in "/etc/audit/audit.rules" file.

    -a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
    -a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
    -a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
    -a always,exit -F arch=b32 -S open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
    -a always,exit -F arch=b32 -S open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
    -a always,exit -F arch=b32 -S open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access

    If the system is 64 bit then also add the following lines:

    -a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
    -a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
    -a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
    -a always,exit -F arch=b64 -S open_by_handle_at -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
    -a always,exit -F arch=b64 -S open_by_handle_at -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
    -a always,exit -F arch=b64 -S open_by_handle_at -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      Is it the case that the rules are in a different order?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_creat_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 generates an audit record for unsuccessful attempts to create files using the open system call with O_CREAT flag.

If the auditd daemon is configured to use the "augenrules" program to read audit rules during daemon startup (the default), run the following command:

$ sudo grep -r open /etc/audit/rules.d

If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, run the following command:

$ sudo grep open /etc/audit/audit.rules

The output should be the following:

-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_o_trunc_write_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 generates an audit record for unsuccessful attempts to modify files using the open system call with O_TRUNC_WRITE flag.

If the auditd daemon is configured to use the "augenrules" program to read audit rules during daemon startup (the default), run the following command:

$ sudo grep -r open /etc/audit/rules.d

If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, run the following command:

$ sudo grep open /etc/audit/audit.rules

The output should be the following:

-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_open_rule_order_question:question:1">
          <ocil:question_text>Verify that rules for unsuccessful calls of the open syscall are in the order shown below.

    If the auditd daemon is configured to use the "augenrules" program to read audit rules during daemon startup (the default), check the order of rules below in a file with suffix ".rules" in the directory "/etc/audit/rules.d".
    If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, check the order of rules below in "/etc/audit/audit.rules" file.

    -a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
    -a always,exit -F arch=b32 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
    -a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
    -a always,exit -F arch=b32 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
    -a always,exit -F arch=b32 -S open -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
    -a always,exit -F arch=b32 -S open -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access

    If the system is 64 bit then also add the following lines:

    -a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
    -a always,exit -F arch=b64 -S open -F a1&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
    -a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
    -a always,exit -F arch=b64 -S open -F a1&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
    -a always,exit -F arch=b64 -S open -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
    -a always,exit -F arch=b64 -S open -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      Is it the case that the rules are in a different order?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 generates an audit record for unsuccessful attempts to use the openat system call.

If the auditd daemon is configured to use the "augenrules" program to to read audit rules during daemon startup (the default), run the following command:

$ sudo grep -r openat /etc/audit/rules.d

If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, run the following command:

$ sudo grep openat /etc/audit/audit.rules

The output should be the following:

-a always,exit -F arch=b32 -S openat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b64 -S openat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b32 -S openat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b64 -S openat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k access
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_creat_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 generates an audit record for unsuccessful attempts to create files using the openat system call with O_CREAT flag.

If the auditd daemon is configured to use the "augenrules" program to read audit rules during daemon startup (the default), run the following command:

$ sudo grep -r openat /etc/audit/rules.d

If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, run the following command:

$ sudo grep openat /etc/audit/audit.rules

The output should be the following:

-a always,exit -F arch=b32 -S openat -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S openat -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_o_trunc_write_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 generates an audit record for unsuccessful attempts to modify files using the openat system call with O_TRUNC_WRITE flag.

If the auditd daemon is configured to use the "augenrules" program to read audit rules during daemon startup (the default), run the following command:

$ sudo grep -r openat /etc/audit/rules.d

If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, run the following command:

$ sudo grep openat /etc/audit/audit.rules

The output should be the following:

-a always,exit -F arch=b32 -S openat -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b32 -S openat -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
-a always,exit -F arch=b64 -S openat -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_openat_rule_order_question:question:1">
          <ocil:question_text>Verify that rules for unsuccessful calls of the openat syscall are in the order shown below.

    If the auditd daemon is configured to use the "augenrules" program to read audit rules during daemon startup (the default), check the order of rules below in a file with suffix ".rules" in the directory "/etc/audit/rules.d".
    If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, check the order of rules below in "/etc/audit/audit.rules" file.

    -a always,exit -F arch=b32 -S openat -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
    -a always,exit -F arch=b32 -S openat -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
    -a always,exit -F arch=b32 -S openat -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
    -a always,exit -F arch=b32 -S openat -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
    -a always,exit -F arch=b32 -S openat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
    -a always,exit -F arch=b32 -S openat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access

    If the system is 64 bit then also add the following lines:

    -a always,exit -F arch=b64 -S openat -F a2&amp;0100 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
    -a always,exit -F arch=b64 -S openat -F a2&amp;0100 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-create
    -a always,exit -F arch=b64 -S openat -F a2&amp;01003 -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
    -a always,exit -F arch=b64 -S openat -F a2&amp;01003 -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-modification
    -a always,exit -F arch=b64 -S openat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
    -a always,exit -F arch=b64 -S openat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -F key=unsuccesful-access
      Is it the case that the rules are in a different order?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_removexattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit unsuccessful calls
to the removexattr system call, run the following command:
$ sudo grep "removexattr" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_rename_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 generates an audit record for unsuccessful attempts to use the rename system call.

If the auditd daemon is configured to use the "augenrules" program to to read audit rules during daemon startup (the default), run the following command:

$ sudo grep -r rename /etc/audit/rules.d

If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, run the following command:

$ sudo grep rename /etc/audit/audit.rules

The output should be the following:

-a always,exit -F arch=b32 -S rename -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k unsuccessful-delete
-a always,exit -F arch=b64 -S rename -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k unsuccessful-delete
-a always,exit -F arch=b32 -S rename -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k unsuccessful-delete
-a always,exit -F arch=b64 -S rename -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k unsuccessful-delete
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_renameat_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 generates an audit record for unsuccessful attempts to use the renameat system call.

If the auditd daemon is configured to use the "augenrules" program to to read audit rules during daemon startup (the default), run the following command:

$ sudo grep -r renameat /etc/audit/rules.d

If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, run the following command:

$ sudo grep renameat /etc/audit/audit.rules

The output should be the following:

-a always,exit -F arch=b32 -S renameat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k unsuccessful-delete
-a always,exit -F arch=b64 -S renameat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k unsuccessful-delete
-a always,exit -F arch=b32 -S renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k unsuccessful-delete
-a always,exit -F arch=b64 -S renameat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k unsuccessful-delete
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_setxattr_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit unsuccessful calls
to the setxattr system call, run the following command:
$ sudo grep "setxattr" /etc/audit.*
If the system is configured to audit this activity, it will return a line.

      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_truncate_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 generates an audit record for unsuccessful attempts to use the truncate system call.

If the auditd daemon is configured to use the "augenrules" program to to read audit rules during daemon startup (the default), run the following command:

$ sudo grep -r truncate /etc/audit/rules.d

If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, run the following command:

$ sudo grep truncate /etc/audit/audit.rules

The output should be the following:

-a always,exit -F arch=b32 -S truncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b64 -S truncate -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b32 -S truncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k access
-a always,exit -F arch=b64 -S truncate -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k access
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_unlink_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 generates an audit record for unsuccessful attempts to use the unlink system call.

If the auditd daemon is configured to use the "augenrules" program to to read audit rules during daemon startup (the default), run the following command:

$ sudo grep -r unlink /etc/audit/rules.d

If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, run the following command:

$ sudo grep unlink /etc/audit/audit.rules

The output should be the following:

-a always,exit -F arch=b32 -S unlink -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k unsuccessful-delete
-a always,exit -F arch=b64 -S unlink -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k unsuccessful-delete
-a always,exit -F arch=b32 -S unlink -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k unsuccessful-delete
-a always,exit -F arch=b64 -S unlink -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k unsuccessful-delete
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_unsuccessful_file_modification_unlinkat_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 generates an audit record for unsuccessful attempts to use the unlinkat system call.

If the auditd daemon is configured to use the "augenrules" program to to read audit rules during daemon startup (the default), run the following command:

$ sudo grep -r unlinkat /etc/audit/rules.d

If the auditd daemon is configured to use the "auditctl" utility to read audit rules during daemon startup, run the following command:

$ sudo grep unlinkat /etc/audit/audit.rules

The output should be the following:

-a always,exit -F arch=b32 -S unlinkat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k unsuccessful-delete
-a always,exit -F arch=b64 -S unlinkat -F exit=-EPERM -F auid&gt;=1000 -F auid!=unset -k unsuccessful-delete
-a always,exit -F arch=b32 -S unlinkat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k unsuccessful-delete
-a always,exit -F arch=b64 -S unlinkat -F exit=-EACCES -F auid&gt;=1000 -F auid!=unset -k unsuccessful-delete
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_usergroup_modification_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit account changes,
run the following command:
auditctl -l | grep -E '(/etc/passwd|/etc/shadow|/etc/group|/etc/gshadow|/etc/security/opasswd)'
If the system is configured to watch for account changes, lines should be returned for
each file specified (and with perm=wa for each).
      Is it the case that the system is not configured to audit account changes?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_usergroup_modification_group_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/etc/group" with the following command:

$ sudo auditctl -l | grep /etc/group

-w /etc/group -p wa -k audit_rules_usergroup_modification
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_usergroup_modification_gshadow_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/etc/gshadow" with the following command:

$ sudo auditctl -l | grep /etc/gshadow

-w /etc/gshadow -p wa -k audit_rules_usergroup_modification
      Is it the case that the system is not configured to audit account changes?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_usergroup_modification_nsswitch_conf_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/etc/group" with the following command:

$ sudo auditctl -l | grep /etc/group

-w /etc/group -p wa -k audit_rules_usergroup_modification
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_usergroup_modification_opasswd_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/etc/security/opasswd" with the following command:

$ sudo auditctl -l | grep /etc/security/opasswd

-w /etc/security/opasswd -p wa -k audit_rules_usergroup_modification
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_usergroup_modification_pam_conf_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/etc/pam.conf" with the following command:

$ sudo auditctl -l | grep /etc/pam.conf

-w /etc/pam.conf -p wa -k audit_rules_usergroup_modification
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_usergroup_modification_pamd_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/etc/pam.conf" with the following command:

$ sudo auditctl -l | grep /etc/pam.conf

-w /etc/pam.conf -p wa -k audit_rules_usergroup_modification
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_usergroup_modification_passwd_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/etc/passwd" with the following command:

$ sudo auditctl -l | grep /etc/passwd

-w /etc/passwd -p wa -k audit_rules_usergroup_modification
      Is it the case that the command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_usergroup_modification_shadow_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/etc/shadow" with the following command:

$ sudo auditctl -l | grep /etc/shadow

-w /etc/shadow -p wa -k audit_rules_usergroup_modification
      Is it the case that command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_rules_var_spool_cron_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/var/spool/cron" with the following command:

$ sudo auditctl -l | grep /var/spool/cron

-w /var/spool/cron -p wa -k cronjobs
      Is it the case that command does not return a line, or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-audit_sudo_log_events_question:question:1">
          <ocil:question_text>
Verify AlmaLinux OS 8 generates audit records for all events that affect "/var/log/sudo.log" with the following command:

$ sudo auditctl -l | grep /var/log/sudo.log

-w /var/log/sudo.log -p wa -k maintenance
      Is it the case that Audit rule is not present?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_audispd_configure_remote_server_question:question:1">
          <ocil:question_text>To verify the audispd plugin off-loads audit records onto a different system or
media from the system being audited, run the following command:
$ sudo grep -i remote_server /etc/audit/audisp-remote.conf
The output should return something similar to
remote_server = 
      Is it the case that audispd is not sending logs to a remote system?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_audispd_configure_sufficiently_large_partition_question:question:1">
          <ocil:question_text>To verify whether audispd plugin off-loads audit records onto a different
system or media from the system being audited, run the following command:

$ sudo grep -i remote_server /etc/audit/audisp-remote.conf

The output should return something similar to where REMOTE_SYSTEM
is an IP address or hostname:
remote_server = REMOTE_SYSTEM

Determine which partition the audit records are being written to with the
following command:

$ sudo grep log_file /etc/audit/auditd.conf
log_file = /var/log/audit/audit.log

Check the size of the partition that audit records are written to with the
following command and verify whether it is sufficiently large:

$ sudo df -h /var/log/audit/
/dev/sda2 24G 10.4G 13.6G 43% /var/log/audit
      Is it the case that audispd is not sending logs to a remote system and the local partition has inadequate space?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_audispd_disk_full_action_question:question:1">
          <ocil:question_text>Inspect /etc/audit/audisp-remote.conf and locate the following line to
determine if the system is configured to either send to syslog, switch to single user mode,
or halt when the disk is full:
$ sudo grep -i disk_full_action /etc/audit/audisp-remote.conf
The output should return something similar to:
disk_full_action = single
Acceptable values also include syslog and halt.
      Is it the case that the system is not configured to switch to single user mode for corrective action?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_audispd_encrypt_sent_records_question:question:1">
          <ocil:question_text>To verify the audispd plugin encrypts audit records off-loaded onto a different
system or media from the system being audited, run the following command:

$ sudo grep -i transport /etc/audit/audisp-remote.conf
The output should return the following:
transport = KRB5
      Is it the case that audispd is not encrypting audit records when sent over the network?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_audispd_network_failure_action_question:question:1">
          <ocil:question_text>Inspect /etc/audit/audisp-remote.conf and locate the following line to
determine if the system is configured to perform a correct action according to the policy:
$ sudo grep -i network_failure_action /etc/audit/audisp-remote.conf
The output should return:
network_failure_action = 
      Is it the case that the system is not configured to switch to single user mode for corrective action?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_audispd_syslog_plugin_activated_question:question:1">
          <ocil:question_text>To verify the audispd's syslog plugin is active, run the following command:
$ sudo grep active /etc/audit/plugins.d/syslog.conf
If the plugin is active, the output will show yes.
      Is it the case that it is not activated?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_data_disk_error_action_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 takes the appropriate action when an audit processing failure occurs.

Check that AlmaLinux OS 8 takes the appropriate action when an audit processing failure occurs with the following command:

$ sudo grep disk_error_action /etc/audit/auditd.conf

disk_error_action = 

If the value of the "disk_error_action" option is not "SYSLOG", "SINGLE", or "HALT", or the line is commented out, ask the system administrator to indicate how the system takes appropriate action when an audit process failure occurs.
      Is it the case that there is no evidence of appropriate action?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_data_disk_error_action_stig_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 takes the appropriate action when an audit processing failure occurs.

Check that AlmaLinux OS 8 takes the appropriate action when an audit processing failure occurs with the following command:

$ sudo grep disk_error_action /etc/audit/auditd.conf

disk_error_action = HALT

If the value of the "disk_error_action" option is not "SYSLOG", "SINGLE", or "HALT", or the line is commented out, ask the system administrator to indicate how the system takes appropriate action when an audit process failure occurs.
      Is it the case that there is no evidence of appropriate action?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_data_disk_full_action_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 takes the appropriate action when the audit storage volume is full.

Check that AlmaLinux OS 8 takes the appropriate action when the audit storage volume is full with the following command:

$ sudo grep disk_full_action /etc/audit/auditd.conf

disk_full_action = 

If the value of the "disk_full_action" option is not "SYSLOG", "SINGLE", or "HALT", or the line is commented out, ask the system administrator to indicate how the system takes appropriate action when an audit storage volume is full.
      Is it the case that there is no evidence of appropriate action?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_data_disk_full_action_stig_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 takes the appropriate action when the audit storage volume is full.

Check that AlmaLinux OS 8 takes the appropriate action when the audit storage volume is full with the following command:

$ sudo grep disk_full_action /etc/audit/auditd.conf

disk_full_action = 

If the value of the "disk_full_action" option is not "SYSLOG", "SINGLE", or "HALT", or the line is commented out, ask the system administrator to indicate how the system takes appropriate action when an audit storage volume is full.
      Is it the case that there is no evidence of appropriate action?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_data_retention_action_mail_acct_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to notify the SA and/or ISSO (at a minimum) in the event of an audit processing failure with the following command:

$ sudo grep action_mail_acct /etc/audit/auditd.conf

action_mail_acct = 
      Is it the case that the value of the "action_mail_acct" keyword is not set to "&lt;sub idref="var_auditd_action_mail_acct" /&gt;" and/or other accounts for security personnel, the "action_mail_acct" keyword is missing, or the returned line is commented out, ask the system administrator to indicate how they and the ISSO are notified of an audit process failure. If there is no evidence of the proper personnel being notified of an audit processing failure?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_data_retention_admin_space_left_action_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to take action in the event of allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity with the following command:

$ sudo grep admin_space_left_action /etc/audit/auditd.conf

admin_space_left_action = single

If the value of the "admin_space_left_action" is not set to "single", or if the line is commented out, ask the System Administrator to indicate how the system is providing real-time alerts to the SA and ISSO.
      Is it the case that there is no evidence that real-time alerts are configured on the system?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_data_retention_admin_space_left_percentage_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 takes action when allocated audit record storage volume reaches 95 percent of the repository maximum audit record storage capacity with the following command:

$ sudo grep -w admin_space_left /etc/audit/auditd.conf

admin_space_left = %

If the value of the "admin_space_left" keyword is not set to % of the storage volume allocated to audit logs, or if the line is commented out, ask the System Administrator to indicate how the system is taking action if the allocated storage is about to reach capacity.
      Is it the case that the "admin_space_left" value is not configured to the correct value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_data_retention_flush_question:question:1">
          <ocil:question_text>Inspect /etc/audit/auditd.conf and locate the following line to
determine if the system is configured to synchronize audit event data
with the log files on the disk:
$ sudo grep flush /etc/audit/auditd.conf
flush = DATA
Acceptable values are DATA, and SYNC. The setting is
case-insensitive.
      Is it the case that auditd is not configured to synchronously write audit event data to disk?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_data_retention_max_log_file_question:question:1">
          <ocil:question_text>Inspect /etc/audit/auditd.conf and locate the following line to
determine how much data the system will retain in each audit log file:
$ sudo grep max_log_file /etc/audit/auditd.conf
max_log_file = 6
      Is it the case that the system audit data threshold has not been properly configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_data_retention_max_log_file_action_question:question:1">
          <ocil:question_text>Verify that the SA and ISSO (at a minimum) are notified when the audit storage volume is full.

Check which action AlmaLinux OS 8 takes when the audit storage volume is full with the following command:

$ sudo grep max_log_file_action /etc/audit/auditd.conf
max_log_file_action = 
      Is it the case that the value of the "max_log_file_action" option is set to "ignore", "rotate", or "suspend", or the line is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_data_retention_max_log_file_action_stig_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 takes the appropriate action when the audit files have reached maximum size.

Check that AlmaLinux OS 8 takes the appropriate action when the audit files have reached maximum size with the following command:

$ sudo grep max_log_file_action /etc/audit/auditd.conf

max_log_file_action = 
      Is it the case that the value of the "max_log_file_action" option is not "ROTATE", "SINGLE", or the line is commented out, ask the system administrator to indicate how the system takes appropriate action when an audit storage volume is full. If there is no evidence of appropriate action?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_data_retention_num_logs_question:question:1">
          <ocil:question_text>Inspect /etc/audit/auditd.conf and locate the following line to
determine how many logs the system is configured to retain after rotation:
$ sudo grep num_logs /etc/audit/auditd.conf
num_logs = 5
      Is it the case that the system log file retention has not been properly configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_data_retention_space_left_question:question:1">
          <ocil:question_text>Inspect /etc/audit/auditd.conf and locate the following line to
determine if the system is configured correctly:
space_left SIZE_in_MB
      Is it the case that the system is not configured a specific size in MB to notify administrators of an issue?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_data_retention_space_left_action_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 notifies the SA and ISSO (at a minimum) when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity with the following command:

$ sudo grep -w space_left_action /etc/audit/auditd.conf

space_left_action = 

If the value of the "space_left_action" is not set to "", or if the line is commented out, ask the System Administrator to indicate how the system is providing real-time alerts to the SA and ISSO.
      Is it the case that there is no evidence that real-time alerts are configured on the system?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_data_retention_space_left_percentage_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 takes action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity with the following command:

$ sudo grep -w space_left /etc/audit/auditd.conf

space_left = %
      Is it the case that the value of the "space_left" keyword is not set to &lt;sub idref="var_auditd_space_left_percentage" /&gt;% of the storage volume allocated to audit logs, or if the line is commented out, ask the System Administrator to indicate how the system is providing real-time alerts to the SA and ISSO. If the "space_left" value is not configured to the correct value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_freq_question:question:1">
          <ocil:question_text>To verify that Audit Daemon is configured to flush to disk after
every  records, run the following command:
$ sudo grep freq /etc/audit/auditd.conf
The output should return the following:
freq = 
      Is it the case that freq isn't set to &lt;sub idref="var_auditd_freq" /&gt;?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_local_events_question:question:1">
          <ocil:question_text>To verify that Audit Daemon is configured to include local events, run the
following command:
$ sudo grep local_events /etc/audit/auditd.conf
The output should return the following:
local_events = yes
      Is it the case that local_events isn't set to yes?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_log_format_question:question:1">
          <ocil:question_text>To verify that Audit Daemon is configured to resolve all uid, gid, syscall,
architecture, and socket address information before writing the event to disk,
run the following command:
$ sudo grep log_format /etc/audit/auditd.conf
The output should return the following:
log_format = ENRICHED
      Is it the case that log_format isn't set to ENRICHED?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_name_format_question:question:1">
          <ocil:question_text>To verify that Audit Daemon is configured to record the computer node
name in the audit events, run the following command:
$ sudo grep name_format /etc/audit/auditd.conf
The output should return the following:
name_format = 
      Is it the case that name_format isn't set to &lt;sub idref="var_auditd_name_format" /&gt;?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_overflow_action_question:question:1">
          <ocil:question_text>Verify the audit system is configured to take an appropriate action when the internal event queue is full:
$ sudo grep -i overflow_action /etc/audit/auditd.conf

The output should contain overflow_action = syslog

If the value of the "overflow_action" option is not set to syslog,
single, halt or the line is commented out, ask the System Administrator
to indicate how the audit logs are off-loaded to a different system or media.
      Is it the case that auditd overflow action is not set correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-auditd_write_logs_question:question:1">
          <ocil:question_text>To verify that Audit Daemon is configured to write logs to the disk, run the
following command:
$ sudo grep write_logs /etc/audit/auditd.conf
The output should return the following:
write_logs = yes
      Is it the case that write_logs isn't set to yes?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-banner_etc_issue_question:question:1">
          <ocil:question_text>To check if the system login banner is compliant,
run the following command:

$ cat /etc/issue
      Is it the case that it does not display the required banner?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-banner_etc_issue_cis_question:question:1">
          <ocil:question_text>Run the following command and verify no results are returned:

$ grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/issue
      Is it the case that any results are returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-banner_etc_issue_net_question:question:1">
          <ocil:question_text>To check if the system login banner is compliant, run the following command:
$ cat /etc/issue.net
      Is it the case that it does not display the required banner?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-banner_etc_issue_net_cis_question:question:1">
          <ocil:question_text>Run the following command and verify no results are returned:

$ grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/issue.net
      Is it the case that any results are returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-banner_etc_motd_question:question:1">
          <ocil:question_text>To check if the system motd banner is compliant,
run the following command:
$ cat /etc/motd
      Is it the case that it does not display the required banner?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-banner_etc_motd_cis_question:question:1">
          <ocil:question_text>Run the following command and verify no results are returned:

$ grep -E -i "(\\\v|\\\r|\\\m|\\\s|$(grep '^ID=' /etc/os-release | cut -d= -f2 | sed -e 's/"//g'))" /etc/motd
      Is it the case that any results are returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-bios_disable_usb_boot_question:question:1">
          <ocil:question_text>Verify that booting from USB devices is disabled in the system boot firmware (BIOS/UEFI).
The process to configure this setting varies by hardware manufacturer and model.
Consult your hardware manual or vendor documentation for specific instructions on how to
access the firmware setup during boot and disable USB boot capabilities.
      Is it the case that the system allows booting from USB devices?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-bios_enable_execution_restrictions_question:question:1">
          <ocil:question_text>Verify the NX (no-execution) bit flag is set on the system.

Check that the no-execution bit flag is set with the following commands:

$ sudo dmesg | grep NX

[ 0.000000] NX (Execute Disable) protection: active

If "dmesg" does not show "NX (Execute Disable) protection" active, check the cpuinfo settings with the following command:

$ sudo grep flags /proc/cpuinfo
flags : fpu vme de pse tsc ms nx rdtscp lm constant_ts

The output should contain the "nx" flag.
      Is it the case that NX is disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-chronyd_client_only_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 disables the chrony daemon from acting as a server with the following command:
$ grep -w port /etc/chrony.conf
port 0
      Is it the case that the "port" option is not set to "0", is commented out, or is missing?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-chronyd_configure_local_socket_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 configures chrony-wait.service to use Unix socket with the following command:
$ systemctl cat chrony-wait.service | grep ExecStart
ExecStart=/usr/bin/chronyc waitsync 0 0.1 0.0 1

The ExecStart line should not contain -h 127.0.0.1,::1 or similar network address specifications.
      Is it the case that chrony-wait.service uses network addresses?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-chronyd_no_chronyc_network_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 disables network management of the chrony daemon with the following command:
$ grep -w cmdport /etc/chrony.conf
cmdport 0
      Is it the case that the "cmdport" option is not set to "0", is commented out, or is missing?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-chronyd_or_ntpd_set_maxpoll_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 is securely comparing internal information system clocks at a regular interval with an NTP server with the following command:
$ sudo grep maxpoll /etc/ntp.conf /etc/chrony.conf /etc/chrony.d/
server [ntp.server.name] iburst maxpoll .
      Is it the case that "maxpoll" has not been set to the value of "&lt;sub idref="var_time_service_set_maxpoll" /&gt;", is commented out, or is missing?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-chronyd_or_ntpd_specify_remote_server_question:question:1">
          <ocil:question_text>To verify that a remote NTP service is configured for time synchronization,
open the following file:

/etc/chrony.conf in the case the system in question is
configured to use the chronyd as the NTP daemon (default setting)
/etc/ntp.conf in the case the system in question is configured
to use the ntpd as the NTP daemon

In the file, there should be a section similar to the following:
server ntpserver
      Is it the case that this is not the case?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-chronyd_run_as_chrony_user_question:question:1">
          <ocil:question_text>Run the following command and verify that OPTIONS are configured correctly:
# grep "^OPTIONS" /etc/sysconfig/chronyd
OPTIONS="-u chrony"
      Is it the case that chronyd is not running under chrony user account?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-chronyd_server_directive_question:question:1">
          <ocil:question_text>Run the following command and verify that time sources are only configured with server directive:
# grep -E "^(server|pool)" /etc/chrony.conf
A line with the appropriate server should be returned, any line returned starting with pool is a finding.
      Is it the case that an authoritative remote time server is not configured or configured with pool directive?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-chronyd_specify_remote_server_question:question:1">
          <ocil:question_text>Verify that a remote time server is configured. First, check the main configuration file:
# grep -E "^(server|pool)" /etc/chrony.conf
If no server or pool directive is found, check for sourcedir or confdir directives:
# grep -E "^(sourcedir|confdir)" /etc/chrony.conf
For each sourcedir found, check .sources files in that directory:
# grep -E "^(server|pool)" /path/to/sourcedir/*.sources
For each confdir found, check .conf files in that directory:
# grep -E "^(server|pool)" /path/to/confdir/*.conf
At least one server or pool directive must be present in the main configuration file
or in files within directories specified by sourcedir or confdir directives.
      Is it the case that a remote time server is not configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-clean_components_post_updating_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 removes all software components after updated versions have been installed.


$ grep clean_requirements_on_remove /etc/yum.conf
clean_requirements_on_remove=1
      Is it the case that '"clean_requirements_on_remove" is not set to "1"'?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_bashrc_exec_tmux_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 shell initialization file is configured to start each shell with the tmux terminal multiplexer.

Determine the location of the tmux script with the following command:

$ sudo grep tmux /etc/bashrc /etc/profile.d/*

/etc/profile.d/tmux.sh:  case "$name" in (sshd|login) exec tmux ;; esac

Review the tmux script by using the following example:

$ cat /etc/profile.d/tmux.sh

if [ "$PS1" ]; then
parent=$(ps -o ppid= -p $$)
name=$(ps -o comm= -p $parent)
case "$name" in (sshd|login) exec tmux ;; esac
fi

If the shell file is not configured as the example above, is commented out, or is missing, this is a finding.

Determine if tmux is currently running with the following command:

$ sudo ps all | grep tmux | grep -v grep
      Is it the case that the command does not produce output?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_bashrc_tmux_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 shell initialization file is configured to start each shell with the tmux terminal multiplexer.

Determine the location of the tmux script with the following command:

$ sudo grep tmux /etc/bashrc /etc/profile.d/*

/etc/profile.d/tmux.sh:  case "$name" in (sshd|login) tmux ;; esac

Review the tmux script by using the following example:

$ cat /etc/profile.d/tmux.sh

if [ "$PS1" ]; then
parent=$(ps -o ppid= -p $$)
name=$(ps -o comm= -p $parent)
case "$name" in (sshd|login) tmux ;; esac
fi

If the shell file is not configured as the example above, is commented out, or is missing, this is a finding.

Determine if tmux is currently running with the following command:

$ sudo ps all | grep tmux | grep -v grep
      Is it the case that the command does not produce output?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_bind_crypto_policy_question:question:1">
          <ocil:question_text>To verify that BIND uses the system crypto policy, check out that the BIND config file
/etc/named.conf contains the include "/etc/crypto-policies/back-ends/bind.config";
directive:
$ sudo grep 'include "/etc/crypto-policies/back-ends/bind.config";' /etc/named.conf
Verify that the directive is at the bottom of the options section of the config file.
      Is it the case that BIND is installed and the BIND config file doesn't contain the
&lt;pre&gt;include "/etc/crypto-policies/back-ends/bind.config";&lt;/pre&gt; directive?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_crypto_policy_question:question:1">
          <ocil:question_text>To verify that cryptography policy has been configured correctly, run the
following command:
$ update-crypto-policies --show
The output should return .
Run the command to check if the policy is correctly applied:
$ update-crypto-policies --is-applied
The output should be The configured policy is applied.
Moreover, check if settings for selected crypto policy are as expected.
List all libraries for which it holds that their crypto policies do not have symbolic link in /etc/crypto-policies/back-ends.
$ ls -l /etc/crypto-policies/back-ends/ | grep '^[^l]' | tail -n +2 | awk -F' ' '{print $NF}' | awk -F'.' '{print $1}' | sort
Subsequently, check if matching libraries have drop in files in the /etc/crypto-policies/local.d directory.
$ ls /etc/crypto-policies/local.d/ | awk -F'-' '{print $1}' | uniq | sort
Outputs of two previous commands should match.
      Is it the case that cryptographic policy is not configured or is configured incorrectly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_custom_crypto_policy_cis_question:question:1">
          <ocil:question_text>

Verify that /etc/crypto-policies/policies/modules/NO-SSHCBC.pmod exists and has the following content:

cipher@SSH = -*-CBC




Verify that /etc/crypto-policies/policies/modules/NO-SSHWEAKCIPHERS.pmod exists and has the following content:

cipher@SSH = -3DES-CBC -AES-128-CBC -AES-192-CBC -AES-256-CBC -CHACHA20-POLY1305




Verify that /etc/crypto-policies/policies/modules/NO-SSHWEAKMACS.pmod exists and has the following content:

mac@SSH = -HMAC-MD5* -UMAC-64* -UMAC-128*




Verify that /etc/crypto-policies/policies/modules/NO-WEAKMAC.pmod exists and has the following content:

mac = -*-128*

      Is it the case that the custom crypto policy modules do not exist?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_firewalld_ports_question:question:1">
          <ocil:question_text>Inspect the list of enabled firewall ports and verify they are configured correctly by running
the following command:

$ sudo firewall-cmd --list-all

Ask the System Administrator for the site or program Ports, Protocols, and Services Management Component Local Service Assessment (PPSM CLSA). Verify the services allowed by the firewall match the PPSM CLSA.
      Is it the case that there are additional ports, protocols, or services that are not in the PPSM CLSA, or there are ports, protocols, or services that are prohibited by the PPSM Category Assurance List (CAL), or there are no firewall rules configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_gnutls_tls_crypto_policy_question:question:1">
          <ocil:question_text>To verify if GnuTLS uses defined DoD-approved TLS Crypto Policy, run:
$ sudo grep
'+VERS-ALL:-VERS-DTLS0.9:-VERS-TLS1.1:-VERS-TLS1.0:-VERS-SSL3.0:-VERS-DTLS1.0'
/etc/crypto-policies/back-ends/gnutls.config and verify that a match exists.
      Is it the case that cryptographic policy for gnutls is not configured or is configured incorrectly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_kerberos_crypto_policy_question:question:1">
          <ocil:question_text>Check that the symlink exists and target the correct Kerberos crypto policy, with the following command:
file /etc/krb5.conf.d/crypto-policies
If command output shows the following line, Kerberos is configured to use the system-wide crypto policy.
/etc/krb5.conf.d/crypto-policies: symbolic link to /etc/crypto-policies/back-ends/krb5.config
      Is it the case that the symlink does not exist or points to a different target?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_libreswan_crypto_policy_question:question:1">
          <ocil:question_text>Verify that the IPsec service uses the system crypto policy.

If the IPsec service is not installed, this requirement is not applicable.

Check to see if the "IPsec" service is active with the following command:

$ systemctl status ipsec

ipsec.service - Internet Key Exchange (IKE) Protocol Daemon for IPsec
Loaded: loaded (/usr/lib/systemd/system/ipsec.service; disabled)
Active: inactive (dead)

If the "IPsec" service is active, check to see if it is using the system crypto policy with the following command:

$ sudo grep include /etc/ipsec.conf /etc/ipsec.d/*.conf

/etc/ipsec.conf:include /etc/crypto-policies/back-ends/libreswan.config
      Is it the case that the "IPsec" service is active and the ipsec configuration file does not contain does not contain &lt;tt&gt;include /etc/crypto-policies/back-ends/libreswan.config&lt;/tt&gt;?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_opensc_card_drivers_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 loads the  driver with the following command:

$ grep card_drivers /etc/opensc.conf

card_drivers = ;
      Is it the case that "&lt;sub idref="var_smartcard_drivers" /&gt;" is not listed as a card driver, or there is no line returned for "card_drivers"?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_openssl_crypto_policy_question:question:1">
          <ocil:question_text>To verify that OpenSSL uses the system crypto policy, check out that the OpenSSL config file
/etc/pki/tls/openssl.cnf contains the [ crypto_policy ] section with the
.include /etc/crypto-policies/back-ends/opensslcnf.config directive:

$ sudo grep '\.include\s* /etc/crypto-policies/back-ends/opensslcnf.config$' /etc/pki/tls/openssl.cnf.
      Is it the case that the OpenSSL config file doesn't contain the whole section,
or the section doesn't contain the &lt;pre&gt;.include /etc/crypto-policies/back-ends/opensslcnf.config&lt;/pre&gt; directive?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_openssl_tls_crypto_policy_question:question:1">
          <ocil:question_text>To verify if the OpenSSL uses defined TLS Crypto Policy, run:
$ grep -P '^(TLS\.)?MinProtocol' /etc/crypto-policies/back-ends/opensslcnf.config
and verify that the value is
TLSv1.2
      Is it the case that cryptographic policy for openssl is not configured or is configured incorrectly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_ssh_crypto_policy_question:question:1">
          <ocil:question_text>Verify that sshd isn't configured to ignore the system wide cryptographic policy.

Check that the CRYPTO_POLICY variable is not set or is commented out in the
/etc/sysconfig/sshd.

Run the following command:

$ sudo grep CRYPTO_POLICY /etc/sysconfig/sshd
      Is it the case that the CRYPTO_POLICY variable is set or is not commented out in /etc/sysconfig/sshd?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_tmux_lock_after_time_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 initiates a session lock after 15 minutes of inactivity.

Check the value of the system inactivity timeout with the following command:

$ grep -i lock-after-time /etc/tmux.conf

set -g lock-after-time 900

Then, verify that the /etc/tmux.conf file can be read by other users than root:

$ sudo ls -al /etc/tmux.conf
      Is it the case that "lock-after-time" is not set to "900" or less in the global tmux configuration file to enforce session lock after inactivity?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_tmux_lock_command_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 enables the user to initiate a session lock with the following command:

$ grep lock-command /etc/tmux.conf

set -g lock-command vlock

Then, verify that the /etc/tmux.conf file can be read by other users than root:

$ sudo ls -al /etc/tmux.conf
      Is it the case that the "lock-command" is not set in the global settings to call "vlock"?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_tmux_lock_keybinding_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 enables the user to initiate a session lock through key bindings with the following commands:

$ grep "lock-session" /etc/tmux.conf

bind X lock-session

Then, verify that the /etc/tmux.conf file can be read by other users than root:

$ sudo ls -al /etc/tmux.conf
      Is it the case that the "lock-session" is not bound to a specific key?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_usbguard_auditbackend_question:question:1">
          <ocil:question_text>To verify that Linux Audit logging is enabled for the USBGuard daemon,
run the following command:
$ sudo grep AuditBackend /etc/usbguard/usbguard-daemon.conf
The output should be
AuditBackend=LinuxAudit
      Is it the case that AuditBackend is not set to LinuxAudit?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configure_user_data_backups_question:question:1">
          <ocil:question_text>Verify that the system backups user data.
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-configured_firewalld_default_deny_question:question:1">
          <ocil:question_text>Verify "firewalld" is configured to employ a deny-all, allow-by-exception policy for allowing connections to other systems with the following commands:

$ sudo firewall-cmd --state

running

$ sudo firewall-cmd --get-active-zones

[custom]
interfaces: ens33

$ sudo firewall-cmd --info-zone=[custom] | grep target

target: DROP
      Is it the case that no zones are active on the interfaces or if the target is set to a different option other than "DROP"?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-coredump_disable_backtraces_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 disables core dump backtraces by issuing the following command:

$ grep -i process /etc/systemd/coredump.conf /etc/systemd/coredump.conf.d/*.conf

ProcessSizeMax=0
      Is it the case that the "ProcessSizeMax" item is missing, commented out, or the value is anything other than "0" and the need for core dumps is not documented with the Information System Security Officer (ISSO) as an operational requirement for all domains that have the "core" item assigned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-coredump_disable_storage_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 disables storing core dumps for all users by issuing the following command:

$ grep -i storage /etc/systemd/coredump.conf /etc/systemd/coredump.conf.d/*.conf

Storage=none
      Is it the case that Storage is not set to none or is commented out and the need for core dumps is not documented with the Information System Security Officer (ISSO) as an operational requirement for all domains that have the "core" item assigned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-coreos_enable_selinux_kernel_argument_question:question:1">
          <ocil:question_text>Inspect /proc/cmdline for any instances of selinux=0
in the kernel boot arguments.  Presence of selinux=0 indicates
that SELinux is disabled at boot time.

If it would be disabled anywhere, make sure to enable it via a
MachineConfig object.
      Is it the case that SELinux is disabled at boot time?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-cups_disable_browsing_question:question:1">
          <ocil:question_text>To verify that CUPS printer browsing is disabled, run the following command:
$ sudo grep "Browsing\|BrowseAllow" /etc/cups/cupsd.conf
The output should return the following:
Browsing Off
BrowseAllow none
      Is it the case that printer browsing is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_db_up_to_date_question:question:1">
          <ocil:question_text>In order to be sure that the databases are up-to-date, run the
dconf update
command as the administrator.
      Is it the case that The system-wide dconf databases are up-to-date with regards to respective keyfiles?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_banner_enabled_question:question:1">
          <ocil:question_text>To ensure a login warning banner is enabled, run the following:
$ grep banner-message-enable /etc/dconf/db/gdm.d/*
If properly configured, the output should be true.
To ensure a login warning banner is locked and cannot be changed by a user, run the following:
$ grep banner-message-enable /etc/dconf/db/gdm.d/locks/*
If properly configured, the output should be /org/gnome/login-screen/banner-message-enable.
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_disable_automount_question:question:1">
          <ocil:question_text>These settings can be verified by running the following:
$ gsettings get org.gnome.desktop.media-handling automount
If properly configured, the output for automount should be false.
To ensure that users cannot enable automount in GNOME3, run the following:
$ grep 'automount' /etc/dconf/db/gdm.d/locks/*
If properly configured, the output for automount should be /org/gnome/desktop/media-handling/automount
      Is it the case that GNOME automounting is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_disable_automount_open_question:question:1">
          <ocil:question_text>These settings can be verified by running the following:
$ gsettings get org.gnome.desktop.media-handling automount-open
If properly configured, the output for automount-openshould be false.
To ensure that users cannot enable automount opening in GNOME3, run the following:
$ grep 'automount-open' /etc/dconf/db/gdm.d/locks/*
If properly configured, the output for automount-open should be /org/gnome/desktop/media-handling/automount-open
      Is it the case that GNOME automounting is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_disable_autorun_question:question:1">
          <ocil:question_text>These settings can be verified by running the following:
$ gsettings get org.gnome.desktop.media-handling autorun-never
If properly configured, the output for autorun-nevershould be true.
To ensure that users cannot enable autorun in GNOME3, run the following:
$ grep 'autorun-never' /etc/dconf/db/gdm.d/locks/*
If properly configured, the output for autorun-never should be /org/gnome/desktop/media-handling/autorun-never
      Is it the case that GNOME autorun is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_disable_ctrlaltdel_reboot_question:question:1">
          <ocil:question_text>To ensure the system is configured to ignore the Ctrl-Alt-Del sequence,
run the following command:
$ gsettings get org.gnome.settings-daemon.plugins.media-keys logout
$ grep logout /etc/dconf/db/local.d/locks/*
If properly configured, the output should be
/org/gnome/settings-daemon/plugins/media-keys/logout
      Is it the case that GNOME3 is configured to reboot when Ctrl-Alt-Del is pressed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_disable_geolocation_question:question:1">
          <ocil:question_text>To ensure that system location tracking is not active, run the following command:
$ gsettings get org.gnome.system.location enabled
$ gsettings get org.gnome.clocks geolocation
If properly configured, the output should be false.
To ensure that users cannot enable system location tracking, run the following:
$ grep location /etc/dconf/db/local.d/locks/*
If properly configured, the output should be
/org/gnome/system/location/enabled and /org/gnome/clocks/geolocation.
      Is it the case that geolocation is enabled and not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_disable_power_settings_question:question:1">
          <ocil:question_text>To ensure that the GUI power settings are not active, run the following command:
$ gsettings get org.gnome.settings-daemon.plugins.power active
If properly configured, the output should be false.
To ensure that users cannot enable the power settings, run the following:
$ grep power /etc/dconf/db/local.d/locks/*
If properly configured, the output should be
/org/gnome/settings-daemon/plugins/power/active
      Is it the case that power settings are enabled and are not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_disable_restart_shutdown_question:question:1">
          <ocil:question_text>To ensure disable and restart on the login screen are disabled, run the following command:
$ grep disable-restart-buttons /etc/dconf/db/gdm.d/*
The output should be true.
To ensure that users cannot enable disable and restart on the login screen, run the following:
$ grep disable-restart-buttons /etc/dconf/db/gdm.d/locks/*
If properly configured, the output should be /org/gnome/login-screen/disable-restart-buttons
      Is it the case that disable-restart-buttons has not been configured or is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_disable_thumbnailers_question:question:1">
          <ocil:question_text>These settings can be verified by running the following:
$ gsettings get org.gnome.desktop.thumbnailers disable-all
If properly configured, the output should be true.
To ensure that users cannot how long until the screensaver locks, run the following:
$ grep disable-all /etc/dconf/db/local.d/locks/*
If properly configured, the output should be /org/gnome/desktop/thumbnailers/disable-all
      Is it the case that GNOME thumbnailers are not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_disable_user_admin_question:question:1">
          <ocil:question_text>To ensure the GUI does not allow user administratrion capabilities to all users,
run the following command:
$ gsettings get org.gnome.desktop.lockdown user-administration-disabled
If properly configured, the output should be true.
To ensure that users cannot enable user administration, run the following:
$ grep user-administration /etc/dconf/db/local.d/locks/*
If properly configured, the output should be
/org/gnome/desktop/lockdown/user-administration-disabled
      Is it the case that user administration is not configured or disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_disable_user_list_question:question:1">
          <ocil:question_text>To ensure the user list is disabled, run the following command:
$ grep disable-user-list /etc/dconf/db/gdm.d/*
The output should be true.
To ensure that users cannot enable displaying the user list, run the following:
$ grep disable-user-list /etc/dconf/db/gdm.d/locks/*
If properly configured, the output should be /org/gnome/login-screen/disable-user-list
      Is it the case that disable-user-list has not been configured or is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_disable_wifi_create_question:question:1">
          <ocil:question_text>To ensure that WIFI connections caanot be created, run the following command:
$ gsettings get org.gnome.nm-applet disable-wifi-create
If properly configured, the output should be true.
To ensure that users cannot enable WIFI connection creation, run the following:
$ grep wifi-create /etc/dconf/db/local.d/locks/*
If properly configured, the output should be
/org/gnome/nm-applet/disable-wifi-create
      Is it the case that WIFI connections can be created through GNOME?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_disable_wifi_notification_question:question:1">
          <ocil:question_text>To ensure that wireless network notification is disabled, run the following command:
$ gsettings get org.gnome.nm-applet suppress-wireless-networks-available
If properly configured, the output should be true.
To ensure that users cannot enable wireless notification, run the following:
$ grep wireless-networks-available /etc/dconf/db/local.d/locks/*
If properly configured, the output should be
/org/gnome/nm-applet/suppress-wireless-networks-available
      Is it the case that wireless network notification is enabled and not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_enable_smartcard_auth_question:question:1">
          <ocil:question_text>To ensure smart card authentication on the login screen is enabled, run the following command:
$ grep enable-smartcard-authentication /etc/dconf/db/gdm.d/*
The output should be true.
To ensure that users cannot disable smart card authentication on the login screen, run the following:
$ grep enable-smartcard-authentication /etc/dconf/db/gdm.d/locks/*
If properly configured, the output should be /org/gnome/login-screen/enable-smartcard-authentication
      Is it the case that enable-smartcard-authentication has not been configured or is disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_lock_screen_on_smartcard_removal_question:question:1">
          <ocil:question_text>To ensure screen locking on smartcard removal is enabled, run the following command:
$ grep removal-action /etc/dconf/db/local.d/*
The output should be 'lock-screen'.
To ensure that users cannot disable screen locking on smartcard removal, run the following:
$ grep removal-action /etc/dconf/db/local.d/locks/*
If properly configured, the output should be /org/gnome/settings-daemon/peripherals/smartcard/removal-action
      Is it the case that removal-action has not been configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_login_banner_text_question:question:1">
          <ocil:question_text>
To ensure the login warning banner text is properly set, run the following:
$ grep banner-message-text /etc/dconf/db/gdm.d/*
If properly configured, the proper banner text will appear.
To ensure the login warning banner text is locked and cannot be changed by a user, run the following:
$ grep banner-message-text /etc/dconf/db/gdm.d/locks/*
If properly configured, the output should be /org/gnome/login-screen/banner-message-text.
      Is it the case that it does not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_login_retries_question:question:1">
          <ocil:question_text>To ensure the login screen resets after a specified number of failures,
run the following command:
$ grep allowed-failures /etc/dconf/db/gdm.d/*
The output should be 3 or less.
To ensure that users cannot change or configure the resets after a specified
number of failures on the login screen, run the following:
$ grep allowed-failures /etc/dconf/db/gdm.d/locks/*
If properly configured, the output should be /org/gnome/login-screen/allowed-failures
      Is it the case that allowed-failures is not equal to or less than the expected value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_remote_access_credential_prompt_question:question:1">
          <ocil:question_text>To ensure that remote access requires credentials, run the following command:
$ gsettings get org.gnome.Vino authentication-methods
If properly configured, the output should be false.
To ensure that users cannot disable credentials for remote access, run the following:
$ grep authentication-methods /etc/dconf/db/gdm.d/locks/*
If properly configured, the output should be
/org/gnome/Vino/authentication-methods
      Is it the case that wireless network notification is enabled and not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_remote_access_encryption_question:question:1">
          <ocil:question_text>To ensure that remote access connections are encrypted, run the following command:
$ gsettings get org.gnome.Vino require-encrpytion
If properly configured, the output should be true.
To ensure that users cannot disable encrypted remote connections, run the following:
$ grep require-encryption /etc/dconf/db/gdm.d/locks/*
If properly configured, the output should be
/org/gnome/Vino/require-encryption
      Is it the case that remote access connections are not encrypted?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_screensaver_idle_activation_enabled_question:question:1">
          <ocil:question_text>To check the screensaver mandatory use status, run the following command:
$ gsettings get org.gnome.desktop.screensaver idle-activation-enabled
If properly configured, the output should be true.
To ensure that users cannot disable the screensaver idle inactivity setting, run the following:
$ grep idle-activation-enabled /etc/dconf/db/gdm.d/locks/*
If properly configured, the output should be /org/gnome/desktop/screensaver/idle-activation-enabled
      Is it the case that idle-activation-enabled is not enabled or configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_screensaver_idle_activation_locked_question:question:1">
          <ocil:question_text>To ensure that users cannot disable the screensaver idle inactivity setting, run the following:
$ grep idle-activation-enabled /etc/dconf/db/local.d/locks/*
If properly configured, the output should be /org/gnome/desktop/screensaver/idle-activation-enabled
      Is it the case that idle-activation-enabled is not locked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_screensaver_idle_delay_question:question:1">
          <ocil:question_text>To check the current idle time-out value, run the following command:
$ gsettings get org.gnome.desktop.session idle-delay
If properly configured, the output should be 'uint32 '.
To ensure that users cannot change the screensaver inactivity timeout setting, run the following:
$ grep idle-delay /etc/dconf/db/gdm.d/locks/*
If properly configured, the output should be /org/gnome/desktop/session/idle-delay
      Is it the case that idle-delay is set to 0 or a value greater than &lt;sub idref="inactivity_timeout_value" /&gt;?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_screensaver_lock_delay_question:question:1">
          <ocil:question_text>To check that the screen locks immediately when activated, run the following command:
$ gsettings get org.gnome.desktop.screensaver lock-delay
If properly configured, the output should be 'uint32 '.
      Is it the case that the screensaver lock delay is missing, or is set to a value greater than &lt;sub idref="var_screensaver_lock_delay" /&gt;?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_screensaver_lock_enabled_question:question:1">
          <ocil:question_text>To check the status of the idle screen lock activation, run the following command:

$ gsettings get org.gnome.desktop.screensaver lock-enabled
If properly configured, the output should be true.
To ensure that users cannot change how long until the screensaver locks, run the following:
$ grep lock-enabled /etc/dconf/db/gdm.d/locks/*
If properly configured, the output for lock-enabled should be /org/gnome/desktop/screensaver/lock-enabled
      Is it the case that screensaver locking is not enabled and/or has not been set or configured correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_screensaver_lock_locked_question:question:1">
          <ocil:question_text>To ensure that users cannot change how long until the screensaver locks, run the following:
$ grep lock-enabled /etc/dconf/db/local.d/locks/*
If properly configured, the output for lock-enabled should be /org/gnome/desktop/screensaver/lock-enabled
      Is it the case that screensaver locking is not locked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_screensaver_mode_blank_question:question:1">
          <ocil:question_text>To ensure the screensaver is configured to be blank, run the following command:
$ gsettings get org.gnome.desktop.screensaver picture-uri
If properly configured, the output should be ''.

To ensure that users cannot set the screensaver background, run the following:
$ grep picture-uri /etc/dconf/db/gdm.d/locks/*
If properly configured, the output should be /org/gnome/desktop/screensaver/picture-uri
      Is it the case that it is not set or configured properly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_screensaver_user_info_question:question:1">
          <ocil:question_text>To ensure the splash screen is configured not to show user name, run the following command:
$ gsettings get org.gnome.desktop.screensaver show-full-name-in-top-bar
If properly configured, the output should be false.
To ensure that users cannot enable user name on the lock screen, run the following:
$ grep show-full-name-in-top-bar /etc/dconf/db/local.d/locks/*
If properly configured, the output should be /org/gnome/desktop/screensaver/show-full-name-in-top-bar
      Is it the case that it is not set or configured properly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_screensaver_user_locks_question:question:1">
          <ocil:question_text>To ensure that users cannot change session idle and lock settings, run the following:
$ grep 'lock-delay' /etc/dconf/db/gdm.d/locks/*
If properly configured, the output should return:
/org/gnome/desktop/screensaver/lock-delay
      Is it the case that GNOME3 session settings are not locked or configured properly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dconf_gnome_session_idle_user_locks_question:question:1">
          <ocil:question_text>To ensure that users cannot change session idle and lock settings, run the following:
$ grep 'idle-delay' /etc/dconf/db/gdm.d/locks/*
If properly configured, the output should return:
/org/gnome/desktop/session/idle-delay
      Is it the case that idle-delay is not locked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dir_group_ownership_library_dirs_question:question:1">
          <ocil:question_text>Verify the system-wide shared library directories are group-owned by "root" with the following command:

$ sudo find /lib /lib64 /usr/lib /usr/lib64 ! -group root -type d -exec stat -c "%n %G" '{}' \;

If any system-wide shared library directory is returned and is not group-owned by a required system account, this is a finding.
      Is it the case that any system-wide shared library directory is returned and is not group-owned by a required system account?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dir_ownership_binary_dirs_question:question:1">
          <ocil:question_text>System executables are stored in the following directories by default:
/bin
/sbin
/usr/bin
/usr/local/bin
/usr/local/sbin
/usr/sbin
For each of these directories, run the following command to find files
not owned by root:
$ sudo find -L DIR/ ! -user root -type d -exec chown root {} \;
      Is it the case that any system executables directories are found to not be owned by root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dir_ownership_library_dirs_question:question:1">
          <ocil:question_text>Verify the system-wide shared library directories are owned by "root" with the following command:

$ sudo find /lib /lib64 /usr/lib /usr/lib64 ! -user root -type d -exec stat -c "%n %U" '{}' \;
      Is it the case that any system-wide shared library directory is not owned by root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dir_permissions_binary_dirs_question:question:1">
          <ocil:question_text>System executables are stored in the following directories by default:
/bin
/sbin
/usr/bin
/usr/sbin
/usr/local/bin
/usr/local/sbin
To find system executables directories that are group-writable or
world-writable, run the following command for each directory DIR
which contains system executables:
$ sudo find -L DIR -perm /022 -type d
      Is it the case that any of these files are group-writable or world-writable?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dir_permissions_library_dirs_question:question:1">
          <ocil:question_text>Shared libraries are stored in the following directories:
/lib
/lib64
/usr/lib
/usr/lib64

To find shared libraries that are group-writable or world-writable,
run the following command for each directory DIR which contains shared libraries:
$ sudo find -L DIR -perm /022 -type d
      Is it the case that any of these files are group-writable or world-writable?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dir_perms_etc_httpd_conf_question:question:1">
          <ocil:question_text>To check the permissions of /etc/http/conf,
run the command:
$ ls -l /etc/http/conf
If properly configured, the output should indicate the following permissions:
-rwxr-x---
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dir_perms_var_log_httpd_question:question:1">
          <ocil:question_text>Run the following command to check the mode of the httpd log
directory:
$ ls -l /var/log/ | grep httpd
Log directory must be mode 0700 or less permissive.
      Is it the case that it is more permissive?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dir_perms_world_writable_root_owned_question:question:1">
          <ocil:question_text>The following command will discover and print world-writable directories that
are not owned by root. Run it once for each local partition PART:
$ sudo find PART -xdev -type d -perm -0002 -uid +0 -print
      Is it the case that there are world-writable directories not owned by root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dir_perms_world_writable_sticky_bits_question:question:1">
          <ocil:question_text>To find world-writable directories that lack the sticky bit, run the following command:
$ sudo find / -type d \( -perm -0002 -a ! -perm -1000 \) -print 2&gt;/dev/null
fixtext: |-
Configure all world-writable directories to have the sticky bit set to prevent unauthorized and unintended information transferred via shared system resources.

Set the sticky bit on all world-writable directories using the command, replace "[World-Writable Directory]" with any directory path missing the sticky bit:

$ chmod a+t [World-Writable Directory]
srg_requirement:
A sticky bit must be set on all AlmaLinux OS 8 public directories to prevent unauthorized and unintended information transferred via shared system resources.
      Is it the case that any world-writable directories are missing the sticky bit?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dir_perms_world_writable_system_owned_question:question:1">
          <ocil:question_text>The following command will discover and print world-writable directories that are not owned by
a system account, given the assumption that only system accounts have a uid lower than 500.
Run it once for each local partition PART:
$ sudo find PART -xdev -type d -perm -0002 -uid +1000 -print
      Is it the case that there is output?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dir_perms_world_writable_system_owned_group_question:question:1">
          <ocil:question_text>The following command will discover and print world-writable directories that
are not group owned by a system account, given the assumption that only system
accounts have a gid lower than 1000.  Run it once for each local partition PART:
$ sudo find PART -xdev -type d -perm -0002 -gid +999 -print
      Is it the case that there is output?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dir_system_commands_group_root_owned_question:question:1">
          <ocil:question_text>System commands are stored in the following directories:
/bin 
/sbin 
/usr/bin 
/usr/sbin 
/usr/local/bin 
/usr/local/sbin
For each of these directories, run the following command to find directories not
owned by root:
$ sudo find -L $DIR ! -group root -type d -exec chgrp root {} \;
      Is it the case that any of these directories are not group owned by root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dir_system_commands_root_owned_question:question:1">
          <ocil:question_text>System commands are stored in the following directories:
/bin 
/sbin 
/usr/bin 
/usr/sbin 
/usr/local/bin 
/usr/local/sbin
For each of these directories, run the following command to find directories not
owned by root:
$ sudo find -L $DIR ! -user root -type d
      Is it the case that any of these directories are not owned by root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_access_var_log_audit_question:question:1">
          <ocil:question_text>To determine if the system is configured to audit accesses to
/var/log/audit directory, run the following command:
$ sudo grep "dir=/var/log/audit" /etc/audit/audit.rules
If the system is configured to audit this activity, it will return a line.
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_group_ownership_var_log_audit_question:question:1">
          <ocil:question_text>
Determine the audit log group by running the following command:

$ sudo grep -P '^[ ]*log_group[ ]+=.*$' /etc/audit/auditd.conf

Then, check that all directories within the /var/log/audit directory are owned by the group specified as log_group or by root if the log_group is not specified.
Run the following command:

$ sudo find /var/log/audit -type d -printf "%p %g\n"

All listed directories must be owned by the log_group or by root if the log_group is not specified.
      Is it the case that there is a directory owned by different group?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_groupowner_etc_ipsecd_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/ipsec.d,
run the command:
$ ls -lL /etc/ipsec.d
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/ipsec.d does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_groupowner_etc_iptables_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/iptables,
run the command:
$ ls -lL /etc/iptables
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/iptables does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_groupowner_etc_nftables_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/nftables,
run the command:
$ ls -lL /etc/nftables
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/nftables does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_groupowner_etc_selinux_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/selinux,
run the command:
$ ls -lL /etc/selinux
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/selinux does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_groupowner_etc_sudoersd_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/sudoers.d,
run the command:
$ ls -lL /etc/sudoers.d
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/sudoers.d does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_groupowner_etc_sysctld_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/sysctl.d,
run the command:
$ ls -lL /etc/sysctl.d
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/sysctl.d does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_owner_etc_ipsecd_question:question:1">
          <ocil:question_text>To check the ownership of /etc/ipsec.d,
run the command:
$ ls -lL /etc/ipsec.d
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/ipsec.d does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_owner_etc_iptables_question:question:1">
          <ocil:question_text>To check the ownership of /etc/iptables,
run the command:
$ ls -lL /etc/iptables
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/iptables does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_owner_etc_nftables_question:question:1">
          <ocil:question_text>To check the ownership of /etc/nftables,
run the command:
$ ls -lL /etc/nftables
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/nftables does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_owner_etc_selinux_question:question:1">
          <ocil:question_text>To check the ownership of /etc/selinux,
run the command:
$ ls -lL /etc/selinux
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/selinux does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_owner_etc_sudoersd_question:question:1">
          <ocil:question_text>To check the ownership of /etc/sudoers.d,
run the command:
$ ls -lL /etc/sudoers.d
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/sudoers.d does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_owner_etc_sysctld_question:question:1">
          <ocil:question_text>To check the ownership of /etc/sysctl.d,
run the command:
$ ls -lL /etc/sysctl.d
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/sysctl.d does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_ownership_var_log_audit_question:question:1">
          <ocil:question_text>Determine where the audit logs are stored with the following command:

$ sudo grep -iw log_file /etc/audit/auditd.conf

log_file = /var/log/audit/audit.log

Determine the owner of the audit log directory by using the output of the above command
(default: "/var/log/audit/"). Run the following command with the correct audit log directory
path:

$ sudo ls -ld /var/log/audit

drwx------ 2 root root 23 Jun 11 11:56 /var/log/audit

The audit log directory must be owned by "root"
      Is it the case that the directory is not owned by root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_permissions_etc_ipsecd_question:question:1">
          <ocil:question_text>To check the permissions of /etc/ipsec.d,
run the command:
$ ls -l /etc/ipsec.d
If properly configured, the output should indicate the following permissions:
0700
      Is it the case that /etc/ipsec.d does not have unix mode 0700?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_permissions_etc_iptables_question:question:1">
          <ocil:question_text>To check the permissions of /etc/iptables,
run the command:
$ ls -l /etc/iptables
If properly configured, the output should indicate the following permissions:
0700
      Is it the case that /etc/iptables does not have unix mode 0700?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_permissions_etc_nftables_question:question:1">
          <ocil:question_text>To check the permissions of /etc/nftables,
run the command:
$ ls -l /etc/nftables
If properly configured, the output should indicate the following permissions:
0700
      Is it the case that /etc/nftables does not have unix mode 0700?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_permissions_etc_selinux_question:question:1">
          <ocil:question_text>To check the permissions of /etc/selinux,
run the command:
$ ls -l /etc/selinux
If properly configured, the output should indicate the following permissions:
0755
      Is it the case that /etc/selinux does not have unix mode 0755?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_permissions_etc_sudoersd_question:question:1">
          <ocil:question_text>To check the permissions of /etc/sudoers.d,
run the command:
$ ls -l /etc/sudoers.d
If properly configured, the output should indicate the following permissions:
0750
      Is it the case that /etc/sudoers.d does not have unix mode 0750?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_permissions_etc_sysctld_question:question:1">
          <ocil:question_text>To check the permissions of /etc/sysctl.d,
run the command:
$ ls -l /etc/sysctl.d
If properly configured, the output should indicate the following permissions:
0755
      Is it the case that /etc/sysctl.d does not have unix mode 0755?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-directory_permissions_var_log_audit_question:question:1">
          <ocil:question_text>Verify the audit log directories have a correct mode or less permissive mode.

Find the location of the audit logs:

$ sudo grep "^log_file" /etc/audit/auditd.conf

Find the group that owns audit logs:

$ sudo grep "^log_group" /etc/audit/auditd.conf

Run the following command to check the mode of the system audit logs:

$ sudo stat -c "%a %n" [audit_log_directory]

Replace "[audit_log_directory]" to the correct audit log directory path, by default this location is "/var/log/audit".

If the log_group is "root" or is not set, the correct permissions are 0700, otherwise they are 0750.
      Is it the case that audit logs have a more permissive mode?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-disable_anacron_question:question:1">
          <ocil:question_text>Run the following command to determine if the cronie-anacron package is installed: $ rpm -q cronie-anacron
      Is it the case that the cronie-anacron package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-disable_ctrlaltdel_burstaction_question:question:1">
          <ocil:question_text>To ensure the system is configured to ignore the Ctrl-Alt-Del setting,
enter the following command:
$ sudo grep -i ctrlaltdelburstaction /etc/systemd/system.conf
The output should return:
CtrlAltDelBurstAction=none
      Is it the case that the system is configured to reboot when Ctrl-Alt-Del is pressed more than 7 times in 2 seconds.?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-disable_ctrlaltdel_reboot_question:question:1">
          <ocil:question_text>To ensure the system is configured to mask the Ctrl-Alt-Del sequence, Check
that the ctrl-alt-del.target is masked and not active with the following
command:
sudo systemctl status ctrl-alt-del.target
The output should indicate that the target is masked and not active. It
might resemble following output:
ctrl-alt-del.target
Loaded: masked (/dev/null; bad)
Active: inactive (dead)
      Is it the case that the system is configured to reboot when Ctrl-Alt-Del is pressed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-disable_host_auth_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's HostbasedAuthentication option is set, run the following command:

$ sudo grep -i HostbasedAuthentication /etc/ssh/sshd_config

If a line indicating no is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-disable_users_coredumps_question:question:1">
          <ocil:question_text>Verify that core dumps are disabled for all users, run the following command:
$ grep core /etc/security/limits.conf
*     hard   core    0
      Is it the case that the "core" item is missing, commented out, or the value is anything other than "0" and the need for core dumps is not documented with the Information System Security Officer (ISSO) as an operational requirement for all domains that have the "core"?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-disable_weak_deps_question:question:1">
          <ocil:question_text>To verify that weak dependencies are disabled, run the following command:
# grep -Pi -- '^\h*install_weak_deps\h*=\h*(0|false|no)\b' /etc/dnf/dnf.conf
The output should return the following:
install_weak_deps = 0
      Is it the case that the install_weak_deps option is not set to 0?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-disallow_bypass_password_sudo_question:question:1">
          <ocil:question_text>Verify the operating system is not configured to bypass password requirements for privilege
escalation. Check the configuration of the "/etc/pam.d/sudo" file with the following command:
$ sudo grep pam_succeed_if /etc/pam.d/sudo
      Is it the case that system is configured to bypass password requirements for privilege escalation?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-display_login_attempts_question:question:1">
          <ocil:question_text>Verify users are provided with feedback on when account accesses last occurred with the following command:

$ sudo grep pam_lastlog /etc/pam.d/postlogin

session [default=1] pam_lastlog.so showfailed
      Is it the case that "pam_lastlog.so" is not properly configured in "/etc/pam.d/postlogin" file?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dnf-automatic_apply_updates_question:question:1">
          <ocil:question_text>To verify that packages comprising the available updates will be automatically installed by dnf-automatic, run the following command:
$ sudo grep apply_updates /etc/dnf/automatic.conf
The output should return the following:
apply_updates = yes
      Is it the case that apply_updates is not set to yes?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-dnf-automatic_security_updates_only_question:question:1">
          <ocil:question_text>To verify that only security updates will be automatically installed by dnf-automatic, run the following command:
$ sudo grep upgrade_type /etc/dnf/automatic.conf
The output should return the following:
upgrade_type = security
      Is it the case that the upgrade_type is not set to security?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-enable_authselect_question:question:1">
          <ocil:question_text>Verify that authselect is enabled by running
authselect current
If authselect is enabled on the system, the output should show the ID of the profile which is currently in use.
      Is it the case that authselect is not used to manage user authentication setup on the system?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-enable_dconf_user_profile_question:question:1">
          <ocil:question_text>To verify that the DConf User profile is configured correctly, run the following
command:

$ cat /etc/dconf/profile/user
The output should show the following:
user-db:user
system-db:local
system-db:site
system-db:distro
      Is it the case that DConf User profile does not exist or is not configured correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-enable_dracut_fips_module_question:question:1">
          <ocil:question_text>To verify that the Dracut FIPS module is enabled, run the following command:
grep "add_dracutmodules" /etc/dracut.conf.d/40-fips.conf
The output should look like this:
add_dracutmodules+=" fips "
      Is it the case that the Dracut FIPS module is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-enable_fips_mode_question:question:1">
          <ocil:question_text>To verify that FIPS mode is enabled properly, run the following command:
cat /proc/sys/crypto/fips_enabled
The output be must:
1
      Is it the case that FIPS mode is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-enable_gpgcheck_for_all_repositories_question:question:1">
          <ocil:question_text>To determine whether yum has been configured to disable
gpgcheck for any repos, inspect all files in
 and ensure the following does not appear in any
sections:
gpgcheck=0
A value of 0 indicates that gpgcheck has been disabled for that repo.
      Is it the case that GPG checking is disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-enable_ldap_client_question:question:1">
          <ocil:question_text>To determine if LDAP is being used for authentication, use the following
command:
$ sudo grep -i useldapauth /etc/sysconfig/authconfig
The output should return:
USELDAPAUTH=yes
      Is it the case that USELDAPAUTH=yes is not configured correctly in /etc/sysconfig/authconfig?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-enable_pam_namespace_question:question:1">
          <ocil:question_text>To check if pam_namespace.so is required for user login, run the following command:
$ grep pam_namespace.so /etc/pam.d/login
The output should return the following uncommented:
session    required     pam_namespace.so
      Is it the case that pam_namespace.so is not required or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-encrypt_partitions_question:question:1">
          <ocil:question_text>Check the system partitions to determine if they are encrypted with the following command:
blkid

Output will be similar to:
/dev/sda1: UUID=" ab12c3de-4f56-789a-8f33-3850cc8ce3a2
" TYPE="crypto_LUKS"
/dev/sda2: UUID=" bc98d7ef-6g54-321h-1d24-9870de2ge1a2
" TYPE="crypto_LUKS"

The boot partition and pseudo-file systems, such as /proc, /sys, and tmpfs,
are not required to use disk encryption and are not a finding.
      Is it the case that partitions do not have a type of crypto_LUKS?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ensure_almalinux_gpgkey_installed_question:question:1">
          <ocil:question_text>To ensure that the GPG key is installed, run:
$ rpm -q --queryformat "%{SUMMARY}\n" gpg-pubkey
The command should return the string below:
gpg(AlmaLinux OS 8 &lt;packager@almalinux.org&gt;
      Is it the case that the AlmaLinux GPG Key is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ensure_epel_repos_disabled_question:question:1">
          <ocil:question_text>To verify that EPEL repository is not enabled, run the following commands:
$ grep -r "^\[.*epel.*\]" /etc/yum.repos.d/
For each EPEL repository found, check if it is enabled:
$ grep -A 5 "^\[.*epel.*\]" /etc/yum.repos.d/*.repo | grep "enabled"
The output should show enabled=0 for all EPEL repositories, or no EPEL repositories
should be present.
      Is it the case that EPEL repository is enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ensure_gpgcheck_globally_activated_question:question:1">
          <ocil:question_text>Verify that yum verifies the signature of packages from a repository prior to install with the following command:

$ grep gpgcheck /etc/yum.conf

gpgcheck=1

If "gpgcheck" is not set to "1", or if the option is missing or commented out, ask the System Administrator how the certificates for patches and other operating system components are verified.
      Is it the case that there is no process to validate certificates that is approved by the organization?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ensure_gpgcheck_local_packages_question:question:1">
          <ocil:question_text>Verify that yum verifies the signature of local packages prior to install with the following command:

$ grep localpkg_gpgcheck /etc/yum.conf

localpkg_gpgcheck=1

If "localpkg_gpgcheck" is not set to "1", or if the option is missing or commented out, ask the System Administrator how the certificates for patches and other operating system components are verified.
      Is it the case that there is no process to validate certificates for local packages that is approved by the organization?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ensure_gpgcheck_never_disabled_question:question:1">
          <ocil:question_text>To determine whether yum has been configured to disable
gpgcheck for any repos,  inspect all files in
/etc/yum.repos.d and ensure the following does not appear in any
sections:
gpgcheck=0
A value of 0 indicates that gpgcheck has been disabled for that repo.
      Is it the case that GPG checking is disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ensure_gpgcheck_repo_metadata_question:question:1">
          <ocil:question_text>To verify that repo_gpgcheck is configured properly, run the following
command:
$ grep repo_gpgcheck /etc/yum.conf
The output should return something similar to:
repo_gpgcheck=1
      Is it the case that gpgcheck is not enabled or configured correctly to verify repository metadata?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ensure_logrotate_activated_question:question:1">
          <ocil:question_text>To determine the status and frequency of logrotate, run the following command:
$ sudo grep logrotate /var/log/cron*
If logrotate is configured properly, output should include references to
/etc/cron.daily.
      Is it the case that logrotate is not configured to run daily?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ensure_pam_wheel_group_empty_question:question:1">
          <ocil:question_text>Run the following command to check if the  group exists:
grep  /etc/group
The output should contain the following line:
:x:
      Is it the case that group  exists and has no user members?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ensure_root_password_configured_question:question:1">
          <ocil:question_text>root password is not set
      Is it the case that Perform the following to determine if a password is set for the
root user:
&lt;pre&gt;# grep -Eq '^root:\$[0-9]' /etc/shadow || echo "root is locked"&lt;/pre&gt;
No results should be returned.
Otherwise, run the following command and follow the prompts to set a
password for the root user:
&lt;pre&gt;# passwd root&lt;/pre&gt;?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-etc_system_fips_exists_question:question:1">
          <ocil:question_text>To verify /etc/system-fips exists, run the following command:
ls -l /etc/system-fips
The output should be similar to the following:
-rw-r--r--. 1 root root 36 Nov 26 11:31 /etc/system-fips
      Is it the case that /etc/system-fips does not exist?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-fapolicy_default_deny_question:question:1">
          <ocil:question_text>Verify the AlmaLinux OS 8 "fapolicyd" employs a deny-all, permit-by-exception policy.

Check that "fapolicyd" is in enforcement mode with the following command:

$ sudo grep permissive /etc/fapolicyd/fapolicyd.conf

permissive = 0

Check that fapolicyd employs a deny-all policy on system mounts with the following commands:

For RHEL 8.5 systems and older:
$ sudo tail /etc/fapolicyd/fapolicyd.rules

For RHEL 8.6 systems and newer:
$ sudo tail /etc/fapolicyd/compiled.rules

allow exe=/usr/bin/python3.7 : ftype=text/x-python
deny_audit perm=any pattern=ld_so : all
deny perm=any all : all

Note: The "deny_log" and "deny_audit" actions also meet the security requirements as they deny
execution while additionally providing logging.
      Is it the case that fapolicyd is not running in enforcement mode with a deny-all, permit-by-exception policy?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_at_allow_exists_question:question:1">
          <ocil:question_text>The file /etc/at.allow should exist.
This can be checked by running the following command:

stat /etc/at.allow

and the output should list the file.
      Is it the case that the file /etc/at.allow does not exist?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_at_deny_not_exist_question:question:1">
          <ocil:question_text>The file /etc/at.deny should not exist.
This can be checked by running the following

stat /etc/at.deny

and the output should be

stat: cannot stat `/etc/at.deny': No such file or directory

      Is it the case that the file /etc/at.deny exists?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_audit_tools_group_ownership_question:question:1">
          <ocil:question_text>Verify the audit tools are group-owned by "root" to prevent any unauthorized access, deletion, or modification.

Check the group-owner of each audit tool by running the following command:

$ sudo stat -c "%G %n" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/rsyslogd /sbin/augenrules

root /sbin/auditctl
root /sbin/aureport
root /sbin/ausearch
root /sbin/autrace
root /sbin/auditd
root /sbin/rsyslogd
root /sbin/augenrules
      Is it the case that any audit tools are not group-owned by root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_audit_tools_ownership_question:question:1">
          <ocil:question_text>Verify the audit tools are owned by "root" to prevent any unauthorized access, deletion, or modification.

Check the owner of each audit tool by running the following command:

$ sudo stat -c "%U %n" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/rsyslogd /sbin/augenrules

root /sbin/auditctl
root /sbin/aureport
root /sbin/ausearch
root /sbin/autrace
root /sbin/auditd
root /sbin/rsyslogd
root /sbin/augenrules
      Is it the case that any audit tools are not owned by root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_audit_tools_permissions_question:question:1">
          <ocil:question_text>Verify the audit tools are protected from unauthorized access, deletion, or modification by checking the permissive mode.

Check the octal permission of each audit tool by running the following command:

$ sudo stat -c "%U %n" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/rsyslogd /sbin/augenrules
      Is it the case that any of these files have more permissive permissions than 0755?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_cron_allow_exists_question:question:1">
          <ocil:question_text>The file /etc/cron.allow should exist.
This can be checked by running the following command:

stat /etc/cron.allow

and the output should list the file.
      Is it the case that the file /etc/cron.allow does not exist?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_cron_deny_not_exist_question:question:1">
          <ocil:question_text>The file /etc/cron.deny should not exist.
This can be checked by running the following

stat /etc/cron.deny

and the output should be

stat: cannot stat `/etc/cron.deny': No such file or directory

      Is it the case that the file /etc/cron.deny exists?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_etc_security_opasswd_question:question:1">
          <ocil:question_text>To check the ownership of /etc/security/opasswd,
run the command:
$ ls -lL /etc/security/opasswd
If properly configured, the output should indicate the following owner:
root
To check the group ownership of /etc/security/opasswd,
run the command:
$ ls -lL /etc/security/opasswd
If properly configured, the output should indicate the following group-owner:

  root
  

To check the permissions of /etc/security/opasswd,
run the command:
$ ls -l /etc/security/opasswd
If properly configured, the output should indicate the following permissions:
0600
      Is it the case that /etc/security/opasswd does not have an owner of root and /etc/security/opasswd does not have a group owner of
root
and /etc/security/opasswd does not have unix mode 0600?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_group_ownership_var_log_audit_question:question:1">
          <ocil:question_text>Check group owners of the system audit logs.

First, determine where the audit log file is located.

$ sudo grep -iw ^log_file /etc/audit/auditd.conf
log_file = /var/log/audit/audit.log

The log_file option specifies the audit log file path.
If the log_file option isn't defined, check all files within /var/log/audit directory.


Then, determine the audit log group by running the following command:
$ sudo grep -P '^[ ]*log_group[ ]+=.*$' /etc/audit/auditd.conf


Then, check that the audit log file is owned by the correct group.
Run the following command to display the owner of the audit log file:

$ sudo stat -c "%n %G" log_file


The audit log file must be owned by the log_group or by root if the log_group is not specified.
      Is it the case that audit log files are owned by incorrect group?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_at_allow_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/at.allow,
run the command:
$ ls -lL /etc/at.allow
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/at.allow does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_backup_etc_group_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/group-,
run the command:
$ ls -lL /etc/group-
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/group- does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_backup_etc_gshadow_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/gshadow-,
run the command:
$ ls -lL /etc/gshadow-
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/gshadow- does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_backup_etc_passwd_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/passwd-,
run the command:
$ ls -lL /etc/passwd-
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/passwd- does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_backup_etc_shadow_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/shadow-,
run the command:
$ ls -lL /etc/shadow-
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/shadow- does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_cron_allow_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/cron.allow,
run the command:
$ ls -lL /etc/cron.allow
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/cron.allow does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_cron_d_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/cron.d,
run the command:
$ ls -lL /etc/cron.d
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/cron.d does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_cron_daily_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/cron.daily,
run the command:
$ ls -lL /etc/cron.daily
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/cron.daily does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_cron_hourly_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/cron.hourly,
run the command:
$ ls -lL /etc/cron.hourly
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/cron.hourly does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_cron_monthly_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/cron.monthly,
run the command:
$ ls -lL /etc/cron.monthly
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/cron.monthly does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_cron_weekly_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/cron.weekly,
run the command:
$ ls -lL /etc/cron.weekly
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/cron.weekly does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_cron_yearly_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/cron.yearly,
run the command:
$ ls -lL /etc/cron.yearly
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/cron.yearly does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_crontab_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/crontab,
run the command:
$ ls -lL /etc/crontab
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/crontab does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_efi_grub2_cfg_question:question:1">
          <ocil:question_text>To check the group ownership of /boot/efi/EFI/almalinux/grub.cfg,
run the command:
$ ls -lL /boot/efi/EFI/almalinux/grub.cfg
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /boot/efi/EFI/almalinux/grub.cfg does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_efi_user_cfg_question:question:1">
          <ocil:question_text>To check the group ownership of /boot/efi/EFI/almalinux/user.cfg,
run the command:
$ ls -lL /boot/efi/EFI/almalinux/user.cfg
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /boot/efi/EFI/almalinux/user.cfg does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_etc_chrony_keys_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/chrony.keys,
run the command:
$ ls -lL /etc/chrony.keys
If properly configured, the output should indicate the following group-owner:

  chrony
  
      Is it the case that /etc/chrony.keys does not have a group owner of
chrony
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_etc_crypttab_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/crypttab,
run the command:
$ ls -lL /etc/crypttab
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/crypttab does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_etc_group_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/group,
run the command:
$ ls -lL /etc/group
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/group does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_etc_gshadow_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/gshadow,
run the command:
$ ls -lL /etc/gshadow
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/gshadow does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_etc_ipsec_conf_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/ipsec.conf,
run the command:
$ ls -lL /etc/ipsec.conf
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/ipsec.conf does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_etc_ipsec_secrets_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/ipsec.secrets,
run the command:
$ ls -lL /etc/ipsec.secrets
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/ipsec.secrets does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_etc_issue_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/issue,
run the command:
$ ls -lL /etc/issue
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/issue does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_etc_issue_net_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/issue.net,
run the command:
$ ls -lL /etc/issue.net
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/issue.net does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_etc_motd_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/motd,
run the command:
$ ls -lL /etc/motd
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/motd does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_etc_passwd_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/passwd,
run the command:
$ ls -lL /etc/passwd
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/passwd does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_etc_security_opasswd_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/security/opasswd,
run the command:
$ ls -lL /etc/security/opasswd
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/security/opasswd does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_etc_security_opasswd_old_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/security/opasswd.old,
run the command:
$ ls -lL /etc/security/opasswd.old
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/security/opasswd.old does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_etc_sestatus_conf_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/sestatus.conf,
run the command:
$ ls -lL /etc/sestatus.conf
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/sestatus.conf does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_etc_shadow_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/shadow,
run the command:
$ ls -lL /etc/shadow
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/shadow does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_etc_shells_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/shells,
run the command:
$ ls -lL /etc/shells
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/shells does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_etc_sudoers_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/sudoers,
run the command:
$ ls -lL /etc/sudoers
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/sudoers does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_etc_sysconfig_sshd_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/sysconfig/sshd,
run the command:
$ ls -lL /etc/sysconfig/sshd
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/sysconfig/sshd does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_grub2_cfg_question:question:1">
          <ocil:question_text>To check the group ownership of /boot/grub2/grub.cfg,
run the command:
$ ls -lL /boot/grub2/grub.cfg
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /boot/grub2/grub.cfg does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_sshd_config_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/ssh/sshd_config,
run the command:
$ ls -lL /etc/ssh/sshd_config
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/ssh/sshd_config does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_systemmap_question:question:1">
          <ocil:question_text>To check the group ownership of /boot/System.map*,
run the command:
$ ls -lL /boot/System.map*
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /boot/System.map* does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_user_cfg_question:question:1">
          <ocil:question_text>To check the group ownership of /boot/grub2/user.cfg,
run the command:
$ ls -lL /boot/grub2/user.cfg
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /boot/grub2/user.cfg does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_var_log_question:question:1">
          <ocil:question_text>To check the group ownership of /var/log,
run the command:
$ ls -lL /var/log
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /var/log does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_var_log_messages_question:question:1">
          <ocil:question_text>To check the group ownership of /var/log/messages,
run the command:
$ ls -lL /var/log/messages
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /var/log/messages does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupowner_var_log_syslog_question:question:1">
          <ocil:question_text>To check the group ownership of /var/log/syslog,
run the command:
$ ls -lL /var/log/syslog
If properly configured, the output should indicate the following group-owner:

  adm
  
      Is it the case that /var/log/syslog does not have a group owner of
adm
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupownership_audit_binaries_question:question:1">
          <ocil:question_text>Verify it by running the following command:
$ stat -c "%n %G" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd /sbin/augenrules

/sbin/auditctl root

/sbin/aureport root

/sbin/ausearch root

/sbin/autrace root

/sbin/auditd root

/sbin/audispd root

/sbin/augenrules root



If the command does not return all the above lines, the missing ones
need to be added.

Run the following command to correct the permissions of the missing
entries:
$ sudo chown :root [audit_tool] 

Replace "[audit_tool]" with each audit tool not group-owned by root.
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupownership_audit_configuration_question:question:1">
          <ocil:question_text>To properly set the group owner of /etc/audit/, run the command:

  $ sudo chgrp root /etc/audit/
  

To properly set the group owner of /etc/audit/rules.d/, run the command:

  $ sudo chgrp root /etc/audit/rules.d/
  
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupownership_home_directories_question:question:1">
          <ocil:question_text>To verify the assigned home directory of all interactive users is group-
owned by that users primary GID, run the following command:
# ls -ld $(awk -F: '($3&gt;=1000)&amp;&amp;($7 !~ /nologin/){print $6}' /etc/passwd)
      Is it the case that the group ownership is incorrect?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupownership_sshd_private_key_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/ssh/*_key,
run the command:
$ ls -lL /etc/ssh/*_key
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/ssh/*_key does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupownership_sshd_pub_key_question:question:1">
          <ocil:question_text>To check the group ownership of /etc/ssh/*.pub,
run the command:
$ ls -lL /etc/ssh/*.pub
If properly configured, the output should indicate the following group-owner:

  root
  
      Is it the case that /etc/ssh/*.pub does not have a group owner of
root
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_groupownership_system_commands_dirs_question:question:1">
          <ocil:question_text>Verify the system commands contained in the following directories are group-owned by "root", or a required system account, with the following command:
$ sudo find -L /bin /sbin /usr/bin /usr/sbin /usr/local/bin /usr/local/sbin ! -group root -exec ls -l {} \;
      Is it the case that any system commands are returned and is not group-owned by a required system account?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_at_allow_question:question:1">
          <ocil:question_text>To check the ownership of /etc/at.allow,
run the command:
$ ls -lL /etc/at.allow
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/at.allow does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_backup_etc_group_question:question:1">
          <ocil:question_text>To check the ownership of /etc/group-,
run the command:
$ ls -lL /etc/group-
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/group- does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_backup_etc_gshadow_question:question:1">
          <ocil:question_text>To check the ownership of /etc/gshadow-,
run the command:
$ ls -lL /etc/gshadow-
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/gshadow- does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_backup_etc_passwd_question:question:1">
          <ocil:question_text>To check the ownership of /etc/passwd-,
run the command:
$ ls -lL /etc/passwd-
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/passwd- does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_backup_etc_shadow_question:question:1">
          <ocil:question_text>To check the ownership of /etc/shadow-,
run the command:
$ ls -lL /etc/shadow-
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/shadow- does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_cron_allow_question:question:1">
          <ocil:question_text>To check the ownership of /etc/cron.allow,
run the command:
$ ls -lL /etc/cron.allow
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/cron.allow does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_cron_d_question:question:1">
          <ocil:question_text>To check the ownership of /etc/cron.d,
run the command:
$ ls -lL /etc/cron.d
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/cron.d does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_cron_daily_question:question:1">
          <ocil:question_text>To check the ownership of /etc/cron.daily,
run the command:
$ ls -lL /etc/cron.daily
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/cron.daily does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_cron_hourly_question:question:1">
          <ocil:question_text>To check the ownership of /etc/cron.hourly,
run the command:
$ ls -lL /etc/cron.hourly
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/cron.hourly does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_cron_monthly_question:question:1">
          <ocil:question_text>To check the ownership of /etc/cron.monthly,
run the command:
$ ls -lL /etc/cron.monthly
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/cron.monthly does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_cron_weekly_question:question:1">
          <ocil:question_text>To check the ownership of /etc/cron.weekly,
run the command:
$ ls -lL /etc/cron.weekly
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/cron.weekly does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_cron_yearly_question:question:1">
          <ocil:question_text>To check the ownership of /etc/cron.yearly,
run the command:
$ ls -lL /etc/cron.yearly
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/cron.yearly does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_crontab_question:question:1">
          <ocil:question_text>To check the ownership of /etc/crontab,
run the command:
$ ls -lL /etc/crontab
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/crontab does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_efi_grub2_cfg_question:question:1">
          <ocil:question_text>To check the ownership of /boot/efi/EFI/almalinux/grub.cfg,
run the command:
$ ls -lL /boot/efi/EFI/almalinux/grub.cfg
If properly configured, the output should indicate the following owner:
root
      Is it the case that /boot/efi/EFI/almalinux/grub.cfg does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_efi_user_cfg_question:question:1">
          <ocil:question_text>To check the ownership of /boot/efi/EFI/almalinux/user.cfg,
run the command:
$ ls -lL /boot/efi/EFI/almalinux/user.cfg
If properly configured, the output should indicate the following owner:
root
      Is it the case that /boot/efi/EFI/almalinux/user.cfg does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_etc_chrony_keys_question:question:1">
          <ocil:question_text>To check the ownership of /etc/chrony.keys,
run the command:
$ ls -lL /etc/chrony.keys
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/chrony.keys does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_etc_crypttab_question:question:1">
          <ocil:question_text>To check the ownership of /etc/crypttab,
run the command:
$ ls -lL /etc/crypttab
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/crypttab does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_etc_group_question:question:1">
          <ocil:question_text>To check the ownership of /etc/group,
run the command:
$ ls -lL /etc/group
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/group does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_etc_gshadow_question:question:1">
          <ocil:question_text>To check the ownership of /etc/gshadow,
run the command:
$ ls -lL /etc/gshadow
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/gshadow does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_etc_ipsec_conf_question:question:1">
          <ocil:question_text>To check the ownership of /etc/ipsec.conf,
run the command:
$ ls -lL /etc/ipsec.conf
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/ipsec.conf does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_etc_ipsec_secrets_question:question:1">
          <ocil:question_text>To check the ownership of /etc/ipsec.secrets,
run the command:
$ ls -lL /etc/ipsec.secrets
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/ipsec.secrets does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_etc_issue_question:question:1">
          <ocil:question_text>To check the ownership of /etc/issue,
run the command:
$ ls -lL /etc/issue
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/issue does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_etc_issue_net_question:question:1">
          <ocil:question_text>To check the ownership of /etc/issue.net,
run the command:
$ ls -lL /etc/issue.net
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/issue.net does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_etc_motd_question:question:1">
          <ocil:question_text>To check the ownership of /etc/motd,
run the command:
$ ls -lL /etc/motd
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/motd does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_etc_passwd_question:question:1">
          <ocil:question_text>To check the ownership of /etc/passwd,
run the command:
$ ls -lL /etc/passwd
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/passwd does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_etc_security_opasswd_question:question:1">
          <ocil:question_text>To check the ownership of /etc/security/opasswd,
run the command:
$ ls -lL /etc/security/opasswd
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/security/opasswd does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_etc_security_opasswd_old_question:question:1">
          <ocil:question_text>To check the ownership of /etc/security/opasswd.old,
run the command:
$ ls -lL /etc/security/opasswd.old
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/security/opasswd.old does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_etc_sestatus_conf_question:question:1">
          <ocil:question_text>To check the ownership of /etc/sestatus.conf,
run the command:
$ ls -lL /etc/sestatus.conf
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/sestatus.conf does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_etc_shadow_question:question:1">
          <ocil:question_text>To check the ownership of /etc/shadow,
run the command:
$ ls -lL /etc/shadow
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/shadow does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_etc_shells_question:question:1">
          <ocil:question_text>To check the ownership of /etc/shells,
run the command:
$ ls -lL /etc/shells
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/shells does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_etc_sudoers_question:question:1">
          <ocil:question_text>To check the ownership of /etc/sudoers,
run the command:
$ ls -lL /etc/sudoers
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/sudoers does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_etc_sysconfig_sshd_question:question:1">
          <ocil:question_text>To check the ownership of /etc/sysconfig/sshd,
run the command:
$ ls -lL /etc/sysconfig/sshd
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/sysconfig/sshd does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_grub2_cfg_question:question:1">
          <ocil:question_text>To check the ownership of /boot/grub2/grub.cfg,
run the command:
$ ls -lL /boot/grub2/grub.cfg
If properly configured, the output should indicate the following owner:
root
      Is it the case that /boot/grub2/grub.cfg does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_sshd_config_question:question:1">
          <ocil:question_text>To check the ownership of /etc/ssh/sshd_config,
run the command:
$ ls -lL /etc/ssh/sshd_config
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/ssh/sshd_config does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_systemmap_question:question:1">
          <ocil:question_text>To check the ownership of /boot/System.map*,
run the command:
$ ls -lL /boot/System.map*
If properly configured, the output should indicate the following owner:
root
      Is it the case that /boot/System.map* does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_user_cfg_question:question:1">
          <ocil:question_text>To check the ownership of /boot/grub2/user.cfg,
run the command:
$ ls -lL /boot/grub2/user.cfg
If properly configured, the output should indicate the following owner:
root
      Is it the case that /boot/grub2/user.cfg does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_var_log_question:question:1">
          <ocil:question_text>To check the ownership of /var/log,
run the command:
$ ls -lL /var/log
If properly configured, the output should indicate the following owner:
root
      Is it the case that /var/log does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_var_log_messages_question:question:1">
          <ocil:question_text>To check the ownership of /var/log/messages,
run the command:
$ ls -lL /var/log/messages
If properly configured, the output should indicate the following owner:
root
      Is it the case that /var/log/messages does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_owner_var_log_syslog_question:question:1">
          <ocil:question_text>To check the ownership of /var/log/syslog,
run the command:
$ ls -lL /var/log/syslog
If properly configured, the output should indicate the following owner:
syslog
      Is it the case that /var/log/syslog does not have an owner of syslog?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_ownership_audit_binaries_question:question:1">
          <ocil:question_text>Verify it by running the following command:
$ stat -c "%n %U" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd /sbin/augenrules

/sbin/auditctl root

/sbin/aureport root

/sbin/ausearch root

/sbin/autrace root

/sbin/auditd root

/sbin/audispd root

/sbin/augenrules root


If the command does not return all the above lines, the missing ones
need to be added.

Run the following command to correct the permissions of the missing
entries:
$ sudo chown root [audit_tool] 

Replace "[audit_tool]" with each audit tool not owned by root.
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_ownership_audit_configuration_question:question:1">
          <ocil:question_text>To properly set the owner of /etc/audit/, run the command:

  $ sudo chown root /etc/audit/ 
  

To properly set the owner of /etc/audit/rules.d/, run the command:

  $ sudo chown root /etc/audit/rules.d/ 
  
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_ownership_binary_dirs_question:question:1">
          <ocil:question_text>Verify the system commands contained in the following directories are owned by "root" with the following command:

$ sudo find -L /bin /sbin /usr/bin /usr/sbin /usr/libexec /usr/local/bin /usr/local/sbin ! -user root -exec ls -l {} \;
      Is it the case that any system commands are found to not be owned by root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_ownership_home_directories_question:question:1">
          <ocil:question_text>To verify the home directory ownership, run the following command:
# ls -ld $(awk -F: '($3&gt;=1000)&amp;&amp;($7 !~ /nologin/){print $6}' /etc/passwd)
      Is it the case that the user ownership is incorrect?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_ownership_library_dirs_question:question:1">
          <ocil:question_text>Verify the system-wide shared library files are owned by "root" with the following command:

$ sudo find -L /lib /lib64 /usr/lib /usr/lib64 ! -user root -exec ls -l {} \;
      Is it the case that any system wide shared library file is not owned by root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_ownership_sshd_private_key_question:question:1">
          <ocil:question_text>To check the ownership of /etc/ssh/*_key,
run the command:
$ ls -lL /etc/ssh/*_key
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/ssh/*_key does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_ownership_sshd_pub_key_question:question:1">
          <ocil:question_text>To check the ownership of /etc/ssh/*.pub,
run the command:
$ ls -lL /etc/ssh/*.pub
If properly configured, the output should indicate the following owner:
root
      Is it the case that /etc/ssh/*.pub does not have an owner of root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_ownership_var_log_audit_question:question:1">
          <ocil:question_text>To properly set the owner of /var/log/audit, run the command:

  $ sudo chown root /var/log/audit 
  

To properly set the owner of /var/log/audit/*, run the command:

  $ sudo chown root /var/log/audit/* 
  
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_ownership_var_log_audit_stig_question:question:1">
          <ocil:question_text>Verify the audit logs are owned by "root". First, determine where the audit logs are stored with the following command:
$ sudo grep -iw log_file /etc/audit/auditd.conf
log_file = /var/log/audit/audit.log
Using the location of the audit log file, determine if the audit log is owned by "root" using the following command:
$ sudo stat -c "%n %U" /var/log/audit/audit.log
Audit logs must be owned by user root.
If the log_file isn't defined in /etc/audit/auditd.conf, check all files in /var/log/audit/ directory instead.
      Is it the case that the audit log is not owned by root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permission_user_bash_history_question:question:1">
          <ocil:question_text>To verify that .bash_history has a mode of 0600 or
less permissive, run the following command:
$ sudo find /home -type f -name '\.bash_history' -perm /0177
There should be no output.
      Is it the case that file is not 0600 or more permissive?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permission_user_init_files_question:question:1">
          <ocil:question_text>To verify that all user initialization files have a mode of 0740 or
less permissive, run the following command:
$ sudo find /home -type f -name '\.*' \( -perm -0002 -o -perm -0020 \)
There should be no output.
      Is it the case that they are not 0740 or more permissive?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permission_user_init_files_root_question:question:1">
          <ocil:question_text>To verify that all user initialization files have a mode of 0740 or
less permissive, run the following command:
$ sudo find /home -type f -name '\.*' \( -perm -0002 -o -perm -0020 \)
There should be no output.
      Is it the case that they are not 0740 or more permissive?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_at_allow_question:question:1">
          <ocil:question_text>To check the permissions of /etc/at.allow,
run the command:
$ ls -l /etc/at.allow
If properly configured, the output should indicate the following permissions:
-rw-r-----
      Is it the case that /etc/at.allow does not have unix mode -rw-r-----?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_audit_binaries_question:question:1">
          <ocil:question_text>Verify it by running the following command:
$ stat -c "%n %a" /sbin/auditctl /sbin/aureport /sbin/ausearch /sbin/autrace /sbin/auditd /sbin/audispd /sbin/augenrules

/sbin/auditctl 755

/sbin/aureport 755

/sbin/ausearch 755

/sbin/autrace 755

/sbin/auditd 755

/sbin/audispd 755

/sbin/augenrules 755


If the command does not return all the above lines, the missing ones
need to be added.

Run the following command to correct the permissions of the missing
entries:
$ sudo chmod 0755 [audit_tool] 

Replace "[audit_tool]" with the audit tool that does not have the
correct permissions.
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_audit_configuration_question:question:1">
          <ocil:question_text>To properly set the permissions of /etc/audit/, run the command:
$ sudo chmod 0640 /etc/audit/
To properly set the permissions of /etc/audit/rules.d/, run the command:
$ sudo chmod 0640 /etc/audit/rules.d/
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_backup_etc_group_question:question:1">
          <ocil:question_text>To check the permissions of /etc/group-,
run the command:
$ ls -l /etc/group-
If properly configured, the output should indicate the following permissions:
-rw-r--r--
      Is it the case that /etc/group- does not have unix mode -rw-r--r--?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_backup_etc_gshadow_question:question:1">
          <ocil:question_text>To check the permissions of /etc/gshadow-,
run the command:
$ ls -l /etc/gshadow-
If properly configured, the output should indicate the following permissions:
----------
      Is it the case that /etc/gshadow- does not have unix mode ----------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_backup_etc_passwd_question:question:1">
          <ocil:question_text>To check the permissions of /etc/passwd-,
run the command:
$ ls -l /etc/passwd-
If properly configured, the output should indicate the following permissions:
-rw-r--r--
      Is it the case that /etc/passwd- does not have unix mode -rw-r--r--?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_backup_etc_shadow_question:question:1">
          <ocil:question_text>To check the permissions of /etc/shadow-,
run the command:
$ ls -l /etc/shadow-
If properly configured, the output should indicate the following permissions:
----------
      Is it the case that /etc/shadow- does not have unix mode ----------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_binary_dirs_question:question:1">
          <ocil:question_text>Verify the system commands contained in the following directories have mode "755" or less permissive with the following command:

$ sudo find -L /bin /sbin /usr/bin /usr/sbin /usr/libexec /usr/local/bin /usr/local/sbin -perm /022 -exec ls -l {} \;
      Is it the case that any system commands are found to be group-writable or world-writable?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_cron_allow_question:question:1">
          <ocil:question_text>To check the permissions of /etc/cron.allow,
run the command:
$ ls -l /etc/cron.allow
If properly configured, the output should indicate the following permissions:
-rw-r-----
      Is it the case that /etc/cron.allow does not have unix mode -rw-r-----?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_cron_d_question:question:1">
          <ocil:question_text>To check the permissions of /etc/cron.d,
run the command:
$ ls -l /etc/cron.d
If properly configured, the output should indicate the following permissions:
-rwx------
      Is it the case that /etc/cron.d does not have unix mode -rwx------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_cron_daily_question:question:1">
          <ocil:question_text>To check the permissions of /etc/cron.daily,
run the command:
$ ls -l /etc/cron.daily
If properly configured, the output should indicate the following permissions:
-rwx------
      Is it the case that /etc/cron.daily does not have unix mode -rwx------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_cron_hourly_question:question:1">
          <ocil:question_text>To check the permissions of /etc/cron.hourly,
run the command:
$ ls -l /etc/cron.hourly
If properly configured, the output should indicate the following permissions:
-rwx------
      Is it the case that /etc/cron.hourly does not have unix mode -rwx------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_cron_monthly_question:question:1">
          <ocil:question_text>To check the permissions of /etc/cron.monthly,
run the command:
$ ls -l /etc/cron.monthly
If properly configured, the output should indicate the following permissions:
-rwx------
      Is it the case that /etc/cron.monthly does not have unix mode -rwx------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_cron_weekly_question:question:1">
          <ocil:question_text>To check the permissions of /etc/cron.weekly,
run the command:
$ ls -l /etc/cron.weekly
If properly configured, the output should indicate the following permissions:
-rwx------
      Is it the case that /etc/cron.weekly does not have unix mode -rwx------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_cron_yearly_question:question:1">
          <ocil:question_text>To check the permissions of /etc/cron.yearly,
run the command:
$ ls -l /etc/cron.yearly
If properly configured, the output should indicate the following permissions:
-rwx------
      Is it the case that /etc/cron.yearly does not have unix mode -rwx------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_crontab_question:question:1">
          <ocil:question_text>To check the permissions of /etc/crontab,
run the command:
$ ls -l /etc/crontab
If properly configured, the output should indicate the following permissions:
-rw-------
      Is it the case that /etc/crontab does not have unix mode -rw-------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_efi_grub2_cfg_question:question:1">
          <ocil:question_text>To check the permissions of /boot/efi/EFI/almalinux/grub.cfg, run the command:
$ sudo ls -lL /boot/efi/EFI/almalinux/grub.cfg
If properly configured, the output should indicate the following
permissions: -rwx------
      Is it the case that it does not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_efi_user_cfg_question:question:1">
          <ocil:question_text>To check the permissions of /boot/efi/EFI/almalinux/user.cfg,
run the command:
$ ls -l /boot/efi/EFI/almalinux/user.cfg
If properly configured, the output should indicate the following permissions:
-rw-------
      Is it the case that /boot/efi/EFI/almalinux/user.cfg does not have unix mode -rw-------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_audit_auditd_question:question:1">
          <ocil:question_text>To check the permissions of /etc/audit/auditd.conf,
run the command:
$ ls -l /etc/audit/auditd.conf
If properly configured, the output should indicate the following permissions:
-rw-r-----
      Is it the case that /etc/audit/auditd.conf does not have unix mode -rw-r-----?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_audit_rulesd_question:question:1">
          <ocil:question_text>To check the permissions of /etc/audit/rules.d/*.rules,
run the command:
$ ls -l /etc/audit/rules.d/*.rules
If properly configured, the output should indicate the following permissions:
-rw-------
      Is it the case that /etc/audit/rules.d/*.rules does not have unix mode -rw-------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_chrony_keys_question:question:1">
          <ocil:question_text>To check the permissions of /etc/chrony.keys,
run the command:
$ ls -l /etc/chrony.keys
If properly configured, the output should indicate the following permissions:
0640
      Is it the case that /etc/chrony.keys does not have unix mode 0640?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_crypttab_question:question:1">
          <ocil:question_text>To check the permissions of /etc/crypttab,
run the command:
$ ls -l /etc/crypttab
If properly configured, the output should indicate the following permissions:
0600
      Is it the case that /etc/crypttab does not have unix mode 0600?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_group_question:question:1">
          <ocil:question_text>To check the permissions of /etc/group,
run the command:
$ ls -l /etc/group
If properly configured, the output should indicate the following permissions:
-rw-r--r--
      Is it the case that /etc/group does not have unix mode -rw-r--r--?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_gshadow_question:question:1">
          <ocil:question_text>To check the permissions of /etc/gshadow,
run the command:
$ ls -l /etc/gshadow
If properly configured, the output should indicate the following permissions:
----------
      Is it the case that /etc/gshadow does not have unix mode ----------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_ipsec_conf_question:question:1">
          <ocil:question_text>To check the permissions of /etc/ipsec.conf,
run the command:
$ ls -l /etc/ipsec.conf
If properly configured, the output should indicate the following permissions:
0644
      Is it the case that /etc/ipsec.conf does not have unix mode 0644?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_ipsec_secrets_question:question:1">
          <ocil:question_text>To check the permissions of /etc/ipsec.secrets,
run the command:
$ ls -l /etc/ipsec.secrets
If properly configured, the output should indicate the following permissions:
0644
      Is it the case that /etc/ipsec.secrets does not have unix mode 0644?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_issue_question:question:1">
          <ocil:question_text>To check the permissions of /etc/issue,
run the command:
$ ls -l /etc/issue
If properly configured, the output should indicate the following permissions:
-rw-r--r--
      Is it the case that /etc/issue does not have unix mode -rw-r--r--?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_issue_net_question:question:1">
          <ocil:question_text>To check the permissions of /etc/issue.net,
run the command:
$ ls -l /etc/issue.net
If properly configured, the output should indicate the following permissions:
-rw-r--r--
      Is it the case that /etc/issue.net does not have unix mode -rw-r--r--?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_motd_question:question:1">
          <ocil:question_text>To check the permissions of /etc/motd,
run the command:
$ ls -l /etc/motd
If properly configured, the output should indicate the following permissions:
-rw-r--r--
      Is it the case that /etc/motd does not have unix mode -rw-r--r--?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_passwd_question:question:1">
          <ocil:question_text>To check the permissions of /etc/passwd,
run the command:
$ ls -l /etc/passwd
If properly configured, the output should indicate the following permissions:
-rw-r--r--
      Is it the case that /etc/passwd does not have unix mode -rw-r--r--?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_security_opasswd_question:question:1">
          <ocil:question_text>To check the permissions of /etc/security/opasswd,
run the command:
$ ls -l /etc/security/opasswd
If properly configured, the output should indicate the following permissions:
0600
      Is it the case that /etc/security/opasswd does not have unix mode 0600?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_security_opasswd_old_question:question:1">
          <ocil:question_text>To check the permissions of /etc/security/opasswd.old,
run the command:
$ ls -l /etc/security/opasswd.old
If properly configured, the output should indicate the following permissions:
0600
      Is it the case that /etc/security/opasswd.old does not have unix mode 0600?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_sestatus_conf_question:question:1">
          <ocil:question_text>To check the permissions of /etc/sestatus.conf,
run the command:
$ ls -l /etc/sestatus.conf
If properly configured, the output should indicate the following permissions:
0644
      Is it the case that /etc/sestatus.conf does not have unix mode 0644?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_shadow_question:question:1">
          <ocil:question_text>To check the permissions of /etc/shadow,
run the command:
$ ls -l /etc/shadow
If properly configured, the output should indicate the following permissions:
----------
      Is it the case that /etc/shadow does not have unix mode ----------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_shells_question:question:1">
          <ocil:question_text>To check the permissions of /etc/shells,
run the command:
$ ls -l /etc/shells
If properly configured, the output should indicate the following permissions:
0644
      Is it the case that /etc/shells does not have unix mode 0644?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_sudoers_question:question:1">
          <ocil:question_text>To check the permissions of /etc/sudoers,
run the command:
$ ls -l /etc/sudoers
If properly configured, the output should indicate the following permissions:
0440
      Is it the case that /etc/sudoers does not have unix mode 0440?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_etc_sysconfig_sshd_question:question:1">
          <ocil:question_text>To check the permissions of /etc/sysconfig/sshd,
run the command:
$ ls -l /etc/sysconfig/sshd
If properly configured, the output should indicate the following permissions:
-rw-r-----
      Is it the case that /etc/sysconfig/sshd does not have unix mode -rw-r-----?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_grub2_cfg_question:question:1">
          <ocil:question_text>To check the permissions of /boot/grub2/grub.cfg, run the command:
$ sudo ls -lL /boot/grub2/grub.cfg
If properly configured, the output should indicate the following
permissions: -rw-------
      Is it the case that it does not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_home_directories_question:question:1">
          <ocil:question_text>To verify the assigned home directory of all interactive user home directories
have a mode of 0750 or less permissive, run the following command:
$ sudo ls -l /home
Inspect the output for any directories with incorrect permissions.
      Is it the case that they are more permissive?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_home_dirs_question:question:1">
          <ocil:question_text>To ensure the user home directory is not group-writable or world-readable, run the following:
# ls -ld /home/USER
      Is it the case that the user home directory is group-writable or world-readable?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_httpd_server_conf_d_files_question:question:1">
          <ocil:question_text>To check the permissions of /etc/http/conf.d/*,
run the command:
$ ls -l /etc/http/conf.d/*
If properly configured, the output should indicate the following permissions:
-rw-r-----
      Is it the case that /etc/http/conf.d/* does not have unix mode -rw-r-----?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_httpd_server_conf_files_question:question:1">
          <ocil:question_text>To check the permissions of /etc/http/conf/*,
run the command:
$ ls -l /etc/http/conf/*
If properly configured, the output should indicate the following permissions:
-rw-r-----
      Is it the case that /etc/http/conf/* does not have unix mode -rw-r-----?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_httpd_server_modules_files_question:question:1">
          <ocil:question_text>To check the permissions of /etc/http/conf.modules.d/*,
run the command:
$ ls -l /etc/http/conf.modules.d/*
If properly configured, the output should indicate the following permissions:
-rw-r-----
      Is it the case that /etc/http/conf.modules.d/* does not have unix mode -rw-r-----?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_library_dirs_question:question:1">
          <ocil:question_text>Verify the system-wide shared library files contained in the following directories have mode "755" or less permissive with the following command:

$ sudo find -L /lib /lib64 /usr/lib /usr/lib64 -perm /022 -type f -exec ls -l {} \;
      Is it the case that any system-wide shared library file is found to be group-writable or world-writable?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_sshd_config_question:question:1">
          <ocil:question_text>To check the permissions of /etc/ssh/sshd_config,
run the command:
$ ls -l /etc/ssh/sshd_config
If properly configured, the output should indicate the following permissions:
-rw-------
      Is it the case that /etc/ssh/sshd_config does not have unix mode -rw-------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_sshd_private_key_question:question:1">
          <ocil:question_text>To check the permissions of /etc/ssh/*_key,
run the command:
$ ls -l /etc/ssh/*_key
If properly configured, the output should indicate the following permissions:
-rw-------
      Is it the case that /etc/ssh/*_key does not have unix mode -rw-------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_sshd_pub_key_question:question:1">
          <ocil:question_text>To check the permissions of /etc/ssh/*.pub,
run the command:
$ ls -l /etc/ssh/*.pub
If properly configured, the output should indicate the following permissions:
-rw-r--r--
      Is it the case that /etc/ssh/*.pub does not have unix mode -rw-r--r--?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_systemmap_question:question:1">
          <ocil:question_text>To check the permissions of /boot/System.map*,
run the command:
$ ls -l /boot/System.map*
If properly configured, the output should indicate the following permissions:
-rw-------
      Is it the case that /boot/System.map* does not have unix mode -rw-------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_unauthorized_sgid_question:question:1">
          <ocil:question_text>To find SGID files, run the following command:
$ sudo find / -xdev -type f -perm -2000
      Is it the case that there is output?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_unauthorized_suid_question:question:1">
          <ocil:question_text>To find SUID files, run the following command:
$ sudo find / -xdev -type f -perm -4000
      Is it the case that only authorized files appear in the output of the find command?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_unauthorized_world_writable_question:question:1">
          <ocil:question_text>To find world-writable files, run the following command:
$ sudo find / -xdev -type f -perm -002
      Is it the case that there is output?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_ungroupowned_question:question:1">
          <ocil:question_text>The following command will locate the mount points related to local devices:
$ findmnt -n -l -k -it $(awk '/nodev/ { print $2 }' /proc/filesystems | paste -sd,)

The following command will show files which do not belong to a valid group:
$ sudo find MOUNTPOINT -xdev -nogroup 2&gt;/dev/null

Replace MOUNTPOINT by the mount points listed by the fist command.

No files without a valid group should be located.
      Is it the case that there is output?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_user_cfg_question:question:1">
          <ocil:question_text>To check the permissions of /boot/grub2/user.cfg,
run the command:
$ ls -l /boot/grub2/user.cfg
If properly configured, the output should indicate the following permissions:
-rw-------
      Is it the case that /boot/grub2/user.cfg does not have unix mode -rw-------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_var_log_question:question:1">
          <ocil:question_text>To check the permissions of /var/log,
run the command:
$ ls -l /var/log
If properly configured, the output should indicate the following permissions:
drwxr-xr-x
      Is it the case that /var/log does not have unix mode drwxr-xr-x?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_var_log_audit_question:question:1">
          <ocil:question_text>Run the following command to check the mode of the system audit logs:
$ sudo grep -iw log_file /etc/audit/auditd.conf
log_file=/var/log/audit/audit.log
$ sudo stat -c "%n %a" /var/log/audit/*
$ sudo ls -l /var/log/audit
Audit logs must be mode 0640 or less permissive.
      Is it the case that any permissions are more permissive?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_var_log_messages_question:question:1">
          <ocil:question_text>To check the permissions of /var/log/messages,
run the command:
$ ls -l /var/log/messages
If properly configured, the output should indicate the following permissions:
-rw-------
      Is it the case that /var/log/messages does not have unix mode -rw-------?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-file_permissions_var_log_syslog_question:question:1">
          <ocil:question_text>To check the permissions of /var/log/syslog,
run the command:
$ ls -l /var/log/syslog
If properly configured, the output should indicate the following permissions:
-rw-r-----
      Is it the case that /var/log/syslog does not have unix mode -rw-r-----?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-fips_crypto_subpolicy_question:question:1">
          <ocil:question_text>Show the configured systemwide cryptographic policy by running the following command:

$ sudo update-crypto-policies --show
FIPS
      Is it the case that using an insecure sub-policy?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-fips_custom_stig_sub_policy_question:question:1">
          <ocil:question_text>Verify that /etc/crypto-policies/policies/modules/STIG.pmod exists and has the following content:

cipher@SSH=AES-256-GCM AES-256-CTR AES-128-GCM AES-128-CTR
mac@SSH=HMAC-SHA2-512 HMAC-SHA2-256

      Is it the case that the STIG subpolicy does not exist?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firewalld-backend_question:question:1">
          <ocil:question_text>Verify "nftables" is configured to allow rate limits on any connection to the system with the following command:

Verify "firewalld" has "nftables" set as the default backend:

$ sudo grep -i firewallbackend /etc/firewalld/firewalld.conf

# FirewallBackend
FirewallBackend=nftables
      Is it the case that the "nftables" is not set as the "firewallbackend"?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firewalld_loopback_traffic_restricted_question:question:1">
          <ocil:question_text>Inspect the firewalld trusted and default zones and verify the loopback traffic is restricted
to the lo interface by running the following command:

$ sudo firewall-cmd --list-rich-rules --zone=trusted

The following rich-rules should be listed:

rule family="ipv4" source address="127.0.0.1" destination not address="127.0.0.1" drop
rule family="ipv6" source address="::1" destination not address="127.0.0.1" drop

      Is it the case that loopback traffic is not restricted?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firewalld_loopback_traffic_trusted_question:question:1">
          <ocil:question_text>Inspect the network interfaces assigned to the firewalld trusted zone and verify the
lo interface is listed by running the following command:

$ sudo firewall-cmd --list-interfaces --zone=trusted
      Is it the case that loopback traffic is not trusted?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-firewalld_sshd_port_enabled_question:question:1">
          <ocil:question_text>


To determine if firewalld is configured to allow access

on port 22/tcp, run the following command(s):
    firewall-cmd --list-ports


to ssh
    firewall-cmd --list-services

If firewalld is configured to allow access through the firewall, something similar to the following will be output:

If it is a service:
ssh


If it is a port:
22/tcp

      Is it the case that sshd service is not enabled in the proper firewalld zone?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-force_opensc_card_drivers_question:question:1">
          <ocil:question_text>To verify that  is configured
as the smart card driver, run the following command:
$ grep force_card_driver /etc/opensc.conf
The output should return something similar to:
force_card_driver = ;
      Is it the case that the smart card driver is not configured correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ftp_log_transactions_question:question:1">
          <ocil:question_text>Find if logging is applied to the FTP daemon.

Procedures:

If vsftpd is started by xinetd the following command will indicate the xinetd.d startup file:
$ grep vsftpd /etc/xinetd.d/*
$ grep server_args vsftpd xinetd.d startup file
This will indicate the vsftpd config file used when starting through xinetd.
If the server_args line is missing or does not include the vsftpd configuration file, then the default config file (/etc/vsftpd/vsftpd.conf) is used.
$ sudo grep xferlog_enable vsftpd config file
      Is it the case that xferlog_enable is missing, or is not set to yes?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ftp_present_banner_question:question:1">
          <ocil:question_text>If FTP services are not installed, this is not applicable.

To verify this configuration, run the following command:

grep "banner_file" /etc/vsftpd/vsftpd.conf


The output should show the value of banner_file is set to /etc/issue, an example of which is shown below:

$ sudo grep "banner_file" /etc/vsftpd/vsftpd.conf

banner_file=/etc/issue
      Is it the case that it does not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-gid_passwd_group_same_question:question:1">
          <ocil:question_text>To ensure all GIDs referenced in /etc/passwd are defined in /etc/group,
run the following command:
$ sudo pwck -qr
There should be no output.
      Is it the case that GIDs referenced in /etc/passwd are returned as not defined in /etc/group?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-gnome_gdm_disable_automatic_login_question:question:1">
          <ocil:question_text>To verify that automatic logins are disabled, run the following command:
$ grep -Pzoi "^\[daemon]\\nautomaticlogin.*" /etc/gdm/custom.conf
The output should show the following:
[daemon]
AutomaticLoginEnable=false
      Is it the case that GDM allows users to automatically login?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-gnome_gdm_disable_guest_login_question:question:1">
          <ocil:question_text>To verify that timed logins are disabled, run the following command:
$ grep -Pzoi "^\[daemon]\\ntimedlogin.*" /etc/gdm/custom.conf
The output should show the following:
[daemon]
TimedLoginEnable=false
      Is it the case that GDM allows a guest to login without credentials?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-gnome_gdm_disable_xdmcp_question:question:1">
          <ocil:question_text>To ensure that XDMCP is disabled in /etc/gdm/custom.conf, run the following command:
grep -Pzo "\[xdmcp\]\nEnable=false" /etc/gdm/custom.conf
The output should return the following:

[xdmcp]
Enable=false

      Is it the case that the Enable is not set to false or is missing in the xdmcp section of the /etc/gdm/custom.conf gdm configuration file?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-group_unique_id_question:question:1">
          <ocil:question_text>Run the following command to check for duplicate group names:
Check that the operating system contains no duplicate Group ID (GID) for interactive users by running the following command:

    cut -d : -f 3 /etc/group | uniq -d

If output is produced, this is a finding.
Configure the operating system to contain no duplicate GIDs.
Edit the file "/etc/group" and provide each group that has a duplicate GID with a unique GID.
      Is it the case that the system has duplicate group ids?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-group_unique_name_question:question:1">
          <ocil:question_text>Run the following command to check for duplicate group names:
Check that the operating system contains no duplicate group names for interactive users by running the following command:

    cut -d : -f 1 /etc/group | uniq -d

If output is produced, this is a finding.
Configure the operating system to contain no duplicate names for groups.
Edit the file "/etc/group" and provide each group that has a duplicate group name with a unique group name.
      Is it the case that has duplicate group names?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-groups_no_zero_gid_except_root_question:question:1">
          <ocil:question_text>Verify that only the "root" group has a GID "0" assignment with the
following command:
$ awk -F: '$3 == 0 {print $1}' /etc/group
root
      Is it the case that any groups other than "root" have a GID of "0"?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_admin_username_question:question:1">
          <ocil:question_text>To verify the boot loader superuser account has been set, run the following
command:
sudo grep -A1 "superusers" /boot/grub2/grub.cfg
The output should show the following:
set superusers="superusers-account"
export superusers
where superusers-account is the actual account name different from common names like root,
admin, or administrator and different from any other existing user name.
      Is it the case that superuser account is not set or is set to root, admin, administrator or any other existing user name?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_audit_argument_question:question:1">
          <ocil:question_text>Inspect the form of default GRUB 2 command line for the Linux operating system
in grubenv that can be found either in /boot/grub2 in case of legacy BIOS systems, or in /boot/efi/EFI/almalinux in case of UEFI systems.
If they include audit=1, then the parameter
is configured at boot time.
$ sudo grep 'kernelopts.*audit=1.*' GRUBENV_FILE_LOCATION
Fill in GRUBENV_FILE_LOCATION based on information above.
      Is it the case that auditing is not enabled at boot time?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_audit_backlog_limit_argument_question:question:1">
          <ocil:question_text>Inspect the form of default GRUB 2 command line for the Linux operating system
in grubenv that can be found either in /boot/grub2 in case of legacy BIOS systems, or in /boot/efi/EFI/almalinux in case of UEFI systems.
If they include audit_backlog_limit=, then the parameter
is configured at boot time.
$ sudo grep 'kernelopts.*audit_backlog_limit=.*' GRUBENV_FILE_LOCATION
Fill in GRUBENV_FILE_LOCATION based on information above.
      Is it the case that audit backlog limit is not configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_disable_interactive_boot_question:question:1">
          <ocil:question_text>Inspect /etc/default/grub for any instances of
systemd.confirm_spawn=(1|yes|true|on) in the kernel boot arguments.
Presence of a systemd.confirm_spawn=(1|yes|true|on) indicates
that interactive boot is enabled at boot time and verify that
GRUB_DISABLE_RECOVERY=true to disable recovery boot.
      Is it the case that Interactive boot is enabled at boot time?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_disable_recovery_question:question:1">
          <ocil:question_text>Verify that GRUB_DISABLE_RECOVERY is set to true in /etc/default/grub to disable recovery boot.
Run the following command:

$ sudo grep GRUB_DISABLE_RECOVERY /etc/default/grub
      Is it the case that GRUB_DISABLE_RECOVERY is not set to true or is missing?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_enable_iommu_force_question:question:1">
          <ocil:question_text>Inspect the form of default GRUB 2 command line for the Linux operating system
in grubenv that can be found either in /boot/grub2 in case of legacy BIOS systems, or in /boot/efi/EFI/almalinux in case of UEFI systems.
If they include iommu=force, then the parameter
is configured at boot time.
$ sudo grep 'kernelopts.*iommu=force.*' GRUBENV_FILE_LOCATION
Fill in GRUBENV_FILE_LOCATION based on information above.
      Is it the case that I/OMMU is not activated?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_enable_selinux_question:question:1">
          <ocil:question_text>Inspect /etc/default/grub for any instances of selinux=0
in the kernel boot arguments.  Presence of selinux=0 indicates
that SELinux is disabled at boot time.
      Is it the case that SELinux is disabled at boot time?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_ipv6_disable_argument_question:question:1">
          <ocil:question_text>Inspect the form of default GRUB 2 command line for the Linux operating system
in grubenv that can be found either in /boot/grub2 in case of legacy BIOS systems, or in /boot/efi/EFI/almalinux in case of UEFI systems.
If they include ipv6.disable=1, then the parameter
is configured at boot time.
$ sudo grep 'kernelopts.*ipv6.disable=1.*' GRUBENV_FILE_LOCATION
Fill in GRUBENV_FILE_LOCATION based on information above.
      Is it the case that IPv6 is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_kernel_trust_cpu_rng_question:question:1">
          <ocil:question_text>Make sure that the kernel is configured to trust the CPU RNG by following
commands. To check if the option was correctly configured at kernel compile
time, run the following command:
grep -q CONFIG_RANDOM_TRUST_CPU=y /boot/config-`uname -r`
If the command outputs:
CONFIG_RANDOM_TRUST_CPU=y,
it means that the option is compiled into the kernel. Make sure that the
option is not overridden through a boot parameter:
sudo grep 'kernelopts.*random\.trust_cpu=off.*' /boot/grub2/grubenv
The command should not return any output. If the option is not compiled into
the kernel, check that the option is configured through boot parameter.
Inspect the form of default GRUB 2 command line for the Linux operating system
in grubenv that can be found either in /boot/grub2 in case of legacy BIOS systems, or in /boot/efi/EFI/almalinux in case of UEFI systems.
If they include random.trust_cpu=on, then the parameter
is configured at boot time.
$ sudo grep 'kernelopts.*random.trust_cpu=on.*' GRUBENV_FILE_LOCATION
Fill in GRUBENV_FILE_LOCATION based on information above.
      Is it the case that the kernel is not configured to trust the CPU RNG?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_l1tf_argument_question:question:1">
          <ocil:question_text>Inspect the form of default GRUB 2 command line for the Linux operating system
in grubenv that can be found either in /boot/grub2 in case of legacy BIOS systems, or in /boot/efi/EFI/almalinux in case of UEFI systems.
If they include l1tf=, then the parameter
is configured at boot time.
$ sudo grep 'kernelopts.*l1tf=.*' GRUBENV_FILE_LOCATION
Fill in GRUBENV_FILE_LOCATION based on information above.
      Is it the case that l1tf mitigations are not configured appropriately?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_mce_argument_question:question:1">
          <ocil:question_text>Inspect the form of default GRUB 2 command line for the Linux operating system
in grubenv that can be found either in /boot/grub2 in case of legacy BIOS systems, or in /boot/efi/EFI/almalinux in case of UEFI systems.
If they include mce=0, then the parameter
is configured at boot time.
$ sudo grep 'kernelopts.*mce=0.*' GRUBENV_FILE_LOCATION
Fill in GRUBENV_FILE_LOCATION based on information above.
      Is it the case that MCE tolerance is not set to zero?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_no_removeable_media_question:question:1">
          <ocil:question_text>To verify the system is not configured to use a boot loader on removable media,
check that the grub configuration file has the set root command in each menu
entry with the following commands:
$ sudo grep -cw menuentry /boot/grub2/grub.cfg
Note that the -c option for the grep command will print
only the count of menuentry occurrences. This number should match
the number of occurrences reported by the following command:
$ sudo grep "set root='hd0" /boot/grub2/grub.cfg
The output should return something similar to:
set root='hd0,msdos1'
usb0, cd, fd0, etc. are some examples of removable
media which should not exist in the lines:
set root='hd0,msdos1'
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_nosmap_argument_absent_question:question:1">
          <ocil:question_text>Make sure that the kernel is not disabling SMAP with the following
commands.
grep -q nosmap /boot/config-`uname -r`
If the command returns a line, it means that SMAP is being disabled.
      Is it the case that the kernel is configured to disable SMAP?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_nosmep_argument_absent_question:question:1">
          <ocil:question_text>Make sure that the kernel is not disabling SMEP with the following
commands.
grep -q nosmep /boot/config-`uname -r`
If the command returns a line, it means that SMEP is being disabled.
      Is it the case that the kernel is configured to disable SMEP?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_nousb_argument_question:question:1">
          <ocil:question_text>Inspect the form of default GRUB 2 command line for the Linux operating system
in grubenv that can be found either in /boot/grub2 in case of legacy BIOS systems, or in /boot/efi/EFI/almalinux in case of UEFI systems.
If they include nousb, then the parameter
is configured at boot time.
$ sudo grep 'kernelopts.*nousb.*' GRUBENV_FILE_LOCATION
Fill in GRUBENV_FILE_LOCATION based on information above.
      Is it the case that usb is enabled at boot time?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_page_poison_argument_question:question:1">
          <ocil:question_text>Inspect the form of default GRUB 2 command line for the Linux operating system
in grubenv that can be found either in /boot/grub2 in case of legacy BIOS systems, or in /boot/efi/EFI/almalinux in case of UEFI systems.
If they include page_poison=1, then the parameter
is configured at boot time.
$ sudo grep 'kernelopts.*page_poison=1.*' GRUBENV_FILE_LOCATION
Fill in GRUBENV_FILE_LOCATION based on information above.
      Is it the case that page allocator poisoning is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_password_question:question:1">
          <ocil:question_text>First, check whether the password is defined in either /boot/grub2/user.cfg or
/boot/grub2/grub.cfg.
Run the following commands:
$ sudo grep '^[\s]*GRUB2_PASSWORD=grub\.pbkdf2\.sha512.*$' /boot/grub2/user.cfg
$ sudo grep '^[\s]*password_pbkdf2[\s]+.*[\s]+grub\.pbkdf2\.sha512.*$' /boot/grub2/grub.cfg


Second, check that a superuser is defined in /boot/grub2/grub.cfg.
$ sudo grep '^[\s]*set[\s]+superusers=("?)[a-zA-Z_]+\1$'  /boot/grub2/grub.cfg
      Is it the case that it does not produce any output?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_pti_argument_question:question:1">
          <ocil:question_text>Inspect the form of default GRUB 2 command line for the Linux operating system
in grubenv that can be found either in /boot/grub2 in case of legacy BIOS systems, or in /boot/efi/EFI/almalinux in case of UEFI systems.
If they include pti=on, then the parameter
is configured at boot time.
$ sudo grep 'kernelopts.*pti=on.*' GRUBENV_FILE_LOCATION
Fill in GRUBENV_FILE_LOCATION based on information above.
      Is it the case that Kernel page-table isolation is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_rng_core_default_quality_argument_question:question:1">
          <ocil:question_text>Inspect the form of default GRUB 2 command line for the Linux operating system
in grubenv that can be found either in /boot/grub2 in case of legacy BIOS systems, or in /boot/efi/EFI/almalinux in case of UEFI systems.
If they include rng_core.default_quality=, then the parameter
is configured at boot time.
$ sudo grep 'kernelopts.*rng_core.default_quality=.*' GRUBENV_FILE_LOCATION
Fill in GRUBENV_FILE_LOCATION based on information above.
      Is it the case that trust on hardware random number generator is not configured appropriately?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_slab_nomerge_argument_question:question:1">
          <ocil:question_text>Inspect the form of default GRUB 2 command line for the Linux operating system
in grubenv that can be found either in /boot/grub2 in case of legacy BIOS systems, or in /boot/efi/EFI/almalinux in case of UEFI systems.
If they include slab_nomerge=yes, then the parameter
is configured at boot time.
$ sudo grep 'kernelopts.*slab_nomerge=yes.*' GRUBENV_FILE_LOCATION
Fill in GRUBENV_FILE_LOCATION based on information above.
      Is it the case that merging of slabs with similar size is enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_slub_debug_argument_question:question:1">
          <ocil:question_text>Inspect the form of default GRUB 2 command line for the Linux operating system
in grubenv that can be found either in /boot/grub2 in case of legacy BIOS systems, or in /boot/efi/EFI/almalinux in case of UEFI systems.
If they include slub_debug=, then the parameter
is configured at boot time.
$ sudo grep 'kernelopts.*slub_debug=.*' GRUBENV_FILE_LOCATION
Fill in GRUBENV_FILE_LOCATION based on information above.
      Is it the case that SLUB/SLAB poisoning is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_spec_store_bypass_disable_argument_question:question:1">
          <ocil:question_text>Inspect the form of default GRUB 2 command line for the Linux operating system
in grubenv that can be found either in /boot/grub2 in case of legacy BIOS systems, or in /boot/efi/EFI/almalinux in case of UEFI systems.
If they include spec_store_bypass_disable=, then the parameter
is configured at boot time.
$ sudo grep 'kernelopts.*spec_store_bypass_disable=.*' GRUBENV_FILE_LOCATION
Fill in GRUBENV_FILE_LOCATION based on information above.
      Is it the case that SSB is not configured appropriately?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_spectre_v2_argument_question:question:1">
          <ocil:question_text>Inspect the form of default GRUB 2 command line for the Linux operating system
in grubenv that can be found either in /boot/grub2 in case of legacy BIOS systems, or in /boot/efi/EFI/almalinux in case of UEFI systems.
If they include spectre_v2=on, then the parameter
is configured at boot time.
$ sudo grep 'kernelopts.*spectre_v2=on.*' GRUBENV_FILE_LOCATION
Fill in GRUBENV_FILE_LOCATION based on information above.
      Is it the case that spectre_v2 mitigation is not enforced?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_systemd_debug-shell_argument_absent_question:question:1">
          <ocil:question_text>Ensure that debug-shell service is not enabled with the following command:
grep systemd\.debug-shell=1 /boot/grub2/grubenv /etc/default/grub
If the command returns a line, it means that debug-shell service is being enabled.
      Is it the case that the command returns a line?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_uefi_admin_username_question:question:1">
          <ocil:question_text>To verify the boot loader superuser account has been set, run the following
command:
sudo grep -A1 "superusers" /boot/efi/EFI/almalinux/grub.cfg
The output should show the following:
set superusers="superusers-account"
export superusers
where superusers-account is the actual account name different from common names like root,
admin, or administrator and different from any other existing user name.
      Is it the case that superuser account is not set or is set to an existing name or to a common name?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_uefi_password_question:question:1">
          <ocil:question_text>To verify the boot loader superuser password has been set, run the following command:
$ sudo grep "^[\s]*GRUB2_PASSWORD=grub\.pbkdf2\.sha512.*$" /boot/efi/EFI/almalinux/user.cfg
The output should be similar to:
GRUB2_PASSWORD=grub.pbkdf2.sha512.10000.C4E08AC72FBFF7E837FD267BFAD7AEB3D42DDC
2C99F2A94DD5E2E75C2DC331B719FE55D9411745F82D1B6CFD9E927D61925F9BBDD1CFAA0080E0
916F7AB46E0D.1302284FCCC52CD73BA3671C6C12C26FF50BA873293B24EE2A96EE3B57963E6D7
0C83964B473EC8F93B07FE749AA6710269E904A9B08A6BBACB00A2D242AD828
      Is it the case that no password is set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-grub2_vsyscall_argument_question:question:1">
          <ocil:question_text>Inspect the form of default GRUB 2 command line for the Linux operating system
in grubenv that can be found either in /boot/grub2 in case of legacy BIOS systems, or in /boot/efi/EFI/almalinux in case of UEFI systems.
If they include vsyscall=none, then the parameter
is configured at boot time.
$ sudo grep 'kernelopts.*vsyscall=none.*' GRUBENV_FILE_LOCATION
Fill in GRUBENV_FILE_LOCATION based on information above.
      Is it the case that vsyscalls are enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-harden_openssl_crypto_policy_question:question:1">
          <ocil:question_text>To verify if the OpenSSL uses defined Crypto Policy, run:
$ grep 'Ciphersuites' /etc/crypto-policies/back-ends/opensslcnf.config | tail -n 1
and verify that the line matches
Ciphersuites = TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256
      Is it the case that Crypto Policy for OpenSSL is not configured according to CC requirements?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-harden_ssh_client_crypto_policy_question:question:1">
          <ocil:question_text>To verify if the OpenSSH Client uses defined Crypto Policy, run:
$ cat /etc/ssh/ssh_config.d/02-ospp.conf
and verify that the line matches
Match final all
RekeyLimit 512M 1h
GSSAPIAuthentication no
Ciphers aes256-ctr,aes256-cbc,aes128-ctr,aes128-cbc
PubkeyAcceptedKeyTypes ssh-rsa,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256
MACs hmac-sha2-512,hmac-sha2-256
KexAlgorithms ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group14-sha1
      Is it the case that Crypto Policy for OpenSSH Client is not configured according to CC requirements?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-harden_sshd_ciphers_openssh_conf_crypto_policy_question:question:1">
          <ocil:question_text>To verify if the OpenSSH client uses defined Cipher suite in the Crypto Policy, run:
$ grep -i ciphers /etc/crypto-policies/back-ends/openssh.config
and verify that the line matches:
Ciphers 
      Is it the case that Crypto Policy for OpenSSH client is not configured correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-harden_sshd_ciphers_opensshserver_conf_crypto_policy_question:question:1">
          <ocil:question_text>To verify if the OpenSSH server uses defined ciphers in the Crypto Policy, run:
$ grep -Po '(-oCiphers=\S+)' /etc/crypto-policies/back-ends/opensshserver.config
and verify that the line matches:
-oCiphers=
      Is it the case that Crypto Policy for OpenSSH Server is not configured correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-harden_sshd_crypto_policy_question:question:1">
          <ocil:question_text>To verify if the OpenSSH server uses defined Crypto Policy, run:
$ grep 'CRYPTO_POLICY' /etc/crypto-policies/back-ends/opensshserver.config | tail -n 1
and verify that the line matches
CRYPTO_POLICY='-oCiphers=aes256-ctr,aes128-ctr,aes256-cbc,aes128-cbc -oMACs=hmac-sha2-512,hmac-sha2-256 -oGSSAPIKeyExchange=no -oKexAlgorithms=ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group14-sha1 -oHostKeyAlgorithms=ssh-rsa,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256 -oPubkeyAcceptedKeyTypes=rsa-sha2-512,rsa-sha2-256,ssh-rsa,ecdsa-sha2-nistp384,ecdsa-sha2-nistp256'
      Is it the case that Crypto Policy for OpenSSH Server is not configured according to CC requirements?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-harden_sshd_macs_openssh_conf_crypto_policy_question:question:1">
          <ocil:question_text>To verify if the OpenSSH client uses defined MACs in the Crypto Policy, run:
$ grep -i macs /etc/crypto-policies/back-ends/openssh.config
and verify that the line matches:
MACs 
      Is it the case that Crypto Policy for OpenSSH client is not configured correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-harden_sshd_macs_opensshserver_conf_crypto_policy_question:question:1">
          <ocil:question_text>To verify if the OpenSSH server uses defined MACs in the Crypto Policy, run:
$ grep -Po '(-oMACs=\S+)' /etc/crypto-policies/back-ends/opensshserver.config
and verify that the line matches:
-oMACS=
      Is it the case that Crypto Policy for OpenSSH Server is not configured correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-has_nonlocal_mta_question:question:1">
          <ocil:question_text>Run the following command to verify that the MTA is not listening on
any non-loopback address (127.0.0.1 or ::1).
# ss -lntu | grep -E ':25\s' | grep -E -v '\s(127.0.0.1|::1):25\s'
Nothing should be returned
      Is it the case that MTA is listening on any non-loopback address?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-http_configure_log_file_ownership_question:question:1">
          <ocil:question_text>To properly set the owner of /var/log/httpd, run the command:

  $ sudo chown root /var/log/httpd 
  

To properly set the owner of /var/log/httpd/*, run the command:

  $ sudo chown root /var/log/httpd/* 
  
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_anonymous_content_sharing_question:question:1">
          <ocil:question_text>To verify that web content directories should not be shared anonymously over
remote filesystems such as nfs and smb, inspect each instance
of DocumentRoot and serverRoot and verify that no entry in
/etc/fstab exists or no remote filesystem process is running for
any instance.
$ ps -ef | grep "nfs\|smb"
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_antivirus_scan_uploads_question:question:1">
          <ocil:question_text>Remote web authors should not be able to upload files to the Document Root
directory structure without virus checking and checking for malicious or mobile
code.
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_configure_banner_page_question:question:1">
          <ocil:question_text>The document, DoDI 8500.01, establishes the policy on the use of DoD
information systems. It requires the use of a standard Notice and Consent Banner
and standard text to be included in user agreements. The banner should be set
to the following:
      Is it the case that it is not display the required banner?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_configure_documentroot_question:question:1">
          <ocil:question_text>To verify that each web content directory has an index.html file,
run the following command:
$ sudo find `grep -i documentroot /etc/httpd/conf/httpd.conf | awk -F'"' '{print $2}'` -name index.html
The output should return an index.html file for every
DocumentRoot that is set.
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_configure_firewall_question:question:1">
          <ocil:question_text>Review the web site to determine if HTTP and HTTPs are used in accordance with
well known ports (e.g., 80 and 443) or over alternate ports that are explicitly registered
and approved for use by the organization's network security policy.

To configure firewalld to allow http access, run the following command(s):
firewall-cmd --permanent --add-service=http
Then run the following command to load the newly created rule(s):
firewall-cmd --reload

To configure firewalld to allow https access, run the following command(s):
firewall-cmd --permanent --add-service=https
Then run the following command to load the newly created rule(s):
firewall-cmd --reload
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_configure_log_format_question:question:1">
          <ocil:question_text>To verify if LogFormat is configured correctly in
/etc/httpd/conf/httpd.conf, run the following command:
$ grep -i logformat /etc/httpd/conf/httpd.conf
The output should contain the following:
LogFormat "a %A %h %H %l %m %s %t %u %U \"%{Referer}i\" \"%{User-Agent}i\"" combined
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_configure_max_keepalive_requests_question:question:1">
          <ocil:question_text>To verify if MaxKeepAliveRequests is configured correctly in
/etc/httpd/conf/httpd.conf, run the following command:
$ grep -i maxkeepaliverequests /etc/httpd/conf/httpd.conf
The command should return the following:
MaxKeepAliveRequests 100
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_configure_perl_taint_question:question:1">
          <ocil:question_text>To verify if the mod_perl is installed, run the following command:
$ rpm -qa | grep mod_perl
If the mod_perl module is installed, verify that PerlSwitches -T
is enabled in /etc/httpd/conf.d/perl.conf by running the following
command:
$ grep -i "PerlSwitches -T" /etc/httpd/conf.d/perl.conf
The output should return uncommented:
PerlSwitches -T
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_configure_remote_session_encryption_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
sshd service:
$ sudo systemctl is-active sshd
If the service is running, it should return the following: active
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_configure_script_permissions_question:question:1">
          <ocil:question_text>Verify that the files and directories of each instance of Alias,
ScriptAlias, and ScriptAliasMatch that exist
have the correct file and directory permissions applied.
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_configure_tls_question:question:1">
          <ocil:question_text>To verify that TLS is configured properly in
/etc/httpd/conf.modules.d/ssl.conf, run the following command:
$ grep -i "sslengine\|sslprotocol" /etc/httpd/conf.d/ssl.conf
The output should return the following:

SSLEngine on
SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1

      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_configure_valid_server_cert_question:question:1">
          <ocil:question_text>Open browser window and browse to the appropriate site. Before entry to the
site, you should be presented with the server's PKI credentials. Review
these credentials for authenticity.

For DoD, find an entry which cites:

Issuer:
CN =
DOD CLASS 3 CA-3
OU = PKI
OU = DoD
O = U.S. Government
C = US

      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_disable_anonymous_ftp_access_question:question:1">
          <ocil:question_text>Locate the directories containing the CGI scripts. These directories should be
language-specific (e.g., PERL, ASP, JS, JSP, etc.). Examine the file permissions
on the directories using the following command:
ls -l directories
Anonymous FTP users must not have access to these directories.
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_disable_content_symlinks_question:question:1">
          <ocil:question_text>Inspect each &lt;Directory&gt; instance and verify that either
FollowSymLinks does not exist, or
Options SymLinksIfOwnerMatchDisable is configured properly.
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_disable_mime_types_question:question:1">
          <ocil:question_text>Enter the following commands:

grep Action /etc/httpd/conf/httpd.conf
grep AddHandler /etc/httpd/conf/httpd.conf
      Is it the case that either of these exist and they configure csh, or any other shell as a viewer for documents?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_enable_error_logging_question:question:1">
          <ocil:question_text>To verify if ErrorLog is configured correctly in
/etc/httpd/conf/httpd.conf, run the following command:
$ grep -i errorlog /etc/httpd/conf/httpd.conf
The output should return the following:
ErrorLog "logs/error_log"
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_enable_log_config_question:question:1">
          <ocil:question_text>To verify that the log_config_module exists in
/etc/httpd/conf/httpd.conf, run the following command:
$ grep log_config_module /etc/httpd/conf/httpd.conf
The output should return:
&lt;IfModule log_config_module&gt;
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_enable_loglevel_question:question:1">
          <ocil:question_text>To verify if LogLevel is configured correctly in
/etc/httpd/conf/httpd.conf, run the following command:
$ grep -i loglevel /etc/httpd/conf/httpd.conf
The command should return the following:
LogLevel warn
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_enable_system_logging_question:question:1">
          <ocil:question_text>To verify if CustomLog is configured correctly in
/etc/httpd/conf/httpd.conf, run the following command:
$ grep -i customlog /etc/httpd/conf/httpd.conf
The output should return the following:
CustomLog "logs/access_log" combined
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_encrypt_file_uploads_question:question:1">
          <ocil:question_text>Determine if there is a process for the uploading of files to the web site.
This process should include the requirement for the use of a secure encrypted
logon and secure encrypted connection. If the remote users are uploading files
without utilizing approved encryption methods, this is a finding.
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_entrust_passwords_question:question:1">
          <ocil:question_text>The reviewed should make a note of the name of the account being used for
the web service. This information may be needed later in the SRR. There
may also be other server services running related to the web server in
support of a particular web application, these passwords must be entrusted
to the SA or Web Manager as well.

Query the SA or Web Manager to determine if they have the web service
password(s).

NOTE: For installations that run as a service, or without a password,
the SA or Web Manager having an Admin account on the system would meet
the intent of this check.
      Is it the case that the web server password(s) are not entrusted to the SA or Web Manager?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_ignore_htaccess_files_question:question:1">
          <ocil:question_text>To preclude access to the servers root directory, ensure the following
directive is in the httpd.conf file. This entry will also stop users
from setting up .htaccess files which can override security features
configured in /etc/httpd/conf/httpd.conf.
AllowOverride none
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_limit_java_files_question:question:1">
          <ocil:question_text>To verify that no .java and .jpp files exist, run the
following command:
find / -name *.java -o -name *.jpp
The output should not return any .java or .jpp files
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_nipr_accredited_dmz_question:question:1">
          <ocil:question_text>Interview the SA or web administrator to see where the public web server
is logically located in the data center. Review the site network diagram
to see how the web server is connected to the LAN. Visually check the web
server hardware connections to see if it conforms to the site network
diagram.
      Is it the case that the web server is not isolated in an accredited DoD DMZ Extension?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_no_compilers_in_prod_question:question:1">
          <ocil:question_text>Query the SA and the Web Manager to determine if a compiler is present on
the server.
      Is it the case that the web server is part of an application suite and a compiler is needed
for installation, patching, and upgrading of the suite or if the compiler
is embedded and can't be removed without breaking the suite, document the
installation of the compiler with the ISSO/ISSM and verify that the compiler
is restricted to administrative users only. If documented and restricted to
administrative users, this is not a finding.

If an undocumented compiler is present, and available to non-administrative
users?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_private_server_on_separate_subnet_question:question:1">
          <ocil:question_text>Verify the site's network diagram and visually check the web server, to
ensure that the private web server is located on a separate controlled
access subnet and is not part of the public DMZ that houses the public
web servers.

In addition, the private web server needs to be isolated via a controlled
access mechanism from the local general population lan.
      Is it the case that the private web server is not on a separate controlled access subnet?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_public_resources_not_shared_question:question:1">
          <ocil:question_text>Configure the public web server to not have a trusted relationship with
any system resources that is also not accessible to the public. Web
content is not to be shared via Microsoft shares or NFS mounts.

Determine whether the public web server has a two-way trust relationship
with any private asset located within the network. Private web server
resources (e.g. drives, folders, printers, etc.) will not be directly
mapped to or shared with public web servers.
      Is it the case that sharing is selected for any web folder, this is a finding.

If private resources (e.g. drives, partitions, folders/directories,
printers, etc.) are sharedw ith the public web server?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_remove_backups_question:question:1">
          <ocil:question_text>Ensure that CGI backup scripts are not left on the production web server.
This check is limited to CGI/interactive content and not static HTML.

Search for backup copies of CGI scripts on the web server or ask the Web
Administrator if they keep backup copies of CGI scripts on the web server.

Common backup file extensions are: *.bak, *.old, *.temp, *.tmp, *.backup,
*.??0. This would also apply to .jsp files.

On Red Hat Enterprise Linux, run the following commands to find backup
scripts:
find / name "*.bak" -print
find / name "*.*" -print
find / name "*.old" -print
      Is it the case that If fileos with these extensions have no relationship with web activity,
such as backup batch file for operating system utility, and they are
not accessible by the web application, this is not a finding.

If files with these extensions are found in either the document
directory or the home directory of the web server, this is
a finding.

If files with these extensions are stored in a repository (not in the
document root) as backups for the web server?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_remove_robots_file_question:question:1">
          <ocil:question_text>Inspect all instances of DocumentRoot and Alias. No
robots.txt file should exist.
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-httpd_require_client_certs_question:question:1">
          <ocil:question_text>To verify if SSLVerifyClient is configured correctly in
/etc/httpd/conf/httpd.conf, run the following command:
$ grep -i sslverifyclient /etc/httpd/conf/httpd.conf
The command should return the following:
SSLVerifyClient require
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-install_antivirus_question:question:1">
          <ocil:question_text>Verify an anti-virus solution is installed on the system. The anti-virus solution may be
bundled with an approved host-based security solution.
      Is it the case that there is no anti-virus solution installed on the system?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-install_hids_question:question:1">
          <ocil:question_text>Inspect the system to determine if intrusion detection software has been installed.
Verify this intrusion detection software is active.
      Is it the case that no host-based intrusion detection tools are installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-install_mcafee_antivirus_question:question:1">
          <ocil:question_text>To verify that McAfee VirusScan Enterprise for Linux is installed
and running, run the following command(s):
$ sudo systemctl status nails
$ rpm -q McAfeeVSEForLinux
      Is it the case that virus scanning software is not installed or running?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-install_mcafee_cma_rt_question:question:1">
          <ocil:question_text>To verify that McAfee Runtime Libraries (MFErt) and Linux Agent (MFEcma)
are installed, run the following command(s):
$ rpm -q MFEcma
$ rpm -q MFErt
      Is it the case that the HBSS HIPS module is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-install_mcafee_hbss_accm_question:question:1">
          <ocil:question_text>To verify that HBSS ACCM is installed, run the following command(s):
$ sudo ls /opt/McAfee/accm/bin/accm
      Is it the case that the HBSS ACCM module is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-install_mcafee_hbss_pa_question:question:1">
          <ocil:question_text>To verify that HBSS PA is installed, run the following command(s):
$ sudo ls /opt/McAfee/auditengine/bin/auditmanager
      Is it the case that the HBSS PA module is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-install_smartcard_packages_question:question:1">
          <ocil:question_text>Check that AlmaLinux OS 8 has the packages for smart card support installed.


Run the following command to determine if the openssl-pkcs11 package is installed: $ rpm -q openssl-pkcs11
      Is it the case that smartcard software is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-installed_OS_is_FIPS_certified_question:question:1">
          <ocil:question_text>To verify that the installed operating system is supported or certified, run
the following command:

The output should contain something similar to:
AlmaLinux OS 8
      Is it the case that the installed operating system is not FIPS 140-2 certified?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-installed_OS_is_vendor_supported_question:question:1">
          <ocil:question_text>To verify that the installed operating system is supported, run
the following command:

AlmaLinux OS 8
      Is it the case that the installed operating system is not supported?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ip6tables_rules_for_open_ports_question:question:1">
          <ocil:question_text>Run the following command to determine open ports:
# ss -6tuln
Run the following command to determine firewall rules:
# ip6tables -L INPUT -v -n
For each port identified in the audit which does not have a firewall
rule, add rule for accepting or denying inbound connections
# ip6tables -A INPUT -p \ --dport \ -m state --state NEW -j ACCEPT
      Is it the case that open ports are denied connection?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-iptables_rules_for_open_ports_question:question:1">
          <ocil:question_text>Run the following command to determine open ports:
# ss -4tuln
Run the following command to determine firewall rules:
# iptables -L INPUT -v -n
For each port identified in the audit which does not have a firewall
rule, add rule for accepting or denying inbound connections
# iptables -A INPUT -p  --dport  -m state --state NEW -j ACCEPT
      Is it the case that open ports are denied connection?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-journald_compress_question:question:1">
          <ocil:question_text>Storing logs with compression can help avoid filling the system disk.
Run the following command to verify that journald is compressing logs.

grep "^\sCompress" /etc/systemd/journald.conf


and it should return

Compress=yes

      Is it the case that is commented out or not configured correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-journald_disable_forward_to_syslog_question:question:1">
          <ocil:question_text>Run the following command to verify that journald is not forwarding logs to syslog.

grep "^\sForwardToSyslog" /etc/systemd/journald.conf


and it should return

ForwardToSyslog=no

      Is it the case that is commented out or not configured correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-journald_forward_to_syslog_question:question:1">
          <ocil:question_text>Storing logs remotely protects the integrity of the data from local attacks.
Run the following command to verify that journald is forwarding logs to a remote host.

grep "^\sForwardToSyslog" /etc/systemd/journald.conf


and it should return

ForwardToSyslog=yes

      Is it the case that is commented out or not configured correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-journald_storage_question:question:1">
          <ocil:question_text>Storing logs with persistent storage ensures they are available after a reboot or system crash.
Run the command below to verify that logs are being persistently stored to disk.

grep "^\sStorage" /etc/systemd/journald.conf


and it should return

Storage=persistent

      Is it the case that is commented out or not configured correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kerberos_disable_no_keytab_question:question:1">
          <ocil:question_text>Run the following command to see if there are some keytabs
that would potentially allow the use of Kerberos by system daemons.
$ ls -la /etc/*.keytab
The expected result is
ls: cannot access '/etc/*.keytab': No such file or directory
      Is it the case that a keytab file is present on the system?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_acpi_custom_method_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_ACPI_CUSTOM_METHOD /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_arm64_sw_ttbr0_pan_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_ARM64_SW_TTBR0_PAN /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_binfmt_misc_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_BINFMT_MISC /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_bug_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_BUG /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_bug_on_data_corruption_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_BUG_ON_DATA_CORRUPTION /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_compat_brk_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_COMPAT_BRK /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_compat_vdso_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_COMPAT_VDSO /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_debug_credentials_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_DEBUG_CREDENTIALS /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_debug_fs_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_DEBUG_FS /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_debug_list_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_DEBUG_LIST /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_debug_notifiers_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_DEBUG_NOTIFIERS /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_debug_sg_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_DEBUG_SG /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_debug_wx_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_DEBUG_WX /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_default_mmap_min_addr_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
$ grep CONFIG_DEFAULT_MMAP_MIN_ADDR /boot/config.*
For each kernel installed, a line with value should be returned.
If the system architecture is x86_64, the value should be 65536.
If the system architecture is aarch64, the value should be 32768.
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_devkmem_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_DEVKMEM /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_fortify_source_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_FORTIFY_SOURCE /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_gcc_plugin_latent_entropy_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_GCC_PLUGIN_LATENT_ENTROPY /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_gcc_plugin_structleak_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_GCC_PLUGIN_STRUCTLEAK /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_hardened_usercopy_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_HARDENED_USERCOPY /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_hardened_usercopy_fallback_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_HARDENED_USERCOPY_FALLBACK /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_hibernation_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_HIBERNATION /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_ia32_emulation_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_IA32_EMULATION /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_ipv6_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_IPV6 /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_kexec_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_KEXEC /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_legacy_ptys_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_LEGACY_PTYS /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_legacy_vsyscall_emulate_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_LEGACY_VSYSCALL_EMULATE /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_legacy_vsyscall_none_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_LEGACY_VSYSCALL_NONE /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_modify_ldt_syscall_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_MODIFY_LDT_SYSCALL /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_module_sig_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_MODULE_SIG /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_module_sig_all_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_MODULE_SIG_ALL /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_module_sig_force_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_MODULE_SIG_FORCE /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_module_sig_hash_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_MODULE_SIG_HASH /boot/config.*
    
    For each kernel installed, a line with value "" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_module_sig_key_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_MODULE_SIG_KEY /boot/config.*
    
    For each kernel installed, a line with value "" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_module_sig_sha512_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_MODULE_SIG_SHA512 /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_page_poisoning_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_PAGE_POISONING /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_page_poisoning_no_sanity_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_PAGE_POISONING_NO_SANITY /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_page_poisoning_zero_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_PAGE_POISONING_ZERO /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_page_table_isolation_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_PAGE_TABLE_ISOLATION /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_panic_on_oops_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_PANIC_ON_OOPS /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_panic_timeout_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_PANIC_TIMEOUT /boot/config.*
    
    For each kernel installed, a line with value "" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_proc_kcore_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_PROC_KCORE /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_randomize_base_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_RANDOMIZE_BASE /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_randomize_memory_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_RANDOMIZE_MEMORY /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_refcount_full_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_REFCOUNT_FULL /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_retpoline_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_RETPOLINE /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_sched_stack_end_check_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_SCHED_STACK_END_CHECK /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_seccomp_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_SECCOMP /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_seccomp_filter_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_SECCOMP_FILTER /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_security_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_SECURITY /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_security_dmesg_restrict_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_SECURITY_DMESG_RESTRICT /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_security_writable_hooks_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_SECURITY_WRITABLE_HOOKS /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_security_yama_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_SECURITY_YAMA /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_slab_freelist_hardened_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_SLAB_FREELIST_HARDENED /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_slab_freelist_random_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_SLAB_FREELIST_RANDOM /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_slab_merge_default_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_SLAB_MERGE_DEFAULT /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_slub_debug_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_SLUB_DEBUG /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_stackprotector_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_STACKPROTECTOR /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_stackprotector_strong_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_STACKPROTECTOR_STRONG /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_strict_kernel_rwx_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_STRICT_KERNEL_WRX /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_strict_module_rwx_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_STRICT_MODULE_RWX /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_syn_cookies_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_SYN_COOKIES /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_unmap_kernel_at_el0_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_UNMAP_KERNEL_AT_EL0 /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_vmap_stack_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_VMAP_STACK /boot/config.*
    
    For each kernel installed, a line with value "y" should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_config_x86_vsyscall_emulation_question:question:1">
          <ocil:question_text>To determine the config value the kernel was built with, run the following command:
    $ grep CONFIG_X86_VSYSCALL_EMULATION /boot/config.*
    
    Configs with value 'n' are not explicitly set in the file, so either commented lines or no
    lines should be returned.
    
      Is it the case that the kernel was not built with the required value?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_module_atm_disabled_question:question:1">
          <ocil:question_text>
If the system is configured to prevent the loading of the atm kernel module,
it will contain lines inside any file in /etc/modprobe.d or the deprecated /etc/modprobe.conf.
These lines instruct the module loading system to run another program (such as /bin/false) upon a module install event.

Run the following command to search for such lines in all files in /etc/modprobe.d and the deprecated /etc/modprobe.conf:
$ grep -r atm /etc/modprobe.conf /etc/modprobe.d
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_module_bluetooth_disabled_question:question:1">
          <ocil:question_text>
If the system is configured to prevent the loading of the bluetooth kernel module,
it will contain lines inside any file in /etc/modprobe.d or the deprecated /etc/modprobe.conf.
These lines instruct the module loading system to run another program (such as /bin/false) upon a module install event.

Run the following command to search for such lines in all files in /etc/modprobe.d and the deprecated /etc/modprobe.conf:
$ grep -r bluetooth /etc/modprobe.conf /etc/modprobe.d
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_module_can_disabled_question:question:1">
          <ocil:question_text>
If the system is configured to prevent the loading of the can kernel module,
it will contain lines inside any file in /etc/modprobe.d or the deprecated /etc/modprobe.conf.
These lines instruct the module loading system to run another program (such as /bin/false) upon a module install event.

Run the following command to search for such lines in all files in /etc/modprobe.d and the deprecated /etc/modprobe.conf:
$ grep -r can /etc/modprobe.conf /etc/modprobe.d
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_module_cfg80211_disabled_question:question:1">
          <ocil:question_text>
If the system is configured to prevent the loading of the cfg80211 kernel module,
it will contain lines inside any file in /etc/modprobe.d or the deprecated /etc/modprobe.conf.
These lines instruct the module loading system to run another program (such as /bin/false) upon a module install event.

Run the following command to search for such lines in all files in /etc/modprobe.d and the deprecated /etc/modprobe.conf:
$ grep -r cfg80211 /etc/modprobe.conf /etc/modprobe.d
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_module_cramfs_disabled_question:question:1">
          <ocil:question_text>
If the system is configured to prevent the loading of the cramfs kernel module,
it will contain lines inside any file in /etc/modprobe.d or the deprecated /etc/modprobe.conf.
These lines instruct the module loading system to run another program (such as /bin/false) upon a module install event.

Run the following command to search for such lines in all files in /etc/modprobe.d and the deprecated /etc/modprobe.conf:
$ grep -r cramfs /etc/modprobe.conf /etc/modprobe.d
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_module_dccp_disabled_question:question:1">
          <ocil:question_text>
If the system is configured to prevent the loading of the dccp kernel module,
it will contain lines inside any file in /etc/modprobe.d or the deprecated /etc/modprobe.conf.
These lines instruct the module loading system to run another program (such as /bin/false) upon a module install event.

Run the following command to search for such lines in all files in /etc/modprobe.d and the deprecated /etc/modprobe.conf:
$ grep -r dccp /etc/modprobe.conf /etc/modprobe.d
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_module_firewire-core_disabled_question:question:1">
          <ocil:question_text>
If the system is configured to prevent the loading of the firewire-core kernel module,
it will contain lines inside any file in /etc/modprobe.d or the deprecated /etc/modprobe.conf.
These lines instruct the module loading system to run another program (such as /bin/false) upon a module install event.

Run the following command to search for such lines in all files in /etc/modprobe.d and the deprecated /etc/modprobe.conf:
$ grep -r firewire-core /etc/modprobe.conf /etc/modprobe.d
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_module_ipv6_option_disabled_question:question:1">
          <ocil:question_text>If the system uses IPv6, this is not applicable.

If the system is configured to disable the
ipv6 kernel module, it will contain a line
of the form:
options ipv6 disable=1
Such lines may be inside any file in /etc/modprobe.d or the
deprecated/etc/modprobe.conf.  This permits insertion of the IPv6
kernel module (which other parts of the system expect to be present), but
otherwise keeps it inactive.  Run the following command to search for such
lines in all files in /etc/modprobe.d and the deprecated
/etc/modprobe.conf:
$ grep -r ipv6 /etc/modprobe.conf /etc/modprobe.d
      Is it the case that the ipv6 kernel module is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_module_iwlmvm_disabled_question:question:1">
          <ocil:question_text>
If the system is configured to prevent the loading of the iwlmvm kernel module,
it will contain lines inside any file in /etc/modprobe.d or the deprecated /etc/modprobe.conf.
These lines instruct the module loading system to run another program (such as /bin/false) upon a module install event.

Run the following command to search for such lines in all files in /etc/modprobe.d and the deprecated /etc/modprobe.conf:
$ grep -r iwlmvm /etc/modprobe.conf /etc/modprobe.d
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_module_iwlwifi_disabled_question:question:1">
          <ocil:question_text>
If the system is configured to prevent the loading of the iwlwifi kernel module,
it will contain lines inside any file in /etc/modprobe.d or the deprecated /etc/modprobe.conf.
These lines instruct the module loading system to run another program (such as /bin/false) upon a module install event.

Run the following command to search for such lines in all files in /etc/modprobe.d and the deprecated /etc/modprobe.conf:
$ grep -r iwlwifi /etc/modprobe.conf /etc/modprobe.d
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_module_mac80211_disabled_question:question:1">
          <ocil:question_text>
If the system is configured to prevent the loading of the mac80211 kernel module,
it will contain lines inside any file in /etc/modprobe.d or the deprecated /etc/modprobe.conf.
These lines instruct the module loading system to run another program (such as /bin/false) upon a module install event.

Run the following command to search for such lines in all files in /etc/modprobe.d and the deprecated /etc/modprobe.conf:
$ grep -r mac80211 /etc/modprobe.conf /etc/modprobe.d
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_module_rds_disabled_question:question:1">
          <ocil:question_text>
If the system is configured to prevent the loading of the rds kernel module,
it will contain lines inside any file in /etc/modprobe.d or the deprecated /etc/modprobe.conf.
These lines instruct the module loading system to run another program (such as /bin/false) upon a module install event.

Run the following command to search for such lines in all files in /etc/modprobe.d and the deprecated /etc/modprobe.conf:
$ grep -r rds /etc/modprobe.conf /etc/modprobe.d
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_module_sctp_disabled_question:question:1">
          <ocil:question_text>
If the system is configured to prevent the loading of the sctp kernel module,
it will contain lines inside any file in /etc/modprobe.d or the deprecated /etc/modprobe.conf.
These lines instruct the module loading system to run another program (such as /bin/false) upon a module install event.

Run the following command to search for such lines in all files in /etc/modprobe.d and the deprecated /etc/modprobe.conf:
$ grep -r sctp /etc/modprobe.conf /etc/modprobe.d
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_module_tipc_disabled_question:question:1">
          <ocil:question_text>
If the system is configured to prevent the loading of the tipc kernel module,
it will contain lines inside any file in /etc/modprobe.d or the deprecated /etc/modprobe.conf.
These lines instruct the module loading system to run another program (such as /bin/false) upon a module install event.

Run the following command to search for such lines in all files in /etc/modprobe.d and the deprecated /etc/modprobe.conf:
$ grep -r tipc /etc/modprobe.conf /etc/modprobe.d
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_module_usb-storage_disabled_question:question:1">
          <ocil:question_text>
If the system is configured to prevent the loading of the usb-storage kernel module,
it will contain lines inside any file in /etc/modprobe.d or the deprecated /etc/modprobe.conf.
These lines instruct the module loading system to run another program (such as /bin/false) upon a module install event.

Run the following command to search for such lines in all files in /etc/modprobe.d and the deprecated /etc/modprobe.conf:
$ grep -r usb-storage /etc/modprobe.conf /etc/modprobe.d
      Is it the case that no line is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-kernel_module_uvcvideo_disabled_question:question:1">
          <ocil:question_text>If the device or AlmaLinux OS 8 does not have a camera installed, this requirement is not applicable.

This requirement is not applicable to mobile devices (smartphones and tablets), where the use of the camera is a local Authorizing Official (AO) decision.

This requirement is not applicable to dedicated VTC suites located in approved VTC locations that are centrally managed.

For an external camera, if there is not a method for the operator to manually disconnect the camera at the end of collaborative computing sessions, this is a finding.

For a built-in camera, the camera must be protected by a camera cover (e.g., laptop camera cover slide) when not in use. If the built-in camera is not protected with a camera cover, or is not physically disabled, this is a finding.

If the camera is not disconnected, covered, or physically disabled, determine if it is being disabled via software.

Verify the operating system disables the ability to load the uvcvideo kernel module and ensure that the uvcvideo protocol module is disabled with the following command:

$ sudo grep -r uvcvideo /etc/modprobe.d/

/etc/modprobe.d/uvcvideo-blacklist.conf:install uvcvideo /bin/false
/etc/modprobe.d/uvcvideo-blacklist.conf:blacklist uvcvideo
      Is it the case that the command does not return any output, or the line is commented out, and the collaborative computing device has not been authorized for use?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ldap_client_start_tls_question:question:1">
          <ocil:question_text>To ensure LDAP is configured to use TLS for all transactions, run the following command:
$ grep start_tls /etc/pam_ldap.conf
The result should contain:
ssl start_tls
      Is it the case that LDAP is not in use, the line is commented out, or not configured correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ldap_client_tls_cacertpath_question:question:1">
          <ocil:question_text>To ensure TLS is configured with trust certificates, run the following command:
$ grep cert /etc/nslcd.conf
      Is it the case that LDAP is not in use, the line is commented out, or not configured correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-libreswan_approved_tunnels_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 does not have unauthorized IP tunnels configured.




If "libreswan" is installed, check to see if the "IPsec" service is active with the following command:



# systemctl status ipsec
ipsec.service - Internet Key Exchange (IKE) Protocol Daemon for IPsec
Loaded: loaded (/usr/lib/systemd/system/ipsec.service; disabled)
Active: inactive (dead)



If the "IPsec" service is active, check for configured IPsec connections (conn), perform the following:
grep -rni conn /etc/ipsec.conf /etc/ipsec.d/


Verify any returned results for organizational approval.
      Is it the case that the IPSec tunnels are not approved?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-logind_session_timeout_question:question:1">
          <ocil:question_text>Display the contents of the file /etc/systemd/logind.conf:
cat /etc/systemd/logind.conf
Ensure that there is a section [login] which contains the
configuration StopIdleSessionSec=.
      Is it the case that the option is not configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mcafee_antivirus_definitions_updated_question:question:1">
          <ocil:question_text>To check on the age of McAfee virus definition files, run the following command:
$ sudo cd /opt/NAI/LinuxShield/engine/dat
$ sudo ls -la avvscan.dat avvnames.dat avvclean.dat
      Is it the case that signatures are out of date?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_boot_efi_nosuid_question:question:1">
          <ocil:question_text>Verify the nosuid option is configured for the /boot/efi mount point,
    run the following command:
    $ sudo mount | grep '\s/boot/efi\s'
    . . . /boot/efi . . . nosuid . . .

      Is it the case that the "/boot/efi" file system does not have the "nosuid" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_boot_noauto_question:question:1">
          <ocil:question_text>Verify the noauto option is configured for the /boot mount point,
    run the following command:
    $ sudo mount | grep '\s/boot\s'
    . . . /boot . . . noauto . . .

      Is it the case that the "/boot" file system does not have the "noauto" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_boot_nodev_question:question:1">
          <ocil:question_text>Verify the nodev option is configured for the /boot mount point,
    run the following command:
    $ sudo mount | grep '\s/boot\s'
    . . . /boot . . . nodev . . .

      Is it the case that the "/boot" file system does not have the "nodev" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_boot_noexec_question:question:1">
          <ocil:question_text>Verify the noexec option is configured for the /boot mount point,
    run the following command:
    $ sudo mount | grep '\s/boot\s'
    . . . /boot . . . noexec . . .

      Is it the case that the "/boot" file system does not have the "noexec" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_boot_nosuid_question:question:1">
          <ocil:question_text>Verify the nosuid option is configured for the /boot mount point,
    run the following command:
    $ sudo mount | grep '\s/boot\s'
    . . . /boot . . . nosuid . . .

      Is it the case that the "/boot" file system does not have the "nosuid" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_dev_shm_nodev_question:question:1">
          <ocil:question_text>Verify the nodev option is configured for the /dev/shm mount point,
    run the following command:
    $ sudo mount | grep '\s/dev/shm\s'
    . . . /dev/shm . . . nodev . . .

      Is it the case that the "/dev/shm" file system does not have the "nodev" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_dev_shm_noexec_question:question:1">
          <ocil:question_text>Verify the noexec option is configured for the /dev/shm mount point,
    run the following command:
    $ sudo mount | grep '\s/dev/shm\s'
    . . . /dev/shm . . . noexec . . .

      Is it the case that the "/dev/shm" file system does not have the "noexec" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_dev_shm_nosuid_question:question:1">
          <ocil:question_text>Verify the nosuid option is configured for the /dev/shm mount point,
    run the following command:
    $ sudo mount | grep '\s/dev/shm\s'
    . . . /dev/shm . . . nosuid . . .

      Is it the case that the "/dev/shm" file system does not have the "nosuid" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_home_grpquota_question:question:1">
          <ocil:question_text>Verify the grpquota option is configured for the /home mount point,
    run the following command:
    $ sudo mount | grep '\s/home\s'
    . . . /home . . . grpquota . . .

      Is it the case that the "/home" file system does not have the "grpquota" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_home_nodev_question:question:1">
          <ocil:question_text>Verify the nodev option is configured for the /home mount point,
    run the following command:
    $ sudo mount | grep '\s/home\s'
    . . . /home . . . nodev . . .

      Is it the case that the "/home" file system does not have the "nodev" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_home_noexec_question:question:1">
          <ocil:question_text>Verify the noexec option is configured for the /home mount point,
    run the following command:
    $ sudo mount | grep '\s/home\s'
    . . . /home . . . noexec . . .

      Is it the case that the "/home" file system does not have the "noexec" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_home_nosuid_question:question:1">
          <ocil:question_text>Verify the nosuid option is configured for the /home mount point,
    run the following command:
    $ sudo mount | grep '\s/home\s'
    . . . /home . . . nosuid . . .

      Is it the case that the "/home" file system does not have the "nosuid" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_home_usrquota_question:question:1">
          <ocil:question_text>Verify the usrquota option is configured for the /home mount point,
    run the following command:
    $ sudo mount | grep '\s/home\s'
    . . . /home . . . usrquota . . .

      Is it the case that the "/home" file system does not have the "usrquota" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_krb_sec_remote_filesystems_question:question:1">
          <ocil:question_text>To verify the sec option is configured for all NFS mounts, run the following command:
$ mount | grep "sec="
All NFS mounts should show the sec=krb5:krb5i:krb5p setting in parentheses.
This is not applicable if NFS is not implemented.
      Is it the case that the setting is not configured, has the 'sys' option added, or does not have all Kerberos options added?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_nodev_nonroot_local_partitions_question:question:1">
          <ocil:question_text>To verify the nodev option is configured for non-root local partitions,
run the following command:
$ sudo mount | grep '^/dev\S* on /\S' | grep --invert-match 'nodev'
The output shows local non-root partitions mounted without the nodev option,
and there should be no output at all.

      Is it the case that some mounts appear among output lines?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_nodev_remote_filesystems_question:question:1">
          <ocil:question_text>To verify the nodev option is configured for all NFS mounts, run
the following command:
$ mount | grep nfs
All NFS mounts should show the nodev setting in parentheses. This
is not applicable if NFS is not implemented.
      Is it the case that the setting does not show?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_nodev_removable_partitions_question:question:1">
          <ocil:question_text>Verify file systems that are used for removable media are mounted with the "nodev" option with the following command:

$ sudo more /etc/fstab

UUID=2bc871e4-e2a3-4f29-9ece-3be60c835222 /mnt/usbflash vfat noauto,owner,ro,nosuid,nodev,noexec 0 0
      Is it the case that a file system found in "/etc/fstab" refers to removable media and it does not have the "nodev" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_noexec_remote_filesystems_question:question:1">
          <ocil:question_text>To verify the noexec option is configured for all NFS mounts, run the following command:
$ mount | grep nfs
All NFS mounts should show the noexec setting in parentheses.  This is not applicable if NFS is
not implemented.
      Is it the case that the setting does not show?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_noexec_removable_partitions_question:question:1">
          <ocil:question_text>To verify that binaries cannot be directly executed from removable media, run the following command:
$ grep -v noexec /etc/fstab
The resulting output will show partitions which do not have the noexec flag. Verify all partitions
in the output are not removable media.
      Is it the case that removable media partitions are present?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_nosuid_remote_filesystems_question:question:1">
          <ocil:question_text>To verify the nosuid option is configured for all NFS mounts, run
the following command:
$ mount | grep nfs
All NFS mounts should show the nosuid setting in parentheses. This
is not applicable if NFS is not implemented.
      Is it the case that the setting does not show?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_nosuid_removable_partitions_question:question:1">
          <ocil:question_text>Verify file systems that are used for removable media are mounted with the "nosuid" option with the following command:

$ sudo more /etc/fstab

UUID=2bc871e4-e2a3-4f29-9ece-3be60c835222 /mnt/usbflash vfat noauto,owner,ro,nosuid,nodev,noexec 0 0
      Is it the case that file system found in "/etc/fstab" refers to removable media and it does not have the "nosuid" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_opt_nosuid_question:question:1">
          <ocil:question_text>Verify the nosuid option is configured for the /opt mount point,
    run the following command:
    $ sudo mount | grep '\s/opt\s'
    . . . /opt . . . nosuid . . .

      Is it the case that the "/opt" file system does not have the "nosuid" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_proc_hidepid_question:question:1">
          <ocil:question_text>Verify the hidepid=value option is configured for the /proc mount point,
    run the following command:
    $ sudo mount | grep '\s/proc\s'
    . . . /proc . . . hidepid=value . . .

      Is it the case that the "/proc" file system does not have the "hidepid=value" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_smb_client_signing_question:question:1">
          <ocil:question_text>To verify that Samba clients using mount.cifs must use packet signing, run the following command:
$ grep sec /etc/fstab
The output should show either krb5i or ntlmv2i in use.
      Is it the case that it does not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_srv_nosuid_question:question:1">
          <ocil:question_text>Verify the nosuid option is configured for the /srv mount point,
    run the following command:
    $ sudo mount | grep '\s/srv\s'
    . . . /srv . . . nosuid . . .

      Is it the case that the "/srv" file system does not have the "nosuid" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_tmp_nodev_question:question:1">
          <ocil:question_text>Verify the nodev option is configured for the /tmp mount point,
    run the following command:
    $ sudo mount | grep '\s/tmp\s'
    . . . /tmp . . . nodev . . .

      Is it the case that the "/tmp" file system does not have the "nodev" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_tmp_noexec_question:question:1">
          <ocil:question_text>Verify the noexec option is configured for the /tmp mount point,
    run the following command:
    $ sudo mount | grep '\s/tmp\s'
    . . . /tmp . . . noexec . . .

      Is it the case that the "/tmp" file system does not have the "noexec" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_tmp_nosuid_question:question:1">
          <ocil:question_text>Verify the nosuid option is configured for the /tmp mount point,
    run the following command:
    $ sudo mount | grep '\s/tmp\s'
    . . . /tmp . . . nosuid . . .

      Is it the case that the "/tmp" file system does not have the "nosuid" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_var_log_audit_nodev_question:question:1">
          <ocil:question_text>Verify the nodev option is configured for the /var/log/audit mount point,
    run the following command:
    $ sudo mount | grep '\s/var/log/audit\s'
    . . . /var/log/audit . . . nodev . . .

      Is it the case that the "/var/log/audit" file system does not have the "nodev" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_var_log_audit_noexec_question:question:1">
          <ocil:question_text>Verify the noexec option is configured for the /var/log/audit mount point,
    run the following command:
    $ sudo mount | grep '\s/var/log/audit\s'
    . . . /var/log/audit . . . noexec . . .

      Is it the case that the "/var/log/audit" file system does not have the "noexec" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_var_log_audit_nosuid_question:question:1">
          <ocil:question_text>Verify the nosuid option is configured for the /var/log/audit mount point,
    run the following command:
    $ sudo mount | grep '\s/var/log/audit\s'
    . . . /var/log/audit . . . nosuid . . .

      Is it the case that the "/var/log/audit" file system does not have the "nosuid" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_var_log_nodev_question:question:1">
          <ocil:question_text>Verify the nodev option is configured for the /var/log mount point,
    run the following command:
    $ sudo mount | grep '\s/var/log\s'
    . . . /var/log . . . nodev . . .

      Is it the case that the "/var/log" file system does not have the "nodev" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_var_log_noexec_question:question:1">
          <ocil:question_text>Verify the noexec option is configured for the /var/log mount point,
    run the following command:
    $ sudo mount | grep '\s/var/log\s'
    . . . /var/log . . . noexec . . .

      Is it the case that the "/var/log" file system does not have the "noexec" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_var_log_nosuid_question:question:1">
          <ocil:question_text>Verify the nosuid option is configured for the /var/log mount point,
    run the following command:
    $ sudo mount | grep '\s/var/log\s'
    . . . /var/log . . . nosuid . . .

      Is it the case that the "/var/log" file system does not have the "nosuid" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_var_nodev_question:question:1">
          <ocil:question_text>Verify the nodev option is configured for the /var mount point,
    run the following command:
    $ sudo mount | grep '\s/var\s'
    . . . /var . . . nodev . . .

      Is it the case that the "/var" file system does not have the "nodev" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_var_noexec_question:question:1">
          <ocil:question_text>Verify the noexec option is configured for the /var mount point,
    run the following command:
    $ sudo mount | grep '\s/var\s'
    . . . /var . . . noexec . . .

      Is it the case that the "/var" file system does not have the "noexec" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_var_nosuid_question:question:1">
          <ocil:question_text>Verify the nosuid option is configured for the /var mount point,
    run the following command:
    $ sudo mount | grep '\s/var\s'
    . . . /var . . . nosuid . . .

      Is it the case that the "/var" file system does not have the "nosuid" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_var_tmp_nodev_question:question:1">
          <ocil:question_text>Verify the nodev option is configured for the /var/tmp mount point,
    run the following command:
    $ sudo mount | grep '\s/var/tmp\s'
    . . . /var/tmp . . . nodev . . .

      Is it the case that the "/var/tmp" file system does not have the "nodev" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_var_tmp_noexec_question:question:1">
          <ocil:question_text>Verify the noexec option is configured for the /var/tmp mount point,
    run the following command:
    $ sudo mount | grep '\s/var/tmp\s'
    . . . /var/tmp . . . noexec . . .

      Is it the case that the "/var/tmp" file system does not have the "noexec" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-mount_option_var_tmp_nosuid_question:question:1">
          <ocil:question_text>Verify the nosuid option is configured for the /var/tmp mount point,
    run the following command:
    $ sudo mount | grep '\s/var/tmp\s'
    . . . /var/tmp . . . nosuid . . .

      Is it the case that the "/var/tmp" file system does not have the "nosuid" option set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-network_configure_name_resolution_question:question:1">
          <ocil:question_text>Verify that DNS servers have been configured properly, perform the following:
$ sudo grep nameserver /etc/resolv.conf
      Is it the case that less than two lines are returned that are not commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-network_disable_ddns_interfaces_question:question:1">
          <ocil:question_text>To verify that clients cannot automatically update DNS records, perform the
following:
$ grep -i dhcp_hostname /etc/sysconfig/network-scripts/ifcfg-*
$ grep -rni "send host-name" /etc/dhclient.conf /etc/dhcp
The output should return no results.
      Is it the case that client Dynamic DNS updates are not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-network_nmcli_permissions_question:question:1">
          <ocil:question_text>Using a non-privileged account, verify that users cannot modify or change
network settings with the nmcli command with the following command:
$ nmcli general permissions
The output should contain the following:
PERMISSION                                                        VALUE
org.freedesktop.NetworkManager.enable-disable-network             auth
org.freedesktop.NetworkManager.enable-disable-wifi                auth
org.freedesktop.NetworkManager.enable-disable-wwan                auth
org.freedesktop.NetworkManager.enable-disable-wimax               auth
org.freedesktop.NetworkManager.sleep-wake                         auth
org.freedesktop.NetworkManager.network-control                    auth
org.freedesktop.NetworkManager.wifi.share.protected               auth
org.freedesktop.NetworkManager.wifi.share.open                    auth
org.freedesktop.NetworkManager.settings.modify.system             auth
org.freedesktop.NetworkManager.settings.modify.own                auth
org.freedesktop.NetworkManager.settings.modify.hostname           auth
org.freedesktop.NetworkManager.settings.modify.global-dns         auth
org.freedesktop.NetworkManager.reload                             auth
org.freedesktop.NetworkManager.checkpoint-rollback                auth
org.freedesktop.NetworkManager.enable-disable-statistics          auth
org.freedesktop.NetworkManager.enable-disable-connectivity-check  auth
org.freedesktop.NetworkManager.wifi.scan                          auth

      Is it the case that non-privileged users can modify or change network settings?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-network_sniffer_disabled_question:question:1">
          <ocil:question_text>Verify that Promiscuous mode of an interface is disabled, run the following command:
$ ip link | grep PROMISC
      Is it the case that any network device is in promiscuous mode?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-nfs_no_anonymous_question:question:1">
          <ocil:question_text>Inspect the mounts configured in /etc/exports. Each mount should specify a value
greater than UID_MAX and GID_MAX as defined in /etc/login.defs.
      Is it the case that anonuid or anongid are not set to a value greater than UID_MAX (for anonuid) and GID_MAX (for anongid)?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_all_squash_exports_question:question:1">
          <ocil:question_text>To verify all squashing has been disabled, run the following command:
$ grep all_squash /etc/exports
      Is it the case that there is output?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_direct_root_logins_question:question:1">
          <ocil:question_text>To ensure root may not directly login to the system over physical consoles,
run the following command:
cat /etc/securetty
If any output is returned, this is a finding.
      Is it the case that the /etc/securetty file is not empty?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_empty_passwords_question:question:1">
          <ocil:question_text>To verify that null passwords cannot be used, run the following command:

$ grep nullok /etc/pam.d/system-auth /etc/pam.d/password-auth

If this produces any output, it may be possible to log into accounts
with empty passwords. Remove any instances of the nullok option to
prevent logins with empty passwords.
      Is it the case that NULL passwords can be used?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_empty_passwords_etc_shadow_question:question:1">
          <ocil:question_text>To verify that null passwords cannot be used, run the following command:
$ sudo awk -F: '!$2 {print $1}' /etc/shadow
If this produces any output, it may be possible to log into accounts
with empty passwords.
      Is it the case that Blank or NULL passwords can be used?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_files_or_dirs_ungroupowned_question:question:1">
          <ocil:question_text>The following command will locate the mount points related to local devices:
$ findmnt -n -l -k -it $(awk '/nodev/ { print $2 }' /proc/filesystems | paste -sd,)

The following command will show files and directories which do not belong to a valid group:
$ sudo find MOUNTPOINT -xdev -nogroup 2&gt;/dev/null

Replace MOUNTPOINT by the mount points listed by the fist command.

No files and directories without a valid group should be located.
      Is it the case that files and directories exist that are not owned by a valid group?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_files_or_dirs_unowned_by_user_question:question:1">
          <ocil:question_text>The following command will locate the mount points related to local devices:
$ findmnt -n -l -k -it $(awk '/nodev/ { print $2 }' /proc/filesystems | paste -sd,)

The following command will show files and directories which do not belong to a valid user:
$ sudo find MOUNTPOINT -xdev -nouser 2&gt;/dev/null

Replace MOUNTPOINT by the mount points listed by the fist command.

No files and directories without a valid user should be located.
      Is it the case that files exist that are not owned by a valid user?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_files_unowned_by_user_question:question:1">
          <ocil:question_text>The following command will locate the mount points related to local devices:
$ findmnt -n -l -k -it $(awk '/nodev/ { print $2 }' /proc/filesystems | paste -sd,)

The following command will show files which do not belong to a valid user:
$ sudo find MOUNTPOINT -xdev -nouser 2&gt;/dev/null

Replace MOUNTPOINT by the mount points listed by the fist command.

No files without a valid user should be located.
      Is it the case that files exist that are not owned by a valid user?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_forward_files_question:question:1">
          <ocil:question_text>To check the system for the existence of any .forward files,
run the following command:
$ sudo find /home -xdev -name .forward
      Is it the case that any .forward files exist?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_host_based_files_question:question:1">
          <ocil:question_text>Verify that there are no shosts.equiv files on the system, run the following command:
$ find / -name shosts.equiv
      Is it the case that shosts.equiv files exist?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_insecure_locks_exports_question:question:1">
          <ocil:question_text>To verify insecure file locking has been disabled, run the following command:
$ grep insecure_locks /etc/exports
      Is it the case that there is output?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_legacy_plus_entries_etc_group_question:question:1">
          <ocil:question_text>To check for legacy lines in /etc/group, run the following command:
 grep '^\+' /etc/group
The command should not return any output.
      Is it the case that the file contains legacy lines?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_legacy_plus_entries_etc_passwd_question:question:1">
          <ocil:question_text>To check for legacy lines in /etc/passwd, run the following command:
 grep '^\+' /etc/passwd
The command should not return any output.
      Is it the case that the file contains legacy lines?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_legacy_plus_entries_etc_shadow_question:question:1">
          <ocil:question_text>To check for legacy lines in /etc/shadow, run the following command:
 grep '^\+' /etc/shadow
The command should not return any output.
      Is it the case that the file contains legacy lines?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_netrc_files_question:question:1">
          <ocil:question_text>To check the system for the existence of any .netrc files,
run the following command:
$ sudo find /home -xdev -name .netrc
      Is it the case that any .netrc files exist?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_nis_in_nsswitch_question:question:1">
          <ocil:question_text>Run the following command:
grep '^\w+\s+(\w+\s+)*nis($|\s+.*$)' /etc/nsswitch.conf
If a line is returned and it contains the word nis in the list
of services, it is a finding.
      Is it the case that a nis database is configured in nsswitch.conf?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_nologin_in_shells_question:question:1">
          <ocil:question_text>To verify that nologin is not listed in /etc/shells, run:
$ grep nologin /etc/shells
The command should return no output.
      Is it the case that nologin is listed in /etc/shells?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_password_auth_for_systemaccounts_question:question:1">
          <ocil:question_text>To obtain a list of all users and the content of their shadow password field, run the command:
$ sudo readarray -t systemaccounts 
Verify if all accounts are locked.
      Is it the case that system accounts are not locked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_rhost_files_question:question:1">
          <ocil:question_text>To check the system for the existence of any .rhost files,
run the following command:
$ sudo find /home -xdev -name .rhost
      Is it the case that any .rhost files exist?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_root_webbrowsing_question:question:1">
          <ocil:question_text>Check the root home directory for a .mozilla directory. If
one exists, ensure browsing is limited to local service administration.
      Is it the case that this is not the case?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_rsh_trust_files_question:question:1">
          <ocil:question_text>The existence of the file /etc/hosts.equiv or a file named
.rhosts inside a user home directory indicates the presence
of an Rsh trust relationship.
      Is it the case that these files exist?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_shelllogin_for_systemaccounts_question:question:1">
          <ocil:question_text>To obtain a listing of all users, their UIDs, and their shells, run the command:
$ awk -F: '{print $1 ":" $3 ":" $7}' /etc/passwd
Identify the system accounts from this listing. These will primarily be the accounts with UID
numbers less than 1000, other than root.
      Is it the case that any system account other than root has a login shell?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_tmux_in_shells_question:question:1">
          <ocil:question_text>To verify that tmux is not listed as allowed shell on the system
run the following command:
$ grep 'tmux$' /etc/shells
The output should be empty.
      Is it the case that tmux is listed in /etc/shells?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-no_user_host_based_files_question:question:1">
          <ocil:question_text>To verify that there are no .shosts files
on the system, run the following command:
$ sudo find / -name '.shosts'
      Is it the case that .shosts files exist?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ntpd_specify_remote_server_question:question:1">
          <ocil:question_text>To verify that a remote NTP service is configured for time synchronization,
open the following file:
/etc/ntp.conf
In the file, there should be a section similar to the following:
server ntpserver
      Is it the case that this is not the case?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-openssl_use_strong_entropy_question:question:1">
          <ocil:question_text>To determine whether OpenSSL is wrapped by a shell function that ensures that every invocation
uses a SP800-90A compliant entropy source,
make sure that the /etc/profile.d/openssl-rand.sh file contents exactly match those
that are included in the rule's description.
      Is it the case that there is no &lt;tt&gt;/etc/profile.d/openssl-rand.sh&lt;/tt&gt; file, or its contents don't match those in the description?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_389-ds-base_removed_question:question:1">
          <ocil:question_text>To verify the 389-ds-base package is not installed, run the
following command:
$ rpm -q 389-ds-base
The output should show the following:
package 389-ds-base is not installed
      Is it the case that the package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_MFEhiplsm_installed_question:question:1">
          <ocil:question_text>To verify that McAfee HIPS is installed, run the following command(s):
$ rpm -q MFEhiplsm
      Is it the case that the HBSS HIPS module is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_abrt-addon-ccpp_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the abrt-addon-ccpp package is installed: $ rpm -q abrt-addon-ccpp
      Is it the case that the abrt-addon-ccpp package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_abrt-addon-kerneloops_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the abrt-addon-kerneloops package is installed: $ rpm -q abrt-addon-kerneloops
      Is it the case that the abrt-addon-kerneloops package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_abrt-cli_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the abrt-cli package is installed: $ rpm -q abrt-cli
      Is it the case that the abrt-cli package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_abrt-plugin-logger_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the abrt-plugin-logger package is installed: $ rpm -q abrt-plugin-logger
      Is it the case that the abrt-plugin-logger package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_abrt-plugin-rhtsupport_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the abrt-plugin-rhtsupport package is installed: $ rpm -q abrt-plugin-rhtsupport
      Is it the case that the abrt-plugin-rhtsupport package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_abrt-plugin-sosreport_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the abrt-plugin-sosreport package is installed: $ rpm -q abrt-plugin-sosreport
      Is it the case that the abrt-plugin-sosreport package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_abrt_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the abrt package is installed: $ rpm -q abrt
      Is it the case that the abrt package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_aide_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the aide package is installed: $ rpm -q aide
      Is it the case that the aide package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_audispd-plugins_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the audispd-plugins package is installed: $ rpm -q audispd-plugins
      Is it the case that the audispd-plugins package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_audit-audispd-plugins_installed_question:question:1">
          <ocil:question_text>
      Is it the case that the package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_audit-libs_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the audit-libs package is installed: $ rpm -q audit-libs
      Is it the case that the audit-libs package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_audit_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the audit package is installed: $ rpm -q audit
      Is it the case that the audit package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_authselect_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the authselect package is installed: $ rpm -q authselect
      Is it the case that the authselect package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_avahi-autoipd_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the avahi-autoipd package is installed: $ rpm -q avahi-autoipd
      Is it the case that the avahi-autoipd package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_avahi_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the avahi package is installed: $ rpm -q avahi
      Is it the case that the avahi package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_bind_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the bind package is installed: $ rpm -q bind
      Is it the case that the bind package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_binutils_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the binutils package is installed: $ rpm -q binutils
      Is it the case that the binutils package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_chrony_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the chrony package is installed: $ rpm -q chrony
      Is it the case that the chrony package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_cron_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the cron package is installed: $ rpm -q cron
      Is it the case that the cron package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_crypto-policies_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the crypto-policies package is installed: $ rpm -q crypto-policies
      Is it the case that the crypto-policies package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_cups_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the cups package is installed: $ rpm -q cups
      Is it the case that the cups package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_cyrus-imapd_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the cyrus-imapd package is installed: $ rpm -q cyrus-imapd
      Is it the case that the cyrus-imapd package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_dhcp_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the dhcp package is installed: $ rpm -q dhcp
      Is it the case that the dhcp package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_dnf-automatic_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the dnf-automatic package is installed: $ rpm -q dnf-automatic
      Is it the case that the dnf-automatic package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_dnf-plugin-subscription-manager_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the dnf-plugin-subscription-manager package is installed: $ rpm -q dnf-plugin-subscription-manager
      Is it the case that the dnf-plugin-subscription-manager package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_dnsmasq_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the dnsmasq package is installed: $ rpm -q dnsmasq
      Is it the case that the dnsmasq package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_dovecot_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the dovecot package is installed: $ rpm -q dovecot
      Is it the case that the dovecot package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_fapolicyd_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the fapolicyd package is installed: $ rpm -q fapolicyd
      Is it the case that the fapolicyd package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_firewalld_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the firewalld package is installed: $ rpm -q firewalld
      Is it the case that the firewalld package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_freeradius_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the freeradius package is installed: $ rpm -q freeradius
      Is it the case that the freeradius package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_ftp_removed_question:question:1">
          <ocil:question_text>The ftp package can be removed with the following command:  $ sudo yum erase ftp
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_gdm_removed_question:question:1">
          <ocil:question_text>To ensure the gdm package group is removed, run the following command:
$ rpm -qi gdm
The output should be:
package gdm is not installed
      Is it the case that gdm has not been removed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_geolite2-city_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the geolite2-city package is installed: $ rpm -q geolite2-city
      Is it the case that the geolite2-city package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_geolite2-country_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the geolite2-country package is installed: $ rpm -q geolite2-country
      Is it the case that the geolite2-country package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_gnutls-utils_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the gnutls-utils package is installed: $ rpm -q gnutls-utils
      Is it the case that the gnutls-utils package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_gssproxy_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the gssproxy package is installed: $ rpm -q gssproxy
      Is it the case that the gssproxy package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_httpd_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the httpd package is installed: $ rpm -q httpd
      Is it the case that the httpd package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_iprutils_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the iprutils package is installed: $ rpm -q iprutils
      Is it the case that the iprutils package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_iptables-services_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the iptables-services package is installed: $ rpm -q iptables-services
      Is it the case that the iptables-services package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_iptables-services_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the iptables-services package is installed: $ rpm -q iptables-services
      Is it the case that the iptables-services package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_iptables_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the iptables package is installed: $ rpm -q iptables
      Is it the case that the iptables package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_krb5-server_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the krb5-server package is installed: $ rpm -q krb5-server
      Is it the case that the krb5-server package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_krb5-workstation_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the krb5-workstation package is installed: $ rpm -q krb5-workstation
      Is it the case that the krb5-workstation package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_libcap-ng-utils_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the libcap-ng-utils package is installed: $ rpm -q libcap-ng-utils
      Is it the case that the libcap-ng-utils package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_libreport-plugin-logger_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the libreport-plugin-logger package is installed: $ rpm -q libreport-plugin-logger
      Is it the case that the libreport-plugin-logger package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_libreport-plugin-rhtsupport_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the libreport-plugin-rhtsupport package is installed: $ rpm -q libreport-plugin-rhtsupport
      Is it the case that the libreport-plugin-rhtsupport package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_libreswan_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the libreswan package is installed: $ rpm -q libreswan
      Is it the case that the libreswan package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_libselinux_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the libselinux package is installed: $ rpm -q libselinux
      Is it the case that the libselinux package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_logrotate_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the logrotate package is installed: $ rpm -q logrotate
      Is it the case that the logrotate package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_mailx_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the mailx package is installed: $ rpm -q mailx
      Is it the case that the mailx package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_mcafeetp_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the McAfeeTP package is installed: $ rpm -q McAfeeTP
      Is it the case that the McAfeeTP package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_net-snmp_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the net-snmp package is installed: $ rpm -q net-snmp
      Is it the case that the net-snmp package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_nfs-utils_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the nfs-utils package is installed: $ rpm -q nfs-utils
      Is it the case that the nfs-utils package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_nftables_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the nftables package is installed: $ rpm -q nftables
      Is it the case that the nftables package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_nginx_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the nginx package is installed: $ rpm -q nginx
      Is it the case that the nginx package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_nss-tools_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the nss-tools package is installed: $ rpm -q nss-tools
      Is it the case that the nss-tools package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_ntp_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the ntp package is installed: $ rpm -q ntp
      Is it the case that the ntp package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_openldap-clients_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the openldap-clients package is installed: $ rpm -q openldap-clients
      Is it the case that the openldap-clients package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_openldap-servers_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the openldap-servers package is installed: $ rpm -q openldap-servers
      Is it the case that the openldap-servers package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_opensc_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the opensc package is installed: $ rpm -q opensc
      Is it the case that the opensc package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_openscap-scanner_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the openscap-scanner package is installed: $ rpm -q openscap-scanner
      Is it the case that the openscap-scanner package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_openssh-clients_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the openssh-clients package is installed: $ rpm -q openssh-clients
      Is it the case that the openssh-clients package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_openssh-server_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the openssh-server package is installed: $ rpm -q openssh-server
      Is it the case that the openssh-server package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_openssh-server_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the openssh-server package is installed: $ rpm -q openssh-server
      Is it the case that the openssh-server package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_pam_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the pam package is installed: $ rpm -q pam
      Is it the case that the pam package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_pam_pwquality_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the libpwquality package is installed: $ rpm -q libpwquality
      Is it the case that the libpwquality package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_pcsc-lite_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the pcsc-lite package is installed: $ rpm -q pcsc-lite
      Is it the case that the pcsc-lite package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_pigz_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the pigz package is installed: $ rpm -q pigz
      Is it the case that the pigz package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_policycoreutils-python-utils_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the policycoreutils-python-utils package is installed: $ rpm -q policycoreutils-python-utils
      Is it the case that the policycoreutils-python-utils package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_policycoreutils_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the policycoreutils package is installed: $ rpm -q policycoreutils
      Is it the case that the policycoreutils package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_postfix_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the postfix package is installed: $ rpm -q postfix
      Is it the case that the postfix package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_psacct_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the psacct package is installed: $ rpm -q psacct
      Is it the case that the psacct package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_python3-abrt-addon_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the python3-abrt-addon package is installed: $ rpm -q python3-abrt-addon
      Is it the case that the python3-abrt-addon package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_quagga_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the quagga package is installed: $ rpm -q quagga
      Is it the case that the quagga package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_rear_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the rear package is installed: $ rpm -q rear
      Is it the case that the rear package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_rng-tools_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the rng-tools package is installed: $ rpm -q rng-tools
      Is it the case that the rng-tools package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_rpcbind_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the rpcbind package is installed: $ rpm -q rpcbind
      Is it the case that the rpcbind package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_rsh-server_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the rsh-server package is installed: $ rpm -q rsh-server
      Is it the case that the rsh-server package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_rsh_removed_question:question:1">
          <ocil:question_text>The rsh package can be removed with the following command:  $ sudo yum erase rsh
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_rsync_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the rsync package is installed: $ rpm -q rsync
      Is it the case that the rsync package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_rsyslog-gnutls_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the rsyslog-gnutls package is installed: $ rpm -q rsyslog-gnutls
      Is it the case that the rsyslog-gnutls package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_rsyslog_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the rsyslog package is installed: $ rpm -q rsyslog
      Is it the case that the rsyslog package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_samba-common_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the samba-common package is installed: $ rpm -q samba-common
      Is it the case that the samba-common package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_samba_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the samba package is installed: $ rpm -q samba
      Is it the case that the samba package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_scap-security-guide_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the scap-security-guide package is installed: $ rpm -q scap-security-guide
      Is it the case that the scap-security-guide package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_sendmail_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the sendmail package is installed: $ rpm -q sendmail
      Is it the case that the sendmail package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_setroubleshoot-plugins_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the setroubleshoot-plugins package is installed: $ rpm -q setroubleshoot-plugins
      Is it the case that the setroubleshoot-plugins package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_setroubleshoot-server_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the setroubleshoot-server package is installed: $ rpm -q setroubleshoot-server
      Is it the case that the setroubleshoot-server package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_squid_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the squid package is installed: $ rpm -q squid
      Is it the case that the squid package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_sssd-ipa_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the sssd-ipa package is installed: $ rpm -q sssd-ipa
      Is it the case that the sssd-ipa package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_sssd_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the sssd package is installed: $ rpm -q sssd
      Is it the case that the sssd package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_subscription-manager_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the subscription-manager package is installed: $ rpm -q subscription-manager
      Is it the case that the subscription-manager package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_sudo_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the sudo package is installed: $ rpm -q sudo
      Is it the case that the sudo package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_syslogng_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the syslog-ng-core package is installed: $ rpm -q syslog-ng-core
      Is it the case that the syslog-ng-core package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_systemd-journal-remote_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the systemd-journal-remote package is installed: $ rpm -q systemd-journal-remote
      Is it the case that the systemd-journal-remote package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_talk-server_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the talk-server package is installed: $ rpm -q talk-server
      Is it the case that the talk-server package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_talk_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the talk package is installed: $ rpm -q talk
      Is it the case that the talk package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_tar_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the tar package is installed: $ rpm -q tar
      Is it the case that the tar package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_telnet-server_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the telnet-server package is installed: $ rpm -q telnet-server
      Is it the case that the telnet-server package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_telnet_removed_question:question:1">
          <ocil:question_text>The telnet package can be removed with the following command:  $ sudo yum erase telnet
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_tftp-server_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the tftp-server package is installed: $ rpm -q tftp-server
      Is it the case that the tftp-server package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_tftp_removed_question:question:1">
          <ocil:question_text>The tftp package can be removed with the following command:  $ sudo yum erase tftp
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_tmux_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the tmux package is installed: $ rpm -q tmux
      Is it the case that the tmux package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_tuned_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the tuned package is installed: $ rpm -q tuned
      Is it the case that the tuned package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_usbguard_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the usbguard package is installed: $ rpm -q usbguard
      Is it the case that the usbguard package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_vim_installed_question:question:1">
          <ocil:question_text>Run the following command to determine if the vim-enhanced package is installed: $ rpm -q vim-enhanced
      Is it the case that the vim-enhanced package is not installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_vsftpd_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the vsftpd package is installed: $ rpm -q vsftpd
      Is it the case that the vsftpd package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_xinetd_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the xinetd package is installed: $ rpm -q xinetd
      Is it the case that the xinetd package is installed and the network services are not using the xinetd service?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_xorg-x11-server-Xwayland_removed_question:question:1">
          <ocil:question_text>The xorg-x11-server-Xwayland package can be removed with the following command:

$ sudo yum erase xorg-x11-server-Xwayland
      Is it the case that The xorg-x11-server-Xwayland package is installed.?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_xorg-x11-server-common_removed_question:question:1">
          <ocil:question_text>To ensure the X Windows package group is removed, run the following command:
$ rpm -qi xorg-x11-server-common
The output should be:
package xorg-x11-server-common is not installed
      Is it the case that the X Windows package group or xorg-x11-server-common has not be removed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_ypbind_removed_question:question:1">
          <ocil:question_text>The ypbind package can be removed with the following command:  $ sudo yum erase ypbind
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-package_ypserv_removed_question:question:1">
          <ocil:question_text>Run the following command to determine if the ypserv package is installed: $ rpm -q ypserv
      Is it the case that the ypserv package is installed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-partition_for_boot_question:question:1">
          <ocil:question_text>Verify that a separate file system/partition has been created for /boot with the following command:

$ mountpoint /boot

      Is it the case that "/boot is not a mountpoint" is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-partition_for_dev_shm_question:question:1">
          <ocil:question_text>Verify that a separate file system/partition has been created for /dev/shm with the following command:

$ mountpoint /dev/shm

      Is it the case that "/dev/shm is not a mountpoint" is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-partition_for_home_question:question:1">
          <ocil:question_text>Verify that a separate file system/partition has been created for /home with the following command:

$ mountpoint /home

      Is it the case that "/home is not a mountpoint" is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-partition_for_opt_question:question:1">
          <ocil:question_text>Verify that a separate file system/partition has been created for /opt with the following command:

$ mountpoint /opt

      Is it the case that "/opt is not a mountpoint" is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-partition_for_srv_question:question:1">
          <ocil:question_text>Verify that a separate file system/partition has been created for /srv with the following command:

$ mountpoint /srv

      Is it the case that "/srv is not a mountpoint" is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-partition_for_tmp_question:question:1">
          <ocil:question_text>Verify that a separate file system/partition has been created for /tmp with the following command:

$ mountpoint /tmp

      Is it the case that "/tmp is not a mountpoint" is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-partition_for_usr_question:question:1">
          <ocil:question_text>Verify that a separate file system/partition has been created for /usr with the following command:

$ mountpoint /usr

      Is it the case that "/usr is not a mountpoint" is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-partition_for_var_question:question:1">
          <ocil:question_text>Verify that a separate file system/partition has been created for /var with the following command:

$ mountpoint /var

      Is it the case that "/var is not a mountpoint" is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-partition_for_var_log_question:question:1">
          <ocil:question_text>Verify that a separate file system/partition has been created for /var/log with the following command:

$ mountpoint /var/log

      Is it the case that "/var/log is not a mountpoint" is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-partition_for_var_log_audit_question:question:1">
          <ocil:question_text>Verify that a separate file system/partition has been created for /var/log/audit with the following command:

$ mountpoint /var/log/audit

      Is it the case that "/var/log/audit is not a mountpoint" is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-partition_for_var_tmp_question:question:1">
          <ocil:question_text>Verify that a separate file system/partition has been created for /var/tmp with the following command:

$ mountpoint /var/tmp

      Is it the case that "/var/tmp is not a mountpoint" is returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-partition_for_web_content_question:question:1">
          <ocil:question_text>To verify that each web content directory exists on separate partitions,
run the following command:
$ grep `grep -i documentroot /etc/httpd/conf/httpd.conf | awk -F'"' '{print $2}'` /etc/fstab
Each of the corresponding DocumentRoot entries should have a
corresponding entry in /etc/fstab.
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-postfix_client_configure_mail_alias_question:question:1">
          <ocil:question_text>Find the list of alias maps used by the Postfix mail server:
$ sudo postconf alias_maps
Query the Postfix alias maps for an alias for the root user:
$ sudo postmap -q root hash:/etc/aliases
The output should return an alias.
      Is it the case that the alias is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-postfix_client_configure_mail_alias_postmaster_question:question:1">
          <ocil:question_text>Find the list of alias maps used by the Postfix mail server:
$ sudo postconf alias_maps
Query the Postfix alias maps for an alias for the postmaster user:
$ sudo postmap -q postmaster hash:/etc/aliases
The output should return root.
      Is it the case that the alias is not set or is not root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-postfix_client_configure_relayhost_question:question:1">
          <ocil:question_text>Run the following command to ensure postfix routes mail to this system:
$ grep relayhost /etc/postfix/main.cf
If properly configured, the output should show only .
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-postfix_network_listening_disabled_question:question:1">
          <ocil:question_text>Run the following command to ensure postfix accepts mail messages from only the local system:
$ grep inet_interfaces /etc/postfix/main.cf
If properly configured, the output should show only .
      Is it the case that it does not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-postfix_prevent_unrestricted_relay_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to prevent unrestricted mail relaying,
run the following command:
$ sudo postconf -n smtpd_client_restrictions
      Is it the case that the "smtpd_client_restrictions" parameter contains any entries other than "permit_mynetworks" and "reject"?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-prefer_64bit_os_question:question:1">
          <ocil:question_text>To check if the installed Operating System is 64-bit, run the following command:
$ uname -m
The output should be one of the following: x86_64, aarch64, ppc64le or s390x.
If the output is i686 or i386 the operating system is 32-bit.
Check if the installed CPU supports 64-bit operating systems by running the following command:
$ lscpu | grep "CPU op-mode"
If the output contains 64bit, the CPU supports 64-bit operating systems.
      Is it the case that the installed operating system is 32-bit but the CPU supports operation in 64-bit?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-require_emergency_target_auth_question:question:1">
          <ocil:question_text>To check if authentication is required for emergency mode, run the following command:
$ grep sulogin /usr/lib/systemd/system/emergency.service
The output should be similar to the following, and the line must begin with
ExecStart and /usr/lib/systemd/systemd-sulogin-shell.
    ExecStart=-/usr/lib/systemd/systemd-sulogin-shell emergency

Then, check if the emergency target requires the emergency service:
Run the following command:
$ sudo grep Requires /usr/lib/systemd/system/emergency.target
The output should be the following:
Requires=emergency.service

Then, check if there is no custom emergency target configured in systemd configuration.
Run the following command:
$ sudo grep -r emergency.target /etc/systemd/system/
The output should be empty.

Then, check if there is no custom emergency service configured in systemd configuration.
Run the following command:
$ sudo grep -r emergency.service /etc/systemd/system/
The output should be empty.
      Is it the case that the output is different?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-require_singleuser_auth_question:question:1">
          <ocil:question_text>To check if authentication is required for single-user mode, run the following command:
$ grep sulogin /usr/lib/systemd/system/rescue.service
The output should be similar to the following, and the line must begin with
ExecStart and /sbin/sulogin.
    ExecStart=-/bin/sh -c "/sbin/sulogin; /usr/bin/systemctl --fail --no-block default"

In case the output does not match, check if the ExecStart directive is not overridden:
grep ExecStart /etc/systemd/system/rescue.service.d/*.conf
The output should contain two lines:
ExecStart=
ExecStart=-/bin/sh -c "/sbin/sulogin; /usr/bin/systemctl --fail --no-block default"



Then, verify that the rescue service is in the runlevel1.target.
Run the following command:
$ sudo grep "^Requires=.*rescue\.service" /usr/lib/systemd/system/runlevel1.target
The output should be the following:
Requires=sysinit.target rescue.service

Then, check if there is no custom runlevel1 target configured in systemd configuration.
Run the following command:
$ sudo grep -r "^runlevel1.target$" /etc/systemd/system
There should be no output.

Then, check if there is no custom rescue service configured in systemd configuration.
Run the following command:
$ sudo grep -r "^rescue.service$" /etc/systemd/system
There should be no output.
      Is it the case that the output is different?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-require_smb_client_signing_question:question:1">
          <ocil:question_text>To verify that Samba clients running smbclient must use packet signing, run the following command:
$ grep signing /etc/samba/smb.conf
The output should show:
client signing = mandatory
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-restrict_serial_port_logins_question:question:1">
          <ocil:question_text>To check for serial port entries which permit root login,
run the following command:
$ sudo grep ^ttyS/[0-9] /etc/securetty
If any output is returned, then root login over serial ports is permitted.
      Is it the case that root login over serial ports is permitted?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-root_path_default_question:question:1">
          <ocil:question_text>To view the root user's PATH, run the following command:
$ sudo env | grep PATH
If correctly configured, the PATH must: use vendor default settings,
have no empty entries, and have no entries beginning with a character
other than a slash (/).
      Is it the case that any of these conditions are not met?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-root_permissions_syslibrary_files_question:question:1">
          <ocil:question_text>Verify the system-wide shared library files are group-owned by root with the following command:

$ sudo find -L /lib /lib64 /usr/lib /usr/lib64 ! -group root -exec ls -l {} \;
      Is it the case that any system wide shared library file is returned and is not group-owned by root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rootfiles_configured_question:question:1">
          <ocil:question_text>Check the all files from /usr/share/rootfiles/ are overridden correctly.

    $ grep /usr/share/rootfiles/.bash_logout *.conf
    C /root/.bash_logout   600 root root - /usr/share/rootfiles/.bash_logout
    C /root/.bash_profile  600 root root - /usr/share/rootfiles/.bash_profile
    C /root/.bashrc        600 root root - /usr/share/rootfiles/.bashrc
    C /root/.cshrc         600 root root - /usr/share/rootfiles/.cshrc
    C /root/.tcshrc        600 root root - /usr/share/rootfiles/.tcshrc

      Is it the case that that rootfiles are not configured correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rpm_verify_hashes_question:question:1">
          <ocil:question_text>The following command will list which files on the system have file hashes different from what
is expected by the RPM database.
$ rpm -Va --noconfig | awk '$1 ~ /..5/'
      Is it the case that there is output?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rpm_verify_ownership_question:question:1">
          <ocil:question_text>The following command will list which files on the system have ownership different from what
is expected by the RPM database:
$ rpm -Va | rpm -Va --nofiledigest | awk '{ if (substr($0,6,1)=="U" || substr($0,7,1)=="G") print $NF }'
      Is it the case that there is output?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rpm_verify_permissions_question:question:1">
          <ocil:question_text>The following command will list which files on the system have permissions different from what
is expected by the RPM database:
$ rpm -Va | awk '{ if (substr($0,2,1)=="M") print $NF }'
      Is it the case that there is output?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rsyslog_cron_logging_question:question:1">
          <ocil:question_text>Verify that cron is logging to rsyslog,
run the following command:
grep -rni "cron\.\*" /etc/rsyslog.*
cron.*                                                  /var/log/cron
or
cron.* action(type="omfile" file="/var/log/cron")
      Is it the case that cron is not logging to rsyslog?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdriverauthmode_question:question:1">
          <ocil:question_text>Verify the operating system authenticates the remote logging server for off-loading audit logs with the following command:

$ sudo grep -i '$ActionSendStreamDriverAuthMode' /etc/rsyslog.conf /etc/rsyslog.d/*.conf
The output should be
$/etc/rsyslog.conf:$ActionSendStreamDriverAuthMode x509/name
      Is it the case that $ActionSendStreamDriverAuthMode in /etc/rsyslog.conf is not set to x509/name?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rsyslog_encrypt_offload_actionsendstreamdrivermode_question:question:1">
          <ocil:question_text>Verify the operating system encrypts audit records off-loaded onto a different system
or media from the system being audited with the following commands:

$ sudo grep -i '$ActionSendStreamDriverMode' /etc/rsyslog.conf /etc/rsyslog.d/*.conf

The output should be:

/etc/rsyslog.conf:$ActionSendStreamDriverMode 1
      Is it the case that rsyslogd ActionSendStreamDriverMode is not set to 1?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rsyslog_encrypt_offload_defaultnetstreamdriver_question:question:1">
          <ocil:question_text>Verify the operating system encrypts audit records off-loaded onto a different system
or media from the system being audited with the following commands:

$ sudo grep -i '$DefaultNetstreamDriver' /etc/rsyslog.conf /etc/rsyslog.d/*.conf

The output should be:

/etc/rsyslog.conf:$DefaultNetstreamDriver gtls
      Is it the case that rsyslogd DefaultNetstreamDriver not set to gtls?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rsyslog_filecreatemode_question:question:1">
          <ocil:question_text>Run the following command:
# grep ^\$FileCreateMode /etc/rsyslog.conf /etc/rsyslog.d/*.conf
Verify the output matches:
$FileCreateMode 0640
Should a site policy dictate less restrictive permissions, ensure to follow
said policy.
      Is it the case that $FileCreateMode is not set or is more permissive than 0640?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rsyslog_files_groupownership_question:question:1">
          <ocil:question_text>The group-owner of all log files written by rsyslog should be
root.
These log files are determined by the second part of each Rule line in
/etc/rsyslog.conf and typically all appear in /var/log.
To see the group-owner of a given log file, run the following command:
$ ls -l LOGFILE
      Is it the case that the group-owner is not correct?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rsyslog_files_ownership_question:question:1">
          <ocil:question_text>The owner of all log files written by rsyslog should be

root.

These log files are determined by the second part of each Rule line in
/etc/rsyslog.conf and typically all appear in /var/log.
To see the owner of a given log file, run the following command:
$ ls -l LOGFILE
      Is it the case that the owner is not correct?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rsyslog_files_permissions_question:question:1">
          <ocil:question_text>The file permissions for all log files written by rsyslog should
be set to 640, or more restrictive. These log files are determined by the
second part of each Rule line in /etc/rsyslog.conf and typically
all appear in /var/log. To see the permissions of a given log
file, run the following command:
$ ls -l LOGFILE
The permissions should be 640, or more restrictive.
      Is it the case that the permissions are not correct?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rsyslog_logging_configured_question:question:1">
          <ocil:question_text>Review the contents of the /etc/rsyslog.conf and /etc/rsyslog.d/*.conf
files to ensure appropriate logging is set. In addition, run the following command:
ls -l /var/log/
and verify that the log files are logging information
      Is it the case that no logging is configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rsyslog_nolisten_question:question:1">
          <ocil:question_text>Verify that the system is not accepting "rsyslog" messages from other systems unless it is
documented as a log aggregation server.
Display the contents of the rsyslog configuration files:
find /etc -maxdepth 2 -regex '/etc/rsyslog\(\.conf\|\.d\/.*\.conf\)' -exec cat '{}' \;

If any of the below lines are found, ask to see the documentation for the system being used
for log aggregation:

If using legacy syntax:
$ModLoad imtcp
$InputTCPServerRun port
$ModLoad imudp
$UDPServerRun port
$ModLoad imrelp
$InputRELPServerRun port

If using RainerScript syntax:
module(load="imtcp")
module(load="imudp")
input(type="imtcp" port="514")
input(type="imudp" port="514")

      Is it the case that rsyslog accepts remote messages and is not documented as a log aggregation system?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rsyslog_remote_access_monitoring_question:question:1">
          <ocil:question_text>To verify that remote access methods are logging to rsyslog,
run the following command:

grep -rE '(auth.\*|authpriv.\*|daemon.\*)' /etc/rsyslog.*

The output should contain auth.*, authpriv.*, and daemon.*
pointing to a log file.
      Is it the case that remote access methods are not logging to rsyslog?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rsyslog_remote_loghost_question:question:1">
          <ocil:question_text>To ensure logs are sent to a remote host, examine the file
/etc/rsyslog.conf.
If using UDP, a line similar to the following should be present:
 *.* @
or
*.* action(type="omfwd" ... target="" protocol="udp")
If using TCP, a line similar to the following should be present:
 *.* @@
or
*.* action(type="omfwd" ... target="" protocol="tcp")
If using RELP, a line similar to the following should be present:
 *.* :omrelp:
or
*.* action(type="omfwd" ... target="" protocol="relp")
      Is it the case that no evidence that the audit logs are being off-loaded to another system or media?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rsyslog_remote_tls_question:question:1">
          <ocil:question_text>To verify that rsyslog's Forwarding Output Module is configured
to use TLS for logging to remote server, run the following command:
$ grep omfwd /etc/rsyslog.conf /etc/rsyslog.d/*.conf
The output should include record similar to
action(type="omfwd" protocol="tcp" Target="&lt;remote system&gt;" port="6514"
    StreamDriver="gtls" StreamDriverMode="1" StreamDriverAuthMode="x509/name" streamdriver.CheckExtendedKeyPurpose="on")

where the &lt;remote system&gt; present in the configuration line above must be a valid IP address or a host name of the remote logging server.
      Is it the case that omfwd is not configured with gtls and AuthMode?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-rsyslog_remote_tls_cacert_question:question:1">
          <ocil:question_text>To verify that rsyslog's Forwarding Output Module has CA certificate
configured for its TLS connections to remote server, run the following command:
$ grep DefaultNetstreamDriverCAFile /etc/rsyslog.conf /etc/rsyslog.d/*.conf
The output should include record similar to
global(DefaultNetstreamDriverCAFile="/etc/pki/tls/cert.pem")
where the path to the CA file (/etc/pki/tls/cert.pem in case above) must point to the correct CA certificate.
      Is it the case that CA certificate for rsyslog remote logging via TLS is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_abrt_anon_write_question:question:1">
          <ocil:question_text>
Run the following command to determine if the abrt_anon_write SELinux boolean is disabled:
$ getsebool abrt_anon_write
If properly configured, the output should show the following:
abrt_anon_write --&gt; off
      Is it the case that abrt_anon_write is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_abrt_handle_event_question:question:1">
          <ocil:question_text>
Run the following command to determine if the abrt_handle_event SELinux boolean is disabled:
$ getsebool abrt_handle_event
If properly configured, the output should show the following:
abrt_handle_event --&gt; off
      Is it the case that abrt_handle_event is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_abrt_upload_watch_anon_write_question:question:1">
          <ocil:question_text>
Run the following command to determine if the abrt_upload_watch_anon_write SELinux boolean is disabled:
$ getsebool abrt_upload_watch_anon_write
If properly configured, the output should show the following:
abrt_upload_watch_anon_write --&gt; off
      Is it the case that abrt_upload_watch_anon_write is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_antivirus_can_scan_system_question:question:1">
          <ocil:question_text>
Run the following command to determine if the antivirus_can_scan_system SELinux boolean is enabled:
$ getsebool antivirus_can_scan_system
If properly configured, the output should show the following:
antivirus_can_scan_system --&gt; on
      Is it the case that antivirus_can_scan_system is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_antivirus_use_jit_question:question:1">
          <ocil:question_text>
Run the following command to determine if the antivirus_use_jit SELinux boolean is disabled:
$ getsebool antivirus_use_jit
If properly configured, the output should show the following:
antivirus_use_jit --&gt; off
      Is it the case that antivirus_use_jit is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_auditadm_exec_content_question:question:1">
          <ocil:question_text>
Run the following command to determine if the auditadm_exec_content SELinux boolean is enabled:
$ getsebool auditadm_exec_content
If properly configured, the output should show the following:
auditadm_exec_content --&gt; on
      Is it the case that auditadm_exec_content is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_authlogin_nsswitch_use_ldap_question:question:1">
          <ocil:question_text>
Run the following command to determine if the authlogin_nsswitch_use_ldap SELinux boolean is disabled:
$ getsebool authlogin_nsswitch_use_ldap
If properly configured, the output should show the following:
authlogin_nsswitch_use_ldap --&gt; off
      Is it the case that authlogin_nsswitch_use_ldap is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_authlogin_radius_question:question:1">
          <ocil:question_text>
Run the following command to determine if the authlogin_radius SELinux boolean is disabled:
$ getsebool authlogin_radius
If properly configured, the output should show the following:
authlogin_radius --&gt; off
      Is it the case that authlogin_radius is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_authlogin_yubikey_question:question:1">
          <ocil:question_text>
Run the following command to determine if the authlogin_yubikey SELinux boolean is disabled:
$ getsebool authlogin_yubikey
If properly configured, the output should show the following:
authlogin_yubikey --&gt; off
      Is it the case that authlogin_yubikey is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_awstats_purge_apache_log_files_question:question:1">
          <ocil:question_text>
Run the following command to determine if the awstats_purge_apache_log_files SELinux boolean is disabled:
$ getsebool awstats_purge_apache_log_files
If properly configured, the output should show the following:
awstats_purge_apache_log_files --&gt; off
      Is it the case that awstats_purge_apache_log_files is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_boinc_execmem_question:question:1">
          <ocil:question_text>
Run the following command to determine if the boinc_execmem SELinux boolean is disabled:
$ getsebool boinc_execmem
If properly configured, the output should show the following:
boinc_execmem --&gt; off
      Is it the case that boinc_execmem is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_cdrecord_read_content_question:question:1">
          <ocil:question_text>
Run the following command to determine if the cdrecord_read_content SELinux boolean is disabled:
$ getsebool cdrecord_read_content
If properly configured, the output should show the following:
cdrecord_read_content --&gt; off
      Is it the case that cdrecord_read_content is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_cluster_can_network_connect_question:question:1">
          <ocil:question_text>
Run the following command to determine if the cluster_can_network_connect SELinux boolean is disabled:
$ getsebool cluster_can_network_connect
If properly configured, the output should show the following:
cluster_can_network_connect --&gt; off
      Is it the case that cluster_can_network_connect is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_cluster_manage_all_files_question:question:1">
          <ocil:question_text>
Run the following command to determine if the cluster_manage_all_files SELinux boolean is disabled:
$ getsebool cluster_manage_all_files
If properly configured, the output should show the following:
cluster_manage_all_files --&gt; off
      Is it the case that cluster_manage_all_files is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_cluster_use_execmem_question:question:1">
          <ocil:question_text>
Run the following command to determine if the cluster_use_execmem SELinux boolean is disabled:
$ getsebool cluster_use_execmem
If properly configured, the output should show the following:
cluster_use_execmem --&gt; off
      Is it the case that cluster_use_execmem is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_cobbler_anon_write_question:question:1">
          <ocil:question_text>
Run the following command to determine if the cobbler_anon_write SELinux boolean is disabled:
$ getsebool cobbler_anon_write
If properly configured, the output should show the following:
cobbler_anon_write --&gt; off
      Is it the case that cobbler_anon_write is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_cobbler_can_network_connect_question:question:1">
          <ocil:question_text>
Run the following command to determine if the cobbler_can_network_connect SELinux boolean is disabled:
$ getsebool cobbler_can_network_connect
If properly configured, the output should show the following:
cobbler_can_network_connect --&gt; off
      Is it the case that cobbler_can_network_connect is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_cobbler_use_cifs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the cobbler_use_cifs SELinux boolean is disabled:
$ getsebool cobbler_use_cifs
If properly configured, the output should show the following:
cobbler_use_cifs --&gt; off
      Is it the case that cobbler_use_cifs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_cobbler_use_nfs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the cobbler_use_nfs SELinux boolean is disabled:
$ getsebool cobbler_use_nfs
If properly configured, the output should show the following:
cobbler_use_nfs --&gt; off
      Is it the case that cobbler_use_nfs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_collectd_tcp_network_connect_question:question:1">
          <ocil:question_text>
Run the following command to determine if the collectd_tcp_network_connect SELinux boolean is disabled:
$ getsebool collectd_tcp_network_connect
If properly configured, the output should show the following:
collectd_tcp_network_connect --&gt; off
      Is it the case that collectd_tcp_network_connect is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_condor_tcp_network_connect_question:question:1">
          <ocil:question_text>
Run the following command to determine if the condor_tcp_network_connect SELinux boolean is disabled:
$ getsebool condor_tcp_network_connect
If properly configured, the output should show the following:
condor_tcp_network_connect --&gt; off
      Is it the case that condor_tcp_network_connect is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_conman_can_network_question:question:1">
          <ocil:question_text>
Run the following command to determine if the conman_can_network SELinux boolean is disabled:
$ getsebool conman_can_network
If properly configured, the output should show the following:
conman_can_network --&gt; off
      Is it the case that conman_can_network is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_container_connect_any_question:question:1">
          <ocil:question_text>
Run the following command to determine if the container_connect_any SELinux boolean is disabled:
$ getsebool container_connect_any
If properly configured, the output should show the following:
container_connect_any --&gt; off
      Is it the case that container_connect_any is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_cron_can_relabel_question:question:1">
          <ocil:question_text>
Run the following command to determine if the cron_can_relabel SELinux boolean is disabled:
$ getsebool cron_can_relabel
If properly configured, the output should show the following:
cron_can_relabel --&gt; off
      Is it the case that cron_can_relabel is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_cron_system_cronjob_use_shares_question:question:1">
          <ocil:question_text>
Run the following command to determine if the cron_system_cronjob_use_shares SELinux boolean is disabled:
$ getsebool cron_system_cronjob_use_shares
If properly configured, the output should show the following:
cron_system_cronjob_use_shares --&gt; off
      Is it the case that cron_system_cronjob_use_shares is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_cron_userdomain_transition_question:question:1">
          <ocil:question_text>
Run the following command to determine if the cron_userdomain_transition SELinux boolean is enabled:
$ getsebool cron_userdomain_transition
If properly configured, the output should show the following:
cron_userdomain_transition --&gt; on
      Is it the case that cron_userdomain_transition is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_cups_execmem_question:question:1">
          <ocil:question_text>
Run the following command to determine if the cups_execmem SELinux boolean is disabled:
$ getsebool cups_execmem
If properly configured, the output should show the following:
cups_execmem --&gt; off
      Is it the case that cups_execmem is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_cvs_read_shadow_question:question:1">
          <ocil:question_text>
Run the following command to determine if the cvs_read_shadow SELinux boolean is disabled:
$ getsebool cvs_read_shadow
If properly configured, the output should show the following:
cvs_read_shadow --&gt; off
      Is it the case that cvs_read_shadow is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_daemons_dump_core_question:question:1">
          <ocil:question_text>
Run the following command to determine if the daemons_dump_core SELinux boolean is disabled:
$ getsebool daemons_dump_core
If properly configured, the output should show the following:
daemons_dump_core --&gt; off
      Is it the case that daemons_dump_core is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_daemons_enable_cluster_mode_question:question:1">
          <ocil:question_text>
Run the following command to determine if the daemons_enable_cluster_mode SELinux boolean is disabled:
$ getsebool daemons_enable_cluster_mode
If properly configured, the output should show the following:
daemons_enable_cluster_mode --&gt; off
      Is it the case that daemons_enable_cluster_mode is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_daemons_use_tcp_wrapper_question:question:1">
          <ocil:question_text>
Run the following command to determine if the daemons_use_tcp_wrapper SELinux boolean is disabled:
$ getsebool daemons_use_tcp_wrapper
If properly configured, the output should show the following:
daemons_use_tcp_wrapper --&gt; off
      Is it the case that daemons_use_tcp_wrapper is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_daemons_use_tty_question:question:1">
          <ocil:question_text>
Run the following command to determine if the daemons_use_tty SELinux boolean is disabled:
$ getsebool daemons_use_tty
If properly configured, the output should show the following:
daemons_use_tty --&gt; off
      Is it the case that daemons_use_tty is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_dbadm_exec_content_question:question:1">
          <ocil:question_text>
Run the following command to determine if the dbadm_exec_content SELinux boolean is enabled:
$ getsebool dbadm_exec_content
If properly configured, the output should show the following:
dbadm_exec_content --&gt; on
      Is it the case that dbadm_exec_content is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_dbadm_manage_user_files_question:question:1">
          <ocil:question_text>
Run the following command to determine if the dbadm_manage_user_files SELinux boolean is disabled:
$ getsebool dbadm_manage_user_files
If properly configured, the output should show the following:
dbadm_manage_user_files --&gt; off
      Is it the case that dbadm_manage_user_files is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_dbadm_read_user_files_question:question:1">
          <ocil:question_text>
Run the following command to determine if the dbadm_read_user_files SELinux boolean is disabled:
$ getsebool dbadm_read_user_files
If properly configured, the output should show the following:
dbadm_read_user_files --&gt; off
      Is it the case that dbadm_read_user_files is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_deny_execmem_question:question:1">
          <ocil:question_text>
Run the following command to get the current configured value for deny_execmem
SELinux boolean:
$ getsebool deny_execmem
The expected cofiguration is .
"on" means true, and "off" means false
      Is it the case that deny_execmem is not set as expected?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_deny_ptrace_question:question:1">
          <ocil:question_text>
Run the following command to determine if the deny_ptrace SELinux boolean is disabled:
$ getsebool deny_ptrace
If properly configured, the output should show the following:
deny_ptrace --&gt; off
      Is it the case that deny_ptrace is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_dhcpc_exec_iptables_question:question:1">
          <ocil:question_text>
Run the following command to determine if the dhcpc_exec_iptables SELinux boolean is disabled:
$ getsebool dhcpc_exec_iptables
If properly configured, the output should show the following:
dhcpc_exec_iptables --&gt; off
      Is it the case that dhcpc_exec_iptables is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_dhcpd_use_ldap_question:question:1">
          <ocil:question_text>
Run the following command to determine if the dhcpd_use_ldap SELinux boolean is disabled:
$ getsebool dhcpd_use_ldap
If properly configured, the output should show the following:
dhcpd_use_ldap --&gt; off
      Is it the case that dhcpd_use_ldap is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_domain_fd_use_question:question:1">
          <ocil:question_text>
Run the following command to determine if the domain_fd_use SELinux boolean is enabled:
$ getsebool domain_fd_use
If properly configured, the output should show the following:
domain_fd_use --&gt; on
      Is it the case that domain_fd_use is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_domain_kernel_load_modules_question:question:1">
          <ocil:question_text>
Run the following command to determine if the domain_kernel_load_modules SELinux boolean is disabled:
$ getsebool domain_kernel_load_modules
If properly configured, the output should show the following:
domain_kernel_load_modules --&gt; off
      Is it the case that domain_kernel_load_modules is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_entropyd_use_audio_question:question:1">
          <ocil:question_text>
Run the following command to determine if the entropyd_use_audio SELinux boolean is disabled:
$ getsebool entropyd_use_audio
If properly configured, the output should show the following:
entropyd_use_audio --&gt; off
      Is it the case that entropyd_use_audio is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_exim_can_connect_db_question:question:1">
          <ocil:question_text>
Run the following command to determine if the exim_can_connect_db SELinux boolean is disabled:
$ getsebool exim_can_connect_db
If properly configured, the output should show the following:
exim_can_connect_db --&gt; off
      Is it the case that exim_can_connect_db is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_exim_manage_user_files_question:question:1">
          <ocil:question_text>
Run the following command to determine if the exim_manage_user_files SELinux boolean is disabled:
$ getsebool exim_manage_user_files
If properly configured, the output should show the following:
exim_manage_user_files --&gt; off
      Is it the case that exim_manage_user_files is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_exim_read_user_files_question:question:1">
          <ocil:question_text>
Run the following command to determine if the exim_read_user_files SELinux boolean is disabled:
$ getsebool exim_read_user_files
If properly configured, the output should show the following:
exim_read_user_files --&gt; off
      Is it the case that exim_read_user_files is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_fcron_crond_question:question:1">
          <ocil:question_text>
Run the following command to determine if the fcron_crond SELinux boolean is disabled:
$ getsebool fcron_crond
If properly configured, the output should show the following:
fcron_crond --&gt; off
      Is it the case that fcron_crond is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_fenced_can_network_connect_question:question:1">
          <ocil:question_text>
Run the following command to determine if the fenced_can_network_connect SELinux boolean is disabled:
$ getsebool fenced_can_network_connect
If properly configured, the output should show the following:
fenced_can_network_connect --&gt; off
      Is it the case that fenced_can_network_connect is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_fenced_can_ssh_question:question:1">
          <ocil:question_text>
Run the following command to determine if the fenced_can_ssh SELinux boolean is disabled:
$ getsebool fenced_can_ssh
If properly configured, the output should show the following:
fenced_can_ssh --&gt; off
      Is it the case that fenced_can_ssh is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_fips_mode_question:question:1">
          <ocil:question_text>
Run the following command to determine if the fips_mode SELinux boolean is enabled:
$ getsebool fips_mode
If properly configured, the output should show the following:
fips_mode --&gt; on
      Is it the case that fips_mode is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_ftpd_anon_write_question:question:1">
          <ocil:question_text>
Run the following command to determine if the ftpd_anon_write SELinux boolean is disabled:
$ getsebool ftpd_anon_write
If properly configured, the output should show the following:
ftpd_anon_write --&gt; off
      Is it the case that ftpd_anon_write is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_ftpd_connect_all_unreserved_question:question:1">
          <ocil:question_text>
Run the following command to determine if the ftpd_connect_all_unreserved SELinux boolean is disabled:
$ getsebool ftpd_connect_all_unreserved
If properly configured, the output should show the following:
ftpd_connect_all_unreserved --&gt; off
      Is it the case that ftpd_connect_all_unreserved is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_ftpd_connect_db_question:question:1">
          <ocil:question_text>
Run the following command to determine if the ftpd_connect_db SELinux boolean is disabled:
$ getsebool ftpd_connect_db
If properly configured, the output should show the following:
ftpd_connect_db --&gt; off
      Is it the case that ftpd_connect_db is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_ftpd_full_access_question:question:1">
          <ocil:question_text>
Run the following command to determine if the ftpd_full_access SELinux boolean is disabled:
$ getsebool ftpd_full_access
If properly configured, the output should show the following:
ftpd_full_access --&gt; off
      Is it the case that ftpd_full_access is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_ftpd_use_cifs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the ftpd_use_cifs SELinux boolean is disabled:
$ getsebool ftpd_use_cifs
If properly configured, the output should show the following:
ftpd_use_cifs --&gt; off
      Is it the case that ftpd_use_cifs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_ftpd_use_fusefs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the ftpd_use_fusefs SELinux boolean is disabled:
$ getsebool ftpd_use_fusefs
If properly configured, the output should show the following:
ftpd_use_fusefs --&gt; off
      Is it the case that ftpd_use_fusefs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_ftpd_use_nfs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the ftpd_use_nfs SELinux boolean is disabled:
$ getsebool ftpd_use_nfs
If properly configured, the output should show the following:
ftpd_use_nfs --&gt; off
      Is it the case that ftpd_use_nfs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_ftpd_use_passive_mode_question:question:1">
          <ocil:question_text>
Run the following command to determine if the ftpd_use_passive_mode SELinux boolean is disabled:
$ getsebool ftpd_use_passive_mode
If properly configured, the output should show the following:
ftpd_use_passive_mode --&gt; off
      Is it the case that ftpd_use_passive_mode is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_git_cgi_enable_homedirs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the git_cgi_enable_homedirs SELinux boolean is disabled:
$ getsebool git_cgi_enable_homedirs
If properly configured, the output should show the following:
git_cgi_enable_homedirs --&gt; off
      Is it the case that git_cgi_enable_homedirs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_git_cgi_use_cifs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the git_cgi_use_cifs SELinux boolean is disabled:
$ getsebool git_cgi_use_cifs
If properly configured, the output should show the following:
git_cgi_use_cifs --&gt; off
      Is it the case that git_cgi_use_cifs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_git_cgi_use_nfs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the git_cgi_use_nfs SELinux boolean is disabled:
$ getsebool git_cgi_use_nfs
If properly configured, the output should show the following:
git_cgi_use_nfs --&gt; off
      Is it the case that git_cgi_use_nfs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_git_session_bind_all_unreserved_ports_question:question:1">
          <ocil:question_text>
Run the following command to determine if the git_session_bind_all_unreserved_ports SELinux boolean is disabled:
$ getsebool git_session_bind_all_unreserved_ports
If properly configured, the output should show the following:
git_session_bind_all_unreserved_ports --&gt; off
      Is it the case that git_session_bind_all_unreserved_ports is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_git_session_users_question:question:1">
          <ocil:question_text>
Run the following command to determine if the git_session_users SELinux boolean is disabled:
$ getsebool git_session_users
If properly configured, the output should show the following:
git_session_users --&gt; off
      Is it the case that git_session_users is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_git_system_enable_homedirs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the git_system_enable_homedirs SELinux boolean is disabled:
$ getsebool git_system_enable_homedirs
If properly configured, the output should show the following:
git_system_enable_homedirs --&gt; off
      Is it the case that git_system_enable_homedirs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_git_system_use_cifs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the git_system_use_cifs SELinux boolean is disabled:
$ getsebool git_system_use_cifs
If properly configured, the output should show the following:
git_system_use_cifs --&gt; off
      Is it the case that git_system_use_cifs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_git_system_use_nfs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the git_system_use_nfs SELinux boolean is disabled:
$ getsebool git_system_use_nfs
If properly configured, the output should show the following:
git_system_use_nfs --&gt; off
      Is it the case that git_system_use_nfs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_gitosis_can_sendmail_question:question:1">
          <ocil:question_text>
Run the following command to determine if the gitosis_can_sendmail SELinux boolean is disabled:
$ getsebool gitosis_can_sendmail
If properly configured, the output should show the following:
gitosis_can_sendmail --&gt; off
      Is it the case that gitosis_can_sendmail is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_glance_api_can_network_question:question:1">
          <ocil:question_text>
Run the following command to determine if the glance_api_can_network SELinux boolean is disabled:
$ getsebool glance_api_can_network
If properly configured, the output should show the following:
glance_api_can_network --&gt; off
      Is it the case that glance_api_can_network is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_glance_use_execmem_question:question:1">
          <ocil:question_text>
Run the following command to determine if the glance_use_execmem SELinux boolean is disabled:
$ getsebool glance_use_execmem
If properly configured, the output should show the following:
glance_use_execmem --&gt; off
      Is it the case that glance_use_execmem is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_glance_use_fusefs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the glance_use_fusefs SELinux boolean is disabled:
$ getsebool glance_use_fusefs
If properly configured, the output should show the following:
glance_use_fusefs --&gt; off
      Is it the case that glance_use_fusefs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_global_ssp_question:question:1">
          <ocil:question_text>
Run the following command to determine if the global_ssp SELinux boolean is disabled:
$ getsebool global_ssp
If properly configured, the output should show the following:
global_ssp --&gt; off
      Is it the case that global_ssp is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_gluster_anon_write_question:question:1">
          <ocil:question_text>
Run the following command to determine if the gluster_anon_write SELinux boolean is disabled:
$ getsebool gluster_anon_write
If properly configured, the output should show the following:
gluster_anon_write --&gt; off
      Is it the case that gluster_anon_write is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_gluster_export_all_ro_question:question:1">
          <ocil:question_text>
Run the following command to determine if the gluster_export_all_ro SELinux boolean is disabled:
$ getsebool gluster_export_all_ro
If properly configured, the output should show the following:
gluster_export_all_ro --&gt; off
      Is it the case that gluster_export_all_ro is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_gluster_export_all_rw_question:question:1">
          <ocil:question_text>
Run the following command to determine if the gluster_export_all_rw SELinux boolean is disabled:
$ getsebool gluster_export_all_rw
If properly configured, the output should show the following:
gluster_export_all_rw --&gt; off
      Is it the case that gluster_export_all_rw is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_gpg_web_anon_write_question:question:1">
          <ocil:question_text>
Run the following command to determine if the gpg_web_anon_write SELinux boolean is disabled:
$ getsebool gpg_web_anon_write
If properly configured, the output should show the following:
gpg_web_anon_write --&gt; off
      Is it the case that gpg_web_anon_write is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_gssd_read_tmp_question:question:1">
          <ocil:question_text>
Run the following command to determine if the gssd_read_tmp SELinux boolean is enabled:
$ getsebool gssd_read_tmp
If properly configured, the output should show the following:
gssd_read_tmp --&gt; on
      Is it the case that gssd_read_tmp is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_guest_exec_content_question:question:1">
          <ocil:question_text>
Run the following command to determine if the guest_exec_content SELinux boolean is disabled:
$ getsebool guest_exec_content
If properly configured, the output should show the following:
guest_exec_content --&gt; off
      Is it the case that guest_exec_content is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_haproxy_connect_any_question:question:1">
          <ocil:question_text>
Run the following command to determine if the haproxy_connect_any SELinux boolean is disabled:
$ getsebool haproxy_connect_any
If properly configured, the output should show the following:
haproxy_connect_any --&gt; off
      Is it the case that haproxy_connect_any is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_anon_write_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_anon_write SELinux boolean is disabled:
$ getsebool httpd_anon_write
If properly configured, the output should show the following:
httpd_anon_write --&gt; off
      Is it the case that httpd_anon_write is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_builtin_scripting_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_builtin_scripting SELinux boolean is disabled:
$ getsebool httpd_builtin_scripting
If properly configured, the output should show the following:
httpd_builtin_scripting --&gt; off
      Is it the case that httpd_builtin_scripting is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_can_check_spam_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_can_check_spam SELinux boolean is disabled:
$ getsebool httpd_can_check_spam
If properly configured, the output should show the following:
httpd_can_check_spam --&gt; off
      Is it the case that httpd_can_check_spam is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_can_connect_ftp_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_can_connect_ftp SELinux boolean is disabled:
$ getsebool httpd_can_connect_ftp
If properly configured, the output should show the following:
httpd_can_connect_ftp --&gt; off
      Is it the case that httpd_can_connect_ftp is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_can_connect_ldap_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_can_connect_ldap SELinux boolean is disabled:
$ getsebool httpd_can_connect_ldap
If properly configured, the output should show the following:
httpd_can_connect_ldap --&gt; off
      Is it the case that httpd_can_connect_ldap is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_can_connect_mythtv_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_can_connect_mythtv SELinux boolean is disabled:
$ getsebool httpd_can_connect_mythtv
If properly configured, the output should show the following:
httpd_can_connect_mythtv --&gt; off
      Is it the case that httpd_can_connect_mythtv is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_can_connect_zabbix_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_can_connect_zabbix SELinux boolean is disabled:
$ getsebool httpd_can_connect_zabbix
If properly configured, the output should show the following:
httpd_can_connect_zabbix --&gt; off
      Is it the case that httpd_can_connect_zabbix is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_can_network_connect_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_can_network_connect SELinux boolean is disabled:
$ getsebool httpd_can_network_connect
If properly configured, the output should show the following:
httpd_can_network_connect --&gt; off
      Is it the case that httpd_can_network_connect is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_can_network_connect_cobbler_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_can_network_connect_cobbler SELinux boolean is disabled:
$ getsebool httpd_can_network_connect_cobbler
If properly configured, the output should show the following:
httpd_can_network_connect_cobbler --&gt; off
      Is it the case that httpd_can_network_connect_cobbler is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_can_network_connect_db_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_can_network_connect_db SELinux boolean is disabled:
$ getsebool httpd_can_network_connect_db
If properly configured, the output should show the following:
httpd_can_network_connect_db --&gt; off
      Is it the case that httpd_can_network_connect_db is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_can_network_memcache_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_can_network_memcache SELinux boolean is disabled:
$ getsebool httpd_can_network_memcache
If properly configured, the output should show the following:
httpd_can_network_memcache --&gt; off
      Is it the case that httpd_can_network_memcache is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_can_network_relay_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_can_network_relay SELinux boolean is disabled:
$ getsebool httpd_can_network_relay
If properly configured, the output should show the following:
httpd_can_network_relay --&gt; off
      Is it the case that httpd_can_network_relay is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_can_sendmail_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_can_sendmail SELinux boolean is disabled:
$ getsebool httpd_can_sendmail
If properly configured, the output should show the following:
httpd_can_sendmail --&gt; off
      Is it the case that httpd_can_sendmail is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_dbus_avahi_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_dbus_avahi SELinux boolean is disabled:
$ getsebool httpd_dbus_avahi
If properly configured, the output should show the following:
httpd_dbus_avahi --&gt; off
      Is it the case that httpd_dbus_avahi is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_dbus_sssd_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_dbus_sssd SELinux boolean is disabled:
$ getsebool httpd_dbus_sssd
If properly configured, the output should show the following:
httpd_dbus_sssd --&gt; off
      Is it the case that httpd_dbus_sssd is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_dontaudit_search_dirs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_dontaudit_search_dirs SELinux boolean is disabled:
$ getsebool httpd_dontaudit_search_dirs
If properly configured, the output should show the following:
httpd_dontaudit_search_dirs --&gt; off
      Is it the case that httpd_dontaudit_search_dirs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_enable_cgi_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_enable_cgi SELinux boolean is disabled:
$ getsebool httpd_enable_cgi
If properly configured, the output should show the following:
httpd_enable_cgi --&gt; off
      Is it the case that httpd_enable_cgi is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_enable_ftp_server_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_enable_ftp_server SELinux boolean is disabled:
$ getsebool httpd_enable_ftp_server
If properly configured, the output should show the following:
httpd_enable_ftp_server --&gt; off
      Is it the case that httpd_enable_ftp_server is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_enable_homedirs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_enable_homedirs SELinux boolean is disabled:
$ getsebool httpd_enable_homedirs
If properly configured, the output should show the following:
httpd_enable_homedirs --&gt; off
      Is it the case that httpd_enable_homedirs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_execmem_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_execmem SELinux boolean is disabled:
$ getsebool httpd_execmem
If properly configured, the output should show the following:
httpd_execmem --&gt; off
      Is it the case that httpd_execmem is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_graceful_shutdown_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_graceful_shutdown SELinux boolean is enabled:
$ getsebool httpd_graceful_shutdown
If properly configured, the output should show the following:
httpd_graceful_shutdown --&gt; on
      Is it the case that httpd_graceful_shutdown is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_manage_ipa_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_manage_ipa SELinux boolean is disabled:
$ getsebool httpd_manage_ipa
If properly configured, the output should show the following:
httpd_manage_ipa --&gt; off
      Is it the case that httpd_manage_ipa is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_mod_auth_ntlm_winbind_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_mod_auth_ntlm_winbind SELinux boolean is disabled:
$ getsebool httpd_mod_auth_ntlm_winbind
If properly configured, the output should show the following:
httpd_mod_auth_ntlm_winbind --&gt; off
      Is it the case that httpd_mod_auth_ntlm_winbind is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_mod_auth_pam_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_mod_auth_pam SELinux boolean is disabled:
$ getsebool httpd_mod_auth_pam
If properly configured, the output should show the following:
httpd_mod_auth_pam --&gt; off
      Is it the case that httpd_mod_auth_pam is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_read_user_content_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_read_user_content SELinux boolean is disabled:
$ getsebool httpd_read_user_content
If properly configured, the output should show the following:
httpd_read_user_content --&gt; off
      Is it the case that httpd_read_user_content is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_run_ipa_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_run_ipa SELinux boolean is disabled:
$ getsebool httpd_run_ipa
If properly configured, the output should show the following:
httpd_run_ipa --&gt; off
      Is it the case that httpd_run_ipa is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_run_preupgrade_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_run_preupgrade SELinux boolean is disabled:
$ getsebool httpd_run_preupgrade
If properly configured, the output should show the following:
httpd_run_preupgrade --&gt; off
      Is it the case that httpd_run_preupgrade is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_run_stickshift_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_run_stickshift SELinux boolean is disabled:
$ getsebool httpd_run_stickshift
If properly configured, the output should show the following:
httpd_run_stickshift --&gt; off
      Is it the case that httpd_run_stickshift is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_serve_cobbler_files_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_serve_cobbler_files SELinux boolean is disabled:
$ getsebool httpd_serve_cobbler_files
If properly configured, the output should show the following:
httpd_serve_cobbler_files --&gt; off
      Is it the case that httpd_serve_cobbler_files is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_setrlimit_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_setrlimit SELinux boolean is disabled:
$ getsebool httpd_setrlimit
If properly configured, the output should show the following:
httpd_setrlimit --&gt; off
      Is it the case that httpd_setrlimit is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_ssi_exec_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_ssi_exec SELinux boolean is disabled:
$ getsebool httpd_ssi_exec
If properly configured, the output should show the following:
httpd_ssi_exec --&gt; off
      Is it the case that httpd_ssi_exec is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_sys_script_anon_write_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_sys_script_anon_write SELinux boolean is disabled:
$ getsebool httpd_sys_script_anon_write
If properly configured, the output should show the following:
httpd_sys_script_anon_write --&gt; off
      Is it the case that httpd_sys_script_anon_write is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_tmp_exec_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_tmp_exec SELinux boolean is disabled:
$ getsebool httpd_tmp_exec
If properly configured, the output should show the following:
httpd_tmp_exec --&gt; off
      Is it the case that httpd_tmp_exec is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_tty_comm_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_tty_comm SELinux boolean is disabled:
$ getsebool httpd_tty_comm
If properly configured, the output should show the following:
httpd_tty_comm --&gt; off
      Is it the case that httpd_tty_comm is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_unified_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_unified SELinux boolean is disabled:
$ getsebool httpd_unified
If properly configured, the output should show the following:
httpd_unified --&gt; off
      Is it the case that httpd_unified is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_use_cifs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_use_cifs SELinux boolean is disabled:
$ getsebool httpd_use_cifs
If properly configured, the output should show the following:
httpd_use_cifs --&gt; off
      Is it the case that httpd_use_cifs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_use_fusefs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_use_fusefs SELinux boolean is disabled:
$ getsebool httpd_use_fusefs
If properly configured, the output should show the following:
httpd_use_fusefs --&gt; off
      Is it the case that httpd_use_fusefs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_use_gpg_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_use_gpg SELinux boolean is disabled:
$ getsebool httpd_use_gpg
If properly configured, the output should show the following:
httpd_use_gpg --&gt; off
      Is it the case that httpd_use_gpg is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_use_nfs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_use_nfs SELinux boolean is disabled:
$ getsebool httpd_use_nfs
If properly configured, the output should show the following:
httpd_use_nfs --&gt; off
      Is it the case that httpd_use_nfs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_use_openstack_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_use_openstack SELinux boolean is disabled:
$ getsebool httpd_use_openstack
If properly configured, the output should show the following:
httpd_use_openstack --&gt; off
      Is it the case that httpd_use_openstack is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_use_sasl_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_use_sasl SELinux boolean is disabled:
$ getsebool httpd_use_sasl
If properly configured, the output should show the following:
httpd_use_sasl --&gt; off
      Is it the case that httpd_use_sasl is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_httpd_verify_dns_question:question:1">
          <ocil:question_text>
Run the following command to determine if the httpd_verify_dns SELinux boolean is disabled:
$ getsebool httpd_verify_dns
If properly configured, the output should show the following:
httpd_verify_dns --&gt; off
      Is it the case that httpd_verify_dns is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_icecast_use_any_tcp_ports_question:question:1">
          <ocil:question_text>
Run the following command to determine if the icecast_use_any_tcp_ports SELinux boolean is disabled:
$ getsebool icecast_use_any_tcp_ports
If properly configured, the output should show the following:
icecast_use_any_tcp_ports --&gt; off
      Is it the case that icecast_use_any_tcp_ports is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_irc_use_any_tcp_ports_question:question:1">
          <ocil:question_text>
Run the following command to determine if the irc_use_any_tcp_ports SELinux boolean is disabled:
$ getsebool irc_use_any_tcp_ports
If properly configured, the output should show the following:
irc_use_any_tcp_ports --&gt; off
      Is it the case that irc_use_any_tcp_ports is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_irssi_use_full_network_question:question:1">
          <ocil:question_text>
Run the following command to determine if the irssi_use_full_network SELinux boolean is disabled:
$ getsebool irssi_use_full_network
If properly configured, the output should show the following:
irssi_use_full_network --&gt; off
      Is it the case that irssi_use_full_network is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_kdumpgui_run_bootloader_question:question:1">
          <ocil:question_text>
Run the following command to determine if the kdumpgui_run_bootloader SELinux boolean is disabled:
$ getsebool kdumpgui_run_bootloader
If properly configured, the output should show the following:
kdumpgui_run_bootloader --&gt; off
      Is it the case that kdumpgui_run_bootloader is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_kerberos_enabled_question:question:1">
          <ocil:question_text>
Run the following command to determine if the kerberos_enabled SELinux boolean is enabled:
$ getsebool kerberos_enabled
If properly configured, the output should show the following:
kerberos_enabled --&gt; on
      Is it the case that kerberos_enabled is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_ksmtuned_use_cifs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the ksmtuned_use_cifs SELinux boolean is disabled:
$ getsebool ksmtuned_use_cifs
If properly configured, the output should show the following:
ksmtuned_use_cifs --&gt; off
      Is it the case that ksmtuned_use_cifs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_ksmtuned_use_nfs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the ksmtuned_use_nfs SELinux boolean is disabled:
$ getsebool ksmtuned_use_nfs
If properly configured, the output should show the following:
ksmtuned_use_nfs --&gt; off
      Is it the case that ksmtuned_use_nfs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_logadm_exec_content_question:question:1">
          <ocil:question_text>
Run the following command to determine if the logadm_exec_content SELinux boolean is enabled:
$ getsebool logadm_exec_content
If properly configured, the output should show the following:
logadm_exec_content --&gt; on
      Is it the case that logadm_exec_content is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_logging_syslogd_can_sendmail_question:question:1">
          <ocil:question_text>
Run the following command to determine if the logging_syslogd_can_sendmail SELinux boolean is disabled:
$ getsebool logging_syslogd_can_sendmail
If properly configured, the output should show the following:
logging_syslogd_can_sendmail --&gt; off
      Is it the case that logging_syslogd_can_sendmail is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_logging_syslogd_run_nagios_plugins_question:question:1">
          <ocil:question_text>
Run the following command to determine if the logging_syslogd_run_nagios_plugins SELinux boolean is disabled:
$ getsebool logging_syslogd_run_nagios_plugins
If properly configured, the output should show the following:
logging_syslogd_run_nagios_plugins --&gt; off
      Is it the case that logging_syslogd_run_nagios_plugins is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_logging_syslogd_use_tty_question:question:1">
          <ocil:question_text>
Run the following command to determine if the logging_syslogd_use_tty SELinux boolean is enabled:
$ getsebool logging_syslogd_use_tty
If properly configured, the output should show the following:
logging_syslogd_use_tty --&gt; on
      Is it the case that logging_syslogd_use_tty is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_login_console_enabled_question:question:1">
          <ocil:question_text>
Run the following command to determine if the login_console_enabled SELinux boolean is enabled:
$ getsebool login_console_enabled
If properly configured, the output should show the following:
login_console_enabled --&gt; on
      Is it the case that login_console_enabled is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_logrotate_use_nfs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the logrotate_use_nfs SELinux boolean is disabled:
$ getsebool logrotate_use_nfs
If properly configured, the output should show the following:
logrotate_use_nfs --&gt; off
      Is it the case that logrotate_use_nfs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_logwatch_can_network_connect_mail_question:question:1">
          <ocil:question_text>
Run the following command to determine if the logwatch_can_network_connect_mail SELinux boolean is disabled:
$ getsebool logwatch_can_network_connect_mail
If properly configured, the output should show the following:
logwatch_can_network_connect_mail --&gt; off
      Is it the case that logwatch_can_network_connect_mail is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_lsmd_plugin_connect_any_question:question:1">
          <ocil:question_text>
Run the following command to determine if the lsmd_plugin_connect_any SELinux boolean is disabled:
$ getsebool lsmd_plugin_connect_any
If properly configured, the output should show the following:
lsmd_plugin_connect_any --&gt; off
      Is it the case that lsmd_plugin_connect_any is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mailman_use_fusefs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mailman_use_fusefs SELinux boolean is disabled:
$ getsebool mailman_use_fusefs
If properly configured, the output should show the following:
mailman_use_fusefs --&gt; off
      Is it the case that mailman_use_fusefs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mcelog_client_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mcelog_client SELinux boolean is disabled:
$ getsebool mcelog_client
If properly configured, the output should show the following:
mcelog_client --&gt; off
      Is it the case that mcelog_client is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mcelog_exec_scripts_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mcelog_exec_scripts SELinux boolean is enabled:
$ getsebool mcelog_exec_scripts
If properly configured, the output should show the following:
mcelog_exec_scripts --&gt; on
      Is it the case that mcelog_exec_scripts is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mcelog_foreground_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mcelog_foreground SELinux boolean is disabled:
$ getsebool mcelog_foreground
If properly configured, the output should show the following:
mcelog_foreground --&gt; off
      Is it the case that mcelog_foreground is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mcelog_server_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mcelog_server SELinux boolean is disabled:
$ getsebool mcelog_server
If properly configured, the output should show the following:
mcelog_server --&gt; off
      Is it the case that mcelog_server is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_minidlna_read_generic_user_content_question:question:1">
          <ocil:question_text>
Run the following command to determine if the minidlna_read_generic_user_content SELinux boolean is disabled:
$ getsebool minidlna_read_generic_user_content
If properly configured, the output should show the following:
minidlna_read_generic_user_content --&gt; off
      Is it the case that minidlna_read_generic_user_content is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mmap_low_allowed_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mmap_low_allowed SELinux boolean is disabled:
$ getsebool mmap_low_allowed
If properly configured, the output should show the following:
mmap_low_allowed --&gt; off
      Is it the case that mmap_low_allowed is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mock_enable_homedirs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mock_enable_homedirs SELinux boolean is disabled:
$ getsebool mock_enable_homedirs
If properly configured, the output should show the following:
mock_enable_homedirs --&gt; off
      Is it the case that mock_enable_homedirs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mount_anyfile_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mount_anyfile SELinux boolean is enabled:
$ getsebool mount_anyfile
If properly configured, the output should show the following:
mount_anyfile --&gt; on
      Is it the case that mount_anyfile is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mozilla_plugin_bind_unreserved_ports_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mozilla_plugin_bind_unreserved_ports SELinux boolean is disabled:
$ getsebool mozilla_plugin_bind_unreserved_ports
If properly configured, the output should show the following:
mozilla_plugin_bind_unreserved_ports --&gt; off
      Is it the case that mozilla_plugin_bind_unreserved_ports is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mozilla_plugin_can_network_connect_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mozilla_plugin_can_network_connect SELinux boolean is disabled:
$ getsebool mozilla_plugin_can_network_connect
If properly configured, the output should show the following:
mozilla_plugin_can_network_connect --&gt; off
      Is it the case that mozilla_plugin_can_network_connect is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mozilla_plugin_use_bluejeans_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mozilla_plugin_use_bluejeans SELinux boolean is disabled:
$ getsebool mozilla_plugin_use_bluejeans
If properly configured, the output should show the following:
mozilla_plugin_use_bluejeans --&gt; off
      Is it the case that mozilla_plugin_use_bluejeans is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mozilla_plugin_use_gps_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mozilla_plugin_use_gps SELinux boolean is disabled:
$ getsebool mozilla_plugin_use_gps
If properly configured, the output should show the following:
mozilla_plugin_use_gps --&gt; off
      Is it the case that mozilla_plugin_use_gps is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mozilla_plugin_use_spice_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mozilla_plugin_use_spice SELinux boolean is disabled:
$ getsebool mozilla_plugin_use_spice
If properly configured, the output should show the following:
mozilla_plugin_use_spice --&gt; off
      Is it the case that mozilla_plugin_use_spice is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mozilla_read_content_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mozilla_read_content SELinux boolean is disabled:
$ getsebool mozilla_read_content
If properly configured, the output should show the following:
mozilla_read_content --&gt; off
      Is it the case that mozilla_read_content is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mpd_enable_homedirs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mpd_enable_homedirs SELinux boolean is disabled:
$ getsebool mpd_enable_homedirs
If properly configured, the output should show the following:
mpd_enable_homedirs --&gt; off
      Is it the case that mpd_enable_homedirs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mpd_use_cifs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mpd_use_cifs SELinux boolean is disabled:
$ getsebool mpd_use_cifs
If properly configured, the output should show the following:
mpd_use_cifs --&gt; off
      Is it the case that mpd_use_cifs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mpd_use_nfs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mpd_use_nfs SELinux boolean is disabled:
$ getsebool mpd_use_nfs
If properly configured, the output should show the following:
mpd_use_nfs --&gt; off
      Is it the case that mpd_use_nfs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mplayer_execstack_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mplayer_execstack SELinux boolean is disabled:
$ getsebool mplayer_execstack
If properly configured, the output should show the following:
mplayer_execstack --&gt; off
      Is it the case that mplayer_execstack is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_mysql_connect_any_question:question:1">
          <ocil:question_text>
Run the following command to determine if the mysql_connect_any SELinux boolean is disabled:
$ getsebool mysql_connect_any
If properly configured, the output should show the following:
mysql_connect_any --&gt; off
      Is it the case that mysql_connect_any is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_nagios_run_pnp4nagios_question:question:1">
          <ocil:question_text>
Run the following command to determine if the nagios_run_pnp4nagios SELinux boolean is disabled:
$ getsebool nagios_run_pnp4nagios
If properly configured, the output should show the following:
nagios_run_pnp4nagios --&gt; off
      Is it the case that nagios_run_pnp4nagios is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_nagios_run_sudo_question:question:1">
          <ocil:question_text>
Run the following command to determine if the nagios_run_sudo SELinux boolean is disabled:
$ getsebool nagios_run_sudo
If properly configured, the output should show the following:
nagios_run_sudo --&gt; off
      Is it the case that nagios_run_sudo is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_named_tcp_bind_http_port_question:question:1">
          <ocil:question_text>
Run the following command to determine if the named_tcp_bind_http_port SELinux boolean is disabled:
$ getsebool named_tcp_bind_http_port
If properly configured, the output should show the following:
named_tcp_bind_http_port --&gt; off
      Is it the case that named_tcp_bind_http_port is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_named_write_master_zones_question:question:1">
          <ocil:question_text>
Run the following command to determine if the named_write_master_zones SELinux boolean is disabled:
$ getsebool named_write_master_zones
If properly configured, the output should show the following:
named_write_master_zones --&gt; off
      Is it the case that named_write_master_zones is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_neutron_can_network_question:question:1">
          <ocil:question_text>
Run the following command to determine if the neutron_can_network SELinux boolean is disabled:
$ getsebool neutron_can_network
If properly configured, the output should show the following:
neutron_can_network --&gt; off
      Is it the case that neutron_can_network is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_nfs_export_all_ro_question:question:1">
          <ocil:question_text>
Run the following command to determine if the nfs_export_all_ro SELinux boolean is enabled:
$ getsebool nfs_export_all_ro
If properly configured, the output should show the following:
nfs_export_all_ro --&gt; on
      Is it the case that nfs_export_all_ro is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_nfs_export_all_rw_question:question:1">
          <ocil:question_text>
Run the following command to determine if the nfs_export_all_rw SELinux boolean is enabled:
$ getsebool nfs_export_all_rw
If properly configured, the output should show the following:
nfs_export_all_rw --&gt; on
      Is it the case that nfs_export_all_rw is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_nfsd_anon_write_question:question:1">
          <ocil:question_text>
Run the following command to determine if the nfsd_anon_write SELinux boolean is disabled:
$ getsebool nfsd_anon_write
If properly configured, the output should show the following:
nfsd_anon_write --&gt; off
      Is it the case that nfsd_anon_write is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_nis_enabled_question:question:1">
          <ocil:question_text>
Run the following command to determine if the nis_enabled SELinux boolean is disabled:
$ getsebool nis_enabled
If properly configured, the output should show the following:
nis_enabled --&gt; off
      Is it the case that nis_enabled is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_nscd_use_shm_question:question:1">
          <ocil:question_text>
Run the following command to determine if the nscd_use_shm SELinux boolean is enabled:
$ getsebool nscd_use_shm
If properly configured, the output should show the following:
nscd_use_shm --&gt; on
      Is it the case that nscd_use_shm is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_openshift_use_nfs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the openshift_use_nfs SELinux boolean is disabled:
$ getsebool openshift_use_nfs
If properly configured, the output should show the following:
openshift_use_nfs --&gt; off
      Is it the case that openshift_use_nfs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_openvpn_can_network_connect_question:question:1">
          <ocil:question_text>
Run the following command to determine if the openvpn_can_network_connect SELinux boolean is disabled:
$ getsebool openvpn_can_network_connect
If properly configured, the output should show the following:
openvpn_can_network_connect --&gt; off
      Is it the case that openvpn_can_network_connect is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_openvpn_enable_homedirs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the openvpn_enable_homedirs SELinux boolean is disabled:
$ getsebool openvpn_enable_homedirs
If properly configured, the output should show the following:
openvpn_enable_homedirs --&gt; off
      Is it the case that openvpn_enable_homedirs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_openvpn_run_unconfined_question:question:1">
          <ocil:question_text>
Run the following command to determine if the openvpn_run_unconfined SELinux boolean is disabled:
$ getsebool openvpn_run_unconfined
If properly configured, the output should show the following:
openvpn_run_unconfined --&gt; off
      Is it the case that openvpn_run_unconfined is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_pcp_bind_all_unreserved_ports_question:question:1">
          <ocil:question_text>
Run the following command to determine if the pcp_bind_all_unreserved_ports SELinux boolean is disabled:
$ getsebool pcp_bind_all_unreserved_ports
If properly configured, the output should show the following:
pcp_bind_all_unreserved_ports --&gt; off
      Is it the case that pcp_bind_all_unreserved_ports is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_pcp_read_generic_logs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the pcp_read_generic_logs SELinux boolean is disabled:
$ getsebool pcp_read_generic_logs
If properly configured, the output should show the following:
pcp_read_generic_logs --&gt; off
      Is it the case that pcp_read_generic_logs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_piranha_lvs_can_network_connect_question:question:1">
          <ocil:question_text>
Run the following command to determine if the piranha_lvs_can_network_connect SELinux boolean is disabled:
$ getsebool piranha_lvs_can_network_connect
If properly configured, the output should show the following:
piranha_lvs_can_network_connect --&gt; off
      Is it the case that piranha_lvs_can_network_connect is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_polipo_connect_all_unreserved_question:question:1">
          <ocil:question_text>
Run the following command to determine if the polipo_connect_all_unreserved SELinux boolean is disabled:
$ getsebool polipo_connect_all_unreserved
If properly configured, the output should show the following:
polipo_connect_all_unreserved --&gt; off
      Is it the case that polipo_connect_all_unreserved is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_polipo_session_bind_all_unreserved_ports_question:question:1">
          <ocil:question_text>
Run the following command to determine if the polipo_session_bind_all_unreserved_ports SELinux boolean is disabled:
$ getsebool polipo_session_bind_all_unreserved_ports
If properly configured, the output should show the following:
polipo_session_bind_all_unreserved_ports --&gt; off
      Is it the case that polipo_session_bind_all_unreserved_ports is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_polipo_session_users_question:question:1">
          <ocil:question_text>
Run the following command to determine if the polipo_session_users SELinux boolean is disabled:
$ getsebool polipo_session_users
If properly configured, the output should show the following:
polipo_session_users --&gt; off
      Is it the case that polipo_session_users is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_polipo_use_cifs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the polipo_use_cifs SELinux boolean is disabled:
$ getsebool polipo_use_cifs
If properly configured, the output should show the following:
polipo_use_cifs --&gt; off
      Is it the case that polipo_use_cifs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_polipo_use_nfs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the polipo_use_nfs SELinux boolean is disabled:
$ getsebool polipo_use_nfs
If properly configured, the output should show the following:
polipo_use_nfs --&gt; off
      Is it the case that polipo_use_nfs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_polyinstantiation_enabled_question:question:1">
          <ocil:question_text>
Run the following command to get the current configured value for polyinstantiation_enabled
SELinux boolean:
$ getsebool polyinstantiation_enabled
The expected cofiguration is .
"on" means true, and "off" means false
      Is it the case that polyinstantiation_enabled is not set as expected?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_postfix_local_write_mail_spool_question:question:1">
          <ocil:question_text>
Run the following command to determine if the postfix_local_write_mail_spool SELinux boolean is enabled:
$ getsebool postfix_local_write_mail_spool
If properly configured, the output should show the following:
postfix_local_write_mail_spool --&gt; on
      Is it the case that postfix_local_write_mail_spool is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_postgresql_can_rsync_question:question:1">
          <ocil:question_text>
Run the following command to determine if the postgresql_can_rsync SELinux boolean is disabled:
$ getsebool postgresql_can_rsync
If properly configured, the output should show the following:
postgresql_can_rsync --&gt; off
      Is it the case that postgresql_can_rsync is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_postgresql_selinux_transmit_client_label_question:question:1">
          <ocil:question_text>
Run the following command to determine if the postgresql_selinux_transmit_client_label SELinux boolean is disabled:
$ getsebool postgresql_selinux_transmit_client_label
If properly configured, the output should show the following:
postgresql_selinux_transmit_client_label --&gt; off
      Is it the case that postgresql_selinux_transmit_client_label is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_postgresql_selinux_unconfined_dbadm_question:question:1">
          <ocil:question_text>
Run the following command to determine if the postgresql_selinux_unconfined_dbadm SELinux boolean is enabled:
$ getsebool postgresql_selinux_unconfined_dbadm
If properly configured, the output should show the following:
postgresql_selinux_unconfined_dbadm --&gt; on
      Is it the case that postgresql_selinux_unconfined_dbadm is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_postgresql_selinux_users_ddl_question:question:1">
          <ocil:question_text>
Run the following command to determine if the postgresql_selinux_users_ddl SELinux boolean is enabled:
$ getsebool postgresql_selinux_users_ddl
If properly configured, the output should show the following:
postgresql_selinux_users_ddl --&gt; on
      Is it the case that postgresql_selinux_users_ddl is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_pppd_can_insmod_question:question:1">
          <ocil:question_text>
Run the following command to determine if the pppd_can_insmod SELinux boolean is disabled:
$ getsebool pppd_can_insmod
If properly configured, the output should show the following:
pppd_can_insmod --&gt; off
      Is it the case that pppd_can_insmod is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_pppd_for_user_question:question:1">
          <ocil:question_text>
Run the following command to determine if the pppd_for_user SELinux boolean is disabled:
$ getsebool pppd_for_user
If properly configured, the output should show the following:
pppd_for_user --&gt; off
      Is it the case that pppd_for_user is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_privoxy_connect_any_question:question:1">
          <ocil:question_text>
Run the following command to determine if the privoxy_connect_any SELinux boolean is disabled:
$ getsebool privoxy_connect_any
If properly configured, the output should show the following:
privoxy_connect_any --&gt; off
      Is it the case that privoxy_connect_any is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_prosody_bind_http_port_question:question:1">
          <ocil:question_text>
Run the following command to determine if the prosody_bind_http_port SELinux boolean is disabled:
$ getsebool prosody_bind_http_port
If properly configured, the output should show the following:
prosody_bind_http_port --&gt; off
      Is it the case that prosody_bind_http_port is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_puppetagent_manage_all_files_question:question:1">
          <ocil:question_text>
Run the following command to determine if the puppetagent_manage_all_files SELinux boolean is disabled:
$ getsebool puppetagent_manage_all_files
If properly configured, the output should show the following:
puppetagent_manage_all_files --&gt; off
      Is it the case that puppetagent_manage_all_files is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_puppetmaster_use_db_question:question:1">
          <ocil:question_text>
Run the following command to determine if the puppetmaster_use_db SELinux boolean is disabled:
$ getsebool puppetmaster_use_db
If properly configured, the output should show the following:
puppetmaster_use_db --&gt; off
      Is it the case that puppetmaster_use_db is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_racoon_read_shadow_question:question:1">
          <ocil:question_text>
Run the following command to determine if the racoon_read_shadow SELinux boolean is disabled:
$ getsebool racoon_read_shadow
If properly configured, the output should show the following:
racoon_read_shadow --&gt; off
      Is it the case that racoon_read_shadow is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_rsync_anon_write_question:question:1">
          <ocil:question_text>
Run the following command to determine if the rsync_anon_write SELinux boolean is disabled:
$ getsebool rsync_anon_write
If properly configured, the output should show the following:
rsync_anon_write --&gt; off
      Is it the case that rsync_anon_write is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_rsync_client_question:question:1">
          <ocil:question_text>
Run the following command to determine if the rsync_client SELinux boolean is disabled:
$ getsebool rsync_client
If properly configured, the output should show the following:
rsync_client --&gt; off
      Is it the case that rsync_client is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_rsync_export_all_ro_question:question:1">
          <ocil:question_text>
Run the following command to determine if the rsync_export_all_ro SELinux boolean is disabled:
$ getsebool rsync_export_all_ro
If properly configured, the output should show the following:
rsync_export_all_ro --&gt; off
      Is it the case that rsync_export_all_ro is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_rsync_full_access_question:question:1">
          <ocil:question_text>
Run the following command to determine if the rsync_full_access SELinux boolean is disabled:
$ getsebool rsync_full_access
If properly configured, the output should show the following:
rsync_full_access --&gt; off
      Is it the case that rsync_full_access is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_samba_create_home_dirs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the samba_create_home_dirs SELinux boolean is disabled:
$ getsebool samba_create_home_dirs
If properly configured, the output should show the following:
samba_create_home_dirs --&gt; off
      Is it the case that samba_create_home_dirs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_samba_domain_controller_question:question:1">
          <ocil:question_text>
Run the following command to determine if the samba_domain_controller SELinux boolean is disabled:
$ getsebool samba_domain_controller
If properly configured, the output should show the following:
samba_domain_controller --&gt; off
      Is it the case that samba_domain_controller is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_samba_enable_home_dirs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the samba_enable_home_dirs SELinux boolean is disabled:
$ getsebool samba_enable_home_dirs
If properly configured, the output should show the following:
samba_enable_home_dirs --&gt; off
      Is it the case that samba_enable_home_dirs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_samba_export_all_ro_question:question:1">
          <ocil:question_text>
Run the following command to determine if the samba_export_all_ro SELinux boolean is disabled:
$ getsebool samba_export_all_ro
If properly configured, the output should show the following:
samba_export_all_ro --&gt; off
      Is it the case that samba_export_all_ro is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_samba_export_all_rw_question:question:1">
          <ocil:question_text>
Run the following command to determine if the samba_export_all_rw SELinux boolean is disabled:
$ getsebool samba_export_all_rw
If properly configured, the output should show the following:
samba_export_all_rw --&gt; off
      Is it the case that samba_export_all_rw is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_samba_load_libgfapi_question:question:1">
          <ocil:question_text>
Run the following command to determine if the samba_load_libgfapi SELinux boolean is disabled:
$ getsebool samba_load_libgfapi
If properly configured, the output should show the following:
samba_load_libgfapi --&gt; off
      Is it the case that samba_load_libgfapi is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_samba_portmapper_question:question:1">
          <ocil:question_text>
Run the following command to determine if the samba_portmapper SELinux boolean is disabled:
$ getsebool samba_portmapper
If properly configured, the output should show the following:
samba_portmapper --&gt; off
      Is it the case that samba_portmapper is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_samba_run_unconfined_question:question:1">
          <ocil:question_text>
Run the following command to determine if the samba_run_unconfined SELinux boolean is disabled:
$ getsebool samba_run_unconfined
If properly configured, the output should show the following:
samba_run_unconfined --&gt; off
      Is it the case that samba_run_unconfined is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_samba_share_fusefs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the samba_share_fusefs SELinux boolean is disabled:
$ getsebool samba_share_fusefs
If properly configured, the output should show the following:
samba_share_fusefs --&gt; off
      Is it the case that samba_share_fusefs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_samba_share_nfs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the samba_share_nfs SELinux boolean is disabled:
$ getsebool samba_share_nfs
If properly configured, the output should show the following:
samba_share_nfs --&gt; off
      Is it the case that samba_share_nfs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_sanlock_use_fusefs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the sanlock_use_fusefs SELinux boolean is disabled:
$ getsebool sanlock_use_fusefs
If properly configured, the output should show the following:
sanlock_use_fusefs --&gt; off
      Is it the case that sanlock_use_fusefs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_sanlock_use_nfs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the sanlock_use_nfs SELinux boolean is disabled:
$ getsebool sanlock_use_nfs
If properly configured, the output should show the following:
sanlock_use_nfs --&gt; off
      Is it the case that sanlock_use_nfs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_sanlock_use_samba_question:question:1">
          <ocil:question_text>
Run the following command to determine if the sanlock_use_samba SELinux boolean is disabled:
$ getsebool sanlock_use_samba
If properly configured, the output should show the following:
sanlock_use_samba --&gt; off
      Is it the case that sanlock_use_samba is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_saslauthd_read_shadow_question:question:1">
          <ocil:question_text>
Run the following command to determine if the saslauthd_read_shadow SELinux boolean is disabled:
$ getsebool saslauthd_read_shadow
If properly configured, the output should show the following:
saslauthd_read_shadow --&gt; off
      Is it the case that saslauthd_read_shadow is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_secadm_exec_content_question:question:1">
          <ocil:question_text>
Run the following command to determine if the secadm_exec_content SELinux boolean is enabled:
$ getsebool secadm_exec_content
If properly configured, the output should show the following:
secadm_exec_content --&gt; on
      Is it the case that secadm_exec_content is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_secure_mode_question:question:1">
          <ocil:question_text>
Run the following command to determine if the secure_mode SELinux boolean is disabled:
$ getsebool secure_mode
If properly configured, the output should show the following:
secure_mode --&gt; off
      Is it the case that secure_mode is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_secure_mode_insmod_question:question:1">
          <ocil:question_text>
Run the following command to get the current configured value for secure_mode_insmod
SELinux boolean:
$ getsebool secure_mode_insmod
The expected cofiguration is .
"on" means true, and "off" means false
      Is it the case that secure_mode_insmod is not set as expected?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_secure_mode_policyload_question:question:1">
          <ocil:question_text>
Run the following command to determine if the secure_mode_policyload SELinux boolean is disabled:
$ getsebool secure_mode_policyload
If properly configured, the output should show the following:
secure_mode_policyload --&gt; off
      Is it the case that secure_mode_policyload is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_selinuxuser_direct_dri_enabled_question:question:1">
          <ocil:question_text>
Run the following command to determine if the selinuxuser_direct_dri_enabled SELinux boolean is disabled:
$ getsebool selinuxuser_direct_dri_enabled
If properly configured, the output should show the following:
selinuxuser_direct_dri_enabled --&gt; off
      Is it the case that selinuxuser_direct_dri_enabled is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_selinuxuser_execheap_question:question:1">
          <ocil:question_text>
Run the following command to determine if the selinuxuser_execheap SELinux boolean is disabled:
$ getsebool selinuxuser_execheap
If properly configured, the output should show the following:
selinuxuser_execheap --&gt; off
      Is it the case that selinuxuser_execheap is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_selinuxuser_execmod_question:question:1">
          <ocil:question_text>
Run the following command to determine if the selinuxuser_execmod SELinux boolean is enabled:
$ getsebool selinuxuser_execmod
If properly configured, the output should show the following:
selinuxuser_execmod --&gt; on
      Is it the case that selinuxuser_execmod is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_selinuxuser_execstack_question:question:1">
          <ocil:question_text>
Run the following command to determine if the selinuxuser_execstack SELinux boolean is disabled:
$ getsebool selinuxuser_execstack
If properly configured, the output should show the following:
selinuxuser_execstack --&gt; off
      Is it the case that selinuxuser_execstack is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_selinuxuser_mysql_connect_enabled_question:question:1">
          <ocil:question_text>
Run the following command to determine if the selinuxuser_mysql_connect_enabled SELinux boolean is disabled:
$ getsebool selinuxuser_mysql_connect_enabled
If properly configured, the output should show the following:
selinuxuser_mysql_connect_enabled --&gt; off
      Is it the case that selinuxuser_mysql_connect_enabled is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_selinuxuser_ping_question:question:1">
          <ocil:question_text>
Run the following command to determine if the selinuxuser_ping SELinux boolean is enabled:
$ getsebool selinuxuser_ping
If properly configured, the output should show the following:
selinuxuser_ping --&gt; on
      Is it the case that selinuxuser_ping is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_selinuxuser_postgresql_connect_enabled_question:question:1">
          <ocil:question_text>
Run the following command to determine if the selinuxuser_postgresql_connect_enabled SELinux boolean is disabled:
$ getsebool selinuxuser_postgresql_connect_enabled
If properly configured, the output should show the following:
selinuxuser_postgresql_connect_enabled --&gt; off
      Is it the case that selinuxuser_postgresql_connect_enabled is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_selinuxuser_rw_noexattrfile_question:question:1">
          <ocil:question_text>
Run the following command to determine if the selinuxuser_rw_noexattrfile SELinux boolean is disabled:
$ getsebool selinuxuser_rw_noexattrfile
If properly configured, the output should show the following:
selinuxuser_rw_noexattrfile --&gt; off
      Is it the case that selinuxuser_rw_noexattrfile is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_selinuxuser_share_music_question:question:1">
          <ocil:question_text>
Run the following command to determine if the selinuxuser_share_music SELinux boolean is disabled:
$ getsebool selinuxuser_share_music
If properly configured, the output should show the following:
selinuxuser_share_music --&gt; off
      Is it the case that selinuxuser_share_music is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_selinuxuser_tcp_server_question:question:1">
          <ocil:question_text>
Run the following command to determine if the selinuxuser_tcp_server SELinux boolean is disabled:
$ getsebool selinuxuser_tcp_server
If properly configured, the output should show the following:
selinuxuser_tcp_server --&gt; off
      Is it the case that selinuxuser_tcp_server is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_selinuxuser_udp_server_question:question:1">
          <ocil:question_text>
Run the following command to determine if the selinuxuser_udp_server SELinux boolean is disabled:
$ getsebool selinuxuser_udp_server
If properly configured, the output should show the following:
selinuxuser_udp_server --&gt; off
      Is it the case that selinuxuser_udp_server is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_selinuxuser_use_ssh_chroot_question:question:1">
          <ocil:question_text>
Run the following command to determine if the selinuxuser_use_ssh_chroot SELinux boolean is disabled:
$ getsebool selinuxuser_use_ssh_chroot
If properly configured, the output should show the following:
selinuxuser_use_ssh_chroot --&gt; off
      Is it the case that selinuxuser_use_ssh_chroot is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_sge_domain_can_network_connect_question:question:1">
          <ocil:question_text>
Run the following command to determine if the sge_domain_can_network_connect SELinux boolean is disabled:
$ getsebool sge_domain_can_network_connect
If properly configured, the output should show the following:
sge_domain_can_network_connect --&gt; off
      Is it the case that sge_domain_can_network_connect is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_sge_use_nfs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the sge_use_nfs SELinux boolean is disabled:
$ getsebool sge_use_nfs
If properly configured, the output should show the following:
sge_use_nfs --&gt; off
      Is it the case that sge_use_nfs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_smartmon_3ware_question:question:1">
          <ocil:question_text>
Run the following command to determine if the smartmon_3ware SELinux boolean is disabled:
$ getsebool smartmon_3ware
If properly configured, the output should show the following:
smartmon_3ware --&gt; off
      Is it the case that smartmon_3ware is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_smbd_anon_write_question:question:1">
          <ocil:question_text>
Run the following command to determine if the smbd_anon_write SELinux boolean is disabled:
$ getsebool smbd_anon_write
If properly configured, the output should show the following:
smbd_anon_write --&gt; off
      Is it the case that smbd_anon_write is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_spamassassin_can_network_question:question:1">
          <ocil:question_text>
Run the following command to determine if the spamassassin_can_network SELinux boolean is disabled:
$ getsebool spamassassin_can_network
If properly configured, the output should show the following:
spamassassin_can_network --&gt; off
      Is it the case that spamassassin_can_network is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_spamd_enable_home_dirs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the spamd_enable_home_dirs SELinux boolean is enabled:
$ getsebool spamd_enable_home_dirs
If properly configured, the output should show the following:
spamd_enable_home_dirs --&gt; on
      Is it the case that spamd_enable_home_dirs is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_squid_connect_any_question:question:1">
          <ocil:question_text>
Run the following command to determine if the squid_connect_any SELinux boolean is disabled:
$ getsebool squid_connect_any
If properly configured, the output should show the following:
squid_connect_any --&gt; off
      Is it the case that squid_connect_any is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_squid_use_tproxy_question:question:1">
          <ocil:question_text>
Run the following command to determine if the squid_use_tproxy SELinux boolean is disabled:
$ getsebool squid_use_tproxy
If properly configured, the output should show the following:
squid_use_tproxy --&gt; off
      Is it the case that squid_use_tproxy is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_ssh_chroot_rw_homedirs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the ssh_chroot_rw_homedirs SELinux boolean is disabled:
$ getsebool ssh_chroot_rw_homedirs
If properly configured, the output should show the following:
ssh_chroot_rw_homedirs --&gt; off
      Is it the case that ssh_chroot_rw_homedirs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_ssh_keysign_question:question:1">
          <ocil:question_text>
Run the following command to determine if the ssh_keysign SELinux boolean is disabled:
$ getsebool ssh_keysign
If properly configured, the output should show the following:
ssh_keysign --&gt; off
      Is it the case that ssh_keysign is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_ssh_sysadm_login_question:question:1">
          <ocil:question_text>
Run the following command to determine if the ssh_sysadm_login SELinux boolean is disabled:
$ getsebool ssh_sysadm_login
If properly configured, the output should show the following:
ssh_sysadm_login --&gt; off
      Is it the case that ssh_sysadm_login is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_staff_exec_content_question:question:1">
          <ocil:question_text>
Run the following command to determine if the staff_exec_content SELinux boolean is enabled:
$ getsebool staff_exec_content
If properly configured, the output should show the following:
staff_exec_content --&gt; on
      Is it the case that staff_exec_content is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_staff_use_svirt_question:question:1">
          <ocil:question_text>
Run the following command to determine if the staff_use_svirt SELinux boolean is disabled:
$ getsebool staff_use_svirt
If properly configured, the output should show the following:
staff_use_svirt --&gt; off
      Is it the case that staff_use_svirt is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_swift_can_network_question:question:1">
          <ocil:question_text>
Run the following command to determine if the swift_can_network SELinux boolean is disabled:
$ getsebool swift_can_network
If properly configured, the output should show the following:
swift_can_network --&gt; off
      Is it the case that swift_can_network is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_sysadm_exec_content_question:question:1">
          <ocil:question_text>
Run the following command to determine if the sysadm_exec_content SELinux boolean is enabled:
$ getsebool sysadm_exec_content
If properly configured, the output should show the following:
sysadm_exec_content --&gt; on
      Is it the case that sysadm_exec_content is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_telepathy_connect_all_ports_question:question:1">
          <ocil:question_text>
Run the following command to determine if the telepathy_connect_all_ports SELinux boolean is disabled:
$ getsebool telepathy_connect_all_ports
If properly configured, the output should show the following:
telepathy_connect_all_ports --&gt; off
      Is it the case that telepathy_connect_all_ports is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_telepathy_tcp_connect_generic_network_ports_question:question:1">
          <ocil:question_text>
Run the following command to determine if the telepathy_tcp_connect_generic_network_ports SELinux boolean is disabled:
$ getsebool telepathy_tcp_connect_generic_network_ports
If properly configured, the output should show the following:
telepathy_tcp_connect_generic_network_ports --&gt; off
      Is it the case that telepathy_tcp_connect_generic_network_ports is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_tftp_anon_write_question:question:1">
          <ocil:question_text>
Run the following command to determine if the tftp_anon_write SELinux boolean is disabled:
$ getsebool tftp_anon_write
If properly configured, the output should show the following:
tftp_anon_write --&gt; off
      Is it the case that tftp_anon_write is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_tftp_home_dir_question:question:1">
          <ocil:question_text>
Run the following command to determine if the tftp_home_dir SELinux boolean is disabled:
$ getsebool tftp_home_dir
If properly configured, the output should show the following:
tftp_home_dir --&gt; off
      Is it the case that tftp_home_dir is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_tmpreaper_use_nfs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the tmpreaper_use_nfs SELinux boolean is disabled:
$ getsebool tmpreaper_use_nfs
If properly configured, the output should show the following:
tmpreaper_use_nfs --&gt; off
      Is it the case that tmpreaper_use_nfs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_tmpreaper_use_samba_question:question:1">
          <ocil:question_text>
Run the following command to determine if the tmpreaper_use_samba SELinux boolean is disabled:
$ getsebool tmpreaper_use_samba
If properly configured, the output should show the following:
tmpreaper_use_samba --&gt; off
      Is it the case that tmpreaper_use_samba is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_tor_bind_all_unreserved_ports_question:question:1">
          <ocil:question_text>
Run the following command to determine if the tor_bind_all_unreserved_ports SELinux boolean is disabled:
$ getsebool tor_bind_all_unreserved_ports
If properly configured, the output should show the following:
tor_bind_all_unreserved_ports --&gt; off
      Is it the case that tor_bind_all_unreserved_ports is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_tor_can_network_relay_question:question:1">
          <ocil:question_text>
Run the following command to determine if the tor_can_network_relay SELinux boolean is disabled:
$ getsebool tor_can_network_relay
If properly configured, the output should show the following:
tor_can_network_relay --&gt; off
      Is it the case that tor_can_network_relay is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_unconfined_chrome_sandbox_transition_question:question:1">
          <ocil:question_text>
Run the following command to determine if the unconfined_chrome_sandbox_transition SELinux boolean is enabled:
$ getsebool unconfined_chrome_sandbox_transition
If properly configured, the output should show the following:
unconfined_chrome_sandbox_transition --&gt; on
      Is it the case that unconfined_chrome_sandbox_transition is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_unconfined_login_question:question:1">
          <ocil:question_text>
Run the following command to determine if the unconfined_login SELinux boolean is enabled:
$ getsebool unconfined_login
If properly configured, the output should show the following:
unconfined_login --&gt; on
      Is it the case that unconfined_login is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_unconfined_mozilla_plugin_transition_question:question:1">
          <ocil:question_text>
Run the following command to determine if the unconfined_mozilla_plugin_transition SELinux boolean is enabled:
$ getsebool unconfined_mozilla_plugin_transition
If properly configured, the output should show the following:
unconfined_mozilla_plugin_transition --&gt; on
      Is it the case that unconfined_mozilla_plugin_transition is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_unprivuser_use_svirt_question:question:1">
          <ocil:question_text>
Run the following command to determine if the unprivuser_use_svirt SELinux boolean is disabled:
$ getsebool unprivuser_use_svirt
If properly configured, the output should show the following:
unprivuser_use_svirt --&gt; off
      Is it the case that unprivuser_use_svirt is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_use_ecryptfs_home_dirs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the use_ecryptfs_home_dirs SELinux boolean is disabled:
$ getsebool use_ecryptfs_home_dirs
If properly configured, the output should show the following:
use_ecryptfs_home_dirs --&gt; off
      Is it the case that use_ecryptfs_home_dirs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_use_fusefs_home_dirs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the use_fusefs_home_dirs SELinux boolean is disabled:
$ getsebool use_fusefs_home_dirs
If properly configured, the output should show the following:
use_fusefs_home_dirs --&gt; off
      Is it the case that use_fusefs_home_dirs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_use_lpd_server_question:question:1">
          <ocil:question_text>
Run the following command to determine if the use_lpd_server SELinux boolean is disabled:
$ getsebool use_lpd_server
If properly configured, the output should show the following:
use_lpd_server --&gt; off
      Is it the case that use_lpd_server is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_use_nfs_home_dirs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the use_nfs_home_dirs SELinux boolean is disabled:
$ getsebool use_nfs_home_dirs
If properly configured, the output should show the following:
use_nfs_home_dirs --&gt; off
      Is it the case that use_nfs_home_dirs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_use_samba_home_dirs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the use_samba_home_dirs SELinux boolean is disabled:
$ getsebool use_samba_home_dirs
If properly configured, the output should show the following:
use_samba_home_dirs --&gt; off
      Is it the case that use_samba_home_dirs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_user_exec_content_question:question:1">
          <ocil:question_text>
Run the following command to determine if the user_exec_content SELinux boolean is enabled:
$ getsebool user_exec_content
If properly configured, the output should show the following:
user_exec_content --&gt; on
      Is it the case that user_exec_content is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_varnishd_connect_any_question:question:1">
          <ocil:question_text>
Run the following command to determine if the varnishd_connect_any SELinux boolean is disabled:
$ getsebool varnishd_connect_any
If properly configured, the output should show the following:
varnishd_connect_any --&gt; off
      Is it the case that varnishd_connect_any is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_virt_read_qemu_ga_data_question:question:1">
          <ocil:question_text>
Run the following command to determine if the virt_read_qemu_ga_data SELinux boolean is disabled:
$ getsebool virt_read_qemu_ga_data
If properly configured, the output should show the following:
virt_read_qemu_ga_data --&gt; off
      Is it the case that virt_read_qemu_ga_data is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_virt_rw_qemu_ga_data_question:question:1">
          <ocil:question_text>
Run the following command to determine if the virt_rw_qemu_ga_data SELinux boolean is disabled:
$ getsebool virt_rw_qemu_ga_data
If properly configured, the output should show the following:
virt_rw_qemu_ga_data --&gt; off
      Is it the case that virt_rw_qemu_ga_data is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_virt_sandbox_use_all_caps_question:question:1">
          <ocil:question_text>
Run the following command to determine if the virt_sandbox_use_all_caps SELinux boolean is disabled:
$ getsebool virt_sandbox_use_all_caps
If properly configured, the output should show the following:
virt_sandbox_use_all_caps --&gt; off
      Is it the case that virt_sandbox_use_all_caps is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_virt_sandbox_use_audit_question:question:1">
          <ocil:question_text>
Run the following command to determine if the virt_sandbox_use_audit SELinux boolean is enabled:
$ getsebool virt_sandbox_use_audit
If properly configured, the output should show the following:
virt_sandbox_use_audit --&gt; on
      Is it the case that virt_sandbox_use_audit is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_virt_sandbox_use_mknod_question:question:1">
          <ocil:question_text>
Run the following command to determine if the virt_sandbox_use_mknod SELinux boolean is disabled:
$ getsebool virt_sandbox_use_mknod
If properly configured, the output should show the following:
virt_sandbox_use_mknod --&gt; off
      Is it the case that virt_sandbox_use_mknod is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_virt_sandbox_use_netlink_question:question:1">
          <ocil:question_text>
Run the following command to determine if the virt_sandbox_use_netlink SELinux boolean is disabled:
$ getsebool virt_sandbox_use_netlink
If properly configured, the output should show the following:
virt_sandbox_use_netlink --&gt; off
      Is it the case that virt_sandbox_use_netlink is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_virt_sandbox_use_sys_admin_question:question:1">
          <ocil:question_text>
Run the following command to determine if the virt_sandbox_use_sys_admin SELinux boolean is disabled:
$ getsebool virt_sandbox_use_sys_admin
If properly configured, the output should show the following:
virt_sandbox_use_sys_admin --&gt; off
      Is it the case that virt_sandbox_use_sys_admin is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_virt_transition_userdomain_question:question:1">
          <ocil:question_text>
Run the following command to determine if the virt_transition_userdomain SELinux boolean is disabled:
$ getsebool virt_transition_userdomain
If properly configured, the output should show the following:
virt_transition_userdomain --&gt; off
      Is it the case that virt_transition_userdomain is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_virt_use_comm_question:question:1">
          <ocil:question_text>
Run the following command to determine if the virt_use_comm SELinux boolean is disabled:
$ getsebool virt_use_comm
If properly configured, the output should show the following:
virt_use_comm --&gt; off
      Is it the case that virt_use_comm is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_virt_use_execmem_question:question:1">
          <ocil:question_text>
Run the following command to determine if the virt_use_execmem SELinux boolean is disabled:
$ getsebool virt_use_execmem
If properly configured, the output should show the following:
virt_use_execmem --&gt; off
      Is it the case that virt_use_execmem is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_virt_use_fusefs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the virt_use_fusefs SELinux boolean is disabled:
$ getsebool virt_use_fusefs
If properly configured, the output should show the following:
virt_use_fusefs --&gt; off
      Is it the case that virt_use_fusefs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_virt_use_nfs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the virt_use_nfs SELinux boolean is disabled:
$ getsebool virt_use_nfs
If properly configured, the output should show the following:
virt_use_nfs --&gt; off
      Is it the case that virt_use_nfs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_virt_use_rawip_question:question:1">
          <ocil:question_text>
Run the following command to determine if the virt_use_rawip SELinux boolean is disabled:
$ getsebool virt_use_rawip
If properly configured, the output should show the following:
virt_use_rawip --&gt; off
      Is it the case that virt_use_rawip is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_virt_use_samba_question:question:1">
          <ocil:question_text>
Run the following command to determine if the virt_use_samba SELinux boolean is disabled:
$ getsebool virt_use_samba
If properly configured, the output should show the following:
virt_use_samba --&gt; off
      Is it the case that virt_use_samba is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_virt_use_sanlock_question:question:1">
          <ocil:question_text>
Run the following command to determine if the virt_use_sanlock SELinux boolean is disabled:
$ getsebool virt_use_sanlock
If properly configured, the output should show the following:
virt_use_sanlock --&gt; off
      Is it the case that virt_use_sanlock is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_virt_use_usb_question:question:1">
          <ocil:question_text>
Run the following command to determine if the virt_use_usb SELinux boolean is disabled:
$ getsebool virt_use_usb
If properly configured, the output should show the following:
virt_use_usb --&gt; off
      Is it the case that virt_use_usb is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_virt_use_xserver_question:question:1">
          <ocil:question_text>
Run the following command to determine if the virt_use_xserver SELinux boolean is disabled:
$ getsebool virt_use_xserver
If properly configured, the output should show the following:
virt_use_xserver --&gt; off
      Is it the case that virt_use_xserver is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_webadm_manage_user_files_question:question:1">
          <ocil:question_text>
Run the following command to determine if the webadm_manage_user_files SELinux boolean is disabled:
$ getsebool webadm_manage_user_files
If properly configured, the output should show the following:
webadm_manage_user_files --&gt; off
      Is it the case that webadm_manage_user_files is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_webadm_read_user_files_question:question:1">
          <ocil:question_text>
Run the following command to determine if the webadm_read_user_files SELinux boolean is disabled:
$ getsebool webadm_read_user_files
If properly configured, the output should show the following:
webadm_read_user_files --&gt; off
      Is it the case that webadm_read_user_files is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_wine_mmap_zero_ignore_question:question:1">
          <ocil:question_text>
Run the following command to determine if the wine_mmap_zero_ignore SELinux boolean is disabled:
$ getsebool wine_mmap_zero_ignore
If properly configured, the output should show the following:
wine_mmap_zero_ignore --&gt; off
      Is it the case that wine_mmap_zero_ignore is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_xdm_bind_vnc_tcp_port_question:question:1">
          <ocil:question_text>
Run the following command to determine if the xdm_bind_vnc_tcp_port SELinux boolean is disabled:
$ getsebool xdm_bind_vnc_tcp_port
If properly configured, the output should show the following:
xdm_bind_vnc_tcp_port --&gt; off
      Is it the case that xdm_bind_vnc_tcp_port is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_xdm_exec_bootloader_question:question:1">
          <ocil:question_text>
Run the following command to determine if the xdm_exec_bootloader SELinux boolean is disabled:
$ getsebool xdm_exec_bootloader
If properly configured, the output should show the following:
xdm_exec_bootloader --&gt; off
      Is it the case that xdm_exec_bootloader is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_xdm_sysadm_login_question:question:1">
          <ocil:question_text>
Run the following command to determine if the xdm_sysadm_login SELinux boolean is disabled:
$ getsebool xdm_sysadm_login
If properly configured, the output should show the following:
xdm_sysadm_login --&gt; off
      Is it the case that xdm_sysadm_login is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_xdm_write_home_question:question:1">
          <ocil:question_text>
Run the following command to determine if the xdm_write_home SELinux boolean is disabled:
$ getsebool xdm_write_home
If properly configured, the output should show the following:
xdm_write_home --&gt; off
      Is it the case that xdm_write_home is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_xen_use_nfs_question:question:1">
          <ocil:question_text>
Run the following command to determine if the xen_use_nfs SELinux boolean is disabled:
$ getsebool xen_use_nfs
If properly configured, the output should show the following:
xen_use_nfs --&gt; off
      Is it the case that xen_use_nfs is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_xend_run_blktap_question:question:1">
          <ocil:question_text>
Run the following command to determine if the xend_run_blktap SELinux boolean is enabled:
$ getsebool xend_run_blktap
If properly configured, the output should show the following:
xend_run_blktap --&gt; on
      Is it the case that xend_run_blktap is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_xend_run_qemu_question:question:1">
          <ocil:question_text>
Run the following command to determine if the xend_run_qemu SELinux boolean is enabled:
$ getsebool xend_run_qemu
If properly configured, the output should show the following:
xend_run_qemu --&gt; on
      Is it the case that xend_run_qemu is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_xguest_connect_network_question:question:1">
          <ocil:question_text>
Run the following command to determine if the xguest_connect_network SELinux boolean is disabled:
$ getsebool xguest_connect_network
If properly configured, the output should show the following:
xguest_connect_network --&gt; off
      Is it the case that xguest_connect_network is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_xguest_exec_content_question:question:1">
          <ocil:question_text>
Run the following command to determine if the xguest_exec_content SELinux boolean is disabled:
$ getsebool xguest_exec_content
If properly configured, the output should show the following:
xguest_exec_content --&gt; off
      Is it the case that xguest_exec_content is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_xguest_mount_media_question:question:1">
          <ocil:question_text>
Run the following command to determine if the xguest_mount_media SELinux boolean is disabled:
$ getsebool xguest_mount_media
If properly configured, the output should show the following:
xguest_mount_media --&gt; off
      Is it the case that xguest_mount_media is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_xguest_use_bluetooth_question:question:1">
          <ocil:question_text>
Run the following command to determine if the xguest_use_bluetooth SELinux boolean is disabled:
$ getsebool xguest_use_bluetooth
If properly configured, the output should show the following:
xguest_use_bluetooth --&gt; off
      Is it the case that xguest_use_bluetooth is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_xserver_clients_write_xshm_question:question:1">
          <ocil:question_text>
Run the following command to determine if the xserver_clients_write_xshm SELinux boolean is disabled:
$ getsebool xserver_clients_write_xshm
If properly configured, the output should show the following:
xserver_clients_write_xshm --&gt; off
      Is it the case that xserver_clients_write_xshm is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_xserver_execmem_question:question:1">
          <ocil:question_text>
Run the following command to determine if the xserver_execmem SELinux boolean is disabled:
$ getsebool xserver_execmem
If properly configured, the output should show the following:
xserver_execmem --&gt; off
      Is it the case that xserver_execmem is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_xserver_object_manager_question:question:1">
          <ocil:question_text>
Run the following command to determine if the xserver_object_manager SELinux boolean is disabled:
$ getsebool xserver_object_manager
If properly configured, the output should show the following:
xserver_object_manager --&gt; off
      Is it the case that xserver_object_manager is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_zabbix_can_network_question:question:1">
          <ocil:question_text>
Run the following command to determine if the zabbix_can_network SELinux boolean is disabled:
$ getsebool zabbix_can_network
If properly configured, the output should show the following:
zabbix_can_network --&gt; off
      Is it the case that zabbix_can_network is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_zarafa_setrlimit_question:question:1">
          <ocil:question_text>
Run the following command to determine if the zarafa_setrlimit SELinux boolean is disabled:
$ getsebool zarafa_setrlimit
If properly configured, the output should show the following:
zarafa_setrlimit --&gt; off
      Is it the case that zarafa_setrlimit is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_zebra_write_config_question:question:1">
          <ocil:question_text>
Run the following command to determine if the zebra_write_config SELinux boolean is disabled:
$ getsebool zebra_write_config
If properly configured, the output should show the following:
zebra_write_config --&gt; off
      Is it the case that zebra_write_config is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_zoneminder_anon_write_question:question:1">
          <ocil:question_text>
Run the following command to determine if the zoneminder_anon_write SELinux boolean is disabled:
$ getsebool zoneminder_anon_write
If properly configured, the output should show the following:
zoneminder_anon_write --&gt; off
      Is it the case that zoneminder_anon_write is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sebool_zoneminder_run_sudo_question:question:1">
          <ocil:question_text>
Run the following command to determine if the zoneminder_run_sudo SELinux boolean is disabled:
$ getsebool zoneminder_run_sudo
If properly configured, the output should show the following:
zoneminder_run_sudo --&gt; off
      Is it the case that zoneminder_run_sudo is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-securetty_root_login_console_only_question:question:1">
          <ocil:question_text>To check for virtual console entries which permit root login, run the
following command:
$ sudo grep ^vc/[0-9] /etc/securetty
If any output is returned, then root logins over virtual console devices is permitted.
      Is it the case that root login over virtual console devices is permitted?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-security_patches_up_to_date_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 security patches and updates are installed and up to date.
Updates are required to be applied with a frequency determined by organizational policy.



Typical update frequency may be overridden by Information Assurance Vulnerability Alert (IAVA) notifications from CYBERCOM.
      Is it the case that AlmaLinux OS 8 is in non-compliance with the organizational patching policy?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-selinux_all_devicefiles_labeled_question:question:1">
          <ocil:question_text>To check for incorrectly labeled device files, run following commands:
$ sudo find /dev -context *:device_t:* \( -type c -o -type b \) -printf "%p %Z\n"
$ sudo find /dev -context *:unlabeled_t:* \( -type c -o -type b \) -printf "%p %Z\n"
It should produce no output in a well-configured system.
      Is it the case that there is output?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-selinux_confinement_of_daemons_question:question:1">
          <ocil:question_text>Ensure there are no unconfined daemons running on the system,
the following command should produce no output:
$ sudo ps -eZ | grep "unconfined_service_t"
      Is it the case that There are unconfined daemons running on the system?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-selinux_context_elevation_for_sudo_question:question:1">
          <ocil:question_text>Verify the operating system elevates the SELinux context when an administrator calls the
sudo command with the following command:

This command must be ran as root:
grep sysadm_r /etc/sudoers.d/*
%wheel ALL=(ALL) TYPE=sysadm_t ROLE=sysadm_r ALL

      Is it the case that selinux context does not elevate when running sudo command?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-selinux_not_disabled_question:question:1">
          <ocil:question_text>Ensure that AlmaLinux OS 8 does not disable SELinux.

Check if "SELinux" is active and in "enforcing" or "permissive" mode with the following command:

$ sudo getenforce
Enforcing
-OR-
Permissive
      Is it the case that SELinux is disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-selinux_policytype_question:question:1">
          <ocil:question_text>Verify the SELINUX on AlmaLinux OS 8 is using the  policy with the following command:

$ sestatus | grep policy

Loaded policy name:             
      Is it the case that the loaded policy name is not "&lt;sub idref="var_selinux_policy_name" /&gt;"?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-selinux_state_question:question:1">
          <ocil:question_text>Ensure that AlmaLinux OS 8 verifies correct operation of security functions.

Check if "SELinux" is active and in "" mode with the following command:

$ sudo getenforce

      Is it the case that SELINUX is not set to enforcing?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-selinux_user_login_roles_question:question:1">
          <ocil:question_text>To verify the operating system prevents non-privileged users from executing
privileged functions to include disabling, circumventing, or altering
implemented security safeguards/countermeasures, run the following
command:
$ sudo semanage login -l
All administrators must be mapped to the sysadm_u or staff_u
users with the appropriate domains (sysadm_t and staff_t).

All authorized non-administrative
users must be mapped to the user_u role or the appropriate domain
(user_t).
      Is it the case that non-admin users are not confined correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_abrtd_disabled_question:question:1">
          <ocil:question_text>To check that the abrtd service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled abrtd
Output should indicate the abrtd service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled abrtd disabled

Run the following command to verify abrtd is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active abrtd

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the abrtd is masked, run the following command:
$ sudo systemctl show abrtd | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "abrtd" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_acpid_disabled_question:question:1">
          <ocil:question_text>To check that the acpid service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled acpid
Output should indicate the acpid service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled acpid disabled

Run the following command to verify acpid is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active acpid

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the acpid is masked, run the following command:
$ sudo systemctl show acpid | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "acpid" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_atd_disabled_question:question:1">
          <ocil:question_text>To check that the atd service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled atd
Output should indicate the atd service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled atd disabled

Run the following command to verify atd is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active atd

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the atd is masked, run the following command:
$ sudo systemctl show atd | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "atd" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_auditd_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
auditd service:
$ sudo systemctl is-active auditd
If the service is running, it should return the following: active
      Is it the case that the auditd service is not running?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_autofs_disabled_question:question:1">
          <ocil:question_text>To check that the autofs service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled autofs
Output should indicate the autofs service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled autofs disabled

Run the following command to verify autofs is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active autofs

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the autofs is masked, run the following command:
$ sudo systemctl show autofs | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "autofs" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_avahi-daemon_disabled_question:question:1">
          <ocil:question_text>To check that the avahi-daemon service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled avahi-daemon
Output should indicate the avahi-daemon service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled avahi-daemon disabled

Run the following command to verify avahi-daemon is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active avahi-daemon

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the avahi-daemon is masked, run the following command:
$ sudo systemctl show avahi-daemon | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "avahi-daemon" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_bluetooth_disabled_question:question:1">
          <ocil:question_text>To check that the bluetooth service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled bluetooth
Output should indicate the bluetooth service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled bluetooth disabled

Run the following command to verify bluetooth is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active bluetooth

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the bluetooth is masked, run the following command:
$ sudo systemctl show bluetooth | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "bluetooth" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_certmonger_disabled_question:question:1">
          <ocil:question_text>To check that the certmonger service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled certmonger
Output should indicate the certmonger service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled certmonger disabled

Run the following command to verify certmonger is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active certmonger

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the certmonger is masked, run the following command:
$ sudo systemctl show certmonger | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "certmonger" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_chronyd_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
chronyd service:
$ sudo systemctl is-active chronyd
If the service is running, it should return the following: active
      Is it the case that the chronyd process is not running?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_chronyd_or_ntpd_enabled_question:question:1">
          <ocil:question_text>


Run the following command to determine the current status of the
chronyd service:
$ sudo systemctl is-active chronyd
If the service is running, it should return the following: active



Run the following command to determine the current status of the
ntpd service:
$ sudo systemctl is-active ntpd
If the service is running, it should return the following: active
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_cockpit_disabled_question:question:1">
          <ocil:question_text>To check that the cockpit service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled cockpit
Output should indicate the cockpit service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled cockpit disabled

Run the following command to verify cockpit is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active cockpit

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the cockpit is masked, run the following command:
$ sudo systemctl show cockpit | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "cockpit" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_cpupower_disabled_question:question:1">
          <ocil:question_text>To check that the cpupower service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled cpupower
Output should indicate the cpupower service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled cpupower disabled

Run the following command to verify cpupower is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active cpupower

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the cpupower is masked, run the following command:
$ sudo systemctl show cpupower | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "cpupower" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_cron_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
crond service:
$ sudo systemctl is-active crond
If the service is running, it should return the following: active
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_crond_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
crond service:
$ sudo systemctl is-active crond
If the service is running, it should return the following: active
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_cups_disabled_question:question:1">
          <ocil:question_text>To check that the cups service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled cups
Output should indicate the cups service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled cups disabled

Run the following command to verify cups is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active cups

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the cups is masked, run the following command:
$ sudo systemctl show cups | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "cups" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_debug-shell_disabled_question:question:1">
          <ocil:question_text>To check that the debug-shell service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled debug-shell
Output should indicate the debug-shell service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled debug-shell disabled

Run the following command to verify debug-shell is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active debug-shell

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the debug-shell is masked, run the following command:
$ sudo systemctl show debug-shell | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "debug-shell" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_dhcpd_disabled_question:question:1">
          <ocil:question_text>To check that the dhcpd service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled dhcpd
Output should indicate the dhcpd service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled dhcpd disabled

Run the following command to verify dhcpd is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active dhcpd

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the dhcpd is masked, run the following command:
$ sudo systemctl show dhcpd | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "dhcpd" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_dovecot_disabled_question:question:1">
          <ocil:question_text>To check that the dovecot service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled dovecot
Output should indicate the dovecot service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled dovecot disabled

Run the following command to verify dovecot is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active dovecot

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the dovecot is masked, run the following command:
$ sudo systemctl show dovecot | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "dovecot" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_fapolicyd_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
fapolicyd service:
$ sudo systemctl is-active fapolicyd
If the service is running, it should return the following: active
      Is it the case that the service is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_firewalld_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
firewalld service:
$ sudo systemctl is-active firewalld
If the service is running, it should return the following: active
      Is it the case that the "firewalld" service is disabled, masked, or not started.?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_httpd_disabled_question:question:1">
          <ocil:question_text>To check that the httpd service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled httpd
Output should indicate the httpd service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled httpd disabled

Run the following command to verify httpd is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active httpd

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the httpd is masked, run the following command:
$ sudo systemctl show httpd | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "httpd" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_ip6tables_enabled_question:question:1">
          <ocil:question_text>If IPv6 is disabled, this is not applicable.



Run the following command to determine the current status of the
ip6tables service:
$ sudo systemctl is-active ip6tables
If the service is running, it should return the following: active
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_iptables_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
iptables service:
$ sudo systemctl is-active iptables
If the service is running, it should return the following: active
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_kdump_disabled_question:question:1">
          <ocil:question_text>To check that the kdump service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled kdump
Output should indicate the kdump service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled kdump disabled

Run the following command to verify kdump is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active kdump

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the kdump is masked, run the following command:
$ sudo systemctl show kdump | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "kdump" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_mdmonitor_disabled_question:question:1">
          <ocil:question_text>To check that the mdmonitor service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled mdmonitor
Output should indicate the mdmonitor service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled mdmonitor disabled

Run the following command to verify mdmonitor is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active mdmonitor

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the mdmonitor is masked, run the following command:
$ sudo systemctl show mdmonitor | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "mdmonitor" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_nails_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
nails service:
$ sudo systemctl is-active nails
If the service is running, it should return the following: active
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_named_disabled_question:question:1">
          <ocil:question_text>To check that the named service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled named
Output should indicate the named service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled named disabled

Run the following command to verify named is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active named

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the named is masked, run the following command:
$ sudo systemctl show named | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "named" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_netconsole_disabled_question:question:1">
          <ocil:question_text>To check that the netconsole service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled netconsole
Output should indicate the netconsole service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled netconsole disabled

Run the following command to verify netconsole is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active netconsole

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the netconsole is masked, run the following command:
$ sudo systemctl show netconsole | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "netconsole" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_nfs_disabled_question:question:1">
          <ocil:question_text>To check that the nfs-server service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled nfs-server
Output should indicate the nfs-server service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled nfs-server disabled

Run the following command to verify nfs-server is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active nfs-server

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the nfs-server is masked, run the following command:
$ sudo systemctl show nfs-server | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "nfs-server" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_nftables_disabled_question:question:1">
          <ocil:question_text>To check that the nftables service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled nftables
Output should indicate the nftables service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled nftables disabled

Run the following command to verify nftables is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active nftables

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the nftables is masked, run the following command:
$ sudo systemctl show nftables | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "nftables" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_nftables_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
nftables service:
$ sudo systemctl is-active nftables
If the service is running, it should return the following: active
      Is it the case that the "nftables" service is disabled, masked, or not started.?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_ntp_enabled_question:question:1">
          <ocil:question_text>


Run the following command to determine the current status of the
ntp service:
$ sudo systemctl is-active ntp
If the service is running, it should return the following: active
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_ntpd_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
ntpd service:
$ sudo systemctl is-active ntpd
If the service is running, it should return the following: active
      Is it the case that ?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_ntpdate_disabled_question:question:1">
          <ocil:question_text>To check that the ntpdate service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled ntpdate
Output should indicate the ntpdate service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled ntpdate disabled

Run the following command to verify ntpdate is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active ntpdate

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the ntpdate is masked, run the following command:
$ sudo systemctl show ntpdate | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "ntpdate" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_oddjobd_disabled_question:question:1">
          <ocil:question_text>To check that the oddjobd service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled oddjobd
Output should indicate the oddjobd service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled oddjobd disabled

Run the following command to verify oddjobd is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active oddjobd

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the oddjobd is masked, run the following command:
$ sudo systemctl show oddjobd | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "oddjobd" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_pcscd_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
pcscd service:
$ sudo systemctl is-active pcscd
If the service is running, it should return the following: active
      Is it the case that the pcscd service is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_portreserve_disabled_question:question:1">
          <ocil:question_text>To check that the portreserve service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled portreserve
Output should indicate the portreserve service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled portreserve disabled

Run the following command to verify portreserve is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active portreserve

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the portreserve is masked, run the following command:
$ sudo systemctl show portreserve | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "portreserve" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_postfix_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
postfix service:
$ sudo systemctl is-active postfix
If the service is running, it should return the following: active
      Is it the case that the system is not a cross domain solution and the service is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_psacct_enabled_question:question:1">
          <ocil:question_text>To check that the psacct service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled psacct
Output should indicate the psacct service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled psacct disabled

Run the following command to verify psacct is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active psacct

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the psacct is masked, run the following command:
$ sudo systemctl show psacct | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "psacct" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_qpidd_disabled_question:question:1">
          <ocil:question_text>To check that the qpidd service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled qpidd
Output should indicate the qpidd service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled qpidd disabled

Run the following command to verify qpidd is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active qpidd

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the qpidd is masked, run the following command:
$ sudo systemctl show qpidd | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "qpidd" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_quota_nld_disabled_question:question:1">
          <ocil:question_text>To check that the quota_nld service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled quota_nld
Output should indicate the quota_nld service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled quota_nld disabled

Run the following command to verify quota_nld is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active quota_nld

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the quota_nld is masked, run the following command:
$ sudo systemctl show quota_nld | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "quota_nld" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_rdisc_disabled_question:question:1">
          <ocil:question_text>To check that the rdisc service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled rdisc
Output should indicate the rdisc service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled rdisc disabled

Run the following command to verify rdisc is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active rdisc

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the rdisc is masked, run the following command:
$ sudo systemctl show rdisc | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "rdisc" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_rexec_disabled_question:question:1">
          <ocil:question_text>
To check that the rexec service is disabled in system boot configuration with xinetd, run the following command:
$ chkconfig rexec --list
Output should indicate the rexec service has either not been installed, or has been disabled, as shown in the example below:
$ chkconfig rexec --list

Note: This output shows SysV services only and does not include native
systemd services. SysV configuration data might be overridden by native
systemd configuration.

If you want to list systemd services use 'systemctl list-unit-files'.
To see services enabled on particular target use
'systemctl list-dependencies [target]'.

rexec       off

To check that the rexec socket is disabled in system boot configuration with systemd, run the following command:
$ systemctl is-enabled rexec
Output should indicate the rexec socket has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled rexecdisabled

Run the following command to verify rexec is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active rexec

If the socket is not running the command will return the following output:
inactive

The socket will also be masked, to check that the rexec is masked, run the following command:
$ sudo systemctl show rexec | grep "LoadState\|UnitFileState"

If the socket is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that service and/or socket are running?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_rhnsd_disabled_question:question:1">
          <ocil:question_text>To check that the rhnsd service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled rhnsd
Output should indicate the rhnsd service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled rhnsd disabled

Run the following command to verify rhnsd is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active rhnsd

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the rhnsd is masked, run the following command:
$ sudo systemctl show rhnsd | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "rhnsd" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_rhsmcertd_disabled_question:question:1">
          <ocil:question_text>To check that the rhsmcertd service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled rhsmcertd
Output should indicate the rhsmcertd service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled rhsmcertd disabled

Run the following command to verify rhsmcertd is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active rhsmcertd

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the rhsmcertd is masked, run the following command:
$ sudo systemctl show rhsmcertd | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "rhsmcertd" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_rlogin_disabled_question:question:1">
          <ocil:question_text>
To check that the rlogin service is disabled in system boot configuration with xinetd, run the following command:
$ chkconfig rlogin --list
Output should indicate the rlogin service has either not been installed, or has been disabled, as shown in the example below:
$ chkconfig rlogin --list

Note: This output shows SysV services only and does not include native
systemd services. SysV configuration data might be overridden by native
systemd configuration.

If you want to list systemd services use 'systemctl list-unit-files'.
To see services enabled on particular target use
'systemctl list-dependencies [target]'.

rlogin       off

To check that the rlogin socket is disabled in system boot configuration with systemd, run the following command:
$ systemctl is-enabled rlogin
Output should indicate the rlogin socket has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled rlogindisabled

Run the following command to verify rlogin is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active rlogin

If the socket is not running the command will return the following output:
inactive

The socket will also be masked, to check that the rlogin is masked, run the following command:
$ sudo systemctl show rlogin | grep "LoadState\|UnitFileState"

If the socket is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that service and/or socket are running?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_rngd_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
rngd service:
$ sudo systemctl is-active rngd
If the service is running, it should return the following: active
      Is it the case that the "rngd" service is disabled, masked, or not started.?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_rpcsvcgssd_disabled_question:question:1">
          <ocil:question_text>To check that the rpcsvcgssd service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled rpcsvcgssd
Output should indicate the rpcsvcgssd service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled rpcsvcgssd disabled

Run the following command to verify rpcsvcgssd is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active rpcsvcgssd

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the rpcsvcgssd is masked, run the following command:
$ sudo systemctl show rpcsvcgssd | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "rpcsvcgssd" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_rsh_disabled_question:question:1">
          <ocil:question_text>
To check that the rsh service is disabled in system boot configuration with xinetd, run the following command:
$ chkconfig rsh --list
Output should indicate the rsh service has either not been installed, or has been disabled, as shown in the example below:
$ chkconfig rsh --list

Note: This output shows SysV services only and does not include native
systemd services. SysV configuration data might be overridden by native
systemd configuration.

If you want to list systemd services use 'systemctl list-unit-files'.
To see services enabled on particular target use
'systemctl list-dependencies [target]'.

rsh       off

To check that the rsh socket is disabled in system boot configuration with systemd, run the following command:
$ systemctl is-enabled rsh
Output should indicate the rsh socket has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled rshdisabled

Run the following command to verify rsh is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active rsh

If the socket is not running the command will return the following output:
inactive

The socket will also be masked, to check that the rsh is masked, run the following command:
$ sudo systemctl show rsh | grep "LoadState\|UnitFileState"

If the socket is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that service and/or socket are running?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_rsyncd_disabled_question:question:1">
          <ocil:question_text>To check that the rsyncd service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled rsyncd
Output should indicate the rsyncd service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled rsyncd disabled

Run the following command to verify rsyncd is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active rsyncd

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the rsyncd is masked, run the following command:
$ sudo systemctl show rsyncd | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "rsyncd" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_rsyslog_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
rsyslog service:
$ sudo systemctl is-active rsyslog
If the service is running, it should return the following: active
      Is it the case that the "rsyslog" service is disabled, masked, or not started.?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_saslauthd_disabled_question:question:1">
          <ocil:question_text>To check that the saslauthd service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled saslauthd
Output should indicate the saslauthd service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled saslauthd disabled

Run the following command to verify saslauthd is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active saslauthd

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the saslauthd is masked, run the following command:
$ sudo systemctl show saslauthd | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "saslauthd" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_slapd_disabled_question:question:1">
          <ocil:question_text>To check that the slapd service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled slapd
Output should indicate the slapd service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled slapd disabled

Run the following command to verify slapd is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active slapd

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the slapd is masked, run the following command:
$ sudo systemctl show slapd | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "slapd" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_smb_disabled_question:question:1">
          <ocil:question_text>To check that the smb service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled smb
Output should indicate the smb service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled smb disabled

Run the following command to verify smb is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active smb

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the smb is masked, run the following command:
$ sudo systemctl show smb | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "smb" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_snmpd_disabled_question:question:1">
          <ocil:question_text>To check that the snmpd service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled snmpd
Output should indicate the snmpd service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled snmpd disabled

Run the following command to verify snmpd is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active snmpd

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the snmpd is masked, run the following command:
$ sudo systemctl show snmpd | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "snmpd" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_squid_disabled_question:question:1">
          <ocil:question_text>To check that the squid service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled squid
Output should indicate the squid service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled squid disabled

Run the following command to verify squid is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active squid

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the squid is masked, run the following command:
$ sudo systemctl show squid | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "squid" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_sshd_disabled_question:question:1">
          <ocil:question_text>To check that the sshd service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled sshd
Output should indicate the sshd service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled sshd disabled

Run the following command to verify sshd is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active sshd

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the sshd is masked, run the following command:
$ sudo systemctl show sshd | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "sshd" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_sshd_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
sshd service:
$ sudo systemctl is-active sshd
If the service is running, it should return the following: active
      Is it the case that sshd service is disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_sssd_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
sssd service:
$ sudo systemctl is-active sssd
If the service is running, it should return the following: active
      Is it the case that the service is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_syslogng_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
syslog-ng service:
$ sudo systemctl is-active syslog-ng
If the service is running, it should return the following: active
      Is it the case that the "syslog-ng" service is disabled, masked, or not started.?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_sysstat_disabled_question:question:1">
          <ocil:question_text>To check that the sysstat service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled sysstat
Output should indicate the sysstat service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled sysstat disabled

Run the following command to verify sysstat is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active sysstat

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the sysstat is masked, run the following command:
$ sudo systemctl show sysstat | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "sysstat" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_systemd-coredump_disabled_question:question:1">
          <ocil:question_text>To verify that acquiring, saving, and processing core dumps is disabled, run the
following command:
$ systemctl status systemd-coredump.socket
The output should be similar to:
● systemd-coredump.socket
   Loaded: masked (Reason: Unit systemd-coredump.socket is masked.)
   Active: inactive (dead) ...

      Is it the case that unit systemd-coredump.socket is not masked or running?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_systemd-journal-upload_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
systemd-journal-upload service:
$ sudo systemctl is-active systemd-journal-upload
If the service is running, it should return the following: active
      Is it the case that the systemd-journal-upload service is not running?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_systemd-journald_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
systemd-journald service:
$ sudo systemctl is-active systemd-journald
If the service is running, it should return the following: active
      Is it the case that the systemd-journald service is not running?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_telnet_disabled_question:question:1">
          <ocil:question_text>
To check that the telnet service is disabled in system boot configuration with xinetd, run the following command:
$ chkconfig telnet --list
Output should indicate the telnet service has either not been installed, or has been disabled, as shown in the example below:
$ chkconfig telnet --list

Note: This output shows SysV services only and does not include native
systemd services. SysV configuration data might be overridden by native
systemd configuration.

If you want to list systemd services use 'systemctl list-unit-files'.
To see services enabled on particular target use
'systemctl list-dependencies [target]'.

telnet       off

To check that the telnet socket is disabled in system boot configuration with systemd, run the following command:
$ systemctl is-enabled telnet
Output should indicate the telnet socket has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled telnetdisabled

Run the following command to verify telnet is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active telnet

If the socket is not running the command will return the following output:
inactive

The socket will also be masked, to check that the telnet is masked, run the following command:
$ sudo systemctl show telnet | grep "LoadState\|UnitFileState"

If the socket is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that service and/or socket are running?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_tftp_disabled_question:question:1">
          <ocil:question_text>To check that the tftp service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled tftp
Output should indicate the tftp service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled tftp disabled

Run the following command to verify tftp is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active tftp

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the tftp is masked, run the following command:
$ sudo systemctl show tftp | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "tftp" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_ufw_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
ufw service:
$ sudo systemctl is-active ufw
If the service is running, it should return the following: active
      Is it the case that the service is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_usbguard_enabled_question:question:1">
          <ocil:question_text>

Run the following command to determine the current status of the
usbguard service:
$ sudo systemctl is-active usbguard
If the service is running, it should return the following: active
      Is it the case that the service is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_vsftpd_disabled_question:question:1">
          <ocil:question_text>To check that the vsftpd service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled vsftpd
Output should indicate the vsftpd service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled vsftpd disabled

Run the following command to verify vsftpd is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active vsftpd

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the vsftpd is masked, run the following command:
$ sudo systemctl show vsftpd | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "vsftpd" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_xinetd_disabled_question:question:1">
          <ocil:question_text>If network services are using the xinetd service, this is not applicable.

To check that the xinetd service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled xinetd
Output should indicate the xinetd service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled xinetd disabled

Run the following command to verify xinetd is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active xinetd

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the xinetd is masked, run the following command:
$ sudo systemctl show xinetd | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "xinetd" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_ypbind_disabled_question:question:1">
          <ocil:question_text>To check that the ypbind service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled ypbind
Output should indicate the ypbind service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled ypbind disabled

Run the following command to verify ypbind is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active ypbind

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the ypbind is masked, run the following command:
$ sudo systemctl show ypbind | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "ypbind" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_ypserv_disabled_question:question:1">
          <ocil:question_text>To check that the ypserv service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled ypserv
Output should indicate the ypserv service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled ypserv disabled

Run the following command to verify ypserv is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active ypserv

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the ypserv is masked, run the following command:
$ sudo systemctl show ypserv | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "ypserv" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-service_zebra_disabled_question:question:1">
          <ocil:question_text>To check that the zebra service is disabled in system boot configuration,
run the following command:
$ sudo systemctl is-enabled zebra
Output should indicate the zebra service has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled zebra disabled

Run the following command to verify zebra is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active zebra

If the service is not running the command will return the following output:
inactive

The service will also be masked, to check that the zebra is masked, run the following command:
$ sudo systemctl show zebra | grep "LoadState\|UnitFileState"

If the service is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the "zebra" is loaded and not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-set_firewalld_appropriate_zone_question:question:1">
          <ocil:question_text>To verify that the interface(s) follow site policy for zone assignment run the 
following command: 
$ sudo nmcli -t connection show | awk -F: '{if($4){print $4}}' | while read INT;
do firewall-cmd --get-active-zones | grep -B1 $INT; done
If your have to assign an interface to the appropriate zone run the following command: 
$ sudo firewall-cmd --zone= --change-interface=
      Is it the case that Your system accepts all incoming packets for unnecessary services and ports?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-set_firewalld_default_zone_question:question:1">
          <ocil:question_text>Inspect the file /etc/firewalld/firewalld.conf to determine
the default zone for the firewalld. It should be set to DefaultZone=drop:
$ sudo grep DefaultZone /etc/firewalld/firewalld.conf
      Is it the case that the default zone is not set to DROP?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-set_ip6tables_default_rule_question:question:1">
          <ocil:question_text>If IPv6 is disabled, this is not applicable.

Inspect the file /etc/sysconfig/ip6tables to determine
the default policy for the INPUT chain. It should be set to DROP:
$ sudo grep ":INPUT" /etc/sysconfig/ip6tables
      Is it the case that the default policy for the INPUT chain is not set to DROP?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-set_iptables_default_rule_question:question:1">
          <ocil:question_text>Inspect the file /etc/sysconfig/iptables to determine
the default policy for the INPUT chain. It should be set to DROP:
$ sudo grep ":INPUT" /etc/sysconfig/iptables
      Is it the case that the default policy for the INPUT chain is not set to DROP?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-set_iptables_default_rule_forward_question:question:1">
          <ocil:question_text>Run the following command to ensure the default FORWARD policy is DROP:
grep ":FORWARD" /etc/sysconfig/iptables
The output should be similar to the following:
$ sudo grep ":FORWARD" /etc/sysconfig/iptables
:FORWARD DROP [0:0
      Is it the case that the default policy for the FORWARD chain is not set to DROP?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-set_ipv6_loopback_traffic_question:question:1">
          <ocil:question_text>Verify that the ipv6 loopback interface has required rules in order:
$ iptables -L INPUT -v -n
      Is it the case that ipv6 loopback traffic is not configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-set_loopback_traffic_question:question:1">
          <ocil:question_text>Run the following commands and verify output:

# iptables -L INPUT -v -n | grep lo | grep ACCEPT


# iptables -L INPUT -v -n | grep 127.0.0.0\/8 | grep DROP


# iptables -L OUTPUT -v -n | grep lo | grep ACCEPT

      Is it the case that loopback traffic is not configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-set_nftables_table_question:question:1">
          <ocil:question_text>To verify that a nftables table exists, run the following command:
$ sudo nft list tables
Output should include a list of nftables similar to:

  table  

      Is it the case that a nftables table does not exist?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-set_password_hashing_algorithm_libuserconf_question:question:1">
          <ocil:question_text>
Verify that the libuser is set to encrypt password with a FIPS 140-2 approved cryptographic hashing algorithm.

Check the hashing algorithm that is being used to hash passwords with the following command:

$ sudo grep -i crypt_style /etc/libuser.conf

crypt_style = 
      Is it the case that crypt_style is not set to sha512?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-set_password_hashing_algorithm_logindefs_question:question:1">
          <ocil:question_text>
Verify that the shadow password suite configuration is set to encrypt password with a FIPS 140-2 approved cryptographic hashing algorithm.

Check the hashing algorithm that is being used to hash passwords with the following command:

$ sudo grep -i ENCRYPT_METHOD  /etc/login.defs

ENCRYPT_METHOD 
      Is it the case that ENCRYPT_METHOD is not set to &lt;sub idref="var_password_hashing_algorithm" /&gt;?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-set_password_hashing_algorithm_passwordauth_question:question:1">
          <ocil:question_text>Inspect the password section of /etc/pam.d/password-auth
and ensure that the pam_unix.so module is configured to use the argument
:

$ grep  /etc/pam.d/password-auth
      Is it the case that it does not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-set_password_hashing_algorithm_systemauth_question:question:1">
          <ocil:question_text>Inspect the password section of /etc/pam.d/system-auth
and ensure that the pam_unix.so module is configured to use the argument
:

$ sudo grep "^password.*pam_unix\.so.*" /etc/pam.d/system-auth

password sufficient pam_unix.so 
      Is it the case that "&lt;sub idref="var_password_hashing_algorithm_pam" /&gt;" is missing, or is commented out?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-set_password_hashing_min_rounds_logindefs_question:question:1">
          <ocil:question_text>Inspect /etc/login.defs and ensure that if either
SHA_CRYPT_MIN_ROUNDS or SHA_CRYPT_MAX_ROUNDS
are set, they must have the minimum value of .
      Is it the case that it does not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-snmpd_no_rwusers_question:question:1">
          <ocil:question_text>To ensure there are no read-write users, run the following command:
$ sudo grep -v "^#" /etc/snmp/snmpd.conf| grep 'rwuser'
There should be no output.
      Is it the case that there are users who can write to SNMP values?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-snmpd_not_default_password_question:question:1">
          <ocil:question_text>To ensure the default password is not set, run the following command:
$ sudo grep -v "^#" /etc/snmp/snmpd.conf| grep -E 'public|private'
There should be no output.
      Is it the case that the default SNMP passwords public and private have not been changed or removed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-snmpd_use_newer_protocol_question:question:1">
          <ocil:question_text>To ensure only SNMPv3 or newer is used, run the following command:
$ sudo grep 'rocommunity\|rwcommunity\|com2sec' /etc/snmp/snmpd.conf | grep -v "^#"
There should be no output.
      Is it the case that there is output?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-socket_systemd-journal-remote_disabled_question:question:1">
          <ocil:question_text>
To check that the systemd-journal-remote.socket socket is disabled in system boot configuration with systemd, run the following command:
$ systemctl is-enabled systemd-journal-remote.socket
Output should indicate the systemd-journal-remote.socket socket has either not been installed,
or has been disabled at all runlevels, as shown in the example below:
$ sudo systemctl is-enabled systemd-journal-remote.socketdisabled

Run the following command to verify systemd-journal-remote.socket is not active (i.e. not running) through current runtime configuration:
$ sudo systemctl is-active systemd-journal-remote.socket

If the socket is not running the command will return the following output:
inactive

The socket will also be masked, to check that the systemd-journal-remote.socket is masked, run the following command:
$ sudo systemctl show systemd-journal-remote.socket | grep "LoadState\|UnitFileState"

If the socket is masked the command will return the following outputs:

LoadState=masked

UnitFileState=masked
      Is it the case that the systemd-journal-remote socket is not masked?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ssh_client_rekey_limit_question:question:1">
          <ocil:question_text>To check if RekeyLimit is set correctly, run the following command:
$ sudo grep RekeyLimit /etc/ssh/ssh_config.d/*.conf
If configured properly, output should be
/etc/ssh/ssh_config.d/02-rekey-limit.conf:
RekeyLimit  
Check also the main configuration file with the following command:
$ sudo grep RekeyLimit /etc/ssh/ssh_config
The command should not return any output.
      Is it the case that it is commented out or is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ssh_client_use_strong_rng_csh_question:question:1">
          <ocil:question_text>Run the following command to verify that SSH client is configured to use 32 bytes of entropy:
grep SSH_USE_STRONG_RNG /etc/profile.d/cc-ssh-strong-rng.csh
It should return the following output:
setenv SSH_USE_STRONG_RNG 32.
      Is it the case that SSH client is not configured to use 32 bytes of entropy or more?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ssh_client_use_strong_rng_sh_question:question:1">
          <ocil:question_text>Run the following command to verify that SSH client is configured to use 32 bytes of entropy:
grep SSH_USE_STRONG_RNG /etc/profile.d/cc-ssh-strong-rng.sh
The output should be:
export SSH_USE_STRONG_RNG=32
      Is it the case that SSH client is not configured to use 32 bytes of entropy or more?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-ssh_keys_passphrase_protected_question:question:1">
          <ocil:question_text>For each private key stored on the system, use the following command:
$ sudo ssh-keygen -y -f /path/to/file
If the contents of the key are displayed, this is a finding.
      Is it the case that no ssh private key is accessible without a passcode?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_allow_only_protocol2_question:question:1">
          <ocil:question_text>To check which SSH protocol version is allowed, check version of openssh-server with following command:

$ rpm -qi openssh-server | grep Version

Versions equal to or higher than 7.4 only allow Protocol 2.
If version is lower than 7.4, run the following command to check configuration:
$ sudo grep Protocol /etc/ssh/sshd_config
If configured properly, output should be Protocol 2
      Is it the case that it is commented out or is not set correctly to Protocol 2?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_disable_compression_question:question:1">
          <ocil:question_text>To check if compression is enabled or set correctly, run the
following command:
$ sudo grep Compression /etc/ssh/sshd_config
If configured properly, output should be no or delayed.
      Is it the case that it is commented out, or is not set to no or delayed?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_disable_empty_passwords_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's PermitEmptyPasswords option is set, run the following command:

$ sudo grep -i PermitEmptyPasswords /etc/ssh/sshd_config

If a line indicating no is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_disable_forwarding_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's DisableForwarding option is set, run the following command:

$ sudo grep -i DisableForwarding /etc/ssh/sshd_config

If a line indicating yes is returned, then the required value is set.
      Is it the case that The DisableForwarding option doesn't exist or isn't set to yes?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_disable_gssapi_auth_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's GSSAPIAuthentication option is set, run the following command:

$ sudo grep -i GSSAPIAuthentication /etc/ssh/sshd_config

If a line indicating no is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_disable_kerb_auth_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's KerberosAuthentication option is set, run the following command:

$ sudo grep -i KerberosAuthentication /etc/ssh/sshd_config

If a line indicating no is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_disable_pubkey_auth_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's PubkeyAuthentication option is set, run the following command:

$ sudo grep -i PubkeyAuthentication /etc/ssh/sshd_config

If a line indicating no is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_disable_rhosts_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's IgnoreRhosts option is set, run the following command:

$ sudo grep -i IgnoreRhosts /etc/ssh/sshd_config

If a line indicating yes is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_disable_rhosts_rsa_question:question:1">
          <ocil:question_text>To check which SSH protocol version is allowed, check version of
openssh-server with following command:
$ rpm -qi openssh-server | grep Version
Versions equal to or higher than 7.4 have deprecated the RhostsRSAAuthentication option.
If version is lower than 7.4, run the following command to check configuration:



To determine how the SSH daemon's RhostsRSAAuthentication option is set, run the following command:

$ sudo grep -i RhostsRSAAuthentication /etc/ssh/sshd_config

If a line indicating no is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_disable_root_login_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's PermitRootLogin option is set, run the following command:

$ sudo grep -i PermitRootLogin /etc/ssh/sshd_config

If a line indicating no is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_disable_root_password_login_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's PermitRootLogin option is set, run the following command:

$ sudo grep -i PermitRootLogin /etc/ssh/sshd_config

If a line indicating prohibit-password is returned, then the required value is set.
      Is it the case that it is commented out or not configured properly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_disable_tcp_forwarding_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's AllowTcpForwarding option is set, run the following command:

$ sudo grep -i AllowTcpForwarding /etc/ssh/sshd_config

If a line indicating no is returned, then the required value is set.
      Is it the case that The AllowTcpForwarding option exists and is disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_disable_user_known_hosts_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's IgnoreUserKnownHosts option is set, run the following command:

$ sudo grep -i IgnoreUserKnownHosts /etc/ssh/sshd_config

If a line indicating yes is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_disable_x11_forwarding_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's X11Forwarding option is set, run the following command:

$ sudo grep -i X11Forwarding /etc/ssh/sshd_config

If a line indicating no is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_do_not_permit_user_env_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's PermitUserEnvironment option is set, run the following command:

$ sudo grep -i PermitUserEnvironment /etc/ssh/sshd_config

If a line indicating no is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_enable_gssapi_auth_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's GSSAPIAuthentication option is set, run the following command:

$ sudo grep -i GSSAPIAuthentication /etc/ssh/sshd_config

If a line indicating yes is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_enable_pam_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's UsePAM option is set, run the following command:

$ sudo grep -i UsePAM /etc/ssh/sshd_config

If a line indicating yes is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_enable_pubkey_auth_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's PubkeyAuthentication option is set, run the following command:

$ sudo grep -i PubkeyAuthentication /etc/ssh/sshd_config

If a line indicating yes is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_enable_strictmodes_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's StrictModes option is set, run the following command:

$ sudo grep -i StrictModes /etc/ssh/sshd_config

If a line indicating yes is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_enable_warning_banner_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's Banner option is set, run the following command:

$ sudo grep -i Banner /etc/ssh/sshd_config

If a line indicating /etc/issue is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_enable_warning_banner_net_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's Banner option is set, run the following command:

$ sudo grep -i Banner /etc/ssh/sshd_config

If a line indicating /etc/issue.net is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_enable_x11_forwarding_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's X11Forwarding option is set, run the following command:

$ sudo grep -i X11Forwarding /etc/ssh/sshd_config

If a line indicating yes is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_limit_user_access_question:question:1">
          <ocil:question_text>To ensure sshd limits the users who can log in, run the following:
$ sudo grep -rPi '^\h*(allow|deny)(users|groups)\h+\H+(\h+.*)?$' /etc/ssh/sshd_config*
If properly configured, the output should be a list of usernames and/or
groups allowed to log in to this system.
      Is it the case that sshd does not limit the users who can log in?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_print_last_log_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's PrintLastLog option is set, run the following command:

$ sudo grep -i PrintLastLog /etc/ssh/sshd_config

If a line indicating yes is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_rekey_limit_question:question:1">
          <ocil:question_text>To check if RekeyLimit is set correctly, run the
following command:

$ sudo grep RekeyLimit /etc/ssh/sshd_config

If configured properly, output should be
RekeyLimit  
      Is it the case that it is commented out or is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_set_idle_timeout_question:question:1">
          <ocil:question_text>Run the following command to see what the timeout interval is:
$ sudo grep ClientAliveInterval /etc/ssh/sshd_config
If properly configured, the output should be:
ClientAliveInterval 
      Is it the case that it is commented out or not configured properly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_set_keepalive_question:question:1">
          <ocil:question_text>To ensure ClientAliveInterval is set correctly, run the following command:
$ sudo grep ClientAliveCountMax /etc/ssh/sshd_config
If properly configured, the output should be:
ClientAliveCountMax 
For SSH earlier than v8.2, a ClientAliveCountMax value of 0 causes a timeout precisely when
the ClientAliveInterval is set.  Starting with v8.2, a value of 0 disables the timeout
functionality completely.
If the option is set to a number greater than 0, then the session will be disconnected after
ClientAliveInterval * ClientAliveCountMax seconds without receiving a keep alive message.
      Is it the case that it is commented out or not configured properly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_set_keepalive_0_question:question:1">
          <ocil:question_text>To ensure ClientAliveInterval is set correctly, run the following command:

$ sudo grep ClientAliveCountMax /etc/ssh/sshd_config

If properly configured, the output should be:
ClientAliveCountMax 0

In this case, the SSH timeout occurs precisely when
the ClientAliveInterval is set.
      Is it the case that it is commented out or not configured properly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_set_login_grace_time_question:question:1">
          <ocil:question_text>To ensure LoginGraceTime is set correctly, run the following command:
$ sudo grep LoginGraceTime /etc/ssh/sshd_config
If properly configured, the output should be:
LoginGraceTime 
If the option is set to a number greater than 0, then the unauthenticated session will be disconnected
after the configured number seconds.
      Is it the case that it is commented out or not configured properly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_set_loglevel_info_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's LogLevel option is set, run the following command:

$ sudo grep -i LogLevel /etc/ssh/sshd_config

If a line indicating INFO is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_set_loglevel_verbose_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's LogLevel option is set, run the following command:

$ sudo grep -i LogLevel /etc/ssh/sshd_config

If a line indicating VERBOSE is returned, then the required value is set.

      Is it the case that the required value is not set?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_set_max_auth_tries_question:question:1">
          <ocil:question_text>To ensure the MaxAuthTries parameter is set, run the following command:
$ sudo grep MaxAuthTries /etc/ssh/sshd_config
If properly configured, output should be:
MaxAuthTries 
      Is it the case that it is commented out or not configured properly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_set_max_sessions_question:question:1">
          <ocil:question_text>Run the following command to see what the max sessions number is:
$ sudo grep MaxSessions /etc/ssh/sshd_config
If properly configured, the output should be:
MaxSessions 
      Is it the case that MaxSessions is not configured or not configured correctly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_set_maxstartups_question:question:1">
          <ocil:question_text>To check if MaxStartups is configured, run the following command:
$ sudo grep -r ^[\s]*MaxStartups /etc/ssh/sshd_config*
If configured, this command should output the configuration.
      Is it the case that maxstartups is not configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_use_approved_ciphers_question:question:1">
          <ocil:question_text>Only FIPS ciphers should be used. To verify that only FIPS-approved
ciphers are in use, run the following command:
$ sudo grep Ciphers /etc/ssh/sshd_config
The output should contain only those ciphers which are FIPS-approved.
      Is it the case that FIPS ciphers are not configured or the enabled ciphers are not FIPS-approved?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_use_approved_kex_ordered_stig_question:question:1">
          <ocil:question_text>Only FIPS-approved key exchange algorithms must be used. To verify that only FIPS-approved
key exchange algorithms are in use, run the following command:
$ sudo grep -i kexalgorithms 
The output should contain only following algorithms (or a subset) in the exact order:

      Is it the case that KexAlgorithms option is commented out, contains non-approved algorithms, or the FIPS-approved algorithms are not in the exact order?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_use_approved_macs_question:question:1">
          <ocil:question_text>Only FIPS-approved MACs should be used. To verify that only FIPS-approved
MACs are in use, run the following command:
$ sudo grep -i macs /etc/ssh/sshd_config
The output should contain only those MACs which are FIPS-approved. Any use of other
ciphers or algorithms will result in the module entering the non-FIPS mode of
operation.
      Is it the case that MACs option is commented out or not using FIPS-approved hash algorithms?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_use_priv_separation_question:question:1">
          <ocil:question_text>To check if UsePrivilegeSeparation is enabled or set correctly, run the
following command:
$ sudo grep UsePrivilegeSeparation /etc/ssh/sshd_config
If configured properly, output should be .
      Is it the case that it is commented out or is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_use_strong_kex_question:question:1">
          <ocil:question_text>Only strong KEX algorithms should be used. To verify that only strong
KexAlgorithms are in use, run the following command:
$ sudo grep -i kexalgorithms /etc/ssh/sshd_config
The output should contain only those KexAlgorithms which are strong, namely,

      Is it the case that KexAlgorithms option is commented out or not using strong hash algorithms?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_use_strong_macs_question:question:1">
          <ocil:question_text>Only strong MACs should be used. To verify that only strong
MACs are in use, run the following command:
$ sudo grep -i macs /etc/ssh/sshd_config
The output should contain only those MACs which are strong, namely,
 hash functions.
      Is it the case that MACs option is commented out or not using strong hash algorithms?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_use_strong_rng_question:question:1">
          <ocil:question_text>To determine whether the SSH service is configured to use strong entropy seed,
run $ sudo grep SSH_USE_STRONG_RNG /etc/sysconfig/sshd
If a line indicating that SSH_USE_STRONG_RNG is set to 32 is returned,
then the option is set correctly.
      Is it the case that the SSH_USE_STRONG_RNG is not set to 32 in /etc/sysconfig/sshd?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sshd_x11_use_localhost_question:question:1">
          <ocil:question_text>


To determine how the SSH daemon's X11UseLocalhost option is set, run the following command:

$ sudo grep -i X11UseLocalhost /etc/ssh/sshd_config

If a line indicating yes is returned, then the required value is set.
      Is it the case that the display proxy is listening on wildcard address?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sssd_certificate_verification_question:question:1">
          <ocil:question_text>Check to see if Online Certificate Status Protocol (OCSP)
is enabled and using the proper digest value on the system with the following command:
$ sudo grep certificate_verification /etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf | grep -v "^#"
If configured properly, output should look like

    certificate_verification = ocsp_dgst=

      Is it the case that certificate_verification in sssd is not configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sssd_enable_certmap_question:question:1">
          <ocil:question_text>To verify Certmap is enabled in SSSD, run the following command:
$ sudo cat /etc/sssd/sssd.conf
If configured properly, output should contain section like the following

[certmap/testing.test/rule_name]
matchrule =&lt;SAN&gt;.*EDIPI@mil
maprule = (userCertificate;binary={cert!bin})
domains = testing.test

      Is it the case that Certmap is not configured in SSSD?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sssd_enable_pam_services_question:question:1">
          <ocil:question_text>To verify that SSSD is configured for PAM services, run the following command:
$ sudo grep services /etc/sssd/sssd.conf
If configured properly, output should be similar to
services = pam
      Is it the case that it does not exist or 'pam' is not added to the 'services' option under the 'sssd' section?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sssd_enable_smartcards_question:question:1">
          <ocil:question_text>To verify that smart cards are enabled in SSSD, run the following command:
$ sudo grep pam_cert_auth /etc/sssd/sssd.conf
If configured properly, output should be
pam_cert_auth = True
      Is it the case that smart cards are not enabled in SSSD?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sssd_has_trust_anchor_question:question:1">
          <ocil:question_text>Verify AlmaLinux OS 8 for PKI-based authentication has valid certificates by constructing a
certification path (which includes status information) to an accepted trust anchor.

Check that the system has a valid DoD root CA installed with the following command:

$ sudo openssl x509 -text -in /etc/sssd/pki/sssd_auth_ca_db.pem

Certificate:
Data:
Version: 3 (0x2)
Serial Number: 1 (0x1)
Signature Algorithm: sha256WithRSAEncryption
Issuer: C = US, O = U.S. Government, OU = DoD, OU = PKI, CN = DoD Root CA 3
Validity
Not Before: Mar 20 18:46:41 2012 GMT
Not After : Dec 30 18:46:41 2029 GMT
Subject: C = US, O = U.S. Government, OU = DoD, OU = PKI, CN = DoD Root CA 3
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
      Is it the case that root CA file is not a DoD-issued certificate with a valid date and installed in the /etc/sssd/pki/sssd_auth_ca_db.pem location?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sssd_ldap_configure_tls_ca_question:question:1">
          <ocil:question_text>To verify the operating system implements cryptography to protect the integrity of
remote ldap access sessions, run the following command:
$ sudo grep ldap_tls_cacert /etc/sssd/sssd.conf
The output should return the following with a correctly configured CA cert path:
ldap_tls_cacert /path/to/tls/ca.cert
      Is it the case that the TLS CA cert is not configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sssd_ldap_configure_tls_ca_dir_question:question:1">
          <ocil:question_text>To verify the operating system implements cryptography to protect the integrity of
remote ldap access sessions, run the following command:
$ sudo grep ldap_tls_cacertdir /etc/sssd/sssd.conf
The output should return the following with a correctly configured CA cert path:
ldap_tls_cacertdir /path/to/tls/cacert
      Is it the case that the TLS CA cert is not configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sssd_ldap_configure_tls_reqcert_question:question:1">
          <ocil:question_text>To verify the LDAP client backend demands a valid certificate from the server in
remote LDAP access sessions, run the following command:
$ sudo grep ldap_tls_reqcert /etc/sssd/sssd.conf
The output should return the following:
ldap_tls_reqcert = demand
      Is it the case that the TLS reqcert is not set to demand?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sssd_ldap_start_tls_question:question:1">
          <ocil:question_text>If the system is not using TLS, set the ldap_id_use_start_tls option
in /etc/sssd/sssd.conf to true.
      Is it the case that the 'ldap_id_use_start_tls' option is not set to 'true'?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sssd_memcache_timeout_question:question:1">
          <ocil:question_text>To verify that SSSD's in-memory cache expires after a day, run the following command:
$ sudo grep memcache_timeout /etc/sssd/sssd.conf
If configured properly, output should be memcache_timeout = .
      Is it the case that it does not exist or is not configured properly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sssd_offline_cred_expiration_question:question:1">
          <ocil:question_text>
Check if SSSD allows cached authentications with the following command:

$ sudo grep cache_credentials /etc/sssd/sssd.conf
cache_credentials = true

If "cache_credentials" is set to "false" or is missing no further checks are required.

To verify that SSSD expires offline credentials, run the following command:
$ sudo grep offline_credentials_expiration /etc/sssd/sssd.conf /etc/sssd/conf.d/*.conf
If configured properly, output should be
offline_credentials_expiration = 1
      Is it the case that it does not exist or is not configured properly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sssd_run_as_sssd_user_question:question:1">
          <ocil:question_text>To verify that SSSD is configured to run as user sssd, run the following command:
$ sudo grep -r '\buser\b' /etc/sssd
If configured properly, output should similar to /etc/sssd/conf.d/ospp.conf:user = sssd.
Sanity of SSSD configuration in general can be checked using $ sudo sssctl config-check
      Is it the case that it does not exist or is not configured properly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sssd_ssh_known_hosts_timeout_question:question:1">
          <ocil:question_text>To verify that SSSD expires known SSH host keys, run the following command:
$ sudo grep ssh_known_hosts_timeout /etc/sssd/sssd.conf
If configured properly, output should be
ssh_known_hosts_timeout = 
      Is it the case that it does not exist or is not configured properly?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudo_add_env_reset_question:question:1">
          <ocil:question_text>To determine if env_reset has been configured for sudo, run the following command:
$ sudo grep -ri "^[\s]*Defaults.*\benv_reset\b.*" /etc/sudoers /etc/sudoers.d/
The command should return a matching output.
      Is it the case that env_reset is not enabled in sudo?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudo_add_ignore_dot_question:question:1">
          <ocil:question_text>To determine if ignore_dot has been configured for sudo, run the following command:
$ sudo grep -ri "^[\s]*Defaults.*\bignore_dot\b.*" /etc/sudoers /etc/sudoers.d/
The command should return a matching output.
      Is it the case that ignore_dot is not enabled in sudo?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudo_add_noexec_question:question:1">
          <ocil:question_text>To determine if NOEXEC has been configured for sudo, run the following command:
$ sudo grep -ri "^[\s]*Defaults.*\bnoexec\b.*" /etc/sudoers /etc/sudoers.d/
The command should return a matching output.
      Is it the case that noexec is not enabled in sudo?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudo_add_passwd_timeout_question:question:1">
          <ocil:question_text>To determine if passwd_timeout has been configured for sudo, run the following command:
$ sudo grep -ri '^Defaults.*passwd_timeout=' /etc/sudoers /etc/sudoers.d/
The command should return a matching output.
      Is it the case that passwd_timeout is not set with the appropriate value for sudo?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudo_add_requiretty_question:question:1">
          <ocil:question_text>To determine if requiretty has been configured for sudo, run the following command:
$ sudo grep -ri "^[\s]*Defaults.*\brequiretty\b.*" /etc/sudoers /etc/sudoers.d/
The command should return a matching output.
      Is it the case that requiretty is not enabled in sudo?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudo_add_umask_question:question:1">
          <ocil:question_text>To determine if umask has been configured for sudo with the appropriate value,
run the following command:
$ sudo grep -ri '^Defaults.*umask=' /etc/sudoers /etc/sudoers.d/
The command should return a matching output.
      Is it the case that umask is not set with the appropriate value for sudo?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudo_add_use_pty_question:question:1">
          <ocil:question_text>To determine if use_pty has been configured for sudo, run the following command:
$ sudo grep -ri "^[\s]*Defaults.*\buse_pty\b.*" /etc/sudoers /etc/sudoers.d/
The command should return a matching output.
      Is it the case that use_pty is not enabled in sudo?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudo_custom_logfile_question:question:1">
          <ocil:question_text>To determine if logfile has been configured for sudo, run the following command:
$ sudo grep -ri "^[\s]*Defaults\s*\blogfile\b.*" /etc/sudoers /etc/sudoers.d/
The command should return a matching output.
      Is it the case that logfile is not enabled in sudo?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudo_dedicated_group_question:question:1">
          <ocil:question_text>To check the group ownership of /usr/bin/sudo,
run the command:
$ ls -lL /usr/bin/sudo
If properly configured, the output should indicate the following group-owner:

  
  
      Is it the case that /usr/bin/sudo does not have a group owner of
&lt;sub idref="var_sudo_dedicated_group" /&gt;
?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudo_remove_no_authenticate_question:question:1">
          <ocil:question_text>To determine if !authenticate has not been configured for sudo, run the following command:
$ sudo grep -r \!authenticate /etc/sudoers /etc/sudoers.d/
The command should return no output.
      Is it the case that !authenticate is specified in the sudo config files?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudo_remove_nopasswd_question:question:1">
          <ocil:question_text>To determine if NOPASSWD has been configured for sudo, run the following command:
$ sudo grep -ri nopasswd /etc/sudoers /etc/sudoers.d/
The command should return no output.
      Is it the case that nopasswd is specified in the sudo config files?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudo_require_authentication_question:question:1">
          <ocil:question_text>To determine if NOPASSWD or !authenticate have been configured for
sudo, run the following command:
$ sudo grep -ri "nopasswd\|\!authenticate" /etc/sudoers /etc/sudoers.d/
The command should return no output.
      Is it the case that nopasswd and/or !authenticate is enabled in sudo?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudo_require_reauthentication_question:question:1">
          <ocil:question_text>Verify the operating system requires re-authentication
when using the "sudo" command to elevate privileges, run the following command:
sudo grep -ri '^Defaults.*timestamp_timeout' /etc/sudoers /etc/sudoers.d
The output should be:
/etc/sudoers:Defaults timestamp_timeout=0 or "timestamp_timeout" is set to a positive number.
If conflicting results are returned, this is a finding.
      Is it the case that timestamp_timeout is not set with the appropriate value for sudo?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudo_restrict_others_executable_permission_question:question:1">
          <ocil:question_text>To check the permissions of /usr/bin/sudo,
run the command:
$ ls -l /usr/bin/sudo
If properly configured, the output should indicate the following permissions:
---s--x---
      Is it the case that /usr/bin/sudo does not have unix mode ---s--x---?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudo_restrict_privilege_elevation_to_authorized_question:question:1">
          <ocil:question_text>Determine if "sudoers" file restricts sudo access run the following commands:
$ sudo grep -PR '^\s*ALL\s+ALL\=\(ALL\)\s+ALL\s*$' /etc/sudoers /etc/sudoers.d/*
$ sudo grep -PR '^\s*ALL\s+ALL\=\(ALL\:ALL\)\s+ALL\s*$' /etc/sudoers /etc/sudoers.d/*
      Is it the case that either of the commands returned a line?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudo_vdsm_nopasswd_question:question:1">
          <ocil:question_text>To determine if NOPASSWD has been configured for the vdsm user for sudo,
run the following command:
$ sudo grep -ri nopasswd /etc/sudoers.d/
The command should return output only for the vdsm user.
      Is it the case that nopasswd is set for any users beyond vdsm?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudoers_default_includedir_question:question:1">
          <ocil:question_text>To determine whether sudo command includes configuration files from the appropriate directory,
run the following command:
$ sudo grep -rP '^[#@]include(dir)?' /etc/sudoers /etc/sudoers.d
If only the line /etc/sudoers:#includedir /etc/sudoers.d is returned, then the drop-in include configuration is set correctly.
Any other line returned is a finding.
      Is it the case that the /etc/sudoers doesn't include /etc/sudores.d or includes other directories??
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudoers_explicit_command_args_question:question:1">
          <ocil:question_text>To determine if arguments that commands can be executed with are restricted, run the following command:
$ sudo grep -PR '^(?:\s*[^#=]+)=(?:\s*(?:\([^\)]+\))?\s*(?!\s*\()[^,\s]+(?:[ \t]+[^,\s]+)+[ \t]*,)*(\s*(?:\([^\)]+\))?\s*(?!\s*\()[^,\s]+[ \t]*(?:,|$))' /etc/sudoers /etc/sudoers.d/
The command should return no output.
      Is it the case that /etc/sudoers file contains user specifications that allow execution of commands with any arguments?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudoers_no_command_negation_question:question:1">
          <ocil:question_text>To determine if negation is used to define commands users are allowed to execute using sudo, run the following command:
$ sudo grep -PR '^(?:\s*[^#=]+)=(?:\s*(?:\([^\)]+\))?\s*(?!\s*\()[^,!\n][^,\n]+,)*\s*(?:\([^\)]+\))?\s*(?!\s*\()(!\S+).*' /etc/sudoers /etc/sudoers.d/
The command should return no output.
      Is it the case that /etc/sudoers file contains rules that define the set of allowed commands using negation?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudoers_no_root_target_question:question:1">
          <ocil:question_text>To determine if the users are allowed to run commands as root, run the following commands:
$ sudo grep -PR '^\s*((?!root\b)[\w]+)\s*(\w+)\s*=\s*(.*,)?\s*[^\(\s]' /etc/sudoers /etc/sudoers.d/
and
$ sudo grep -PR '^\s*((?!root\b)[\w]+)\s*(\w+)\s*=\s*(.*,)?\s*\([\w\s]*\b(root|ALL)\b[\w\s]*\)' /etc/sudoers /etc/sudoers.d/
Both commands should return no output.
      Is it the case that /etc/sudoers file contains rules that allow non-root users to run commands as root?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sudoers_validate_passwd_question:question:1">
          <ocil:question_text>Run the following command to Verify that the sudoers security policy is configured to use the invoking user's password for privilege escalation:
 sudo cvtsudoers -f sudoers /etc/sudoers | grep -E '^Defaults !?(rootpw|targetpw|runaspw)' 
or if cvtsudoers not supported:
 sudo find /etc/sudoers /etc/sudoers.d \( \! -name '*~' -a \! -name '*.*' \) -exec grep -E --with-filename '^[[:blank:]]*Defaults[[:blank:]](.*[[:blank:]])?!?\b(rootpw|targetpw|runaspw)' -- {} \; 
If no results are returned, this is a finding.
If conflicting results are returned, this is a finding.
If "Defaults !targetpw" is not defined, this is a finding.
If "Defaults !rootpw" is not defined, this is a finding.
If "Defaults !runaspw" is not defined, this is a finding.
      Is it the case that invoke user passwd when using sudo?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysconfig_networking_bootproto_ifcfg_question:question:1">
          <ocil:question_text>To verify that DHCP is not being used, examine the following file for each interface:
# /etc/sysconfig/network-scripts/ifcfg-interface
Look for the following:
BOOTPROTO=none
and the following, substituting the appropriate values based on your site's addressing scheme:
NETMASK=255.255.255.0
IPADDR=192.168.1.2
GATEWAY=192.168.1.1
      Is it the case that it does not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_crypto_fips_enabled_question:question:1">
          <ocil:question_text>To verify that kernel parameter 'crypto.fips_enabled' is set properly, run the following command:
sysctl crypto.fips_enabled
The output should contain the following:
crypto.fips_enabled = 1
      Is it the case that crypto.fips_enabled is not 1?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_fs_protected_hardlinks_question:question:1">
          <ocil:question_text>The runtime status of the fs.protected_hardlinks kernel parameter can be queried
by running the following command:
$ sysctl fs.protected_hardlinks
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_fs_protected_symlinks_question:question:1">
          <ocil:question_text>The runtime status of the fs.protected_symlinks kernel parameter can be queried
by running the following command:
$ sysctl fs.protected_symlinks
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_fs_suid_dumpable_question:question:1">
          <ocil:question_text>The runtime status of the fs.suid_dumpable kernel parameter can be queried
by running the following command:
$ sysctl fs.suid_dumpable
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_kernel_core_pattern_question:question:1">
          <ocil:question_text>The runtime status of the kernel.core_pattern kernel parameter can be queried
by running the following command:
$ sysctl kernel.core_pattern
|/bin/false.

      Is it the case that the returned line does not have a value of "|/bin/false", or a line is not
returned and the need for core dumps is not documented with the Information
System Security Officer (ISSO) as an operational requirement?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_kernel_core_uses_pid_question:question:1">
          <ocil:question_text>The runtime status of the kernel.core_uses_pid kernel parameter can be queried
by running the following command:
$ sysctl kernel.core_uses_pid
0.
      Is it the case that the returned line does not have a value of 0?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_kernel_dmesg_restrict_question:question:1">
          <ocil:question_text>The runtime status of the kernel.dmesg_restrict kernel parameter can be queried
by running the following command:
$ sysctl kernel.dmesg_restrict
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_kernel_exec_shield_question:question:1">
          <ocil:question_text>To verify ExecShield is enabled on 64-bit AlmaLinux OS 8 systems,
run the following command:
$ dmesg | grep '[NX|DX]*protection'
The output should not contain 'disabled by kernel command line option'.
Inspect the form of default GRUB 2 command line for the Linux operating system
in grubenv that can be found either in /boot/grub2 in case of legacy BIOS systems, or in /boot/efi/EFI/almalinux in case of UEFI systems.
If they include noexec=off, then the parameter
is configured at boot time.
$ sudo grep 'kernelopts.*noexec=off.*' GRUBENV_FILE_LOCATION
Fill in GRUBENV_FILE_LOCATION based on information above.



For 32-bit AlmaLinux OS 8 systems, run the following command:
$ sysctl kernel.exec-shield
The output should be:
To set the runtime status of the kernel.exec-shield kernel parameter,
run the following command:
$ sudo sysctl -w kernel.exec-shield=1

To make sure that the setting is persistent,
add the following line to a file in the directory /etc/sysctl.d:
kernel.exec-shield = 1
      Is it the case that ExecShield is not supported by the hardware, is not enabled, or has been disabled by the kernel configuration.?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_kernel_kexec_load_disabled_question:question:1">
          <ocil:question_text>The runtime status of the kernel.kexec_load_disabled kernel parameter can be queried
by running the following command:
$ sysctl kernel.kexec_load_disabled
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_kernel_kptr_restrict_question:question:1">
          <ocil:question_text>The runtime status of the kernel.kptr_restrict kernel parameter can be queried
by running the following command:
$ sysctl kernel.kptr_restrict
The output of the command should indicate:
kernel.kptr_restrict = 1

or:
kernel.kptr_restrict = 2

The output of the command should not indicate:
kernel.kptr_restrict = 0

The preferable way how to assure the runtime compliance is to have
correct persistent configuration, and rebooting the system.

The persistent kernel parameter configuration is performed by specifying the appropriate
assignment in any file located in the /etc/sysctl.d directory.
Verify that there is not any existing incorrect configuration by executing the following command:
$ grep -r '^\s*kernel.kptr_restrict\s*=' /etc/sysctl.conf /etc/sysctl.d
The command should not find any assignments other than:
kernel.kptr_restrict = 1

or:
kernel.kptr_restrict = 2


Conflicting assignments are not allowed.
      Is it the case that the kernel.kptr_restrict is not set to 1 or 2 or is configured to be 0?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_kernel_modules_disabled_question:question:1">
          <ocil:question_text>The runtime status of the kernel.modules_disabled kernel parameter can be queried
by running the following command:
$ sysctl kernel.modules_disabled
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_kernel_panic_on_oops_question:question:1">
          <ocil:question_text>The runtime status of the kernel.panic_on_oops kernel parameter can be queried
by running the following command:
$ sysctl kernel.panic_on_oops
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_kernel_perf_cpu_time_max_percent_question:question:1">
          <ocil:question_text>The runtime status of the kernel.perf_cpu_time_max_percent kernel parameter can be queried
by running the following command:
$ sysctl kernel.perf_cpu_time_max_percent
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_kernel_perf_event_max_sample_rate_question:question:1">
          <ocil:question_text>The runtime status of the kernel.perf_event_max_sample_rate kernel parameter can be queried
by running the following command:
$ sysctl kernel.perf_event_max_sample_rate
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_kernel_perf_event_paranoid_question:question:1">
          <ocil:question_text>The runtime status of the kernel.perf_event_paranoid kernel parameter can be queried
by running the following command:
$ sysctl kernel.perf_event_paranoid
2.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_kernel_pid_max_question:question:1">
          <ocil:question_text>The runtime status of the kernel.pid_max kernel parameter can be queried
by running the following command:
$ sysctl kernel.pid_max
65536.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_kernel_randomize_va_space_question:question:1">
          <ocil:question_text>The runtime status of the kernel.randomize_va_space kernel parameter can be queried
by running the following command:
$ sysctl kernel.randomize_va_space
2.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_kernel_sysrq_question:question:1">
          <ocil:question_text>The runtime status of the kernel.sysrq kernel parameter can be queried
by running the following command:
$ sysctl kernel.sysrq
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_kernel_unprivileged_bpf_disabled_question:question:1">
          <ocil:question_text>The runtime status of the kernel.unprivileged_bpf_disabled kernel parameter can be queried
by running the following command:
$ sysctl kernel.unprivileged_bpf_disabled
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_kernel_yama_ptrace_scope_question:question:1">
          <ocil:question_text>The runtime status of the kernel.yama.ptrace_scope kernel parameter can be queried
by running the following command:
$ sysctl kernel.yama.ptrace_scope
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_core_bpf_jit_harden_question:question:1">
          <ocil:question_text>The runtime status of the net.core.bpf_jit_harden kernel parameter can be queried
by running the following command:
$ sysctl net.core.bpf_jit_harden
2.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_local_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.all.accept_local kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.all.accept_local
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_redirects_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.all.accept_redirects kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.all.accept_redirects
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.all.accept_source_route kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.all.accept_source_route
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_filter_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.all.arp_filter kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.all.arp_filter
.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_all_arp_ignore_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.all.arp_ignore kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.all.arp_ignore
.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_all_drop_gratuitous_arp_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.all.drop_gratuitous_arp kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.all.drop_gratuitous_arp
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_all_forwarding_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.all.forwarding kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.all.forwarding
0.
The ability to forward packets is only appropriate for routers.
      Is it the case that IP forwarding value is "1" and the system is not router?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_all_log_martians_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.all.log_martians kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.all.log_martians
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_all_route_localnet_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.all.route_localnet kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.all.route_localnet
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_all_rp_filter_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.all.rp_filter parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.all.rp_filter
The output of the command should indicate either:
net.ipv4.conf.all.rp_filter = 1
or:
net.ipv4.conf.all.rp_filter = 2

The output of the command should not indicate:
net.ipv4.conf.all.rp_filter = 0

The preferable way how to assure the runtime compliance is to have
correct persistent configuration, and rebooting the system.

The persistent sysctl parameter configuration is performed by specifying the appropriate
assignment in any file located in the /etc/sysctl.d directory.
Verify that there is not any existing incorrect configuration by executing the following command:
$ grep -r '^\s*net.ipv4.conf.all.rp_filter\s*=' /etc/sysctl.conf /etc/sysctl.d
The command should not find any assignments other than:
net.ipv4.conf.all.rp_filter = 1
or:
net.ipv4.conf.all.rp_filter = 2


Conflicting assignments are not allowed.
      Is it the case that the net.ipv4.conf.all.rp_filter is not set to 1 or 2 or is configured to be 0?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_all_secure_redirects_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.all.secure_redirects kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.all.secure_redirects
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_all_send_redirects_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.all.send_redirects kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.all.send_redirects
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_all_shared_media_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.all.shared_media kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.all.shared_media
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_redirects_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.default.accept_redirects kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.default.accept_redirects
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.default.accept_source_route kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.default.accept_source_route
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_default_forwarding_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.default.forwarding kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.default.forwarding
0.
The ability to forward packets is only appropriate for routers.
      Is it the case that IP forwarding value is "1" and the system is not router?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_default_log_martians_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.default.log_martians kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.default.log_martians
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.default.rp_filter kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.default.rp_filter
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.default.secure_redirects kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.default.secure_redirects
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_default_send_redirects_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.default.send_redirects kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.default.send_redirects
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_conf_default_shared_media_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.conf.default.shared_media kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.conf.default.shared_media
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_icmp_echo_ignore_broadcasts_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.icmp_echo_ignore_broadcasts kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.icmp_echo_ignore_broadcasts
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_icmp_ignore_bogus_error_responses_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.icmp_ignore_bogus_error_responses kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.icmp_ignore_bogus_error_responses
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_ip_forward_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.ip_forward kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.ip_forward
0.
The ability to forward packets is only appropriate for routers.
      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_ip_local_port_range_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.ip_local_port_range kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.ip_local_port_range
32768 65535.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_tcp_invalid_ratelimit_question:question:1">
          <ocil:question_text>To verify that the operating system protects against or limits the effects of DoS
attacks by ensuring implementation of rate-limiting measures
on impacted network interfaces, run the following command:
# grep 'net.ipv4.tcp_invalid_ratelimit' /etc/sysctl.conf /etc/sysctl.d/*
The command should output the following line:
/etc/sysctl.conf:net.ipv4.tcp_invalid_ratelimit = 
The file where the line has been found can differ, but it must be either /etc/sysctl.conf
or a file located under the /etc/sysctl.d/ directory.
      Is it the case that rate limiting of duplicate TCP acknowledgments is not configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_tcp_rfc1337_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.tcp_rfc1337 kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.tcp_rfc1337
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv4_tcp_syncookies_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv4.tcp_syncookies kernel parameter can be queried
by running the following command:
$ sysctl net.ipv4.tcp_syncookies
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.all.accept_ra kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.all.accept_ra
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_defrtr_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.all.accept_ra_defrtr kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.all.accept_ra_defrtr
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_pinfo_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.all.accept_ra_pinfo kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.all.accept_ra_pinfo
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_ra_rtr_pref_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.all.accept_ra_rtr_pref kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.all.accept_ra_rtr_pref
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_redirects_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.all.accept_redirects kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.all.accept_redirects
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_all_accept_source_route_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.all.accept_source_route kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.all.accept_source_route
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_all_autoconf_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.all.autoconf kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.all.autoconf
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_all_disable_ipv6_question:question:1">
          <ocil:question_text>If the system uses IPv6, this is not applicable.

If the system is configured to prevent the usage of the ipv6 on
network interfaces, it will contain a line of the form:
net.ipv6.conf.all.disable_ipv6 = 1
Such lines may be inside any file in the /etc/sysctl.d directory.
This permits insertion of the IPv6 kernel module (which other parts of the
system expect to be present), but otherwise keeps all network interfaces
from using IPv6. Run the following command to search for such lines in all
files in /etc/sysctl.d:
$ grep -r ipv6 /etc/sysctl.d
      Is it the case that the ipv6 support is disabled on all network interfaces?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_all_forwarding_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.all.forwarding kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.all.forwarding
0.
The ability to forward packets is only appropriate for routers.
      Is it the case that IP forwarding value is "1" and the system is not router?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_all_max_addresses_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.all.max_addresses kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.all.max_addresses
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_all_router_solicitations_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.all.router_solicitations kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.all.router_solicitations
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.default.accept_ra kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.default.accept_ra
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_defrtr_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.default.accept_ra_defrtr kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.default.accept_ra_defrtr
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_pinfo_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.default.accept_ra_pinfo kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.default.accept_ra_pinfo
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_ra_rtr_pref_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.default.accept_ra_rtr_pref kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.default.accept_ra_rtr_pref
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_redirects_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.default.accept_redirects kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.default.accept_redirects
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_default_accept_source_route_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.default.accept_source_route kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.default.accept_source_route
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_default_autoconf_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.default.autoconf kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.default.autoconf
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_default_disable_ipv6_question:question:1">
          <ocil:question_text>If the system uses IPv6, this is not applicable.

If the system is configured to prevent the usage of the ipv6 on
network interfaces, it will contain a line of the form:
net.ipv6.conf.default.disable_ipv6 = 1
Such lines may be inside any file in the /etc/sysctl.d directory.
This permits insertion of the IPv6 kernel module (which other parts of the
system expect to be present), but otherwise keeps network interfaces
from using IPv6. Run the following command to search for such lines in all
files in /etc/sysctl.d:
$ grep -r ipv6 /etc/sysctl.d
      Is it the case that the ipv6 support is disabled by default on network interfaces?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_default_forwarding_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.default.forwarding kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.default.forwarding
0.
The ability to forward packets is only appropriate for routers.
      Is it the case that IPv6 Forwarding is not disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_default_max_addresses_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.default.max_addresses kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.default.max_addresses
1.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_net_ipv6_conf_default_router_solicitations_question:question:1">
          <ocil:question_text>The runtime status of the net.ipv6.conf.default.router_solicitations kernel parameter can be queried
by running the following command:
$ sysctl net.ipv6.conf.default.router_solicitations
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_user_max_user_namespaces_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 disables the use of user namespaces with the following commands:

Note: User namespaces are used primarily for Linux containers. If containers are in use, this requirement is not applicable.

The runtime status of the user.max_user_namespaces kernel parameter can be queried
by running the following command:
$ sysctl user.max_user_namespaces
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_user_max_user_namespaces_no_remediation_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 disables the use of user namespaces with the following commands:

Note: User namespaces are used primarily for Linux containers. If containers are in use, this requirement is not applicable.

The runtime status of the user.max_user_namespaces kernel parameter can be queried
by running the following command:
$ sysctl user.max_user_namespaces
0.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-sysctl_vm_mmap_min_addr_question:question:1">
          <ocil:question_text>The runtime status of the vm.mmap_min_addr kernel parameter can be queried
by running the following command:
$ sysctl vm.mmap_min_addr
65536.

      Is it the case that the correct value is not returned?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-systemd_tmp_mount_enabled_question:question:1">
          <ocil:question_text>
Run the following command to determine the current status of the
tmp mount:
$ sudo systemctl is-active tmp.mount
If the mount unit is running, it should return the following: active
      Is it the case that the tmp.mount unit is masked or disabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-tftp_uses_secure_mode_systemd_question:question:1">
          <ocil:question_text>Use sudo systemctl show tftp to verify that tftp service is using secure mode.
$ sudo systemctl show tftp | grep ExecStart=
ExecStart={ path=/usr/sbin/in.tftpd ; argv[]=/usr/sbin/in.tftpd -s /var/lib/tftpboot ; ignore_errors=no ; start_time=[n/a] ; stop_time=[n/a] ; pid=0 ; code=(null) ; status=0/0 }e


and ensure the ExecStart line on that file includes the -s option with a subdirectory:
ExecStart=/usr/sbin/in.tftpd -s 
      Is it the case that the ExecStart property of tftp does not contain correctly set -s flag?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-tftpd_uses_secure_mode_question:question:1">
          <ocil:question_text>Verify the TFTP daemon is configured to operate in secure mode.

Check if a TFTP server is installed with the following command:

$ rpm -qa | grep tftp


If a TFTP server is not installed, this is Not Applicable.


If a TFTP server is installed, verify TFTP is configured by with
the -s option by running the following command:

grep "server_args" /etc/xinetd.d/tftp
server_args = -s 
      Is it the case that '"server_args" line does not have a "-s" option, and a subdirectory is not assigned'?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-timer_dnf-automatic_enabled_question:question:1">
          <ocil:question_text> Run the following command to determine the current status of the dnf-automatic timer: $ sudo systemctl is-active dnf-automatic.timer If the timer is running, it should return the following: active
      Is it the case that the dnf-automatic.timer is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-timer_logrotate_enabled_question:question:1">
          <ocil:question_text> Run the following command to determine the current status of the logrotate timer: $ sudo systemctl is-active logrotate.timer If the timer is running, it should return the following: active
      Is it the case that logrotate timer is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-uefi_no_removeable_media_question:question:1">
          <ocil:question_text>To verify the system is not configured to use a boot loader on removable media,
check that the grub configuration file has the set root command in each menu
entry with the following commands:
$ sudo grep -cw menuentry /boot/efi/EFI/almalinux/grub.cfg
Note that the -c option for the grep command will print
only the count of menuentry occurrences. This number should match
the number of occurrences reported by the following command:
$ sudo grep "set root='hd0" /boot/efi/EFI/almalinux/grub.cfg
The output should return something similar to:
set root='hd0,msdos1'
usb0, cd, fd0, etc. are some examples of removable
media which should not exist in the lines:
set root='hd0,msdos1'
      Is it the case that it is not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-umask_for_daemons_question:question:1">
          <ocil:question_text>To check the value of the umask, run the following command:
$ grep umask /etc/init.d/functions
The output should show .
      Is it the case that it does not?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-usbguard_allow_hid_question:question:1">
          <ocil:question_text>To verify that USB Human Interface Devices will be authorized by the USBGuard daemon,
run the following command:
$ sudo grep allow /etc/usbguard/rules.conf
The output lines should include
allow with-interface match-all { 03:*:* }
      Is it the case that USB devices of class 3 are not authorized?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-usbguard_allow_hid_and_hub_question:question:1">
          <ocil:question_text>To verify that USB Human Interface Devices and hubs will be authorized by the USBGuard daemon,
run the following command:
$ sudo grep allow /etc/usbguard/rules.conf
The output lines should include
allow with-interface match-all { 03:*:* 09:00:* }
      Is it the case that USB devices of class 3 and 9:00 are not authorized?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-usbguard_allow_hub_question:question:1">
          <ocil:question_text>To verify that USB hubs will be authorized by the USBGuard daemon,
run the following command:
$ sudo grep allow /etc/usbguard/rules.conf
One of the output lines should be
allow with-interface match-all { 09:00:* }
      Is it the case that USB devices of class 9 are not authorized?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-usbguard_generate_policy_question:question:1">
          <ocil:question_text>Verify the USBGuard has a policy configured with the following command:

$ usbguard list-rules

allow id 1d6b:0001 serial

If the command does not return results or an error is returned, ask the SA to indicate how unauthorized peripherals are being blocked.
      Is it the case that there is no evidence that unauthorized peripherals are being blocked before establishing a connection?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-use_kerberos_security_all_exports_question:question:1">
          <ocil:question_text>To verify the sec option is configured for all NFS mounts, run the following command:
$ grep "sec=" /etc/exports
All configured NFS exports should show the sec=krb5:krb5i:krb5p setting in parentheses.
This is not applicable if NFS is not implemented.
      Is it the case that the setting is not configured, has the 'sys' option added, or does not have all Kerberos options added?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-use_pam_wheel_for_su_question:question:1">
          <ocil:question_text>Run the following command to check if the line is present:
grep pam_wheel /etc/pam.d/su
The output should contain the following line:
auth required pam_wheel.so use_uid
      Is it the case that the line is not in the file or it is commented?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-use_pam_wheel_group_for_su_question:question:1">
          <ocil:question_text>Run the following command to check if the line is present:
grep pam_wheel /etc/pam.d/su
The output should contain the following line:
auth required pam_wheel.so use_uid group=
      Is it the case that the line is not in the file or it is commented?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-wireless_disable_in_bios_question:question:1">
          <ocil:question_text>Verify that built-in wireless devices (WiFi and Bluetooth) are disabled in the system
boot firmware (BIOS/UEFI). The process to configure this setting varies by hardware
manufacturer and model. Some systems may not have wireless devices or may not provide
BIOS-level controls for wireless devices.
Consult your hardware manual or vendor documentation for specific instructions on how to
access the firmware setup during boot and disable wireless device support.
      Is it the case that wireless devices (WiFi or Bluetooth) are enabled in BIOS?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-wireless_disable_interfaces_question:question:1">
          <ocil:question_text>Verify that there are no wireless interfaces configured on the system
with the following command:

Note: This requirement is Not Applicable for systems that do not have physical wireless network radios.

$ nmcli device status
DEVICE          TYPE      STATE         CONNECTION
virbr0          bridge    connected     virbr0
wlp7s0          wifi      connected     wifiSSID
enp6s0          ethernet  disconnected  --
p2p-dev-wlp7s0  wifi-p2p  disconnected  --
lo              loopback  unmanaged     --
virbr0-nic      tun       unmanaged     --
      Is it the case that a wireless interface is configured and has not been documented and approved by the Information System Security Officer (ISSO)?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-xwayland_disabled_question:question:1">
          <ocil:question_text>To verify that XWayland is disabled, run the following command:
sed -n '/\[daemon\]/,/\[/p' /etc/gdm/custom.conf | grep -Psi '^\h*waylandenable\b'
The output should return the following:

[daemon]
WaylandEnable=false

      Is it the case that The WaylandEnable parameter is not set to false in the [daemon] section of the /etc/gdm/custom.conf file.?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-xwindows_remove_packages_question:question:1">
          <ocil:question_text>To ensure the X Windows package group is removed, run the following command:
$ rpm -qi xorg-x11-server-Xorg
$ rpm -qi xorg-x11-server-common
$ rpm -qi xorg-x11-server-utils
$ rpm -qi xorg-x11-server-Xwayland
For each package mentioned above you should receive following line:
package &lt;package&gt; is not installed
      Is it the case that xorg related packages are not removed and run level is not correctly configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-xwindows_runlevel_target_question:question:1">
          <ocil:question_text>Verify that AlmaLinux OS 8 is configured to boot to the command line:
$ systemctl get-default
multi-user.target
      Is it the case that the system default target is not set to "multi-user.target" and the Information System Security Officer (ISSO) lacks a documented requirement for a graphical user interface?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-zipl_audit_argument_question:question:1">
          <ocil:question_text>To check that audit is enabled at boot time, check all boot entries with following command:
sudo grep -L "^options\s+.*\baudit=1\b" /boot/loader/entries/*.conf
No line should be returned, each line returned is a boot entry that doesn't enable audit.
      Is it the case that auditing is not enabled at boot time?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-zipl_audit_backlog_limit_argument_question:question:1">
          <ocil:question_text>To check that all boot entries extend the backlog limit;
Check that all boot entries extend the log events queue:
sudo grep -L "^options\s+.*\baudit_backlog_limit=8192\b" /boot/loader/entries/*.conf
No line should be returned, each line returned is a boot entry that does not extend the log events queue.
      Is it the case that audit backlog limit is not configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-zipl_bls_entries_only_question:question:1">
          <ocil:question_text>Check that no boot image file is specified in /etc/zipl.conf:
grep -R "^image\s*=" /etc/zipl.conf
No line should be returned, if a line is returned non BLS compliant boot entries are configured for zIPL.
      Is it the case that a non BLS boot entry is configured?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-zipl_bootmap_is_up_to_date_question:question:1">
          <ocil:question_text>Make sure that /boot/bootmap is newer than /boot/loader/entries/*.conf
and /etc/zipl.conf:
find /boot/loader/entries/*.conf /etc/zipl.conf -newer /boot/bootmap
No line should be returned, if a line is returned /boot/bootmap is outdated and needs to be regenerated.
      Is it the case that the bootmap is outdated?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-zipl_enable_selinux_question:question:1">
          <ocil:question_text>To check that SELinux is not disabled at boot time;
Check that no boot entry disables selinux:
sudo grep -L "^options\s+.*\bselinux=0\b" /boot/loader/entries/*.conf
No line should be returned, each line returned is a boot entry that disables SELinux.
      Is it the case that SELinux is disabled at boot time?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-zipl_page_poison_argument_question:question:1">
          <ocil:question_text>To check that page poisoning is enabled at boot time, check all boot entries with following command:
sudo grep -L "^options\s+.*\bpage_poison=1\b" /boot/loader/entries/*.conf
No line should be returned, each line returned is a boot entry that doesn't enable page poisoning.
      Is it the case that page allocator poisoning is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-zipl_slub_debug_argument_question:question:1">
          <ocil:question_text>To check that SLUB/SLAB poisoning is enabled, check all boot entries with following command;
sudo grep -L "^options\s+.*\bslub_debug=P\b" /boot/loader/entries/*.conf
No line should be returned, each line returned is a boot entry that does not enable poisoning.
      Is it the case that SLUB/SLAB poisoning is not enabled?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-zipl_systemd_debug-shell_argument_absent_question:question:1">
          <ocil:question_text>Ensure that debug-shell service is not enabled with the following command:
sudo grep -L "^options\s+.*\bsystemd.debug-shell=1\b" /boot/loader/entries/*.conf
No line should be returned, each line returned is a boot entry that enables the debug-shell.
      Is it the case that the command returns a line?
      </ocil:question_text>
        </ocil:boolean_question>
        <ocil:boolean_question id="ocil:ssg-zipl_vsyscall_argument_question:question:1">
          <ocil:question_text>To check that virtual syscalls are disabled at boot time, check all boot entries with following command:
sudo grep -L "^options\s+.*\bvsyscall=none\b" /boot/loader/entries/*.conf
No line should be returned, each line returned is a boot entry that doesn't disable virtual syscalls.
      Is it the case that vsyscalls are enabled?
      </ocil:question_text>
        </ocil:boolean_question>
      </ocil:questions>
    </ocil:ocil>
  </ds:component>
  <ds:component id="scap_org.open-scap_comp_ssg-almalinux8-cpe-oval.xml" timestamp="2026-06-15T09:09:30">
    <oval-def:oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
      <oval-def:generator>
        <oval:product_name>build_cpe.py from SCAP Security Guide</oval:product_name>
        <oval:product_version>ssg: [0, 1, 81], python: 3.6.8</oval:product_version>
        <oval:schema_version>5.11</oval:schema_version>
        <oval:timestamp>2026-06-15T09:09:29</oval:timestamp>
      </oval-def:generator>
      <oval-def:definitions>
        <oval-def:definition class="inventory" id="oval:ssg-bootc:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title/>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>Bootable container or bootc system</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="kernel is installed" test_ref="oval:ssg-bootc_platform_test_kernel_installed:tst:1"/>
            <oval-def:criterion comment="rpm-ostree is installed" test_ref="oval:ssg-bootc_platform_test_rpm_ostree_installed:tst:1"/>
            <oval-def:criterion comment="bootc is installed" test_ref="oval:ssg-bootc_platform_test_bootc_installed:tst:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="/run/ostree-booted exists, suggesting that we are in a running bootc environment" test_ref="oval:ssg-bootc_platform_test_run_ostree_booted_exists:tst:1"/>
              <oval-def:criterion comment="/ostree symlink exists, suggesting that we are in a bootc environment being built and hardened" test_ref="oval:ssg-bootc_platform_test_ostree_symlink_exists:tst:1"/>
            </oval-def:criteria>
            <oval-def:criterion comment="openshift-kubelet is not installed" test_ref="oval:ssg-bootc_platform_test_openshift_kubelet_removed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_env_has_grub2_package:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package grub2 is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/a:grub2" source="CPE"/>
            <oval-def:description>Checks if package grub2-common is installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Package grub2-common is installed" test_ref="oval:ssg-test_env_has_grub2_installed:tst:1"/>
            <oval-def:criteria operator="OR">
              <oval-def:criterion comment="Test for ppcle64 architecture" negate="true" test_ref="oval:ssg-test_system_info_architecture_ppcle_64:tst:1"/>
              <oval-def:criterion comment="Test if OPAL is not used" negate="true" test_ref="oval:ssg-test_system_using_opal:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_env_has_no_ovirt:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Check if the system doesn't act as an oVirt host or manager</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>Check if the system has neither ovirt-host nor ovirt-engine installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Package ovirt-host is not installed" definition_ref="oval:ssg-installed_env_has_ovirt:def:1" negate="true"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_env_has_ovirt:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Check if the system acts as an oVirt host or manager</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/a:ovirt-host" source="CPE"/>
            <oval-def:description>Check if the system has ovirt-host or ovirt-engine installed</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="Package ovirt-host is installed" test_ref="oval:ssg-test_env_has_ovirt-host_installed:tst:1"/>
            <oval-def:criterion comment="Package ovirt-engine is installed" test_ref="oval:ssg-test_env_has_ovirt-engine_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_env_has_wifi_interface:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>WiFi interface is present</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/a:wifi-iface" source="CPE"/>
            <oval-def:description>Checks if any wifi interface is present.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="WiFi interface is present" test_ref="oval:ssg-test_proc_net_wireless_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_env_is_a_container:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Check if the scan target is a container</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/a:container" source="CPE"/>
            <oval-def:description>Check for presence of files characterizing container filesystems.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="Check if /.dockerenv exists" test_ref="oval:ssg-test_installed_env_is_a_docker_container:tst:1"/>
            <oval-def:criterion comment="Check if /run/.containerenv exists" test_ref="oval:ssg-test_installed_env_is_a_podman_container:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_env_is_a_machine:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Check if the scan target is a machine</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/a:machine" source="CPE"/>
            <oval-def:description>Check for absence of files characterizing container filesystems.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="If environment is not a container, it is machine" definition_ref="oval:ssg-installed_env_is_a_container:def:1" negate="true"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-krb5_server_older_than_1_17_18:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Kerberos server is older than 1.17-18</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/a:krb5_server_older_than_1_17-18" source="CPE"/>
            <oval-def:description>Check if version of Kerberos server is lesser than 1.17-18
            </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Kerberos server version is lesser than 1.17-18" operator="OR">
            <oval-def:criterion comment="Check if version of Kerberos server is lesser than 1.17-18" test_ref="oval:ssg-test_krb5_server_version_1_17_18:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-krb5_workstation_older_than_1_17_18:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Kerberos workstation is older than 1.17-18</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/a:krb5_workstation_older_than_1_17-18" source="CPE"/>
            <oval-def:description>Check if version of Kerberos workstation is lesser than 1.17-18
            </oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="Kerberos workstation version is lesser than 1.17-18" operator="OR">
            <oval-def:criterion comment="Check if version of Kerberos workstation is lesser than 1.17-18" test_ref="oval:ssg-test_krb5_workstation_version_1_17_18:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-nfs_mount_defined:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Remote NFS file system mount is defined</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/a:nfs_mount_defined" source="CPE"/>
            <oval-def:description>At least one remote NFS file system mount is defined in  /etc/fstab</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="remote nfs filesystem exist" test_ref="oval:ssg-test_nfs_mount_exists:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Test that the architecture is aarch64</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>Check that architecture of kernel in /proc/sys/kernel is aarch64</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Architecture is aarch64" test_ref="oval:ssg-test_proc_sys_kernel_osrelease_arch_aarch64:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Test for different architecture than s390x</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>Check that architecture of kernel in /proc/sys/kernel/osrelease is not s390x</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Architecture is not s390x" definition_ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1" negate="true"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Test that the architecture is s390x</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>Check that architecture of kernel in /proc/sys/kernel is s390x</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Architecture is s390x" test_ref="oval:ssg-test_proc_sys_kernel_osrelease_arch_s390x:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Test that the architecture is x86_64</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>Check that architecture of kernel in /proc/sys/kernel is x86_64</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Architecture is x86_64" test_ref="oval:ssg-test_proc_sys_kernel_osrelease_arch_x86_64:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-runtime_kernel_fips_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Running kernel has fips mode enabled</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/a:runtime-kernel-fips-enabled" source="CPE"/>
            <oval-def:description>Check if sysctl crypto.fips_enabled = 1</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="check if sysctl crypto.fips_enabled = 1" test_ref="oval:ssg-test_runtime_kernel_fips_enabled:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-selinux_is_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>SELinux status check</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/a:selinux" source="CPE"/>
            <oval-def:description>Check if System has SELinux enabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="enforce is disabled" test_ref="oval:ssg-test_etc_selinux_configured:tst:1"/>
            <oval-def:criterion comment="/sys/fs/selinux is present" test_ref="oval:ssg-test_selinux_sys_fs_exist:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-sssd_conf_uses_ldap:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>SSSD is configured to use LDAP</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/a:sssd-ldap" source="CPE"/>
            <oval-def:description>Identification provider is not set to ad within /etc/sssd/sssd.conf</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Identification provider is set to ldap within /etc/sssd/sssd.conf" test_ref="oval:ssg-test_id_provider_is_set_to_ldap:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-system_boot_mode_is_non_uefi:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Non-UEFI system boot mode check</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/a:non-uefi" source="CPE"/>
            <oval-def:description>Check if System boot mode is non-UEFI.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:extend_definition comment="Pass if System boot mode is non-UEFI" definition_ref="oval:ssg-system_boot_mode_is_uefi:def:1" negate="true"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-system_boot_mode_is_uefi:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>UEFI system boot mode check</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/a:uefi" source="CPE"/>
            <oval-def:description>Check if system boot mode is UEFI.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="check if /sys/firmware/efi folder exists" test_ref="oval:ssg-test_efi_dir_existence:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-system_with_kernel:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title/>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The kernel is installed</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="kernel is installed" test_ref="oval:ssg-inventory_test_kernel_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_almalinux8:def:1" version="3">
          <oval-def:metadata>
            <oval-def:title>AlmaLinux OS 8</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/o:almalinux:almalinux:8" source="CPE"/>
            <oval-def:description>The operating system installed on the system is AlmaLinux OS 8</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="current OS is 8" operator="AND">
            <oval-def:extend_definition comment="Installed OS is part of the Unix family" definition_ref="oval:ssg-installed_OS_is_part_of_Unix_family:def:1"/>
            <oval-def:criterion comment="AlmaLinux OS is installed" test_ref="oval:ssg-test_almalinux:tst:1"/>
            <oval-def:criterion comment="AlmaLinux OS 8 is installed" test_ref="oval:ssg-test_almalinux8:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_part_of_Unix_family:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Installed operating system is part of the Unix family</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The operating system installed on the system is part of the Unix OS family</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Installed operating system is part of the unix family" test_ref="oval:ssg-test_unix_family:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Red Hat Enterprise Linux CoreOS RHEL9 Based</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/o:redhat:rhcos4:9" source="CPE"/>
            <oval-def:description>The operating system installed on the system is
      Red Hat Enterprise Linux CoreOS RHEL9 Based</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria comment="Old format: ID=rhcos with RHEL_VERSION=9.x" operator="AND">
              <oval-def:criterion comment="ID is rhcos" test_ref="oval:ssg-test_rhcos:tst:1"/>
              <oval-def:criterion comment="RHEL_VERSION is 9" test_ref="oval:ssg-test_rhcos4_rhel9_rhel_version:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria comment="New format: ID=rhel with VERSION_ID=9.x" operator="AND">
              <oval-def:criterion comment="ID is rhel" test_ref="oval:ssg-test_rhel_id:tst:1"/>
              <oval-def:criterion comment="CoreOS variant" test_ref="oval:ssg-test_rhel_coreos_variant:tst:1"/>
              <oval-def:criterion comment="VERSION_ID is 9.x" test_ref="oval:ssg-test_rhel_coreos_version9:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_env_is_osbuild:def:1" version="2">
          <oval-def:metadata>
            <oval-def:title>Check if the environment is a OSBuild pipeline</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:reference ref_id="cpe:/a:osbuild" source="CPE"/>
            <oval-def:description>Check the value of environment variable container.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Check the value of container variable" test_ref="oval:ssg-test_installed_env_is_osbuild:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-ipv6_enabled:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>IPv6 is enabled on system</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description/>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criterion comment="check if ipv6.disable argument is correct in GRUB_CMDLINE_LINUX" test_ref="oval:ssg-test_grub2_ipv6_disable_is_correct:tst:1"/>
            <oval-def:criterion comment="check if ipv6.disable parameter is defined in /etc/default/grub" test_ref="oval:ssg-test_grub2_ipv6_disable_is_absent:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_env_mount_boot-efi:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Mountpoint /boot/efi is active (mounted) or configured in /etc/fstab</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description/>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /boot/efi is an active (mounted) mount point" test_ref="oval:ssg-test_mount_active_boot_efi_exists:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /boot/efi is a mount point configured in /etc/fstab" test_ref="oval:ssg-test_mount_configured_fstab_boot_efi_exists:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_env_mount_home:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Mountpoint /home is active (mounted) or configured in /etc/fstab</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description/>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /home is an active (mounted) mount point" test_ref="oval:ssg-test_mount_active_home_exists:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /home is a mount point configured in /etc/fstab" test_ref="oval:ssg-test_mount_configured_fstab_home_exists:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_env_mount_opt:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Mountpoint /opt is active (mounted) or configured in /etc/fstab</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description/>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /opt is an active (mounted) mount point" test_ref="oval:ssg-test_mount_active_opt_exists:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /opt is a mount point configured in /etc/fstab" test_ref="oval:ssg-test_mount_configured_fstab_opt_exists:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_env_mount_srv:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Mountpoint /srv is active (mounted) or configured in /etc/fstab</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description/>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /srv is an active (mounted) mount point" test_ref="oval:ssg-test_mount_active_srv_exists:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /srv is a mount point configured in /etc/fstab" test_ref="oval:ssg-test_mount_configured_fstab_srv_exists:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_env_mount_tmp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Mountpoint /tmp is active (mounted) or configured in /etc/fstab</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description/>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /tmp is an active (mounted) mount point" test_ref="oval:ssg-test_mount_active_tmp_exists:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /tmp is a mount point configured in /etc/fstab" test_ref="oval:ssg-test_mount_configured_fstab_tmp_exists:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_env_mount_var-log-audit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Mountpoint /var/log/audit is active (mounted) or configured in /etc/fstab</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description/>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /var/log/audit is an active (mounted) mount point" test_ref="oval:ssg-test_mount_active_var_log_audit_exists:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /var/log/audit is a mount point configured in /etc/fstab" test_ref="oval:ssg-test_mount_configured_fstab_var_log_audit_exists:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_env_mount_var-log:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Mountpoint /var/log is active (mounted) or configured in /etc/fstab</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description/>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /var/log is an active (mounted) mount point" test_ref="oval:ssg-test_mount_active_var_log_exists:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /var/log is a mount point configured in /etc/fstab" test_ref="oval:ssg-test_mount_configured_fstab_var_log_exists:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_env_mount_var-tmp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Mountpoint /var/tmp is active (mounted) or configured in /etc/fstab</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description/>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /var/tmp is an active (mounted) mount point" test_ref="oval:ssg-test_mount_active_var_tmp_exists:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /var/tmp is a mount point configured in /etc/fstab" test_ref="oval:ssg-test_mount_configured_fstab_var_tmp_exists:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-installed_env_mount_var:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Mountpoint /var is active (mounted) or configured in /etc/fstab</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description/>
          </oval-def:metadata>
          <oval-def:criteria operator="OR">
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /var is an active (mounted) mount point" test_ref="oval:ssg-test_mount_active_var_exists:tst:1"/>
            </oval-def:criteria>
            <oval-def:criteria operator="AND">
              <oval-def:criterion comment="The path /var is a mount point configured in /etc/fstab" test_ref="oval:ssg-test_mount_configured_fstab_var_exists:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Operating System is ol</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The installed operating system is Oracle Linux</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="The operating system installed on the system is Oracle Linux" test_ref="oval:ssg-test_os_id_is_os_linux_ol_gt_or_eq_8_7:tst:1"/>
            <oval-def:criterion comment="The operating system Oracle Linux of version greater than or equal 8.7 is installed" test_ref="oval:ssg-test_os_linux_ol_gt_or_eq_8_7_gt_or_eq_8_7:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-os_linux_ol_gt_or_eq_9_0:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Operating System is ol</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The installed operating system is Oracle Linux</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="The operating system installed on the system is Oracle Linux" test_ref="oval:ssg-test_os_id_is_os_linux_ol_gt_or_eq_9_0:tst:1"/>
            <oval-def:criterion comment="The operating system Oracle Linux of version greater than or equal 9.0 is installed" test_ref="oval:ssg-test_os_linux_ol_gt_or_eq_9_0_gt_or_eq_9_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-os_linux_rhel_gt_or_eq_8_2:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Operating System is rhel</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The installed operating system is Red Hat Enterprise Linux</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="The operating system installed on the system is Red Hat Enterprise Linux" test_ref="oval:ssg-test_os_id_is_os_linux_rhel_gt_or_eq_8_2:tst:1"/>
            <oval-def:criterion comment="The operating system Red Hat Enterprise Linux of version greater than or equal 8.2 is installed" test_ref="oval:ssg-test_os_linux_rhel_gt_or_eq_8_2_gt_or_eq_8_2:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-os_linux_rhel_gt_or_eq_8_4:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Operating System is rhel</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The installed operating system is Red Hat Enterprise Linux</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="The operating system installed on the system is Red Hat Enterprise Linux" test_ref="oval:ssg-test_os_id_is_os_linux_rhel_gt_or_eq_8_4:tst:1"/>
            <oval-def:criterion comment="The operating system Red Hat Enterprise Linux of version greater than or equal 8.4 is installed" test_ref="oval:ssg-test_os_linux_rhel_gt_or_eq_8_4_gt_or_eq_8_4:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Operating System is rhel</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The installed operating system is Red Hat Enterprise Linux</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="The operating system installed on the system is Red Hat Enterprise Linux" test_ref="oval:ssg-test_os_id_is_os_linux_rhel_gt_or_eq_8_7:tst:1"/>
            <oval-def:criterion comment="The operating system Red Hat Enterprise Linux of version greater than or equal 8.7 is installed" test_ref="oval:ssg-test_os_linux_rhel_gt_or_eq_8_7_gt_or_eq_8_7:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-os_linux_rhel_gt_or_eq_9_0:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Operating System is rhel</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The installed operating system is Red Hat Enterprise Linux</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="The operating system installed on the system is Red Hat Enterprise Linux" test_ref="oval:ssg-test_os_id_is_os_linux_rhel_gt_or_eq_9_0:tst:1"/>
            <oval-def:criterion comment="The operating system Red Hat Enterprise Linux of version greater than or equal 9.0 is installed" test_ref="oval:ssg-test_os_linux_rhel_gt_or_eq_9_0_gt_or_eq_9_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-os_linux_rhel_le_or_eq_8_3:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Operating System is rhel</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The installed operating system is Red Hat Enterprise Linux</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="The operating system installed on the system is Red Hat Enterprise Linux" test_ref="oval:ssg-test_os_id_is_os_linux_rhel_le_or_eq_8_3:tst:1"/>
            <oval-def:criterion comment="The operating system Red Hat Enterprise Linux of version less than or equal 8.3 is installed" test_ref="oval:ssg-test_os_linux_rhel_le_or_eq_8_3_le_or_eq_8_3:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-os_linux_rhel_le_or_eq_8_4:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Operating System is rhel</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The installed operating system is Red Hat Enterprise Linux</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="The operating system installed on the system is Red Hat Enterprise Linux" test_ref="oval:ssg-test_os_id_is_os_linux_rhel_le_or_eq_8_4:tst:1"/>
            <oval-def:criterion comment="The operating system Red Hat Enterprise Linux of version less than or equal 8.4 is installed" test_ref="oval:ssg-test_os_linux_rhel_le_or_eq_8_4_le_or_eq_8_4:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-os_linux_rhel_ne_9_0:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Operating System is rhel</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The installed operating system is Red Hat Enterprise Linux</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="The operating system installed on the system is Red Hat Enterprise Linux" test_ref="oval:ssg-test_os_id_is_os_linux_rhel_ne_9_0:tst:1"/>
            <oval-def:criterion comment="The operating system Red Hat Enterprise Linux of version not equal 9.0 is installed" test_ref="oval:ssg-test_os_linux_rhel_ne_9_0_ne_9_0:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-os_linux_sles_gt_or_eq_15:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Operating System is sles</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The installed operating system is SUSE Linux Enterprise Server</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="The operating system installed on the system is SUSE Linux Enterprise Server" test_ref="oval:ssg-test_os_id_is_os_linux_sles_gt_or_eq_15:tst:1"/>
            <oval-def:criterion comment="The operating system SUSE Linux Enterprise Server of version greater than or equal 15 is installed" test_ref="oval:ssg-test_os_linux_sles_gt_or_eq_15_gt_or_eq_15:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_audit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package audit is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package audit should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package audit is installed" test_ref="oval:ssg-inventory_test_package_audit_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_autofs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package autofs is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package autofs should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package autofs is installed" test_ref="oval:ssg-inventory_test_package_autofs_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_avahi:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package avahi is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package avahi should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package avahi is installed" test_ref="oval:ssg-inventory_test_package_avahi_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_bash:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package bash is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package bash should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package bash is installed" test_ref="oval:ssg-inventory_test_package_bash_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_bind:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package bind is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package bind should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package bind is installed" test_ref="oval:ssg-inventory_test_package_bind_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_chrony:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package chrony is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package chrony should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package chrony is installed" test_ref="oval:ssg-inventory_test_package_chrony_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_dnf:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package dnf is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package dnf should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package dnf is installed" test_ref="oval:ssg-inventory_test_package_dnf_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_firewalld:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package firewalld is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package firewalld should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package firewalld is installed" test_ref="oval:ssg-inventory_test_package_firewalld_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_gdm:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package gdm is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package gdm should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package gdm is installed" test_ref="oval:ssg-inventory_test_package_gdm_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_iptables:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package iptables is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package iptables should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package iptables is installed" test_ref="oval:ssg-inventory_test_package_iptables_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_krb5-libs:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package krb5-libs is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package krb5-libs should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package krb5-libs is installed" test_ref="oval:ssg-inventory_test_package_krb5-libs_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_libpwquality:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package libpwquality is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package libpwquality should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package libpwquality is installed" test_ref="oval:ssg-inventory_test_package_libpwquality_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_libreswan:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package libreswan is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package libreswan should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package libreswan is installed" test_ref="oval:ssg-inventory_test_package_libreswan_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_libuser:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package libuser is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package libuser should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package libuser is installed" test_ref="oval:ssg-inventory_test_package_libuser_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_logrotate:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package logrotate is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package logrotate should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package logrotate is installed" test_ref="oval:ssg-inventory_test_package_logrotate_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_net-snmp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package net-snmp is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package net-snmp should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package net-snmp is installed" test_ref="oval:ssg-inventory_test_package_net-snmp_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_nftables:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package nftables is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package nftables should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package nftables is installed" test_ref="oval:ssg-inventory_test_package_nftables_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_nss-pam-ldapd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package nss-pam-ldapd is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package nss-pam-ldapd should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package nss-pam-ldapd is installed" test_ref="oval:ssg-inventory_test_package_nss-pam-ldapd_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_ntp:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package ntp is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package ntp should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package ntp is installed" test_ref="oval:ssg-inventory_test_package_ntp_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_openssh-clients:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package openssh-clients is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package openssh-clients should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package openssh-clients is installed" test_ref="oval:ssg-inventory_test_package_openssh-clients_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_openssh-server_le_7_0:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package openssh-server is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package openssh-server version less than 7.0 should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package openssh-server of version less than 7.0 is installed" test_ref="oval:ssg-inventory_test_package_openssh-server_le_7_0_le_7_0_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_openssh-server_le_7_5:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package openssh-server is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package openssh-server version less than 7.5 should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package openssh-server of version less than 7.5 is installed" test_ref="oval:ssg-inventory_test_package_openssh-server_le_7_5_le_7_5_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_openssh:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package openssh is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package openssh should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package openssh is installed" test_ref="oval:ssg-inventory_test_package_openssh_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_openssl:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package openssl is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package openssl should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package openssl is installed" test_ref="oval:ssg-inventory_test_package_openssl_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_pam:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package pam is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package pam should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package pam is installed" test_ref="oval:ssg-inventory_test_package_pam_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_polkit:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package polkit is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package polkit should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package polkit is installed" test_ref="oval:ssg-inventory_test_package_polkit_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_postfix:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package postfix is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package postfix should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package postfix is installed" test_ref="oval:ssg-inventory_test_package_postfix_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_rootfiles:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package rootfiles is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package rootfiles should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package rootfiles is installed" test_ref="oval:ssg-inventory_test_package_rootfiles_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_rsh-server:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package rsh-server is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package rsh-server should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package rsh-server is installed" test_ref="oval:ssg-inventory_test_package_rsh-server_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_rsyslog:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package rsyslog is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package rsyslog should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package rsyslog is installed" test_ref="oval:ssg-inventory_test_package_rsyslog_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_shadow-utils:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package shadow-utils is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package shadow-utils should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package shadow-utils is installed" test_ref="oval:ssg-inventory_test_package_shadow-utils_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_snmpd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package net-snmp is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package net-snmp should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package net-snmp is installed" test_ref="oval:ssg-inventory_test_package_snmpd_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_squid:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package squid is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package squid should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package squid is installed" test_ref="oval:ssg-inventory_test_package_squid_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_sssd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package sssd-common is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package sssd-common should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package sssd-common is installed" test_ref="oval:ssg-inventory_test_package_sssd_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_sudo:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package sudo is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package sudo should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package sudo is installed" test_ref="oval:ssg-inventory_test_package_sudo_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_systemd-journal-remote:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package systemd-journal-remote is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package systemd-journal-remote should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package systemd-journal-remote is installed" test_ref="oval:ssg-inventory_test_package_systemd-journal-remote_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_systemd:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package systemd is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package systemd should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package systemd is installed" test_ref="oval:ssg-inventory_test_package_systemd_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_tcsh:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package tcsh is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package tcsh should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package tcsh is installed" test_ref="oval:ssg-inventory_test_package_tcsh_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_telnet-server:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package telnet-server is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package telnet-server should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package telnet-server is installed" test_ref="oval:ssg-inventory_test_package_telnet-server_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_tftp-server:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package tftp-server is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package tftp-server should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package tftp-server is installed" test_ref="oval:ssg-inventory_test_package_tftp-server_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_tmux:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package tmux is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package tmux should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package tmux is installed" test_ref="oval:ssg-inventory_test_package_tmux_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_ufw:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package ufw is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package ufw should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package ufw is installed" test_ref="oval:ssg-inventory_test_package_ufw_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_usbguard:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package usbguard is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package usbguard should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package usbguard is installed" test_ref="oval:ssg-inventory_test_package_usbguard_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-package_yum:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>Package yum is installed</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The RPM package yum should be installed.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria operator="AND">
            <oval-def:criterion comment="Platform package yum is installed" test_ref="oval:ssg-inventory_test_package_yum_installed:tst:1"/>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-service_disabled_firewalld:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>The firewalld is disabled on the system</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The firewalld service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package firewalld removed or service firewalld is not configured to start" operator="OR">
            <oval-def:criterion comment="firewalld removed" test_ref="oval:ssg-service_disabled_firewalldtest_service_firewalld_package_firewalld_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service firewalld is not configured to start" operator="AND">
                <oval-def:criterion comment="firewalld is not running" test_ref="oval:ssg-test_service_not_running_service_disabled_firewalld_firewalld:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service firewalld is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_disabled_firewalld_firewalld:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="firewalld is not found" test_ref="oval:ssg-test_service_not_found_service_disabled_firewalld_firewalld:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-service_disabled_iptables:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>The iptables is disabled on the system</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The iptables service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package iptables removed or service iptables is not configured to start" operator="OR">
            <oval-def:criterion comment="iptables removed" test_ref="oval:ssg-service_disabled_iptablestest_service_iptables_package_iptables_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service iptables is not configured to start" operator="AND">
                <oval-def:criterion comment="iptables is not running" test_ref="oval:ssg-test_service_not_running_service_disabled_iptables_iptables:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service iptables is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_disabled_iptables_iptables:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="iptables is not found" test_ref="oval:ssg-test_service_not_found_service_disabled_iptables_iptables:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-service_disabled_nftables:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>The nftables is disabled on the system</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The nftables service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package nftables removed or service nftables is not configured to start" operator="OR">
            <oval-def:criterion comment="nftables removed" test_ref="oval:ssg-service_disabled_nftablestest_service_nftables_package_nftables_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service nftables is not configured to start" operator="AND">
                <oval-def:criterion comment="nftables is not running" test_ref="oval:ssg-test_service_not_running_service_disabled_nftables_nftables:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service nftables is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_disabled_nftables_nftables:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="nftables is not found" test_ref="oval:ssg-test_service_not_found_service_disabled_nftables_nftables:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
        <oval-def:definition class="inventory" id="oval:ssg-service_disabled_ufw:def:1" version="1">
          <oval-def:metadata>
            <oval-def:title>The ufw is disabled on the system</oval-def:title>
            <oval-def:affected family="unix">
              <oval-def:platform>AlmaLinux OS 8</oval-def:platform>
            </oval-def:affected>
            <oval-def:description>The ufw service should be disabled.</oval-def:description>
          </oval-def:metadata>
          <oval-def:criteria comment="package ufw removed or service ufw is not configured to start" operator="OR">
            <oval-def:criterion comment="ufw removed" test_ref="oval:ssg-service_disabled_ufwtest_service_ufw_package_ufw_removed:tst:1"/>
            <oval-def:criteria comment="service is not present or not configured" operator="OR">
              <oval-def:criteria comment="service ufw is not configured to start" operator="AND">
                <oval-def:criterion comment="ufw is not running" test_ref="oval:ssg-test_service_not_running_service_disabled_ufw_ufw:tst:1"/>
                <oval-def:criterion comment="Property LoadState of service ufw is masked" test_ref="oval:ssg-test_service_loadstate_is_masked_service_disabled_ufw_ufw:tst:1"/>
              </oval-def:criteria>
              <oval-def:criterion comment="ufw is not found" test_ref="oval:ssg-test_service_not_found_service_disabled_ufw_ufw:tst:1"/>
            </oval-def:criteria>
          </oval-def:criteria>
        </oval-def:definition>
      </oval-def:definitions>
      <oval-def:tests>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package kernel is installed" id="oval:ssg-bootc_platform_test_kernel_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_bootc_platform_test_kernel_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package rpm-ostree is installed" id="oval:ssg-bootc_platform_test_rpm_ostree_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_bootc_platform_test_rpm_ostree_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package bootc is installed" id="oval:ssg-bootc_platform_test_bootc_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_bootc_platform_test_bootc_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package openshift-kubelet is removed" id="oval:ssg-bootc_platform_test_openshift_kubelet_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_bootc_platform_test_openshift_kubelet_removed:obj:1"/>
        </linux:rpminfo_test>
        <unix:file_test check="all" check_existence="all_exist" comment="The file /run/ostree-booted exists" id="oval:ssg-bootc_platform_test_run_ostree_booted_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-bootc_platform_obj_run_ostree_booted_exists:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="The file /ostree is a symlink" id="oval:ssg-bootc_platform_test_ostree_symlink_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-bootc_platform_obj_ostree_symlink_exists:obj:1"/>
          <unix:state state_ref="oval:ssg-bootc_platform_ste_ostree_symlink_exists:ste:1"/>
        </unix:file_test>
        <linux:rpminfo_test check="all" comment="system has package grub2-common installed" id="oval:ssg-test_env_has_grub2_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_env_has_grub2_installed:obj:1"/>
        </linux:rpminfo_test>
        <unix:file_test check="all" check_existence="all_exist" comment="Check if /sys/firmware/opal exists" id="oval:ssg-test_system_using_opal:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_system_using_opal:obj:1"/>
        </unix:file_test>
        <linux:rpminfo_test check="all" comment="system has package ovirt-host installed" id="oval:ssg-test_env_has_ovirt-host_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_env_has_ovirt-host_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" comment="system has package ovirt-engine installed" id="oval:ssg-test_env_has_ovirt-engine_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_env_has_ovirt-engine_installed:obj:1"/>
        </linux:rpminfo_test>
        <unix:file_test check="all" check_existence="all_exist" comment="Test if /proc/net/wireless exists" id="oval:ssg-test_proc_net_wireless_exists:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_proc_net_wireless_exists:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="Check if /.dockerenv exists" id="oval:ssg-test_installed_env_is_a_docker_container:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_installed_env_is_a_docker_container:obj:1"/>
        </unix:file_test>
        <unix:file_test check="all" check_existence="all_exist" comment="Check if /run/.containerenv exists" id="oval:ssg-test_installed_env_is_a_podman_container:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_installed_env_is_a_podman_container:obj:1"/>
        </unix:file_test>
        <linux:rpminfo_test check="all" comment="Kerberos server version is lesser than 1.17-18" id="oval:ssg-test_krb5_server_version_1_17_18:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_krb5_server_version_1_17_18:obj:1"/>
          <linux:state state_ref="oval:ssg-state_krb5_server_version_1_17_18:ste:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" comment="Kerberos workstation version is lesser than 1.17-18" id="oval:ssg-test_krb5_workstation_version_1_17_18:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_krb5_workstation_version_1_17_18:obj:1"/>
          <linux:state state_ref="oval:ssg-state_krb5_workstation_version_1_17_18:ste:1"/>
        </linux:rpminfo_test>
        <ind:textfilecontent54_test check="all" comment="at least one nfs is defined" id="oval:ssg-test_nfs_mount_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_nfs_mount_defined:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="proc_sys_kernel is for aarch64 architecture" id="oval:ssg-test_proc_sys_kernel_osrelease_arch_aarch64:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_proc_sys_kernel_osrelease_arch_aarch64:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="proc_sys_kernel is for s390x architecture" id="oval:ssg-test_proc_sys_kernel_osrelease_arch_s390x:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_proc_sys_kernel_osrelease_arch_s390x:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="proc_sys_kernel is for x86_64 architecture" id="oval:ssg-test_proc_sys_kernel_osrelease_arch_x86_64:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_proc_sys_kernel_osrelease_arch_x86_64:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:sysctl_test check="all" check_existence="all_exist" comment="kernel runtime parameter crypto.fips_enabled set to 1" id="oval:ssg-test_runtime_kernel_fips_enabled:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_runtime_kernel_fips_enabled:obj:1"/>
          <unix:state state_ref="oval:ssg-state_runtime_kernel_fips_enabled:ste:1"/>
        </unix:sysctl_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="/selinux/enforce is 1" id="oval:ssg-test_etc_selinux_configured:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_etc_selinux_configured:obj:1"/>
          <ind:state state_ref="oval:ssg-state_etc_selinux_configured:ste:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" check_existence="all_exist" comment="check if /sys/fs/selinux exists" id="oval:ssg-test_selinux_sys_fs_exist:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_selinux_sys_fs_exist:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="SSSD Configuration is set to use LDAP" id="oval:ssg-test_id_provider_is_set_to_ldap:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_id_provider_is_set_to_ldap:obj:1"/>
        </ind:textfilecontent54_test>
        <unix:file_test check="all" comment="Verify if /sys/firmware/efi folder exists" id="oval:ssg-test_efi_dir_existence:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_file_sys_firmware_efi:obj:1"/>
        </unix:file_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package kernel-core is installed" id="oval:ssg-inventory_test_kernel_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_kernel_installed:obj:1"/>
        </linux:rpminfo_test>
        <unix:file_test check="all" check_existence="all_exist" comment="/etc/almalinux-release exists" id="oval:ssg-test_almalinux:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-obj_almalinux:obj:1"/>
        </unix:file_test>
        <ind:textfilecontent54_test check="all" comment="Check Custom OS version" id="oval:ssg-test_almalinux8:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_almalinux8:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:family_test check="all" comment="Test installed OS is part of the unix family" id="oval:ssg-test_unix_family:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_unix_family:obj:1"/>
          <ind:state state_ref="oval:ssg-state_unix_family:ste:1"/>
        </ind:family_test>
        <ind:textfilecontent54_test check="all" comment="os-release is rhcos" id="oval:ssg-test_rhcos:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhcos:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhcos:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check for variant=CoreOS" id="oval:ssg-test_rhel_coreos_variant:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhel_coreos_variant:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhel_coreos_variant:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="Check if VERSION_ID=9.x" id="oval:ssg-test_rhel_coreos_version9:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhel_coreos_version9:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhel_coreos_version9:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="ID is rhel" id="oval:ssg-test_rhel_id:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhel_id:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhel_id:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="rhcoreos RHEL_VERSION is 9 (old format)" id="oval:ssg-test_rhcos4_rhel9_rhel_version:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_rhcos4_rhel9_rhel_version:obj:1"/>
          <ind:state state_ref="oval:ssg-state_rhcos4_rhel9_rhel_version:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:environmentvariable58_test check="all" check_existence="all_exist" comment="environment variable container is set to bwrap-osbuild" id="oval:ssg-test_installed_env_is_osbuild:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_installed_env_is_osbuild:obj:1"/>
          <ind:state state_ref="oval:ssg-state_installed_env_is_osbuild:ste:1"/>
        </ind:environmentvariable58_test>
        <unix:uname_test check="all" comment="64 bit architecture" id="oval:ssg-test_system_info_architecture_ppcle_64:tst:1" state_operator="AND" version="1">
          <unix:object object_ref="oval:ssg-object_system_info_architecture_ppcle_64:obj:1"/>
          <unix:state state_ref="oval:ssg-state_system_info_architecture_ppcle_64:ste:1"/>
        </unix:uname_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="check GRUB_CMDLINE_LINUX parameters in /etc/default/grub" id="oval:ssg-test_grub2_ipv6_disable_is_correct:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_ipv6_disable_parameter:obj:1"/>
          <ind:state state_ref="oval:ssg-state_grub2_ipv6_disable_argument:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" check_existence="none_exist" comment="ipv6.disable is not defined in /etc/default/grub" id="oval:ssg-test_grub2_ipv6_disable_is_absent:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_grub2_ipv6_disable_parameter:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="Mountpoint /boot/efi exists" id="oval:ssg-test_mount_active_boot_efi_exists:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mount_active_boot_efi_exists:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Mountpoint /boot/efi is configured" id="oval:ssg-test_mount_configured_fstab_boot_efi_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_mount_configured_fstab_boot_efi_exists:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="Mountpoint /home exists" id="oval:ssg-test_mount_active_home_exists:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mount_active_home_exists:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Mountpoint /home is configured" id="oval:ssg-test_mount_configured_fstab_home_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_mount_configured_fstab_home_exists:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="Mountpoint /opt exists" id="oval:ssg-test_mount_active_opt_exists:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mount_active_opt_exists:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Mountpoint /opt is configured" id="oval:ssg-test_mount_configured_fstab_opt_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_mount_configured_fstab_opt_exists:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="Mountpoint /srv exists" id="oval:ssg-test_mount_active_srv_exists:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mount_active_srv_exists:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Mountpoint /srv is configured" id="oval:ssg-test_mount_configured_fstab_srv_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_mount_configured_fstab_srv_exists:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="Mountpoint /tmp exists" id="oval:ssg-test_mount_active_tmp_exists:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mount_active_tmp_exists:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Mountpoint /tmp is configured" id="oval:ssg-test_mount_configured_fstab_tmp_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_mount_configured_fstab_tmp_exists:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="Mountpoint /var/log/audit exists" id="oval:ssg-test_mount_active_var_log_audit_exists:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mount_active_var_log_audit_exists:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Mountpoint /var/log/audit is configured" id="oval:ssg-test_mount_configured_fstab_var_log_audit_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_mount_configured_fstab_var_log_audit_exists:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="Mountpoint /var/log exists" id="oval:ssg-test_mount_active_var_log_exists:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mount_active_var_log_exists:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Mountpoint /var/log is configured" id="oval:ssg-test_mount_configured_fstab_var_log_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_mount_configured_fstab_var_log_exists:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="Mountpoint /var/tmp exists" id="oval:ssg-test_mount_active_var_tmp_exists:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mount_active_var_tmp_exists:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Mountpoint /var/tmp is configured" id="oval:ssg-test_mount_configured_fstab_var_tmp_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_mount_configured_fstab_var_tmp_exists:obj:1"/>
        </ind:textfilecontent54_test>
        <linux:partition_test check="all" check_existence="all_exist" comment="Mountpoint /var exists" id="oval:ssg-test_mount_active_var_exists:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-object_mount_active_var_exists:obj:1"/>
        </linux:partition_test>
        <ind:textfilecontent54_test check="all" check_existence="all_exist" comment="Mountpoint /var is configured" id="oval:ssg-test_mount_configured_fstab_var_exists:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-object_mount_configured_fstab_var_exists:obj:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="ID in os-release is ol" id="oval:ssg-test_os_id_is_os_linux_ol_gt_or_eq_8_7:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_id_is_os_linux_ol_gt_or_eq_8_7:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_id_is_os_linux_ol_gt_or_eq_8_7:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="VERSION_ID in os-release is greater than or equal 8.7" id="oval:ssg-test_os_linux_ol_gt_or_eq_8_7_gt_or_eq_8_7:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_linux_ol_gt_or_eq_8_7_gt_or_eq_8_7:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_linux_ol_gt_or_eq_8_7_gt_or_eq_8_7:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="ID in os-release is ol" id="oval:ssg-test_os_id_is_os_linux_ol_gt_or_eq_9_0:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_id_is_os_linux_ol_gt_or_eq_9_0:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_id_is_os_linux_ol_gt_or_eq_9_0:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="VERSION_ID in os-release is greater than or equal 9.0" id="oval:ssg-test_os_linux_ol_gt_or_eq_9_0_gt_or_eq_9_0:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_linux_ol_gt_or_eq_9_0_gt_or_eq_9_0:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_linux_ol_gt_or_eq_9_0_gt_or_eq_9_0:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="ID in os-release is rhel" id="oval:ssg-test_os_id_is_os_linux_rhel_gt_or_eq_8_2:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_id_is_os_linux_rhel_gt_or_eq_8_2:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_id_is_os_linux_rhel_gt_or_eq_8_2:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="VERSION_ID in os-release is greater than or equal 8.2" id="oval:ssg-test_os_linux_rhel_gt_or_eq_8_2_gt_or_eq_8_2:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_linux_rhel_gt_or_eq_8_2_gt_or_eq_8_2:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_linux_rhel_gt_or_eq_8_2_gt_or_eq_8_2:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="ID in os-release is rhel" id="oval:ssg-test_os_id_is_os_linux_rhel_gt_or_eq_8_4:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_id_is_os_linux_rhel_gt_or_eq_8_4:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_id_is_os_linux_rhel_gt_or_eq_8_4:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="VERSION_ID in os-release is greater than or equal 8.4" id="oval:ssg-test_os_linux_rhel_gt_or_eq_8_4_gt_or_eq_8_4:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_linux_rhel_gt_or_eq_8_4_gt_or_eq_8_4:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_linux_rhel_gt_or_eq_8_4_gt_or_eq_8_4:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="ID in os-release is rhel" id="oval:ssg-test_os_id_is_os_linux_rhel_gt_or_eq_8_7:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_id_is_os_linux_rhel_gt_or_eq_8_7:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_id_is_os_linux_rhel_gt_or_eq_8_7:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="VERSION_ID in os-release is greater than or equal 8.7" id="oval:ssg-test_os_linux_rhel_gt_or_eq_8_7_gt_or_eq_8_7:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_linux_rhel_gt_or_eq_8_7_gt_or_eq_8_7:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_linux_rhel_gt_or_eq_8_7_gt_or_eq_8_7:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="ID in os-release is rhel" id="oval:ssg-test_os_id_is_os_linux_rhel_gt_or_eq_9_0:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_id_is_os_linux_rhel_gt_or_eq_9_0:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_id_is_os_linux_rhel_gt_or_eq_9_0:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="VERSION_ID in os-release is greater than or equal 9.0" id="oval:ssg-test_os_linux_rhel_gt_or_eq_9_0_gt_or_eq_9_0:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_linux_rhel_gt_or_eq_9_0_gt_or_eq_9_0:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_linux_rhel_gt_or_eq_9_0_gt_or_eq_9_0:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="ID in os-release is rhel" id="oval:ssg-test_os_id_is_os_linux_rhel_le_or_eq_8_3:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_id_is_os_linux_rhel_le_or_eq_8_3:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_id_is_os_linux_rhel_le_or_eq_8_3:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="VERSION_ID in os-release is less than or equal 8.3" id="oval:ssg-test_os_linux_rhel_le_or_eq_8_3_le_or_eq_8_3:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_linux_rhel_le_or_eq_8_3_le_or_eq_8_3:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_linux_rhel_le_or_eq_8_3_le_or_eq_8_3:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="ID in os-release is rhel" id="oval:ssg-test_os_id_is_os_linux_rhel_le_or_eq_8_4:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_id_is_os_linux_rhel_le_or_eq_8_4:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_id_is_os_linux_rhel_le_or_eq_8_4:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="VERSION_ID in os-release is less than or equal 8.4" id="oval:ssg-test_os_linux_rhel_le_or_eq_8_4_le_or_eq_8_4:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_linux_rhel_le_or_eq_8_4_le_or_eq_8_4:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_linux_rhel_le_or_eq_8_4_le_or_eq_8_4:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="ID in os-release is rhel" id="oval:ssg-test_os_id_is_os_linux_rhel_ne_9_0:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_id_is_os_linux_rhel_ne_9_0:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_id_is_os_linux_rhel_ne_9_0:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="VERSION_ID in os-release is not equal 9.0" id="oval:ssg-test_os_linux_rhel_ne_9_0_ne_9_0:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_linux_rhel_ne_9_0_ne_9_0:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_linux_rhel_ne_9_0_ne_9_0:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="ID in os-release is sles" id="oval:ssg-test_os_id_is_os_linux_sles_gt_or_eq_15:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_id_is_os_linux_sles_gt_or_eq_15:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_id_is_os_linux_sles_gt_or_eq_15:ste:1"/>
        </ind:textfilecontent54_test>
        <ind:textfilecontent54_test check="all" comment="VERSION_ID in os-release is greater than or equal 15" id="oval:ssg-test_os_linux_sles_gt_or_eq_15_gt_or_eq_15:tst:1" state_operator="AND" version="1">
          <ind:object object_ref="oval:ssg-obj_os_linux_sles_gt_or_eq_15_gt_or_eq_15:obj:1"/>
          <ind:state state_ref="oval:ssg-state_os_linux_sles_gt_or_eq_15_gt_or_eq_15:ste:1"/>
        </ind:textfilecontent54_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package audit is installed" id="oval:ssg-inventory_test_package_audit_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_audit_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package autofs is installed" id="oval:ssg-inventory_test_package_autofs_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_autofs_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package avahi is installed" id="oval:ssg-inventory_test_package_avahi_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_avahi_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package bash is installed" id="oval:ssg-inventory_test_package_bash_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_bash_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package bind is installed" id="oval:ssg-inventory_test_package_bind_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_bind_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package chrony is installed" id="oval:ssg-inventory_test_package_chrony_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_chrony_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package dnf is installed" id="oval:ssg-inventory_test_package_dnf_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_dnf_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package firewalld is installed" id="oval:ssg-inventory_test_package_firewalld_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_firewalld_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package gdm is installed" id="oval:ssg-inventory_test_package_gdm_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_gdm_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package iptables is installed" id="oval:ssg-inventory_test_package_iptables_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_iptables_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package krb5-libs is installed" id="oval:ssg-inventory_test_package_krb5-libs_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_krb5-libs_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package libpwquality is installed" id="oval:ssg-inventory_test_package_libpwquality_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_libpwquality_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package libreswan is installed" id="oval:ssg-inventory_test_package_libreswan_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_libreswan_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package libuser is installed" id="oval:ssg-inventory_test_package_libuser_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_libuser_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package logrotate is installed" id="oval:ssg-inventory_test_package_logrotate_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_logrotate_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package net-snmp is installed" id="oval:ssg-inventory_test_package_net-snmp_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_net-snmp_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package nftables is installed" id="oval:ssg-inventory_test_package_nftables_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_nftables_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package nss-pam-ldapd is installed" id="oval:ssg-inventory_test_package_nss-pam-ldapd_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_nss-pam-ldapd_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package ntp is installed" id="oval:ssg-inventory_test_package_ntp_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_ntp_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package openssh-clients is installed" id="oval:ssg-inventory_test_package_openssh-clients_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_openssh-clients_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package openssh-server is installed" id="oval:ssg-inventory_test_package_openssh-server_le_7_0_le_7_0_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_openssh-server_le_7_0_le_7_0_installed:obj:1"/>
          <linux:state state_ref="oval:ssg-ste_inventory_test_package_openssh-server_le_7_0_le_7_0_installed:ste:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package openssh-server is installed" id="oval:ssg-inventory_test_package_openssh-server_le_7_5_le_7_5_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_openssh-server_le_7_5_le_7_5_installed:obj:1"/>
          <linux:state state_ref="oval:ssg-ste_inventory_test_package_openssh-server_le_7_5_le_7_5_installed:ste:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package openssh is installed" id="oval:ssg-inventory_test_package_openssh_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_openssh_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package openssl is installed" id="oval:ssg-inventory_test_package_openssl_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_openssl_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package pam is installed" id="oval:ssg-inventory_test_package_pam_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_pam_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package polkit is installed" id="oval:ssg-inventory_test_package_polkit_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_polkit_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package postfix is installed" id="oval:ssg-inventory_test_package_postfix_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_postfix_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package rootfiles is installed" id="oval:ssg-inventory_test_package_rootfiles_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_rootfiles_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package rsh-server is installed" id="oval:ssg-inventory_test_package_rsh-server_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_rsh-server_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package rsyslog is installed" id="oval:ssg-inventory_test_package_rsyslog_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_rsyslog_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package shadow-utils is installed" id="oval:ssg-inventory_test_package_shadow-utils_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_shadow-utils_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package net-snmp is installed" id="oval:ssg-inventory_test_package_snmpd_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_snmpd_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package squid is installed" id="oval:ssg-inventory_test_package_squid_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_squid_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package sssd-common is installed" id="oval:ssg-inventory_test_package_sssd_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_sssd_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package sudo is installed" id="oval:ssg-inventory_test_package_sudo_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_sudo_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package systemd-journal-remote is installed" id="oval:ssg-inventory_test_package_systemd-journal-remote_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_systemd-journal-remote_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package systemd is installed" id="oval:ssg-inventory_test_package_systemd_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_systemd_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package tcsh is installed" id="oval:ssg-inventory_test_package_tcsh_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_tcsh_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package telnet-server is installed" id="oval:ssg-inventory_test_package_telnet-server_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_telnet-server_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package tftp-server is installed" id="oval:ssg-inventory_test_package_tftp-server_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_tftp-server_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package tmux is installed" id="oval:ssg-inventory_test_package_tmux_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_tmux_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package ufw is installed" id="oval:ssg-inventory_test_package_ufw_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_ufw_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package usbguard is installed" id="oval:ssg-inventory_test_package_usbguard_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_usbguard_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:rpminfo_test check="all" check_existence="all_exist" comment="package yum is installed" id="oval:ssg-inventory_test_package_yum_installed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_inventory_test_package_yum_installed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the firewalld service is not running" id="oval:ssg-test_service_not_running_service_disabled_firewalld_firewalld:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_disabled_firewalld_firewalld:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_disabled_firewalld_firewalld:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service firewalld is masked" id="oval:ssg-test_service_loadstate_is_masked_service_disabled_firewalld_firewalld:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_disabled_firewalld_firewalld:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_disabled_firewalld_firewalld:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service firewalld is not found" id="oval:ssg-test_service_not_found_service_disabled_firewalld_firewalld:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_disabled_firewalld_firewalld:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_disabled_firewalld_firewalld:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package firewalld is removed" id="oval:ssg-service_disabled_firewalldtest_service_firewalld_package_firewalld_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_disabled_firewalldtest_service_firewalld_package_firewalld_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the iptables service is not running" id="oval:ssg-test_service_not_running_service_disabled_iptables_iptables:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_disabled_iptables_iptables:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_disabled_iptables_iptables:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service iptables is masked" id="oval:ssg-test_service_loadstate_is_masked_service_disabled_iptables_iptables:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_disabled_iptables_iptables:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_disabled_iptables_iptables:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service iptables is not found" id="oval:ssg-test_service_not_found_service_disabled_iptables_iptables:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_disabled_iptables_iptables:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_disabled_iptables_iptables:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package iptables is removed" id="oval:ssg-service_disabled_iptablestest_service_iptables_package_iptables_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_disabled_iptablestest_service_iptables_package_iptables_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the nftables service is not running" id="oval:ssg-test_service_not_running_service_disabled_nftables_nftables:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_disabled_nftables_nftables:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_disabled_nftables_nftables:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service nftables is masked" id="oval:ssg-test_service_loadstate_is_masked_service_disabled_nftables_nftables:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_disabled_nftables_nftables:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_disabled_nftables_nftables:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service nftables is not found" id="oval:ssg-test_service_not_found_service_disabled_nftables_nftables:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_disabled_nftables_nftables:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_disabled_nftables_nftables:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package nftables is removed" id="oval:ssg-service_disabled_nftablestest_service_nftables_package_nftables_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_disabled_nftablestest_service_nftables_package_nftables_removed:obj:1"/>
        </linux:rpminfo_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the ufw service is not running" id="oval:ssg-test_service_not_running_service_disabled_ufw_ufw:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_not_running_service_disabled_ufw_ufw:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_not_running_service_disabled_ufw_ufw:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the property LoadState from the service ufw is masked" id="oval:ssg-test_service_loadstate_is_masked_service_disabled_ufw_ufw:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_disabled_ufw_ufw:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_loadstate_is_masked_service_disabled_ufw_ufw:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:systemdunitproperty_test check="all" check_existence="any_exist" comment="Test that the service ufw is not found" id="oval:ssg-test_service_not_found_service_disabled_ufw_ufw:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_loadstate_is_masked_service_disabled_ufw_ufw:obj:1"/>
          <linux:state state_ref="oval:ssg-state_service_is_not_found_service_disabled_ufw_ufw:ste:1"/>
        </linux:systemdunitproperty_test>
        <linux:rpminfo_test check="all" check_existence="none_exist" comment="package ufw is removed" id="oval:ssg-service_disabled_ufwtest_service_ufw_package_ufw_removed:tst:1" state_operator="AND" version="1">
          <linux:object object_ref="oval:ssg-obj_service_disabled_ufwtest_service_ufw_package_ufw_removed:obj:1"/>
        </linux:rpminfo_test>
      </oval-def:tests>
      <oval-def:objects>
        <linux:rpminfo_object id="oval:ssg-obj_bootc_platform_test_kernel_installed:obj:1" version="1">
          <linux:name>kernel</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_bootc_platform_test_rpm_ostree_installed:obj:1" version="1">
          <linux:name>rpm-ostree</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_bootc_platform_test_bootc_installed:obj:1" version="1">
          <linux:name>bootc</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_bootc_platform_test_openshift_kubelet_removed:obj:1" version="1">
          <linux:name>openshift-kubelet</linux:name>
        </linux:rpminfo_object>
        <unix:file_object comment="The file /run/ostree-booted exists" id="oval:ssg-bootc_platform_obj_run_ostree_booted_exists:obj:1" version="1">
          <unix:filepath operation="equals">/run/ostree-booted</unix:filepath>
        </unix:file_object>
        <unix:file_object comment="The file /ostree exists" id="oval:ssg-bootc_platform_obj_ostree_symlink_exists:obj:1" version="1">
          <unix:filepath operation="equals">/ostree</unix:filepath>
        </unix:file_object>
        <linux:rpminfo_object id="oval:ssg-obj_env_has_grub2_installed:obj:1" version="1">
          <linux:name>grub2-common</linux:name>
        </linux:rpminfo_object>
        <unix:file_object id="oval:ssg-object_system_using_opal:obj:1" version="1">
          <unix:filepath>/sys/firmware/opal</unix:filepath>
        </unix:file_object>
        <linux:rpminfo_object id="oval:ssg-obj_env_has_ovirt-host_installed:obj:1" version="1">
          <linux:name>ovirt-host</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_env_has_ovirt-engine_installed:obj:1" version="1">
          <linux:name>ovirt-engine</linux:name>
        </linux:rpminfo_object>
        <unix:file_object comment="/proc/net/wireless file" id="oval:ssg-object_proc_net_wireless_exists:obj:1" version="1">
          <unix:filepath>/proc/net/wireless</unix:filepath>
        </unix:file_object>
        <unix:file_object comment="Check file /.dockerenv" id="oval:ssg-object_installed_env_is_a_docker_container:obj:1" version="1">
          <unix:filepath datatype="string">/.dockerenv</unix:filepath>
        </unix:file_object>
        <unix:file_object comment="Check file /run/.containerenv" id="oval:ssg-object_installed_env_is_a_podman_container:obj:1" version="1">
          <unix:filepath datatype="string">/run/.containerenv</unix:filepath>
        </unix:file_object>
        <linux:rpminfo_object id="oval:ssg-obj_krb5_server_version_1_17_18:obj:1" version="1">
          <linux:name>krb5-server</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_krb5_workstation_version_1_17_18:obj:1" version="1">
          <linux:name>krb5-workstation</linux:name>
        </linux:rpminfo_object>
        <ind:textfilecontent54_object id="oval:ssg-object_nfs_mount_defined:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^\s*\[?[\.\w:-]+\]?[:=][/\w-]+\s+[/\w\\-]+\s+nfs[4]?\s+(.*)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_proc_sys_kernel_osrelease_arch_aarch64:obj:1" version="1">
          <ind:filepath operation="pattern match">^/proc/sys/kernel/(osrelease|arch)</ind:filepath>
          <ind:pattern operation="pattern match">^.*\.aarch64$|^aarch64$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_proc_sys_kernel_osrelease_arch_s390x:obj:1" version="1">
          <ind:filepath operation="pattern match">^/proc/sys/kernel/(osrelease|arch)</ind:filepath>
          <ind:pattern operation="pattern match">^.*\.s390x$|^s390x$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-object_proc_sys_kernel_osrelease_arch_x86_64:obj:1" version="1">
          <ind:filepath operation="pattern match">^/proc/sys/kernel/(osrelease|arch)</ind:filepath>
          <ind:pattern operation="pattern match">^.*\.x86_64$|^x86_64$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:sysctl_object id="oval:ssg-obj_runtime_kernel_fips_enabled:obj:1" version="1">
          <unix:name>crypto.fips_enabled</unix:name>
        </unix:sysctl_object>
        <ind:textfilecontent54_object id="oval:ssg-object_etc_selinux_configured:obj:1" version="1">
          <ind:filepath>/etc/selinux/config</ind:filepath>
          <ind:pattern operation="pattern match">^SELINUX=(.*)$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/sys/fs/selinux" id="oval:ssg-object_selinux_sys_fs_exist:obj:1" version="1">
          <unix:path>/sys/fs/selinux</unix:path>
          <unix:filename xsi:nil="true"/>
        </unix:file_object>
        <ind:textfilecontent54_object id="oval:ssg-object_id_provider_is_set_to_ldap:obj:1" version="1">
          <ind:filepath>/etc/sssd/sssd.conf</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*\[domain\/[^]]*]([^\n\[\]]*\n+)+?[\s]*id_provider[ \t]*=[ \t]*((?i)ldap)[ \t]*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <unix:file_object comment="/sys/firmware/efi" id="oval:ssg-object_file_sys_firmware_efi:obj:1" version="1">
          <unix:path>/sys/firmware/efi</unix:path>
          <unix:filename xsi:nil="true"/>
        </unix:file_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_kernel_installed:obj:1" version="1">
          <linux:name>kernel-core</linux:name>
        </linux:rpminfo_object>
        <unix:file_object comment="check /etc/almalinux file" id="oval:ssg-obj_almalinux:obj:1" version="1">
          <unix:filepath>/etc/almalinux-release</unix:filepath>
        </unix:file_object>
        <ind:textfilecontent54_object comment="Check AlmaLinux OS version" id="oval:ssg-obj_almalinux8:obj:1" version="1">
          <ind:filepath>/etc/almalinux-release</ind:filepath>
          <ind:pattern operation="pattern match">^AlmaLinux release 8.[0-9]+ .*$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:family_object id="oval:ssg-object_unix_family:obj:1" version="1"/>
        <ind:textfilecontent54_object id="oval:ssg-obj_rhcos:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^ID="(\w+)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rhel_coreos_variant:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^VARIANT_ID=(\S+)$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rhel_coreos_version9:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^VERSION_ID="(\d+\.\d+)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rhel_id:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^ID="(\w+)"$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_rhcos4_rhel9_rhel_version:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^RHEL_VERSION="?(\d+\.?\d*)"?$</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:environmentvariable58_object id="oval:ssg-object_installed_env_is_osbuild:obj:1" version="1">
          <ind:pid datatype="int" xsi:nil="true"/>
          <ind:name>container</ind:name>
        </ind:environmentvariable58_object>
        <unix:uname_object comment="64 bit architecture" id="oval:ssg-object_system_info_architecture_ppcle_64:obj:1" version="1"/>
        <ind:textfilecontent54_object id="oval:ssg-object_grub2_ipv6_disable_parameter:obj:1" version="1">
          <ind:filepath>/etc/default/grub</ind:filepath>
          <ind:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX=".*ipv6\.disable=(\d).*$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_mount_active_boot_efi_exists:obj:1" version="1">
          <linux:mount_point>/boot/efi</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_mount_configured_fstab_boot_efi_exists:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*[\S]+[\s]+/boot/efi[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_mount_active_home_exists:obj:1" version="1">
          <linux:mount_point>/home</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_mount_configured_fstab_home_exists:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*[\S]+[\s]+/home[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_mount_active_opt_exists:obj:1" version="1">
          <linux:mount_point>/opt</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_mount_configured_fstab_opt_exists:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*[\S]+[\s]+/opt[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_mount_active_srv_exists:obj:1" version="1">
          <linux:mount_point>/srv</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_mount_configured_fstab_srv_exists:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*[\S]+[\s]+/srv[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_mount_active_tmp_exists:obj:1" version="1">
          <linux:mount_point>/tmp</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_mount_configured_fstab_tmp_exists:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*[\S]+[\s]+/tmp[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_mount_active_var_log_audit_exists:obj:1" version="1">
          <linux:mount_point>/var/log/audit</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_mount_configured_fstab_var_log_audit_exists:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*[\S]+[\s]+/var/log/audit[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_mount_active_var_log_exists:obj:1" version="1">
          <linux:mount_point>/var/log</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_mount_configured_fstab_var_log_exists:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*[\S]+[\s]+/var/log[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_mount_active_var_tmp_exists:obj:1" version="1">
          <linux:mount_point>/var/tmp</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_mount_configured_fstab_var_tmp_exists:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*[\S]+[\s]+/var/tmp[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:partition_object id="oval:ssg-object_mount_active_var_exists:obj:1" version="1">
          <linux:mount_point>/var</linux:mount_point>
        </linux:partition_object>
        <ind:textfilecontent54_object id="oval:ssg-object_mount_configured_fstab_var_exists:obj:1" version="1">
          <ind:filepath>/etc/fstab</ind:filepath>
          <ind:pattern operation="pattern match">^[\s]*[\S]+[\s]+/var[\s]+[\S]+[\s]+([\S]+)</ind:pattern>
          <ind:instance datatype="int">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_id_is_os_linux_ol_gt_or_eq_8_7:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_linux_ol_gt_or_eq_8_7_gt_or_eq_8_7:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^VERSION_ID=["']?([\w.]+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_id_is_os_linux_ol_gt_or_eq_9_0:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_linux_ol_gt_or_eq_9_0_gt_or_eq_9_0:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^VERSION_ID=["']?([\w.]+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_id_is_os_linux_rhel_gt_or_eq_8_2:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_linux_rhel_gt_or_eq_8_2_gt_or_eq_8_2:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^VERSION_ID=["']?([\w.]+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_id_is_os_linux_rhel_gt_or_eq_8_4:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_linux_rhel_gt_or_eq_8_4_gt_or_eq_8_4:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^VERSION_ID=["']?([\w.]+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_id_is_os_linux_rhel_gt_or_eq_8_7:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_linux_rhel_gt_or_eq_8_7_gt_or_eq_8_7:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^VERSION_ID=["']?([\w.]+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_id_is_os_linux_rhel_gt_or_eq_9_0:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_linux_rhel_gt_or_eq_9_0_gt_or_eq_9_0:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^VERSION_ID=["']?([\w.]+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_id_is_os_linux_rhel_le_or_eq_8_3:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_linux_rhel_le_or_eq_8_3_le_or_eq_8_3:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^VERSION_ID=["']?([\w.]+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_id_is_os_linux_rhel_le_or_eq_8_4:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_linux_rhel_le_or_eq_8_4_le_or_eq_8_4:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^VERSION_ID=["']?([\w.]+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_id_is_os_linux_rhel_ne_9_0:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_linux_rhel_ne_9_0_ne_9_0:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^VERSION_ID=["']?([\w.]+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_id_is_os_linux_sles_gt_or_eq_15:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <ind:textfilecontent54_object id="oval:ssg-obj_os_linux_sles_gt_or_eq_15_gt_or_eq_15:obj:1" version="1">
          <ind:filepath>/etc/os-release</ind:filepath>
          <ind:pattern operation="pattern match">^VERSION_ID=["']?([\w.]+)["']?$</ind:pattern>
          <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
        </ind:textfilecontent54_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_audit_installed:obj:1" version="1">
          <linux:name>audit</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_autofs_installed:obj:1" version="1">
          <linux:name>autofs</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_avahi_installed:obj:1" version="1">
          <linux:name>avahi</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_bash_installed:obj:1" version="1">
          <linux:name>bash</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_bind_installed:obj:1" version="1">
          <linux:name>bind</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_chrony_installed:obj:1" version="1">
          <linux:name>chrony</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_dnf_installed:obj:1" version="1">
          <linux:name>dnf</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_firewalld_installed:obj:1" version="1">
          <linux:name>firewalld</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_gdm_installed:obj:1" version="1">
          <linux:name>gdm</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_iptables_installed:obj:1" version="1">
          <linux:name>iptables</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_krb5-libs_installed:obj:1" version="1">
          <linux:name>krb5-libs</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_libpwquality_installed:obj:1" version="1">
          <linux:name>libpwquality</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_libreswan_installed:obj:1" version="1">
          <linux:name>libreswan</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_libuser_installed:obj:1" version="1">
          <linux:name>libuser</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_logrotate_installed:obj:1" version="1">
          <linux:name>logrotate</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_net-snmp_installed:obj:1" version="1">
          <linux:name>net-snmp</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_nftables_installed:obj:1" version="1">
          <linux:name>nftables</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_nss-pam-ldapd_installed:obj:1" version="1">
          <linux:name>nss-pam-ldapd</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_ntp_installed:obj:1" version="1">
          <linux:name>ntp</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_openssh-clients_installed:obj:1" version="1">
          <linux:name>openssh-clients</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_openssh-server_le_7_0_le_7_0_installed:obj:1" version="1">
          <linux:name>openssh-server</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_openssh-server_le_7_5_le_7_5_installed:obj:1" version="1">
          <linux:name>openssh-server</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_openssh_installed:obj:1" version="1">
          <linux:name>openssh</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_openssl_installed:obj:1" version="1">
          <linux:name>openssl</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_pam_installed:obj:1" version="1">
          <linux:name>pam</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_polkit_installed:obj:1" version="1">
          <linux:name>polkit</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_postfix_installed:obj:1" version="1">
          <linux:name>postfix</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_rootfiles_installed:obj:1" version="1">
          <linux:name>rootfiles</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_rsh-server_installed:obj:1" version="1">
          <linux:name>rsh-server</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_rsyslog_installed:obj:1" version="1">
          <linux:name>rsyslog</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_shadow-utils_installed:obj:1" version="1">
          <linux:name>shadow-utils</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_snmpd_installed:obj:1" version="1">
          <linux:name>net-snmp</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_squid_installed:obj:1" version="1">
          <linux:name>squid</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_sssd_installed:obj:1" version="1">
          <linux:name>sssd-common</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_sudo_installed:obj:1" version="1">
          <linux:name>sudo</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_systemd-journal-remote_installed:obj:1" version="1">
          <linux:name>systemd-journal-remote</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_systemd_installed:obj:1" version="1">
          <linux:name>systemd</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_tcsh_installed:obj:1" version="1">
          <linux:name>tcsh</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_telnet-server_installed:obj:1" version="1">
          <linux:name>telnet-server</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_tftp-server_installed:obj:1" version="1">
          <linux:name>tftp-server</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_tmux_installed:obj:1" version="1">
          <linux:name>tmux</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_ufw_installed:obj:1" version="1">
          <linux:name>ufw</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_usbguard_installed:obj:1" version="1">
          <linux:name>usbguard</linux:name>
        </linux:rpminfo_object>
        <linux:rpminfo_object id="oval:ssg-obj_inventory_test_package_yum_installed:obj:1" version="1">
          <linux:name>yum</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of firewalld" id="oval:ssg-obj_service_not_running_service_disabled_firewalld_firewalld:obj:1" version="1">
          <linux:unit operation="pattern match">^firewalld\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of firewalld" id="oval:ssg-obj_service_loadstate_is_masked_service_disabled_firewalld_firewalld:obj:1" version="1">
          <linux:unit operation="pattern match">^firewalld\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_disabled_firewalldtest_service_firewalld_package_firewalld_removed:obj:1" version="1">
          <linux:name>firewalld</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of iptables" id="oval:ssg-obj_service_not_running_service_disabled_iptables_iptables:obj:1" version="1">
          <linux:unit operation="pattern match">^iptables\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of iptables" id="oval:ssg-obj_service_loadstate_is_masked_service_disabled_iptables_iptables:obj:1" version="1">
          <linux:unit operation="pattern match">^iptables\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_disabled_iptablestest_service_iptables_package_iptables_removed:obj:1" version="1">
          <linux:name>iptables</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of nftables" id="oval:ssg-obj_service_not_running_service_disabled_nftables_nftables:obj:1" version="1">
          <linux:unit operation="pattern match">^nftables\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of nftables" id="oval:ssg-obj_service_loadstate_is_masked_service_disabled_nftables_nftables:obj:1" version="1">
          <linux:unit operation="pattern match">^nftables\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_disabled_nftablestest_service_nftables_package_nftables_removed:obj:1" version="1">
          <linux:name>nftables</linux:name>
        </linux:rpminfo_object>
        <linux:systemdunitproperty_object comment="Retrieve the ActiveState property of ufw" id="oval:ssg-obj_service_not_running_service_disabled_ufw_ufw:obj:1" version="1">
          <linux:unit operation="pattern match">^ufw\.(service|socket)$</linux:unit>
          <linux:property>ActiveState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:systemdunitproperty_object comment="Retrieve the LoadState property of ufw" id="oval:ssg-obj_service_loadstate_is_masked_service_disabled_ufw_ufw:obj:1" version="1">
          <linux:unit operation="pattern match">^ufw\.(service|socket)$</linux:unit>
          <linux:property>LoadState</linux:property>
        </linux:systemdunitproperty_object>
        <linux:rpminfo_object id="oval:ssg-obj_service_disabled_ufwtest_service_ufw_package_ufw_removed:obj:1" version="1">
          <linux:name>ufw</linux:name>
        </linux:rpminfo_object>
      </oval-def:objects>
      <oval-def:states>
        <unix:file_state comment="The file /ostree is a symlink" id="oval:ssg-bootc_platform_ste_ostree_symlink_exists:ste:1" operator="AND" version="1">
          <unix:filepath operation="equals">/ostree</unix:filepath>
          <unix:type operation="equals">symbolic link</unix:type>
        </unix:file_state>
        <linux:rpminfo_state id="oval:ssg-state_krb5_server_version_1_17_18:ste:1" operator="AND" version="1">
          <linux:evr datatype="evr_string" operation="less than">0:1.17-18</linux:evr>
        </linux:rpminfo_state>
        <linux:rpminfo_state id="oval:ssg-state_krb5_workstation_version_1_17_18:ste:1" operator="AND" version="1">
          <linux:evr datatype="evr_string" operation="less than">0:1.17-18</linux:evr>
        </linux:rpminfo_state>
        <unix:sysctl_state id="oval:ssg-state_runtime_kernel_fips_enabled:ste:1" operator="AND" version="1">
          <unix:value datatype="int" operation="equals">1</unix:value>
        </unix:sysctl_state>
        <ind:textfilecontent54_state id="oval:ssg-state_etc_selinux_configured:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="string" operation="pattern match">^(enforcing|permissive)$</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:family_state id="oval:ssg-state_unix_family:ste:1" operator="AND" version="1">
          <ind:family>unix</ind:family>
        </ind:family_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rhcos:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">rhcos</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rhel_coreos_variant:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">coreos</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rhel_coreos_version9:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^9\.</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rhel_id:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">rhel</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_rhcos4_rhel9_rhel_version:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">^9\.</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:environmentvariable58_state id="oval:ssg-state_installed_env_is_osbuild:ste:1" operator="AND" version="1">
          <ind:value>bwrap-osbuild</ind:value>
        </ind:environmentvariable58_state>
        <unix:uname_state comment="64 bit architecture" id="oval:ssg-state_system_info_architecture_ppcle_64:ste:1" operator="AND" version="1">
          <unix:processor_type operation="equals">ppc64le</unix:processor_type>
        </unix:uname_state>
        <ind:textfilecontent54_state id="oval:ssg-state_grub2_ipv6_disable_argument:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="int" operation="equals">0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_id_is_os_linux_ol_gt_or_eq_8_7:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">ol</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_linux_ol_gt_or_eq_8_7_gt_or_eq_8_7:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="version" operation="greater than or equal">8.7</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_id_is_os_linux_ol_gt_or_eq_9_0:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">ol</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_linux_ol_gt_or_eq_9_0_gt_or_eq_9_0:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="version" operation="greater than or equal">9.0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_id_is_os_linux_rhel_gt_or_eq_8_2:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">rhel</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_linux_rhel_gt_or_eq_8_2_gt_or_eq_8_2:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="version" operation="greater than or equal">8.2</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_id_is_os_linux_rhel_gt_or_eq_8_4:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">rhel</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_linux_rhel_gt_or_eq_8_4_gt_or_eq_8_4:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="version" operation="greater than or equal">8.4</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_id_is_os_linux_rhel_gt_or_eq_8_7:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">rhel</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_linux_rhel_gt_or_eq_8_7_gt_or_eq_8_7:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="version" operation="greater than or equal">8.7</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_id_is_os_linux_rhel_gt_or_eq_9_0:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">rhel</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_linux_rhel_gt_or_eq_9_0_gt_or_eq_9_0:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="version" operation="greater than or equal">9.0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_id_is_os_linux_rhel_le_or_eq_8_3:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">rhel</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_linux_rhel_le_or_eq_8_3_le_or_eq_8_3:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="version" operation="less than or equal">8.3</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_id_is_os_linux_rhel_le_or_eq_8_4:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">rhel</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_linux_rhel_le_or_eq_8_4_le_or_eq_8_4:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="version" operation="less than or equal">8.4</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_id_is_os_linux_rhel_ne_9_0:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">rhel</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_linux_rhel_ne_9_0_ne_9_0:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="version" operation="not equal">9.0</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_id_is_os_linux_sles_gt_or_eq_15:ste:1" operator="AND" version="1">
          <ind:subexpression operation="pattern match">sles</ind:subexpression>
        </ind:textfilecontent54_state>
        <ind:textfilecontent54_state id="oval:ssg-state_os_linux_sles_gt_or_eq_15_gt_or_eq_15:ste:1" operator="AND" version="1">
          <ind:subexpression datatype="version" operation="greater than or equal">15</ind:subexpression>
        </ind:textfilecontent54_state>
        <linux:rpminfo_state id="oval:ssg-ste_inventory_test_package_openssh-server_le_7_0_le_7_0_installed:ste:1" operator="AND" version="1">
          <linux:evr datatype="evr_string" operation="less than">0:7.0-0</linux:evr>
        </linux:rpminfo_state>
        <linux:rpminfo_state id="oval:ssg-ste_inventory_test_package_openssh-server_le_7_5_le_7_5_installed:ste:1" operator="AND" version="1">
          <linux:evr datatype="evr_string" operation="less than">0:7.5-0</linux:evr>
        </linux:rpminfo_state>
        <linux:systemdunitproperty_state comment="firewalld is not running" id="oval:ssg-state_service_not_running_service_disabled_firewalld_firewalld:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_disabled_firewalld_firewalld:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_disabled_firewalld_firewalld:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="iptables is not running" id="oval:ssg-state_service_not_running_service_disabled_iptables_iptables:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_disabled_iptables_iptables:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_disabled_iptables_iptables:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="nftables is not running" id="oval:ssg-state_service_not_running_service_disabled_nftables_nftables:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_disabled_nftables_nftables:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_disabled_nftables_nftables:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="ufw is not running" id="oval:ssg-state_service_not_running_service_disabled_ufw_ufw:ste:1" operator="AND" version="1">
          <linux:value operation="pattern match">inactive|failed</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="LoadState is set to masked" id="oval:ssg-state_service_loadstate_is_masked_service_disabled_ufw_ufw:ste:1" operator="AND" version="1">
          <linux:value>masked</linux:value>
        </linux:systemdunitproperty_state>
        <linux:systemdunitproperty_state comment="Service is not found" id="oval:ssg-state_service_is_not_found_service_disabled_ufw_ufw:ste:1" operator="AND" version="1">
          <linux:value>not-found</linux:value>
        </linux:systemdunitproperty_state>
      </oval-def:states>
    </oval-def:oval_definitions>
  </ds:component>
</ds:data-stream-collection>

Youez - 2016 - github.com/yon3zu
LinuXploit